Skip to main content

Gray hat hacking: the ethical hacker's handbook, fifth edition daniel regalado - ebook pdf - The com

Page 1


Gray Hat Hacking: The Ethical Hacker's Handbook, Fifth Edition Daniel Regalado - eBook PDF download

https://ebooksecure.com/download/gray-hat-hacking-the-ethicalhackers-handbook-fifth-edition-ebook-pdf/ Download

We believe these products will be a great fit for you. Click the link to download now, or visit ebooksecure.com to discover even more!

Gray Hat Hacking: The Ethical Hacker's Handbook Sixth Edition Daniel Regalado - eBook PDF

https://ebooksecure.com/download/gray-hat-hacking-the-ethicalhackers-handbook-sixth-edition-ebook-pdf/

Gray Hat Hacking: The Ethical Hacker's Handbook 5th Edition Allen Harper - eBook PDF https://ebooksecure.com/download/gray-hat-hacking-the-ethicalhackers-handbook-ebook-pdf/

(eBook PDF) The Bedford Handbook 10th Edition by Diana Hacker http://ebooksecure.com/product/ebook-pdf-the-bedfordhandbook-10th-edition-by-diana-hacker/

(eBook PDF) Hands-On Ethical Hacking and Network Defense 3rd Edition

http://ebooksecure.com/product/ebook-pdf-hands-on-ethicalhacking-and-network-defense-3rd-edition/

CEH Certified Ethical Hacker Practice Exams, 5th Edition Matt Walker - eBook PDF

https://ebooksecure.com/download/ceh-certified-ethical-hackerpractice-exams-5th-edition-ebook-pdf/

CEH Certified Ethical Hacker All-in-One Exam Guide 4th Edition (eBook PDF)

http://ebooksecure.com/product/ceh-certified-ethical-hacker-allin-one-exam-guide-4th-edition-ebook-pdf/

Hands-On Ethical Hacking and Network Defense Third Edition Michael T. Simpson - eBook PDF

https://ebooksecure.com/download/hands-on-ethical-hacking-andnetwork-defense-ebook-pdf/

The Audit Process 7th Edition Iain Gray - eBook PDF

https://ebooksecure.com/download/the-audit-process-ebook-pdf/

Hands-On Ethical Hacking and Network Defense (MindTap Course List) [Team-IRA] [True PDF] 4th Edition Rob Wilson - eBook PDF

https://ebooksecure.com/download/hands-on-ethical-hacking-andnetwork-defense-mindtap-course-list-team-ira-true-pdf-ebook-pdf/

Praise forGrayHat Hacking: The EthicalHacker’sHandbook, Fifth Edition

“TheGrayHatHackingbookseriescontinuetoprovideanup-to-dateanddetailed view onalargevarietyofoffensiveITsecuritydisciplines.Inthisfifthedition,agroup ofrespectedinfosecprofessionalssparednoefforttosharetheir experienceand expertiseonnovel techniquestobypasssecuritymechanisms.

Theexploitdevelopmentchapters,writtenbyStephenSims,reveal ingreatdetail whatittakestowriteanexploitfor modernapplications.InChapter 14,Stephenusesa recentvulnerabilityinamajor webbrowser todemystifythecomplexityofwriting modernexploitsfor heap-relatedmemorycorruptions,bypassingmemoryprotections alongtheroad.

Thisbookisamustreadfor anyonewhowantstostepupandbroadentheir skillsin infosec.”

PeterVanEeckhoutte CorelanTeam(@corelanc0d3r)

“Oneofthefew bookserieswhereIALWAYSbuytheupdatedversion.Learnupdated exploit-devtechniquesfromthebestinstructorsinthebusiness.Thevolumeofnew informationavailabletotheaverageinformationsecuritypractitioner isstaggering.The authors,whoaresomeofthebestintheir respectivefields,helpusstayuptodatewith currenttrendsandtechniques.GHH’supdatesonRedTeamOps,BugBounties, PowerShell Techniques,andIoT&EmbeddedDevicesareexactlywhatinfosec practitionersneedtoaddtotheir tool kits.”

ChrisGates Sr.SecurityEngineer (Uber)

“Never beforehastherebeensomuchtechnologytoattacknor suchhighlevelsof controlsandpreventionmechanisms.For example,theadvancementsinmodern operatingsystemsandapplicationstoprotectagainstexploitationareveryimpressive, yettimeandtimeagainwiththerightconditionstheyarebypassed.Amongstalitanyof modernandup-to-datetechniques,GrayHatHackingprovidesdetailedandinformative walkthroughsofvulnerabilitiesandhow controlslikeASLRandDEParebypassed. Filledwithreal examplesyoucanfollow ifyouareseekingtoupgradeyour understandingofthelatesthackingtechniques thisisthebookfor you.”

Copyright©2018byMcGraw-Hill Education.All rightsreserved.Exceptaspermitted under theUnitedStatesCopyrightActof1976,nopartofthispublicationmaybe reproducedor distributedinanyformor byanymeans,or storedinadatabaseor retrieval system,withouttheprior writtenpermissionofthepublisher,withthe exceptionthattheprogramlistingsmaybeentered,stored,andexecutedinacomputer system,buttheymaynotbereproducedfor publication.

ISBN: 978-1-26-010842-2

MHID: 1-26-010842-2

Thematerial inthiseBookalsoappearsintheprintversionofthistitle: ISBN: 978-126-010841-5, MHID: 1-26-010841-4.

eBookconversionbycodeMantra Version1.0

All trademarksaretrademarksoftheir respectiveowners.Rather thanputatrademark symbol after everyoccurrenceofatrademarkedname,weusenamesinaneditorial fashiononly,andtothebenefitofthetrademarkowner,withnointentionofinfringement ofthetrademark.Wheresuchdesignationsappear inthisbook,theyhavebeenprinted withinitial caps.

McGraw-Hill Educationebooksareavailableatspecial quantitydiscountstouseas premiumsandsalespromotionsor for useincorporatetrainingprograms.Tocontacta representative,pleasevisittheContactUspageatwww.mhprofessional.com.

All trademarksor copyrightsmentionedhereinarethepossessionoftheir respective ownersandMcGraw-Hill Educationmakesnoclaimofownershipbythementionof productsthatcontainthesemarks.

InformationhasbeenobtainedbyMcGraw-Hill Educationfromsourcesbelievedtobe reliable.However,becauseofthepossibilityofhumanor mechanical error byour sources,McGraw-Hill Education,or others,McGraw-Hill Educationdoesnot guaranteetheaccuracy,adequacy,or completenessofanyinformationandisnot responsiblefor anyerrorsor omissionsor theresultsobtainedfromtheuseofsuch information.

TERMSOFUSE

ThisisacopyrightedworkandMcGraw-Hill Educationanditslicensorsreserveall rightsinandtothework.Useofthisworkissubjecttotheseterms.Exceptaspermitted under theCopyrightActof1976andtherighttostoreandretrieveonecopyofthework, youmaynotdecompile,disassemble,reverseengineer,reproduce,modify,create derivativeworksbasedupon,transmit,distribute,disseminate,sell,publishor sublicensetheworkor anypartofitwithoutMcGraw-Hill Education’sprior consent. Youmayusetheworkfor your ownnoncommercial andpersonal use;anyother useof theworkisstrictlyprohibited.Your righttousetheworkmaybeterminatedifyoufail tocomplywiththeseterms.

THEWORKISPROVIDED“ASIS.”McGRAW-HILLEDUCATIONANDITS LICENSORSMAKENOGUARANTEESORWARRANTIESASTOTHE ACCURACY,ADEQUACYORCOMPLETENESSOFORRESULTSTOBE OBTAINEDFROMUSINGTHEWORK,INCLUDINGANYINFORMATIONTHAT CANBEACCESSEDTHROUGHTHEWORKVIAHYPERLINKOROTHERWISE, ANDEXPRESSLYDISCLAIMANYWARRANTY,EXPRESSORIMPLIED, INCLUDINGBUTNOTLIMITEDTOIMPLIEDWARRANTIESOF MERCHANTABILITYORFITNESSFORAPARTICULARPURPOSE.McGraw-Hill Educationanditslicensorsdonotwarrantor guaranteethatthefunctionscontainedin theworkwill meetyour requirementsor thatitsoperationwill beuninterruptedor error free.Neither McGraw-Hill Educationnor itslicensorsshall beliabletoyouor anyone elsefor anyinaccuracy,error or omission,regardlessofcause,intheworkor for any damagesresultingtherefrom.McGraw-Hill Educationhasnoresponsibilityfor the contentofanyinformationaccessedthroughthework.Under nocircumstancesshall McGraw-Hill Educationand/or itslicensorsbeliablefor anyindirect,incidental, special,punitive,consequential or similar damagesthatresultfromtheuseofor inabilitytousethework,evenifanyofthemhasbeenadvisedofthepossibilityofsuch damages.Thislimitationofliabilityshall applytoanyclaimor causewhatsoever whether suchclaimor causearisesincontract,tortor otherwise.

In Memoryof Shon Harris

Inthepreviousedition,IspokeinmemoryofShonHarris,myfriend,mentor,anda personIcreditwithjump-startingmycareer after mytimeintheMarineCorps.Simply put,neither thisbooknor mostofmyprofessional accomplishmentswouldhave happenedwithouther.Icontinuetomissher andIknow Ispeakonbehalfoftheother authorsthatwewishshewerestill withus.Ifyoudidnotknow Shonor havenever heardofher,youoweittoyourselftolearnabouther inspiringstoryinthelastedition andelsewhere.For thoseofuswhoknew her andhaveour own“Shon”stories,joinme inkeepingher memoryaliveandshareher storywithanyonewhowill listen.Shewas anamazingpersonandislovedandmisseddearly.Wededicatethisbooktoher memory.

AllenHarper

Leadauthor andfriendofShonHarris

TomybrothersandsistersinChrist,keeprunningtherace.Letyour lightshinefor Him, thatothersmaybedrawntoHimthroughyou.

AllenHarper

Dedicadoati mamitaAdelinaAriasCruz,cuandomepreguntodedondesalemi garra denodejarmedenadieoel sacrificioincansableparaconseguir mismetas,solotengo quevoltear averte,parati nohayimposibles,teadoro!

Daniel Regalado

ToMom,whoreadtomewhenIwaslittle,soIcouldachievethelevel ofliteracyI neededtobecomeanauthor oneday.

RyanLinn

TomylovelywifeLeAnneandmydaughter Audrey,thankyoufor your ongoingsupport!

StephenSims

Tomylovelydaughter Elysia,thankyoufor your unconditional loveandsupport.You inspiremeinsomanyways.Iam,andwill alwaysbe,your biggestfan.

Tomyfamilyandfriendsfor their unconditional supportandmakingthislifefunnyand interesting.

Tomydaughter Tiernan,thankyoufor your supportandcontinuousreminderstoenjoy lifeandlearningeachandeveryday.Ilookforwardtoseeingthewonderful womanyou will become.

TomysonAaron,thanksfor all your lovewhileIspendtoomuchtimeatthekeyboard, andthanksfor sharingyour joyonall theprojectsweworkontogether.

ChrisEagle

ABOUTTHEAUTHORS

Dr.AllenHarper,CISSP.In2007,AllenHarper retiredfromthemilitaryasaMarine CorpsOfficer after atour inIraq.Hehasmorethan30yearsofIT/securityexperience. HeholdsaPhDinITwithafocusinInformationAssuranceandSecurityfromCapella, anMSinComputer SciencefromtheNaval PostgraduateSchool,andaBSinComputer EngineeringfromNorthCarolinaStateUniversity.Allenledthedevelopmentofthe GENIIIhoneywall CD-ROM,calledroo,for theHoneynetProject.Hehasworkedasa securityconsultantfor manyFortune500andgovernmententities.Hisinterestsinclude theInternetofThings,reverseengineering,vulnerabilitydiscovery,andall formsof ethical hacking.Allenwasthefounder ofN2NetSecurity,Inc.,servedastheEVPand chiefhacker atTangibleSecurity,andnow servestheLordatLibertyUniversityin Lynchburg,Virginia.

DanielRegalado,akaDanux,isaMexicansecurityresearcher withmorethan16 yearsinthesecurityfield,dissectingor pen-testingmalware,0-dayexploits,ATMs,IoT devices,IVpumps,andcar infotainmentsystems.Heisaformer employeeofwidely respectedcompanieslikeFireEyeandSymantecandiscurrentlyaprincipal security researcher atZingbox.Daniel isprobablybestknownfor hismultiplediscoveriesand dissectionofATMmalwareattackingbanksworldwide,withthemostnotorious findingsbeingPloutus,Padpin,andRipper.

RyanLinnhasover 20yearsinthesecurityindustry,rangingfromsystems programmer tocorporatesecurity,toleadingaglobal cybersecurityconsultancy.Ryan hascontributedtoanumber ofopensourceprojects,includingMetasploitandthe Browser ExploitationFramework(BeEF).RyanparticipatesinTwitter as@sussurro, andhehaspresentedhisresearchatnumeroussecurityconferences,includingBlackHat andDEFCON,andhasprovidedtraininginattacktechniquesandforensicsworldwide.

StephenSimsisanindustryexpertwithover 15yearsofexperienceininformation technologyandsecurity.HecurrentlyworksoutofSanFranciscoasaconsultant performingreverseengineering,exploitdevelopment,threatmodeling,andpenetration testing.StephenhasanMSininformationassurancefromNorwichUniversityandisa courseauthor,fellow,andcurriculumleadfor theSANSInstitute,authoringcourseson advancedexploitdevelopmentandpenetrationtesting.Hehasspokenatnumerous conferences,includingRSA,BSides,OWASPAppSec,ThaiCERT,AISA,andmany others.Hemaybereachedontwitter: @Steph3nSims

BrankoSpasojevicisasecurityengineer onGoogle’sDetectionandResponseteam. Beforethatheworkedasareverseengineer for Symantecandanalyzedvariousthreats andAPTgroups.

LindaMartinez istheChiefInformationSecurityOfficer (CISO) andVicePresident ofCommercial ServiceDeliveryatTangibleSecurity.Lindaisaproveninformation securityexecutiveandindustryexpertwithover 18yearsofexperienceleading technical teams,developingtechnical businesslines,andprovidinghigh-quality consultingservicestoclients.Sheisresponsiblefor TangibleSecurity’sCommercial Division,wheresheleadsthefollowingbusinesslines: penetrationtesting,including redandpurpleteamoperations;hardwarehacking;productandsupplychainsecurity; governance,riskmanagement,andcompliance;incidentresponseanddigital forensics. Lindaalsoleadsateamofvirtual ChiefInformationSecurityOfficers(CISOs) in providingexpertguidancetomanyorganizations.Prior toher currentposition,Linda wastheVicePresidentofOperationsfor N2NetSecurity.Beforethat,sheco-founded andservedasChiefOperatingOfficer (COO) for ExecutiveInstruments,aninformation securityresearchandconsultingfirm.

MichaelBaucomcurrentlyworksfor TangibleSecurityastheVPofTangibleLabs. WhileatTangiblehehasworkedonawidevarietyofprojects,includingsoftware securityassessments,SDLCconsulting,tool development,andpenetrationtests.Prior to workingatTangibleSecurity,heservedintheMarineCorpsasagroundradio repairman.Additionally,heworkedfor IBM,Motorola,andBroadcominseveral capacities,includingtestengineering,devicedriver development,andsystemsoftware developmentfor embeddedsystems.Inadditiontohisworkactivities,Michael hasbeen atrainer atBlackHat,speaker atseveral conferences,andtechnical editor for GrayHat Hacking: TheEthical Hacker’sHandbook.Hiscurrentinterestsareinautomatingpentestactivities,embeddedsystemsecurity,andmobilephonesecurity.

ChrisEagle isasenior lecturer inthecomputer sciencedepartmentattheNaval PostgraduateSchool inMonterey,California.Acomputer engineer/scientistfor more than30years,hehasauthoredseveral books,servedasthechiefarchitectfor DARPA’s Cyber GrandChallenge,frequentlyspeaksatsecurityconferences,andhascontributed several popular opensourcetoolstothesecuritycommunity.

ThelateShonHarrisisgreatlymissed.ShewasthepresidentofLogical Security,a securityconsultant,aformer engineer intheAir Force’sInformationWarfareunit,an instructor,andanauthor.Sheauthoredthebest-sellingCISSPExamGuide(currentlyin itsseventhedition),alongwithmanyother books.Shonconsultedfor avarietyof companiesinmanydifferentindustries.Shontaughtcomputer andinformationsecurity toawiderangeofclients,includingRSA,DepartmentofDefense,Departmentof Energy,WestPoint,National SecurityAgency(NSA),BankofAmerica,Defense InformationSystemsAgency(DISA),BMC,andmanymore.Shonwasrecognizedas

oneofthetop25womenintheInformationSecurityfieldbyInformationSecurity Magazine.

Disclaimer: The viewsexpressedinthisbookare those of the authorsandnot of the U.S.government oranycompanymentionedherein.

AbouttheTechnicalEditor

HeatherLinnhasover 20yearsinthesecurityindustryandhasheldrolesincorporate security,penetrationtesting,andaspartofahuntteam.Shehascontributedtoopen sourceframeworks,includingMetasploit,andhascontributedtocoursematerialson forensics,penetrationtesting,andinformationsecuritytaughtaroundtheglobe.

Heather haspresentedatmanysecurityconferences,includingmultipleBSides conferences,local ISSAchapter conferences,andstudenteventsaimedatproviding realisticexpectationsfor new studentsenteringtheinformationsecurityfield.

CONTENTSATAGLANCE

Part I Preparation

Chapter1 WhyGrayHatHacking?EthicsandLaw

Chapter2 ProgrammingSurvival Skills

Chapter3 Next-GenerationFuzzing

Chapter4 Next-GenerationReverseEngineering

Chapter5 Software-DefinedRadio

Part II Businessof Hacking

Chapter6 SoYouWanttoBeaPenTester?

Chapter7 RedTeamingOperations

Chapter8 PurpleTeaming

Chapter9 BugBountyPrograms

Part III ExploitingSystems

Chapter10 GettingShellsWithoutExploits

Chapter11 BasicLinuxExploits

Chapter12 AdvancedLinuxExploits

Chapter13 WindowsExploits

Chapter14 AdvancedWindowsExploitation

Chapter15 PowerShell Exploitation

Chapter16 Next-GenerationWebApplicationExploitation

Chapter17 Next-GenerationPatchExploitation

Part

Chapter18 DissectingMobileMalware

Chapter19 DissectingRansomware

Chapter20 ATMMalware

Chapter21 Deception: Next-GenerationHoneypots

Part V Internetof Things

Chapter22 InternetofThingstoBeHacked

Chapter23 DissectingEmbeddedDevices

Chapter24 ExploitingEmbeddedDevices

Chapter25 FightingIoTMalware

Index

Preface

Acknowledgments

Introduction

Part I Preparation

Chapter1 WhyGrayHatHacking?EthicsandLaw

Know Your Enemy

TheCurrentSecurityLandscape

RecognizinganAttack

TheGrayHatWay

EmulatingtheAttack

FrequencyandFocusofTesting

EvolutionofCyberlaw

UnderstandingIndividual Cyberlaws

Summary References

Chapter2 ProgrammingSurvival Skills

CProgrammingLanguage

BasicCLanguageConstructs

SampleProgram

Compilingwithgcc

Computer Memory

RandomAccessMemory

Endian

SegmentationofMemory

ProgramsinMemory

Buffers

StringsinMemory

Pointers

PuttingthePiecesofMemoryTogether

Intel Processors Registers

AssemblyLanguageBasics

Machinevs.Assemblyvs.C

AT&Tvs.NASM

AddressingModes

AssemblyFileStructure

Assembling

Debuggingwithgdb

gdbBasics

Disassemblywithgdb

PythonSurvival Skills

GettingPython

“Hello,World!”inPython

PythonObjects

Strings

Numbers

Lists Dictionaries

FileswithPython

SocketswithPython

Summary For Further Reading References

Chapter3 Next-GenerationFuzzing

IntroductiontoFuzzing

TypesofFuzzers

MutationFuzzers

GenerationFuzzers

GeneticFuzzing

MutationFuzzingwithPeach

Lab3-1: MutationFuzzingwithPeach

GenerationFuzzingwithPeach

CrashAnalysis

Lab3-2: GenerationFuzzingwithPeach Geneticor EvolutionaryFuzzingwithAFL Lab3-3: GeneticFuzzingwithAFL Summary

For Further Reading

Chapter4 Next-GenerationReverseEngineering CodeAnnotation

IDBAnnotationwithIDAscope C++CodeAnalysis CollaborativeAnalysis

LeveragingCollaborativeKnowledgeUsingFIRST CollaborationwithBinNavi DynamicAnalysis

AutomatedDynamicAnalysiswithCuckooSandbox BridgingtheStatic-DynamicTool GapwithLabeless Summary

For Further Reading References

Chapter5 Software-DefinedRadio GettingStartedwithSDR WhattoBuy NotSoQuick: Know theRules LearnbyExample Search Capture Replay Analyze Preview Execute Summary

For Further Reading

Part II Businessof Hacking

Chapter6 SoYouWanttoBeaPenTester?

TheJourneyfromNovicetoExpert

PenTester Ethos

PenTester Taxonomy

TheFutureofHacking

Know theTech

Know WhatGoodLooksLike

PenTester Training

Practice

DegreePrograms

KnowledgeTransfer

PenTester Tradecraft

Personal Liability

BeingtheTrustedAdvisor

ManagingaPenTest

Summary

For Further Reading

Chapter7 RedTeamingOperations

RedTeamOperations

Strategic,Operational,andTactical Focus

AssessmentComparisons

RedTeamingObjectives

WhatCanGoWrong

LimitedScope

LimitedTime

LimitedAudience

OvercomingLimitations

Communications

PlanningMeetings

DefiningMeasurableEvents

UnderstandingThreats

AttackFrameworks

TestingEnvironment

AdaptiveTesting

External Assessment

Physical SecurityAssessment

Social Engineering

Internal Assessment

Summary

References

Chapter8 PurpleTeaming

IntroductiontoPurpleTeaming

BlueTeamOperations

Know Your Enemy

Know Yourself

SecurityProgram

IncidentResponseProgram

CommonBlueTeamingChallenges

PurpleTeamingOperations

DecisionFrameworks

DisruptingtheKill Chain

Kill ChainCountermeasureFramework

Communication

PurpleTeamOptimization

Summary For Further Reading References

Chapter9

BugBountyPrograms

HistoryofVulnerabilityDisclosure

Full Vendor Disclosure

Full PublicDisclosure

ResponsibleDisclosure

NoMoreFreeBugs

BugBountyPrograms

TypesofBugBountyPrograms

Incentives

ControversySurroundingBugBountyPrograms

Popular BugBountyProgramFacilitators

BugcrowdinDepth

ProgramOwner WebInterface

ProgramOwner APIExample

Researcher WebInterface

EarningaLivingFindingBugs

SelectingaTarget

Registering(IfRequired)

UnderstandingtheRulesoftheGame

FindingVulnerabilities

ReportingVulnerabilities

CashingOut

IncidentResponse

Communication

Triage

Remediation

DisclosuretoUsers

PublicRelations

Summary For Further Reading References

Part III ExploitingSystems

Chapter10 GettingShellsWithoutExploits

CapturingPasswordHashes

UnderstandingLLMNRandNBNS UnderstandingWindowsNTLMv1andNTLMv2Authentication UsingResponder

Lab10-1: GettingPasswordswithResponder UsingWinexe

Lab10-2: UsingWinexetoAccessRemoteSystems

Lab10-3: UsingWinexetoGainElevatedPrivileges UsingWMI

Lab10-4: QueryingSystemInformationwithWMI

Lab10-5: ExecutingCommandswithWMI TakingAdvantageofWinRM

Lab10-6: ExecutingCommandswithWinRM

Lab10-7: UsingWinRMtoRunPowerShell Remotely Summary

For Further Reading Reference

Chapter11 BasicLinuxExploits

StackOperationsandFunction-CallingProcedures

Buffer Overflows

Lab11-1: Overflowingmeet.c

RamificationsofBuffer Overflows

Local Buffer Overflow Exploits

Lab11-2: ComponentsoftheExploit

Lab11-3: ExploitingStackOverflowsfromtheCommandLine

Lab11-4: ExploitingStackOverflowswithGenericExploit Code

Lab11-5: ExploitingSmall Buffers

ExploitDevelopmentProcess

Lab11-6: BuildingCustomExploits

Summary For Further Reading

Chapter12 AdvancedLinuxExploits

FormatStringExploits

FormatStrings

Lab12-1: ReadingfromArbitraryMemory

Lab12-2: WritingtoArbitraryMemory

Lab12-3: ChangingProgramExecution

MemoryProtectionSchemes

Compiler Improvements

Lab11-4: BypassingStackProtection Kernel PatchesandScripts

Lab12-5: ReturntolibcExploits

Lab12-6: MaintainingPrivilegeswithret2libc BottomLine

Summary For Further Reading References

Chapter13 WindowsExploits

CompilingandDebuggingWindowsPrograms

Lab13-1: CompilingonWindows WindowsCompiler Options

Chapter14

DebuggingonWindowswithImmunityDebugger

Lab13-2: CrashingtheProgram

WritingWindowsExploits

ExploitDevelopmentProcessReview

Lab13-3: ExploitingProSSHDServer

UnderstandingStructuredExceptionHandling(SEH) UnderstandingandBypassingWindowsMemoryProtections

SafeStructuredExceptionHandling(SafeSEH)

BypassingSafeSEH

SEHOverwriteProtection(SEHOP)

BypassingSEHOP

Stack-BasedBuffer OverrunDetection(/GS)

Bypassing/GS

HeapProtections

Summary For Further Reading

References

AdvancedWindowsExploitation

DataExecutionPrevention(DEP)

AddressSpaceLayoutRandomization(ASLR) EnhancedMitigationExperienceToolkit(EMET) andWindows

Defender ExploitGuard

BypassingASLR

BypassingDEPandAvoidingASLR

VirtualProtect

Return-OrientedProgramming Gadgets

BuildingtheROPChain

DefeatingASLRThroughaMemoryLeak

TriggeringtheBug

TracingtheMemoryLeak

WeaponizingtheMemoryLeak

BuildingtheRVAROPChain

Summary

For Further Reading

References

Chapter15 PowerShell Exploitation

WhyPowerShell

LivingOfftheLand

PowerShell Logging

PowerShell Portability

LoadingPowerShell Scripts

Lab15-1: TheFailureCondition

Lab15-2: PassingCommandsontheCommandLine

Lab15-3: EncodedCommands

Lab15-4: BootstrappingviatheWeb ExploitationandPost-ExploitationwithPowerSploit

Lab15-5: SettingUpPowerSploit

Lab15-6: RunningMimikatzThroughPowerShell

Lab15-7: CreatingaPersistentMeterpreter UsingPowerSploit UsingPowerShell Empirefor C2

Lab15-8: SettingUpEmpire

Lab15-9: StaginganEmpireC2

Lab15-10: UsingEmpiretoOwntheSystem Summary

For Further Reading References

Chapter16

Next-GenerationWebApplicationExploitation

TheEvolutionofCross-SiteScripting(XSS)

SettingUptheEnvironment

Lab16-1: XSSRefresher

Lab16-2: XSSEvasionfromInternetWisdom

Lab16-3: ChangingApplicationLogicwithXSS

Lab16-4: UsingtheDOMfor XSS FrameworkVulnerabilities

SettingUptheEnvironment

Lab16-5: ExploitingCVE-2017-5638

Lab16-6: ExploitingCVE-2017-9805 PaddingOracleAttacks

Lab16-7: ChangingDatawiththePaddingOracleAttack Summary For Further Reading

References

Chapter17 Next-GenerationPatchExploitation

IntroductiontoBinaryDiffing

ApplicationDiffing

PatchDiffing

BinaryDiffingTools

BinDiff

turbodiff

Lab17-1: Our FirstDiff

PatchManagementProcess

MicrosoftPatchTuesday

ObtainingandExtractingMicrosoftPatches

Lab17-2: DiffingMS17-010

PatchDiffingfor Exploitation

DLLSide-LoadingBugs

Lab17-3: DiffingMS16-009

Summary

For Further Reading References

Part IV Advanced MalwareAnalysis

Chapter18 DissectingMobileMalware

TheAndroidPlatform

AndroidApplicationPackage ApplicationManifest

AnalyzingDEX

JavaDecompilation

DEXDecompilation

DEXDisassembling

Example18-1: RunningAPKinEmulator

MalwareAnalysis

TheiOSPlatform

iOSSecurity

iOSApplications

Summary

For Further Reading References

Chapter19 DissectingRansomware

TheBeginningsofRansomware

Optionsfor PayingtheRansom

DissectingRansomlock

Example19-1: DynamicAnalysis

Example19-2: StaticAnalysis

Wannacry

Example19-3: AnalyzingWannacryRansomware

Summary For Further Reading

Chapter20 ATMMalware

ATMOverview

XFSOverview

XFSArchitecture

XFSManager

ATMMalwareAnalysis

TypesofATMMalware

Techniquesfor InstallingMalwareonATMs

Techniquesfor DissectingtheMalware ATMMalwareCountermeasures

Summary For Further Reading References

Chapter21 Deception: Next-GenerationHoneypots

BriefHistoryofDeception

HoneypotsasaFormofDeception DeploymentConsiderations

SettingUpaVirtual Machine

OpenSourceHoneypots

Lab21-1: Dionaea

Lab21-2: ConPot

Lab21-3: Cowrie

Lab21-4: T-Pot

Commercial Alternative: TrapX

Summary

For Further Reading References

Part V Internetof Things

Chapter22

InternetofThingstoBeHacked

InternetofThings(IoT)

TypesofConnectedThings

WirelessProtocols

CommunicationProtocols

SecurityConcerns

ShodanIoTSearchEngine

WebInterface

ShodanCommand-LineInterface

Lab22-1: UsingtheShodanCommandLine ShodanAPI

Lab22-2: TestingtheShodanAPI

Lab22-3: PlayingwithMQTT

ImplicationsofThisUnauthenticatedAccesstoMQTT

IoTWorms: ItWasaMatter ofTime

Lab22-4: Mirai Lives Prevention

Summary For Further Reading References

Chapter23 DissectingEmbeddedDevices

CPU

Microprocessor

Microcontrollers

SystemonChip(SoC)

CommonProcessor Architectures

Serial Interfaces

UART

SPI

DebugInterfaces

JTAG

SWD(Serial WireDebug)

Software

Bootloader

NoOperatingSystem

Real-TimeOperatingSystem

General OperatingSystem

Summary For Further Reading References

Chapter24 ExploitingEmbeddedDevices

StaticAnalysisofVulnerabilitiesinEmbeddedDevices

Lab24-1: AnalyzingtheUpdatePackage

Lab24-2: PerformingVulnerabilityAnalysis

DynamicAnalysiswithHardware

TheTestEnvironmentSetup Ettercap

DynamicAnalysiswithEmulation FIRMADYNE

Lab24-3: SettingUpFIRMADYNE

Lab24-4: EmulatingFirmware

Lab24-5: ExploitingFirmware

Summary

Further Reading References

Chapter25 FightingIoTMalware

Physical AccesstotheDevice

RS-232Overview

RS-232Pinout

Exercise25-1: TroubleshootingaMedical Device’sRS-232 Port

SettingUptheThreatLab

ARMandMIPSOverview

Lab25-1: SettingUpSystemswithQEMU DynamicAnalysisofIoTMalware

Lab25-2: IoTMalwareDynamicAnalysis Platformfor Architecture-Neutral DynamicAnalysis(PANDA) BeagleBoneBlackBoard

ReverseEngineeringIoTMalware

Crash-CourseARM/MIPSInstructionSet

Lab25-3: IDAProRemoteDebuggingandReversing IoTMalwareReversingExercise

Summary

For Further Reading Index

Thisbookhasbeendevelopedbyandfor securityprofessionalswhoarededicatedto workinginanethical andresponsiblemanner toimprovetheoverall securitypostureof individuals,corporations,andnations.

ACKNOWLEDGMENTS

Eachof the authorswouldliketothankthestaffatMcGraw-Hill Education.In particular,wewouldliketothankWendyRinaldi andClaireYee.Youreallywent aboveandbeyond,keepingusontrackandgreatlyhelpingusthroughtheprocess.Your highestlevelsofprofessionalismandtirelessdedicationtothisprojectweretruly noteworthyandbringgreatcredittoyour publisher.Thanks.

AllenHarperwouldliketothankhiswonderful wifeCorannandbeautiful daughters HaleyandMadisonfor their supportandunderstandingasIchasedyetanother dream.

Itiswonderful toseeour familyandeachofusindividuallygrow stronger inChrist eachyear.MadisonandHaley,Iloveyoubothdearlyandamproudoftheyoungladies youhavebecome.Inaddition,Iwouldliketothankthemembersofmyformer and currentemployer.TothefriendsatTangibleSecurity,Iamthankful for your impacton mylife youmademebetter.TomybrothersandsistersinChristatLibertyUniversity, Iamexcitedfor theyearsaheadaswelabor together andaimtotrainChampionsfor Christ!

DanielRegaladolegustaríaagradecer primeroaDiospor labendicióndeestar vivo,asuesposaDianapor aguantarlo,por siempremotivarlo,por festejar cadaunode sustriunfoscomosi fuerandeella,por ser tanbellayatlética,teamo!Asushijos FerchoyAndrickpor ser laluzdelacasaysumotor decadadiayfinalmenteperono menosimportantealaFamiliaRegaladoArias: Fernando,Adelina,SusanaErwiny Belem,sinellos,sustriunfosnosabríanigual,losamo!YasuPapaFernando,hastael ultimodiaquerespire,viviréconlaesperanzadevolver aabrazarte.Cape,Cone, Rober,hermandadparasiempre!

BrankoSpasojevicwouldliketothankhisfamily Sanja,Sandra,AnaMarija, Magdalena,Ilinka,Jevrem,Olga,Dragisa,Marija,andBranislav for all thesupport andknowledgetheypassedon.

Another bigthanksgoestoall myfriendsandcolleagueswhomakeworkandplay fun.Somepeoplewhodeservespecial mentionareAnteGulam,Antonio,Cedric, Clement,Domagoj,Drazen,Goran,Keith,Luka,Leon,Matko,Santiago,Tory,and everyoneinTAG,Zynamics,D&R,andOrca.

RyanLinnwouldliketothankHeather for her support,encouragement,andadviceas well ashisfamilyandfriendsfor their supportandfor puttingupwiththelonghours

andinfrequentcommunicationwhilethebookwascomingtogether.

ThanksalsogoouttoEdSkoudisfor pushingmetodoawesomethings,andtoHD, Egypt,Nate,Shawn,andall theother friendsandfamilywhohaveofferedcode assistance,guidance,andsupportwhenI’veneededitthemost.

StephenSimswouldliketothankhiswifeLeAnneanddaughter Audreyfor their ongoingsupportwiththetimeneededtoresearch,write,work,teach,andtravel.

Hewouldalsoliketothankhisparents,GeorgeandMary,andsister,Lisa,for their supportfromafar.Finally,aspecial thankstoall ofthebrilliantsecurityresearchers whocontributesomuchtothecommunitywithpublications,lectures,andtools.

ChrisEagle wouldliketothankhiswifeKristenfor beingtherockthatallowshimto doall ofthethingshedoes.Noneofitwouldbepossiblewithouther continuedsupport.

LindaMartinez wouldliketothankher momanddadfor beingtrulydelightful peopleandalwayssettingagreatexampletofollow.Lindawouldalsoliketothankher daughter Elysiafor theyearsofencouragementthatallowedher topursueher passions.

Abigthankstomyfriendsandsomeofthebrightestmindsintheindustry Allen, Zack,Rob,Ryan,Bill,andShon,maysherestinpeace.

MichaelBaucomwouldliketothankhiswife,Bridget,anddaughter,Tiernan,for their sacrificesandsupportinallowinghimtopursuehisprofessional goals.

I’dalsoliketothankmyparentsfor your love,support,andinstillinginmethework ethicthathascarriedmetothispoint.Additionally,I’dliketothanktheMarineCorps for givingmethecourageandconfidencetounderstandthatall thingsarepossible. Finally,I’dliketothankmybrother inChrist,long-timefriend,andcolleague,Allen Harper.Nothingcanbeaccomplishedwithoutagreatteam.

We,the authors,wouldalsoliketocollectivelythankHex-Raysfor thegeneroususe oftheir tool,IDAPro.

INTRODUCTION

Historyteachesthatwarsbeginwhengovernmentsbelievethepriceofaggression ischeap.

Youcan’tsaycivilizationdon’tadvance…ineverywar theykill youinanew way. Will Rogers

Thesupremeartofwar istosubduetheenemywithoutfighting.

Thepurposeofthisbookistoprovideindividualstheinformationonceheldonlyby governmentsandafew blackhathackers.Inthisdayandage,individualsstandinthe breachofcyberwar,notonlyagainstblackhathackers,butsometimesagainst governments.Ifyoufindyourselfinthisposition,either aloneor asadefender ofyour organization,wewantyoutobeequippedwithasmuchknowledgeoftheattacker as possible.Tothatend,wesubmittoyouthemindsetofthegrayhathacker,anethical hacker thatusesoffensivetechniquesfor defensivepurposes.Theethical hacker always respectslawsandtherightsofothers,butbelievestheadversarymaybebeattothe punchbytestingoneselffirst.

Theauthorsofthisbookwanttoprovideyou,thereader,withsomethingwebelieve theindustryandsocietyingeneral needs: aholisticreview ofethical hackingthatis responsibleandtrulyethical initsintentionsandmaterial.Thisiswhywekeep releasingnew editionsofthisbookwithaclear definitionofwhatethical hackingisand isnot somethingour societyisveryconfusedabout.

Wehaveupdatedthematerial fromthefourtheditionandhaveattemptedtodeliver the mostcomprehensiveandup-to-dateassemblyoftechniques,procedures,andmaterial withreal hands-onlabsthatcanbereplicatedbythereaders.Thirteennew chaptersare presented,andtheother chaptershavebeenupdated.

InPartI,weprepareyoufor thebattlewithall thenecessarytoolsandtechniquesto getthebestunderstandingofthemoreadvancedtopics.Thissectionmovesquite quicklybutisnecessaryfor thosejuststartingoutinthefieldandotherslookingtomove tothenextlevel.Thissectioncoversthefollowing:

SunTzu

• White,black,andgrayhatdefinitionsandcharacteristics

• Theslipperyethical issuesthatshouldbeunderstoodbeforecarryingoutanytype ofethical hackingactivities

• Programmingsurvival skills,whichisamust-haveskill for agrayhathacker tobe abletocreateexploitsor review sourcecode

• Fuzzing,whichisawonderful skill for finding0-dayexploits

• Reverseengineering,whichisamandatoryskill whendissectingmalwareor researchingvulnerabilities

• Exploitingwithsoftware-definedradios

InPartII,wediscussthebusinesssideofhacking.Ifyouarelookingtomovebeyond hackingasahobbyandstartpayingthebills,thissectionisfor you.Ifyouarea seasonedhackingprofessional,wehopetooffer youafew tipsaswell.Inthissection, wecover someofthesofter skillsrequiredbyanethical hacker tomakealiving:

• How togetintothepenetrationtestingbusiness

• How toimprovetheenterprisesecurityposturethroughredteaming

• Anovel approachtodevelopingapurpleteam

• Bugbountyprogramsandhow togetpaidfindingvulnerabilities,ethically

InPartIII,wediscusstheskillsrequiredtoexploitsystems.Eachofthesetopicshas beencoveredbefore,buttheoldexploitsdon’tworkanymore;therefore,wehave updatedthediscussionstoworkpastsystemprotections.Wecover thefollowingtopics inthissection:

• How togainshell accesswithoutexploits

• BasicandadvancedLinuxexploits

• BasicandadvancedWindowsexploits

• UsingPowerShell toexploitsystems

• Modernwebexploits

• Usingpatchestodevelopexploits

InPartIV,wecover advancedmalwareanalysis.Inmanyways,thisisthemost advancedtopicinthefieldofcybersecurity.Onthefrontlinesofcyberwar ismalware, andweaimtoequipyouwiththetoolsandtechniquesnecessarytoperformmalware analysis.Inthissection,wecover thefollowing:

• Mobilemalwareanalysis

• Recentransomwareanalysis

• ATMmalwareanalysis

• Usingnext-generationhoneypotstofindadvancedattackersandmalwareinthe network

Finally,inPartV,weareproudtodiscussthetopicofInternetofThings(IoT) hacking.TheInternetofThingsisexplodingand,unfortunately,soarethevulnerabilities therein.Inthissection,wediscusstheselatesttopics:

• InternetofThingstobehacked

• Dissectingembeddeddevices

• Exploitingembeddeddevices

• MalwareanalysisofIoTdevices

Wedohopeyouwill seethevalueofthenew contentthathasbeenprovidedandwill alsoenjoythenewlyupdatedchapters.Ifyouarenew tothefieldor readytotakethe nextsteptoadvanceanddeepenyour understandingofethical hacking,thisisthebook for you.

NOTE Toensureyour systemisproperlyconfiguredtoperformthelabs,wehave providedthefilesyouwill need.Thelabmaterialsanderratamaybedownloadedfrom either theGitHubrepositoryathttps://github.com/GrayHatHacking/GHHv5or the publisher’ssite,atwww.mhprofessional.com.

PARTI Preparation

Chapter1 WhyGrayHatHacking?EthicsandLaw

Chapter2 ProgrammingSurvival Skills

Chapter3 Next-GenerationFuzzing

Chapter4 Next-GenerationReverseEngineering

Chapter5 Software-DefinedRadio

WhyGrayHatHacking?Ethicsand Law

Thepurposeofthisbookistosupportindividualswhowanttorefinetheir ethical hackingskillstobetter defendagainstmaliciousattackers.Thisbookisnotwrittentobe usedasatool bythosewhowishtoperformillegal andunethical activities. Inthischapter,wediscussthefollowingtopics:

• Know your enemy: understandingyour enemy’stactics

• Thegrayhatwayandtheethical hackingprocess

• Theevolutionofcyberlaw

KnowYourEnemy

“Wecannotsolveour problemswiththesamelevel ofthinkingthatcreatedthem.”

AlbertEisenstein

Thesecuritychallengeswefacetodaywill paleincomparisontothosewe’ll faceinthe future.Wealreadyliveinaworldsohighlyintegratedwithtechnologythat cybersecurityhasanimpactonour financial markets,our elections,our families,and our healthcare.Technologyisadvancingandthethreatlandscapeisincreasing.Onthe onehand,vehiclesthatarecapableofautonomousdrivingarebeingmass-producedas smartcitiesarebeingdeveloped.Ontheother hand,hospitalsarebeingheldfor ransom,power gridsarebeingshutdown,intellectual propertyandsecretsarebeing stolen,andcybercrimeisaboomingindustry.Inorder todefendandprotectour assets andour people,wemustunderstandtheenemyandhow theyoperate.Understanding how attacksareperformedisoneofthemostchallengingandimportantaspectsof defendingthetechnologyonwhichwerely.After all,how canwepossiblydefend ourselvesagainsttheunknown?

Thisbookwaswrittentoproviderelevantsecurityinformationtothosewhoare dedicatedtostoppingcyberthreats.Theonlywaytoaddresstodayandtomorrow’s

Turn static files into dynamic content formats.

Create a flipbook
Gray hat hacking: the ethical hacker's handbook, fifth edition daniel regalado - ebook pdf - The com by pearltryon9973 - Issuu