Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Mortar - Evasion Technique To Defeat And Divert Detection And Prevention Of Security Products (AV/EDR/XDR)
https://blogger.googleusercontent.com/img/a/AVvXsEhvnvzhn-_TCLrXogCPlq79hBcS-wGNTuNd-3fNf_Vs2NthcX9cM52F3FFkSo8YXZHH1vyZj2FjUV9I8IhZ3QQAjBfnsvC-ro5kyhXuw5t2xO54UhGm6_pLLhrntvTMn_vN03zl7ww0N99_pJxB4g2rZ3n4ycpdqmDFJhKtJppYpiDKltQ_Wjjb4iOM=w640-h360
red teaming evasion technique to defeat and divert detection and prevention of security products.Mortar Loader performs encryption and decryption of selected binary inside the memory streams and execute it directly with out writing any malicious indicator into the hard-drive. Mortar is able to bypass modern anti-virus products and advanced XDR solutions and it has been tested and confirmed bypass for the following:
* Kaspersky
* ESET
* Malewarebytes
* Mcafee
* Cortex XDR
* Windows defender
* Cylance
* TrendMicro
detailed research and techniques : https://0xsp.com/security%20research%20&%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions
CrestCon Asia 2021 talk : https://www.youtube.com/watch?v=H7EMBz7GLMk
Usage
Encryptor
Loader (DLL)
for bypassing Cortex XDR,add agressor.dll with bin.enc in the same folder and script the following bat file
for normal usage you can directly execute the agressor.dll
Loader (EXE)
the executable version has more options you can use, as you able to pass commands for the loaded binary
Compiling the Loader (windows only)
the project has been coded using FPC(Free Pascal), the compiling procedures are straightforward by downloading and installing Lazarus IDE (https://www.lazarus-ide.org/index.php?page=downloads) and navigate into file > open -> Run -> build
Compiling Encryptor(Linux/BSD/Arm/MacOS//windows)
either by downloading and installing Lazarus-IDE from the official site(https://www.lazarus-ide.org/index.php?page=downloads)
Support the research
if you think you have benefited from this open-source project and want more updates in the future, please mind time and efforts by making a donation https://donorbox.org/support-0xsp
Download Mortar
___________________________
@hacking_Attack
@Hacking_Video
Mortar - Evasion Technique To Defeat And Divert Detection And Prevention Of Security Products (AV/EDR/XDR)
https://blogger.googleusercontent.com/img/a/AVvXsEhvnvzhn-_TCLrXogCPlq79hBcS-wGNTuNd-3fNf_Vs2NthcX9cM52F3FFkSo8YXZHH1vyZj2FjUV9I8IhZ3QQAjBfnsvC-ro5kyhXuw5t2xO54UhGm6_pLLhrntvTMn_vN03zl7ww0N99_pJxB4g2rZ3n4ycpdqmDFJhKtJppYpiDKltQ_Wjjb4iOM=w640-h360
red teaming evasion technique to defeat and divert detection and prevention of security products.Mortar Loader performs encryption and decryption of selected binary inside the memory streams and execute it directly with out writing any malicious indicator into the hard-drive. Mortar is able to bypass modern anti-virus products and advanced XDR solutions and it has been tested and confirmed bypass for the following:
* Kaspersky
* ESET
* Malewarebytes
* Mcafee
* Cortex XDR
* Windows defender
* Cylance
* TrendMicro
detailed research and techniques : https://0xsp.com/security%20research%20&%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions
CrestCon Asia 2021 talk : https://www.youtube.com/watch?v=H7EMBz7GLMk
Usage
Encryptor
root@kali>./encryptor -f mimikatz.exe -o bin.enc
Loader (DLL)
for bypassing Cortex XDR,add agressor.dll with bin.enc in the same folder and script the following bat file
@echo off
cmd.exe /c rundll32.exe agressor.dll,stealth
for normal usage you can directly execute the agressor.dll
rundll32.exe agressor.dll,dec
Loader (EXE)
the executable version has more options you can use, as you able to pass commands for the loaded binary
##Mimikatz dump LSA
deliver.exe -d -c sekurlsa::logonpasswords -f mimikatz.enc
## Cobalt strike beacon
deliver.exe -d -f cobalt.enc
Compiling the Loader (windows only)
the project has been coded using FPC(Free Pascal), the compiling procedures are straightforward by downloading and installing Lazarus IDE (https://www.lazarus-ide.org/index.php?page=downloads) and navigate into file > open -> Run -> build
Compiling Encryptor(Linux/BSD/Arm/MacOS//windows)
either by downloading and installing Lazarus-IDE from the official site(https://www.lazarus-ide.org/index.php?page=downloads)
#Debian & Ubuntu
apt install fpc
apt install lazarus-ide
Support the research
if you think you have benefited from this open-source project and want more updates in the future, please mind time and efforts by making a donation https://donorbox.org/support-0xsp
Download Mortar
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Mortar - Evasion Technique To Defeat And Divert Detection And Prevention Of Security Products (AV/EDR/XDR)
hacking: security in practice
I want to know what happened to our family computer back in late 2000’s.
So our family shared a desktop computer and at that time being no older than 5-6 years old, I had no knowledge of the dangers of clicking suspicious links or ads. I don’t believe my parents had either, because they still tend to click on sketchy links on facebook until this day. Here are some things I remember. The main tab didn’t look like Google at all, it was full of russian bookmarks. It was extremely laggy. The thing that creeped me out the most was slient male russian voices coming through the speakers. You could only hear them when the volume was turned off to the lowest, but when you slightly increased the volume, the voices disappeared. It sounded almost like a radio station. As I am more aware of these things now that I grew older, I am 100% sure the computer was hacked because of how the main tab looked like. But I don’t know about the voices part. Where were they coming from? Why could you only hear them when the volume was down? Could it have been that bad that someone could have watched us through the webcam? Please someone help me get the answers for something that haunts me ‘til this day. Also, sorry for my english, it’s not my native language. Thank you!
submitted by /u/D3composition
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I want to know what happened to our family computer back in late 2000’s.
So our family shared a desktop computer and at that time being no older than 5-6 years old, I had no knowledge of the dangers of clicking suspicious links or ads. I don’t believe my parents had either, because they still tend to click on sketchy links on facebook until this day. Here are some things I remember. The main tab didn’t look like Google at all, it was full of russian bookmarks. It was extremely laggy. The thing that creeped me out the most was slient male russian voices coming through the speakers. You could only hear them when the volume was turned off to the lowest, but when you slightly increased the volume, the voices disappeared. It sounded almost like a radio station. As I am more aware of these things now that I grew older, I am 100% sure the computer was hacked because of how the main tab looked like. But I don’t know about the voices part. Where were they coming from? Why could you only hear them when the volume was down? Could it have been that bad that someone could have watched us through the webcam? Please someone help me get the answers for something that haunts me ‘til this day. Also, sorry for my english, it’s not my native language. Thank you!
submitted by /u/D3composition
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I want to know what happened to our family computer back in late...
So our family shared a desktop computer and at that time being no older than 5-6 years old, I had no knowledge of the dangers of clicking...
EDR Parallel-asis through Analysis - @MDSecLabs
https://www.reddit.com/r/redteamsec/comments/ry777q/edr_parallelasis_through_analysis_mdseclabs/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mdsec.co.uk/2022/01/edr-parallel-asis-through-analysis/) [comments] (https://www.reddit.com/r/redteamsec/comments/ry777q/edr_parallelasis_through_analysis_mdseclabs/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ry777q/edr_parallelasis_through_analysis_mdseclabs/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mdsec.co.uk/2022/01/edr-parallel-asis-through-analysis/) [comments] (https://www.reddit.com/r/redteamsec/comments/ry777q/edr_parallelasis_through_analysis_mdseclabs/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
EDR Parallel-asis through Analysis - @MDSecLabs
Posted in r/redteamsec by u/dmchell • 3 points and 0 comments
Bypassing Door Passwords w/wo default passwords
https://www.reddit.com/r/redteamsec/comments/ry9pof/bypassing_door_passwords_wwo_default_passwords/
submitted by /u/SocketPuppets (https://www.reddit.com/user/SocketPuppets)
[link] (https://sockpuppets.medium.com/bypassing-door-passwords-4004b8d7995) [comments] (https://www.reddit.com/r/redteamsec/comments/ry9pof/bypassing_door_passwords_wwo_default_passwords/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ry9pof/bypassing_door_passwords_wwo_default_passwords/
submitted by /u/SocketPuppets (https://www.reddit.com/user/SocketPuppets)
[link] (https://sockpuppets.medium.com/bypassing-door-passwords-4004b8d7995) [comments] (https://www.reddit.com/r/redteamsec/comments/ry9pof/bypassing_door_passwords_wwo_default_passwords/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bypassing Door Passwords w/wo default passwords
Posted in r/redteamsec by u/SocketPuppets • 1 point and 0 comments
XXE — TryHackme WriteUp
https://infosecwriteups.com/xxe-tryhackme-writeup-29fb1e0e2666?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/xxe-tryhackme-writeup-29fb1e0e2666?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
XXE — TryHackme WriteUp
XML External Entity Writeup
XML External Entity WriteupContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/xxe-tryhackme-writeup-29fb1e0e2666?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
XXE — TryHackme WriteUp
XML External Entity Writeup
GYSR Bug Bounty Program
https://medium.com/gysr/gysr-bug-bounty-program-8a7617950e57?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/gysr/gysr-bug-bounty-program-8a7617950e57?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
GYSR Bug Bounty Program
Our highest priority has always been safety and security. Introducing the GYSR bug bounty program in partnership with Immunefi.
Our highest priority has always been safety and security. Introducing the GYSR bug bounty program in partnership with Immunefi.Continue reading on GYSR » (https://medium.com/gysr/gysr-bug-bounty-program-8a7617950e57?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
GYSR Bug Bounty Program
Our highest priority has always been safety and security. Introducing the GYSR bug bounty program in partnership with Immunefi.
Bypassing Door Passwords
https://sockpuppets.medium.com/bypassing-door-passwords-4004b8d7995?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sockpuppets.medium.com/bypassing-door-passwords-4004b8d7995?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bypassing Door Passwords
Instead of a key, this type of lock system requires a numerical code to grant entry to a facility or property. The code is punched in by…
Instead of a key, this type of lock system requires a numerical code to grant entry to a facility or property. The code is punched in by…Continue reading on Medium » (https://sockpuppets.medium.com/bypassing-door-passwords-4004b8d7995?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bypassing Door Passwords
Instead of a key, this type of lock system requires a numerical code to grant entry to a facility or property. The code is punched in by…
A Cool Account Takeover Vulnerability due to lack of Client Side Validation
Hello Everyone, My Name is Arth Bajpai , I’m from Lucknow India and this is my First writeup related to bug bountyContinue reading on Medium »
Read more...
Hello Everyone, My Name is Arth Bajpai , I’m from Lucknow India and this is my First writeup related to bug bountyContinue reading on Medium »
Read more...
Being Anonymous on the Internet(proxychains)
https://mirabbasagalarov.medium.com/being-anonymous-on-the-internet-proxychains-99837138c19e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://mirabbasagalarov.medium.com/being-anonymous-on-the-internet-proxychains-99837138c19e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Being Anonymous on the Internet(proxychains)
Proxy chains
Proxy chainsContinue reading on Medium » (https://mirabbasagalarov.medium.com/being-anonymous-on-the-internet-proxychains-99837138c19e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Being Anonymous on the Internet(proxychains)
Proxy chains
A Cool Account Takeover Vulnerability due to lack of Client Side Validation
https://medium.com/@arthbajpai277/hello-everyone-my-name-is-arth-bajpai-im-from-lucknow-india-and-this-is-my-first-writeup-2ec6a54226c5?source=rss------bug_bounty-5
Hello Everyone, My Name is Arth Bajpai , I’m from Lucknow India and this is my First writeup related to bug bountyContinue reading on Medium » (https://medium.com/@arthbajpai277/hello-everyone-my-name-is-arth-bajpai-im-from-lucknow-india-and-this-is-my-first-writeup-2ec6a54226c5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@arthbajpai277/hello-everyone-my-name-is-arth-bajpai-im-from-lucknow-india-and-this-is-my-first-writeup-2ec6a54226c5?source=rss------bug_bounty-5
Hello Everyone, My Name is Arth Bajpai , I’m from Lucknow India and this is my First writeup related to bug bountyContinue reading on Medium » (https://medium.com/@arthbajpai277/hello-everyone-my-name-is-arth-bajpai-im-from-lucknow-india-and-this-is-my-first-writeup-2ec6a54226c5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hello Everyone, My Name is Arth Bajpai , I’m from Lucknow India and this is my First writeup…
I have been asked multiple times , to do some write-ups on my findings, So here is one about my one of the recent findings for a awesome…