Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Live Cyber Attack Map Global
https://cdn-images-1.medium.com/max/1556/1*qamCUBhedW_o7saxqxEfEw.png
When it comes to real-time cyber-attack maps, some are funny, some seem ominous, and all of them tell a story that words alone cannot…
Continue reading on Medium »
Live Cyber Attack Map Global
https://cdn-images-1.medium.com/max/1556/1*qamCUBhedW_o7saxqxEfEw.png
When it comes to real-time cyber-attack maps, some are funny, some seem ominous, and all of them tell a story that words alone cannot…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Free online courses backed by Cisco’s
expertise and connected to real career paths.
Continue reading on Medium »
Free online courses backed by Cisco’s
expertise and connected to real career paths.
Continue reading on Medium »
Hacking on Medium
Hack Android Phone using Metasploit
https://cdn-images-1.medium.com/max/2600/0*IlF2-6lsSTxMqyaF
This article shows how an Android device can be compromised using Metasploit.
Continue reading on Medium »
Hack Android Phone using Metasploit
https://cdn-images-1.medium.com/max/2600/0*IlF2-6lsSTxMqyaF
This article shows how an Android device can be compromised using Metasploit.
Continue reading on Medium »
Medium
Hack Android Phone using Metasploit
This article shows how an Android device can be compromised using Metasploit.
Hacking on Medium
Unveiling the Extraordinary Journey of a SaaS Business: Achieving $10k MRR in Just One Month!
https://cdn-images-1.medium.com/max/2600/0*NGJ2LoCyIRlAk9wu
Discover the remarkable story of a SaaS business that achieved an astounding $10k MRR in a single month.
Continue reading on Medium »
Unveiling the Extraordinary Journey of a SaaS Business: Achieving $10k MRR in Just One Month!
https://cdn-images-1.medium.com/max/2600/0*NGJ2LoCyIRlAk9wu
Discover the remarkable story of a SaaS business that achieved an astounding $10k MRR in a single month.
Continue reading on Medium »
Medium
Unveiling the Extraordinary Journey of a SaaS Business: Achieving $10k MRR in Just One Month!
Discover the remarkable story of a SaaS business that achieved an astounding $10k MRR in a single month.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Safeguarding User Sessions in Node.js: Expert Strategies for Uncompromised Security
https://cdn-images-1.medium.com/max/628/0*RNlkf6whGJrotpWc.jpg
Discover the essential techniques and best practices for fortifying user sessions in Node.js applications. Enhance your understanding…
Continue reading on Medium »
Safeguarding User Sessions in Node.js: Expert Strategies for Uncompromised Security
https://cdn-images-1.medium.com/max/628/0*RNlkf6whGJrotpWc.jpg
Discover the essential techniques and best practices for fortifying user sessions in Node.js applications. Enhance your understanding…
Continue reading on Medium »
Hacking on Medium
What’s the Difference Between Ethical Hacking and Penetration Testing?
https://cdn-images-1.medium.com/max/2600/0*CaWg7lv9iIzoPmoD
Ethical hacker and penetration tester are both important roles in the cybersecurity domain, but some confusion exists regarding the…
Continue reading on Medium »
What’s the Difference Between Ethical Hacking and Penetration Testing?
https://cdn-images-1.medium.com/max/2600/0*CaWg7lv9iIzoPmoD
Ethical hacker and penetration tester are both important roles in the cybersecurity domain, but some confusion exists regarding the…
Continue reading on Medium »
Medium
What’s the Difference Between Ethical Hacking and Penetration Testing?
Ethical hacker and penetration tester are both important roles in the cybersecurity domain, but some confusion exists regarding the…
Hacking on Medium
Scholarship for Cybersecurity Career!
https://cdn-images-1.medium.com/max/1250/1*kXwXRagDEdXowyKwSqbQuw.jpeg
This scholarship initiative will offer successful awardees a unique, entry-level technical course which will be partially funded by…
Continue reading on Medium »
Scholarship for Cybersecurity Career!
https://cdn-images-1.medium.com/max/1250/1*kXwXRagDEdXowyKwSqbQuw.jpeg
This scholarship initiative will offer successful awardees a unique, entry-level technical course which will be partially funded by…
Continue reading on Medium »
Medium
Scholarship for Cybersecurity Career!
This scholarship initiative will offer successful awardees a unique, entry-level technical course which will be partially funded by…
Hacking on Medium
robots.txt, um cardápio para os hackers!
https://cdn-images-1.medium.com/max/1080/1*tx2jXfKXT6L2tuHihB9IGw.png
Sempre que me perguntam qual é a forma mais segura de proteger um website, sempre me vem a cabeça falar para ter muito cuidado ao usar…
Continue reading on Medium »
robots.txt, um cardápio para os hackers!
https://cdn-images-1.medium.com/max/1080/1*tx2jXfKXT6L2tuHihB9IGw.png
Sempre que me perguntam qual é a forma mais segura de proteger um website, sempre me vem a cabeça falar para ter muito cuidado ao usar…
Continue reading on Medium »
Medium
robots.txt, um cardápio para os hackers!
Sempre que me perguntam qual é a forma mais segura de proteger um website, sempre me vem a cabeça falar para ter muito cuidado ao usar…
Halo Wallet MVP Open Testing Is Officially Launched!
https://medium.com/@HaloDotSocial/halo-wallet-mvp-open-testing-is-officially-launched-97a5d47da378?source=rss------bug_bounty-5
https://medium.com/@HaloDotSocial/halo-wallet-mvp-open-testing-is-officially-launched-97a5d47da378?source=rss------bug_bounty-5
We are thrilled to announce that MVP version of Halo wallet is is ready for open beta testing!Continue reading on Medium » (https://medium.com/@HaloDotSocial/halo-wallet-mvp-open-testing-is-officially-launched-97a5d47da378?source=rss------bug_bounty-5)
Wafaray - Enhance Your Malware Detection With WAF + YARA (WAFARAY)
https://www.kitploit.com/2023/05/wafaray-enhance-your-malware-detection.html
https://www.kitploit.com/2023/05/wafaray-enhance-your-malware-detection.html
WAFARAY is a LAB deployment based on Debian 11.3.0 (stable) x64 made and cooked between two main ingredients WAF + YARA to detect malicious files (e.g. webshells, virus, malware, binaries) typically through web functions (upload files).
Purpose In essence, the main idea came to use WAF + YARA (YARA right-to-left = ARAY) to detect malicious files at the WAF level before WAF can forward them to the backend e.g. files uploaded through web functions see: https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload When a web page allows uploading files, most of the WAFs are not inspecting files before sending them to the backend. Implementing WAF + YARA could provide malware detection before WAF forwards the files to the backend. Do malware detection through WAF? Yes, one solution is to use ModSecurity (https://www.kitploit.com/search/label/ModSecurity) + Clamav, most of the pages call ClamAV as a process and not as a daemon, in this case, analysing a file could take more than 50 seconds per file. See this resource: https://kifarunix.com/intercept-malicious-file-upload-with-modsecurity-and-clamav/ Do malware detection through WAF + YARA? :-( A few clues here Black Hat Asia 2019 (https://portswigger.net/daily-swig/waf-reloaded-modsecurity-3-1-showcased-at-black-hat-asia) please continue reading and see below our quick LAB deployment. WAFARAY: how does it work ? Basically, It is a quick deployment (1) with pre-compiled and ready-to-use YARA rules via ModSecurity (WAF) using a custom rule; (2) this custom rule will perform an inspection and detection of the files that might contain malicious code, (3) typically web functions (upload files) if the file is suspicious will reject them receiving a 403 code Forbidden by ModSecurity.
Purpose In essence, the main idea came to use WAF + YARA (YARA right-to-left = ARAY) to detect malicious files at the WAF level before WAF can forward them to the backend e.g. files uploaded through web functions see: https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload When a web page allows uploading files, most of the WAFs are not inspecting files before sending them to the backend. Implementing WAF + YARA could provide malware detection before WAF forwards the files to the backend. Do malware detection through WAF? Yes, one solution is to use ModSecurity (https://www.kitploit.com/search/label/ModSecurity) + Clamav, most of the pages call ClamAV as a process and not as a daemon, in this case, analysing a file could take more than 50 seconds per file. See this resource: https://kifarunix.com/intercept-malicious-file-upload-with-modsecurity-and-clamav/ Do malware detection through WAF + YARA? :-( A few clues here Black Hat Asia 2019 (https://portswigger.net/daily-swig/waf-reloaded-modsecurity-3-1-showcased-at-black-hat-asia) please continue reading and see below our quick LAB deployment. WAFARAY: how does it work ? Basically, It is a quick deployment (1) with pre-compiled and ready-to-use YARA rules via ModSecurity (WAF) using a custom rule; (2) this custom rule will perform an inspection and detection of the files that might contain malicious code, (3) typically web functions (upload files) if the file is suspicious will reject them receiving a 403 code Forbidden by ModSecurity.
✔️The YaraCompile.py compiles all the yara rules. (Python3 code) ✔️The test.conf is a virtual host that contains the mod security rules. (ModSecurity Code) ✔️ModSecurity rules calls the modsec_yara.py in order to inspect the file that is trying to upload. (Python3 code) ✔️Yara returns two options 1 (200 OK) or 0 (403 Forbidden)Main Paths: Yara Compiled rules: /YaraRules/Compiled Yara Default rules: /YaraRules/rules Yara Scripts: /YaraRules/YaraScripts Apache vhosts: /etc/apache2/sites-enabled Temporal Files: /temporal
Approach Blueteamers: Rule enforcement, best alerting, malware detection on files uploaded through web functions. Redteamers/pentesters: GreyBox scope , upload and bypass with a malicious file, rule enforcement. Security Officers: Keep alerting, threat hunting. SOC: Best monitoring about malicious files. CERT: Malware Analysis, Determine new IOC. Building Detection Lab The Proof of Concept is based on Debian 11.3.0 (stable) x64 OS system, OWASP CRC v3.3.2 and Yara 4.0.5, you will find the automatic installation script here wafaray_install.sh and an optional manual installation guide can be found here: manual_instructions.txt also a PHP page has been created as a "mock" to observe the interaction and detection of malicious files using WAF + YARA. Installation (recommended) with shell scripts ✔️Step 1: Download Debian 11.3.0: https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/debian-11.3.0-amd64-DVD-1.iso ✔️Step 2: Deploy using VMware or VirtualBox ✔️Step 3: Once installed, please follow the instructions below: > log_install.log # Test your LAB environment alex@waf-labs:~$ firefox localhost:8080/upload.php" dir="auto">alex@waf-labs:~$ su root
root@waf-labs:/home/alex#
# Remember to change YOUR_USER by your username (e.g waf)
root@waf-labs:/home/alex# sed -i 's/^\(# User privi.*\)/\1\nalex ALL=(ALL) NOPASSWD:ALL/g' /etc/sudoers
root@waf-labs:/home/alex# exit
alex@waf-labs:~$ sudo sed -i 's/^\(deb cdrom.*\)/#\1/g' /etc/apt/sources.list
alex@waf-labs:~$ sudo sed -i 's/^# \(deb\-src http.*\)/ \1/g' /etc/apt/sources.list
alex@waf-labs:~$ sudo sed -i 's/^# \(deb http.*\)/ \1/g' /etc/apt/sources.list
alex@waf-labs:~$ echo -ne "\n\ndeb http://deb.debian.org/debian/ bullseye main\ndeb-src http://deb.debian.org/debian/ bullseye main\n" | sudo tee -a /etc/apt/sources.list
alex@waf-labs:~$ sudo apt-get update
alex@waf-labs:~$ sudo apt-get install sudo -y
alex@waf-labs:~$ sudo apt-get install git vim dos2unix net-tools -y
alex@waf-labs:~$ git clone https://github.com/alt3kx/wafarayalex@waf-labs:~$ cd wafaray
alex@waf-labs:~$ dos2unix wafaray_install.sh
alex@waf-labs:~$ chmod +x wafaray_install.sh
alex@waf-labs:~$ sudo ./wafaray_install.sh >> log_install.log
# Test your LAB environment
alex@waf-labs:~$ firefox localhost:8080/upload.php
Approach Blueteamers: Rule enforcement, best alerting, malware detection on files uploaded through web functions. Redteamers/pentesters: GreyBox scope , upload and bypass with a malicious file, rule enforcement. Security Officers: Keep alerting, threat hunting. SOC: Best monitoring about malicious files. CERT: Malware Analysis, Determine new IOC. Building Detection Lab The Proof of Concept is based on Debian 11.3.0 (stable) x64 OS system, OWASP CRC v3.3.2 and Yara 4.0.5, you will find the automatic installation script here wafaray_install.sh and an optional manual installation guide can be found here: manual_instructions.txt also a PHP page has been created as a "mock" to observe the interaction and detection of malicious files using WAF + YARA. Installation (recommended) with shell scripts ✔️Step 1: Download Debian 11.3.0: https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/debian-11.3.0-amd64-DVD-1.iso ✔️Step 2: Deploy using VMware or VirtualBox ✔️Step 3: Once installed, please follow the instructions below: > log_install.log # Test your LAB environment alex@waf-labs:~$ firefox localhost:8080/upload.php" dir="auto">alex@waf-labs:~$ su root
root@waf-labs:/home/alex#
# Remember to change YOUR_USER by your username (e.g waf)
root@waf-labs:/home/alex# sed -i 's/^\(# User privi.*\)/\1\nalex ALL=(ALL) NOPASSWD:ALL/g' /etc/sudoers
root@waf-labs:/home/alex# exit
alex@waf-labs:~$ sudo sed -i 's/^\(deb cdrom.*\)/#\1/g' /etc/apt/sources.list
alex@waf-labs:~$ sudo sed -i 's/^# \(deb\-src http.*\)/ \1/g' /etc/apt/sources.list
alex@waf-labs:~$ sudo sed -i 's/^# \(deb http.*\)/ \1/g' /etc/apt/sources.list
alex@waf-labs:~$ echo -ne "\n\ndeb http://deb.debian.org/debian/ bullseye main\ndeb-src http://deb.debian.org/debian/ bullseye main\n" | sudo tee -a /etc/apt/sources.list
alex@waf-labs:~$ sudo apt-get update
alex@waf-labs:~$ sudo apt-get install sudo -y
alex@waf-labs:~$ sudo apt-get install git vim dos2unix net-tools -y
alex@waf-labs:~$ git clone https://github.com/alt3kx/wafarayalex@waf-labs:~$ cd wafaray
alex@waf-labs:~$ dos2unix wafaray_install.sh
alex@waf-labs:~$ chmod +x wafaray_install.sh
alex@waf-labs:~$ sudo ./wafaray_install.sh >> log_install.log
# Test your LAB environment
alex@waf-labs:~$ firefox localhost:8080/upload.php