Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Jscythe - Abuse The Node.Js Inspector Mechanism In Order To Force Any Node.Js/Electron/V8 Based Process To Execute Arbitrary Javascript Code

https://blogger.googleusercontent.com/img/a/AVvXsEgLC9Dxt9yBdiz2pq3Q2c74VF0pe_SsZ-WUdP5Si9Z6hkSqbUZV4E8-7312uXYH-WXijdbNanQGafOyRVPBAFrgm7vNOLJMAHmk6CRNx_hcnEkCNrhU-Z1WyrIBQ93rgNn6UUFoxpj5yIt3CQcO1jRhCPnqqWwSgTivtZXwfwz1q2G_wkXcUPNX3jNyTw=w640-h314
jscythe abuses the node.js inspector mechanism in order to force any node.js/electron/v8 based process to execute arbitrary javascript code, even if their debugging capabilities are disabled.

Tested and working against Visual Studio Code, Discord, any Node.js application and more!

How

1. Locate the target process.
2. Send SIGUSR1signal to the process, this will enable the debugger on a port (depending on the software, sometimes it's random, sometimes it's not).
3. Determine debugging port by diffing open ports before and after sending SIGUSR1.
4. Get the websocket debugging URL and session id from http://localhost:.
5. Send a Runtime.evaluaterequest with the provided code.
6. Profit.

Building

cargo build --release

Running

Target a specific process and execute a basic expression:

./target/debug/jscythe --pid 666 --code "5 - 3 + 2"

Execute code from a file:

./target/debug/jscythe --pid 666 --script example_script.js

The example_script.jscan require any node module and execute any code, like:

require('child_process').spawnSync('/System/Applications/Calculator.app/Contents/MacOS/Calculator', { encoding : 'utf8' }).stdout

Search process by expression:

./target/debug/jscythe --search extensionHost --script example_script.js

Other options

Run jscythe --helpfor the complete list of options.

License

This project is made with by @evilsocket and it is released under the GPL3 license.
Download Jscythe

___________________________
@hacking_Attack
@Hacking_Video
jscythe abuses the node.js inspector mechanism (https://nodejs.org/en/docs/guides/debugging-getting-started/) in order to force any node.js/electron/v8 based process to execute arbitrary javascript code, even if their debugging (https://www.kitploit.com/search/label/Debugging) capabilities are disabled. Tested and working against Visual Studio Code, Discord, any Node.js application and more! How Locate the target process. Send SIGUSR1 signal to the process, this will enable the debugger (https://www.kitploit.com/search/label/Debugger) on a port (depending on the software, sometimes it's random, sometimes it's not). Determine debugging port by diffing open ports (https://www.kitploit.com/search/label/Open%20Ports) before and after sending SIGUSR1. Get the websocket (https://www.kitploit.com/search/label/WebSocket) debugging URL and session id from http://localhost:/json. Send a Runtime.evaluate request with the provided code. Profit. Building cargo build --release Running Target a specific process and execute a basic expression: ./target/debug/jscythe --pid 666 --code "5 - 3 + 2" Execute code from a file: ./target/debug/jscythe --pid 666 --script example_script.js The example_script.js can require any node module and execute any code, like: require('child_process').spawnSync('/System/Applications/Calculator.app/Contents/MacOS/Calculator', { encoding (https://www.kitploit.com/search/label/Encoding) : 'utf8' }).stdout Search process by expression: ./target/debug/jscythe --search extensionHost --script example_script.js Other options Run jscythe --help for the complete list of options. License This project is made with by @evilsocket (https://twitter.com/evilsocket) and it is released under the GPL3 license.
Download Jscythe (https://github.com/evilsocket/jscythe)

___________________________
@hacking_Attack
@Hacking_Video
Any tips for how to conduct first pentest gig?
https://www.reddit.com/r/Pentesting/comments/yk2ga1/any_tips_for_how_to_conduct_first_pentest_gig/

Hi, I've recently passed OSCP/CEH and have been asked by a friend who owns a small company to conduct a web app pentesting for them. I need to submit a proposal for them to review. This will be my first pentest gig so I have no prior experience, which also means I don't know what is expected in such proposals. Would anyone be able to help me with following questions I have? What should the proposal look like and what information should it encompass (type of test to conduct? Estimated time taken?)? What info do I need from client side in order for me to formulate this (e.g. scope / rules of engagement)? I imagine one also needs to look at the scale of web app in order to determine how long it takes to conduct the test and therefore before I can put together a proposal? I understand pentesting is different to CTF, as one needs to be more thorough with pentesting to find all vulnerabilities rather than to find the 1 vulnerability to exploit to capture the flag. How does one make sure that it is conducted thoroughly? Do you try to test every aspect of OWASP 10 on every aspect of the web app? I imagine pentesters use vulnerability scanners to assist them to be "thorough" but what are the scanners pentesters use for this? As I was trained in the OSCP framework, I don't know much about different scanners. I know only of Nikto, Nessus.. in addition to nmap scripts. With regards to reporting at the end, how does one determine the severity of the vulnerabilities found? Is this normally just the severity given to them in CVE / CWE? Or should it be a product of that and the consequence it has to the specific client? Any advices/guidances would be helpful and are greatly appreciated!! submitted by /u/afp_chx (https://www.reddit.com/user/afp_chx)
[link] (https://www.reddit.com/r/Pentesting/comments/yk2ga1/any_tips_for_how_to_conduct_first_pentest_gig/) [comments] (https://www.reddit.com/r/Pentesting/comments/yk2ga1/any_tips_for_how_to_conduct_first_pentest_gig/)

___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty / Cybersecurity Resource Management Guide

thebinarybotContinue reading on Medium »
Read more...