Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials DDexec : A Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another Process DDexec is a Technique To Run Binaries Filelessly And Stealthily On Linux Using Dd To Replace The Shell With Another…
vector (needed by the loader).
* Jump into the loader and let it do the rest (load libraries needed by the program).

* Obtain from the syscallfile the address to which the process will return after the syscall it is executing.
* Overwrite that place, which will be executable, with our shellcode (through memwe can modify unwritable pages).
* Pass the program we want to run to the stdin of the process (will be read()by said “shell”code).
* At this point it is up to the loader to load the necessary libraries for our program and jump into it.

Oh, and all of this must be done in shell scripting, or what would be the point? Download

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
DoS Vulnerability Allows Easy Envoy Proxy Crashes

The DoS vulnerability allows an attacker to create a Brotli "zip bomb," resulting in acute performance issues on Envoy proxy servers.
Dark Reading: Attacks/Breaches
3 Big Takeaways From the Verizon DBIR 2022

The annual report is always filled with useful security information. Here are several of the most important lessons from this year's edition.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)

https://blogger.googleusercontent.com/img/a/AVvXsEhvJYSxBzvhziiqnNQMt1sVNIxlGDPxGaEDU73ligxfwzMzbXBi3yU8ypWCvQXp4yv7swHFon8H2aJCrn8HmJ8P_U1VRKcyPGulS3ckJLMWG9BozW5mcPC4jFdBmj9GCHuwx1YkvX_tI6PP7DHV1cHwoJnI1zhRwdnEHR4gHpUl8wsRJXX2MsN1_rv7=w640-h190
ConfluencePot is a simple honeypot for the Atlassian Confluence unauthenticated and remote OGNL injection vulnerability (CVE-2022-26134).
About the vulnerability

You can find the official advisory by Atlassian to this vulerability here. For details about the inner workings and exploits in the wild you should refer to the reports by Rapid7 and Cloudflare. Affected but not yet patched systems should be deemed compromised until further investigation.

About the tool

ConfluencePot is written in Golang and implements its own HTTPS server to minimize the overall attack surface. To make it appear like a legit Confluence instance it returns a bare-bones version of a Confluence landing page. Log output is written to stdout and a log file on disk. ConfluencePot DOES NOT allow attackers to execute commands/code on your machine, it only logs requests and returns a bogus response.

Building & Running it

You need a recent version of Golang to run/build confluencePot and the appropriate privileges to bind to port 443. We recommend to execute it in a tmux session for easier handling. To run ConfluencePot you either need to create a self-signed TLS certificate with openssl or request one from e.g. Let's Encrypt.

go build confluencePot.go
./confluencePot


Testing and Issues

ConfluencePot was tested using the public exploit by Nwqda, which seems to be the most used variant in the wild at the time of writing. If you find anything wrong with confluencePot please feel free to open an issue or send us a pull request.

Follow us on Twitter --> @SI_FalconTeam <--
Download confluencePot

___________________________
@hacking_Attack
@Hacking_Video