Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
JWTweak : Detects The Algorithm Of Input JWT Token And Provide Options To Generate The New JWT Token Based On The User Selected Algorithm

JWTweak is a tool to detects The Algorithm Of Input JWT Token And Provide Options To Generate The New JWT Token Based On The User Selected Algorithm. With the global increase in JSON Web Token (JWT) usage, the attack surface has also increased significantly. Having said that, this utility is designed with the aim to […]

The post JWTweak : Detects The Algorithm Of Input JWT Token And Provide Options To Generate The New JWT Token Based On The User Selected Algorithm appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
TeamsUserEnum - User Enumeration With Microsoft Teams API

https://1.bp.blogspot.com/-IhBE2Nih42k/YPietjm52kI/AAAAAAAAjTs/o7RwUa4J6bsTBLcZguVGUfCLXJlzzS7CgCNcBGAsYHQ/w640-h182/TeamsUserEnum_1_enumeration-users.png
Sometimes user enumeration could be sometimes useful during the reconnaissance of an assessment. This tool will determine if an email is registered on teams or not. More details on the immunIT's blog
Usage

Microsoft Teams with the search features. This tool validates an email address or a list of email addresses. If these emails exist the presence of the user is retrieved as well as the device used to connect Usage: UserEnumTeams userenum [flags] Flags: -e, --email string Email address -f, --file string File containing the email address -h, --help help for userenum -t, --token string Bearer token (only the base64 part: eyJ0...) Global Flags: -v, --verbose Verbose ">> .\UserEnumTeams userenum --help
Users can be enumerated on Microsoft Teams with the search features.
This tool validates an email address or a list of email addresses.
If these emails exist the presence of the user is retrieved as well as the device used to connect

Usage:
UserEnumTeams userenum [flags]

Flags:
-e, --email string Email address
-f, --file string File containing the email address
-h, --help help for userenum
-t, --token string Bearer token (only the base64 part: eyJ0...)

Global Flags:
-v, --verbose Verbose


.\UserEnumTeams userenum -u emails.txt -t eyJ0eXAiOiJKV1QiLCJub25jZSI6IlpNc3FVTnJDeUJaYTBJZ3RXSmFsNUZWVjRU……vKiXYtCir3GJ9rMPAhPXiXSzSMeOPiSaM7SDoCg


http://2.bp.blogspot.com/--6w21XZ3QiY/YPib5qXx9kI/AAAAAAAAjRY/FlzmssMup7Iy-lmRzQ0v8BaR5vSXOrgtACK4BGAYYCw/w640-h182/TeamsUserEnum_1_enumeration-users-764594.png

.\UserEnumTeams userenum -u emails.txt -t eyJ0eXAiOiJKV1QiLCJub25jZSI6IlpNc3FVTnJDeUJaYTBJZ3RXSmFsNUZWVjRU……vKiXYtCir3GJ9rMPAhPXiXSzSMeOPiSaM7SDoCg -v

https://1.bp.blogspot.com/-PcCp2kG2ZZA/YPifI65guII/AAAAAAAAjT8/WJ6c754pwc8qJVSUyZ4Y7jbukqmWMLHHgCNcBGAsYHQ/w640-h426/enumeration-users-verbose.png
Download TeamsUserEnum

___________________________
@hacking_Attack
@Hacking_Video
Story OF MY 3RD Bounty From Facebook

Hi , I am Aashish Jung Kunwar from Dhangadhi , Nepal . Today I am back with a new writeup . The writeup is about how I got my 3rd bounty…Continue reading on Medium »
Read more...
TeamsUserEnum - User Enumeration With Microsoft Teams API

Sometimes user enumeration could be sometimes useful during the reconnaissance of an assessment. This tool will determine if an email is registered on teams or not. More details on the immunIT's blogUsage Microsoft Teams with the search features. This tool validates an email address or a list of email addresses. If these emails exist the presence of the user is retrieved as well as the device used to connect Usage: UserEnumTeams userenum flags Flags: -e, --email string Email address -f, --file string File containing the email address -h, --help help for userenum -t, --token string Bearer token (only the base64 part: eyJ0...) Global Flags: -v, --verbose Verbose ">> .\UserEnumTeams userenum --helpUsers can be enumerated on Microsoft Teams with the search features.This tool validates an email address or a list of email addresses.If these emails exist the presence of the user is retrieved as well as the device used to connectUsage: UserEnumTeams userenum flagsFlags: -e, --email string Email address -f, --file string File containing the email address -h, --help help for userenum -t, --token string Bearer token (only the base64 part: eyJ0...)Global Flags: -v, --verbose Verbose .\UserEnumTeams userenum -u emails.txt -t eyJ0eXAiOiJKV1QiLCJub25jZSI6IlpNc3FVTnJDeUJaYTBJZ3RXSmFsNUZWVjRU……vKiXYtCir3GJ9rMPAhPXiXSzSMeOPiSaM7SDoCg .\UserEnumTeams userenum -u emails.txt -t eyJ0eXAiOiJKV1QiLCJub25jZSI6IlpNc3FVTnJDeUJaYTBJZ3RXSmFsNUZWVjRU……vKiXYtCir3GJ9rMPAhPXiXSzSMeOPiSaM7SDoCg -v Download TeamsUserEnum
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Sometimes user enumeration (https://www.kitploit.com/search/label/User%20Enumeration) could be sometimes useful during the reconnaissance (https://www.kitploit.com/search/label/Reconnaissance) of an assessment. This tool will determine if an email is registered on teams or not. More details on the immunIT's blog (https://www.immunit.ch/blog/2021/07/05/microsoft-teams-user-enumeration/)
Usage
.\UserEnumTeams userenum --help Users can be enumerated on Microsoft Teams with the search features. This tool validates an email address or a list of email addresses. If these emails (https://www.kitploit.com/search/label/Emails) exist the presence of the user is retrieved as well as the device used to connect Usage: UserEnumTeams userenum [flags] Flags: -e, --email string Email address -f, --file string File containing the email address -h, --help help for userenum -t, --token string Bearer token (only the base64 part: eyJ0...) Global Flags: -v, --verbose Verbose ">> .\UserEnumTeams userenum --help
Users can be enumerated on Microsoft Teams with the search features.
This tool validates an email address or a list of email addresses.
If these emails exist the presence of the user is retrieved as well as the device used to connect

Usage:
UserEnumTeams userenum [flags]

Flags:
-e, --email string Email address
-f, --file string File containing the email address
-h, --help help for userenum
-t, --token string Bearer token (only the base64 part: eyJ0...)

Global Flags:
-v, --verbose Verbose
.\UserEnumTeams userenum -u emails.txt -t eyJ0eXAiOiJKV1QiLCJub25jZSI6IlpNc3FVTnJDeUJaYTBJZ3RXSmFsNUZWVjRU……vKiXYtCir3GJ9rMPAhPXiXSzSMeOPiSaM7SDoCg

___________________________
@hacking_Attack
@Hacking_Video
.\UserEnumTeams userenum -u emails.txt -t eyJ0eXAiOiJKV1QiLCJub25jZSI6IlpNc3FVTnJDeUJaYTBJZ3RXSmFsNUZWVjRU……vKiXYtCir3GJ9rMPAhPXiXSzSMeOPiSaM7SDoCg -v

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
IKS to keep your identity secure even when your connection drops

For those who wish to keep themselves protected when you're up to something not so good, a slight internet disconnection and this will halt all your internet activities until your connection is back so that your IP doesn't gets leaked.

submitted by /u/nancypjones
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Finding the website root directory on a Windows IIS web server using LFI exploit

I am currently doing a CTF and everything here is part of it.

I have found an LFI vulnerability in a website that allows me to download files on both the C drive and D drive. The D drive contains content relevant to the website however no jsp (the site uses jsp) scripts that I can download which could contain useful information.

I found a way to read the D drive using the exploit and have gathered several config files. I attempted to access what I believed to be the website root directory at C:/inetpub/wwwroot and it contains an iisstart.htm file however there is nothing related to the actual site.

Is there a config, log or any kind of file on the system which may give me more information as to where the website root is? Maybe I'm missing a config file or it could be located in a log? I have even downloaded and checked files such as lnk files to see if it contains useful paths.

submitted by /u/_chun_chun_maru
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video