Senin, 31 Agustus 2020

RapidScan: The Multi-Tool Website Vulnerabilities Scanner With Artificial Intelligence

RapidScan's Features:
  • One-step installation.
  • Executes a multitude of security scanning tools, does other custom coded checks and prints the results spontaneously.
  • Come of the tools include nmap, dnsrecon, wafw00f, uniscan, sslyze, fierce, lbd, theharvester, dnswalk, golismero etc executes under one entity.
  • Saves a lot of time, indeed a lot time!
  • Checks for same vulnerabilities with multiple tools to help you zero-in on false positives effectively.
  • Legends to help you understand which tests may take longer time, so you can Ctrl+C to skip if needed.
  • Association with OWASP Top 10 2017 on the list of vulnerabilities discovered. (under development)
  • Critical, high, large, low and informational classification of vulnerabilities.
  • Vulnerability definitions guides you what the vulnerability actually is and the threat it can pose
  • Remediations tells you how to plug/fix the found vulnerability.
  • Executive summary gives you an overall context of the scan performed with critical, high, low and informational issues discovered. (under development)
  • Artificial intelligence to deploy tools automatically depending upon the issues found. for eg; automates the launch of wpscan and plecost tools when a wordpress installation is found. (under development)
  • Detailed comprehensive report in a portable document format (*.pdf) with complete details of the scans and tools used. (under development)

For Your Infomation about RapidScan:
  • Program is still under development, works and currently supports 80 vulnerability tests.
  • Parallel processing is not yet implemented, may be coded as more tests gets introduced.

RapidScan supports checking for these vulnerabilities:
  • DNS/HTTP Load Balancers & Web Application Firewalls. 
  • Checks for Joomla, WordPress and Drupal
  • SSL related Vulnerabilities (HEARTBLEED, FREAK, POODLE, CCS Injection, LOGJAM, OCSP Stapling).
  • Commonly Opened Ports.
  • DNS Zone Transfers using multiple tools (Fierce, DNSWalk, DNSRecon, DNSEnum).
  • Sub-Domains Brute Forcing.
  • Open Directory/File Brute Forcing.
  • Shallow XSS, SQLi and BSQLi Banners.
  • Slow-Loris DoS Attack, LFI (Local File Inclusion), RFI (Remote File Inclusion) & RCE (Remote Code Execution).

RapidScan's Requirements:
  • Kali Linux, Parrot Security OS, BlackArch... Linux distros that based for pentesters and hackers.
  • Python 2.7.x

RapidScan Installation:


RapidScan's screenshots:
RapidScan helping menu
RapidScan Intro
RapidScan Outro

How to contribute?
If you want to contribute to the author. Read this.

Related links


  1. Pentest Tools Android
  2. Hacking Tools Github
  3. Beginner Hacker Tools
  4. Pentest Tools For Windows
  5. Pentest Tools Github
  6. Best Hacking Tools 2020
  7. Pentest Tools Free
  8. Hacker Tools 2019
  9. Hack Website Online Tool
  10. Hacker Tools Apk
  11. Hacking Tools For Windows Free Download
  12. What Is Hacking Tools
  13. Hacking Tools 2020
  14. Best Hacking Tools 2020
  15. Hacker Tools Linux
  16. Pentest Tools Linux
  17. Hack Tools
  18. Hack Tool Apk
  19. Hacking Tools Windows
  20. Termux Hacking Tools 2019
  21. Pentest Tools Tcp Port Scanner
  22. Hacker
  23. Pentest Tools Alternative
  24. Pentest Tools Kali Linux
  25. Wifi Hacker Tools For Windows
  26. Game Hacking
  27. Pentest Tools Download
  28. Easy Hack Tools
  29. Pentest Tools
  30. Github Hacking Tools
  31. Hacking Tools Hardware
  32. Underground Hacker Sites
  33. How To Make Hacking Tools
  34. Hack Tools
  35. Hacking App
  36. Hacking Tools Software
  37. Hacker Tools Github
  38. Pentest Tools Website Vulnerability
  39. New Hack Tools
  40. Pentest Tools Alternative
  41. Easy Hack Tools
  42. Pentest Tools Android
  43. Hacker Tools Online
  44. Hacker Tools Free
  45. Pentest Tools Open Source
  46. Hackrf Tools
  47. Hacking Tools Pc
  48. Pentest Tools Bluekeep
  49. Hacks And Tools
  50. Hacker Tools Github
  51. Hacker Search Tools
  52. Pentest Tools Website
  53. Nsa Hack Tools
  54. Hack Website Online Tool
  55. Hack Tools For Mac
  56. Hack Tools 2019
  57. Hacker Tools
  58. Hacker Tools Free
  59. Hacking Tools Windows 10
  60. Top Pentest Tools
  61. Hacker Tools For Windows
  62. Hack Tools For Windows
  63. Hacking Tools For Beginners
  64. Hack Tools For Ubuntu
  65. Hacker Tools Software
  66. Hacker Tools Windows
  67. Pentest Tools Online
  68. Pentest Tools Nmap
  69. Computer Hacker
  70. Hacking Tools Hardware
  71. Pentest Tools Linux
  72. Hacker Hardware Tools
  73. Hack Website Online Tool
  74. Free Pentest Tools For Windows
  75. Best Hacking Tools 2019
  76. Hacker Tools
  77. Hacking Tools Usb
  78. Easy Hack Tools
  79. Github Hacking Tools
  80. Pentest Tools
  81. Hacks And Tools
  82. Hacker
  83. Hacker Hardware Tools
  84. Hacking Tools And Software
  85. World No 1 Hacker Software
  86. Bluetooth Hacking Tools Kali
  87. Hack Tool Apk No Root
  88. Hacking Tools And Software
  89. Hack Tool Apk No Root
  90. Pentest Tools List
  91. Hacker Tools 2019
  92. Pentest Tools Find Subdomains
  93. Pentest Tools Subdomain
  94. Bluetooth Hacking Tools Kali
  95. Hacker Tools 2019
  96. Hacker Tools 2020
  97. Hacking Tools 2020
  98. Blackhat Hacker Tools
  99. New Hack Tools
  100. Hacker Tools Github
  101. Hack Tools For Mac
  102. Hacking Tools For Beginners
  103. Pentest Tools Apk
  104. Hack Tools Pc
  105. Blackhat Hacker Tools
  106. Underground Hacker Sites
  107. Hacker
  108. Pentest Tools Download
  109. Hacking Tools Name
  110. Hack Tools For Pc
  111. Best Hacking Tools 2020
  112. Hacking App
  113. Install Pentest Tools Ubuntu
  114. Hacker Tools Linux
  115. Hack Tools For Ubuntu
  116. Hak5 Tools
  117. Hacker Tools Windows
  118. Top Pentest Tools
  119. Hacking App
  120. Hacking Tools Software
  121. Hacker
  122. Physical Pentest Tools
  123. Best Hacking Tools 2019
  124. Hacking Tools 2019
  125. Hacker Tools 2019
  126. Hacker Tools For Mac
  127. Hack Tools For Games
  128. Physical Pentest Tools
  129. Hacking Tools 2019
  130. Hack Tools For Games
  131. Hacker
  132. Nsa Hacker Tools
  133. Hack Tools For Pc
  134. Hacker Tools Hardware
  135. Hack Tools Pc
  136. Hacking Tools For Windows
  137. Pentest Tools Windows
  138. Hacker Tools Mac
  139. Hacker Hardware Tools
  140. Pentest Tools Website
  141. Hack Tool Apk

Minggu, 30 Agustus 2020

TLS V1.2 Sigalgs Remote Crash (CVE-2015-0291)


OpenSSL 1.0.2a fix several security issues, one of them let crash TLSv1.2 based services remotelly from internet.


Regarding to the TLSv1.2 RFC,  this version of TLS provides a "signature_algorithms" extension for the client_hello. 

Data Structures


If a bad signature is sent after the renegotiation, the structure will be corrupted, becouse structure pointer:
s->c->shared_sigalgs will be NULL, and the number of algorithms:
s->c->shared_sigalgslen will not be zeroed.
Which will be interpreted as one algorithm to process, but the pointer points to 0x00 address. 


Then tls1_process_sigalgs() will try to process one signature algorithm (becouse of shared_sigalgslen=1) then sigptr will be pointer to c->shared_sigalgs (NULL) and then will try to derreference sigptr->rhash. 


This mean a Segmentation Fault in  tls1_process_sigalgs() function, and called by tls1_set_server_sigalgs() with is called from ssl3_client_hello() as the stack trace shows.




StackTrace

The following code, points sigptr to null and try to read sigptr->rsign, which is assembled as movzbl eax,  byte ptr [0x0+R12] note in register window that R12 is 0x00

Debugger in the crash point.


radare2 static decompiled


The patch fix the vulnerability zeroing the sigalgslen.
Get  David A. Ramos' proof of concept exploit here





More information


Linux Command Line Hackery Series - Part 4




Welcome back to Linux Command Line Hackery, hope you have enjoyed this series so far. Today we are going to learn new Linux commands and get comfortable with reading text files on Linux.

Suppose that you wanted to view your /etc/passwd file. How will you do that? From what we have learned so far what you'll do is type:

cat /etc/passwd

And there you go, but really did you see all the output in one terminal? No, you just ended up with last few lines and you'll have to cheat (i,e use graphical scroll bar) in order to see all the contents of /etc/passwd file. So is there a command line tool in linux with which we can see all the contents of a file easily without cheating? Yes, there are actually a few of them and in this article we'll look at some common ones.

Command: more
Syntax:  more [options] file...
Function: more is a filter for paging through text one screenful at a time. With more we can parse a file one terminal at a time or line by line. We can also go backward and forward a number of lines using more.

So if we're to use more on /etc/passwd file how will we do that? We'll simply type

more /etc/passwd

now we'll get a screenful output of the file and have a prompt at the bottom of terminal. In order to move forward one line at a time press <Enter Key>. Using enter we can scroll through the file one line at a time. If you want to move one screen at a time, you can press <Space Key> to move one screen at a time. There are more functions of more program, you can know about them by pressing <h key>. To exit out of more program simply type <q key> and you'll get out of more program.

Command: less
Syntax: less [options] file...
Function: less is similar to more but less has more functionality than more. less is particularly useful when reading large files as less does not have to read the entire input file before starting, so it starts up quickly than many other editors.

less command is based on more so what you've done above with more can be done with less as well. Try it out yourself.

Command: head
Syntax: head [OPTION]... [FILE]...
Function: head command prints the head or first part of a file. By default head prints out first 10 lines of a file. If more than one file is specified, head prints first 10 lines of all files as a default behavior.

If we want to see only first 10 lines of /etc/passwd we can type:

head /etc/passwd

We can also specify to head how many lines we want to view by using the -n flag. Suppose you want to see first 15 lines of /etc/passwd file you've to type:

head -n 15 /etc/passwd

Ok you can view the first lines of a file what about last lines, is there a tool for that also? Exactly that's what our next command will be about.

Command: tail
Syntax: tail [OPTION]... [FILE]...
Function: tail is opposite of head. It prints the last 10 lines of a file by default. And if more than one file is specified, tail prints last 10 lines of all files by default.

To view last 10 lines of /etc/passwd file you'll type:

tail /etc/passwd

and as is the case with head -n flag can be used to specify the number of lines

tail -n 15 /etc/passwd

Now one more thing that we're going to learn today is grep.

Command: grep
Syntax: grep [OPTIONS] PATTERN [FILE...]
Function: grep is used to search a file for lines matching the pattern specified in the command.

A PATTERN can simply be a word like "hello" or it can be a regular expression (in geek speak regex). If you aren't familiar with regex, it's ok we'll not dive into that it's a very big topic but if you want to learn about it I'll add a link at the end of this article that will help you get started with regex.

Now back to grep say we want to find a line in /etc/passwd file which contains my user if we'll simply type:

grep myusername /etc/passwd

Wohoo! It gives out just that data that we're looking for. Remember here myusername is your username.
One cool flag of grep is -v which is used to look in file for every line except the line containing the PATTERN specified after -v [it's lowercase v].

Take your time practicing with these commands especially grep and more. We'll learn a lot more about grep in other upcoming articles.

References:
https://en.wikipedia.org/wiki/Regular_expression
http://www.regular-expressions.info/
Awesome website to learn Regular expressions - http://www.regexr.com/
Read more

Sabtu, 29 Agustus 2020

BurpSuite Introduction & Installation



What is BurpSuite?
Burp Suite is a Java based Web Penetration Testing framework. It has become an industry standard suite of tools used by information security professionals. Burp Suite helps you identify vulnerabilities and verify attack vectors that are affecting web applications. Because of its popularity and breadth as well as depth of features, we have created this useful page as a collection of Burp Suite knowledge and information.

In its simplest form, Burp Suite can be classified as an Interception Proxy. While browsing their target application, a penetration tester can configure their internet browser to route traffic through the Burp Suite proxy server. Burp Suite then acts as a (sort of) Man In The Middle by capturing and analyzing each request to and from the target web application so that they can be analyzed.











Everyone has their favorite security tools, but when it comes to mobile and web applications I've always found myself looking BurpSuite . It always seems to have everything I need and for folks just getting started with web application testing it can be a challenge putting all of the pieces together. I'm just going to go through the installation to paint a good picture of how to get it up quickly.

BurpSuite is freely available with everything you need to get started and when you're ready to cut the leash, the professional version has some handy tools that can make the whole process a little bit easier. I'll also go through how to install FoxyProxy which makes it much easier to change your proxy setup, but we'll get into that a little later.

Requirements and assumptions:

Mozilla Firefox 3.1 or Later Knowledge of Firefox Add-ons and installation The Java Runtime Environment installed

Download BurpSuite from http://portswigger.net/burp/download.htmland make a note of where you save it.

on for Firefox from   https://addons.mozilla.org/en-US/firefox/addon/foxyproxy-standard/


If this is your first time running the JAR file, it may take a minute or two to load, so be patient and wait.


Video for setup and installation.




You need to install compatible version of java , So that you can run BurpSuite.
More information

  1. What Are Hacking Tools
  2. Pentest Tools Github
  3. Hack Rom Tools
  4. Hack Tools
  5. Nsa Hack Tools Download
  6. Hackrf Tools
  7. Tools Used For Hacking
  8. Pentest Tools For Windows
  9. Hacking Tools Github
  10. Hack Tools Pc
  11. Hackrf Tools
  12. Hacking Tools Hardware
  13. Hacker Tools Free
  14. Hack Tools Github
  15. Pentest Tools Website Vulnerability
  16. Hacking Tools For Games
  17. Game Hacking
  18. Hacker Tools Free Download
  19. Tools Used For Hacking
  20. Hack Tools For Games
  21. Hack Tools For Windows
  22. Hacker Tools For Mac
  23. Hacking Tools For Games
  24. Pentest Tools Alternative
  25. Hacking Tools For Kali Linux
  26. What Are Hacking Tools
  27. Hacking Tools And Software
  28. Hacker Tools Software
  29. What Is Hacking Tools
  30. Hacker Search Tools
  31. Termux Hacking Tools 2019
  32. Pentest Tools Tcp Port Scanner
  33. Hack Tool Apk
  34. Hacker Tools Online
  35. Hack Apps
  36. Growth Hacker Tools
  37. Hacking Tools For Beginners
  38. Pentest Tools Port Scanner
  39. Hacker Tools For Windows
  40. Hacker Tools Software
  41. New Hacker Tools
  42. Pentest Tools Kali Linux
  43. Physical Pentest Tools
  44. How To Hack
  45. How To Make Hacking Tools
  46. Hacking Tools Software
  47. Pentest Tools Windows
  48. Physical Pentest Tools
  49. Pentest Tools For Ubuntu
  50. Pentest Tools Find Subdomains
  51. Hack Tools For Windows
  52. Hacker Hardware Tools
  53. Pentest Tools Free
  54. Pentest Tools Alternative
  55. Hack Tools For Mac
  56. Hacking App
  57. Pentest Tools Framework
  58. Black Hat Hacker Tools
  59. Pentest Tools Nmap
  60. How To Install Pentest Tools In Ubuntu
  61. Pentest Tools Website
  62. Hacking Tools Usb
  63. Hack Tool Apk No Root
  64. Hacker
  65. Game Hacking
  66. Pentest Tools For Windows
  67. Hack Tools For Mac
  68. Hack App
  69. Hacking Tools Pc
  70. Hacker Tools For Windows
  71. Hacks And Tools
  72. Hacker Tools Online
  73. Pentest Tools Port Scanner
  74. Hacker Tools Mac
  75. Hacker Tools Free
  76. Hacking Tools Hardware
  77. Hack Tools
  78. Hackers Toolbox