Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Let’s Explore OAuth 2.0 Vulnerability.

Hello Amazing People,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
WhiteBeam : Transparent Endpoint Security

WhiteBeam is a Transparent endpoint security

Features

* Block and detect advanced attacks
* Modern audited cryptography: RustCrypto for hashing and encryption
* Highly compatible: Development focused on all platforms (incl. legacy) and architectures
* Source available: Audits welcome
* Reviewed by security researchers with combined 100+ years of experience

Installation

WhiteBeam is currently unavailable for installation due to backwards-incompatible security enhancements for 0.3. Check back soon!

From Packages (Linux)

Distro-specific packages have not been released yet for WhiteBeam, check again soon!

From Releases (Linux)

1. Download the latest release
2. Ensure the release file hash matches the official hashes (How-to)
3. Install:
* ./whitebeam-installer install
From Source (Linux)

1. Run tests (Optional):
* cargo run test

2. Compile:
* cargo run build

3. Install WhiteBeam:
* cargo run install
Quick start

1. Become root (sudo su/su root)
2. Set a recovery secret: whitebeam --setting RecoverySecret mask. After setting the recovery secret, you can run whitebeam --authto make changes to the system.

How to Detect Attacks with WhiteBeam

Multiple guides are provided depending on your preference. Contact us so we can help you integrate WhiteBeam with your environment.

1. Serverless guide, for passive review
2. osquery Fleet setup guide, for passive review
3. WhiteBeam Server setup guide, for active response

How to Prevent Attacks with WhiteBeam

https://s.w.org/images/core/emoji/14.0.0/72x72/2139.png WhiteBeam is experimental software. Contact us for assistance safely implementing it.

1. Become root (sudo su/su root)
2. Review the baseline at least 24 hours after installing WhiteBeam:
* whitebeam --baseline

3. Add trusted behavior to the whitelist, following the whitelisting guide
4. Enable WhiteBeam prevention:
* whitebeam --setting Prevention true
Download
*
*
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Pulsar : Data Exfiltration And Covert Communication Tool

Pulsar is a tool for data exfiltration and covert communication that enable you to create a secure data transfer, a bizarre chat or a network tunnel through different protocols, for example you can receive data from tcp connection and resend it to real destination through DNS packets

Setting up Pulsar

First, getting the code from repository and compile it with following command:

$ cd pulsar
$ export GOPATH=$(shell pwd)
$ go get golang.org/x/net/icmp
$ go build -o bin/pulsar src/main.go

or run:

$ make

Connectors

A connector is a simple channel to the external world, with the connector you can read and write data from different sources.

* Console:
* Default in/out connector, read data from stdin and write to stdout

* TCP
* Read and write data through tcp connections
tcp:127.0.0.1:9000

UDP

* Read and write data through udp packet

udp:127.0.0.1:9000

ICMP

* Read and write data through icmp packet

icmp:127.0.0.1 (the connection port is obviously useless)

You can use option –in in order to select input connector and option –out to select output connector:

–in tcp:127.0.0.1:9000
–out dns:fkdns.lol:2.3.4.5:8989

Handlers

A handler allows you to change data in transit, you can combine handlers arbitrarily.

* Stub:
* Default, do nothing, pass through

* Base32
* Base32 encoder/decoder
–handlers base32

You can use the –decode option to use ALL handlers in decoding mode

–handlers base64,base32,base64,cipher:key –decode

Example

In the following example Pulsar will be used to create a secure two-way tunnel on DNS protocol, data will be read from TCP connection (simple nc client) and resend encrypted through the tunnel.

[nc 127.0.0.1 9000] <–tcp–[pulsar] <–dns–[pulsar] <–tcp–[nc -l 127.0.0.1 -p 9900]

$ ./pulsar –in tcp:127.0.0.1:9000 –out dns:test.org@192.168.1.199:8989 –duplex –plain in –handlers ‘cipher:supersekretkey!!’
$ nc 127.0.0.1 9000
Download
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Bpflock - eBPF Driven Security For Locking And Auditing Linux Machines

https://blogger.googleusercontent.com/img/a/AVvXsEg87_fg2zsjt2SOO-S02EVTzzIzNcHHACD_2bJFljEMQCyb3jN66NI5lINUpXtWdEC9aDY3PP4URkC8TlKRekqwM4eSKSdTEDzbbAQ9kElur2Eonb_wBEP4ErgqClkSqV8eT7HAKNPXE9OcYE8u46-U7m0HhcYYrQDTIEP46ywptZxBIp_MGbuzWv8A=w640-h180 bpflock - eBPF driven security for locking and auditing Linux machines.

Note: bpflock is currently in experimental stage, it may break, options and security semantics may change, some BPF programs will be updated to use Cilium ebpf library. 1. Introductionbpflock uses eBPF to strength Linux security. By restricting access to a various range of Linux features, bpflock is able to reduce the attack surface and block some well known attack techniques.

Only programs like container managers, systemd and other containers/programs that run in the host pid and network namespaces are allowed access to full Linux features, containers and applications that run on their own namespace will be restricted. If bpflock bpf programs run under the restrictedprofile then all programs/containers including privileged ones will have their access denied.

bpflock protects Linux machines by taking advantage of multiple security features including Linux Security Modules + BPF.

Architecture and Security design notes:

* bpflock is not a mandatory access control labeling solution, and it does not intent to replace AppArmor, SELinux, and other MAC solutions. bpflock uses a simple declarative security profile.
* bpflock offers multiple small bpf programs that can be reused in multiple contexts from Cloud Native deployments to Linux IoT devices.
* bpflock is able to restrict root from accessing certain Linux features, however it does not protect against evil root. 2. Functionality Overview2.1 Security featuresbpflock offer multiple security protections that can be classified as:

* Memory Protections

* Kernel Image Lock-down
* Kernel Modules Protection
* BPF Protection

* Process Protections

* Fileless Memory Execution
* Namespaces protection

* Hardware Addition Attacks

* USB Additions Protection

* System and Application tracing

* Trace Application Execution
* Trace Privileged System Operations

*
Filesystem Protections

* Read-only root filesystem protection
* sysfs protection

*
Network protections

* bpflock may include in future a simple network protection that can be used in single machine workload or Linux-IoT, but will not include a Cloud Native protection. Cilium and other kubernetes CNI related solutions are by far better. 2.2 Semanticsbpflock keeps the security semantics simple. It support three global profiles to broadly cover the security sepctrum, and restrict access to specific Linux features.

* profile: this is the global profile that can be applied per bpf program, it takes one of the followings:

* allow|none|privileged: they are the same, they define the least secure profile. In this profile access is logged and allowed for all processes. Useful to log security events.
* baseline: restrictive profile where access is denied for all processes, except privileged applications and containers that run in the host namespaces, or per cgroup allowed profiles in the bpflock_cgroupmapbpf map.
* restricted: heavily restricted profile where access is denied for all processes.

* Allowedor blockedoperations/commands:

Under the allow|privilegedor baselineprofiles, a list of allowed or blocked commands can be specified and will be applied.

* --protection-allow: comma-separated list of allowed operations. Valid under baselineprofile, this is useful for applications that are too specific and perform privileged operations. It[...]