Skip to main content
HTTP/HTTPS listeners are the primary method for external agent communication with the Havoc teamserver. They provide a flexible, customizable communication channel that can be tailored to blend in with legitimate network traffic.

Basic Configuration

HTTP listeners are defined in the Listeners block of your profile:

Configuration Options

Required Parameters

string
required
Unique identifier for the listener. This name is displayed in the Havoc client and used to reference the listener.
array
required
List of callback hosts that agents will connect to. Multiple hosts can be specified for redundancy and rotation.
string
required
The network interface address where the listener binds. Use "0.0.0.0" to bind to all interfaces, or specify a specific IP address.
integer
required
The port on which the teamserver listens for incoming agent connections.

Network Configuration

integer
default:"PortBind value"
The port that agents use to connect. This is useful when operating behind a redirector or port forwarding setup where the external port differs from the bind port.
string
default:"round-robin"
Strategy for rotating through multiple callback hosts. Supported values:
  • "round-robin": Cycle through hosts sequentially
  • "random": Randomly select from available hosts

Security Options

boolean
default:"false"
Enable HTTPS/TLS encryption for the listener. When true, the teamserver automatically generates self-signed certificates or uses provided certificates.
Always set Secure = true for production operations to encrypt agent communications.
block
Custom TLS certificate configuration. If not specified with Secure = true, self-signed certificates are automatically generated.

Traffic Shaping

string
Custom User-Agent string that agents must use for callbacks. The listener validates this header and rejects requests with mismatched User-Agent values.
array
List of valid URI paths for agent callbacks. Requests to other paths are rejected with a fake 404 page.
array
Custom HTTP headers that agents must include in requests. The listener validates these headers (case-insensitive) and rejects non-matching requests.
Headers Connection and Accept-Encoding are automatically ignored during validation as they may vary by HTTP client implementation.
string
default:"POST"
HTTP method for agent callbacks. Typically POST for C2 traffic.

Response Configuration

block
Configure custom response headers to blend in with legitimate services.

Proxy Support

block
Configure agents to use a proxy for callbacks. Useful when agents are deployed in environments with restricted egress.

Operational Security

string
Automatically terminate agent operations after the specified date and time. Format: YYYY-MM-DD HH:MM:SS
string
Restrict agent callbacks to specific hours. Format: HH:MM-HH:MM (24-hour format)

Configuration Examples

Basic HTTP Listener

HTTPS Listener with Custom Certificates

Microsoft Teams Profile Mimicry

This example mimics Microsoft Teams traffic for evasion:

Listener with Kill Date and Working Hours

Redirector Setup

When using a redirector (e.g., Apache mod_rewrite, Nginx reverse proxy), configure different bind and connection ports:

Request Validation

The HTTP/HTTPS listener implements strict request validation to prevent unauthorized access:
  1. User-Agent Validation: If UserAgent is set, requests with mismatched User-Agent headers are rejected
  2. URI Validation: If Uris are specified, requests to unlisted paths receive a fake 404 response
  3. Header Validation: All headers in the Headers list must match (case-insensitive value comparison)
  4. Protocol Validation: The request must contain valid Havoc protocol data
Failed validation results in a fake nginx 404 error page being served to the client.

Behind Redirectors

When operating behind a redirector or load balancer, configure the Demon block in your profile:
This instructs the listener to trust the X-Forwarded-For header for identifying the true client IP address.
Only enable TrustXForwardedFor when operating behind a trusted redirector. Enabling this on publicly accessible listeners can allow IP spoofing.

Multiple Listeners

You can define multiple HTTP/HTTPS listeners in a single profile:

Troubleshooting

Listener Won’t Start

  • Verify the port is not already in use: netstat -tuln | grep <port>
  • Check file permissions for custom certificates
  • Ensure HostBind IP address exists on the system
  • Review teamserver logs for detailed error messages

Agents Not Connecting

  • Verify firewall rules allow traffic on PortBind
  • Check that Hosts resolve to the correct IP address
  • Ensure agent profile matches listener configuration (headers, URIs, User-Agent)
  • Test connectivity: curl -v http(s)://<host>:<port>/<uri>

Certificate Errors

  • Verify certificate and key file paths are correct and readable
  • Ensure certificate matches the hostname in Hosts
  • Check certificate expiration date
  • For auto-generated certificates, verify the listener path is writable