terça-feira, 30 de maio de 2023

OWASP Web 2.0 Project Update

Some of you likely recall the talk back in 2016 or so of updating the OWASP Foundation website to not appear so much like a...well, a wiki.  That talk was carried forward into 2017 and 2018 and, with each year, the proposal got pushed ahead as there were other, deeper projects to tackle.  With the arrival of 2019 and a firm project plan under the guidance of Mike McCamon, Executive Director, we are finally moving toward a functioning, modern website that will be a whole lot less...wiki-like.  The journey has been circuitous and, while we are not anywhere near complete, we have a set plan in place to bring it to fruition within the calendar year (second quarter of the year, actually).

TLDR: How Can You Help? 

There are certainly ways in which you can get involved now.  For instance, we are looking for a clean way to get wiki pages into GitHub markdown format for archival.  I have done some work here but there are parsing issues with some of the tools.  Do you know a good tool or have you done similar work?  Also, are you or do you know a good designer, someone familiar with GitHub pages that can provide some useful help and feedback along the way?  A Jekyll expert to help code a theme with a handful of templates would be a great addition.  In addition, we could use website server admins who could help with assigning redirects to maintain search integrity.  Finally, there will be a great many pages to move that we will also eventually need community involvement in.  

So, What Have We Done? 

Thus far we have researched various ideas for standing up a new site, including modifying the current wiki, spinning up our own web server, contracting a third party to host and build a new site, and also using existing infrastructure with our own content to launch a new face for OWASP.  Our discussions led us to a familiar place, one that nearly every developer in the OWASP space is familiar with: GitHub.   

In our conversations with GitHub, it became readily apparent that using the platform would be a win for the Foundation as well as GitHub.  Nearly everyone who runs a project at OWASP (documentation or otherwise) uses GitHub.  Because our target audience is also mostly developers we know that they are also very comfortable with the platform.  And while GitHub has a number of high profile companies using their GitHub Pages, the use of the platform as the basis for the entire website of the number one non-profit foundation in the application security sector is a big draw.

We have run with that GitHub Pages idea and have spent internal manpower on a proof of concept.  This proof of concept is less about the UX of the site than the functionality, the ability to utilize the authentication systems, and the ability to utilize automation to push out changes quickly.

Where Are We Now?

We are doing the final stages of website architecture. We are also planning what needs to be in the site, how the pieces will integrate with current projects and chapters, and how we might utilize the community to integrate the pieces so that we have a visually and functionally cohesive website that spans across multiple repositories.

What Is Next?

We will soon be looking for a modern website design that is responsive and clean.  We will begin using the knowledge gained from our proof of concept to build out the internals of the website and then we will start implementing the highest traffic pages and administrative areas into the new platform.  Once we have the big-ticket items moved we will start looking at what is left and moving over those pieces.  The eventual goal would be to have a new, modern website for the future of OWASP while keeping the wiki as an archive of really useful information.


We hope you are as excited as we are about the future of the OWASP Foundation website and will join us as we move toward a modern web presence.  If you have any questions or would like to volunteer your time, experience or knowledge, please contact me at harold.blankenship@owasp.com

Continue reading


  1. Hack Rom Tools
  2. Hacking Tools Windows
  3. New Hacker Tools
  4. Hacker Tools
  5. Hack Tools For Windows
  6. Pentest Box Tools Download
  7. How To Hack
  8. Hacker Tools 2019
  9. Hack Tools For Windows
  10. What Are Hacking Tools
  11. Hak5 Tools
  12. Hacking Tools Windows
  13. Hacker Hardware Tools
  14. Best Hacking Tools 2019
  15. Nsa Hack Tools Download
  16. Game Hacking
  17. Hacking Tools And Software
  18. Hack Tools
  19. Hacking Tools For Windows
  20. Black Hat Hacker Tools
  21. Hacker Tools Github
  22. Hacking App
  23. Hack Tools Pc
  24. Ethical Hacker Tools
  25. Pentest Tools Windows
  26. Hacker Tools For Pc
  27. Hacking Tools For Mac
  28. Black Hat Hacker Tools
  29. Hack Tools
  30. Hacking Tools 2020
  31. Hacker Search Tools
  32. Pentest Tools Website
  33. Hacking Tools For Beginners
  34. Hacker Tools For Ios
  35. Best Hacking Tools 2019
  36. Hackrf Tools
  37. Hacking Tools Hardware
  38. Pentest Tools Review
  39. Hack Tools For Ubuntu
  40. Hackers Toolbox
  41. New Hacker Tools
  42. Hack Website Online Tool
  43. Pentest Tools
  44. Physical Pentest Tools
  45. Pentest Tools Android
  46. Black Hat Hacker Tools
  47. Hack Apps
  48. Hackers Toolbox
  49. Hak5 Tools
  50. Hacking Tools Free Download
  51. Best Hacking Tools 2020
  52. Hacking Tools Free Download
  53. Hacker Tools Free Download
  54. Tools 4 Hack
  55. Hack Tools For Ubuntu
  56. Hacking Tools Usb
  57. Hacking Tools Hardware
  58. Pentest Recon Tools
  59. Hacking Tools Github
  60. Hacker Tools Apk
  61. Blackhat Hacker Tools
  62. Github Hacking Tools
  63. Hacking Tools Online
  64. Hacking Tools Mac
  65. Hacking Tools For Windows 7
  66. Nsa Hack Tools
  67. Ethical Hacker Tools
  68. Hack Tools
  69. Hacker Tools Apk Download
  70. Best Hacking Tools 2019
  71. Hacking Tools 2019
  72. Hacking Tools Online
  73. Hacker Tools Github
  74. How To Install Pentest Tools In Ubuntu
  75. Pentest Tools Github
  76. Pentest Tools Windows
  77. Hack Tools Mac
  78. Tools 4 Hack
  79. Physical Pentest Tools

APPLE IPHONE X FACE ID CAN BE HACKED WITH SILICON MASK

Just a week after Apple released its brand new iPhone X on November 3, a team of researchers has claimed to successfully hack Apple's Face ID facial recognition technology with a mask that costs less than $150. They said Apple iPhone x face id can be hacked with silicon mask easily.

apple iPhone x face id hacked
Yes, Apple's "ultra-secure" Face ID security for the iPhone X is not as secure as the company claimed during its launch event in September this year.

"Apple engineering teams have even gone and worked with professional mask makers and makeup artists in Hollywood to protect against these attempts to beat Face ID," Apple's senior VP of worldwide marketing Phil Schiller said about Face ID system during the event.

"These are actual masks used by the engineering team to train the neural network to protect against them in Face ID."

However, the bad news is that researchers from Vietnamese cybersecurity firm Bkav were able to unlock the iPhone X using a mask.

Yes, Bkav researchers have a better option than holding it up to your face while you sleep. Bkav researchers re-created the owner's face through a combination of 3D printed mask, makeup, and 2D images with some "special processing done on the cheeks and around the face, where there are large skin areas" and the nose is created from silicone.

The researchers have also published a proof-of-concept video, showing the brand-new iPhone X first being unlocked using the specially constructed mask, and then using the Bkav researcher's face, in just one go.

"Many people in the world have tried different kinds of masks but all failed. It is because we understand how AI of Face ID works and how to bypass it," an FAQ on the Bkav website said.

"You can try it out with your own iPhone X, the phone shall recognize you even when you cover a half of your face. It means the recognition mechanism is not as strict as you think, Apple seems to rely too much on Face ID's AI. We just need a half face to create the mask. It was even simpler than we ourselves had thought."

Researchers explain that their "proof-of-concept" demo took about five days after they got iPhone X on November 5th. They also said the demo was performed against one of their team member's face without training iPhone X to recognize any components of the mask.

"We used a popular 3D printer. The nose was made by a handmade artist. We use 2D printing for other parts (similar to how we tricked Face Recognition 9 years ago). The skin was also hand-made to trick Apple's AI," the firm said.

The security firm said it cost the company around $150 for parts (which did not include a 3D printer), though it did not specify how many attempts its researchers took them to bypass the security of Apple's Face ID.

It should be noted that creating such a mask to unlock someone's iPhone is a time-consuming process and it is not possible to hack into a random person's iPhone.

However, if you prefer privacy and security over convenience, we highly recommend you to use a passcode instead of fingerprint or Face ID to unlock your phone.
More information
  1. Hacking Tools For Windows Free Download
  2. Pentest Automation Tools
  3. How To Install Pentest Tools In Ubuntu
  4. Best Pentesting Tools 2018
  5. Hacker Tools For Pc
  6. Hacking Tools 2019
  7. Hacker Tools Online
  8. Hacker Tools 2020
  9. Hack Tools Download
  10. Hacker Tools 2020
  11. Hacking Tools Kit
  12. Pentest Tools Kali Linux
  13. Pentest Tools Framework
  14. Hacking Tools For Pc
  15. Hacking Tools Usb
  16. Android Hack Tools Github
  17. Pentest Tools List
  18. Hack Tools For Games
  19. Hacker Tools Github
  20. Bluetooth Hacking Tools Kali
  21. Hacking Tools For Beginners
  22. Hacker Search Tools
  23. Pentest Tools Subdomain
  24. Pentest Tools For Windows
  25. Hacking Tools Hardware
  26. Tools For Hacker
  27. Physical Pentest Tools
  28. Hacking Tools For Windows
  29. Pentest Tools Github
  30. Physical Pentest Tools
  31. Hacker Security Tools
  32. What Are Hacking Tools
  33. Hacking App
  34. How To Install Pentest Tools In Ubuntu
  35. Android Hack Tools Github
  36. Pentest Tools Kali Linux
  37. Termux Hacking Tools 2019
  38. Hack Rom Tools
  39. Wifi Hacker Tools For Windows
  40. Pentest Reporting Tools
  41. Hack Tools Online
  42. Hacking Apps
  43. Hacks And Tools
  44. Growth Hacker Tools
  45. Tools 4 Hack
  46. Hacker Tools 2019
  47. Hack Website Online Tool
  48. Hack Website Online Tool
  49. Pentest Tools For Windows
  50. New Hack Tools
  51. Hacking Tools For Kali Linux
  52. Hacker
  53. Hack Tools Online
  54. Hacker Security Tools
  55. Hack Tool Apk No Root
  56. Pentest Tools Website Vulnerability
  57. Wifi Hacker Tools For Windows
  58. Tools 4 Hack
  59. Hacker Hardware Tools
  60. Ethical Hacker Tools
  61. Hack Tools Mac
  62. How To Hack
  63. Hack Tool Apk No Root
  64. Usb Pentest Tools
  65. Hacker Tools Online
  66. Hacker
  67. Beginner Hacker Tools
  68. Install Pentest Tools Ubuntu
  69. Best Hacking Tools 2020
  70. Top Pentest Tools
  71. Black Hat Hacker Tools
  72. Hacking Tools Software
  73. Pentest Tools Windows
  74. Pentest Reporting Tools
  75. Physical Pentest Tools
  76. Pentest Tools Bluekeep
  77. Hack And Tools
  78. Termux Hacking Tools 2019
  79. Nsa Hacker Tools
  80. Hacker Tools For Windows
  81. Free Pentest Tools For Windows
  82. New Hack Tools
  83. Hack Rom Tools
  84. Hack Tools Github
  85. Pentest Reporting Tools
  86. Pentest Tools Port Scanner
  87. Hacking Tools For Windows
  88. Pentest Tools Find Subdomains
  89. Hacker Tools Github
  90. How To Install Pentest Tools In Ubuntu
  91. What Is Hacking Tools
  92. Underground Hacker Sites
  93. Hacker Tools Mac
  94. Pentest Tools Windows
  95. Physical Pentest Tools
  96. Hacking Tools Kit
  97. Hacker Techniques Tools And Incident Handling
  98. Pentest Tools Online
  99. Hack Tools For Mac
  100. Growth Hacker Tools
  101. Hacking Tools 2019
  102. Pentest Tools Android
  103. Pentest Tools Kali Linux
  104. Best Hacking Tools 2020
  105. Hack Tools For Mac
  106. Pentest Tools Kali Linux
  107. Wifi Hacker Tools For Windows
  108. Hack Website Online Tool
  109. How To Make Hacking Tools
  110. Hacker Tools Online
  111. Hacker Tool Kit
  112. Hackers Toolbox
  113. Nsa Hacker Tools
  114. Wifi Hacker Tools For Windows
  115. Growth Hacker Tools
  116. Hacker
  117. Pentest Tools For Ubuntu
  118. Hack Tools
  119. Hackrf Tools
  120. Hacking Tools For Mac
  121. Hacking Tools Free Download
  122. Hacker Tools For Ios
  123. Hacker Search Tools
  124. Computer Hacker
  125. Hacker Tools Online
  126. Blackhat Hacker Tools
  127. Hack Tools
  128. Hacker Tools For Windows
  129. Hack Tools For Ubuntu
  130. Hack App
  131. Pentest Tools Find Subdomains

Hacking Windows 95, Part 2

In the Hacking Windows 95, part 1 blog post, we covered that through a nasty bug affecting Windows 95/98/ME, the share password can be guessed in no time. In this article, I'm going to try to use this vulnerability to achieve remote code execution (with the help of publicly available tools only).

The first thing we can do when we have read access to the Windows directory through the share, is to locate all the *.pwl files on the c:\windows directory, copy them to your machine where Cain is installed, switch to Cracker tab, pwl files, load the pwl file, add username based on the filename, and try to crack it. If you can't crack it you might still try to add a .pwl file where you already know the password in the remote windows directory. Although this is a fun post-exploitation task, but still, no remote code execution. These passwords are useless without physical access.


One might think that after having a share password and user password, it is easy to achieve remote code execution. The problem is:
  • there is no "at" command (available since Windows 95 plus!)
  • there is no admin share
  • there is no RPC
  • there is no named pipes
  • there is no remote registry
  • there is no remote service management
If you think about security best practices, disabling unnecessary services is always the first task you should do. Because Windows 95 lacks all of these services, it is pretty much secure!

During my quest for a tool to hack Windows 95, I came across some pretty cool stuff:
LanSpy

But the best of the best is Fluxay, which has been written by chinese hackers. It is the metasploit from the year 2000. A screenshot is worth more than a 1000 words. 4 screenshot > 4 thousand words :)





It is pretty hard to find the installer, but it is still out there!

But at the end, no remote code execution for me.

My idea here was that if I can find a file which executes regularly (on a scheduled basis), I can change that executable to my backdoor and I'm done. Although there is no scheduler in the default Windows 95, I gave it a try. 

Let's fire up taskman.exe to get an idea what processes are running:


Looks like we need a more powerful tool here, namely Process Explorer. Let's try to download this from oldapps.com:


LOL, IE3 hangs, can't render the page. Copying files to the Win95 VM is not that simple, because there are no shared folders in Win95 VM. And you can't use pendrives either, Win95 can't handle USB (at least the retail version). After downloading the application with a newer browser from oldapps, let's start Process Explorer on the test Windows 95.


Don't try to download the Winsocks 2 patch from the official MS site, it is not there anymore, but you can download it from other sites

Now let's look at the processes running:


After staring it for minutes, turned out it is constant, no new processes appeared.
Looking at the next screenshot, one can notice this OS was not running a lot of background processes ...


My current Win7 has 1181 threads and 84 processes running, no wonder it is slow as hell :)

We have at least the following options:
  1. You are lucky and not the plain Windows 95 is installed, but Windows 95 Plus! The main difference here is that Windows 95 Plus! has built-in scheduler, especially the "at" command. Just overwrite a file which is scheduled to execution, and wait. Mission accomplished!
  2. Ping of death - you can crash the machine (no BSOD, just crash) with long (over 65535 bytes) ICMP ping commands, and wait for someone to reboot it. Just don't forget to put your backdoor on the share and add it to autoexec.bat before crashing it. 
  3. If your target is a plain Windows 95, I believe you are out of luck. No at command, no named pipes, no admin share, nothing. Meybe you can try to fuzz port 137 138 139, and write an exploit for those. Might be even Ping of Death is exploitable?
Let's do the first option, and hack Windows 95 plus!
Look at the cool features we have by installing Win95 Plus!


Cool new boot splash screen!


But our main interest is the new, scheduled tasks!


Now we can replace diskalm.exe with our backdoor executable, and wait maximum one hour to be scheduled.

Instead of a boring text based tutorial, I created a YouTube video for you. Based on the feedbacks on my previous tutorialz, it turned out I'm way too old, and can't do interesting tutorials. That's why I analyzed the cool skiddie videoz, and found that I have to do the followings so my vidz won't suck anymore:
  • use cool black windows theme
  • put meaningless performance monitor gadgets on the sidebar
  • use a cool background, something related with hacking and skullz
  • do as many opsec fails as possible
  • instead of captions, use notepad with spelling errorz
  • there is only one rule of metal: Play it fuckin' loud!!!!
Related articles
  1. Hacking Tools Software
  2. Hacking Tools Windows
  3. Game Hacking
  4. Hacker Tools Github
  5. Hacker Tools Windows
  6. Pentest Box Tools Download
  7. Hack Tools For Windows
  8. Hack Tools Download
  9. How To Hack
  10. World No 1 Hacker Software
  11. Pentest Tools Review
  12. Hacking Tools For Kali Linux
  13. Pentest Tools Port Scanner
  14. Hacker Tools Apk
  15. Pentest Tools For Ubuntu
  16. Hacker Tools Apk Download
  17. Pentest Tools Url Fuzzer
  18. Hack Tools
  19. Hacker Tools For Mac
  20. Computer Hacker
  21. Pentest Tools Android
  22. Hacker Tools Apk Download
  23. Pentest Tools Free
  24. Pentest Tools Kali Linux
  25. Pentest Tools Github
  26. Hack Tools For Ubuntu
  27. Hack Tool Apk
  28. Underground Hacker Sites
  29. Tools For Hacker
  30. Pentest Recon Tools
  31. Hacking Tools And Software
  32. Hacker Tools
  33. Hack And Tools
  34. Hacker Tool Kit
  35. Hacker Security Tools
  36. Hacking App
  37. Pentest Tools Free
  38. Pentest Tools Subdomain
  39. Easy Hack Tools
  40. Hack App
  41. Hacker Tools
  42. Hacker Tools Windows
  43. Tools For Hacker
  44. Hacker Tools Github
  45. Hacker Tools Online
  46. Pentest Tools
  47. Hacker Tools For Mac
  48. Hacker Tools Windows
  49. Game Hacking
  50. How To Hack
  51. Best Hacking Tools 2020
  52. Pentest Tools Alternative
  53. Pentest Tools For Ubuntu
  54. Pentest Recon Tools
  55. Hacking Tools Pc
  56. Hacking Apps

segunda-feira, 29 de maio de 2023

Exploiting Golang Unsafe Pointers


There are situations when c interacts with golang for example in a library, and its possible to exploit a golang function writing raw memory using an unsafe.Pointer() parameter.

When golang receive a null terminated string on a *C.Char parameter, can be converted to golang s tring with  s2 := C.GoString(s1) we can do string operations with s2 safelly if the null byte is there.

When golang receives a pointer to a buffer on an unsafe.Pointer() and the length of the buffer on a C.int, if the length is not cheated can be converted to a []byte safelly with b := C.GoBytes(buf,sz)

Buuut what happens if golang receives a pointer to a buffer on an unsafe.Pointer() and is an OUT variable? the golang routine has to write on this pointer unsafelly for example we can create a golangs memcpy in the following way:



We convert to uintptr for indexing the pointer and then convert again to pointer casted to a byte pointer dereferenced and every byte is writed in this way.

If b is controlled, the memory can be written and the return pointer of main.main or whatever function can be modified.

https://play.golang.org/p/HppcVpLfuMf


The return addres can be pinpointed, for example 0x41 buffer 0x42 address:



We can reproduce it simulating the buffer from golang in this way:


we can dump the address of a function and redirect the execution to it:


https://play.golang.org/p/7htJHJp8gUJ

In this way it's possible to build a rop chain using golang runtime to unprotect a shellcode.

More info