Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
ropr is a blazing fast multithreaded (https://www.kitploit.com/search/label/multithreaded) ROP Gadget finder What is a ROP Gadget? ROP (Return Oriented Programming) Gadgets are small snippets of a few assembly instructions typically ending in a ret instruction which already exist as executable code within each binary or library. These gadgets may be used for binary exploitation (https://www.kitploit.com/search/label/Binary%20Exploitation) and to subvert vulnerable executables. When the addresses of many ROP Gadgets are written into a buffer we have formed a ROP Chain. If an attacker can move the stack pointer into this ROP Chain then control can be completely transferred to the attacker. Most executables contain enough gadgets to write a turing-complete ROP Chain. For those that don't, one can always use dynamic libraries contained in the same address-space such as libc once we know their addresses. The beauty of using ROP Gadgets is that no new executable code needs to be written anywhere - an attacker may achieve their objective using only the code that already exists in the program.
How do I use a ROP Gadget? Typically the first requirement to use ROP Gadgets is to have a place to write your ROP Chain - this can be any readable buffer. Simply write the addresses of each gadget you would like to use into this buffer. If the buffer is too small there may not be enough room to write a long ROP Chain into and so an attacker should be careful to craft their ROP Chain to be efficient enough to fit into the space available. The next requirement is to be able to control the stack - This can take the form of a stack overflow - which allows the ROP Chain to be written directly under the stack pointer, or a "stack pivot" - which is usually a single gadget which moves the stack pointer to the rest of the ROP Chain. Once the stack pointer is at the start of your ROP Chain, the next ret instruction will trigger the gadgets to be excuted in sequence - each using the next as its return address on its own stack frame. It is also possible to add function poitners into a ROP Chain - taking care that function arguments be supplied after the next element of the ROP Chain. This is typically combined with a "pop gadget", which pops the arguments off the stack in order to smoothly transition to the next gadget after the function arguments. How do I install ropr? Requires cargo (the rust build system) Easy install: cargo install ropr
the application will install to ~/.cargo/bin From source: git clone https://github.com/Ben-Lichtman/ropr
cd ropr
cargo build --release
the resulting binary will be located in target/release/ropr Alternatively: git clone https://github.com/Ben-Lichtman/ropr
cd ropr
cargo install --path .
the application will install to ~/.cargo/bin How do I use ropr? For example if I was looking for a way to fill rax with a value from another register I may choose to filter by the regex ^mov eax, ...;: Now I can add some filters to the command line (https://www.kitploit.com/search/label/Command%20Line) for the highest quality results: Now I have a good mov gadget candidate at address 0x00052252

Download Ropr (https://github.com/Ben-Lichtman/ropr)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Creating a Fully CLI Hacking-Server

Hello everyone,

I'm trying to create a full Pentest-Server with all the utils necessary to do fully web-pentesting on it.

Why? Because I have a cloud server hosted that I can access worldwide and, I usually use it while I have "dead-time" at work, but I really want to use it "more" professionally/for more "high-level" things.

Days ago I created a post talking about having an util like BurpSuite only on CLI, and you recommend me mitmproxy that's a great utility but, it can't do all the things that Burp does for example, so I need to find some other tools that let me test things like repeater or intruder options via cURL.

For now, I only use it to do wargames on Ssh, and I have installed wfuzz, mitmproxy, nmap, and nuclei.

I create this post with the intentionality of creating with all of the community a post fulfilled with command-line tools being capable to do a full pentesting audit.

Thank you all!

submitted by /u/Ajotah
[link] [comments]
Dark Reading: Attacks/Breaches
Google Cloud Adds Curated Detection to Chronicle

The curated detection feature for Chronicle SecOps Suite provides security teams with actionable insights on cloud threats and Windows-based attacks from Google Cloud Threat Intelligence Team.
Dark Reading: Attacks/Breaches
How to Upskill Tech Staff to Meet Cybersecurity Needs

Cybersecurity is the largest current tech skills gap; closing it requires a concerted effort to upskill existing staff.
Dark Reading: Attacks/Breaches
Summertime Blues: TA558 Ramps Up Attacks on Hospitality, Travel Sectors

The cybercriminal crew has used 15 malware families to target travel and hospitality companies globally, constantly changing tactics over the course of its four-year history.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Add Unlimited Member On Telegram

I would provide you with the script that can ultimately add the members on the telegram

Continue reading on Medium »