Showing posts with label tools. Show all posts
Showing posts with label tools. Show all posts

Teams Phishing

     Security controls like Sender Policy Framework (SPF) that can prevent direct spoofing of domains and email security gateways that can flag suspicious domains. Those security controls don’t exist for IM, so we have new options for spoofing.
 

Phishing is Evolving Quickly

Phishing kits are Evolving 

SaaS Attacks 

SAML Jacking 

    It’s not just application-level lateral movement and persistence to worry about, though. It’s possible the attacker can start moving laterally across other user accounts. If they have selected their targets well, they might even find they have admin access to some downstream SaaS application that has been configured for SAML logins using Okta. 

    For example, maybe they compromise a finance employee who has admin access to their business expenses SaaS application. Then the attacker might be able to use a new technique like SAMLjacking to start attacking other users in a watering hole attack to achieve lateral movement. 

    There are many options for lateral movement and persistence after an account compromise, so simple containment actions like password resets for SSO credentials are not nearly enough to contain a knowledgeable attacker. 

    Update IR playbooks to to deal with SSO account compromise, factoring in lateral movement and persistence across cloud apps. This really necessitates that you understand what business apps your organization is using, how they are accessed (e.g. SSO or username and password) and what functionality exists that could be abused by an attacker. 

https://www.lab539.com/aitm 

Tools :: no vnc :: EvilnoVNC :: Modlishka 

Read More ::

wget mirror

wget
  --directory-prefix=/root/Desktop/
  --header="Accept: text/html"
  --user-agent="(Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6"
  --domains test.com
  -e robots=off
  --recursive
  --no-clobber
  --page-requisites
  --html-extension
  --convert-links
  -R gif,jpg,png,css,pdf,mp3,wmv 

http://<domain>.com

new logwatch

Logwatch 7.5.2
https://packetstormsecurity.com/files/153783/logwatch-7.5.2.tar.gz

look at yer logs........

Iran has its turn in limelight

A Mystery Agent Is Doxing Iran's Hackers and Dumping Their Code
https://www.wired.com/story/iran-hackers-oilrig-read-my-lips

Russian VPNfilter Malware Was A Swiss Army Hacking Knife

https://packetstormsecurity.com/news/view/29349/Russian-VPNfilter-Malware-Was-A-Swiss-Army-Hacking-Knife.html

Quickjack

Advanced Clickjacking & Frame Slicing Attack Tool

https://www.darknet.org.uk/2018/02/quickjack-advanced-clickjacking-frame-slicing-attack-tool/

Understanding and Exploiting Web-based LDAP

http://pen-testing.sans.org/blog/2017/11/27/understanding-and-exploiting-web-based-ldap

Rtfdump update

Version 0.0.6 https://blog.didierstevens.com/2017/12/10/update-rtfdump-py-version-0-0-6/

Analyze Embedded PDF file

https://blog.didierstevens.com/2017/04/20/malicious-documents-the-matryoshka-edition/