Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Covert-Control - Google Drive, OneDrive And Youtube As Covert-Channels - Control Systems Remotely By Uploading Files To Google Drive, OneDrive, Youtube Or Telegram https://blogger.googleusercontent.com/img/a/AVvXsEhNNj9sLoHsQzeN…
tional input argument is the public folder url, which can be also configured in config.py:
python3 covert-googledrive.py [FOLDER_URL] The listener will check the Google Drive folder every 300 seconds by default (can be updated in config.py). In this case a video, "video.avi", is uploaded with the command in the QR of the video: https://blogger.googleusercontent.com/img/a/AVvXsEh7PO-zrz2mNqj_VY_kmDQET7GpTa-DBXLbSgqobq2g57tZlhzliEKTGAY4hQC6pRLnEfj-At1mg8ocvDhXVSQVxuq7fvza7DpwVXbRaFC6Gydeo93dLx8wONmBH7fW1XR5IUTzt13waDxHiN0IOeE9fwKULFFNWT82Sa4lqucyf6LZ_WcVPejBNAknRw=s16000 After finding there is a new file uploaded to the folder, it is downloaded, processed and the commands are executed: https://blogger.googleusercontent.com/img/a/AVvXsEhrO6AoXrhATjZf2RQwnQrgOpG3b_o9XgLVB63mwZ-83yszv1b21pgZDz8CdKhDZ3tPG11FEzXk7kffgTQQgRrU9bIswB2s7zWezpL4RVDEiU_oxJOXMj3XTqZ0_nkjFqjYP0R0fDhklk5bfc_wwh4DGYNAHhIcQkrEZVWLpehorezYJ4CcHF9egZt8Yg=w640-h146 OnedriveIt allows to execute commands uploading text files, images, audio and videos, unencrypted or encrypted with AES. The optional input argument is the public folder url, which can be also configured in config.py: python3 covert-onedrive.py [FOLDER_URL] The listener will check the OneDrive folder every 300 seconds by default (this can be updated in config.py). In this case an audio, "audio_encrypted.wav", is uploaded with the command encrypted with AES: https://blogger.googleusercontent.com/img/a/AVvXsEhEyfjlRlenIcZsZjpFU-fKoRCujugREmhXvznuTVo5LXdBscQx9TmCoqBGXl5q-pTCbJfUPbYWT7FD3pdnQHPEw-kRqsjw02HYsJ2km0pPurJXlNjlvI-G4wGo79bCKiUliQvnfDwA3_-ID0hfYEMJ0hs9vmIAj35E_uUwoUd8nMsDJSd_IES3UuxFUA After finding there is a new file uploaded to the folder, it is downloaded, processed and the commands are executed: https://blogger.googleusercontent.com/img/a/AVvXsEiYLaLyA0SBCBnmOefTKuBCm0mJPxRan9E7afhg4-uciPfaCkQMcdFcve7ndZBzmXSD10jt_16Wqb05gt9xUM4_HEPtR7dV79aPbeCM59iqecrORaNbMZ0ou5bkx_FCnmtdEZKAOaBD9OffGoed6WEaEgvW3aDtTXqErE7biGhOEp0gxnLLU9BGRcorBA=w640-h192 NOTE: This will only work if you do not delete any file in the folder, if you do it you must create a new one. It could be possible to implement it to work even after deleting files, but it would be necessary to create many requests and would be less stealthy. YoutubeIt allows to execute commands uploading videos, unencrypted or encrypted with AES. The optional input arguments are the Youtube channel ID to monitor and the API key, which can be also configured in config.py: python3 covert-youtube.py [CHANNEL_ID] [API_KEY] The listener will check the Youtube channel every 300 seconds by default (this can be updated in config.py). First the video is uploaded: https://blogger.googleusercontent.com/img/a/AVvXsEhNNj9sLoHsQzeNXPg9G_wuz6tFFACZnQ5qGqK1LIj-vlqDBim9fO-3iCFDcjp5QX800dYWWEKLEGmAgUixYXCriGVhNVsDUUqmv2x0If0tDj-m0ZMxGcUyeMY5sM5TGdXeYW9G-1z0_BBJ4Moj4rpASC7R2ZzAKbMIgIugT6IN3tbKJtU2hiX-rPl5CA=w640-h208 After finding there is a new video in the channel, it is downloaded, processed and the commands are executed: https://raw.githubusercontent.com/ricardojoserf/ricardojoserf.github.io/master/images/covert-control/image6.png TelegramControl systems remotely with a Telegram bot. This option does not allow to upload files, but it is possible to send the commands in cleartext ("/cmd") or encrypted with AES ("/encrypted"). The first optional input argument is the bot token, which can be also configured in config.py; the second one is used to configure a single Telegram user who can send commands to the bot (without "@"): python3 covert-telegram.py [BOT_TOKEN] [TELEGRAM_USER] The listener will check the commands in the chat and show the output: /cmd CLEARTEXT_COMMAND
/encrypted AES_ENCRYPTED_COMMAND https://blogger.googleusercontent.com/img/a/AVvXsEg-1_4o1us_yNCz9ZidsoW_mtZlnwav_5QydCPGjjnMdEt-TlN5UY7dmKmynXIpULarG7g6oUPWHrR98moyAscbq7799a-2mh7wBL8hCR13dPe1bLfYqPsJQ0FLUXOpG[...]
Hacking Articles Tips Tricks Videos Tutorials
tional input argument is the public folder url, which can be also configured in config.py: python3 covert-googledrive.py [FOLDER_URL] The listener will check the Google Drive folder every 300 seconds by default (can be updated in config.py). In this case a…
vxlWTVvRfguyrFXYVG4Ud-n4FdSsXgN5QHdX_z6f7bcMkc05RgBa9j1f5zXnw=w640-h330 Installation
sudo apt install libzbar0
pip install bs4 Pillow opencv-python pyqrcode pypng pyzbar youtube_dl pytesseract python-telegram-bot requests argparse pycryptodome
git clone https://github.com/ricardojoserf/covert-control && cd covert-control/ Creating standalone binariespyinstaller --onefile covert-googledrive.py
pyinstaller --onefile covert-onedrive.py
pyinstaller --onefile covert-telegram.py
pyinstaller --onefile covert-youtube.py
rm -rf build
rm *spec
ls dist/ Download Covert-Control➖ Sent by @TheFeedReaderBot ➖
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Should Our Security Controls Be More Like North Korea or Norway?
When the drive for additional visibility and awareness is led by the business rather than just a SOC team, both the business and security can benefit.
Should Our Security Controls Be More Like North Korea or Norway?
When the drive for additional visibility and awareness is led by the business rather than just a SOC team, both the business and security can benefit.
How I got $200 in 30 Seconds.
https://medium.com/@yashhunter772/how-i-got-200-in-30-seconds-3dd742f60186?source=rss------bug_bounty-5
https://medium.com/@yashhunter772/how-i-got-200-in-30-seconds-3dd742f60186?source=rss------bug_bounty-5
Hello Guys. I am Yash working as a security researcher,Continue reading on Medium » (https://medium.com/@yashhunter772/how-i-got-200-in-30-seconds-3dd742f60186?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Stolen Robinhood Data Listed for Sale on Deep Web | ChangeNOW
https://external-preview.redd.it/MRLDvsgek7_oK9gj4P7zAXd1TkL7P6wIartMavqBNtQ.jpg?width=640&crop=smart&auto=webp&s=9c8dfda7b6c58a64e56cf41fa00ad0974d19780b submitted by /u/ChangeNow_io
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Stolen Robinhood Data Listed for Sale on Deep Web | ChangeNOW
https://external-preview.redd.it/MRLDvsgek7_oK9gj4P7zAXd1TkL7P6wIartMavqBNtQ.jpg?width=640&crop=smart&auto=webp&s=9c8dfda7b6c58a64e56cf41fa00ad0974d19780b submitted by /u/ChangeNow_io
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Stolen Robinhood Data Listed for Sale on Deep Web | ChangeNOW
Posted in r/deepweb by u/ChangeNow_io • 8 points and 0 comments
From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy
https://hector0x.medium.com/from-url-dumps-digging-to-idor-bac-massive-phishing-in-udemy-6fa7f94ef256?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hector0x.medium.com/from-url-dumps-digging-to-idor-bac-massive-phishing-in-udemy-6fa7f94ef256?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy
Hey All,
Hey All,Continue reading on Medium » (https://hector0x.medium.com/from-url-dumps-digging-to-idor-bac-massive-phishing-in-udemy-6fa7f94ef256?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy
Hey All,
4 Risky bugs to report to bounty programs
https://redsec.medium.com/5-risky-bugs-to-report-to-bounty-programs-c36395972926?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://redsec.medium.com/5-risky-bugs-to-report-to-bounty-programs-c36395972926?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
4 Risky bugs to (not)report to bounty programs
Bugs that you should avoid or reconsider before reporting to programs.
Bugs that you should avoid or reconsider before reporting to programs.Continue reading on Medium » (https://redsec.medium.com/5-risky-bugs-to-report-to-bounty-programs-c36395972926?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
4 Risky bugs to (not)report to bounty programs
Bugs that you should avoid or reconsider before reporting to programs.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Inside the Mind of a Hacker
https://cdn-images-1.medium.com/max/1920/1*bJF_FisPo6UCAeGjAMa8Qg.jpeg
Consciousness feels like its inside a ROM chip in the brain. You can only read from it, but can’t write to it whenever you feel like. The…
Continue reading on Developer Students Club, VJTI »
___________________________
@hacking_Attack
@Hacking_Video
Inside the Mind of a Hacker
https://cdn-images-1.medium.com/max/1920/1*bJF_FisPo6UCAeGjAMa8Qg.jpeg
Consciousness feels like its inside a ROM chip in the brain. You can only read from it, but can’t write to it whenever you feel like. The…
Continue reading on Developer Students Club, VJTI »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Inside the Mind of a Hacker
Consciousness feels like its inside a ROM chip in the brain. You can only read from it, but can’t write to it whenever you feel like. The…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
An Untrustworthy Pinball Machine
https://cdn-images-1.medium.com/max/612/1*InmYiQ30ckxLonpKZvMTGQ.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
An Untrustworthy Pinball Machine
https://cdn-images-1.medium.com/max/612/1*InmYiQ30ckxLonpKZvMTGQ.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
An Untrustworthy Pinball Machine
On October 22nd, infamous whitehat samczsun posted a tweet containing nothing but an Ethereum address. It didn’t take long for people to track it to an address on the Rinkeby network where the…