A New Internet Library: Add Your Website/Blog or Suggest A Website/Blog to our Free Web Directory http://anil.myfunda.net.

Its very simple, free and SEO Friendly.
Submit Now....

Thursday, May 7, 2020

Linux/AirDropBot Samples



Reference








Download

       
      Other malware






Hashes

MD5
SHA256
SHA1
85a8aad8d938c44c3f3f51089a60ec16
1a75642976449d37acd14b19f67ed7d69499c41aa6304e78c7b2d977e0910e37
2f0079bb42d5088f1fec341cb68f15cdd447ac43
2c0afe7b13cdd642336ccc7b3e952d8d
64c0e594d4926a293a1f1771187db8cfb44a0dda80d8b25b4f0c975e1e77745c
fef65085a92654cbcf1e3e0d851c6cda8dd3b03d
94b8337a2d217286775bcc36d9c862d2
71c02b99046c3be12e31577aa6623ce47dfb7f369e67af564d2bd499080c03b6
d5deeb1b61026479acb421583b7b82d09d63e921
417151777eaaccfc62f778d33fd183ff
bf6941e644a430fef43afc749479859665a57b711d5483c2c7072049c7db17b7
f76b9447db23229edae17a3160e04df41bc35a9d
d31f047c125deb4c2f879d88b083b9d5
2785845c97a69e15c9c1535216732a9d24bcf8f7244ce7872a2b0d2d4bcb92c3
4693505ef4c029112c4b85a16762cf90f0d69c15
ff1eb225f31e5c29dde47c147f40627e
f7ab3d315961d84da43f30a186136a56f5aa1e9afe6b56a0d357accd5f0ab81a
d5f2a976b703b5e687ffc58c408e0bc880838ae7
f3aed39202b51afdd1354adc8362d6bf
fa2bc8d988c8dfbdc965f1373bd80e9f5862868397c1bcb5e84b1e9c1756e0e2
31f0bca917cfbffcc126219439d38fe80d5c8460
083a5f463cb84f7ae8868cb2eb6a22eb
d654850f7785a5adb34f0808e2952f66e3784c0a32427fab9e97c75f0a48d9f5
ed4359a2805ce69771253d2257598b5c63c36c8e
9ce4decd27c303a44ab2e187625934f3
a2a245f12ae44cca79f03a465e2dc3dfa222dfcfda1017824b16abf397f16255
710e85ae3d362d3c8f3759319c308ff9b4dcdc86
b6c6c1b2e89de81db8633144f4cb4b7d
2480be0d00193250bc9eb50b35403399ed44f53d5d919600ee5bab14ef769530
ee77141054ac8d2fad062bcd79832b5f481c7dfb
abd5008522f69cca92f8eefeb5f160e2
509299df2f6150f59ed777873d3b7c708587c68a4004b4654a8cf2a640dd50aa
15cf94828c07e080b9c455738f3219859d9ab732
a84bbf660ace4f0159f3d13e058235e9
565deb4b1a7397d2497c75c9635b81d2e3b6427f0c576e5cd3c4224660712b56
c56fea8c1c949394e539d5ab3e3df7dfd329844a
5fec65455bd8c842d672171d475460b6
121c7ebfb99d8ef39f72bf7c787be4c15e2e08b731f01172605a4d34d27f08eb
3b6ca4525c3aad0583400b911b015071a0ea6133
4d3cab2d0c51081e509ad25fbd7ff596
7f71577b63b449c1a9e9aa516fa9e4320fe5f79548a00025a430894a269ab57b
d521f25362791de4d8a82a2683f032c1dd816e74
252e2dfdf04290e7e9fc3c4d61bb3529
834fc5c0ccfde1f3d52d88355717f119221118ee2d26018b417c50d066e9e978
c8f3130e64a6f825b1e97060cf258e9086a2b650
5dcdace449052a596bce05328bd23a3b
22949a7a3424f3b3bdf7d92c5e7a7a0de4eb6bbe9c523d57469944f6a8b1d012
f2c072560559a3f112e2000c8e28ee975b2b9db3
9c66fbe776a97a8613bfa983c7dca149
18c08d3c39170652d4770b2f7785e402b58c1f6c51ba1338be4330498ef268f4
18a99ec770109357d1adbc1c2475b17d4dcca651
59af44a74873ac034bd24ca1c3275af5
1c345b5e7c7fdcc79daa5829e0f93f6ae2646f493ae0ec5e8d66ab84a12a2426
98f789e91809203fbf1b7255bd0579fc86a982ba
9642b8aff1fda24baa6abe0aa8c8b173
98165c65d83fd95379e2e7878ac690c492ac54143d7b12beec525a9d048bedae
bd447e0e77a9192b29da032db8e1216b7b97f9ed
e56cec6001f2f6efc0ad7c2fb840aceb
7a2bf405c5d75e4294c980a26d32e80e108908241751de4c556298826f0960f1
b1c271d11797baac2504916ac80fd9e6fac61973
54d93673f9539f1914008cfe8fd2bbdd
c396a1214956eb35c89b62abc68f7d9e1e5bd0e487f330ed692dd49afed37d5a
72a9b8d499cce2de352644a8ffeb63fd0edd414b
6d202084d4f25a0aa2225589dab536e7
c691fecb7f0d121b5a9b8b807c5767ad17ae3dd9981c47f114d253615d0ef171
a68149c19bfddcdfc537811a3a78cd48c7c74740
cfbf1bd882ae7b87d4b04122d2ab42cb
892986403d33acb57fca1f61fc87d088b721bdd4b8de3cd99942e1735188125b
a067a0cf99650345a32a65f5bc14ab0da97789b6

Continue reading

$$$ Bug Bounty $$$

What is Bug Bounty ?



A bug bounty program, also called a vulnerability rewards program (VRP), is a crowdsourcing initiative that rewards individuals for discovering and reporting software bugs. Bug bounty programs are often initiated to supplement internal code audits and penetration tests as part of an organization's vulnerability management strategy.




Many software vendors and websites run bug bounty programs, paying out cash rewards to software security researchers and white hat hackers who report software vulnerabilities that have the potential to be exploited. Bug reports must document enough information for for the organization offering the bounty to be able to reproduce the vulnerability. Typically, payment amounts are commensurate with the size of the organization, the difficulty in hacking the system and how much impact on users a bug might have.


Mozilla paid out a $3,000 flat rate bounty for bugs that fit its criteria, while Facebook has given out as much as $20,000 for a single bug report. Google paid Chrome operating system bug reporters a combined $700,000 in 2012 and Microsoft paid UK researcher James Forshaw $100,000 for an attack vulnerability in Windows 8.1.  In 2016, Apple announced rewards that max out at $200,000 for a flaw in the iOS secure boot firmware components and up to $50,000 for execution of arbitrary code with kernel privileges or unauthorized iCloud access.


While the use of ethical hackers to find bugs can be very effective, such programs can also be controversial. To limit potential risk, some organizations are offering closed bug bounty programs that require an invitation. Apple, for example, has limited bug bounty participation to few dozen researchers.

Related links


Wednesday, May 6, 2020

Kali Linux 2018.3 Release - Penetration Testing And Ethical Hacking Linux Distribution



Kali 2018.3 brings the kernel up to version 4.17.0 and while 4.17.0 did not introduce many changes, 4.16.0 had a huge number of additions and improvements including more Spectre and Meltdown fixes, improved power management, and better GPU support.

New Tools and Tool Upgrades

Since our last release, we have added a number of new tools to the repositories, including:
  • idb – An iOS research / penetration testing tool
  • gdb-peda – Python Exploit Development Assistance for GDB
  • datasploit – OSINT Framework to perform various recon techniques
  • kerberoast – Kerberos assessment tools

In addition to these new packages, we have also upgraded a number of tools in our repos including aircrack-ng, burpsuite, openvas,wifite, and wpscan.
For the complete list of updates, fixes, and additions, please refer to the Kali Bug Tracker Changelog.

Download Kali Linux 2018.3


If you would like to check out this latest and greatest Kali release, you can find download links for ISOs and Torrents on the Kali Downloads page along with links to the Offensive Security virtual machine and ARM images, which have also been updated to 2018.3. If you already have a Kali installation you're happy with, you can easily upgrade in place as follows.
root@kali:~# apt update && apt -y full-upgrade
If you come across any bugs in Kali, please open a report on our bug tracker. It's more than a little challenging to fix what we don't know about.

Making sure you are up-to-date


To double check your version, first make sure your network repositories is enabled.
root@kali:~# cat</etc/apt/sources.list
deb http://http.kali.org/kali kali-rolling main non-free contrib
EOF
root@kali:~#

Then after running apt -y full-upgrade, you may require a reboot before checking:
root@kali:~# grep VERSION /etc/os-release
VERSION="2018.3"
VERSION_ID="2018.3"
root@kali:~#



More information


  1. Hacking Code
  2. Hacker Blanco
  3. Libro Hacker
  4. Hacking Growth Sean Ellis
  5. Tutoriales Hacking
  6. Programa Hacker
  7. Raspberry Pi Hacking
  8. Defcon Hacking
  9. Hacking Pdf

$$$ Bug Bounty $$$

What is Bug Bounty ?



A bug bounty program, also called a vulnerability rewards program (VRP), is a crowdsourcing initiative that rewards individuals for discovering and reporting software bugs. Bug bounty programs are often initiated to supplement internal code audits and penetration tests as part of an organization's vulnerability management strategy.




Many software vendors and websites run bug bounty programs, paying out cash rewards to software security researchers and white hat hackers who report software vulnerabilities that have the potential to be exploited. Bug reports must document enough information for for the organization offering the bounty to be able to reproduce the vulnerability. Typically, payment amounts are commensurate with the size of the organization, the difficulty in hacking the system and how much impact on users a bug might have.


Mozilla paid out a $3,000 flat rate bounty for bugs that fit its criteria, while Facebook has given out as much as $20,000 for a single bug report. Google paid Chrome operating system bug reporters a combined $700,000 in 2012 and Microsoft paid UK researcher James Forshaw $100,000 for an attack vulnerability in Windows 8.1.  In 2016, Apple announced rewards that max out at $200,000 for a flaw in the iOS secure boot firmware components and up to $50,000 for execution of arbitrary code with kernel privileges or unauthorized iCloud access.


While the use of ethical hackers to find bugs can be very effective, such programs can also be controversial. To limit potential risk, some organizations are offering closed bug bounty programs that require an invitation. Apple, for example, has limited bug bounty participation to few dozen researchers.
Related articles
  1. Hacking 2019
  2. Hacker Definicion
  3. Whatsapp Hacking
  4. Hacking Informatico
  5. Herramientas Hacking Android
  6. Linux Hacking Distro
  7. Phone Hacking
  8. Hacking Time
  9. Growth Hacking Que Es
  10. Amiibo Hacking
  11. Hacking Xbox One
  12. Computer Hacking
  13. Ethical Hacking
  14. Programas Para Hackear
  15. Hacking Games

Friday, May 1, 2020

Thinking Fast And Slow: Book Review (Monday Musings 84)

I heard about this book from one of my streamer friends after I mentioned how I don't think of myself as good at responding to unexpected things. I rarely think on my feet as well as I'd like. She'd heard about Thinking Fast and Slow by Daniel Kahneman and felt it might explain why some people can't respond quickly to surprises. Further, those types of people are more thoughtful, so I might not feel too bad about myself.

However, the book goes into different matters than what I hoped. Kahneman's thesis is that humans are not rational and how that was a huge breakthrough in the world of economics. This surprised me, because we all know that people do really stupid things, even the most rational among us...for example, we all know usually sensible people who don't wear helmets or seatbelts nor take other easy to implement safety precautionss.

Even so, the predominant tendency in economics for most of its existence as a science is to hold that people are rational and will do rational things. Kahneman proposes otherwise. He describes two systems that we use: System 1 is the immediate reaction we have to stimulus, our gut instinct. If we see an animal, we know right away that it's a dog, we don't have to think about it. Or, if we see smoke, we're know to try to put the fire out...or to flee.

While System 2 is your conscious mind, where you think things through. For instance, making a decision to buy one product rather than another. In a series of experiments, Kahneman shows that System 2 isn't always rational and thoughtful, but can be rather lazy. This can be very true, because we have to deal with a lot of issues in life, so that we can't spend that much energy carefully thinking through every decision and thought process. That would be too exhausting.

One experiment proving his thesis is the following problem: A ball and a bat costs $1.10, and the bat costs $1.00, how much does the ball cost?

I would immediately say "definitely not 10 cents" but only because I'm aware of these psychological experiments where the answer is often not what you think at first.

Even so, if I were a participant in this study, I would've answered, "Definitely not 10 cents, but I'm too tired to figure out the true cost of the ball". Most people answer 10 cents, because that's your impulse from System 1, and System 2 is too lazy to override the impulse.

As you can see from this example, your system 1 comes up immediately 10 cents, but your system 2 doesn't override this answer. The correct answer is 5 cents.

Kahneman also describes how system 2 is very biased - in one of many experiments he conducted, he showed how sentences in big bold letters are believed to be true more so than the same sentences in small lettering.

I found the first few chapters very interesting, and the experiments thought provoking. However, midway through the book, I couldn't get past the rest of the book because Kahneman gives so many thought experiments, it becomes tiring.

Indeed, the book appeared to be a monograph, where he would make a statement and then show examples to prove his theory. By answering all of the questions that he asks, I got fatigued.

As a result, I skipped the rest of the book to the conclusion. Because humans don't do things that are good for us, policies should allow for freedom of choice, but steer people toward the right thing to do.

For instance, employees are automatically opted in an IRA retirement savings plan at 10% of their salary. However, you can easily opt out of this plan if you want to.

Therefore, you have a choice to opt in or opt out. But with this policy, people may be too "lazy" to opt out, and unbeknownst to them, 10% goes into retirement fund. 10 years later, they will be surprised that it increased to a really nice sum.

Kahneman didn't mention this in his conclusion, but the conclusion I got from the book is to be open minded. We may think something is absolutely true, come to find out, we didn't realize that we were wrong all along, and never questioned it. By being open minded and nonjudgmental, your life will be more enriching. 

For instance, someone whom you had negative first impressions (System 1 making snap judgments), keep an open mind about that person, and you may find the person becoming your friend. Of course, if that person does awful things one after the other, then your first impressions were correct and System 2 will note to avoid that person. But this will be due to empirical evidence as opposed to a snap judgment.

It's easy to say people do dumb things all the time, but how do you explain why that's the case, and how do you prove it in a systematic way? In Thinking Fast and Slow, Kahneman does a superb job answering those questions, albeit in an eventually exhausting to read manner.

The How of Happiness Review

UCLan Games Design Projects With GSM Research Group


Latest News from Paresh Parmar: Head of International Development & Partnerships for School of Art, Design & Fashion at University of Central Lancashire.

















'We are grateful that 2019 gave us (GSM - Global Sound Movement) the opportunity to present our working concepts on cultural preservation at the '2019 British Science Festive Press Conference'. Happy to share that it caught the eye of some top press. The Virtual Reality Hani Drum was sighted as innovation in cultural preservation. Thanks to Josh Taylor, Josh Write & Bev Bush 'BA (Hons) Games Design' at UCLan. You really helped us push the boundaries. Josh Wright and Josh Taylor from UCLan Games Design developed the VR Hani Drum. Now people can actually play this ancient drum, without damaging it, our travelling to the distant mountains of the Yunnan, China. Watch the clip, more coming soon...'










GSM on BBC North West Tonight - 18 Sept 2019.
The pioneering work in virtual reality (VR) from UCLan's Global Sound Movement (GSM), which is allowing rare musical instruments from around the world to be digitally preserved, was showcased at the British Science Festival. GSM's innovative work with VR allows user interactivity with instruments from hard to reach geographical locations. Participants play music whilst receiving haptic feedback and triggering the actual sound of the musical instrument. The technology also allows for remote tutoring from someone in a different location, but within the same VR environment. Paresh Parmar, Co-founder of Global Sound Movement and Senior Lecturer at UCLan, said: "GSM is dedicated to preserving musical instruments of cultural significance and combining innovative new technologies making them globally accessible. This enables musicians and non-musicians to access these wonderful instruments and sounds, whilst providing resources for the original communities GSM worked with." A core belief of GSM is to preserve and share the sounds of the world. To achieve this, GSM is constantly developing new technologies to expand the reach of their work and enable people, regardless of musical talent, to engage, compose or simply enjoy music. The virtual instruments and corresponding
sound libraries can also be integrated with music production software, enabling composers internationally to use these rare sounds. All proceeds from the technology goes back into the local communities from which the instruments are recorded.
Also see:
https://www.britishscienceassociation.org/blog/preserving-rare-instruments-in-the-virtual-world

Bev Bush from UCLan Games Design worked with GSM to develop the Hani Embroidery App.






This research is part of a collaboration with The Global Sound Movement. Audiences can interact in a unique way with GSM sampled sounds from the drums of the Hani Tribe in China to create an embroidery pattern which celebrates their rhythms and traditional costume designs.
"Can gamification be used as an interactive and transformative tool for artistic expression to engage learning, encourage appreciation and to illustrate traditional, historical and cultural related experience?"
Advertising designer Elliot Harris' animated film of 2002, 'Burberry-Rain' identifies the 4 – dimensional properties of Burberry fabric. In 2013 Sophia George developed a game based on 'The Strawberry Thief' which re-vitalized the art of William Morris. The Hani App moves beyond re-vitalization of a design to involve interaction with sound and illustration of traditional crafts, exploring the use of digital tools to create unique artefacts. This acknowledges and records ideas and objects which may otherwise be lost or forgotten.
'The Art of Computer Game Design.'(Crawford, C. 1997)
'Play, Games and Gamification in Contemporary Art Museums.'(Romualdo, S. 2013)
'Gamification in the Arts.' (Bouchard, A. 2014)
An exploratory, prototyping methodology was used in this project, allowing for a flexible development style. Sprite Designs were created in Adobe Photoshop and implemented into the App using Scirra's Construct game engine. The work was inspired by GSM's photos and sampled sounds and is available to the public as an interactive App on the GSM website, also in the GSM South China Exhibitions and as a video on Vimeo with images of artefacts that can be purchased from the shop at this link.




Sunday, April 26, 2020

Testing SAML Endpoints For XML Signature Wrapping Vulnerabilities

A lot can go wrong when validating SAML messages. When auditing SAML endpoints, it's important to look out for vulnerabilities in the signature validation logic. XML Signature Wrapping (XSW) against SAML is an attack where manipulated SAML message is submitted in an attempt to make the endpoint validate the signed parts of the message -- which were correctly validated -- while processing a different attacker-generated part of the message as a way to extract the authentication statements. Because the attacker can arbitrarily forge SAML assertions which are accepted as valid by the vulnerable endpoint, the impact can be severe. [1,2,3]

Testing for XSW vulnerabilities in SAML endpoints can be a tedious process, as the auditor needs to not only know the details of the various XSW techniques, but also must handle a multitude of repetitive copy-and-paste tasks and apply the appropriate encoding onto each message. The latest revision of the XSW-Attacker module in our BurpSuite extension EsPReSSo helps to make this testing process easier, and even comes with a semi-automated mode. Read on to learn more about the new release! 

 SAML XSW-Attacker

After a signed SAML message has been intercepted using the Burp Proxy and shown in EsPReSSO, you can open the XSW-Attacker by navigating to the SAML tab and then the Attacker tab.  Select Signature Wrapping from the drop down menu, as shown in the screenshot below:



To simplify its use, the XSW-Attacker performs the attack in a two step process of initialization and execution, as reflected by its two tabs Init Attack and Execute Attack. The interface of the XSW-Attacker is depicted below.
XSW-Attacker overview

The Init Attack tab displays the current SAML message. To execute a signature wrapping attack, a payload needs to be configured in a way that values of the originally signed message are replaced with values of the attacker's choice. To do this, enter the value of a text-node you wish to replace in the Current value text-field. Insert the replacement value in the text-field labeled New value and click the Add button. Multiple values can be provided; however, all of which must be child nodes of the signed element. Valid substitution pairs and the corresponding XPath selectors are displayed in the Modifications Table. To delete an entry from the table, select the entry and press `Del`, or use the right-click menu.

Next, click the Generate vectors button - this will prepare the payloads accordingly and brings the Execute Attack tab to the front of the screen.

At the top of the Execute Attack tab, select one of the pre-generated payloads. The structure of the selected vector is explained in a shorthand syntax in the text area below the selector.
The text-area labeled Attack vector is editable and can be used to manually fine-tune the chosen payload if necessary. The button Pretty print opens up a syntax-highlighted overview of the current vector.
To submit the manipulated SAML response, use Burp's Forward button (or Go, while in the Repeater).

Automating XSW-Attacker with Burp Intruder

Burp's Intruder tool allows the sending of automated requests with varying payloads to a test target and analyzes the responses. EsPReSSO now includes a Payload Generator called XSW Payloads to facilitate when testing the XML processing endpoints for XSW vulnerabilities. The following paragraphs explain how to use the automated XSW attacker with a SAML response.

First, open an intercepted request in Burp's Intruder (e.g., by pressing `Ctrl+i`). For the attack type, select Sniper. Open the Intruder's Positions tab, clear all payload positions but the value of the XML message (the `SAMLResponse` parameter, in our example). Note: the XSW-Attacker can only handle XML messages that contain exactly one XML Signature.
Next, switch to the Payloads tab and for the Payload Type, select Extension-generated. From the newly added Select generator drop-down menu, choose XSW Payloads, as depicted in the screenshot below.



While still in the Payloads tab, disable the URL-encoding checkbox in the Payload Encoding section, since Burp Intruder deals with the encoding automatically and should suffice for most cases.
Click the Start Attack button and a new window will pop up. This window is shown below and is similar to the XSW Attacker's Init Attack tab.


Configure the payload as explained in the section above. In addition, a schema analyzer can be selected and checkboxes at the bottom of the window allow the tester to choose a specific encoding. However, for most cases the detected presets should be correct.

Click the Start Attack button and the Intruder will start sending each of the pre-generated vectors to the configured endpoint. Note that this may result in a huge number of outgoing requests. To make it easier to recognize the successful Signature Wrapping attacks, it is recommended to use the Intruder's Grep-Match functionality. As an example, consider adding the replacement values from the Modifications Table as a Grep-Match rule in the Intruder's Options tab. By doing so, a successful attack vector will be marked with a checkmark in the results table, if the response includes any of the configure grep rules.

Credits

EsPReSSO's XSW Attacker is based on the WS-Attacker [4] library by Christian Mainka and the original adoption for EsPReSSO has been implemented by Tim Günther.
Our students Nurullah Erinola, Nils Engelberts and David Herring did a great job improving the execution of XSW and implementing a much better UI.

---

[1] On Breaking SAML - Be Whoever You Want to Be
[2] Your Software at My Service
[3] Se­cu­ri­ty Ana­ly­sis of XAdES Va­li­da­ti­on in the CEF Di­gi­tal Si­gna­tu­re Ser­vices (DSS)
[4] WS-Attacker

Related links


Dotnet-Interviews