Hacking Articles
23K subscribers
1.36K photos
165 files
971 links
House of Pentester
Download Telegram
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance
πŸ” Cyber Security Training Programs (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Ignite Technologies is excited to announce exclusive online Cyber Security Training Programs with limited seats available. Enroll now to secure your place in the upcoming batch and upskill in real-world offensive security techniques.

πŸš€ Key Learning Areas:
πŸ›‘ Ethical Hacking
🌐 Network Penetration Testing
🐞 Bug Bounty Hunting
πŸ›  Advanced Burp Suite
πŸ“± Android Application Pentesting
🏒 Source Code Review
🎯 CTF Challenges
πŸ•΅οΈ Red Team Operations
πŸ”“ Active Directory Attacks
πŸ’Ύ MSSQL Security Assessment
πŸ”Ό Windows Privilege Escalation
🐧 Linux Privilege Escalation

πŸ’‘ Hands-on, practical, and industry-focused training designed for aspiring and working cybersecurity professionals.
❀3
Active Directory Penetration Testing Using Impacket

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Impacket is a powerful toolkit used to perform enumeration, exploitation, and post-exploitation in Active Directory environments.

⚑️ Attack Highlights
πŸ” Enumerate users, SIDs & computers (lookupsid, GetADUsers)
🎯 Perform Kerberos attacks (AS-REP Roasting, Kerberoasting)
πŸ” Abuse delegation (RBCD) for privilege escalation
🎟 Dump credentials (DCSync, LAPS, GMSA)
πŸ’‰ Execute remote commands (psexec, wmiexec)
πŸš€ Achieve Domain Admin access

πŸ’‘ Impacket enables attackers to simulate real-world AD attacks like credential dumping, lateral movement, and privilege escalation without deploying agents.

πŸ“– Article: https://www.hackingarticles.in/active-directory-penetration-testing-using-impacket/
Impacket for Pentester – MSSQL Exploitation

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

MSSQL servers are high-value targets in internal networks β€” and tools like Impacket make exploitation powerful & flexible πŸ”

πŸ›  In this guide you’ll learn:
πŸ” MSSQL enumeration & access using Impacket
πŸ” Authentication techniques (Windows & SQL)
βš™οΈ Command execution via xp_cmdshell
πŸ“‚ Data extraction & privilege escalation
πŸ”— Linked server exploitation & lateral movement
πŸš€ Real-world pentesting workflows

⚑️ Exploit MSSQL like a pro and level up your internal network attacks.

πŸ“– Read the full guide:
https://www.hackingarticles.in/impacket-for-pentester-mssql-exploitation/
Impacket: SecretsDump for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Impacket’s secretsdump allows attackers to extract credentials remotely without deploying any agent, making it a powerful tool for post-exploitation in Active Directory environments.

⚑️ What It Dumps
πŸ” NTLM password hashes
πŸ“‚ SAM & LSA secrets
🎟 Kerberos keys
πŸ“Š NTDS.dit (Domain Controller database)

⚑️ Techniques
🧠 DCSync attack (replicate DC credentials)
πŸ“‘ Remote registry extraction
πŸ’Ύ NTDS.dit dumping via VSS

πŸ’‘ With proper privileges, attackers can dump domain credentials and move laterally across the network without touching disk.

πŸ“– Article: https://www.hackingarticles.in/imapacket-for-pentester-secretdump/
Impacket: Change Password Abuse

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Misconfigured AD permissions like ForceChangePassword allow attackers to reset a user’s password without knowing the originalβ€”leading to account takeover and privilege escalation.

⚑️ Attack Highlights
πŸ” Reset user password without old credentials
πŸ‘€ Target privileged accounts
πŸš€ Privilege escalation & lateral movement
πŸ“‘ Abuse SMB/RPC protocols

⚑️ Tool
πŸ›  impacket-changepasswd

πŸ’‘ Attackers can abuse delegated rights to gain control over other accounts, making weak AD permission management a critical security risk.

πŸ“– Article: https://www.hackingarticles.in/impacket-for-pentester-change-password/
🎯 Ignite Technologies presents: OSCP Training Program (Online)

A hands-on, exam-focused program that trains you the way real pentesters actually work β€” built for aspirants who want to clear OSCP on the first attempt.

πŸ”₯ What you'll master:
βœ”οΈ Introduction to Exam Strategy & Methodology
βœ”οΈ Information Gathering & Enumeration
βœ”οΈ Vulnerability Scanning & Analysis
βœ”οΈ Windows Privilege Escalation
βœ”οΈ Linux Privilege Escalation
βœ”οΈ Client-Side Attacks
βœ”οΈ Web Application Attacks
βœ”οΈ Password Attacks & Credential Exploitation
βœ”οΈ Tunneling & Pivoting Techniques
βœ”οΈ Active Directory Attacks
βœ”οΈ Exploiting Public Exploits Effectively
βœ”οΈ Professional Report Writing
πŸ’Ž What makes this different:
βœ… Hands-on practical labs
βœ… Realistic attack scenarios
βœ… OSCP-oriented training
βœ… Beginner to advanced guidance
βœ… Industry-focused techniques
πŸ‘¨β€πŸ’» Perfect for:
πŸ”Ή OSCP Aspirants
πŸ”Ή Ethical Hackers
πŸ”Ή Pentesters
πŸ”Ή Red Teamers
πŸ”Ή Cybersecurity Students

πŸ’‘ Why this matters: OSCP isn't just a cert β€” it's a career accelerator. But the 24-hour exam doesn't care how many machines you've rooted on HTB. It rewards the hacker who knows exactly what to enumerate, when to pivot, and how to document it. That's what we train.

πŸ“… Limited seats. Admissions closing soon.

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

πŸ‘‰ Tag an OSCP aspirant who needs to see this.
πŸ’¬ Drop a comment: What's stopping you from booking your OSCP exam?
♻️ Repost to help someone in your network land their dream pentest role.
🎯 Ignite Technologies presents: Bug Bounty Training Program (Online)

A hands-on, exclusive program built for beginners and intermediates ready to break into bug bounty hunting and ethical hacking β€” the right way.

πŸ”₯ What you'll master:
βœ”οΈ Introduction to WAPT & OWASP Top 10
βœ”οΈ Pentest Lab Setup
βœ”οΈ Information Gathering & Reconnaissance
βœ”οΈ Netcat for Pentesters
βœ”οΈ Configuration Management Testing
βœ”οΈ Cryptography
βœ”οΈ Authentication Attacks
βœ”οΈ Session Management Exploitation
βœ”οΈ Local File Inclusion (LFI)
βœ”οΈ Remote File Inclusion (RFI)
βœ”οΈ Path Traversal
βœ”οΈ OS Command Injection
βœ”οΈ Open Redirect
βœ”οΈ Unrestricted File Upload
βœ”οΈ PHP Web Shells
βœ”οΈ HTML Injection
βœ”οΈ Cross-Site Scripting (XSS)
βœ”οΈ Client-Side Request Forgery (CSRF)
βœ”οΈ SQL Injection
βœ”οΈ XXE Injection
βœ”οΈ Bonus Section 🎁

πŸ’‘ Why this matters: Bug bounty isn't just about tools β€” it's about thinking like an attacker. This program walks you through the OWASP Top 10 and beyond, with real exploitation techniques you can apply on live programs (HackerOne, Bugcrowd, Intigriti).

πŸ“… Limited seats. Enroll today.

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

πŸ‘‰ Tag someone who's been talking about getting into bug bounty.
πŸ’¬ Drop a comment: What's the first vulnerability you ever found?
♻️ Repost to help an aspiring hacker in your network.
❀3
πŸ§ͺ Nmap Scans using Hex Value of Flags

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Nmap allows pentesters to manually craft TCP packets using hexadecimal values of TCP flags with the --scanflags option. This technique helps analyze how different TCP flag combinations affect port responses during network enumeration.

⚑️ Scans covered in this guide:

πŸ•³ NULL Scan (0x00)
🏁 FIN Scan (0x01)
🀝 SYN Scan (0x02)
πŸ”„ RST Scan (0x04)
πŸ“€ PSH Scan (0x08)
πŸ“© ACK Scan (0x10)
🚨 URG Scan (0x20)
πŸŽ„ XMAS Scan (0x29)
πŸ§ͺ Custom TCP Flag Combinations

🎯 These techniques help security researchers understand TCP behavior, bypass filtering rules, and perform advanced port enumeration.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-scans-using-hex-value-flags/
❀2
πŸ”₯ Nmap Firewall Scan: Bypassing Firewall Filters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Firewalls can block basic scans… but Nmap offers advanced techniques to evade filtering ⚠️

⚑️ Techniques Covered
πŸ” TCP Connect & SYN Scan Analysis
🎭 FIN / NULL / XMAS Stealth Scans
🧬 IP Option & Packet Manipulation
πŸ›‘ Firewall Rule Bypass Techniques
πŸ“‘ MAC Address Spoofing
🌐 Source IP Spoofing
πŸ§ͺ Custom Data String & Hex Injection
πŸ“Š Wireshark Packet Analysis

πŸ’‘ Understanding packet behavior & TCP flags is critical for both attackers and defenders

⚠️ Misconfigured firewall rules can leak open ports even when standard scans fail

πŸ“– Article: https://www.hackingarticles.in/a-detailed-guide-on-nmap-firewall-scan/
❀1
Nmap for Pentester: Output Format Scan

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

While performing reconnaissance, pentesters often need to save and analyze scan results efficiently. Nmap provides multiple output formats that help in reporting, automation, and log analysis.

⚑️ Output formats covered:

πŸ“„ Normal Output (-oN)
🧾 XML Output (-oX)
πŸ”Ž Grepable Output (-oG)
πŸ“¦ All Formats / Alias (-oA)
πŸ“’ Verbose Mode (-v, -vv)
🐞 Debug Mode (-d)

🎯 These formats help security professionals organize scan results, automate analysis, and integrate Nmap data into other security tools.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-output-format-scan/
❀1
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance
❀3
🚨 Credential Dumping: Applications

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Many applications store credentials, authentication tokens, or configuration secrets locally on a system. Attackers can extract these stored credentials from application files or memory to gain unauthorized access and move laterally across the network. ()

⚑️ Key Applications Targeted for Credential Dumping
🌐 FileZilla
πŸ—„ WinSCP
πŸ’» PuTTY
πŸ“‘ mRemoteNG
πŸ›  OpenVPN
πŸ“‚ Remote Desktop Connection Manager (RDCMan)
🧰 VNC
πŸ” KeePass

πŸ“– Article: https://www.hackingarticles.in/credential-dumping-applications/

#CyberSecurity #EthicalHacking #RedTeam #Pentesting #CredentialDumping #InfoSec #BlueTeam
❀1
Credential Dumping: Clipboard

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Credential Dumping via clipboard is a technique where attackers capture sensitive data (like passwords or tokens) copied by users, exploiting the fact that clipboard data is accessible to applications and can be monitored or extracted.

πŸ“š Topic Covered

πŸ“– Introduction
πŸ“‹ Understanding Clipboard Data Leakage
🧠 How Attackers Monitor Clipboard
πŸ’» Credential Capture via Clipboard
πŸ›  Tools & Techniques for Clipboard Dumping
πŸ” Extracting Sensitive Information
πŸš€ Post-Exploitation Use of Credentials
πŸ›‘ Detection & Mitigation Techniques

πŸ“– Article:
https://hackingarticles.in/credential-dumping-clipboard/

#CyberSecurity #RedTeam #Pentesting #EthicalHacking #CredentialDumping #InfoSec
❀1
Credential Dumping: Domain Cached Credentials

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Domain Cached Credentials (DCC) are stored locally to allow offline authentication. Attackers can dump these cached hashes and crack them offline to recover user credentials.

πŸ“š Topic Covered

πŸ— Domain Cache Credential
πŸ’£ Metasploit
πŸ“¦ Impacket
πŸͺͺ Mimikatz
⚑️ PowerShell Empire
πŸ•΅οΈ Koadic
🐍 Python Script

πŸ“– Article:
https://hackingarticles.in/credential-dumping-domain-cache-credential/

#CyberSecurity #RedTeam #Pentesting #EthicalHacking #CredentialDumping #ActiveDirectory #InfoSec
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€

#CyberSecurity #InfoSec #EthicalHacking #RedTeam #PenetrationTesting #CloudSecurity #OSCP #OSEP #ActiveDirectory #SecurityTraining #CyberSecurityTraining
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance
πŸ’° Companies paid out over $300M in bug bounties last year β€” and the demand is only growing.

From Google to the Pentagon, ethical hackers are getting rewarded for finding what others miss. But here's the truth: most aspiring bounty hunters fail not because they lack curiosity β€” they lack a structured roadmap.

🎯 Ignite Technologies presents: Bug Bounty Training Program (Online)

A hands-on, exclusive program built for beginners and intermediates ready to break into bug bounty hunting and ethical hacking β€” the right way.

πŸ”₯ What you'll master:
βœ”οΈ Introduction to WAPT & OWASP Top 10
βœ”οΈ Pentest Lab Setup
βœ”οΈ Information Gathering & Reconnaissance
βœ”οΈ Netcat for Pentesters
βœ”οΈ Configuration Management Testing
βœ”οΈ Cryptography
βœ”οΈ Authentication Attacks
βœ”οΈ Session Management Exploitation
βœ”οΈ Local File Inclusion (LFI)
βœ”οΈ Remote File Inclusion (RFI)
βœ”οΈ Path Traversal
βœ”οΈ OS Command Injection
βœ”οΈ Open Redirect
βœ”οΈ Unrestricted File Upload
βœ”οΈ PHP Web Shells
βœ”οΈ HTML Injection
βœ”οΈ Cross-Site Scripting (XSS)
βœ”οΈ Client-Side Request Forgery (CSRF)
βœ”οΈ SQL Injection
βœ”οΈ XXE Injection
βœ”οΈ Bonus Section 🎁

πŸ’‘ Why this matters: Bug bounty isn't just about tools β€” it's about thinking like an attacker. This program walks you through the OWASP Top 10 and beyond, with real exploitation techniques you can apply on live programs (HackerOne, Bugcrowd, Intigriti).

πŸ“… Limited seats. Enroll today.

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

πŸ‘‰ Tag someone who's been talking about getting into bug bounty.
πŸ’¬ Drop a comment: What's the first vulnerability you ever found?
♻️ Repost to help an aspiring hacker in your network.
❀1πŸ‘1
Lateral Movement: Pass-the-Hash Attack πŸ”₯

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Pass-the-Hash (PtH) is a powerful lateral movement technique where attackers use NTLM hashes instead of plaintext passwords to authenticate and access systems within a network. It allows attackers to move across machines without cracking credentials.

πŸ“š Topics Covered

πŸ” NTLM Authentication
πŸ“‚ Credential Dumping (SAM, NTDS, LSASS)
⚑️ Hash Authentication Technique
🧠 Working of PtH (Extract & Pass Hash)
πŸ“‘ Lateral Movement via SMB, WMI, RPC
πŸ›  Tools: Mimikatz, Impacket, CrackMapExec
🚨 Detection Techniques
πŸ›‘ Mitigation Strategies

🧠 Read More:
https://www.hackingarticles.in/lateral-movement-pass-the-hash-attack/
Active Directory Pentesting with BloodyAD 🩸

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

BloodyAD is a powerful Active Directory exploitation tool used to abuse AD permissions (DACLs) for privilege escalation, persistence, and domain compromise. It enables attackers to manipulate objects, reset passwords, and gain full control over the domain.

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
πŸ”Ž Understanding AD ACL & DACL Abuse
🧠 BloodHound Path Analysis
πŸ” Authentication (Password / Hash / Kerberos)
πŸ‘₯ Add User to Privileged Groups
πŸ”‘ Reset Password & Takeover Accounts
⚑️ GenericAll / GenericWrite Abuse
πŸ›  WriteDACL & WriteOwner Exploitation
πŸ“‘ Resource-Based Constrained Delegation (RBCD)
🐚 Shadow Credentials Attack
🎯 Privilege Escalation to Domain Admin

πŸ“– Article:
https://www.hackingarticles.in/active-directory-penetration-testing-with-bloodyad/
Active Directory Enumeration: Ldeep

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Ldeep is a lightweight LDAP-based post-exploitation enumeration tool used in Active Directory to extract users, groups, computers, delegation settings, and misconfigurations after gaining authenticated access.

πŸ“š Topic Covered

πŸ“– Overview of Ldeep
βš™οΈ Setup & Configuration
πŸ” Enumerating Computer Objects
🧠 Enumerating AD Metadata (conf)
πŸ” Delegation Enumeration
πŸ— gMSA Credential Enumeration
πŸ“‚ GPO Enumeration
πŸ‘₯ Group Enumeration
πŸ–₯ Machine Enumeration
🏒 OU Enumeration
πŸ“œ ADCS / Certificate Services Enumeration
🧬 Schema Enumeration
πŸ‘€ User Enumeration
⚑️ Kerberos Pre-Auth Enumeration (AS-REP Roast)
🎟 SPN Enumeration (Kerberoasting)
πŸ‘‘ Domain Admin Enumeration
πŸ”Ž Extracting User Attributes (userPassword)
βž• Machine Account Creation
βž• User Account Creation
πŸ”“ Account Unlock & Privilege Abuse

πŸ“– Article:
https://hackingarticles.in/active-directory-enumeration-ldeep/