Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
PORTSWIGGER WEB SECURITY - XXE (XML EXTERNAL ENTITY) INJECTION LAB ÇÖZÜMLERİ

XXE (XML External Entity) Injection, bir saldırganın web uygulama üzerinde XML verilerini enjekte etmesine veya değiştirmesine olanak…Continue reading on Medium »
Read more...
2FA Misconfiguration leads to adding any number as 2FA verification

I was testing 2FA on a website. At first, I tried to bypass 2FA but I was not successful, then I thought of something else. What if I can…Continue reading on Techiepedia »
Read more...
My Pentest Log -7-

Greetings to all from Sergius and Bacchus,Continue reading on Medium »
Read more...
Behind-the-Scenes of Infosec Writeups

How the publication grew since 2017, one message at a time.Continue reading on InfoSec Write-ups »
Read more...
PORTSWIGGER WEB SECURITY - XXE (XML EXTERNAL ENTITY) INJECTION LAB ÇÖZÜMLERİ

XXE (XML External Entity) Injection, bir saldırganın web uygulama üzerinde XML verilerini enjekte etmesine veya değiştirmesine olanak…Continue reading on Medium »
Read more...
Behind-the-Scenes of Infosec Writeups

How the publication grew since 2017, one message at a time.
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Introducing Ghostbuster – AWS security tool protects against dangling elastic IP takeovers

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Introducing Ghostbuster – AWS security tool protects against dangling elastic IP takeoversPost Views: 99
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 1 Minute
Ghostbuster from AWS, an open source security tool has been launched with the promise of a “fool-proof way” to detect dangling elastic IP takeovers.
Organizations leave themselves vulnerable to these subdomain takeover attacks when they delete Amazon Web Services (AWS) EC2 instances or assign them new IPs but forget to remove DNS records that point to IPs associated with the instances.

Attackers can identify these vulnerable subdomains by continually claiming elastic IPs until they find an IP associated with the subdomain of a targeted organization.

This ‘lottery’ approach has also been proposed as a means for defenders to detect dangling elastic IPs in research into the attack technique dating back to 2015.

However, the ‘Ghostbuster’ tool, developed by Australian cybersecurity firm Assetnote, offers a different approach: It enumerates all public IPs associated with an organization’s AWS accounts and checks for DNS records pointing to elastic IPs that its AWS accounts don’t own.
See Also: Complete Offensive Security and Ethical Hacking Course Attack vector eliminatedShubham Shah, co-founder and CTO at Assetnote, said the firm’s own hit-and-miss experiments with the lottery approach had prompted AWS to tell its researchers to stop using the technique.

“This approach is, as the name suggests, like a lottery: you may get lucky, you may not,” he told The Daily Swig. “It is not a fool-proof way at detecting dangling elastic IP takeovers, whereas Ghostbuster is.

He added: “Whereas the lottery approach is the only approach attackers can use, with Ghostbuster, you can eliminate dangling elastic IP takeovers entirely.”

The only caveat is that you need “access to all of your AWS accounts and your DNS records” in order to obtain “accurate and complete results”. High impactDangling elastic IP subdomain takeovers are one of many frequently occurring misconfiguration vulnerabilities to arise from the “shared responsibility” security model used by major cloud providers, Shah said in a blog post.

This particular flavor of subdomain takeover is becoming more common, as organizations migrate services to the public cloud and inadvertently misconfigure their instances – something that is “exacerbated by automatic provisioning”.

The potential impact is also more serious than for other subdomain takeover techniques where attackers can only control the content being served.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH As well as hosting malicious content or leveraging a ‘trusted’ domain for phishing attacks, attackers can also potentially claim the subdomain’s SSL certificates via ACME TLS challenges; intercept sensitive information being sent to the subdomain; and run server-side scripts that steal HTTPOnly cookies, thus enabling one-click account takeover attacks.

“Almost every company that uses AWS suffers from this attack vector,” said Shah. “In many cases, it is possible to perform account takeover attacks due to broad cookie scoping as well.”

Some bug hunters earn as much as $50,000 a month exploiting the issue on AWS customers, said Shah.

AWS currently combats the threat by blocking accounts that perform suspicious attack patterns, wh[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Introducing Ghostbuster – AWS security tool protects against dangling elastic IP takeovers https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Introducing Ghostbuster – AWS security tool protects…
ich “raises the bar for exploitation to some extent (particularly at scale)”, but “is not an effective long-term mitigation to the underlying issue”.

AWS is apparently working on additional mitigations. The Daily Swig has asked AWS when these mitigations might arrive, so we will update the article if and when we receive a reply. See Also: Offensive Security Tool: Swaks – Swiss Army Knife for SMTP GhostbustingGhostbuster “uses your .aws/config and .aws/credentials files to iterate through every configured account and perform processing”, said Shah.

You can use Route53, Cloudflare, or manual inputs to manage your DNS zones, and “it is also possible to configure a Slack webhook so that this tool will send a notification upon detecting a potential takeover”.

Ghostbuster can also “run as a cron job on a frequent basis, informing you of potential elastic IP takeovers over time”.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: How ILOVEYOU worm became the first global computer virus pandemic Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/zabbix_blog_java-apps-90x90.png Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-4-1-90x90.jpg GitHub code scanning now finds more security vulnerabilities4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/012qzWe52HXVPxkc8nUrPyv-1.fit_lim.size_1200x630.v1617817629-90x90.jpg Massive LinkedIn Phishing, Bot Attacks Feed on the Job-Hungry5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Unredacter-Pixelize-90x90.gif New tool can uncover redacted, pixelated text to reveal sensitive data6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-3-1-90x90.jpg Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/banner-2022.1-release-90x90.jpg Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/acastro_210104_1777_google_0001-90x90.jpg Google Project Zero: Vendors are now quicker at fixing zero-days1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Apple-Warning-90x90.jpg Apple patches new zero-day exploited to hack iPhones, iPads, Macs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/f4bc-article-200611-wordpress-body-text-90x90.jpg PHP Everywhere RCE flaws threaten thousands of WordPress sites2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/178-706-450-android-patch-770x439_c-90x90.jpg Google fixes remote escalation of privileges bug on Android2 weeks ago
The post Introducing Ghostbuster – AWS security tool protects against dangling elastic IP takeovers first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I made a hacking challenge

Hey :)

For anyone who's bored I've made a hacking challenge you can download on github.

It's a collection of rar archives going from level 1-8 which increase in hash difficulty.

Good luck and let me know anything to change as I made this on no sleep and I'm only 16



https://github.com/JustAHubber/JustAHubber/releases/tag/crack

submitted by /u/Lanky_Ad4113
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Simulating Linux on Windows to Stay Safe

I've been researching into stating anonymous while browsing and a large issue I have is how all my accounts are linked together via Google, Samsung, and Microsoft OneDrive. I'm wondering if I could add a layer of protection to my online presence by plugging in a USB with a Linux kernel to surf the web. I'm wondering if it can stay almost or completely separate to anything else I use as currently I dont use Linux at all. Would this be a good way to protect myself from hacks and have a more anonymous presence?

submitted by /u/Yagg3rnaut
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Web Cache Vulnerability Scanner : A Go-based CLI Tool For Testing Web Cache Poisoning

Web Cache Vulnerability Scanner (WCVS) is a fast and versatile CLI scanner for web cache poisoning developed by Hackmanit.

The scanner supports many different web cache poisoning techniques, includes a crawler to identify further URLs to test, and can adapt to a specific web cache for more efficient testing. It is highly customizable and can be easily integrated into existing CI/CD pipelines.

Features

* Support for 9 web cache poisoning techniques:
* Unkeyed header poisoning
* Unkeyed parameter poisoning
* Parameter cloaking
* Fat GET
* HTTP response splitting
* HTTP request smuggling
* HTTP header oversize (HHO)
* HTTP meta character (HMC)
* HTTP method override (HMO)

* Analyzing a web cache before testing and adapting to it for more efficient testing
* Generating a report in JSON format
* Crawling websites for further URLs to scan
* Routing traffic through a proxy (e.g., Burp Suite)
* Limiting requests per second to bypass rate limiting Installation Option 1: Pre-built Binary (Recommended)

Prebuilt binaries of WCVS are provided on the releases page. These releases include 2 default wordlists, as well. Option 2: Fetch Repository Using Go

The repository can be fetched using Go.

go1.17 and higher

go install -v github.com/Hackmanit/Web-Cache-Vulnerability-Scanner@latest

go1.16 and lower

go get -u https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner

Option 3: Docker

* Clone repository or download the latest source code release

* Build image (the wordlists folder will also be copied)

$ docker build .
Sending build context to Docker daemon 29.54MB
Step 1/10 : FROM golang:latest AS builder
—> 05c8f6d2538a
Step 2/10 : WORKDIR /go/src/app
—> Using cache
—> f591f24be8cf
Step 3/10 : COPY . .
—> 38b358dd3472
Step 4/10 : RUN go get -d -v ./…
—> Running in 41f53de436c5
….
Removing intermediate container 9e2e84d14ff3
—> 1668edcf6ee3
Successfully built 1668edcf6ee3

Run wcvs

$ docker run -it 1668edcf6ee3 /wcvs –help
https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner
version 1.0.0

Usage

WCVS is highly customizable using its flags. Many of the flags can either contain a value directly or the path to a file.

The only mandatory flag is -u/--urlto provide the target URL which should be tested for web cache poisoning. The target URL can be provided in different formats,

WCVS needs two wordlists in order to test for the first 5 techniques – one wordlist with header names and one with parameter names. The wordlists can either be present in the same directory WCVS is executed from or specified using the --headerwordlist/-hwand --parameterwordlist/-pwflags.

Examples

wcvs -u 127.0.0.1
wcvs -u http://127.0.0.1
wcvs -u https://example.com
wcvs -u file:path/to/url_list
wcvs -u https://example.com -hw “file:/home/user/Documents/wordlist-header.txt”
wcvs -u https://example.com -pw “file:/home/user/Documents/wordlist-parameter.txt”
wcvs -u https://example.com -hw “file:/home/user/Documents/wordlist-header.txt” -pw “file:/home/user/Documents/wordlist-parameter.txt”

Specify Headers, Parameters, Cookies, and More

* --setcookies/-scspecifies cookies which shall be added to the request
* --setheaders/-shspecifies headers which shall be added to the request
* --setparameters/-spspecifies parameters which shall be added to the request. While it is also possible to simply add them to the URL, it might be more useful in some cases to add them via this flag.
* --post/-postchanges the HTTP method from GET to POST
* --setbody/-sbspecifies the body which shall be added to the request
* --contenttype/-ctspecifies the value of th[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Web Cache Vulnerability Scanner : A Go-based CLI Tool For Testing Web Cache Poisoning Web Cache Vulnerability Scanner (WCVS) is a fast and versatile CLI scanner for web cache poisoning developed by Hackmanit. The scanner supports many…
e Content-Type header
* --useragentchrome/-uacchanges the User-Agent from WebCacheVulnerabilityScanner v{Version-Number}to Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36. While the same can be achieved with e.g. -sh "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ..., this flag provides a quicker way. Examples

wcvs -u https://example.com -sc “PHPSESSID=123”
wcvs -u https://example.com -sc “file:/home/user/Documents/cookies.txt”
wcvs -u https://example.com -sh “Referer: localhost”
wcvs -u https://example.com -sh “file:/home/user/Documents/headers.txt”
wcvs -u https://example.com -sp “admin=true”
wcvs -u https://example.com -sp “file:/home/user/Documents/parameters.txt”
wcvs -u https://example.com -post -sb “admin=true”
wcvs -u https://example.com -post -sb “file:/home/user/Documents/body.txt”
wcvs -u https://example.com -post -sb “{}” -ct “application/json”
wcvs -u https://example.com -uac

Generate a JSON Report

A JSON report is generated and updated after each scanned URL if the flag --generatereport/-gris set. The report is written, just like a log file, into the same directory WCVS is executed from. In order to change the directory for all output files use --generatepath/-gp. If HTML special chars shall be encoded in the report, use --escapejson/-ej. Examples

wcvs -u https://example.com -gr
wcvs -u https://example.com -gr -ej
wcvs -u https://example.com -gr -gp /home/user/Documents
wcvs -u https://example.com -gr -gp /home/user/Documents -ej

Use a Proxy

To use a proxy, a CA certificate of the proxy in PEM format is needed. Burp Suite certificates are provided in DER format, for example. To convert them, the following command can be used: openssl x509 -inform DER -outform PEM -text -in cacert.der -out cacert.pem. The path to the certificate can be specified with --proxycertpath/-ppath. The default URL for the proxy is http://127.0.0.1:8080. In order to change it, use --proxyurl/-purl. Examples

wcvs -u https://example.com -ppath /home/user/Documents/cacert.pem
wcvs -u https://example.com -ppath /home/user/Documents/cacert.pem -purl http://127.0.0.1:8081

Throttle or Accelerate

The number of maximum allowed requests per second can be set with --reqrate/-rr. By default, this number is unrestricted. Contrary, the number of requests per second can be increased potentially, if --threads/-tis used to increase the number of concurrent threads WCVS utilizes. The default value is 20. Examples

wcvs -u https://example.com -rr 10
wcvs -u https://example.com -rr 1
wcvs -u https://example.com -rr 0.5
wcvs -u https://example.com -t 50

Further Flags

WCVS provides even more than the beforehand mentioned flags and options. --help/-hprovides a list of each flag, its meaning, and how to use it. Example

wcvs -h Download

___________________________
@hacking_Attack
@Hacking_Video