Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Keeweb - Free Cross-Platform Password Manager Compatible With KeePass

This webapp is a browser and desktop password manager compatible with KeePass databases. It doesn't require any server or additional resources. The app can run either in browser, or as a desktop app.Quick Links Apps: Web, Desktop Timeline: Release Notes, TODO On one page: Features, FAQ Website: keeweb.info Twitter: kee_web Donate: OpenCollective, GitHub Status The app is quite stable now. Basic stuff, as well as more advanced operations, should be rather reliable. Self-hosting Everything you need to host this app on your server is any static file server. The app is a single HTML file + a service worker (optionally; for offline access). You can download the latest distribution files from gh-pages branch. If you are using Docker: put your dh.pem, cert.pem, key.pem to /etc/nginx/external/ run this script: docker run --name keeweb -d -p 443:443 -p 80:80 -v $EXT_DIR:/etc/nginx/external/ antelle/keeweb To make Dropbox work in your self-hosted app, go to this Wiki page. Building The easiest way to clone all KeeWeb repos is: curl https://raw.githubusercontent.com/keeweb/keeweb/develop/dev-env.sh | bash - The app can be built with grunt: grunt (html files will be in dist/). Desktop apps are built with grunt desktop. This requires some magic and currently works only on CI, you can find more details in the GitHub Actions workflow. To run the desktop (electron) app without building an installer, build the app with grunt and start it this way: npm run devnpm run electron For debug build: run npm run dev open http://localhost:8085 To build desktop apps, use these goals, the result can be found in tmp: npm run dev-desktop-macosnpm run dev-desktop-windowsnpm run dev-desktop-linux Contributing Please read contribution guidelines for pull requests. Here's a list of issues where your help would be very welcome. Also you can help by translating KeeWeb to your language. Other ways of contribution can be found on this page. Important notes for pull requests please branch from develop, not master don't edit translation files except base.json, they will be replaced Donations KeeWeb is not free to develop. It takes time, requires paid code signing certificates and domains. You can help the project or say "thank you" with this button: You can also sponsor the developer directly on GitHub. Please note: donation does not imply any type of service contract. Thank you Notable contributions to KeeWeb: Florian Reuschel (@Loilo): German translation Dennis Ploeger (@dploeger): auto-type improvements Hackmanit (hackmanit.de): penetration test Peter Bittner (@bittner): Wikipedia article Download Keeweb
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Windows Privilege Escalation: Boot Logon Autostart Execution (Startup Folder)

Windows Startup folder may be targeted by an attacker to escalate privileges or persistence attacks. Adding an application to a startup folder or referencing it using a Registry run key are two ways to do this. When a user signs in, the application linked will be executed if an item is in the "run keys" in the Registry or startup folder. These programs will be executed under the perspective of the user and will have the account's associated permissions level.

Table of Content· Enumerating Assign Premissions using Icacls Windows Startup Folder The Startup folder was a folder accessible from the Start Menu. Programs saved in this folder would start up immediately once users turned on their machine. There are two locations for the startup folder in windows. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUpo Run dialog box: Windows Key + R), type shell:common startupC:\Users\o Run dialog box: Windows Key + R), type shell: startupBoot | Logon Autostart Execution: Startup Folder Injecting a malicious program within a startup folder will also cause that program to execute when a user logs in, thus it may help an attacker to perform persistence or privilege escalation Attacks from misconfigured startup folder locations. Mitre ID:T1574.001Tactics:Privilege Escalation & PersistencePlatforms:WindowsPrerequisiteWindows 10Attacker Machine:Kali LinuxTools: AccessChk.exeCondition:Compromise the target machine with low privilege access either using Metasploit or Netcat, etc.Objective:Escalate the NT Authority /SYSTEM privileges for a low privileged user by exploiting the Misconfigured Startup folder.Lab SetupNote: Given steups will create a loophole through misconfigured startup folder, thus avoid such configuration in a production environment.C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp___________________________
@hacking_Attack
@Hacking_Video