Vesper Rebase Vulnerability Postmortem and Bug Bounty
https://medium.com/immunefi/vesper-rebase-vulnerability-postmortem-and-bug-bounty-55354a49d184?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/vesper-rebase-vulnerability-postmortem-and-bug-bounty-55354a49d184?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vesper Rebase Vulnerability Postmortem and Bug Bounty
Summary
SummaryContinue reading on Immunefi » (https://medium.com/immunefi/vesper-rebase-vulnerability-postmortem-and-bug-bounty-55354a49d184?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CISA Publishes Analysis on New 'FiveHands' Ransomware
Attackers used publicly available tools, FiveHands ransomware, and SombRAT to successfully target an organization, officials report.
___________________________
@hacking_Attack
@Hacking_Video
CISA Publishes Analysis on New 'FiveHands' Ransomware
Attackers used publicly available tools, FiveHands ransomware, and SombRAT to successfully target an organization, officials report.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
CISA Publishes Analysis on New 'FiveHands' Ransomware
Attackers used publicly available tools, FiveHands ransomware, and SombRAT to successfully target an organization, officials report.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Google Plans to Automatically Enable Two-Factor Authentication
The company plans to automatically enroll users in two-step verification if their accounts are properly configured.
___________________________
@hacking_Attack
@Hacking_Video
Google Plans to Automatically Enable Two-Factor Authentication
The company plans to automatically enroll users in two-step verification if their accounts are properly configured.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Google Plans to Automatically Enable Two-Factor Authentication
The company plans to automatically enroll users in two-step verification if their accounts are properly configured.
Apple Bug bounty XSS(2021)
https://takashi-suzuki.medium.com/apple-bug-bounty-xss-2021-78c2f4fc4106?source=rss------bug_bounty-5
About me:Continue reading on Medium » (https://takashi-suzuki.medium.com/apple-bug-bounty-xss-2021-78c2f4fc4106?source=rss------bug_bounty-5)
https://takashi-suzuki.medium.com/apple-bug-bounty-xss-2021-78c2f4fc4106?source=rss------bug_bounty-5
About me:Continue reading on Medium » (https://takashi-suzuki.medium.com/apple-bug-bounty-xss-2021-78c2f4fc4106?source=rss------bug_bounty-5)
Is the Web Application Hacker's Handbook still relevant?
https://www.reddit.com/r/Pentesting/comments/n6hyq9/is_the_web_application_hackers_handbook_still/
Python Dev breaking into pentesting here, and I can't help but wonder if a book written years ago can still get you actionable results. I have zero problems committing myself to reading it - I just want to know that there are others out there who continue to find the investment worthwhile. submitted by /u/K3ystr0k3 (https://www.reddit.com/user/K3ystr0k3)
[link] (https://www.reddit.com/r/Pentesting/comments/n6hyq9/is_the_web_application_hackers_handbook_still/) [comments] (https://www.reddit.com/r/Pentesting/comments/n6hyq9/is_the_web_application_hackers_handbook_still/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/n6hyq9/is_the_web_application_hackers_handbook_still/
Python Dev breaking into pentesting here, and I can't help but wonder if a book written years ago can still get you actionable results. I have zero problems committing myself to reading it - I just want to know that there are others out there who continue to find the investment worthwhile. submitted by /u/K3ystr0k3 (https://www.reddit.com/user/K3ystr0k3)
[link] (https://www.reddit.com/r/Pentesting/comments/n6hyq9/is_the_web_application_hackers_handbook_still/) [comments] (https://www.reddit.com/r/Pentesting/comments/n6hyq9/is_the_web_application_hackers_handbook_still/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is the Web Application Hacker's Handbook still relevant?
Python Dev breaking into pentesting here, and I can't help but wonder if a book written years ago can still get you actionable results. I have...
hacking: security in practice
Recovery Software
Okay I’ve spent the last 2 hours trying so hard to recover my deleted messages on my iPhone using recovery softwares, I’ve grown so desperate that I paid for one, but realized it made no difference. Am I just blinded by my desperation to see that every one of these is a scam? Or is there any softwares that’ll help me out? Not looking for anything free that’ll for sure fail, if you can promise me success I’ll pay for it no doubt.
submitted by /u/astrodaren
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recovery Software
Okay I’ve spent the last 2 hours trying so hard to recover my deleted messages on my iPhone using recovery softwares, I’ve grown so desperate that I paid for one, but realized it made no difference. Am I just blinded by my desperation to see that every one of these is a scam? Or is there any softwares that’ll help me out? Not looking for anything free that’ll for sure fail, if you can promise me success I’ll pay for it no doubt.
submitted by /u/astrodaren
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Recovery Software
Okay I’ve spent the last 2 hours trying so hard to recover my deleted messages on my iPhone using recovery softwares, I’ve grown so desperate that...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Conservative family member sent me this video, how much of this is bullshit?
https://external-preview.redd.it/SYl_mO-eyEvHyjO3e_vwJ_9meal4KerQK6Yi3bGFX48.jpg?width=320&crop=smart&auto=webp&s=084c3dae649ab3632da73a41055debcf2c553bdc submitted by /u/TheAoxo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Conservative family member sent me this video, how much of this is bullshit?
https://external-preview.redd.it/SYl_mO-eyEvHyjO3e_vwJ_9meal4KerQK6Yi3bGFX48.jpg?width=320&crop=smart&auto=webp&s=084c3dae649ab3632da73a41055debcf2c553bdc submitted by /u/TheAoxo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Conservative family member sent me this video, how much of this is...
Posted in r/hacking by u/TheAoxo • 1 point and 0 comments
Pentesting ISP 101 | How I hacked & fixed My ISP
This blog is about the misconfiguration issue in the ISP I was using. While working on Shodan, I discovered that ISP has left WiFi…Continue reading on InfoSec Write-ups »
Read more...
This blog is about the misconfiguration issue in the ISP I was using. While working on Shodan, I discovered that ISP has left WiFi…Continue reading on InfoSec Write-ups »
Read more...
Judge-Jury-and-Executable - A File System Forensics Analysis Scanner And Threat Hunting Tool
http://www.kitploit.com/2021/05/judge-jury-and-executable-file-system.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/05/judge-jury-and-executable-file-system.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Judge-Jury-and-Executable - A File System Forensics Analysis Scanner And Threat Hunting Tool
Features:
Scan a mounted filesystem (https://www.kitploit.com/search/label/Filesystem) for threats right away Or gather a system baseline before an incident, for extra threat hunting ability Can be used before, during or after an incident For one to many workstations Scans the MFT, bypassing file permissions, file locks or OS file protections/hiding/shadowing Up to 51 different properties gathered for every file Scan results go into an SQL table for later searching, aggregating results over many scans and/or many machines, and historical or retrospective analysis Leverage the power of SQL to search file systems, query file properties, answer complex or high-level questions, and hunt for threats or indicators of compromise
Requirements:
.NET Framework v4.8 Local or remote SQL database with read/write/create access. Visual studio (if you wish to compile the C# code) Access to the internet (or else how did you get this code??? Also for nuget packages...) Basic knowlege of SQL
Hunt for viruses, malware, and APTs on (multiple) file systems using by writing queries in SQL.
Allow me to elaborate... You start with a disk or disk images that are potentially dirty with malware, viruses, APT's (advanced persistent threats) or the like, and then scan them with this tool. (Optionally, and assuming you have the wisdom and foresight to do so, you may wish to scan a known good baseline disk image with this tool first (or later--doesn't matter). This is certainly not necessary, but can only serve to aid you.) The forensics-level scanning portion of this tool collects a bunch of properties about each file in a file system (or an image(s) of one), and places these properties in a SQL relational database table. The secret sauce comes from being able to threat hunt, investigate, or ask questions about the data through the use of queries, in the language of SQL, against the database that is created. A key feature here was NOT inventing a proprietary query language. If you know SQL, and how to click a button, then you already know how to use this tool like a boss. Even if you don't, this concept is powerful enough that canned queries (see below) will get you a lot of mileage.
Forensics-level scanning.
Firstly, the tool creates an entry in the database for each record found in the MFT (master file table--its how NTFS does its record keeping). This bypasses file security permissions, file hiding, stealth or obfuscation (https://www.kitploit.com/search/label/Obfuscation) techniques, file deletion, or timestamp tampering. These techniques will not prevent the file from being scanned and catalogued. The bytes of the file are read from the MFT and as many data points as possible are taken from the bytes of the file read from the MFT before attempting to access any data points using the higher-level OS API calls.
Rich, high-level data analytics.
After the MFT and forensics-level data is secured, operating-system-level properties, data and meta-data available about each file is collected and augments each entry created from the MFT entry. As a result of this, even if the file or its properties from the Operating System API or the dotnet framework cannot be accessed due to file permissions (ACL), file locks (is in use), disk corruption, a zero-byte-length file, or any of the various other reasons, the file's existence will still be recorded, logged and tracked. The entry, however, will simply not contain the information about it that was not accessible to the operating system. Up to 51 different data points may be collected for every file.
___________________________
@hacking_Attack
@Hacking_Video
Scan a mounted filesystem (https://www.kitploit.com/search/label/Filesystem) for threats right away Or gather a system baseline before an incident, for extra threat hunting ability Can be used before, during or after an incident For one to many workstations Scans the MFT, bypassing file permissions, file locks or OS file protections/hiding/shadowing Up to 51 different properties gathered for every file Scan results go into an SQL table for later searching, aggregating results over many scans and/or many machines, and historical or retrospective analysis Leverage the power of SQL to search file systems, query file properties, answer complex or high-level questions, and hunt for threats or indicators of compromise
Requirements:
.NET Framework v4.8 Local or remote SQL database with read/write/create access. Visual studio (if you wish to compile the C# code) Access to the internet (or else how did you get this code??? Also for nuget packages...) Basic knowlege of SQL
Hunt for viruses, malware, and APTs on (multiple) file systems using by writing queries in SQL.
Allow me to elaborate... You start with a disk or disk images that are potentially dirty with malware, viruses, APT's (advanced persistent threats) or the like, and then scan them with this tool. (Optionally, and assuming you have the wisdom and foresight to do so, you may wish to scan a known good baseline disk image with this tool first (or later--doesn't matter). This is certainly not necessary, but can only serve to aid you.) The forensics-level scanning portion of this tool collects a bunch of properties about each file in a file system (or an image(s) of one), and places these properties in a SQL relational database table. The secret sauce comes from being able to threat hunt, investigate, or ask questions about the data through the use of queries, in the language of SQL, against the database that is created. A key feature here was NOT inventing a proprietary query language. If you know SQL, and how to click a button, then you already know how to use this tool like a boss. Even if you don't, this concept is powerful enough that canned queries (see below) will get you a lot of mileage.
Forensics-level scanning.
Firstly, the tool creates an entry in the database for each record found in the MFT (master file table--its how NTFS does its record keeping). This bypasses file security permissions, file hiding, stealth or obfuscation (https://www.kitploit.com/search/label/Obfuscation) techniques, file deletion, or timestamp tampering. These techniques will not prevent the file from being scanned and catalogued. The bytes of the file are read from the MFT and as many data points as possible are taken from the bytes of the file read from the MFT before attempting to access any data points using the higher-level OS API calls.
Rich, high-level data analytics.
After the MFT and forensics-level data is secured, operating-system-level properties, data and meta-data available about each file is collected and augments each entry created from the MFT entry. As a result of this, even if the file or its properties from the Operating System API or the dotnet framework cannot be accessed due to file permissions (ACL), file locks (is in use), disk corruption, a zero-byte-length file, or any of the various other reasons, the file's existence will still be recorded, logged and tracked. The entry, however, will simply not contain the information about it that was not accessible to the operating system. Up to 51 different data points may be collected for every file.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
For each file, information collected includes:
SHA256 hash MD5 hash Import table hash (if it exists) MFT Number & Sequence Number MFT Create/Modified/Accessed Dates Create/Modified/Accessed Dates Reported by OS All the 'Standard' OS file properties: location, size, datestamps, attributes, metadata Is a PE or DLL or Driver? Is Authenticode signed? Does the X.509 certificate chain verify? Custom YARA rules (Lists the rule names that match) File entropy File entropy Up to 51 different data points in total
Canned Queries:
/*
IDEA: All files in the directory C:\Windows\System32\ should be 'owned' by TrustedInstaller.
If a file in the System32 directory is owned by a different user, this indicates an anomaly,
and that user is likely the user that created that file.
Malware likes to masquerade around as valid Windows system files.
Executables that are placed in the System32 directory not only look more official, as it is a common path for
system files, but an explicit path to that executable does not need to be supplied to execute it from the
command line, windows 'Run' dialog box of the start menu, or the win32 API call ShellExecute.
*/
SELECT
TOP 1000 *
FROM [FileProperties]
WHERE
[FileOwner] <> 'TrustedInstaller'
AND [DirectoryLocation] = ':\Windows\System32'
AND IsSigned = 0
ORDER BY [PrevalenceCount] DESC
/*
IDEA: The MFT creation timestamp and the OS creation timestamp sh ould match.
If the MFT creation timestamp occurs after the creation time reported by the OS meta-data,
this indicates an anomaly.
Timestomp is a tool that is part of the Metasploit Framework (https://www.kitploit.com/search/label/Metasploit%20Framework) that allows a user to backdate a file
to an arbitrary time of their choosing. There really isn't a good legitimate reason for doing this
(let me know if you can think of one), and is considered an anti-forensics technique.
*/
SELECT
TOP 1000 *
FROM [FileProperties]
WHERE
([MftTimeAccessed] <> [LastAccessTime]) OR
([MftTimeCreation] <> [CreationTime]) OR
([MftTimeMftModified] <> [LastWriteTime])
ORDER BY [DateSeen] DESC
/*
IDEA: The 'CompileDate' property of any executable or dll should always come before the creation timestamp for that file.
Similar logic applies as for the MFT creation timestamp occuring after the creation timestamp. How could a program have been
compiled AFTER the file that holds it was created? This anomaly indicates backdating or timestomping has occurred.
*/
SELECT
TOP 1000 *
FROM [FileProperties]
WHERE
([MftTimeCreation] < [CompileDate]) OR
([CreationTime] < [CompileDate])
ORDER BY [DateSeen] DESC
Download Judge-Jury-and-Executable (https://github.com/AdamWhiteHat/Judge-Jury-and-Executable)
___________________________
@hacking_Attack
@Hacking_Video
SHA256 hash MD5 hash Import table hash (if it exists) MFT Number & Sequence Number MFT Create/Modified/Accessed Dates Create/Modified/Accessed Dates Reported by OS All the 'Standard' OS file properties: location, size, datestamps, attributes, metadata Is a PE or DLL or Driver? Is Authenticode signed? Does the X.509 certificate chain verify? Custom YARA rules (Lists the rule names that match) File entropy File entropy Up to 51 different data points in total
Canned Queries:
/*
IDEA: All files in the directory C:\Windows\System32\ should be 'owned' by TrustedInstaller.
If a file in the System32 directory is owned by a different user, this indicates an anomaly,
and that user is likely the user that created that file.
Malware likes to masquerade around as valid Windows system files.
Executables that are placed in the System32 directory not only look more official, as it is a common path for
system files, but an explicit path to that executable does not need to be supplied to execute it from the
command line, windows 'Run' dialog box of the start menu, or the win32 API call ShellExecute.
*/
SELECT
TOP 1000 *
FROM [FileProperties]
WHERE
[FileOwner] <> 'TrustedInstaller'
AND [DirectoryLocation] = ':\Windows\System32'
AND IsSigned = 0
ORDER BY [PrevalenceCount] DESC
/*
IDEA: The MFT creation timestamp and the OS creation timestamp sh ould match.
If the MFT creation timestamp occurs after the creation time reported by the OS meta-data,
this indicates an anomaly.
Timestomp is a tool that is part of the Metasploit Framework (https://www.kitploit.com/search/label/Metasploit%20Framework) that allows a user to backdate a file
to an arbitrary time of their choosing. There really isn't a good legitimate reason for doing this
(let me know if you can think of one), and is considered an anti-forensics technique.
*/
SELECT
TOP 1000 *
FROM [FileProperties]
WHERE
([MftTimeAccessed] <> [LastAccessTime]) OR
([MftTimeCreation] <> [CreationTime]) OR
([MftTimeMftModified] <> [LastWriteTime])
ORDER BY [DateSeen] DESC
/*
IDEA: The 'CompileDate' property of any executable or dll should always come before the creation timestamp for that file.
Similar logic applies as for the MFT creation timestamp occuring after the creation timestamp. How could a program have been
compiled AFTER the file that holds it was created? This anomaly indicates backdating or timestomping has occurred.
*/
SELECT
TOP 1000 *
FROM [FileProperties]
WHERE
([MftTimeCreation] < [CompileDate]) OR
([CreationTime] < [CompileDate])
ORDER BY [DateSeen] DESC
Download Judge-Jury-and-Executable (https://github.com/AdamWhiteHat/Judge-Jury-and-Executable)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The goldmine that are Javascript files for bug bounties
https://cdn-images-1.medium.com/max/600/0*KtslEOsVnz41iVHT.jpg
A lot has already been written on this topic. It is a well-known fact, that Javascript files are a gold mine for bug bounty hunters.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The goldmine that are Javascript files for bug bounties
https://cdn-images-1.medium.com/max/600/0*KtslEOsVnz41iVHT.jpg
A lot has already been written on this topic. It is a well-known fact, that Javascript files are a gold mine for bug bounty hunters.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The goldmine that are Javascript files for bug bounties
A lot has already been written on this topic. It is a well-known fact, that Javascript files are a gold mine for bug bounty hunters.