I am stuck and looking for tips/ suggestions
https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/
<!-- SC_OFF -->I was "tasked" to do a pentest (as a training) of this one modified machine that was used in the previous local pentest competition and it was the "hardest" machine. I got one of the user access, okay, I can ssh , great. but as a non-root, I cant literally do anything other than read useless files. I cant do an scp transfer, cant modified file, cant make a dir, cant do a wget because the machine seemed to have no connection to the internet (any tips on this is?). in the user home I see a userflag, but since its a modified machine, my objective is to get root access. its a linux ubuntu kernel 3.0.0 generic, and I got the username from exploiting webmin. with the obtained hash infos, Jacktheripper quickly got one of the pass, but for the other users? ETA 24 hours, the keywords is obviously not in english or a very unique one so I think it is a waste of time. I tried: mempodipper , but no permission, tried writing the mempodipper there, cant modified, tried to download (wget) mempo, no permission. in every similar case on the internet I found, they all use msf . well in this training I cannot use any of that so its all manual. however, there is one text file that I can write on but not rename (so its useless?) any tips how to approach this? keywords maybe? *ps the teacher didnt actually expect us to do this machine, he only tasked us with the previous 4 machines and I did all of them, Im just curious and annoyed with this last one. sorry, english is not first language. *EDIT: typos <!-- SC_ON --> submitted by /u/Arcyma (https://www.reddit.com/user/Arcyma)
[link] (https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/)
https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/
<!-- SC_OFF -->I was "tasked" to do a pentest (as a training) of this one modified machine that was used in the previous local pentest competition and it was the "hardest" machine. I got one of the user access, okay, I can ssh , great. but as a non-root, I cant literally do anything other than read useless files. I cant do an scp transfer, cant modified file, cant make a dir, cant do a wget because the machine seemed to have no connection to the internet (any tips on this is?). in the user home I see a userflag, but since its a modified machine, my objective is to get root access. its a linux ubuntu kernel 3.0.0 generic, and I got the username from exploiting webmin. with the obtained hash infos, Jacktheripper quickly got one of the pass, but for the other users? ETA 24 hours, the keywords is obviously not in english or a very unique one so I think it is a waste of time. I tried: mempodipper , but no permission, tried writing the mempodipper there, cant modified, tried to download (wget) mempo, no permission. in every similar case on the internet I found, they all use msf . well in this training I cannot use any of that so its all manual. however, there is one text file that I can write on but not rename (so its useless?) any tips how to approach this? keywords maybe? *ps the teacher didnt actually expect us to do this machine, he only tasked us with the previous 4 machines and I did all of them, Im just curious and annoyed with this last one. sorry, english is not first language. *EDIT: typos <!-- SC_ON --> submitted by /u/Arcyma (https://www.reddit.com/user/Arcyma)
[link] (https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Instagram is (not) for Idiots! Also, what to do if your account is compromised!
https://cdn-images-1.medium.com/max/1920/1*iaqFy4_yk3QQN6805zLOXA.jpeg
By now we all know Instagram is more than a social networking site. It is a platform where a public image gets built, nurtured and thenβ¦
Continue reading on Medium Β»
Instagram is (not) for Idiots! Also, what to do if your account is compromised!
https://cdn-images-1.medium.com/max/1920/1*iaqFy4_yk3QQN6805zLOXA.jpeg
By now we all know Instagram is more than a social networking site. It is a platform where a public image gets built, nurtured and thenβ¦
Continue reading on Medium Β»
hacking: security in practice
CTF Walk through
I've been trying to find a good person to watch as they do CTF's. There are a bunch on Youtube but, as I'm just starting to get into CTFs, I'm finding some videos are hard to follow. I was wondering if anyone could recommend someone who explains the ins and outs as they go through it? If you have a favorite person you follow I'd be happy to check them out as well. Thanks in advance!
submitted by /u/MolotovBoy
[link] [comments]
CTF Walk through
I've been trying to find a good person to watch as they do CTF's. There are a bunch on Youtube but, as I'm just starting to get into CTFs, I'm finding some videos are hard to follow. I was wondering if anyone could recommend someone who explains the ins and outs as they go through it? If you have a favorite person you follow I'd be happy to check them out as well. Thanks in advance!
submitted by /u/MolotovBoy
[link] [comments]
reddit
CTF Walk through
I've been trying to find a good person to watch as they do CTF's. There are a bunch on Youtube but, as I'm just starting to get into CTFs, I'm...
hacking: security in practice
Hey guys and girls π
How can I bypass a payment wall on only fansππ
submitted by /u/Careplusuk
[link] [comments]
Hey guys and girls π
How can I bypass a payment wall on only fansππ
submitted by /u/Careplusuk
[link] [comments]
reddit
Hey guys and girls π
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Test lab 15 writeup
https://cdn-images-1.medium.com/max/780/0*mYqUP0g9NiZVV5WF.jpg
Penetration Testing Laboratory 15 by Pentestitβββwalk through
Continue reading on The Startup Β»
Test lab 15 writeup
https://cdn-images-1.medium.com/max/780/0*mYqUP0g9NiZVV5WF.jpg
Penetration Testing Laboratory 15 by Pentestitβββwalk through
Continue reading on The Startup Β»
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Cyber security Awareness Training is Important For Startups?
https://cdn-images-1.medium.com/max/1500/1*zonp__o2phLgdLEXcyRDOA.png
In todayβs world, one of the important aspects of the information technology sector is Cybersecurity. Cybersecurity is just a way to keepβ¦
Continue reading on Medium Β»
How Cyber security Awareness Training is Important For Startups?
https://cdn-images-1.medium.com/max/1500/1*zonp__o2phLgdLEXcyRDOA.png
In todayβs world, one of the important aspects of the information technology sector is Cybersecurity. Cybersecurity is just a way to keepβ¦
Continue reading on Medium Β»
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The BoxβββLame: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*n3tirIS46hkYiX00wcEXhA.png
Hack The BoxβββLame: Walkthrough (without Metasploit) | Road to OSP | SMB attack | Linux Easy Level | Beginner Friendly | FTP Enumeration
Continue reading on Medium Β»
Hack The BoxβββLame: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*n3tirIS46hkYiX00wcEXhA.png
Hack The BoxβββLame: Walkthrough (without Metasploit) | Road to OSP | SMB attack | Linux Easy Level | Beginner Friendly | FTP Enumeration
Continue reading on Medium Β»
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hub Weekly Digest: GE, DOE, Verkada Hack, VMware and the DHS
https://cdn-images-1.medium.com/max/2600/1*_ouolRTZtZ1LXMl5z_BVXw.jpeg
Hub Securityβs weekly digest covers top stories happening around the world related to fintech, critical infrastructure, cloud, andβ¦
Continue reading on HUB Security Β»
Hub Weekly Digest: GE, DOE, Verkada Hack, VMware and the DHS
https://cdn-images-1.medium.com/max/2600/1*_ouolRTZtZ1LXMl5z_BVXw.jpeg
Hub Securityβs weekly digest covers top stories happening around the world related to fintech, critical infrastructure, cloud, andβ¦
Continue reading on HUB Security Β»
Obfuscation\_Detection - Collection Of Scripts To Pinpoint Obfuscated Code
Automatically detect control-flow flattening and other state machines Author: Tim BlazytkoDescription: Scripts and binaries to automatically detect control-flow flattening and other state machines in binaries. Implementation is based on Binary Ninja. Check out the following blog post for more information: Automated Detection of Control-flow FlatteningUsage $ ./detect_flattening.py samples/finspy Function 0x401602 has a flattening score of 0.9473684210526315.Function 0x4017c0 has a flattening score of 0.9981378026070763.Function 0x405150 has a flattening score of 0.9166666666666666.Function 0x405270 has a flattening score of 0.9166666666666666.Function 0x405370 has a flattening score of 0.9984544049459042.Function 0x4097a0 has a flattening score of 0.9992378048780488.Function 0x412c70 has a flattening score of 0.9629629629629629.Function 0x412df0 has a flattening score of 0.9629629629629629.Function 0x412f70 has a flattening score of 0.9927007299270073.Function 0x4138e0 has a flattening score of 0.9629629629629629. Note The password for the zipped malware samples is "infected". To unpack, use the following command line: $ unzip -P infected samples.zip Contact For more information, contact @mr_phrazer. Download Obfuscation_Detection
Read more...
Automatically detect control-flow flattening and other state machines Author: Tim BlazytkoDescription: Scripts and binaries to automatically detect control-flow flattening and other state machines in binaries. Implementation is based on Binary Ninja. Check out the following blog post for more information: Automated Detection of Control-flow FlatteningUsage $ ./detect_flattening.py samples/finspy Function 0x401602 has a flattening score of 0.9473684210526315.Function 0x4017c0 has a flattening score of 0.9981378026070763.Function 0x405150 has a flattening score of 0.9166666666666666.Function 0x405270 has a flattening score of 0.9166666666666666.Function 0x405370 has a flattening score of 0.9984544049459042.Function 0x4097a0 has a flattening score of 0.9992378048780488.Function 0x412c70 has a flattening score of 0.9629629629629629.Function 0x412df0 has a flattening score of 0.9629629629629629.Function 0x412f70 has a flattening score of 0.9927007299270073.Function 0x4138e0 has a flattening score of 0.9629629629629629. Note The password for the zipped malware samples is "infected". To unpack, use the following command line: $ unzip -P infected samples.zip Contact For more information, contact @mr_phrazer. Download Obfuscation_Detection
Read more...
Obfuscation_Detection - Collection Of Scripts To Pinpoint Obfuscated Code
http://www.kitploit.com/2021/03/obfuscationdetection-collection-of.html
http://www.kitploit.com/2021/03/obfuscationdetection-collection-of.html
Automatically detect control-flow flattening and other state machines Author: Tim Blazytko
Description:
Scripts and binaries to automatically detect control-flow flattening and other state machines in binaries. Implementation is based on Binary (https://www.kitploit.com/search/label/Binary) Ninja. Check out the following blog post for more information: Automated Detection of Control-flow Flattening (https://synthesis.to/2021/03/03/flattening_detection.html)
Usage
$ ./detect_flattening.py samples/finspy
Function 0x401602 has a flattening score of 0.9473684210526315.
Function 0x4017c0 has a flattening score of 0.9981378026070763.
Function 0x405150 has a flattening score of 0.9166666666666666.
Function 0x405270 has a flattening score of 0.9166666666666666.
Function 0x405370 has a flattening score of 0.9984544049459042.
Function 0x4097a0 has a flattening score of 0.9992378048780488.
Function 0x412c70 has a flattening score of 0.9629629629629629.
Function 0x412df0 has a flattening score of 0.9629629629629629.
Function 0x412f70 has a flattening score of 0.9927007299270073.
Function 0x4138e0 has a flattening score of 0.9629629629629629.
Note
The password for the zipped malware samples (https://www.kitploit.com/search/label/Malware%20Samples) is "infected". To unpack, use the following command line: $ unzip -P infected samples.zip
Contact
For more information, contact @mr_phrazer (https://twitter.com/mr_phrazer).
Download Obfuscation_Detection (https://github.com/mrphrazer/obfuscation_detection)
Description:
Scripts and binaries to automatically detect control-flow flattening and other state machines in binaries. Implementation is based on Binary (https://www.kitploit.com/search/label/Binary) Ninja. Check out the following blog post for more information: Automated Detection of Control-flow Flattening (https://synthesis.to/2021/03/03/flattening_detection.html)
Usage
$ ./detect_flattening.py samples/finspy
Function 0x401602 has a flattening score of 0.9473684210526315.
Function 0x4017c0 has a flattening score of 0.9981378026070763.
Function 0x405150 has a flattening score of 0.9166666666666666.
Function 0x405270 has a flattening score of 0.9166666666666666.
Function 0x405370 has a flattening score of 0.9984544049459042.
Function 0x4097a0 has a flattening score of 0.9992378048780488.
Function 0x412c70 has a flattening score of 0.9629629629629629.
Function 0x412df0 has a flattening score of 0.9629629629629629.
Function 0x412f70 has a flattening score of 0.9927007299270073.
Function 0x4138e0 has a flattening score of 0.9629629629629629.
Note
The password for the zipped malware samples (https://www.kitploit.com/search/label/Malware%20Samples) is "infected". To unpack, use the following command line: $ unzip -P infected samples.zip
Contact
For more information, contact @mr_phrazer (https://twitter.com/mr_phrazer).
Download Obfuscation_Detection (https://github.com/mrphrazer/obfuscation_detection)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Obfuscation_Detection - Collection Of Scripts To Pinpoint Obfuscated Code
https://1.bp.blogspot.com/-pVG_GY_Kvjg/YFexRwJ3VZI/AAAAAAAAVrY/p638kM3wVY895SoSAenvnyZFnfoxs9u-wCNcBGAsYHQ/w640-h380/Obfuscation_Detection.png
Automatically detect control-flow flattening and other state machines
Author: Tim Blazytko
Description:
Scripts and binaries to automatically detect control-flow flattening and other state machines in binaries.
Implementation is based on Binary Ninja. Check out the following blog post for more information:
Automated Detection of Control-flow Flattening
Usage
Note
The password for the zipped malware samples is "infected". To unpack, use the following command line:
Contact
For more information, contact @mr_phrazer.
Download Obfuscation_Detection
Obfuscation_Detection - Collection Of Scripts To Pinpoint Obfuscated Code
https://1.bp.blogspot.com/-pVG_GY_Kvjg/YFexRwJ3VZI/AAAAAAAAVrY/p638kM3wVY895SoSAenvnyZFnfoxs9u-wCNcBGAsYHQ/w640-h380/Obfuscation_Detection.png
Automatically detect control-flow flattening and other state machines
Author: Tim Blazytko
Description:
Scripts and binaries to automatically detect control-flow flattening and other state machines in binaries.
Implementation is based on Binary Ninja. Check out the following blog post for more information:
Automated Detection of Control-flow Flattening
Usage
$ ./detect_flattening.py samples/finspy
Function 0x401602 has a flattening score of 0.9473684210526315.
Function 0x4017c0 has a flattening score of 0.9981378026070763.
Function 0x405150 has a flattening score of 0.9166666666666666.
Function 0x405270 has a flattening score of 0.9166666666666666.
Function 0x405370 has a flattening score of 0.9984544049459042.
Function 0x4097a0 has a flattening score of 0.9992378048780488.
Function 0x412c70 has a flattening score of 0.9629629629629629.
Function 0x412df0 has a flattening score of 0.9629629629629629.
Function 0x412f70 has a flattening score of 0.9927007299270073.
Function 0x4138e0 has a flattening score of 0.9629629629629629.
Note
The password for the zipped malware samples is "infected". To unpack, use the following command line:
$ unzip -P infected samples.zip
Contact
For more information, contact @mr_phrazer.
Download Obfuscation_Detection
hacking: security in practice
Can I use Alfa AWUS1900 for monitor mode and packet Injection in Kali Linux?
Can I use Alfa AWUS1900 in Kali Linux 2021? Can it support monitor mode and packet injection?
submitted by /u/MasterWizard102
[link] [comments]
Can I use Alfa AWUS1900 for monitor mode and packet Injection in Kali Linux?
Can I use Alfa AWUS1900 in Kali Linux 2021? Can it support monitor mode and packet injection?
submitted by /u/MasterWizard102
[link] [comments]
reddit
Can I use Alfa AWUS1900 for monitor mode and packet Injection in...
Can I use Alfa AWUS1900 in Kali Linux 2021? Can it support monitor mode and packet injection?
hacking: security in practice
CREATING EDUCATIONAL LAB ON IOT Security
Hey, first time posting here (please be patient with me). I'm trying to create a lab to demonstrate the types of attacks that can be used against IoT devices. I'm having trouble of figuring out how to setup an environment for me to perform the lab.
Essentially, there is a sensor attached to the Pi and I'll have a custom program with some badly written code. I am trying to use an attack to either show service degradation or a stack overflow attack that could overwrite the program and give the attacker access into the device. How would I go about this? Does this make sense so far? If I left out any information needed don't hesitate to ask?
My setup as of right now is a Raspberry Pi 4 with stock OS.
submitted by /u/Admirable_Cranberry1
[link] [comments]
CREATING EDUCATIONAL LAB ON IOT Security
Hey, first time posting here (please be patient with me). I'm trying to create a lab to demonstrate the types of attacks that can be used against IoT devices. I'm having trouble of figuring out how to setup an environment for me to perform the lab.
Essentially, there is a sensor attached to the Pi and I'll have a custom program with some badly written code. I am trying to use an attack to either show service degradation or a stack overflow attack that could overwrite the program and give the attacker access into the device. How would I go about this? Does this make sense so far? If I left out any information needed don't hesitate to ask?
My setup as of right now is a Raspberry Pi 4 with stock OS.
submitted by /u/Admirable_Cranberry1
[link] [comments]
reddit
CREATING EDUCATIONAL LAB ON IOT Security
Hey, first time posting here (please be patient with me). I'm trying to create a lab to demonstrate the types of attacks that can be used against...