Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Any advice for learning cyber security

I already received some hate like "we didn't have classes 10 years ago" or "just Google it" but I have learning disabilities and I struggle to learn from a page. I only do well doing thing hands on, hence why I'm really good at fixing things.. only way to learn is hands on. But I just want some suggestions on ways to learn or maybe if someone would be willing to help me get started.

I can't really afford to pay anything, I don't have more than 3 dollars in my account but I just wanna learn. Cause I doubt I'll go to college. My dad's saving for my sister to go, so I got put to the side, mom spent my college funds on pain pills.

Thanks for any advice. Sorry for being a bother.

submitted by /u/No_Positive_5235
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Snake Keylogger Spreads Through Malicious PDFs

Snake Keylogger Spreads Through Malicious PDFsPost Views: 2
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
While most malicious e-mail campaigns use Word documents to hide and spread malware, a recently discovered campaign uses a malicious PDF file and a 22-year-old Office bug to propagate the Snake Keylogger malware, researchers have found.
The campaign—discovered by researchers at HP Wolf Security—aims to dupe victims with an attached PDF file purporting to have information about a remittance payment, according to a blog post published Friday. Instead, it loads the info-stealing malware, using some tricky evasion tactics to avoid detection.

“While Office formats remain popular, this campaign shows how attackers are also using weaponized PDF documents to infect systems,” HP Wolf Security researcher Patrick Schlapfer wrote in the post, which opined in the headline that “PDF Malware Is Not Yet Dead.”

Indeed, attackers using malicious email campaigns have preferred to package malware in Microsoft Office file formats, particularly Word and Excel, for the past decade, Schlapfer said. In the first quarter of 2022 alone, nearly half (45 percent) of malware stopped by HP Wolf Security used Office formats, according to researchers.

“The reasons are clear: users are familiar with these file types, the applications used to open them are ubiquitous, and they are suited to social engineering lures,” he wrote.

Still, while the new campaign does use PDF in the file lure, it later employs Microsoft Word to deliver the ultimate payload—the Snake Keylogger, researchers found. Snake Keylogger is a malware developed using .NET that first appeared in late 2020 and is aimed at stealing sensitive information from a victim’s device, including saved credentials, the victim’s keystrokes, screenshots of the victim’s screen, and clipboard data, according to Fortinet. ‘Unusual’ CampaignThe HPW Wolf Security team noticed a new PDF-based threat campaign on March 23 with an “unusual infection chain,” involving not just a PDF but also “several tricks to evade detection, such as embedding malicious files, loading remotely-hosted exploits and shellcode encryption,” Schlapfer wrote.

Attackers target victims with emails that include a PDF document named “REMMITANCE INVOICE.pdf”—misspelling intended–as attachment. If someone opens the file, Adobe Reader prompts the user to open a .docx file with a rather curious name, researchers found.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png “The attackers sneakily named the Word document “has been verified. However PDF, Jpeg, xlsx, .docx” to make it look as though the file name was part of the Adobe Reader prompt,” according to the post.

The.docx file is stored as an EmbeddedFile object within the PDF, which opens Microsoft Word if clicked on, researchers found. If Protected View is disabled, Word downloads a Rich Text Format (.rtf) file from a web server, which then is run in the context of the open document.

Researchers unzipped the contents of the .rtf—which is an Office Open XML file—finding a URL hidden in the “document.xml.rels” file that is not a legitimate domain found in Office documents, they said. 17-Year-Old Bug ExploitedConnecting to this URL leads to a redirect and then downloads an RTF document called “f_document_shp.doc. This document contained two “not well-formed” OLE objects that revealed shellcode exploiting CVE-2017-11882, which researchers said is an “over four-years-old” remote code execution vulnerability (RCE) [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Snake Keylogger Spreads Through Malicious PDFs Snake Keylogger Spreads Through Malicious PDFsPost Views: 2 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch…
in Equation Editor.

Equation Editor is app installed by default with the Office suite that’s used to insert and edit complex equations as Object Linking and Embedding (OLE) items in Microsoft Word documents.
See Also: Kali Linux 2022.2 released with new tools, terminal tweaks and more
It turns out, however, that the bug that attackers leverage in the campaign is actually one that Microsoft patched more than four years ago–in 2017, to be exact—but actually had existed some 17 years before that, making it 22 years old now.

As the final act of the attack, researchers found shellcode stored in the “OLENativeStream” structure at the end of one of the OLE objects they examined. The code eventually decrypts a ciphertext that turns out to be more shellcode, which is then executed after to lead to an executable called fresh.exe that loads the Snake Keylogger, researchers found. See Also: Recon Tool: Dorks collections list Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20212 weeks ago
The post Snake Keylogger Spreads Through Malicious PDFs first appeared on Black Hat Ethical Hacking.
My Pentest Log -20 — (A Little Tip in Nessus)

Greetings to all from Porte Drungari,Continue reading on Medium »
Read more...
How I Found a company’s internal S3 Bucket with 41k Files

I found a company’s S3 bucket which was used internally and was not referenced anywhere in GitHub or its domain. This was my first valid…Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Phantun : Transforms UDP Stream Into (Fake) TCP Streams That Can Go Through Layer 3 &Amp

Phantun is a project that obfuscated UDP packets into TCP connections. It aims to achieve maximum performance with minimum processing and encapsulation overhead.

It is commonly used in environments where UDP is blocked/throttled but TCP is allowed through.

Phantun simply converts a stream of UDP packets into obfuscated TCP stream packets. The TCP stack used by Phantun is designed to pass through most L3/L4 stateful/stateless firewalls/NAT devices. It will not be able to pass through L7 proxies. However, the advantage of this approach is that none of the common UDP over TCP performance killer such as retransmissions and flow control will occur. The underlying UDP properties such as out-of-order delivery are fully preserved even if the connection ends up looking like a TCP connection from the perspective of firewalls/NAT devices.

Phantun means Phantom TUN, as it is an obfuscator for UDP traffic that does just enough work to make it pass through stateful firewall/NATs as TCP packets.

Phantun is written in 100% safe Rust. It has been optimized extensively to scale well on multi-core systems and has no issue saturating all available CPU resources on a fast connection. See the Performance section for benchmarking results.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlWNAAXGD0R3siJSz7fCP2qg8vftAwVdsK9kWjpzCvoH_-Gu4KY0GreG3Cj7RXwGcMllZr5lkQaFLWP8QIlztytNtq0lVfAd97rOPShuH1bG8DHKPo8uUFi4DPYJRtOqfMAD-3dvi13zPLHioty-wF8pKYtCpYC9Wq7aefzEWahhcm0r7leJKrzvCd/s600/1.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcOpClKihsTt08fw72WaS7t0PEnkeYOe3idYlaAV8hU1nxspwSwMXb7E-hiQWSNsFK2gYoHo6lW2R9CY1g-itA4AXQmgq5m9He8e274vd6dC1vd8IBbUnrn-0Mw1iCoV4SO3qPUGjsXddlUYpnG2b8W0OByweq0l4NdBa4yXjxegPT6Cm50GoyppGF/s1035/2.png UsageFor the example below, it is assumed that Phantun Server listens for incoming Phantun Client connections at port 4567(the --localoption for server), and it forwards UDP packets to UDP server at 127.0.0.1:1234(the --remoteoption for server).

It is also assumed that Phantun Client listens for incoming UDP packets at 127.0.0.1:1234(the --localoption for client) and connects to Phantun Server at 10.0.0.1:4567(the --remoteoption for client).

Phantun creates TUN interface for both the Client and Server. For Client, Phantun assigns itself the IP address 192.168.200.2and fcc8::2by default. For Server, it assigns 192.168.201.2and fcc9::2by default. Therefore, your Kernel must have IPv4/IPv6 forwarding enabled and setup appropriate iptables/nftables rules for NAT between your physical NIC address and Phantun’s Tun interface address.

You may customize the name of Tun interface created by Phantun and the assigned addresses. Please run the executable with -hoptions to see how to change them.

Another way to help understand this network topology (please see the diagram above for an illustration of this topology):

Phantun Client is like a machine with private IP address (192.168.200.2/fcc8::2) behind a router. In order for it to reach the Internet, you will need to SNAT the private IP address before it’s traffic leaves the NIC.

Phantun Server is like a server with private IP address (192.168.201.2/fcc9::2) behind a router. In order to access it from the Internet, you need to DNATit’s listening port on the router and change the destination IP address to where the server is listening for incoming connections.

In those cases, the machine/iptables running Phantun acts as the “router” that allows Phantun to communicate with outside using it’s private IP addresses.

As of Phantun v0.4.1, IPv6 is fully supported for both TCP and UDP [...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Phantun : Transforms UDP Stream Into (Fake) TCP Streams That Can Go Through Layer 3 &Amp Phantun is a project that obfuscated UDP packets into TCP connections. It aims to achieve maximum performance with minimum processing and encapsulation…
sides. To specify an IPv6 address, use the following format: [::1]:1234with the command line options. Resolving AAAA record is also supported. Please run the program with -hto see detailed options on how to control the IPv6 behavior. Enable Kernel IP forwardingEdit /etc/sysctl.conf, add net.ipv4.ip_forward=1and run sudo sysctl -p /etc/sysctl.conf.IPv6 specific config net.ipv6.conf.all.forwarding=1will need to be set as well.

Back to TOC Add required firewall rulesClientClient simply need SNAT enabled on the physical interface to translate Phantun’s address into one that can be used on the physical network. This can be done simply with masquerade.

Note: change eth0to whatever actual physical interface name is

Back to TOC Using nftablestable inet nat {
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
iifname tun0 oif eth0 masquerade
}
}

Note: The above rule uses inetas the table family type, so it is compatible with both IPv4 and IPv6 usage.

Back to TOC Using iptablesiptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
ip6tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE ServerServer needs to DNAT the TCP listening port to Phantun’s TUN interface address.

Note: change eth0to whatever actual physical interface name is and 4567to actual TCP port number used by Phantun server

Back to TOC Using nftablestable inet nat {
chain prerouting {
type nat hook prerouting priority dstnat; policy accept;
iif eth0 tcp dport 4567 dnat ip to 192.168.201.2
iif eth0 tcp dport 4567 dnat ip6 to fcc9::2
}
} Using iptablesiptables -t nat -A PREROUTING -p tcp -i eth0 –dport 4567 -j DNAT –to-destination 192.168.201.2
ip6tables -t nat -A PREROUTING -p tcp -i eth0 –dport 4567 -j DNAT –to-destination fcc9::2 Run Phantun binaries as non-root (Optional)It is ill-advised to run network facing applications as root user. Phantun can be run fully as non-root user with the cap_net_admincapability.

sudo setcap cap_net_admin=+pe phantun_server
sudo setcap cap_net_admin=+pe phantun_client Start Phantun daemonNote: Run Phantun executable with -hoption to see full detailed options.

Back to TOC ServerNote: 4567is the TCP port Phantun should listen on and must corresponds to the DNAT rule specified above. 127.0.0.1:1234is the UDP Server to connect to for new connections.

RUST_LOG=info /usr/local/bin/phantun_server –local 4567 –remote 127.0.0.1:1234

Or use host name with --remote:

RUST_LOG=info /usr/local/bin/phantun_server –local 4567 –remote example.com:1234

Note: Server by default assigns both IPv4 and IPv6 private address to the Tun interface. If you do not wish to use IPv6, you can simply skip creating the IPv6 DNAT rule above and the presence of IPv6 address on the Tun interface should have no side effect to the server.

Back to TOC ClientNote: 127.0.0.1:1234is the UDP address and port Phantun should listen on. 10.0.0.1:4567is the Phantun Server to connect.

RUST_LOG=info /usr/local/bin/phantun_client –local 127.0.0.1:1234 –remote 10.0.0.1:4567

Or use host name with --remote:

RUST_LOG=info /usr/local/bin/phantun_client –local 127.0.0.1:1234 –remote example.com:4567 MTU overheadPhantun aims to keep tunneling overhead to the minimum. The overhead compared to a plain UDP packet is the following (using IPv4 below as an example):

Standard UDP packet: 20 byte IP header + 8 byte UDP header = 28 bytesObfuscated packet: 20 byte IP header + 20 byte TCP header = 40 bytesNote that Phantun does not add any additional header other than IP and TCP headers in order to pass through stateful packet inspection!

Phantun’s additional overhead: 12 bytes. I other words, when using Ph[...]

___________________________
@hacking_Attack
@Hacking_Video