Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hacking stories – Operation Troy – How researchers linked the cyberattacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Hacking stories – Operation Troy – How researchers linked the cyberattackshttps://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Post Views: 128
Reading Time: 7 Minutes
South Korea was the victim of an enormous cyberattack on March 20, 2013. The attack was meant to cause damage and affected multiple organizations like South Korean TV networks and financial institutions by deleting thousands of computer hard drives using wiper-malware.
A lot of security firms provided insights into the likely source of these attacks and how they happened. The attack was initially known as “Dark Seoul” and now as “Operation Troy”. The name Troy comes from repeated citations of the ancient city found in the compile path strings of the malware code.
The analysis from the McAfee security firm showed that the attacks, in addition to the data losses of the master boot record (MBR), were actually the last part of the attack of a covert espionage campaign coming from North Korea.
The adversaries
Software developers or hackers tend to leave fingerprints and footprints in their code, little pieces of artifacts in the code that can be used by forensic investigators to try and determine the original source of the intended piece of code or program.
Researchers determine that the primary hacking group responsible for the attacks was the New Romanic Cyber Army Team, which significantly uses Roman terms in their code. The majority of wipers contained strings named “principes” and “hastati,” which also appear in a message left on one of the targeted websites in the form of a web pop-up.
The other hacking group was “The Whois Hacking Team”, where they defaced the website of the network provider LG on March 20th. Researchers found that some wiper components worked differently from the wipers employed by the New Romanic team, where it also included the same graphics (in a resource file in the binary) that appeared on the defaced LG website.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/whoisgroup.png
Message by the Whois Hacking team on a defaced website - credit: Tracing the Lineage of DarkSeoul - David Martin.
Anatomy of the attack
What types of malware involved?
A few types of malware were involved in those attacks which had a direct result of the destruction of computer machines using the MBR wiper component and remote access to the targets for a period before the attack.
The dropper Trojan was primarily used to download the executable that destroyed the systems’ MBRs. MBR wiper, upon execution, it was immediately starting to wipe the system and render it unbootable. The dropper installed the wiper, which destroyed the MBRs, when the dropper was executed, the systems were wiped within minutes.
The remote-access Trojan, as McAfee researchers determine that the attackers had access to the systems before wiping them, the remote-access trojan was likely delivered to an internal machine via a successful spear-phishing attack.
They also used an IRC botnet that relied upon a network of hacked South Korean websites where they hosted their IRC servers. The infected machines communicated through the IRC servers and used functions imported from the Microsoft Cryptography API library, bs.dll, where they hardcoded the control domains in it.
NSTAR Trojan was the first in the production of the Troy family, dating back in 2009 when it was created for a phishing espionage campaign. NSTAR used c[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking stories – Operation Troy – How researchers linked the cyberattacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Hacking stories – Operation Troy – How researchers linked the cyberattackshttps://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Post Views: 128
Reading Time: 7 Minutes
South Korea was the victim of an enormous cyberattack on March 20, 2013. The attack was meant to cause damage and affected multiple organizations like South Korean TV networks and financial institutions by deleting thousands of computer hard drives using wiper-malware.
A lot of security firms provided insights into the likely source of these attacks and how they happened. The attack was initially known as “Dark Seoul” and now as “Operation Troy”. The name Troy comes from repeated citations of the ancient city found in the compile path strings of the malware code.
The analysis from the McAfee security firm showed that the attacks, in addition to the data losses of the master boot record (MBR), were actually the last part of the attack of a covert espionage campaign coming from North Korea.
The adversaries
Software developers or hackers tend to leave fingerprints and footprints in their code, little pieces of artifacts in the code that can be used by forensic investigators to try and determine the original source of the intended piece of code or program.
Researchers determine that the primary hacking group responsible for the attacks was the New Romanic Cyber Army Team, which significantly uses Roman terms in their code. The majority of wipers contained strings named “principes” and “hastati,” which also appear in a message left on one of the targeted websites in the form of a web pop-up.
The other hacking group was “The Whois Hacking Team”, where they defaced the website of the network provider LG on March 20th. Researchers found that some wiper components worked differently from the wipers employed by the New Romanic team, where it also included the same graphics (in a resource file in the binary) that appeared on the defaced LG website.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/whoisgroup.png
Message by the Whois Hacking team on a defaced website - credit: Tracing the Lineage of DarkSeoul - David Martin.
Anatomy of the attack
What types of malware involved?
A few types of malware were involved in those attacks which had a direct result of the destruction of computer machines using the MBR wiper component and remote access to the targets for a period before the attack.
The dropper Trojan was primarily used to download the executable that destroyed the systems’ MBRs. MBR wiper, upon execution, it was immediately starting to wipe the system and render it unbootable. The dropper installed the wiper, which destroyed the MBRs, when the dropper was executed, the systems were wiped within minutes.
The remote-access Trojan, as McAfee researchers determine that the attackers had access to the systems before wiping them, the remote-access trojan was likely delivered to an internal machine via a successful spear-phishing attack.
They also used an IRC botnet that relied upon a network of hacked South Korean websites where they hosted their IRC servers. The infected machines communicated through the IRC servers and used functions imported from the Microsoft Cryptography API library, bs.dll, where they hardcoded the control domains in it.
NSTAR Trojan was the first in the production of the Troy family, dating back in 2009 when it was created for a phishing espionage campaign. NSTAR used c[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Hacking stories – Operation Troy – How researchers linked the cyberattacks | Black Hat Ethical Hacking
South Korea was the victim of an enormous cyberattack on March 20, 2013. The attack was meant to cause damage and affected multiple organizations like South Korean TV networks and financial institutions by deleting thousands of computer hard drives using…
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hacking stories – Operation Troy – How researchers linked the cyberattacks https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Hacking stories – Operation Troy – How researchers linked the c…
omponents in the same way that the 7 later variants of the Troy family did, as it included a shared DLL (bs.dll) that was found in the 2010 and 2011 variants.
The next variants that will follow “Chang and EagleXP” 2010, “HTTP Troy” 2011, “Http Dr0pper” 2012,” Tong” 2012, “TDrop” 2013, haven’t had much of change in their core functionality but had more to do with the programming technique.
The researchers based their results to trace the legacy of the Troy variants on the fingerprints and footprints left from the malicious developers that were examined in the source code of the malware variants.
The compile paths, a type of fingerprint, that was tracked by the researchers, are the paths through the developer’s computer file directory (work directory) to the location at which the source code is stored, where documented in the report.
The NSTAR variant used the same DLL as Troy, Chang/EagleXP as we can see below.
The compile path of NSTAR was: E:\Work\BackUp\2011\nstar_1103\BackDoor\BsDllup\Release\BsDll.pdb whileHTTP Troy’s was:
Z:\source\1\HttpTroy\BsDll-up\Release\BsDll.pdb
Http Dr0pper, included the compile path: Z:\\1Mission\\Team_Project\\[2012.6~]\\HTTPTroy\\HttpDr0pper\\Win32\\Release, indicating that it was based on HTTP Troy variant as a more advanced version compiled in 2012.
Many of the variants were disguised as executable files of a security product. Http Dr0per was used to disguise its dropper component with the AhnlabUpdate.exe. Just as Http Dr0per , TDrop which was compiled on January 15, 2013, used the same executable (AhnlabUpdate.exe) to disguise its dropper.
They also shared the same file-mapping function and DLL as well.
Http Dr0per code:
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/http-dr0pper.png
TDrop code:
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/tdr0p.png
When the main Trojan file (Main.exe) executes, it launches RunCmd.exe, then launches AhnlabUpdate.exe. These files are created in a directory that sits in a temp directory created on the desktop. It was obvious for the researchers that the attackers knew what security software the victims used and attempted to make the malware appear as legitimate as possible.
AhnlabUpdate.exe then dropped and run an additional executable, a RAT payload that established the connection to the control server.
In early 2013, Concealment Troy Trojan had functional improvements to the first variants. It had better abilities to conceal itself from standard security techniques. The 3RAT client was the first version of troy to inject itself into Internet Explorer.
The wiper functionality was added in combination with the Concealment Trojan in the last attack named “DarkSeoul”, wherein in April 2013, crippled thousands of computers of financial services and media companies in South Korea.
This variant did not employ real-time IRC control as the earlier variants did. It was a typical HTTP botnet that used HTTP as its primary channel of communication. That solved potential problems that may arise with the earlier versions of the malware where the communications went through the installed IRC servers on the hacked South Korean websites.
The 2 main problems that arise with the previous Troy variants were that at any time, if the owners of the infected servers discovered the IRC process, they might remove it, thus making the attackers lose control of the servers that each Troy variant deployed.
The second problem was that the hackers hardcoded the name of the infected IRC server into each Troy variant source code. So, if the IRC server was compromised, they had to find another vulnerable server, install an IRC server and then recompile a new Troy variant with that specific IRC server.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/campaign-malware1.png
The targeted attack Dark Seoul reached its culmination in March 2013,
but its roots go back at least to 2009, whe[...]
___________________________
@hacking_Attack
@Hacking_Video
The next variants that will follow “Chang and EagleXP” 2010, “HTTP Troy” 2011, “Http Dr0pper” 2012,” Tong” 2012, “TDrop” 2013, haven’t had much of change in their core functionality but had more to do with the programming technique.
The researchers based their results to trace the legacy of the Troy variants on the fingerprints and footprints left from the malicious developers that were examined in the source code of the malware variants.
The compile paths, a type of fingerprint, that was tracked by the researchers, are the paths through the developer’s computer file directory (work directory) to the location at which the source code is stored, where documented in the report.
The NSTAR variant used the same DLL as Troy, Chang/EagleXP as we can see below.
The compile path of NSTAR was: E:\Work\BackUp\2011\nstar_1103\BackDoor\BsDllup\Release\BsDll.pdb whileHTTP Troy’s was:
Z:\source\1\HttpTroy\BsDll-up\Release\BsDll.pdb
Http Dr0pper, included the compile path: Z:\\1Mission\\Team_Project\\[2012.6~]\\HTTPTroy\\HttpDr0pper\\Win32\\Release, indicating that it was based on HTTP Troy variant as a more advanced version compiled in 2012.
Many of the variants were disguised as executable files of a security product. Http Dr0per was used to disguise its dropper component with the AhnlabUpdate.exe. Just as Http Dr0per , TDrop which was compiled on January 15, 2013, used the same executable (AhnlabUpdate.exe) to disguise its dropper.
They also shared the same file-mapping function and DLL as well.
Http Dr0per code:
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/http-dr0pper.png
TDrop code:
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/tdr0p.png
When the main Trojan file (Main.exe) executes, it launches RunCmd.exe, then launches AhnlabUpdate.exe. These files are created in a directory that sits in a temp directory created on the desktop. It was obvious for the researchers that the attackers knew what security software the victims used and attempted to make the malware appear as legitimate as possible.
AhnlabUpdate.exe then dropped and run an additional executable, a RAT payload that established the connection to the control server.
In early 2013, Concealment Troy Trojan had functional improvements to the first variants. It had better abilities to conceal itself from standard security techniques. The 3RAT client was the first version of troy to inject itself into Internet Explorer.
The wiper functionality was added in combination with the Concealment Trojan in the last attack named “DarkSeoul”, wherein in April 2013, crippled thousands of computers of financial services and media companies in South Korea.
This variant did not employ real-time IRC control as the earlier variants did. It was a typical HTTP botnet that used HTTP as its primary channel of communication. That solved potential problems that may arise with the earlier versions of the malware where the communications went through the installed IRC servers on the hacked South Korean websites.
The 2 main problems that arise with the previous Troy variants were that at any time, if the owners of the infected servers discovered the IRC process, they might remove it, thus making the attackers lose control of the servers that each Troy variant deployed.
The second problem was that the hackers hardcoded the name of the infected IRC server into each Troy variant source code. So, if the IRC server was compromised, they had to find another vulnerable server, install an IRC server and then recompile a new Troy variant with that specific IRC server.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/campaign-malware1.png
The targeted attack Dark Seoul reached its culmination in March 2013,
but its roots go back at least to 2009, whe[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
omponents in the same way that the 7 later variants of the Troy family did, as it included a shared DLL (bs.dll) that was found in the 2010 and 2011 variants. The next variants that will follow “Chang and EagleXP” 2010, “HTTP Troy” 2011, “Http Dr0pper” 2012…
n the Trojan’s source code was first compiled.
Subsequent variations of the malware have also been involved in these threats.
Military Espionage Malware: 2009–2013
The researchers also uncovered a sophisticated military spying network that targeted South Korea since 2009.
First, the attackers would compromise internal systems via a watering-hole attack where they placed a zero-day exploit on a military social networking site and in later cases via spear-phishing attacks on a specific target.
Then the malware performed the necessary recon for interesting documents, scrape out passwords and registry information on the target systems. The attacker would then request directory contents based on the number of interesting files found and then grab the specific files.
At last, the stolen files would then be transmitted via an HTTP-encrypted channel to the attacker’s server.
Linking the threat actors through technical means.
Researchers also uncovered numerous sub-campaigns and linked all the attacks as a part of the overall Operation Troy which occurred in 2009 through 2013.
* The Troy family of malware shared the same source code, components that were shared over the years with the other Troy variants.
* The same zip encryption password found in almost all variants except the Concealment Troy.
* All variants except Concealment Troy used the same IRC botnet channel and encryption method.
* The military keywords found in the components from 2009-2013 Troy variants verify the intent of the attackers.
* The same obfuscation techniques were used through the 2009-10 and 2012-13 campaigns.
Conclusion
Despite MacAfee haven’t pointed to the origin of the attacks, many researchers do not doubt that North Korea sponsored the attacks and point them as the main culprits.
The cybercriminals had attempted from 2009 to 2013, to at first, gather intelligence on South Korean military targets and then install the capability in their malware’s source code to destroy their targets using an MBR wiper component as seen in the last major attack “DarkSeoul”.
After the research of the attacks, the South Korean government said that they will double their cyber-security budget as it was clear that they needed to enhance their nation’s capabilities to protect computer networks and critical infrastructures from the next possible “DarkSeoul”. More than 5000 new trained ethical hackers were added to their cyber-army the year after the attacks.
As we already know Payloads can be designed in a sophisticated manner even more as technology progresses.
These attacks dated back to 2013 are now more dangerous due to the FUDs (Fully Undetectable) malware that can be generated with timed triggering and unique signatures that can still go unnoticed against even the most secure software/hardware measures set in place. Only through special solutions offered by the Offensive Security side can test your systems on how they would withstand such attacks.
Continuously inspecting and improving your cybersecurity strategy should be crucial for every company and government. The red team, that provides the offensive side of cybersecurity should be a major part of the strategy, as it will be always beneficial to test your systems and networks against real attack scenarios instead of building your defense and waiting to be cracked to fix it again.
References:
⦿ More Shots Fired on the Cyber Front: Key Takeaways From Operation Troy | HuffPost Impact ⦿ Tracing the Lineage of DarkSeoul – David Martin ⦿ Hackers hit South Korea also spread malware to steal military secrets – Security Affairs
⦿ Data Wiping Attacks in South Korea – Multi-Year Espionage Campaign | SecurityWeek ⦿ Dissecting operation Troy: Cyberespionage in South Korea – Help Net Security
⦿ Dissecting Operation Troy: Cyberespionage in South Korea | McAfee Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Operation-Aurora-90x90[...]
___________________________
@hacking_Attack
@Hacking_Video
Subsequent variations of the malware have also been involved in these threats.
Military Espionage Malware: 2009–2013
The researchers also uncovered a sophisticated military spying network that targeted South Korea since 2009.
First, the attackers would compromise internal systems via a watering-hole attack where they placed a zero-day exploit on a military social networking site and in later cases via spear-phishing attacks on a specific target.
Then the malware performed the necessary recon for interesting documents, scrape out passwords and registry information on the target systems. The attacker would then request directory contents based on the number of interesting files found and then grab the specific files.
At last, the stolen files would then be transmitted via an HTTP-encrypted channel to the attacker’s server.
Linking the threat actors through technical means.
Researchers also uncovered numerous sub-campaigns and linked all the attacks as a part of the overall Operation Troy which occurred in 2009 through 2013.
* The Troy family of malware shared the same source code, components that were shared over the years with the other Troy variants.
* The same zip encryption password found in almost all variants except the Concealment Troy.
* All variants except Concealment Troy used the same IRC botnet channel and encryption method.
* The military keywords found in the components from 2009-2013 Troy variants verify the intent of the attackers.
* The same obfuscation techniques were used through the 2009-10 and 2012-13 campaigns.
Conclusion
Despite MacAfee haven’t pointed to the origin of the attacks, many researchers do not doubt that North Korea sponsored the attacks and point them as the main culprits.
The cybercriminals had attempted from 2009 to 2013, to at first, gather intelligence on South Korean military targets and then install the capability in their malware’s source code to destroy their targets using an MBR wiper component as seen in the last major attack “DarkSeoul”.
After the research of the attacks, the South Korean government said that they will double their cyber-security budget as it was clear that they needed to enhance their nation’s capabilities to protect computer networks and critical infrastructures from the next possible “DarkSeoul”. More than 5000 new trained ethical hackers were added to their cyber-army the year after the attacks.
As we already know Payloads can be designed in a sophisticated manner even more as technology progresses.
These attacks dated back to 2013 are now more dangerous due to the FUDs (Fully Undetectable) malware that can be generated with timed triggering and unique signatures that can still go unnoticed against even the most secure software/hardware measures set in place. Only through special solutions offered by the Offensive Security side can test your systems on how they would withstand such attacks.
Continuously inspecting and improving your cybersecurity strategy should be crucial for every company and government. The red team, that provides the offensive side of cybersecurity should be a major part of the strategy, as it will be always beneficial to test your systems and networks against real attack scenarios instead of building your defense and waiting to be cracked to fix it again.
References:
⦿ More Shots Fired on the Cyber Front: Key Takeaways From Operation Troy | HuffPost Impact ⦿ Tracing the Lineage of DarkSeoul – David Martin ⦿ Hackers hit South Korea also spread malware to steal military secrets – Security Affairs
⦿ Data Wiping Attacks in South Korea – Multi-Year Espionage Campaign | SecurityWeek ⦿ Dissecting operation Troy: Cyberespionage in South Korea – Help Net Security
⦿ Dissecting Operation Troy: Cyberespionage in South Korea | McAfee Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Operation-Aurora-90x90[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
n the Trojan’s source code was first compiled. Subsequent variations of the malware have also been involved in these threats. Military Espionage Malware: 2009–2013 The researchers also uncovered a sophisticated military spying network that targeted South…
.png Hacking stories – Operation Aurora: When China hacked Google1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ancheta2-90x90.png Hacking stories – The first botnet hijacker aka the Zombie King2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/featured_image_jonathan_james_hacker-90x90.png Hacking Stories: Jonathan James – The teenager who hacked NASA for fun3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-4-90x90.png Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/photo-1468436139062-f60a71c5c892-scaled-90x90.jpg “Worst” MacOS Security Bug Recently Patched by Apple4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/wallpaperflare.com_wallpaper-90x90.jpg Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Xbox-Underground-90x90.png Hacking Stories: Xbox Underground6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Pentago-hak-90x90.png Hacking Stories: When two young hackers played war games with Pentagon7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/picture-788930-90x90.jpg Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbers8 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/cover-photo-90x90.png SolarWinds Supply Chain Hack – The hack that shone a light on the gaps in the cybersecurity of governments and big companies9 months ago
The post Hacking stories – Operation Troy – How researchers linked the cyberattacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ancheta2-90x90.png Hacking stories – The first botnet hijacker aka the Zombie King2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/featured_image_jonathan_james_hacker-90x90.png Hacking Stories: Jonathan James – The teenager who hacked NASA for fun3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-4-90x90.png Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/photo-1468436139062-f60a71c5c892-scaled-90x90.jpg “Worst” MacOS Security Bug Recently Patched by Apple4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/wallpaperflare.com_wallpaper-90x90.jpg Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Xbox-Underground-90x90.png Hacking Stories: Xbox Underground6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Pentago-hak-90x90.png Hacking Stories: When two young hackers played war games with Pentagon7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/picture-788930-90x90.jpg Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbers8 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/cover-photo-90x90.png SolarWinds Supply Chain Hack – The hack that shone a light on the gaps in the cybersecurity of governments and big companies9 months ago
The post Hacking stories – Operation Troy – How researchers linked the cyberattacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
DonPAPI - Dumping DPAPI Credz Remotely
http://1.bp.blogspot.com/-XYvl-5h8hJc/YXMCiULuH4I/AAAAAAAAwgw/5bkYH2RCticEOxe88DFnm2lgkUnqoSVWACK4BGAYYCw/w640-h438/DonPAPI_1_Logo%252520DonPapi-729454.png Dumping revelant information on compromised targets without AV detection DPAPI dumpingLots of credentials are protected by DPAPI.
We aim at locating those "secured" credentials, and retreive them using :
* User password
* Domaine DPAPI BackupKey
* Local machine DPAPI Key (protecting
* Windows Vaults
* Windows RDP credentials
* AdConnect (still require a manual operation)
* Wifi key
* Intenet explorer Creentials
* Chrome cookies & credentials
* Firefox cookies & credentials
* VNC passwords
* mRemoteNG password (with default config) Check for a bit of compliance* SMB signing status
* OS/Domain/Hostname/Ip of the audited scope Operational useWith local admin account on a host, we can :
* Gather machine protected DPAPI secrets
* ScheduledTask that will contain cleartext login/password of the account configured to run the task
* Wi-Fi passwords
* Extract Masterkey's hash value for every user profiles (masterkeys beeing protected by the user's password, let's try to crack them with Hashcat)
* Identify who is connected from where, in order to identify admin's personal computers.
* Extract other non-dpapi protected secrets (VNC/Firefox/mRemoteNG)
* Gather protected secrets from IE, Chrome, Firefox and start reaching the Azure tenant.
With a user password, or the domain PVK we can unprotect the user's DPAPI secrets. ExamplesDump all secrets of the target machine with an admin account :
This credential file must have the following syntax:
* Benjamin Delpy (@gentilkiwi) for most of the DPAPI research (always greatly commented, <3
* Alberto Solino (@agsolino) for the tremendous work of Impacket (https://github.com/SecureAuthCorp/impacket). Almost everything we do here comes from impacket.
* Alesandro Z & everyone who worked on Lazagne (https://github.com/AlessandroZ/LaZagne/wiki) for the VNC & Firefox modules, and most likely for a lots of other ones in the futur.
* dirkjanm @_dirkjan for the base code of adconnect dump (https://github.com/fox-it/adconnectdump) & every research he ever did. I le[...]
___________________________
@hacking_Attack
@Hacking_Video
DonPAPI - Dumping DPAPI Credz Remotely
http://1.bp.blogspot.com/-XYvl-5h8hJc/YXMCiULuH4I/AAAAAAAAwgw/5bkYH2RCticEOxe88DFnm2lgkUnqoSVWACK4BGAYYCw/w640-h438/DonPAPI_1_Logo%252520DonPapi-729454.png Dumping revelant information on compromised targets without AV detection DPAPI dumpingLots of credentials are protected by DPAPI.
We aim at locating those "secured" credentials, and retreive them using :
* User password
* Domaine DPAPI BackupKey
* Local machine DPAPI Key (protecting
TaskScheduledblob) Curently gathered info* Windows credentials (Taskscheduled credentials & a lot more)* Windows Vaults
* Windows RDP credentials
* AdConnect (still require a manual operation)
* Wifi key
* Intenet explorer Creentials
* Chrome cookies & credentials
* Firefox cookies & credentials
* VNC passwords
* mRemoteNG password (with default config) Check for a bit of compliance* SMB signing status
* OS/Domain/Hostname/Ip of the audited scope Operational useWith local admin account on a host, we can :
* Gather machine protected DPAPI secrets
* ScheduledTask that will contain cleartext login/password of the account configured to run the task
* Wi-Fi passwords
* Extract Masterkey's hash value for every user profiles (masterkeys beeing protected by the user's password, let's try to crack them with Hashcat)
* Identify who is connected from where, in order to identify admin's personal computers.
* Extract other non-dpapi protected secrets (VNC/Firefox/mRemoteNG)
* Gather protected secrets from IE, Chrome, Firefox and start reaching the Azure tenant.
With a user password, or the domain PVK we can unprotect the user's DPAPI secrets. ExamplesDump all secrets of the target machine with an admin account :
DonPAPI.py domain/user:passw0rd@targetUsing user's hash DonPAPI.py --hashes Using kerberos (-k) and local auth (-local_auth) DonPAPI.py -k domain/user@target
DonPAPI.py -local_auth user@targetUsing a user with LAPS password reading rights DonPAPI.py -laps domain/user:passw0rd@targetIt is also possible to provide the tool with a list of credentials that will be tested on the target. DonPAPI will try to use them to decipher masterkeys.This credential file must have the following syntax:
user1:pass1 user2:pass2 ... user1:pass1
user2:pass2
... When a domain admin user is available, it is possible to dump the domain backup key using impacket dpapi.pytool. DonPAPI.py -credz credz_file.txt domain/user:passw0rd@targetThis backup key can then be used to dump all domain user's secrets! python DonPAPI.py -pvk domain_backupkey.pvk domain/user:passw0rd@domain_network_listTarget can be an IP, IP range, CIDR, file containing list targets (one per line) Opsec considerationThe RemoteOps part can be spoted by some EDR. It can be disabled using --no_remoteopsflag, but then the machine DPAPI key won't be retrieved, and scheduled task credentials/Wi-Fi passwords won't be harvested. Installationdpapi.py backupkey --exportCreditsAll the credits goes to these great guys for doing the hard research & coding :* Benjamin Delpy (@gentilkiwi) for most of the DPAPI research (always greatly commented, <3
* Alberto Solino (@agsolino) for the tremendous work of Impacket (https://github.com/SecureAuthCorp/impacket). Almost everything we do here comes from impacket.
* Alesandro Z & everyone who worked on Lazagne (https://github.com/AlessandroZ/LaZagne/wiki) for the VNC & Firefox modules, and most likely for a lots of other ones in the futur.
* dirkjanm @_dirkjan for the base code of adconnect dump (https://github.com/fox-it/adconnectdump) & every research he ever did. I le[...]
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! DonPAPI - Dumping DPAPI Credz Remotely http://1.bp.blogspot.com/-XYvl-5h8hJc/YXMCiULuH4I/AAAAAAAAwgw/5bkYH2RCticEOxe88DFnm2lgkUnqoSVWACK4BGAYYCw/w640-h438/DonPAPI_1_Logo%252520DonPapi-729454.png Dumping revelant information on compromised…
arned so much on so many subjects thanks to you.
* @byt3bl33d3r for CME (lots of inspiration and code comes from CME : https://github.com/byt3bl33d3r/CrackMapExec )
* All the Team at @LoginSecurite for their help in debugging my shity code (special thanks to @layno & @HackAndDo for that) Todo* Finish ADSync/ADConnect password extraction
* CREDHISTORY full extraction
* Extract windows Certificates
* Further analysis ADAL/msteams
* Implement Chrome Changelog
___________________________
@hacking_Attack
@Hacking_Video
* @byt3bl33d3r for CME (lots of inspiration and code comes from CME : https://github.com/byt3bl33d3r/CrackMapExec )
* All the Team at @LoginSecurite for their help in debugging my shity code (special thanks to @layno & @HackAndDo for that) Todo* Finish ADSync/ADConnect password extraction
* CREDHISTORY full extraction
* Extract windows Certificates
* Further analysis ADAL/msteams
* Implement Chrome Changelog
git clone https://github.com/login-securite/DonPAPI.git
cd DonPAPI
python3 -m pip install -r requirements.txt
python3 DonPAPI.py Download DonPAPI___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - byt3bl33d3r/CrackMapExec: A swiss army knife for pentesting networks
A swiss army knife for pentesting networks. Contribute to byt3bl33d3r/CrackMapExec development by creating an account on GitHub.
Announcing IRISnet Bug Bounty Program IV
IRISnet (mainnet IRIS Hub) is about to upgrade with the integration of Terse IBC (TIBC) module and refactored NFT.Continue reading on IRISnet Blog »
Read more...
IRISnet (mainnet IRIS Hub) is about to upgrade with the integration of Terse IBC (TIBC) module and refactored NFT.Continue reading on IRISnet Blog »
Read more...
Thông báo Chương trình Bug Bounty IRISnet IV
IRISnet (mainnet IRIS Hub) sắp nâng cấp với việc tích hợp mô-đun Terse IBC (TIBC) và NFT được tái cấu trúc.Continue reading on Medium »
Read more...
IRISnet (mainnet IRIS Hub) sắp nâng cấp với việc tích hợp mô-đun Terse IBC (TIBC) và NFT được tái cấu trúc.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Crawlergo : A Powerful Browser Crawler For Web Vulnerability Scanners
crawlergo is a browser crawler that uses
crawlergo currently supports the following features:
* chrome browser environment rendering
* Intelligent form filling, automated submission
* Full DOM event collection with automated triggering
* Smart URL de-duplication to remove most duplicate requests
* Intelligent analysis of web pages and collection of URLs, including javascript file content, page comments, robots.txt files and automatic Fuzz of common paths
* Support Host binding, automatically fix and add Referer
* Support browser request proxy
* Support pushing the results to passive web vulnerability scanners
Screenshot
https://blogger.googleusercontent.com/img/a/AVvXsEgLq1-4ACgJPrqGinDHnWA-JyLwc_B9ysgLdJTqK1LXqgW1UOM3a-8j3qrEj6OHsdlaYwa3wqMFVM3o5n-bP1RE1fsVIbAGz731_11NxBl-v3Ql8DIN3KU_Y7-kHua7ZKkqDtGO2TZ8dsiZrBvVGRTt_Wgl3QboHhF77AsDveMhlERrmdQUdsnGwevC=s2132
Installation
Please read and confirm disclaimer carefully before installing and using。
Build
cd crawlergo/cmd/crawlergo
go build crawlergo_cmd.go
* crawlergo relies only on the chrome environment to run, go to download for the new version of chromium, or just click to download Linux version 79.
* Go to download page for the latest version of crawlergo and extract it to any directory. If you are on linux or macOS, please give crawlergo executable permissions (+x).
* Or you can modify the code and build it yourself.
If you are using a linux system and chrome prompts you with missing dependencies, please see TroubleShooting below
Quick Start Go!
Assuming your chromium installation directory is
./crawlergo -c /tmp/chromium/chrome -t 10 http://testphp.vulnweb.com/
Using Proxy
./crawlergo -c /tmp/chromium/chrome -t 10 –request-proxy socks5://127.0.0.1:7891 http://testphp.vulnweb.com/
Calling crawlergo with python
By default, crawlergo prints the results directly on the screen. We next set the output mode to
#!/usr/bin/python3
#coding: utf-8
import simplejson
import subprocess
def main():
target = “http://testphp.vulnweb.com/”
cmd = [“./crawlergo”, “-c”, “/tmp/chromium/chrome”, “-o”, “json”, target]
rsp = subprocess.Popen(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE)
output, error = rsp.communicate()
# “–[Mission Complete]–” is the end-of-task separator string
result = simplejson.loads(output.decode().split(“–[Mission Complete]–“)[1])
req_list = result[“req_list”]
print(req_list[0])
if name == ‘main’:
main()
Crawl Results
When the output mode is set to
*
*
*
*
crawlergo returns the full request and URL, which can be used in a variety of ways:
[...]
___________________________
@hacking_Attack
@Hacking_Video
Crawlergo : A Powerful Browser Crawler For Web Vulnerability Scanners
crawlergo is a browser crawler that uses
chrome headlessmode for URL collection. It hooks key positions of the whole web page with DOM rendering stage, automatically fills and submits forms, with intelligent JS event triggering, and collects as many entries exposed by the website as possible. The built-in URL de-duplication module filters out a large number of pseudo-static URLs, still maintains a fast parsing and crawling speed for large websites, and finally gets a high-quality collection of request results.crawlergo currently supports the following features:
* chrome browser environment rendering
* Intelligent form filling, automated submission
* Full DOM event collection with automated triggering
* Smart URL de-duplication to remove most duplicate requests
* Intelligent analysis of web pages and collection of URLs, including javascript file content, page comments, robots.txt files and automatic Fuzz of common paths
* Support Host binding, automatically fix and add Referer
* Support browser request proxy
* Support pushing the results to passive web vulnerability scanners
Screenshot
https://blogger.googleusercontent.com/img/a/AVvXsEgLq1-4ACgJPrqGinDHnWA-JyLwc_B9ysgLdJTqK1LXqgW1UOM3a-8j3qrEj6OHsdlaYwa3wqMFVM3o5n-bP1RE1fsVIbAGz731_11NxBl-v3Ql8DIN3KU_Y7-kHua7ZKkqDtGO2TZ8dsiZrBvVGRTt_Wgl3QboHhF77AsDveMhlERrmdQUdsnGwevC=s2132
Installation
Please read and confirm disclaimer carefully before installing and using。
Build
cd crawlergo/cmd/crawlergo
go build crawlergo_cmd.go
* crawlergo relies only on the chrome environment to run, go to download for the new version of chromium, or just click to download Linux version 79.
* Go to download page for the latest version of crawlergo and extract it to any directory. If you are on linux or macOS, please give crawlergo executable permissions (+x).
* Or you can modify the code and build it yourself.
If you are using a linux system and chrome prompts you with missing dependencies, please see TroubleShooting below
Quick Start Go!
Assuming your chromium installation directory is
/tmp/chromium/, set up 10 tabs open at the same time and crawl the testphp.vulnweb.com:./crawlergo -c /tmp/chromium/chrome -t 10 http://testphp.vulnweb.com/
Using Proxy
./crawlergo -c /tmp/chromium/chrome -t 10 –request-proxy socks5://127.0.0.1:7891 http://testphp.vulnweb.com/
Calling crawlergo with python
By default, crawlergo prints the results directly on the screen. We next set the output mode to
json, and the sample code for calling it using python is as follows:#!/usr/bin/python3
#coding: utf-8
import simplejson
import subprocess
def main():
target = “http://testphp.vulnweb.com/”
cmd = [“./crawlergo”, “-c”, “/tmp/chromium/chrome”, “-o”, “json”, target]
rsp = subprocess.Popen(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE)
output, error = rsp.communicate()
# “–[Mission Complete]–” is the end-of-task separator string
result = simplejson.loads(output.decode().split(“–[Mission Complete]–“)[1])
req_list = result[“req_list”]
print(req_list[0])
if name == ‘main’:
main()
Crawl Results
When the output mode is set to
json, the returned result, after JSON deserialization, contains four parts:*
all_req_list: All requests found during this crawl task, containing any resource type from other domains.*
req_list:Returns the current domain results of this crawl task, pseudo-statically de-duplicated, without static resource links. It is a subset of all_req_list .*
all_domain_list:List of all domains found.*
sub_domain_list:List of subdomains found. Examplescrawlergo returns the full request and URL, which can be used in a variety of ways:
[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Crawlergo : A Powerful Browser Crawler For Web Vulnerability Scanners
crawlergo is a browser crawler that uses chrome headless mode for URL collection. It hooks key positions of the whole web page.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Domain-Protect : Protect Against Subdomain Takeover
* Domain-Protect scans Amazon Route53 across an AWS Organization for domain records vulnerable to takeover
* vulnerable domains in Google Cloud DNS can be detected by Domain Protect for GCP
deploy to security audit account
https://blogger.googleusercontent.com/img/a/AVvXsEj4eWqlSQ1BudjfekG-Np88RpvhMtoPGkNUm0lpCJrC23pgvLpFVPQweKnPGofzGmh9Oh6QMy3ElDBiM87TRlsqo1ynsRUlLd1Dbpn_dTfoo7qZ_7ZNr5V5eZV4L76_9Ttjh421ZfpGp1PuoDAukrecagJzSNZ00D1LBFNG9a3eqX3eyV_PxOmfLeWz=s1217
scan your entire AWS Organization
https://blogger.googleusercontent.com/img/a/AVvXsEh9QpEj7tSUWWGUVLNwXE4ksfS9CMb75uTEWEAzHvMbP5jsWUnjjF1Pf141mRyy2jbAyuL8FKlph400gFkY3ZPK-bQgoJyJal8w2t6hwVkfjz8SNyJFqfLk4XMMDxMxL0tTDXDNzTKlcjP61-MszXXKs3RQE6Oi_d3TrnelVY18yC5jEbWjbPNg6a7_=s1240
receive alerts by Slack or email
https://blogger.googleusercontent.com/img/a/AVvXsEjwqq4pdZqG9e7FL26QNnuxWmaOXj7EH5xNyCsG1feWqGtnn5Ae_wKfqVfbCd6cUY4O7-0WM3oMkr8OSbRlyBdvdYD_8wYH5HnJc7h7M1Evo8oaEWGWNG8mLII6qOeYDL7825Kh4dZMQfUAgqDFgipMjgYZ0GAGVjzYbtXnUjimcSM1uSEg-XDk61oU=s1654
or manually scan from your laptop
https://blogger.googleusercontent.com/img/a/AVvXsEg6B9vNVbzzstumACj9zM4qGy7DMnYE32ewjAkulm2_MQXcNKxE6OwcpWRl6IPfodUNoGcup-s2b38y9x9H9chTiPKJ0B1OmHChXid5imLy9vzQ6hATOq_PrX-ucrn-xreDc2gFz5nq-Qs6X3rCzFEaLTAg812aDXVhh98T42J3nAYSnYa3SArcosoG=s944
Subdomain Detection Functionality
Scans Amazon Route53 to identify:
* Alias records for CloudFront distributions with missing S3 origin
* CNAME records for CloudFront distributions with missing S3 origin
* ElasticBeanstalk Alias records vulnerable to takeover
* ElasticBeanstalk CNAMES vulnerable to takeover
* Registered domains with missing hosted zones
* Subdomain NS delegations vulnerable to takeover
* S3 Alias records vulnerable to takeover
* S3 CNAMES vulnerable to takeover
* Vulnerable CNAME records for Azure resources
* CNAME records for missing Google Cloud Storage buckets
Optional Additional Check
Turned off by default as it may result in Lambda timeouts for large organisations
* A records for missing storage buckets, e.g. Google Cloud Load Balancer with missing backend storage
To enable, create this Terraform variable in your tfvars file or CI/CD pipeline:
lambdas = [“alias-cloudfront-s3”, “alias-eb”, “alias-s3”, “cname-cloudfront-s3”, “cname-eb”, “cname-s3”, “ns-domain”, “ns-subdomain”, “cname-azure”, “cname-google”, “a-storage”]
Options
1. scheduled lambda functions with email and Slack alerts, across an AWS Organization, deployed using Terraform
2. manual scans run from your laptop or CloudShell, in a single AWS account
Notifications
* Slack channel notification per vulnerability type, listing account names and vulnerable domains
* Email notification in JSON format with account names, account IDs and vulnerable domains by subscribing to SNS topic
Requirements
* Security audit account within AWS Organizations
* Security audit read-only role with an identical name in every AWS account of the Organization
* Storage bucket for Terraform state file
* Terraform 1.0.x
Usage
* replace the Terraform state S3 bucket fields in the command below as appropriate
* for local testing, duplicate terraform.tfvars.example, rename without the .example suffix
* enter details appropriate to your organization and save
* alternatively enter Terraform variables within your CI/CD pipeline
terraform init -backend-config=bucket=TERRAFORM_STATE_BUCKET -backend-config=key=TERRAFORM_STATE_KEY -backend-config=region=TERRAFORM_STATE_REGION
terraform workspace new dev
terraform plan
terraform apply
AWS IAM Policies
For least privilege access control, example AWS IAM policies are provided:
* domain-protect audit policy – attach to domain-protect audit role in every AWS account
* domain-protect audit trust relationship for domain-protec[...]
___________________________
@hacking_Attack
@Hacking_Video
Domain-Protect : Protect Against Subdomain Takeover
* Domain-Protect scans Amazon Route53 across an AWS Organization for domain records vulnerable to takeover
* vulnerable domains in Google Cloud DNS can be detected by Domain Protect for GCP
deploy to security audit account
https://blogger.googleusercontent.com/img/a/AVvXsEj4eWqlSQ1BudjfekG-Np88RpvhMtoPGkNUm0lpCJrC23pgvLpFVPQweKnPGofzGmh9Oh6QMy3ElDBiM87TRlsqo1ynsRUlLd1Dbpn_dTfoo7qZ_7ZNr5V5eZV4L76_9Ttjh421ZfpGp1PuoDAukrecagJzSNZ00D1LBFNG9a3eqX3eyV_PxOmfLeWz=s1217
scan your entire AWS Organization
https://blogger.googleusercontent.com/img/a/AVvXsEh9QpEj7tSUWWGUVLNwXE4ksfS9CMb75uTEWEAzHvMbP5jsWUnjjF1Pf141mRyy2jbAyuL8FKlph400gFkY3ZPK-bQgoJyJal8w2t6hwVkfjz8SNyJFqfLk4XMMDxMxL0tTDXDNzTKlcjP61-MszXXKs3RQE6Oi_d3TrnelVY18yC5jEbWjbPNg6a7_=s1240
receive alerts by Slack or email
https://blogger.googleusercontent.com/img/a/AVvXsEjwqq4pdZqG9e7FL26QNnuxWmaOXj7EH5xNyCsG1feWqGtnn5Ae_wKfqVfbCd6cUY4O7-0WM3oMkr8OSbRlyBdvdYD_8wYH5HnJc7h7M1Evo8oaEWGWNG8mLII6qOeYDL7825Kh4dZMQfUAgqDFgipMjgYZ0GAGVjzYbtXnUjimcSM1uSEg-XDk61oU=s1654
or manually scan from your laptop
https://blogger.googleusercontent.com/img/a/AVvXsEg6B9vNVbzzstumACj9zM4qGy7DMnYE32ewjAkulm2_MQXcNKxE6OwcpWRl6IPfodUNoGcup-s2b38y9x9H9chTiPKJ0B1OmHChXid5imLy9vzQ6hATOq_PrX-ucrn-xreDc2gFz5nq-Qs6X3rCzFEaLTAg812aDXVhh98T42J3nAYSnYa3SArcosoG=s944
Subdomain Detection Functionality
Scans Amazon Route53 to identify:
* Alias records for CloudFront distributions with missing S3 origin
* CNAME records for CloudFront distributions with missing S3 origin
* ElasticBeanstalk Alias records vulnerable to takeover
* ElasticBeanstalk CNAMES vulnerable to takeover
* Registered domains with missing hosted zones
* Subdomain NS delegations vulnerable to takeover
* S3 Alias records vulnerable to takeover
* S3 CNAMES vulnerable to takeover
* Vulnerable CNAME records for Azure resources
* CNAME records for missing Google Cloud Storage buckets
Optional Additional Check
Turned off by default as it may result in Lambda timeouts for large organisations
* A records for missing storage buckets, e.g. Google Cloud Load Balancer with missing backend storage
To enable, create this Terraform variable in your tfvars file or CI/CD pipeline:
lambdas = [“alias-cloudfront-s3”, “alias-eb”, “alias-s3”, “cname-cloudfront-s3”, “cname-eb”, “cname-s3”, “ns-domain”, “ns-subdomain”, “cname-azure”, “cname-google”, “a-storage”]
Options
1. scheduled lambda functions with email and Slack alerts, across an AWS Organization, deployed using Terraform
2. manual scans run from your laptop or CloudShell, in a single AWS account
Notifications
* Slack channel notification per vulnerability type, listing account names and vulnerable domains
* Email notification in JSON format with account names, account IDs and vulnerable domains by subscribing to SNS topic
Requirements
* Security audit account within AWS Organizations
* Security audit read-only role with an identical name in every AWS account of the Organization
* Storage bucket for Terraform state file
* Terraform 1.0.x
Usage
* replace the Terraform state S3 bucket fields in the command below as appropriate
* for local testing, duplicate terraform.tfvars.example, rename without the .example suffix
* enter details appropriate to your organization and save
* alternatively enter Terraform variables within your CI/CD pipeline
terraform init -backend-config=bucket=TERRAFORM_STATE_BUCKET -backend-config=key=TERRAFORM_STATE_KEY -backend-config=region=TERRAFORM_STATE_REGION
terraform workspace new dev
terraform plan
terraform apply
AWS IAM Policies
For least privilege access control, example AWS IAM policies are provided:
* domain-protect audit policy – attach to domain-protect audit role in every AWS account
* domain-protect audit trust relationship for domain-protec[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Domain-Protect : Protect Against Subdomain Takeover
Domain-Protect scans Amazon Route53 across an AWS Organization for domain records vulnerable to takeover. vulnerable domains in Google Cloud.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Networkit : A Growing Open-Source Toolkit For Large-Scale Network Analysis
NetworKit is an open-source tool suite for high-performance network analysis. Its aim is to provide tools for the analysis of large networks in the size range from thousands to billions of edges. For this purpose, it implements efficient graph algorithms, many of them parallel to utilize multicore architectures. These are meant to compute standard measures of network analysis. NetworKit is focused on scalability and comprehensiveness. NetworKit is also a testbed for algorithm engineering and contains novel algorithms from recently published research (see list of publications below).
NetworKit is a Python module. High-performance algorithms are written in C++ and exposed to Python via the Cython toolchain. Python in turn gives us the ability to work interactively and a rich environment of tools for data analysis and scientific computing. Furthermore, NetworKit’s core can be built and used as a native library if needed. Requirements
You will need the following software to install NetworKit as a python package:
* A modern C++ compiler, e.g.: g++ (>= 6.1), clang++ (>= 3.9) or MSVC (>= 14.13)
* OpenMP for parallelism (usually ships with the compiler)
* Python3 (3.6 or higher is supported)
* Development libraries for Python3. The package name depends on your distribution. Examples:
* Debian/Ubuntu:
* Pip
* CMake version 3.6 or higher (Advised to use system packages if available. Alternative:
* Build system: Make or Ninja
* Cython version 0.29 or higher (e.g.,
In order to use NetworKit, you can either install it via package managers or build the Python module from source. Install via package manager
While the most recent version is in general available for all package managers, the number of older downloadable versions differ. pip
pip3 install [–user] networkit
conda (channel conda-forge)
conda config –add channels conda-forge
conda install networkit [-c conda-forge]
brew
brew install networkit
spack
spack install py-networkit
Building the Python module from source
git clone https://github.com/networkit/networkit networkit
cd networkit
python3 setup.py build_ext [-jX]
pip3 install -e .
The script will call
To get an overview and learn about NetworKit’s different functions/classes, have a look at our interactive notebooks-section, especially the Networkit UserGuide. Note: To view and edit the computed output from the notebooks, it is recommended to use Jupyter Notebook. This requires the prior installation of NetworKit. You should really check that out before start working on your network analysis.
We also provide a Binder-instance of our notebooks. To access this service, you can either click on the badge at the top or follow this link. Disclaimer: Due to rebuilds of the underlying image, it can takes some time until your Binder instance is ready for usage.
If you only want to see in short how NetworKit is used – the following example provides a climpse at that. Here we generate a random hyperbolic graph with 100k nodes and compute its communities with the PLM method:
import networkit as nk
g = nk.generators.HyperbolicGenerator(1e5).generate()
communities = nk.community.detectCommunities(g, inspect=True)
PLM(balan[...]
___________________________
@hacking_Attack
@Hacking_Video
Networkit : A Growing Open-Source Toolkit For Large-Scale Network Analysis
NetworKit is an open-source tool suite for high-performance network analysis. Its aim is to provide tools for the analysis of large networks in the size range from thousands to billions of edges. For this purpose, it implements efficient graph algorithms, many of them parallel to utilize multicore architectures. These are meant to compute standard measures of network analysis. NetworKit is focused on scalability and comprehensiveness. NetworKit is also a testbed for algorithm engineering and contains novel algorithms from recently published research (see list of publications below).
NetworKit is a Python module. High-performance algorithms are written in C++ and exposed to Python via the Cython toolchain. Python in turn gives us the ability to work interactively and a rich environment of tools for data analysis and scientific computing. Furthermore, NetworKit’s core can be built and used as a native library if needed. Requirements
You will need the following software to install NetworKit as a python package:
* A modern C++ compiler, e.g.: g++ (>= 6.1), clang++ (>= 3.9) or MSVC (>= 14.13)
* OpenMP for parallelism (usually ships with the compiler)
* Python3 (3.6 or higher is supported)
* Development libraries for Python3. The package name depends on your distribution. Examples:
* Debian/Ubuntu:
apt-get install python3-dev* RHEL/CentOS: dnf install python3-devel* Windows: Use the official release installer from www.python.org* Pip
* CMake version 3.6 or higher (Advised to use system packages if available. Alternative:
pip3 install cmake)* Build system: Make or Ninja
* Cython version 0.29 or higher (e.g.,
pip3 install cython) InstallIn order to use NetworKit, you can either install it via package managers or build the Python module from source. Install via package manager
While the most recent version is in general available for all package managers, the number of older downloadable versions differ. pip
pip3 install [–user] networkit
conda (channel conda-forge)
conda config –add channels conda-forge
conda install networkit [-c conda-forge]
brew
brew install networkit
spack
spack install py-networkit
Building the Python module from source
git clone https://github.com/networkit/networkit networkit
cd networkit
python3 setup.py build_ext [-jX]
pip3 install -e .
The script will call
cmakeand ninja(make as fallback) to compile NetworKit as a library, build the extensions and copy it to the top folder. By default, NetworKit will be built with the amount of available cores in optimized mode. It is possible the add the option -jNthe number of threads used for compilation. Usage ExampleTo get an overview and learn about NetworKit’s different functions/classes, have a look at our interactive notebooks-section, especially the Networkit UserGuide. Note: To view and edit the computed output from the notebooks, it is recommended to use Jupyter Notebook. This requires the prior installation of NetworKit. You should really check that out before start working on your network analysis.
We also provide a Binder-instance of our notebooks. To access this service, you can either click on the badge at the top or follow this link. Disclaimer: Due to rebuilds of the underlying image, it can takes some time until your Binder instance is ready for usage.
If you only want to see in short how NetworKit is used – the following example provides a climpse at that. Here we generate a random hyperbolic graph with 100k nodes and compute its communities with the PLM method:
import networkit as nk
g = nk.generators.HyperbolicGenerator(1e5).generate()
communities = nk.community.detectCommunities(g, inspect=True)
PLM(balan[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Networkit : A Growing Open-Source Toolkit For Large-Scale Network
NetworKit is an open-source tool suite for high-performance network analysis. Its aim is to provide tools for the analysis of large networks.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Crawlergo : A Powerful Browser Crawler For Web Vulnerability Scanners crawlergo is a browser crawler that uses chrome headlessmode for URL collection. It hooks key positions of the whole web page with DOM rendering stage, automatically…
* Used in conjunction with other passive web vulnerability scannersFirst, start a passive scanner and set the listening address to:
* Host binding (not available for high version chrome) (example)
* Custom Cookies (example)
* Regularly clean up zombie processes generated by crawlergo (example) , contributed by @ring04h Bypass headless detect
crawlergo can bypass headless mode detection by default.
https://intoli.com/blog/not-possible-to-block-chrome-headless/chrome-headless-test.html
https://blogger.googleusercontent.com/img/a/AVvXsEhUJnn28fH3Kwx6FXk90txEPS6_KxuXlhuOakB4U_7MjdJnbJkfEbXBpJ3x1b1p68S60_yqWJEnARgS0Fm8BHMwBdgE4y9fNNxmF8JRdHHfrXceimKURtJu6H5Vpq23pPkLAlNqjZivLl4cEh_83bws7deibsSE8LkLDysdU11EiXV66023SynqNtut=s546
TroubleShooting
* ‘Fetch.enable’ wasn’t foundFetch is a feature supported by the new version of chrome, if this error occurs, it means your version is too low, please upgrade the chrome version.
* chrome runs with missing dependencies such as xxx.so
// Ubuntu
apt-get install -yq –no-install-recommends \
libasound2 libatk1.0-0 libc6 libcairo2 libcups2 libdbus-1-3 \
libexpat1 libfontconfig1 libgcc1 libgconf-2-4 libgdk-pixbuf2.0-0 libglib2.0-0 libgtk-3-0 libnspr4 \
libpango-1.0-0 libpangocairo-1.0-0 libstdc++6 libx11-6 libx11-xcb1 libxcb1 \
libxcursor1 libxdamage1 libxext6 libxfixes3 libxi6 libxrandr2 libxrender1 libxss1 libxtst6 libnss3
// CentOS 7
sudo yum install pango.x86_64 libXcomposite.x86_64 libXcursor.x86_64 libXdamage.x86_64 libXext.x86_64 libXi.x86_64 \
libXtst.x86_64 cups-libs.x86_64 libXScrnSaver.x86_64 libXrandr.x86_64 GConf2.x86_64 alsa-lib.x86_64 atk.x86_64 gtk3.x86_64 \
ipa-gothic-fonts xorg-x11-fonts-100dpi xorg-x11-fonts-75dpi xorg-x11-utils xorg-x11-fonts-cyrillic xorg-x11-fonts-Type1 xorg-x11-fonts-misc -y
sudo yum update nss -y
Run prompt Navigation timeout / browser not found / don’t know correct browser executable path
Make sure the browser executable path is configured correctly, type:
https://blogger.googleusercontent.com/img/a/AVvXsEieZZm_piWBcJKMs3rbPb2flmQbkJu3AYVNuYCCGcpbReytwMUT77xgINvQ6IUWOUwdeITjzKNgciwbljGt7xjS1zDV47LCFYFYSIZ-EoL8bcir7Ny_LjYpkxSEsJJuWgVdSH6F-AXbCXM0yCkMiTej9MdlUvvAWiJeIUxJ-wTT4NaxJNwrmGiQ-9Tq=s579
Parameters Required parameters
*
*
*
*
*
*
*
*
*
___________________________
@hacking_Attack
@Hacking_Video
http://127.0.0.1:1234/Next, assuming crawlergo is on the same machine as the scanner, start crawlergo and set the parameters:--push-to-proxy http://127.0.0.1:1234/* Host binding (not available for high version chrome) (example)
* Custom Cookies (example)
* Regularly clean up zombie processes generated by crawlergo (example) , contributed by @ring04h Bypass headless detect
crawlergo can bypass headless mode detection by default.
https://intoli.com/blog/not-possible-to-block-chrome-headless/chrome-headless-test.html
https://blogger.googleusercontent.com/img/a/AVvXsEhUJnn28fH3Kwx6FXk90txEPS6_KxuXlhuOakB4U_7MjdJnbJkfEbXBpJ3x1b1p68S60_yqWJEnARgS0Fm8BHMwBdgE4y9fNNxmF8JRdHHfrXceimKURtJu6H5Vpq23pPkLAlNqjZivLl4cEh_83bws7deibsSE8LkLDysdU11EiXV66023SynqNtut=s546
TroubleShooting
* ‘Fetch.enable’ wasn’t foundFetch is a feature supported by the new version of chrome, if this error occurs, it means your version is too low, please upgrade the chrome version.
* chrome runs with missing dependencies such as xxx.so
// Ubuntu
apt-get install -yq –no-install-recommends \
libasound2 libatk1.0-0 libc6 libcairo2 libcups2 libdbus-1-3 \
libexpat1 libfontconfig1 libgcc1 libgconf-2-4 libgdk-pixbuf2.0-0 libglib2.0-0 libgtk-3-0 libnspr4 \
libpango-1.0-0 libpangocairo-1.0-0 libstdc++6 libx11-6 libx11-xcb1 libxcb1 \
libxcursor1 libxdamage1 libxext6 libxfixes3 libxi6 libxrandr2 libxrender1 libxss1 libxtst6 libnss3
// CentOS 7
sudo yum install pango.x86_64 libXcomposite.x86_64 libXcursor.x86_64 libXdamage.x86_64 libXext.x86_64 libXi.x86_64 \
libXtst.x86_64 cups-libs.x86_64 libXScrnSaver.x86_64 libXrandr.x86_64 GConf2.x86_64 alsa-lib.x86_64 atk.x86_64 gtk3.x86_64 \
ipa-gothic-fonts xorg-x11-fonts-100dpi xorg-x11-fonts-75dpi xorg-x11-utils xorg-x11-fonts-cyrillic xorg-x11-fonts-Type1 xorg-x11-fonts-misc -y
sudo yum update nss -y
Run prompt Navigation timeout / browser not found / don’t know correct browser executable path
Make sure the browser executable path is configured correctly, type:
chrome://versionin the address bar, and find the executable file path:https://blogger.googleusercontent.com/img/a/AVvXsEieZZm_piWBcJKMs3rbPb2flmQbkJu3AYVNuYCCGcpbReytwMUT77xgINvQ6IUWOUwdeITjzKNgciwbljGt7xjS1zDV47LCFYFYSIZ-EoL8bcir7Ny_LjYpkxSEsJJuWgVdSH6F-AXbCXM0yCkMiTej9MdlUvvAWiJeIUxJ-wTT4NaxJNwrmGiQ-9Tq=s579
Parameters Required parameters
*
--chromium-path Path, -c PathThe path to the chrome executable. (Required) Basic parameters*
--custom-headers HeadersCustomize the HTTP header. Please pass in the data after JSON serialization, this is globally defined and will be used for all requests. (Default: null)*
--post-data PostData, -d PostDataPOST data. (Default: null)*
--max-crawled-count Number, -m NumberThe maximum number of tasks for crawlers to avoid long crawling time due to pseudo-static. (Default: 200)*
--filter-mode Mode, -f ModeFiltering mode, simple: only static resources and duplicate requests are filtered. smart: with the ability to filter pseudo-static. strict: stricter pseudo-static filtering rules. (Default: smart)*
--output-mode value, -o valueResult output mode, console: print the glorified results directly to the screen. json: print the json serialized string of all results. none: don’t print the output. (Default: console)*
--output-json filepathWrite the result to the specified file after JSON serializing it. (Default: null)*
--request-proxy proxyAddresssocks5 proxy address, all network requests from crawlergo and chrome browser are sent through the proxy. (Default: null) Expand input URL*
--fuzz-pathUse the built-in dictionar[...]___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Domain-Protect : Protect Against Subdomain Takeover * Domain-Protect scans Amazon Route53 across an AWS Organization for domain records vulnerable to takeover * vulnerable domains in Google Cloud DNS can be detected by Domain Protect…
t audit role in every AWS account
* domain-protect audit trust relationship with External ID for domain-protect audit role in every AWS account
* domain-protect deploy policy – attach to IAM group or role assumed by CI/CD pipeline
Adding New Checks
* create a new subdirectory within the terraform-modules/lambda/code directory
* add Python code file with same name as the subdirectory
* add the name of the file without extension to
* add a subdirectory within the terraform-modules/lambda/build directory, following the existing naming pattern
* add a .gitkeep file into the new directory
* update the .gitignore file following the pattern of existing directories
* apply Terraform
Adding Notifications To Extra Slack Channels
* add an extra channel to your slack_channels variable list
* add an extra webhook URL or repeat the same webhook URL to your slack_webhook_urls variable list
* apply Terraform
Testing
* use multiple Terraform workspace environments, e.g. dev, prd
* use the
* for new subdomain takeover categories, create correctly configured and vulnerable domain names in Route53
* minimise the risk of malicious takeover by using a test domain, with domain names which are hard to enumerate
* remove any vulnerable domains as soon as possible ci/cd
* infrastructure has been deployed using CircleCI
* environment variables to be entered in CircleCI project settings:
ENVIRONMENT VARIABLEEXAMPLE VALUE / COMMENTAWS_ACCESS_KEY_IDusing domain-protect deploy policyAWS_SECRET_ACCESS_KEY–TERRAFORM_STATE_BUCKETtfstate48903TERRAFORM_STATE_KEYdomain-protectTERRAFORM_STATE_REGIONus-east-1TF_VAR_org_primary_account012345678901TF_VAR_security_audit_role_namenot needed if “domain-protect-audit” usedTF_VAR_external_idonly required if External ID is configuredTF_VAR_slack_channels[“security-alerts”]TF_VAR_slack_channels_dev[“security-alerts-dev”]TF_VAR_slack_webhook_urls[“https://hooks.slack.com/services/XXX/XXX/XXX”]
* to validate an updated CircleCI configuration:
docker run -v
___________________________
@hacking_Attack
@Hacking_Video
* domain-protect audit trust relationship with External ID for domain-protect audit role in every AWS account
* domain-protect deploy policy – attach to IAM group or role assumed by CI/CD pipeline
Adding New Checks
* create a new subdirectory within the terraform-modules/lambda/code directory
* add Python code file with same name as the subdirectory
* add the name of the file without extension to
var.lambdasin variables.tf* add a subdirectory within the terraform-modules/lambda/build directory, following the existing naming pattern
* add a .gitkeep file into the new directory
* update the .gitignore file following the pattern of existing directories
* apply Terraform
Adding Notifications To Extra Slack Channels
* add an extra channel to your slack_channels variable list
* add an extra webhook URL or repeat the same webhook URL to your slack_webhook_urls variable list
* apply Terraform
Testing
* use multiple Terraform workspace environments, e.g. dev, prd
* use the
slack_channels_devvariable for your dev environment to notify a test Slack channel* for new subdomain takeover categories, create correctly configured and vulnerable domain names in Route53
* minimise the risk of malicious takeover by using a test domain, with domain names which are hard to enumerate
* remove any vulnerable domains as soon as possible ci/cd
* infrastructure has been deployed using CircleCI
* environment variables to be entered in CircleCI project settings:
ENVIRONMENT VARIABLEEXAMPLE VALUE / COMMENTAWS_ACCESS_KEY_IDusing domain-protect deploy policyAWS_SECRET_ACCESS_KEY–TERRAFORM_STATE_BUCKETtfstate48903TERRAFORM_STATE_KEYdomain-protectTERRAFORM_STATE_REGIONus-east-1TF_VAR_org_primary_account012345678901TF_VAR_security_audit_role_namenot needed if “domain-protect-audit” usedTF_VAR_external_idonly required if External ID is configuredTF_VAR_slack_channels[“security-alerts”]TF_VAR_slack_channels_dev[“security-alerts-dev”]TF_VAR_slack_webhook_urls[“https://hooks.slack.com/services/XXX/XXX/XXX”]
* to validate an updated CircleCI configuration:
docker run -v
pwd:/whatever circleci/circleci-cli circleci config validate /whatever/.circleci/config.yml Download___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Packet-Sniffer : A pure-Python Network Packet Sniffing Tool
Packet-Sniffer is a simple pure-Python network packet sniffer. Packets are disassembled as they arrive at a given network interface controller and their information is displayed on the screen.
This application maintains no dependencies on third-party modules and can be run by any Python 3.x interpreter.
Installation
GNU / Linux
Simply clone this repository with
user@host:~/DIR$ git clone https://github.com/EONRaider/Packet-Sniffer.git
Other Systems
This project is dependent on
Use this command to build and run from the project directory:
docker build -t sniff . && docker run –network host sniff
Note that the entry command is simply
docker run –network host sniff [your command goes here]
echo “Now let’s print help”
docker run –network host sniff python packet_sniffer.py –help
Usage of
Usage
packet_sniffer.py [-h] [-i INTERFACE] [-d]
A pure-Python network packet sniffer.
optional arguments:
-h, –help show this help message and exit
-i INTERFACE, –interface INTERFACE
Interface from which packets will be captured (captures
from all available interfaces by default).
-d, –displaydata Output packet data during capture.
Running the Application
ObjectiveInitiate the capture of packets on all available interfacesExecutionsudo python3 packet_sniffer.pyOutcomeRefer to sample output below
Sample output:
[>] Packet #476 at 17:45:13:
[+] MAC ……ae:45:39:30:8f:5a -> dc:d9:ae:71:c8:b9
[+] IPv4 ……….192.168.1.65 -> 140.82.113.3 | PROTO: TCP TTL: 64
[+] TCP ………………40820 -> 443 | Flags: 0x010 > ACK
[>] Packet #477 at 17:45:14:
[+] MAC ……dc:d9:ae:71:c8:b9 -> ae:45:39:30:8f:5a
[+] IPv4 ……….140.82.113.3 -> 192.168.1.65 | PROTO: TCP TTL: 49
[+] TCP ………………..443 -> 40820 | Flags: 0x010 > ACK
[>] Packet #478 at 17:45:18:
[+] MAC ……dc:d9:ae:71:c8:b9 -> ae:45:39:30:8f:5a
[+] ARP Who has 192.168.1.65 ? -> Tell 192.168.1.254
[>] Packet #479 at 17:45:18:
[+] MAC ……ae:45:39:30:8f:5a -> dc:d9:ae:71:c8:b9
[+] ARP ………..192.168.1.65 -> Is at ae:45:39:30:8f:5a
Download
___________________________
@hacking_Attack
@Hacking_Video
Packet-Sniffer : A pure-Python Network Packet Sniffing Tool
Packet-Sniffer is a simple pure-Python network packet sniffer. Packets are disassembled as they arrive at a given network interface controller and their information is displayed on the screen.
This application maintains no dependencies on third-party modules and can be run by any Python 3.x interpreter.
Installation
GNU / Linux
Simply clone this repository with
git cloneand execute the packet_sniffer.pyfile as described in the following Usage section.user@host:~/DIR$ git clone https://github.com/EONRaider/Packet-Sniffer.git
Other Systems
This project is dependent on
PF_PACKET– a stateful packet filter not found on Windows or Mac OS X. For demonstration purposes, you can try out this package in a Docker container. Although it will not have full access to localhost on your machine, you can still sniff on the Docker subnet and at least get the module running.Use this command to build and run from the project directory:
docker build -t sniff . && docker run –network host sniff
Note that the entry command is simply
python packet_sniffer.py, so feel free to use the full functionality of the module by overriding the default command. Remember that we tagged the container with the name “sniff” before, so we can pass command-line arguments to the sniffer in the following manner:docker run –network host sniff [your command goes here]
echo “Now let’s print help”
docker run –network host sniff python packet_sniffer.py –help
Usage of
--network hostis not supported on OS X or Windows so this container won’t be fully functional – but you will see packets traveling within the docker subnet.Usage
packet_sniffer.py [-h] [-i INTERFACE] [-d]
A pure-Python network packet sniffer.
optional arguments:
-h, –help show this help message and exit
-i INTERFACE, –interface INTERFACE
Interface from which packets will be captured (captures
from all available interfaces by default).
-d, –displaydata Output packet data during capture.
Running the Application
ObjectiveInitiate the capture of packets on all available interfacesExecutionsudo python3 packet_sniffer.pyOutcomeRefer to sample output below
Sample output:
[>] Packet #476 at 17:45:13:
[+] MAC ……ae:45:39:30:8f:5a -> dc:d9:ae:71:c8:b9
[+] IPv4 ……….192.168.1.65 -> 140.82.113.3 | PROTO: TCP TTL: 64
[+] TCP ………………40820 -> 443 | Flags: 0x010 > ACK
[>] Packet #477 at 17:45:14:
[+] MAC ……dc:d9:ae:71:c8:b9 -> ae:45:39:30:8f:5a
[+] IPv4 ……….140.82.113.3 -> 192.168.1.65 | PROTO: TCP TTL: 49
[+] TCP ………………..443 -> 40820 | Flags: 0x010 > ACK
[>] Packet #478 at 17:45:18:
[+] MAC ……dc:d9:ae:71:c8:b9 -> ae:45:39:30:8f:5a
[+] ARP Who has 192.168.1.65 ? -> Tell 192.168.1.254
[>] Packet #479 at 17:45:18:
[+] MAC ……ae:45:39:30:8f:5a -> dc:d9:ae:71:c8:b9
[+] ARP ………..192.168.1.65 -> Is at ae:45:39:30:8f:5a
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Packet-Sniffer : A pure-Python Network Packet Sniffing Tool
Packet-Sniffer is a simple pure-Python network packet sniffer. Packets are disassembled as they arrive at a given network interface controll.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Networkit : A Growing Open-Source Toolkit For Large-Scale Network Analysis NetworKit is an open-source tool suite for high-performance network analysis. Its aim is to provide tools for the analysis of large networks in the size range…
ced,pc,turbo) detected communities in 0.14577102661132812 [s]
solution properties:
communities 4536
min community size 1
max community size 2790
avg. community size 22.0459
modularity 0.987243
——————- ———–
Install the C++ Core only
In case you only want to work with NetworKit’s C++ core, you can either install it via package managers or build it from source. Install C++ core via package manager conda (channel conda-forge)
conda config –add channels conda-forge
conda install libnetworkit [-c conda-forge]
brew
brew install libnetworkit
spack
spack install libnetworkit
Building the C++ core from source
We recommend CMake and your preferred build system for building the C++ part of NetworKit.
The following description shows how to use CMake in order to build the C++ Core only:
First you have to create and change to a build directory: (in this case named
mkdir build
cd build
Then call CMake to generate files for the
cmake ..
make -jX
o speed up the compilation with make a multi-core machine, you can append
This paragraph explains how to use the NetworKit core C++ library in case it has been built from source. For how to use it when installed via package managers, best refer to the official documentation (brew, conda, spack).
In order to use the previous compiled networkit library, you need to have it installed, and link it while compiling your project. Use these instructions to compile and install NetworKit in
cmake ..
make -jX install
Once NetworKit has been installed, you can use include directives in your C++-application as follows:
# include
You can compile your source as follows:
g++ my_file.cpp -lnetworkit
Unit Tests
Building and running NetworKit unit tests is not mandatory. However, as a developer you might want to write and run unit tests for your code, or if you experience any issues with NetworKit, you might want to check if NetworKit runs properly. The unit tests can only be run from a clone or copy of the repository and not from a pip installation. In order to run the unit tests, you need to compile them first. This is done by setting the CMake
cmake -DNETWORKIT_BUILD_TESTS=ON ..
Unit tests are implemented using GTest macros such as
./networkit_tests –gtest_filter=CentralityGTest.testBetweennessCentrality
Additionally, one can specify the level of the logs outputs by adding --loglevel ; supported log levels are:
Compiling with address/leak sanitizers
Sanitizers are great tools to debug your code. NetworKit provides additional Cmake flags to enable address, leak, and undefined behavior sanitizers. To compile your code with sanitizers, set the CMake
cmake -DNETWORKIT_WITH_SANITIZERS=leak ..
By setting this flag to
___________________________
@hacking_Attack
@Hacking_Video
solution properties:
communities 4536
min community size 1
max community size 2790
avg. community size 22.0459
modularity 0.987243
——————- ———–
Install the C++ Core only
In case you only want to work with NetworKit’s C++ core, you can either install it via package managers or build it from source. Install C++ core via package manager conda (channel conda-forge)
conda config –add channels conda-forge
conda install libnetworkit [-c conda-forge]
brew
brew install libnetworkit
spack
spack install libnetworkit
Building the C++ core from source
We recommend CMake and your preferred build system for building the C++ part of NetworKit.
The following description shows how to use CMake in order to build the C++ Core only:
First you have to create and change to a build directory: (in this case named
build)mkdir build
cd build
Then call CMake to generate files for the
makebuild system, specifying the directory of the root CMakeLists.txtfile (e.g., ..). After this makeis called to start the build process:cmake ..
make -jX
o speed up the compilation with make a multi-core machine, you can append
-jXwhere X denotes the number of threads to compile with. Use NetworKit as a libraryThis paragraph explains how to use the NetworKit core C++ library in case it has been built from source. For how to use it when installed via package managers, best refer to the official documentation (brew, conda, spack).
In order to use the previous compiled networkit library, you need to have it installed, and link it while compiling your project. Use these instructions to compile and install NetworKit in
/usr/local:cmake ..
make -jX install
Once NetworKit has been installed, you can use include directives in your C++-application as follows:
# include
You can compile your source as follows:
g++ my_file.cpp -lnetworkit
Unit Tests
Building and running NetworKit unit tests is not mandatory. However, as a developer you might want to write and run unit tests for your code, or if you experience any issues with NetworKit, you might want to check if NetworKit runs properly. The unit tests can only be run from a clone or copy of the repository and not from a pip installation. In order to run the unit tests, you need to compile them first. This is done by setting the CMake
NETWORKI_BUILD_TESTSflag to ON:cmake -DNETWORKIT_BUILD_TESTS=ON ..
Unit tests are implemented using GTest macros such as
TEST_F(CentralityGTest, testBetweennessCentrality). Single tests can be executed with:./networkit_tests –gtest_filter=CentralityGTest.testBetweennessCentrality
Additionally, one can specify the level of the logs outputs by adding --loglevel ; supported log levels are:
TRACE, DEBUG, INFO, WARN, ERROR, and FATAL.Compiling with address/leak sanitizers
Sanitizers are great tools to debug your code. NetworKit provides additional Cmake flags to enable address, leak, and undefined behavior sanitizers. To compile your code with sanitizers, set the CMake
NETWORKIT_WITH_SANITIZERSto either addressor leak:cmake -DNETWORKIT_WITH_SANITIZERS=leak ..
By setting this flag to
address, your code will be compiled with the addressand the undefinedsanitizers. Setting it to leakalso adds the leaksanitizer. Download___________________________
@hacking_Attack
@Hacking_Video