La dépêche de l’Agora — Bulletin Hebdomadaire de la communauté Olympus — Mercredi 4 Août 2021
https://agora-frohmies.medium.com/la-d%C3%A9p%C3%AAche-de-lagora-bulletin-hebdomadaire-de-la-communaut%C3%A9-olympus-mercredi-4-ao%C3%BBt-2021-791fb2e73d7a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://agora-frohmies.medium.com/la-d%C3%A9p%C3%AAche-de-lagora-bulletin-hebdomadaire-de-la-communaut%C3%A9-olympus-mercredi-4-ao%C3%BBt-2021-791fb2e73d7a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
La dépêche de l’Agora — Bulletin Hebdomadaire de la communauté Olympus — Mercredi 4 Août 2021
Bienvenue dans la dépêche de l’Agora, une newsletter gérée par la communauté Olympus, créée par les Ohmies, pour les Ohmies !
Bienvenue dans la dépêche de l’Agora, une newsletter gérée par la communauté Olympus, créée par les Ohmies, pour les Ohmies !Continue reading on Medium » (https://agora-frohmies.medium.com/la-d%C3%A9p%C3%AAche-de-lagora-bulletin-hebdomadaire-de-la-communaut%C3%A9-olympus-mercredi-4-ao%C3%BBt-2021-791fb2e73d7a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
La dépêche de l’Agora — Bulletin Hebdomadaire de la communauté Olympus — Mercredi 4 Août 2021
Bienvenue dans la dépêche de l’Agora, une newsletter gérée par la communauté Olympus, créée par les Ohmies, pour les Ohmies !
hacking: security in practice
Can this be achieved ?
Hello guys so I've only experimented with metasploitable b4 and never on real targets and my friend owns a router and it's running an old firmware and i found it on shodan and have his permission and knowledge that I'll teat its security My question is do i look for an exploit targeting that router firmware and just do it or am i missing a point here ?
submitted by /u/iiMoe
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can this be achieved ?
Hello guys so I've only experimented with metasploitable b4 and never on real targets and my friend owns a router and it's running an old firmware and i found it on shodan and have his permission and knowledge that I'll teat its security My question is do i look for an exploit targeting that router firmware and just do it or am i missing a point here ?
submitted by /u/iiMoe
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can this be achieved ?
Hello guys so I've only experimented with metasploitable b4 and never on real targets and my friend owns a router and it's running an old firmware...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Why and how to use Limit Login Attemps system in WordPress.
https://cdn-images-1.medium.com/max/820/1*YLZI7roz7z_Gc3icBq0O8g.png
Would you like to have a Limit Login Attempts system on your WordPress site?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Why and how to use Limit Login Attemps system in WordPress.
https://cdn-images-1.medium.com/max/820/1*YLZI7roz7z_Gc3icBq0O8g.png
Would you like to have a Limit Login Attempts system on your WordPress site?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why and how to use Limit Login Attemps system in WordPress.
Would you like to have a Limit Login Attempts system on your WordPress site?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Over 30,000 GitLab servers still unpatched against critical bug
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Over 30,000 GitLab servers still unpatched against critical bugPost Views: 115
Reading Time: 1 Minute
A critical unauthenticated, remote code execution GitLab flaw fixed on April 14, 2021, remains exploitable, with over 50% of deployments remaining unpatched.
The vulnerability is tracked as CVE-2021-22205 and has a CVSS v3 score of 10.0, allowing an unauthenticated, remote attacker to execute arbitrary commands as the ‘git’ user (repository admin).
This vulnerability gives the remote attacker full access to the repository, including deleting, modifying, and stealing source code.
See Also: Complete Offensive Security and Ethical Hacking Course Exploitation in the wildHackers first started exploiting internet-facing GitLab servers in June 2021 to create new users and give them admin rights.
The actors used a working exploit published on GitHub on June 4, 2021, allowing them to abuse the vulnerable ExifTool component.
The threat actors do not need to authenticate or use a CSRF token or even a valid HTTP endpoint to use the exploit.
With the exploitation continuing to this day, researchers from Rapid7 decided to look into the number of unpatched systems and determine the scope of the underlying problem.
See Also: All Windows versions impacted by new LPE zero-day vulnerability According to a report published by Rapid7, at least 50% of the 60,000 internet-facing GitLab installations they found are not patched against the critical RCE flaw fixed six months ago.
Moreover, another 29% may or may not be vulnerable, as the analysts couldn’t extract the version string for those servers.
Admins need to update to one of the following versions to patch the flaw:
* 13.10.3
* 13.9.6
* 13.8.8
Any versions earlier than that and down to 11.9 are vulnerable to exploitation whether you’re using GitLab Enterprise Edition (EE) or GitLab Community Edition (CE).
See Also: Offensive Security Tool: ZipExec For more details on how to update GitLab, check out this dedicated portal.
To ensure that your GitLab instance isn’t vulnerable to exploitation, you can check its response to POST requests that attempt to exploit ExifTool’s mishandling of image files.
The patched versions still allow someone to reach out to ExifTool, but the response to the request should be a rejection in the form of an HTTP 404 error.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-4-90x90.jpg Chaos ransomware targets gamers via fake Minecraft alt lists2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png All Windows versions impacted by new LPE zero-day vulnerability5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/social_preview-scaled-90x90.jpg Sensitive data of 400,000 German students exposed by API flaw6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021[...]
___________________________
@hacking_Attack
@Hacking_Video
Over 30,000 GitLab servers still unpatched against critical bug
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Over 30,000 GitLab servers still unpatched against critical bugPost Views: 115
Reading Time: 1 Minute
A critical unauthenticated, remote code execution GitLab flaw fixed on April 14, 2021, remains exploitable, with over 50% of deployments remaining unpatched.
The vulnerability is tracked as CVE-2021-22205 and has a CVSS v3 score of 10.0, allowing an unauthenticated, remote attacker to execute arbitrary commands as the ‘git’ user (repository admin).
This vulnerability gives the remote attacker full access to the repository, including deleting, modifying, and stealing source code.
See Also: Complete Offensive Security and Ethical Hacking Course Exploitation in the wildHackers first started exploiting internet-facing GitLab servers in June 2021 to create new users and give them admin rights.
The actors used a working exploit published on GitHub on June 4, 2021, allowing them to abuse the vulnerable ExifTool component.
The threat actors do not need to authenticate or use a CSRF token or even a valid HTTP endpoint to use the exploit.
With the exploitation continuing to this day, researchers from Rapid7 decided to look into the number of unpatched systems and determine the scope of the underlying problem.
See Also: All Windows versions impacted by new LPE zero-day vulnerability According to a report published by Rapid7, at least 50% of the 60,000 internet-facing GitLab installations they found are not patched against the critical RCE flaw fixed six months ago.
Moreover, another 29% may or may not be vulnerable, as the analysts couldn’t extract the version string for those servers.
Admins need to update to one of the following versions to patch the flaw:
* 13.10.3
* 13.9.6
* 13.8.8
Any versions earlier than that and down to 11.9 are vulnerable to exploitation whether you’re using GitLab Enterprise Edition (EE) or GitLab Community Edition (CE).
See Also: Offensive Security Tool: ZipExec For more details on how to update GitLab, check out this dedicated portal.
To ensure that your GitLab instance isn’t vulnerable to exploitation, you can check its response to POST requests that attempt to exploit ExifTool’s mishandling of image files.
The patched versions still allow someone to reach out to ExifTool, but the response to the request should be a rejection in the form of an HTTP 404 error.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-4-90x90.jpg Chaos ransomware targets gamers via fake Minecraft alt lists2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png All Windows versions impacted by new LPE zero-day vulnerability5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/social_preview-scaled-90x90.jpg Sensitive data of 400,000 German students exposed by API flaw6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Over 30,000 GitLab servers still unpatched against critical bug | Black Hat Ethical Hacking
A critical unauthenticated, remote code execution GitLab flaw fixed on April 14, 2021, remains exploitable, with over 50% of deployments remaining unpatched.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Over 30,000 GitLab servers still unpatched against critical bug https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Over 30,000 GitLab servers still unpatched against critical bugPost Views:…
/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor2 weeks ago
The post Over 30,000 GitLab servers still unpatched against critical bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor2 weeks ago
The post Over 30,000 GitLab servers still unpatched against critical bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Any tools like Namicsoft for Linux?
https://www.reddit.com/r/Pentesting/comments/qlrg9v/any_tools_like_namicsoft_for_linux/
I’ve been using Namicsoft on Windows to import Nessus and burp findings and export the results as tables for the report. This is mostly useful when I have a hundred results that I don’t need to manually import 🤦♂️. Any alternatives? submitted by /u/LiterallyBlah (https://www.reddit.com/user/LiterallyBlah)
[link] (https://www.reddit.com/r/Pentesting/comments/qlrg9v/any_tools_like_namicsoft_for_linux/) [comments] (https://www.reddit.com/r/Pentesting/comments/qlrg9v/any_tools_like_namicsoft_for_linux/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/qlrg9v/any_tools_like_namicsoft_for_linux/
I’ve been using Namicsoft on Windows to import Nessus and burp findings and export the results as tables for the report. This is mostly useful when I have a hundred results that I don’t need to manually import 🤦♂️. Any alternatives? submitted by /u/LiterallyBlah (https://www.reddit.com/user/LiterallyBlah)
[link] (https://www.reddit.com/r/Pentesting/comments/qlrg9v/any_tools_like_namicsoft_for_linux/) [comments] (https://www.reddit.com/r/Pentesting/comments/qlrg9v/any_tools_like_namicsoft_for_linux/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Any tools like Namicsoft for Linux?
I’ve been using Namicsoft on Windows to import Nessus and burp findings and export the results as tables for the report. This is mostly useful...
La dépêche de l’Agora — Bulletin Hebdomadaire de la communauté Olympus — Mercredi 4 Août 2021
Bienvenue dans la dépêche de l’Agora, une newsletter gérée par la communauté Olympus, créée par les Ohmies, pour les Ohmies !Continue reading on Medium »
Read more...
Bienvenue dans la dépêche de l’Agora, une newsletter gérée par la communauté Olympus, créée par les Ohmies, pour les Ohmies !Continue reading on Medium »
Read more...
USD 1,337,133.7 Bug Bounty to Improve On-chain Security for the Cronos Ecosystem
We are excited to announce a Cronos bug bounty program, with a maximum bounty of up to USD 1,337,133.7 sponsored by Blockchain accelerator…Continue reading on Cronos »
Read more...
We are excited to announce a Cronos bug bounty program, with a maximum bounty of up to USD 1,337,133.7 sponsored by Blockchain accelerator…Continue reading on Cronos »
Read more...
Kali Linux Tutorials
Metabadger : Prevent SSRF Attacks On AWS EC2 Via Automated Upgrades To The More Secure Instance Metadata Service V2 (IMDSv2)
Metabadger Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).
Metabadger
Purpose and functionality
* Diagnose and evaluate your current usage of the AWS Instance Metadata Service along with understanding how the service works
* Prepare you to upgrade to v2 of the Instance Metadata service to safeguard against v1 attack vectors
* Give you the ability to specifically update your instances to only use IMDSv2
* Give you the ability to disable the Instance Metadata service where you do not need it as a way to reduce attack surface
What Is The AWS Instance Metadata Service?
* The AWS metadata service essentially gives you access to all the things within an instance, including the instance role credential & session token
* Known SSRF vulnerabilities that exploit and use this attack as a pivot into your environment
* The famous attacks you have heard about, some of which involved this method of gaining access via a vulnerable web app with access to the instance metadata service
* Attacker could take said credentials from metadata service and use them outside of that particular instance IMDSv2 And Why It Should Be Used
* Ensuring that instances are using V2 of the metadata service at all times by making it a requirement within it’s configuration
* Enabling session tokens with a PUT request with a mandatory request header to the AWS metadata API, IMDSv1 does not check for this making it easier for attackers to exploit the service
* X-Forwarded-For header is not allowed in IMDSv2 ensuring that no proxy based traffic is allowed to communicate with the metadata service Problem Statement
Engineering teams may have a vast variety of compute infrastructure in AWS that they need to protect from certain vulnerabilities that leverage the metadata service. The metadata service is required to run on instances if any IAM is used or if there is any user data information the instance might need when it boots. Limiting the attack surface of your instances is crucial in preventing the ability to pivot in your environment by stealing information provided by the service itself. Numerous famous attacks in the past have leveraged this particular service to exploit a role that is attached to the instance or dump sensitive data that is accessible via the metadata service. Metabadger can help to identify where and how you are using the instance metadata service while also giving you the ability to reduce any unwanted attack leverage to lower your overall risk posture while operating in EC2. Disclaimer and Rollback
Using this tool may impact your AWS compute infrastructure as not all services and applications may work either without the metadata service or on version 2. Take caution when deploying this in your production environment and have a rollback plan in place incase something seems out of the ordinary. Metabadger comes built in with the ability to roll back to the default version 1 of the service using the -v1 flag, you can use this to quickly roll back your instances to use the default. Ideally, you should run this tool and update your metadata version in non-production environments as a proving grounds before applying it. Guided Steps for Hardening
Step 1
Initially, we want to discover our overall usage of the metadata service in a particular AWS region. Metabadger will evaluate the current status of your usage in the region where your credentials point to in your
___________________________
@hacking_Attack
@Hacking_Video
Metabadger : Prevent SSRF Attacks On AWS EC2 Via Automated Upgrades To The More Secure Instance Metadata Service V2 (IMDSv2)
Metabadger Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).
Metabadger
Purpose and functionality
* Diagnose and evaluate your current usage of the AWS Instance Metadata Service along with understanding how the service works
* Prepare you to upgrade to v2 of the Instance Metadata service to safeguard against v1 attack vectors
* Give you the ability to specifically update your instances to only use IMDSv2
* Give you the ability to disable the Instance Metadata service where you do not need it as a way to reduce attack surface
What Is The AWS Instance Metadata Service?
* The AWS metadata service essentially gives you access to all the things within an instance, including the instance role credential & session token
* Known SSRF vulnerabilities that exploit and use this attack as a pivot into your environment
* The famous attacks you have heard about, some of which involved this method of gaining access via a vulnerable web app with access to the instance metadata service
* Attacker could take said credentials from metadata service and use them outside of that particular instance IMDSv2 And Why It Should Be Used
* Ensuring that instances are using V2 of the metadata service at all times by making it a requirement within it’s configuration
* Enabling session tokens with a PUT request with a mandatory request header to the AWS metadata API, IMDSv1 does not check for this making it easier for attackers to exploit the service
* X-Forwarded-For header is not allowed in IMDSv2 ensuring that no proxy based traffic is allowed to communicate with the metadata service Problem Statement
Engineering teams may have a vast variety of compute infrastructure in AWS that they need to protect from certain vulnerabilities that leverage the metadata service. The metadata service is required to run on instances if any IAM is used or if there is any user data information the instance might need when it boots. Limiting the attack surface of your instances is crucial in preventing the ability to pivot in your environment by stealing information provided by the service itself. Numerous famous attacks in the past have leveraged this particular service to exploit a role that is attached to the instance or dump sensitive data that is accessible via the metadata service. Metabadger can help to identify where and how you are using the instance metadata service while also giving you the ability to reduce any unwanted attack leverage to lower your overall risk posture while operating in EC2. Disclaimer and Rollback
Using this tool may impact your AWS compute infrastructure as not all services and applications may work either without the metadata service or on version 2. Take caution when deploying this in your production environment and have a rollback plan in place incase something seems out of the ordinary. Metabadger comes built in with the ability to roll back to the default version 1 of the service using the -v1 flag, you can use this to quickly roll back your instances to use the default. Ideally, you should run this tool and update your metadata version in non-production environments as a proving grounds before applying it. Guided Steps for Hardening
Step 1
Initially, we want to discover our overall usage of the metadata service in a particular AWS region. Metabadger will evaluate the current status of your usage in the region where your credentials point to in your
/.aws/credentialsfile or the current role that is assumed. You may also specify the --regionflag when running the discover-metadatacommand if you would like to change to another region than what is currently configured. Once you have a[...]___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Metabadger : Prevent SSRF Attacks On AWS EC2
Metabadger Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Metabadger : Prevent SSRF Attacks On AWS EC2 Via Automated Upgrades To The More Secure Instance Metadata Service V2 (IMDSv2) Metabadger Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service…
good idea of which version your instances are running and if the service is enabled or disabled, you will be able to make a much more defined action plan for hardening the service. Note that you can find specific meaning to every metadata option that is set here.
Step 2
One of the areas that should be evaluated when making the switch to v2 of the service is the use of IAM roles. Metabadger lets you identify instances in a region that may already be using an IAM role. The
Step 3
Upon completion of doing your initial discovery and evaluation, you can now create a staged approach to hardening your compute infrastructure to use either v2 of the metadata service or disable it where it may not be used. The
Metabadger requires an IAM role or credentials with the following permission:
ec2:ModifyInstanceAttribute
ec2:DescribeInstances
When making changes to the Instance Metadata service, you should be cautious and follow additional guidance from AWS on how to safely upgrade to version 2. Metabadger was designed to assist you with this process to further secure your compute infrastructure in AWS.
AWS Best Practice Guide on Updating to IMDSv2 Usage & Installation
Install via pip
pip3 install –user metabadger
Install via Github
$ git clone https://github.com/salesforce/metabadger
$ cd metabadger
$ pip install -e .
$ metabadger
Usage: metabadger [OPTIONS] COMMAND [ARGS]…
Metabadger is an AWS Security Tool used for discovering and hardening the
Instance Metadata service.
Options:
–version Show the version and exit.
–help Show this message and exit.
Commands:
disable-metadata Disable the IMDS service on EC2 instances
discover-metadata Discover summary of IMDS service usage within EC2
discover-role-usage Discover summary of IAM role usage for EC2
harden-metadata Harden the AWS instance metadata service from v1 to v2
Commands
discover-metadata
A summary of your overall instance metadata service usage including which version and an overall enforcement percentage. Using these numbers will help you understand the overall posture of how hardened your metadata usage is and where you’re enforcing v2 vs v1.
Options:
-a, –all-region Provide a metadata summary for all available regions in the AWS account
-j, –json Get metadata summary in JSON format
-r, –region TEXT Specify which AWS region you will perform this command in
-p, –profile TEXT Specify the AWS IAM profile.
discover-role-usage
A summary of instances and the roles that they are using, this will give you a good idea of the caution you must take when making updates to the metadata service itself.
Options:
-p, –profile TEXT Specify the AWS IAM profile.
-r, –region TEXT Specify which AWS region you will perform this command in
harden-metadata
The ability to modify the instances to use either metadata v1 or v2 and to get an understanding of how many instances would be modified by running a dry run mode.
Options:
-a, –all-region Update IMDS across all regions in your account
-e, –exclusion The exclusion flag will apply t[...]
___________________________
@hacking_Attack
@Hacking_Video
Step 2
One of the areas that should be evaluated when making the switch to v2 of the service is the use of IAM roles. Metabadger lets you identify instances in a region that may already be using an IAM role. The
discover-role-usagecommand will output a list of instances that have roles attached to them. If you have a lot of instances using roles, you should take precaution when updating the service to v2 to ensure the overall functionality of your workloads does not become impacted.Step 3
Upon completion of doing your initial discovery and evaluation, you can now create a staged approach to hardening your compute infrastructure to use either v2 of the metadata service or disable it where it may not be used. The
harden-metadatacommand allows you to update all instances in a particular region by default. You can also pass instance tags using the --tagsflag or an input file containing a csv of instances that you would like to apply a configuration for. Once you have made the appropriate updates to v2 and disabled the service where it is not used you can re-evaluate using the items in Step 1 to confirm your environment is locked down. If you have certain instances that you don’t want to update you can exlude them via the --exclusionflag by tag or instance id. RequirementsMetabadger requires an IAM role or credentials with the following permission:
ec2:ModifyInstanceAttribute
ec2:DescribeInstances
When making changes to the Instance Metadata service, you should be cautious and follow additional guidance from AWS on how to safely upgrade to version 2. Metabadger was designed to assist you with this process to further secure your compute infrastructure in AWS.
AWS Best Practice Guide on Updating to IMDSv2 Usage & Installation
Install via pip
pip3 install –user metabadger
Install via Github
$ git clone https://github.com/salesforce/metabadger
$ cd metabadger
$ pip install -e .
$ metabadger
Usage: metabadger [OPTIONS] COMMAND [ARGS]…
Metabadger is an AWS Security Tool used for discovering and hardening the
Instance Metadata service.
Options:
–version Show the version and exit.
–help Show this message and exit.
Commands:
disable-metadata Disable the IMDS service on EC2 instances
discover-metadata Discover summary of IMDS service usage within EC2
discover-role-usage Discover summary of IAM role usage for EC2
harden-metadata Harden the AWS instance metadata service from v1 to v2
Commands
discover-metadata
A summary of your overall instance metadata service usage including which version and an overall enforcement percentage. Using these numbers will help you understand the overall posture of how hardened your metadata usage is and where you’re enforcing v2 vs v1.
Options:
-a, –all-region Provide a metadata summary for all available regions in the AWS account
-j, –json Get metadata summary in JSON format
-r, –region TEXT Specify which AWS region you will perform this command in
-p, –profile TEXT Specify the AWS IAM profile.
discover-role-usage
A summary of instances and the roles that they are using, this will give you a good idea of the caution you must take when making updates to the metadata service itself.
Options:
-p, –profile TEXT Specify the AWS IAM profile.
-r, –region TEXT Specify which AWS region you will perform this command in
harden-metadata
The ability to modify the instances to use either metadata v1 or v2 and to get an understanding of how many instances would be modified by running a dry run mode.
Options:
-a, –all-region Update IMDS across all regions in your account
-e, –exclusion The exclusion flag will apply t[...]
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - salesforce/metabadger: Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service…
Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2). - GitHub - salesforce/metabadger: Prevent SSRF attacks on AWS EC2 via automated upgr...
Hacking Articles Tips Tricks Videos Tutorials
good idea of which version your instances are running and if the service is enabled or disabled, you will be able to make a much more defined action plan for hardening the service. Note that you can find specific meaning to every metadata option that is set here.…
o everything besides what is specified, tags or instances
-d, –dry-run Dry run of hardening metadata changes
-v1, –v1 Enforces v1 of the metadata service
-i, –input-file PATH Path of csv file of instances to harden IMDS for
-t, –tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, –region TEXT Specify which AWS region you will perform this command in
-p, –profile TEXT Specify the AWS IAM profile.
disable-metadata
Use this command to completely disable the metadata servie on instances
Options:
-e, –exclusion The exclusion flag will apply to everything besides what is specified, tags or instances
-d, –dry-run Dry run of disabling the metadata service
-i, –input-file PATH Path of csv file of instances to disable IMDS for
-t, –tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, –region TEXT Specify which AWS region you will perform this command in
-p, –profile TEXT Specify the AWS IAM profile.
Logging
All changes made by Metabadger will be logged to a file saved in the working directory called
* The time and date stamp for when a change was made
* Change that occured (disabled, hardened, or updated)
* The instance ID where the change was made
* Dry run information
* A status on if the change was successful or not Download
___________________________
@hacking_Attack
@Hacking_Video
-d, –dry-run Dry run of hardening metadata changes
-v1, –v1 Enforces v1 of the metadata service
-i, –input-file PATH Path of csv file of instances to harden IMDS for
-t, –tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, –region TEXT Specify which AWS region you will perform this command in
-p, –profile TEXT Specify the AWS IAM profile.
disable-metadata
Use this command to completely disable the metadata servie on instances
Options:
-e, –exclusion The exclusion flag will apply to everything besides what is specified, tags or instances
-d, –dry-run Dry run of disabling the metadata service
-i, –input-file PATH Path of csv file of instances to disable IMDS for
-t, –tags TEXT A comma seperated list of tags to apply the hardening setting to
-r, –region TEXT Specify which AWS region you will perform this command in
-p, –profile TEXT Specify the AWS IAM profile.
Logging
All changes made by Metabadger will be logged to a file saved in the working directory called
metabadger.log. The file will include the following for every action that the tool takes when it changes the metadata service:* The time and date stamp for when a change was made
* Change that occured (disabled, hardened, or updated)
* The instance ID where the change was made
* Dry run information
* A status on if the change was successful or not Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Disallowing CAP_NET_RAW Capability for Root User using AppArmor
Is root the ultimate user in Linux? You will get the answer to this question in a post by confining the cap_net_raw for ping command using AppArmor
https://tbhaxor.com/disallowing-cap_net_raw-capability-for-root-user-using-apparmor/
submitted by /u/tbhaxor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Disallowing CAP_NET_RAW Capability for Root User using AppArmor
Is root the ultimate user in Linux? You will get the answer to this question in a post by confining the cap_net_raw for ping command using AppArmor
https://tbhaxor.com/disallowing-cap_net_raw-capability-for-root-user-using-apparmor/
submitted by /u/tbhaxor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Disallowing CAP_NET_RAW Capability for Root User using AppArmor
Is root the ultimate user in Linux? You will get the answer to this question in a post by confining the cap\_net\_raw for ping command using...
HandleKatz - PIC Lsass Dumper Using Cloned Handles
http://www.kitploit.com/2021/11/handlekatz-pic-lsass-dumper-using.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/11/handlekatz-pic-lsass-dumper-using.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
This tool was implemented as part of our Brucon2021 conference talk and demonstrates the usage of cloned handles to Lsass in order to create an obfuscated memory dump of the same. It compiles down to an executable living fully in its text segment. Thus, the extracted .text segment of the PE file is fully position independent code (=PIC), meaning that it can be treated like any shellcode. The execution of HandleKatz in memory has a very small footprint, as itself does not allocate any more executable memory and can therefore efficiently be combined with concepts such as (Phantom)DLL-Hollowing as described by @_ForrestOrr (https://www.forrest-orr.net/post/malicious-memory-artifacts-part-i-dll-hollowing). This is in contrast to PIC PE loaders, such as Donut, SRDI or Reflective Loaders which, during PE loading, allocate more executable memory. Additionally, it makes use of a modified version of ReactOS MiniDumpWriteDumpA using direct system calls to write an obfuscated dump to disk. For detailed information please refer to the PDF file PICYourMalware.pdf in this repository.
Usage
make all to build HandleKatzPIC.exe, HandleKatz.bin and loader.exe Please note that different compiler (https://www.kitploit.com/search/label/Compiler) (versions) yield different results. This might produce a PE file with relocations. All tests were carried out using x86_64-w64-mingw32-gcc mingw-gcc version 11.2.0 (GCC). The produced PIC was successfully tested on: Windows 10 (https://www.kitploit.com/search/label/Windows%2010) Pro 10.0.17763. On other versions of windows, API hashes might differ. To use the PIC, cast a pointer to the shellcode in executable memory and call it according to the definition: DWORD handleKatz(BOOL b_only_recon, char* ptr_output_path, uint32_t pid, char* ptr_buf_output);
b_only_recon If set, HandleKatz will only enumerate suitable handles without dumping ptr_output_path Determines where the obfuscated dump will be written to pid What PID to clone a handle from ptr_buf_output A char pointer to which HandleKatz writes its internal output For deobfuscation (https://www.kitploit.com/search/label/Deobfuscation) of the dump file, the script Decoder.py can be used. Loader implements a sample loader for HandleKatz: loader.exe --pid:7331 --outfile:C:\Temp\dump.obfuscated
___________________________
@hacking_Attack
@Hacking_Video
Usage
make all to build HandleKatzPIC.exe, HandleKatz.bin and loader.exe Please note that different compiler (https://www.kitploit.com/search/label/Compiler) (versions) yield different results. This might produce a PE file with relocations. All tests were carried out using x86_64-w64-mingw32-gcc mingw-gcc version 11.2.0 (GCC). The produced PIC was successfully tested on: Windows 10 (https://www.kitploit.com/search/label/Windows%2010) Pro 10.0.17763. On other versions of windows, API hashes might differ. To use the PIC, cast a pointer to the shellcode in executable memory and call it according to the definition: DWORD handleKatz(BOOL b_only_recon, char* ptr_output_path, uint32_t pid, char* ptr_buf_output);
b_only_recon If set, HandleKatz will only enumerate suitable handles without dumping ptr_output_path Determines where the obfuscated dump will be written to pid What PID to clone a handle from ptr_buf_output A char pointer to which HandleKatz writes its internal output For deobfuscation (https://www.kitploit.com/search/label/Deobfuscation) of the dump file, the script Decoder.py can be used. Loader implements a sample loader for HandleKatz: loader.exe --pid:7331 --outfile:C:\Temp\dump.obfuscated
___________________________
@hacking_Attack
@Hacking_Video
ForrestOrr
Masking Malicious Memory Artifacts – Part I: Phantom DLL Hollowing
IntroductionI've written this article with the intention of improving the skill of the reader as relating to the topic of memory stealth when designing malware. First by detailing a technique I term DLL hollowing which has not yet gained widespread recognition…