Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Elon Musk’s Private Jet Tracked – Teen Demands $500,00 to Stop – Read Right Now
https://external-preview.redd.it/xabXQEVv3BUtalOL-er8TsnNOLH8YBW7N93lyDIMLok.jpg?width=640&crop=smart&auto=webp&s=1fd74a62c98b63a45aa9aa0187fdfcbd5d903624 submitted by /u/businesstells
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Elon Musk’s Private Jet Tracked – Teen Demands $500,00 to Stop – Read Right Now
https://external-preview.redd.it/xabXQEVv3BUtalOL-er8TsnNOLH8YBW7N93lyDIMLok.jpg?width=640&crop=smart&auto=webp&s=1fd74a62c98b63a45aa9aa0187fdfcbd5d903624 submitted by /u/businesstells
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Elon Musk’s Private Jet Tracked – Teen Demands $500,00 to Stop –...
Posted in r/hacking by u/businesstells • 1 point and 0 comments
How I was able to buy a product for free — $$$
https://radianid.medium.com/how-i-was-able-to-buy-a-product-for-free-e91516409ffc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://radianid.medium.com/how-i-was-able-to-buy-a-product-for-free-e91516409ffc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I was able to buy a product for free — $$$
Hi everyone, I hope you are good. It’s been a long time I haven’t write again. So in this article I will share about my finding..
Hi everyone, I hope you are good. It’s been a long time I haven’t write again. So in this article I will share about my finding..Continue reading on Medium » (https://radianid.medium.com/how-i-was-able-to-buy-a-product-for-free-e91516409ffc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I was able to buy a product for free — $$$
Hi everyone, I hope you are good. It’s been a long time I haven’t write again. So in this article I will share about my finding..
Vulnerability Capstone — Tryhackme
https://mukibas37.medium.com/vulnerability-capstone-tryhackme-b0e520720dcf?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://mukibas37.medium.com/vulnerability-capstone-tryhackme-b0e520720dcf?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnerability Capstone — Tryhackme
Vulnerability Researching
Vulnerability ResearchingContinue reading on Medium » (https://mukibas37.medium.com/vulnerability-capstone-tryhackme-b0e520720dcf?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnerability Capstone — Tryhackme
Vulnerability Researching
rDEX Bug Bounty
https://olalekanalaka11.medium.com/rdex-bug-bounty-789934e94ff1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://olalekanalaka11.medium.com/rdex-bug-bounty-789934e94ff1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
rDEX Bug Bounty
Overview
OverviewContinue reading on Medium » (https://olalekanalaka11.medium.com/rdex-bug-bounty-789934e94ff1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
rDEX Bug Bounty
Overview
XSS Discovery and Exploitation With BurpSuite
https://medium.com/@kaorrosi/xss-discovery-and-exploitation-with-burpsuite-91d98865c1ee?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@kaorrosi/xss-discovery-and-exploitation-with-burpsuite-91d98865c1ee?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS Discovery and Exploitation With BurpSuite
I’ve recently completed TryHackMe’s cross-site-scripting room and PortSwigger’s XSS labs and here’s what I’ve learned! This piece assumes…
I’ve recently completed TryHackMe’s cross-site-scripting room and PortSwigger’s XSS labs and here’s what I’ve learned! This piece assumes…Continue reading on Medium » (https://medium.com/@kaorrosi/xss-discovery-and-exploitation-with-burpsuite-91d98865c1ee?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS Discovery and Exploitation With BurpSuite
I’ve recently completed TryHackMe’s cross-site-scripting room and PortSwigger’s XSS labs and here’s what I’ve learned! This piece assumes…
Bluffy - Convert Shellcode Into Different Formats!
http://www.kitploit.com/2022/01/bluffy-convert-shellcode-into-different.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/01/bluffy-convert-shellcode-into-different.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Bluffy - Convert Shellcode Into Different Formats!
Bluffy is a utility which was used in experiments to bypass Anti-Virus products (statically) by formatting shellcode into realistic looking data formats. Proof-of-concept tools, such as 0xBoku (https://twitter.com/0xBoku)'s Ninja_UUID_Runner (https://github.com/boku7/Ninja_UUID_Runner) and ChoiSG (https://github.com/ChoiSG)'s UuidShellcodeExec (https://github.com/ChoiSG/UuidShellcodeExec), inspired the initial concept for Bluffy. So far, we implemented: UUID CLSID SVG CSS CSV
Help payload prior to C formatting --list List all the available masks">$ python3 bluffy.py -h
⣇⣿⠘⣿⣿⣿⡿⡿⣟⣟⢟⢟⢝⠵⡝⣿⡿⢂⣼⣿⣷⣌⠩⡫⡻⣝⠹⢿⣿⣷
⡆⣿⣆⠱⣝⡵⣝⢅⠙⣿⢕⢕⢕⢕⢝⣥⢒⠅⣿⣿⣿⡿⣳⣌⠪⡪⣡⢑⢝⣇
⡆⣿⣿⣦⠹⣳⣳⣕⢅⠈⢗⢕⢕⢕⢕⢕⢈⢆⠟⠋⠉⠁⠉⠉⠁⠈⠼⢐⢕⢽
⡗⢰⣶⣶⣦⣝⢝⢕⢕⠅⡆⢕⢕⢕⢕⢕⣴⠏⣠& #10358;⠛⡉⡉⡛⢶⣦⡀⠐⣕⢕
⡝⡄⢻⢟⣿⣿⣷⣕⣕⣅⣿⣔⣕⣵⣵⣿⣿⢠⣿⢠⣮⡈⣌⠨⠅⠹⣷⡀⢱⢕
⡝⡵⠟⠈⢀⣀⣀⡀⠉⢿⣿⣿⣿⣿⣿⣿⣿⣼⣿⢈⡋⠴⢿⡟⣡⡇⣿⡇⡀⢕
⡝⠁⣠⣾⠟⡉⡉⡉⠻⣦⣻⣿⣿⣿⣿⣿⣿⣿⣿⣧⠸⣿⣦⣥⣿⡇⡿⣰⢗⢄
⠁⢰⣿⡏⣴⣌⠈⣌⠡⠈⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿&# 10495;⣬⣉⣉⣁⣄⢖⢕⢕⢕
⡀⢻⣿⡇⢙⠁⠴⢿⡟⣡⡆⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣵⣵⣿
⡻⣄⣻⣿⣌⠘⢿⣷⣥⣿⠇⣿⣿⣿⣿⣿⣿⠛⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿
⣷⢄⠻⣿⣟⠿⠦⠍⠉⣡⣾⣿⣿⣿⣿⣿⣿⢸⣿⣦⠙⣿⣿⣿⣿⣿⣿⣿⣿⠟
⡕⡑⣑⣈⣻⢗⢟⢞⢝⣻⣿⣿⣿⣿⣿⣿⣿⠸⣿⠿⠃ 0495;⣿⣿⣿⣿⣿⡿⠁⣠
⡝⡵⡈⢟⢕⢕⢕⢕⣵⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣶⣿⣿⣿⣿⣿⠿⠋⣀⣈⠙
⡝⡵⡕⡀⠑⠳⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⢉⡠⡲⡫⡪⡪⡣
Convert shellcode into ✨ different ✨ formats!
Written by:
~ Mez0
~ Michael Ranaldo
usage: Bluffy [-h] -b -o -m
optional arguments:
-h, --help show this help message and exit
-b , --bin Specify bin file to load
-m , --mask Specify the mask for the shellcode
-x , --xor XOR the payload
-p , --preview Preview the created format
-pp, --payload_preview Preview the payload prior to C formatting
--list List all the available masks
Written by: Michael Ranaldo (https://twitter.com/michaeljranaldo) Mez0 (https://twitter.com/__mez0__) Requirements and installation The following items must be installed prior to using Bluff: python3.9 or greater: sudo apt install python3.9 rich: sudo pip3 install rich pcre2.8: Depending on whether its going to be ran on Kali, Ubuntu 18, 19, 20, and so on, the process of getting and building with pcre2.8 may be different. For us on Ubuntu, it was developed on: $ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 21.04
Release: 21.04
Codename: hirsute
In order to link libpcre2-8.a, the .a file had to be included within: /usr/lib/gcc/x86_64-w64-mingw32/10-win32
As for obtaining the header and lib files, MSYS2 (https://packages.msys2.org/base/mingw-w64-pcre2) was used. But if you're smarter than us, then just do it from source for Mingw64: https://pcre.org/. The simplest way to thus acquire and install is to run the following commands (after double checking your architecture etc.): sudo apt install mingw-64
sudo wget https://packages.msys2.org/package/mingw-w64-x86_64-pcre2?repo=mingw64 -P /usr/lib/gcc/x86_64-w64-mingw32/10-win32 Using Bluffy To build a payload, get your binary (https://www.kitploit.com/search/label/Binary) file. For this example, we used calc.bin, which just loads calc.exe as a proof of concept. As Bluffy only seeks to evade static analysis (https://www.kitploit.com/search/label/Analysis) using steganography, by hiding the binary within an otherwise innocuous file, you will need to do further research (https://www.kitploit.com/search/label/Research) to ensure that your payload also evades dynamic detection. Run bluffy, choosing a mask of your choice and providing your .bin file: python ./bluffy.py -b calc.bin -m css -x Check your payload, then build it. To build your payload, copy the .h file bluffy creates, rename it css.c, run make to build it to an executable, then test using the included examples directory: mv css.h examples/css/css.h
cd examples/css
make
This will use the included "main.c" to build an Windows (https://www.kitploit.com/search/label/Windows) executable. Test this to confirm. If you have also used calc.bin, you should be greeted by a new Calc window opening. If so, congratulations! For more details on using Bluffy and
___________________________
@hacking_Attack
@Hacking_Video
Help payload prior to C formatting --list List all the available masks">$ python3 bluffy.py -h
⣇⣿⠘⣿⣿⣿⡿⡿⣟⣟⢟⢟⢝⠵⡝⣿⡿⢂⣼⣿⣷⣌⠩⡫⡻⣝⠹⢿⣿⣷
⡆⣿⣆⠱⣝⡵⣝⢅⠙⣿⢕⢕⢕⢕⢝⣥⢒⠅⣿⣿⣿⡿⣳⣌⠪⡪⣡⢑⢝⣇
⡆⣿⣿⣦⠹⣳⣳⣕⢅⠈⢗⢕⢕⢕⢕⢕⢈⢆⠟⠋⠉⠁⠉⠉⠁⠈⠼⢐⢕⢽
⡗⢰⣶⣶⣦⣝⢝⢕⢕⠅⡆⢕⢕⢕⢕⢕⣴⠏⣠& #10358;⠛⡉⡉⡛⢶⣦⡀⠐⣕⢕
⡝⡄⢻⢟⣿⣿⣷⣕⣕⣅⣿⣔⣕⣵⣵⣿⣿⢠⣿⢠⣮⡈⣌⠨⠅⠹⣷⡀⢱⢕
⡝⡵⠟⠈⢀⣀⣀⡀⠉⢿⣿⣿⣿⣿⣿⣿⣿⣼⣿⢈⡋⠴⢿⡟⣡⡇⣿⡇⡀⢕
⡝⠁⣠⣾⠟⡉⡉⡉⠻⣦⣻⣿⣿⣿⣿⣿⣿⣿⣿⣧⠸⣿⣦⣥⣿⡇⡿⣰⢗⢄
⠁⢰⣿⡏⣴⣌⠈⣌⠡⠈⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿&# 10495;⣬⣉⣉⣁⣄⢖⢕⢕⢕
⡀⢻⣿⡇⢙⠁⠴⢿⡟⣡⡆⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣵⣵⣿
⡻⣄⣻⣿⣌⠘⢿⣷⣥⣿⠇⣿⣿⣿⣿⣿⣿⠛⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿
⣷⢄⠻⣿⣟⠿⠦⠍⠉⣡⣾⣿⣿⣿⣿⣿⣿⢸⣿⣦⠙⣿⣿⣿⣿⣿⣿⣿⣿⠟
⡕⡑⣑⣈⣻⢗⢟⢞⢝⣻⣿⣿⣿⣿⣿⣿⣿⠸⣿⠿⠃ 0495;⣿⣿⣿⣿⣿⡿⠁⣠
⡝⡵⡈⢟⢕⢕⢕⢕⣵⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣶⣿⣿⣿⣿⣿⠿⠋⣀⣈⠙
⡝⡵⡕⡀⠑⠳⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⢉⡠⡲⡫⡪⡪⡣
Convert shellcode into ✨ different ✨ formats!
Written by:
~ Mez0
~ Michael Ranaldo
usage: Bluffy [-h] -b -o -m
optional arguments:
-h, --help show this help message and exit
-b , --bin Specify bin file to load
-m , --mask Specify the mask for the shellcode
-x , --xor XOR the payload
-p , --preview Preview the created format
-pp, --payload_preview Preview the payload prior to C formatting
--list List all the available masks
Written by: Michael Ranaldo (https://twitter.com/michaeljranaldo) Mez0 (https://twitter.com/__mez0__) Requirements and installation The following items must be installed prior to using Bluff: python3.9 or greater: sudo apt install python3.9 rich: sudo pip3 install rich pcre2.8: Depending on whether its going to be ran on Kali, Ubuntu 18, 19, 20, and so on, the process of getting and building with pcre2.8 may be different. For us on Ubuntu, it was developed on: $ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 21.04
Release: 21.04
Codename: hirsute
In order to link libpcre2-8.a, the .a file had to be included within: /usr/lib/gcc/x86_64-w64-mingw32/10-win32
As for obtaining the header and lib files, MSYS2 (https://packages.msys2.org/base/mingw-w64-pcre2) was used. But if you're smarter than us, then just do it from source for Mingw64: https://pcre.org/. The simplest way to thus acquire and install is to run the following commands (after double checking your architecture etc.): sudo apt install mingw-64
sudo wget https://packages.msys2.org/package/mingw-w64-x86_64-pcre2?repo=mingw64 -P /usr/lib/gcc/x86_64-w64-mingw32/10-win32 Using Bluffy To build a payload, get your binary (https://www.kitploit.com/search/label/Binary) file. For this example, we used calc.bin, which just loads calc.exe as a proof of concept. As Bluffy only seeks to evade static analysis (https://www.kitploit.com/search/label/Analysis) using steganography, by hiding the binary within an otherwise innocuous file, you will need to do further research (https://www.kitploit.com/search/label/Research) to ensure that your payload also evades dynamic detection. Run bluffy, choosing a mask of your choice and providing your .bin file: python ./bluffy.py -b calc.bin -m css -x Check your payload, then build it. To build your payload, copy the .h file bluffy creates, rename it css.c, run make to build it to an executable, then test using the included examples directory: mv css.h examples/css/css.h
cd examples/css
make
This will use the included "main.c" to build an Windows (https://www.kitploit.com/search/label/Windows) executable. Test this to confirm. If you have also used calc.bin, you should be greeted by a new Calc window opening. If so, congratulations! For more details on using Bluffy and
___________________________
@hacking_Attack
@Hacking_Video
X (formerly Twitter)
Bobby Cooke (@0xBoku) on X
Adversary Services @ IBM X-Force Red
a walkthrough of how it works and what the output looks like, check out our blog (https://ad-995.group/posts/bluffy/bluffy.html) Here is a full example: ✨ different ✨ formats! (17)">
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video