Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Delivery HackTheBox Walkthrough

Hello! Everyone and Welcome to yet another CTF challenge from Hack the Box, called ‘Delivery,’ which is available online for those who want to increase their skills in penetration testing and Black box testing. Delivery is a retired vulnerable lab presented by Hack the Box for making online penetration testing practice suitable to your experience level; they have a large collection of vulnerable labs as challenges ranging from beginner to expert level. Level:EasyTask:Find user.txt and root.txt in the victim’s machinePenetration Methodologies* ScanningEnumerationExploitationPrivilege EscalationCapturing the flagWalkthroughLet’s get started then!

IP Address assigned to delivery machine: 10.129.149.209Let us scan the VM with the most popular port scanning tool, nmap to enumerate open ports on the machinedelivery.htbFrom the result below we found three working ports on the VM, port SSH(22), HTTP(80) and Unknown(8065).helpdesk.delivery.htb10.129.149.79delivery.htb helpdesk.delivery.htb___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Delivery HackTheBox Walkthrough

Hello! Everyone and Welcome to yet another CTF challenge from Hack the Box, called ‘Delivery,’ which is available online for those who want to increase their skills in penetration testing and Black box testing. Delivery is a retired vulnerable lab presented by Hack the Box for making online penetration testing

The post Delivery HackTheBox Walkthrough appeared first on Hacking Articles.
External Penetration Testing Methodologie
https://www.reddit.com/r/Pentesting/comments/nk7eew/external_penetration_testing_methodologie/

Hey everyone! ​ I'm currently conducting some black box external pentesting on real world companies as internship trainee. This is my first experience with that. Basically what i m doing is the following : Recon: use some tools (whois, theHarvester, amass, dnsenum, Recon-ng, GHDB...) to gather the maximum informations (subdomaines, login pages that uses http protocole - believe me i already found this one -...). Scan: i try to scan the subdomaines i found with nmap, find Hidden Directories (GOBuster, Dirbuster). Also run nikto, whatweb and Wpscan incase the website is made with wordpress. Then i run the vulnerability scan Nessus. Gaining Access: identify the vulnerabilities that are exploitable to provide access to the target (brute force ssh, upload reverseshell...). ​ Since this is my first experience, and there isnt a senior pentester in the company to ask and exchange with (i'm doing the pentesting and report alone), i would like to ask the pentester guys what techniques/tools should i add to this methodo ? Any guidance/helpful information is really much appreciated. ​ Thanks for taking the time to read! submitted by /u/Adel_Maestro (https://www.reddit.com/user/Adel_Maestro)
[link] (https://www.reddit.com/r/Pentesting/comments/nk7eew/external_penetration_testing_methodologie/) [comments] (https://www.reddit.com/r/Pentesting/comments/nk7eew/external_penetration_testing_methodologie/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Air India Confirms Data of 4.5M Travelers Compromised

Affected data includes names, birthdates, contact information, passport details, and credit card data, the airline reports.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
CiLocks - Android LockScreen Bypass

https://1.bp.blogspot.com/-gC11e2udHzY/YKru8f-wuYI/AAAAAAAAWQc/EejT8t57b1Uo-8mjMlBFiPaFOqSgGXpBgCNcBGAsYHQ/w640-h506/CiLocks_1_Screenshot_2021-05-02_14-32-27.png
CiLocks - Android LockScreen Bypass

Features

* Brute Pin 4 Digit
* Brute Pin 6 Digit
* Brute LockScreen Using Wordlist
* Bypass LockScreen {Antiguard} Not Support All OS Version
* Root Android {Supersu} Not Support All OS Version
* Steal File
* Reset Data
Required

- Adb {Android SDK}
- Cable Usb
- Android Emulator {NetHunter/Termux} Root
- Or Computer

Compatible

- Linux
- Windows
- Mac

Tested On

- Kali Linux

How To Run

- git clone https://github.com/tegal1337/CiLocks
- cd CiLocks
- chmod +x cilocks
- bash cilocks
For Android Emulator

- Install Busybox
- Root

If brute doesn't work then uncomment this code

`# adb shell input keyevent 26`
if 5x the wrong password will automatically delay 30 seconds

Image
https://1.bp.blogspot.com/-1jb1PwOotyw/YKrvCT5hkBI/AAAAAAAAWQg/lsvFZOPolQ8y_HhOKjZILre_iRpd9hpSACNcBGAsYHQ/w640-h506/CiLocks_1_Screenshot_2021-05-02_14-32-27.png
Video

Bypass LockScreen
https://youtu.be/PPMhzt4lGmU
BruteForce Pin
https://youtu.be/D2xjJUQ9Lsw
Reference And Media

https://stackoverflow.com/questions/29072501/how-to-unlock-android-phone-through-adb
http://www.hak5.org/episodes/hak5-1205
https://github.com/kosborn/p2p-adb
https://forum.xda-developers.com/t/universal-guide-root-any-android-device-manually.2684210/
https://stackoverflow.com/questions/14685721/how-can-i-do-factory-reset-using-adb-in-android
Contac Me Email
Download CiLocks
CiLocks - Android LockScreen Bypass

CiLocks - Android LockScreen BypassFeatures Brute Pin 4 Digit Brute Pin 6 Digit Brute LockScreen Using Wordlist Bypass LockScreen {Antiguard} Not Support All OS Version Root Android {Supersu} Not Support All OS Version Steal File Reset DataRequired - Adb {Android SDK} - Cable Usb - Android Emulator {NetHunter/Termux} Root - Or Computer Compatible - Linux - Windows - Mac Tested On - Kali Linux How To Run - git clone https://github.com/tegal1337/CiLocks - cd CiLocks - chmod +x cilocks - bash cilocks For Android Emulator - Install Busybox - Root If brute doesn't work then uncomment this code `# adb shell input keyevent 26` if 5x the wrong password will automatically delay 30 seconds Image Video Bypass LockScreen https://youtu.be/PPMhzt4lGmU BruteForce Pin https://youtu.be/D2xjJUQ9Lsw Reference And Media https://stackoverflow.com/questions/29072501/how-to-unlock-android-phone-through-adb http://www.hak5.org/episodes/hak5-1205 https://github.com/kosborn/p2p-adb https://forum.xda-developers.com/t/universal-guide-root-any-android-device-manually.2684210/ https://stackoverflow.com/questions/14685721/how-can-i-do-factory-reset-using-adb-in-android Contac Me Email Download CiLocks
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Stored XSS with two different parameters

Hello Readers,Continue reading on Medium »
Read more...
All about Multi-factor Authentication security Bypass

Bypassing 2FA securityContinue reading on Medium »
Read more...