Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
New 0-Day Attack Targeting Windows Users With Microsoft Office Documents
https://external-preview.redd.it/dz1aBBToRC280g8LmIpDJpAKR-z169dMQQX8nUJKIic.jpg?width=640&crop=smart&auto=webp&s=a878e0d8242195e0367aaf15f3787b60cf0dcf28 submitted by /u/CodePerfect
[link] [comments]
New 0-Day Attack Targeting Windows Users With Microsoft Office Documents
https://external-preview.redd.it/dz1aBBToRC280g8LmIpDJpAKR-z169dMQQX8nUJKIic.jpg?width=640&crop=smart&auto=webp&s=a878e0d8242195e0367aaf15f3787b60cf0dcf28 submitted by /u/CodePerfect
[link] [comments]
hacking: security in practice
Arpspoofing not working
Apologies for bad formatting I am typing this from mobile
I am pretty new to this stuff so sorry if I am not using proper terminology I am using 2 virtual boxes, both use nat network, 1 is kali and another is windows. While using arpspoofing I am able to spoof the windows such that after spoofing the mac address of the network in windows is changing to that of kali machine but even after port forwarding windows is unable to use internet
The commands I am using on kali (on 3 seperate root terminals)
$ arpspoofing -i eth0 -t 10.0.2.1 10.0.2.4
$ arpspoofing -i eth0 -t 10.0.2.4 10.0.2.1
$ echo 1 > /proc/sys/net/ipv4/ip_forward
So any help would be appreciated
Edit: Some formatting
submitted by /u/Varad_88
[link] [comments]
Arpspoofing not working
Apologies for bad formatting I am typing this from mobile
I am pretty new to this stuff so sorry if I am not using proper terminology I am using 2 virtual boxes, both use nat network, 1 is kali and another is windows. While using arpspoofing I am able to spoof the windows such that after spoofing the mac address of the network in windows is changing to that of kali machine but even after port forwarding windows is unable to use internet
The commands I am using on kali (on 3 seperate root terminals)
$ arpspoofing -i eth0 -t 10.0.2.1 10.0.2.4
$ arpspoofing -i eth0 -t 10.0.2.4 10.0.2.1
$ echo 1 > /proc/sys/net/ipv4/ip_forward
So any help would be appreciated
Edit: Some formatting
submitted by /u/Varad_88
[link] [comments]
reddit
Arpspoofing not working
Apologies for bad formatting I am typing this from mobile I am pretty new to this stuff so sorry if I am not using proper terminology I am using...
Tryhackme Gatekeeper Walkthrough
Hi guys my name is Ahmed and my nickname is SadC0d3rContinue reading on Medium »
Read more...
Hi guys my name is Ahmed and my nickname is SadC0d3rContinue reading on Medium »
Read more...
Tryhackme Gatekeeper Walkthrough
https://sadc0d3r.medium.com/tryhackme-gatekeeper-writeup-31e6747ce01a?source=rss------bug_bounty-5
https://sadc0d3r.medium.com/tryhackme-gatekeeper-writeup-31e6747ce01a?source=rss------bug_bounty-5
Hi guys my name is Ahmed and my nickname is SadC0d3rContinue reading on Medium » (https://sadc0d3r.medium.com/tryhackme-gatekeeper-writeup-31e6747ce01a?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft shares temp fix for ongoing Office 365 zero-day attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft shares temp fix for ongoing Office 365 zero-day attacksPost Views: 83
Reading Time: 1 Minute
Microsoft shared yesterday a mitigation for a remote code execution vulnerability in Windows that is being exploited in targeted attacks against Office 365 and Office 2019 on Windows 10.
The flaw is in MSHTML, the browser rendering engine that is also used by Microsoft Office documents. Ongoing attacks against Office 365Identified as CVE-2021-40444, the security issue affects Windows Server 2008 through 2019 and Windows 8.1 through 10 and has a severity level of 8.8 out of the maximum 10.
Microsoft is aware of targeted attacks that try to exploit the vulnerability by sending specially-crafted Microsoft Office documents to potential victims, the company says in an advisory today.
“An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document” – Microsoft
However, the attack is thwarted if Microsoft Office runs with the default configuration, where documents from the web are opened in Protected View mode or Application Guard for Office 365.
Protected View is a read-only mode that has most of the editing functions disabled, while Application Guard isolates untrusted documents, denying them access to corporate resources, the intranet, or other files on the system.
Systems with active Microsoft’s Defender Antivirus and Defender for Endpoint (build 1.349.22.0 and above) benefit from protection against attempts to exploit CVE-2021-40444.
Microsoft’s enterprise security platform will display alerts about this attack as “Suspicious Cpl File Execution.”
See Also: Complete Offensive Security and Ethical Hacking Course Researchers from multiple cybersecurity companies are credited for finding and reporting the vulnerability: Haifei Li of EXPMON, Dhanesh Kizhakkinan, Bryce Abdo, and Genwei Jiang – all three of Mandiant, and Rick Cole of Microsoft Security Intelligence.
In a tweet today, EXPMON (exploit monitor) says that they found the vulnerability after detecting a “highly sophisticated zero-day attack” aimed at Microsoft Office users.
https://www.bleepstatic.com/images/news/u/1100723/2021/EXPMONBug-40444.jpg
<figcaptionsource: EXPMON
EXPMON researchers reproduced the attack on the latest Office 2019 / Office 365 on Windows 10.
In a reply to BleepingComputer, Haifei Li of EXPMON said that the attackers used a .DOCX file. Upon opening it, the document loaded the Internet Explorer engine to render a remote web page from the threat actor.
Malware is then downloaded by using a specific ActiveX control in the web page. Executing the threat is done using “a trick called ‘Cpl File Execution’,” referenced in Microsoft’s advisory.
The researcher told us that the attack method is 100% reliable, which makes it very dangerous. He reported the vulnerability to Microsoft early Sunday morning.
See Also: Bluetooth Bugs Open Billions of Devices to DoS, Code Execution Workaround for CVE-2021-40444 zero-day attacksAs there is no security update available at this time, Microsoft has provided the following workaround – disable the installation of all ActiveX controls in Internet Explorer.
A Windows registry update ensures that ActiveX is rendered inactive for all sites, while already available ActiveX controls will keep functioning.
Users should save the file below with the .REG extension and execute it t[...]
Microsoft shares temp fix for ongoing Office 365 zero-day attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft shares temp fix for ongoing Office 365 zero-day attacksPost Views: 83
Reading Time: 1 Minute
Microsoft shared yesterday a mitigation for a remote code execution vulnerability in Windows that is being exploited in targeted attacks against Office 365 and Office 2019 on Windows 10.
The flaw is in MSHTML, the browser rendering engine that is also used by Microsoft Office documents. Ongoing attacks against Office 365Identified as CVE-2021-40444, the security issue affects Windows Server 2008 through 2019 and Windows 8.1 through 10 and has a severity level of 8.8 out of the maximum 10.
Microsoft is aware of targeted attacks that try to exploit the vulnerability by sending specially-crafted Microsoft Office documents to potential victims, the company says in an advisory today.
“An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document” – Microsoft
However, the attack is thwarted if Microsoft Office runs with the default configuration, where documents from the web are opened in Protected View mode or Application Guard for Office 365.
Protected View is a read-only mode that has most of the editing functions disabled, while Application Guard isolates untrusted documents, denying them access to corporate resources, the intranet, or other files on the system.
Systems with active Microsoft’s Defender Antivirus and Defender for Endpoint (build 1.349.22.0 and above) benefit from protection against attempts to exploit CVE-2021-40444.
Microsoft’s enterprise security platform will display alerts about this attack as “Suspicious Cpl File Execution.”
See Also: Complete Offensive Security and Ethical Hacking Course Researchers from multiple cybersecurity companies are credited for finding and reporting the vulnerability: Haifei Li of EXPMON, Dhanesh Kizhakkinan, Bryce Abdo, and Genwei Jiang – all three of Mandiant, and Rick Cole of Microsoft Security Intelligence.
In a tweet today, EXPMON (exploit monitor) says that they found the vulnerability after detecting a “highly sophisticated zero-day attack” aimed at Microsoft Office users.
https://www.bleepstatic.com/images/news/u/1100723/2021/EXPMONBug-40444.jpg
<figcaptionsource: EXPMON
EXPMON researchers reproduced the attack on the latest Office 2019 / Office 365 on Windows 10.
In a reply to BleepingComputer, Haifei Li of EXPMON said that the attackers used a .DOCX file. Upon opening it, the document loaded the Internet Explorer engine to render a remote web page from the threat actor.
Malware is then downloaded by using a specific ActiveX control in the web page. Executing the threat is done using “a trick called ‘Cpl File Execution’,” referenced in Microsoft’s advisory.
The researcher told us that the attack method is 100% reliable, which makes it very dangerous. He reported the vulnerability to Microsoft early Sunday morning.
See Also: Bluetooth Bugs Open Billions of Devices to DoS, Code Execution Workaround for CVE-2021-40444 zero-day attacksAs there is no security update available at this time, Microsoft has provided the following workaround – disable the installation of all ActiveX controls in Internet Explorer.
A Windows registry update ensures that ActiveX is rendered inactive for all sites, while already available ActiveX controls will keep functioning.
Users should save the file below with the .REG extension and execute it t[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft shares temp fix for ongoing Office 365 zero-day attacks https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft shares temp fix for ongoing Office 365 zero-day attacksPost Views:…
o apply it to the Policy hive. After a system reboot, the new configuration should be applied.
As updates are not available yet for the CVE-2021-40444, they have released the following workaround that prevents ActiveX controls from running in Internet Explorer and applications that embed the browser.
To disable ActiveX controls, please follow these steps:
1. Open Notepad and paste the following text into a text file. Then save the file as disable-activex.reg. Make sure you have the displaying of file extensions enabled to properly create the Registry file.
Alternatively, you can download the registry file from here.
3. Reboot your computer to apply the new configuration.
See Also: Offensive Security Tool: Pegasus Spyware – Decompiled Once you reboot your computer, ActiveX controls will be disabled in Internet Explorer.
When Microsoft provides an official security update for this vulnerability, you can remove this temporary Registry fix by manually deleting the created Registry keys.
Alternatively, you can utilize this reg file to automatically delete the entries.
Update: Added comment received after publication from Haifei Li of EXPMON, one of the researchers that reported the vulnerability to Microsoft. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerSource: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Jenkins-90x90.jpg Jenkins project’s Confluence server hacked to mine Monero1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/unnamed-e1630998483665-90x90.jpg Critical Auth Bypass Bug Affect NETGEAR Smart Switches2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/loyalty-card-90x90.jpg Brute-Force Attacks Target Inboxes for Gift Card Data3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Braktooth-New-Bluetooth-gaps-threaten-countless-devices-1024x576-1-90x90.jpg Bluetooth Bugs Open Billions of Devices to DoS, Code Execution6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/wordpress_plugin_vuln-90x90.jpg Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ransomware-cpu-90x90.jpg LockFile Ransomware Uses Never-Before Seen Encryption to Avoid Detection1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Windows-Abstract-90x90.jpg Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/F5-Big-IP-e1619725870974-90x90.jpg F5 Bug Could Lead to Complete System Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/steel-series-e1629915533369-90x90.jpg Win10 Admin Rights Tossed Off by Yet Another Plug-In2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/white-pegasus-e1626804896117-90x90.jpg Pegasus Spyware Uses iPhone Zero-Click iMessage Zero-Day2 weeks ago
style="displa[...]
As updates are not available yet for the CVE-2021-40444, they have released the following workaround that prevents ActiveX controls from running in Internet Explorer and applications that embed the browser.
To disable ActiveX controls, please follow these steps:
1. Open Notepad and paste the following text into a text file. Then save the file as disable-activex.reg. Make sure you have the displaying of file extensions enabled to properly create the Registry file.
Alternatively, you can download the registry file from here.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1001"=dword:00000003
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1001"=dword:00000003
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1001"=dword:00000003
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1001"=dword:00000003
"1004"=dword:000000032. Find the newly created disable-activex.reg and double-click on it. When a UAC prompt is displayed, click on the Yes button to import the Registry entries.3. Reboot your computer to apply the new configuration.
See Also: Offensive Security Tool: Pegasus Spyware – Decompiled Once you reboot your computer, ActiveX controls will be disabled in Internet Explorer.
When Microsoft provides an official security update for this vulnerability, you can remove this temporary Registry fix by manually deleting the created Registry keys.
Alternatively, you can utilize this reg file to automatically delete the entries.
Update: Added comment received after publication from Haifei Li of EXPMON, one of the researchers that reported the vulnerability to Microsoft. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerSource: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Jenkins-90x90.jpg Jenkins project’s Confluence server hacked to mine Monero1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/unnamed-e1630998483665-90x90.jpg Critical Auth Bypass Bug Affect NETGEAR Smart Switches2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/loyalty-card-90x90.jpg Brute-Force Attacks Target Inboxes for Gift Card Data3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Braktooth-New-Bluetooth-gaps-threaten-countless-devices-1024x576-1-90x90.jpg Bluetooth Bugs Open Billions of Devices to DoS, Code Execution6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/wordpress_plugin_vuln-90x90.jpg Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ransomware-cpu-90x90.jpg LockFile Ransomware Uses Never-Before Seen Encryption to Avoid Detection1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Windows-Abstract-90x90.jpg Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/F5-Big-IP-e1619725870974-90x90.jpg F5 Bug Could Lead to Complete System Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/steel-series-e1629915533369-90x90.jpg Win10 Admin Rights Tossed Off by Yet Another Plug-In2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/white-pegasus-e1626804896117-90x90.jpg Pegasus Spyware Uses iPhone Zero-Click iMessage Zero-Day2 weeks ago
style="displa[...]
Hacking Articles Tips Tricks Videos Tutorials
o apply it to the Policy hive. After a system reboot, the new configuration should be applied. As updates are not available yet for the CVE-2021-40444, they have released the following workaround that prevents ActiveX controls from running in Internet Explorer…
y:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Microsoft shares temp fix for ongoing Office 365 zero-day attacks first appeared on Black Hat Ethical Hacking.
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Microsoft shares temp fix for ongoing Office 365 zero-day attacks first appeared on Black Hat Ethical Hacking.
Hook Heaps and Live Free
https://www.reddit.com/r/redteamsec/comments/pkte0o/hook_heaps_and_live_free/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.arashparsa.com/hook-heaps-and-live-free/) [comments] (https://www.reddit.com/r/redteamsec/comments/pkte0o/hook_heaps_and_live_free/)
https://www.reddit.com/r/redteamsec/comments/pkte0o/hook_heaps_and_live_free/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.arashparsa.com/hook-heaps-and-live-free/) [comments] (https://www.reddit.com/r/redteamsec/comments/pkte0o/hook_heaps_and_live_free/)
Shellcode Detection Using Real-Time Kernel Monitoring
https://www.reddit.com/r/redteamsec/comments/pkttjd/shellcode_detection_using_realtime_kernel/
submitted by /u/0xDangerous_bit (https://www.reddit.com/user/0xDangerous_bit)
[link] (https://www.countercraftsec.com/blog/post/shellcode-detection-using-realtime-kernel-monitoring/) [comments] (https://www.reddit.com/r/redteamsec/comments/pkttjd/shellcode_detection_using_realtime_kernel/)
https://www.reddit.com/r/redteamsec/comments/pkttjd/shellcode_detection_using_realtime_kernel/
submitted by /u/0xDangerous_bit (https://www.reddit.com/user/0xDangerous_bit)
[link] (https://www.countercraftsec.com/blog/post/shellcode-detection-using-realtime-kernel-monitoring/) [comments] (https://www.reddit.com/r/redteamsec/comments/pkttjd/shellcode_detection_using_realtime_kernel/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Fowsniff CTF — TryHackMe
https://cdn-images-1.medium.com/max/1200/1*Y1LqUXLKQDryVaOkv6BZqg.jpeg
CTF’s walkthrough will show you how to get the flag. This CTF is ideal for Beginners
Continue reading on Medium »
Fowsniff CTF — TryHackMe
https://cdn-images-1.medium.com/max/1200/1*Y1LqUXLKQDryVaOkv6BZqg.jpeg
CTF’s walkthrough will show you how to get the flag. This CTF is ideal for Beginners
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
One Way or The OTHER!
https://cdn-images-1.medium.com/max/1920/0*dCFzWAte0IRlGaeO
Cybercriminals Abusing Internet-Sharing Services to Monetize Malware/Ransomware Campaigns
Continue reading on rootissh »
One Way or The OTHER!
https://cdn-images-1.medium.com/max/1920/0*dCFzWAte0IRlGaeO
Cybercriminals Abusing Internet-Sharing Services to Monetize Malware/Ransomware Campaigns
Continue reading on rootissh »
Graphw00F - GraphQL fingerprinting tool for GQL endpoints
Credits to Nick Aleks for the logo!How does it work? graphw00f (inspired by wafw00f) is the GraphQL fingerprinting tool for GQL endpoints, it sends a mix of benign and malformed queries to determine the GraphQL engine running behind the scenes. graphw00f will provide insights into what security defences each technology provides out of the box, and whether they are on or off by default. Specially crafted queries cause different GraphQL server implementations to respond uniquely to queries, mutations and subscriptions, this makes it trivial to fingerprint the backend engine and distinguish between the various GraphQL implementations. (CWE: CWE-200)Detections graphw00f currently attempts to discover the following GraphQL engines: Graphene - Python Ariadne - Python Apollo - TypeScript graphql-go - Go gqlgen - Go WPGraphQL - PHP GraphQL API for Wordpress - PHP Ruby - GraphQL graphql-php - PHP Hasura - Haskell HyperGraphQL - Java graphql-java - Java Juniper - Rust Sangria - Scala Flutter - Dart Diana.jl - Julia Strawberry - Python Tartiflette - Python GraphQL Technologies Defence Matrices Each fingerprinted technology (e.g. Graphene, Ariadne, ...) has an associated document (example for graphene) which covers the security defence mechanisms the specific technology supports to give a better idea how the implementation may be attacked. | Field Suggestions | Query Depth Limit | Query Cost Analysis | Automatic Persisted Queries | Introspection | Debug Mode | Batch Requests ||-------------------|-------------------|---------------------|-----------------------------|--------------------|------------|-----------------|| On by Default | No Support | No Support | No Support | Enabled by Default | N/A | Off by Default | Prerequisites python3 requests Installation Clone Repository git clone git@github.com:dolevf/graphw00f.git Run graphw00f python3 main.py -h Usage: main.py -hOptions: -h, --help show this help message and exit -r, --noredirect Do not follow redirections given by 3xx responses -t URL, --target=URL target url with the path -o OUTPUT_FILE, --output-file=OUTPUT_FILE Output results to a file (CSV) -l, --list List all GraphQL technologies graphw00f is able to detect -v, --version Print out the current version and exit. Example python3 main.py -t http://127.0.0.1:5000/graphql +-------------------+ | graphw00f | +-------------------+ *** *** ** *** ** ** +--------------+ +--------------+ | Node X | | Node Y | +--------------+ +--------------+ *** *** ** ** ** ** +------------+ | Node Z | +------------+ graphw00f - v1.0.0 The fingerprinting tool for GraphQL \* Checking if GraphQL is available at https://demo.hypergraphql.org:8484/graphql...\* Found GraphQL...\* Attempting to fingerprint...\* Discovered GraphQL Engine: (HyperGraphQL)! Attack Surface Matrix: https://github.com/dolevf/graphw00f/blob/main/docs/hypergraphql.md! Technologies: Java! Homepage: https://www.hypergraphql.org\* Completed. Support and Issues Any issues with graphw00f such as false positives, inaccurate detections, bugs, etc. please create a GitHub issue with environment details. Resources Want to learn more about GraphQL? head over to my other project and hack GraphQL away: Damn Vulnerable GraphQL Application Download Graphw00F
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Credits to Nick Aleks for the logo!How does it work? graphw00f (inspired by wafw00f) is the GraphQL fingerprinting tool for GQL endpoints, it sends a mix of benign and malformed queries to determine the GraphQL engine running behind the scenes. graphw00f will provide insights into what security defences each technology provides out of the box, and whether they are on or off by default. Specially crafted queries cause different GraphQL server implementations to respond uniquely to queries, mutations and subscriptions, this makes it trivial to fingerprint the backend engine and distinguish between the various GraphQL implementations. (CWE: CWE-200)Detections graphw00f currently attempts to discover the following GraphQL engines: Graphene - Python Ariadne - Python Apollo - TypeScript graphql-go - Go gqlgen - Go WPGraphQL - PHP GraphQL API for Wordpress - PHP Ruby - GraphQL graphql-php - PHP Hasura - Haskell HyperGraphQL - Java graphql-java - Java Juniper - Rust Sangria - Scala Flutter - Dart Diana.jl - Julia Strawberry - Python Tartiflette - Python GraphQL Technologies Defence Matrices Each fingerprinted technology (e.g. Graphene, Ariadne, ...) has an associated document (example for graphene) which covers the security defence mechanisms the specific technology supports to give a better idea how the implementation may be attacked. | Field Suggestions | Query Depth Limit | Query Cost Analysis | Automatic Persisted Queries | Introspection | Debug Mode | Batch Requests ||-------------------|-------------------|---------------------|-----------------------------|--------------------|------------|-----------------|| On by Default | No Support | No Support | No Support | Enabled by Default | N/A | Off by Default | Prerequisites python3 requests Installation Clone Repository git clone git@github.com:dolevf/graphw00f.git Run graphw00f python3 main.py -h Usage: main.py -hOptions: -h, --help show this help message and exit -r, --noredirect Do not follow redirections given by 3xx responses -t URL, --target=URL target url with the path -o OUTPUT_FILE, --output-file=OUTPUT_FILE Output results to a file (CSV) -l, --list List all GraphQL technologies graphw00f is able to detect -v, --version Print out the current version and exit. Example python3 main.py -t http://127.0.0.1:5000/graphql +-------------------+ | graphw00f | +-------------------+ *** *** ** *** ** ** +--------------+ +--------------+ | Node X | | Node Y | +--------------+ +--------------+ *** *** ** ** ** ** +------------+ | Node Z | +------------+ graphw00f - v1.0.0 The fingerprinting tool for GraphQL \* Checking if GraphQL is available at https://demo.hypergraphql.org:8484/graphql...\* Found GraphQL...\* Attempting to fingerprint...\* Discovered GraphQL Engine: (HyperGraphQL)! Attack Surface Matrix: https://github.com/dolevf/graphw00f/blob/main/docs/hypergraphql.md! Technologies: Java! Homepage: https://www.hypergraphql.org\* Completed. Support and Issues Any issues with graphw00f such as false positives, inaccurate detections, bugs, etc. please create a GitHub issue with environment details. Resources Want to learn more about GraphQL? head over to my other project and hack GraphQL away: Damn Vulnerable GraphQL Application Download Graphw00F
Read more...
___________________________
@hacking_Attack
@Hacking_Video
GitHub
graphw00f/hypergraphql.md at main · dolevf/graphw00f
graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint. - graphw00f/hypergraphq...
Graphw00F - GraphQL fingerprinting tool for GQL endpoints
http://www.kitploit.com/2021/09/graphw00f-graphql-fingerprinting-tool.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/graphw00f-graphql-fingerprinting-tool.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Graphw00F - GraphQL fingerprinting tool for GQL endpoints