Hacking Articles
20.8K subscribers
1.12K photos
165 files
771 links
House of Pentester
Download Telegram
πŸ“‘ Nmap for Pentester: Host Discovery

πŸ”₯ Telegram: https://t.me/hackinarticles

Host Discovery is the first step in network reconnaissance. It helps pentesters identify which systems are alive in a network before performing deeper scans like port scanning or service enumeration.

⚑️ Techniques covered:

πŸ“‘ Ping Sweep (-sn)
🀝 TCP SYN Ping (-PS)
πŸ“© TCP ACK Ping (-PA)
πŸ“¨ ICMP Echo Ping (-PE)
πŸ“¦ UDP Ping (-PU)
🌐 IP Protocol Ping (-PO)
πŸ–§ ARP Ping (-PR)
🚫 No Ping Scan (-Pn)

🎯 These techniques help pentesters identify live hosts, bypass firewall restrictions, and improve target discovery during information gathering.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-host-discovery/
❀4
πŸ”΅ Blue Teaming Active Directory: EvenMonitor

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Attackers target AD… defenders must monitor EVERYTHING ⚠️

⚑️ Defense Highlights
πŸ” Monitor AD events & suspicious logins
πŸ“Š Track user/group/permission changes
🚨 Detect privilege escalation & lateral movement
🧠 Identify abnormal behavior patterns
πŸ›‘ Improve visibility across domain

πŸ’‘ Active Directory monitoring = continuous tracking of accounts, permissions & activities to detect threats early

⚠️ Without proper monitoring β†’ attacks stay invisible until domain compromise

πŸ“– Article: https://www.hackingarticles.in/blue-teaming-active-directory-evenmonitor/
❀2
Active Directory Pentesting with BloodyAD 🩸

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

BloodyAD is a powerful Active Directory exploitation tool used to abuse AD permissions (DACLs) for privilege escalation, persistence, and domain compromise. It enables attackers to manipulate objects, reset passwords, and gain full control over the domain.

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
πŸ”Ž Understanding AD ACL & DACL Abuse
🧠 BloodHound Path Analysis
πŸ” Authentication (Password / Hash / Kerberos)
πŸ‘₯ Add User to Privileged Groups
πŸ”‘ Reset Password & Takeover Accounts
⚑️ GenericAll / GenericWrite Abuse
πŸ›  WriteDACL & WriteOwner Exploitation
πŸ“‘ Resource-Based Constrained Delegation (RBCD)
🐚 Shadow Credentials Attack
🎯 Privilege Escalation to Domain Admin

πŸ“– Article:
https://www.hackingarticles.in/active-directory-penetration-testing-with-bloodyad/
❀2
Active Directory User Enumeration: Complete Guide 🧠

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

User Enumeration is the foundation of every Active Directory attack. It helps attackers map users, privileges, and misconfigurations to identify attack paths.

⚑️ Key Features of User Enumeration
πŸ” Enumerate all domain users (PowerView, pywerview)
🧩 Extract user attributes & group memberships
βš™οΈ Identify privileged & admin accounts
πŸ›‘ Discover SPN users (Kerberoasting targets)
πŸ“‘ Analyze login activity & password metadata

🎯 Enumeration Insights
πŸ’₯ Find Domain Admin & high-value targets
πŸ§ͺ Detect weak password practices
🧬 Identify Kerberoastable accounts
🌐 Discover delegation & ACL misconfigs
⚑️ Map attack paths for privilege escalation

πŸ“– Article: https://www.hackingarticles.in/active-directory-user-enumeration-a-comprehensive-guide/
❀5πŸ‘2
πŸ”΄ NetExec for OSCP & AD Pentesting: Complete Guide

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

NetExec is becoming the go-to tool for Active Directory enumeration, credential attacks & post-exploitation ⚑️

⚑️ What You’ll Learn
πŸ” SMB, LDAP & WinRM enumeration
πŸ”‘ Password spraying & credential validation
🎯 Kerberoasting & AS-REP Roasting
🩸 BloodHound data collection
πŸ“‚ LAPS & shares enumeration
πŸš€ Remote command execution & lateral movement
βš”οΈ AD exploitation techniques for OSCP labs

πŸ’‘ NetExec combines the power of CrackMapExec with modern modules, better performance & streamlined AD operations πŸ”₯

⚠️ One tool can uncover the entire attack surface of Active Directory

πŸ“– Article: https://www.hackingarticles.in/netexec-for-oscp-ad-pentesting/
πŸ‘2
Windows Privilege Escalation: Bypass UAC

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

User Account Control (UAC) is designed to prevent unauthorized administrative actions, but attackers often abuse trusted Windows components to bypass UAC and gain elevated privileges without triggering security prompts.

πŸ“š What You’ll Learn in This Guide

πŸͺŸ Understanding User Account Control (UAC)
πŸ” Identifying Current Privilege Levels
βš™οΈ UAC Bypass Techniques & Attack Surface
πŸ’» Registry-Based UAC Bypass Methods
πŸš€ Bypassing UAC with fodhelper.exe
πŸ”‘ UAC Bypass Using ComputerDefaults.exe
🐚 Gaining Elevated Shell Access
πŸ›  Using Metasploit for UAC Bypass
πŸ“‹ Verifying High-Integrity Sessions
🧠 Understanding Auto-Elevating Windows Binaries
πŸ›‘ Detection & Monitoring Strategies
⚠️ UAC Hardening & Mitigation Techniques

πŸ“– Article:
https://www.hackingarticles.in/windows-privilege-escalation-bypass-uac/
πŸ‘3πŸ”₯3
Linux Privilege Escalation Using Misconfigured NFS

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Misconfigured NFS shares can become a direct path to root access on Linux systems ⚠️

πŸ“š What You'll Learn in This Guide

πŸ” Understanding NFS & Network File Sharing
πŸ“‹ Enumerating NFS Exports and Permissions
βš™οΈ Identifying Dangerous NFS Configurations
🚨 Exploiting no_root_squash Misconfigurations
πŸ“‚ Mounting Remote NFS Shares
πŸ›  Creating and Deploying SUID Binaries
🐚 Gaining Root Access via NFS Abuse
πŸ”‘ Privilege Escalation Walkthrough
🧠 Enumeration & Post-Exploitation Techniques
πŸ›‘ Securing NFS Shares and Permissions
⚠️ Detection & Mitigation Best Practices

πŸ’‘ NFS misconfigurations, especially the no_root_squash option, can allow attackers to create privileged files on shared directories and escalate privileges to root on Linux systems.

πŸ“– Article:
https://www.hackingarticles.in/linux-privilege-escalation-using-misconfigured-nfs/
🚨 Windows Privilege Escalation: SeImpersonatePrivilege

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SeImpersonatePrivilege is a powerful Windows privilege that allows a user or service to impersonate another user after authentication, often leading to SYSTEM-level access if abused. ()

πŸ“˜ Introduction to SeImpersonatePrivilege
❓ What is β€œImpersonate a Client After Authentication”
βš™οΈ Lab Setup (IIS Server on Windows Server)
πŸ“‚ Gaining Initial Access via File Upload
πŸ“Ÿ Web Shell Upload & Command Execution
πŸ” Enumerating Privileges (whoami /priv)
πŸ§ͺ Identifying SeImpersonatePrivilege
πŸ’£ Exploitation using PrintSpoofer
🎯 Escalating to NT AUTHORITY\SYSTEM
πŸ›  Alternative Exploits (JuicyPotato, RoguePotato)

⚑️ If this privilege is enabled, attackers can impersonate privileged tokens and escalate to SYSTEM, resulting in full control over the machine. ()

πŸ”— Read Full Guide: https://hackingarticles.in/windows-privilege-escalation-seimpersonateprivilege/
🀯1
🚨 Windows Privilege Escalation: SeBackupPrivilege

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SeBackupPrivilege allows users to bypass file ACLs and read any file on the system, making it a powerful vector for privilege escalation after initial access.

⚑️ Attack Highlights
πŸ“‚ Read sensitive files (SAM, SYSTEM, NTDS.dit)
πŸ” Bypass file permission restrictions
🧠 Extract NTLM hashes
πŸš€ Escalate to Administrator / SYSTEM

πŸ“˜ Lab Workflow
βš™οΈ Setup privilege on Windows & DC
πŸ§ͺ Verify using whoami /priv
πŸ’₯ Dump SAM & SYSTEM hives
🎯 Extract hashes & escalate access

πŸ’‘ Since this privilege grants full read access, attackers can dump credential files and reuse hashes to gain elevated access across the system or domain.

πŸ“– Article: https://www.hackingarticles.in/windows-privilege-escalation-sebackupprivilege/
🚨 Windows Privilege Escalation: Insecure GUI Application

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Insecure GUI Applications can lead to privilege escalation when misconfigured apps run with higher privileges and allow execution of system commands. ()

πŸ“˜ Introduction to Insecure GUI Applications
❓ How Misconfigured GUI Apps Lead to Privilege Escalation
πŸ–₯ Applications Running as Administrator
βš™οΈ Lab Setup (Windows + Vulnerable Application)
πŸ“‚ Identifying High-Privilege Applications
πŸ” Enumerating Running Processes (tasklist /V)
πŸ›  Abusing GUI Application Features
πŸ“Ÿ Using β€œOpen File” Functionality
πŸ’£ Spawning cmd.exe with Elevated Privileges
πŸ‘€ Creating New Admin Users via Elevated Shell
⚑️ Privilege Comparison (User vs Application)

⚑️ If a GUI app runs with admin rights and allows file execution, attackers can break out to a privileged shell, leading to full system compromise. ()

πŸ”— Read Full Guide: https://hackingarticles.in/windows-privilege-escalation-insecure-gui-application/
❀4
Windows Privilege Escalation: Scheduled Task/Job (T1573.005)

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

An attacker can exploit Windows Task Scheduler to maintain persistence and escalate privileges by scheduling malicious programs to run at startup or specified intervals under a chosen user context.

πŸ“… Task Scheduler
πŸ›  Misconfigured Scheduled Task/Job
🧰 Prerequisite
πŸ§ͺ Lab Setup
βš™οΈ Abusing Scheduled Task/Job
πŸ” Detection
πŸ›‘ Mitigation

πŸ“– Article: https://www.hackingarticles.in/windows-privilege-escalation-scheduled-task-job-t1573-005/
❀1
Most OSCP students waste months watching random tutorials.

What actually matters?
πŸ‘‰ Methodology
πŸ‘‰ Enumeration
πŸ‘‰ Privilege Escalation
πŸ‘‰ Active Directory Attacks

🚨 OSCP Training – Admissions Open 🚨

Learn through practical labs & real-world attack scenarios:

πŸ”“ Windows & Linux PrivEsc
🌐 Web Application Attacks
🏰 Active Directory Exploitation
🧠 Pivoting & Tunneling
🧬 Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Report Writing

βœ… Hands-On Training
βœ… OSCP-Focused Approach
βœ… Beginner to Advanced Guidance

πŸ”₯ Limited Seats Available

πŸ”— Register:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in
❀3πŸ‘1