Hacking Articles Tips Tricks Videos Tutorials
473 subscribers
66.9K photos
15 videos
157 files
134K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
token). For blind exfiltration, the scanner serves the DTD through one of three mechanisms: a built-in HTTP server (--oob-listen), a directory served by the operator's own web server (--oob-dtd-dir), or the WebUI's Flask routes. Exfiltrated content is routed through the same file-content and credential extractors used for in-band reads, so a blind read of /etc/passwd produces the same loot entry as an in-band read. Credential extraction Seven credential kinds are recognized and stored with paste-ready shell snippets: AWS IAM — JSON from IMDS, and INI from the CLI credentials file. Snippets: aws sts get-caller-identity, aws s3 ls, IAM policy enumeration, and an export block for the current shell. Alibaba RAM — aliyun sts GetCallerIdentity, aliyun oss ls, and an export block with the correct ALIBABA_CLOUD_* variables. SSH private keys — install, fingerprint, and try against github.com / gitlab.com / bitbucket.org. GCP service accounts — activate with gcloud auth activate-service-account. OAuth access tokens — curl against Google's userinfo endpoint (works for GCP tokens) and Azure's subscriptions endpoint. Kubernetes service-account tokens — JWT payload decoded to namespace and service-account name. Generic bearer tokens — curl against httpbin.org/bearer to test liveness. Chain analysis A ChainTracker derives chain stages from finding IDs and evidence. When all stages of a template are present, a rollup finding names the end-to-end impact. Thirteen templates ship with the scanner: XXE -> in-band file read -> credential theft XXE -> IMDS -> IAM credentials -> AWS account takeover XXE -> error-based leak -> file content recovered XXE -> PHP filter -> source disclosure XXE -> protocol wrapper -> RCE chain XXE -> blind OOB callback confirmed XXE -> SSRF -> internal service reached XXE -> WAF bypass -> entity resolution confirmed XXE -> Kubernetes secrets API -> cluster credential theft XXE -> in-cluster SA token read XXE -> SSH private key -> lateral movement primitive XXE -> GCP metadata -> OAuth token extraction XXE -> Azure IMDS -> managed-identity token Rollups appear in JSON, SARIF, and HTML output like any other finding. WAF bypass Fifteen encoders across three families: Document encoders: utf16be, utf16le, utf16decl, utf16nobom, utf32be, utf32le, ebcdic, ucs4_2143, utf8bom Keyword-evasion encoders: public, public_charref, b64_uri Grammar-level encoders: whitespace_pad, doctype_closure, pe_stager The WAF bypass phase runs after the core phases, not before. A target that responds to a plain SYSTEM "file://" payload does not need to be sent 1,500 encoded variants first — the direct probes find it in roughly 20 requests, and the encoded sweep is the fallback for when they were blocked. Encoders whose output is byte-identical to the input are skipped (no request sent). Interface and output CLI with Burp request ingestion, cookie management, pre-auth request replay, rate limiting, wall-clock budget, and cooperative cancellation. Web console (Flask, single self-contained HTML file, no CDN) with live event streaming, a command palette, keyboard navigation, and per-job download buttons for JSON, SARIF, and HTML. JSON (schema 1.1), SARIF v2.1.0, and self-contained printable HTML. CI exit codes for --fail-on thresholds; works with GitHub Actions and GitLab CI. Reliability Per-phase exception isolation — a crash in one technique family cannot lose findings from phases already completed. Rate limiting independent of thread count. Retry with backoff on transient failures (ConnectError, RemoteProtocolError, ReadError, WriteError, TimeoutException). HTTP 500 is deliberately not retried, because error-based XXE targets return 500 on purpose. On-disk fingerprint cache so repeat scans skip the probe phase. Cooperative cancellation; every phase checks the ScanContext before each payload send. Test labs The repository ships with two local test labs — a Python/Flask lab and a Java/Xerces lab — totalling 54 endpoints split across
vulnerable, safe, and false-negative-bait categories. They exist so the scanner's detection and false-positive vetoes can be verified rather than assumed. A correct scanner reports no findings on all seventeen safe endpoints. Note: the labs are not included in the PyPI package or any other distribution package. They can be installed and run separately from the GitHub repository. Repository: https://github.com/kamalx06/XXERipper Installation: pip install xxeripper Feedback on detection accuracy against real-world targets is welcome. <!-- SC_ON --> submitted by /u/kamalx06 (https://www.reddit.com/user/kamalx06)
[link] (https://www.reddit.com/r/redteamsec/comments/1wpwryt/xxeripper_an_opensource_xxe_scanner_with/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wpwryt/xxeripper_an_opensource_xxe_scanner_with/)
LocalStranger is a PoC for vulnerable “Microsoft Windows Hardware Compatibility Publisher” signed driver, demonstrated through a basic unsigned driver mapper and NT AUTHORITY escalation.
https://www.reddit.com/r/redteamsec/comments/1wqmasc/localstranger_is_a_poc_for_vulnerable_microsoft/

submitted by /u/noobesINC (https://www.reddit.com/user/noobesINC)
[link] (https://github.com/nbs32k/LocalStranger) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqmasc/localstranger_is_a_poc_for_vulnerable_microsoft/)
How to get a red team job? (pasted anything just to post, not sure if cant post this type of content, sorry lol)
https://www.reddit.com/r/redteamsec/comments/1wqsq4v/how_to_get_a_red_team_job_pasted_anything_just_to/

<!-- SC_OFF -->Sup guys, lemme ask u something, ive been working as a web developer for 5 years, and in 2024 i started to learn cibersecurity, but due to work and other things that happened i lost the focus, so in the 2025 october i started back to practice and learn, studying at htb academy, tryhackme ive already done and learnt a lot, im doing portswigger labs(xss, sqli, idoor and etc), maldev(shellcode injection, process hollowing, dll side-loading, reflective dll, peb walking, api hashing, junk code), reverse engineering(have already done some crackmes to learn assembly), network(i study by myself cuz i like this subject a lot, test everything in my vps, firewall, docker, tcpdump, ssh tunelling to disguise traffic, macspoof to bypass switches configs, deauth to attack some networks), started to learn about slive c2(dns exfiltration, tcp exfiltration, icmp exfiltration) and etc. My point here is, i would like to hear from people that already work with it, what is the path to get there, cuz a lotta things a know and practice everyday, but theres things that i know that i need to study more like AD, OSINT, OPSEC. That said what would u guys recommend me to do to get there, cuz red team is my dream work And another thing, i feel lost cuz like, at web dev i can get a work easily even with ai, but in security as i dont have any experience how could a jr get a job lol, with all those ai's out there, and i think im a skid, but im not sure lmao thanks, know that u guys work what i ever wanted i my life <!-- SC_ON --> submitted by /u/Deex__ (https://www.reddit.com/user/Deex__)
[link] (https://www.youtube.com/watch?v=rHxYZwMz-DY&list=PLBf0hzazHTGMjSlPmJ73Cydh9vCqxukCu) [comments] (https://www.reddit.com/r/redteamsec/comments/1wqsq4v/how_to_get_a_red_team_job_pasted_anything_just_to/)
Build guide for GOAD lab on Proxmox, Sliver C2, Redirectors and Operator behind pfSense.
https://www.reddit.com/r/redteamsec/comments/1wrjjn7/build_guide_for_goad_lab_on_proxmox_sliver_c2/

<!-- SC_OFF -->Hi guys, this is my guide and the notes uploaded in github for the lab. I wanted to build this avoiding using Ludus and Wireguard, as I needed a more realistic approach and also to manage the network from pfSense. As the GOAD repo and the process build on Proxmox needed troubleshooting and some changes in the configuration files, decided to upload a guide and post here for anyone interested to create the lab. <!-- SC_ON --> submitted by /u/GMCobra (https://www.reddit.com/user/GMCobra)
[link] (https://github.com/pho5nix/Red-Team-GOAD-Lab-Proxmox) [comments] (https://www.reddit.com/r/redteamsec/comments/1wrjjn7/build_guide_for_goad_lab_on_proxmox_sliver_c2/)
Nvidia just announced their DPU-based Open Agent Safety Platform. Here is an architectural comparison against kernel-level eBPF containment.
https://www.reddit.com/r/redteamsec/comments/1wsb63j/nvidia_just_announced_their_dpubased_open_agent/

<!-- SC_OFF -->Nvidia launched their Open Agent Safety Platform this morning, relying on an out-of-band DPU (Sentry on BlueField) to achieve what they call "millisecond-scale quarantine" for autonomous agents. For the red and blue teams looking at agent containment, the architectural contrast between their hardware approach and an in-line kernel approach is worth breaking down: The DPU Approach (Nvidia): Moving the enforcement layer physically out-of-band to a DPU is excellent for surviving a total host-kernel root compromise. However, it relies on telemetry crossing the PCIe bus to evaluate policy. In compute time, a millisecond is an eternity—more than enough time for a rogue agent to successfully exfiltrate a small payload or drop a beacon before the DPU drops the connection. The In-Line Kernel Approach (eBPF): In my recent preprint (Hard Stop, arXiv: 2609.29808), we tested an alternative software-only approach. By hooking security_bpf and security_file_open via eBPF LSM at the syscall boundary, you can achieve sub-5-microsecond preemption. Because it stays in-line, it intercepts and denies the action before the kernel processes it, achieving zero-leakage containment without the hardware round-trip. Nvidia’s platform is a massive step forward for enterprise zero-trust, but it requires proprietary silicon. If you rigorously enforce your unprivileged namespace and cgroup boundaries, kernel-level preemption gets you true zero-leakage isolation orders of magnitude faster on commodity Linux hardware. Curious to hear from the offensive side—if you were red-teaming an agent, would you rather race an out-of-band DPU or try to bypass an in-line eBPF LSM hook? (Paper link: https://arxiv.org/abs/2609.29808 / Code: https://github.com/joseluispino/hardstop) <!-- SC_ON --> submitted by /u/wlvmtb (https://www.reddit.com/user/wlvmtb)
[link] (https://nvidianews.nvidia.com/news/open-agent-safety-platform) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsb63j/nvidia_just_announced_their_dpubased_open_agent/)
WINDOWS PRIVILEGE ESCALATION USING NCSI ACTIVE PROBES
https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/

<!-- SC_OFF -->Peter Gabaldon from LABS @ ITRES discusess a vulnerability in the Windows Network Connectivity Status Indicator (NCSI) that can be exploited to escalate privileges from a low-privileged user to local admin. The attack leverages proxy configuration flaws to relay authentication to an Active Directory Certificate Services endpoint, enabling attackers to forge access tickets. <!-- SC_ON --> submitted by /u/That_Address_2122 (https://www.reddit.com/user/That_Address_2122)
[link] (https://labs.itresit.es/2026/09/28/windows-privilege-escalation-using-ncsi-active-probes/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/)
Benchmark and defense code for persistent memory attacks on OpenClaw-style computer-use agents, with memory-zoning mitigation, attack scenarios, and evaluation scripts.
Community Cryptography Test Vectors
web-check v2.3.0

🕵️‍♂️ All-in-one OSINT tool for analysing any website
Read more...