2019-010-Zach_Ruble-building_a_better_cheaper_C2_infra episode artwork

EPISODE · Mar 18, 2019 · 1H 12M

2019-010-Zach_Ruble-building_a_better_cheaper_C2_infra

from BrakeSec Education Podcast

Shout-out to Thomas…     Tried to meetup while at SEA comic-con Patreon Log-MD Hacker's Health - Ms. Roddie is at TROOPERS (Ms. Berlin?) 4 podcasts? SpecterOps Training / workshopCon  - https://www.workshopcon.com/events Zach Ruble- @sendrublez C2 infra using Public WebApps TARCE - Teaching Assistant RCE(?) - they run your code every week, don't check for backdoors before running it... C2 Basics     Local HTTPd server (bashfile)     Python scrapes web server 3 components -Servers -Communication channels -Malware and client - 3 Requirements of a C2 -victim receives commands -Vic executes -Send results back Web server serving a static file Malware on machine scraping site with python requests and executing it as commands. Crontab @reboot   State change = change the text field https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-britney-spears-instagram-posts-to-control-malware/ https://uwbacm.com/   Long haul/short haul server Long haul - regain persistence Short haul - sends commands to victims   Slack as C2 - Blends in to the Env     Send and receive messages     Using Real Time Messaging API https://3xpl01tc0d3r.blogspot.com/2018/06/how-to-use-slack-as-c2-sever.html https://link.springer.com/chapter/10.1007/978-3-319-27137-8_24 https://glitch.com/ Https://github.com/bkup/SlackShell   Reddit as a C2     "Reddit Rising"   Glitch.com     Serverless platform   Using Google search results as     Would Google Algos see odd behavior of hundreds of hosts searching for the same thing? Log file analysis?     How can we protect against this? C2 News (If we go short) : https://www.zdnet.com/article/outlaws-shellbot-infects-servers-for-monero-mining Automating OSINT https://twitter.com/jms_dot_py http://www.automatingosint.com/blog/   Check out our Store on Teepub! https://brakesec.com/store Join us on our #Slack Channel! Send a request to @brakesec on Twitter or email [email protected] #Brakesec Store!:https://www.teepublic.com/user/bdspodcast #Spotify: https://brakesec.com/spotifyBDS #RSS: https://brakesec.com/BrakesecRSS #Youtube Channel:  http://www.youtube.com/c/BDSPodcast #iTunes Store Link: https://brakesec.com/BDSiTunes #Google Play Store: https://brakesec.com/BDS-GooglePlay Our main site:  https://brakesec.com/bdswebsite #iHeartRadio App:  https://brakesec.com/iHeartBrakesec #SoundCloud: https://brakesec.com/SoundcloudBrakesec Comments, Questions, Feedback: [email protected] Support Brakeing Down Security Podcast by using our #Paypal: https://brakesec.com/PaypalBDS OR our #Patreon https://brakesec.com/BDSPatreon #Twitter: @brakesec @boettcherpwned @bryanbrake @infosystir #Player.FM : https://brakesec.com/BDS-PlayerFM #Stitcher Network: https://brakesec.com/BrakeSecStitcher #TuneIn Radio App: https://brakesec.com/TuneInBrakesec

NOW PLAYING

2019-010-Zach_Ruble-building_a_better_cheaper_C2_infra

0:00 1:12:04

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Big Old Life: Heather Blackbird interviews people on planet earth. Heather Blackbird loves asking questions. This podcast is a learning experience. Join me, Heather Blackbird, as I talk to people about their lives. Frequency of new episodes is a little all over the place and I'm learning as I go. Big Old Life is a small way of talking about the vastness of life, one person at a time. If you are reading this or found this podcast it's probably because someone you know gave you a link to it. :) Explicit The Sacred +Profane Podcast nephtaragrace The Sacred + Profane Podcast is a provocative conversation dedicated to cementing a better future for all. We specialize in unpacking the nuances of what is considered sacred and profane, particularly focusing on sex, death, and all that pertains to the circle of life. Our aim in focusing on such ”taboo” subject matter is to demystify what is unconscious, bring to light what has been known for centuries as ”the occult,” and empower the rapid transformation that is occurring on the Planet. Explicit Undeniable w/ Braxton Curtis Braxton Curtis The official Podcast of Braxton Curtis.A Father, Husband, and Business Owner just trying to figure it all out. Explicit Bitcoin Gateway Lea meakin Welcome to Bitcoin Gateway, the podcast where we dive deep into the world of Bitcoin, hosted by Lea Meakin. This show is for anyone who’s ever felt overwhelmed by the complex world of cryptocurrencies and wants a simple, straightforward explanation. Each episode, we’ll break down the basics of Bitcoin, explore its history, and discuss its potential impact on the future of finance. Whether you’re a complete beginner or just looking to expand your knowledge, Bitcoin Gateway is here to help you understand Bitcoin, one episode at a time. Explicit

Frequently Asked Questions

How long is this episode of BrakeSec Education Podcast?

This episode is 1 hour and 12 minutes long.

When was this BrakeSec Education Podcast episode published?

This episode was published on March 18, 2019.

What is this episode about?

Shout-out to Thomas…     Tried to meetup while at SEA comic-con Patreon Log-MD Hacker's Health - Ms. Roddie is at TROOPERS (Ms. Berlin?) 4 podcasts? SpecterOps Training / workshopCon  - https://www.workshopcon.com/events Zach Ruble- @sendrublez C2...

Can I download this BrakeSec Education Podcast episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!