Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Maat : Open-source Symbolic Execution Framework
Maat is an open-source Dynamic Symbolic Execution and Binary Analysis framework. It provides various functionalities such as symbolic execution, taint analysis, constraint solving, binary loading, environment simulation, and leverages Ghidra’s sleigh library for assembly lifting: https://maat.re
Key Features
* Fast & Portable: Designed to scale to real-world applications. Fully written in C++ for good runtime performance. There are hardly any runtime dependencies, and most of them are optional
* User-friendly: Maat has a flexible debugger-like API, and its features are configurable to adapt to many different use-cases. As any self-respecting modern framework, it comes with Python bindings
* Multi-arch: With lifting and emulation based on Ghidra’s awesome sleigh library, Maat has the potential to emulate many architectures, including exotic ones
Installation
To install Maat’s python module:
python3 -m pip install pymaat
To install Maat’s native SDK and use the C++ API, check out BUILDING.md
Example
from maat import *
Create a symbolic engine for Linux X86-32bits
engine = MaatEngine(ARCH.X86, OS.LINUX)
Load a binary with one command line argument
engine.load(“./some_binary”, BIN.ELF32, args=[engine.vars.new_symbolic_buffer(“some_arg”, 20)])
Get current eax value
engine.cpu.eax
Read 4 bytes at the top of the stack
engine.mem.read(engine.cpu.esp, 4)
Set a callback displaying every memory read
def show_mem_access(engine):
mem_access = engine.info.mem_access
print(f”Instruction at {engine.info.addr} reads {mem_access.size} bytes at {mem_access.addr}”)
engine.hooks.add(EVENT.MEM_R, WHEN.BEFORE, callbacks=[show_mem_access])
Take and restore snapshots
snap = engine.take_snapshot()
engine.restore_snapshot(snap)
Run the binary
engine.run()
Download
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Maat : Open-source Symbolic Execution Framework
Maat is an open-source Dynamic Symbolic Execution and Binary Analysis framework. It provides various functionalities such as symbolic execution, taint analysis, constraint solving, binary loading, environment simulation, and leverages Ghidra’s sleigh library for assembly lifting: https://maat.re
Key Features
* Fast & Portable: Designed to scale to real-world applications. Fully written in C++ for good runtime performance. There are hardly any runtime dependencies, and most of them are optional
* User-friendly: Maat has a flexible debugger-like API, and its features are configurable to adapt to many different use-cases. As any self-respecting modern framework, it comes with Python bindings
* Multi-arch: With lifting and emulation based on Ghidra’s awesome sleigh library, Maat has the potential to emulate many architectures, including exotic ones
Installation
To install Maat’s python module:
python3 -m pip install pymaat
To install Maat’s native SDK and use the C++ API, check out BUILDING.md
Example
from maat import *
Create a symbolic engine for Linux X86-32bits
engine = MaatEngine(ARCH.X86, OS.LINUX)
Load a binary with one command line argument
engine.load(“./some_binary”, BIN.ELF32, args=[engine.vars.new_symbolic_buffer(“some_arg”, 20)])
Get current eax value
engine.cpu.eax
Read 4 bytes at the top of the stack
engine.mem.read(engine.cpu.esp, 4)
Set a callback displaying every memory read
def show_mem_access(engine):
mem_access = engine.info.mem_access
print(f”Instruction at {engine.info.addr} reads {mem_access.size} bytes at {mem_access.addr}”)
engine.hooks.add(EVENT.MEM_R, WHEN.BEFORE, callbacks=[show_mem_access])
Take and restore snapshots
snap = engine.take_snapshot()
engine.restore_snapshot(snap)
Run the binary
engine.run()
Download
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Maat : Open-source Symbolic Execution Framework
Maat is an open-source Dynamic Symbolic Execution and Binary Analysis framework. It provides various functionalities.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Melody : A Transparent Internet Sensor Built For Threat Intelligence
Melody is a transparent internet sensor built for threat intelligence and supported by a detection rule framework which allows you to tag packets of interest for further analysis and threat monitoring. FeaturesHere are some key features of Melody :
* Transparent capture
* Write detection rules and tag specific packets to analyze them at scale
* Mock vulnerable websites using the builtin HTTP/S server
* Supports the main internet protocols over IPv4 and IPv6
* Handles log rotation for you : Melody is designed to run forever on the smallest VPS
* Minimal configuration required
* Standalone mode : configure Melody using only the CLI
* Easily scalable :
* Statically compiled binary
* Up-to-date Docker image WishlistSince I have to focus on other projects right now, I can’t put much time in Melody’s development.
There is a lot of rom for improvement though, so here are some features that I’d like to implement someday :
* Dedicated helper program to create, test and manage rules -> Check Meloctl in
* Per port mock application Use casesInternet facing sensor* Extract trends and patterns from Internet’s noise
* Index malicious activity, exploitation attempts and targeted scanners
* Monitor emerging threats exploitation
* Keep an eye on specific threats Stream analysis* Build a background noise profile to make targeted attacks stand out
* Replay captures to tag malicious packets in a suspicious stream QuickstartTL;DRReleaseGet the latest release at
make install # Set default outfacing interface
make cap # Set network capabilities to start Melody without elevated privileges
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
make service # Create a systemd service to restart the program automatically and launch it at startup
sudo systemctl stop melody # Stop the service while we’re configuring it
Update the
sudo systemctl start melody # Start Melody
sudo systemctl status melody # Check that Melody is running
The logs should start to pile up in
tail -f /opt/melody/logs/melody.ndjson # | jq
From source
git clone https://github.com/bonjourmalware/melody /opt/melody
cd /opt/melody
make build
Then continue with the steps from the release TL;DR. Dockermake certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
mkdir -p /opt/melody/logs
cd /opt/melody/
docker pull bonjourmalware/melody:latest
MELODY_CLI=”” # Put your CLI options here. Example : export MELODY_CLI=”-s -i ‘lo’ -F ‘dst port 5555’ -o ‘server.http.port: 5555′”
docker run \
–net=host \
-e “MELODY_CLI=$MELODY_CLI” \
–mount type=bind,source=”$(pwd)/filter.bpf”,target=/app/filter.bpf,readonly \
–mount type=bind,source=”$(pwd)/config.yml”,target=/app/config.yml,readonly \
–mount type=bind,source=”$(pwd)/var”,target=/app/var,readonly \
–mount type=bind,source=”$(pwd)/rules”,target=/app/rules,readonly \
–mount type=bind,source=”$(pwd)/logs”,target=/app/logs/ \
bonjourmalware/melody RulesExampleCVE-2020-14882 Oracle Weblogic Server RCE:
layer: http
meta:
id: 3e1d86d8-fba6-4e15-8c74-941c3375fd3e
version: 1.0
author: BonjourMalware
status: stable
created: 2020/11/07
modified: 2020/20/07
description: “Checking or trying to exploit CVE-2020-14882”
references:
– “https://nvd.nist.gov/vuln/detail/CVE-2020-14882”
match:
http.uri:
startswith|any|nocase:
– “/console/css/”
– “/console/images”
contains|any|nocase:
– “console.portal”
– “consolejndi.portal?test_handle=”
tags:
cve: “cve-2020-14882”
vendor: “oracl[...]
___________________________
@hacking_Attack
@Hacking_Video
Melody : A Transparent Internet Sensor Built For Threat Intelligence
Melody is a transparent internet sensor built for threat intelligence and supported by a detection rule framework which allows you to tag packets of interest for further analysis and threat monitoring. FeaturesHere are some key features of Melody :
* Transparent capture
* Write detection rules and tag specific packets to analyze them at scale
* Mock vulnerable websites using the builtin HTTP/S server
* Supports the main internet protocols over IPv4 and IPv6
* Handles log rotation for you : Melody is designed to run forever on the smallest VPS
* Minimal configuration required
* Standalone mode : configure Melody using only the CLI
* Easily scalable :
* Statically compiled binary
* Up-to-date Docker image WishlistSince I have to focus on other projects right now, I can’t put much time in Melody’s development.
There is a lot of rom for improvement though, so here are some features that I’d like to implement someday :
* Dedicated helper program to create, test and manage rules -> Check Meloctl in
cmd/meloctl* Centralized rules management* Per port mock application Use casesInternet facing sensor* Extract trends and patterns from Internet’s noise
* Index malicious activity, exploitation attempts and targeted scanners
* Monitor emerging threats exploitation
* Keep an eye on specific threats Stream analysis* Build a background noise profile to make targeted attacks stand out
* Replay captures to tag malicious packets in a suspicious stream QuickstartTL;DRReleaseGet the latest release at
https://github.com/bonjourmalware/melody/releases.make install # Set default outfacing interface
make cap # Set network capabilities to start Melody without elevated privileges
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
make service # Create a systemd service to restart the program automatically and launch it at startup
sudo systemctl stop melody # Stop the service while we’re configuring it
Update the
filter.bpffile to filter out unwanted packetssudo systemctl start melody # Start Melody
sudo systemctl status melody # Check that Melody is running
The logs should start to pile up in
/opt/melody/logs/melody.ndjson.tail -f /opt/melody/logs/melody.ndjson # | jq
From source
git clone https://github.com/bonjourmalware/melody /opt/melody
cd /opt/melody
make build
Then continue with the steps from the release TL;DR. Dockermake certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
mkdir -p /opt/melody/logs
cd /opt/melody/
docker pull bonjourmalware/melody:latest
MELODY_CLI=”” # Put your CLI options here. Example : export MELODY_CLI=”-s -i ‘lo’ -F ‘dst port 5555’ -o ‘server.http.port: 5555′”
docker run \
–net=host \
-e “MELODY_CLI=$MELODY_CLI” \
–mount type=bind,source=”$(pwd)/filter.bpf”,target=/app/filter.bpf,readonly \
–mount type=bind,source=”$(pwd)/config.yml”,target=/app/config.yml,readonly \
–mount type=bind,source=”$(pwd)/var”,target=/app/var,readonly \
–mount type=bind,source=”$(pwd)/rules”,target=/app/rules,readonly \
–mount type=bind,source=”$(pwd)/logs”,target=/app/logs/ \
bonjourmalware/melody RulesExampleCVE-2020-14882 Oracle Weblogic Server RCE:
layer: http
meta:
id: 3e1d86d8-fba6-4e15-8c74-941c3375fd3e
version: 1.0
author: BonjourMalware
status: stable
created: 2020/11/07
modified: 2020/20/07
description: “Checking or trying to exploit CVE-2020-14882”
references:
– “https://nvd.nist.gov/vuln/detail/CVE-2020-14882”
match:
http.uri:
startswith|any|nocase:
– “/console/css/”
– “/console/images”
contains|any|nocase:
– “console.portal”
– “consolejndi.portal?test_handle=”
tags:
cve: “cve-2020-14882”
vendor: “oracl[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Melody : A Transparent Internet Sensor Built For Threat Intelligence
Melody is a transparent internet sensor built for threat intelligence and supported by a detection rule framework.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Melody : A Transparent Internet Sensor Built For Threat Intelligence Melody is a transparent internet sensor built for threat intelligence and supported by a detection rule framework which allows you to tag packets of interest for further…
e”
product: “weblogic”
impact: “rce” LogsExampleNetcat TCP packet over IPv4 :
{
“tcp”: {
“window”: 512,
“seq”: 1906765553,
“ack”: 2514263732,
“data_offset”: 8,
“flags”: “PA”,
“urgent”: 0,
“payload”: {
“content”: “I made a discovery today. I found a computer.\n”,
“base64”: “SSBtYWRlIGEgZGlzY292ZXJ5IHRvZGF5LiAgSSBmb3VuZCBhIGNvbXB1dGVyLgo=”,
“truncated”: false
}
},
“ip”: {
“version”: 4,
“ihl”: 5,
“tos”: 0,
“length”: 99,
“id”: 39114,
“fragbits”: “DF”,
“frag_offset”: 0,
“ttl”: 64,
“protocol”: 6
},
“timestamp”: “2020-11-16T15:50:01.277828+01:00”,
“session”: “bup9368o4skolf20rt8g”,
“type”: “tcp”,
“src_ip”: “127.0.0.1”,
“dst_port”: 1234,
“matches”: {},
“inline_matches”: [],
“embedded”: {}
} Download
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
product: “weblogic”
impact: “rce” LogsExampleNetcat TCP packet over IPv4 :
{
“tcp”: {
“window”: 512,
“seq”: 1906765553,
“ack”: 2514263732,
“data_offset”: 8,
“flags”: “PA”,
“urgent”: 0,
“payload”: {
“content”: “I made a discovery today. I found a computer.\n”,
“base64”: “SSBtYWRlIGEgZGlzY292ZXJ5IHRvZGF5LiAgSSBmb3VuZCBhIGNvbXB1dGVyLgo=”,
“truncated”: false
}
},
“ip”: {
“version”: 4,
“ihl”: 5,
“tos”: 0,
“length”: 99,
“id”: 39114,
“fragbits”: “DF”,
“frag_offset”: 0,
“ttl”: 64,
“protocol”: 6
},
“timestamp”: “2020-11-16T15:50:01.277828+01:00”,
“session”: “bup9368o4skolf20rt8g”,
“type”: “tcp”,
“src_ip”: “127.0.0.1”,
“dst_port”: 1234,
“matches”: {},
“inline_matches”: [],
“embedded”: {}
} Download
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
modifyCertTemplate : ADCS Cert Template Modification And ACL Enumeration
modifyCertTemplate tool is designed to aid an operator in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege escalation (and then reset the template to its previous state afterwards). This is specifically designed for a scenario where
[-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-ldaps]
target
Modify the attributes of an Active Directory certificate template
positional arguments:
target [[domain/]username[:password]
optional arguments:
-h, –help show this help message and exit
-template template name
Name of the target certificate template
-property property name
Name of the target template property
-value new value Value to set the specified template property to
-get-acl Print the certificate’s ACEs
-dn distinguished name
Explicitly set the distinguished name of the certificate template
-raw Output the raw certificate template attributes
-add flag name Add a flag to an attribute, maintaining the existing flags
-debug Turn DEBUG output ON
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don’t ask for password (useful for -k)
-k Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will
use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (128 or 256 bits)
connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-ldaps Use LDAPS instead of LDAP ExamplesQuerying a Template or Property ValueQuery a certificate template (all attributes)
python3 modifyCertTemplate.py -template KerberosAuthentication ez.lab/administrator:pass
Query a single attribute from a certificate template
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Query the raw values of all template attributes
python3 modifyCertTemplate.py -template KerberosAuthentication -raw ez.lab/administrator:pass Querying ACL InfoQuery the ACL for a certificate template
python3 modifyCertTemplate.py -template KerberosAuthentication -get-acl ez.lab/administrator:pass
Although unrelated to certificate templates, any object’s ACL can be queried by providing the object’s distinguished name
python3 modifyCertTemplate.py -dn “CN=ws1,CN=computers,DC=ez,DC=lab” -get-acl ez.lab/administrator:pass Modifying a TemplateAdd the
python3 modifyCertTemplate.py -template KerberosAuthentication -add enrollee_supplies_subject -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Update the value of a certificate template attribute (non-list properties)
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag -value -150994944 ez.lab/administrator:pass
Add an EKU to the
python3 modifyCertTemplate.py -template KerberosAuthentication -add “client authentication” -property pKIExtendedKeyUsage ez.lab/administrator:pass
Update the value of a list-formatted attribute (i.e. explicitly set the value of
python3 modifyCertTemplate.py -template KerberosAuthentication -value “‘1.3.6.1.5.5.7.3.4’, ‘1.3.6.1.5.5.7.3.2’” -property pKIExtendedKeyUsage ez.lab/administrator:pass Download
➖ Sent by @TheFeedReaderBot ➖
modifyCertTemplate : ADCS Cert Template Modification And ACL Enumeration
modifyCertTemplate tool is designed to aid an operator in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege escalation (and then reset the template to its previous state afterwards). This is specifically designed for a scenario where
WritePropertyrights over a template have been compromised, but the operator is unsure which properties the right applies to. In this scenairo, the template’s ACL can be queried and the applicable ACE information can be cross-referenced with property GUIDs to determine the modifiable properties. Usageusage: modifyCertTemplate.py [-h] -template template name [-property property name] [-value new value] [-get-acl] [-dn distinguished name] [-raw] [-add flag name] [-debug][-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-ldaps]
target
Modify the attributes of an Active Directory certificate template
positional arguments:
target [[domain/]username[:password]
optional arguments:
-h, –help show this help message and exit
-template template name
Name of the target certificate template
-property property name
Name of the target template property
-value new value Value to set the specified template property to
-get-acl Print the certificate’s ACEs
-dn distinguished name
Explicitly set the distinguished name of the certificate template
-raw Output the raw certificate template attributes
-add flag name Add a flag to an attribute, maintaining the existing flags
-debug Turn DEBUG output ON
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don’t ask for password (useful for -k)
-k Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will
use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (128 or 256 bits)
connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-ldaps Use LDAPS instead of LDAP ExamplesQuerying a Template or Property ValueQuery a certificate template (all attributes)
python3 modifyCertTemplate.py -template KerberosAuthentication ez.lab/administrator:pass
Query a single attribute from a certificate template
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Query the raw values of all template attributes
python3 modifyCertTemplate.py -template KerberosAuthentication -raw ez.lab/administrator:pass Querying ACL InfoQuery the ACL for a certificate template
python3 modifyCertTemplate.py -template KerberosAuthentication -get-acl ez.lab/administrator:pass
Although unrelated to certificate templates, any object’s ACL can be queried by providing the object’s distinguished name
python3 modifyCertTemplate.py -dn “CN=ws1,CN=computers,DC=ez,DC=lab” -get-acl ez.lab/administrator:pass Modifying a TemplateAdd the
ENROLLEE_SUPPLIES_SUBJECTflag to the template’s msPKI-Certificate-Name-Flagpropertypython3 modifyCertTemplate.py -template KerberosAuthentication -add enrollee_supplies_subject -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Update the value of a certificate template attribute (non-list properties)
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag -value -150994944 ez.lab/administrator:pass
Add an EKU to the
pKIExtendedKeyUsagepropertypython3 modifyCertTemplate.py -template KerberosAuthentication -add “client authentication” -property pKIExtendedKeyUsage ez.lab/administrator:pass
Update the value of a list-formatted attribute (i.e. explicitly set the value of
pKIExtendedKeyUsage)python3 modifyCertTemplate.py -template KerberosAuthentication -value “‘1.3.6.1.5.5.7.3.4’, ‘1.3.6.1.5.5.7.3.2’” -property pKIExtendedKeyUsage ez.lab/administrator:pass Download
➖ Sent by @TheFeedReaderBot ➖
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Shhhloader : SysWhispers Shellcode Loader
Shhhloader is a SysWhispers Shellcode Loader that is currently a Work in Progress. It takes raw shellcode as input and compiles a C++ stub that has been integrated with SysWhispers in order to bypass AV/EDR. The included python builder will work on any Linux system that has Mingw-w64 installed.
The tool has been confirmed to successfully load Meterpreter and a Cobalt Strike beacon on fully updated systems with Windows Defender enabled. The project itself is still in a PoC/WIP state, as it currently doesn’t work with all payloads.
2/9/22 EDIT: Shhhloader now includes 5 different ways to execute your shellcode! See below for updated usage. Big thanks to @Snovvcrash and their DInjector project for inspiration! I highly recommend taking a look at it for more information regarding the shellcode injection techniques and code that this tool is now based on.
┳┻|
┻┳|
┳┻|
┻┳|
┳┻| _
┻┳| •.•) – Shhhhh, AV might hear us!
┳┻|⊂ノ
┻┳|
usage: Shhhloader.py [-h] [-p explorer.exe] [-m QueueUserAPC] [-nr] [-v] [-d] [-o a.exe] file
ICYGUIDER’S CUSTOM SYSWHISPERS SHELLCODE LOADER
positional arguments:
file File containing raw shellcode
optional arguments:
-h, –help show this help message and exit
-p explorer.exe, –process explorer.exe
Process to inject into (Default: explorer.exe)
-m QueueUserAPC, –method QueueUserAPC
Method for shellcode execution (Options: ProcessHollow, QueueUserAPC,
RemoteThreadContext, RemoteThreadSuspended, CurrentThread) (Default: QueueUserAPC)
-nr, –no-randomize Disable syscall name randomization
-v, –verbose Enable debugging messages upon execution
-d, –dll-sandbox Use DLL based sandbox checks instead of the standard ones
-o a.exe, –outfile a.exe
Name of compiled file
Features
* 5 Different Shellcode Execution Methods (ProcessHollow, QueueUserAPC, RemoteThreadContext, RemoteThreadSuspended, CurrentThread)
* PPID Spoofing
* Block 3rd Party DLLs
* Syscall Name Randomization
* XOR Encryption with Dynamic Key Generation
* Sandbox Evasion via Loaded DLL Enumeration
* Sandbox Evasion via Checking Processors, Memory, and Time
Tested and Confirmed Working on:
* Windows 10 21H1 (10.0.19043)
* Windows 10 20H2 (10.0.19042)
* Windows Server 2019 (10.0.17763)
Download
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Shhhloader : SysWhispers Shellcode Loader
Shhhloader is a SysWhispers Shellcode Loader that is currently a Work in Progress. It takes raw shellcode as input and compiles a C++ stub that has been integrated with SysWhispers in order to bypass AV/EDR. The included python builder will work on any Linux system that has Mingw-w64 installed.
The tool has been confirmed to successfully load Meterpreter and a Cobalt Strike beacon on fully updated systems with Windows Defender enabled. The project itself is still in a PoC/WIP state, as it currently doesn’t work with all payloads.
2/9/22 EDIT: Shhhloader now includes 5 different ways to execute your shellcode! See below for updated usage. Big thanks to @Snovvcrash and their DInjector project for inspiration! I highly recommend taking a look at it for more information regarding the shellcode injection techniques and code that this tool is now based on.
┳┻|
┻┳|
┳┻|
┻┳|
┳┻| _
┻┳| •.•) – Shhhhh, AV might hear us!
┳┻|⊂ノ
┻┳|
usage: Shhhloader.py [-h] [-p explorer.exe] [-m QueueUserAPC] [-nr] [-v] [-d] [-o a.exe] file
ICYGUIDER’S CUSTOM SYSWHISPERS SHELLCODE LOADER
positional arguments:
file File containing raw shellcode
optional arguments:
-h, –help show this help message and exit
-p explorer.exe, –process explorer.exe
Process to inject into (Default: explorer.exe)
-m QueueUserAPC, –method QueueUserAPC
Method for shellcode execution (Options: ProcessHollow, QueueUserAPC,
RemoteThreadContext, RemoteThreadSuspended, CurrentThread) (Default: QueueUserAPC)
-nr, –no-randomize Disable syscall name randomization
-v, –verbose Enable debugging messages upon execution
-d, –dll-sandbox Use DLL based sandbox checks instead of the standard ones
-o a.exe, –outfile a.exe
Name of compiled file
Features
* 5 Different Shellcode Execution Methods (ProcessHollow, QueueUserAPC, RemoteThreadContext, RemoteThreadSuspended, CurrentThread)
* PPID Spoofing
* Block 3rd Party DLLs
* Syscall Name Randomization
* XOR Encryption with Dynamic Key Generation
* Sandbox Evasion via Loaded DLL Enumeration
* Sandbox Evasion via Checking Processors, Memory, and Time
Tested and Confirmed Working on:
* Windows 10 21H1 (10.0.19043)
* Windows 10 20H2 (10.0.19042)
* Windows Server 2019 (10.0.17763)
Download
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Shhhloader : SysWhispers Shellcode Loader !!! Kali Linux Tutorials
Shhhloader is a SysWhispers Shellcode Loader that is currently a Work in Progress. It takes raw shellcode as input and compiles a C++.
hacking: security in practice
Can a virus hidden as a picture or text document on a pc that you're connecting to remotely infect your machine
Can a virus hidden as a picture or text document on a pc that you're connecting to remotely infect your machine?
If so, can someone please explain how?
Picture this scenario for context: A remote user attempts to open a text document titled "bank details" and it infects their pc (the remote user) with a rat (remote administration tool) which the other user could then use to gain access later on without knowledge.
What is the best way to do this?
submitted by /u/Repulsive_Problem272
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can a virus hidden as a picture or text document on a pc that you're connecting to remotely infect your machine
Can a virus hidden as a picture or text document on a pc that you're connecting to remotely infect your machine?
If so, can someone please explain how?
Picture this scenario for context: A remote user attempts to open a text document titled "bank details" and it infects their pc (the remote user) with a rat (remote administration tool) which the other user could then use to gain access later on without knowledge.
What is the best way to do this?
submitted by /u/Repulsive_Problem272
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can a virus hidden as a picture or text document on a pc that...
Can a virus hidden as a picture or text document on a pc that you're connecting to remotely infect your machine? If so, can someone please...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Windows Subsystem For Linux Virus Steals Browser Auth Cookies
https://external-preview.redd.it/g1dtaOhvBUpH1oqaev0bAQLebIyIqYw-BfweUgtPlZI.jpg?width=640&crop=smart&auto=webp&s=2a0ab65eafe3fa44cae0c588c09ede3b77bb4d53 submitted by /u/Dip14099
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Windows Subsystem For Linux Virus Steals Browser Auth Cookies
https://external-preview.redd.it/g1dtaOhvBUpH1oqaev0bAQLebIyIqYw-BfweUgtPlZI.jpg?width=640&crop=smart&auto=webp&s=2a0ab65eafe3fa44cae0c588c09ede3b77bb4d53 submitted by /u/Dip14099
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Windows Subsystem For Linux Virus Steals Browser Auth Cookies
Posted in r/hacking by u/Dip14099 • 1 point and 0 comments
hacking: security in practice
Anybody want some low profile hacking tech? (Hardware)
If you want some high quality, low profile hacking tech like packet sniffers, key loggers, or general hacking usb (like the rubber ducky on Mr. Robot) start a chat with me and I’ll give you a link to a website.
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anybody want some low profile hacking tech? (Hardware)
If you want some high quality, low profile hacking tech like packet sniffers, key loggers, or general hacking usb (like the rubber ducky on Mr. Robot) start a chat with me and I’ll give you a link to a website.
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anybody want some low profile hacking tech? (Hardware)
If you want some high quality, low profile hacking tech like packet sniffers, key loggers, or general hacking usb (like the rubber ducky on Mr....
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Windows Exploitation Resources
https://github.com/FULLSHADE/WindowsExploitationResources
READ
submitted by /u/saqfi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Windows Exploitation Resources
https://github.com/FULLSHADE/WindowsExploitationResources
READ
submitted by /u/saqfi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Windows Exploitation Resources
[https://github.com/FULLSHADE/WindowsExploitationResources](https://github.com/FULLSHADE/WindowsExploitationResources) ***READ***
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Domain Escalation: Unconstrained Delegation
IntroductionPost-Windows 2000, Microsoft introduced an option where users could authenticate to one system via Kerberos and work with another system. This was made possible via the delegation option. Unconstrained delegation is achieved via TGT forwarding technique which is what we’ll talk about in this article. Kerberos DelegationKerberos Delegation enables a service to impersonate a computer or user in order to engage with a second service using the user’s privileges and permissions.
The classic illustration of why delegating is necessary, for instance when a user authenticates to a web server using Kerberos or other protocols, and the server wishes to interact with a SQL backend or file server.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiT6dkXPLddG5IuKSagZR5txZ9p5bLDh32OrC3BxJJb_XiZCBEFRfPmvSA8dKfgAFqBzCztEpTUjjkJ3KH7MXd6MORZzXEqOBefk3gwqKjKioiB1vOA6dMsDEO5KgtRFo5IjLy24Ibus1hyhZXiBh5qaiJUhCOt7xlqhj4lhSHpfz7bq-NWB3OuFN1XGw/s16000/0.1.png
Type of Kerberos Delegation:
* Unconstrained delegation
* Constrained delegation
* RBCD (Resource-Based Constrained Delegation) Service Principal NameA unique name (identifier) of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have an account name. Unconstrained DelegationThe feature debuted initially in Windows Server 2000 but it is still there for backwards compatibility. Basically, if a user requests a service ticket for a service on a server set with unconstrained delegation, that server will extract the user’s TGT and cache it in its memory for later use. This means the server can pretend to be that user to any resource on the domain.
On a computer account, an admin can set the following property for unconstrained delegation.
* AD Users and Computers -> Computers -> Trust this computer for delegation to any service.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXngS6FPbtTdwbHQ687LfOcd_uZABKNSedSHmsro5f3SgCVKyjgItHMwPAoP6HS-9E8_kycr7VmDrwh7FQ4ocyg-R5o46Lncuo3-cLi_J4URGZ5aklxjW8v6Zz2o5pRAI5SGptpRRD0wiqQe2cweaI1-fNhF9XUoKrjAZri2nnOdd9_sCwOT75_pvSWA/s16000/0.png
Key features of the unconstrained delegation are:
* Usually, the privilege is given to computers running services like IIS, and MSSQL because these computers usually require some back-end connectivity to other resources.
* When given Delegation rights, these computers ask for a user’s TGT and store them in their cached memory.
* With this TGT, they can access back-end resources on behalf of the authenticated user.
* Catch is that these systems can also request access to any resource on the domain using this TGT!
* https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqFAGuNirtaPHgWk_LvIt9f-qm8EJwKOdqfzL_wzG-Qr_5En7FzemiCuQBNGXfWxOJ1Zse_1A2zduOZLsMb2NJrDINCVtSPmGfosm0icublTCa4ZJmngjYJzIOcu5txGUQl8Eo62XbMGlBlobsRR9gRUO9Un3Ih1YQVOeJoBHva3GDI6Bf3JQhn02UMg/s16000/0.2.png
An attacker may Abuse Unconstrained Delegation by requesting TGS for any domain services (SPN) using user delegated TGT.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiE4Wvh2cFkn0IbfCy2Gz9rPLB03qMnHJAW6q3pJ10ccC7Pu3TUvAT6JxiNfRCKMDcJUVJu_TDh2D2kHD00POOd28EGW9xaKPvxmm6SvKxyCqoWHQ7pIJvkKr0VnlRb8R6kkMB2Nsp93__hiCLnH-P-s1bRIVUEaTGsk4fJOQp5X0Ka3mEpHNTnt4qNA/s16000/0.3.png TGT extraction via Unconstrained DelegationIt is obvious that we need to run our attack on the machine that has delegation enabled. So we are assuming the attacker has compromised one such machine. Assumption 1: Attacker compromised DC1$ system running IIS on Kerberos authentication.
* Assumption 2: Attacker has access to a domain-joined system (Here, powershell window running on that s[...]
___________________________
@hacking_Attack
@Hacking_Video
Domain Escalation: Unconstrained Delegation
IntroductionPost-Windows 2000, Microsoft introduced an option where users could authenticate to one system via Kerberos and work with another system. This was made possible via the delegation option. Unconstrained delegation is achieved via TGT forwarding technique which is what we’ll talk about in this article. Kerberos DelegationKerberos Delegation enables a service to impersonate a computer or user in order to engage with a second service using the user’s privileges and permissions.
The classic illustration of why delegating is necessary, for instance when a user authenticates to a web server using Kerberos or other protocols, and the server wishes to interact with a SQL backend or file server.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiT6dkXPLddG5IuKSagZR5txZ9p5bLDh32OrC3BxJJb_XiZCBEFRfPmvSA8dKfgAFqBzCztEpTUjjkJ3KH7MXd6MORZzXEqOBefk3gwqKjKioiB1vOA6dMsDEO5KgtRFo5IjLy24Ibus1hyhZXiBh5qaiJUhCOt7xlqhj4lhSHpfz7bq-NWB3OuFN1XGw/s16000/0.1.png
Type of Kerberos Delegation:
* Unconstrained delegation
* Constrained delegation
* RBCD (Resource-Based Constrained Delegation) Service Principal NameA unique name (identifier) of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have an account name. Unconstrained DelegationThe feature debuted initially in Windows Server 2000 but it is still there for backwards compatibility. Basically, if a user requests a service ticket for a service on a server set with unconstrained delegation, that server will extract the user’s TGT and cache it in its memory for later use. This means the server can pretend to be that user to any resource on the domain.
On a computer account, an admin can set the following property for unconstrained delegation.
* AD Users and Computers -> Computers -> Trust this computer for delegation to any service.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXngS6FPbtTdwbHQ687LfOcd_uZABKNSedSHmsro5f3SgCVKyjgItHMwPAoP6HS-9E8_kycr7VmDrwh7FQ4ocyg-R5o46Lncuo3-cLi_J4URGZ5aklxjW8v6Zz2o5pRAI5SGptpRRD0wiqQe2cweaI1-fNhF9XUoKrjAZri2nnOdd9_sCwOT75_pvSWA/s16000/0.png
Key features of the unconstrained delegation are:
* Usually, the privilege is given to computers running services like IIS, and MSSQL because these computers usually require some back-end connectivity to other resources.
* When given Delegation rights, these computers ask for a user’s TGT and store them in their cached memory.
* With this TGT, they can access back-end resources on behalf of the authenticated user.
* Catch is that these systems can also request access to any resource on the domain using this TGT!
* https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqFAGuNirtaPHgWk_LvIt9f-qm8EJwKOdqfzL_wzG-Qr_5En7FzemiCuQBNGXfWxOJ1Zse_1A2zduOZLsMb2NJrDINCVtSPmGfosm0icublTCa4ZJmngjYJzIOcu5txGUQl8Eo62XbMGlBlobsRR9gRUO9Un3Ih1YQVOeJoBHva3GDI6Bf3JQhn02UMg/s16000/0.2.png
An attacker may Abuse Unconstrained Delegation by requesting TGS for any domain services (SPN) using user delegated TGT.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiE4Wvh2cFkn0IbfCy2Gz9rPLB03qMnHJAW6q3pJ10ccC7Pu3TUvAT6JxiNfRCKMDcJUVJu_TDh2D2kHD00POOd28EGW9xaKPvxmm6SvKxyCqoWHQ7pIJvkKr0VnlRb8R6kkMB2Nsp93__hiCLnH-P-s1bRIVUEaTGsk4fJOQp5X0Ka3mEpHNTnt4qNA/s16000/0.3.png TGT extraction via Unconstrained DelegationIt is obvious that we need to run our attack on the machine that has delegation enabled. So we are assuming the attacker has compromised one such machine. Assumption 1: Attacker compromised DC1$ system running IIS on Kerberos authentication.
* Assumption 2: Attacker has access to a domain-joined system (Here, powershell window running on that s[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Domain Escalation: Unconstrained Delegation
Learn how attackers exploit Unconstrained Delegation in Active Directory to extract TGTs and escalate domain privileges.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles Domain Escalation: Unconstrained Delegation IntroductionPost-Windows 2000, Microsoft introduced an option where users could authenticate to one system via Kerberos and work with another system. This was made possible via the delegation option.…
ystem)
* User: Administrator
Now, in real-life scenario, you might not have direct access to the DC system for simplicity we have installed IIS on DC and using that only so that you get the gist.
Moving on with our extraction, we need to learn the systems that have unconstrained delegation enabled. This can be done by using PowerShell and AD module.
Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Properties trustedfordelegation,serviceprincipalname,description
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVnK7rS34mzNVUEiA9a8iFu-AWGIa1769BQ5rhHzo4SP7EbvihjQp8w8dUSECl3vxQYp3YZxsWhPRRj9yQnycufs-Oz0puzoYimptCyRR-tvb4yd2v2vdA4vyK4GEZOTf5BNPMidKow9FWbIIoVooMsbXuYDHAr_psusYrohNuoHGHfzlimbxJvJXKBQ/s16000/1.png
The same can also be achieved by using the powerview script which is part of the PowerSploit framework created for offensive security using PowerShell. You can find it here.
Once an AD system is compromised, you can install and use powerview.
Import-Module .\powerview.ps1
Get-NetComputer -Unconstrained
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6OQ9WL5m9pj7MTD6OV-I3k1JRSPYRi_oNLBHHBTbDLlKs20gkF7ucGDcc2e_P6FlLq1wOxv15MgqpAhkFV5xxV-N0G749iWdV3Tr1Bj77-xfFSUqrb8MKnvOOgO5-4SaLmdAOqmRIHkfeVue6F4_0WKwn1qBFAOaCd-30xxHDJO13r3VepawQDneUAA/s16000/2.png
Now, on the target system we need to run Rubeus in monitor mode on the dc1 system. After that, whenever a user connects/authenticates to dc1$ Rubeus will dump TGT of the user.
rubeus.exe monitor /monitorinterval:10 /targetuser:dc1$ /nowrap
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiI9fqrYrtznEJtRXkIbdKMbwUatKKh_PeDTxcSpTgotlMeT4oj6ytWQOXV8nxKW9oJLHKNiEEnJML5en_gSdXMREzbULMa19Tz48ZUsq-dalm7uBdDWTX3tGG3iK7OL33qWxnKhcij6u9kUfFtZP6kPRQkrpY5bT6IPk-1UsnY6RtlE-O0C9f62i2AXg/s16000/3.png
Now, let’s wait for genuine users to connect to dc1$ running IIS service. For simplicity, let’s do that manually using the IWR module.
Invoke-WebRequest http://dc1.offense.local -UseDefaultCredentials -UseBasicParsing
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgp_YUQfI-8qvUbBWr9ife7GS2VzpcXEi97j6Xci64URJ1-nugreRG3ljY8DRP8kwxlCIYfdGz_CEuETmTQL6zqRHRH1LmvI8LpOz-o5gIADMM3VbC3DRD0Pzu6K0tTpgxApaPS_ZV2dsdnI0QoHgB7Oxesv9eMwLdttMpvhLqThgdY072ubnIcITj0Mg/s16000/4.png
As you can see, Rubeus has now captured a new ticket granting ticket (TGT) from the user IGNITE\Administrator.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-nDccubWmWTErFBCqYxzNhZTWpDkhP-iTwG4ntW-SaJhyG9nmBcNOsMqk2wpD_YZZWqs3C-I10whKM6wgcqnyUAAxrwpT9HeMFbOP8UNr2NZmMSzxMQwO6AvC6D3KMaG5zHwAuYTJneVJcHmTVi_uuKzrYOZI02k0cNY-gj184-CfG6pAp4aTyMdu7w/s16000/5.png
Now, you can use this TGT to request access to any resource by requesting a TGS to that resource. You can use Rubeus asktgs for that purpose. Follow the detailed Rubeus guide here for more. ConclusionThe article demonstrated a delegation technique called Unconstrained Delegation because as the name suggests, there are no restrictions upon how the system that has delegation rights use a user’s authentication information. The security loopholes made Microsoft introduce Constrained Delegation. You’ll read more about that in the next article. Hope you liked the article. Thanks for reading.
References: https://www.harmj0y.net/blog/activedirectory/
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post Domain Escalation: Unconstrained Delegation appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
* User: Administrator
Now, in real-life scenario, you might not have direct access to the DC system for simplicity we have installed IIS on DC and using that only so that you get the gist.
Moving on with our extraction, we need to learn the systems that have unconstrained delegation enabled. This can be done by using PowerShell and AD module.
Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Properties trustedfordelegation,serviceprincipalname,description
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVnK7rS34mzNVUEiA9a8iFu-AWGIa1769BQ5rhHzo4SP7EbvihjQp8w8dUSECl3vxQYp3YZxsWhPRRj9yQnycufs-Oz0puzoYimptCyRR-tvb4yd2v2vdA4vyK4GEZOTf5BNPMidKow9FWbIIoVooMsbXuYDHAr_psusYrohNuoHGHfzlimbxJvJXKBQ/s16000/1.png
The same can also be achieved by using the powerview script which is part of the PowerSploit framework created for offensive security using PowerShell. You can find it here.
Once an AD system is compromised, you can install and use powerview.
Import-Module .\powerview.ps1
Get-NetComputer -Unconstrained
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6OQ9WL5m9pj7MTD6OV-I3k1JRSPYRi_oNLBHHBTbDLlKs20gkF7ucGDcc2e_P6FlLq1wOxv15MgqpAhkFV5xxV-N0G749iWdV3Tr1Bj77-xfFSUqrb8MKnvOOgO5-4SaLmdAOqmRIHkfeVue6F4_0WKwn1qBFAOaCd-30xxHDJO13r3VepawQDneUAA/s16000/2.png
Now, on the target system we need to run Rubeus in monitor mode on the dc1 system. After that, whenever a user connects/authenticates to dc1$ Rubeus will dump TGT of the user.
rubeus.exe monitor /monitorinterval:10 /targetuser:dc1$ /nowrap
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiI9fqrYrtznEJtRXkIbdKMbwUatKKh_PeDTxcSpTgotlMeT4oj6ytWQOXV8nxKW9oJLHKNiEEnJML5en_gSdXMREzbULMa19Tz48ZUsq-dalm7uBdDWTX3tGG3iK7OL33qWxnKhcij6u9kUfFtZP6kPRQkrpY5bT6IPk-1UsnY6RtlE-O0C9f62i2AXg/s16000/3.png
Now, let’s wait for genuine users to connect to dc1$ running IIS service. For simplicity, let’s do that manually using the IWR module.
Invoke-WebRequest http://dc1.offense.local -UseDefaultCredentials -UseBasicParsing
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgp_YUQfI-8qvUbBWr9ife7GS2VzpcXEi97j6Xci64URJ1-nugreRG3ljY8DRP8kwxlCIYfdGz_CEuETmTQL6zqRHRH1LmvI8LpOz-o5gIADMM3VbC3DRD0Pzu6K0tTpgxApaPS_ZV2dsdnI0QoHgB7Oxesv9eMwLdttMpvhLqThgdY072ubnIcITj0Mg/s16000/4.png
As you can see, Rubeus has now captured a new ticket granting ticket (TGT) from the user IGNITE\Administrator.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-nDccubWmWTErFBCqYxzNhZTWpDkhP-iTwG4ntW-SaJhyG9nmBcNOsMqk2wpD_YZZWqs3C-I10whKM6wgcqnyUAAxrwpT9HeMFbOP8UNr2NZmMSzxMQwO6AvC6D3KMaG5zHwAuYTJneVJcHmTVi_uuKzrYOZI02k0cNY-gj184-CfG6pAp4aTyMdu7w/s16000/5.png
Now, you can use this TGT to request access to any resource by requesting a TGS to that resource. You can use Rubeus asktgs for that purpose. Follow the detailed Rubeus guide here for more. ConclusionThe article demonstrated a delegation technique called Unconstrained Delegation because as the name suggests, there are no restrictions upon how the system that has delegation rights use a user’s authentication information. The security loopholes made Microsoft introduce Constrained Delegation. You’ll read more about that in the next article. Hope you liked the article. Thanks for reading.
References: https://www.harmj0y.net/blog/activedirectory/
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post Domain Escalation: Unconstrained Delegation appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
BinAbsInspector - Vulnerability Scanner For Binaries
http://www.kitploit.com/2022/05/binabsinspector-vulnerability-scanner.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/binabsinspector-vulnerability-scanner.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
BinAbsInspector - Vulnerability Scanner For Binaries
BinAbsInspector (Binary Abstract Inspector) is a static analyzer (https://www.kitploit.com/search/label/Static%20Analyzer) for automated reverse engineering (https://www.kitploit.com/search/label/Reverse%20Engineering) and scanning vulnerabilities in binaries, which is a long-term research project (https://www.kitploit.com/search/label/Research%20Project) incubated at Keenlab (https://keenlab.tencent.com/). It is based on abstract interpretation (https://www.kitploit.com/search/label/Abstract%20Interpretation) with the support from Ghidra. It works on Ghidra's Pcode instead of assembly. Currently it supports binaries on x86,x64, armv7 and aarch64.
Installation Install Ghidra according to Ghidra's documentation (https://github.com/NationalSecurityAgency/ghidra#install) Install Z3 (https://github.com/Z3Prover/z3) (tested version: 4.8.15) Note that generally there are two parts for Z3 library: one is Java package, the other one is native library. The Java package is already included in "/lib" directory, but we suggest that you replace it with your own Java package for version compatibility. For Windows, download a pre-built package from here (https://github.com/Z3Prover/z3/releases), extract the zip file and add a PATH environment variable pointing to z3-${version}-win/bin For Linux, install with package manager is NOT recommended, there are two options: You can download suitable pre-build package from here (https://github.com/Z3Prover/z3/releases), extract the zip file and copy z3-${version}-win/bin/*.so to /usr/local/lib/ or you can build and install z3 according to Building Z3 using make and GCC/Clang (https://github.com/Z3Prover/z3#building-z3-using-make-and-gccclang) For MacOS, it is similar to Linux. Download the extension zip file from release page (https://github.com/KeenSecurityLab/BinAbsInspector/releases) Install the extension according to Ghidra Extension Notes (https://ghidra-sre.org/InstallationGuide.html#GhidraExtensionNotes) Building Build the extension by yourself, if you want to develop a new feature, please refer to development guide (https://github.com/KeenSecurityLab/BinAbsInspector/wiki/Developer-Guide). Install Ghidra and Z3 Install Gradle 7.x (https://gradle.org/releases/) (tested version: 7.4) Pull the repository Run gradle buildExtension under repository root The extension will be generated at dist/${GhidraVersion}_${date}_BinAbsInspector.zip Usage You can run BinAbsInspector in headless mode, GUI mode, or with docker. With Ghidra headless mode. $GHIDRA_INSTALL_DIR/support/analyzeHeadless -import -postScript BinAbsInspector "@@"
-- Ghidra project path.
-- Ghidra project name.
-- The argument for our analyzer, provides following options: Parameter Description [-K ] KSet size limit K (https://github.com/KeenSecurityLab/BinAbsInspector/wiki/Technical-Details#kset) [-callStringK ] Call string maximum length K (https://github.com/KeenSecurityLab/BinAbsInspector/wiki/Technical-Details#context) [-Z3Timeout ] Z3 timeout [-timeout ] Analysis timeout [-entry ] Entry address [-externalMap ] External function model config [-json] Output in json format [-disableZ3] Disable Z3 [-all] Enable all checkers [-debug] Enable debugging log output [-check "[;...]"] Enable specific checkers With Ghidra GUI Run Ghidra and import the target binary into a project Analyze the binary with default settings When the analysis is done, open Window -> Script Manager and find BinAbsInspector.java Double-click on BinAbsInspector.java entry, set the parameters in configuration window and click OK When the analysis is done, you can see the CWE reports in console window, double-click the addresses from the report can jump to corresponding address With Docker " -import '>git clone git@github.com:KeenSecurityLab/BinAbsInspector.git
cd BinAbsInspector
docker build . -t bai
___________________________
@hacking_Attack
@Hacking_Video
Installation Install Ghidra according to Ghidra's documentation (https://github.com/NationalSecurityAgency/ghidra#install) Install Z3 (https://github.com/Z3Prover/z3) (tested version: 4.8.15) Note that generally there are two parts for Z3 library: one is Java package, the other one is native library. The Java package is already included in "/lib" directory, but we suggest that you replace it with your own Java package for version compatibility. For Windows, download a pre-built package from here (https://github.com/Z3Prover/z3/releases), extract the zip file and add a PATH environment variable pointing to z3-${version}-win/bin For Linux, install with package manager is NOT recommended, there are two options: You can download suitable pre-build package from here (https://github.com/Z3Prover/z3/releases), extract the zip file and copy z3-${version}-win/bin/*.so to /usr/local/lib/ or you can build and install z3 according to Building Z3 using make and GCC/Clang (https://github.com/Z3Prover/z3#building-z3-using-make-and-gccclang) For MacOS, it is similar to Linux. Download the extension zip file from release page (https://github.com/KeenSecurityLab/BinAbsInspector/releases) Install the extension according to Ghidra Extension Notes (https://ghidra-sre.org/InstallationGuide.html#GhidraExtensionNotes) Building Build the extension by yourself, if you want to develop a new feature, please refer to development guide (https://github.com/KeenSecurityLab/BinAbsInspector/wiki/Developer-Guide). Install Ghidra and Z3 Install Gradle 7.x (https://gradle.org/releases/) (tested version: 7.4) Pull the repository Run gradle buildExtension under repository root The extension will be generated at dist/${GhidraVersion}_${date}_BinAbsInspector.zip Usage You can run BinAbsInspector in headless mode, GUI mode, or with docker. With Ghidra headless mode. $GHIDRA_INSTALL_DIR/support/analyzeHeadless -import -postScript BinAbsInspector "@@"
-- Ghidra project path.
-- Ghidra project name.
-- The argument for our analyzer, provides following options: Parameter Description [-K ] KSet size limit K (https://github.com/KeenSecurityLab/BinAbsInspector/wiki/Technical-Details#kset) [-callStringK ] Call string maximum length K (https://github.com/KeenSecurityLab/BinAbsInspector/wiki/Technical-Details#context) [-Z3Timeout ] Z3 timeout [-timeout ] Analysis timeout [-entry ] Entry address [-externalMap ] External function model config [-json] Output in json format [-disableZ3] Disable Z3 [-all] Enable all checkers [-debug] Enable debugging log output [-check "[;...]"] Enable specific checkers With Ghidra GUI Run Ghidra and import the target binary into a project Analyze the binary with default settings When the analysis is done, open Window -> Script Manager and find BinAbsInspector.java Double-click on BinAbsInspector.java entry, set the parameters in configuration window and click OK When the analysis is done, you can see the CWE reports in console window, double-click the addresses from the report can jump to corresponding address With Docker " -import '>git clone git@github.com:KeenSecurityLab/BinAbsInspector.git
cd BinAbsInspector
docker build . -t bai
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.