Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The South Korean Atomic Research Hack in 2 Minutes
https://cdn-images-1.medium.com/max/2600/0*y2kTkUpzfuBycM_C
Spoiler Alert: It was North Korea
Continue reading on 2 Minute Madness »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
The South Korean Atomic Research Hack in 2 Minutes
https://cdn-images-1.medium.com/max/2600/0*y2kTkUpzfuBycM_C
Spoiler Alert: It was North Korea
Continue reading on 2 Minute Madness »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
The South Korean Atomic Research Hack in 2 Minutes
Spoiler Alert: It was North Korea
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
NamedPipePTH - Pass The Hash To A Named Pipe For Token Impersonation
http://3.bp.blogspot.com/-Wd1GldbL2VA/YMaXF-Tns4I/AAAAAAAAbAo/wGru31c4r_AehF11gNxRCo5cmYO4LY9JwCK4BGAYYCw/w640-h200/NamedPipePTH_2_Example2-738687.jpeg This project is a PoC code to use Pass-the-Hash for authentication on a local Named Pipe user Impersonation. There also is a blog post for explanation: https://s3cur3th1ssh1t.github.io/Named-Pipe-PTH/
It is heavily based on the code from the projects Invoke-SMBExec.ps1 and RoguePotato.
I faced certain Offensive Security project situations in the past, where I already had the NTLM-Hash of a
My personal goals for a tool/technique were:
* Fully featured shell or C2-connection as the victim user-account
* It must to able to also Impersonate
* The tool can be used as C2-module
The impersonated user unfortunately has no network authentication allowed, as the new process is using an Impersonation Token which is restricted. So you can only use this technique for local actions with another user.
There are two ways to use this technique. Either you can compile
___________________________
@hacking_Attack
@Hacking_Video
NamedPipePTH - Pass The Hash To A Named Pipe For Token Impersonation
http://3.bp.blogspot.com/-Wd1GldbL2VA/YMaXF-Tns4I/AAAAAAAAbAo/wGru31c4r_AehF11gNxRCo5cmYO4LY9JwCK4BGAYYCw/w640-h200/NamedPipePTH_2_Example2-738687.jpeg This project is a PoC code to use Pass-the-Hash for authentication on a local Named Pipe user Impersonation. There also is a blog post for explanation: https://s3cur3th1ssh1t.github.io/Named-Pipe-PTH/
It is heavily based on the code from the projects Invoke-SMBExec.ps1 and RoguePotato.
I faced certain Offensive Security project situations in the past, where I already had the NTLM-Hash of a
low privilegeduser account and needed a shell for that user on the current compromised system - but that was not possible with the current public tools. Imagine two more facts for a situation like that - the NTLM Hash could not be cracked and there is no process of the victim user to execute shellcode in it or to migrate into that process. This may sound like an absurd edge-case for some of you. I still experienced that multiple times. Not only in one engagement I spend a lot of time searching for the right tool/technique in that specific situation.My personal goals for a tool/technique were:
* Fully featured shell or C2-connection as the victim user-account
* It must to able to also Impersonate
low privilegedaccounts - depending on engagement goals it might be needed to access a system with a specific user such as the CEO, HR-accounts, SAP-administrators or others* The tool can be used as C2-module
The impersonated user unfortunately has no network authentication allowed, as the new process is using an Impersonation Token which is restricted. So you can only use this technique for local actions with another user.
There are two ways to use this technique. Either you can compile
\Resources\PipeServerImpersonate.slnand drop the executable on the remote host and connect to the Named Pipe via \Resources\Invoke-NamedPipePTH.ps1: http://4.bp.blogspot.com/-Tv_9d9o_-hk/YMaXEfMyOCI/AAAAAAAAbAc/5Yw7wdPLKSIZSZtjc_8ZnvOjnWcXexkmwCK4BGAYYCw/w640-h130/NamedPipePTH_1_Example1-733312.jpeg Or you can use the standalone script to stay in memory: http://3.bp.blogspot.com/-Wd1GldbL2VA/YMaXF-Tns4I/AAAAAAAAbAo/wGru31c4r_AehF11gNxRCo5cmYO4LY9JwCK4BGAYYCw/w640-h200/NamedPipePTH_2_Example2-738687.jpeg If you don't want to drop a binary for execution just pass arguments for native Windows binaries such as Powershell Invoke-ImpersonateUser-PTH -Username USERNAME -Hash NTLMHASH -Domain DOMAIN -PipeName mypipe -binary "C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -argument "-nop -w 1 -sta -enc BASEBLOB"Download NamedPipePTH___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
NamedPipePTH - Pass The Hash To A Named Pipe For Token Impersonation
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
HackMe1 for frontend devs (high seniority)
Hi !
This is my first HackMe for frontend devs.
Analyze the algorithm to find the correct box-clicking order.
The source code is fully working so there is no need to modify it.
And of course... do not use brute force.
https://github.com/lucianoaibar/HackMe1
Enjoy!
submitted by /u/lucianoaibar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
HackMe1 for frontend devs (high seniority)
Hi !
This is my first HackMe for frontend devs.
Analyze the algorithm to find the correct box-clicking order.
The source code is fully working so there is no need to modify it.
And of course... do not use brute force.
https://github.com/lucianoaibar/HackMe1
Enjoy!
submitted by /u/lucianoaibar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
HackMe1 for frontend devs (high seniority)
Hi ! This is my first HackMe for frontend devs. Analyze the algorithm to find the correct box-clicking order. The source code is fully...
hacking: security in practice
How to stop ISP tracking seaches
im looking for some advice on hiding my seaches and websites ive visited. Im using TOR currently and a VPN and i have changed my MAC address but my ISP is still seeing my searches. Does any1 know how i can avoid this? any help would be appriciated
submitted by /u/Sammy42p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to stop ISP tracking seaches
im looking for some advice on hiding my seaches and websites ive visited. Im using TOR currently and a VPN and i have changed my MAC address but my ISP is still seeing my searches. Does any1 know how i can avoid this? any help would be appriciated
submitted by /u/Sammy42p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to stop ISP tracking seaches
im looking for some advice on hiding my seaches and websites ive visited. Im using TOR currently and a VPN and i have changed my MAC address but...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
New exploit
The GIF here shows an infamous, EF-4 tornado sucking a house into its vortex, disintegrating it in the process.
In this house, there was a man. This footage is confirmed as showing the exact moment the man was killed.
Therefore, this link officially shows a real human dying without breaking discord TOS! How do I upload this exploit to the exploit database?
submitted by /u/xSerpentine
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
New exploit
The GIF here shows an infamous, EF-4 tornado sucking a house into its vortex, disintegrating it in the process.
In this house, there was a man. This footage is confirmed as showing the exact moment the man was killed.
Therefore, this link officially shows a real human dying without breaking discord TOS! How do I upload this exploit to the exploit database?
submitted by /u/xSerpentine
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
New exploit
The GIF [here](https://tenor.com/view/twister-tornado-natural-disaster-destruction-gif-5932648) shows an infamous, EF-4 tornado sucking a house...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The South Korean Atomic Research Facility Hack
https://cdn-images-1.medium.com/max/2600/0*ms2jUi5Z6hFUxj3O
Spoiler Alert: It Was North Korea
Continue reading on Medium »
The South Korean Atomic Research Facility Hack
https://cdn-images-1.medium.com/max/2600/0*ms2jUi5Z6hFUxj3O
Spoiler Alert: It Was North Korea
Continue reading on Medium »
CERTIFIED RED TEAM OPERATOR
https://www.reddit.com/r/Pentesting/comments/o4lmoq/certified_red_team_operator/
<!-- SC_OFF -->I have been trying to prepare for crto by red team security! Is there anyone who could suggest me some good resources ? <!-- SC_ON --> submitted by /u/falcnix (https://www.reddit.com/user/falcnix)
[link] (https://www.reddit.com/r/Pentesting/comments/o4lmoq/certified_red_team_operator/) [comments] (https://www.reddit.com/r/Pentesting/comments/o4lmoq/certified_red_team_operator/)
https://www.reddit.com/r/Pentesting/comments/o4lmoq/certified_red_team_operator/
<!-- SC_OFF -->I have been trying to prepare for crto by red team security! Is there anyone who could suggest me some good resources ? <!-- SC_ON --> submitted by /u/falcnix (https://www.reddit.com/user/falcnix)
[link] (https://www.reddit.com/r/Pentesting/comments/o4lmoq/certified_red_team_operator/) [comments] (https://www.reddit.com/r/Pentesting/comments/o4lmoq/certified_red_team_operator/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
The Lazarus heist: How North Korea almost pulled off a billion-dollar hack
https://external-preview.redd.it/DxipTzGjfpgZ9PLRLxNKdFtMwaHGVG9P124jjYT02iU.jpg?width=640&crop=smart&auto=webp&s=a7d82b4e8ad603547b873793191c08d4800d7cd1 submitted by /u/n1ght_w1ng08
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The Lazarus heist: How North Korea almost pulled off a billion-dollar hack
https://external-preview.redd.it/DxipTzGjfpgZ9PLRLxNKdFtMwaHGVG9P124jjYT02iU.jpg?width=640&crop=smart&auto=webp&s=a7d82b4e8ad603547b873793191c08d4800d7cd1 submitted by /u/n1ght_w1ng08
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Lazarus heist: How North Korea almost pulled off a...
Posted in r/hacking by u/n1ght_w1ng08 • 1 point and 0 comments
Phant0m | Windows Event Log Killer
https://www.reddit.com/r/redteamsec/comments/o4pjt9/phant0m_windows_event_log_killer/
submitted by /u/hlldz (https://www.reddit.com/user/hlldz)
[link] (https://github.com/hlldz/Phant0m) [comments] (https://www.reddit.com/r/redteamsec/comments/o4pjt9/phant0m_windows_event_log_killer/)
https://www.reddit.com/r/redteamsec/comments/o4pjt9/phant0m_windows_event_log_killer/
submitted by /u/hlldz (https://www.reddit.com/user/hlldz)
[link] (https://github.com/hlldz/Phant0m) [comments] (https://www.reddit.com/r/redteamsec/comments/o4pjt9/phant0m_windows_event_log_killer/)
What programming language for pen tester in application security?
https://www.reddit.com/r/Pentesting/comments/o4qd4o/what_programming_language_for_pen_tester_in/
I'm going to do my master's in another country and decided to level up my skills. I have 10 months of work experience in application security. And I know the basics of how things function in the app sec domain. So thought of learning a programming language. And after some research I came to this conclusion. Learning the basics of Javascript to understand how the application is written. Learning python in depth so that I can write/modify existing tools and automate tasks. PHP basics incase of server side understanding and exploitation. Is this a correct way to go about it or do I need to make some changes? Please let me know. submitted by /u/Sad-Maintenance-3274 (https://www.reddit.com/user/Sad-Maintenance-3274)
[link] (https://www.reddit.com/r/Pentesting/comments/o4qd4o/what_programming_language_for_pen_tester_in/) [comments] (https://www.reddit.com/r/Pentesting/comments/o4qd4o/what_programming_language_for_pen_tester_in/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/o4qd4o/what_programming_language_for_pen_tester_in/
I'm going to do my master's in another country and decided to level up my skills. I have 10 months of work experience in application security. And I know the basics of how things function in the app sec domain. So thought of learning a programming language. And after some research I came to this conclusion. Learning the basics of Javascript to understand how the application is written. Learning python in depth so that I can write/modify existing tools and automate tasks. PHP basics incase of server side understanding and exploitation. Is this a correct way to go about it or do I need to make some changes? Please let me know. submitted by /u/Sad-Maintenance-3274 (https://www.reddit.com/user/Sad-Maintenance-3274)
[link] (https://www.reddit.com/r/Pentesting/comments/o4qd4o/what_programming_language_for_pen_tester_in/) [comments] (https://www.reddit.com/r/Pentesting/comments/o4qd4o/what_programming_language_for_pen_tester_in/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What programming language for pen tester in application security?
I'm going to do my master's in another country and decided to level up my skills. I have 10 months of work experience in application security. And...
403 forbidden bypass leads to HALL OF FAME
Assalamu Alaikum peace be upon youContinue reading on InfoSec Write-ups »
Read more...
Assalamu Alaikum peace be upon youContinue reading on InfoSec Write-ups »
Read more...
Recon-ng
https://hacksheets.medium.com/recon-ng-a7f45a3d1a1e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hacksheets.medium.com/recon-ng-a7f45a3d1a1e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Recon-ng
Recon-ng is a reconnaissance tool that is used to provide a powerful environment to conduct open-source web-based reconnaissance quickly and thoroughly. It is based on Open Source Intelligence…
Continue reading on Medium » (https://hacksheets.medium.com/recon-ng-a7f45a3d1a1e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Recon-ng
Recon-ng is a reconnaissance tool that is used to provide a powerful environment to conduct open-source web-based reconnaissance quickly and thoroughly. It is based on Open Source Intelligence…