https://external-preview.redd.it/6xG6cSZj2FEiqexYkUQOlQvI7sekCLiTMaYLPklTJBQ.jpg?width=640&crop=smart&auto=webp&s=483fe6e4c42d213304bb210589bdc099c9b5a55e Not too long ago my brother's account got hacked. My dad got quite pissed, and decided to text the person (who hacked the account) through my brothers account. It was quite entertaining. Now, the hacker is requesting us to change the email, to re-gain access into the account.
I am not stupid, nor am I smart. What repercussions would there be if I followed through with his requests? It seems fishy.
https://preview.redd.it/ocwwnuo3a3p81.jpg?width=720&format=pjpg&auto=webp&s=cd764c1a0d45c6f40aa2c2647a2a16d62ae182d7
submitted by /u/AlphaDrop
[link] [comments]
I am not stupid, nor am I smart. What repercussions would there be if I followed through with his requests? It seems fishy.
https://preview.redd.it/ocwwnuo3a3p81.jpg?width=720&format=pjpg&auto=webp&s=cd764c1a0d45c6f40aa2c2647a2a16d62ae182d7
submitted by /u/AlphaDrop
[link] [comments]
hacking: security in practice
i just got ddosed by some guy is there anything i can do
long story short my ps5 is connected via lan cable from my modem. some guy was talking crazy claiming he has a botnet and saying i’ll be offline for 6 hours. i have no access to router logs or any sort of source of data because i just moved in here and it’s not my house. is there anything i can do to get my wifi working again.
submitted by /u/oXerpz
[link] [comments]
i just got ddosed by some guy is there anything i can do
long story short my ps5 is connected via lan cable from my modem. some guy was talking crazy claiming he has a botnet and saying i’ll be offline for 6 hours. i have no access to router logs or any sort of source of data because i just moved in here and it’s not my house. is there anything i can do to get my wifi working again.
submitted by /u/oXerpz
[link] [comments]
reddit
i just got ddosed by some guy is there anything i can do
long story short my ps5 is connected via lan cable from my modem. some guy was talking crazy claiming he has a botnet and saying i’ll be offline...
How I Was Able To TakeOver Any Account On One Of Europe's Largest Media Companies
Welcome back, I have not produced a writeup in over a week due to hunting for further vulnerabilities on Hall Of Fame sites, many of which…Continue reading on Medium »
Read more...
Welcome back, I have not produced a writeup in over a week due to hunting for further vulnerabilities on Hall Of Fame sites, many of which…Continue reading on Medium »
Read more...
How I Was Able To TakeOver Any Account On One Of Europe's Largest Media Companies
https://medium.com/@tobydavenn/how-i-was-able-to-takeover-any-account-on-one-of-europes-largest-media-companies-e8d25e59c08?source=rss------bug_bounty-5
https://medium.com/@tobydavenn/how-i-was-able-to-takeover-any-account-on-one-of-europes-largest-media-companies-e8d25e59c08?source=rss------bug_bounty-5
Welcome back, I have not produced a writeup in over a week due to hunting for further vulnerabilities on Hall Of Fame sites, many of which…Continue reading on Medium » (https://medium.com/@tobydavenn/how-i-was-able-to-takeover-any-account-on-one-of-europes-largest-media-companies-e8d25e59c08?source=rss------bug_bounty-5)
User Uncontrained Delegation
https://www.reddit.com/r/Pentesting/comments/tkrh1g/user_uncontrained_delegation/
<!-- SC_OFF -->Hello everyone ! I want to make sure I am understanding this vulnerability correctly: If you want to exploit this vulnerability you need: - A compromised user account with "TRUSTED_FOR_DELEGATION" - A compromised user account with privileges to create SPNs - A compromised user account with privileges to create DNS entries Is that right ? It seems pretty hard to find this in real life ? any experience on this ? <!-- SC_ON --> submitted by /u/hegusung (https://www.reddit.com/user/hegusung)
[link] (https://www.reddit.com/r/Pentesting/comments/tkrh1g/user_uncontrained_delegation/) [comments] (https://www.reddit.com/r/Pentesting/comments/tkrh1g/user_uncontrained_delegation/)
https://www.reddit.com/r/Pentesting/comments/tkrh1g/user_uncontrained_delegation/
<!-- SC_OFF -->Hello everyone ! I want to make sure I am understanding this vulnerability correctly: If you want to exploit this vulnerability you need: - A compromised user account with "TRUSTED_FOR_DELEGATION" - A compromised user account with privileges to create SPNs - A compromised user account with privileges to create DNS entries Is that right ? It seems pretty hard to find this in real life ? any experience on this ? <!-- SC_ON --> submitted by /u/hegusung (https://www.reddit.com/user/hegusung)
[link] (https://www.reddit.com/r/Pentesting/comments/tkrh1g/user_uncontrained_delegation/) [comments] (https://www.reddit.com/r/Pentesting/comments/tkrh1g/user_uncontrained_delegation/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta
Lapsus$ Data Kidnappers Claim Snatches From Microsoft, OktaPost Views: 49
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Lapsus$ shared screenshots of internal Okta systems and 40Gb of purportedly stolen Microsoft data on Bing, Bing Maps and Cortana.
Both Microsoft and Okta are investigating claims by the new, precocious data extortion group Lapsus$ that the gang has breached their systems.
Lapsus$ claimed to have gotten itself “superuser/admin” access to internal systems at authentication firm Okta. It also posted 40GB worth of files to its Telegram channel, including screenshots and source code, of what the group said is Microsoft’s internal projects and systems.
The news was first reported by Vice and Reuters.
Okta confirmed on Tuesday that it had been hit and that some customers may have been affected. The scope of the breach isn’t yet clear, but it could be huge: According to Okta, it has hundreds of millions of users that use its platform to provide access to networks, including employees at thousands of large companies such as Fedex, Moody’s, T-Mobile, Hewlett Packard Enterprise and GrubHub, to name a few.
A Microsoft spokesperson told Threatpost that its investigation found that an account had been compromised, “granting limited access.” Its cybersecurity response teams quickly engaged to remediate the compromised account and prevent further activity, the spokesperson said.
“We do not rely on the secrecy of code as a security measure and viewing source code isn’t tied to elevation of risk,” Microsoft said. The Microsoft Threat Intelligence team on Tuesday published a blog detailing observed activity of the Lapsus$, which Microsoft tracks as DEV-0537. ‘Very Worrisome’ ScreenshotsThe purported Okta screenshots included one that appears to show Okta’s Slack channels and another with a Cloudflare interface. In an accompanying message, the group said its focus was “ONLY on Okta customers.”
Bill Demirkapi, an independent security researcher, tweeted that the screenshots “are very worrisome. … LAPSUS$ appears to have gotten access to the @Cloudflare tenant with the ability to reset employee passwords.”
Cloudflare announced on Tuesday that it’s not up for risking its employees’ Okta credentials. The company, which uses Okta for employee authentication, is resetting its employees credentials, Co-founder and CEO Matthew Prince said on Twitter, “out of an abundance of caution.”
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
We are resetting the @Okta credentials of any employees who’ve changed their passwords in the last 4 months, out of abundance of caution. We’ve confirmed no compromise. Okta is one layer of security. Given they may have an issue we’re evaluating alternatives for that layer.
— Matthew Prince 🌥 (@eastdakota) March 22, 2022 Breach Dates to JanuaryDemirkapi noted another scary thing about the screenshots: Namely, they indicate a date of Jan. 21, 2022. If the date is correct, it suggests that Okta “failed to publicly acknowledge any breach for at least two months,” he said.
The LAPSUS$ ransomware group has claimed to breach Okta sharing the following images from internal systems. pic.twitter.com/eTtpgRzer7
— Bill Demirkapi (@BillDemirkapi) March 22, 2022
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Yes, the dates could mean that Lapsus$ has had access to Okta for months, but then again, they could instead indicate that Lapsus$ enjoyed a brief [...]
Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta
Lapsus$ Data Kidnappers Claim Snatches From Microsoft, OktaPost Views: 49
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Lapsus$ shared screenshots of internal Okta systems and 40Gb of purportedly stolen Microsoft data on Bing, Bing Maps and Cortana.
Both Microsoft and Okta are investigating claims by the new, precocious data extortion group Lapsus$ that the gang has breached their systems.
Lapsus$ claimed to have gotten itself “superuser/admin” access to internal systems at authentication firm Okta. It also posted 40GB worth of files to its Telegram channel, including screenshots and source code, of what the group said is Microsoft’s internal projects and systems.
The news was first reported by Vice and Reuters.
Okta confirmed on Tuesday that it had been hit and that some customers may have been affected. The scope of the breach isn’t yet clear, but it could be huge: According to Okta, it has hundreds of millions of users that use its platform to provide access to networks, including employees at thousands of large companies such as Fedex, Moody’s, T-Mobile, Hewlett Packard Enterprise and GrubHub, to name a few.
A Microsoft spokesperson told Threatpost that its investigation found that an account had been compromised, “granting limited access.” Its cybersecurity response teams quickly engaged to remediate the compromised account and prevent further activity, the spokesperson said.
“We do not rely on the secrecy of code as a security measure and viewing source code isn’t tied to elevation of risk,” Microsoft said. The Microsoft Threat Intelligence team on Tuesday published a blog detailing observed activity of the Lapsus$, which Microsoft tracks as DEV-0537. ‘Very Worrisome’ ScreenshotsThe purported Okta screenshots included one that appears to show Okta’s Slack channels and another with a Cloudflare interface. In an accompanying message, the group said its focus was “ONLY on Okta customers.”
Bill Demirkapi, an independent security researcher, tweeted that the screenshots “are very worrisome. … LAPSUS$ appears to have gotten access to the @Cloudflare tenant with the ability to reset employee passwords.”
Cloudflare announced on Tuesday that it’s not up for risking its employees’ Okta credentials. The company, which uses Okta for employee authentication, is resetting its employees credentials, Co-founder and CEO Matthew Prince said on Twitter, “out of an abundance of caution.”
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
We are resetting the @Okta credentials of any employees who’ve changed their passwords in the last 4 months, out of abundance of caution. We’ve confirmed no compromise. Okta is one layer of security. Given they may have an issue we’re evaluating alternatives for that layer.
— Matthew Prince 🌥 (@eastdakota) March 22, 2022 Breach Dates to JanuaryDemirkapi noted another scary thing about the screenshots: Namely, they indicate a date of Jan. 21, 2022. If the date is correct, it suggests that Okta “failed to publicly acknowledge any breach for at least two months,” he said.
The LAPSUS$ ransomware group has claimed to breach Okta sharing the following images from internal systems. pic.twitter.com/eTtpgRzer7
— Bill Demirkapi (@BillDemirkapi) March 22, 2022
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Yes, the dates could mean that Lapsus$ has had access to Okta for months, but then again, they could instead indicate that Lapsus$ enjoyed a brief [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta Lapsus$ Data Kidnappers Claim Snatches From Microsoft, OktaPost Views: 49 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png Reading Time: 2…
romp before it got kicked out. The latter is the case, Okta CEO Todd McKinnon.
On Tuesday, the CEO tweeted that in January 2022, Okta detected an attempted compromise of “a third-party customer support engineer working for one of our subprocessors” but that “the matter was investigated and contained by the subprocessor.”
Okta believes the screenshots Lapsus$ shared online are connected to the January incident. “Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January,” McKinnon said.
We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January. (2 of 2)
— Todd McKinnon (@toddmckinnon) March 22, 2022
See Also: Offensive Security Tool: Scapy Did Rogue Employees Pitch In?If the dates are accurate, it means that Lapsus$ may well have been successful when it put up a “help wanted” notice on its Telegram channel on March 10. The group posted that it recruiting company insiders – including those at Microsoft; other big software/gaming companies such as Apple, IBM or EA; telecoms such as Telefonica, ATT; and more – to help it carry out its dirty work.
From its March 10 Telegram post:
“We recruit employees/insider at the following!!!! … TO NOTE: WE ARE NOT LOOKING FOR DATA, WE ARE LOOKING FOR THE EMPLOYEE TO PROVIDE US A VPN OR CITRIX TO THE NETWORK, or some anydesk” – references to technologies that the cybercriminals could use to penetrate targets’ networks with insiders’ help. Data on Bing, Bing Maps, Cortana Allegedly StolenOn Monday, Lapsus$ began to circulate a 10GB compressed archive that purportedly contains internal data on Microsoft’s Bing search engine and Bing Maps, along with the source code to the company’s voice assistant software Cortana.
The leaked data is dated March 20, 2022.
“Bing maps is 90% complete dump. Bing and Cortana around 45%,” Lapsus$ wrote on its Telegram channel.
Microsoft acknowledged the claims and said that it’s investigating. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Full posthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/79ohvicqaKcVP9KT2mDdTH-90x90.jpg Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Lapsus-group-has-hacked-Ubisoft-as-well-90x90.jpg Ubisoft has confirmed it was hacked by Lapsus$ group1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/raccoon-stealer-90x90.jpg Raccoon Stealer Crawls Into Telegram1 week ago
* h[...]
On Tuesday, the CEO tweeted that in January 2022, Okta detected an attempted compromise of “a third-party customer support engineer working for one of our subprocessors” but that “the matter was investigated and contained by the subprocessor.”
Okta believes the screenshots Lapsus$ shared online are connected to the January incident. “Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January,” McKinnon said.
We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January. (2 of 2)
— Todd McKinnon (@toddmckinnon) March 22, 2022
See Also: Offensive Security Tool: Scapy Did Rogue Employees Pitch In?If the dates are accurate, it means that Lapsus$ may well have been successful when it put up a “help wanted” notice on its Telegram channel on March 10. The group posted that it recruiting company insiders – including those at Microsoft; other big software/gaming companies such as Apple, IBM or EA; telecoms such as Telefonica, ATT; and more – to help it carry out its dirty work.
From its March 10 Telegram post:
“We recruit employees/insider at the following!!!! … TO NOTE: WE ARE NOT LOOKING FOR DATA, WE ARE LOOKING FOR THE EMPLOYEE TO PROVIDE US A VPN OR CITRIX TO THE NETWORK, or some anydesk” – references to technologies that the cybercriminals could use to penetrate targets’ networks with insiders’ help. Data on Bing, Bing Maps, Cortana Allegedly StolenOn Monday, Lapsus$ began to circulate a 10GB compressed archive that purportedly contains internal data on Microsoft’s Bing search engine and Bing Maps, along with the source code to the company’s voice assistant software Cortana.
The leaked data is dated March 20, 2022.
“Bing maps is 90% complete dump. Bing and Cortana around 45%,” Lapsus$ wrote on its Telegram channel.
Microsoft acknowledged the claims and said that it’s investigating. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Full posthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/79ohvicqaKcVP9KT2mDdTH-90x90.jpg Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Lapsus-group-has-hacked-Ubisoft-as-well-90x90.jpg Ubisoft has confirmed it was hacked by Lapsus$ group1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/raccoon-stealer-90x90.jpg Raccoon Stealer Crawls Into Telegram1 week ago
* h[...]
Hacking Articles Tips Tricks Videos Tutorials
romp before it got kicked out. The latter is the case, Okta CEO Todd McKinnon. On Tuesday, the CEO tweeted that in January 2022, Okta detected an attempted compromise of “a third-party customer support engineer working for one of our subprocessors” but that…
ttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/kali-bright-90x90.jpg Kali Unkaputtbar – a new feature on Kali Linux2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/wolf-in-sheps-clothing-2-scaled-e1646927438585-90x90.jpeg Malware Posing as Russia DDoS Tool Bites Ukraine Hackers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-90x90.jpg Agencies in Ukraine targeted with MicroBackdoor malware2 weeks ago
The post Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/wolf-in-sheps-clothing-2-scaled-e1646927438585-90x90.jpeg Malware Posing as Russia DDoS Tool Bites Ukraine Hackers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-90x90.jpg Agencies in Ukraine targeted with MicroBackdoor malware2 weeks ago
The post Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta first appeared on Black Hat Ethical Hacking.
ShellcodeTemplate - An Easily Modifiable Shellcode Template For Windows X64/X86
http://www.kitploit.com/2022/03/shellcodetemplate-easily-modifiable.html
http://www.kitploit.com/2022/03/shellcodetemplate-easily-modifiable.html
An easily modifiable shellcode template for Windows (https://www.kitploit.com/search/label/Windows) x64/x86 How does it work? This template is heavily based on Austin Hudson's (aka SecIdiot) (https://twitter.com/ilove2pwn_) TitanLdr (https://github.com/SecIdiot/TitanLdr) It compiles the project into a PE Executable and extracts the .text section
Example The entrypoint of the shellcode looks like this. Of course, this can be changed for your need. First we need to initialize needed libraries and functions by using our custom written GetModuleHandle and GetProcAddress. SEC( text, B ) VOID Entry( VOID )
{
INSTANCE Instance = { };
Instance.Modules.Kernel32 = TGetModuleHandle( HASH_KERNEL32 );
Instance.Modules.Ntdll = TGetModuleHandle( HASH_NTDLL );
if ( Instance.Modules.Kernel32 != NULL )
{
// Load needed functions
Instance.Win32.LoadLibraryA = TGetProcAddr( Instance.Modules.Kernel32, 0xb7072fdb );
// Load needed Libraries
Instance.Modules.User32 = Instance.Win32.LoadLibraryA( GET_SYMBOL( "User32" ) );
if ( Instance.Modules.User32 != NULL )
{
Instance.Win32.MessageBoxA = TGetProcAddr( Instance.Modules.User32, 0xb303ebb4 );
}
}
// ------ Code ------
Instance.Win32.MessageBoxA( NULL, GET_SYMBOL( "Hello World" ), GET_SYMBOL( "MessageBox Title" ), MB_OK );
} Btw as you can see we can use normal strings in our shellcode. This is because we include the .rdata section into our shellcode at linking time. And GET_SYMBOL gets the pointer to the function or string via its relative offset to GetRIP()
Example The entrypoint of the shellcode looks like this. Of course, this can be changed for your need. First we need to initialize needed libraries and functions by using our custom written GetModuleHandle and GetProcAddress. SEC( text, B ) VOID Entry( VOID )
{
INSTANCE Instance = { };
Instance.Modules.Kernel32 = TGetModuleHandle( HASH_KERNEL32 );
Instance.Modules.Ntdll = TGetModuleHandle( HASH_NTDLL );
if ( Instance.Modules.Kernel32 != NULL )
{
// Load needed functions
Instance.Win32.LoadLibraryA = TGetProcAddr( Instance.Modules.Kernel32, 0xb7072fdb );
// Load needed Libraries
Instance.Modules.User32 = Instance.Win32.LoadLibraryA( GET_SYMBOL( "User32" ) );
if ( Instance.Modules.User32 != NULL )
{
Instance.Win32.MessageBoxA = TGetProcAddr( Instance.Modules.User32, 0xb303ebb4 );
}
}
// ------ Code ------
Instance.Win32.MessageBoxA( NULL, GET_SYMBOL( "Hello World" ), GET_SYMBOL( "MessageBox Title" ), MB_OK );
} Btw as you can see we can use normal strings in our shellcode. This is because we include the .rdata section into our shellcode at linking time. And GET_SYMBOL gets the pointer to the function or string via its relative offset to GetRIP()
Get Started Clone this project and you are ready to start git clone https://www.github.com/Cracked5pider/ShellcodeTemplate
Next you would need to change the project name in the makefile from ShellcodeTemplate to whatever you want Then you can compile the project by using make make // to compile x64 and x86
make x64 // to compile only x64
make x86 // to compile only x86
Credit Huge credit goes to Austin Hudson (aka SecIdiot) (https://twitter.com/ilove2pwn_)!!!
Download ShellcodeTemplate (https://github.com/Cracked5pider/ShellcodeTemplate)
Next you would need to change the project name in the makefile from ShellcodeTemplate to whatever you want Then you can compile the project by using make make // to compile x64 and x86
make x64 // to compile only x64
make x86 // to compile only x86
Credit Huge credit goes to Austin Hudson (aka SecIdiot) (https://twitter.com/ilove2pwn_)!!!
Download ShellcodeTemplate (https://github.com/Cracked5pider/ShellcodeTemplate)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Dive : A Tool For Exploring Each Layer In A Docker Image
Dive is a tool for exploring a docker image, layer contents, and discovering ways to shrink the size of your Docker/OCI image.
To analyze a Docker image simply run dive with an image tag/id/digest:
dive <your-image-tag
or if you want to build your image then jump straight into analyzing it:
dive build -t <some-tag
Building on Macbook (supporting only the Docker container engine)
docker run –rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-v “$(pwd)”:”$(pwd)” \
-w “$(pwd)” \
-v “$HOME/.dive.yaml”:”$HOME/.dive.yaml” \
wagoodman/dive:latest build -t .
Additionally you can run this in your CI pipeline to ensure you’re keeping wasted space to a minimum (this skips the UI):
CI=true dive <your-image Basic FeaturesShow Docker image contents broken down by layer
As you select a layer on the left, you are shown the contents of that layer combined with all previous layers on the right. Also, you can fully explore the file tree with the arrow keys.
Indicate what’s changed in each layer
Files that have changed, been modified, added, or removed are indicated in the file tree. This can be adjusted to show changes for a specific layer, or aggregated changes up to this layer.
Estimate “image efficiency”
The lower left pane shows basic layer info and an experimental metric that will guess how much wasted space your image contains. This might be from duplicating files across layers, moving files across layers, or not fully removing files. Both a percentage “score” and total wasted file space is provided.
Quick build/analysis cycles
You can build a Docker image and do an immediate analysis with one command:
CI Integration
Analyze an image and get a pass/fail result based on the image efficiency and wasted space. Simply set
Multiple Image Sources and Container Engines Supported
With the
dive <your-image–source
With valid
*
*
*
wget https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_linux_amd64.deb
sudo apt install ./dive_0.9.2_linux_amd64.deb
RHEL/Centos
curl -OL https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_linux_amd64.rpm
rpm -i dive_0.9.2_linux_amd64.rpm
Arch Linux
Available as dive in the Arch User Repository (AUR).
yay -S dive
The above example assumes
Mac
If you use Homebrew:
brew install dive
If you use MacPorts:
sudo port install dive
Or download the latest Darwin build from the releases page.
Windows
Download the latest release.
Go tools Requires Go version 1.10 or higher. CI IntegrationWhen running dive with the environment variable
rules:
# If the efficiency is measured below X%, mark as failed.
# Expressed as a ratio between 0-1.
lowestEfficiency: 0.95
# If the amount of wasted space is at least X or larger than X, mark as failed.
# Expressed in B, KB, MB, and GB.
highestWastedBytes: 20MB
# If the amount of wasted space makes up for [...]
Dive : A Tool For Exploring Each Layer In A Docker Image
Dive is a tool for exploring a docker image, layer contents, and discovering ways to shrink the size of your Docker/OCI image.
To analyze a Docker image simply run dive with an image tag/id/digest:
dive <your-image-tag
or if you want to build your image then jump straight into analyzing it:
dive build -t <some-tag
Building on Macbook (supporting only the Docker container engine)
docker run –rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-v “$(pwd)”:”$(pwd)” \
-w “$(pwd)” \
-v “$HOME/.dive.yaml”:”$HOME/.dive.yaml” \
wagoodman/dive:latest build -t .
Additionally you can run this in your CI pipeline to ensure you’re keeping wasted space to a minimum (this skips the UI):
CI=true dive <your-image Basic FeaturesShow Docker image contents broken down by layer
As you select a layer on the left, you are shown the contents of that layer combined with all previous layers on the right. Also, you can fully explore the file tree with the arrow keys.
Indicate what’s changed in each layer
Files that have changed, been modified, added, or removed are indicated in the file tree. This can be adjusted to show changes for a specific layer, or aggregated changes up to this layer.
Estimate “image efficiency”
The lower left pane shows basic layer info and an experimental metric that will guess how much wasted space your image contains. This might be from duplicating files across layers, moving files across layers, or not fully removing files. Both a percentage “score” and total wasted file space is provided.
Quick build/analysis cycles
You can build a Docker image and do an immediate analysis with one command:
dive build -t some-tag .You only need to replace your docker buildcommand with the same dive buildcommand.CI Integration
Analyze an image and get a pass/fail result based on the image efficiency and wasted space. Simply set
CI=truein the environment when invoking any valid dive command.Multiple Image Sources and Container Engines Supported
With the
--sourceoption, you can select where to fetch the container image from:dive <your-image–source
With valid
sourceoptions as such:*
docker: Docker engine (the default option)*
docker-archive: A Docker Tar Archive from disk*
podman: Podman engine (linux only) InstallationUbuntu/Debianwget https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_linux_amd64.deb
sudo apt install ./dive_0.9.2_linux_amd64.deb
RHEL/Centos
curl -OL https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_linux_amd64.rpm
rpm -i dive_0.9.2_linux_amd64.rpm
Arch Linux
Available as dive in the Arch User Repository (AUR).
yay -S dive
The above example assumes
yayas the tool for installing AUR packages.Mac
If you use Homebrew:
brew install dive
If you use MacPorts:
sudo port install dive
Or download the latest Darwin build from the releases page.
Windows
Download the latest release.
Go tools Requires Go version 1.10 or higher. CI IntegrationWhen running dive with the environment variable
CI=truethen the dive UI will be bypassed and will instead analyze your docker image, giving it a pass/fail indication via return code. Currently there are three metrics supported via a .dive-cifile that you can put at the root of your repo:rules:
# If the efficiency is measured below X%, mark as failed.
# Expressed as a ratio between 0-1.
lowestEfficiency: 0.95
# If the amount of wasted space is at least X or larger than X, mark as failed.
# Expressed in B, KB, MB, and GB.
highestWastedBytes: 20MB
# If the amount of wasted space makes up for [...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Dive : A Tool For Exploring Each Layer In A Docker Image Dive is a tool for exploring a docker image, layer contents, and discovering ways to shrink the size of your Docker/OCI image. To analyze a Docker image simply run dive with an…
X% or more of the image, mark as failed.
# Note: the base image layer is NOT included in the total image size.
# Expressed as a ratio between 0-1; fails if the threshold is met or crossed.
highestUserWastedPercent: 0.20 KeyBindingsKey BindingDescriptionCtrl + CExitTabSwitch between the layer and filetree viewsCtrl + FFilter filesPageUpScroll up a pagePageDownScroll down a pageCtrl + ALayer view: see aggregated image modificationsCtrl + LLayer view: see current layer modificationsSpaceFiletree view: collapse/uncollapse a directoryCtrl + SpaceFiletree view: collapse/uncollapse all directoriesCtrl + AFiletree view: show/hide added filesCtrl + RFiletree view: show/hide removed filesCtrl + MFiletree view: show/hide modified filesCtrl + UFiletree view: show/hide unmodified filesCtrl + BFiletree view: show/hide file attributesPageUpFiletree view: scroll up a pagePageDownFiletree view: scroll down a page UI ConfigurationNo configuration is necessary, however, you can create a config file and override values: supported options are “docker” and “podman”container-engine: docker continue with analysis even if there are errors parsing the image archiveignore-errors: false
log:
enabled: true
path: ./dive.log
level: info Note: you can specify multiple bindings by separating values with a comma.Note: UI hinting is derived from the first bindingkeybinding:
# Global bindings
quit: ctrl+c
toggle-view: tab
filter-files: ctrl+f, ctrl+slash
# Layer view specific bindings
compare-all: ctrl+a
compare-layer: ctrl+l
# File view specific bindings
toggle-collapse-dir: space
toggle-collapse-all-dir: ctrl+space
toggle-added-files: ctrl+a
toggle-removed-files: ctrl+r
toggle-modified-files: ctrl+m
toggle-unmodified-files: ctrl+u
toggle-filetree-attributes: ctrl+b
page-up: pgup
page-down: pgdn
diff:
# You can change the default files shown in the filetree (right pane). All diff types are shown by default.
hide:
– added
– removed
– modified
– unmodified
filetree:
# The default directory-collapse state
collapse-dir: false
# The percentage of screen width the filetree should take on the screen (must be >0 and
pane-width: 0.5
# Show the file attributes next to the filetree
show-attributes: true
layer:
# Enable showing all changes from this layer and every previous layer
show-aggregated-changes: false
dive will search for configs in the following locations:
*
# Note: the base image layer is NOT included in the total image size.
# Expressed as a ratio between 0-1; fails if the threshold is met or crossed.
highestUserWastedPercent: 0.20 KeyBindingsKey BindingDescriptionCtrl + CExitTabSwitch between the layer and filetree viewsCtrl + FFilter filesPageUpScroll up a pagePageDownScroll down a pageCtrl + ALayer view: see aggregated image modificationsCtrl + LLayer view: see current layer modificationsSpaceFiletree view: collapse/uncollapse a directoryCtrl + SpaceFiletree view: collapse/uncollapse all directoriesCtrl + AFiletree view: show/hide added filesCtrl + RFiletree view: show/hide removed filesCtrl + MFiletree view: show/hide modified filesCtrl + UFiletree view: show/hide unmodified filesCtrl + BFiletree view: show/hide file attributesPageUpFiletree view: scroll up a pagePageDownFiletree view: scroll down a page UI ConfigurationNo configuration is necessary, however, you can create a config file and override values: supported options are “docker” and “podman”container-engine: docker continue with analysis even if there are errors parsing the image archiveignore-errors: false
log:
enabled: true
path: ./dive.log
level: info Note: you can specify multiple bindings by separating values with a comma.Note: UI hinting is derived from the first bindingkeybinding:
# Global bindings
quit: ctrl+c
toggle-view: tab
filter-files: ctrl+f, ctrl+slash
# Layer view specific bindings
compare-all: ctrl+a
compare-layer: ctrl+l
# File view specific bindings
toggle-collapse-dir: space
toggle-collapse-all-dir: ctrl+space
toggle-added-files: ctrl+a
toggle-removed-files: ctrl+r
toggle-modified-files: ctrl+m
toggle-unmodified-files: ctrl+u
toggle-filetree-attributes: ctrl+b
page-up: pgup
page-down: pgdn
diff:
# You can change the default files shown in the filetree (right pane). All diff types are shown by default.
hide:
– added
– removed
– modified
– unmodified
filetree:
# The default directory-collapse state
collapse-dir: false
# The percentage of screen width the filetree should take on the screen (must be >0 and
pane-width: 0.5
# Show the file attributes next to the filetree
show-attributes: true
layer:
# Enable showing all changes from this layer and every previous layer
show-aggregated-changes: false
dive will search for configs in the following locations:
*
$XDG_CONFIG_HOME/dive/*.yaml* $XDG_CONFIG_DIRS/dive/*.yaml* ~/.config/dive/*.yaml* ~/.dive.yamlDownload