Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking metasploit with metasploit
https://cdn-images-1.medium.com/max/694/0*51nL0tXdIrHEyBS4.png
msfd — Provides an instance of msfconsole that remote clients can connect to
Continue reading on InfoSec Write-ups »
Hacking metasploit with metasploit
https://cdn-images-1.medium.com/max/694/0*51nL0tXdIrHEyBS4.png
msfd — Provides an instance of msfconsole that remote clients can connect to
Continue reading on InfoSec Write-ups »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Otro defecto crítico de RCE descubierto en la plataforma SolarWinds Orion.
https://cdn-images-1.medium.com/max/895/0*zuD9fsb6bU5cDrOw
El proveedor de administración de infraestructura de TI SolarWinds lanzó el jueves una nueva actualización de su herramienta de monitoreo…
Continue reading on Medium »
Otro defecto crítico de RCE descubierto en la plataforma SolarWinds Orion.
https://cdn-images-1.medium.com/max/895/0*zuD9fsb6bU5cDrOw
El proveedor de administración de infraestructura de TI SolarWinds lanzó el jueves una nueva actualización de su herramienta de monitoreo…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OpenSSL lanza parches para 2 vulnerabilidades de seguridad de alta gravedad.
https://cdn-images-1.medium.com/max/836/0*tUoRjcksTFdDQrp3
Los mantenedores de OpenSSL han publicado una solución para dos fallas de seguridad de alta gravedad en su software que podrían explotarse…
Continue reading on Medium »
OpenSSL lanza parches para 2 vulnerabilidades de seguridad de alta gravedad.
https://cdn-images-1.medium.com/max/836/0*tUoRjcksTFdDQrp3
Los mantenedores de OpenSSL han publicado una solución para dos fallas de seguridad de alta gravedad en su software que podrían explotarse…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Book | Cult Of The Dead Cow: How The Original Hacking Supergroup Might Just Save The World | An…
https://cdn-images-1.medium.com/max/1920/1*HoSqkDLBYZjGtHrok_glcA.png
Let’s face it, hacking got a bad reputation — it has been in the making for over 30 years, it got worse, and we have to change that…
Continue reading on ITSPmagazine »
Book | Cult Of The Dead Cow: How The Original Hacking Supergroup Might Just Save The World | An…
https://cdn-images-1.medium.com/max/1920/1*HoSqkDLBYZjGtHrok_glcA.png
Let’s face it, hacking got a bad reputation — it has been in the making for over 30 years, it got worse, and we have to change that…
Continue reading on ITSPmagazine »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Test lab 15 writeup
https://cdn-images-1.medium.com/max/780/0*mYqUP0g9NiZVV5WF.jpg
Penetration Testing Laboratory 15 by Pentestit — walk through
Continue reading on Medium »
Test lab 15 writeup
https://cdn-images-1.medium.com/max/780/0*mYqUP0g9NiZVV5WF.jpg
Penetration Testing Laboratory 15 by Pentestit — walk through
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Different Types of Hacking Techniques
The field of computer security is fast becoming a field full of hacking techniques. It is important to remember that just because you do…
Continue reading on Medium »
Different Types of Hacking Techniques
The field of computer security is fast becoming a field full of hacking techniques. It is important to remember that just because you do…
Continue reading on Medium »
OSCP Prep.
https://www.reddit.com/r/Pentesting/comments/me1k70/oscp_prep/
<!-- SC_OFF -->Hi, I am thinking of taking the OSCP, what kind of prerequisites do I need to get in order to pass the exam? I'm a mediumish-beginner in this topic, and over the next 1-2 years I am willing to obtain the knowledge and skills to be ready for the OSCP. I know that the Offensive Security website says that I just need some basic bash/perl/c knowledge and then tcp/ip, but I've looked around on the internet and most people say that that is not nearly enough. So, I would really appreciate it if someone could share their thoughts on what I need to learn and get good at. Thanks! <!-- SC_ON --> submitted by /u/oniono12 (https://www.reddit.com/user/oniono12)
[link] (https://www.reddit.com/r/Pentesting/comments/me1k70/oscp_prep/) [comments] (https://www.reddit.com/r/Pentesting/comments/me1k70/oscp_prep/)
https://www.reddit.com/r/Pentesting/comments/me1k70/oscp_prep/
<!-- SC_OFF -->Hi, I am thinking of taking the OSCP, what kind of prerequisites do I need to get in order to pass the exam? I'm a mediumish-beginner in this topic, and over the next 1-2 years I am willing to obtain the knowledge and skills to be ready for the OSCP. I know that the Offensive Security website says that I just need some basic bash/perl/c knowledge and then tcp/ip, but I've looked around on the internet and most people say that that is not nearly enough. So, I would really appreciate it if someone could share their thoughts on what I need to learn and get good at. Thanks! <!-- SC_ON --> submitted by /u/oniono12 (https://www.reddit.com/user/oniono12)
[link] (https://www.reddit.com/r/Pentesting/comments/me1k70/oscp_prep/) [comments] (https://www.reddit.com/r/Pentesting/comments/me1k70/oscp_prep/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
cve_manager_VS - A Collection Of Python Apps And Shell Scripts To Email An Xlsx Spreadsheet Of New Vulnerabilities In The NIST CVE Database And Their Associated Products On A Daily Schedule
https://1.bp.blogspot.com/-jaOqBSyroOk/YFewWJ1Dk6I/AAAAAAAAVrM/ZLkomCybkq4Kzp_amvDzXg8fotHSOgS5QCNcBGAsYHQ/w640-h326/cve_manager.png A collection of python apps and shell scripts to email an xlsx spreadsheet of new vulnerabilities in the NIST CVE database and their associated products on a daily schedule. The spreadsheet can then be manually interpreted for risk to your specific organization.
* Based off of an opensource product on github originally by Antonios Atlasis
* Syncs the NIST database for CVEs and CPEs locally and provides basic query capabilities
* Creates xlsx reports from the data and Emails those reports
File: cve_manager.py
A python script originally authored by Antonios Atlasis - aatlasis@secfu.net https://github.com/aatlasis/cve_manager
* create postgresql databases and views
* downloads the latest NIST CVE, CPE, and CWE raw data files
* unzips and loads the NIST raw data files into the database
* automates custom queries, searches and reports of the NIST data
* creates csv export reports of the data
Changes from original:
Added import of data manipulation library pandas
sudo pip3 install pandas openpyxl
Added database view that joins cve and cpe data
Modified default cpe queries and reports to include cvssv3 vector string instead of cvssv2 score
Modified default cpe queries and reports to sort by published date ASC, CVSS DESC, and CPE ASC
Modified cpe output to csv function to automatically save a copy in xlsx format for every csv saved
File: email_xlsx_attach.py
New python script, authored by Shane Lawrence
sends the xlsx reports as email attachments through a local smtp relay
File: daily.sh
a bash shell script, authored by Shane Lawrence
Puts it all together in something that cron can run daily
Automates the following uses of cve_manager.py:
* truncates the old database, deletes old datafiles
* downloads new raw datafiles for CVE data - the vulnerabilities
* downloads new raw data file for CPE - the vulnerable products
* downloads new top 1000 CWE - the code problems that cause vulnerabilities
* jams all of the above into a postgres database
* runs the searches relevant to you
* creates csv reports of the relevant searches, formatted and sorted for your preferences
* reads in the csv reports and outputs to xlsx
* deletes the csvs
Automates the usage of email_xlsx_attach.py
New server setup:
Read the original pdf at: https://github.com/aatlasis/cve_manager/blob/master/CVE%20Manager.pdf
1.
Setup python:
Requires python 3
Do yourself a favor and install pip3 also
pip3 install psycopg2, openpyxl, pandas
Required includes:
psycopg2 - data science libs
pandas - data manipulation libs (dependency on openpyxl)
sys, argparse, os, zipfile, json, requests, re, io, csv, smtplib, base64, email, datetime
2.
Setup postgres:
Install the latest postgreql database for your distribution.
as root, systemctl enable postgresql
systemctl start postgresql
then set a password for postgresql user by:
sudo -u postgres psql
\l lists databases
\du lists users
CREATE USER username WITH PASSWORD 'password';
3.
Use cve_manager to create the database:
The user must have create privlileges
./cve_manager.py -u postgres -ps $PASSWORD -server localhost -db $DB -ow $USER -cd
4.
Use cve_manager.py to create the schema
The user must have create privileges
./cve_manager.py -u postgres -ps $PASSWORD -server localhost -db $DB -ct
5.
Use cve_manager to download the CVE and CPE data
./cve_manager.py -u $user -ps $pass -host $host -db $db -d -p -csv
6.
Manually download and unzip the CWE data
wget https://cwe.mitre.org/data/csv/1000.[...]
cve_manager_VS - A Collection Of Python Apps And Shell Scripts To Email An Xlsx Spreadsheet Of New Vulnerabilities In The NIST CVE Database And Their Associated Products On A Daily Schedule
https://1.bp.blogspot.com/-jaOqBSyroOk/YFewWJ1Dk6I/AAAAAAAAVrM/ZLkomCybkq4Kzp_amvDzXg8fotHSOgS5QCNcBGAsYHQ/w640-h326/cve_manager.png A collection of python apps and shell scripts to email an xlsx spreadsheet of new vulnerabilities in the NIST CVE database and their associated products on a daily schedule. The spreadsheet can then be manually interpreted for risk to your specific organization.
* Based off of an opensource product on github originally by Antonios Atlasis
* Syncs the NIST database for CVEs and CPEs locally and provides basic query capabilities
* Creates xlsx reports from the data and Emails those reports
File: cve_manager.py
A python script originally authored by Antonios Atlasis - aatlasis@secfu.net https://github.com/aatlasis/cve_manager
* create postgresql databases and views
* downloads the latest NIST CVE, CPE, and CWE raw data files
* unzips and loads the NIST raw data files into the database
* automates custom queries, searches and reports of the NIST data
* creates csv export reports of the data
Changes from original:
Added import of data manipulation library pandas
sudo pip3 install pandas openpyxl
Added database view that joins cve and cpe data
Modified default cpe queries and reports to include cvssv3 vector string instead of cvssv2 score
Modified default cpe queries and reports to sort by published date ASC, CVSS DESC, and CPE ASC
Modified cpe output to csv function to automatically save a copy in xlsx format for every csv saved
File: email_xlsx_attach.py
New python script, authored by Shane Lawrence
sends the xlsx reports as email attachments through a local smtp relay
File: daily.sh
a bash shell script, authored by Shane Lawrence
Puts it all together in something that cron can run daily
Automates the following uses of cve_manager.py:
* truncates the old database, deletes old datafiles
* downloads new raw datafiles for CVE data - the vulnerabilities
* downloads new raw data file for CPE - the vulnerable products
* downloads new top 1000 CWE - the code problems that cause vulnerabilities
* jams all of the above into a postgres database
* runs the searches relevant to you
* creates csv reports of the relevant searches, formatted and sorted for your preferences
* reads in the csv reports and outputs to xlsx
* deletes the csvs
Automates the usage of email_xlsx_attach.py
New server setup:
Read the original pdf at: https://github.com/aatlasis/cve_manager/blob/master/CVE%20Manager.pdf
1.
Setup python:
Requires python 3
Do yourself a favor and install pip3 also
pip3 install psycopg2, openpyxl, pandas
Required includes:
psycopg2 - data science libs
pandas - data manipulation libs (dependency on openpyxl)
sys, argparse, os, zipfile, json, requests, re, io, csv, smtplib, base64, email, datetime
2.
Setup postgres:
Install the latest postgreql database for your distribution.
as root, systemctl enable postgresql
systemctl start postgresql
then set a password for postgresql user by:
sudo -u postgres psql
\l lists databases
\du lists users
CREATE USER username WITH PASSWORD 'password';
3.
Use cve_manager to create the database:
The user must have create privlileges
./cve_manager.py -u postgres -ps $PASSWORD -server localhost -db $DB -ow $USER -cd
4.
Use cve_manager.py to create the schema
The user must have create privileges
./cve_manager.py -u postgres -ps $PASSWORD -server localhost -db $DB -ct
5.
Use cve_manager to download the CVE and CPE data
./cve_manager.py -u $user -ps $pass -host $host -db $db -d -p -csv
6.
Manually download and unzip the CWE data
wget https://cwe.mitre.org/data/csv/1000.[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! cve_manager_VS - A Collection Of Python Apps And Shell Scripts To Email An Xlsx Spreadsheet Of New Vulnerabilities In The NIST CVE Database And Their Associated Products On A Daily Schedule https://1.bp.blogspot.com/-jaOqBSyroOk…
csv.zip
unzip 1000.csv.zip
7.
Use cve_manager to import the NIST CVE and CPE data into the database
./cve_manager.py -u $user -ps $pass -host $host -db $db -idb -p
8.
Use cve_manager to import the CWE data into the database
./cve_manager.py -u $user -ps $pass -host $host -db $db -icwe 1000.csv
9.
Run an example report.
This example creates a csv and xlsx of the vulnerabilities and products they affect,
only rated severity 7.0 or greater, created or updated since 01 July 2020
./cve_manager.py -u $user -ps $password -host $host -db $db -sc 7.0 -dt 2020-07-01 -cpe cpe -csv -o $reports
10.
Email the xlsx reports
Modify email_xlsx_attach.py for your smtp relay, sender, recipients, and reports directory.
TODO:
Next iteration is to figure out how to incorperate a list of a critical product inventory,
and only create reports that apply to the CPEs on product inventory.
Shane Lawrence
Sr Advisor, Cloud Platform Security Download cve_manager_VS
unzip 1000.csv.zip
7.
Use cve_manager to import the NIST CVE and CPE data into the database
./cve_manager.py -u $user -ps $pass -host $host -db $db -idb -p
8.
Use cve_manager to import the CWE data into the database
./cve_manager.py -u $user -ps $pass -host $host -db $db -icwe 1000.csv
9.
Run an example report.
This example creates a csv and xlsx of the vulnerabilities and products they affect,
only rated severity 7.0 or greater, created or updated since 01 July 2020
./cve_manager.py -u $user -ps $password -host $host -db $db -sc 7.0 -dt 2020-07-01 -cpe cpe -csv -o $reports
10.
Email the xlsx reports
Modify email_xlsx_attach.py for your smtp relay, sender, recipients, and reports directory.
TODO:
Next iteration is to figure out how to incorperate a list of a critical product inventory,
and only create reports that apply to the CPEs on product inventory.
Shane Lawrence
Sr Advisor, Cloud Platform Security Download cve_manager_VS
hacking: security in practice
Can new hardware have malicious software on it?
What are the chances that buying something like a budget keyboard off Amazon that's made in China has malicious software already on it?
I'm guessing the chance is low, but why is that? Are there third party entities that vet hardware built in other countries? Would it be relatively easy to make batches of hardware that can be connected to consumer computers all over the world to record user inputs and then send that info back to the attackers?
Thanks!
submitted by /u/5evenThirty
[link] [comments]
Can new hardware have malicious software on it?
What are the chances that buying something like a budget keyboard off Amazon that's made in China has malicious software already on it?
I'm guessing the chance is low, but why is that? Are there third party entities that vet hardware built in other countries? Would it be relatively easy to make batches of hardware that can be connected to consumer computers all over the world to record user inputs and then send that info back to the attackers?
Thanks!
submitted by /u/5evenThirty
[link] [comments]
reddit
Can new hardware have malicious software on it?
What are the chances that buying something like a budget keyboard off Amazon that's made in China has malicious software already on it? I'm...
hacking: security in practice
How bad is this?
https://b.thumbs.redditmedia.com/cUId1cwxA9CeDKLOBflD_ZMNEbay5FUhWDZR3sx04bc.jpg submitted by /u/GalaxyOverlord
[link] [comments]
How bad is this?
https://b.thumbs.redditmedia.com/cUId1cwxA9CeDKLOBflD_ZMNEbay5FUhWDZR3sx04bc.jpg submitted by /u/GalaxyOverlord
[link] [comments]
reddit
How bad is this?
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
hide a bitcoin miner in a pc without creating "suspicions"?
yes I know you hear it from the fan but I wanted to know if you can hide the miner by disguising it in other programs etc..
submitted by /u/31tnary
[link] [comments]
hide a bitcoin miner in a pc without creating "suspicions"?
yes I know you hear it from the fan but I wanted to know if you can hide the miner by disguising it in other programs etc..
submitted by /u/31tnary
[link] [comments]
reddit
hide a bitcoin miner in a pc without creating "suspicions"?
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...