Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackThisSite Realistic Mission 2
https://cdn-images-1.medium.com/max/700/0*s-Gkzc8J73lVm_eh.jpg
Alright I can’t post full screenshots of how this website looks as the contents of the fake website have Nazi material. However, I’ll post…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackThisSite Realistic Mission 2
https://cdn-images-1.medium.com/max/700/0*s-Gkzc8J73lVm_eh.jpg
Alright I can’t post full screenshots of how this website looks as the contents of the fake website have Nazi material. However, I’ll post…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackThisSite Realistic Mission 2
Alright I can’t post full screenshots of how this website looks as the contents of the fake website have Nazi material. However, I’ll post…
hacking: security in practice
How do I access the deep web through Tor broswer?
I mean, every time I try to access some website it displays a message telling me that they've found unusual traffic through my network. How do I solve it? And does the IP address they show is really valid?
submitted by /u/Puzzleheaded_703
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do I access the deep web through Tor broswer?
I mean, every time I try to access some website it displays a message telling me that they've found unusual traffic through my network. How do I solve it? And does the IP address they show is really valid?
submitted by /u/Puzzleheaded_703
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do I access the deep web through Tor broswer?
I mean, every time I try to access some website it displays a message telling me that they've found unusual traffic through my network. How do I...
hacking: security in practice
Is this even possible?
Very long and complicated story short….
One of my family members believes they are part of a targeted hack (and actually have a valid legal related reason as to why it could be) but part of their reasoning is:
*
When they use their computer to search on google the location at the bottom traditionally states where they live.
*
until they search something specific related to the case they are involved in which then the Google location changes to another area “from your IP address”.
*
now this other location is very specific, not near where they live and actually relates very much to the person they believe is involved in hacking them
Therefore they believe they have a key logger which is monitoring what they are searching and changing to a different server/ IP when something specific is searched.
There is a bunch of other weird things going on with their phone/ laptop but above was quite specific example which they brought up and I’m not sure is even possible/makes sense at all…
I’m aware IP addresses ping from all sorts of places but the specificity of this location is shockingly odd.
submitted by /u/Crafty-Bad-4511
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is this even possible?
Very long and complicated story short….
One of my family members believes they are part of a targeted hack (and actually have a valid legal related reason as to why it could be) but part of their reasoning is:
*
When they use their computer to search on google the location at the bottom traditionally states where they live.
*
until they search something specific related to the case they are involved in which then the Google location changes to another area “from your IP address”.
*
now this other location is very specific, not near where they live and actually relates very much to the person they believe is involved in hacking them
Therefore they believe they have a key logger which is monitoring what they are searching and changing to a different server/ IP when something specific is searched.
There is a bunch of other weird things going on with their phone/ laptop but above was quite specific example which they brought up and I’m not sure is even possible/makes sense at all…
I’m aware IP addresses ping from all sorts of places but the specificity of this location is shockingly odd.
submitted by /u/Crafty-Bad-4511
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is this even possible?
Very long and complicated story short…. One of my family members believes they are part of a targeted hack (and actually have a valid legal...
hacking: security in practice
how do I get elements from a website?
I don't know if I worded the title correctly. I started playing around with BeEF and copied the source code from McDonald's to inject with the "hook". everything works fine but the website looks obviously fake because it lacks the pictures the real McDonald's site normally has. I know it's because my computer doesn't have the pictures downloaded to it. I'm not a web developer or anything close to being one so what code would I have to change if any to make it work properly?
submitted by /u/Background_Gene_3657
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
how do I get elements from a website?
I don't know if I worded the title correctly. I started playing around with BeEF and copied the source code from McDonald's to inject with the "hook". everything works fine but the website looks obviously fake because it lacks the pictures the real McDonald's site normally has. I know it's because my computer doesn't have the pictures downloaded to it. I'm not a web developer or anything close to being one so what code would I have to change if any to make it work properly?
submitted by /u/Background_Gene_3657
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
how do I get elements from a website?
I don't know if I worded the title correctly. I started playing around with BeEF and copied the source code from McDonald's to inject with the...
hacking: security in practice
Yes Another CTF team
I’ve been doing ctfs for about a month now and looking to get a team of people who are interested in improving ctf skills / talk about hacking in general. No skill level required, while I’m a beginner myself.
I would ideally like to collaborate while doing ctfs, to further gain our knowledge and methodology. But just Want to have a smaller group of people who are truly interested in CTFs/hacking/cybersecurity to communicate with
Please let me know if your interested.
submitted by /u/Round-Beach9498
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Yes Another CTF team
I’ve been doing ctfs for about a month now and looking to get a team of people who are interested in improving ctf skills / talk about hacking in general. No skill level required, while I’m a beginner myself.
I would ideally like to collaborate while doing ctfs, to further gain our knowledge and methodology. But just Want to have a smaller group of people who are truly interested in CTFs/hacking/cybersecurity to communicate with
Please let me know if your interested.
submitted by /u/Round-Beach9498
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Yes Another CTF team
I’ve been doing ctfs for about a month now and looking to get a team of people who are interested in improving ctf skills / talk about hacking in...
hacking: security in practice
How hard is it to hack a random Gmail email
Hi I was wondering how hard would it be to hack a random Gmail without knowing anything about the person. Is it possible to brute force on Gmail.
submitted by /u/Ok_Contact_1020
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How hard is it to hack a random Gmail email
Hi I was wondering how hard would it be to hack a random Gmail without knowing anything about the person. Is it possible to brute force on Gmail.
submitted by /u/Ok_Contact_1020
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How hard is it to hack a random Gmail email
Hi I was wondering how hard would it be to hack a random Gmail without knowing anything about the person. Is it possible to brute force on Gmail.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover
Critical Vulnerability in Premium WordPress Themes Allows for Site TakeoverPost Views: 1
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
A critical privilege escalation flaw found in two themes used by more than 90,000 WordPress sites can allow threat actors to take over the sites completely, researchers have found.
WordFence Threat Intelligence Team researcher Ramuel Gall discovered the flaw, one of five vulnerabilities he found between early April and early May in the Jupiter and JupiterX Premium WordPress themes, he revealed in a blog post published Wednesday.
One of the flaws—tracked as CVE-2022-1654 and rated as 9.9, or critical on the CVSS–allows for “any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges and completely take over any site running either the Jupiter Theme or JupiterX Core Plugin,” he wrote. The plugin is required to run the JupiterX theme.
Affected versions of the themes are: Jupiter Theme 6.10.1 or earlier, and JupiterX Core Plugin 2.0.7 or earlier.
WordFence finished their investigation of most of flaws on April 5 and reported them to the Jupiter and JupiterX theme developer ArtBees on the same day; on May 3 they notified the developer of an additional Jupiter theme flaw. By May 10, the developed had released updated versions of both the Jupiter and JupiterX themes that had patched all the flaws.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Critical VulnerabilityThe critical flaw found resides in a function, uninstallTemplate, which is intended to reset a site after a template is uninstalled. However, it “has the additional effect of elevating the user calling the function to an administrator role,” Gall wrote. In the Jupiter theme, the function is found in the theme itself; in JupiterX, it’s present in the JupiterX Core plugin.
“Vulnerable versions register AJAX actions but do not perform any capability checks or nonce checks,” he wrote.
On a site with a vulnerable version of the Jupiter Theme installed, any logged-in user can elevate their privileges to those of an administrator by sending an AJAX request with the action parameter set to abb_uninstall_template. This calls the uninstallTemplate function, which calls the resetWordpressDatabase function, which effectively reinstalls the site with the currently logged-in user as the new site owner, Gall explained.
On a site where a vulnerable version of the JupiterX Core plugin is installed, someone can access the same functionality by sending an AJAX request with the action parameter set to jupiterx_core_cp_uninstall_template, he said.
See Also: Attackers Use Event Logs to Hide Fileless Malware See Also: Offensive Security Tool: malicious-pdf Other VulnerabilitiesWordPress plugins, often developed by third-party developers, are notoriously buggy. Previous flaws found in plugins for the popular website-creation and -hosting platform also have allowed for site takeover, as well as enabled WordPress subscribers to totally wipe sites not belonging to them, or attackers to forge emails to subscribers.
Of the other flaws that Gall discovered, three—tracked as CVE-2022-1656, CVE-2022-1658 and CVE-2022-1659–are rated as medium risk and one, CVE-2022-1657 is rated as high risk.
The high-risk flaw, which affects JupiterX Theme 2.0.6 or earlier and Jupiter Theme 6.10.1 or earlier, can allow an attacker to obtain[...]
___________________________
@hacking_Attack
@Hacking_Video
Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover
Critical Vulnerability in Premium WordPress Themes Allows for Site TakeoverPost Views: 1
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
A critical privilege escalation flaw found in two themes used by more than 90,000 WordPress sites can allow threat actors to take over the sites completely, researchers have found.
WordFence Threat Intelligence Team researcher Ramuel Gall discovered the flaw, one of five vulnerabilities he found between early April and early May in the Jupiter and JupiterX Premium WordPress themes, he revealed in a blog post published Wednesday.
One of the flaws—tracked as CVE-2022-1654 and rated as 9.9, or critical on the CVSS–allows for “any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges and completely take over any site running either the Jupiter Theme or JupiterX Core Plugin,” he wrote. The plugin is required to run the JupiterX theme.
Affected versions of the themes are: Jupiter Theme 6.10.1 or earlier, and JupiterX Core Plugin 2.0.7 or earlier.
WordFence finished their investigation of most of flaws on April 5 and reported them to the Jupiter and JupiterX theme developer ArtBees on the same day; on May 3 they notified the developer of an additional Jupiter theme flaw. By May 10, the developed had released updated versions of both the Jupiter and JupiterX themes that had patched all the flaws.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Critical VulnerabilityThe critical flaw found resides in a function, uninstallTemplate, which is intended to reset a site after a template is uninstalled. However, it “has the additional effect of elevating the user calling the function to an administrator role,” Gall wrote. In the Jupiter theme, the function is found in the theme itself; in JupiterX, it’s present in the JupiterX Core plugin.
“Vulnerable versions register AJAX actions but do not perform any capability checks or nonce checks,” he wrote.
On a site with a vulnerable version of the Jupiter Theme installed, any logged-in user can elevate their privileges to those of an administrator by sending an AJAX request with the action parameter set to abb_uninstall_template. This calls the uninstallTemplate function, which calls the resetWordpressDatabase function, which effectively reinstalls the site with the currently logged-in user as the new site owner, Gall explained.
On a site where a vulnerable version of the JupiterX Core plugin is installed, someone can access the same functionality by sending an AJAX request with the action parameter set to jupiterx_core_cp_uninstall_template, he said.
See Also: Attackers Use Event Logs to Hide Fileless Malware See Also: Offensive Security Tool: malicious-pdf Other VulnerabilitiesWordPress plugins, often developed by third-party developers, are notoriously buggy. Previous flaws found in plugins for the popular website-creation and -hosting platform also have allowed for site takeover, as well as enabled WordPress subscribers to totally wipe sites not belonging to them, or attackers to forge emails to subscribers.
Of the other flaws that Gall discovered, three—tracked as CVE-2022-1656, CVE-2022-1658 and CVE-2022-1659–are rated as medium risk and one, CVE-2022-1657 is rated as high risk.
The high-risk flaw, which affects JupiterX Theme 2.0.6 or earlier and Jupiter Theme 6.10.1 or earlier, can allow an attacker to obtain[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover | Black Hat Ethical Hacking
A critical privilege escalation flaw found in two themes used by more than 90,000 WordPress sites can allow threat actors to take over the sites completely, researchers have found.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover Critical Vulnerability in Premium WordPress Themes Allows for Site TakeoverPost Views: 1 Premium Content https://www.blackhatethicalhacking.com/wp-cont…
privileged information, such as nonce values, or perform restricted actions, Gall explained. This can be done by including and executing files from any location on the site.
“Vulnerable versions of the Jupiter and JupiterX Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion,” Gall explained. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Find hidden and encrypted secrets from any website In the JupiterX theme, this can be done by using the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php file to call the load_control_panel_pane function. “It is possible to use this action to include any local PHP file via the slug parameter,” Gall wrote.
The Jupiter theme has a nearly identical vulnerability, which an attacker can exploit via the mka_cp_load_pane_action AJAX action present in the framework/admin/control-panel/logic/functions.php file, which calls the mka_cp_load_pane_action function, he said.
Wordfence researchers recommend that anyone using the affected themes updated to the patched versions immediately. The company released a firewall rule to protect Wordfence Premium, Wordfence Care and Wordfence Response customers on April 5, and free Wordfence users on May 4.
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell24 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20211 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-azure-cloud-90x90.jpg Microsoft releases fixes for Azure flaw allowing RCE attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/f5-big-ip-hacking-90x90.jpg Exploits created for critical F5 BIG-IP flaw, install patch immediately2 weeks ago
The post Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
“Vulnerable versions of the Jupiter and JupiterX Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion,” Gall explained. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Find hidden and encrypted secrets from any website In the JupiterX theme, this can be done by using the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php file to call the load_control_panel_pane function. “It is possible to use this action to include any local PHP file via the slug parameter,” Gall wrote.
The Jupiter theme has a nearly identical vulnerability, which an attacker can exploit via the mka_cp_load_pane_action AJAX action present in the framework/admin/control-panel/logic/functions.php file, which calls the mka_cp_load_pane_action function, he said.
Wordfence researchers recommend that anyone using the affected themes updated to the patched versions immediately. The company released a firewall rule to protect Wordfence Premium, Wordfence Care and Wordfence Response customers on April 5, and free Wordfence users on May 4.
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell24 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20211 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-azure-cloud-90x90.jpg Microsoft releases fixes for Azure flaw allowing RCE attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/f5-big-ip-hacking-90x90.jpg Exploits created for critical F5 BIG-IP flaw, install patch immediately2 weeks ago
The post Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
ZPrize Competition: 7 million in Prizes
The Z-Prize is an industry-wide effort to accelerate zero-knowledge technology. This effort will be in the form of a competition, in the likeness of the X-Prize, or DARPA Grand Challenge. The results of the competition will be open-sourced for the benefit of all as public goods.
You're invited to compete - more information here: https://www.youtube.com/watch?v=iGcRgiSCFHM
submitted by /u/dhethz
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
ZPrize Competition: 7 million in Prizes
The Z-Prize is an industry-wide effort to accelerate zero-knowledge technology. This effort will be in the form of a competition, in the likeness of the X-Prize, or DARPA Grand Challenge. The results of the competition will be open-sourced for the benefit of all as public goods.
You're invited to compete - more information here: https://www.youtube.com/watch?v=iGcRgiSCFHM
submitted by /u/dhethz
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
ZPrize Competition: 7 million in Prizes
The Z-Prize is an industry-wide effort to accelerate zero-knowledge technology. This effort will be in the form of a competition, in the likeness...
hacking: security in practice
Different domains on a same IP security pattern
Hello security people,
Question about security issues, when different domains are resolved with the same IP address?
submitted by /u/IntelligentPattern10
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Different domains on a same IP security pattern
Hello security people,
Question about security issues, when different domains are resolved with the same IP address?
submitted by /u/IntelligentPattern10
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Different domains on a same IP security pattern
Hello security people, Question about security issues, when different domains are resolved with the same IP address?
hacking: security in practice
how run macro script (game)
I searched across the internet but I found nothing so I wonder is anyone know how run it
submitted by /u/roxtoxbox
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
how run macro script (game)
I searched across the internet but I found nothing so I wonder is anyone know how run it
submitted by /u/roxtoxbox
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
how run macro script (game)
I searched across the internet but I found nothing so I wonder is anyone know how run it
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Offensive Security Tool: Arjun
Offensive Security Tool: ArjunPost Views: 58
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Offensive Security Tool: Arjun GitHub Link
When you are in a Red Team or a Pentester and working on a web application, before you start injection-based attacks you need URLs with Parameters. Without Parameters, you cannot inject, so you got to find an injection point to start attacking with different types such as XSS, SQLi, LFI, etc. Arjun, does this for you. Once you find a URL with a parameter after performing some spidering, you then can use this tool and it will check and find for you the parameters, that can be injected. What’s Arjun?Arjun by s0md3v can find query parameters for URL endpoints. If you don’t get what that means, it’s okay, read along. Web applications use parameters (or queries) to accept user input, consider the following example:
The best part? It takes less than 10 seconds to go through this huge list while making just 20-30 requests to the target. Here’s how.
See Also: Complete Offensive Security and Ethical Hacking Course Why Arjun?* Supports GET/POST/POST-JSON/POST-XML requests
* Automatically handles rate limits and timeouts
* Export results to: Burp Suite, text or JSON file
* Import targets from: Burp Suite, text file or a raw request file
* Can passively extract parameters from JS or 3 external sources Installing ArjunYou can install arjun with pip as following:
Direct links to some basic options are given below:
* Scan a single URL
* Import targets
* Export results
* Use custom HTTP headers
Optionally, you can use the –help argument to explore Arjun on your own.
See Also: Write up: Find hidden and encrypted secrets from any website https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Dorks-collections-list-90x90.png Recon Tool: Dorks collections list1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/malicious-pdf-90x90.png Offensive Security Tool: malicious-pdf1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/scanmycode-90x90.png Static Code Analysis Tool: scanmycode-ce2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/MOSINT-1-90x90.png OSINT Tool: MOSINT3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/findomain-90x90.png Recon Tool: Findomain3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/keethief-90x90.png Offensive Security Tool: KeeThief4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/reconftw-90x90.png Recon Tool: ReconFTW4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/smap-demo-90x90.png Recon Tool: Smap1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Proxmark3-90x90.png Offensive Security Tool: Proxmark31 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/boomerang-90x90.png Offensive Security Tool: Boomerang2 months ago
The post Offensive Security Tool: Arjun first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Offensive Security Tool: Arjun
Offensive Security Tool: ArjunPost Views: 58
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Offensive Security Tool: Arjun GitHub Link
When you are in a Red Team or a Pentester and working on a web application, before you start injection-based attacks you need URLs with Parameters. Without Parameters, you cannot inject, so you got to find an injection point to start attacking with different types such as XSS, SQLi, LFI, etc. Arjun, does this for you. Once you find a URL with a parameter after performing some spidering, you then can use this tool and it will check and find for you the parameters, that can be injected. What’s Arjun?Arjun by s0md3v can find query parameters for URL endpoints. If you don’t get what that means, it’s okay, read along. Web applications use parameters (or queries) to accept user input, consider the following example:
http://api.example.com/v1/userinfo?id=751634589This URL seems to load user information for a specific user id, but what if there is a parameter named admin that, when set to True, makes the endpoint provide more information about the user? This is what Arjun does, it finds valid HTTP parameters with a huge default dictionary of 10,985 parameter names.The best part? It takes less than 10 seconds to go through this huge list while making just 20-30 requests to the target. Here’s how.
See Also: Complete Offensive Security and Ethical Hacking Course Why Arjun?* Supports GET/POST/POST-JSON/POST-XML requests
* Automatically handles rate limits and timeouts
* Export results to: Burp Suite, text or JSON file
* Import targets from: Burp Suite, text file or a raw request file
* Can passively extract parameters from JS or 3 external sources Installing ArjunYou can install arjun with pip as following:
pip3 install arjunor, by downloading this repository and running python3 setup.py installSee Also: Recon Tool: Dorks collections list How to use Arjun?A detailed usage guide is available on Usage section of the Wiki.Direct links to some basic options are given below:
* Scan a single URL
* Import targets
* Export results
* Use custom HTTP headers
Optionally, you can use the –help argument to explore Arjun on your own.
See Also: Write up: Find hidden and encrypted secrets from any website https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Dorks-collections-list-90x90.png Recon Tool: Dorks collections list1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/malicious-pdf-90x90.png Offensive Security Tool: malicious-pdf1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/scanmycode-90x90.png Static Code Analysis Tool: scanmycode-ce2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/MOSINT-1-90x90.png OSINT Tool: MOSINT3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/findomain-90x90.png Recon Tool: Findomain3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/keethief-90x90.png Offensive Security Tool: KeeThief4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/reconftw-90x90.png Recon Tool: ReconFTW4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/smap-demo-90x90.png Recon Tool: Smap1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Proxmark3-90x90.png Offensive Security Tool: Proxmark31 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/boomerang-90x90.png Offensive Security Tool: Boomerang2 months ago
The post Offensive Security Tool: Arjun first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Offensive Security Tool: Arjun | Black Hat Ethical Hacking
When you are in a Red Team or a Pentester and working on a web app, before you start injection-based attacks, you need URLs with Parameters. Arjun can find query parameters for URL endpoints.
Dark Reading: Attacks/Breaches
New Open Source Project Brings Consistent Identity Access to Multicloud
Hexa and IDQL allows organizations using cloud platforms such as Microsoft Azure, Amazon Web Services, and Google Cloud Platform to apply consistent access policy across all applications, regardless of environment.
New Open Source Project Brings Consistent Identity Access to Multicloud
Hexa and IDQL allows organizations using cloud platforms such as Microsoft Azure, Amazon Web Services, and Google Cloud Platform to apply consistent access policy across all applications, regardless of environment.
Octopus - Open Source Pre-Operation C2 Server Based On Python And Powershell
http://www.kitploit.com/2022/05/octopus-open-source-pre-operation-c2.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/octopus-open-source-pre-operation-c2.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Octopus - Open Source Pre-Operation C2 Server Based On Python And Powershell
Octopus is an open source, pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S. The main purpose of creating Octopus is for use before any red team operation, where rather than starting the engagement with your full operational arsenal and infrastructure, you can use Octopus first to attack the target and gather information before you start your actual red team operation. Octopus works in a very simple way to execute commands and exchange information with the C2 over a well encrypted channel, which makes it inconspicuous and undetectable (https://www.kitploit.com/search/label/Undetectable) from almost every AV, endpoint protection, and network monitoring solution. One cool feature in Octopus is called ESA, which stands for "Endpoint Situational Awareness", which will gather some important information about the target that will help you to gain better understanding of the target network endpoints that you will face during your operation, thus giving you a shot to customize your real operation based on this information. Octopus is designed to be stealthy and covert while communicating with the C2, as it uses AES-256 by default for its encrypted channel between the powershell agent and the C2 server. You can also opt for using SSL/TLS by providing a valid certficate for your domain and configuring the Octopus C2 server to use it.
Octopus key features Octopus is packed with a number of features that allows you to gain an insight into your upcoming engagement before you actually need to deploy your full aresenal or tools and techniques, such as: Control agents throught HTTP/S. Execute system commands. Download / Upload files. Load external powershell modules. Use encrypted channels (AES-256) between C2 and agents. Use inconspicuous techniques to execute commands and transfer results. Create custom and multiple listeners for each target. Generate different types of payloads. Support all windows versions with powershell 2.0 and higher. Run Octopus windows executable agent without touching powershell.exe process. Gather information automatically from the endpoint (endpoint situational awareness) feature. Requirements You can install all of Octopus' requirements (https://www.kitploit.com/search/label/Requirements) via : pip install -r requirements.txt You need to install nasm for linux and 'mingw-w64' compiler to use the shellcoding (https://www.kitploit.com/search/label/Shellcoding) feature and the spoofed args agent. You can install nasm on Debian based distros using: apt install nasm And you can install mingw-w64 on Debian based distros using: apt install mingw-w64 Octopus has been tested on the following operating systems: Ubuntu (18.04) Ubuntu (16.04) Kali Linux (2019.2) You will also need to install mono to make sure that you can compile the C# source without issues. Octopus depends on mono-csc binary to compile the C# source and you can install it by the following command apt install mono-devel which has been tested on kali and ubuntu 16.04. you can use Octopus without installing mono but you will not be able to use generate_exe command. Also please note that compling C# depends on the System.Management.Automation.dll assembly with SHA1 hash a43ed886b68c6ee913da85df9ad2064f1d81c470. If you encounter any issues using Octopus, feel free to file a bug report (https://github.com/mhaskar/Octopus/issues)! Installation First of all make sure to download the latest version of Octopus using the following command : git clone https://github.com/mhaskar/Octopus/ Then you need to install the requirements using the following command : pip install -r requirements.txt After that you can start the octopus server by running the following : ./octopus.py You will by greeted with the following once you run it : > ">┌─[askar@hackbook]─[/opt/redteaming/Octopus] └──╼ $python3 octopus.py ___ ___ ___
___________________________
@hacking_Attack
@Hacking_Video
Octopus key features Octopus is packed with a number of features that allows you to gain an insight into your upcoming engagement before you actually need to deploy your full aresenal or tools and techniques, such as: Control agents throught HTTP/S. Execute system commands. Download / Upload files. Load external powershell modules. Use encrypted channels (AES-256) between C2 and agents. Use inconspicuous techniques to execute commands and transfer results. Create custom and multiple listeners for each target. Generate different types of payloads. Support all windows versions with powershell 2.0 and higher. Run Octopus windows executable agent without touching powershell.exe process. Gather information automatically from the endpoint (endpoint situational awareness) feature. Requirements You can install all of Octopus' requirements (https://www.kitploit.com/search/label/Requirements) via : pip install -r requirements.txt You need to install nasm for linux and 'mingw-w64' compiler to use the shellcoding (https://www.kitploit.com/search/label/Shellcoding) feature and the spoofed args agent. You can install nasm on Debian based distros using: apt install nasm And you can install mingw-w64 on Debian based distros using: apt install mingw-w64 Octopus has been tested on the following operating systems: Ubuntu (18.04) Ubuntu (16.04) Kali Linux (2019.2) You will also need to install mono to make sure that you can compile the C# source without issues. Octopus depends on mono-csc binary to compile the C# source and you can install it by the following command apt install mono-devel which has been tested on kali and ubuntu 16.04. you can use Octopus without installing mono but you will not be able to use generate_exe command. Also please note that compling C# depends on the System.Management.Automation.dll assembly with SHA1 hash a43ed886b68c6ee913da85df9ad2064f1d81c470. If you encounter any issues using Octopus, feel free to file a bug report (https://github.com/mhaskar/Octopus/issues)! Installation First of all make sure to download the latest version of Octopus using the following command : git clone https://github.com/mhaskar/Octopus/ Then you need to install the requirements using the following command : pip install -r requirements.txt After that you can start the octopus server by running the following : ./octopus.py You will by greeted with the following once you run it : > ">┌─[askar@hackbook]─[/opt/redteaming/Octopus] └──╼ $python3 octopus.py ___ ___ ___
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
___ ___ ___ / /\ / /\ ___ / /\ / /\ /__/\ / /\ / /::\ / /:/ / /\ / /::\ / /::\ \ \:\ / /:/_ / /:/\:\ / /:/ / /:/ / /:/\:\ / /:/\:\ \ \:\ / /:/ /\ / /:/ \:\ / /:/ ___ / /:/ / /:/ \:\ / /:/~/:/ ___ \ \:\ / /:/ /::\ /__/:/ \__\:\ /__/:/ / /\ / /::\ /__/:/ \__\:\ /__/:/ /:/ /__/\ \__\:\ /__/:/ /:/\:\ \ \:\ / /:/ \ \:\ / /:/ /__/:/\:\ \ \:\ / /:/ \ \:\/:/ \ \:\ / /:/ \ \:\/:/~/:/ \ \:\ /:/ \ \:\ /:/ \__\/ \:\ \ \:\ /:/ \ \::/ \ \:\ /:/ \ \::/ /:/ \ \:\/:/ \ \:\/:/ \ \:\ \ \:\/:/ \ \:\ \ \:\/:/ \__\/ /:/ \ \::/ \ \::/ \__\/ \ \::/ \ \:\ \ \::/ /__/:/ \__\/ \__\/ \__\/ \__\/ \__\/ \__\/ v1.2 stable ! Octopus C2 | Control your shells Octopus >> Usage Using Octopus is quite simple to use, as you just need to start a listener and generate your agent based on that listener's information. You can generate as many listeners as you need, and then you can start interacting with your agents that connect to them. Profile setup Before you can start using Octopus you have to setup a URL handling profile which will control the C2 behavior and functions, as Octopus is an HTTP based C2 thus it depends on URLs to handle the connections and to guarantee that the URLs will not serve as a signatures or IoC in the network you are currently attacking, the URLs can be easily customized and renamed as needed. Profile setup currently only support URL handling, auto kill value and headers. Setting up your profile To start setting up your profile you need to edit the profile.py file , which contains a number of key variables, which are: file_reciever_url: handles file downloading. report_url: handle ESA reports. command_send_url: handles the commands that will be sent to the target. command_receiver_url: handles commands will be executed on the target. first_ping_url: handles the first connection from the target. server_response_header: this header will show in every response. auto_kill: variable to control when the agent will be killed after N failed connections with the C2 Example: as it with the same format # Ex : /profile/ # Ex : /messages/ # Ex : /bills/ command_send_url = "/view/" # handling the executed command # Ex : /anything # Ex : /anything.php command_receiver_url = "/bills" # handling the first connection from the agent # Ex : /anything # Ex : /anything.php first_ping_url = "/login" # will return in every response as Server header server_response_header = "nginx" # will return white page that includes HTA script mshta_url = "/hta" # auto kill value after n tries auto_kill = 10 '>#!/usr/bin/python3 # this is the web listener profile for Octopus C2 # you can customize your profile to handle a specific URLs to communicate with the agent # TODO : add the ability to customize the request headers # handling the file downloading # Ex : /anything # Ex : /anything.php file_receiver_url = "/messages" # handling the report generation # Ex : /anything # Ex : /anything.php report_url = "/calls" # command sending to agent (store the command will be executed on a host) # leave as it with the same format # Ex : /profile/ # Ex : /messages/ # Ex : /bills/ command_send_url = "/view/" # handling the executed command # Ex : /anything # Ex : /anything.php command_receiver_url = "/bills" # handling the first connection from the agent # Ex : /anything # Ex : /anything.php first_ping_url = "/login" # will return in every response as Server header server_response_header = "nginx" # will return white page that includes HTA script
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
mshta_url = "/hta" # auto kill value after n tries auto_kill = 10 The agent and the listeners will be configured to use this profile to communicate with each other. Next we need to know how to create a listener. Listeners Octopus has two main listeners,"http listener" and "https listener" , and the options of the two listeners are mostly identical. HTTP listener : listen_http command takes the following arguments to start: BindIP Defines the IP address that will be used by the listener. BindPort Defines the port you want to listen on. Hostname Will be used to request the payload from. Interval How number of seconds the agent will wait before checking for commands. URL The name of the page hosting the payload. Listener_name Listener name to use. you can also view an example of it by running the listen_http command: >listen_http [-] Please check listener arguments ! Syntax : listen_http BindIP BindPort hostname interval URL listener_name Example (with domain) : listen_http 0.0.0.0 8080 myc2.live 5 comments.php op1_listener Example (without domain) : listen_http 0.0.0.0 8080 172.0.1.3 5 profile.php op1_listener ########## Options info : BindIP IP address that will be used by the listener BindPort port you want to listen on Hostname will be used to request the payload from Interval how may seconds that agent will wait before check for commands URL page name will hold the payload Listener_name listener name to use Octopus >>">Octopus >>listen_http [-] Please check listener arguments ! Syntax : listen_http BindIP BindPort hostname interval URL listener_name Example (with domain) : listen_http 0.0.0.0 8080 myc2.live 5 comments.php op1_listener Example (without domain) : listen_http 0.0.0.0 8080 172.0.1.3 5 profile.php op1_listener ########## Options info : BindIP IP address that will be used by the listener BindPort port you want to listen on Hostname will be used to request the payload from Interval how may seconds that agent will wait before check for commands URL page name will hold the payload Listener_name listener name to use Octopus >> And we can start a listener using the following command : listen_http 0.0.0.0 8080 192.168.178.1 5 page.php operation1 The following result will be returned: >listen_http 0.0.0.0 8080 192.168.178.1 5 page.php operation1 Octopus >> * Serving Flask app "core.weblistener" (lazy loading) * Environment: production WARNING: Do not use the development server in a production environment. Use a production WSGI server instead. * Debug mode: off Octopus >>'>Octopus >>listen_http 0.0.0.0 8080 192.168.178.1 5 page.php operation1 Octopus >> * Serving Flask app "core.weblistener" (lazy loading) * Environment: production WARNING: Do not use the development server in a production environment. Use a production WSGI server instead. * Debug mode: off Octopus >> a listener has been started successfully, and we can view all the listeners using the listeners command: >listeners Name IP Port Host Interval Path SSL ---------- ------- ------ ------------- ---------- -------- ----- operation1 0.0.0.0 8080 192.168.178.1 5 page.php False Octopus >>">Octopus >>listeners Name IP Port Host Interval Path SSL ---------- ------- ------ ------------- ---------- -------- ----- operation1 0.0.0.0 8080 192.168.178.1 5 page.php False Octopus >> HTTPS listener : To create an HTTPS listener you can use listen_https command as such: >listen_https [-] Please check listener arguments ! Syntax : listen_https BindIP BindPort hostname interval URL listener_name certficate_path key_path Example (with domain) : listen_https 0.0.0.0 443 myc2.live 5 login.php op1_listener certs/cert.pem certs/key.pem Octopus >>listen_https
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video