How to Get Into Bug Bounties?( Beginner’s guide)
Hello Future Bug Bounty Hunters!Continue reading on Medium »
Read more...
Hello Future Bug Bounty Hunters!Continue reading on Medium »
Read more...
Reflected XSS using Double Encoding
Bypassing XSS filters using Double EncodingContinue reading on Medium »
Read more...
Bypassing XSS filters using Double EncodingContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Updated RapperBot malware targets game servers in DDoS attacks
Updated RapperBot malware targets game servers in DDoS attacksPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The Mirai-based botnet ‘RapperBot’ has re-emerged via a new campaign that infects IoT devices for DDoS (Distributed Denial of Service) attacks against game servers.The malware was discovered by Fortinet researchers last August when it used SSH brute-forcing to spread on Linux servers.
By tracing its activities, the researchers found that RapperBot has been operational since May 2021, but its exact goals were hard to decipher.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/campaigns.png
Lifting the lid on RapperBotFortinet analysts could sample the new variant using C2 communication artifacts collected in the previous campaigns, indicating that this aspect of the botnet’s operation has not changed.
The analysts noticed the new variant featured several differences, including support for Telnet brute-forcing, using the following commands:
* Register (used by the client)
* Keep-Alive/Do nothing
* Stop all DoS attacks and terminate the client
* Perform a DoS attack
* Stop all DoS attacks
* Restart Telnet brute forcing
* Stop Telnet brute forcing
The malware tries to brute force devices using common weak credentials from a hardcoded list, whereas previously, it fetched a list from the C2.
“To optimize brute forcing efforts, the malware compares the server prompt upon connection to a hardcoded list of strings to identify the possible device and then only tries the known credentials for that device,” explains Fortinet.
“Unlike less sophisticated IoT malware, this allows the malware to avoid trying to test a full list of credentials.”
After successfully finding credentials, it reports it to the C2 via port 5123 and then attempts to fetch and install the correct version of the primary payload binary for the detected device architecture.
Currently supported architectures are ARM, MIPS, PowerPC, SH4, and SPARC.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/wget.png
Likely the same operatorsFo[...]
___________________________
@hacking_Attack
@Hacking_Video
Updated RapperBot malware targets game servers in DDoS attacks
Updated RapperBot malware targets game servers in DDoS attacksPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The Mirai-based botnet ‘RapperBot’ has re-emerged via a new campaign that infects IoT devices for DDoS (Distributed Denial of Service) attacks against game servers.The malware was discovered by Fortinet researchers last August when it used SSH brute-forcing to spread on Linux servers.
By tracing its activities, the researchers found that RapperBot has been operational since May 2021, but its exact goals were hard to decipher.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/campaigns.png
Lifting the lid on RapperBotFortinet analysts could sample the new variant using C2 communication artifacts collected in the previous campaigns, indicating that this aspect of the botnet’s operation has not changed.
The analysts noticed the new variant featured several differences, including support for Telnet brute-forcing, using the following commands:
* Register (used by the client)
* Keep-Alive/Do nothing
* Stop all DoS attacks and terminate the client
* Perform a DoS attack
* Stop all DoS attacks
* Restart Telnet brute forcing
* Stop Telnet brute forcing
The malware tries to brute force devices using common weak credentials from a hardcoded list, whereas previously, it fetched a list from the C2.
“To optimize brute forcing efforts, the malware compares the server prompt upon connection to a hardcoded list of strings to identify the possible device and then only tries the known credentials for that device,” explains Fortinet.
“Unlike less sophisticated IoT malware, this allows the malware to avoid trying to test a full list of credentials.”
After successfully finding credentials, it reports it to the C2 via port 5123 and then attempts to fetch and install the correct version of the primary payload binary for the detected device architecture.
Currently supported architectures are ARM, MIPS, PowerPC, SH4, and SPARC.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/wget.png
Likely the same operatorsFo[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Updated RapperBot malware targets game servers in DDoS attacks | Black Hat Ethical Hacking
The Mirai-based botnet 'RapperBot' has re-emerged via a new campaign that infects IoT devices for DDoS (Distributed Denial of Service) attacks against game servers.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Updated RapperBot malware targets game servers in DDoS attacks Updated RapperBot malware targets game servers in DDoS attacksPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png…
rtinet believes all detected RapperBot campaigns are orchestrated by the same operators, as newer variants indicate access to the malware’s source code.
Moreover, the C2 communication protocol remains unchanged, the list of credentials used for brute forcing attempts has been the same since August 2021, and there have been no signs of campaign overlaps at this time.
To protect your IoT devices from botnet infections, keep the firmware up to date, change default credentials with a strong and unique password, and place them behind a firewall if possible.
Trending: Azov Ransomware is a wiper, destroying data 666 bytes at a time Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: www.bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-1-300x150.png Mastodon users vulnerable to password-stealing attacksNovember 16, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-300x150.png Windows Kerberos authentication breaks after November updatesNovember 15, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-300x150.png Russian hacktivists use new Somnia ransomwareNovember 14, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-3-300x150.png Google Pixel screen-lock hack with $70k bug bounty payoutNovember 11, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Updated RapperBot malware targets game servers in DDoS attacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Moreover, the C2 communication protocol remains unchanged, the list of credentials used for brute forcing attempts has been the same since August 2021, and there have been no signs of campaign overlaps at this time.
To protect your IoT devices from botnet infections, keep the firmware up to date, change default credentials with a strong and unique password, and place them behind a firewall if possible.
Trending: Azov Ransomware is a wiper, destroying data 666 bytes at a time Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: www.bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-1-300x150.png Mastodon users vulnerable to password-stealing attacksNovember 16, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-300x150.png Windows Kerberos authentication breaks after November updatesNovember 15, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-300x150.png Russian hacktivists use new Somnia ransomwareNovember 14, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-3-300x150.png Google Pixel screen-lock hack with $70k bug bounty payoutNovember 11, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Updated RapperBot malware targets game servers in DDoS attacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Pentesting CTFs
https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/
All (Jeopardy) CTFs I have participated (Goole, Plaid, etc., etc...) in only had challenges that were based on implementation vulnerabilities. I.e. You get some code (or sometimes not) and you only have to read some flag on the server by exploiting the software without having to nmap etc. the machine and without any priv. escalation. Are there CTFs that provide challenges with all stages of a pentest i.e. Scanning a machine, Finding the vulnerable software and correct operating system, RCE, FIRST FLAG, priv. esc., SECOND FLAG... I failed to find anything but articles that explained the difference between "Real" Pentesting and CTFs... Edit: If possible I would like to avoid Attack-Defense CTFs as they seem really stressful to me. submitted by /u/Hellstorme (https://www.reddit.com/user/Hellstorme)
[link] (https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/) [comments] (https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/
All (Jeopardy) CTFs I have participated (Goole, Plaid, etc., etc...) in only had challenges that were based on implementation vulnerabilities. I.e. You get some code (or sometimes not) and you only have to read some flag on the server by exploiting the software without having to nmap etc. the machine and without any priv. escalation. Are there CTFs that provide challenges with all stages of a pentest i.e. Scanning a machine, Finding the vulnerable software and correct operating system, RCE, FIRST FLAG, priv. esc., SECOND FLAG... I failed to find anything but articles that explained the difference between "Real" Pentesting and CTFs... Edit: If possible I would like to avoid Attack-Defense CTFs as they seem really stressful to me. submitted by /u/Hellstorme (https://www.reddit.com/user/Hellstorme)
[link] (https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/) [comments] (https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pentesting CTFs
All (Jeopardy) CTFs I have participated (Goole, Plaid, etc., etc...) in only had challenges that were based on implementation vulnerabilities....
hacking: security in practice
Where to begin
Hello world, how are well hopefully doing well but I came here today to ask you lovely people on this subreddit where to begin my hacking career, I have a limited experience with Linux and networking and some programming here and there.
submitted by /u/Spread-Particular
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Where to begin
Hello world, how are well hopefully doing well but I came here today to ask you lovely people on this subreddit where to begin my hacking career, I have a limited experience with Linux and networking and some programming here and there.
submitted by /u/Spread-Particular
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Where to begin
Hello world, how are well hopefully doing well but I came here today to ask you lovely people on this subreddit where to begin my hacking career,...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Get Into Bug Bounties?( Beginner’s guide)
https://cdn-images-1.medium.com/max/1200/1*8qJ8TrZTtaZufZRP-G_cFQ.jpeg
Hello Future Bug Bounty Hunters!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Get Into Bug Bounties?( Beginner’s guide)
https://cdn-images-1.medium.com/max/1200/1*8qJ8TrZTtaZufZRP-G_cFQ.jpeg
Hello Future Bug Bounty Hunters!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Get Into Bug Bounties?( Beginner’s guide)
Hello Future Bug Bounty Hunters!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ingeniería inversa de un “crackme” (parte 3)
https://cdn-images-1.medium.com/max/2600/0*lwzHeDBlrFr6MmfB
Reversing 101. “Hooking is the new Hacking”
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ingeniería inversa de un “crackme” (parte 3)
https://cdn-images-1.medium.com/max/2600/0*lwzHeDBlrFr6MmfB
Reversing 101. “Hooking is the new Hacking”
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ingeniería inversa de un “crackme” (parte 3)
Reversing 101. “Hooking is the new Hacking”
nuvola - Tool To Dump And Perform Automatic And Manual Security Analysis On Aws Environments Configurations And Services
http://www.kitploit.com/2022/11/nuvola-tool-to-dump-and-perform.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/11/nuvola-tool-to-dump-and-perform.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
nuvola - Tool To Dump And Perform Automatic And Manual Security Analysis On Aws Environments Configurations And Services
nuvola (with the lowercase n) is a tool to dump and perform automatic and manual security analysis on AWS environments configurations and services using predefined, extensible and custom rules created using a simple Yaml syntax. The general idea behind this project is to create an abstracted digital twin of a cloud platform. For a more concrete example: nuvola reflects the BloodHound (https://www.kitploit.com/search/label/BloodHound) traits used for Active Directory (https://www.kitploit.com/search/label/Active%20Directory) analysis but on cloud environments (at the moment only AWS). The usage of a graph database also increases the possibility of finding different and innovative attack paths and can be used as an offline, centralised and lightweight digital twin.
Quick Start Requirements docker-compose installed an AWS account configured to be used with awscli with full access to the cloud resources, better if in ReadOnly mode (the policy arn:aws:iam::aws:policy/ReadOnlyAccess is fine) Setup Clone the repository git clone --depth=1 https://github.com/primait/nuvola.git; cd nuvola Create and edit, if required, the .env file to set your DB username/password/URL cp .env_example .env; Start the Neo4j docker instance make start Build the tool make build Usage Firstly you need to dump all the supported AWS services configurations and load the data into the Neo4j database: ./nuvola dump -profile default_RO -outputdir ~/DumpDumpFolder -format zip To import a previously executed dump operation into the Neo4j database: ./nuvola assess -import ~/DumpDumpFolder/nuvola-default_RO_20220901.zip To only perform static assessments on the data loaded into the Neo4j database using the predefined ruleset (https://github.com/primait/nuvola/tree/master/assess/rules): ./nuvola assess Or use Neo4j Browser (https://neo4j.com/docs/operations-manual/current/installation/neo4j-browser/) to manually explore the digital twin.
___________________________
@hacking_Attack
@Hacking_Video
Quick Start Requirements docker-compose installed an AWS account configured to be used with awscli with full access to the cloud resources, better if in ReadOnly mode (the policy arn:aws:iam::aws:policy/ReadOnlyAccess is fine) Setup Clone the repository git clone --depth=1 https://github.com/primait/nuvola.git; cd nuvola Create and edit, if required, the .env file to set your DB username/password/URL cp .env_example .env; Start the Neo4j docker instance make start Build the tool make build Usage Firstly you need to dump all the supported AWS services configurations and load the data into the Neo4j database: ./nuvola dump -profile default_RO -outputdir ~/DumpDumpFolder -format zip To import a previously executed dump operation into the Neo4j database: ./nuvola assess -import ~/DumpDumpFolder/nuvola-default_RO_20220901.zip To only perform static assessments on the data loaded into the Neo4j database using the predefined ruleset (https://github.com/primait/nuvola/tree/master/assess/rules): ./nuvola assess Or use Neo4j Browser (https://neo4j.com/docs/operations-manual/current/installation/neo4j-browser/) to manually explore the digital twin.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
About nuvola To get started with nuvola and its database schema, check out the nuvola Wiki (https://github.com/primait/nuvola/wiki). No data is sent or shared with Prima Assicurazioni. How to contribute reporting bugs and issues reporting new improvements reviewing issues and pull requests fixing bugs and issues creating new rules improving the overall quality Presentations RomHack 2022 Slides (https://github.com/primait/nuvola/tree/master/assets/slides/RomHack_2022-You_shall_not_PassRole.pdf) Demos (https://github.com/primait/nuvola/tree/master/assets/demos/) License nuvola uses graph theory (https://www.kitploit.com/search/label/Graph%20Theory) to reveal possible attack paths and security misconfigurations (https://www.kitploit.com/search/label/Misconfigurations) on cloud environments. This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed (https://www.kitploit.com/search/label/Distributed) in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this repository and program. If not, see http://www.gnu.org/licenses/.
Download Nuvola (https://github.com/primait/nuvola)
___________________________
@hacking_Attack
@Hacking_Video
Download Nuvola (https://github.com/primait/nuvola)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Home · primait/nuvola Wiki
Contribute to primait/nuvola development by creating an account on GitHub.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Recon Tool: SecretScanner
Recon Tool: SecretScannerPost Views: 39 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes SecretScannerDeepfence SecretScanner can find unprotected secrets in container images or file systems.
* SecretScanner is a standalone tool that retrieves and searches container and host filesystems, matching the contents against a database of approximately 140 secret types.
* SecretScanner is also included in ThreatMapper, an open source scanner that identifies vulnerable dependencies and unprotected secrets in cloud native applications, and ranks these vulnerabilities based on their risk-of-exploit (example)
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course What are Secrets?Secrets are any kind of sensitive or private data which gives authorized users permission to access critical IT infrastructure (such as accounts, devices, networks, and cloud-based services), applications, storage, databases, and other kinds of critical data for an organization. For example, passwords, AWS access IDs, AWS secret access keys, Google OAuth Key, etc. are secrets. However, sometimes attackers can easily access secrets due to flawed security policies or inadvertent mistakes by developers. Sometimes
developers use default secrets or leave hard-coded secrets such as passwords, API keys, encryption keys, SSH keys, tokens, etc. in container images, especially during rapid development and deployment cycles in CI/CD pipeline. Also, sometimes users store passwords in plain text. Leakage of secrets to unauthorized entities can put your organization and infrastructure at a serious security risk.
SecretScanner by Deepfence helps users scan their container images or local directories on hosts and outputs a JSON file with details of all the secrets found.
Check out their blog for more details. When to use SecretScannerUse SecretScanner if you need a lightweight, efficient method to scan container images and filesystems for possible secrets (keys, tokens, passwords). You can then review these possible ‘secrets’ to determine if any of them should be removed from production deployments.
Trending: Offensive Security Tool: Mangle
Trending: Offensive Security Tool: WinPwnage Quick StartFor full instructions, refer to the SecretScanner Documentation.
Install docker and run SecretScanner on a container image using the following instructions:
* Build SecretScanner:
./bootstrap.sh
docker build --rm=true --tag=deepfenceio/deepfence_secret_scanner:latest -f Dockerfile .
* Or, pull the latest build from docker hub by doing:
docker pull deepfenceio/deepfence_secret_scanner:latest
* Pull a container image for scanning:
docker pull node:8.11
* Scan the container image:
docker run -it --rm --name=deepfence-secretscanner -v $(pwd):/home/deepfence/output -v /var/run/docker.sock:/var/run/docker.sock deepfenceio/deepfence_secret_scanner:latest -image-name node:8.11 Trending: Exploit XSS Injections in a one-line powerful Technique DisclaimerThis tool is not meant to be used for hacking. Use it only for legitimate purposes like detecting secrets on the infrastructure you own, not on others’ infrastructure. DEEPFENCE shall not be liable for loss of profit, loss of business, other financial loss, or any other loss or damage which may be caused, directly or indirectly, by the inadequacy of SecretScanner for any purpose or use thereof or by any defect or deficiency therein.
Clone the repo from here: GitHub Link
Trending: Article: Using VPS for Bug Bounty, comparing VPS providers https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Tools* https://www.blackhatethi[...]
___________________________
@hacking_Attack
@Hacking_Video
Recon Tool: SecretScanner
Recon Tool: SecretScannerPost Views: 39 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes SecretScannerDeepfence SecretScanner can find unprotected secrets in container images or file systems.
* SecretScanner is a standalone tool that retrieves and searches container and host filesystems, matching the contents against a database of approximately 140 secret types.
* SecretScanner is also included in ThreatMapper, an open source scanner that identifies vulnerable dependencies and unprotected secrets in cloud native applications, and ranks these vulnerabilities based on their risk-of-exploit (example)
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course What are Secrets?Secrets are any kind of sensitive or private data which gives authorized users permission to access critical IT infrastructure (such as accounts, devices, networks, and cloud-based services), applications, storage, databases, and other kinds of critical data for an organization. For example, passwords, AWS access IDs, AWS secret access keys, Google OAuth Key, etc. are secrets. However, sometimes attackers can easily access secrets due to flawed security policies or inadvertent mistakes by developers. Sometimes
developers use default secrets or leave hard-coded secrets such as passwords, API keys, encryption keys, SSH keys, tokens, etc. in container images, especially during rapid development and deployment cycles in CI/CD pipeline. Also, sometimes users store passwords in plain text. Leakage of secrets to unauthorized entities can put your organization and infrastructure at a serious security risk.
SecretScanner by Deepfence helps users scan their container images or local directories on hosts and outputs a JSON file with details of all the secrets found.
Check out their blog for more details. When to use SecretScannerUse SecretScanner if you need a lightweight, efficient method to scan container images and filesystems for possible secrets (keys, tokens, passwords). You can then review these possible ‘secrets’ to determine if any of them should be removed from production deployments.
Trending: Offensive Security Tool: Mangle
Trending: Offensive Security Tool: WinPwnage Quick StartFor full instructions, refer to the SecretScanner Documentation.
Install docker and run SecretScanner on a container image using the following instructions:
* Build SecretScanner:
./bootstrap.sh
docker build --rm=true --tag=deepfenceio/deepfence_secret_scanner:latest -f Dockerfile .
* Or, pull the latest build from docker hub by doing:
docker pull deepfenceio/deepfence_secret_scanner:latest
* Pull a container image for scanning:
docker pull node:8.11
* Scan the container image:
docker run -it --rm --name=deepfence-secretscanner -v $(pwd):/home/deepfence/output -v /var/run/docker.sock:/var/run/docker.sock deepfenceio/deepfence_secret_scanner:latest -image-name node:8.11 Trending: Exploit XSS Injections in a one-line powerful Technique DisclaimerThis tool is not meant to be used for hacking. Use it only for legitimate purposes like detecting secrets on the infrastructure you own, not on others’ infrastructure. DEEPFENCE shall not be liable for loss of profit, loss of business, other financial loss, or any other loss or damage which may be caused, directly or indirectly, by the inadequacy of SecretScanner for any purpose or use thereof or by any defect or deficiency therein.
Clone the repo from here: GitHub Link
Trending: Article: Using VPS for Bug Bounty, comparing VPS providers https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Tools* https://www.blackhatethi[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Recon Tool: SecretScanner | Black Hat Ethical Hacking
SecretScanner helps users scan their container images or local directories on hosts and outputs a JSON file with details of all the secrets found.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Recon Tool: SecretScanner Recon Tool: SecretScannerPost Views: 39 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode. Reading Time: 2 Minutes S…
calhacking.com/wp-content/uploads/2022/11/Mangle-300x150.png Offensive Security Tool: MangleNovember 11, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/WinPwnage-300x150.jpg Offensive Security Tool: WinPwnageNovember 4, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/lazypariah-300x150.png Offensive Security Tool: LAZYPARIAHOctober 28, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Parth-300x150.png Recon Tool: ParthOctober 27, 2022
Reading Time: 2 minutes https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Recon Tool: SecretScanner first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/WinPwnage-300x150.jpg Offensive Security Tool: WinPwnageNovember 4, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/lazypariah-300x150.png Offensive Security Tool: LAZYPARIAHOctober 28, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Parth-300x150.png Recon Tool: ParthOctober 27, 2022
Reading Time: 2 minutes https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Recon Tool: SecretScanner first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
nuvola - Tool To Dump And Perform Automatic And Manual Security Analysis On Aws Environments Configurations And Services
https://blogger.googleusercontent.com/img/a/AVvXsEgzmURPzSN2TgWknr8VkU8lZFi3OmYW__FqXcXK7E9EggsniyF5TvTVmMkKbOIKnap0o2Y1DI6g4cLEOzbHGR0qrBmOjamJvS2h2TdFbUwECaXkQxQzYiAZus36OWa753eMRyLrSlm0mKYO5tC58u_46q3tBSefqEQX4QwN7BrEixhuXt0TQqQOXgUQ3Q=s320 nuvola (with the lowercase n) is a tool to dump and perform automatic and manual security analysis on AWS environments configurations and services using predefined, extensible and custom rules created using a simple Yaml syntax.
The general idea behind this project is to create an abstracted digital twin of a cloud platform. For a more concrete example: nuvola reflects the BloodHound traits used for Active Directory analysis but on cloud environments (at the moment only AWS).
The usage of a graph database also increases the possibility of finding different and innovative attack paths and can be used as an offline, centralised and lightweight digital twin. Quick StartRequirements*
* an AWS account configured to be used with
No data is sent or shared with Prima Assicurazioni. How to contribute* reporting bugs and issues
* reporting new improvements
* reviewing issues and pull requests
* fixing bugs and issues
* creating new rules
* improving the overall quality Presentations* RomHack 2022
* Slides
* Demos Licensenuvola uses graph theory to reveal possible attack paths and security misconfigurations on cloud environments.
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with this repository and program. If not, see http://www.gnu.org/licenses/. Download Nuvola
___________________________
@hacking_Attack
@Hacking_Video
nuvola - Tool To Dump And Perform Automatic And Manual Security Analysis On Aws Environments Configurations And Services
https://blogger.googleusercontent.com/img/a/AVvXsEgzmURPzSN2TgWknr8VkU8lZFi3OmYW__FqXcXK7E9EggsniyF5TvTVmMkKbOIKnap0o2Y1DI6g4cLEOzbHGR0qrBmOjamJvS2h2TdFbUwECaXkQxQzYiAZus36OWa753eMRyLrSlm0mKYO5tC58u_46q3tBSefqEQX4QwN7BrEixhuXt0TQqQOXgUQ3Q=s320 nuvola (with the lowercase n) is a tool to dump and perform automatic and manual security analysis on AWS environments configurations and services using predefined, extensible and custom rules created using a simple Yaml syntax.
The general idea behind this project is to create an abstracted digital twin of a cloud platform. For a more concrete example: nuvola reflects the BloodHound traits used for Active Directory analysis but on cloud environments (at the moment only AWS).
The usage of a graph database also increases the possibility of finding different and innovative attack paths and can be used as an offline, centralised and lightweight digital twin. Quick StartRequirements*
docker-composeinstalled* an AWS account configured to be used with
awscliwith full access to the cloud resources, better if in ReadOnly mode (the policy arn:aws:iam::aws:policy/ReadOnlyAccessis fine) Setup1. Clone the repository git clone --depth=1 https://github.com/primait/nuvola.git; cd nuvola1. Create and edit, if required, the .envfile to set your DB username/password/URL cp .env_example .env;1. Start the Neo4j docker instance make start1. Build the tool make buildUsage1. Firstly you need to dump all the supported AWS services configurations and load the data into the Neo4j database: ./nuvola dump -profile default_RO -outputdir ~/DumpDumpFolder -format zip1. To import a previously executed dump operation into the Neo4j database: ./nuvola assess -import ~/DumpDumpFolder/nuvola-default_RO_20220901.zip1. To only perform static assessments on the data loaded into the Neo4j database using the predefined ruleset: ./nuvola assess1. Or use Neo4j Browser to manually explore the digital twin. https://blogger.googleusercontent.com/img/a/AVvXsEjQbhoTT8iOZvEXyq-5kXJNngssFxDFe-QmxWTq817OKgNJNDzsJu7KH4bcwagoqFcbOzC2BRsx4ME8h1U0Xijgd-f_OAD2sx9nFIL_JzpvzmhGcUNxbIdN-yOLC8qzUzTDMsNVOz6OiVv3LyTyaljP3kYmEOiGiGw9XebHCthRKNnWXhMfB6Jd2FWCGQ=w640-h276 About nuvolaTo get started with nuvola and its database schema, check out the nuvola Wiki.No data is sent or shared with Prima Assicurazioni. How to contribute* reporting bugs and issues
* reporting new improvements
* reviewing issues and pull requests
* fixing bugs and issues
* creating new rules
* improving the overall quality Presentations* RomHack 2022
* Slides
* Demos Licensenuvola uses graph theory to reveal possible attack paths and security misconfigurations on cloud environments.
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with this repository and program. If not, see http://www.gnu.org/licenses/. Download Nuvola
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
nuvola - Tool To Dump And Perform Automatic And Manual Security Analysis On Aws Environments Configurations And Services