Monday, May 29, 2023

Vlang Binary Debugging

Why vlang? V is a featured, productive, safe and confortable language highly compatible with c, that generates neat binaries with c-speed, the decompilation also seems quite clear as c code.
https://vlang.io/

After open the binary with radare in debug mode "-d" we proceed to do the binary recursive analysis with "aaaa" the more a's the more deep analys.



The function names are modified when the binary is crafted, if we have a function named hello in a module named main we will have the symbol main__hello, but we can locate them quicly thanks to radare's grep done with "~" token in this case applied to the "afl" command which lists all the symbols.


Being in debug mode we can use "d*" commands, for example "db" for breakpointing the function and then "dc" to start or continue execution.


Let's dissasemble the function with "pD" command, it also displays the function variables and arguments as well, note also the xref "call xref from main"


Let's take a look to the function arguments, radare detect's this three 64bits registers used on the function.


Actually the function parameter is rsi that contains a testing html to test the href extraction algorithm.


The string structure is quite simple and it's plenty of implemented methods.




With F8 we can step over the code as we were in ollydbg on linux.


Note the rip marker sliding into the code.


We can recognize the aray creations, and the s.index_after() function used to find substrings since a specific position.


If we take a look de dissasembly we sill see quite a few calls to tos3() functions.
Those functions are involved in string initialization, and implements safety checks.

  • tos(string, len)
  • tos2(byteptr)
  • tos3(charptr)

In this case I have a crash in my V code and I want to know what is crashing, just continue the execution with "dc" and see what poits the rip register.



In visual mode "V" we can see previous instructions to figure out the arguments and state.


We've located the crash on the substring operation which is something like "s2 := s1[a..b]" probably one of the arguments of the substring is out of bounds but luckily the V language has safety checks and is a controlled termination:



Switching the basic block view "space" we can see the execution flow, in this case we know the loops and branches because we have the code but this view also we can see the tos3 parameter "href=" which is useful to locate the position on the code.



When it reach the substr, we can see the parameters with "tab" command.



Looking the implementation the radare parameter calculation is quite exact.


Let's check the param values:


so the indexes are from 0x0e to 0x24 which are inside the buffer, lets continue to next iteration,
if we set a breakpoint and check every iteration, on latest iteration before the crash we have the values 0x2c to 0x70 with overflows the buffer and produces a controlled termination of the v compiled process.





Related articles

Sunday, May 28, 2023

TOP ANDROID HACKING TOOLS OF 2018

An Android remote administration tool (RAT) is a programmed tool that allows a remote device to control a smartphone as if they have physical access to that system. While screen sharing and remote administration have many legal uses, "RAT" software is usually associated with the unauthorized or malicious activity. I have streamlined here top android hacking tools of 2018.

TOP ANDROID HACKING TOOLS OF 2018

Here are the most advanced in functionality top android hacking tools of 2018.

1. DROIDJACK

DroidJack gives you the power to establish control over your beloveds' Android devices with an easy to use GUI and all the features you need to monitor them. It has many advanced features that you can perform over the remote smartphone. DroidJack is one of the top lists as it also has the functionality to read/write WhatsApp messages.

You can also follow a step by step tutorial on how to hack smartphone remotely using droidjack.

2. OMNIRAT

OmniRAT is the super powerful multi-OS remote administration tool that can a smartphone either using a smartphone or using a Windows or Mac PC. It has a huge list of features that make it very powerful. It can make calls through that smartphone remotely. It's completely fully undetectable.

3. ANDRORAT

AndroRat is a client/server application developed in Java Android for the client side and in Java/Swing for the Server. The name AndroRat is a mix of Android and RAT (Remote Access Tool). It was developed as a project by the university students, which works great for hacking into Android devices.

You can also follow a step by step tutorial on how to hacking a smartphone remotely using androrat.

4. SPYNOTE

SpyNote is a lightweight Android remote administration tool (RAT) to hack into a smartphone device remotely. It gives you the power to establish control over Android devices with an easy to use GUI and all the features you need to monitor them. Build a custom APK or bind the payload to an already existing APK such as a game or social media app.

You can also follow a step by step tutorial on how to hack any android phone remotely with spynote.

5. AHMYTH

AhMyth is a powerful android remote administrator tool that gives you the power to establish control over your beloveds' android devices with an easy to use GUI and all the features you need to monitor them.

These are all the top android hacking tools of 2018. There are also many other rats but these are the most advanced in tech and features. There may appear few more that can compete these and make a place to be in the top android list.
Related posts
  1. Pentest Tools For Windows
  2. Hacker Tool Kit
  3. How To Make Hacking Tools
  4. Nsa Hack Tools Download
  5. Hacking Tools Kit
  6. Hacking App
  7. Hack Website Online Tool
  8. Hacker Tool Kit
  9. Pentest Tools
  10. Physical Pentest Tools
  11. Hacker Tools For Ios
  12. Growth Hacker Tools
  13. Pentest Tools Url Fuzzer
  14. Pentest Tools Windows
  15. Hackers Toolbox
  16. Pentest Tools Free
  17. Hacker Search Tools
  18. Pentest Tools Android
  19. Hack App
  20. Hacking Tools Windows
  21. Hack Tools
  22. Hacker Tools Free
  23. Pentest Tools Android
  24. Pentest Tools Download
  25. Hacking Apps
  26. Pentest Tools Open Source
  27. Install Pentest Tools Ubuntu
  28. Hacking Tools For Beginners
  29. How To Install Pentest Tools In Ubuntu
  30. Hacking App
  31. Hacking Tools For Pc
  32. Hacker Tools Online
  33. Hacking Tools Download
  34. Hacking Tools
  35. Pentest Tools Android
  36. How To Make Hacking Tools
  37. Pentest Tools Kali Linux
  38. Hacker Tools For Pc
  39. Hack Tools Mac
  40. How To Install Pentest Tools In Ubuntu
  41. Hack And Tools
  42. Hacker Tools For Pc
  43. Hacking Tools Windows
  44. Hack Tools For Ubuntu
  45. Hack Tools For Pc
  46. Github Hacking Tools
  47. Hacker Tools For Windows
  48. Hacker Tools For Ios
  49. How To Hack
  50. Best Hacking Tools 2019
  51. Hak5 Tools
  52. Nsa Hack Tools Download
  53. Hack Tools Mac
  54. Pentest Automation Tools
  55. Tools 4 Hack
  56. Hacker Tools For Windows
  57. Hacker Tools Free Download
  58. Hacker Search Tools
  59. Usb Pentest Tools
  60. Hacker Tools 2019
  61. Hack Apps
  62. Tools 4 Hack
  63. Growth Hacker Tools
  64. Hacker Tools Linux
  65. Pentest Tools Bluekeep
  66. Hacking Tools 2019
  67. Hackers Toolbox
  68. Pentest Tools Review
  69. Pentest Tools Alternative
  70. Pentest Tools Url Fuzzer
  71. Hack Tools Mac
  72. Hack Tools
  73. Pentest Tools For Windows
  74. Hacker Tools Apk
  75. Pentest Tools Free
  76. Hacking Tools For Windows 7
  77. Pentest Tools Github
  78. Hacking Tools Github
  79. Pentest Tools Tcp Port Scanner
  80. Hack Tools Download
  81. Hacking Tools For Mac
  82. Hacking Tools Mac
  83. Hacker Tools Github

Top System Related Commands In Linux With Descriptive Definitions


Commands are just like an instructions given to a system to do something and display an output for that instruction. So if you don't know how to gave an order to a system to do a task then how it can do while you don't know how to deal with. So commands are really important for Linux users. If you don't have any idea about commands of Linux and definitely you also don't know about the Linux terminal. You cannot explore Linux deeply. Because terminal is the brain of the Linux and you can do everything by using Linux terminal in any Linux distribution. So, if you wanna work over the Linux distro then you should know about the commands as well.
In this blog you will get a content about commands of Linux which are collectively related to the system. That means if you wanna know any kind of information about the system like operating system, kernel release information, reboot history, system host name, ip address of the host, current date and time and many more.

Note:

If you know about the command but you don't have any idea to use it. In this way you just type the command, then space and then type -h or --help or ? to get all the usage information about that particular command like "uname" this command is used for displaying the Linux system information. You don't know how to use it. Just type the command with help parameter like: uname -h or uname --help etc.

uname 

The "uname" is a Linux terminal command responsible of displaying the information about Linux system. This command has different parameter to display a particular part of information like kernel release (uname -r) or all the information displayed by typing only one command (uname -a).

uptime

This command is used to show how long the system has been running and how much load on it at current state of the CPU. This command is very useful when you system slows down or hang etc and you can easily get the info about the load on the CPU with the help of this command.

hostname

The "hostname" is the the command in Linux having different parameters to display the information bout the current host which is running the kernel at that time. If you wanna know about the parameters of hostname command then you just type hostname --help or hostname -h to get all the info about the command and the usage of the command.

last reboot

The "last reboot" is the command in Linux operating system used to display the reboot history. You just have to type this command over the Linux terminal it will display the reboot history of that Linux system.

date

The "date" is the command used in Linux operating system to show the date of the day along with the current time of the day.

cal

The "cal" command in Linux used to display the calendar which has the current date highlighted with a square box along with a current month dates and days just like a real calendar.

w

The "w" is the command used in Linux distro for the sake of getting the information about current user. If you type this command it will display who is online at the time.

whoami

The "whoami" is the command in Linux operating system used to show the information that who you are logged in as. For example if you are logged in as a root then it'll display "root" etc.

finger user

The "finger user" is the command used in Linux distribution to display the information about user which is online currently over that Linux system.

Related word


  1. Hacking Tools Free Download
  2. Hack Tools Github
  3. Pentest Box Tools Download
  4. Pentest Tools For Mac
  5. Pentest Tools Free
  6. Nsa Hacker Tools
  7. Pentest Recon Tools
  8. New Hack Tools
  9. Hacker Tools Linux
  10. Hacking Tools Name
  11. Pentest Tools List
  12. Hack And Tools
  13. Hack Tools
  14. Hack App
  15. What Is Hacking Tools
  16. Hacker Tools Apk Download
  17. Hack Tools Pc
  18. Kik Hack Tools
  19. Hacking Tools For Windows
  20. Hacking Tools For Windows Free Download
  21. Termux Hacking Tools 2019
  22. Hacker Tools 2019
  23. Pentest Tools Url Fuzzer
  24. Easy Hack Tools
  25. Nsa Hacker Tools
  26. Pentest Tools Bluekeep
  27. Hack Tools For Games
  28. Hacking Tools For Windows 7
  29. Hacking Tools 2020
  30. Hackers Toolbox
  31. Hacking Tools
  32. Pentest Tools Github
  33. Growth Hacker Tools
  34. Hacker Tools List
  35. Best Hacking Tools 2020
  36. Nsa Hacker Tools
  37. Hack Tools
  38. What Are Hacking Tools
  39. Hacker Tools 2020
  40. Hack Tools Mac
  41. Hack Tools 2019
  42. Hacking Tools Free Download
  43. Hacker Tools Free Download
  44. Pentest Tools For Ubuntu
  45. Nsa Hack Tools Download
  46. Hacking Tools Usb
  47. Best Hacking Tools 2020
  48. Wifi Hacker Tools For Windows
  49. Hacker Tools Free
  50. Tools For Hacker
  51. Hacking Tools Github
  52. Hacking Tools For Windows
  53. Hacking Tools Windows
  54. Hacker Tools Mac
  55. Pentest Tools Website
  56. Hacking Tools Windows
  57. Hacker Tools Free Download
  58. Hacker Tools For Ios
  59. Pentest Tools Alternative
  60. Blackhat Hacker Tools
  61. Best Hacking Tools 2019
  62. Pentest Tools Website Vulnerability
  63. Pentest Tools Framework
  64. Pentest Tools Windows
  65. Pentest Tools Framework
  66. Hack Website Online Tool
  67. Hacker Tools Hardware
  68. Hack Rom Tools
  69. Computer Hacker
  70. Pentest Tools List
  71. Tools Used For Hacking
  72. Pentest Tools Linux
  73. Hacker Tools Free Download
  74. Best Hacking Tools 2020
  75. Physical Pentest Tools
  76. Nsa Hack Tools Download
  77. Tools For Hacker
  78. Hacking Tools For Mac
  79. Hacker Techniques Tools And Incident Handling
  80. Hacking Tools For Windows Free Download
  81. Pentest Tools Framework
  82. Growth Hacker Tools
  83. Hacking Tools 2020
  84. Usb Pentest Tools
  85. Kik Hack Tools
  86. Hacker Tools List
  87. Hacking Tools Name
  88. Pentest Tools Website
  89. Hacker Tools List
  90. Hacker
  91. Hacker Tools List
  92. Pentest Tools List
  93. Hacker Tools Online
  94. Pentest Box Tools Download
  95. Hacker Tools Software
  96. Hacking Tools For Windows Free Download
  97. Pentest Tools Tcp Port Scanner
  98. Hacker Tools Free Download
  99. Hacking Tools For Windows 7
  100. Hacker Tools For Ios
  101. New Hacker Tools
  102. How To Hack
  103. Pentest Tools Open Source
  104. Pentest Tools Download
  105. Pentest Tools Free
  106. Hacker
  107. Black Hat Hacker Tools
  108. Hack Rom Tools
  109. Hacker Security Tools
  110. Pentest Tools Linux
  111. How To Make Hacking Tools
  112. Pentest Tools Bluekeep
  113. Tools For Hacker
  114. What Is Hacking Tools
  115. Hacking Tools Mac
  116. Hacking Tools Online
  117. Pentest Tools Website Vulnerability
  118. Hack Apps
  119. Black Hat Hacker Tools
  120. Pentest Tools For Mac
  121. Wifi Hacker Tools For Windows
  122. Pentest Tools Subdomain
  123. Pentest Reporting Tools
  124. Hacking Tools For Windows
  125. Hacker Tools Mac
  126. Hacking Tools 2020
  127. Pentest Tools Website
  128. Hacker Tools Free Download
  129. Hacking Tools For Mac
  130. Hack Website Online Tool
  131. Pentest Tools Port Scanner
  132. Beginner Hacker Tools
  133. Pentest Tools Website Vulnerability
  134. Hack Tools For Ubuntu
  135. Hacking Tools And Software
  136. Hacker Tools Software
  137. Hack Tools Github
  138. Hacking Tools Windows
  139. Hacking Tools Name
  140. Hacker Tools Mac
  141. Pentest Automation Tools
  142. Bluetooth Hacking Tools Kali
  143. Kik Hack Tools
  144. Hacker Tools Software
  145. Hacking Apps
  146. Game Hacking
  147. Pentest Tools Online
  148. Pentest Tools Bluekeep
  149. Nsa Hack Tools Download
  150. Hacking Tools And Software
  151. Hacker Tools Mac
  152. Hack Tools Github
  153. Hacking Tools Windows 10
  154. Hacker Techniques Tools And Incident Handling
  155. Tools For Hacker
  156. Nsa Hack Tools Download
  157. Hack Tools Mac
  158. Pentest Tools Apk
  159. Kik Hack Tools
  160. Hack Tools Mac
  161. Hacking Tools Name
  162. Hacker Tools Free Download
  163. World No 1 Hacker Software

Recovering Data From An Old Encrypted Time Machine Backup

Recovering data from a backup should be an easy thing to do. At least this is what you expect. Yesterday I had a problem which should have been easy to solve, but it was not. I hope this blog post can help others who face the same problem.


The problem

1. I had an encrypted Time Machine backup which was not used for months
2. This backup was not on an official Apple Time Capsule or on a USB HDD, but on a WD MyCloud NAS
3. I needed files from this backup
4. After running out of time I only had SSH access to the macOS, no GUI

The struggle

By default, Time Machine is one of the best and easiest backup solution I have seen. As long as you stick to the default use case, where you have one active backup disk, life is pink and happy. But this was not my case.

As always, I started to Google what shall I do. One of the first options recommended that I add the backup disk to Time Machine, and it will automagically show the backup snapshots from the old backup. Instead of this, it did not show the old snapshots but started to create a new backup. Panic button has been pressed, backup canceled, back to Google.


Other tutorials recommend to click on the Time Machine icon and pressing alt (Option) key, where I can choose "Browse other backup disks". But this did not list the old Time Machine backup. It did list the backup when selecting disks in Time Machine preferences, but I already tried and failed that way.


YAT (yet another tutorial) recommended to SSH into the NAS, and browse the backup disk, as it is just a simple directory where I can see all the files. But all the files inside where just a bunch of nonsense, no real directory structure.

YAT (yet another tutorial) recommended that I can just easily browse the content of the backup from the Finder by double-clicking on the sparse bundle file. After clicking on it, I can see the disk image on the left part of the Finder, attached as a new disk.
Well, this is true, but because of some bug, when you connect to the Time Capsule, you don't see the sparse bundle file. And I got inconsistent results, for the WD NAS, double-clicking on the sparse bundle did nothing. For the Time Capsule, it did work.
At this point, I had to leave the location where the backup was present, and I only had remote SSH access. You know, if you can't solve a problem, let's complicate things by restrict yourself in solutions.

Finally, I tried to check out some data forensics blogs, and besides some expensive tools, I could find the solution.

The solution

Finally, a blog post provided the real solution - hdiutil.
The best part of hdiutil is that you can provide the read-only flag to it. This can be very awesome when it comes to forensics acquisition.


To mount any NAS via SMB:
mount_smbfs afp://<username>@<NAS_IP>/<Share_for_backup> /<mountpoint>

To mount a Time Capsule share via AFP:
mount_afp afp://any_username:password@<Time_Capsule_IP>/<Share_for_backup> /<mountpoint>

And finally this command should do the job:
hdiutil attach test.sparsebundle -readonly

It is nice that you can provide read-only parameter.

If the backup was encrypted and you don't want to provide the password in a password prompt, use the following:
printf '%s' 'CorrectHorseBatteryStaple' | hdiutil attach test.sparsebundle -stdinpass -readonly

Note: if you receive the error "resource temporarily unavailable", probably another machine is backing up to the device

And now, you can find your backup disk under /Volumes. Happy restoring!

Probably it would have been quicker to either enable the remote GUI, or to physically travel to the system and login locally, but that would spoil the fun.
Continue reading

  1. Pentest Tools Linux
  2. Pentest Tools Kali Linux
  3. Pentest Tools Website Vulnerability
  4. Hacker Tools
  5. Hacker Tools Windows
  6. Hacker Techniques Tools And Incident Handling
  7. Pentest Tools Download
  8. Pentest Tools Apk
  9. Pentest Tools Linux
  10. Hacker Tools For Windows
  11. Hacking Tools For Pc
  12. Hackrf Tools
  13. Hacking Tools Windows
  14. Hacking Tools Kit
  15. Hacker
  16. Pentest Tools Github
  17. Hacker Tools List
  18. Hacker Security Tools
  19. Hacking Tools For Windows Free Download
  20. World No 1 Hacker Software
  21. Hacker Tools Mac
  22. Tools Used For Hacking
  23. Beginner Hacker Tools
  24. Growth Hacker Tools
  25. Hackers Toolbox
  26. Pentest Tools
  27. Pentest Tools Android
  28. Hack Tools For Windows
  29. Pentest Tools Framework
  30. Hacking Tools Mac
  31. Pentest Tools Apk
  32. Pentest Tools List
  33. Hack Tools For Windows
  34. New Hack Tools
  35. Hacking Tools And Software
  36. Hacking Tools Hardware
  37. Hacker Search Tools
  38. Hack Apps
  39. Hacker Tool Kit
  40. Wifi Hacker Tools For Windows
  41. Pentest Reporting Tools
  42. Hack Tools Download
  43. Hacker
  44. Pentest Tools Alternative
  45. Beginner Hacker Tools
  46. Hacking Tools Download
  47. Hacker Search Tools
  48. Hacking Tools 2020
  49. Hacker Tools Free Download
  50. Hack Tools For Windows
  51. Hacking Tools Github
  52. Hacking Tools Windows
  53. Pentest Tools Framework
  54. Pentest Tools For Windows
  55. Hacker Tools
  56. New Hack Tools
  57. Hacks And Tools
  58. Growth Hacker Tools
  59. Hacking Tools
  60. Nsa Hacker Tools
  61. Hack Tools For Windows
  62. Hacker Tools List
  63. What Are Hacking Tools
  64. Hacker Hardware Tools
  65. Hacking Tools And Software
  66. Hacking Tools
  67. Blackhat Hacker Tools
  68. Android Hack Tools Github
  69. Hacking Tools Download

Saturday, May 27, 2023

Reversing C++ String And QString

After the rust string overview of its internal substructures, let's see if c++ QString storage is more light, but first we'r going to take a look to the c++ standard string object:



At first sight we can see the allocation and deallocation created by the clang++ compiler, and the DAT_00400d34 is the string.

If we use same algorithm than the rust code but in c++:



We have a different decompilation layout. Note that the Ghidra scans very fast the c++ binaries, and with rust binaries gets crazy for a while.
Locating main is also very simple in a c++ compiled binary, indeed is more  low-level than rust.


The byte array is initialized with a simply move instruction:
        00400c4b 48 b8 68        MOV        RAX,0x6f77206f6c6c6568

And basic_string generates the string, in the case of rust this was carazy endless set of calls, detected by ghidra as a runtime, but nevertheless the basic_string is an external imported function not included on the binary.

(gdb) x/x 0x7fffffffe1d0
0x7fffffffe1d0: 0xffffe1e0            low str ptr
0x7fffffffe1d4: 0x00007fff           hight str ptr
0x7fffffffe1d8: 0x0000000b        sz
0x7fffffffe1dc: 0x00000000
0x7fffffffe1e0: 0x6c6c6568         "hello world"
0x7fffffffe1e4: 0x6f77206f
0x7fffffffe1e8: 0x00646c72
0x7fffffffe1ec: 0x00000000        null terminated
(gdb) x/s 0x7fffffffe1e0
0x7fffffffe1e0: "hello world"

The string is on the stack, and it's very curious to see what happens if there are two followed strings like these:

  auto s = string(cstr);
  string s2 = "test";

Clang puts toguether both stack strings:
[ptr1][sz1][string1][null][string2][null][ptr2][sz2]

C++ QString datatype

Let's see the great and featured QString object defined on qstring.cpp and qstring.h

Some QString methods use the QCharRef class whose definition is below:

class Q_EXPORT QCharRef {     friend class QString;     QString& s;     uint p;
 
 Searching for the properties on the QString class I've realized that one improvement that  rust and golang does is the separation from properties and methods, so in the large QString class the methods are  hidden among the hundreds of methods, but basically the storage is a QStringData *;

After removing the methods of QStringData class definition we have this:

struct Q_EXPORT QStringData : public QShared {
    QChar *unicode;
    char *ascii;
#ifdef Q_OS_MAC9
    uint len;
#else
    uint len : 30;