Hacking Articles
21.1K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Dork
❀3
Mass Scan
πŸ‘5πŸ‘Œ1
Top 25 SQL
πŸ‘4
AD Hardening Risks Explained Through Restaurant Scenarios
✴ Twitter: https://x.com/hackinarticles


Secure your Active Directory kitchen with these bite-sized analogies:

☒ Credential Stealer
Scenario: Dishwasher steals the head chef’s keys β†’ Accesses the wine cellar.
Risk: Stolen credentials grant unauthorized access to critical systems.
Defense: Never log in with admin credentials on workstations.

☒ Public Pwn (MS14-068)
Scenario: Customer forges a VIP pass β†’ Gets kitchen control.
Risk: Kerberos flaw escalates to Domain Admin in minutes.
Defense: Patch KB3011780 + automate compliance checks.

☒ Leaked in Kitchen (GPP Passwords)
Scenario: Recipes with secret ingredients left on the counter.
Risk: Group Policy Preferences expose passwords in SYSVOL.
Defense: Delete groups.xml, install KB2962486, audit GPPs.

☒ DCSync Attack
Scenario: Impostor poses as health inspector β†’ Demands all recipes.
Risk: Attackers mimic Domain Controllers to steal password hashes.
Defense: Restrict "Replicating Directory Changes" rights.

☒ LLMNR Poisoning
Scenario: Fake waiter intercepts orders β†’ Serves poisoned dishes.
Risk: Spoofed network responses steal NTLM hashes.
Defense: Disable LLMNR/NBT-NS via Group Policy.

☒ AS-REP Roasting
Scenario: No ID check at the door β†’ Burglars walk in freely.
Risk: Kerberos pre-authentication bypassed for hash theft.
Defense: Enforce pre-auth for all accounts.

☒ Vulnerable GPO Abuse
Scenario: Dishwasher edits kitchen rules β†’ Adds backdoor access.
Risk: Malicious Group Policies deploy malware.
Defense: Audit GPO permissions with BloodHound.

☒ Pass-the-Ticket Attack
Scenario: Stolen meal voucher reused β†’ Free dinners forever.
Risk: Kerberos tickets reused for lateral movement.
Defense: Monitor TGT anomalies, reset compromised passwords.
ADCS ESC15 - Exploiting Template Schema v1

✴ Twitter: https://x.com/hackinarticles

The ESC15 vulnerability (EKUwu), affects Active Directory Certificate Services (AD CS), allowing attackers to inject unauthorized EKUs (e.g., Client Authentication) into Schema Version 1 templates.

πŸ“˜ Overview of the ESC15 Attack
πŸ“ What is Schema Version 1?
πŸ“‹ Prerequisites
πŸ§ͺ Lab Setup
🎯 Enumeration & Exploitation
🧠 Post Exploitation
πŸ›‘οΈ Mitigation
❀1
πŸ”₯ OSCP+/CTF Exam Practice Training (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join IGNITE TECHNOLOGIES’ exclusive "Capture the Flag" Training Program and enhance your skills with the following modules:

🧠 Introduction
🌐 Information Gathering
🧱 Vulnerability Scanning
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘οΈ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks
🧠 Tunneling & Pivoting
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits
πŸ“‹ Report Writing
❀2
How to Spot a Pentester
Type of Logs
Web Application Tools
OT Cybersecurity in 5 Bite-Sized Scenarios

✴ Twitter: Share this thread
1. No Incident Plan
Kitchen fire β†’ Staff panics
βœ… Fix: OT-specific response drills

2. Weak Architecture
Open kitchen β†’ Rats everywhere
βœ… Fix: Segment IT/OT networks

3. Blind Monitoring
No cameras β†’ Thieves steal freely
βœ… Fix: ICS-aware sensors (e.g., Dragos)

4. Risky Remote Access
Backdoor open β†’ Hackers walk in
βœ… Fix: MFA + time-limited access

5. Ignored Vulnerabilities
Rotten food β†’ Customers sick
βœ… Fix: Patch "NOW" threats first

Stats:
Only 29% secure remote access
61% monitor networks properly
πŸ”₯1
A Detailed Guide on Certipy

✴ Twitter: https://x.com/hackinarticles

In this Certipy Active Directory Exploitation guide, we explore how to use Certipyβ€”an offensive and defensive toolkit designed for Active Directory Certificate Services (AD CS)β€”to enumerate misconfigurations and abuse CA templates.

πŸ“˜ Overview of Certipy
πŸ›οΈ ADCS Key Concepts
πŸ“‹ Prerequisites
πŸ•΅οΈ Finding Vulnerable Templates
🧾 Examining Account Privileges
πŸ”§ Manipulating Accounts
πŸ“œ Requesting Certificates
πŸ” Authenticating via Certificate
πŸ‘₯ Managing Shadow Credentials
πŸ› οΈ Modifying Templates & CA
πŸŒ€ Forging & Relaying Certificates
πŸ›‘οΈ Mitigation
❀1πŸ‘1πŸ”₯1
πŸš€ AI Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

🧠 LLM Architecture
πŸ” LLM Security Principles
πŸ—„οΈ Data Security in AI Systems
πŸ›‘οΈ Model Security
πŸ—οΈ Infrastructure Security
πŸ“œ OWASP Top 10 for LLMs
βš™οΈ LLM Installation and Deployment
πŸ“‘ Model Context Protocol (MCP)
πŸš€ Publishing Your Model Using Ollama
πŸ” Introduction to Retrieval-Augmented Generation (RAG)
🌐 Making Your AI Application Public
πŸ“Š Types of Enumeration Using AI
🎯 Prompt Injection Attacks
🐞 Exploiting LLM APIs: Real-World Bug Scenarios
πŸ”‘ Password Leakage via AI Models
🎭 Indirect Prompt Injection Techniques
⚠️ Misconfigurations in LLM Deployments
πŸ‘‘ Exploitation of LLM APIs with Excessive Privileges
πŸ“ Content Manipulation in LLM Outputs
πŸ“€ Data Extraction Attacks on LLMs
πŸ”’ Securing AI Systems
🧾 System Prompts and Their Security Implications
πŸ€– Automated Penetration Testing with AI
❀3
2fa Bypass
❀1