Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Symfonos — Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/705/0*dQJ6IjaZ2AxfYIh2.png
Difficulty : Easy
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Symfonos — Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/705/0*dQJ6IjaZ2AxfYIh2.png
Difficulty : Easy
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Symfonos — Vulnhub Walkthrough
Difficulty : Easy
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Evolution of Data.
https://cdn-images-1.medium.com/max/2600/1*PqhSpiLQ5fO8w8tzf3fRiA.jpeg
In today’s date and time data is more important than anything else. It is actually correct to say now that data is more expensive than…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Evolution of Data.
https://cdn-images-1.medium.com/max/2600/1*PqhSpiLQ5fO8w8tzf3fRiA.jpeg
In today’s date and time data is more important than anything else. It is actually correct to say now that data is more expensive than…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Evolution of Data.
In today’s date and time data is more important than anything else. It is actually correct to say now that data is more expensive than…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Google: YouTubers’ accounts hijacked with cookie-stealing malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Google: YouTubers’ accounts hijacked with cookie-stealing malwarePost Views: 115
Reading Time: 1 Minute
Google says YouTube creators have been targeted with password-stealing malware in phishing attacks coordinated by financially motivated threat actors.
Researchers with Google’s Threat Analysis Group (TAG), who first spotted the campaign in late 2019, found that multiple hack-for-hire actors recruited via job ads on Russian-speaking forums were behind these attacks.
The threat actors used social engineering (via fake software landing pages and social media accounts) and phishing emails to infect YouTube creators with information-stealing malware, chosen based on each attacker’s preference. Channels hijacked in pass-the-cookie attacksMalware observed in the attacks includes commodity strains like RedLine, Vidar, Predator The Thief, Nexus stealer, Azorult, Raccoon, Grand Stealer, Vikro Stealer, Masad, and Kantal, as well as open-source ones like AdamantiumThief and leaked tools such as Sorano.
Once delivered on the targets’ systems, the malware was used to steal their credentials and browser cookies which allowed the attackers to hijack the victims’ accounts in pass-the-cookie attacks.
“While the technique has been around for decades, its resurgence as a top security risk could be due to a wider adoption of multi-factor authentication (MFA) making it difficult to conduct abuse, and shifting attacker focus to social engineering tactics,” said Ashley Shen, a TAG Security Engineer.
See Also: Complete Offensive Security and Ethical Hacking Course
“Most of the observed malware was capable of stealing both user passwords and cookies. Some of the samples employed several anti-sandboxing techniques including enlarged files, encrypted archive and download IP cloaking.”
Google identified at least 1,011 domains linked to these attacks and roughly 15,000 actor accounts specifically created for this campaign and used to deliver phishing emails containing links redirecting to malware landing pages to YouTube creators’ business emails.
https://www.bleepstatic.com/images/news/u/1109292/2021/Attack%20flow(1).png
Sold for up to $4,000 on underground marketsA significant number of YouTube channels hijacked in these attacks were later rebranded to impersonate high-profile tech executives or cryptocurrency exchange firms and used for live streaming cryptocurrency scams.
Others were sold on underground account-trading markets, where they’re worth anything between $3 to $4,000, depending on their total number of subscribers.
Shen added that Google’s Threat Analysis Group cut down phishing emails linked to these attacks on Gmail by 99.6% since May 2021. “We blocked 1.6M messages to targets, displayed ~62K Safe Browsing phishing page warnings, blocked 2.4K files, and successfully restored ~4K accounts,” Shen said.
“With increased detection efforts, we’ve observed attackers shifting away from Gmail to other email providers (mostly email.cz, seznam.cz, post.cz and aol.com).”
Google also reported this malicious activity to the FBI for further investigation to protect YouTube users and creators targeted in the campaign.
See Also: Offensive Security Tool: Dalfox See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10[...]
___________________________
@hacking_Attack
@Hacking_Video
Google: YouTubers’ accounts hijacked with cookie-stealing malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Google: YouTubers’ accounts hijacked with cookie-stealing malwarePost Views: 115
Reading Time: 1 Minute
Google says YouTube creators have been targeted with password-stealing malware in phishing attacks coordinated by financially motivated threat actors.
Researchers with Google’s Threat Analysis Group (TAG), who first spotted the campaign in late 2019, found that multiple hack-for-hire actors recruited via job ads on Russian-speaking forums were behind these attacks.
The threat actors used social engineering (via fake software landing pages and social media accounts) and phishing emails to infect YouTube creators with information-stealing malware, chosen based on each attacker’s preference. Channels hijacked in pass-the-cookie attacksMalware observed in the attacks includes commodity strains like RedLine, Vidar, Predator The Thief, Nexus stealer, Azorult, Raccoon, Grand Stealer, Vikro Stealer, Masad, and Kantal, as well as open-source ones like AdamantiumThief and leaked tools such as Sorano.
Once delivered on the targets’ systems, the malware was used to steal their credentials and browser cookies which allowed the attackers to hijack the victims’ accounts in pass-the-cookie attacks.
“While the technique has been around for decades, its resurgence as a top security risk could be due to a wider adoption of multi-factor authentication (MFA) making it difficult to conduct abuse, and shifting attacker focus to social engineering tactics,” said Ashley Shen, a TAG Security Engineer.
See Also: Complete Offensive Security and Ethical Hacking Course
“Most of the observed malware was capable of stealing both user passwords and cookies. Some of the samples employed several anti-sandboxing techniques including enlarged files, encrypted archive and download IP cloaking.”
Google identified at least 1,011 domains linked to these attacks and roughly 15,000 actor accounts specifically created for this campaign and used to deliver phishing emails containing links redirecting to malware landing pages to YouTube creators’ business emails.
https://www.bleepstatic.com/images/news/u/1109292/2021/Attack%20flow(1).png
Sold for up to $4,000 on underground marketsA significant number of YouTube channels hijacked in these attacks were later rebranded to impersonate high-profile tech executives or cryptocurrency exchange firms and used for live streaming cryptocurrency scams.
Others were sold on underground account-trading markets, where they’re worth anything between $3 to $4,000, depending on their total number of subscribers.
Shen added that Google’s Threat Analysis Group cut down phishing emails linked to these attacks on Gmail by 99.6% since May 2021. “We blocked 1.6M messages to targets, displayed ~62K Safe Browsing phishing page warnings, blocked 2.4K files, and successfully restored ~4K accounts,” Shen said.
“With increased detection efforts, we’ve observed attackers shifting away from Gmail to other email providers (mostly email.cz, seznam.cz, post.cz and aol.com).”
Google also reported this malicious activity to the FBI for further investigation to protect YouTube users and creators targeted in the campaign.
See Also: Offensive Security Tool: Dalfox See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Google: YouTubers’ accounts hijacked with cookie-stealing malware | Black Hat Ethical Hacking
Google says YouTube creators have been targeted with password-stealing malware in phishing attacks coordinated by financially motivated threat actors.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Google: YouTubers’ accounts hijacked with cookie-stealing malware https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Google: YouTubers’ accounts hijacked with cookie-stealing malwarePost Views:…
/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
The post Google: YouTubers’ accounts hijacked with cookie-stealing malware first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
The post Google: YouTubers’ accounts hijacked with cookie-stealing malware first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Python script to convert Ducky Script into AutoHotKey scripts
I think that the USB Rubber Ducky is such a cool and useful little tool, but it isn't exactly cheap. I have used AHK to get similar functionality a bit now, and I made this script to make converting payloads to AHK scripts a bit easier... I thought maybe I'm not the only one who could use something like this, so here is the script.
Let me know what you think about it.
submitted by /u/InActiveSoda
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Python script to convert Ducky Script into AutoHotKey scripts
I think that the USB Rubber Ducky is such a cool and useful little tool, but it isn't exactly cheap. I have used AHK to get similar functionality a bit now, and I made this script to make converting payloads to AHK scripts a bit easier... I thought maybe I'm not the only one who could use something like this, so here is the script.
Let me know what you think about it.
submitted by /u/InActiveSoda
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Python script to convert Ducky Script into AutoHotKey scripts
I think that the USB Rubber Ducky is such a cool and useful little tool, but it isn't exactly cheap. I have used AHK to get similar functionality...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hackers Stealing Browser Cookies to Hijack High-Profile YouTube Accounts
https://external-preview.redd.it/hBQpdtp7UtC1x2vfsT4n30d2y2LJDbp6w8dL6YTPopE.jpg?width=640&crop=smart&auto=webp&s=81749d5f633389e34e9031872bcceeaf807d8ea0 submitted by /u/CodePerfect
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hackers Stealing Browser Cookies to Hijack High-Profile YouTube Accounts
https://external-preview.redd.it/hBQpdtp7UtC1x2vfsT4n30d2y2LJDbp6w8dL6YTPopE.jpg?width=640&crop=smart&auto=webp&s=81749d5f633389e34e9031872bcceeaf807d8ea0 submitted by /u/CodePerfect
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hackers Stealing Browser Cookies to Hijack High-Profile YouTube...
Posted in r/hacking by u/CodePerfect • 278 points and 12 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
450M Cyberattacks Blocked During Tokyo Olympic Games
https://external-preview.redd.it/evIt8lFVP_l2dAjsw_vlCjFJFwSr7a40rgfDdiKwn4w.jpg?width=640&crop=smart&auto=webp&s=7287e4a5228c6ef872794a4f9b5c01f971ebe709 submitted by /u/george-alexander2k
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
450M Cyberattacks Blocked During Tokyo Olympic Games
https://external-preview.redd.it/evIt8lFVP_l2dAjsw_vlCjFJFwSr7a40rgfDdiKwn4w.jpg?width=640&crop=smart&auto=webp&s=7287e4a5228c6ef872794a4f9b5c01f971ebe709 submitted by /u/george-alexander2k
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
450M Cyberattacks Blocked During Tokyo Olympic Games
Posted in r/hacking by u/george-alexander2k • 5 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Free Training on CompTIA A+ Full Course
Hi everyone,
I'm currently delivering free training on the CompTIA A+ course. The course consists of 18 modules and I will be doing a dedicated video on each module. Some of these videos might be a bit long since it will be a whole module in each video so please feel free to make use of the time stamps in descriptions if your looking for specific topics only or just want to refresh on certain topics only.
The time stamps are there to make life easier for you so it's your own fault if you end up skimming through the module back and forth like a crazy person looking for their lost teeth.
I will make 20 videos for this course, the first is just the 4min intro explaining the course, the last will be a dedicated exam tips video and then obviously the 18 videos in between will be your modules.
The training should be enough to pass both the international exams for A+ and the other courses I deliver should also be enough to pass the exams associated if there is a exam associated to that specific course.
If you have a question about a specific topic in a module or the course in general that you would like more clarity on, please feel free to ask and I will try to assist you where I can if I'm online.
Here is the course intro
CompTIA A+ Course Intro
submitted by /u/BurningIce2020
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Free Training on CompTIA A+ Full Course
Hi everyone,
I'm currently delivering free training on the CompTIA A+ course. The course consists of 18 modules and I will be doing a dedicated video on each module. Some of these videos might be a bit long since it will be a whole module in each video so please feel free to make use of the time stamps in descriptions if your looking for specific topics only or just want to refresh on certain topics only.
The time stamps are there to make life easier for you so it's your own fault if you end up skimming through the module back and forth like a crazy person looking for their lost teeth.
I will make 20 videos for this course, the first is just the 4min intro explaining the course, the last will be a dedicated exam tips video and then obviously the 18 videos in between will be your modules.
The training should be enough to pass both the international exams for A+ and the other courses I deliver should also be enough to pass the exams associated if there is a exam associated to that specific course.
If you have a question about a specific topic in a module or the course in general that you would like more clarity on, please feel free to ask and I will try to assist you where I can if I'm online.
Here is the course intro
CompTIA A+ Course Intro
submitted by /u/BurningIce2020
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Free Training on CompTIA A+ Full Course
Hi everyone, I'm currently delivering free training on the CompTIA A+ course. The course consists of 18 modules and I will be doing a dedicated...
NTFSTool - Forensics Tool For NTFS (Parser, MTF, Bitlocker, Deleted Files)
http://www.kitploit.com/2021/10/ntfstool-forensics-tool-for-ntfs-parser.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/10/ntfstool-forensics-tool-for-ntfs-parser.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Bitlocker support
For bitlocked partition, it can display FVE records, check a password and key (bek, password, recovery key), extract VMK and FVEK. There is no bruteforce (https://www.kitploit.com/search/label/Bruteforce) feature because GPU-based cracking is better (see Bitcracker (https://arxiv.org/pdf/1901.01337) and Hashcat (https://hashcat.net/hashcat/)) but you can get the hash for these tools.
EFS support
In the current version, masterkeys, private keys and certificates (https://www.kitploit.com/search/label/Certificates) can be listed, displayed and decrypted using needed inputs (SID, password). Certificates with private keys can be exported using the backup command. Reinmport the backup on another machine to be able to read your encrypted file again!More information on Mimikatz Wiki (https://github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files#installing-the-pfx)Decryption of EFS encrypted files is coming!
Shell
There is a limited shell with few commands (exit, cd, ls, cat, pwd, cp).
Help & Examples
Help command displays description and examples for each command. Options can be entered as decimal or hex number with "0x" prefix (ex: inode).ntfstool help [command]
CommandDescriptioninfo (https://github.com/thewhiteninja/ntfstool#info)Display information for all disks and volumesmbr (https://github.com/thewhiteninja/ntfstool#mbr)Display MBR structure, code and partitions for a diskgpt (https://github.com/thewhiteninja/ntfstool#gpt)Display GPT structure, code and partitions for a diskvbr (https://github.com/thewhiteninja/ntfstool#vbr)Display VBR structure and code for a specidifed volume (ntfs, fat32, fat1x, bitlocker supported)extract (https://github.com/thewhiteninja/ntfstool#extract)Extract a file from a volume.image (https://github.com/thewhiteninja/ntfstool#image)Create an image file of a disk or volume.mft (https://github.com/thewhiteninja/ntfstool#mft)Display FILE record details for a specified MFT inode. Almost all attribute types supportedbtree (https://github.com/thewhiteninja/ntfstool#btree)Display VCN content and Btree index for an inodebitlocker (https://github.com/thewhiteninja/ntfstool#bitlocker)Display detailed information and hash ($bitlocker$) for all VMK. It is possible to test a password or recovery key. If it is correct, the decrypted VMK and FVEK is displayed.bitdecrypt (https://github.com/thewhiteninja/ntfstool#bitdecrypt)Decrypt a volume to a file using password, recovery key or bek.efs.backup (https://github.com/thewhiteninja/ntfstool#efs-backup)Export EFS keys in PKCS12 (pfx) format.efs.certificate (https://github.com/thewhiteninja/ntfstool#efs-certificate)List, display and export system certificates (SystemCertificates/My/Certificates).efs.key (https://github.com/thewhiteninja/ntfstool#efs-key)List, display, decrypt and export private keys (Crypto/RSA).efs.masterkey (https://github.com/thewhiteninja/ntfstool#efs-masterkey)List, display and decrypt masterkeys (Protect).fve (https://github.com/thewhiteninja/ntfstool#fve)Display information for the specified FVE block (0, 1, 2)reparse (https://github.com/thewhiteninja/ntfstool#reparse)Parse and display reparse points from $Extend$Reparse.logfile (https://github.com/thewhiteninja/ntfstool#logfile)Dump $LogFile file in specified format: csv, json, raw.usn (https://github.com/thewhiteninja/ntfstool#usn)Dump $UsnJrnl file in specified format: csv, json, raw.shadow (https://github.com/thewhiteninja/ntfstool#shadow)List volume shadow snapshots from selected disk and volume.streams (https://github.com/thewhiteninja/ntfstool#streams)Display Alternate Data Streamsundelete (https://github.com/thewhiteninja/ntfstool#undelete)Search and extract deleted files for a volume.shell (https://github.com/thewhiteninja/ntfstool#shell-1)Start a mini Unix-like shellsmart (https://github.com/thewhiteninja/ntfstool#smart)Display S.M.A.R.T data
Limitations
Some unsupported cases. WIP.No documentationFeel free to open an issue or ask for a new feature!
Build
___________________________
@hacking_Attack
@Hacking_Video
For bitlocked partition, it can display FVE records, check a password and key (bek, password, recovery key), extract VMK and FVEK. There is no bruteforce (https://www.kitploit.com/search/label/Bruteforce) feature because GPU-based cracking is better (see Bitcracker (https://arxiv.org/pdf/1901.01337) and Hashcat (https://hashcat.net/hashcat/)) but you can get the hash for these tools.
EFS support
In the current version, masterkeys, private keys and certificates (https://www.kitploit.com/search/label/Certificates) can be listed, displayed and decrypted using needed inputs (SID, password). Certificates with private keys can be exported using the backup command. Reinmport the backup on another machine to be able to read your encrypted file again!More information on Mimikatz Wiki (https://github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files#installing-the-pfx)Decryption of EFS encrypted files is coming!
Shell
There is a limited shell with few commands (exit, cd, ls, cat, pwd, cp).
Help & Examples
Help command displays description and examples for each command. Options can be entered as decimal or hex number with "0x" prefix (ex: inode).ntfstool help [command]
CommandDescriptioninfo (https://github.com/thewhiteninja/ntfstool#info)Display information for all disks and volumesmbr (https://github.com/thewhiteninja/ntfstool#mbr)Display MBR structure, code and partitions for a diskgpt (https://github.com/thewhiteninja/ntfstool#gpt)Display GPT structure, code and partitions for a diskvbr (https://github.com/thewhiteninja/ntfstool#vbr)Display VBR structure and code for a specidifed volume (ntfs, fat32, fat1x, bitlocker supported)extract (https://github.com/thewhiteninja/ntfstool#extract)Extract a file from a volume.image (https://github.com/thewhiteninja/ntfstool#image)Create an image file of a disk or volume.mft (https://github.com/thewhiteninja/ntfstool#mft)Display FILE record details for a specified MFT inode. Almost all attribute types supportedbtree (https://github.com/thewhiteninja/ntfstool#btree)Display VCN content and Btree index for an inodebitlocker (https://github.com/thewhiteninja/ntfstool#bitlocker)Display detailed information and hash ($bitlocker$) for all VMK. It is possible to test a password or recovery key. If it is correct, the decrypted VMK and FVEK is displayed.bitdecrypt (https://github.com/thewhiteninja/ntfstool#bitdecrypt)Decrypt a volume to a file using password, recovery key or bek.efs.backup (https://github.com/thewhiteninja/ntfstool#efs-backup)Export EFS keys in PKCS12 (pfx) format.efs.certificate (https://github.com/thewhiteninja/ntfstool#efs-certificate)List, display and export system certificates (SystemCertificates/My/Certificates).efs.key (https://github.com/thewhiteninja/ntfstool#efs-key)List, display, decrypt and export private keys (Crypto/RSA).efs.masterkey (https://github.com/thewhiteninja/ntfstool#efs-masterkey)List, display and decrypt masterkeys (Protect).fve (https://github.com/thewhiteninja/ntfstool#fve)Display information for the specified FVE block (0, 1, 2)reparse (https://github.com/thewhiteninja/ntfstool#reparse)Parse and display reparse points from $Extend$Reparse.logfile (https://github.com/thewhiteninja/ntfstool#logfile)Dump $LogFile file in specified format: csv, json, raw.usn (https://github.com/thewhiteninja/ntfstool#usn)Dump $UsnJrnl file in specified format: csv, json, raw.shadow (https://github.com/thewhiteninja/ntfstool#shadow)List volume shadow snapshots from selected disk and volume.streams (https://github.com/thewhiteninja/ntfstool#streams)Display Alternate Data Streamsundelete (https://github.com/thewhiteninja/ntfstool#undelete)Search and extract deleted files for a volume.shell (https://github.com/thewhiteninja/ntfstool#shell-1)Start a mini Unix-like shellsmart (https://github.com/thewhiteninja/ntfstool#smart)Display S.M.A.R.T data
Limitations
Some unsupported cases. WIP.No documentationFeel free to open an issue or ask for a new feature!
Build
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Vcpkg is the best way to install required third-party libs.Install vcpkg as described here: vcpkg#getting-started (https://github.com/microsoft/vcpkg#getting-started)git clone https://github.com/microsoft/vcpkg
.\vcpkg\bootstrap-vcpkg.bat
Integrate it to your VisualStudio env:vcpkg integrate install
At build time, VisualStudio will detect the vcpkg.json file and install required packages automatically.Current third-party libs:openssl (https://www.openssl.org/): OpenSSL is an open source project that provides a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.nlohmann-json (https://github.com/nlohmann/json): JSON for Modern C++distorm (https://github.com/gdabah/distorm): Powerful Disassembler (https://www.kitploit.com/search/label/Disassembler) Library For x86/AMD64cppcoro (https://github.com/lewissbaker/cppcoro): A library of C++ coroutine abstractions for the coroutines TS.
Examples
Info
info+-------------------------------------------------------------------------------------+
| Id | Model | Type | Partition | Size |
+-------------------------------------------------------------------------------------+
| 0 | Samsung SSD 850 EVO 500GB | Fixed SSD | GPT | 500107862016 (465.76 GiBs) |
| 1 | ST2000DM001-1ER164 | Fixed HDD | GPT | 2000398934016 (1.82 TiB) |
| 2 | 15EADS External | Fixed HDD | MBR | 1500301910016 (1.36 TiB) |
| 3 | osfdisk | Fixed HDD | MBR | 536870912 (512.00 MiBs) |
+-------------------------------------------------------------------------------------+
info disk=3Model : osfdisk
Version : 1
Serial :
Media Type : Fixed HDD
Size : 536870912 (512.00 MiBs)
Geometry : 512 bytes * 63 sectors * 255 tracks * 65 cylinders
Volume : MBR
+--------------------------------------------------------------------------------------------------+
| Id | Boot | Label | Mounted | Filesystem | Offset | Size |
+--------------------------------------------------------------------------------------------------+
| 1 | No | NTFSDRIVE | F:\ | Bitlocker | 0000000000000200 | 000000001ffffe00 (512.00 MiBs) |
+--------------------------------------------------------------------------------------------------+
info disk=3 volume=1Serial Number : 0000aa60-00002eae
Filesystem : Bitlocker
Bootable : False
Type : Fixed
Label : NTFSDRIVE
Offset : 512 (512.00 bytes)
Size : 536870400 (512.00 MiBs)
Free : 519442432 (495.38 MiBs)
Mounted : True (F:\)
Bitlocker : True (Unlocked)
MBR
mbr disk=2MBR from \\.\PhysicalDrive2
---------------------------
Disk signature : e4589462
Reserved bytes : 0000
Partition table :
+---------------------------------------------------------------------------------------------------+
| Id | Boot | Flags | Filesystem | First sector | Last sector | Offset | Sectors | Size |
+---------------------------------------------------------------------------------------------------+
| 1 | No | Principal | NTFS / exFAT | 0 2 3 | 255 254 255 | 128 | 16771072 | 8.00 GiBs |
+---------------------------------------------------------------------------------------------------+
MBR signature : 55aa
Strings:
[63] : Invalid partition table
[7b] : Error loading operating system
[9a] : Missing operating system
Disassemble Bootstrap Code [y/N] ? y
0000 : 33c0 : xor ax, ax
0002 : 8ed0 : mov ss, ax
0004 : bc007c : mov sp, 0x7c00
0007 : 8ec0 : mov es, ax
0009 : 8ed8 : mov ds, ax
000b : be007c : mov si, 0x7c00
000e : bf0006 : mov di, 0x600
0011 : b90002 : mov cx, 0x200
...
GPT
gpt disk=1Signature : EFI PART
Revision : 1.0
___________________________
@hacking_Attack
@Hacking_Video
.\vcpkg\bootstrap-vcpkg.bat
Integrate it to your VisualStudio env:vcpkg integrate install
At build time, VisualStudio will detect the vcpkg.json file and install required packages automatically.Current third-party libs:openssl (https://www.openssl.org/): OpenSSL is an open source project that provides a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.nlohmann-json (https://github.com/nlohmann/json): JSON for Modern C++distorm (https://github.com/gdabah/distorm): Powerful Disassembler (https://www.kitploit.com/search/label/Disassembler) Library For x86/AMD64cppcoro (https://github.com/lewissbaker/cppcoro): A library of C++ coroutine abstractions for the coroutines TS.
Examples
Info
info+-------------------------------------------------------------------------------------+
| Id | Model | Type | Partition | Size |
+-------------------------------------------------------------------------------------+
| 0 | Samsung SSD 850 EVO 500GB | Fixed SSD | GPT | 500107862016 (465.76 GiBs) |
| 1 | ST2000DM001-1ER164 | Fixed HDD | GPT | 2000398934016 (1.82 TiB) |
| 2 | 15EADS External | Fixed HDD | MBR | 1500301910016 (1.36 TiB) |
| 3 | osfdisk | Fixed HDD | MBR | 536870912 (512.00 MiBs) |
+-------------------------------------------------------------------------------------+
info disk=3Model : osfdisk
Version : 1
Serial :
Media Type : Fixed HDD
Size : 536870912 (512.00 MiBs)
Geometry : 512 bytes * 63 sectors * 255 tracks * 65 cylinders
Volume : MBR
+--------------------------------------------------------------------------------------------------+
| Id | Boot | Label | Mounted | Filesystem | Offset | Size |
+--------------------------------------------------------------------------------------------------+
| 1 | No | NTFSDRIVE | F:\ | Bitlocker | 0000000000000200 | 000000001ffffe00 (512.00 MiBs) |
+--------------------------------------------------------------------------------------------------+
info disk=3 volume=1Serial Number : 0000aa60-00002eae
Filesystem : Bitlocker
Bootable : False
Type : Fixed
Label : NTFSDRIVE
Offset : 512 (512.00 bytes)
Size : 536870400 (512.00 MiBs)
Free : 519442432 (495.38 MiBs)
Mounted : True (F:\)
Bitlocker : True (Unlocked)
MBR
mbr disk=2MBR from \\.\PhysicalDrive2
---------------------------
Disk signature : e4589462
Reserved bytes : 0000
Partition table :
+---------------------------------------------------------------------------------------------------+
| Id | Boot | Flags | Filesystem | First sector | Last sector | Offset | Sectors | Size |
+---------------------------------------------------------------------------------------------------+
| 1 | No | Principal | NTFS / exFAT | 0 2 3 | 255 254 255 | 128 | 16771072 | 8.00 GiBs |
+---------------------------------------------------------------------------------------------------+
MBR signature : 55aa
Strings:
[63] : Invalid partition table
[7b] : Error loading operating system
[9a] : Missing operating system
Disassemble Bootstrap Code [y/N] ? y
0000 : 33c0 : xor ax, ax
0002 : 8ed0 : mov ss, ax
0004 : bc007c : mov sp, 0x7c00
0007 : 8ec0 : mov es, ax
0009 : 8ed8 : mov ds, ax
000b : be007c : mov si, 0x7c00
000e : bf0006 : mov di, 0x600
0011 : b90002 : mov cx, 0x200
...
GPT
gpt disk=1Signature : EFI PART
Revision : 1.0
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - microsoft/vcpkg: C++ Library Manager for Windows, Linux, and MacOS
C++ Library Manager for Windows, Linux, and MacOS. Contribute to microsoft/vcpkg development by creating an account on GitHub.
Header Size : 92
Header CRC32 : cc72e4d3
Reserved : 00000000
Current LBA : 1
Backup LBA : 3907029167
First Usable LBA : 34
Last Usable LBA : 3907029134
GUID : {a21d6495-cd58-4b8d-b968-dc337adcf6ac}
Entry LBA : 2
Entries Num : 128
Entries Size : 128
Partitions CRC32 : 0c9a0a25
Partition table : 2 entries
+------------------------------------------------------------------------------------------------------------------------+
| Id | Name | GUID | First sector | Last sector | Flags |
+------------------------------------------------------------------------------------------------------------------------+
| 1 | Microsoft reserved partition | {da0ac4a1-a78c-4053-bab5-36c70a71fe63} | 34 | 262177 | 000000000000 |
| 2 | Basic data partition | {4b4ea4b3-64a1-4c6d-bd4b-1c2b0e4e706f} | 264192 | 3907028991 | 000000000000 |
+------------------------------------------------------------------------------------------------------------------------+
VBR
vbr disk=3 volume=1Structure :
Jump : eb5890 (jmp 0x7c5a)
OEM id : -FVE-FS-
BytePerSector : 512
SectorPerCluster : 8
Reserved Sectors : 0
Number of FATs : 0
Root Max Entries : 0
Total Sectors : 0
Media Type : f8
SectorPerFat : 8160
SectorPerTrack : 63
Head Count : 255
FS Offset : 1
Total Sectors : 0
FAT Flags : 0000
FAT Version : 0000
Root Cluster : 0
FS Info Sector : 1
Backup BootSector: 6
Reserved : 00000000
Reserved : 00000000
Reserved : 00000000
Drive Number : 80
Reserved : 00
Ext. Boot Sign : 29
Serial Nuumber : 00000000
Volume Name : NO NAME
FileSystem Type : FAT32
Volume GUID : {4967d63b-2e29-4ad8-8399-f6a339e3d001}
FVE Block 1 : 0000000002100000
FVE Block 2 : 00000000059e4000
FVE Block 3 : 00000000092c8000
End marker : 55aa
Strings:
[00] : Remove disks or other media.
[1f] : Disk error
[2c] : Press any key to restart
Disassemble Bootstrap Code [y/N] ? y
7c5a : eb58 : jmp 0x7cb4
7c5c : 90 : nop
7c5d : 2d4656 : sub ax, 0x5646
7c60 : 45 : inc bp
7c61 : 2d4653 : sub ax, 0x5346
7c64 : 2d0002 : sub ax, 0x200
[...]
Extract
extract disk=3 volume=1 from=\bob.txt output=d:\bob.txt Volume:1 ----------------------------------------------- [+] Opening \\?\Volume{00023d5d-0000-0000-0002-000000000000}\ [-] Source : \bob.txt [-] Destination : d:\bob.txt [-] Record Num : 47 (0000002fh) [+] File extracted (42 bytes written) ">Extract file from \\.\PhysicalDrive3 > Volume:1
-----------------------------------------------
[+] Opening \\?\Volume{00023d5d-0000-0000-0002-000000000000}\
[-] Source : \bob.txt
[-] Destination : d:\bob.txt
[-] Record Num : 47 (0000002fh)
[+] File extracted (42 bytes written)
extract disk=0 volume=4 --system output=d:\system Volume:4 ----------------------------------------------- [+] Opening \\?\Volume{ee732b26-571c-4516-b8fd-32282aa8e66b}\ [-] Source : c:\windows\system32\config\system [-] Destination : d:\system [-] Record Num : 623636 (00098414h) [+] File extracted (19398656 bytes written) ">Extract file from \\.\PhysicalDrive0 > Volume:4
-----------------------------------------------
[+] Opening \\?\Volume{ee732b26-571c-4516-b8fd-32282aa8e66b}\
[-] Source : c:\windows\system32\config\system
[-] Destination : d:\system
[-] Record Num : 623636 (00098414h)
[+] File extracted (19398656 bytes written)
Image
___________________________
@hacking_Attack
@Hacking_Video
Header CRC32 : cc72e4d3
Reserved : 00000000
Current LBA : 1
Backup LBA : 3907029167
First Usable LBA : 34
Last Usable LBA : 3907029134
GUID : {a21d6495-cd58-4b8d-b968-dc337adcf6ac}
Entry LBA : 2
Entries Num : 128
Entries Size : 128
Partitions CRC32 : 0c9a0a25
Partition table : 2 entries
+------------------------------------------------------------------------------------------------------------------------+
| Id | Name | GUID | First sector | Last sector | Flags |
+------------------------------------------------------------------------------------------------------------------------+
| 1 | Microsoft reserved partition | {da0ac4a1-a78c-4053-bab5-36c70a71fe63} | 34 | 262177 | 000000000000 |
| 2 | Basic data partition | {4b4ea4b3-64a1-4c6d-bd4b-1c2b0e4e706f} | 264192 | 3907028991 | 000000000000 |
+------------------------------------------------------------------------------------------------------------------------+
VBR
vbr disk=3 volume=1Structure :
Jump : eb5890 (jmp 0x7c5a)
OEM id : -FVE-FS-
BytePerSector : 512
SectorPerCluster : 8
Reserved Sectors : 0
Number of FATs : 0
Root Max Entries : 0
Total Sectors : 0
Media Type : f8
SectorPerFat : 8160
SectorPerTrack : 63
Head Count : 255
FS Offset : 1
Total Sectors : 0
FAT Flags : 0000
FAT Version : 0000
Root Cluster : 0
FS Info Sector : 1
Backup BootSector: 6
Reserved : 00000000
Reserved : 00000000
Reserved : 00000000
Drive Number : 80
Reserved : 00
Ext. Boot Sign : 29
Serial Nuumber : 00000000
Volume Name : NO NAME
FileSystem Type : FAT32
Volume GUID : {4967d63b-2e29-4ad8-8399-f6a339e3d001}
FVE Block 1 : 0000000002100000
FVE Block 2 : 00000000059e4000
FVE Block 3 : 00000000092c8000
End marker : 55aa
Strings:
[00] : Remove disks or other media.
[1f] : Disk error
[2c] : Press any key to restart
Disassemble Bootstrap Code [y/N] ? y
7c5a : eb58 : jmp 0x7cb4
7c5c : 90 : nop
7c5d : 2d4656 : sub ax, 0x5646
7c60 : 45 : inc bp
7c61 : 2d4653 : sub ax, 0x5346
7c64 : 2d0002 : sub ax, 0x200
[...]
Extract
extract disk=3 volume=1 from=\bob.txt output=d:\bob.txt Volume:1 ----------------------------------------------- [+] Opening \\?\Volume{00023d5d-0000-0000-0002-000000000000}\ [-] Source : \bob.txt [-] Destination : d:\bob.txt [-] Record Num : 47 (0000002fh) [+] File extracted (42 bytes written) ">Extract file from \\.\PhysicalDrive3 > Volume:1
-----------------------------------------------
[+] Opening \\?\Volume{00023d5d-0000-0000-0002-000000000000}\
[-] Source : \bob.txt
[-] Destination : d:\bob.txt
[-] Record Num : 47 (0000002fh)
[+] File extracted (42 bytes written)
extract disk=0 volume=4 --system output=d:\system Volume:4 ----------------------------------------------- [+] Opening \\?\Volume{ee732b26-571c-4516-b8fd-32282aa8e66b}\ [-] Source : c:\windows\system32\config\system [-] Destination : d:\system [-] Record Num : 623636 (00098414h) [+] File extracted (19398656 bytes written) ">Extract file from \\.\PhysicalDrive0 > Volume:4
-----------------------------------------------
[+] Opening \\?\Volume{ee732b26-571c-4516-b8fd-32282aa8e66b}\
[-] Source : c:\windows\system32\config\system
[-] Destination : d:\system
[-] Record Num : 623636 (00098414h)
[+] File extracted (19398656 bytes written)
Image
___________________________
@hacking_Attack
@Hacking_Video
Update Offset : 48
Update Number : 3
$LogFile LSN : 274035114
Sequence Number : 5
Hardlink Count : 1
Attribute Offset : 56
Flags : In_use | Directory
Real Size : 704
Allocated Size : 1024
Base File Record : 0
Next Attribute ID : 56
MFT Record Index : 5
Update Seq Number : 4461
Update Seq Array : 00000000
Attributes:
-----------
+------------------------------------------------------------------------------------------------------------------+
| Id | Type | Non-resident | Length | Overview |
+------------------------------------------------------------------------------------------------------------------+
| 1 | $STANDARD_INFORMATION | False | 72 | File Created Time : 2009-12-02 02:03:31 |
| | | | | Last File Write Time : 2020-02-24 19:42:23 |
| | | | | FileRecord Changed Time : 2020-02-24 19:42:23 |
| | | | | Last Access Time : 2020-02-24 19:42:23 |
| | | | | Permissions : |
| | | | | read_only : 0 |
| | | | | hidden : 1 |
| | | | | system : 1 |
| | | | | device : 0 |
| | | | | normal : 0 |
| | | | | temporary : 0 |
| | | | | sparse : 0 |
| | | | | reparse_point : 0 |
| | | | | compressed : 0 |
| | | | | offline : 0 |
| | | | | not_indexed : 1 |
| | | | | encrypted : 0 |
| | | | | Max Number of Versions : 0 |
| | | | | Version Number : 0 |
+------------------------------------------------------------------------------------------------------------------+
| 2 | $FILE_NAME | False | 68 | Parent Dir Record Index : 5 |
| | | | | Parent Dir Sequence Num : 5 |
| | | | | File Created Time : 2009-12-02 02:03:31 |
| | | | | Last File Write Time : 2011-12-24 03:13:12 |
| | | | | FileRecord Changed Time : 2011-12-24 03:13:12 |
| | | | | Last Access Time : 1970-01-01 00:59:59 |
| | | | | Allocated Size : 0 |
___________________________
@hacking_Attack
@Hacking_Video
Update Number : 3
$LogFile LSN : 274035114
Sequence Number : 5
Hardlink Count : 1
Attribute Offset : 56
Flags : In_use | Directory
Real Size : 704
Allocated Size : 1024
Base File Record : 0
Next Attribute ID : 56
MFT Record Index : 5
Update Seq Number : 4461
Update Seq Array : 00000000
Attributes:
-----------
+------------------------------------------------------------------------------------------------------------------+
| Id | Type | Non-resident | Length | Overview |
+------------------------------------------------------------------------------------------------------------------+
| 1 | $STANDARD_INFORMATION | False | 72 | File Created Time : 2009-12-02 02:03:31 |
| | | | | Last File Write Time : 2020-02-24 19:42:23 |
| | | | | FileRecord Changed Time : 2020-02-24 19:42:23 |
| | | | | Last Access Time : 2020-02-24 19:42:23 |
| | | | | Permissions : |
| | | | | read_only : 0 |
| | | | | hidden : 1 |
| | | | | system : 1 |
| | | | | device : 0 |
| | | | | normal : 0 |
| | | | | temporary : 0 |
| | | | | sparse : 0 |
| | | | | reparse_point : 0 |
| | | | | compressed : 0 |
| | | | | offline : 0 |
| | | | | not_indexed : 1 |
| | | | | encrypted : 0 |
| | | | | Max Number of Versions : 0 |
| | | | | Version Number : 0 |
+------------------------------------------------------------------------------------------------------------------+
| 2 | $FILE_NAME | False | 68 | Parent Dir Record Index : 5 |
| | | | | Parent Dir Sequence Num : 5 |
| | | | | File Created Time : 2009-12-02 02:03:31 |
| | | | | Last File Write Time : 2011-12-24 03:13:12 |
| | | | | FileRecord Changed Time : 2011-12-24 03:13:12 |
| | | | | Last Access Time : 1970-01-01 00:59:59 |
| | | | | Allocated Size : 0 |
___________________________
@hacking_Attack
@Hacking_Video