hacking: security in practice
Anyone know where to find a copy of Backtrack (not Kali)?
I know it’s a long shot for sure, but my dad used to be a pen tester (Cisco Certified with Bachelor’s in 2005) and he was talking about Backtrack being his favorite OS from the time.
I’m going into the field at the moment and would love to play with the OS my dad used during CTF back in the day.
submitted by /u/Le_7r011
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anyone know where to find a copy of Backtrack (not Kali)?
I know it’s a long shot for sure, but my dad used to be a pen tester (Cisco Certified with Bachelor’s in 2005) and he was talking about Backtrack being his favorite OS from the time.
I’m going into the field at the moment and would love to play with the OS my dad used during CTF back in the day.
submitted by /u/Le_7r011
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anyone know where to find a copy of Backtrack (not Kali)?
I know it’s a long shot for sure, but my dad used to be a pen tester (Cisco Certified with Bachelor’s in 2005) and he was talking about Backtrack...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Future of binary exploitation
Hello! I'm starting to learn about binary exploitation and 0day development. I have learned about stackoverflows, ASLR, DEP, stack cookies and so on... But then I came across this video:
https://www.youtube.com/watch?v=o_hk9nh8S1M
I was very motivated by the subject, but after watching that video, I really don't know if it is worth the effort to keep learning about this.
Do you think that memory corrumption techniques will disappear completely in the future? What about binary exploitation and 0day development in general? Will it completly disappear?
And by binary exploitation I mean this exploits that hackers use in chrome, ios, safari, etc. To gain remote code execution without user interaction.
Thanks.
submitted by /u/PuzzledWhereas991
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Future of binary exploitation
Hello! I'm starting to learn about binary exploitation and 0day development. I have learned about stackoverflows, ASLR, DEP, stack cookies and so on... But then I came across this video:
https://www.youtube.com/watch?v=o_hk9nh8S1M
I was very motivated by the subject, but after watching that video, I really don't know if it is worth the effort to keep learning about this.
Do you think that memory corrumption techniques will disappear completely in the future? What about binary exploitation and 0day development in general? Will it completly disappear?
And by binary exploitation I mean this exploits that hackers use in chrome, ios, safari, etc. To gain remote code execution without user interaction.
Thanks.
submitted by /u/PuzzledWhereas991
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Future of binary exploitation
Hello! I'm starting to learn about binary exploitation and 0day development. I have learned about stackoverflows, ASLR, DEP, stack cookies and so...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
ICYMI: Security and ATOs…
https://cdn-images-1.medium.com/max/1242/1*Abg0R34-0ek4A9Vczg9NwA.png
ICYMI is an ongoing series of blog posts memorializing important Twitter threads from thought leaders at Coinbase and beyond. In this…
Continue reading on The Coinbase Blog »
___________________________
@hacking_Attack
@Hacking_Video
ICYMI: Security and ATOs…
https://cdn-images-1.medium.com/max/1242/1*Abg0R34-0ek4A9Vczg9NwA.png
ICYMI is an ongoing series of blog posts memorializing important Twitter threads from thought leaders at Coinbase and beyond. In this…
Continue reading on The Coinbase Blog »
___________________________
@hacking_Attack
@Hacking_Video
Do you share every single findings to stakeholder?
https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/
Taken from rapid7 (https://www.rapid7.com/blog/post/2016/06/23/penetration-testing-vs-red-teaming-the-age-old-debate-of-pirates-vs-ninja-continues/) The goal of the Red Team Assessment is NOT to find as many vulnerabilities as possible. The goal is to test the organization's detection and response capabilities. Question is, do you share every single findings that you have in Red Team Assessment? Or do you keep some of them to be used in the following exercise later? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/) [comments] (https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/
Taken from rapid7 (https://www.rapid7.com/blog/post/2016/06/23/penetration-testing-vs-red-teaming-the-age-old-debate-of-pirates-vs-ninja-continues/) The goal of the Red Team Assessment is NOT to find as many vulnerabilities as possible. The goal is to test the organization's detection and response capabilities. Question is, do you share every single findings that you have in Red Team Assessment? Or do you keep some of them to be used in the following exercise later? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/) [comments] (https://www.reddit.com/r/redteamsec/comments/pohpm0/do_you_share_every_single_findings_to_stakeholder/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Do you share every single findings to stakeholder?
Taken from...
How to "hack" Roku TVs in 5 minutes!
https://www.reddit.com/r/Pentesting/comments/pojdsq/how_to_hack_roku_tvs_in_5_minutes/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/pojdsq/how_to_hack_roku_tvs_in_5_minutes/
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to "hack" Roku TVs in 5 minutes!
Posted in r/Pentesting by u/entropydaemon3 • 1 point and 0 comments
submitted by /u/entropydaemon3 (https://www.reddit.com/user/entropydaemon3)
[link] (https://github.com/Kleptocratic/Abusing-Roku-APIs) [comments] (https://www.reddit.com/r/Pentesting/comments/pojdsq/how_to_hack_roku_tvs_in_5_minutes/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://github.com/Kleptocratic/Abusing-Roku-APIs) [comments] (https://www.reddit.com/r/Pentesting/comments/pojdsq/how_to_hack_roku_tvs_in_5_minutes/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How does one find their leaked passwords from HaveIBeenpwned?
I'm trying to recover an old blockchain.com account. I cannot for the life of me remember the password I used at the time and because of how the site is set up I cannot verify as they don't store the passwords. I've noticed my email in a few leaks on HaveIbeenpwned and some of the sites listed I'm pretty sure the password would be the same or a variation on it.
So yeah, how does one go about finding these password lists?
submitted by /u/toomanynamesaretook
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How does one find their leaked passwords from HaveIBeenpwned?
I'm trying to recover an old blockchain.com account. I cannot for the life of me remember the password I used at the time and because of how the site is set up I cannot verify as they don't store the passwords. I've noticed my email in a few leaks on HaveIbeenpwned and some of the sites listed I'm pretty sure the password would be the same or a variation on it.
So yeah, how does one go about finding these password lists?
submitted by /u/toomanynamesaretook
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How does one find their leaked passwords from HaveIBeenpwned?
I'm trying to recover an old [blockchain.com](https://blockchain.com) account. I cannot for the life of me remember the password I used at the...
Rootend - A \Nix Enumerator And Auto Privilege Escalation Tool
rootend is a python \nix Enumerator & Auto Privilege Escalation tool. For a full list of our tools, please visit our website https://www.twelvesec.com/ Written by: nickvourd (twitter) maldevel (twitter) servoUsage Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">_ ._ _ \_ _/_ _ _ _ | |_ _ _ / _/ _ _ | | \ \/ \/ // _ \| |\ \/ // _ \ \_ \_/ _ \_/ _\ | | \ /\ _/| |_\ /\ _/ / \ _/\ \_ |_| \/\_/ \_ >_/\_/ \_ >_ /\_ >\_ > \/ \/ \/ \/ \/ rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.rootend is an open source tool licensed under GPLv3.Affected systems: *nix.Written by: @nickvourd of @twelvesec.Special thanks to @maldevel & servo.https://www.twelvesec.com/Please visit https://github.com/twelvesec/rootend for more..optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalatio n process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumerationusage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -bSpecific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. Version 2.0.2 Supports Python 2.x Python 3.x Tested on Python 2.7.18rc1 Python 3.8.2 Modes Manual Auto Exploitation Categories Suid Binaries: General Suids Suids for reading files Suids for creating file as root Limited Suids Custom Suids Weak Permissions: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Weak Ownership: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Capabilities: General Capabilities Custom Capabilities With CAP_SETUID Interesting Files: PHP Configuration Files World Writable Files Download Rootend
Read more...
___________________________
@hacking_Attack
@Hacking_Video
rootend is a python \nix Enumerator & Auto Privilege Escalation tool. For a full list of our tools, please visit our website https://www.twelvesec.com/ Written by: nickvourd (twitter) maldevel (twitter) servoUsage Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">_ ._ _ \_ _/_ _ _ _ | |_ _ _ / _/ _ _ | | \ \/ \/ // _ \| |\ \/ // _ \ \_ \_/ _ \_/ _\ | | \ /\ _/| |_\ /\ _/ / \ _/\ \_ |_| \/\_/ \_ >_/\_/ \_ >_ /\_ >\_ > \/ \/ \/ \/ \/ rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.rootend is an open source tool licensed under GPLv3.Affected systems: *nix.Written by: @nickvourd of @twelvesec.Special thanks to @maldevel & servo.https://www.twelvesec.com/Please visit https://github.com/twelvesec/rootend for more..optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalatio n process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumerationusage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -bSpecific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. Version 2.0.2 Supports Python 2.x Python 3.x Tested on Python 2.7.18rc1 Python 3.8.2 Modes Manual Auto Exploitation Categories Suid Binaries: General Suids Suids for reading files Suids for creating file as root Limited Suids Custom Suids Weak Permissions: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Weak Ownership: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Capabilities: General Capabilities Custom Capabilities With CAP_SETUID Interesting Files: PHP Configuration Files World Writable Files Download Rootend
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!Rootend - A *Nix Enumerator And Auto Privilege Escalation Tool
rootend is a python *nix Enumerator & Auto Privilege Escalation tool.
For a full list of our tools, please visit our website https://www.twelvesec.com/
Written by:
* nickvourd (twitter)
* maldevel (twitter)
* servo
Usage
Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">
Version
2.0.2
Supports
* Python 2.x
* Python 3.x
Tested on
* Python 2.7.18rc1
* Python 3.8.2
Modes
* Manual
* Auto
Exploitation Categories
Suid Binaries:
* General Suids
* Suids for reading files
* Suids for creating file as root
* Limited Suids
* Custom Suids
Weak Permissions:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Weak Ownership:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Capabilities:
* General Capabilities
* Custom Capabilities
* With CAP_SETUID
Interesting Files:
* PHP Configuration Files
* World Writable Files
Download Rootend
___________________________
@hacking_Attack
@Hacking_Video
rootend is a python *nix Enumerator & Auto Privilege Escalation tool.
For a full list of our tools, please visit our website https://www.twelvesec.com/
Written by:
* nickvourd (twitter)
* maldevel (twitter)
* servo
Usage
Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">
___________ .__ _________
\__ ___/_ _ __ ____ | |___ __ ____ / _____/ ____ ____
| | \ \/ \/ // __ \| |\ \/ // __ \ \_____ \_/ __ \_/ ___\
| | \ /\ ___/| |_\ /\ ___/ / \ ___/\ \___
|____| \/\_/ \___ >____/\_/ \___ >_______ /\___ >\___ >
\/ \/ \/ \/ \/
rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.
rootend is an open source tool licensed under GPLv3.
Affected systems: *nix.
Written by: @nickvourd of @twelvesec.
Special thanks to @maldevel & servo.
https://www.twelvesec.com/
Please visit https://github.com/twelvesec/rootend for more..
optional arguments:
-h, --help show this help message and exit
-v, --version show version and exit
-a, --auto automated privilege escalatio n process
-m, --manual system enumeration
-n, --nocolor disable color
-b, --banner show banner and exit
-s, --suid suid binary enumeration
-w, --weak weak permissions of files enumeration
-p, --php PHP configuration files enumeration
-c, --capabilities capabilities enumeration
-f, --full-writables world writable files enumeration
usage examples:
./rootend.py -a
./rootend.py -m
./rootend.py -v
./rootend.py -b
Specific categories usage examples:
./rootend.py -a -s
./rootend.py -m -w
./rootend.py -a -s -p
./rootend.py -m -w -c -p
./rootend.py -a -s -c -p -f
*Use the above arguments with -n to disable color.
Version
2.0.2
Supports
* Python 2.x
* Python 3.x
Tested on
* Python 2.7.18rc1
* Python 3.8.2
Modes
* Manual
* Auto
Exploitation Categories
Suid Binaries:
* General Suids
* Suids for reading files
* Suids for creating file as root
* Limited Suids
* Custom Suids
Weak Permissions:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Weak Ownership:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Capabilities:
* General Capabilities
* Custom Capabilities
* With CAP_SETUID
Interesting Files:
* PHP Configuration Files
* World Writable Files
Download Rootend
___________________________
@hacking_Attack
@Hacking_Video