Wednesday, May 6, 2020

Linux/AirDropBot Samples



Reference








Download

       
      Other malware






Hashes

MD5
SHA256
SHA1
85a8aad8d938c44c3f3f51089a60ec16
1a75642976449d37acd14b19f67ed7d69499c41aa6304e78c7b2d977e0910e37
2f0079bb42d5088f1fec341cb68f15cdd447ac43
2c0afe7b13cdd642336ccc7b3e952d8d
64c0e594d4926a293a1f1771187db8cfb44a0dda80d8b25b4f0c975e1e77745c
fef65085a92654cbcf1e3e0d851c6cda8dd3b03d
94b8337a2d217286775bcc36d9c862d2
71c02b99046c3be12e31577aa6623ce47dfb7f369e67af564d2bd499080c03b6
d5deeb1b61026479acb421583b7b82d09d63e921
417151777eaaccfc62f778d33fd183ff
bf6941e644a430fef43afc749479859665a57b711d5483c2c7072049c7db17b7
f76b9447db23229edae17a3160e04df41bc35a9d
d31f047c125deb4c2f879d88b083b9d5
2785845c97a69e15c9c1535216732a9d24bcf8f7244ce7872a2b0d2d4bcb92c3
4693505ef4c029112c4b85a16762cf90f0d69c15
ff1eb225f31e5c29dde47c147f40627e
f7ab3d315961d84da43f30a186136a56f5aa1e9afe6b56a0d357accd5f0ab81a
d5f2a976b703b5e687ffc58c408e0bc880838ae7
f3aed39202b51afdd1354adc8362d6bf
fa2bc8d988c8dfbdc965f1373bd80e9f5862868397c1bcb5e84b1e9c1756e0e2
31f0bca917cfbffcc126219439d38fe80d5c8460
083a5f463cb84f7ae8868cb2eb6a22eb
d654850f7785a5adb34f0808e2952f66e3784c0a32427fab9e97c75f0a48d9f5
ed4359a2805ce69771253d2257598b5c63c36c8e
9ce4decd27c303a44ab2e187625934f3
a2a245f12ae44cca79f03a465e2dc3dfa222dfcfda1017824b16abf397f16255
710e85ae3d362d3c8f3759319c308ff9b4dcdc86
b6c6c1b2e89de81db8633144f4cb4b7d
2480be0d00193250bc9eb50b35403399ed44f53d5d919600ee5bab14ef769530
ee77141054ac8d2fad062bcd79832b5f481c7dfb
abd5008522f69cca92f8eefeb5f160e2
509299df2f6150f59ed777873d3b7c708587c68a4004b4654a8cf2a640dd50aa
15cf94828c07e080b9c455738f3219859d9ab732
a84bbf660ace4f0159f3d13e058235e9
565deb4b1a7397d2497c75c9635b81d2e3b6427f0c576e5cd3c4224660712b56
c56fea8c1c949394e539d5ab3e3df7dfd329844a
5fec65455bd8c842d672171d475460b6
121c7ebfb99d8ef39f72bf7c787be4c15e2e08b731f01172605a4d34d27f08eb
3b6ca4525c3aad0583400b911b015071a0ea6133
4d3cab2d0c51081e509ad25fbd7ff596
7f71577b63b449c1a9e9aa516fa9e4320fe5f79548a00025a430894a269ab57b
d521f25362791de4d8a82a2683f032c1dd816e74
252e2dfdf04290e7e9fc3c4d61bb3529
834fc5c0ccfde1f3d52d88355717f119221118ee2d26018b417c50d066e9e978
c8f3130e64a6f825b1e97060cf258e9086a2b650
5dcdace449052a596bce05328bd23a3b
22949a7a3424f3b3bdf7d92c5e7a7a0de4eb6bbe9c523d57469944f6a8b1d012
f2c072560559a3f112e2000c8e28ee975b2b9db3
9c66fbe776a97a8613bfa983c7dca149
18c08d3c39170652d4770b2f7785e402b58c1f6c51ba1338be4330498ef268f4
18a99ec770109357d1adbc1c2475b17d4dcca651
59af44a74873ac034bd24ca1c3275af5
1c345b5e7c7fdcc79daa5829e0f93f6ae2646f493ae0ec5e8d66ab84a12a2426
98f789e91809203fbf1b7255bd0579fc86a982ba
9642b8aff1fda24baa6abe0aa8c8b173
98165c65d83fd95379e2e7878ac690c492ac54143d7b12beec525a9d048bedae
bd447e0e77a9192b29da032db8e1216b7b97f9ed
e56cec6001f2f6efc0ad7c2fb840aceb
7a2bf405c5d75e4294c980a26d32e80e108908241751de4c556298826f0960f1
b1c271d11797baac2504916ac80fd9e6fac61973
54d93673f9539f1914008cfe8fd2bbdd
c396a1214956eb35c89b62abc68f7d9e1e5bd0e487f330ed692dd49afed37d5a
72a9b8d499cce2de352644a8ffeb63fd0edd414b
6d202084d4f25a0aa2225589dab536e7
c691fecb7f0d121b5a9b8b807c5767ad17ae3dd9981c47f114d253615d0ef171
a68149c19bfddcdfc537811a3a78cd48c7c74740
cfbf1bd882ae7b87d4b04122d2ab42cb
892986403d33acb57fca1f61fc87d088b721bdd4b8de3cd99942e1735188125b
a067a0cf99650345a32a65f5bc14ab0da97789b6

Read more

How Do I Get Started With Bug Bounty ?

How do I get started with bug bounty hunting? How do I improve my skills?



These are some simple steps that every bug bounty hunter can use to get started and improve their skills:

Learn to make it; then break it!
A major chunk of the hacker's mindset consists of wanting to learn more. In order to really exploit issues and discover further potential vulnerabilities, hackers are encouraged to learn to build what they are targeting. By doing this, there is a greater likelihood that hacker will understand the component being targeted and where most issues appear. For example, when people ask me how to take over a sub-domain, I make sure they understand the Domain Name System (DNS) first and let them set up their own website to play around attempting to "claim" that domain.

Read books. Lots of books.
One way to get better is by reading fellow hunters' and hackers' write-ups. Follow /r/netsec and Twitter for fantastic write-ups ranging from a variety of security-related topics that will not only motivate you but help you improve. For a list of good books to read, please refer to "What books should I read?".

Join discussions and ask questions.
As you may be aware, the information security community is full of interesting discussions ranging from breaches to surveillance, and further. The bug bounty community consists of hunters, security analysts, and platform staff helping one and another get better at what they do. There are two very popular bug bounty forums: Bug Bounty Forum and Bug Bounty World.

Participate in open source projects; learn to code.
Go to https://github.com/explore or https://gitlab.com/explore/projects and pick a project to contribute to. By doing so you will improve your general coding and communication skills. On top of that, read https://learnpythonthehardway.org/ and https://linuxjourney.com/.

Help others. If you can teach it, you have mastered it.
Once you discover something new and believe others would benefit from learning about your discovery, publish a write-up about it. Not only will you help others, you will learn to really master the topic because you can actually explain it properly.

Smile when you get feedback and use it to your advantage.
The bug bounty community is full of people wanting to help others so do not be surprised if someone gives you some constructive feedback about your work. Learn from your mistakes and in doing so use it to your advantage. I have a little physical notebook where I keep track of the little things that I learnt during the day and the feedback that people gave me.


Learn to approach a target.
The first step when approaching a target is always going to be reconnaissance — preliminary gathering of information about the target. If the target is a web application, start by browsing around like a normal user and get to know the website's purpose. Then you can start enumerating endpoints such as sub-domains, ports and web paths.

A woodsman was once asked, "What would you do if you had just five minutes to chop down a tree?" He answered, "I would spend the first two and a half minutes sharpening my axe."
As you progress, you will start to notice patterns and find yourself refining your hunting methodology. You will probably also start automating a lot of the repetitive tasks.

More articles

Tuesday, May 5, 2020

OWASP Web 2.0 Project Update

Some of you likely recall the talk back in 2016 or so of updating the OWASP Foundation website to not appear so much like a...well, a wiki.  That talk was carried forward into 2017 and 2018 and, with each year, the proposal got pushed ahead as there were other, deeper projects to tackle.  With the arrival of 2019 and a firm project plan under the guidance of Mike McCamon, Executive Director, we are finally moving toward a functioning, modern website that will be a whole lot less...wiki-like.  The journey has been circuitous and, while we are not anywhere near complete, we have a set plan in place to bring it to fruition within the calendar year (second quarter of the year, actually).

TLDR: How Can You Help? 

There are certainly ways in which you can get involved now.  For instance, we are looking for a clean way to get wiki pages into GitHub markdown format for archival.  I have done some work here but there are parsing issues with some of the tools.  Do you know a good tool or have you done similar work?  Also, are you or do you know a good designer, someone familiar with GitHub pages that can provide some useful help and feedback along the way?  A Jekyll expert to help code a theme with a handful of templates would be a great addition.  In addition, we could use website server admins who could help with assigning redirects to maintain search integrity.  Finally, there will be a great many pages to move that we will also eventually need community involvement in.  

So, What Have We Done? 

Thus far we have researched various ideas for standing up a new site, including modifying the current wiki, spinning up our own web server, contracting a third party to host and build a new site, and also using existing infrastructure with our own content to launch a new face for OWASP.  Our discussions led us to a familiar place, one that nearly every developer in the OWASP space is familiar with: GitHub.   

In our conversations with GitHub, it became readily apparent that using the platform would be a win for the Foundation as well as GitHub.  Nearly everyone who runs a project at OWASP (documentation or otherwise) uses GitHub.  Because our target audience is also mostly developers we know that they are also very comfortable with the platform.  And while GitHub has a number of high profile companies using their GitHub Pages, the use of the platform as the basis for the entire website of the number one non-profit foundation in the application security sector is a big draw.

We have run with that GitHub Pages idea and have spent internal manpower on a proof of concept.  This proof of concept is less about the UX of the site than the functionality, the ability to utilize the authentication systems, and the ability to utilize automation to push out changes quickly.

Where Are We Now?

We are doing the final stages of website architecture. We are also planning what needs to be in the site, how the pieces will integrate with current projects and chapters, and how we might utilize the community to integrate the pieces so that we have a visually and functionally cohesive website that spans across multiple repositories.

What Is Next?

We will soon be looking for a modern website design that is responsive and clean.  We will begin using the knowledge gained from our proof of concept to build out the internals of the website and then we will start implementing the highest traffic pages and administrative areas into the new platform.  Once we have the big-ticket items moved we will start looking at what is left and moving over those pieces.  The eventual goal would be to have a new, modern website for the future of OWASP while keeping the wiki as an archive of really useful information.


We hope you are as excited as we are about the future of the OWASP Foundation website and will join us as we move toward a modern web presence.  If you have any questions or would like to volunteer your time, experience or knowledge, please contact me at harold.blankenship@owasp.com

Read more

Why Receipt Notifications Increase Security In Signal

This blog post is aimed to express and explain my surprise about Signal being more secure than I thought (due to receipt acknowledgments). I hope you find it interesting, too.

Signal, and especially its state update protocol, the Double Ratchet algorithm, are widely known for significantly increasing security for instant messaging. While most users first see the end-to-end security induced by employing Signal in messaging apps, the properties achieved due to ratcheting go far beyond protecting communication against (active) attackers on the wire. Due to updating the local device secrets via the Double Ratchet algorithm, the protocol ensures that attackers, who temporarily obtain a device's local storage (on which Signal runs), only compromise confidentiality of parts of the communications with this device. Thus, the leakage of local secrets from a device only affects security of a short frame of communication. The exact duration of compromise depends on the messaging pattern among the communicating parties (i.e., who sends and receives when), as the state update is conducted during the sending and receiving of payload messages.


The Double Ratchet

The Double Ratchet algorithm consists of two different update mechanisms: the symmetric ratchet and the asymmetric ratchet. The former updates symmetric key material by hashing and then overwriting it with the hash output (i.e.,  k:=H(k)). Thus, an attacker, obtaining key material can only predict future versions of the state but, due to the one-wayness of the hash function, cannot recover past states. The asymmetric ratchet consists of Diffie-Hellman key exchanges (DHKE). If, during the communication, party A receives a new DH share gb as part of a message from the communication partner B, then A samples a new DH exponent a and responds with the respective DH share ga in the next sent message. On receipt of this DH share, B will again sample a new DH exponent b' and attach the DH share gb' to the next message to A. With every new DH share, a new DHKE gab is computed among A and B and mixed into the key material (i.e., k:=H(k,gab)). For clarity, I leave out a lot of details and accuracy. As new DH shares ga and gb are generated from randomly sampled DH exponents a and b, and the computation of gab is hard if neither a nor b are known, the key material recovers from an exposure of the local secrets to an attacker after a new value gab was freshly established and mixed into it. Summing up this mechanism, if an attacker obtains the local state of a Signal client, then this attacker cannot recover any previously received message (if the message itself was not contained in the local state), nor can it read messages that are sent after a new gab was established and mixed into the state. The latter case happens with every full round-trip among A and B (i.e., A receives from B, A sends to B, and A receives again from B).
Conceptual depiction of Double Ratchet in Signal two years ago (acknowledgments were only protected between client and server). The asymmetric ratchet fully updates the local secrets after one round-trip of payload messages.

Research on Ratcheting

During the last two years, the Signal protocol inspired the academic research community: First, a formal security proof of Signal was conducted [1] and then ratcheting was formalized as a generic primitive (independent of Signal) [2,3,4]. This formalization includes security definitions that are derived via 1. defining an attacker, 2. requiring security unless it is obvious that security cannot be reached. Protocols, meeting this optimal notion of security, were less performant than the Double Ratchet algorithm [3,4]. However, it became evident that the Double Ratchet algorithm is not as secure as it could be (e.g., recovery from exposure could be achieved quicker than after a full round-trip; see, e.g., Appendix G of our paper [3]). Afterwards, protocols (for slightly weakened security notions) were proposed that are similarly performant as Signal but also a bit more secure [5,6,7].

Protecting Acknowledgments ...

In our analysis of instant messaging group chats [8] two years ago (blog posts: [9,10]), we found out that none of the group chat protocols (Signal, WhatsApp, Threema) actually achieves real recovery from an exposure (thus the asymmetric ratchet is not really effective in groups; a good motivation for the MLS project) and that receipt acknowledgments were not integrity protected in Signal nor WhatsApp. The latter issue allowed an attacker to drop payload messages in transmission and forge receipt acknowledgments to the sender such that the sender falsely thinks the message was received. Signal quickly reacted on our report by treating acknowledgments as normal payload messages: they are now authenticated(-encrypted) using the Double Ratchet algorithm.

... Supports Asymmetric Ratchet

Two years after our analysis, I recently looked into the Signal code again. For a training on ratcheting I wanted to create an exercise for which the lines in the code should be found that execute the symmetric and the asymmetric ratchet respectively. Somehow I observed that the pure symmetric ratchet (only updates via hash functions) was nearly never executed (especially not when I expected it) when lively debugging the app but almost always new DH shares were sent or received. I realized that, due to encrypting the receipt acknowledgments now, the app always conducts full round-trips with every payload message. In order to observe the symmetric ratchet, I needed to temporarily turn on the flight mode on my phone such that acknowledgments are not immediately returned.
Conceptual depiction of Double Ratchet in Signal now (acknowledgments encrypted). The asymmetric ratchet fully updates the local secrets after an acknowledgment for a message is received.

Consequently, Signal conducts a full DHKE on every sent payload message (in case the receiving device is not offline) and mixes the result into the state. However, a new DH exponent is always already sampled on the previous receipt (see sketch of protocol above). Thus, the exponent for computing a DHKE maybe remained in the local device state for a while. In order to fully update the state's key material, two round-trips must be initiated by sending two payload messages and receiving the resulting two acknowledgments. Please note that not only the mandatory receipt acknowledgments are encrypted but also notifications on typing and reading a message.

If you didn't understand exactly what that means, here a tl;dr: If an attacker obtains your local device state, then with Signal all previous messages stay secure and (if the attacker does not immediately use these secrets to actively manipulate future conversations) all future messages are secure after you wrote two messages (and received receipt acknowledgments) in all of your conversations. Even though this is very (in practice certainly sufficiently) secure, recent protocols provide stronger security (as mentioned above) and it remains an interesting research goal to increase their performance.

[1] https://eprint.iacr.org/2016/1013.pdf
[2] https://eprint.iacr.org/2016/1028.pdf
[3] https://eprint.iacr.org/2018/296.pdf
[4] https://eprint.iacr.org/2018/553.pdf
[5] https://eprint.iacr.org/2018/889.pdf
[6] https://eprint.iacr.org/2018/954.pdf
[7] https://eprint.iacr.org/2018/1037.pdf
[8] https://eprint.iacr.org/2017/713.pdf
[9] https://web-in-security.blogspot.com/2017/07/insecurities-of-whatsapps-signals-and.html
[10] https://web-in-security.blogspot.com/2018/01/group-instant-messaging-why-baming.html
Related posts

  1. Etica Hacker
  2. Viral Hacking
  3. Como Aprender A Hackear Desde Cero
  4. Geekprank Hacking
  5. Etica Definicion
  6. Como Hackear
  7. Curso De Hacking Etico Gratis

DarkFly Tool V4.0 | 500 Tools | Termux

Related links


Friday, May 1, 2020

Building A Magnetic Model Transport System

Last June I started collecting Convergence of Cyriss.  Since I was getting the faction almost completely by doing model trades, the project turned into a bit more work than I had planned for it as more than half of what I got in trades were in a horrible state.

That said, I did get most of the faction in one swoop and after a bit of hard modeling work, I had everything ready to go.

Except I couldn't really go anywhere with it because as any war gamer knows, you need some kind of transport system for an army.

That's a lot of CoC!

I've typically used Sabol foam trays carried around in a Battle Foam Pack Air case, but huge based models require specialty foam from Battle Foam, and those are pretty pricey - $23 per huge base.  If anyone knows about CoC, they know you will have at least 3 huge bases, and I ended up with 4 after all the trading was done.

I'm looking at almost $100 in foam just for the huge bases, then at roughly $8 per Sabol tray, I'm easily blowing $150 or more getting everything in foam for this faction.  Then I'm lugging the large pack air case plus an old Sabol Army Transport bag to hold my huge bases if I'm using them in my list pair.

There simply had to be a better way. Then the idea hit me...





Magnets!

I went to the local craft store and bought myself some bins that were the same length and width, but had different heights. I did some pre-measuring of each of my huge bases and my "floating" vectors to check heights.

Each bin is 15.5" x 11.5" and I ended up with 5 bins in total: 1x 8.3" tall, 2x 5.6" tall, and 2x 2.9" tall.  The bins were about $12 a piece, but more importantly I wouldn't ever have to buy more in the future. The only recurring cost for this system is going to be purchasing magnets for new models.


Securing the Models

Magnets don't work on plastic, so I needed to line the bottom of my bins with metal. My local big-box hardware store had 1 foot square steel sheet at about $5 per. Not too shabby.  The only problem was that I'd need to shave off some of the sheet to fit into the bottom of my bins. What's more is that while the overall top dimensions of the bins are the same, the bottoms are not.  

There was a bigger problem. I'm not particularly handy, and I don't have a ton of power tools.  What I do have however is my friend Ray.

This is Ray. Ray is handy. Be like Ray.

Ray is one of those guys who makes his own furniture - as a hobby...and the furniture actually looks good when he's done! He's got tools galore and was kind enough to help me out by cutting my metal for me. I had used a pair of metal snips to cut one sheet and it worked, but it didn't look great. Ray sanded that shit down for me and trimmed it up so it looked better. 

So now I had 5 sheets of steel cut to the right size for my bins. 

Mixing Plastic and Steel

Next up I just gotta stick my steel to my bins, should be easy right?

I tried superglue. That failed spectacularly. The steel pulled right off with a tiny bit of tugging. It worked well enough to hold if I didn't rumble it too much, which was good for a short term solution of carrying the CoC to play games locally. 

So next I decided to buy a two part epoxy that said it would work on metal and plastics.  So I put on my gloves, was really careful, sanded down parts of the steel where the super glue didn't take and weighted down my bins:




After 24 hours of curing....the steel peeled right off with just a little bit of force, just like the the superglue. 

At this point I was done trying to find some kind of glue or epoxy based solution. It was time for nuts and bolts. Luckily the bins I bought had the raised section in the middle where I could have the bolt-ends sit while not exceeding the lip of the base of the actual bin (ie. I won't scratch up any tables due to having bolts on the bottom of my bins). 

Construction Tips

One thing I learned: Drilling through steel sheet isn't great if you don't have special drill bits, which not being a handyman, I didn't have.  You can however put a thick nail through the steel pretty easily, which then lets the drill go through easily and drill through the plastic.  I only hammered my thumb once. Ray would be proud. Sorta. 

Because bolts take up model space, and my huge base solution is kind of tight, I elected to only use two bolts per bin rather than 4. I will see how well this holds up, and if I need to secure it more it's easy enough to mark where to put the holes, remove the plates, make the holes, and re-secure it all. 

That said, there's only a tiny bit of wiggle with the two corners secured as it is, so I believe this setup will work.  Here are my results:






Magnet Advice

I recommend buying strong rare earth magnets for this, stronger than what you'd usually buy if you're magnetizing jacks/beasts. Specifically N52 strength is preferred.  I've gotten some magnets off Amazon but the affordable ones there are generally the weaker kind, so I've preferred to get magnets for this from K&J Magnetics. I'm not affiliated with them at all, but I've used them for years and they deliver quality stuff. 

You can get away with cheaper magnets if you use multiple, and cheaper magnets work well for small based plastic models that don't require as much force. Amazon can help out here. 

I actually had quite a few magnets laying around from years gone by which reduced my magnet purchasing requirements a bit.

That said, once you've used the right magnets, everything stays very secure in the bins. I didn't take a picture, but I was able to turn the bin upside down with the models in it and not have any casualties. 

Carrying Solutions

The final bit that isn't finished yet for this is a bag to hold it all. Currently I use a set of straps I had for carrying a PC around to LAN parties to secure the bins and hold my dice bag + widgets.  This works but isn't exactly pretty.

I am lucky in that my wife is a quilter, and she's currently sewing up a bag to hold this in, complete with pockets, straps for easy carrying, and all the rest. I realize not everyone can do this or has the luxury.  The alternative was trying to find a piece of luggage or a transport/case for a sewing machine that would have the internal dimensions to hold my bins. With better planning up front (buy bins that fit in luggage more easily) this is probably more achievable, but again you're still spending a decent amount of money this way. It's still probably less than a equivalent sized Battle Foam bag + rack system, but it's a lot of work to find the right combo of bin + case. 

Costs and Benefits

I started this project thinking it'd be good long term going forward wargaming wise and would save me money. Did it? Yes, but partially because I've cheated.

I am saving a good bit of money and getting a custom case + transport system, but that's really only because my wife isn't charging for her labor to assemble the bag, Ray didn't charge me for cutting the metal to size, and I don' t have to pay myself for all the work I've done getting the bins setup.  I also didn't have to buy lots of my strongest magnets because I already had a bunch from when I played 40k/WHFB. 

I probably could have just spent the extra money up front and bought Battle Foam's Magna-Rack system and one of their cases. They're pretty damn expensive, and you still have to buy the magnets, but it's basically none of the work and it looks great.  My custom case will look as good if not better, but not everyone is married to a quilter with sewing equipment to make a custom bag. 

The real savings are in the fact that going forward for any new armies I ever pick up, I'm using magnets, not foam. 

Magnets can cost up to $0.50 per magnet of the right size/strength, so 100 models is $50 in magnets. Is there really a cost savings here?  I think so, but in hindsight, it's probably not much.

Typically $50 in foam is not going to store 100 models, especially if you're counting lots of bigger models (30mm to 50mm bases) which take up a lot of foam space, but still only require one strong magnet.   Huge bases (120mm) require multiple magnets per, but even then it's only like $2 in magnets as opposed to $22 for a foam tray. 

You can also use weaker magnets for small based plastic models, where the magnet costs are significantly cheaper, especially if you look around on Amazon where you can get 50 to 100 magnets of the right size for something like $15. 

The real savings comes in the fact that once you've bought+built your bins to transport the minis, you can use them with basically any model set you want. Compared to foam where you need to pluck out whatever kind of foam for your specific models. The other benefit is storing models that have long reach weapons or stick out oddly...like Inverters or Reciprocators. 

When it comes to storing models long term (ie. when I'm switched to another army), I can put some metal sheet in larger storage bins and just put my models into one decent sized bin. This is probably more efficient than what I have to do now to store foam trays for models. 

The other benefit is when it comes to going to tournaments. I can fit my two list pair onto a single baking sheet, which makes for a great tournament tray that securely holds everything. I've already attended one event this way and it has worked out great. The baking sheet was something like $5 and slips easily into my bag. 

Overall I'm pretty happy with how the project has come out and I've certainly saved some money going this route, but it's definitely a lot of work to get here.

If I Could Impose On A Moment Of Your Time?

As you all know DreamForge is embarking on a new path, new releases in a new format.

Although the Kickstarter platform has a lot of advantages, it only makes sense to put your best foot forward and provide your customers with the items they desire.




To that end, I have created a very short survey to get all of your feedback, not just about the StuG and Shadokesh, but about DreamForge and the general direction you would like to see.

Please... Take a moment and let your voice be heard.

SURVEY LINK

Thank you so very much for your time!