Keep in mind that exposing the host's network to docker can compromise the isolation between your container and the host. If you plan on using the player, X11 forwarding using an SSH connection would be a more secure way.
PyRDP Lore
Introduction blog post (https://www.gosecure.net/blog/2018/12/19/rdp-man-in-the-middle-smile-youre-on-camera) in which we demonstrated that we can catch a real threat actor in action (https://www.youtube.com/watch?v=eB7RC9FmL6Q) Talk at NorthSec 2019 (https://docs.google.com/presentation/d/1avcn8Sh2b3IE7AA0G9l7Cj5F1pxqizUm98IbXUo2cvY/edit#slide=id.g404b70030f_0_581) where two demos were performed: First demo (https://youtu.be/5JztJzi-m48): credential logging, clipboard stealing, client-side file browsing and a session take-over Second demo (https://youtu.be/bU67tj1RkMA): the execution of cmd or powershell payloads when a client successfully authenticates PyRDP Logo (https://github.com/GoSecure/pyrdp/blob/master/docs/pyrdp-logo.png) licensed under CC-BY-SA 4.0. BlackHat USA Arsenal 2019 Slides (https://docs.google.com/presentation/d/17P_l2n-hgCehQ5eTWilru4IXXHnGIRTj4ftoW4BiX5A/edit?usp=sharing) DerbyCon 2019 Slides (https://docs.google.com/presentation/d/1UAiN2EZwDcmBjLe_t5HXB0LzbNclU3nnigC-XM4neIU/edit?usp=sharing) (Video (https://www.youtube.com/watch?v=zgt3N6Nrnss)) Blog: PyRDP on Autopilot (https://www.gosecure.net/blog/2020/02/26/pyrdp-on-autopilot-unattended-credential-harvesting-and-client-side-file-stealing/)
Contributing to PyRDP
See our contribution guidelines (https://github.com/GoSecure/pyrdp/blob/master/CONTRIBUTING.md).
Acknowledgements
PyRDP uses code from the following open-source software: RC4-Python (https://github.com/bozhu/RC4-Python) for the RC4 implementation. rdesktop (https://github.com/rdesktop/rdesktop) for bitmap decompression. rdpy (https://github.com/citronneur/rdpy) for RC4 keys, the bitmap decompression bindings and the base GUI code for the PyRDP player. FreeRDP (https://github.com/FreeRDP/FreeRDP) for the scan code enumeration.
Download Pyrdp (https://github.com/GoSecure/pyrdp)
PyRDP Lore
Introduction blog post (https://www.gosecure.net/blog/2018/12/19/rdp-man-in-the-middle-smile-youre-on-camera) in which we demonstrated that we can catch a real threat actor in action (https://www.youtube.com/watch?v=eB7RC9FmL6Q) Talk at NorthSec 2019 (https://docs.google.com/presentation/d/1avcn8Sh2b3IE7AA0G9l7Cj5F1pxqizUm98IbXUo2cvY/edit#slide=id.g404b70030f_0_581) where two demos were performed: First demo (https://youtu.be/5JztJzi-m48): credential logging, clipboard stealing, client-side file browsing and a session take-over Second demo (https://youtu.be/bU67tj1RkMA): the execution of cmd or powershell payloads when a client successfully authenticates PyRDP Logo (https://github.com/GoSecure/pyrdp/blob/master/docs/pyrdp-logo.png) licensed under CC-BY-SA 4.0. BlackHat USA Arsenal 2019 Slides (https://docs.google.com/presentation/d/17P_l2n-hgCehQ5eTWilru4IXXHnGIRTj4ftoW4BiX5A/edit?usp=sharing) DerbyCon 2019 Slides (https://docs.google.com/presentation/d/1UAiN2EZwDcmBjLe_t5HXB0LzbNclU3nnigC-XM4neIU/edit?usp=sharing) (Video (https://www.youtube.com/watch?v=zgt3N6Nrnss)) Blog: PyRDP on Autopilot (https://www.gosecure.net/blog/2020/02/26/pyrdp-on-autopilot-unattended-credential-harvesting-and-client-side-file-stealing/)
Contributing to PyRDP
See our contribution guidelines (https://github.com/GoSecure/pyrdp/blob/master/CONTRIBUTING.md).
Acknowledgements
PyRDP uses code from the following open-source software: RC4-Python (https://github.com/bozhu/RC4-Python) for the RC4 implementation. rdesktop (https://github.com/rdesktop/rdesktop) for bitmap decompression. rdpy (https://github.com/citronneur/rdpy) for RC4 keys, the bitmap decompression bindings and the base GUI code for the PyRDP player. FreeRDP (https://github.com/FreeRDP/FreeRDP) for the scan code enumeration.
Download Pyrdp (https://github.com/GoSecure/pyrdp)
Do not make this mistake when it comes to passive information gathering
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Do not make this mistake when it comes to passive information gathering
https://thexssrat.medium.com/do-not-make-this-mistake-when-it-comes-to-passive-information-gathering-c85ffef69fac?source=rss------bug_bounty-5
https://thexssrat.medium.com/do-not-make-this-mistake-when-it-comes-to-passive-information-gathering-c85ffef69fac?source=rss------bug_bounty-5
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Are uni courses worth it?
I want to do cybersecurity for my career and was wondering if university is worth it or if I could just learn what they teach there on an online course?
submitted by /u/wengsweat
[link] [comments]
Are uni courses worth it?
I want to do cybersecurity for my career and was wondering if university is worth it or if I could just learn what they teach there on an online course?
submitted by /u/wengsweat
[link] [comments]
reddit
Are uni courses worth it?
I want to do cybersecurity for my career and was wondering if university is worth it or if I could just learn what they teach there on an online...
hacking: security in practice
From the hacker point of view what’s the best car?
I’m wonder what a hacker would suggest as the most reliable, practical, useful car: New and used?
Thanks in advance.
submitted by /u/Digital-Wave
[link] [comments]
From the hacker point of view what’s the best car?
I’m wonder what a hacker would suggest as the most reliable, practical, useful car: New and used?
Thanks in advance.
submitted by /u/Digital-Wave
[link] [comments]
reddit
From the hacker point of view what’s the best car?
I’m wonder what a hacker would suggest as the most reliable, practical, useful car: New and used? Thanks in advance.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Walking An Application[TryHackme + Intro To Web Hacking]
https://cdn-images-1.medium.com/max/600/1*kuXooUVn-50NkSQpRAx_pw.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
Walking An Application[TryHackme + Intro To Web Hacking]
https://cdn-images-1.medium.com/max/600/1*kuXooUVn-50NkSQpRAx_pw.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Content Discovery [TryHackme+Intro To Web Hacking]
https://cdn-images-1.medium.com/max/600/1*ezg4L2ZIA_1E73GEyuqRIA.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
Content Discovery [TryHackme+Intro To Web Hacking]
https://cdn-images-1.medium.com/max/600/1*ezg4L2ZIA_1E73GEyuqRIA.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CVE-2021–40290
https://cdn-images-1.medium.com/max/750/0*nI_MUEQP4-Jgr0KI
In this blog post, I’ll share the recent vulnerability I found in a CMS, how I found it and a POC exploit.
Continue reading on Medium »
CVE-2021–40290
https://cdn-images-1.medium.com/max/750/0*nI_MUEQP4-Jgr0KI
In this blog post, I’ll share the recent vulnerability I found in a CMS, how I found it and a POC exploit.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El FBI, la NSA y CISA explican cómo evitar este peligroso ransomware
https://cdn-images-1.medium.com/max/1518/0*z6YZ7LMfeD2JKeQd
PUBLICADO EN 1 NOVIEMBRE, 2021POR EHACKING
Continue reading on Medium »
El FBI, la NSA y CISA explican cómo evitar este peligroso ransomware
https://cdn-images-1.medium.com/max/1518/0*z6YZ7LMfeD2JKeQd
PUBLICADO EN 1 NOVIEMBRE, 2021POR EHACKING
Continue reading on Medium »