Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to build your NO-log VPN Server on AWS cloud for FREE
https://cdn-images-1.medium.com/max/869/1*oTO0zi18v2o020RT_VvHaQ.png
Hello friend, Today I want to show you how to build a VPN server on the AWS cloud. We will also configure it for no logging of data.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to build your NO-log VPN Server on AWS cloud for FREE
https://cdn-images-1.medium.com/max/869/1*oTO0zi18v2o020RT_VvHaQ.png
Hello friend, Today I want to show you how to build a VPN server on the AWS cloud. We will also configure it for no logging of data.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to build your NO-log VPN Server on AWS cloud for FREE
Hello friend, Today I want to show you how to build a VPN server on the AWS cloud. We will also configure it for no logging of data.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
https://cdn-images-1.medium.com/max/1024/0*zb0GzPvxSsnwuBOu.png
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
https://cdn-images-1.medium.com/max/1024/0*zb0GzPvxSsnwuBOu.png
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
5 mistakes to avoid on the bug bounty program
https://cdn-images-1.medium.com/max/2600/0*xJiHMTDM5_zG0Y7C
Improve your testing accuracy and get the most out of your findings
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
5 mistakes to avoid on the bug bounty program
https://cdn-images-1.medium.com/max/2600/0*xJiHMTDM5_zG0Y7C
Improve your testing accuracy and get the most out of your findings
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 mistakes to avoid on the bug bounty program
Improve your testing accuracy and get the most out of your findings
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding The Skills Needed to Become a Cybersecurity Hacker
https://cdn-images-1.medium.com/max/1280/1*C0YDJe7k0vzu_p0yUFS_Wg.png
As technology is advancing, so is the need for more robust cybersecurity. The adoption of cutting-edge technology by global businesses is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Understanding The Skills Needed to Become a Cybersecurity Hacker
https://cdn-images-1.medium.com/max/1280/1*C0YDJe7k0vzu_p0yUFS_Wg.png
As technology is advancing, so is the need for more robust cybersecurity. The adoption of cutting-edge technology by global businesses is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Understanding The Skills Needed to Become a Cybersecurity Hacker
As technology is advancing, so is the need for more robust cybersecurity. The adoption of cutting-edge technology by global businesses is…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What talking to 50+ web3 security experts and protocols has taught us
https://cdn-images-1.medium.com/max/2600/1*vfnGyReXQQS848tkaG7Dig.png
~$3B has been stolen so far in 2022, nearly double the $1.5B hackers took in 2021. And the frequency and scale of attacks are increasing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What talking to 50+ web3 security experts and protocols has taught us
https://cdn-images-1.medium.com/max/2600/1*vfnGyReXQQS848tkaG7Dig.png
~$3B has been stolen so far in 2022, nearly double the $1.5B hackers took in 2021. And the frequency and scale of attacks are increasing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What talking to 50+ web3 security experts and protocols has taught us
~$3B has been stolen so far in 2022, nearly double the $1.5B hackers took in 2021. And the frequency and scale of attacks are increasing…
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
https://infosecwriteups.com/cross-origin-resource-sharing-cors-explanation-exploitation-b4179235728b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/cross-origin-resource-sharing-cors-explanation-exploitation-b4179235728b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cross-origin-resource-sharing-cors-explanation-exploitation-b4179235728b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).Continue reading on InfoSec Write-ups »
Read more...
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
NGWAF - First Iteration Of ML Based Feedback WAF
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg The Motivation | What is the N3XT ST3P?With the explosive growth of web applications since the early 2000s, web-based attacks have progressively become more rampant. One common solution is the Web Application Firewall (WAF). However, tweaking rules of current WAFs to improve the detection mechanisms can be complex and difficult. NGWAF seeks to address these drawbacks with a novel machine learning and quarantine-to-honeypot based architecture.
Inspired by actual pain points from operating WAFs, NGWAF intends to simplify and reimagine WAF operations through the following processes:
Pain point NGWAF Feature Maintenance of detection mechanisms and rules can be complex Leverage machine learning to automate the process of creating and updating detection mechanisms Immediate blocking of malicious traffic reduces chances of learning from threat actor behavior for future WAF improvements Threat elimination through redirected quarantine as opposed to conventional dropping and blocking of malicious traffic
To make deployment simple and portable, we have containerised the different components in the architecture using docker and configured them in a docker-compose file. This allows running it on a fresh install to be quick and easy as the dependencies are handled by docker automatically. The deployment can be expanded to be deployed into a local or cloud provider based kubernetes cluster, making scalabe as users can increase the number of nodes/pods to handle large amounts of traffic.
The deployment have been tested on macOS (Docker desktop), linux (ubuntu).
Check out our demo video here
NGWAF is created by @yupengfei, @zhangbosen, @matthewng and @elizabethlim
Special shoutout to @ruinahkoh for her contributions to the initial stages of NGWAF. How does NGWAF work?NGWAF runs out-of-the-box with three key components, these components as mentioned above are all containerised and are scalable according to desired usage. The protected resource can be customised by making a deployment change within the setup. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg High level architecture of NGWAF with expected traffic flows from different partiesKey BenefitsNGWAF was engineered with the following key user benefits in mind: 1. Rule Complexity ReductionNGWAF replaces traditional rulesets with deep learning models to reduce the complexity of managing and updating rules. Instead of manually editting rules, NGWAF's machine learning automates the pattern learning process from malicious data. Data collected from the quarantine environment are automatically scrubbed and batched, allowing it to be retrained into our detection model if desired. 2. Cyber DeceptionNGWAF adopts a novel architecture consisting an interactive and quarantine environment built to isolate potential hostile attackers. Unlike conventional WAFs which blocks upon detection, NGWAF diverts threat actors to emulated systems, trapping them to soften the impact of their malicious actions. The environment also act as a sinkhole to gather current attack methods, enabling the observation and collection of malicious data. These data can be used to further improve NGWAF's detection capability. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSPPvwQcqpDBqGZgS83fC6zZRKfTE8up_R40JZ80Ab-lLpki22XPcI82iTjII[...]
___________________________
@hacking_Attack
@Hacking_Video
NGWAF - First Iteration Of ML Based Feedback WAF
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg The Motivation | What is the N3XT ST3P?With the explosive growth of web applications since the early 2000s, web-based attacks have progressively become more rampant. One common solution is the Web Application Firewall (WAF). However, tweaking rules of current WAFs to improve the detection mechanisms can be complex and difficult. NGWAF seeks to address these drawbacks with a novel machine learning and quarantine-to-honeypot based architecture.
Inspired by actual pain points from operating WAFs, NGWAF intends to simplify and reimagine WAF operations through the following processes:
Pain point NGWAF Feature Maintenance of detection mechanisms and rules can be complex Leverage machine learning to automate the process of creating and updating detection mechanisms Immediate blocking of malicious traffic reduces chances of learning from threat actor behavior for future WAF improvements Threat elimination through redirected quarantine as opposed to conventional dropping and blocking of malicious traffic
To make deployment simple and portable, we have containerised the different components in the architecture using docker and configured them in a docker-compose file. This allows running it on a fresh install to be quick and easy as the dependencies are handled by docker automatically. The deployment can be expanded to be deployed into a local or cloud provider based kubernetes cluster, making scalabe as users can increase the number of nodes/pods to handle large amounts of traffic.
The deployment have been tested on macOS (Docker desktop), linux (ubuntu).
Check out our demo video here
NGWAF is created by @yupengfei, @zhangbosen, @matthewng and @elizabethlim
Special shoutout to @ruinahkoh for her contributions to the initial stages of NGWAF. How does NGWAF work?NGWAF runs out-of-the-box with three key components, these components as mentioned above are all containerised and are scalable according to desired usage. The protected resource can be customised by making a deployment change within the setup. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg High level architecture of NGWAF with expected traffic flows from different partiesKey BenefitsNGWAF was engineered with the following key user benefits in mind: 1. Rule Complexity ReductionNGWAF replaces traditional rulesets with deep learning models to reduce the complexity of managing and updating rules. Instead of manually editting rules, NGWAF's machine learning automates the pattern learning process from malicious data. Data collected from the quarantine environment are automatically scrubbed and batched, allowing it to be retrained into our detection model if desired. 2. Cyber DeceptionNGWAF adopts a novel architecture consisting an interactive and quarantine environment built to isolate potential hostile attackers. Unlike conventional WAFs which blocks upon detection, NGWAF diverts threat actors to emulated systems, trapping them to soften the impact of their malicious actions. The environment also act as a sinkhole to gather current attack methods, enabling the observation and collection of malicious data. These data can be used to further improve NGWAF's detection capability. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSPPvwQcqpDBqGZgS83fC6zZRKfTE8up_R40JZ80Ab-lLpki22XPcI82iTjII[...]
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
NGWAF - First Iteration Of ML Based Feedback WAF
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! NGWAF - First Iteration Of ML Based Feedback WAF https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfI…
usE0NdILS6cAnNYtW5DuoEBMteSldRNCW_TJ-vpoZgN52ivrPcoUmzYqymhDAiRIiE5UIMpm5SBLBWxAJ2lmcgSE5xh8WtGwNTIV3qobzOctHK4Jkl6Z2Zz1THV0vyw/w640-h400/NGWAF_2_Detection.gif NGWAF in action: Upon detection of SQL injection, NGWAF redirects to our quarantine environment, instead of dropping or blocking the attempt.3. Compliance to Internationally Recognised StandardsThe guiding principal behind the creation of NGWAF is to guard against the risks highlighted from the Open Web Application Security Project's standard awareness document - The OWASP Top 10 2021.
Training data and compliance checks for NGWAF are collected and conducted based on this requirement. The Components of NGWAF1. The Brains - Machine-Learning based WAF | Who needs manual when we can go NEURALInstead of traditional rulesets which require analysts to manually identify and add rules as time goes by, NGWAF leverages end-to-end machine learning pipelines for the detection mechanism, greatly reducing the complexity in WAF rule management, especially for detecting complex payloads. Base ModelTo do so, we needed to first create a base model and architecture that users can start off with, before they later use data collected from their own applications for retraining and fine-tuning:
1. We collected malicious and non-malicious payloads from various application logs (total of ~40k observations)
2. Instead of manually identifying rules, we leverage machine and deep learning to automate the process of learning patterns from previous malicious data.
3. We then experimented with several model architectures, and our final model utilized a sequential neural network to predict whether an incoming payload was malicious or not. PerformanceOur model was able to achieve 99.6% accuracy on our training dataset. Maintenance & RetrainingAlthough we have included logs from various applications in order to improve the generalizability of the base model, further maintenance and retraining of the model will be important to:
1. Tune the model for better performance on traffic from the user's specific application
2. Reduce model degradation over time, as threat actors discover new methods and opportunities
To address this, users of NGWAF benefit from our packaged end-to-end model retaining pipeline, and can easily trigger model maintenance with a few simple steps without having to dig under the hood. (See Section 3 below). 2. The Looking Glass - Scalable Interactive Quarantine Environment | Don't let them go, DETAIN THEM!Contrary to traditional WAFs where malicious traffic are blocked or dropped right away. NGWAF is going with a more flexible approach. Whereby, it redirects and detains malicious actors within a quarantine environment. This environment consists of various interactive emulated honeypots to try and gather more attack methods/data, these data will be utilised to potentially enhance NGWAF's detection rate of more modern and complex attacks. Capturing of Malicious data and Auto-Scrubbing for retraining purposesCurrently, NGWAF's quarantine environment forwards all data submitted by the trapped attacker to our ELK stack for analysis and visualisation. The data are auto-scrubbed into different components of the HTTP request, then packaged internally on the environment's backend in JSON format before forwarding. This helps to lower the manpower cost required to clean and index the data when we kickstart the retraining process. Creating your customised quarantine environmentNGWAF currently provides users to make changes to the look and feel of the front-end aspect of our honeypots within the quarantine environment (based off a customised version of drupot). Users simply have to replace the assets folder within the docker volume with their front-end assets of choice.
NGWAF is also accommodating to users who would like to link their own honeypots as part of the quarantine environment. Users just have to forward the honeypot's HTTP requests to the environment[...]
___________________________
@hacking_Attack
@Hacking_Video
Training data and compliance checks for NGWAF are collected and conducted based on this requirement. The Components of NGWAF1. The Brains - Machine-Learning based WAF | Who needs manual when we can go NEURALInstead of traditional rulesets which require analysts to manually identify and add rules as time goes by, NGWAF leverages end-to-end machine learning pipelines for the detection mechanism, greatly reducing the complexity in WAF rule management, especially for detecting complex payloads. Base ModelTo do so, we needed to first create a base model and architecture that users can start off with, before they later use data collected from their own applications for retraining and fine-tuning:
1. We collected malicious and non-malicious payloads from various application logs (total of ~40k observations)
2. Instead of manually identifying rules, we leverage machine and deep learning to automate the process of learning patterns from previous malicious data.
3. We then experimented with several model architectures, and our final model utilized a sequential neural network to predict whether an incoming payload was malicious or not. PerformanceOur model was able to achieve 99.6% accuracy on our training dataset. Maintenance & RetrainingAlthough we have included logs from various applications in order to improve the generalizability of the base model, further maintenance and retraining of the model will be important to:
1. Tune the model for better performance on traffic from the user's specific application
2. Reduce model degradation over time, as threat actors discover new methods and opportunities
To address this, users of NGWAF benefit from our packaged end-to-end model retaining pipeline, and can easily trigger model maintenance with a few simple steps without having to dig under the hood. (See Section 3 below). 2. The Looking Glass - Scalable Interactive Quarantine Environment | Don't let them go, DETAIN THEM!Contrary to traditional WAFs where malicious traffic are blocked or dropped right away. NGWAF is going with a more flexible approach. Whereby, it redirects and detains malicious actors within a quarantine environment. This environment consists of various interactive emulated honeypots to try and gather more attack methods/data, these data will be utilised to potentially enhance NGWAF's detection rate of more modern and complex attacks. Capturing of Malicious data and Auto-Scrubbing for retraining purposesCurrently, NGWAF's quarantine environment forwards all data submitted by the trapped attacker to our ELK stack for analysis and visualisation. The data are auto-scrubbed into different components of the HTTP request, then packaged internally on the environment's backend in JSON format before forwarding. This helps to lower the manpower cost required to clean and index the data when we kickstart the retraining process. Creating your customised quarantine environmentNGWAF currently provides users to make changes to the look and feel of the front-end aspect of our honeypots within the quarantine environment (based off a customised version of drupot). Users simply have to replace the assets folder within the docker volume with their front-end assets of choice.
NGWAF is also accommodating to users who would like to link their own honeypots as part of the quarantine environment. Users just have to forward the honeypot's HTTP requests to the environment[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
usE0NdILS6cAnNYtW5DuoEBMteSldRNCW_TJ-vpoZgN52ivrPcoUmzYqymhDAiRIiE5UIMpm5SBLBWxAJ2lmcgSE5xh8WtGwNTIV3qobzOctHK4Jkl6Z2Zz1THV0vyw/w640-h400/NGWAF_2_Detection.gif NGWAF in action: Upon detection of SQL injection, NGWAF redirects to our quarantine environment…
's backend server (backend processes will automatically scrub and forward data to the analysis dashboard - ELK stack). 3. The Library - Retraining Sequence to Reinforce the Brains | Smart isn't really smart till you can keep learning.As new payloads and attack vectors emerge, it is important to upgrade detection capabilities in order to ensure security. Hence, a retraining function is built into NGWAF to ensure defenders are able to train the machine learning model to detect those newer payloads.
Retraining of datasets is one of the main features in NGWAF. On our dashboard, users can insert new dataset for retraining, to strengthen and improve the quality of NGWAF detection of malicious payloads. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXMN96I_NlC7n-NaFAtHiAjmBidGLdV3eMSoT-dO53A1_dTyMwz0sWBd0YOP6XnOYLaGPyeOLblUuUZ7ju0w3ikggWDWwPQmk_BK2BH9mVc_TXKr9yLKEjFGeoVxd5ryoZXJ_0CcPbFuqUQeHjTgi1JujdidPEAMzAkkvbznWxllCCCnzXvnKfQqqnQ/w640-h400/NGWAF_3_Training.gif This can be achieved in the following steps:
1.
Create a new dataset (.csv) for upload in the following format (empty column, training data, label). You can refer to
2.
Navigate to
3.
Select the "Import Dataset" tab and upload the training set you have created https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOGi6j2OjObUliMlc5L3a6bcs26IW30_JW31c6yoebSp8S12LQ3Hueve23a5hR1oN7UIXbDvHigZJz0-ofxKnN5mpsAhC0bI3TuXfRWqE98AIhgdFQu0VZ5R-tJsZlLnfjr6i8HfDfq-wx9El9Qf0q2xDZywb0PD270c6ASfcedFAGHrto_52NmIP9MQ/w640-h318/NGWAF_4_ngwaf_admin_upload_panel.png 1. Confirm that the training set have been uploaded successfully under the "Manage Datasets" tab. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8GC1sBxm3JV7dmdlzC24xEPvkzoeBvswwqoo8SS5kgRRgtDTU1skUfNBMR7FCbNWC9MiANk9lp3i9rN9ooe9G_yS0zrJGC-zjDPa359B2Ov971rHVc01VDJNIXANHdiQ5L8iiOV0Druj8d2xjZI0BYUuFT5LjcZDUBZt5GY_xsuOBV_chE4MnInA25g/w640-h318/NGWAF_5_ngwaf_admin_view_datasets.png 1. Under "Manage Model" tab, select the dataset(s) you want to retrain the model on and click on the "UPDATE WAF MODEL" button. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTz5H5OOjRnPDT2vPzTsA9fx_ixDJkINHHW5YSxChKovBZ7xV3KxO5jWuUZ5tJztNv4_lzY58o7KYhC6XeL53rZuIjeBnfA6iebp52HH4bXXfek9ulrHJlA0B10vxevSLoNW7PsGDKDl5eqxgDhPBij3r1dotqSpgCgXl2iyrh9tRazOj-iJTjhZjrdA/w640-h318/NGWAF_6_ngwaf_admin_retrain_model.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpB_FDAtqMDUIlgGpxfcHW-fBXsC2r5HFQldLXIkk_hGlw05rOoeaZrR81aPHBpPOt-8Egg4eQ4JZCDxXIa15G7o3Y5aHmtPwPTzeLb68IF6cQzsi-bzanwoYDxQbY76Hjj_QGqOzq2Drg7Mpmah20a5I9OnlQlwoOzMcPIyBU0GIycq2g8bmjXFIAxQ/w640-h316/NGWAF_7_ngwaf_admin_retrain_model_wait.png 1. Congrats! The model should finish re-training after some time. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM4Q0N5_Wjd5Nz2eQEwURHyrdDWTdpYY-lEJGZx5Mj4jbTdAUfHlHtvG-WDDXGdxG5odn--rSuLaJyMacKg6AWoMmoMl0NVRvdU6EQADrdaQfV88DLiJVk7BfGzFQLFN9vABQC2FHN4jMQv84yVUGGqXCRvoUKmENvzraWoGBQZdO_OrSf901MoqpoZg/w640-h318/NGWAF_8.png 4. Additional Features:NGWAF uses ELK stack to capture logs of network data that passes through NGWAF, allowing users to monitor the traffic that passes through the NGWAF for further analysis. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1eYCFZaSmTZOmXsjkZFNzFz0uvbvCn0-6bT2Aj8j4UTvLNVn-cmsi5ZWdMikOWuGfq_SOHASJBwfr-oUSORugV2nGVmlLfYXaniIvG1ESAIeCDkfB_tOm2WFdwoBtlIIzoGwN7bT93JWUn1muHdbIZxeTS8z-9p16XtObuc1B6VwqW7H-Y3rwMsBHiQ/w640-h400/NGWAF_9_ElasticSearch.gif NGWAF also comes with live Telegram notification, to inform owners about live malicious threats that is detected by NGWAF. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhV7JirXJJqOL_uJeTvU2IxFFDd5AUDTGBdxBI8hzGPzHsDo_23nWYAiSU4OgwnpldgBM1icC0lKJhP9HgdKHBcSHOCxdS6ilMmOy13Aax2AEwf0sgZC39B_bwxuSvC7x19-dBtegbJwyF0K9GgleJPNUgvyI3nxwpesPM0_iFr_pX6hvv52ISrgjdZw/w640-h400/NGWAF_10_Telegram_notif.gif Sample Usage Scenarios1. N[...]
___________________________
@hacking_Attack
@Hacking_Video
Retraining of datasets is one of the main features in NGWAF. On our dashboard, users can insert new dataset for retraining, to strengthen and improve the quality of NGWAF detection of malicious payloads. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXMN96I_NlC7n-NaFAtHiAjmBidGLdV3eMSoT-dO53A1_dTyMwz0sWBd0YOP6XnOYLaGPyeOLblUuUZ7ju0w3ikggWDWwPQmk_BK2BH9mVc_TXKr9yLKEjFGeoVxd5ryoZXJ_0CcPbFuqUQeHjTgi1JujdidPEAMzAkkvbznWxllCCCnzXvnKfQqqnQ/w640-h400/NGWAF_3_Training.gif This can be achieved in the following steps:
1.
Create a new dataset (.csv) for upload in the following format (empty column, training data, label). You can refer to
patch_sqli.csvas an example.2.
Navigate to
http://localhost:8088to view NGWAF admin panel.3.
Select the "Import Dataset" tab and upload the training set you have created https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOGi6j2OjObUliMlc5L3a6bcs26IW30_JW31c6yoebSp8S12LQ3Hueve23a5hR1oN7UIXbDvHigZJz0-ofxKnN5mpsAhC0bI3TuXfRWqE98AIhgdFQu0VZ5R-tJsZlLnfjr6i8HfDfq-wx9El9Qf0q2xDZywb0PD270c6ASfcedFAGHrto_52NmIP9MQ/w640-h318/NGWAF_4_ngwaf_admin_upload_panel.png 1. Confirm that the training set have been uploaded successfully under the "Manage Datasets" tab. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8GC1sBxm3JV7dmdlzC24xEPvkzoeBvswwqoo8SS5kgRRgtDTU1skUfNBMR7FCbNWC9MiANk9lp3i9rN9ooe9G_yS0zrJGC-zjDPa359B2Ov971rHVc01VDJNIXANHdiQ5L8iiOV0Druj8d2xjZI0BYUuFT5LjcZDUBZt5GY_xsuOBV_chE4MnInA25g/w640-h318/NGWAF_5_ngwaf_admin_view_datasets.png 1. Under "Manage Model" tab, select the dataset(s) you want to retrain the model on and click on the "UPDATE WAF MODEL" button. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTz5H5OOjRnPDT2vPzTsA9fx_ixDJkINHHW5YSxChKovBZ7xV3KxO5jWuUZ5tJztNv4_lzY58o7KYhC6XeL53rZuIjeBnfA6iebp52HH4bXXfek9ulrHJlA0B10vxevSLoNW7PsGDKDl5eqxgDhPBij3r1dotqSpgCgXl2iyrh9tRazOj-iJTjhZjrdA/w640-h318/NGWAF_6_ngwaf_admin_retrain_model.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpB_FDAtqMDUIlgGpxfcHW-fBXsC2r5HFQldLXIkk_hGlw05rOoeaZrR81aPHBpPOt-8Egg4eQ4JZCDxXIa15G7o3Y5aHmtPwPTzeLb68IF6cQzsi-bzanwoYDxQbY76Hjj_QGqOzq2Drg7Mpmah20a5I9OnlQlwoOzMcPIyBU0GIycq2g8bmjXFIAxQ/w640-h316/NGWAF_7_ngwaf_admin_retrain_model_wait.png 1. Congrats! The model should finish re-training after some time. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM4Q0N5_Wjd5Nz2eQEwURHyrdDWTdpYY-lEJGZx5Mj4jbTdAUfHlHtvG-WDDXGdxG5odn--rSuLaJyMacKg6AWoMmoMl0NVRvdU6EQADrdaQfV88DLiJVk7BfGzFQLFN9vABQC2FHN4jMQv84yVUGGqXCRvoUKmENvzraWoGBQZdO_OrSf901MoqpoZg/w640-h318/NGWAF_8.png 4. Additional Features:NGWAF uses ELK stack to capture logs of network data that passes through NGWAF, allowing users to monitor the traffic that passes through the NGWAF for further analysis. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1eYCFZaSmTZOmXsjkZFNzFz0uvbvCn0-6bT2Aj8j4UTvLNVn-cmsi5ZWdMikOWuGfq_SOHASJBwfr-oUSORugV2nGVmlLfYXaniIvG1ESAIeCDkfB_tOm2WFdwoBtlIIzoGwN7bT93JWUn1muHdbIZxeTS8z-9p16XtObuc1B6VwqW7H-Y3rwMsBHiQ/w640-h400/NGWAF_9_ElasticSearch.gif NGWAF also comes with live Telegram notification, to inform owners about live malicious threats that is detected by NGWAF. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhV7JirXJJqOL_uJeTvU2IxFFDd5AUDTGBdxBI8hzGPzHsDo_23nWYAiSU4OgwnpldgBM1icC0lKJhP9HgdKHBcSHOCxdS6ilMmOy13Aax2AEwf0sgZC39B_bwxuSvC7x19-dBtegbJwyF0K9GgleJPNUgvyI3nxwpesPM0_iFr_pX6hvv52ISrgjdZw/w640-h400/NGWAF_10_Telegram_notif.gif Sample Usage Scenarios1. N[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
's backend server (backend processes will automatically scrub and forward data to the analysis dashboard - ELK stack). 3. The Library - Retraining Sequence to Reinforce the Brains | Smart isn't really smart till you can keep learning.As new payloads and attack…
ewly normal application (Use the inbuilt web cloner / create another duplicate deployment to use as isolation environment)
2. Integrate into existing honeypot/honeynet (Update the configuration to point to honeypot/honeynet) Setting up NGWAF | Requirements, installation, and usageRequirementsTested Operating Systems
1. macOS (Docker Desktop)
2. linux WAF Component1. Python
2. request
3. fastapi
4. pandas
5. scikit-learn
6. tensorflow (tentative)
7. nltk WAF Admin Panel Component1. fastapi
2. scikit-learn
3. nltk
4. pandas
5. Create React App
6. React Material Admin Template by Flatlogic Decode Layer1. Cyberchef Server Caching Layer1. Redis Quarantine Environment1. Drupot
2. Elastic Search Stack Components (Elasticsearch, Logstash, Kibana, Filebeats) Web App1. DVWA
2. OWASP Installation and UsageWith Docker running, run the following file using the command below:
Port Service Remarks Credentials (If applicable) 8080 DVWA Where the WAF resides admin:password 5601 Elasticsearch To view logs elastic:changeme 8088 Admin Dashboard Dashboard to manage the WAF model 5001 Drupot Honeypot
To allow for Telegram live notifications, do replace the following variables in
___________________________
@hacking_Attack
@Hacking_Video
2. Integrate into existing honeypot/honeynet (Update the configuration to point to honeypot/honeynet) Setting up NGWAF | Requirements, installation, and usageRequirementsTested Operating Systems
1. macOS (Docker Desktop)
2. linux WAF Component1. Python
2. request
3. fastapi
4. pandas
5. scikit-learn
6. tensorflow (tentative)
7. nltk WAF Admin Panel Component1. fastapi
2. scikit-learn
3. nltk
4. pandas
5. Create React App
6. React Material Admin Template by Flatlogic Decode Layer1. Cyberchef Server Caching Layer1. Redis Quarantine Environment1. Drupot
2. Elastic Search Stack Components (Elasticsearch, Logstash, Kibana, Filebeats) Web App1. DVWA
2. OWASP Installation and UsageWith Docker running, run the following file using the command below:
./run.shTo replace the targets, point the dest_serverand honey_pot_servervariable to the correct targets in the /waf/WafApp/waf.pyfile # Replace me
dest_server = "dvwa"
honey_pot_server = "drupot:5000"Once the Docker container is up, you can visit your localhost, in which these ports are running these services:Port Service Remarks Credentials (If applicable) 8080 DVWA Where the WAF resides admin:password 5601 Elasticsearch To view logs elastic:changeme 8088 Admin Dashboard Dashboard to manage the WAF model 5001 Drupot Honeypot
To allow for Telegram live notifications, do replace the following variables in
/waf/WafApp/waf.pywith a valid TELEGRAM tokens. token='Disclaimers & Other ConsiderationsNGWAF is a W.I.P, Open source project, functions and features may change from patch to patch. If you are interested to contribute, please feel free to create an issue or pull request! LicensingLicenseGNU General Public License Download NGWAF___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New StrelaStealer malware steals your Outlook, Thunderbird accounts
New StrelaStealer malware steals your Outlook, Thunderbird accountsPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A new information-stealing malware named ‘StrelaStealer’ is actively stealing email account credentials from Outlook and Thunderbird, two widely used email clients.This behavior deviates from most info-stealers, which attempt to steal data from various data sources, including browsers, cryptocurrency wallet apps, cloud gaming apps, the clipboard, etc.
The previously unknown malware was discovered by analysts at DCSO CyTec, who report that they first saw it in the wild in early November 2022, targeting Spanish-speaking users.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Polyglot file infectionStrelaStealer arrives on the victim’s system via email attachments, currently ISO files with varying content.
In one example, the ISO contains an executable (‘msinfo32.exe’) that sideloads the bundled malware via DLL order hijacking.
In a more interesting case seen by the analysts, the ISO contains an LNK file (‘Factura.lnk’) and an HTML file (‘x.html’). The x.html file is of particular interest because it is a polyglot file, which is a file that can be treated as different file formats depending on the application that opens it.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/diagram(19).png
StrelaStealer detailsUpon execution, StrelaStealer searches the ‘%APPDATA%\Thunderbird\Profiles\’ directory for ‘logins.json’ (account and password) and ‘key4.db’ (password database) and exfiltrates their contents to the C2 server.
For Outlook, StrelaStealer reads the Windows Registry to retrieve the software’s key and then locates the ‘IMAP User’, ‘IMAP Server’, and ‘IMAP Password’ values.
The IMAP Password contains the user password in encrypted form, so the malware uses the Windows CryptUnprotectData function to decrypt it before it’s exfiltrated to the C2 along with the server and user details.
Finally, StrelaStealer validates that the C2 received the data by checking for a specific response and quits when it receives it. Otherwise, it enters a 1-second sleep and retries this data-theft routine.
Since the malware is spread using Spanish-language lures and focuses on very specific software, it may be used in highly targeted attacks. However, DCSO CyTec couldn’t determine more about its distribution.
Trending: The Emotet botnet returns with a vengeance
Are u a security researcher? Or a company that writes articles or wr[...]
___________________________
@hacking_Attack
@Hacking_Video
New StrelaStealer malware steals your Outlook, Thunderbird accounts
New StrelaStealer malware steals your Outlook, Thunderbird accountsPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A new information-stealing malware named ‘StrelaStealer’ is actively stealing email account credentials from Outlook and Thunderbird, two widely used email clients.This behavior deviates from most info-stealers, which attempt to steal data from various data sources, including browsers, cryptocurrency wallet apps, cloud gaming apps, the clipboard, etc.
The previously unknown malware was discovered by analysts at DCSO CyTec, who report that they first saw it in the wild in early November 2022, targeting Spanish-speaking users.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Polyglot file infectionStrelaStealer arrives on the victim’s system via email attachments, currently ISO files with varying content.
In one example, the ISO contains an executable (‘msinfo32.exe’) that sideloads the bundled malware via DLL order hijacking.
In a more interesting case seen by the analysts, the ISO contains an LNK file (‘Factura.lnk’) and an HTML file (‘x.html’). The x.html file is of particular interest because it is a polyglot file, which is a file that can be treated as different file formats depending on the application that opens it.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/diagram(19).png
StrelaStealer detailsUpon execution, StrelaStealer searches the ‘%APPDATA%\Thunderbird\Profiles\’ directory for ‘logins.json’ (account and password) and ‘key4.db’ (password database) and exfiltrates their contents to the C2 server.
For Outlook, StrelaStealer reads the Windows Registry to retrieve the software’s key and then locates the ‘IMAP User’, ‘IMAP Server’, and ‘IMAP Password’ values.
The IMAP Password contains the user password in encrypted form, so the malware uses the Windows CryptUnprotectData function to decrypt it before it’s exfiltrated to the C2 along with the server and user details.
Finally, StrelaStealer validates that the C2 received the data by checking for a specific response and quits when it receives it. Otherwise, it enters a 1-second sleep and retries this data-theft routine.
Since the malware is spread using Spanish-language lures and focuses on very specific software, it may be used in highly targeted attacks. However, DCSO CyTec couldn’t determine more about its distribution.
Trending: The Emotet botnet returns with a vengeance
Are u a security researcher? Or a company that writes articles or wr[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New StrelaStealer malware steals your Outlook, Thunderbird accounts | Black Hat Ethical Hacking
A new information-stealing malware named 'StrelaStealer' is actively stealing email account credentials from Outlook and Thunderbird, two widely used email clients.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New StrelaStealer malware steals your Outlook, Thunderbird accounts New StrelaStealer malware steals your Outlook, Thunderbird accountsPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png…
ite ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-1-300x150.png Malicious extension lets attackers control Google Chrome remotelyNovember 9, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-300x150.png Azov Ransomware is a wiper, destroying data 666 bytes at a timeNovember 8, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-13-300x150.png Microsoft sued for open-source piracy through GitHub CopilotNovember 7, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-11-300x150.png New clipboard hijacker replaces crypto wallet addresses with lookalikesNovember 4, 2022
Reading Time: 5 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post New StrelaStealer malware steals your Outlook, Thunderbird accounts first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-1-300x150.png Malicious extension lets attackers control Google Chrome remotelyNovember 9, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-300x150.png Azov Ransomware is a wiper, destroying data 666 bytes at a timeNovember 8, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-13-300x150.png Microsoft sued for open-source piracy through GitHub CopilotNovember 7, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-11-300x150.png New clipboard hijacker replaces crypto wallet addresses with lookalikesNovember 4, 2022
Reading Time: 5 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post New StrelaStealer malware steals your Outlook, Thunderbird accounts first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video