Join in on some super cool infosec discussions from experts all over the world!Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/iwcon2022-networking-rooms-are-now-open-new-speaker-announcement-de2394b4fd0e?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Codecepticon : .NET Application That Allows You To Obfuscate C#, VBA/VB6 (Macros), And PowerShell Source Code
Codecepticon is a .NET application that allows you to obfuscate C#, VBA/VB6 (macros), and PowerShell source code, and is developed for offensive security engagements such as Red/Purple Teams. What separates Codecepticon from other obfuscators is that it targets the source code rather than the compiled executables, and was developed specifically for AV/EDR evasion.
Codecepticon allows you to obfuscate and rewrite code, but also provides features such as rewriting the command line as well. Read This First! Before we begin !
* This documentation is on how to install and use Codecepticon only. Compilation, usage, and support for tools like Rubeus and SharpHound will not be provided. Refer to each project’s repo separately for more information.
* Codecepticon is actively developed/tested in VS2022, but it should work in VS2019 as well. Any tickets/issues created for VS2019 and below, will not be investigated unless the issue is reproducible in VS2022. So please use the latest and greatest VS2022.
* The following packages MUST be v3.9.0, as newer versions have the following issue which is still open: dotnet/roslyn#58463
* Microsoft.CodeAnalysis.CSharp.Workspaces
* Microsoft.CodeAnalysis.Workspaces.MSBuild
Codecepticon checks the version of these packages on runtime and will inform you if the version is different to v3.9.0.
* It cannot be stressed this enough: always test your obfuscated code locally first. PrerequisitesVisual Studio Pro/Community 2022https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhi8QrObT0IBT1rLQoxH69U-U5JFvRNldLoZpNP82ZJAMP7mKXA0Xh1WtYutMLdNPx-zFV9h1HDtsdyuQt92xB1SJMjKvZgodbNzYQK7sVC39VsIx5HhXDtUnK0fbAoY7OxW0UF2hmb1JFkuZ1PGRvJAjQxgUWBhUNanEd2YiEDY6pr1kHuRmXfiEWX/s1228/Codecepticon1.png Roslyn Compilerhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV2Y78wapAV7Wwxl5m6V0qiwdGlgs-hNKjOd3QIdh7Uyu3kNoaGWm6haPzFAEp4W4t1aueajqJpcaSJ8MKTLH9B4oMLA0Hc8YSPFHj7Y1qozspWq4lKMFZddUcGjVG4k5hO86D985SK2u-h3XfR98ji9b4XbTfhKIzCyqziDxyfLZ6A0Jd-LrM6CrO/s1228/Codecepticon2.png Open and CompileOpen Codecepticon, wait until all NuGet packages are downloaded and then build the solution. Using CodecepticonThere are two ways to use Codecepticon, either by putting all arguments in the command line or by passing a single XML configuration file. Due to the high level of supported customisations, It’s not recommended manually going through
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0PAkqyqGsULUR-DoqpFOnlV8YHU3IJcsMPZyzShvKAubgs3609WEEyNCkurhZLQBEd83kCAcMcHetrCr82W5YE2F863p41f0OrztXSU1c_uv7ejDMI3_kU3nyZrgxiFWYbUs2kf_CldiC0dNGMEzrJv3MkKs6PCH7ZKyc4lsuzEhgYSlItHzIr7RA/s795/Codecepticon3.png
The command generator’s output format can be either
For tips you can use, check out this document. C#Obfuscating a C# project is simple, simply select the solution you wish to target. Note that a backup of the solution itself will not be taken, and the current one will be the one that will be obfuscated. Make sure that you can independently compile the target project before trying to run Codecepticon against it. VBA/VB6The VBA obfuscation works against source code itself rather than a Microsoft Office document. This means that you cannot pass a
Codecepticon : .NET Application That Allows You To Obfuscate C#, VBA/VB6 (Macros), And PowerShell Source Code
Codecepticon is a .NET application that allows you to obfuscate C#, VBA/VB6 (macros), and PowerShell source code, and is developed for offensive security engagements such as Red/Purple Teams. What separates Codecepticon from other obfuscators is that it targets the source code rather than the compiled executables, and was developed specifically for AV/EDR evasion.
Codecepticon allows you to obfuscate and rewrite code, but also provides features such as rewriting the command line as well. Read This First! Before we begin !
* This documentation is on how to install and use Codecepticon only. Compilation, usage, and support for tools like Rubeus and SharpHound will not be provided. Refer to each project’s repo separately for more information.
* Codecepticon is actively developed/tested in VS2022, but it should work in VS2019 as well. Any tickets/issues created for VS2019 and below, will not be investigated unless the issue is reproducible in VS2022. So please use the latest and greatest VS2022.
* The following packages MUST be v3.9.0, as newer versions have the following issue which is still open: dotnet/roslyn#58463
* Microsoft.CodeAnalysis.CSharp.Workspaces
* Microsoft.CodeAnalysis.Workspaces.MSBuild
Codecepticon checks the version of these packages on runtime and will inform you if the version is different to v3.9.0.
* It cannot be stressed this enough: always test your obfuscated code locally first. PrerequisitesVisual Studio Pro/Community 2022https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhi8QrObT0IBT1rLQoxH69U-U5JFvRNldLoZpNP82ZJAMP7mKXA0Xh1WtYutMLdNPx-zFV9h1HDtsdyuQt92xB1SJMjKvZgodbNzYQK7sVC39VsIx5HhXDtUnK0fbAoY7OxW0UF2hmb1JFkuZ1PGRvJAjQxgUWBhUNanEd2YiEDY6pr1kHuRmXfiEWX/s1228/Codecepticon1.png Roslyn Compilerhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV2Y78wapAV7Wwxl5m6V0qiwdGlgs-hNKjOd3QIdh7Uyu3kNoaGWm6haPzFAEp4W4t1aueajqJpcaSJ8MKTLH9B4oMLA0Hc8YSPFHj7Y1qozspWq4lKMFZddUcGjVG4k5hO86D985SK2u-h3XfR98ji9b4XbTfhKIzCyqziDxyfLZ6A0Jd-LrM6CrO/s1228/Codecepticon2.png Open and CompileOpen Codecepticon, wait until all NuGet packages are downloaded and then build the solution. Using CodecepticonThere are two ways to use Codecepticon, either by putting all arguments in the command line or by passing a single XML configuration file. Due to the high level of supported customisations, It’s not recommended manually going through
--helpoutput to try and figure out which parameters to use and how. Use CommandLineGenerator.html and generate your command quickly:https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0PAkqyqGsULUR-DoqpFOnlV8YHU3IJcsMPZyzShvKAubgs3609WEEyNCkurhZLQBEd83kCAcMcHetrCr82W5YE2F863p41f0OrztXSU1c_uv7ejDMI3_kU3nyZrgxiFWYbUs2kf_CldiC0dNGMEzrJv3MkKs6PCH7ZKyc4lsuzEhgYSlItHzIr7RA/s795/Codecepticon3.png
The command generator’s output format can be either
Consoleor XML, depending what you prefer. Console commands can be executed as: Codecepticon.exe --action obfuscate --module csharp --verbose ...etc While when using an XML config file, as: Codecepticon.exe --config C:\Your\Path\To\The\File.xml If you want to deep dive into Codecepticon’s functionality, check out this document.For tips you can use, check out this document. C#Obfuscating a C# project is simple, simply select the solution you wish to target. Note that a backup of the solution itself will not be taken, and the current one will be the one that will be obfuscated. Make sure that you can independently compile the target project before trying to run Codecepticon against it. VBA/VB6The VBA obfuscation works against source code itself rather than a Microsoft Office document. This means that you cannot pass a
doc(x)or xls(x)fi[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Codecepticon : .NET Application That Allows You To Obfuscate C#, VBA/VB6 (Macros), And PowerShell Source Code Codecepticon is a .NET application that allows you to obfuscate C#, VBA/VB6 (macros), and PowerShell source code, and is developed…
le to Codecepticon. It will have to be the source code of the module itself (press Alt-F11 and copy the code from there). PowerShellDue to the complexity of PowerShell scripts, along with the freedom it provides in how to write scripts it is challenging to cover all edge cases and ensure that the obfuscated result will be fully functional. Although it’s expected for Codecepticon to work fine against simple scripts/functionality, running it against complex ones such as PowerView will not work – this is a work in progress. Obfuscating Command Line ArgumentsAfter obfuscating an application or a script, it is very likely that the command line arguments have also been renamed. The solution to this is to use the HTML mapping file to find what the new names are. For example, let’s convert the following command line:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDsK0fGua7Rru0UFsVVpSn_l118UNmJiRxTjIZLqMC1npUXHouKxXS3kbjBqAZrHH5OYMmWS1bZToa2p8wa-Hdv87ZjPTa4c30C-YO0SpGoJrQQhdbj-UpOubxUTc5ru3PIPoQSohNW9brrwKsL3iFP7tB1k5hUwRmsJScTrN0BlnC5_-kF_Qo_1Hu/s465/Codecepticon8.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuHsNES-DwRO0V5q3sso7DJl4NPwlVJK_sZOL9iu8XR2XN35XNkB2_TkpV-PXQAZXaZR5xA_saZJMmUR4DZJ05kTFD805zogKycrSO50DJLFFvw9rEy6239t_7by37RJGHKkuCnpudnNhSB1pBk_WHxR8KnIRMLPRp_jvI4feR69FwnZUwZCCnkbg2/s455/Codecepticon6.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjONAoaY5nYhmpfyjxBcsq-Kvff-eDEPijBCG2FfR63K3neM1gJx8EElCOBKwe2EdLP55c4qIftzCQBtX08Qyy8N0CBucAOyAxxrouKfl3TuojXZBSdZ8-1TmxRZv2bsV9ZyqnzVPdDNnM5uX-6wotXY0QfN0uJABT7PcYtNcUen7c9eRjwMCkpjROa/s450/Codecepticon7.png
And by replacing all strings the result is:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-kuckq93wmtKUZtchal7y2D7ngKthpARHCK7E6RJsffyW_t4AgIRbduhAe0VKhRvVk3OxNzLRRrH24noshTI0gSeqwGDCpzOPb0_7GKeVnqmVCtI6ytRYOaDGaERpkxvfLl8WrrSwo9lEhOWZ7cAVIsYfNjYRl5u_9vKW_2nLgKq09MMuvb68Oh45/s366/Codecepticon5.png
Therefore it is critical to always test your result in a local environment first. Click Here To Download
SharpHound.exe --CollectionMethods DCOnly --OutputDirectory C:\temp\ By searching through the HTML mapping file for each argument, we get:https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDsK0fGua7Rru0UFsVVpSn_l118UNmJiRxTjIZLqMC1npUXHouKxXS3kbjBqAZrHH5OYMmWS1bZToa2p8wa-Hdv87ZjPTa4c30C-YO0SpGoJrQQhdbj-UpOubxUTc5ru3PIPoQSohNW9brrwKsL3iFP7tB1k5hUwRmsJScTrN0BlnC5_-kF_Qo_1Hu/s465/Codecepticon8.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuHsNES-DwRO0V5q3sso7DJl4NPwlVJK_sZOL9iu8XR2XN35XNkB2_TkpV-PXQAZXaZR5xA_saZJMmUR4DZJ05kTFD805zogKycrSO50DJLFFvw9rEy6239t_7by37RJGHKkuCnpudnNhSB1pBk_WHxR8KnIRMLPRp_jvI4feR69FwnZUwZCCnkbg2/s455/Codecepticon6.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjONAoaY5nYhmpfyjxBcsq-Kvff-eDEPijBCG2FfR63K3neM1gJx8EElCOBKwe2EdLP55c4qIftzCQBtX08Qyy8N0CBucAOyAxxrouKfl3TuojXZBSdZ8-1TmxRZv2bsV9ZyqnzVPdDNnM5uX-6wotXY0QfN0uJABT7PcYtNcUen7c9eRjwMCkpjROa/s450/Codecepticon7.png
And by replacing all strings the result is:
ObfuscatedSharpHound.exe --AphylesPiansAsp TurthsTance --AnineWondon C:\temp\ However, some values may exist in more than one category:https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-kuckq93wmtKUZtchal7y2D7ngKthpARHCK7E6RJsffyW_t4AgIRbduhAe0VKhRvVk3OxNzLRRrH24noshTI0gSeqwGDCpzOPb0_7GKeVnqmVCtI6ytRYOaDGaERpkxvfLl8WrrSwo9lEhOWZ7cAVIsYfNjYRl5u_9vKW_2nLgKq09MMuvb68Oh45/s366/Codecepticon5.png
Therefore it is critical to always test your result in a local environment first. Click Here To Download
CVE-2022–42710: A journey through XXE to Stored-XSS
Hi everybody, I will share with you in this article in detail how I was able to find CVE-2022–42710 through static analysisContinue reading on Medium »
Read more...
Hi everybody, I will share with you in this article in detail how I was able to find CVE-2022–42710 through static analysisContinue reading on Medium »
Read more...
Simple CORS misconfig leads to disclose the sensitive token worth of $$$
https://0xraminfosec.medium.com/simple-cors-misconfig-leads-to-disclose-the-sensitive-token-worth-of-91433763f4d6?source=rss------bug_bounty-5
https://0xraminfosec.medium.com/simple-cors-misconfig-leads-to-disclose-the-sensitive-token-worth-of-91433763f4d6?source=rss------bug_bounty-5
Hey fellow hacker’s and Bug hunters , Recently i found some weird CORS misconfiguration in one of my targets.Continue reading on Medium » (https://0xraminfosec.medium.com/simple-cors-misconfig-leads-to-disclose-the-sensitive-token-worth-of-91433763f4d6?source=rss------bug_bounty-5)
CVE-2022–42710: A journey through XXE to Stored-XSS
https://omar0x01.medium.com/cve-2022-42710-a-journey-through-xxe-to-stored-xss-851d74dfe917?source=rss------bug_bounty-5
https://omar0x01.medium.com/cve-2022-42710-a-journey-through-xxe-to-stored-xss-851d74dfe917?source=rss------bug_bounty-5
Hi everybody, I will share with you in this article in detail how I was able to find CVE-2022–42710 through static analysisContinue reading on Medium » (https://omar0x01.medium.com/cve-2022-42710-a-journey-through-xxe-to-stored-xss-851d74dfe917?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
GitHub anuncia escaneo secreto gratuito para todos los repositorios públicos
https://cdn-images-1.medium.com/max/1293/0*Roupl0VqtaPJTU0b
GitHub dijo el jueves que está poniendo a disposición su servicio de escaneo secreto para todos los repositorios públicos en la plataforma…
Continue reading on Medium »
GitHub anuncia escaneo secreto gratuito para todos los repositorios públicos
https://cdn-images-1.medium.com/max/1293/0*Roupl0VqtaPJTU0b
GitHub dijo el jueves que está poniendo a disposición su servicio de escaneo secreto para todos los repositorios públicos en la plataforma…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Importance of Self Custody
https://cdn-images-1.medium.com/max/1200/0*-MtZy06hicTnTlmT
A Self custody wallet is a wallet that you hold the keys for, giving you ownership of and control over the funds it holds. Learn more.
Continue reading on Medium »
The Importance of Self Custody
https://cdn-images-1.medium.com/max/1200/0*-MtZy06hicTnTlmT
A Self custody wallet is a wallet that you hold the keys for, giving you ownership of and control over the funds it holds. Learn more.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
IWCON2022 Networking Rooms Are Now Open + New Speaker Announcement
https://cdn-images-1.medium.com/max/1149/1*X2C_TKOy7MIrKdbpXjQgBA.png
Join in on some super cool infosec discussions from experts all over the world!
Continue reading on InfoSec Write-ups »
IWCON2022 Networking Rooms Are Now Open + New Speaker Announcement
https://cdn-images-1.medium.com/max/1149/1*X2C_TKOy7MIrKdbpXjQgBA.png
Join in on some super cool infosec discussions from experts all over the world!
Continue reading on InfoSec Write-ups »