Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CVSS
https://cdn-images-1.medium.com/max/662/1*Ew5xZ4ttA2lPwsEX2lmgpg.png
Common Vulnerability Scoring System
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CVSS
https://cdn-images-1.medium.com/max/662/1*Ew5xZ4ttA2lPwsEX2lmgpg.png
Common Vulnerability Scoring System
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVSS
Common Vulnerability Scoring System
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cronos — HackTheBox WriteUp
https://cdn-images-1.medium.com/max/936/1*_qmPkudKwlr9tS8L_u6fIw.png
Hello and welcome to my article about Cronos machine in HTB.
My name is Idan and I am a penetration tester / red teamer.
Also, I am Linux…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cronos — HackTheBox WriteUp
https://cdn-images-1.medium.com/max/936/1*_qmPkudKwlr9tS8L_u6fIw.png
Hello and welcome to my article about Cronos machine in HTB.
My name is Idan and I am a penetration tester / red teamer.
Also, I am Linux…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cronos — HackTheBox WriteUp
Hello and welcome to my article about Cronos machine in HTB. My name is Idan and I am a penetration tester / red teamer. Also, I am Linux…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Stealthier zloader variant spreading via pretend teamviewer transfer ads!!
https://cdn-images-1.medium.com/max/768/0*UpauvKMAupyR6WqC
Author-Prabhjot Kaur
Continue reading on rootissh »
___________________________
@hacking_Attack
@Hacking_Video
Stealthier zloader variant spreading via pretend teamviewer transfer ads!!
https://cdn-images-1.medium.com/max/768/0*UpauvKMAupyR6WqC
Author-Prabhjot Kaur
Continue reading on rootissh »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Stealthier zloader variant spreading via pretend teamviewer transfer ads!!
Author-Prabhjot Kaur
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers exploiting critical VMware vCenter CVE-2021-22005 bug
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Hackers exploiting critical VMware vCenter CVE-2021-22005 bugPost Views: 172
Reading Time: 1 Minute
Exploit code that could be used for remote code execution on VMware vCenter Server vulnerable to CVE-2021-22005 has been released today and attackers are already using it.
Publicly disclosed earlier this week when VMware also addressed it, the bug comes with a critical severity rating of 9.8 and a strong recommendation to install the available patch. Attacks have startedThe vulnerability affects machines running vCenter Server versions 6.7, and 7.0. Given the severity of the issue, VMware urges administrators to act immediately under the assumption that an adversary is already on the network, ready to take advantage.
Exposed vCenter servers are currently being targeted from various countries over multiple ports, threat intelligence company Bad Packets shared with BleepingComputer today; VMware confirmed this in an update to their security advisory for CVE-2021-22005, an arbitrary file upload vulnerability:
“VMware has confirmed reports that CVE-2021-22005 is being exploited in the wild”
Data recorded by Bad Packets shows attacks starting to hit their VMware honeypots at 16:21 (GMT) originating from Canada, the U.S., Romania, the Netherlands, China, and Singapore.
See Also: Complete Offensive Security and Ethical Hacking Course
Signs of these attacks coming were seen shortly after VMware disclosed the security issue and released a patch. Just hours later, Bad Packets saw scanning activity targeting CVE-2021-22005. The spark for the exploitTroy Mursch, chief research officer at Bad Packets, told BleepingComputer that the attacks he saw against the company honeypots used code based on an incomplete exploit released earlier today by Vietnamese security researcher Jang.
Jang published technical notes for CVE-2021-22005 based on the workaround and the patch from VMware. The details are enough for experienced developers to create a working exploit that allows remote code execution with root privileges, the researcher told BleepingComputer.
At the end of the post, Jang also provides a link to his PoC version for CVE-2021-22005. It is not a fully functional variant, though, intentionally so to prevent less skilled threat actors from using it in attacks directly.
The researcher told us that in its current form the code does no harm because it is missing the important part leading to remote code execution.
An adversary would have to put in some effort to turn it into a full-fledged exploit but they should be able to create an exploit that is 100% reliable.
See Also: Windows MSHTML zero-day defenses bypassed as new info emerges Penetration tester and Synack Envoy Nicolas Krassas tested the code and confirmed that it needs some modifications to work properly. But it does prove that CVE-2021-22005 can be used to create a backdoor on a vulnerable system. Attacks were imminentJang built a fully functional exploit and tested it in a controlled environment. He said that it works just fine, obtaining remote code execution before detection can catch it.
Currently, search engines for internet-connected devices show thousands of VMware vCenter Server instances exposed to the public internet. Shodan retrieved more than 5,000 machines while a rough search on Censys shows around 6,800.
https://www.bleepstatic.com/images/news/u/1100723/2021/Vulnerabilities/censys_vmware-1-1024x603.png
___________________________
@hacking_Attack
@Hacking_Video
Hackers exploiting critical VMware vCenter CVE-2021-22005 bug
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Hackers exploiting critical VMware vCenter CVE-2021-22005 bugPost Views: 172
Reading Time: 1 Minute
Exploit code that could be used for remote code execution on VMware vCenter Server vulnerable to CVE-2021-22005 has been released today and attackers are already using it.
Publicly disclosed earlier this week when VMware also addressed it, the bug comes with a critical severity rating of 9.8 and a strong recommendation to install the available patch. Attacks have startedThe vulnerability affects machines running vCenter Server versions 6.7, and 7.0. Given the severity of the issue, VMware urges administrators to act immediately under the assumption that an adversary is already on the network, ready to take advantage.
Exposed vCenter servers are currently being targeted from various countries over multiple ports, threat intelligence company Bad Packets shared with BleepingComputer today; VMware confirmed this in an update to their security advisory for CVE-2021-22005, an arbitrary file upload vulnerability:
“VMware has confirmed reports that CVE-2021-22005 is being exploited in the wild”
Data recorded by Bad Packets shows attacks starting to hit their VMware honeypots at 16:21 (GMT) originating from Canada, the U.S., Romania, the Netherlands, China, and Singapore.
See Also: Complete Offensive Security and Ethical Hacking Course
Signs of these attacks coming were seen shortly after VMware disclosed the security issue and released a patch. Just hours later, Bad Packets saw scanning activity targeting CVE-2021-22005. The spark for the exploitTroy Mursch, chief research officer at Bad Packets, told BleepingComputer that the attacks he saw against the company honeypots used code based on an incomplete exploit released earlier today by Vietnamese security researcher Jang.
Jang published technical notes for CVE-2021-22005 based on the workaround and the patch from VMware. The details are enough for experienced developers to create a working exploit that allows remote code execution with root privileges, the researcher told BleepingComputer.
At the end of the post, Jang also provides a link to his PoC version for CVE-2021-22005. It is not a fully functional variant, though, intentionally so to prevent less skilled threat actors from using it in attacks directly.
The researcher told us that in its current form the code does no harm because it is missing the important part leading to remote code execution.
An adversary would have to put in some effort to turn it into a full-fledged exploit but they should be able to create an exploit that is 100% reliable.
See Also: Windows MSHTML zero-day defenses bypassed as new info emerges Penetration tester and Synack Envoy Nicolas Krassas tested the code and confirmed that it needs some modifications to work properly. But it does prove that CVE-2021-22005 can be used to create a backdoor on a vulnerable system. Attacks were imminentJang built a fully functional exploit and tested it in a controlled environment. He said that it works just fine, obtaining remote code execution before detection can catch it.
Currently, search engines for internet-connected devices show thousands of VMware vCenter Server instances exposed to the public internet. Shodan retrieved more than 5,000 machines while a rough search on Censys shows around 6,800.
https://www.bleepstatic.com/images/news/u/1100723/2021/Vulnerabilities/censys_vmware-1-1024x603.png
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Hackers exploiting critical VMware vCenter CVE-2021-22005 bug | Black Hat Ethical Hacking
Google researchers spotted malware developers creating malformed code signatures seen as valid in Windows to bypass security software.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers exploiting critical VMware vCenter CVE-2021-22005 bug https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Hackers exploiting critical VMware vCenter CVE-2021-22005 bugPost Views: 172…
otes that 3,264 of these internet-facing hosts are “are potentially vulnerable” and 436 are patched.
Still the number of potential targets is quite high and given the threat actors’ early interest in scanning for vulnerable machines it is easy to conclude that attacks were imminent.
Talking to BleepingComputer about his incomplete exploit, Jang said that an average-skilled adversary should need about an hour to build a working, reliable version. He strongly advises administrators to patch their systems to defend against attacks leveraging CVE-2021-22005.
See Also: Offensive Security Tool: Discover The U.S. Cybersecurity and Infrastructure Seurity Agency (CISA) urges critical infrastructrure organizations with vulnerable vCenter deployments to apply the updates or the termporary workaround from VMware.
A post from Censys explains that a remote code execution exploit is not difficult to create based on the technical details already published in the public space:
“The cURL-based exploit in blog post does not demonstrate direct code execution, although a savvy reader can use the information in this post to achieve this goal with some knowledge of the Linux operating system. Censys has decided to release this detail, given that opportunistic scanning is already taking place, and VMware’s workaround mentions the specific vulnerable endpoint.”
The researcher also published a video to demonstrate how an attacker could exploit the vulnerability:
Update [September 24, 2021 – 17:41 EST]: Shortly after publishing, BleepingComputer learned that hackers have started to exploit CVE-2021-22005 using code released by security researcher Jang. We have updated the article with information about the attacks.
Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/malware-800x449-1-90x90.jpg Malware devs trick Windows validation with malformed certs3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-1-90x90.jpg Unpatched Apple Zero-Day in macOS Finder Allows Code Execution4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-90x90.jpg New macOS zero-day bug lets attackers run commands remotely5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Windows-attack-90x90.jpg Hacked sites push TeamViewer using fake expired certificate alert6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/hackers-waging-living-off-land-attacks-on-azure-showcase_image-7-a-16158-90x90.jpg Azure Zero-Day Flaws Highlight Lurking Supply-Chain Risk1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Anonymous-90x90.png Anonymous leaks gigabytes of data from alt-right web host Epik1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-90x90.jpg New malware uses Windows Subsystem for Linux for stealthy attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Google-Chrome-Browser-90x90.jpg Pair of Google Chrome Zero-Day Bugs Actively Exploited2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/banner-2021.3-release-90x90.jpg Kali Linux 2021.3 released: Kali NetHunter on a smartwatch, wider OpenSSL compatibility, new tools2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/microsoft-exploit-90x90.jpg Microsoft Patches Actively Exploited Windows Zero-Day Bug2 weeks ago
The post Hackers exploiting critical VMware vCenter CVE-2021-22005 bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Still the number of potential targets is quite high and given the threat actors’ early interest in scanning for vulnerable machines it is easy to conclude that attacks were imminent.
Talking to BleepingComputer about his incomplete exploit, Jang said that an average-skilled adversary should need about an hour to build a working, reliable version. He strongly advises administrators to patch their systems to defend against attacks leveraging CVE-2021-22005.
See Also: Offensive Security Tool: Discover The U.S. Cybersecurity and Infrastructure Seurity Agency (CISA) urges critical infrastructrure organizations with vulnerable vCenter deployments to apply the updates or the termporary workaround from VMware.
A post from Censys explains that a remote code execution exploit is not difficult to create based on the technical details already published in the public space:
“The cURL-based exploit in blog post does not demonstrate direct code execution, although a savvy reader can use the information in this post to achieve this goal with some knowledge of the Linux operating system. Censys has decided to release this detail, given that opportunistic scanning is already taking place, and VMware’s workaround mentions the specific vulnerable endpoint.”
The researcher also published a video to demonstrate how an attacker could exploit the vulnerability:
Update [September 24, 2021 – 17:41 EST]: Shortly after publishing, BleepingComputer learned that hackers have started to exploit CVE-2021-22005 using code released by security researcher Jang. We have updated the article with information about the attacks.
Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/malware-800x449-1-90x90.jpg Malware devs trick Windows validation with malformed certs3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-1-90x90.jpg Unpatched Apple Zero-Day in macOS Finder Allows Code Execution4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-90x90.jpg New macOS zero-day bug lets attackers run commands remotely5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Windows-attack-90x90.jpg Hacked sites push TeamViewer using fake expired certificate alert6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/hackers-waging-living-off-land-attacks-on-azure-showcase_image-7-a-16158-90x90.jpg Azure Zero-Day Flaws Highlight Lurking Supply-Chain Risk1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Anonymous-90x90.png Anonymous leaks gigabytes of data from alt-right web host Epik1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-90x90.jpg New malware uses Windows Subsystem for Linux for stealthy attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Google-Chrome-Browser-90x90.jpg Pair of Google Chrome Zero-Day Bugs Actively Exploited2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/banner-2021.3-release-90x90.jpg Kali Linux 2021.3 released: Kali NetHunter on a smartwatch, wider OpenSSL compatibility, new tools2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/microsoft-exploit-90x90.jpg Microsoft Patches Actively Exploited Windows Zero-Day Bug2 weeks ago
The post Hackers exploiting critical VMware vCenter CVE-2021-22005 bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Host Header Injection On Password Reset Functionality An Easy #P2
This article is about a vulnerability I was able to find in the BugCrowd private program.Continue reading on Medium »
Read more...
This article is about a vulnerability I was able to find in the BugCrowd private program.Continue reading on Medium »
Read more...
What is the Bug bounty ?
Often translated into French as “prime au bogue” or “bounty for the detected flaw”, the bug bounty appeared in the 90s…Continue reading on Medium »
Read more...
Often translated into French as “prime au bogue” or “bounty for the detected flaw”, the bug bounty appeared in the 90s…Continue reading on Medium »
Read more...
Polysynth Bug Bounty
Earn up to 500,000 POL Tokens for finding bugsContinue reading on Medium »
Read more...
Earn up to 500,000 POL Tokens for finding bugsContinue reading on Medium »
Read more...
Bypass of biometrics & password security functionality for Android
Reported : Sat, Feb 27, 8:52 PM — 2020 Reported Again : Mon, Nov 2, 2020, 3:12 AM Req for an update : Sat, Nov 7, 2020, 10:02 AM Another…Continue reading on Medium »
Read more...
Reported : Sat, Feb 27, 8:52 PM — 2020 Reported Again : Mon, Nov 2, 2020, 3:12 AM Req for an update : Sat, Nov 7, 2020, 10:02 AM Another…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Image File Execution Options Injection
I've been reading about https://attack.mitre.org/techniques/T1546/012/
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers. IFEOs enable a developer to attach a debugger to an application. When a process is created, a debugger present in an application’s IFEO will be prepended to the application’s name, effectively launching the new process under the debugger
e.g.,
C:\dbg\ntsd.exe -g notepad.exe
Few questions:
Can adversaries execute malware undetected using this technique?
e.g.
If yes, does that mean that ntsd.exe pose a risk and should be blocked?
I would like to test this, but how do I get ntsd.exe? I don't see this in Ms Windows.
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Image File Execution Options Injection
I've been reading about https://attack.mitre.org/techniques/T1546/012/
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers. IFEOs enable a developer to attach a debugger to an application. When a process is created, a debugger present in an application’s IFEO will be prepended to the application’s name, effectively launching the new process under the debugger
e.g.,
C:\dbg\ntsd.exe -g notepad.exe
Few questions:
Can adversaries execute malware undetected using this technique?
e.g.
C:\dbg\ntsd.exe -g malware.exe If yes, does that mean that ntsd.exe pose a risk and should be blocked?
I would like to test this, but how do I get ntsd.exe? I don't see this in Ms Windows.
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Image File Execution Options Injection
I've been reading about [https://attack.mitre.org/techniques/T1546/012/](https://attack.mitre.org/techniques/T1546/012/) >Adversaries may...
Cloudquery - Transforms Your Cloud Infrastructure Into SQL Database For Easy Monitoring, Governance And Security
http://www.kitploit.com/2021/09/cloudquery-transforms-your-cloud.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/cloudquery-transforms-your-cloud.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Cloudquery - Transforms Your Cloud Infrastructure Into SQL Database For Easy Monitoring, Governance And Security
What is CloudQuery and why use it?
CloudQuery pulls, normalize, expose and monitor your cloud infrastructure and SaaS apps as SQL database. This abstracts various scattered APIs enabling you to define security, governance, cost and compliance (https://www.kitploit.com/search/label/Compliance) policies with SQL. CloudQuery can be easily extended to more resources and SaaS providers (open an Issue (https://github.com/cloudquery/cloudquery/issues)). CloudQuery comes with built-in policy packs such as: AWS CIS (https://github.com/cloudquery/cloudquery#running-policy-packs) (more is coming!). Think about CloudQuery as a compliance-as-code tool inspired by tools like osquery (https://github.com/osquery/osquery) and terraform (https://github.com/hashicorp/terraform), cool right?
Links
Homepage: https://cloudquery.io (https://cloudquery.io/) Releases: https://github.com/cloudquery/cloudquery/releases Documentation: https://docs.cloudquery.io (https://docs.cloudquery.io/) Hub (Provider and schema docs): https://hub.cloudquery.io/
Supported providers (Actively expanding)
Checkout https://hub.cloudquery.io (https://hub.cloudquery.io/) If you want us to add a new provider or resource please open an Issue (https://github.com/cloudquery/cloudquery/issues). See docs (https://docs.cloudquery.io/developers/developing-new-provider) for developing new provider.
Download & install
You can download the precompiled binary (https://www.kitploit.com/search/label/Binary) from releases (https://github.com/cloudquery/cloudquery/releases), or using CLI: export OS=Darwin # Possible values: Linux,Windows,Darwin
curl -L https://github.com/cloudquery/cloudquery/releases/latest/download/cloudquery_${OS}_x86_64 -o cloudquery
chmod a+x cloudquery
./cloudquery --help
# if you want to download a specific version and not latest use the following endpoint
export VERSION= # specifiy a version
curl -L https://github.com/cloudquery/cloudquery/releases/download/${VERSION}/cloudquery_${OS}_x86_64 -o cloudquery Homebrew brew install cloudquery/tap/cloudquery
# After initial install you can upgrade the version via:
brew upgrade cloudquery
Quick Start
Running
First generate a config.hcl file that will describe which resources you want cloudquery to pull, normalize and transform resources to the specified SQL database by running the following command: azure gcp okta] # cloudquery init gcp azure # This will generate a config containing gcp and azure providers # cloudquery init --help # Show all possible auto generated configs and flags ">cloudquery init aws # choose one or more from: [aws azure gcp okta]
# cloudquery init gcp azure # This will generate a config containing gcp and azure providers
# cloudquery init --help # Show all possible auto generated configs and flags Once your config.hcl is generated run the following command to fetch the resources: # you can spawn a local postgresql with docker
# docker run -p 5432:5432 -e POSTGRES_PASSWORD=pass -d postgres
cloudquery fetch --dsn "postgres://postgres:pass@localhost:5432/postgres"
# cloudquery fetch --help # Show all possible fetch flags Using psql -h localhost -p 5432 -U postgres -d postgres postgres=# \dt
List of relations
Schema | Name | Type | Owner
--------+-------------------------------------------------------------+-------+----------
public | aws_autoscaling_launch_configuration_block_device_mapping | table | postgres
public | aws_autoscaling_launch_configurations | table | postgres Run the following example queries from psql shell List ec2_images SELECT * FROM aws_ec2_images; Find all public facing AWS load balancers SELECT * FROM aws_elbv2_load_balancers WHERE scheme = 'internet-facing';
Running policy packs
___________________________
@hacking_Attack
@Hacking_Video
CloudQuery pulls, normalize, expose and monitor your cloud infrastructure and SaaS apps as SQL database. This abstracts various scattered APIs enabling you to define security, governance, cost and compliance (https://www.kitploit.com/search/label/Compliance) policies with SQL. CloudQuery can be easily extended to more resources and SaaS providers (open an Issue (https://github.com/cloudquery/cloudquery/issues)). CloudQuery comes with built-in policy packs such as: AWS CIS (https://github.com/cloudquery/cloudquery#running-policy-packs) (more is coming!). Think about CloudQuery as a compliance-as-code tool inspired by tools like osquery (https://github.com/osquery/osquery) and terraform (https://github.com/hashicorp/terraform), cool right?
Links
Homepage: https://cloudquery.io (https://cloudquery.io/) Releases: https://github.com/cloudquery/cloudquery/releases Documentation: https://docs.cloudquery.io (https://docs.cloudquery.io/) Hub (Provider and schema docs): https://hub.cloudquery.io/
Supported providers (Actively expanding)
Checkout https://hub.cloudquery.io (https://hub.cloudquery.io/) If you want us to add a new provider or resource please open an Issue (https://github.com/cloudquery/cloudquery/issues). See docs (https://docs.cloudquery.io/developers/developing-new-provider) for developing new provider.
Download & install
You can download the precompiled binary (https://www.kitploit.com/search/label/Binary) from releases (https://github.com/cloudquery/cloudquery/releases), or using CLI: export OS=Darwin # Possible values: Linux,Windows,Darwin
curl -L https://github.com/cloudquery/cloudquery/releases/latest/download/cloudquery_${OS}_x86_64 -o cloudquery
chmod a+x cloudquery
./cloudquery --help
# if you want to download a specific version and not latest use the following endpoint
export VERSION= # specifiy a version
curl -L https://github.com/cloudquery/cloudquery/releases/download/${VERSION}/cloudquery_${OS}_x86_64 -o cloudquery Homebrew brew install cloudquery/tap/cloudquery
# After initial install you can upgrade the version via:
brew upgrade cloudquery
Quick Start
Running
First generate a config.hcl file that will describe which resources you want cloudquery to pull, normalize and transform resources to the specified SQL database by running the following command: azure gcp okta] # cloudquery init gcp azure # This will generate a config containing gcp and azure providers # cloudquery init --help # Show all possible auto generated configs and flags ">cloudquery init aws # choose one or more from: [aws azure gcp okta]
# cloudquery init gcp azure # This will generate a config containing gcp and azure providers
# cloudquery init --help # Show all possible auto generated configs and flags Once your config.hcl is generated run the following command to fetch the resources: # you can spawn a local postgresql with docker
# docker run -p 5432:5432 -e POSTGRES_PASSWORD=pass -d postgres
cloudquery fetch --dsn "postgres://postgres:pass@localhost:5432/postgres"
# cloudquery fetch --help # Show all possible fetch flags Using psql -h localhost -p 5432 -U postgres -d postgres postgres=# \dt
List of relations
Schema | Name | Type | Owner
--------+-------------------------------------------------------------+-------+----------
public | aws_autoscaling_launch_configuration_block_device_mapping | table | postgres
public | aws_autoscaling_launch_configurations | table | postgres Run the following example queries from psql shell List ec2_images SELECT * FROM aws_ec2_images; Find all public facing AWS load balancers SELECT * FROM aws_elbv2_load_balancers WHERE scheme = 'internet-facing';
Running policy packs
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
cloudquery comes with some ready compliance policy pack which you can use as is or modify to fit your use-case. Currently, cloudquery support AWS CIS (https://d0.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf) policy pack (it is under active development, so it doesn't cover the whole spec yet). To run AWS CIS pack enter the following commands (make sure you fetched all the resources beforehand by the fetch command): --output= --dsn "postgres://postgres:pass@localhost:5432/postgres" '>./cloudquery policy --path= --output= --dsn "postgres://postgres:pass@localhost:5432/postgres" You can also create your own policy file. E.g.: CREATE VIEW my_custom_view AS ... queries: - name: "Find thing that violates policy" query: > SELECT account_id, arn FROM ... '>views:
- name: "my_custom_view"
query: >
CREATE VIEW my_custom_view AS ...
queries:
- name: "Find thing that violates policy"
query: >
SELECT account_id, arn FROM ... The policy command uses the policy file path ./policy.yml by default, but this can be overridden via the --path flag, or the CQ_POLICY_PATH environment variable. Full Documentation, resources and SQL schema definitions are available here (https://hub.cloudquery.io/).
Providers Authentication
See additional documentation for each provider at https://hub.cloudquery.io (https://hub.cloudquery.io/).
Compile and run
go build .
./cloudquery # --help to see all options
Running on AWS (Lambda, Terraform)
Checkout cloudquery/terraform-aws-cloudquery (https://github.com/cloudquery/terraform-aws-cloudquery)
License
By contributing to cloudquery you agree that your contributions will be licensed as defined on the LICENSE file.
Hiring
If you are into Go, Backend, Cloud, GCP, AWS - ping us at jobs [at] our domain
Contribution
Feel free to open Pull-Request for small fixes and changes. For bigger changes and new providers please open an issue first to prevent double work and discuss relevant stuff.
Download Cloudquery (https://github.com/cloudquery/cloudquery)
___________________________
@hacking_Attack
@Hacking_Video
- name: "my_custom_view"
query: >
CREATE VIEW my_custom_view AS ...
queries:
- name: "Find thing that violates policy"
query: >
SELECT account_id, arn FROM ... The policy command uses the policy file path ./policy.yml by default, but this can be overridden via the --path flag, or the CQ_POLICY_PATH environment variable. Full Documentation, resources and SQL schema definitions are available here (https://hub.cloudquery.io/).
Providers Authentication
See additional documentation for each provider at https://hub.cloudquery.io (https://hub.cloudquery.io/).
Compile and run
go build .
./cloudquery # --help to see all options
Running on AWS (Lambda, Terraform)
Checkout cloudquery/terraform-aws-cloudquery (https://github.com/cloudquery/terraform-aws-cloudquery)
License
By contributing to cloudquery you agree that your contributions will be licensed as defined on the LICENSE file.
Hiring
If you are into Go, Backend, Cloud, GCP, AWS - ping us at jobs [at] our domain
Contribution
Feel free to open Pull-Request for small fixes and changes. For bigger changes and new providers please open an issue first to prevent double work and discuss relevant stuff.
Download Cloudquery (https://github.com/cloudquery/cloudquery)
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pubg 1.6 ConfIg anti ban file.
Pubg 1.6 ConfIg anti ban file.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pubg 1.6 ConfIg anti ban file.
Pubg 1.6 ConfIg anti ban file.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pubg 1.6 ConfIg anti ban file.
Pubg 1.6 ConfIg anti ban file.