hacking: security in practice
NVME firmware unlock
Currently the market is about flooded with a western digital (sandisk) NVME drive model CH SN530 labeled as a 1TB, this drive is very small in the 2230 formfactor, and is what is used for xbox series S. formatted, this drive is only 867GB, and from what i read, this is something to do with a reserved portion for xbox. the commercial unit is a PC SN530, which i imagine has the full amount available. Does anyone know any more about this drive, or some user base the plays with firmware? I came accross a gnome blog with a user called u/hughsie , unsure if this is uncharted waters for all or just me? I'm going to be installing this in a r/SteamDeck and would be cool to use the full amount of the chip. ~940GB.
thanks
submitted by /u/Jgsieve
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
NVME firmware unlock
Currently the market is about flooded with a western digital (sandisk) NVME drive model CH SN530 labeled as a 1TB, this drive is very small in the 2230 formfactor, and is what is used for xbox series S. formatted, this drive is only 867GB, and from what i read, this is something to do with a reserved portion for xbox. the commercial unit is a PC SN530, which i imagine has the full amount available. Does anyone know any more about this drive, or some user base the plays with firmware? I came accross a gnome blog with a user called u/hughsie , unsure if this is uncharted waters for all or just me? I'm going to be installing this in a r/SteamDeck and would be cool to use the full amount of the chip. ~940GB.
thanks
submitted by /u/Jgsieve
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
NVME firmware unlock
Currently the market is about flooded with a western digital (sandisk) NVME drive model CH SN530 labeled as a 1TB, this drive is very small in the...
hacking: security in practice
Bruteforce
Is there a brute force that will type a username and password into a window for me?
I been looking into bruteforce but most require you to already have the hash?
submitted by /u/Tgottie5
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Bruteforce
Is there a brute force that will type a username and password into a window for me?
I been looking into bruteforce but most require you to already have the hash?
submitted by /u/Tgottie5
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bruteforce
Is there a brute force that will type a username and password into a window for me? I been looking into bruteforce but most require you to...
hacking: security in practice
Bruteforce
I am trying to get into my DVR, I no longer have the admin password. I tried to use some applications for bruteforce, but most seem to require the hash file.
Is there a program that will type in password for me? The dvr is log on able from the computer, I can attempt the password as many times as possible with no penalty.
submitted by /u/Tgottie5
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Bruteforce
I am trying to get into my DVR, I no longer have the admin password. I tried to use some applications for bruteforce, but most seem to require the hash file.
Is there a program that will type in password for me? The dvr is log on able from the computer, I can attempt the password as many times as possible with no penalty.
submitted by /u/Tgottie5
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bruteforce
I am trying to get into my DVR, I no longer have the admin password. I tried to use some applications for bruteforce, but most seem to require the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SysmonForLinux — Logging File Create Events
https://cdn-images-1.medium.com/max/1000/1*RqcQecp3Ot502htmHOuZ8w.jpeg
In this article, I will explain how to use SysmonForLinux for creating specific configurations to keep track of file creation events.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SysmonForLinux — Logging File Create Events
https://cdn-images-1.medium.com/max/1000/1*RqcQecp3Ot502htmHOuZ8w.jpeg
In this article, I will explain how to use SysmonForLinux for creating specific configurations to keep track of file creation events.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SysmonForLinux — Logging File Create Events
In this article, I will explain how to use SysmonForLinux for creating specific configurations to keep track of file creation events.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Twitch, Protect Your Streamers
https://cdn-images-1.medium.com/max/1000/0*8Yqy3OxYHHakFD0i
Who did the Twitch hacks hurt the most?
Continue reading on SUPERJUMP »
___________________________
@hacking_Attack
@Hacking_Video
Twitch, Protect Your Streamers
https://cdn-images-1.medium.com/max/1000/0*8Yqy3OxYHHakFD0i
Who did the Twitch hacks hurt the most?
Continue reading on SUPERJUMP »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Twitch, Protect Your Streamers
Who did the Twitch hacks hurt the most?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Malware Analysis
Hi Fam! Today we’re gonna talk about a term we have preety much come across or heard about it in the field of Digital Security i.e
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Malware Analysis
Hi Fam! Today we’re gonna talk about a term we have preety much come across or heard about it in the field of Digital Security i.e
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Malware Analysis
Hi Fam! Today we’re gonna talk about a term we have preety much come across or heard about it in the field of Digital Security i.e “Malware…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CreatureToadz Discord Hack
https://cdn-images-1.medium.com/max/1060/1*Kg-vp8_LmBVg32K34D06_g.png
The attack on Discord represented an assault on what has been, since the inception of NFT-based communities, a pillar of trust. The formal…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CreatureToadz Discord Hack
https://cdn-images-1.medium.com/max/1060/1*Kg-vp8_LmBVg32K34D06_g.png
The attack on Discord represented an assault on what has been, since the inception of NFT-based communities, a pillar of trust. The formal…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CreatureToadz Discord Hack
The attack on Discord represented an assault on what has been, since the inception of NFT-based communities, a pillar of trust. The formal…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Building a simple reverse shell on Windows with Netcat (Part 2)
https://cdn-images-1.medium.com/max/2600/0*cKT3hboN4gBzZDis
After understanding how we can set up a reverse shell using Netcat, following part one of this serie, let’s talk about how to hide the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Building a simple reverse shell on Windows with Netcat (Part 2)
https://cdn-images-1.medium.com/max/2600/0*cKT3hboN4gBzZDis
After understanding how we can set up a reverse shell using Netcat, following part one of this serie, let’s talk about how to hide the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Building a simple reverse shell on Windows with Netcat (Part 2)
After understanding how we can set up a reverse shell using Netcat, following part one of this serie, let’s talk about how to hide the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack This Site: Javascript Mission — Level 2
https://cdn-images-1.medium.com/max/2000/0*wNF0mqONOWlVh3aV
Introduction
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Hack This Site: Javascript Mission — Level 2
https://cdn-images-1.medium.com/max/2000/0*wNF0mqONOWlVh3aV
Introduction
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack This Site: Javascript Mission — Level 2
Introduction
Metabadger - Prevent SSRF Attacks On AWS EC2 Via Automated Upgrades To The More Secure Instance Metadata Service V2 (IMDSv2)
http://www.kitploit.com/2021/10/metabadger-prevent-ssrf-attacks-on-aws.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/10/metabadger-prevent-ssrf-attacks-on-aws.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Problem Statement
Engineering teams may have a vast variety of compute infrastructure (https://www.kitploit.com/search/label/Infrastructure) in AWS that they need to protect from certain vulnerabilities that leverage the metadata service. The metadata service is required to run on instances if any IAM is used or if there is any user data information the instance might need when it boots. Limiting the attack surface of your instances is crucial in preventing the ability to pivot in your environment by stealing information provided by the service itself. Numerous famous attacks in the past have leveraged this particular service to exploit a role that is attached to the instance or dump sensitive data that is accessible via the metadata service. Metabadger can help to identify where and how you are using the instance metadata service while also giving you the ability to reduce any unwanted attack leverage to lower your overall risk posture while operating in EC2.
Disclaimer and Rollback
Using this tool may impact your AWS compute infrastructure as not all services and applications may work either without the metadata service or on version 2. Take caution when deploying this in your production environment and have a rollback plan in place incase something seems out of the ordinary. Metabadger comes built in with the ability to roll back to the default version 1 of the service using the -v1 flag, you can use this to quickly roll back your instances to use the default. Ideally, you should run this tool and update your metadata version in non-production environments as a proving grounds before applying it.
Guided Steps for Hardening
Step 1Initially, we want to discover our overall usage of the metadata service in a particular AWS region. Metabadger will evaluate the current status of your usage in the region where your credentials point to in your /.aws/credentials file or the current role that is assumed. You may also specify the --region flag when running the discover-metadata command if you would like to change to another region than what is currently configured. Once you have a good idea of which version your instances are running and if the service is enabled or disabled, you will be able to make a much more defined action plan for hardening the service. Note that you can find specific meaning to every metadata option that is set here (https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/modify-instance-metadata-options.html).Step 2One of the areas that should be evaluated when making the switch to v2 of the service is the use of IAM roles. Metabadger lets you identify instances in a region that may already be using an IAM role. The discover-role-usage command will output a list of instances that have roles attached to them. If you have a lot of instances using roles, you should take precaution when updating the service to v2 to ensure the overall functionality of your workloads does not become impacted.Step 3Upon completion of doing your initial discovery and evaluation, you can now create a staged approach to hardening your compute infrastructure to use either v2 of the metadata service or disable it where it may not be used. The harden-metadata command allows you to update all instances in a particular region by default. You can also pass instance tags using the --tags flag or an input file containing a csv of instances that you would like to apply a configuration for. Once you have made the appropriate updates to v2 and disabled the service where it is not used you can re-evaluate using the items in Step 1 to confirm your environment is locked down. If you have certain instances that you don't want to update you can exlude them via the --exclusion flag by tag or instance id.
Requirements
Metabadger requires an IAM role or credentials with the following permission:ec2:ModifyInstanceAttribute
___________________________
@hacking_Attack
@Hacking_Video
Engineering teams may have a vast variety of compute infrastructure (https://www.kitploit.com/search/label/Infrastructure) in AWS that they need to protect from certain vulnerabilities that leverage the metadata service. The metadata service is required to run on instances if any IAM is used or if there is any user data information the instance might need when it boots. Limiting the attack surface of your instances is crucial in preventing the ability to pivot in your environment by stealing information provided by the service itself. Numerous famous attacks in the past have leveraged this particular service to exploit a role that is attached to the instance or dump sensitive data that is accessible via the metadata service. Metabadger can help to identify where and how you are using the instance metadata service while also giving you the ability to reduce any unwanted attack leverage to lower your overall risk posture while operating in EC2.
Disclaimer and Rollback
Using this tool may impact your AWS compute infrastructure as not all services and applications may work either without the metadata service or on version 2. Take caution when deploying this in your production environment and have a rollback plan in place incase something seems out of the ordinary. Metabadger comes built in with the ability to roll back to the default version 1 of the service using the -v1 flag, you can use this to quickly roll back your instances to use the default. Ideally, you should run this tool and update your metadata version in non-production environments as a proving grounds before applying it.
Guided Steps for Hardening
Step 1Initially, we want to discover our overall usage of the metadata service in a particular AWS region. Metabadger will evaluate the current status of your usage in the region where your credentials point to in your /.aws/credentials file or the current role that is assumed. You may also specify the --region flag when running the discover-metadata command if you would like to change to another region than what is currently configured. Once you have a good idea of which version your instances are running and if the service is enabled or disabled, you will be able to make a much more defined action plan for hardening the service. Note that you can find specific meaning to every metadata option that is set here (https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/modify-instance-metadata-options.html).Step 2One of the areas that should be evaluated when making the switch to v2 of the service is the use of IAM roles. Metabadger lets you identify instances in a region that may already be using an IAM role. The discover-role-usage command will output a list of instances that have roles attached to them. If you have a lot of instances using roles, you should take precaution when updating the service to v2 to ensure the overall functionality of your workloads does not become impacted.Step 3Upon completion of doing your initial discovery and evaluation, you can now create a staged approach to hardening your compute infrastructure to use either v2 of the metadata service or disable it where it may not be used. The harden-metadata command allows you to update all instances in a particular region by default. You can also pass instance tags using the --tags flag or an input file containing a csv of instances that you would like to apply a configuration for. Once you have made the appropriate updates to v2 and disabled the service where it is not used you can re-evaluate using the items in Step 1 to confirm your environment is locked down. If you have certain instances that you don't want to update you can exlude them via the --exclusion flag by tag or instance id.
Requirements
Metabadger requires an IAM role or credentials with the following permission:ec2:ModifyInstanceAttribute
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
ec2:DescribeInstancesWhen making changes to the Instance Metadata service, you should be cautious and follow additional guidance from AWS on how to safely upgrade to version 2. Metabadger was designed to assist you with this process to further secure your compute infrastructure in AWS.AWS Best Practice Guide on Updating to IMDSv2 (https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html)
Usage & Installation
Install via pippip3 install --user metabadger
Install via Github$ git clone https://github.com/salesforce/metabadger
$ cd metabadger
$ pip install -e .
$ metabadger
Usage: metabadger [OPTIONS] COMMAND [ARGS]...
Metabadger is an AWS Security Tool used for discovering and hardening the
Instance Metadata service.
Options:
--version Show the version and exit.
--help Show this message and exit.
Commands:
disable-metadata Disable the IMDS service on EC2 instances
discover-metadata Discover summary of IMDS service usage within EC2
discover-role-usage Discover summary of IAM role usage for EC2
harden-metadata Harden the AWS instance metadata service from v1 to v2
Commands
discover-metadataA summary of your overall instance metadata service usage including which version and an overall enforcement percentage. Using these numbers will help you understand the overall posture of how hardened your metadata usage is and where you're enforcing v2 vs v1.Options:
-a, --all-region Provide a metadata summary for all available regions in the AWS account
-j, --json Get metadata summary in JSON format
-r, --region TEXT Specify which AWS region you will perform this command in
-p, --profile TEXT Specify the AWS IAM profile.
discover-role-usageA summary of instances and the roles that they are using, this will give you a good idea of the caution you must take when making updates to the metadata service itself.Options:
-p, --profile TEXT Specify the AWS IAM profile.
-r, --region TEXT Specify which AWS region you will perform this command in
harden-metadataThe ability to modify the instances to use either metadata v1 or v2 and to get an understanding of how many instances would be modified by running a dry run mode.Options:
-e, --exclusion The exclusion flag will apply to everything besides what is specified, tags or instances
-d, --dry-run Dry run of hardening metadata changes
-v1, --v1 Enforces v1 of the metadata service
-i, --input-file PATH Path of csv file of instances to harden IMDS for
-t, --tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, --region TEXT Specify which AWS region you will perform this command in
-p, --profile TEXT Specify the AWS IAM profile.
disable-metadataUse this command to completely disable the metadata servie on instances.Options:
-e, --exclusion The exclusion flag will apply to everything besides what is specified, tags or instances
-d, --dry-run Dry run of disabling the metadata service
-i, --input-file PATH Path of csv file of instances to disable IMDS for
-t, --tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, --region TEXT Specify which AWS region you will perform this command in
-p, --profile TEXT Specify the AWS IAM profile.
Logging
All changes made by Metabadger will be logged to a file saved in the working directory called metabadger.log. The file will include the following for every action that the tool takes when it changes the metadata service:The time and date stamp for when a change was madeChange that occured (disabled, hardened, or updated)The instance ID where the change was madeDry run informationA status on if the change was successful or not
___________________________
@hacking_Attack
@Hacking_Video
Usage & Installation
Install via pippip3 install --user metabadger
Install via Github$ git clone https://github.com/salesforce/metabadger
$ cd metabadger
$ pip install -e .
$ metabadger
Usage: metabadger [OPTIONS] COMMAND [ARGS]...
Metabadger is an AWS Security Tool used for discovering and hardening the
Instance Metadata service.
Options:
--version Show the version and exit.
--help Show this message and exit.
Commands:
disable-metadata Disable the IMDS service on EC2 instances
discover-metadata Discover summary of IMDS service usage within EC2
discover-role-usage Discover summary of IAM role usage for EC2
harden-metadata Harden the AWS instance metadata service from v1 to v2
Commands
discover-metadataA summary of your overall instance metadata service usage including which version and an overall enforcement percentage. Using these numbers will help you understand the overall posture of how hardened your metadata usage is and where you're enforcing v2 vs v1.Options:
-a, --all-region Provide a metadata summary for all available regions in the AWS account
-j, --json Get metadata summary in JSON format
-r, --region TEXT Specify which AWS region you will perform this command in
-p, --profile TEXT Specify the AWS IAM profile.
discover-role-usageA summary of instances and the roles that they are using, this will give you a good idea of the caution you must take when making updates to the metadata service itself.Options:
-p, --profile TEXT Specify the AWS IAM profile.
-r, --region TEXT Specify which AWS region you will perform this command in
harden-metadataThe ability to modify the instances to use either metadata v1 or v2 and to get an understanding of how many instances would be modified by running a dry run mode.Options:
-e, --exclusion The exclusion flag will apply to everything besides what is specified, tags or instances
-d, --dry-run Dry run of hardening metadata changes
-v1, --v1 Enforces v1 of the metadata service
-i, --input-file PATH Path of csv file of instances to harden IMDS for
-t, --tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, --region TEXT Specify which AWS region you will perform this command in
-p, --profile TEXT Specify the AWS IAM profile.
disable-metadataUse this command to completely disable the metadata servie on instances.Options:
-e, --exclusion The exclusion flag will apply to everything besides what is specified, tags or instances
-d, --dry-run Dry run of disabling the metadata service
-i, --input-file PATH Path of csv file of instances to disable IMDS for
-t, --tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, --region TEXT Specify which AWS region you will perform this command in
-p, --profile TEXT Specify the AWS IAM profile.
Logging
All changes made by Metabadger will be logged to a file saved in the working directory called metabadger.log. The file will include the following for every action that the tool takes when it changes the metadata service:The time and date stamp for when a change was madeChange that occured (disabled, hardened, or updated)The instance ID where the change was madeDry run informationA status on if the change was successful or not
___________________________
@hacking_Attack
@Hacking_Video
Amazon
Use the Instance Metadata Service to access instance metadata - Amazon Elastic Compute Cloud
Use the Instance Metadata Service (IMDS) to access instance metadata from an Amazon EC2 instance.