Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Pass-the-Certificate: Lateral Movement Technique

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Pass-the-Certificate is an advanced post-exploitation technique where attackers use X.509 certificates (.pfx) to authenticate instead of passwords or NTLM hashes.

⚑️ Key Features
🎟 Authentication using PFX certificates
πŸ” Leverages Kerberos PKINIT (certificate-based login)
πŸ’» Works with NetExec & Impacket tools
πŸš€ Lateral movement via SMB, WMI, WinRM & MSSQL
πŸ–₯ Remote access using Evil-WinRM
⚑️ Supports certificate β†’ CCACHE conversion
πŸ•΅οΈ Stealthy & hard to detect

πŸ’‘ Attackers can use stolen or forged certificates to request Kerberos TGTs and access domain systems without credentials, enabling seamless lateral movement across Active Directory.

πŸ“– Article: https://www.hackingarticles.in/lateral-movement-pass-the-certificate/
❀5πŸ”₯2
Comprehensive Guide on SSH Tunneling

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SSH Tunneling is a technique used to securely transmit network traffic through an encrypted SSH connection, allowing users to access services on remote or internal networks while bypassing firewall restrictions. ()

πŸ“š SSH Tunneling Techniques Covered

πŸ” Dynamic SSH Tunneling
πŸ“‘ Local SSH Tunneling
🌐 Remote SSH Tunneling

🧰 Tools & Techniques Used

πŸ–₯ PuTTY
🐧 Kali Linux
🧦 SOCKS5 Proxy
πŸ“¦ tsocks

πŸ“– Article:
https://www.hackingarticles.in/comprehensive-guide-on-ssh-tunneling/
❀2
Port Forwarding & Tunnelling CheatSheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Port forwarding and tunnelling are essential techniques used to access internal services, bypass firewalls, and pivot across networks during post-exploitation.

⚑️ Key Concepts
πŸ” Port Forwarding (Local & Remote)
🌐 Tunnelling (Encapsulation over SSH/VPN)
πŸ”— Pivoting into internal networks
πŸ›‘ Bypassing firewall restrictions

⚑️ Common Tools
🐧 SSH (Local/Remote/Dynamic forwarding)
πŸ”Œ Socat
πŸ’» Netcat
πŸ›  Metasploit (portfwd)
⚑️ Chisel / Plink

πŸ’‘ Tunnelling encapsulates traffic through another protocol (like SSH), enabling secure communication and access to restricted services across networks.

πŸ“– CheatSheet: https://www.hackingarticles.in/port-forwarding-tunnelling-cheatsheet/
❀1
Chisel Port Forwarding: A Detailed Guide

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Chisel is a fast and lightweight TCP/UDP tunneling tool written in Golang that allows penetration testers to bypass firewalls and access internal services securely using HTTP tunnels and SSH encryption. ()

⚑️ Key Techniques Covered
πŸ” Reverse Port Forwarding
πŸ”Œ Local Port Forwarding
🌐 SOCKS5 Proxy Tunneling
🧭 Network Pivoting
πŸ“‘ Internal Service Access

πŸ›  Tools & Utilities Used
πŸ’» Chisel Server & Client
🧰 Proxychains
🌐 SOCKS5 Proxy
πŸ–₯ Netcat (nc)
πŸ”— VNC Viewer / FTP / Telnet

πŸ“– Article: https://www.hackingarticles.in/chisel-port-forwarding-a-detailed-guide/
πŸ‘1
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀2
πŸš€ Active Directory Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
❀4
🚨 Windows Privilege Escalation: Unquoted Service Path

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Unquoted Service Path is a common Windows misconfiguration where service executable paths are not enclosed in quotes, allowing attackers to execute malicious binaries and gain SYSTEM privileges. ()

πŸ“˜ Introduction to Unquoted Service Path
❓ What is an Unquoted Service Path
πŸ“‚ How Windows Interprets Unquoted Paths
βš™οΈ Vulnerable Service Path Example
πŸ” Enumeration using WMIC & PowerShell
πŸ§ͺ Automated Enumeration (WinPEAS, PowerUp)
πŸ“Ÿ Identifying Writable Directories
πŸ’£ Placing Malicious Executable (e.g., Program.exe)
πŸ”„ Service Restart / System Reboot
🎯 Gaining NT AUTHORITY\SYSTEM Shell
πŸ›  Exploitation using Metasploit
πŸ›‘ Mitigation (Proper Quoting & Permissions)

⚑️ If a service path contains spaces and is not quoted, Windows may execute attacker-controlled binaries placed earlier in the pathβ€”leading to full system compromise.

πŸ”— Read Full Guide: https://hackingarticles.in/windows-privilege-escalation-unquoted-service-path/
❀1πŸ‘1
🚨 Windows Privilege Escalation: AlwaysInstallElevated

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

AlwaysInstallElevated is a dangerous Windows misconfiguration that allows low-privileged users to install MSI packages with SYSTEM-level privileges, leading to full privilege escalation. ()

πŸ“˜ Introduction to AlwaysInstallElevated
❓ What is β€œAlways Install with Elevated Privileges”
βš™οΈ Group Policy Misconfiguration (HKLM & HKCU)
πŸ“‚ Windows Installer & MSI Packages
πŸ” Enumeration via Registry (reg query)
πŸ§ͺ Automated Enumeration (WinPEAS)
πŸ“Ÿ Checking Both Registry Keys Enabled
πŸ’£ Exploitation using Malicious MSI
πŸ“₯ Payload Creation (msfvenom)
πŸ›  Execution via msiexec
🎯 Gaining NT AUTHORITY\SYSTEM Shell
⚑️ Privilege Escalation using Metasploit

⚑️ If both registry keys are enabled, any user can execute MSI files as SYSTEMβ€”effectively granting full administrative control over the machine. ()

πŸ”— Read Full Guide: https://www.hackingarticles.in/windows-privilege-escalation-alwaysinstallelevated/
❀1
🚨 Windows Privilege Escalation: SeBackupPrivilege

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SeBackupPrivilege allows users to bypass file ACLs and read any file on the system, making it a powerful vector for privilege escalation after initial access.

⚑️ Attack Highlights
πŸ“‚ Read sensitive files (SAM, SYSTEM, NTDS.dit)
πŸ” Bypass file permission restrictions
🧠 Extract NTLM hashes
πŸš€ Escalate to Administrator / SYSTEM

πŸ“˜ Lab Workflow
βš™οΈ Setup privilege on Windows & DC
πŸ§ͺ Verify using whoami /priv
πŸ’₯ Dump SAM & SYSTEM hives
🎯 Extract hashes & escalate access

πŸ’‘ Since this privilege grants full read access, attackers can dump credential files and reuse hashes to gain elevated access across the system or domain.

πŸ“– Article: https://www.hackingarticles.in/windows-privilege-escalation-sebackupprivilege/
❀1
🚨 Windows Privilege Escalation: Stored Credentials (Runas)

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Stored Credentials abuse is a common privilege escalation technique where attackers leverage saved credentials in Windows Credential Manager to execute commands with higher privileges. ()

πŸ“˜ Introduction to Stored Credentials
❓ What is Windows Credential Manager
πŸ” Web Credentials vs Windows Credentials
πŸ“‚ Stored Credentials Enumeration
πŸ“Ÿ Using cmdkey /list
πŸ§ͺ Credential Discovery via WinPEAS
βš™οΈ Runas Utility Explained
πŸ” Using /savecred Parameter
πŸ’£ Executing Commands as Administrator
πŸ“₯ Creating Malicious Payload (msfvenom)
🌐 Transferring Payload to Target
🎯 Gaining NT AUTHORITY\SYSTEM Shell
πŸ‘ Post-Exploitation Access

⚑️ If administrative credentials are stored, attackers can execute commands without knowing the password using runas /savecred, leading to full system compromise. ()

πŸ”— Read Full Guide: https://hackingarticles.in/windows-privilege-escalation-stored-credentials-runas/
❀1πŸ‘1
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀3πŸ‘1
πŸš€ Active Directory Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
❀1πŸ‘1
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
πŸ‘2
Impacket: SecretsDump for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Impacket’s secretsdump.py allows attackers to extract credentials remotely without deploying any agent, making it a powerful tool for post-exploitation in Active Directory environments.

⚑️ What It Dumps
πŸ” NTLM password hashes
πŸ“‚ SAM & LSA secrets
🎟 Kerberos keys
πŸ“Š NTDS.dit (Domain Controller database)

⚑️ Techniques
🧠 DCSync attack (replicate DC credentials)
πŸ“‘ Remote registry extraction
πŸ’Ύ NTDS.dit dumping via VSS

πŸ’‘ With proper privileges, attackers can dump domain credentials and move laterally across the network without touching disk.

πŸ“– Article: https://www.hackingarticles.in/imapacket-for-pentester-secretdump/
❀1
Impacket for Pentester – MSSQL Exploitation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

MSSQL servers are high-value targets in internal networks β€” and tools like Impacket make exploitation powerful & flexible πŸ”

πŸ›  In this guide you’ll learn:
πŸ” MSSQL enumeration & access using Impacket
πŸ” Authentication techniques (Windows & SQL)
βš™οΈ Command execution via xp_cmdshell
πŸ“‚ Data extraction & privilege escalation
πŸ”— Linked server exploitation & lateral movement
πŸš€ Real-world pentesting workflows

⚑️ Exploit MSSQL like a pro and level up your internal network attacks.

πŸ“– Read the full guide:
https://www.hackingarticles.in/impacket-for-pentester-mssql-exploitation/
Kerberos Constrained Delegation Exploitation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Kerberos Constrained Delegation (KCD) can be abused to impersonate any domain user and access critical services when misconfigured.

⚑️ Attack Highlights
πŸ” Enumerate delegation settings (msDS-AllowedToDelegateTo)
🎯 Identify accounts with Protocol Transition enabled
🎟 Abuse S4U2Self + S4U2Proxy to impersonate users
πŸ” Request service tickets as Administrator
πŸš€ Gain SYSTEM access & dump credentials

πŸ’‘ With Protocol Transition enabled, attackers can generate service tickets for any user without knowing their password and access delegated services.

πŸ“– Article: https://www.hackingarticles.in/kerberos-constrained-delegation-exploitation/
Shadow Credentials Attack

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Shadow Credentials attack abuses Active Directory Certificate Services (AD CS) by injecting rogue public keys into the msDS-KeyCredentialLink attribute, allowing attackers to authenticate as a target user without knowing their password or NTLM hash.

πŸ“š Topic Covered

πŸ“– Introduction
🧠 Understanding Kerberos & PKINIT
πŸ”‘ msDS-KeyCredentialLink Attribute
βš™οΈ Prerequisites & Lab Setup
πŸ” Hunting Weak Permissions (BloodHound)
πŸ’‰ Injecting Shadow Credentials
πŸ“¦ Tools: PyWhisker, Certipy, Impacket
πŸ” PKINIT Authentication using Certificate
🎟 Obtaining TGT (Kerberos Ticket)
πŸͺͺ Extracting NTLM Hash (getnthash.py)
πŸ’» NTLM Relay Attack (ntlmrelayx)
πŸ’£ Metasploit Shadow Credentials Module
πŸš€ Privilege Escalation & Persistence
πŸ›‘ Detection (Event ID 4768, 5136)
βš™οΈ Mitigation & Hardening Techniques

πŸ“– Article:
https://hackingarticles.in/shadow-credentials-attack/
❀1
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀1
❀1πŸ‘Ž1