Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Melody Monitor the Internet's background noiseMelody is a transparent internet sensor built for threat intelligence (https://www.kitploit.com/search/label/Threat%20Intelligence) and supported by a detection rule framework which allows you to tag packets of interest for further analysis and threat monitoring.
Features Here are some key features of Melody : Transparent capture Write detection rules and tag specific packets to analyze them at scale Mock vulnerable (https://www.kitploit.com/search/label/Vulnerable) websites using the builtin HTTP/S server Supports the main internet protocols over IPv4 and IPv6 Handles log rotation for you : Melody is designed to run forever on the smallest VPS Minimal configuration required Standalone mode : configure Melody using only the CLI Easily scalable : Statically compiled binary Up-to-date Docker image Wishlist Since I have to focus on other projects right now, I can't put much time in Melody's development. There is a lot of rom for improvement though, so here are some features that I'd like to implement someday : Dedicated helper program to create, test and manage rules -> Check Meloctl in cmd/meloctl Centralized rules management Per port mock application Use cases Internet facing sensor Extract trends and patterns from Internet's noise Index malicious activity, exploitation (https://www.kitploit.com/search/label/Exploitation) attempts and targeted scanners Monitor emerging threats exploitation Keep an eye on specific threats Stream analysis Build a background noise profile to make targeted attacks stand out Replay captures to tag malicious packets in a suspicious stream Preview

___________________________
@hacking_Attack
@Hacking_Video
Quickstart Quickstart details. (https://bonjourmalware.github.io/melody/installation) TL;DR Release Get the latest release at https://github.com/bonjourmalware/melody/releases. make install # Set default outfacing interface
make cap # Set network capabilities to start Melody without elevated privileges
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
make service # Create a systemd service to restart the program automatically and launch it at startup

sudo systemctl stop melody # Stop the service while we're configuring it Update the filter.bpf file to filter out unwanted packets. sudo systemctl start melody # Start Melody
sudo systemctl status melody # Check that Melody is running The logs should start to pile up in /opt/melody/logs/melody.ndjson. tail -f /opt/melody/logs/melody.ndjson # | jq From source git clone https://github.com/bonjourmalware/melody /opt/melody
cd /opt/melody
make build Then continue with the steps from the release (https://github.com/bonjourmalware/melody#release) TL;DR. Docker make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
mkdir -p /opt/melody/logs
cd /opt/melody/

docker pull bonjourmalware/melody:latest

MELODY_CLI="" # Put your CLI options here. Example : export MELODY_CLI="-s -i 'lo' -F 'dst port 5555' -o 'server.http.port: 5555'"

docker run \
--net=host \
-e "MELODY_CLI=$MELODY_CLI" \
--mount type=bind,source="$(pwd)/filter.bpf",target=/app/filter.bpf,readonly \
--mount type=bind,source="$(pwd)/config.yml",target=/app/config.yml,readonly \
--mount type=bind,source="$(pwd)/var",target=/app/var,readonly \
--mount type=bind,source="$(pwd)/rules",target=/app/rules,readonly \
--mount type=bind,source="$(pwd)/logs",target=/app/logs/ \
bonjourmalware/melody The logs should start to pile up in /opt/melody/logs/melody.ndjson. Rules Rule syntax details. (https://bonjourmalware.github.io/melody/installation) Example CVE-2020-14882 Oracle Weblogic Server RCE:
layer: http
meta:
id: 3e1d86d8-fba6-4e15-8c74-941c3375fd3e
version: 1.0
author: BonjourMalware
status: stable
created: 2020/11/07
modified: 2020/20/07
description: "Checking or trying to exploit CVE-2020-14882"
references:
- "https://nvd.nist.gov/vuln/detail/CVE-2020-14882"
match:
http.uri:
startswith|any|nocase:
- "/console/css/"
- "/console/images"
contains|any|nocase:
- "console.portal"
- "consolejndi.portal?test_handle="
tags:
cve: "cve-2020-14882"
vendor: "oracle"
product: "weblogic"
impact: "rce" Logs Logs content details. (https://bonjourmalware.github.io/melody/layers) Example Netcat TCP packet over IPv4 : {
"tcp": {
"window": 512,
"seq": 1906765553,
"ack": 2514263732,
"data_offset": 8,
"flags": "PA",
"urgent": 0,
"payload": {
"content": "I made a discovery today. I found a computer.\n",
"base64": "SSBtYWRlIGEgZGlzY292ZXJ5IHRvZGF5LiAgSSBmb3VuZCBhIGNvbXB1dGVyLgo=",
"truncated": false
}
},
"ip": {
"version": 4,
"ihl": 5,
"tos": 0,
"length": 99,
"id": 39114,
"fragbits": "DF",
"frag_offset": 0,
"ttl": 64,
"protocol": 6
},
"timestamp": "2020-11-16T15:50:01.277828+01:00",
"session": "bup9368o4skolf20rt8g",
"type": "tcp",
"src_ip": "127.0.0.1",
"dst_port": 1234,
"matches": {},
"inline_matches": [],
"embedded": {}
}

Download Melody (https://github.com/bonjourmalware/melody)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Where to find "true/real" domains of hacking forums or anything else?

For example, I want to search a leaked database right now and looked up to forums containing leaks section. In this subreddit's wiki I found "leakforums" and on www this one seems like a popular one but how am I supposed to find the real "leakforums"? Is it .su, .co, .fr, .net (.com, .org forwards to .net) or anything else? Would appreciate the help. Thx.

submitted by /u/IHateFacelessPorn
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do i transfer a malicious file from my laptop to my vm

So I made a script that once deployed or downloaded it will immediately make random txt files in a very fast manner and spams it on the desktop and just overwhelms the pc. Now im just hella curious how i can transfer it from my desktop to my VM

submitted by /u/Barlie2
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Codecat v0.56 : An Open-Source Tool To Help You Find/Track User Input Sinks And Security Bugs

CodeCat is an open-source tool to help you find/track user input sinks and security bugs using static code analysis. These points follow regex rules. Current rules for C,C++,GO, Python, javascript, Swift, PHP, Ruby, ASP, Kotlin, Dart and Java.(you can create your rules).

How too install, step by step

Go to CodeCat directory, install backend and frontend libs:

$ apt install python3-venv python3-dev libffi-dev rustc libssl-dev
$ python3 -m venv .venv
$ . .venv/bin/activate
$ pip install wheel
$ pip install -r Frontend/requirements.txt
$ pip install -r Backend/requirements.txt

Run backend and frontend

$ cd Codecat
$ cd Frontend; python3 wsgi.py &
$ cd ..
$ cd Backend; python3 wsgi.py &

Next step you need save your user to login:

$ curl -i -X POST -H “Content-Type: application/json” -d ‘{“email”:”admin2@test.com”,”username”:”admin”,”password”:”rubrik123″}’ https://127.0.0.1:50001/api/users -k

These endpoint /API/users run only once in the first deployment. If you try to send a request again to insert a user, the endpoint return 404 is security to block resources of possible attacks.

Go to the following “https://127.0.0.1:50093/front/auth/”. Now you can enter this system-auth, use login “admin”, pass “rubrik123”.

Note About TLS: You can configure and load your TLS cert in “wsgi.py”.

Production

Suppose you need to run in production. So I recommend another way.

$ gunicorn -b 127.0.0.1:50001 wsgi:app

If you want, you can use TLS with CERT resources:

$ gunicorn –certfile=server.crt –keyfile=server.key -b 127.0.0.1:50001 wsgi:app

The same command to frontend, but you need to use port 50093.
Download

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Wifi password algorithm - PBKDF location

I'm writing a security analysis article and I'm trying to reproduce the results given here in https://www.usenix.org/system/files/conference/woot15/woot15-paper-lorente.pdf with candidate firmware https://www.mediafire.com/file/sda5rzxqmfs5gh9/upfr.zip/file . Till now, I'm unable to locate the PBKDF algorithm location in the firmware. Can anybody help me with this? Pm me for further information. The firmware is an outdated version and not in use now at all.

submitted by /u/ProcedureDelicious95
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video