Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
MSSQL for Pentesters: Abusing Linked Database

πŸ”₯ Telegram: https://t.me/hackinarticles

Learn how attackers can enumerate and exploit MSSQL linked servers to pivot between databases and achieve remote command execution using tools like PowerUpSQL and Metasploit.

🧠 Topics covered:
β€’ Linked Server Enumeration
β€’ Pivoting through Linked Databases
β€’ Enabling xp_cmdshell remotely
β€’ Gaining Meterpreter session

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-abusing-linked-database/
MSSQL for Pentesters: Abusing Trustworthy

πŸ”₯ Telegram: https://t.me/hackinarticles

Learn how attackers can escalate privileges in Microsoft SQL Server by abusing the TRUSTWORTHY database property to gain sysadmin rights from a low-privileged user.

🧠 Topics covered:
β€’ Understanding TRUSTWORTHY property
β€’ Privilege Escalation in MSSQL
β€’ Exploitation using PowerUpSQL
β€’ Metasploit automation for escalation

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-abusing-trustworthy/
MSSQL for Pentesters: Command Execution with External Scripts

πŸ”₯ Telegram: https://t.me/hackinarticles

Learn how attackers can execute OS commands through MSSQL external scripts by leveraging Python and R integration in SQL Server. This technique can lead to system command execution directly from the database engine.

🧠 Topics covered:
β€’ Enabling External Scripts in MSSQL
β€’ Command Execution via Python
β€’ Command Execution via R
β€’ Post-exploitation tradecraft in SQL Server

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-command-execution-with-external-scripts/
πŸš€ Active Directory Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀5
Domain Escalation: Unconstrained Delegation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Unconstrained Delegation allows systems to impersonate users across the domain, making it a critical misconfiguration that can lead to full domain compromise.

⚑️ Attack Highlights
🎯 Identify systems with unconstrained delegation
🎟 Capture user TGT from memory
πŸ”„ Request service tickets (TGS) using stolen TGT
πŸš€ Access any resource as the impersonated user

πŸ’‘ When enabled, the server stores user TGTs in memory, allowing attackers to reuse them and move laterally across the domain.

πŸ“– Article: https://www.hackingarticles.in/domain-escalation-unconstrained-delegation/
NetExec for Pentester: Command Execution

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

NetExec (nxc) is a powerful post-exploitation tool that enables pentesters to execute commands remotely across multiple protocols, making lateral movement faster and more efficient.

🎯 Execution Methods
πŸ’» SMB β€” for file sharing (port 445)
πŸ–₯ WinRM β€” for remote management (port 5985)
🧩 WMI β€” via RPC/DCOM (port 135)
πŸ—„ MSSQL β€” for database access (port 1433)
πŸ“‘ RDP β€” for full desktop access (port 3389)
πŸ” SSH β€” for Linux systems (port 22)

πŸ“– Article: https://www.hackingarticles.in/netexec-for-pentester-command-execution/
Sock Puppets in OSINT

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

A sock puppet is a fake online identity used by OSINT professionals to gather intelligence anonymously while protecting their real identity.

⚑️ Essentials
πŸ§‘β€πŸ’» Generate a Realistic Identity
πŸ“§ Create a Unique Email Address
πŸ“± Obtain a Phone Number
πŸ–Ό Set Up a Profile Picture
🌐 Privacy-Focused VPNs
🧭 Secure Browsers for Anonymity
πŸ’» Privacy-Focused Operating Systems
πŸ§ͺ Testing Your Browser
πŸ’¬ Secure Messaging Tools
πŸ•΅οΈ Mask Your Connection and Device
πŸ“² Register and Build Social Presence
πŸ” Maintain Good OPSEC (Operational Security)

πŸ’‘ Sock puppets help access restricted spaces, interact safely, and collect intelligence without exposing your real identity.

πŸ“– Article: https://hackingarticles.in/sock-puppets-in-osint/
rivacy Protection: Browser Extensions

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Browser extensions can significantly enhance your online privacy by blocking trackers, securing connections, and reducing data collection beyond default browser protections.

⚑️ Essentials
πŸ›‘ Block Trackers & Ads (uBlock Origin, Privacy Badger)
πŸ”— Remove Tracking URLs (ClearURLs)
πŸ” Enforce HTTPS Connections (HTTPS Everywhere)
πŸͺ Auto-Delete Cookies (Cookie AutoDelete)
🧠 Prevent CDN Tracking (Decentraleyes)
πŸ“Ί Skip Sponsored Content (SponsorBlock)

πŸ’‘ Extensions help stop tracking scripts, protect sensitive data, and defend against threats like malvertising and man-in-the-middle attacks.

πŸ“– Article: https://hackingarticles.in/privacy-protection-browser-extensions/
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀2
πŸ‘5❀3
🐧 Linux Privilege Escalation – Pentester Cheatsheet

πŸ”₯ Telegram: https://t.me/hackinarticles

A practical Linux Privilege Escalation reference guide designed for OSCP aspirants, Red Teamers, and penetration testers.
This cheatsheet helps security researchers understand multiple ways to escalate privileges from a low-privileged user to root on Linux systems.

⚑️ Topics Covered:

πŸ” Abusing Sudo Rights
🧩 SUID Binaries Exploitation
βš™οΈ Linux Capabilities Abuse
🐳 Docker Privilege Escalation
πŸ“¦ LXD / LXC Container Escape
⏱️ Exploiting Cron Jobs
πŸ“‚ Writable /etc/passwd File
🌐 Misconfigured NFS
πŸƒ Wildcard Injection
🧬 LD_PRELOAD Privilege Escalation
πŸ›£ PATH Variable Exploitation
🐍 Python Library Hijacking
πŸ›‘ Polkit Vulnerability (CVE-2021-3560)
πŸ’£ PwnKit (CVE-2021-4034)
πŸ”₯ DirtyPipe (CVE-2022-0847) Kernel Exploit

🎯 Useful for CTF players, OSCP preparation, Red Team operations, and Linux post-exploitation assessments.

πŸ”— GitHub Repository:
https://github.com/Ignitetechnologies/Linux-Privilege-Escalation
❀7
5 Tools for AD Enumeration
❀2
9 Ways to gain Expersience in CYber Security
❀2
Network Trafic Analysis Tools
❀3
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
πŸ”₯ Ethical Hacking Proactive Training – Live & Practical πŸ”₯

Ready to build real-world cybersecurity skills with hands-on experience?

πŸš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure β€” at an affordable price.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

πŸ“˜ What You’ll Learn:

βœ… Introduction to Ethical Hacking
βœ… Old School Learning Methodology
βœ… Networking Fundamentals
βœ… Reconnaissance (Footprinting, Scanning & Enumeration)
βœ… System Hacking
βœ… Post Exploitation & Persistence
βœ… Web Server Penetration Testing
βœ… Website Hacking Techniques
βœ… Malware Threats & Analysis
βœ… Wireless Network Security
βœ… Cryptography & Steganography
βœ… Sniffing Attacks
βœ… Denial of Service (DoS)
βœ… Evading IDS, Firewalls & Honeypots
βœ… Social Engineering Techniques
βœ… Mobile Platform Security

πŸ’‘ Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.