Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Add new tools
The scripts for downloading the tools are in the Tools folder in yml format. New tools can be added by creating new yml files with the following format: Rubeus.yml file: tool:
- name: Rubeus
description: Rubeus is a C# toolset for raw Kerberos interaction and abuses
gitLink: https://github.com/GhostPack/Rubeus
solutionPath: Rubeus\Rubeus.sln
Requirements for the release version (Visual Studio 2019 is not required)
Microsoft .NET Framework 3.5 Service Pack 1 (for some tools): https://www.microsoft.com/en-us/download/details.aspx?id=22 Build Tools for Visual Studio 2019: https://visualstudio.microsoft.com/thank-you-downloading-visual-studio/?sku=BuildTools&rel=16 Install .NET desktop build tools
Disable the antivirus :D Teste on Windows 10 Pro - Version 20H2 - Build 19042.631
Requirements for build
Net framework 3.5.1 (for some tools): https://www.microsoft.com/en-us/download/details.aspx?id=22 Visual Studio 2019 -> https://visualstudio.microsoft.com/thank-you-downloading-visual-studio/?sku=Community&rel=16 Install .NET desktop build tools
Supported tools
Internal-Monologue: Description: Retrieving NTLM Hashes without Touching LSASS GitLink: https://github.com/eladshamir/Internal-Monologue InveighZero: Description: InveighZero is a C# LLMNR/NBNS/mDNS/DNS/DHCPv6 spoofer and man-in-the-middle (https://www.kitploit.com/search/label/Man-in-the-Middle) tool GitLink: https://github.com/Kevin-Robertson/InveighZero Rubeus: Description: Rubeus is a C# toolset for raw Kerberos interaction and abuses GitLink: https://github.com/GhostPack/Rubeus Seatbelt: Description: Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives. GitLink: https://github.com/GhostPack/Seatbelt SharpChromium: Description: SharpChromium (https://www.kitploit.com/search/label/SharpChromium) is a .NET 4.0+ CLR project to retrieve data from Google Chrome, Microsoft Edge, and Microsoft Edge Beta. Currently, it can extract GitLink: https://github.com/djhohnstein/SharpChromium SharpDPAPI: Description: SharpDPAPI is a C# port of some DPAPI functionality from @gentilkiwi's Mimikatz project. GitLink: https://github.com/GhostPack/SharpDPAPI SharpGPOAbuse: Description: SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO. GitLink: https://github.com/FSecureLABS/SharpGPOAbuse SharpHound3: Description: C# Rewrite of the BloodHound Ingestor GitLink: https://github.com/BloodHoundAD/SharpHound3 SharpMove: Description: .NET authenticated execution for remote hosts GitLink: https://github.com/0xthirteen/SharpMove SharpRDP: Description: Remote Desktop Protocol (https://www.kitploit.com/search/label/Remote%20Desktop%20Protocol) Console Application for Authenticated Command Execution GitLink: https://github.com/0xthirteen/SharpRDP Sharp-SMBExec: Description: A native C# conversion of Kevin Robertsons Invoke-SMBExec powershell script GitLink: https://github.com/checkymander/Sharp-SMBExec SharpSpray: Description: SharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike. GitLink: https://github.com/jnqpblc/SharpSpray SharpStay: Description: .NET Persistence GitLink: https://github.com/0xthirteen/SharpStay SharpUp: Description: SharpUp is a C# port of various PowerUp functionality GitLink: https://github.com/GhostPack/SharpUp SharpView: Description: .NET port of PowerView GitLink: https://github.com/tevora-threat/SharpView SharpWMI: Description: SharpWMI is a C# implementation of various WMI functionality. GitLink: https://github.com/GhostPack/SharpWMI ThreatCheck: Description: Modified version of Matterpreter's DefenderCheck GitLink: https://github.com/rasta-mouse/ThreatCheck Watson: Description: Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation (https://www.kitploit.com/search/label/Privilege%20Escalation) vulnerabilities. GitLink: https://github.com/rasta-mouse/Watson winPEAS: Description: Privilege Escalation Awesome Scripts SUITE GitLink: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite

Download OffensivePipeline (https://github.com/Aetsu/OffensivePipeline)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Verkada Attacker Charged With Wire Fraud, Conspiracy in US

Swiss national Till Kottmann and co-conspirators are accused of breaking into dozens of US companies and government entities.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Academy — Write Up

https://cdn-images-1.medium.com/max/600/1*E9GkHDHtM8RsLxc0D3wBcg.png
Academy is an easy difficulty Linux machine that features an Apache server hosting a PHP website. The website is found to be the HTB Academy…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CTFs Passo a Passo — PARTE 2 — Lista De Rooms — TryHackMe

Esta é uma lista de rooms gratuitas que criei para você, do site TryHackMe, levando você do iniciante ao médio. O objetivo desse guia é…

Continue reading on roxlmz »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
OffensivePipeline - Tool To Download, Compile (Without Visual Studio) And Obfuscate C# Tools For Red Team Exercises

https://1.bp.blogspot.com/-rE0u73muQuY/YE6H5C_EIZI/AAAAAAAAVmw/Bua9alQCLKoQU2ElfOlHCStyQeE1H5X7QCNcBGAsYHQ/w640-h288/OffensivePipeline_1_2021-02-18-20-54-21.png OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.

OffensivePipeline downloads the tool from the git repository, then compiles it with msbuild and finally obfuscates it with ConfuserEx. Examples* List all tools: OffensivePipeline.exe list * Build all tools: OffensivePipeline.exe all * Build a tool OffensivePipeline.exe t toolName https://1.bp.blogspot.com/-jwefLcOfEHQ/YE6IHgNNsrI/AAAAAAAAVm0/ai1guvgBJvY-GaWAlSZAKC3w8qx2ofw2gCNcBGAsYHQ/w640-h326/OffensivePipeline_2_2021-02-18-20-58-21.png Add new toolsThe scripts for downloading the tools are in the Tools folder in yml format. New tools can be added by creating new yml files with the following format:

* Rubeus.yml file: tool:
- name: Rubeus
description: Rubeus is a C# toolset for raw Kerberos interaction and abuses
gitLink: https://github.com/GhostPack/Rubeus
solutionPath: Rubeus\Rubeus.sln
Requirements for the release version (Visual Studio 2019 is not required)* Microsoft .NET Framework 3.5 Service Pack 1 (for some tools): https://www.microsoft.com/en-us/download/details.aspx?id=22
* Build Tools for Visual Studio 2019: https://visualstudio.microsoft.com/thank-you-downloading-visual-studio/?sku=BuildTools&rel=16
* Install .NET desktop build tools https://1.bp.blogspot.com/-MXyYKJfoXkk/YE6IOrAIHFI/AAAAAAAAVm8/BVfKCswGC-I-E5ISmdu7qXmUqh94mTPLACNcBGAsYHQ/w640-h322/OffensivePipeline_3_lib01.png * Disable the antivirus :D
* Teste on Windows 10 Pro - Version 20H2 - Build 19042.631 Requirements for build* Net framework 3.5.1 (for some tools): https://www.microsoft.com/en-us/download/details.aspx?id=22
* Visual Studio 2019 -> https://visualstudio.microsoft.com/thank-you-downloading-visual-studio/?sku=Community&rel=16
* Install .NET desktop build tools Supported tools* Internal-Monologue:
* Description: Retrieving NTLM Hashes without Touching LSASS
* GitLink: https://github.com/eladshamir/Internal-Monologue

* InveighZero:
* Description: InveighZero is a C# LLMNR/NBNS/mDNS/DNS/DHCPv6 spoofer and man-in-the-middle tool
* GitLink: https://github.com/Kevin-Robertson/InveighZero

* Rubeus:
* Description: Rubeus is a C# toolset for raw Kerberos interaction and abuses
* GitLink: https://github.com/GhostPack/Rubeus

* Seatbelt:
* Description: Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
* GitLink: https://github.com/GhostPack/Seatbelt

* SharpChromium:
* Description: SharpChromium is a .NET 4.0+ CLR project to retrieve data from Google Chrome, Microsoft Edge, and Microsoft Edge Beta. Currently, it can extract
* GitLink: https://github.com/djhohnstein/SharpChromium

* SharpDPAPI:
* Description: SharpDPAPI is a C# port of some DPAPI functionality from @gentilkiwi's Mimikatz project.
* GitLink: https://github.com/GhostPack/SharpDPAPI

* SharpGPOAbuse:
* Description: SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.
* GitLink: https://github.com/FSecureLABS/SharpGPOAbuse

* SharpHound3:
* Description: C# Rewrite of the BloodHound Ingestor
* GitLink: https://github.com/BloodHoundAD/SharpHound3

* SharpMove:
* Description: .NET authenticated execution for remote hosts
* GitLink: https://github.com/0xthirteen/SharpMov[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! OffensivePipeline - Tool To Download, Compile (Without Visual Studio) And Obfuscate C# Tools For Red Team Exercises https://1.bp.blogspot.com/-rE0u73muQuY/YE6H5C_EIZI/AAAAAAAAVmw/Bua9alQCLKoQU2ElfOlHCStyQeE1H5X7QCNcBGAsYHQ/w640-…
e

* SharpRDP:
* Description: Remote Desktop Protocol Console Application for Authenticated Command Execution
* GitLink: https://github.com/0xthirteen/SharpRDP

* Sharp-SMBExec:
* Description: A native C# conversion of Kevin Robertsons Invoke-SMBExec powershell script
* GitLink: https://github.com/checkymander/Sharp-SMBExec

* SharpSpray:
* Description: SharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike.
* GitLink: https://github.com/jnqpblc/SharpSpray

* SharpStay:
* Description: .NET Persistence
* GitLink: https://github.com/0xthirteen/SharpStay

* SharpUp:
* Description: SharpUp is a C# port of various PowerUp functionality
* GitLink: https://github.com/GhostPack/SharpUp

* SharpView:
* Description: .NET port of PowerView
* GitLink: https://github.com/tevora-threat/SharpView

* SharpWMI:
* Description: SharpWMI is a C# implementation of various WMI functionality.
* GitLink: https://github.com/GhostPack/SharpWMI

* ThreatCheck:
* Description: Modified version of Matterpreter's DefenderCheck
* GitLink: https://github.com/rasta-mouse/ThreatCheck

* Watson:
* Description: Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation vulnerabilities.
* GitLink: https://github.com/rasta-mouse/Watson

* winPEAS:
* Description: Privilege Escalation Awesome Scripts SUITE
* GitLink: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite Download OffensivePipeline
hacking: security in practice
XSS vulnerability in a hidden field in a website.

Hello, I am working on this website. It had hidden inputs ,i tried injecting “onclick=alert(1)” in one of the inputs after making them from hidden to “display” . It worked and a pop up appeared. Does this mean i have to stop at this point and report to the website? Or what is next?

submitted by /u/Ramseesthe4th
[link] [comments]
hacking: security in practice
Decoding challenge

I have a homework assignment I need help with. The base64 piece of it is straightforward enough, but didn't get any further.

https://pastebin.com/xTThPgy5

submitted by /u/secureartisan
[link] [comments]