Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
🚨 Credential Dumping: Applications

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Many applications store credentials, authentication tokens, or configuration secrets locally on a system. Attackers can extract these stored credentials from application files or memory to gain unauthorized access and move laterally across the network. ()

⚑️ Key Applications Targeted for Credential Dumping
🌐 FileZilla
πŸ—„ WinSCP
πŸ’» PuTTY
πŸ“‘ mRemoteNG
πŸ›  OpenVPN
πŸ“‚ Remote Desktop Connection Manager (RDCMan)
🧰 VNC
πŸ” KeePass

πŸ“– Article: https://www.hackingarticles.in/credential-dumping-applications/
❀3
Credential Dumping: Clipboard

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Credential Dumping via clipboard is a technique where attackers capture sensitive data (like passwords or tokens) copied by users, exploiting the fact that clipboard data is accessible to applications and can be monitored or extracted.

πŸ“š Topic Covered

πŸ“– Introduction
πŸ“‹ Understanding Clipboard Data Leakage
🧠 How Attackers Monitor Clipboard
πŸ’» Credential Capture via Clipboard
πŸ›  Tools & Techniques for Clipboard Dumping
πŸ” Extracting Sensitive Information
πŸš€ Post-Exploitation Use of Credentials
πŸ›‘ Detection & Mitigation Techniques

πŸ“– Article:
https://hackingarticles.in/credential-dumping-clipboard/
Credential Dumping: Domain Cached Credentials

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Domain Cached Credentials (DCC) are stored locally to allow offline authentication. Attackers can dump these cached hashes and crack them offline to recover user credentials.

πŸ“š Topic Covered

πŸ— Domain Cache Credential
πŸ’£ Metasploit
πŸ“¦ Impacket
πŸͺͺ Mimikatz
⚑️ PowerShell Empire
πŸ•΅οΈ Koadic
🐍 Python Script

πŸ“– Article:
https://hackingarticles.in/credential-dumping-domain-cache-credential/
Credential Dumping: Fake Services

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Credential Dumping using fake services is a technique where attackers deploy rogue servers to capture authentication attempts and steal credentials or hashes for further exploitation.

πŸ“š Topic Covered

πŸ“– Introduction
πŸ“‚ FTP
πŸ”Œ Telnet
πŸ–₯ VNC
πŸ“ SMB
🌐 HTTP Basic
πŸ“© POP3
πŸ“€ SMTP
🐘 PostgreSQL
πŸ—„ MSSQL
πŸ” HTTP NTLM
πŸ—ƒ MSSQL

πŸ“– Article:
https://www.hackingarticles.in/credential-dumping-fake-services/
πŸ”₯ Ethical Hacking Proactive Training – Live & Practical πŸ”₯

Ready to build real-world cybersecurity skills with hands-on experience?

πŸš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure β€” at an affordable price.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

πŸ“˜ What You’ll Learn:

βœ… Introduction to Ethical Hacking
βœ… Old School Learning Methodology
βœ… Networking Fundamentals
βœ… Reconnaissance (Footprinting, Scanning & Enumeration)
βœ… System Hacking
βœ… Post Exploitation & Persistence
βœ… Web Server Penetration Testing
βœ… Website Hacking Techniques
βœ… Malware Threats & Analysis
βœ… Wireless Network Security
βœ… Cryptography & Steganography
βœ… Sniffing Attacks
βœ… Denial of Service (DoS)
βœ… Evading IDS, Firewalls & Honeypots
βœ… Social Engineering Techniques
βœ… Mobile Platform Security

πŸ’‘ Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
❀3
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀3
Impacket for Pentester – PsExec Exploitation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Gaining remote command execution is a key step in internal pentesting β€” and Impacket PsExec makes it powerful ⚑️

πŸ›  In this guide you’ll learn:
πŸ” Remote command execution via SMB
βš™οΈ Using psexec.py for interactive shells
πŸ”‘ Pass-the-Hash authentication techniques
πŸ“‚ Upload & execute payloads on target
πŸ”— Lateral movement across network
πŸš€ Real-world attack scenarios

⚑️ Turn credentials into full system access and move like a pro inside networks.

πŸ“– Read the full guide:
https://www.hackingarticles.in/impacket-for-pentester-psexec/
❀1
Impacket for Pentester – MSSQL Exploitation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

MSSQL servers are high-value targets in internal networks β€” and tools like Impacket make exploitation powerful & flexible πŸ”

πŸ›  In this guide you’ll learn:
πŸ” MSSQL enumeration & access using Impacket
πŸ” Authentication techniques (Windows & SQL)
βš™οΈ Command execution via xp_cmdshell
πŸ“‚ Data extraction & privilege escalation
πŸ”— Linked server exploitation & lateral movement
πŸš€ Real-world pentesting workflows

⚑️ Exploit MSSQL like a pro and level up your internal network attacks.

πŸ“– Read the full guide:
https://www.hackingarticles.in/impacket-for-pentester-mssql-exploitation/
❀4
FTP Password Cracking

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

FTP services often rely on weak or default credentials and transmit data in plaintext, making them an easy target for attackers to gain initial access.

⚑️ Tools
πŸ”₯ Hydra
πŸ›  Metasploit
⚑️ Medusa
πŸš€ Ncrack
πŸ“‘ Patator
πŸ’£ BruteSpray
πŸ” Nmap NSE

πŸ“– Article: https://www.hackingarticles.in/ftp-password-cracking/
❀1😁1
MS-SQL Password Cracking

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

MS-SQL services often rely on weak or default credentials, making them an easy target for attackers to gain unauthorized database access.

⚑️ Tools
πŸ”₯ Hydra
πŸ›  Metasploit
⚑️ Medusa
πŸš€ NetExec
πŸ’£ BruteSpray
πŸ” Nmap NSE

πŸ“– Article: https://hackingarticles.in/password-crackingms-sql/
❀1
PostgreSQL Password Cracking

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

PostgreSQL services often rely on weak or default credentials, making them an easy target for attackers to gain unauthorized database access.

⚑️ Tools
πŸ”₯ Hydra
πŸ›  Metasploit
⚑️ Medusa
πŸš€ Ncrack
πŸ“‘ Patator
πŸ’£ BruteSpray
πŸ” Nmap NSE

πŸ“– Article: https://www.hackingarticles.in/postgresql-password-cracking/
❀1
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
πŸš€ AI Penetration Testing Training (Live Online Program)

The future of cybersecurity is AI-driven β€” are you ready to test and secure it?

Ignite Technologies is launching an intensive AI Penetration Testing Training designed for security professionals, pentesters, red teamers, and researchers who want to understand how to attack and defend Large Language Models (LLMs) and AI systems.

πŸ”— Register Now: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

⚠️ Limited seats available.

🧠 What You’ll Learn

πŸ”Ή LLM Architecture & Security Principles
πŸ”Ή Data Security in AI Systems
πŸ”Ή Model & Infrastructure Security
πŸ”Ή OWASP Top 10 for LLMs
πŸ”Ή LLM Installation & Secure Deployment
πŸ”Ή Model Context Protocol (MCP)
πŸ”Ή Publishing Models using Ollama
πŸ”Ή Retrieval-Augmented Generation (RAG) Security

πŸ”₯ Offensive AI Security Modules

βœ”οΈ Prompt Injection & Indirect Injection Attacks
βœ”οΈ Exploiting LLM APIs (Real-World Bug Scenarios)
βœ”οΈ Password & Sensitive Data Leakage via AI
βœ”οΈ Excessive Privilege Exploitation
βœ”οΈ LLM Misconfigurations
βœ”οΈ Data Extraction Attacks
βœ”οΈ Content Manipulation in LLM Outputs
βœ”οΈ AI-based Enumeration Techniques

πŸ›‘ Defensive & Automation Focus

βœ… Securing AI Systems
βœ… System Prompt Security Implications
βœ… Automated Penetration Testing with AI
βœ… Making AI Applications Secure & Public-Ready

If you're already into Pentesting, Red Teaming, Bug Bounty, OSCP prep, or Offensive Security, this program will give you a cutting-edge advantage in AI security.

Secure your seat before registrations close.
❀3
MSSQL for Pentesters: Stored Procedures Persistence

πŸ”₯ Telegram: https://t.me/hackinarticles

Learn how attackers achieve persistence in Microsoft SQL Server using start-up stored procedures and xp_cmdshell to execute payloads automatically when the SQL service restarts.

🧠 Topics covered:
β€’ Startup Stored Procedures
β€’ Persistence in MSSQL
β€’ PowerShell reverse shell execution
β€’ Red Team tradecraft

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-stored-procedures-persistence/
MSSQL for Pentesters: Abusing Linked Database

πŸ”₯ Telegram: https://t.me/hackinarticles

Learn how attackers can enumerate and exploit MSSQL linked servers to pivot between databases and achieve remote command execution using tools like PowerUpSQL and Metasploit.

🧠 Topics covered:
β€’ Linked Server Enumeration
β€’ Pivoting through Linked Databases
β€’ Enabling xp_cmdshell remotely
β€’ Gaining Meterpreter session

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-abusing-linked-database/
MSSQL for Pentesters: Abusing Trustworthy

πŸ”₯ Telegram: https://t.me/hackinarticles

Learn how attackers can escalate privileges in Microsoft SQL Server by abusing the TRUSTWORTHY database property to gain sysadmin rights from a low-privileged user.

🧠 Topics covered:
β€’ Understanding TRUSTWORTHY property
β€’ Privilege Escalation in MSSQL
β€’ Exploitation using PowerUpSQL
β€’ Metasploit automation for escalation

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-abusing-trustworthy/
MSSQL for Pentesters: Command Execution with External Scripts

πŸ”₯ Telegram: https://t.me/hackinarticles

Learn how attackers can execute OS commands through MSSQL external scripts by leveraging Python and R integration in SQL Server. This technique can lead to system command execution directly from the database engine.

🧠 Topics covered:
β€’ Enabling External Scripts in MSSQL
β€’ Command Execution via Python
β€’ Command Execution via R
β€’ Post-exploitation tradecraft in SQL Server

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-command-execution-with-external-scripts/
πŸš€ Active Directory Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀5
Domain Escalation: Unconstrained Delegation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Unconstrained Delegation allows systems to impersonate users across the domain, making it a critical misconfiguration that can lead to full domain compromise.

⚑️ Attack Highlights
🎯 Identify systems with unconstrained delegation
🎟 Capture user TGT from memory
πŸ”„ Request service tickets (TGS) using stolen TGT
πŸš€ Access any resource as the impersonated user

πŸ’‘ When enabled, the server stores user TGTs in memory, allowing attackers to reuse them and move laterally across the domain.

πŸ“– Article: https://www.hackingarticles.in/domain-escalation-unconstrained-delegation/
NetExec for Pentester: Command Execution

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

NetExec (nxc) is a powerful post-exploitation tool that enables pentesters to execute commands remotely across multiple protocols, making lateral movement faster and more efficient.

🎯 Execution Methods
πŸ’» SMB β€” for file sharing (port 445)
πŸ–₯ WinRM β€” for remote management (port 5985)
🧩 WMI β€” via RPC/DCOM (port 135)
πŸ—„ MSSQL β€” for database access (port 1433)
πŸ“‘ RDP β€” for full desktop access (port 3389)
πŸ” SSH β€” for Linux systems (port 22)

πŸ“– Article: https://www.hackingarticles.in/netexec-for-pentester-command-execution/