Showing posts with label hk. Show all posts
Showing posts with label hk. Show all posts

Tuesday, October 3, 2017

Obfuscating Powershell script with Powershell

Hi Mates,
I was intrigued by a book that I was reading about Pen Testing. The author wrote a Python script used, together with other functions, to obfuscate a Powershell script.
Since I love Powershell and I’m trying to learn Python I was just curious to see if I was able to re-create the Python script in Powershell.
On the web there are many example but most of them didn’t work (for me). In fact most of them don’t clean the script from some useless chars (CR, BOM, Comments and so on).
I decided to try….. I’ve learned what is BOM and how to get a raw file at the end of some steps.
If the original file respect some specifications (I’ll illustrate later) the obfuscation should happen without any issue.

Wednesday, March 15, 2017

Brute Force/Random password for an Excel protected file : embryonic Powershell exercise

Hi Mates,
only a brief exercise in Powershell.
I would like to know if it is possible to crack Excel password with this scripting language.
Theoretically YES. Practically this is only another opportunity to learn it better.
You can improve it for sure but it's only a good point from which to start and , maybe, go deeper.....
With more diligence you could be able to convert this script to compare some hash.
This is a random password generator ...it's up to you to decide what is the best approach : if you know some information about the secret you can sight better your target and modify the script to exclude some useless calculation. Otherwise you will have to check N passwords /2.....at least (consider it the average).

Wednesday, August 31, 2016

DNS Poisoning : how it works, precautions and a quick demo

Hi mates,
few months ago some friends asked me some additional info regarding specific attacks that were done to redirect user traffic to a desired/different web site.
The attack is called DNS Poisoning and it's done, simply speaking, polluting the DNS cache of specific servers. More popular is the web site attacked, more amplified will be the impact.
In that way when a user will try to resolve the name of the website that he/she is asking for, the DNS will give him/she a different IP instead of the right one.(consider that the same approach could be used for mail system for example)