Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Penetration testing, or pentesting, is the process of simulating a cyber attacks
https://medium.com/@shaheemanthony786/penetration-testing-or-pentesting-is-the-process-of-simulating-a-cyber-attacks-8cc1926f1d33?source=rss------bug_bounty-5

On a computer system, network, or web application to test its defenses and identify vulnerabilities. This is often done by ethical hackers…Continue reading on Medium » (https://medium.com/@shaheemanthony786/penetration-testing-or-pentesting-is-the-process-of-simulating-a-cyber-attacks-8cc1926f1d33?source=rss------bug_bounty-5)
Penetration testing, or pentesting, is the process of simulating a cyber attacks

On a computer system, network, or web application to test its defenses and identify vulnerabilities. This is often done by ethical hackers…Continue reading on Medium »
Read more...
apk.sh, make reverse engineering Android apps easier!
https://www.reddit.com/r/Pentesting/comments/zlbjec/apksh_make_reverse_engineering_android_apps_easier/

<!-- SC_OFF -->🕹 apk.sh apk.sh (https://github.com/ax/apk.sh) is a Bash script that makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK. Features apk.sh basically uses apktool (https://ibotpeaches.github.io/Apktool/) to disassemble, decode and rebuild resources and some bash to automate the frida (https://https://frida.re/) gadget injection process. It also supports app bundles/split APKs. 🍄 Patching APKs to load frida-gadget.so on start. 🆕 Support for app bundles/split APKs. 🔧 Disassembling resources to nearly original form with apktool. 🔩 Rebuilding decoded resources back to binary APK/JAR with apktool. 🗝 Code signing the apk with apksigner. 🖥 Multiple arch support (arm, arm64, x86, x86_64). 📵 No rooted Android device needed. Getting started Pulling an APK from a device is simple as running ./apk.sh pull 🔧 Decoding an APK is simple as running ./apk.sh decode 🔩 Rebuilding an APK is simple as running ./apk.sh build apk.sh pull apk.sh pull pull an APK from a device. It supports app bundles/split APKs, which means that split APKs will be joined in a single APK (this is useful for patching). If the package is an app bundle/split APK, apk.sh will combine the APKs into a single APK, fixing all public resource identifiers. apk.sh patch apk.sh patch patch an APK to load frida-gadget.so (https://frida.re/docs/gadget/) on start. frida-gadget.so is a Frida's shared library meant to be loaded by programs to be instrumented (when the Injected mode of operation isn’t suitable). By simply loading the library it will allow you to interact with it using existing Frida-based tools like frida-trace. It also supports a fully autonomous approach where it can run scripts off the filesystem without any outside communication. Patching an APK is simple as running ./apk.sh patch --arch arm. You can calso specify a Frida gadget configuration in a json ./apk.sh patch --arch arm --gadget-conf 🍄 Frida's Gadget configurations In the default interaction, Frida Gadget exposes a frida-server compatible interface, listening on localhost:27042 by default. In order to achieve early instrumentation Frida let Gadget’s constructor function block until you either attach() to the process, or call resume() after going through the usual spawn() -> attach() -> ...apply instrumentation... steps. If you don’t want this blocking behavior and want to let the program boot right up, or you’d prefer it listening on a different interface or port, you can customize this through a json configuration file. The default configuration is: { "interaction": { "type": "listen", "address": "127.0.0.1", "port": 27042, "on_port_conflict": "fail", "on_load": "wait" } } You can pass the gadget configuration file to apk.sh with the --gadget-conf option. A typically suggested configuration might be: { "interaction": { "type": "script", "path": "/data/local/tmp/script.js", "on_change":"reload" } } script.js could be something like: var android_log_write = new NativeFunction( Module.getExportByName(null, '__android_log_write'), 'int', ['int', 'pointer', 'pointer'] ); var tag = Memory.allocUtf8String("[frida-sript][ax]"); var work = function() { setTimeout(function() { android_log_write(3, tag, Memory.allocUtf8String("ping @ " + Date.now())); work(); }, 1000); } work(); // console.log does not seems to work. see: https://github.com/frida/frida/issues/382 console.log("console.log"); console.error("console.error"); console.warn("WARN"); android_log_write(3, tag, Memory.allocUtf8String(">--(O.o)-<)"); adb push script.js /data/local/tmp ./apk.sh patch --arch arm --gadget-conf adb install file.gadget.apk Requirements apktool apksigner unxz zipalign aapt adb 📃Links of Interest https://frida.re/docs/gadget/
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Penetration testing, or pentesting, is the process of simulating a cyber attacks

On a computer system, network, or web application to test its defenses and identify vulnerabilities. This is often done by ethical hackers…

Continue reading on Medium »
Dark Reading: Attacks/Breaches
Microsoft Squashes Zero-Day, Actively Exploited Bugs in Dec. Update

Here's what you need to patch now, including six critical updates for Microsoft's final Patch Tuesday of the year.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Zenmap GUI not appearing on current MacOS

Running the latest version of MacOS and using the most recent Nmap version every time I click on the application nothing happens at all, I’ve redownloaded several times and no fix, I can run scans on the CLI, but I want to import a previous scan and want to use the GUI that Zenmap provides

submitted by /u/MoneyLazlo
[link] [comments]