Hacking Articles Tips Tricks Videos Tutorials
466 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
ADenum - A Pentesting Tool That Allows To Find Misconfiguration Through The The Protocol LDAP And Exploit Some Of Those Weaknesses With Kerberos

https://blogger.googleusercontent.com/img/a/AVvXsEhTiJ8aPNkJFJDlwiC_9agfcKhcNMWHPT6f3OuxNNDFzNjcuEwtNDb4OsWbpl21-F0ztOGoAQJrp0kEdRmjkmHF17rNsIwo1HxsZaclyMYjD7YwJacVP9v_gRFSrOwmLTUyvo3nztQa-ERh2fiKtU6dio5S1bfdYoBhFEAPyPQZVRv6RHvtwX59nTgAjQ=w640-h592 AD Enum is a pentesting tool that allows to find misconfiguration through the protocol LDAP and exploit some of those weaknesses with Kerberos.
cracking (john) -jp [path] John binary path -w [wordList] The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -v, --version Show program's version number and exit -s Use LDAP with SSL ">█████╗ ██████╗ ███████╗███╗ ██╗██╗ ██╗███╗ ███╗
██╔══██╗██╔══██╗ ██╔════╝████╗ ██║██║ ██║████╗ ████║
███████║██║ ██║ █████╗ ██╔██╗ ██║██║ ██║██╔███ ╔██║
██╔══██║██║ ██║ ██╔══╝ ██║╚██╗██║██║ ██║██║╚██╔╝██║
██║ ██║██████╔╝ ███████╗██║ ╚████║╚██████╔╝██║ ╚═╝ ██║
╚═╝ ╚═╝╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝
usage: ADenum.py -d [domain] -u [username] -p [password]

Pentest tool that detect misconfig in AD with LDAP

optional arguments:
-h, --help show this help message and exit
-d [domain] The name of domain (e.g. "test.local")
-u [username] The user name
-p [password] The user password
-ip [ipAddress] The IP address of the server (e.g. "1.1.1.1")
-j Enable hash cracking (john)
-jp [path] John binary path
-w [wordList] The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt
-v, --version Show program's version number and exit
-s Use LDAP with SSL
Requirement* Impacket (https://github.com/SecureAuthCorp/impacket)
* John (https://github.com/openwall/john)
* Python 3
* If you are using debian or kali: $ sudo apt-get install libsasl2-dev python-dev libldap2-dev libssl-dev* pip3: $ pip3 install -r Requirements.txtFeatures and FunctionalityLDAP:* Enum Domain Admin users
* Enum Domain Controllers
* Enum Domain users with Password Not Expire
* Enum Domain users with old password
* Enum Domain users with interesting description
* Enum Domain users with not the default encryption
* Enum Domain users with Protecting Privileged Domain Accounts Kerberos:* AS-REP Roastable
* Kerberoastable
* Password cracking with john (krb5tgs and krb5asrep) Demohttps://camo.githubusercontent.com/d8a9ab9b9eb4bc9e9761fcc378ab58c365a198fed8dad2728688ed10a91c1815/68747470733a2f2f61736369696e656d612e6f72672f612f3336323031372e737667 Microsoft Advanced Threat AnalyticsATA detects two suspicious events but does not trigger an alert:

* The connection with the protocol LDAP without SSL
* The Kerberoastable attack

As shown in this screenshot: http://1.bp.blogspot.com/-yKIeO2cppno/YZ3Se4tWywI/AAAAAAAA4KQ/57jRZRJfkp4NoIEJnwTi7Oa4LksEmO6TACK4BGAYYCw/s320/ADenum_2_ATAdetection-777808.png SourceDocumentation:

* https://labs.f-secure.com/blog/attack-detection-fundamentals-discovery-and-lateral-movement-lab-1/
* https://theitbros.com/ldap-query-examples-active-directory/
* https://docs.microsoft.com/en-us/advanced-threat-analytics/what-is-ata

Impacket:

* https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py
* https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py Legal Disclaimer:testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers [...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! ADenum - A Pentesting Tool That Allows To Find Misconfiguration Through The The Protocol LDAP And Exploit Some Of Those Weaknesses With Kerberos https://blogger.googleusercontent.com/img/a/AVvXsEhTiJ8aPNkJFJDlwiC_9agfcKhcNMWHPT6…
assume no liability and are not responsible for any misuse or damage caused by this program. ">This project is made for educational and ethical testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal.
It is the end user's responsibility to obey all applicable local, state and federal laws.
Developers assume no liability and are not responsible for any misuse or damage caused by this program.
Download ADenum

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
PC requirements for hacking?

Hello there, These are my PC specs:
.6GB RAM
.256GB SSD and 1TB HDD
.Intel i-5;10th gen
.Windows 10
Can I get into (DECENT)hacking/coding with these features or should i wait for few years and buy a better PC.

submitted by /u/19yroldman
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video