Account Takeover in $Million Company? Report Rejected? Whats wrong???
Hi, I am GodsonContinue reading on Medium »
Read more...
Hi, I am GodsonContinue reading on Medium »
Read more...
Account Takeover in $Million Company? Report Rejected? Whats wrong???
https://0xgodson.medium.com/account-takeover-in-million-company-report-rejected-whats-wrong-60041f1815fb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xgodson.medium.com/account-takeover-in-million-company-report-rejected-whats-wrong-60041f1815fb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Account Takeover in $Million Company?
Hi, I am Godson
Hi, I am GodsonContinue reading on Medium » (https://0xgodson.medium.com/account-takeover-in-million-company-report-rejected-whats-wrong-60041f1815fb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Account Takeover in $Million Company?
Hi, I am Godson
How I Found My First XSS Bug
https://medium.com/@thedarkwayg/how-i-found-my-first-xss-bug-96fb8e85a24c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@thedarkwayg/how-i-found-my-first-xss-bug-96fb8e85a24c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found My First XSS Bug
Hi everyone,
Hi everyone,Continue reading on Medium » (https://medium.com/@thedarkwayg/how-i-found-my-first-xss-bug-96fb8e85a24c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found My First XSS Bug
Hi everyone,
Wireless security assessments
https://www.reddit.com/r/Pentesting/comments/r12bvv/wireless_security_assessments/
I am looking for a framework like ASVS from OWASP that covers wireless security assessments. Anyone know of such a thing? Or checklists and maybe a lists of tools in use for these types of assessments. I have been doing ASVS assessments for years but want to start offering my clients the same level of assessment for wireless engagements. submitted by /u/73ninjas (https://www.reddit.com/user/73ninjas)
[link] (https://www.reddit.com/r/Pentesting/comments/r12bvv/wireless_security_assessments/) [comments] (https://www.reddit.com/r/Pentesting/comments/r12bvv/wireless_security_assessments/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/r12bvv/wireless_security_assessments/
I am looking for a framework like ASVS from OWASP that covers wireless security assessments. Anyone know of such a thing? Or checklists and maybe a lists of tools in use for these types of assessments. I have been doing ASVS assessments for years but want to start offering my clients the same level of assessment for wireless engagements. submitted by /u/73ninjas (https://www.reddit.com/user/73ninjas)
[link] (https://www.reddit.com/r/Pentesting/comments/r12bvv/wireless_security_assessments/) [comments] (https://www.reddit.com/r/Pentesting/comments/r12bvv/wireless_security_assessments/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Wireless security assessments
I am looking for a framework like ASVS from OWASP that covers wireless security assessments. Anyone know of such a thing? Or checklists and maybe...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Fixing 0x0 00x0 Error Codes
https://cdn-images-1.medium.com/max/800/1*-IDTxUArvtZ6aQTded_-Tg.jpeg
If you have received an error message with the code ‘0x0 00x0’ on your computer, you may need to repair your PC.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Fixing 0x0 00x0 Error Codes
https://cdn-images-1.medium.com/max/800/1*-IDTxUArvtZ6aQTded_-Tg.jpeg
If you have received an error message with the code ‘0x0 00x0’ on your computer, you may need to repair your PC.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fixing 0x0 00x0 Error Codes
If you have received an error message with the code ‘0x0 00x0’ on your computer, you may need to repair your PC. While the problem might be…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TCAPT: DLL Hijacking
https://cdn-images-1.medium.com/max/1390/1*o0zq24LmGKC5X-L0HqSGbg.jpeg
Hello Hackmates, I’ve been learning about Thick Client Application Penetration Testing and recently, came up with the topic: DLL Hijacking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TCAPT: DLL Hijacking
https://cdn-images-1.medium.com/max/1390/1*o0zq24LmGKC5X-L0HqSGbg.jpeg
Hello Hackmates, I’ve been learning about Thick Client Application Penetration Testing and recently, came up with the topic: DLL Hijacking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TCAPT: DLL Hijacking
Hello Hackmates, I’ve been learning about Thick Client Application Penetration Testing and recently, came up with the topic: DLL Hijacking…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking personal space.
https://cdn-images-1.medium.com/max/1080/1*u93vo6LdY3RPNlPSwEPD1g.jpeg
Are we becoming or making a robot of ourselves?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking personal space.
https://cdn-images-1.medium.com/max/1080/1*u93vo6LdY3RPNlPSwEPD1g.jpeg
Are we becoming or making a robot of ourselves?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking personal space.
Are we becoming or making a robot of ourselves?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Web Scanning Room Walkthrough | TryHackMe
https://cdn-images-1.medium.com/max/1280/1*L5SJpYFR8Ez9qfASXo-zWA.png
Glad that you could join me again
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Web Scanning Room Walkthrough | TryHackMe
https://cdn-images-1.medium.com/max/1280/1*L5SJpYFR8Ez9qfASXo-zWA.png
Glad that you could join me again
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Web Scanning Room Walkthrough | TryHackMe
Glad that you could join me again
Whoc - A Container Image That Extracts The Underlying Container Runtime
A container image that extracts the underlying container runtime and sends it to a remote server. Poke at the underlying container runtime of your favorite CSP container platform!WhoC at Defcon 29 Cloud VillageAzurescape - whoc-powered research, the first cross-account container takeover in the public cloud (70,000$ bounty)How does it work?As shown by runc CVE-2019-5736, traditional Linux container runtimes expose themselves to the containers they're running through /proc/self/exe. whoc uses this link to read the container runtime executing it.Dynamic ModeThis is whoc default mode that works against dynamically linked container runtimes.The whoc image entrypoint is set to /proc/self/exe, and the image's dynamic linker (ld.so) is replaced with fake_ld.Once the image is run, the container runtime re-executes itself inside the container.Given the runtime is dynamically linked, the kernel loads our fake dynamic linker to the runtime process and passes execution to it.fake_ld obtains a file descriptor for the runtime binary by opening /proc/self/exe, and executes upload_runtime.upload_runtime reads the runtime binary from /proc/self/fd/ and sends it to the configured remote server.Wait-For-Exec ModeFor statically linked container runtimes, whoc comes in another flavor: whoc:waitforexec.upload_runtime is the image entrypoint, and runs as the whoc container PID 1.The user is expected to exec into the whoc container and invoke a file pointing to /proc/self/exe (e.g. docker exec whoc-ctr /proc/self/exe)Once the exec occurs, the container runtime re-executes itself inside the containerupload_runtime reads the runtime binary through /proc//exe and sends it to the configured remote serverTry LocallyYou'll need docker and python3 installed. Clone the repository:$ git clone git@github.com:twistlock/whoc.gitSet up a file server to receive the extracted container runtime:$ cd whoc$ mkdir -p stash && cd stash$ ln -s ../util/fileserver.py fileserver $ ./fileserverFrom another shell, run the whoc image in your container environment of choice, for example Docker:$ cd whoc$ docker build -f Dockerfile_dynamic -t whoc:latest src # or ./util/build.sh$ docker run --rm -it --net=host whoc:latest 127.0.0.1 # or ./util/run_local.shSee that the file server received the container runtime. Since we run whoc under vanilla Docker, the received container runtime should be runc.--net=host is only used in local tests so that the whoc container could easily reach the fileserver on the host via 127.0.0.1.HelpHelp for whoc's main binary, upload_runtime:Usage: upload_runtime options Options: -p, --port Port of remote server, defaults to 8080 -e, --exec Wait-for-exec mode for static container runtimes, waits until an exec to the container occurred -b, --exec-bin In exec mode, overrides the default binary created for the exec, default is /bin/enter -a, --exec-extra-argument In exec mode, pass an additional argument to the runtime so it won't exit quickly -r, --exec-readdir-proc In exec mode, instead of guessing the runtime pid (which gives whoc one shot of catching the runtime), find the runtime by searching for new processes under '/proc'Download Whoc
Read more...
___________________________
@hacking_Attack
@Hacking_Video
A container image that extracts the underlying container runtime and sends it to a remote server. Poke at the underlying container runtime of your favorite CSP container platform!WhoC at Defcon 29 Cloud VillageAzurescape - whoc-powered research, the first cross-account container takeover in the public cloud (70,000$ bounty)How does it work?As shown by runc CVE-2019-5736, traditional Linux container runtimes expose themselves to the containers they're running through /proc/self/exe. whoc uses this link to read the container runtime executing it.Dynamic ModeThis is whoc default mode that works against dynamically linked container runtimes.The whoc image entrypoint is set to /proc/self/exe, and the image's dynamic linker (ld.so) is replaced with fake_ld.Once the image is run, the container runtime re-executes itself inside the container.Given the runtime is dynamically linked, the kernel loads our fake dynamic linker to the runtime process and passes execution to it.fake_ld obtains a file descriptor for the runtime binary by opening /proc/self/exe, and executes upload_runtime.upload_runtime reads the runtime binary from /proc/self/fd/ and sends it to the configured remote server.Wait-For-Exec ModeFor statically linked container runtimes, whoc comes in another flavor: whoc:waitforexec.upload_runtime is the image entrypoint, and runs as the whoc container PID 1.The user is expected to exec into the whoc container and invoke a file pointing to /proc/self/exe (e.g. docker exec whoc-ctr /proc/self/exe)Once the exec occurs, the container runtime re-executes itself inside the containerupload_runtime reads the runtime binary through /proc//exe and sends it to the configured remote serverTry LocallyYou'll need docker and python3 installed. Clone the repository:$ git clone git@github.com:twistlock/whoc.gitSet up a file server to receive the extracted container runtime:$ cd whoc$ mkdir -p stash && cd stash$ ln -s ../util/fileserver.py fileserver $ ./fileserverFrom another shell, run the whoc image in your container environment of choice, for example Docker:$ cd whoc$ docker build -f Dockerfile_dynamic -t whoc:latest src # or ./util/build.sh$ docker run --rm -it --net=host whoc:latest 127.0.0.1 # or ./util/run_local.shSee that the file server received the container runtime. Since we run whoc under vanilla Docker, the received container runtime should be runc.--net=host is only used in local tests so that the whoc container could easily reach the fileserver on the host via 127.0.0.1.HelpHelp for whoc's main binary, upload_runtime:Usage: upload_runtime options Options: -p, --port Port of remote server, defaults to 8080 -e, --exec Wait-for-exec mode for static container runtimes, waits until an exec to the container occurred -b, --exec-bin In exec mode, overrides the default binary created for the exec, default is /bin/enter -a, --exec-extra-argument In exec mode, pass an additional argument to the runtime so it won't exit quickly -r, --exec-readdir-proc In exec mode, instead of guessing the runtime pid (which gives whoc one shot of catching the runtime), find the runtime by searching for new processes under '/proc'Download Whoc
Read more...
___________________________
@hacking_Attack
@Hacking_Video
STORY OF AN ENCODED XSS
https://faiyazhacks.medium.com/story-of-an-encoded-xss-e83c7ea9e02?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://faiyazhacks.medium.com/story-of-an-encoded-xss-e83c7ea9e02?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
STORY OF AN ENCODED XSS
Hi everyone, I hope you all are doing well and great! In this article we are going to talk about a weird xss that i found in one of the…
Hi everyone, I hope you all are doing well and great! In this article we are going to talk about a weird xss that i found in one of the…Continue reading on Medium » (https://faiyazhacks.medium.com/story-of-an-encoded-xss-e83c7ea9e02?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
STORY OF AN ENCODED XSS
Hi everyone, I hope you all are doing well and great! In this article we are going to talk about a weird xss that i found in one of the…