A exposição da sua empresa não espera o próximo relatório trimestral. Enquanto você planeja o próximo trimestre, informações sensíveis sobre sua operação, seus executivos e seus dados já podem estar circulando onde não deveriam. Processos judiciais, fraudes e crises de imagem raramente começam do nada — eles começam com um risco que ninguém viu a tempo. Ofereço consultoria em inteligência de segurança digital, identificando riscos reais antes que virem litígio, fraude ou crise de imagem. Discrição. Precisão. Resultado direto para quem decide. Se a segurança da sua empresa ainda depende de reagir depois que o problema aparece, vamos conversar. 📩 Me chame no inbox ou comente " SEGURANÇA " que te explico como funciona. #CiberSegurança #GestãoDeRisco #CLevel #Compliance #SegurançaDigital
This tool was created during our research at Checkpoint Software Technologies on Whatsapp Protocol (This repository will be updated after BlackHat 2019)
Copy stdint.h to C:\Users\Administrator\AppData\Local\Programs\Common\Microsoft\Visual C++ for Python\9.0\VC\include
Execute the command pip install -r requirements.txt
On Linux/Mac use python2 -m pip install -r requirements.txt
About the extension
This extension allow you to view and manipulate the actual data that sent via whatsapp.
Open chrome developer tool and break on keyPair: t, (line 3311) and wait until the keys will appear (5 minutes or so).
Run the decoder server which is parser.py (in helper dir).
Install burpWhatsapp.py to your burp suite extensions.
Break get the keys from step 1.
get the secret parameter from the websocket in burp websocket history.
Functionality
Decrypt incoming data, you have to paste the data as base64 to the extension ctrl+b
Encrypt incoming data, after you decrypt the data you can encrypt and put it back to burp by copy pase the base64 and ctrl+shift+b
Decrypt outgoing data, to decrypt outgoing data you have to take it from AesCbcEncrypt function in list format.
Encrypt outgoing data, after the extension encrypt the data back you have to put it back via the console.
you can use the following helper function to do that:
functionstr2unit8(str) {
var buf =newArrayBuffer(str.length);
var bufView =newUint8Array(buf);
for (var i=0, strLen=str.length; i < strLen; i++) {
bufView[i] = str[i];
}
return buf;
}
TO-DO
The extension currently can decrypt and encrypt only the message related functionality, in order to add more function you have to map the protobuf and add it to our protobuf file.
Comentários
Postar um comentário