Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Heappy is an editor based on gdb/gef that helps you to handle the heap during your exploitation (https://www.kitploit.com/search/label/Exploitation) development.
The project should be considered a didactic tool useful to understand the evolution of the heap during the process life cycle. It has been created to simplify (https://www.kitploit.com/search/label/Simplify) the study of the most common heap exploitation techniques and to support you to solve some binary exploitation (https://www.kitploit.com/search/label/Binary%20Exploitation) CTFs related to this fantastic topic.
Main features
This is what Heappy implements:
take heap snapshots and compare them each other recognize immediately type and fields of heap bins search and edit heap values by decimal, hex or string find yourself with the panoramic view of the heap status take notes about a cell in the comment column enjoy the light and dark mode
Getting Started
These instructions will help you to install and run Heappy fastly.
Prerequisites
If you don't have it, install GEF in GDB: wget -q -O- https://github.com/hugsy/gef/raw/master/scripts/gef.sh | sh
md5(gef.sh): eb053864d050048cb001c80c79fde7b5
Installing
Install Node.js (https://www.kitploit.com/search/label/Node.js) and npm: apt update
sudo apt install nodejs npm
Download and install Heappy: git clone https://github.com/gand3lf/heappy
cd heappy/
npm install
Load the server inside GDB: gef➤ source /my/path/heappy/server/heappy.py
It is suggested to run the Heappy GUI after that the target heap has been initialized.
For example: gef➤ break main
gef➤ run
From another terminal launch the GUI: cd /my/path/heappy/
npm start
Have fun! 
Not yet implemented
 32-bit addresses support (coming soon)
 multiple heaps support
 gdb checkpoint integration

Download Heappy (https://github.com/gand3lf/heappy)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Rustcat : Netcat Alternative

Rustcat is a port listener that can be used for different purposes.It is basically like netcat but with fewer options. Why Use Rustcat? Serves it purpose of listening to ports Has command history It is easy to use Supports udp Uses colors Installation Debian wget https://github.com/robiot/rustcat/releases/latest/download/rustcat_amd64.debsudo apt install ./rustcat_amd64.deb Arch git clone https://aur.archlinux.org/rustcat.gitcd rustcatmakepkg -si […]

The post Rustcat : Netcat Alternative appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
FalconEye : Real-time detection software for Windows process injections

FalconEye is a windows endpoint detection software for real-time process injections. It is a kernel-mode driver that aims to catch process injections as they are happening (real-time). Since FalconEye runs in kernel mode, it provides a stronger and reliable defense against process injection techniques that try to evade various user-mode hooks. You can check our […]

The post FalconEye : Real-time detection software for Windows process injections appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
RdpCacheStitcher : RdpCacheStitcher Is A Tool That Supports Forensic Analysts

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps. Using raw RDP cache tile bitmaps extracted by tools like e.g. ANSSI’s BMC-Tools (https://github.com/ANSSI-FR/bmc-tools) as input, it provides a graphical user interface and several placement heuristics for stitching tiles together so that meaningful images or even full screenshots can be reconstructed. […]

The post RdpCacheStitcher : RdpCacheStitcher Is A Tool That Supports Forensic Analysts appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Heappy - A Happy Heap Editor To Support Your Exploitation Process

http://2.bp.blogspot.com/-997OcegewTs/YNEeshXoYQI/AAAAAAAAdM8/yN51-8Td_S4KngHVjwjTjOlQcFRpmDDmACK4BGAYYCw/w640-h442/heappy_1-713884.png

Heappy is an editor based on gdb/gef that helps you to handle the heap during your exploitation development.
The project should be considered a didactic tool useful to understand the evolution of the heap during the process life cycle. It has been created to simplify the study of the most common heap exploitation techniques and to support you to solve some binary exploitation CTFs related to this fantastic topic.
Main features

This is what Heappy implements:
take heap snapshots and compare them each other

recognize immediately type and fields of heap bins

search and edit heap values by decimal, hex or string

find yourself with the panoramic view of the heap status

take notes about a cell in the comment column

enjoy the light and dark mode
Getting Started

These instructions will help you to install and run Heappy fastly.

Prerequisites

If you don't have it, install GEF in GDB:

wget -q -O- https://github.com/hugsy/gef/raw/master/scripts/gef.sh | sh


md5(gef.sh): eb053864d050048cb001c80c79fde7b5

Installing

Install Node.js and npm:

apt update
sudo apt install nodejs npm


Download and install Heappy:

git clone https://github.com/gand3lf/heappy
cd heappy/
npm install


Load the server inside GDB:

gef➤ source /my/path/heappy/server/heappy.py


It is suggested to run the Heappy GUI after that the target heap has been initialized.
For example:

gef➤ break main
gef➤ run


From another terminal launch the GUI:

cd /my/path/heappy/
npm start


Have fun!



Not yet implemented

32-bit addresses support (coming soon)


multiple heaps support


gdb checkpoint integration
Download Heappy
hacking: security in practice
Can conversations recorded without my consent be used against me in court?

Sorry I don’t know if this is the right place to ask this but… that’s basically what I want to know. My ex hacked my iPhone and is trying to use recordings he obtained through hacking to get my children taken away

submitted by /u/Rumanda
[link] [comments]
hacking: security in practice
Airodump-ng won't show stations on some networks

So I've just downloaded aircrack and it's not working on some networks. I have the rt5372 chipset. I've tried airodump on one network and it won't show any stations and my phone is hooked up to it so I know it's there. But I've tried another where my phone is hooked up and it will show it. I've tried to reinstall aircrack and I've tried to upgrade kali. I've also tried it on my manjaro box as well and it's the same results. My guess is that I need to install an older version of aircrack. Does anyone have any fixes? Thank you.

submitted by /u/grim_ops
[link] [comments]
hacking: security in practice
Hello everyone

A recent event has occurred in regards to A video game called Black Ops 3 and YouTube Stars.

Essentially, there is these YouTubers that record gameplay of “custom BO3 zombies.” Some do it for a living, and some play other games as well. This gives people, such as me; the entertainment we subscribed to them for.

Well, recently, a group of hackers have found code in the game that allows them to crash anyone’s game just by knowing their “steam id” or in other words, their username. They have been targeting these YouTubers, such as NoahJ456, creating quite the hit in revenue from his videos.

If there is any tips you have for them, please let me or them know.

The game developers are not prioritizing the game because it is a few years old, but the only one with this “custom zombies” game mode.

I will put a link of the video in the description.

submitted by /u/STRAlGHTCANCER
[link] [comments]
hacking: security in practice
Google Issues

I'm looking to get back into my old email after someone hacked it,



google keeps saying the following



An email with a verification code was just sent to wef••••••••••••@pro•••••••.com



what email is this? Where can i acquire the tools to hack back my email or that one to get my email back? Any form of help would be lovely thank you

submitted by /u/Ominosu_Nebyura
[link] [comments]
hacking: security in practice
COM ports not showing up

I'm setting up this esp8266 but the pc doesn't detect any COM device which is weird because It should detect the esp, I go check into device manager and there's nothing there, how do I fix

submitted by /u/xX_zEnUs_Xx
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Digital Forensics in Medical Devices

Hi, I’m a researcher with the University of Minnesota working on a project related to digital forensics in Medical devices. We were hoping to get some more insight into the digital forensics field. If you have any insights in forensics, cybersecurity or medical devices and would be willing to fill out the following form that would be greatly appreciated.

Digital Forensics Survey

submitted by /u/Nosrack_
[link] [comments]
hacking: security in practice
Bypassing geo-blocking

My company issues pre-built laptops which use certificate based VPNs to connect to the infrastructure. Furthermore, there is IP based geo-blocking in place to deter outside access. The only possible thing that can be changed are the WiFi settings to connect to a home WiFi network for remote working. No ethernet port. I'm of the opinion that it should be possible to setup a secondary device to create a WiFi that tunnels all traffic through a VPN to a location of my choosing. My boss thinks it's not possible so I would like to work up a proof of concept to show that it's not as safe as they think.

Does anyone have any pointers/ideas/guides how I could set this up with e.g. a 2nd laptop acting as the gateway device?

Thanks for any input

submitted by /u/Handsome_Me
[link] [comments]