Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium » (https://peteranh910.medium.com/ch%C6%B0%C6%A1ng-tr%C3%ACnh-ti%E1%BB%81n-th%C6%B0%E1%BB%9Fng-l%E1%BB%97i-openleverage-30a50b8fc340?source=rss------bug_bounty-5)
hacking: security in practice
Code execution in restricted VDI environments
Normally, execution of cmd.exe and powershell.exe is prohibited in restricted VDI environments. However, I've seen cases where this can be circumvented by executing a script directly (.bat, .vbs, .ps) and redirect it to another output.
What is the name for this technique? Is it local code execution? What is the risk rating for this use case? High? Medium? Low?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Code execution in restricted VDI environments
Normally, execution of cmd.exe and powershell.exe is prohibited in restricted VDI environments. However, I've seen cases where this can be circumvented by executing a script directly (.bat, .vbs, .ps) and redirect it to another output.
What is the name for this technique? Is it local code execution? What is the risk rating for this use case? High? Medium? Low?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Code execution in restricted VDI environments
Normally, execution of cmd.exe and powershell.exe is prohibited in restricted VDI environments. However, I've seen cases where this can be...
hacking: security in practice
Exfiltrate data with built-in windows ping command
I know it's possible to exfiltrate data using 3rd party tool. But, is it possible to do it with built-in windows ping command on the client side?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Exfiltrate data with built-in windows ping command
I know it's possible to exfiltrate data using 3rd party tool. But, is it possible to do it with built-in windows ping command on the client side?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Exfiltrate data with built-in windows ping command
I know it's possible to exfiltrate data using 3rd party tool. But, is it possible to do it with built-in windows ping command on the client side?
Chương trình tiền thưởng lỗi OpenLeverage
Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium »
Read more...
Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Truffle Security Recommends Doppler For Remediating Leaked Secrets
https://cdn-images-1.medium.com/max/1600/0*WjPHSPycMbPx8XLs.jpg
Keeping your secrets secure is not just about secrets management, but detecting accidental leaks when they occur and fixing them fast.
Continue reading on Doppler »
___________________________
@hacking_Attack
@Hacking_Video
Truffle Security Recommends Doppler For Remediating Leaked Secrets
https://cdn-images-1.medium.com/max/1600/0*WjPHSPycMbPx8XLs.jpg
Keeping your secrets secure is not just about secrets management, but detecting accidental leaks when they occur and fixing them fast.
Continue reading on Doppler »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Truffle Security Recommends Doppler For Remediating Leaked Secrets
Keeping your secrets secure is not just about secrets management, but detecting accidental leaks when they occur and fixing them fast.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I hacked Cambridge, little telling about an easy XSS!
https://cdn-images-1.medium.com/max/1361/1*PJIGzkh3HE9Z4tpo5lq02Q.png
Hey hackers! Hope you guys are doing well! Here I’m back with another writeup of an easy XSS I found in University of Cambridge’s website…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How I hacked Cambridge, little telling about an easy XSS!
https://cdn-images-1.medium.com/max/1361/1*PJIGzkh3HE9Z4tpo5lq02Q.png
Hey hackers! Hope you guys are doing well! Here I’m back with another writeup of an easy XSS I found in University of Cambridge’s website…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I hacked Cambridge, little telling about an easy XSS!
Hey hackers! Hope you guys are doing well! Here I’m back with another writeup of an easy XSS I found in University of Cambridge’s website…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
how to track phone with imei — Knowledge World
https://cdn-images-1.medium.com/max/1280/0*Dx9w9Qqru1bHuU4g.jpg
Friends, I hope everyone is well. At the time we all have smartphones in our hands. You all know that every mobile has two unique IMEI…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
how to track phone with imei — Knowledge World
https://cdn-images-1.medium.com/max/1280/0*Dx9w9Qqru1bHuU4g.jpg
Friends, I hope everyone is well. At the time we all have smartphones in our hands. You all know that every mobile has two unique IMEI…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
how to track phone with imei — Knowledge World
Friends, I hope everyone is well. At the time we all have smartphones in our hands. You all know that every mobile has two unique IMEI…
How To Find Confluence Servers With CVE-2021–26084 Vulnerability Using Nuclei
https://gkarumbi.medium.com/how-to-find-confluence-servers-with-cve-2021-26084-vulnerability-using-nuclei-7b86625127e5?source=rss------bug_bounty-5
Step 1:Continue reading on Medium » (https://gkarumbi.medium.com/how-to-find-confluence-servers-with-cve-2021-26084-vulnerability-using-nuclei-7b86625127e5?source=rss------bug_bounty-5)
https://gkarumbi.medium.com/how-to-find-confluence-servers-with-cve-2021-26084-vulnerability-using-nuclei-7b86625127e5?source=rss------bug_bounty-5
Step 1:Continue reading on Medium » (https://gkarumbi.medium.com/how-to-find-confluence-servers-with-cve-2021-26084-vulnerability-using-nuclei-7b86625127e5?source=rss------bug_bounty-5)
How To Find Confluence Servers With CVE-2021–26084 Vulnerability Using Nuclei
Step 1:Continue reading on Medium »
Read more...
Step 1:Continue reading on Medium »
Read more...
Facebook email disclosure and account takeover
I have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find…Continue reading on Medium »
Read more...
I have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find…Continue reading on Medium »
Read more...
TREVORspray - A Featureful Round-Robin SOCKS Proxy And Python O365 Sprayer Based On MSOLSpray Which Uses The Microsoft Graph API
http://www.kitploit.com/2021/09/trevorspray-featureful-round-robin.html
http://www.kitploit.com/2021/09/trevorspray-featureful-round-robin.html
TREVORproxy is a SOCKS proxy that round-robins requests through SSH hosts. TREVORspray is a A featureful Python O365 sprayer based on MSOLSpray (https://github.com/dafthack/MSOLSpray) which uses the Microsoft Graph API (https://docs.microsoft.com/en-us/graph/overview)By @thetechr0mancer (https://twitter.com/thetechr0mancer)
Microsoft is getting better and better about blocking password spraying attacks against O365. TREVORspray can solve this by proxying its requests through an unlimited number of --ssh hosts. No weird dependencies or cumbersome setup required - all you need is a cloud VM with port 22 open.CREDIT WHERE CREDIT IS DUE - MANY THANKS TO:@dafthack (https://twitter.com/dafthack) for writing MSOLSpray (https://github.com/dafthack/MSOLSpray)@Mrtn9 (https://twitter.com/Mrtn9) for his Python port of MSOLSpray (https://github.com/MartinIngesen/MSOLSpray)@KnappySqwurl (https://twitter.com/KnappySqwurl) for being a splunk wizard and showing me how heckin loud I was being :)
Features
Tells you the status of each account: if it exists, is locked, has MFA enabled, etc.Automatic cancel/resume (attempted user/pass combos are remembered in ./logs/tried_logins.txt)Round-robin proxy through multiple IPs using only vanilla --sshAutomatic infinite reconnect/retry if a proxy goes down (or if you lose internet)Spoofs User-Agent and client_id to look like legitimate auth trafficLogs everything to ./logs/trevorspray.logSaves valid usernames (https://www.kitploit.com/search/label/Usernames) to ./logs/valid_usernames.txtOptional --delay between request to bypass M$ lockout countermeasures
Installation:
$ git clone https://github.com/blacklanternsecurity/trevorspray
$ cd trevorspray
$ pip install -r requirements.txt
Example: Spray O365 with 5-second delay between requests
$ trevorspray.py -e bob@evilcorp.com -p Fall2020! --delay 5
Example: Spray O365 and round-robin between 3 IPs (the current IP is used as well.)
$ trevorspray.py -e emails.txt -p Fall2020! --ssh root@1.2.3.4 root@4.3.2.1
TREVORspray - Help:
traffic through SSH hosts optional arguments: -h, --help show this help message and exit -e EMAILS [EMAILS ...], --emails EMAILS [EMAILS ...] Emails(s) and/or file(s) filled with emails -p PASSWORDS [PASSWORDS ...], --passwords PASSWORDS [PASSWORDS ...] Password(s) that will be used to perform the password spray -f, --force Forces the spray to continue and not stop when multiple account lockouts are detected -d DELAY, --delay DELAY Sleep for this many seconds between requests -u URL, --url URL The URL to spray against (default is https://login.microsoft.com) -v, --verbose Show which proxy is being used for each request -s SSH [SSH ...], --ssh SSH [SSH ...] Round-robin load-balance through these SSH hosts (user@host) NOTE: Current IP address is also used once per round -k KEY, --key KEY Use this SSH key when connecting to proxy hosts -b BASE_PORT, --base-port BASE_PORT Base listening port to use for SOCKS proxies -n, --no-current-ip Don't spray from the current IP, only use SSH proxies ">$ ./trevorspray.py --help
usage: trevorspray.py [-h] -e EMAILS [EMAILS ...] -p PASSWORDS [PASSWORDS ...] [-f] [-d DELAY] [-u URL] [-v] [-s SSH [SSH ...]] [-k KEY] [-b BASE_PORT] [-n]
Execute password sprays against O365, optionally proxying the traffic through SSH hosts
optional arguments:
-h, --help show this help message and exit
-e EMAILS [EMAILS ...], --emails EMAILS [EMAILS ...]
Emails(s) and/or file(s) filled with emails
-p PASSWORDS [PASSWORDS ...], --passwords PASSWORDS [PASSWORDS ...]
Password(s) that will be used to perform the password spray
-f, --force Forces the spray to continue and not stop when multiple account lockouts are detected
-d DELAY, --delay DELAY
Microsoft is getting better and better about blocking password spraying attacks against O365. TREVORspray can solve this by proxying its requests through an unlimited number of --ssh hosts. No weird dependencies or cumbersome setup required - all you need is a cloud VM with port 22 open.CREDIT WHERE CREDIT IS DUE - MANY THANKS TO:@dafthack (https://twitter.com/dafthack) for writing MSOLSpray (https://github.com/dafthack/MSOLSpray)@Mrtn9 (https://twitter.com/Mrtn9) for his Python port of MSOLSpray (https://github.com/MartinIngesen/MSOLSpray)@KnappySqwurl (https://twitter.com/KnappySqwurl) for being a splunk wizard and showing me how heckin loud I was being :)
Features
Tells you the status of each account: if it exists, is locked, has MFA enabled, etc.Automatic cancel/resume (attempted user/pass combos are remembered in ./logs/tried_logins.txt)Round-robin proxy through multiple IPs using only vanilla --sshAutomatic infinite reconnect/retry if a proxy goes down (or if you lose internet)Spoofs User-Agent and client_id to look like legitimate auth trafficLogs everything to ./logs/trevorspray.logSaves valid usernames (https://www.kitploit.com/search/label/Usernames) to ./logs/valid_usernames.txtOptional --delay between request to bypass M$ lockout countermeasures
Installation:
$ git clone https://github.com/blacklanternsecurity/trevorspray
$ cd trevorspray
$ pip install -r requirements.txt
Example: Spray O365 with 5-second delay between requests
$ trevorspray.py -e bob@evilcorp.com -p Fall2020! --delay 5
Example: Spray O365 and round-robin between 3 IPs (the current IP is used as well.)
$ trevorspray.py -e emails.txt -p Fall2020! --ssh root@1.2.3.4 root@4.3.2.1
TREVORspray - Help:
traffic through SSH hosts optional arguments: -h, --help show this help message and exit -e EMAILS [EMAILS ...], --emails EMAILS [EMAILS ...] Emails(s) and/or file(s) filled with emails -p PASSWORDS [PASSWORDS ...], --passwords PASSWORDS [PASSWORDS ...] Password(s) that will be used to perform the password spray -f, --force Forces the spray to continue and not stop when multiple account lockouts are detected -d DELAY, --delay DELAY Sleep for this many seconds between requests -u URL, --url URL The URL to spray against (default is https://login.microsoft.com) -v, --verbose Show which proxy is being used for each request -s SSH [SSH ...], --ssh SSH [SSH ...] Round-robin load-balance through these SSH hosts (user@host) NOTE: Current IP address is also used once per round -k KEY, --key KEY Use this SSH key when connecting to proxy hosts -b BASE_PORT, --base-port BASE_PORT Base listening port to use for SOCKS proxies -n, --no-current-ip Don't spray from the current IP, only use SSH proxies ">$ ./trevorspray.py --help
usage: trevorspray.py [-h] -e EMAILS [EMAILS ...] -p PASSWORDS [PASSWORDS ...] [-f] [-d DELAY] [-u URL] [-v] [-s SSH [SSH ...]] [-k KEY] [-b BASE_PORT] [-n]
Execute password sprays against O365, optionally proxying the traffic through SSH hosts
optional arguments:
-h, --help show this help message and exit
-e EMAILS [EMAILS ...], --emails EMAILS [EMAILS ...]
Emails(s) and/or file(s) filled with emails
-p PASSWORDS [PASSWORDS ...], --passwords PASSWORDS [PASSWORDS ...]
Password(s) that will be used to perform the password spray
-f, --force Forces the spray to continue and not stop when multiple account lockouts are detected
-d DELAY, --delay DELAY
Sleep for this many seconds between requests
-u URL, --url URL The URL to spray against (default is https://login.microsoft.com)
-v, --verbose Show which proxy is being used for each request
-s SSH [SSH ...], --ssh SSH [SSH ...]
Round-robin load-balance through these SSH hosts (user@host) NOTE: Current IP address is also used once per round
-k KEY, --key KEY Use this SSH key when connecting to proxy hosts
-b BASE_PORT, --base-port BASE_PORT
Base listening port to use for SOCKS proxies
-n, --no-current-ip Don't spray from the current IP, only use SSH proxies
Known Limitations:
Untested on WindowsCurrently only works against the M$ Graph API
TREVORproxy - Help:
debugging info -k KEY, --key KEY Use this SSH key when connecting to proxy hosts --base-port BASE_PORT Base listening port to use for SOCKS proxies ">$ ./trevorproxy.py --help
usage: trevorproxy.py [-h] [-p PORT] [-l LISTEN_ADDRESS] [-v] [-k KEY] [--base-port BASE_PORT] ssh_hosts [ssh_hosts ...]
Spawns a SOCKS server which round-robins requests through the specified SSH hosts
positional arguments:
ssh_hosts Round-robin load-balance through these SSH hosts (user@host)
optional arguments:
-h, --help show this help message and exit
-p PORT, --port PORT Port for SOCKS server to listen on (default: 1080)
-l LISTEN_ADDRESS, --listen-address LISTEN_ADDRESS
Listen address for SOCKS server (default: 127.0.0.1)
-v, --verbose Print extra debugging info
-k KEY, --key KEY Use this SSH key when connecting to proxy hosts
--base-port BASE_PORT
Base listening port to use for SOCKS proxies
Download TREVORspray (https://github.com/blacklanternsecurity/TREVORspray)
-u URL, --url URL The URL to spray against (default is https://login.microsoft.com)
-v, --verbose Show which proxy is being used for each request
-s SSH [SSH ...], --ssh SSH [SSH ...]
Round-robin load-balance through these SSH hosts (user@host) NOTE: Current IP address is also used once per round
-k KEY, --key KEY Use this SSH key when connecting to proxy hosts
-b BASE_PORT, --base-port BASE_PORT
Base listening port to use for SOCKS proxies
-n, --no-current-ip Don't spray from the current IP, only use SSH proxies
Known Limitations:
Untested on WindowsCurrently only works against the M$ Graph API
TREVORproxy - Help:
debugging info -k KEY, --key KEY Use this SSH key when connecting to proxy hosts --base-port BASE_PORT Base listening port to use for SOCKS proxies ">$ ./trevorproxy.py --help
usage: trevorproxy.py [-h] [-p PORT] [-l LISTEN_ADDRESS] [-v] [-k KEY] [--base-port BASE_PORT] ssh_hosts [ssh_hosts ...]
Spawns a SOCKS server which round-robins requests through the specified SSH hosts
positional arguments:
ssh_hosts Round-robin load-balance through these SSH hosts (user@host)
optional arguments:
-h, --help show this help message and exit
-p PORT, --port PORT Port for SOCKS server to listen on (default: 1080)
-l LISTEN_ADDRESS, --listen-address LISTEN_ADDRESS
Listen address for SOCKS server (default: 127.0.0.1)
-v, --verbose Print extra debugging info
-k KEY, --key KEY Use this SSH key when connecting to proxy hosts
--base-port BASE_PORT
Base listening port to use for SOCKS proxies
Download TREVORspray (https://github.com/blacklanternsecurity/TREVORspray)
Facebook email disclosure and account takeover
https://rikeshbaniyaaa.medium.com/facebook-email-disclosure-and-account-takeover-ecdb44ee12e9?source=rss------bug_bounty-5
https://rikeshbaniyaaa.medium.com/facebook-email-disclosure-and-account-takeover-ecdb44ee12e9?source=rss------bug_bounty-5
I have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find…Continue reading on Medium » (https://rikeshbaniyaaa.medium.com/facebook-email-disclosure-and-account-takeover-ecdb44ee12e9?source=rss------bug_bounty-5)