Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Assalamualaikum, Bug Hunter!
Bagaimana Kabarnya ? Semoga Baik-baik saja ya, kali ini saya mau membuat Write Up yang menurut saya Bug ini…Continue reading on Medium » (https://medium.com/@ibnu1337/privilege-escalation-lead-to-data-breach-1e4975c3edaa?source=rss------bug_bounty-5)
There’s always a way to exploit xss in different contextsContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/dont-give-up-on-xss-fun-firefox-xss-3fce0ee297a?source=rss------bug_bounty-5)
Hey guys, in this tutorial, I will be sharing my learning about account takeover which I have learned after reading some blogs only on…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/account-takeover-guide-eaff94d4ffe8?source=rss------bug_bounty-5)
Stored XSS — PARK TICKETING MANAGEMENT SYSTEM(Phpgurukul)

# Exploit Title: PARK TICKETING MANAGEMENT SYSTEM — Stored XSS Vulnreability. # Date: 25–01–2023 # Exploit Author: Venkata Siva Kumar…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Monomorph - MD5-Monomorphic Shellcode Packer - All Payloads Have The Same MD5 Hash

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnwjNE0lyLEzAnqddmf6LIbUH381tCsODiPQ2DC3OLrtlLh5M80qBZicWGIYcGUBoFBgEOyDCF4yhHzGZ7hJiPkqHfpzQoGHb9rU5mylhb7Dk55E-G8WnXSm69ebU5OniUXwwRo4PeLMNcm7oTc7yISuZbbPVx7B9XndFedxqJ_MYmaBzxaJAARvnPZg/w640-h354/monomorph.png


════════════════════════════════════╦═══
╔═╦═╗ ╔═╗ ╔═╗ ╔═╗ ╔═╦═╗ ╔═╗ ╔══╔═╗ ╠═╗
═╩ ╩ ╩═╚═╝═╩ ╩═╚═╝═╩ ╩ ╩═╚═╝═╩ ╠═╝═╩ ╩═
════════════════════════════════╩═══════
By Retr0id

═══ MD5-Monomorphic Shellcode Packer ═ ══
USAGE: python3 monomorph.py input_file output_file [payload_file]


What does it do?

It packs up to 4KB of compressed shellcode into an executable binary, near-instantly. The output file will always have the same MD5 hash: 3cebbe60d91ce760409bbe513593e401

Currently, only Linux x86-64 is supported. It would be trivial to port this technique to other platforms, although each version would end up with a different MD5. It would also be possible to use a multi-platform polyglot file like APE.

Example usage:

$ python3 monomorph.py bin/monomorph.linux.x86-64.benign bin/monomorph.linux.x86-64.meterpreter sample_payloads/bin/linux.x64.meterpreter.bind_tcp.bin


Why?

People have previously used single collisions to toggle a binary between "good" and "evil" modes. Monomorph takes this concept to the next level.

Some people still insist on using MD5 to reference file samples, for various reasons that don't make sense to me. If any of these people end up investigating code packed using Monomorph, they're going to get very confused.

How does it work?

For every bit we want to encode, a colliding MD5 block has been pre-calculated using FastColl. As summarised here, each collision gives us a pair of blocks that we can swap out without changing the overall MD5 hash. The loader checks which block was chosen at runtime, to decode the bit.

To encode 4KB of data, we need to generate 4*1024*8 collisions (which takes a few hours), taking up 4MB of space in the final file.

To speed this up, I made some small tweaks to FastColl to make it even faster in practice, enabling it to be run in parallel. I'm sure there are smarter ways to parallelise it, but my naive approach is to start N instances simultaneously and wait for the first one to complete, then kill all the others.

Since I've already done the pre-computation, reconfiguring the payload can be done near-instantly. Swapping the state of the pre-computed blocks is done using a technique implemented by Ange Albertini.

Is it detectable?

Yes. It's not very stealthy at all, nor does it try to be. You can detect the collision blocks using detectcoll.
Download Monomorph
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
[ Removed by Reddit ]

[ Removed by reddit on account of violating the content policy. ]

submitted by /u/Fsociety621
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Windows 10/11 Proxy Server

How do you turn Windows 10/11 into a proxy server.

I want to make it clear, I don't want to connect to a proxy with Windows. That's all I've been able to find on the web.

I want the Windows machine to be a proxy. Ideally I'd like to set the user, pass, and port.

TIA for any help

Edit: tips for http proxy setup is alright but I would prefer to know how to turn a windows machine into a socks5 proxy server

submitted by /u/DankHacks26
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How do I get bettet at hacking?

Yes, im a white hat who is trying to get better at hacking, but i don't know the best way to practice. Please help me. P.s. i use Tryhackme

submitted by /u/QuirkyData3500
[link] [comments]