Hacking on Medium
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve…
https://cdn-images-1.medium.com/max/600/1*J4n0kSbU9ev1MHaoR_rf2A.jpeg
Bu yazı serisinde bir siber saldırı türü olan MITM(ortadaki adam) saldırısı hakkında bilgileri derlediğim ve örneklerinin…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve…
https://cdn-images-1.medium.com/max/600/1*J4n0kSbU9ev1MHaoR_rf2A.jpeg
Bu yazı serisinde bir siber saldırı türü olan MITM(ortadaki adam) saldırısı hakkında bilgileri derlediğim ve örneklerinin…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve Gerçekleştirilmesi #1
Bu yazı serisinde bir siber saldırı türü olan MITM(ortadaki adam) saldırısı hakkında bilgileri derlediğim ve örneklerinin…
Hacking on Medium
Documents reveal depth of anxiety over possible Russian cyberattacks on U.S. grid
https://cdn-images-1.medium.com/max/1400/1*ev0D1VZgIHPjbxOtgpoGMg.png
A trove of emails from top Homeland Security officials expose how the U.S. government scrambled to ensure the defenses of American…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Documents reveal depth of anxiety over possible Russian cyberattacks on U.S. grid
https://cdn-images-1.medium.com/max/1400/1*ev0D1VZgIHPjbxOtgpoGMg.png
A trove of emails from top Homeland Security officials expose how the U.S. government scrambled to ensure the defenses of American…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Documents reveal depth of anxiety over possible Russian cyberattacks on U.S. grid
A trove of emails from top Homeland Security officials expose how the U.S. government scrambled to ensure the defenses of American…
Hacking on Medium
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve…
https://cdn-images-1.medium.com/max/612/1*s4fuJxYQijFrtQBeqgSsqQ.jpeg
Serinin ikinci yazısında ilk yazıda kali komutları ile gerçekleştirilen saldırının, bettercap adı verilen bir yazılımla gerçekleştirerek…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve…
https://cdn-images-1.medium.com/max/612/1*s4fuJxYQijFrtQBeqgSsqQ.jpeg
Serinin ikinci yazısında ilk yazıda kali komutları ile gerçekleştirilen saldırının, bettercap adı verilen bir yazılımla gerçekleştirerek…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve Gerçekleştirilmesi #2
Serinin ikinci yazısında ilk yazıda kali komutları ile gerçekleştirilen saldırının, bettercap adı verilen bir yazılımla gerçekleştirerek…
Hacking on Medium
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve…
https://cdn-images-1.medium.com/max/612/1*_CjNzhr6aoEPIYupysfqoA.png
Serinin son yazısında kali komutları ve bettercap http siteler üzerinden bilgilerin dinlenerek alınmasından bahsedilmişti. Bu yazıda ise…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve…
https://cdn-images-1.medium.com/max/612/1*_CjNzhr6aoEPIYupysfqoA.png
Serinin son yazısında kali komutları ve bettercap http siteler üzerinden bilgilerin dinlenerek alınmasından bahsedilmişti. Bu yazıda ise…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kali Linux Ve Bettercap Kullanarak MITM Saldırısı ile Arp, DNS Spoofing Saldırısı Ve Gerçekleştirilmesi #3
Serinin son yazısında kali komutları ve bettercap http siteler üzerinden bilgilerin dinlenerek alınmasından bahsedilmişti. Bu yazıda ise…
Hacking on Medium
Your SIM Card Can Get Hacked, And Hackers Can Use It To Steal Your Entire Bank Savings!
https://cdn-images-1.medium.com/max/2400/1*kURJcZT5oVFsQptd6CE5Cw.jpeg
Cyber hackers have discovered a very clever way to plunder money without making too much effort on their part.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Your SIM Card Can Get Hacked, And Hackers Can Use It To Steal Your Entire Bank Savings!
https://cdn-images-1.medium.com/max/2400/1*kURJcZT5oVFsQptd6CE5Cw.jpeg
Cyber hackers have discovered a very clever way to plunder money without making too much effort on their part.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Your SIM Card Can Get Hacked, And Hackers Can Use It To Steal Your Entire Bank Savings!
Cyber hackers have discovered a very clever way to plunder money without making too much effort on their part.
Hacking on Medium
Bracing for cyberattacks as Russia readies for war
https://cdn-images-1.medium.com/max/1400/1*rp2DJeX_bWG2RmOovWwN2g.png
Welcome to Changelog for 2/13/22, published by Synack! I’m your host, Blake. From some pretty serious Apple patches to a disheartening…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Bracing for cyberattacks as Russia readies for war
https://cdn-images-1.medium.com/max/1400/1*rp2DJeX_bWG2RmOovWwN2g.png
Welcome to Changelog for 2/13/22, published by Synack! I’m your host, Blake. From some pretty serious Apple patches to a disheartening…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bracing for cyberattacks as Russia readies for war
Welcome to Changelog for 2/13/22, published by Synack! I’m your host, Blake. From some pretty serious Apple patches to a disheartening…
Hacking on Medium
CH4INRULZ: 1.0.1 VM WalkThrough
https://cdn-images-1.medium.com/max/804/0*wWK5GtcUPxE2gouP
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CH4INRULZ: 1.0.1 VM WalkThrough
https://cdn-images-1.medium.com/max/804/0*wWK5GtcUPxE2gouP
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CH4INRULZ: 1.0.1 VM WalkThrough
Makineyi indirebilirsiniz.
KitPloit - PenTest Tools!
Exrop - Automatic ROP Chain Generation
___________________________
@hacking_Attack
@Hacking_Video
Exrop - Automatic ROP Chain Generation
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Exrop - Automatic ROP Chain Generation
Exrop - Automatic ROP Chain Generation
http://www.kitploit.com/2022/02/exrop-automatic-rop-chain-generation.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/exrop-automatic-rop-chain-generation.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Exrop - Automatic ROP Chain Generation
Exrop is automatic ROP chains generator (https://www.kitploit.com/search/label/Generator) tool which can build gadget chain automatically from given binary and constraints Requirements : Triton (https://github.com/JonathanSalwan/Triton), ROPGadget (https://github.com/JonathanSalwan/ROPgadget) Only support for x86-64 for now! Features: handling non-return gadgets (https://www.kitploit.com/search/label/Gadgets) (jmp reg, call reg) set registers (rdi=0xxxxxx, rsi=0xxxxxx) set register to register (rdi=rax) write to mem write string/bytes to mem function call (open('/etc/passwd',0)) pass register in function call (read('rax', bss, 0x100)) avoiding badchars stack pivoting (https://www.kitploit.com/search/label/Pivoting) (Exrop.stack_pivot) syscall (Exrop.syscall) see examples (https://github.com/d4em0n/exrop/blob/master/examples)
Installation install python (3.6 is recomended and tested) install triton (https://triton.quarkslab.com/documentation/doxygen/index.html#linux_install_sec), make sure you add -DPYTHON36=on as cmake option install ropgadget (https://www.kitploit.com/search/label/ROPgadget) (https://github.com/JonathanSalwan/ROPgadget) to install exrop, easily add export PYTHONPATH=/path/to/exrop:$PYTHONPATH in your .bashrc (depends on your shell) Demo from Exrop import Exrop
rop = Exrop("/bin/ls")
rop.find_gadgets(cache=True)
print("write-regs gadgets: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545")
chain = rop.set_regs({'rdi':0x41414141, 'rsi': 0x42424242, 'rdx':0x43434343, 'rax':0x44444444, 'rbx': 0x45454545})
chain.dump()
print("write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011")
chain = rop.set_writes({0x41414141: 0xdeadbeefff, 0x43434343: 0x00110011})
chain.dump()
print("write-string gadgets 0x41414141=\"Hello world!\\n\"")
chain = rop.set_string({0x41414141: "Hello world!\n"})
chain.dump()
print("func-call gadgets 0x41414141(0x20, 0x30, \"Hello\")")
chain = rop.func_call(0x41414141, (0x20, 0x30, "Hello"), 0x7fffff00)
chain.dump() Output: write-regs gadget: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545
$RSP+0x0000 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0008 : 0x0000000044444444
$RSP+0x0010 : 0x0000000000014852 # mov rax, rbx; pop rbx; ret
$RSP+0x0018 : 0x0000000000000000
$RSP+0x0020 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0028 : 0x0000000041414141
$RSP+0x0030 : 0x000000000000629c # pop rsi; ret
$RSP+0x0038 : 0x0000000042424242
$RSP+0x0040 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0048 : 0x0000000043434343
$RSP+0x0050 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0058 : 0x0000000045454545
write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x000000deadbeefff
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0 x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000110011
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x000000004343433b
$RSP+0x0058 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
write-string gadgets 0x41414141="Hello world!\n"
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x6f77206f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000a21646c72
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x0000000041414141
$RSP+0x0058 : 0x000000000000e0 fb # mov qword ptr [rdi + 8], rax; ret
func-call gadgets 0x41414141(0x20, 0x30, "Hello")
___________________________
@hacking_Attack
@Hacking_Video
Installation install python (3.6 is recomended and tested) install triton (https://triton.quarkslab.com/documentation/doxygen/index.html#linux_install_sec), make sure you add -DPYTHON36=on as cmake option install ropgadget (https://www.kitploit.com/search/label/ROPgadget) (https://github.com/JonathanSalwan/ROPgadget) to install exrop, easily add export PYTHONPATH=/path/to/exrop:$PYTHONPATH in your .bashrc (depends on your shell) Demo from Exrop import Exrop
rop = Exrop("/bin/ls")
rop.find_gadgets(cache=True)
print("write-regs gadgets: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545")
chain = rop.set_regs({'rdi':0x41414141, 'rsi': 0x42424242, 'rdx':0x43434343, 'rax':0x44444444, 'rbx': 0x45454545})
chain.dump()
print("write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011")
chain = rop.set_writes({0x41414141: 0xdeadbeefff, 0x43434343: 0x00110011})
chain.dump()
print("write-string gadgets 0x41414141=\"Hello world!\\n\"")
chain = rop.set_string({0x41414141: "Hello world!\n"})
chain.dump()
print("func-call gadgets 0x41414141(0x20, 0x30, \"Hello\")")
chain = rop.func_call(0x41414141, (0x20, 0x30, "Hello"), 0x7fffff00)
chain.dump() Output: write-regs gadget: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545
$RSP+0x0000 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0008 : 0x0000000044444444
$RSP+0x0010 : 0x0000000000014852 # mov rax, rbx; pop rbx; ret
$RSP+0x0018 : 0x0000000000000000
$RSP+0x0020 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0028 : 0x0000000041414141
$RSP+0x0030 : 0x000000000000629c # pop rsi; ret
$RSP+0x0038 : 0x0000000042424242
$RSP+0x0040 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0048 : 0x0000000043434343
$RSP+0x0050 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0058 : 0x0000000045454545
write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x000000deadbeefff
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0 x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000110011
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x000000004343433b
$RSP+0x0058 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
write-string gadgets 0x41414141="Hello world!\n"
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x6f77206f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000a21646c72
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x0000000041414141
$RSP+0x0058 : 0x000000000000e0 fb # mov qword ptr [rdi + 8], rax; ret
func-call gadgets 0x41414141(0x20, 0x30, "Hello")
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x0000006f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x000000007ffffef8
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000000020
$RSP+0x0040 : 0x000000000000629c # pop rsi; ret
$RSP+0x0048 : 0x0000000000000030
$RSP+0x0050 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0058 : 0x000000007fffff00
$RSP+0x0060 : 0x0000000041414141
python3 tests.py 1,48s user 0,05s system 97% cpu 1,566 total
Another example: open-read-write gadgets! from pwn import *
import time
from Exrop import Exrop
binname = "/lib/x86_64-linux-gnu/libc.so.6"
libc = ELF(binname, checksec=False)
open = libc.symbols['open']
read = libc.symbols['read']
write = libc.symbols['write']
bss = libc.bss()
t = time.mktime(time.gmtime())
rop = Exrop(binname)
rop.find_gadgets(cache=True)
print("open('/etc/passwd', 0)")
chain = rop.func_call(open, ("/etc/passwd", 0), bss)
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("read('rax', bss, 0x100)") # register can be used as argument too!
chain = rop.func_call(read, ('rax', bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("write(1, bss, 0x100)")
chain = rop.func_call(write, (1, bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("done in {}s".format(time.mktime(time.gmtime ()) - t)) Output: (0x0002155f) # pop rdi ; ret $RSP+0x0038 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0040 : 0x7361702f6374652f $RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret $RSP+0x0058 : 0x00000000003ec868 $RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret $RSP+0x0068 : 0x00007ffff7a0555f $RSP+0x0070 : 0x0000000000000000 $RSP+0x0078 : 0x0000000000000000 $RSP+0x0080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0090 : 0x0000000000647773 $RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret $RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x00b0 : 0x00000000003ec860 $RSP+0x00b8 : 0x000000000010fc40 read('rax', bss, 0x100) $RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret $RSP+0x0008 : 0x0000000000000000 $RSP+0x0010 : 0x0000000000000000 $RSP+0x0018 : 0x00007ffff7a0555f $RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret $RSP+0x0030 : 0x00007ffff79e5b96 $RSP+0x0038 : 0x0000000000000000 $RSP+0x0040 : 0x0000000000000000 $RSP+0x0048 : 0x00007ffff7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret $RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0058 : 0x0000000000000100 $RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0068 : 0x00000000003ec860 $RSP+0x0070 : 0x0000000000110070 write(1, bss, 0x100) $RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0008 : 0x0000000000000001 $RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0018 : 0x0000000000000100 $RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0028 : 0x00000000003ec860 $RSP+0x0030 : 0x0000000000110140 done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))">open('/etc/passwd', 0)
$RSP+0x0000 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0008 : 0x00000000003ec860
$RSP+0x0010 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x0000000000000000
$RSP+0x0028 : 0x0000000000000000
$RSP+0x0030 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
___________________________
@hacking_Attack
@Hacking_Video
$RSP+0x0008 : 0x0000006f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x000000007ffffef8
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000000020
$RSP+0x0040 : 0x000000000000629c # pop rsi; ret
$RSP+0x0048 : 0x0000000000000030
$RSP+0x0050 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0058 : 0x000000007fffff00
$RSP+0x0060 : 0x0000000041414141
python3 tests.py 1,48s user 0,05s system 97% cpu 1,566 total
Another example: open-read-write gadgets! from pwn import *
import time
from Exrop import Exrop
binname = "/lib/x86_64-linux-gnu/libc.so.6"
libc = ELF(binname, checksec=False)
open = libc.symbols['open']
read = libc.symbols['read']
write = libc.symbols['write']
bss = libc.bss()
t = time.mktime(time.gmtime())
rop = Exrop(binname)
rop.find_gadgets(cache=True)
print("open('/etc/passwd', 0)")
chain = rop.func_call(open, ("/etc/passwd", 0), bss)
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("read('rax', bss, 0x100)") # register can be used as argument too!
chain = rop.func_call(read, ('rax', bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("write(1, bss, 0x100)")
chain = rop.func_call(write, (1, bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("done in {}s".format(time.mktime(time.gmtime ()) - t)) Output: (0x0002155f) # pop rdi ; ret $RSP+0x0038 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0040 : 0x7361702f6374652f $RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret $RSP+0x0058 : 0x00000000003ec868 $RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret $RSP+0x0068 : 0x00007ffff7a0555f $RSP+0x0070 : 0x0000000000000000 $RSP+0x0078 : 0x0000000000000000 $RSP+0x0080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0090 : 0x0000000000647773 $RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret $RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x00b0 : 0x00000000003ec860 $RSP+0x00b8 : 0x000000000010fc40 read('rax', bss, 0x100) $RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret $RSP+0x0008 : 0x0000000000000000 $RSP+0x0010 : 0x0000000000000000 $RSP+0x0018 : 0x00007ffff7a0555f $RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret $RSP+0x0030 : 0x00007ffff79e5b96 $RSP+0x0038 : 0x0000000000000000 $RSP+0x0040 : 0x0000000000000000 $RSP+0x0048 : 0x00007ffff7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret $RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0058 : 0x0000000000000100 $RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0068 : 0x00000000003ec860 $RSP+0x0070 : 0x0000000000110070 write(1, bss, 0x100) $RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0008 : 0x0000000000000001 $RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0018 : 0x0000000000000100 $RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0028 : 0x00000000003ec860 $RSP+0x0030 : 0x0000000000110140 done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))">open('/etc/passwd', 0)
$RSP+0x0000 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0008 : 0x00000000003ec860
$RSP+0x0010 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x0000000000000000
$RSP+0x0028 : 0x0000000000000000
$RSP+0x0030 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
___________________________
@hacking_Attack
@Hacking_Video
$RSP+0x0038 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0040 : 0x7361702f6374652f
$RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0058 : 0x00000000003ec868
$RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0068 : 0x00007ffff7a0555f
$RSP+0x0070 : 0x0000000000000000
$RSP+0x0078 : 0x0000000000000000
$RSP+0x0 080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0090 : 0x0000000000647773
$RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret
$RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x00b0 : 0x00000000003ec860
$RSP+0x00b8 : 0x000000000010fc40
read('rax', bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret
$RSP+0x0008 : 0x0000000000000000
$RSP+0x0010 : 0x0000000000000000
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret
$RSP+0x0030 : 0x00007ffff79e5b96
$RSP+0x0038 : 0x0000000000000000
$RSP+0x0040 : 0x0000000000000000
$RSP+0x0048 : 0x00007fff f7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret
$RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0058 : 0x0000000000000100
$RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0068 : 0x00000000003ec860
$RSP+0x0070 : 0x0000000000110070
write(1, bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0008 : 0x0000000000000001
$RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0018 : 0x0000000000000100
$RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0028 : 0x00000000003ec860
$RSP+0x0030 : 0x0000000000110140
done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))
Download Exrop (https://github.com/d4em0n/exrop)
___________________________
@hacking_Attack
@Hacking_Video
$RSP+0x0040 : 0x7361702f6374652f
$RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0058 : 0x00000000003ec868
$RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0068 : 0x00007ffff7a0555f
$RSP+0x0070 : 0x0000000000000000
$RSP+0x0078 : 0x0000000000000000
$RSP+0x0 080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0090 : 0x0000000000647773
$RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret
$RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x00b0 : 0x00000000003ec860
$RSP+0x00b8 : 0x000000000010fc40
read('rax', bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret
$RSP+0x0008 : 0x0000000000000000
$RSP+0x0010 : 0x0000000000000000
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret
$RSP+0x0030 : 0x00007ffff79e5b96
$RSP+0x0038 : 0x0000000000000000
$RSP+0x0040 : 0x0000000000000000
$RSP+0x0048 : 0x00007fff f7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret
$RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0058 : 0x0000000000000100
$RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0068 : 0x00000000003ec860
$RSP+0x0070 : 0x0000000000110070
write(1, bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0008 : 0x0000000000000001
$RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0018 : 0x0000000000000100
$RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0028 : 0x00000000003ec860
$RSP+0x0030 : 0x0000000000110140
done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))
Download Exrop (https://github.com/d4em0n/exrop)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - d4em0n/exrop: Automatic ROPChain Generation
Automatic ROPChain Generation. Contribute to d4em0n/exrop development by creating an account on GitHub.
#Bug Bounty - How I was able to purchased premium feature just for “1” PKR by (Parameter…
Price ManipulationContinue reading on Medium »
Read more...
Price ManipulationContinue reading on Medium »
Read more...
hacking: security in practice
How to take ethical revenge on extortion scammer?
I know it’s a little off topic but yesterday I checked my spam and saw an extortion email(with an outdated password I haven’t used for long) and I was wondering what can I do to revenge, some people might fall for it and maybe I can do my part. Any help is greatly appreciated!
submitted by /u/MarbleMan100
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to take ethical revenge on extortion scammer?
I know it’s a little off topic but yesterday I checked my spam and saw an extortion email(with an outdated password I haven’t used for long) and I was wondering what can I do to revenge, some people might fall for it and maybe I can do my part. Any help is greatly appreciated!
submitted by /u/MarbleMan100
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to take ethical revenge on extortion scammer?
I know it’s a little off topic but yesterday I checked my spam and saw an extortion email(with an outdated password I haven’t used for long) and I...
hacking: security in practice
Aspiring ethical hacker here, how much of networks should I know?
I know that I should not only know about networks but also programming, Linux, Windows to get a solid base before studying how hacking works. I am watching the same videos that people watch to pass the Cisco certification and using flashcards. Should I prepare like I were going to pass Ciscos test? Or just get to know about networks superficially with a handful of videos or a short guide? Any recommendations? Also, I plan just to become a bounty hunter of vulnerabilities, and just do it as a hobby.
submitted by /u/digitalwriternow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Aspiring ethical hacker here, how much of networks should I know?
I know that I should not only know about networks but also programming, Linux, Windows to get a solid base before studying how hacking works. I am watching the same videos that people watch to pass the Cisco certification and using flashcards. Should I prepare like I were going to pass Ciscos test? Or just get to know about networks superficially with a handful of videos or a short guide? Any recommendations? Also, I plan just to become a bounty hunter of vulnerabilities, and just do it as a hobby.
submitted by /u/digitalwriternow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Aspiring ethical hacker here, how much of networks should I know?
I know that I should not only know about networks but also programming, Linux, Windows to get a solid base before studying how hacking works. I...
hacking: security in practice
capturing deleted files
I have a program that is creating temp files, doing something with them and then deleting them very quickly. What is the best way to capture these files so I can see what is in them? Windows os. Thanks!
submitted by /u/ricka777
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
capturing deleted files
I have a program that is creating temp files, doing something with them and then deleting them very quickly. What is the best way to capture these files so I can see what is in them? Windows os. Thanks!
submitted by /u/ricka777
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
capturing deleted files
I have a program that is creating temp files, doing something with them and then deleting them very quickly. What is the best way to capture...
eXtreme Short Scripting Game | Intigriti’s February XSS Challenge
https://jmrcsnchz.medium.com/extreme-short-scripting-game-intigritis-february-xss-challenge-c19938fecc74?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://jmrcsnchz.medium.com/extreme-short-scripting-game-intigritis-february-xss-challenge-c19938fecc74?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Today, I will be sharing about my solution on Intigriti’s February XSS Challenge 0222.Continue reading on Medium » (https://jmrcsnchz.medium.com/extreme-short-scripting-game-intigritis-february-xss-challenge-c19938fecc74?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video