Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Neko Hacking Incident Review

Recently a new attack on the smart contract lending pools was discovered. Maze protocol team was the first who had suffered from it. We…

Continue reading on Medium »
Neste artigo falaremos sobre uma falha popular classificada como TOP 6 na OWASP TOP 10 API 2019, uma falha que permite que um atacante…Continue reading on Medium » (https://gabrieldkgh.medium.com/mass-assignment-entendendo-o-que-%C3%A9-como-explorar-caso-de-estudo-e-corrigindo-a-falha-3165f9971b60?source=rss------bug_bounty-5)
Nimplant is a cross-platform (Linux & Windows) implant written in Nim as a fun project to learn about Nim and see what it can bring to the table for red team (https://www.kitploit.com/search/label/Red%20Team) tool development. Currently, Nimplant lacks extensive evasive tradecraft; however, overtime Nimplant will become much more sophisticated.
Installation
To install Nimplant, you'll need Mythic (https://www.kitploit.com/search/label/Mythic) installed on a remote computer. You can find installation instructions for Mythic at the Mythic project page (https://github.com/its-a-feature/Mythic/). From the Mythic install root, run the command: ./install_agent_from_github.sh https://github.com/MythicAgents/Nimplant Once installed, restart Mythic to build a new agent.
Highlighted Agent Features
Cross-platform Fully asynchronous Can generate agents compiled from both C and C++ source code
Commands Manual Quick Reference
Command Syntax Description cat cat [file] Retrieve the output of a file. cd cd [dir] Change working directory. cp cp [source] [destination] Copy a file from source to destination. Modal popup. curl curl [url] [method] [headers] [body] Execute a single web request. download download [path] Download a file off the target system. exit exit Exit a callback. getenv getenv Get all of the current environment variables. jobs jobs List all running jobs. kill kill [pid] Attempt to kill the process specified by [pid]. ls ls [path] [recurse] List files and folders in [path] with optional param to list recursively. Defaults to current working directory. mkdir mkdir [dir] Create a directory. mv mv [source] [destination] Move a file from source to destination. Modal popup. ps ps List process information. pwd pwd Print working directory. rm rm [path] Remove a file specified by [path] shell shell [command] Run a shell command which will translate to a process being spawned with command line: cmd.exe /r[command] unsetenv setenv [envname] [value] Sets an environment variable to your choosing. sleep sleep [seconds] Set the callback interval of the agent in seconds. unsetenv unsetenv [envname] Unset an environment variable. upload upload Upload a file to a remote path on the machine. Modal popup.
Supported C2 Profiles
Currently, only one C2 profile is available to use when creating a new Nimplant agent: HTTP.
HTTP Profile
The HTTP profile calls back to the Mythic server over the basic, non-dynamic profile. When selecting options to be stamped into Nimplant at compile time, all options are respected with the exception of those parameters relating to GET requests.
More coming soon!
Roadmap
[] Ability to compile to Objective-C for macOS capabilities [] Integration of Donut (https://github.com/theWover/Donut) to allow user to generate shellcode as output [] Communication via WebSockets [] Screenshotting capabilities [] Remote (https://www.kitploit.com/search/label/Remote) process injection (https://www.kitploit.com/search/label/Injection) capabilities

Download Nimplant (https://github.com/MythicAgents/Nimplant)
Nimplant - A Cross-Platform Implant Written In Nim

Nimplant is a cross-platform (Linux & Windows) implant written in Nim as a fun project to learn about Nim and see what it can bring to the table for red team tool development. Currently, Nimplant lacks extensive evasive tradecraft; however, overtime Nimplant will become much more sophisticated.Installation To install Nimplant, you'll need Mythic installed on a remote computer. You can find installation instructions for Mythic at the Mythic project page. From the Mythic install root, run the command: ./install_agent_from_github.sh https://github.com/MythicAgents/Nimplant Once installed, restart Mythic to build a new agent. Highlighted Agent Features Cross-platform Fully asynchronous Can generate agents compiled from both C and C++ source code Commands Manual Quick Reference Command Syntax Description cat cat file Retrieve the output of a file. cd cd dir Change working directory. cp cp source destination Copy a file from source to destination. Modal popup. curl curl url method headers body Execute a single web request. download download path Download a file off the target system. exit exit Exit a callback. getenv getenv Get all of the current environment variables. jobs jobs List all running jobs. kill kill pid Attempt to kill the process specified by pid. ls ls path recurse List files and folders in path with optional param to list recursively. Defaults to current working directory. mkdir mkdir dir Create a directory. mv mv source destination Move a file from source to destination. Modal popup. ps ps List process information. pwd pwd Print working directory. rm rm path Remove a file specified by path shell shell command Run a shell command which will translate to a process being spawned with command line: cmd.exe /rcommand unsetenv setenv envname value Sets an environment variable to your choosing. sleep sleep seconds Set the callback interval of the agent in seconds. unsetenv unsetenv envname Unset an environment variable. upload upload Upload a file to a remote path on the machine. Modal popup. Supported C2 Profiles Currently, only one C2 profile is available to use when creating a new Nimplant agent: HTTP. HTTP Profile The HTTP profile calls back to the Mythic server over the basic, non-dynamic profile. When selecting options to be stamped into Nimplant at compile time, all options are respected with the exception of those parameters relating to GET requests. More coming soon! Roadmap Ability to compile to Objective-C for macOS capabilities Integration of Donut to allow user to generate shellcode as output Communication via WebSockets Screenshotting capabilities Remote process injection capabilities Download Nimplant
Read more...