Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
HoneyCreds - Network Credential Injection To Detect Responder And Other Network Poisoners
http://4.bp.blogspot.com/-BJlVYH49uKs/YNEgVQkPoaI/AAAAAAAAdSc/DhcgJDPJ6-AM0XlSFVMyEnfpKv2EVeAEwCK4BGAYYCw/w640-h404/HoneyCreds_1_honeycreds_screenshot-728277.png
HoneyCreds network credential injection to detect responder and other network poisoners.
Requirements
Installation
Running
Settings
It is advised that you change these settings to best suit your environment. Note: You can use an existing account, just change the password.
Change these in honeycreds.conf
Choose a legit looking username
This can match your current Short Domain
Make this whatever you want. Note: HTTP requests will send this in plaintext
The FQDN. Leave .local at the end.
The hostname that DOES NOT EXIST but looks legit.
The log file and location
Ability to turn SMB or HTTP on or off. Set to "OFF" to turn off.
The time to pause in seconds between requests.
Download HoneyCreds
HoneyCreds - Network Credential Injection To Detect Responder And Other Network Poisoners
http://4.bp.blogspot.com/-BJlVYH49uKs/YNEgVQkPoaI/AAAAAAAAdSc/DhcgJDPJ6-AM0XlSFVMyEnfpKv2EVeAEwCK4BGAYYCw/w640-h404/HoneyCreds_1_honeycreds_screenshot-728277.png
HoneyCreds network credential injection to detect responder and other network poisoners.
Requirements
Requires Python 3.6+ (tested on Python 3.9)
smbprotocol
cffi
splunk-sdk
Installation
git clone https://github.com/Ben0xA/HoneyCreds.git
cd HoneyCreds
pip3 install -r requirements.txt
Running
python3 honeycreds.py
Settings
It is advised that you change these settings to best suit your environment. Note: You can use an existing account, just change the password.
Change these in honeycreds.conf
Choose a legit looking username
def_username = 'honeycreds' This can match your current Short Domain
def_domain = 'XQQX'Make this whatever you want. Note: HTTP requests will send this in plaintext
def_password = 'This is a honey cred account.'The FQDN. Leave .local at the end.
def_fqdn = 'xqqx.local'The hostname that DOES NOT EXIST but looks legit.
def_hostname = 'HNECRD01'The log file and location
def_logfile = 'honeycreds.log'Ability to turn SMB or HTTP on or off. Set to "OFF" to turn off.
SMB = 'ON'
HTTP = 'ON'The time to pause in seconds between requests.
SMB_SLEEP = 5
HTTP_SLEEP = 12Download HoneyCreds
Install Burp Suite [v2021.5.2] Pro on Windows
https://medium.com/@sherlock297/install-burp-suite-v2021-5-2-pro-on-windows-eaa2bcd4894f?source=rss------bug_bounty-5
Steps to Install Latest Burp Suite Pro v2021.5.2 on Windows.Continue reading on Medium » (https://medium.com/@sherlock297/install-burp-suite-v2021-5-2-pro-on-windows-eaa2bcd4894f?source=rss------bug_bounty-5)
https://medium.com/@sherlock297/install-burp-suite-v2021-5-2-pro-on-windows-eaa2bcd4894f?source=rss------bug_bounty-5
Steps to Install Latest Burp Suite Pro v2021.5.2 on Windows.Continue reading on Medium » (https://medium.com/@sherlock297/install-burp-suite-v2021-5-2-pro-on-windows-eaa2bcd4894f?source=rss------bug_bounty-5)
How to find out about vulnerabilities in web applications before attackers
Haven’t seen you for a long time, right?Continue reading on Medium »
Read more...
Haven’t seen you for a long time, right?Continue reading on Medium »
Read more...
Install Burp Suite [v2021.5.2] Pro on Windows
Steps to Install Latest Burp Suite Pro v2021.5.2 on Windows.Continue reading on Medium »
Read more...
Steps to Install Latest Burp Suite Pro v2021.5.2 on Windows.Continue reading on Medium »
Read more...
Deep Web
News articles on dark web dolls
A few weeks ago there was a post here about the famous "lolita slave dolls" and the consensus seemed to be that it was just another dark web urban myth based on the creepypasta, and all content/photos are fake. I cant find the post/comment anymore but a user mentioned this did in fact occur in Mexico a couple of years ago and dealings took place through the dark/deep web.
I've looked all over and apart from the odd youtube comment all I could find was a facebook article on the story - I am unable to read spanish so I can´t be sure if it is fake or not. I will link below.
Has anyone heard of something similar/is the story fake?
https://www.facebook.com/notihora/posts/1432680000171986
https://www.facebook.com/587859931331082/posts/encuentran-siete-jovencitas-vivas-sin-brazos-ni-piernas-en-cuernavacala-tarde-de/1539683559482043/
submitted by /u/dylstan
[link] [comments]
News articles on dark web dolls
A few weeks ago there was a post here about the famous "lolita slave dolls" and the consensus seemed to be that it was just another dark web urban myth based on the creepypasta, and all content/photos are fake. I cant find the post/comment anymore but a user mentioned this did in fact occur in Mexico a couple of years ago and dealings took place through the dark/deep web.
I've looked all over and apart from the odd youtube comment all I could find was a facebook article on the story - I am unable to read spanish so I can´t be sure if it is fake or not. I will link below.
Has anyone heard of something similar/is the story fake?
https://www.facebook.com/notihora/posts/1432680000171986
https://www.facebook.com/587859931331082/posts/encuentran-siete-jovencitas-vivas-sin-brazos-ni-piernas-en-cuernavacala-tarde-de/1539683559482043/
submitted by /u/dylstan
[link] [comments]
reddit
News articles on dark web dolls
A few weeks ago there was a post here about the famous "lolita slave dolls" and the consensus seemed to be that it was just another dark web urban...
Elevating Cross-Frame Scripting (why it matters more than experts think…)
https://ethr.medium.com/elevating-cross-frame-scripting-why-it-matters-more-than-experts-think-be6dd7ffc78c?source=rss------bug_bounty-5
https://ethr.medium.com/elevating-cross-frame-scripting-why-it-matters-more-than-experts-think-be6dd7ffc78c?source=rss------bug_bounty-5
Are you able to hijack the source of an iFrame, or execute JavaScript inside? This attack (called an XFS attack) typically is considered…Continue reading on Medium » (https://ethr.medium.com/elevating-cross-frame-scripting-why-it-matters-more-than-experts-think-be6dd7ffc78c?source=rss------bug_bounty-5)
hacking: security in practice
Script that can download videos
I was wondering if anyone on here could make a script that will download videos from a web page.
Specifically this page https://www.cbtnuggets.com/learn/it-training/playlist/nrn:playlist:certification:5e0a78b76be15b00159a71d1/1?autostart=1
I want to download the entire course so I can watch offline on my laptop.
submitted by /u/aspiller98
[link] [comments]
Script that can download videos
I was wondering if anyone on here could make a script that will download videos from a web page.
Specifically this page https://www.cbtnuggets.com/learn/it-training/playlist/nrn:playlist:certification:5e0a78b76be15b00159a71d1/1?autostart=1
I want to download the entire course so I can watch offline on my laptop.
submitted by /u/aspiller98
[link] [comments]
reddit
Script that can download videos
I was wondering if anyone on here could make a script that will download videos from a web page. Specifically this page...
Elevating Cross-Frame Scripting (why it matters more than experts think…)
Are you able to hijack the source of an iFrame, or execute JavaScript inside? This attack (called an XFS attack) typically is considered…Continue reading on Medium »
Read more...
Are you able to hijack the source of an iFrame, or execute JavaScript inside? This attack (called an XFS attack) typically is considered…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Aggrokatz : An Aggressor Plugin Extension For Cobalt Strike Which Enables Pypykatz To Interface With The Beacons Remotely
aggrokatz is an Aggressor plugin extension for CobaltStrike which enables pypykatz to interface with the beacons remotely.The current version of aggrokatz allows pypykatz to parse LSASS dump files and Registry hive files to extract credentials and other secrets stored without downloading the file and without uploading any suspicious code to the beacon (Cobalt Strike is already there anyhow). In the future this project aims […]
The post Aggrokatz : An Aggressor Plugin Extension For Cobalt Strike Which Enables Pypykatz To Interface With The Beacons Remotely appeared first on Kali Linux Tutorials.
Aggrokatz : An Aggressor Plugin Extension For Cobalt Strike Which Enables Pypykatz To Interface With The Beacons Remotely
aggrokatz is an Aggressor plugin extension for CobaltStrike which enables pypykatz to interface with the beacons remotely.The current version of aggrokatz allows pypykatz to parse LSASS dump files and Registry hive files to extract credentials and other secrets stored without downloading the file and without uploading any suspicious code to the beacon (Cobalt Strike is already there anyhow). In the future this project aims […]
The post Aggrokatz : An Aggressor Plugin Extension For Cobalt Strike Which Enables Pypykatz To Interface With The Beacons Remotely appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Researchers are developing an unhackable CPU Watch out, Intel!
https://cdn-images-1.medium.com/max/724/1*aGXnn5-RipN3OsBpEpM8Aw.jpeg
Cybersecurity researchers are developing a new CPU named Morpheus that turns a PC into a complex puzzle to prevent attackers from hacking…
Continue reading on Medium »
Researchers are developing an unhackable CPU Watch out, Intel!
https://cdn-images-1.medium.com/max/724/1*aGXnn5-RipN3OsBpEpM8Aw.jpeg
Cybersecurity researchers are developing a new CPU named Morpheus that turns a PC into a complex puzzle to prevent attackers from hacking…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top White Hat Hacker For Hire Services — White Hat Services Only
https://cdn-images-1.medium.com/max/640/1*gWTxut0K6JwBL3UrRH0SCw.jpeg
Without a doubt, RxBOT Hijacked is the best ethical hacker for hire for service information providers. Based on their high rating in the…
Continue reading on Medium »
Top White Hat Hacker For Hire Services — White Hat Services Only
https://cdn-images-1.medium.com/max/640/1*gWTxut0K6JwBL3UrRH0SCw.jpeg
Without a doubt, RxBOT Hijacked is the best ethical hacker for hire for service information providers. Based on their high rating in the…
Continue reading on Medium »