Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
ODBParser : OSINT Tool To Search, Parse And Dump Only The Open Elasticsearch And MongoDB Directories That Have The Data You Care About Exposing
ODBParser is a tool to search for PII being exposed in open databases.
ONLY to be used to identify exposed PII and warn server owners of irresponsible database maintenance
OR to query databases you have permission to access!
PLEASE USE RESPONSIBLY What Is This?
Wrote this as wanted to create one-stop OSINT tool for searching, parsing and analyzing open databases in order to identify leakages of PII on third-party servers. Other tools seem to either only search for open databases or dump them once you’ve identified them and then will grab data indiscriminately. Grew from function or two into what’s in this repo, so code isn’t as clean and pretty as it could be. Features
To identify open databases you can:
* query Shodan and BinaryEdge using all possible parameters (filter by country, port number, whatever)
* specify single IP address
* load up file that has list of IP addresses
* paste list of IP addresses from clipboard
Dumping options:
* parses all databases/collections to identify data you specify
* grab everything hosted on server
* grab just one index/collection
* Use ctrl+c to skip dumping certain index
Post-Processing:
* convert JSON dumps to CSV
* remove useless columns from CSV
Other features:
* keeps track of all the IP addresses and databases you have queried along with info about each server.
* maintains stats file with number of IP’s you’ve queried, number of databases you’ve parsed and number of records you’ve dumped
* convert JSON dumps you already have to CSV
* for every database that has total number of records above your limit, script will create an entry in a special file along with 5 sample records so you can review and decide whether the database is worth grabbing
* Default output is line-separated JSON file with a JSON object on each line. You can choose to have it output a “proper JSON” file by using the “properjson” flag
* You can convert the files to CSV on the fly or you can convert only certain files after run is complete (I recommend latter). Converted JSON files will be moved to folder called “JSON backups” in same directory. NOTE: When converting to CSV, script drops exact duplicate rows and drops columns and rows where all values are NaN, because that’s what I wanted to do. Feel free to edit function if you’d rather have exact copy of JSON file.
* Windows ONLY If script pulls back huge number of indices that have field you care about, script will list names of the dbs, pause and give you ten seconds to decide whether you want to go ahead and pull all the data from every index as I’ve found if you get too many databases returned even after you’ve specified fields you want, there is a good chance data is fake or useless logs and you can usually tell from name whether either possibility is the case. If you don’t act within 10 seconds, script will go ahead and dump every index.
* as you may have noticed, lot of people have been scanning for MongoDB databases and holding them hostage, often changing name to something like “TO_RESTORE_EMAIL_XXXRESTORE.COM.” The MongoDb scraper will ignore all databases and collections that have been pwned by checking name of DB/collection against list of strings that indicate pwnage
* script is pretty verbose (maybe too verbose) but I like seeing what’s going on. Feel free to silence print statements if you prefer. Customization
See the odbconfig.py file to specify your parameters, because really name of the game is exposing the data YOU are interested in. I provided some examples in the config file. Play around with them!
You can:
* specify what index or collection names you want to collect by specifying substrings in config file. For example, if have the term “client”, scri[...]
ODBParser : OSINT Tool To Search, Parse And Dump Only The Open Elasticsearch And MongoDB Directories That Have The Data You Care About Exposing
ODBParser is a tool to search for PII being exposed in open databases.
ONLY to be used to identify exposed PII and warn server owners of irresponsible database maintenance
OR to query databases you have permission to access!
PLEASE USE RESPONSIBLY What Is This?
Wrote this as wanted to create one-stop OSINT tool for searching, parsing and analyzing open databases in order to identify leakages of PII on third-party servers. Other tools seem to either only search for open databases or dump them once you’ve identified them and then will grab data indiscriminately. Grew from function or two into what’s in this repo, so code isn’t as clean and pretty as it could be. Features
To identify open databases you can:
* query Shodan and BinaryEdge using all possible parameters (filter by country, port number, whatever)
* specify single IP address
* load up file that has list of IP addresses
* paste list of IP addresses from clipboard
Dumping options:
* parses all databases/collections to identify data you specify
* grab everything hosted on server
* grab just one index/collection
* Use ctrl+c to skip dumping certain index
Post-Processing:
* convert JSON dumps to CSV
* remove useless columns from CSV
Other features:
* keeps track of all the IP addresses and databases you have queried along with info about each server.
* maintains stats file with number of IP’s you’ve queried, number of databases you’ve parsed and number of records you’ve dumped
* convert JSON dumps you already have to CSV
* for every database that has total number of records above your limit, script will create an entry in a special file along with 5 sample records so you can review and decide whether the database is worth grabbing
* Default output is line-separated JSON file with a JSON object on each line. You can choose to have it output a “proper JSON” file by using the “properjson” flag
* You can convert the files to CSV on the fly or you can convert only certain files after run is complete (I recommend latter). Converted JSON files will be moved to folder called “JSON backups” in same directory. NOTE: When converting to CSV, script drops exact duplicate rows and drops columns and rows where all values are NaN, because that’s what I wanted to do. Feel free to edit function if you’d rather have exact copy of JSON file.
* Windows ONLY If script pulls back huge number of indices that have field you care about, script will list names of the dbs, pause and give you ten seconds to decide whether you want to go ahead and pull all the data from every index as I’ve found if you get too many databases returned even after you’ve specified fields you want, there is a good chance data is fake or useless logs and you can usually tell from name whether either possibility is the case. If you don’t act within 10 seconds, script will go ahead and dump every index.
* as you may have noticed, lot of people have been scanning for MongoDB databases and holding them hostage, often changing name to something like “TO_RESTORE_EMAIL_XXXRESTORE.COM.” The MongoDb scraper will ignore all databases and collections that have been pwned by checking name of DB/collection against list of strings that indicate pwnage
* script is pretty verbose (maybe too verbose) but I like seeing what’s going on. Feel free to silence print statements if you prefer. Customization
See the odbconfig.py file to specify your parameters, because really name of the game is exposing the data YOU are interested in. I provided some examples in the config file. Play around with them!
You can:
* specify what index or collection names you want to collect by specifying substrings in config file. For example, if have the term “client”, scri[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
On-The-Fly : Tool Which Gives Capabilities To Perform Pentesting Tests In Several Domains (IoT, ICS & IT)
On-The-Fly was written in Python and made extensive use of Scapy and netfilterqueue. It is crucial to have Scapy in Python and net filter queue installed with a compatible version of Python. For this, a version of Python 3 up to Python version 3.7.5 is recommended (and no higher, as there may be incompatibilities with 3.8 and 3.9 in some libraries that it uses ‘on-the-fly’). There is a requirements.txt file that must be executed the first time the tool is launched using ‘pip install -r requirements.txt’. Again the pip version must be oriented to a Python 3 version up to 3.7.5.
pip install -r requirements.txt
Usage
python on-the-fly.py
Example Videos
on-the-fly: MySQL_manipulation Module
https://1.bp.blogspot.com/-SvguRi6lDUk/YUggJLQyQSI/AAAAAAAAK4w/_tLzVMmuSAIvwiyS5-3V7lBy90sDMD-WACLcBGAsYHQ/s480/1.jpg
on-the-fly: SSDP_fake Module
https://1.bp.blogspot.com/-5IRA6_cJi7I/YUggjHDtXMI/AAAAAAAAK44/8nojFRFSfIgfiiDAGqNHoeq3fyS8XAWLQCLcBGAsYHQ/s480/2.jpg
on-the-fly: Proxy_socks4 Module
https://1.bp.blogspot.com/-Z9NEPGYCf5s/YUgg8DyXRdI/AAAAAAAAK5A/2qeq169LBuUg_1snM7xDea_ZSSduicOOgCLcBGAsYHQ/s480/3.jpg
on-the-fly: Port_forwarding Module
https://1.bp.blogspot.com/-JouHDDJnc7k/YUgh9_-lzzI/AAAAAAAAK5I/mNyBb3o8730mkxiMY6e3JzcW0TxknTNIACLcBGAsYHQ/s480/4.jpg
on-the-fly: MDNS_Scan Module
https://1.bp.blogspot.com/-9rlNeiBeJzw/YUgiRtGOVMI/AAAAAAAAK5Q/VMmJ-VVEe3YLKb-3dO4oRovVCTKXsn-SQCLcBGAsYHQ/s480/5.jpg
Download
On-The-Fly : Tool Which Gives Capabilities To Perform Pentesting Tests In Several Domains (IoT, ICS & IT)
On-The-Fly was written in Python and made extensive use of Scapy and netfilterqueue. It is crucial to have Scapy in Python and net filter queue installed with a compatible version of Python. For this, a version of Python 3 up to Python version 3.7.5 is recommended (and no higher, as there may be incompatibilities with 3.8 and 3.9 in some libraries that it uses ‘on-the-fly’). There is a requirements.txt file that must be executed the first time the tool is launched using ‘pip install -r requirements.txt’. Again the pip version must be oriented to a Python 3 version up to 3.7.5.
pip install -r requirements.txt
Usage
python on-the-fly.py
Example Videos
on-the-fly: MySQL_manipulation Module
https://1.bp.blogspot.com/-SvguRi6lDUk/YUggJLQyQSI/AAAAAAAAK4w/_tLzVMmuSAIvwiyS5-3V7lBy90sDMD-WACLcBGAsYHQ/s480/1.jpg
on-the-fly: SSDP_fake Module
https://1.bp.blogspot.com/-5IRA6_cJi7I/YUggjHDtXMI/AAAAAAAAK44/8nojFRFSfIgfiiDAGqNHoeq3fyS8XAWLQCLcBGAsYHQ/s480/2.jpg
on-the-fly: Proxy_socks4 Module
https://1.bp.blogspot.com/-Z9NEPGYCf5s/YUgg8DyXRdI/AAAAAAAAK5A/2qeq169LBuUg_1snM7xDea_ZSSduicOOgCLcBGAsYHQ/s480/3.jpg
on-the-fly: Port_forwarding Module
https://1.bp.blogspot.com/-JouHDDJnc7k/YUgh9_-lzzI/AAAAAAAAK5I/mNyBb3o8730mkxiMY6e3JzcW0TxknTNIACLcBGAsYHQ/s480/4.jpg
on-the-fly: MDNS_Scan Module
https://1.bp.blogspot.com/-9rlNeiBeJzw/YUgiRtGOVMI/AAAAAAAAK5Q/VMmJ-VVEe3YLKb-3dO4oRovVCTKXsn-SQCLcBGAsYHQ/s480/5.jpg
Download
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials ODBParser : OSINT Tool To Search, Parse And Dump Only The Open Elasticsearch And MongoDB Directories That Have The Data You Care About Exposing ODBParser is a tool to search for PII being exposed in open databases. ONLY to be used to…
pt will pull index called “clients” or “client_data.” I recommend you keep these lists blank as you never know what databases you care about will be called and instead specify the fields you care about.
* specify what fields you care about: if you only want to grab ES indices that have “email” in a field name, e.g.”user_emails”, you can do that. If you want to make sure the index has at least 2 fields you care about, you can do that too. Or if you just want to grab everything no matter what fields are in there, you can do that too.
* specify what indices you DON’T want e.g., system index names and others that are generally used for basic logging. Examples provided in config file.
* override config and grab everything on a server
* specify output (default is JSON, can choose CSV)
* set minimum and maximum size database script will dump by default and you can set flag to override max docs on case by case basis. Installation and Requirements
* Clone or download to machine
* Get API keys for Shodan and/or BinaryEdge
* configure parameters in ODBconfig.py file
* install requirements from file
I suggest creating virtual environment for ODBParser so have no issues with incorrect module versions. Note: Tested ONLY on Python 3.7.3 and on Windows 10.
PLEASE USE RESPONSIBLY Next Steps and Known Issues
* clean up code a bit more
* multithread various processes.
* expand to other db types
* add other open directory search engines (Zoomeye, etc.)
* unable to scroll past first page for certain ES instances due to way ES <2.0Pretty sure fixed this. Open issue if get scrollid errors
Usage
Examples: python ODBParser.py -cn US -p 8080 -t users –elastic –shodan –csv –limit 100
python ODBParser.py -ip 192.168.2:8080 –mongo –ignorelogs –nosizelimits
Damage to-date: 0 servers parsed | 0 databases dumped | 0 records pulled
optional arguments:
-h, –help show this help message and exit
Query Options:
–shodan, -sh Add this flag if using Shodan. Specify ES or MDB w/
flags.
–binary, -be Add this flag if using BinaryEdge. Specify ES or MDB
w/ flags.
–ip , -ip Query one server. Add port like so ‘192.165.2.1:8080’
or will use default ports for each db type. Add ES or
MDB flags to specify parser.
–file , -f Load line-separated IPs from file. Add port or will
assume default ports for each db type. Add ES or MDB
flags to specify parser.
–paste, -v Query line-separated IPs from clipboard. Add port or
will assume default ports for each db type, e.g. 9200
for ES. Add ES or MDB flags to specify parser.
Shodan/BinaryEdge Options:
–limit , -l Max number of results per query. Default is
500.
–port , -p Filter by port.
–country , -cn Filter by country (two-letter country code).
–terms , -t Enter any additional query terms you want here, e.g.
‘users’
Dump Options:
–mongo, -mdb Use for IP, Shodan, BinaryEdge & Paste methods to
specify parser.
–elastic, -es Use for IP, Shodan, BinaryEdge & Paste methods to
specify parser.
–properjson, -pj Add this flag if would like out put to be proper JSON
file. Default is one JSON string object per line.
–database , -db Specify database you want to grab. For MDB must be in
format format ‘db:collection’. Use with IP arg & ‘es’
or ‘mdb’ flag
–getall, -g Get all indices regardless of fields and
collection/index names (overrides selections in config
file).
–ignorelogs Connect to a server you’ve already checked out.
–nosizelimits, -n Dump index no matter how big it is. Default max doc
count is 800,000.
–csv Convert JSON dumps into CSV format on the fly. (Puts
JSON files in backup folder in case there is issue
with coversion)
CSV/Post-processing Options:
–convertToCSV , -c Convert JSON file or folder of JSON dumps to CSVs
after the fact. Enter full path or folder name in
current working directory
–dontflatten Use if run into memory issues converting JSON files to
CSV during post-processing.
–basic Use with –convertToCSV flag if your JSON dumps are
[...]
* specify what fields you care about: if you only want to grab ES indices that have “email” in a field name, e.g.”user_emails”, you can do that. If you want to make sure the index has at least 2 fields you care about, you can do that too. Or if you just want to grab everything no matter what fields are in there, you can do that too.
* specify what indices you DON’T want e.g., system index names and others that are generally used for basic logging. Examples provided in config file.
* override config and grab everything on a server
* specify output (default is JSON, can choose CSV)
* set minimum and maximum size database script will dump by default and you can set flag to override max docs on case by case basis. Installation and Requirements
* Clone or download to machine
* Get API keys for Shodan and/or BinaryEdge
* configure parameters in ODBconfig.py file
* install requirements from file
I suggest creating virtual environment for ODBParser so have no issues with incorrect module versions. Note: Tested ONLY on Python 3.7.3 and on Windows 10.
PLEASE USE RESPONSIBLY Next Steps and Known Issues
* clean up code a bit more
* multithread various processes.
* expand to other db types
* add other open directory search engines (Zoomeye, etc.)
* unable to scroll past first page for certain ES instances due to way ES <2.0Pretty sure fixed this. Open issue if get scrollid errors
Usage
Examples: python ODBParser.py -cn US -p 8080 -t users –elastic –shodan –csv –limit 100
python ODBParser.py -ip 192.168.2:8080 –mongo –ignorelogs –nosizelimits
Damage to-date: 0 servers parsed | 0 databases dumped | 0 records pulled
optional arguments:
-h, –help show this help message and exit
Query Options:
–shodan, -sh Add this flag if using Shodan. Specify ES or MDB w/
flags.
–binary, -be Add this flag if using BinaryEdge. Specify ES or MDB
w/ flags.
–ip , -ip Query one server. Add port like so ‘192.165.2.1:8080’
or will use default ports for each db type. Add ES or
MDB flags to specify parser.
–file , -f Load line-separated IPs from file. Add port or will
assume default ports for each db type. Add ES or MDB
flags to specify parser.
–paste, -v Query line-separated IPs from clipboard. Add port or
will assume default ports for each db type, e.g. 9200
for ES. Add ES or MDB flags to specify parser.
Shodan/BinaryEdge Options:
–limit , -l Max number of results per query. Default is
500.
–port , -p Filter by port.
–country , -cn Filter by country (two-letter country code).
–terms , -t Enter any additional query terms you want here, e.g.
‘users’
Dump Options:
–mongo, -mdb Use for IP, Shodan, BinaryEdge & Paste methods to
specify parser.
–elastic, -es Use for IP, Shodan, BinaryEdge & Paste methods to
specify parser.
–properjson, -pj Add this flag if would like out put to be proper JSON
file. Default is one JSON string object per line.
–database , -db Specify database you want to grab. For MDB must be in
format format ‘db:collection’. Use with IP arg & ‘es’
or ‘mdb’ flag
–getall, -g Get all indices regardless of fields and
collection/index names (overrides selections in config
file).
–ignorelogs Connect to a server you’ve already checked out.
–nosizelimits, -n Dump index no matter how big it is. Default max doc
count is 800,000.
–csv Convert JSON dumps into CSV format on the fly. (Puts
JSON files in backup folder in case there is issue
with coversion)
CSV/Post-processing Options:
–convertToCSV , -c Convert JSON file or folder of JSON dumps to CSVs
after the fact. Enter full path or folder name in
current working directory
–dontflatten Use if run into memory issues converting JSON files to
CSV during post-processing.
–basic Use with –convertToCSV flag if your JSON dumps are
[...]
Hacking Articles Tips Tricks Videos Tutorials
pt will pull index called “clients” or “client_data.” I recommend you keep these lists blank as you never know what databases you care about will be called and instead specify the fields you care about. * specify what fields you care about: if you only want…
not true JSON files, but rather line separated JSON
objects that you got from other sources.
–dontclean, -dc Choose if want to keep useless data when convert to
CSV. See docs for more info. Download
objects that you got from other sources.
–dontclean, -dc Choose if want to keep useless data when convert to
CSV. See docs for more info. Download
hacking: security in practice
Can someone give me an easy way to find someones username and password
I have minimal knowledge and experience on hacking and I am interested in finding a way to grab someone's username and password. It hasn't been saved anywhere and I do have access to the computer, if that makes a difference
Any help would be appreciated :)
submitted by /u/LforLife11
[link] [comments]
Can someone give me an easy way to find someones username and password
I have minimal knowledge and experience on hacking and I am interested in finding a way to grab someone's username and password. It hasn't been saved anywhere and I do have access to the computer, if that makes a difference
Any help would be appreciated :)
submitted by /u/LforLife11
[link] [comments]
reddit
Can someone give me an easy way to find someones username and password
I have minimal knowledge and experience on hacking and I am interested in finding a way to grab someone's username and password. It hasn't been...
#4 SERVER SIDE TEMPLATE INJECTION ( EASILY FOUND )
https://medium.com/@gandhim373/4-server-side-template-injection-easily-found-d7ca345aa55f?source=rss------bug_bounty-5
https://medium.com/@gandhim373/4-server-side-template-injection-easily-found-d7ca345aa55f?source=rss------bug_bounty-5
Hello Cybersecurity Researchers,Continue reading on Medium » (https://medium.com/@gandhim373/4-server-side-template-injection-easily-found-d7ca345aa55f?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cara menghapus virus trojan paling ampuh
Virus trojan, merupakan salah satu jenis malware yang banyak ditakuti oleh para pengguna komputer maupun handphone. Virus ini cepat sekali…
Continue reading on Medium »
Cara menghapus virus trojan paling ampuh
Virus trojan, merupakan salah satu jenis malware yang banyak ditakuti oleh para pengguna komputer maupun handphone. Virus ini cepat sekali…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
An easy Explanation of Terms related to Networking and Hacking
Hey guys , in previous , blogs we have learnt how to setup kali linux and some basics commands that are mostly used .
Now as most of you…
Continue reading on Medium »
An easy Explanation of Terms related to Networking and Hacking
Hey guys , in previous , blogs we have learnt how to setup kali linux and some basics commands that are mostly used .
Now as most of you…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Username Enumeration using Kerbrute Tool
https://cdn-images-1.medium.com/max/1017/1*iqvDJH-5PZE--_XUw1LFVg.png
In attacking Kerberos the first step is to enumerate the users abusing the Kerberos pre-authetication. If you are not familiar with the…
Continue reading on Medium »
Username Enumeration using Kerbrute Tool
https://cdn-images-1.medium.com/max/1017/1*iqvDJH-5PZE--_XUw1LFVg.png
In attacking Kerberos the first step is to enumerate the users abusing the Kerberos pre-authetication. If you are not familiar with the…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Malware devs trick Windows validation with malformed certs
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Malware devs trick Windows validation with malformed certsPost Views: 153
Reading Time: 1 Minute
Google researchers spotted malware developers creating malformed code signatures seen as valid in Windows to bypass security software.
This tactic is actively used to push OpenSUpdater, a family of unwanted software also known as riskware, which injects ads into victims’ browsers and installs other unwanted programs onto their devices.
Campaigns coordinated by the financially motivated threat actors behind OpenSUpdater will attempt to infect as many devices as possible.
Most targets are from the US and likely interested in downloading game cracks and other potentially booby-trapped tools. Breaking certificate parsing for detection evasionRoughly a month ago, Google Threat Analysis Group (TAG) security researcher Neel Mehta discovered that the developers of an unwanted software known as OpenSUpdater started signing their samples with legitimate but intentionally malformed certificates, accepted by Windows but rejected by OpenSSL.
By breaking certificate parsing for OpenSSL (which won’t be able to decode the digital signatures and check them), the malicious samples would not be detected by some security solutions that use OpenSSL-powered detection rules and allowed to perform their malicious tasks on victims’ PCs.
See Also: Complete Offensive Security and Ethical Hacking Course
“Since mid-August, OpenSUpdater samples have carried an invalid signature, and further investigation showed this was a deliberate attempt to evade detection,” Mehta said.
“Security products using OpenSSL to extract signature information will reject this encoding as invalid.
“However, to a parser that permits these encodings, the digital signature of the binary will otherwise appear legitimate and valid.”
https://www.bleepstatic.com/images/news/u/1109292/2021/OpenSUpdater%20malformed%20signature.png
<figcaptionOpenSUpdater malformed signature parsed as valid (Google TAG)
That last part is what allows OpenSUpdater to bypass security defenses, enabling samples deployed on a victim’s computer will be able to launch without issues.
See Also: Windows MSHTML zero-day defenses bypassed as new info emerges This happens because security solutions that use OpenSSL to parse digital signatures will virtually ignore the samples’ malicious nature because they will reject the signature information as invalid, confusing and breaking the malware scan process.
“Since first discovering this activity, OpenSUpdater’s authors have tried other variations on invalid encodings to further evade detection,” Mehta added.
“This is the first time TAG has observed actors using this technique to evade detection while preserving a valid digital signature on PE files.”
See Also: Offensive Security Tool: SniperPhish After discovering the issue, the Google TAG researcher has also contacted Microsoft to report this detection evasion tactic.
Google TAG is currently working with the Google Safe Browsing team to block this family of unwanted software from further spreading onto other victims’ computers.
The security research also urged Google users to download and install software only from trustworthy sources.
Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-1-90x90.jpg Unpatched Apple Zero-Day in macOS Finder Allows Code Execution23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09[...]
Malware devs trick Windows validation with malformed certs
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Malware devs trick Windows validation with malformed certsPost Views: 153
Reading Time: 1 Minute
Google researchers spotted malware developers creating malformed code signatures seen as valid in Windows to bypass security software.
This tactic is actively used to push OpenSUpdater, a family of unwanted software also known as riskware, which injects ads into victims’ browsers and installs other unwanted programs onto their devices.
Campaigns coordinated by the financially motivated threat actors behind OpenSUpdater will attempt to infect as many devices as possible.
Most targets are from the US and likely interested in downloading game cracks and other potentially booby-trapped tools. Breaking certificate parsing for detection evasionRoughly a month ago, Google Threat Analysis Group (TAG) security researcher Neel Mehta discovered that the developers of an unwanted software known as OpenSUpdater started signing their samples with legitimate but intentionally malformed certificates, accepted by Windows but rejected by OpenSSL.
By breaking certificate parsing for OpenSSL (which won’t be able to decode the digital signatures and check them), the malicious samples would not be detected by some security solutions that use OpenSSL-powered detection rules and allowed to perform their malicious tasks on victims’ PCs.
See Also: Complete Offensive Security and Ethical Hacking Course
“Since mid-August, OpenSUpdater samples have carried an invalid signature, and further investigation showed this was a deliberate attempt to evade detection,” Mehta said.
“Security products using OpenSSL to extract signature information will reject this encoding as invalid.
“However, to a parser that permits these encodings, the digital signature of the binary will otherwise appear legitimate and valid.”
https://www.bleepstatic.com/images/news/u/1109292/2021/OpenSUpdater%20malformed%20signature.png
<figcaptionOpenSUpdater malformed signature parsed as valid (Google TAG)
That last part is what allows OpenSUpdater to bypass security defenses, enabling samples deployed on a victim’s computer will be able to launch without issues.
See Also: Windows MSHTML zero-day defenses bypassed as new info emerges This happens because security solutions that use OpenSSL to parse digital signatures will virtually ignore the samples’ malicious nature because they will reject the signature information as invalid, confusing and breaking the malware scan process.
“Since first discovering this activity, OpenSUpdater’s authors have tried other variations on invalid encodings to further evade detection,” Mehta added.
“This is the first time TAG has observed actors using this technique to evade detection while preserving a valid digital signature on PE files.”
See Also: Offensive Security Tool: SniperPhish After discovering the issue, the Google TAG researcher has also contacted Microsoft to report this detection evasion tactic.
Google TAG is currently working with the Google Safe Browsing team to block this family of unwanted software from further spreading onto other victims’ computers.
The security research also urged Google users to download and install software only from trustworthy sources.
Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-1-90x90.jpg Unpatched Apple Zero-Day in macOS Finder Allows Code Execution23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Offensive Security Tool: Discover
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Offensive Security Tool: DiscoverPost Views: 30 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 4 Minutes
Offensive Security Tool: Discover GitHub Link DiscoverDiscover by Leebaird, is a set of custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit. This sets of tool covers a lot of steps from recon, osint to payload generation, passive and active scans as part of a workflow that you can integrate in your methodology to get things done real fast. Download, setup and usage* git clone https://github.com/leebaird/discover /opt/discover/
* All scripts must be ran from this location.
* cd /opt/discover/
* ./update.sh
See Also: Malware devs trick Windows validation with malformed certs
RECON
1. Domain
2. Person
SCANNING
3. Generate target list
4. CIDR
5. List
6. IP, range, or domain
7. Rerun Nmap scripts and MSF aux
WEB
8. Insecure direct object reference
9. Open multiple tabs in Firefox
10. Nikto
11. SSL
MISC
12. Parse XML
13. Generate a malicious payload
14. Start a Metasploit listener
15. Update
16. Exit RECONDomainRECON
1. Passive
2. Active
3. Import names into an existing recon-ng workspace
4. Previous menu
Passive uses ARIN, dnsrecon, goofile, goog-mail, goohost, theHarvester, Metasploit, URLCrazy, Whois, multiple websites, and recon-ng.
Active uses dnsrecon, WAF00W, traceroute, Whatweb, and recon-ng.
[*] Acquire API keys for Bing, Builtwith, Fullcontact, GitHub, Google, Hashes, Hunter, SecurityTrails, and Shodan for maximum results with recon-ng and theHarvester.
API key locations:
recon-ng
show keys
keys add bing_api <value
theHarvester
/opt/theHarvester/api-keys.yaml PersonRECON
First name:
Last name:
* Combines info from multiple websites.
See Also: Hacking stories – The first botnet hijacker aka the Zombie King SCANNINGGenerate target listSCANNING
1. Local area network
2. NetBIOS
3. netdiscover
4. Ping sweep
5. Previous menu
* Use different tools to create a target list including Angry IP Scanner, arp-scan, netdiscover, and nmap pingsweep. CIDR, List, IP, Range or URLType of scan:
1. External
2. Internal
3. Previous menu
* External scan will set the nmap source port to 53 and the max-rrt-timeout to 1500ms.
* Internal scan will set the nmap source port to 88 and the max-rrt-timeout to 500ms.
* Nmap is used to perform host discovery, port scanning, service enumeration and OS identification.
* Matching nmap scripts are used for additional enumeration.
* Addition tools: enum4linux, smbclient, and ike-scan.
* Matching Metasploit auxiliary modules are also leveraged. WEBInsecure direct object referenceUsing Burp, authenticate to a site, map & Spider, then log out.
Target > Site map > select the URL > right click > Copy URLs in this host.
Paste the results into a new file.
Enter the location of your file: Open multiple tabs in FirefoxOpen multiple tabs in Firefox with:
1. List
2. Directories from robots.txt
3. Previous menu
* Use a list containing IPs and/or URLs.
* Use wget to pull a domain’s robot.txt file, then open all of the directories. NiktoRun multiple instances of Nikto in parallel.
1. List of IPs
2. List of IP:port
3. Previous menu SSLCheck for SSL certificate issues.
Enter the location of your list:
* Use sslscan and sslyze to check for SSL/TLS certificate issues. MISCParse XMLParse XML to CSV
1. Burp (Base64)
2. N[...]
Offensive Security Tool: Discover
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Offensive Security Tool: DiscoverPost Views: 30 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 4 Minutes
Offensive Security Tool: Discover GitHub Link DiscoverDiscover by Leebaird, is a set of custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit. This sets of tool covers a lot of steps from recon, osint to payload generation, passive and active scans as part of a workflow that you can integrate in your methodology to get things done real fast. Download, setup and usage* git clone https://github.com/leebaird/discover /opt/discover/
* All scripts must be ran from this location.
* cd /opt/discover/
* ./update.sh
See Also: Malware devs trick Windows validation with malformed certs
RECON
1. Domain
2. Person
SCANNING
3. Generate target list
4. CIDR
5. List
6. IP, range, or domain
7. Rerun Nmap scripts and MSF aux
WEB
8. Insecure direct object reference
9. Open multiple tabs in Firefox
10. Nikto
11. SSL
MISC
12. Parse XML
13. Generate a malicious payload
14. Start a Metasploit listener
15. Update
16. Exit RECONDomainRECON
1. Passive
2. Active
3. Import names into an existing recon-ng workspace
4. Previous menu
Passive uses ARIN, dnsrecon, goofile, goog-mail, goohost, theHarvester, Metasploit, URLCrazy, Whois, multiple websites, and recon-ng.
Active uses dnsrecon, WAF00W, traceroute, Whatweb, and recon-ng.
[*] Acquire API keys for Bing, Builtwith, Fullcontact, GitHub, Google, Hashes, Hunter, SecurityTrails, and Shodan for maximum results with recon-ng and theHarvester.
API key locations:
recon-ng
show keys
keys add bing_api <value
theHarvester
/opt/theHarvester/api-keys.yaml PersonRECON
First name:
Last name:
* Combines info from multiple websites.
See Also: Hacking stories – The first botnet hijacker aka the Zombie King SCANNINGGenerate target listSCANNING
1. Local area network
2. NetBIOS
3. netdiscover
4. Ping sweep
5. Previous menu
* Use different tools to create a target list including Angry IP Scanner, arp-scan, netdiscover, and nmap pingsweep. CIDR, List, IP, Range or URLType of scan:
1. External
2. Internal
3. Previous menu
* External scan will set the nmap source port to 53 and the max-rrt-timeout to 1500ms.
* Internal scan will set the nmap source port to 88 and the max-rrt-timeout to 500ms.
* Nmap is used to perform host discovery, port scanning, service enumeration and OS identification.
* Matching nmap scripts are used for additional enumeration.
* Addition tools: enum4linux, smbclient, and ike-scan.
* Matching Metasploit auxiliary modules are also leveraged. WEBInsecure direct object referenceUsing Burp, authenticate to a site, map & Spider, then log out.
Target > Site map > select the URL > right click > Copy URLs in this host.
Paste the results into a new file.
Enter the location of your file: Open multiple tabs in FirefoxOpen multiple tabs in Firefox with:
1. List
2. Directories from robots.txt
3. Previous menu
* Use a list containing IPs and/or URLs.
* Use wget to pull a domain’s robot.txt file, then open all of the directories. NiktoRun multiple instances of Nikto in parallel.
1. List of IPs
2. List of IP:port
3. Previous menu SSLCheck for SSL certificate issues.
Enter the location of your list:
* Use sslscan and sslyze to check for SSL/TLS certificate issues. MISCParse XMLParse XML to CSV
1. Burp (Base64)
2. N[...]