Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Generating violent misogyny with GPT-3 or How To Model the Mind of an INCEL

DISCLAIMER: Miranda “agquarx” McKennitt doesn’t approve the message of the machine-generated song. We’re not an INCEL — nor a horny and…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Our Goal Of Realistic CTFs

https://cdn-images-1.medium.com/max/600/1*2vMMGi_vW65rYrDPUwC1Ig.png
Train your hacker persistence. The Parrot CTFs experience is a challenge, persist and finally find a solution that models real-life…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft patches Windows zero-day used to drop ransomware

Microsoft patches Windows zero-day used to drop ransomwarePost Views: 37 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Microsoft has fixed a security vulnerability used by threat actors to circumvent the Windows SmartScreen security feature and deliver Magniber ransomware and Qbot malware payloads.The attackers used malicious standalone JavaScript files to exploit the CVE-2022-44698 zero-day to bypass Mark-of-the-Web security warnings displayed by Windows to alert users that files originating from the Internet should be treated with caution.

“An attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging,” Redmond explained on Tuesday.

According to Microsoft, this security flaw can only be exploited using three attack vectors:

* In a web-based attack scenario, an attacker could host a malicious website that exploits the security feature bypass.
* In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted .url file to exploit the bypass.
* Compromised websites or websites that accept or host user-provided content could contain specially crafted content to exploit the security feature bypass.

However, in all these scenarios, the threat actors would have to trick their targets into opening malicious files or accessing attacker-controlled websites with CVE-2022-44698 exploits.

Microsoft released security updates to address this zero-day during the December 2022 Patch Tuesday after working on a fix for this actively exploited zero-day vulnerability since late October, as the company told BleepingComputer.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course ​Exploited in malware attacksHP’s threat intelligence team first reported in October that phishing attacks were distributing the Magniber ransomware using standalone.JS JavaScript files digitally signed with a malformed as discovered by Will Dormann, a senior vulnerability analyst at ANALYGENCE.

This would cause SmartCheck to error out and allow the malicious files to execute without throwing any security warnings and install the Magniber ransomware, even though it got tagged with a MoTW flag.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/magniber-chain(1).png
<figcaptionMagniber’s JS infection chain (BleepingComputer)
Last month, the same Windows zero-day vulnerability was also abused in phishing attacks to drop the Qbot malware without displaying MOTW security warnings.

As security researcher ProxyLife found, threat actors behind this recent QBot phishing campaign switched to the Windows Mark of the Web zero-day by distributing JS files signed with the same malformed key used in the Magniber ransomware attacks.

QBot (aka Qakbot) is a Windows banking trojan that has evolved into a malware dropper that will steal emails for use in subsequent phishing attacks or deliver additional payloads such as Brute Ratel, Cobalt Strike, and other malware.
Trending: Exploit XSS Injections in a one-line powerful Technique Trending: Offensive Security Tool: Pycrypt The Egregor, Prolock, and Black Basta ransomware operations are also known to have partnered with QBot to gain access to victims’ corporate networks.

During the December 2022 Patch Tuesday, Microsoft also fixed a publicly disclosed zero-day (CVE-2022-44710) that would allow attackers to gain SYSTEM privileges on unpatc[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft patches Windows zero-day used to drop ransomware Microsoft patches Windows zero-day used to drop ransomwarePost Views: 37 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe…
hed Windows 11 systems.
Trending: Kali Linux 2022.4 – New Release adds 6 new tools, Kali NetHunter Update, Azure Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-1-300x150.png Apple security update fixes new iOS zero-day used to hack iPhonesDecember 14, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-300x150.png New Python malware backdoors VMware ESXi servers for remote accessDecember 13, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/1-300x150.png JSON syntax hack allowed SQL injection payloads to be smuggled past WAFsDecember 12, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-21-300x150.png Cisco discloses high-severity IP phone bug with exploit codeDecember 9, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft patches Windows zero-day used to drop ransomware first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Most efficient method of proxying Android apps?

Is there a moderately easy way of proxying Android apps to observe https traffic?

Seems like android app API is super insecure compared to web apps.

submitted by /u/thehunter699
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to decrypt a video?

So I have a video file which is actually in bin format as it is read by my windows file system, but the actual name is 1-11-2.mp_cs_MH6yrX_sz_tesfasyesf_1660830086.

This file is only opened by an app provided to me and not by any other means.

The videos are some tutorials, i wanted to watch even when the subscription is expired.

The Coaching institute have given me the following - 1. An apk( for viewing it in mobile) and a exe file( for viewing it in a PC). 2. A key, which was generated only for me and I inserted it in the first time when i installed and opened the app. 3. List of videos like one above.

For viewing each video I have to open it via the app only.

So, I wanted to some how decrypt this video so that I can view it later also.

So far I have tried to change the extension of the video, but it doesn't work. I have also used a bin to video converter but that was also futile.

I am planning to decompile the apk and some how use it to open the file.

Are there any suggestions, if someone can help me with this.

Thanks

submitted by /u/noswear94
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Metasploit Framework – A Beginner’s Guide for Penetration Testing & Exploit Development

Metasploit Framework is a collection of exploits, shellcodes, fuzzing tools, payloads, encoders etc. Moreover, we can regard it as a collection of exploitation tools bundled into a single framework.

It is available in all major Linux, Windows, OS X platforms. Its main objective is to test your/company’s/organization’s defenses by attacking them. Something like “Offense for Defense”.

This is actually where a penetration tester/Security Analyst begins attacking the victim after a huge recon. Metasploit has a wide range of tools & utilities to perform attacks against all operating systems including Android & iOS. Metasploit Framework HistoryMetasploit was first written in Perl by H.D.Moore. Initially, it was intended to be a maintainable framework that automates the process of exploiting rather than manually verifying it. The first version was released in 2003 and consisted of 8-11(exact number not sure) no exploits.

Then more contributors collaborated & contributed to it a major release was 2.7 in 2006 which consisted of 150+ exploits. Then a major change was in version 3. It was reprogrammed in Ruby & was made cross-platform.

Also, the coolest thing is that new exploits & modules can be downloaded and added with ease by the release of this Metasploit Framework version. In 2009 Rapid7 acquired the project and still owns & maintains it. Still, now the basic architecture of Metasploit is not changed & basic versions are free. Metasploit Framework Modules & InterfacesMetasploit Framework comes in a variety of interfaces

* msfconsole – An interactive curses like a shell to do all tasks.
* msfcli – Calls msf functions from the terminal/cmd itself. Doesn’t change the terminal.
* msfgui –  the Metasploit Framework Graphical User Interface.
* Armitag – Another graphical tool written in Java to manage pentest performed with MSF.
* Metasploit Community(or above) Web Interface – The web-based interface provided by rapid7 for easy pentesting.
* CobaltStrike – Yet another GUI with some added features for post-exploitation, reporting etc. Metasploit Framework ModulesExploitAn exploit is a method by which the attacker takes advantage of a flaw within a system, service, application etc. The attacker generally uses this to do something with the particular system/service/application which he/she is attacking which the developer/implementer never intended to do. Kind of like misusing. This is the thing that an attacker uses to gain access to a system.

Exploits are always accompanied by payloads

Source: “Metasploit- A pentester’s Guide” PayloadA payload is the piece of code which is run in the successfully exploited system. After an exploit works successfully, the framework injects the payload through the exploited vulnerability(flaw) and makes it run it within the target system. Thus an attacker gets inside the system or can get data from the compromised system using the payload. AuxiliaryProvides additional functionality like fuzzing, scanning, recon, dos attack etc. Auxiliary scans for banners or OSes fuzzes or does a DOS attack on the target. It doesn’t inject a payload like exploits. Means you won’t be able to gain access to a system using an auxiliary

Source: “Mastering Metasploit” from PacktPub EncodersEncoders are used to obfuscate modules to avoid detection by a protection mechanism such as an antivirus or a firewall. This is widely used when we create a backdoor. The backdoor is encoded (even multiple times) and sent to the victim.

Source: “Mastering Metasploit” from PacktPub ShellcodeShellcode is a set of instructions used as a payload when exploitation occurs. Shellcode is typically written in assembly language. In most cases, a command shell or a Meterpreter shell will be provided after the series of instructions h[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
AzureGraph : Azure AD Enumeration Over MS Graph

AzureGraph is an Azure AD information gathering tool over Microsoft Graph.

Thanks to Microsoft Graph technology, it is possible to obtain all kinds of information from Azure AD, such as users, devices, applications, domains and much more.

This application, allows you to query this data through the API in an easy and simple way through a PowerShell console. Additionally, you can download all the information from the cloud and use it completely offline.

Requirements

* PowerShell 4.0 or higher

Download

It’s recommended to clone the complete repository or download the zip file.
You can do this by running the following command:

git clone https://github.com/JoelGMSec/AzureGraph

Usage

.\AzureGraph.ps1 -h

Info: This tool helps you to obtain information from Azure AD
like Users or Devices, using de Microsft Graph REST API

Usage: .\AzureGraph.ps1 -h
Show this help, more info on my blog: darkbyte.net

.\AzureGraph.ps1
Execute AzureGraph in fully interactive mode

Warning: You need previously generated MS Graph token to use it
You can use a refresh token too, or generate a new one

The detailed guide of use can be found at the following link:

https://darkbyte.net/azuregraph-enumerando-azure-ad-desde-microsoft-graph
Click Here To Download
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Metasploit Framework – A Beginner’s Guide for Penetration Testing & Exploit Development Metasploit Framework is a collection of exploits, shellcodes, fuzzing tools, payloads, encoders etc. Moreover, we can regard it as a collection of…
ave been performed by the target machine, hence the name. ListenerA listener listens for connections from a payload injected into a compromised system. PostAs the name suggests, these modules are used for post-exploitation. After a system is been compromised, we can dig deeper into the system or set it as a pivot to attack other systems using these modules NopsNop is No Operation popularly known for x86 processors. This is related to shellcode & machine language instructions. Briefly, it prevents a program(here the payload) from crashing while using jump statements in its shellcode.

Nops kind of loops the machine language instructions from the beginning if it lands into an invalid memory location after issuing a jump statement. Thus prevents the payload from crashing. This is somewhat of an advanced concept and you must understand shell coding in order to understand & use nops.

Okay, that’s enough of the blah blah…Let’s have some fun. For now let’s proceed with a tutorial. I will keep you posted on the basics & commands of msfconsole in upcoming posts.

Here is a brief block diagram about the architecture of Metasploit Framework http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf11.png <figcaptionMetasploit Architecture Lab 1: Gather publicly available email-ids from search engines.In this Metasploit Framework lab, we are gonna try to gather email ids from a specific domain. Here we use an auxiliary module through the msfconsole. Step 1: Prerequisites: Start & enable PostgreSQL service, check your IP, start Metasploit service & msfconsoleCommand:service postgresql start Command:update-rc.d postresql enable Command: ip a | grep inet Command: service metasploit start Command: msfconsole http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf2.png <figcaptionStarting Services & initial setup http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf1-1024x768.png <figcaptionThe MSF-console Step 2: Take the Initial steps of Metasploit Framework.Check & Connect db to msfconsole.
Command:db_status
The above command checks whether there is a database connection. I will explain this in detail in upcoming posts.

If the Metasploit service is started correctly, there will be a connection. Else, open a new terminal, start the service(command given above) and follow these:
db_connect msf3:msf3@localhost/msf3
Then check DB status again. If it didn’t succeed don’t worry, msf will work fine but without a database connection and some extended features. For the solution, check  Step 2 in the following link Step 3: Let’s proceed. There is an auxiliary module which gathers all emailIDs found publically through a company’s website, social profiles etc. The module works by searching them in search engines like google, bing & yahoo.In the msf prompt type:
search email http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf4.png <figcaptionThe Msf-console & Database status http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf5.png <figcaptionModules listed after the search

This will show a list of modules. Here we are gonna use an auxiliary module: auxiliary/gather/search_email_collector

Type in:
info auxiliary/gather/search_email_collector
This displays some information on the module. http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf6.png <figcaptionInformation of the module Step 4: Let’s Proceed to use the moduleuse auxiliary/gather/search_email_collector
Then there are certain options for this module, we can view this by using the following command
show options
We are gonna search for publicly available Gmail ids. so we set domain as Gmail, and save the output to gmails.txt.
set DOMAIN gmail.com set OUTFILE /root/gmails.txt <make http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf7.png <figcaptionSetting Options in the module

All set, we can run the auxiliary now but it’s always better to view all options set before running.
show opti[...]
Hacking Articles Tips Tricks Videos Tutorials
ave been performed by the target machine, hence the name. ListenerA listener listens for connections from a payload injected into a compromised system. PostAs the name suggests, these modules are used for post-exploitation. After a system is been compromised…
ons
The moment of truth
run http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf8.png <figcaptionThe module running & displaying results http://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf9.png <figcaptionThe module showing final results

After successful completion, the result will be in the file we specified. Verify it by going to the home folder or just opening a new terminal and type:
Command: cat gmails.txt | less <replacehttp://kalilinuxtutorials.com/wp-content/uploads/2015/06/msf10.png Reading the outfile

Press q to exit.

This is a very-very basic demo of the Metasploit Framework & made exclusively for beginners. Also, this module is useful for collecting email IDs of a company during penetration tests. You can set the domain option to your target domain and run. Msfconsole provides a handy all-in-one interface to almost every option and setting available in the Framework; it’s like a one-stop shop for all of your exploitation dreams. You can use msfconsole to do everything, including launching an exploit, loading auxiliary modules, performing enumeration, creating listeners, or running mass exploitation against an entire network.

Msfconsole is really an interactive shell with which you can work with the metasploit framework dynamically & easily. As said above we can exploit all the functionalities of the metasploit framework with this interactive shell.

The most amazing feature is that, even if the core framework changes(gets updated or changes in modules)the msfconsole adjusts dynamically with a whole lot of features like help system, a search command, ability to create & manage users, databases, workspaces, hosts, vulnerabilities etc.

We can see the information & documentation for a module, see matching payloads and of course run the exploit in an interactive & easy way.

Some more terms & Concepts related to Metasploit & the MSFConsole

* Database: A dedicated database for the management of information like hosts, ip adderesses, ranges, vulnerabilities etc. Typically & usefully we can create a new database for each of our pentesting projects. Default is the postgresql.
* DB-User : Guess what…? The user who is using the database. This becomes very handy while integrating with the web interface.
* Workspace: Kind of like an exclusive space for each projects. Really helpful for managing the data of your projects. Creating a new project in Web-UI creates new workspace in console.

For all these labs, we need some machines. You can use VMs or Physical Machines. For most of the labs, I am using metasploitable. It has got a number of vulnerable services, exclusively made for learning Pentesting. I suggest you download it, & work with it. Setup the network so that, your Kali Linux Box & the Metasploitable Box are in same network. Metasploit Framework OptionsCore Commands Command       Description
    -------       -----------
    ?             Help menu
    back          Move back from the current context
    banner        Display an awesome metasploit banner
    cd            Change the current working directory
    color         Toggle color
    connect       Communicate with a host
    edit          Edit the current module with $VISUAL or $EDITOR
    exit          Exit the console
    get           Gets the value of a context-specific variable
    getg          Gets the value of a global variable
    go_pro        Launch Metasploit web GUI
    grep          Grep the output of another command
    help          Help menu
    info          Displays information about one or more module
    irb           Drop into irb scripting mode
    jobs          Displays and manages jobs
    kill          Kill a job
    load          Load a framework plugin
    loadpath      Searches for and loads modules from a path
    makerc        Save commands entered since start to a file
    popm          Pops the latest module off the stack and makes it active
    previous      Sets the previously loaded module as the current module[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Whatweb – A Scanning Tool to Find Security Vulnerabilities in Web App

Whatweb is the perfect name for this tool. Simply it answers the question, “What is that Website?” Whatweb can identify all sorts of information about a live website, like:

* Platform
* CMS platform
* Type of Script
* Google Analytics
* Web server Platform
* IP address, Country
* 900+ Plugins & their libraries used
* Server Headers, Cookies and a lot more.

Whatweb offers both passive scanning and aggressive testing. Passive scanning just extracts data from HTTP headers simulating a normal visit. Aggressive options get deeper with recursion & various types of queries & identify all technologies just like a vulnerability scanner.

So a pentester can use this tool as both a recon tool & vulnerability scanner. There are various other features like proxy support, scan tuning, scanning a range of IPs, spidering etc. Whatweb OptionsSyntax: whatweb [options] <urls
Options is deprecated. Only major options or listed. Visit whatweb tool homepage for complete options
TARGET SELECTION: <urlsEnter URLs, filenames or nmap-format IP ranges.
--input-file=FILE, -i Identify URLs found in FILE, eg. -i /dev/stdin TARGET MODIFICATION:
--url-prefix          Add a prefix to target URLs
--url-suffix          Add a suffix to target URLs
--url-pattern         Insert the targets into a URL. Requires --input-file, AGGRESSION:
The aggression level controls the trade-off between speed/stealth and reliability.
--aggression, -a=LEVEL Set the aggression level. Default: 1
Aggression levels are: 1,2,3 & 4 HTTP OPTIONS:
--user-agent, -U=AGENT Identify as AGENT instead of WhatWeb/0.4.8-dev.
--follow-redirect=WHEN Control when to follow redirects.Default: always
--max-redirects=NUM   Maximum number of contiguous redirects. Default: 10 AUTHENTICATION:
--user, -u=<user:password HTTP basic authentication
Add session cookies with --header, e.g. --header "Cookie: SESSID=1a2b3c;" PROXY:
--proxy <hostname[:port]Set proxy hostname and port Default: 8080
--proxy-user <username:passwordSet proxy user and password PLUGINS:
--list-plugins, -l    List all plugins OUTPUT:
--verbose, -v         Verbose output includes plugin descriptions. Use twice for debugging.
--colour,--color=WHEN control whether colour is used. WHEN='always', 'never' or 'auto'
--quiet, -q           Do not display brief logging to STDOUT
--no-errors           Suppress error messages LOGGING:
--log-brief=FILE      Log brief, one-line output
--log-verbose=FILE    Log verbose output
--log-xml=FILE        Log XML format PERFORMANCE & STABILITY:
--max-threads, -t     Number of simultaneous threads. Default: 25.
--open-timeout        Time in seconds. Default: 15
--read-timeout        Time in seconds. Default: 30
--wait=SECONDS        Wait SECONDS between connections HELP & MISCELLANEOUS:
--help, -h            This help
--debug               Raise errors in plugins
--version             Display version information. (WhatWeb 0.4.8-dev) Whatweb Lab 1: Perform Simple enumeration of websites over the internet.In this lab, we will perform simple enumeration of websites. The result of this is we can get to know the technologies used in the website & webserver.

Note: Please don’t use this against government or military websites without prior permission. The author of this article or tool itself are not responsible for any consequences if misused. Scenario:Attacker: Kali Linux VM

Target: www.facebook.com
Command: whatweb www.facebook.com http://kalilinuxtutorials.com/wp-content/uploads/2015/07/whatweb1.png <figcaptionBasic Details

To give a more verbose Output
Command: whatweb -v www.facebook.com http://kalilinuxtutorials.com/wp-content/uploads/2015/07/whatweb2.png <figcaptionDisplaying Details about modules http://kalilinuxtutorials.com/wp-content/uploads/2015/07/whatweb3.png <figcaptionDisplaying Details about modules
Practically, how we can u[...]