Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Freedom Hosting Admin Sentenced to 27 Years in Prison
https://external-preview.redd.it/Bn5uT7ReHZJQod0Xb7NNDib52YJdtbLxqLNJEjcA3F4.jpg?width=640&crop=smart&auto=webp&s=b943d43a1f6e23f3df7e5690a765cfd5084d8dbf submitted by /u/kirby__000
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Freedom Hosting Admin Sentenced to 27 Years in Prison
https://external-preview.redd.it/Bn5uT7ReHZJQod0Xb7NNDib52YJdtbLxqLNJEjcA3F4.jpg?width=640&crop=smart&auto=webp&s=b943d43a1f6e23f3df7e5690a765cfd5084d8dbf submitted by /u/kirby__000
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Freedom Hosting Admin Sentenced to 27 Years in Prison
Posted in r/deepweb by u/kirby__000 • 1 point and 0 comments
PyHook - An Offensive API Hooking Tool Written In Python Designed To Catch Various Credentials Within The API Call
PyHook is the python implementation of my SharpHook project, It uses various API hooks in order to give us the desired credentials. PyHook Uses frida to inject it's dependencies into the target processSupported Processes Process API Call Description Progress mstsc CredUnPackAuthenticationBufferW This will hook into mstsc and should give you Username and Password DONE runas CreateProcessWithLogonW This will hook into runas and should give you Username, Password and the domain name DONE cmd RtlInitUnicodeStringEx This should hook into cmd and then would be able to filter keywords like: PsExec,password etc.. DONE MobaXterm CharUpperBuffA This will hook into MobaXterm and should give you credentials for SSH and RDP logins DONE explorer (UAC Prompt) CredUnPackAuthenticationBufferW This will hook into explorer and should give you Username, Password and the Domain name from the UAC Prompt DONE Link my blog post covering this topic: https://ilankalendarov.github.io/posts/offensive-hooking Download PyHook
Read more...
___________________________
@hacking_Attack
@Hacking_Video
PyHook is the python implementation of my SharpHook project, It uses various API hooks in order to give us the desired credentials. PyHook Uses frida to inject it's dependencies into the target processSupported Processes Process API Call Description Progress mstsc CredUnPackAuthenticationBufferW This will hook into mstsc and should give you Username and Password DONE runas CreateProcessWithLogonW This will hook into runas and should give you Username, Password and the domain name DONE cmd RtlInitUnicodeStringEx This should hook into cmd and then would be able to filter keywords like: PsExec,password etc.. DONE MobaXterm CharUpperBuffA This will hook into MobaXterm and should give you credentials for SSH and RDP logins DONE explorer (UAC Prompt) CredUnPackAuthenticationBufferW This will hook into explorer and should give you Username, Password and the Domain name from the UAC Prompt DONE Link my blog post covering this topic: https://ilankalendarov.github.io/posts/offensive-hooking Download PyHook
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Ilan Kalendarov
Offensive API Hooking
Introduction
Difficulty in finding jobs
https://www.reddit.com/r/Pentesting/comments/psvgyz/difficulty_in_finding_jobs/
Hello friends, I'm a Linux systems administrator with +12y experience. Also having worked as Security Analyst and Security Admin for around 5y in total. 2 years ago I decided to move to offensive security. September 1st I took my OSCP credential, since then, I'm looking for a formal position in ethical hacking/pentesting/red pill team; there's a LOT of available jobs, but I couldn't found any country accepting people from outside - for many reasons that you guys may know (citizenship, TS/SCI clearance, etc.) even for remote jobs. 2 months ago I left my 5 years job at IBM to focus on my offensive security career. Now I'm afraid to not be able to have a job in this area. Could you guys please give me a direction? I really appreciate PS: I also have a dozen other certificates (as RHCE, AWS DevOps Engineer...) and I live in Brazil. submitted by /u/brunoanjoz (https://www.reddit.com/user/brunoanjoz)
[link] (https://www.reddit.com/r/Pentesting/comments/psvgyz/difficulty_in_finding_jobs/) [comments] (https://www.reddit.com/r/Pentesting/comments/psvgyz/difficulty_in_finding_jobs/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/psvgyz/difficulty_in_finding_jobs/
Hello friends, I'm a Linux systems administrator with +12y experience. Also having worked as Security Analyst and Security Admin for around 5y in total. 2 years ago I decided to move to offensive security. September 1st I took my OSCP credential, since then, I'm looking for a formal position in ethical hacking/pentesting/red pill team; there's a LOT of available jobs, but I couldn't found any country accepting people from outside - for many reasons that you guys may know (citizenship, TS/SCI clearance, etc.) even for remote jobs. 2 months ago I left my 5 years job at IBM to focus on my offensive security career. Now I'm afraid to not be able to have a job in this area. Could you guys please give me a direction? I really appreciate PS: I also have a dozen other certificates (as RHCE, AWS DevOps Engineer...) and I live in Brazil. submitted by /u/brunoanjoz (https://www.reddit.com/user/brunoanjoz)
[link] (https://www.reddit.com/r/Pentesting/comments/psvgyz/difficulty_in_finding_jobs/) [comments] (https://www.reddit.com/r/Pentesting/comments/psvgyz/difficulty_in_finding_jobs/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Difficulty in finding jobs
Hello friends, I'm a Linux systems administrator with +12y experience. Also having worked as Security Analyst and Security Admin for...
hacking: security in practice
Anyone know how to fix this Beef-xss problem im having?
Heres the log
[i] GeoIP database is missing
[i] Run geoipupdate to download / update Maxmind GeoIP database
[*] Please wait for the BeEF service to start.
[*]
[*] You might need to refresh your browser once it opens.
[*]
[*] Web UI: http://127.0.0.1:3000/ui/panel
[*] Hook:
[*] Example:
● beef-xss.service - beef-xss
Loaded: loaded (/lib/systemd/system/beef-xss.service; disabled; vendor preset: disabled)
Active: failed (Result: exit-code) since Tue 2021-09-21 20:33:54 EDT; 3s ago
Process: 1241 ExecStart=/usr/share/beef-xss/beef (code=exited, status=1/FAILURE)
Main PID: 1241 (code=exited, status=1/FAILURE)
CPU: 1.159s
Sep 21 20:33:54 kali beef[1241]: [20:33:54][*] Browser Exploitation Framework (BeEF) 0.5.0.0
Sep 21 20:33:54 kali beef[1241]: [20:33:54] | Twit: u/beefproject
Sep 21 20:33:54 kali beef[1241]: [20:33:54] | Site: https://beefproject.com
Sep 21 20:33:54 kali beef[1241]: [20:33:54] | Blog: http://blog.beefproject.com
Sep 21 20:33:54 kali beef[1241]: [20:33:54] |_ Wiki: https://github.com/beefproject/beef/wiki
Sep 21 20:33:54 kali beef[1241]: [20:33:54][*] Project Creator: Wade Alcorn (@WadeAlcorn)
Sep 21 20:33:54 kali beef[1241]: -- migration_context()
Sep 21 20:33:54 kali systemd[1]: beef-xss.service: Main process exited, code=exited, status=1/FAILURE
Sep 21 20:33:54 kali systemd[1]: beef-xss.service: Failed with result 'exit-code'.
Sep 21 20:33:54 kali systemd[1]: beef-xss.service: Consumed 1.159s CPU time.
[*] Opening Web UI (http://127.0.0.1:3000/ui/panel) in: 5... 4... 3... 2... 1...
┌──(kali㉿kali)-[~]
└─$
submitted by /u/o1blique1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anyone know how to fix this Beef-xss problem im having?
Heres the log
[i] GeoIP database is missing
[i] Run geoipupdate to download / update Maxmind GeoIP database
[*] Please wait for the BeEF service to start.
[*]
[*] You might need to refresh your browser once it opens.
[*]
[*] Web UI: http://127.0.0.1:3000/ui/panel
[*] Hook:
[*] Example:
● beef-xss.service - beef-xss
Loaded: loaded (/lib/systemd/system/beef-xss.service; disabled; vendor preset: disabled)
Active: failed (Result: exit-code) since Tue 2021-09-21 20:33:54 EDT; 3s ago
Process: 1241 ExecStart=/usr/share/beef-xss/beef (code=exited, status=1/FAILURE)
Main PID: 1241 (code=exited, status=1/FAILURE)
CPU: 1.159s
Sep 21 20:33:54 kali beef[1241]: [20:33:54][*] Browser Exploitation Framework (BeEF) 0.5.0.0
Sep 21 20:33:54 kali beef[1241]: [20:33:54] | Twit: u/beefproject
Sep 21 20:33:54 kali beef[1241]: [20:33:54] | Site: https://beefproject.com
Sep 21 20:33:54 kali beef[1241]: [20:33:54] | Blog: http://blog.beefproject.com
Sep 21 20:33:54 kali beef[1241]: [20:33:54] |_ Wiki: https://github.com/beefproject/beef/wiki
Sep 21 20:33:54 kali beef[1241]: [20:33:54][*] Project Creator: Wade Alcorn (@WadeAlcorn)
Sep 21 20:33:54 kali beef[1241]: -- migration_context()
Sep 21 20:33:54 kali systemd[1]: beef-xss.service: Main process exited, code=exited, status=1/FAILURE
Sep 21 20:33:54 kali systemd[1]: beef-xss.service: Failed with result 'exit-code'.
Sep 21 20:33:54 kali systemd[1]: beef-xss.service: Consumed 1.159s CPU time.
[*] Opening Web UI (http://127.0.0.1:3000/ui/panel) in: 5... 4... 3... 2... 1...
┌──(kali㉿kali)-[~]
└─$
submitted by /u/o1blique1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anyone know how to fix this Beef-xss problem im having?
Heres the log \[i\] GeoIP database is missing \[i\] Run geoipupdate to download / update Maxmind GeoIP database \[\*\]...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
When is it possible to make an attack like this?
I'm starting to study pentest and cybersecurity.
I found this attack on a website. I would like to know how this attack would work. When is it possible and what information is needed to carry it out.
I created an environment of servers and fake sites to play with, but I couldn't hack into any system. I must have something wrong.
What do you say?
submitted by /u/essencedata
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
When is it possible to make an attack like this?
I'm starting to study pentest and cybersecurity.
I found this attack on a website. I would like to know how this attack would work. When is it possible and what information is needed to carry it out.
I created an environment of servers and fake sites to play with, but I couldn't hack into any system. I must have something wrong.
What do you say?
submitted by /u/essencedata
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
When is it possible to make an attack like this?
I'm starting to study pentest and cybersecurity. I found this attack on a website. I would like to know how [this...
hacking: security in practice
GCP - recommended vulnerability scanners
I have worked with AWS for years and recently found myself within a Google Cloud architecture at a new position. I’m not very familiar with GCP in the first place so I’m cautious/skeptical of integrations.
We utilize most of the Firebase suite (functions, pubsub, Firestore, etc). Honestly, it’s all a seemingly a little cookie cutter for my taste but it’s what it is.
Outside of me doing my own DD with their blogs and recommendations on security setup I wanted to reach out to this group.
Are there recommend automation tools someone could suggest for me to run a high level pen test best suited for GCP?
submitted by /u/jalapeno-grill
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
GCP - recommended vulnerability scanners
I have worked with AWS for years and recently found myself within a Google Cloud architecture at a new position. I’m not very familiar with GCP in the first place so I’m cautious/skeptical of integrations.
We utilize most of the Firebase suite (functions, pubsub, Firestore, etc). Honestly, it’s all a seemingly a little cookie cutter for my taste but it’s what it is.
Outside of me doing my own DD with their blogs and recommendations on security setup I wanted to reach out to this group.
Are there recommend automation tools someone could suggest for me to run a high level pen test best suited for GCP?
submitted by /u/jalapeno-grill
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
GCP - recommended vulnerability scanners
I have worked with AWS for years and recently found myself within a Google Cloud architecture at a new position. I’m not very familiar with GCP in...
1*4KBdxYRJ1tCKCvY9gQ2hQw.gif
47 KB
Hacking on Medium
Hacker101 CTF — Encrypted Pastebin — 2/4 FLAGS (Español)
Hola terrícolas, espero estén teniendo un excelente mes.
Continue reading on Medium »
Hacker101 CTF — Encrypted Pastebin — 2/4 FLAGS (Español)
Hola terrícolas, espero estén teniendo un excelente mes.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!Weakpass - Rule-Based Online Generator To Create A Wordlist Based On A Set Of Words
The tool generates a wordlist based on a set of words entered by the user.
For example, during penetration testing, you need to gain access to some service, device, account, or Wi-Fi network that is password protected. For example, let it be the Wi-Fi network of EvilCorp. Sometimes, a password is a combination of device/network/organization name with some date, special character, etc. Therefore, it is simpler and easier to test some combinations before launching more complex and time-consuming checks. For example, cracking a Wi-Fi password with a wordlist can take several hours and can fail, even if you choose a great wordlist because there was no such password in it like Evilcorp2019.
Therefore, using the generated wordlist, it is possible to organize a targeted and effective online password check.
Link: https://zzzteph.github.io/weakpass/
Secondary: https://weakpass.com/generate
Features
The hashcat rule syntax is used to generate the wordlist. By default, the generator uses a set of rules "online.rule", which performs the following mutations:
1. Adding special characters and popular endings to the end of the word - !,!@, !@#, 123! etc. evilcorp!, evilcorp!123
2. Adding digits from 1 to 31, from 01 to 12 - evilcorp01, evilcorp12.
3. Adding the date 2018-2023 - evilcorp2018, evilcorp2019
4. Various combinations of 1-3 - evilcorp2018!
5. Capitalize the first letter and lower the rest, apply 1-4. Evilcorp!2021
As a result, for the word evilcorp, the following passwords will be generated (216 in total):
* evilcorp
* Evilcorp
* EVILCORP
* evilcorp123456
* evilcorp2018
* Evilcorp!2021
* Evilcorp!2022
* Evilcorp2018!@#
You can use your own hashcat rules, just click "Show rules" and put in the "Rules" textarea them with the list of rules you like best. Rules that are supported (source https://hashcat.net/wiki/doku.php?id=rule_based_attack):
NameFunctionDescriptionExample RuleInput WordOutput WordNothing:Do nothing (passthrough):p@ssW0rdp@ssW0rdLowercaselLowercase all letterslp@ssW0rdp@ssw0rdUppercaseuUppercase all lettersup@ssW0rdP@SSW0RDCapitalizecCapitalize the first letter and lower the restcp@ssW0rdP@ssw0rdInvert CapitalizeCLowercase first found character, uppercase the restCp@ssW0rdp@SSW0RDToggle CasetToggle the case of all characters in word.tp@ssW0rdP@SSw0RDToggle @TNToggle the case of characters at position NT3p@ssW0rdp@sSW0rdReverserReverse the entire wordrp@ssW0rddr0Wss@pDuplicatedDuplicate entire worddp@ssW0rdp@ssW0rdp@ssW0rdDuplicate NpNAppend duplicated word N timesp2p@ssW0rdp@ssW0rdp@ssW0rdp@ssW0rdReflectfDuplicate word reversedfp@ssW0rdp@ssW0rddr0Wss@pRotate Left{Rotate the word left.{p@ssW0rd@ssW0rdpRotate Right}Rotate the word right}p@ssW0rddp@ssW0rAppend Character$XAppend character X to end$1p@ssW0rdp@ssW0rd1Prepend Character^XPrepend character X to front^1p@ssW0rd1p@ssW0rdTruncate left[Delete first character[p@ssW0rd@ssW0rdTrucate right]Delete last character]p@ssW0rdp@assW0rDelete @ NDNDelete character at position ND3p@ssW0rdp@sW0rdExtract rangexNMExtract M characters, starting at position Nx04p@ssW0rdp@ssOmit rangeONMDelete M characters, starting at position NO12p@ssW0rdpsW0rdInsert @ NiNXInsert character X at position Ni4!p@ssW0rdp@ss!W0rdOverwrite @ NoNXOverwrite character at position N with Xo3$p@ssW0rdp@s$W0rdTruncate @ N'NTruncate word at position N'6p@ssW0rdp@ssW0ReplacesXYReplace all instances of X with Yss$p@ssW0rdp@$$W0rdPurge@XPurge all instances of X@sp@ssW0rdp@W0rdDuplicate first NzNDuplicate first character N timesz2p@ssW0rdppp@ssW0rdDuplicate last NZNDuplicate last character N timesZ2p@ssW0rdp@ssW0rdddDuplicate allqDuplicate every characterqp@ssW0rdpp@@ssssWW00rrdd
The generator automatically removes duplicate passwords.
By pressing the Wi-Fi, all passwords less than 8 characters long will be automaticall[...]
___________________________
@hacking_Attack
@Hacking_Video
The tool generates a wordlist based on a set of words entered by the user.
For example, during penetration testing, you need to gain access to some service, device, account, or Wi-Fi network that is password protected. For example, let it be the Wi-Fi network of EvilCorp. Sometimes, a password is a combination of device/network/organization name with some date, special character, etc. Therefore, it is simpler and easier to test some combinations before launching more complex and time-consuming checks. For example, cracking a Wi-Fi password with a wordlist can take several hours and can fail, even if you choose a great wordlist because there was no such password in it like Evilcorp2019.
Therefore, using the generated wordlist, it is possible to organize a targeted and effective online password check.
Link: https://zzzteph.github.io/weakpass/
Secondary: https://weakpass.com/generate
Features
The hashcat rule syntax is used to generate the wordlist. By default, the generator uses a set of rules "online.rule", which performs the following mutations:
1. Adding special characters and popular endings to the end of the word - !,!@, !@#, 123! etc. evilcorp!, evilcorp!123
2. Adding digits from 1 to 31, from 01 to 12 - evilcorp01, evilcorp12.
3. Adding the date 2018-2023 - evilcorp2018, evilcorp2019
4. Various combinations of 1-3 - evilcorp2018!
5. Capitalize the first letter and lower the rest, apply 1-4. Evilcorp!2021
As a result, for the word evilcorp, the following passwords will be generated (216 in total):
* evilcorp
* Evilcorp
* EVILCORP
* evilcorp123456
* evilcorp2018
* Evilcorp!2021
* Evilcorp!2022
* Evilcorp2018!@#
You can use your own hashcat rules, just click "Show rules" and put in the "Rules" textarea them with the list of rules you like best. Rules that are supported (source https://hashcat.net/wiki/doku.php?id=rule_based_attack):
NameFunctionDescriptionExample RuleInput WordOutput WordNothing:Do nothing (passthrough):p@ssW0rdp@ssW0rdLowercaselLowercase all letterslp@ssW0rdp@ssw0rdUppercaseuUppercase all lettersup@ssW0rdP@SSW0RDCapitalizecCapitalize the first letter and lower the restcp@ssW0rdP@ssw0rdInvert CapitalizeCLowercase first found character, uppercase the restCp@ssW0rdp@SSW0RDToggle CasetToggle the case of all characters in word.tp@ssW0rdP@SSw0RDToggle @TNToggle the case of characters at position NT3p@ssW0rdp@sSW0rdReverserReverse the entire wordrp@ssW0rddr0Wss@pDuplicatedDuplicate entire worddp@ssW0rdp@ssW0rdp@ssW0rdDuplicate NpNAppend duplicated word N timesp2p@ssW0rdp@ssW0rdp@ssW0rdp@ssW0rdReflectfDuplicate word reversedfp@ssW0rdp@ssW0rddr0Wss@pRotate Left{Rotate the word left.{p@ssW0rd@ssW0rdpRotate Right}Rotate the word right}p@ssW0rddp@ssW0rAppend Character$XAppend character X to end$1p@ssW0rdp@ssW0rd1Prepend Character^XPrepend character X to front^1p@ssW0rd1p@ssW0rdTruncate left[Delete first character[p@ssW0rd@ssW0rdTrucate right]Delete last character]p@ssW0rdp@assW0rDelete @ NDNDelete character at position ND3p@ssW0rdp@sW0rdExtract rangexNMExtract M characters, starting at position Nx04p@ssW0rdp@ssOmit rangeONMDelete M characters, starting at position NO12p@ssW0rdpsW0rdInsert @ NiNXInsert character X at position Ni4!p@ssW0rdp@ss!W0rdOverwrite @ NoNXOverwrite character at position N with Xo3$p@ssW0rdp@s$W0rdTruncate @ N'NTruncate word at position N'6p@ssW0rdp@ssW0ReplacesXYReplace all instances of X with Yss$p@ssW0rdp@$$W0rdPurge@XPurge all instances of X@sp@ssW0rdp@W0rdDuplicate first NzNDuplicate first character N timesz2p@ssW0rdppp@ssW0rdDuplicate last NZNDuplicate last character N timesZ2p@ssW0rdp@ssW0rdddDuplicate allqDuplicate every characterqp@ssW0rdpp@@ssssWW00rrdd
The generator automatically removes duplicate passwords.
By pressing the Wi-Fi, all passwords less than 8 characters long will be automaticall[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools!Weakpass - Rule-Based Online Generator To Create A Wordlist Based On A Set Of Words The tool generates a wordlist based on a set of words entered by the user. For example, during penetration testing, you need to gain access…
y deleted.
All data is generated using Javascript so that you can use the generator without internet access.
How-to
1. To generate a wordlist, enter in the Words field, words that can be used as part of the password.
2. Click on the Generate button
3. Copy the received content or click on the Copy to clipboard button for automatic copying.
4. ...
5. Profit!
Download Weakpass
___________________________
@hacking_Attack
@Hacking_Video
All data is generated using Javascript so that you can use the generator without internet access.
How-to
1. To generate a wordlist, enter in the Words field, words that can be used as part of the password.
2. Click on the Generate button
3. Copy the received content or click on the Copy to clipboard button for automatic copying.
4. ...
5. Profit!
Download Weakpass
___________________________
@hacking_Attack
@Hacking_Video
My hacking journey and How i got my First Bug after 50+ duplicates?
https://medium.com/@tbw_lucilu/my-hacking-journey-and-how-i-got-my-first-bug-after-50-duplicates-a1ec22c365fb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@tbw_lucilu/my-hacking-journey-and-how-i-got-my-first-bug-after-50-duplicates-a1ec22c365fb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
My hacking journey and How i got my First Bug after 50+ duplicates?
Hello Hunters,
Hello Hunters,Continue reading on Medium » (https://medium.com/@tbw_lucilu/my-hacking-journey-and-how-i-got-my-first-bug-after-50-duplicates-a1ec22c365fb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My hacking journey and How i got my First Bug after 50+ duplicates?
Hello Hunters,