Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Zero-day attack: colpiti 60 mila server Microsoft Exchange, in arrivo nuove minacce?
https://cdn-images-1.medium.com/max/1600/1*gzG5Dn3DuG-mLJmpfxyVPw.jpeg
Un team di hacker chiamato Hafnium sta utilizzando da circa il mese di gennaio quattro vulnerabilità precedentemente sconosciute nei…
Continue reading on BV TECH Group »
Zero-day attack: colpiti 60 mila server Microsoft Exchange, in arrivo nuove minacce?
https://cdn-images-1.medium.com/max/1600/1*gzG5Dn3DuG-mLJmpfxyVPw.jpeg
Un team di hacker chiamato Hafnium sta utilizzando da circa il mese di gennaio quattro vulnerabilità precedentemente sconosciute nei…
Continue reading on BV TECH Group »
403 Forbidden Page Bypass — Rare Exploitation of frequently seen Vulnerability
https://medium.com/@uduthalavankumar/403-forbidden-page-bypass-rare-exploitation-of-frequently-seen-vulnerability-ee16c434add7?source=rss------bug_bounty-5
https://medium.com/@uduthalavankumar/403-forbidden-page-bypass-rare-exploitation-of-frequently-seen-vulnerability-ee16c434add7?source=rss------bug_bounty-5
Welcome to my knowledge hub spot and Hope you all are doing Good. During my hunting time, I have seen many URL’s which is showing 403…Continue reading on Medium » (https://medium.com/@uduthalavankumar/403-forbidden-page-bypass-rare-exploitation-of-frequently-seen-vulnerability-ee16c434add7?source=rss------bug_bounty-5)
Strafer - A Tool To Detect Potential Infections In Elasticsearch Instances
Elasticsearch infections are rising exponentially. The adversaries are exploiting open and exposed Elasticsearch interfaces to trigger infections in the cloud and non-cloud deployments. During this talk, we will release a tool named "STRAFER" to detect potential infections in the Elasticsearch instances. The tool allows security researchers, penetration testers, and threat intelligence experts to detect compromised and infected Elasticsearch instances running malicious code. The tool also enables you to conduct efficient research in the field of malware targeting cloud databases. In this version of the tool, the following modules are supported: Elasticsearch instance information gathering and reconnaissance Elasticsearch instance exposure on the Internet Detecting potential ransomware infections in the Elasticsearch instances Detecting potential botnet infections such as meow botnet. Detecting infected indices in the Elasticsearch instances Detecting Elasticsearch honeypots Note: This is the first release of the tool and we expect to add more modules in the nearby future. Researched and Developed By: Aditya K Sood and Rohit Bansal Download Strafer
Read more...
Elasticsearch infections are rising exponentially. The adversaries are exploiting open and exposed Elasticsearch interfaces to trigger infections in the cloud and non-cloud deployments. During this talk, we will release a tool named "STRAFER" to detect potential infections in the Elasticsearch instances. The tool allows security researchers, penetration testers, and threat intelligence experts to detect compromised and infected Elasticsearch instances running malicious code. The tool also enables you to conduct efficient research in the field of malware targeting cloud databases. In this version of the tool, the following modules are supported: Elasticsearch instance information gathering and reconnaissance Elasticsearch instance exposure on the Internet Detecting potential ransomware infections in the Elasticsearch instances Detecting potential botnet infections such as meow botnet. Detecting infected indices in the Elasticsearch instances Detecting Elasticsearch honeypots Note: This is the first release of the tool and we expect to add more modules in the nearby future. Researched and Developed By: Aditya K Sood and Rohit Bansal Download Strafer
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Strafer - A Tool To Detect Potential Infections In Elasticsearch Instances
https://1.bp.blogspot.com/-3uVRHmgMPzw/YEGeAYwHheI/AAAAAAAAVlI/J5tPR986h1MC24GWzCA0yeATaQ_GZmvjQCNcBGAsYHQ/w640-h276/strafer_1_strafer.png
Elasticsearch infections are rising exponentially. The adversaries are exploiting open and exposed Elasticsearch interfaces to trigger infections in the cloud and non-cloud deployments. During this talk, we will release a tool named "STRAFER" to detect potential infections in the Elasticsearch instances. The tool allows security researchers, penetration testers, and threat intelligence experts to detect compromised and infected Elasticsearch instances running malicious code. The tool also enables you to conduct efficient research in the field of malware targeting cloud databases. In this version of the tool, the following modules are supported:
* Elasticsearch instance information gathering and reconnaissance
* Elasticsearch instance exposure on the Internet
* Detecting potential ransomware infections in the Elasticsearch instances
* Detecting potential botnet infections such as meow botnet.
* Detecting infected indices in the Elasticsearch instances
* Detecting Elasticsearch honeypots
Note: This is the first release of the tool and we expect to add more modules in the nearby future.
Researched and Developed By: Aditya K Sood and Rohit Bansal
Download Strafer
Strafer - A Tool To Detect Potential Infections In Elasticsearch Instances
https://1.bp.blogspot.com/-3uVRHmgMPzw/YEGeAYwHheI/AAAAAAAAVlI/J5tPR986h1MC24GWzCA0yeATaQ_GZmvjQCNcBGAsYHQ/w640-h276/strafer_1_strafer.png
Elasticsearch infections are rising exponentially. The adversaries are exploiting open and exposed Elasticsearch interfaces to trigger infections in the cloud and non-cloud deployments. During this talk, we will release a tool named "STRAFER" to detect potential infections in the Elasticsearch instances. The tool allows security researchers, penetration testers, and threat intelligence experts to detect compromised and infected Elasticsearch instances running malicious code. The tool also enables you to conduct efficient research in the field of malware targeting cloud databases. In this version of the tool, the following modules are supported:
* Elasticsearch instance information gathering and reconnaissance
* Elasticsearch instance exposure on the Internet
* Detecting potential ransomware infections in the Elasticsearch instances
* Detecting potential botnet infections such as meow botnet.
* Detecting infected indices in the Elasticsearch instances
* Detecting Elasticsearch honeypots
Note: This is the first release of the tool and we expect to add more modules in the nearby future.
Researched and Developed By: Aditya K Sood and Rohit Bansal
Download Strafer
Black Hat Ethical Hacking
Cisco Plugs Security Hole in Small Business Routers
Cisco Plugs Security Hole in Small Business Routers
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
What's the difference deep web v dark web
Hi, sorry if it has already been asked a zillion times here, but I'm just very curious what's the difference between deep web v dark web? I tried looking for an answer myself, so the best explanation that I read was - all non-indexed content refers to deep web, whereas dark web involves illegal niches specifically (found it here). Correct me if I'm wrong !
submitted by /u/NoDomes
[link] [comments]
What's the difference deep web v dark web
Hi, sorry if it has already been asked a zillion times here, but I'm just very curious what's the difference between deep web v dark web? I tried looking for an answer myself, so the best explanation that I read was - all non-indexed content refers to deep web, whereas dark web involves illegal niches specifically (found it here). Correct me if I'm wrong !
submitted by /u/NoDomes
[link] [comments]
hacking: security in practice
USB traffic emulation?
Heya, I've monitored some traffic through a USB port (Just some basics to create directories) although I would like to know if there is a method I can use to emulate the traffic I've saved.
eg. Plug another USB in and replicate the exact data transfer.
submitted by /u/pilchard2002
[link] [comments]
USB traffic emulation?
Heya, I've monitored some traffic through a USB port (Just some basics to create directories) although I would like to know if there is a method I can use to emulate the traffic I've saved.
eg. Plug another USB in and replicate the exact data transfer.
submitted by /u/pilchard2002
[link] [comments]
reddit
USB traffic emulation?
Heya, I've monitored some traffic through a USB port (Just some basics to create directories) although I would like to know if there is a method I...
Strafer - A Tool To Detect Potential Infections In Elasticsearch Instances
http://www.kitploit.com/2021/03/strafer-tool-to-detect-potential.html
http://www.kitploit.com/2021/03/strafer-tool-to-detect-potential.html
Elasticsearch infections are rising exponentially. The adversaries are exploiting (https://www.kitploit.com/search/label/Exploiting) open and exposed Elasticsearch (https://www.kitploit.com/search/label/Elasticsearch) interfaces to trigger infections in the cloud and non-cloud deployments. During this talk, we will release a tool named "STRAFER" to detect potential infections in the Elasticsearch instances. The tool allows security researchers, penetration testers, and threat intelligence (https://www.kitploit.com/search/label/Threat%20Intelligence) experts to detect compromised and infected Elasticsearch instances running malicious code. The tool also enables you to conduct efficient research in the field of malware targeting cloud databases. In this version of the tool, the following modules are supported: Elasticsearch instance information gathering (https://www.kitploit.com/search/label/Information%20Gathering) and reconnaissance Elasticsearch instance exposure on the Internet Detecting potential ransomware infections in the Elasticsearch instances Detecting potential botnet infections such as meow botnet. Detecting infected indices in the Elasticsearch instances Detecting Elasticsearch honeypots
Note: This is the first release of the tool and we expect to add more modules in the nearby future. Researched and Developed By: Aditya K Sood and Rohit Bansal
Download Strafer (https://github.com/adityaks/strafer)
Note: This is the first release of the tool and we expect to add more modules in the nearby future. Researched and Developed By: Aditya K Sood and Rohit Bansal
Download Strafer (https://github.com/adityaks/strafer)
Improper Validation of Certificate with Host Mismatch [CWE-297] — The Hacktivists
This weakness describes Improper Validation of Certificate with Host Mismatch.Continue reading on Medium »
Read more...
This weakness describes Improper Validation of Certificate with Host Mismatch.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Thick Client Penetration Testing: Traffic Analysis
Traffic analysis is one of the crucial parts of any successful penetration test. In this article we’re going to discuss some of the different techniques that can be used to analyze thick client applications. If a thick client using HTTP traffic then it is pretty straight forward to intercept the traffic. We can use the tools like
<o:p
To Intercept the HTTP like Traffic: -<o:p
· Burp Suite<o:p
<o:p
To Intercept TCP like Traffic: -<o:p
· Wireshark<o:p
· MITM Relay + Burp Suite <o:p
· Echo Mirage (Properly Maintained)<o:p
<o:p
As we’re pen-testing Damn Vulnerable thick client applications and DVTA is using non-HTTP protocols for example., FTP. It doesn’t make any HTTP connections so we can’t use Burp Suite directly. So, we have another option to monitor the traffic by using a tool like Wireshark but it doesn’t allow you to tamper the traffic you can only monitor and understand the traffic. But if our goal is to intercept and modify the traffic, we will have to go with a tool called Echo Mirage.<o:p
So, without wasting much time let’s begin the Traffic Analysis.<o:p
<o:p
Table of content <o:p
· Prerequisites <o:p
· What is Traffic Analysis <o:p
· Traffic Analysis Via Wireshark<o:p
· Traffic Analysis Via Echo Mirage<o:p
· Traffic Analysis Via Burp Suite + MITM Relay<o:p
<o:p
Traffic Analysis <o:p
Any Thick client application communicating with the backend means they are sending some data to its backend components like web server, FTP Server, database server, etc. Analyzing the data during transfer is a very crucial part of the analysis of an application. some applications perform data transit without enforcing any encryption. So, the concept of intercepting traffic of thick clients is not much different than thin clients, the tools will differ depending on the protocols used by the application also these applications are non-proxy aware as well the intercepting techniques also will slightly vary.<o:p
<o:p
Prerequisites <o:p
· Wireshark <o:p
· Python 3<o:p
· Burp Suite<o:p
· Echo Mirage<o:p
· Python pip script<o:p
· MITM Relay <o:p
<o:p
Traffic Analysis via Wireshark<o:p
As a penetration tester, you must have good knowledge how to use a network packet sniffer is essential for day-to-day operations. Whether you are trying to understand a protocol, debug a network client or analyze traffic, you’ll always end up needing a network sniffer.<o:p
Examining the traffic between the tested thick client application and the server might reveal sensitive and unencrypted data such as:<o:p
· Most Sensitive data transferred over an unencrypted tunnel such as clear-text credentials/secrets/API Keys etc.<o:p
· HTTP and HTTPS web endpoints <o:p
· File blobs/chunks sent over the wire<o:p
· Proprietary protocols used by the program<o:p
<o:p
We are going to analyze FTP traffic that’s generated by DVTA. For this we are going to use Loop Back address. So, first of all Launch Wireshark and choose “Adapter for loopback Traffic Capture”.<o:p https://1.bp.blogspot.com/-nsCNLxEMnRU/YFNBxrDZWdI/AAAAAAAAuwM/uHxZJ6Bw3ag503IJpNqli4Lm4TyvQriiwCLcBGAsYHQ/s16000/1.png <o:p
Then after launch modified DVTA application and login to the application by using admin credentials as shown below.<o:p https://1.bp.blogspot.com/-d7gZuDEJbkw/YFNB3mCjDsI/AAAAAAAAuwQ/XOzI8JWvd4IxAb2h_pCbxebSx-BHzwJegCLcBGAsYHQ/s16000/2.png As you can see, we have successfully logged in and it showing Backup data to FTP server <o:p https://1.bp.blogspot.com/-allZ6bSpxZ8/YFNB8DgpkfI/AAAAAAAAuwU/0sFFyx77kPU2SbWgL4xCnpbAKLlPaBR1ACLcBGAsYHQ/s16000/3.png When [...]
Thick Client Penetration Testing: Traffic Analysis
Traffic analysis is one of the crucial parts of any successful penetration test. In this article we’re going to discuss some of the different techniques that can be used to analyze thick client applications. If a thick client using HTTP traffic then it is pretty straight forward to intercept the traffic. We can use the tools like
<o:p
To Intercept the HTTP like Traffic: -<o:p
· Burp Suite<o:p
<o:p
To Intercept TCP like Traffic: -<o:p
· Wireshark<o:p
· MITM Relay + Burp Suite <o:p
· Echo Mirage (Properly Maintained)<o:p
<o:p
As we’re pen-testing Damn Vulnerable thick client applications and DVTA is using non-HTTP protocols for example., FTP. It doesn’t make any HTTP connections so we can’t use Burp Suite directly. So, we have another option to monitor the traffic by using a tool like Wireshark but it doesn’t allow you to tamper the traffic you can only monitor and understand the traffic. But if our goal is to intercept and modify the traffic, we will have to go with a tool called Echo Mirage.<o:p
So, without wasting much time let’s begin the Traffic Analysis.<o:p
<o:p
Table of content <o:p
· Prerequisites <o:p
· What is Traffic Analysis <o:p
· Traffic Analysis Via Wireshark<o:p
· Traffic Analysis Via Echo Mirage<o:p
· Traffic Analysis Via Burp Suite + MITM Relay<o:p
<o:p
Traffic Analysis <o:p
Any Thick client application communicating with the backend means they are sending some data to its backend components like web server, FTP Server, database server, etc. Analyzing the data during transfer is a very crucial part of the analysis of an application. some applications perform data transit without enforcing any encryption. So, the concept of intercepting traffic of thick clients is not much different than thin clients, the tools will differ depending on the protocols used by the application also these applications are non-proxy aware as well the intercepting techniques also will slightly vary.<o:p
<o:p
Prerequisites <o:p
· Wireshark <o:p
· Python 3<o:p
· Burp Suite<o:p
· Echo Mirage<o:p
· Python pip script<o:p
· MITM Relay <o:p
<o:p
Traffic Analysis via Wireshark<o:p
As a penetration tester, you must have good knowledge how to use a network packet sniffer is essential for day-to-day operations. Whether you are trying to understand a protocol, debug a network client or analyze traffic, you’ll always end up needing a network sniffer.<o:p
Examining the traffic between the tested thick client application and the server might reveal sensitive and unencrypted data such as:<o:p
· Most Sensitive data transferred over an unencrypted tunnel such as clear-text credentials/secrets/API Keys etc.<o:p
· HTTP and HTTPS web endpoints <o:p
· File blobs/chunks sent over the wire<o:p
· Proprietary protocols used by the program<o:p
<o:p
We are going to analyze FTP traffic that’s generated by DVTA. For this we are going to use Loop Back address. So, first of all Launch Wireshark and choose “Adapter for loopback Traffic Capture”.<o:p https://1.bp.blogspot.com/-nsCNLxEMnRU/YFNBxrDZWdI/AAAAAAAAuwM/uHxZJ6Bw3ag503IJpNqli4Lm4TyvQriiwCLcBGAsYHQ/s16000/1.png <o:p
Then after launch modified DVTA application and login to the application by using admin credentials as shown below.<o:p https://1.bp.blogspot.com/-d7gZuDEJbkw/YFNB3mCjDsI/AAAAAAAAuwQ/XOzI8JWvd4IxAb2h_pCbxebSx-BHzwJegCLcBGAsYHQ/s16000/2.png As you can see, we have successfully logged in and it showing Backup data to FTP server <o:p https://1.bp.blogspot.com/-allZ6bSpxZ8/YFNB8DgpkfI/AAAAAAAAuwU/0sFFyx77kPU2SbWgL4xCnpbAKLlPaBR1ACLcBGAsYHQ/s16000/3.png When [...]