Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 5 Most Destructive Computer Viruses of All Time
Most of us, at one time or another, have had to deal with a computer virus. Usually it means running your antivirus program and sometimes…
Continue reading on VIEH Group »
Top 5 Most Destructive Computer Viruses of All Time
Most of us, at one time or another, have had to deal with a computer virus. Usually it means running your antivirus program and sometimes…
Continue reading on VIEH Group »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to prevent Facebook cloning
Imagine having an evil twin somewhere out in the wild causing chaos in your name. On Facebook, that fear can become reality. Facebook…
Continue reading on VIEH Group »
How to prevent Facebook cloning
Imagine having an evil twin somewhere out in the wild causing chaos in your name. On Facebook, that fear can become reality. Facebook…
Continue reading on VIEH Group »
Unprivileged User with Read/Write permission to \`User Access\` can escalate their role to ADMIN —…
Hello, I wanted to share with you the “Privilege Escalation” vulnerability that I found in a private program on HackerOne.Continue reading on Medium »
Read more...
Hello, I wanted to share with you the “Privilege Escalation” vulnerability that I found in a private program on HackerOne.Continue reading on Medium »
Read more...
Best companies to work for as a penetration tester
https://www.reddit.com/r/Pentesting/comments/o3nk68/best_companies_to_work_for_as_a_penetration_tester/
Hello, I currently work as a pentester in the government contractor space and looking to explore other opportunities. Anyone have any companies they would recommend ( I am U.S based) to work as a pentester?. submitted by /u/mountainhacker1 (https://www.reddit.com/user/mountainhacker1)
[link] (https://www.reddit.com/r/Pentesting/comments/o3nk68/best_companies_to_work_for_as_a_penetration_tester/) [comments] (https://www.reddit.com/r/Pentesting/comments/o3nk68/best_companies_to_work_for_as_a_penetration_tester/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/o3nk68/best_companies_to_work_for_as_a_penetration_tester/
Hello, I currently work as a pentester in the government contractor space and looking to explore other opportunities. Anyone have any companies they would recommend ( I am U.S based) to work as a pentester?. submitted by /u/mountainhacker1 (https://www.reddit.com/user/mountainhacker1)
[link] (https://www.reddit.com/r/Pentesting/comments/o3nk68/best_companies_to_work_for_as_a_penetration_tester/) [comments] (https://www.reddit.com/r/Pentesting/comments/o3nk68/best_companies_to_work_for_as_a_penetration_tester/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Best companies to work for as a penetration tester
Hello, I currently work as a pentester in the government contractor space and looking to explore other opportunities. Anyone have any companies...
Unprivileged User with Read/Write permission to `User Access` can escalate their role to ADMIN —…
https://ertugrull.medium.com/unprivileged-user-with-read-write-permission-to-user-access-can-escalate-their-role-to-admin-a217d2d280a8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://ertugrull.medium.com/unprivileged-user-with-read-write-permission-to-user-access-can-escalate-their-role-to-admin-a217d2d280a8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unprivileged User with Read/Write permission to `User Access` can escalate their role to ADMIN — Privilege Escalation
Hello, I wanted to share with you the “Privilege Escalation” vulnerability that I found in a private program on HackerOne.
Hello, I wanted to share with you the “Privilege Escalation” vulnerability that I found in a private program on HackerOne.Continue reading on Medium » (https://ertugrull.medium.com/unprivileged-user-with-read-write-permission-to-user-access-can-escalate-their-role-to-admin-a217d2d280a8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unprivileged User with Read/Write permission to `User Access` can escalate their role to ADMIN — Privilege Escalation
Hello, I wanted to share with you the “Privilege Escalation” vulnerability that I found in a private program on HackerOne.
Deep Web
Is the channel Project Nightfall and the info they post legit?
If you’ve seen his videos on yt or fb you’ll know who I’m talking about.
submitted by /u/EdwinGo7
[link] [comments]
Is the channel Project Nightfall and the info they post legit?
If you’ve seen his videos on yt or fb you’ll know who I’m talking about.
submitted by /u/EdwinGo7
[link] [comments]
reddit
Is the channel Project Nightfall and the info they post legit?
If you’ve seen his videos on yt or fb you’ll know who I’m talking about.
hacking: security in practice
Cultivating the hacker mindset
As I continue to learn more about hacker culture and methodology, and build my own skills to be a better hacker, what fascinates me is the hacker's ability to problem solve and come up with creative ways to bypass systems and technologies.
I can read books and practice web exploitation and other such security topics, but how do I develop the ability to see problems in a new light? Even though I've been practicing for a few months, I often get stuck on problems and sometimes use solutions/walkthroughs for guidance, and more often than not I think to myself, "Oh, why didn't I think of that--it seemed so obvious!" Or worse: I should've known that, but for whatever reason didn't make the connection. I feel like this is fundamental to being a successful hacker; I don't want to be a script kiddie, but actually be able to understand and manipulate the internals of whatever I'm tinkering with.
What do your methodologies look like when tackling new problems? How do you practice making connections so that you're able to tackle new problems in inventive and efficient ways?
submitted by /u/majestic-gold
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Cultivating the hacker mindset
As I continue to learn more about hacker culture and methodology, and build my own skills to be a better hacker, what fascinates me is the hacker's ability to problem solve and come up with creative ways to bypass systems and technologies.
I can read books and practice web exploitation and other such security topics, but how do I develop the ability to see problems in a new light? Even though I've been practicing for a few months, I often get stuck on problems and sometimes use solutions/walkthroughs for guidance, and more often than not I think to myself, "Oh, why didn't I think of that--it seemed so obvious!" Or worse: I should've known that, but for whatever reason didn't make the connection. I feel like this is fundamental to being a successful hacker; I don't want to be a script kiddie, but actually be able to understand and manipulate the internals of whatever I'm tinkering with.
What do your methodologies look like when tackling new problems? How do you practice making connections so that you're able to tackle new problems in inventive and efficient ways?
submitted by /u/majestic-gold
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cultivating the hacker mindset
As I continue to learn more about hacker culture and methodology, and build my own skills to be a better hacker, what fascinates me is the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Made this video on Reflected XSS attack in brief •XSS attack•
Reflected XSS attack is type of XSS attack Using this attack the attacker can steal the user's session cookies and take over their account.
If you want me to make a detailed video on it lemme know.
https://youtu.be/45T_G_iGBYM
submitted by /u/dominatevil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Made this video on Reflected XSS attack in brief •XSS attack•
Reflected XSS attack is type of XSS attack Using this attack the attacker can steal the user's session cookies and take over their account.
If you want me to make a detailed video on it lemme know.
https://youtu.be/45T_G_iGBYM
submitted by /u/dominatevil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Made this video on Reflected XSS attack in brief •XSS attack•
Reflected XSS attack is type of XSS attack Using this attack the attacker can steal the user's session cookies and take over their account. If...
FalconEye - Real-time detection software for Windows process injections
http://www.kitploit.com/2021/06/falconeye-real-time-detection-software.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/06/falconeye-real-time-detection-software.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
FalconEye - Real-time detection software for Windows process injections
FalconEye is a windows endpoint detection software for real-time process injections. It is a kernel-mode driver that aims to catch process injections as they are happening (real-time). Since FalconEye runs in kernel mode, it provides a stronger and reliable defense against process injection techniques that try to evade various user-mode hooks. You can check our presentation at 2021 Blackhat ASIA Arsenal (https://www.blackhat.com/asia-21/arsenal/schedule/#falconeye-windows-process-injection-techniques---catch-them-all-22612) and slides (https://github.com/rajiv2790/FalconEye/blob/main/2021BHASIA_FalconEye.pdf).
Project Overview
Detection Coverage
The table below shows the implementation status and the detection logic for the various process injection techniques. WPM stands for WriteProcessMemory. To test the detection, one can refer to the references section. Technique Status Detection POC Used Atombombing ✓ Hook QueueUserAPC and look for GlobalGetAtom family of functions Pinjectra Instrumentation callback injection ✓ Detect if a new thread is created from floating code https://github.com/antonioCoco/Mapping-Injection Reflective DLL Injection ✓ Detect if a new thread is created from floating code and if PE header is being written into victim MInjector PROPagate ✓ Hook SetProp to get the address of the property being written and corelate with the previous WPM calls to get the address of floating code Pinjectra Process Hollowing ✓ Detected using PE header written into target process memory MInjector CreateRemoteThread with LoadLibrary ✓ New thread with start address pointing to LoadLibrary. MInjector version also writes DLL path using WPM which is also detected MInjector, Pinjectra CreateRemoteThread with MapViewOfFile ✓ Detect if a new thread is created from floating code Pinjectra Suspend-Inject-Resume ✓ Detect if a new thread is created from floating code(MInjector). DLL Path being written via WPM (MInjector). Detect if context set on a previously suspended thread (Pinjectra) MInjector, Pinjectra QueueUserAPC ✓ DLL path being written via WPM MInjector QueueUserAPC with memset (Stackbombing) ✓ Hook QueueUserAPC and look for memset Pinjectra SetWindowLong (Extra window memory injection) ✓ Hook SetWindowLong to get the address of the function pointer being written and corelate with the previous WPM calls to get the address of floating code Pinjectra Unmap + Overwrite ✓ Alert if attacker process is unmapping ntdll from the victim Pinjectra Kernel Ctrl Table ✓ Detect if WPM is overwriting KernelCallbackTable field in the PEB of the victim https://github.com/odzhan/injection/blob/master/kct USERDATA ✓ Check if WPM target address is in conhost.exe range. If so check if any relevant function pointers from conhost match previously stored WPM address https://github.com/odzhan/injection/blob/master/conhost Ctrl-inject ✓ Detect if the attacker does WPM in victim's KernelBase.dll range Pinjectra ALPC Callback ✓ Extract victim pid in NtConnectPort calls to ALPC port. For attacker-victim pid tuple check prior WPM calls and apply Floating code detection Pinjectra WNF Callback ✓ WPM followed by UpdateWNFStateData call https://github.com/odzhan/injection/tree/master/wnf SetWindowsHook ✓ Save module paths registered in NtUserSetWindowsHookEx hook. Later when a module matching this path loads in a different process, generate alert MInjector GhostWriting ✓ Detect if context is set (NtSetContextThread is called) on a previously suspended thread Pinjectra Service Control ✓ WPM overwriting Service IDE of a process (service) https://github.com/odzhan/injection/tree/master/svcctrl Shellcode injection ✓ New thread started from floating code. DLL path being written by WPM MInjector Image Mapping ✓ Thread started from floating code. PE header being written by WPM.
___________________________
@hacking_Attack
@Hacking_Video
Project Overview
Detection Coverage
The table below shows the implementation status and the detection logic for the various process injection techniques. WPM stands for WriteProcessMemory. To test the detection, one can refer to the references section. Technique Status Detection POC Used Atombombing ✓ Hook QueueUserAPC and look for GlobalGetAtom family of functions Pinjectra Instrumentation callback injection ✓ Detect if a new thread is created from floating code https://github.com/antonioCoco/Mapping-Injection Reflective DLL Injection ✓ Detect if a new thread is created from floating code and if PE header is being written into victim MInjector PROPagate ✓ Hook SetProp to get the address of the property being written and corelate with the previous WPM calls to get the address of floating code Pinjectra Process Hollowing ✓ Detected using PE header written into target process memory MInjector CreateRemoteThread with LoadLibrary ✓ New thread with start address pointing to LoadLibrary. MInjector version also writes DLL path using WPM which is also detected MInjector, Pinjectra CreateRemoteThread with MapViewOfFile ✓ Detect if a new thread is created from floating code Pinjectra Suspend-Inject-Resume ✓ Detect if a new thread is created from floating code(MInjector). DLL Path being written via WPM (MInjector). Detect if context set on a previously suspended thread (Pinjectra) MInjector, Pinjectra QueueUserAPC ✓ DLL path being written via WPM MInjector QueueUserAPC with memset (Stackbombing) ✓ Hook QueueUserAPC and look for memset Pinjectra SetWindowLong (Extra window memory injection) ✓ Hook SetWindowLong to get the address of the function pointer being written and corelate with the previous WPM calls to get the address of floating code Pinjectra Unmap + Overwrite ✓ Alert if attacker process is unmapping ntdll from the victim Pinjectra Kernel Ctrl Table ✓ Detect if WPM is overwriting KernelCallbackTable field in the PEB of the victim https://github.com/odzhan/injection/blob/master/kct USERDATA ✓ Check if WPM target address is in conhost.exe range. If so check if any relevant function pointers from conhost match previously stored WPM address https://github.com/odzhan/injection/blob/master/conhost Ctrl-inject ✓ Detect if the attacker does WPM in victim's KernelBase.dll range Pinjectra ALPC Callback ✓ Extract victim pid in NtConnectPort calls to ALPC port. For attacker-victim pid tuple check prior WPM calls and apply Floating code detection Pinjectra WNF Callback ✓ WPM followed by UpdateWNFStateData call https://github.com/odzhan/injection/tree/master/wnf SetWindowsHook ✓ Save module paths registered in NtUserSetWindowsHookEx hook. Later when a module matching this path loads in a different process, generate alert MInjector GhostWriting ✓ Detect if context is set (NtSetContextThread is called) on a previously suspended thread Pinjectra Service Control ✓ WPM overwriting Service IDE of a process (service) https://github.com/odzhan/injection/tree/master/svcctrl Shellcode injection ✓ New thread started from floating code. DLL path being written by WPM MInjector Image Mapping ✓ Thread started from floating code. PE header being written by WPM.
___________________________
@hacking_Attack
@Hacking_Video
Blackhat
Black Hat Asia 2021
DLL path being written by WPM MInjector Thread Reuse ✓ Thread started from floating code. DLL path being written by WPM MInjector
Architecture Overview
___________________________
@hacking_Attack
@Hacking_Video
Architecture Overview
___________________________
@hacking_Attack
@Hacking_Video
The driver is an on-demand load driver The initialization includes setting up callbacks and syscall hooks via libinfinityhook The callbacks maintain a map of Pids built from cross process activity such as OpenProcess but it is not limited to OpenProcess Subsequent callbacks and syscall hooks use this Pid map to reduce the noise in processing. As a part of noise reduction, syscall hooks filter out same process activity. The detection logic is divided into subcategories namely - stateless (example: Atombombing), stateful (Unmap+Overwrite) and Floating code(Shellcode from multiple techniques) For stateful detections, syscall hooks record an ActionHistory which is implemented as a circular buffer. e.g. It records all the NtWriteVirtualMemory calls where the caller process is different from the target process. The detection logic has common anomaly detection functionality such as floating code detection and detection for shellcode triggers in remote processes. Both callbacks and syscall hooks invoke this common functionality for actual detection. NOTE: Our focus has been detection and not creating a performant detection engine. We’ll continue on these efforts past the BlackHat presentation.
Files
.
├── src
│ ├── FalconEye ---------------------------# FalconEye user and kernel space
│ └── libinfinityhook ---------------------# Kernel hook implementation
├── 2021BHASIA_FalconEye.pdf
└── README.md
Getting Started
Prerequisites
Windows 10 Build 1903/1909 Microsoft Visual Studio 2019 onwards Virtualization Software such as VmWare, Hyper-V (Optional)
Installation
Build
Open the solution with Visual Studio 2019 Select x64 as build platform Build solution. This should generate FalconEye.sys binary under src\kernel\FalconEye\x64\Debug or src\kernel\FalconEye\x64\Release
Test Machine Setup
Install Windows 10 (https://www.kitploit.com/search/label/Windows%2010) Build 1903/1909 in a VM Configure VM for testing unsigned driver Using bcdedit, disable integrity checks : BCDEDIT /set nointegritychecks ON Run DbgView from sysinternals (https://www.kitploit.com/search/label/Sysinternals) in the VM or start a debugging (https://www.kitploit.com/search/label/Debugging) connection using WinDbg.
Usage
Copy FalconEye.sys to the Test Machine (Windows 10 VM) Load FalconEye.sys as 'On Demand' load driver using OSR Loader or similar tools Run injection test tools such as pinjectra, minjector or other samples Monitor debug logs either via WinDbg or DbgView
References
InfinityHook, 2019 (https://github.com/everdox/InfinityHook/) Itzik Kotler and Amit Klein. Process Injection Techniques - Gotta Catch Them All, Blackhat USA Briengs, 2019 (https://www.blackhat.com/us-19/briefings/schedule/#process-injection-techniques---gotta-catch-them-all-16010) Pinjectra, 2019 (https://github.com/SafeBreach-Labs/pinjectra/) Mapping-Injection, 2020 (https://github.com/antonioCoco/Mapping-Injection) Atombombing: Brand new code injection for windows, 2016 (https://blog.ensilo.com/atombombing-brand-new-code-injection-for-windows) Propagate - a new code injection trick, 2017 (http://www.hexacorn.com/blog/2017/10/26/propagate-a-new-code-injection-trick/) Windows process injection: Extra window bytes, 2018 (https://modexp.wordpress.com/2018/08/26/process-injection-ctray/) Pavel Asinovsky. Diving into zberp's unconventional process injection technique, 2016 (https://securityintelligence.com/diving-into-zberps-unconventional-process-injection-technique/) Rotem Kerner. Ctrl-inject, 2018 (https://blog.ensilo.com/ctrl-inject) Windows process injection: Consolewindowclass, 2018 (https://modexp.wordpress.com/2018/09/12/process-injection-user-data/) Windows process injection: Windows notication facility, 2018 (https://modexp.wordpress.com/2019/06/15/4083/) A paradox: Writing to another process without openning it nor actually writing to it, 2007
___________________________
@hacking_Attack
@Hacking_Video
Files
.
├── src
│ ├── FalconEye ---------------------------# FalconEye user and kernel space
│ └── libinfinityhook ---------------------# Kernel hook implementation
├── 2021BHASIA_FalconEye.pdf
└── README.md
Getting Started
Prerequisites
Windows 10 Build 1903/1909 Microsoft Visual Studio 2019 onwards Virtualization Software such as VmWare, Hyper-V (Optional)
Installation
Build
Open the solution with Visual Studio 2019 Select x64 as build platform Build solution. This should generate FalconEye.sys binary under src\kernel\FalconEye\x64\Debug or src\kernel\FalconEye\x64\Release
Test Machine Setup
Install Windows 10 (https://www.kitploit.com/search/label/Windows%2010) Build 1903/1909 in a VM Configure VM for testing unsigned driver Using bcdedit, disable integrity checks : BCDEDIT /set nointegritychecks ON Run DbgView from sysinternals (https://www.kitploit.com/search/label/Sysinternals) in the VM or start a debugging (https://www.kitploit.com/search/label/Debugging) connection using WinDbg.
Usage
Copy FalconEye.sys to the Test Machine (Windows 10 VM) Load FalconEye.sys as 'On Demand' load driver using OSR Loader or similar tools Run injection test tools such as pinjectra, minjector or other samples Monitor debug logs either via WinDbg or DbgView
References
InfinityHook, 2019 (https://github.com/everdox/InfinityHook/) Itzik Kotler and Amit Klein. Process Injection Techniques - Gotta Catch Them All, Blackhat USA Briengs, 2019 (https://www.blackhat.com/us-19/briefings/schedule/#process-injection-techniques---gotta-catch-them-all-16010) Pinjectra, 2019 (https://github.com/SafeBreach-Labs/pinjectra/) Mapping-Injection, 2020 (https://github.com/antonioCoco/Mapping-Injection) Atombombing: Brand new code injection for windows, 2016 (https://blog.ensilo.com/atombombing-brand-new-code-injection-for-windows) Propagate - a new code injection trick, 2017 (http://www.hexacorn.com/blog/2017/10/26/propagate-a-new-code-injection-trick/) Windows process injection: Extra window bytes, 2018 (https://modexp.wordpress.com/2018/08/26/process-injection-ctray/) Pavel Asinovsky. Diving into zberp's unconventional process injection technique, 2016 (https://securityintelligence.com/diving-into-zberps-unconventional-process-injection-technique/) Rotem Kerner. Ctrl-inject, 2018 (https://blog.ensilo.com/ctrl-inject) Windows process injection: Consolewindowclass, 2018 (https://modexp.wordpress.com/2018/09/12/process-injection-user-data/) Windows process injection: Windows notication facility, 2018 (https://modexp.wordpress.com/2019/06/15/4083/) A paradox: Writing to another process without openning it nor actually writing to it, 2007
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
(http://blog.txipinet.com/2007/04/05/69-a-paradox-writing-to-another-process-without-openning-it-nor-actually-writing-to-it/) Windows process injection: Service control handler, 2018 (https://modexp.wordpress.com/2018/08/30/windows-process-injection-control-handler/) Marcos Oviedo. Memhunter - (https://github.com/marcosd4h/memhunter)Automated (https://www.kitploit.com/search/label/Automated) hunting of memory resident malware at scale. Defcon Demo Labs, 2019
Download FalconEye (https://github.com/rajiv2790/FalconEye)
___________________________
@hacking_Attack
@Hacking_Video
Download FalconEye (https://github.com/rajiv2790/FalconEye)
___________________________
@hacking_Attack
@Hacking_Video
txipi:blog
A paradox: Writing to another process without openning it nor actually writing to it
This post is written in English because it’s the explanation (and release of functional code) of a new technique for win32 based systems called GhostWriting. It’s author, c0de90e7, is a…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
You Might Like This Simple Hack for Calendar Blocking
https://cdn-images-1.medium.com/max/1281/1*aW-JRoFO_1fiyGCJJkyIJQ.png
As a productivity hack, this trick works for me.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
You Might Like This Simple Hack for Calendar Blocking
https://cdn-images-1.medium.com/max/1281/1*aW-JRoFO_1fiyGCJJkyIJQ.png
As a productivity hack, this trick works for me.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
You Might Like This Simple Hack for Calendar Blocking
As a productivity hack, this trick works for me.