Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hash cracking service for members /r/redteamsec
https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/

If you need a hash cracking service write to me. Here I have a sample of brute force cracking of an 11 character password for SHA256. It took 11 seconds. I have built computers for my own red teaming and pentesting. But sometimes computers don't work so I'm happy to help for money to crack your hash. ​ Maybe this will make your red teaming better. ​ https://preview.redd.it/ra2wbv44ajx71.png?width=1061&format=png&auto=webp&s=72a971b5456ca7f3f9ba6e8efff33ea6b61ec095 ​ My computers: 6 x GPU RX 6600 XT 10 x GPU RX 6600 XT I can crack bruteforce or on my or your dictionaries. We bill hourly for the number of GPUs. I suggest a price of $1 per GPU per hour of work. Discounts for larger orders. ​ If you order for example 10 hours and the password is broken after 2 hours I will return you money for not used time. ​ If you have any other idea then let me know. submitted by /u/blaszczakm (https://www.reddit.com/user/blaszczakm)
[link] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/) [comments] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy CampaignPost Views: 103
Reading Time: 1 Minute
A new version of a banking trojan known as Mekotio is being deployed in the wild, with malware analysts reporting that it’s using a new, stealthier infection flow.
The last notable activity of Mekotio dates back to the summer of 2020 when the trojan’s operators deployed it in a campaign targeting Latin American countries.

The targeting scope appears to be the same in recent attacks, with Spanish being the language of choice for the phishing emails that start the infection chain. A new attack flowThe infection begins with a phishing email bundling a ZIP attachment containing an obfuscated batch script that fetches and executes a PowerShell script.

Once the PowerShell script gets launched, it will download a second ZIP archive after some basic location and anti-analysis checks.

If the checks confirm the victim is in Latin America and the malware isn’t running on a virtual machine, the second ZIP, which contains the Mekotio payload in DLL form, is extracted.
https://www.bleepstatic.com/images/news/u/1220909/Security/attack%20flow.jpg
Same old code in new wrappingThe three novel elements that make the latest Mekotio version harder to detect are the following:

* A stealthier batch file with at least two layers of obfuscation
* New file-less PowerShell script that runs directly in memory
* Use of Themida v3 for packing the final DLL payload
See Also: All Windows versions impacted by new LPE zero-day vulnerability CheckPoint reports seeing approximately 100 attacks in the past three months deploying cipher substitution techniques, which albeit simple, help Mekotio go undetected by most AV products.

The second layer of obfuscation is slicing the PowerShell commands into parts saved in different environment variables and then concatenating the values during execution.
https://www.bleepstatic.com/images/news/u/1220909/Security/obfuscation.jpg
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy CampaignPost…
terized this particular trojan as “chaotic” last year due to the concurrent development that resulted in the simultaneous circulation of different variants.

That activity has now waned, and the most recent campaign uses the variant analyzed by CheckPoint.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/GitLab-90x90.jpg Over 30,000 GitLab servers still unpatched against critical bug1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-4-90x90.jpg Chaos ransomware targets gamers via fake Minecraft alt lists3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png All Windows versions impacted by new LPE zero-day vulnerability6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/social_preview-scaled-90x90.jpg Sensitive data of 400,000 German students exposed by API flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware2 weeks ago
The post Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
LDAPmonitor - Monitor Creation, Deletion And Changes To LDAP Objects Live During Your Pentest Or System Administration!
http://www.kitploit.com/2021/11/ldapmonitor-monitor-creation-deletion.html
Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object.
Features
Feature Python (.py) (https://github.com/p0dalirius/LDAPmonitor/blob/master/python) CSharp (.exe) (https://github.com/p0dalirius/LDAPmonitor/blob/master/csharp) Powershell (.ps1) (https://github.com/p0dalirius/LDAPmonitor/blob/master/powershell) LDAPS support ✔️ ✔️ ✔️ Random delay in seconds between queries ✔️ ✔️ ✔️ Custom delay in seconds between queries ✔️ ✔️ ✔️ Save output to logfile ✔️ ✔️ ✔️ Colored or not colored output with --no-colors ✔️ Custom page size for paged queries ✔️ ✔️ ✔️ Authenticate with user and password ✔️ ✔️ ✔️ Authenticate as current shell user ✔️ ✔️ Authenticate with LM:NT hashes ✔️ Authenticate with kerberos (https://www.kitploit.com/search/label/Kerberos) tickets ✔️ Option to ignore user logon events ✔️ ✔️ ✔️

Download LDAPmonitor (https://github.com/p0dalirius/LDAPmonitor)
hacking: security in practice
What is exactly is hackable from a shared public wifi?

I never use them because I'm paranoid about my data being intercepted/sensitive documents on my phone being lifted, my friend thinks I'm paranoid. Anyone can answer or point me in the direction of finding out what is hackable on a phone using public wifi?

submitted by /u/looseboy
[link] [comments]
hacking: security in practice
child hood

hi i used to play Roblox all the time when i was a kid, and i have forgotten the password for my old account. if anyone wants to help out it would be much appreciated

account name: AaronAJO

submitted by /u/AaronAJ0
[link] [comments]
Deep Web
Gore forum websites? I need help finding a video I saw a while back.

I need help finding a video I saw.

It was a video of a Mexican cartel (I think). They tied a guy down and started cutting their limbs with an axe. They started with the foot, then limbs, arm, etc, and so on.

That’s all I can remember.

If anyone can find it, it would be greatly appreciated.

Are there any forum links for gore that I can ask these things on?

submitted by /u/illustrator101
[link] [comments]
LDAPmonitor - Monitor Creation, Deletion And Changes To LDAP Objects Live During Your Pentest Or System Administration!

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object. Features Feature Python (.py) CSharp (.exe) Powershell (.ps1) LDAPS support ✔️ ✔️ ✔️ Random delay in seconds between queries ✔️ ✔️ ✔️ Custom delay in seconds between queries ✔️ ✔️ ✔️ Save output to logfile ✔️ ✔️ ✔️ Colored or not colored output with --no-colors ✔️ Custom page size for paged queries ✔️ ✔️ ✔️ Authenticate with user and password ✔️ ✔️ ✔️ Authenticate as current shell user ✔️ ✔️ Authenticate with LM:NT hashes ✔️ Authenticate with kerberos tickets ✔️ Option to ignore user logon events ✔️ ✔️ ✔️ Download LDAPmonitor
Read more...
Thorstarter запускает баг-баунти программу совместно с Immunefi

Это перевод данной статьиContinue reading on Medium »
Read more...