hacking: security in practice
Is it possible creating an exploit for PIE x86_64 programs?
I think is possible only having memory leaks and knowing the address of libc..., then you can create a ROP/JOP but without leaks with PIE and the stack protector in x86_64 practically is impossible to exploit it.
What you guys think?
submitted by /u/0xhaku
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible creating an exploit for PIE x86_64 programs?
I think is possible only having memory leaks and knowing the address of libc..., then you can create a ROP/JOP but without leaks with PIE and the stack protector in x86_64 practically is impossible to exploit it.
What you guys think?
submitted by /u/0xhaku
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible creating an exploit for PIE x86_64 programs?
I think is possible only having memory leaks and knowing the address of libc..., then you can create a ROP/JOP but without leaks with PIE and the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
EvilnoVNC - Ready To Go Phishing Platform
https://blogger.googleusercontent.com/img/a/AVvXsEjS0YsH-959lRu1uWmj0ocq3aNQJGwOsU8S6La4QVtlPoatkSdx6E6RtAMauwx-jcdmtDV3GD7u1YuHNMHeAElabczWZXHyWz9-_0caNDYjUIfvcysktOnr1HQiHoqDHXVrIBsXmqx4aPh4u7D6qEACAflv0Z1-T8VcfJ2Jfb_nfDRhAkc2il42Dk2nDw=w640-h320
EvilnoVNC is a Ready to go Phishing Platform.
Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.
In addition, this tool allows us to see in real time all of the victim's actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.
Requirements
* Docker
* Chromium
Download
It's recommended to clone the complete repository or download the zip file.
Additionally, it's necessary to build Docker manually. You can do this by running the following commands:
Usage
The detailed guide of use can be found at the following link:
https://darkbyte.net/robando-sesiones-y-bypasseando-2fa-con-evilnovnc
Features & To Do
* Export Evil-Chromium profile to host
* Save download files on host
* Disable parameters in URL (like password)
* Disable key combinations (like Alt+1 or Ctrl+S)
* Disable access to Thunar
* Decrypt cookies in real time
* Expand cookie life to 99999999999999999
* Dynamic title from original website
* Dynamic resolution from preload page
* Replicate real user-agent and other stuff
* Basic keylogger
License
This project is licensed under the GNU 3.0 license - see the LICENSE file for more details.
Credits and Acknowledgments
Original idea by @mrd0x: https://mrd0x.com/bypass-2fa-using-novnc
This tool has been created and designed from scratch by Joel Gámez Molina // @JoelGMSec
Contact
This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it.
For more information, you can find me on Twitter as @JoelGMSec and on my blog darkbyte.net.
Download EvilnoVNC
___________________________
@hacking_Attack
@Hacking_Video
EvilnoVNC - Ready To Go Phishing Platform
https://blogger.googleusercontent.com/img/a/AVvXsEjS0YsH-959lRu1uWmj0ocq3aNQJGwOsU8S6La4QVtlPoatkSdx6E6RtAMauwx-jcdmtDV3GD7u1YuHNMHeAElabczWZXHyWz9-_0caNDYjUIfvcysktOnr1HQiHoqDHXVrIBsXmqx4aPh4u7D6qEACAflv0Z1-T8VcfJ2Jfb_nfDRhAkc2il42Dk2nDw=w640-h320
EvilnoVNC is a Ready to go Phishing Platform.
Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.
In addition, this tool allows us to see in real time all of the victim's actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.
Requirements
* Docker
* Chromium
Download
It's recommended to clone the complete repository or download the zip file.
Additionally, it's necessary to build Docker manually. You can do this by running the following commands:
git clone https://github.com/JoelGMSec/EvilnoVNC
cd EvilnoVNC ; sudo chown -R 103 Downloads
sudo docker build -t joelgmsec/evilnovnc .
Usage
./start.sh -h
_____ _ _ __ ___ _ ____
| ____|_ _(_) |_ __ __\ \ / / \ | |/ ___|
| _| \ \ / / | | '_ \ / _ \ \ / /| \| | |
| |___ \ V /| | | | | | (_) \ V / | |\ | |___
|_____| \_/ |_|_|_| |_|\___/ \_/ |_| \_|\____|
---------------- by @JoelGMSec --------------
Usage: ./start.sh $resolution $url
Examples:
1280x720 16bits: ./start.sh 1280x720x16 http://example.com
1280x720 24bits: ./start.sh 1280x720x24 http://example.com
1920x1080 16bits: ./start.sh 1920x1080x16 http://example.com
1920x1080 24bits: ./start.sh 1920x1080x24 http://example.com
The detailed guide of use can be found at the following link:
https://darkbyte.net/robando-sesiones-y-bypasseando-2fa-con-evilnovnc
Features & To Do
* Export Evil-Chromium profile to host
* Save download files on host
* Disable parameters in URL (like password)
* Disable key combinations (like Alt+1 or Ctrl+S)
* Disable access to Thunar
* Decrypt cookies in real time
* Expand cookie life to 99999999999999999
* Dynamic title from original website
* Dynamic resolution from preload page
* Replicate real user-agent and other stuff
* Basic keylogger
License
This project is licensed under the GNU 3.0 license - see the LICENSE file for more details.
Credits and Acknowledgments
Original idea by @mrd0x: https://mrd0x.com/bypass-2fa-using-novnc
This tool has been created and designed from scratch by Joel Gámez Molina // @JoelGMSec
Contact
This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it.
For more information, you can find me on Twitter as @JoelGMSec and on my blog darkbyte.net.
Download EvilnoVNC
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
EvilnoVNC - Ready To Go Phishing Platform
Everything About Path Traversal Vulnerability
IntroductionContinue reading on InfoSec Write-ups »
Read more...
IntroductionContinue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
EXPLOITING OS COMMAND INJECTION VULNERABILITIES
https://cdn-images-1.medium.com/max/1200/0*fsDcLw9CU5hxtTs-.png
Hi! My name is Hashar Mujahid. And today we are going to learn what OS command injections are and how we can exploit them.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
EXPLOITING OS COMMAND INJECTION VULNERABILITIES
https://cdn-images-1.medium.com/max/1200/0*fsDcLw9CU5hxtTs-.png
Hi! My name is Hashar Mujahid. And today we are going to learn what OS command injections are and how we can exploit them.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
EXPLOITING OS COMMAND INJECTION VULNERABILITIES
Hi! My name is Hashar Mujahid. And today we are going to learn what OS command injections are and how we can exploit them.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HACKTHEBOX (HTB) WRITEUP: AMBASSADOR [MEDIUM]
https://cdn-images-1.medium.com/max/1080/0*JAHBNwd1Su7t9a6_
SCANNING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HACKTHEBOX (HTB) WRITEUP: AMBASSADOR [MEDIUM]
https://cdn-images-1.medium.com/max/1080/0*JAHBNwd1Su7t9a6_
SCANNING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HACKTHEBOX (HTB) WRITEUP: AMBASSADOR [MEDIUM]
SCANNING
Everything About Path Traversal Vulnerability
IntroductionContinue reading on InfoSec Write-ups »
Read more...
IntroductionContinue reading on InfoSec Write-ups »
Read more...
Everything About Path Traversal Vulnerability
https://infosecwriteups.com/everything-about-path-traversal-vulnerability-c40ba5465bc4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/everything-about-path-traversal-vulnerability-c40ba5465bc4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Everything About Path Traversal Vulnerability
Introduction
IntroductionContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/everything-about-path-traversal-vulnerability-c40ba5465bc4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Everything About Path Traversal Vulnerability
Introduction
hacking: security in practice
Using the undo-feature of Tinder for free (Tinder in "Grid Mode")
Hello everyone,
in my previous post I shared how you can unblur people that liked you on Tinder for free (bypassing their previous fix). In this guide, I will explain how one can achieve the functionality of the undo-feature for free. It's neither difficult nor very sophisticated but it works anyways.
TL;DR
Tinder doesn't check if you swiped left on a person. So if you've saved the profile data before you do so, you can still send a "Like" request to Tinder's API afterwards hence emulating the undo-feature which usually costs money.
A script that does this automatically as a proof of concept is at the end of this post at "Automated script for this"
What is the undo-feature?
When you dislike/swipe-left on a person you can't just change your mind and revoke that action. There is an undo button but you have to pay in order to use it. This feature is useful when you disliked someone by accident or changed your mind afterwards because e.g. Tinder told you "oops, you just missed a match".
How to undo for free?
A "Like" is a POST request to a specific URL with a specific body and your X-Auth-Token as a header. If you have the URL and body you can hence send a "Like" manually. But after swiping left you can't get this data afaik. So you just save it beforehand. That's all! Nothing fancy, just exploiting the fact that Tinder doesn't enforce any checks if you already swiped a profile.
The URL schema is the following: https://api.gotinder.co/like/** s_number mapping is saved as well.
2. If you put your x-auth-token and the path to an image (copy+paste or drag+drop) as arguments, it will send a "Like" to the profile the image belongs to. This is done by parsing the information from the file path and looking up the s_number.
So the usage would be like this:
* `python3 ./tinder-grid.py X-AUTH-TOKEN` - to download some profiles and
* `python3 ./tinder-grid.py X-AUTH-TOKEN "/path/to/an/image.jpeg"` - to like a person.
Link to the script: https://pastebin.com/tk8ykGjb
Disclaimer
I used it only on debian 11 but since it's python I guess it works elsewhere too...
submitted by /u/nachfarbensortiert [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Using the undo-feature of Tinder for free (Tinder in "Grid Mode")
Hello everyone,
in my previous post I shared how you can unblur people that liked you on Tinder for free (bypassing their previous fix). In this guide, I will explain how one can achieve the functionality of the undo-feature for free. It's neither difficult nor very sophisticated but it works anyways.
TL;DR
Tinder doesn't check if you swiped left on a person. So if you've saved the profile data before you do so, you can still send a "Like" request to Tinder's API afterwards hence emulating the undo-feature which usually costs money.
A script that does this automatically as a proof of concept is at the end of this post at "Automated script for this"
What is the undo-feature?
When you dislike/swipe-left on a person you can't just change your mind and revoke that action. There is an undo button but you have to pay in order to use it. This feature is useful when you disliked someone by accident or changed your mind afterwards because e.g. Tinder told you "oops, you just missed a match".
How to undo for free?
A "Like" is a POST request to a specific URL with a specific body and your X-Auth-Token as a header. If you have the URL and body you can hence send a "Like" manually. But after swiping left you can't get this data afaik. So you just save it beforehand. That's all! Nothing fancy, just exploiting the fact that Tinder doesn't enforce any checks if you already swiped a profile.
The URL schema is the following: https://api.gotinder.co/like/** s_number mapping is saved as well.
2. If you put your x-auth-token and the path to an image (copy+paste or drag+drop) as arguments, it will send a "Like" to the profile the image belongs to. This is done by parsing the information from the file path and looking up the s_number.
So the usage would be like this:
* `python3 ./tinder-grid.py X-AUTH-TOKEN` - to download some profiles and
* `python3 ./tinder-grid.py X-AUTH-TOKEN "/path/to/an/image.jpeg"` - to like a person.
Link to the script: https://pastebin.com/tk8ykGjb
Disclaimer
I used it only on debian 11 but since it's python I guess it works elsewhere too...
submitted by /u/nachfarbensortiert [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Using the undo-feature of Tinder for free (Tinder in "Grid Mode")
Hello everyone, in my previous post I shared how you can unblur people that liked you on Tinder for free (bypassing their previous fix). In this...
hacking: security in practice
Are password manager on mobile safe?
Hey guys,
so until now i always used the good ol' paper and pen to write down and save my password but now i'm struggling accessing them if i'm not at home. My question is: are password manager on mobile "safe"?
If yes, what's the best application for password managing for android?
submitted by /u/Valrion06
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are password manager on mobile safe?
Hey guys,
so until now i always used the good ol' paper and pen to write down and save my password but now i'm struggling accessing them if i'm not at home. My question is: are password manager on mobile "safe"?
If yes, what's the best application for password managing for android?
submitted by /u/Valrion06
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are password manager on mobile safe?
Hey guys, so until now i always used the good ol' paper and pen to write down and save my password but now i'm struggling accessing them if i'm...
hacking: security in practice
looking for an apk editor, either for android or windows
As the title says, I am looking for an apk editor. Essentially I just need to edit the manifest of an app, kiwi browser. The last update allows only to be installed from android 6+. I need to install it on Android 5.
submitted by /u/FarVehicle5333
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
looking for an apk editor, either for android or windows
As the title says, I am looking for an apk editor. Essentially I just need to edit the manifest of an app, kiwi browser. The last update allows only to be installed from android 6+. I need to install it on Android 5.
submitted by /u/FarVehicle5333
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
looking for an apk editor, either for android or windows
As the title says, I am looking for an apk editor. Essentially I just need to edit the manifest of an app, kiwi browser. The last update allows...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
RazorBlack TryHackMe Writeup/Walkthrough
https://cdn-images-1.medium.com/max/938/1*wIAtLMHRaWLR39cz9gnUBQ.png
RazorBlack
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
RazorBlack TryHackMe Writeup/Walkthrough
https://cdn-images-1.medium.com/max/938/1*wIAtLMHRaWLR39cz9gnUBQ.png
RazorBlack
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
RazorBlack TryHackMe Writeup/Walkthrough
RazorBlack
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
whois @t0nberry— An Introduction
https://cdn-images-1.medium.com/max/600/1*q16gYFe_BLcPrWyQW_2d1A.jpeg
Around February 2022 I set out to learn Python. I’ve done a little programming in my career as a Mechanical Engineer using Matlab, VBA…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
whois @t0nberry— An Introduction
https://cdn-images-1.medium.com/max/600/1*q16gYFe_BLcPrWyQW_2d1A.jpeg
Around February 2022 I set out to learn Python. I’ve done a little programming in my career as a Mechanical Engineer using Matlab, VBA…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
whois @t0nberry— An Introduction
Around February 2022 I set out to learn Python. I’ve done a little programming in my career as a Mechanical Engineer using Matlab, VBA, and…