This blog is only for informational purpose only so that emerging bug hunters could follow similar methodology and responsibly disclose…Continue reading on Medium » (https://medium.com/@the_harvester/how-i-exploited-4-vulnerabilities-in-a-website-3be6b28259cc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Exploited 4 Vulnerabilities In A Website
This blog is only for informational purpose only so that emerging bug hunters could follow similar methodology and responsibly disclose…
How I Exploited 4 Vulnerabilities In A Website
This blog is only for informational purpose only so that emerging bug hunters could follow similar methodology and responsibly disclose…Continue reading on Medium »
Read more...
This blog is only for informational purpose only so that emerging bug hunters could follow similar methodology and responsibly disclose…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4ShellPost Views: 11
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Recently reported VMware bugs are being used by hackers who are focused on using them to deliver Mirai denial-of-service malware and exploit the Log4Shell vulnerability. Security researchers at Barracuda discovered that attempts were made to exploit the recent vulnerabilities CVE-2022-22954 and CVE-2022-22960, both reported last month.
“Barracuda researchers analyzed the attacks and payloads detected by Barracuda systems between April to May and found a steady stream of attempts to exploit two recently uncovered VMware vulnerabilities: CVE-2022-22954 and CVE-2022-22960” reported by Barracuda.
VMware published an advisory on April 6, 2022, which detailed multiple security vulnerabilities. The most severe of these is CVE-2022-22954 with a CVSS score of 9.8, the bug allows an attacker with network access to perform remote code execution via server-side template injection on VMware Workspace ONE Access and Identity Manager Solutions.
The other bug involved CVE-2022-22960 (CVSS score 7.8), is a local privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation. According to the advisory by VMware, the bug arises due to improper permission in support scripts allowing an attacker with local access to gain root privileges.
The VMware Workspace One is an intelligent-drive workspace platform that helps to manage any app on any device in a secure and simpler manner. The Identity manager handles the authentication to the platform and vRealize Automation is a DevOps-based infrastructure management platform for config of IT resources and automating the delivery of container-based applications.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Exploitation Occurred After PoC ReleaseThe Barracuda researchers noted that the previous flaws are chained together for a potential full exploitation vector.
After the bug was disclosed by VMware in April, a proof-of-concept (PoC) was released on Github and shared via Twitter.
“Barracuda researchers started seeing probes and exploit attempts for this vulnerability soon after the release of the advisory and the initial release of the proof of concept on GitHub,” reported Barracuda.
After the release of PoC, the spike in attempts is noticed by the researcher, they classified it as a probe rather than actual attempts to exploit.
“The attacks have been consistent over time, barring a few spikes, and the vast majority of them are what would be classified as probes rather than actual exploit attempts,” they added.
See Also: Attackers Use Event Logs to Hide Fileless Malware The researchers at Barracuda also revealed that most of the exploit attempts are primarily from botnet operators, the IPs discovered still seem to host variants of the Mirai distributed-denial-of-service (DDoS) botnet malware, along with some Log4Shell exploits and low levels of EnemyBot (a type of DDoS botnet) attempts.
The majority of the attacks (76 percent) originated from the U.S. geographically, with most of them coming from data centers and cloud providers. The researcher added that there is a spike in IP addresses from the UK and Russia and about (6 percent) of the attacks emanate from these locations.
The researchers noted, “there are also consistent background attempts from known bad IPs in Russia.”
[...]
___________________________
@hacking_Attack
@Hacking_Video
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4ShellPost Views: 11
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Recently reported VMware bugs are being used by hackers who are focused on using them to deliver Mirai denial-of-service malware and exploit the Log4Shell vulnerability. Security researchers at Barracuda discovered that attempts were made to exploit the recent vulnerabilities CVE-2022-22954 and CVE-2022-22960, both reported last month.
“Barracuda researchers analyzed the attacks and payloads detected by Barracuda systems between April to May and found a steady stream of attempts to exploit two recently uncovered VMware vulnerabilities: CVE-2022-22954 and CVE-2022-22960” reported by Barracuda.
VMware published an advisory on April 6, 2022, which detailed multiple security vulnerabilities. The most severe of these is CVE-2022-22954 with a CVSS score of 9.8, the bug allows an attacker with network access to perform remote code execution via server-side template injection on VMware Workspace ONE Access and Identity Manager Solutions.
The other bug involved CVE-2022-22960 (CVSS score 7.8), is a local privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation. According to the advisory by VMware, the bug arises due to improper permission in support scripts allowing an attacker with local access to gain root privileges.
The VMware Workspace One is an intelligent-drive workspace platform that helps to manage any app on any device in a secure and simpler manner. The Identity manager handles the authentication to the platform and vRealize Automation is a DevOps-based infrastructure management platform for config of IT resources and automating the delivery of container-based applications.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Exploitation Occurred After PoC ReleaseThe Barracuda researchers noted that the previous flaws are chained together for a potential full exploitation vector.
After the bug was disclosed by VMware in April, a proof-of-concept (PoC) was released on Github and shared via Twitter.
“Barracuda researchers started seeing probes and exploit attempts for this vulnerability soon after the release of the advisory and the initial release of the proof of concept on GitHub,” reported Barracuda.
After the release of PoC, the spike in attempts is noticed by the researcher, they classified it as a probe rather than actual attempts to exploit.
“The attacks have been consistent over time, barring a few spikes, and the vast majority of them are what would be classified as probes rather than actual exploit attempts,” they added.
See Also: Attackers Use Event Logs to Hide Fileless Malware The researchers at Barracuda also revealed that most of the exploit attempts are primarily from botnet operators, the IPs discovered still seem to host variants of the Mirai distributed-denial-of-service (DDoS) botnet malware, along with some Log4Shell exploits and low levels of EnemyBot (a type of DDoS botnet) attempts.
The majority of the attacks (76 percent) originated from the U.S. geographically, with most of them coming from data centers and cloud providers. The researcher added that there is a spike in IP addresses from the UK and Russia and about (6 percent) of the attacks emanate from these locations.
The researchers noted, “there are also consistent background attempts from known bad IPs in Russia.”
[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell | Black Hat Ethical Hacking
Recently reported VMware bugs are being used by hackers who are focused on using them to deliver Mirai denial-of-service malware and exploit the Log4Shell vulnerability.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4ShellPost Views: 11 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
“Some of these IPs perform scans for specific vulnerabilities at regular intervals, and it looks like the VMware vulnerabilities have been added to their usual rotating list of Laravel/Drupal/PHP probes,” researchers explained See Also: Offensive Security Tool: malicious-pdf Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
According to Barracuda “the interest levels on these vulnerabilities have stabilized” after the initial spike in April, the researcher expected to analyze low-level scanning and attempts for some time.
The best way to protect the systems is to apply the patches immediately, especially if the system is internet-facing, and to place a Web application firewall (WAF) in front of such systems “will add to defense in depth against zero-day attacks and other vulnerabilities, including Log4Shell,” advised by Barracuda.
See Also: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20211 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-azure-cloud-90x90.jpg Microsoft releases fixes for Azure flaw allowing RCE attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/f5-big-ip-hacking-90x90.jpg Exploits created for critical F5 BIG-IP flaw, install patch immediately1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Fileless-Malware-660x400-1-90x90.jpg Attackers Use Event Logs to Hide Fileless Malware2 weeks ago
The post April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
According to Barracuda “the interest levels on these vulnerabilities have stabilized” after the initial spike in April, the researcher expected to analyze low-level scanning and attempts for some time.
The best way to protect the systems is to apply the patches immediately, especially if the system is internet-facing, and to place a Web application firewall (WAF) in front of such systems “will add to defense in depth against zero-day attacks and other vulnerabilities, including Log4Shell,” advised by Barracuda.
See Also: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20211 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-azure-cloud-90x90.jpg Microsoft releases fixes for Azure flaw allowing RCE attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/f5-big-ip-hacking-90x90.jpg Exploits created for critical F5 BIG-IP flaw, install patch immediately1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Fileless-Malware-660x400-1-90x90.jpg Attackers Use Event Logs to Hide Fileless Malware2 weeks ago
The post April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
How I Got $1083 worth of book bundle for just $1 — #Bugbounty
Price manipulation at checkout:Continue reading on Medium »
Read more...
Price manipulation at checkout:Continue reading on Medium »
Read more...
How I Got $1083 worth of book bundle for just $1 — #Bugbounty
https://medium.com/@prasanth.bodepu/how-i-got-1083-worth-of-book-bundle-for-just-1-bugbounty-b94b6ed47730?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@prasanth.bodepu/how-i-got-1083-worth-of-book-bundle-for-just-1-bugbounty-b94b6ed47730?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Got $1083 worth of book bundle for just $1 — #Bugbounty
Price manipulation at checkout:
Price manipulation at checkout:Continue reading on Medium » (https://medium.com/@prasanth.bodepu/how-i-got-1083-worth-of-book-bundle-for-just-1-bugbounty-b94b6ed47730?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Got $1083 worth of book bundle for just $1 — #Bugbounty
Price manipulation at checkout:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe : Ignite write-up
https://cdn-images-1.medium.com/max/2600/1*nB3Y_iqhGVA_nnxayHzHLQ.png
I start usually by updating the hosts file on my computer, in order to make accessing the machine easier without the need of typing the IP…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe : Ignite write-up
https://cdn-images-1.medium.com/max/2600/1*nB3Y_iqhGVA_nnxayHzHLQ.png
I start usually by updating the hosts file on my computer, in order to make accessing the machine easier without the need of typing the IP…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe : Ignite write-up
I start usually by updating the hosts file on my computer, in order to make accessing the machine easier without the need of typing the IP…
hacking: security in practice
Shell code used in payloads
Why is shell code allways used to write payloads?
submitted by /u/dannova23
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Shell code used in payloads
Why is shell code allways used to write payloads?
submitted by /u/dannova23
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Shell code used in payloads
Why is shell code allways used to write payloads?
hacking: security in practice
Nmap with Ping and Firewall
Hey guys,
i am scanning a server within a Network with nmap. If i use my machine (not in the network) it shows me 3 open ports the rest is blocked by the firewall. If i use a VM within the Network all 1000 ports seems blocked. But if i ping the machine and scan then it shows the expected output of 15 open ports.
Does anyone has an idea why the intern scan is blocked but works after i ping the machine with it?
submitted by /u/magnacrio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Nmap with Ping and Firewall
Hey guys,
i am scanning a server within a Network with nmap. If i use my machine (not in the network) it shows me 3 open ports the rest is blocked by the firewall. If i use a VM within the Network all 1000 ports seems blocked. But if i ping the machine and scan then it shows the expected output of 15 open ports.
Does anyone has an idea why the intern scan is blocked but works after i ping the machine with it?
submitted by /u/magnacrio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Nmap with Ping and Firewall
Hey guys, i am scanning a server within a Network with nmap. If i use my machine (not in the network) it shows me 3 open ports the rest...
hacking: security in practice
Trying to remember web hacking challenge
I am trying to remember a web hacking challenge/practise site but am failing to find it again.
It was set up as a series of servers running on different subdomains (something like p1.something.com p2.something.com etc) and the goal in each server is to find the login details for the next. You mainly interact with the site through http in a browser. I remember most early tasks revolving around exploiting some classic injection weaknesses through forms or url parameters, at one point being able to inject and execute linux terminal commands.
It was not some kind of community site or anything of the like. It was a really plain site with only these tasks and an introductory page.
Does anybody know of this site? Has it been discontinued?
submitted by /u/Loewenpower
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Trying to remember web hacking challenge
I am trying to remember a web hacking challenge/practise site but am failing to find it again.
It was set up as a series of servers running on different subdomains (something like p1.something.com p2.something.com etc) and the goal in each server is to find the login details for the next. You mainly interact with the site through http in a browser. I remember most early tasks revolving around exploiting some classic injection weaknesses through forms or url parameters, at one point being able to inject and execute linux terminal commands.
It was not some kind of community site or anything of the like. It was a really plain site with only these tasks and an introductory page.
Does anybody know of this site? Has it been discontinued?
submitted by /u/Loewenpower
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Trying to remember web hacking challenge
I am trying to remember a web hacking challenge/practise site but am failing to find it again. It was set up as a series of servers running on...
Kali Linux Tutorials
LAZYPARIAH : A Tool For Generating Reverse Shell Payloads On The Fly
___________________________
@hacking_Attack
@Hacking_Video
LAZYPARIAH : A Tool For Generating Reverse Shell Payloads On The Fly
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
LAZYPARIAH : A Tool For Generating Reverse Shell Payloads On The Fly
LAZYPARIAH is a simple and easily installable command-line tool written in pure Ruby that can be used during penetration tests and CTF.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Casper-Fs : A Custom Hidden Linux Kernel Module Generator
Casper-fs is a custom Linux Kernel Module generator to work with resources to protect or hide a custom list of files. Each LKM has resources to protect or hide files following a custom list in the YAML rule file. Yes, not even the root has permission to see the files or make actions like edit and remove. The files only can be caught, edited, and deleted if the user sends a proper key to the custom device to liberate the action in the file system. OverviewThe first point, the user sends input to the Casper-FS the YAML file with rules to generate a custom LKM(Linux kernel module), each generated module works in the file system to protect and hide secret files (Not even the root has permission to see the file, only can see with a proper sending key to the custom device). This program has two principal functions: turning private files hidden. The second function is to protect confidential files to prevent reading, writing and removal.
The motivation: An attacker can read every file in your machine in a bad situation(if he got root). But if you have a Casper-fs custom module, the attacker will not find the hidden kernel module that has functions to protect your private data files such as logs and password vaults.
My beginning purpose at this project is to protect my server, which is to protect my friends’ machines. When I talk to friends, I say peoples that don’t know how to write low-level code. Using the Casper-fs, you can generate your custom kernel module to protect your secret files. The low-level programmer can write new templates for modules etc. The first step, understand before the run.Verify if the kernel version is 3.x, 4.x, or 5.x:
$ uname -r
Clone the repository
$ git clone https://github.com/CoolerVoid/casper-fs
Enter the folder and install python3 modules:
$ cd casper-fs/module_generator
$ sudo python3 -m pip install -r requirements.txt
Edit your file rules in directory module_generator/rules/fs-rules.yaml, the python scripts, use that file to generate a new casper-fs custom module.
$ cat module_generator/rules/fs-rules.yaml
binary_name: casperfs
module_name: Casperfs
unhide_module_key: AbraKadabra
hide_module_key: Shazam
fake_device_name: usb15
unhide-hide-file-key: Alakazam
unprotect-protect-file-key: Sesame
fs-rules:
hidden:
1: secret.txt
2: my_vault.db
protect:
1: backup_httpd.log
The array is hidden and array protected. You can insert a lot of the elements of another file on context, for example:
protect:
1: backup_httpd.log
2: secret_img.iso
3: secret_file.img
4: secret_file2.img
5: secret_file3.img
If you want to study the static code to generate, look at the directory “templates” content. The second step, generate your module.If you want to generate a kernel module following your YAML file of rules, follow that command:
$ python3 casper-fs-gen.py –rules rules/fs-rules.yaml The third step, install your module.If you use Fedora Linux, install kernel packages for the developer:
dnf update
dnf install kernel-headers.x86_64 kernel-modules.x86_64 kernel.x86_64 kernel-devel kmod
On Ubuntu Linux:
apt install linux-headers-generic gcc make
To test module:
cd output; make clean; make
insmod casperfs.ko The fourth step runs your custom module.* The password to turn casper-fs module visible for lsmod is the key “Shazam”.
* The password to turn the casper-fs invisible is “AbraKadabra”.
* The password to turn the secret files in hidden is “Alakazam”, the same to turn to unhidden.
* The password to protect files or unprotect is “Sesame”.
You need to send the password for your fake device, “usb15” for example, to test hidden and unhidden resources on the file system:
$ touch secret.txt
$ ls
— no results–
$ echo “Alakazam” > /dev/usb15
$ ls
secret.txt
$ echo “Alakazam” > /dev/usb15
$ ls
— no results–
Not[...]
___________________________
@hacking_Attack
@Hacking_Video
Casper-Fs : A Custom Hidden Linux Kernel Module Generator
Casper-fs is a custom Linux Kernel Module generator to work with resources to protect or hide a custom list of files. Each LKM has resources to protect or hide files following a custom list in the YAML rule file. Yes, not even the root has permission to see the files or make actions like edit and remove. The files only can be caught, edited, and deleted if the user sends a proper key to the custom device to liberate the action in the file system. OverviewThe first point, the user sends input to the Casper-FS the YAML file with rules to generate a custom LKM(Linux kernel module), each generated module works in the file system to protect and hide secret files (Not even the root has permission to see the file, only can see with a proper sending key to the custom device). This program has two principal functions: turning private files hidden. The second function is to protect confidential files to prevent reading, writing and removal.
The motivation: An attacker can read every file in your machine in a bad situation(if he got root). But if you have a Casper-fs custom module, the attacker will not find the hidden kernel module that has functions to protect your private data files such as logs and password vaults.
My beginning purpose at this project is to protect my server, which is to protect my friends’ machines. When I talk to friends, I say peoples that don’t know how to write low-level code. Using the Casper-fs, you can generate your custom kernel module to protect your secret files. The low-level programmer can write new templates for modules etc. The first step, understand before the run.Verify if the kernel version is 3.x, 4.x, or 5.x:
$ uname -r
Clone the repository
$ git clone https://github.com/CoolerVoid/casper-fs
Enter the folder and install python3 modules:
$ cd casper-fs/module_generator
$ sudo python3 -m pip install -r requirements.txt
Edit your file rules in directory module_generator/rules/fs-rules.yaml, the python scripts, use that file to generate a new casper-fs custom module.
$ cat module_generator/rules/fs-rules.yaml
binary_name: casperfs
module_name: Casperfs
unhide_module_key: AbraKadabra
hide_module_key: Shazam
fake_device_name: usb15
unhide-hide-file-key: Alakazam
unprotect-protect-file-key: Sesame
fs-rules:
hidden:
1: secret.txt
2: my_vault.db
protect:
1: backup_httpd.log
The array is hidden and array protected. You can insert a lot of the elements of another file on context, for example:
protect:
1: backup_httpd.log
2: secret_img.iso
3: secret_file.img
4: secret_file2.img
5: secret_file3.img
If you want to study the static code to generate, look at the directory “templates” content. The second step, generate your module.If you want to generate a kernel module following your YAML file of rules, follow that command:
$ python3 casper-fs-gen.py –rules rules/fs-rules.yaml The third step, install your module.If you use Fedora Linux, install kernel packages for the developer:
dnf update
dnf install kernel-headers.x86_64 kernel-modules.x86_64 kernel.x86_64 kernel-devel kmod
On Ubuntu Linux:
apt install linux-headers-generic gcc make
To test module:
cd output; make clean; make
insmod casperfs.ko The fourth step runs your custom module.* The password to turn casper-fs module visible for lsmod is the key “Shazam”.
* The password to turn the casper-fs invisible is “AbraKadabra”.
* The password to turn the secret files in hidden is “Alakazam”, the same to turn to unhidden.
* The password to protect files or unprotect is “Sesame”.
You need to send the password for your fake device, “usb15” for example, to test hidden and unhidden resources on the file system:
$ touch secret.txt
$ ls
— no results–
$ echo “Alakazam” > /dev/usb15
$ ls
secret.txt
$ echo “Alakazam” > /dev/usb15
$ ls
— no results–
Not[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Casper-Fs : A Custom Hidden Linux Kernel Module Generator
Casper-fs is a custom Linux Kernel Module generator to work with resources to protect or hide a custom list of files.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Casper-Fs : A Custom Hidden Linux Kernel Module Generator Casper-fs is a custom Linux Kernel Module generator to work with resources to protect or hide a custom list of files. Each LKM has resources to protect or hide files following…
e You need to turn casperfs visible at the “lsmod” command. Need this action before removing module
rmmod casperfs
rmmod: ERROR: ../libkmod/libkmod-module.c:799 kmod_module_remove_module() could not remove ‘casperfs’: No such file or directory
rmmod: ERROR: could not remove module casperfs: No such file or directory
lsmod | grep casper
echo “Shazam” > /dev/usb15
lsmod | grep casper
casperfs
rmmod casperfs Download
___________________________
@hacking_Attack
@Hacking_Video
rmmod casperfs
rmmod: ERROR: ../libkmod/libkmod-module.c:799 kmod_module_remove_module() could not remove ‘casperfs’: No such file or directory
rmmod: ERROR: could not remove module casperfs: No such file or directory
lsmod | grep casper
echo “Shazam” > /dev/usb15
lsmod | grep casper
casperfs
rmmod casperfs Download
___________________________
@hacking_Attack
@Hacking_Video
CRLF (%0D%0A) Injection
Hello Guys! I am vasu a bug bounty learnerContinue reading on Medium »
Read more...
Hello Guys! I am vasu a bug bounty learnerContinue reading on Medium »
Read more...