إظهار الرسائل ذات التسميات windows hacking. إظهار كافة الرسائل
إظهار الرسائل ذات التسميات windows hacking. إظهار كافة الرسائل
الأربعاء، 23 مارس 2016
Badlock — Unpatched Windows-Samba Vulnerability Affects All Versions of Windows
Security researchers have discovered a nasty security vulnerability that is said to affect almost every version of Windows and Samba and will be patched on April 12, 2016, the Samba development team announced Tuesday.
So, Save the Date if you are a Windows or Samba file server administrator.
Samba is a free, open source implementation of the SMB/CIFS network file sharing protocol that
الثلاثاء، 13 أكتوبر 2015
Patch Report: All Versions of Windows affected by Critical Vulnerability
Microsoft has rolled out six security updates this Patch Tuesday, out of which three are considered to be "critical," while the rest are marked as "important."
Bulletin MS15-106 is considered to be critical for Internet Explorer (IE) and affects absolutely all versions of Windows operating system.
The update addresses a flaw in the way IE handles objects in memory. The flaw could be
الثلاثاء، 24 فبراير 2015
DAWS - Advanced Web Shell For Windows And Linux
DAWS - Advanced Web Shell For Windows And Linux
There's multiple things that makes DAws better than every Web Shell out there:
- Supports CGI by dropping Bash Shells (for Linux) and Batch Shells (for Windows).
- Bypasses WAFs, Disablers and Protection Systems; DAws isn't just about using a particular function to get the job done, it uses up to 6 functions if needed, for example, if shell_exec was disabled it would automatically use exec or passthru or system or popen or proc_open instead, same for Downloading a File from a Link, if Curl was disabled then file_get_content is used instead and this Feature is widely used in every section and fucntion of the shell. (Yes, it bypasses Suhosin too)
- Automatic Encoding; DAws randomly and automatically encodes most of your GET and POST data using XOR(Randomized key for every session) + Base64(We created our own Base64 encoding functions instead of using the PHP ones to bypass Disablers) which will allow your shell to Bypass pretty much every WAF out there.
- Advanced File Manager; DAws's File Manager contains everything a File Manager needs and even more but the main Feature is that everything is dynamically printed; the permissions of every File and Folder are checked, now, the functions that can be used will be available based on these permissions, this will save time and make life much easier.
- Tools: DAws holds bunch of useful tools such as "bpscan" which can identify useable and unblocked ports on the server within few minutes which can later on allow you to go for a bind shell for example.
- Everything that can't be used at all will be simply removed so Users do not have to waste their time. We're for example mentioning the execution of c++ scripts when there's no c++ compilers on the server(DAws would have checked for multiple compilers in the first place) in this case, the function would be automatically removed and the User would know.
- Supports Windows and Linux.
- Opened Source.
Extra Info
- Directory Romaing:
- DAws checks, within the `web` directory, for a Writable and Readable Directory which will then be used to Drop and Execute needed scripts which will guarantee their success.
- Eval Form:
- `include`, `include_once`, `require` or `require_once` are being used instead PHP `eval` to bypass Protection Systems.
- Download from Link - Methods:
- PHP Curl
- File_put_content
- Zip - Methods:
- Linux:
- Zip
- Windows:
- Vbs Script
- Shells and Tools:
- Extra:
- `nohup`, if installed, is automatically used for background processing.
Samba Service Hit By Remote Code Execution Vulnerability
A critical vulnerability has been fixed in Samba — Open Source standard Windows interoperability suite of programs for Linux and Unix, that could have allowed hackers to remotely execute an arbitrary code in the Samba daemon (smbd).
Samba is an open source implementation of the SMB/CIFS network file sharing protocol that works on the majority of operating systems available today, which
الأربعاء، 11 فبراير 2015
15-Year-Old JasBug Vulnerability Affects All Versions of Microsoft Windows
Microsoft just issued a critical patch to fix a 15-year-old vulnerability that could be exploited by hackers to remotely hijack users’ PCs running all supported versions of Windows operating system.
The critical vulnerability — named "JASBUG" by the researcher who reported the flaw — is due to a flaw in the fundamental design of Windows that took Microsoft more than 12 months to release a fix.
The critical vulnerability — named "JASBUG" by the researcher who reported the flaw — is due to a flaw in the fundamental design of Windows that took Microsoft more than 12 months to release a fix.
Labels:
hacking news,
JasBug Vulnerability,
Microsoft,
Microsoft Patch Update,
remote code execution,
Vulnerability,
windows hacking,
Windows Kernel,
windows updates
الجمعة، 28 فبراير 2014
How to Use Network Monitor (Netmon Tutorial)
Microsoft's Network Monitor is a tools that allow capturing and protocol analysis of network traffic. Network Monitor 3 is a protocol analyzer. It enables you to capture, to view, and to analyze network data. You can use it to help troubleshoot problems with applications on the network. This article contains download and support information, installation notes, and general usage information about Network Monitor 3. Network Monitor 3.4 is the latest version.
Network Monitor 3 is a complete overhaul of the earlier Network Monitor 2.x version. Some key features of Network Monitor 3 include the following:
- Script-based parser model with frequent updates
- Concurrent live capture sessions
- Support for Windows 7
- Support for 32-bit platforms and for 64-bit platforms
- Support for network conversations and process tracking
- API to access capture and parsing engine
- Wireless Monitor Mode Capturing
Supported Operating System ::
Windows 7, Windows 8, Windows Server 2003 Service Pack 2, Windows Server 2003 Service Pack 2 x64 Edition, Windows Server 2008, Windows Server 2008 R2, Windows Server 2008 R2 for Itanium-based Systems, Windows Server 2012, Windows Vista 64-bit Editions Service Pack 1, Windows Vista Service Pack 1, Windows XP 64-bit, Windows XP Service Pack 3
- Hardware ::
- 1 GHz or greater CPU
- 1 GB or greater memory
- 60 MB free hard disk space plus extra room for capture files
Tutorials ::
Installation Instruction ::
The Network Monitor core engine has been decoupled from the parser set. To install the full Network Monitor 3.4 product:
- Run the setup.exe for the platform you are installing.
- You will be prompted first to install the core engine. Follow the installation directions. Make sure you close existing instances of netmon.exe, nmcap.exe and any running NMAPI applications.
- Next you will be prompted to install the parser package. Follow the installation directions:
To uninstall the full Network Monitor 3.4 product ::
- Go to Add/Remove Programs in Control Panel
- Uninstall both Microsoft Network Monitor 3.4 and Microsoft Network Monitor: Network Monitor Parsers 3.4
Network Monitor Blog :: Click Here
Video Tutorial :: Click Here
Download ::
Windows :: Network Monitor 3.4 (x86) | Network Monitor (x64)
Official Website :: http://www.microsoft.com/en-us/download/details.aspx?id=4865
الجمعة، 21 فبراير 2014
الأربعاء، 15 يناير 2014
Malaysian Security Researcher Found XSS Vulnerability In Google
How much Google is secure we will tell you today, One Malaysian security researcher named Ahmad Ashraff talk to us and shared tutorial with us that, how he found XSS Vulnerability in Google and Youtube.
"On 9th January 2014, posted below image on twitter
https://twitter.com/yappare/status/421470672330571777/photo/1
So is this post related to that? Will get to it soon or probably next month.haha..
In this post I'm going to share to you a bug that manage me to be inside Google Vulnerability Reward Program G+ Community here
The bug is a Self Stored XSS in Youtube.
Let us see how the XSS exist.
In Youtube video manager, there's a function for a user to create Captions for his/her video(s).
Put our XSS payload in the script box and save.
Once we play the video, our XSS will be executed.
Check on below screenshots :)
But..there's a problem! The XSS only executing in Caption's Video Manager. Which in other word the XSS is only stored for that user only.
Hmmm...
There's must be a way to exploit or to manipulate this vulnerability. Last time I managed to find a way to Yaying this Nay in Google Adwords. You guys can check on it http://c0rni3sm.blogspot.com/2013/12/google-adwords-stored-xss-from-nay-to.html
I browsed a few times to see is there any share or embed function in this Captions thing. And then.
I noticed that, there's a function where a user can request for a translation from 3rd party or other users. So how this function working?
User request for his/her video for a translation.
User able to choose either from 3rd party or by other Google Users.
Manipulating time.Let assume that, there's a community for English series, Movies, Korean dramas that have some translator for Youtube's caption..and among them, there's an attacker >: )
Attacker will received the invitation.
Attacker put his/her evil code in the middle of translations.
Send to the requester for approval.
Once done, the requester will get an email notification and what she/he need to do is review the translated caption and approve it. So what happen next? The XSS will be executed
03 December 2013 - Reported via VRP form
07 December 2013 - Received a reply from Martin,Google Security Team
07 December 2013 - Google Team asked for more information to reproduce
08-10 December 2013 - Fixed around these dates.
11 December 2013 - Received a reward email from Google
10 January 2014 - Kevin,Google Security Team confirmed the fix. "
"On 9th January 2014, posted below image on twitter
https://twitter.com/yappare/status/421470672330571777/photo/1
So is this post related to that? Will get to it soon or probably next month.haha..
In this post I'm going to share to you a bug that manage me to be inside Google Vulnerability Reward Program G+ Community here
The bug is a Self Stored XSS in Youtube.
Let us see how the XSS exist.
In Youtube video manager, there's a function for a user to create Captions for his/her video(s).
Put our XSS payload in the script box and save.
Once we play the video, our XSS will be executed.
Check on below screenshots :)
But..there's a problem! The XSS only executing in Caption's Video Manager. Which in other word the XSS is only stored for that user only.
Hmmm...
There's must be a way to exploit or to manipulate this vulnerability. Last time I managed to find a way to Yaying this Nay in Google Adwords. You guys can check on it http://c0rni3sm.blogspot.com/2013/12/google-adwords-stored-xss-from-nay-to.html
I browsed a few times to see is there any share or embed function in this Captions thing. And then.
I noticed that, there's a function where a user can request for a translation from 3rd party or other users. So how this function working?
User request for his/her video for a translation.
User able to choose either from 3rd party or by other Google Users.
Manipulating time.Let assume that, there's a community for English series, Movies, Korean dramas that have some translator for Youtube's caption..and among them, there's an attacker >: )
Attacker will received the invitation.
Attacker put his/her evil code in the middle of translations.
Send to the requester for approval.
Once done, the requester will get an email notification and what she/he need to do is review the translated caption and approve it. So what happen next? The XSS will be executed
03 December 2013 - Reported via VRP form
07 December 2013 - Received a reply from Martin,Google Security Team
07 December 2013 - Google Team asked for more information to reproduce
08-10 December 2013 - Fixed around these dates.
11 December 2013 - Received a reward email from Google
10 January 2014 - Kevin,Google Security Team confirmed the fix. "
About The Author:
Ahmad Ashraff, he is cyber security researcher and working with IT sec Community.
الجمعة، 10 يناير 2014
Windows 8 Forensics Analysis Database [Tutorial]
Windows 8, latest version of Microsoft Windows operating systems, is set to be released to the general public on October 26, 2012. Which was intended to be a more focused, incremental upgrade to the Windows line, Windows 8 is an operating system "reimagined from the chipset to the user experience" according to the Windows Design Team. Windows 8 features a new user interface based on Microsoft's Metro design language, very similar to features found in the current Windows Phone operating system (commonly referred to as Windows Mobile). The new metro-style interface is designed to better suit touch screen and pen input, along with traditional mouse and keyboard input.
As is the case with any newly released operating system, new forensic changes and challenges arise. As digital forensic investigators it is important to address these new changes and challenges with diligence and understanding. Just like older versions of Windows, Windows 8 contains valuable bits of information known as “artifacts.” The average user is mostly unaware that the operating system is leaving traces of their activity behind that is specific to their usage. Knowing where these artifacts are stored can greatly assist in recreating a particular user account’s history. With that said, it may be a relief to many investigators out there that Windows 8 retained many of the key artifacts that were present in earlier Windows operating system builds. However, the immersive experience of Windows 8 also leans itself to artifacts nonexistent in previous releases. This article will focus on artifacts exclusive to Windows 8, including registry differences and artifacts of the new Metro User Interface and Immersive Web Browser.
In this article will introduce the Microsoft Windows 8 forensic analysis database.
Microsoft windows 8 introduced the application data or you can called AppData. That folder allowed for forensic investigators to to see that information belonged to the OS and that information belonged to a specific user. The location of Windows 8 AppData is in the C:\Users folder, the same place as in Microsoft windows 7.If you cannot see the AppData folder it could be because it's hidden from view.
Metro App Cache
%Root%\Users\%User%\AppData\Local\Packages\
%MetroAppName%\AC\INetCache
Contains Web cache specific to each Metro App.
%Root%\Users\%User%\AppData\Local\Packages\
%MetroAppName%\AC\INetCache
Contains Web cache specific to each Metro App.
Metro App Cookies
%Root%\Users\%User%\AppData\Local\Packages\
%MetroAppName%\AC\INetCookies
Contains cookie files specific to each Metro App. Data is contained in a text file.
%Root%\Users\%User%\AppData\Local\Packages\
%MetroAppName%\AC\INetCookies
Contains cookie files specific to each Metro App. Data is contained in a text file.
Metro App History
%Root%\Users\%User%\AppData\Local\Packages\
%MetroAppName%\AC\INetHistory
Contains Internet history files specific to each Metro App and the format of the data is consistent with previous versions.
%Root%\Users\%User%\AppData\Local\Packages\
%MetroAppName%\AC\INetHistory
Contains Internet history files specific to each Metro App and the format of the data is consistent with previous versions.
All these folders are named INetCache, INetCookies, and InetHistory contain a wealth of information and artifacts that may be of importance to the forensic investigators.
Here one example about how you can extract history from metro app for this demo i m using Google search.
Google search Metro App History
%Root%\Users\%User%\AppData\Local\Packages\GoogleInc.GoogleSearch_yfg5n0ztvskxp\LocalState
Now you can see file called history.json open with hex editors
IE 10 Web sites Visited (Immersive Interface)
%Root%\Users\%User%\AppData\Local\Microsoft\InternetExplorer\Recovery\Immersive\Active
Internet History
Communication App Artifacts
Windows 8 is virtually connected to everything; wherever you sign in, it’s connected. E-mail is connected to Facebook, Facebook is connected to the photo album, and the photo album is connected to the Microsoft account, which allows the user the ability to transfer many of the settings of the UI and immersive browser from PC to PC. The operating system is built around the premise of the recent social media revolution, with many of the newer features focused around such communication. The Communications App, as coined by Microsoft, includes the user’s e-mail, chat clients such as Windows Live and AIM, Facebook, and other social networking sites (e.g. Twitter). Anything that can allow the user to interact with another person appears to fall under “Communications Apps.” Each communication app has its own Web cache.
Communication App Web Cache
%Root%\Users\%User%\AppData\Local\Packages\microsoft.windowscommunicatisapps_8wekyb3d8bbwe\AC\INetCache
%Root%\Users\%User%\AppData\Local\Packages\microsoft.windowscommunicatisapps_8wekyb3d8bbwe\AC\INetCookies
Communications Apps offline email and Contacts from
%Root%\Users\%User%\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\de425268464fa2fe\120712-0049
Windows 8 Registry
Registry is a tool intended for advanced users. It's used to view and change settings in the system registry, which contains information about how your computer runs. Windows refers to this information and updates it when you make changes to your computer, such as installing a new program, creating a user profile, or adding new hardware. Registry Editor lets you view registry folders, files, and the settings for each registry file.
Mounted USB Devices
HKLM\SYSTEM\CurrentControlSet\Enum\USB\
Conclusion
In this article, we’ve seen that, when conducting a windows 8 forensic . The goal of this articles teach you about windows 8 forensic is to do a structured investigation and find out exactly what happened in a digital system and who was responsible for it. There is still a lot of research that must be done in order to improve windows 8 forensic that we going to cover in my upcoming articles.
About The Author:
Nikhaleshsingh bhadoria. He is Cyber Security Expert, Ethical Hacker, Penetration Tester and tech geek.
الجمعة، 25 أكتوبر 2013
How to Hack Windows in 5 minutes
Security: Methods to explore Windows 8 and windows 7.
By Rafael Fontes (Backtrack Team).
ABSTRACT
Readers, this article everybody would be going to understand techniques to exploit the operating system Microsoft Windows 8 (only for teaching purposes, for network administrators and security specialists understand how the mind works and to prevent the attacker). Through the Metasploit will learn how to hack some machines with Windows OS vulnerable, Windows 7 SP1 other OS is also applicable.
INTRODUCTION
This exploit works "using Java Signed Applet Method" on any browser, but requires the java plugin installed, a file is created. "Jar", it is necessary that the target open a URL and allow the java applet to run in the browser. The applet is presented to the target through a web page. The Java Virtual Machine, of the victim will pop up a window asking if they trust the signed applet, after the victim clicks on "run" the applet is run with full permissions.
STEP BY STEP
Requirements for pentest:
I. You must have installed the Windows 8 operating system.
II. Some target computer or VMware (Virtual Machine) with a Linux distribution, can be Backtrack or Kali, whatever, the important thing is to have the “metasploit” up and running.
First reader, you need to open the terminal and enter the command:
"msfconsole".
Figure 1) Open metasploit.
After, we choose the exploit to use:
Let’s type use exploit/multi/browser/java_signed_applet .
Press enter and type “Show options”.
Figure 2) Use exploit and show options.
Essential concepts:
The SRVHOST and SRVPORT have defined default values 0.0.0.0 and 8080. The SRVHOST is the IP address that the server will work to make the connection url to be opened by the target browser. SRVHOST is set to 0.0.0.0, the target must be able to connect to this machine using your public ip.
Figure 3) Set payload.
The LHOST should be the IP address that the victim is connected.
Figure 4) LHOST and exploit.
When the target open this link on your browser displays a warning in a dialog box .
A window will open, and the victim can check the "I accept the risk and want to run this application", click "Run".
Figure 5) Java applet.
FINISHING
Therefore, after the victim open the malicious URL, then click Run, Metasploit will start a meterpreter session to the target machine, and you get full access!
You can directly run "sessions l" to see the active sessions.
Example: sessions-i 1, where 1 is the ID of the session.
The applet is able to connect to Metasploit.
Meterpreter session starts and is ready, as planned, and available options for you to exploit the system.
Figure 6) Session starts.
This article is only for ethical hacking, now you can have fun with the commands.
Figure 7) Webcam shot: Just 4 fun.
الثلاثاء، 1 أكتوبر 2013
How To Hack Same LAN Computers
How To Hack Same LAN Computers?
If you are working in Office / Colleges and want to hack your friends & college mate PC then here is a trick follow below steps:
Go to Run> Cmd
now type command
C:\>net view
Server Name Remark
-----------------------------------------------
\\xyz
\\abc
Here you can get all the names of all the computers machine names which connect with your LAN.
Now you got the name. Lets start hacking into the systems.
After you get server name now type tracert command for knowing IP of the victim machine.
Example: C:\> tracert xyz
Here you get the IP address of the XYZ computer machine.
now go to windows start button and type Remote Desktop Connection
After click on Remote Desktop Connection you get below..
If you are working in Office / Colleges and want to hack your friends & college mate PC then here is a trick follow below steps:
Go to Run> Cmd
now type command
C:\>net view
Server Name Remark
-----------------------------------------------
\\xyz
\\abc
Here you can get all the names of all the computers machine names which connect with your LAN.
Now you got the name. Lets start hacking into the systems.
After you get server name now type tracert command for knowing IP of the victim machine.
Example: C:\> tracert xyz
Here you get the IP address of the XYZ computer machine.
now go to windows start button and type Remote Desktop Connection
After click on Remote Desktop Connection you get below..
Now type the IP address or computer name of victim machine.
Click on connect <-|
It will also ask administrator password which is common as usual you known about.
After few second Victim machine shown in your Computer..
Now you can access that machine to open website, files, Software's, etc
Enjoy the trick..
الاشتراك في:
الرسائل (Atom)















.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)








