الثلاثاء، 5 مايو 2020

goGetBucket - A Penetration Testing Tool To Enumerate And Analyse Amazon S3 Buckets Owned By A Domain


When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.

What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.

The following information about every bucket found to exist will be returned:
  • List Permission
  • Write Permission
  • Region the Bucket exists in
  • If the bucket has all access disabled

Installation
go get -u github.com/glen-mac/goGetBucket

Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i) of subdomains for a root domain I am interested in. E.G:
www.domain.com
mail.domain.com
dev.domain.com
The test file (-f) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?
The keyword list (-k) is concatenated with the root domain name (-d) and the domain without the TLD to permutate using the supplied permuation wordlist (-m).
Be sure not to increase the threads too high (-t) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.

Related articles

الاثنين، 4 مايو 2020

PortWitness - Tool For Checking Whether A Domain Or Its Multiple Sub-Domains Are Up And Running



PortWitness is a bash tool designed to find out active domain and subdomains of websites using port scanning. It helps penetration testers and bug hunters collect and gather information about active subdomains for the domain they are targeting.PortWitness enumerates subdomains using Sublist3r and uses Nmap alongwith nslookup to check for active sites.Active domain or sub-domains are finally stored in an output file.Using that Output file a user can directly start testing those sites.
Sublist3r has also been integrated with this module.It's very effective and accurate when it comes to find out which sub-domains are active using Nmap and nslookup.
This tool also helps a user in getting the ip addresses of all sub-domains and stores then in a text file , these ip's can be used for further scanning of the target.

Installation
git clone https://github.com/viperbluff/PortWitness.git

BASH
This tool has been created using bash scripting so all you require is a linux machine.

Usage
bash portwitness.sh url




More info

الجمعة، 1 مايو 2020

Ep 28: Grimdunk Is Live!

Ep 28: Grimdunk is live!
We talk with Mike Hobbs about Warhammer 40,000 and his new fantasy wargame project.

https://soundcloud.com/user-989538417/episode-28-grimdunk

Join the conversation at https://theveteranwargamer.blogspot.com, email theveteranwargamer@gmail.com, Twitter @veteranwargamer

Follow Mike on Twitter @wargamer_mike or his blog http://mikehobbs.co.uk/

Other companies we mentioned:
McVitie's Dark Chocolate Digestives http://www.mcvities.co.uk/products/chocolate-digestives
McVitie's Chocolate Hobnobs http://www.mcvities.co.uk/products/hobnobs
Sachertorte https://www.sacher.com/en/original-sacher-cake/
Previous Episode with Mike https://soundcloud.com/user-989538417/episode-15-in-my-day
Oldhammer https://soundcloud.com/user-989538417/episode-3-everything-oldhammer-is-new-again
Oldhammer II https://soundcloud.com/user-989538417/episode-22-give-me-lead-til-im-dead
Meeples and Minatures with Jon Tuffley https://www.youtube.com/watch?v=iH4MJlW8vHk




Music courtesy bensound.com. Recorded with zencastr.com. Edited with Audacity. Make your town beautiful; get a haircut.

People Behind The Meeples - Episode 222: Mikael Lyck

Welcome to People Behind the Meeples, a series of interviews with indie game designers.  Here you'll find out more than you ever wanted to know about the people who make the best games that you may or may not have heard of before.  If you'd like to be featured, head over to http://gjjgames.blogspot.com/p/game-designer-interview-questionnaire.html and fill out the questionnaire! You can find all the interviews here: People Behind the Meeples. Support me on Patreon!


Name:Mikael Lyck
Email:info@gamesbylyck.com
Location:Sweden
Day Job:Developer
Designing:Two to five years.
Webpage:gamesbylyck.com
BGG:Mikael Lyck
Facebook:Phan Card Game/
Instagram:@thephantomthecardgame
Other:https://kickstarter.com/projects/gamesbylyck/the-phantom-the-card-game
Find my games at:https://gamesbylyck.com/print-and-play/
Today's Interview is with:

Mikael Lyck
Interviewed on: 2/17/2020

This week's interview is with Mikael Lyck, who is planning on Kickstarting his card game based on the comic book hero The Phantom this week! He has a number of other projects in the works as well. Keep reading to learn more about Mikael!

Some Basics
Tell me a bit about yourself.

How long have you been designing tabletop games?
Two to five years.

Why did you start designing tabletop games?
It started with a thought about how I would do a game if I got the chance, I could not get the thought out of my head so I had to write the rules and a deck of cards. I realized that I love the process of designing games and figuring out how to do things in the best possible way.

What game or games are you currently working on?
The Phantom the Card Game

Have you designed any games that have been published?
Not yet

What is your day job?
Developer

Your Gaming Tastes
My readers would like to know more about you as a gamer.

Where do you prefer to play games?
At home or flgs

Who do you normally game with?
Friends and family

If you were to invite a few friends together for game night tonight, what games would you play?
Dominion, 7 wonders and lately these exit games have been a blast.

And what snacks would you eat?
Potato crisps and loose candy

Do you like to have music playing while you play games? If so, what kind?
Depends on the game, fantasy games are ok with some ambient music, but I prefer no music since it can be distracting.

What's your favorite FLGS?
Dragons Lair here in Stockholm

What is your current favorite game? Least favorite that you still enjoy? Worst game you ever played?
Dominion has been my favorite for years that gets played, I might love Hansa Teutonica more, but have a hard time convincing people to play it with me… The worst game for me is Uno and memory, I didn't enjoy them that much a few years ago and after that my kids have made me play them quite more than I like.

What is your favorite game mechanic? How about your least favorite?
Love drafting and my least favourite must be rolling dice, it can be so frustrating. It works in some games but kill other games for me, like x-wing

What's your favorite game that you just can't ever seem to get to the table?
Oh that would be Hansa Teutonica that I mentioned earlier.

What styles of games do you play?
I like to play Board Games, Card Games, Miniatures Games, Video Games

Do you design different styles of games than what you play?
I like to design Board Games, Card Games

OK, here's a pretty polarizing game. Do you like and play Cards Against Humanity?
No

You as a Designer
OK, now the bit that sets you apart from the typical gamer. Let's find out about you as a game designer.

When you design games, do you come up with a theme first and build the mechanics around that? Or do you come up with mechanics and then add a theme? Or something else?
It is either theme or mechanic first, but it is important to me that they work together.

Have you ever entered or won a game design competition?
Haven't entered but looked at a few and gotten inspiration on design ideas from the different rules.

Do you have a current favorite game designer or idol?
A few, nobody mentioned, nobody forgotten.

Where or when or how do you get your inspiration or come up with your best ideas?
When I try to sleep is most common, that and in the shower.

How do you go about playtesting your games?
Start out with close friends and family, after that with a great game design community in my hometown. First tests can be a disaster, where I look for what is fun and memorable in the game, usually I have over designed and need to cut away a lot of things after each playtests.

Do you like to work alone or as part of a team? Co-designers, artists, etc.?
I have help from a few great friends, Dejan have done the wonderful graphical design and Johan have helps me with contracts and deals

What do you feel is your biggest challenge as a game designer?
Second guessing myself about most of the steps I take.

If you could design a game within any IP, what would it be?
The IP that my game already is. If I get the chance my next IP would be Masters of the Universe.

What do you wish someone had told you a long time ago about designing games?
That I should reach out more online. There are so many nice people that are willing to help, and it is great. It also works both ways, it is quite fun to help others too!

What advice would you like to share about designing games?
Have fun! And focus on the fun things in game. Even if the fun part of the game you are designing is backstabbing or getting thinking so hard your brain hurts.

Would you like to tell my readers what games you're working on and how far along they are?
I'm planning to crowdfund: The Phantom the Card Game
Games that I'm playtesting are: Craft a Raft
Games that are in the early stages of development and beta testing are: Do My Bidding, Roll and Paint
And games that are still in the very early idea phase are: Motu fighting game, King of the Junk Hill

Are you a member of any Facebook or other design groups? (Game Maker's Lab, Card and Board Game Developers Guild, etc.)
Yes on most I can find, with my personal account

And the oddly personal, but harmless stuff…
OK, enough of the game stuff, let's find out what really makes you tick! These are the questions that I'm sure are on everyone's minds!

Star Trek or Star Wars? Coke or Pepsi? VHS or Betamax?
I am both a trekkie and a Star wars nerd, but if I had to choose it would be Star wars, named my kids Lucas and Leia after the Star wars characters. Pepsi max, I drink it too much… Growing up we had both, but haven't used a betamax for over 30 years.

What hobbies do you have besides tabletop games?
Video games, movies and comic books

What is something you learned in the last week?
I learn stuff all the time, last week I learned how to play wingspan

Favorite type of music? Books? Movies?
Listen to all kinds of music, punk, classic rock, pop mostly though. Am a sucker for Young adult books, fantasy and science fiction. I love the pretentious stuff, like Oscars winners.

What was the last book you read?
The latest book in the Magic 2.0 series, Out of sight out of mind if I recall correctly

Do you play any musical instruments?
The latest book in the Magic 2.0 series, "Out of Sight Out of Mind" if I recall correctly

Tell us something about yourself that you think might surprise people.
I am quite a good chef and enjoy making advanced dishes

Tell us about something crazy that you once did.
Quit my job to live on playing poker.

Biggest accident that turned out awesome?
Some old fungus was left unattended and antibiotics were discovered.

Who is your idol?
I try to not idolize people. But there are a lot of great people that I respect very much.

What would you do if you had a time machine?
I wouldn't use it, it seems very dangerous in the Back to the Future movies.

Are you an extrovert or introvert?
Depending on the day

If you could be any superhero, which one would you be?
Easy, The Phantom of course

Have any pets?
Nope, I am allergic to all cute furry animals.

When the next asteroid hits Earth, causing the Yellowstone caldera to explode, California to fall into the ocean, the sea levels to rise, and the next ice age to set in, what current games or other pastimes do you think (or hope) will survive into the next era of human civilization? What do you hope is underneath that asteroid to be wiped out of the human consciousness forever?
I hope compassion and love survives and hate and wars would be wiped out. "violins playing"

If you'd like to send a shout out to anyone, anyone at all, here's your chance (I can't guarantee they'll read this though):
Hi kids, hi wife and hi mom!


Thanks for answering all my crazy questions!




Thank you for reading this People Behind the Meeples indie game designer interview! You can find all the interviews here: People Behind the Meeples and if you'd like to be featured yourself, you can fill out the questionnaire here: http://gjjgames.blogspot.com/p/game-designer-interview-questionnaire.html

Did you like this interview?  Please show your support: Support me on Patreon! Or click the heart at Board Game Links , like GJJ Games on Facebook , or follow on Twitter .  And be sure to check out my games on  Tabletop Generation.

السبت، 25 أبريل 2020

Group Instant Messaging: Why Blaming Developers Is Not Fair But Enhancing The Protocols Would Be Appropriate

After presenting our work at Real World Crypto 2018 [1] and seeing the enormous press coverage, we want to get two things straight: 1. Most described weaknesses are only exploitable by the malicious server or by knowing a large secret number and thereby the protocols are still very secure (what we wrote in the paper but some newspapers did not adopt) and 2. we see ways to enhance the WhatsApp protocol without breaking its features.


We are of course very happy that our research reached so many people and even though IT security and cryptography are often hard to understand for outsiders, Andy Greenberg [2], Patrick Beuth [3] and other journalists [4,5,6,7,8] wrote articles that were understandable on the one hand and very accurate and precise on the other hand. In contrast to this, we also saw some inaccurate articles [9,10] that fanned fear and greatly diverged in their description from what we wrote in our paper. We expected this from the boulevard press in Germany and therefore asked them to stick to the facts when they were contacting us. But none of the worst two articles' [9,10] authors contacted us in advance. Since our aim was never to blame any application or protocol but rather we wanted to encourage the developers to enhance the protocols, it contradicts our aim that WhatsApp and Signal are partially declared attackable by "anyone" "easily" [9,10].

Against this background, we understand Moxie's vexation about certain headlines that were on the Internet in the last days [11]. However, we believe that the ones who understand the weaknesses, comprehend that only the malicious server can detectably make use of them (in WhatsApp) or the secret group ID needs to be obtained from a member (in Signal). As such, we want to make clear that our paper does not primarily focus on the description of weaknesses but presents a new approach for analyzing and evaluating the security of group instant messaging protocols. Further we propose measures to enhance the analyzed protocols. The description of the protocols' weaknesses is only one part of the evaluation of our analysis approach and thereby of the investigation of real world protocols. This is the scientific contribution of our paper. The practical contribution of the analyzed messengers, which is the communication confidentiality for billion users (in most cases), is great and should be noted. Therefore we believe that being Signal, WhatsApp, or Threema by applying encryption to all messages and consequently risking research with negative results is much better than being a messenger that does not encrypt group messages end-to-end at all. We do not want to blame messengers that are far less secure (read Moxie's post [11] if you are interested).

Finally we want note that applying security measures according to the ticket approach (as we call it in the paper [12]) to the invitation links would solve the issues that Facebook's security head mentioned in his reply [13] on our findings. To our knowledge, adding authenticity to group update messages would not affect invitation links: If no invitation link was generated for a group, group members should only accept joining users if they were added by an authentic group update message. As soon as a group invitation link was generated, all joining users would need to be accepted as new group members with the current design. However there are plenty ways how WhatsApp could use invitation links without endowing the server with the power to manage groups without the group admins' permission:
One approach would be generating the invitation links secretly and sharing them without the knowledge of the server. An invitation link could then contain a secret ticket for the group and the ID of the group. As soon as a user, who received the link, wants to join the group, she can request the server with the group ID to obtain all current group members. The secret ticket can now be sent to all existing group members encrypted such that the legitimate join can be verified.

Of course this would require engineering but the capability of WhatsApp, shipping drastic protocol updates, can be assumed since they applied end-to-end encryption in the first place.

[1] https://www.youtube.com/watch?v=i5i38WlHfds
[2] https://www.wired.com/story/whatsapp-security-flaws-encryption-group-chats/
[3] http://www.spiegel.de/netzwelt/apps/whatsapp-gruppenchats-schwachstelle-im-verschluesselungs-protokoll-a-1187338.html
[4] http://www.sueddeutsche.de/digital/it-sicherheit-wie-fremde-sich-in-whatsapp-gruppenchats-einladen-koennen-1.3821656
[5] https://techcrunch.com/2018/01/10/security-researchers-flag-invite-bug-in-whatsapp-group-chats/
[6] http://www.telegraph.co.uk/technology/2018/01/10/whatsapp-bug-raises-questions-group-message-privacy/
[7] http://www.handelsblatt.com/technik/it-internet/verschluesselung-umgangen-forscher-finden-sicherheitsluecke-bei-whatsapp/20836518.html
[8] https://www.heise.de/security/meldung/WhatsApp-und-Signal-Forscher-beschreiben-Schwaechen-verschluesselter-Gruppenchats-3942046.html
[9] https://www.theinquirer.net/inquirer/news/3024215/whatsapp-bug-lets-anyone-easily-infiltrate-private-group-chats
[10] http://www.dailymail.co.uk/sciencetech/article-5257713/WhatsApp-security-flaw-lets-spy-private-chats.html
[11] https://news.ycombinator.com/item?id=16117487
[12] https://eprint.iacr.org/2017/713.pdf
[13] https://twitter.com/alexstamos/status/951169036947107840

Further articles:
- Matthew Green's blog post: https://blog.cryptographyengineering.com/2018/01/10/attack-of-the-week-group-messaging-in-whatsapp-and-signal/
- Schneier on Security: https://www.schneier.com/blog/archives/2018/01/whatsapp_vulner.html
- Bild: http://www.bild.de/digital/smartphone-und-tablet/whatsapp/whatsapp-sicherheitsluecke-in-gruppenchats-54452080.bild.html
- Sun: https://www.thesun.co.uk/tech/5316110/new-whatsapp-bug-how-to-stay-safe/

Related posts


  1. Viral Hacking
  2. Hacker En Español
  3. Libro Hacking Etico
  4. Que Es Hacker En Informatica
  5. Wargames Hacking