Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!On-The-Fly - Tool Which Gives Capabilities To Perform Pentesting Tests In Several Domains (IoT, ICS & IT)
Different technologies and paradigms are hyperconnected and offer advances to society. The usage of other technologies among these devices makes security uneven. When facing a pentest in any environment, one major factor is the network. The network interconnects the world of the Internet of Things, the world of industrial control systems, and information technology. This README introduces the 'on-the-fly' tool, which gives capabilities to perform pentesting tests in several domains (IoT, ICS & IT). It is an innovative tool by bringing together different worlds sharing a common factor: the network.
Prerequisities
'on-the-fly' was written in Python and made extensive use of Scapy and netfilterqueue. It is crucial to have Scapy in Python and netfilterqueue installed with a compatible version of Python. For this, a version of Python 3 up to Python version 3.7.5 is recommended (and no higher, as there may be incompatibilities with 3.8 and 3.9 in some libraries that it uses 'on-the-fly'). There is a requirements.txt file that must be executed the first time the tool is launched using 'pip install -r requirements.txt'. Again the pip version must be oriented to a Python 3 version up to 3.7.5.
Usage
Example videos
on-the-fly: MySQL_manipulation Module
on-the-fly: SSDP_fake Module
on-the-fly: Proxy_socks4 Module
on-the-fly: Port_forwarding Module
on-the-fly: MDNS_Scan Module
Contact
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. WHENEVER YOU MAKE A CONTRIBUTION TO A REPOSITORY CONTAINING NOTICE OF A LICENSE, YOU LICENSE YOUR CONTRIBUTION UNDER THE SAME TERMS, AND YOU AGREE THAT YOU HAVE THE RIGHT TO LICENSE YOUR CONTRIBUTION UNDER THOSE TERMS. IF YOU HAVE A SEPARATE AGREEMENT TO LICENSE YOUR CONTRIBUTIONS UNDER DIFFERENT TERMS, SUCH AS A CONTRIBUTOR LICENSE AGREEMENT, THAT AGREEMENT WILL SUPERSEDE.
This software doesn't have a QA Process. This software is a Proof of Concept.
If you have any problems, you can contact:
ideaslocas@telefonica.com
Download On-The-Fly
___________________________
@hacking_Attack
@Hacking_Video
▒█████ ███▄ █ ▄▄▄█████▓ ██░ ██ ▓█████ █████ ██▓ ▓██ ██▓
▒██▒ ██▒ ██ ▀█ █ ▓ ██▒ ▓▒▒▓██░ ██ ▓█ ▀ ▓██ ▓██▒ ▒██ ██▒
▒██░ ██▒▓██ ▀█ ██▒ ▒ ▓██░ ▒░░▒██▀▀██ ▒███ ▒████ ▒██░ ▒██ ██░
▒██ ██░▓██▒ ▐▌██▒ ░ ▓██▓ ░ ░▓█ ░██ ▒▓█ ▄ ░▓█▒ ▒██░ ░ ▐██▓░
░ ████▓▒░▒██░ ▓██░ ▒██▒ ░ ░▓█▒░██▓▒░▒████ ▒░▒█░ ▒░██████ ░ ██▒▓░
░ ▒░▒░▒░ ░ ▒░ ▒ ▒ ▒ ░░ ▒ ░░▒░▒░░░ ▒░ ░ ▒ ░ ░░ ▒░▓ ██▒▒▒
░ ▒ ▒░ ░ ░░ ░ ▒░ ░ ▒ ░▒░ ░░ ░ ░ ░ ░ ░░ ░ ▒ ▓██ ░▒░
░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░░ ░ ░ ░ ░ ░ ░ ▒ ▒ ░░
░ ░ ░ ░ ░ ░░ ░ ░ ░ ░ ░ ░
Different technologies and paradigms are hyperconnected and offer advances to society. The usage of other technologies among these devices makes security uneven. When facing a pentest in any environment, one major factor is the network. The network interconnects the world of the Internet of Things, the world of industrial control systems, and information technology. This README introduces the 'on-the-fly' tool, which gives capabilities to perform pentesting tests in several domains (IoT, ICS & IT). It is an innovative tool by bringing together different worlds sharing a common factor: the network.
Prerequisities
'on-the-fly' was written in Python and made extensive use of Scapy and netfilterqueue. It is crucial to have Scapy in Python and netfilterqueue installed with a compatible version of Python. For this, a version of Python 3 up to Python version 3.7.5 is recommended (and no higher, as there may be incompatibilities with 3.8 and 3.9 in some libraries that it uses 'on-the-fly'). There is a requirements.txt file that must be executed the first time the tool is launched using 'pip install -r requirements.txt'. Again the pip version must be oriented to a Python 3 version up to 3.7.5.
pip install -r requirements.txt
Usage
python on-the-fly.py
Example videos
on-the-fly: MySQL_manipulation Module
on-the-fly: SSDP_fake Module
on-the-fly: Proxy_socks4 Module
on-the-fly: Port_forwarding Module
on-the-fly: MDNS_Scan Module
Contact
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. WHENEVER YOU MAKE A CONTRIBUTION TO A REPOSITORY CONTAINING NOTICE OF A LICENSE, YOU LICENSE YOUR CONTRIBUTION UNDER THE SAME TERMS, AND YOU AGREE THAT YOU HAVE THE RIGHT TO LICENSE YOUR CONTRIBUTION UNDER THOSE TERMS. IF YOU HAVE A SEPARATE AGREEMENT TO LICENSE YOUR CONTRIBUTIONS UNDER DIFFERENT TERMS, SUCH AS A CONTRIBUTOR LICENSE AGREEMENT, THAT AGREEMENT WILL SUPERSEDE.
This software doesn't have a QA Process. This software is a Proof of Concept.
If you have any problems, you can contact:
ideaslocas@telefonica.com
Download On-The-Fly
___________________________
@hacking_Attack
@Hacking_Video
Ntlm_Theft - A Tool For Generating Multiple Types Of NTLMv2 Hash Theft Files
http://www.kitploit.com/2021/09/ntlmtheft-tool-for-generating-multiple.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/ntlmtheft-tool-for-generating-multiple.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Ntlm_Theft - A Tool For Generating Multiple Types Of NTLMv2 Hash Theft Files
A tool for generating multiple types of NTLMv2 hash theft files. ntlm_theft is an Open Source Python3 Tool that generates 21 different types of hash theft documents. These can be used for phishing when either the target allows smb traffic outside their network, or if you are already inside the internal network. The benefits of these file types over say macro based documents or exploit documents are that all of these are built using "intended functionality". None were flagged by Windows Defender (https://www.kitploit.com/search/label/Windows%20Defender) Antivirus on June 2020, and 17 of the 21 attacks worked on a fully patched Windows 10 host.
ntlm_theft supports the following attack types: Browse to Folder Containing .url – via URL field .url – via ICONFILE field .lnk - via icon_location field .scf – via ICONFILE field (Not Working on Latest Windows) autorun.inf via OPEN field (Not Working on Latest Windows) desktop.ini - via IconResource field (Not Working on Latest Windows) Open Document .xml – via Microsoft Word external stylesheet .xml – via Microsoft Word includepicture field .htm – via Chrome & IE & Edge img src (only if opened locally, not hosted) .docx – via Microsoft Word includepicture field .docx – via Microsoft Word external template .docx – via Microsoft Word frameset webSettings .xlsx - via Microsoft Excel external cell .wax - via Windows Media Player playlist (Better, primary open) .asx – via Windows Media Player playlist (Better, primary open) .m3u – via Windows Media Player playlist (Worse, Win10 opens first in Groovy) .jnlp – via Java external jar .application – via any Browser (Must be served via a browser downloaded or won’t run) Open Document and Accept Popup .pdf – via Adobe Acrobat Reader Click Link in Chat Program .txt – formatted link to paste into Zoom chat
Usecases (Why you want to run this)
ntlm_theft is primarily aimed at Penetration Testers and Red Teamers, who will use it to perform internal phishing on target company employees, or to mass test antivirus and email gateways. It may also be used for external phishing if outbound SMB access is allowed on the perimeter firewall. I've found it useful while penetration testing (https://www.kitploit.com/search/label/Penetration%20Testing) to easily see what file types I have available to me, rather than spending time configuring a specific attack as would be used on red teaming (https://www.kitploit.com/search/label/Red%20Teaming) engagements. You could send a .rtf or .docx file to the HR department, and a .xlsx spreadsheet doc to the finance department.
Getting Started
These instructions will show you the requirements (https://www.kitploit.com/search/label/Requirements) for and how to use ntlm_theft.
Prerequisites
ntlm_theft requires Python3 and xlsxwriter: pip3 install xlsxwriter
Required Parameters
To start up the tool 4 parameters must be provided, an input format, the input file or folder and the basic running mode: -g, --generate : Choose to generate all files or a specific filetype
-s, --server : The IP address of your SMB hash capture server (Responder, impacket ntlmrelayx, Metasploit auxiliary/server/capture/smb, etc)
-f, --filename : The base filename without extension, can be renamed later (eg: test, Board-Meeting2020, Bonus_Payment_Q4)
Example Runs
Here is an example of what a run looks like generating all files: # python3 ntlm_theft.py -g all -s 127.0.0.1 -f test
Created: test/test.scf (BROWSE)
Created: test/test-(url).url (BROWSE)
Created: test/test-(icon).url (BROWSE)
Created: test/test.rtf (OPEN)
Created: test/test-(stylesheet).xml (OPEN)
Created: test/test-(fulldocx).xml (OPEN)
Created: test/test.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
Created: test/test-(includepicture).docx (OPEN)
Created: test/test-(remotetemplate).docx (OPEN)
Created: test/test-(frameset).docx (OPEN)
Created: test/test.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
___________________________
@hacking_Attack
@Hacking_Video
ntlm_theft supports the following attack types: Browse to Folder Containing .url – via URL field .url – via ICONFILE field .lnk - via icon_location field .scf – via ICONFILE field (Not Working on Latest Windows) autorun.inf via OPEN field (Not Working on Latest Windows) desktop.ini - via IconResource field (Not Working on Latest Windows) Open Document .xml – via Microsoft Word external stylesheet .xml – via Microsoft Word includepicture field .htm – via Chrome & IE & Edge img src (only if opened locally, not hosted) .docx – via Microsoft Word includepicture field .docx – via Microsoft Word external template .docx – via Microsoft Word frameset webSettings .xlsx - via Microsoft Excel external cell .wax - via Windows Media Player playlist (Better, primary open) .asx – via Windows Media Player playlist (Better, primary open) .m3u – via Windows Media Player playlist (Worse, Win10 opens first in Groovy) .jnlp – via Java external jar .application – via any Browser (Must be served via a browser downloaded or won’t run) Open Document and Accept Popup .pdf – via Adobe Acrobat Reader Click Link in Chat Program .txt – formatted link to paste into Zoom chat
Usecases (Why you want to run this)
ntlm_theft is primarily aimed at Penetration Testers and Red Teamers, who will use it to perform internal phishing on target company employees, or to mass test antivirus and email gateways. It may also be used for external phishing if outbound SMB access is allowed on the perimeter firewall. I've found it useful while penetration testing (https://www.kitploit.com/search/label/Penetration%20Testing) to easily see what file types I have available to me, rather than spending time configuring a specific attack as would be used on red teaming (https://www.kitploit.com/search/label/Red%20Teaming) engagements. You could send a .rtf or .docx file to the HR department, and a .xlsx spreadsheet doc to the finance department.
Getting Started
These instructions will show you the requirements (https://www.kitploit.com/search/label/Requirements) for and how to use ntlm_theft.
Prerequisites
ntlm_theft requires Python3 and xlsxwriter: pip3 install xlsxwriter
Required Parameters
To start up the tool 4 parameters must be provided, an input format, the input file or folder and the basic running mode: -g, --generate : Choose to generate all files or a specific filetype
-s, --server : The IP address of your SMB hash capture server (Responder, impacket ntlmrelayx, Metasploit auxiliary/server/capture/smb, etc)
-f, --filename : The base filename without extension, can be renamed later (eg: test, Board-Meeting2020, Bonus_Payment_Q4)
Example Runs
Here is an example of what a run looks like generating all files: # python3 ntlm_theft.py -g all -s 127.0.0.1 -f test
Created: test/test.scf (BROWSE)
Created: test/test-(url).url (BROWSE)
Created: test/test-(icon).url (BROWSE)
Created: test/test.rtf (OPEN)
Created: test/test-(stylesheet).xml (OPEN)
Created: test/test-(fulldocx).xml (OPEN)
Created: test/test.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
Created: test/test-(includepicture).docx (OPEN)
Created: test/test-(remotetemplate).docx (OPEN)
Created: test/test-(frameset).docx (OPEN)
Created: test/test.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Created: test/test.asx (OPEN)
Created: test/test.jnlp (OPEN)
Created: test/test.application (DOWNLOAD AND OPEN)
Created: test/test.pdf (OPEN AND ALLOW)
Created: test/zoom-attack-instructions.txt (PASTE TO CHAT)
Generation Complete.
___________________________
@hacking_Attack
@Hacking_Video
Created: test/test.jnlp (OPEN)
Created: test/test.application (DOWNLOAD AND OPEN)
Created: test/test.pdf (OPEN AND ALLOW)
Created: test/zoom-attack-instructions.txt (PASTE TO CHAT)
Generation Complete.
___________________________
@hacking_Attack
@Hacking_Video
Here is an example of what a run looks like generating only modern files: # python3 ntlm_theft.py -g modern -s 127.0.0.1 -f meeting
Skipping SCF as it does not work on modern Windows
Created: meeting/meeting-(url).url (BROWSE TO FOLDER)
Created: meeting/meeting-(icon).url (BROWSE TO FOLDER)
Created: meeting/meeting.rtf (OPEN)
Created: meeting/meeting-(stylesheet).xml (OPEN)
Created: meeting/meeting-(fulldocx).xml (OPEN)
Created: meeting/meeting.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
Created: meeting/meeting-(includepicture).docx (OPEN)
Created: meeting/meeting-(remotetemplate).docx (OPEN)
Created: meeting/meeting-(frameset).docx (OPEN)
Created: meeting/meeting-(externalcell).xlsx (OPEN)
Created: meeting/meeting.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
Created: meeting/meeting.asx (OPEN)
Created: meeting/meeting.jnlp (OPEN)
Created: meeting/meeting.application (DOWNLOAD AND OPEN)
Created: meeting/meeting.pdf (OPEN AND ALLOW)
Skipping zoom as it does not work on the late st versions
Skipping Autorun.inf as it does not work on modern Windows
Skipping desktop.ini as it does not work on modern Windows
Generation Complete.
Here is an example of what a run looks like generating only a xlsx file: # python3 ntlm_theft.py -g xlsx -s 192.168.1.103 -f Bonus_Payment_Q4
Created: Bonus_Payment_Q4/Bonus_Payment_Q4-(externalcell).xlsx (OPEN)
Generation Complete.
Authors
Jacob Wilkin - Research and Development
License
ntlm_theft Created by Jacob Wilkin Copyright (C) 2020 Jacob Wilkin This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed (https://www.kitploit.com/search/label/Distributed) in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
Acknowledgments
Ired (https://ired.team/offensive-security/initial-access/t1187-forced-authentication) Securify (https://www.securify.nl/blog/SFY20180501/living-off-the-land_-stealing-netntlm-hashes.html) Pentestlab (https://pentestlab.blog/2017/12/18/microsoft-office-ntlm-hashes-via-frameset/) deepzec (https://github.com/deepzec/Bad-Pdf/blob/master/badpdf.py) rocketscientist911 (https://github.com/rocketscientist911/excel-ntlmv2) Osanda (https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/) Violation Industry (https://www.youtube.com/watch?v=PDpBEY1roRc) @kazkansouh (https://github.com/kazkansouh) - Adding .lnk support
Download Ntlm_Theft (https://github.com/Greenwolf/ntlm_theft)
___________________________
@hacking_Attack
@Hacking_Video
Skipping SCF as it does not work on modern Windows
Created: meeting/meeting-(url).url (BROWSE TO FOLDER)
Created: meeting/meeting-(icon).url (BROWSE TO FOLDER)
Created: meeting/meeting.rtf (OPEN)
Created: meeting/meeting-(stylesheet).xml (OPEN)
Created: meeting/meeting-(fulldocx).xml (OPEN)
Created: meeting/meeting.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
Created: meeting/meeting-(includepicture).docx (OPEN)
Created: meeting/meeting-(remotetemplate).docx (OPEN)
Created: meeting/meeting-(frameset).docx (OPEN)
Created: meeting/meeting-(externalcell).xlsx (OPEN)
Created: meeting/meeting.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
Created: meeting/meeting.asx (OPEN)
Created: meeting/meeting.jnlp (OPEN)
Created: meeting/meeting.application (DOWNLOAD AND OPEN)
Created: meeting/meeting.pdf (OPEN AND ALLOW)
Skipping zoom as it does not work on the late st versions
Skipping Autorun.inf as it does not work on modern Windows
Skipping desktop.ini as it does not work on modern Windows
Generation Complete.
Here is an example of what a run looks like generating only a xlsx file: # python3 ntlm_theft.py -g xlsx -s 192.168.1.103 -f Bonus_Payment_Q4
Created: Bonus_Payment_Q4/Bonus_Payment_Q4-(externalcell).xlsx (OPEN)
Generation Complete.
Authors
Jacob Wilkin - Research and Development
License
ntlm_theft Created by Jacob Wilkin Copyright (C) 2020 Jacob Wilkin This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed (https://www.kitploit.com/search/label/Distributed) in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
Acknowledgments
Ired (https://ired.team/offensive-security/initial-access/t1187-forced-authentication) Securify (https://www.securify.nl/blog/SFY20180501/living-off-the-land_-stealing-netntlm-hashes.html) Pentestlab (https://pentestlab.blog/2017/12/18/microsoft-office-ntlm-hashes-via-frameset/) deepzec (https://github.com/deepzec/Bad-Pdf/blob/master/badpdf.py) rocketscientist911 (https://github.com/rocketscientist911/excel-ntlmv2) Osanda (https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/) Violation Industry (https://www.youtube.com/watch?v=PDpBEY1roRc) @kazkansouh (https://github.com/kazkansouh) - Adding .lnk support
Download Ntlm_Theft (https://github.com/Greenwolf/ntlm_theft)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Ntlm_Theft - A Tool For Generating Multiple Types Of NTLMv2 Hash Theft Files
http://2.bp.blogspot.com/-Lc-pMQxsfVg/YTVKVhCUJqI/AAAAAAAAt1I/Hsik9IJaHQENyEWH7b1bKIx-2vjj3ttNwCK4BGAYYCw/w640-h336/ntlm_theft_1_example-run-781145.png
A tool for generating multiple types of NTLMv2 hash theft files.
ntlm_theft is an Open Source Python3 Tool that generates 21 different types of hash theft documents. These can be used for phishing when either the target allows smb traffic outside their network, or if you are already inside the internal network.
The benefits of these file types over say macro based documents or exploit documents are that all of these are built using "intended functionality". None were flagged by Windows Defender Antivirus on June 2020, and 17 of the 21 attacks worked on a fully patched Windows 10 host.
ntlm_theft supports the following attack types:
* Browse to Folder Containing
* .url – via URL field
* .url – via ICONFILE field
* .lnk - via icon_location field
* .scf – via ICONFILE field (Not Working on Latest Windows)
* autorun.inf via OPEN field (Not Working on Latest Windows)
* desktop.ini - via IconResource field (Not Working on Latest Windows)
* Open Document
* .xml – via Microsoft Word external stylesheet
* .xml – via Microsoft Word includepicture field
* .htm – via Chrome & IE & Edge img src (only if opened locally, not hosted)
* .docx – via Microsoft Word includepicture field
* .docx – via Microsoft Word external template
* .docx – via Microsoft Word frameset webSettings
* .xlsx - via Microsoft Excel external cell
* .wax - via Windows Media Player playlist (Better, primary open)
* .asx – via Windows Media Player playlist (Better, primary open)
* .m3u – via Windows Media Player playlist (Worse, Win10 opens first in Groovy)
* .jnlp – via Java external jar
* .application – via any Browser (Must be served via a browser downloaded or won’t run)
* Open Document and Accept Popup
* .pdf – via Adobe Acrobat Reader
* Click Link in Chat Program
* .txt – formatted link to paste into Zoom chat
Usecases (Why you want to run this)
ntlm_theft is primarily aimed at Penetration Testers and Red Teamers, who will use it to perform internal phishing on target company employees, or to mass test antivirus and email gateways. It may also be used for external phishing if outbound SMB access is allowed on the perimeter firewall.
I've found it useful while penetration testing to easily see what file types I have available to me, rather than spending time configuring a specific attack as would be used on red teaming engagements. You could send a .rtf or .docx file to the HR department, and a .xlsx spreadsheet doc to the finance department.
Getting Started
These instructions will show you the requirements for and how [...]
Ntlm_Theft - A Tool For Generating Multiple Types Of NTLMv2 Hash Theft Files
http://2.bp.blogspot.com/-Lc-pMQxsfVg/YTVKVhCUJqI/AAAAAAAAt1I/Hsik9IJaHQENyEWH7b1bKIx-2vjj3ttNwCK4BGAYYCw/w640-h336/ntlm_theft_1_example-run-781145.png
A tool for generating multiple types of NTLMv2 hash theft files.
ntlm_theft is an Open Source Python3 Tool that generates 21 different types of hash theft documents. These can be used for phishing when either the target allows smb traffic outside their network, or if you are already inside the internal network.
The benefits of these file types over say macro based documents or exploit documents are that all of these are built using "intended functionality". None were flagged by Windows Defender Antivirus on June 2020, and 17 of the 21 attacks worked on a fully patched Windows 10 host.
ntlm_theft supports the following attack types:
* Browse to Folder Containing
* .url – via URL field
* .url – via ICONFILE field
* .lnk - via icon_location field
* .scf – via ICONFILE field (Not Working on Latest Windows)
* autorun.inf via OPEN field (Not Working on Latest Windows)
* desktop.ini - via IconResource field (Not Working on Latest Windows)
* Open Document
* .xml – via Microsoft Word external stylesheet
* .xml – via Microsoft Word includepicture field
* .htm – via Chrome & IE & Edge img src (only if opened locally, not hosted)
* .docx – via Microsoft Word includepicture field
* .docx – via Microsoft Word external template
* .docx – via Microsoft Word frameset webSettings
* .xlsx - via Microsoft Excel external cell
* .wax - via Windows Media Player playlist (Better, primary open)
* .asx – via Windows Media Player playlist (Better, primary open)
* .m3u – via Windows Media Player playlist (Worse, Win10 opens first in Groovy)
* .jnlp – via Java external jar
* .application – via any Browser (Must be served via a browser downloaded or won’t run)
* Open Document and Accept Popup
* .pdf – via Adobe Acrobat Reader
* Click Link in Chat Program
* .txt – formatted link to paste into Zoom chat
Usecases (Why you want to run this)
ntlm_theft is primarily aimed at Penetration Testers and Red Teamers, who will use it to perform internal phishing on target company employees, or to mass test antivirus and email gateways. It may also be used for external phishing if outbound SMB access is allowed on the perimeter firewall.
I've found it useful while penetration testing to easily see what file types I have available to me, rather than spending time configuring a specific attack as would be used on red teaming engagements. You could send a .rtf or .docx file to the HR department, and a .xlsx spreadsheet doc to the finance department.
Getting Started
These instructions will show you the requirements for and how [...]
hacking: security in practice
How to block text hackcer
Hi,
A text hacker is changing the words in every site I type in.
How can I block him?
And is it possible to know his location?
submitted by /u/Survector
[link] [comments]
How to block text hackcer
Hi,
A text hacker is changing the words in every site I type in.
How can I block him?
And is it possible to know his location?
submitted by /u/Survector
[link] [comments]
reddit
How to block text hackcer
Hi, A text hacker is changing the words in every site I type in. How can I block him? And is it possible to know his location?
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
is there any way to figure out who the owner of a cellphone number is?
first off i have ABSOLUTELY no malicious intent with this at all. also, im sorry if this isnt the right sub for this. feel free to let me know if theres a better one for this kinda thing, i just thought this one might be a good one to ask. basically a while back someone was texting me telling me some things abt a relationship i was in and at the time i thought they were lying or playing a prank on me, but now i have reason to believe they weren’t. i really would just like to know some details abt the situation. i tried texting the number back but not sure if they will respond.
i think it could have been a fake number from google voice or something, i tried 2 different websites/paid for them and it said no results on a name except a location they could be in that wasn’t accurate. i can give more details about what the websites said if needed but i dont think it matters or if its even accurate. i also have an apple phone, their texts appeared green and thats what happens if theyre texting off google voice or something like that.
so i guess im just asking if theres any possible way that i could figure out who it is? if its a fake can i somehow trace their real number of the phone they’re using? any good websites or anything i can do myself? if anyone would like to help me with this privately feel free to send me a private message, im more than happy to pay if you can help me with this.
submitted by /u/jmdeman
[link] [comments]
is there any way to figure out who the owner of a cellphone number is?
first off i have ABSOLUTELY no malicious intent with this at all. also, im sorry if this isnt the right sub for this. feel free to let me know if theres a better one for this kinda thing, i just thought this one might be a good one to ask. basically a while back someone was texting me telling me some things abt a relationship i was in and at the time i thought they were lying or playing a prank on me, but now i have reason to believe they weren’t. i really would just like to know some details abt the situation. i tried texting the number back but not sure if they will respond.
i think it could have been a fake number from google voice or something, i tried 2 different websites/paid for them and it said no results on a name except a location they could be in that wasn’t accurate. i can give more details about what the websites said if needed but i dont think it matters or if its even accurate. i also have an apple phone, their texts appeared green and thats what happens if theyre texting off google voice or something like that.
so i guess im just asking if theres any possible way that i could figure out who it is? if its a fake can i somehow trace their real number of the phone they’re using? any good websites or anything i can do myself? if anyone would like to help me with this privately feel free to send me a private message, im more than happy to pay if you can help me with this.
submitted by /u/jmdeman
[link] [comments]
reddit
is there any way to figure out who the owner of a cellphone number is?
first off i have ABSOLUTELY no malicious intent with this at all. also, im sorry if this isnt the right sub for this. feel free to let me know if...
hacking: security in practice
Tricking a motion detector with a camera?
Hi there,
Again I post this in hacking, as it would be something illegal but the purpose is completely legitimate.
I'm at a co-working space that at night have the lights of a room triggered by a motion detector (there are 3 of them in the room), the issue is that as I'm studying I'm not moving from the position and lights keep turning off , as soon as I move a bit the chair the lights turn on again. I can't stand this to be honest , either turn them on or turn them off , but don't play around with me as it's drawing my attention.
How can I trick one of this motion sensors to detect always movement in a room with the devices I have with me? I would need a pendulum or something like that , but that is not feasible , I could set up the phone to flash directly to the motion sensor each time it turns off (periodically) , but there is no flash light apps that I have found that do that periodically.
I just sticked some post-its see if at least it detect no motion at all for a while and then it turns off completely.
Any ideas?
submitted by /u/brohermano
[link] [comments]
Tricking a motion detector with a camera?
Hi there,
Again I post this in hacking, as it would be something illegal but the purpose is completely legitimate.
I'm at a co-working space that at night have the lights of a room triggered by a motion detector (there are 3 of them in the room), the issue is that as I'm studying I'm not moving from the position and lights keep turning off , as soon as I move a bit the chair the lights turn on again. I can't stand this to be honest , either turn them on or turn them off , but don't play around with me as it's drawing my attention.
How can I trick one of this motion sensors to detect always movement in a room with the devices I have with me? I would need a pendulum or something like that , but that is not feasible , I could set up the phone to flash directly to the motion sensor each time it turns off (periodically) , but there is no flash light apps that I have found that do that periodically.
I just sticked some post-its see if at least it detect no motion at all for a while and then it turns off completely.
Any ideas?
submitted by /u/brohermano
[link] [comments]
reddit
Tricking a motion detector with a camera?
Hi there, Again I post this in hacking, as it would be something illegal but the purpose is completely legitimate. I'm at a co-working space...