How to cite us
WAF-A-MoLE implements the methodology presented in "WAF-A-MoLE: Evading Web Application (https://www.researchgate.net/publication/340917525_WAF-A-MoLE_Evading_Web_Application_Firewalls_through_Adversarial_Machine_Learning)Firewalls (https://www.kitploit.com/search/label/Firewalls) through Adversarial (https://www.kitploit.com/search/label/Adversarial) Machine Learning". If you want to cite us, please use the following (BibTeX) reference: @inproceedings{demetrio20wafamole,
title={WAF-A-MoLE: evading web application firewalls through adversarial machine learning},
author={Demetrio, Luca and Valenza, Andrea and Costa, Gabriele and Lagorio, Giovanni},
booktitle={Proceedings of the 35th Annual ACM Symposium on Applied Computing},
pages={1745--1752},
year={2020}
}
Running WAF-A-MoLE
Prerequisites
numpy (https://numpy.org/) keras (https://keras.io/) scikit-learn (https://scikit-learn.org/stable/) joblib (https://github.com/joblib/joblib) sqlparse (https://github.com/andialbrecht/sqlparse) networkx (https://networkx.github.io/) Click (https://click.palletsprojects.com/en/7.x/)
Setup
pip install -r requirements.txt
Sample Usage
You can evaluate the robustness of your own WAF, or try WAF-A-MoLE against some example classifiers. In the first case, have a look at the Model (https://github.com/AvalZ/waf-a-mole/blob/master/wafamole/models/model.py) class. Your custom model needs to implement this class in order to be evaluated by WAF-A-MoLE. We already provide wrappers for sci-kit learn and keras classifiers that can be extend to fit your feature extraction phase (if any).
Help
wafamole --help Usage: wafamole [OPTIONS] COMMAND [ARGS]...
Options:
--help Show this message and exit.
Commands:
evade Launch WAF-A-MoLE against a target classifier.
wafamole evade --help Usage: wafamole evade [OPTIONS] MODEL_PATH PAYLOAD
Launch WAF-A-MoLE against a target classifier.
Options:
-T, --model-type TEXT Type of classifier to load
-t, --timeout INTEGER Timeout when evading the model
-r, --max-rounds INTEGER Maximum number of fuzzing rounds
-s, --round-size INTEGER Fuzzing step size for each round (parallel fuzzing
steps)
--threshold FLOAT Classification threshold of the target WAF [0.5]
--random-engine TEXT Use random transformations instead of evolution
engine. Set the number of trials
--output-path TEXT Location were to save the results of the random
engine. NOT USED WITH REGULAR EVOLUTION ENGINE
--help Show this message and exit.
Evading example models
We provide some pre-trained models you can have fun with, located in wafamole/models/custom/example_models (https://github.com/AvalZ/waf-a-mole/tree/master/wafamole/models/custom/example_models). The classifiers we used are listed in the table below. Classifier name Algorithm WafBrain (https://github.com/BBVA/waf-brain) Recurrent Neural Network Token-based Naive Bayes Token-based Random Forest Token-based Linear SVM Token-based Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Directed Proportional Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Directed Unproportional Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Undirected Proportional Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Undirected Unproportional Gaussian SVM
WAF-BRAIN - Recurrent Neural Newtork
Bypass the pre-trained WAF-Brain classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type waf-brain wafamole/models/custom/example_models/waf-brain.h5 "admin' OR 1=1#"
Token-based - Naive Bayes
WAF-A-MoLE implements the methodology presented in "WAF-A-MoLE: Evading Web Application (https://www.researchgate.net/publication/340917525_WAF-A-MoLE_Evading_Web_Application_Firewalls_through_Adversarial_Machine_Learning)Firewalls (https://www.kitploit.com/search/label/Firewalls) through Adversarial (https://www.kitploit.com/search/label/Adversarial) Machine Learning". If you want to cite us, please use the following (BibTeX) reference: @inproceedings{demetrio20wafamole,
title={WAF-A-MoLE: evading web application firewalls through adversarial machine learning},
author={Demetrio, Luca and Valenza, Andrea and Costa, Gabriele and Lagorio, Giovanni},
booktitle={Proceedings of the 35th Annual ACM Symposium on Applied Computing},
pages={1745--1752},
year={2020}
}
Running WAF-A-MoLE
Prerequisites
numpy (https://numpy.org/) keras (https://keras.io/) scikit-learn (https://scikit-learn.org/stable/) joblib (https://github.com/joblib/joblib) sqlparse (https://github.com/andialbrecht/sqlparse) networkx (https://networkx.github.io/) Click (https://click.palletsprojects.com/en/7.x/)
Setup
pip install -r requirements.txt
Sample Usage
You can evaluate the robustness of your own WAF, or try WAF-A-MoLE against some example classifiers. In the first case, have a look at the Model (https://github.com/AvalZ/waf-a-mole/blob/master/wafamole/models/model.py) class. Your custom model needs to implement this class in order to be evaluated by WAF-A-MoLE. We already provide wrappers for sci-kit learn and keras classifiers that can be extend to fit your feature extraction phase (if any).
Help
wafamole --help Usage: wafamole [OPTIONS] COMMAND [ARGS]...
Options:
--help Show this message and exit.
Commands:
evade Launch WAF-A-MoLE against a target classifier.
wafamole evade --help Usage: wafamole evade [OPTIONS] MODEL_PATH PAYLOAD
Launch WAF-A-MoLE against a target classifier.
Options:
-T, --model-type TEXT Type of classifier to load
-t, --timeout INTEGER Timeout when evading the model
-r, --max-rounds INTEGER Maximum number of fuzzing rounds
-s, --round-size INTEGER Fuzzing step size for each round (parallel fuzzing
steps)
--threshold FLOAT Classification threshold of the target WAF [0.5]
--random-engine TEXT Use random transformations instead of evolution
engine. Set the number of trials
--output-path TEXT Location were to save the results of the random
engine. NOT USED WITH REGULAR EVOLUTION ENGINE
--help Show this message and exit.
Evading example models
We provide some pre-trained models you can have fun with, located in wafamole/models/custom/example_models (https://github.com/AvalZ/waf-a-mole/tree/master/wafamole/models/custom/example_models). The classifiers we used are listed in the table below. Classifier name Algorithm WafBrain (https://github.com/BBVA/waf-brain) Recurrent Neural Network Token-based Naive Bayes Token-based Random Forest Token-based Linear SVM Token-based Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Directed Proportional Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Directed Unproportional Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Undirected Proportional Gaussian SVM SQLiGoT (https://www.sciencedirect.com/science/article/pii/S0167404816300451) - Undirected Unproportional Gaussian SVM
WAF-BRAIN - Recurrent Neural Newtork
Bypass the pre-trained WAF-Brain classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type waf-brain wafamole/models/custom/example_models/waf-brain.h5 "admin' OR 1=1#"
Token-based - Naive Bayes
Bypass the pre-trained token-based Naive Bayes classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type token wafamole/models/custom/example_models/naive_bayes_trained.dump "admin' OR 1=1#"
Token-based - Random Forest
Bypass the pre-trained token-based Random Forest classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type token wafamole/models/custom/example_models/random_forest_trained.dump "admin' OR 1=1#"
Token-based - Linear SVM
Bypass the pre-trained token-based Linear SVM classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type token wafamole/models/custom/example_models/lin_svm_trained.dump "admin' OR 1=1#"
Token-based - Gaussian SVM
Bypass the pre-trained token-based Gaussian SVM classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type token wafamole/models/custom/example_models/gauss_svm_trained.dump "admin' OR 1=1#"
SQLiGoT
Bypass the pre-trained SQLiGOT classifier using a admin' OR 1=1# equivalent. Use DP, UP, DU, or UU for (respectivly) Directed Proportional, Undirected Proportional, Directed Unproportional and Undirected Unproportional. wafamole evade --model-type DP wafamole/models/custom/example_models/graph_directed_proportional_sqligot "admin' OR 1=1#" BEFORE LAUNCHING EVALUATION ON SQLiGoT These classifiers are more robust than the others, as the feature extraction phase produces vectors with a more complex structure, and all pre-trained classifiers have been strongly regularized. It may take hours for some variants to produce a payload that achieves evasion (https://www.kitploit.com/search/label/Evasion) (see Benchmark section).
Custom adapters
First, create a custom Model class that implements the extract_features and classify methods. class YourCustomModel(Model):
def extract_features(self, value: str):
# TODO: extract features
feature_vector = your_custom_feature_function(value)
return feature_vector
def classify(self, value):
# TODO: compute confidence
confidence = your_confidence_eval(value)
return confidence Then, create an object from the model and instantiate an engine object that uses your model class. model = YourCustomModel() #your init
engine = EvasionEngine(model)
result = engine.evaluate(payload, max_rounds, round_size, timeout, threshold)
Benchmark
We evaluated WAF-A-MoLE against all our example models. The plot below shows the time it took for WAF-A-MoLE to mutate the admin' OR 1=1# payload until it was accepted by each classifier as benign. On the x axis we have time (in seconds, logarithmic scale). On the y axis we have the confidence value, i.e., how sure a classifier is that a given payload is a SQL injection (in percentage). Notice that being "50% sure" that a payload is a SQL injection is equivalent to flipping a coin. This is the usual classification threshold: if the confidence is lower, the payload is classified as benign.
Token-based - Random Forest
Bypass the pre-trained token-based Random Forest classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type token wafamole/models/custom/example_models/random_forest_trained.dump "admin' OR 1=1#"
Token-based - Linear SVM
Bypass the pre-trained token-based Linear SVM classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type token wafamole/models/custom/example_models/lin_svm_trained.dump "admin' OR 1=1#"
Token-based - Gaussian SVM
Bypass the pre-trained token-based Gaussian SVM classifier using a admin' OR 1=1# equivalent. wafamole evade --model-type token wafamole/models/custom/example_models/gauss_svm_trained.dump "admin' OR 1=1#"
SQLiGoT
Bypass the pre-trained SQLiGOT classifier using a admin' OR 1=1# equivalent. Use DP, UP, DU, or UU for (respectivly) Directed Proportional, Undirected Proportional, Directed Unproportional and Undirected Unproportional. wafamole evade --model-type DP wafamole/models/custom/example_models/graph_directed_proportional_sqligot "admin' OR 1=1#" BEFORE LAUNCHING EVALUATION ON SQLiGoT These classifiers are more robust than the others, as the feature extraction phase produces vectors with a more complex structure, and all pre-trained classifiers have been strongly regularized. It may take hours for some variants to produce a payload that achieves evasion (https://www.kitploit.com/search/label/Evasion) (see Benchmark section).
Custom adapters
First, create a custom Model class that implements the extract_features and classify methods. class YourCustomModel(Model):
def extract_features(self, value: str):
# TODO: extract features
feature_vector = your_custom_feature_function(value)
return feature_vector
def classify(self, value):
# TODO: compute confidence
confidence = your_confidence_eval(value)
return confidence Then, create an object from the model and instantiate an engine object that uses your model class. model = YourCustomModel() #your init
engine = EvasionEngine(model)
result = engine.evaluate(payload, max_rounds, round_size, timeout, threshold)
Benchmark
We evaluated WAF-A-MoLE against all our example models. The plot below shows the time it took for WAF-A-MoLE to mutate the admin' OR 1=1# payload until it was accepted by each classifier as benign. On the x axis we have time (in seconds, logarithmic scale). On the y axis we have the confidence value, i.e., how sure a classifier is that a given payload is a SQL injection (in percentage). Notice that being "50% sure" that a payload is a SQL injection is equivalent to flipping a coin. This is the usual classification threshold: if the confidence is lower, the payload is classified as benign.
Experiments were performed on DigitalOcean Standard Droplets.
Contribute
Questions, bug reports and pull requests are welcome. In particular, if you are interested in expanding this project, we look for the following contributions: New WAF adapters New mutation operators New search algorithms
Team
Luca Demetrio (http://csec.it/people/luca_demetrio/) - CSecLab (https://csec.it/), DIBRIS, University of Genova Andrea Valenza (https://avalz.it/) - CSecLab (https://csec.it/), DIBRIS, University of Genova Gabriele Costa (https://www.imtlucca.it/it/gabriele.costa) - SysMA (http://sysma.imtlucca.it/), IMT Lucca Giovanni Lagorio (https://csec.it/people/giovanni_lagorio/) - CSecLab (https://csec.it/), DIBRIS, University of Genova
Download WAF-A-MoLE (https://github.com/AvalZ/WAF-A-MoLE)
Contribute
Questions, bug reports and pull requests are welcome. In particular, if you are interested in expanding this project, we look for the following contributions: New WAF adapters New mutation operators New search algorithms
Team
Luca Demetrio (http://csec.it/people/luca_demetrio/) - CSecLab (https://csec.it/), DIBRIS, University of Genova Andrea Valenza (https://avalz.it/) - CSecLab (https://csec.it/), DIBRIS, University of Genova Gabriele Costa (https://www.imtlucca.it/it/gabriele.costa) - SysMA (http://sysma.imtlucca.it/), IMT Lucca Giovanni Lagorio (https://csec.it/people/giovanni_lagorio/) - CSecLab (https://csec.it/), DIBRIS, University of Genova
Download WAF-A-MoLE (https://github.com/AvalZ/WAF-A-MoLE)
How I was able to Takeover Accounts on Foxit.com
https://gonzx.medium.com/how-i-was-able-to-takeover-any-account-on-foxit-com-7a08efa0144f?source=rss------bug_bounty-5
https://gonzx.medium.com/how-i-was-able-to-takeover-any-account-on-foxit-com-7a08efa0144f?source=rss------bug_bounty-5
Hello to all Security Researchers and Bug Hunters who is reading this blog, Im Jefferson Gonzales also new in bug hunting, so without…Continue reading on Medium » (https://gonzx.medium.com/how-i-was-able-to-takeover-any-account-on-foxit-com-7a08efa0144f?source=rss------bug_bounty-5)
hacking: security in practice
Hashcat on Virtual Machine
Hashcat doesn't work in virtual machines because it's not an actual computer right?
submitted by /u/ACCube
[link] [comments]
Hashcat on Virtual Machine
Hashcat doesn't work in virtual machines because it's not an actual computer right?
submitted by /u/ACCube
[link] [comments]
reddit
Hashcat on Virtual Machine
Hashcat doesn't work in virtual machines because it's not an actual computer right?
hacking: security in practice
Bluetooth deauth attack?
I'm wondering if there's a tool for Bluetooth like mdk4 that send deuth packets to cut the connection between two devices
submitted by /u/_xd22
[link] [comments]
Bluetooth deauth attack?
I'm wondering if there's a tool for Bluetooth like mdk4 that send deuth packets to cut the connection between two devices
submitted by /u/_xd22
[link] [comments]
reddit
Bluetooth deauth attack?
I'm wondering if there's a tool for Bluetooth like mdk4 that send deuth packets to cut the connection between two devices
AD CS relay attack guide
https://www.reddit.com/r/Pentesting/comments/oa7ffi/ad_cs_relay_attack_guide/
https://www.reddit.com/r/Pentesting/comments/oa7ffi/ad_cs_relay_attack_guide/
submitted by /u/mediocre_haxor (https://www.reddit.com/user/mediocre_haxor)
[link] (https://www.exandroid.dev/2021/06/23/ad-cs-relay-attack-practical-guide/) [comments] (https://www.reddit.com/r/Pentesting/comments/oa7ffi/ad_cs_relay_attack_guide/)
[link] (https://www.exandroid.dev/2021/06/23/ad-cs-relay-attack-practical-guide/) [comments] (https://www.reddit.com/r/Pentesting/comments/oa7ffi/ad_cs_relay_attack_guide/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Squalr : Squalr Memory Editor – Game Hacking Tool Written In C#
Squalr is performant Memory Editing software that allows users to create and share cheats in their windows desktop games. This includes memory scanning, pointers, x86/x64 assembly injection, and so on. Squalr achieves fast scans through multi-threading combined with SIMD instructions. See this article: SIMD in .NET. To take advantage of these gains, your CPU needs to have […]
The post Squalr : Squalr Memory Editor – Game Hacking Tool Written In C# appeared first on Kali Linux Tutorials.
Squalr : Squalr Memory Editor – Game Hacking Tool Written In C#
Squalr is performant Memory Editing software that allows users to create and share cheats in their windows desktop games. This includes memory scanning, pointers, x86/x64 assembly injection, and so on. Squalr achieves fast scans through multi-threading combined with SIMD instructions. See this article: SIMD in .NET. To take advantage of these gains, your CPU needs to have […]
The post Squalr : Squalr Memory Editor – Game Hacking Tool Written In C# appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
LocCheck : A Tool For Simplifying The Process Of Researching IOCs
LocCheck is a tool for simplifying the process of researching file hashes, IP addresses, and other indicators of compromise (IOCs). Features Look up hashes across multiple threat intelligence services, from a single command or a few lines of Python. Currenty supports the following services: VirusTotal MalwareBazaar Shodan.io Planned support: URLhaus OTX InQuest Labs MalShare Malpedia […]
The post LocCheck : A Tool For Simplifying The Process Of Researching IOCs appeared first on Kali Linux Tutorials.
LocCheck : A Tool For Simplifying The Process Of Researching IOCs
LocCheck is a tool for simplifying the process of researching file hashes, IP addresses, and other indicators of compromise (IOCs). Features Look up hashes across multiple threat intelligence services, from a single command or a few lines of Python. Currenty supports the following services: VirusTotal MalwareBazaar Shodan.io Planned support: URLhaus OTX InQuest Labs MalShare Malpedia […]
The post LocCheck : A Tool For Simplifying The Process Of Researching IOCs appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Clear And Uncommon Story About Overcoming Issues With AWS.
https://cdn-images-1.medium.com/max/902/1*uowv55RdCB7xexMnJARBEQ.png
See how the Uran Company overcame the hacking of the AWS account through SES using a compromised API Key with maximum privileges.
Continue reading on Medium »
Clear And Uncommon Story About Overcoming Issues With AWS.
https://cdn-images-1.medium.com/max/902/1*uowv55RdCB7xexMnJARBEQ.png
See how the Uran Company overcame the hacking of the AWS account through SES using a compromised API Key with maximum privileges.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bashed HTB Writeup
https://cdn-images-1.medium.com/max/1920/1*DJN9OvrLDrrEgQ80mVWx4Q.png
Hi everyone, this is my writeup for box “Bashed” found on HackTheBox .
Continue reading on Medium »
Bashed HTB Writeup
https://cdn-images-1.medium.com/max/1920/1*DJN9OvrLDrrEgQ80mVWx4Q.png
Hi everyone, this is my writeup for box “Bashed” found on HackTheBox .
Continue reading on Medium »