Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
🚨 Credential Dumping: LAPS Abuse

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

In Windows environments, Local Administrator Password Solution (LAPS) stores local administrator passwords inside Active Directory attributes. If an attacker gains permission to read these attributes, they can retrieve the credentials and perform lateral movement across the network.

⚑️ Key Tools for LAPS Enumeration & Dumping
πŸ›  Impacket
βš”οΈ NXC Tool
🐍 PyLaps
πŸ“¦ LAPSDumper
🩸 BloodyAD
πŸ”Ž ldapsearch
πŸ’£ Metasploit: ldap_query
πŸ”— impacket-ntlmrelayx
πŸ–₯ ldap_shell
πŸ“œ PowerShell
🌐 NetTools
πŸ’Ž SharpLAPS
πŸš€ Metasploit: enum_laps
🧠 PowerView

πŸ“– Article: https://www.hackingarticles.in/credential-dumping-laps/
❀1
🚨 Credential Dumping: Phishing Windows Credentials

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Phishing attacks are commonly used to capture Windows credentials by tricking users into entering their login details on malicious prompts or fake login screens. Once obtained, attackers can reuse these credentials to gain unauthorized access and move laterally inside the network.

⚑️ Key Tools Used for Windows Credential Phishing
πŸ›  Metasploit Framework
🎣 phish_windows_credentials
πŸ–₯ FakeLogonScreen
πŸ” SharpLocker
βš”οΈ PowerShell Empire
πŸ“¦ Collection/prompt
🍞 Collection/toasted
πŸ’‰ Koadic
πŸ“© Password_box
πŸ“œ PowerShell
πŸ§ͺ Invoke-CredentialsPhish.ps1
πŸ”‘ Invoke-LoginPrompt.ps1
🎭 Lockphish

πŸ“– Article: https://www.hackingarticles.in/credential-dumping-phishing-windows-credentials/
🚨 Credential Dumping: Applications

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Many applications store credentials, authentication tokens, or configuration secrets locally on a system. Attackers can extract these stored credentials from application files or memory to gain unauthorized access and move laterally across the network. ()

⚑️ Key Applications Targeted for Credential Dumping
🌐 FileZilla
πŸ—„ WinSCP
πŸ’» PuTTY
πŸ“‘ mRemoteNG
πŸ›  OpenVPN
πŸ“‚ Remote Desktop Connection Manager (RDCMan)
🧰 VNC
πŸ” KeePass

πŸ“– Article: https://www.hackingarticles.in/credential-dumping-applications/
❀2πŸ‘1
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀5πŸ‘1
Android Meterpreter Commands Cheatsheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Android Meterpreter is a powerful payload used in the Metasploit Framework to interact with compromised Android devices. It allows pentesters to access device information, capture data, and perform post-exploitation tasks.

⚑️ Key Android Meterpreter Commands

πŸ“± dump_contacts
πŸ’¬ dump_sms
πŸ“ž dump_calllog
πŸ“· webcam_snap
🎀 record_mic
πŸ“ geolocate
πŸ“‚ ls
πŸ“ cd
πŸ“₯ download
πŸ“€ upload
πŸ“² send_sms
πŸ“‘ sysinfo
πŸ”‹ check_root
πŸ“¦ app_list
🧠 getpid
πŸ”Ž ps

πŸ“š Metasploit Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Metasploit
❀1
🚨 Wireshark Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Wireshark is a powerful network protocol analyzer used to capture and inspect network traffic. It helps security professionals analyze packets, detect suspicious activity, and troubleshoot network issues.

⚑️ Useful Wireshark Filters & Commands

🌐 ip.addr == 192.168.1.1
πŸ“‘ tcp.port == 80
πŸ” tcp.port == 443
πŸ“§ smtp
πŸ“ ftp
🧠 dns
πŸ” http.request
πŸ“₯ tcp.flags.syn == 1
πŸ“€ tcp.flags.ack == 1
⚠️ icmp
πŸ•΅οΈ arp
πŸ“Š frame contains "password"

These filters help analysts quickly identify protocol activity, suspicious traffic, and potential security incidents.

πŸ“š Wireshark Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Wireshark
❀1πŸ‘1
Social Engineering Attack Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Social Engineering is a technique used to manipulate people into revealing confidential information or performing actions that compromise security. It is commonly used as an initial access vector in many cyber attacks.

⚑️ Common Social Engineering Attacks

🎣 Phishing
πŸ“± Smishing (SMS Phishing)
πŸ“ž Vishing (Voice Phishing)
🎭 Pretexting
🎁 Baiting
πŸͺ€ Quid Pro Quo
πŸ‘€ Shoulder Surfing
πŸ—‘ Dumpster Diving
πŸ§‘β€πŸ’» Impersonation
πŸ”— Malicious Links

Understanding these techniques helps security professionals and organizations identify, prevent, and mitigate social engineering attacks.

πŸ“š Social Engineering Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Social%20Engineering
πŸ‘1
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀2πŸ‘1
Shodan Cheat Sheet for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Shodan is a powerful search engine that discovers internet-connected devices such as servers, routers, webcams, IoT devices, and industrial systems. Unlike Google that indexes websites, Shodan indexes devices, services, and open ports across the internet. ()

⚑️ Useful Shodan Search Filters

πŸ”Ž port:22
🌍 country:US
🏒 org:"Amazon"
πŸ’» os:Windows
πŸ“¦ product:Apache
🌐 hostname:example.com
πŸ“‘ net:192.168.1.0/24
🏷 city:London
🧠 vuln:CVE-2021-44228
πŸ” ssl:true

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Shodan
❀1
Subdomain Enumeration Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Subdomain Enumeration is the process of discovering subdomains associated with a target domain during reconnaissance. It helps pentesters identify hidden services, development environments, APIs, and misconfigured systems that may expose vulnerabilities. ()

⚑️ Popular Subdomain Enumeration Tools

πŸ”Ž Subfinder
πŸ›° Amass
πŸ“‘ Assetfinder
🧠 Sublist3r
🌐 Findomain
πŸ“‚ DNSenum
πŸ“ DNSrecon
πŸ’£ Gobuster (DNS Mode)
⚑️ FFUF (DNS Fuzzing)
🧩 Knockpy

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Subdomain%20Enumeration
❀3πŸ‘1
πŸ”₯ Ethical Hacking Proactive Training – Live & Practical πŸ”₯

Ready to build real-world cybersecurity skills with hands-on experience?

πŸš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure β€” at an affordable price.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

πŸ“˜ What You’ll Learn:

βœ… Introduction to Ethical Hacking
βœ… Old School Learning Methodology
βœ… Networking Fundamentals
βœ… Reconnaissance (Footprinting, Scanning & Enumeration)
βœ… System Hacking
βœ… Post Exploitation & Persistence
βœ… Web Server Penetration Testing
βœ… Website Hacking Techniques
βœ… Malware Threats & Analysis
βœ… Wireless Network Security
βœ… Cryptography & Steganography
βœ… Sniffing Attacks
βœ… Denial of Service (DoS)
βœ… Evading IDS, Firewalls & Honeypots
βœ… Social Engineering Techniques
βœ… Mobile Platform Security

πŸ’‘ Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
πŸ‘1
Censys Search Engine for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Censys is a powerful internet scanning and reconnaissance platform used by security researchers and penetration testers to discover exposed assets, services, and vulnerabilities across the internet.

⚑️ Useful Censys Search Queries

🌐 services.port: 21
πŸ” services.port: 22
πŸ’» services.port: 3389
πŸ“‘ services.service_name: HTTP
πŸ”Ž services.tls.certificates.leaf_data.subject.common_name: example.com
🧠 services.software.product: Apache
πŸ“Š location.country: "India"
⚠️ services.port: 23
πŸ›° autonomous_system.name: "Amazon"

πŸ“š Mindmap: https://github.com/Ignitetechnologies/Mindmap/tree/main/Censys

These queries help pentesters perform internet-wide reconnaissance and asset discovery.
🚨 Cloud Security Framework Mindmap

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Cloud security frameworks help organizations secure cloud infrastructure, identities, applications, and data across different cloud platforms.

⚑️ Key Areas in Cloud Security Framework

☁️ Identity & Access Management (IAM)
πŸ” Data Security & Encryption
πŸ›‘ Network Security
πŸ“¦ Workload & Container Security
πŸ“Š Logging & Monitoring
πŸ”Ž Security Posture Management
βš™οΈ DevSecOps & CI/CD Security
🧠 Threat Detection & Incident Response
πŸ“‘ Governance, Risk & Compliance

🧠 Cloud Security Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Cloud%20Security%20Framework
❀1πŸ‘1
🚨 Container Security Mindmap

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Container security focuses on protecting containerized applications, images, registries, and runtime environments from vulnerabilities and misconfigurations. Containers share the host kernel, so weaknesses in images, runtime, or configuration can expose the host system or other containers. ()

⚑️ Key Areas in Container Security

🐳 Docker Security
☸️ Kubernetes Security
πŸ–Ό Container Image Security
πŸ“¦ Container Registry Security
πŸ›‘ Runtime Security
πŸ”‘ Secrets Management
πŸ“Š Monitoring & Logging
πŸ” Vulnerability Scanning
βš™οΈ DevSecOps Integration
🚨 Container Breakout Prevention

🧠 Container Security Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Container%20Security
❀1
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
API Penetration Testing Training (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with Ignite Technologies’ fully exclusive Training Program "API Penetration Testing Training."

βœ”οΈ Table of Content

πŸ“˜ Course Introduction
πŸ” How API works with Web application
βš–οΈ Types of APIs and their advantages/disadvantages
πŸ”Ž Analysing HTTP request and response headers
πŸ›‘ API Hacking methodologies
πŸ“„ Enumerate web pages and analyse functionalities
πŸ•΅οΈ API passive reconnaissance Strategies
πŸš€ API active reconnaissance (Kite runner)
πŸ”§ Introduction to POSTMAN
πŸ” Testing for Excessive data exposure
πŸ“‚ Directory indexing / brute force
πŸ”‘ Password mutation
🎯 Password spray attacks against web application
πŸ›‘ Introduction to JSON Web Token
πŸ•΅οΈ Hunting for JWT authentication vulnerabilities
πŸ’£ Exploiting JWT unverified signature
πŸ”“ Cracking JWT secret keys
🚫 Bypass JWT removing signature
🌍 Testing out-band SSRF vulnerabilities in an API
βš™οΈ Testing OS Command Injection
β˜•οΈ Exploiting Java deserialization vulnerabilities
πŸ—‚ Testing for improper assets management
πŸ“¦ Testing for Mass assignment vulnerabilities
🚧 Bypass filter, space, and blacklisted characters
πŸ” Bypass Captcha and MFA
πŸ“‹ Remediations and Reporting
❀2
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀1
Bug Bounty Tools Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Bug bounty hunters use a combination of reconnaissance, scanning, and exploitation tools to discover vulnerabilities in web applications and infrastructure.

⚑️ Popular Bug Bounty Tools

πŸ”Ž Subfinder
🌐 Amass
πŸ“‘ Assetfinder
⚑️ FFUF
🧠 Nuclei
πŸ•· Burp Suite
πŸ’‰ SQLMap
πŸ“‚ Dirsearch
πŸ” WPScan
πŸ“Š Dalfox

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Tools