Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Random domain name hijacking at DigitalOcean DNS as easy as ABC
In my line of work, I found an obvious vulnerability in the Digital Ocean panel. I wrote more about it in my blog.
This allows you to bind someone else's domain to your server, which points to the digital ocean but is not bound to the server
If you write a simple WHOIS parser, you can exploit random domains!
I don't understand why the team of Digital Ocean doesn't care about this?
submitted by /u/smeshny
[link] [comments]
Random domain name hijacking at DigitalOcean DNS as easy as ABC
In my line of work, I found an obvious vulnerability in the Digital Ocean panel. I wrote more about it in my blog.
This allows you to bind someone else's domain to your server, which points to the digital ocean but is not bound to the server
If you write a simple WHOIS parser, you can exploit random domains!
I don't understand why the team of Digital Ocean doesn't care about this?
submitted by /u/smeshny
[link] [comments]
hacking: security in practice
It is kaspersky actually bad?
Why some infosec experts on tw say that Kasperky isnt reliable at all?
submitted by /u/sandfoxJ
[link] [comments]
It is kaspersky actually bad?
Why some infosec experts on tw say that Kasperky isnt reliable at all?
submitted by /u/sandfoxJ
[link] [comments]
reddit
It is kaspersky actually bad?
Why some infosec experts on tw say that Kasperky isnt reliable at all?
ProxyLogon - PoC Exploit for Microsoft Exchange
PoC Exploit for Microsoft Exchange Launche Original PoC: https://github.com/testanullHow to use: python proxylogon.py <name or IP of server> <user@fqdn> Example: python proxylogon.py primary administrator@lab.local If successful you will be dropped into a webshell. exit or quit to escape from the webshell (or ctrl+c) By default, it will create a file test.aspx. This can be changed. Special Thanks and resources: @Flangvik @Testanull https://www.praetorian.com/blog/reproducing-proxylogon-exploit/ Download ProxyLogon
Read more...
PoC Exploit for Microsoft Exchange Launche Original PoC: https://github.com/testanullHow to use: python proxylogon.py <name or IP of server> <user@fqdn> Example: python proxylogon.py primary administrator@lab.local If successful you will be dropped into a webshell. exit or quit to escape from the webshell (or ctrl+c) By default, it will create a file test.aspx. This can be changed. Special Thanks and resources: @Flangvik @Testanull https://www.praetorian.com/blog/reproducing-proxylogon-exploit/ Download ProxyLogon
Read more...
ProxyLogon - PoC Exploit for Microsoft Exchange
http://www.kitploit.com/2021/03/proxylogon-poc-exploit-for-microsoft.html
http://www.kitploit.com/2021/03/proxylogon-poc-exploit-for-microsoft.html
PoC Exploit for Microsoft Exchange Launche Original PoC: https://github.com/testanull
How to use:
python proxylogon.py
Example:
python proxylogon.py primary administrator@lab.local If successful you will be dropped into a webshell. exit or quit to escape from the webshell (or ctrl+c) By default, it will create a file test.aspx. This can be changed.
Special Thanks and resources:
@Flangvik @Testanull https://www.praetorian.com/blog/reproducing-proxylogon-exploit/
Download ProxyLogon (https://github.com/hausec/ProxyLogon)
How to use:
python proxylogon.py
Example:
python proxylogon.py primary administrator@lab.local If successful you will be dropped into a webshell. exit or quit to escape from the webshell (or ctrl+c) By default, it will create a file test.aspx. This can be changed.
Special Thanks and resources:
@Flangvik @Testanull https://www.praetorian.com/blog/reproducing-proxylogon-exploit/
Download ProxyLogon (https://github.com/hausec/ProxyLogon)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tutorial Hacking : Password Cracking Menggunakan Fern Wifi Cracker pada Wifi / Hotspot WPA
https://cdn-images-1.medium.com/max/618/1*pQ4cpmBE4dZKuqadUk9xmw.png
Hi Everyone, kali ini saya akan membagikan tutorial bagaimana caranya kita dapat melihat password wifi yang dienkripsi WPA/WPA2 dengan…
Continue reading on Medium »
Tutorial Hacking : Password Cracking Menggunakan Fern Wifi Cracker pada Wifi / Hotspot WPA
https://cdn-images-1.medium.com/max/618/1*pQ4cpmBE4dZKuqadUk9xmw.png
Hi Everyone, kali ini saya akan membagikan tutorial bagaimana caranya kita dapat melihat password wifi yang dienkripsi WPA/WPA2 dengan…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Атака по на точку доступа WPA3 c Wacker
https://cdn-images-1.medium.com/max/1280/1*TA0-8QOsXQe0d2-J1xBv2Q.jpeg
Wacker это набор скриптов, помогающих выполнить атаку по онлайн словарю на точку доступа WPA3.
Continue reading on Medium »
Атака по на точку доступа WPA3 c Wacker
https://cdn-images-1.medium.com/max/1280/1*TA0-8QOsXQe0d2-J1xBv2Q.jpeg
Wacker это набор скриптов, помогающих выполнить атаку по онлайн словарю на точку доступа WPA3.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Controlling a botnet army using a blog
https://cdn-images-1.medium.com/max/639/1*PmkhbIC0X2-qhpZTVI5g4A.png
This is how I created a undetectable bot that can be controlled by a simple free blog . Take this journey to reflect on more possibilities.
Continue reading on Medium »
Controlling a botnet army using a blog
https://cdn-images-1.medium.com/max/639/1*PmkhbIC0X2-qhpZTVI5g4A.png
This is how I created a undetectable bot that can be controlled by a simple free blog . Take this journey to reflect on more possibilities.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
ProxyLogon - PoC Exploit for Microsoft Exchange
https://1.bp.blogspot.com/-EvoCyU4_fQo/YFeu6JagbtI/AAAAAAAAVqw/f9HZ50LM2Cs-IjsNOcqLs6gNvSL5MsFiQCNcBGAsYHQ/w640-h340/ProxyLogon_1_screenshot.png
PoC Exploit for Microsoft Exchange Launche
Original PoC: https://github.com/testanull
How to use:
Example:
If successful you will be dropped into a webshell.
By default, it will create a file
Special Thanks and resources:
@Flangvik @Testanull https://www.praetorian.com/blog/reproducing-proxylogon-exploit/
Download ProxyLogon
ProxyLogon - PoC Exploit for Microsoft Exchange
https://1.bp.blogspot.com/-EvoCyU4_fQo/YFeu6JagbtI/AAAAAAAAVqw/f9HZ50LM2Cs-IjsNOcqLs6gNvSL5MsFiQCNcBGAsYHQ/w640-h340/ProxyLogon_1_screenshot.png
PoC Exploit for Microsoft Exchange Launche
Original PoC: https://github.com/testanull
How to use:
python proxylogon.py <name<user@fqdnExample:
python proxylogon.py primary administrator@lab.localIf successful you will be dropped into a webshell.
exitor quitto escape from the webshell (or ctrl+c)By default, it will create a file
test.aspx. This can be changed.Special Thanks and resources:
@Flangvik @Testanull https://www.praetorian.com/blog/reproducing-proxylogon-exploit/
Download ProxyLogon
hacking: security in practice
Best wireless network adapter
I have searched the entire internet for an affordable wireless usb wifi adapter that can do all these monitoring and ap modes and such. Any tips+links?
submitted by /u/MahatmaGandhiiii
[link] [comments]
Best wireless network adapter
I have searched the entire internet for an affordable wireless usb wifi adapter that can do all these monitoring and ap modes and such. Any tips+links?
submitted by /u/MahatmaGandhiiii
[link] [comments]
reddit
Best wireless network adapter
I have searched the entire internet for an affordable wireless usb wifi adapter that can do all these monitoring and ap modes and such. Any...
hacking: security in practice
New version of sslstrip/sslstrip+
SSLStrip as well as SSLStrip+ or SSLStrip 2, whilst using a DNS server seems to be very old now,
I believe SSL strip being last updated 10 years ago and, I've even seen SSLStrip+ posts dating back over 6 years ago.
So, I'm wondering is there any newer tools released to bypass HSTS security. Or is this type of attack not used anymore and they are alternatives?
Thanks in advanced
submitted by /u/Hollas99
[link] [comments]
New version of sslstrip/sslstrip+
SSLStrip as well as SSLStrip+ or SSLStrip 2, whilst using a DNS server seems to be very old now,
I believe SSL strip being last updated 10 years ago and, I've even seen SSLStrip+ posts dating back over 6 years ago.
So, I'm wondering is there any newer tools released to bypass HSTS security. Or is this type of attack not used anymore and they are alternatives?
Thanks in advanced
submitted by /u/Hollas99
[link] [comments]
reddit
New version of sslstrip/sslstrip+
SSLStrip as well as SSLStrip+ or SSLStrip 2, whilst using a DNS server seems to be very old now, I believe SSL strip being last updated 10 years...
hacking: security in practice
Do WiFi/signal jammers affect Ring doorbells or other WiFi based security?
I watched a video on Hak5 a while back and was curious if its possible to jam someones security system with a jammer?
submitted by /u/SM1334
[link] [comments]
Do WiFi/signal jammers affect Ring doorbells or other WiFi based security?
I watched a video on Hak5 a while back and was curious if its possible to jam someones security system with a jammer?
submitted by /u/SM1334
[link] [comments]
reddit
Do WiFi/signal jammers affect Ring doorbells or other WiFi based...
I watched a video on Hak5 a while back and was curious if its possible to jam someones security system with a jammer?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Acer Reportedly Hit With $50M Ransomware Attack
Reports say a ransomware gang has given Acer until March 28 to pay, or it will double the ransom amount.
Acer Reportedly Hit With $50M Ransomware Attack
Reports say a ransomware gang has given Acer until March 28 to pay, or it will double the ransom amount.