7 subscribers
34 photos
6 videos
29 files
29 links
Backup
Download Telegram
Forwarded from Team ETF ([โ˜…๐ƒ๐•โ˜…]โšกNรธรธbma๐”ฐแด›e๐–—69โšกโš”๏ธเธฟโฑ โ‚ณโ‚ตโ‚ญ โ‚ฆล‚โ‚ฆJโ‚ณ โ‚ฃร˜โฑคโ‚ตษ†โš”๏ธ ล‚โ‚ฆฤล‚โ‚ณโ‚ฆ Vษ†โฑคล‚โ‚ฃล‚ษ†ฤ ใ€Ž#๐‚๐„๐๐“๐”๐‘๐˜โ„ขใ€๐Ÿ›กXLR8VERIFIED๐Ÿ›ก | ๐ƒ๐„๐•๐ˆ๐‹'๐’ ๐•๐„๐‘๐ˆ๐…๐ˆ๐„๐ƒ |#แด›สœแด‡แด…สษดแด€แดษชแด„ษดแด‡แด›แดกแดส€แด‹)
Day6:
Commonly used terms in Carding.

#carding

โ–ก๐Ÿ’ณCC: CREDIT CARD. Without this how will you card.๐Ÿ˜‚

โ–ก๐ŸŒSOCKS5 IP:It is a proxy. It routes your traffic through a proxy server and generates an arbitrary IP address before you reach your destination. To say simply,it changes your IP address like a VPN. But it is much secured and provides good anonymity than a VPN.

โ–ก๐Ÿ–ฅVPS/VM: VPS which everyone calls as RDP is a virtual cloud hosted pc. It is a virtual pc which has different MAC ADDRESS,different RAM,different storage than your computer. You can access a VPS using RDP or a Remote client. To say simply,you are accessing a different pc from your pc

VM(virtual machine) is like a vps,but it is not cloud hosted. It is made with the properties of your computer,means the VM has same MAC ADDRESS which your computer has.

But whatever happens in a VM or VPS wont effect your computer.

โ–ก๐Ÿ’ณ6๏ธโƒฃBIN: BIN(Bank Identification Number) is the first 6digits of a CC number. Every bank has their own BIN. The first digit of the BIN says the provider of the CC

If it starts with 3: It is AMEX Card
If it starts with 4: It is VISA card
If it starts with 5: It is MASTERCARD card
If it starts with 6: It is DISCOVER/RUPAY(in india)

โ–ก๐Ÿ‘จFULLZ: FULLZ means the complete details of a person
like CC details,Address,DOB,Phone number,Email address,SSN(Social Security Number is a Number which the US government provides to US citizens)

โ–ก๐ŸŒ๐Ÿ›911: 911 is a site which sells SOCKS5 proxies. You buy proxies from any site which sells proxies,but 911 proxies have good anonymity and good security than proxies from other sites.

โ–ก๐ŸŒ๐Ÿ’ณUNICC: UNICC is a CC selling. It is a highly trusted CC selling site. You can buy CC there for less prices. You can even buy FULLZ,CC with FULLZ.

โ–ก๐ŸŒ๐Ÿ’ฒBITCOIN: BTC(BITCOIN) is a Digital currency.
Most of the sites like UNICC,911 accepts BTC only to buy CC,proxies. So if you dont have BTC,buy from BTC sellers. You can store your BTC in BTC wallets like Coinbase(most preferred wallet).

โ–ก๐Ÿก๐Ÿ—บDROP: DROP is an address where your product will be shipped to. Suppose think that you are carding an E-COMMERCE site like bestbuy,amazon with a USA CC. So definitely the shipping address which you type in checkout should be a USA address. Orelse the site will see this SUSPICIOUS and cancels your order.

For the CC owner Shipping address will be the Drop address. But as we wont live with that CC owner we ship that product to another address from where we can get the product. If you have relatives or your house in USA,then you can keep their address. From them you can get your product. If you dont have any relatives then you can get DROP address from dropshipping sites. They will ship the product to you if you keep the DROP address they gave.


๐Ÿšจ๐Ÿšจ๐ŸšจThese are the most commonly used terms in carding,but there are more terms you need to know. We will post them later. Peace๐Ÿ˜‡
Forwarded from Team ETF (แดต แตƒแต แตสณแต’แต’แต—)
Day7 :-

#forensics

๐˜ฟ๐™š๐™ฉ๐™š๐™˜๐™ฉ ๐Ÿ‡ฉโ€Œ๐Ÿ‡ฉโ€Œ๐Ÿ‡ดโ€Œ๐Ÿ‡ธโ€Œ, ๐Ÿ‡ตโ€Œ๐Ÿ‡ฎโ€Œ๐Ÿ‡ณโ€Œ๐Ÿ‡ฌโ€Œ ๐™š๐™ฉ๐™˜... ๐™ช๐™จ๐™ž๐™ฃ๐™œ ๐Ÿ‡ธโ€Œ๐Ÿ‡ณโ€Œ๐Ÿ‡ดโ€Œ๐Ÿ‡ทโ€Œ๐Ÿ‡นโ€Œ


Snort is a packet sniffer that monitors network traffic in real time, scrutinizing each packet closely to detect a dangerous payload or suspicious anomalies.

My OS :- ubuntu
Let my ip address be 192.168.1.103

๐Ÿ…ข๐Ÿ…”๐Ÿ…ฃ๐Ÿ…ค๐Ÿ…Ÿ:- ( will be easy in future )

First you need to make some changes in configuration of snort.

๐šœ๐šž๐š๐š˜ ๐š๐šŽ๐š๐š’๐š /๐šŽ๐š๐šŒ/๐šœ๐š—๐š˜๐š›๐š/๐šœ๐š—๐š˜๐š›๐š.๐šŒ๐š˜๐š—๐š

Now, change HOME_NET IP address to your ip range.
Like,
๐š’๐š™๐šŸ๐šŠ๐š› ๐™ท๐™พ๐™ผ๐™ด_๐™ฝ๐™ด๐šƒ ๐Ÿท๐Ÿฟ๐Ÿธ.๐Ÿท๐Ÿผ๐Ÿพ.๐Ÿท.๐Ÿถ/๐Ÿธ๐Ÿบ

Now go to
/๐šŽ๐š๐šŒ/๐šœ๐š—๐š˜๐š›๐š/๐š›๐šž๐š•๐šŽ๐šœ/๐š•๐š˜๐šŒ๐šŠ๐š•.๐š›๐šž๐š•๐šŽ๐šœ
and add the rules given below

( Watch rules writing in the image. )

๐Ÿ…“๐Ÿ…”๐Ÿ…ฃ๐Ÿ…”๐Ÿ…’๐Ÿ…ฃ ๐Ÿ…Ÿ๐Ÿ…˜๐Ÿ…๐Ÿ…– ๐Ÿ…ข๐Ÿ…’๐Ÿ…๐Ÿ…

๐™๐™ช๐™ก๐™š:-
๐šŠ๐š•๐šŽ๐š›๐š ๐š’๐šŒ๐š–๐š™ ๐šŠ๐š—๐šข ๐šŠ๐š—๐šข -> $๐™ท๐™พ๐™ผ๐™ด_๐™ฝ๐™ด๐šƒ ๐šŠ๐š—๐šข (๐š–๐šœ๐š:"๐™ฟ๐š’๐š—๐š ๐š๐šŽ๐š๐šŽ๐šŒ๐š๐šŽ๐š"; ๐šœ๐š’๐š:๐Ÿท๐Ÿถ๐Ÿถ๐Ÿถ๐Ÿถ๐Ÿถ๐Ÿท; ๐š›๐šŽ๐šŸ:๐Ÿท; ๐šŒ๐š•๐šŠ๐šœ๐šœ๐š๐šข๐š™๐šŽ:๐š’๐šŒ๐š–๐š™-๐šŽ๐šŸ๐šŽ๐š—๐š;)

alert ---> show alert

ICMP ---> It's a protocol used to report error in ipv4

-> :- to

$HOME_NET ---> destination ip

msg ---> shows message which you write

sid --->  keyword is used to uniquely identify Snort rules. This information allows output plugins to identify rules easily.
100 - 1,000,000 Rules already registered . So u need to use greater than this id like 1,000,123.

rev --->  keyword is used to uniquely identify revisions of Snort rules

classtype:icmp-event ---> Categorizes the rule as an โ€œicmp-eventโ€, one of the predefined Snort categories. This option helps with rule organization.

๐˜ฟ๐™š๐™ฉ๐™š๐™˜๐™ฉ๐™ž๐™ฃ๐™œ
๐šœ๐šž๐š๐š˜ ๐šœ๐š—๐š˜๐š›๐š -๐™ฐ ๐šŒ๐š˜๐š—๐šœ๐š˜๐š•๐šŽ -๐šš -๐šŒ /๐šŽ๐š๐šŒ/๐šœ๐š—๐š˜๐š›๐š/๐šœ๐š—๐š˜๐š›๐š.๐šŒ๐š˜๐š—๐š -๐š’ ๐šŽ๐š‘๐š๐Ÿถ


-A console ----> shows standard output alert
-q ----> quite mode
-i ----> interface
-c ----> config


๐Ÿ…“๐Ÿ…”๐Ÿ…ฃ๐Ÿ…”๐Ÿ…’๐Ÿ…ฃ ๐Ÿ…ฃ๐Ÿ…’๐Ÿ…Ÿ ๐Ÿ…ข๐Ÿ…’๐Ÿ…๐Ÿ…

๐™๐™ช๐™ก๐™š:-
๐šŠ๐š•๐šŽ๐š›๐š ๐š๐šŒ๐š™ ๐šŠ๐š—๐šข ๐šŠ๐š—๐šข -> $๐™ท๐™พ๐™ผ๐™ด_๐™ฝ๐™ด๐šƒ ๐šŠ๐š—๐šข (๐š–๐šœ๐š: "๐šƒ๐™ฒ๐™ฟ ๐š‚๐šŒ๐šŠ๐š— ๐™ณ๐šŽ๐š๐šŽ๐šŒ๐š๐šŽ๐š"; ๐šœ๐š’๐š:๐Ÿท๐Ÿถ๐Ÿถ๐Ÿถ๐Ÿถ๐Ÿถ๐Ÿถ๐Ÿป; ๐š›๐šŽ๐šŸ:๐Ÿธ; )


๐Ÿ…“๐Ÿ…”๐Ÿ…ฃ๐Ÿ…”๐Ÿ…’๐Ÿ…ฃ ๐Ÿ…“๐Ÿ…ž๐Ÿ…ข ๐Ÿ…๐Ÿ…ฃ๐Ÿ…ฃ๐Ÿ…๐Ÿ…’๐Ÿ…š

๐™๐™ช๐™ก๐™š:-
๐šŠ๐š•๐šŽ๐š›๐š ๐š๐šŒ๐š™ ๐šŠ๐š—๐šข ๐šŠ๐š—๐šข -> $๐™ท๐™พ๐™ผ๐™ด_๐™ฝ๐™ด๐šƒ ๐Ÿพ๐Ÿถ (๐š๐š•๐šŠ๐š๐šœ: ๐š‚; ๐š–๐šœ๐š:"๐™ฟ๐š˜๐šœ๐šœ๐š’๐š‹๐š•๐šŽ ๐™ณ๐š˜๐š‚ ๐™ฐ๐š๐š๐šŠ๐šŒ๐š” ๐šƒ๐šข๐š™๐šŽ : ๐š‚๐šˆ๐™ฝ ๐š๐š•๐š˜๐š˜๐š"; ๐š๐š•๐š˜๐š :๐šœ๐š๐šŠ๐š๐šŽ๐š•๐šŽ๐šœ๐šœ; ๐šœ๐š’๐š:๐Ÿน; ๐š๐šŽ๐š๐šŽ๐šŒ๐š๐š’๐š˜๐š—_๐š๐š’๐š•๐š๐šŽ๐š›:๐š๐š›๐šŠ๐šŒ๐š” ๐š‹๐šข_๐š๐šœ๐š, ๐šŒ๐š˜๐šž๐š—๐š ๐Ÿธ๐Ÿถ, ๐šœ๐šŽ๐šŒ๐š˜๐š—๐š๐šœ ๐Ÿท๐Ÿถ;)

#reference__researchgate-website

๐™€๐™ญ๐™ฉ๐™ง๐™–
Ping scan :- nmap 192.168.1.103
Tcp scan :- nmap -sT 192.168.1.103
Dos :- Use any tools๐Ÿ˜

Written by :- I am groot [ @Etf_Zan ]
Forwarded from Team ETF (แดต แตƒแต แตสณแต’แต’แต—)
Forwarded from Team ETF (แดต แตƒแต แตสณแต’แต’แต—)
Day8:-

#forensics

Well we have have learnt about snort yesterday ,on how to write your own snort rules as well as using it.

To detect ARP SPOOF,
You can use any tools from github or create your own using scapy.

Easy way:- just by looking MAC address.

Today we learn about some basics of windows registry.

Source :- YT ( 13 cubed )

I won't be covering this, u can learn in 13 cubed yt channel for more about windows forensics
Forwarded from Team ETF (แดต แตƒแต แตสณแต’แต’แต—)
dfir_cheat_sheet.pdf
62.9 KB
Forwarded from Team ETF (แดต แตƒแต แตสณแต’แต’แต—)
Introduction_to_Windows_Forensics.247.mkv
176.8 MB
Forwarded from Team ETF (Groot)
#forensics

Today we will discuss about malware forensics.

Here we will find the malware in our pc.

Tool :- volatility ( open source github )
Forwarded from Team ETF (Groot)
Forwarded from Team ETF (Groot)
Explanation:-

There are two types of scan in volatility to detect profile.
1. By imageinfo ( above picture )
2. Kdbg scan ( tmrw I will discuss this)

Here in the above figure we can see that there we scanned using imageinfo, and it detected some of the profiles ( which os memory fike it is ).

Profile :- WinXPSP2x86 ( see highlighted)

Possible doubts :-
1.Here we have used memory dump of cridex.vmem

.vmem -> virtualbox memory
cridex is the one of the malware name

2. I already thought you earlier how to get memory file.

Error:-
There's installation error in my tool. Probably you won't get failed error while running tool.
Forwarded from Team ETF (Groot)
In new version ( volatility3)
There's no need to do profile scan, you can skip this step.


Next class :-
Tomorrow be ready
Forwarded from Groot
Forwarded from Team ETF (Groot)
๐Ÿ‘† here we did profile scan of another memory dump file.
Forwarded from Groot
Forwarded from Team ETF (Groot)
๐Ÿ‘†Here u can see that we used lsadump plugin, which gives default saved passwords.
Forwarded from Groot
Forwarded from Team ETF (Groot)
๐Ÿ‘† netscan plugin is used to scan all the connected devices to that device .
Forwarded from Team ETF (Groot)
Now, we need to find the pc name .
WKT it is present in the system ( we learnt in windows registery section ) .
To find that using volatility ,
First we need to get the offset of system file.
Offset:- address

So we us hivelist plugin๐Ÿ‘‡
Forwarded from Groot
Forwarded from Team ETF (Groot)
Now we get the offset of system file,
WKT when we explore registry there were many directories, it may change for some pc. So we will go one by one directory using printkey plugin๐Ÿ‘‡
Forwarded from Team ETF (Groot)
Forwarded from Team ETF (Groot)
By doing these step by step we will find the required file, I skipped 1 step, you do this by ur own๐Ÿ‘‡