Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Owt - The Most Compact WiFi Auditing Tool That Works On Command Line Linux

http://4.bp.blogspot.com/-47zK45rNNLA/YTVOua-LQZI/AAAAAAAAuOQ/k5ma7Uosp3gkK_4A5k7dyVJXQk3QcAzugCK4BGAYYCw/w640-h150/owt_1_img6-703729.png
This tool compiles some necessary tools for wifi auditing in a unix bash script with a user friendly interface. The goal of owt is to have the smallest file size possible while still functioning at maximum proficiency.
Installation & Running the script

~ $ git clone https://github.com/clu3bot/OWT.git
~ $ cd owt
~ $ sudo bash owt.sh


Note: owt requires root privileges

Make sure to allow updates regularly

Usage

Detailed How-to of owt can be found here

* Usage

Troubleshooting

Troubleshoot.sh will detect possible problems you may have with owt

~ $ cd owt
~ $ sudo bash troubleshoot.sh


owt Premium Edition

* Premium

Dependencies

* aircrack-ng
* mdk3
* xterm
* macchanger
* owt tool will prompt the user to download these dependencies if they arent installed.

In The Works

* Expanding owt from being just for wireless network attacking. More information below.
* Adding more advanced functionality to owt such as NTP amplification attacks to screw with NTP servers for dosing websites.
* Adding AP tracking functionality and ability to save lists of common saved networks that devices have in the area. I.E if there is a starbucks near by you can track if starbucks is a common AP that phones in the area have as a saved network. This is useful for knowing which APs to spoof.
* Adding a method of saving text or csv files of device names and mac-addresses on a newtwork.
* Making a windows version of owt.
* Major U.I changes
* Fixing the "issue" where owt doesn't support use within Virtual Machines. Not priority as this is a pain in the ass but has been requested :)

History

owt Version History can be found here

* Versions

Stable Releases Source Code can be found here

* Releases

All Resources

* Contact me here
* Tutorial for owt here
* owt wiki here
* Updates/Versions history here
* Help and Troubleshooting here

Legal Notice

This script is intended to be used on networks you own. Don't use this script maliciously. You are responsible for your own actions.
Download Owt

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
New fucked australian police laws

Haven't researched much about it but from what I know new laws in australia allow the police to access your computer, add, delete and modify files based on very broad circumstances and without a warrant approved. I was wondering if anyone knew any ways to get around this?

What I say next is just what I think would work but I'm pretty new so would love some honest criticism

I'm thinking a vpn although i'm assuming that most of the popular ones would have to have a backdoor when sold to an australian. Also I think virus protection software would have one to make sure the police force can access the computer. What can I do if the software I need is backdoored?

Sorry if this is a bit confusing, again I'm new to all of this but I'm willing to answer questions to clear up anything that doesn't make sense.

Also here are some articles about it if you want to read more

https://tutanota.com/blog/posts/australia-surveillance-bill/

https://www.xycinews.com/new-surveillance-laws-give-authorities-the-power-to-change-social-media-posts/

https://thenextweb.com/news/new-surveillance-laws-authorities-power-change-social-media-posts-syndication

submitted by /u/yaydabear
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Hardware Hacking (RF, RFID, NFC, MagStripe, SmartCard, etc).

Hey r/Hacking!

Hope you’ve had a fantastic day.

I’m a college student and I’ve got some money lying around I could use to buy some tools to expand my hardware hacking skills.

I’m aware there exists a LOT of different tools for different things. I’ve done research and found 4 different things that do RFID reading and writing, but couldn’t quite figure out which was the best.

I’m looking to read/write RF, RFID, NFC, MagStripe and SmartCard and resources I could learn from.

This far, I’ve found the RF One by Hak5 for RF.

Proxmark for RFID and NFC.

MSR605X for MagStripe.

Any SmartCard tools?

Thank you!

submitted by /u/secjoe
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Thoughts on how to protect against a LSA secrets dump/ NTDS.DIT attack

Looking to probe the minds of the many brilliant people on here as to how I can protect our environment from a attack. We recently had a security audit and the tester was able to pull clear text passwords from some PCs from LSA and use that to move laterally. Then he found some admin creds in clear text and game over was able to pull the entire NTDS.DIT database. We have since then made the following changes:

Limited credentials to be cached to 0 and 1 in some instances (laptops)

Disabled Debugging/ added LSA protection as per Microsoft article "Here"

Deployed LAPS for local admin password policys to avoid the lateral movement.

Patched the heck out of all servers via nessus vul scan /results.

How else could I protect myself from this kind of attack in future or block this kind of toolset.

submitted by /u/idahud
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
일이 취미가 되고 취미가 일이 될 때

새로운 취미를 함께 즐기는 동료를 만날 수 있어요!Continue reading on Delivery Tech Korea — 요기요기술 블로그 »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bus Pass Management System 1.0 Cross Site Scripting

https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Bus Pass Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

MD5 | c6c1e5986347851fef16dc0de5d2b63f

Download
# Exploit Title: Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
# Date: 2021-09-08
# Exploit Author: Emre Aslan
# Vendor Homepage: https://phpgurukul.com/
# Software Link: https://phpgurukul.com/wp-content/uploads/2021/07/Bus-Pass-Management-System-Using-PHP-MySQL.zip
# Version: 1.0
# Tested on: Windows 11 - XAMPP Server

# Vulnerable page: host/admin/*

# Vulnerable Code:

Admin[PAYLOAD]
# Vulnerable Parameter: adminname[ POST Data ]

# Tested Payload:

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video