Hacking Articles
23K subscribers
1.37K photos
165 files
976 links
House of Pentester
Download Telegram
Impacket: Change Password Abuse

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Misconfigured AD permissions like ForceChangePassword allow attackers to reset a user’s password without knowing the originalβ€”leading to account takeover and privilege escalation.

⚑️ Attack Highlights
πŸ” Reset user password without old credentials
πŸ‘€ Target privileged accounts
πŸš€ Privilege escalation & lateral movement
πŸ“‘ Abuse SMB/RPC protocols

⚑️ Tool
πŸ›  impacket-changepasswd

πŸ’‘ Attackers can abuse delegated rights to gain control over other accounts, making weak AD permission management a critical security risk.

πŸ“– Article: https://www.hackingarticles.in/impacket-for-pentester-change-password/
Impacket DACLedit: Active Directory Privilege Escalation πŸ”₯

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Impacket-dacledit is a powerful tool used to modify Active Directory DACLs, allowing attackers to abuse permissions like WriteDACL, WriteOwner, and FullControl to escalate privileges and take over domain objects.

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
🧠 Understanding AD ACL & DACL
πŸ”Ž Enumerating Object Permissions
⚑️ WriteDACL Abuse using dacledit
πŸ”‘ Granting FullControl over Users/Groups
πŸ‘₯ Adding User to Domain Admins
πŸ’» WriteOwner Abuse & Ownership Takeover
πŸ”„ Reset Password without Knowing Current
πŸ“‘ Privilege Escalation using DACL Misconfigurations
πŸ›  Post-Exploitation with Impacket Tools

πŸ‘‰ Abuse of DACL permissions can lead to full domain compromise if misconfigured and not monitored properly.

πŸ“– Article:
https://www.hackingarticles.in/impacket-for-pentester-dacledit/
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.
❀5
πŸ”₯ Arsenal-NG: The Ultimate Pentest Cheat Sheet

From enumeration to exploitation, Arsenal-NG generates commands on demand, helping security professionals save time during assessments. ⚠️

πŸ“š In This Guide

πŸ€– Introduction to Arsenal-NG
βš™οΈ Installing Arsenal-NG
πŸ” Generating Reconnaissance Commands
🌐 Network Enumeration Made Easy
πŸ›  Web Application Testing Commands
🎯 Active Directory Assessment Workflows
πŸ”‘ Credential Attack Command Generation
πŸ“‘ Service Enumeration Techniques
🐧 Linux & Windows Pentesting Commands
πŸš€ Red Team & Post-Exploitation Use Cases
🧠 AI-Assisted Command Generation
πŸ“‹ Practical Pentesting Cheat Sheet Examples

πŸ’‘ Why remember every Nmap, NetExec, CrackMapExec, Impacket, BloodHound, or Metasploit command when you can generate them instantly? Arsenal-NG acts as a smart command assistant, helping pentesters quickly find the right syntax and workflow during authorized security assessments.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/arsenal-ng-pentest-cheat-sheet/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀6πŸ‘1
πŸ”₯ Active Directory Enumeration with BloodHound Python

BloodHound Python transforms raw Active Directory data into a visual attack graph, helping security teams identify privilege escalation paths, dangerous permissions, and hidden relationships. ⚠️

πŸ“š In This Guide

🐍 Introduction to BloodHound Python
βš™οΈ Installing BloodHound & Dependencies
🌐 LDAP-Based Data Collection from Kali Linux
πŸ” Enumerating Users, Groups & Computers
πŸ‘₯ Mapping Active Directory Relationships
🩸 Collecting Data with BloodHound Python
πŸ“Š Importing Results into BloodHound CE
🎯 Finding Paths to Domain Admin
πŸ”‘ Identifying DCSync Privileges
πŸš€ Discovering Kerberoastable & AS-REP Roastable Accounts
πŸ›  Analyzing ACL Abuse Paths
🧠 Prioritizing High-Value Targets
πŸ›‘ Detection & Defensive Insights

πŸ’‘ Attackers don't compromise domains by guessing.

They follow relationships, permissions, delegated rights, and trust paths. BloodHound turns thousands of AD objects into a visual roadmap that helps uncover the shortest path to privilege escalation.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/active-directory-enumeration-with-bloodhound-python/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
πŸ”₯ Impacket for Pentester: Atexec

Need remote command execution without creating a service? Atexec leverages Windows Task Scheduler to execute commands remotely, making it a valuable technique for lateral movement assessments in Active Directory environments. ⚠️

πŸ“š In This Guide

⏰ Understanding Atexec & Task Scheduler
βš™οΈ Installing & Configuring Impacket
πŸ”‘ Authentication with Passwords, NTLM Hashes & Kerberos
🌐 Remote Command Execution over SMB
πŸ“‹ Running Single Commands on Remote Hosts
πŸ–₯ Interactive Execution Workflows
🎯 Lateral Movement in Active Directory
πŸ”„ Comparing Atexec vs PsExec vs WMIExec
πŸ“Š Understanding Windows Scheduled Task Artifacts
🧠 Detection & DFIR Considerations
πŸ›‘ Hardening Remote Administration Paths
⚠️ Monitoring Scheduled Task Abuse

πŸ’‘ Unlike PsExec, Atexec executes commands through the Windows Task Scheduler service instead of creating a temporary service. Understanding how different Impacket execution methods work helps security teams assess, detect, and defend against unauthorized remote administration activity.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/impacket-for-pentester-atexec/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀1
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.
❀3