RSSAmplifier

Blog

Hack the Galaxy

Recent content on Hack the Galaxy

johnjhacking.comRSS feed ↗30 posts

Latest posts

CVE-2023-24068 && CVE-2023-24069: Abusing Signal Desktop Client for fun and for Espionage

Identification While using signal, it was observed that the preview of an image was still visible even after having deleted the image because the image had been “replied” to. After looking through multiple files, the culprit directory was identified. C:\Users\foo\AppData\Roaming\Signal\attachments.noindex\*\ To replicate, an image was sent in a group chat The image was stored as a…

OSCP Reborn - 2023 Exam Preparation Guide

OSCP Reborn - 2023 Exam Preparation Guide Prologue Many of you are likely aware that the Offensive Security Certified Professional Exam was revised, with the changes officially published on January 11, 2022. The old version of the exam required the student to perform a buffer overflow attack (it still may end up on your exam, but is not a guarantee). Since then, the model has shifted towards an…

Stealing Data with Zix - Bypassing Data Loss Prevention Policies

Background If you haven’t done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly after the spear phishing writeup, I discovered that Zix is also an excellent data…

Stealing Data with Zix - Bypassing Data Loss Prevention Policies

Background If you haven’t done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly after the spear phishing writeup, I discovered that Zix is also an excellent data…

Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT

Background Typically, organizations utilize Zix Secure Messaging as a convenient alternative to Dropbox or other file sharing related tools because it’s easier to share sensitive information with users outside of the organization. Shadow IT has always been a standing issue among large enterprises and the ability to securely share files and communications with vendors, clients, and colleagues…

The Ultimate CRTO Preparation Guide

The Ultimate CRTO Preparation Guide Understanding this Guide The CRTO (Certified Red Team Operator) course is offered through Zero Point Security. Originally, I had purchased the course when the exam was on version 1, and the entire course was organized in a different way. I stopped working on the course because I kept having issues with the initial access part of the lab environment because of…

An Open Letter to the Japanese Government on Cybersecurity

An Open Letter to the Japanese Government on Cybersecurity Credits John Github: https://github.com/johnjhacking Daichi Twitter: https://twitter.com/da1mshlomd Background Every nation that has grown in the Cybersecurity space has felt the woes of malicious threat actors exploiting their systems. The United States for instance, has felt the pain of continued occurrences of ransomware, with one of…

CVE-2022-27226: CSRF to RCE in iRZ Mobile Routers through 2022-03-16

Credits Vulnerability Discovery John Chris Mack Exploit Development Stephen Chavez Robert Willis Identification Default credentials were discovered on an iRZ Mobile Router login page. Utilizing root:root gave us access to the administrative functionality for the device. Having administrative access allows for various manipulation. Any setting that can be modified by an administrator was…

Google Earth Hacking - EaaS (Espionage as a Service)

Credits John Github: https://github.com/johnjhacking Molly White Twitter: https://twitter.com/molly0xFFF Zultan Twitter: https://twitter.com/orpheus9001 Summary First and foremost, we may have taken the phrase “Hack the Planet” a little too serious. Google Earth Enterprise is an application that is utilized by Scientific, Government, Military and Educational organizations. We…

The Ultimate Guide to Crashing Your Friend's Wedding - The Knot, Business Logic Flaw

Credits John Github: https://github.com/johnjhacking Robert Willis: Twitter: https://twitter.com/rej_ex Identification The Wedding websites that can be created with The Knot have many components built in. Among some of the functions included the ability to send out RSVP invites to friends or family. The websites that utilize RSVP can easily be identified: inurl:"theknot.com" intext:"rsvp-link"…

CVE-2021-40875: Improper Access Control in Gurock TestRail versions ≤ 7.2.0.3014 results in sensitive file exposure

Credits John Github: https://github.com/johnjhacking SickCodes Twitter: https://twitter.com/sickcodes Identification During research, I stumbled upon a TestRail application. While using Burp Suite to look at various requests and responses of the application, I noticed a files.md5 path: It seemed fairly normal at first, until I saw how massive the list was: I attempted to try some of the paths, and…

CVE-2021-24495: Improper Neutralization of Input During Web Page Generation on ‘id’ parameter in Wordpress Marmoset Viewer Plugin versions 1.9.3 ≤ leads to Reflected Cross Site Scripting

Credits John Github: https://github.com/johnjhacking Jackson Henry [Helped simplify the payload] Twitter: https://twitter.com/JacksonHHax Wabaf3t [Provided post-code analysis/looked for escalation] Twitter: https://twitter.com/wabafet1 Kelly Kaoudis [Reviewed the writeup] Twitter: https://twitter.com/kaoudis Robert Willis [Reviewed the writeup] Twitter: https://twitter.com/rej_ex Erwan [Identified…

Indian Government Breach, Disclosure

Indian Government Breach, Disclosure Last month, Sakura Samurai announced that we had uncovered a massive amount of critical vulnerabilities. Obviously, to prevent threat actors from exploiting the vulnerabilities, we ensured that we redacted the specific issues and only gave a brief overview on what we had discovered. After working with the NSCS, we have been given the green-light to disclose…

CVE-2021-23827: Sakura Samurai discover cleartext pictures in Keybase Desktop Client; Windows, macOS, Linux

Credits John Github: https://github.com/johnjhacking Aubrey Cottle Twitter: https://twitter.com/Kirtaner Jackson Henry Twitter: https://twitter.com/JacksonHHax Robert Willis Twitter: https://twitter.com/rej_ex Identification During security research, John Jackson stumbled upon the Keybase Client directories and decided to take a look considering Keybase operates a Bug Bounty Program. Within…

Indian Government Breached, Massive Amount of Critical Vulnerabilities

Indian Government Breach, Massive Amount of Critical Vulnerabilities Executive Summary Sakura Samurai knew that the Indian Government operated an RVDP (Responsible Vulnerability Disclosure Program). Jackson Henry put a list together of initial assets in scope for Sakura Samurai to legally test. Robert Willis reported that he had found sensitive data and was able to breach police assets. Jackson…

UNEP Breached, 100K+ Employee Records Accessed

United Nations Environment Programme Breached, 100K+ Employee Records Accessed Executive Summary We noticed that The United Nations had a Vulnerability Disclosure Program and a Hall of Fame, therefore Sakura Samurai 桜の侍 our security research group, set out to look for vulnerabilities to report to the United Nations. During the research process Jackson Henry @JacksonHHax , Nick Sahler, John…

CVE-2020-28360: npm private-ip SSRF Bypass (IP Phone Home)

Credits Sick.Codes Github: (https://github.com/sickcodes) Twitter: (https://twitter.com/sickcodes) John Github: (https://github.com/johnjhacking) Nick Sahler Github: (https://github.com/nicksahler) Twitter: (https://twitter.com/tensor_bodega) With Collaboration from: Harold Hunt LinkedIn: (https://www.linkedin.com/in/huntharo) Identification Over the course of several months, John dealt with…

Account Takeover on the Jack Daniel's Tennessee Squire Association Platform

Summary Many people do not know about the Jack Daniel’s Tennessee Squires. The Squire Association is an Elite Club for “friends of Jack Daniel’s”. Anyone that has ever dreamed of being a Tennessee Squire knows how difficult - if not impossible it is to obtain membership without paying thousands of dollars (or knowing someone who can nominate you). Tonight, I give you an…

CVE-2020-27388: YOURLS 1.5 - 1.7.10, Multiple Stored Cross Site Scripting (XSS) Vulnerabilities in Admin Panel

Potential Abuse on a hooked Function There is a potential for abuse with any plugins that implement the hook function ‘shunt_is_valid_user’. In the code below we simply demonstrate that authentication can be completely bypassed by returning TRUE in the hooked function. This would be an ideal place for a stealthy backdoor or any other malicious code. It should be noted that this itself is not a…

P1: Critical - Discovering and Foiling a Threat Actor

P1: Critical - Discovering and Foiling a Threat Actor Disclaimers, Credits: Thank you to everyone who helped validate any part of the project. It took a lot of work to figure out the extent of who was/is affected. I appreciate all of the help that we have received, with a special thank you to those who confirmed our suspicions. As a general rule of thumb, we will have to redact specific parts of…

The Ultimate OSCP Preparation Guide [DEPRECATED]

The Ultimate OSCP Preparation Guide [DEPRECATED] Update Notes This guide is now deprecated due to exam revisions made by Offensive Security on January 11, 2022. I published this guide on August 17th, of 2020. Offensive Security no longer requires the buffer overflow, and to pass this exam, you’ll have to understand Active Directory hacking. Since I’m not going to retake the OSCP to…

CEH Master, An Honest Review

Certified Ethical Hacker | Master The CEH Master offered by EC-Council, claims to be a real-world, hands-on approach to everyday life as an ethical hacker: In the above photo, what stood out the most to me was, “We test your abilities with real-world challenges in a real-world environment, and a time limit, just as you would find in your job.” The CEH Master is a combination of the CEH…

Linux Privilege Escalation: Quick and Dirty

Linux Privilege Escalation: Quick and Dirty Automated Tooling Usually, my approach is to use an automated tool in conjunction with some manual enumeration. However, you can completely accomplish the Privilege Escalation process from an automated tool paired with the right exploitation methodology. 1. Linpeas.sh (my go-to, fully automated)…

research1_section2

research3_Section3

research4_section1

research5_Section1

research6_section1

research7_section1

ressearch2_section3