Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
SharpStrike - A Post Exploitation Tool Written In C# Uses Either CIM Or WMI To Query Remote Systems

http://4.bp.blogspot.com/-Otf_VvCzU4w/YTVRcJwkDeI/AAAAAAAAua0/Xz7sOQY5CT8AIFY2cbJQCoeT3XwRrwrFACK4BGAYYCw/w640-h388/SharpStrike_2_SharpStrike-GUI-799028.png SharpStrike is a post-exploitation tool written in C# that uses either CIM or WMI to query remote systems. It can use provided credentials or the current user's session.

Note: Some commands will use PowerShell in combination with WMI, denoted with ** in the --show-commandscommand. IntroductionSharpStrike is a C# rewrite and expansion on @Matt_Grandy_'s CIMplant and @christruncer's WMImplant.

SharpStrike allows you to gather data about a remote system, execute commands, exfil data, and more. The tool allows connections using Windows Management Instrumentation, WMI, or Common Interface Model, CIM ; well more accurately Windows Management Infrastructure, MI. CIMplant requires local administrator permissions on the target system. Setup:It's probably easiest to use the built version under Releases, just note that it is compiled in Debug mode. If you want to build the solution yourself, follow the steps below.

1. Load SharpStrike.sln into Visual Studio
2. Go to Build at the top and then Build Solution if no modifications are wanted

The Build will produce two versions of SharpStrike: GUI (WinForms) & Console application. Each version implements the same features. UsageConsole Version:

SharpStrike.exe --help
SharpStrike.exe --show-commands
SharpStrike.exe --show-examples
SharpStrike.exe -c ls_domain_admins
SharpStrike.exe -c ls_domain_users_list
SharpStrike.exe -c cat -f "c:\users\user\desktop\file.txt" -s [remote IP address]
SharpStrike.exe -c cat -f "c:\users\user\desktop\file.txt" -s [remote IP address] -u [username] -d [domain] -p [password] -c
SharpStrike.exe -c command_exec -e "quser" -s [remote IP address] -u [username] -d [domain] -p [password]

GUI version:

show-commands
show-examples
ls_domain_admins
ls_domain_users_list
cat -f "c:\users\user\desktop\file.txt" -s [remote IP address]
cat -f "c:\users\user\desktop\file.txt" -s [remote IP address] -u [username] -d [domain] -p [password]
command_exec -e "quser" [remote IP address] -u [username] -d [domain] -p [password]
FunctionsFile Operations:cat - Reads the contents of a file
copy - Copies a file from one location to another
download** - Download a file from the targeted machine
ls - File/Directory listing of a specific directory
search - Search for a file on a user
upload** - Upload a file to the targeted machine
Lateral Movement Facilitationcommand line command and receive the output. Run with nops flag to disable PowerShell disable_wdigest - Sets the registry value for UseLogonCredential to zero enable_wdigest - Adds registry value UseLogonCredential disable_winrm** - Disables WinRM on the targeted system enable_winrm** - Enables WinRM on the targeted system reg_mod - Modify the registry on the targeted machine reg_create - Create the registry value on the targeted machine reg_delete - Delete the registry on the targeted machine remote_posh** - Run a PowerShell script on a remote machine and receive the output sched_job - Not implimented due to the Win32_ScheduledJobs accessing an outdated API service_mod - Create, delete, or modify system services ls_domain_users*** - List domain users ls_domain_users_list*** [...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! SharpStrike - A Post Exploitation Tool Written In C# Uses Either CIM Or WMI To Query Remote Systems http://4.bp.blogspot.com/-Otf_VvCzU4w/YTVRcJwkDeI/AAAAAAAAua0/Xz7sOQY5CT8AIFY2cbJQCoeT3XwRrwrFACK4BGAYYCw/w640-h388/SharpStrike_2_SharpStrike…
- List domain users sAMAccountName ls_domain_users_email*** - List domain users email address ls_domain_groups*** - List domain user groups ls_domain_admins*** - List domain admin users ls_user_groups*** - List domain user with their associated groups ls_computers*** - List computers on current domain ">command_exec** - Run a command line command and receive the output. Run with nops flag to disable PowerShell
disable_wdigest - Sets the registry value for UseLogonCredential to zero
enable_wdigest - Adds registry value UseLogonCredential
disable_winrm** - Disables WinRM on the targeted system
enable_winrm** - Enables WinRM on the targeted system
reg_mod - Modify the registry on the targeted machine
reg_create - Create the registry value on the targeted machine
reg_delete - Delete the registry on the targeted machine
remote_posh** - Run a PowerShell script on a remote machine and receive the output
sched_job - Not implimented due to the Win32_ScheduledJobs accessing an outdated API
service_mod - Create, delete, or modify system services
ls_do main_users*** - List domain users
ls_domain_users_list*** - List domain users sAMAccountName
ls_domain_users_email*** - List domain users email address
ls_domain_groups*** - List domain user groups
ls_domain_admins*** - List domain admin users
ls_user_groups*** - List domain user with their associated groups
ls_computers*** - List computers on current domain
Process Operationsprocess_kill - Kill a process via name or process id on the targeted machine
process_start - Start a process on the targeted machine
ps - Process listing
System Operationsactive_users - List domain users with active processes on the targeted system
basic_info - Used to enumerate basic metadata about the targeted system
drive_list - List local and network drives
share_list - List network shares
ifconfig - Receive IP info from NICs with active network connections
installed_programs - Receive a list of the installed programs on the targeted machine
logoff - Log users off the targeted machine
reboot (or restart) - Reboot the targeted machine
power_off (or shutdown) - Power off the targeted machine
vacant_system - Determine if a user is away from the system
edr_query - Query the local or remote system for EDR vendors
Log Operationslogon_events - Identify users that have logged onto a system

* All PowerShell can be disabled by using the --nops flag, although some commands will not execute (upload/download, enable/disable WinRM)
** Denotes PowerShell usage (either using a PowerShell Runspace or through Win32_Process::Create method)
*** Denotes LDAP usage - "root\directory\ldap" namespace
Some Example Usage CommandsConsole version: https://github.com/iomoath/SharpStrike/raw/master/Extras/SharpStrike-Usage.gif?raw=true GUI version: http://4.bp.blogspot.com/-Otf_VvCzU4w/YTVRcJwkDeI/AAAAAAAAua0/Xz7sOQY5CT8AIFY2cbJQCoeT3XwRrwrFACK4BGAYYCw/w640-h388/SharpStrike_2_SharpStrike-GUI-799028.png Solution ArchitectureSharpStrike is composed of three main projects

1. ServiceLayer -- Provides core functionality and consumed by the UI layer
2. Models -- Contains types, shared across all projects
3. User Interface -- GUI/Console ServiceLayer1. Connector[...]
Hacking Articles Tips Tricks Videos Tutorials
- List domain users sAMAccountName ls_domain_users_email*** - List domain users email address ls_domain_groups*** - List domain user groups ls_domain_admins*** - List…
.cs

This is where the initial CIM/WMI connections are made and passed to the rest of the application

1. ExecuteWMI.cs

All function code for the WMI commands

1. ExecuteCIM.cs

All function code for the CIM (MI) commands Read moreCIMplant Part 1: Detection of a C# Implementation of WMImplant WMImplant – A WMI Based Agentless Post-Exploitation RAT Developed in PowerShell SharpStrike | Post-exploitation tool | CIM & WMI Inside Download SharpStrike
AWS cloud pentesting. PACSP : Pentester Academy Cloud Security Bootcamp and Certification Review.
https://www.reddit.com/r/Pentesting/comments/pkr0s2/aws_cloud_pentesting_pacsp_pentester_academy/
hacking: security in practice
Arpspoofing not working

Apologies for bad formatting I am typing this from mobile

I am pretty new to this stuff so sorry if I am not using proper terminology I am using 2 virtual boxes, both use nat network, 1 is kali and another is windows. While using arpspoofing I am able to spoof the windows such that after spoofing the mac address of the network in windows is changing to that of kali machine but even after port forwarding windows is unable to use internet

The commands I am using on kali (on 3 seperate root terminals)

$ arpspoofing -i eth0 -t 10.0.2.1 10.0.2.4

$ arpspoofing -i eth0 -t 10.0.2.4 10.0.2.1

$ echo 1 > /proc/sys/net/ipv4/ip_forward

So any help would be appreciated

Edit: Some formatting

submitted by /u/Varad_88
[link] [comments]
Tryhackme Gatekeeper Walkthrough

Hi guys my name is Ahmed and my nickname is SadC0d3rContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft shares temp fix for ongoing Office 365 zero-day attacks

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft shares temp fix for ongoing Office 365 zero-day attacksPost Views: 83
Reading Time: 1 Minute
Microsoft shared yesterday a mitigation for a remote code execution vulnerability in Windows that is being exploited in targeted attacks against Office 365 and Office 2019 on Windows 10.
The flaw is in MSHTML, the browser rendering engine that is also used by Microsoft Office documents. Ongoing attacks against Office 365Identified as CVE-2021-40444, the security issue affects Windows Server 2008 through 2019 and Windows 8.1 through 10 and has a severity level of 8.8 out of the maximum 10.

Microsoft is aware of targeted attacks that try to exploit the vulnerability by sending specially-crafted Microsoft Office documents to potential victims, the company says in an advisory today.
“An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document” – Microsoft
However, the attack is thwarted if Microsoft Office runs with the default configuration, where documents from the web are opened in Protected View mode or Application Guard for Office 365.

Protected View is a read-only mode that has most of the editing functions disabled, while Application Guard isolates untrusted documents, denying them access to corporate resources, the intranet, or other files on the system.

Systems with active Microsoft’s Defender Antivirus and Defender for Endpoint (build 1.349.22.0 and above) benefit from protection against attempts to exploit CVE-2021-40444.

Microsoft’s enterprise security platform will display alerts about this attack as “Suspicious Cpl File Execution.”
See Also: Complete Offensive Security and Ethical Hacking Course Researchers from multiple cybersecurity companies are credited for finding and reporting the vulnerability: Haifei Li of EXPMON, Dhanesh Kizhakkinan, Bryce Abdo, and Genwei Jiang – all three of Mandiant, and Rick Cole of Microsoft Security Intelligence.

In a tweet today, EXPMON (exploit monitor) says that they found the vulnerability after detecting a “highly sophisticated zero-day attack” aimed at Microsoft Office users.
https://www.bleepstatic.com/images/news/u/1100723/2021/EXPMONBug-40444.jpg
<figcaptionsource: EXPMON
EXPMON researchers reproduced the attack on the latest Office 2019 / Office 365 on Windows 10.

In a reply to BleepingComputer, Haifei Li of EXPMON said that the attackers used a .DOCX file. Upon opening it, the document loaded the Internet Explorer engine to render a remote web page from the threat actor.

Malware is then downloaded by using a specific ActiveX control in the web page. Executing the threat is done using “a trick called ‘Cpl File Execution’,” referenced in Microsoft’s advisory.

The researcher told us that the attack method is 100% reliable, which makes it very dangerous. He reported the vulnerability to Microsoft early Sunday morning.
See Also: Bluetooth Bugs Open Billions of Devices to DoS, Code Execution Workaround for CVE-2021-40444 zero-day attacksAs there is no security update available at this time, Microsoft has provided the following workaround – disable the installation of all ActiveX controls in Internet Explorer.

A Windows registry update ensures that ActiveX is rendered inactive for all sites, while already available ActiveX controls will keep functioning.

Users should save the file below with the .REG extension and execute it t[...]