Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Distribute Your Data, Secure Your Future

https://cdn-images-1.medium.com/max/799/1*sfj60bzDFnDiH6SJ1qqv1A.jpeg
If data is the new oil and oil is the new gold, then let’s talk about data and cybersecurity in terms of gold and the famous Fort Knox…

Continue reading on Medium »
Hello everyone, Today i’m going to share how i found 2F-Authentication Bypass vulnerability in singup page and found the same…Continue reading on Medium » (https://cmuppin9.medium.com/2f-authentication-bypass-in-sign-up-page-c738de3a1a4c?source=rss------bug_bounty-5)
2F-Authentication Bypass in Sign-up Page

Hello everyone, Today i’m going to share how i found 2F-Authentication Bypass vulnerability in singup page and found the same…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HTB Spectra Walkthrough (No Metasploit)

https://cdn-images-1.medium.com/max/2100/1*x3p8DR8qDem_prxw0l7s6g.jpeg
This box is a great introduction to Wordpress information disclosure and improper configurations, an ideal machine for beginners to build…

Continue reading on Medium »
hacking: security in practice
A hat of a particular color

Is this a good place to discuss Analysis and Assessment of Gateway Process (1983) and its hacking techniques of non-electrical devices via quantum mechanical manipulation? I'm pretty sure that's phrased correctly. Thank you

submitted by /u/Snoo_82970
[link] [comments]
hacking: security in practice
Is it possible to be hacked like this?

Hello everyone, I hope this post is okay with the community guidelines.

I received a couple of days ago an email (with the title being my password) saying that someone has recorded me through my webcam (I guess on my phone since I haven't used my desktop nor have a cam on it) while being on an adult website. That being said, I have a registration on a couple of those with that same password across all of them. Also, the person said they will share a video of the screen and my webcam to my facebook friends if I don't send 5k$ in bitcoin. The person said that that while watching vids "the web broswer started out working as a Remote control Desktop with a key logged which provided them accessibility to my screen and cam". After that their software collected every one of my contacts from messenger and facebook as well as email. At the end of the email they're saying to send a message if I want evidence and they'll send the video to my 11 friends (I have a lot more than that?). I tried replying but gmail blocked me saying Message not delivered, access denied.

My question is - is that really possible? Is it just someone who has seen my password on one of those websites and is now trying to exploit me? I use an iPhone X and do all of that stuff through Firefox Focus. I've never been on any websites that are not from the very few really popular ones.

submitted by /u/NinjasInBananas
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Covenant for Pentester: Basics

This article will showcase the installation, process for compromising a Windows Machine, and the various attacks and tasks that can be performed on that compromised machine through Covenant. Table of Content<o:p· Introduction<o:p· Installation<o:p· Creating Listener<o:p· Creating Launcher<o:p· Exploitation<o:p· Post-Exploitation<o:po Task: Screenshot<o:po Task: Process-List<o:po Task: Mimikatz: SAM Dump<o:po Task: Key Logger<o:po Task: Shell Commands<o:po Task: Port Scan<o:po Task: Directory Listing<o:po Task: Download Files<o:p· Taskings<o:p· Data: Credentials<o:p· Creating Users<o:p· Conclusion<o:pIntroduction<o:pCovenant is a .NET Command and Control Framework that was created to target the invade the .NET surface and provide the ability to go offensive. It provides a collaborative C2 platform for performing Red Team Assessments. It was developed in ASP.NET Core. It provides a cross-platform application that also has an interactive interface that handles multiple users and can be accessed on a Web Browser.<o:p

In our Red Teaming articles, we have covered a huge array of Command-and-Control Frameworks. There is no shortage of these frameworks, but we always seem to be getting back to some of our reliable frameworks. Hence, when we used and tested Covenant, it felt that this is one of the frameworks that can be a default choice to many users. The things that we admired about the Covenant are:<o:p

Multi-User Support: The ability to provide a platform for collaborating data from multiple users is a key to a successful Red Team Assessment.<o:p

Interface: The ease and the clean interface that it provides is not only easy to learn and master but provide the data required at demand. The ability to operate the Server from a Web-Based interface has made it easier to use as well as provide independence to the Red Teams to be platform-independent. <o:p

Profiles: The ability to make the listeners into profiles provides control to the attacker between various implants and listeners. <o:p Installation<o:pWe will begin the installation of Covenant by first cloning all the files from the official Covenant GitHub.<o:p git clone --recurse-submodules https://github.com/cobbr/Covenant<o:phttps://1.bp.blogspot.com/-uVwnkxcQuNo/YNripWTD52I/AAAAAAAAw-4/dF422L1MiS8m4Ugyu3YQtRk5tifcHhPqQCLcBGAsYHQ/s16000/1.png We cloned the repository into a directory named Covenant. Moving into it there are multiple methods to install. We will use the docker methodology as it requires very few configurations from our end. We will build the application on docker as demonstrated below.<o:p cd Covenant/Covenant<o:pdocker build -t covenant .<o:phttps://1.bp.blogspot.com/-UuSWisSOsJQ/YNritUSQE3I/AAAAAAAAw-8/90wHB83ml48GrhUbVyHwuSR_7stydFrdwCLcBGAsYHQ/s16000/2.png After building Covenant, we now have to run the container. Here, we will specify the local ports that the container should use to run the application. Here we need to provide the absolute path to the Covenant on your machine.<o:p docker run -it -p 7443:7443 -p 80:80 -p 443:443 --name covenant -v /root/Covenant /Covenant /Data:/app/Data covenant<o:phttps://1.bp.blogspot.com/-L12kCTklbaQ/YNrixQUl4jI/AAAAAAAAw_A/S4idLsTmpMk0sW89CZ0MD0tioCU9fJi8ACLcBGAsYHQ/s16000/3.png Since our docker container is up and running we can access the Covenant Framework using the web browser. It starts on port 7433 since we mentioned this port while running docker in the previous stage. Upon the first try, it will ask the user to create an account with a username and passwor[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Covenant for Pentester: Basics This article will showcase the installation, process for compromising a Windows Machine, and the various attacks and tasks that can be performed on that compromised machine through Covenant.…
d.<o:p https://1.bp.blogspot.com/-EyBkXUzpxrI/YNri1IT_MxI/AAAAAAAAw_E/21PmLzWeVZIs-fjRD7DeZpSD6rSo33HswCLcBGAsYHQ/s16000/5.png Creating Listener<o:pAfter creating the user and logging in to the said user, we see that the framework is neatly categorized between sections and menus with a left-hand side menu. This is where we are first introduced to the Listeners. Creating a Listener is not at all difficult. As per its default configurations, the HTTP listeners will listen to the interfaces on the machine. To begin creating one we just need to click on the Create button as shown below.<o:p

<o:p https://1.bp.blogspot.com/-ash6Xp9moKg/YNri5YmBYRI/AAAAAAAAw_I/OECTLxGUkLwfFlGBsJSAbkun9SLT5T7igCLcBGAsYHQ/s16000/6.png As discussed, the Listeners listen to the HTTP protocol and the attacker can name them as per their wish. We are going to create one by the name of Ignite for now. We choose the Bind Address as 0.0.0.0 as it is the default. The Bind Port is also left default i.e., 80. The Connection port has been set to 80. We need to provide a ConnectAddress, it is important while performing a Red Team Assessment since you would require to set up the C2 environment. There is an option to set the HTTPProfile. This can administer how the network requests will interact with the Covenant. After filling in all the details, click on the Create button.<o:p https://1.bp.blogspot.com/-QEIuuwDP_ms/YNri9Wd_fxI/AAAAAAAAw_M/HbagH8n1pH0BtAnwm2N66WwuUSgJEWXkwCLcBGAsYHQ/s16000/7.png Now the Listener Section should reveal the listener that we just created. The Name can be clicked on to access the details of the listener. <o:p https://1.bp.blogspot.com/-Jfu8O28jz5E/YNrjC2Gu7WI/AAAAAAAAw_U/_KfE7eikTMwctgzOpUrlpsVqo6x5WvaKQCLcBGAsYHQ/s16000/8.png Creating Launcher<o:pNext, we require Launcher. The launcher is the payload that will execute and connect to the target while hosting the stager to establish the connection with the target machine. The available Launchers are wide-ranging from MSBuild to CScript. To perform a simple demonstration in our native environment, we ill are using a Binary Launcher.<o:p https://1.bp.blogspot.com/-mDSg7qKP4oc/YNrjHgtt8xI/AAAAAAAAw_Y/urFh8VDjQz8W3JBsNeTVw2GV1YwZVtxdwCLcBGAsYHQ/s16000/9.png As soon as we click on Binary Link in the previous stage we are provided with the form where we can configure the Launcher as per our requirement. We provide the Listener from the drop-down menu that we created. Toggling the Dot Net Version is available for the attacker. There are other options if the attacker wants to use Certificate Pinning and the amount of delay should be accepted by the launcher with the Jitter Percentage. There is also the option to schedule a Kill Date for the launcher which could come in handy. <o:p https://1.bp.blogspot.com/-R1UWM__ImMA/YNrjQS-hDrI/AAAAAAAAw_k/glI3Us8oUooofJN5YgywlRiZygsGEnZmACLcBGAsYHQ/s16000/10.png We provide all the required options and click on the Generate Button and Download button to download the Launcher to our local machine. We see that we have an executable created by the Name of GruntHTTP.exe. We can rename it before downloading as per our requirement.<o:p https://1.bp.blogspot.com/-VNHdInEGe2E/YNrjUst_EYI/AAAAAAAAw_s/XEW2kDSTeNQvh0OuY-lItaQsM6IA8BPEACLcBGAsYHQ/s16000/11.png Exploitation<o:pWe download the executable to our Local machine so that we can transfer the launcher to the target machine and execute it to get a session back to our Covenant Session. <o:p https://1.bp.blogspot.com/-8yXDKKoYwuY/YNrjb4w_I_I/AAAAAAAAw_w/tR-rI3VfpU0mL2BlNXWkce7sfiJpqM2eACLcBGAsYHQ/s16000/12.png We are not covering the method to use for transferring the launcher to the target and execution since there are endless methods to do so and you can choose your preferred method to do so. But as soon as the launcher is executed, we have what the Covenant calls Grunts and we call agents in PowerShell Empire or Session in simpler terms. The Gru[...]
Hacking Articles Tips Tricks Videos Tutorials
d.<o:p https://1.bp.blogspot.com/-EyBkXUzpxrI/YNri1IT_MxI/AAAAAAAAw_E/21PmLzWeVZIs-fjRD7DeZpSD6rSo33HswCLcBGAsYHQ/s16000/5.png Creating Listener<o:pAfter creating the user and logging in to the said user, we see that the framework is neatly categorized between…
nt section will have the Name, Hostname, User, and other information regarding the particular grunt.<o:p https://1.bp.blogspot.com/-yH5caIR2P8Y/YNrj14JPFXI/AAAAAAAAw_8/4IYDuPXzAsQxIg-sL6vSrKBIOavXGLrnwCLcBGAsYHQ/s16000/14.png Upon clicking the Grunt Name from the Grunt Section, we have detailed information about the target and among other things, we have some activities that we can perform. The Info tab shows the information about the target, then the Interact Tab provides the ability to interact with a grunt. Then we have the Task tab to perform various predefined tasks on the target machine and at the list, we have the Taskings that have a detail about the various tasks performed on the target.<o:p https://1.bp.blogspot.com/-y1HUOyQfliw/YNrj5xCTdxI/AAAAAAAAxAA/Q4yPz8A4VCMdHCo8n2UTW8DZ4NpCzCA5ACLcBGAsYHQ/s16000/16.png Post-Exploitation <o:pWe click on the Interact Tab to find a CLI interface that can be used to interact with the target with a set of predefined commands. We find the list of commands to learn using the help command.<o:p https://1.bp.blogspot.com/-egOmZz0p1OY/YNrj95TG5KI/AAAAAAAAxAE/tgO6PMfN4KU282wtUgLZQ75YOXL-hcteACLcBGAsYHQ/s16000/18.png Among the various command that we can perform on the target, we decide to perform the Screenshot first. As soon as we run the command, we see the screenshot image captured and shown in the CLI itself as demonstrated. <o:p https://1.bp.blogspot.com/-bmVjSKVKUP0/YNrkDKt6ZrI/AAAAAAAAxAI/BK0V1uNxWOcMqjnxhmZzw-LftY0m1uYugCLcBGAsYHQ/s16000/19.png <o:p
The next command on our list was to check out all the various tasks that are supposedly running on the target machine at the moment. We use the ProcessList command for extracting this information. We see that we have the details of various tasks such as the Process ID, Name, Session ID, and Owner of the process.<o:p https://1.bp.blogspot.com/-wkJEQv9kGwA/YNrkHJhHq0I/AAAAAAAAxAM/32xgyy20G9Y6a-jRkaJ22A6eIiIoml_eACLcBGAsYHQ/s16000/20.png The Covenant is integrated with Mimikatz. This means that we have all the functionality of Mimikatz without the hassle that comes with it. To demonstrate the ability, we use the SamDump command to activate Mimikatz and gather credentials from the SAM. We can see that we have the hash for the Administrator user on the target machine.<o:p https://1.bp.blogspot.com/-DIA1Dd-MnIQ/YNrkLGvKi_I/AAAAAAAAxAU/ahB_HaskTGkmHX0nix25ROS94o3OqeojACLcBGAsYHQ/s16000/21.png Next, we will be tracking the keystrokes on our target machine. We will use the Keylogger command for this task. It requires the time in seconds in which the keylogger will be recorded. We used the 120-second interval for the demonstration. We see that that the target user visits a website and enters their credentials which are logged and displayed to us.<o:p

<o:p https://1.bp.blogspot.com/-nKFPtkfOrns/YNrkaeotRPI/AAAAAAAAxAk/VhxQTYXNEk0C0j8pnwBziX7N5achLRiMgCLcBGAsYHQ/s16000/22.png We are not limited by the command that is visible when we ran the help command. We can run all the shell command on the target machine. To do this we will need to precede the command with the shellcmd command. We ran the ipconfig command on the target machine as shown in the image.<o:p https://1.bp.blogspot.com/-ImWmvyZHyZ4/YNrkeq1N8VI/AAAAAAAAxAs/w4kIeOmwd7Yrjy4mcHzm5ToVaLuZkdjIQCLcBGAsYHQ/s16000/23.png We move to the Tasks tab to see what are the various tasks that we can perform on the target machine. We see the list of various tasks in the drop-down menu labeled GruntTask. We select PortScan. We can provide the Ports or range of Ports to test. We can disable Ping as well. After filling in all details, click on the Task button.<o:p https://1.bp.blogspot.com/-g4aKHpWD35A/YNrkj8o3YoI/AAAAAAAAxAw/q0BEph4mx8cUAjnvvpO5Myqfb-iuVqJRwCLcBGAsYHQ/s16000/24.png We get back to the Interact tab to see that a PortScan has been performed on the target machine. We see that there are two ports open on the machine: 445 and 3389.<o:[...]