JQ: Another Tool We Thought We Knew, (Mon, Jul 24th)

So often you&#;x26;#;39;ll see folks (me included) use “jq” to take an unformatted JSON mess and turn it into a readable output. For instance, last thursday we used the Shodan API to dump about 650k of host info like this:
curl -s -k “https://api.shodan.io/shodan/host/%1?key=%shodan-api-key%” | jq

Continue reading JQ: Another Tool We Thought We Knew, (Mon, Jul 24th)→

Posted in Uncategorized

Install & Configure Filebeat on Raspberry Pi ARM64 to Parse DShield Sensor Logs, (Sun, Jul 23rd)

Follow the step-by-step instructions provided [1] to install our DShield Sensor using Raspberry Pi Imager with Raspberry Pi OS Lite (64-bit). The following are the scripts used to parse the data published in this diary [4]. Al the scripts part of this diary are listed here with my other Elasticsearch projects.

Continue reading Install & Configure Filebeat on Raspberry Pi ARM64 to Parse DShield Sensor Logs, (Sun, Jul 23rd)→

Posted in Uncategorized

Shodan’s API For The (Recon) Win!, (Fri, Jul 21st)

Ever been on a call with a client, and had that “I need a full set of nmap results for that host in 5 seconds” moment&#;x26;#;x3f;&#;x26;#;xc2;&#;x26;#;xa0; Like when you&#;x26;#;39;re trying to scope out the size of a project (maybe a pentest project) and if you *just* had the list of open ports you&#;x26;#;39;d have an answer other than “I&#;x26;#;39;ll call you back”, because nmap will take 10 minutes&#;x26;#;x3f;

Continue reading Shodan’s API For The (Recon) Win!, (Fri, Jul 21st)→

Posted in Uncategorized

Deobfuscation of Malware Delivered Through a .bat File, (Thu, Jul 20th)

I found a phishing email that delivered a RAR archive (password protected). Inside the archive, there was a simple .bat file (SHA256: 57ebd5a707eb69dd719d461e1fbd14f98a42c6c3dcb8505e4669c55762810e70) with the following name: SRI DISTRITAL – DPTO DE COBRO -SRI Informa-Deuda pendiente.bat. Its current VT score is only 1/59![1]

Continue reading Deobfuscation of Malware Delivered Through a .bat File, (Thu, Jul 20th)→

Posted in Uncategorized

Citrix ADC Vulnerability CVE-2023-3519, 3466 and 3467 – Patch Now!, (Wed, Jul 19th)

Citrix released details on a new vulnerability on their ADC (Application Delivery Controller) yesterday (18 July 2023), CVE-2023-3519. This is an unauthenticated RCE (remote code execution), which means an attacker can run arbitrary code on your ADC without authentication.
This affects ADC hosts configured in any of the “gateway” roles (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), which commonly face the internet, or as an authentication virtual server (AAA server), which is usually visible only from internal or management subnets.

Continue reading Citrix ADC Vulnerability CVE-2023-3519, 3466 and 3467 – Patch Now!, (Wed, Jul 19th)→

Posted in Uncategorized