Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
IrpDumper.sys in itself then acts a rootkit, proxy-ing all calls to the targeted driver(s). When a DeviceIoControl is sent to a hooked driver, IrpDumper will simply capture the data if any, and push a message to the user-land agent (Broker), and yield the execution back to the legitimate drivers, allowing the intended code to continue as expected. The Broker stores all this data in user-land waiting for a event to ask for them.
Build

GUI
Clone the repository, and build the Broker in the solution CFB.sln at the project root with Visual Studio (Debug - very verbose - or Release). Additionally, you can build the App GUI by building the GUI (Universal Windows) project.
Command line
Clone the repository and in a VS prompt run msbuild CFB.sln /p:Configuration=$Conf ">C:\cfb\> msbuild CFB.sln /p:Configuration=$Conf
Where $Conf can be set to Release to Debug.
Setup
A Windows 7+ machine (Windows 10 SDK VM (https://developer.microsoft.com/en-us/windows/downloads/virtual-machines) is recommended)On this target machine, simply enable BCD test signing flag (in cmd.exe as Admin): bcdedit.exe /set {whatever-profile} testsigning on ">C:\> bcdedit.exe /set {whatever-profile} testsigning on
If using in Debug mode, IrpDumper.sys will provide a lot more valuable information as to what's being hooked (the price of performance). All those info can be visible via tools like DebugView.exe or a kernel debugger like WinDbg. In either case, you must enable kernel debug BCD flag (in cmd.exe as Admin): bcdedit.exe /set {whatever-profile} debug on ">C:\> bcdedit.exe /set {whatever-profile} debug on
It is also recommended to edit the KD verbosity level, via:the registry for a permanent effect (reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Debug Print Filter" /v DEFAULT /t REG_DWORD /d 0xf)directly from WinDbg for only the current session (ed nt!Kd_Default_Mask 0xf)If you plan on (re-)compiling any of the tools, you must install VS (2019 preferred). If using the Release binaries, you only need VS C++ Redist installed (x86 or x64 depending on your VM architecture).Follow the indications in the Docs/ folder to improve your setup.
Command-line client
Several command line (https://www.kitploit.com/search/label/Command%20Line) tools (such as dumping all data to SQLite database, fuzzing IRP, etc.) can be found in the external repository CFB-cli (https://github.com/hugsy/CFB-cli).
Why the name?
Because I had no idea for the name of this tool, so it was graciously generated by a script of mine (https://github.com/hugsy/stuff/tree/master/random-word).

Download CFB (https://github.com/hugsy/CFB)

___________________________
@hacking_Attack
@Hacking_Video
Guide to Bug Bounty Hunting

MindsetContinue reading on Techiepedia »
Read more...
Broken Link Hijacking — 404 Google Play Store— xxx$ Bounty

This is my first write-up and I will tell you how I ended up getting a xxx$ bounty for a simple Broken Link Hijacking with Google Play…Continue reading on Medium »
Read more...
Earn AMPT Rewards in our DAO Bug Hunt and Bounty Campaign! Official Instructions!

Top Prize of $5K plus thousands of additional prizes! Everyone WINS!Continue reading on Medium »
Read more...
hacking: security in practice
Implementing Memcached DDoS in Java?

Hello. For my mobile security class, we are building out an Android botnet. We have built out the Android application to run Slowloris DDoS attacks, but we are looking to add Memcached attacks in order to have something thats a little more current day applicable. We are having trouble trying to implement this as we can't edit source addresses in Java so we can't redirect responses to our victim. Does anyone here have experience in this? Thanks.

submitted by /u/TheGuyWhoCodes
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Web Hacking Incentive

Other than for fun, what are the incentives for black hats to hack websites? I can understand if Law Enforcement for example is interested in someone's behavior it makes sense that they would want surveillance of that person, so installing malware either on their computer or mobile phone enables that, but what are black hats looking to accomplish when attacking websites, is PII really worth that much?

submitted by /u/Hawker_G
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Finding stalkers identity

Is there anyway I can find a 1 year old stalker’s identity through hacking methods ?

submitted by /u/BlackHermes
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video