Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HTB Spectra Walkthrough (No Metasploit)
https://cdn-images-1.medium.com/max/2100/1*x3p8DR8qDem_prxw0l7s6g.jpeg
This box is a great introduction to Wordpress information disclosure and improper configurations, an ideal machine for beginners to build…
Continue reading on Medium »
HTB Spectra Walkthrough (No Metasploit)
https://cdn-images-1.medium.com/max/2100/1*x3p8DR8qDem_prxw0l7s6g.jpeg
This box is a great introduction to Wordpress information disclosure and improper configurations, an ideal machine for beginners to build…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Privilege escalation through insecure configuration.
https://cdn-images-1.medium.com/max/1080/1*p2EqqWqhc_UZc9tWNnUUqA.jpeg
First of all, let’s deal with the insecure configuration. To begin with, IT professionals often use manuals and resources like…
Continue reading on Medium »
Privilege escalation through insecure configuration.
https://cdn-images-1.medium.com/max/1080/1*p2EqqWqhc_UZc9tWNnUUqA.jpeg
First of all, let’s deal with the insecure configuration. To begin with, IT professionals often use manuals and resources like…
Continue reading on Medium »
hacking: security in practice
A hat of a particular color
Is this a good place to discuss Analysis and Assessment of Gateway Process (1983) and its hacking techniques of non-electrical devices via quantum mechanical manipulation? I'm pretty sure that's phrased correctly. Thank you
submitted by /u/Snoo_82970
[link] [comments]
A hat of a particular color
Is this a good place to discuss Analysis and Assessment of Gateway Process (1983) and its hacking techniques of non-electrical devices via quantum mechanical manipulation? I'm pretty sure that's phrased correctly. Thank you
submitted by /u/Snoo_82970
[link] [comments]
reddit
A hat of a particular color
Is this a good place to discuss Analysis and Assessment of Gateway Process (1983) and its hacking techniques of non-electrical devices via quantum...
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
CSC CTF 2021 — Flag Shop (Reverse Engineering Android)(Smali Patch) #2
https://cdn-images-1.medium.com/max/600/1*hUUkpx2bkhTTMCP-29DGEw.gif
Pada part kali ini, saya sebagai penulis ingin berbagi beberapa cara bagaimana dengan uang 150 kita dapat membeli semua flag. Apakah kita…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CSC CTF 2021 — Flag Shop (Reverse Engineering Android)(Smali Patch) #2
https://cdn-images-1.medium.com/max/600/1*hUUkpx2bkhTTMCP-29DGEw.gif
Pada part kali ini, saya sebagai penulis ingin berbagi beberapa cara bagaimana dengan uang 150 kita dapat membeli semua flag. Apakah kita…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSC CTF 2021 — Flag Shop (Reverse Engineering Android)(Smali Patch) #2
Pada part kali ini, saya sebagai penulis ingin berbagi beberapa cara bagaimana dengan uang 150 kita dapat membeli semua flag. Apakah kita…
hacking: security in practice
Is it possible to be hacked like this?
Hello everyone, I hope this post is okay with the community guidelines.
I received a couple of days ago an email (with the title being my password) saying that someone has recorded me through my webcam (I guess on my phone since I haven't used my desktop nor have a cam on it) while being on an adult website. That being said, I have a registration on a couple of those with that same password across all of them. Also, the person said they will share a video of the screen and my webcam to my facebook friends if I don't send 5k$ in bitcoin. The person said that that while watching vids "the web broswer started out working as a Remote control Desktop with a key logged which provided them accessibility to my screen and cam". After that their software collected every one of my contacts from messenger and facebook as well as email. At the end of the email they're saying to send a message if I want evidence and they'll send the video to my 11 friends (I have a lot more than that?). I tried replying but gmail blocked me saying Message not delivered, access denied.
My question is - is that really possible? Is it just someone who has seen my password on one of those websites and is now trying to exploit me? I use an iPhone X and do all of that stuff through Firefox Focus. I've never been on any websites that are not from the very few really popular ones.
submitted by /u/NinjasInBananas
[link] [comments]
Is it possible to be hacked like this?
Hello everyone, I hope this post is okay with the community guidelines.
I received a couple of days ago an email (with the title being my password) saying that someone has recorded me through my webcam (I guess on my phone since I haven't used my desktop nor have a cam on it) while being on an adult website. That being said, I have a registration on a couple of those with that same password across all of them. Also, the person said they will share a video of the screen and my webcam to my facebook friends if I don't send 5k$ in bitcoin. The person said that that while watching vids "the web broswer started out working as a Remote control Desktop with a key logged which provided them accessibility to my screen and cam". After that their software collected every one of my contacts from messenger and facebook as well as email. At the end of the email they're saying to send a message if I want evidence and they'll send the video to my 11 friends (I have a lot more than that?). I tried replying but gmail blocked me saying Message not delivered, access denied.
My question is - is that really possible? Is it just someone who has seen my password on one of those websites and is now trying to exploit me? I use an iPhone X and do all of that stuff through Firefox Focus. I've never been on any websites that are not from the very few really popular ones.
submitted by /u/NinjasInBananas
[link] [comments]
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Covenant for Pentester: Basics
This article will showcase the installation, process for compromising a Windows Machine, and the various attacks and tasks that can be performed on that compromised machine through Covenant. Table of Content<o:p· Introduction<o:p· Installation<o:p· Creating Listener<o:p· Creating Launcher<o:p· Exploitation<o:p· Post-Exploitation<o:po Task: Screenshot<o:po Task: Process-List<o:po Task: Mimikatz: SAM Dump<o:po Task: Key Logger<o:po Task: Shell Commands<o:po Task: Port Scan<o:po Task: Directory Listing<o:po Task: Download Files<o:p· Taskings<o:p· Data: Credentials<o:p· Creating Users<o:p· Conclusion<o:pIntroduction<o:pCovenant is a .NET Command and Control Framework that was created to target the invade the .NET surface and provide the ability to go offensive. It provides a collaborative C2 platform for performing Red Team Assessments. It was developed in ASP.NET Core. It provides a cross-platform application that also has an interactive interface that handles multiple users and can be accessed on a Web Browser.<o:p
In our Red Teaming articles, we have covered a huge array of Command-and-Control Frameworks. There is no shortage of these frameworks, but we always seem to be getting back to some of our reliable frameworks. Hence, when we used and tested Covenant, it felt that this is one of the frameworks that can be a default choice to many users. The things that we admired about the Covenant are:<o:p
Multi-User Support: The ability to provide a platform for collaborating data from multiple users is a key to a successful Red Team Assessment.<o:p
Interface: The ease and the clean interface that it provides is not only easy to learn and master but provide the data required at demand. The ability to operate the Server from a Web-Based interface has made it easier to use as well as provide independence to the Red Teams to be platform-independent. <o:p
Profiles: The ability to make the listeners into profiles provides control to the attacker between various implants and listeners. <o:p Installation<o:pWe will begin the installation of Covenant by first cloning all the files from the official Covenant GitHub.<o:p git clone --recurse-submodules https://github.com/cobbr/Covenant<o:phttps://1.bp.blogspot.com/-uVwnkxcQuNo/YNripWTD52I/AAAAAAAAw-4/dF422L1MiS8m4Ugyu3YQtRk5tifcHhPqQCLcBGAsYHQ/s16000/1.png We cloned the repository into a directory named Covenant. Moving into it there are multiple methods to install. We will use the docker methodology as it requires very few configurations from our end. We will build the application on docker as demonstrated below.<o:p cd Covenant/Covenant<o:pdocker build -t covenant .<o:phttps://1.bp.blogspot.com/-UuSWisSOsJQ/YNritUSQE3I/AAAAAAAAw-8/90wHB83ml48GrhUbVyHwuSR_7stydFrdwCLcBGAsYHQ/s16000/2.png After building Covenant, we now have to run the container. Here, we will specify the local ports that the container should use to run the application. Here we need to provide the absolute path to the Covenant on your machine.<o:p docker run -it -p 7443:7443 -p 80:80 -p 443:443 --name covenant -v /root/Covenant /Covenant /Data:/app/Data covenant<o:phttps://1.bp.blogspot.com/-L12kCTklbaQ/YNrixQUl4jI/AAAAAAAAw_A/S4idLsTmpMk0sW89CZ0MD0tioCU9fJi8ACLcBGAsYHQ/s16000/3.png Since our docker container is up and running we can access the Covenant Framework using the web browser. It starts on port 7433 since we mentioned this port while running docker in the previous stage. Upon the first try, it will ask the user to create an account with a username and passwor[...]
Covenant for Pentester: Basics
This article will showcase the installation, process for compromising a Windows Machine, and the various attacks and tasks that can be performed on that compromised machine through Covenant. Table of Content<o:p· Introduction<o:p· Installation<o:p· Creating Listener<o:p· Creating Launcher<o:p· Exploitation<o:p· Post-Exploitation<o:po Task: Screenshot<o:po Task: Process-List<o:po Task: Mimikatz: SAM Dump<o:po Task: Key Logger<o:po Task: Shell Commands<o:po Task: Port Scan<o:po Task: Directory Listing<o:po Task: Download Files<o:p· Taskings<o:p· Data: Credentials<o:p· Creating Users<o:p· Conclusion<o:pIntroduction<o:pCovenant is a .NET Command and Control Framework that was created to target the invade the .NET surface and provide the ability to go offensive. It provides a collaborative C2 platform for performing Red Team Assessments. It was developed in ASP.NET Core. It provides a cross-platform application that also has an interactive interface that handles multiple users and can be accessed on a Web Browser.<o:p
In our Red Teaming articles, we have covered a huge array of Command-and-Control Frameworks. There is no shortage of these frameworks, but we always seem to be getting back to some of our reliable frameworks. Hence, when we used and tested Covenant, it felt that this is one of the frameworks that can be a default choice to many users. The things that we admired about the Covenant are:<o:p
Multi-User Support: The ability to provide a platform for collaborating data from multiple users is a key to a successful Red Team Assessment.<o:p
Interface: The ease and the clean interface that it provides is not only easy to learn and master but provide the data required at demand. The ability to operate the Server from a Web-Based interface has made it easier to use as well as provide independence to the Red Teams to be platform-independent. <o:p
Profiles: The ability to make the listeners into profiles provides control to the attacker between various implants and listeners. <o:p Installation<o:pWe will begin the installation of Covenant by first cloning all the files from the official Covenant GitHub.<o:p git clone --recurse-submodules https://github.com/cobbr/Covenant<o:phttps://1.bp.blogspot.com/-uVwnkxcQuNo/YNripWTD52I/AAAAAAAAw-4/dF422L1MiS8m4Ugyu3YQtRk5tifcHhPqQCLcBGAsYHQ/s16000/1.png We cloned the repository into a directory named Covenant. Moving into it there are multiple methods to install. We will use the docker methodology as it requires very few configurations from our end. We will build the application on docker as demonstrated below.<o:p cd Covenant/Covenant<o:pdocker build -t covenant .<o:phttps://1.bp.blogspot.com/-UuSWisSOsJQ/YNritUSQE3I/AAAAAAAAw-8/90wHB83ml48GrhUbVyHwuSR_7stydFrdwCLcBGAsYHQ/s16000/2.png After building Covenant, we now have to run the container. Here, we will specify the local ports that the container should use to run the application. Here we need to provide the absolute path to the Covenant on your machine.<o:p docker run -it -p 7443:7443 -p 80:80 -p 443:443 --name covenant -v /root/Covenant /Covenant /Data:/app/Data covenant<o:phttps://1.bp.blogspot.com/-L12kCTklbaQ/YNrixQUl4jI/AAAAAAAAw_A/S4idLsTmpMk0sW89CZ0MD0tioCU9fJi8ACLcBGAsYHQ/s16000/3.png Since our docker container is up and running we can access the Covenant Framework using the web browser. It starts on port 7433 since we mentioned this port while running docker in the previous stage. Upon the first try, it will ask the user to create an account with a username and passwor[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Covenant for Pentester: Basics This article will showcase the installation, process for compromising a Windows Machine, and the various attacks and tasks that can be performed on that compromised machine through Covenant.…
d.<o:p https://1.bp.blogspot.com/-EyBkXUzpxrI/YNri1IT_MxI/AAAAAAAAw_E/21PmLzWeVZIs-fjRD7DeZpSD6rSo33HswCLcBGAsYHQ/s16000/5.png Creating Listener<o:pAfter creating the user and logging in to the said user, we see that the framework is neatly categorized between sections and menus with a left-hand side menu. This is where we are first introduced to the Listeners. Creating a Listener is not at all difficult. As per its default configurations, the HTTP listeners will listen to the interfaces on the machine. To begin creating one we just need to click on the Create button as shown below.<o:p
<o:p https://1.bp.blogspot.com/-ash6Xp9moKg/YNri5YmBYRI/AAAAAAAAw_I/OECTLxGUkLwfFlGBsJSAbkun9SLT5T7igCLcBGAsYHQ/s16000/6.png As discussed, the Listeners listen to the HTTP protocol and the attacker can name them as per their wish. We are going to create one by the name of Ignite for now. We choose the Bind Address as 0.0.0.0 as it is the default. The Bind Port is also left default i.e., 80. The Connection port has been set to 80. We need to provide a ConnectAddress, it is important while performing a Red Team Assessment since you would require to set up the C2 environment. There is an option to set the HTTPProfile. This can administer how the network requests will interact with the Covenant. After filling in all the details, click on the Create button.<o:p https://1.bp.blogspot.com/-QEIuuwDP_ms/YNri9Wd_fxI/AAAAAAAAw_M/HbagH8n1pH0BtAnwm2N66WwuUSgJEWXkwCLcBGAsYHQ/s16000/7.png Now the Listener Section should reveal the listener that we just created. The Name can be clicked on to access the details of the listener. <o:p https://1.bp.blogspot.com/-Jfu8O28jz5E/YNrjC2Gu7WI/AAAAAAAAw_U/_KfE7eikTMwctgzOpUrlpsVqo6x5WvaKQCLcBGAsYHQ/s16000/8.png Creating Launcher<o:pNext, we require Launcher. The launcher is the payload that will execute and connect to the target while hosting the stager to establish the connection with the target machine. The available Launchers are wide-ranging from MSBuild to CScript. To perform a simple demonstration in our native environment, we ill are using a Binary Launcher.<o:p https://1.bp.blogspot.com/-mDSg7qKP4oc/YNrjHgtt8xI/AAAAAAAAw_Y/urFh8VDjQz8W3JBsNeTVw2GV1YwZVtxdwCLcBGAsYHQ/s16000/9.png As soon as we click on Binary Link in the previous stage we are provided with the form where we can configure the Launcher as per our requirement. We provide the Listener from the drop-down menu that we created. Toggling the Dot Net Version is available for the attacker. There are other options if the attacker wants to use Certificate Pinning and the amount of delay should be accepted by the launcher with the Jitter Percentage. There is also the option to schedule a Kill Date for the launcher which could come in handy. <o:p https://1.bp.blogspot.com/-R1UWM__ImMA/YNrjQS-hDrI/AAAAAAAAw_k/glI3Us8oUooofJN5YgywlRiZygsGEnZmACLcBGAsYHQ/s16000/10.png We provide all the required options and click on the Generate Button and Download button to download the Launcher to our local machine. We see that we have an executable created by the Name of GruntHTTP.exe. We can rename it before downloading as per our requirement.<o:p https://1.bp.blogspot.com/-VNHdInEGe2E/YNrjUst_EYI/AAAAAAAAw_s/XEW2kDSTeNQvh0OuY-lItaQsM6IA8BPEACLcBGAsYHQ/s16000/11.png Exploitation<o:pWe download the executable to our Local machine so that we can transfer the launcher to the target machine and execute it to get a session back to our Covenant Session. <o:p https://1.bp.blogspot.com/-8yXDKKoYwuY/YNrjb4w_I_I/AAAAAAAAw_w/tR-rI3VfpU0mL2BlNXWkce7sfiJpqM2eACLcBGAsYHQ/s16000/12.png We are not covering the method to use for transferring the launcher to the target and execution since there are endless methods to do so and you can choose your preferred method to do so. But as soon as the launcher is executed, we have what the Covenant calls Grunts and we call agents in PowerShell Empire or Session in simpler terms. The Gru[...]
<o:p https://1.bp.blogspot.com/-ash6Xp9moKg/YNri5YmBYRI/AAAAAAAAw_I/OECTLxGUkLwfFlGBsJSAbkun9SLT5T7igCLcBGAsYHQ/s16000/6.png As discussed, the Listeners listen to the HTTP protocol and the attacker can name them as per their wish. We are going to create one by the name of Ignite for now. We choose the Bind Address as 0.0.0.0 as it is the default. The Bind Port is also left default i.e., 80. The Connection port has been set to 80. We need to provide a ConnectAddress, it is important while performing a Red Team Assessment since you would require to set up the C2 environment. There is an option to set the HTTPProfile. This can administer how the network requests will interact with the Covenant. After filling in all the details, click on the Create button.<o:p https://1.bp.blogspot.com/-QEIuuwDP_ms/YNri9Wd_fxI/AAAAAAAAw_M/HbagH8n1pH0BtAnwm2N66WwuUSgJEWXkwCLcBGAsYHQ/s16000/7.png Now the Listener Section should reveal the listener that we just created. The Name can be clicked on to access the details of the listener. <o:p https://1.bp.blogspot.com/-Jfu8O28jz5E/YNrjC2Gu7WI/AAAAAAAAw_U/_KfE7eikTMwctgzOpUrlpsVqo6x5WvaKQCLcBGAsYHQ/s16000/8.png Creating Launcher<o:pNext, we require Launcher. The launcher is the payload that will execute and connect to the target while hosting the stager to establish the connection with the target machine. The available Launchers are wide-ranging from MSBuild to CScript. To perform a simple demonstration in our native environment, we ill are using a Binary Launcher.<o:p https://1.bp.blogspot.com/-mDSg7qKP4oc/YNrjHgtt8xI/AAAAAAAAw_Y/urFh8VDjQz8W3JBsNeTVw2GV1YwZVtxdwCLcBGAsYHQ/s16000/9.png As soon as we click on Binary Link in the previous stage we are provided with the form where we can configure the Launcher as per our requirement. We provide the Listener from the drop-down menu that we created. Toggling the Dot Net Version is available for the attacker. There are other options if the attacker wants to use Certificate Pinning and the amount of delay should be accepted by the launcher with the Jitter Percentage. There is also the option to schedule a Kill Date for the launcher which could come in handy. <o:p https://1.bp.blogspot.com/-R1UWM__ImMA/YNrjQS-hDrI/AAAAAAAAw_k/glI3Us8oUooofJN5YgywlRiZygsGEnZmACLcBGAsYHQ/s16000/10.png We provide all the required options and click on the Generate Button and Download button to download the Launcher to our local machine. We see that we have an executable created by the Name of GruntHTTP.exe. We can rename it before downloading as per our requirement.<o:p https://1.bp.blogspot.com/-VNHdInEGe2E/YNrjUst_EYI/AAAAAAAAw_s/XEW2kDSTeNQvh0OuY-lItaQsM6IA8BPEACLcBGAsYHQ/s16000/11.png Exploitation<o:pWe download the executable to our Local machine so that we can transfer the launcher to the target machine and execute it to get a session back to our Covenant Session. <o:p https://1.bp.blogspot.com/-8yXDKKoYwuY/YNrjb4w_I_I/AAAAAAAAw_w/tR-rI3VfpU0mL2BlNXWkce7sfiJpqM2eACLcBGAsYHQ/s16000/12.png We are not covering the method to use for transferring the launcher to the target and execution since there are endless methods to do so and you can choose your preferred method to do so. But as soon as the launcher is executed, we have what the Covenant calls Grunts and we call agents in PowerShell Empire or Session in simpler terms. The Gru[...]
Hacking Articles Tips Tricks Videos Tutorials
d.<o:p https://1.bp.blogspot.com/-EyBkXUzpxrI/YNri1IT_MxI/AAAAAAAAw_E/21PmLzWeVZIs-fjRD7DeZpSD6rSo33HswCLcBGAsYHQ/s16000/5.png Creating Listener<o:pAfter creating the user and logging in to the said user, we see that the framework is neatly categorized between…
nt section will have the Name, Hostname, User, and other information regarding the particular grunt.<o:p https://1.bp.blogspot.com/-yH5caIR2P8Y/YNrj14JPFXI/AAAAAAAAw_8/4IYDuPXzAsQxIg-sL6vSrKBIOavXGLrnwCLcBGAsYHQ/s16000/14.png Upon clicking the Grunt Name from the Grunt Section, we have detailed information about the target and among other things, we have some activities that we can perform. The Info tab shows the information about the target, then the Interact Tab provides the ability to interact with a grunt. Then we have the Task tab to perform various predefined tasks on the target machine and at the list, we have the Taskings that have a detail about the various tasks performed on the target.<o:p https://1.bp.blogspot.com/-y1HUOyQfliw/YNrj5xCTdxI/AAAAAAAAxAA/Q4yPz8A4VCMdHCo8n2UTW8DZ4NpCzCA5ACLcBGAsYHQ/s16000/16.png Post-Exploitation <o:pWe click on the Interact Tab to find a CLI interface that can be used to interact with the target with a set of predefined commands. We find the list of commands to learn using the help command.<o:p https://1.bp.blogspot.com/-egOmZz0p1OY/YNrj95TG5KI/AAAAAAAAxAE/tgO6PMfN4KU282wtUgLZQ75YOXL-hcteACLcBGAsYHQ/s16000/18.png Among the various command that we can perform on the target, we decide to perform the Screenshot first. As soon as we run the command, we see the screenshot image captured and shown in the CLI itself as demonstrated. <o:p https://1.bp.blogspot.com/-bmVjSKVKUP0/YNrkDKt6ZrI/AAAAAAAAxAI/BK0V1uNxWOcMqjnxhmZzw-LftY0m1uYugCLcBGAsYHQ/s16000/19.png <o:p
The next command on our list was to check out all the various tasks that are supposedly running on the target machine at the moment. We use the ProcessList command for extracting this information. We see that we have the details of various tasks such as the Process ID, Name, Session ID, and Owner of the process.<o:p https://1.bp.blogspot.com/-wkJEQv9kGwA/YNrkHJhHq0I/AAAAAAAAxAM/32xgyy20G9Y6a-jRkaJ22A6eIiIoml_eACLcBGAsYHQ/s16000/20.png The Covenant is integrated with Mimikatz. This means that we have all the functionality of Mimikatz without the hassle that comes with it. To demonstrate the ability, we use the SamDump command to activate Mimikatz and gather credentials from the SAM. We can see that we have the hash for the Administrator user on the target machine.<o:p https://1.bp.blogspot.com/-DIA1Dd-MnIQ/YNrkLGvKi_I/AAAAAAAAxAU/ahB_HaskTGkmHX0nix25ROS94o3OqeojACLcBGAsYHQ/s16000/21.png Next, we will be tracking the keystrokes on our target machine. We will use the Keylogger command for this task. It requires the time in seconds in which the keylogger will be recorded. We used the 120-second interval for the demonstration. We see that that the target user visits a website and enters their credentials which are logged and displayed to us.<o:p
<o:p https://1.bp.blogspot.com/-nKFPtkfOrns/YNrkaeotRPI/AAAAAAAAxAk/VhxQTYXNEk0C0j8pnwBziX7N5achLRiMgCLcBGAsYHQ/s16000/22.png We are not limited by the command that is visible when we ran the help command. We can run all the shell command on the target machine. To do this we will need to precede the command with the shellcmd command. We ran the ipconfig command on the target machine as shown in the image.<o:p https://1.bp.blogspot.com/-ImWmvyZHyZ4/YNrkeq1N8VI/AAAAAAAAxAs/w4kIeOmwd7Yrjy4mcHzm5ToVaLuZkdjIQCLcBGAsYHQ/s16000/23.png We move to the Tasks tab to see what are the various tasks that we can perform on the target machine. We see the list of various tasks in the drop-down menu labeled GruntTask. We select PortScan. We can provide the Ports or range of Ports to test. We can disable Ping as well. After filling in all details, click on the Task button.<o:p https://1.bp.blogspot.com/-g4aKHpWD35A/YNrkj8o3YoI/AAAAAAAAxAw/q0BEph4mx8cUAjnvvpO5Myqfb-iuVqJRwCLcBGAsYHQ/s16000/24.png We get back to the Interact tab to see that a PortScan has been performed on the target machine. We see that there are two ports open on the machine: 445 and 3389.<o:[...]
The next command on our list was to check out all the various tasks that are supposedly running on the target machine at the moment. We use the ProcessList command for extracting this information. We see that we have the details of various tasks such as the Process ID, Name, Session ID, and Owner of the process.<o:p https://1.bp.blogspot.com/-wkJEQv9kGwA/YNrkHJhHq0I/AAAAAAAAxAM/32xgyy20G9Y6a-jRkaJ22A6eIiIoml_eACLcBGAsYHQ/s16000/20.png The Covenant is integrated with Mimikatz. This means that we have all the functionality of Mimikatz without the hassle that comes with it. To demonstrate the ability, we use the SamDump command to activate Mimikatz and gather credentials from the SAM. We can see that we have the hash for the Administrator user on the target machine.<o:p https://1.bp.blogspot.com/-DIA1Dd-MnIQ/YNrkLGvKi_I/AAAAAAAAxAU/ahB_HaskTGkmHX0nix25ROS94o3OqeojACLcBGAsYHQ/s16000/21.png Next, we will be tracking the keystrokes on our target machine. We will use the Keylogger command for this task. It requires the time in seconds in which the keylogger will be recorded. We used the 120-second interval for the demonstration. We see that that the target user visits a website and enters their credentials which are logged and displayed to us.<o:p
<o:p https://1.bp.blogspot.com/-nKFPtkfOrns/YNrkaeotRPI/AAAAAAAAxAk/VhxQTYXNEk0C0j8pnwBziX7N5achLRiMgCLcBGAsYHQ/s16000/22.png We are not limited by the command that is visible when we ran the help command. We can run all the shell command on the target machine. To do this we will need to precede the command with the shellcmd command. We ran the ipconfig command on the target machine as shown in the image.<o:p https://1.bp.blogspot.com/-ImWmvyZHyZ4/YNrkeq1N8VI/AAAAAAAAxAs/w4kIeOmwd7Yrjy4mcHzm5ToVaLuZkdjIQCLcBGAsYHQ/s16000/23.png We move to the Tasks tab to see what are the various tasks that we can perform on the target machine. We see the list of various tasks in the drop-down menu labeled GruntTask. We select PortScan. We can provide the Ports or range of Ports to test. We can disable Ping as well. After filling in all details, click on the Task button.<o:p https://1.bp.blogspot.com/-g4aKHpWD35A/YNrkj8o3YoI/AAAAAAAAxAw/q0BEph4mx8cUAjnvvpO5Myqfb-iuVqJRwCLcBGAsYHQ/s16000/24.png We get back to the Interact tab to see that a PortScan has been performed on the target machine. We see that there are two ports open on the machine: 445 and 3389.<o:[...]
Hacking Articles Tips Tricks Videos Tutorials
nt section will have the Name, Hostname, User, and other information regarding the particular grunt.<o:p https://1.bp.blogspot.com/-yH5caIR2P8Y/YNrj14JPFXI/AAAAAAAAw_8/4IYDuPXzAsQxIg-sL6vSrKBIOavXGLrnwCLcBGAsYHQ/s16000/14.png Upon clicking the Grunt Name from…
p https://1.bp.blogspot.com/-F8uwHqqnBrU/YNrkoTuwRfI/AAAAAAAAxA0/-9aaRwEhK3QEOyUXIRgGkKS9kJNCbHSfwCLcBGAsYHQ/s16000/25.png The next task we can perform is List Directory. It will list the content of the requested directory. It defaults to the current directory if no path is provided. We clicked on the Task button to perform the task on the target machine.<o:p https://1.bp.blogspot.com/-gw2wcdrQ7WM/YNrkuYup6jI/AAAAAAAAxA4/Ygn6pGj7-Rc_N5KyKaircu5q645GURnRwCLcBGAsYHQ/s16000/26.png We see that the current directory turned out to be the Downloads directory for the user Raj. We see the Size of files, Creation Time, and Last Accessed Time for various files and directories inside the selected directory. <o:p https://1.bp.blogspot.com/-qEv0i1bbnFM/YNrkyWqWjZI/AAAAAAAAxBA/ZUtq_Yl-gR0k1p1SZ-K_H46UZlpzeMRMQCLcBGAsYHQ/s16000/27.png After listing the contents, we found a particular file that we need to extract from the target machine. We can use the Download task to get that file transferred to our local machine. It requires the name of the file that we need to download. In our demonstration, we are downloading the Sysmon.zip file from the current directory. <o:p https://1.bp.blogspot.com/-G1OhIH-lJv8/YNrk60KRrFI/AAAAAAAAxBM/4fHJI6k3KSQ-Znx5sYrE8xlFqTqA9AkeACLcBGAsYHQ/s16000/28.png To access the file that we downloading, we need to move to the Data section of the Covenant Menu. Here we see the Downloads section under the Downloads Tab. We see the file name and size of the file that we requested. We have the Download button that will get the file to our local machine.<o:p https://1.bp.blogspot.com/-Me_v5BBanzM/YNrk_9jv6RI/AAAAAAAAxBQ/Z1hJjujjHMIaVpUFP2sHg1s1vCZLqS32ACLcBGAsYHQ/s16000/30.png Taskings<o:pNext, we move back to the Grunt from the menu and select the active grunt. Here we click on the Tasking tab to see the wide list of the tasks that we performed on the target machine. The various information includes the Name of the task, Name of the Grunt it was performed, Status of Task, Username for the task, and Command that was used to perform the task. <o:p https://1.bp.blogspot.com/-COTizoTvJnk/YNrlFciMBoI/AAAAAAAAxBY/8R6eOwDkVvIYSk1jpwV_FDfCLYb8njwZwCLcBGAsYHQ/s16000/31.png Data: Credentials<o:pAs we move onto the various data that is collected based on the commands that we run on the target machine. As we demonstrated earlier, we performed the SamDump task on the target. It grabs the credentials for various users on the machine. The data section collects all that information for the red teams to note.<o:p https://1.bp.blogspot.com/-EVgXwncSIa8/YNrlKsfyfeI/AAAAAAAAxBc/3ygNPjn0v1sPe5z0a46w99rT5vhqlbh0ACLcBGAsYHQ/s16000/32.png Creating Users<o:pAs we discussed in the Introduction, that we can create and manage multiple users on Covenant. This helps in management across various members of the team and collaboration in an effective way. We need to click on the Users Section from the Left-hand side menu. This will open up a form that requires us to provide a username and password that can be used to log in.<o:p https://1.bp.blogspot.com/-0OAMYWpFZ_4/YNrlP_fymUI/AAAAAAAAxBk/vi_Y68yuApE_99VbrnrS3oDHb0aV_x2vACLcBGAsYHQ/s16000/33.png After filling up the information and clicking the Create button we see that there are two users now that can access the Covenant Framework. Those users are raj and aarti with raj users having administrative access.<o:p https://1.bp.blogspot.com/-x0NNQYJsL3o/YNrlVzJvjmI/AAAAAAAAxBs/MF5dz4EbW9wgCnMnpudSBpXsVv6CesbyQCLcBGAsYHQ/s16000/34.png Conclusion<o:pAs we saw that setting up Covenant or installing it is a very simple task of running a few commands and providing a docker instance. We also saw the process to create a listener and a Launcher. We performed a large array of tasks on grunt. This covers the basics of using this framework.<o:p
<o:p
<o:p
<o:p
<o:p
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Covenant for Pentester: Basics
This article will showcase the installation, process for compromising a Windows Machine, and the various attacks and tasks that can be performed on that compromised machine through Covenant. Table of Content Introduction Installation Creating Listener Creating Launcher Exploitation Post-Exploitation Task: Screenshot Task: Process-List Task: Mimikatz: SAM Dump Task: Key Logger
The post Covenant for Pentester: Basics appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Covenant for Pentester: Basics
This article will showcase the installation, process for compromising a Windows Machine, and the various attacks and tasks that can be performed on that compromised machine through Covenant. Table of Content Introduction Installation Creating Listener Creating Launcher Exploitation Post-Exploitation Task: Screenshot Task: Process-List Task: Mimikatz: SAM Dump Task: Key Logger
The post Covenant for Pentester: Basics appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Covenant for Pentester: Basics
Learn Covenant for Pentester basics including setup, listener creation, launcher config, and post-exploitation tasks.
Black Hat Ethical Hacking
NVIDIA Patches High-Severity GeForce Spoof-Attack Bug
NVIDIA Patches High-Severity GeForce Spoof-Attack Bug
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete.
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete.Post Views: 123 https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Reading Time: 2 Minutes
Fact: 73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete.
“Humans are the most responsible for security breaches” – 80% of hackers say that for a reason.
A lot of misconfigurations found by hackers in the wild while performing assessments take place in such environments where Firewalls and Antivirus no longer pose a challenge for experienced hackers, but every business, needs to put their machines into real tests. Using methods like Phishing, Social Engineering, and Honeypots, malicious hackers gain direct access to user-privileged accounts, thereby easily passing through the various layers of security in place.
See Also: 7 out of 10 businesses are not prepared to respond to a Cyber Attack
When Thycotic, a provider of Privilege Management Security solutions, surveyed 250+ attendees at the Black Hat 2017 conference in Las Vegas, they found that 32% of hackers say accessing privileged accounts was the number one choice for the easiest and fastest way to get at sensitive data.
No matter how much you spend your budget on your building your infrastructure, hardware & software, each week a new exploit is being found that affects millions of businesses while many do not even patch up. That is when it comes to equipment costs. Social Engineering, is not new and is very effective. A hacker does not even need to touch your Firewalls or Protection if they target an employee that they see fit to attack, giving them access basically through their account while it can escalate to taking over all your network infrastructure.
See Also: 30M Dell Devices at Risk for Remote BIOS Attacks, RCE
Those that protect your company, should not be the same people that would test it. Penetration Testing is something that must be done, and the budget should be even set as a standard.
This is another wake-up call for organizations to bolster their Cyber Security efforts. In today’s ever-evolving threat environment, Offensive Security is absolutely critical for helping organizations sniff out cracks in their defenses before the bad guys do.
See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3Gn0bEI-e1624621931936-90x90.png Offensive Security Tool: Pixload4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Vqwdgis-90x90.png Offensive Security Tool: SecretFinder2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3v1wot9-90x90.png Offensive Security Tool: CloudFail3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Screenshot_2021-06-04_053854-90x90.png Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Screenshot_20210527_200634-90x90.png OSINT Tool: LinkedIn Scraper1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/sna-768x373-1-90x90.png Offensive Security Tool: Snallygaster1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-14_115500-90x90.[...]
73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete.
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete.Post Views: 123 https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Reading Time: 2 Minutes
Fact: 73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete.
“Humans are the most responsible for security breaches” – 80% of hackers say that for a reason.
A lot of misconfigurations found by hackers in the wild while performing assessments take place in such environments where Firewalls and Antivirus no longer pose a challenge for experienced hackers, but every business, needs to put their machines into real tests. Using methods like Phishing, Social Engineering, and Honeypots, malicious hackers gain direct access to user-privileged accounts, thereby easily passing through the various layers of security in place.
See Also: 7 out of 10 businesses are not prepared to respond to a Cyber Attack
When Thycotic, a provider of Privilege Management Security solutions, surveyed 250+ attendees at the Black Hat 2017 conference in Las Vegas, they found that 32% of hackers say accessing privileged accounts was the number one choice for the easiest and fastest way to get at sensitive data.
No matter how much you spend your budget on your building your infrastructure, hardware & software, each week a new exploit is being found that affects millions of businesses while many do not even patch up. That is when it comes to equipment costs. Social Engineering, is not new and is very effective. A hacker does not even need to touch your Firewalls or Protection if they target an employee that they see fit to attack, giving them access basically through their account while it can escalate to taking over all your network infrastructure.
See Also: 30M Dell Devices at Risk for Remote BIOS Attacks, RCE
Those that protect your company, should not be the same people that would test it. Penetration Testing is something that must be done, and the budget should be even set as a standard.
This is another wake-up call for organizations to bolster their Cyber Security efforts. In today’s ever-evolving threat environment, Offensive Security is absolutely critical for helping organizations sniff out cracks in their defenses before the bad guys do.
See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3Gn0bEI-e1624621931936-90x90.png Offensive Security Tool: Pixload4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Vqwdgis-90x90.png Offensive Security Tool: SecretFinder2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3v1wot9-90x90.png Offensive Security Tool: CloudFail3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Screenshot_2021-06-04_053854-90x90.png Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Screenshot_20210527_200634-90x90.png OSINT Tool: LinkedIn Scraper1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/sna-768x373-1-90x90.png Offensive Security Tool: Snallygaster1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-14_115500-90x90.[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking 73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete. https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 73% of Hackers said traditional Firewall…
png Offensive Security Tool: Breacher2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-07_124858-90x90.png Offensive Security Tool: EyeWitness2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Selection_017-90x90.png Offensive Security Tool: SSHPry2.02 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/image1-90x90.png Offensive Security Tool: ADFSBrute2 months ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post 73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete. first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-07_124858-90x90.png Offensive Security Tool: EyeWitness2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Selection_017-90x90.png Offensive Security Tool: SSHPry2.02 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/image1-90x90.png Offensive Security Tool: ADFSBrute2 months ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post 73% of Hackers said traditional Firewall and Antivirus Security is irrelevant or obsolete. first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Kconfig : Hardened-Check – A Tool For Checking The Hardening Options In The Linux Kernel Config
Kconfig is a tool For Checking The Hardening Options In The Linux Kernel Config There are plenty of Linux kernel hardening config options. A lot of them are not enabled by the major distros. We have to enable these options ourselves to make our systems more secure. But nobody likes checking configs manually. So let […]
The post Kconfig : Hardened-Check – A Tool For Checking The Hardening Options In The Linux Kernel Config appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kconfig : Hardened-Check – A Tool For Checking The Hardening Options In The Linux Kernel Config
Kconfig is a tool For Checking The Hardening Options In The Linux Kernel Config There are plenty of Linux kernel hardening config options. A lot of them are not enabled by the major distros. We have to enable these options ourselves to make our systems more secure. But nobody likes checking configs manually. So let […]
The post Kconfig : Hardened-Check – A Tool For Checking The Hardening Options In The Linux Kernel Config appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Kconfig : A Tool For Checking Hardening Options In The Linux Kernel
Kconfig is a tool For Checking The Hardening Options In The Linux Kernel Config. There are plenty of Linux kernel hardening config options.