Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top Basic Kali Linux Commands — 2021

https://cdn-images-1.medium.com/max/656/0*ZQ9c84h7aeLVhSVY.png
Kali Linux is a Debian-derived Linux distribution designed for digital forensics and penetration testing, It is maintained and funded by…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackerMan Sergio: CSRF Tutorial (DVWA High Security Level)

https://cdn-images-1.medium.com/max/1194/1*G0ja7KSm5fRGVH_IBnm76A.png
Today we will learn how to conduct a Cross-Site Request Forgery attack on the DVWA (Damn Vulnerable Web Application) on the high security…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cross-Site Request Forgery test case

https://cdn-images-1.medium.com/max/669/0*EDLJXjBJd2dUxK7E.png
Cross-site request forgery(csrf) also known as one-click attack or session riding is type of attack where application server accept the…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Encryption?

Hey folks, welcome to this module, In this tutorial, we will study What is encryption and what is decryption techniques, What are the…

Continue reading on Medium »
Cross-Site Request Forgery test case

Cross-site request forgery(csrf) also known as one-click attack or session riding is type of attack where application server accept the…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
IOTA's (cryptocurrency) organises a CTF for their cryptography libary. Price: $5000

Stronghold is an open-source software library that was originally built to protect IOTA Seeds, but can be used to protect any digital secret. It is a secure database for working with cryptography, which ensures that secrets (like private keys) are never revealed. It provides its own peer-to-peer communication layer, so that different apps can securely communicate using the state-of-the-art Noise Protocol over libp2p. Stronghold will form a secure base for the new IOTA Firefly wallet and will be integrated into IOTA Identity. Blog post

submitted by /u/Keenstijl
[link] [comments]
hacking: security in practice
What are some great networking certifications to strenghen an ethical hacker's resume?

I am new to hacking and I want to create a studying schedule. Having a certification as a goal seems ideal, so what would be a certification in networking fundamentals that are usefull in hacking?

submitted by /u/cantthinkofanicename
[link] [comments]
hacking: security in practice
Searching for recoding-robust steganography library

As mentioned above, I search for a library able to embed data into an image so that the content even can be restored after the filetyp of the image is changed from e.g. png to jpeg or the jpeg is recompressed? Python preferred... Can anyone help me, please?

submitted by /u/Josef-Knecht
[link] [comments]
hacking: security in practice
Internet Restricted Country

Hey guys, basically I need your advice.

I am from a country that has the worst internet censorship to the point where most basic stuff like Instagram, Facebook, BBC news and etc are restricted. When we use VPN to avoid block the internet gets soo slow to the point where they can use the internet but with a huge pain a waiting time. However, it happens that one day that VPN stops working at all (maybe they blocking them too). My sister currently located in that country, I can not talk to her via Facetime and etc, so I have to directly call her using apps like Yolla. I spend tons of money to keep a balance to call her directly but she says that these calls are always listened to by authorities. So questions:

1. How can she avoid those blocks, what generally people from countries with heavily restricted internet can do?
2. What my sister can do so they could not listen to help phone talks? Or me maybe.

Thank you, all of you for your response.

p.s I am not a hacker and I am just entry-level at CSC so thought you guys have more experience in those to give me valuable advice.

submitted by /u/nineteen19nineteen19
[link] [comments]
OffensivePipeline - Tool To Download, Compile (Without Visual Studio) And Obfuscate C# Tools For Red Team Exercises
http://www.kitploit.com/2021/03/offensivepipeline-tool-to-download.html
OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises. OffensivePipeline downloads the tool from the git repository, then compiles it with msbuild and finally obfuscates it with ConfuserEx (https://github.com/mkaring/ConfuserEx/tree/v1.4.1).
Examples
List all tools: OffensivePipeline.exe list
Build all tools: OffensivePipeline.exe all
Build a tool OffensivePipeline.exe t toolName
Add new tools
The scripts for downloading the tools are in the Tools folder in yml format. New tools can be added by creating new yml files with the following format: Rubeus.yml file: tool:
- name: Rubeus
description: Rubeus is a C# toolset for raw Kerberos interaction and abuses
gitLink: https://github.com/GhostPack/Rubeus
solutionPath: Rubeus\Rubeus.sln
Requirements for the release version (Visual Studio 2019 is not required)
Microsoft .NET Framework 3.5 Service Pack 1 (for some tools): https://www.microsoft.com/en-us/download/details.aspx?id=22 Build Tools for Visual Studio 2019: https://visualstudio.microsoft.com/thank-you-downloading-visual-studio/?sku=BuildTools&rel=16 Install .NET desktop build tools
Disable the antivirus :D Teste on Windows 10 Pro - Version 20H2 - Build 19042.631
Requirements for build
Net framework 3.5.1 (for some tools): https://www.microsoft.com/en-us/download/details.aspx?id=22 Visual Studio 2019 -> https://visualstudio.microsoft.com/thank-you-downloading-visual-studio/?sku=Community&rel=16 Install .NET desktop build tools
Supported tools
Internal-Monologue: Description: Retrieving NTLM Hashes without Touching LSASS GitLink: https://github.com/eladshamir/Internal-Monologue InveighZero: Description: InveighZero is a C# LLMNR/NBNS/mDNS/DNS/DHCPv6 spoofer and man-in-the-middle (https://www.kitploit.com/search/label/Man-in-the-Middle) tool GitLink: https://github.com/Kevin-Robertson/InveighZero Rubeus: Description: Rubeus is a C# toolset for raw Kerberos interaction and abuses GitLink: https://github.com/GhostPack/Rubeus Seatbelt: Description: Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives. GitLink: https://github.com/GhostPack/Seatbelt SharpChromium: Description: SharpChromium (https://www.kitploit.com/search/label/SharpChromium) is a .NET 4.0+ CLR project to retrieve data from Google Chrome, Microsoft Edge, and Microsoft Edge Beta. Currently, it can extract GitLink: https://github.com/djhohnstein/SharpChromium SharpDPAPI: Description: SharpDPAPI is a C# port of some DPAPI functionality from @gentilkiwi's Mimikatz project. GitLink: https://github.com/GhostPack/SharpDPAPI SharpGPOAbuse: Description: SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO. GitLink: https://github.com/FSecureLABS/SharpGPOAbuse SharpHound3: Description: C# Rewrite of the BloodHound Ingestor GitLink: https://github.com/BloodHoundAD/SharpHound3 SharpMove: Description: .NET authenticated execution for remote hosts GitLink: https://github.com/0xthirteen/SharpMove SharpRDP: Description: Remote Desktop Protocol (https://www.kitploit.com/search/label/Remote%20Desktop%20Protocol) Console Application for Authenticated Command Execution GitLink: https://github.com/0xthirteen/SharpRDP Sharp-SMBExec: Description: A native C# conversion of Kevin Robertsons Invoke-SMBExec powershell script GitLink: https://github.com/checkymander/Sharp-SMBExec SharpSpray: Description: SharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike. GitLink: https://github.com/jnqpblc/SharpSpray SharpStay: Description: .NET Persistence GitLink: https://github.com/0xthirteen/SharpStay SharpUp: Description: SharpUp is a C# port of various PowerUp functionality GitLink: https://github.com/GhostPack/SharpUp SharpView: Description: .NET port of PowerView GitLink: https://github.com/tevora-threat/SharpView SharpWMI: Description: SharpWMI is a C# implementation of various WMI functionality. GitLink: https://github.com/GhostPack/SharpWMI ThreatCheck: Description: Modified version of Matterpreter's DefenderCheck GitLink: https://github.com/rasta-mouse/ThreatCheck Watson: Description: Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation (https://www.kitploit.com/search/label/Privilege%20Escalation) vulnerabilities. GitLink: https://github.com/rasta-mouse/Watson winPEAS: Description: Privilege Escalation Awesome Scripts SUITE GitLink: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite

Download OffensivePipeline (https://github.com/Aetsu/OffensivePipeline)