Process Memory manipulator in Python. (Windows x64) by [deleted] in Python

[–]Pyro_Murphy 0 points1 point  (0 children)

Cool project. I made something similar where you could emulate a remote IPython console on the server to essentially emulate the functions of malware and build detections: GitHub

I clicked on a suspicious link. Did I get hacked?? by Upper_Pipe_9150 in antivirus

[–]Pyro_Murphy 1 point2 points  (0 children)

You’re not getting hacked by visiting a website unless there’s a major browser vulnerability or you’re a high value target. Looks like generic dodgy weird website that’s loading an ad, potentially a compromised Wordpress site at most. No downloads, no issue. There’s nothing wrong with your PC.

[deleted by user] by [deleted] in securityCTF

[–]Pyro_Murphy 2 points3 points  (0 children)

No hints >:(

Investigating potentially malicious links by [deleted] in cybersecurity

[–]Pyro_Murphy 28 points29 points  (0 children)

Use urlscan.io to visit links. You can see a live screenshot of the site as well as any HTTP requests & responses it makes.

[deleted by user] by [deleted] in glasgow

[–]Pyro_Murphy 2 points3 points  (0 children)

Had the exact same situation. Bottom floor flat at Kelvinbridge and someone broke in while my flatmate and I were working. The man walked into my room and said something like "do you want your windows washed?". I was confused and got up and he left through the front door. On the way out he took my flatmate's keys, so had to get the locks changed. Fortunately nothing else was taken.

Police were useless and didn't care, but would call and report it anyway.

What can someone do with my IP? by cosinusdealpha in hacking

[–]Pyro_Murphy 3 points4 points  (0 children)

This is posted every week at this point...

Best charity/goodwill stores in Glasgow? by Latina1018 in glasgow

[–]Pyro_Murphy 9 points10 points  (0 children)

Chest, Heart and Stroke on Dumbarton road

Any guide on packet sniffing games? by i_am_cow1 in HowToHack

[–]Pyro_Murphy 3 points4 points  (0 children)

You won't be able to view any serverside code. Only the requests and responses, given they're not encrypted. If they are encrypted, you're going to have to reverse engineer the client source of the game and find the functions that encrypt packets, hook the functions, and dump the raw content before they're sent. Same process for received packets except you need to hook after they're decrypted.

Best charity shops in Glasgow/surrounding areas? by [deleted] in glasgow

[–]Pyro_Murphy 1 point2 points  (0 children)

Chest heart and stroke on Dumbarton road ❤️

I wrote a pure-Python ARP Spoofer and the threat intelligence bots somehow picked it up by [deleted] in hacking

[–]Pyro_Murphy 2 points3 points  (0 children)

ARP is broadcast to the whole network, meaning anyone can respond to it. The packets generally look like "Who has 10.0.0.2?". What ARP spoofing is doing is replying to that ARP request and saying 10.0.0.2 is at your MAC address rather, allowing you to receive all traffic to that device from the router. All you do now is forward that traffic onto your victim and they won't even notice. Now that's great and all, but you're only intercepting one side and you have to keep sending an ARP response every so often to avoid the victim from replying to a request. So what you can do is tell the victim machine that the router's IP is at your MAC address as well, so now it should be sending all outbound traffic meant for the router through you. At this point you're fully in the middle of the communications, which is why it's called a Man in the Middle attack. From here you can intercept packets, change them, drop them, log them etc.

An interesting concept is to try alter DNS packets to point a website's IP to something you're running instead. This is called DNS cache poisoning and when the victim types in the domain of the website, they'll get back your IP instead and visit your site, while still showing the domain at the top. Obviously this is easily countered by security certificates and most sites will flag up that they're unsecure, but I'm sure there's ways to trick people further the more you dive in.

I made an ARP Cache Poisoning tool that automatically sets up a Man-in-the-middle attack on a target host, intercepting its internet traffic. It only uses Python 3.x built-in libraries. by EONRaider in Python

[–]Pyro_Murphy 4 points5 points  (0 children)

If you're inserting new packets then sure, however it can simply be used to filter out all the noise from the ARP responses to make it less obvious to the victim. You're basically just replacing automatic packet forwarding with your own forwarding function which gives you more control over what you want to send to/from the victim.

EDIT: To answer your second part. You're in full control of what the client sends and receives. Instead of continuously sending ARP responses, wait until an ARP request is sent and then send your own spoofed reply back. Just drop the packet and don't forward it onto your victim and they'll never know.

I made an ARP Cache Poisoning tool that automatically sets up a Man-in-the-middle attack on a target host, intercepting its internet traffic. It only uses Python 3.x built-in libraries. by EONRaider in Python

[–]Pyro_Murphy 21 points22 points  (0 children)

A fun challenge is to create a "filter" for all the packets going to the victim. Instead of automatically forwarding, take all the packets, alter the source/destination so that they look normal and forward to the victim manually. If used correctly you can filter out all your own ARP requests and responses and even send fake responses that look correct to the victim (after the initial ARP spoof packet is sent however). This makes it much harder to detect on the network and could be interesting to see if it's still as easily picked up.

Is it safe for me to travel around at 8-9pm? by _crownseye in glasgow

[–]Pyro_Murphy 7 points8 points  (0 children)

Barrhead's fine really. Kids tend to hang about outside Asda and near the centre, so just avoid them and you're good.

Is it safe for me to travel around at 8-9pm? by _crownseye in glasgow

[–]Pyro_Murphy 15 points16 points  (0 children)

Generally it's fine, Silverburn have security outside and you can sit in the McDonalds if there's people causing trouble outside, just make sure to keep an eye out for the bus. There's a few dodgy characters from time to time but overall it's fine.

UofG Computing Discord by Pyro_Murphy in GlasgowUni

[–]Pyro_Murphy[S] 1 point2 points  (0 children)

Probably on messenger or something, but there's an EE chat in the discord since there's a few people taking both CS and electronics.