Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
πŸ”₯ OSCP+/CTF Exam Practice Training (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join IGNITE TECHNOLOGIES’ exclusive "Capture the Flag" Training Program and enhance your skills with the following modules:

🧠 Introduction
🌐 Information Gathering
🧱 Vulnerability Scanning
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘οΈ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks
🧠 Tunneling & Pivoting
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits
πŸ“‹ Report Writing

#infosec #cybersecurity #cybersecuritytips #microsoft #AI #informationsecurity #CyberSec #microsoft #offensivesecurity #infosecurity #cyberattacks #security #oscp #cybersecurityawareness #bugbounty #bugbountytips
❀2⚑1πŸ”₯1
πŸ“± Android Application Framework: Beginner’s Guide

Dive into the core architecture of Android with this detailed guide. Essential for developers and security researchers.

πŸ”— Read the full article: hackingarticles.in
❀4
πŸ” Credential Dumping: Windows Autologon Password

Attackers often target stored AutoLogon credentials to escalate access. Learn how this technique works and how to defend against it:

βœ” Method: Extracts plaintext passwords from the Registry (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon).

βœ” Tools Used: Mimikatz, PowerShell, or manual registry queries.

βœ” Impact: Compromises domain/logon persistence.

βœ” Mitigation: Disable AutoLogon or use LSA protection.


πŸ“– Read the guide: hackingarticles.in
❀5
MSSQL for Pentester Command Execution with xp_cmdshell.pdf
4 MB
πŸ” MSSQL Pentesting: Command Execution via xp_cmdshell


This guide covers practical exploitation of MSSQL Server using xp_cmdshell:

Enabling xp_cmdshell (GUI, sqsh, impactet-mssqlclient)

Reverse shell methods: .hta, netcat, Python, nxc, crackmapexec, Metasploit

PowerUPSQL for command execution


πŸ”” Turn on notifications for more hacking writeups!
πŸ”₯4❀1
abusing trustworthy.pdf
2.1 MB
New Article Alert!
Title: Abusing Trustworthy Property in MSSQL
Description: Introduction to Trustworthy Property:
Understand the importance of trustworthy property in MSSQL for database security.
Lab Setup: Learn to set up a lab to demonstrate trustworthy property abuse.
Abusing Trustworthy Property: Discover exploitation methods, including manual tactics and remote exploitation with PowerUpSQL and Metasploit. Practical Examples: View examples of trustworthy property abuse, including code snippets and screenshots.
❀2
Password Cracking: FTP

Gaining initial access through an open FTP port is a common and effective technique in penetration testing.

βœ… Hydra
πŸ› οΈ Metasploit
πŸ’£ Medusa
🧰 NetExec (nxc)
πŸ”“ Ncrack
βš™οΈ Patator
πŸ“‚ Nmap NSE Script (ftp-brute.nse)
πŸš€ BruteSpray
❀3
Bug Bounty Training Program (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIES’ fully exclusive Training Program β€œBug Bounty.”

βœ”οΈ Table of Content
πŸš€ Introduction to WAPT & OWASP Top 10
πŸ› οΈ Pentest Lab Setup
πŸ” Information Gathering & Reconnaissance
πŸ’» Netcat for Pentester
βš™οΈ Configuration Management Testing
πŸ” Cryptography
πŸ”‘ Authentication
πŸ•’ Session Management
πŸ“‚ Local File Inclusion
🌐 Remote File Inclusion
πŸ“ Path Traversal
πŸ’£ OS Command Injection
πŸ”€ Open Redirect
πŸ“€ Unrestricted File Upload
🐚 PHP Web Shells
πŸ“ HTML Injection
🌟 Cross-Site Scripting (XSS)
πŸ”„ Client-Side Request Forgery
πŸ›‘ SQL Injection
πŸ“œ XXE Injection
🎁 Bonus Section
❀3
πŸ“‘ Wireless Penetration Testing Using Aircrack-ng

Master wireless security assessments with this comprehensive guide to Aircrack-ng, the essential WiFi hacking toolkit:

β€’ Captures WiFi handshakes (monitor mode)
β€’ Cracks WPA/WPA2 passwords (dictionary attacks)
β€’ Analyzes network traffic (packet injection)
β€’ Supports all major wireless adapters

πŸ” Key Attacks Covered:

WEP cracking

WPA/WPA2-PSK brute force

Deauthentication attacks

πŸ“– Full Tutorial: Read Here
❀2πŸ†’2
docker.png
1.3 MB
🐳 Docker Privilege Escalation Techniques

Escalate privileges in containerized environments using critical misconfigurations:

β€’ Breakout Methods:
Abusing --privileged flag
Exploiting writable cgroups
Docker socket exposure (/var/run/docker.sock)
Capability abuse (e.g., CAP_SYS_ADMIN)

β€’ Post-Exploitation:
Host filesystem access
Container-to-host process injection
Stealing secrets from mounted volumes

πŸ” Mitigation:
Principle of Least Privilege
Read-only containers
Regular vulnerability scanning

πŸ“– Full Guide: Docker Privilege Escalation
❀3
πŸ” Learn SIEM with He-Man – The Defender of Eternia’s Cybersecurity!

This fun yet powerful guide explains Security Information & Event Management (SIEM) using He-Man’s world:
βœ… Log Collection: Like Castle Grayskull’s magic, SIEM gathers logs from servers, firewalls, and even Skeletor’s lair!
βœ… Threat Detection: Correlates events (e.g., five login failures in 2 minutes = attack!).
βœ… Dashboards & Alerts: Real-time threat visualizationβ€”no magic, just data!
βœ… False Positives: "Royal teapot accessed at midnight?" Not every alert is evil.
βœ… Compliance: Generates reports for audits (ISO, SOC 2).
❀3