Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pegasus Spyware - Is it really possible to completely hack a mobile device just with a text message?

After extensive research by OCCRP, The Guardian, and other reliable sources, the investigators have confirmed that 10 governments have been spying on their journalists, activists, businesspeople, and even government officials using software developed by an Israeli cyber firm NSO group. You can read about it here: https://www.occrp.org/en/the-pegasus-project/

I personally know a lot of people (mainly journalists) who were victims, and after Amnesty International Security Office did an analysis on their phone, they found the Pegasus app itself, if not its traces showing that the software deleted itself for not exposing it to the owner. The owners knew the government might have been listening to them (e.g. intercepting cellular signals or not even need to think deeply, all cell carriers are compromised), but they had no idea such an app could have been installed in their phone. Most of them were also very practical at security, not clicking any links even from friends or using only anonymous chatting apps.

Then I saw this video by The Guardian. In the first minute, it tells how the software can be injected into the operating system just by a text message. I have been doing programming for many years now, even got into learning some hacking, but I can't think of a proper way that there is such thing as hacking only with a text message. The only such vulnerability would mean the OSs themselves have a big security issue (don't know the mobile term for this, but something like XSS injection), but that is of very low probability. Nowadays all updated versions of the mobile OS even ask for permissions for all apps, so I cannot really believe how this happened. I would like to hear what do you think about it. Is such hacking really possible?

submitted by /u/BarishNamazov
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to crack username with ssh key?

I managed to get a ssh key from an (authorized) nfs server, now i want to crack the ssh username but i don't know how to pass my prívate key to the cracker(i'm currently using hydra) how can i do it?

submitted by /u/tuviejaentanga37
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Guys, so I wanted to ask about a real-life experience you had of the cyber-attacks exploiting a VPN connection to get into a network.

To make things clear, basically, I want to get multiple scenarios that happened in your experience with preventing cyber-attacks where VPN IPsec or SSL VPN were exploited (it doesn't matter what specifically). To clarify, due to a pandemic decent amount of companies started using a VPN for their employees, and I want to go through what can happen and what happened based on your experience and how you prevented it.

PS. just curious ))

submitted by /u/rubenamizyan
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Pentesting iOS| Starting With iOS Emulator Corellium & Re-signing IPA

Corellium provided virtual iOS-based devices for individual accounts on our groundbreaking security research platform, CORSEC. Corellium’s…Continue reading on InfoSec Write-ups »
Read more...
Crawl SMB shares for juicy information. File content searching + regex is supported!

___________________________
@hacking_Attack
@Hacking_Video
File types supported:
PDF DOCX XLSX PPTX any text-based format and many more!!
MAN-SPIDER will crawl every share on every target system. If provided creds don't work, it will fall back to "guest", then to a null session.

___________________________
@hacking_Attack
@Hacking_Video
Example #5: Search for certificates
$ manspider share.evilcorp.local -e pfx p12 pkcs12 pem key crt cer csr jks keystore key keys der -d evilcorp -u bob -p Passw0rd

Usage Tip #1:
You can run multiple instances of manspider at one time. This is useful when one instance is already running, and you want to search what it's downloaded (similar to grep -R). To do this, specify the keyword loot as the target, which will search the downloaded files in $HOME/.manspider/loot.
Usage Tip #2:
Reasonable defaults help prevent unwanted scenarios like getting stuck on a single target. All of these can be overridden: default spider (https://www.kitploit.com/search/label/Spider) depth: 10 (override with -m) default max filesize: 10MB (override with -s) default threads: 5 (override with -t) shares excluded: C$, IPC$, ADMIN$, PRINT$ (override with --exclude-sharenames)
Usage Tip #3:
Manspider accepts any combination of the following as targets: IPs hostnames subnets (CIDR format) files containing any of the above local folders containing files For example, you could specify any or all of these: 192.168.1.250 share.evilcorp.local 192.168.1.0/24 smb_hosts.txt loot (to search already-downloaded files) /mnt/share (to recursively search a directory) NOTE: when searching local files, you must specify a directory, not an individual file
Usage:
CIDR ranges, or files containing targets to spider (NOTE: local searching also supported, specify directory name or keyword "loot" to search downloaded files) optional arguments: -h, --help show this help message and exit -u USERNAME, --username USERNAME username for authentication -p PASSWORD, --password PASSWORD password for authentication -d DOMAIN, --domain DOMAIN domain for authentication -m MAXDEPTH, --maxdepth MAXDEPTH maximum depth to spider (default: 10) -H HASH, --hash HASH NTLM hash for authentication -t THREADS, --threads THREADS concurrent threads (default: 5) -f REGEX [REGEX ...], --filenames REGEX [REGEX ...] filter filenames using regex (space-separated) -e EXT [EXT ...], --extensions EXT [EXT ...] only show filenames with these extensions (space-separated, e.g. `docx xlsx` for only word & excel docs) --exclude-extensions EXT [EXT ...] ignore files with these extensions -c REGEX [REGEX ...], --content REGEX [REGEX ...] search for file content using regex (multiple supported) --sharenames SHARE [SHARE ...] only search shares with these names (multiple supported) --exclude-sharenames [SHARE ...] don't search shares with these names (multiple supported) --dirnames DIR [DIR ...] only search directories containing these strings (multiple supported) --exclude-dirnames DIR [DIR ...] don't search directories containing these strings (multiple supported) -q, --quiet don't display matching file content -n, --no-download don't download matching files -mfail INT, --max-failed-logons INT limit failed logons -o, --or-logic use OR logic instead of AND (files are downloaded if filename OR extension OR content match) -s SIZE, --max-filesize SIZE don't retrieve files over this size, e.g. "500K" or ".5M" (default: 10M) -v, --verbose show debugging (https://www.kitploit.com/search/label/Debugging) messages ">usage: manspider [-h] [-u USERNAME] [-p PASSWORD] [-d DOMAIN] [-m MAXDEPTH] [-H HASH] [-t THREADS] [-f REGEX [REGEX ...]] [-e EXT [EXT ...]] [--exclude-extensions EXT [EXT ...]]

___________________________
@hacking_Attack
@Hacking_Video
[-c REGEX [REGEX ...]] [--sharenames SHARE [SHARE ...]] [--exclude-sharenames [SHARE ...]] [--dirnames DIR [DIR ...]] [--exclude-dirnames DIR [DIR ...]] [-q] [-n]
[-mfail INT] [-o] [-s SIZE] [-v]
targets [targets ...]

Scan for juicy data on SMB shares. Matching files and logs are stored in $HOME/.manspider. All filters are case-insensitive.

positional arguments:
targets IPs, Hostnames, CIDR ranges, or files containing targets to spider (NOTE: local searching also supported, specify directory name or keyword "loot" to search
downloaded files)

optional arguments:
-h, --help show this help message and exit
-u USERNAME, --username USERNAME
username for authentication
-p PASSWORD, --password PASSWORD
password for authentication
-d DOMAIN, --domain DOMAIN
domain for authentication
-m MAXDEPTH, --maxdepth MAXDEPTH
maximum depth to spider (default: 10)
-H HASH, --hash HASH NTLM hash for authentication
-t THREADS, --threads THREADS
concurrent threads (default: 5)
-f REGEX [REGEX ...], --filenames REGEX [REGEX ...]
filter filenames using regex (space-separated)
-e EXT [EXT ...], --extensions EXT [EXT ...]
only show filenames with these extensions (space-separated, e.g. `docx xlsx` for only word & excel docs)
--exclude-extensions EXT [EXT ...]
ignore files with these extensions
-c REGEX [REGEX ...], --content REGEX [REGEX ...]
search for file content using regex (multiple supported)
--sharenames SHARE [SHARE ...]
only search shares with these names (multiple supported)
--exclude-sharenames [SHARE ...]
don't search shares with these names (multiple supported)
--dirnames DIR [DIR ...]
only search directories containing these strings (multiple supported)
--exclude-dirnames DIR [DIR ...]
don't search directories containing these strings (multiple supported)
-q, --quiet don't display matching file content
-n, --no-download don't download matching files
-mfail INT, --max-failed-logons INT
limit failed logons
-o, --or-logic use OR logic instead of AND (files are downloaded if filename OR extension OR content match)
-s SIZE, --max-filesize SIZE
don't retrieve files over this size, e.g. "500K" or ".5M" (default: 10M)
-v, --verbose show debugging messages


Download MANSPIDER (https://github.com/blacklanternsecurity/MANSPIDER)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
MANSPIDER - Spider Entire Networks For Juicy Files Sitting On SMB Shares. Search Filenames Or File Content - Regex Supported!

http://4.bp.blogspot.com/-1VejID09mE8/YOfZjjCEplI/AAAAAAAAizQ/MOsQC5GieQguI-NBPVTJKHy6DaWSa7CywCK4BGAYYCw/w640-h348/MANSPIDER_2-741248.png Crawl SMB shares for juicy information. File content searching + regex is supported!http://2.bp.blogspot.com/-GwxIwSE3Uqg/YOfZiJjAkCI/AAAAAAAAizI/PYVJTu7judo4GoJtp0OZzOuBvCX2jenVgCK4BGAYYCw/w640-h360/MANSPIDER_1-736157.gif File types supported:* PDF* DOCX* XLSX* PPTX* any text-based format
* and many more!! MAN-SPIDER will crawl every share on every target system. If provided creds don't work, it will fall back to "guest", then to a null session.http://4.bp.blogspot.com/-1VejID09mE8/YOfZjjCEplI/AAAAAAAAizQ/MOsQC5GieQguI-NBPVTJKHy6DaWSa7CywCK4BGAYYCw/w640-h348/MANSPIDER_2-741248.png Installation:(Optional) Install these dependencies to add additional file parsing capability: # for images (png, jpeg)
$ sudo apt install tesseract tesseract-data-eng

# for legacy document support (.doc)
$ sudo apt install antiword
Install manspider (please be patient, this can take a while): $ pip install pipx
$ pipx install man-spider
Example #1: Search the network for filenames that may contain credsNOTE: matching files are automatically downloaded into $HOME/.manspider/loot! (-n to disable)

login logon cred -d evilcorp -u bob -p Passw0rd ">$ manspider 192.168.0.0/24 -f passw user admin account network login logon cred -d evilcorp -u bob -p Passw0rd Example #2: Search for XLSX files containing "password"$ manspider share.evilcorp.local -c password -e xlsx -d evilcorp -u bob -p Passw0rd Example #3: Search for interesting file extensions$ manspider share.evilcorp.local -e bat com vbs ps1 psd1 psm1 pem key rsa pub reg txt cfg conf config -d evilcorp -u bob -p Passw0rd Example #4: Search for finance-related filesThis example searches financy-sounding directories for filenames containing 5 or more consecutive numbers (e.g. 000202006.EFT)

swift -f '[0-9]{5,}' -d evilcorp -u bob -p Passw0rd ">$ manspider share.evilcorp.local --dirnames bank financ payable payment reconcil remit voucher vendor eft swift -f '[0-9]{5,}' -d evilcorp -u bob -p Passw0rd Example #5: Search for certificates$ manspider share.evilcorp.local -e pfx p12 pkcs12 pem key crt cer csr jks keystore key keys der -d evilcorp -u bob -p Passw0rd Usage Tip #1:You can run multiple instances of manspider at one time. This is useful when one instance is already running, and you want to search what it's downloaded (similar to grep -R). To do this, specify the keyword lootas the target, which will search the downloaded files in $HOME/.manspider/loot. Usage Tip #2:Reasonable defaults help prevent unwanted scenarios like getting stuck on a single target. All of these can be overridden:

* default spider depth: 10 (override with -m)
* default max filesize: 10MB (override with -s)
* default threads: 5 (override with -t)
* shares excluded: C$, IPC$, ADMIN$, PRINT$(override with --exclude-sharenames) Usage Tip #3:Manspider accepts any combination of the following as targets:

* IPs
* hostnames
* subnets (CIDR format)
* files containing any of the above
* local folders containing files

For example, you could specify any or all of these:

* 192.168.1.250* share.evilcorp.local* 192.168.1.0/24* smb_hosts.txt* loot(to [...]

___________________________
@hacking_Attack
@Hacking_Video