Hi All, My understanding is moving a with a laptop WIFI scanner is best way to map and find a wireless device. I am looking for the location of the Wi-Fi of the device selected in blue. Is there software to do this; Windows or Linux. preferably free. https://preview.redd.it/vobfxc8er9471.png?width=1918&format=png&auto=webp&s=38c8c8835ddb9c786ce13de2e284fb2984f355cc submitted by /u/Fearless_Reporter_33 (https://www.reddit.com/user/Fearless_Reporter_33)
[link] (https://www.reddit.com/r/Pentesting/comments/nw0ek0/finding_location_of_wireless_router/) [comments] (https://www.reddit.com/r/Pentesting/comments/nw0ek0/finding_location_of_wireless_router/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://www.reddit.com/r/Pentesting/comments/nw0ek0/finding_location_of_wireless_router/) [comments] (https://www.reddit.com/r/Pentesting/comments/nw0ek0/finding_location_of_wireless_router/)
___________________________
@hacking_Attack
@Hacking_Video
How do teams of pentesters collaborate on heaps of critical information?
https://www.reddit.com/r/Pentesting/comments/nw2aoa/how_do_teams_of_pentesters_collaborate_on_heaps/
This question is for anyone in the field or has information on how this is usually conducted. How do teams of penetration testers collaborate on the heaps of information that pass through them while conducting an assessment? Currently, I am just using Obsidian.md (https://obsidian.md/) as a way to try and keep my notes organized when rooting Hack The Box or Try Hack Me machines for practice. But even then, it can get quite cluttered and difficult to understand the big picture if I were a third party reading over them. I imagine this process becomes even more complicated when writing up the final report to be presented to a client. submitted by /u/Slab-McHardBeef (https://www.reddit.com/user/Slab-McHardBeef)
[link] (https://www.reddit.com/r/Pentesting/comments/nw2aoa/how_do_teams_of_pentesters_collaborate_on_heaps/) [comments] (https://www.reddit.com/r/Pentesting/comments/nw2aoa/how_do_teams_of_pentesters_collaborate_on_heaps/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/nw2aoa/how_do_teams_of_pentesters_collaborate_on_heaps/
This question is for anyone in the field or has information on how this is usually conducted. How do teams of penetration testers collaborate on the heaps of information that pass through them while conducting an assessment? Currently, I am just using Obsidian.md (https://obsidian.md/) as a way to try and keep my notes organized when rooting Hack The Box or Try Hack Me machines for practice. But even then, it can get quite cluttered and difficult to understand the big picture if I were a third party reading over them. I imagine this process becomes even more complicated when writing up the final report to be presented to a client. submitted by /u/Slab-McHardBeef (https://www.reddit.com/user/Slab-McHardBeef)
[link] (https://www.reddit.com/r/Pentesting/comments/nw2aoa/how_do_teams_of_pentesters_collaborate_on_heaps/) [comments] (https://www.reddit.com/r/Pentesting/comments/nw2aoa/how_do_teams_of_pentesters_collaborate_on_heaps/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do teams of pentesters collaborate on heaps of critical...
This question is for anyone in the field or has information on how this is usually conducted. How do teams of penetration testers collaborate on...
ғαιвεяsgαтє.5 Cm (2012)Indo.720pWEB-DL.mp4▱▰▱▰▱▰▱▰▱▰▱▰▱▰
⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥
➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥
➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿
➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥
⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥
⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉
🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
▱▰▱▰▱▰▱▰▱▰▱▰▱▰
⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥
➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥
➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿
➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥
⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢
💥
⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉
🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
Hacking Articles Tips Tricks Videos Tutorials
ғαιвεяsgαтє.5 Cm (2012)Indo.720pWEB-DL.mp4 ▱▰▱▰▱▰▱▰▱▰▱▰▱▰ ⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥 ➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥 ➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿 ➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥 ⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥 ⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉ 🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят…
Deep Web
Who is j1337?
https://hive.blog/@j1337
https://steemit.com/@j1337
submitted by /u/Your-username-must-b
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Who is j1337?
https://hive.blog/@j1337
https://steemit.com/@j1337
submitted by /u/Your-username-must-b
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Who is j1337?
https://hive.blog/@j1337 https://steemit.com/@j1337
Deep Web
Reverse image search on deepweb
Is there any equivalent to reverse image search on google but for deep web (onion sites) ? would it be safe
submitted by /u/bluuumoo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reverse image search on deepweb
Is there any equivalent to reverse image search on google but for deep web (onion sites) ? would it be safe
submitted by /u/bluuumoo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Reverse image search on deepweb
Is there any equivalent to reverse image search on google but for deep web (onion sites) ? would it be safe
On how to access (protected) networks
https://www.reddit.com/r/redteamsec/comments/nw1e5j/on_how_to_access_protected_networks/
submitted by /u/S3cur3Th1sSh1t (https://www.reddit.com/user/S3cur3Th1sSh1t)
[link] (https://s3cur3th1ssh1t.github.io/On-how-to-access-protected-networks/) [comments] (https://www.reddit.com/r/redteamsec/comments/nw1e5j/on_how_to_access_protected_networks/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/nw1e5j/on_how_to_access_protected_networks/
submitted by /u/S3cur3Th1sSh1t (https://www.reddit.com/user/S3cur3Th1sSh1t)
[link] (https://s3cur3th1ssh1t.github.io/On-how-to-access-protected-networks/) [comments] (https://www.reddit.com/r/redteamsec/comments/nw1e5j/on_how_to_access_protected_networks/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
On how to access (protected) networks
Posted in r/redteamsec by u/S3cur3Th1sSh1t • 10 points and 1 comment
hacking: security in practice
dsi
anyone know how to jailbreak dsi without sd card?
submitted by /u/Vyibe
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
dsi
anyone know how to jailbreak dsi without sd card?
submitted by /u/Vyibe
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
dsi
anyone know how to jailbreak dsi without sd card?
hacking: security in practice
How do you guys approach problems/challenges when you have little to no knowledge about the topic involved and the time to get to a solution is scarce?
So the more I learn about ITSec the more I realize that solving problems(or creating them sometimes lol) seems to be the bread and butter of people working in this.
So I wanted to know from you guys, how do you approach scenarios in which you have close to no knowledge and almost no learning resources available to find a solution(i.e find a vulnerability, break into system etc), in a limited amount of time?
I understand that such scenarios in which you have a 'novel problem' can be rare in "real life", but every once in a while we might be faced with them and I just want to understand from y'all what strategies do you use to get to solutions?
I am asking this because I've been on an "exploit" learning saga, solving CTFs here and there and the deeper I get into the rabbit hole the more I am beginning to realize that there will be point when stackoverflow and writeups will no longer be viable options and the most relevant result on google is maybe a documentation page or "a highly technical blog post written by a kernel developer of the system on which the program to be exploited is running" I guess you get the picture. Currently being a "lone wolf" I often find myself staring at the terminal for days unsure of what to do next.
Anyway, sorry for the long question, and any response is welcome.
submitted by /u/yuyumprod
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do you guys approach problems/challenges when you have little to no knowledge about the topic involved and the time to get to a solution is scarce?
So the more I learn about ITSec the more I realize that solving problems(or creating them sometimes lol) seems to be the bread and butter of people working in this.
So I wanted to know from you guys, how do you approach scenarios in which you have close to no knowledge and almost no learning resources available to find a solution(i.e find a vulnerability, break into system etc), in a limited amount of time?
I understand that such scenarios in which you have a 'novel problem' can be rare in "real life", but every once in a while we might be faced with them and I just want to understand from y'all what strategies do you use to get to solutions?
I am asking this because I've been on an "exploit" learning saga, solving CTFs here and there and the deeper I get into the rabbit hole the more I am beginning to realize that there will be point when stackoverflow and writeups will no longer be viable options and the most relevant result on google is maybe a documentation page or "a highly technical blog post written by a kernel developer of the system on which the program to be exploited is running" I guess you get the picture. Currently being a "lone wolf" I often find myself staring at the terminal for days unsure of what to do next.
Anyway, sorry for the long question, and any response is welcome.
submitted by /u/yuyumprod
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/hacking - How do you guys approach problems/challenges when you have little to no knowledge about the topic involved and the…
281 votes and 35 comments so far on Reddit
hacking: security in practice
DDoS or DoS online tools
I want to DoS a guy that really pissed me off, however im not able to use my conputer.(im left with a mobile)is there an app, or preferably website that can do this from mobile?
submitted by /u/kuriza69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
DDoS or DoS online tools
I want to DoS a guy that really pissed me off, however im not able to use my conputer.(im left with a mobile)is there an app, or preferably website that can do this from mobile?
submitted by /u/kuriza69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
DDoS or DoS online tools
I want to DoS a guy that really pissed me off, however im not able to use my conputer.(im left with a mobile)is there an app, or preferably...
TheWizard[EngSub].srt▱▰▱▰▱▰▱▰▱▰▱▰▱▰
⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥
➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥
➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿
➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥
⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥
⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉
🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
hacking: security in practice
Extracting data from peripherals and network devices?
I think I once read an article about how the controllers in a lot of devices, from keyboards and mice, to USB controllers, to your router, often end up storing user data deep inside them, at least temporarily, which can be exploited if you have access to those devices (for example, if a high profile target throws them away assuming they contain no information). For example, some keyboards might have your past keystrokes cached somewhere in its processor, maybe even on nonvolatile memory, same for routers and your network traffic, etc. Does anyone know if this is actually a thing in information security or forensics, or am I barking up the wrong tree here?
Could the swap file be where this information is being kept for devices with operating systems? Do, for example, consumer routers, have swap files? If they do, are they liable to writing network traffic that is being processed to it? Old swap data can linger if that part of the swap file is not overwritten, or with wear levelling and overprovisioning on a flash chip, it might be quite a while before it's permanently overwritten or zeroed out even if it is overwritten in the filesystem.
submitted by /u/LatterEngineer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Extracting data from peripherals and network devices?
I think I once read an article about how the controllers in a lot of devices, from keyboards and mice, to USB controllers, to your router, often end up storing user data deep inside them, at least temporarily, which can be exploited if you have access to those devices (for example, if a high profile target throws them away assuming they contain no information). For example, some keyboards might have your past keystrokes cached somewhere in its processor, maybe even on nonvolatile memory, same for routers and your network traffic, etc. Does anyone know if this is actually a thing in information security or forensics, or am I barking up the wrong tree here?
Could the swap file be where this information is being kept for devices with operating systems? Do, for example, consumer routers, have swap files? If they do, are they liable to writing network traffic that is being processed to it? Old swap data can linger if that part of the swap file is not overwritten, or with wear levelling and overprovisioning on a flash chip, it might be quite a while before it's permanently overwritten or zeroed out even if it is overwritten in the filesystem.
submitted by /u/LatterEngineer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Extracting data from peripherals and network devices?
I think I once read an article about how the controllers in a lot of devices, from keyboards and mice, to USB controllers, to your router, often...
Hacking Articles Tips Tricks Videos Tutorials
TheWizard[EngSub].srt ▱▰▱▰▱▰▱▰▱▰▱▰▱▰ ⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥 ➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥 ➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿 ➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥 ⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥 ⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉ 🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
hacking: security in practice
rockyou2021.txt, A Short Summary (and Download Link)
https://external-preview.redd.it/d5LtQbHMM0t_4Ss9aMQIpWlGJTc69OaQlh2_KCvTrUE.jpg?width=320&crop=smart&auto=webp&s=ff0d89fdfb92557d9258e7c2a81b86423300d68a submitted by /u/tweedge
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
rockyou2021.txt, A Short Summary (and Download Link)
https://external-preview.redd.it/d5LtQbHMM0t_4Ss9aMQIpWlGJTc69OaQlh2_KCvTrUE.jpg?width=320&crop=smart&auto=webp&s=ff0d89fdfb92557d9258e7c2a81b86423300d68a submitted by /u/tweedge
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
rockyou2021.txt, A Short Summary (and Download Link)
Posted in r/hacking by u/tweedge • 341 points and 48 comments
m4rd3r.mkv▱▰▱▰▱▰▱▰▱▰▱▰▱▰
⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥
➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥
➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿
➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥
⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢
💥
⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉
🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
Hacking Articles Tips Tricks Videos Tutorials
m4rd3r.mkv ▱▰▱▰▱▰▱▰▱▰▱▰▱▰ ⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥 ➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥 ➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿 ➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥 ⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥 ⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉ 🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
hacking: security in practice
Hacking Unity Games with Malicious GameObjects
https://external-preview.redd.it/gu6pm52m9mt9-kwgz2SJZzBg2VzNr6yUD8x-F-JFllE.jpg?width=108&crop=smart&auto=webp&s=b9bedd8def0518e2b4782e47611842419042b322 submitted by /u/IncludeSec
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Unity Games with Malicious GameObjects
https://external-preview.redd.it/gu6pm52m9mt9-kwgz2SJZzBg2VzNr6yUD8x-F-JFllE.jpg?width=108&crop=smart&auto=webp&s=b9bedd8def0518e2b4782e47611842419042b322 submitted by /u/IncludeSec
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking Unity Games with Malicious GameObjects
Posted in r/hacking by u/IncludeSec • 1 point and 1 comment
hacking: security in practice
What can I do with an old Samsung Galaxy S4?
My apologies in advance if this is not the right place for this question, but I recently came into possession of an extra Galaxy S4 smartphone that I would like to tinker around with.
Does anyone have any cool ideas about what sort of things I can do with it?
submitted by /u/RobbieQuarantino
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What can I do with an old Samsung Galaxy S4?
My apologies in advance if this is not the right place for this question, but I recently came into possession of an extra Galaxy S4 smartphone that I would like to tinker around with.
Does anyone have any cool ideas about what sort of things I can do with it?
submitted by /u/RobbieQuarantino
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What can I do with an old Samsung Galaxy S4?
My apologies in advance if this is not the right place for this question, but I recently came into possession of an extra Galaxy S4 smartphone...
SharpWebServer - HTTP And WebDAV Server With Net-NTLM Hashes Capture Functionality
http://www.kitploit.com/2021/06/sharpwebserver-http-and-webdav-server.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/06/sharpwebserver-http-and-webdav-server.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
SharpWebServer - HTTP And WebDAV Server With Net-NTLM Hashes Capture Functionality
@I_M_D_B Poltergeist.2015.EXTENDED.720p.BluRay.PersianSub.mkv▱▰▱▰▱▰▱▰▱▰▱▰▱▰
⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥
➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥
➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿
➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥
⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥
⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉
🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
A Red Team (https://www.kitploit.com/search/label/Red%20Team) oriented simple HTTP & WebDAV server written in C# with functionality to capture (https://www.kitploit.com/search/label/Capture) Net-NTLM hashes. To be used for serving payloads on compromised machines for lateral movement (https://www.kitploit.com/search/label/Lateral%20Movement) purposes. Requires .NET Framework 4.5 and System.Net and System.Net.Sockets references.
Usage
- combined all building blocks together, added connection keep-alive to NTLM Authentication Usage: SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path] Options: port - TCP Port number on which to listen (1-65535) dir - Directory with files to be hosted. verbose - Turn verbose mode on. seconds - Specifies how long should the server be running. Default: indefinitely ntlm - Require NTLM Authentication before serving files. Useful to collect NetNTLMv2 hashes (in MDSec's Farmer style) logfile - Path to output logfile. "> :: SharpWebServer ::
a Red Team oriented C# Simple HTTP Server with Net-NTLMv1/2 hashes capture functionality
Authors:
- Can Güney Aksakalli (github.com/aksakalli) - original implementation
- harrypatrick442 (github.com/harrypatrick442) - aksakalli's fork & changes
- Dominic Chell (@domchell) from MDSec - Net-NTLMv2 hashes capture code borrowed from Farmer
- Mariusz B. / mgeeky, - combined all building blocks together,
added connection keep-alive to NTLM Authentication
Usage:
SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path]
Options:
port - TCP Port number on which to listen (1-65535)
dir - Directory with files to be hosted.
verbose - Turn verbose mode on.
seconds - Specifies h ow long should the server be running. Default: indefinitely
ntlm - Require NTLM Authentication before serving files. Useful to collect NetNTLMv2 hashes
(in MDSec's Farmer style)
logfile - Path to output logfile.
Example
Example use-case serving files and capturing Net-NTLM hashes at the same time: Server: SharpWebServer.exe port=8888 dir=C:\Windows\Temp verbose=true ntlm=true :: SharpWebServer :: a Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality Authors: - Dominic Chell (@domchell) from MDSec - Net-NTLM hashes capture code borrowed from Farmer - Mariusz B. / mgeeky, - WebDAV implementation, NTLM Authentication keep-alive, all the rest. Usage: SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path] Options: port - TCP Port number on which to listen (1-65535) dir - Directory with files to be hosted. verbose - Turn verbose mode on. seconds - Specifies how long should the server be running. Default: indefinitely ntlm - Require NTLM Authentication before serving files. Useful to collect NetNTLM hashes (in MDSec's Farmer style) logfile - Path to output logfile. ">C:\> SharpWebServer.exe port=8888 dir=C:\Windows\Temp verbose=true ntlm=true
:: SharpWebServer ::
a Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality
Authors:
- Dominic Chell (@domchell) from MDSec - Net-NTLM hashes capture code borrowed from Farmer
- Mariusz B. / mgeeky, - WebDAV implementation, NTLM Authentication keep-alive,
all the rest.
Usage:
SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path]
Options:
port - TCP Port number on which to listen (1-65535)
dir - Directory with files to be hosted.
___________________________
@hacking_Attack
@Hacking_Video
Usage
- combined all building blocks together, added connection keep-alive to NTLM Authentication Usage: SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path] Options: port - TCP Port number on which to listen (1-65535) dir - Directory with files to be hosted. verbose - Turn verbose mode on. seconds - Specifies how long should the server be running. Default: indefinitely ntlm - Require NTLM Authentication before serving files. Useful to collect NetNTLMv2 hashes (in MDSec's Farmer style) logfile - Path to output logfile. "> :: SharpWebServer ::
a Red Team oriented C# Simple HTTP Server with Net-NTLMv1/2 hashes capture functionality
Authors:
- Can Güney Aksakalli (github.com/aksakalli) - original implementation
- harrypatrick442 (github.com/harrypatrick442) - aksakalli's fork & changes
- Dominic Chell (@domchell) from MDSec - Net-NTLMv2 hashes capture code borrowed from Farmer
- Mariusz B. / mgeeky, - combined all building blocks together,
added connection keep-alive to NTLM Authentication
Usage:
SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path]
Options:
port - TCP Port number on which to listen (1-65535)
dir - Directory with files to be hosted.
verbose - Turn verbose mode on.
seconds - Specifies h ow long should the server be running. Default: indefinitely
ntlm - Require NTLM Authentication before serving files. Useful to collect NetNTLMv2 hashes
(in MDSec's Farmer style)
logfile - Path to output logfile.
Example
Example use-case serving files and capturing Net-NTLM hashes at the same time: Server: SharpWebServer.exe port=8888 dir=C:\Windows\Temp verbose=true ntlm=true :: SharpWebServer :: a Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality Authors: - Dominic Chell (@domchell) from MDSec - Net-NTLM hashes capture code borrowed from Farmer - Mariusz B. / mgeeky, - WebDAV implementation, NTLM Authentication keep-alive, all the rest. Usage: SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path] Options: port - TCP Port number on which to listen (1-65535) dir - Directory with files to be hosted. verbose - Turn verbose mode on. seconds - Specifies how long should the server be running. Default: indefinitely ntlm - Require NTLM Authentication before serving files. Useful to collect NetNTLM hashes (in MDSec's Farmer style) logfile - Path to output logfile. ">C:\> SharpWebServer.exe port=8888 dir=C:\Windows\Temp verbose=true ntlm=true
:: SharpWebServer ::
a Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality
Authors:
- Dominic Chell (@domchell) from MDSec - Net-NTLM hashes capture code borrowed from Farmer
- Mariusz B. / mgeeky, - WebDAV implementation, NTLM Authentication keep-alive,
all the rest.
Usage:
SharpWebServer.exe [dir=path] [verbose=true] [ntlm=true] [logfile=path]
Options:
port - TCP Port number on which to listen (1-65535)
dir - Directory with files to be hosted.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
verbose - Turn verbose mode on.
seconds - Specifies how long should the server be running. Default: indefinitely
ntlm - Require NTLM Authentication befo re serving files. Useful to collect NetNTLM hashes
(in MDSec's Farmer style)
logfile - Path to output logfile. Client: curl -sD- http://localhost:8888/test.txt --ntlm --negotiate -u TestUser:TestPassword HTTP/1.1 401 Unauthorized Transfer-Encoding: chunked WWW-Authenticate: NTLM Date: Mon, 29 Mar 2021 15:55:14 GMT HTTP/1.1 401 Unauthorized Transfer-Encoding: chunked WWW-Authenticate: NTLM TlRMTVNTUAACAAAABgAGADgAAAAFAomiESIzRFVmd4gAAAAAAAAAAIAAgAA+AAAABQLODgAAAA9TAE0AQgACAAYAUwBNAEIAAQAWAFMATQBCAC0AVABPAE8ATABLAEkAVAAEABIAcwBtAGIALgBsAG8AYwBhAGwAAwAoAHMAZQByAHYAZQByADIAMAAwADMALgBzAG0AYgAuAGwAbwBjAGEAbAAFABIAcwBtAGIALgBsAG8AYwBhAGwAAAAAAA== Date: Mon, 29 Mar 2021 15:55:14 GMT HTTP/1.1 200 OK Content-Length: 6 Content-Type: text/plain Date: Mon, 29 Mar 2021 15:55:14 GMT foobar ">C:\> curl -sD- http://localhost:8888/test.txt --ntlm --negotiate -u TestUser:TestPassword
HTTP/1.1 401 Unauthorized
Transfer-Encoding: chunked
WWW-Authenticate: NTLM
Date: Mon, 29 Mar 2021 15:55:14 GMT
HTTP/1.1 401 Unauthorized
Transfer-Encoding: chunked
WWW-Authenticate: NTLM TlRMTVNTUAACAAAABgAGADgAAAAFAomiESIzRFVmd4gAAAAAAAAAAIAAgAA+AAAABQLODgAAAA9TAE0AQgACAAYAUwBNAEIAAQAWAFMATQBCAC0AVABPAE8ATABLAEkAVAAEABIAcwBtAGIALgBsAG8AYwBhAGwAAwAoAHMAZQByAHYAZQByADIAMAAwADMALgBzAG0AYgAuAGwAbwBjAGEAbAAFABIAcwBtAGIALgBsAG8AYwBhAGwAAAAAAA==
Date: Mon, 29 Mar 2021 15:55:14 GMT
HTTP/1.1 200 OK
Content-Length: 6
Content-Type: text/plain
Date: Mon, 29 Mar 2021 15:55:14 GMT
foobar WebDAV client: dir \\localhost@8888\test Volume in drive \\localhost@8888\test has no label. Volume Serial Number is 0000-0000 Directory of \\localhost@8888\test 30.03.2021 05:12 . 30.03.2021 05:12 .. 30.03.2021 04:27 11 test2.txt 30.03.2021 05:12 12 test3.txt 30.03.2021 05:12 test4 2 File(s) 23 bytes 3 Dir(s) 225 268 776 960 bytes free C:\> type \\localhost@8888\test\test4\test5.txt Hello world! C:\> copy \\localhost@8888\test\test4\test5.txt . 1 file(s) copied. ">C:\> dir \\localhost@8888\test
Volume in drive \\localhost@8888\test has no label.
Volume Serial Number is 0000-0000
Directory of \\localhost@8888\test
30.03.2021 05:12 .
30.03.2021 05:12 ..
30.03.2021 04:27 11 test2.txt
30.03.2021 05:12 12 test3.txt
30.03.2021 05:12 test4
2 File(s) 23 bytes
3 Dir(s) 225 268 776 960 bytes free
C:\> type \\localhost@8888\test\test4\test5.txt
Hello world!
C:\> copy \\localhost@8888\test\test4\test5.txt .
1 file(s) copied.
Authors
NTLM hashes capture code & TCP Listener (https://www.kitploit.com/search/label/Listener) backbone borrowed from MDSec ActiveBreach Farmer project written by Dominic Chell (@domchell): https://github.com/mdsecactivebreach/Farmer WebDAV implementation, NTLM Authentication keep-alive logic & all the rest Mariusz B. / mgeeky, '21,
Download SharpWebServer (https://github.com/mgeeky/SharpWebServer)
___________________________
@hacking_Attack
@Hacking_Video
seconds - Specifies how long should the server be running. Default: indefinitely
ntlm - Require NTLM Authentication befo re serving files. Useful to collect NetNTLM hashes
(in MDSec's Farmer style)
logfile - Path to output logfile. Client: curl -sD- http://localhost:8888/test.txt --ntlm --negotiate -u TestUser:TestPassword HTTP/1.1 401 Unauthorized Transfer-Encoding: chunked WWW-Authenticate: NTLM Date: Mon, 29 Mar 2021 15:55:14 GMT HTTP/1.1 401 Unauthorized Transfer-Encoding: chunked WWW-Authenticate: NTLM TlRMTVNTUAACAAAABgAGADgAAAAFAomiESIzRFVmd4gAAAAAAAAAAIAAgAA+AAAABQLODgAAAA9TAE0AQgACAAYAUwBNAEIAAQAWAFMATQBCAC0AVABPAE8ATABLAEkAVAAEABIAcwBtAGIALgBsAG8AYwBhAGwAAwAoAHMAZQByAHYAZQByADIAMAAwADMALgBzAG0AYgAuAGwAbwBjAGEAbAAFABIAcwBtAGIALgBsAG8AYwBhAGwAAAAAAA== Date: Mon, 29 Mar 2021 15:55:14 GMT HTTP/1.1 200 OK Content-Length: 6 Content-Type: text/plain Date: Mon, 29 Mar 2021 15:55:14 GMT foobar ">C:\> curl -sD- http://localhost:8888/test.txt --ntlm --negotiate -u TestUser:TestPassword
HTTP/1.1 401 Unauthorized
Transfer-Encoding: chunked
WWW-Authenticate: NTLM
Date: Mon, 29 Mar 2021 15:55:14 GMT
HTTP/1.1 401 Unauthorized
Transfer-Encoding: chunked
WWW-Authenticate: NTLM TlRMTVNTUAACAAAABgAGADgAAAAFAomiESIzRFVmd4gAAAAAAAAAAIAAgAA+AAAABQLODgAAAA9TAE0AQgACAAYAUwBNAEIAAQAWAFMATQBCAC0AVABPAE8ATABLAEkAVAAEABIAcwBtAGIALgBsAG8AYwBhAGwAAwAoAHMAZQByAHYAZQByADIAMAAwADMALgBzAG0AYgAuAGwAbwBjAGEAbAAFABIAcwBtAGIALgBsAG8AYwBhAGwAAAAAAA==
Date: Mon, 29 Mar 2021 15:55:14 GMT
HTTP/1.1 200 OK
Content-Length: 6
Content-Type: text/plain
Date: Mon, 29 Mar 2021 15:55:14 GMT
foobar WebDAV client: dir \\localhost@8888\test Volume in drive \\localhost@8888\test has no label. Volume Serial Number is 0000-0000 Directory of \\localhost@8888\test 30.03.2021 05:12 . 30.03.2021 05:12 .. 30.03.2021 04:27 11 test2.txt 30.03.2021 05:12 12 test3.txt 30.03.2021 05:12 test4 2 File(s) 23 bytes 3 Dir(s) 225 268 776 960 bytes free C:\> type \\localhost@8888\test\test4\test5.txt Hello world! C:\> copy \\localhost@8888\test\test4\test5.txt . 1 file(s) copied. ">C:\> dir \\localhost@8888\test
Volume in drive \\localhost@8888\test has no label.
Volume Serial Number is 0000-0000
Directory of \\localhost@8888\test
30.03.2021 05:12 .
30.03.2021 05:12 ..
30.03.2021 04:27 11 test2.txt
30.03.2021 05:12 12 test3.txt
30.03.2021 05:12 test4
2 File(s) 23 bytes
3 Dir(s) 225 268 776 960 bytes free
C:\> type \\localhost@8888\test\test4\test5.txt
Hello world!
C:\> copy \\localhost@8888\test\test4\test5.txt .
1 file(s) copied.
Authors
NTLM hashes capture code & TCP Listener (https://www.kitploit.com/search/label/Listener) backbone borrowed from MDSec ActiveBreach Farmer project written by Dominic Chell (@domchell): https://github.com/mdsecactivebreach/Farmer WebDAV implementation, NTLM Authentication keep-alive logic & all the rest Mariusz B. / mgeeky, '21,
Download SharpWebServer (https://github.com/mgeeky/SharpWebServer)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Welcome.The.Stranger.2018.WEBDL.@Qualitymovies.mkv▱▰▱▰▱▰▱▰▱▰▱▰▱▰
⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥
➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥
➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿
➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥
⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥
⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉
🎗️ ʝσιи 🎗️ ѕнαяє🎗️ ѕυρρσят 🎗️
Hacking Articles Tips Tricks Videos Tutorials
Welcome.The.Stranger.2018.WEBDL.@Qualitymovies.mkv ▱▰▱▰▱▰▱▰▱▰▱▰▱▰ ⤇ᴄʜᴀɴɴᴇʟ : @FC_tvseries🎥 ➥ᴄʜᴀɴɴᴇʟ : @fc_filmcorner 🔥 ➠ɢʀᴏᴜᴘ : @fcfilmcornerCC 🍿 ➺ɴᴇᴡ ᴍᴏᴠɪᴇꜱ : @fcfilmcornerNr💥 ⭆ᴄᴏʟʟᴇᴄᴛɪᴏɴ: @Fcfilmcornerfc💢 💥 ⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉⑉ 🎗️ ʝσιи 🎗️ ѕнαяє🎗️…
Dark Reading: Attacks/Breaches
New Security Event @Hack to Take Place in Saudi Arabia
The Saudi Federation of Cybersecurity, Programming, and Drones (SAFCSP) and Informa Tech will launch a multi-day event in Riyadh this November.
___________________________
@hacking_Attack
@Hacking_Video
New Security Event @Hack to Take Place in Saudi Arabia
The Saudi Federation of Cybersecurity, Programming, and Drones (SAFCSP) and Informa Tech will launch a multi-day event in Riyadh this November.
___________________________
@hacking_Attack
@Hacking_Video