sexta-feira, 26 de maio de 2023

Emulating Shellcodes - Chapter 2

 Lets check different  Cobalt Strike shellcodes and stages in the shellcodes emulator SCEMU.




This stages are fully emulated well and can get the IOC and the behavior of the shellcode.

But lets see another first stage big shellcode with c runtime embedded in a second stage.


In this case is loading tons of API using GetProcAddress at the beginning, then some encode/decode pointer and tls get/set values to store an address. And ends up crashing because is jumping an address that seems more code than address 0x9090f1eb.

Here there are two types of allocations:


Lets spawn a console on -c 3307548 and see if some of this allocations has the next stage.

The "m" command show all the memory maps but the "ma" show only the allocations done by the shellcode.



Dumping memory with "md" we see that there is data, and dissasembling this address with "d" we see the prolog of a function.

So we have second stage unpacked in alloc_e40064


With "mdd" we do a memory dump to disk we found the size in previous screenshot,  and we can do  some static reversing of stage2 in radare/ghidra/ida

In radare we can verify that the extracted is the next stage:


I usually do correlation between the emulation and ghidra, to understand the algorithms.

If wee look further we can realize that the emulator called a function on the stage2, we can see the change of code base address and  is calling the allocated buffer in 0x4f...



And this  stage2 perform several API calls let's check it in ghidra.


We can see in the emulator that enters in the IF block, and what are the (*DAT_...)() calls

Before a crash lets continue to the SEH pointer, in this case is the way, and the exception routine checks IsDebuggerPresent() which is not any debugger pressent for sure, so eax = 0;



So lets say yes and continue the emulation.


Both IsDebuggerPresent() and UnHandledExceptionFilter() can be used to detect a debugger, but the emulator return what has to return to not be detected. 

Nevertheless the shellcode detects something and terminates the process.

Lets trace the branches to understand the logic:


target/release/scemu -f shellcodes/unsuported_cs.bin -vv | egrep '(\*\*|j|cmp|test)'



Continuing the emulation it's setting the SEH  pointer to previous stage:


Lets see from the console where is pointing the SEH chain item:


to be continued ...


https://github.com/sha0coder/scemu






Related articles


  1. Physical Pentest Tools
  2. Hacking Tools Name
  3. Hacker Tools For Pc
  4. How To Install Pentest Tools In Ubuntu
  5. Hack Tools For Mac
  6. Hacker Tool Kit
  7. Hacker Techniques Tools And Incident Handling
  8. Hacking Tools Software
  9. Hacking Tools Online
  10. World No 1 Hacker Software
  11. Tools Used For Hacking
  12. Hacker Tool Kit
  13. Pentest Tools
  14. Nsa Hack Tools
  15. Hacking Tools For Windows Free Download
  16. Hacker Tools Windows
  17. Hacking Tools For Games
  18. Hacking Tools
  19. Nsa Hack Tools
  20. What Is Hacking Tools
  21. Hacking Tools Kit
  22. Pentest Tools Review
  23. Beginner Hacker Tools
  24. Hack Tools Mac
  25. Pentest Box Tools Download
  26. Hacking Tools For Kali Linux
  27. Hack Tools Mac
  28. Hacker Techniques Tools And Incident Handling
  29. Hacking Tools For Mac
  30. Hack Tools Pc
  31. Hacker Tool Kit
  32. Hack Rom Tools
  33. Hacker Hardware Tools
  34. Hacking Tools For Pc
  35. Hacking Tools For Pc
  36. Hacking Tools Hardware
  37. Pentest Tools Url Fuzzer
  38. Hack App
  39. Hacker Tools 2019
  40. Pentest Tools For Mac
  41. Hacker Tools For Pc
  42. Hack Tools Online
  43. Hacker Tools For Pc
  44. Hack Tools Online
  45. World No 1 Hacker Software
  46. Pentest Tools
  47. Hack Tools For Windows
  48. Hacker Search Tools
  49. Hacking Tools Windows 10
  50. Hacking Tools Free Download
  51. Tools 4 Hack
  52. Android Hack Tools Github
  53. Hacker Tools For Ios
  54. Hack Website Online Tool
  55. Pentest Tools
  56. Pentest Automation Tools
  57. Hacker Hardware Tools
  58. Hacking Tools Windows 10
  59. Pentest Tools For Mac
  60. Hacking Tools Windows
  61. Pentest Tools Find Subdomains
  62. Hacking Tools 2019
  63. Hack And Tools
  64. Hack Rom Tools
  65. Hacker Tools Free Download
  66. Pentest Tools Find Subdomains
  67. Pentest Tools Github
  68. Hack Tools
  69. Wifi Hacker Tools For Windows
  70. Pentest Tools Review
  71. Hacker Tools Windows
  72. Hacker Hardware Tools
  73. Hacking Tools Usb
  74. Pentest Tools List
  75. Wifi Hacker Tools For Windows
  76. Install Pentest Tools Ubuntu
  77. Tools For Hacker
  78. Nsa Hacker Tools
  79. Hack Tools Pc
  80. Pentest Tools Url Fuzzer
  81. Hack Rom Tools
  82. Tools 4 Hack
  83. Hacker Hardware Tools
  84. Tools For Hacker
  85. Hacker Tools List
  86. Hack Tools Download
  87. Hacking Tools Online
  88. Wifi Hacker Tools For Windows
  89. Blackhat Hacker Tools
  90. Best Pentesting Tools 2018
  91. Hacking Tools For Beginners
  92. Hacker Tools 2020
  93. Hacker Tools For Pc
  94. Hacking Tools And Software
  95. Install Pentest Tools Ubuntu
  96. How To Hack
  97. Hacking Tools For Windows
  98. Hack Tool Apk
  99. Hacking Tools Kit
  100. Hack Rom Tools
  101. Hacking Tools Usb
  102. Pentest Tools For Ubuntu
  103. Hacking Tools Windows 10
  104. Hack Tools For Windows
  105. Hackers Toolbox
  106. Hack Tools 2019
  107. Hack Tool Apk
  108. How To Hack
  109. Pentest Tools List
  110. Hacking Tools Online
  111. Hacking Tools For Kali Linux
  112. Hackers Toolbox
  113. Hack Tools For Pc
  114. Hackers Toolbox
  115. Nsa Hacker Tools
  116. Android Hack Tools Github
  117. Hack Tools Pc
  118. Computer Hacker
  119. Hacking Tools Mac
  120. Termux Hacking Tools 2019
  121. Blackhat Hacker Tools
  122. Github Hacking Tools
  123. Hacker Tools Software
  124. Pentest Tools Review
  125. Pentest Tools Github
  126. Hacking Tools Free Download
  127. Pentest Tools Nmap
  128. Hacking Tools Windows 10
  129. Hack Website Online Tool
  130. Hacking Tools Kit
  131. Hacker Tools For Ios
  132. Hacker Tools Free
  133. Pentest Tools List
  134. Best Hacking Tools 2020
  135. Pentest Tools Kali Linux
  136. Hacking Tools Kit
  137. Pentest Tools List
  138. Free Pentest Tools For Windows
  139. Pentest Tools Apk
  140. Hacker Tools Hardware
  141. Hack Website Online Tool
  142. What Are Hacking Tools
  143. Best Hacking Tools 2019
  144. Pentest Tools List
  145. Hacker Tools Github
  146. Hack Tools For Ubuntu
  147. Usb Pentest Tools
  148. Pentest Tools Framework
  149. Ethical Hacker Tools
  150. Hacker Tools
  151. Hacker Tools For Pc
  152. Hack Website Online Tool
  153. Game Hacking
  154. Hacker Tools
  155. Pentest Box Tools Download
  156. Hack Tools Mac
  157. Pentest Tools Subdomain
  158. Tools For Hacker
  159. Hack Tool Apk No Root
  160. Bluetooth Hacking Tools Kali
  161. Hacker Tools Hardware
  162. Pentest Tools Bluekeep

Mythbusters: Is An Open (Unencrypted) WiFi More Dangerous Than A WPA2-PSK? Actually, It Is Not.

Introduction


Whenever security professionals recommend the 5 most important IT security practices to average users, one of the items is usually something like: "Avoid using open Wifi" or "Always use VPN while using open WiFi" or "Avoid sensitive websites (e.g. online banking) while using open WiFI", etc.

What I think about this? It is bullshit. But let's not jump to the conclusions. Let's analyze all risks and factors here.


During the following analysis, I made two assumptions. The first one is that we are comparing public WiFi hotspots with no encryption at all (referred to as Open), and we compare this to public WiFi hotspots with WPA2-PSK (and just hope WEP died years before). The other assumption is there are people who are security-aware, and those who just don't care. They just want to browse the web, access Facebook, write e-mails, etc.

The risks


Let's discuss the different threats people face using public hotspots, compared to home/work internet usage:
1. Where the website session data is not protected with SSL/TLS (and the cookie is not protected with secure flag), attackers on the same hotspot can obtain the session data and use it in session/login credentials stealing. Typical protocols affected:

  • HTTP sites
  • HTTPS sites but unsecured cookie
  • FTP without encryption
  • IMAP/SMTP/POP3 without SSL/TLS or STARTTLS

2. Attackers can inject extra data into the HTTP traffic, which can be used for exploits, or social engineer attacks (e.g. update Flash player with our malware) – see the Dark Hotel campaign

3. Attackers can use tools like SSLStrip to keep the user's traffic on clear text HTTP and steal password/session data/personal information

4. Attackers can monitor and track user activity

5. Attackers can directly attack the user's machine (e.g. SMB service)

WPA2-PSK security


So, why is a public WPA2-PSK WiFi safer than an open WiFi? Spoiler alert: it is not!

In a generic public WPA2-PSK scenario, all users share the same password. And guess what, the whole traffic can be decrypted with the following information: SSID + shared password + information from the 4-way handshake. https://wiki.wireshark.org/HowToDecrypt802.11
If you want to see it in action, here is a nice tutorial for you
Decrypted WPA2-PSK traffic

Any user having access to the same WPA2-PSK network knows this information. So they can instantly decrypt your traffic. Or the attackers can just set up an access point with the same SSID, same password, and stronger signal. And now, the attacker can instantly launch active man-in-the-middle attacks. It is a common belief (even among ITSEC experts) that WPA2-PSK is not vulnerable to this attack. I am not sure why this vulnerability was left in the protocol, if you have the answer, let me know. Edit (2015-08-03): I think the key message here is that without server authentication (e.g. via PKI), it is not possible to solve this.
Let me link here one of my previous posts here with a great skiddie tool:

To sum up, attackers on a WPA2-PSK network can:

  • Decrypt all HTTP/FTP/IMAP/SMTP/POP3 passwords or other sensitive information
  • Can launch active attacks like SSLStrip, or modify HTTP traffic to include exploit/social engineer attacks
  • Can monitor/track user activity

The only difference between open and WPA2-PSK networks is that an open network can be hacked with an attacker of the skill level of 1 from 10, while the WPA2-PSK network needs and an attacker with a skill level of 1.5. That is the difference.

The real solutions



1. Website owners, service providers should deploy proper (trusted) SSL/TLS infrastructure, protect session cookies, etc. Whenever a user (or security professional) notices a problem with the quality of the service (e.g. missing SSL/TLS), the service provider has to be notified. If no change is made, it is recommended to drop the service provider and choose a more secure one. Users have to use HTTPS Everywhere plugin.

2. Protect the device against exploits by patching the software on it, use a secure browser (Chrome, IE11 + enhanced protection), disable unnecessary plugins (Java, Flash, Silverlight), or at least use it via click-to-play. Also, the use of exploit mitigations tools (EMET, HitmanPro Alert, Malwarebytes AntiExploit) and a good internet security suite is a good idea.

3. Website owners have to deploy HSTS, and optionally include their site in an HSTS preload list

4. Don't click blindly on fake downloads (like fake Flash Player updates)


5. The benefits of a VPN is usually overestimated. A VPN provider is just another provider, like the hotspot provider, or the ISP. They can do the same malicious stuff (traffic injecting, traffic monitoring, user tracking). Especially when people use free VPNs. And "Average Joe" will choose a free VPN. Also, VPN connections tend to be disconnected, and almost none of the VPN providers provide fail secure VPNs. Also, for the price of a good VPN service you can buy a good data plan and use 4G/3G instead of low-quality public hotspots. But besides this, on mobile OSes (Android, iOS, etc.) I strongly recommend the use of VPN, because it is not practically feasible to know for users which app is using SSL/TLS and which is not.

6. Use a location-aware firewall, and whenever the network is not trusted, set it to a Public.

7. In a small-business/home environment, buy a WiFi router with guest WiFi access possibility, where the different passwords can be set to guest networks than used for the other.

Asking the question "Are you using open WiFi?", or "Do you do online banking on open WiFi?" are the wrong questions. The good questions are:
  • Do you trust the operator(s) of the network you are using?
  • Are the clients separated?
  • If clients are not separated, is it possible that there are people with malicious intent on the network?
  • Are you security-aware, and are you following the rules previously mentioned? If you do follow these rules, those will protect you on whatever network you are.

And call me an idiot, but I do online banking, e-shopping, and all the other sensitive stuff while I'm using open WiFi. And whenever I order pizza from an HTTP website, attackers can learn my address. Which is already in the phone book, on Facebook, and in every photo metadata I took with my smartphone about my cat and uploaded to the Internet (http://iknowwhereyourcatlives.com/).


Most articles and research publications are full of FUD about what people can learn from others. Maybe they are just outdated, maybe they are not. But it is totally safe to use Gmail on an open WiFi, no one will be able to read my e-mails.

PS: I know "Average Joe" won't find my blog post, won't start to read it, won't understand half I wrote. But even if they do, they won't patch their browser plugins, pay for a VPN, or check the session cookie. So they are doomed to fail. That's life. Deal with it.

Related articles


quinta-feira, 25 de maio de 2023

OWASP ZAP RELEASES V2.8.0 WITH THE HEADS UP DISPLAY

OWASP ZAP RELEASES V2.8.0 WITH THE HEADS UP DISPLAY
Heads Up Display simplifies and improves vulnerability testing for developers

London, England, 20 June 2019. OWASP™ ZAP (Open Web Application Security Project™  Zed Attack Proxy) has released a new version of its leading ZAP Project which now includes an innovative Heads Up Display (HUD) bringing security information and functionality right into the browser. Now software developers can interactively test the reliability and security of their applications in real time while controlling a wide variety of features designed to test the quality of their software.

ZAP is a free, easy to use integrated penetration testing tool. With the addition of the Heads Up Display, ZAP can be used by security professionals and developers of all skill levels to quickly and more easily find security vulnerabilities in their applications. Given the unique and integrated design of the Heads Up Display, developers and functional testers who might be new to security testing will find ZAP an indispensable tool to build secure software.

The latest version of ZAP can be downloaded from https://www.owasp.org/index.php/ZAP  The full release notes are available at https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0.

In addition to being the most popular free and open source security tools available, ZAP is also one of the most active with hundreds of volunteers around the globe continually improving and enhancing its features. ZAP provides automated scanners as well as a set of tools that allows new users and security professionals to manually identify security vulnerabilities. ZAP has also been translated into over 25 languages including French, Italian, Dutch, Turkish and Chinese. 

Simon Bennetts, OWASP ZAP Project Leader commented: "This is a really important release for the project team and developers who want to build great and secure applications. The HUD is a completely new interface for ZAP and one that is unique in the industry. It shows that open source projects continue to create high-quality, new and exciting tools that deliver real value to the market - and at no cost to users." 

"ZAP is the Foundation's most popular software tool," said Mike McCamon interim executive director of the OWASP Foundation. McCamon continued, "For nearly two decades OWASP continues to be a great destination for innovators to host, develop, and release software that will secure the web. Simon and the entire ZAP community deserves great recognition for their continued devotion to open source excellence."

For further information please contact:
Simon Bennetts, OWASP ZAP Project Leader: simon.bennetts@owasp.org  or Mike McCamon, Interim Executive Director, mike.mccamon@owasp.com

More articles


1/700 HMS Hood

 

The 1/700 WW2 Project rolls on and while I've been concentrating on the easier to game with Destroyers, I have had this monster being worked on in the background.


The ship is a Tamiya kit and is based on a 420 x 100 base. I haven't used any fancy photo etch extras or additional wooden decking, I've just painted and weathered the basic kit.


It even looks pretty good in black and white !


I've done very limited amounts of weathering on the ship as it was pretty pristine when it set off on its final journey, I would like to give a special shout out to the HMS Hood Association website which has loads of details on colour schemes for the ship



I've added a small spar to the rear of the rear mast and run a rigging line down from it for the Ensign, the flag just won't face backward and just seems to have a mind of its own !


I've said it before and will reiterate it here, I am having so much fun with this Project, maybe I needed a break from constant figure painting but I have found myself going back to the ships time and time again.


I've got a pair of O Class Destroyers already finished and will be working on a couple of German Destroyers next, as well as making a start on the Bismark.

quarta-feira, 23 de setembro de 2020

The Taiwanese Connection - The Source For Many Unlicensed NES/Famicom Games

Joy Van - Twin Eagle
AVE - Double Strike

















Taiwan was called one of the four Asian Tigers (with Singapore, South Korea and Hong Kong), small countries which had developed economically very rapidly after from the 1960s to the present to compete with much larger countries.  Taiwan embraced technology, creating chip fabrication plants and becoming indispensable to the PC revolution.  Video game consoles were hardly overlooked by the island, and Nintendo was the largest publisher of console video games in Asia.  There was no protection system in place for the Nintendo Famicom, so Taiwan programming firms began developing unlicensed games for that console around 1986.

At the same time, Nintendo was becoming the largest publisher of video games in North America thanks to the success of the NES.  Third parties were naturally attracted to the increasingly successful system, but Nintendo was a hard business partner.  Nintendo required companies to buy cartridges manufactured by Nintendo, required cartridge orders in large unit quantities, limited the number of cartridges a company could release in a year and scrutinized the content of the games to be published.  After Tengen showed that it was possible to develop and release cartridges without Nintendo's sanction, other companies like AVE and Color Dreams entered the market as unlicensed publishers.  But they needed games to sell and the number of programmers who could handle Nintendo's console were limited, so sometimes they turned to Taiwan.

Read more »

Quando eu te falei em amor

Quando os meus olhos te tocaram
Eu senti que encontrara
A outra, metade de mim
Tive medo de acordar
Como se vivesse um sonho
Que não pensei em realizar
E a força do desejo
Faz me chegar perto de ti

Quando eu te falei em amor
Tu sorriste para mim
E o mundo ficou bem melhor
Quando eu te falei em amor
Nos sentimos os dois
Que o amanha vem depois
E não no fim

Estas linhas que hoje escrevo
São do livro da memória
Do que eu sinto por ti
E tudo o que tu me das
É parte da história que eu ainda não vivi
E a força do desejo
Faz me chegar de ti

Quando eu te falei em amor
Tu sorriste para mim
E o mundo ficou bem melhor
Quando eu te falei em amor
Nos sentimos os dois
Que o amanha vem depois e não no fim

André Sardet

Collide

The dawn is breaking
A light shining through
You're barely waking
And I'm tangled up in you
Yeah

But I'm open, you're closed
Where I follow, you'll go
I worry I won't see your face
Light up again

Even the best fall down sometimes
Even the wrong words seem to rhyme
Out of the doubt that fills my mind
I somehow find, you and I collide

I'm quiet, you know
You make a first impression
I've found I'm scared to know
I'm always on your mind

Even the best fall down sometimes
Even the stars refuse to shine
Out of the back you fall in time
I somehow find, you and I collide

Don't stop here
I've lost my place
I'm close behind

Even the best fall down sometimes
Even the wrong words seem to rhyme
Out of the doubt that fills your mind

You finally find, you and I collide
You finally find You and I collide
You finally findYou and I collide

Howie Day


Everything

You're a falling star, You're the get away
car.

You're the line in the sand when I go too
far.

You're the swimming pool, on an August day.
And You're the perfect thing to see.

And you play it coy, but it's kinda cute.
Ah, When you smile at me you know exactly what you
do.

Baby don't pretend, that you don't know it's
true.

Cause you can see it when I look at you.

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing.
You're every line, you're every word, you're
everything.


You're a carousel, you're a wishing well,
And you light me up, when you ring my bell.
You're a mystery, you're from outer space,
You're every minute of my everyday.

And I can't believe, uh that I'm your man,
And I get to kiss you baby just because I
can.

Whatever comes our way, ah we'll see it
through,

And you know that's what our love can do.

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing
You're every line, you're every word, you're
everything.


So, La, La, La, La, La, La, La
So, La, La, La, La, La, La, La

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing.
You're every line, you're every word, you're
everything.

You're every song, and I sing along.
Cause you're my everything.
yeah, yeah

So, La, La, La, La, La, La, La
So, La, La, La, La, La, La, La

Michael Bublé