Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
In the summer of 2020, Chef Nomi (@NomiChef) [1] presented the MasterChef contract [2], one of the most redeployed contracts during the…Continue reading on Amber Group » (https://medium.com/amber-group/dinosaur-eggs-liquiditypool-loophole-explained-ac6ef10faafe?source=rss------bug_bounty-5)
Dinosaur Eggs’ LiquidityPool Loophole Explained

In the summer of 2020, Chef Nomi (@NomiChef) 1 presented the MasterChef contract 2, one of the most redeployed contracts during the…Continue reading on Amber Group »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Alibaba ECS instances actively hijacked by cryptomining malware

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Alibaba ECS instances actively hijacked by cryptomining malwarePost Views: 92
Reading Time: 1 Minute
​Threat actors are hijacking Alibaba Elastic Computing Service (ECS) instances to install cryptominer malware and harness the available server resources for their own profit.
Alibaba is a Chinese technology giant with a global market presence, with its cloud services being used primarily in southeast Asia.

In particular, the ECS service is marketed as offering fast memory, Intel CPUs, and promising low-latency operations. Even better, to protect against malware such as cryptominers, ECS comes with a pre-installed security agent. Hackers remove ECS security agent to install minersAccording to a report by Trend Micro, one of the issues with Alibaba ECS is the lack of different privilege levels configured on an instance, with all instances offering root access by default.

This makes it possible for threats actors who gain access to login credentials to access the target server via SSH as root without any preparatory (escalation of privilege) work.
See Also: Complete Offensive Security and Ethical Hacking Course
“The threat actor has the highest possible privilege upon compromise, including vulnerability exploitation, any misconfiguration issue, weak credentials or data leakage,” explains Trend Micro’s report.

Furthermore, these elevated privileges allow the threat actors to create firewall rules that drop incoming packets from IP ranges belonging to internal Alibaba servers to prevent the installed security agent from detecting suspicious behavior.

The threat actors can then run scripts that stop the security agent on the compromised device.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/remove_protection.jpg
<figcaptionDisabling the security agent on ECS
Source: Trend Micro
Given how easy it is to plant kernel module rootkits and cryptojacking malware due to the elevated privileges, it is no surprise that multiple threat actors compete to take over Alibaba Cloud ECS instances.
See Also: All Windows versions impacted by new LPE zero-day vulnerability Trend Micro has also observed scripts looking for processes running on specific ports commonly used by malware and backdoors and terminating the associated processes to remove competing malware.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/mining.png
<figcaptionCryptojacking malware tuning an ECS instance and terminating processes
Source: Trend Micro
Another ECS feature exploited by the actors is an auto-scaling system that enables the service to automatically adjust computing resources based on the volume of user requests.

This is to help prevent service interruptions and hiccups from sudden traffic burdens, but it’s an opportunity for cryptojackers.

By abusing this when it’s active on the targeted account, the actors can scale up their Monero mining power and incur additional costs to the instance owner.

Considering that the billing cycles are monthly in the best-case scenario, it would take the victim some time to realize the problem and take action.

When auto-scaling isn’t available, mining will cause a more immediate and noticeable slow-down effect as the miners utilize the available CPU power.
See Also: Offensive Security Tool: Pentesting Tools All cloud services should be vettedAlibaba ECS is yet another case of a cloud service targeted by cryptominers, with other notable recent campaigns targeting Docker and Huawei Cloud.

Trend Micr[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Alibaba ECS instances actively hijacked by cryptomining malware https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Alibaba ECS instances actively hijacked by cryptomining malwarePost Views:…
o has notified Alibaba of its findings but hasn’t received a response yet.

If you are using Alibaba’s cloud service, ensure that your security settings are correct and follow best practices.

Moreover, avoid running apps under root privilege, use cryptographic keys for access, and follow the principle of least privilege.

In the case of ECS, its built-in malware protection isn’t enough, so adding a second layer of detection for malware and vulnerabilities on the cloud environment should be part of your standard security practice.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-90x90.jpg QBot returns for a new wave of infections using Squirrelwaffle1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/face-malware-virus-infected-red-network-90x90.jpg BotenaGo botnet targets millions of IoT devices with 33 exploits4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Pwn2OwnBlur-90x90.png Pwn2Own – Over 1 million dollars in Bounties, Samsung Galaxy S21 hacked twice, Printer plays AC/DC1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/maxresdefault-1024x576-1-90x90.jpg Microsoft Exchange ProxyShell exploits used to deploy Babuk ransomware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Mekotio-Banking-Trojan-90x90.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/GitLab-90x90.jpg Over 30,000 GitLab servers still unpatched against critical bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code2 weeks ago
The post Alibaba ECS instances actively hijacked by cryptomining malware first appeared on Black Hat Ethical Hacking.
This project is born with the aim to develop a lightweight, but useful tool. The reason is that the existing hex editors have some different limitations (e.g. too many dependencies, missing hex coloring features, etc.).
 This project is based on qhexedit2, capstone and keystone engines. New features could be added in the future, PRs are welcomed.
Features
Chunks loader - Used to load only a portion of large files without exhaust the memory (use alt + left/right arrows to move among chunks). Please note that in chunk mode, all the operations (https://www.kitploit.com/search/label/Operations) (e.g. search) applies only to the current chunk except for file save (the entire file is saved). However, each time you edit a chunk, save it before to move to another chunk, otherwise you will lose your changes.Search and replace (UTF-8, HEX, regex, reverse search supported) [CTRL + F]Colored output (white spaces, ASCII characters, 0xFF, UTF-8 and NULL bytes have different colors)Interpret selected bytes as integer, long, unsigned long [CTRL + B]Copy & Paste [CTRL + C and CTRL + V]Copy selected unicode characters [CTRL + Space]Zeroing all the selected bytes [Delete or CTRL + D]Undo & Redo [CTRL + Z and CTRL + Y]Drag & Drop (Hint: Drag&Drop two files to diff them)Overwrite the same file or create a new one [CTRL + S]Goto offset [CTRL + G]Insert mode supported in order to insert new bytes instead to overwrite the existing one [INS]Create new instances [CTRL + N]Basic text viewer for the selected text [CTRL + T]Reload the current file [F5]Compare two different files at byte levelBrowsable Binary Chart (see later for details) [F1]Hex - Dec number converter (https://www.kitploit.com/search/label/Converter) [F2]Hex String escaper (e.g from 010203 to \x01\x02\x03) [F3]Pattern Matching Engine (see later for details)Disassebler based on Capstone Engine (https://www.kitploit.com/search/label/Capstone%20Engine) [F4]Assembler based on Keystone Engine (https://www.kitploit.com/search/label/Keystone%20Engine) [F4]Zoom-Out/Zoom-In bytes view (CTRL + Up/Down or CTRL + -/+)Shortcuts for all these features
Pattern Matching Engine
Fhex can load at startup a configuration file (from ~/fhex/config.json) in JSON format with a list of strings or bytes to highlight and a comment/label to add close to the matches.Examples:{
"PatternMatching":
[
{
"string" : "://www.",
"color" : "rgba(250,200,200,50)",
"message" : "Found url"
},
{
"bytes" : "414243",
"color" : "rgba(250,200,200,50)",
"message" : "Found ABC"
}
]
}To activate pattern matching (https://www.kitploit.com/search/label/Pattern%20Matching) press CTRL + PAt the end, Fhex will show also an offset list with all the result references. Note: Labels with comments are added only if the window is maximized, if labels are not displayed correctly please try to run pattern matching again.
Binary Chart
Fhex has the feature to chart the loaded binary file (Note: In order to compile the project, now you need also qt5-charts installed on the system). The y-axis range is between 0 and 255 (in hex 0x0 and 0xff, i.e. the byte values). The x-axis range is between 0 and the filesize.The chart plots the byte values of the binary file and let you focus only on the relevant sections. For example, if in a binary file there is an area full of null bytes, you can easily detect it from the chart.
License
GPL-3

Download Fhex (https://github.com/echo-devim/fhex)