Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Xmap - A Fast Network Scanner Designed For Performing Internet-wide IPv6 &Amp; IPv4 Network Research Scanning

https://blogger.googleusercontent.com/img/a/AVvXsEiIykjf6pqIxFErLOWXeKbCoONaK4Vd-4egAmOuIUTd6DLoQuUxne5mGJrBRGJI2_r4JktIN5LWsa68F5OPdvSyeQX9YIPvLjDpu_DzajIvVy6s--D1zZWVQKwiaAoz0qAMtOZKw3AKAHdgUGPz27D-ZSm73xxrHYzb83uPdXiO4fG2Eb36_ANHi5BHLg=w640-h278 XMap is a fast network scanner designed for performing Internet-wide IPv6 & IPv4 network research scanning.

XMap is reimplemented and improved thoroughly from ZMap and is fully compatible with ZMap, armed with the "5 minutes" probing speed and novel scanning techniques. XMap is capable of scanning the 32-bits address space in under 45 minutes. With a 10 gigE connection and PF_RING, XMap can scan the 32-bits address space in under 5 minutes. Moreover, leveraging the novel IPv6 scanning approach, XMap can discover the IPv6 Network Periphery fast. Furthermore, XMap can scan the network space randomly with any length and at any position, such as 2001:db8::/32-64 and 192.168.0.1/16-20. Besides, XMap can probe multiple ports simultaneously.

XMap operates on GNU/Linux, Mac OS, and BSD. XMap currently has implemented probe modules for ICMP Echo scans, TCP SYN scans, and UDP probes.

With banner grab and TLS handshake tool, ZGrab2, more involved scans could be performed. InstallationThe latest stable release of XMap is version 1.0.0 and supports Linux, macOS, and BSD. We recommend installing XMap from HEAD rather than using a distro package manager (not supported yet).

Instructions on building XMap from source can be found in INSTALL. UsageA guide to using XMap can be found in our GitHub Wiki.

Simple commands and options to using XMap can be found in USAGE. PaperFast IPv6 Network Periphery Discovery and Security Implications.

Abstract. Numerous measurement researches have been performed to discover the IPv4 network security issues by leveraging the fast Internet-wide scanning techniques. However, IPv6 brings the 128-bits address space and renders brute-force network scanning impractical. Although significant efforts have been dedicated to enumerating active IPv6 hosts, limited by technique efficiency and probing accuracy, large-scale empirical measurement studies under the increasing IPv6 networks are infeasible now.

To fill this research gap, by leveraging the extensively adopted IPv6 address allocation strategy, we propose a novel IPv6 network periphery discovery approach. Specifically, XMap, a fast network scanner, is developed to find the periphery, such as a home router. We evaluate it on twelve prominent Internet service providers and harvest 52M active peripheries. Grounded on these found devices, we explore IPv6 network risks of the unintended exposed security services and the flawed traffic routing strategies. First, we demonstrate the unintended exposed security services in IPv6 networks, such as DNS, and HTTP, have become emerging security risks by analyzing 4.7M peripheries. Second, by inspecting the periphery’s packet routing strategies, we present the flawed implementations of IPv6 routing protocol affecting 5.8M router devices. Attackers can exploit this common vulnerability to conduct effective routing loop attacks, inducing DoS to the ISP’s and home routers with an amplification factor of >200. We responsibly disclose those issues to all involved vendors and ASes and discuss mitigation solutions. Our research results indicate that the security community should revisit IPv6 network strategies immediately.

Authors. Xiang Li, Baojun Liu, Xiaofeng Zheng, Haixin Duan, Qi Li, Youjun Huang.

Conference. Proceedings of the 2021 IEEE/IFIP International Conference on Dependable Systems and Networks (DSN '21)

Paper. [PDF], [Slides] and [Video].

CNVD/CVE. [Lists]. License and CopyrightX[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Xmap - A Fast Network Scanner Designed For Performing Internet-wide IPv6 &Amp; IPv4 Network Research Scanning https://blogger.googleusercontent.com/img/a/AVvXsEiIykjf6pqIxFErLOWXeKbCoONaK4Vd-4egAmOuIUTd6DLoQuUxne5mGJrBRGJI2_r4Jk…
Map Copyright 2021 Xiang Li from Network and Information Security Lab Tsinghua University

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See LICENSE for the specific language governing permissions and limitations under the License. Download Xmap

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
6 Lessons From the Expiration of the Let's Encrypt Root Certificate

Fallout from the transition highlights the need for organizations to monitor and have processes for updating CA roots, experts say.
GoPhish tracking email malfunction!
https://www.reddit.com/r/redteamsec/comments/q7zzsf/gophish_tracking_email_malfunction/

Hello everyone, I'm doing local phishing simulation with gophish but cant seem to track whenever I open the email. Quick lab guide: ​ [SERVER SIDE] GoPhish running on kali and port 80 is exposed to the whole /24 network. GoPhish is setup with gmail smtp with less secure apps enabled. Tracker image is added to every email template I use. ​ [CLIENT SIDE] Windows 10 fully pathed and updated, running outlook 2016 and gmail through web browser. ​ [OBSERVATION] When phishing emails are opened from web (gmail) all of the images load but still gophish does not note the action. When phishing emails are opened from Outlook 2016 the images do not render unless you click pop up > download all images and then gophish notes this action and counts email to be opened. ​ [QUESTION] Is there a way to bypass this pop-up action and gmail security to count email being open without performing additional actions? ​ Thanks :) submitted by /u/luzunov (https://www.reddit.com/user/luzunov)
[link] (https://www.reddit.com/r/redteamsec/comments/q7zzsf/gophish_tracking_email_malfunction/) [comments] (https://www.reddit.com/r/redteamsec/comments/q7zzsf/gophish_tracking_email_malfunction/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CarPunk : The Car Hacking Toolkit

CarPunk IS VERY SIMILAR TO CANghost, ONLY THE DEFFERENCE IS, IT COMES WITH OPTIONS TO ENABLE OR DISABLE INTERFACE AND BASIC SNIFFING AS EXTRA.

* IT WORKS ON BOTH SIMULATION & REAL CARS.
* HAS THE OPTIONS TO RECORD AND PLAY THE CAN PACKETS.
* NO ANY ARGUMENTS REQUIRED WHEN RUNNING BUT NEED CHANGES(Interface & Name for logfile), IF YOU’RE TRYING IN REAL-WORLD.
* TESTED ON UBUNTU WITH BOTH SIMULATOR & REAL CARS.

THINGS TO DO BEFORE RUNNING CARPUNK

* YOU HAVE TO LOAD YOUR CANBUS DRIVER MANUALLY, CARPUNK ONLY DOES UP AND DOWN.
* OPEN carpunk.sh FILE INTO YOUR FAVORITE TEXT-EDITOR AND CHANGE THE INTERFACE AND LOG-FILENAME AS PER YOUR NEED. DELAFULT INTERFCE IS vcan0 & carpunk AS LOG-FILENAME.
* Installation & Usage of CarPunk :

git clone https://github.com/souravbaghz/CarPunk
cd CarPunk
sudo bash carpunk.sh
https://blogger.googleusercontent.com/img/a/AVvXsEhCqc_1M1I_4YgT-CZ9BFEBLTkDWD_7vLNmByECwTBKSSlGIpu7XWpysKcOqbNhSBXfz1tUvaCsHewiXVwjpOanSMEEU23JTl2YjCJ8uJw6SZ0q-6j8KyqfxlG44Xmh3jRGunlHaIECBMPz511HXjA8XPbAi5WM4EMFNYpiWUlDD5xn0Vm7ORcr5-2c=s1851
* [1] UP the CAN Interface : To Enable/UP the CAN Interface.
* [2] Down the CAN Interface : Make The CAN Interface Down.
* [3] Start the Basic Sniffing : To Start Sniffing Only(get terminal clear as soon as you stop it by ctrl+c).
* [4] Record the CAN Packets : To Capture/Record The CAN Packets Into File(as carpunk1.log- name will be carpunk2.log,carpunk3.log,so on for multiple times).
* [5] Play the CAN Packets : Replay The CAN Packets Which You Captured Earlier(Need to specify the log-file. e.g: carpunk1.log).
* [0] Exit : To Exit The CarPunk Script.
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
GIF
Kali Linux Tutorials
BurpCrypto : A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)

Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).

Build

$ mvn package

Usage

中文使用说明

* Download the precompiled jar package from Releases.
* Add this jar package to your burpsuite’s Extensions.
* Switch to BurpCrypto tab, select you need Cipher tab.
* Set key or some value.
* press “Add processor”, and give a name for this processor.
* Switch to Intruder->Payloads->Payload Processing.
* press “Add”, select “Invoke Burp extension”, and select processor you just created.
* press “Start attack”, have fun!

Key Example

* Aes Key(UTF8String): abcdefgabcdefg12
* Aes IV(UTF8String): abcdefgabcdefg12
* Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQAB
* Rsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07
* Rsa Exponent: 010001
* DES Key: 12345678
* DESede Key: 123456781234567812345678

Screenshots

AES Example:
https://1.bp.blogspot.com/-jz5UtZAmt4w/YV2d4YZsexI/AAAAAAAALCs/jbwM3zTeuvYxdf23rK0gGW_qRMQB1vgbgCLcBGAsYHQ/s1409/1.gif
ExecJs Example (Here is the modified MD5 algorithm):
https://1.bp.blogspot.com/--D5NTnQsoVs/YV2fbyR7EhI/AAAAAAAALC0/1s92_bJxso40eASDbelps1c3_HByAbeyQCLcBGAsYHQ/s1297/2.gif
Quick Crypto:
https://1.bp.blogspot.com/-899xj4IgMEM/YV2glZ6m_rI/AAAAAAAALC8/BawsFGyiB0spder-9qxOpPCIzr6yckGuACLcBGAsYHQ/s1048/3.gif

Download

___________________________
@hacking_Attack
@Hacking_Video
Finding known exploits for bugbounties.

Hello everyone, in this blog we will be looking at how I found criticals on a private program using known vulnerabilities. This is a…Continue reading on Medium »
Read more...
Into the art of Binary Exploitation 0x000003 [Prominence of Integer-Overflow]

Hey hackers , I’m back again with another portion of our enterprise, the binary exploitation series. In case you’re perusing my article…Continue reading on InfoSec Write-ups »
Read more...