Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Pen Test Report Writing Tool
https://www.reddit.com/r/Pentesting/comments/nln3ee/pen_test_report_writing_tool/

I'm working on a side project of trying to build a web-based tool for managing and helping me generate pen-testing reports. The idea is to define some attributes, such as the company you're doing the work for, dates, etc., and then drag-and-drop blocks of the report into place. For example, an executive summary, scope, various issues found. All would come in customized already with the various known attributes, and then you can tweak/modify each section as needed. You can then also save your blocks to re-use later. This might be particularly handy for various vulnerabilities since we tend to find the same things over and over again. I'd be curious to hear from as many people as possible regarding what features they would want in a web-based report writer, and I'm also looking for sample reports. Anything redacted or open-source would be fine, but please nothing confidential. I've started this Workflowy list to try and capture the requirements: https://workflowy.com/s/penetration-report-w/h1fcj6ru5b3ca4r7 Any help is appreciated. Happy to share the final result with you, if it ever comes into being. If I build it, I will likely charge a monthly or annual fee for it, but anyone who helps will get a large discount and/or some extended trial period (3 months +?). submitted by /u/ltmodcs (https://www.reddit.com/user/ltmodcs)
[link] (https://www.reddit.com/r/Pentesting/comments/nln3ee/pen_test_report_writing_tool/) [comments] (https://www.reddit.com/r/Pentesting/comments/nln3ee/pen_test_report_writing_tool/)

___________________________
@hacking_Attack
@Hacking_Video
Cmd injection
https://www.reddit.com/r/Pentesting/comments/nlquki/cmd_injection/

<!-- SC_OFF -->Really struggling to do a command injection on a server that I am told, is vulnerable for cmd injection on an application port. The application does not have UI so no URL to use tools like burp, commix etc. I know it’s too generic but is there a way command injections can be done checking with Linux level commands from external server like trying to write files in target server etc ? Any help would be appreciated. TIA. <!-- SC_ON --> submitted by /u/Pamelaxyz (https://www.reddit.com/user/Pamelaxyz)
[link] (https://www.reddit.com/r/Pentesting/comments/nlquki/cmd_injection/) [comments] (https://www.reddit.com/r/Pentesting/comments/nlquki/cmd_injection/)
DNS-Black-Cat(DBC) - Multi Platform Toolkit For An Interactive DNS Shell Commands Exfiltration, By Using DNS-Cat You Will Be Able To Execute System Commands In Shell Mode Over DNS Protocol

Multi-platform toolkit for an interactive C2C DNS shell, by using DNS-Black-Cat, you will be able to execute system commands in shell mode over a fully encrypted covert channel.Server ported as a python script, which acts as DNS server with required functionalities to provide interactive shell command interface. Client ported as the following file formats Windows 32/64 executable (exe) Linux 32/64 executable (ELF) Powershell Script (ps1) Dynamic Link Library (DLL) MacOS Darwin x86_64 Highlights The agent supports multi-platforms. built-in feature with 0xsp-mongoose RED. Available as win32/64 executable, Powershell script, Linux ELF. Encrypted and encoded DNS Queries. Traffic Segmentation. Speed and stability. Stealth and undetectable. Releases System Supported Windows (EXE) YES Windows (PS) YES Windows (DLL) YES Linux YES MacOS YES BSD Still Android Still Support Support the project for continuous development (ETH 0xf340c15c5e669a4ababab856e9f2bccd659d6e42) Wiki ? https://0xsp.com/security%20research%20&%20development%20(SRD)/covert-dns-cc-for-red-teaming-ops Download Dns-Black-Cat
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
DNS-Black-Cat(DBC) - Multi Platform Toolkit For An Interactive DNS Shell Commands Exfiltration, By Using DNS-Cat You Will Be Able To Execute System Commands In Shell Mode Over DNS Protocol

https://1.bp.blogspot.com/-LJ3lpMgEgkk/YKryYpKcThI/AAAAAAAAWRA/uVqHfzIDYfcZWqyp2dbUpRpUs_t6A8_twCNcBGAsYHQ/w640-h508/dns-black-cat_1_DNS-Cat.png
Multi-platform toolkit for an interactive C2C DNS shell, by using DNS-Black-Cat, you will be able to execute system commands in shell mode over a fully encrypted covert channel.
Server

ported as a python script, which acts as DNS server with required functionalities to provide interactive shell command interface.

Client

ported as the following file formats

* Windows 32/64 executable (exe)
* Linux 32/64 executable (ELF)
* Powershell Script (ps1)
* Dynamic Link Library (DLL)
* MacOS Darwin x86_64

Highlights

* The agent supports multi-platforms.
* built-in feature with 0xsp-mongoose RED.
* Available as win32/64 executable, Powershell script, Linux ELF.
* Encrypted and encoded DNS Queries.
* Traffic Segmentation.
* Speed and stability.
* Stealth and undetectable.

Releases
System Supported Windows (EXE) YES Windows (PS) YES Windows (DLL) YES Linux YES MacOS YES BSD Still Android Still
Support

Support the project for continuous development (ETH 0xf340c15c5e669a4ababab856e9f2bccd659d6e42)

Wiki ?

https://0xsp.com/security%20research%20&%20development%20(SRD)/covert-dns-cc-for-red-teaming-ops
Download Dns-Black-Cat

___________________________
@hacking_Attack
@Hacking_Video
DNS-Black-Cat(DBC) - Multi Platform Toolkit For An Interactive DNS Shell Commands Exfiltration, By Using DNS-Cat You Will Be Able To Execute System Commands In Shell Mode Over DNS Protocol
http://www.kitploit.com/2021/05/dns-black-catdbc-multi-platform-toolkit.html

___________________________
@hacking_Attack
@Hacking_Video
Multi-platform toolkit (https://www.kitploit.com/search/label/Toolkit) for an interactive C2C DNS shell, by using DNS-Black-Cat, you will be able to execute system commands in shell mode over a fully encrypted covert channel.
Server
ported as a python script, which acts as DNS server with required functionalities to provide interactive shell command interface.
Client
ported as the following file formats Windows 32/64 executable (exe) Linux 32/64 executable (ELF) Powershell Script (ps1) Dynamic Link Library (https://www.kitploit.com/search/label/Library) (DLL) MacOS Darwin x86_64
Highlights
The agent supports multi-platforms. built-in feature with 0xsp-mongoose (https://www.kitploit.com/search/label/0xsp-Mongoose) RED. Available as win32/64 executable, Powershell script, Linux (https://www.kitploit.com/search/label/Linux) ELF. Encrypted and encoded DNS Queries. Traffic Segmentation. Speed and stability. Stealth and undetectable.
Releases
System Supported Windows (EXE) YES Windows (PS) YES Windows (DLL) YES Linux YES MacOS YES BSD Still Android Still
Support
Support the project for continuous development (ETH 0xf340c15c5e669a4ababab856e9f2bccd659d6e42)
Wiki ?
https://0xsp.com/security%20research%20&%20development%20(SRD)/covert-dns-cc-for-red-teaming-ops

Download Dns-Black-Cat (https://github.com/lawrenceamer/dns-black-cat)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can someone suggest me a good course regarding facial recognition and identification?

I come across a number of violent and bad videos and I would like to help the local police to identify the victim and culprits in those videos.

But I don't poses the skills necessary to identify the faces. Is there any courses,tools or anything I can use to learn to identify faces.

submitted by /u/Lost-Toe6731
[link] [comments]