Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Perils of Using Free VPN Service
https://cdn-images-1.medium.com/max/1280/1*dz8UwihNLEN2Tjda3I3iCw.jpeg
In the era of unprecedented cyber advancements and the new needs arising every other day, people have resorted to the use of VPN (Virtual…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Perils of Using Free VPN Service
https://cdn-images-1.medium.com/max/1280/1*dz8UwihNLEN2Tjda3I3iCw.jpeg
In the era of unprecedented cyber advancements and the new needs arising every other day, people have resorted to the use of VPN (Virtual…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Perils of Using Free VPN Service
In the era of unprecedented cyber advancements and the new needs arising every other day, people have resorted to the use of VPN (Virtual…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BOOK — HackTheBox WriteUp
https://cdn-images-1.medium.com/max/840/1*DTdisikBgGH_3l8LmFVCNQ.png
This box is a part of TJnull’s list of boxes. I am doing these boxes as a part of my preparation for OSCP. I will be sharing the writeups…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
BOOK — HackTheBox WriteUp
https://cdn-images-1.medium.com/max/840/1*DTdisikBgGH_3l8LmFVCNQ.png
This box is a part of TJnull’s list of boxes. I am doing these boxes as a part of my preparation for OSCP. I will be sharing the writeups…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
BOOK — HackTheBox WriteUp
This box is a part of TJnull’s list of boxes. I am doing these boxes as a part of my preparation for OSCP. I will be sharing the writeups…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Malware Backdoor.Win32.Zdemon.10 Vulnerable To Remote Command Execution (RCE)
More @ https://skynettools.com
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Malware Backdoor.Win32.Zdemon.10 Vulnerable To Remote Command Execution (RCE)
More @ https://skynettools.com
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Malware Backdoor.Win32.Zdemon.10 Vulnerable To Remote Command Execution (RCE)
More @ https://skynettools.com
Hats.finance is live with $100k active bounty!
https://hatsfinance.medium.com/hats-finance-is-live-with-100k-active-bounty-41988b1984b7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hatsfinance.medium.com/hats-finance-is-live-with-100k-active-bounty-41988b1984b7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hats.finance is live with $100k active bounty!
We are excited to create the first Hats bug bounty vault on mainnet to incentivize responsible disclosure for Hats protocol.
We are excited to create the first Hats bug bounty vault on mainnet to incentivize responsible disclosure for Hats protocol.Continue reading on Medium » (https://hatsfinance.medium.com/hats-finance-is-live-with-100k-active-bounty-41988b1984b7?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hats.finance is live with $100k active bounty!
We are excited to create the first Hats bug bounty vault on mainnet to incentivize responsible disclosure for Hats protocol.
The Graph Joins Immunefi with the World’s Largest ug bounty in history: $2.5 Million
https://medium.com/immunefi/the-graph-joins-immunefi-with-the-worlds-largest-ug-bounty-in-history-2-5-million-d63a466f7485?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/the-graph-joins-immunefi-with-the-worlds-largest-ug-bounty-in-history-2-5-million-d63a466f7485?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Graph Joins Immunefi with the World’s Largest Bug Bounty in History: $2.5 Million
The Graph Foundation is offering a record-breaking $2.5 million bug bounty to incentivize developers and whitehat hackers to dig up…
The Graph Foundation is offering a record-breaking $2.5 million bug bounty to incentivize developers and whitehat hackers to dig up…Continue reading on Immunefi » (https://medium.com/immunefi/the-graph-joins-immunefi-with-the-worlds-largest-ug-bounty-in-history-2-5-million-d63a466f7485?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Graph Joins Immunefi with the World’s Largest Bug Bounty in History: $2.5 Million
The Graph Foundation is offering a record-breaking $2.5 million bug bounty to incentivize developers and whitehat hackers to dig up…
Deep Web
New to the deep web, I’ve seen some archives. What do I do next?
How do you find sites that aren’t as well known or “explore” the deep web?
submitted by /u/Alien1772
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
New to the deep web, I’ve seen some archives. What do I do next?
How do you find sites that aren’t as well known or “explore” the deep web?
submitted by /u/Alien1772
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
New to the deep web, I’ve seen some archives. What do I do next?
How do you find sites that aren’t as well known or “explore” the deep web?
Karton - Distributed Malware Processing Framework Based On Python, Redis And MinIO
http://www.kitploit.com/2021/08/karton-distributed-malware-processing.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/08/karton-distributed-malware-processing.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Karton - Distributed Malware Processing Framework Based On Python, Redis And MinIO
Distributed malware processing framework based on Python, Redis and MinIO.
The idea
Karton is a robust framework for creating flexible and lightweight malware analysis (https://www.kitploit.com/search/label/Malware%20Analysis) backends. It can be used to connect malware* analysis systems into a robust pipeline with very little effort. We've been in the automation (https://www.kitploit.com/search/label/Automation) business for a long time. We're dealing with more and more threats, and we have to automate everything to keep up with incidents. Because of this, we often end up with many scripts stuck together with duck duct tape and WD-40. These scripts are written by analysts in the heat of the moment, fragile and ugly - but they work, and produce intel that must be stored, processed further, sent to other systems or shared with other organisations. We needed a way to take our PoC scripts and easily insert them into our analysis pipeline. We also wanted to monitor their execution, centralise logging, improve robustness, reduce development inertia... For this exact purpose, we created Karton. * while Karton was designed with malware analysis in mind, it works nicely in every microservice-oriented project.
Installation
Installation is as easy as a single pip install command: pip3 install karton-core
In order to setup the whole backend environment you will also need MinIO and Redis, see the docs (https://karton-core.readthedocs.io/en/latest/getting_started.html#installation) for details.
Example usage
To use karton you have to provide class that inherits from Karton. None: # Get sample object packed_sample = task.get_resource('sample') # Log with self.log self.log.info(f"Hi {packed_sample.name}, let me analyze you!") ... # Send our results for further processing or reporting task = Task( { "type": "sample", "kind": "raw" }, payload = { "parent": packed_sample, "sample": Resource(filename, unpacked) }) self.send_task(task) if __name__ == "__main__": # Here comes the main loop GenericUnpacker().loop() ">from karton.core import Karton, Task, Resource
class GenericUnpacker(Karton):
"""
Performs sample unpacking
"""
identity = "karton.generic-unpacker"
filters = [
{
"type": "sample",
"kind": "runnable",
"platform": "win32"
}
]
def process(self, task: Task) -> None:
# Get sample object
packed_sample = task.get_resource('sample')
# Log with self.log
self.log.info(f"Hi {packed_sample.name}, let me analyze you!")
...
# Send our results for further processing or reporting
task = Task(
{
"type": "sample",
"kind": "raw"
}, payload = {
"parent": packed_sample,
"sample": Resource(filename, unpacked)
})
self.send_task(task)< br/>
if __name__ == "__main__":
# Here comes the main loop
GenericUnpacker().loop()
Karton systems
Some Karton systems are universal and useful to everyone. We decided to share them with the community.
karton (https://github.com/CERT-Polska/karton)
This repository. It contains the karton.system service - main service, responsible for dispatching tasks within the system. It also contains the karton.core module, that is used as a library by other systems.
karton-dashboard (https://github.com/CERT-Polska/karton-dashboard)
A small Flask dashboard (https://www.kitploit.com/search/label/Dashboard) for task and queue management (https://www.kitploit.com/search/label/Management) and monitoring.
karton-classifier (https://github.com/CERT-Polska/karton-classifier)
___________________________
@hacking_Attack
@Hacking_Video
The idea
Karton is a robust framework for creating flexible and lightweight malware analysis (https://www.kitploit.com/search/label/Malware%20Analysis) backends. It can be used to connect malware* analysis systems into a robust pipeline with very little effort. We've been in the automation (https://www.kitploit.com/search/label/Automation) business for a long time. We're dealing with more and more threats, and we have to automate everything to keep up with incidents. Because of this, we often end up with many scripts stuck together with duck duct tape and WD-40. These scripts are written by analysts in the heat of the moment, fragile and ugly - but they work, and produce intel that must be stored, processed further, sent to other systems or shared with other organisations. We needed a way to take our PoC scripts and easily insert them into our analysis pipeline. We also wanted to monitor their execution, centralise logging, improve robustness, reduce development inertia... For this exact purpose, we created Karton. * while Karton was designed with malware analysis in mind, it works nicely in every microservice-oriented project.
Installation
Installation is as easy as a single pip install command: pip3 install karton-core
In order to setup the whole backend environment you will also need MinIO and Redis, see the docs (https://karton-core.readthedocs.io/en/latest/getting_started.html#installation) for details.
Example usage
To use karton you have to provide class that inherits from Karton. None: # Get sample object packed_sample = task.get_resource('sample') # Log with self.log self.log.info(f"Hi {packed_sample.name}, let me analyze you!") ... # Send our results for further processing or reporting task = Task( { "type": "sample", "kind": "raw" }, payload = { "parent": packed_sample, "sample": Resource(filename, unpacked) }) self.send_task(task) if __name__ == "__main__": # Here comes the main loop GenericUnpacker().loop() ">from karton.core import Karton, Task, Resource
class GenericUnpacker(Karton):
"""
Performs sample unpacking
"""
identity = "karton.generic-unpacker"
filters = [
{
"type": "sample",
"kind": "runnable",
"platform": "win32"
}
]
def process(self, task: Task) -> None:
# Get sample object
packed_sample = task.get_resource('sample')
# Log with self.log
self.log.info(f"Hi {packed_sample.name}, let me analyze you!")
...
# Send our results for further processing or reporting
task = Task(
{
"type": "sample",
"kind": "raw"
}, payload = {
"parent": packed_sample,
"sample": Resource(filename, unpacked)
})
self.send_task(task)< br/>
if __name__ == "__main__":
# Here comes the main loop
GenericUnpacker().loop()
Karton systems
Some Karton systems are universal and useful to everyone. We decided to share them with the community.
karton (https://github.com/CERT-Polska/karton)
This repository. It contains the karton.system service - main service, responsible for dispatching tasks within the system. It also contains the karton.core module, that is used as a library by other systems.
karton-dashboard (https://github.com/CERT-Polska/karton-dashboard)
A small Flask dashboard (https://www.kitploit.com/search/label/Dashboard) for task and queue management (https://www.kitploit.com/search/label/Management) and monitoring.
karton-classifier (https://github.com/CERT-Polska/karton-classifier)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
The "router". It recognises samples/files and produces various task types depending on the file format. Thanks to this, other systems may only listen for tasks with a specific format (for example, only zip archives).
karton-archive-extractor (https://github.com/CERT-Polska/karton-archive-extractor)
Generic archive unpacker. Archives uploaded into the system will be extracted, and every file will be processed individually.
karton-config-extractor (https://github.com/CERT-Polska/karton-config-extractor)
Malware extractor. It uses Yara rules and Python modules to extract static configuration from malware samples (https://www.kitploit.com/search/label/Malware%20Samples) and analyses. It's a fishing rod, not a fish - we don't share the modules themselves. But it's easy to write your own!
karton-mwdb-reporter (https://github.com/CERT-Polska/karton-mwdb-reporter)
A very important part of the pipeline. Reporter submits all files, tags, comments and other intel produced during the analysis to MWDB (https://github.com/CERT-Polska/mwdb-core). If you don't use MWDB yet or just prefer other backends, it's easy to write your own reporter.
karton-yaramatcher (https://github.com/CERT-Polska/karton-yaramatcher)
Automatically runs Yara rules on all files in the pipeline, and tags samples appropriately. Rules not included ;).
karton-asciimagic (https://github.com/CERT-Polska/karton-asciimagic)
Karton system that decodes files encoded with common methods, like hex, base64, etc. (You wouldn't believe how common it is).
karton-autoit-ripper (https://github.com/CERT-Polska/karton-autoit-ripper)
A small wrapper around AutoIt-Ripper (https://github.com/nazywam/AutoIt-Ripper) that extracts embedded AutoIt scripts and resources from compiled AutoIt executables.
DRAKVUF Sandbox (https://github.com/CERT-Polska/drakvuf-sandbox)
Automated black-box malware analysis system with DRAKVUF engine under the hood, which does not require an agent on guest OS. Coming soon:
karton-misp-pusher
A reporter, that submits observed events to MISP. This is how these systems can be used to form a basic malware analysis pipeline:
___________________________
@hacking_Attack
@Hacking_Video
karton-archive-extractor (https://github.com/CERT-Polska/karton-archive-extractor)
Generic archive unpacker. Archives uploaded into the system will be extracted, and every file will be processed individually.
karton-config-extractor (https://github.com/CERT-Polska/karton-config-extractor)
Malware extractor. It uses Yara rules and Python modules to extract static configuration from malware samples (https://www.kitploit.com/search/label/Malware%20Samples) and analyses. It's a fishing rod, not a fish - we don't share the modules themselves. But it's easy to write your own!
karton-mwdb-reporter (https://github.com/CERT-Polska/karton-mwdb-reporter)
A very important part of the pipeline. Reporter submits all files, tags, comments and other intel produced during the analysis to MWDB (https://github.com/CERT-Polska/mwdb-core). If you don't use MWDB yet or just prefer other backends, it's easy to write your own reporter.
karton-yaramatcher (https://github.com/CERT-Polska/karton-yaramatcher)
Automatically runs Yara rules on all files in the pipeline, and tags samples appropriately. Rules not included ;).
karton-asciimagic (https://github.com/CERT-Polska/karton-asciimagic)
Karton system that decodes files encoded with common methods, like hex, base64, etc. (You wouldn't believe how common it is).
karton-autoit-ripper (https://github.com/CERT-Polska/karton-autoit-ripper)
A small wrapper around AutoIt-Ripper (https://github.com/nazywam/AutoIt-Ripper) that extracts embedded AutoIt scripts and resources from compiled AutoIt executables.
DRAKVUF Sandbox (https://github.com/CERT-Polska/drakvuf-sandbox)
Automated black-box malware analysis system with DRAKVUF engine under the hood, which does not require an agent on guest OS. Coming soon:
karton-misp-pusher
A reporter, that submits observed events to MISP. This is how these systems can be used to form a basic malware analysis pipeline:
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - CERT-Polska/karton-archive-extractor: Extractor of various archive formats for Karton framework
Extractor of various archive formats for Karton framework - CERT-Polska/karton-archive-extractor
Download Karton (https://github.com/CERT-Polska/karton)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - CERT-Polska/karton: Distributed malware processing framework based on Python, Redis and S3.
Distributed malware processing framework based on Python, Redis and S3. - CERT-Polska/karton