Let python automate your bug bounty work!Continue reading on InfoSec Write-ups Β» (https://infosecwriteups.com/directory-fuzzing-bug-bounty-3deb4dd3c32?source=rss------bug_bounty-5)
RECON FOR DUMMIES
https://newrouge.medium.com/recon-for-dummies-632f8f50ce12?source=rss------bug_bounty-5
Hey everyone, I hope you all are doing good. Now as i said i will be writing about creating my own recon methodology with all the toolsβ¦Continue reading on Medium Β» (https://newrouge.medium.com/recon-for-dummies-632f8f50ce12?source=rss------bug_bounty-5)
https://newrouge.medium.com/recon-for-dummies-632f8f50ce12?source=rss------bug_bounty-5
Hey everyone, I hope you all are doing good. Now as i said i will be writing about creating my own recon methodology with all the toolsβ¦Continue reading on Medium Β» (https://newrouge.medium.com/recon-for-dummies-632f8f50ce12?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploiting a Windows-Based Buffer Overflow
https://cdn-images-1.medium.com/max/681/1*ek7Od8WlbZYFk_RYI7RE0Q.png
This article is based on exploiting a simple buffer overflow in Windows using Vulnserver. If you donβt have an idea about buffer overflowsβ¦
Continue reading on InfoSec Write-ups Β»
Exploiting a Windows-Based Buffer Overflow
https://cdn-images-1.medium.com/max/681/1*ek7Od8WlbZYFk_RYI7RE0Q.png
This article is based on exploiting a simple buffer overflow in Windows using Vulnserver. If you donβt have an idea about buffer overflowsβ¦
Continue reading on InfoSec Write-ups Β»
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
RECON FOR DUMMIES
Hey everyone, I hope you all are doing good. Now as i said i will be writing about creating my own recon methodology with all the toolsβ¦
Continue reading on Medium Β»
RECON FOR DUMMIES
Hey everyone, I hope you all are doing good. Now as i said i will be writing about creating my own recon methodology with all the toolsβ¦
Continue reading on Medium Β»
Should one use browserstack for iOS pentesting?
https://www.reddit.com/r/Pentesting/comments/mpazd5/should_one_use_browserstack_for_ios_pentesting/
<!-- SC_OFF -->Hey! I'm a noob in pentesting and I want to start with iOS mobile pentesting. I came across browserstack. Is it enough? I'd like to know pros and cons. I've experienced too much latency in browserstack tho. <!-- SC_ON --> submitted by /u/aniketdvd (https://www.reddit.com/user/aniketdvd)
[link] (https://www.reddit.com/r/Pentesting/comments/mpazd5/should_one_use_browserstack_for_ios_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/mpazd5/should_one_use_browserstack_for_ios_pentesting/)
https://www.reddit.com/r/Pentesting/comments/mpazd5/should_one_use_browserstack_for_ios_pentesting/
<!-- SC_OFF -->Hey! I'm a noob in pentesting and I want to start with iOS mobile pentesting. I came across browserstack. Is it enough? I'd like to know pros and cons. I've experienced too much latency in browserstack tho. <!-- SC_ON --> submitted by /u/aniketdvd (https://www.reddit.com/user/aniketdvd)
[link] (https://www.reddit.com/r/Pentesting/comments/mpazd5/should_one_use_browserstack_for_ios_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/mpazd5/should_one_use_browserstack_for_ios_pentesting/)
Deep Web
Most people think Deep/Dark Web is mostly Tor which is not right. Deep/Dark web would exist even without Tor. Why do you think most people associate Deep/Dark web as a only Tor thing (like you can be here only with Tor) Why is that tho?
submitted by /u/MichalVelc
[link] [comments]
Most people think Deep/Dark Web is mostly Tor which is not right. Deep/Dark web would exist even without Tor. Why do you think most people associate Deep/Dark web as a only Tor thing (like you can be here only with Tor) Why is that tho?
submitted by /u/MichalVelc
[link] [comments]
reddit
Most people think Deep/Dark Web is mostly Tor which is not right....
Posted in r/deepweb by u/MichalVelc β’ 1 point and 1 comment
Deep Web
Create a website
Hello everyone, Iβm looking for to set up a website to sell electronics schematics and have no idea where to start. How can I pay for a server and stay anonymous? For a paiement only with Bitcoin? Thanks
submitted by /u/artotal
[link] [comments]
Create a website
Hello everyone, Iβm looking for to set up a website to sell electronics schematics and have no idea where to start. How can I pay for a server and stay anonymous? For a paiement only with Bitcoin? Thanks
submitted by /u/artotal
[link] [comments]
reddit
Create a website
Hello everyone, Iβm looking for to set up a website to sell electronics schematics and have no idea where to start. How can I pay for a server...
hacking: security in practice
Beginner - Recommend Me some resources from where to learn
Beginner - Recommend Me some resources from where to learn
reddit
Beginner - Recommend Me some resources from where to learn
Hello to everyone. Recently I decided on the career to follow, that is IT Security, well I guess hacking has its part in it, perhaps I write in...
hacking: security in practice
Xiaomi band hacking: General discusion.
Hello,
This is the same post as:: https://www.reddit.com/r/hacking/comments/mosj9n/xiaomi_band_hacking/ but I want to actually post any progress I make, and would like you guys to join in and help me, so we can do it together ;)
Cheers
submitted by /u/PaintballAlex
[link] [comments]
Xiaomi band hacking: General discusion.
Hello,
This is the same post as:: https://www.reddit.com/r/hacking/comments/mosj9n/xiaomi_band_hacking/ but I want to actually post any progress I make, and would like you guys to join in and help me, so we can do it together ;)
Cheers
submitted by /u/PaintballAlex
[link] [comments]
reddit
Xiaomi band hacking: General discusion.
Hello, This is the same post as::...
hacking: security in practice
Email flooding
Are there are any newsletters which will flood an email?
submitted by /u/ThinMaterial929
[link] [comments]
Email flooding
Are there are any newsletters which will flood an email?
submitted by /u/ThinMaterial929
[link] [comments]
reddit
Email flooding
Are there are any newsletters which will flood an email?
[Question] limit app from reading certain files
https://www.reddit.com/r/Pentesting/comments/mpc9rc/question_limit_app_from_reading_certain_files/
<!-- SC_OFF -->I have an iOS application that reads some cydia files to tell if the device is jailbroken, is there a way to limit this app from reading specific files. Something like this, pseudocode: chmod -r myApp.app /Applications/Cydia.app so only this app is not allowed to read this file. <!-- SC_ON --> submitted by /u/SackBiscuit (https://www.reddit.com/user/SackBiscuit)
[link] (https://www.reddit.com/r/Pentesting/comments/mpc9rc/question_limit_app_from_reading_certain_files/) [comments] (https://www.reddit.com/r/Pentesting/comments/mpc9rc/question_limit_app_from_reading_certain_files/)
https://www.reddit.com/r/Pentesting/comments/mpc9rc/question_limit_app_from_reading_certain_files/
<!-- SC_OFF -->I have an iOS application that reads some cydia files to tell if the device is jailbroken, is there a way to limit this app from reading specific files. Something like this, pseudocode: chmod -r myApp.app /Applications/Cydia.app so only this app is not allowed to read this file. <!-- SC_ON --> submitted by /u/SackBiscuit (https://www.reddit.com/user/SackBiscuit)
[link] (https://www.reddit.com/r/Pentesting/comments/mpc9rc/question_limit_app_from_reading_certain_files/) [comments] (https://www.reddit.com/r/Pentesting/comments/mpc9rc/question_limit_app_from_reading_certain_files/)
SYNwall - A Zero-Configuration (IoT) Firewall
http://www.kitploit.com/2021/04/synwall-zero-configuration-iot-firewall.html
http://www.kitploit.com/2021/04/synwall-zero-configuration-iot-firewall.html
Configuration
The module can be loaded in the usual way, with insmod or modprobe. It has several parameters that allow you to customize the behaviour: Pre-Shared Key used for the OneTimePassword psk: The PSK, must be a sequence of bytes from 32 to 1024. It will be part of the OTP, so the length of it will influence the size of the OTP injected in the packet. Without this parameter, the module will not load. Enable UDP enable_udp: 0 Enable/Disable the OTP for UDP protocol. By default it is disabled. Set to 1 to enable it. The OTP on UDP requires the module to be active on both of the communicating devices, since the OTP must be removed (by the module) before the packet is forwarded to the application level. If this is not true, you may experience weird behaviors. The UDP connection tracking, relies on conntrack module, so you may have to insert it to use this functionality (this depends on the installation). An error will be displayed in the kernel log if so. NOTE: by default, port 53 (DNS) and 123 (NTP) are blacklisted for outgoing connection, so the OTP is not added. If you need to change this, look for udp_blacklist[] array. I will add a parameter for this in the future. Time precision parameter precision: 10 The OTP is computed also with the current device time. Since the date could be different on the participating devices, you can "round" the time on a specific value, to allow time skew. Default is 10. The precision is expressed in power of two (you may argue why...it has been a decision to increase performance (https://www.kitploit.com/search/label/Performance) and have low impact on low end devices): ...
9 -> 1 second
10 -> 8 seconds
...
Precision under 8 is probably not going to work. If you increase the precision value at 11 or more, consider to increase also the MAX_TRASH value in SYNgate_netfilter.c Disable the OTP for outgoing packets disable_out: 0 You may want to disable the OTP in outgoing packet, by settings this to 1. In this case the module will just drop the packets without OTP, but it will not participate to the communication mesh with other SYNwall devices. It can be useful in case of issues with the outgoing packets on uplink devices. Enable DoS protection enable_antidos: 0 This option can be enabled by setting this to 1. If set, this will limit the OTP computation on the device to a given number (allow_otp_ms variable, set to 1000 by default). In this case, only one OTP computation per second is allowed, preserving the CPU time of the device in case of a DoS attack. Enable IP Spoofing protection enable_antispoof: 0 By default the IP is not part of the OTP. This could lead to some replay attack. You can enable the antispoof protection to be fully safe. This may break the communication if some NATs are in place between the devices. Delay in starting up the module functionalities (ms) load_delay: 10000 You can decide to wait a while before activating the protection after the module load. This could be useful, in case of issues and after a reboot, to gain access to the device. The default is 10 seconds. List of ports for port knocking (https://www.kitploit.com/search/label/Port%20Knocking) failsafe portk: 0,0,0,0,0 If the device clock is going bananas, it could be difficult to get access. One way could be the "delay" discussed before, but you can also set a sequence of "port knocking" which can disable the module for a while. The list, if defined, must be of 5 TCP ports. If the module identify a SYN packet on these ports in one second, it disable itself for the same time set as "load_delay". NOTE: if you actively use the sequence, remember to change it, since it can be easily sniffed!
Example of usage
The module can be loaded in the usual way, with insmod or modprobe. It has several parameters that allow you to customize the behaviour: Pre-Shared Key used for the OneTimePassword psk: The PSK, must be a sequence of bytes from 32 to 1024. It will be part of the OTP, so the length of it will influence the size of the OTP injected in the packet. Without this parameter, the module will not load. Enable UDP enable_udp: 0 Enable/Disable the OTP for UDP protocol. By default it is disabled. Set to 1 to enable it. The OTP on UDP requires the module to be active on both of the communicating devices, since the OTP must be removed (by the module) before the packet is forwarded to the application level. If this is not true, you may experience weird behaviors. The UDP connection tracking, relies on conntrack module, so you may have to insert it to use this functionality (this depends on the installation). An error will be displayed in the kernel log if so. NOTE: by default, port 53 (DNS) and 123 (NTP) are blacklisted for outgoing connection, so the OTP is not added. If you need to change this, look for udp_blacklist[] array. I will add a parameter for this in the future. Time precision parameter precision: 10 The OTP is computed also with the current device time. Since the date could be different on the participating devices, you can "round" the time on a specific value, to allow time skew. Default is 10. The precision is expressed in power of two (you may argue why...it has been a decision to increase performance (https://www.kitploit.com/search/label/Performance) and have low impact on low end devices): ...
9 -> 1 second
10 -> 8 seconds
...
Precision under 8 is probably not going to work. If you increase the precision value at 11 or more, consider to increase also the MAX_TRASH value in SYNgate_netfilter.c Disable the OTP for outgoing packets disable_out: 0 You may want to disable the OTP in outgoing packet, by settings this to 1. In this case the module will just drop the packets without OTP, but it will not participate to the communication mesh with other SYNwall devices. It can be useful in case of issues with the outgoing packets on uplink devices. Enable DoS protection enable_antidos: 0 This option can be enabled by setting this to 1. If set, this will limit the OTP computation on the device to a given number (allow_otp_ms variable, set to 1000 by default). In this case, only one OTP computation per second is allowed, preserving the CPU time of the device in case of a DoS attack. Enable IP Spoofing protection enable_antispoof: 0 By default the IP is not part of the OTP. This could lead to some replay attack. You can enable the antispoof protection to be fully safe. This may break the communication if some NATs are in place between the devices. Delay in starting up the module functionalities (ms) load_delay: 10000 You can decide to wait a while before activating the protection after the module load. This could be useful, in case of issues and after a reboot, to gain access to the device. The default is 10 seconds. List of ports for port knocking (https://www.kitploit.com/search/label/Port%20Knocking) failsafe portk: 0,0,0,0,0 If the device clock is going bananas, it could be difficult to get access. One way could be the "delay" discussed before, but you can also set a sequence of "port knocking" which can disable the module for a while. The list, if defined, must be of 5 TCP ports. If the module identify a SYN packet on these ports in one second, it disable itself for the same time set as "load_delay". NOTE: if you actively use the sequence, remember to change it, since it can be easily sniffed!
Example of usage
WARNING: this is going to drop all the traffic to your device, so be sure to know how to access with another SYNwall device or by disabling it remotely (port knocking). sudo insmod SYNwall.ko psk=123456789012345678901234567890123 precision=10 portk=12,13,14,15,16 load_delay=5000 enable_udp=1
Project Structure
SYNwall repository: SYNwall_netfilter (.c and .h): Netfilter main package, with hooks and basic process functions SYNauth (.c and .h): authentication functions, used to manage hashes and crypt stuff SYNquark (.c and .h): Quark hashing implementation, directly based on the work done by Jean-Philippe Aumasson (@veorq) at https://github.com/veorq/Quark SYNgate_netfilter (.c and .h): Netfilter package for SOCKS server module. It implements only the "outgoing" packet marking and is able to manage multiple PSK and Networks SYNwall_distrib repository: Ansible scripts for automatic distribution. See README.md there SYNwall_ATAES132 repository: PoC for secure EEPROM usage (PSK storage). See README.md there SYNwall_docs repository: Some docs, videos, DEMOs
Performance
Everything has been implemented to be used on low end devices, with very low resources. The choice of Quark hashing for the crypto hash has been done for this reason. The overhead added by the OTP computation is almost invisible in the regular usage:
Project Structure
SYNwall repository: SYNwall_netfilter (.c and .h): Netfilter main package, with hooks and basic process functions SYNauth (.c and .h): authentication functions, used to manage hashes and crypt stuff SYNquark (.c and .h): Quark hashing implementation, directly based on the work done by Jean-Philippe Aumasson (@veorq) at https://github.com/veorq/Quark SYNgate_netfilter (.c and .h): Netfilter package for SOCKS server module. It implements only the "outgoing" packet marking and is able to manage multiple PSK and Networks SYNwall_distrib repository: Ansible scripts for automatic distribution. See README.md there SYNwall_ATAES132 repository: PoC for secure EEPROM usage (PSK storage). See README.md there SYNwall_docs repository: Some docs, videos, DEMOs
Performance
Everything has been implemented to be used on low end devices, with very low resources. The choice of Quark hashing for the crypto hash has been done for this reason. The overhead added by the OTP computation is almost invisible in the regular usage: