Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Last week the United Kingdom’s National Cyber Security Centre urged UK organizations “to strengthen their cyber resilience in response to the situation in Ukraine”. They followed that warning by adopting a set of actions to take when the cyber threat is heightened.
https://external-preview.redd.it/fl8KxYVZMid-QC2e5GlyXxKEFNGfilv0JfZJVD6QrMU.jpg?width=640&crop=smart&auto=webp&s=ebb74bc033a94a069347ff99540ad6d3a1b73cdd submitted by /u/mobfig316
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Last week the United Kingdom’s National Cyber Security Centre urged UK organizations “to strengthen their cyber resilience in response to the situation in Ukraine”. They followed that warning by adopting a set of actions to take when the cyber threat is heightened.
https://external-preview.redd.it/fl8KxYVZMid-QC2e5GlyXxKEFNGfilv0JfZJVD6QrMU.jpg?width=640&crop=smart&auto=webp&s=ebb74bc033a94a069347ff99540ad6d3a1b73cdd submitted by /u/mobfig316
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Last week the United Kingdom’s National Cyber Security Centre...
Posted in r/hacking by u/mobfig316 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Has anyone signed up all of those leaked defense ministry emails for Mailbait? It would be a shame if their inboxes got flooded with thousands of emails with every new entry
https://external-preview.redd.it/YxEXpxmxDxDp1IpKnGsy-0SQXyxoI1FXx08mCNvbTIo.jpg?width=320&crop=smart&auto=webp&s=cf1207173b44c0429fbdf7122b454d50a0ee92d9 submitted by /u/Ok-Abbreviations2486
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Has anyone signed up all of those leaked defense ministry emails for Mailbait? It would be a shame if their inboxes got flooded with thousands of emails with every new entry
https://external-preview.redd.it/YxEXpxmxDxDp1IpKnGsy-0SQXyxoI1FXx08mCNvbTIo.jpg?width=320&crop=smart&auto=webp&s=cf1207173b44c0429fbdf7122b454d50a0ee92d9 submitted by /u/Ok-Abbreviations2486
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Has anyone signed up all of those leaked defense ministry emails...
Posted in r/hacking by u/Ok-Abbreviations2486 • 3 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Demonstration of how use Counter-Strike 1.6 as Malware C2
If you're a malware operator who likes to Rush B and want to manage your victims while playing games, this is for you.
https://www.youtube.com/watch?v=b2L1lWtwBiI&t=1s
https://twitter.com/kaganisildak/status/1498585440680656896
submitted by /u/kaganisildak
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Demonstration of how use Counter-Strike 1.6 as Malware C2
If you're a malware operator who likes to Rush B and want to manage your victims while playing games, this is for you.
https://www.youtube.com/watch?v=b2L1lWtwBiI&t=1s
https://twitter.com/kaganisildak/status/1498585440680656896
submitted by /u/kaganisildak
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Demonstration of how use Counter-Strike 1.6 as Malware C2
If you're a malware operator who likes to Rush B and want to manage your victims while playing games, this is for...
hacking: security in practice
What I should do?
Long story in short - I’ve had beef w someone who somehow was using my social accounts for months without me knowing it, until now - I know who that is and I know his IP
What I can do with it?
submitted by /u/OkCryptographer9015
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What I should do?
Long story in short - I’ve had beef w someone who somehow was using my social accounts for months without me knowing it, until now - I know who that is and I know his IP
What I can do with it?
submitted by /u/OkCryptographer9015
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What I should do?
Long story in short - I’ve had beef w someone who somehow was using my social accounts for months without me knowing it, until now - I know who...
hacking: security in practice
Ukrainian startup is offering hackers $100,000 to bring down Russian websites
submitted by /u/theinternetstapler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Ukrainian startup is offering hackers $100,000 to bring down Russian websites
submitted by /u/theinternetstapler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Ukrainian startup is offering hackers $100,000 to bring down...
Posted in r/hacking by u/theinternetstapler • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
PasteMonitor : Scrape Pastebin API To Collect Daily Pastes, Setup A Wordlist And Be Alerted By Email When You Have A Match
PasteMonitor is a Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.
Description
The PasteMonitor tool allows you to perform two main actions (for educational purposes only):
* Download daily new public pastes
https://blogger.googleusercontent.com/img/a/AVvXsEiSW3YW9ajBY6pwvP14WIzIwJGZvcDZGtNmP4vHEbHsFF37E5cVg2INFagr6tNn3Nfnn9B1RFHASb2A8af_OhccbklGinr1u1ichAIionGUGwCi2oYRFQgP96TTKlS18uso5xUqTbscilAOGJIok1hlLkUN3ptHPqne2H1twOTj4m4-IaInOwFPs-9S=s1123 Download
___________________________
@hacking_Attack
@Hacking_Video
PasteMonitor : Scrape Pastebin API To Collect Daily Pastes, Setup A Wordlist And Be Alerted By Email When You Have A Match
PasteMonitor is a Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.
Description
The PasteMonitor tool allows you to perform two main actions (for educational purposes only):
* Download daily new public pastes
https://blogger.googleusercontent.com/img/a/AVvXsEiSW3YW9ajBY6pwvP14WIzIwJGZvcDZGtNmP4vHEbHsFF37E5cVg2INFagr6tNn3Nfnn9B1RFHASb2A8af_OhccbklGinr1u1ichAIionGUGwCi2oYRFQgP96TTKlS18uso5xUqTbscilAOGJIok1hlLkUN3ptHPqne2H1twOTj4m4-IaInOwFPs-9S=s1123 Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
PasteMonitor : Scrape Pastebin API To Collect Daily Pastes.
PasteMonitor is a Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.
Do data practitioners are the new (security) weakest link?
Secrets in codeContinue reading on CodeX »
Read more...
Secrets in codeContinue reading on CodeX »
Read more...
Do data practitioners are the new (security) weakest link?
https://medium.com/codex/do-data-practitioners-are-the-new-security-weakest-link-9880ec91de63?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/codex/do-data-practitioners-are-the-new-security-weakest-link-9880ec91de63?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Do data practitioners are the new (security) weakest link?
Secrets in code
Secrets in codeContinue reading on CodeX » (https://medium.com/codex/do-data-practitioners-are-the-new-security-weakest-link-9880ec91de63?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Do data practitioners are the new (security) weakest link?
Secrets in code
Hacking on Medium
PicoCTF \\ Wave The Flag \\ General Skills
https://cdn-images-1.medium.com/max/623/1*HV0_auxUi5bFUnMbO9poPg.png
Write-up for Wave The Flag — PicoCTF
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PicoCTF \\ Wave The Flag \\ General Skills
https://cdn-images-1.medium.com/max/623/1*HV0_auxUi5bFUnMbO9poPg.png
Write-up for Wave The Flag — PicoCTF
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PicoCTF \\ Wave The Flag \\ General Skills
Write-up for Wave The Flag — PicoCTF
Hacking on Medium
Which programming language is best for you
https://cdn-images-1.medium.com/max/900/1*4exbjhfgXA922WJa29zWKA.jpeg
I’m so glad you asked! This is a tough question.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Which programming language is best for you
https://cdn-images-1.medium.com/max/900/1*4exbjhfgXA922WJa29zWKA.jpeg
I’m so glad you asked! This is a tough question.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Which programming language is best for you
I’m so glad you asked! This is a tough question.
CAPEv2 - Malware Configuration And Payload Extraction
http://www.kitploit.com/2022/03/capev2-malware-configuration-and.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/capev2-malware-configuration-and.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
CAPEv2 - Malware Configuration And Payload Extraction
CAPE is a malware sandbox. It was derived from Cuckoo with the goal of adding automated malware unpacking and config extraction - hence its name is an acronym: 'Config And Payload Extraction'. Automated (https://www.kitploit.com/search/label/Automated) unpacking allows classification based on Yara signatures to complement network (Suricata) and behavior (API) signatures. There is a free community instance online which anyone can use: https://capesandbox.com (https://capesandbox.com/)
Although config and payload extraction was the original stated goal, it was the development of the debugger in CAPE which first inspired the project: in order to extract configs or unpacked payloads from arbitrary malware families without relying on process dumps (which sooner or later the bad guys will thwart), instruction-level monitoring and control is necessary. The novel debugger in CAPE follows the principle of maximising use of processor hardware and minimising (almost completely) use of Windows debugging (https://www.kitploit.com/search/label/Debugging) interfaces, allowing malware to be stealthily instrumented and manipulated from the entry point with hardware breakpoints programmatically set during detonation by Yara signatures or API calls. This allows instruction traces to be captured, or actions to be performed such as control flow manipulation (https://www.kitploit.com/search/label/Manipulation) or dumping of a memory region. The debugger has allowed CAPE to continue to evolve beyond its original capabilities, which now include dynamic anti-evasion bypasses. Since modern malware commonly tries to evade analysis (https://www.kitploit.com/search/label/Analysis) within sandboxes, for example by using timing traps for virtualisation or API hook detection, CAPE allows dynamic countermeasures to be developed combining debugger actions within Yara signatures to detect evasive malware as it detonates, and perform control-flow manipulation to force the sample to detonate fully or skip evasive actions. The list of dynamic bypasses in CAPE is growing but includes: Guloader Ursnif Dridex Zloader Formbook BuerLoader Pafish CAPE takes advantage of many malware techniques (https://www.kitploit.com/search/label/Malware%20Techniques) or behaviours to allow for unpacked payload capture: Process injection Shellcode injection DLL injection Process Hollowing Process Doppelganging Decompression of executable modules in memory Extraction of executable modules or shellcode in memory These behaviours will result in the capture of payloads being injected, extracted or decompressed for further analysis. In addition CAPE automatically creates a process dump for each process, or, in the case of a DLL, the DLL's module image in memory. This is useful for samples packed with simple packers, where often the module image dump is fully unpacked. Quick access to the debugger is made possible with the breakpoint options 'bp0' through 'bp3' accepting RVA or VA values to set breakpoints, whereupon a short instruction trace will be output, governed by 'count' and 'depth' options (e.g. bp0=0x1234,depth=1,count=100). To set a breakpoint at the module entry point, 'ep' is used instead of an address (e.g. bp0=ep). Alternatively 'break-on-return' allows for a breakpoint on the return address of a hooked API (e.g. break-on-return=NtGetContextThread). An optional 'base-on-api' parameter allows the image base for RVA breakpoints to be set by API call (e.g. base-on-api=NtReadFile,bp0=0x2345). Options 'action0' - 'action3' allow actions to be performed when breakpoints are hit, such as dumping memory regions (e.g. action0=dumpebx) or changing the execution control flow (e.g. action1=skip). CAPE's documentation contains further examples of such actions. 'dump-on-api' allows a module to be dumped when it calls a specific API function which can be specified in the web interface which can be useful for quickly unpacking/dumping novel samples
___________________________
@hacking_Attack
@Hacking_Video
Although config and payload extraction was the original stated goal, it was the development of the debugger in CAPE which first inspired the project: in order to extract configs or unpacked payloads from arbitrary malware families without relying on process dumps (which sooner or later the bad guys will thwart), instruction-level monitoring and control is necessary. The novel debugger in CAPE follows the principle of maximising use of processor hardware and minimising (almost completely) use of Windows debugging (https://www.kitploit.com/search/label/Debugging) interfaces, allowing malware to be stealthily instrumented and manipulated from the entry point with hardware breakpoints programmatically set during detonation by Yara signatures or API calls. This allows instruction traces to be captured, or actions to be performed such as control flow manipulation (https://www.kitploit.com/search/label/Manipulation) or dumping of a memory region. The debugger has allowed CAPE to continue to evolve beyond its original capabilities, which now include dynamic anti-evasion bypasses. Since modern malware commonly tries to evade analysis (https://www.kitploit.com/search/label/Analysis) within sandboxes, for example by using timing traps for virtualisation or API hook detection, CAPE allows dynamic countermeasures to be developed combining debugger actions within Yara signatures to detect evasive malware as it detonates, and perform control-flow manipulation to force the sample to detonate fully or skip evasive actions. The list of dynamic bypasses in CAPE is growing but includes: Guloader Ursnif Dridex Zloader Formbook BuerLoader Pafish CAPE takes advantage of many malware techniques (https://www.kitploit.com/search/label/Malware%20Techniques) or behaviours to allow for unpacked payload capture: Process injection Shellcode injection DLL injection Process Hollowing Process Doppelganging Decompression of executable modules in memory Extraction of executable modules or shellcode in memory These behaviours will result in the capture of payloads being injected, extracted or decompressed for further analysis. In addition CAPE automatically creates a process dump for each process, or, in the case of a DLL, the DLL's module image in memory. This is useful for samples packed with simple packers, where often the module image dump is fully unpacked. Quick access to the debugger is made possible with the breakpoint options 'bp0' through 'bp3' accepting RVA or VA values to set breakpoints, whereupon a short instruction trace will be output, governed by 'count' and 'depth' options (e.g. bp0=0x1234,depth=1,count=100). To set a breakpoint at the module entry point, 'ep' is used instead of an address (e.g. bp0=ep). Alternatively 'break-on-return' allows for a breakpoint on the return address of a hooked API (e.g. break-on-return=NtGetContextThread). An optional 'base-on-api' parameter allows the image base for RVA breakpoints to be set by API call (e.g. base-on-api=NtReadFile,bp0=0x2345). Options 'action0' - 'action3' allow actions to be performed when breakpoints are hit, such as dumping memory regions (e.g. action0=dumpebx) or changing the execution control flow (e.g. action1=skip). CAPE's documentation contains further examples of such actions. 'dump-on-api' allows a module to be dumped when it calls a specific API function which can be specified in the web interface which can be useful for quickly unpacking/dumping novel samples
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
(e.g. dump-on-api=DnsQuery_A). CAPE also has an option 'upx=1' which can dynamically unpack samples that use 'hacked' (modified) UPX, very popular with malware authors. These samples are run in CAPE's debugger until their OEP (original entry point), whereupon they are dumped, fixed and their imports are automatically reconstructed, ready for analysis. CAPE is constantly growing in malware family coverage, but has config parsers for the following examples: Emotet TrickBot QakBot Hancitor Ursnif Dridex SmokeLoader IcedID RedLeaf ChChes HttpBrowser Enfal PoisonIvy Screech TSCookie CAPE uses Yara signatures as its principal classification method to detect unpacked payloads. This list is constantly growing, and includes: Azorult, Formbook, Ryuk, Hermes, Shade, Remcos, Ramnit, Gootkit, QtBot, ZeroT, WanaCry, NetTraveler, Locky, BadRabbit, Magniber, Redsip, Kronos, PetrWrap, Kovter, Azer, Petya, Dreambot, Atlas, NanoLocker, Mole, Codoso, Cryptoshield, Loki, Jaff, IcedID, Scarab, Cutlet, RokRat, OlympicDestroyer, Gandcrab, Fareit, ZeusPanda, AgentTesla, Imminent, Arkei, Sorgu, tRat, T5000, TClient, TreasureHunter. There is a community repository of signatures containing several hundred signatures developed by the CAPE community: https://github.com/kevoreilly/community Config parsing can be done using either of CAPE's config parsing frameworks, the RATDecoders framework from malwareconfig.com and DC3-MWCP (Defense Cyber Crime Center - Malware Configuration Parser). The many parsers/decoders from malwareconfig.com are also included, comprising among many others: Sakula, DarkComet, PredatorPain and PoisonIvy. Thanks to Kevin Breen/TechAnarchy for this framework and parsers (https://github.com/kevthehermit/RATDecoders), and to DC3 for their framework (https://github.com/Defense-Cyber-Crime-Center/DC3-MWCP). Special thanks to Jason Reaves (@sysopfb) for the TrickBot parser and Fabien Perigaud for the PlugX parser. The repository containing the code for the monitor DLLs is a distinct one: https://github.com/kevoreilly/capemon. Please contribute to this project by helping create new signatures, parsers or bypasses for further malware families. There are many in the works currently, so watch this space. CAPEv2! A huge thank you to @D00m3dR4v3n for single-handedly porting CAPE to Python 3. Python3 agent.py is tested with python (3.7.2|3.8) x86. You should use x86 python version inside of the VM! host tested with python3 version 3.7 and 3.8, but newer versions should works too Installation recommendations and scripts for optimal performance Become familiar with documentation (https://capev2.readthedocs.io/en/latest/installation/guest/network.html#virtual-networking) for proper configuration For best compability we strongly suggest installing on Ubuntu 20.04 LTS (https://ubuntu.com/#download) KVM (https://github.com/doomedraven/Tools/blob/master/Virtualization/kvm-qemu.sh) is recommended as hypervisor, replace to real pattern sudo ./kvm-qemu.sh all | tee kvm-qemu.log To install CAPE itself, cape2.sh (https://github.com/doomedraven/Tools/blob/master/Sandbox/cape2.sh) with all optimizations sudo ./cape2.sh base cape | tee cape.log CAPE Services cape.service cape-processor.service cape-web.service cape-rooter.service To restart any service use systemctl restart To debug any problem, stop service and run the command that runs service by hand to see more logs, check -h, debug mode (-d) can help. Only rooter should be executed as root, the rest as cape user. Running as root will mess with permissions Reboot and enjoy All scripts contain help -h, but please check the scripts to understand what they are doing. How to create VMs with virt-manager see docs for configration step by step (https://www.doomedraven.com/2020/04/how-to-create-virtual-machine-with-virt.html) Virtual machine core dependecy choco.bat
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - kevoreilly/community: Community modules for CAPE Sandbox
Community modules for CAPE Sandbox. Contribute to kevoreilly/community development by creating an account on GitHub.
(https://github.com/doomedraven/Tools/blob/master/Windows/choco.bat) How to update CAPE: git pull community: python3 utils/community.py -waf see -h before to ensure you understand How to upgrade with a lot of custom small modifications that can't be public? With rebase git add --all
git commit -m '[STASH]'
git pull --rebase origin master
# fix conflict (rebase) if needed
git reset HEAD~1
With merge ' # fetch changes from kevoreilly repo git fetch kevoreilly # merge kevoreilly master branch into your current branch git merge kevoreilly/master # fix merge conflicts if needed # push to your repo if desired git push"># make sure kevoreilly repo has been added as a remote (only needs to be done once)
git remote add kevoreilly https://github.com/kevoreilly/CAPEv2.git
# make sure all your changes are commited on the branch which you will be merging
git commit -a -m ''
# fetch changes from kevoreilly repo
git fetch kevoreilly
# merge kevoreilly master branch into your current branch
git merge kevoreilly/master
# fix merge conflicts if needed
# push to your repo if desired
git push
Special note about config parsing frameworks: Due to the nature of malware, since it changes constantly, when any new version is released, something might become broken! We suggest using only pure Python with entrypoint def config(data): that will be called by cape_utils.py and 0 complications. As bonus you can reuse your extractors in other projects. Docs ReadTheDocs (https://capev2.readthedocs.io/en/latest/#)
Download CAPEv2 (https://github.com/kevoreilly/CAPEv2)
___________________________
@hacking_Attack
@Hacking_Video
git commit -m '[STASH]'
git pull --rebase origin master
# fix conflict (rebase) if needed
git reset HEAD~1
With merge ' # fetch changes from kevoreilly repo git fetch kevoreilly # merge kevoreilly master branch into your current branch git merge kevoreilly/master # fix merge conflicts if needed # push to your repo if desired git push"># make sure kevoreilly repo has been added as a remote (only needs to be done once)
git remote add kevoreilly https://github.com/kevoreilly/CAPEv2.git
# make sure all your changes are commited on the branch which you will be merging
git commit -a -m ''
# fetch changes from kevoreilly repo
git fetch kevoreilly
# merge kevoreilly master branch into your current branch
git merge kevoreilly/master
# fix merge conflicts if needed
# push to your repo if desired
git push
Special note about config parsing frameworks: Due to the nature of malware, since it changes constantly, when any new version is released, something might become broken! We suggest using only pure Python with entrypoint def config(data): that will be called by cape_utils.py and 0 complications. As bonus you can reuse your extractors in other projects. Docs ReadTheDocs (https://capev2.readthedocs.io/en/latest/#)
Download CAPEv2 (https://github.com/kevoreilly/CAPEv2)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Tools/choco.bat at master · doomedraven/Tools
Combination of different utilities, have fun! . Contribute to doomedraven/Tools development by creating an account on GitHub.