A Defense Content Developer will be answering questions on Reddit.
https://www.reddit.com/r/Pentesting/comments/yfm6d5/a_defense_content_developer_will_be_answering/
submitted by /u/Offsec_Community (https://www.reddit.com/user/Offsec_Community)
[link] (https://www.reddit.com/r/offensive_security/comments/ycl3i6/a_defense_content_developer_will_be_answering/) [comments] (https://www.reddit.com/r/Pentesting/comments/yfm6d5/a_defense_content_developer_will_be_answering/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/yfm6d5/a_defense_content_developer_will_be_answering/
submitted by /u/Offsec_Community (https://www.reddit.com/user/Offsec_Community)
[link] (https://www.reddit.com/r/offensive_security/comments/ycl3i6/a_defense_content_developer_will_be_answering/) [comments] (https://www.reddit.com/r/Pentesting/comments/yfm6d5/a_defense_content_developer_will_be_answering/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
A Defense Content Developer will be answering questions on Reddit.
Posted in r/Pentesting by u/Offsec_Community • 4 points and 0 comments
This is a short write up and to be honest “lazy” to write this.Continue reading on Medium » (https://medium.com/@nanwinata/rce-docker-api-but-11ff70825935?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
RCE docker api, but …
This is a short write up and to be honest “lazy” to write this.
The Top 6 Bug Hunters With $1M+ Net Bounties
https://medium.com/the-gray-area/the-top-6-bug-hunters-with-1m-net-bounties-f4c998fe2ded?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/the-gray-area/the-top-6-bug-hunters-with-1m-net-bounties-f4c998fe2ded?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Top 6 Bug Hunters With $1M+ Net Bounties
TL;DR- There are only a handful of hunters who have passed $1,000,000 in total bounty payouts, the first of them barely out of high school…
TL;DR- There are only a handful of hunters who have passed $1,000,000 in total bounty payouts, the first of them barely out of high school…Continue reading on The Gray Area » (https://medium.com/the-gray-area/the-top-6-bug-hunters-with-1m-net-bounties-f4c998fe2ded?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Top 6 Bug Hunters With $1M+ Net Bounties
TL;DR- There are only a handful of hunters who have passed $1,000,000 in total bounty payouts, the first of them barely out of high school…
Bug Zero at a Glance [Week 22–28 October]
https://blog.bugzero.io/so-what-happened-this-week-22-28-october-266348be46d1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://blog.bugzero.io/so-what-happened-this-week-22-28-october-266348be46d1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Zero at a Glance [Week 22–28 October]
What happened with Bug Zero?
What happened with Bug Zero?Continue reading on Bug Zero » (https://blog.bugzero.io/so-what-happened-this-week-22-28-october-266348be46d1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Zero at a Glance [Week 22–28 October]
What happened with Bug Zero?
RCE docker api, but …
This is a short write up and to be honest “lazy” to write this.Continue reading on Medium »
Read more...
This is a short write up and to be honest “lazy” to write this.Continue reading on Medium »
Read more...
The Top 6 Bug Hunters With $1M+ Net Bounties
TL;DR- There are only a handful of hunters who have passed $1,000,000 in total bounty payouts, the first of them barely out of high school…Continue reading on The Gray Area »
Read more...
TL;DR- There are only a handful of hunters who have passed $1,000,000 in total bounty payouts, the first of them barely out of high school…Continue reading on The Gray Area »
Read more...
Bug Zero at a Glance [Week 22–28 October]
What happened with Bug Zero?Continue reading on Bug Zero »
Read more...
What happened with Bug Zero?Continue reading on Bug Zero »
Read more...
KitPloit - PenTest Tools!
Sandman - NTP Based Backdoor For Red Team Engagements In Hardened Networks
https://blogger.googleusercontent.com/img/a/AVvXsEgojLgd6sJR_TeNcazI5aPkQwckwIr_3-PCUhF6PXGkwVB9Lej80_ciLS0tK2LrUGVDOPl2C-j8eoYpcZGdT0zyklHu1IjRZmdWysuVBw91kmbQ2kWZR2nJ_7lhea417b22apQ-kXEU3QYNCvk-XcuA_N23Peog566GqAvQlCU9YPmqBisQeUr9jgVFsA=w640-h388 Sandman is a backdoor that is meant to work on hardened networks during red team engagements.
Sandman works as a stager and leverages NTP (a protocol to sync time & date) to get and run an arbitrary shellcode from a pre-defined server.
Since NTP is a protocol that is overlooked by many defenders resulting in wide network accessibility. UsageSandmanServer (Usage)Run on windows / *nix machine:
Network Adapter: The adapter that you want the server to listen on (for example Ethernet for Windows, eth0 for *nix).
*
Payload Url: The URL to your shellcode, it could be your agent (for example, CobaltStrike or meterpreter) or another stager.
*
IP to Spoof: If you want to spoof a legitimate IP address (for example, time.microsoft.com's IP address). SandmanBackdoor (Usage)To start, you can compile the SandmanBackdoor as mentioned below, because it is a single lightweight C# executable you can execute it via ExecuteAssembly, run it as an NTP provider or just execute/inject it. SandmanBackdoorTimeProvider (Usage)To use it, you will need to follow simple steps:
* Add the following registry value:
Getting and executing an arbitrary payload from an attacker's controlled server.
*
Can work on hardened networks since NTP is usually allowed in FW.
*
Impersonating a legitimate NTP server via IP spoofing. SetupSandmanServer (Setup)*
Python 3.9
*
The requirements are specified in the requirements file. SandmanBackdoor (Setup)To compile the backdoor I used Visual Studio 2022, but as mentioned in the usage section it can be compiled with both VS2022 and CSC. You can compile it either using the USE_SHELLCODE and use Orca's shellcode or without USE_SHELLCODE to use WebClient. SandmanBackdoorTimeProvider (Setup)To compile the backdoor I used Visual Studio 2022, you will also need to install DllExport (via Nuget or any other way) to compile it. You can compile it either using the USE_SHELLCODE and use Orca's shellcode or without USE_SHELLCODE to use WebClient. IOCs*
A shellcode is injected into RuntimeBroker.
*
Suspicious NTP communication starts with a known magic header.
*
YARA rule. Contributes* Orca for the shellcode.
*
Special thanks to Tim McGuffin for the time provider idea.
Thanks to those who already contributed and I'll happily accept contributions, make a pull request and I will review it! Download Sandman
___________________________
@hacking_Attack
@Hacking_Video
Sandman - NTP Based Backdoor For Red Team Engagements In Hardened Networks
https://blogger.googleusercontent.com/img/a/AVvXsEgojLgd6sJR_TeNcazI5aPkQwckwIr_3-PCUhF6PXGkwVB9Lej80_ciLS0tK2LrUGVDOPl2C-j8eoYpcZGdT0zyklHu1IjRZmdWysuVBw91kmbQ2kWZR2nJ_7lhea417b22apQ-kXEU3QYNCvk-XcuA_N23Peog566GqAvQlCU9YPmqBisQeUr9jgVFsA=w640-h388 Sandman is a backdoor that is meant to work on hardened networks during red team engagements.
Sandman works as a stager and leverages NTP (a protocol to sync time & date) to get and run an arbitrary shellcode from a pre-defined server.
Since NTP is a protocol that is overlooked by many defenders resulting in wide network accessibility. UsageSandmanServer (Usage)Run on windows / *nix machine:
python3 sandman_server.py "Network Adapter" "Payload Url" "optional: ip to spoof"* Network Adapter: The adapter that you want the server to listen on (for example Ethernet for Windows, eth0 for *nix).
*
Payload Url: The URL to your shellcode, it could be your agent (for example, CobaltStrike or meterpreter) or another stager.
*
IP to Spoof: If you want to spoof a legitimate IP address (for example, time.microsoft.com's IP address). SandmanBackdoor (Usage)To start, you can compile the SandmanBackdoor as mentioned below, because it is a single lightweight C# executable you can execute it via ExecuteAssembly, run it as an NTP provider or just execute/inject it. SandmanBackdoorTimeProvider (Usage)To use it, you will need to follow simple steps:
* Add the following registry value:
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient" /v DllName /t REG_SZ /d "C:\Path\To\TheDll.dll"* Restart the w32time service: sc stop w32time
sc start w32timeNOTE: Make sure you are compiling with the x64 option and not any CPU option! Capabilities* Getting and executing an arbitrary payload from an attacker's controlled server.
*
Can work on hardened networks since NTP is usually allowed in FW.
*
Impersonating a legitimate NTP server via IP spoofing. SetupSandmanServer (Setup)*
Python 3.9
*
The requirements are specified in the requirements file. SandmanBackdoor (Setup)To compile the backdoor I used Visual Studio 2022, but as mentioned in the usage section it can be compiled with both VS2022 and CSC. You can compile it either using the USE_SHELLCODE and use Orca's shellcode or without USE_SHELLCODE to use WebClient. SandmanBackdoorTimeProvider (Setup)To compile the backdoor I used Visual Studio 2022, you will also need to install DllExport (via Nuget or any other way) to compile it. You can compile it either using the USE_SHELLCODE and use Orca's shellcode or without USE_SHELLCODE to use WebClient. IOCs*
A shellcode is injected into RuntimeBroker.
*
Suspicious NTP communication starts with a known magic header.
*
YARA rule. Contributes* Orca for the shellcode.
*
Special thanks to Tim McGuffin for the time provider idea.
Thanks to those who already contributed and I'll happily accept contributions, make a pull request and I will review it! Download Sandman
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Sandman - NTP Based Backdoor For Red Team Engagements In Hardened Networks
My Methodology for Making a Book library with Notion for Bug Bounty and Pentesting
https://sl4x0.medium.com/my-methodology-for-making-a-book-library-with-notion-for-bug-bounty-and-pentesting-b9bf0fbbbb6d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sl4x0.medium.com/my-methodology-for-making-a-book-library-with-notion-for-bug-bounty-and-pentesting-b9bf0fbbbb6d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Methodology for Making a Book library with Notion for Bug Bounty and Pentesting
How to Use Notion 100% in Your Bug Bounyt and Pentesting Self-Study.
How to Use Notion 100% in Your Bug Bounyt and Pentesting Self-Study.Continue reading on Medium » (https://sl4x0.medium.com/my-methodology-for-making-a-book-library-with-notion-for-bug-bounty-and-pentesting-b9bf0fbbbb6d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Methodology for Making a Book library with Notion for Bug Bounty and Pentesting
How to Use Notion 100% in Your Bug Bounyt and Pentesting Self-Study.
Summary of almost all paid bounty reports on H1Continue reading on Medium » (https://medium.com/@reconshell.com/bug-bounty-reports-6385b37a468e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty Reports
Summary of almost all paid bounty reports on H1
Practical Dynamic Analysis Of Mobile Applications
https://medium.com/@abwahab5095/practical-dynamic-analysis-of-mobile-applications-660e9be0955b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@abwahab5095/practical-dynamic-analysis-of-mobile-applications-660e9be0955b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Practical Dynamic Analysis Of Mobile Applications
Hands-on Practical Dynamic Analysis Of Mobile Applications