Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bug Hunting PhoenixRadioBali [ SQL Injection ]
https://cdn-images-1.medium.com/max/2560/1*6y5E7hR3pMWd5afjIJ7dIw.png
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bug Hunting PhoenixRadioBali [ SQL Injection ]
https://cdn-images-1.medium.com/max/2560/1*6y5E7hR3pMWd5afjIJ7dIw.png
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Hunting PhoenixRadioBali [ SQL Injection ]
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Coveted DEFCON “Black Badge”
https://cdn-images-1.medium.com/max/2084/1*2AlIP2hhJtioll-nh2rzLw.png
Adobe continually invests in both cross-industry collaboration as well as in ongoing development of the technical skills of our security…
Continue reading on Adobe Tech Blog »
___________________________
@hacking_Attack
@Hacking_Video
The Coveted DEFCON “Black Badge”
https://cdn-images-1.medium.com/max/2084/1*2AlIP2hhJtioll-nh2rzLw.png
Adobe continually invests in both cross-industry collaboration as well as in ongoing development of the technical skills of our security…
Continue reading on Adobe Tech Blog »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Coveted DEFCON “Black Badge”
Adobe continually invests in both cross-industry collaboration as well as in ongoing development of the technical skills of our security…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking the Tenda AC10–1200 Router Part 3: Yet Another Buffer Overflow
https://cdn-images-1.medium.com/max/921/1*CcGSvTTqL4XnAUSmatjDHQ.png
Hi. This is my third writeup in my hacking the tenda ac10 series where i try to get a cve. Lets get started.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking the Tenda AC10–1200 Router Part 3: Yet Another Buffer Overflow
https://cdn-images-1.medium.com/max/921/1*CcGSvTTqL4XnAUSmatjDHQ.png
Hi. This is my third writeup in my hacking the tenda ac10 series where i try to get a cve. Lets get started.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking the Tenda AC10–1200 Router Part 3: Yet Another Buffer Overflow
Hi. This is my third writeup in my hacking the tenda ac10 series where i try to get a cve. Lets get started.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Hack APIs in 2021
https://cdn-images-1.medium.com/max/1024/0*7YIYGswTMSvDBSp8.png
In past, APIs were not nearly as common as they are now. This is due to the explosion in the popularity of Single Page Applications (SPAs)…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Hack APIs in 2021
https://cdn-images-1.medium.com/max/1024/0*7YIYGswTMSvDBSp8.png
In past, APIs were not nearly as common as they are now. This is due to the explosion in the popularity of Single Page Applications (SPAs)…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Hack APIs in 2021
In past, APIs were not nearly as common as they are now. This is due to the explosion in the popularity of Single Page Applications (SPAs)…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What are Command Injection vulnerabilities?
https://cdn-images-1.medium.com/max/2600/0*6Hmz77Xo2H6Hs-JU
How command injection vulnerabilities allow attackers to take over your machine, and how you can prevent these vulnerabilities.
Continue reading on ShiftLeft Blog »
___________________________
@hacking_Attack
@Hacking_Video
What are Command Injection vulnerabilities?
https://cdn-images-1.medium.com/max/2600/0*6Hmz77Xo2H6Hs-JU
How command injection vulnerabilities allow attackers to take over your machine, and how you can prevent these vulnerabilities.
Continue reading on ShiftLeft Blog »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What are Command Injection vulnerabilities?
How command injection vulnerabilities allow attackers to take over your machine, and how you can prevent these vulnerabilities.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Smuggling Script via URL: Short HTML-based XSS payload
https://cdn-images-1.medium.com/max/820/1*PfXVCUs0WfKBjKkyiOHwHg@2x.png
Let’s learn a neat trick on having the XSS payload in the URL for achieving shorter XSS payloads — straight from the greats!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Smuggling Script via URL: Short HTML-based XSS payload
https://cdn-images-1.medium.com/max/820/1*PfXVCUs0WfKBjKkyiOHwHg@2x.png
Let’s learn a neat trick on having the XSS payload in the URL for achieving shorter XSS payloads — straight from the greats!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Smuggling Script via URL: Short HTML-based XSS payload
Let’s learn a neat trick on having the XSS payload in the URL for achieving shorter XSS payloads — straight from the greats!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google Chrome → DevTools disabled by your Company’s IT Dept on Microsoft Windows? Try this…
https://cdn-images-1.medium.com/max/1950/0*vtdf2WS4GPqhSJPr
NOTE: You will need Local Admin privileges for this to work on your Windows machine
Continue reading on Code Kings »
___________________________
@hacking_Attack
@Hacking_Video
Google Chrome → DevTools disabled by your Company’s IT Dept on Microsoft Windows? Try this…
https://cdn-images-1.medium.com/max/1950/0*vtdf2WS4GPqhSJPr
NOTE: You will need Local Admin privileges for this to work on your Windows machine
Continue reading on Code Kings »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google Chrome → DevTools disabled by your Company’s IT Dept on Microsoft Windows? Try this…
NOTE: You will need Local Admin privileges for this to work on your Windows machine
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Burp’s Recursive Grep for Owning Emdee five for life HTB Challenge
https://cdn-images-1.medium.com/max/600/1*ye-Tb-2PiktFPNwsQ26shw.png
A super special h@shtalk for a hashing challenge.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Burp’s Recursive Grep for Owning Emdee five for life HTB Challenge
https://cdn-images-1.medium.com/max/600/1*ye-Tb-2PiktFPNwsQ26shw.png
A super special h@shtalk for a hashing challenge.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Burp’s Recursive Grep for Owning Emdee five for life HTB Challenge
A super special h@shtalk for a hashing challenge.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SlowMist: Tracking possible identification clues related to Poly Network attackers
https://cdn-images-1.medium.com/max/600/1*bJHoQ4gh6wc7akYzVdrBbQ.jpeg
Further tracking and detailed vulnerabilities and technical details are being analyzed by the SlowMist security team.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SlowMist: Tracking possible identification clues related to Poly Network attackers
https://cdn-images-1.medium.com/max/600/1*bJHoQ4gh6wc7akYzVdrBbQ.jpeg
Further tracking and detailed vulnerabilities and technical details are being analyzed by the SlowMist security team.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SlowMist: Tracking possible identification clues related to Poly Network attackers
Further tracking and detailed vulnerabilities and technical details are being analyzed by the SlowMist security team.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Kenobi TryHackMe Walkthrough
Today it is time to solve another challenge called “Kenobi”. It is available at TryHackMe for penetration testing practice. The challenge is an easy difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The breakdown of the Machine with redacted flags is as follow: Level: Easy· Network Scanningo Nmap ScanEnumerationo Connecting SMB ServiceExploitationo Searching for exploit using SearchsploitPrivilege Escalationo Enumerating SUID PermissionsWalkthroughThere are two flags in this machine to discover. After Booting up the target machine from the TryHackMe: Kenobi Page, an IP will be assigned to the machine and will be visible on that page as well.IP Address: 10.10.101.175We will start a Nmap scan with the -sV from performing a Version Scan and -sC for default scripts on the target machine. nmap -sV -sC 10.10.101.175https://1.bp.blogspot.com/-fiAfgwHbELM/YRKpsbkt_mI/AAAAAAAAyIA/TZGZwfyU1HMxVxyXUpNJ1coE-IUwAw-7gCLcBGAsYHQ/s16000/1.png We have five services running on the target machine. We have 21 (FTP), 22 (SSH), 80 (HTTP), 111 & 2049 (RPC), 139 & 445 (SMB). EnumerationTo enumerate the SMB service, we will use the smbclient with the IP address of the target machine as shown in the image. We can see that there is a share by the name of anonymous. Upon accessing the share, we find a text file by the name of log.txt. We transfer the log file to our Kali machine to take a better look at it.smbclient -L \\10.10.101.175https://1.bp.blogspot.com/-YW9uMwqYc1M/YRKp5TgXoiI/AAAAAAAAyII/qeDqrwgPo-UzQ-bdwKBwNB-TZL-hllS1ACLcBGAsYHQ/s16000/2.png Reading the log, we can see that it contains the path for the id_rsa key stored on the target machine. Also, it points to the fact that the FTP service running on the target machine is ProFTPD. cat log.txthttps://1.bp.blogspot.com/-Zzo_jGcQKqs/YRKpxyjR3QI/AAAAAAAAyIE/Uk3UekyFbgsaQX5QL6Q3QbK-TxpvzTXpwCLcBGAsYHQ/s16000/3.png ExploitationAs we need to get our hands on the id_rsa file and we see that we have the ProFTPD on the target, we need to figure out a way to get access to that file through the FTP service. To check if we have any known vulnerabilities regarding the ProFTPD using Searchsploit. We see that we have the vulnerability named File Copy. We used the searchsploit to download the exploit file using the -m option. Here, we see that we need to run two significant commands: CPFR which means Copy From, and CPTO means Copy To. So we can use these commands to copy the id_rsa file from its location to a place from where we can acquire it.searchsploit ProFTPD 1.3.5https://1.bp.blogspot.com/-fv3BVdRRGKg/YRKqGdVZrgI/AAAAAAAAyIM/DX5dalHWgMk5VPz0WWvPBbz2-rxd2u6kwCLcBGAsYHQ/s16000/4.png We used netcat to connect to the FTP service on the target machine.[...]
___________________________
@hacking_Attack
@Hacking_Video
Kenobi TryHackMe Walkthrough
Today it is time to solve another challenge called “Kenobi”. It is available at TryHackMe for penetration testing practice. The challenge is an easy difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The breakdown of the Machine with redacted flags is as follow: Level: Easy· Network Scanningo Nmap ScanEnumerationo Connecting SMB ServiceExploitationo Searching for exploit using SearchsploitPrivilege Escalationo Enumerating SUID PermissionsWalkthroughThere are two flags in this machine to discover. After Booting up the target machine from the TryHackMe: Kenobi Page, an IP will be assigned to the machine and will be visible on that page as well.IP Address: 10.10.101.175We will start a Nmap scan with the -sV from performing a Version Scan and -sC for default scripts on the target machine. nmap -sV -sC 10.10.101.175https://1.bp.blogspot.com/-fiAfgwHbELM/YRKpsbkt_mI/AAAAAAAAyIA/TZGZwfyU1HMxVxyXUpNJ1coE-IUwAw-7gCLcBGAsYHQ/s16000/1.png We have five services running on the target machine. We have 21 (FTP), 22 (SSH), 80 (HTTP), 111 & 2049 (RPC), 139 & 445 (SMB). EnumerationTo enumerate the SMB service, we will use the smbclient with the IP address of the target machine as shown in the image. We can see that there is a share by the name of anonymous. Upon accessing the share, we find a text file by the name of log.txt. We transfer the log file to our Kali machine to take a better look at it.smbclient -L \\10.10.101.175https://1.bp.blogspot.com/-YW9uMwqYc1M/YRKp5TgXoiI/AAAAAAAAyII/qeDqrwgPo-UzQ-bdwKBwNB-TZL-hllS1ACLcBGAsYHQ/s16000/2.png Reading the log, we can see that it contains the path for the id_rsa key stored on the target machine. Also, it points to the fact that the FTP service running on the target machine is ProFTPD. cat log.txthttps://1.bp.blogspot.com/-Zzo_jGcQKqs/YRKpxyjR3QI/AAAAAAAAyIE/Uk3UekyFbgsaQX5QL6Q3QbK-TxpvzTXpwCLcBGAsYHQ/s16000/3.png ExploitationAs we need to get our hands on the id_rsa file and we see that we have the ProFTPD on the target, we need to figure out a way to get access to that file through the FTP service. To check if we have any known vulnerabilities regarding the ProFTPD using Searchsploit. We see that we have the vulnerability named File Copy. We used the searchsploit to download the exploit file using the -m option. Here, we see that we need to run two significant commands: CPFR which means Copy From, and CPTO means Copy To. So we can use these commands to copy the id_rsa file from its location to a place from where we can acquire it.searchsploit ProFTPD 1.3.5https://1.bp.blogspot.com/-fv3BVdRRGKg/YRKqGdVZrgI/AAAAAAAAyIM/DX5dalHWgMk5VPz0WWvPBbz2-rxd2u6kwCLcBGAsYHQ/s16000/4.png We used netcat to connect to the FTP service on the target machine.[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Kenobi TryHackMe Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.