Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Fork and inject method was used with bdllspawn in the execution type of Aggressor Script (phant0m.cna) for Cobalt Strike. If you want to inject Phant0m into your existing process and run it, you can review this project (https://github.com/rxwx/cs-rdll-ipc-example) and you can do it easily. You can also convert the code to DLL and then to Shellcode with Donut (https://github.com/TheWover/donut). NOTE: The project only supports x64 architecture. Special Thanks to Those Who Mentioned Phant0m Detecting in-memory attacks with Sysmon and Azure Security Center - https://azure.microsoft.com/tr-tr/blog/detecting-in-memory-attacks-with-sysmon-and-azure-security-center/ Experiments with Invoke-Phant0m (https://www.kitploit.com/search/label/Invoke-Phant0m) - http://www.insomniacsecurity.com/2017/08/27/phant0m.html Event Log Tampering Part 1: Disrupting the EventLog Service - https://medium.com/@7a616368/event-log-tampering-part-1-disrupting-the-eventlog-service-8d4b7d67335c Flying under the radar - https://www.exploit-db.com/docs/english/45898-flying-under-the-radar.pdf?rss Denetim ve Log'lamanın Elli Tonu - https://gallery.technet.microsoft.com/Denetim-ve-Loglamann-Elli-cbed0000 Disabling Windows Event Logs (https://www.kitploit.com/search/label/Windows%20Event%20Logs) by Suspending EventLog Service Threads - https://www.ired.team/offensive-security/defense-evasion/disabling-windows-event-logs-by-suspending-eventlog-service-threads Event Log Service – Between Offensive And Defensive - https://blog.cybercastle.io/event-log-service-between-offensive-and-defensive/ Hunting Event Logging Coverup - https://malwarenailed.blogspot.com/2017/10/update-to-hunting-mimikatz-using-sysmon.html Defense Evasion: Windows Event Logging (T1562.002) - https://hacker.observer/defense-evasion-windows-event-logging-t1562-002/ Pwning Windows Event Logging with YARA rules - https://labs.jumpsec.com/pwning-windows-event-logging-with-yara-rules/ Various Notes - Incidence Response on Attacker Tricks for EventLog - https://hannahsuarez.github.io/2019/IncidentResponseNotes-Attackers-EventLog/

Download Phant0m (https://github.com/hlldz/Phant0m)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
KRACK-attack

Before KRACK-attack (Key Reinstallation Attack) was publicly known is 2016/2017 - could a normal hacker / person with little to high experience perform this type of attack?

submitted by /u/Witty_Control6793
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
SMS displaying a name instead of a phone number

Hi all, I've been receiving some SMS messages, that I'm pretty sure are a scam. Interestingly, the sender is shown as a name instead of a phone number (for example CARL instead of some +311..... number). I have no way to reply to that sender either.

Can anyone point me at a resource on how is this accomplished? I'd be interesting to see if it'd be possible to backtrack the name-number in some way and gather more information about the scammer.

If somebody knows how this name-number translation is even called that'd be very useful. Thanks.

Edit: I'm from Europe if that changes anything on how the mobile networks function.

submitted by /u/VeryWicked
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
https://b.thumbs.redditmedia.com/jCgECO-E__9rPboSp0agnYEXDyVOvEaQPkacj-MxRNg.jpg https://github.com/Lusin333/Minecraft-Server-DDoSer

Is it real or..just a program with buttons and stuff?

I'm reviewing the code with Trillix Flash Decompiler, but for me it just seems like it's a scam program..but

how do you guys think?

can anyone test or something?

This is the class MainTimeline code in package MinecraftDDOSAdobeAnimatecc2017_fla : https://pastebin.com/3v3xX5NQ

https://preview.redd.it/pltkbm2g7ff81.png?width=404&format=png&auto=webp&s=13ae02fdd9da4a17455768b2be8daac2e0e0d68c

and this is the overall picture



https://preview.redd.it/3hd3h38j7ff81.png?width=310&format=png&auto=webp&s=0d6e48a04342d914f13a8343b7b91082158bc921

submitted by /u/PuzzleheadedDebate33
[link] [comments]
How I Made $16,500+ By Hacking Caching Servers — Part 1

@bxmbn
Read more...
How I Made +$16,500 Hacking CDN Caching Servers — Part 2

@bxmbn
Read more...
How I Made +$16,500 Hacking CDN Caching Servers — Part 3

@bxmbn
Read more...
Vulnerability Capstone — Tryhackme

Vulnerability Researching
Read more...
Dark Reading: Attacks/Breaches
Tens of Thousands of Websites Vulnerable to RCE Flaw in WordPress Plug-in

Now-patched issue in Essential Addons for Elementor gives attackers a way to carry out local file inclusion attacks, researchers say.
Dark Reading: Attacks/Breaches
TikTok's Roland Cloutier: How CISOs Can Foster a Culture of Security & Transparency

The social media platform's global security chief boils it down to being consistent, keeping it fun, and demonstrating the impact of choices.
Dark Reading: Attacks/Breaches
8 Security Dinosaurs and What Filled Their Footprints

Security technology has to evolve as new threats emerge and defenses improve. Here is a look back at the old breeds that are dying out.