Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
This is a collection of tools you may like if you are interested on reverse engineering (https://www.kitploit.com/search/label/Reverse%20Engineering) and/or malware analysis (https://www.kitploit.com/search/label/Malware%20Analysis) on x86 and x64 Windows systems. After installing this toolkit you'll have a folder in your desktop (https://www.kitploit.com/search/label/Desktop) with shortcuts to RE tools like these:
Why do I need it?
You don't. Obviously, you can download such tools from their own website and install them by yourself in a new VM. But if you download retoolkit, it can probably save you some time. Additionally, the tools come pre-configured so you'll find things like x64dbg with a few plugins, command-line tools working from any directory, etc. You may like it if you're setting up a new analysis (https://www.kitploit.com/search/label/Analysis) VM.
Download
The *.iss files you see here are the source code for our setup program built with Inno Setup (https://jrsoftware.org/isinfo.php). To download the real thing, you have to go to the Releases (https://github.com/mentebinaria/retoolkit/releases) section and download the setup program.
Included tools
Check the wiki (https://github.com/mentebinaria/retoolkit/wiki).
Is it safe to install it in my environment?
I don't know. Some included tools are not open source and come from shady places. You should use it exclusively in virtual machines and under your own responsibility.
Can you add tool X?
It depends. The idea is to keep it simple. We won't add a tool just because it's not here yet. But if you think there's a good reason to do so, and the license allows us to redistribuite the software, please file a request here (https://github.com/mentebinaria/retoolkit/discussions/categories/new-app-requests).

Download Retoolkit (https://github.com/mentebinaria/retoolkit)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Retoolkit - Reverse Engineer's Toolkit

https://1.bp.blogspot.com/-h3zUjXIqD94/YFevZ6TF4kI/AAAAAAAAVq4/ctwJfCSMdOwOMd9c922fgZketTQKRHJMACNcBGAsYHQ/w640-h506/retoolkit_1_ret2021c.png
This is a collection of tools you may like if you are interested on reverse engineering and/or malware analysis on x86 and x64 Windows systems. After installing this toolkit you'll have a folder in your desktop with shortcuts to RE tools like these:
Why do I need it?

You don't. Obviously, you can download such tools from their own website and install them by yourself in a new VM. But if you download retoolkit, it can probably save you some time. Additionally, the tools come pre-configured so you'll find things like x64dbg with a few plugins, command-line tools working from any directory, etc. You may like it if you're setting up a new analysis VM.

Download

The *.iss files you see here are the source code for our setup program built with Inno Setup. To download the real thing, you have to go to the Releases section and download the setup program.

Included tools

Check the wiki.
https://1.bp.blogspot.com/-4oetWUTvvmY/YFeveotNrtI/AAAAAAAAVq8/JbNuiFxOQcYG4uJFB8aYsnU46lYQVL8hQCNcBGAsYHQ/w640-h498/retoolkit_2_ret.gif
Is it safe to install it in my environment?

I don't know. Some included tools are not open source and come from shady places. You should use it exclusively in virtual machines and under your own responsibility.

Can you add tool X?

It depends. The idea is to keep it simple. We won't add a tool just because it's not here yet. But if you think there's a good reason to do so, and the license allows us to redistribuite the software, please file a request here.
Download Retoolkit
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Offers Up To $30K For Teams Bugs

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Offers Up To $30K For Teams BugsPost Views: 116
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
A bug-bounty program launched for the Teams desktop video-conferencing and collaboration application has big payouts for finding security holes.
Microsoft wants to send the message the company is serious about the security of its popular Teams desktop application and it’s willing to put some cash behind the talk. A new bug-bounty program offers up to $30,000 for security vulnerabilities, with top payouts going to those with the most potential to expose Teams user data.

“The Teams desktop client is the first in-scope application under the new Apps Bounty Program, we look forward to sharing updates as we bring additional apps into this bounty program scope,” the program manager Lynn Miyashita said in her statement about the launch.
See Also: Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws Researchers can claim five scenario-based awards under the new Apps Bounty Program, ranging from $6,000 to $30,000, with the highest payouts available for “vulnerabilities that have the highest potential impact on customer privacy and security,” the company said.

General bounties are awarded between $500 and $15,000, with other incentives: Standout bug hunters can earn a spot on Microsoft’s “Researcher Recognition Program” and eligibility for the yearly MSRC Most Valuable Security Researcher list, Miyashita explained.

Security researchers with Teams online vulnerabilities to report will still submit those through the Online Services Program, the announcement added.
See Also: Offensive Security Tool: Skipfish Bug-Bounty Programs Inspire Customer ConfidenceBeyond offering a nice payday for security researchers, the move to dedicate a bug-bounty program gives Microsoft some brand support to customers, judging from a recent survey.

Conducted by the Ponemon Institute and commissioned by Intel, the poll found that three-quarters of IT pros in charge of purchasing tech prefer to buy from vendors who are proactive about security. Bug-bounty programs are increasingly part of that package.

“Security doesn’t just happen,” Suzy Greenberg, vice president, Intel Product Assurance and Security, said about the Poneman Institute survey findings. “If you are not finding vulnerabilities, then you are not looking hard enough.”

Certainly, the cloud-collaboration market has seen plenty of security bugs and breaches in recent months, particularly following lockdowns, when these services became vital to everyday business. See Also: Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbersCollaboration App Security StormTeams has been used in phishing lure scams, and last fall attackers used fake Teams updates to target users with malware.

Rival cloud-collab service Zoom has also had its share of embarrassing security fails, including a vanity URL zero-day flaw discovered last July, re-occurring Zoom bombings, impersonation attacks and this month’s Zoom screen-sharing glitch, which “briefly” leaked sensitive data.

The launch of Microsoft’s bug bounty program will both help root out these flaws before they become headlines and signal a renewed commitment to proactive security.
“Partnering with the security research community is an important part of Microsoft’s holistic approach to defending against security threats,” Microsoft’s Miy[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Information Security Tool: Chameleon

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Information Security Tool: ChameleonPost Views: 45
Reading Time: 4 Minutes

Information Security Tool: Chameleon GitHub Link https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/chameleonlogo.png Chameleon by qeeqbox, are customizable honeypots for monitoring network traffic, bots activities and username/password credentials. (DNS, HTTP Proxy, HTTP, HTTPS, SSH, POP3, IMAP, STMP, RDP, VNC, SMB, SOCKS5, Redis, TELNET and Postgres and MySQL) Grafana Interfacehttps://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/intro-1024x432.png NMAP Scanhttps://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/nmap_scan-1024x377.png Credentials Monitoringhttps://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/creds_monitoring-1024x470.png General Features⦿ Modular approach (honeypots run as scripts or imported as objects)
⦿ Most honeypots serve as servers (Only a few that emulate the application layer protocols)
⦿ Settings servers with username, password and banner (Default username and password are test)
⦿ ICMP, DNS TCP and UDP payloads are parsed and check against common patterns
⦿ Visualized Grafana interfaces for monitoring the results (Filter by IP – default is all)
⦿ Unstructured and structured logs are parsed and inserted into Postgres
⦿ All honeypots contain clients for testing the servers
⦿ All ports are opened and monitored by default
⦿ Easy automation and can be deployed on AWS ec2
⦿ & More features to Explore Install and runOn ubuntu 18 or 19 System (Auto-configure)
git clone https://github.com/qeeqbox/chameleon.git cd chameleon
chmod +x ./run.sh
./run.sh auto_configure
The Grafana interface http://localhost:3000 will open automatically after finishing the initialization process (username is changeme457f6460cb287 and password is changemed23b8cc6a20e0). If you don’t see Chameleon dashboard, click on the search icon in the left bar and add it.

Wait for a few seconds until honeypot shows the IP address
...
honeypot_1 | Your IP: 172.19.0.3
honeypot_1 | Your MAC: 09:45:aa:23:10:03
...
You can interact with the honeypot from your local system
ping 172.19.0.3
or run any network tool against it
nmap 172.19.0.3
On ubuntu 18 or 19 System (Auto-configure test)
git clone https://github.com/qeeqbox/chameleon.git cd chameleon
chmod +x ./run.sh
./run.sh auto_configure_test
The Grafana interface http://localhost:3000 will open automatically after finishing the initialization process (username is admin and password is admin). If you don’t see Chameleon dashboard, click on the search icon in the left bar and add it.
Or, import your desired non-blocking server as object (SSH Server)
copy ssh_server.py to your folder # ip= String E.g. 0.0.0.0 # port= Int E.g. 9999 # username= String E.g. Test # password= String E.g. Test # mocking= Boolean or String E.g OpenSSH 7.0 # logs= String E.g db, terminal or all # -------------------------------------------------------------------- # always remember to add process=true to run_server() for non-blocking from ssh_server import QSSHServer qsshserver = QSSHServer(port=9999) qsshserver.run_server(process=True) qsshserver.test_server(port=9999) qsshserver.kill_server() ssh test@127.0.0.1 INFO:chameleonlogger:['servers', {'status': 'success', 'username': 'test', 'ip': '127.0.0.1', 'server': 'ssh_server', 'action': 'login', 'password': 'test', 'port': 38696}] Or, docker stanalone simple
git clone https://github.com/qeeqbox/chameleon.git cd chameleon # choose which honeypot http, https, ssh etc and use -p in docker for the ports
docker build -t honeypot ./honeypot/. && [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft Offers Up To $30K For Teams Bugs https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Offers Up To $30K For Teams BugsPost Views: 116 style="display:block" data…
ashita wrote.
Source: https://threatpost.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/thrive-themes-1030x391-1-90x90.png Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/HL-color-90x90.jpg Hobby Lobby Exposes Customer Data in Cloud Misconfiguration2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/adobe_coldfusion-700x412-e1542041238507-90x90.jpg Adobe Fixes Critical ColdFusion Flaw in Emergency Update3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Clubhouse-e1614022265127-90x90.jpg Bogus Android Clubhouse App Drops Credential-Swiping Malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/apple-security-90x90.jpg Trojanized Xcode Project Slips MacOS Malware to Apple Developers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Cisco_Systems_Sign-90x90.jpg Cisco Plugs Security Hole in Small Business Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/JPG-Malicious-Two-90x90.jpg Magecart Attackers Save Stolen Credit-Card Data in JPG Files1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Google-Chrome-Browser-1-90x90.jpg Google Warns Mac, Windows Users of Chrome Zero-Day Flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/internet-of-things-90x90.jpg Critical Security Hole Can Knock Smart Meters Offline2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Linux-kernel-vulnerability-90x90.png Linux Systems Under Attack By New RedXOR Malware2 weeks ago
The post Microsoft Offers Up To $30K For Teams Bugs first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Information Security Tool: Chameleon https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Information Security Tool: ChameleonPost Views: 45 Reading Time: 4 Minutes Information Security…
docker run -p 9999:9999 -p 9998:9998 -it honeypot --mode normal --servers "ssh:9999 http:9998"
If you don’t see Chameleon dashboard, click on the search icon in the left bar and add it

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/find.png
Raspberry Pi 3B+ (setup zram first to avoid lockups) Requirements (Servers only)apt-get update -y && apt-get install -y iptables-persistent tcpdump nmap iputils-ping python python-pip python-psycopg2 lsof psmisc dnsutils
pip install scapy==2.4.4 netifaces==0.10.9 pyftpdlib==1.5.6 sqlalchemy==1.3.23 pyyaml==5.4.1 paramiko==2.7.1 impacket==0.9.22 twisted==20.3.0 psutil==5.8.0 requests==2.25.1 redis==3.5.3 mysql-connector-python==8.0.23 pygments==2.5.2
pip install -U requests[socks]
pip install -Iv rsa==4.0
pip install rdpy==1.3.2 Current Servers/Emulators⦿ DNS (Server using Twisted)
⦿ HTTP Proxy (Server using Twisted)
⦿ HTTP (Server using Twisted)
⦿ HTTPS (Server using Twisted)
⦿ SSH (Server using socket)
⦿ POP3 (Server using Twisted)
⦿ IMAP (Server using Twisted)
⦿ STMP (Server using smtpd)
⦿ RDP (Server using Twisted)
⦿ SMB (Server using impacket)
⦿ SOCK5 (Server using socketserver)
⦿ TELNET (Server using Twisted)
⦿ VNC (Emulator using Twisted)
⦿ Postgres (Emulator using Twisted)
⦿ Redis (Emulator using Twisted)
⦿ Mysql (Emulator using Twisted)
⦿ Elasticsearch (Coming..)
⦿ Oracle (Coming..)
⦿ ldap (maybe) Changes⦿ 2020.V.01.05 added mysql
⦿ 2020.V.01.04 added redis
⦿ 2020.V.01.03 switched ftp servers to twisted
⦿ 2020.V.01.02 switched http and https servers to twisted
⦿ 2020.V.01.02 Fixed changing ip in grafana interface Roadmap⦿ Refactoring logging
⦿ Fixing logger
⦿ Code Cleanup
⦿ Switching some servers to twisted
⦿ Adding graceful connection close (error response)
⦿ Implementing the rest of servers
⦿ Adding some detection logic to the sinffer
⦿ Adding a control panel ResourcesTwisted, documentation, Impacket, documentation, Grafana, documentation, Expert, Twisted, robertheaton. Other LicensesBy using this framework, you are accepting the license terms of all these packages: grafana, tcpdump, nmap, psycopg, dnsutils, scapy, netifaces, pyftpdlib, sqlalchemy, pyyaml, paramiko, impacket, rdpy, psutil, requests, FreeRDP, SMBClient, tigervnc. Articleskitploit redteaming.net my-infosec-awesome https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/skipfish_screenshot-90x90.png Offensive Security Tool: Skipfish2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/sparta2-90x90.png Offensive Security Tool: Sparta3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/02/ScareCrow2-90x90.png Offensive Security Tool: ScareCrow1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/john_the_ripper_bg-90x90.jpg Offensive Security Tool: JTR – John the Ripper2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/shad0w_msf_shad0w-2-90x90.png Offensive Security Tool: Shad0w3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/12/hack-like-pro-snort-ids-for-aspiring-hacker-part-2-setting-up-basic-configuration-90x90.png Offensive Security Tools: FireEye Red Team Tool Countermeasures4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/12/image-90x90.png Offensive Security Tool: CrackMapExec4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/3-90x90.png Offensive Security Tool: PRET – Printer Exploitation Toolkit5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/10/xsstrike-90x90.png Offensive Security Tool: XSStrike5 months ago
* https://www.blackhat[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Incident Response(Olay Müdahalesi) Nedir ?

https://cdn-images-1.medium.com/max/600/1*cMrOWmcl7dIsp5-PVLzGpg.png
Olay müdahalesi, bir kurum veya kuruluşun siber saldırı veya güvenlik ihlali ile karşılaştığında bu olayları ele alma sürecini tanımlayan…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacakable Book Review

https://cdn-images-1.medium.com/max/600/0*l-8F5m7uuE89aCC1.jpg
This is a review of the book Hackable by Ted Harrington. This book takes application security and makes it easy to understand how and why…

Continue reading on Medium »
Retoolkit - Reverse Engineer's Toolkit

This is a collection of tools you may like if you are interested on reverse engineering and/or malware analysis on x86 and x64 Windows systems. After installing this toolkit you'll have a folder in your desktop with shortcuts to RE tools like these:Why do I need it? You don't. Obviously, you can download such tools from their own website and install them by yourself in a new VM. But if you download retoolkit, it can probably save you some time. Additionally, the tools come pre-configured so you'll find things like x64dbg with a few plugins, command-line tools working from any directory, etc. You may like it if you're setting up a new analysis VM. Download The *.iss files you see here are the source code for our setup program built with Inno Setup. To download the real thing, you have to go to the Releases section and download the setup program. Included tools Check the wiki. Is it safe to install it in my environment? I don't know. Some included tools are not open source and come from shady places. You should use it exclusively in virtual machines and under your own responsibility. Can you add tool X? It depends. The idea is to keep it simple. We won't add a tool just because it's not here yet. But if you think there's a good reason to do so, and the license allows us to redistribuite the software, please file a request here. Download Retoolkit
Read more...