Selamat Datang

Selasa, 14 April 2020

goGetBucket - A Penetration Testing Tool To Enumerate And Analyse Amazon S3 Buckets Owned By A Domain


When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.

What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.

The following information about every bucket found to exist will be returned:
  • List Permission
  • Write Permission
  • Region the Bucket exists in
  • If the bucket has all access disabled

Installation
go get -u github.com/glen-mac/goGetBucket

Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i) of subdomains for a root domain I am interested in. E.G:
www.domain.com
mail.domain.com
dev.domain.com
The test file (-f) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?
The keyword list (-k) is concatenated with the root domain name (-d) and the domain without the TLD to permutate using the supplied permuation wordlist (-m).
Be sure not to increase the threads too high (-t) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.

Related articles

Best Hacking Tools

      MOST USEFUL HACKING TOOL

1-Nmap-Network Mapper is popular and free open source hacker's tool.It is mainly used for discovery and security auditing.It is used for network inventory,inspect open ports manage service upgrade, as well as to inspect host or service uptime.Its advantages is that the admin user can monitor whether the network and associated nodes require patching.

2-Haschat-It is the self-proclaimed world's fastest password recovery tool. It is designed to break even the most complex password. It is now released as free software for Linux, OS X, and windows.


3-Metasploit-It is an extremely famous hacking framework or pentesting. It is the collection of hacking tools used to execute different tasks. It is a computer severity  framework which gives the necessary information about security vulnerabilities. It is widely used by cyber security experts and ethical hackers also.

4-Acutenix Web Vulnerability Scanner- It crawls your website and monitor your web application and detect dangerous SQL injections.This is used for protecting your business from hackers.


5-Aircrack-ng - This tool is categorized among WiFi hacking tool. It is recommended for beginners  who are new to Wireless Specefic Program. This tool is very effective when used rightly.


6-Wireshark-It is a network analyzer which permit the the tester to captyre packets transffering through the network and to monitor it. If you would like to become a penetration tester or cyber security expert it is necessary to learn how to use wireshark. It examine networks and teoubleshoot for obstacle and intrusion.


7-Putty-Is it very beneficial tool for a hacker but it is not a hacking tool. It serves as a client for Ssh and Telnet, which can help to connect computer remotely. It is also used to carry SSH tunneling to byepass firewalls. So, this is also one of the best hacking tools for hackers.


8-THC Hydra- It is one of the best password cracker tools and it consist of operative and highly experienced development team. It is the fast and stable Network Login Hacking Tools that will use dictonary or bruteforce attack to try various combination of passwords against in a login page.This Tool is also very useful for facebook hacking , instagram hacking and other social media platform as well as computer folder password hacking.


9-Nessus-It is a proprietary vulnerability scanner developed by tennable Network Security. Nessus is the world's most popular vulnerability scanner according to the surveys taking first place in 2000,2003,2006 in security tools survey.


10-Ettercap- It is a network sniffing tool. Network sniffing is a computer tool that monitors,analyse and defend malicious attacks with packet sniffing  enterprise can keep track of network flow. 


11-John the Ripper-It is a free famous password cracking pen testing tool that is used to execute dictionary attacks. It is initially developed for Unix OS. The Ripper has been awarded for having a good name.This tools can also be used to carry out different modifications to dictionary attacks.


12-Burp Suite- It is a network vulnerability scanner,with some advance features.It is important tool if you are working on cyber security.


13-Owasp Zed Attack Proxy Project-ZAP and is abbreviated as Zed  Attack Proxy is among popular OWASP project.It is use to find vulnerabilities in Web Applications.This hacking and penetesting tool is very easy to use  as well as very efficient.OWASP community is superb resource for those people that work with Cyber Security.


14-Cain & Abel-It is a password recovery tool for Microsoft Operating System. It allow easy recovery of various kinds of passwords by sniffing the networks using dictonary attacks.


15-Maltego- It is a platform that was designed to deliver an overall cyber threat pictures to the enterprise or local environment in which an organisation operates. It is used for open source intelligence and forensics developed by Paterva.It is an interactive data mining tool.

These are the Best Hacking Tools and Application Which are very useful for penetration testing to gain unauthorized access for steal crucial data, wi-fi hacking , Website hacking ,Vulnerability Scanning and finding loopholes,Computer hacking, Malware Scanning etc.

This post is only for educational purpose to know about top hacking tools which are very important for a hacker to gain unauthorized access. I am not responsible for any type of crime.





Related links


BASICS OF METASPLOIT – BASIC COMMANDS OF METASPLOIT

Metasploit is an advanced hacking tool that comes itself with a complete lack of advanced penetration testing tools. Penetration testers and hackers are taking so much advantage of this tool. It's a complete hack pack for a hacker that he can play almost any attack with it. Here I am going to discuss the basics of Metasploit. I am not covering attacks in this article, as I am just making sure to share the basics of Metasploit and basic commands of Metasploit. So, we can get back to cover attacks of Metasploit in the next articles.

BASICS OF METASPLOIT

The Metasploit framework has three types of working environments.
  1. msfconsole
  2. msfcli interface
  3. msfweb interface
However, the most preferred and used is the 'msfconsole'. It's a very efficient command-line interface that has its own set of commands and system's working environment.
First of all, it's most important to know and understand all the useful commands of Metasploit that are going to be used.

BASIC COMMANDS OF METASPLOIT

Metasploit have a huge number of command that we can use in different type of attacks, but I am just going to share the most used and useful commands here that a beginner can easily understand and follow 'em.
  • help (It will give the basic commands you need to launch an exploit.
  • search (Finds out the keywords in the selected attack method).
  • show exploits (Shows list of an available exploit in the selected option).
  • show payloads (It lists all the payloads available).
  • show options (It helps you to know all the options if you might have forgotten one).
  • info (This is used to get information about any exploit or payload).
  • use (It tells Metasploit to use the exploit with the specified name).
  • set RHOST (Sets the address of specified remote host).
  • set RPORT (Sets up a port that connects to on the remote host).
  • set PAYLOAD (It sets the payload that gives you a shell when a service is exploited).
  • set LPORT (Sets the port number that the payload will open on the server when an exploit is exploited).
  • exploit  (It actually exploits the service).
  • rexploit (Reloads your exploit code and then executes the exploit without restarting the console).
These are the most used Metasploit commands which come in handy in most of the situations during any sort of attack. You must give all the commands a try and understand 'em how it works and then move to the next part of designing an attack.

More info


  1. Hacking Tools Windows
  2. Hacking Tools Usb
  3. Hacking Tools 2019
  4. Wifi Hacker Tools For Windows
  5. Hack Tools
  6. Hacking App
  7. Computer Hacker
  8. Hacking Apps
  9. Hack Tools
  10. Physical Pentest Tools
  11. Hacking Tools For Windows
  12. Hacking Tools Online
  13. Hacking Tools For Beginners
  14. Hack Rom Tools
  15. Pentest Tools For Mac
  16. Tools Used For Hacking
  17. Pentest Box Tools Download
  18. Kik Hack Tools
  19. Hack App
  20. Ethical Hacker Tools
  21. Hacking Tools
  22. Best Pentesting Tools 2018
  23. Hacker Search Tools
  24. Hacker Tools Online
  25. Hacks And Tools

HTML5 Games On Android

On my last hollidays, I made two HTML5 games, and published on android market. Nowadays javascript has powerful libraries for doing almost everything, and also there are several compilers from java or c code to javascript, converting opengl c code to html5 canvas, but definitely, javascript execution is slower than dalvik applications, and of course much slower than arm c libs. For improving the speed of sounds and images loader, I have used javascript asynchronous execution and scheduling priority has been controlled with setTimeout/setInterval which deprioritize or priorize a code block. This games are published on the android market here: Android Planets and here: Far Planet

More articles


  1. Hack Tools 2019
  2. Hacking Tools 2019
  3. Pentest Tools Windows
  4. Pentest Tools Find Subdomains
  5. Pentest Tools Url Fuzzer
  6. Hacking Tools Windows 10
  7. Hacker Tools Linux
  8. Pentest Tools For Ubuntu
  9. Beginner Hacker Tools
  10. How To Make Hacking Tools
  11. Pentest Box Tools Download
  12. Hack Tools For Pc
  13. Hack Tools For Pc
  14. Hacker Tools Windows
  15. Pentest Box Tools Download
  16. How To Install Pentest Tools In Ubuntu
  17. Pentest Tools Tcp Port Scanner
  18. Tools Used For Hacking
  19. Hackrf Tools
  20. Blackhat Hacker Tools
  21. Black Hat Hacker Tools
  22. Hack Tools For Mac
  23. Hacking Tools Online
  24. Hacking Tools For Windows 7
  25. Hack Tools For Pc
  26. Hacking Tools Windows
  27. Hacker Security Tools
  28. Easy Hack Tools

Gremlin Botnets: El Club De Los Poetas Muertos [Parte 6 De 6]

Y paso a paso llegamos a la última parte de esta serie. Ya hemos visto cómo puede robar fácilmente el control de una Cuenta de Developer de Android de un desarrollador si se caduca la cuenta de correo electrónico asociada a ella. Esto es algo que puede ocurrir por muchas factores, como que la cuenta de e-mail sea abandonada, o el fallezca el desarrollador y nadie elimine sus apps o tome control de ellas "legítimamente".

Figura 60: Gremlin Botnets: El club de los poetas muertos [Parte 6 de 6]

En la prueba que hicimos en la parte anterior de este artículo vimos como habíamos sido capaces de localizar con un test no demasiado grande un total de ocho cuentas de desarrolladores que podíamos controlar al ser capaces de tomar posesión de sus direcciones caducadas de correo electrónico. Pero si evaluamos ahora el impacto que estas cuentas tienen, el resultado es muy grande.

Impacto de la investigación de "los poetas muertos"

Al final, un desarrollador tiene varias apps subidas a Google Play, y cada una de esas apps tiene una base de usuarios que las han instalado. Es decir, una cuenta de desarrollador puede traer miles o cientos de miles de dispositivos móviles que unir a nuestra Gremlin Botnet por medio de convertir una a una todas esas apps en nuevas Gremlin Apps.

Figura 61: Lista de apps afectadas

En nuestro caso, con solo 8 cuentas de desarrollador se podían controlar un total de 35 diferentes apps, todas ellas con un diferente número de instalaciones, como podéis ver en la tabla, llevando a que un atacante se hiciera con una Gremlin Botnet de apps que poder volver maliciosas de una forma sencilla y de un tamaño considerable.

En nuestra investigación, el número total de instalaciones activas de estas apps ascendía a un nada desdeñable número de 4.854.350 descargas, lo que da una clara idea de la magnitud del problema que se puede producir si no se controla la caducidad de las cuentas de correo de los desarrolladores de las apps que tú, como administrador del parque móvil y/o responsable de seguridad de una empresa, no controlas.

Figura 62: Clasificación de los paquetes APK de apps en riesgo

Por supuesto, todos los paquetes de las apps que tienen una cuenta de desarrollador con una dirección de e-mail que cualquiera puede registrar debe levantar una alerta en todos los sistemas de seguridad, por eso en Tacyt, mASAPP y CyberThreats se generan esos reportes de seguridad que, si tienes la gestión de seguridad automatizada con una plataforma tipo SandaS GRC para ver tus indicadores de riesgo, te muestra la situación en tiempo real en cualquier cuadro de mandos.


Figura 63: Control del riesgo digital con SandaS GRC

Por supuesto, el problema, desde el punto de vista de seguridad, es un poco mayor y no nos podemos quedar aquí, ya que si tenemos la cuenta de un desarrollador de una app, probablemente esa aplicación necesitará infraestructura, y puede que también esté en riesgo.

Cuenta de developer, cuenta de infraestructura

Al final, cuando un desarrollador hace una aplicación móvil, probablemente necesite un backend donde almacenar datos. A este backend, que puede ser un servidor en un proveedor de hosting, o un entorno de cloud IaaS o PaaS, tendrá algún nombre de dominio, que seguramente esté registrado a su nombre, etcetera.

Es decir, si tienes una dirección de correo electrónico que pertenece a un desarrollador, probablemente también tengas la cuenta que abre muchos otros servicios de infraestructura que se pueden descubrir simplemente abriendo el código de la app extrayéndolo del APK y viendo a qué servidores se conectan, algo que como sabéis hacemos en Tacyt.

Figura 65: Links extraídos en Tacyt de una app

Por supuesto, una vez descubiertos esos servidores de backend, un atacante puede utilizar esa cuenta para ver si el desarrollador la ha utilizado como identificador del servicio. Algo muy común, pero que no debería haber pasado nunca.

El día que utilizamos la dirección de correo electrónico como identificador de cuentas, convertimos algo que debería ser siempre público (una dirección de mensajería) en algo que no tiene por qué ser público, el id que abre una zona segura en una plataforma. Una de las cosas por las que dije aquello de que el e-mail estaba muerto, ¡larga vida al e-mail!

Tacyt & CARMA: Investigar en el mundo del malware

Como muchas veces hemos contado, en ElevenPaths hacemos muchas investigaciones al respecto del malware, adware, cibercrimen o mejoras de seguridad en el mundo de las apps móviles, y compartimos esas investigaciones con otros centros de formación, organizaciones y empresas. Así, tenemos un programa de colaboración para investigación en Tacyt para evolucionar los sistemas de seguridad del mundo de las apps móviles. Nuestro compañero Sergio de los Santos ha dirigido investigaciones con la Universidad Politécnica de Madrid e IMDEA o con la Universidad Piraeus en Grecia, donde hemos dado acceso a nuestra plataforma a sus equipos de investigación. 

Figura 66: CARMA ofrece muestras de malware en apps para investigadores

Y ahora hemos dado un paso más con el lanzamiento del programa Curated Android Malware APK Set (CARMA), que es un servicio gratuito ofrecido por el área de Innovación y Laboratorio de ElevenPaths. En él se proporciona a los investigadores un conjunto de muestras de malware, adware y otros archivos potencialmente peligrosos recopilados para el sistema operativo Android. Estas muestras tienen un uso exclusivamente destinado a la investigación o estudio académico y está prohibido su uso para cualquier otro fin, lucrativo o no.

Figura 67: Solicitud de participar en el programa CARMA

El fin de estos conjuntos es proporcionar muestras de calidad que puedan ser utilizadas para su análisis en sistemas expertos, Machine Learning aplicado a Ciberseguridad, nuevas ideas usando Inteligencia Artificial o cualquier otro método que permita mejorar la detección futura de este tipo de amenazas.

Figura 68: Tipo, año y tamaños de las muestras que se pueden solicitar

Como se puede ver, en él se ofrece un conjunto de varios Gigabytes de muestras de malware completas en su formato original, no alteradas y clasificadas por año, origen y tipo de amenaza. Desde Google Play y otros markets de aplicaciones, PUP, adware, malware, etcétera, todas ellas clasificadas por años desde 2017, y  donde también hay goodware.

Conclusiones finales y PPTs

El smartphone se ha convertido en el centro de nuestra vida digital personal, y por tanto las apps son parte de nuestro desarrollo persona, profesional y en sociedad. Necesitamos tener un ecosistema seguro de aplicaciones móviles para salvaguardar nuestra vida digital.

Entender los riesgos, las amenazadas y como gestionar esos peligros es fundamental. Las Gremlin Botnets bajo el control de grupos cibercriminales o de ciberespionaje son un riesgo importante para gobiernos y empresas. Las Gremlin Apps son un riesgo para las personas en Internet que pueden ver su vida totalmente comprometida.

Figura 69: Cómo protegerse de los peligros en Internet

En esta investigación solo quisimos poner de manifiesto cómo, si no tomamos precauciones, el poseedor de una Gremlin Botnet puede tener un poder muy peligroso, y por lo tanto todos tenemos que colaborar en su erradicación.


Para terminar os, dejo las diapositivas que utilicé para la presentación de esta charla en RootedCON 2020 subidas a mi SlideShare, donde podéis ver resumido todo este largo artículo de seis partes. Esperamos que esta investigación os haya sido de utilidad y podáis aplicar alguna medida de contención de estos riesgos.

Saludos Malignos!

*********************************************************************************
- Gremlin Botnets: El club de los poetas muertos [Parte 6 de 6]
*********************************************************************************

Autor: Chema Alonso (Contactar con Chema Alonso)



Related news

Minggu, 12 April 2020

ASOIAF: Tywin Lannister 40Pt Army

My point exactly.

In my previous article, I gave you guys the rundown for how I go about building army lists.  I always start with the Commander first and then try to take units that best take advantage of their tactics cards.  Well, I decided to get the party started with my favorite character from GoT:  Tywin Lannister.  Lannisters, in general, have a ton of control elements and I think Tywin just adds to the flavor in a big way.  He is a battlefield commander so that means you put him with your frontline troops in any one of the units that he can be taken in.  Since he's considered an infantry character, you have to put him in one of your infantry units.  I decided to put Tywin inside a unit of Mountain Men because they have a pretty respectable save of 4+.  Besides, having two chances to apply Panic-based damage is great.  More on this later.

For now, let's take a look at Tywin himself and his Tactics cards to see what he offers us:

Just look at this badass.

From the get-go, you can see that Tywin is all about making your opponents' units Weakened and then exploiting those tokens and effects to your advantage.  Immediately, you can see that Tywin's Commander card has built-in Lannister Supremacy and Fear of the Lion.  Fear of the Lion combos really nicely with Tywin's tactics cards because it allows him to place a free Weaken token on any enemy unit within Long Range of his unit when he activates.  I put him with Mountain Men because MMs already have built-in Vicious so on the offense, they can make opponents take Panic Tests with a -2 modifier.  When they attack back, Tywin's Lannister Supremacy makes it so if I roll a 7+ on my Panic test, my opponent has to take another test at -2 again.  This is some pretty silly free damage if my opponent rolls poorly and can also be a form of damage negation because the more models they lose to Panic checks, the less damage they will do because of the ranks lost.  Throw Weaken on top of this from Tywin and it becomes a force multiplier.

The Lion doesn't mess around.

The Tactics cards themselves are very nasty. Exploit Weakness is a perfect example of a card that kicks your opponent when they're down.  If you spend the Weaken token, you can force your opponent re-roll all of their successful hits and any 1s to pop up will deal automatic wounds to their unit on top of whiffing on their attacks.  This is extremely effective at taking down heavy cavalry because it essentially turns that units attack into wounds that bypass saves.  The Lion's Wrath is a great card because it affects ALL enemy units on the board that has Weaken on them and it lasts until the end of the round.  You will hear me say this a lot, but anything that lasts an entire round is super good.  Players take alternating turns activating their units, but rounds last after all player turns are finished.  This means that for the duration of the round, anything Weakened on the battlefield will be moving -1 movement AND suffering Disorderly Charge on a roll of 1-2.  First, this card auto-applies a Weaken effect anywhere on the board, but Disorderly Charge is super frustrating when it happens.  Another example of Lannisters kicking you while you're down, but Disorderly Charge robs you from your ability to re-roll hits on a Charge AND essentially silences you for the rest of that unit's turn.  Players cannot play Tactics cards for the remainder of that unit's action, and if you miss the actual charge itself, that unit has to take a Panic test.  Lastly, we have Lannister Intimidation.  This is pretty much a hard silence on the enemy unit and all of its attachments until the end of the round.  Again, end of the round here folks, Tywin doesn't F around.  Almost everything he does is centered around making your opponents' units weaker while giving slightly leveraging your battlefield position.

Pycelle is an auto-include with Tywin.

As for unit selection, there are quite a few things you can do and I think Tywin is one of the more flexible commanders for how you want to build the list.  To make things a little easier, let me first start off by saying that you should probably take Pycelle as your first NCU.  Pycelle is incredible with Tywin because he puts Weaken tokens on your opponents when he claims a zone.  This is exactly what Tywin needs when playing his Tactics cards and Pycelle on the Tactics zone after The Lion's Wrath will see 3 enemy units Weakend on a single turn.  Now, Varys is pretty much one of the best NCUs in the game IMO.  His ability is incredibly good even if you only have a limited amount of Order tokens.  The ability to stop a crucial game-altering tactics board play or NCU ability from triggering when claiming a zone can be huge.  Since Lannisters is a control-heavy faction in general, you will see me playing Varys a lot in my lists.

Alright, enough talk, here's the list:

Faction: House Lannister
Commander: Tywin Lannister – Lord of Casterly Rock
Points: 40 (4 Neutral)

Combat Units:
• Lannister Guardsmen (5)
  with Assault Veteran (1)
• House Clegane Mountain Men (6)
  with Tywin Lannister – Lord of Casterly Rock (0)
• House Clegane Mountain Men (6)
  with Assault Veteran (1)
• Lannister Crossbowmen (6)
• Knights of Casterly Rock (8)

Non-Combat Units:
• Pycelle – Grand Maester (3)
• Lord Varys – The Spider (4)

Made with ASOIAFBuilder.com

As you can see, I have quite a bit of diversity in there with 7 total activations (5 combat and 2 NCUs).  Combat activations matter for deployment, but total activations matter for how much control you have over the board state.  That will be its own article at another time, but this isn't the first time I've played a minis game where activation and unit activation order matters a lot.  Anyways, let's take a look at the rest of the list I have here:  You will see Guardsman with Assault Vet, Tywin in MM and another unit of MM because they're a rock-solid unit.  Assault Veterans because I love the aggression and they are great with Tywin because Weaken basically ensures that there will be a second round of combat and your guys will attrition quite well.  For the Guardsman, you can also choose to bring along a Guard Captain to auto-pass Panic and therefore guarantees Lannister Supremacy every time.

When it comes to rounding out the rest of the army, Crossbowmen are there so they can pick off enemy units from range.  From here, you can generally branch into any direction you want to bring for the meta.  You can take another unit of Lannister Guards, another unit of MM, but for diversity and the ability to harass objectives, I decided to go with Xbows.  If you think about it, if you're running a pretty aggressive infantry army, having 7 shots of Sundering from Long Range that hits on 3s is no joke.  On top of that, I've decided to go wih a unit of Knights of Casterly Rock because they're a pretty decent unit to have for the points.  Some people don't like them because you need to play them well and they're not push and win like the Flayed Men, but if you get them on the flank of a combat you need to win, you will like them a lot.  They're designed to win on the charge so if you're not destroying units on the charge, think about saving them until you do or else you'll have to waste turns (or Manuever on the Tactics Board) to set them up again.

Stay tuned for my next article where I cover one of my favorite Stark lists to play right now!

Kamis, 09 April 2020

Riders Of The Pony Express Update

A few months ago, I dusted off my Riders of the Pony Express prototype. It went over really well with my current playtest group, which is always nice to see -- they don't love every game, and it makes me feel bad forcing them to play the ones they don't enjoy enough to "finish" them.

I played RotPE a couple more times lately, and tried the changes I listed in my last post:
1. Increase value of Bears from +2 to +3. I wanted to make the Bears more different from the Bandits (which are +2), and I wanted to make the Shotgun item better... a shotgun can be discarded to remove a bear or bandit from the board, but that's really not worth using ever. This change to +3 accomplished both of those goals, though the shotgun STILL wasn't good enough. Yesterday I tried an improved version of the shotgun: ONCE PER ROUND you can "kill" (turn face down) a Bandit or a Bear. This way you can use it twice, for 2-3 each time, which is a little better - maybe worthwhile. But I'm considering not even having that limit (after all, removing the tile helps other players too!)

2. Deal mandatory parcels face up instead of face down, they don't use up inventory slots. This change seemed good, and simplifies the rules quite a bit. Along with this change, I reduced the max inventory back down to 4 items. Of course, this means you must deliver it before the end of the round.

3. Instead of random parcels for rounds 2 and 3, let players draft from a face up supply of N+1 parcels when they arrive back at the post office. This worked well. It might be a little awkward to have to deal more cads out when you're done auctioning cards for the turn -- maybe better is to deal them at the same time you deal he cards to auction (put the auction cards on one side of the board and the new parcels on the other side)? Anyway, it seemed like a good change.

4. Movement change: Move from town to hazard, or hazard to town... This was proposed by Hoss because he did not feel like it made sense the way I was doing it (move from town to hazard, and on your next turn, finish moving into the town you were heading towards). However, we found hazard-town-hazard to be sort of tedious, and didn't like how that felt. As a compromise, we went back to what I had, but explained it a little differently: you move from town to town, but you ACT at the BEGINNING of your turn, not as you arrive in a town. So you move to the next town, paying whatever cost (by moving your time marker). Then next turn you deliver (if you have anything, costs 1 time), buy an item (if you want, costs 1 time), and then move to the next town (costs some amount based on route, hazard tile, and items you have). This format worked well, and I think it communicated better also.

In addition to those changes, one of my players had a good suggestion: the time track started out going down $1 per space, then later along the track it went 2 spaces per $ drop, and eventually 3 spaces. Aaron pointed out that that felt backwards... once you're already spending a lot of time, spending even more time didn't really cost you anything. So I reversed that... now at the beginning of the track you move several spaces before your reward drops, but farther along the track you lose $1 per space, and near the very end of the track you actually lose $2 per space! I also added a dead stop at the end of the track -- if you hit that, then your delivery phase is automatically over, and you lose $10 for each undelivered parcel. Those changes have all helped combat dynamics I didn't like in the game, and they work toward making sure players care how much they bid for things.

As I mentioned above, I beefed up the shotgun item, which is a definite improvement (side note, it combos with Spurs now, since you can remove the hazard AND then get your spurs discount). In addition, I tried changing the maps to say "ignore the hazard tile when moving to town X" rather than a discount of 2. This made the maps a little more variable, potentially more attractive (at least in some cases), and reduced some of the match involved in calculating your route. As it turns out, this makes maps better for Mountains (+5) and Bears (+3), the same for Banidts (+2) and Lost! (+2), and worse for Snakes (+1) and Rivers (+1). At first I didn't like that (I fear the maps are already not good enough), but you CAN discard them to any Lost! tile, and players seem to think they're worth getting, so maybe they're fine. I think I'll try the "ignore hazard" rule again to see if I want to keep it.

Similarly, Compass should say "ignore Lost! tiles" to help minimize the arithmetic in the game.

Finally, one of the worst parts of the game is the fiddly setup -- drawing a million square tiles and placing them on the board, then removing the tumbleweeds and snakes. Then in week 2, adding more tiles, only to remove tumbleweeds again, etc. I'm looking for a way to do bigger tiles that each cover several hazard spaces, so that setup can be simpler but the map board could still be somewhat variable with respect to where the mountains, rivers, and Lost! tiles are.

It would be cool to make the map not look like a schematic/grid as well!