Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Trying to close the expanding software bug ID gap

Giving ID numbers and severity ratings to every newly discovered software bug is a constant game of catch-up.

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Information Gathering — Hacking

https://cdn-images-1.medium.com/max/1600/1*xVWVQfysHH79xkKRzM6Szg.jpeg
Before you can attack any computer system you have to understand the system and understanding it means gathering information on the system…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
youtube-dl كيفية استخدام

https://cdn-images-1.medium.com/max/1106/1*H2J0MZsGtZjG37bOy1aGPA.png
هي اداة لتحميل مقاطع الفيديو من يوتيوب و اكثر من ألف موقع اخر للمزيد عن المواقع المدعومة, وهي مجانية ومفتوحة المصدر وقدراتها جبارة وتعتمد…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe walk-through CRACKING THE HASHES {OWASP }

https://cdn-images-1.medium.com/max/1000/0*KgUJfAw_8UTLjOVn
Today I was stumbled across a hacking challenge website called tryhackme. Multiple challenges can be found and each of the challenges is…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
PowerShell Empire for Pentester: Mimikatz Module

This article will showcase various attacks and tasks that can be performed on a compromised Windows Machine which is a part of a Domain Controller through PowerShell Empire inbuilt Mimikatz Module. Table of Content Introduction DC Sync Attack DC Sync Hash Dump Golden Tickets Extracting Tickets Domain Cache Mimikatz Commands

The post PowerShell Empire for Pentester: Mimikatz Module appeared first on Hacking Articles.
hacking: security in practice
What do you use for tracking / threat actor information gathering?

Hi folks,

a small but intensive part of my assignments concerns chatting up threat actors and getting as much information as possible about them (e.g. IP, system locale, device, settings etc.).

So far, I have used either Canarytokens or Grabify and a my social engineering skills.

Recently, I have been wondering whether there is something nifty that I perhaps do not know about and wanted to ask you guys.

Cheers.

submitted by /u/gspnst
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
PowerShell Empire for Pentester: Mimikatz Module

This article will showcase various attacks and tasks that can be performed on a compromised Windows Machine which is a part of a Domain Controller through PowerShell Empire inbuilt Mimikatz Module.

<o:p Table of Content<o:p· Introduction<o:p· DC Sync Attack<o:p· DC Sync Hash Dump<o:p· Golden Tickets<o:p· Extracting Tickets<o:p· Domain Cache<o:p· Mimikatz Commands<o:p· Extracting Certificates<o:p· Mimitokens<o:p· Crypto Keys<o:p· Purging Tickets<o:p· Local Security Authority (LSA|LSASS.EXE)<o:p· SAM<o:p· Conclusion<o:pIntroduction<o:pPowerShell Empire is one those tools that keeps on giving to the Penetration Community for as long as it was first introduced. Any other tool that we could remember that has more utility than anything is the Mimikatz. It has been years since the release of both of these tools but their ability to consistently attack the Windows Machine is unmatched. We know that neither PowerShell Empire nor Mimikatz is being used in the wild currently because of their signature that has been added to almost all of the Anti-Virus Software and across Virus Total. This has although made them less usable as compared to Cobalt Strike and other alternatives but when it comes to understanding the basics of Windows Authentication Systems such as SAM and LSASS and attack them and extract credentials there is no tool that can work as efficiently as Mimikatz. <o:p

We covered various forms of Credential Dumping with Mimikatz in our Seriesbut we didn’t present a consolidated guide to use Mimikatz with PowerShell Empire. Hence, we created this resource. <o:p DC Sync Attack<o:pThe Mimikatz DCSYNC-function allows an attacker to replicate Domain Controller (DC) behavior. Typically impersonates as a domain controller and request other DC’s for user credential data via GetNCChanges. But compromised account should be a member of administrators, Domain Admin or Enterprise Admin to retrieve account password hashes from the others domain controller. As a result, the intruder will build Kerberos forged tickets using a retrieved hash to obtain any of the Active Directory ‘s resources. We have compromised the machine and its user who is a member of privilege account (Administrators, Domain Admin or Enterprise Admin). <o:p usemodule credentials/mimikatz/dcsync<o:pset user krbtgt<o:pexecute<o:phttps://1.bp.blogspot.com/-MDIEUy7UOYQ/YGywfoOWgYI/AAAAAAAAvQI/k9oZuH3Z2A0Jc2h617hChmm1sgHv4XV4gCLcBGAsYHQ/s16000/1.png <v:shapetype<v:stroke<v:formulas<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:path<o:lock<v:shape<v:imagedata<o:p

Loading the dcsync module will invoke the mimikatz PowerShell script to execute the dcsync attack to obtain the credential by asking from an others domain controller in the domain. Here, we are requesting for KRBTGT account Hashes and as result, it will retrieve the KRBTGT NTLM HASH.<o:p https://1.bp.blogspot.com/-7AsV6asRNSw/YGywoEuvZjI/AAAAAAAAvQM/GaoX2JK4vaA9C_R413VntdmwZYFpn0qCACLcBGAsYHQ/s16000/2.png <v:shape<v:imagedata<o:p Learn More: Credential Dumping: DCSync Attack<o:pDC Sync Hash Dump<o:pSimilar to the DC Sync attack we just performed on a particular user so the NTLM hash returned is also of that particular user. But in case the attacker wants to extract the hash of the entirety of all the users created on the Domain Controller. This is when the hashdump module comes into action. It will perform the DC Sync attack for each and every user and then provide the hashes for all of them in a consoli[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog PowerShell Empire for Pentester: Mimikatz Module This article will showcase various attacks and tasks that can be performed on a compromised Windows Machine which is a part of a Domain Controller through PowerShell Empire…
dated view as shown in the image below.<o:p usemodule credentials/mimikatz/dcsync_hashdump<o:pexecute<o:phttps://1.bp.blogspot.com/-5029MPgShRs/YGyxDepQN8I/AAAAAAAAvQY/1mrRwfcchsY_NVuek8gDUtevCctoUIm3ACLcBGAsYHQ/s16000/3.png <v:shape<v:imagedata<o:p Golden Ticket<o:pGolden Ticket attack is a famous technique of impersonating users on an AD domain by abusing Kerberos authentication. <o:p

Default local accounts are built-in accounts that are created automatically when a Windows Server domain controller is installed, and the domain is created. These default local accounts have counterparts in Active Directory. The default local accounts in the Users container include: Administrator, Guest, and KRBTGT. In the Active Directory domain, every domain controller runs a KDC (Kerberos Distribution Center) service that processes all requests for tickets to Kerberos. For Kerberos tickets, AD uses the KRBTGT account in the AD domain. A legitimate user begins the communication for a service request to the Application Server. The KBRTGT account acts as a service account for the Key Distribution Center (KDC) and separated into three parts: Database (db), Authentication Server (AS) and Ticket Granting Server (TGS). The Authentication Server (AS) verifies client authentication. If the logged user is authenticated successfully the AS issues a ticket called TGT which confirms to other servers that user has been authenticated. Then the User request for TGS from the KDC that will be used to access the service of the application server.<o:p

Forging Kerberos tickets depends on the password hash available to the attacker. Golden Tickets requires the KRBTGT password hash. Golden Tickets are forged Ticket-Granting Tickets (TGTs), also called authentication tickets, Attacker escapes authentication and initializes communication with KCD. Since a Golden Ticket is a forged TGT, it is sent to the Domain Controller as part of the TGS-REQ to get a service ticket. The TGT is used mainly to inform KDC’s domain controller that another domain controller has authenticated the users. The reality is that the TGT has the hash KRBTGT password encrypted and any KDC service inside the domain may decrypt to proves it is valid.<o:p

If an intruder has access to an Active Directory forest/domain administrator/local administrator account, he/she can exploit Kerberos tickets for identity theft. A golden ticket attack is something that he/ he creates a ticket created by Kerberos that is valid for 10 years. However, if any other user has changed its password, the attacker may use the KRBTGT account to stay on the network. The attacker may also create accessible user/computer/service tickets from Kerberos for a non-existent Active Directory account. As we know, there is some basic requirement create a forge TGT i.e., extract the “domain Name, SID, krbtgt Hash”, Once an attacker has admin access to a Domain Controller, the KRBTGT account password hashes can be extracted using Mimikatz.<o:p

Once we have compromised the victim machine who is member of AD, then we can use the following module directly without admin privilege session.<o:p usemodule credentials/mimikatz/golden_ticket<o:pset domain <domain_name<o:pset sid <sid<o:pset group 500<o:pset user pavan<o:pset krbtgt_hash <ntlm_hash<o:pset id 500<o:pexecute<o:pkerberos::golden /user:pavan /domain:ignite.local /sid: SID<o:pback<o:pshell dir \\DC1.ignite.local\c$<o:phttps://1.bp.blogspot.com/-SQHkt68HNg8/YGyxJRnzjaI/AAAAAAAAvQc/sZDitySvbLYCwYvtl2lYtKXD8h8RVsyaACLcBGAsYHQ/s16000/4.png <v:shape<v:imagedata<o:p

This is a dynamic way to generate ticket because this module can be run without having admin privilege session and it will inject the ticket into the current session and the attacker can get direct access of[...]