Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
In memory (via Process Hacker):
Clone: Use recursive clone to get the repo together with all the submodules: git clone --recursive https://github.com/hasherezade/process_overwriting.git

Download Process_Overwriting (https://github.com/hasherezade/process_overwriting)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is the definition of a social engineering attack?

https://cdn-images-1.medium.com/max/1280/1*RUfzVFArmqIXZG84rW1DcA.jpeg
Have you seen some alarming stories about a new “social engineering attack” going around but aren’t sure what it means? Then you’re in the…

Continue reading on Medium »
From android app to access admin dashboard
https://medium.com/@odayalhalbe1/from-android-app-to-access-admin-dashboard-a8f825e8e806?source=rss------bug_bounty-5

One of easy and interesting vulnerability that I found and lead to access admin dashboard for company (internal system) :Continue reading on Medium » (https://medium.com/@odayalhalbe1/from-android-app-to-access-admin-dashboard-a8f825e8e806?source=rss------bug_bounty-5)
hacking: security in practice
Noob-Friendly CTF Team / Educational Opportunity

Good afternoon, r/hacking. I am looking to create a small group (roughly 8 more people) of hacking enthusiasts who are looking to get into the CTF space and are, in general, looking to learn more about Cybersecurity. This would basically be a CTF team, but also a group which could help those involved cultivate their skills, doing things like HTB, TryHackMe, etc. The group will, as of right now, be largely consolidated on Discord. The first target on my list is the upcoming HacktheBox Cyber Apocalypse CTF. Beyond that, I'll be keeping an eye out for other upcoming CTFs to get involved with.

I want to keep the group pretty relaxed, I know life happens, time zones are different, you have work/school/kids. For example, the HTB CTF runs from Tomorrow to this coming Thursday, but there is no need for every person to be active every single day at the same time. In my case, I sit for the Security+ next week so I won't be active on that day. If I find a CTF and send it in the Discord and a member decides to sit it out, then that's completely fine.

This group is N00b friendly, of course, but you l33t bois are more than welcome, too. All I ask is that you bring a desire to learn and have a good time in the process. I'll have to keep this limited to the first 8 people as of now, but plan to invite more people in the future (when I hopefully have this figured out.)

PM me if interested, I'll get that Discord up and running at some point today and send you a HTB Team Link, Discord Link, and my personal TryHackMe profile.

Take care.

TLDR: I'm starting a noob-friendly CTF team with a Discord chat, want to aim for 1 CTF per month. Opportunity for fun and educational experience, no stress. 8 people will be accepted, more to come in the future. PM if interested.

submitted by /u/SumComputerGuy
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Process_Overwriting - Yet Another Variant Of Process Hollowing

https://blogger.googleusercontent.com/img/a/AVvXsEiL9t_UvFtJsraz-herQjgyfT2zlF5eeegekrccL_ygK0JQ7qzqo6kieLn9CNbuVB2a8m17slx0ZYjam7VPYd1NeJr-B8VYpUURZeK0AScAzbR3ujfHdbvgHu3LK5PnvXNnW2UFS1_eJSRbUxUE3Ivr5qKtSryRRTjpmu2dpJqcuQT0pqTeDR9hPIwl=w640-h320 Process Overwriting is a PE injection technique, closely related to Process Hollowing and Module Overloading

Process Hollowing (aka RunPE) is an old and popular PE injection technique. It comes in has variety of flavors, but there are some steps in common:

1. Start by creating a process in a suspended state
2. Write our own PE module in its memory
3. Redirect to the new module
4. Resume the thread
Process Hollowing does not require manual loading of payload's imports. Thanks to the step 3 Windows loader treat our PE implant as the main module of the process, and will load imports automatically when its execution resumes.

To make our implant recognized by Windows loader, its Module Base must be set in the PEB. It is usually done by one of the two ways:

* in the most classic variant, the original PE is unmapped from memory, and the new PE is mapped on its place, at the same address.
* in another, yet common variant, the old module is left as is, and another PE is mapped in a new memory region. Then the new module's base address is manually written into the PEB (this variant was demonstrated here)

As a result of those classic implementations we get a payload running as main module, yet it is mapped as MEM_PRIVATE(not as MEM_IMAGElike typically loaded PEs). To obtain payload mapped as MEM_IMAGEwe can use some closely related techniques, such as Transacted Hollowing or its variant "Ghostly Hollowing".

Process Overwriting is yet another take on solving this problem.

In contrast to the classic Process Hollowing, we are not unmapping the original PE, but writing over it. No new memory is allocated: we are using the memory that was originally allocated for the main module of the process.

Pros:

* the implanted PE looks like if it was loaded by Windows loader:
* mapped as MEM_IMAGE* divided into sections with specific access rights
* the image is named

* convenience of loading:
* no need to manually relocate the implant prior to injection: Windows loader will take care of this (in classic Process Hollowing we have to relocate the module)
* no need to fill imports (like in every variant of Process Hollowing)
* no need to allocate new memory in the process
Cons:

* It doesn't work if the target has GFG (Control Flow Guard) enabled (yet it is possible to disable it on process creation)
* The target's ImageSize must not be smaller than payload's ImageSize (remember we are using only the memory that was already allocated!) - this limitation does not occur in other flavors of Process Hollowing
* Can be detected by comparing of the module in memory with corresponding file (PE-sieve detects it) - just like every variant of Process Hollowing Demo:The demo payload (demo.bin) injected into Windows Calc (default target): https://blogger.googleusercontent.com/img/a/AVvXsEiL9t_UvFtJsraz-herQjgyfT2zlF5eeegekrccL_ygK0JQ7qzqo6kieLn9CNbuVB2a8m17slx0ZYjam7VPYd1NeJr-B8VYpUURZeK0AScAzbR3ujfHdbvgHu3LK5PnvXNnW2UFS1_eJSRbUxUE3Ivr5qKtSryRRTjpmu2dpJqcuQT0pqTeDR9hPIwl=w640-h320 In memory (via Process Hacker): https://blogger.googleusercontent.com/img/a/AVvXsEgpqZk-xeCouXqFchrvO9Fu8XJ7swWKoi_4UxZS1oY6G_PhHP8jaOyCqhTCtThRDtYhfw18hCxUfCzgqlk6lwsrtDwt-XX8zhct2OLlSXYCyOVaL_csUgqiHvdMgNnlqZ5ieTHyRfcygikZHiAp2VzriHJ4fgfwndPg0WtzzcclrhnxCpCmSOga3okJ=w640-h400 Clone:Use recursive clone to get the repo together with all the submodules: git clone --recursive https://github.com/hasherezade/process_overwriting.gitDownload Process_Overwriting
From android app to access admin dashboard

One of easy and interesting vulnerability that I found and lead to access admin dashboard for company (internal system) :Continue reading on Medium »
Read more...
Announcing Pay At Triage for Bug Bounty
https://medium.com/uber-security-privacy/announcing-pay-at-triage-for-bug-bounty-6960ad14a7d9?source=rss------bug_bounty-5

By John Turner, Staff Security Technologist & Vinay Venkateswara Rao, Senior Security TechnologistContinue reading on Uber Privacy & Security » (https://medium.com/uber-security-privacy/announcing-pay-at-triage-for-bug-bounty-6960ad14a7d9?source=rss------bug_bounty-5)
Announcing Pay At Triage for Bug Bounty

By John Turner, Staff Security Technologist & Vinay Venkateswara Rao, Senior Security TechnologistContinue reading on Uber Privacy & Security »
Read more...