jueves, 25 de mayo de 2023

Introduction To Reversing Golang Binaries


Golang binaries are a bit hard to analyze but there are some tricks to locate the things and view what is doing the code.






Is possible to list all the go files compiled in the binary even in an striped binaries, in this case we have only one file gohello.go this is a good clue to guess what is doing the program.


On stripped binaries the runtime functions are not resolved so is more difficult to locate the user algorithms:


If we start from the entry point, we will found this mess:

The golang string initialization are encoded and is not displayed on the strings window.


How to locate main?  if its not stripped just bp on [package name].main for example bp main.main, (you can locate the package-name searching strings with ".main")


And here is our main.main:


The code is:

So in a stripped binary we cant find the string "hello world" neither the initialization 0x1337 nor the comparator 0x1337, all this is obfuscated.

The initialization sequence is:


The procedure for locating main.main in stripped binaries is:
1. Click on the entry point and locate the runtime.mainPC pointer:



2. click on runtime.main function (LAB_0042B030):


3. locate the main.main call after the zero ifs:



4. click on it and here is the main:




The runtime is not obvious for example the fmt.Scanf() call perform several internal calls until reach the syscall, and in a stripped binary there are no function names.



In order to identify the functions one option is compile another binary with symbols and make function fingerprinting.

In Ghidra we have the script golang_renamer.py which is very useful:


After applying this plugin the main looks like more clear:




This script is an example of function fingerprinting, in this case all the opcodes are included on the crc hashing:
# This script fingerprints the functions
#@author: sha0coder
#@category fingerprinting

print "Fingerprinting..."

import zlib


# loop through program functions
function = getFirstFunction()
while function is not None:
name = str(function.getName())
entry = function.getEntryPoint()
body = function.getBody()
addresses = body.getAddresses(True)

if not addresses.hasNext():
# empty function
continue

ins = getInstructionAt(body.getMinAddress())
opcodes = ''
while ins and ins.getMinAddress() <= body.getMaxAddress():
for b in ins.bytes:
opcodes += chr(b & 0xff)
ins = getInstructionAfter(ins)
crchash = zlib.crc32(opcodes) & 0xffffffff

print name, hex(crchash)


function = getFunctionAfter(function)





More information


Ambermoon: Frankreich Ist Speck

A pretty well in the center of town. I just haven't been able to find anything to do with it.
          
It is sixty years after the events of Amberstar. The hero is the granddaughter of the first game's hero, born two decades ago, just as the third moon fell out of orbit and crashed into the world of Lyramion. Orphaned during the devastation, she was raised by her grandfather, who is now on his deathbed. He has sent her from home on a vague quest to "find out what is happening . . . and what risks there are to you and life on Lyramion." To be successful in this quest, she'll need some magic armor, currently buried beneath a pile of rubble in her grandfather's basement. She has thus traveled west to the nearby city of Spannenberg, which has been invaded by bandits. They've stolen four golden horseshoes from the farrier, Tolimar. He'll give the heroine the tools she needs if she'll recover the shoes.
   
And thus this chapter opens in Spannenberg, which I think means something like "stretchy mountain" in German. The small city has a park with a well in its center. Ringed around the edges are a tavern, a stable, a food store, a general store, a healer, a training center, city hall, Baron George's compound, and a couple of private residences. 
     
Too bad I don't have Spike from the last game.
    
If you've played modern games like the Fallout series, the Elder Scrolls series, or the Dragon Age series, you've had this experience a thousand times: You visit a city for one reason and leave with a dozen main quests, side quests, and miscellaneous objectives. Ambermoon might be the earliest example of this common trope, albeit without an in-game quest list. That omission is fine with me, as I enjoy--prefer, even--keeping my own notes and quest lists. This is my list after my Spannenberg visit, including a couple items I had before I arrived:
    
  • Find some location to use Shandra's Amber to make contact with him.
  • Get tools from the Spannenberg stables to clear the rubble in grandfather's basement.
  • Recover the four stolen golden horseshoes for the owner of the Spannenberg stables.
  • Find the bandit camp in the desert north of Spannenberg and end the threat to the city.
  • Find the treasure that the bandits are searching for in the desert.
  • Deal with the band of orcs raiding the city from the mountains to the west.  
     
Lots of NPC dialogue about these orcs.
     
  • Investigate the supposed magic powers of the well at the center of the city.
  • Retrieve a brooch from the gardener in the graveyard, take it to the Thieves' Guild for entrance.
  • Put to rest the undead that the gardener, Gordon, has been raising.
  • Retrieve the golden wine goblets stolen from married couple Canth and Noralael, the first by a green creature with wings, the second by two bandits. 
  • The Baron is missing his chain of office. His wife, Lady Heidi, woke up to observe a couple of blue-green winged fairies gamboling about her house. She followed them to a cave west of town.
  • Explore an old crypt far to the north, near the Tower of the Alchemist, where powerful magicians (and perhaps their artifacts) are buried.
  • A man named Wat the Fisher is at the bedside of his daughter, who is dying of swamp fever. He wants me to ask Father Anthony about an antidote.
  • The healer, Sandra, hasn't heard anything lately from her daughter, Sabine, who practices in Burnville on an island to the south.
     
I guess when I find Sabine, she'll give me the cat's name.
     
  • The shipbuilder, Captain Torle, is also missing in Burnville. Without him, no new ships can be built.
  • Father Anthony has closed the Spring of Life, because of the orc threat, the bandit threat, or both.
  • An elf named Sandire is wandering around town, claiming she's been robbed by bandits. She's trying to sell a "Monster Eye," which tells you if monsters are following you, but she wants 5,000 gold.
     
The bandits are clearly the "main quest." Not only do I have to slay them to get the horseshoes and thus the tools, Baron George himself asked me to do so when I visited his office. He also asked me to deal with the orcs. 
      
The Baron has some amazing floor art.
      
The bandits are headquartered north of town in the desert, looking for some kind of treasure. The Baron says they're led by someone named Silverhand. He says that the masters of the Thieves' Guild have disavowed any relationship with the bandits, though he's not so sure. 
   
I find the town's graveyard during my explorations, and I'm attacked by a couple of zombies. My sword does nothing to them as they tear me apart with bows and blades. I'll have to return when stronger.
       
This did not end well.
       
In the "training centre," I find the first NPC who will join my party, a Level 1 human fighter named Egil. He's after the fortune and glory that the Baron has promised. He comes with padded armor, a long sword, a buckler, sandals, and a few potions.   
       
The first ally willing to put his sword where his mouth is.
   
The training center gives me my first taste of character development. It appears that every trainer specializes in a particular skill. This training center has two: attacking and parrying. Each point that you train costs 20 gold (at least, in this center), and each raises the associated skill by 1 point. I spend 5 on "Attacking" and 5 on "Parrying" and save the rest for now.
      
Half an hour every morning.
      
I haven't been noticing how training points increase per level. I started with 6 and got 5 when I hit Level 2, then somehow got 14 more in three levels. Maybe it's random. Similarly, my maximum hit points went up by 10 between Level 1 and Level 2 but then only 18 more between Levels 2 and 5. Attributes have not budged. The manual, I should note, has little to offer about these issues.
 
Next to the training center is a building housing the "Wise Men of Spannenberg." Their sign has some runes that I guess I haven't found the in-game document required to translate. One of them will identify items; the other sells spells. I'm a little bit confused as to how spells work in this game, and most of the scrolls are out of my price range, so I leave it for now.
    
I've been looting weapons and armor from the bandits. I'm eager to sell them to the merchant. I visit his store and he buys a dagger for 11 gold, then refuses to buy anything else that I have. But then I buy a rune table from him, and suddenly he's happy to buy all my excess stuff. Weird. I use the rune table, and it tells me that I can use the table of runes included in the package. Yay! The mage's guild sign translates as: "KNOWLEDGE IS POWER." Indeed.
       
Still can't use the map, though.
        
I'm not sure what to do with the well in the center of town. I figured it might be the place where I'm supposed to commune with Shandra, as the well, according to an NPC, was "built by a powerful magician when the town was founded." But using the amber doesn't accomplish anything there. I can't get anything to happen with the "Look" or "Grasp" buttons, either.
   
The House of Healing is the largest building in town. It has an inn, a scroll-seller, several NPCs recovering from wounds inflicted by orcs and bandits, and a healer named Sandra. The aforementioned Father Anthony is not here, having gone to administer last rites to a resident somewhere. One of the NPCs mentions that some orcs broke the wings on a "green fairy" and dragged her off; I'm not sure how this might relate to the various quests involving fairies. Perhaps they're compelling fairies to do their bidding by holding one of them hostage. 
      
Oh, my darlin'. . .
    
The healers' cook, Clementine, tells me of a mad mage in a cell in the basement. He arrived on the island after the Great Disaster, carrying half an amulet and a torn robe. Some farmers cared for him, but he's grown increasingly violent over the years. Clementine warns me not to approach him and to speak to him only through the bars. We head down, easily defeat some giant spiders at the foot of the stairs, and wander into the mage's room just in time to see him fireball a stray mouse. He cackles at us but doesn't respond to any dialogue options. A chest with his amulet is in a nearby room, but it's locked and I have no way to open it. I suppose this is a quest for later.
     
Egil and I head outside. We travel west into the mountains, round a volcano, and encounter a band of orcs. The leader is commanding his troops to search for more of "those bright-winged beings." By torturing one of them, they apparently found that they live in a cave in the area. They attack when they see us. Qamar is killed in the first round and Egil doesn't last much longer.  
      
Does this mean that Egil can continue the quest without the main character?
       
Reloading, I return to the merchant and splurge on some chain armor and leather boots. While I'm back in town, for no reason other than I don't want to remember it later, I spend 200 gold on horses. This puts a little horse icon outside of town, which you have to remember to mount when you leave. 
      
This is so cute.
      
Miscellaneous notes:
   
  • Either the bandit encounters occur at fixed points or their overall number is fixed. At some point, I stopped encountering them.
  • The game requires a certain amount of time to pass between rests. You can't rest just because you want the night to pass. This can make outdoor exploration annoying if you time things poorly.
       
My character is incapable of just passing time without sleeping.
      
  • If you try self-typed keywords in NPC dialogue, they remain in the dialogue list if they're words that someone, somewhere will respond to.
       
AMBER and AMULET got me no results with the madman, but they stayed on the list.
      
  • I keep being surprised at how non-interactive the overhead view of the game is. The houses and buildings have a lot of interesting objects, and I keep expecting that you should be able to do things with them, I guess since the game feels so much like an Ultima.
       
I feel like I should be able to do more here.
      
  • The "continuous" 3D interface is extremely cumbersome. It is too slow with a keyboard, comically fast with the mouse, and too easy to get turned around and lost with either method. Since the world is not interactive, there's really no need for it except that someone thought that it looked cool.
  • Mitigating the interface somewhat is the excellent automap with its fast travel options.
       
Once you've explored a map once, you hardly ever have to walk through it again. The fast travel points are copious.
     
I either have to get past one of these enemy obstacles or find some place to grind. I seem to remember that finding easy early-game combats was an issue in Amberstar, too. I'll probably head back to the cemetery next and see if my new equipment and skill points avail me at all against the zombies.
       
Maybe I'll do better this time.
        
I apologize for the long break before this entry--it was just a series of things that robbed me of my free time. May is a great time to start playing again, though. The weather is warm and sunny here in Maine, and nothing takes me back to my childhood more than sitting in a dark room playing a CRPG while a woman periodically tells me that I'm wasting a beautiful day indoors. Let's get on to the summer and waste plenty more!
    
Time so far: 6 hours
   

Playing With TLS-Attacker

In the last two years, we changed the TLS-Attacker Project quite a lot but kept silent about most changes we implemented. Since we do not have so much time to keep up with the documentation (we are researchers and not developers in the end), we thought about creating a small series on some of our recent changes to the project on this blog.


We hope this gives you an idea on how to use the most recent version (TLS-Attacker 2.8). If you feel like you found a bug, don't hesitate to contact me via GitHub/Mail/Twitter. This post assumes that you have some idea what this is all about. If you have no idea, checkout the original paper from Juraj or our project on GitHub.

TLDR: TLS-Attacker is a framework which allows you to send arbitrary protocol flows.


Quickstart:
# Install & Use Java JDK 8
$ sudo apt-get install maven
$ git clone https://github.com/RUB-NDS/TLS-Attacker
$ cd TLS-Attacker
$ mvn clean package

So, what changed since the release of the original paper in 2016? Quite a lot! We discovered that we could make the framework much more powerful by adding some new concepts to the code which I want to show you now.

Action System

In the first Version of TLS-Attacker (1.x), WorkflowTraces looked like this:
Although this design looks straight forward, it lacks flexibility. In this design, a WorkflowTrace is basically a list of messages. Each message is annotated with a <messageIssuer>, to tell TLS-Attacker that it should either try to receive this message or send it itself. If you now want to support more advanced workflows, for example for renegotiation or session resumption, TLS-Attacker will soon reach its limits. There is also a missing angle for fuzzing purposes. TLS-Attacker will by default try to use the correct parameters for the message creation, and then apply the modifications afterward. But what if we want to manipulate parameters of the connection which influence the creation of messages? This was not possible in the old version, therefore, we created our action system. With this action system, a WorkflowTrace does not only consist of a list of messages but a list of actions. The most basic actions are the Send- and ReceiveAction. These actions allow you to basically recreate the previous behavior of TLS-Attacker 1.x . Here is an example to show how the same workflow would look like in the newest TLS-Attacker version:


As you can see, the <messageIssuer> tags are gone. Instead, you now indicate with the type of action how you want to deal with the message. Another important thing: TLS-Attacker uses WorkflowTraces as an input as well as an output format. In the old version, once a WorkflowTrace was executed it was hard to see what actually happened. Especially, if you specify what messages you expect to receive. In the old version, your WorkflowTrace could change during execution. This was very confusing and we, therefore, changed the way the receiving of messages works. The ReceiveAction has a list of <expectedMessages>. You can specify what you expect the other party to do. This is mostly interesting for performance tricks (more on that in another post), but can also be used to validate that your workflow executedAsPlanned. Once you execute your ReceiveAction an additional <messages> tag will pop up in the ReceiveAction to show you what has actually been observed. Your original WorkflowTrace stays intact.


During the execution, TLS-Attacker will execute the actions one after the other. There are specific configuration options with which you can control what TLS-Attacker should do in the case of an error. By default, TLS-Attacker will never stop, and just execute whatever is next.

Configs

As you might have seen the <messageIssuer> tags are not the only thing which is missing. Additionally, the cipher suites, compression algorithms, point formats, and supported curves are missing. This is no coincidence. A big change in TLS-Attacker 2.x is the separation of the WorkflowTrace from the parameter configuration and the context. To explain how this works I have to talk about how the new TLS-Attacker version creates messages. Per default, the WorkflowTrace does not contain the actual contents of the messages. But let us step into TLS-Attackers point of view. For example, what should TLS-Attacker do with the following WorkflowTrace:

Usually, the RSAClientKeyExchange message is constructed with the public key from the received certificate message. But in this WorkflowTrace, we did not receive a certificate message yet. So what public key are we supposed to use? The previous version had "some" key hardcoded. The new version does not have these default values hardcoded but allows you as the user to define the default values for missing values, or how our own messages should be created. For this purpose, we introduced the new concept of Configs. A Config is a file/class which you can provide to TLS-Attacker in addition to a WorkflowTrace, to define how TLS-Attacker should behave, and how TLS-Attacker should create its messages (even in the absence of needed parameters). For this purpose, TLS-Attacker has a default Config, with all the known hardcoded values. It is basically a long list of possible parameters and configuration options. We chose sane values for most things, but you might have other ideas on how to do things. You can execute a WorkflowTrace with a specific config. The provided Config will then overwrite all existing default values with your specified values. If you do not specify a certain value, the default value will be used. I will get back to how Configs work, once we played a little bit with TLS-Attacker.

TLS-Attacker ships with a few example applications (found in the "apps/" folder after you built the project). While TLS-Attacker 1.x was mostly a standalone tool, we currently see TLS-Attacker more as a library which we can use by our more sophisticated projects. The current example applications are:
  • TLS-Client (A TLS-Client to execute WorkflowTraces with)
  • TLS-Server (A TLS-Server to execute WorkflowTraces with)
  • Attacks (We'll talk about this in another blog post)
  • TLS-Forensics (We'll talk about this in another blog post)
  • TLS-Mitm (We'll talk about this in another blog post)
  • TraceTool (We'll talk about this in another blog post) 

TLS-Client

The TLS-Client is a simple TLS-Client. Per default, it executes a handshake for the default selected cipher suite (RSA). The only mandatory parameter is the server you want to connect to (-connect).

The most trivial command you can start it with is:

Note: The example tool does not like "https://" or other protocol information. Just provide a hostname and port

Depending on the host you chose your output might look like this:

or like this:

So what is going on here? Let's start with the first execution. As I already mentioned. TLS-Attacker constructs the default WorkflowTrace based on the default selected cipher suite. When you run the client, the WorkflowExecutor (part of TLS-Attacker which is responsible for the execution of a WorkflowTrace) will try to execute the handshake. For this purpose, it will first start the TCP connection.
This is what you see here:

After that, it will execute the actions specified in the default WorkflowTrace. The default WorkflowTrace looks something like this:
This is basically what you see in the console output. The first action which gets executed is the SendAction with the ClientHello.

Then, we expect to receive messages. Since we want to be an RSA handshake, we do not expect a ServerKeyExchange message, but only want a ServerHello, Certificate and a ServerHelloDone message.

We then execute the second SendAction:

and finally, we want to receive a ChangeCipherSpec and Finished Message:

In the first execution, these steps all seem to have worked. But why did they fail in the second execution? The reason is that our default Config does not only allow specify RSA cipher suites but creates ClientHello messages which also contain elliptic curve cipher suites. Depending on the server you are testing with, the server will either select and RSA cipher suite, or an elliptic curve one. This means, that the WorkflowTrace will not executeAsPlanned. The server will send an additional ECDHEServerKeyExchange. If we would look at the details of the ServerHello message we would also see that an (ephemeral) elliptic curve cipher suite is selected:

Since our WorkflowTrace is configured to send an RSAClientKeyExchange message next, it will just do that:

Note: ClientKeyExchangeMessage all have the same type field, but are implemented inside of TLS-Attacker as different messages

Since this RSAClientKeyExchange does not make a lot of sense for the server, it rejects this message with a DECODE_ERROR alert:

If we would change the Config of TLS-Attacker, we could change the way our ClientHello is constructed. If we specify only RSA cipher suites, the server has no choice but to select an RSA one (or immediately terminate the connection). We added command line flags for the most common Config changes. Let's try to change the default cipher suite to TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA:

As you can see, we now executed a complete ephemeral elliptic curve handshake. This is, because the -cipher flag changed the <defaultSelectedCiphersuite> parameter (among others) in the Config. Based on this parameter the default WorkflowTrace is constructed. If you want, you can specify multiple cipher suites at once, by seperating them with a comma.

We can do the same change by supplying TLS-Attacker with a custom Config via XML. To this we need to create a new file (I will name it config.xml) like this:

You can then load the Config with the -config flag:

For a complete reference of the supported Config options, you can check out the default_config.xml. Most Config options should be self-explanatory, for others, you might want to check where and how they are used in the code (sorry).

Now let's try to execute an arbitrary WorkflowTrace. To do this, we need to store our WorkflowTrace in a file and load it with the -workflow_input parameter. I just created the following WorkflowTrace:


As you can see I just send a ServerHello message instead of a ClientHello message at the beginning of the handshake. This should obviously never happen but let's see how the tested server reacts to this.
We can execute the workflow with the following command:

The server (correctly) responded with an UNEXPECTED_MESSAGE alert. Great!

Output parameters & Modifications

You are now familiar with the most basic concepts of TLS-Attacker, so let's dive into other things TLS-Attacker can do for you. As a TLS-Attacker user, you are sometimes interested in the actual values which are used during a WorkflowTrace execution. For this purpose, we introduced the -workflow_output flag. With this parameter, you can ask TLS-Attacker to store the executed WorkflowTrace with all its values in a file.
Let's try to execute our last created WorkflowTrace, and store the output WorkflowTrace in the file out.xml:


The resulting WorkflowTrace looks like this:

As you can see, although the input WorkflowTrace was very short, the output trace is quite noisy. TLS-Attacker will display all its intermediate values and modification points (this is where the modifiable variable concept becomes interesting). You can also execute the output workflow again.


Note that at this point there is a common misunderstanding: TLS-Attacker will reset the WorkflowTrace before it executes it again. This means, it will delete all intermediate values you see in the WorkflowTrace and recompute them dynamically. This means that if you change a value within <originalValue> tags, your changes will just be ignored. If you want to influence the values TLS-Attacker uses, you either have to manipulate the Config (as already shown) or apply modifications to TLS-Attackers ModifiableVariables. The concept of ModifiableVariables is mostly unchanged to the previous version, but we will show you how to do this real quick anyway.

So let us imagine we want to manipulate a value in the WorkflowTrace using a ModifiableVariable via XML. First, we have to select a field which we want to manipulate. I will choose the protocol version field in the ServerHello message we sent. In the WorkflowTrace this looked like this:

For historical reasons, 0x0303 means TLS 1.2. 0x0300 was SSL 3. When they introduced TLS 1.0 they chose 0x0301 and since then they just upgraded the minor version.

In order to manipulate this ModifiableVariable, we first need to know its type. In some cases it is currently non-trivial to determine the exact type, this is mostly undocumented (sorry). If you don't know the exact type of a field you currently have to look at the code. The following types and modifications are defined:
  • ModifiableBigInteger: add, explicitValue, shiftLeft, shiftRight, subtract, xor
  • ModifiableBoolean: explicitValue, toggle
  • ModifiableByteArray: delete, duplicate, explicitValue, insert, shuffle, xor
  • ModifiableInteger: add, explicitValue, shiftLeft, shiftRight, subtract, xor
  • ModifiableLong: add, explicitValue, subtract, xor
  • ModifiableByte: add, explicitValue, subtract, xor
  • ModifiableString: explicitValue
As a rule of thumb: If the value is only up to 1 byte of length we use a ModifiableByte. If the value is up to 4 bytes of length, but the values are used as a normal number (for example in length fields) it is a ModifiableInteger. Fields which are used as a number which are bigger than 4 bytes (for example a modulus) is usually a ModifiableBigInteger. Most other types are encoded as ModifiableByteArrays. The other types are very rare (we are currently working on making this whole process more transparent).
Once you have found your type you have to select a modification to apply to it. For manual analysis, the most common modifications are the XOR modification and the explicit value modification. However, during fuzzing other modifications might be useful as well. Often times you just want to flip a bit and see how the server responds, or you want to directly overwrite a value. In this example, we want to overwrite a value.
Let us force TLS-Attacker to send the version 0x3A3A. To do this I consult the ModifiableVariable README.md for the exact syntax. Since <protocolVersion> is a ModifiableByteArray I search in the ByteArray section.

I find the following snippet:

If I now want to change the value to 0x3A3A I modify my WorkflowTrace like this:

You can then execute the WorkflowTrace with:

With Wireshark you can now observe  that the protocol version got actually changed. You would also see the change if you would specify a -workflow_output or if you start the TLS-Client with the -debug flag.

More Actions

As I already hinted, TLS-Attacker has more actions to offer than just a basic Send- and ReceiveAction (50+ in total). The most useful, and easiest to understand actions are now introduced:

ActivateEncryptionAction

This action does basically what the CCS message does. It activates the currently "negotiated" parameters. If necessary values are missing in the context of the connection, they are drawn from the Config.


DeactivateEncryptionAction

This action does the opposite. If the encryption was active, we now send unencrypted again.


PrintLastHandledApplicationDataAction

Prints the last application data message either sent or received.


PrintProposedExtensionsAction

Prints the proposed extensions (from the client)


PrintSecretsAction

Prints the secrets (RSA) from the current connection. This includes the nonces, cipher suite, public key, modulus, premaster secret, master secret and verify data.


RenegotiationAction

Resets the message digest. This is usually done if you want to perform a renegotiation.


ResetConnectionAction

Closes and reopens the connection. This can be useful if you want to analyze session resumption or similar things which involve more than one handshake.


SendDynamicClientKeyExchangeAction

Send a ClientKeyExchange message, and always chooses the correct one (depending on the current connection state). This is useful if you just don't care about the actual cipher suite and just want the handshake done.


SendDynamicServerKeyExchangeAction

(Maybe) sends a ServerKeyExchange message. This depends on the currently selected cipher suite. If the cipher suite requires the transmission of a ServerKeyExchange message, then a ServerKeyExchange message will be sent, otherwise, nothing is done. This is useful if you just don't care about the actual cipher suite and just want the handshake done.


WaitAction

This lets TLS-Attacker sleep for a specified amount of time (in ms).





As you might have already seen there is so much more to talk about in TLS-Attacker. But this should give you a rough idea of what is going on.

If you have any research ideas or need support feel free to contact us on Twitter (@ic0nz1, @jurajsomorovsky ) or at https://www.hackmanit.de/.

If TLS-Attacker helps you to find a bug in a TLS implementation, please acknowledge our tool(s). If you want to learn more about TLS, Juraj and I are also giving a Training about TLS at Ruhrsec (27.05.2019).
More articles

  1. What Are Hacking Tools
  2. Hack Rom Tools
  3. Pentest Tools Review
  4. Pentest Tools List
  5. Hacking Tools Free Download
  6. Pentest Recon Tools
  7. Hacking Tools Kit
  8. Pentest Tools Kali Linux
  9. Hacking Tools Name
  10. How To Make Hacking Tools
  11. Pentest Box Tools Download
  12. Hacker Tools For Windows
  13. Pentest Tools Url Fuzzer
  14. Hacking Tools Hardware
  15. Computer Hacker
  16. Hacker Hardware Tools
  17. Hacking Tools 2019
  18. How To Make Hacking Tools
  19. Hacking Tools Download
  20. Hack And Tools
  21. Hacker Tools
  22. Pentest Tools Download
  23. Hacker Search Tools
  24. Hack Tools Online
  25. Game Hacking
  26. Hacker Tools
  27. Github Hacking Tools
  28. How To Hack
  29. Hack Tools Pc
  30. Pentest Tools Download
  31. Hacker Tools Apk Download
  32. Pentest Tools Github
  33. Usb Pentest Tools
  34. Pentest Recon Tools
  35. Hacker Tools List
  36. Pentest Tools Alternative
  37. Hacking Tools Windows
  38. Hack Website Online Tool
  39. Hacking Tools For Games
  40. Usb Pentest Tools
  41. Hacking Tools Kit
  42. Hacker Tools Software
  43. Hack Tools For Games
  44. Bluetooth Hacking Tools Kali
  45. Hack Tool Apk No Root
  46. Pentest Tools For Windows
  47. Hacking Tools For Windows 7
  48. Hacker Tools For Pc
  49. Pentest Tools Kali Linux
  50. Tools Used For Hacking
  51. Hacking Tools Software
  52. Hack Tools
  53. Pentest Tools Website
  54. Tools For Hacker
  55. Hack Tools For Mac
  56. Nsa Hack Tools
  57. Usb Pentest Tools
  58. Hack Tools For Games
  59. Tools 4 Hack
  60. Hacking Tools
  61. Hacking Apps
  62. Hack Website Online Tool

miércoles, 24 de mayo de 2023

Urge You To Treat It Genuinely.

FEDERAL BUREAU OF INVESTIGATION

NOTE: If you received this message in your SPAM/BULK/JUNK folder that is because of the restrictions implemented by your Internet Service Provider we the (Federal Bureau of Investigation) Urge You To Treat It Genuinely.

Federal Bureau of Investigation
Anti-Terrorist and Cyber Crime Division
J. Edgar Hoover Building
935 Pennsylvania Avenue,
NW, Washington, D.C
20535-0001, USA
http://oag.ca.gov/bi

Service Hours / Monday to Saturday:

Attention

We bring to your notice that your Email address has been in our database of scammed victims for a long time, Due to complains by individuals and Governmental agencies, an emergency meeting was held at the United Nation Building in New York with the general secretary of the United Nation Antуnio Guterres. And Heads of the Federal Bureau of Investigation (F.B.I) and Cyber Crime Division. You were randomly selected to be compensated, that is why we are in contact with you so take your time to read this information carefully. Series of meetings have been held over the past 4 months with the secretary General of the United Nations, which Ended 4days ago. It is obvious that you have not received your funds valued at $2.5 Million US dollars, due to past corrupt governmental officials who almost held the funds to them self for their selfish reasons.

The National Central Bureau of Interpol enhanced by the United Nations and Federal Bureau of Investigation, have successfully passed A mandate to the president of the United States of America and United Kingdom to boost the Exercise of clearing all foreign debts Owed to individuals and organizations, Who have not Receive their Funds yet to effect the release of your fund Valued at $2.5Million US Dollars, You are advised to contact F.B.I funds Transfer agent Mr. Smith Anderson with The information below,
Name: Agent Smith Anderson
Email: AAderwe845@gmail.com
You are advised to contact him with the information's as Stated Below:

1. Full Name:
2. Delivery Address:
3. Phone:
4. Fax Number:
6. Age:
7. Marital Status:
8. Country:
9. Occupation:
10. Preferred Payment Method (ATM / Cashier Check)



Do disregard any email you get from any impostors or offices claiming to be in possession of your ATM CARD, you are hereby advices only to be in contact with your assigned F.B.I funds transfer agent Mr. Smith Anderson. Forward any emails you get from impostors to his office so we could act upon and commence Investigation.
CC. TO:
Supreme Court of the United States

U. S. Courts of Appeals
U. S. District Courts
U. S. Circuit Courts

Courts of Special Jurisdiction

Bankruptcy Courts
Court of Claims, 1855 - 1982
U. S. Court of Federal Claims, 1982 -
Customs Court, 1890 - 1980
U. S. Court of Customs and Patent Appeals, 1910 -

1982
U. S. Court of International Trade, 1980 -
Commerce Court, 1910 - 1913

Territorial Courts

Courts of the District of Columbia
Temporary Emergency Court of Appeals
Judicial Panel on Multi-District Litigation `
Foreign Intelligence Surveillance Court
Federal Courts outside the Judiciary

Note: This email is fully under supervision of the FBI and will be until your funds have been remitted to you, Meanwhile we urge you to treat the above requirement with utmost urgency to enable us dispense our duties and obligation accordingly thereby allowing us to serve you in a timely fashion. Upon satisfactory receipt of all the above mentioned, you will be further acquainted with the detailed delivery itinerary including information of the diplomat who will accompany your consignment.

Yours sincerely,
Christopher A. Wray
FEDERAL BUREAU OF INVESTIGATION
UNITED STATES, DEPARTMENT OF JUSTICE
J. Edgar. Hoover Building
935 Pennsylvania Avenue,
Nw Washington, D.C.
20535-0001, USA

-----------------------------------------------------------------WARNING------------------------------------------------------
This Communication is from the Federal Bureau of Investigation, beneficiaries are advised to adhere strictly to directives. Any fund beneficiary who ignores instructions will be doing so at his/her own risk.© 2023 Federal Bureau of Investigation

jueves, 18 de mayo de 2023

Urge You To Treat It Genuinely.

FEDERAL BUREAU OF INVESTIGATION

NOTE: If you received this message in your SPAM/BULK/JUNK folder that is because of the restrictions implemented by your Internet Service Provider we the (Federal Bureau of Investigation) Urge You To Treat It Genuinely.

Federal Bureau of Investigation
Anti-Terrorist and Cyber Crime Division
J. Edgar Hoover Building
935 Pennsylvania Avenue,
NW, Washington, D.C
20535-0001, USA
http://oag.ca.gov/bi

Service Hours / Monday to Saturday:

Attention

We bring to your notice that your Email address has been in our database of scammed victims for a long time, Due to complains by individuals and Governmental agencies, an emergency meeting was held at the United Nation Building in New York with the general secretary of the United Nation Antуnio Guterres. And Heads of the Federal Bureau of Investigation (F.B.I) and Cyber Crime Division. You were randomly selected to be compensated, that is why we are in contact with you so take your time to read this information carefully. Series of meetings have been held over the past 4 months with the secretary General of the United Nations, which Ended 4days ago. It is obvious that you have not received your funds valued at $2.5 Million US dollars, due to past corrupt governmental officials who almost held the funds to them self for their selfish reasons.

The National Central Bureau of Interpol enhanced by the United Nations and Federal Bureau of Investigation, have successfully passed A mandate to the president of the United States of America and United Kingdom to boost the Exercise of clearing all foreign debts Owed to individuals and organizations, Who have not Receive their Funds yet to effect the release of your fund Valued at $2.5Million US Dollars, You are advised to contact F.B.I funds Transfer agent Mr. Smith Anderson with The information below,
Name: Agent Smith Anderson
Email: AAderwe845@gmail.com
You are advised to contact him with the information's as Stated Below:

1. Full Name:
2. Delivery Address:
3. Phone:
4. Fax Number:
6. Age:
7. Marital Status:
8. Country:
9. Occupation:
10. Preferred Payment Method (ATM / Cashier Check)



Do disregard any email you get from any impostors or offices claiming to be in possession of your ATM CARD, you are hereby advices only to be in contact with your assigned F.B.I funds transfer agent Mr. Smith Anderson. Forward any emails you get from impostors to his office so we could act upon and commence Investigation.
CC. TO:
Supreme Court of the United States

U. S. Courts of Appeals
U. S. District Courts
U. S. Circuit Courts

Courts of Special Jurisdiction

Bankruptcy Courts
Court of Claims, 1855 - 1982
U. S. Court of Federal Claims, 1982 -
Customs Court, 1890 - 1980
U. S. Court of Customs and Patent Appeals, 1910 -

1982
U. S. Court of International Trade, 1980 -
Commerce Court, 1910 - 1913

Territorial Courts

Courts of the District of Columbia
Temporary Emergency Court of Appeals
Judicial Panel on Multi-District Litigation `
Foreign Intelligence Surveillance Court
Federal Courts outside the Judiciary

Note: This email is fully under supervision of the FBI and will be until your funds have been remitted to you, Meanwhile we urge you to treat the above requirement with utmost urgency to enable us dispense our duties and obligation accordingly thereby allowing us to serve you in a timely fashion. Upon satisfactory receipt of all the above mentioned, you will be further acquainted with the detailed delivery itinerary including information of the diplomat who will accompany your consignment.

Yours sincerely,
Christopher A. Wray
FEDERAL BUREAU OF INVESTIGATION
UNITED STATES, DEPARTMENT OF JUSTICE
J. Edgar. Hoover Building
935 Pennsylvania Avenue,
Nw Washington, D.C.
20535-0001, USA

-----------------------------------------------------------------WARNING------------------------------------------------------
This Communication is from the Federal Bureau of Investigation, beneficiaries are advised to adhere strictly to directives. Any fund beneficiary who ignores instructions will be doing so at his/her own risk.© 2023 Federal Bureau of Investigation

lunes, 15 de mayo de 2023

Your account is hacked. Your data is stolen. Learn how to regain access.

Hi,

I am a hacker, and I have successfully gained access to your operating system.
I also have full access to your account.

When I hacked into your account, your password was: ghtwaycsco

I've been watching you for a few months now.

The fact is that your computer has been infected with malware through an adult site that you visited.
If you are not familiar with this, I will explain.
Trojan Virus gives me full access and control over a computer or other device.
This means that I can see everything on your screen, turn on the camera and microphone, but you do not know about it.
I also have access to all your contacts and all your correspondence.

Why did your antivirus not detect malware?
Answer: The malware I used is driver-based, I update its signatures every 4 hours. Hence your antivirus is unable to detect its presence.
I made a video showing how you satisfy yourself in the left half of the screen, and the right half shows the video you were watching at the time.

With one mouse click, I can send this video to all your emails and contacts on your social networks.
I can also make public all your e-mail correspondence and chat history on the messengers that you use.

If you don't want this to happen, transfer $1350 in Bitcoin equivalent to my Bitcoin address (if you do not know how to do this, just search "buy bitcoin" on Google).

My Bitcoin address (BTC Wallet) is: 1MTn8ubF6VBkyjx5eHxX133RumyLzHHmy3

After confirming your payment, I will delete the video immediately, and that's it. You will never hear from me again.
I will give you 50 hours (more than 2 days) to pay. I will get a notice, when you open this email, and the timer will start.
Filing a complaint somewhere does not make sense because this email cannot be tracked like my Bitcoin address.

I never make any mistakes.
If I find that you have shared this message with someone else, the video will be immediately distributed.

Best regards!

jueves, 11 de mayo de 2023

Re : Dobrý den,

Dobrэ den,
Omlouvбm se za tento zpusob kontaktovбnн, jen jsem videl vбљ profil a myslel jsem, ћe jste osoba, kterou potrebuji. Strucne receno, mй jmйno je Jacques BOUCHEX, francouzskйho puvodu. Trpнm vбћnou nemocн, kterб me odsuzuje k jistй smrti, rakovinou mozku, a disponuji cбstkou dvacet pet milionu pet set tisнc eur (25 500 000 eur), kterou chci predat spolehlivй a cestnй tretн strane k jejнmu rбdnйmu vyuћitн. Mбm spolecnost, kterб dovбћн cervenэ olej do Francie a dalљнch zemн. Pred deseti lety jsem pri neљtastnй dopravnн nehode priљel o manћelku a dve milovanй deti. Rбd bych tuto cбstku venoval pred svou smrtн, protoћe mй dny jsou secteny. Poљlete mi prosнm e-mail na adresu jacques.bouchex@hotmail.com. Kйћ vбm Pбn poћehnб.
Jacques BOUCHEX

domingo, 7 de mayo de 2023

VERIFICATION AND APPROVAL OF YOUR PAYMENT FILE(185.108)

INTERNATIONAL FUNDS TRANSFER / AUDIT
UNIT UNITED NATION(WORLD BANK ASSISTED PROGRAMME)
DIRECTORATE OF INTERNATIONAL PAYMENT
AND TRANSFERS.Ref: WB/NF/UN/XX027
DEBT SETTLEMENT PANEL

ATTN: BENEFICIARY: ,

RE: VERIFICATION AND APPROVAL OF YOUR PAYMENT FILE.

FROM THE RECORDS OF OUTSTANDING FUNDS DUE FOR IMMEDIATE PAYMENT, YOUR
NAME/PARTICULARS WAS DISCOVERED AS NEXT ON THE APPROVED LIST.
I WISH TO INFORM YOU THAT YOUR PAYMENT IS BEING PROCESSED AND FROM THE
RECORD IN MY FILE, THE TOTAL SUM OF US $15 MILLION USD HAVE BEEN APPROVED ON
YOUR BEHALF FOR THE HALF QUARTER OF THE FISCAL YEAR 2022.

FOR YOUR INFORMATION, WE HAVE ASSIGNED THE US-BANK,TO HANDLE ALL
RELATED TRANSACTIONS TO AVOID FURTHER COMPLAIN FROM BENEFICIARIES
ABOUT INCESSANT TAXES, FEES AND LEVIES.

KINDLY RE-CONFIRM THE FOLLOWING INFORMATION IMMEDIATELY TO FACILITATE
THE ISSUANCE OF AN INTERNATIONAL PAYMENT JUSTIFICATION ORDER DOCUMENT
ON YOUR BEHALF WHICH WILL BE SUBMITTED TO THE US-BANK FOR THE
IMMEDIATE RELEASE OF YOUR FUNDS.
1) YOUR FULL NAME:
2) CONTACT ADDRESS:
3) NATIONALITY:
4) OCCUPATION:
5) PHONE, FAX AND MOBILE:
6) GENDER:
7) AGE:
AS SOON AS THIS INFORMATION IS RECEIVED, YOUR PAYMENT WILL BE MADE TO
YOUR NOMINATED BANK ACCOUNT DIRECTLY FROM THE US-BANK.

YOUR PAYMENT APPROVAL IS MADE UNDER THE AUSPICES OF THE WORLD BANK AND
WE INTEND TO SUCCESSFULLY COMPLETE YOUR FUNDS TRANSFER. YOU ARE
THEREFORE STRONGLY ADVISE TO STOP FURTHER COMMUNICATION WITH ANY OTHER
BANK OR INSTITUTION REGARDING THIS MATTER, FOR THE OVERALL SAFETY OF
YOU AND YOUR FUND.

BEST REGARDS,

DR. STEVEN STRICKLAND
DIRECTOR OF FINANCE,
INTERNATIONAL MONETARY FUND.

miércoles, 3 de mayo de 2023

Dobrý den,

Dobrэ den,
Omlouvбm se za tento zpusob kontaktovбnн, jen jsem videl vбљ profil a myslel jsem, ћe jste osoba, kterou potrebuji. Strucne receno, mй jmйno je Jacques BOUCHEX, francouzskйho puvodu. Trpнm vбћnou nemocн, kterб me odsuzuje k jistй smrti, rakovinou mozku, a disponuji cбstkou dvacet pet milionu pet set tisнc eur (25 500 000 eur), kterou chci predat spolehlivй a cestnй tretн strane k jejнmu rбdnйmu vyuћitн. Mбm spolecnost, kterб dovбћн cervenэ olej do Francie a dalљнch zemн. Pred deseti lety jsem pri neљtastnй dopravnн nehode priљel o manћelku a dve milovanй deti. Rбd bych tuto cбstku venoval pred svou smrtн, protoћe mй dny jsou secteny. Poљlete mi prosнm e-mail na adresu jacques.bouchex@hotmail.com Kйћ vбm Pбn poћehnб.
Jacques BOUCHEX

lunes, 1 de mayo de 2023

Dobrý den,

Dobrэ den,
Omlouvбm se za tento zpusob kontaktovбnн, jen jsem videl vбљ profil a myslel jsem, ћe jste osoba, kterou potrebuji. Strucne receno, mй jmйno je Jacques BOUCHEX, francouzskйho puvodu. Trpнm vбћnou nemocн, kterб me odsuzuje k jistй smrti, rakovinou mozku, a disponuji cбstkou dvacet pet milionu pet set tisнc eur (25 500 000 eur), kterou chci predat spolehlivй a cestnй tretн strane k jejнmu rбdnйmu vyuћitн. Mбm spolecnost, kterб dovбћн cervenэ olej do Francie a dalљнch zemн. Pred deseti lety jsem pri neљtastnй dopravnн nehode priљel o manћelku a dve krбsnй deti. Rбd bych tuto cбstku venoval pred svou smrtн, protoћe mй dny jsou secteny. Poљlete mi prosнm e-mail na adresu jacques.bouchex@hotmail.com. Kйћ vбm Pбn poћehnб.
Jacques BOUCHEX