hacking: security in practice
Inbuilt Wifi for Hacking
I am total beginner in computer world.. But, Ihave tried fern-cracker once. I bought a 722n V2 adapter for enabling me monitor mode. But, I recenly found out that my brothers laptop (Legion 5 5600h) has an intel built in wifi card which, as i checked, has support for monitor mode. Will it be as capable as 722n for hacking purpose? What are its limitations and what is it poor/ strong at in comparison to 722n?
Not of concern to question: I bought a L5p too.. It will arrive to me in 25 days or so. I dont know now, if it has intel or mediatek wifi.. I hope I get lucky with an intel card too.. Wish me Luck.
submitted by /u/glitchystar_717
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Inbuilt Wifi for Hacking
I am total beginner in computer world.. But, Ihave tried fern-cracker once. I bought a 722n V2 adapter for enabling me monitor mode. But, I recenly found out that my brothers laptop (Legion 5 5600h) has an intel built in wifi card which, as i checked, has support for monitor mode. Will it be as capable as 722n for hacking purpose? What are its limitations and what is it poor/ strong at in comparison to 722n?
Not of concern to question: I bought a L5p too.. It will arrive to me in 25 days or so. I dont know now, if it has intel or mediatek wifi.. I hope I get lucky with an intel card too.. Wish me Luck.
submitted by /u/glitchystar_717
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Inbuilt Wifi for Hacking
I am total beginner in computer world.. But, Ihave tried fern-cracker once. I bought a 722n V2 adapter for enabling me monitor mode. But, I...
hacking: security in practice
Looking for memory forensics tutorials.
I am looking learn how analyze malware that’s running in memory and was wondering if there are any recommendations for good tutorials before I just hit YouTube/google
submitted by /u/sgtwtf22
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Looking for memory forensics tutorials.
I am looking learn how analyze malware that’s running in memory and was wondering if there are any recommendations for good tutorials before I just hit YouTube/google
submitted by /u/sgtwtf22
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Looking for memory forensics tutorials.
I am looking learn how analyze malware that’s running in memory and was wondering if there are any recommendations for good tutorials before I...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Heyserial - Programmatically Create Hunting Rules For Deserialization Exploitation With Multiple Keywords, Gadget Chains, Object Types, Encodings, And Rule Types
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh96iyLi-WJuKHxzsUe2ew0LLbVkwXkKoWXWpcZ0mRX6YUdBo7uzVq0lxIihLA9awRncMpRG3Pz54Becx4VdqrQLs5gSE0N0eXTFeY3SvASRKmLUj29WSoNXUB9oiczpcdLkgyqQmTBmYpjyy432kXPM87zwjhA7s0hfpa0u5aqBPpNFNzCyggYVI4E/w640-h370/deserialization1.png Programmatically create hunting rules for deserialization exploitation with multiple
* keywords (e.g. cmd.exe)
* gadget chains (e.g. CommonsCollection)
* object types (e.g. ViewState, Java, Python Pickle, PHP)
* encodings (e.g. Base64, raw)
* rule types (e.g. Snort, Yara) DisclaimerRules generated by this tool are intended for hunting/research purposes and are not designed for high fidelity/blocking purposes.
Please test thoroughly before deploying to any production systems.
The Yara rules are primarily intended for scanning web server logs. Some of the "object prefixes" are only 2 bytes long, so they can make large scans a bit slow. (Translation: please don't drop them all into VT Retrohunt.) UsageHelp:
Usage:
* Source: https://github.com/pwntester/ysoserial.net
* License: ysoserial.net_LICENSE.txt utils/generate_payloads.shYSoSerial payload generation. Run on Linux from the ./utils directory.
* Source: https://github.com/frohoff/ysoserial
* License: ysoserial_LICENSE.txt utils/install_snort.shInstalling Snort on a Debian based system was a bit finnicky for me, so I wrote my install notes here.
Use at your own risk in a VM that you have snapshotted recently. utils/server.pySimple Python script that runs an HTTP server on 127.0.0.1:12345 and accepts POST requests.
Handy for generating test PCAPs. LicenseCopyright (C) 2021 Alyssa Rahman, Mandiant, Inc. All Rights Reserved. Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at: [package root]/LICENSE.txt Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. ContributingCheck out the Developers' guide (DEVELOPERS.md) for more details on extending HeySerial! Prior Work/Related ResourcesTools
* Deserialization-Cheat-Sheet – @GrrrDog
* Ysoserial - @frohoff
* MarshalSec - @frohoff
* Ysoserial (forked) - @wh1t3p1g
* Ysoserial.NET and v2 branch - @pwntester
* ViewGen – 0xacb
* Rogue-JNDI - @veracode-research
Vulnerabilities
* Log4J (CVE-2021-44228)
* Exchange (CVE-2021-42321)
* Zoho ManageEngine (CVE-2020-10189)
* Jira (CVE-2020-36239)
* Telerik (CVE-2019-18935)
* C1 CMS (CVE-2019-18211)
* Jenkins (CVE-2016-9299)
* What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnera[...]
___________________________
@hacking_Attack
@Hacking_Video
Heyserial - Programmatically Create Hunting Rules For Deserialization Exploitation With Multiple Keywords, Gadget Chains, Object Types, Encodings, And Rule Types
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh96iyLi-WJuKHxzsUe2ew0LLbVkwXkKoWXWpcZ0mRX6YUdBo7uzVq0lxIihLA9awRncMpRG3Pz54Becx4VdqrQLs5gSE0N0eXTFeY3SvASRKmLUj29WSoNXUB9oiczpcdLkgyqQmTBmYpjyy432kXPM87zwjhA7s0hfpa0u5aqBPpNFNzCyggYVI4E/w640-h370/deserialization1.png Programmatically create hunting rules for deserialization exploitation with multiple
* keywords (e.g. cmd.exe)
* gadget chains (e.g. CommonsCollection)
* object types (e.g. ViewState, Java, Python Pickle, PHP)
* encodings (e.g. Base64, raw)
* rule types (e.g. Snort, Yara) DisclaimerRules generated by this tool are intended for hunting/research purposes and are not designed for high fidelity/blocking purposes.
Please test thoroughly before deploying to any production systems.
The Yara rules are primarily intended for scanning web server logs. Some of the "object prefixes" are only 2 bytes long, so they can make large scans a bit slow. (Translation: please don't drop them all into VT Retrohunt.) UsageHelp:
python3 heyserial.py -hExamples: python3 heyserial.py -c 'ExampleChain::condition1+condition2' -t JavaObj python3 heyserial.py -k cmd.exe whoami 'This file cannot be run in DOS mode' python3 heyserial.py -k Process.Start -t NETViewState -e base64 "base64+utf16le" Utilsutils/checkyoself.pyThis is a tool to automate bulk testing of Snort and Yara rules on a variety of sample files.Usage:
python3 checkyoself.py [-y rules.yara] [-s rules.snort] [-o file_output_prefix] [--matches] [--misses] -d malware.exe malware.pcapExamples: python3 checkyoself.py -y rules/javaobj -s rules/javaobj -d payloads/javaobj pcaps --misses -o java_missesutils/generate_payloads.ps1YSoSerial.NET v1.34 payload generation. Run on Windows from the ./utils directory.* Source: https://github.com/pwntester/ysoserial.net
* License: ysoserial.net_LICENSE.txt utils/generate_payloads.shYSoSerial payload generation. Run on Linux from the ./utils directory.
* Source: https://github.com/frohoff/ysoserial
* License: ysoserial_LICENSE.txt utils/install_snort.shInstalling Snort on a Debian based system was a bit finnicky for me, so I wrote my install notes here.
Use at your own risk in a VM that you have snapshotted recently. utils/server.pySimple Python script that runs an HTTP server on 127.0.0.1:12345 and accepts POST requests.
Handy for generating test PCAPs. LicenseCopyright (C) 2021 Alyssa Rahman, Mandiant, Inc. All Rights Reserved. Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at: [package root]/LICENSE.txt Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. ContributingCheck out the Developers' guide (DEVELOPERS.md) for more details on extending HeySerial! Prior Work/Related ResourcesTools
* Deserialization-Cheat-Sheet – @GrrrDog
* Ysoserial - @frohoff
* MarshalSec - @frohoff
* Ysoserial (forked) - @wh1t3p1g
* Ysoserial.NET and v2 branch - @pwntester
* ViewGen – 0xacb
* Rogue-JNDI - @veracode-research
Vulnerabilities
* Log4J (CVE-2021-44228)
* Exchange (CVE-2021-42321)
* Zoho ManageEngine (CVE-2020-10189)
* Jira (CVE-2020-36239)
* Telerik (CVE-2019-18935)
* C1 CMS (CVE-2019-18211)
* Jenkins (CVE-2016-9299)
* What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnera[...]
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Heyserial - Programmatically Create Hunting Rules For Deserialization Exploitation With Multiple Keywords, Gadget Chains, Object…
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Heyserial - Programmatically Create Hunting Rules For Deserialization Exploitation With Multiple Keywords, Gadget Chains, Object Types, Encodings, And Rule Types https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh96iyLi…
bility. – @breenmachine, FoxGloveSecurity (2015)
Talks and Write-Ups
* PSA: Log4Shell and the current state of JNDI injection - Moritz Bechler (2021)
* This is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits – Chris Glyer, Dan Perez, Sarah Jones, Steve Miller (2020)
* Deep Dive into .NET ViewState deserialization and its exploitation – Swapneil Dash (2019)
* Exploiting Deserialization in ASP.NET via ViewState – Soroush Dalili (2019)
* Use of Deserialization in .NET Framework Methods and Classes – Soroush Dalili(2018)
* Friday the 13th, JSON Attacks – Alvaro Muños and Oleksandr Mirosh (2017)
* Exploiting .NET Managed DCOM – James Forshaw, Project Zero (2017)
* Java Unmarshaller Security – Moritz Bechler (2017)
* Deserialize My Shorts – Chris Frohoff (2016)
* Pwning Your Java Messaging with Deserialization Vulnerabilities – Matthias Kaiser (2016)
* Journey from JNDI/LDAP Manipulation to Remote Code Execution Dream Land – Alvaro Muños and Oleksandr Mirosh (2016)
* Marshalling Pickles – Chris Frohoff and Gabriel Lawrence (2015)
* Are you my Type? Breaking .NET Through Serialization – James Forshaw (2012)
* A Spirited Peek into ViewState – Mike Shema (2011)
Author: Alyssa Rahman @ramen0x3f
Created: 2021-10-27
Last Updated: 2021-12-02
Blog: https://www.mandiant.com/resources/hunting-deserialization-exploits
For more details on this tool and the research process behind it, check out our blog! Download Heyserial
___________________________
@hacking_Attack
@Hacking_Video
Talks and Write-Ups
* PSA: Log4Shell and the current state of JNDI injection - Moritz Bechler (2021)
* This is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits – Chris Glyer, Dan Perez, Sarah Jones, Steve Miller (2020)
* Deep Dive into .NET ViewState deserialization and its exploitation – Swapneil Dash (2019)
* Exploiting Deserialization in ASP.NET via ViewState – Soroush Dalili (2019)
* Use of Deserialization in .NET Framework Methods and Classes – Soroush Dalili(2018)
* Friday the 13th, JSON Attacks – Alvaro Muños and Oleksandr Mirosh (2017)
* Exploiting .NET Managed DCOM – James Forshaw, Project Zero (2017)
* Java Unmarshaller Security – Moritz Bechler (2017)
* Deserialize My Shorts – Chris Frohoff (2016)
* Pwning Your Java Messaging with Deserialization Vulnerabilities – Matthias Kaiser (2016)
* Journey from JNDI/LDAP Manipulation to Remote Code Execution Dream Land – Alvaro Muños and Oleksandr Mirosh (2016)
* Marshalling Pickles – Chris Frohoff and Gabriel Lawrence (2015)
* Are you my Type? Breaking .NET Through Serialization – James Forshaw (2012)
* A Spirited Peek into ViewState – Mike Shema (2011)
Author: Alyssa Rahman @ramen0x3f
Created: 2021-10-27
Last Updated: 2021-12-02
Blog: https://www.mandiant.com/resources/hunting-deserialization-exploits
For more details on this tool and the research process behind it, check out our blog! Download Heyserial
___________________________
@hacking_Attack
@Hacking_Video
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Proving Grounds — DC-1
https://cdn-images-1.medium.com/max/600/1*MbbAxfr88Xl0gsBizvePdg.png
DC-1 (VulnHub: https://www.vulnhub.com/entry/dc-1,292/) is an easy box in Proving Grounds: Play. Bottom line up front — this box should be…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Proving Grounds — DC-1
https://cdn-images-1.medium.com/max/600/1*MbbAxfr88Xl0gsBizvePdg.png
DC-1 (VulnHub: https://www.vulnhub.com/entry/dc-1,292/) is an easy box in Proving Grounds: Play. Bottom line up front — this box should be…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Proving Grounds — DC-1
DC-1 (VulnHub: https://www.vulnhub.com/entry/dc-1,292/) is an easy box in Proving Grounds: Play. Bottom line up front — this box should be…
hacking: security in practice
How to set ip address to a specific location in my own city?
I want to set my device's ip address location to a specific neighborhood. So whenever I log in on social media it shows activity being done from that location. I have the GPS location for the area I want to show my IP address of if that helps.
anyone get any idea how to do it?
submitted by /u/Physical-Mushroom-76
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to set ip address to a specific location in my own city?
I want to set my device's ip address location to a specific neighborhood. So whenever I log in on social media it shows activity being done from that location. I have the GPS location for the area I want to show my IP address of if that helps.
anyone get any idea how to do it?
submitted by /u/Physical-Mushroom-76
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to set ip address to a specific location in my own city?
I want to set my device's ip address location to a specific neighborhood. So whenever I log in on social media it shows activity being done from...
[Bug Bounty] Sql Injection and Bypass Sql Login
https://medium.com/@ryuukhagetsu/bug-bounty-sql-injection-and-bypass-sql-login-8759b222e70c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ryuukhagetsu/bug-bounty-sql-injection-and-bypass-sql-login-8759b222e70c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
[Bug Bounty] Sql Injection and Bypass Sql Login
Hi Semuanya bagaimana kabarnya ?, semoga dalam keadaan baik baik saja. Kali ini saya ingin membagikan tulisan saya mengenai bug bounty dan…
Hi Semuanya bagaimana kabarnya ?, semoga dalam keadaan baik baik saja. Kali ini saya ingin membagikan tulisan saya mengenai bug bounty dan…Continue reading on Medium » (https://medium.com/@ryuukhagetsu/bug-bounty-sql-injection-and-bypass-sql-login-8759b222e70c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
[Bug Bounty] Sql Injection and Bypass Sql Login
Hi Semuanya bagaimana kabarnya ?, semoga dalam keadaan baik baik saja. Kali ini saya ingin membagikan tulisan saya mengenai bug bounty dan…
[Bug Bounty] Sql Injection and Bypass Sql Login
Hi Semuanya bagaimana kabarnya ?, semoga dalam keadaan baik baik saja. Kali ini saya ingin membagikan tulisan saya mengenai bug bounty dan…Continue reading on Medium »
Read more...
Hi Semuanya bagaimana kabarnya ?, semoga dalam keadaan baik baik saja. Kali ini saya ingin membagikan tulisan saya mengenai bug bounty dan…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best Hackers Online — Hire a Crypto Hacker
https://cdn-images-1.medium.com/max/880/1*RbEJcLgHib3G-fVMSHegGw.jpeg
Best Hackers Online — Hire A Crypto Hacker To Recover Stolen Funds
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Best Hackers Online — Hire a Crypto Hacker
https://cdn-images-1.medium.com/max/880/1*RbEJcLgHib3G-fVMSHegGw.jpeg
Best Hackers Online — Hire A Crypto Hacker To Recover Stolen Funds
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Best Hackers Online — Hire a Crypto Hacker
Best Hackers Online — Hire A Crypto Hacker To Recover Stolen Funds
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
CVE-2022-30525, Zyxel critical RCE vulnerability : Zyxel fixed Firewall Unauthenticated Remote Command Injection.
https://external-preview.redd.it/08j3lnTCIqlRcyrKj_HOp6N-XegG1xIuurXwNaF7v7U.jpg?width=640&crop=smart&auto=webp&s=a93b8a0dae40ce2c8b7fefeda7584ed149da1865 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
CVE-2022-30525, Zyxel critical RCE vulnerability : Zyxel fixed Firewall Unauthenticated Remote Command Injection.
https://external-preview.redd.it/08j3lnTCIqlRcyrKj_HOp6N-XegG1xIuurXwNaF7v7U.jpg?width=640&crop=smart&auto=webp&s=a93b8a0dae40ce2c8b7fefeda7584ed149da1865 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
CVE-2022-30525, Zyxel critical RCE vulnerability : Zyxel fixed...
Posted in r/hacking by u/Late_Ice_9288 • 84 points and 4 comments
hacking: security in practice
Getting started
What’s a good way to get into hacking? Just curious
submitted by /u/Minimum-Sir-2747
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Getting started
What’s a good way to get into hacking? Just curious
submitted by /u/Minimum-Sir-2747
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Getting started
What’s a good way to get into hacking? Just curious