Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
https://external-preview.redd.it/FcLRtlzqnFl1tHrCDeMa3KMpr_1TusB3Y56yxAxOMQs.jpg?width=640&crop=smart&auto=webp&s=a07ccd315cc59b8d52d064538fcb1f0b9d8ac4db According to https://github.com/blackc03r/OSCP-Cheatsheets/blob/master/offensive-security/credential-access-and-credential-dumping/dumping-and-cracking-mscash-cached-domain-credentials.md, Domain Credentials Cached can be found at HKEY_LOCAL_MACHINE\SECURITY.

It should looks like this

NL$1..10 are the cached hashes for 10 previously logged users

However, when I checked one my client's pc HKEY_LOCAL_MACHINE\SECURITY was empty.

Then, I perform reg query hklm\security but was denied even with Administrator's cmd
c:\> reg query hklm\security ERROR: Access is denied.
https://preview.redd.it/8dih64aq8l581.png?width=820&format=png&auto=webp&s=395e3f482690e5a01149ce49cede1293b546e6cd

What's wrong? Is it possible to view NL$1..10 and it's data/value in this case?

submitted by /u/w0lfcat
[link] [comments]
hacking: security in practice
Would you consider exploiting flaws in systems “hacking”?

Saw a recent article about how some people were abusing instagrams flawed reporting system to ban innocent accounts and was thinking that it’s pretty cool that they were able to do that.. with things like this would they even count as hacking? Would there be legal repercussions for exploiting flaws and not for monetary gain such as this

submitted by /u/juliusseizures9000
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Microsoft Patches Zero-Day Spreading Emotet Malware

The December rollout includes 67 security patches and addresses one zero-day and five more publicly known vulnerabilities.
Dark Reading: Attacks/Breaches
Attackers Target Log4J to Drop Ransomware, Web Shells, Backdoors

Amid the increase in Log4J attack activity, at least one Iranian state-backed threat group is preparing to target the vulnerability, experts say.
Dark Reading: Attacks/Breaches
Cisco's Ash Devata on Securing the Hybrid Workforce With Zero Trust

Hybrid work is here to stay, and organizations can apply zero trust's three core principles to ensure a secure workforce, Devata says.