Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
DDexec : A Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process
DDexec is a Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process. In Linux in order to run a program it must exist as a file, it must be accessible in some way through the file system hierarchy (this is just how
But this technique is here to change all of this. If you can not start the process you want… then you hijack one already existing. UsagePipe into the
Here, try this:
base64 -w0 /bin/ls | bash ddexec.sh /bin/ls -lA
There is also the
bash ddsc.sh -x <<
or
bash ddsc.sh < <(xxd<<
And yes. It works with meterpreter.
Tested Linux distributions are Debian, Alpine and Arch. Supported shells are bash, zsh and ash over x86_64 and aarch64 (arm64) architectures. DependenciesThis script depends on the following tools to work.
dd
bash | zsh | ash (busybox)
head
tail
cut
grep
od
readlink
wc
tr
base64 The techniqueIf you are able to modify arbitrarily the memory of a process then you can take over it. This can be used to hijack an already existing process and replace it with another program. We can achieve this either by using the
The file
Now, we have four basic problems to face:
* In general, only root and the program owner of the file may modify it.
* ASLR.
* If we try to read or write to an address not mapped in the address space of the program we will get an I/O error.
This problems have solutions that, although they are not perfect, are good:
* Most shell interpreters allow the creation of file descriptors that will then be inherited by child processes. We can create a fd pointing to the
* ASLR isn’t even a problem, we can check the shell’s
* So we need to
* Parse the binary we want to run and the loader to find out what mappings they need. Then craft a “shell”code that will perform, broadly speaking, the same steps that the kernel does upon each call to
* Create said mappings.
* Read the binaries into them.
* Set up permissions.
* Finally initialize the stack with the arguments for the program and place the auxiliary[...]
___________________________
@hacking_Attack
@Hacking_Video
DDexec : A Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process
DDexec is a Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process. In Linux in order to run a program it must exist as a file, it must be accessible in some way through the file system hierarchy (this is just how
execve()works). This file may reside on disk or in ram (tmpfs, memfd) but you need a filepath. This has made very easy to control what is run on a Linux system, it makes easy to detect threats and attacker’s tools or to prevent them from trying to execute anything of theirs at all (e. g. not allowing unprivileged users to place executable files anywhere).But this technique is here to change all of this. If you can not start the process you want… then you hijack one already existing. UsagePipe into the
ddexec.shscript the base64 of the binary you want to run (without newlines). The arguments for the script are the arguments for the program (starting with argv[0]).Here, try this:
base64 -w0 /bin/ls | bash ddexec.sh /bin/ls -lA
There is also the
ddsc.shscript that allows you to run binary code directly. The following is a “Hello world” shellcode.bash ddsc.sh -x <<
or
bash ddsc.sh < <(xxd<<
And yes. It works with meterpreter.
Tested Linux distributions are Debian, Alpine and Arch. Supported shells are bash, zsh and ash over x86_64 and aarch64 (arm64) architectures. DependenciesThis script depends on the following tools to work.
dd
bash | zsh | ash (busybox)
head
tail
cut
grep
od
readlink
wc
tr
base64 The techniqueIf you are able to modify arbitrarily the memory of a process then you can take over it. This can be used to hijack an already existing process and replace it with another program. We can achieve this either by using the
ptrace()syscall (which requires you to have the ability to execute syscalls or to have gdb available on the system) or, more interestingly, writing to /proc/$pid/mem.The file
/proc/$pid/memis a one-to-one mapping of the entire address space of a process (e. g. from 0x0000000000000000to 0x7ffffffffffff000in x86-64). This means that reading from or writing to this file at an offset xis the same as reading from or modifying the contents at the virtual address x.Now, we have four basic problems to face:
* In general, only root and the program owner of the file may modify it.
* ASLR.
* If we try to read or write to an address not mapped in the address space of the program we will get an I/O error.
This problems have solutions that, although they are not perfect, are good:
* Most shell interpreters allow the creation of file descriptors that will then be inherited by child processes. We can create a fd pointing to the
memfile of the sell with write permissions… so child processes that use that fd will be able to modify the shell’s memory.* ASLR isn’t even a problem, we can check the shell’s
mapsfile or any other from the procfs in order to gain information about the address space of the process.* So we need to
lseek()over the file. From the shell this cannot be done unless using the infamous dd. In more detailThe steps are relatively easy and do not require any kind of expertise to understand them:* Parse the binary we want to run and the loader to find out what mappings they need. Then craft a “shell”code that will perform, broadly speaking, the same steps that the kernel does upon each call to
execve():* Create said mappings.
* Read the binaries into them.
* Set up permissions.
* Finally initialize the stack with the arguments for the program and place the auxiliary[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
DDexec : A Technique To Run Binaries Filelessly And Stealthily On Linux
DDexec is a Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials DDexec : A Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process DDexec is a Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another…
vector (needed by the loader).
* Jump into the loader and let it do the rest (load libraries needed by the program).
* Obtain from the
* Overwrite that place, which will be executable, with our shellcode (through
* Pass the program we want to run to the stdin of the process (will be
* At this point it is up to the loader to load the necessary libraries for our program and jump into it.
Oh, and all of this must be done in shell scripting, or what would be the point? Download
___________________________
@hacking_Attack
@Hacking_Video
* Jump into the loader and let it do the rest (load libraries needed by the program).
* Obtain from the
syscallfile the address to which the process will return after the syscall it is executing.* Overwrite that place, which will be executable, with our shellcode (through
memwe can modify unwritable pages).* Pass the program we want to run to the stdin of the process (will be
read()by said “shell”code).* At this point it is up to the loader to load the necessary libraries for our program and jump into it.
Oh, and all of this must be done in shell scripting, or what would be the point? Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Security Leaders Discuss Industry Drivers at Dark Reading's News Desk at RSAC 2022
Tune into Dark Reading's News Desk interviews with the industry’s leaders, discussing news and hot topics, such as this year’s "Transofrm" theme, at RSA Conference 2022 in San Francisco
___________________________
@hacking_Attack
@Hacking_Video
Security Leaders Discuss Industry Drivers at Dark Reading's News Desk at RSAC 2022
Tune into Dark Reading's News Desk interviews with the industry’s leaders, discussing news and hot topics, such as this year’s "Transofrm" theme, at RSA Conference 2022 in San Francisco
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Security Leaders Discuss Industry Drivers at Dark Reading's News Desk at RSAC 2022
Tune into Dark Reading's News Desk interviews with the industry’s leaders, discussing news and hot topics, such as this year’s "Transform" theme, at RSA Conference 2022 in San Francisco
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 10 Filters of Wireshark Packet Analysis Program
https://cdn-images-1.medium.com/max/640/0*VnWmdMns9OmSI2UM.png
Top 10 Filters of Wireshark
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 10 Filters of Wireshark Packet Analysis Program
https://cdn-images-1.medium.com/max/640/0*VnWmdMns9OmSI2UM.png
Top 10 Filters of Wireshark
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 10 Filters of Wireshark Packet Analysis Program
Top 10 Filters of Wireshark
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Termux LSD : Install File & Folder Icons in Termux
https://cdn-images-1.medium.com/max/1280/1*09K0-h1axkslDcfEvchPDQ.png
Hey Guys 🙋♂️, So nowadays I am more into terminal styling and there are a lot of tools available that can change the theme of our termux…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Termux LSD : Install File & Folder Icons in Termux
https://cdn-images-1.medium.com/max/1280/1*09K0-h1axkslDcfEvchPDQ.png
Hey Guys 🙋♂️, So nowadays I am more into terminal styling and there are a lot of tools available that can change the theme of our termux…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Termux LSD : Install File & Folder Icons in Termux
Hey Guys 🙋♂️, So nowadays I am more into terminal styling and there are a lot of tools available that can change the theme of our termux…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox: Bucket — Writeup
https://cdn-images-1.medium.com/max/1404/1*SwunC8bwHZ5AYIcRQVRQBw.png
This is one of the machines that when you play it after being used to Easy or Medium difficulty machines it really punches you in the face…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox: Bucket — Writeup
https://cdn-images-1.medium.com/max/1404/1*SwunC8bwHZ5AYIcRQVRQBw.png
This is one of the machines that when you play it after being used to Easy or Medium difficulty machines it really punches you in the face…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox: Bucket — Writeup
This is one of the machines that when you play it after being used to Easy or Medium difficulty machines it really punches you in the face…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Meta — HackTheBox WalkThrough
https://cdn-images-1.medium.com/max/718/1*1PSQpeoAHn6u5zER9tSxiw.png
Hello all! In this blog, I am writing the steps that I followed to crack the box “Meta” which is marked as “medium” severity on hackthebox…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Meta — HackTheBox WalkThrough
https://cdn-images-1.medium.com/max/718/1*1PSQpeoAHn6u5zER9tSxiw.png
Hello all! In this blog, I am writing the steps that I followed to crack the box “Meta” which is marked as “medium” severity on hackthebox…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Meta — HackTheBox WalkThrough
Hello all! In this blog, I am writing the steps that I followed to crack the box “Meta” which is marked as “medium” severity on hackthebox…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Symbiote: un malware sigiloso de Linux dirigido al sector financiero latinoamericano.
https://cdn-images-1.medium.com/max/1400/0*ZW2yzz4zKwlGE6o4
PUBLICADO EN 9 JUNIO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Symbiote: un malware sigiloso de Linux dirigido al sector financiero latinoamericano.
https://cdn-images-1.medium.com/max/1400/0*ZW2yzz4zKwlGE6o4
PUBLICADO EN 9 JUNIO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Symbiote: un malware sigiloso de Linux dirigido al sector financiero latinoamericano.
PUBLICADO EN 9 JUNIO, 2022 EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Victim of Cyber Fraud Getting Money Back
Victims of Cyber Fraud Getting Money Back
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Victim of Cyber Fraud Getting Money Back
Victims of Cyber Fraud Getting Money Back
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Victim of Cyber Fraud Getting Money Back
Victims of Cyber Fraud Getting Money Back
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)
https://blogger.googleusercontent.com/img/a/AVvXsEhvJYSxBzvhziiqnNQMt1sVNIxlGDPxGaEDU73ligxfwzMzbXBi3yU8ypWCvQXp4yv7swHFon8H2aJCrn8HmJ8P_U1VRKcyPGulS3ckJLMWG9BozW5mcPC4jFdBmj9GCHuwx1YkvX_tI6PP7DHV1cHwoJnI1zhRwdnEHR4gHpUl8wsRJXX2MsN1_rv7=w640-h190
ConfluencePot is a simple honeypot for the Atlassian Confluence unauthenticated and remote OGNL injection vulnerability (CVE-2022-26134).
About the vulnerability
You can find the official advisory by Atlassian to this vulerability here. For details about the inner workings and exploits in the wild you should refer to the reports by Rapid7 and Cloudflare. Affected but not yet patched systems should be deemed compromised until further investigation.
About the tool
ConfluencePot is written in Golang and implements its own HTTPS server to minimize the overall attack surface. To make it appear like a legit Confluence instance it returns a bare-bones version of a Confluence landing page. Log output is written to stdout and a log file on disk. ConfluencePot DOES NOT allow attackers to execute commands/code on your machine, it only logs requests and returns a bogus response.
Building & Running it
You need a recent version of Golang to run/build confluencePot and the appropriate privileges to bind to port 443. We recommend to execute it in a tmux session for easier handling. To run ConfluencePot you either need to create a self-signed TLS certificate with openssl or request one from e.g. Let's Encrypt.
Testing and Issues
ConfluencePot was tested using the public exploit by Nwqda, which seems to be the most used variant in the wild at the time of writing. If you find anything wrong with confluencePot please feel free to open an issue or send us a pull request.
Follow us on Twitter --> @SI_FalconTeam <--
Download confluencePot
___________________________
@hacking_Attack
@Hacking_Video
confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)
https://blogger.googleusercontent.com/img/a/AVvXsEhvJYSxBzvhziiqnNQMt1sVNIxlGDPxGaEDU73ligxfwzMzbXBi3yU8ypWCvQXp4yv7swHFon8H2aJCrn8HmJ8P_U1VRKcyPGulS3ckJLMWG9BozW5mcPC4jFdBmj9GCHuwx1YkvX_tI6PP7DHV1cHwoJnI1zhRwdnEHR4gHpUl8wsRJXX2MsN1_rv7=w640-h190
ConfluencePot is a simple honeypot for the Atlassian Confluence unauthenticated and remote OGNL injection vulnerability (CVE-2022-26134).
About the vulnerability
You can find the official advisory by Atlassian to this vulerability here. For details about the inner workings and exploits in the wild you should refer to the reports by Rapid7 and Cloudflare. Affected but not yet patched systems should be deemed compromised until further investigation.
About the tool
ConfluencePot is written in Golang and implements its own HTTPS server to minimize the overall attack surface. To make it appear like a legit Confluence instance it returns a bare-bones version of a Confluence landing page. Log output is written to stdout and a log file on disk. ConfluencePot DOES NOT allow attackers to execute commands/code on your machine, it only logs requests and returns a bogus response.
Building & Running it
You need a recent version of Golang to run/build confluencePot and the appropriate privileges to bind to port 443. We recommend to execute it in a tmux session for easier handling. To run ConfluencePot you either need to create a self-signed TLS certificate with openssl or request one from e.g. Let's Encrypt.
go build confluencePot.go
./confluencePot
Testing and Issues
ConfluencePot was tested using the public exploit by Nwqda, which seems to be the most used variant in the wild at the time of writing. If you find anything wrong with confluencePot please feel free to open an issue or send us a pull request.
Follow us on Twitter --> @SI_FalconTeam <--
Download confluencePot
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)