Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux TutorialspacketsifterTool : A Tool To Aid Analysts In Sifting Through A Packet Capture (Pcap) To Find Noteworthy Traffic
packetsifterTool is to perform batch processing of PCAP data to uncover potential IOCs.
Simply initialize PacketSifter with your desired integrations (Virus Total, Abuse IPDB) and pass PacketSifter a pcap and the desired switches and PacketSifter will sift through the data and generate several output files.
Note Please run AbuseIPDBInitial.sh and VTInitial.sh prior to using their corresponding switches or the integrations will not work
05/27/2021
PacketSifter has been revamped to allow a more streamlined interaction with the user. Simply download the new updated packetsifter.sh, run ./packetsifter -h and learn how to properly use the new PacketSifter!
How It Works
Simply pass PacketSifter your pcap to analyze along with your desired flags and let PacketSifter do the work for you!
Example:
root@ubuntu:~# ./packetsifter -i /tmp/testing.pcap -a -r -v
Command Line Options
OPTIONS:
* -a enable abuseipdb lookups of IP addresses in DNS A records
* -h print help
* -i input file [Required]
* -r resolve hostnames in pcap [Can result in DNS queries to attacker infrastructure]
* -v enable VirusTotal lookup of exported SMB/HTTP objects
Requirements
tshark – https://tshark.dev/setup/install/
Output
Currently, PacketSifter generates the following pcaps:
* http.pcap – All conversations containing port 80, 8080, or 8000
* smb.pcap – All conversations categorized by tshark dissectors as NBSS, SMB, or SMB2
* dns.pcap – All conversations categorized by tshark dissectors as DNS
* ftp.pcap – All conversations categorized by tshark dissectors as FTP
Currently, PacketSifter generates the following text files:
* IOstatistics.txt – Protocol Hierarchy and Input/Output broken up in 30 second intervals (useful to find potential beaconing)
* IPstatistics.txt – Overall stats to/from endpoints over IP and individual conversations over IP
* TCPstatistics – Overall stats to/from endpoints over TCP and individual TCP conversations broken down. <> This file can contain a large amount of information. It is recommended to use less or grep for a conversation in question.
* http_info.txt – Statistical data about HTTP conversations
* hostnamesResolved.txt (optional) – Resolved hostnames observed in pcap. <> This can result in DNS queries for attacker infrastructure. Proceed with caution!!
* SMBstatistics.txt – Stats on commands ran using smb or smb2
* dnsARecords.txt – DNS A query/responses
* dnsTXTRecords.txt – DNS TXT query/responses
* errors.txt – trash file
VirusTotal Integration output text files (all optional):
* httpHashToObject.txt – Text file containing md5 hash to object pairing for reference
* httpVTResults.txt – Text file containing results of md5 hash lookup of http objects via VirusTotal API
* smbHashToObject.txt – Text file containing md5 hash to object pairing for reference
* smbVTResults.txt – Text file containing results of md5 hash lookup of smb objects via VirusTotal API
AbuseIPDB Integration output text files (optional):
* IPLookupResults.txt – Text file containing IP Geo-location + IP reputation results
Currently, PacketSifter generates the following tar.gz files:
* httpObjects.tar.gz – HTTP objects observed in pcap. <> There could be a lot of HTTP objects and you can potentially extract malicious http objects depending on the pcap. Use with caution!!
* smbObjects.tar.gz – SMB objects observed in pcap. There could be a lot of SMB objects and you can potentially extract malicious SMB objects depending on the pcap. Use with caution!!
VirusTotal Integration
PacketSifter can now perform hash lookups via VirusTotal API of exported object[...]
packetsifterTool is to perform batch processing of PCAP data to uncover potential IOCs.
Simply initialize PacketSifter with your desired integrations (Virus Total, Abuse IPDB) and pass PacketSifter a pcap and the desired switches and PacketSifter will sift through the data and generate several output files.
Note Please run AbuseIPDBInitial.sh and VTInitial.sh prior to using their corresponding switches or the integrations will not work
05/27/2021
PacketSifter has been revamped to allow a more streamlined interaction with the user. Simply download the new updated packetsifter.sh, run ./packetsifter -h and learn how to properly use the new PacketSifter!
How It Works
Simply pass PacketSifter your pcap to analyze along with your desired flags and let PacketSifter do the work for you!
Example:
root@ubuntu:~# ./packetsifter -i /tmp/testing.pcap -a -r -v
Command Line Options
OPTIONS:
* -a enable abuseipdb lookups of IP addresses in DNS A records
* -h print help
* -i input file [Required]
* -r resolve hostnames in pcap [Can result in DNS queries to attacker infrastructure]
* -v enable VirusTotal lookup of exported SMB/HTTP objects
Requirements
tshark – https://tshark.dev/setup/install/
Output
Currently, PacketSifter generates the following pcaps:
* http.pcap – All conversations containing port 80, 8080, or 8000
* smb.pcap – All conversations categorized by tshark dissectors as NBSS, SMB, or SMB2
* dns.pcap – All conversations categorized by tshark dissectors as DNS
* ftp.pcap – All conversations categorized by tshark dissectors as FTP
Currently, PacketSifter generates the following text files:
* IOstatistics.txt – Protocol Hierarchy and Input/Output broken up in 30 second intervals (useful to find potential beaconing)
* IPstatistics.txt – Overall stats to/from endpoints over IP and individual conversations over IP
* TCPstatistics – Overall stats to/from endpoints over TCP and individual TCP conversations broken down. <> This file can contain a large amount of information. It is recommended to use less or grep for a conversation in question.
* http_info.txt – Statistical data about HTTP conversations
* hostnamesResolved.txt (optional) – Resolved hostnames observed in pcap. <> This can result in DNS queries for attacker infrastructure. Proceed with caution!!
* SMBstatistics.txt – Stats on commands ran using smb or smb2
* dnsARecords.txt – DNS A query/responses
* dnsTXTRecords.txt – DNS TXT query/responses
* errors.txt – trash file
VirusTotal Integration output text files (all optional):
* httpHashToObject.txt – Text file containing md5 hash to object pairing for reference
* httpVTResults.txt – Text file containing results of md5 hash lookup of http objects via VirusTotal API
* smbHashToObject.txt – Text file containing md5 hash to object pairing for reference
* smbVTResults.txt – Text file containing results of md5 hash lookup of smb objects via VirusTotal API
AbuseIPDB Integration output text files (optional):
* IPLookupResults.txt – Text file containing IP Geo-location + IP reputation results
Currently, PacketSifter generates the following tar.gz files:
* httpObjects.tar.gz – HTTP objects observed in pcap. <> There could be a lot of HTTP objects and you can potentially extract malicious http objects depending on the pcap. Use with caution!!
* smbObjects.tar.gz – SMB objects observed in pcap. There could be a lot of SMB objects and you can potentially extract malicious SMB objects depending on the pcap. Use with caution!!
VirusTotal Integration
PacketSifter can now perform hash lookups via VirusTotal API of exported object[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux TutorialspacketsifterTool : A Tool To Aid Analysts In Sifting Through A Packet Capture (Pcap) To Find Noteworthy Traffic packetsifterTool is to perform batch processing of PCAP data to uncover potential IOCs. Simply initialize PacketSifter with…
s found via SMB/HTTP.
Steps to configure PacketSifter with VirusTotal integration:
1. Ensure you have jq (https://stedolan.github.io/jq/download/) installed.
root@ubuntu:~# apt-get install jq
* Ensure you have curl installed.
root@ubuntu:~# apt-get install curl
* Download the new version of packetsifter.sh and the new script VTInitial.sh
* Run VTInitial.sh in the same folder as packetsifter.sh and supply your 64 character alphanumeric VirusTotal API Key when prompted
* For instructions on how to obtain a free VirusTotal API Key https://developers.virustotal.com/reference
Successful output of VTInitial.sh is shown below:
Run PacketSifter with the -v flag to enable VirusTotal lookups of exported HTTP and SMB objects.
Successful output of VirusTotal integration and subsequent generated httpVTResults.txt / smbVTResults.txt shown below:
AbuseIPDB Integration
PacketSifter can perform IP Geo-location + IP reputation lookups of IP addresses returned in DNS A Records.
Steps to configure PacketSifter with AbuseIPDB integration:
* Ensure you have jq (https://stedolan.github.io/jq/download/) installed.
root@ubuntu:~# apt-get install jq
* Ensure you have curl installed.
root@ubuntu:~# apt-get install curl
* Download the new version of packetsifter.sh and the new script AbuseIPDBInitial.sh
* Run AbuseIPDBInitial.sh in the same folder as packetsifter.sh and supply your 80 character alphanumeric AbuseIPDB API Key when prompted.
* For instructions on how to obtain a free AbuseIPDB API Key https://www.abuseipdb.com/register
**AbuseIPDB free API keys have a limit of 1000 lookups a day**
Successful output of AbuseIPDBInitial.sh is shown below:
* Run PacketSifter with the -a flag to enable lookups on DNS A records via AbuseIPDB.
Successful output of AbuseIPDB integration and subsequent generated IPLookupResults.txt shown below:
**Confidence Score is on a 0-100 percent confidence scale**
Download
Steps to configure PacketSifter with VirusTotal integration:
1. Ensure you have jq (https://stedolan.github.io/jq/download/) installed.
root@ubuntu:~# apt-get install jq
* Ensure you have curl installed.
root@ubuntu:~# apt-get install curl
* Download the new version of packetsifter.sh and the new script VTInitial.sh
* Run VTInitial.sh in the same folder as packetsifter.sh and supply your 64 character alphanumeric VirusTotal API Key when prompted
* For instructions on how to obtain a free VirusTotal API Key https://developers.virustotal.com/reference
Successful output of VTInitial.sh is shown below:
Run PacketSifter with the -v flag to enable VirusTotal lookups of exported HTTP and SMB objects.
Successful output of VirusTotal integration and subsequent generated httpVTResults.txt / smbVTResults.txt shown below:
AbuseIPDB Integration
PacketSifter can perform IP Geo-location + IP reputation lookups of IP addresses returned in DNS A Records.
Steps to configure PacketSifter with AbuseIPDB integration:
* Ensure you have jq (https://stedolan.github.io/jq/download/) installed.
root@ubuntu:~# apt-get install jq
* Ensure you have curl installed.
root@ubuntu:~# apt-get install curl
* Download the new version of packetsifter.sh and the new script AbuseIPDBInitial.sh
* Run AbuseIPDBInitial.sh in the same folder as packetsifter.sh and supply your 80 character alphanumeric AbuseIPDB API Key when prompted.
* For instructions on how to obtain a free AbuseIPDB API Key https://www.abuseipdb.com/register
**AbuseIPDB free API keys have a limit of 1000 lookups a day**
Successful output of AbuseIPDBInitial.sh is shown below:
* Run PacketSifter with the -a flag to enable lookups on DNS A records via AbuseIPDB.
Successful output of AbuseIPDB integration and subsequent generated IPLookupResults.txt shown below:
**Confidence Score is on a 0-100 percent confidence scale**
Download
How to keep getting better at reconnaissance ?
https://www.reddit.com/r/Pentesting/comments/pshmws/how_to_keep_getting_better_at_reconnaissance/
<!-- SC_OFF -->i mean beyond the usual subdomain enumeration, port scanning, directory brute forcing, how do you usually get better at it? how do you get ideas for new recon techniques/tools ? <!-- SC_ON --> submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/pshmws/how_to_keep_getting_better_at_reconnaissance/) [comments] (https://www.reddit.com/r/Pentesting/comments/pshmws/how_to_keep_getting_better_at_reconnaissance/)
https://www.reddit.com/r/Pentesting/comments/pshmws/how_to_keep_getting_better_at_reconnaissance/
<!-- SC_OFF -->i mean beyond the usual subdomain enumeration, port scanning, directory brute forcing, how do you usually get better at it? how do you get ideas for new recon techniques/tools ? <!-- SC_ON --> submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/pshmws/how_to_keep_getting_better_at_reconnaissance/) [comments] (https://www.reddit.com/r/Pentesting/comments/pshmws/how_to_keep_getting_better_at_reconnaissance/)
How can I learn Pen testing as a kid?
https://www.reddit.com/r/Pentesting/comments/pshspb/how_can_i_learn_pen_testing_as_a_kid/
<!-- SC_OFF -->Hello I’m interested in pen testing but let’s just say I can’t go to collage yet, Any ways I already know some pretty basic Linux and semi fluent in python but not in the exploit way. anyways how can I learn the most about pen testing and no I’m not a egy black hat script kiddie lol and I want to eventually get a job in pen testing and helping people. Ok so know that you know a little of what I want. how can I learn this and prepare for this things. Like learning sockets in python and hack the box and back doors using msg venom ok I’m sorry I’m rambling on now so I’m gonna end it now. Admins I’m new to this so if this breaks any rules feel free to remove this Don’t mind the name btw I can’t change it or be bothered making a new account Thxs <!-- SC_ON --> submitted by /u/gallacticscambaiter (https://www.reddit.com/user/gallacticscambaiter)
[link] (https://www.reddit.com/r/Pentesting/comments/pshspb/how_can_i_learn_pen_testing_as_a_kid/) [comments] (https://www.reddit.com/r/Pentesting/comments/pshspb/how_can_i_learn_pen_testing_as_a_kid/)
https://www.reddit.com/r/Pentesting/comments/pshspb/how_can_i_learn_pen_testing_as_a_kid/
<!-- SC_OFF -->Hello I’m interested in pen testing but let’s just say I can’t go to collage yet, Any ways I already know some pretty basic Linux and semi fluent in python but not in the exploit way. anyways how can I learn the most about pen testing and no I’m not a egy black hat script kiddie lol and I want to eventually get a job in pen testing and helping people. Ok so know that you know a little of what I want. how can I learn this and prepare for this things. Like learning sockets in python and hack the box and back doors using msg venom ok I’m sorry I’m rambling on now so I’m gonna end it now. Admins I’m new to this so if this breaks any rules feel free to remove this Don’t mind the name btw I can’t change it or be bothered making a new account Thxs <!-- SC_ON --> submitted by /u/gallacticscambaiter (https://www.reddit.com/user/gallacticscambaiter)
[link] (https://www.reddit.com/r/Pentesting/comments/pshspb/how_can_i_learn_pen_testing_as_a_kid/) [comments] (https://www.reddit.com/r/Pentesting/comments/pshspb/how_can_i_learn_pen_testing_as_a_kid/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Execute Unmanaged Code via C# PInvoke
An unmanaged code is one that is written outside the DotNet framework which is allowed to be executed at runtime. In this, you will learn how to use C# and DotNet to execute a shellcode crafted from Metasploit.
https://tbhaxor.com/execute-unmanaged-code-via-c-pinvoke/
submitted by /u/tbhaxor
[link] [comments]
Execute Unmanaged Code via C# PInvoke
An unmanaged code is one that is written outside the DotNet framework which is allowed to be executed at runtime. In this, you will learn how to use C# and DotNet to execute a shellcode crafted from Metasploit.
https://tbhaxor.com/execute-unmanaged-code-via-c-pinvoke/
submitted by /u/tbhaxor
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
don't want to sound like a d-ck, but really want to get an old tactile phone to work again
I'm really not trying to be a hipster guys, but I really want to have a phone that has true buttons (like the nokia 3310). Also super durable like those phones. I've gotten better about it, but sometimes I get distracted and don't need/want all of the features of a smartphone everyday. Plus I just like the feel of buttons.
I tried doing this a year back, but they said that it couldn't be done since it could only go to 2g.
If there are different routes/hacks please let me know.
thanks again guys
submitted by /u/Ihaveastupidstory
[link] [comments]
don't want to sound like a d-ck, but really want to get an old tactile phone to work again
I'm really not trying to be a hipster guys, but I really want to have a phone that has true buttons (like the nokia 3310). Also super durable like those phones. I've gotten better about it, but sometimes I get distracted and don't need/want all of the features of a smartphone everyday. Plus I just like the feel of buttons.
I tried doing this a year back, but they said that it couldn't be done since it could only go to 2g.
If there are different routes/hacks please let me know.
thanks again guys
submitted by /u/Ihaveastupidstory
[link] [comments]
reddit
don't want to sound like a d-ck, but really want to get an old...
I'm really not trying to be a hipster guys, but I really want to have a phone that has true buttons (like the nokia 3310). Also super durable ...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Exploit WebDAV using Metasploit
WebDAV is an extension to the HTTP protocol that allows users to upload, move or change the documents on the server via HTTP verbs. In this post learn how to exploit WebDAV using Metasploit. https://tbhaxor.com/exploit-webdav-using-metasploit/
I am sorry to share another post today, This is for the task of PentesterAcademy's weekend lab sprint
submitted by /u/tbhaxor
[link] [comments]
Exploit WebDAV using Metasploit
WebDAV is an extension to the HTTP protocol that allows users to upload, move or change the documents on the server via HTTP verbs. In this post learn how to exploit WebDAV using Metasploit. https://tbhaxor.com/exploit-webdav-using-metasploit/
I am sorry to share another post today, This is for the task of PentesterAcademy's weekend lab sprint
submitted by /u/tbhaxor
[link] [comments]
Super Admin panel without Credentials
https://rizwansiddiqu1.medium.com/super-admin-panel-without-credentials-c2022a23bb35?source=rss------bug_bounty-5
https://rizwansiddiqu1.medium.com/super-admin-panel-without-credentials-c2022a23bb35?source=rss------bug_bounty-5
As-Salaam-Alaikum.Continue reading on Medium » (https://rizwansiddiqu1.medium.com/super-admin-panel-without-credentials-c2022a23bb35?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My OSCP Journey
I would like to start off by saying my path to OSCP was very unconventional. Let’s start from the beginning shall we? My path to OSCP…
Continue reading on Medium »
My OSCP Journey
I would like to start off by saying my path to OSCP was very unconventional. Let’s start from the beginning shall we? My path to OSCP…
Continue reading on Medium »