Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
AzureC2Relay - An Azure Function That Validates And Relays Cobalt Strike Beacon Traffic By Verifying The Incoming Requests Based On A Cobalt Strike Malleable C2 Profile
http://www.kitploit.com/2021/04/azurec2relay-azure-function-that.html
AzureC2Relay is an Azure Function that validates and relays Cobalt Strike (https://www.kitploit.com/search/label/Cobalt%20Strike) beacon (https://www.kitploit.com/search/label/Beacon) traffic (https://www.kitploit.com/search/label/Traffic) by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile. Any incoming requests that do not share the profiles user-agent, URI paths, headers, and query parameters, will be redirected to a configurable decoy website. The validated C2 traffic is relayed to a team server within the same virtual network that is further restricted by a network security group. Allowing the VM to only expose SSH.
Deploy
AzureC2Relay is deployed via terraform (https://www.kitploit.com/search/label/Terraform) azure modules as well as some local az cli commands Make sure you have terraform , az cli and the dotnet core 3.1 runtime installed Windows (Powershell) &([scriptblock]::Create((Invoke-WebRequest -UseBasicParsing 'https://dot.net/v1/dotnet-install.ps1'))) -runtime dotnet -version 3.1.0
Invoke-WebRequest 'https://releases.hashicorp.com/terraform/0.14.6/terraform_0.14.6_windows_amd64.zip' -OutFile 'terraform.zip'
Expand-Archive -Path terraform.zip -DestinationPath "$([Environment]::GetFolderPath('ApplicationData'))\TerraForm\"
setx PATH "%PATH%;$([Environment]::GetFolderPath('ApplicationData'))\TerraForm\"
Invoke-WebRequest -Uri https://aka.ms/installazurecliwindows -OutFile .\AzureCLI.msi; Start-Process msiexec.exe -Wait -ArgumentList '/I AzureCLI.msi /quiet'; rm .\AzureCLI.msi
Mac curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0
brew update
brew tap hashicorp/tap
brew install hashicorp/tap/terraform
brew install azure-cli
Ubuntu , Debian curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0
wget https://releases.hashicorp.com/terraform/0.14.5/terraform_0.14.5_linux_amd64.zip
unzip terraform_0.14.5_linux_amd64.zip
sudo cp terraform /usr/local/bin/terraform
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
Kali curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0
wget https://releases.hashicorp.com/terraform/0.14.5/terraform_0.14.5_linux_amd64.zip
unzip terraform_0.14.5_linux_amd64.zip
sudo cp terraform /usr/local/bin/terraform
echo "deb [arch=amd64] https://packages.microsoft.com/repos/azure-cli/ stretch main" | sudo tee /etc/apt/sources.list.d/azure-cli.list
curl -L https://packages.microsoft.com/keys/microsoft.asc | sudo apt-key add -
sudo apt-get update && sudo apt-get install apt-transport-https azure-cli
Modify the first variables defined in config.tf to suit your needs Replace the dummy "cobaltstrike-dist.tgz" with an actual cobaltstrike download Edit/Replace the Malleable profile inside the Ressources folder (Make sure the profile filename matches the variables you set in step 1) login with azure az login run terraform init run terraform apply -auto-approve to deploy the infra Wait for the CDN to become active and enjoy! Once terraform completes it will provide you with the needed ssh command, the CobaltStrike (https://www.kitploit.com/search/label/CobaltStrike) teamserver will be running inside an tmux session on the deployed VM When your done using the infra, you can remove it with terraform destroy -auto-approve

Download AzureC2Relay (https://github.com/Flangvik/AzureC2Relay)
hacking: security in practice
Abandoning a profitable side project due to lack of time, looking for someone to take over.

Mainly Puppeteer, probs 1 or 2 hours a day. Been working on this for a few months, and there's quite a bit of money in it. I just have other things to concentrate. Whoever takes over the work takes over the profits. I just don't want to see it die. DM me.

submitted by /u/AsinusRex
[link] [comments]
AzureC2Relay - An Azure Function That Validates And Relays Cobalt Strike Beacon Traffic By Verifying The Incoming Requests Based On A Cobalt Strike Malleable C2 Profile

AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile. Any incoming requests that do not share the profiles user-agent, URI paths, headers, and query parameters, will be redirected to a configurable decoy website. The validated C2 traffic is relayed to a team server within the same virtual network that is further restricted by a network security group. Allowing the VM to only expose SSH.Deploy AzureC2Relay is deployed via terraform azure modules as well as some local az cli commands Make sure you have terraform , az cli and the dotnet core 3.1 runtime installed Windows (Powershell) &(scriptblock::Create((Invoke-WebRequest -UseBasicParsing 'https://dot.net/v1/dotnet-install.ps1'))) -runtime dotnet -version 3.1.0Invoke-WebRequest 'https://releases.hashicorp.com/terraform/0.14.6/terraform_0.14.6_windows_amd64.zip' -OutFile 'terraform.zip'Expand-Archive -Path terraform.zip -DestinationPath "$(Environment::GetFolderPath('ApplicationData'))\TerraForm\"setx PATH "%PATH%;$(Environment::GetFolderPath('ApplicationData'))\TerraForm\"Invoke-WebRequest -Uri https://aka.ms/installazurecliwindows -OutFile .\AzureCLI.msi; Start-Process msiexec.exe -Wait -ArgumentList '/I AzureCLI.msi /quiet'; rm .\AzureCLI.msi Mac curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0brew update brew tap hashicorp/tapbrew install hashicorp/tap/terraformbrew install azure-cli Ubuntu , Debian curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0wget https://releases.hashicorp.com/terraform/0.14.5/terraform_0.14.5_linux_amd64.zipunzip terraform_0.14.5_linux_amd64.zipsudo cp terraform /usr/local/bin/terraformcurl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash Kali curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0wget https://releases.hashicorp.com/terraform/0.14.5/terraform_0.14.5_linux_amd64.zipunzip terraform_0.14.5_linux_amd64.zipsudo cp terraform /usr/local/bin/terraformecho "deb arch=amd64 https://packages.microsoft.com/repos/azure-cli/ stretch main" | sudo tee /etc/apt/sources.list.d/azure-cli.listcurl -L https://packages.microsoft.com/keys/microsoft.asc | sudo apt-key add -sudo apt-get update && sudo apt-get install apt-transport-https azure-cli Modify the first variables defined in config.tf to suit your needs Replace the dummy "cobaltstrike-dist.tgz" with an actual cobaltstrike download Edit/Replace the Malleable profile inside the Ressources folder (Make sure the profile filename matches the variables you set in step 1) login with azure az login run terraform init run terraform apply -auto-approve to deploy the infra Wait for the CDN to become active and enjoy! Once terraform completes it will provide you with the needed ssh command, the CobaltStrike teamserver will be running inside an tmux session on the deployed VM When your done using the infra, you can remove it with terraform destroy -auto-approve Download AzureC2Relay
Read more...
Digging Deep Into Dom XSS

IntroductionContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
TUF : A Framework For Securing Software Update Systems

TUF is a repository is the reference implementation of The Update Framework (TUF). It is written in Python and intended to conform to version 1.0 of the TUF specification. This implementation is in use in production systems, but is also intended to be a readable guide and demonstration for those working on implementing TUF in […]

The post TUF : A Framework For Securing Software Update Systems appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Relevante — episodio 8 ☠️

https://cdn-images-1.medium.com/max/640/0*gIUb__uPaUoNebJV
Se vino el otoño, 2021. Un editorial dedicado al futuro distópico: Los robots de Boston Dynamics van por todo. Controlaremos el teléfono…

Continue reading on Relevantenews »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
AzureC2Relay - An Azure Function That Validates And Relays Cobalt Strike Beacon Traffic By Verifying The Incoming Requests Based On A Cobalt Strike Malleable C2 Profile

https://1.bp.blogspot.com/-oa6G92plSqA/YGvgYtysKHI/AAAAAAAAV0o/t4My_zkK6c8t1pBye3UvChXovumbmPIBgCNcBGAsYHQ/w640-h326/AzureC2Relay_1_AzureRelay.png AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile. Any incoming requests that do not share the profiles user-agent, URI paths, headers, and query parameters, will be redirected to a configurable decoy website. The validated C2 traffic is relayed to a team server within the same virtual network that is further restricted by a network security group. Allowing the VM to only expose SSH. DeployAzureC2Relay is deployed via terraform azure modules as well as some local az cli commands

Make sure you have terraform , az cli and the dotnet core 3.1 runtime installed

Windows (Powershell) &([scriptblock]::Create((Invoke-WebRequest -UseBasicParsing 'https://dot.net/v1/dotnet-install.ps1'))) -runtime dotnet -version 3.1.0
Invoke-WebRequest 'https://releases.hashicorp.com/terraform/0.14.6/terraform_0.14.6_windows_amd64.zip' -OutFile 'terraform.zip'
Expand-Archive -Path terraform.zip -DestinationPath "$([Environment]::GetFolderPath('ApplicationData'))\TerraForm\"
setx PATH "%PATH%;$([Environment]::GetFolderPath('ApplicationData'))\TerraForm\"
Invoke-WebRequest -Uri https://aka.ms/installazurecliwindows -OutFile .\AzureCLI.msi; Start-Process msiexec.exe -Wait -ArgumentList '/I AzureCLI.msi /quiet'; rm .\AzureCLI.msi
Mac curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0
brew update
brew tap hashicorp/tap
brew install hashicorp/tap/terraform
brew install azure-cli
Ubuntu , Debian curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0
wget https://releases.hashicorp.com/terraform/0.14.5/terraform_0.14.5_linux_amd64.zip
unzip terraform_0.14.5_linux_amd64.zip
sudo cp terraform /usr/local/bin/terraform
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
Kali curl -L https://dot.net/v1/dotnet-install.sh | bash -s -- --runtime dotnet --version 3.1.0
wget https://releases.hashicorp.com/terraform/0.14.5/terraform_0.14.5_linux_amd64.zip
unzip terraform_0.14.5_linux_amd64.zip
sudo cp terraform /usr/local/bin/terraform
echo "deb [arch=amd64] https://packages.microsoft.com/repos/azure-cli/ stretch main" | sudo tee /etc/apt/sources.list.d/azure-cli.list
curl -L https://packages.microsoft.com/keys/microsoft.asc | sudo apt-key add -
sudo apt-get update && sudo apt-get install apt-transport-https azure-cli
1. Modify the first variables defined in config.tfto suit your needs
2. Replace the dummy "cobaltstrike-dist.tgz" with an actual cobaltstrike download
3. Edit/Replace the Malleable profile inside the Ressources folder (Make sure the profile filename matches the variables you set in step 1)
4. login with azure az login5. run terraform init6. run terraform apply -auto-approveto deploy the infra
7. Wait for the CDN to become active and enjoy!

Once terraform completes it will provide you with the needed ssh command, the CobaltStrike teamserver will be running inside an tmux session on the deployed VM

When your done using the infra, you can remove it with terraform destroy -auto-approveDownload AzureC2Relay
https://b.thumbs.redditmedia.com/OWJgznW6gWiwYYPLEUfNtdN375PzpWUbMhGPIE2L2mY.jpg so my phone run out of battery and I started to charge it and went about my day but when I went back and turned it on I saw a messages pop-up in the middle with out me opening my messages app of my screen never had this before I would show you a pic but I don't know where to add it on here

(am on Samsung android 7.0)

https://preview.redd.it/krwwf2wjjks61.png?width=1440&format=png&auto=webp&s=be5bbdf8a35c7ce1527810b1d3a1bafcd4b9ef1b

submitted by /u/the_dead_revenant1
[link] [comments]
hacking: security in practice
Xiaomi band hacking.

Hello,

It really amases me how many people have the xiaomi band. I have one laying around and I am tinking about hacking it. The smart band coneccts to a phone, and it gets software updates like that, so in theory if I reverce engineer the app and make my own app to send a malicous update to the watch that would allow me to controll it. But that's theory, it just leaves too much questions, for example: how would I program a malicous update, is it linux based? How do I actually program the content of the update? And so on... I actually didin't find a post disccusing hacking this band, it would be fun ;) Do you have any ideas? We could work it out together! The hack could just simply consist of desplaying custom text on the screen.

Cheers

submitted by /u/PaintballAlex
[link] [comments]