Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Phantun : Transforms UDP Stream Into (Fake) TCP Streams That Can Go Through Layer 3 &Amp
Phantun is a project that obfuscated UDP packets into TCP connections. It aims to achieve maximum performance with minimum processing and encapsulation overhead.
It is commonly used in environments where UDP is blocked/throttled but TCP is allowed through.
Phantun simply converts a stream of UDP packets into obfuscated TCP stream packets. The TCP stack used by Phantun is designed to pass through most L3/L4 stateful/stateless firewalls/NAT devices. It will not be able to pass through L7 proxies. However, the advantage of this approach is that none of the common UDP over TCP performance killer such as retransmissions and flow control will occur. The underlying UDP properties such as out-of-order delivery are fully preserved even if the connection ends up looking like a TCP connection from the perspective of firewalls/NAT devices.
Phantun means Phantom TUN, as it is an obfuscator for UDP traffic that does just enough work to make it pass through stateful firewall/NATs as TCP packets.
Phantun is written in 100% safe Rust. It has been optimized extensively to scale well on multi-core systems and has no issue saturating all available CPU resources on a fast connection. See the Performance section for benchmarking results.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlWNAAXGD0R3siJSz7fCP2qg8vftAwVdsK9kWjpzCvoH_-Gu4KY0GreG3Cj7RXwGcMllZr5lkQaFLWP8QIlztytNtq0lVfAd97rOPShuH1bG8DHKPo8uUFi4DPYJRtOqfMAD-3dvi13zPLHioty-wF8pKYtCpYC9Wq7aefzEWahhcm0r7leJKrzvCd/s600/1.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcOpClKihsTt08fw72WaS7t0PEnkeYOe3idYlaAV8hU1nxspwSwMXb7E-hiQWSNsFK2gYoHo6lW2R9CY1g-itA4AXQmgq5m9He8e274vd6dC1vd8IBbUnrn-0Mw1iCoV4SO3qPUGjsXddlUYpnG2b8W0OByweq0l4NdBa4yXjxegPT6Cm50GoyppGF/s1035/2.png UsageFor the example below, it is assumed that Phantun Server listens for incoming Phantun Client connections at port
It is also assumed that Phantun Client listens for incoming UDP packets at
Phantun creates TUN interface for both the Client and Server. For Client, Phantun assigns itself the IP address
You may customize the name of Tun interface created by Phantun and the assigned addresses. Please run the executable with
Another way to help understand this network topology (please see the diagram above for an illustration of this topology):
Phantun Client is like a machine with private IP address (
Phantun Server is like a server with private IP address (
In those cases, the machine/iptables running Phantun acts as the “router” that allows Phantun to communicate with outside using it’s private IP addresses.
As of Phantun v0.4.1, IPv6 is fully supported for both TCP and UDP [...]
___________________________
@hacking_Attack
@Hacking_Video
Phantun : Transforms UDP Stream Into (Fake) TCP Streams That Can Go Through Layer 3 &Amp
Phantun is a project that obfuscated UDP packets into TCP connections. It aims to achieve maximum performance with minimum processing and encapsulation overhead.
It is commonly used in environments where UDP is blocked/throttled but TCP is allowed through.
Phantun simply converts a stream of UDP packets into obfuscated TCP stream packets. The TCP stack used by Phantun is designed to pass through most L3/L4 stateful/stateless firewalls/NAT devices. It will not be able to pass through L7 proxies. However, the advantage of this approach is that none of the common UDP over TCP performance killer such as retransmissions and flow control will occur. The underlying UDP properties such as out-of-order delivery are fully preserved even if the connection ends up looking like a TCP connection from the perspective of firewalls/NAT devices.
Phantun means Phantom TUN, as it is an obfuscator for UDP traffic that does just enough work to make it pass through stateful firewall/NATs as TCP packets.
Phantun is written in 100% safe Rust. It has been optimized extensively to scale well on multi-core systems and has no issue saturating all available CPU resources on a fast connection. See the Performance section for benchmarking results.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlWNAAXGD0R3siJSz7fCP2qg8vftAwVdsK9kWjpzCvoH_-Gu4KY0GreG3Cj7RXwGcMllZr5lkQaFLWP8QIlztytNtq0lVfAd97rOPShuH1bG8DHKPo8uUFi4DPYJRtOqfMAD-3dvi13zPLHioty-wF8pKYtCpYC9Wq7aefzEWahhcm0r7leJKrzvCd/s600/1.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcOpClKihsTt08fw72WaS7t0PEnkeYOe3idYlaAV8hU1nxspwSwMXb7E-hiQWSNsFK2gYoHo6lW2R9CY1g-itA4AXQmgq5m9He8e274vd6dC1vd8IBbUnrn-0Mw1iCoV4SO3qPUGjsXddlUYpnG2b8W0OByweq0l4NdBa4yXjxegPT6Cm50GoyppGF/s1035/2.png UsageFor the example below, it is assumed that Phantun Server listens for incoming Phantun Client connections at port
4567(the --localoption for server), and it forwards UDP packets to UDP server at 127.0.0.1:1234(the --remoteoption for server).It is also assumed that Phantun Client listens for incoming UDP packets at
127.0.0.1:1234(the --localoption for client) and connects to Phantun Server at 10.0.0.1:4567(the --remoteoption for client).Phantun creates TUN interface for both the Client and Server. For Client, Phantun assigns itself the IP address
192.168.200.2and fcc8::2by default. For Server, it assigns 192.168.201.2and fcc9::2by default. Therefore, your Kernel must have IPv4/IPv6 forwarding enabled and setup appropriate iptables/nftables rules for NAT between your physical NIC address and Phantun’s Tun interface address.You may customize the name of Tun interface created by Phantun and the assigned addresses. Please run the executable with
-hoptions to see how to change them.Another way to help understand this network topology (please see the diagram above for an illustration of this topology):
Phantun Client is like a machine with private IP address (
192.168.200.2/fcc8::2) behind a router. In order for it to reach the Internet, you will need to SNAT the private IP address before it’s traffic leaves the NIC.Phantun Server is like a server with private IP address (
192.168.201.2/fcc9::2) behind a router. In order to access it from the Internet, you need to DNATit’s listening port on the router and change the destination IP address to where the server is listening for incoming connections.In those cases, the machine/iptables running Phantun acts as the “router” that allows Phantun to communicate with outside using it’s private IP addresses.
As of Phantun v0.4.1, IPv6 is fully supported for both TCP and UDP [...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Phantun : Transforms UDP Stream Into (Fake) TCP Streams
Phantun is a project that obfuscated UDP packets into TCP connections. It aims to achieve maximum performance with minimum processing.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Phantun : Transforms UDP Stream Into (Fake) TCP Streams That Can Go Through Layer 3 &Amp Phantun is a project that obfuscated UDP packets into TCP connections. It aims to achieve maximum performance with minimum processing and encapsulation…
sides. To specify an IPv6 address, use the following format:
Back to TOC Add required firewall rulesClientClient simply need SNAT enabled on the physical interface to translate Phantun’s address into one that can be used on the physical network. This can be done simply with masquerade.
Note: change
Back to TOC Using nftablestable inet nat {
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
iifname tun0 oif eth0 masquerade
}
}
Note: The above rule uses
Back to TOC Using iptablesiptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
ip6tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE ServerServer needs to DNAT the TCP listening port to Phantun’s TUN interface address.
Note: change
Back to TOC Using nftablestable inet nat {
chain prerouting {
type nat hook prerouting priority dstnat; policy accept;
iif eth0 tcp dport 4567 dnat ip to 192.168.201.2
iif eth0 tcp dport 4567 dnat ip6 to fcc9::2
}
} Using iptablesiptables -t nat -A PREROUTING -p tcp -i eth0 –dport 4567 -j DNAT –to-destination 192.168.201.2
ip6tables -t nat -A PREROUTING -p tcp -i eth0 –dport 4567 -j DNAT –to-destination fcc9::2 Run Phantun binaries as non-root (Optional)It is ill-advised to run network facing applications as root user. Phantun can be run fully as non-root user with the
sudo setcap cap_net_admin=+pe phantun_server
sudo setcap cap_net_admin=+pe phantun_client Start Phantun daemonNote: Run Phantun executable with
Back to TOC ServerNote:
RUST_LOG=info /usr/local/bin/phantun_server –local 4567 –remote 127.0.0.1:1234
Or use host name with
RUST_LOG=info /usr/local/bin/phantun_server –local 4567 –remote example.com:1234
Note: Server by default assigns both IPv4 and IPv6 private address to the Tun interface. If you do not wish to use IPv6, you can simply skip creating the IPv6 DNAT rule above and the presence of IPv6 address on the Tun interface should have no side effect to the server.
Back to TOC ClientNote:
RUST_LOG=info /usr/local/bin/phantun_client –local 127.0.0.1:1234 –remote 10.0.0.1:4567
Or use host name with
RUST_LOG=info /usr/local/bin/phantun_client –local 127.0.0.1:1234 –remote example.com:4567 MTU overheadPhantun aims to keep tunneling overhead to the minimum. The overhead compared to a plain UDP packet is the following (using IPv4 below as an example):
Standard UDP packet:
Phantun’s additional overhead:
___________________________
@hacking_Attack
@Hacking_Video
[::1]:1234with the command line options. Resolving AAAA record is also supported. Please run the program with -hto see detailed options on how to control the IPv6 behavior. Enable Kernel IP forwardingEdit /etc/sysctl.conf, add net.ipv4.ip_forward=1and run sudo sysctl -p /etc/sysctl.conf.IPv6 specific config net.ipv6.conf.all.forwarding=1will need to be set as well.Back to TOC Add required firewall rulesClientClient simply need SNAT enabled on the physical interface to translate Phantun’s address into one that can be used on the physical network. This can be done simply with masquerade.
Note: change
eth0to whatever actual physical interface name isBack to TOC Using nftablestable inet nat {
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
iifname tun0 oif eth0 masquerade
}
}
Note: The above rule uses
inetas the table family type, so it is compatible with both IPv4 and IPv6 usage.Back to TOC Using iptablesiptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
ip6tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE ServerServer needs to DNAT the TCP listening port to Phantun’s TUN interface address.
Note: change
eth0to whatever actual physical interface name is and 4567to actual TCP port number used by Phantun serverBack to TOC Using nftablestable inet nat {
chain prerouting {
type nat hook prerouting priority dstnat; policy accept;
iif eth0 tcp dport 4567 dnat ip to 192.168.201.2
iif eth0 tcp dport 4567 dnat ip6 to fcc9::2
}
} Using iptablesiptables -t nat -A PREROUTING -p tcp -i eth0 –dport 4567 -j DNAT –to-destination 192.168.201.2
ip6tables -t nat -A PREROUTING -p tcp -i eth0 –dport 4567 -j DNAT –to-destination fcc9::2 Run Phantun binaries as non-root (Optional)It is ill-advised to run network facing applications as root user. Phantun can be run fully as non-root user with the
cap_net_admincapability.sudo setcap cap_net_admin=+pe phantun_server
sudo setcap cap_net_admin=+pe phantun_client Start Phantun daemonNote: Run Phantun executable with
-hoption to see full detailed options.Back to TOC ServerNote:
4567is the TCP port Phantun should listen on and must corresponds to the DNAT rule specified above. 127.0.0.1:1234is the UDP Server to connect to for new connections.RUST_LOG=info /usr/local/bin/phantun_server –local 4567 –remote 127.0.0.1:1234
Or use host name with
--remote:RUST_LOG=info /usr/local/bin/phantun_server –local 4567 –remote example.com:1234
Note: Server by default assigns both IPv4 and IPv6 private address to the Tun interface. If you do not wish to use IPv6, you can simply skip creating the IPv6 DNAT rule above and the presence of IPv6 address on the Tun interface should have no side effect to the server.
Back to TOC ClientNote:
127.0.0.1:1234is the UDP address and port Phantun should listen on. 10.0.0.1:4567is the Phantun Server to connect.RUST_LOG=info /usr/local/bin/phantun_client –local 127.0.0.1:1234 –remote 10.0.0.1:4567
Or use host name with
--remote:RUST_LOG=info /usr/local/bin/phantun_client –local 127.0.0.1:1234 –remote example.com:4567 MTU overheadPhantun aims to keep tunneling overhead to the minimum. The overhead compared to a plain UDP packet is the following (using IPv4 below as an example):
Standard UDP packet:
20 byte IP header + 8 byte UDP header = 28 bytesObfuscated packet: 20 byte IP header + 20 byte TCP header = 40 bytesNote that Phantun does not add any additional header other than IP and TCP headers in order to pass through stateful packet inspection!Phantun’s additional overhead:
12 bytes. I other words, when using Ph[...]___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CobaltBus : Cobalt Strike External C2 Integration With Azure Servicebus, C2 Traffic Via Azure Servicebus
CobaltBus is a Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDbEZgNT49Ik_NL885CtcocoA5kBYpgfG0sLt1OcTfO51qfVLT096tNV9kpchzvXtnlVuWZ0VEDyCSYxu4ieMeXc8RWqNVSKU4e_XeVW5d07wQX9rrIVJ12OwG-HYOcM9zWI2eDg6aorU0PrzE3y7K8_zag_kV_atjgjQZhtfclW8jiOvZXf4lhC08/s4399/1.png
Setup
* Create an Azure Service Bus
* Create a Shared access policy (Connection string) that can only Send and Listen
* Edit the static connectionString variable in Beacon C# projects to match the “Primary Connection String” value for the Shared access policy created in step 2.
* The same variables need to be updated for the CobaltBus project, but the “Primary Connection String” for the “RootManageSharedAccessKey” Shared access policy must be used. (Needs the “manage” permission)
* Setup Cobalt and start en External C2 listener on port 4444, 127.0.0.1 (can be changed by editing the ExternalC2Port ExternalC2Ip vars in the C# project)
How does it work?
Then CobaltBus DotNetCore binary that integrates with CobaltStrikes ExternalC2, will create a local SqliteDB in order to keep track of multiple beacons. The messages inbound to CobaltBus will be captured and written to the database. The database names “CobaltBus.db” and “CobaltBus-log.db” will be created in the directory CobaltBus.dll is running from. Once a Beacon binary runs, it will push an “INITIALIZE” message to the baseQueueName queue, with a randomly generated BeaconId and Pipename. The CobaltBus handler will then capture this, create and move into the two new queues based on the BeaconId sent, request stager shellcode from the CobaltStrike, and push it back down the new queue as an “INJECT” message. From here, the Beacon project injects the captured shellcode into memory and establishes a connection with the CobaltStrike beacon over the generated pipe name. When a command is issued from CobaltBus, it is pushed down the beacon respective queue and into the beacon pipe name.
Download
___________________________
@hacking_Attack
@Hacking_Video
CobaltBus : Cobalt Strike External C2 Integration With Azure Servicebus, C2 Traffic Via Azure Servicebus
CobaltBus is a Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDbEZgNT49Ik_NL885CtcocoA5kBYpgfG0sLt1OcTfO51qfVLT096tNV9kpchzvXtnlVuWZ0VEDyCSYxu4ieMeXc8RWqNVSKU4e_XeVW5d07wQX9rrIVJ12OwG-HYOcM9zWI2eDg6aorU0PrzE3y7K8_zag_kV_atjgjQZhtfclW8jiOvZXf4lhC08/s4399/1.png
Setup
* Create an Azure Service Bus
* Create a Shared access policy (Connection string) that can only Send and Listen
* Edit the static connectionString variable in Beacon C# projects to match the “Primary Connection String” value for the Shared access policy created in step 2.
* The same variables need to be updated for the CobaltBus project, but the “Primary Connection String” for the “RootManageSharedAccessKey” Shared access policy must be used. (Needs the “manage” permission)
* Setup Cobalt and start en External C2 listener on port 4444, 127.0.0.1 (can be changed by editing the ExternalC2Port ExternalC2Ip vars in the C# project)
How does it work?
Then CobaltBus DotNetCore binary that integrates with CobaltStrikes ExternalC2, will create a local SqliteDB in order to keep track of multiple beacons. The messages inbound to CobaltBus will be captured and written to the database. The database names “CobaltBus.db” and “CobaltBus-log.db” will be created in the directory CobaltBus.dll is running from. Once a Beacon binary runs, it will push an “INITIALIZE” message to the baseQueueName queue, with a randomly generated BeaconId and Pipename. The CobaltBus handler will then capture this, create and move into the two new queues based on the BeaconId sent, request stager shellcode from the CobaltStrike, and push it back down the new queue as an “INJECT” message. From here, the Beacon project injects the captured shellcode into memory and establishes a connection with the CobaltStrike beacon over the generated pipe name. When a command is issued from CobaltBus, it is pushed down the beacon respective queue and into the beacon pipe name.
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
CobaltBus : Cobalt Strike External C2 Integration With Azure Servicebus
CobaltBus is a Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus.
Hacking Articles Tips Tricks Videos Tutorials
sides. To specify an IPv6 address, use the following format: [::1]:1234with the command line options. Resolving AAAA record is also supported. Please run the program with -hto see detailed options on how to control the IPv6 behavior. Enable Kernel IP forwardingEdit…
antun, the usable payload for UDP packet is reduced by 12 bytes. This is the minimum overhead possible when doing such kind of obfuscation. MTU calculation for WireGuardFor people who use Phantun to tunnel WireGuard® UDP packets, here are some guidelines on figuring out the correct MTU to use for your WireGuard interface.
WireGuard MTU = Interface MTU – IPv4 header (20 bytes) – TCP header (20 bytes) – WireGuard overhead (32 bytes)
or
WireGuard MTU = Interface MTU – IPv6 header (40 bytes) – TCP header (20 bytes) – WireGuard overhead (32 bytes)
For example, for a Ethernet interface with 1500 bytes MTU, the WireGuard interface MTU should be set as:
IPv4:
Phantun
Test command: iperf3 -c ModeSend SpeedReceive SpeedOverall CPU UsageDirect (1 stream)3.00 Gbits/sec2.37 Gbits/sec25% (1 core at 100%)Phantun (1 stream)1.30 Gbits/sec1.20 Gbits/sec60% (1 core at 100%, 3 cores at 50%)udp2raw (
Here is a quick overview of comparison between those two to help you choose:
Phantunudp2rawUDP over FakeTCP obfuscationhttps://s.w.org/images/core/emoji/13.1.0/72x72/2705.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png UDP over ICMP obfuscationhttps://s.w.org/images/core/emoji/13.1.0/72x72/274c.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png UDP over UDP obfuscationhttps://s.w.org/images/core/emoji/13.1.0/72x72/274c.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png Multi-threadedhttps://s.w.org/images/core/emoji/13.1.0/72x72/2705.png https://s.w.org/images/core/emoji/13.1.0/72x72/274c.png ThroughputBetterGoodLayer 3 modeTUN interfaceRaw sockets + BPFTunneling MTU overhead12 bytes44 bytesSeprate TCP connections for each UDP connectionClient/ServerServer onl[...]
___________________________
@hacking_Attack
@Hacking_Video
WireGuard MTU = Interface MTU – IPv4 header (20 bytes) – TCP header (20 bytes) – WireGuard overhead (32 bytes)
or
WireGuard MTU = Interface MTU – IPv6 header (40 bytes) – TCP header (20 bytes) – WireGuard overhead (32 bytes)
For example, for a Ethernet interface with 1500 bytes MTU, the WireGuard interface MTU should be set as:
IPv4:
1500 - 20 - 20 - 32 = 1428 bytesIPv6: 1500 - 40 - 20 - 32 = 1408 bytesThe resulted Phantun TCP data packet will be 1500 bytes which does not exceed the interface MTU of 1500. Please note it is strongly recommended to use the same interface MTU for both ends of a WireGuard tunnel, or unexpected packet loss may occur and these issues are generally very hard to troubleshoot. Version compatibilityWhile the TCP stack is fairly stable, the general expectation is that you should run same minor versions of Server/Client of Phantun on both ends to ensure maximum compatibility. PerformancePerformance was tested on 2 AWS t4g.xlargeinstances with 4 vCPUs and 5 Gb/s NIC over LAN. nftableswas used to redirect UDP stream of iperf3to go through the Phantun/udp2raw tunnel between two test instances and MTU has been tuned to avoid fragmentation.Phantun
v0.3.2and udp2raw_arm_asm_aes20200818.0was used. These were the latest release of both projects as of Apr 2022.Test command: iperf3 -c ModeSend SpeedReceive SpeedOverall CPU UsageDirect (1 stream)3.00 Gbits/sec2.37 Gbits/sec25% (1 core at 100%)Phantun (1 stream)1.30 Gbits/sec1.20 Gbits/sec60% (1 core at 100%, 3 cores at 50%)udp2raw (
cipher-mode=none auth-mode=nonedisable-anti-replay) (1 stream)1.30 Gbits/sec715 Mbits/sec40% (1 core at 100%, 1 core at 50%, 2 cores idling)Direct connection (5 streams)5.00 Gbits/sec3.64 Gbits/sec25% (1 core at 100%)Phantun (5 streams)5.00 Gbits/sec2.38 Gbits/sec95% (all cores utilized)udp2raw (cipher-mode=none auth-mode=nonedisable-anti-replay) (5 streams)5.00 Gbits/sec770 Mbits/sec50% (2 cores at 100%) Compariation to udp2rawudp2raw is another popular project by @wangyu- that is very similar to what Phantun can do. In fact I took inspirations of Phantun from udp2raw. The biggest reason for developing Phantun is because of lack of performance when running udp2raw (especially on multi-core systems such as Raspberry Pi). However, the goal is never to be as feature complete as udp2raw and only support the most common use cases. Most notably, UDP over ICMP and UDP over UDP mode are not supported and there is no anti-replay nor encryption support. The benefit of this is much better performance overall and less MTU overhead because lack of additional headers inside the TCP payload.Here is a quick overview of comparison between those two to help you choose:
Phantunudp2rawUDP over FakeTCP obfuscationhttps://s.w.org/images/core/emoji/13.1.0/72x72/2705.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png UDP over ICMP obfuscationhttps://s.w.org/images/core/emoji/13.1.0/72x72/274c.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png UDP over UDP obfuscationhttps://s.w.org/images/core/emoji/13.1.0/72x72/274c.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png Multi-threadedhttps://s.w.org/images/core/emoji/13.1.0/72x72/2705.png https://s.w.org/images/core/emoji/13.1.0/72x72/274c.png ThroughputBetterGoodLayer 3 modeTUN interfaceRaw sockets + BPFTunneling MTU overhead12 bytes44 bytesSeprate TCP connections for each UDP connectionClient/ServerServer onl[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Live-Forensicator : Powershell Script To Aid Incidence Response And Live Forensics
Live Forensicator is part of the Black Widow Toolbox, its aim is to assist Forensic Investigators and Incidence responders in carrying out a quick live forensic investigation.
It achieves this by gathering different system information for further review for anomalous behaviour or unexpected data entry, it also looks out for unusual files or activities and points it out to the investigator.
It is paramount to note that this script has no inbuilt intelligence its left for the investigator to analyse the output and decide on a conclusion or decide on carrying out more deeper investigation. Optional DependenciesThis script is written in powershell for use on windows PCs and Servers.
For additional features it depends on external binaries.
It has a supporting file WINPMEM for taking RAM dumps https://github.com/Velocidex/WinPmem
It also depends on Nirsoft’s BrowserHistoryView for exporting browser history http://www.nirsoft.net/utils/browsing_history_view.html
This script is expected to work out of the box.
winpmem_mini_x64_rc2.exe | BrowsingHistoryView64.exe | BrowsingHistoryView86.exe | etl2pcapng64.exe | etl2pcapng86.exe Usagecopy the files to the computer
git clone https://github.com/Johnng007/Live-Forensicator.git
Execution
.\Forensicator.ps1 ExamplesBasic
.\Forensicator.ps1
Check your Version
.\Forensicator.ps1 -Version
Check for Updates
.\Forensicator.ps1 -Update
Decrypt An Encrypted Artifact
.\Forensicator.ps1 -DECRYPT DECRYPT
Extract Event Logs alongside Basic Usage
.\Forensicator.ps1 -EVTX EVTX
Grab weblogs IIS & Apache
.\Forensicator.ps1 -WEBLOGS WEBLOGS
Run Network Tracing & Capture PCAPNG for 120 secounds
.\Forensicator.ps1 -PCAP PCAP
Extract RAM Dump alongside Basic Usage
.\Forensicator.ps1 -RAM RAM
Check for log4j with the JNDILookup.class
.\Forensicator.ps1 -log4j log4j
Encrypt Artifact after collecting it
.\Forensicator.ps1 -ENCRYPTED ENCRYPTED
Yes of course you can do all
.\Forensicator.ps1 -EVTX EVTX -RAM RAM -log4j log4j -PCAP PCAP -WEBLOGS WEBLOGS
For Unattended Mode on Basic Usage
.\Forensicator.ps1 -OPERATOR “Ebuka John” -CASE 01123 -TITLE “Ransomeware Infected Laptop” -LOCATION Nigeria -DEVICE AZUZ
You can use unattended mode for each of the other parameters
.\Forensicator.ps1 -OPERATOR “Ebuka John” -CASE 01123 -TITLE “Ransomeware Infected Laptop” -LOCATION Nigeria -DEVICE AZUZ -EVTX EVTX -RAM RAM -log4j log4j
Check for files that has similar extensions with ransomeware encrypted files (can take some time to complete)
.\Forensicator.ps1 -RANSOMEWARE RANSOMEWARE
You can compress the Forensicator output immidiately after execution Oneliner
.\Forensicator.ps1 ; Start-Sleep -s 15 ; Compress-Archive -Path “$env:computername” -DestinationPath “C:\inetpub\wwwroot\$env:computername.zip” -Force NotesRun the script as an administrator to get value.
The results are outputed in nice looking html files with an index file.
You can find all extracted Artifacts in the script’s working directory.
Forensicator Has the ability to Search through all the folders within a system looking for files with similar extensions as well known Ransomewares, Albeit this search takes long but its helpful if the Alert you recieved is related to a Ransomeware attack, Use the -RANSOMEWARE Parameter to invoke this.
Forensictor now hs the ability to capture network traffic using netsh trace, this is useful when your investigation has to do with asset communicating with known malicious IPs, this way you can parse the pcapng file to wireshark and examine for C&C servers. By Defult i set the capture to take 120secs
Sometimes it may be paramount to maintain the integrity of the Artifacts, where lawyers may argue that it might have been compromised on transit to your lab. Forensicator can now encrypt the Artifact with a unique randome[...]
___________________________
@hacking_Attack
@Hacking_Video
Live-Forensicator : Powershell Script To Aid Incidence Response And Live Forensics
Live Forensicator is part of the Black Widow Toolbox, its aim is to assist Forensic Investigators and Incidence responders in carrying out a quick live forensic investigation.
It achieves this by gathering different system information for further review for anomalous behaviour or unexpected data entry, it also looks out for unusual files or activities and points it out to the investigator.
It is paramount to note that this script has no inbuilt intelligence its left for the investigator to analyse the output and decide on a conclusion or decide on carrying out more deeper investigation. Optional DependenciesThis script is written in powershell for use on windows PCs and Servers.
For additional features it depends on external binaries.
It has a supporting file WINPMEM for taking RAM dumps https://github.com/Velocidex/WinPmem
It also depends on Nirsoft’s BrowserHistoryView for exporting browser history http://www.nirsoft.net/utils/browsing_history_view.html
This script is expected to work out of the box.
winpmem_mini_x64_rc2.exe | BrowsingHistoryView64.exe | BrowsingHistoryView86.exe | etl2pcapng64.exe | etl2pcapng86.exe Usagecopy the files to the computer
git clone https://github.com/Johnng007/Live-Forensicator.git
Execution
.\Forensicator.ps1 ExamplesBasic
.\Forensicator.ps1
Check your Version
.\Forensicator.ps1 -Version
Check for Updates
.\Forensicator.ps1 -Update
Decrypt An Encrypted Artifact
.\Forensicator.ps1 -DECRYPT DECRYPT
Extract Event Logs alongside Basic Usage
.\Forensicator.ps1 -EVTX EVTX
Grab weblogs IIS & Apache
.\Forensicator.ps1 -WEBLOGS WEBLOGS
Run Network Tracing & Capture PCAPNG for 120 secounds
.\Forensicator.ps1 -PCAP PCAP
Extract RAM Dump alongside Basic Usage
.\Forensicator.ps1 -RAM RAM
Check for log4j with the JNDILookup.class
.\Forensicator.ps1 -log4j log4j
Encrypt Artifact after collecting it
.\Forensicator.ps1 -ENCRYPTED ENCRYPTED
Yes of course you can do all
.\Forensicator.ps1 -EVTX EVTX -RAM RAM -log4j log4j -PCAP PCAP -WEBLOGS WEBLOGS
For Unattended Mode on Basic Usage
.\Forensicator.ps1 -OPERATOR “Ebuka John” -CASE 01123 -TITLE “Ransomeware Infected Laptop” -LOCATION Nigeria -DEVICE AZUZ
You can use unattended mode for each of the other parameters
.\Forensicator.ps1 -OPERATOR “Ebuka John” -CASE 01123 -TITLE “Ransomeware Infected Laptop” -LOCATION Nigeria -DEVICE AZUZ -EVTX EVTX -RAM RAM -log4j log4j
Check for files that has similar extensions with ransomeware encrypted files (can take some time to complete)
.\Forensicator.ps1 -RANSOMEWARE RANSOMEWARE
You can compress the Forensicator output immidiately after execution Oneliner
.\Forensicator.ps1 ; Start-Sleep -s 15 ; Compress-Archive -Path “$env:computername” -DestinationPath “C:\inetpub\wwwroot\$env:computername.zip” -Force NotesRun the script as an administrator to get value.
The results are outputed in nice looking html files with an index file.
You can find all extracted Artifacts in the script’s working directory.
Forensicator Has the ability to Search through all the folders within a system looking for files with similar extensions as well known Ransomewares, Albeit this search takes long but its helpful if the Alert you recieved is related to a Ransomeware attack, Use the -RANSOMEWARE Parameter to invoke this.
Forensictor now hs the ability to capture network traffic using netsh trace, this is useful when your investigation has to do with asset communicating with known malicious IPs, this way you can parse the pcapng file to wireshark and examine for C&C servers. By Defult i set the capture to take 120secs
Sometimes it may be paramount to maintain the integrity of the Artifacts, where lawyers may argue that it might have been compromised on transit to your lab. Forensicator can now encrypt the Artifact with a unique randome[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Live-Forensicator : Powershell Script To Aid Incidence Response
Live Forensicator is part of the Black Widow Toolbox, its aim is to assist Forensic Investigators and Incidence responders.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
FormatFuzzer : A Framework For High-Efficiency, High-Quality Generation And Parsing Of Binary Inputs
FormatFuzzer is a framework for high-efficiency, high-quality generation and parsing of binary inputs. It takes a binary template that describes the format of a binary input and generates an executable that produces and parses the given binary format. From a binary template for GIF, for instance,
Generators produced by
The binary templates used by FormatFuzzer come from the 010 editor. There are more than 170 binary templates, which either can be used directly for
Contributors are welcome! Visit the FormatFuzzer project page for filing ideas and issues, or adding pull requests. For details on how
FormatFuzzer is available from the FormatFuzzer project page. You can download and unpack the latest release from the releases page.
For the very latest and greatest, you can also clone its git repository:
git clone https://github.com/uds-se/FormatFuzzer.git
All further actions take place in its main folder:
cd FormatFuzzer
Prerequisites
To run FormatFuzzer, you need the following:
* Python 3
* A C++ compiler with GNU libraries (notably
* A
If you plan to edit the build and configuration scripts (
* GNU autoconf
* GNU automake Installing Requirements on Linux (Debian Packages)
sudo apt install git g++ make automake python3-pip zlib1g-dev libboost1.71-dev
pip3 install py010parser six intervaltree
Installing Requirements on MacOS (with Xcode & Homebrew)
xcode-select –install
brew install python3 automake boost
pip3 install py010parser six intervaltree
Installing Python Packages Only (All Operating Systems)
On all systems, using
pip install py010parser
pip install six
pip install intervaltree
Building
Note: all building commands require you to be in the same folder as this
There’s a
./build.sh gif
to create a GIF fuzzer.
This works for all file formats provided in
There’s a
touch configure Makefile.in
then
./configure
and then
make gif-fuzzer
to create a GIF fuzzer.
This works for all file formats[...]
___________________________
@hacking_Attack
@Hacking_Video
FormatFuzzer : A Framework For High-Efficiency, High-Quality Generation And Parsing Of Binary Inputs
FormatFuzzer is a framework for high-efficiency, high-quality generation and parsing of binary inputs. It takes a binary template that describes the format of a binary input and generates an executable that produces and parses the given binary format. From a binary template for GIF, for instance,
FormatFuzzerproduces a GIF generator – also known as GIF fuzzer.Generators produced by
FormatFuzzerare highly efficient, producing thousands of valid test inputs per second – in sharp contrast to mutation-based fuzzers, where the large majority of inputs is invalid. Inputs generated by FormatFuzzerare independent from the program under test (or actually, any program), so you can also use them in black-box settings. However, FormatFuzzeralso integrates with AFL++ to produce valid inputs that also aim for maximum coverage. In our experiments, this “best of two worlds” approach surpasses all other settings; see our paper for details.The binary templates used by FormatFuzzer come from the 010 editor. There are more than 170 binary templates, which either can be used directly for
FormatFuzzeror adapted for its use. Out of the box, FormatFuzzerproduces formats such as AVI, BMP, GIF, JPG, MIDI, MP3, MP4, PCAP, PNG, WAV, and ZIP; and we keep on extending this list every week.Contributors are welcome! Visit the FormatFuzzer project page for filing ideas and issues, or adding pull requests. For details on how
FormatFuzzerworks and how it compares, read our paper for more info. GettingFormatFuzzer is available from the FormatFuzzer project page. You can download and unpack the latest release from the releases page.
For the very latest and greatest, you can also clone its git repository:
git clone https://github.com/uds-se/FormatFuzzer.git
All further actions take place in its main folder:
cd FormatFuzzer
Prerequisites
To run FormatFuzzer, you need the following:
* Python 3
* A C++ compiler with GNU libraries (notably
getopt_long()) such as clangor gcc* The Python packages py010parser, six, and intervaltree* A zliblibrary (for compression functions)* A
boostlibrary (for checksum functions)If you plan to edit the build and configuration scripts (
.ac and .amfiles), you will also need* GNU autoconf
* GNU automake Installing Requirements on Linux (Debian Packages)
sudo apt install git g++ make automake python3-pip zlib1g-dev libboost1.71-dev
pip3 install py010parser six intervaltree
Installing Requirements on MacOS (with Xcode & Homebrew)
xcode-select –install
brew install python3 automake boost
pip3 install py010parser six intervaltree
Installing Python Packages Only (All Operating Systems)
On all systems, using
pip:pip install py010parser
pip install six
pip install intervaltree
Building
Note: all building commands require you to be in the same folder as this
READMEfile. Building a fuzzer outside of this folder is not yet supported. Method 1: Using the build.sh scriptThere’s a
build.shscript which automates all construction steps. Simply run./build.sh gif
to create a GIF fuzzer.
This works for all file formats provided in
templates/; if there is a file templates/FOO.bt, then ./build.sh FOOwill build a fuzzer. Method 2: Using MakeThere’s a
Makefile(source in Makefile.am) which automates all construction steps. (Requires GNU make.) First dotouch configure Makefile.in
then
./configure
and then
make gif-fuzzer
to create a GIF fuzzer.
This works for all file formats[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
FormatFuzzer : A Framework For High-Efficiency, High-Quality Generation
FormatFuzzer is a framework for high-efficiency, high-quality generation and parsing of binary inputs. It takes a binary template.
Hacking Articles Tips Tricks Videos Tutorials
antun, the usable payload for UDP packet is reduced by 12 bytes. This is the minimum overhead possible when doing such kind of obfuscation. MTU calculation for WireGuardFor people who use Phantun to tunnel WireGuard® UDP packets, here are some guidelines on…
yAnti-replay, encryptionhttps://s.w.org/images/core/emoji/13.1.0/72x72/274c.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png IPv6https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png https://s.w.org/images/core/emoji/13.1.0/72x72/2705.png Download
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Live-Forensicator : Powershell Script To Aid Incidence Response And Live Forensics Live Forensicator is part of the Black Widow Toolbox, its aim is to assist Forensic Investigators and Incidence responders in carrying out a quick live…
ly generated key using AES algorithm, you can specify this by using the -ENCRYPTED parameter. You can decrypt it at will anywhere anytime even with another copy of Forensicator, just keep your key safe. This task is performed by the FileCryptography.psm1 file What Forensicator GrabsUSER AND ACCOUNT INFORMATION
1. GETS CURRENT USER.
2. SYSTEM DETAILS.
3. USER ACCOUNTS
4. LOGON SESSIONS
5. USER PROFILES
6. ADMINISTRATOR ACCOUNTS
7. LOCAL GROUPS
SYSTEM INFORMATION
1. INSTALLED PROGRAMS.
2. INSTALLED PROGRAMS FROM REGISTERY.
3. ENVIRONMENT VARIABLES
4. SYSTEM INFORMATION
5. OPERATING SYSTEM INFORMATION
6. HOTFIXES
8. WINDOWS DEFENDER STATUS AND DETAILS
NETWORK INFORMATION
1. NETWORK ADAPTER INFORMATION.
2. CURRENT IP CONFIGURATION IPV6 IPV4.
3. CURRENT CONNECTION PROFILES.
4. ASSOCIATED WIFI NETWORKS AND PASSWORDS.
5. ARP CACHES
6. CURRENT TCP CONNECTIONS AND ASSOCIATED PROCESSES
7. DNS CACHE
8. CURRENT FIREWALL RULES
9. ACTIVE SMB SESSIONS (IF ITS A SERVER)
10. ACTIVE SMB SHARES
11. IP ROUTES TO NON LOCAL DESTINATIONS
12. NETWORK ADAPTERS WITH IP ROUTES TO NON LOCAL DESTINATIONS
13. IP ROUTES WITH INFINITE VALID LIFETIME
PROCESSES | SCHEDULED TASK | REGISTRY
1. PROCESSES.
2. STARTUP PROGRAMS
3. SCHEDULED TASK
4. SCHEDULED TASKS AND STATE
5. SERVICES
6. PERSISTANCE IN REGISTRY
OTHER CHECKS
1. LOGICAL DRIVES
2. CONNECTED AND DISCONNECTED WEBCAMS
3. USB DEVICES
4. UPNP DEVICES
5. ALL PREVIOUSLY CONNECTED DRIVES
6. ALL FILES CREATED IN THE LAST 180 DAYS
7. 100 DAYS WORTH OF POWERSHELL HISTORY
8. EXECUTABLES IN DOWNLOADS FOLDER
9. EXECUTABLES IN APPDATA
10. EXECUATBLES IN TEMP
11. EXECUTABLES IN PERFLOGS
12. EXECUTABLES IN THE DOCUMENTS FOLDER
ORTHER REPORTS IN THE HTML INDEX FILE
1. GROUP POLICY REPORT
2. WINPMEM RAM CAPTURE
3. LOG4J
4. IIS LOGS
5. TOMCAT LOGS
6. BROWSING HISTORY OF ALL USERS
7. CHECK FOR FILES THAT HAS SIMILAR EXTENSIONS WITH KNOWN RANSOMEWARE ENCRYPTED FILES
NOTE: THIS CHECK CAN TAKE SOME TIME TO COMPLETE DEPENDING ON THE NUMBER OF DRIVES AND AMOUNT OF FILES.
8. RUNS NETWORK TRACING USING NETSH TRACE & CONVERTS TO PCAPNG FOR FURTHER ANALYSIS Download
___________________________
@hacking_Attack
@Hacking_Video
1. GETS CURRENT USER.
2. SYSTEM DETAILS.
3. USER ACCOUNTS
4. LOGON SESSIONS
5. USER PROFILES
6. ADMINISTRATOR ACCOUNTS
7. LOCAL GROUPS
SYSTEM INFORMATION
1. INSTALLED PROGRAMS.
2. INSTALLED PROGRAMS FROM REGISTERY.
3. ENVIRONMENT VARIABLES
4. SYSTEM INFORMATION
5. OPERATING SYSTEM INFORMATION
6. HOTFIXES
8. WINDOWS DEFENDER STATUS AND DETAILS
NETWORK INFORMATION
1. NETWORK ADAPTER INFORMATION.
2. CURRENT IP CONFIGURATION IPV6 IPV4.
3. CURRENT CONNECTION PROFILES.
4. ASSOCIATED WIFI NETWORKS AND PASSWORDS.
5. ARP CACHES
6. CURRENT TCP CONNECTIONS AND ASSOCIATED PROCESSES
7. DNS CACHE
8. CURRENT FIREWALL RULES
9. ACTIVE SMB SESSIONS (IF ITS A SERVER)
10. ACTIVE SMB SHARES
11. IP ROUTES TO NON LOCAL DESTINATIONS
12. NETWORK ADAPTERS WITH IP ROUTES TO NON LOCAL DESTINATIONS
13. IP ROUTES WITH INFINITE VALID LIFETIME
PROCESSES | SCHEDULED TASK | REGISTRY
1. PROCESSES.
2. STARTUP PROGRAMS
3. SCHEDULED TASK
4. SCHEDULED TASKS AND STATE
5. SERVICES
6. PERSISTANCE IN REGISTRY
OTHER CHECKS
1. LOGICAL DRIVES
2. CONNECTED AND DISCONNECTED WEBCAMS
3. USB DEVICES
4. UPNP DEVICES
5. ALL PREVIOUSLY CONNECTED DRIVES
6. ALL FILES CREATED IN THE LAST 180 DAYS
7. 100 DAYS WORTH OF POWERSHELL HISTORY
8. EXECUTABLES IN DOWNLOADS FOLDER
9. EXECUTABLES IN APPDATA
10. EXECUATBLES IN TEMP
11. EXECUTABLES IN PERFLOGS
12. EXECUTABLES IN THE DOCUMENTS FOLDER
ORTHER REPORTS IN THE HTML INDEX FILE
1. GROUP POLICY REPORT
2. WINPMEM RAM CAPTURE
3. LOG4J
4. IIS LOGS
5. TOMCAT LOGS
6. BROWSING HISTORY OF ALL USERS
7. CHECK FOR FILES THAT HAS SIMILAR EXTENSIONS WITH KNOWN RANSOMEWARE ENCRYPTED FILES
NOTE: THIS CHECK CAN TAKE SOME TIME TO COMPLETE DEPENDING ON THE NUMBER OF DRIVES AND AMOUNT OF FILES.
8. RUNS NETWORK TRACING USING NETSH TRACE & CONVERTS TO PCAPNG FOR FURTHER ANALYSIS Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Covert-Control : Google Drive, OneDrive And Youtube As Covert-Channels – Control Systems Remotely By Uploading Files To Google Drive, OneDrive, Youtube Or Telegram
Covert-Control systems remotely by uploading files to Google Drive, OneDrive, Youtube or Telegram using Python to create the files and the listeners. It allows to create text files, images, audio or videos, with the commands in cleartext or encrypted using AES.
* covert-googledrive.py – Control systems uploading files to a public folder in Google Drive.
* covert-onedrive.py – Control systems uploading files to a public folder in OneDrive.
* covert-youtube.py – Control systems uploading videos to Youtube (updated from covert-tube).
* covert-telegram.py – Control systems with a Telegram bot. Create Files To Upload
You can find example files in the folder test_files or create new ones with generate_file.py:
python3 generate_file.py -t TYPE [-o OUTPUTFILE] [-c COMMAND] [-e]
* -t (–type) [Required]: Types of file: “text”, “image”, “audio” or “video”.
* -o (–outputfile) [Optional]: Output file.
* -c (–command) [Optional]: Command to execute.
* -e (–encrypted) [Optional]: Add this flag to encrypt the command with AES.
Examples:
python3 generate_file.py -t text -c “whoami” -o text.txt
python3 generate_file.py -t text -c “whoami” -o text_encrypted.txt -e
python3 generate_file.py -t audio -c “whoami” -o audio.wav
python3 generate_file.py -t audio -c “whoami” -o audio_encrypted.wav -e
python3 generate_file.py -t image -c “whoami” -o image.png
python3 generate_file.py -t image -c “whoami” -o image_encrypted.png -e
python3 generate_file.py -t video -c “whoami” -o video.avi
python3 generate_file.py -t video -c “whoami” -o video_encrypted.avi -e
Configuration
Common configuration values:
* data_type (Optional. Default: “text”):data_typeFile typeEncryptedValid forExtensiontextText fileNoGoogle Drive, OneDrive.txttext_encryptedText fileYesGoogle Drive, OneDrive.txtimageImageNoGoogle Drive, OneDrive.pngimage_encryptedImageYesGoogle Drive, OneDrive.pngaudioAudioNoGoogle Drive, OneDrive.wavaudio_encryptedAudioYesGoogle Drive, OneDrive.wavvideoVideoNoGoogle Drive, OneDrive, Youtube.avivideo_encryptedVideoYesGoogle Drive, OneDrive, Youtube.avi
* delay_seconds (Optional. Default: 300): Seconds between checks of new files uploaded to the Google Drive or OneDrive folder or new videos in the Youtube channel.
* aes_key (Optional. Default: “covert-control21”): Key for AES encryption.
* debug (Optional. Default: True): Print messages and timestamps in the listener or not.
Specific configuration values:
* googledrive_folder: Url of public Google Drive folder to monitor (for covert-googledrive.py).
* onedrive_folder: Url of public OneDrive folder to monitor (for covert-onedrive.py).
* youtube_channel_id: Youtube channel ID of the channel to monitor. You can get it from here (for covert-youtube.py).
* youtube_api_key: Get an API key creating an application and generating the key in here (for covert-youtube.py).
* telegram_token: Bot token, create it using BotFather. Write “/newbot”, then send a name for the bot (for example, “botname”) and a username for the bot ending in “-bot” (for example, “somethingrandombot”) (for covert-telegram.py).
* telegram_username: Specify a Telegram username so it only executes commands received from this user (without “@”). Google Drive
It allows to execute commands uploading text files, images, audio and videos, unencrypted or encrypted with AES. The optional input argument is the public folder url, which can be also configured in config.py:
python3 covert-googledrive.py [FOLDER_URL]
The listener will check the Google Drive folder every 300 seconds by default (can be updated in config.py). In this case a video, “video.avi”, is uploaded with the command in the QR of the video:
https://blogger.googleusercontent.com/img/a/AVvXsEiQ0Xy9TjU938xPAZF_0oVr2j4Z00_HTeKkBr[...]
___________________________
@hacking_Attack
@Hacking_Video
Covert-Control : Google Drive, OneDrive And Youtube As Covert-Channels – Control Systems Remotely By Uploading Files To Google Drive, OneDrive, Youtube Or Telegram
Covert-Control systems remotely by uploading files to Google Drive, OneDrive, Youtube or Telegram using Python to create the files and the listeners. It allows to create text files, images, audio or videos, with the commands in cleartext or encrypted using AES.
* covert-googledrive.py – Control systems uploading files to a public folder in Google Drive.
* covert-onedrive.py – Control systems uploading files to a public folder in OneDrive.
* covert-youtube.py – Control systems uploading videos to Youtube (updated from covert-tube).
* covert-telegram.py – Control systems with a Telegram bot. Create Files To Upload
You can find example files in the folder test_files or create new ones with generate_file.py:
python3 generate_file.py -t TYPE [-o OUTPUTFILE] [-c COMMAND] [-e]
* -t (–type) [Required]: Types of file: “text”, “image”, “audio” or “video”.
* -o (–outputfile) [Optional]: Output file.
* -c (–command) [Optional]: Command to execute.
* -e (–encrypted) [Optional]: Add this flag to encrypt the command with AES.
Examples:
python3 generate_file.py -t text -c “whoami” -o text.txt
python3 generate_file.py -t text -c “whoami” -o text_encrypted.txt -e
python3 generate_file.py -t audio -c “whoami” -o audio.wav
python3 generate_file.py -t audio -c “whoami” -o audio_encrypted.wav -e
python3 generate_file.py -t image -c “whoami” -o image.png
python3 generate_file.py -t image -c “whoami” -o image_encrypted.png -e
python3 generate_file.py -t video -c “whoami” -o video.avi
python3 generate_file.py -t video -c “whoami” -o video_encrypted.avi -e
Configuration
Common configuration values:
* data_type (Optional. Default: “text”):data_typeFile typeEncryptedValid forExtensiontextText fileNoGoogle Drive, OneDrive.txttext_encryptedText fileYesGoogle Drive, OneDrive.txtimageImageNoGoogle Drive, OneDrive.pngimage_encryptedImageYesGoogle Drive, OneDrive.pngaudioAudioNoGoogle Drive, OneDrive.wavaudio_encryptedAudioYesGoogle Drive, OneDrive.wavvideoVideoNoGoogle Drive, OneDrive, Youtube.avivideo_encryptedVideoYesGoogle Drive, OneDrive, Youtube.avi
* delay_seconds (Optional. Default: 300): Seconds between checks of new files uploaded to the Google Drive or OneDrive folder or new videos in the Youtube channel.
* aes_key (Optional. Default: “covert-control21”): Key for AES encryption.
* debug (Optional. Default: True): Print messages and timestamps in the listener or not.
Specific configuration values:
* googledrive_folder: Url of public Google Drive folder to monitor (for covert-googledrive.py).
* onedrive_folder: Url of public OneDrive folder to monitor (for covert-onedrive.py).
* youtube_channel_id: Youtube channel ID of the channel to monitor. You can get it from here (for covert-youtube.py).
* youtube_api_key: Get an API key creating an application and generating the key in here (for covert-youtube.py).
* telegram_token: Bot token, create it using BotFather. Write “/newbot”, then send a name for the bot (for example, “botname”) and a username for the bot ending in “-bot” (for example, “somethingrandombot”) (for covert-telegram.py).
* telegram_username: Specify a Telegram username so it only executes commands received from this user (without “@”). Google Drive
It allows to execute commands uploading text files, images, audio and videos, unencrypted or encrypted with AES. The optional input argument is the public folder url, which can be also configured in config.py:
python3 covert-googledrive.py [FOLDER_URL]
The listener will check the Google Drive folder every 300 seconds by default (can be updated in config.py). In this case a video, “video.avi”, is uploaded with the command in the QR of the video:
https://blogger.googleusercontent.com/img/a/AVvXsEiQ0Xy9TjU938xPAZF_0oVr2j4Z00_HTeKkBr[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Covert-Control : Google Drive, OneDrive And Youtube As Covert-Channels
Covert-Control systems remotely by uploading files to Google Drive, OneDrive, Youtube or Telegram using Python to create the files.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials FormatFuzzer : A Framework For High-Efficiency, High-Quality Generation And Parsing Of Binary Inputs FormatFuzzer is a framework for high-efficiency, high-quality generation and parsing of binary inputs. It takes a binary template that…
provided in
If the above
Run the
./ffcompile templates/gif.bt gif.cpp
Step 2: Compiling the C++ code
Use the following commands to create a fuzzer
g++ -c -I . -std=c++17 -g -O3 -Wall fuzzer.cpp
(
Then, compile the binary parser/compiler:
g++ -c -I . -std=c++17 -g -O3 -Wall gif.cpp
Finally, link the binary parser/compiler with the command-line driver to obtain an executable. If you use any extra libraries (such as
g++ -O3 gif.o fuzzer.o -o gif-fuzzer -lz
Running the Fuzzer
FormatFuzzer can be run as a standalone parser, generator or mutator of specific formats. In addition, it can called by general-purpose fuzzers such as AFL++ to integrate those format-specific capabilities into the fuzzing process (see the section below on AFL++ integration).
The generated fuzzer takes a command as first argument, followed by options and arguments to that command.
The most important command is
Run the generator as
./gif-fuzzer fuzz output.gif
to create a random binary file
./gif-fuzzer fuzz out1.gif out2.gif out3.gif
to create three GIF files
Note that the
You can also run the fuzzer as a parser for binary files, using the
To run the parser, use
./gif-fuzzer parse input.gif
You will see error messages if
Decision Files
While parsing, you can also store all parsing decisions (i.e. which parsing alternatives were taken) in a decision file. This is a sequence of bytes enumerating the decisions taken. Each byte stands for a single parsing decision. A byte value of
You can generate such a decision file when parsing an input:
./gif-fuzzer parse –decisions input.dec input.gif
Here,
You can also use such a decision file when generating inputs. The fuzzer will then take the exact same decisions as found during parsing. The following command generates a new GIF file using the decisions determined while parsing `input.gif’:
./gif-fuzzer fuzz –decisions input.dec input2.gif
If everything works well, both files should be identical:
cmp input.gif input2.gif
By mutating a decision file (e.g. replacing individual bytes), you can create inputs that are similar to the original file parsed. This is useful for interfacing with specific testing strategies and fuzzers such as AFL, where you can use
___________________________
@hacking_Attack
@Hacking_Video
templates/; if there is a file templates/FOO.bt, then make FOO-fuzzerwill build a fuzzer. Method 3: Manual stepsIf the above
makemethod does not work, or if you want more control, you may have to proceed manually. Step 1: Compiling Binary Template Files into C++ codeRun the
ffcompilecompiler to compile the binary template into C++ code. It takes two arguments: the .btbinary template, and a .cppC++ file to be generated../ffcompile templates/gif.bt gif.cpp
Step 2: Compiling the C++ code
Use the following commands to create a fuzzer
gif-fuzzer. First, compile the generic command-line driver:g++ -c -I . -std=c++17 -g -O3 -Wall fuzzer.cpp
(
-I . denotes the location of the bt.hfile; -std=c++17sets the C++ standard.)Then, compile the binary parser/compiler:
g++ -c -I . -std=c++17 -g -O3 -Wall gif.cpp
Finally, link the binary parser/compiler with the command-line driver to obtain an executable. If you use any extra libraries (such as
-lz), be sure to specify these here too.g++ -O3 gif.o fuzzer.o -o gif-fuzzer -lz
Running the Fuzzer
FormatFuzzer can be run as a standalone parser, generator or mutator of specific formats. In addition, it can called by general-purpose fuzzers such as AFL++ to integrate those format-specific capabilities into the fuzzing process (see the section below on AFL++ integration).
The generated fuzzer takes a command as first argument, followed by options and arguments to that command.
The most important command is
fuzz, for producing outputs. Its arguments are files to be generated in the appropriate format.Run the generator as
./gif-fuzzer fuzz output.gif
to create a random binary file
output.gif, or./gif-fuzzer fuzz out1.gif out2.gif out3.gif
to create three GIF files
out1.gif, out2.gif, and out3.gif.Note that the
gif.bttemplate we provide has been augmented with special functions to make generation of valid files easier. If you use an original .bttemplate files without adaptations, you may get warnings during generation and create invalid files. Running ParsersYou can also run the fuzzer as a parser for binary files, using the
parsecommand. This is useful if you want to test the accuracy of the binary template, or if you want to mutate an input (see `Decision Files’, below).To run the parser, use
./gif-fuzzer parse input.gif
You will see error messages if
input.gifcannot be successfully parsed.Decision Files
While parsing, you can also store all parsing decisions (i.e. which parsing alternatives were taken) in a decision file. This is a sequence of bytes enumerating the decisions taken. Each byte stands for a single parsing decision. A byte value of
0means that the first alternative was taken, a byte value of 1means that the second alternative was taken, and so on.You can generate such a decision file when parsing an input:
./gif-fuzzer parse –decisions input.dec input.gif
Here,
input.decstores the decisions made for parsing `input.gif’.You can also use such a decision file when generating inputs. The fuzzer will then take the exact same decisions as found during parsing. The following command generates a new GIF file using the decisions determined while parsing `input.gif’:
./gif-fuzzer fuzz –decisions input.dec input2.gif
If everything works well, both files should be identical:
cmp input.gif input2.gif
By mutating a decision file (e.g. replacing individual bytes), you can create inputs that are similar to the original file parsed. This is useful for interfacing with specific testing strategies and fuzzers such as AFL, where you can use
gif-fuzzerand the like as translators from decision files to binary fil[...]___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Covert-Control : Google Drive, OneDrive And Youtube As Covert-Channels – Control Systems Remotely By Uploading Files To Google Drive, OneDrive, Youtube Or Telegram Covert-Control systems remotely by uploading files to Google Drive, OneDrive…
6v1JBNHF7ZDeKXgeJWeSsGqDFomNal3Avs_ZkElM6OSuGYkDGSxpF7MRGTwIEWhs2PvYKG8u4IY64BLmNVJbmqg126yR00dj2PyBYF7NlYwCreHd5GG8ZSIc7Lc0NHXlTI2k_ADNI8azm7R-uQIre8=s376
After finding there is a new file uploaded to the folder, it is downloaded, processed and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEhsOuOHIKhkahz-AJ5a6F8uvfW2baUemeOgtonRJc1v5c_NEe4z4aZBxnwW6crKIXRtzIHR69tKyRfB86rTzlsmo9xq_cu1xhNZlzaYGFc5caGIGC8YNsMp8ahO6EH1nfJNrRjtFfabGzl5kVArSvEQjJawiDDfvIB_9Fq0dbH6pc9EpRCpkkk8OJ44=s567
Onedrive
It allows to execute commands uploading text files, images, audio and videos, unencrypted or encrypted with AES. The optional input argument is the public folder url, which can be also configured in config.py:
python3 covert-onedrive.py [FOLDER_URL]
The listener will check the OneDrive folder every 300 seconds by default (this can be updated in config.py). In this case an audio, “audio_encrypted.wav”, is uploaded with the command encrypted with AES:
https://blogger.googleusercontent.com/img/a/AVvXsEgKKyiPs1qyXjJ9F6eiuflhcdBoLMvdCVv9EbYl-0sl8AGGfTwYNBUKHswlMb0nMu-0HcgcQj_0_oXQ3mWogRwjfJs9e4pjddn_iwcQZJwAFDAC10JltaCDfar3Jj8ID6wuPU0_HFotbJh2F4po37r9JW7-G-Uk6q1lqYYWm7JK2j77dpVO8UnLs47O=s230
After finding there is a new file uploaded to the folder, it is downloaded, processed and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEiFWipP0330C1-vfJAbjmIuUyGCeQA-SuPh1TLTpFrvMss2fKvJ-PBcxmzPrVr1UjKsu3LYCA5I6WreBSjnQNY5ZxjeV5fSjZLnQezc98PN5B9UHsuewtVLmjW3Iz56BNl-zpwAX1TE9xeQapnMCmUoqePR2XOduNMOaNHgABJsNwRNJ6B-TJzJeRs5=s605
NOTE: This will only work if you do not delete any file in the folder, if you do it you must create a new one. It could be possible to implement it to work even after deleting files, but it would be necessary to create many requests and would be less stealthy. Youtube
It allows to execute commands uploading videos, unencrypted or encrypted with AES. The optional input arguments are the Youtube channel ID to monitor and the API key, which can be also configured in config.py:
python3 covert-youtube.py [CHANNEL_ID] [API_KEY]
The listener will check the Youtube channel every 300 seconds by default (this can be updated in config.py). First the video is uploaded:
https://blogger.googleusercontent.com/img/a/AVvXsEgVTIoZe4SSgWs-qxCQsipdPVG2QywLg-E9Jq-73XJQQjCKQq3c_64Tga8EhH-95rb02-UfCmNKgSRJBfL9Wo8zLpb_LrtvTijnikOT4EcXJnIs66wsP8A6P5V9D1bLhffYPKjk2bPt_eA_6ayXodnLiwy791JawsRINUHvcTR1jBArUibWJBuXAgfb=s640
After finding there is a new video in the channel, it is downloaded, processed and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEgabeaMu4DUfInuM5x5acxzrfau9oIFqSVcTv0Vh5h2cGBwwVL0hb2zxjmc_J-oNNDysKYY-vM7E72wFV103upM0f6aOXkkyRaeXB2SDjPifmx5NRKF4sBMl5YWTUX7LklxzerJ3JMHcLeKKQZBxjiQyqLZaPLJRJqA5lZDdhAlORwwV1c0DI0GiaDZ=s657
Telegram
Control systems remotely with a Telegram bot. This option does not allow to upload files, but it is possible to send the commands in cleartext (“/cmd”) or encrypted with AES (“/encrypted”). The first optional input argument is the bot token, which can be also configured in config.py; the second one is used to configure a single Telegram user who can send commands to the bot (without “@”):
python3 covert-telegram.py [BOT_TOKEN] [TELEGRAM_USER]
The listener will check the commands in the chat and show the output:
/cmd CLEARTEXT_COMMAND
/encrypted AES_ENCRYPTED_COMMAND
https://blogger.googleusercontent.com/img/a/AVvXsEh7_SVWVNyeyjDVsGhq3iHdElVdakxkYRaTkF0QGiZ15VPVgSeASBdklvFuYDa4V7-LcPiFsa2L-kbDesjClpxaPlVMZdc3-_2fOmTE7e0iBSUX8ufUXN-FsnkUqspj2zo8NtSfKvlpnOa1AbLG5Kxx-uYkKs_FWTU0TEsFfJtfhAgUKU2c4cWWEPdN=s485
Installation
sudo apt install libzbar0
pip install bs4 Pillow opencv-python pyqrcode pypng pyzbar youtube_dl pytesseract python-telegram-bot requests argparse pycryptodome
git clone https://github.com/ricardojoserf/covert-control && cd covert-control/
Creating standalone binaries
pyinstaller –onefile covert-googledrive.py
[...]
___________________________
@hacking_Attack
@Hacking_Video
After finding there is a new file uploaded to the folder, it is downloaded, processed and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEhsOuOHIKhkahz-AJ5a6F8uvfW2baUemeOgtonRJc1v5c_NEe4z4aZBxnwW6crKIXRtzIHR69tKyRfB86rTzlsmo9xq_cu1xhNZlzaYGFc5caGIGC8YNsMp8ahO6EH1nfJNrRjtFfabGzl5kVArSvEQjJawiDDfvIB_9Fq0dbH6pc9EpRCpkkk8OJ44=s567
Onedrive
It allows to execute commands uploading text files, images, audio and videos, unencrypted or encrypted with AES. The optional input argument is the public folder url, which can be also configured in config.py:
python3 covert-onedrive.py [FOLDER_URL]
The listener will check the OneDrive folder every 300 seconds by default (this can be updated in config.py). In this case an audio, “audio_encrypted.wav”, is uploaded with the command encrypted with AES:
https://blogger.googleusercontent.com/img/a/AVvXsEgKKyiPs1qyXjJ9F6eiuflhcdBoLMvdCVv9EbYl-0sl8AGGfTwYNBUKHswlMb0nMu-0HcgcQj_0_oXQ3mWogRwjfJs9e4pjddn_iwcQZJwAFDAC10JltaCDfar3Jj8ID6wuPU0_HFotbJh2F4po37r9JW7-G-Uk6q1lqYYWm7JK2j77dpVO8UnLs47O=s230
After finding there is a new file uploaded to the folder, it is downloaded, processed and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEiFWipP0330C1-vfJAbjmIuUyGCeQA-SuPh1TLTpFrvMss2fKvJ-PBcxmzPrVr1UjKsu3LYCA5I6WreBSjnQNY5ZxjeV5fSjZLnQezc98PN5B9UHsuewtVLmjW3Iz56BNl-zpwAX1TE9xeQapnMCmUoqePR2XOduNMOaNHgABJsNwRNJ6B-TJzJeRs5=s605
NOTE: This will only work if you do not delete any file in the folder, if you do it you must create a new one. It could be possible to implement it to work even after deleting files, but it would be necessary to create many requests and would be less stealthy. Youtube
It allows to execute commands uploading videos, unencrypted or encrypted with AES. The optional input arguments are the Youtube channel ID to monitor and the API key, which can be also configured in config.py:
python3 covert-youtube.py [CHANNEL_ID] [API_KEY]
The listener will check the Youtube channel every 300 seconds by default (this can be updated in config.py). First the video is uploaded:
https://blogger.googleusercontent.com/img/a/AVvXsEgVTIoZe4SSgWs-qxCQsipdPVG2QywLg-E9Jq-73XJQQjCKQq3c_64Tga8EhH-95rb02-UfCmNKgSRJBfL9Wo8zLpb_LrtvTijnikOT4EcXJnIs66wsP8A6P5V9D1bLhffYPKjk2bPt_eA_6ayXodnLiwy791JawsRINUHvcTR1jBArUibWJBuXAgfb=s640
After finding there is a new video in the channel, it is downloaded, processed and the commands are executed:
https://blogger.googleusercontent.com/img/a/AVvXsEgabeaMu4DUfInuM5x5acxzrfau9oIFqSVcTv0Vh5h2cGBwwVL0hb2zxjmc_J-oNNDysKYY-vM7E72wFV103upM0f6aOXkkyRaeXB2SDjPifmx5NRKF4sBMl5YWTUX7LklxzerJ3JMHcLeKKQZBxjiQyqLZaPLJRJqA5lZDdhAlORwwV1c0DI0GiaDZ=s657
Telegram
Control systems remotely with a Telegram bot. This option does not allow to upload files, but it is possible to send the commands in cleartext (“/cmd”) or encrypted with AES (“/encrypted”). The first optional input argument is the bot token, which can be also configured in config.py; the second one is used to configure a single Telegram user who can send commands to the bot (without “@”):
python3 covert-telegram.py [BOT_TOKEN] [TELEGRAM_USER]
The listener will check the commands in the chat and show the output:
/cmd CLEARTEXT_COMMAND
/encrypted AES_ENCRYPTED_COMMAND
https://blogger.googleusercontent.com/img/a/AVvXsEh7_SVWVNyeyjDVsGhq3iHdElVdakxkYRaTkF0QGiZ15VPVgSeASBdklvFuYDa4V7-LcPiFsa2L-kbDesjClpxaPlVMZdc3-_2fOmTE7e0iBSUX8ufUXN-FsnkUqspj2zo8NtSfKvlpnOa1AbLG5Kxx-uYkKs_FWTU0TEsFfJtfhAgUKU2c4cWWEPdN=s485
Installation
sudo apt install libzbar0
pip install bs4 Pillow opencv-python pyqrcode pypng pyzbar youtube_dl pytesseract python-telegram-bot requests argparse pycryptodome
git clone https://github.com/ricardojoserf/covert-control && cd covert-control/
Creating standalone binaries
pyinstaller –onefile covert-googledrive.py
[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
provided in templates/; if there is a file templates/FOO.bt, then make FOO-fuzzerwill build a fuzzer. Method 3: Manual steps If the above makemethod does not work, or if you want more control, you may have to proceed manually. Step 1: Compiling Binary Template…
es and back: AFL would mutate decision files, and the program under test would run on the translated binary files. In contrast to mutating binary files directly (as AFL would normally do), this would have the advantage of always having valid inputs – and thus progressing much faster towards coverage. AFL++ Integration
In addition to the format-specific fuzzers, such as
To run AFL++ with FormatFuzzer, just follow the instructions on our modified version of AFL++. We support different fuzzing strategies, including:
* AFL+FFMut: runs AFL++ using FormatFuzzer to provide format-specific smart mutations.
* AFL+FFGen: uses FormatFuzzer as a format-specific generator, while AFL++ mutates its decision seeds. Creating and Customizing Binary Templates
To write your own
In many cases, a template of the format you are looking for (or a similar one) may already exist. Have a look at the 010 editor binary template collection whether there is something that you can use or base your format on.
Note that the
In this section, we discuss some of the ways in which you can customize
For example, for the GIF format, the file templates/gif-orig.bt shows the original binary template, which was only designed for parsing, while the file templates/gif.bt is a modified version which is capable of generating valid GIFs. Comparing the two files, we see that a small number changes was required to achieve this.
If you have created a
The GIF binary template makes use of lookahead functions
By default, our translation procedure
./ffcompile templates/gif.bt gif.cpp
a printed message shows the lookahead functions identified, as well as the mined interesting values:
Finished creating cpp generator.
Lookahead functions found:
ReadUByte
ReadUShort
Mined interesting values:
GlobalColorTableFlag: [‘1’]
LocalColorTableFlag: [‘1’]
ReadUByte: [‘0x3B’, ‘0x2C’]
ReadUShort: [‘0xF921’, ‘0xFE21’, ‘0x0121’, ‘0xFF21’]
Signature: [‘”GIF”‘]
For GIF generation, however, it is better to specify the set of good known values for
const local [...]
___________________________
@hacking_Attack
@Hacking_Video
In addition to the format-specific fuzzers, such as
gif-fuzzer, FormatFuzzer can also be compiled into format-specific shared libraries, such as gif.so(for that, simply run ./build.sh gifor make gif.so). Those shared libraries can be loaded by general-purpose fuzzers, such as AFL++.To run AFL++ with FormatFuzzer, just follow the instructions on our modified version of AFL++. We support different fuzzing strategies, including:
* AFL+FFMut: runs AFL++ using FormatFuzzer to provide format-specific smart mutations.
* AFL+FFGen: uses FormatFuzzer as a format-specific generator, while AFL++ mutates its decision seeds. Creating and Customizing Binary Templates
To write your own
.btbinary templates (and thus create a high-efficiency fuzzer/parser for this format), read the section Introduction to Templates and Scripts from the 010 Editor Manual.In many cases, a template of the format you are looking for (or a similar one) may already exist. Have a look at the 010 editor binary template collection whether there is something that you can use or base your format on.
Note that the
.btfiles provided in the repository generally target parsing files. They can be used for generating files, too; but they often lack exact information which parts of the input are required.In this section, we discuss some of the ways in which you can customize
.btfiles to work well with FormatFuzzer.For example, for the GIF format, the file templates/gif-orig.bt shows the original binary template, which was only designed for parsing, while the file templates/gif.bt is a modified version which is capable of generating valid GIFs. Comparing the two files, we see that a small number changes was required to achieve this.
If you have created a
gif-fuzzer, either by running make gif-fuzzeror by using the ffcompiletool, you have already obtained a C++ file gif.cppwhich contains an implementation of the GIF generator and parser. This is useful to see how the changes you make to the binary template are translated into executable code. More details on the C++ code are presented on the next section.The GIF binary template makes use of lookahead functions
ReadUByte()and ReadUShort()to look ahead at the values of the next bytes in the file before actually parsing them into a struct field. At generation time, we allow those functions to receive an additional argument specifying a set of good known values to pick for the bytes that we look ahead. In addition, we also allow specifying a global set of good known values to always use when calling a particular lookahead function, such as ReadUByte(). Those are stored in the ReadUByteInitValuesvector.By default, our translation procedure
ffcompiletries to mine interesting values which have been used in comparisons against lookahead bytes and use them as a global set of known values. When running./ffcompile templates/gif.bt gif.cpp
a printed message shows the lookahead functions identified, as well as the mined interesting values:
Finished creating cpp generator.
Lookahead functions found:
ReadUByte
ReadUShort
Mined interesting values:
GlobalColorTableFlag: [‘1’]
LocalColorTableFlag: [‘1’]
ReadUByte: [‘0x3B’, ‘0x2C’]
ReadUShort: [‘0xF921’, ‘0xFE21’, ‘0x0121’, ‘0xFF21’]
Signature: [‘”GIF”‘]
For GIF generation, however, it is better to specify the set of good known values for
ReadUByte()individually at each call to the function. So we define an empty array (size 0)const local [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
6v1JBNHF7ZDeKXgeJWeSsGqDFomNal3Avs_ZkElM6OSuGYkDGSxpF7MRGTwIEWhs2PvYKG8u4IY64BLmNVJbmqg126yR00dj2PyBYF7NlYwCreHd5GG8ZSIc7Lc0NHXlTI2k_ADNI8azm7R-uQIre8=s376 After finding there is a new file uploaded to the folder, it is downloaded, processed and the commands…
pyinstaller –onefile covert-onedrive.py
pyinstaller –onefile covert-telegram.py
pyinstaller –onefile covert-youtube.py
rm -rf build
rm *spec
ls dist/ Download
___________________________
@hacking_Attack
@Hacking_Video
pyinstaller –onefile covert-telegram.py
pyinstaller –onefile covert-youtube.py
rm -rf build
rm *spec
ls dist/ Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
es and back: AFL would mutate decision files, and the program under test would run on the translated binary files. In contrast to mutating binary files directly (as AFL would normally do), this would have the advantage of always having valid inputs – and thus…
UBYTE ReadUByteInitValues[0];
to overwrite the set of global
if(GifHeader.Version == “89a”)
local UBYTE values[] = { 0x3B, 0x2C, 0x21 };
else
local UBYTE values[] = { 0x3B, 0x2C };
while (ReadUByte(FTell(), values) != 0x3B) {
…
}
The remaining edits required for the GIF binary template are similar. For example, for each struct field can also specify a set of known good values. For example this specifies the correct values for the
char Version[3] = { {“87a”}, {“89a”} };
Understanding the Generated C++ Code
For debugging purposes, as well as for understanding how to make appropriate changes to improve your generators and parsers, it may be useful to understand some inner workings of the generated C++ code. Ideally, you should be able to edit the binary template files until they can be used to generate valid files with high probability, so you wouldn’t have to edit the generated C++ code.
The C++ code creates a class for each
At construction time, when initializing a variable, we can define a set of good known values that this variable can assume. For example, the constructor call
char_array_class cname(cname_element, { “IHDR”, “tEXt”, “PLTE”, “cHRM”, “sRGB”, “iEXt”, “zEXt”, “tIME”, “pHYs”, “bKGD”, “sBIT”, “sPLT”, “acTL”, “fcTL”, “fdAT”, “IHDR”, “IEND” });
would specify 17 good values to use for variable
GENERATE(chunk, ::g->chunk.generate({ “IHDR” }, false));
When generating the second chunk, we might use this long list of possible chunks that can come between the IHDR chunk and the PLTE chunk:
GENERATE(chunk, ::g->chunk.generate({ “iCCP”, “sRGB”, “sBIT”, “gAMA”, “cHRM”, “pHYs”, “sPLT”, “tIME”, “zTXt”, “tEXt”, “iTXt”, “eXIf”, “oFFs”, “pCAL”, “sCAL”, “acTL”, “fcTL”, “fdAT”, “fRAc”, “gIFg”, “gIFt”, “gIFx”, “sTER” }, true));
The generator will then uniformly pick one of the good known values to use for the new instance. We also allow the choice of an evil value which is not one of the good known values with small probability 1/128. This feature can be enabled or disabled any time by using the method
All the random choices taken by the generator are done by calling the
long long rand_int(unsigned long long x, std::function parse);
When running the program as a generator, this method samples an integer from 0 to x-1 by reading bytes from the random buffer. When running the program as a parser, this method uses the
___________________________
@hacking_Attack
@Hacking_Video
to overwrite the set of global
ReadUByteInitValuesand for each call to ReadUByte(), we use an additional argument to specify the set of good values to use for that particular location. The binary template language is also powerful enough to allow this choice to be made based on runtime conditions. For example, in the following code we show how the choice of appropriate values for a ReadUByte()call can depend on the current GIF version we are generating. A GIF version 89aallows one extra possible value for the byte (0x21).if(GifHeader.Version == “89a”)
local UBYTE values[] = { 0x3B, 0x2C, 0x21 };
else
local UBYTE values[] = { 0x3B, 0x2C };
while (ReadUByte(FTell(), values) != 0x3B) {
…
}
The remaining edits required for the GIF binary template are similar. For example, for each struct field can also specify a set of known good values. For example this specifies the correct values for the
Versionfield: 87aand 89a.char Version[3] = { {“87a”}, {“89a”} };
Understanding the Generated C++ Code
For debugging purposes, as well as for understanding how to make appropriate changes to improve your generators and parsers, it may be useful to understand some inner workings of the generated C++ code. Ideally, you should be able to edit the binary template files until they can be used to generate valid files with high probability, so you wouldn’t have to edit the generated C++ code.
The C++ code creates a class for each
structand uniondefined in the binary template, as well as for native types, such as int.At construction time, when initializing a variable, we can define a set of good known values that this variable can assume. For example, the constructor call
char_array_class cname(cname_element, { “IHDR”, “tEXt”, “PLTE”, “cHRM”, “sRGB”, “iEXt”, “zEXt”, “tIME”, “pHYs”, “bKGD”, “sBIT”, “sPLT”, “acTL”, “fcTL”, “fdAT”, “IHDR”, “IEND” });
would specify 17 good values to use for variable
cname. But this is often not enough, since the choice of appropriate chunk types is context sensitive. So we also allow specifying a set of good values at generation time when generating a new chunk. For example, this call could be used to generate an instance of chunkfor the first chunk, which must have type IHDR.GENERATE(chunk, ::g->chunk.generate({ “IHDR” }, false));
When generating the second chunk, we might use this long list of possible chunks that can come between the IHDR chunk and the PLTE chunk:
GENERATE(chunk, ::g->chunk.generate({ “iCCP”, “sRGB”, “sBIT”, “gAMA”, “cHRM”, “pHYs”, “sPLT”, “tIME”, “zTXt”, “tEXt”, “iTXt”, “eXIf”, “oFFs”, “pCAL”, “sCAL”, “acTL”, “fcTL”, “fdAT”, “fRAc”, “gIFg”, “gIFt”, “gIFx”, “sTER” }, true));
The generator will then uniformly pick one of the good known values to use for the new instance. We also allow the choice of an evil value which is not one of the good known values with small probability 1/128. This feature can be enabled or disabled any time by using the method
set_evil_bit.All the random choices taken by the generator are done by calling the
rand_int()method.long long rand_int(unsigned long long x, std::function parse);
When running the program as a generator, this method samples an integer from 0 to x-1 by reading bytes from the random buffer. When running the program as a parser, this method uses the
parse()function to find out which random bytes must be present in the random buffer in order to generate the target file, and then writes those bytes to the random buffer. The parsefunction receives as an argument the buffer at the current position of the file and must then return which value would have to be returned by the current call to rand_int()in order to generate this exact file configuration. Download___________________________
@hacking_Attack
@Hacking_Video
SQL Injection [CWE-89] — The Hacktivists
SQL Injection is a weakness that is caused by improper neutralization of special elements used in an SQL query.Continue reading on Medium »
Read more...
SQL Injection is a weakness that is caused by improper neutralization of special elements used in an SQL query.Continue reading on Medium »
Read more...
LDAP Injection [CWE-90] — The Hacktivists
LDAP Injection weakness describes improper neutralization of special elements used in LDAP queries.Continue reading on Medium »
Read more...
LDAP Injection weakness describes improper neutralization of special elements used in LDAP queries.Continue reading on Medium »
Read more...
XML Injection [CWE-91] — The Hacktivists
XML Injection weakness describes improper neutralization of special elements used in XML queries.Continue reading on Medium »
Read more...
XML Injection weakness describes improper neutralization of special elements used in XML queries.Continue reading on Medium »
Read more...