Hey all,Continue reading on Medium » (https://itsdeepceh.medium.com/a-business-logic-error-bug-worth-600-a0050720bfee?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Windows zero-day with public exploit lets you become an admin
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New Windows zero-day with public exploit lets you become an adminPost Views: 404
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/BF-1.gif
Reading Time: 1 Minute
A security researcher has publicly disclosed an exploit for a new Windows zero-day local privilege elevation vulnerability that gives admin privileges in Windows 10, Windows 11, and Windows Server.
BleepingComputer has tested the exploit and used it to open to command prompt with SYSTEM privileges from an account with only low-level ‘Standard’ privileges.
Using this vulnerability, threat actors with limited access to a compromised device can easily elevate their privileges to help spread laterally within the network.
The vulnerability affects all supported versions of Windows, including Windows 10, Windows 11, and Windows Server 2022. Researcher releases bypass to patched vulnerabilityAs part of the November 2021 Patch Tuesday, Microsoft fixed a ‘Windows Installer Elevation of Privilege Vulnerability’ vulnerability tracked as CVE-2021-41379.
This vulnerability was discovered by security researcher Abdelhamid Naceri, who found a bypass to the patch and a more powerful new zero-day privilege elevation vulnerability after examining Microsoft’s fix.
Yesterday, Naceri published a working proof-of-concept exploit for the new zero-day on GitHub, explaining that it works on all supported versions of Windows.
“This variant was discovered during the analysis of CVE-2021-41379 patch. the bug was not fixed correctly, however, instead of dropping the bypass,” explains Naceri in his writeup. “I have chosen to actually drop this variant as it is more powerful than the original one.”
See Also: Complete Offensive Security and Ethical Hacking Course
Furthermore, Naceri explained that while it is possible to configure group policies to prevent ‘Standard’ users from performing MSI installer operations, his zero-day bypasses this policy and will work anyway.
BleepingComputer tested Naceri’s ‘InstallerFileTakeOver’ exploit, and it only took a few seconds to gain SYSTEM privileges from a test account with ‘Standard’ privileges, as demonstrated in the video below.
The test was performed on a fully up-to-date Windows 10 21H1 build 19043.1348 install.
When BleepingComputer asked Naceri why he publicly disclosed the zero-day vulnerability, we were told he did it out of frustration over Microsoft’s decreasing payouts in their bug bounty program.
“Microsoft bounties has been trashed since April 2020, I really wouldn’t do that if MSFT didn’t take the decision to downgrade those bounties,” explained Naceri.
See Also: Microsoft Exchange servers hacked in internal reply-chain attacks Under Microsoft's new bug bounty program one of my zerodays has gone from being worth $10,000 to $1,000 💀
— MalwareTech (@MalwareTechBlog) July 27, 2020
BE CAREFUL! Microsoft will reduce your bounty at any time! This is a Hyper-V RCE vulnerability be able to trigger from a Guest Machine, but it is just eligible for a $5000.00 bounty award under the Windows Insider Preview Bounty Program. Unfair! @msftsecresponse @msftsecurity pic.twitter.com/sJw3cjsliF
— rthhh (@rthhh17) November 9, 2021
BleepingComputer has reached out to Microsoft about the disclosed zero-day and will update the article if we receive a reply.
As is typical with zero days, Microsoft will likely fix the vulnerability in a future Patch Tuesday update.
See Also: Offensive Security Tools: Awesome Bug Bounty Tools However, Naceri warned that it i[...]
New Windows zero-day with public exploit lets you become an admin
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New Windows zero-day with public exploit lets you become an adminPost Views: 404
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/BF-1.gif
Reading Time: 1 Minute
A security researcher has publicly disclosed an exploit for a new Windows zero-day local privilege elevation vulnerability that gives admin privileges in Windows 10, Windows 11, and Windows Server.
BleepingComputer has tested the exploit and used it to open to command prompt with SYSTEM privileges from an account with only low-level ‘Standard’ privileges.
Using this vulnerability, threat actors with limited access to a compromised device can easily elevate their privileges to help spread laterally within the network.
The vulnerability affects all supported versions of Windows, including Windows 10, Windows 11, and Windows Server 2022. Researcher releases bypass to patched vulnerabilityAs part of the November 2021 Patch Tuesday, Microsoft fixed a ‘Windows Installer Elevation of Privilege Vulnerability’ vulnerability tracked as CVE-2021-41379.
This vulnerability was discovered by security researcher Abdelhamid Naceri, who found a bypass to the patch and a more powerful new zero-day privilege elevation vulnerability after examining Microsoft’s fix.
Yesterday, Naceri published a working proof-of-concept exploit for the new zero-day on GitHub, explaining that it works on all supported versions of Windows.
“This variant was discovered during the analysis of CVE-2021-41379 patch. the bug was not fixed correctly, however, instead of dropping the bypass,” explains Naceri in his writeup. “I have chosen to actually drop this variant as it is more powerful than the original one.”
See Also: Complete Offensive Security and Ethical Hacking Course
Furthermore, Naceri explained that while it is possible to configure group policies to prevent ‘Standard’ users from performing MSI installer operations, his zero-day bypasses this policy and will work anyway.
BleepingComputer tested Naceri’s ‘InstallerFileTakeOver’ exploit, and it only took a few seconds to gain SYSTEM privileges from a test account with ‘Standard’ privileges, as demonstrated in the video below.
The test was performed on a fully up-to-date Windows 10 21H1 build 19043.1348 install.
When BleepingComputer asked Naceri why he publicly disclosed the zero-day vulnerability, we were told he did it out of frustration over Microsoft’s decreasing payouts in their bug bounty program.
“Microsoft bounties has been trashed since April 2020, I really wouldn’t do that if MSFT didn’t take the decision to downgrade those bounties,” explained Naceri.
See Also: Microsoft Exchange servers hacked in internal reply-chain attacks Under Microsoft's new bug bounty program one of my zerodays has gone from being worth $10,000 to $1,000 💀
— MalwareTech (@MalwareTechBlog) July 27, 2020
BE CAREFUL! Microsoft will reduce your bounty at any time! This is a Hyper-V RCE vulnerability be able to trigger from a Guest Machine, but it is just eligible for a $5000.00 bounty award under the Windows Insider Preview Bounty Program. Unfair! @msftsecresponse @msftsecurity pic.twitter.com/sJw3cjsliF
— rthhh (@rthhh17) November 9, 2021
BleepingComputer has reached out to Microsoft about the disclosed zero-day and will update the article if we receive a reply.
As is typical with zero days, Microsoft will likely fix the vulnerability in a future Patch Tuesday update.
See Also: Offensive Security Tools: Awesome Bug Bounty Tools However, Naceri warned that it i[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New Windows zero-day with public exploit lets you become an admin https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New Windows zero-day with public exploit lets you become an adminPost Views:…
s not advised to try and fix the vulnerability by attempting to patch the binary as it will likely break the installer.
“The best workaround available at the time of writing this is to wait Microsoft to release a security patch, due to the complexity of this vulnerability,” explained Naceri.
“Any attempt to patch the binary directly will break windows installer. So you better wait and see how Microsoft will screw the patch again.”
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers hacked in internal reply-chain attacks1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/slembunk-android-banking-trojan-targets-31-banks-across-the-world-497808-3-90x90.jpg Android malware BrazKing returns as a stealthier banking trojan4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/redcurl-90x90.jpg RedCurl corporate espionage hackers resume attacks with updated tools5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-1-90x90.jpg WordPress sites are being hacked in fake ransomware attacks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ECS-Instance-Types-90x90.png Alibaba ECS instances actively hijacked by cryptomining malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-90x90.jpg QBot returns for a new wave of infections using Squirrelwaffle1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/face-malware-virus-infected-red-network-90x90.jpg BotenaGo botnet targets millions of IoT devices with 33 exploits2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers2 weeks ago
The post New Windows zero-day with public exploit lets you become an admin first appeared on Black Hat Ethical Hacking.
“The best workaround available at the time of writing this is to wait Microsoft to release a security patch, due to the complexity of this vulnerability,” explained Naceri.
“Any attempt to patch the binary directly will break windows installer. So you better wait and see how Microsoft will screw the patch again.”
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers hacked in internal reply-chain attacks1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/slembunk-android-banking-trojan-targets-31-banks-across-the-world-497808-3-90x90.jpg Android malware BrazKing returns as a stealthier banking trojan4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/redcurl-90x90.jpg RedCurl corporate espionage hackers resume attacks with updated tools5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-1-90x90.jpg WordPress sites are being hacked in fake ransomware attacks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ECS-Instance-Types-90x90.png Alibaba ECS instances actively hijacked by cryptomining malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-90x90.jpg QBot returns for a new wave of infections using Squirrelwaffle1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/face-malware-virus-infected-red-network-90x90.jpg BotenaGo botnet targets millions of IoT devices with 33 exploits2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers2 weeks ago
The post New Windows zero-day with public exploit lets you become an admin first appeared on Black Hat Ethical Hacking.
UDP-Hunter - Network Assessment Tool For Various UDP Services Covering Both IPv4 And IPv6 Protocols
http://www.kitploit.com/2021/11/udp-hunter-network-assessment-tool-for.html
http://www.kitploit.com/2021/11/udp-hunter-network-assessment-tool-for.html
UDP Hunter creates a list of IPs when any IP range is provided to it. It also supports domain names which will be resolved and the IP will be added to the list. Once the list has been created internally by UDP Hunter, it will send UDP probes to all listed IPs. If the host is running a UDP service, it will respond. UDP Hunter basically sniffs network particularly for UDP traffic, then reads all UDP packets coming to the target host. All UDP probes received after running UDP Hunter will be reported. However, there is an option (by setting --noise=false) to ignore irrelevant UDP packets and only observe the UDP traffic of interest originated from the hosts and services/ports which are mentioned in the target list. The idea behind creating UDP Hunter was initially inspired by udp-proto-scanner. I heartily thank Portcullis Labs for it and also Anant and Sumit Siddharth(Sid) for their valuable inputs while working on UDP Hunter.
Supported UDP Probes:
As of today, we support the following UDP service probes on their default ports:ike - 500 portrpc / RPCCheck - 111 portntp / NTPRequest - 123 portsnmp-public / SNMPv3GetRequest - 161 portms-sql / ms-sql-slam - 1434 portnetop - 6502 porttftp - 69 portdb2 - 523 portcitrix - 1604 portecho - 7 portchargen - 19 portsystat - 11 portdaytime / time - 13 portDNSStatusRequest / DNSVersionBindReq - 53 portNBTStat - 137 portxdmcp - 177 portnet-support - 5405 portmdns-zeroconf - 5353 portgtpv1 - 2123 port
Setup:
Download the tool from here (https://github.com/NotSoSecure/udp-hunter) or Clone the repository:
git clone https://github.com/NotSoSecure/udp-hunter
Requirements:
Python 3.xPython Modules - also mentioned in “requirements.txt” file netaddrcoloramaargparseifaddrdatetime
This should help you with the initial setup:
Install all required modules: pip3 install -r requirements.txt
Configuration files required:
udp.txt - This file contains UDP probesudphelp.txt - This file contains list of tools, suggestions for each UDP probes or services
You can also change configuration files by using command line (https://www.kitploit.com/search/label/Command%20Line) argument:
“--configfile ” and “--probehelp ”
Verify the configurations by running following command:
python udp-hunter.pyNote: It should display following help details, if this throws any error check your configurations or connect with me for any tool specific errors.
Features / Options:
UDP Hunter v0.1beta has the following features:
Mandatory Options:
--host - Single Host - Required or--file - File of ips - Required
Optional:
--output - Output file - Required--probes - Name of probe or 'all' (default: all probes) (Optional) Probe list - ike, rpc, ntp, snmp-public, ms-sql, ms-sql-slam, netop, tftp, db2, citrix, echo, chargen, systat, daytime, time, RPCCheck, DNSStatusRequest, DNSVersionBindReq, NBTStat, NTPRequest, SNMPv3GetRequest, xdmcp, net-support, mdns-zeroconf, gtpv1--ports - List of ports or 'all' (default: all ports) (Optional)--retries - Number of packets to send to each host. Default 2 (Optional)--noise - To filter output from non-listed IPs (Optional)--verbose - verbosity, will show sniffer output also --- please keep this a true, by default this is true. This will help us to analyze output.--timeout - Timeout 1.0, 2.0 in minutes (Optional)--lhost6 - Provide IPv6 of listner interface--lhost4 - Provide IPv4 of listner interface--configfile - Configuration file location - default is 'udp.txt' in same directory--probehelp - Help file location - default is 'udphelp.txt' in same directory
Usage:
Usage: python udp-hunter.py --file=inputfile.txt --output=outputfile.txt [optional arguments] Usage: python udp-hunter.py --file=inputfile.txt --output=outputfile.txt [--probes=NTPRequest,SNMPv3GetReques] [--ports=123,161,53] [--retries=3] [--noise=true] [--verbose=false] [--timeout=1.0] [--configfile]
Credits:
Supported UDP Probes:
As of today, we support the following UDP service probes on their default ports:ike - 500 portrpc / RPCCheck - 111 portntp / NTPRequest - 123 portsnmp-public / SNMPv3GetRequest - 161 portms-sql / ms-sql-slam - 1434 portnetop - 6502 porttftp - 69 portdb2 - 523 portcitrix - 1604 portecho - 7 portchargen - 19 portsystat - 11 portdaytime / time - 13 portDNSStatusRequest / DNSVersionBindReq - 53 portNBTStat - 137 portxdmcp - 177 portnet-support - 5405 portmdns-zeroconf - 5353 portgtpv1 - 2123 port
Setup:
Download the tool from here (https://github.com/NotSoSecure/udp-hunter) or Clone the repository:
git clone https://github.com/NotSoSecure/udp-hunter
Requirements:
Python 3.xPython Modules - also mentioned in “requirements.txt” file netaddrcoloramaargparseifaddrdatetime
This should help you with the initial setup:
Install all required modules: pip3 install -r requirements.txt
Configuration files required:
udp.txt - This file contains UDP probesudphelp.txt - This file contains list of tools, suggestions for each UDP probes or services
You can also change configuration files by using command line (https://www.kitploit.com/search/label/Command%20Line) argument:
“--configfile ” and “--probehelp ”
Verify the configurations by running following command:
python udp-hunter.pyNote: It should display following help details, if this throws any error check your configurations or connect with me for any tool specific errors.
Features / Options:
UDP Hunter v0.1beta has the following features:
Mandatory Options:
--host - Single Host - Required or--file - File of ips - Required
Optional:
--output - Output file - Required--probes - Name of probe or 'all' (default: all probes) (Optional) Probe list - ike, rpc, ntp, snmp-public, ms-sql, ms-sql-slam, netop, tftp, db2, citrix, echo, chargen, systat, daytime, time, RPCCheck, DNSStatusRequest, DNSVersionBindReq, NBTStat, NTPRequest, SNMPv3GetRequest, xdmcp, net-support, mdns-zeroconf, gtpv1--ports - List of ports or 'all' (default: all ports) (Optional)--retries - Number of packets to send to each host. Default 2 (Optional)--noise - To filter output from non-listed IPs (Optional)--verbose - verbosity, will show sniffer output also --- please keep this a true, by default this is true. This will help us to analyze output.--timeout - Timeout 1.0, 2.0 in minutes (Optional)--lhost6 - Provide IPv6 of listner interface--lhost4 - Provide IPv4 of listner interface--configfile - Configuration file location - default is 'udp.txt' in same directory--probehelp - Help file location - default is 'udphelp.txt' in same directory
Usage:
Usage: python udp-hunter.py --file=inputfile.txt --output=outputfile.txt [optional arguments] Usage: python udp-hunter.py --file=inputfile.txt --output=outputfile.txt [--probes=NTPRequest,SNMPv3GetReques] [--ports=123,161,53] [--retries=3] [--noise=true] [--verbose=false] [--timeout=1.0] [--configfile]
Credits:
The UDP probes are mainly taken from amap (https://github.com/vanhauser-thc/THC-Archive/tree/master/Tools), ike-scan (https://github.com/royhills/ike-scan), nmap (https://nmap.org/book/scan-methods-udp-scan.html) and udp-proto-scanner (https://github.com/portcullislabs/udp-proto-scanner). Inspiration for the scanning code was drawn from udp-proto-scanner (https://github.com/portcullislabs/udp-proto-scanner).
Future Work:
Addition of more UDP probesDifferent reporting (https://www.kitploit.com/search/label/Reporting) formatsUpdate exploitation-related helps
Read More:
UDP Hunter - An Open Source Network Assessment Tool (https://www.gadhiyasavan.com/2020/02/udp-hunter.html)Setup Steps for UDP Hunter (https://asciinema.org/a/305052)Sample Execution of UDP Hunter (https://asciinema.org/a/305053)
Download Udp-Hunter (https://github.com/NotSoSecure/udp-hunter)
Future Work:
Addition of more UDP probesDifferent reporting (https://www.kitploit.com/search/label/Reporting) formatsUpdate exploitation-related helps
Read More:
UDP Hunter - An Open Source Network Assessment Tool (https://www.gadhiyasavan.com/2020/02/udp-hunter.html)Setup Steps for UDP Hunter (https://asciinema.org/a/305052)Sample Execution of UDP Hunter (https://asciinema.org/a/305053)
Download Udp-Hunter (https://github.com/NotSoSecure/udp-hunter)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HTB — Legacy — Walkthrough without Metasploit
https://cdn-images-1.medium.com/max/699/1*X5q4vJtNhR0ACkZeUgfa2g.png
Legacy is a retired Windows machine on Hack The Box. This walkthrough will guide you through the steps of how to get root without the use…
Continue reading on Medium »
HTB — Legacy — Walkthrough without Metasploit
https://cdn-images-1.medium.com/max/699/1*X5q4vJtNhR0ACkZeUgfa2g.png
Legacy is a retired Windows machine on Hack The Box. This walkthrough will guide you through the steps of how to get root without the use…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Certified White Hat Hacker™
Certified White Hat Hacker is a specially designed training and certification course by Global Tech Council. Demand for ethical hackers is…
Continue reading on Medium »
Certified White Hat Hacker™
Certified White Hat Hacker is a specially designed training and certification course by Global Tech Council. Demand for ethical hackers is…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My First Pre-Auth Account Takeover in 20 secs
https://cdn-images-1.medium.com/max/820/1*uwzTIiw1la6qBcsqCP265A.jpeg
Hello All, this is my first account takeover writeup and I hope it helps everyone. Taking over another user’s account is something that…
Continue reading on Medium »
My First Pre-Auth Account Takeover in 20 secs
https://cdn-images-1.medium.com/max/820/1*uwzTIiw1la6qBcsqCP265A.jpeg
Hello All, this is my first account takeover writeup and I hope it helps everyone. Taking over another user’s account is something that…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Multi-industry ransomware survey. The results provide a better understanding of lesser-known aspects of the current ransomware epidemic.
https://external-preview.redd.it/cjur5c57HHSB8yt_KJAK9fUbdkf6dwg2KbxQ2QQz_KM.jpg?width=640&crop=smart&auto=webp&s=42a2637675c66687ce7bf79b9dfd68625143d608 submitted by /u/oxowewry
[link] [comments]
Multi-industry ransomware survey. The results provide a better understanding of lesser-known aspects of the current ransomware epidemic.
https://external-preview.redd.it/cjur5c57HHSB8yt_KJAK9fUbdkf6dwg2KbxQ2QQz_KM.jpg?width=640&crop=smart&auto=webp&s=42a2637675c66687ce7bf79b9dfd68625143d608 submitted by /u/oxowewry
[link] [comments]