Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Wpgarlic : A Proof-Of-Concept WordPress Plugin Fuzzer Wpgarlic is a proof-of-concept WordPress plugin fuzzer used in the research described in https://kazet.cc/2022/02/03/fuzzing-wordpress-plugins.html that helped to discover more than…
s may take about an hour, because we need to build the Docker image with instrumented PHP and WordPress. Fuzzing a plugin by name./bin/fuzz_plugin PLUGIN_SLUG Fuzzing a plugin from fileYou can also install a plugin from a local zip file:

./bin/fuzz_plugin PLUGIN_FILE_NAME.zip Printing findingsTo print what the fuzzer found, use:

./bin/print_findings data/plugin_fuzz_results/ Running testsTo run the tests, use:

./bin/test Manual testing environmentYou may start a test environment with only one plugin installed using:

./bin/manual_testing PLUGIN_SLUG|PLUGIN_PATH.zip [version]

You can install a plugin using its slug or from a local zip file.

It will listen on http://127.0.0.1:8001/

There will be two test users in the database:

* username: admin, password: admin, privileges: administrator
* username: subscriber, password: subscriber, privileges: subscriber Extending and configuring the fuzzerThis tool is a proof of concept – this section contains places where it can be improved to find more vulnerabilities.

You may want to edit filtering.py— it contains the rules that deem a particular crash important or not. If you change them, you may have more false positives, but find more vulnerabilities as well. For example, the only header that I consider interesting when emitted is the Location header, to detect Open Redirect vulnerabilities. That is just one idea and you may have others.

Another file that may be worth extending is docker_image/patch_wordpress.sh. It describes calls to which functions will be logged as interesting.

If you want to inject other payloads (or change the probabilities with which they are injected) edit docker_image/magic_payloads.phpand docker_image/fuzz/config.py. crash_detector.pycontans regular expressions that find interesting crashes or interesting information (e.g. e-mails) being exposed.

Fuzzing files (i.e. executing each PHP file with injected payloads) has been disabled because it didn’t lead to many findings. Uncomment filesin config.DEFAULT_ENABLED_FEATURESto change that. Fuzzer internalsBlocklistsSome plugins need other ones (e.g. woocommerce) as a dependency. When fuzzing a plugin that has a dependency, we want to fuzz only the chosen plugin and skip the dependency AJAX actions, REST routes and menu pages. We want to fuzz woocommerce actions/routes/pages only when we picked woocommerce to fuzz.

List of dependency actions/routes/pages are called blocklists and are listed in docker_image/blocklists/. Files named commoncontain the WordPress core actions/routes/pages – we don’t want to fuzz these as well.

To update these blocklists, use ./bin/update_blocklists. Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
DDexec : A Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process

DDexec is a Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process. In Linux in order to run a program it must exist as a file, it must be accessible in some way through the file system hierarchy (this is just how execve()works). This file may reside on disk or in ram (tmpfs, memfd) but you need a filepath. This has made very easy to control what is run on a Linux system, it makes easy to detect threats and attacker’s tools or to prevent them from trying to execute anything of theirs at all (e. g. not allowing unprivileged users to place executable files anywhere).

But this technique is here to change all of this. If you can not start the process you want… then you hijack one already existing. UsagePipe into the ddexec.shscript the base64 of the binary you want to run (without newlines). The arguments for the script are the arguments for the program (starting with argv[0]).

Here, try this:

base64 -w0 /bin/ls | bash ddexec.sh /bin/ls -lA

There is also the ddsc.shscript that allows you to run binary code directly. The following is a “Hello world” shellcode.

bash ddsc.sh -x <<

or

bash ddsc.sh < <(xxd<<

And yes. It works with meterpreter.

Tested Linux distributions are Debian, Alpine and Arch. Supported shells are bash, zsh and ash over x86_64 and aarch64 (arm64) architectures. DependenciesThis script depends on the following tools to work.

dd
bash | zsh | ash (busybox)
head
tail
cut
grep
od
readlink
wc
tr
base64 The techniqueIf you are able to modify arbitrarily the memory of a process then you can take over it. This can be used to hijack an already existing process and replace it with another program. We can achieve this either by using the ptrace()syscall (which requires you to have the ability to execute syscalls or to have gdb available on the system) or, more interestingly, writing to /proc/$pid/mem.

The file /proc/$pid/memis a one-to-one mapping of the entire address space of a process (e. g. from 0x0000000000000000to 0x7ffffffffffff000in x86-64). This means that reading from or writing to this file at an offset xis the same as reading from or modifying the contents at the virtual address x.

Now, we have four basic problems to face:

* In general, only root and the program owner of the file may modify it.
* ASLR.
* If we try to read or write to an address not mapped in the address space of the program we will get an I/O error.

This problems have solutions that, although they are not perfect, are good:

* Most shell interpreters allow the creation of file descriptors that will then be inherited by child processes. We can create a fd pointing to the memfile of the sell with write permissions… so child processes that use that fd will be able to modify the shell’s memory.
* ASLR isn’t even a problem, we can check the shell’s mapsfile or any other from the procfs in order to gain information about the address space of the process.
* So we need to lseek()over the file. From the shell this cannot be done unless using the infamous dd. In more detailThe steps are relatively easy and do not require any kind of expertise to understand them:

* Parse the binary we want to run and the loader to find out what mappings they need. Then craft a “shell”code that will perform, broadly speaking, the same steps that the kernel does upon each call to execve():
* Create said mappings.
* Read the binaries into them.
* Set up permissions.
* Finally initialize the stack with the arguments for the program and place the auxiliary[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials DDexec : A Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process DDexec is a Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another…
vector (needed by the loader).
* Jump into the loader and let it do the rest (load libraries needed by the program).

* Obtain from the syscallfile the address to which the process will return after the syscall it is executing.
* Overwrite that place, which will be executable, with our shellcode (through memwe can modify unwritable pages).
* Pass the program we want to run to the stdin of the process (will be read()by said “shell”code).
* At this point it is up to the loader to load the necessary libraries for our program and jump into it.

Oh, and all of this must be done in shell scripting, or what would be the point? Download

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
DoS Vulnerability Allows Easy Envoy Proxy Crashes

The DoS vulnerability allows an attacker to create a Brotli "zip bomb," resulting in acute performance issues on Envoy proxy servers.
Dark Reading: Attacks/Breaches
3 Big Takeaways From the Verizon DBIR 2022

The annual report is always filled with useful security information. Here are several of the most important lessons from this year's edition.