Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How does one find their leaked passwords from HaveIBeenpwned?
I'm trying to recover an old blockchain.com account. I cannot for the life of me remember the password I used at the time and because of how the site is set up I cannot verify as they don't store the passwords. I've noticed my email in a few leaks on HaveIbeenpwned and some of the sites listed I'm pretty sure the password would be the same or a variation on it.
So yeah, how does one go about finding these password lists?
submitted by /u/toomanynamesaretook
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How does one find their leaked passwords from HaveIBeenpwned?
I'm trying to recover an old blockchain.com account. I cannot for the life of me remember the password I used at the time and because of how the site is set up I cannot verify as they don't store the passwords. I've noticed my email in a few leaks on HaveIbeenpwned and some of the sites listed I'm pretty sure the password would be the same or a variation on it.
So yeah, how does one go about finding these password lists?
submitted by /u/toomanynamesaretook
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How does one find their leaked passwords from HaveIBeenpwned?
I'm trying to recover an old [blockchain.com](https://blockchain.com) account. I cannot for the life of me remember the password I used at the...
Rootend - A \Nix Enumerator And Auto Privilege Escalation Tool
rootend is a python \nix Enumerator & Auto Privilege Escalation tool. For a full list of our tools, please visit our website https://www.twelvesec.com/ Written by: nickvourd (twitter) maldevel (twitter) servoUsage Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">_ ._ _ \_ _/_ _ _ _ | |_ _ _ / _/ _ _ | | \ \/ \/ // _ \| |\ \/ // _ \ \_ \_/ _ \_/ _\ | | \ /\ _/| |_\ /\ _/ / \ _/\ \_ |_| \/\_/ \_ >_/\_/ \_ >_ /\_ >\_ > \/ \/ \/ \/ \/ rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.rootend is an open source tool licensed under GPLv3.Affected systems: *nix.Written by: @nickvourd of @twelvesec.Special thanks to @maldevel & servo.https://www.twelvesec.com/Please visit https://github.com/twelvesec/rootend for more..optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalatio n process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumerationusage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -bSpecific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. Version 2.0.2 Supports Python 2.x Python 3.x Tested on Python 2.7.18rc1 Python 3.8.2 Modes Manual Auto Exploitation Categories Suid Binaries: General Suids Suids for reading files Suids for creating file as root Limited Suids Custom Suids Weak Permissions: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Weak Ownership: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Capabilities: General Capabilities Custom Capabilities With CAP_SETUID Interesting Files: PHP Configuration Files World Writable Files Download Rootend
Read more...
___________________________
@hacking_Attack
@Hacking_Video
rootend is a python \nix Enumerator & Auto Privilege Escalation tool. For a full list of our tools, please visit our website https://www.twelvesec.com/ Written by: nickvourd (twitter) maldevel (twitter) servoUsage Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">_ ._ _ \_ _/_ _ _ _ | |_ _ _ / _/ _ _ | | \ \/ \/ // _ \| |\ \/ // _ \ \_ \_/ _ \_/ _\ | | \ /\ _/| |_\ /\ _/ / \ _/\ \_ |_| \/\_/ \_ >_/\_/ \_ >_ /\_ >\_ > \/ \/ \/ \/ \/ rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.rootend is an open source tool licensed under GPLv3.Affected systems: *nix.Written by: @nickvourd of @twelvesec.Special thanks to @maldevel & servo.https://www.twelvesec.com/Please visit https://github.com/twelvesec/rootend for more..optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalatio n process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumerationusage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -bSpecific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. Version 2.0.2 Supports Python 2.x Python 3.x Tested on Python 2.7.18rc1 Python 3.8.2 Modes Manual Auto Exploitation Categories Suid Binaries: General Suids Suids for reading files Suids for creating file as root Limited Suids Custom Suids Weak Permissions: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Weak Ownership: /etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root Capabilities: General Capabilities Custom Capabilities With CAP_SETUID Interesting Files: PHP Configuration Files World Writable Files Download Rootend
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!Rootend - A *Nix Enumerator And Auto Privilege Escalation Tool
rootend is a python *nix Enumerator & Auto Privilege Escalation tool.
For a full list of our tools, please visit our website https://www.twelvesec.com/
Written by:
* nickvourd (twitter)
* maldevel (twitter)
* servo
Usage
Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">
Version
2.0.2
Supports
* Python 2.x
* Python 3.x
Tested on
* Python 2.7.18rc1
* Python 3.8.2
Modes
* Manual
* Auto
Exploitation Categories
Suid Binaries:
* General Suids
* Suids for reading files
* Suids for creating file as root
* Limited Suids
* Custom Suids
Weak Permissions:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Weak Ownership:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Capabilities:
* General Capabilities
* Custom Capabilities
* With CAP_SETUID
Interesting Files:
* PHP Configuration Files
* World Writable Files
Download Rootend
___________________________
@hacking_Attack
@Hacking_Video
rootend is a python *nix Enumerator & Auto Privilege Escalation tool.
For a full list of our tools, please visit our website https://www.twelvesec.com/
Written by:
* nickvourd (twitter)
* maldevel (twitter)
* servo
Usage
Enumeration & Automation Privilege Escalation tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">
___________ .__ _________
\__ ___/_ _ __ ____ | |___ __ ____ / _____/ ____ ____
| | \ \/ \/ // __ \| |\ \/ // __ \ \_____ \_/ __ \_/ ___\
| | \ /\ ___/| |_\ /\ ___/ / \ ___/\ \___
|____| \/\_/ \___ >____/\_/ \___ >_______ /\___ >\___ >
\/ \/ \/ \/ \/
rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.
rootend is an open source tool licensed under GPLv3.
Affected systems: *nix.
Written by: @nickvourd of @twelvesec.
Special thanks to @maldevel & servo.
https://www.twelvesec.com/
Please visit https://github.com/twelvesec/rootend for more..
optional arguments:
-h, --help show this help message and exit
-v, --version show version and exit
-a, --auto automated privilege escalatio n process
-m, --manual system enumeration
-n, --nocolor disable color
-b, --banner show banner and exit
-s, --suid suid binary enumeration
-w, --weak weak permissions of files enumeration
-p, --php PHP configuration files enumeration
-c, --capabilities capabilities enumeration
-f, --full-writables world writable files enumeration
usage examples:
./rootend.py -a
./rootend.py -m
./rootend.py -v
./rootend.py -b
Specific categories usage examples:
./rootend.py -a -s
./rootend.py -m -w
./rootend.py -a -s -p
./rootend.py -m -w -c -p
./rootend.py -a -s -c -p -f
*Use the above arguments with -n to disable color.
Version
2.0.2
Supports
* Python 2.x
* Python 3.x
Tested on
* Python 2.7.18rc1
* Python 3.8.2
Modes
* Manual
* Auto
Exploitation Categories
Suid Binaries:
* General Suids
* Suids for reading files
* Suids for creating file as root
* Limited Suids
* Custom Suids
Weak Permissions:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Weak Ownership:
* /etc/passwd
* /etc/shadow
* apache2.conf
* httpd.conf
* redis.conf
* /root
Capabilities:
* General Capabilities
* Custom Capabilities
* With CAP_SETUID
Interesting Files:
* PHP Configuration Files
* World Writable Files
Download Rootend
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux TutorialsKali Linux 2021.3 Released for NetHunter Smartwatch and With New Hacking Tools
The most popular penetration testing distro Kali linux announced a new version that included extended support for OpenSSL, new Tools, Live VM Support, and support for smartwatch.
The Kali Linux 2021.3 is the third release of the year, now it is available for ready download or users can update to the latest version.
What’s New With Kali Linux 2021.3
OpenSSL by Default
Starting from Kali Linux 2021.3, support for legacy protocols and ciphers are enabled by default. This would help researchers to test older machines that still using older protocols.
Complete OpenSSL Configurations can be found here.
New Kali-Tools
The tools pages have been refreshed with a new design that helps users to pick the tools and contribute.”We have refreshed every aspect of the previous site, giving a new, faster, layout, content, and system!”
Following are the new tools introduced;
* Berate_ap – Orchestrating MANA rogue Wi-Fi Access Points
* CALDERA – Scalable automated adversary emulation platform
* EAPHammer – Targeted evil twin attacks against WPA2-Enterprise Wi-Fi networks
* HostHunter – Recon tool for discovering hostnames using OSINT techniques
* RouterKeygenPC – Generate default WPA/WEP Wi-Fi keys
* Subjack – Subdomain takeover
* WPA_Sycophant – Evil client portion of EAP relay attack
Virtualization and Desktop
Hyper-V Enhanced Session Mode made simple with the new release, it can be enabled by just hitting an enter.
Following are improvements with Desktop
* Improved GTK3 theme for Xfce’s notifications and logout-dialog
* Redesigned GTK2 theme for a better fit of older programs
* Improved Kali-Dark and Kali-Light syntax-highlighting themes for GNOME and Xfce
Kali NetHunter
For the first time, Kali linux was introduced for a smartwatch, the TicHunter Pro, it is still in the experimental phase, there be many limitations now, hope in the future it will be promising.
You can find the documentation of how to install it here.
Kali Linux 2021.3 is available to download from here, you can also update using the following commands.
┌──(kali㉿kali)-[~]
└─$ echo "deb http://http.kali.org/kali kali-rolling main non-free contrib" | sudo tee /etc/apt/sources.list
┌──(kali㉿kali)-[~]
└─$ sudo apt update && sudo apt -y full-upgrade
┌──(kali㉿kali)-[~]
└─$ [ -f /var/run/reboot-required ] && sudo reboot -f
To check the update
┌──(kali㉿kali)-[~]
└─$ grep VERSION /etc/os-release VERSION="2021.3" VERSION_ID="2021.3" VERSION_CODENAME="kali-rolling"
Offensive security team is having plans to refresh the kali menus by making some alteration in structre and to change load balancers that handles OS images.
___________________________
@hacking_Attack
@Hacking_Video
The most popular penetration testing distro Kali linux announced a new version that included extended support for OpenSSL, new Tools, Live VM Support, and support for smartwatch.
The Kali Linux 2021.3 is the third release of the year, now it is available for ready download or users can update to the latest version.
What’s New With Kali Linux 2021.3
OpenSSL by Default
Starting from Kali Linux 2021.3, support for legacy protocols and ciphers are enabled by default. This would help researchers to test older machines that still using older protocols.
Complete OpenSSL Configurations can be found here.
New Kali-Tools
The tools pages have been refreshed with a new design that helps users to pick the tools and contribute.”We have refreshed every aspect of the previous site, giving a new, faster, layout, content, and system!”
Following are the new tools introduced;
* Berate_ap – Orchestrating MANA rogue Wi-Fi Access Points
* CALDERA – Scalable automated adversary emulation platform
* EAPHammer – Targeted evil twin attacks against WPA2-Enterprise Wi-Fi networks
* HostHunter – Recon tool for discovering hostnames using OSINT techniques
* RouterKeygenPC – Generate default WPA/WEP Wi-Fi keys
* Subjack – Subdomain takeover
* WPA_Sycophant – Evil client portion of EAP relay attack
Virtualization and Desktop
Hyper-V Enhanced Session Mode made simple with the new release, it can be enabled by just hitting an enter.
Following are improvements with Desktop
* Improved GTK3 theme for Xfce’s notifications and logout-dialog
* Redesigned GTK2 theme for a better fit of older programs
* Improved Kali-Dark and Kali-Light syntax-highlighting themes for GNOME and Xfce
Kali NetHunter
For the first time, Kali linux was introduced for a smartwatch, the TicHunter Pro, it is still in the experimental phase, there be many limitations now, hope in the future it will be promising.
You can find the documentation of how to install it here.
Kali Linux 2021.3 is available to download from here, you can also update using the following commands.
┌──(kali㉿kali)-[~]
└─$ echo "deb http://http.kali.org/kali kali-rolling main non-free contrib" | sudo tee /etc/apt/sources.list
┌──(kali㉿kali)-[~]
└─$ sudo apt update && sudo apt -y full-upgrade
┌──(kali㉿kali)-[~]
└─$ [ -f /var/run/reboot-required ] && sudo reboot -f
To check the update
┌──(kali㉿kali)-[~]
└─$ grep VERSION /etc/os-release VERSION="2021.3" VERSION_ID="2021.3" VERSION_CODENAME="kali-rolling"
Offensive security team is having plans to refresh the kali menus by making some alteration in structre and to change load balancers that handles OS images.
___________________________
@hacking_Attack
@Hacking_Video
Rootend - A *Nix Enumerator And Auto Privilege Escalation Tool
http://www.kitploit.com/2021/09/rootend-nix-enumerator-and-auto.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/rootend-nix-enumerator-and-auto.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Rootend - A *Nix Enumerator And Auto Privilege Escalation Tool
rootend is a python *nix Enumerator & Auto Privilege Escalation (https://www.kitploit.com/search/label/Privilege%20Escalation) tool. For a full list of our tools, please visit our website https://www.twelvesec.com/ Written by: nickvourd (https://github.com/nickvourd) (twitter (https://twitter.com/nickvourd)) maldevel (https://github.com/maldevel) (twitter (https://twitter.com/maldevel)) servo (https://github.com/gbkaragiannidis)
Usage
____/\_/ \___ >_______ /\___ >\___ > \/ \/ \/ \/ \/ rootend v.2.0.2 - Enumeration & Automation (https://www.kitploit.com/search/label/Automation) Privilege Escalation (https://www.kitploit.com/search/label/Escalation) tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration (https://www.kitploit.com/search/label/PHP%20configuration) files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">___________ .__ _________
\__ ___/_ _ __ ____ | |___ __ ____ / _____/ ____ ____
| | \ \/ \/ // __ \| |\ \/ // __ \ \_____ \_/ __ \_/ ___\
| | \ /\ ___/| |_\ /\ ___/ / \ ___/\ \___
|____| \/\_/ \___ >____/\_/ \___ >_______ /\___ >\___ >
\/ \/ \/ \/ \/
rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.
rootend is an open source tool licensed under GPLv3.
Affected systems: *nix.
Written by: @nickvourd of @twelvesec.
Special thanks to @maldevel & servo.
https://www.twelvesec.com/
Please visit https://github.com/twelvesec/rootend for more..
optional arguments:
-h, --help show this help message and exit
-v, --version show version and exit
-a, --auto automated privilege escalatio n process
-m, --manual system enumeration
-n, --nocolor disable color
-b, --banner show banner and exit
-s, --suid suid binary enumeration
-w, --weak weak permissions of files enumeration
-p, --php PHP configuration files enumeration
-c, --capabilities capabilities enumeration
-f, --full-writables world writable files enumeration
usage examples:
./rootend.py -a
./rootend.py -m
./rootend.py -v
./rootend.py -b
Specific categories usage examples:
./rootend.py -a -s
./rootend.py -m -w
./rootend.py -a -s -p
./rootend.py -m -w -c -p
./rootend.py -a -s -c -p -f
*Use the above arguments with -n to disable color.
Version
2.0.2
Supports
Python 2.x Python 3.x
Tested on
Python 2.7.18rc1 Python 3.8.2
Modes
Manual Auto
Exploitation Categories
Suid Binaries:
General Suids Suids for reading files Suids for creating file as root Limited Suids Custom Suids
Weak Permissions:
/etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root
Weak Ownership:
___________________________
@hacking_Attack
@Hacking_Video
Usage
____/\_/ \___ >_______ /\___ >\___ > \/ \/ \/ \/ \/ rootend v.2.0.2 - Enumeration & Automation (https://www.kitploit.com/search/label/Automation) Privilege Escalation (https://www.kitploit.com/search/label/Escalation) tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration (https://www.kitploit.com/search/label/PHP%20configuration) files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">___________ .__ _________
\__ ___/_ _ __ ____ | |___ __ ____ / _____/ ____ ____
| | \ \/ \/ // __ \| |\ \/ // __ \ \_____ \_/ __ \_/ ___\
| | \ /\ ___/| |_\ /\ ___/ / \ ___/\ \___
|____| \/\_/ \___ >____/\_/ \___ >_______ /\___ >\___ >
\/ \/ \/ \/ \/
rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.
rootend is an open source tool licensed under GPLv3.
Affected systems: *nix.
Written by: @nickvourd of @twelvesec.
Special thanks to @maldevel & servo.
https://www.twelvesec.com/
Please visit https://github.com/twelvesec/rootend for more..
optional arguments:
-h, --help show this help message and exit
-v, --version show version and exit
-a, --auto automated privilege escalatio n process
-m, --manual system enumeration
-n, --nocolor disable color
-b, --banner show banner and exit
-s, --suid suid binary enumeration
-w, --weak weak permissions of files enumeration
-p, --php PHP configuration files enumeration
-c, --capabilities capabilities enumeration
-f, --full-writables world writable files enumeration
usage examples:
./rootend.py -a
./rootend.py -m
./rootend.py -v
./rootend.py -b
Specific categories usage examples:
./rootend.py -a -s
./rootend.py -m -w
./rootend.py -a -s -p
./rootend.py -m -w -c -p
./rootend.py -a -s -c -p -f
*Use the above arguments with -n to disable color.
Version
2.0.2
Supports
Python 2.x Python 3.x
Tested on
Python 2.7.18rc1 Python 3.8.2
Modes
Manual Auto
Exploitation Categories
Suid Binaries:
General Suids Suids for reading files Suids for creating file as root Limited Suids Custom Suids
Weak Permissions:
/etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root
Weak Ownership:
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
/etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root
Capabilities:
General Capabilities Custom Capabilities With CAP_SETUID
Interesting Files:
PHP Configuration Files World Writable Files
Download Rootend (https://github.com/twelvesec/rootend)
___________________________
@hacking_Attack
@Hacking_Video
Capabilities:
General Capabilities Custom Capabilities With CAP_SETUID
Interesting Files:
PHP Configuration Files World Writable Files
Download Rootend (https://github.com/twelvesec/rootend)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - twelvesec/rootend: A *nix Enumerator & Auto Privilege Escalation tool.
A *nix Enumerator & Auto Privilege Escalation tool. - twelvesec/rootend
How to Get a Bigger Bounty by Optimizing Attack Parameters
This guide was written by whitehat Alexander Schlindwein, known for discovering the critical vulnerability in Fei Protocol discussed in…Continue reading on Immunefi »
Read more...
This guide was written by whitehat Alexander Schlindwein, known for discovering the critical vulnerability in Fei Protocol discussed in…Continue reading on Immunefi »
Read more...
How to Get a Bigger Bounty by Optimizing Attack Parameters
https://medium.com/immunefi/how-to-get-a-bigger-bounty-by-optimizing-attack-parameters-a51b144f5cc2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/how-to-get-a-bigger-bounty-by-optimizing-attack-parameters-a51b144f5cc2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Get a Bigger Bounty by Optimizing Attack Parameters
This guide was written by whitehat Alexander Schlindwein, known for discovering the critical vulnerability in Fei Protocol discussed in…