MY BUG HUNTING METHODOLOGY
https://medium.com/@duncanochieng682/my-bug-hunting-methodology-4ec079dd0985?source=rss------bug_bounty-5
RECONContinue reading on Medium » (https://medium.com/@duncanochieng682/my-bug-hunting-methodology-4ec079dd0985?source=rss------bug_bounty-5)
https://medium.com/@duncanochieng682/my-bug-hunting-methodology-4ec079dd0985?source=rss------bug_bounty-5
RECONContinue reading on Medium » (https://medium.com/@duncanochieng682/my-bug-hunting-methodology-4ec079dd0985?source=rss------bug_bounty-5)
Top Tools Reconnaisance: Unlocking the Secrets of Cybersecurity
https://medium.com/@balengbughunter/top-tools-reconnaisance-unlocking-the-secrets-of-cybersecurity-5837870fed4f?source=rss------bug_bounty-5
https://medium.com/@balengbughunter/top-tools-reconnaisance-unlocking-the-secrets-of-cybersecurity-5837870fed4f?source=rss------bug_bounty-5
Uncovering Information Disclosures: A Step-by-Step Guide for Beginners
https://security-sphinx.medium.com/uncovering-information-disclosures-a-step-by-step-guide-for-beginners-e14bcb8c8e1b?source=rss------bug_bounty-5
https://security-sphinx.medium.com/uncovering-information-disclosures-a-step-by-step-guide-for-beginners-e14bcb8c8e1b?source=rss------bug_bounty-5
Introduction :Continue reading on Medium » (https://security-sphinx.medium.com/uncovering-information-disclosures-a-step-by-step-guide-for-beginners-e14bcb8c8e1b?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Python Variant of NodeStealer – Targeting Facebook Business Accounts and Cryptocurrency
Python Variant of NodeStealer – Targeting Facebook Business Accounts and CryptocurrencyPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Cybersecurity researchers from Palo Alto Network Unit 42 have recently discovered a Python variant of the infamous NodeStealer malware. This sophisticated strain is now fully equipped to not only take over Facebook business accounts but also to siphon cryptocurrency, making it a grave threat to both individuals and organizations. The campaign carrying this stealthy malware began in December 2022, but there is currently no evidence of its active presence.
Initially exposed by Meta in May 2023, NodeStealer was known as a potent stealer capable of harvesting sensitive data such as cookies and passwords from web browsers. It aimed to compromise Facebook, Gmail, and Outlook accounts. While earlier versions of NodeStealer were written in JavaScript, the latest iterations employ Python, showcasing the malware’s evolving capabilities.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
The attack campaign commences with deceptive messages circulating on Facebook, offering free “professional” budget tracking Microsoft Excel and Google Sheets templates. Unsuspecting victims are tricked into downloading a ZIP archive file hosted on Google Drive. Concealed within this ZIP file lies the malicious stealer executable, designed to capture valuable information from Facebook business accounts. In addition, it deploys BitRAT and XWorm malware in the form of ZIP files, disables Microsoft Defender Antivirus, and conducts cryptocurrency theft by exploiting MetaMask credentials from Google Chrome, Cốc Cốc, and Brave web browsers.
To facilitate the downloads of additional malware, the attackers utilize a User Account Control (UAC) bypass technique employing fodhelper.exe. This method allows the execution of PowerShell scripts that retrieve the ZIP files from a remote server, granting attackers elevated privileges over infected hosts.
Notably, Unit 42 has identified an upgraded Python variant of NodeStealer, exhibiting anti-analysis features and advanced capabilities. It now parses emails from Microsoft Outlook and makes attempts to take over the associated Facebook account.
Trending: The Difference between Internal and External Pentesting Trending: Offensive Security Tool: Nucleimonst3r Once the necessary information is collected, the malware exfiltrates the files through the Telegram API before promptly erasing any trace of its activity from the infected machine.
NodeStealer has emerged as a prominent part of a concerning trend among Vietnamese threat actors, who are increasingly targeting Facebook business accounts for advertising fraud and disseminating malware to other users on the social media platform.
https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEg6vQDTCmrQOISC6FPDbHMsd15nSSha7QUCqCh4fmirTIAstO5ph2b8BI2rm3UKmXdocJ7w4bMEPDlfmeGRQxPneAz26MQyk6SbxGyKuWZusjRAGlShs_t2yV8oY2gI9d0OpywZde6OJSU8Dcm7VW091ZiZcOwJDnzkbfaX-VNfdHcmcceAxNc9dEQOXkor/s728-e365/hack.jpg
In light of these emerging threats, Facebook business account owners are urged to implement strong passwords and enable multi-factor authentication. Additionally, organizations should prioritize educating their staff about phishing tactics, particularly modern and targeted approaches that exploit current events and business needs, to defend against such pernicious cyberattacks.
Trending: HotRat Malware -The Sneaky Trojan [...]
Python Variant of NodeStealer – Targeting Facebook Business Accounts and Cryptocurrency
Python Variant of NodeStealer – Targeting Facebook Business Accounts and CryptocurrencyPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Cybersecurity researchers from Palo Alto Network Unit 42 have recently discovered a Python variant of the infamous NodeStealer malware. This sophisticated strain is now fully equipped to not only take over Facebook business accounts but also to siphon cryptocurrency, making it a grave threat to both individuals and organizations. The campaign carrying this stealthy malware began in December 2022, but there is currently no evidence of its active presence.
Initially exposed by Meta in May 2023, NodeStealer was known as a potent stealer capable of harvesting sensitive data such as cookies and passwords from web browsers. It aimed to compromise Facebook, Gmail, and Outlook accounts. While earlier versions of NodeStealer were written in JavaScript, the latest iterations employ Python, showcasing the malware’s evolving capabilities.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
The attack campaign commences with deceptive messages circulating on Facebook, offering free “professional” budget tracking Microsoft Excel and Google Sheets templates. Unsuspecting victims are tricked into downloading a ZIP archive file hosted on Google Drive. Concealed within this ZIP file lies the malicious stealer executable, designed to capture valuable information from Facebook business accounts. In addition, it deploys BitRAT and XWorm malware in the form of ZIP files, disables Microsoft Defender Antivirus, and conducts cryptocurrency theft by exploiting MetaMask credentials from Google Chrome, Cốc Cốc, and Brave web browsers.
To facilitate the downloads of additional malware, the attackers utilize a User Account Control (UAC) bypass technique employing fodhelper.exe. This method allows the execution of PowerShell scripts that retrieve the ZIP files from a remote server, granting attackers elevated privileges over infected hosts.
Notably, Unit 42 has identified an upgraded Python variant of NodeStealer, exhibiting anti-analysis features and advanced capabilities. It now parses emails from Microsoft Outlook and makes attempts to take over the associated Facebook account.
Trending: The Difference between Internal and External Pentesting Trending: Offensive Security Tool: Nucleimonst3r Once the necessary information is collected, the malware exfiltrates the files through the Telegram API before promptly erasing any trace of its activity from the infected machine.
NodeStealer has emerged as a prominent part of a concerning trend among Vietnamese threat actors, who are increasingly targeting Facebook business accounts for advertising fraud and disseminating malware to other users on the social media platform.
https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEg6vQDTCmrQOISC6FPDbHMsd15nSSha7QUCqCh4fmirTIAstO5ph2b8BI2rm3UKmXdocJ7w4bMEPDlfmeGRQxPneAz26MQyk6SbxGyKuWZusjRAGlShs_t2yV8oY2gI9d0OpywZde6OJSU8Dcm7VW091ZiZcOwJDnzkbfaX-VNfdHcmcceAxNc9dEQOXkor/s728-e365/hack.jpg
In light of these emerging threats, Facebook business account owners are urged to implement strong passwords and enable multi-factor authentication. Additionally, organizations should prioritize educating their staff about phishing tactics, particularly modern and targeted approaches that exploit current events and business needs, to defend against such pernicious cyberattacks.
Trending: HotRat Malware -The Sneaky Trojan [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Python Variant of NodeStealer – Targeting Facebook Business Accounts and Cryptocurrency Python Variant of NodeStealer – Targeting Facebook Business Accounts and CryptocurrencyPost Views: 2 Premium Contenthttps://www.blackhatethi…
Lurking in Cracked Software Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: thehackernews.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/08/Images-for-the-News-posts-2-300x150.png P2PInfect Server Botnet Turns Compromised Redis Servers into a Peer-to-Peer NetworkAugust 1, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-300x150.png Abyss Locker: New Linux Encryptor Targets VMware’s ESXi Virtual MachinesJuly 31, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-16-300x150.png 40% of Ubuntu users vulnerable to new privilege elevation flawsJuly 28, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-15-300x150.png SEC Mandates Rapid Cyberattack Disclosures, Companies Must Act Within 4 Business DaysJuly 27, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Python Variant of NodeStealer – Targeting Facebook Business Accounts and Cryptocurrency first appeared on Black Hat Ethical Hacking.
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: thehackernews.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/08/Images-for-the-News-posts-2-300x150.png P2PInfect Server Botnet Turns Compromised Redis Servers into a Peer-to-Peer NetworkAugust 1, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-300x150.png Abyss Locker: New Linux Encryptor Targets VMware’s ESXi Virtual MachinesJuly 31, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-16-300x150.png 40% of Ubuntu users vulnerable to new privilege elevation flawsJuly 28, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-15-300x150.png SEC Mandates Rapid Cyberattack Disclosures, Companies Must Act Within 4 Business DaysJuly 27, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Python Variant of NodeStealer – Targeting Facebook Business Accounts and Cryptocurrency first appeared on Black Hat Ethical Hacking.
KRBUACBypass - UAC Bypass By Abusing Kerberos Tickets
http://www.kitploit.com/2023/08/krbuacbypass-uac-bypass-by-abusing.html
http://www.kitploit.com/2023/08/krbuacbypass-uac-bypass-by-abusing.html
This POC is inspired by James Forshaw (@tiraniddo (https://twitter.com/tiraniddo)) shared at BlackHat (https://www.kitploit.com/search/label/BlackHat) USA 2022 titled “Taking Kerberos (https://www.kitploit.com/search/label/Kerberos) To The Next Level ” topic, he shared a Demo of abusing Kerberos tickets to achieve UAC bypass. By adding a KERB-AD-RESTRICTION-ENTRY to the service ticket, but filling in a fake MachineID, we can easily bypass UAC and gain SYSTEM privileges by accessing the SCM to create a system service. James Forshaw explained the rationale behind this in a blog post called "Bypassing UAC in the most Complex Way Possible!", which got me very interested. Although he didn't provide the full exploit code, I built a POC based on Rubeus (https://github.com/GhostPack/Rubeus#tgtdeleg). As a C# toolset (https://www.kitploit.com/search/label/Toolset) for raw Kerberos interaction and ticket abuse, Rubeus provides an easy interface that allows us to easily initiate Kerberos requests and manipulate Kerberos tickets. You can see related articles about KRBUACBypass in my blog "Revisiting a UAC Bypass By Abusing Kerberos Tickets", including the background principle and how it is implemented. As said in the article, this article was inspired by @tiraniddo's "Taking Kerberos To The Next Level" (I would not have done it without his sharing) and I just implemented it as a tool before I graduated from college.
Tgtdeleg Trick We cannot manually generate a TGT as we do not have and do not have access to the current user's credentials. However, Benjamin Delpy (@gentilkiwi (https://github.com/gentilkiwi)) in his Kekeo (https://github.com/gentilkiwi/kekeo/blob/4fbb44ec54ff093ae0fbe4471de19681a8e71a86/kekeo/modules/kuhl_m_tgt.c#L189) A trick (tgtdeleg) was added that allows you to abuse unconstrained delegation to obtain a local TGT with a session key. Tgtdeleg abuses the Kerberos GSS-API to obtain available TGTs for the current user without obtaining elevated privileges on the host. This method uses the AcquireCredentialsHandle function to obtain the Kerberos security credentials (https://www.kitploit.com/search/label/Credentials) handle for the current user, and calls the InitializeSecurityContext function for HOST/DC.domain.com using the ISC_REQ_DELEGATE flag and the target SPN to prepare the pseudo-delegation context to send to the domain controller. This causes the KRB_AP-REQ in the GSS-API output to include the KRB_CRED in the Authenticator Checksum. The service ticket's session key is then extracted from the local Kerberos cache and used to decrypt the KRB_CRED in the Authenticator to obtain a usable TGT. The Rubeus toolset also incorporates this technique. For details, please refer to “Rubeus – Now With More Kekeo”. With this TGT, we can generate our own service ticket, and the feasible operation process is as follows: Use the Tgtdeleg trick to get the user's TGT. Use the TGT to request the KDC to generate a new service ticket for the local computer. Add a KERB-AD-RESTRICTION-ENTRY, but fill in a fake MachineID. Submit the service ticket into the cache. Krbscm Once you have a service ticket, you can use Kerberos authentication (https://www.kitploit.com/search/label/Authentication) to access Service Control Manager (SCM) Named Pipes or TCP via HOST/HOSTNAME or RPC/HOSTNAME SPN. Note that SCM's Win32 API always uses Negotiate authentication. James Forshaw created a simple POC: SCMUACBypass.cpp (https://gist.github.com/tyranid/c24cfd1bd141d14d4925043ee7e03c82), through the two APIs HOOK AcquireCredentialsHandle and InitializeSecurityContextW, the name of the authentication package called by SCM (pszPack age ) to Kerberos to enable the SCM to use Kerberos when authenticating locally. Let’s see it in action Now let's take a look at the running effect, as shown in the figure below. First request a ticket for the HOST service of the current server through the asktgs function, and then create a system service through
Tgtdeleg Trick We cannot manually generate a TGT as we do not have and do not have access to the current user's credentials. However, Benjamin Delpy (@gentilkiwi (https://github.com/gentilkiwi)) in his Kekeo (https://github.com/gentilkiwi/kekeo/blob/4fbb44ec54ff093ae0fbe4471de19681a8e71a86/kekeo/modules/kuhl_m_tgt.c#L189) A trick (tgtdeleg) was added that allows you to abuse unconstrained delegation to obtain a local TGT with a session key. Tgtdeleg abuses the Kerberos GSS-API to obtain available TGTs for the current user without obtaining elevated privileges on the host. This method uses the AcquireCredentialsHandle function to obtain the Kerberos security credentials (https://www.kitploit.com/search/label/Credentials) handle for the current user, and calls the InitializeSecurityContext function for HOST/DC.domain.com using the ISC_REQ_DELEGATE flag and the target SPN to prepare the pseudo-delegation context to send to the domain controller. This causes the KRB_AP-REQ in the GSS-API output to include the KRB_CRED in the Authenticator Checksum. The service ticket's session key is then extracted from the local Kerberos cache and used to decrypt the KRB_CRED in the Authenticator to obtain a usable TGT. The Rubeus toolset also incorporates this technique. For details, please refer to “Rubeus – Now With More Kekeo”. With this TGT, we can generate our own service ticket, and the feasible operation process is as follows: Use the Tgtdeleg trick to get the user's TGT. Use the TGT to request the KDC to generate a new service ticket for the local computer. Add a KERB-AD-RESTRICTION-ENTRY, but fill in a fake MachineID. Submit the service ticket into the cache. Krbscm Once you have a service ticket, you can use Kerberos authentication (https://www.kitploit.com/search/label/Authentication) to access Service Control Manager (SCM) Named Pipes or TCP via HOST/HOSTNAME or RPC/HOSTNAME SPN. Note that SCM's Win32 API always uses Negotiate authentication. James Forshaw created a simple POC: SCMUACBypass.cpp (https://gist.github.com/tyranid/c24cfd1bd141d14d4925043ee7e03c82), through the two APIs HOOK AcquireCredentialsHandle and InitializeSecurityContextW, the name of the authentication package called by SCM (pszPack age ) to Kerberos to enable the SCM to use Kerberos when authenticating locally. Let’s see it in action Now let's take a look at the running effect, as shown in the figure below. First request a ticket for the HOST service of the current server through the asktgs function, and then create a system service through
krbscm to gain the SYSTEM privilege. KRBUACBypass.exe asktgs
KRBUACBypass.exe krbscm
Download KRBUACBypass (https://github.com/wh0amitz/KRBUACBypass)
KRBUACBypass.exe krbscm
Download KRBUACBypass (https://github.com/wh0amitz/KRBUACBypass)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Kioptrix Level 1.3 (#4) | VulnHub Walkthrough by Mark de Moras
https://cdn-images-1.medium.com/max/1920/1*nuV2T9Ie5horvfeCFxR75g.png
This is a full walkthrough to the Kioptrix Level 1.3 (#4) machine from VulnHub. I made a video in correlation with this writeup which you…
Continue reading on Medium »
Kioptrix Level 1.3 (#4) | VulnHub Walkthrough by Mark de Moras
https://cdn-images-1.medium.com/max/1920/1*nuV2T9Ie5horvfeCFxR75g.png
This is a full walkthrough to the Kioptrix Level 1.3 (#4) machine from VulnHub. I made a video in correlation with this writeup which you…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Curve Finance Hacked
https://cdn-images-1.medium.com/max/1300/1*OWipN5wmBefLrKNATPMQ3Q.jpeg
The recent hacking of Curve Finance liquidity pools could have far and wide reaching consequences for the crypto and DeFi space.
Continue reading on Medium »
Curve Finance Hacked
https://cdn-images-1.medium.com/max/1300/1*OWipN5wmBefLrKNATPMQ3Q.jpeg
The recent hacking of Curve Finance liquidity pools could have far and wide reaching consequences for the crypto and DeFi space.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Exploit de Curve: Impacto DeFi”
https://cdn-images-1.medium.com/max/1200/1*u7hOec2oemUmjCzdjhrFTA.png
El 30 de julio se explotaron varios grupos estables en Curve Finance que usaban Vyper, con pérdidas que superaron los 47 millones de…
Continue reading on Medium »
“Exploit de Curve: Impacto DeFi”
https://cdn-images-1.medium.com/max/1200/1*u7hOec2oemUmjCzdjhrFTA.png
El 30 de julio se explotaron varios grupos estables en Curve Finance que usaban Vyper, con pérdidas que superaron los 47 millones de…
Continue reading on Medium »