Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Threat Analysis Honey Pot — Tokyo
https://cdn-images-1.medium.com/max/800/0*DgZJ0aalxYDsfcFE
INTRODUCTION
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Threat Analysis Honey Pot — Tokyo
https://cdn-images-1.medium.com/max/800/0*DgZJ0aalxYDsfcFE
INTRODUCTION
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Threat Analysis Honey Pot — Tokyo
INTRODUCTION
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Thanks for checking out my profile, just found this site by accident.
If you still use IRC (yes, people still use it) feel free to join #9x/EFNet to connect with a bunch of my long time hax0r friends,.. many…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Thanks for checking out my profile, just found this site by accident.
If you still use IRC (yes, people still use it) feel free to join #9x/EFNet to connect with a bunch of my long time hax0r friends,.. many…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Thanks for checking out my profile, just found this site by accident.
If you still use IRC (yes, people still use it) feel free to join #9x/EFNet to connect with a bunch of my long time hax0r friends,.. many…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Sensitive data of 400,000 German students exposed by API flaw
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Sensitive data of 400,000 German students exposed by API flawPost Views: 89
Reading Time: 1 Minute
Approximately 400,000 users of Scoolio, a student community app widely used in Germany, had sensitive information exposed due to an API flaw in the platform. Lilith Wittmann, a security researcher from the IT security collective “Zerforchung” discovered the bug and immediately disclosed their findings to the Scoolio team. A “student” businessScoolio is a German student community app that aims to build better time management skills, tutoring, homework planning, and group chats to network with peers. The app also allows companies to network with students to share job openings or internship opportunities.
Scoolio makes money by collecting data generated through these tools and features and then monetizing it with targeted advertising. However, Scoolio states that they do not collect or share any information from students without their consent.
To build student membership, Scoolio has partnered with schools around Germany to use their platform as a remote teaching assistance tool for file exchanges or remote digital homework collection.
It’s very development was financially backed by three state-owned investment groups, namely SIB Innovations – und Beteiligungsgesellschaft mbH, Technologiegründerfonds Sachsen, and Kreissparkasse Bautzen.
Due to the partnerships and government backings, many students use the app as a standard tool in their classes.
See Also: Complete Offensive Security and Ethical Hacking Course Data exposed by leaky APIIn Zerforchung’s report, Wittmann explains how she exploited Scoolio API flaws to retrieve extremely sensitive data for any user ID used on the app.
The exposed personal data includes:
* User nickname
* User and parent email addresses
* GPS location at which the app was last opened
* Name of school and class
* Interests
* UUID details
* Personality traits (origin, religion, sexuality)
Wittman shared a fictitious sample of the types of data exposed by the flaw below.
https://www.bleepstatic.com/images/news/security/scoolio-data.jpg
Fix released after thirty daysZerforchung states that they disclosed the flaw to Scoolio on September 21, 2021, but it took the software developer until October 25, 2021 to deploy a patch.
However, due to the simplicity of the fix and the sensitive nature of the exposed data, Wittmann believes the fix should have been released more quickly. “I would like to thank Ms. Wittmann for the information and the SDS for the exchange and thank you for your feedback on our security measures,” Danny Roller, CEO andFounder of the Scoolio app, shared in a statement.
“Fortunately, after extensive testing, we can confirm that No user data was intercepted by third parties prior to the investigation by Ms. Wittmann and we have successfull[...]
___________________________
@hacking_Attack
@Hacking_Video
Sensitive data of 400,000 German students exposed by API flaw
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Sensitive data of 400,000 German students exposed by API flawPost Views: 89
Reading Time: 1 Minute
Approximately 400,000 users of Scoolio, a student community app widely used in Germany, had sensitive information exposed due to an API flaw in the platform. Lilith Wittmann, a security researcher from the IT security collective “Zerforchung” discovered the bug and immediately disclosed their findings to the Scoolio team. A “student” businessScoolio is a German student community app that aims to build better time management skills, tutoring, homework planning, and group chats to network with peers. The app also allows companies to network with students to share job openings or internship opportunities.
Scoolio makes money by collecting data generated through these tools and features and then monetizing it with targeted advertising. However, Scoolio states that they do not collect or share any information from students without their consent.
To build student membership, Scoolio has partnered with schools around Germany to use their platform as a remote teaching assistance tool for file exchanges or remote digital homework collection.
It’s very development was financially backed by three state-owned investment groups, namely SIB Innovations – und Beteiligungsgesellschaft mbH, Technologiegründerfonds Sachsen, and Kreissparkasse Bautzen.
Due to the partnerships and government backings, many students use the app as a standard tool in their classes.
See Also: Complete Offensive Security and Ethical Hacking Course Data exposed by leaky APIIn Zerforchung’s report, Wittmann explains how she exploited Scoolio API flaws to retrieve extremely sensitive data for any user ID used on the app.
The exposed personal data includes:
* User nickname
* User and parent email addresses
* GPS location at which the app was last opened
* Name of school and class
* Interests
* UUID details
* Personality traits (origin, religion, sexuality)
Wittman shared a fictitious sample of the types of data exposed by the flaw below.
https://www.bleepstatic.com/images/news/security/scoolio-data.jpg
Fix released after thirty daysZerforchung states that they disclosed the flaw to Scoolio on September 21, 2021, but it took the software developer until October 25, 2021 to deploy a patch.
However, due to the simplicity of the fix and the sensitive nature of the exposed data, Wittmann believes the fix should have been released more quickly. “I would like to thank Ms. Wittmann for the information and the SDS for the exchange and thank you for your feedback on our security measures,” Danny Roller, CEO andFounder of the Scoolio app, shared in a statement.
“Fortunately, after extensive testing, we can confirm that No user data was intercepted by third parties prior to the investigation by Ms. Wittmann and we have successfull[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Sensitive data of 400,000 German students exposed by API flaw | Black Hat Ethical Hacking
Approximately 400,000 users of Scoolio, a student community app widely used in Germany, had sensitive information exposed due to an API flaw in the platform.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Sensitive data of 400,000 German students exposed by API flaw https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Sensitive data of 400,000 German students exposed by API flawPost Views: 89 …
y closed the gaps found.”
See Also: OSINT Tool: Osintgram
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers2 weeks ago
The post Sensitive data of 400,000 German students exposed by API flaw first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
See Also: OSINT Tool: Osintgram
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers2 weeks ago
The post Sensitive data of 400,000 German students exposed by API flaw first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
SQL Injection JR. Pentester -TryHackMe Part 2
https://mukibas37.medium.com/sql-injection-jr-pentester-tryhackme-part-2-3b9d106e9d7b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://mukibas37.medium.com/sql-injection-jr-pentester-tryhackme-part-2-3b9d106e9d7b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
SQL Injection JR. Pentester -TryHackMe Part 2
Hi folks, welcome back to part 2 of SQL injection in JR. Pentester path.
Hi folks, welcome back to part 2 of SQL injection in JR. Pentester path.Continue reading on Medium » (https://mukibas37.medium.com/sql-injection-jr-pentester-tryhackme-part-2-3b9d106e9d7b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
SQL Injection JR. Pentester -TryHackMe Part 2
Hi folks, welcome back to part 2 of SQL injection in JR. Pentester path.
Analyzing Java Heap dumps via OQL queries
https://blog.defmax.io/analyzing-java-heap-dumps-via-oql-queries-fef8a8416017?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://blog.defmax.io/analyzing-java-heap-dumps-via-oql-queries-fef8a8416017?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Analyzing Java Heap Dumps via OQL queries
Java heap dumps contain sensitive data like Environment files, Passwords, Secret keys. This head dump is exposed by the Spring boot…
Java heap dumps contain sensitive data like Environment files, Passwords, Secret keys. This head dump is exposed by the Spring boot…Continue reading on Defmax » (https://blog.defmax.io/analyzing-java-heap-dumps-via-oql-queries-fef8a8416017?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Analyzing Java Heap Dumps via OQL queries
Java heap dumps contain sensitive data like Environment files, Passwords, Secret keys. This head dump is exposed by the Spring boot…
DonPAPI - Dumping DPAPI Credz Remotely
http://www.kitploit.com/2021/10/donpapi-dumping-dpapi-credz-remotely.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/10/donpapi-dumping-dpapi-credz-remotely.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Curently gathered info
Windows credentials (Taskscheduled credentials & a lot more) Windows Vaults Windows RDP credentials AdConnect (still require a manual operation) Wifi key Intenet explorer Creentials Chrome cookies & credentials Firefox cookies & credentials VNC passwords mRemoteNG password (with default config)
Check for a bit of compliance
SMB signing status OS/Domain/Hostname/Ip of the audited scope
Operational use
With local admin account on a host, we can : Gather machine protected DPAPI secrets ScheduledTask that will contain cleartext login/password of the account configured to run the task Wi-Fi passwords Extract Masterkey's hash value for every user profiles (masterkeys beeing protected by the user's password, let's try to crack them with Hashcat) Identify who is connected from where, in order to identify admin's personal computers. Extract other non-dpapi protected secrets (VNC/Firefox/mRemoteNG) Gather protected secrets from IE, Chrome, Firefox and start reaching the Azure tenant. With a user password, or the domain PVK we can unprotect the user's DPAPI secrets.
Examples
Dump all secrets of the target machine with an admin account : DonPAPI.py domain/user:passw0rd@target Using user's hash : domain/user@target ">DonPAPI.py --hashes : domain/user@target Using kerberos (-k) and local auth (-local_auth) DonPAPI.py -k domain/user@target
DonPAPI.py -local_auth user@target Using a user with LAPS password reading rights DonPAPI.py -laps domain/user:passw0rd@target It is also possible to provide the tool with a list of credentials that will be tested on the target. DonPAPI will try to use them to decipher masterkeys. This credential file must have the following syntax: user1:pass1 user2:pass2 ... user1:pass1
user2:pass2
...
When a domain admin user is available, it is possible to dump the domain backup key using impacket dpapi.py tool. DonPAPI.py -credz credz_file.txt domain/user:passw0rd@target This backup key can then be used to dump all domain user's secrets! python DonPAPI.py -pvk domain_backupkey.pvk domain/user:passw0rd@domain_network_list Target can be an IP, IP range, CIDR, file containing list targets (one per line)
Opsec consideration
The RemoteOps part can be spoted by some EDR. It can be disabled using --no_remoteops flag, but then the machine DPAPI key won't be retrieved, and scheduled task credentials/Wi-Fi passwords (https://www.kitploit.com/search/label/Passwords) won't be harvested.
Installation
dpapi.py backupkey --export
Credits
All the credits goes to these great guys for doing the hard research & coding : Benjamin Delpy (@gentilkiwi (https://twitter.com/gentilkiwi)) for most of the DPAPI research (always greatly commented, Alberto Solino (@agsolino (https://twitter.com/agsolino)) for the tremendous work of Impacket (https://www.kitploit.com/search/label/Impacket) (https://github.com/SecureAuthCorp/impacket). Almost everything we do here comes from impacket. Alesandro Z (https://github.com/AlessandroZ) & everyone who worked on Lazagne (https://github.com/AlessandroZ/LaZagne/wiki) for the VNC & Firefox modules, and most likely for a lots of other ones in the futur. dirkjanm @_dirkjan (https://twitter.com/_dirkjan) for the base code of adconnect dump (https://github.com/fox-it/adconnectdump) & every research he ever did. I learned so much on so many subjects thanks to you. @byt3bl33d3r (https://twitter.com/byt3bl33d3r) for CME (lots of inspiration and code comes from CME : https://github.com/byt3bl33d3r/CrackMapExec ) All the Team at @LoginSecurite (https://twitter.com/LoginSecurite) for their help in debugging (https://www.kitploit.com/search/label/Debugging) my shity code (special thanks to @layno (https://github.com/clayno) & @HackAndDo (https://twitter.com/HackAndDo) for that)
Todo
___________________________
@hacking_Attack
@Hacking_Video
Windows credentials (Taskscheduled credentials & a lot more) Windows Vaults Windows RDP credentials AdConnect (still require a manual operation) Wifi key Intenet explorer Creentials Chrome cookies & credentials Firefox cookies & credentials VNC passwords mRemoteNG password (with default config)
Check for a bit of compliance
SMB signing status OS/Domain/Hostname/Ip of the audited scope
Operational use
With local admin account on a host, we can : Gather machine protected DPAPI secrets ScheduledTask that will contain cleartext login/password of the account configured to run the task Wi-Fi passwords Extract Masterkey's hash value for every user profiles (masterkeys beeing protected by the user's password, let's try to crack them with Hashcat) Identify who is connected from where, in order to identify admin's personal computers. Extract other non-dpapi protected secrets (VNC/Firefox/mRemoteNG) Gather protected secrets from IE, Chrome, Firefox and start reaching the Azure tenant. With a user password, or the domain PVK we can unprotect the user's DPAPI secrets.
Examples
Dump all secrets of the target machine with an admin account : DonPAPI.py domain/user:passw0rd@target Using user's hash : domain/user@target ">DonPAPI.py --hashes : domain/user@target Using kerberos (-k) and local auth (-local_auth) DonPAPI.py -k domain/user@target
DonPAPI.py -local_auth user@target Using a user with LAPS password reading rights DonPAPI.py -laps domain/user:passw0rd@target It is also possible to provide the tool with a list of credentials that will be tested on the target. DonPAPI will try to use them to decipher masterkeys. This credential file must have the following syntax: user1:pass1 user2:pass2 ... user1:pass1
user2:pass2
...
When a domain admin user is available, it is possible to dump the domain backup key using impacket dpapi.py tool. DonPAPI.py -credz credz_file.txt domain/user:passw0rd@target This backup key can then be used to dump all domain user's secrets! python DonPAPI.py -pvk domain_backupkey.pvk domain/user:passw0rd@domain_network_list Target can be an IP, IP range, CIDR, file containing list targets (one per line)
Opsec consideration
The RemoteOps part can be spoted by some EDR. It can be disabled using --no_remoteops flag, but then the machine DPAPI key won't be retrieved, and scheduled task credentials/Wi-Fi passwords (https://www.kitploit.com/search/label/Passwords) won't be harvested.
Installation
dpapi.py backupkey --export
Credits
All the credits goes to these great guys for doing the hard research & coding : Benjamin Delpy (@gentilkiwi (https://twitter.com/gentilkiwi)) for most of the DPAPI research (always greatly commented, Alberto Solino (@agsolino (https://twitter.com/agsolino)) for the tremendous work of Impacket (https://www.kitploit.com/search/label/Impacket) (https://github.com/SecureAuthCorp/impacket). Almost everything we do here comes from impacket. Alesandro Z (https://github.com/AlessandroZ) & everyone who worked on Lazagne (https://github.com/AlessandroZ/LaZagne/wiki) for the VNC & Firefox modules, and most likely for a lots of other ones in the futur. dirkjanm @_dirkjan (https://twitter.com/_dirkjan) for the base code of adconnect dump (https://github.com/fox-it/adconnectdump) & every research he ever did. I learned so much on so many subjects thanks to you. @byt3bl33d3r (https://twitter.com/byt3bl33d3r) for CME (lots of inspiration and code comes from CME : https://github.com/byt3bl33d3r/CrackMapExec ) All the Team at @LoginSecurite (https://twitter.com/LoginSecurite) for their help in debugging (https://www.kitploit.com/search/label/Debugging) my shity code (special thanks to @layno (https://github.com/clayno) & @HackAndDo (https://twitter.com/HackAndDo) for that)
Todo
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Finish ADSync/ADConnect password extraction CREDHISTORY full extraction Extract windows Certificates Further analysis (https://www.kitploit.com/search/label/Analysis) ADAL/msteams Implement Chrome Find a way to implement Lazagne's great modules
Changelog
git clone https://github.com/login-securite/DonPAPI.git
cd DonPAPI
python3 -m pip install -r requirements.txt
python3 DonPAPI.py
Download DonPAPI (https://github.com/login-securite/DonPAPI)
___________________________
@hacking_Attack
@Hacking_Video
Changelog
git clone https://github.com/login-securite/DonPAPI.git
cd DonPAPI
python3 -m pip install -r requirements.txt
python3 DonPAPI.py
Download DonPAPI (https://github.com/login-securite/DonPAPI)
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Covert-Tube : Youtube As Covert-Channel – Control Systems Remotely And Execute Commands By Uploading Videos To Youtube
Covert-Tube is a program to control systems remotely by uploading videos to Youtube using Python to create the videos and the listener, emulating some malware I was reading about. It allows to create videos with frames formed of simple text, QR codes with cleartext or QR codes using AES encryption.
Create A Video
The videos can be created using generate_video.py: enter the commands and generate the video writing “exit”. The video generated is called by default output.avi (can be updated in config.py):
python3 generate_video.py
https://blogger.googleusercontent.com/img/a/AVvXsEiZfWLWnijr25g6LxqO9tVlFUxm3Bo9Anf1oMDYZY2pa7Qmb8fmMIecNitcrWecbTjVfuyHA4haOyvbNI2dh67Y3zc-FzCIdhZpSSv1qMaVM-32aR-n26qB_u5B75E5E5_nJfN2Pn2uzCtgY3Si2Wvy07CiIbDQ9OyYQIQ1cB7NTLFqXBElMTIlX5ye=s762
Run the listener and upload the video to Youtube
python3 main.py
The listener will check the Youtube channel every 300 seconds by default (can be updated in config.py). First the video is uploaded:
https://blogger.googleusercontent.com/img/a/AVvXsEg62SFLdUnJkUq_Dd3_HIMmJ-gCtMFQ5gbr_1AxObary_4Q-6uoyg-qZvkET9akcLaWfxAMKXngJg1456QiEKTLytTLbKzNEfdsefZRuVabQgdkaZcBkEAjunT_1vkGsZbsE7WOWPUqOJ8Ffso9cptgYIalFmdk1Pen3Vi6hEjb8h9EqHTroQV_xoot=s463
After finding there is a new video in the channel, it is downloaded and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEhwriT696LFBPvKl8YHPXrJ1M_QJ6dcnJ8rDxU4HChbc-wmJs8QS5ZWA0-dauipND_soyiJJmMB88Lp1Db8gD7yzetAYGDXrngPynr8-7Jr3DxinonhHpca4vR21nmG2gA6VS7ejrN1Vv2ekRX0B7-Pj3o0PcS-bfqztVyxscYrwPDyjF10T-4DTPby=s662
We can see the output from the commands:
https://blogger.googleusercontent.com/img/a/AVvXsEgMvI-MegjSOa3qQxQNhrb1trN5S4fpUe6vCVo4Dd2C4vfjsZKEYy58BNQqCrJ8A9BnVQA3mY6SFtPzgp0KIK0sgAp5tXbXtxbF1NciWSYgcCdBLCmwsxDvE0fGk6Cullud10zzjzylStAVUCtUSFIlsjfFvgWGYV_mW80mJtgCr9SXzZXSJRDWQjKF=s571
Configuration
Update the config.py file:
* channel_id (Mandatory!!!): Get your Youtube channel ID from here.
* api_key (Mandatory!!!): To get the API key create an application and generate the key from here.
* image_type (Optional. Default: “qr_aes”): Different types of images for the video.
* “cleartext” creates images with the words of the commands.
* “qr” creates QR codes with the commands.
* “qr_aes” creates QR codes with the commands encrypted with AES.
* upload_seconds_delay (Optional. Default: 300): Seconds delay until checking if a new video has been uploaded.
* debug (Optional. Default: True): Print messages or not.
* aes_key (Optional. Default: “covert-tube_2021”): Key for AES encryption, used in the “qr_aes” option.
* generated_video_path (Optional. Default: “output.avi”): Path of video generated with generate_video.py.
* downloaded_video_path (Optional. Default: “/tmp/test.mp4”): Path where the new video will be downloaded.
* temp_folder (Optional. Default: “/tmp/”): Path where images of every frame from the video are stored, with the format image_X.png.
Installation
For all the project:
sudo apt install libzbar0
pip3 install Pillow opencv-python youtube_dl pytesseract pyqrcode pypng pyzbar pycrypto
git clone https://github.com/ricardojoserf/covert-tube
Creating a standalone binary
pyinstaller –onefile main.py
cp dist/main covert-tube
rm -rf dist build
rm main.spec
Download
___________________________
@hacking_Attack
@Hacking_Video
Covert-Tube : Youtube As Covert-Channel – Control Systems Remotely And Execute Commands By Uploading Videos To Youtube
Covert-Tube is a program to control systems remotely by uploading videos to Youtube using Python to create the videos and the listener, emulating some malware I was reading about. It allows to create videos with frames formed of simple text, QR codes with cleartext or QR codes using AES encryption.
Create A Video
The videos can be created using generate_video.py: enter the commands and generate the video writing “exit”. The video generated is called by default output.avi (can be updated in config.py):
python3 generate_video.py
https://blogger.googleusercontent.com/img/a/AVvXsEiZfWLWnijr25g6LxqO9tVlFUxm3Bo9Anf1oMDYZY2pa7Qmb8fmMIecNitcrWecbTjVfuyHA4haOyvbNI2dh67Y3zc-FzCIdhZpSSv1qMaVM-32aR-n26qB_u5B75E5E5_nJfN2Pn2uzCtgY3Si2Wvy07CiIbDQ9OyYQIQ1cB7NTLFqXBElMTIlX5ye=s762
Run the listener and upload the video to Youtube
python3 main.py
The listener will check the Youtube channel every 300 seconds by default (can be updated in config.py). First the video is uploaded:
https://blogger.googleusercontent.com/img/a/AVvXsEg62SFLdUnJkUq_Dd3_HIMmJ-gCtMFQ5gbr_1AxObary_4Q-6uoyg-qZvkET9akcLaWfxAMKXngJg1456QiEKTLytTLbKzNEfdsefZRuVabQgdkaZcBkEAjunT_1vkGsZbsE7WOWPUqOJ8Ffso9cptgYIalFmdk1Pen3Vi6hEjb8h9EqHTroQV_xoot=s463
After finding there is a new video in the channel, it is downloaded and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEhwriT696LFBPvKl8YHPXrJ1M_QJ6dcnJ8rDxU4HChbc-wmJs8QS5ZWA0-dauipND_soyiJJmMB88Lp1Db8gD7yzetAYGDXrngPynr8-7Jr3DxinonhHpca4vR21nmG2gA6VS7ejrN1Vv2ekRX0B7-Pj3o0PcS-bfqztVyxscYrwPDyjF10T-4DTPby=s662
We can see the output from the commands:
https://blogger.googleusercontent.com/img/a/AVvXsEgMvI-MegjSOa3qQxQNhrb1trN5S4fpUe6vCVo4Dd2C4vfjsZKEYy58BNQqCrJ8A9BnVQA3mY6SFtPzgp0KIK0sgAp5tXbXtxbF1NciWSYgcCdBLCmwsxDvE0fGk6Cullud10zzjzylStAVUCtUSFIlsjfFvgWGYV_mW80mJtgCr9SXzZXSJRDWQjKF=s571
Configuration
Update the config.py file:
* channel_id (Mandatory!!!): Get your Youtube channel ID from here.
* api_key (Mandatory!!!): To get the API key create an application and generate the key from here.
* image_type (Optional. Default: “qr_aes”): Different types of images for the video.
* “cleartext” creates images with the words of the commands.
* “qr” creates QR codes with the commands.
* “qr_aes” creates QR codes with the commands encrypted with AES.
* upload_seconds_delay (Optional. Default: 300): Seconds delay until checking if a new video has been uploaded.
* debug (Optional. Default: True): Print messages or not.
* aes_key (Optional. Default: “covert-tube_2021”): Key for AES encryption, used in the “qr_aes” option.
* generated_video_path (Optional. Default: “output.avi”): Path of video generated with generate_video.py.
* downloaded_video_path (Optional. Default: “/tmp/test.mp4”): Path where the new video will be downloaded.
* temp_folder (Optional. Default: “/tmp/”): Path where images of every frame from the video are stored, with the format image_X.png.
Installation
For all the project:
sudo apt install libzbar0
pip3 install Pillow opencv-python youtube_dl pytesseract pyqrcode pypng pyzbar pycrypto
git clone https://github.com/ricardojoserf/covert-tube
Creating a standalone binary
pyinstaller –onefile main.py
cp dist/main covert-tube
rm -rf dist build
rm main.spec
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Covert-Tube : Youtube As Covert-Channel - Control Systems Remotely
Covert-Tube is a program to control systems remotely by uploading videos to Youtube using Python to create the videos and the listener.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
AF-ShellHunter : Auto Shell Lookup
AF-ShellHunter its a script designed to automate the search of WebShell’s in AF Team
How To
pip3 install -r requirements.txt
python3 shellhunter.py –help
Basic Usage
You can run shellhunter in two modes
* –url -u When scanning a single url
* –file -f Scanning multiple URLs at once
Example searching webshell with burpsuite proxy, hiding string “404” with a size between 100 and 1000 chars
┌──(blueudp㉿xxxxxxxx)-[~/AF-ShellHunter]
└─$ python3 shellhunter.py -u https://xxxxxxxxxx -hs “404” -p burp –greater-than 100 –smaller-than 1000
Running AF-Team ShellHunt 1.1.0
URL: https://xxxxxxxxxx
Showing only: 200, 302
Threads: 20
Not showing coincidence with: 404
Proxy: burp
Greater than: 100
Smaller than: 1000
Found https://xxxxxxxxxx/system.php len: 881
File Configuration For Multiple Sites
phishing_list
#How to?
#set country block with [country], please read user_files/config.txt
#’show-response-code “option1” “option2″‘ -> show responses with those status codes, as -sc
#’show-string’ -> show match with that string, as -ss
#’show-regex’ -> show match with regex, as -sr
#use ‘not’ for not showing X in above options, as -h[option]
#’greater-than’ -> Show response greater than X, as -gt ( –greater-than )
#’smaller-than’ -> Show responses smaller than X, as -st ( –smaller-than )
#Example searching webshell with BurpSuite proxy. 302, 200 status code, not showing results w/ ‘página en mantenimiento’ with size between 100 and 1000 chars
[burp]
https://banco.phishing->show-response-code “302” “200”, not show-string “página en mantenimiento”, greater-than 100, smaller-than 1000
[noproxy]
banco.es-> # ShellHunt will add ‘http://
Setting Your Proxies And Custom Headers
config.txt
[HEADERS] # REQUESTS CUSTOM HEADERS, ADD ‘OPTION: VALUE’
User-Agent? Mozilla/5.0 (Linux; Android 8.0.0; SM-G960F Build/R16NW) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.84 Mobile Safari/537.36
Referer? bit.ly/THIS_is_PHISHING # Bypass referer protection
[PROXIES]
burp? https://127.0.0.1:8080,http://127.0.0.1:8080
Other Features
* Filter by regex
* Filter by string
* Filter by HTTP Status code
* Filter by length
* Custom Headers
* Custom proxy or proxy block for URL file
* Multithreading ( custom workers number )
Download
___________________________
@hacking_Attack
@Hacking_Video
AF-ShellHunter : Auto Shell Lookup
AF-ShellHunter its a script designed to automate the search of WebShell’s in AF Team
How To
pip3 install -r requirements.txt
python3 shellhunter.py –help
Basic Usage
You can run shellhunter in two modes
* –url -u When scanning a single url
* –file -f Scanning multiple URLs at once
Example searching webshell with burpsuite proxy, hiding string “404” with a size between 100 and 1000 chars
┌──(blueudp㉿xxxxxxxx)-[~/AF-ShellHunter]
└─$ python3 shellhunter.py -u https://xxxxxxxxxx -hs “404” -p burp –greater-than 100 –smaller-than 1000
Running AF-Team ShellHunt 1.1.0
URL: https://xxxxxxxxxx
Showing only: 200, 302
Threads: 20
Not showing coincidence with: 404
Proxy: burp
Greater than: 100
Smaller than: 1000
Found https://xxxxxxxxxx/system.php len: 881
File Configuration For Multiple Sites
phishing_list
#How to?
#set country block with [country], please read user_files/config.txt
#’show-response-code “option1” “option2″‘ -> show responses with those status codes, as -sc
#’show-string’ -> show match with that string, as -ss
#’show-regex’ -> show match with regex, as -sr
#use ‘not’ for not showing X in above options, as -h[option]
#’greater-than’ -> Show response greater than X, as -gt ( –greater-than )
#’smaller-than’ -> Show responses smaller than X, as -st ( –smaller-than )
#Example searching webshell with BurpSuite proxy. 302, 200 status code, not showing results w/ ‘página en mantenimiento’ with size between 100 and 1000 chars
[burp]
https://banco.phishing->show-response-code “302” “200”, not show-string “página en mantenimiento”, greater-than 100, smaller-than 1000
[noproxy]
banco.es-> # ShellHunt will add ‘http://
Setting Your Proxies And Custom Headers
config.txt
[HEADERS] # REQUESTS CUSTOM HEADERS, ADD ‘OPTION: VALUE’
User-Agent? Mozilla/5.0 (Linux; Android 8.0.0; SM-G960F Build/R16NW) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.84 Mobile Safari/537.36
Referer? bit.ly/THIS_is_PHISHING # Bypass referer protection
[PROXIES]
burp? https://127.0.0.1:8080,http://127.0.0.1:8080
Other Features
* Filter by regex
* Filter by string
* Filter by HTTP Status code
* Filter by length
* Custom Headers
* Custom proxy or proxy block for URL file
* Multithreading ( custom workers number )
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
AF-ShellHunter : Auto Shell Lookup !!! Kali Linux Tutorials
AF-ShellHunter its a script designed to automate the search of WebShell's in AF Team. You can run shellhunter in two modes.
SQL Injection JR. Pentester -TryHackMe Part 2
Hi folks, welcome back to part 2 of SQL injection in JR. Pentester path.Continue reading on Medium »
Read more...
Hi folks, welcome back to part 2 of SQL injection in JR. Pentester path.Continue reading on Medium »
Read more...
Analyzing Java Heap dumps via OQL queries
Java heap dumps contain sensitive data like Environment files, Passwords, Secret keys. This head dump is exposed by the Spring boot…Continue reading on Defmax »
Read more...
Java heap dumps contain sensitive data like Environment files, Passwords, Secret keys. This head dump is exposed by the Spring boot…Continue reading on Defmax »
Read more...