Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
πŸ‘2
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀5
πŸš€ Level Up Your Cyber Security Skills β€” Online Training by Ignite Technologies

Ready to break into πŸ” Cyber Security or sharpen your Red Team edge? Limited seats. Serious learners only.

πŸŽ“ Programs Offered:
⚑️ Ethical Hacking
🐞 Bug Bounty Mastery
πŸ€– AI-Powered Pentesting
πŸ“± Android (APK) Pentesting
🍏 iOS Pentesting
🏒 Source Code Review
🎯 Real-World CTF Challenges
πŸ•΅οΈβ€β™‚οΈ Active Directory Red Teaming
🐧 OSEP (Defense Evasion)
☁️ Cloud Pentesting

⏳ Seats are limited β€” secure yours now!

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1
πŸ“§ info@ignitetechnologies.in
❀3⚑1
Active Directory Penetration Testing Using Impacket

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Impacket is a powerful toolkit used to perform enumeration, exploitation, and post-exploitation in Active Directory environments.

⚑️ Attack Highlights
πŸ” Enumerate users, SIDs & computers (lookupsid, GetADUsers)
🎯 Perform Kerberos attacks (AS-REP Roasting, Kerberoasting)
πŸ” Abuse delegation (RBCD) for privilege escalation
🎟 Dump credentials (DCSync, LAPS, GMSA)
πŸ’‰ Execute remote commands (psexec, wmiexec)
πŸš€ Achieve Domain Admin access

πŸ’‘ Impacket enables attackers to simulate real-world AD attacks like credential dumping, lateral movement, and privilege escalation without deploying agents.

πŸ“– Article: https://www.hackingarticles.in/active-directory-penetration-testing-using-impacket/
Impacket for Pentester – MSSQL Exploitation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

MSSQL servers are high-value targets in internal networks β€” and tools like Impacket make exploitation powerful & flexible πŸ”

πŸ›  In this guide you’ll learn:
πŸ” MSSQL enumeration & access using Impacket
πŸ” Authentication techniques (Windows & SQL)
βš™οΈ Command execution via xp_cmdshell
πŸ“‚ Data extraction & privilege escalation
πŸ”— Linked server exploitation & lateral movement
πŸš€ Real-world pentesting workflows

⚑️ Exploit MSSQL like a pro and level up your internal network attacks.

πŸ“– Read the full guide:
https://www.hackingarticles.in/impacket-for-pentester-mssql-exploitation/
Impacket: SecretsDump for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Impacket’s secretsdump.py allows attackers to extract credentials remotely without deploying any agent, making it a powerful tool for post-exploitation in Active Directory environments.

⚑️ What It Dumps
πŸ” NTLM password hashes
πŸ“‚ SAM & LSA secrets
🎟 Kerberos keys
πŸ“Š NTDS.dit (Domain Controller database)

⚑️ Techniques
🧠 DCSync attack (replicate DC credentials)
πŸ“‘ Remote registry extraction
πŸ’Ύ NTDS.dit dumping via VSS

πŸ’‘ With proper privileges, attackers can dump domain credentials and move laterally across the network without touching disk.

πŸ“– Article: https://www.hackingarticles.in/imapacket-for-pentester-secretdump/
Impacket: Change Password Abuse

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Misconfigured AD permissions like ForceChangePassword allow attackers to reset a user’s password without knowing the originalβ€”leading to account takeover and privilege escalation.

⚑️ Attack Highlights
πŸ” Reset user password without old credentials
πŸ‘€ Target privileged accounts
πŸš€ Privilege escalation & lateral movement
πŸ“‘ Abuse SMB/RPC protocols

⚑️ Tool
πŸ›  impacket-changepasswd

πŸ’‘ Attackers can abuse delegated rights to gain control over other accounts, making weak AD permission management a critical security risk.

πŸ“– Article: https://www.hackingarticles.in/impacket-for-pentester-change-password/
Impacket DACLedit: Active Directory Privilege Escalation πŸ”₯

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Impacket-dacledit is a powerful tool used to modify Active Directory DACLs, allowing attackers to abuse permissions like WriteDACL, WriteOwner, and FullControl to escalate privileges and take over domain objects.

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
🧠 Understanding AD ACL & DACL
πŸ”Ž Enumerating Object Permissions
⚑️ WriteDACL Abuse using dacledit
πŸ”‘ Granting FullControl over Users/Groups
πŸ‘₯ Adding User to Domain Admins
πŸ’» WriteOwner Abuse & Ownership Takeover
πŸ”„ Reset Password without Knowing Current
πŸ“‘ Privilege Escalation using DACL Misconfigurations
πŸ›  Post-Exploitation with Impacket Tools

πŸ‘‰ Abuse of DACL permissions can lead to full domain compromise if misconfigured and not monitored properly.

πŸ“– Article:
https://www.hackingarticles.in/impacket-for-pentester-dacledit/
Impacket for Pentester – PsExec Exploitation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Gaining remote command execution is a key step in internal pentesting β€” and Impacket PsExec makes it powerful ⚑️

πŸ›  In this guide you’ll learn:
πŸ” Remote command execution via SMB
βš™οΈ Using psexec.py for interactive shells
πŸ”‘ Pass-the-Hash authentication techniques
πŸ“‚ Upload & execute payloads on target
πŸ”— Lateral movement across network
πŸš€ Real-world attack scenarios

⚑️ Turn credentials into full system access and move like a pro inside networks.

πŸ“– Read the full guide:
https://www.hackingarticles.in/impacket-for-pentester-psexec/
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) πŸš€
Level up your penetration testing skills with real exam-like scenarios & hands-on labs. Perfect for OSCP+ aspirants, CTF players & security pros.
🎯 Learn: Priv Esc β€’ AD Attacks β€’ Pivoting β€’ Web Exploitation β€’ Report Writing
πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1
⚑️ Limited seats – Train smart. Hack ethically.
❀2
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀4
πŸš€ Active Directory Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
πŸ”₯1
πŸ”΄ Active Directory Attack Architecture – Visualized Like Never Before

If you’re into Red Teaming / AD Exploitation, this is πŸ”₯

This interactive map breaks down how attackers move from initial access ➝ domain dominance using real-world techniques.

πŸ’‘ Why it matters:
Modern cyber attacks don’t happen in one step β€” they follow structured paths like reconnaissance, exploitation, lateral movement, and privilege escalation ()

🎯 What you’ll learn:
β€’ Attack paths inside AD
β€’ Privilege escalation chains
β€’ Lateral movement techniques
β€’ Real attacker mindset

🧠 Think like an attacker β†’ defend like a pro

πŸ”— Explore here: https://kypvas.github.io/ad_attack_architecture/

#cybersecurity #redteam #activedirectory #pentesting #infosec #ethicalhacking #mitreattack #oscp
❀1
πŸ”΄ File Upload Bypass Cheat Sheet (Extension Splitting)

If you're testing file upload functionality, this is pure gold πŸ”₯

Attackers don’t just upload shell.php… they play with encoding, null bytes, separators, and edge-case parsing tricks to bypass filters.

πŸ’‘ Common tricks:
β€’ Double extensions (.php.png)
β€’ Encoded characters (%0a, %00, %23)
β€’ Unicode bypasses
β€’ Special chars & separators
β€’ Tabs / Newlines injection

🎯 Lesson:
If your validation relies ONLY on extension checks β†’ it's already broken.

🧠 Think like an attacker. Validate like a defender.
πŸ”΅ Governance, Risk & Compliance (GRC) – Simplified

Most people think GRC is just policies… it’s not.
It’s a complete system that connects risk, compliance, audits, and decision-making.

πŸ“Š This visual breaks it down into:
β€’ Compliance β†’ tracking obligations & remediation
β€’ Control Management β†’ mapping risks to controls
β€’ Governance β†’ decision-making & accountability (RACI)
β€’ ERM β†’ managing enterprise risks
β€’ Incident & Issue β†’ tracking and closing gaps
β€’ Internal Audit β†’ evidence, findings, and coverage
β€’ KPI/KRI β†’ measuring risk & performance

πŸ’‘ Reality:
If your GRC is in scattered Excel sheets β†’ you don’t have GRC, you have chaos.

🧠 Strong GRC = Better security + Better business decisions
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
πŸ”₯4❀2
A Detailed Guide on Ligolo-Ng

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Ligolo-Ng is a modern tunneling and pivoting tool used by penetration testers to perform lateral movement and access internal network services through compromised machines. It enables secure communication channels between attacker and target systems.

πŸ“š What You’ll Learn in This Guide

βš™οΈ Introduction to Ligolo-Ng
🧰 Installation & Setup
πŸ–₯ Ligolo-Ng Server Configuration
πŸ’» Ligolo-Ng Agent Setup
🌐 Creating Tunnels
πŸ” Network Pivoting
πŸ“‘ Accessing Internal Services
πŸ§ͺ Scanning Internal Network through Tunnel

πŸ“– Article:
https://www.hackingarticles.in/a-detailed-guide-on-ligolo-ng/
πŸ₯°4
Path Traversal (Directory Traversal): Complete Guide for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Path Traversal is a critical web vulnerability that allows attackers to access files outside the web root by manipulating file path inputs (e.g., ../).

πŸ“˜ Introduction to Path Traversal
❓ How Path Traversal Works
πŸ”£ Traversal Sequences (../, encoding, bypasses)
πŸ“‚ Types of Path Traversal Attacks
πŸ’₯ Impact (Sensitive File Disclosure)
🧭 Steps to Exploit – Path Traversal
πŸ›  Linux Exploitation Techniques
πŸ“Ÿ Basic Path Traversal
🚫 Blocked Traversal Sequences
πŸ” Validation & Bypass Techniques
πŸ” URL Encoding & Double Encoding
🧩 Path Disclosure in URL
πŸ’£ Null Byte Bypass
πŸͺŸ Windows Exploitation Techniques
πŸ”€ Forward & Backward Slash Bypass
πŸ“ Accessing Sensitive Files (win.ini)
πŸ›‘ Mitigation & Secure Coding Practices

⚑️ Improper input validation can expose critical system files like /etc/passwd, credentials, and application source code.

πŸ”— Read Full Guide: https://hackingarticles.in/comprehensive-guide-on-path-traversal/
❀3
Remote File Inclusion (RFI): Complete Guide for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Remote File Inclusion (RFI) is a critical web vulnerability where attackers include malicious files hosted on remote servers into vulnerable applications, leading to remote code execution. ()

πŸ“˜ Introduction to RFI
❓ Why Remote File Inclusion Occurs
πŸ”— Difference Between LFI & RFI
πŸ“‚ Remote File Inclusion Exploitation
πŸ“Ÿ Basic RFI Attack
🐚 Reverse Shell via Netcat
🎯 RFI using Metasploit
🚫 Bypass Blacklist Implementations
πŸ’£ Null Byte Attack
πŸ–§ Exploitation via SMB Server
βš™οΈ PHP Misconfigurations (allow_url_include)
πŸ›‘ Mitigation Techniques

⚑️ RFI can lead to full server compromise, remote command execution, data theft, and web defacement if input validation is not properly implemented.

πŸ”— Read Full Guide: https://hackingarticles.in/comprehensive-guide-on-remote-file-inclusion-rfi/
❀2
Unrestricted File Upload: Complete Guide for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Unrestricted File Upload is a critical vulnerability where attackers upload malicious files (web shells, scripts) due to improper validation, leading to remote code execution and server compromise. ()

πŸ“˜ Introduction to Unrestricted File Upload
❓ How File Upload Vulnerability Occurs
πŸ“‚ File Upload Exploitation
πŸ“Ÿ Basic File Upload
πŸ§ͺ Content-Type Restriction Bypass
🧬 Double Extension Attack
πŸ“ Image Size Validation Bypass
🚫 Blacklisted Extension Bypass
βš™οΈ Server Misconfiguration Issues
πŸ’₯ Impact of Unrestricted File Upload
πŸ›  Gaining Reverse Shell via Upload
🎯 Exploitation using Metasploit
πŸ›‘ Mitigation Techniques

⚑️ Improper validation allows attackers to upload malicious files, leading to full server takeover, data exposure, defacement, and backdoor access.

πŸ”— Read Full Guide: https://hackingarticles.in/comprehensive-guide-on-unrestricted-file-upload/
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€