Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Boomerang - A Tool To Expose Multiple Internal Servers To Web/Cloud
https://1.bp.blogspot.com/-BvyNfPJMZBs/YFfV0nsU1EI/AAAAAAAAVto/DnRkdlcBAWsJOXBlHzvglbQPSqkQY2J8ACNcBGAsYHQ/w640-h260/Boomerang_2_Boomerang_v0.png
Boomerang is a tool to expose multiple internal servers to web/cloud using HTTP+TCP Tunneling. The Server will expose 2 ports on the Cloud. One will be where tools like proxychains can connect over socks, another will be for the agent to connect. The agent can be executed on any internal host. The agent will connect to the server and listen for any connection that can be forwarded to internal machine like a socks server. A more detailed information can be found in the image below. Features like authentication are in pipeline and will be added soon.
Agent & Server are pretty stable and can be used in Red Team for Multiple levels of Pivoting and exposing services to external/other networks
Boomerang Agent & Server support Windows, Linux and Arm architecture
Features in Progress: Proxy Authentication (Use IP Whitelisting for C2s till then)
Download Boomerang
Boomerang - A Tool To Expose Multiple Internal Servers To Web/Cloud
https://1.bp.blogspot.com/-BvyNfPJMZBs/YFfV0nsU1EI/AAAAAAAAVto/DnRkdlcBAWsJOXBlHzvglbQPSqkQY2J8ACNcBGAsYHQ/w640-h260/Boomerang_2_Boomerang_v0.png
Boomerang is a tool to expose multiple internal servers to web/cloud using HTTP+TCP Tunneling. The Server will expose 2 ports on the Cloud. One will be where tools like proxychains can connect over socks, another will be for the agent to connect. The agent can be executed on any internal host. The agent will connect to the server and listen for any connection that can be forwarded to internal machine like a socks server. A more detailed information can be found in the image below. Features like authentication are in pipeline and will be added soon.
Agent & Server are pretty stable and can be used in Red Team for Multiple levels of Pivoting and exposing services to external/other networks
Boomerang Agent & Server support Windows, Linux and Arm architecture
Features in Progress: Proxy Authentication (Use IP Whitelisting for C2s till then)
Download Boomerang
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hacking Stories: When two young hackers played war games with Pentagon
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: When two young hackers played war games with Pentagonhttps://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Post Views: 388
Reading Time: 6 Minutes
Mathew Bevan, and Richard Pryce, the two young hackers who in their spare time, from the comfort of their bedrooms, had penetrated what should have been the most secure defense network in the world back in the ’90s.
Their success was based on a mixture of persistence and good luck, which was assisted by simple security mistakes in the Pentagon computer system.
Back story
Richard Pryce
He was British and living in the UK, and he was still going to school at the time of his arrest. He had a musical upbringing with his two sisters and had a passion for playing the double bass.
He bought his first computer when he was 15 to help him with his studies at the time. He was spending his free time on a bulletin board (computer forums) on the Internet where computer users chatted and traded information, it was here where he got his first introduction to hacking.
Got software off the forums and one of them called the “bluebox”, could recreate various frequencies to get free phone calls. He used the software to make calls anywhere in the world for free. It became normal to him and he would then get on the Internet and use various ‘hacker’ forums and learn techniques to download the software he needed along with text files that were explaining what you can do to different computer types.
He was treating hacking like a game, a challenge and he got good at it as time was passing. It escalated quickly and went from hacking low-profile computer targets like universities to being able to hack military systems.
His nickname ‘Datastream Cowboy’ came to him in a flash of inspiration.
Mathew Bevan
Mathew was also British and at the age of 12, he got his first computer, a Sinclair ZX81.
He was a nerd by his own words, and he was beaten and bullied almost every day of his school life.
At 15, he bought an Amiga 500 which at the time was better than most personal computers. Just like Pryce who was younger than Mathew, Mathew discovered the bulletin boards (online forums) and started exploring the Internet. He would call all the BBS (bulleting Boards) numbers he could found, resulting in a 400$ bill and a warning from his mother.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/bulleting-board.jpeg
Bulletin Board - Original BBSs/Jason Scott
He then started learning how to manipulate the phone system until he was able to make free calls and even obfuscate call origin. He wanted to be anonymous so he found out that he could divert the calls through several countries before reaching his destination, giving him the ability to call from anywhere in the world free and remain untraceable.
He met various people on the BBS who wanted to learn his skills and tricks he accumulated on the phone system, as a trade for that information he would get documents and other information on how to hack computer systems.
By gaining such knowledge he would then become fearless and strong in the digital world but scared and powerless in real life, he would spend countless hours in front of his pc after school and repeat the cycle all over again for months.
It was not long before he started breaking into all sorts of machines, small and big, and he was doing it just because he could. He became addicted to the nature of hacking, by looking int[...]
Hacking Stories: When two young hackers played war games with Pentagon
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: When two young hackers played war games with Pentagonhttps://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Post Views: 388
Reading Time: 6 Minutes
Mathew Bevan, and Richard Pryce, the two young hackers who in their spare time, from the comfort of their bedrooms, had penetrated what should have been the most secure defense network in the world back in the ’90s.
Their success was based on a mixture of persistence and good luck, which was assisted by simple security mistakes in the Pentagon computer system.
Back story
Richard Pryce
He was British and living in the UK, and he was still going to school at the time of his arrest. He had a musical upbringing with his two sisters and had a passion for playing the double bass.
He bought his first computer when he was 15 to help him with his studies at the time. He was spending his free time on a bulletin board (computer forums) on the Internet where computer users chatted and traded information, it was here where he got his first introduction to hacking.
Got software off the forums and one of them called the “bluebox”, could recreate various frequencies to get free phone calls. He used the software to make calls anywhere in the world for free. It became normal to him and he would then get on the Internet and use various ‘hacker’ forums and learn techniques to download the software he needed along with text files that were explaining what you can do to different computer types.
He was treating hacking like a game, a challenge and he got good at it as time was passing. It escalated quickly and went from hacking low-profile computer targets like universities to being able to hack military systems.
His nickname ‘Datastream Cowboy’ came to him in a flash of inspiration.
Mathew Bevan
Mathew was also British and at the age of 12, he got his first computer, a Sinclair ZX81.
He was a nerd by his own words, and he was beaten and bullied almost every day of his school life.
At 15, he bought an Amiga 500 which at the time was better than most personal computers. Just like Pryce who was younger than Mathew, Mathew discovered the bulletin boards (online forums) and started exploring the Internet. He would call all the BBS (bulleting Boards) numbers he could found, resulting in a 400$ bill and a warning from his mother.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/bulleting-board.jpeg
Bulletin Board - Original BBSs/Jason Scott
He then started learning how to manipulate the phone system until he was able to make free calls and even obfuscate call origin. He wanted to be anonymous so he found out that he could divert the calls through several countries before reaching his destination, giving him the ability to call from anywhere in the world free and remain untraceable.
He met various people on the BBS who wanted to learn his skills and tricks he accumulated on the phone system, as a trade for that information he would get documents and other information on how to hack computer systems.
By gaining such knowledge he would then become fearless and strong in the digital world but scared and powerless in real life, he would spend countless hours in front of his pc after school and repeat the cycle all over again for months.
It was not long before he started breaking into all sorts of machines, small and big, and he was doing it just because he could. He became addicted to the nature of hacking, by looking int[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hacking Stories: When two young hackers played war games with Pentagon https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: When two young hackers played war games…
o institutions’ files to bypassing security systems. He was lured by the rush of excitement and he couldn’t stop hacking into systems, again and again.
By hacking everything he could, he felt unfulfilled and wanted a direction. He got his direction when he was on a bulletin board in Australia, called Destiny Stone, and was run by a phone phreaker (someone who hacks into systems using a phone connection) called Ripmax. While Ripmax ended on the wrong side of the law, Mathew was able to find hundreds of documents about UFO, government cover-ups, and conspiracy theories on Ripmax’s machine.
His direction in hacking was found, he would then try to uncover conspiracy theories and government cover-ups in his pursuit of the ultimate truth and hacking pleasure.
His nickname was Kuji.
The hacking story from Kuji and Datastream Cowboy side
April 1994, American special agents were waiting patiently for an upcoming attack. They have identified suspicious activity for weeks now, and the unknown enemy was moving across the Pentagon network computers, cracking codes and downloading confidential files. The unknown enemy was Pryce, or by his nickname Datastream Cowboy, who was hacking around the military base systems of the Pentagon.
He was first spotted by a systems manager at the Rome Laboratory at the Griffiss Air Force Base in New York. He had breached the security systems and was using assumed computer identities from the airbase to attack other targets like NASA, Wright-Patterson air force base which monitors UFO sightings, and Hanscom air force. He planted sniffing programs to get the passwords he used in the systems.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Rome_lab.jpg
Rome Laboratory at the Griffiss Air Force Base in New York - www.wrvo.org
The American military had been preparing for such cyber-attacks for years then, and they created a new breed of special agents’ force called the Air Force Office of Special Investigations (AFOSI). The special agents were dispatched to the Rome Laboratory to identify the attacker.
Datastream Cowboys’ successful hacking in the Rome Laboratory relied heavily on luck.
He gained low-level access to the Rome computer systems using a default guest password, then he retrieved the password file and downloaded them. He tried brute-forcing the password file with a passwords list containing 50K random words and left his computer running overnight until it cracked it.
With luck on his side, he managed to crack the weak password of a United States Air Force (USAF) lieutenant who was using as a password, his pet ferret name, called ‘Carmen’.
Once he cracked the password, he was free to explore highly classified and confidential documents. He was able to escalate his privileges and became a root user which gave him the power to do whatever he wanted into the system, from deleting, creating, editing accounts, to shutting down the entire system. He read about the UFO material being kept at the Wright Patterson base and decided also to get in their systems and also hacked a NASA site.
Pryce had as his main target the Rome Laboratory because he knew that there, the military was developing stuff, he downloaded on his computer a programming code for an artificial intelligence project he found. Then he proceeded to visit a computer in Korea, from the Rome laboratory computer, he just tapped in the address for the Korean research computer and he did nothing after that, he just fancied having a go at a different sort of computer.
In 3 months, Pryce was sending weekly e-mails to the fellow hacker he knew as Kuji, without knowing his real identity was Mathew Bevan.
Bevan at the time became interested in hacking after finding on Ripmax’s computer all the documents for UFOs, government cover-ups, and conspiracy theories. He saw on a hacker publication called PHRACK, a story about the alleged disappearance of 40 hackers who were targeting military systems[...]
By hacking everything he could, he felt unfulfilled and wanted a direction. He got his direction when he was on a bulletin board in Australia, called Destiny Stone, and was run by a phone phreaker (someone who hacks into systems using a phone connection) called Ripmax. While Ripmax ended on the wrong side of the law, Mathew was able to find hundreds of documents about UFO, government cover-ups, and conspiracy theories on Ripmax’s machine.
His direction in hacking was found, he would then try to uncover conspiracy theories and government cover-ups in his pursuit of the ultimate truth and hacking pleasure.
His nickname was Kuji.
The hacking story from Kuji and Datastream Cowboy side
April 1994, American special agents were waiting patiently for an upcoming attack. They have identified suspicious activity for weeks now, and the unknown enemy was moving across the Pentagon network computers, cracking codes and downloading confidential files. The unknown enemy was Pryce, or by his nickname Datastream Cowboy, who was hacking around the military base systems of the Pentagon.
He was first spotted by a systems manager at the Rome Laboratory at the Griffiss Air Force Base in New York. He had breached the security systems and was using assumed computer identities from the airbase to attack other targets like NASA, Wright-Patterson air force base which monitors UFO sightings, and Hanscom air force. He planted sniffing programs to get the passwords he used in the systems.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Rome_lab.jpg
Rome Laboratory at the Griffiss Air Force Base in New York - www.wrvo.org
The American military had been preparing for such cyber-attacks for years then, and they created a new breed of special agents’ force called the Air Force Office of Special Investigations (AFOSI). The special agents were dispatched to the Rome Laboratory to identify the attacker.
Datastream Cowboys’ successful hacking in the Rome Laboratory relied heavily on luck.
He gained low-level access to the Rome computer systems using a default guest password, then he retrieved the password file and downloaded them. He tried brute-forcing the password file with a passwords list containing 50K random words and left his computer running overnight until it cracked it.
With luck on his side, he managed to crack the weak password of a United States Air Force (USAF) lieutenant who was using as a password, his pet ferret name, called ‘Carmen’.
Once he cracked the password, he was free to explore highly classified and confidential documents. He was able to escalate his privileges and became a root user which gave him the power to do whatever he wanted into the system, from deleting, creating, editing accounts, to shutting down the entire system. He read about the UFO material being kept at the Wright Patterson base and decided also to get in their systems and also hacked a NASA site.
Pryce had as his main target the Rome Laboratory because he knew that there, the military was developing stuff, he downloaded on his computer a programming code for an artificial intelligence project he found. Then he proceeded to visit a computer in Korea, from the Rome laboratory computer, he just tapped in the address for the Korean research computer and he did nothing after that, he just fancied having a go at a different sort of computer.
In 3 months, Pryce was sending weekly e-mails to the fellow hacker he knew as Kuji, without knowing his real identity was Mathew Bevan.
Bevan at the time became interested in hacking after finding on Ripmax’s computer all the documents for UFOs, government cover-ups, and conspiracy theories. He saw on a hacker publication called PHRACK, a story about the alleged disappearance of 40 hackers who were targeting military systems[...]
Hacking Articles Tips Tricks Videos Tutorials
o institutions’ files to bypassing security systems. He was lured by the rush of excitement and he couldn’t stop hacking into systems, again and again. By hacking everything he could, he felt unfulfilled and wanted a direction. He got his direction when he…
to try and uncover the truth. The publication also printed the names of the bases that were thought to have been the targets by the missing group.
He had already hacked so many other systems, from corporate, educational to government and he was able to begin a systematic attack on each one of the targets that PHRACK cited.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/phrack-magazine.jpg
Phrack Magazine issue 60 - www.phrack.org
The hack from the American cyber agents’ view
As Pryce got spotted first by a systems manager at the Rome Laboratory, the computer specialists from AFOSI dispatched to the Rome laboratory to catch him.
In the second week of their investigation, they saw that Datastream Cowboy (as he called himself) was online again. They carefully tracked him when he used the access code, he cracked from the high-ranking Pentagon lieutenant to login. As he was shifting from folder to folder, navigating through highly confidential reports, battlefield simulation data, and downloading the AI code, the agents worked hard to track him to found out who he was and where he came from.
Datastream cowboy though was bouncing around the world before launching the attacks, making it impossible for the agents to establish in which country he was.
As he left the Pentagon systems, the agents were chilled to see that he was trying to access a computer at a nuclear facility somewhere in Korea.
The shocked agents saw a terrible crisis coming, in 1994, the United States was embroiled intense negotiations with North Korea about its suspected nuclear weapons program. If the Koreans detected the attack on their nuclear facility coming from an American airbase (Datastream cowboy has assumed an American military identity by routing his assault through the Rome laboratory computer) they would have thought that the attack was an act of war. In the end, they detect that his target was in South Korea, not the North and the security alert was over.
In the view of the American military, Datastream cowboy was “No 1 threat to US security “.
The agents feared that Datastream cowboy was dangerous as they noticed that he didn’t hack alone. They would watch him attacking a military site unsuccessfully, retreat, send an email to ‘’Kuji”, who was a more sophisticated hacker than him, and then return to hack the site successfully. Their path was not easy to follow, they were weaving a path through computer systems in Africa, Mexico, and Europe before making the attack.
Over 30 days, they tracked them hacking the Rome Laboratory more than 150 times, while Kuji was monitored attempting an attack on the computers of NATO HQ in Brussels.
The American military was so vulnerable because the Internet, and the computer communications system that had been developed by Pentagon scientists as a tool for survival after a nuclear war, and was opening up in 1994 to anyone in the world who had access to a cheap and powerful personal computer, this automatically opened the gates of military secret files to cyber-attackers.
It would be simple to shut them down but the Pentagon generals wanted to be found and put out of action. If they were to shut them down, they would survive to attack again, so their identities and the information they had stolen would remain unknown.
The cyber agents tried to track the stepping stones of Datastream cowboys’ before attacking them, they wanted to trace Datastream Cowboy’s path backward. Due to the huge amount of traffic in the network they couldn’t find the exact path. Then, by knowing the nickname of Pryce, some of the agent’s informants managed to found that Datastream cowboy hung out at Cyberspace, an ISP based in Seattle.
Pryce, being naive and eager to engage with other hackers via email, got exploited without knowing it by an informant. He gave out his home telephone number to the informant, allowing the informant to know that Datastream cowboy lived in the[...]
He had already hacked so many other systems, from corporate, educational to government and he was able to begin a systematic attack on each one of the targets that PHRACK cited.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/phrack-magazine.jpg
Phrack Magazine issue 60 - www.phrack.org
The hack from the American cyber agents’ view
As Pryce got spotted first by a systems manager at the Rome Laboratory, the computer specialists from AFOSI dispatched to the Rome laboratory to catch him.
In the second week of their investigation, they saw that Datastream Cowboy (as he called himself) was online again. They carefully tracked him when he used the access code, he cracked from the high-ranking Pentagon lieutenant to login. As he was shifting from folder to folder, navigating through highly confidential reports, battlefield simulation data, and downloading the AI code, the agents worked hard to track him to found out who he was and where he came from.
Datastream cowboy though was bouncing around the world before launching the attacks, making it impossible for the agents to establish in which country he was.
As he left the Pentagon systems, the agents were chilled to see that he was trying to access a computer at a nuclear facility somewhere in Korea.
The shocked agents saw a terrible crisis coming, in 1994, the United States was embroiled intense negotiations with North Korea about its suspected nuclear weapons program. If the Koreans detected the attack on their nuclear facility coming from an American airbase (Datastream cowboy has assumed an American military identity by routing his assault through the Rome laboratory computer) they would have thought that the attack was an act of war. In the end, they detect that his target was in South Korea, not the North and the security alert was over.
In the view of the American military, Datastream cowboy was “No 1 threat to US security “.
The agents feared that Datastream cowboy was dangerous as they noticed that he didn’t hack alone. They would watch him attacking a military site unsuccessfully, retreat, send an email to ‘’Kuji”, who was a more sophisticated hacker than him, and then return to hack the site successfully. Their path was not easy to follow, they were weaving a path through computer systems in Africa, Mexico, and Europe before making the attack.
Over 30 days, they tracked them hacking the Rome Laboratory more than 150 times, while Kuji was monitored attempting an attack on the computers of NATO HQ in Brussels.
The American military was so vulnerable because the Internet, and the computer communications system that had been developed by Pentagon scientists as a tool for survival after a nuclear war, and was opening up in 1994 to anyone in the world who had access to a cheap and powerful personal computer, this automatically opened the gates of military secret files to cyber-attackers.
It would be simple to shut them down but the Pentagon generals wanted to be found and put out of action. If they were to shut them down, they would survive to attack again, so their identities and the information they had stolen would remain unknown.
The cyber agents tried to track the stepping stones of Datastream cowboys’ before attacking them, they wanted to trace Datastream Cowboy’s path backward. Due to the huge amount of traffic in the network they couldn’t find the exact path. Then, by knowing the nickname of Pryce, some of the agent’s informants managed to found that Datastream cowboy hung out at Cyberspace, an ISP based in Seattle.
Pryce, being naive and eager to engage with other hackers via email, got exploited without knowing it by an informant. He gave out his home telephone number to the informant, allowing the informant to know that Datastream cowboy lived in the[...]
Hacking Articles Tips Tricks Videos Tutorials
to try and uncover the truth. The publication also printed the names of the bases that were thought to have been the targets by the missing group. He had already hacked so many other systems, from corporate, educational to government and he was able to begin…
UK.
After the senior AFOSI agent contacted Scotland Yards’ computer crime unit, they located his house in Colindale, a suburb in north London. After examining the telephone lines, it was revealed that he was first dialing into Colombia and then using a free phone line from there to hack into the military sites.
American agents wanted to catch Datastream Cowboy in the act, so they flew to the UK and meet with the British police to arrest him.
On May 12, 1994, they parked outside his Colindale house and were waiting for the signal that the Datastream Cowboy was online. When the agent’s mobile rang, the officers, posing as a courier, knocked on the door. Pryces’ dad opened the door and the agents begun to search the house and found him on his computer in the house’s loft-room. Shocked as the agents were preparing to arrest him, Pryce collapsed on the floor in tears. To their surprise, agents who thought that they are going to arrest a dangerous criminal, just found a teenager from the Purcell School in Harrow, playing around on his computer.
They arrested him and took his personal computer but he was released on bail on the same night. The agent found dozen stolen files on Pryce’s hard-disk, including a battle simulation program.
Later they found out that he also downloaded an Artificial Intelligence file about a military project that was too big to be saved on his pc, so he had to save it in his own storage space at an Internet service provider that he used in New York.
Also, during the later subsequent police interviews, he was asked to name Kuji. He told the officers that he didn’t know him, or where he lived and that he was only talking to him online.
The agents regarded Kuji as far more sophisticated than Datastream Cowboy because he would only stay on a telephone for a short period, not long enough to be traced. Kuji assisted Pryce but nobody knew what Kuji did with the information he collected or why he collected them in the first place.
The Kuji file case
Pryce gave them a telephone number but it was a school library number in Surrey.
The detectives caught Pryce, but their main target then was Kuji, the fear that he could be a spy working for foreign intelligence agencies fueled them to push and arrest Kuji.
During the next two years of compiling evidence in the UK and US in the case against Pryce, the agents failed to turn in any evidence that might lead them to Kuji.
In June 1996, the computer crime unit went through the mass of information they got from Pryce’s hard drive again, a process said to took over 3 weeks, found what they were looking for. At the bottom of a file in the DOS directory, the name Kuji, and a telephone number next to the name were found. Pryce might not have even known that that information was on his hard drive because he downloaded so much information.
Kuji’s telephone number was a disappointment for the agents that thought he would be a foreign spy. The telephone number was based in Cardiff, Wales.
The agents drove up to the address and finally discovered Kuji’s identity to be a 21 years old Mathew Bevan, a computer worker with a fascination for science fiction. His room was covered with posters from X-files.
Charges
Mathew was arrested on June 21, 1996, at the offices of Admiral Insurance where he worked.
He was convinced that if it wasn’t for Pryce he would never have been caught and that the only reason that Pryce got caught was that he mistakenly gave his number to a secret agent. He said to the agents that he wasn’t tutoring Pryce but just gave him tips here and there as he did for everyone.
Mathew also said that he had not even been alarmed when Datastream cowboy disappeared from the Internet. Everyone was joking with him on the emails that he might have been arrested. One year later when the story for Pryce appeared in the news, Mathew thought that he had escaped detection. He was charged the next day of his arrest with two counts [...]
After the senior AFOSI agent contacted Scotland Yards’ computer crime unit, they located his house in Colindale, a suburb in north London. After examining the telephone lines, it was revealed that he was first dialing into Colombia and then using a free phone line from there to hack into the military sites.
American agents wanted to catch Datastream Cowboy in the act, so they flew to the UK and meet with the British police to arrest him.
On May 12, 1994, they parked outside his Colindale house and were waiting for the signal that the Datastream Cowboy was online. When the agent’s mobile rang, the officers, posing as a courier, knocked on the door. Pryces’ dad opened the door and the agents begun to search the house and found him on his computer in the house’s loft-room. Shocked as the agents were preparing to arrest him, Pryce collapsed on the floor in tears. To their surprise, agents who thought that they are going to arrest a dangerous criminal, just found a teenager from the Purcell School in Harrow, playing around on his computer.
They arrested him and took his personal computer but he was released on bail on the same night. The agent found dozen stolen files on Pryce’s hard-disk, including a battle simulation program.
Later they found out that he also downloaded an Artificial Intelligence file about a military project that was too big to be saved on his pc, so he had to save it in his own storage space at an Internet service provider that he used in New York.
Also, during the later subsequent police interviews, he was asked to name Kuji. He told the officers that he didn’t know him, or where he lived and that he was only talking to him online.
The agents regarded Kuji as far more sophisticated than Datastream Cowboy because he would only stay on a telephone for a short period, not long enough to be traced. Kuji assisted Pryce but nobody knew what Kuji did with the information he collected or why he collected them in the first place.
The Kuji file case
Pryce gave them a telephone number but it was a school library number in Surrey.
The detectives caught Pryce, but their main target then was Kuji, the fear that he could be a spy working for foreign intelligence agencies fueled them to push and arrest Kuji.
During the next two years of compiling evidence in the UK and US in the case against Pryce, the agents failed to turn in any evidence that might lead them to Kuji.
In June 1996, the computer crime unit went through the mass of information they got from Pryce’s hard drive again, a process said to took over 3 weeks, found what they were looking for. At the bottom of a file in the DOS directory, the name Kuji, and a telephone number next to the name were found. Pryce might not have even known that that information was on his hard drive because he downloaded so much information.
Kuji’s telephone number was a disappointment for the agents that thought he would be a foreign spy. The telephone number was based in Cardiff, Wales.
The agents drove up to the address and finally discovered Kuji’s identity to be a 21 years old Mathew Bevan, a computer worker with a fascination for science fiction. His room was covered with posters from X-files.
Charges
Mathew was arrested on June 21, 1996, at the offices of Admiral Insurance where he worked.
He was convinced that if it wasn’t for Pryce he would never have been caught and that the only reason that Pryce got caught was that he mistakenly gave his number to a secret agent. He said to the agents that he wasn’t tutoring Pryce but just gave him tips here and there as he did for everyone.
Mathew also said that he had not even been alarmed when Datastream cowboy disappeared from the Internet. Everyone was joking with him on the emails that he might have been arrested. One year later when the story for Pryce appeared in the news, Mathew thought that he had escaped detection. He was charged the next day of his arrest with two counts [...]
Black Hat Ethical Hacking
Hacking Stories: When two young hackers played war games with Pentagon
Hacking Stories: When two young hackers played war games with Pentagon
Boomerang - A Tool To Expose Multiple Internal Servers To Web/Cloud
Boomerang is a tool to expose multiple internal servers to web/cloud using HTTP+TCP Tunneling. The Server will expose 2 ports on the Cloud. One will be where tools like proxychains can connect over socks, another will be for the agent to connect. The agent can be executed on any internal host. The agent will connect to the server and listen for any connection that can be forwarded to internal machine like a socks server. A more detailed information can be found in the image below. Features like authentication are in pipeline and will be added soon.Agent & Server are pretty stable and can be used in Red Team for Multiple levels of Pivoting and exposing services to external/other networks Boomerang Agent & Server support Windows, Linux and Arm architecture Features in Progress: Proxy Authentication (Use IP Whitelisting for C2s till then) Download Boomerang
Read more...
Boomerang is a tool to expose multiple internal servers to web/cloud using HTTP+TCP Tunneling. The Server will expose 2 ports on the Cloud. One will be where tools like proxychains can connect over socks, another will be for the agent to connect. The agent can be executed on any internal host. The agent will connect to the server and listen for any connection that can be forwarded to internal machine like a socks server. A more detailed information can be found in the image below. Features like authentication are in pipeline and will be added soon.Agent & Server are pretty stable and can be used in Red Team for Multiple levels of Pivoting and exposing services to external/other networks Boomerang Agent & Server support Windows, Linux and Arm architecture Features in Progress: Proxy Authentication (Use IP Whitelisting for C2s till then) Download Boomerang
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Wordlists for Pentester
A Pentester is as good as their tools and when it comes to cracking the password, stressing authentication panels or even a simple directory Bruteforce it all drills down to the wordlists that you use. Today we are going to understand wordlists, look around for some good wordlists, run some
The post Wordlists for Pentester appeared first on Hacking Articles.
Wordlists for Pentester
A Pentester is as good as their tools and when it comes to cracking the password, stressing authentication panels or even a simple directory Bruteforce it all drills down to the wordlists that you use. Today we are going to understand wordlists, look around for some good wordlists, run some
The post Wordlists for Pentester appeared first on Hacking Articles.
Boomerang - A Tool To Expose Multiple Internal Servers To Web/Cloud
http://www.kitploit.com/2021/03/boomerang-tool-to-expose-multiple.html
http://www.kitploit.com/2021/03/boomerang-tool-to-expose-multiple.html
Boomerang is a tool to expose multiple internal servers to web/cloud using HTTP+TCP Tunneling. The Server will expose 2 ports on the Cloud. One will be where tools like proxychains can connect over socks, another will be for the agent to connect. The agent can be executed on any internal host. The agent will connect to the server and listen for any connection that can be forwarded to internal machine like a socks server. A more detailed information can be found in the image below. Features like authentication are in pipeline (https://www.kitploit.com/search/label/Pipeline) and will be added soon.
Agent & Server are pretty stable and can be used in Red Team (https://www.kitploit.com/search/label/Red%20Team) for Multiple levels of Pivoting (https://www.kitploit.com/search/label/Pivoting) and exposing (https://www.kitploit.com/search/label/Exposing) services to external/other networks Boomerang Agent & Server support Windows, Linux and Arm architecture
Features in Progress: Proxy Authentication (Use IP Whitelisting (https://www.kitploit.com/search/label/Whitelisting) for C2s till then)
Download Boomerang (https://github.com/paranoidninja/Boomerang)
Agent & Server are pretty stable and can be used in Red Team (https://www.kitploit.com/search/label/Red%20Team) for Multiple levels of Pivoting (https://www.kitploit.com/search/label/Pivoting) and exposing (https://www.kitploit.com/search/label/Exposing) services to external/other networks Boomerang Agent & Server support Windows, Linux and Arm architecture
Features in Progress: Proxy Authentication (Use IP Whitelisting (https://www.kitploit.com/search/label/Whitelisting) for C2s till then)
Download Boomerang (https://github.com/paranoidninja/Boomerang)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Guide to Stack Buffer Overflow (OSCP)
Stack buffer overflow is a memory corruption vulnerability that occurs when a program writes more data to a buffer located on the stack than what is actually allocated for that buffer, therefore overflowing to a memory address that is outside of the intended data structure.
This will often cause the program to crash, and if certain conditions are met, it could allow an attacker to gain remote control of the machine with privileges as high as the user running the program, by redirecting the flow execution of the application to malicious code.
https://steflan-security.com/complete-guide-to-stack-buffer-overflow-oscp/
Feel free to check out the rest of my blog if you're interested in ethical hacking :)
submitted by /u/cantchooseone96
[link] [comments]
Guide to Stack Buffer Overflow (OSCP)
Stack buffer overflow is a memory corruption vulnerability that occurs when a program writes more data to a buffer located on the stack than what is actually allocated for that buffer, therefore overflowing to a memory address that is outside of the intended data structure.
This will often cause the program to crash, and if certain conditions are met, it could allow an attacker to gain remote control of the machine with privileges as high as the user running the program, by redirecting the flow execution of the application to malicious code.
https://steflan-security.com/complete-guide-to-stack-buffer-overflow-oscp/
Feel free to check out the rest of my blog if you're interested in ethical hacking :)
submitted by /u/cantchooseone96
[link] [comments]
hacking: security in practice
ForceBindIP issue
Hello,
I tried using ForceBindIP on windows to decide which network interfaces must use certain applications.
I just have a couple of curiosities:
- How can I see if it worked?
- What happens if I restart the pc? Save or lose everything?
- If I lose everything, is there a way to not have to do it again every time, or should I create a script with all the programs and run it every time I need?
Many thanks in advance!
submitted by /u/Cikuozzo
[link] [comments]
ForceBindIP issue
Hello,
I tried using ForceBindIP on windows to decide which network interfaces must use certain applications.
I just have a couple of curiosities:
- How can I see if it worked?
- What happens if I restart the pc? Save or lose everything?
- If I lose everything, is there a way to not have to do it again every time, or should I create a script with all the programs and run it every time I need?
Many thanks in advance!
submitted by /u/Cikuozzo
[link] [comments]
reddit
ForceBindIP issue
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
I know hacking is connected to programing so i was wondering anyone know work at C++
We just started in high school work at c++.I need simple program for 1 game that can read certian part of screen and when he see In game name from player bot to type /msg player name + TEXT . in this game there is log bar so u can easly put just to see people names entering. I hope someone know if its not truble to help i can pay if it works :D
submitted by /u/Doki39
[link] [comments]
I know hacking is connected to programing so i was wondering anyone know work at C++
We just started in high school work at c++.I need simple program for 1 game that can read certian part of screen and when he see In game name from player bot to type /msg player name + TEXT . in this game there is log bar so u can easly put just to see people names entering. I hope someone know if its not truble to help i can pay if it works :D
submitted by /u/Doki39
[link] [comments]
reddit
I know hacking is connected to programing so i was wondering...
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
Got attacked by an ENFP RANSOMWARE
I got an enfp ransomware on my laptop. Googling it i found the best way to get rid of it is with an antivirus and then use emisoft to recover the files. But the antivirus keeps on lagging for getting rid of it . It's already been 18 hours since i started the antivirus scan it's still not done. And the emisoft software says the files are encrypted by an online key . Is there any way i can recover my files and get rid of the ransomware. I got some pretty important stuff on the laptop with no backup... Anyone can you please help me.
submitted by /u/Food_is_Gone
[link] [comments]
Got attacked by an ENFP RANSOMWARE
I got an enfp ransomware on my laptop. Googling it i found the best way to get rid of it is with an antivirus and then use emisoft to recover the files. But the antivirus keeps on lagging for getting rid of it . It's already been 18 hours since i started the antivirus scan it's still not done. And the emisoft software says the files are encrypted by an online key . Is there any way i can recover my files and get rid of the ransomware. I got some pretty important stuff on the laptop with no backup... Anyone can you please help me.
submitted by /u/Food_is_Gone
[link] [comments]
reddit
Got attacked by an ENFP RANSOMWARE
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Poking At Elasticsearch: Beyond Just Dumping Data
https://www.reddit.com/r/redteamsec/comments/mfnvpy/poking_at_elasticsearch_beyond_just_dumping_data/
submitted by /u/DLLCoolJ (https://www.reddit.com/user/DLLCoolJ)
[link] (https://www.archcloudlabs.com/projects/poking-at-elasticsearch-beyond-dumping-data/) [comments] (https://www.reddit.com/r/redteamsec/comments/mfnvpy/poking_at_elasticsearch_beyond_just_dumping_data/)
https://www.reddit.com/r/redteamsec/comments/mfnvpy/poking_at_elasticsearch_beyond_just_dumping_data/
submitted by /u/DLLCoolJ (https://www.reddit.com/user/DLLCoolJ)
[link] (https://www.archcloudlabs.com/projects/poking-at-elasticsearch-beyond-dumping-data/) [comments] (https://www.reddit.com/r/redteamsec/comments/mfnvpy/poking_at_elasticsearch_beyond_just_dumping_data/)