Ransomware-Simulator - Ransomware Simulator Written In Golang
http://www.kitploit.com/2022/05/ransomware-simulator-ransomware.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/ransomware-simulator-ransomware.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Ransomware-Simulator - Ransomware Simulator Written In Golang
The goal of this repository is to provide a simple, harmless way to check your AV's protection (https://www.kitploit.com/search/label/Protection) on ransomware. This tool simulates typical ransomware behaviour, such as: Staging from a Word document macro Deleting Volume Shadow Copies Encrypting documents (embedded and dropped by the simulator (https://www.kitploit.com/search/label/Simulator) into a new folder) Dropping a ransomware note to the user's desktop The ransomware simulator takes no action that actually encrypts pre-existing files on the device, or deletes Volume Shadow Copies. However, any AV products looking for such behaviour should still hopefully trigger. Each step, as listed above, can also be disabled via a command line (https://www.kitploit.com/search/label/Command%20Line) flag. This allows you to check responses to later steps as well, even if an AV already detects earlier steps.
Usage Run command: Run Ransomware Simulator
Usage:
ransomware-simulator run [flags]
Flags:
--dir string Directory (https://www.kitploit.com/search/label/Directory) where files that will be encrypted should be staged (default "./encrypted-files")
--disable-file-encryption Don't simulate document encryption
--disable-macro-simulation Don't simulate start from a macro by building the following process chain: winword.exe -> cmd.exe -> ransomware-simulator.exe
--disable-note-drop Don't drop pseudo ransomware note
--disable-shadow-copy-deletion Don't simulate volume shadow copy deletion
-h, --help help for run
--note-location string Ransomware note location (default "C:\\Users\\neo\\Desktop\\ransomware-simulator-note.txt")
Download Ransomware-Simulator (https://github.com/NextronSystems/ransomware-simulator)
___________________________
@hacking_Attack
@Hacking_Video
Usage Run command: Run Ransomware Simulator
Usage:
ransomware-simulator run [flags]
Flags:
--dir string Directory (https://www.kitploit.com/search/label/Directory) where files that will be encrypted should be staged (default "./encrypted-files")
--disable-file-encryption Don't simulate document encryption
--disable-macro-simulation Don't simulate start from a macro by building the following process chain: winword.exe -> cmd.exe -> ransomware-simulator.exe
--disable-note-drop Don't drop pseudo ransomware note
--disable-shadow-copy-deletion Don't simulate volume shadow copy deletion
-h, --help help for run
--note-location string Ransomware note location (default "C:\\Users\\neo\\Desktop\\ransomware-simulator-note.txt")
Download Ransomware-Simulator (https://github.com/NextronSystems/ransomware-simulator)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
How to Report Buggs and claim your bounty?
https://medium.com/sagemaster/how-to-report-buggs-and-claim-your-bounty-153c41f075b6?source=rss------bug_bounty-5
Steps:Continue reading on SageMaster » (https://medium.com/sagemaster/how-to-report-buggs-and-claim-your-bounty-153c41f075b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/sagemaster/how-to-report-buggs-and-claim-your-bounty-153c41f075b6?source=rss------bug_bounty-5
Steps:Continue reading on SageMaster » (https://medium.com/sagemaster/how-to-report-buggs-and-claim-your-bounty-153c41f075b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Report Buggs and claim your bounty?
instruction will be updated soon
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is DNS Reconnaissance and its Tools
https://cdn-images-1.medium.com/max/1200/0*0G4KYesHG5ZodXmD.jpg
DNS Reconnaissance is the search for freely available information to assist in an attack.
Continue reading on Zerosuniverse »
___________________________
@hacking_Attack
@Hacking_Video
What is DNS Reconnaissance and its Tools
https://cdn-images-1.medium.com/max/1200/0*0G4KYesHG5ZodXmD.jpg
DNS Reconnaissance is the search for freely available information to assist in an attack.
Continue reading on Zerosuniverse »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is DNS Reconnaissance and its Tools
DNS Reconnaissance is the search for freely available information to assist in an attack.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Anonymous Declares Cyberwar on Pro-Russian Hacker Gang Killnet
https://cdn-images-1.medium.com/max/640/0*EPkXgByfn0Ww9fja.jpg
Our Confidential Information on the Internet must be safe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Anonymous Declares Cyberwar on Pro-Russian Hacker Gang Killnet
https://cdn-images-1.medium.com/max/640/0*EPkXgByfn0Ww9fja.jpg
Our Confidential Information on the Internet must be safe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Anonymous Declares Cyberwar on Pro-Russian Hacker Gang Killnet
Our Confidential Information on the Internet must be safe.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Paper Walkthrough — HTB
https://cdn-images-1.medium.com/max/688/0*fZzcIC-XXvBmOtQu.png
In this machine on port 80 it first leak the new vhost called office.paper on response header X-Backend-Server. After that a Wordpress…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Paper Walkthrough — HTB
https://cdn-images-1.medium.com/max/688/0*fZzcIC-XXvBmOtQu.png
In this machine on port 80 it first leak the new vhost called office.paper on response header X-Backend-Server. After that a Wordpress…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Paper Walkthrough — HTB
In this machine on port 80 it first leak the new vhost called office.paper on response header X-Backend-Server. After that a Wordpress…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I hacked custom Wordle in one hour
https://cdn-images-1.medium.com/max/1280/1*In1JYJe6A1_eL5D7KBBCiQ.png
Wordle is the new trendy game. And since I am really bad at it, I decided to never fail again at custom Wordle by hacking it!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How I hacked custom Wordle in one hour
https://cdn-images-1.medium.com/max/1280/1*In1JYJe6A1_eL5D7KBBCiQ.png
Wordle is the new trendy game. And since I am really bad at it, I decided to never fail again at custom Wordle by hacking it!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I hacked custom Wordle in one hour
Wordle is the new trendy game. And since I am really bad at it, I decided to never fail again at custom Wordle by hacking it!
Improving my career by becoming a developer
https://www.reddit.com/r/Pentesting/comments/uyxtr7/improving_my_career_by_becoming_a_developer/
Hello im a security professional, ive worked in a csirt and then in secure development giving tips and doing pentests In my actual job ive realized how important is for a security professional to understand the developer's job, the technologies they use, the methodologies, documentation, libraries, etc So ive been thinking of switching fields and becoming a developer, do you guys have any kind of recommendations? I know some java, javascript and python and right now im learning java spring I alao have some coding background, mostly in monitoring and automation but nothing that faces users submitted by /u/clavita (https://www.reddit.com/user/clavita)
[link] (https://www.reddit.com/r/Pentesting/comments/uyxtr7/improving_my_career_by_becoming_a_developer/) [comments] (https://www.reddit.com/r/Pentesting/comments/uyxtr7/improving_my_career_by_becoming_a_developer/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/uyxtr7/improving_my_career_by_becoming_a_developer/
Hello im a security professional, ive worked in a csirt and then in secure development giving tips and doing pentests In my actual job ive realized how important is for a security professional to understand the developer's job, the technologies they use, the methodologies, documentation, libraries, etc So ive been thinking of switching fields and becoming a developer, do you guys have any kind of recommendations? I know some java, javascript and python and right now im learning java spring I alao have some coding background, mostly in monitoring and automation but nothing that faces users submitted by /u/clavita (https://www.reddit.com/user/clavita)
[link] (https://www.reddit.com/r/Pentesting/comments/uyxtr7/improving_my_career_by_becoming_a_developer/) [comments] (https://www.reddit.com/r/Pentesting/comments/uyxtr7/improving_my_career_by_becoming_a_developer/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Improving my career by becoming a developer
Hello im a security professional, ive worked in a csirt and then in secure development giving tips and doing pentests In my actual job ive...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Ransomware-Simulator - Ransomware Simulator Written In Golang
https://blogger.googleusercontent.com/img/a/AVvXsEgjAP0ObAUMq5lPna7dnteYffhlm1j2RJ4vi5wPK1iHnhiJCDAznktH0zK-opGAGn2D-hI53o5JtzGBAg_Ekpf5dOQ7P0t7NrUrtjzBi7uwtbBvHQlwTrc4ZmxchU7SgxpHWmA-OsdPv5sBuCP35jEeCGq7Z9TL3KA1Qql-sngplUviMRQaUsLukaBA=w640-h268
The goal of this repository is to provide a simple, harmless way to check your AV's protection on ransomware.
This tool simulates typical ransomware behaviour, such as:
* Staging from a Word document macro
* Deleting Volume Shadow Copies
* Encrypting documents (embedded and dropped by the simulator into a new folder)
* Dropping a ransomware note to the user's desktop
The ransomware simulator takes no action that actually encrypts pre-existing files on the device, or deletes Volume Shadow Copies. However, any AV products looking for such behaviour should still hopefully trigger.
Each step, as listed above, can also be disabled via a command line flag. This allows you to check responses to later steps as well, even if an AV already detects earlier steps.
Usage
Run command:
Download Ransomware-Simulator
___________________________
@hacking_Attack
@Hacking_Video
Ransomware-Simulator - Ransomware Simulator Written In Golang
https://blogger.googleusercontent.com/img/a/AVvXsEgjAP0ObAUMq5lPna7dnteYffhlm1j2RJ4vi5wPK1iHnhiJCDAznktH0zK-opGAGn2D-hI53o5JtzGBAg_Ekpf5dOQ7P0t7NrUrtjzBi7uwtbBvHQlwTrc4ZmxchU7SgxpHWmA-OsdPv5sBuCP35jEeCGq7Z9TL3KA1Qql-sngplUviMRQaUsLukaBA=w640-h268
The goal of this repository is to provide a simple, harmless way to check your AV's protection on ransomware.
This tool simulates typical ransomware behaviour, such as:
* Staging from a Word document macro
* Deleting Volume Shadow Copies
* Encrypting documents (embedded and dropped by the simulator into a new folder)
* Dropping a ransomware note to the user's desktop
The ransomware simulator takes no action that actually encrypts pre-existing files on the device, or deletes Volume Shadow Copies. However, any AV products looking for such behaviour should still hopefully trigger.
Each step, as listed above, can also be disabled via a command line flag. This allows you to check responses to later steps as well, even if an AV already detects earlier steps.
Usage
Run command:
Run Ransomware Simulator
Usage:
ransomware-simulator run [flags]
Flags:
--dir string Directory where files that will be encrypted should be staged (default "./encrypted-files")
--disable-file-encryption Don't simulate document encryption
--disable-macro-simulation Don't simulate start from a macro by building the following process chain: winword.exe -> cmd.exe -> ransomware-simulator.exe
--disable-note-drop Don't drop pseudo ransomware note
--disable-shadow-copy-deletion Don't simulate volume shadow copy deletion
-h, --help help for run
--note-location string Ransomware note location (default "C:\\Users\\neo\\Desktop\\ransomware-simulator-note.txt")Download Ransomware-Simulator
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Ransomware-Simulator - Ransomware Simulator Written In Golang
Kali Linux Tutorials
EvilSelenium : A Tool That Weaponizes Selenium To Attack Chromium Based Browsers
___________________________
@hacking_Attack
@Hacking_Video
EvilSelenium : A Tool That Weaponizes Selenium To Attack Chromium Based Browsers
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
EvilSelenium : A Tool That Weaponizes Selenium To Attack Chromium
EvilSelenium is a new project that weaponizes Selenium to abuse Chromium-based browsers. The current features right now.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Wholeaked : A File-Sharing Tool That Allows You To Find The Responsible Person In Case Of A Leakage
Wholeaked is a file-sharing tool that allows you to find the responsible person in case of a leakage. It’s written in Go. How?wholeaked gets the file that will be shared and a list of recipients. It creates a unique signature for each recipient and adds it to the file secretly. After then, it can automatically send files to the corresponding recipients by using Sendgrid, AWS SES or SMTP integrations. Instead of sending them by e-mail, you can also share them manually.
wholeaked works with every file type. However, it has additional features for common file types such as PDF, DOCX, MOV etc. Sharing Process+———–++———–+ / |Top Secret |
|Top Secret ||Recipient | / |.pdf |
|.pdf ||List | +———+ / | |
| || | |utkusen/ | / b@gov | |
| ||a@gov |—–>|wholeaked| /———-+ |
| ||b@gov | | | \ |Hidden |
| ||c@gov | +———+ \ |signature2 |
| || | \ +———–+
+———–++———–+ \ +———–+
\ |Top Secret |
\ |.pdf |
c@gov \ | |
\ | |
\ | |
\ |Hidden |
-|signature3 |
+———–+ Validation PartTo find who leaked the document, you just need to provide the leaked file to wholeaked, and it will reveal the responsible person by comparing the signatures in the database.
+———–+ +———+
|Top Secret | |Signature|
|.pdf | +———+|Database |
| | |utkusen/ || | Document leaked by
| |->|wholeaked|| |——–+
| | | || | b@gov
|Hidden | +———+| |
|Signature2 | | |
+———–+ +———+ File Types and Detection Modeswholeaked can add the unique signature to different sections of a file. Available detection modes are given below:
File Hash: SHA256 hash of the file. All file types are supported.
Binary: The signature is directly added to the binary. Almost all file types are supported.
Metadata: The signature is added to a metadata section of a file. Supported file types: PDF, DOCX, XLSX, PPTX, MOV, JPG, PNG, GIF, EPS, AI, PSD
Watermark: An invisible signature is inserted into the text. Only PDF files are supported. InstallationFrom BinaryYou can download the pre-built binaries from the releases page and run. For example:
* Run:
1. Debian-based Linux: Run
wholeaked requires
1. Download “Xpdf command line tools” for Linux, macOS or Windows from here: https://www.xpdfreader.com/download.html
2. Extract the archive and navigate to
3. Copy the
4. For Debian Based Linux: Run
Utku Sen,utku@utkusen.com
Bill Gates,bill@microsoft.com
After execution is completed, the following unique files will be generated:
test_project/files/Utku_Sen/secret.pdf
test_project/files/Bill_Gates/secret.pdf
By default, whol[...]
___________________________
@hacking_Attack
@Hacking_Video
Wholeaked : A File-Sharing Tool That Allows You To Find The Responsible Person In Case Of A Leakage
Wholeaked is a file-sharing tool that allows you to find the responsible person in case of a leakage. It’s written in Go. How?wholeaked gets the file that will be shared and a list of recipients. It creates a unique signature for each recipient and adds it to the file secretly. After then, it can automatically send files to the corresponding recipients by using Sendgrid, AWS SES or SMTP integrations. Instead of sending them by e-mail, you can also share them manually.
wholeaked works with every file type. However, it has additional features for common file types such as PDF, DOCX, MOV etc. Sharing Process+———–++———–+ / |Top Secret |
|Top Secret ||Recipient | / |.pdf |
|.pdf ||List | +———+ / | |
| || | |utkusen/ | / b@gov | |
| ||a@gov |—–>|wholeaked| /———-+ |
| ||b@gov | | | \ |Hidden |
| ||c@gov | +———+ \ |signature2 |
| || | \ +———–+
+———–++———–+ \ +———–+
\ |Top Secret |
\ |.pdf |
c@gov \ | |
\ | |
\ | |
\ |Hidden |
-|signature3 |
+———–+ Validation PartTo find who leaked the document, you just need to provide the leaked file to wholeaked, and it will reveal the responsible person by comparing the signatures in the database.
+———–+ +———+
|Top Secret | |Signature|
|.pdf | +———+|Database |
| | |utkusen/ || | Document leaked by
| |->|wholeaked|| |——–+
| | | || | b@gov
|Hidden | +———+| |
|Signature2 | | |
+———–+ +———+ File Types and Detection Modeswholeaked can add the unique signature to different sections of a file. Available detection modes are given below:
File Hash: SHA256 hash of the file. All file types are supported.
Binary: The signature is directly added to the binary. Almost all file types are supported.
Metadata: The signature is added to a metadata section of a file. Supported file types: PDF, DOCX, XLSX, PPTX, MOV, JPG, PNG, GIF, EPS, AI, PSD
Watermark: An invisible signature is inserted into the text. Only PDF files are supported. InstallationFrom BinaryYou can download the pre-built binaries from the releases page and run. For example:
unzip wholeaked_0.1.0_macOS_amd64.zip./wholeaked --helpFrom Source* Install Go on your system* Run:
go install github.com/utkusen/wholeaked@latestInstalling Dependencieswholeaked requires exiftoolfor adding signatures to metadata section of files. If you don’t want to use this feature, you don’t need to install it.1. Debian-based Linux: Run
apt install exiftool2. macOS: Run brew install exiftool3. Windows: Download exiftool from here https://exiftool.org/ and put the exiftool.exein the same directory with wholeaked.wholeaked requires
pdftotextfor verifying watermarks inside PDF files. If you don’t want to use this feature, you don’t need to install it.1. Download “Xpdf command line tools” for Linux, macOS or Windows from here: https://www.xpdfreader.com/download.html
2. Extract the archive and navigate to
bin64folder.3. Copy the
pdftotext(or pdftotext.exe) executable to the same folder with wholeaked4. For Debian Based Linux: Run
apt install libfontconfigcommand. UsageBasic Usagewholeaked requires a project name -n, the path of the base file which the signatures will add -fand a list of target recipients -tExample command: ./wholeaked -n test_project -f secret.pdf -t targets.txtThe targets.txtfile should contain name and the e-mail address in the following format:Utku Sen,utku@utkusen.com
Bill Gates,bill@microsoft.com
After execution is completed, the following unique files will be generated:
test_project/files/Utku_Sen/secret.pdf
test_project/files/Bill_Gates/secret.pdf
By default, whol[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Wholeaked : A File-Sharing Tool That Allows To Find Responsible Person
Wholeaked is a file-sharing tool that allows you to find the responsible person in case of a leakage. It's written in Go.