Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Journey to the first 2 CVEs
https://cdn-images-1.medium.com/max/728/1*DkGtePD8FwvWNS-H8RsaUQ.png
Hello Hackers,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Journey to the first 2 CVEs
https://cdn-images-1.medium.com/max/728/1*DkGtePD8FwvWNS-H8RsaUQ.png
Hello Hackers,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Journey to the first 2 CVEs
Hello Hackers,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Alfred — TryHackMe walkthrough
https://cdn-images-1.medium.com/max/600/1*LCrIBEvO-NKFN5IQWxjZYQ.png
Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Alfred — TryHackMe walkthrough
https://cdn-images-1.medium.com/max/600/1*LCrIBEvO-NKFN5IQWxjZYQ.png
Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Alfred — TryHackMe walkthrough
Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tiny File Manager Authenticated RCE
https://cdn-images-1.medium.com/max/1024/0*--imb12G6Pw53VMg
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Tiny File Manager Authenticated RCE
https://cdn-images-1.medium.com/max/1024/0*--imb12G6Pw53VMg
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tiny File Manager Authenticated RCE
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Kerberoast : Kerberoast Attack -Pure Python-
Kerberoast attack toolkit -pure python
Install
pip3 install kerberoast
Prerequirements
Python 3.6 See requirements.txt For the impatient
IMPORTANT: the accepted target url formats for LDAP and Kerberos are the following : : Steps -with SSPI-: kerberoast auto Steps -SSPI not used-:
* Look for vulnerable users via LDAP
___________________________
@hacking_Attack
@Hacking_Video
Kerberoast : Kerberoast Attack -Pure Python-
Kerberoast attack toolkit -pure python
Install
pip3 install kerberoast
Prerequirements
Python 3.6 See requirements.txt For the impatient
IMPORTANT: the accepted target url formats for LDAP and Kerberos are the following : : Steps -with SSPI-: kerberoast auto Steps -SSPI not used-:
* Look for vulnerable users via LDAP
kerberoast ldap all * Use ASREP roast against users in the ldapenum_asrep_users.txtfile kerberoast asreproast * Use SPN roast against users in the ldapenum_spn_users.txtfile kerberoast spnroast * Crack SPN roast and ASPREP roast output with hashcat Commands ldap
This command group is for enumerating potentially vulnerable users via LDAP. Command structure kerberoast ldap Type: It supports three types of users to be enumerated
* spnEnumerates users with servicePrincipalNameattribute set.
* asrepEnumerates users with DONT_REQ_PREAUTHflag set in their UAC attribute.
* allStartes all the above mentioned enumerations. ldap_connection_url: Specifies the usercredential and the target server in the msldap url format (see help) options: -o: Output file base name brute
This command is to perform username enumeration by brute-forcing the kerberos service with possible username candidates Command structure kerberoast brute realm: The kerberos realm usually looks like COMPANY.corpdc_ip: IP or hostname of the domain controller targets: Path to the file which contains the possible username candidates options: -o: Output file base name asreproast
This command is to perform ASREProast attack Command structure kerberoast asreproast dc_ip: IP or hostname of the domain controller options: -r: Specifies the kerberos realm to be used. It overrides all other realm info. -o: Output file base name -t: Path to the file which contains the usernames to perform the attack on -u: Specifies the user to perform the attack on. Format is either or but in the first case, the -roption must be used to specify the realm spnroast
This command is to perform SPNroast (AKA kerberoast) attack. Command structure kerberoast spnroast kerberos_connection_url: Specifies the usercredential and the target server in the kerberos URL format (see help) options: -r: Specifies the kerberos realm to be used. It overrides all other realm info. -o: Output file base name -t: Path to the file which contains the usernames to perform the attack on -u: Specifies the user to perform the attack on. Format is either or but in the first case, the -roption must be used to specify the realm Download___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Kerberoast : Kerberoast Attack -Pure Python- !!! Kali Linux
Kerberoast attack toolkit -pure python. IMPORTANT: the accepted target url formats for LDAP and Kerberos are the following.
hacking: security in practice
Linkedin Account Generator
I am writing a script to generate linkedin account for digital makerting , I am in testing phase, so I created various accounts manually with different cellphone sms verification numbers, but days after that without any actions, all these accounts are blocked with restricctions including my original account, I need to upload an real ID document to recovery each of them, Does anybody knows how Microsoft/ Linkedin known these accounts are 'fakes' and how linked with my original account? I am thinking about use diferent proxies to manage my accounts, but I donot know if i am right? And how to bypass this posible detection.
submitted by /u/happygroweed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Linkedin Account Generator
I am writing a script to generate linkedin account for digital makerting , I am in testing phase, so I created various accounts manually with different cellphone sms verification numbers, but days after that without any actions, all these accounts are blocked with restricctions including my original account, I need to upload an real ID document to recovery each of them, Does anybody knows how Microsoft/ Linkedin known these accounts are 'fakes' and how linked with my original account? I am thinking about use diferent proxies to manage my accounts, but I donot know if i am right? And how to bypass this posible detection.
submitted by /u/happygroweed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Explained: The OpenSea NFT Listing Vulnerability
https://external-preview.redd.it/4TcJsI4xV3GkJta_amRNS-Lv_dIgfbNHe1bfpT2_4BI.jpg?width=640&crop=smart&auto=webp&s=afcbd0a97708f5b4139f3739dcd01aadad3789f9 submitted by /u/joe691013
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Explained: The OpenSea NFT Listing Vulnerability
https://external-preview.redd.it/4TcJsI4xV3GkJta_amRNS-Lv_dIgfbNHe1bfpT2_4BI.jpg?width=640&crop=smart&auto=webp&s=afcbd0a97708f5b4139f3739dcd01aadad3789f9 submitted by /u/joe691013
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Explained: The OpenSea NFT Listing Vulnerability
Posted in r/hacking by u/joe691013 • 1 point and 0 comments
hacking: security in practice
Private hacking eviroment
Hey guys, how would you aproach creating really private hacking enviroment? I thought about QubesOs hacking but i think it would be kinda painfull, also thought about creating Hacking vm's inside of base Debian Os and wiping them weekly, but yeah i've gotta grab some ideas on how to aproach it with it actually being practical.
submitted by /u/Mtay___
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Private hacking eviroment
Hey guys, how would you aproach creating really private hacking enviroment? I thought about QubesOs hacking but i think it would be kinda painfull, also thought about creating Hacking vm's inside of base Debian Os and wiping them weekly, but yeah i've gotta grab some ideas on how to aproach it with it actually being practical.
submitted by /u/Mtay___
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Private hacking eviroment
Hey guys, how would you aproach creating really private hacking enviroment? I thought about QubesOs hacking but i think it would be kinda...
hacking: security in practice
Password database dumps
are there places where password database dumps are available for download? I would love to do some of my own analysis.
submitted by /u/Omgfunsies
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Password database dumps
are there places where password database dumps are available for download? I would love to do some of my own analysis.
submitted by /u/Omgfunsies
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Password database dumps
are there places where password database dumps are available for download? I would love to do some of my own analysis.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Friendly reminder creationism is not new.
https://external-preview.redd.it/mWPahFPkqB5DXeQmNJEp14Xqf82AEgpsJhCzOHhpJ-A.jpg?width=320&crop=smart&auto=webp&s=61d82019a4d1d757be776ede94c6ab62acb23dee submitted by /u/Omgbomber
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Friendly reminder creationism is not new.
https://external-preview.redd.it/mWPahFPkqB5DXeQmNJEp14Xqf82AEgpsJhCzOHhpJ-A.jpg?width=320&crop=smart&auto=webp&s=61d82019a4d1d757be776ede94c6ab62acb23dee submitted by /u/Omgbomber
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Friendly reminder creationism is not new.
Posted in r/hacking by u/Omgbomber • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Deep Web Real alien caught on tape interviewed rare footage
https://external-preview.redd.it/CLb49-3R8yEsITP0H68BOtCCjrD_VI7UswSRBk9qfCU.jpg?width=320&crop=smart&auto=webp&s=5bc5245dd98f629b2afc1d39a895f024eb6e8802 submitted by /u/Interesting_Stand877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Deep Web Real alien caught on tape interviewed rare footage
https://external-preview.redd.it/CLb49-3R8yEsITP0H68BOtCCjrD_VI7UswSRBk9qfCU.jpg?width=320&crop=smart&auto=webp&s=5bc5245dd98f629b2afc1d39a895f024eb6e8802 submitted by /u/Interesting_Stand877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Deep Web Real alien caught on tape interviewed rare footage
Posted in r/deepweb by u/Interesting_Stand877 • 0 points and 8 comments
Mininode - A CLI Tool To Reduce The Attack Surface Of The Node.js Applications By Using Static Analysis
Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis of source code. It supports two modes of reduction (1) coarse, (2) fine. Mininode constructs the dependency graph (modules and functions used) of the application starting from main file, i.e. entry point of the application. Mininode initializes entry point to package.json file's main field if it exists. Otherwise default to index.js. Example usage: node index.js --mode=(coarse|fine). Below is the list of options that can be passed to Mininode. Options List of command line options that can be passed to mininode. --destination, -d: the path where mininode will save the reduced Node.js application. The default value: mininode. --dry-run: just generates mininode.json without modifying the initial application. --mode, -m: reduction mode. The value can be either coarse or fine. In coarse mode mininode will perform only coarse-grained reduction. While in fine mode mininode will perform fine-grained reduction. In general coarse-grained reduction is more reliable, because mininode will not try to reduce unused functions inside the module. Default value: coarse. --silent: console output is disabled. This will improve the performance of the mininode. --verbose: outputs additional information to the console. The default value: false --log: mininode will generate log file inside, which contains dependency graph of the application in json format. The default value: true. --log-output: the name of the log file generated by mininode. The default value: mininode.json. --compress-log: compresses the final log file. By default it will dump everything into log file. In production it is advised to pass the --compress-log flag to save space. --seeds: seed files from where mininode will start building dependency graph. You can provide many seed files by separating them with colon. --skip-stat: skips calculating the statistics --skip-reduction: if passed mininode will not reduce the JavaScript files. The default value: false. --skip-remove: if passed mininode will not remove unused JavaScript files. The default value: false. Limitaions Mininode uses static analysis, which means it can not reduce the attack surface of the Node.js application which uses dynamic behaviour, such as eval. If Mininode detects dynamic behaviour in the application it exits with error DYNAMIC_BEHAVOUR_DETECTED. Research Paper You can read more about the details of our work in the following research paper: Mininode: Reducing the Attack Surface of Node.js Applications PDF Igibek Koishybayev, Alexandros Kapravelos Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2020 If you use Mininode in your research, consider citing our work using this Bibtex entry: @conference{mininode-raid20, title = {{Mininode: Reducing the Attack Surface of Node.js Applications}}, author = {Koishybayev, Igibek and Kapravelos, Alexandros}, booktitle = {{Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID)}}, year = {2020}} Download Mininode
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis of source code. It supports two modes of reduction (1) coarse, (2) fine. Mininode constructs the dependency graph (modules and functions used) of the application starting from main file, i.e. entry point of the application. Mininode initializes entry point to package.json file's main field if it exists. Otherwise default to index.js. Example usage: node index.js --mode=(coarse|fine). Below is the list of options that can be passed to Mininode. Options List of command line options that can be passed to mininode. --destination, -d: the path where mininode will save the reduced Node.js application. The default value: mininode. --dry-run: just generates mininode.json without modifying the initial application. --mode, -m: reduction mode. The value can be either coarse or fine. In coarse mode mininode will perform only coarse-grained reduction. While in fine mode mininode will perform fine-grained reduction. In general coarse-grained reduction is more reliable, because mininode will not try to reduce unused functions inside the module. Default value: coarse. --silent: console output is disabled. This will improve the performance of the mininode. --verbose: outputs additional information to the console. The default value: false --log: mininode will generate log file inside, which contains dependency graph of the application in json format. The default value: true. --log-output: the name of the log file generated by mininode. The default value: mininode.json. --compress-log: compresses the final log file. By default it will dump everything into log file. In production it is advised to pass the --compress-log flag to save space. --seeds: seed files from where mininode will start building dependency graph. You can provide many seed files by separating them with colon. --skip-stat: skips calculating the statistics --skip-reduction: if passed mininode will not reduce the JavaScript files. The default value: false. --skip-remove: if passed mininode will not remove unused JavaScript files. The default value: false. Limitaions Mininode uses static analysis, which means it can not reduce the attack surface of the Node.js application which uses dynamic behaviour, such as eval. If Mininode detects dynamic behaviour in the application it exits with error DYNAMIC_BEHAVOUR_DETECTED. Research Paper You can read more about the details of our work in the following research paper: Mininode: Reducing the Attack Surface of Node.js Applications PDF Igibek Koishybayev, Alexandros Kapravelos Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2020 If you use Mininode in your research, consider citing our work using this Bibtex entry: @conference{mininode-raid20, title = {{Mininode: Reducing the Attack Surface of Node.js Applications}}, author = {Koishybayev, Igibek and Kapravelos, Alexandros}, booktitle = {{Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID)}}, year = {2020}} Download Mininode
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Mininode - A CLI Tool To Reduce The Attack Surface Of The Node.js Applications By Using Static Analysis
http://www.kitploit.com/2022/01/mininode-cli-tool-to-reduce-attack.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/01/mininode-cli-tool-to-reduce-attack.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Mininode - A CLI Tool To Reduce The Attack Surface Of The Node.js Applications By Using Static Analysis