hacking: security in practice
Keydemon.com
Hi!
Has anyone ordered from www.keydemon.com? It has a few items that I am interested in, but dont really know about the legitimacy of the site. Can anyone tell me something about the site etc?
submitted by /u/GoodKello
[link] [comments]
Keydemon.com
Hi!
Has anyone ordered from www.keydemon.com? It has a few items that I am interested in, but dont really know about the legitimacy of the site. Can anyone tell me something about the site etc?
submitted by /u/GoodKello
[link] [comments]
reddit
Keydemon.com
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
smsprivacy.org alternative
Hey lads, this service recently stopped selling new numbers. Need help, any good alternative?
submitted by /u/icanlolalldaylong
[link] [comments]
smsprivacy.org alternative
Hey lads, this service recently stopped selling new numbers. Need help, any good alternative?
submitted by /u/icanlolalldaylong
[link] [comments]
reddit
smsprivacy.org alternative
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
NtHiM - Super Fast Sub-domain Takeover Detection
http://www.kitploit.com/2021/04/nthim-super-fast-sub-domain-takeover.html
http://www.kitploit.com/2021/04/nthim-super-fast-sub-domain-takeover.html
NtHiM - Super Fast Sub-domain Takeover Detection
Installation
Method 1: Using Pre-compiled Binaries
The pre-compiled binaries for different systems are available in the Releases page. You can download the one suitable for your system, unzip the file and start using NtHiM.
Method 2: Using Crates.io
NtHiM is available on Crates.io (https://crates.io/crates/NtHiM). So, if you have Rust (https://www.kitploit.com/search/label/Rust) installed on your system, you can simply install NtHiM with the following command: cargo install NtHiM
Method 3: Manual Build
You will need Cargo to perform the manual build for NtHiM. If you have Cargo installed, you can simply follow the steps below: Clone this repository, git clone https://github.com/TheBinitGhimire/NtHiM; Go inside the folder, cd NtHiM; Use the cargo build command, Go inside the newly-created target folder, and open the debug folder inside it, cd target/debug; You will find NtHiM.exe (on Microsoft (https://www.kitploit.com/search/label/Microsoft) Windows) or NtHiM binary (https://www.kitploit.com/search/label/Binary) (on Linux). The installation walkthrough for NtHiM has been uploaded to YouTube, covering all of these three methods, and you can watch the video here: How to Install and Use NtHiM (Now, the Host is Mine!)? Super Fast Sub-domain Takeover Detection! (https://youtu.be/CUTbqFhRjwY)
Usage
Flag Description Example -h Display help related to usage! NtHiM -h -t Scan a single target! NtHiM -t https://example.example.com (https://example.example.com/) -f Scan a list of targets from a file! NtHiM -f hostnames.txt -c Number of Concurrent Threads! NtHiM -c 100 -f hostnames.txt -V Display the version information! NtHiM -V
Use Case 1 (Single Target):
NtHiM -t https://example.example.com
Use Case 2 (Multiple Targets):
NtHiM -f hostnames.txt
Usage Demonstration:
Installation
Method 1: Using Pre-compiled Binaries
The pre-compiled binaries for different systems are available in the Releases page. You can download the one suitable for your system, unzip the file and start using NtHiM.
Method 2: Using Crates.io
NtHiM is available on Crates.io (https://crates.io/crates/NtHiM). So, if you have Rust (https://www.kitploit.com/search/label/Rust) installed on your system, you can simply install NtHiM with the following command: cargo install NtHiM
Method 3: Manual Build
You will need Cargo to perform the manual build for NtHiM. If you have Cargo installed, you can simply follow the steps below: Clone this repository, git clone https://github.com/TheBinitGhimire/NtHiM; Go inside the folder, cd NtHiM; Use the cargo build command, Go inside the newly-created target folder, and open the debug folder inside it, cd target/debug; You will find NtHiM.exe (on Microsoft (https://www.kitploit.com/search/label/Microsoft) Windows) or NtHiM binary (https://www.kitploit.com/search/label/Binary) (on Linux). The installation walkthrough for NtHiM has been uploaded to YouTube, covering all of these three methods, and you can watch the video here: How to Install and Use NtHiM (Now, the Host is Mine!)? Super Fast Sub-domain Takeover Detection! (https://youtu.be/CUTbqFhRjwY)
Usage
Flag Description Example -h Display help related to usage! NtHiM -h -t Scan a single target! NtHiM -t https://example.example.com (https://example.example.com/) -f Scan a list of targets from a file! NtHiM -f hostnames.txt -c Number of Concurrent Threads! NtHiM -c 100 -f hostnames.txt -V Display the version information! NtHiM -V
Use Case 1 (Single Target):
NtHiM -t https://example.example.com
Use Case 2 (Multiple Targets):
NtHiM -f hostnames.txt
Usage Demonstration:
Examples
Single Target
Single Target
Multiple Targets using Concurrent Threads
Workflow
Platform Identification
NtHiM uses the data provided in EdOverflow/can-i-take-over-xyz (https://github.com/EdOverflow/can-i-take-over-xyz) for the platform identification.
Frequently Asked Questions (FAQs)
If you have any questions regarding NtHiM, please raise an issue by going to the Issues (https://github.com/TheBinitGhimire/NtHiM/issues) page. Some of your queries might have been answered in one of the existing issues, so please make sure to check the Issues with the FAQ (https://github.com/TheBinitGhimire/NtHiM/issues?q=is%3Aissue+label%3AFAQ) label before raising an issue on your own.
Contributions and Feature RequestsIf you are interested in contributing in the development of NtHiM, you can feel free to create a Pull Request with modifications in the original code, or you shall open up a new issue, and I will try to include the feature as requested. There is no restriction on anyone for contributing to the development of NtHiM. If you would like to contribute, you can feel free to do so.
Download NtHiM (https://github.com/TheBinitGhimire/NtHiM)
Platform Identification
NtHiM uses the data provided in EdOverflow/can-i-take-over-xyz (https://github.com/EdOverflow/can-i-take-over-xyz) for the platform identification.
Frequently Asked Questions (FAQs)
If you have any questions regarding NtHiM, please raise an issue by going to the Issues (https://github.com/TheBinitGhimire/NtHiM/issues) page. Some of your queries might have been answered in one of the existing issues, so please make sure to check the Issues with the FAQ (https://github.com/TheBinitGhimire/NtHiM/issues?q=is%3Aissue+label%3AFAQ) label before raising an issue on your own.
Contributions and Feature RequestsIf you are interested in contributing in the development of NtHiM, you can feel free to create a Pull Request with modifications in the original code, or you shall open up a new issue, and I will try to include the feature as requested. There is no restriction on anyone for contributing to the development of NtHiM. If you would like to contribute, you can feel free to do so.
Download NtHiM (https://github.com/TheBinitGhimire/NtHiM)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Metasploit for Pentester: Mimikatz
This article will showcase various attacks and tasks that can be performed on a compromised Windows Machine which is a part of a Domain Controller through Metasploit inbuilt Mimikatz Module which is also known as kiwi. We covered various forms of Credential Dumping with Mimikatz in our Seriesbut we didnβt present a consolidated guide to use Mimikatz with Metasploit. Also, after the response from the PowerShell Empire for Pentester: Mimikatz Module, We were encouraged to create this resource.
<o:p Table of Content<o:pΒ· Introduction<o:pΒ· Local Security Authority (LSA|LSASS.EXE)<o:pΒ· LSA Secrets<o:pΒ· Changing Password of a User<o:pΒ· DC Sync Attack<o:pΒ· Golden Tickets<o:pΒ· Purging Tickets<o:pΒ· Extract Credentials from Security Packages<o:po MSV<o:p
o Kerberos<o:p
o SSP<o:p
o WDigest<o:p
o All<o:p
Β· Mimikatz Commands<o:pΒ· Extract Wi-Fi Credentials<o:pΒ· Conclusion<o:pIntroduction<o:pTo begin with the demonstration, we first need to compromise a Windows Machine that is a part of a Network governed by a Domain Controller. The choice of compromise is your own. After the initial compromise through Metasploit, we get a meterpreter shell. There are a bunch of inbuilt commands that are loaded inside the meterpreter shell if some commands or a set of commands are not loaded then they can be loaded in the form of a module. Mimikatz is also a module that needs to be loaded inside the meterpreter shell. After loading the module, you can hit the help command to see a list of different options and attacks that can be performed on the target machine through this meterpreter shell.<o:p load kiwi<o:phelp kiwi<o:phttps://1.bp.blogspot.com/-Evjggspiecs/YG7pwFJLK5I/AAAAAAAAvSE/AHjae27b0V4X-38fekswKKE7_G6Q9a7iQCLcBGAsYHQ/s16000/1.png <v:shapetype<v:stroke<v:formulas<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:path<o:lock<v:shape<v:imagedata<o:p Local Security Authority (LSA|LSASS.EXE)<o:pThe lsa_dump_sam moduel gets the SysKey to decrypt SAM entries (from registry or hive). It connects to the local Security Account Manager (SAM) database and dumps credentials for local accounts. As we known that LSA is a system process that authenticates and logs users on the system. LSA authenticates the Domain Credentials that are used by the Operating System. The user information is validated by LSA by accessing the SAM of each computer. If there is a code that is running inside the LSA process than that process is able to access the credentials. LSA is able to store Reversibly encrypted plaintext, Kerberos tickets (ticket-granting tickets (TGTs), service tickets), NT hash, LAN Manager (LM) has. Here we can see that NTLM hash is extracted of the raj user. <o:p lsa_dump_sam<o:phttps://1.bp.blogspot.com/-XTMeRfnd804/YG7p2jSHI2I/AAAAAAAAvSI/4kg57BqseVY3pYqq1rfKGaRSvKXyRkz5QCLcBGAsYHQ/s16000/2.png <v:shape<v:imagedata<o:p Learn More: Credential Dumping: Local Security Authority (LSA|LSASS.EXE)<o:pLSA Secrets<o:pLSA secrets, Letβs understand what is the secret behind this? Earlier it was designed to store the cached domain records. After a while Microsoft expanded its usage to store passwords, IE passwords, SQL Passwords, RAS Passwords and CISCO passwords and much more. A slice of the secrets can be seen in the screenshot below. This is quite less information than it was promised as this is a Local Lab Environment. Real Working Domain Controllers have much more data. <o:p lsa_dump_secrets<o:p<o:p https://1.bp.blogspot.com/-4AHI1Zy20ok/YG7p-nAJKc[...]
Metasploit for Pentester: Mimikatz
This article will showcase various attacks and tasks that can be performed on a compromised Windows Machine which is a part of a Domain Controller through Metasploit inbuilt Mimikatz Module which is also known as kiwi. We covered various forms of Credential Dumping with Mimikatz in our Seriesbut we didnβt present a consolidated guide to use Mimikatz with Metasploit. Also, after the response from the PowerShell Empire for Pentester: Mimikatz Module, We were encouraged to create this resource.
<o:p Table of Content<o:pΒ· Introduction<o:pΒ· Local Security Authority (LSA|LSASS.EXE)<o:pΒ· LSA Secrets<o:pΒ· Changing Password of a User<o:pΒ· DC Sync Attack<o:pΒ· Golden Tickets<o:pΒ· Purging Tickets<o:pΒ· Extract Credentials from Security Packages<o:po MSV<o:p
o Kerberos<o:p
o SSP<o:p
o WDigest<o:p
o All<o:p
Β· Mimikatz Commands<o:pΒ· Extract Wi-Fi Credentials<o:pΒ· Conclusion<o:pIntroduction<o:pTo begin with the demonstration, we first need to compromise a Windows Machine that is a part of a Network governed by a Domain Controller. The choice of compromise is your own. After the initial compromise through Metasploit, we get a meterpreter shell. There are a bunch of inbuilt commands that are loaded inside the meterpreter shell if some commands or a set of commands are not loaded then they can be loaded in the form of a module. Mimikatz is also a module that needs to be loaded inside the meterpreter shell. After loading the module, you can hit the help command to see a list of different options and attacks that can be performed on the target machine through this meterpreter shell.<o:p load kiwi<o:phelp kiwi<o:phttps://1.bp.blogspot.com/-Evjggspiecs/YG7pwFJLK5I/AAAAAAAAvSE/AHjae27b0V4X-38fekswKKE7_G6Q9a7iQCLcBGAsYHQ/s16000/1.png <v:shapetype<v:stroke<v:formulas<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:f<v:path<o:lock<v:shape<v:imagedata<o:p Local Security Authority (LSA|LSASS.EXE)<o:pThe lsa_dump_sam moduel gets the SysKey to decrypt SAM entries (from registry or hive). It connects to the local Security Account Manager (SAM) database and dumps credentials for local accounts. As we known that LSA is a system process that authenticates and logs users on the system. LSA authenticates the Domain Credentials that are used by the Operating System. The user information is validated by LSA by accessing the SAM of each computer. If there is a code that is running inside the LSA process than that process is able to access the credentials. LSA is able to store Reversibly encrypted plaintext, Kerberos tickets (ticket-granting tickets (TGTs), service tickets), NT hash, LAN Manager (LM) has. Here we can see that NTLM hash is extracted of the raj user. <o:p lsa_dump_sam<o:phttps://1.bp.blogspot.com/-XTMeRfnd804/YG7p2jSHI2I/AAAAAAAAvSI/4kg57BqseVY3pYqq1rfKGaRSvKXyRkz5QCLcBGAsYHQ/s16000/2.png <v:shape<v:imagedata<o:p Learn More: Credential Dumping: Local Security Authority (LSA|LSASS.EXE)<o:pLSA Secrets<o:pLSA secrets, Letβs understand what is the secret behind this? Earlier it was designed to store the cached domain records. After a while Microsoft expanded its usage to store passwords, IE passwords, SQL Passwords, RAS Passwords and CISCO passwords and much more. A slice of the secrets can be seen in the screenshot below. This is quite less information than it was promised as this is a Local Lab Environment. Real Working Domain Controllers have much more data. <o:p lsa_dump_secrets<o:p<o:p https://1.bp.blogspot.com/-4AHI1Zy20ok/YG7p-nAJKc[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Metasploit for Pentester: Mimikatz This article will showcase various attacks and tasks that can be performed on a compromised Windows Machine which is a part of a Domain Controller through Metasploit inbuilt Mimikatz Moduleβ¦
I/AAAAAAAAvSM/-NIr1rA6tWM2MGnHkLLjhM81JLHf0P2cgCLcBGAsYHQ/s16000/3.png <v:shape<v:imagedata<o:p Changing Password of a User<o:pThe ability to change the password for a user can be not only a high-risk situation but also can be a tad bit annoying. The password_change module can help you do just that. There is an option to change the password if the old password is known. It generates and stores a NTLM hash for the new user. The other option is if you are able to extract the NTLM hash of a user, say using the lsadump then you have the ability to change the password for that user. <o:p password_change -u raj -p 123 -P 9876<o:ppassword_change -u raj -n <ntlm-hash-P 1234<o:phttps://1.bp.blogspot.com/-3TcnZinkKzQ/YG7qTHG7L5I/AAAAAAAAvSc/pKYlPf7rXpY4cFeVCFMyXyYmOtyk3349gCLcBGAsYHQ/s16000/4.png <v:shape<v:imagedata<o:p DC Sync Attack<o:pAs discussed earlier, the DC Sync attack allows an attacker to replicate Domain Controller (DC) behavior. In simple words it impersonates as a domain controller and request other DCβs for user credential data via GetNCChanges. The only barrier is that you need a compromised machine and its user who is a member of the privilege account (Administrators, Domain Admin or Enterprise Admin).<o:p dcsync_ntlm krbtgt<o:pdcsync krbtgt<o:p<o:p https://1.bp.blogspot.com/-EnqHepWQVDQ/YG7qYuMZvnI/AAAAAAAAvSg/2Po6-eWPgxw3_YgTPdA-rM68yDdnGDkHwCLcBGAsYHQ/s16000/5.png <v:shape<v:imagedata<o:p Learn More: Credential Dumping: DCSync Attack<o:pGolden Tickets<o:pGolden Tickets is an attack that forges the Kerberos Ticket Granting Tickets (TGT) which in turn is used to authenticate users with the help of Kerberos. The Ticket Granting Services (TGS) is depended upon the TGTs to verify the authenticity of tickets. This means that the forged ticket can be used to be directly authenticate the attacker. These tickets can have a life span up to a decade. That makes them so valuable almost as gold. <o:p golden_ticket_create -d ignite.local -u pavan -s <sid-k<o:pkerberos_ticket_use /root/ticket.kirbi<o:pshell<o:pdir\\DC1.ignite.local\c$<o:phttps://1.bp.blogspot.com/-wSIYUYnQsdI/YG7qlLR5PWI/AAAAAAAAvSo/FBumzpUTbt4QqRhFLPCZF4-SpsTzpOx3wCLcBGAsYHQ/s16000/6.png <v:shape<v:imagedata<o:p Learn More: Domain Persistence: Golden Ticket Attack<o:pPurging Tickets<o:pWhile working with the tokens and tickets, there will be a time where the number of tickets would be too large to work with. This scenario will arise sooner or later and thatβs when the purge command will help you. It will purge all the tickets in the current session.<o:p kerberos _ticket_list<o:pkerberos_ticket_purge<o:pkerberos_ticket_list<o:phttps://1.bp.blogspot.com/--vrrKtD5e8g/YG7qptawxFI/AAAAAAAAvSw/ERrKvAMVjsgJXTtD6noxDW12qX9-YZjOQCLcBGAsYHQ/s16000/7.png <v:shape<v:imagedata<o:p Extract Credentials from Security Packages<o:pMSV<o:pMicrosoft provides the MSV1_0 authentication package for local machine logons that do not require custom authentication. The Local Security Authority (LSA) calls the MSV1_0 authentication package to process logon data collected by the GINA for the Winlogon logon process. The MSV1_0 package checks the local security accounts manager (SAM) database to determine whether the logon data belongs to a valid security principal and then returns the result of the logon attempt to the LSA. MSV1_0 also supports domain logons. MSV1_0 processes domain logons using pass-through authentication We can extract the hash using the creds_msv command on meterpreter as shown in the image. <o:p creds_msv<o:phttps://1.bp.blogspot.com/-rEC47ARxz6s/YG7qv3yEPcI/AAAAAAAAvS0/zJa4Fn0apdgYEwN58xt6x6z1DPlWkgOcQCLcBGAsYHQ/s16000/8.png <o:p
<o:p
<v:shape<v:imagedata<[...]
<o:p
<v:shape<v:imagedata<[...]
Hacking Articles Tips Tricks Videos Tutorials
I/AAAAAAAAvSM/-NIr1rA6tWM2MGnHkLLjhM81JLHf0P2cgCLcBGAsYHQ/s16000/3.png <v:shape<v:imagedata<o:p Changing Password of a User<o:pThe ability to change the password for a user can be not only a high-risk situation but also can be a tad bit annoying. The password_changeβ¦
o:p Kerberos<o:pSimilarly, if we want to extract the credentials from the Kerberos Service, we can run the creds_kerberos to attack the Kerberos. This however have the ability to extract clear text passwords for the users. <o:p creds_kerberos<o:phttps://1.bp.blogspot.com/-d5hwj4Dmihs/YG7q3WyW5ZI/AAAAAAAAvS8/weBIQW1cbuctx3RsJH-zUCvnj2L01WRiQCLcBGAsYHQ/s16000/9.png <v:shape<v:imagedata<o:p SSP<o:pSSP or Securtiy Support Provider is dynamic-link library (DLL) that implements the SSPI by making one or more security packages available to applications. Each security package provides mappings between an application's SSPI function calls and an actual security modelβs function. Security packages support security protocols such as Kerberos authentication and the Microsoft LAN Manager. Due to the connection of the SSP with the Kerberos, it can extract credentials in clear text as shown in the image below.<o:p creds_ssp<o:phttps://1.bp.blogspot.com/-MP7vtKLmN7U/YG7rHH3FHqI/AAAAAAAAvTM/vUTf6abia4AlBEGHxtnFTsA2-rmNcFlLQCLcBGAsYHQ/s16000/10.png <v:shape<v:imagedata<o:p WDigest<o:pWDigest.dll was introduced in the Windows XP operating system The Digest Authentication protocol is designed for use with Hypertext Transfer Protocol (HTTP) and Simple Authentication Security Layer (SASL) exchanges. These exchanges require that parties that seek to authenticate must demonstrate their knowledge of secret keys. This process improves upon earlier versions of HTTP authentication, in which users provide passwords that are not encrypted when they are sent to a server, leaving them vulnerable to capture by attackers by using the creds_wdigest.<o:p creds_wdigest<o:phttps://1.bp.blogspot.com/-mZrber0SfLU/YG7rLU18b5I/AAAAAAAAvTQ/PI6PK_WlQ5wVVN4buBYcCaIWQxOmE9PfQCLcBGAsYHQ/s16000/11.png <v:shape<v:imagedata<o:p All<o:pIncase, you want to extract all the possible hashes or credentials from all the security packages on the target machine, then use creds_all command on the meterpreter. It will show all the credentials from the packages that we just discussed in one go. <o:p creds_all<o:p<o:p https://1.bp.blogspot.com/-usJEI-Ehgzs/YG7rPD5bnPI/AAAAAAAAvTU/Cqmzt03UIP4JsZIz_l5ljO8rolTq561KgCLcBGAsYHQ/s16000/12.png <o:p
<v:shape<v:imagedata<o:p Learn More: Credential Dumping: SAM<o:pMimikatz Commands<o:pThere are modules inside the Mimikatz that donβt have the direct access in the form of commands in kiwi. This is where the ability to run the Mimikatz commands comes to the rescue. This acts as a normal shell with the ability to run the Mimikatz commands and perform almost all the attacks possible in the scenario. <o:p kiwi_cmd hostname<o:phttps://1.bp.blogspot.com/-EKbPpYsjDKw/YG7rTrxEEEI/AAAAAAAAvTY/C-J6qq_fOEMCxCNFBEjiGmIgZWielSLTACLcBGAsYHQ/s16000/13.png <v:shape<v:imagedata<o:p Extract Wi-Fi Credentials<o:pAmong the attacks that duplicate that tickets to provide the ability to run the commands as domain controller, the ability to read the Wi-Fi credentials seems a bit dim but the this is not the case. The Wi-Fi passwords are not the most thought-out passwords. It usually the first things that comes into the userβs mind. This provides insight as to how that particular user will create passwords. There is a good chance that the account of that user will have the same passwords. Even if it turned out to be that case, you get free Wi-Fi access and thatβs not bad. <o:p wifi_list<o:phttps://1.bp.blogspot.com/-A1t5eeUHo0M/YG7raVH3k8I/AAAAAAAAvTg/QYuNW1xER-oUVW5rL1bwNHjDgQTQ7Wz_ACLcBGAsYHQ/s16000/14.png <v:shape<v:imagedata<o:p Conclusion<o:pAfter Credential Dumping Series which contained different tools that can be used against a specific vulnerability and PowerShell Empire for Pentester: Mimikatz Module whic[...]
<v:shape<v:imagedata<o:p Learn More: Credential Dumping: SAM<o:pMimikatz Commands<o:pThere are modules inside the Mimikatz that donβt have the direct access in the form of commands in kiwi. This is where the ability to run the Mimikatz commands comes to the rescue. This acts as a normal shell with the ability to run the Mimikatz commands and perform almost all the attacks possible in the scenario. <o:p kiwi_cmd hostname<o:phttps://1.bp.blogspot.com/-EKbPpYsjDKw/YG7rTrxEEEI/AAAAAAAAvTY/C-J6qq_fOEMCxCNFBEjiGmIgZWielSLTACLcBGAsYHQ/s16000/13.png <v:shape<v:imagedata<o:p Extract Wi-Fi Credentials<o:pAmong the attacks that duplicate that tickets to provide the ability to run the commands as domain controller, the ability to read the Wi-Fi credentials seems a bit dim but the this is not the case. The Wi-Fi passwords are not the most thought-out passwords. It usually the first things that comes into the userβs mind. This provides insight as to how that particular user will create passwords. There is a good chance that the account of that user will have the same passwords. Even if it turned out to be that case, you get free Wi-Fi access and thatβs not bad. <o:p wifi_list<o:phttps://1.bp.blogspot.com/-A1t5eeUHo0M/YG7raVH3k8I/AAAAAAAAvTg/QYuNW1xER-oUVW5rL1bwNHjDgQTQ7Wz_ACLcBGAsYHQ/s16000/14.png <v:shape<v:imagedata<o:p Conclusion<o:pAfter Credential Dumping Series which contained different tools that can be used against a specific vulnerability and PowerShell Empire for Pentester: Mimikatz Module whic[...]
Hacking Articles Tips Tricks Videos Tutorials
o:p Kerberos<o:pSimilarly, if we want to extract the credentials from the Kerberos Service, we can run the creds_kerberos to attack the Kerberos. This however have the ability to extract clear text passwords for the users. <o:p creds_kerberos<o:phttps://1β¦
h provided an insight on the ability of PowerShell Empire to attack the Windows Authentication Process. We felt the need for a guide that can help a person who is trying to get the reins of Metasploit. <o:p
<o:p
β Sent by @TheFeedReaderBot β
<o:p
β Sent by @TheFeedReaderBot β
PASSWORD RESET POISIONING LEADS TO TOKEN THEFT
1.Go to password reset funtion. 2.Enter email and intercept the request. 3.Change host header to some other host i.e, Host:target.comβ¦Continue reading on Medium Β»
Read more...
1.Go to password reset funtion. 2.Enter email and intercept the request. 3.Change host header to some other host i.e, Host:target.comβ¦Continue reading on Medium Β»
Read more...
NtHiM - Super Fast Sub-domain Takeover Detection
NtHiM - Super Fast Sub-domain Takeover DetectionInstallation Method 1: Using Pre-compiled Binaries The pre-compiled binaries for different systems are available in the Releases page. You can download the one suitable for your system, unzip the file and start using NtHiM. Method 2: Using Crates.io NtHiM is available on Crates.io. So, if you have Rust installed on your system, you can simply install NtHiM with the following command: cargo install NtHiM Method 3: Manual Build You will need Cargo to perform the manual build for NtHiM. If you have Cargo installed, you can simply follow the steps below: Clone this repository, git clone https://github.com/TheBinitGhimire/NtHiM; Go inside the folder, cd NtHiM; Use the cargo build command, Go inside the newly-created target folder, and open the debug folder inside it, cd target/debug; You will find NtHiM.exe (on Microsoft Windows) or NtHiM binary (on Linux). The installation walkthrough for NtHiM has been uploaded to YouTube, covering all of these three methods, and you can watch the video here: How to Install and Use NtHiM (Now, the Host is Mine!)? Super Fast Sub-domain Takeover Detection! Usage Flag Description Example -h Display help related to usage! NtHiM -h -t Scan a single target! NtHiM -t https://example.example.com -f Scan a list of targets from a file! NtHiM -f hostnames.txt -c Number of Concurrent Threads! NtHiM -c 100 -f hostnames.txt -V Display the version information! NtHiM -V Use Case 1 (Single Target): NtHiM -t https://example.example.com Use Case 2 (Multiple Targets): NtHiM -f hostnames.txt Usage Demonstration: Examples Single Target Multiple Targets using Concurrent Threads Workflow Platform Identification NtHiM uses the data provided in EdOverflow/can-i-take-over-xyz for the platform identification. Frequently Asked Questions (FAQs) If you have any questions regarding NtHiM, please raise an issue by going to the Issues page. Some of your queries might have been answered in one of the existing issues, so please make sure to check the Issues with the FAQ label before raising an issue on your own. Contributions and Feature RequestsIf you are interested in contributing in the development of NtHiM, you can feel free to create a Pull Request with modifications in the original code, or you shall open up a new issue, and I will try to include the feature as requested. There is no restriction on anyone for contributing to the development of NtHiM. If you would like to contribute, you can feel free to do so. Download NtHiM
Read more...
NtHiM - Super Fast Sub-domain Takeover DetectionInstallation Method 1: Using Pre-compiled Binaries The pre-compiled binaries for different systems are available in the Releases page. You can download the one suitable for your system, unzip the file and start using NtHiM. Method 2: Using Crates.io NtHiM is available on Crates.io. So, if you have Rust installed on your system, you can simply install NtHiM with the following command: cargo install NtHiM Method 3: Manual Build You will need Cargo to perform the manual build for NtHiM. If you have Cargo installed, you can simply follow the steps below: Clone this repository, git clone https://github.com/TheBinitGhimire/NtHiM; Go inside the folder, cd NtHiM; Use the cargo build command, Go inside the newly-created target folder, and open the debug folder inside it, cd target/debug; You will find NtHiM.exe (on Microsoft Windows) or NtHiM binary (on Linux). The installation walkthrough for NtHiM has been uploaded to YouTube, covering all of these three methods, and you can watch the video here: How to Install and Use NtHiM (Now, the Host is Mine!)? Super Fast Sub-domain Takeover Detection! Usage Flag Description Example -h Display help related to usage! NtHiM -h -t Scan a single target! NtHiM -t https://example.example.com -f Scan a list of targets from a file! NtHiM -f hostnames.txt -c Number of Concurrent Threads! NtHiM -c 100 -f hostnames.txt -V Display the version information! NtHiM -V Use Case 1 (Single Target): NtHiM -t https://example.example.com Use Case 2 (Multiple Targets): NtHiM -f hostnames.txt Usage Demonstration: Examples Single Target Multiple Targets using Concurrent Threads Workflow Platform Identification NtHiM uses the data provided in EdOverflow/can-i-take-over-xyz for the platform identification. Frequently Asked Questions (FAQs) If you have any questions regarding NtHiM, please raise an issue by going to the Issues page. Some of your queries might have been answered in one of the existing issues, so please make sure to check the Issues with the FAQ label before raising an issue on your own. Contributions and Feature RequestsIf you are interested in contributing in the development of NtHiM, you can feel free to create a Pull Request with modifications in the original code, or you shall open up a new issue, and I will try to include the feature as requested. There is no restriction on anyone for contributing to the development of NtHiM. If you would like to contribute, you can feel free to do so. Download NtHiM
Read more...
GitHub
GitHub - TheBinitGhimire/NtHiM: Now, the Host is Mine! - Super Fast Sub-domain Takeover Detection!
Now, the Host is Mine! - Super Fast Sub-domain Takeover Detection! - TheBinitGhimire/NtHiM
APT-C-23 Threat Group Uses Voice Changing Software in Espionage Attempt
https://www.reddit.com/r/redteamsec/comments/mmq4c3/aptc23_threat_group_uses_voice_changing_software/
submitted by /u/malware_bender (https://www.reddit.com/user/malware_bender)
[link] (https://www.cadosecurity.com/post/threat-group-uses-voice-changing-software-in-espionage-attempt) [comments] (https://www.reddit.com/r/redteamsec/comments/mmq4c3/aptc23_threat_group_uses_voice_changing_software/)
https://www.reddit.com/r/redteamsec/comments/mmq4c3/aptc23_threat_group_uses_voice_changing_software/
submitted by /u/malware_bender (https://www.reddit.com/user/malware_bender)
[link] (https://www.cadosecurity.com/post/threat-group-uses-voice-changing-software-in-espionage-attempt) [comments] (https://www.reddit.com/r/redteamsec/comments/mmq4c3/aptc23_threat_group_uses_voice_changing_software/)