Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
d496f29cd6fe6d23463b28ae8233d65e2731a Deleted: sha256:116de39c14160d43d2a3fb24aed18b9c9b2228ae0d8e5cec533990c01548cf95 Deleted: sha256:b042ec9beedfd8aaa9b070900a080385ea705003a97633b2a3710b3a25c90740 Deleted: sha256:e68cb0e1bd2b8346e2de7dde87ae5d2b7dba3b1…
ramework
$ sudo ./deploy.sh -s 172.23.163.163 -a 10 -db

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((#
*** (((
[*] DETECTED PARAMETERS:
[!] INIT DB: TRUE
[!] GENERATE CA: FALSE
[!] GENERATE CERTS: FALSE
[!] GENERATE KEYS: FALSE
[!] GENERATE USERS: FALSE
[!] PUBLIC HOSTNAME: 172.23.163.163
[!] ASSETS COUNT: 10
[!] VPN NET CIDR: 10.11.0.0/16
[!] DOCKER OVPNSRV NAME: ovpnsrv
[!] DOCKER OVPNSRV ADDRESS: 10.10.0.2
[!] DOCKER HERDSRV NAME: herdsrv
[!] DOCKER HERDSRV ADDRESS: 10.10.0.3
[!] DOCKER HERDVIEW NAME: herdview
[!] DOCKER HERDVIEW ADDRESS: 10.10.0.5
[!] DOCKER FTPSRV NAME: ftpsrv
[!] DOCKER FTPSRV ADDRESS: 10.10.0.4
[!] DOCKER DSTRSRV NAME: dstrsrv
Continue? [y/N]: y

Certification Authority regeneration

Deploy the framework and regenerate the Certification Authority:

$ cd redherd-framework
$ sudo ./deploy.sh -s 172.23.163.163 -a 10 -ca

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((#
*** (((
[*] DETECTED PARAMETERS:
[!] INIT DB: FALSE
[!] GENERATE CA: TRUE
[!] GENERATE CERTS: TRUE
[!] GENERATE KEYS: FALSE
[!] GENERATE USERS: FALSE
[!] PUBLIC HOSTNAME: 172.23.163.163
[!] ASSETS COUNT: 10
[!] VPN NET CIDR: 10.11.0.0/16
[!] DOCKER OVPNSRV NAME: ovpnsrv
[!] DOCKER OVPNSRV ADDRESS: 10.10.0.2
[!] DOCKER HERDSRV NAME: herdsrv
[!] DOCKER HERDSRV ADDRESS: 10.10.0.3
[!] DOCKER HERDVIEW NAME: herdview
[!] DOCKER HERDVIEW ADDRESS: 10.10.0.5
[!] DOCKER FTPSRV NAME: ftpsrv
[!] DOCKER FTPSRV ADDRESS: 10.10.0.4
[!] DOCKER DSTRSRV NAME: dstrsrv
Continue? [y/N]: y

Distribution-Server credentials regeneration

Deploy the framework and regenerate all credentials relative to Distribution-Server:

$ cd redherd-framework
$ sudo ./deploy.sh -s 172.23.163.163 -a 10 -u

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((#
*** (((
[*] DETECTED PARAMETERS:
[!] INIT DB: FALSE
[!] GENERATE CA: FALSE
[!] GENERATE CERTS: FALSE
[!] GENERATE KEYS: FALSE
[!] GENERATE USERS: TRUE
[!] PUBLIC HOSTNAME: 172.23.163.163
[!] ASSETS COUNT: 10
[!] VPN NET CIDR: 10.11.0.0/16
[!] DOCKER OVPNSRV NAME: ovpnsrv
[!] DOCKER OVPNSRV ADDRESS: 10.10.0.2
[!] DOCKER HERDSRV NAME: herdsrv
[!] DOCKER HERDSRV ADDRESS: 10.10.0.3
[!] DOCKER HERDVIEW NAME: herdview
[!] DOCKER HERDVIEW ADDRESS: 10.10.0.5
[!] DOCKER FTPSRV NAME: ftpsrv
[!] DOCKER FTPSRV ADDRESS: 10.10.0.4
[!] DOCKER DSTRSRV NAME: dstrsrv
Continue? [y/N]: y

Client Management :: Intro

As for the asset also for the client we have tried to provide high flexibility and reduced interaction. Again, a one-line script interacts with Distribution-Server, downloads the user-related OpenVPNconfiguration file and initiates the VPN encrypted channel.

Docker

The dockerized client case is the most simple. The one-liner provided locally by the Herd-CLI creates an Ubuntu container that joins the infrastructure and allows the host machine to act as a client:

$ herd-cli endpoint -s 172.23.16.16 -o docker -m client -i 1

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
sudo docker run -d –rm –cap-add=NET_ADMIN –device /dev/net/tun -e DSTRSRV_PUBLIC_ADDRESS=”172.23.16.16″ -e USERNAME=”HyXqpOOx41″ -e PASSWORD=”l9tcuv6GKUDBYtcyt2fyEcktDE578cs1″ –network host -v $(pwd)/redherd-certificates:/usr/local/share/ca-certificates –name redherd-client redherd/client

Debian

It is just required to run the Herd-CLI one-[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ramework $ sudo ./deploy.sh -s 172.23.163.163 -a 10 -db * # ** (# ** ((# * #((# ( ( (((((( #(((( ((((((((((((((((((((# (((((((((((((((((( ** ((((((((((( (((((((# ( ((( _ _ _ _ _ * ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/ *** ((# *** ((( [*]…
liner on the Debian host:

$ herd-cli endpoint -s 172.23.16.16 -o debian -m client -i 1

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
sudo bash -c “apt update && apt install openvpn -y && curl -k -u HyXqpOOx41:l9tcuv6GKUDBYtcyt2fyEcktDE578cs1 https://172.23.16.16:8443/f6865d8c51bb7a1ba155bdfbeb3f686e/config.ovpn > ./redherd.ovpn && /usr/sbin/openvpn ./redherd.ovpn

Windows

Download and install the OpenVPN-Client, then use the PowerShellone-liner to download the OpenVPNconfiguration.

$ herd-cli endpoint -s 172.23.16.16 -o windows -m client -i 1

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** ((( $block = {
[Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}; $webclient = New-Object System.Net.WebClient; $basic = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes(“HyXqpOOx41” + “:” + “l9tcuv6GKUDBYtcyt2fyEcktDE578cs1”));$webclient.Headers[“Authorization”] = “Basic “;
$webclient.DownloadFile(“https://172.23.16.16:8443/f6865d8c51bb7a1ba155bdfbeb3f686e/config.ovpn”, “redherd.ovpn”)
}; powershell -ep bypass -nop -c $block
[!] Manually run OpenVPN with downloaded redherd.ovpn config file

Android

Download and install the OpenVPN-Client, then download the OpenVPNconfiguration from the provided link

$ herd-cli endpoint -s 172.23.16.16 -o android -m client -i 1

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
[!] Manually download the OpenVPN config file:
[!] Url: https://172.23.16.16:8443/f6865d8c51bb7a1ba155bdfbeb3f686e/config.ovpn
[!] Username: HyXqpOOx41
[!] Password: l9tcuv6GKUDBYtcyt2fyEcktDE578cs1
*

MacOS

Download and install the OpenVPN-Client, then use the Zshone-liner to download the OpenVPNconfiguration.

$ herd-cli endpoint -s 172.23.16.16 -o macos -m client -i 1

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
curl -k -u HyXqpOOx41:l9tcuv6GKUDBYtcyt2fyEcktDE578cs1 https://172.23.16.16:8443/f6865d8c51bb7a1ba155bdfbeb3f686e/config.ovpn > ./redherd.ovpn
[!] Manually run OpenVPN with the downloaded redherd.ovpnconfig file

Herd-View Access

After successfully joined the framework VPN, connect to Herd-View using a browser and visiting the URL https://10.10.0.5, then download the RedHerd Certification Authority certificate clicking on the upper-left button and install it in your system. Alternatively, you can obtain this certificate directly from https://10.10.0.3:3000/ca.crt.
https://blogger.googleusercontent.com/img/a/AVvXsEjK8Qjdqy8WxzQlxtLKatMYAPXsAUUDcPAV1wWMxIGfmgC6HH_Sky5JuygplXGZsLAu0kpuCoi4Hj-jIOjRy0P-be9XbVa4aUnOvVddb0tLU5_lbfWUmv4A2xZzzZdbK5tPPCrFHoXMYfcBpxxWR5KkDJwM6ncJHtsQasWT3NwBk0dG7xIXiGWrhlwq=s1611 https://blogger.googleusercontent.com/img/a/AVvXsEhxnpFmcdZfLT_Oku2N5Zau1GNLseCnunsMn8-4pdF9IghPXxgVjOHG-zJSEXodqv4hHhsmVqCxvoSkzmYaimznnPQYYpp5LpFO610GYiGcIn8lEhTicea8x_C9SmrPoWX1QjlsXDW_gjmeTW3PjBfDnylGxMaRQLeRLDTJtz06iqvcs5xEPZ4Gs4Zk=s443
Once the certificate has been trusted, it is possible to fill the login page with your user credentials.h
https://blogger.googleusercontent.com/img/a/AVvXsEjca3JhBQudge107Zgg45mst95iQisahLZwt6FAsbpbTmlXabUBKjeCG4EKmPEla-fgLbGSYu_q[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
liner on the Debian host: $ herd-cli endpoint -s 172.23.16.16 -o debian -m client -i 1 * # ** (# ** ((# * #((# ( ( (((((( #(((( ((((((((((((((((((((# (((((((((((((((((( ** ((((((((((( (((((((# ( ((( _ _ _ _ _ * ((( |/ | | \ || | |/ | \ **** (( | _ | |/ |…
qlNOlYg6zGFcUYVYbpBeDiAbe4AwJ2ExfV_f6xzVm8UmyWC0UzFAAAUObXoyFwKNRgCtxe2WFkG7YSyQ0oT7FTbWkUgkKgugzT7nerleohsHn4FB=s1613
Asset Management :: Intro

One of the aspects which is particularly relevant is the asset setup and join procedure. The implementation of this feature has been ruled by two design drivers: high flexibility and low user interaction. The former characteristic is needed in order to grant a remarkable level of compatibility with different operating systems, while the latter is fundamental to minimize failures and reduce the skills required to add a new asset to RedHerd. The result is a manually triggered yet fully automated procedure that involves only the execution of a one-linescript which is different for each compatible platform: Bashfor Android and Linux, PowerShellfor Windows and Zshfor MacOS.

This one-liner interacts with Distribution-Server and acts as a dropper downloading the full setup script and the related OpenVPNconfiguration file. The second stage fully configures the device in order to fulfill the framework requirements, i.e., dependencies management, certificate trusting, firewall and SSH daemon set up. Then, the VPN connection is initiated and the API are used to interact with Herd-Server and insert the new asset into the framework database. At this point, the asset is effectively part of the framework and so it is completely accessible by the operators.

Docker

Add

$ herd-cli endpoint -s 172.23.16.16 -o docker -m install -i 2

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
sudo docker run -d –rm –cap-add=NET_ADMIN –device /dev/net/tun -e DSTRSRV_PUBLIC_ADDRESS=”172.23.16.16″ -e USERNAME=”78l8zUBjpm” -e PASSWORD=”2GHDUWvZxtbn18LeiVoEv4UmhGv0rUrY” –privileged=true –network host –name redherd-asset redherd/asset

Remove

$ herd-cli endpoint -s 172.23.16.16 -o docker -m remove -i 2

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
sudo docker stop redherd-asset

Debian

Add

$ herd-cli endpoint -s 172.23.16.16 -o debian -m install -i 2 * # ** (# ** ((# *** #((# ****( (***** (((((( #(((( ******************* ((((((((((((((((((((# ***************** (((((((((((((((((( *********** ((((((((((( ******* (((((((# (***** ((( ______ _______ ______ _ _ _______ ______ ______ ***** ((( |_____/ |______ | \ |_____| |______ |_____/ | \ **** (( | \_ |______ |_____/ | | |______ | \_ |_____/ *** ((# Command-line Interface *** ((( sudo bash -c “curl -k -u 78l8zUBjpm:2GHDUWvZxtbn18LeiVoEv4UmhGv0rUrY https://172.23.16.16:8443/50f3331a80894d85bcda8c4b404a919c/debian_asset_setup.sh > /tmp/script.sh && chmod +x /tmp/script.sh && /tmp/script.sh install && rm -rf /tmp/script.sh

Remove

$ herd-cli endpoint -s 172.23.16.16 -o debian -m remove -i 2

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
sudo bash -c “curl -k -u 78l8zUBjpm:2GHDUWvZxtbn18LeiVoEv4UmhGv0rUrY https://172.23.16.16:8443/50f3331a80894d85bcda8c4b404a919c/debian_asset_setup.sh > /tmp/script.sh && chmod +x /tmp/script.sh && /tmp/script.sh remove && rm -rf /tmp/script.sh

CentOS

Add

$ herd-cli endpoint -s 172.23.16.16 -o centos -m install -i 2

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
sudo bash -c “curl -k -u 78l8zUBjpm:2GHDUWv[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
qlNOlYg6zGFcUYVYbpBeDiAbe4AwJ2ExfV_f6xzVm8UmyWC0UzFAAAUObXoyFwKNRgCtxe2WFkG7YSyQ0oT7FTbWkUgkKgugzT7nerleohsHn4FB=s1613 Asset Management :: Intro One of the aspects which is particularly relevant is the asset setup and join procedure. The implementation of…
Zxtbn18LeiVoEv4UmhGv0rUrY https://172.23.16.16:8443/50f3331a80894d85bcda8c4b404a919c/debian_asset_setup.sh > /tmp/script.sh && chmod +x /tmp/script.sh && /tmp/script.sh install && rm -rf /tmp/script.sh

Remove

$ herd-cli endpoint -s 172.23.16.16 -o centos -m remove -i 2

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** (((
sudo bash -c “curl -k -u 78l8zUBjpm:2GHDUWvZxtbn18LeiVoEv4UmhGv0rUrY https://172.23.16.16:8443/50f3331a80894d85bcda8c4b404a919c/debian_asset_setup.sh > /tmp/script.sh && chmod +x /tmp/script.sh && /tmp/script.sh remove && rm -rf /tmp/script.sh
*

Windows

Add

$ herd-cli endpoint -s 172.23.16.16 -o windows -m install -i 2

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** ((( $block = {
[Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}; $webclient = New-Object System.Net.WebClient; $basic = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes(“78l8zUBjpm” + “:” + “2GHDUWvZxtbn18LeiVoEv4UmhGv0rUrY”));$webclient.Headers[“Authorization”] = “Basic “;
$webclient.DownloadFile(“https://172.23.16.16:8443/50f3331a80894d85bcda8c4b404a919c/windows_asset_setup.psm1”, “script.psm1”)
Import-Module .\script.psm1; Add-Asset; Remove-Item .\script.psm1;
}; powershell -ep bypass -nop -c $bloc

Remove

$ herd-cli endpoint -s 172.23.16.16 -o windows -m remove -i 2

* #
** (#
** ((#
* #((# ( ( (((((( #((((
((((((((((((((((((((#
((((((((((((((((((
** (((((((((((
(((((((# ( ((( _ _ _ _ _
* ((( |/ | | \ || | |/ | \ **** (( | _ | |/ | | | | _ |/
*** ((# Command-line Interface
*** ((( $block = {
[Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}; $webclient = New-Object System.Net.WebClient; $basic = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes(“78l8zUBjpm” + “:” + “2GHDUWvZxtbn18LeiVoEv4UmhGv0rUrY”));$webclient.Headers[“Authorization”] = “Basic “;
$webclient.DownloadFile(“https://172.23.16.16:8443/50f3331a80894d85bcda8c4b404a919c/windows_asset_setup.psm1”, “script.psm1”)
Import-Module .\script.psm1; Remove-Asset; Remove-Item .\script.psm1;
}; powershell -ep bypass -nop -c $block

Asset Ban

During the RedHerd Framework lifecycle it is possible that some assets have to be excluded from the operative network due to kidnapping or simply for administrative reasons. This scenario could involve mainly two actions: Full Asset Ban and Single Asset Ban.

Full Asset Ban

In this situation the quickest method is to regeneratethe RedHerd Certification Authority, this action cuts off all assets contemporary.

Single Asset Ban

In this case Herd-CLI offers an administrative command which allows to revoke the VPN certificate assigned to a specific asset. This command is part of the asset realm and requires the asset name.

$ sudo herd-cli asset -b vVDNDUUGjb [-] Attempting to revoke client certificate [!] Certificate successfully revoked Download

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Cloud Adoption Widens the Cybersecurity Skills Gap

No matter what cloud services you employ, you are still responsible for protecting the security of your data.
Dark Reading: Attacks/Breaches
When Patching Security Flaws, Smarter Trumps Faster

Just turning the patch dial to "high" is not enough, and if your company is using the Common Vulnerability Scoring System (CVSS) to prioritize software patching, you are doing it wrong.