Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
YIN Finance and Immunefi Reach Strategy Partnership to Strengthen the Security of YIN’s Liquidity…

As part of the team at YIN Finance, we are excited to announce our strategic partnership with Immunefi. With both of us being core players…Continue reading on Medium »
Read more...
How i was able to bypass Cloudflare WAF for SQLi payload

Bypassing Cloudflare for achieving SQL Injection
Read more...
hacking: security in practice
Revenge! Sorta….

I want to know if possible to get back at the person who stole me Xbox live username. It’s my original username I made when the 360 first came out in 2005. So it’s almost been 20 years with this name and I’m not sure Microsoft is going to help or not. I have this persons email and that’s it. I have no clue how or why my profile was even targeted. If I’m SOL then so be it I figure this is the best place to turn for answers and I appreciate any answer truly.

submitted by /u/etpmane
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Disrupting an Application’s Registration Process in 10 mins

So as usual this writeup will be divided into three sectionsContinue reading on InfoSec Write-ups »
Read more...
ADenum - A Pentesting Tool That Allows To Find Misconfiguration Through The The Protocol LDAP And Exploit Some Of Those Weaknesses With Kerberos

AD Enum is a pentesting tool that allows to find misconfiguration through the protocol LDAP and exploit some of those weaknesses with Kerberos. cracking (john) -jp path John binary path -w wordList The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -v, --version Show program's version number and exit -s Use LDAP with SSL "> █████╗ ██████╗ ███████╗███╗ ██╗██╗ ██╗███╗ ███╗ ██╔══██╗██╔══██╗ ██╔════╝████╗ ██║██║ ██║████╗ ████║ ███████║██║ ██║ █████╗ ██╔██╗ ██║██║ ██║██╔███ ╔██║ ██╔══██║██║ ██║ ██╔══╝ ██║╚██╗██║██║ ██║██║╚██╔╝██║ ██║ ██║██████╔╝ ███████╗██║ ╚████║╚██████╔╝██║ ╚═╝ ██║ ╚═╝ ╚═╝╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝usage: ADenum.py -d domain -u username -p passwordPentest tool that detect misconfig in AD with LDAPoptional arguments: -h, --help show this help message and exit -d domain The name of domain (e.g. "test.local") -u username The user name -p password The user password -ip ipAddress The IP address of the server (e.g. "1.1.1.1") -j Enable hash cracking (john) -jp path John binary path -w wordList The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -v, --version Show program's version number and exit -s Use LDAP with SSL Requirement Impacket (https://github.com/SecureAuthCorp/impacket) John (https://github.com/openwall/john) Python 3 If you are using debian or kali: $ sudo apt-get install libsasl2-dev python-dev libldap2-dev libssl-dev pip3: $ pip3 install -r Requirements.txt Features and Functionality LDAP: Enum Domain Admin users Enum Domain Controllers Enum Domain users with Password Not Expire Enum Domain users with old password Enum Domain users with interesting description Enum Domain users with not the default encryption Enum Domain users with Protecting Privileged Domain Accounts Kerberos: AS-REP Roastable Kerberoastable Password cracking with john (krb5tgs and krb5asrep) Demo Microsoft Advanced Threat Analytics ATA detects two suspicious events but does not trigger an alert: The connection with the protocol LDAP without SSL The Kerberoastable attack As shown in this screenshot: Source Documentation: https://labs.f-secure.com/blog/attack-detection-fundamentals-discovery-and-lateral-movement-lab-1/ https://theitbros.com/ldap-query-examples-active-directory/ https://docs.microsoft.com/en-us/advanced-threat-analytics/what-is-ata Impacket: https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py Legal Disclaimer: testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. ">This project is made for educational and ethical testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Download ADenum
Read more...

___________________________
@hacking_Attack
@Hacking_Video