Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackers were able to exploit macOS zero-day to compromise Hong Kong Users.
https://cdn-images-1.medium.com/max/1500/1*pirF3S9u3AhzcBxEgwUV2w.jpeg
Google researchers announced on Thursday that they discovered a watering hole threat in late August that targeted Hong Kong websites…
Continue reading on Medium »
Hackers were able to exploit macOS zero-day to compromise Hong Kong Users.
https://cdn-images-1.medium.com/max/1500/1*pirF3S9u3AhzcBxEgwUV2w.jpeg
Google researchers announced on Thursday that they discovered a watering hole threat in late August that targeted Hong Kong websites…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cada segundo se cometen 14 ciberdelitos en el mundo: ONU
https://cdn-images-1.medium.com/max/1446/0*WxxxmOXSTHgJSWHE
PUBLICADO EN 12 NOVIEMBRE, 2021 POR EHACKING
Continue reading on Medium »
Cada segundo se cometen 14 ciberdelitos en el mundo: ONU
https://cdn-images-1.medium.com/max/1446/0*WxxxmOXSTHgJSWHE
PUBLICADO EN 12 NOVIEMBRE, 2021 POR EHACKING
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Anyone know a good alternative to vortexau/dnsvalidator?
Repo: https://github.com/vortexau/dnsvalidator
It a tool which takes a list of dnsserver & performs checks on them to determine whether they should be used as resolvers when enumerating subdomains.
There's a issue with this tool (https://github.com/vortexau/dnsvalidator/issues/27)
The internal list of valid resolvers is not being updated at the end of the run. It remains empty.
Also, there's a function\1]) which is supposed to write to output file immediately when a valid resolver is found - but it doesn't.
The maintainer hasn't updated the tool in 2 years ( since version 0.0.1 !!! ) & I'm really lazy so I don't want to spend hours troubleshooting the thing.
Anyone know a good alternative? I've already gone through all the forks to see if someone else's fixed the thing - but no dice. Couldn't find anything on Google either...
[1] dnsvalidatior.lib.core.output.OutputHelper.terminal()
submitted by /u/SexingSexySex
[link] [comments]
Anyone know a good alternative to vortexau/dnsvalidator?
Repo: https://github.com/vortexau/dnsvalidator
It a tool which takes a list of dnsserver & performs checks on them to determine whether they should be used as resolvers when enumerating subdomains.
There's a issue with this tool (https://github.com/vortexau/dnsvalidator/issues/27)
The internal list of valid resolvers is not being updated at the end of the run. It remains empty.
Also, there's a function\1]) which is supposed to write to output file immediately when a valid resolver is found - but it doesn't.
The maintainer hasn't updated the tool in 2 years ( since version 0.0.1 !!! ) & I'm really lazy so I don't want to spend hours troubleshooting the thing.
Anyone know a good alternative? I've already gone through all the forks to see if someone else's fixed the thing - but no dice. Couldn't find anything on Google either...
[1] dnsvalidatior.lib.core.output.OutputHelper.terminal()
submitted by /u/SexingSexySex
[link] [comments]
please help
https://www.reddit.com/r/Pentesting/comments/qt449h/please_help/
<!-- SC_OFF -->7a828bae0910102319b8162edff80a73 It's an md5 hash, hashcat isn't working for me right now and I don't have time to figure out why. please help <!-- SC_ON --> submitted by /u/SnoepieMeansTuckshop (https://www.reddit.com/user/SnoepieMeansTuckshop)
[link] (https://www.reddit.com/r/Pentesting/comments/qt449h/please_help/) [comments] (https://www.reddit.com/r/Pentesting/comments/qt449h/please_help/)
https://www.reddit.com/r/Pentesting/comments/qt449h/please_help/
<!-- SC_OFF -->7a828bae0910102319b8162edff80a73 It's an md5 hash, hashcat isn't working for me right now and I don't have time to figure out why. please help <!-- SC_ON --> submitted by /u/SnoepieMeansTuckshop (https://www.reddit.com/user/SnoepieMeansTuckshop)
[link] (https://www.reddit.com/r/Pentesting/comments/qt449h/please_help/) [comments] (https://www.reddit.com/r/Pentesting/comments/qt449h/please_help/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Metasploit ?
https://cdn-images-1.medium.com/max/600/1*9yKQg1sqE25ah2ivO5r_RA.jpeg
Metasploit is a pen testing framework which is used by both ethical hackers and malicious attackers to analyze vulnerabilities within a…
Continue reading on Techiepedia »
___________________________
@hacking_Attack
@Hacking_Video
What is Metasploit ?
https://cdn-images-1.medium.com/max/600/1*9yKQg1sqE25ah2ivO5r_RA.jpeg
Metasploit is a pen testing framework which is used by both ethical hackers and malicious attackers to analyze vulnerabilities within a…
Continue reading on Techiepedia »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Metasploit ?
Metasploit is a pen testing framework which is used by both ethical hackers and malicious attackers to analyze vulnerabilities within a…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A Vim/Neovim Plugin Ecosystem To Try
https://cdn-images-1.medium.com/max/700/0*CHmXK_5fwYlEP7RV.png
Let’s try out a new Vim/Neovim plugin ecosystem.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
A Vim/Neovim Plugin Ecosystem To Try
https://cdn-images-1.medium.com/max/700/0*CHmXK_5fwYlEP7RV.png
Let’s try out a new Vim/Neovim plugin ecosystem.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
A Vim/Neovim Plugin Ecosystem To Try
Let’s try out a new Vim/Neovim plugin ecosystem.
hacking: security in practice
What kind of services does ESXI SLP port advertise to locally connected hosts?
I got enthusiastic about the last exploitations of ESXI CVE-2021-21974 (heap overflow exploitation) and after researching the SLP service which is the weak point in this CVE I tried to turn it off, after which everything was working perfectly fine, so I had a logical question, what kind of services SLP port on ESXI advertises about?
submitted by /u/rubenamizyan
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
What kind of services does ESXI SLP port advertise to locally connected hosts?
I got enthusiastic about the last exploitations of ESXI CVE-2021-21974 (heap overflow exploitation) and after researching the SLP service which is the weak point in this CVE I tried to turn it off, after which everything was working perfectly fine, so I had a logical question, what kind of services SLP port on ESXI advertises about?
submitted by /u/rubenamizyan
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
What kind of services does ESXI SLP port advertise to locally...
I got enthusiastic about the last exploitations of ESXI CVE-2021-21974 (heap overflow exploitation) and after researching the SLP service which is...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Part 1 of Trying to Hack a Scammer
https://external-preview.redd.it/F6zApWHbpm1AP4jQTM-I3NrEhszQL8zEQ1yosjjuzXk.jpg?width=320&crop=smart&auto=webp&s=6bd80349141ffcfdb42d0c1f0d62dbe5e14811ad submitted by /u/Sina5105
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Part 1 of Trying to Hack a Scammer
https://external-preview.redd.it/F6zApWHbpm1AP4jQTM-I3NrEhszQL8zEQ1yosjjuzXk.jpg?width=320&crop=smart&auto=webp&s=6bd80349141ffcfdb42d0c1f0d62dbe5e14811ad submitted by /u/Sina5105
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Part 1 of Trying to Hack a Scammer
Posted in r/hacking by u/Sina5105 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Windows Privilege Escaslation: HiveNightmare
IntroductionCVE-2021-36934 also known as SeriousSAM and HiveNightmare vulnerability was discovered by Jonas Lykkegaard in July 2021. Due to an ACL misconfiguration in Windows 10 post build 1809 and Windows 11, non-admin users are granted read access to the holy trio of SAM, SYSTEM and SECURITY files under %windir%\system32\configdirectory. For this to be true, however, system protection has to be turned on and a volume shadow copy has to be created. The name ‘HiveNightmare’ is derived from a common name ‘hives’ which refers to the files that have registry data stored.Table of Contents· System protection and creating restore pointsSystem protection and creating restore pointsThis feature is available post Windows ME and XP, and allows a user to create backups, snapshots or restore points in their windows system. Should you feel the need to restore your windows to a previous point in time, you can do so. Microsoft mentions which files, settings and configurations are backed up here.Volume Shadow Copy: Post Windows 7 and Win Server 2003, a VSS (Volume Shadow Copy Service) accompanies users in their quest to properly create backups of their servers, shared folders, and restore points on local or remote systems is NTFS or ReFS is being used. In our case, volume shadow copy refers to a local restore point created by a user.net user administrator /active:yes system and security->system->system protection and configure___________________________
@hacking_Attack
@Hacking_Video
Windows Privilege Escaslation: HiveNightmare
IntroductionCVE-2021-36934 also known as SeriousSAM and HiveNightmare vulnerability was discovered by Jonas Lykkegaard in July 2021. Due to an ACL misconfiguration in Windows 10 post build 1809 and Windows 11, non-admin users are granted read access to the holy trio of SAM, SYSTEM and SECURITY files under %windir%\system32\configdirectory. For this to be true, however, system protection has to be turned on and a volume shadow copy has to be created. The name ‘HiveNightmare’ is derived from a common name ‘hives’ which refers to the files that have registry data stored.Table of Contents· System protection and creating restore pointsSystem protection and creating restore pointsThis feature is available post Windows ME and XP, and allows a user to create backups, snapshots or restore points in their windows system. Should you feel the need to restore your windows to a previous point in time, you can do so. Microsoft mentions which files, settings and configurations are backed up here.Volume Shadow Copy: Post Windows 7 and Win Server 2003, a VSS (Volume Shadow Copy Service) accompanies users in their quest to properly create backups of their servers, shared folders, and restore points on local or remote systems is NTFS or ReFS is being used. In our case, volume shadow copy refers to a local restore point created by a user.net user administrator /active:yes system and security->system->system protection and configure___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Windows Privilege Escaslation: HiveNightmare
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Windows Privilege Escaslation: HiveNightmare IntroductionCVE-2021-36934 also known as SeriousSAM and HiveNightmare vulnerability was discovered by Jonas Lykkegaard in July 2021. Due to an ACL misconfiguration in Windows…
4AFLQA4LCw=s16000 We’re good to go nowExploitation Method 1: HiveNightmare.exe (C++ exploit)Now, to exploit the vulnerability, Kevin Beaumont created a zero day (and PoC) for the same. This exploit looks for the shadow copy in the system and reads it for SAM, SYSTEM and SECURITY hives.Exploitation Method 2: serioussam.ps1 (Powershell exploit)The script created by romarroca can be found here. It is created in powershell and is more portable than the exe variant created by Kevin Beaumont. This copies the SAM and SYSTEM hives from the restore point dump created. Execution is fairly simple, just run the script like soExploitation Method 3: hive.exe (Go exploit)Christian Mehlmauer translated the same exploit in Go and created a ready to be executed exe file which can be found here. It dumps the holy trio in current directory simply by executing the exe file like soPrivilege EscalationTill now, we have obtained the SAM, SECURITY and SYSTEM hive dumps and now we will use these files to extract the hashes and conduct a pass the hash attack. First, we are using impacket toolkit’s secretsdump.py script to dump the hashes. Scenario is that the attacker (us) has successfully obtained hives from the victim’s machine.python3 secretsdump.py -sam /root/SAM -system /root/SAM -security /root/SAM LOCALhttps://blogger.googleusercontent.com/img/a/AVvXsEg6yNAp7IEy6IdySFU7qMk6WDwsOgJJ8I6uHbeLLLGqv062V1oxuMOJcwEEMVCHTKTNVp1PWEGKD3v7CcHqiQuSmd9mFdnF1jS_kmPHXww1tE341VWn4pcHK53tZUnYNEMavP1rura9VDZ87jU-sMdmg1lV8u5HtF-OnMO-M_fRfTR1Xbd-BwXgqD73tA=s16000 As you can see in the screenshot above, we have obtained the NTLM hash for the administrator’s account. Obviously, we knew the password in this case (1234) but ideally, the attacker now cracks this hash using John or other likes of hash cracking tools, or he conducts “pass the hash” attack.PassTheHash (PtH): In this type of attack, the attacker can bypass/flout with authentication mechanisms by providing the hash of a password rather than the password itself. This weakness is the most prevalent in Windows systems. At the time of login to a network service in Windows, the backend ultimately convers a plain text string into a hash and compares it with the existing hash in the database (hives); similarly, in PtH attack, the backend code, due to an in[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
4AFLQA4LCw=s16000 We’re good to go nowExploitation Method 1: HiveNightmare.exe (C++ exploit)Now, to exploit the vulnerability, Kevin Beaumont created a zero day (and PoC) for the same. This exploit looks for the shadow copy in the system and reads it for SAM…
herent weakness, gets fooled when a user enters the hash instead of the password string and allows authentication. Refer the guide here for an in-depth understanding of this attack.PsExec – In Windows, PsTools are used for a number of different process related functions like listing, logging, monitoring etc. PsExec is used to execute processes remotely. According to sysinternals (here), “PsExec's most powerful uses include launching interactive command-prompts on remote systems and remote-enabling tools like IpConfig that otherwise do not have the ability to show information about remote systems.”python3 psexec.py -hashes 00000000000000000000000000000000:7ce21f17c0aee7fb9ceba532d0546ad6 administrator@192.168.1.145https://blogger.googleusercontent.com/img/a/AVvXsEiFo_ZFCa4wPUJSRmoC88J5fnRrK1tjudybiM2ZfKBNg3QhT6GnPXyI_J1ClWma2vESKdUG7IEpzna-b60AvNNS9XedwH9j2YNF6Zb25AfWRArYABLajFQM4xty08uOTJlzgvGAQKyxzBxWrjXrKsqTvsOGX8ZQKlzlyXWW0EWmSJLE9gKow3Kk4AivAw=s16000 And it has worked its magic!Conclusion and MitigationThe ease of exploitation makes this vulnerability a critical threat to any organisation. Microsoft has released security patches for the same, however, one other workaround is to restrict access to the contents of %windir%\system32\configby typing the command in cmd prompt:icacls %windir%\system32\config\*.* /inheritance:eThanks for reading.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video