Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Peirates : Kubernetes Penetration Testing Tool

Peirates, a Kubernetes penetration tool, enables an attacker to escalate privilege and pivot through a Kubernetes cluster. It automates known techniques to steal and collect service accounts, obtain further code execution, and gain control of the cluster.

Where Do I Run Peirates?

You run Peirates from a container running on Kubernetes.

Does Peirates Attack A Kubernetes Cluster?

Yes, it absolutely does. Talk to your lawyer and the cluster owners before using this tool in a Kubernetes cluster.

Who Creates Peirates?

InGuardians’ CTO Jay Beale first conceived of Peirates and put together a group of InGuardians developers to create it with him, including Faith Alderson, Adam Crompton and Dave Mayer. Faith convinced us to all learn Golang, so she could implement the tool’s use of the kubectl library from the Kubernetes project. Adam persuaded the group to use a highly-interactive user interface. Dave brought contagious enthusiasm. Together, these four developers implemented attacks and began releasing this tool that we use on our penetration tests.

Modules

Building And Running

If you just want the peirates binary to start attacking things, grab the latest release from the releases page.

However, if you want to build from source, read on!

Get peirates

go get -v “github.com/inguardians/peirates

Get libary sources if you haven’t already (Warning: this will take almost a gig of space because it needs the whole kubernetes repository)

go get -v “k8s.io/kubectl/pkg/cmd” “github.com/aws/aws-sdk-go

Build the executable

cd $GOPATH/github.com/inguardians/peirates
./build.sh

This will generate an executable file named peiratesin the same directory.
Download

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
how to compile .afa, .qnd and .flat ?

i'm searching for a way to recompile .flat, .qnd and .afa files, if somebody has an idea on how to do that please hep me

submitted by /u/audaidai
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Turns any junk text into a usable wordlist for brute-forcing.
Installation
go install github.com/hakluke/haklistgen@latest

Usage Examples
Scrape all words out of an HTTP response to build a directory bruteforce (https://www.kitploit.com/search/label/Bruteforce) wordlist: curl https://wikipedia.org | haklistgen
Pipe a list of subdomains (https://www.kitploit.com/search/label/Subdomains) to it to generate a wordlist for bruteforcing (https://www.kitploit.com/search/label/Bruteforcing) more subdomains: subfinder -silent -d example.com | haklistgen
Piping in a custom JavaScript file could yield some interesting results: curl https://example.com/app.js | haklistgen
You could create a great custom wordlist (https://www.kitploit.com/search/label/Custom%20Wordlist) for a large-scope target doing something like this: hakrawler | anew endpoints.txt | while read url; do curl $url --insecure | haklistgen | anew wordlist.txt; done cat subdomains.txt urls.txt endpoints.txt | haklistgen | anew wordlist.txt; ">subfinder -silent -d hakluke.com | anew subdomains.txt | httpx -silent | anew urls.txt | hakrawler | anew endpoints.txt | while read url; do curl $url --insecure | haklistgen | anew wordlist.txt; done
cat subdomains.txt urls.txt endpoints.txt | haklistgen | anew wordlist.txt;
This would save subdomains to subdomains.txt, then save httpx output to urls.txt, then crawl each url and save the hakrawler output to endpoints.txt, then fetch every URL in endpoints.txt and make a wordlist out of it, concatenating all of the wordlists to wordlist.txt. Then it takes all of the subdomains and urls, and adds words out of the words in those too.

Download Haklistgen (https://github.com/hakluke/haklistgen)

___________________________
@hacking_Attack
@Hacking_Video
Haklistgen - Turns Any Junk Text Into A Usable Wordlist For Brute-Forcing

Turns any junk text into a usable wordlist for brute-forcing.Installation go install github.com/hakluke/haklistgen@latest Usage Examples Scrape all words out of an HTTP response to build a directory bruteforce wordlist: curl https://wikipedia.org | haklistgen Pipe a list of subdomains to it to generate a wordlist for bruteforcing more subdomains: subfinder -silent -d example.com | haklistgen Piping in a custom JavaScript file could yield some interesting results: curl https://example.com/app.js | haklistgen You could create a great custom wordlist for a large-scope target doing something like this: hakrawler | anew endpoints.txt | while read url; do curl $url --insecure | haklistgen | anew wordlist.txt; done cat subdomains.txt urls.txt endpoints.txt | haklistgen | anew wordlist.txt; ">subfinder -silent -d hakluke.com | anew subdomains.txt | httpx -silent | anew urls.txt | hakrawler | anew endpoints.txt | while read url; do curl $url --insecure | haklistgen | anew wordlist.txt; donecat subdomains.txt urls.txt endpoints.txt | haklistgen | anew wordlist.txt; This would save subdomains to subdomains.txt, then save httpx output to urls.txt, then crawl each url and save the hakrawler output to endpoints.txt, then fetch every URL in endpoints.txt and make a wordlist out of it, concatenating all of the wordlists to wordlist.txt. Then it takes all of the subdomains and urls, and adds words out of the words in those too. Download Haklistgen
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Haklistgen - Turns Any Junk Text Into A Usable Wordlist For Brute-Forcing

https://1.bp.blogspot.com/-tAJa4MDz_Co/YUuoLt01PoI/AAAAAAAAvSU/CkAAccSSGBI6r6apc9d3cLcmRkAjTTyCgCNcBGAsYHQ/w640-h373/some_words.png
Turns any junk text into a usable wordlist for brute-forcing.
Installation

go install github.com/hakluke/haklistgen@latest


Usage Examples

Scrape all words out of an HTTP response to build a directory bruteforce wordlist:

curl https://wikipedia.org | haklistgen


Pipe a list of subdomains to it to generate a wordlist for bruteforcing more subdomains:

subfinder -silent -d example.com | haklistgen


Piping in a custom JavaScript file could yield some interesting results:

curl https://example.com/app.js | haklistgen


You could create a great custom wordlist for a large-scope target doing something like this:

hakrawler | anew endpoints.txt | while read url; do curl $url --insecure | haklistgen | anew wordlist.txt; done cat subdomains.txt urls.txt endpoints.txt | haklistgen | anew wordlist.txt; ">subfinder -silent -d hakluke.com | anew subdomains.txt | httpx -silent | anew urls.txt | hakrawler | anew endpoints.txt | while read url; do curl $url --insecure | haklistgen | anew wordlist.txt; done
cat subdomains.txt urls.txt endpoints.txt | haklistgen | anew wordlist.txt;


This would save subdomains to subdomains.txt, then save httpx output to urls.txt, then crawl each url and save the hakrawler output to endpoints.txt, then fetch every URL in endpoints.txtand make a wordlist out of it, concatenating all of the wordlists to wordlist.txt. Then it takes all of the subdomains and urls, and adds words out of the words in those too.
Download Haklistgen

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
What Is the Difference Between Security and Resilience?

Resilience shifts the focus toward eliminating the probable impact of the full attack chain.
https://b.thumbs.redditmedia.com/lrqohyX2gI4XGPoLFe1hGuI77Xx4iRmJJO8fhY1l7Ro.jpg So, i hope someone can help me with my project, or else i can kiss my plans goodbye...

A while ago i bought a Google Nest Hub (1st gen) to run my own software/dashboard. At first i tried to 'Cast' it as webpage to the device, but that is not fully stable. Especially now that they updated the Hub to run Fuchsia OS.

So, my plan is to OR alter the Google firmware to run my own stuff on top of Fuchsia. Maybe create my own Flutter app or something. OR build linux from source, which is available for the S905D2 u200, which is the CPU of the Nest Hub. The latter gives me more control but i would have to get all hardware running in linux.

Both options give me some problems though:

* The hub has a USB port under the foot. If you press both volume buttons while booting, you get the Amlogic Worldcup device where you can talk to it with the Amlogic burn tool. You can flash firmware here or even dump firmware from it. Problem is: Google password protected this so you first have to upload a password.bin file before you can use the tool. Something that i presume is not possible to bruteforce...
* When you push one of the volume buttons while booting, you boot to Fastboot mode. Hey, that's familliar. So i tried some commands. fastboot unlock, does not work. flashing an own rom, not allowed. Flashing my own recovery image is allowed and completes succesfully. But, while trying to boot to recovery it sais: "Hash of data does not match digest in descriptor.". So it verifies the image which it cannot do.
* The other volume button boots to the recovery image, which is a google's own thing where you can reset the device to factory defaults if you want..



https://preview.redd.it/wy1gylr8gip71.jpg?width=4920&format=pjpg&auto=webp&s=289b62d9803a0191917a3d88773cbc6f09426db7

https://preview.redd.it/duqyimr8gip71.jpg?width=4920&format=pjpg&auto=webp&s=9e42c6b624e980965241713e24828ca30d911305



So i teared the device down, got to the PCB and found a RX/TX port. At least, i noticed that i got uart data when connecting to it. But, i can only read, it does not respond to keyboard presses. I don't know if the other pin is just no TX pin or that there is no software that will respond to keypresses.



My question, what else can i try, or did Google just lock it's hard-/software very well? Of course i could chip-off the NAND chip, but then reflowing it on the device after altering the NAND is almost impossible, especially if you have to do it a lot of times... What else can i do?

submitted by /u/geerttttt
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How would you attack my API?

Hi folks!

I've a REST-API in production and would like to secure it as good as possible. Basic measurements were taken:

* Validating input
* Some obfuscation
* ...

What should I be aware of? How would you try to hack it? Are there any legit recommended tools?

Thanks!

submitted by /u/FattySuperCute
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Why Russia is the perfect country to target with hacking

There are too many Russians attacking the US and other nations, and too little of the reverse, but I believe Russia is an appealing target for the following reasons:

* Wide alternate timezone - When you come back from work in the US, it would be work time for them. They will be logged in and you could respond immediately to a successful phish. Because Russia is spans many time zones, you can find a target that fits your schedule.
* Lack of legal consequence - We all know Russia won't extradite to the US, but the same is true of the reverse. Obviously, you should still use proper opsec anyways (use VPN+Tor with Whonix).
* Less security - Russian networks tend to be less secure than their US counterparts.

If you are a beginner, I would recommend targeting universities because of their poor security and public email addresses (for spear phishing). You can find a list of Russian universities here:

http://universities.hipolabs.com/search?country=Russian%20Federation

I ran sqlmap against the list and found numerous sql injection vulnerabilities, so you can give that a try. Ultimately though, I would recommend using spear phishing. You can use Yandex translate since it's better than Google translate.

submitted by /u/VXer64
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best laptop specs for hacking?

I am going to buy a laptop with Kali or Parrot Linux and it will be dedicated to hacking. Any particular specs or ideas to pay attention to instead of the obvious “good specs” of a laptop?

submitted by /u/SPantazis
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Deep Web
If using Tor, and the built-in VPN, will I find myself in trouble for visiting underdir.com?

Title. I went to underdir.com very briefly without following the links to any of the other sites on underdir.

I'm curious if my ISP will care, or police, or anyone further down that road; and if they would care if I were to go to any of the linked sites on underdir//explore the deep web.

I'm basically just asking what's the best way to be safe, and what's legal/what's not legal.

submitted by /u/moldyharriet
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video