Request Smuggling In Major Crypto Site — road to disappointment
Let me introduce myself since this is my first writing ever. In the beginning sorry if I make mistakes in my writing since English is not…
Read more...
Let me introduce myself since this is my first writing ever. In the beginning sorry if I make mistakes in my writing since English is not…
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
5 Things John Learned Fighting Hackers of His App — A must-read for PM’s and CISO’s
https://cdn-images-1.medium.com/max/1920/1*Tdv4aa6EJuSnd_HF-CRKmg.png
BetterVision is a popular app for the blind and visually impaired. John’s app suffered a cloning attack, and his In-App purchases got…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
5 Things John Learned Fighting Hackers of His App — A must-read for PM’s and CISO’s
https://cdn-images-1.medium.com/max/1920/1*Tdv4aa6EJuSnd_HF-CRKmg.png
BetterVision is a popular app for the blind and visually impaired. John’s app suffered a cloning attack, and his In-App purchases got…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 Things John Learned Fighting Hackers of His App — A must-read for PM’s and CISO’s
BetterVision is a popular app for the blind and visually impaired. John’s app suffered a cloning attack, and his In-App purchases got…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cheating at a Company Group Activity Using Unix Tools
https://cdn-images-1.medium.com/max/1440/1*5FEjuf6P0XY-P7BajMtqag.jpeg
The tools you didn’t know you need
Continue reading on Fundbox Engineering »
___________________________
@hacking_Attack
@Hacking_Video
Cheating at a Company Group Activity Using Unix Tools
https://cdn-images-1.medium.com/max/1440/1*5FEjuf6P0XY-P7BajMtqag.jpeg
The tools you didn’t know you need
Continue reading on Fundbox Engineering »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cheating at a Company Group Activity Using Unix Tools
The tools you didn’t know you need
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BitMart Updates Deposit Addresses to Enhance Security — Action Required
https://cdn-images-1.medium.com/max/2600/1*wD-XRYA_Q5FTIMXZ6hjYCQ.png
BitBook BBT tokens were unaffected by the BitMart hack last week, and BitMart is being extremely proactive in the face of the security…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
BitMart Updates Deposit Addresses to Enhance Security — Action Required
https://cdn-images-1.medium.com/max/2600/1*wD-XRYA_Q5FTIMXZ6hjYCQ.png
BitBook BBT tokens were unaffected by the BitMart hack last week, and BitMart is being extremely proactive in the face of the security…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
BitMart Updates Deposit Addresses to Enhance Security — Action Required
BitBook BBT tokens were unaffected by the BitMart hack last week, and BitMart is being extremely proactive in the face of the security…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Skills Required to Become an Ethical Hacker
https://cdn-images-1.medium.com/max/648/0*FudcEt4SliqRWDlv.png
Skills allow you to achieve your desired goals within the available time and resources. As a hacker, you will need to develop skills that…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Skills Required to Become an Ethical Hacker
https://cdn-images-1.medium.com/max/648/0*FudcEt4SliqRWDlv.png
Skills allow you to achieve your desired goals within the available time and resources. As a hacker, you will need to develop skills that…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Skills Required to Become an Ethical Hacker
Skills allow you to achieve your desired goals within the available time and resources. As a hacker, you will need to develop skills that…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is an Angler Phishing Attack?
https://cdn-images-1.medium.com/max/2440/1*3h5siK9N1wA6lhsd-39yjw.jpeg
Angler phishing is the act of pretending to be a customer service account on social media in the hope of reaching dissatisfied consumers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is an Angler Phishing Attack?
https://cdn-images-1.medium.com/max/2440/1*3h5siK9N1wA6lhsd-39yjw.jpeg
Angler phishing is the act of pretending to be a customer service account on social media in the hope of reaching dissatisfied consumers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is an Angler Phishing Attack?
Angler phishing is the act of pretending to be a customer service account on social media in the hope of reaching dissatisfied consumers…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to restore YouTube dislike stats
https://cdn-images-1.medium.com/max/2600/1*8nzlzqG7v1bX-pFfbXqtSQ.png
Without relying on third-party API
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to restore YouTube dislike stats
https://cdn-images-1.medium.com/max/2600/1*8nzlzqG7v1bX-pFfbXqtSQ.png
Without relying on third-party API
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to restore YouTube dislike stats
Without relying on third-party API
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HUB Digest of FUD & Fury: The Data Breached… is YOU!
https://cdn-images-1.medium.com/max/2400/1*-ILsOcpv9td9XejQZuomLg.png
Greetings, reader. You have arrived at the haunted digest of cyber security.
Continue reading on HUB Security »
___________________________
@hacking_Attack
@Hacking_Video
HUB Digest of FUD & Fury: The Data Breached… is YOU!
https://cdn-images-1.medium.com/max/2400/1*-ILsOcpv9td9XejQZuomLg.png
Greetings, reader. You have arrived at the haunted digest of cyber security.
Continue reading on HUB Security »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HUB Digest of FUD & Fury: The Data Breached… is YOU!
Greetings, reader. You have arrived at the haunted digest of cyber security. This is where we share appalling stories of cyber horrors, but…
Fileless-Xec - Stealth Dropper Executing Remote Binaries Without Dropping Them On Disk
http://www.kitploit.com/2021/12/fileless-xec-stealth-dropper-executing.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/12/fileless-xec-stealth-dropper-executing.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Certainly useful , mainly for fun, rougly inspired by 0x00 article (https://0x00sec.org/t/super-stealthy-droppers/3715)
Pentest use: fileless-xec is used on target machine to stealthy execute a binary file located on attacker machine
Short story fileless-xec enable us to execute a remote binary on a local machine directly from memory without dropping them on disk ➪ Install (https://github.com/ariary/fileless-xec/blob/main/install.md) simple usage fileless-xec (~curl | sh for binaries) execute binary with specified program name: fileless-xec -n /usr/sbin/sshd detach program execution from tty: setsid fileless-xec [...]
___________________________
@hacking_Attack
@Hacking_Video
Pentest use: fileless-xec is used on target machine to stealthy execute a binary file located on attacker machine
Short story fileless-xec enable us to execute a remote binary on a local machine directly from memory without dropping them on disk ➪ Install (https://github.com/ariary/fileless-xec/blob/main/install.md) simple usage fileless-xec (~curl | sh for binaries) execute binary with specified program name: fileless-xec -n /usr/sbin/sshd detach program execution from tty: setsid fileless-xec [...]
___________________________
@hacking_Attack
@Hacking_Video
0x00sec - The Home of the Hacker
Super-Stealthy Droppers
Some weeks ago I found [this interesting article] (https://blog.gdssecurity.com/labs/2017/9/5/linux-based-inter-process-code-injection-without-ptrace2.html), about injecting code in running processes without using ptrace. The article is very interesting and…
Explanation We want to execute writeNsleep binary locate on a remote machine, locally. We first start a python http server on remote. Locally we use fileless-xec and impersonate the /usr/sbin/sshd name for the execution of the binary writeNsleep(for stealthiness & fun). Once writeNsleep started fileless-xec will delete itself (--self-remove) Other use cases Execute binary with stdout/stdin (https://github.com/ariary/fileless-xec/blob/main/usage.md#execute-binary-with-stdoutstdin) Execute binary with arguments (https://github.com/ariary/fileless-xec/blob/main/usage.md#execute-binary-with-arguments) fileless-xec self remove Bypass network restriction using ICMP (https://github.com/ariary/fileless-xec/blob/main/usage.md#bypass-network-restriction-with-icmp) Bypass firewall with HTTP3 (https://github.com/ariary/fileless-xec/blob/main/usage.md#bypass-firewall-with-http3) "Remote go": execute go binaries without having go installed locally (https://github.com/ariary/fileless-xec/blob/main/usage.md#remote-go-execute-go-binaries-without-having-go-installed-locally) Execute a shell script (https://github.com/ariary/fileless-xec/blob/main/usage.md#execute-a-shell-script) fileless-xec server mode RAT (Remote Access Trojan) scenario (https://github.com/ariary/fileless-xec/blob/main/usage.md#rat-remote-access-trojan-scenario) fileless-xec on windows Stealthiness story The binary file is not mapped into the host file system The execution program name could be customizable Bypass 3rd generation firewall could be done with http3 support fileless-xec self removes once launched memfd_create The remote binary file is stored locally using memfd_create syscall, which store it within a memory disk which is not mapped into the file system (ie you can't find it using ls). fexecve Then we execute it using fexecve syscall (as it is currently not provided by syscall golang library (https://www.kitploit.com/search/label/Golang%20Library) we implem it). With fexecve , we could but we reference the program to run using a file descriptor, instead of the full path. HTTP3/QUIC Enable it with -Q/http3 flag.
You can setup a light web rootfs server supporting http3 by running go run ./test/http3/light-server.go -p LISTENING PORT (This is http3 equivalent of python3 -m http.server )
use test/http3/genkey.sh to generate cert and key. QUIC UDP aka http3 is a new generation Internet protocol that speeds online web applications that are susceptible to delay, such as searching, video streaming etc., by reducing the round-trip time (RTT) needed to connect to a server. Because QUIC uses proprietary encryption (https://www.kitploit.com/search/label/Encryption) equivalent to TLS (this will change in the future with a standardized version), 3rd generation firewalls (https://www.kitploit.com/search/label/Firewalls) that provide application control and visibility (https://www.kitploit.com/search/label/Visibility) encounter difficulties to control and monitor QUIC traffic. If you actually use fileless-xec as a dropper (Only for testing purpose or with the authorization), you likely want to execute some type of malwares or other file that could be drop by packet analysis. Hence, with Quic enables you could bypass packet analysis (https://www.kitploit.com/search/label/Packet%20Analysis) and GET a malware. Also, in case firewall is only used for allowing/blocking traffic it could happen that firewall rules forget the udp protocol making your requests go under the radars other skill for stealthiness Although not present on the memory disk, the running program can still be detected using ps command for example. Cover the tracks with a fake program name fileless-xec --name by default the name is [kworker/u:0] Detach from tty to map behaviour of deamon process setsid fileless-xec . WIP call setsid from code Caveats You could still be detected with: $ lsof | grep memfd
___________________________
@hacking_Attack
@Hacking_Video
You can setup a light web rootfs server supporting http3 by running go run ./test/http3/light-server.go -p LISTENING PORT (This is http3 equivalent of python3 -m http.server )
use test/http3/genkey.sh to generate cert and key. QUIC UDP aka http3 is a new generation Internet protocol that speeds online web applications that are susceptible to delay, such as searching, video streaming etc., by reducing the round-trip time (RTT) needed to connect to a server. Because QUIC uses proprietary encryption (https://www.kitploit.com/search/label/Encryption) equivalent to TLS (this will change in the future with a standardized version), 3rd generation firewalls (https://www.kitploit.com/search/label/Firewalls) that provide application control and visibility (https://www.kitploit.com/search/label/Visibility) encounter difficulties to control and monitor QUIC traffic. If you actually use fileless-xec as a dropper (Only for testing purpose or with the authorization), you likely want to execute some type of malwares or other file that could be drop by packet analysis. Hence, with Quic enables you could bypass packet analysis (https://www.kitploit.com/search/label/Packet%20Analysis) and GET a malware. Also, in case firewall is only used for allowing/blocking traffic it could happen that firewall rules forget the udp protocol making your requests go under the radars other skill for stealthiness Although not present on the memory disk, the running program can still be detected using ps command for example. Cover the tracks with a fake program name fileless-xec --name by default the name is [kworker/u:0] Detach from tty to map behaviour of deamon process setsid fileless-xec . WIP call setsid from code Caveats You could still be detected with: $ lsof | grep memfd
___________________________
@hacking_Attack
@Hacking_Video
GitHub
fileless-xec/usage.md at main · ariary/fileless-xec
Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...) - fileless-xec/usage.md at main · ariary/fileless-xec
Download Fileless-Xec (https://github.com/ariary/fileless-xec)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - ariary/fileless-xec: Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support…
Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...) - ariary/fileless-xec