Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
TODO Implement aiohttp based solution for sending requests Integrate a spraying library Add other authentication (https://www.kitploit.com/search/label/Authentication) schemes found to the output Automatic detection of autodiscover domains if domain Overview NTLMRecon looks for NTLM enabled web endpoints, sends a fake authentication request and enumerates the following information from the NTLMSSP response: AD Domain Name Server name DNS Domain Name FQDN Parent DNS Domain Since NTLMRecon leverages a python implementation of NTLMSSP, it eliminates the overhead of running Nmap NSE http-ntlm-info for every successful discovery. On every successful discovery (https://www.kitploit.com/search/label/Discovery) of a NTLM enabled web endpoint, the tool enumerates and saves information about the domain as follows to a CSV file : URL Domain Name Server Name DNS Domain Name FQDN DNS Domain https://contoso.com/EWS/ XCORP EXCHANGE01 xcorp.contoso.net EXCHANGE01.xcorp.contoso.net contoso.net Installation BlackArch NTLMRecon is already packaged for BlackArch (https://www.kitploit.com/search/label/BlackArch) and can be installed by running pacman -S ntlmrecon Arch If you're on Arch Linux (https://www.kitploit.com/search/label/Arch%20Linux) or any Arch linux based distribution, you can grab the latest build from the Arch User Repository (https://aur.archlinux.org/packages/ntlmrecon/). Build from source Clone the repository : git clone https://github.com/sachinkamath/ntlmrecon/ RECOMMENDED - Install virtualenv : pip install virtualenv Start a new virtual environment : virtualenv venv and activate it with source venv/bin/activate Run the setup file : python setup.py install Run ntlmrecon : ntlmrecon --help Usage $ ntlmrecon --help

_ _ _____ _ ___ _________
| \ | |_ _| | | \/ || ___ \
| \| | | | | | | . . || |_/ /___ ___ ___ _ __
| . ` | | | | | | |\/| || // _ \/ __/ _ \| '_ \
| |\ | | | | |____| | | || |\ \ __/ (_| (_) | | | |
\_| \_/ \_/ \_____/\_| |_/\_| \_\___|\___\___/|_| |_| - @pwnfoo

v.0.4 beta - Y'all still exposing NTLM endpoints?

Bug Reports, Feature Requests : https://git.io/JIR5z


usage: ntlmrecon [-h] [--input INPUT | --infile INFILE] [--wordlist WORDLIST]
[--threads THREADS] [--output-type] [--outfile OUTFILE]
[--random-user-agent] [--force-all] [--shuffle] [-f]

optional arguments:
-h, --help show this help message and exit
--input INPUT, -i INPUT
Pass input as an IP address, URL or CIDR to enumerate
NTLM endpoints
--infile INFILE, -I INFILE
Pass input from a local file
--wordlist WORDLIST Override the internal wordlist with a custom wordlist
--threads THREADS Set number of threads (Default: 10)
--output-type, -o Set output type. JSON (TODO) and CSV supported
(Default: CSV)
--outfile OUTFILE, -O OUTFILE
Set output file name (Default: ntlmrecon.csv)
--random-user-agent TODO: Randomize user agents when sending requests
(Default: False)
--force-all Force enumerate all endpoints even if a valid endpoint
is found for a URL (Default : False)
--shuffle Break order of the input files
-f, --force Force replace output file if it already exists

Example Usage Recon on a single URL $ ntlmrecon --input https://mail.contoso.com --outfile ntlmrecon.csv Recon on a CIDR range or IP address $ ntlmrecon --input 192.168.1.1/24 --outfile ntlmrecon-ranges.csv Recon on an input file The tool automatically detects the type of input per line and gives you results automatically. CIDR ranges are expanded automatically even when read from a text file. Input file can be

___________________________
@hacking_Attack
@Hacking_Video
something as mixed up as : mail.contoso.com
CONTOSOHOSTNAME
10.0.13.2/28
192.168.222.1/24
https://mail.contoso.com
To run recon with an input file, just run : $ ntlmrecon --infile /path/to/input/file --outfile ntlmrecon-fromfile.csv Acknowledgements @nyxgeek (https://github.com/nyxgeek) for the idea behind ntlmscan (https://github.com/nyxgeek/ntlmscan). Feedback If you'd like to see a feature added into the tool or something doesn't work for you, please open a new issue (https://github.com/sachinkamath/ntlmrecon/issues/new).

Download NTLMRecon (https://github.com/pwnfoo/NTLMRecon)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Anonymous Hacktivists Launch ‘Cyber Proxy War’ Over Russia-Ukraine Conflict

Multiple anonymous hacktivists and hacker groups have collectively announced this week that they are launching a cyber proxy war and are getting involved in the conflict between Russia and Ukraine.

Experts are concerned as non-government cybercriminals groups are taking sides as Russia invades Ukraine.

On Thursday, a member of Anonymous took to Twitter and announced that they would be launching attacks against the Russian government. The hackers have also defaced local Russian websites, including RT, a popular Russian news outlet.

On Friday, the group also claimed that they would leak login credentials of the Russian Ministry of Defense website.

These actions on cyberspace came just a few hours after Yegor Aushev, CEO of cybersecurity in Kyiv, told Reuters that he was asked by Ukrainian Defense Ministry officials to took for help from the hacking community and seek help from both offensive and defensive threat actors.

After the request, requests for volunteers started appearing on various hackers forums, as Russia bombed Kyiv. The posts read:

“Ukrainian cybercommunity! It’s time to get involved in the cyber defense of our country.”

Anonymous is not the only group that has confirmed its involvement in the conflict as on Friday, ransomware groups Conti and ComingProject announced that they will be supporting the Russian government.

Conti ransomware group officially announced that they will side with the Russian government. The official message read:

“If any body will decide to organize a cyberattack or any war activities against Russia, we are going to use our all possible resources to strike back at the critical infrastructures of an enemy.”

Shortly after sending the message, Conti revised their statement, decreasing their tone saying they would its “full capacity to deliver retaliatory measures in case the Western warmongers attempt to target critical infrastructure in Russia or any Russian-speaking region of the world.”

The message further read that they condemn the ongoing conflict and don’t support any government. That said, they further explained that the “West is known to wage its wars primarily by targeting civilians, we will use our resources in order to strike back if the well being and safety of peaceful citizens will be at stake due to American cyber aggression.”

The announcement from the ransomware community came as Ukraine faced DDoS, wiper malware, phishing attacks, and more. Internet connectivity also remains to be intermittent in the country as reported by Netblocks.

Experts are extremely wary of the hacker groups picking sides in the Russia-Ukraine conflict launching attacks. It further scared the experts as NATO Secretary-General Jens Stoltenberg said that “these cyberattacks can trigger Article 5 of the NATO charter.“Article 5 is about the collective defense that binds each member to protect the other.

Researchers at Sophos, a cybersecurity firm, said that ransomware groups like Anonymous and Conti taking sides in this conflict will “increase the risk for everyone, whether involved in this conflict or not.”

“Vigilante attacks in either direction increase the fog of war and generate confusion and uncertainty for everyone,” said Sophos.

Brett Callow, an Emisoft threat analyst, said that the situation is highly volatile considering the statement from Conti. “This is is probably just bluster too [but] it would be a mistake to assume the threat is empty. If your company hasn’t already gone Shields Up, now is the time,” said Callow.

Casey Ellis, Bugcrowd CTO, said one of his concerns is that the recent developments with hacktivists groups taking sides, could lead to actions with intentional “false flag” cyberattacks that could e[...]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to hack a mobile app undetected?

I know nothing about hacking, but this game I am playing offers some prizes and it is obvious that a lot of people are cheating. How do I proceed?

submitted by /u/RJ2999
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
RPC Firewall : Stopping Lateral Movement via the RPC Firewall

RPC Firewall is the underlying mechanism which is used for numerous lateral movement techniques,
reconnaissances, relay attacks, or simply to exploit vulnerable RPC services.

DCSync attack? over RPC. Remote DCOM? over RPC. WMIC? over RPC. SharpHound? over RPC. PetitPotam? over RPC. PsExec? over RPC. ZeroLogon? over RPC… well, you get the idea https://s.w.org/images/core/emoji/13.1.0/72x72/1f642.png What is it used for? Research

Install the RPC Firewall and configure it to audit all remote RPC calls. Once executing any remote attack tools, you will see which RPC UUIDs and Opnums were called remotely. Remote RPC Attacks Detection

When the RPC Firewall is configured to audit, it write events to the Windows Event Log.

Forward this log to your SIEM, and use it to create baselines of remote RPC traffic for your servers.

Once an abnormal RPC call is audited, use it to trigger an alert for your SOC team. Remote RPC Attacks Protection

The RPC Firewall can be configured to block & audit only potentially malicious RPC calls. All other RPC calls are not audited to reduce noise and improve performance.

Once a potentially malicious RPC call is detected, it is blocked and audited. This could be used to alert your SOC team, while keeping your servers protected. What are the RPC Firewall Components?

It is made up from 3 components:

* RpcFwManager.exe – In charge of managing the RPC Firewall.
* RpcFirewall.dll – Injected DLL which performs the audit & filtering of RPC calls.
* RpcMessages.dll – A common library for sharing functions, and logic that writes data into Windows Event Viewer. How to use? Installing / Uninstalling

Installation simply drops the RPC Firewall DLLs into the %SystemRoot%\System32, and configures the RPCFWP application log for the Event Viewer.

Make sure the event viewer is closed during install/uninstall.

RpcFwManager.exe /install

Uninstalling does the opposite.

RpcFwManager.exe /uninstall

Protecting Process(es)

The RpcFwManager tried to inject the rpcFirewall.dll only to processes which have the RPCRT4.DLL loaded into them.

Once the rpcFirewall.dll is loaded, it verifies that the host process has a valid RPC interface, and is listening for remote connections.

Otherwise, the rpcFirewall.dll unloaded itself from the target process.

If the process is a valid RPC server, the rpcFirewall starts to audit & monitor incoming RPC calls, according to the configuration file.

To protect a single process by pid:

RpcFwManager.exe /pid

To protect a single process by name:

RpcFwManager.exe /process

To protect all process, simply leave the or parametes blank.

RpcFwManager.exe /process
RpcFwManager.exe /pid

Unprotecting Processes

To disable the RPC Firewall, either uninstall it, or use the unprotect parameter:

RpcFwManager.exe /unprotect

This will unload the rpcFirewall.dll from all processes. Persistency
RPC Firewall is not persistent on its own. One method of making sure that processes are continuesly protected is to create a scheduled task that executes a protection command. The following is a powershell command which does just that, just replace match a specific uuid
* opnum -> match a RPC opnum
* addr -> match a remote IP address
* action -> can be either allo[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials RPC Firewall : Stopping Lateral Movement via the RPC Firewall RPC Firewall is the underlying mechanism which is used for numerous lateral movement techniques, reconnaissances, relay attacks, or simply to exploit vulnerable RPC services.…
w or block (default allow)
* audit -> true or false, controls whether events are written to the RPCFWP log (default false)
* verbose -> when true, outputs debug informaiton for specific RPC calls (default false)

The configuration order is important, as the first match determines the outcome of the RPC call.

For example, the following configuration will protect a DC from a DCSync attack by disabling the MS-DRSR UUID from non-domain machines. Also, notice that audit is enabled only for blocked MS-DRSR attempts, which could alert your SOC to a potential attack!

uuid:e3514235-4b06-11d1-ab04-00c04fc2dcd2 addr: action:allow
uuid:e3514235-4b06-11d1-ab04-00c04fc2dcd2 addr: action:allow
uuid:e3514235-4b06-11d1-ab04-00c04fc2dcd2 action:block audit:true

Whenever the configuration changes, you need to notify the rpcFirewall.dll via the update command:

RpcFwManager.exe /update Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Msmailprobe : Office 365 And Exchange Enumeration

Msmailprobe is widely known that OWA (Outlook Web app) is vulnerable to time-based user enumeration attacks. This tool leverages all known, and even some lesser-known services exposed by default Exchange installations to enumerate users. It also targets Office 365 for error-based user enumeration.

Getting Started

If you want to download and compile the simple, non-dependant code, you must first install GoLang! I will let the incredible documentation, and other online resources help you with this task.

https://golang.org/doc/install

You may also download the compiled release here.

Syntax

List examples of commands for this applications, but simply running the binary with the examplescommand:

./msmailprobe examples

You can also get more specific help by running the binary with the arguments you are interested in:

./msmailprobe identify
./msmailprobe userenum
./msmailprobe userenum –onprem
./msmailprobe userenum –o365

Usage

Identify Command

* Used for gathering information about a host that may be pointed towards an Exchange or o365 tied domain
* Queries for specific DNS records related to Office 365 integration
* Attempts to extract internal domain name for onprem instance of Exchange
* Identifies services vulnerable to time-based user enumeration for onprem Exchange
* Lists password-sprayable services exposed for onprem Exchange host

Flag to use:
-t to specify target host
Example:
./msmailprobe identify -t mail.target.com

Userenum (o365) Command

* Error-based user enumeration for Office 365 integrated email addresses

Flags to use:
-E for email list OR -e for single email address
-o [optional]to specify an out file for valid emails identified
–threads [optional] for setting amount of requests to be made concurrently
Examples:
./msmailprobe userenum –o365 -E emailList.txt -o validemails.txt –threads 25
./msmailprobe userenum –o365 -e admin@target.com

Userenum (onprem) Command

* Time-based user enumeration against multiple onprem Exchange services

Flags to use:
-t to specify target host
-U for user list OR -u for single username
-o [optional]to specify an out file for valid users identified
–threads [optional] for setting amount of requests to be made concurrently
Examples:
./msmailprobe userenum –onprem -t mail.target.com -U userList.txt -o validusers.txt –threads 25
./msmailprobe userenum –onprem -t mail.target.com -u admin
Download

___________________________
@hacking_Attack
@Hacking_Video
For people who do pentesting as a job, how frequently do you use Hydra?
https://www.reddit.com/r/Pentesting/comments/t23oox/for_people_who_do_pentesting_as_a_job_how/

Hello all of your wonderful red teamers, I'm on the blue side of the house. I'm going through hackthebox to widen my skills and better understand what's attackers are doing, and to have a bit of fun. I'm wondering how much people really use tools like Hydra in their pentesting gigs. ​ Kind regards submitted by /u/sma92878 (https://www.reddit.com/user/sma92878)
[link] (https://www.reddit.com/r/Pentesting/comments/t23oox/for_people_who_do_pentesting_as_a_job_how/) [comments] (https://www.reddit.com/r/Pentesting/comments/t23oox/for_people_who_do_pentesting_as_a_job_how/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Mifare classic card reading data

I have a mifare classic card I want to view the data from. I tried mfoc and it's ending with a error. So I tried milazycracker and that also ends with the same error after the first 13 keys. It does not go through to hardnested, just does mfoc.

So now I have mfcuk running and the guide says approx 30min but it's been running for more than 3 hours now and all I see is

Let me entertain you Uid 96475b1e Type 08 Key 000000000000 Block 03 Diff Nt 20798 (counting up) Auths 20798 (counting up)

Am I on the right track or just waisting time here?

Kali Linux Live usb on Intel i7 16gb ram, pn532 usb version.

submitted by /u/Dutchy_79
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video