Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Latest hacking news
https://cdn-images-1.medium.com/max/728/1*5tQnpcUhik93GV_k1JQCDQ.png
New Zoom Hack Lets Hackers Compromise Windows and Its Login Password
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Latest hacking news
https://cdn-images-1.medium.com/max/728/1*5tQnpcUhik93GV_k1JQCDQ.png
New Zoom Hack Lets Hackers Compromise Windows and Its Login Password
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Latest hacking news
New Zoom Hack Lets Hackers Compromise Windows and Its Login Password
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mifare 1K Classic
https://cdn-images-1.medium.com/max/1467/1*L5ZiC5SUfc0kCSJW5Vxizg.png
I’ve recently started delving back into RFID attacks since a lot of businesses will likely be asking for physical PenTests or, at the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Mifare 1K Classic
https://cdn-images-1.medium.com/max/1467/1*L5ZiC5SUfc0kCSJW5Vxizg.png
I’ve recently started delving back into RFID attacks since a lot of businesses will likely be asking for physical PenTests or, at the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Mifare 1K Classic
I’ve recently started delving back into RFID attacks since a lot of businesses will likely be asking for physical PenTests or, at the…
hacking: security in practice
How to hack a surefeed microchip pet feeder?
I have two cats. One is a fat ass, one is eating responsibly. I bought a connected feeder with a microchip reader and a scale.
I want to be able to program the feeder such that a given cat isn't allowed to eat more than X grams of food a day, and not more than Y grams of food in the last hour.
The only thing it does right now is to allow access to a set of chips, without quantity or time regulation. Then it notifies me of the time and quantity, thanks to a hub.
How would I reprogram it? Where do I find ressources about the subject? I can imagine it involving a Pi, opening the feeder and hooking up the pi to it somehow. And then, I'd have to figure out the API to control the thing and get access to the required data?
Looks like a lot of fun but I don't know where to begin
submitted by /u/UnDemiNem
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to hack a surefeed microchip pet feeder?
I have two cats. One is a fat ass, one is eating responsibly. I bought a connected feeder with a microchip reader and a scale.
I want to be able to program the feeder such that a given cat isn't allowed to eat more than X grams of food a day, and not more than Y grams of food in the last hour.
The only thing it does right now is to allow access to a set of chips, without quantity or time regulation. Then it notifies me of the time and quantity, thanks to a hub.
How would I reprogram it? Where do I find ressources about the subject? I can imagine it involving a Pi, opening the feeder and hooking up the pi to it somehow. And then, I'd have to figure out the API to control the thing and get access to the required data?
Looks like a lot of fun but I don't know where to begin
submitted by /u/UnDemiNem
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to hack a surefeed microchip pet feeder?
I have two cats. One is a fat ass, one is eating responsibly. I bought a connected feeder with a microchip reader and a scale. I want to be able...
hacking: security in practice
I'm paranoid because every time I sign into my email on google chrome it's signing me into "Person 2". Why am I not being signed into "Person 1"? Was I hacked?
Just to elaborate a bit more.. When I click on the little head icon at the top right of the browser (under the red X), it shows me signed into "Person 2". BUT there isn't even a "Person 1" listed. There's only "Person 2" and "Guest". Is this how it's supposed to be? Why would there be a "Person 2" and not a "Person 1"?
submitted by /u/wutevs-
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I'm paranoid because every time I sign into my email on google chrome it's signing me into "Person 2". Why am I not being signed into "Person 1"? Was I hacked?
Just to elaborate a bit more.. When I click on the little head icon at the top right of the browser (under the red X), it shows me signed into "Person 2". BUT there isn't even a "Person 1" listed. There's only "Person 2" and "Guest". Is this how it's supposed to be? Why would there be a "Person 2" and not a "Person 1"?
submitted by /u/wutevs-
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I'm paranoid because every time I sign into my email on google...
Just to elaborate a bit more.. When I click on the little head icon at the top right of the browser (under the red X), it shows me signed into...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Phantom - A multi-platform HTTP(S) Reverse Shell Server and Client in Python 3
Phantom is a multi-platform HTTP(S) Reverse Shell server and client in Python 3. Binaries for Linux and Windows platforms can be built through an embedded script that executes PyInstaller.
Reverse shells can be established through HTTP or HTTPS. The certificates used for HTTPS can be auto-generated by Phantom or supplied by the user.
Phantom includes a helper shell script that enables fast generation of self-signed certificates for use of both servers and clients. After generation, the server and certificate authority certificates required for encrypted connections are bundled in the binaries for portability and ease of execution.
Check it out on GitHub at https://github.com/EONRaider/BCA-Phantom
submitted by /u/EONRaider
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Phantom - A multi-platform HTTP(S) Reverse Shell Server and Client in Python 3
Phantom is a multi-platform HTTP(S) Reverse Shell server and client in Python 3. Binaries for Linux and Windows platforms can be built through an embedded script that executes PyInstaller.
Reverse shells can be established through HTTP or HTTPS. The certificates used for HTTPS can be auto-generated by Phantom or supplied by the user.
Phantom includes a helper shell script that enables fast generation of self-signed certificates for use of both servers and clients. After generation, the server and certificate authority certificates required for encrypted connections are bundled in the binaries for portability and ease of execution.
Check it out on GitHub at https://github.com/EONRaider/BCA-Phantom
submitted by /u/EONRaider
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Phantom - A multi-platform HTTP(S) Reverse Shell Server and Client...
Phantom is a **multi-platform HTTP(S) Reverse Shell** server and client in Python 3. Binaries for Linux and Windows platforms can be built through...
hacking: security in practice
Is ratting illegal in Canada?
20-year old Canadian here. Someone Im close to showed me that he has remote access to a bunch of people’s computers and had keyloggers running.
He told me he could help me get started, but I don’t want to get into serious trouble.
Disclaimer: my friend does not make a profit from doing this, he merely does it as an interest project.
submitted by /u/quickdr4w_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is ratting illegal in Canada?
20-year old Canadian here. Someone Im close to showed me that he has remote access to a bunch of people’s computers and had keyloggers running.
He told me he could help me get started, but I don’t want to get into serious trouble.
Disclaimer: my friend does not make a profit from doing this, he merely does it as an interest project.
submitted by /u/quickdr4w_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is ratting illegal in Canada?
20-year old Canadian here. Someone Im close to showed me that he has remote access to a bunch of people computers and had keyloggers running. He...
hacking: security in practice
How are black hats able still able to get away with attacks?
In our day and age of extremely prioritized cybersecurity and policing, it is almost every week or less that another breach is reported, and often we only hear about the perpetrators by their associations with groups or hostile nations, but not so often do I see news of individuals being tracked down by authorities successfully. This surprises me as organizations like the NSA and FBI are so advanced in their ability to investigate cyber attacks, that it seems like even if you used every possible method of obscuring your identity and whereabouts during an attack, they would have ways of hunting you down, and seem plenty enthusiastic to do so.
If a black hat hacker got on a public wifi network with a proxy and routed everything through TOR in a McDonald's parking lot, spoofed their IP and MAC address, and then breached the network of some organization and stole a bunch of PIDs and sensitive data, etc., don't these things turn into ruthless federal manhunts for the perpetrators, or have I just watched too many FBI TV shows?
submitted by /u/GrassyNotes
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How are black hats able still able to get away with attacks?
In our day and age of extremely prioritized cybersecurity and policing, it is almost every week or less that another breach is reported, and often we only hear about the perpetrators by their associations with groups or hostile nations, but not so often do I see news of individuals being tracked down by authorities successfully. This surprises me as organizations like the NSA and FBI are so advanced in their ability to investigate cyber attacks, that it seems like even if you used every possible method of obscuring your identity and whereabouts during an attack, they would have ways of hunting you down, and seem plenty enthusiastic to do so.
If a black hat hacker got on a public wifi network with a proxy and routed everything through TOR in a McDonald's parking lot, spoofed their IP and MAC address, and then breached the network of some organization and stole a bunch of PIDs and sensitive data, etc., don't these things turn into ruthless federal manhunts for the perpetrators, or have I just watched too many FBI TV shows?
submitted by /u/GrassyNotes
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Software that can encrypt external drive and wipe all data at the same time?
I've been looking for something that encrypt all data and requires two passwords: one for unlocking the drive, but if I put in an alternative password, it will wipe all the data
submitted by /u/snkhuong
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Software that can encrypt external drive and wipe all data at the same time?
I've been looking for something that encrypt all data and requires two passwords: one for unlocking the drive, but if I put in an alternative password, it will wipe all the data
submitted by /u/snkhuong
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Software that can encrypt external drive and wipe all data at the...
I've been looking for something that encrypt all data and requires two passwords: one for unlocking the drive, but if I put in an alternative...
ELFXtract - An Automated Analysis Tool Used For Enumerating ELF Binaries
http://www.kitploit.com/2021/11/elfxtract-automated-analysis-tool-used.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/11/elfxtract-automated-analysis-tool-used.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
_____ _ ________ ___ _
| ___| | | ___\ \ / / | | |
| |__ | | | |_ \ V /| |_ _ __ __ _ ___| |_
| __|| | | _| / \| __| '__/ _` |/ __| __|
| |___| |____| | / /^\ \ |_| | | (_| | (__| |_
\____/\_____/\_| \/ \/\__|_| \__,_|\___|\__|
@aidenpearce369
***************************************************************************
> FILE INFO :
ELF Name : programvuln
ELF Type : ELF 64-bit LSB shared object
ELF Arch : x86-64
ELF SHA1 Hash : BuildID[sha1]=cf149d97ad1e895561080b1f5c317bc5bc1e8652
This binary is dynamically linked & not stripped
********************** *****************************************************
> SHARED OBJECT DEPENDENCY :
linux-vdso.so.1 (0x00007ffd525a4000)
libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fd610d93000)
/lib64/ld-linux-x86-64.so.2 (0x00007fd610fa1000)
***************************************************************************
> ELF SECURITY MITIGATIONS :
RELRO : Full RELRO
STACK CANARY : No Canary found
NX BIT : NX disabled
PIE : PIE enabled
RPATH : No RPATH
RUNPATH : No RUNPATH
***************************************************************************
> POSSIBLE STRINGS :
nth paddr vaddr len size section type string
―――――――――――――――――――――――& #8213;―――――――――――――――――――――――――――――――
0 0x00002008 0x00002008 31 32 .rodata ascii You have bypassed this function
1 0x00002028 0x00002028 12 13 .rodata ascii cat flag.txt
2 0x00002035 0x00002035 15 16 .rodata ascii Enter your name
3 0x00002045 0x00002045 13 14 .rodata ascii Your name is
***************************************************************************
> RODATA HEXDUMP :
0x00002000 01000200 00000000 596f7520 68617665 ........You have
0x00002010 20627970 61737365 64207468 69732066 bypassed this f
0x00002020 756e6374 696f6e00 63617420 666c6167 unction.cat flag
0x00002030 2e747874 00456e74 65722079 6f757220 .txt.Enter your
0x00002040 6e616d65 00596f75 72206e61 6d652069 name.Your name i
0x00002050 732000 s .
***************************************************************************
> ELF ENTRY POINT :
The entry point of the ELF is at 0x10c0
***************************************************************************
> HEADER MEMORY MAP :
Type Offset VirtAddr PhysAddr
FileSiz MemSiz Flags Align
PHDR 0x0000000000000040 0x0000000000000040 0x0000000000000040
0x00000000000002d8 0x00000000000002d8 R 0x8
INTERP 0x0000000000000318 0x0000000000000318 0x0000000000000318
0x000000000000001c 0x000000000000001c R 0x1
[Requesting program interpreter: /lib64/ld-linux-x86-64.so.2]
LOAD 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x00000000000006a8 0x00000000000006a8 R 0x1000
LOAD 0x0000000000001000 0x0000000000001000 0x0000000000001000
0x00000000000002b5 0x00000000000002b5 R E 0x1000
LOAD 0x0000000000002000 0x0000000000002000 0x0000000000002000
0x00000000000001c8 0x00000000000001c8 R 0x1000
LOAD 0x0000000000002da0 0x0000000000003da0 0x0000000000003da0
0x0000000000000270 0x0000000000000278 RW 0x1000
DYNAMIC 0x0000000000002db0 0x0000000000003db0 0x0000000000003db0
0x00000000000001f0 0x00000000000001f0 RW 0x8
NOTE 0x0000000000000338 0x0000000000000338 0x0000000000000338
___________________________
@hacking_Attack
@Hacking_Video
| ___| | | ___\ \ / / | | |
| |__ | | | |_ \ V /| |_ _ __ __ _ ___| |_
| __|| | | _| / \| __| '__/ _` |/ __| __|
| |___| |____| | / /^\ \ |_| | | (_| | (__| |_
\____/\_____/\_| \/ \/\__|_| \__,_|\___|\__|
@aidenpearce369
***************************************************************************
> FILE INFO :
ELF Name : programvuln
ELF Type : ELF 64-bit LSB shared object
ELF Arch : x86-64
ELF SHA1 Hash : BuildID[sha1]=cf149d97ad1e895561080b1f5c317bc5bc1e8652
This binary is dynamically linked & not stripped
********************** *****************************************************
> SHARED OBJECT DEPENDENCY :
linux-vdso.so.1 (0x00007ffd525a4000)
libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fd610d93000)
/lib64/ld-linux-x86-64.so.2 (0x00007fd610fa1000)
***************************************************************************
> ELF SECURITY MITIGATIONS :
RELRO : Full RELRO
STACK CANARY : No Canary found
NX BIT : NX disabled
PIE : PIE enabled
RPATH : No RPATH
RUNPATH : No RUNPATH
***************************************************************************
> POSSIBLE STRINGS :
nth paddr vaddr len size section type string
―――――――――――――――――――――――& #8213;―――――――――――――――――――――――――――――――
0 0x00002008 0x00002008 31 32 .rodata ascii You have bypassed this function
1 0x00002028 0x00002028 12 13 .rodata ascii cat flag.txt
2 0x00002035 0x00002035 15 16 .rodata ascii Enter your name
3 0x00002045 0x00002045 13 14 .rodata ascii Your name is
***************************************************************************
> RODATA HEXDUMP :
0x00002000 01000200 00000000 596f7520 68617665 ........You have
0x00002010 20627970 61737365 64207468 69732066 bypassed this f
0x00002020 756e6374 696f6e00 63617420 666c6167 unction.cat flag
0x00002030 2e747874 00456e74 65722079 6f757220 .txt.Enter your
0x00002040 6e616d65 00596f75 72206e61 6d652069 name.Your name i
0x00002050 732000 s .
***************************************************************************
> ELF ENTRY POINT :
The entry point of the ELF is at 0x10c0
***************************************************************************
> HEADER MEMORY MAP :
Type Offset VirtAddr PhysAddr
FileSiz MemSiz Flags Align
PHDR 0x0000000000000040 0x0000000000000040 0x0000000000000040
0x00000000000002d8 0x00000000000002d8 R 0x8
INTERP 0x0000000000000318 0x0000000000000318 0x0000000000000318
0x000000000000001c 0x000000000000001c R 0x1
[Requesting program interpreter: /lib64/ld-linux-x86-64.so.2]
LOAD 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x00000000000006a8 0x00000000000006a8 R 0x1000
LOAD 0x0000000000001000 0x0000000000001000 0x0000000000001000
0x00000000000002b5 0x00000000000002b5 R E 0x1000
LOAD 0x0000000000002000 0x0000000000002000 0x0000000000002000
0x00000000000001c8 0x00000000000001c8 R 0x1000
LOAD 0x0000000000002da0 0x0000000000003da0 0x0000000000003da0
0x0000000000000270 0x0000000000000278 RW 0x1000
DYNAMIC 0x0000000000002db0 0x0000000000003db0 0x0000000000003db0
0x00000000000001f0 0x00000000000001f0 RW 0x8
NOTE 0x0000000000000338 0x0000000000000338 0x0000000000000338
___________________________
@hacking_Attack
@Hacking_Video
0x0000000000000020 0x0000000000000020 R 0x8
NOTE 0x0000000000000358 0x0000000000000358 0x0000000000000358
0x0000000000000044 0x0000000000000044 R 0x4
GNU_PROPERTY 0x000000000 0000338 0x0000000000000338 0x0000000000000338
0x0000000000000020 0x0000000000000020 R 0x8
GNU_EH_FRAME 0x0000000000002054 0x0000000000002054 0x0000000000002054
0x000000000000004c 0x000000000000004c R 0x4
GNU_STACK 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x0000000000000000 0x0000000000000000 RWE 0x10
GNU_RELRO 0x0000000000002da0 0x0000000000003da0 0x0000000000003da0
0x0000000000000260 0x0000000000000260 R 0x1
***************************************************************************
[*] Loaded 14 cached gadgets for 'programvuln'
> ROP GADGETS :
0x1017 : add esp, 8;ret
0x1016 : add rsp, 8;ret
0x1221 : leave;ret
0x128c : pop r12;pop r13;pop r14;pop r15;ret
0x128e : pop r13;pop r14;pop r15;ret
0x1290 : pop r14;pop r15;ret
0x12 92 : pop r15;ret
0x128b : pop rbp;pop r12;pop r13;pop r14;pop r15;ret
0x128f : pop rbp;pop r14;pop r15;ret
0x1193 : pop rbp;ret
0x1293 : pop rdi;ret
0x1291 : pop rsi;pop r15;ret
0x128d : pop rsp;pop r13;pop r14;pop r15;ret
0x101a : ret
***************************************************************************
> PLT TABLE :
__cxa_finalize : 0x1074
puts : 0x1084
system : 0x1094
printf : 0x10a4
gets : 0x10b4
***************************************************************************
> GOT TABLE :
_ITM_deregisterTMCloneTable : 0x3fd8
__libc_start_main : 0x3fe0
__gmon_start__ : 0x3fe8
_ITM_registerTMCloneTable : 0x3ff0
__cxa_finalize : 0x3ff8
puts : 0x3fb8
system : 0x3fc0
printf : 0x3fc8
gets : 0x3fd0
***************************************************************************
> FUNCTION TABLE :
__libc_csu_fini : 0x12a0
__libc_csu_init : 0x1230
win : 0x11a9
_start : 0x10c0
main : 0x11d6
***************************************************************************
> POSSIBLE USER DEFINED FUNCTIONS :
win : 0x11a9
main : 0x11d6
***************************************************************************
> ASSEMBLY AND DECOMPILED CODE :
[*] ASM - win :
┌ 45: sym.win ();
│ 0x000011a9 f30f1efa endbr64
│ 0x000011ad 55 push rbp
│ 0x000011ae 4889e5 mov rbp, rsp
│ 0x000011b1 488d3d500e00. lea rdi, str.You_have_bypassed_this_function ; 0x2008 ; "You have bypassed this function" ; const char *format
│ 0x000011b8 b800000000 mov eax, 0
│ 0x000011bd e8defeffff call sym.imp.printf ; int printf(const char *format)
│ 0x000011c2 488d3d5f0e00. lea rdi, str.cat_flag.txt ; 0x2028 ; "cat flag.txt" ; const char *string
│ 0x000011c9 b800000000 mov eax, 0
│ 0x000011ce e8bdfeffff call sym.imp.system ; int system(const char *string)
│ 0x000011d3 90 nop
│ 0x000011d4 5d pop rbp
└ 0x000011d5 c3 ret
___________________________
@hacking_Attack
@Hacking_Video
NOTE 0x0000000000000358 0x0000000000000358 0x0000000000000358
0x0000000000000044 0x0000000000000044 R 0x4
GNU_PROPERTY 0x000000000 0000338 0x0000000000000338 0x0000000000000338
0x0000000000000020 0x0000000000000020 R 0x8
GNU_EH_FRAME 0x0000000000002054 0x0000000000002054 0x0000000000002054
0x000000000000004c 0x000000000000004c R 0x4
GNU_STACK 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x0000000000000000 0x0000000000000000 RWE 0x10
GNU_RELRO 0x0000000000002da0 0x0000000000003da0 0x0000000000003da0
0x0000000000000260 0x0000000000000260 R 0x1
***************************************************************************
[*] Loaded 14 cached gadgets for 'programvuln'
> ROP GADGETS :
0x1017 : add esp, 8;ret
0x1016 : add rsp, 8;ret
0x1221 : leave;ret
0x128c : pop r12;pop r13;pop r14;pop r15;ret
0x128e : pop r13;pop r14;pop r15;ret
0x1290 : pop r14;pop r15;ret
0x12 92 : pop r15;ret
0x128b : pop rbp;pop r12;pop r13;pop r14;pop r15;ret
0x128f : pop rbp;pop r14;pop r15;ret
0x1193 : pop rbp;ret
0x1293 : pop rdi;ret
0x1291 : pop rsi;pop r15;ret
0x128d : pop rsp;pop r13;pop r14;pop r15;ret
0x101a : ret
***************************************************************************
> PLT TABLE :
__cxa_finalize : 0x1074
puts : 0x1084
system : 0x1094
printf : 0x10a4
gets : 0x10b4
***************************************************************************
> GOT TABLE :
_ITM_deregisterTMCloneTable : 0x3fd8
__libc_start_main : 0x3fe0
__gmon_start__ : 0x3fe8
_ITM_registerTMCloneTable : 0x3ff0
__cxa_finalize : 0x3ff8
puts : 0x3fb8
system : 0x3fc0
printf : 0x3fc8
gets : 0x3fd0
***************************************************************************
> FUNCTION TABLE :
__libc_csu_fini : 0x12a0
__libc_csu_init : 0x1230
win : 0x11a9
_start : 0x10c0
main : 0x11d6
***************************************************************************
> POSSIBLE USER DEFINED FUNCTIONS :
win : 0x11a9
main : 0x11d6
***************************************************************************
> ASSEMBLY AND DECOMPILED CODE :
[*] ASM - win :
┌ 45: sym.win ();
│ 0x000011a9 f30f1efa endbr64
│ 0x000011ad 55 push rbp
│ 0x000011ae 4889e5 mov rbp, rsp
│ 0x000011b1 488d3d500e00. lea rdi, str.You_have_bypassed_this_function ; 0x2008 ; "You have bypassed this function" ; const char *format
│ 0x000011b8 b800000000 mov eax, 0
│ 0x000011bd e8defeffff call sym.imp.printf ; int printf(const char *format)
│ 0x000011c2 488d3d5f0e00. lea rdi, str.cat_flag.txt ; 0x2028 ; "cat flag.txt" ; const char *string
│ 0x000011c9 b800000000 mov eax, 0
│ 0x000011ce e8bdfeffff call sym.imp.system ; int system(const char *string)
│ 0x000011d3 90 nop
│ 0x000011d4 5d pop rbp
└ 0x000011d5 c3 ret
___________________________
@hacking_Attack
@Hacking_Video
[*] DECOMPILED CODE - win :
void sym.win(void)
{
sym.imp.printf("You have bypassed this function");
sym.imp.system("cat flag.txt");
return;
}
[*] ASM - main :
; DATA XREF from entry0 @ 0x10e1
┌ 77: int main (int argc, char **argv, char **envp);
│ ; var char *s @ rbp-0x40
│ 0x000011d6 f30f1efa endbr64
│ 0x000011da 55 push rbp
│ 0x000011db 4889e5 mov rbp, rsp
│ 0x000011de 4883ec40 sub rsp, 0x40
│ 0x000011e2 488d3d4c0e00. lea rdi, str.Enter_your_name ; 0x2035 ; "Enter your name" ; const char *s
│ 0x000011e9 e892feffff call sym.imp.puts ; int puts(const char *s)
│ 0x000011ee 488d45c0 lea rax, [s]
│ 0x000011f2 4889c7 mov rdi, rax ; char *s
│ 0x000011f5 b800000000 mov eax, 0
│ 0x000011fa e8b1feffff call sym.imp.gets ; char *gets(char *s)
│ 0x000011ff 488d3d3f0e00. lea rdi, str.Your_name_is_ ; 0x2045 ; "Your name is " ; const char *format
│ 0x00001206 b800000000 mov eax, 0
│ 0x0000120b e890feffff call sym.imp.printf ; int printf(const char *format)
│ 0x00001210 488d45c0 lea rax, [s]
│ 0x00001214 4889c7 mov rdi, rax ; const char *s
│ 0x00001217 e864feffff call sym.imp.puts ; int puts(const char *s)
│ 0x 0000121c b800000000 mov eax, 0
│ 0x00001221 c9 leave
└ 0x00001222 c3 ret
[*] DECOMPILED CODE - main :
// WARNING: [r2ghidra] Failed to match type char * for variable s to Decompiler type:
undefined8 main(void)
{
undefined8 s;
sym.imp.puts("Enter your name");
sym.imp.gets(&s);
sym.imp.printf("Your name is ");
sym.imp.puts(&s);
return 0;
}
***************************************************************************
> VULNERABLE FUNCTIONS :
Possible vulnerability locations - Command Execution
0x000011ce e8bdfeffff call sym.imp.system ; int system(const char *string)
Possible vulnerability locations - Format String
0x000011bd e8defeffff call sym.imp.printf ; int printf(const char * format)
0x0000120b e890feffff call sym.imp.printf ; int printf(const char *format)
Possible vulnerability locations - Buffer Overflow
0x000011fa e8b1feffff call sym.imp.gets ; char *gets(char *s)
*************************************************************************** You can also pass arguments and get the info based on your needs, ra@ubuntu:~/elfxtract$ python3 main.py -h
_____ _ ________ ___ _
| ___| | | ___\ \ / / | | |
| |__ | | | |_ \ V /| |_ _ __ __ _ ___| |_
| __|| | | _| / \| __| '__/ _` |/ __| __|
| |___| |____| | / /^\ \ |_| | | (_| | (__| |_
\____/\_____/\_| \/ \/\__|_| \__,_|\___|\__|
@aidenpearce369
***************************************************************************
usage: main.py [-h] -f FILE [-a] [-i] [-g] [--user-func] [--get-func GET_FUNC] [--asm-only]
[--decompiled-only] [-t]
optional arguments:
-h, --help show this help message and exit
-f FILE, --file FILE Path of the ELF
-a, --all Extract all info
-i, --info Displays bas ic info
-g, --gadgets Displays gadgets
--user-func Displays the details of user defined functions
--get-func GET_FUNC Displays the ASM & decompiled code of the given function
--asm-only Displays the ASM of ELF
___________________________
@hacking_Attack
@Hacking_Video
void sym.win(void)
{
sym.imp.printf("You have bypassed this function");
sym.imp.system("cat flag.txt");
return;
}
[*] ASM - main :
; DATA XREF from entry0 @ 0x10e1
┌ 77: int main (int argc, char **argv, char **envp);
│ ; var char *s @ rbp-0x40
│ 0x000011d6 f30f1efa endbr64
│ 0x000011da 55 push rbp
│ 0x000011db 4889e5 mov rbp, rsp
│ 0x000011de 4883ec40 sub rsp, 0x40
│ 0x000011e2 488d3d4c0e00. lea rdi, str.Enter_your_name ; 0x2035 ; "Enter your name" ; const char *s
│ 0x000011e9 e892feffff call sym.imp.puts ; int puts(const char *s)
│ 0x000011ee 488d45c0 lea rax, [s]
│ 0x000011f2 4889c7 mov rdi, rax ; char *s
│ 0x000011f5 b800000000 mov eax, 0
│ 0x000011fa e8b1feffff call sym.imp.gets ; char *gets(char *s)
│ 0x000011ff 488d3d3f0e00. lea rdi, str.Your_name_is_ ; 0x2045 ; "Your name is " ; const char *format
│ 0x00001206 b800000000 mov eax, 0
│ 0x0000120b e890feffff call sym.imp.printf ; int printf(const char *format)
│ 0x00001210 488d45c0 lea rax, [s]
│ 0x00001214 4889c7 mov rdi, rax ; const char *s
│ 0x00001217 e864feffff call sym.imp.puts ; int puts(const char *s)
│ 0x 0000121c b800000000 mov eax, 0
│ 0x00001221 c9 leave
└ 0x00001222 c3 ret
[*] DECOMPILED CODE - main :
// WARNING: [r2ghidra] Failed to match type char * for variable s to Decompiler type:
undefined8 main(void)
{
undefined8 s;
sym.imp.puts("Enter your name");
sym.imp.gets(&s);
sym.imp.printf("Your name is ");
sym.imp.puts(&s);
return 0;
}
***************************************************************************
> VULNERABLE FUNCTIONS :
Possible vulnerability locations - Command Execution
0x000011ce e8bdfeffff call sym.imp.system ; int system(const char *string)
Possible vulnerability locations - Format String
0x000011bd e8defeffff call sym.imp.printf ; int printf(const char * format)
0x0000120b e890feffff call sym.imp.printf ; int printf(const char *format)
Possible vulnerability locations - Buffer Overflow
0x000011fa e8b1feffff call sym.imp.gets ; char *gets(char *s)
*************************************************************************** You can also pass arguments and get the info based on your needs, ra@ubuntu:~/elfxtract$ python3 main.py -h
_____ _ ________ ___ _
| ___| | | ___\ \ / / | | |
| |__ | | | |_ \ V /| |_ _ __ __ _ ___| |_
| __|| | | _| / \| __| '__/ _` |/ __| __|
| |___| |____| | / /^\ \ |_| | | (_| | (__| |_
\____/\_____/\_| \/ \/\__|_| \__,_|\___|\__|
@aidenpearce369
***************************************************************************
usage: main.py [-h] -f FILE [-a] [-i] [-g] [--user-func] [--get-func GET_FUNC] [--asm-only]
[--decompiled-only] [-t]
optional arguments:
-h, --help show this help message and exit
-f FILE, --file FILE Path of the ELF
-a, --all Extract all info
-i, --info Displays bas ic info
-g, --gadgets Displays gadgets
--user-func Displays the details of user defined functions
--get-func GET_FUNC Displays the ASM & decompiled code of the given function
--asm-only Displays the ASM of ELF
___________________________
@hacking_Attack
@Hacking_Video
--decompiled-only Displays the decompiled C code of ELF
-t, --tables Displays PLT, GOT & Function table Updates elfxtract is fully developed for parsing PWN binaries, Soon, it will be added with new features to analyse system binaries And also, auto-BOF and auto-ret2 exploit features will be added
Download Elfxtract (https://github.com/AidenPearce369/elfxtract)
___________________________
@hacking_Attack
@Hacking_Video
-t, --tables Displays PLT, GOT & Function table Updates elfxtract is fully developed for parsing PWN binaries, Soon, it will be added with new features to analyse system binaries And also, auto-BOF and auto-ret2 exploit features will be added
Download Elfxtract (https://github.com/AidenPearce369/elfxtract)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - m0n1x90/elfxtract
Contribute to m0n1x90/elfxtract development by creating an account on GitHub.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Sahu: Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/920/0*EXAkr-ENTzkJaLHe.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Sahu: Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/920/0*EXAkr-ENTzkJaLHe.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sahu: Vulnhub Walkthrough
Makineyi indirebilirsiniz.