Wednesday, May 20, 2020

Android SSHControl V1.0 Relased!!!

Hoy sabado 15, he subido al Market de Android la versión 1.0 de SSHControl, con nuevas funcionalades y la esperada opción "Custom Commands".






Esta aplicación permite controlar tus servidores linux, bsd y unix con solo un dedo, mediante esta app Android.
Y soluciona las siguientes problemáticas:
- Manejar una shell desde el pequeño teclado de un móvil es engorroso.
- Leer todos los resultados de un comando en la pantalla del móvil, nos dejamos la vista.

Esta app permite interactuar con servidores remotos simplemente haciendo pulsaciones en la pantalla, mediante un explorador de ficheros, de conexiones, etc..

Las funcionalidades nuevas de esta versión 1.0 son:

- Administración del Firewall Iptables.
- Opción de Custom Commands, tal como había prometido.

Las funcionalidades ya presentes en la v0.8 son:

- escalada a root mediante su y sudo
- gestor de procesos
- explorador de ficheros, editor de ficheros, editor de permisos.
- monitorización y baneo de conexiones
- Visualizadores de logs
- administrador de drivers
- estadisticas de disco

Para la versión 2.0 preveo:

- Escuchar música remota
- Descarga de ficheros (wget)
- Transferencia segura de ficheros entre servidores (scp)
- Gestures, para administrar los sitemas en plan minority report :)

App disponible en el market para 861 tipos de dispositivos y pronto disponible en tablets.

https://market.android.com/details?id=net.ssh.SSHControl

Cualquier sugerencia de mejora: sha0 [4t] badchecksum [d0t] net

Related news

Group Instant Messaging: Why Blaming Developers Is Not Fair But Enhancing The Protocols Would Be Appropriate

After presenting our work at Real World Crypto 2018 [1] and seeing the enormous press coverage, we want to get two things straight: 1. Most described weaknesses are only exploitable by the malicious server or by knowing a large secret number and thereby the protocols are still very secure (what we wrote in the paper but some newspapers did not adopt) and 2. we see ways to enhance the WhatsApp protocol without breaking its features.


We are of course very happy that our research reached so many people and even though IT security and cryptography are often hard to understand for outsiders, Andy Greenberg [2], Patrick Beuth [3] and other journalists [4,5,6,7,8] wrote articles that were understandable on the one hand and very accurate and precise on the other hand. In contrast to this, we also saw some inaccurate articles [9,10] that fanned fear and greatly diverged in their description from what we wrote in our paper. We expected this from the boulevard press in Germany and therefore asked them to stick to the facts when they were contacting us. But none of the worst two articles' [9,10] authors contacted us in advance. Since our aim was never to blame any application or protocol but rather we wanted to encourage the developers to enhance the protocols, it contradicts our aim that WhatsApp and Signal are partially declared attackable by "anyone" "easily" [9,10].

Against this background, we understand Moxie's vexation about certain headlines that were on the Internet in the last days [11]. However, we believe that the ones who understand the weaknesses, comprehend that only the malicious server can detectably make use of them (in WhatsApp) or the secret group ID needs to be obtained from a member (in Signal). As such, we want to make clear that our paper does not primarily focus on the description of weaknesses but presents a new approach for analyzing and evaluating the security of group instant messaging protocols. Further we propose measures to enhance the analyzed protocols. The description of the protocols' weaknesses is only one part of the evaluation of our analysis approach and thereby of the investigation of real world protocols. This is the scientific contribution of our paper. The practical contribution of the analyzed messengers, which is the communication confidentiality for billion users (in most cases), is great and should be noted. Therefore we believe that being Signal, WhatsApp, or Threema by applying encryption to all messages and consequently risking research with negative results is much better than being a messenger that does not encrypt group messages end-to-end at all. We do not want to blame messengers that are far less secure (read Moxie's post [11] if you are interested).

Finally we want note that applying security measures according to the ticket approach (as we call it in the paper [12]) to the invitation links would solve the issues that Facebook's security head mentioned in his reply [13] on our findings. To our knowledge, adding authenticity to group update messages would not affect invitation links: If no invitation link was generated for a group, group members should only accept joining users if they were added by an authentic group update message. As soon as a group invitation link was generated, all joining users would need to be accepted as new group members with the current design. However there are plenty ways how WhatsApp could use invitation links without endowing the server with the power to manage groups without the group admins' permission:
One approach would be generating the invitation links secretly and sharing them without the knowledge of the server. An invitation link could then contain a secret ticket for the group and the ID of the group. As soon as a user, who received the link, wants to join the group, she can request the server with the group ID to obtain all current group members. The secret ticket can now be sent to all existing group members encrypted such that the legitimate join can be verified.

Of course this would require engineering but the capability of WhatsApp, shipping drastic protocol updates, can be assumed since they applied end-to-end encryption in the first place.

[1] https://www.youtube.com/watch?v=i5i38WlHfds
[2] https://www.wired.com/story/whatsapp-security-flaws-encryption-group-chats/
[3] http://www.spiegel.de/netzwelt/apps/whatsapp-gruppenchats-schwachstelle-im-verschluesselungs-protokoll-a-1187338.html
[4] http://www.sueddeutsche.de/digital/it-sicherheit-wie-fremde-sich-in-whatsapp-gruppenchats-einladen-koennen-1.3821656
[5] https://techcrunch.com/2018/01/10/security-researchers-flag-invite-bug-in-whatsapp-group-chats/
[6] http://www.telegraph.co.uk/technology/2018/01/10/whatsapp-bug-raises-questions-group-message-privacy/
[7] http://www.handelsblatt.com/technik/it-internet/verschluesselung-umgangen-forscher-finden-sicherheitsluecke-bei-whatsapp/20836518.html
[8] https://www.heise.de/security/meldung/WhatsApp-und-Signal-Forscher-beschreiben-Schwaechen-verschluesselter-Gruppenchats-3942046.html
[9] https://www.theinquirer.net/inquirer/news/3024215/whatsapp-bug-lets-anyone-easily-infiltrate-private-group-chats
[10] http://www.dailymail.co.uk/sciencetech/article-5257713/WhatsApp-security-flaw-lets-spy-private-chats.html
[11] https://news.ycombinator.com/item?id=16117487
[12] https://eprint.iacr.org/2017/713.pdf
[13] https://twitter.com/alexstamos/status/951169036947107840

Further articles:
- Matthew Green's blog post: https://blog.cryptographyengineering.com/2018/01/10/attack-of-the-week-group-messaging-in-whatsapp-and-signal/
- Schneier on Security: https://www.schneier.com/blog/archives/2018/01/whatsapp_vulner.html
- Bild: http://www.bild.de/digital/smartphone-und-tablet/whatsapp/whatsapp-sicherheitsluecke-in-gruppenchats-54452080.bild.html
- Sun: https://www.thesun.co.uk/tech/5316110/new-whatsapp-bug-how-to-stay-safe/

Continue reading


Tuesday, May 19, 2020

Linux Stack Protection By Default

Modern gcc compiler (v9.2.0) protects the stack by default and you will notice it because instead of SIGSEGV on stack overflow you will get a SIGABRT, but it also generates coredumps.




In this case the compiler adds the variable local_10. This variable helds a canary value that is checked at the end of the function.
The memset overflows the four bytes stack variable and modifies the canary value.



The 64bits canary 0x5429851ebaf95800 can't be predicted, but in specific situations is not re-generated and can be bruteforced or in other situations can be leaked from memory for example using a format string vulnerability or an arbitrary read wihout overflowing the stack.

If the canary doesn't match, the libc function __stack_chck_fail is called and terminates the prorgam with a SIGABORT which generates a coredump, in the case of archlinux managed by systemd and are stored on "/var/lib/systemd/coredump/"


❯❯❯ ./test 
*** stack smashing detected ***: terminated
fish: './test' terminated by signal SIGABRT (Abort)

❯❯❯ sudo lz4 -d core.test.1000.c611b7caa58a4fa3bcf403e6eac95bb0.1121.1574354610000000.lz4
[sudo] password for xxxx: 
Decoding file core.test.1000.c611b7caa58a4fa3bcf403e6eac95bb0.1121.1574354610000000 
core.test.1000.c611b : decoded 249856 bytes 

 ❯❯❯ sudo gdb /home/xxxx/test core.test.1000.c611b7caa58a4fa3bcf403e6eac95bb0.1121.1574354610000000 -q 


We specify the binary and the core file as a gdb parameters. We can see only one LWP (light weight process) or linux thread, so in this case is quicker to check. First of all lets see the back trace, because in this case the execution don't terminate in the segfaulted return.




We can see on frame 5 the address were it would had returned to main if it wouldn't aborted.



Happy Idea: we can use this stack canary aborts to detect stack overflows. In Debian with prevous versions it will be exploitable depending on the compilation flags used.
And note that the canary is located as the last variable in the stack so the previous variables can be overwritten without problems.




Related word

  1. Hacking School
  2. Nivel Basico
  3. Rfid Hacking
  4. Libros De Hacking Pdf
  5. Foro Hacking
  6. Hacker Significado
  7. Hacking 2019

El Cuento De "La Princesita De Ocho Piernas"

Hoy, cuando me he sentado a escribir el post diario de El lado del mal no quería ponerme a escribir de algo profesional. Tengo tres artículos rondando mi cabeza sobre temas técnicos y profesionales, pero hoy no me apetecía depurarlos y plasmarlos. Hoy hace sol, y quería dejar que el calor me bañara un poco. Quería dejar que el calorcito sacar algo más humano para el texto del día. 

Figura 1: El cuento de "La princesita de ocho piernas"


Así que, os he traído uno de los cuentos que narro a Mi Hacker y Mi Survivor cuando el tiempo me lo permite. Como todo buen papaéte estoy sufriendo la pre-adolescencia de una niña, y si no la controlas, sus peticiones son infinitas. Me piden de todo y me compran - y hackean - con dibujos, manualidades, etcétera. Pero no las puedo dar todo lo que quieren.

View this post on Instagram

... y así me hackean mis salvajes }:)

A post shared by Chema Alonso (@chemaalonso) on


No les puedo dar todo lo que quieren para que aprendan a priorizar y discernir entre lo que es necesario y lo que es accesorio. Entre la necesidad y el capricho, así que aprovechando a los personajes del Dragón Matías, el Rey Papá, Princesita, Chiquitina, Rapidín, Serpentina, etcétera, les creé este cuento "de mi boca" que os dejo hoy por aquí.

La Princesita de Ocho Piernas

Érase una vez que se era, una princesita muy presumida a la que su padre, el Rey Papá, cuidaba con mucho esmero y detalle. La Princesita era una niña estudiosa y trabajadora, aunque con algún arrebato de rabieta propio de su efervescencia debido a su edad. Con casi doce años estaba a punto de convertirse en una preciosa adolescente, y de vez en cuando – y solo de vez en cuando –, la energía que atesoraba le jugaba una mala pasada en su comportamiento. 

No era nada grave, pero os voy a narrar la aventura que sucedió cuando el Dragón Matías, amigo personal del Rey Papá, se enfadó con Princesita y le impuso un curioso castigo.

Todo comenzó cuando la dulce princesita se acercó con sus grandes ojos color miel y le dijo a su papaete:

- "Rey Papá, Rey Papá, ¿me comprarías unos zapatos nuevos para el vestido nuevo que me compré la semana pasada".

El Rey Papá la miró, y sorprendido la contestó:

- "Princesita mía, compramos el vestido para los zapatos nuevos que tenías, ¿cómo es que ahora quieres unos zapatos nuevos para ese mismo vestido?"

La Princesita comenzó un principio de rabieta y dijo:

- "Rey Papá, Rey Papá, es que ya no me gustan esos zapatos y quiero otros nuevos. No seas malo con tu princesita y cómprame unos nuevos".

El Rey Papá refunfuñó e intentó hacer entrar en razón a la joven Princesita, pero lo único que obtuvo como respuesta a sus razonamientos fuero llantos, rabieta y más quejas de la joven que parecía la niña más desdichada del mundo. Tras media hora de llantos y quejas de la princesita, al final el Rey Papá claudicó y prometió llevar a su hija al día siguiente a comprar unos nuevos zapatos.

Llegado ese día, apareció en la puerta del castillo del Rey Papá su amigo el Dragón Matías para irse a volar por las montañas. Hacía tiempo que no salían juntos y habían quedado para ir al lago de la montaña del norte a darse unos baños en agua cristalina. Cuando llegó feliz, el Rey Papá le dijo:

- "Perdona Dragón Matías, se me olvidó que hoy teníamos la excursión y le he prometido a la princesita que la llevaría a comprar unos zapatos nuevos. Vamos a tener que cancelar la excursión".

El Dragón Matías se quedó consternado, pero no por la cancelación repentina de la excursión, sino por la evolución que estaba siguiendo la pequeña princesita. El Dragón Matías había cuidado de ella y de su hermana "Chiquitinia" desde que nacieron y estos ataques compra compulsiva y caprichosa no le parecían nada bien.

- "Rey Papá", dijo el Dragón Matías, "Tú eres consciente de que Princesita no necesita para nada esos zapatos, y que esta siendo caprichosa, ¿Verdad? ¿No crees que deberías hablar con ella y explicarla que no debería comprarse cosas que no necesite?

El Rey Papá le dio la razón al Dragón Matías y se excusó diciendo que se había puesto muy pesada y no sabía cómo conseguir que se tranquilizara. En ese momento el Rey Papá se sintió un poco avergonzado, pero el Dragón Matías lo consoló.

- "¿Me dejas hablar con ella, Rey Papá?", dijo el Dragón Matías.

El Rey Papá accedió a la petición, y permitió que el Dragón Matías hablara con Princesita. Esta se puso muy contenta cuando vio a su amigo "Matiítas" y le dio un fuerte abrazo. Después, el Dragón Matías habló con ella:

- "Princesita, obligar al Rey Papá a que te compre cosas que no necesitas por medio de llantos, rabietas y enfados, no está bien. Tú sabes que él te quiere muchísimo y no puede verte sufrir, pero es malo para tu educación tener todo lo que quieras aunque no lo necesites"

Princesita se enfadó mucho al oír eso. No quería quedarse sin sus zapatos nuevos, así que empezó a regañar al Dragón Matías por decirle eso.

- "Además", dijo la Princesita, "Los necesitó."

El Dragón Matías la miró pensativo y dijo:

- "No, no los necesitas, pero te voy a dar una pequeña lección. A partir de ahora, tantos zapatos nuevos tendrás, tantos zapatos nuevos necesitarás".

La Princesita se enfado mucho con el Dragón Matías pero siguió con sus planes y obligó al Rey Papá, poniendo sobre la mesa la promesa que le había sacado el día anterior, que la llevara de compras a por los nuevos zapatos. Y se compró unos nuevo y muy caros.

A la mañana siguiente llegó la sorpresa. Cuando Princesita se levantó por la mañana se encontró que tenía cuatro piernas en lugar de tener dos como todas las niñas. Al principio se asustó, pero luego recordó las palabras del Dragón Matías y, en lugar de reflexionar sobre la situación, decidió retar al viejo dragón.

Se vistió con un vestido precioso y se puso cuatro zapatos. Dos en sus dos pies izquierdos y dos en sus dos pies derechos, y se fue a por el Rey Papá sonriendo y decidida a continuar demostrando al Rey Papá y al Dragón Matías quién es la que mandaba en esa situación.

- "Rey Papá, mira que bien me quedan los zapatos nuevos con mis nuevas piernas que tengo gracias al Dragón Matías. Lo que pasa es que ahora necesito quita-y-pon así que tenemos que ir a comprar ahora mismo dos pares de zapatos nuevos".

El Rey Papá no daba crédito a lo que veía, pero Princesita iba feliz con sus cuatro piernas y sus dos pares de zapatos puestos a la vez. Así que, después de superar el susto y de aguantar unos lloros, gritos y pataletas de Princesita, accedió a llevar la de compras a por dos nuevos pares de zapatos.

A la vuelta, el Dragón Matías esperaba al Rey Papá y Princesita. Cuando llegaron, la joven Princesita traía en las manos bolsas con las nuevas compras. Dos nuevos pares de zapatos recién comprados. Cuando llegó a la altura del Dragón Matías le enseñó presumidamente sus cuatro piernas con sus dos pares de zapatos puestos y las bolsas con los nuevos. El Dragón Matías sonrió y dijo:

- "Recuerda Princesita, tantos zapatos tendrás, tantos zapatos necesitarás".

Princesita puso sus zapatos nuevos en el guardarropa de su habitación, en el armario destinado para ellos, y se fue feliz a dormir con sus nuevas compras. Ir de compras le hacía muy feliz y ganar al Dragón Matías y salir con la suya más todavía.

Pero al día siguiente…

Princesita se despertó y se alarmó. Su cama estaba llena de piernas. Le habían crecido cuatro nuevas piernas por la noche y eso ya no le gustaba nada. Tenía ocho piernas y parecía una araña, y eso no le gustaba nada, así que, en pijama, se fue corriendo y llorando a ver al Rey Papá:

- "Papaete, papaete, tengo ocho piernas y parezco una araña.. . Buahhhh, Buahhh".

El Rey Papá esperaba en el salón junto a su amigo el Dragón Matías, que la miró con detenimiento y dijo:

- "Bueno, Princesita, ahora ya has visto lo malo que es hacer de un capricho una necesidad, ¿verdad? Dime una cosa, ¿prefieres tener dos piernas y necesitar solo un par de zapatos o tener cuatro pares de zapatos y necesitarlos todos?"

Princesita, llorando, dijo:

- "Buahh, Buahhh, prefiero tener dos piernas y necesitar solo un par de zapatos. Pero por favor, vuelve a hacer que sea una niña normal".

El Dragón Matías, sopló un humo desde dentro y bañó a Princesita en el calor de su aliento. Cuando el humo se fue, la niña volvió a ser una persona de solo dos piernas.

- "Vete a tu habitación, Princesita, y vístete para desayunar. Yo quiero hablar con el Rey Papá", dijo el Dragón Matías.

Princesita se fue feliz, y el Dragón Matías se quedó mirando seriamente al Rey Papá, para decirle:

- "¿Has visto Rey Papá lo que sucede si le das a una Princesita más de lo que necesita? Harás que su capricho se convierta en una necesidad y dejará de ser una niña normal. Y eso nunca la hará feliz, como has visto".

El Rey Papá se sintió fatal y se disculpó ante el Dragón Matías, por haber dejado que los caprichos de su hija dictaran sus acciones y por haber faltado a su cita del lago. Se abrazaron, y al día siguiente disfrutaron de una preciosa excursión.

Por otro lado, a partir de ese día, Princesita siempre pensó muy mucho que es lo que necesitaba realmente, no fuera a ser que le salieran cuatro brazos, dos bocas, os dos cabezas. ¿Quién se puede fiar de los caprichos?

Y colorín colorado… FIN.

Otros cuentos de mi boca:


Saludos Malignos!

Autor: Chema Alonso (Contactar con Chema Alonso)

Read more


  1. Hacking Pages
  2. Car Hacking
  3. Capture The Flag Hacking
  4. Rfid Hacking
  5. Hacking Kali Linux
  6. Hacking Meaning
  7. Kali Linux Hacking
  8. Herramientas De Seguridad Informatica
  9. Curso De Ciberseguridad Y Hacking Ético
  10. Hacking Y Seguridad
  11. Programa De Hacking
  12. Hacking Attacks
  13. Tecnicas De Ingenieria Social
  14. Hacking Youtube
  15. Hacking Marketing

Setting Up A Burp Development Environment

This quick blog post will document getting started with developing Burp extensions using java. Burp provides interfaces for developers to hook into the Burp application and extend the application or integrate with other tools, this interface is documented on the following site - http://portswigger.net/burp/extender/

For this guide you will need the following items:


After downloading and opening up Eclipse you will need to create a new java project. This can be done by clicking "File->New Java Project". Fill in a project name and click finish.

Once the project has been created you will need to create a new package called "burp". This can be done by right clicking the "src" folder under your new project and selecting "New->Package". When the dialog comes up set the "Name" as "burp":

You should now have a package named "burp" under the source folder in the right pane. Now you will need to import the Burp extender classes into your project. Download all of the extender classes to a local folder, once this is done right click on the "burp" package in your project and select "Import". On the dialog window that comes up select "General->File System" and hit "next":

On the next dialog you will need to navigate to where you downloaded the Burp extender classes to. Once you have done this you should see the classes, click on the folder to select all items and click "Finish":

Next we can add the Burp application into the project. To do this click on "Project->Properties" on the top toolbar. When the dialog opens select "Java Build Path" and then the "Libraries" tab. On this dialog click "Add External JARs..."
Navigate to where ever you have Burp downloaded to and select it. After you have done this click "OK" to dismiss the dialog. You are now ready to build your own Burp extensions. You can test your environment by creating a new class in the burp package named "BurpExtender". Right click the "burp" package and click "New->Class". On the dialog that comes up enter "BurpExtender" and click "Finish":

In the "BurpExtender" class you can enter the following:


package burp;


public class BurpExtender
{
    public void registerExtenderCallbacks(IBurpExtenderCallbacks callbacks)
    {
        callbacks.registerMenuItem("Hello World.", new CustomMenuItem());
    }
}


class CustomMenuItem implements IMenuItemHandler
{
    public void menuItemClicked(String menuItemCaption, IHttpRequestResponse[] messageInfo)
    {
        try
        {
            System.out.println("Hello From Burp!");
            System.out.println("Request Item Details");
            System.out.println("Host: " + messageInfo[0].getHost());
            System.out.println("URL: " + messageInfo[0].getUrl());


        }
        catch (Exception e)
        {
            e.printStackTrace();
        }
    }
}


After adding the content to your "BurpExtender" class you are ready to run the project for the first time. Click on "Run->Run" from the menu. You should see the following dialog asking how it should run your project:
Select "Java Application" and click "Ok". Next you should receive a dialog asking which application you want to run. Select "StartBurp - burp" and click "Ok":

You should now see the burp application running. Intercept a request in the application and right click on the request, you should now see an item in the menu named "Hello World."

When you click the "Hello World." menu button you should see some information about the request in your eclipse console window:

That's it, you now have setup your working development environment for building your own Burp extensions. The javadocs for the Burp Extender interfaces are available on the Extender web page:


Read more

Sharingan - Offensive Security Recon Tool


Sharingan is a recon multitool for offensive security / bug bounty
This is very much a work in progress and I'm relatively new to offensive security in general so if you see something that can be improved please open an issue or PR with suggested changes.

Cloning for development
Outside of your gopath git clone https://github.com/leobeosab/sharingan

Installing
go get github.com/leobeosab/sharingan/cmd/sharingancli

Dependencies
  • NMap
  • Go

Usage

Note
Order matters when it comes to flags it must be sharingancli [globalflags] command [commandflags] if this isn't a wanted feature I can change it but I like how clean it is

DNS

bruteforce
DNS busts the target with a wordlist you provide
sharingancli --target targetname dns --dns-wordlist ~/path/to/wordlist --root-domain target.com


addsubs
Adds subdomains to the program's storage from stdin using pipes
cat subs | sharingancli --target targetname dns addsubs

Scan
Scans all hosts available that were stored in target using nmap
sharingancli --target target scan


interactive
Scan a single host from list of subdomains stored in target
sharingancli --target target scan interactive


info

domains
Outputs all domains as a list in stdout
sharingancli --target target info domains


Features to come
  • Dir brute forcing -- Currently being worked on
  • JSON and regular file exports
  • Automated scans through a daemon?
  • add a way to do SYN / -sS scanning [ must be root so it presents a challenge ]
  • Possible Web ui / html export




via KitPloitRelated links

Monday, May 18, 2020

ADVANTAGE OF ETHICAL HACKING

Advantage of Ethical Hacking

Hacking is quite useful in the following purpose-

1-To recover lost information, especially in case you lost your password.

2-To perform penetration testing to strengthen computer and network security.

3-To put adequate preventative measure in place to prevent security breaches.

4-To have a computer system that prevents malicious hackers from gaining access.

5-Fighting against terrorism and national security breaches.


Related posts