Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Nosferatu - Lsass NTLM Authentication Backdoor

Lsass NTLM Authentication BackdoorHow it WorksFirst, the DLL is injected into the lsass.exe process, and will begin hooking authentication WinAPI calls. The targeted function is MsvpPasswordValidate(), located in NtlmShared.dll. In the pursuit of not being detected, the hooked function will call the original function and allow for the normal flow of authentication. Only after seeing that authentication has failed will the hook swap out the actual NTLM hash with the backdoor hash for comparison.UsageNosferatu must be compiled as a 64 bit DLL. It must be injected using the a DLL Injector with SeDebugPrivilege.You can see it loaded using Procexp: Login example using Impacket:LimitationsIn an Active Directory environment, authentication via RDP, runas, or the lock screen does not work with the nosferatu password. Authentication using SMB, WinRM, and WMI is still possible.In a non-AD environment, authentication works for all aspects.Download Nosferatu
Read more...
Dark Reading: Attacks/Breaches
US Banks Will Be Required to Report Cyberattacks Within 36 Hours

There is currently no specific time frame during which banks must report to federal regulators that a security incident had occurred. A new notification rules changes that to 36 hours.
2FA Bypass Methodologies

Hello folks!! Hope you are doing good… I’m back with another blog after a long time… pretty long time tbh. For all the beginners who are…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Would anyone be interested in joining a small community of makers?

Hi All,

I have started a small community to bring all kinds of makers together and I was wondering whether anyone here would be interested to join? I think a combination of developers, designers and marketing people would be awesome so I'm hoping to get that going xD

https://discord.gg/ncRsYT33uG

submitted by /u/MCtoUMD
[link] [comments]
hacking: security in practice
Turning Windows Defender off in cmd = Trojan???

Hello, I have recently grown interested in pen testing and have been using my laptop as a victim for my rubber ducky scripts. However, any time I try and turn off windows defender via command line, whether through a ducky payload or myself, windows defender detects it as a Trojan. I'd like to infect my laptop with my ransomware with my rubber ducky, but cannot seem to get around this. Any ideas?

submitted by /u/Gravy69420
[link] [comments]
A collection of keys I've acquired over the years as a telecom guy and a couple I recently got from ebay. Also, no I don't reprogram the magstripe on the old hotel keycard...I just use it to slip door latches and punch ethernet cable into cat5e/cat6 jacks instead of chewing up my own bank/ID cards
https://www.reddit.com/r/Pentesting/comments/qxyozq/a_collection_of_keys_ive_acquired_over_the_years/
Help pls
https://www.reddit.com/r/Pentesting/comments/qy2onx/help_pls/

<!-- SC_OFF -->I am Moroccan and I live in Morocco can i work remotely with US company without visa and do my salary have change because i live in morocco ? <!-- SC_ON --> submitted by /u/fenixnni (https://www.reddit.com/user/fenixnni)
[link] (https://www.reddit.com/r/Pentesting/comments/qy2onx/help_pls/) [comments] (https://www.reddit.com/r/Pentesting/comments/qy2onx/help_pls/)
( $1000 ) Insecure direct Object References (IDOR) Via TakeOver Unsubscribe Feature

Assalamualaikum Bug Hunter & Hi everyone.Continue reading on Medium »
Read more...