Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
e.g. user@domain.com
-p, --pass PASS Password to authenticate
-f, --from EMAIL Sender's email (mostly the same as sender email)
e.g. user@domain.com
-t, --to EMAIL|LIST|CSV The receiver's email or a file list of receivers.
e.g. user@domain.com or targets.lst or targets.csv
The csv expected to be in fname,lname,email format without header.
-c, --copy EMAIL|LIST|CSV The CC'ed receiver's email or a file list of receivers.
-b, --bcopy EMAIL|LIST|CSV The BCC'ed receiver's email or a file list of receivers.
-B, --body MSG|FILE The mail's body string or a file contains the body (not attachements.)
For click and message opening and other trackings:
Add {{track-click}} tag to URL in the HTML message.
eg: http://phisher.com/file.exe/{{track-click}}
Add {{track-open}} tag into the HTML message.
eg: Hi{{track-open}}
Add {{name}} tag into the HTML message to be replaced with name (used with --to CSV).
eg: Dear {{name}},
Add {{num}} tag to be replaced with a random phone number.
-a, --attachments FILE1,FILE2 One or more files to be attached seperated by comma.
-S, --subject TITLE The mail subject/title.
--no-ssl Do NOT use SSL connect when connect to the server (default: false).
-g, --groups NUM Number of receivers to send mail to at once. (default all in one group)
-d, --delay NUM The delay, in seconds, to wait after sending each group.
-P, --profile FILE A json file contains all the the above settings in a file
-D, --db FILE Create a sqlite database file (contains emails & its tracking hashes) to be imported by 'getCabrito' server.
--dry Dry test, no actual email sending.
-h, --help Show this message.

Usage:
goCabrito.rb
Examples:
$goCabrito.rb -s smtp.office365.com:587 -u user1@domain.com -p P@ssword1 \
-f user1@domain.com -t targets1.csv -c targets2.lst -b targets3.lst \
-B msg.html -S "This's title" -a file1.docx,file2.xlsx -g 3 -d 10

$goCabrito.rb --profile prf.json
How you really use it? I create directory for each customer Under the customer's directory, I create a directory for each campaign. This sub directory contains The profile The To, CC & BCC lists in CSV format The message body in HTML format I configure the profile and prepare my HTML Execute the campaign profile in dry mode first (check the profile file dry value) ruby goCabrito.rb -P CUSTOMER/3/camp3.json --dry
I remove the --dry switch and make sure the dry value is false in the config file Send to a test email Send to the real lists Troublesheooting SMTP authentication (https://www.kitploit.com/search/label/Authentication) issues Nowadays, many cloud-based email vendors block SMTP authentication by default (e.g. Office365, GSuite). This of course will cause an error. To solve this, here are some steps to help you enabling AMTP authentication on different vendors. Enable SMTP Auth Office 365 To globally enabling SMTP Auth, use powershell. Support SSL For Linux/Nix (run pwsh as sudo required) $ sudo pwsh Install PSWSMan Install-Module -Name PSWSMan -Scope AllUsers

___________________________
@hacking_Attack
@Hacking_Video
Install-WSMan Install ExchangeOnline Module Install-Module -Name ExchangeOnlineManagement Load ExchangeOnline Module Import-Module ExchangeOnlineManagement Connect to Office365 exchange using the main admin user, it will prompt you to enter credentials. Connect-ExchangeOnline -InlineCredential The above command will prompt you to enter Office365 admin's credentials PowerShell credential request
Enter your credentials.
User: admin@domain.onmicrosoft.com
Password for user admin@domain.onmicrosoft.com: **********
Or us this to open web browser to enter your credentils incase of 2FA. Connect-ExchangeOnline -UserPrincipalName admin@pifsaudi.onmicrosoft.com Enable SMTP AUTH Gloabally Set-TransportConfig -SmtpClientAuthenticationDisabled $false To Enable for SMTP Auth for specific email Set-CASMailbox -Identity uuu@ccc.com -SmtpClientAuthenticationDisabled $false
Get-CASMailbox -Identity uuu@ccc.com | Format-List SmtpClientAuthenticationDisabled Confirm Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled Then follow the following steps Go to Asure portal (https://aad.portal.azure.com/) from admin panel (https://www.kitploit.com/search/label/Admin%20Panel) (https://admin.microsoft.com/) Select All Services Select Tenant Properties Click Manage Security defaults Select No Under Enable Security defaults Resources Enable or disable SMTP AUTH | Microsoft Docs (https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission) Azure (https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults)Active Directory (https://www.kitploit.com/search/label/Active%20Directory) security defaults | Microsoft Docs Exchange online plan 1 504 5.7.4 Unrecognized authentication type - Microsoft Q&A (https://docs.microsoft.com/en-us/answers/questions/132991/exchange-online-plan-1-504-574-unrecognized-authen.html) How to set up a multifunction device or application to send email using Microsoft 365 or Office 365 | Microsoft Docs (https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365) Google GSuite Resources Send email from a printer, scanner, or app - Google Workspace Admin Help (https://support.google.com/a/answer/176600?hl=en) Contribution By fixing bugs By enhancing the code By reporting issues By requesting features By spreading the script By click star :)

Download goCabrito (https://github.com/KINGSABRI/goCabrito)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Should Red Teamers read "Practical Malware Analysis" by Sikorski & Honigr?

Despite its high regard, I am hesitant to buy it, since malware analysis is typically a blue team activity. I imagine it includes lots of in depth analysis of popular exploits and an exploit developer could learn a lot from this.

My main concern is picking up new software that I may never use again once I finish it. I totally understand that of course doing malware analysis in general can be beneficial to red teamers, but committing to a 700 pager with strict didactics is a little different.

submitted by /u/noirKook
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video