Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bug Bounty Stories #1: Tale of CSP bypass in an electron app!

Talking of a bug I found a long time back which led to the bypassing of CSP in an electron app :)Continue reading on Medium »
Read more...
Alchemix Access Control Bug Fix Debrief

SummaryContinue reading on Immunefi »
Read more...
LightMe is a Simple HTTP Server serving Powershell Scripts/Payloads after Obfuscate them and run obfuscation (https://www.kitploit.com/search/label/Obfuscation) as a service in backgroud in order to keep obfuscate the payloads which giving almost new obfuscated payload on each HTTP request
Main Features
Obfuscate all powershell (https://www.kitploit.com/search/label/PowerShell) files within a specific directory HTTP Server to serve the obfuscated Powershell Files Background Obfuscator Almost new Payload (https://www.kitploit.com/search/label/Payload) on each request , (depanding on Background obfuscation interval) Powered by Invoke-Obfuscation (https://github.com/danielbohannon/Invoke-Obfuscation)
Install
git clone --recurse-submodules https://github.com/WazeHell/LightMe
cd LightMe/

# install powershell
sudo apt-get install powershell
Using
python3 lightme.py --help
Running as services
vim /etc/supervisor/conf.d/lightme.conf # edit the config [program:lightme_server] directory=/lightme_path/ command=/usr/bin/python3 lightme.py -path /PowerSploitOrWhatever/ numprocs=1 user=yourusername autostart=true autorestart=true stdout_logfile=/lightme_path/lightme_std.log stderr_logfile=/lightme_path/lightme_stderr.log redirect_stderr=true priority=999 stdout_logfile_maxbytes=5MB stderr_logfile_maxbytes=5MB environment=LANG=en_US.UTF-8,LC_ALL=en_US.UTF-8 # Run sudo service supervisor restart sudo supervisorctl reread sudo supervisorctl update sudo supervisorctl restart all ">#install supervisor
sudo apt-get install supervisor

sudo vim /etc/supervisor/conf.d/lightme.conf

# edit the config
[program:lightme_server]
directory=/lightme_path/
command=/usr/bin/python3 lightme.py -path /PowerSploitOrWhatever/
numprocs=1
user=yourusername
autostart=true
autorestart=true
stdout_logfile=/lightme_path/lightme_std.log
stderr_logfile=/lightme_path/lightme_stderr.log
redirect_stderr=true
priority=999
stdout_logfile_maxbytes=5MB
stderr_logfile_maxbytes=5MB
environment=LANG=en_US.UTF-8,LC_ALL=en_US.UTF-8


# Run
sudo service supervisor restart
sudo supervisorctl reread
sudo supervisorctl update
sudo supervisorctl restart all


Download LightMe (https://github.com/WazeHell/LightMe)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
LightMe - HTTP Server Serving Obfuscated Powershell Scripts/Payloads

http://1.bp.blogspot.com/-UImi9-ySwxk/YP8Wnw8Il4I/AAAAAAAAoUE/ba-RB308e48U8hI5qtTjswN3zU9xjez6ACK4BGAYYCw/w640-h564/LightMe_1_screen-702082.png
LightMe is a Simple HTTP Server serving Powershell Scripts/Payloads after Obfuscate them and run obfuscation as a service in backgroud in order to keep obfuscate the payloads which giving almost new obfuscated payload on each HTTP request
Main Features

* Obfuscate all powershell files within a specific directory
* HTTP Server to serve the obfuscated Powershell Files
* Background Obfuscator
* Almost new Payload on each request , (depanding on Background obfuscation interval)
* Powered by Invoke-Obfuscation

Install

git clone --recurse-submodules https://github.com/WazeHell/LightMe
cd LightMe/

# install powershell
sudo apt-get install powershell


Using

python3 lightme.py --help

Running as services

vim /etc/supervisor/conf.d/lightme.conf # edit the config [program:lightme_server] directory=/lightme_path/ command=/usr/bin/python3 lightme.py -path /PowerSploitOrWhatever/ numprocs=1 user=yourusername autostart=true autorestart=true stdout_logfile=/lightme_path/lightme_std.log stderr_logfile=/lightme_path/lightme_stderr.log redirect_stderr=true priority=999 stdout_logfile_maxbytes=5MB stderr_logfile_maxbytes=5MB environment=LANG=en_US.UTF-8,LC_ALL=en_US.UTF-8 # Run sudo service supervisor restart sudo supervisorctl reread sudo supervisorctl update sudo supervisorctl restart all ">#install supervisor
sudo apt-get install supervisor

sudo vim /etc/supervisor/conf.d/lightme.conf

# edit the config
[program:lightme_server]
directory=/lightme_path/
command=/usr/bin/python3 lightme.py -path /PowerSploitOrWhatever/
numprocs=1
user=yourusername
autostart=true
autorestart=true
stdout_logfile=/lightme_path/lightme_std.log
stderr_logfile=/lightme_path/lightme_stderr.log
redirect_stderr=true
priority=999
stdout_logfile_maxbytes=5MB
stderr_logfile_maxbytes=5MB
environment=LANG=en_US.UTF-8,LC_ALL=en_US.UTF-8
# Run
sudo service supervisor restart
sudo supervisorctl reread
sudo supervisorctl update
sudo supervisorctl restart all

Download LightMe

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Airpods stolen

My airpods got stolen in Amsterdam. Can anyone track them for me? Is this possible?

Hit me up pls, I hope that if I can find my airpods, I’ll find my 5k of other stuff as well..

(Picture for views)

submitted by /u/420_Lyrics
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Making a usb rubber ducky with only a stock usb

I want to try my hand on making a usb that can run payloads that use ducky commands that have been converted to python (Ducky to python script on github). But I'm having a hard time finding a way to find a script that can run the script automatically once it's inserted like the Ducky does. I tried with a rooted android but that doesn't work. I know you can set a usb to automatically run it with some installed programs but I want to make it a stand alone. I know its possible on linux thanks to chmod and other commands but windows is a bit more secure. I have thought of using the technician access since usually they usual default credentials most of the time. Another thing I thought of is running from BIOS some how (but that's most likely a strech).

Ducky Script to Python

submitted by /u/Username_1987_
[link] [comments]