Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
I Need A Hacker To Change My University Grades
I need a hacker to change my university grades, changing university/college grades is not a game, it requires professional hacking skills…
Continue reading on Medium »
I Need A Hacker To Change My University Grades
I need a hacker to change my university grades, changing university/college grades is not a game, it requires professional hacking skills…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Las alertas de Google siguen siendo un hervidero de estafas y malware.
https://cdn-images-1.medium.com/max/1262/0*ud7T4c6BWLhUcUkM
PUBLICADO EN 19 ABRIL, 2021 POR EHACKING
Continue reading on Medium »
Las alertas de Google siguen siendo un hervidero de estafas y malware.
https://cdn-images-1.medium.com/max/1262/0*ud7T4c6BWLhUcUkM
PUBLICADO EN 19 ABRIL, 2021 POR EHACKING
Continue reading on Medium »
List of ngrok alternatives and other ngrok-like tunneling software and services. Focus on self-hosting.#ssh #ngrok #tunneling
@club1337 #club1337
https://github.com/anderspitman/awesome-tunneling
GitHub
GitHub - anderspitman/awesome-tunneling: List of ngrok, Cloudflare Tunnel, Tailscale, and ZeroTier alternatives and other tunneling…
List of ngrok, Cloudflare Tunnel, Tailscale, and ZeroTier alternatives and other tunneling software and services. Focus on self-hosting. - anderspitman/awesome-tunneling
Hacking Articles Tips Tricks Videos Tutorials pinned «KitPloit - PenTest Tools! Modded-Ubuntu - Run Ubuntu GUI On Your Termux With Much Features https://1.bp.blogspot.com/-Rcz1QD-c31s/YHpMlkQB04I/AAAAAAAAV5g/kU4EDdCPUlAgJ94DfGhQMUt7FVUawowiwCNcBGAsYHQ/w640-h288/modded-ubuntu_1_image.jpeg Run Ubuntu GUI on your…»
hacking: security in practice
WiFi “Phishing”
A building I am pentesting has a peculiar WiFi system with a potential vulnerability. To log into their WiFi, you enter your company domain email and password (directly into the connection area). Not sure if they have all the valid emails and passwords saved in a database which they then check for a match when you login, or if they forward the info to their own website.
My pentest idea is to phish credentials by: Configure my own fake WiFi under the name “faster [real wifi name]” and have the info automatically forward to my own website, then place the router in a popular building area.
The problem is, I have no idea how to configure a router like this. Could anyone link me to a video on how to do this, or explain it to me? I have virtually 0 pentesting knowledge, so I do not even know is this idea is viable.
submitted by /u/fartsmellerhaha
[link] [comments]
WiFi “Phishing”
A building I am pentesting has a peculiar WiFi system with a potential vulnerability. To log into their WiFi, you enter your company domain email and password (directly into the connection area). Not sure if they have all the valid emails and passwords saved in a database which they then check for a match when you login, or if they forward the info to their own website.
My pentest idea is to phish credentials by: Configure my own fake WiFi under the name “faster [real wifi name]” and have the info automatically forward to my own website, then place the router in a popular building area.
The problem is, I have no idea how to configure a router like this. Could anyone link me to a video on how to do this, or explain it to me? I have virtually 0 pentesting knowledge, so I do not even know is this idea is viable.
submitted by /u/fartsmellerhaha
[link] [comments]
reddit
WiFi “Phishing”
A building I am pentesting has a peculiar WiFi system with a potential vulnerability. To log into their WiFi, you enter your company domain email...
hacking: security in practice
what is grey hat hacking?
I was wondering if it is kind of like black hat or white hat.
submitted by /u/SnooRevelations4180
[link] [comments]
what is grey hat hacking?
I was wondering if it is kind of like black hat or white hat.
submitted by /u/SnooRevelations4180
[link] [comments]
reddit
what is grey hat hacking?
I was wondering if it is kind of like black hat or white hat.
hacking: security in practice
Hacking lab!
What is an Ideal setup for a hacking lab when using tryhackme or hackthebox? Do you use VPN? Or just VM's On a NAT'd network?
submitted by /u/the_only_butchog
[link] [comments]
Hacking lab!
What is an Ideal setup for a hacking lab when using tryhackme or hackthebox? Do you use VPN? Or just VM's On a NAT'd network?
submitted by /u/the_only_butchog
[link] [comments]
reddit
Hacking lab!
What is an Ideal setup for a hacking lab when using tryhackme or hackthebox? Do you use VPN? Or just VM's On a NAT'd network?
KubiScan - A Tool To Scan Kubernetes Cluster For Risky Permissions
http://www.kitploit.com/2021/04/kubiscan-tool-to-scan-kubernetes.html
http://www.kitploit.com/2021/04/kubiscan-tool-to-scan-kubernetes.html
A tool for scanning Kubernetes (https://www.kitploit.com/search/label/Kubernetes) cluster for risky permissions in Kubernetes's Role-based access control (RBAC) authorization (https://www.kitploit.com/search/label/Authorization) model. The tool was published as part of the "Securing Kubernetes Clusters by Eliminating Risky Permissions" research https://www.cyberark.com/threat-research-blog/securing-kubernetes-clusters-by-eliminating-risky-permissions/.
Overview
KubiScan helps cluster administrators identify permissions that attackers could potentially exploit to compromise the clusters. This can be especially helpful on large environments where there are lots of permissions that can be challenging to track. KubiScan gathers information about risky roles\clusterroles, rolebindings\clusterrolebindings, users and pods, automating traditional manual processes and giving administrators the visibility (https://www.kitploit.com/search/label/Visibility) they need to reduce risk.
What can it do?
Identify risky Roles\ClusterRoles Identify risky RoleBindings\ClusterRoleBindings Identify risky Subjects (Users, Groups and ServiceAccounts) Identify risky Pods\Containers Dump tokens from pods (all or by namespace) Get associated RoleBindings\ClusterRoleBindings to Role, ClusterRole or Subject (user, group or service account) List Subjects with specific kind ('User', 'Group' or 'ServiceAccount') List rules of RoleBinding or ClusterRoleBinding Show Pods that have access to secret data through a volume or environment variables Get bootstrap tokens for the cluster
Usage
Container
With ~/.kube/config file
This should be executed within the Master node where the config file is located:
docker run -it --rm -e CONF_PATH=~/.kube/config -v /:/tmp cyberark/kubiscan CONF_PATH - the cluster config file's path Inside the container the command kubiscan is equivalent to python3 /KubiScan/KubiScan.py.
Notice that in this case, the whole file system will be mounted. This is due to the fact that the config files contain paths to other places in the filesystem (https://www.kitploit.com/search/label/Filesystem) that will be different in other environments.
With service account token (good from remote)
Some functionality requires a privileged service account with the following permissions: resources: ["roles", "clusterroles", "rolebindings", "clusterrolebindings", "pods", "secrets"]
verbs: ["get", "list"] resources: ["pods/exec"]
verbs: ["create", "get"] But most of the functionalities are not, so you can use this settings for limited service account:
It can be created by running: kubectl apply -f - << EOF
apiVersion: v1
kind: ServiceAccount
metadata:
name: kubiscan-sa
namespace: default
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
name: kubiscan-clusterrolebinding
subjects:
- kind: ServiceAccount
name: kubiscan-sa
namespace: default
apiGroup: ""
roleRef:
kind: ClusterRole
name: kubiscan-clusterrole
apiGroup: ""
---
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
name: kubiscan-clusterrole
rules:
- apiGroups: ["*"]
resources: ["roles", "clusterroles", "rolebindings", "clusterrolebindings", "pods"]
verbs: ["get", "list"]
EOF
Save the service account's token to a file:
kubectl get secrets $(kubectl get sa kubiscan-sa -o json | jq -r '.secrets[0].name') -o json | jq -r '.data.token' | base64 -d > token Run the container from anywhere you want:
docker run -it --rm -v $PWD/token:/token cyberark/kubiscan In the shell you will be able to to use kubiscan like that:
kubiscan -ho -t /token For example:
kubiscan -ho 192.168.21.129:8443 -t /token -rs Notice that you can also use the certificate authority (ca.crt) to verify the SSL connection:
docker run -it --rm -v $PWD/token:/token -v /ca.crt:/ca.crt cyberark/kubiscan Inside the container:
Overview
KubiScan helps cluster administrators identify permissions that attackers could potentially exploit to compromise the clusters. This can be especially helpful on large environments where there are lots of permissions that can be challenging to track. KubiScan gathers information about risky roles\clusterroles, rolebindings\clusterrolebindings, users and pods, automating traditional manual processes and giving administrators the visibility (https://www.kitploit.com/search/label/Visibility) they need to reduce risk.
What can it do?
Identify risky Roles\ClusterRoles Identify risky RoleBindings\ClusterRoleBindings Identify risky Subjects (Users, Groups and ServiceAccounts) Identify risky Pods\Containers Dump tokens from pods (all or by namespace) Get associated RoleBindings\ClusterRoleBindings to Role, ClusterRole or Subject (user, group or service account) List Subjects with specific kind ('User', 'Group' or 'ServiceAccount') List rules of RoleBinding or ClusterRoleBinding Show Pods that have access to secret data through a volume or environment variables Get bootstrap tokens for the cluster
Usage
Container
With ~/.kube/config file
This should be executed within the Master node where the config file is located:
docker run -it --rm -e CONF_PATH=~/.kube/config -v /:/tmp cyberark/kubiscan CONF_PATH - the cluster config file's path Inside the container the command kubiscan is equivalent to python3 /KubiScan/KubiScan.py.
Notice that in this case, the whole file system will be mounted. This is due to the fact that the config files contain paths to other places in the filesystem (https://www.kitploit.com/search/label/Filesystem) that will be different in other environments.
With service account token (good from remote)
Some functionality requires a privileged service account with the following permissions: resources: ["roles", "clusterroles", "rolebindings", "clusterrolebindings", "pods", "secrets"]
verbs: ["get", "list"] resources: ["pods/exec"]
verbs: ["create", "get"] But most of the functionalities are not, so you can use this settings for limited service account:
It can be created by running: kubectl apply -f - << EOF
apiVersion: v1
kind: ServiceAccount
metadata:
name: kubiscan-sa
namespace: default
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
name: kubiscan-clusterrolebinding
subjects:
- kind: ServiceAccount
name: kubiscan-sa
namespace: default
apiGroup: ""
roleRef:
kind: ClusterRole
name: kubiscan-clusterrole
apiGroup: ""
---
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
name: kubiscan-clusterrole
rules:
- apiGroups: ["*"]
resources: ["roles", "clusterroles", "rolebindings", "clusterrolebindings", "pods"]
verbs: ["get", "list"]
EOF
Save the service account's token to a file:
kubectl get secrets $(kubectl get sa kubiscan-sa -o json | jq -r '.secrets[0].name') -o json | jq -r '.data.token' | base64 -d > token Run the container from anywhere you want:
docker run -it --rm -v $PWD/token:/token cyberark/kubiscan In the shell you will be able to to use kubiscan like that:
kubiscan -ho -t /token For example:
kubiscan -ho 192.168.21.129:8443 -t /token -rs Notice that you can also use the certificate authority (ca.crt) to verify the SSL connection:
docker run -it --rm -v $PWD/token:/token -v /ca.crt:/ca.crt cyberark/kubiscan Inside the container:
kubiscan -ho -t /token -c /ca.crt To remove the privileged service account, run the following commands:
kubectl delete clusterroles kubiscan-clusterrole
kubectl delete clusterrolebindings kubiscan-clusterrolebinding
kubectl delete sa kubiscan-sa
Directly with Python3
Prerequisites:
Python 3.5+ Pip3 Kubernetes Python Client Prettytable openssl (built-in in ubuntu) - used only for join token
Example for installation on Ubuntu:
apt-get update
apt-get install -y python3 python3-pip
pip3 install kubernetes
pip3 install PTable Run alias kubiscan='python3 / to use kubiscan. After installing all of the above requirements (https://www.kitploit.com/search/label/Requirements) you can run it in two different ways:
From the Master node:
On the Master node where ~/.kube/config exist and all the relevant certificates, simply run:
kubiscan
For example: kubiscan -rs will show all the risky subjects (users, service accounts and groups).
From a remote host:
To use this tool from a remote host, you will need a privileged service account like we explained in the container section.
After you have the token inside a file you can run:
kubiscan -ho -t /token
Examples
To see all the examples, run python3 KubiScan.py -e or from within the container kubiscan -e.
Demo
A small example of KubiScan usage:
kubectl delete clusterroles kubiscan-clusterrole
kubectl delete clusterrolebindings kubiscan-clusterrolebinding
kubectl delete sa kubiscan-sa
Directly with Python3
Prerequisites:
Python 3.5+ Pip3 Kubernetes Python Client Prettytable openssl (built-in in ubuntu) - used only for join token
Example for installation on Ubuntu:
apt-get update
apt-get install -y python3 python3-pip
pip3 install kubernetes
pip3 install PTable Run alias kubiscan='python3 / to use kubiscan. After installing all of the above requirements (https://www.kitploit.com/search/label/Requirements) you can run it in two different ways:
From the Master node:
On the Master node where ~/.kube/config exist and all the relevant certificates, simply run:
kubiscan
For example: kubiscan -rs will show all the risky subjects (users, service accounts and groups).
From a remote host:
To use this tool from a remote host, you will need a privileged service account like we explained in the container section.
After you have the token inside a file you can run:
kubiscan -ho -t /token
Examples
To see all the examples, run python3 KubiScan.py -e or from within the container kubiscan -e.
Demo
A small example of KubiScan usage:
Risky Roles YAML
There is a file named risky_roles.yaml. This file contains templates for risky roles with priority.
Although the kind in each role is Role, these templates will be compared against any Role\ClusterRole in the cluster.
When each of these roles is checked against a role in the cluster, it checks if the role in the cluster contains the rules from the risky role. If it does, it will be marked as risky.
We added all the roles we found to be risky, but because each one can define the term "risky" in a different way, you can modify the file by adding\removing roles you think are more\less risky.
References:
For more comments, suggestions or questions, you can contact Eviatar Gerzi (@g3rzi (https://twitter.com/g3rzi)) and CyberArk Labs.
Download KubiScan (https://github.com/cyberark/KubiScan)
There is a file named risky_roles.yaml. This file contains templates for risky roles with priority.
Although the kind in each role is Role, these templates will be compared against any Role\ClusterRole in the cluster.
When each of these roles is checked against a role in the cluster, it checks if the role in the cluster contains the rules from the risky role. If it does, it will be marked as risky.
We added all the roles we found to be risky, but because each one can define the term "risky" in a different way, you can modify the file by adding\removing roles you think are more\less risky.
References:
For more comments, suggestions or questions, you can contact Eviatar Gerzi (@g3rzi (https://twitter.com/g3rzi)) and CyberArk Labs.
Download KubiScan (https://github.com/cyberark/KubiScan)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box-Lame
https://cdn-images-1.medium.com/max/600/1*0jHirL8A8Tp_UuqS36CQ_g.png
This is my 14th write up and I will be discussing my experience with the machine “Lame” from Hack The Box. Htb is a great platform for…
Continue reading on Medium »
Hack The Box-Lame
https://cdn-images-1.medium.com/max/600/1*0jHirL8A8Tp_UuqS36CQ_g.png
This is my 14th write up and I will be discussing my experience with the machine “Lame” from Hack The Box. Htb is a great platform for…
Continue reading on Medium »