How to exploit Log4j vulnerabilities in VMWare…
https://www.reddit.com/r/redteamsec/comments/rntse0/how_to_exploit_log4j_vulnerabilities_in_vmware/
submitted by /u/digicat (https://www.reddit.com/user/digicat)
[link] (https://www.sprocketsecurity.com/blog/how-to-exploit-log4j-vulnerabilities-in-vmware-vcenter) [comments] (https://www.reddit.com/r/redteamsec/comments/rntse0/how_to_exploit_log4j_vulnerabilities_in_vmware/)
https://www.reddit.com/r/redteamsec/comments/rntse0/how_to_exploit_log4j_vulnerabilities_in_vmware/
submitted by /u/digicat (https://www.reddit.com/user/digicat)
[link] (https://www.sprocketsecurity.com/blog/how-to-exploit-log4j-vulnerabilities-in-vmware-vcenter) [comments] (https://www.reddit.com/r/redteamsec/comments/rntse0/how_to_exploit_log4j_vulnerabilities_in_vmware/)
hacking: security in practice
Who wants to join a gc so we can learn to hack
I know a bit of python and what not nothing about linux i was windering if anyone with experience would mind joining a gc with me and anyone else who wants to so we can learn together anything from coding to hacking would be very appreciated
submitted by /u/Virtual_Stuff4719
[link] [comments]
Who wants to join a gc so we can learn to hack
I know a bit of python and what not nothing about linux i was windering if anyone with experience would mind joining a gc with me and anyone else who wants to so we can learn together anything from coding to hacking would be very appreciated
submitted by /u/Virtual_Stuff4719
[link] [comments]
reddit
Who wants to join a gc so we can learn to hack
I know a bit of python and what not nothing about linux i was windering if anyone with experience would mind joining a gc with me and anyone else...
hacking: security in practice
Trying to uncover what private account has been furiously quote tweeting me for the last week
I've googled this pretty extensively and cant find any solutions. All I need to know is the name of the account, dont really care to read the actual tweets. I do have a lead if that helps. Thanks in advance.
submitted by /u/hyundaithumbdrive
[link] [comments]
Trying to uncover what private account has been furiously quote tweeting me for the last week
I've googled this pretty extensively and cant find any solutions. All I need to know is the name of the account, dont really care to read the actual tweets. I do have a lead if that helps. Thanks in advance.
submitted by /u/hyundaithumbdrive
[link] [comments]
reddit
Trying to uncover what private account has been furiously quote...
I've googled this pretty extensively and cant find any solutions. All I need to know is the name of the account, dont really care to read the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spray365 - Makes Spraying Microsoft Accounts (Office 365 / Azure AD) Easy Through Its Customizable Two-Step Password Spraying Approach
https://blogger.googleusercontent.com/img/a/AVvXsEhR2hX7ULXZuPE_rOIE0OCAI4XoX2gFGm88EjGi5NBcgZ-kncODT8nZdT8zpBVutamO7t_hA75jayUUPmWQ186hXrgtMSTRn5Ag9drbLxAlabyxTjuYi50RGGVphP2fRw-Sjw1Eo6nJTIU6c0b33Ywh7cxGKRq25stJzMGxX80yJnQM88xearIKE6zKxQ=w640-h204 Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). How is Spray365 different from the many other password spraying tools that are already available? Spray365 enables passwords to be sprayed from an "execution plan". While having a pre-generated execution plan that describe the spraying operation well before it occurs has many other benefits that Spray365 leverages, this also allows password sprays to be resumed (
Spray365 exposes a few options that are useful when spraying credentials. Random user agents can be used to detect and bypass insecure conditional access policies that are configured to limit the types of allowed devices. Similarly, the
Spray365 - Makes Spraying Microsoft Accounts (Office 365 / Azure AD) Easy Through Its Customizable Two-Step Password Spraying Approach
https://blogger.googleusercontent.com/img/a/AVvXsEhR2hX7ULXZuPE_rOIE0OCAI4XoX2gFGm88EjGi5NBcgZ-kncODT8nZdT8zpBVutamO7t_hA75jayUUPmWQ186hXrgtMSTRn5Ag9drbLxAlabyxTjuYi50RGGVphP2fRw-Sjw1Eo6nJTIU6c0b33Ywh7cxGKRq25stJzMGxX80yJnQM88xearIKE6zKxQ=w640-h204 Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). How is Spray365 different from the many other password spraying tools that are already available? Spray365 enables passwords to be sprayed from an "execution plan". While having a pre-generated execution plan that describe the spraying operation well before it occurs has many other benefits that Spray365 leverages, this also allows password sprays to be resumed (
-R option) after a network error or other interruption. While it is easiest to generate a Spray365 execution plan using Spray365 directly, other tools that produce a compatible JSON structure make it easy to build unique password spraying workflows.Spray365 exposes a few options that are useful when spraying credentials. Random user agents can be used to detect and bypass insecure conditional access policies that are configured to limit the types of allowed devices. Similarly, the
--shuffle_auth_orderargument is a great way to spray credentials in a less-predictable manner. This option was added in an attempt to bypass intelligent account lockouts (e.g., Azure Smart Lockout). While it’s not perfect, randomizing the order in which credentials are attempted have other benefits too, like making the detection of these spraying operations even more difficult. Spray365 also supports proxying traffic over HTTP/HTTPS, which integrates well with other tools like Burp Suite for manipulating the source of the spraying operation. Generating an Execution Plan (Step 1)https://blogger.googleusercontent.com/img/a/AVvXsEhR2hX7ULXZuPE_rOIE0OCAI4XoX2gFGm88EjGi5NBcgZ-kncODT8nZdT8zpBVutamO7t_hA75jayUUPmWQ186hXrgtMSTRn5Ag9drbLxAlabyxTjuYi50RGGVphP2fRw-Sjw1Eo6nJTIU6c0b33Ywh7cxGKRq25stJzMGxX80yJnQM88xearIKE6zKxQ=w640-h204 Spraying Credentials with an Execution Plan (Step 2)https://blogger.googleusercontent.com/img/a/AVvXsEjQfGpo2KIx5Hrjfxgjo8hz0hZJsY950Ve6Y0mOkNr4d8JW4OhG7zudKlPz6qnHbOsswGJwbZiyD1L8xO9S2AKkuL1wiqrQiOwr0IIlJpQUyFzfRYg-l9KDBIxzoftjdmZ3N-NAgLxpuWR3qYmW7AY5nnzHGODXNutnQXRWx80-u1TBdmrytpEnVrzdMw=w640-h210 Getting StartedInstallationClone the repository, install the required Python packages, and run Spray365! $ git clone https://github.com/MarkoH17/Spray365
$ cd Spray365
~/Spray365$ pip3 install -r requirements.txt
~/Spray365$ python3 spray365.pyUsageGenerate an Execution PlanAn execution plan is needed to spray credentials, so we need to create one! Spray365 can generate its own execution plan by running it in "generate" (-g) mode. $ python3 spray365.py -g <path_for_saved_execution_plan-d <domain_name-u <file_containing_usernames-pf <file_containing_passwordse.g. $ python3 spray365.py -g ex-plan.s365 -d example.com -u usernames -pf passwordsSpraying an Execution PlanOnce an execution plan is available, Spray365 can be used to process it. Running Spray365 in "spray" (-s) mode will process the specified execution plan and spray the appropriate credentials. $ python3 spray365.py -s <path_to_execution_plane.g. $ python3 spray365.py -s ex-plan.s365Other Options for Advanced UsageGenerate Mode Options--delay <int: Delay in seconds to wait between authentication attempts (default: 30) -cID / --aad_client <string: Client ID to use during [...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Spray365 - Makes Spraying Microsoft Accounts (Office 365 / Azure AD) Easy Through Its Customizable Two-Step Password Spraying Approach https://blogger.googleusercontent.com/img/a/AVvXsEhR2hX7ULXZuPE_rOIE0OCAI4XoX2gFGm88EjGi5NBcgZ…
authentication workflow (None for random selection, specify multiple in a comma-separated string) (default: None)
-eID / --aad_endpoint <string: Endpoint ID to use during authentication workflow (None for random selection, specify multiple in a comma-separated string) (default: None) -S / --shuffle_auth_order: Shuffle order of authentication attempts so that each iteration (User1:Pass1, User2:Pass1, User3:Pass1) will be sprayed in a random order, and with a random arrangement of passwords, e.g. (User4:Pass16, User13:Pass25, User19:Pass40). Be aware this option introduces the possibility that the time between consecutive authentication attempts for a given user may occur as quickly as DELAYseconds apart. Consider using the -mD / --min_cred_loop_delayoption to enforce a minimum delay between authentication attempts for any given user. (default: False) -SO / --shuffle_optimization_attempts <int: Number of random execution plans to generate for identifying the fastest execution plan (default: 10) -mD / --min_cred_loop_delay <int: Minimum time to wait between authentication attempts for a given user. This option takes into account the time one spray iteration will take, so a pre-authentication delay may not occur every time (disable with 0) (default: 0) -cUA / --custom_user_agent <string: Set custom user agent for authentication requests (default: None) -rUA, --random_user_agent: Randomize user agent for authentication requests (default: False) Spray Mode Options--lockout <int: Number of account lockouts to observe before aborting spraying session (disable with 0) (default: 5) --proxy <string: HTTP Proxy URL (format: http[s]://proxy.address:port) (default: None) -R / --resume_index <int: Resume spraying passwords from this position in the execution plan (default: 0) AcknowledgementsAuthorTool / OtherLink@__TexasRangermsspray: Conduct password spray attacks against Azure AD as well as validate the implementation of MFA on Azure and Office 365 endpointshttps://github.com/SecurityRiskAdvisors/msspray DisclaimerUsage of this software for attacking targets without prior mutual consent is illegal. It is the end user’s responsibility to obey all applicable local, state and federal laws, in addition to any applicable acceptable use policies. Using this software releases the author(s) of any responsiblity for misuse or damage caused. Download Spray365
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TomGhost — TryHackMe Challenge
https://cdn-images-1.medium.com/max/1606/1*x9Qx9m6I3bFEkKIj88lJsw.png
TL;DR: This machine teaches exploitation of CVE-2020–1938, a serious vulnerability in Tomcat that takes advantage of a flat in AJP…
Continue reading on Medium »
TomGhost — TryHackMe Challenge
https://cdn-images-1.medium.com/max/1606/1*x9Qx9m6I3bFEkKIj88lJsw.png
TL;DR: This machine teaches exploitation of CVE-2020–1938, a serious vulnerability in Tomcat that takes advantage of a flat in AJP…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Networking? Try Hack Me -CTF
https://cdn-images-1.medium.com/max/909/1*MSKctMWDGlBwjLyhUkgCUQ.jpeg
So, let’s solve What is Networking room. Let’s go!
Continue reading on Medium »
What is Networking? Try Hack Me -CTF
https://cdn-images-1.medium.com/max/909/1*MSKctMWDGlBwjLyhUkgCUQ.jpeg
So, let’s solve What is Networking room. Let’s go!
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Apache Log4j Vulnerability
https://cdn-images-1.medium.com/max/1920/1*Ls5dBsbdH1mC6eO-SiI6Xw.jpeg
If you are remotely related to or interested in Cyber security, Software engineering or IT you must have recently heard the buzz words i.e…
Continue reading on Medium »
Apache Log4j Vulnerability
https://cdn-images-1.medium.com/max/1920/1*Ls5dBsbdH1mC6eO-SiI6Xw.jpeg
If you are remotely related to or interested in Cyber security, Software engineering or IT you must have recently heard the buzz words i.e…
Continue reading on Medium »
hacking: security in practice
Ratted but no trace?
Hi Today my pc got infected with something. I was watching Netflix and a window popped up and said:“ratted by coazy“. I didn’t think anything about this, but some seconds later I heard sounds not coming from Netflix. Over time they increased and after like 2 minutes my browser was closed and multiple popups showed up and said: „ ratted by coazy“. Seconds later a Jeff the killer image was shown full screen and screams were played. I immediately shut down my pc and booted my Kaspersky cd and did a full scan, but it did not find anything. I started my pc again and checked with malewarebytes, this time it found a folder for RiskWare.KeyLogger in c:\ProgramData\BFKData. I have no idea what BFKData is and how I got ratted without Kaspersky finding anything. Please help me.
submitted by /u/Hallolollmao
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Ratted but no trace?
Hi Today my pc got infected with something. I was watching Netflix and a window popped up and said:“ratted by coazy“. I didn’t think anything about this, but some seconds later I heard sounds not coming from Netflix. Over time they increased and after like 2 minutes my browser was closed and multiple popups showed up and said: „ ratted by coazy“. Seconds later a Jeff the killer image was shown full screen and screams were played. I immediately shut down my pc and booted my Kaspersky cd and did a full scan, but it did not find anything. I started my pc again and checked with malewarebytes, this time it found a folder for RiskWare.KeyLogger in c:\ProgramData\BFKData. I have no idea what BFKData is and how I got ratted without Kaspersky finding anything. Please help me.
submitted by /u/Hallolollmao
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Ratted but no trace?
Hi Today my pc got infected with something. I was watching Netflix and a window popped up and said:“ratted by coazy“. I didn’t think anything...
hacking: security in practice
Did you ever try a Log4J exploit over a bluetooth speaker? What do you think is possible here..
I know many bluetooth speakers with java at its core, how do you think you can inject your log expression or did you ever try it?
submitted by /u/IAmAPureGamer
[link] [comments]
Did you ever try a Log4J exploit over a bluetooth speaker? What do you think is possible here..
I know many bluetooth speakers with java at its core, how do you think you can inject your log expression or did you ever try it?
submitted by /u/IAmAPureGamer
[link] [comments]
reddit
Did you ever try a Log4J exploit over a bluetooth speaker? What do...
I know many bluetooth speakers with java at its core, how do you think you can inject your log expression or did you ever try it?
Information Disclosure leads to sensitive credential($$$)
https://medium.com/@mamunwhh/information-disclosure-leads-to-sensitive-credential-35e779f6f4db?source=rss------bug_bounty-5
https://medium.com/@mamunwhh/information-disclosure-leads-to-sensitive-credential-35e779f6f4db?source=rss------bug_bounty-5
Hi Hackers, hope you are fine.my name is khan mamun(white hat hacker) This is my 3rd write up.Continue reading on Medium » (https://medium.com/@mamunwhh/information-disclosure-leads-to-sensitive-credential-35e779f6f4db?source=rss------bug_bounty-5)
Information Disclosure leads to sensitive credential($$$)
Hi Hackers, hope you are fine.my name is khan mamun(white hat hacker) This is my 3rd write up.Continue reading on Medium »
Read more...
Hi Hackers, hope you are fine.my name is khan mamun(white hat hacker) This is my 3rd write up.Continue reading on Medium »
Read more...
SQL Injection — 1st Dose
An Injection that is not used for treatment!Continue reading on Medium »
Read more...
An Injection that is not used for treatment!Continue reading on Medium »
Read more...