Hackers tampered with transaction records and order details
2.28K subscribers
329 photos
2 videos
7 links
Hackers tampered with transaction records and order details
Download Telegram
On Windows systems, to ensure that users' clear-text passwords are not leaked, the passwords are converted into HASH values for authentication and stored in SAM or ntds.dit (such as mimitakz, procdump, etc.). All account passwords in the domain are stored in Ntds.dit. If you can obtain this file, it means you have gained full domain permissions. This approach is particularly important in domain penetration, as it contains the HASH values of all domain users. However, this method only works on the DC. You don't need to worry about being detected by antivirus software, as you don't need to upload any tools to the target machine.

Manually export NTDS.dit and System and place them in the c:\users\tmp directory:
ntdsutil "ac i ntds" ifm "create full c:\users\tmp" q q

@chuanfua1
The C2-profile file is a built-in tool of Cobalt Strike, which is used to control the traffic of Cobalt Strike and can prevent security devices from monitoring and intercepting traffic characteristics.
Download the profile file corresponding to the CS version and modify it. The main parts that need to be modified are https-certificate and code-signer, which correspond to the information in the cobaltstrike.store file.
Then use Cobalt Strike's c2lint to check whether there are any problems with the profile.

@chuanfua1
Generate a Python executable payload using MSF. By default, the script generated is for Python 2.
The attacker executes the following command to start listening:
Next, the target host uses MSF to execute the generated payload. Since Python can load arbitrary code using the -c parameter, we can simply use the SSL library to encrypt the traffic in the code.

@chuanfua1
We can simply use pip3 install bottle to download the latest version.

Then, write a piece of code here and manually add a test route, which is roughly as follows:
In the command prompt, we can execute the Python code to start the test.
@chuanfua1
First, regarding the use of decorators, we can directly call a route function. Let's take a look at it. It actually has many default parameters. Before looking at the code, we can understand its meaning by reading the documentation description. First, the path we pass in, as shown in the figure /memshell, is our path.
Let's follow the code.
@chuanfua1
— 让搜索更高效 · 让信息更有价值 —

🔍帮你找到有趣的群组、频道、视频、音乐、电影、新闻
📢:
@CJYQNEWS | 🤖: @CJYQ
👇点击下方按钮,进行搜索👇
超索 @ChaoSuoBOT  

让你轻松找到群组、频道、视频、音乐、电影、新闻!

👇点击下方按钮开始搜索👇
The get_score function is used to calculate and return the score of the results of the attack simulation test. It receives a dictionary output_files as a parameter, which contains two key-value pairs, each pointing to the result files of two different types of attack tests: 'dh' (direct harm) and 'ds' (data theft). The purpose of the function is to read the data in these files and calculate the success rate and other statistical information based on the results of the test cases.
@chuanfua1
In the get_simulated_attacker_tool_response function, the client.chat.completions.create method is called, indicating that there is an external GPT client instance called client. However, this client instance is not defined in this code snippet. Therefore, in actual applications, you need to ensure that this instance has been properly initialized and can access the GPT API.

Variables such as SYSTEM_MESSAGE and DS_ATTACKER_TOOL_RESPONSE_GEN_MESSAGE appear to be predefined string templates used to construct requests sent to the GPT API, but they are not defined in this code snippet either. Similarly, in actual environments, you need to ensure that these variables have been properly set.
@chuanfua1
This code is a Python script that is used to perform a simulated attack assessment. The script predicts the possible attack paths in a given situation by using predefined prompts and models, and then evaluates the output.
@chuanfua1
How to insert Hook code into search.html;
The synchronization issue where subsequent code execution needs to be paused when modifying data;
The cross-domain problem of Hook code sending HTTP requests;
The Mixed Content issue caused by different protocols;
How to insert Hook code with minimal changes.
@chuanfua1
Analyzing the DOS header is not complicated. We just need to read the number of bytes equal to the size of the DOS header from the beginning of the file and then assign these data to the predefined class member PEFILE_DOS_HEADER. After that, we can access all the structure members, but we are only interested in and and ..
First, create a new org.apache.activemq.transport.tcp.TcpTransport class under the current source code directory, and then rewrite the corresponding logic. When the program runs, due to the order of classpath search, the TcpTransport class in the current source code directory will be used first.

Next, we exploit the createThrowable method. This is actually similar to the exploitation of PostgreSQL JDBC. Since ActiveMQ comes with Spring-related dependencies, we can use ClassPathXmlApplicationContext to load XML to achieve RCE.

Because the o.getClass().getName() method is used to obtain the class name during marshalling, and the getClass method cannot be overridden (final), I also patched org.springframework.context.support.ClassPathXmlApplicationContext here to make it inherit the Throwable class.
@chuanfua1
❤1