Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
VICIdial 2.14 Multiple Vulnerabilities

https://cdn-images-1.medium.com/max/2600/1*SVAWZ4BZ9pMxQZSYO3HMtw.png
So I was watching one of my favorite Youtube channels the other day when one screen caught my attention. It was a campaign summary page of…

Continue reading on Medium »
Kube-Applier - Enables Automated Deployment And Declarative Configuration For Your Kubernetes Cluster
http://www.kitploit.com/2021/11/kube-applier-enables-automated.html
Setup
Download the source code and build the container image.$ go get github.com/box/kube-applier
$ cd $GOPATH/src/github.com/box/kube-applier
$ make container
You will need to push the image to a registry in order to reference it in a Kubernetes container spec.
Usage

Container Spec
We suggest running kube-applier as a Deployment (see demo/ (https://github.com/box/kube-applier/tree/master/demo) for example YAML files). We only support running one replica at a time at this point, so there may be a gap in application if the node serving the replica goes hard down until it is rescheduled onto another node.IMPORTANT: The Pod containing the kube-applier container must be spawned in a namespace that has write permissions on all namespaces in the API Server (e.g. kube-system).
Environment Variables
Required:REPO_PATH - (string) Absolute path to the directory containing configuration files to be applied. It must be a Git repository or a path within one. All .json and .yaml files within this directory (and its subdirectories) will be applied, unless listed on the blacklist or excluded from the whitelist.LISTEN_PORT - (int) Port for the container. This should be the same port specified in the container spec.Optional:SERVER - (string) Address of the Kubernetes API server. By default, discovery of the API server is handled by kube-proxy. If kube-proxy is not set up, the API server address must be specified with this environment variable (which is then written into a kubeconfig file (http://kubernetes.io/docs/user-guide/kubeconfig-file/) on the backend). Authentication (https://www.kitploit.com/search/label/Authentication) to the API server is handled by service account tokens. See Accessing the Cluster (http://kubernetes.io/docs/user-guide/accessing-the-cluster/#accessing-the-api-from-a-pod) for more info.BLACKLIST_PATH - (string) Path to a "blacklist" file which specifies files that should not be applied. This path should be absolute (e.g. /k8s/conf/kube_applier_blacklist), not relative to REPO_PATH (although you may want to check the blacklist file into the repo). The blacklist file itself should be a plaintext file, with a file path on each line. Each of these paths should be relative to REPO_PATH (for example, if REPO_PATH is set to /git/repo, and the file to be blacklisted is /git/repo/apps/app1.json, the line in the blacklist file should be apps/app1.json).WHITELIST_PATH - (string) Path to a "whitelist" file which is used to make the applier consider a specific subset of files from the repo. Only the files listed in the whitelist file will be considered for apply. Empty whitelist (or unset env var) means all files in repo are eligible to be applied. In case of a file is listed in both the whitelist and the blacklist, the file is not applied. The environment variable and file itself should formatted the same as for the blacklist above.NOTEThe blacklist and whitelist files support line comments. A single line gets ignored if the first non-blank character is # in that line.POLL_INTERVAL_SECONDS - (int) Number of seconds to wait between each check for new commits to the repo (default is 5). Set to 0 to disable the wait period.FULL_RUN_INTERVAL_SECONDS - (int) Number of seconds between automatic full runs (default is 300, or 5 minutes). Set to 0 to disable the wait period.DIFF_URL_FORMAT - (string) If specified, allows the status page to display a link to the source code referencing the diff for a specific commit. DIFF_URL_FORMAT should be a URL for a hosted remote repo that supports linking to a commit hash. Replace the commit hash portion with "%s" so it can be filled in by kube-applier (e.g. https://github.com/kubernetes/kubernetes/commit/%s).LOG_LEVEL - (int) Sets the -v flag on all kubectl commands run. Use this option to configure more verbose logging. If not specified, the -v flag is not set on kubectl commands defaulting to standard log verbosity.
Mounting the Git Repository
There are two ways to mount the Git repository into the kube-applier container.1. Git-sync sidecar containerGit-sync keeps a local directory up to date with a remote repo. The local directory resides in a shared emptyDir volume that is mounted in both the git-sync and kube-applier containers.Reference the git-sync (https://github.com/kubernetes/git-sync) repo for setup and usage.2. Host-mounted volumeMount a Git repository from a host directory. This can be useful when you want kube-applier to apply changes to an object without checking the modified spec file into a remote repo. }, "name": "repo-volume" } ... ] '>"volumes": [
{
"hostPath": {
"path":
},
"name": "repo-volume"
}
...
]
What happens if the contents of the local Git repo change in the middle of a kube-applier run?If there are changes to files in the $REPO_PATH directory during a kube-applier run, those changes may or may not be reflected in that run, depending on the timing of the changes.Given that the $REPO_PATH directory is a Git repo or located within one, it is likely that the majority of changes will be associated with a Git commit. Thus, a change in the middle of a run will likely update the HEAD commit hash, which will immediately trigger another run upon completion of the current run (regardless of whether or not any of the changes were effective in the current run). However, changes that are not associated with a new Git commit will not trigger a run.If I remove a configuration file, will kube-applier remove the associated Kubernetes object?No. If a file is removed from the $REPO_PATH directory, kube-applier will no longer apply the file, but kube-applier WILL NOT delete the cluster object(s) described by the file. These objects must be manually cleaned up using kubectl delete.
"Force Run" Feature
In rare cases, you may wish to trigger a kube-applier run without checking in a commit or waiting for the next scheduled run (e.g. some of your files failed to apply because of some background condition in the cluster, and you have fixed it since the last run). This can be accomplished with the "Force Run" button on the status page, which starts a run immediately if no run is currently in progress, or queues a run to start upon completion of the current run. Only one run may sit in the queue at any given time.
Monitoring

Status UI
kube-applier hosts a status page on a webserver, served at the service endpoint URL. The status page displays information about the most recent apply run, including:Run TypeStart and end timesLatencyMost recent commitWhitelisted filesBlacklisted filesErrorsFiles applied successfullyThe HTML template for the status page lives in templates/status.html, and static/ holds additional assets.
Metrics
kube-applier uses Prometheus (https://github.com/prometheus/client_golang) for metrics. Metrics are hosted on the webserver at /metrics (status UI is the index page). In addition to the Prometheus default metrics, the following custom metrics are included:run_latency_seconds - A Summary (https://godoc.org/github.com/prometheus/client_golang/prometheus#Summary) that keeps track of the durations of each apply run, tagged with the run type and a boolean for whether or not the run was a success (i.e. no failed apply attempts).file_apply_count - A Counter (https://godoc.org/github.com/prometheus/client_golang/prometheus#Counter) for each file that has had an apply attempt over the lifetime of the container, incremented with each apply attempt and tagged by the filepath and the result of the attempt.The Prometheus HTTP API (https://prometheus.io/docs/querying/api/) (also see the Go library (https://github.com/prometheus/client_golang/tree/master/api/prometheus)) can be used for querying the metrics server.
Development
All contributions are welcome to this project. Please review our contributing guidelines (https://github.com/box/kube-applier/blob/master/CONTRIBUTING.md).Some suggestions for running kube-applier locally for development:To reach kube-applier's webserver from your browser, you can use an apiserver proxy URL (https://kubernetes.io/docs/concepts/cluster-administration/access-cluster/#manually-constructing-apiserver-proxy-urls).Although git-sync is recommended for live environments, using a host-mounted volume (https://github.com/box/kube-applier#mounting-the-git-repository) can simplify basic local usage of kube-applier.
Testing
See our contributing guidelines (https://github.com/box/kube-applier/blob/master/CONTRIBUTING.md#step-7-run-the-tests).
Support
Need to contact us directly? Email oss@box.com (mailto:oss@box.com) and be sure to include the name of this project in the subject.
Copyright and License
Copyright 2016 Box, Inc. All rights reserved.Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance (https://www.kitploit.com/search/label/Compliance) with the License. You may obtain a copy of the License athttp://www.apache.org/licenses/LICENSE-2.0Unless required by applicable law or agreed to in writing, software distributed under the License is distributed (https://www.kitploit.com/search/label/Distributed) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Download Kube-Applier (https://github.com/box/kube-applier)
hacking: security in practice
Looking for educational materials about Wifite /handshake capture

Hi all, I’ve used Wifite2 to successfully capture my AP handshake and than I successfully cracked the hash. It got me wondering how does Wifite work, and how handshakes work. I found a lot of material about handshakes but i still don’t understand how does Wifite get a hash of the wifi password from the handshakes, since it doesn’t (to my understanding?) pass through the net? ( i only saw Anonce,Snonce and GTK)

Can anybody explain to me how does this attack work? Or to point me toward relevant educational material?

submitted by /u/guykehat
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
RedCurl corporate espionage hackers resume attacks with updated tools

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png RedCurl corporate espionage hackers resume attacks with updated toolsPost Views: 115
Reading Time: 1 Minute
A crew of highly-skilled hackers specialized in corporate espionage has resumed activity, one of their victims this year being a large wholesale company in Russia.
Tracked as RedCurl, the group attacked the Russian business twice this year, each time using carefully constructed spear-phishing emails with initial-stage malware. Increasing the victim countActive since 2018, RedCurl is responsible for at least 30 attacks against businesses in Russia (18 of them), Ukraine, Canada, Norway, the UK, and Germany, the latest four of them occurring this year.
https://www.bleepstatic.com/images/news/u/1100723/2021/RedCurlVicCount.jpg
The hackers are proficient at staying undetected for long periods, between two and six months, before stealing corporate data (staff records, documents about legal entities, court records, internal files, email history).
See Also: Complete Offensive Security and Ethical Hacking Course Hitting the same company twiceResearchers at cybersecurity company Group-IB noticed a seven-month gap in RedCurl’s activity, which the hackers used to add significant improvements to their set of custom tools and attack methods.

Among the hacker’s latest victims is one of Russia’s largest wholesale companies, which supplies chain stores and other wholesalers with home, office, and leisure goods.

For reasons that remain unknown, RedCurl attacked this company twice, gaining initial access via emails impersonating the company’s human resources department announcing bonuses and the government services portal.
https://www.bleepstatic.com/images/news/u/1100723/2021/RedCurlEmails.jpg
In both cases, the goal was to deploy on the employee’s computer a malware downloader (RedCurl.InitialDropper) hidden in an attached document that could launch the next stage of the attack.

During the investigation, Group-IB found that the RedCurl extended the attack chain to five stages, from the previously observed three or four steps.
See Also: WordPress sites are being hacked in fake ransomware attacks
https://www.bleepstatic.com/images/news/u/1100723/2021/TypicalRedCurlKillChain.jpg
The hackers were careful not to raise any suspicion when the recipient opened the malicious document that launched the initial dropper, so they included a well-crafted decoy file with content related to the organization.

The dropper would fetch the RedCurl.Downloader tool, which collected info about the infected machine and delivered it to a command and control server (C2), and also initiated the next stage of the attack. Updated toolsetGroup-IB discovered that the hackers now used RedCurl.Extractor, a modified version of the RedCurl.Dropper they found in previous attacks from this threat actor.

The purpose of this tool was only to prepare the final step of the attack, which involved achieving persistence on the system.

The researchers note that RedCurl has shifted from the typical use of batch and PowerShell scripts to executable files and that antivirus software failed to detect the initial infection or the attacker moving laterally on the victim network.

However, the improvements to RedCurl’s toolset appear to have been rushed, as Group-IB discovered a logical error in one of the commands. One explanation is that the group had little time to start the attack and could not properly test their tools.
See Also: Offensive Security Tool: Pentesting Tools Group-IB[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking RedCurl corporate espionage hackers resume attacks with updated tools https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png RedCurl corporate espionage hackers resume attacks with updated toolsPost…
has published a report today with indicators of compromise and technical information on RedCurl’s updated set of tools and their functionality:


* RedCurl.InitialDropper: LNK file used in the initial infection stage, downloads batch or PowerShell scripts from the C2 that get malware for the next step
* RedCurl.Downloader (new tool): intermediary stage downloader that collects data about the infected system, downloads and deploys malware for the next stage
* RedCurl.Extractor: DLL file equivalent to RedCurl.Dropper, extracts the legitimate 7-Zip utility, downloads and installs the next stage malware
* RedCurl.FSABIN: binary equivalent of the old RedCurl.FirstStageAgent, gets commands from hacker-controlled HTTP servers
* RedCurl.CHABIN1: a fork of FSABIN
* RedCurl.CHABIN2: similar to CHABIN1, determines the proxy server settings to connect the infected system to servers controlled by the hackers

Despite not being as active as in other years, RedCurl maintains its sophistication and remains an advanced threat actor capable to stay undetected for months.
Group-IB says that of the four attacks identified this year, two were against the same target. However, they expect more victims to appear since RedCurl’s updated tools have been detected in the wild with increased frequency.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-1-90x90.jpg WordPress sites are being hacked in fake ransomware attacks1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ECS-Instance-Types-90x90.png Alibaba ECS instances actively hijacked by cryptomining malware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-90x90.jpg QBot returns for a new wave of infections using Squirrelwaffle3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/face-malware-virus-infected-red-network-90x90.jpg BotenaGo botnet targets millions of IoT devices with 33 exploits6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Pwn2OwnBlur-90x90.png Pwn2Own – Over 1 million dollars in Bounties, Samsung Galaxy S21 hacked twice, Printer plays AC/DC1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/maxresdefault-1024x576-1-90x90.jpg Microsoft Exchange ProxyShell exploits used to deploy Babuk ransomware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Mekotio-Banking-Trojan-90x90.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign2 weeks ago
The post RedCurl corporate espionage hackers resume attacks with updated tools first appeared on Black Hat Ethical Hacking.
HUMAN community newsletter #3

HighlightsContinue reading on HUMAN Protocol »
Read more...