Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
πŸ”₯ OSCP+/CTF Exam Practice Training (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join IGNITE TECHNOLOGIES’ exclusive "Capture the Flag" Training Program and enhance your skills with the following modules:

🧠 Introduction
🌐 Information Gathering
🧱 Vulnerability Scanning
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘οΈ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks
🧠 Tunneling & Pivoting
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits
πŸ“‹ Report Writing

#infosec #cybersecurity #cybersecuritytips #microsoft #AI #informationsecurity #CyberSec #microsoft #offensivesecurity #infosecurity #cyberattacks #security #oscp #cybersecurityawareness #bugbounty #bugbountytips
πŸ” [Day 2] ADCS Exploitation: ESC2


ESC2 involves misconfigured certificate templates permitting enrollment for any purpose, enabling unauthorized authentication or code signing.

πŸ“Œ Key Points:

Risk: Templates with Any Purpose (OID 2.5.29.37.0) or SubCA (OID 2.5.29.19.20) allow misuse.

Exploitation: Attackers obtain certificates for unintended purposes (e.g., domain persistence).

Mitigation: Restrict templates to specific OIDs and enforce least-privilege enrollment.

πŸ“– Reference: ESC2 Technical Breakdown


Next: ESC3 – Agent certificate abuse.
πŸ” GMSA Password Attack: Exploiting Group Managed Service Accounts

Learn to extract & abuse GMSA passwords for AD privilege escalation:

βœ” Retrieve hashes using PowerShell & Mimikatz

βœ” Crack passwords & escalate privileges

βœ” Bypass restrictions via gMSAPassword exploitation

πŸ”§ Key Techniques:

β€’ Get-ADServiceAccount hash extraction

β€’ DSInternals hash conversion

β€’ Kerberos ticket abuse

πŸ“– Full Guide: Read Here
❀1
❀1
πŸ”₯Active Directory Red Team Ops Webinar (Free)πŸ”₯


We’re hosting a free 3-hour live webinar on Active Directory Red Team Operations, designed for professionals interested in real-world attack techniques used against enterprise AD environments.

πŸ—“οΈ Date: 15th June 2025
πŸ•’ Time: 6:00 PM IST to 9 PM IST

What you’ll learn
* MITRE-mapped AD attack paths
* Live demos: Kerberoasting & ACL-based privilege escalation
* Common misconfigurations exploited by attackers
* Red Teaming career roadmap & practical learning paths

πŸŽ“ Ideal for: Red Teamers, Blue Teamers, OSCP aspirants, and security engineers.

We’ll also unveil:
* 3-Weekend AD Workshop – β‚Ή14,999
* 2.5-Month Advanced Course – β‚Ή36,999

πŸ“Œ Join here to register and get webinar details:
πŸ‘‰ https://chat.whatsapp.com/HWKRCQtcIiY27YXbk3BGKU

Feel free to message me if you have any questions.

Best Regards,
Ignite Technologies
❀2
Best of SQL Injection
How to set up SQLI Lab in Kali
https://www.hackingarticles.in/set-sqli-lab-kali/
Beginner’s Guide to SQL Injection (Part 1)
https://www.hackingarticles.in/beginner-guide-sql-injection-part-1/
Beginner Guide to SQL Injection Boolean Based (Part 2)
https://www.hackingarticles.in/beginner-guide-sql-injection-boolean-based-part-2/
How to Bypass SQL Injection Filter Manually
https://www.hackingarticles.in/bypass-filter-sql-injection-manually/
Form Based SQL Injection Manually
https://www.hackingarticles.in/form-based-sql-injection-manually/
Manual SQL Injection Exploitation Step by Step.
https://www.hackingarticles.in/manual-sql-injection-exploitation-step-step/
πŸ‘1