Black Hat Go: Go Programming For Hackers and Pentesters
Book information
Description
Black Hat Go explores the darker side of Go, the popular programming language revered by hackers for its simplicity, efficiency, and reliability. It provides an arsenal of practical tactics from the perspective of security practitioners and hackers to help you test your systems, build and automate tools to fit your needs, and improve your offensive security skillset, all using the power of Go. You'll begin your journey with a basic overview of Go's syntax and philosophy and then start to explore examples that you can leverage for tool development, including common network protocols like HTTP, DNS, and SMB. You'll then dig into various tactics and problems that penetration testers encounter, addressing things like data pilfering, packet sniffing, and exploit development. You'll create dynamic, pluggable tools before diving into cryptography, attacking Microsoft Windows, and implementing steganography. You'll learn how to: • Make performant tools that can be used for your own security projects • Create usable tools that interact with remote APIs • Scrape arbitrary HTML data • Use Go's standard package, net/http, for building HTTP servers • Write your own DNS server and proxy • Use DNS tunneling to establish a C2 channel out of a restrictive network • Create a vulnerability fuzzer to discover an application's security weaknesses • Use plug-ins and extensions to future-proof productsBuild an RC2 symmetric-key brute-forcer • Implant data within a Portable Network Graphics (PNG) image. Are you ready to add to your arsenal of security tools? Then let's Go! Title Page Copyright Page About the Authors BRIEF CONTENTS CONTENTS IN DETAIL FOREWORD ACKNOWLEDGMENTS INTRODUCTION Who This Book Is For What This Book Isn’t Why Use Go for Hacking? Why You Might Not Love Go Chapter Overview 1 GO FUNDAMENTALS Setting Up a Development Environment Understanding Go Syntax Summary 2 TCP, SCANNERS, AND PROXIES Understanding the TCP Handshake Bypassing Firewalls with Port Forwarding Writing a TCP Scanner Building a TCP Proxy Summary 3 HTTP CLIENTS AND REMOTE INTERACTION WITH TOOLS HTTP Fundamentals with Go Building an HTTP Client That Interacts with Shodan Interacting with Metasploit Parsing Document Metadata with Bing Scraping Summary 4 HTTP SERVERS, ROUTING, AND MIDDLEWARE HTTP Server Basics Credential Harvesting Keylogging with the WebSocket API Multiplexing Command-and-Control Summary 5 EXPLOITING DNS Writing DNS Clients Writing DNS Servers Summary 6 INTERACTING WITH SMB AND NTLM The SMB Package Understanding SMB Guessing Passwords with SMB Reusing Passwords with the Pass-the-Hash Technique Recovering NTLM Passwords Summary 7 ABUSING DATABASES AND FILESYSTEMS Setting Up Databases with Docker Connecting and Querying Databases in Go Building a Database Miner Pillaging a Filesystem Summary 8 RAW PACKET PROCESSING Setting Up Your Environment Identifying Devices by Using the pcap Subpackage Live Capturing and Filtering Results Sniffing and Displaying Cleartext User Credentials Port Scanning Through SYN-flood Protections Summary 9 WRITING AND PORTING EXPLOIT CODE Creating a Fuzzer Porting Exploits to Go Creating Shellcode in Go Summary 10 GO PLUGINS AND EXTENDABLE TOOLS Using Go’s Native Plug-in System Building Plug-ins in Lua Summary 11 IMPLEMENTING AND ATTACKING CRYPTOGRAPHY Reviewing Basic Cryptography Concepts Understanding the Standard Crypto Library Exploring Hashing Authenticating Messages Encrypting Data Brute-Forcing RC2 Summary 12 WINDOWS SYSTEM INTERACTION AND ANALYSIS The Windows API’s OpenProcess() Function The unsafe.Pointer and uintptr Types Performing Process Injection with the syscall Package The Portable Executable File Using C with Go Summary 13 HIDING DATA WITH STEGANOGRAPHY Exploring the PNG Format Reading Image Byte Data Writing Image Byte Data to Implant a Payload Encoding and Decoding Image Byte Data by Using XOR Summary Additional Exercises 14 BUILDING A COMMAND-AND-CONTROL RAT Getting Started Defining and Building the gRPC API Creating the Server Creating the Client Implant Building the Admin Component Running the RAT Improving the RAT Summary Index
Similar books
Black Hat Go: Go Programming For Hackers and Pentesters
2020 · PDF
Black Hat Go: Go Programming For Hackers And Pentesters
2020 · PDF
Black Hat Go: Go Programming For Hackers and Pentesters
2020 · EPUB
Black Hat Go
What Next?: Surviving the Twenty-first Century
2008 · EPUB
The Hong Kong Diaries
2022 · EPUB
Black Hat Go: Go Programming for Hackers and Pentesters
2020 · PDF
Not Quite the Diplomat: Home Truths About World Affairs
2005 · PDF