Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Trying to automate the login on a Captive Portal Hi there, So I was just trying to automate the login on a Captive Portal on an AP that I use for work in order to be able to connect my headless Raspberry Pito the network. (I…
omatically
My main question: It looks like the Real Captive Portal uses some sort of encription . But I believe that is available on the HTML code as the POST needs to be done client side. - Is this Encryption process perform by some of the javascript of this landing page? - Am I wrong about many of this assumptions?
Thanks for your help , I will keep you updated with my advatanges as I still need to inspect the JS code and maybe some more php files (although chances are that those have not been indexed)
submitted by /u/brohermano [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
My main question: It looks like the Real Captive Portal uses some sort of encription . But I believe that is available on the HTML code as the POST needs to be done client side. - Is this Encryption process perform by some of the javascript of this landing page? - Am I wrong about many of this assumptions?
Thanks for your help , I will keep you updated with my advatanges as I still need to inspect the JS code and maybe some more php files (although chances are that those have not been indexed)
submitted by /u/brohermano [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to get a reverse shell in my netcat from outside LAN
I am trying to get a reverse shell from outside my LAN on my netcat but I am unable to do so I am on my linux machine and using my laptop for sending a connection request but I am not getting a callback on my linux machine.
So what are the techniques to get shell from outside my network .
submitted by /u/CoolNCocky
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to get a reverse shell in my netcat from outside LAN
I am trying to get a reverse shell from outside my LAN on my netcat but I am unable to do so I am on my linux machine and using my laptop for sending a connection request but I am not getting a callback on my linux machine.
So what are the techniques to get shell from outside my network .
submitted by /u/CoolNCocky
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to get a reverse shell in my netcat from outside LAN
I am trying to get a reverse shell from outside my LAN on my netcat but I am unable to do so I am on my linux machine and using my laptop for...
hacking: security in practice
Sorry if I'm asking in the wrong subreddit. But if one wasn't using a VPN or anything that would have a proxy how off would an IP be location wise?
I'm really not smart when it comes to this stuff so I apologize if this is not the place to ask but would an IP address show several states away... Several hundred miles... if a VPN was not being used? I know that an IP is not an exact location, and that some apps like Gmail use a proxy but usually if those aren't being used it shows an IP within a close radius of the actual spot. In this case the person I'm looking at is hundreds of miles away. This is a domestic abuse situation so we're trying to determine if the person we're attempting to hide from is on vacation or something
submitted by /u/Drinking-Lightning
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Sorry if I'm asking in the wrong subreddit. But if one wasn't using a VPN or anything that would have a proxy how off would an IP be location wise?
I'm really not smart when it comes to this stuff so I apologize if this is not the place to ask but would an IP address show several states away... Several hundred miles... if a VPN was not being used? I know that an IP is not an exact location, and that some apps like Gmail use a proxy but usually if those aren't being used it shows an IP within a close radius of the actual spot. In this case the person I'm looking at is hundreds of miles away. This is a domestic abuse situation so we're trying to determine if the person we're attempting to hide from is on vacation or something
submitted by /u/Drinking-Lightning
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Sorry if I'm asking in the wrong subreddit. But if one wasn't...
I'm really not smart when it comes to this stuff so I apologize if this is not the place to ask but would an IP address show several states...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Bridging the gap for the newcomers - gamified experience
Hey Community!
Last week, World Wide Hack by Lotus Innovations has its Kickstarter launched. I had the opportunity to play the alpha versions and I find this game has a great potential, it is very stable and there is a lot more than just "another hacking MMO". I'm myself a propagator of learning cybersecurity on my blog and I have written the first impression here: https://blog.cyberethical.me/world-wide-hack-alpha-first-impression
Gamified experience can be sometimes enough to bridge the gap for people wanting to try offensive security for the first time.
I'm not associated or sponsored by the developers of the WWH, just want to game to get as much exposure as it is possible, without force-advertising.
submitted by /u/Asentinn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Bridging the gap for the newcomers - gamified experience
Hey Community!
Last week, World Wide Hack by Lotus Innovations has its Kickstarter launched. I had the opportunity to play the alpha versions and I find this game has a great potential, it is very stable and there is a lot more than just "another hacking MMO". I'm myself a propagator of learning cybersecurity on my blog and I have written the first impression here: https://blog.cyberethical.me/world-wide-hack-alpha-first-impression
Gamified experience can be sometimes enough to bridge the gap for people wanting to try offensive security for the first time.
I'm not associated or sponsored by the developers of the WWH, just want to game to get as much exposure as it is possible, without force-advertising.
submitted by /u/Asentinn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bridging the gap for the newcomers - gamified experience
Hey Community! Last week, World Wide Hack by Lotus Innovations has its Kickstarter launched. I had the opportunity to play the alpha versions and...
hacking: security in practice
Should I learn to write shellcodes? Or assembly in general?
I'm new to the field of exploit development. The reason I'm asking this is because recently, I started this course on writing assembly and shellcodes, and tbh I'm really hooked.
But I'm always thinking if this stuff is still relevant today? Like the course I'm doing is really old from I guess 2009-2010. I want to know if this knowledge is going to help me, maybe write exploits in the real world if I take it seriously. Also, the fact that most of the shellcodes are readily available from metasploit, makes me wonder if i should learn it.
Sorry if this is the wrong sub to ask.
submitted by /u/scaryAstronaut
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Should I learn to write shellcodes? Or assembly in general?
I'm new to the field of exploit development. The reason I'm asking this is because recently, I started this course on writing assembly and shellcodes, and tbh I'm really hooked.
But I'm always thinking if this stuff is still relevant today? Like the course I'm doing is really old from I guess 2009-2010. I want to know if this knowledge is going to help me, maybe write exploits in the real world if I take it seriously. Also, the fact that most of the shellcodes are readily available from metasploit, makes me wonder if i should learn it.
Sorry if this is the wrong sub to ask.
submitted by /u/scaryAstronaut
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Should I learn to write shellcodes? Or assembly in general?
I'm new to the field of exploit development. The reason I'm asking this is because recently, I started this course on writing assembly and...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Vaccine has been Pwned!
https://cdn-images-1.medium.com/max/1280/1*ZTVO613o26a5KhNCNioIhA.jpeg
Hack The Box Vaccine walkthrough. This machine requires service enumeration, File Transfer Protocol, SQL Injection and further enumeration.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vaccine has been Pwned!
https://cdn-images-1.medium.com/max/1280/1*ZTVO613o26a5KhNCNioIhA.jpeg
Hack The Box Vaccine walkthrough. This machine requires service enumeration, File Transfer Protocol, SQL Injection and further enumeration.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vaccine has been Pwned!
Hack The Box Vaccine walkthrough. This machine requires service enumeration, File Transfer Protocol, SQL Injection and further enumeration.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[BEST OFFERS] Get Certified online
https://cdn-images-1.medium.com/max/672/1*iugaYQyXvZ7RDiGLsLDKmw.jpeg
ATTENTION students!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
[BEST OFFERS] Get Certified online
https://cdn-images-1.medium.com/max/672/1*iugaYQyXvZ7RDiGLsLDKmw.jpeg
ATTENTION students!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
[BEST OFFERS😍] 📢Get Certified online
ATTENTION students!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SnakeOil
https://cdn-images-1.medium.com/max/630/0*XB0MfbLhDL8SGPyR.png
Link: https://www.vulnhub.com/entry/snakeoil-1,738/
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SnakeOil
https://cdn-images-1.medium.com/max/630/0*XB0MfbLhDL8SGPyR.png
Link: https://www.vulnhub.com/entry/snakeoil-1,738/
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SnakeOil
Link: https://www.vulnhub.com/entry/snakeoil-1,738/
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Cyber Attackers Can Hack Your Car?
https://cdn-images-1.medium.com/max/2600/0*hGhZp4WXxfx_qba0
Technology Cyber Attacks.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Cyber Attackers Can Hack Your Car?
https://cdn-images-1.medium.com/max/2600/0*hGhZp4WXxfx_qba0
Technology Cyber Attacks.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Cyber Attackers Can Hack Your Car?
Vehicles Cyber Attacks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
¿QUÉ ES UN FIREWALL AS A SERVICE (FWAAS)?
https://cdn-images-1.medium.com/max/1013/0*rU1HFoAtxpvn2jPE
PUBLICADO EN 8 SEPTIEMBRE, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
¿QUÉ ES UN FIREWALL AS A SERVICE (FWAAS)?
https://cdn-images-1.medium.com/max/1013/0*rU1HFoAtxpvn2jPE
PUBLICADO EN 8 SEPTIEMBRE, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
¿QUÉ ES UN FIREWALL AS A SERVICE (FWAAS)?
PUBLICADO EN 8 SEPTIEMBRE, 2021 POR EHACKING
SharpStrike - A Post Exploitation Tool Written In C# Uses Either CIM Or WMI To Query Remote Systems
http://www.kitploit.com/2021/09/sharpstrike-post-exploitation-tool.html
http://www.kitploit.com/2021/09/sharpstrike-post-exploitation-tool.html
Setup:
It's probably easiest to use the built version under Releases, just note that it is compiled in Debug mode. If you want to build the solution yourself, follow the steps below. Load SharpStrike.sln into Visual Studio Go to Build at the top and then Build Solution if no modifications are wanted The Build will produce two versions of SharpStrike: GUI (WinForms) & Console application. Each version implements the same features.
Usage
Console Version:
SharpStrike.exe --help
SharpStrike.exe --show-commands
SharpStrike.exe --show-examples
SharpStrike.exe -c ls_domain_admins
SharpStrike.exe -c ls_domain_users_list
SharpStrike.exe -c cat -f "c:\users\user\desktop\file.txt" -s [remote IP address]
SharpStrike.exe -c cat -f "c:\users\user\desktop\file.txt" -s [remote IP address] -u [username] -d [domain] -p [password] -c
SharpStrike.exe -c command_exec -e "quser" -s [remote IP address] -u [username] -d [domain] -p [password]
GUI version:
show-commands
show-examples
ls_domain_admins
ls_domain_users_list
cat -f "c:\users\user\desktop\file.txt" -s [remote IP address]
cat -f "c:\users\user\desktop\file.txt" -s [remote IP address] -u [username] -d [domain] -p [password]
command_exec -e "quser" [remote IP address] -u [username] -d [domain] -p [password]
Functions
File Operations:
cat - Reads the contents of a file
copy - Copies a file from one location to another
download** - Download a file from the targeted machine
ls - File/Directory listing of a specific directory
search - Search for a file on a user
upload** - Upload a file to the targeted machine
Lateral Movement Facilitation
command line command and receive the output. Run with nops flag to disable PowerShell disable_wdigest - Sets the registry value for UseLogonCredential to zero enable_wdigest - Adds registry value UseLogonCredential disable_winrm** - Disables WinRM on the targeted system enable_winrm** - Enables WinRM on the targeted system reg_mod - Modify the registry on the targeted machine reg_create - Create the registry value on the targeted machine reg_delete - Delete the registry on the targeted machine remote_posh** - Run a PowerShell script on a remote machine and receive the output sched_job - Not implimented due to the Win32_ScheduledJobs accessing an outdated API service_mod - Create, delete, or modify system services ls_domain_users*** - List domain users ls_domain_users_list*** - List domain users sAMAccountName ls_domain_users_email*** - List domain users email address ls_domain_groups*** - List domain user groups ls_domain_admins*** - List domain admin users ls_user_groups*** - List domain user with their associated groups ls_computers*** - List computers on current domain ">command_exec** - Run a command line command and receive the output. Run with nops flag to disable PowerShell
disable_wdigest - Sets the registry value for UseLogonCredential to zero
enable_wdigest - Adds registry value UseLogonCredential
disable_winrm** - Disables WinRM on the targeted system
enable_winrm** - Enables WinRM on the targeted system
reg_mod - Modify the registry on the targeted machine
reg_create - Create the registry value on the targeted machine
reg_delete - Delete the registry on the targeted machine
remote_posh** - Run a PowerShell script on a remote machine and receive the output
It's probably easiest to use the built version under Releases, just note that it is compiled in Debug mode. If you want to build the solution yourself, follow the steps below. Load SharpStrike.sln into Visual Studio Go to Build at the top and then Build Solution if no modifications are wanted The Build will produce two versions of SharpStrike: GUI (WinForms) & Console application. Each version implements the same features.
Usage
Console Version:
SharpStrike.exe --help
SharpStrike.exe --show-commands
SharpStrike.exe --show-examples
SharpStrike.exe -c ls_domain_admins
SharpStrike.exe -c ls_domain_users_list
SharpStrike.exe -c cat -f "c:\users\user\desktop\file.txt" -s [remote IP address]
SharpStrike.exe -c cat -f "c:\users\user\desktop\file.txt" -s [remote IP address] -u [username] -d [domain] -p [password] -c
SharpStrike.exe -c command_exec -e "quser" -s [remote IP address] -u [username] -d [domain] -p [password]
GUI version:
show-commands
show-examples
ls_domain_admins
ls_domain_users_list
cat -f "c:\users\user\desktop\file.txt" -s [remote IP address]
cat -f "c:\users\user\desktop\file.txt" -s [remote IP address] -u [username] -d [domain] -p [password]
command_exec -e "quser" [remote IP address] -u [username] -d [domain] -p [password]
Functions
File Operations:
cat - Reads the contents of a file
copy - Copies a file from one location to another
download** - Download a file from the targeted machine
ls - File/Directory listing of a specific directory
search - Search for a file on a user
upload** - Upload a file to the targeted machine
Lateral Movement Facilitation
command line command and receive the output. Run with nops flag to disable PowerShell disable_wdigest - Sets the registry value for UseLogonCredential to zero enable_wdigest - Adds registry value UseLogonCredential disable_winrm** - Disables WinRM on the targeted system enable_winrm** - Enables WinRM on the targeted system reg_mod - Modify the registry on the targeted machine reg_create - Create the registry value on the targeted machine reg_delete - Delete the registry on the targeted machine remote_posh** - Run a PowerShell script on a remote machine and receive the output sched_job - Not implimented due to the Win32_ScheduledJobs accessing an outdated API service_mod - Create, delete, or modify system services ls_domain_users*** - List domain users ls_domain_users_list*** - List domain users sAMAccountName ls_domain_users_email*** - List domain users email address ls_domain_groups*** - List domain user groups ls_domain_admins*** - List domain admin users ls_user_groups*** - List domain user with their associated groups ls_computers*** - List computers on current domain ">command_exec** - Run a command line command and receive the output. Run with nops flag to disable PowerShell
disable_wdigest - Sets the registry value for UseLogonCredential to zero
enable_wdigest - Adds registry value UseLogonCredential
disable_winrm** - Disables WinRM on the targeted system
enable_winrm** - Enables WinRM on the targeted system
reg_mod - Modify the registry on the targeted machine
reg_create - Create the registry value on the targeted machine
reg_delete - Delete the registry on the targeted machine
remote_posh** - Run a PowerShell script on a remote machine and receive the output
sched_job - Not implimented due to the Win32_ScheduledJobs accessing an outdated API
service_mod - Create, delete, or modify system services
ls_do main_users*** - List domain users
ls_domain_users_list*** - List domain users sAMAccountName
ls_domain_users_email*** - List domain users email address
ls_domain_groups*** - List domain user groups
ls_domain_admins*** - List domain admin users
ls_user_groups*** - List domain user with their associated groups
ls_computers*** - List computers on current domain
Process Operations
process_kill - Kill a process via name or process id on the targeted machine
process_start - Start a process on the targeted machine
ps - Process listing
System Operations
active_users - List domain users with active processes on the targeted system
basic_info - Used to enumerate basic metadata about the targeted system
drive_list - List local and network drives
share_list - List network shares
ifconfig - Receive IP info from NICs with active network connections
installed_programs - Receive a list of the installed programs on the targeted machine
logoff - Log users off the targeted machine
reboot (or restart) - Reboot the targeted machine
power_off (or shutdown) - Power off the targeted machine
vacant_system - Determine if a user is away from the system
edr_query - Query the local or remote system for EDR vendors
Log Operations
logon_events - Identify users that have logged onto a system
* All PowerShell can be disabled by using the --nops flag, although some commands will not execute (upload/download, enable/disable WinRM)
** Denotes PowerShell usage (either using a PowerShell Runspace or through Win32_Process::Create method)
*** Denotes LDAP usage - "root\directory\ldap" namespace
Some Example Usage Commands
Console version:
service_mod - Create, delete, or modify system services
ls_do main_users*** - List domain users
ls_domain_users_list*** - List domain users sAMAccountName
ls_domain_users_email*** - List domain users email address
ls_domain_groups*** - List domain user groups
ls_domain_admins*** - List domain admin users
ls_user_groups*** - List domain user with their associated groups
ls_computers*** - List computers on current domain
Process Operations
process_kill - Kill a process via name or process id on the targeted machine
process_start - Start a process on the targeted machine
ps - Process listing
System Operations
active_users - List domain users with active processes on the targeted system
basic_info - Used to enumerate basic metadata about the targeted system
drive_list - List local and network drives
share_list - List network shares
ifconfig - Receive IP info from NICs with active network connections
installed_programs - Receive a list of the installed programs on the targeted machine
logoff - Log users off the targeted machine
reboot (or restart) - Reboot the targeted machine
power_off (or shutdown) - Power off the targeted machine
vacant_system - Determine if a user is away from the system
edr_query - Query the local or remote system for EDR vendors
Log Operations
logon_events - Identify users that have logged onto a system
* All PowerShell can be disabled by using the --nops flag, although some commands will not execute (upload/download, enable/disable WinRM)
** Denotes PowerShell usage (either using a PowerShell Runspace or through Win32_Process::Create method)
*** Denotes LDAP usage - "root\directory\ldap" namespace
Some Example Usage Commands
Console version: