okay here it goes
how many of u guys actually use c2 ? like for learning and shii may be work stuff
if u are not using it am telling u that u are missing a lotta shii there fr
i will share the matrix there are a lot of them around 170 if am not wrong which some of them are paid ( but u can find the cr4cked one hmm :)) ) and most of them are open source
@AfroSec
how many of u guys actually use c2 ? like for learning and shii may be work stuff
if u are not using it am telling u that u are missing a lotta shii there fr
i will share the matrix there are a lot of them around 170 if am not wrong which some of them are paid ( but u can find the cr4cked one hmm :)) ) and most of them are open source
@AfroSec
π₯°3β€1
AfroSec
okay here it goes how many of u guys actually use c2 ? like for learning and shii may be work stuff if u are not using it am telling u that u are missing a lotta shii there fr i will share the matrix there are a lot of them around 170 if am not wrong whichβ¦
Google Docs
C2Matrix
https://docs.google.com/spreadsheets/d/1b4mUxa6cDQuTV2BPC6aA-GR4zGZi0ooPYtBe4IgPsSc/edit?gid=0#gid=0
check them out here
@AfroSec
check them out here
@AfroSec
β‘5
if u ask me why i get mad sometimes, cuz there is no real group in ethio for discussing real red team engagement and stuff like that
so far i didnt see any group, we need to move faster π
knowing idor or other owasp doesnt make us red teamer or knowing about what red teaming doesnt make us red teamer unless we make our hand dirty with that thing, just saying yk
what i like to say is that from now on this channel is for red team and red team only fr πͺ
@AfroSec
so far i didnt see any group, we need to move faster π
knowing idor or other owasp doesnt make us red teamer or knowing about what red teaming doesnt make us red teamer unless we make our hand dirty with that thing, just saying yk
what i like to say is that from now on this channel is for red team and red team only fr πͺ
@AfroSec
β‘6β€3π―1
So⦠u just landed initial access on a server or compromised an org's system.
Whatβs next then ?
sudo rm -rf / π? Nah
u need a solid plan and decent infrastructure that guarantees persistence for as long as you want without having to re-exploit the same vuln over and over :(
Thatβs where proper infra becomes the game-changer in here .
Just running a C2 framework doesnβt magically make us anonymous or stealthy we need infrastructure OPSEC layered with serious evasion techniques and a deep plan to stay hidden through out the engagement.
In my view, we should already know exactly how to deploy and harden the full infra stack:
C2 server
Payload hosting
Phishing kit / landing pages
Redirectors (multiple layers)
Other supporting pieces
Iβve got some resources in hand so will share it to u guys,
just finished spinning up a Discord server for the discussion / sharing. Will drop the link once Iβve customized it properly (rules, channels, etc.).
so u guys down to follow along, share tips, or collab on hardening this kind of infra?
@AfroSec
Whatβs next then ?
sudo rm -rf / π? Nah
u need a solid plan and decent infrastructure that guarantees persistence for as long as you want without having to re-exploit the same vuln over and over :(
Thatβs where proper infra becomes the game-changer in here .
Just running a C2 framework doesnβt magically make us anonymous or stealthy we need infrastructure OPSEC layered with serious evasion techniques and a deep plan to stay hidden through out the engagement.
In my view, we should already know exactly how to deploy and harden the full infra stack:
C2 server
Payload hosting
Phishing kit / landing pages
Redirectors (multiple layers)
Other supporting pieces
Iβve got some resources in hand so will share it to u guys,
just finished spinning up a Discord server for the discussion / sharing. Will drop the link once Iβve customized it properly (rules, channels, etc.).
so u guys down to follow along, share tips, or collab on hardening this kind of infra?
@AfroSec
10π₯7β‘4β€2
so there are 3 DNS records which have impact on email sec
> SPF
> DKIM
> DMARC
lets see each one of them
if u ask me what MOTW is here is the post i wrote abt it > https://t.me/AfroSec/765
@AfroSec
> SPF
> DKIM
> DMARC
lets see each one of them
SPF:- Sender Policy Framework
> lists which servers are allowed to send email for your domain
> for instance example.com's SPF record says like :"only 192.168.x.x can send an email as @example.com"
DKIM:- DomainKeys Identified Mail
> when you send an email, your server stamps it with a unique, invisible signature. when the receiving server gets it, they check that signature against your domainβs public key, if your mail lack this one it will get rejected entirely or flagged as spam
DMARC:- Domain-based Message Authentication, Reporting & Conformance
> simply Tells receiving servers what to do with emails that fail SPF/DKIM checks
so from our RedTeam perspective we will check those records which is kinda passive recon thing,
then if the server miss one of those like
1, No SPF rec
2, SPF and DKIM but No DMARC
3, No SPF and No DMARC
those are our jackpots kinda a way in ;), how ?
social engineering comes to play here
we can send an email as example.com for that example.com employee which have initial access payload either it could be macros, Dll side loading or anykinda thing that u prepare for ur foothold
the main and good thing is email gateways and browsers wont flag for MOTW that attachment why because we just send that email as internal email with trusted domain :)) lucky us huh ?
if u ask me what MOTW is here is the post i wrote abt it > https://t.me/AfroSec/765
@AfroSec
5β‘5
AfroSec
so there are 3 DNS records which have impact on email sec > SPF > DKIM > DMARC lets see each one of them SPF:- Sender Policy Framework > lists which servers are allowed to send email for your domain > for instance example.com's SPF recordβ¦
Mail-Tester
Newsletters spam test by mail-tester.com
mail-tester.com is a free online service that allows you to test your emails for Spam, Malformed Content and Mail Server Configuration problems
β‘4
Discord
Discord - Group Chat Thatβs All Fun & Games
Discord is great for playing games and chilling with friends, or even building a worldwide community. Customize your own space to talk, play, and hang out.
yoo so i just created a Red Team Discord
If you're into hacking, redteaming ofc , or learning real-world security come join us.
π https://discord.gg/t4tcrF95
Letβs grow and learn together :))
@AfroSec
If you're into hacking, redteaming ofc , or learning real-world security come join us.
π https://discord.gg/t4tcrF95
Letβs grow and learn together :))
@AfroSec
β‘6β€1π1