Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Bug Bounty Training Program (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIES’ fully exclusive Training Program β€œBug Bounty.”

βœ”οΈ Table of Content
πŸš€ Introduction to WAPT & OWASP Top 10
πŸ› οΈ Pentest Lab Setup
πŸ” Information Gathering & Reconnaissance
πŸ’» Netcat for Pentester
βš™οΈ Configuration Management Testing
πŸ” Cryptography
πŸ”‘ Authentication
πŸ•’ Session Management
πŸ“‚ Local File Inclusion
🌐 Remote File Inclusion
πŸ“ Path Traversal
πŸ’£ OS Command Injection
πŸ”€ Open Redirect
πŸ“€ Unrestricted File Upload
🐚 PHP Web Shells
πŸ“ HTML Injection
🌟 Cross-Site Scripting (XSS)
πŸ”„ Client-Side Request Forgery
πŸ›‘ SQL Injection
πŸ“œ XXE Injection
🎁 Bonus Section
❀2
Multiple Ways to Crack WordPress login

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, you will be learning how to compromise a WordPress website’s credentials using different brute-force techniques.

πŸ“š Pre-requisites
πŸ›°οΈ WPScan
πŸ’₯ Metasploit
πŸ§ͺ Burp Suite
πŸ›‘οΈ How to avoid a Brute Force Attack?
❀1
Burp Suite for Pentester: Web Scanner & Crawler

✴ Twitter: https://lnkd.in/e7yRpDpY
πŸ”₯Telegram: https://t.me/hackinarticles

In this article, we’ll discuss how you can identify hidden web pages or determine the existing vulnerabilities in a web application. To do this, we will use one of the best intercepting tools – β€œBurp Suite”.

πŸ•·οΈ The Burp’s Crawler
 ❓ What is Crawler?
β€ƒβš™οΈ Crawl with Default Configurations
β€ƒπŸ› οΈ Customizing the Crawler

πŸ›‘οΈ Vulnerability Scanning over Burp Suite
β€ƒπŸ” Auditing with Default Configurations
β€ƒπŸŽ›οΈ Defining Audit Options

πŸ”„ Crawling & Scanning with an Advanced Scenario
πŸ—‘οΈ Deleting the Defined Tasks
Mitre Collection
Mitre Command and Control
Mitre Credential Access
πŸš€ Active Directory Exploitation Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘οΈ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
Abusing AD-DACL: WriteDacl

✴ Twitter: https://lnkd.in/e7yRpDpY
πŸ”₯Telegram: https://t.me/hackinarticles

In this post, we will explore the exploitation of Discretionary Access Control Lists (DACL) using the WriteDacl permission in Active Directory environments.

πŸ§ͺ Lab Setup – User Owns WriteDacl Permission on Another User
βš”οΈ Exploitation Phase I – User Owns WriteDacl Permission on Another User
πŸ•΅οΈ BloodHound – Hunting for Weak Permission

πŸ”§ Method for Exploitation:
β€ƒβ€ƒπŸ“œ Granting Full Control
  πŸ”₯ Kerberoasting (T1558.003) or
β€ƒβ€ƒπŸ”‘ Change Password (T1110.001)

🐧 Linux-Based Tools
🧰 Impacket Tool – Granting Full Control
🐍 Python Script (TargetedKerberoast)
πŸ” Linux – Change Password
πŸ“‘ Net RPC (Samba)
πŸ’‰ BloodyAD

πŸͺŸ Windows PowerShell (PowerView)
🧾 Granting Full Control
🦊 Kerberoasting
πŸ” Change Password

πŸ§ͺ Lab Setup – User Owns WriteDacl Permission on the Domain Admin Group
βš”οΈ Exploitation Phase II – User Owns WriteDacl Permission on a Group
πŸ•΅οΈ BloodHound – Hunting for Weak Permission

πŸ”§ Method for Exploitation:
β€ƒβ€ƒπŸ“œ Granting Full Control
  πŸ‘₯ Account Manipulation (T1098)

🐧 Linux-Based Tools
🧰 Impacket Tool – Granting Full Control
βž• Linux – Adding Member to the Group
πŸ“‘ Net RPC (Samba)
πŸ’‰ BloodyAD

πŸͺŸ Windows-Based Tools
🧾 PowerView – Granting Full Control
βž• Net Command – Adding Member to Group
❀2