Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Raccoon Stealer Crawls Into Telegram
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Raccoon Stealer Crawls Into TelegramPost Views: 51
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
A credential stealer, Raccoon Stealer, the first to rose to popularity a couple of years ago is now abusing Telegram for command-and-control (C2).
A range of cybercriminals continue to widen its attack surface through creative distribution means like this, researchers have reported. Raccoon Stealer, which first appeared on the scene in April 2019, has added the ability to store and update its own actual C2 addresses on Telegram’s infrastructure, according to a blog post published by Avast Threat Labs this week. This gives them a “convenient and reliable” command center on the platform that they can update on the fly, researchers said.
The malware – believed to be developed and maintained by Russia-affiliated cybercriminals – is at its core a credential stealer but is capable of a range of nefarious activity. It can steal not only passwords but also cookies, saved logins and forms data from browsers, login credentials from email clients and messengers, files from crypto wallets, data from browser plugins and extensions, and arbitrary files, based on commands from its C2.
“In addition, it’s able to download and execute arbitrary files by command from its C2,” Avast Threat Labs researcher Vladimir Martyanov wrote in the post. This, in combination with active development and promotion on underground forums, makes Raccoon Stealer “prevalent and dangerous,” he said.
Upon its release in 2019, cybercriminals quickly adopted the malware because of its user-friendly malware-as-a-service (MaaS) model, which has given them a quick and easy way to make money by stealing sensitive data.
See Also: Complete Offensive Security and Ethical Hacking Course Creative DistributionEarly on, attackers were seen delivering Raccoon Stealer via an .IMG file hosted on a hacker-controlled Dropbox account in business email compromise (BEC) campaigns that targeted financial institutions and other organizations.
More recently, Avast Threat Labs researchers observed a number of new and creative ways attackers are distributing Raccoon Stealer, Martyanov said.
“Taking into account that Raccoon Stealer is for sale, its distribution techniques are limited only by the imagination of the end buyers,” he wrote.
In addition to being spread by two loaders – Buer Loader and GCleaner – attackers also are distributing Raccoon Stealer via fake game cheats, patches for cracked software – including hacks and mods for Fortnite, Valorant and NBA2K22 – or other software, Martyanov wrote.
Cybercriminals also are taking care to try to evade detection by packing the credential stealer, using Themida or malware packers, with some samples observed being packed more than five times in a row with the same packer, he added.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Abusing C2 in TelegramThe report detailed how the latest version of Raccoon Stealer communicates with C2 within Telegram: There are four “crucial” values for its C2 communication, which are hardcoded in every Raccoon Stealer sample, according to the post. They are:
* -MAIN_KEY, which has been changed four times during the year;
* -URLs of Telegram gates with a channel name;
* -BotID, a hexadecimal string, sent to the C2 every time; and
* -TELEGRAM_KEY, a key to decrypt the C2 address obtained from Telegram Gate.
To hijack Telegram for its C2, the malware first decrypts MAIN_KEY, which it uses to decrypt Tele[...]
___________________________
@hacking_Attack
@Hacking_Video
Raccoon Stealer Crawls Into Telegram
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Raccoon Stealer Crawls Into TelegramPost Views: 51
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
A credential stealer, Raccoon Stealer, the first to rose to popularity a couple of years ago is now abusing Telegram for command-and-control (C2).
A range of cybercriminals continue to widen its attack surface through creative distribution means like this, researchers have reported. Raccoon Stealer, which first appeared on the scene in April 2019, has added the ability to store and update its own actual C2 addresses on Telegram’s infrastructure, according to a blog post published by Avast Threat Labs this week. This gives them a “convenient and reliable” command center on the platform that they can update on the fly, researchers said.
The malware – believed to be developed and maintained by Russia-affiliated cybercriminals – is at its core a credential stealer but is capable of a range of nefarious activity. It can steal not only passwords but also cookies, saved logins and forms data from browsers, login credentials from email clients and messengers, files from crypto wallets, data from browser plugins and extensions, and arbitrary files, based on commands from its C2.
“In addition, it’s able to download and execute arbitrary files by command from its C2,” Avast Threat Labs researcher Vladimir Martyanov wrote in the post. This, in combination with active development and promotion on underground forums, makes Raccoon Stealer “prevalent and dangerous,” he said.
Upon its release in 2019, cybercriminals quickly adopted the malware because of its user-friendly malware-as-a-service (MaaS) model, which has given them a quick and easy way to make money by stealing sensitive data.
See Also: Complete Offensive Security and Ethical Hacking Course Creative DistributionEarly on, attackers were seen delivering Raccoon Stealer via an .IMG file hosted on a hacker-controlled Dropbox account in business email compromise (BEC) campaigns that targeted financial institutions and other organizations.
More recently, Avast Threat Labs researchers observed a number of new and creative ways attackers are distributing Raccoon Stealer, Martyanov said.
“Taking into account that Raccoon Stealer is for sale, its distribution techniques are limited only by the imagination of the end buyers,” he wrote.
In addition to being spread by two loaders – Buer Loader and GCleaner – attackers also are distributing Raccoon Stealer via fake game cheats, patches for cracked software – including hacks and mods for Fortnite, Valorant and NBA2K22 – or other software, Martyanov wrote.
Cybercriminals also are taking care to try to evade detection by packing the credential stealer, using Themida or malware packers, with some samples observed being packed more than five times in a row with the same packer, he added.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Abusing C2 in TelegramThe report detailed how the latest version of Raccoon Stealer communicates with C2 within Telegram: There are four “crucial” values for its C2 communication, which are hardcoded in every Raccoon Stealer sample, according to the post. They are:
* -MAIN_KEY, which has been changed four times during the year;
* -URLs of Telegram gates with a channel name;
* -BotID, a hexadecimal string, sent to the C2 every time; and
* -TELEGRAM_KEY, a key to decrypt the C2 address obtained from Telegram Gate.
To hijack Telegram for its C2, the malware first decrypts MAIN_KEY, which it uses to decrypt Tele[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Raccoon Stealer Crawls Into Telegram | Black Hat Ethical Hacking
A credential stealer, Raccoon Stealer, the first to rose to popularity a couple of years ago is now abusing Telegram for command-and-control (C2).
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Raccoon Stealer Crawls Into Telegram https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Raccoon Stealer Crawls Into TelegramPost Views: 51 https://www.blackhatethicalhacking.com/wp-content…
gram gates URLs and BotID. The stealer then uses Telegram gate to get to its real C2 using a string of queries that eventually allow it to use the Telegram infrastructure to store and update actual C2 addresses, Martyanov wrote.
By downloading and executing arbitrary files from a command from C2, the stealer also is able to distribute malware. Avast Threat Labs collected about 185 files, with a total size of 265 megabytes – including downloaders, clipboard crypto stealers and the WhiteBlackCrypt ransomware – that were being distributed by Raccoon Stealer. Avoiding Russian EntitiesOnce executed, Racoon Stealer starts checking for the default user locale set on the infected device and won’t work if it’s one of the following: Russian, Ukrainian, Belarusian, Kazakh, Kyrgyz, Armenian, Tajik or Uzbek. This is likely because the developers themselves are Russian, researchers believe.
However, Avast Threat Labs found that in recent activity, “the country where we have blocked the most attempts is Russia, which is interesting because the actors behind the malware don’t want to infect computers in Russia or Central Asia,” Martyanov wrote.
This could be because “the attacks spray and pray, distributing the malware around the world,” he noted. The malware doesn’t check for the location of the user until it actually reaches a device; if it finds that the device is located in a region developers don’t want to target, it won’t run. See Also: Offensive Security Tool: Fibratus “This explains why we detected so many attack attempts in Russia; we block the malware before it can run, i.e. before it can even get to the stage where it checks for the device’s locale,” Martyanov wrote. “If an unprotected device that comes across the malware with its locale set to English or any other language that is not on the exception list but is in Russia, it would still become infected.”
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/kali-bright-90x90.jpg Kali Unkaputtbar – a new feature on Kali Linux2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/wolf-in-sheps-clothing-2-scaled-e1646927438585-90x90.jpeg Malware Posing as Russia DDoS Tool Bites Ukraine Hackers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-90x90.jpg Agencies in Ukraine targeted with MicroBackdoor malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/NINTCHDBPICT000622539771-90x90.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’2 weeks ago
* https://www.blackhatethicalhacking.com[...]
___________________________
@hacking_Attack
@Hacking_Video
By downloading and executing arbitrary files from a command from C2, the stealer also is able to distribute malware. Avast Threat Labs collected about 185 files, with a total size of 265 megabytes – including downloaders, clipboard crypto stealers and the WhiteBlackCrypt ransomware – that were being distributed by Raccoon Stealer. Avoiding Russian EntitiesOnce executed, Racoon Stealer starts checking for the default user locale set on the infected device and won’t work if it’s one of the following: Russian, Ukrainian, Belarusian, Kazakh, Kyrgyz, Armenian, Tajik or Uzbek. This is likely because the developers themselves are Russian, researchers believe.
However, Avast Threat Labs found that in recent activity, “the country where we have blocked the most attempts is Russia, which is interesting because the actors behind the malware don’t want to infect computers in Russia or Central Asia,” Martyanov wrote.
This could be because “the attacks spray and pray, distributing the malware around the world,” he noted. The malware doesn’t check for the location of the user until it actually reaches a device; if it finds that the device is located in a region developers don’t want to target, it won’t run. See Also: Offensive Security Tool: Fibratus “This explains why we detected so many attack attempts in Russia; we block the malware before it can run, i.e. before it can even get to the stage where it checks for the device’s locale,” Martyanov wrote. “If an unprotected device that comes across the malware with its locale set to English or any other language that is not on the exception list but is in Russia, it would still become infected.”
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/kali-bright-90x90.jpg Kali Unkaputtbar – a new feature on Kali Linux2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/wolf-in-sheps-clothing-2-scaled-e1646927438585-90x90.jpeg Malware Posing as Russia DDoS Tool Bites Ukraine Hackers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-90x90.jpg Agencies in Ukraine targeted with MicroBackdoor malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/NINTCHDBPICT000622539771-90x90.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’2 weeks ago
* https://www.blackhatethicalhacking.com[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
gram gates URLs and BotID. The stealer then uses Telegram gate to get to its real C2 using a string of queries that eventually allow it to use the Telegram infrastructure to store and update actual C2 addresses, Martyanov wrote. By downloading and executing…
/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/download-90x90.jpg Cyber-attack on Nvidia linked to Lapsus$ ransomware gang2 weeks ago
The post Raccoon Stealer Crawls Into Telegram first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/download-90x90.jpg Cyber-attack on Nvidia linked to Lapsus$ ransomware gang2 weeks ago
The post Raccoon Stealer Crawls Into Telegram first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
CodeAnalysis - Static Code Analysis
Tencent Cloud Code Analysis (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It also supports the integration of other code analysis tools. Code analysis is a technology, using lexical analysis, syntax analysis, control-flow analysis, data-flow analysis to make a comprehensive analysis of the code, so as to verify whether the code meets the requirements of normative, security, reliability, maintainability and other indicators. Using TCA can help team find normative, structural, security vulnerabilities and other issues in the code, continuously monitor the quality of the project code and issue alerts. At the same time, TCA opens up APIs to support connection with upstream and downstream systems, so as to integrate code analysis capabilities, ensure code quality, and be more conducive to inheriting an excellent team code culture. Experience Apply Link Key Features Language support: It supports Java/C++/Objective-C/C#/JavaScript/Python/Go/PHP and more, covering common programming languages. Code inspection: Discover code quality defects, code specification problems, code security vulnerabilities, invalid codes, etc. At present, many self-developed and well-known open source analysis tools have been integrated. The layered architecture can support rapid self-service management tools for teams. Code measurement: Support comprehensive measurement of code from the three dimensions of code cyclomatic complexity, code repetition rate and code statistics. DevOps integration: The client can be started via the command line. Standard APIs support connection to upstream and downstream systems, and various DevOps systems. Getting Started How to get start How to deploy server and web How to deploy server and web with docker-compose How to use client Deploy Q&A Community QQ Group: 361791391 Discussion Wiki White Paper Changelogs Check our Changelog Contributing Check out CONTRIBUTING to see how to develop with TCA. Tencent Open Source Incentive Program encourages the participation and contribution of developers. We look forward to your active participation. License TCA is MIT licensed Download CodeAnalysis
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Tencent Cloud Code Analysis (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It also supports the integration of other code analysis tools. Code analysis is a technology, using lexical analysis, syntax analysis, control-flow analysis, data-flow analysis to make a comprehensive analysis of the code, so as to verify whether the code meets the requirements of normative, security, reliability, maintainability and other indicators. Using TCA can help team find normative, structural, security vulnerabilities and other issues in the code, continuously monitor the quality of the project code and issue alerts. At the same time, TCA opens up APIs to support connection with upstream and downstream systems, so as to integrate code analysis capabilities, ensure code quality, and be more conducive to inheriting an excellent team code culture. Experience Apply Link Key Features Language support: It supports Java/C++/Objective-C/C#/JavaScript/Python/Go/PHP and more, covering common programming languages. Code inspection: Discover code quality defects, code specification problems, code security vulnerabilities, invalid codes, etc. At present, many self-developed and well-known open source analysis tools have been integrated. The layered architecture can support rapid self-service management tools for teams. Code measurement: Support comprehensive measurement of code from the three dimensions of code cyclomatic complexity, code repetition rate and code statistics. DevOps integration: The client can be started via the command line. Standard APIs support connection to upstream and downstream systems, and various DevOps systems. Getting Started How to get start How to deploy server and web How to deploy server and web with docker-compose How to use client Deploy Q&A Community QQ Group: 361791391 Discussion Wiki White Paper Changelogs Check our Changelog Contributing Check out CONTRIBUTING to see how to develop with TCA. Tencent Open Source Incentive Program encourages the participation and contribution of developers. We look forward to your active participation. License TCA is MIT licensed Download CodeAnalysis
Read more...
___________________________
@hacking_Attack
@Hacking_Video
How I Made The BBC Hall Of Fame 3 Times
Happy Monday to anyone reading this write up. Today I am going to describe how I was able to make the BBC Hall Of Fame 3 times. My…Continue reading on Medium »
Read more...
Happy Monday to anyone reading this write up. Today I am going to describe how I was able to make the BBC Hall Of Fame 3 times. My…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Mininode : A CLI Tool To Reduce The Attack Surface Of The Node.js Applications By Using Static Analysis
Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis of source code. It supports two modes of reduction (1) coarse, (2) fine.
Mininode constructs the dependency graph (modules and functions used) of the application starting from main file, i.e. entry point of the application. Mininode initializes entry point to
Example usage: node index.js . Below is the list of options that can be passed to Mininode.
Options
List of command line options that can be passed to mininode.
*
*
*
*
*
*
*
*
*
*
*
*
Limitaions
* Mininode uses static analysis, which means it can not reduce the attack surface of the Node.js application which uses dynamic behaviour, such as
Download
___________________________
@hacking_Attack
@Hacking_Video
Mininode : A CLI Tool To Reduce The Attack Surface Of The Node.js Applications By Using Static Analysis
Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis of source code. It supports two modes of reduction (1) coarse, (2) fine.
Mininode constructs the dependency graph (modules and functions used) of the application starting from main file, i.e. entry point of the application. Mininode initializes entry point to
package.jsonfile’s mainfield if it exists. Otherwise default to index.js.Example usage: node index.js . Below is the list of options that can be passed to Mininode.
Options
List of command line options that can be passed to mininode.
*
--destination, -d: the path where mininode will save the reduced Node.js application. The default value: mininode.*
--dry-run: just generates mininode.json without modifying the initial application.*
--mode, -m: reduction mode. The value can be either coarseor fine. In coarsemode mininode will perform only coarse-grained reduction. While in finemode mininode will perform fine-grained reduction. In general coarse-grained reduction is more reliable, because mininode will not try to reduce unused functions inside the module. Default value: coarse.*
--silent: console output is disabled. This will improve the performance of the mininode.*
--verbose: outputs additional information to the console. The default value: false*
--log: mininode will generate log file inside, which contains dependency graph of the application in json format. The default value: true.*
--log-output: the name of the log file generated by mininode. The default value: mininode.json.*
--compress-log: compresses the final log file. By default it will dump everything into log file. In production it is advised to pass the --compress-logflag to save space.*
--seeds: seed files from where mininode will start building dependency graph. You can provide many seed files by separating them with colon.*
--skip-stat: skips calculating the statistics*
--skip-reduction: if passed mininode will not reduce the JavaScript files. The default value: false.*
--skip-remove: if passed mininode will not remove unused JavaScript files. The default value: false.Limitaions
* Mininode uses static analysis, which means it can not reduce the attack surface of the Node.js application which uses dynamic behaviour, such as
eval. If Mininode detects dynamic behaviour in the application it exits with error DYNAMIC_BEHAVOUR_DETECTED.Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Mininode : A CLI Tool To Reduce The Attack Surface Of The Node.js
Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis of source code.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CRT : CrowdStrike Reporting Tool for Azure
CRT is a tool to queries the following configurations in the Azure AD/O365 tenant which can shed light on hard-to-find permissions and configuration settings in order to assist organizations in securing these environments.
Exchange Online (O365):
* Federation Configuration
* Federation Trust
* Client Access Settings Configured on Mailboxes
* Mail Forwarding Rules for Remote Domains
* Mailbox SMTP Forwarding Rules
* Mail Transport Rules
* Delegates with ‘Full Access’ Permission Granted
* Delegates with Any Permissions Granted
* Delegates with ‘Send As’ or ‘SendOnBehalf’ Permissions
* Exchange Online PowerShell Enabled Users
* Users with ‘Audit Bypass’ Enabled
* Mailboxes Hidden from the Global Address List (GAL)
* Collect administrator audit logging configuration settings.
Azure AD:
* Service Principal Objects with KeyCredentials
* O365 Admin Groups Report
* Delegated Permissions & Application Permissions
Querying Tenant Partner Information: In order to view Tenant Partner Information, including roles assigned to your partners, you must log into the Microsoft 365 Admin Center as Global Admin:
https://admin.microsoft.com/AdminPortal/Home#/partners
Prerequisites
The following PowerShell modules are required and will be installed automatically:
* ExchangeOnlineManagement
* AzureAD
NOTE: To return the full extent of the configurations being queried, the following role is required:
* Global Admin
When Global Admin privileges are not available, the tool will notify you about what information won’t be available to you as a result.
Usage
No parameters specified: A folder named with date and time (YYYYDDMMTHHMM) will be created automatically in the directory the script is being run from. Default authentication method will prompt for each connection for compatibility with MFA.
.\Get-CRTReport.ps1
.\Get-CRTReport.ps1 -BasicAuth
.\Get-CRTReport.ps1 -JobName MyJobName
.\Get-CRTReport.ps1 -JobName MyJobName -WorkingDirectory ‘C:\Path\to\Job\Folder’ -Commands “Command1,Command2”
.\Get-CRTReport.ps1 -ExchangeEnvironmentName O365USGovGCCHigh -AzureEnvironmentName AzureUSGovernment
Available Commands:
FedConfig
FedTrust
ClientAccess
RemoteDomains
SMTPForward
TransportRules
FullAccessGranted
AnyAccessGranted
SendAsGranted
EXOPowerShell
AuditBypassEnabled
HiddenMailboxes
KeyCredentials
O365AdminGroups
DelegateAppPerms
AdminAuditLogConfig
.\Get-CRTReport.ps1 -JobName MyJobName -WorkingDirectory ‘C:\Path\to\Job\Folder’ -Interactive
Download
___________________________
@hacking_Attack
@Hacking_Video
CRT : CrowdStrike Reporting Tool for Azure
CRT is a tool to queries the following configurations in the Azure AD/O365 tenant which can shed light on hard-to-find permissions and configuration settings in order to assist organizations in securing these environments.
Exchange Online (O365):
* Federation Configuration
* Federation Trust
* Client Access Settings Configured on Mailboxes
* Mail Forwarding Rules for Remote Domains
* Mailbox SMTP Forwarding Rules
* Mail Transport Rules
* Delegates with ‘Full Access’ Permission Granted
* Delegates with Any Permissions Granted
* Delegates with ‘Send As’ or ‘SendOnBehalf’ Permissions
* Exchange Online PowerShell Enabled Users
* Users with ‘Audit Bypass’ Enabled
* Mailboxes Hidden from the Global Address List (GAL)
* Collect administrator audit logging configuration settings.
Azure AD:
* Service Principal Objects with KeyCredentials
* O365 Admin Groups Report
* Delegated Permissions & Application Permissions
Querying Tenant Partner Information: In order to view Tenant Partner Information, including roles assigned to your partners, you must log into the Microsoft 365 Admin Center as Global Admin:
https://admin.microsoft.com/AdminPortal/Home#/partners
Prerequisites
The following PowerShell modules are required and will be installed automatically:
* ExchangeOnlineManagement
* AzureAD
NOTE: To return the full extent of the configurations being queried, the following role is required:
* Global Admin
When Global Admin privileges are not available, the tool will notify you about what information won’t be available to you as a result.
Usage
No parameters specified: A folder named with date and time (YYYYDDMMTHHMM) will be created automatically in the directory the script is being run from. Default authentication method will prompt for each connection for compatibility with MFA.
.\Get-CRTReport.ps1
-BasicAuthParameter: [OPTIONAL] If MFA is not enforced for your user principal, you can use this parameter which will prompt only once for authentication and store credentials using Get-Credential. (Not Recommended).\Get-CRTReport.ps1 -BasicAuth
-JobNameParameter: [OPTIONAL] Use the JobName parameter to distinguish between different tenants. If no JobName is specified, a Date/Time formatted folder will be placed within the working directory..\Get-CRTReport.ps1 -JobName MyJobName
-CommandsParameter: [OPTIONAL] With this parameter, specify the specific commands you want to run in quotes, comma or space separated..\Get-CRTReport.ps1 -JobName MyJobName -WorkingDirectory ‘C:\Path\to\Job\Folder’ -Commands “Command1,Command2”
-AzureEnvironmentName & -ExchangeEnvironmentNameParameter: [OPTIONAL] With this parameter, specify the Azure or Exchange environment names. Using tab complete you can search the acceptable values..\Get-CRTReport.ps1 -ExchangeEnvironmentName O365USGovGCCHigh -AzureEnvironmentName AzureUSGovernment
Available Commands:
FedConfig
FedTrust
ClientAccess
RemoteDomains
SMTPForward
TransportRules
FullAccessGranted
AnyAccessGranted
SendAsGranted
EXOPowerShell
AuditBypassEnabled
HiddenMailboxes
KeyCredentials
O365AdminGroups
DelegateAppPerms
AdminAuditLogConfig
-InteractiveParameter: [OPTIONAL] Some commands may take a long time to process depending on the amount of data in the tenant. Using the Interactive parameter, you will have the option to skip any particular command prior to the module running..\Get-CRTReport.ps1 -JobName MyJobName -WorkingDirectory ‘C:\Path\to\Job\Folder’ -Interactive
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
CRT : CrowdStrike Reporting Tool for Azure !!! Kali Linux
CRT is a tool to queries the following configurations in the Azure AD/O365 tenant which can shed light on hard-to-find permissions.
Insecure comparison in PHP — Business Logic Bypass vulnerability
I have recently spotted an interesting vulnerability in a PHP application, which was in scope of a private bug bounty program. This…
Read more...
I have recently spotted an interesting vulnerability in a PHP application, which was in scope of a private bug bounty program. This…
Read more...
From Recon via Censys and DNSdumpster, to Getting P1 by Login Using Weak Password — “password”
A simple story when Allah allowed me to get P1 by combining several issues, one of which was related to “weak credentials”.
Read more...
A simple story when Allah allowed me to get P1 by combining several issues, one of which was related to “weak credentials”.
Read more...
hacking: security in practice
aircrack-ng -w all password file location
-w is used to define password dictionary file in aircrack-ng. However, I've seen different example where "-w all" is used and I can't even see any file named "all" in that directory.
Now it's time to use our dictionary and crack the network. Open up terminal and type: aircrack-ng -w
http://stephencroberts.blogspot.com/2012/04/cracking-wpa-networks-with.html
http://www.cs.toronto.edu/~arnold/427/18s/427_18S/indepth/scapy_wifi/scapy_tut.html
What is the actual file used to represent "all" in this case?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
aircrack-ng -w all password file location
-w is used to define password dictionary file in aircrack-ng. However, I've seen different example where "-w all" is used and I can't even see any file named "all" in that directory.
Now it's time to use our dictionary and crack the network. Open up terminal and type: aircrack-ng -w
http://stephencroberts.blogspot.com/2012/04/cracking-wpa-networks-with.html
http://www.cs.toronto.edu/~arnold/427/18s/427_18S/indepth/scapy_wifi/scapy_tut.html
What is the actual file used to represent "all" in this case?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
aircrack-ng -w all password file location
\-w is used to define password dictionary file in aircrack-ng. However, I've seen different example where "-w all" is used and I can't even see...
hacking: security in practice
Signal Jammer
I’m trying to put a signal jammer into a altoids can so what boards can I use?
submitted by /u/RedditUserHigh420
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Signal Jammer
I’m trying to put a signal jammer into a altoids can so what boards can I use?
submitted by /u/RedditUserHigh420
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Signal Jammer
I’m trying to put a signal jammer into a altoids can so what boards can I use?
Hacking on Medium
Python Wireless Network Listener — Where has your devices been?
https://cdn-images-1.medium.com/max/1280/1*1tnEDC_-RZwATIFjjvajlA.jpeg
Learn how to build a simple Python script that can be used to probe for devices and their recent network connections. This tutorial covers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Python Wireless Network Listener — Where has your devices been?
https://cdn-images-1.medium.com/max/1280/1*1tnEDC_-RZwATIFjjvajlA.jpeg
Learn how to build a simple Python script that can be used to probe for devices and their recent network connections. This tutorial covers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Python Wireless Network Listener — Where has your devices been?
Learn how to build a simple Python script that can be used to probe for devices and their recent network connections. This tutorial covers…
Hacking on Medium
What is LXC & LXD | How to escalate privileges using LXD in linux systems
https://cdn-images-1.medium.com/max/977/1*0ICh8FBZ_426IeOx3Bo86g.png
Hey Hackers!!!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is LXC & LXD | How to escalate privileges using LXD in linux systems
https://cdn-images-1.medium.com/max/977/1*0ICh8FBZ_426IeOx3Bo86g.png
Hey Hackers!!!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is LXC & LXD | How to escalate privileges using LXD in linux systems
Hey Hackers!!!
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
CodeAnalysis - Static Code Analysis
https://blogger.googleusercontent.com/img/a/AVvXsEhh10PnIKy45SPiRpjS2fjFf4x2ie5fqMsOWno8LL015kvaQAdZcxDGcSxlreb_koP3N8mnWUbuSYR420hyHT9LzS2sW-U_lEAsST0z8ktQFShEW2mPlJWMxIZFDNRz_L5Kh4AL2qpUMAdwJE1HthKuSp-Pj4yFzgB-s2wRyedKc0vC7x5KO9zgpjcY=w400-h384 Tencent Cloud Code Analysis (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It also supports the integration of other code analysis tools.
Code analysis is a technology, using lexical analysis, syntax analysis, control-flow analysis, data-flow analysis to make a comprehensive analysis of the code, so as to verify whether the code meets the requirements of normative, security, reliability, maintainability and other indicators.
Using TCA can help team find normative, structural, security vulnerabilities and other issues in the code, continuously monitor the quality of the project code and issue alerts. At the same time, TCA opens up APIs to support connection with upstream and downstream systems, so as to integrate code analysis capabilities, ensure code quality, and be more conducive to inheriting an excellent team code culture. https://blogger.googleusercontent.com/img/a/AVvXsEiSOSLbVVncbTqw4UTbVh_y_GLxNSsz9vd_mVw1meiRgaBbKBrWp9vdXcjmk51U8bHHepPYWI-uXWyRFsV9gvj2CaQLb8xIGYH3LM_Rqwghz36GhT96VISbpNPDg1Jo2YUM7iC2tvPBarsNZ6XhuNRl-KU15PCvhlprGyYtK5kLcoi9X0JhFfadIWwW=w640-h104 https://blogger.googleusercontent.com/img/a/AVvXsEiSHNogeee8uZtBhrc4HyZycbcqQGtwQT3SoUC5htOiVskKfFXSlfbfsh4Gd44MyiRMBIW8biSAv3fN4YWgeApvuStLJw89hbjHGpWlYBUt_5O1p0KQfm7byjKtVSbjJDw2bzsnN6AWZZ7b3uoIBjVsbjJPKnzIeH3fV-2Je18RjWL4jooQmREMdX04=w640-h304 ExperienceApply Link Key Features1. Language support: It supports Java/C++/Objective-C/C#/JavaScript/Python/Go/PHP and more, covering common programming languages.
2. Code inspection: Discover code quality defects, code specification problems, code security vulnerabilities, invalid codes, etc. At present, many self-developed and well-known open source analysis tools have been integrated. The layered architecture can support rapid self-service management tools for teams.
3. Code measurement: Support comprehensive measurement of code from the three dimensions of code cyclomatic complexity, code repetition rate and code statistics.
4. DevOps integration: The client can be started via the command line. Standard APIs support connection to upstream and downstream systems, and various DevOps systems. Getting Started* How to get start
* How to deploy server and web
* How to deploy server and web with docker-compose
* How to use client
* Deploy Q&A Community* QQ Group: 361791391
* Discussion
* Wiki
* White Paper Changelogs* Check our Changelog Contributing* Check out CONTRIBUTING to see how to develop with TCA.
* Tencent Open Source Incentive Program encourages the participation and contribution of developers. We look forward to your active participation. LicenseTCA is MIT licensed Download CodeAnalysis
___________________________
@hacking_Attack
@Hacking_Video
CodeAnalysis - Static Code Analysis
https://blogger.googleusercontent.com/img/a/AVvXsEhh10PnIKy45SPiRpjS2fjFf4x2ie5fqMsOWno8LL015kvaQAdZcxDGcSxlreb_koP3N8mnWUbuSYR420hyHT9LzS2sW-U_lEAsST0z8ktQFShEW2mPlJWMxIZFDNRz_L5Kh4AL2qpUMAdwJE1HthKuSp-Pj4yFzgB-s2wRyedKc0vC7x5KO9zgpjcY=w400-h384 Tencent Cloud Code Analysis (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It also supports the integration of other code analysis tools.
Code analysis is a technology, using lexical analysis, syntax analysis, control-flow analysis, data-flow analysis to make a comprehensive analysis of the code, so as to verify whether the code meets the requirements of normative, security, reliability, maintainability and other indicators.
Using TCA can help team find normative, structural, security vulnerabilities and other issues in the code, continuously monitor the quality of the project code and issue alerts. At the same time, TCA opens up APIs to support connection with upstream and downstream systems, so as to integrate code analysis capabilities, ensure code quality, and be more conducive to inheriting an excellent team code culture. https://blogger.googleusercontent.com/img/a/AVvXsEiSOSLbVVncbTqw4UTbVh_y_GLxNSsz9vd_mVw1meiRgaBbKBrWp9vdXcjmk51U8bHHepPYWI-uXWyRFsV9gvj2CaQLb8xIGYH3LM_Rqwghz36GhT96VISbpNPDg1Jo2YUM7iC2tvPBarsNZ6XhuNRl-KU15PCvhlprGyYtK5kLcoi9X0JhFfadIWwW=w640-h104 https://blogger.googleusercontent.com/img/a/AVvXsEiSHNogeee8uZtBhrc4HyZycbcqQGtwQT3SoUC5htOiVskKfFXSlfbfsh4Gd44MyiRMBIW8biSAv3fN4YWgeApvuStLJw89hbjHGpWlYBUt_5O1p0KQfm7byjKtVSbjJDw2bzsnN6AWZZ7b3uoIBjVsbjJPKnzIeH3fV-2Je18RjWL4jooQmREMdX04=w640-h304 ExperienceApply Link Key Features1. Language support: It supports Java/C++/Objective-C/C#/JavaScript/Python/Go/PHP and more, covering common programming languages.
2. Code inspection: Discover code quality defects, code specification problems, code security vulnerabilities, invalid codes, etc. At present, many self-developed and well-known open source analysis tools have been integrated. The layered architecture can support rapid self-service management tools for teams.
3. Code measurement: Support comprehensive measurement of code from the three dimensions of code cyclomatic complexity, code repetition rate and code statistics.
4. DevOps integration: The client can be started via the command line. Standard APIs support connection to upstream and downstream systems, and various DevOps systems. Getting Started* How to get start
* How to deploy server and web
* How to deploy server and web with docker-compose
* How to use client
* Deploy Q&A Community* QQ Group: 361791391
* Discussion
* Wiki
* White Paper Changelogs* Check our Changelog Contributing* Check out CONTRIBUTING to see how to develop with TCA.
* Tencent Open Source Incentive Program encourages the participation and contribution of developers. We look forward to your active participation. LicenseTCA is MIT licensed Download CodeAnalysis
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
CodeAnalysis - Static Code Analysis
CodeAnalysis - Static Code Analysis
http://www.kitploit.com/2022/03/codeanalysis-static-code-analysis.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/codeanalysis-static-code-analysis.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
CodeAnalysis - Static Code Analysis
Tencent Cloud Code Analysis (https://www.kitploit.com/search/label/Code%20Analysis) (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It also supports the integration of other code analysis tools.
Code analysis is a technology, using lexical analysis, syntax analysis, control-flow analysis, data-flow analysis to make a comprehensive analysis of the code, so as to verify whether the code meets the requirements (https://www.kitploit.com/search/label/Requirements) of normative, security, reliability, maintainability and other indicators. Using TCA can help team find normative, structural, security vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) and other issues in the code, continuously monitor the quality of the project code and issue alerts. At the same time, TCA opens up APIs to support connection with upstream and downstream systems, so as to integrate code analysis capabilities, ensure code quality, and be more conducive to inheriting an excellent team code culture.
___________________________
@hacking_Attack
@Hacking_Video
Code analysis is a technology, using lexical analysis, syntax analysis, control-flow analysis, data-flow analysis to make a comprehensive analysis of the code, so as to verify whether the code meets the requirements (https://www.kitploit.com/search/label/Requirements) of normative, security, reliability, maintainability and other indicators. Using TCA can help team find normative, structural, security vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) and other issues in the code, continuously monitor the quality of the project code and issue alerts. At the same time, TCA opens up APIs to support connection with upstream and downstream systems, so as to integrate code analysis capabilities, ensure code quality, and be more conducive to inheriting an excellent team code culture.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.