or
or
By clicking below, you agree to our terms of service.
New to HackMD? Sign up
Syntax | Example | Reference | |
---|---|---|---|
# Header | Header | 基本排版 | |
- Unordered List |
|
||
1. Ordered List |
|
||
- [ ] Todo List |
|
||
> Blockquote | Blockquote |
||
**Bold font** | Bold font | ||
*Italics font* | Italics font | ||
~~Strikethrough~~ | |||
19^th^ | 19th | ||
H~2~O | H2O | ||
++Inserted text++ | Inserted text | ||
==Marked text== | Marked text | ||
[link text](https:// "title") | Link | ||
 | Image | ||
`Code` | Code |
在筆記中貼入程式碼 | |
```javascript var i = 0; ``` |
|
||
:smile: | ![]() |
Emoji list | |
{%youtube youtube_id %} | Externals | ||
$L^aT_eX$ | LaTeX | ||
:::info This is a alert area. ::: |
This is a alert area. |
On a scale of 0-10, how likely is it that you would recommend HackMD to your friends, family or business associates?
Please give us some advice and help us improve HackMD.
Do you want to remove this version name and description?
Syncing
xxxxxxxxxx
Pirates of The Nang Hai: Follow the Artifacts of Tropic Trooper, No One Knows - Yusuke Niwa, Suguru Ishimaru
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →歡迎來到 HITCON CMT 2024 共筆
共筆入口:https://hackmd.io/@HITCON/2024-note
(the attacker used the VSCode terminal to run PowerShell)
EntryShell: a varity of keyboy
update
1.ascii2bin + AES 128 ECB
2.malware config
https://blog-en.itochuci.co.jp/entry/2023/10/06/173200
Xiangoop
Cases
1.vscode as RAT attack
create super timeline for compromised host
attacker find wifi artifact through vscode
netsh wlan
2.EvilTwin attack
look for site
set up rogue wifi
victim connect
steal cred
set up a attack pc
Case 4 Datatime,Size, Hash are useful
有道辭典的更新程式惡意內容
js frile from c2 server execute via Wscript
下載偽裝為McAfeeeManager.exe的惡意程式與cab檔
embed
Cobaltstrike Beacon
unconcerned boudary between cyber and physical