Skip to content

Red Team Training Syllabus

Source: Feishu document mind map

(Anti-)Attribution Techniques

Work Environment Configuration

Host Disk Encryption

Virtual Machine Environment Configuration

  • Remove Bluetooth and the NAT network adapter
  • shadow defender
  • Mount a shared folder to place files
  • Keep the penetration machine separate from the reporting machine
  • Do not allow WPS to sync documents
  • mybase
  • keepass

Personal Information Cleanup

Android VM + Physical Machine

Whom Anti-Attribution Targets

  • Gambling white-label platform providers
  • IP
    • Account

Which Chains Were Built

What Information Each Hop of the Chain Leaks

Who Can Obtain This Information

Time Cost?

Required Permissions

Network Environment Configuration

Anonymous Work Chain Configuration

  • Anonymous host environment selection
  • Non-mainland regions
    • shockhosting
    • psychz.net
    • Not Hong Kong Alibaba Cloud
    • Amazon Web Services
    • cf
    • jtti.cc
  • Preferably supports USDT
  • Do not pick hosts from the same hosting provider
  • Chain setup
  • Overseas data SIM -> frp -> SoftEther VPN -> lunaproxy (dynamic residential proxy)
  • https://github.com/SoftEtherVPN/SoftEtherVPN_Stable
  • Overseas data SIM -> lunaproxy -> traffic proxy
  • Domestic data SIM -> SoftEther VPN -> traffic proxy
  • Anonymous traffic device
  • VPN configuration and trace cleanup

Penetration Testing Environment and Tool Configuration

Create Accounts

Tools

Wordlists

https://lcx.cc/post/3213/

White-Label iGaming Platform Providers

Financier -> provides site-building services/development

  • Code + setup
  • Code + setup + operations
  • Self-built site
  • Gambling -> page links to a large batch of sites

Counterintelligence and Counter-espionage

Commercial Espionage (content deleted)

  • How to buy off an insider
  • Commercial consulting firm playbook
  • How to sell out an insider
  • How to investigate and root out an insider
  • Analysis and attribution of stolen-data supply chains

Geopolitical Confrontation | Spies of Different Regimes (content deleted)

Reconnaissance

Website Reconnaissance

SGK data source collection

What to Look at Once You Have a Site

  • Use paramspider to build wordlists
  • to do

Open-Source Reconnaissance

  • github
  • Keywords
    • ldap
    • Combine with domain asset information
      • Internal network asset information
    • login
    • Small businesses
    • Project linkage -> information under the account
    • Pinyin (abbreviations)
    • Subdomains
    • Internal domain names
    • com.xxx
    • Chinese
    • js/css/html/special filenames
  • Person linkage
    • star
    • fork
    • commit
    • follow
  • https://securitytrails.com/
  • Subdomains
  • fofa/hunter/...
  • ico
  • title
  • body
  • Find source code
    • Scan for backups
    • Black-box -> white-box
  • gitee/Kancloud/Yuque/hackmd.io/Shimo
  • site:"yuque.com" "xxx"
  • News
  • https://sigma.world/zh-hant/cis/floor-plan/
  • Google dorks
  • duckduckgo
    • site:xxx.com -www -fare -css -parking
  • hackone/https://zeroday.hitcon.org/
  • Twitter/facebook/linkin
  • Employees
    • Initial passwords follow a pattern
  • Cloud drives
  • Third-party
  • medium
  • Not mandatory
    • Get a membership

Supply Chain Reconnaissance

  • Supplier conferences
  • Overseas enterprises
  • Bidding and tendering
  • Page fingerprints
  • js/css/html

OSINT Reconnaissance

Bypass CDN

  • Page fingerprints to find the real IP
  • Historical DNS resolution to find the real IP
  • IP ranges of related businesses to find the real IP

Practical Attribution of Site-Building Companies

Attribution of Gambling White-Label Platform Providers

  • Same CDN
  • Same DNS
  • Same data center
  • Same page fingerprints to find test-site domain/IP linked to the platform provider
  • Fuzzy search on same-keyword-feature domains
  • Find customer support to match templates

Attribution of Gang Member Information

  • Historical posts linked to accounts
  • Special IDs
  • sgk
  • File metadata
  • Phishing

Penetration-Strike Breakthrough Ideas and Methods

Black-Box Rapid Initial-Access Approach

  • Gambling sites
  • _
    • Penetration testing
    • Identify the version
    • Set up locally
    • Tools
      • Vulnerabilities
      • Vulnerabilities require permissions
      • Vulnerability principles
      • Packet capture
      • Modify yourself
    • Reconnaissance
    • Vulnerability accumulation
    • Vulnerability accumulation
  • Promo sites
    • Injection
    • Modify sqlmap
      • Specified database, specified table
      • Remove all probe content
    • Backup files
    • Framework vulnerabilities
    • RCE/deserialization vulnerabilities
    • Upload
    • Arbitrary file read/write
    • github\google
    • https://xvi.vulbox.com/
    • Temporary setups
    • After compromise, dig through files for lateral movement
      • mq
      • Phishing
    • Before
    • Sold as a package
      • Easy to search
      • Together with the actual site
    • Rare
    • Collect domain assets for further expansion
    • Multiple platform-provider sub-sites share one promo site
    • Use platform-provider-related domains
  • Customer-service sites
    • xss
    • Phishing
    • electron rce
    • Self-built from purchased source code
    • markdown
      • Tags
    • Find the customer-service vendor's demo site and source code
    • Find the admin panel
    • Directory scan
    • Attribute platform-provider assets via customer-service site assets
    • 94chat
    • Social-engineer customer support for more site information
    • Taking the customer-service site does not yield core data
  • Page fingerprints to find related sites
    • js
    • js console
    • Static resource loading
    • wss
    • Unreliable
  • Attack the platform provider
    • Ops services
    • Jenkins
    • Various domestic OA management software
    • mq
    • Test sites
    • Weak passwords
    • getshell
      • Lateral
      • Malware/phishing
      • yun
        • Client machines
      • Grab source code
      • Error debugging
    • Collect admin-panel APIs
      • ../../
    • Source-code resellers
      • Briefly chat
      • Scan backups
      • Black-box
      • Find more page fingerprints from admin-panel page resources
      • money.php
      • Admin-panel debug errors
        • Special database table names, filenames
    • Historical edge assets
    • Platform providers are hard to find
    • bbscan to find backups for quick code audit
    • Backups only apply to this site
      • Admin API, backend filenames
    • Is privilege escalation meaningful?
    • When the admin panel has multiple admin accounts
    • Vertical privilege escalation
      • More API permissions
    • Horizontal privilege escalation
      • Whole site
    • Reconnaissance, black-box, white-box, internal network
      • Attack target
      • Clear division of roles
      • Corporate employees
      • Complete a target end-to-end independently
      • CaA
      • Burp, Yakit
      • cpacha_killer_modify
      • When Burp can't capture traffic because its fingerprint is detected, modify TLS
      • Choose the basic one
      • PoC verification
        • Scanner development
        • Try not to carry attack signatures
        • Make request payloads harmless
  • What is the target
    • Compromise the white-label platform
    • Control all data
    • Rights protection
    • Supply chain
      • Customer credentials and payment info
    • Console sub-permissions
    • Obtain source code
    • Control ops and dev, at worst control customer service
    • Whether to control customers further down
      • 2FA verification
      • Bind HTTPS
      • Google Authenticator
      • Phone binding
      • Microsoft Authenticator
      • IP whitelist
      • XFF header
      • If vulnerable, modify config
      • Login IP
      • Chrome remote debug
      • Cookie/storage
  • Fourth-party payment / external platforms (switched target)
    • Login proxy
    • Username varies
    • Loaded assets change
    • New domain characteristics can't be correlated back to the origin server
    • Find the framework
    • Find assets
    • Find vulnerabilities
  • The big get bigger, the small get smaller
    • Buy a gambling license (registration)
    • Formalize, incorporate, scale up
      • Azure
      • Cloud applications
      • High difficulty, high time cost
      • Long prison terms, dampens motivation
    • The original operation was compromised
    • Sell source code
      • Outdated
      • Frontend unreliable
        • Backend code was modified
        • uniapp frontend
          • Hired private developers
          • Backend | API | filename xxx.php
      • Code incomplete
      • The dumped code
        • Not fully decrypted
      • Logic has issues
      • Collector
        • Legitimate data collection
        • Add lottery types and rounds you can control
    • Credit platform | Casino
      • Main target
    • QB
      • 6-month trial period
      • Compromise and maintain long-term persistence
    • Blockchain
      • Web3
      • Pig-butchering scam
      • BTC gambling games
    • TG bot
    • The original boss quit
      • His people resell it
      • Originally had few vulnerabilities
      • Does the source code have backdoors
    • Micro-trading platform
      • Refined chat
  • cp
  • Injection
    • SQL injection in the betting flow
    • Connects to external lottery APIs, the main site is self-hosted
    • Frontend/backend encryption
    • Check-in injection
    • Roulette event
    • orderby=rand(1=1)
  • Customer service site
    • Invitation code
    • 53
    • meiqia
  • Directory site
  • Chat room
    • XSS
    • ws
    • Locate the white-label platform
  • Image site
    • Locate the white-label platform
    • img.xxx.com
    • Management system
  • Editor
    • Arbitrary file upload
    • XSS
    • ueiditor
    • PHP
      • SSRF
      • Internal network live ports
      • Real IP
        • DNS
        • 176.xxxx
    • dotnet
      • Upload
  • Points system
    • Abandoned
  • Demo site
    • Compromise the source code
  • Error messages
    • JSON closing
    • Array of variable names
    • word[]=xxx
      • java \ php \ middleware
      • cf
  • Multiple ports
    • High ports running other services
    • Real IP
    • Bound to different domains
    • nginx reverse proxy
    • 80-30000+
  • Set up BaoTa / HuWeiShen
    • Lab practice
    • Injection
    • Upload
    • Change password
    • Shut down services
  • Dump the database
    • adminer
    • Transfer to the server in chunks
    • Web directory
    • GitHub LFS
      • Action
  • Deserialization
  • Mainstream domestic domains
    • Common SRCs
    • Gambling sites, fraud sites
    • Collected in bulk via signatures
    • Crawler
    • Build wordlists
  • zp
  • Quick initial access on this site
    • Directories
    • Ports
    • Weak credentials
    • bbscan to find backups, quick code audit
    • Avatar upload
    • Voice Moments upload
    • Phishing
      • SH
    • Nude chat, same-city free
    • Task-based order brushing
  • n websites
    • 1-2 months
  • Half year to 1 year
  • PHP
    • Variable overwrite
  • Routes
    • filter, WAF,
    • Extract and run a scan
  • Vulnerability points
    • Config files
    • Hardcoded
      • Cookie forgery
    • Dangerous functions
    • Debug
      • Black Lily
    • How to trigger and what conditions are needed
    • Routes
    • Permissions
  • Temporarily buy a server

Common Vulnerability Principles and Exploitation Tools and Approaches

Trace cleanup

  • unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG; export HISTFILE=/dev/null; export HISTSIZE=0; export HISTFILESIZE=0
  • Modify file timestamps
  • Internal network discovery logic
  • Strictly no scanning inside the internal network
  • Access the internal network according to machine logic
  • Discover the internal network via existing connections
  • Script tasks
  • Single-threaded
  • Scan a single port
  • Randomized IP addresses
  • Random delay after scanning

**Code Audit **

Hands-on Java Code Audit

BC Site Source-Code Audit for Getshell (Hands-on)

  • pom
  • SQL injection
    • mybatis
    • Strict typing
    • order by ${time}
    • LIKE '%${stuName}%'
    • in (${id})
    • Directly invoked statements
    • OGNL injection
      • .raw -O vmdk .vmdk

      Modify the VM configuration

      • Choose "use existing disk"

      Change the password

      • At the boot screen, select the first entry and press e to enter single-user mode
      • Delete everything after ro and replace it with rw init=/bin/bash
      • Remove the Alibaba Cloud cloud-init
      • rm -rf $(find / 2>/dev/null|grep cloud-init)
      • passwd
      • Change the password

      Modify the network

      • ip a
      • dhclient eth0
      • Set the network to host-only

      View command history

      View services

      Files corresponding to services

      hw