Hacking on Medium
Software Reverse Engineering: Diffusing Phase 1
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Software Reverse Engineering: Diffusing Phase 1
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Software Reverse Engineering: Diffusing Phase 1
Baby, I hate little secrets you keep from me x_x
Hacking on Medium
Software Reverse Engineering: Diffusing Phase 2
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Software Reverse Engineering: Diffusing Phase 2
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Software Reverse Engineering: Diffusing Phase 2
Baby, I hate little secrets you keep from me x_x
Hacking on Medium
Spring4Shell
https://cdn-images-1.medium.com/max/850/1*K88NZStxoHaR27AkKLUcqQ.png
Spring4Shell and Spring Cloud RCE vulnerability Scanner
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Spring4Shell
https://cdn-images-1.medium.com/max/850/1*K88NZStxoHaR27AkKLUcqQ.png
Spring4Shell and Spring Cloud RCE vulnerability Scanner
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Spring4Shell
Spring4Shell and Spring Cloud RCE vulnerability Scanner
Hacking on Medium
TryHackMe: [Day 10] Networking Offensive Is The Best Defence
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
Help McSkidy and run nmap -sT MACHINE_IP. How many ports are open between 1 and 100?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: [Day 10] Networking Offensive Is The Best Defence
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
Help McSkidy and run nmap -sT MACHINE_IP. How many ports are open between 1 and 100?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: [Day 10] Networking Offensive Is The Best Defence
Help McSkidy and run nmap -sT MACHINE_IP. How many ports are open between 1 and 100?
Hacking on Medium
Software Reverse Engineering: Diffusing Phase 6
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Software Reverse Engineering: Diffusing Phase 6
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Software Reverse Engineering: Diffusing Phase 6
Baby, I hate little secrets you keep from me x_x
Hacking on Medium
Software Reverse Engineering: Diffusing Phase 3
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Software Reverse Engineering: Diffusing Phase 3
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Software Reverse Engineering: Diffusing Phase 3
Baby, I hate little secrets you keep from me x_x
Hacking on Medium
Software Reverse Engineering: Diffusing Phase 4
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Software Reverse Engineering: Diffusing Phase 4
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Software Reverse Engineering: Diffusing Phase 4
Baby, I hate little secrets you keep from me x_x
Hacking on Medium
Software Reverse Engineering: Diffusing Phase 5
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Software Reverse Engineering: Diffusing Phase 5
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Software Reverse Engineering: Diffusing Phase 5
Baby, I hate little secrets you keep from me x_x
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
learning metasploit importing modules.
Ok why are some modules and payloads right there like
https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-6470/
And others only have a link to the module like this one I cannot find the module to import? Cannot seem to localize them anywhere else neither.
MSF:ILITIES/REDHAT_LINUX-CVE-2021-25215
submitted by /u/Imaginary_Manager_44
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
learning metasploit importing modules.
Ok why are some modules and payloads right there like
https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-6470/
And others only have a link to the module like this one I cannot find the module to import? Cannot seem to localize them anywhere else neither.
MSF:ILITIES/REDHAT_LINUX-CVE-2021-25215
submitted by /u/Imaginary_Manager_44
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
learning metasploit importing modules.
Ok why are some modules and payloads right there...
Wholeaked - A File-Sharing Tool That Allows You To Find The Responsible Person In Case Of A Leakage
http://www.kitploit.com/2022/04/wholeaked-file-sharing-tool-that-allows.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/04/wholeaked-file-sharing-tool-that-allows.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Wholeaked - A File-Sharing Tool That Allows You To Find The Responsible Person In Case Of A Leakage
\ | |
\ | |
\ |Hidden |
-|signature3 |
+-----------+
Validation Part To find who leaked the document, you just need to provide the leaked file to wholeaked, and it will reveal the responsible person by comparing the signatures in the database. |wholeaked|| |--------+ | | | || | b@gov |Hidden | +---------+| | |Signature2 | | | +-----------+ +---------+ ">+-----------+ +---------+
|Top Secret | |Signature|
|.pdf | +---------+|Database |
| | |utkusen/ || | Document leaked by
| |->|wholeaked|| |--------+
| | | || | b@gov
|Hidden | +---------+| |
|Signature2 | | |
+-----------+ +---------+
Demonstration Video
File Types and Detection Modes wholeaked can add the unique signature to different sections of a file. Available detection modes are given below: File Hash: SHA256 hash of the file. All file types are supported. Binary: The signature is directly added to the binary. Almost all file types are supported. Metadata: The signature is added to a metadata (https://www.kitploit.com/search/label/Metadata) section of a file. Supported file types: PDF, DOCX, XLSX, PPTX, MOV, JPG, PNG, GIF, EPS, AI, PSD Watermark: An invisible (https://www.kitploit.com/search/label/Invisible) signature is inserted into the text. Only PDF files are supported. Installation From Binary You can download the pre-built binaries from the releases (https://github.com/utkusen/wholeaked/releases/latest) page and run. For example: unzip wholeaked_0.1.0_macOS_amd64.zip ./wholeaked --help From Source Install Go on your system Run: go install github.com/utkusen/wholeaked@latest Installing Dependencies wholeaked requires exiftool for adding signatures to metadata section of files. If you don't want to use this feature, you don't need to install it. Debian-based Linux: Run apt install exiftool macOS: Run brew install exiftool Windows: Download exiftool (https://www.kitploit.com/search/label/ExifTool) from here https://exiftool.org/ and put the exiftool.exe in the same directory (https://www.kitploit.com/search/label/Directory) with wholeaked. wholeaked requires pdftotext for verifying watermarks inside PDF files. If you don't want to use this feature, you don't need to install it. Download "Xpdf command line (https://www.kitploit.com/search/label/Command%20Line) tools" for Linux, macOS or Windows from here: https://www.xpdfreader.com/download.html Extract the archive and navigate to bin64 folder. Copy the pdftotext (or pdftotext.exe) executable to the same folder with wholeaked For Debian Based Linux: Run apt install libfontconfig command. Usage Basic Usage wholeaked requires a project name -n, the path of the base file which the signatures will add -f and a list of target recipients -t Example command: ./wholeaked -n test_project -f secret.pdf -t targets.txt The targets.txt file should contain name and the e-mail address in the following format: Utku Sen,utku@utkusen.com
Bill Gates,bill@microsoft.com
___________________________
@hacking_Attack
@Hacking_Video
\ | |
\ |Hidden |
-|signature3 |
+-----------+
Validation Part To find who leaked the document, you just need to provide the leaked file to wholeaked, and it will reveal the responsible person by comparing the signatures in the database. |wholeaked|| |--------+ | | | || | b@gov |Hidden | +---------+| | |Signature2 | | | +-----------+ +---------+ ">+-----------+ +---------+
|Top Secret | |Signature|
|.pdf | +---------+|Database |
| | |utkusen/ || | Document leaked by
| |->|wholeaked|| |--------+
| | | || | b@gov
|Hidden | +---------+| |
|Signature2 | | |
+-----------+ +---------+
Demonstration Video
File Types and Detection Modes wholeaked can add the unique signature to different sections of a file. Available detection modes are given below: File Hash: SHA256 hash of the file. All file types are supported. Binary: The signature is directly added to the binary. Almost all file types are supported. Metadata: The signature is added to a metadata (https://www.kitploit.com/search/label/Metadata) section of a file. Supported file types: PDF, DOCX, XLSX, PPTX, MOV, JPG, PNG, GIF, EPS, AI, PSD Watermark: An invisible (https://www.kitploit.com/search/label/Invisible) signature is inserted into the text. Only PDF files are supported. Installation From Binary You can download the pre-built binaries from the releases (https://github.com/utkusen/wholeaked/releases/latest) page and run. For example: unzip wholeaked_0.1.0_macOS_amd64.zip ./wholeaked --help From Source Install Go on your system Run: go install github.com/utkusen/wholeaked@latest Installing Dependencies wholeaked requires exiftool for adding signatures to metadata section of files. If you don't want to use this feature, you don't need to install it. Debian-based Linux: Run apt install exiftool macOS: Run brew install exiftool Windows: Download exiftool (https://www.kitploit.com/search/label/ExifTool) from here https://exiftool.org/ and put the exiftool.exe in the same directory (https://www.kitploit.com/search/label/Directory) with wholeaked. wholeaked requires pdftotext for verifying watermarks inside PDF files. If you don't want to use this feature, you don't need to install it. Download "Xpdf command line (https://www.kitploit.com/search/label/Command%20Line) tools" for Linux, macOS or Windows from here: https://www.xpdfreader.com/download.html Extract the archive and navigate to bin64 folder. Copy the pdftotext (or pdftotext.exe) executable to the same folder with wholeaked For Debian Based Linux: Run apt install libfontconfig command. Usage Basic Usage wholeaked requires a project name -n, the path of the base file which the signatures will add -f and a list of target recipients -t Example command: ./wholeaked -n test_project -f secret.pdf -t targets.txt The targets.txt file should contain name and the e-mail address in the following format: Utku Sen,utku@utkusen.com
Bill Gates,bill@microsoft.com
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
After execution is completed, the following unique files will be generated: test_project/files/Utku_Sen/secret.pdf
test_project/files/Bill_Gates/secret.pdf
By default, wholeaked adds signatures to all available places that are defined in the "File Types and Detection Modes" section. If you don't want to use a method, you can define it with a false flag. For example: ./wholeaked -n test_project -f secret.pdf -t targets.txt -binary=false -metadata=false -watermark=false Sending E-mails In order to send e-mails, you need to fill some sections in the CONFIG file. If you want to send e-mails via Sendgrid, type your API key to the SENDGRID_API_KEY section. If you want to send e-mails via AWS SES integration, you need to install awscli on your machine and add the required AWS key to it. wholeaked will read the key by itself. But you need to fill the AWS_REGION section in the config file. If you want to send e-mails via a SMTP server, fill the SMTP_SERVER, SMTP_PORT, SMTP_USERNAME, SMTP_PASSWORD sections. The other necessary fields to fill: EMAIL_TEMPLATE_PATH Path of the e-mail's body. You can specify use HTML or text format. EMAIL_CONTENT_TYPE Can be html or text EMAIL_SUBJECT Subject of the e-mail FROM_NAME From name of the e-mail FROM_EMAIL From e-mail of the e-mail To specify the sending method, you can use -sendgrid, -ses or -smtp flags. For example: ./wholeaked -n test_project -f secret.pdf -t targets.txt -sendgrid Validating a Leaked File You can use the -validate flag to reveal the owner of a leaked file. wholeaked will compare the signatures detected in the file and the database located in the project folder. Example: ./wholeaked -n test_project -f secret.pdf -validate Important: You shouldn't delete the project_folder/db.csv file if you want to use the file validation feature. If that file is deleted, wholeaked won't be able to compare the signatures.
Download Wholeaked (https://github.com/utkusen/wholeaked)
___________________________
@hacking_Attack
@Hacking_Video
test_project/files/Bill_Gates/secret.pdf
By default, wholeaked adds signatures to all available places that are defined in the "File Types and Detection Modes" section. If you don't want to use a method, you can define it with a false flag. For example: ./wholeaked -n test_project -f secret.pdf -t targets.txt -binary=false -metadata=false -watermark=false Sending E-mails In order to send e-mails, you need to fill some sections in the CONFIG file. If you want to send e-mails via Sendgrid, type your API key to the SENDGRID_API_KEY section. If you want to send e-mails via AWS SES integration, you need to install awscli on your machine and add the required AWS key to it. wholeaked will read the key by itself. But you need to fill the AWS_REGION section in the config file. If you want to send e-mails via a SMTP server, fill the SMTP_SERVER, SMTP_PORT, SMTP_USERNAME, SMTP_PASSWORD sections. The other necessary fields to fill: EMAIL_TEMPLATE_PATH Path of the e-mail's body. You can specify use HTML or text format. EMAIL_CONTENT_TYPE Can be html or text EMAIL_SUBJECT Subject of the e-mail FROM_NAME From name of the e-mail FROM_EMAIL From e-mail of the e-mail To specify the sending method, you can use -sendgrid, -ses or -smtp flags. For example: ./wholeaked -n test_project -f secret.pdf -t targets.txt -sendgrid Validating a Leaked File You can use the -validate flag to reveal the owner of a leaked file. wholeaked will compare the signatures detected in the file and the database located in the project folder. Example: ./wholeaked -n test_project -f secret.pdf -validate Important: You shouldn't delete the project_folder/db.csv file if you want to use the file validation feature. If that file is deleted, wholeaked won't be able to compare the signatures.
Download Wholeaked (https://github.com/utkusen/wholeaked)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - utkusen/wholeaked: a file-sharing tool that allows you to find the responsible person in case of a leakage
a file-sharing tool that allows you to find the responsible person in case of a leakage - utkusen/wholeaked
Types of Steganography methods that are used for hiding confidential data.
https://prasan26.medium.com/types-of-steganography-methods-that-are-used-for-hiding-confidential-data-b3c00132b972?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://prasan26.medium.com/types-of-steganography-methods-that-are-used-for-hiding-confidential-data-b3c00132b972?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Types of Steganography methods that are used for hiding confidential data.
> Are the images really safe?
> Are the images really safe?Continue reading on Medium » (https://prasan26.medium.com/types-of-steganography-methods-that-are-used-for-hiding-confidential-data-b3c00132b972?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Types of Steganography methods that are used for hiding confidential data.
> Are the images really safe?
Types of Steganography methods that are used for hiding confidential data.
> Are the images really safe?Continue reading on Medium »
Read more...
> Are the images really safe?Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Osmedeus : A Workflow Engine For Offensive Security
Osmedeus is a Workflow Engine for Offensive Security.
Installation
NOTE that you need some essential tools like
bash -c “$(curl -fsSL https://raw.githubusercontent.com/osmedeus/osmedeus-base/master/install.sh)”
Build the engine from source
Make sure you installed
mkdir -p $GOPATH/src/github.com/j3ssie
git clone –depth=1 https://github.com/j3ssie/osmedeus $GOPATH/src/github.com/j3ssie/osmedeus
cd $GOPATH/src/github.com/j3ssie/osmedeus
make build
Usage
Scan Usage:
osmedeus scan -f [flowName] -t [target]
osmedeus scan -m [modulePath] -T [targetsFile]
osmedeus scan -f /path/to/flow.yaml -t [target]
osmedeus scan -m /path/to/module.yaml -t [target] –params ‘port=9200’
osmedeus scan -m /path/to/module.yaml -t [target] -l /tmp/log.log
cat targets | osmedeus scan -f sample
Practical Scan Usage:
osmedeus scan -T list_of_targets.txt -W custom_workspaces
osmedeus scan -t target.com -w workspace_name –debug
osmedeus scan -f general -t www.sample.com
osmedeus scan -f gdirb -T list_of_target.txt
osmedeus scan -m ~/.osmedeus/core/workflow/test/dirbscan.yaml -t list_of_urls.txt
osmedeus scan –wfFolder ~/custom-workflow/ -f your-custom-workflow -t list_of_urls.txt
Provider Usage:
osmedeus provider build
osmedeus provider build –token xxx –rebuild –ic
osmedeus provider create –name ‘sample’
osmedeus provider health –debug
Cloud Usage:
osmedeus cloud -f [flowName] -t [target]
osmedeus cloud -m [modulePath] -t [target]
osmedeus cloud -c 10 -f [flowName] -T [targetsFile]
osmedeus cloud –token xxx -G -c 10 -f [flowName] -T [targetsFile]
osmedeus cloud –chunk -c 10 -f [flowName] -t [targetsFile]
Utilities Usage:
osmedeus health
osmedeus version –json
osmedeus utils tmux ls
osmedeus utils tmux logs -A -l 10
osmedeus utils ps
osmedeus utils ps –proc ‘jaeles’
osmedeus utils cron –cmd ‘osmdeus scan -t example.com’ –sch 60
osmedeus utils cron –for –cmd ‘osmedeus scan -t example.com’
Download
___________________________
@hacking_Attack
@Hacking_Video
Osmedeus : A Workflow Engine For Offensive Security
Osmedeus is a Workflow Engine for Offensive Security.
Installation
NOTE that you need some essential tools like
curl, wget, git, zipand login as root to startbash -c “$(curl -fsSL https://raw.githubusercontent.com/osmedeus/osmedeus-base/master/install.sh)”
Build the engine from source
Make sure you installed
golang >= v1.17mkdir -p $GOPATH/src/github.com/j3ssie
git clone –depth=1 https://github.com/j3ssie/osmedeus $GOPATH/src/github.com/j3ssie/osmedeus
cd $GOPATH/src/github.com/j3ssie/osmedeus
make build
Usage
Scan Usage:
osmedeus scan -f [flowName] -t [target]
osmedeus scan -m [modulePath] -T [targetsFile]
osmedeus scan -f /path/to/flow.yaml -t [target]
osmedeus scan -m /path/to/module.yaml -t [target] –params ‘port=9200’
osmedeus scan -m /path/to/module.yaml -t [target] -l /tmp/log.log
cat targets | osmedeus scan -f sample
Practical Scan Usage:
osmedeus scan -T list_of_targets.txt -W custom_workspaces
osmedeus scan -t target.com -w workspace_name –debug
osmedeus scan -f general -t www.sample.com
osmedeus scan -f gdirb -T list_of_target.txt
osmedeus scan -m ~/.osmedeus/core/workflow/test/dirbscan.yaml -t list_of_urls.txt
osmedeus scan –wfFolder ~/custom-workflow/ -f your-custom-workflow -t list_of_urls.txt
Provider Usage:
osmedeus provider build
osmedeus provider build –token xxx –rebuild –ic
osmedeus provider create –name ‘sample’
osmedeus provider health –debug
Cloud Usage:
osmedeus cloud -f [flowName] -t [target]
osmedeus cloud -m [modulePath] -t [target]
osmedeus cloud -c 10 -f [flowName] -T [targetsFile]
osmedeus cloud –token xxx -G -c 10 -f [flowName] -T [targetsFile]
osmedeus cloud –chunk -c 10 -f [flowName] -t [targetsFile]
Utilities Usage:
osmedeus health
osmedeus version –json
osmedeus utils tmux ls
osmedeus utils tmux logs -A -l 10
osmedeus utils ps
osmedeus utils ps –proc ‘jaeles’
osmedeus utils cron –cmd ‘osmdeus scan -t example.com’ –sch 60
osmedeus utils cron –for –cmd ‘osmedeus scan -t example.com’
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Osmedeus : A Workflow Engine For Offensive Security
Osmedeus is a Workflow Engine for Offensive Security. You need some essential tools like curl, wget, git, zip and login as root to start.