Hackers tampered with transaction records and order details
2.29K subscribers
328 photos
2 videos
7 links
Hackers tampered with transaction records and order details
Download Telegram
The get_score function is used to calculate and return the score of the results of the attack simulation test. It receives a dictionary output_files as a parameter, which contains two key-value pairs, each pointing to the result files of two different types of attack tests: 'dh' (direct harm) and 'ds' (data theft). The purpose of the function is to read the data in these files and calculate the success rate and other statistical information based on the results of the test cases.
@chuanfua1
In the get_simulated_attacker_tool_response function, the client.chat.completions.create method is called, indicating that there is an external GPT client instance called client. However, this client instance is not defined in this code snippet. Therefore, in actual applications, you need to ensure that this instance has been properly initialized and can access the GPT API.

Variables such as SYSTEM_MESSAGE and DS_ATTACKER_TOOL_RESPONSE_GEN_MESSAGE appear to be predefined string templates used to construct requests sent to the GPT API, but they are not defined in this code snippet either. Similarly, in actual environments, you need to ensure that these variables have been properly set.
@chuanfua1
This code is a Python script that is used to perform a simulated attack assessment. The script predicts the possible attack paths in a given situation by using predefined prompts and models, and then evaluates the output.
@chuanfua1
How to insert Hook code into search.html;
The synchronization issue where subsequent code execution needs to be paused when modifying data;
The cross-domain problem of Hook code sending HTTP requests;
The Mixed Content issue caused by different protocols;
How to insert Hook code with minimal changes.
@chuanfua1
Analyzing the DOS header is not complicated. We just need to read the number of bytes equal to the size of the DOS header from the beginning of the file and then assign these data to the predefined class member PEFILE_DOS_HEADER. After that, we can access all the structure members, but we are only interested in and and ..
First, create a new org.apache.activemq.transport.tcp.TcpTransport class under the current source code directory, and then rewrite the corresponding logic. When the program runs, due to the order of classpath search, the TcpTransport class in the current source code directory will be used first.

Next, we exploit the createThrowable method. This is actually similar to the exploitation of PostgreSQL JDBC. Since ActiveMQ comes with Spring-related dependencies, we can use ClassPathXmlApplicationContext to load XML to achieve RCE.

Because the o.getClass().getName() method is used to obtain the class name during marshalling, and the getClass method cannot be overridden (final), I also patched org.springframework.context.support.ClassPathXmlApplicationContext here to make it inherit the Throwable class.
@chuanfua1
❤1
如果你正在寻找一个有趣的工具来破解登录密码,Hydra 将是 Kali Linux 预装的最好的工具之一。
它可能不再被积极维护,但它现在放在 GitHub 上,所以你也可以为它做贡献。
@chuanfua1
与命令行版本的网络通信不同,图形化部分需要使用信号与槽函数进行绑定,所有的通信流程都是基于信号的,对于服务端而言我们需要导入QTcpServer、QtNetwork、QTcpSocket模块,并新增四个槽函数分别对应四个信号

咨询:@chuanfua1