Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Driftwood : Private Key Usage Verification

Driftwood is a tool that can enable you to lookup whether a private key is used for things like TLS or as a GitHub SSH key for a user.

Driftwood performs lookups with the computed public key, so the private key never leaves where you run the tool. Additionally it supports some basic password cracking for encrypted keys.
https://blogger.googleusercontent.com/img/a/AVvXsEgNo8jKSIPoFj6tOWBdseggWS-fK1EPfFbHRL2dJ4XlWi0sM3o9JAYh3tWUvRkcC2XeRM9aYmEtJay6sP_8hW0Y-5kM9p6YaJMNxjUpGk7sL3aD2aXkV2kQWkmI87ctVfSHKxS23B6mi3j9FnJGVpSHNVwZz5NcPKg5Uxb8h8NNXb8y6Umzm9WZoAn6=s652
Installation

Three easy ways to get started.

Run with Docker

cat private.key | docker run –rm -i trufflesecurity/driftwood –pretty-json –

Run pre-built binary

Download the binary from the releases page and run it.

Build yourself

go install github.com/trufflesecurity/driftwood@latest

Usage

Minimal usage is

$ driftwood path/to/privatekey.pem

Run with --helpto see more options.
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Considerations When Building A Future-Proof Security Strategy For Your Business Developing a security strategy for your business shouldn’t just be about the here and now. If you want your business to grow, you need a security system to…
entity, you can optimize your overall safety. Cloud-Based Security PlatformsCloud-based security platforms are far more manageable than in-house computer systems. Not only is the world turning to more remote working, but it’s inconvenient only to check your security when on the premises. As your business scales, it’s easier to adapt and tailor your security system from an online management platform.

Plus, you can install cloud-based physical security so that all your data insights are in one place. Integrating PlatformsIntegrating your platforms allows for automated workflows and easier management. As your business scales, checking multiple security software platforms isn’t practical. Whereas, if you combine access control with video security cameras, you can save yourself time and money. Future LegislationAs we mentioned, future compliance and legislation may change. We cannot predict when or what new rules may drop. There is only so much we can do to ensure our security systems abide by future legislation. However, by implementing a flexible strategy, we can ensure that new regulations won’t cause significant disruption to our security systems. Bottom LineFuture-proofing your security strategy is vital. As technology advances at an incomprehensible rate, cyber and physical threats also increase. However, by adopting a flexible, comprehensive, and proactive security strategy, you can ensure that your business is always in the best position to manage threats.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
ReFlutter : Flutter Reverse Engineering Framework

ReFlutter framework helps with Flutter apps reverse engineering using the patched version of the Flutter library which is already compiled and ready for app repacking. This library has snapshot deserialization process modified to allow you perform dynamic analysis in a convenient way.

Key features:

* socket.ccis patched for traffic monitoring and interception;
* dart.ccis modified to print classes, functions and some fields;
* contains minor changes for successful compilation;
* if you would like to implement your own patches, there is manual Flutter code change is supported using specially crafted DockerfileSupported Engines

* Android: arm64, arm32;
* iOS: arm64;
* Release: Stable, Beta Install Linux, Windows, MacOSpip3 install reflutter

Usage

impact@f:~$ reflutter main.apk
Please enter your Burp Suite IP:
SnapshotHash: 8ee4ef7a67df9845fba331734198a953
The resulting apk file: ./release.RE.apk
Please sign the apk file
Configure Burp Suite proxy server to listen on *:8083
Proxy Tab -> Options -> Proxy Listeners -> Edit -> Binding Tab
Then enable invisible proxying in Request Handling Tab
Support Invisible Proxying -> true
impact@f:~$ reflutter main.ipa

Traffic Interception

You need to specify the IP of your Burp Suite Proxy Server located in the same network where the device with the flutter application is. Next, you should configure the Proxy in BurpSuite -> Listener Proxy -> Options tab* Add port: 8083* Bind to address: All interfaces* Request handling: Support invisible proxying = Truehttps://blogger.googleusercontent.com/img/a/AVvXsEg24NwPTN4xEnSQW1yr6dLEQ_Kja_QV0yzmVTzmhw51Ts-l346yYRv7E-0maiKq1HSm_C7Ac1djvrtbqHk8i0d7DrJT4h2zwMRhvj7krApV-gE4aGqhw8KUOdFu8ekjkRnfDdV3tyiijveW_BKoH80coODTe2auEBWO4sUWVFl2c8buuTqzWoCEl1Fq=s1231
You don’t need to install any certificates. On an Android device, you don’t need root access as well. reFlutter also allows to bypass some of the flutter certificate pinning implementations. Usage On Android

The resulting apk must be aligned and signed. I use uber-apk-signer java -jar uber-apk-signer.jar --allowResign -a release.RE.apk. To see which code is loaded through DartVM, you need to run the application on the device. reFlutter prints its output in logcat with the refluttertag

impact@f:~$ adb logcat -e reflutter | sed ‘s/.*DartVM//’ >> reflutter.txt

Code output

Library:’package:anyapp/navigation/DeepLinkImpl.dart’ Class: Navigation extends Object {
String* DeepUrl = anyapp://evil.com/ ;
Function ‘Navigation.’: constructor. (dynamic, dynamic, dynamic, dynamic) => NavigationInteractor {
}
Function ‘initDeepLinkHandle’:. (dynamic) => Future* {
}
Function ‘_navigateDeepLink@547106886’:. (dynamic, dynamic, {dynamic navigator}) => void {
}
}
Library:’package:anyapp/auth/navigation/AuthAccount.dart’ Class: AuthAccount extends Account {
PlainNotificationToken* _instance = sentinel;
Function ‘getAuthToken’:. (dynamic, dynamic, dynamic, dynamic) => Future> { } Function ‘checkEmail’:. (dynamic, dynamic) => Future> { } Function ‘validateRestoreCode’:. (dynamic, dynamic, dynamic) => Future> { } Function ‘sendSmsRestorePassword’:. (dynamic, dynamic) => Future> {
}
}

Usage on iOS

Use the IPA file created after the execution of reflutter main.ipacommand. To see which code is loaded through DartVM, you need to run the application on the device. reFlutter prints its output in console logs in XCode with the refluttertag.
https://blogger.googleusercontent.com/img/a/AVvXsEhoei2na33P3rmeQy2Cz5N9EDE99sQnJSludWaHtmKSY9Vf8h-xxKA3m14q84lvjuIa-gGn4yuMxnEGAH6bjHXmf_N_8n6E-0Dzd3Nn0KLATnlh4RmRb5u0UwJyBF2k45l5ZyAqUZTg7Iic5OoAszS_Mzz6bcQTAqraAOdURert8Cg3Z25R1l00GRjP=s18[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials ReFlutter : Flutter Reverse Engineering Framework ReFlutter framework helps with Flutter apps reverse engineering using the patched version of the Flutter library which is already compiled and ready for app repacking. This library has…
99
Build Engine

The engines are built using reFlutter in Github Actions to build the desired version, commits and snapshot hashes are used from this table. The hash of the snapshot is extracted from storage.googleapis.com/flutter_infra_release/flutter/Custom Build

If you would like to implement your own patches, manual Flutter code change is supported using specially crafted Docker sudo docker pull ptswarm/reflutterLinux, Windows
EXAMPLE BUILD ANDROID ARM64:
sudo docker run -e WAIT=300 -e x64=0 -e arm=0 -e HASH_PATCH= -e COMMIT= –rm -iv${PWD}:/t ptswarm/reflutter
FLAGS:
-e x64=0
-e arm=0
-e WAIT=300
-e HASH_PATCH=[Snapshot_Hash]
-e COMMIT=[Engine_commit] Download

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Brute force app in iOS

Hello! I wanted to ask if it’s in any way possible to brute force a pin code in an app in iOS.

I have this one app that requires 4-digit passcode to enter, and I forgot the code (yeah, stupid).

This app doesn’t allow any option other than just enter the code. It also provides unlimited amount of attempts.

Is there any way to brute force the passcode? On iPhone 11 Pro Max, iOS 15.0

submitted by /u/MelodicBad2665
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Remote Emulation Optimization

I have a rather powerful main pc that I setup to run Emulators on and would like to access it remotely for remote play on a bigger tv screen in another room.

So far I have set it up with Remote Desktop as it is running win 10 Professional.

I was wondering if there is a better cleaner way to do this that keeps a steady connection and minimal fps drops.

If anyone has had any experience with remote viewing of applications, optimization for remote gaming and graphic intensive applications KVM like applications etc. Please let me know what would be the ideal tool.

submitted by /u/SuperSoakerGuyx
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to retrieve deleted videos from Youtube?

I'm not sure if this is right place for this question, but...

I want to download some deleted videos from Youtube. Wayback machine (archive.org) doesn't help. I have links from my Youtube history. So, how to retrieve this videos? I guess it's not impossible, but I can't find anything useful about the topic on google.

Thanks in advance!

submitted by /u/No-Independent2629
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to get Beef script to inject into websites

Ubuntu 20.04

i have beef and i am familiar with it i want to test it out (ethically of course) outside my home network.

i saw some videos online using Beef-Over-Wan and Ngrok but it did not seem to work. I tried many Port forwarding services and none seem to work well. Please do not bully me i am super new to this field.

submitted by /u/thegoatkai
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
GraphQL Cop - Security Auditor Utility For GraphQL APIs

https://blogger.googleusercontent.com/img/a/AVvXsEj_FDT8o9CyGrYIk9p1mG9e-oIZ2b4mEqATkPiChKSPxFtwwhl-olSHufKqcINIYVTz9Rx_S8eLoJ0WPlJ3UCQsOZhd7PoNMExjSd45c8D4dfBZdB0YyV2U-KNIT93DR3sPrCZTGmBDIGjyUVvEWS4KrnQ0Oe8Xp94b7bIgs1DdxVkEfjhAwb4Pj9Vo=w640-h396
GraphQL Cop is a small Python utility to run common security tests against GraphQL APIs.
Requirements

* Python3
* Requests Library

Detections

* Alias Overloading (DoS)
* Batch Queries (DoS)
* GET based Queries (CSRF)
* GraphQL Tracing / Debug Modes (Info Leak)
* Field Duplication (DoS)
* Field Suggestions (Info Leak)
* GraphiQL (Info Leak)
* Introspection (Info Leak)
* Directives Overloading (DoS)

Usage

CSRF (GET)': {'severity': 'LOW', 'impact': 'Possible CSRF', 'description': 'HTTP GET method supported (maybe CSRF)'}, 'Alias Overloading': {'severity': 'HIGH', 'impact': 'Denial of Service', 'description': 'Alias Overloading with 100+ aliases is allowed'}, 'Field Duplication': {'severity': 'HIGH', 'impact': 'Denial of Service', 'description': 'Queries are allowed with 1000+ of the same repeated field'}, 'Directive Overloading': {'severity': 'HIGH', 'impact': 'Denial of Service', 'description': 'Multiple duplicated directives allowed in a query'}}">python3 main.py -t https://mywebsite.com/graphql

GraphQL Cop 1.0
Security Auditor for GraphQL
Dolev Farhi
Download Graphql-Cop

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Dirty Pipe Linux Privilege Escalation

https://2.bp.blogspot.com/-MVgbYjy2n8E/WWlvDeDSliI/AAAAAAAAIK0/xNViOH31E8QoNbofn2xwVueZLLEvjlYYACLcBGAs/s1600/h130.png
Proof of concept for a vulnerability in the Linux kernel existing since version 5.8 that allows overwriting data in arbitrary read-only files. This leads to privilege escalation because unprivileged processes can inject code into root processes.

MD5 | 5689094308e86708965f5bdb2e727f11

Download
/* SPDX-License-Identifier: GPL-2.0 */
/*
* Copyright 2022 CM4all GmbH / IONOS SE
*
* author: Max Kellermann <max.kellermann@ionos.com
*
* Proof-of-concept exploit for the Dirty Pipe
* vulnerability (CVE-2022-0847) caused by an uninitialized
* "pipe_buffer.flags" variable. It demonstrates how to overwrite any
* file contents in the page cache, even if the file is not permitted
* to be written, immutable or on a read-only mount.
*
* This exploit requires Linux 5.8 or later; the code path was made
* reachable by commit f6dd975583bd ("pipe: merge
* anon_pipe_buf*_ops"). The commit did not introduce the bug, it was
* there before, it just provided an easy way to exploit it.
*
* There are two major limitations of this exploit: the offset cannot
* be on a page boundary (it needs to write one byte before the offset
* to add a reference to this page to the pipe), and the write cannot
* cross a page boundary.
*
* Example: ./write_anything /root/.ssh/authorized_keys 1 $'\nssh-ed25519 AAA......\n'
*
* Further explanation: https://dirtypipe.cm4all.com/
*/

#define _GNU_SOURCE
#include <unistd.h
#include <fcntl.h
#include <stdio.h
#include <stdlib.h
#include <string.h
#include <sys
#include <sys

#ifndef PAGE_SIZE
#define PAGE_SIZE 4096
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Dirty Pipe SUID Binary Hijack Privilege Escalation

https://2.bp.blogspot.com/-swqN45HZtSI/WWlvXv0Z4fI/AAAAAAAAIOY/czRV0nNAPTIk5N0xfOCTXuQJzRjI48a4wCLcBGAs/s1600/h53.png
Variant proof of concept exploit for the Dirty Pipe file overwrite vulnerability. This version hijacks a SUID binary to spawn a root shell.

MD5 | 7068d6d27faedd0b32b56e4d39ae9688

Download
//
// dirtypipez.c
//
// hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn
// a root shell. (and attempts to restore the damaged binary as well)
//
// Wow, Dirty CoW reloaded!
//
// -- blasty <peter@haxx.in// 2022-03-07

/* SPDX-License-Identifier: GPL-2.0 */
/*
* Copyright 2022 CM4all GmbH / IONOS SE
*
* author: Max Kellermann <max.kellermann@ionos.com
*
* Proof-of-concept exploit for the Dirty Pipe
* vulnerability (CVE-2022-0847) caused by an uninitialized
* "pipe_buffer.flags" variable. It demonstrates how to overwrite any
* file contents in the page cache, even if the file is not permitted
* to be written, immutable or on a read-only mount.
*
* This exploit requires Linux 5.8 or later; the code path was made
* reachable by commit f6dd975583bd ("pipe: merge
* anon_pipe_buf*_ops"). The commit did not introduce the bug, it was
* there before, it just provided an easy way to exploit it.
*
* There are two major limitations of this exploit: the offset cannot
* be on a page boundary (it needs to write one byte before the offset
* to add a reference to this page to the pipe), and the write cannot
* cross a page boundary.
*
* Example: ./write_anything /root/.ssh/authorized_keys 1 $'\nssh-ed25519 AAA......\n'
*
* Further explanation: https://dirtypipe.cm4all.com/
*/

#define _GNU_SOURCE
#include <unistd.h
#include <fcntl.h
#include <stdio.h
#include <stdlib.h
#include <string.h
#include <sys
#include <sys
#include <stdint.h

#ifndef PAGE_SIZE
#define PAGE_SIZE 4096
Dark Reading: Attacks/Breaches
AppSec Startup Cider Security Emerges from Stealth to Tackle SDLC Challenges

Cider Security tackles the No. 1 problem in application security -- finding and fixing vulnerabilities in code quickly -- by increasing visibility over code development and deployment.
Dark Reading: Attacks/Breaches
8 More Women in Security You May Not Know but Should

Dark Reading highlights women who are quietly changing the game in cybersecurity. We also revisit some of those we've spoken to in the past to see what they're up to now.