submitted by /u/pythonpsycho1337 (https://www.reddit.com/user/pythonpsycho1337)
[link] (https://tpetersonkth.github.io/2022/04/16/OSWE-Review.html) [comments] (https://www.reddit.com/r/Pentesting/comments/u4sp0i/oswe_review_2022/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://tpetersonkth.github.io/2022/04/16/OSWE-Review.html) [comments] (https://www.reddit.com/r/Pentesting/comments/u4sp0i/oswe_review_2022/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
overview for pythonpsycho1337
The u/pythonpsycho1337 community on Reddit. Reddit gives you the best of the internet in one place.
hacking: security in practice
What’s the difference between an analytics company and a advertising company?
submitted by /u/OptimalBeans
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What’s the difference between an analytics company and a advertising company?
submitted by /u/OptimalBeans
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What’s the difference between an analytics company and a...
Posted in r/hacking by u/OptimalBeans • 1 point and 0 comments
hacking: security in practice
Is a reflected xss attack a real vulnerability?
I'm novice to web security and trying to figure out some things. I stumbled upon xss vulnerabilities and checked the reflected xss. This made me wonder if this is a real threat for a site, as I haven't found any way to efficiently exploit it.
submitted by /u/Tonyb0y
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is a reflected xss attack a real vulnerability?
I'm novice to web security and trying to figure out some things. I stumbled upon xss vulnerabilities and checked the reflected xss. This made me wonder if this is a real threat for a site, as I haven't found any way to efficiently exploit it.
submitted by /u/Tonyb0y
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is a reflected xss attack a real vulnerability?
I'm novice to web security and trying to figure out some things. I stumbled upon xss vulnerabilities and checked the reflected xss. This made me...
hacking: security in practice
Friend claims his iphone was controlled by someone
A friend of mine called me (from a different phone than his own) claiming he just had witnessed his iphone doing crazy things on its own. It was apparently opening apps and trying to login to stuff and all kinds of weird stuff. He told me that he could only watch it happen and couldn’t even power off the phone. Apparently he he saw a mouse cursor navigating the home screen too.
Is this even possible?
submitted by /u/RealOldGamer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Friend claims his iphone was controlled by someone
A friend of mine called me (from a different phone than his own) claiming he just had witnessed his iphone doing crazy things on its own. It was apparently opening apps and trying to login to stuff and all kinds of weird stuff. He told me that he could only watch it happen and couldn’t even power off the phone. Apparently he he saw a mouse cursor navigating the home screen too.
Is this even possible?
submitted by /u/RealOldGamer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Friend claims his iphone was controlled by someone
A friend of mine called me (from a different phone than his own) claiming he just had witnessed his iphone doing crazy things on its own. It was...
hacking: security in practice
This is a long shot...
I'm desperate to recover this old YouTube video and willing to put up a reward. It's been deleted and shouldn't really have been posted anywhere else, possibly Facebook. Just delete this post if I broke the rules or anything sorry.
submitted by /u/Far-Mouse9084
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
This is a long shot...
I'm desperate to recover this old YouTube video and willing to put up a reward. It's been deleted and shouldn't really have been posted anywhere else, possibly Facebook. Just delete this post if I broke the rules or anything sorry.
submitted by /u/Far-Mouse9084
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
This is a long shot...
I'm desperate to recover this old YouTube video and willing to put up a reward. It's been deleted and shouldn't really have been posted anywhere...
hacking: security in practice
Is it possible to find a site that changed its URL if you know the old one?
I don't know if this is the right place to ask this but I'm curious if it's possible to find a site that had a previous URL but they changed it or is that not possible? Assuming you know nothing else but the old URL.
submitted by /u/genisisk
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to find a site that changed its URL if you know the old one?
I don't know if this is the right place to ask this but I'm curious if it's possible to find a site that had a previous URL but they changed it or is that not possible? Assuming you know nothing else but the old URL.
submitted by /u/genisisk
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to find a site that changed its URL if you know the...
I don't know if this is the right place to ask this but I'm curious if it's possible to find a site that had a previous URL but they changed it or...
How we spoofed ENS domains
TL;DR: We found a flaw that allowed us to spoof Ethereum domain names and received a $15k bounty.Continue reading on Medium »
Read more...
TL;DR: We found a flaw that allowed us to spoof Ethereum domain names and received a $15k bounty.Continue reading on Medium »
Read more...
Port scanning and service discovery in 2022 — we have failed as a humanity
There have been a lot of popular port scanning projects lately. In particular, these are projects that seek to combine fast port discovery…Continue reading on Medium »
Read more...
There have been a lot of popular port scanning projects lately. In particular, these are projects that seek to combine fast port discovery…Continue reading on Medium »
Read more...
How we spoofed ENS domains
https://medium.com/@hacxyk/how-we-spoofed-ens-domains-52acea2079f6?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@hacxyk/how-we-spoofed-ens-domains-52acea2079f6?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How we spoofed ENS domains for $15k
TL;DR: We found a flaw that allowed us to spoof Ethereum domain names and received a $15k bounty.
TL;DR: We found a flaw that allowed us to spoof Ethereum domain names and received a $15k bounty.Continue reading on Medium » (https://medium.com/@hacxyk/how-we-spoofed-ens-domains-52acea2079f6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How we spoofed ENS domains for $15k
TL;DR: We found a flaw that allowed us to spoof Ethereum domain names and received a $15k bounty.
Port scanning and service discovery in 2022 — we have failed as a humanity
https://medium.com/@nullt3r/port-scanning-and-service-discovery-in-2022-we-have-failed-as-a-humanity-9d0fe4503c18?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@nullt3r/port-scanning-and-service-discovery-in-2022-we-have-failed-as-a-humanity-9d0fe4503c18?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Port scanning and service discovery in 2022 — we have failed as a humanity
There have been a lot of popular port scanning projects lately. In particular, these are projects that seek to combine fast port discovery…
There have been a lot of popular port scanning projects lately. In particular, these are projects that seek to combine fast port discovery…Continue reading on Medium » (https://medium.com/@nullt3r/port-scanning-and-service-discovery-in-2022-we-have-failed-as-a-humanity-9d0fe4503c18?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Port scanning and service discovery in 2022 — we have failed as a humanity
There have been a lot of popular port scanning projects lately. In particular, these are projects that seek to combine fast port discovery…
Hacking on Medium
Linux User Controls
https://cdn-images-1.medium.com/max/1344/0*pHN3DHTkD58ADCXf.jpg
What is Linux
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Linux User Controls
https://cdn-images-1.medium.com/max/1344/0*pHN3DHTkD58ADCXf.jpg
What is Linux
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Linux User Controls
What is Linux
Hacking on Medium
Blog(MEDIUM)-THM
https://cdn-images-1.medium.com/max/1280/1*Ow9T3grRtiWSwv26KEyyiA.png
It is instructed to make an entry in the etc/hosts file so let's make it
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Blog(MEDIUM)-THM
https://cdn-images-1.medium.com/max/1280/1*Ow9T3grRtiWSwv26KEyyiA.png
It is instructed to make an entry in the etc/hosts file so let's make it
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blog(MEDIUM)-THM
It is instructed to make an entry in the etc/hosts file so let's make it
HOW RECON HELPED ME TO GET A STORED XSS!
RECONNAISSANCE IS THE KEY IN BUG BOUNTIESContinue reading on Medium »
Read more...
RECONNAISSANCE IS THE KEY IN BUG BOUNTIESContinue reading on Medium »
Read more...
EDRSandblast - Tool That Weaponize A Vulnerable Signed Driver To Bypass EDR Detections And LSASS Protections
http://www.kitploit.com/2022/04/edrsandblast-tool-that-weaponize.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/04/edrsandblast-tool-that-weaponize.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
EDRSandblast - Tool That Weaponize A Vulnerable Signed Driver To Bypass EDR Detections And LSASS Protections
int 3 ; overwritten instructions
test byte_7FFE0308, 1 ; <-- execution resumes here after analysis
jnz short loc_7FFCB44AD1E5
syscall
retn
loc_7FFCB44AD1E5:
int 2Eh
retn
NtProtectVirtualMemory endp Hooks detection Userland hooks have the "weakness" to be located in userland memory, which means they are directly observable and modifiable by the process under scrutiny. To automatically detect hooks in the process address space, the main idea is to compare the differences between the original DLL on disk and the library residing in memory, that has been potentially altered by an EDR. To perform this comparison, the following steps are followed by EDRSandblast: The list of all loaded DLLs is enumerated thanks to the InLoadOrderModuleList located int the PEB (to avoid calling any API that could be monitored and suspicious) For each loaded DLL, its content on disk is read and its headers parsed. The corresponding library, residing in memory, is also parsed to identify sections, exports, etc. Relocations of the DLL are parsed and applied, by taking the base address of the corresponding loaded library into account. This allows the content of both the in-memory library and DLL originating from disk to have the exact same content (on sections where relocations are applied), and thus making the comparison reliable. Exported functions are enumerated and the first bytes of the "in-memory" and "on-disk" versions are compared. Any difference indicates an alteration that has been made after the DLL was loaded, and thus is very probably an EDR hook. Note: The process can be generalized to find differences anywhere in non-writable sections and not only at the start of exported functions, for example if EDR products start to apply hooks in the middle of function :) Thus not used by the tool, this has been implemented in findDiffsInNonWritableSections. In order to bypass the monitoring performed by these hooks, multiples techniques are possible, and each has benefits and drawbacks. Hook bypass using ... unhooking The most intuitive method to bypass the hook-based monitoring is to remove the hooks. Since the hooks are present in memory that is reachable by the process itself, to remove a hook, the process can simply: Change the permissions on the page where the hook is located (RX -> RWX or RW) Write the original bytes that are known thanks to the on-disk DLL content Change back the permissions to RX This approach is fairly simple, and can be used to remove every detected hook all at once. Performed by an offensive tool at its beginning, this allows the rest of the code to be completely unaware of the hooking mechnanism and perform normally without being monitored. However, it has two main drawbacks. The EDR is probably monitoring the use of NtProtectVirtualMemory, so using it to change the permissions of the page where the hooks have been installed is (at least conceptually) a bad idea. Also, if a thread is executed by the EDR and periodically check the integrity of the hooks, this could also trigger some detection. For implementation details, check the unhook() function's code path when unhook_method is UNHOOK_WITH_NTPROTECTVIRTUALMEMORY. Important note: for simplicity, this technique is implemented in EDRSandblast as the base technique used to showcase the other bypass techniques; each of them demonstrates how to obtain an unmonitored version of NtProtectVirtualMemory, but performs the same operation afterward (unhooking a specific hook). Hook bypass using a custom trampoline To bypass a specific hook, it is possible to simply "jump over" and execute the rest of the function as is. First, the original bytes of the monitored function, that have been overwritten by the EDR to install the hook, must be recovered from the DLL file. In our previous code example, this would be the bytes corresponding to the following instructions: mov r10, rcx
___________________________
@hacking_Attack
@Hacking_Video
test byte_7FFE0308, 1 ; <-- execution resumes here after analysis
jnz short loc_7FFCB44AD1E5
syscall
retn
loc_7FFCB44AD1E5:
int 2Eh
retn
NtProtectVirtualMemory endp Hooks detection Userland hooks have the "weakness" to be located in userland memory, which means they are directly observable and modifiable by the process under scrutiny. To automatically detect hooks in the process address space, the main idea is to compare the differences between the original DLL on disk and the library residing in memory, that has been potentially altered by an EDR. To perform this comparison, the following steps are followed by EDRSandblast: The list of all loaded DLLs is enumerated thanks to the InLoadOrderModuleList located int the PEB (to avoid calling any API that could be monitored and suspicious) For each loaded DLL, its content on disk is read and its headers parsed. The corresponding library, residing in memory, is also parsed to identify sections, exports, etc. Relocations of the DLL are parsed and applied, by taking the base address of the corresponding loaded library into account. This allows the content of both the in-memory library and DLL originating from disk to have the exact same content (on sections where relocations are applied), and thus making the comparison reliable. Exported functions are enumerated and the first bytes of the "in-memory" and "on-disk" versions are compared. Any difference indicates an alteration that has been made after the DLL was loaded, and thus is very probably an EDR hook. Note: The process can be generalized to find differences anywhere in non-writable sections and not only at the start of exported functions, for example if EDR products start to apply hooks in the middle of function :) Thus not used by the tool, this has been implemented in findDiffsInNonWritableSections. In order to bypass the monitoring performed by these hooks, multiples techniques are possible, and each has benefits and drawbacks. Hook bypass using ... unhooking The most intuitive method to bypass the hook-based monitoring is to remove the hooks. Since the hooks are present in memory that is reachable by the process itself, to remove a hook, the process can simply: Change the permissions on the page where the hook is located (RX -> RWX or RW) Write the original bytes that are known thanks to the on-disk DLL content Change back the permissions to RX This approach is fairly simple, and can be used to remove every detected hook all at once. Performed by an offensive tool at its beginning, this allows the rest of the code to be completely unaware of the hooking mechnanism and perform normally without being monitored. However, it has two main drawbacks. The EDR is probably monitoring the use of NtProtectVirtualMemory, so using it to change the permissions of the page where the hooks have been installed is (at least conceptually) a bad idea. Also, if a thread is executed by the EDR and periodically check the integrity of the hooks, this could also trigger some detection. For implementation details, check the unhook() function's code path when unhook_method is UNHOOK_WITH_NTPROTECTVIRTUALMEMORY. Important note: for simplicity, this technique is implemented in EDRSandblast as the base technique used to showcase the other bypass techniques; each of them demonstrates how to obtain an unmonitored version of NtProtectVirtualMemory, but performs the same operation afterward (unhooking a specific hook). Hook bypass using a custom trampoline To bypass a specific hook, it is possible to simply "jump over" and execute the rest of the function as is. First, the original bytes of the monitored function, that have been overwritten by the EDR to install the hook, must be recovered from the DLL file. In our previous code example, this would be the bytes corresponding to the following instructions: mov r10, rcx
___________________________
@hacking_Attack
@Hacking_Video