# Conquest default configuration file name = "cq-default-profile" # Important file paths and locations private-key-file = "data/keys/conquest-server_x25519_private.key" database-file = "data/conquest.db" # General agent settings [agent] sleep = 5 user-agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" # ---------------------------------------------------------- # HTTP GET # ---------------------------------------------------------- # Defines URI endpoints for HTTP GET requests [http-get] endpoints = [ "/get", "/api/v1.2/status.js" ] # Defines where the heartbeat is placed within the HTTP GET request # Allows for data transformation using encoding (base64, base64url, ...), appending and prepending of strings # Metadata can be stored in a Header (e.g. JWT Token, Session Cookie), URI parameter, appended to the URI or request body # Encoding is only applied to the payload and not the prepended or appended strings [http-get.agent.heartbeat] placement = { type = "header", name = "Authorization" } encoding = { type = "base64", url-safe = true } prefix = "Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9." suffix = ".######################################-####" # Example: PHP session cookie # placement = { type = "header", name = "Cookie" } # prefix = "PHPSESSID=" # suffix = ", path=/" # encoding = { type = "base64", url-safe = true } # Other examples # placement = { type = "parameter", name = "id" } # placement = { type = "uri" } # Defines arbitrary URI parameters that are added to the request [http-get.agent.parameters] id = "#####-#####" lang = "en-US" # Defines arbitrary headers that are added by the agent when performing a HTTP GET request [http-get.agent.headers] Host = [ "wikipedia.org", "google.com", "127.0.0.1" ] Connection = "Keep-Alive" Cache-Control = "no-cache" # Defines arbitrary headers that are added to the server's response [http-get.server.headers] Server = "nginx" Content-Type = "application/octet-stream" Connection = "Keep-Alive" # Defines how the server's response to the task retrieval request is rendered # Allows same data transformation options as the agent metadata, allowing it to be embedded in benign content # e.g base64-encoded in a svg/img [http-get.server.output] placement = { type = "body" } # encoding = { type = "base64" } # prefix = "Wikipedia" # ---------------------------------------------------------- # HTTP POST # ---------------------------------------------------------- [http-post] # Defines URI endpoints for HTTP POST requests endpoints = [ "/post", "/api/v2/get.js" ] # Post request can also be sent with the HTTP verb PUT instead request-methods = [ "POST", "PUT" ] [http-post.agent.headers] Host = [ "wikipedia.org", "google.com", "127.0.0.1" ] Content-Type = "application/octet-stream" Connection = "Keep-Alive" Cache-Control = "no-cache" [http-post.agent.output] placement = { type = "body" } [http-post.server.headers] Server = "nginx" [http-post.server.output] placement = { type = "body" }