Example #2: Using comma separated keywords instead of regex:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Disclaimer: Only tested on Windows 10 (https://www.kitploit.com/search/label/Windows%2010) Pro. Further Options & Usage Tips Notable features: Regex -x search actually returns a unique list of all matched patterns in a file. Be careful when combining it with -v (--verbose), try to be specific and limit the length of chars to match. You can search keywords/regex in binary files as well by providing option -b. You can use this tool as the classic "tree" command if you do not provide keywords -k and regex -x values. This is useful in case you have gained a limited shell on a machine and want to have "tree" with colored output to look around. There's a list variable filetype_blacklist in eviltree.py which can be used to exclude certain file extensions from content search. By default, it excludes the following: gz, zip, tar, rar, 7z, bz2, xz, deb, img, iso, vmdk, dll, ovf, ova. A quite useful feature is the -i (--interesting-only) option. It instructs eviltree to list only files with matching keywords/regex content, significantly reducing the output length:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Useful keywords/regex patterns Regex to look for passwords: -x ".{0,3}passw.{0,3}[=]{1}.{0,18}" Keywords to look for sensitive info: -k passw,db_,admin,account,user,token
Download Eviltree (https://github.com/t3l3machus/eviltree)
___________________________
@hacking_Attack
@Hacking_Video
Download Eviltree (https://github.com/t3l3machus/eviltree)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - t3l3machus/eviltree: A python3 remake of the classic "tree" command with the additional feature of searching for user…
A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those that contain matches. - t3l3m...
hacking: security in practice
Where can I learn how to execute Powershell when a PDF is opened?
I am trying to learn (for my degree thesis) some techniques hackers use. I want to learn how attackers put Powershell bash code in PDFs so it runs when the PDF file opens (on open action launch). I Googled it but I can't find any tutorial or examples on how to do it. Does anyone here know any tutorial by chance?
submitted by /u/Sarciteu
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Where can I learn how to execute Powershell when a PDF is opened?
I am trying to learn (for my degree thesis) some techniques hackers use. I want to learn how attackers put Powershell bash code in PDFs so it runs when the PDF file opens (on open action launch). I Googled it but I can't find any tutorial or examples on how to do it. Does anyone here know any tutorial by chance?
submitted by /u/Sarciteu
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Email hack
A friend uses a MBP for work. She does admin work from home for a small business whose website is hosted by GoDaddy. Last week it was found that the email had been hacked and 3 rules put in place — one of which was to forward emails and replies addressed to her from her boss. Doing this, the hacker tried to have her checks changed to direct deposit. I don’t know if that was opportunistic or the purpose of the hack. GoDaddy said it was a direct hack. Her boss’ email address now shows up in red with the “not a verified email” warning when she uses it. Would that mean his account was the one hacked and not hers? Is it a GoDaddy issue rather than on the MBP itself? Would her home network be at risk now?
submitted by /u/SandiR2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Email hack
A friend uses a MBP for work. She does admin work from home for a small business whose website is hosted by GoDaddy. Last week it was found that the email had been hacked and 3 rules put in place — one of which was to forward emails and replies addressed to her from her boss. Doing this, the hacker tried to have her checks changed to direct deposit. I don’t know if that was opportunistic or the purpose of the hack. GoDaddy said it was a direct hack. Her boss’ email address now shows up in red with the “not a verified email” warning when she uses it. Would that mean his account was the one hacked and not hers? Is it a GoDaddy issue rather than on the MBP itself? Would her home network be at risk now?
submitted by /u/SandiR2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Email hack
A friend uses a MBP for work. She does admin work from home for a small business whose website is hosted by GoDaddy. Last week it was found that...
Dark Reading: Attacks/Breaches
KnowBe4 Launches New Mobile Learner App for Cybersecurity Learning
KnowBe4 empowers end users by introducing security awareness and compliance training on the go at no additional cost.
___________________________
@hacking_Attack
@Hacking_Video
KnowBe4 Launches New Mobile Learner App for Cybersecurity Learning
KnowBe4 empowers end users by introducing security awareness and compliance training on the go at no additional cost.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
KnowBe4 Launches New Mobile Learner App for Cybersecurity Learning
KnowBe4 empowers end users by introducing security awareness and compliance training on the go at no additional cost.
Dark Reading: Attacks/Breaches
NanoLock Brings Built-In Meter-Level Cybersecurity to Renesas Customers
The DLMS-compatible, zero-trust meter-level security is built into the Renesas smart meter solutions, enabling smart meter manufacturers to get to market faster with built-in advanced security solutions.
___________________________
@hacking_Attack
@Hacking_Video
NanoLock Brings Built-In Meter-Level Cybersecurity to Renesas Customers
The DLMS-compatible, zero-trust meter-level security is built into the Renesas smart meter solutions, enabling smart meter manufacturers to get to market faster with built-in advanced security solutions.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
NanoLock Brings Built-In Meter-Level Cybersecurity to Renesas Customers
The DLMS-compatible, zero-trust meter-level security is built into the Renesas smart meter solutions, enabling smart meter manufacturers to get to market faster with built-in advanced security solutions.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
EvilTree - A Remake Of The Classic "Tree" Command With The Additional Feature Of Searching For User Provided Keywords/Regex In Files, Highlighting Those That Contain Matche
https://blogger.googleusercontent.com/img/a/AVvXsEj3vmZM-pdRewX_8qDhW1Sck1XBVQSripBbC9Dn2ImVuKjbSlrM00yY6OKF6KiKayUgDtj3s1zYUdtxDnnNYa9r-kYJADP5BsGIYlSJcUBqTRL25kmeMG41nCyfg61HShNbQdsagkl7C3jycbPhkDJTNvzQ67e6JCSq8fpPmImNdJWn6nNmuqeFy4mhsw=w570-h640 A standalone python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those that contain matches. Created for two main reasons:
* While searching for secrets in files of nested directory structures, being able to visualize which files contain user provided keywords/regex patterns and where those files are located in the hierarchy of folders, provides a significant advantage.
* "tree" is an amazing tool for analyzing directory structures. It's really handy to have a standalone alternative of the command for post-exploitation enumeration as it is not pre-installed on every linux distro and is kind of limited on Windows (compared to the UNIX version). Usage ExamplesExample #1: Running a regex that essentially matches strings similar to:
* Regex
* You can search keywords/regex in binary files as well by providing option
* You can use this tool as the classic "tree" command if you do not provide keywords
* There's a list variable
* A quite useful feature is the
___________________________
@hacking_Attack
@Hacking_Video
EvilTree - A Remake Of The Classic "Tree" Command With The Additional Feature Of Searching For User Provided Keywords/Regex In Files, Highlighting Those That Contain Matche
https://blogger.googleusercontent.com/img/a/AVvXsEj3vmZM-pdRewX_8qDhW1Sck1XBVQSripBbC9Dn2ImVuKjbSlrM00yY6OKF6KiKayUgDtj3s1zYUdtxDnnNYa9r-kYJADP5BsGIYlSJcUBqTRL25kmeMG41nCyfg61HShNbQdsagkl7C3jycbPhkDJTNvzQ67e6JCSq8fpPmImNdJWn6nNmuqeFy4mhsw=w570-h640 A standalone python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those that contain matches. Created for two main reasons:
* While searching for secrets in files of nested directory structures, being able to visualize which files contain user provided keywords/regex patterns and where those files are located in the hierarchy of folders, provides a significant advantage.
* "tree" is an amazing tool for analyzing directory structures. It's really handy to have a standalone alternative of the command for post-exploitation enumeration as it is not pre-installed on every linux distro and is kind of limited on Windows (compared to the UNIX version). Usage ExamplesExample #1: Running a regex that essentially matches strings similar to:
password = somethingagainst /var/wwwhttps://blogger.googleusercontent.com/img/a/AVvXsEjlV0RKRvimp3bbKR5dqybdVaq2Mi66bTb0phTsatOY6XV6JlxD6ACmQLVpRu_APsxgH0D-4Ek2WOhrB8jcBtpJSLdGB-_Mj5N3g7G5d2TN1Nf7qFJYctv5d2mZHXwnCIDxRpgM53Tlg1EswamfvKuwvOnkJOk7u88W_reQzNp46py4az47vWXczCIP-w=w640-h592 Example #2: Using comma separated keywords instead of regex: https://blogger.googleusercontent.com/img/a/AVvXsEj3vmZM-pdRewX_8qDhW1Sck1XBVQSripBbC9Dn2ImVuKjbSlrM00yY6OKF6KiKayUgDtj3s1zYUdtxDnnNYa9r-kYJADP5BsGIYlSJcUBqTRL25kmeMG41nCyfg61HShNbQdsagkl7C3jycbPhkDJTNvzQ67e6JCSq8fpPmImNdJWn6nNmuqeFy4mhsw=w570-h640 Disclaimer: Only tested on Windows 10 Pro. Further Options & Usage TipsNotable features:* Regex
-xsearch actually returns a unique list of all matched patterns in a file. Be careful when combining it with -v(--verbose), try to be specific and limit the length of chars to match.* You can search keywords/regex in binary files as well by providing option
-b.* You can use this tool as the classic "tree" command if you do not provide keywords
-kand regex -xvalues. This is useful in case you have gained a limited shell on a machine and want to have "tree" with colored output to look around.* There's a list variable
filetype_blacklistin eviltree.pywhich can be used to exclude certain file extensions from content search. By default, it excludes the following: gz, zip, tar, rar, 7z, bz2, xz, deb, img, iso, vmdk, dll, ovf, ova.* A quite useful feature is the
-i(--interesting-only) option. It instructs eviltree to list only files with matching keywords/regex content, significantly reducing the output length: https://blogger.googleusercontent.com/img/a/AVvXsEioulvPEN3iWL_MHRFd7-IAu7OrCAmfLVJpx_BGnJQ0AhSwjANokIk0LwbFon-h4o3ADgxwxxhkLB-EDxvhU6KKtFSQf_QcJpSdmbtbXJOMIKw-IAS72xDuFAu3YNUc20TuxJm7deDHDSx8nDyAdBQ2bn9smgbVGH7uWgOz29qjgdR7pO5vPInnyNXoKg=w640-h308 Useful keywords/regex patterns* Regex to look for passwords: -x ".{0,3}passw.{0,3}[=]{1}.{0,18}"* Keywords to look for sensitive info: -k passw,db_,admin,account,user,tokenDownload Eviltree___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
EvilTree - A Remake Of The Classic "Tree" Command With The Additional Feature Of Searching For User Provided Keywords/Regex In…
5 Different Techniques to Perform Account Takeover
1. No Rate-Limit / Brute-ForcingContinue reading on Medium »
Read more...
1. No Rate-Limit / Brute-ForcingContinue reading on Medium »
Read more...
5 Different Techniques to Perform Account Takeover
https://medium.com/@aakashrathee69/5-different-techniques-to-perform-account-takeover-1926901b461a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@aakashrathee69/5-different-techniques-to-perform-account-takeover-1926901b461a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 Different Techniques to Perform Account Takeover
1. No Rate-Limit / Brute-Forcing
1. No Rate-Limit / Brute-ForcingContinue reading on Medium » (https://medium.com/@aakashrathee69/5-different-techniques-to-perform-account-takeover-1926901b461a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 Different Techniques to Perform Account Takeover
1. No Rate-Limit / Brute-Forcing
Kali Linux Tutorials
Octopii : An AI-powered Personal Identifiable Information (PII) Scanner
Octopii is an open-source AI-powered Personal Identifiable Information (PII) scanner that can look for image assets such as Government IDs, passports, photos and signatures in a directory. WorkingOctopii uses Tesseract’s Optical Character Recognition (OCR) and Keras’ Convolutional Neural Networks (CNN) models to detect various forms of personal identifiable information that may be leaked on a publicly facing location. This is done in the following steps: 1. Importing and cleaning image(s)The image is imported via OpenCV and Python Imaging Library (PIL) and is cleaned, deskewed and rotated for scanning. 2. Performing image classification and Optical Character Recognition (OCR)A directory is looped over and searched for images. These images are scanned for unique features via the image classifier (done by comparing it to a trained model), along with OCR for finding substrings within the image. This may have one of the following outcomes:
* Best case (score >=90): The image is sent into the image classifier algorithm to be scanned for features such as an ISO/IEC 7810 card specification, colors, location of text, photos, holograms etc. If it is successfully classified as a type of PII, OCR is performed on it looking for particular words and strings as a final check. When both of these are confirmed, the result from Octopii is extremely reliable.
* Average case (score >=50): The image is partially/incorrectly identified by the image classifier algorithm, but an OCR check finds contradicting substrings and reclassifies it.
* Worst case (score >=0): The image is only identified by the image classifier algorithm but an OCR scan returns no results.
* Incorrect classification: False positives due to a very small model or OCR list may incorrectly classify PIIs, giving inaccurate results.
As a final verification method, images are scanned for certain strings to verify the accuracy of the model.
The accuracy of the scan can determined via the confidence scores in output. If all the mentioned conditions are met, a score of 100.0 is returned.
To train the model, data can also be fed into the
2. Install the Tesseract helper locally via
3. To run Octopii, type python3 octopii.py , for example
Not a valid image format: pii_list/aadhaar/aadhaar-8.gif
[
{
"asset_type": Credit and Debit Cards,
"country_of_origin": "International",
"confidence": 100,
"file_name": "credit-card.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/credit-card.jpg"
},
{
"asset_type": "PAN",
"country_of_origin": "IN",
"confidence": 100,
"file_name": "dummy-PAN-India.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-PAN-India.jpg"
},
{
"asset_type": Aadhaar,
"country_of_origin": "IN",
"confidence": 100,
"file_name": "dummy-aadhaar.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-aadhaar.jpg"
},
{
"asset_type": Driver License,
"country_of_origin": "International",
"confidence": 100,
"file_name": "dummy-drivers-license-nebraska-us.jpg",
"extension": "jpg",
"path": "https[...]
___________________________
@hacking_Attack
@Hacking_Video
Octopii : An AI-powered Personal Identifiable Information (PII) Scanner
Octopii is an open-source AI-powered Personal Identifiable Information (PII) scanner that can look for image assets such as Government IDs, passports, photos and signatures in a directory. WorkingOctopii uses Tesseract’s Optical Character Recognition (OCR) and Keras’ Convolutional Neural Networks (CNN) models to detect various forms of personal identifiable information that may be leaked on a publicly facing location. This is done in the following steps: 1. Importing and cleaning image(s)The image is imported via OpenCV and Python Imaging Library (PIL) and is cleaned, deskewed and rotated for scanning. 2. Performing image classification and Optical Character Recognition (OCR)A directory is looped over and searched for images. These images are scanned for unique features via the image classifier (done by comparing it to a trained model), along with OCR for finding substrings within the image. This may have one of the following outcomes:
* Best case (score >=90): The image is sent into the image classifier algorithm to be scanned for features such as an ISO/IEC 7810 card specification, colors, location of text, photos, holograms etc. If it is successfully classified as a type of PII, OCR is performed on it looking for particular words and strings as a final check. When both of these are confirmed, the result from Octopii is extremely reliable.
* Average case (score >=50): The image is partially/incorrectly identified by the image classifier algorithm, but an OCR check finds contradicting substrings and reclassifies it.
* Worst case (score >=0): The image is only identified by the image classifier algorithm but an OCR scan returns no results.
* Incorrect classification: False positives due to a very small model or OCR list may incorrectly classify PIIs, giving inaccurate results.
As a final verification method, images are scanned for certain strings to verify the accuracy of the model.
The accuracy of the scan can determined via the confidence scores in output. If all the mentioned conditions are met, a score of 100.0 is returned.
To train the model, data can also be fed into the
model_generator.pyscript, and the newly improved h5 file can be used. Usage1. Install all dependencies via pip install -r requirements.txt.2. Install the Tesseract helper locally via
sudo apt install tesseract-ocr -y(for Ubuntu/Debian).3. To run Octopii, type python3 octopii.py , for example
python3 octopii.py pii_list/python3 octopii.py Exampleowais@artemis ~ $ python3 octopii.py pii_listNot a valid image format: pii_list/aadhaar/aadhaar-8.gif
[
{
"asset_type": Credit and Debit Cards,
"country_of_origin": "International",
"confidence": 100,
"file_name": "credit-card.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/credit-card.jpg"
},
{
"asset_type": "PAN",
"country_of_origin": "IN",
"confidence": 100,
"file_name": "dummy-PAN-India.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-PAN-India.jpg"
},
{
"asset_type": Aadhaar,
"country_of_origin": "IN",
"confidence": 100,
"file_name": "dummy-aadhaar.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-aadhaar.jpg"
},
{
"asset_type": Driver License,
"country_of_origin": "International",
"confidence": 100,
"file_name": "dummy-drivers-license-nebraska-us.jpg",
"extension": "jpg",
"path": "https[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Octopii : An AI-powered Personal Identifiable Information (PII) Scanner
Octopii is an open-source AI-powered Personal Identifiable Information (PII) scanner that can look for image assets such as Government IDs
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Octopii : An AI-powered Personal Identifiable Information (PII) Scanner Octopii is an open-source AI-powered Personal Identifiable Information (PII) scanner that can look for image assets such as Government IDs, passports, photos and…
://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-drivers-license-nebraska-us.jpg"
},
{
"asset_type": Passport,
"country_of_origin": "International",
"confidence": 100,
"file_name": "dummy-passport-britain.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-passport-britain.jpg"
},
{
"asset_type": Passport,
"country_of_origin": "International",
"confidence": 100,
"file_name": "dummy-passport-india.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-passport-india.jpg"
},
{
"asset_type": "Signature",
"country_of_origin": null,
"confidence": 7,
"file_name": "dummy-signature.png",
"extension": "png",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-signature.png"
}
] Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video
},
{
"asset_type": Passport,
"country_of_origin": "International",
"confidence": 100,
"file_name": "dummy-passport-britain.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-passport-britain.jpg"
},
{
"asset_type": Passport,
"country_of_origin": "International",
"confidence": 100,
"file_name": "dummy-passport-india.jpg",
"extension": "jpg",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-passport-india.jpg"
},
{
"asset_type": "Signature",
"country_of_origin": null,
"confidence": 7,
"file_name": "dummy-signature.png",
"extension": "png",
"path": "https://pii-carbonconsole.fra1.digitaloceanspaces.com/dummy-signature.png"
}
] Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video