Users can bind to LDAP utilizing valid user account credentials (https://www.kitploit.com/search/label/Credentials) or a valid NTLM hash. Using credentials will obtain the same information as the anonymously binded request, as well as checking for the following: Subnet scan for systems with ports 389 and 636 open Basic Domain Info (Current user permissions, domain SID, password policy, machine account quota) Users Groups Kerberoastable Accounts ASREPRoastable Accounts Constrained Delegation Unconstrained Delegation Computer Accounts - will also attempt DNS lookups on the hostname to identify IP addresses Identify Domain Controllers Identify Servers Identify Deprecated Operating Systems Identify MSSQL Servers Identify Exchange Servers Group Policy Objects (GPO) Passwords in User description fields Each check outputs the raw contents to a text file, and an abbreviated, cleaner version of the results in the terminal environment. The results in the terminal are pulled from the individual text files. Add support for LDAPS (LDAP Secure) NTLM Authentication Figure out why Unix only allows one adapter to make a call out to the LDAP server (removed resolution from Linux until resolved) Add support for querying child domain information (currently does not respond nicely to querying child domain controllers) Figure out how to link the name to the Description field dump at the end of the script mplement command line (https://www.kitploit.com/search/label/Command%20Line) options rather than inputs Check for deprecated operating systems in the domain Mandatory Disclaimer Please keep in mind that this tool is meant for ethical hacking (https://www.kitploit.com/search/label/Ethical%20Hacking) and penetration testing (https://www.kitploit.com/search/label/Penetration%20Testing) purposes only. I do not condone any behavior that would include testing targets that you do not currently have permission to test against.
Download msLDAPDump (https://github.com/dievus/msLDAPDump)
Download msLDAPDump (https://github.com/dievus/msLDAPDump)
How To Abuse A Password Manager
https://blog.devgenius.io/how-to-abuse-a-password-manager-7ea9cbe4dbd0?source=rss------bug_bounty-5
https://blog.devgenius.io/how-to-abuse-a-password-manager-7ea9cbe4dbd0?source=rss------bug_bounty-5
Getting The Master Key to HeavenContinue reading on Dev Genius » (https://blog.devgenius.io/how-to-abuse-a-password-manager-7ea9cbe4dbd0?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
I’m one of the Saki Sanobashi hunters. . .
Alright, so this is gonna sound weird, but on the discord we only have one possible video website listed and I already ruled it out. And since OP listed he saw this on the dark web I’m thinking it was either on TorTube or some other obscure video website platform. Would anyone have some links to help me go on the search?
submitted by /u/RubyTheSilkWing
[link] [comments]
I’m one of the Saki Sanobashi hunters. . .
Alright, so this is gonna sound weird, but on the discord we only have one possible video website listed and I already ruled it out. And since OP listed he saw this on the dark web I’m thinking it was either on TorTube or some other obscure video website platform. Would anyone have some links to help me go on the search?
submitted by /u/RubyTheSilkWing
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Usefulness of links that provide location of people when clicked
https://external-preview.redd.it/F6AGihc6sjMmnVLm-XWIe0jcP2vPZpBwjOqH2PhZX-c.jpg?width=108&crop=smart&auto=webp&s=0563ade4652d2408b81c0d4fd5f4ad1c26458007 The website https://linklocator.net has basically scripted a bunch of things and made it simple to create a tinyurl link that can be sent to someone and if they click it, it will record their location for the person who made the link. The person who creates the link can actually even dictate where the link forwards onto after the geolocation info is retrieved.
This was sort of a side gig I did for some bail bondsmen who weren’t very tech savvy, but it probably has more application than I can think of. Just looking for other ideas.
submitted by /u/newmanog
[link] [comments]
Usefulness of links that provide location of people when clicked
https://external-preview.redd.it/F6AGihc6sjMmnVLm-XWIe0jcP2vPZpBwjOqH2PhZX-c.jpg?width=108&crop=smart&auto=webp&s=0563ade4652d2408b81c0d4fd5f4ad1c26458007 The website https://linklocator.net has basically scripted a bunch of things and made it simple to create a tinyurl link that can be sent to someone and if they click it, it will record their location for the person who made the link. The person who creates the link can actually even dictate where the link forwards onto after the geolocation info is retrieved.
This was sort of a side gig I did for some bail bondsmen who weren’t very tech savvy, but it probably has more application than I can think of. Just looking for other ideas.
submitted by /u/newmanog
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Bettercap - All devices have VMware Mac addresses
Hello, am using kali linux and launching it from my VMware, am trying to learn to use Bettercap. Am running net.probe on and then net.show but i get back only MAC addresses starting with 00:50:56 that are VMware, and the vendors are all VMware. Does someone know how to help me resolve this issue and instead of Vm ware to show the actual devices connected to my wifi?
submitted by /u/GiaxniKolokasi
[link] [comments]
Bettercap - All devices have VMware Mac addresses
Hello, am using kali linux and launching it from my VMware, am trying to learn to use Bettercap. Am running net.probe on and then net.show but i get back only MAC addresses starting with 00:50:56 that are VMware, and the vendors are all VMware. Does someone know how to help me resolve this issue and instead of Vm ware to show the actual devices connected to my wifi?
submitted by /u/GiaxniKolokasi
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Accidentally closed H1 reports as "Not Applicable", costing me signal
I submitted two reports to a public program. This program told me that the bugs I submitted were known internally, and advised me to close my reports to avoid H1 reputation loss, which I did. I also accidentally closed another report instead of deleting a draft. Is there a way I can have these report states modified so that I don't lose signal?
submitted by /u/dominate1090
[link] [comments]
Accidentally closed H1 reports as "Not Applicable", costing me signal
I submitted two reports to a public program. This program told me that the bugs I submitted were known internally, and advised me to close my reports to avoid H1 reputation loss, which I did. I also accidentally closed another report instead of deleting a draft. Is there a way I can have these report states modified so that I don't lose signal?
submitted by /u/dominate1090
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Any news on “Aircrack” suppose to be the best password cracking site, looking to get into old accounts.
Trying to get into old accounts (emails, social media, accounts with old emails attached) - this one says it’s best to do this with password guessing.
They’re all free which makes me nervous, could be downloading a virus. :/
submitted by /u/Gaybaconeater
[link] [comments]
Any news on “Aircrack” suppose to be the best password cracking site, looking to get into old accounts.
Trying to get into old accounts (emails, social media, accounts with old emails attached) - this one says it’s best to do this with password guessing.
They’re all free which makes me nervous, could be downloading a virus. :/
submitted by /u/Gaybaconeater
[link] [comments]
hacking: security in practice
How do hackers hide their ip in reverse shells?
Its not an option to use a vpn, proxies or tor in a reverse shell so, how do they do it?
submitted by /u/PutYourNameHereNow
[link] [comments]
How do hackers hide their ip in reverse shells?
Its not an option to use a vpn, proxies or tor in a reverse shell so, how do they do it?
submitted by /u/PutYourNameHereNow
[link] [comments]
Reddit
From the hacking community on Reddit: How do hackers hide their ip in reverse shells?
Posted by [Deleted Account] - 25 votes and 29 comments