Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Azure RBAC baseline authorization ⚠️Detect principals in privileged subscriptions roles protected only by password-based single factor authentication. Checks for users without MFA policies applied for set of conditions Checks for ServicePrincipals protected only by password (as opposed to using Certificate Credential, workload federation and or workload identity CA policy) Maps to App Registration Best Practices (https://docs.microsoft.com/en-us/azure/active-directory/develop/security-best-practices-for-app-registration#credential-configuration) An unused credential on an application can result in security breach. While it's convenient to use password. secrets as a credential, we strongly recommend that you use x509 certificates as the only credential type for getting tokens for your application State healthy - User result example {
"subscriptionName": "EAST -msdn",
"friendlyName": "joosua@thx138.onmicrosoft.com",
"mfaResults": {
"oid": "138ac68f-d8a7-4000-8d41-c10ff26a9097",
"appliedPol": [{
"GrantConditions": "challengeWithMfa",
"policy": "baseline",
"oid": "138ac68f-d8a7-4000-8d41-c10ff26a9097"
}],
"checkType": "mfa"
},
"basicAuthResults": {
"oid": "138ac68f-d8a7-4000-8d41-c10aa26a9097",
"appliedPol": [{
"GrantConditions": "challengeWithMfa",
"policy": "baseline",
"oid": "138ac68f-d8a7-4000-8d41-c10aa26a9097"
}],
"checkType": "basicAuth"
},
} ⚠️State unHealthy - Application principal example {
"subscriptionName": "EAST - HoneyPot",
"friendlyName": "thx138-kvref-6193053b-408b-44d0-b20f-4e29b9b67394",
"creds": {
"@odata.context": "https://graph.microsoft.com/beta/$metadata#servicePrincipals(id,displayName,appId,keyCredentials,passwordCredentials,servicePrincipalType)/$entity",
"id": "babec804-037d-4caf-946e-7a2b6de3a45f",
"displayName": "thx138-kvref-6193053b-408b-44d0-b20f-4e29b9b67394",
"appId": "5af1760e-89ff-46e4-a968-0ac36a7b7b69",
"servicePrincipalType": "Application",
"keyCredentials": [],
"passwordCredentials": [],
"OnlySingleFactor": [{
"customKeyIdentifier": null,
"endDateTime": "2023-10-20T06:54:59.2014093Z",
"keyId": "7df44f81-a52c-4fd6-b704-4b046771f85a",
"startDateTime": "2021-10-20T06:54:59.2014093Z",
"secretText": null,
"hint": nu ll,
"displayName": null
}],
"StrongSingleFactor": []
}
}
Contributing Following methods work for contributing for the time being: Submit a pull request with code / documentation change Submit a issue issue can be a: ⚠️Problem (issue) Feature request Question Other By default EAST tries to work with the current depedencies - Introducing new (direct) depedencies is not directly encouraged with EAST. If such vital depedency is introduced, then review licensing of such depedency, and update readme.md - depedencies (https://github.com/jsa2/EAST#depedencies) There is nothing to prevent you from creating your own fork of EAST with your own depedencies

Download EAST (https://github.com/jsa2/EAST)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
EAST - Extensible Azure Security Tool - Documentation

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-Pl1O1HnRx2ODYup-qhBPvpEff5QIwlQBaloCIfzIWRftGgjdQCTTdum83fvsyiWs2pX7UQcccQG6woD4w71Y4AZbltjw7PamPenJ1u8EnfKD-HGImv9ECdkCtzqfOz_Si9r4j99GdbJ6l5jTbr9mLciOx6FQZWBVLYPLnKMSUaVSHEHCYB5c7wxL8A/w640-h226/EAST_2.png Extensible Azure Security Tool (Later referred as E.A.S.T) is tool for assessing Azure and to some extent Azure AD security controls. Primary use case of EAST is Security data collection for evaluation in Azure Assessments. This information (JSON content) can then be used in various reporting tools, which we use to further correlate and investigate the data.
This tool is licensed under MIT license. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2sng9X7Sd_ASeKGGeH8w_LA5_S0CWO2kwRq03sNBYXzqmpFSPGpRHjJpgMu37WdK9mo7oGSu--ZLJ1SXEQXcDWqvoJ27xpIu-wqrasukTO-AWir_7sn8QZwUvB09hMDDpndJddjAb5WsGA05nffwlbb3rXra8kOqguHJRyCw4lPu-Q6tFHFE7qjNPEQ/w640-h390/EAST_1.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyKX_cJDBcX_ZMAIF5KeT7d4A5_XnvlH6Gx7-oy_15Baqa2PrEP3qQF7ZHFTzSogMhDtmCqHXA8C0oWrvg34LamuOLoXHCzuuY8YGbBzV_BsdIMXFg62A4zXMB5Pqc1fm7Uau3Tbty0bri3WC1XJ5t9PlzhPEX2yDyn2JVOYVnFgBMBknPLCcGXwI49w/w640-h226/EAST_2.png Collaborators* Yours truly
* Nixu Cloud Security Team Release notes*
Preview branch introduced

Changes:

*
Installation now accounts for use of Azure Cloud Shell's updated version in regards to depedencies (Cloud Shell has now Node.JS v 16 version installed)

*
Checking of Databricks cluster types as per advisory
* Audits Databricks clusters for potential privilege elevation - This control requires typically permissions on the databricks cluster"

*
Content.json is has now key and content based sorting. This enables doing delta checks with git diff HEAD^1¹ as content.json has predetermined order of results https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlLTr8khXWfULOso2mIlLFy8kAeHkAr95FFFpyLM9iiDgagJNKW0hUNspqrUwb9YsfKqUz0n6V57Ftkem0h9qX_eMfZWzmRgX1AggsgCyvF1x1DANHmkomtT2WH0VBG3-aXfG5YFmpGBYCHS1a2GnYdotR3PHp4BACShLx8tasBe3RUS2yEvA0wgq70Q/w640-h234/EAST_3.png ¹Word of caution, if want to check deltas of content.json, then content.json will need to be "unignored" from .gitignoreexposing results to any upstream you might have configured.

Use this feature with caution, and ensure you don't have public upstream set for the branch you are using this feature for

*
Change of programming patterns to avoid possible race conditions with larger datasets. This is mostly changes of using varto letin for await-style loops ImportantCurrent status of the tool is beta

* Fixes, updates etc. are done on "Best effort" basis, with no guarantee of time, or quality of the possible fix applied
* We do some additional tuning before using EAST in our daily work, such as apply various run and environment restrictions, besides formalizing ourselves with the environment in question. Thus we currently recommend, that EAST is run in only in test environments, and with read-only permissions.
* All the calls in the service are largely to Azure Cloud IP's, so it should work well in hardened environments where outbound IP restrictions are applied. This reduces the risk of this tool containing malicious packages which could "phone home" without also having C2 in Azure.
* Essentially running it in read-only mode, reduces a lot of the risk associated with possibly compromised NPM packages (Google compromised NPM)
* Bugs etc: You can protect your environment against certain mistakes in this code by running the tool with reader-only permissions
* Lot of the code is "AS IS": Meaning, it's been serving only the purpose of creating certain result; Lot of cleaning up and modularizing remains to be finished
* There are no tes[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! EAST - Extensible Azure Security Tool - Documentation https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-Pl1O1HnRx2ODYup-qhBPvpEff5QIwlQBaloCIfzIWRftGgjdQCTTdum83fvsyiWs2pX7UQcccQG6woD4w71Y4AZbltjw7PamPenJ1u8EnfKD-HGIm…
ts at the moment, apart from certain manual checks, that are run after changes to main.js and various more advanced controls.
* The control descriptions at this stage are not the final product, so giving feedback on them, while appreciated, is not the focus of the tooling at this stage
* As the name implies, we use it as tool to evaluate environments. It is not meant to be run as unmonitored for the time being, and should not be run in any internet exposed service that accepts incoming connections.
* Documentation could be described as incomplete for the time being
* EAST is mostly focused on PaaS resource, as most of our Azure assessments focus on this resource type
*
No Input sanitization is performed on launch params, as it is always assumed, that the input of these parameters are controlled. That being said, the tool uses extensively exec()- While I have not reviewed all paths, I believe that achieving shellcode execution is trivial. This tool does not assume hostile input, thus the recommendation is that you don't paste launch arguments into command line without reviewing them first. Tool operationDepedenciesTo reduce amount of code we use the following depedencies for operation and aesthetics are used (Kudos to the maintainers of these fantastic packages)
package aesthetics operation license axios
MIT yargs
MIT jsonwebtoken
MIT chalk
MIT js-beautify MIT
Other depedencies for running the tool: If you are planning to run this in Azure Cloud Shell you don't need to install Azure CLI:

* This tool does not include or distribute Microsoft Azure CLI, but rather uses it when it has been installed on the source system (Such as Azure Cloud Shell, which is primary platform for running EAST)

Azure Cloud Shell (BASH) or applicable Linux Distro / WSL
Requirement description Install

AZ CLI AZCLI USE curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
Node.js runtime 14 Node.js runtime for EAST install with NVM ControlsEAST provides three categories of controls: Basic, Advanced, and Composite

The machine readable control looks like this, regardless of the type (Basic/advanced/composite): {
"name": "fn-sql-2079",
"resource": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourcegroups/rg-fn-2079/providers/microsoft.web/sites/fn-sql-2079",
"controlId": "managedIdentity",
"isHealthy": true,
"id": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourcegroups/rg-fn-2079/providers/microsoft.web/sites/fn-sql-2079",
"Description": "\r\n Ensure The Service calls downstream resources with managed identity",
"metadata": {
"principalId": {
"type": "SystemAssigned",
"tenantId": "033794f5-7c9d-4e98-923d-7b49114b7ac3",
"principalId": "cb073f1e-03bc-440e-874d-5ed3ce6df7f8"
},
"roles": [{
"role": [{
"properties": {
"roleDefinitionId": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c",
"principalId": "cb073f1e-03b c-440e-874d-5ed3ce6df7f8",
"scope": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourceGroups/RG-FN-2079",
"createdOn": "2021-12-27T06:03:09.7052113Z",
"updatedOn": "2021-12-27T06:03:09.7052113Z",
"createdBy": "4257db31-3f22-4c0f-bd57-26cbbd4f5851",
"updatedBy": "4257db31-3f22-4c0f-bd57-26cbbd4f5851"
},
"id": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourceGroups/RG-FN-2079/providers/Microsoft.Authorization/roleAssignments/ada69f21-790e-4386-9f47-c9b8a8c15674",
"type": "Microsoft.Authorization/roleAssignments",
"name": "ada69f21-790e-4386-9f47-c9b8a8c15674",
"RoleName": "Contributor"
}]
}]
},
"category": "Access"
},
BasicBasic controls include checks on the initial ARM object for simple "toggle on/off"- boolean settings of said service.

Example: Azure Container Registry adminUser acr_adminUser https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6hStnaw4gkMJDNdqzzxs1kxMx8_6-FEIZU07X3tcHwbiTJ8wddN91_9b1LFq-fF4rLr[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is it possible for someone to breach my reddit acc and pinpoint my location?

This sounds so dumb I know but I am a little paranoid that someone might get my location from my reddit acc since it is linked with a gmail acc.

On another note is it possible(hack into my acc and get personal information) on any other social media platforms?

submitted by /u/AstralMystogan
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Revenge on local gang

Long story short I want revenge on this gang for something they did to some family members they asked me to put some videos on a usb for them how can I use this to my advantage and gain access to their shit undetected with the USB I have Kali Linux but haven't used it yet Need help please

submitted by /u/Timely_Purpose_842
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I'm trying to turn my TP-link archer c6 v2 into a wifi pineapple that runs monitor mode and i can't find a tutorial.

I have done some research but i haven't been able to find any conclusive data regarding this, i figured installing open wrt might be a start but I'm still stuck as of now some guidance would be appreciated. THANKS!

submitted by /u/BlacksmithLucky4855
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Ip adress

I got the Ip of some troll online and I am wondering if there is something more I can do with it apart from knowing his location?

submitted by /u/ElderberryInformal66
[link] [comments]
hacking: security in practice
How do I add a PHP script to a python exploit?

I'm trying to use [this exploit](https://www.exploit-db.com/exploits/44374) on a box from vulnhub, but the part I can't figure out is in the exploit where it says:

#the payload will be injected into the configuration file via this code

#' define(\'DB_DATABASE\', \'' . trim($HTTP_POST_VARS['DB_DATABASE']) . '\');' . "\n" .

#so the format for the exploit will be: '); PAYLOAD; /*

payload = '\');'

payload += 'system("ls");' # this is where you enter you PHP payload

payload += '/*'

data['DB_DATABASE'] = payload

So how do I actually enter the PHP payload? I'm trying to use the PHP reverse shell from Pentest Monkey that comes with Kali. I tried copy pasting and

payload += 'system("php /path/to/php_reverse_shell.php");'

Thanks guys.

submitted by /u/Lazy-Reserve-131
[link] [comments]
Does anyone know if there are online distributions/virtual machines for pentesting that we can use?
https://www.reddit.com/r/Pentesting/comments/10th45n/does_anyone_know_if_there_are_online/

<!-- SC_OFF -->Are there alternatives to using an installed version of Kali Linux? I am asking since it seems convenient to have a virtual machine than having to install Kali for tools. <!-- SC_ON --> submitted by /u/Beginning_java (https://www.reddit.com/user/Beginning_java)
[link] (https://www.reddit.com/r/Pentesting/comments/10th45n/does_anyone_know_if_there_are_online/) [comments] (https://www.reddit.com/r/Pentesting/comments/10th45n/does_anyone_know_if_there_are_online/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is ethical hacking?

Ethical hacking, also known as "white hat" hacking, refers to the practice of using hacking techniques for the purpose of identifying and…

Continue reading on Medium »