Building a Red Team - Which C2 to pick?
https://www.reddit.com/r/redteamsec/comments/ta3htj/building_a_red_team_which_c2_to_pick/
Hello redteamsec community, my company wants to enhance the actual security testing services from basic assessments and penetration tests to red team engagements. At the moment we are planning the Red Team Infrastructure and I am currently looking for the best pick of a C2 Framework. I checked out the following: - Covenenat - PoshC2 - Metasploit (if you can call it C2, you know what I mean) Further on my list are: - Cobalt Strike - SilentTrinity - APfeil - FactionC2 - Merlin What gives me a hard time is, how to decide on the framework we want to run? Thats why I ask you, what you guys recommend and WHY. Regards! submitted by /u/larryxt (https://www.reddit.com/user/larryxt)
[link] (https://www.reddit.com/r/redteamsec/comments/ta3htj/building_a_red_team_which_c2_to_pick/) [comments] (https://www.reddit.com/r/redteamsec/comments/ta3htj/building_a_red_team_which_c2_to_pick/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ta3htj/building_a_red_team_which_c2_to_pick/
Hello redteamsec community, my company wants to enhance the actual security testing services from basic assessments and penetration tests to red team engagements. At the moment we are planning the Red Team Infrastructure and I am currently looking for the best pick of a C2 Framework. I checked out the following: - Covenenat - PoshC2 - Metasploit (if you can call it C2, you know what I mean) Further on my list are: - Cobalt Strike - SilentTrinity - APfeil - FactionC2 - Merlin What gives me a hard time is, how to decide on the framework we want to run? Thats why I ask you, what you guys recommend and WHY. Regards! submitted by /u/larryxt (https://www.reddit.com/user/larryxt)
[link] (https://www.reddit.com/r/redteamsec/comments/ta3htj/building_a_red_team_which_c2_to_pick/) [comments] (https://www.reddit.com/r/redteamsec/comments/ta3htj/building_a_red_team_which_c2_to_pick/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Building a Red Team - Which C2 to pick?
Posted by u/larryxt - 28 votes and 21 comments
hacking: security in practice
Don't remember how to see locked content for free
I know this is against the rules but don't know where to ask. There was a way you could get access to any content in Google by adding something to the URL. I think it was like 12.io , does anybody know please?
submitted by /u/mauricio_es_yo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Don't remember how to see locked content for free
I know this is against the rules but don't know where to ask. There was a way you could get access to any content in Google by adding something to the URL. I think it was like 12.io , does anybody know please?
submitted by /u/mauricio_es_yo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Don't remember how to see locked content for free
I know this is against the rules but don't know where to ask. There was a way you could get access to any content in Google by adding something to...
hacking: security in practice
Hashcat
Hi where is the pot file in Hashcat I can’t find it I am very new to hacking pls help ( I’m testing on my own accounts)
submitted by /u/Historical_Guide_723
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hashcat
Hi where is the pot file in Hashcat I can’t find it I am very new to hacking pls help ( I’m testing on my own accounts)
submitted by /u/Historical_Guide_723
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hashcat
Hi where is the pot file in Hashcat I can’t find it I am very new to hacking pls help ( I’m testing on my own accounts)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Downloaded a 'song' from a SoundCloud to Mp3 site and some code downloaded instead. Does anyone know if the code is malicious? Mp3 converter site link is attached below.
https://external-preview.redd.it/4BHdjlwWilhCnRt6wYjurwEEV71IFtBGmYMHZhgOiE8.jpg?width=640&crop=smart&auto=webp&s=b1fe285d709489221aa396eaf1fa016ffe012574 submitted by /u/FairestHarbor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Downloaded a 'song' from a SoundCloud to Mp3 site and some code downloaded instead. Does anyone know if the code is malicious? Mp3 converter site link is attached below.
https://external-preview.redd.it/4BHdjlwWilhCnRt6wYjurwEEV71IFtBGmYMHZhgOiE8.jpg?width=640&crop=smart&auto=webp&s=b1fe285d709489221aa396eaf1fa016ffe012574 submitted by /u/FairestHarbor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Downloaded a 'song' from a SoundCloud to Mp3 site and some code...
Posted in r/hacking by u/FairestHarbor • 1 point and 0 comments
hacking: security in practice
How to Protect yourself from Being caught?
can anyone tell me all thing i make sure to do before i grab my hands on something . i am beginner so test my skills or to test tool
submitted by /u/UnkownWithUnkownprsn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to Protect yourself from Being caught?
can anyone tell me all thing i make sure to do before i grab my hands on something . i am beginner so test my skills or to test tool
submitted by /u/UnkownWithUnkownprsn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to Protect yourself from Being caught?
can anyone tell me all thing i make sure to do before i grab my hands on something . i am beginner so test my skills or to test tool
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Conti Ransomware Gang
Per many requests - I have made a brief video about Conti Ransomware group that is highly addressed in the news lately. So who are they? How come they catch headlines so frequently now? What tactics and method do they use? And what we can expect to see down the road ?
https://youtu.be/3jDtDaPn6B4
submitted by /u/OkFaithlessness2414
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Conti Ransomware Gang
Per many requests - I have made a brief video about Conti Ransomware group that is highly addressed in the news lately. So who are they? How come they catch headlines so frequently now? What tactics and method do they use? And what we can expect to see down the road ?
https://youtu.be/3jDtDaPn6B4
submitted by /u/OkFaithlessness2414
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Conti Ransomware Gang
Per many requests - I have made a brief video about Conti Ransomware group that is highly addressed in the news lately. So who are they? How come...
hacking: security in practice
What kind of hack is this?
Since time ago, I keep having emails that says that someone is trying to get into my accounts, they had my password for instagram, Amazon and other accounts, good that google never let them get it, and I denied the access and change my passwords. But this morning I got many emails that got me worry, I got about 30 or more emails from different online stores of all kind, that wanted me to confirm my email account, in a lot of different languages, I did not click any link, but the emails seems to came from oficial sites. The also want me to confirm my account from some weird data base pages, and some pages that say that are to make fast shopping online, also some weird emails from different languages that have a username and password. I’m worry I don’t know what are they trying to do, I changed some more password today, please I will appreciate any information.
submitted by /u/Swirlmind
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What kind of hack is this?
Since time ago, I keep having emails that says that someone is trying to get into my accounts, they had my password for instagram, Amazon and other accounts, good that google never let them get it, and I denied the access and change my passwords. But this morning I got many emails that got me worry, I got about 30 or more emails from different online stores of all kind, that wanted me to confirm my email account, in a lot of different languages, I did not click any link, but the emails seems to came from oficial sites. The also want me to confirm my account from some weird data base pages, and some pages that say that are to make fast shopping online, also some weird emails from different languages that have a username and password. I’m worry I don’t know what are they trying to do, I changed some more password today, please I will appreciate any information.
submitted by /u/Swirlmind
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What kind of hack is this?
Since time ago, I keep having emails that says that someone is trying to get into my accounts, they had my password for instagram, Amazon and...
hacking: security in practice
Been PWNED. My journey through getting my info off of a leaked database.
I would say im a novice to the hacking community. Ive tinkered with some Wireshark and started dipping my toes into Kali Linux before some other priorities fell into my lap, and here I am a few years later after never getting back into it.
Nonetheless!
Some account information was leaked in a databreach. Here's the breach:
Warning: Porn Ads. Pop ups. Etc. Run of the mill stuff. https://www.freeaccounts.bi3.shop/p/all-free-account.html
I wont say where my info is on the site for obvious reasons.
Now I admit, ive been aware of that breach for some time now. I wasnt too concerned because the account was very old, and the password that was leaked I only used for random things when I was a student. But a few days ago, a got an email alerting me of a login through my ancient Grammarly account. Low and behold that account used the same login info. I finally got my wisdom teeth pulled, so im taking some time out of the office. I figured this would be a fun project to take on while I swallow Advil like tic tacs. Heres what i've found/done so far:
- Whois search
No luck. I personally dont know whats going on with this URL. But I couldnt find any info on this sucker on any conventional whois websites
- Reporting the website
I tried reporting the website to Google, just because i'd feel a little better if the info was viewable on the most used search engine. They determined it wasn't against their terms. Which...I mean. Yeah whatever.
- Following the yellow brick road
I joined the Discord/Telegram group. Now this was interesting. I found myself in a den of credit card info and all sorts of other scams. It was a bit odd seeing this type of thing outside of TOR, but I digress. I basically just asked the owner to take my stuff down, and he agreed! But heres the tricky part. THIS ISNT HIS WEBSITE. So this website is hosted and maintained (updated almost daily) by somoeone who literally just copies his websites content. So the owner of this Discord/Telegram deleted my info from HIS site, but of course wasnt able to do anything about the ones I was concerned about. What I also found interesting was that this page literally links you to the "legit" shop made by the real owner, where you can buy breached info. Even more interesting was that the "legit" website is brand new. The owners original one was taken down, and so he just published a new one as of 03/07? This guy is an active member.
Anyways, I then noticed this guy literally has his Facebook and Instagram on his website. Hm. They look legit. So I DMed him! (took the "honor among thieves" approach) Sent him a message on Facebook. And now im just waiting for him to see it. Looks like the accounts been dead for nearly a year. But the fact that he's so active with his updates makes me think he'll definitely see it. Whats interesting is that these accounts look personal. He has public accounts, and I believe im looking at this friends and family. I took the liberty of saving all those usernames in a .txt, as they may prove useful should things come down to...social engineering.
And thats where I am the journey now! In all honesty I think theres a solid 80% he just removes it. After all im pretty sure the only purpose for the site is to harvest ad revenue since he's not selling the information itself.
Any recommendations from you guys? Im really curious to see if this website is actually not showing up on any whois? Or if im just dumb? Maybe I just dont understand this part enough. What does a URL like this one indicate about the website? What would you guys have done differently, or in addition?
I also would like to kindly ask you all to please not contact this person or try to interfere with my attempts. I really d[...]
___________________________
@hacking_Attack
@Hacking_Video
Been PWNED. My journey through getting my info off of a leaked database.
I would say im a novice to the hacking community. Ive tinkered with some Wireshark and started dipping my toes into Kali Linux before some other priorities fell into my lap, and here I am a few years later after never getting back into it.
Nonetheless!
Some account information was leaked in a databreach. Here's the breach:
Warning: Porn Ads. Pop ups. Etc. Run of the mill stuff. https://www.freeaccounts.bi3.shop/p/all-free-account.html
I wont say where my info is on the site for obvious reasons.
Now I admit, ive been aware of that breach for some time now. I wasnt too concerned because the account was very old, and the password that was leaked I only used for random things when I was a student. But a few days ago, a got an email alerting me of a login through my ancient Grammarly account. Low and behold that account used the same login info. I finally got my wisdom teeth pulled, so im taking some time out of the office. I figured this would be a fun project to take on while I swallow Advil like tic tacs. Heres what i've found/done so far:
- Whois search
No luck. I personally dont know whats going on with this URL. But I couldnt find any info on this sucker on any conventional whois websites
- Reporting the website
I tried reporting the website to Google, just because i'd feel a little better if the info was viewable on the most used search engine. They determined it wasn't against their terms. Which...I mean. Yeah whatever.
- Following the yellow brick road
I joined the Discord/Telegram group. Now this was interesting. I found myself in a den of credit card info and all sorts of other scams. It was a bit odd seeing this type of thing outside of TOR, but I digress. I basically just asked the owner to take my stuff down, and he agreed! But heres the tricky part. THIS ISNT HIS WEBSITE. So this website is hosted and maintained (updated almost daily) by somoeone who literally just copies his websites content. So the owner of this Discord/Telegram deleted my info from HIS site, but of course wasnt able to do anything about the ones I was concerned about. What I also found interesting was that this page literally links you to the "legit" shop made by the real owner, where you can buy breached info. Even more interesting was that the "legit" website is brand new. The owners original one was taken down, and so he just published a new one as of 03/07? This guy is an active member.
Anyways, I then noticed this guy literally has his Facebook and Instagram on his website. Hm. They look legit. So I DMed him! (took the "honor among thieves" approach) Sent him a message on Facebook. And now im just waiting for him to see it. Looks like the accounts been dead for nearly a year. But the fact that he's so active with his updates makes me think he'll definitely see it. Whats interesting is that these accounts look personal. He has public accounts, and I believe im looking at this friends and family. I took the liberty of saving all those usernames in a .txt, as they may prove useful should things come down to...social engineering.
And thats where I am the journey now! In all honesty I think theres a solid 80% he just removes it. After all im pretty sure the only purpose for the site is to harvest ad revenue since he's not selling the information itself.
Any recommendations from you guys? Im really curious to see if this website is actually not showing up on any whois? Or if im just dumb? Maybe I just dont understand this part enough. What does a URL like this one indicate about the website? What would you guys have done differently, or in addition?
I also would like to kindly ask you all to please not contact this person or try to interfere with my attempts. I really d[...]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Been PWNED. My journey through getting my info off of a leaked database. I would say im a novice to the hacking community. Ive tinkered with some Wireshark and started dipping my toes into Kali Linux before some other priorities…
ont want him having a change of heart because a few of you excellent fellows threaten to hackermans his life.
Thanks all!
submitted by /u/BangkokianFool [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Thanks all!
submitted by /u/BangkokianFool [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Tracing Back an Attack
If you hack into a system, or if your system is hacked, how would you track it back? Like what's the info that is used to trace the attacker? What are the protections placed by attackers to prevent tracking them? How would you mitigate such protection?
submitted by /u/Pranav__472
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tracing Back an Attack
If you hack into a system, or if your system is hacked, how would you track it back? Like what's the info that is used to trace the attacker? What are the protections placed by attackers to prevent tracking them? How would you mitigate such protection?
submitted by /u/Pranav__472
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Tracing Back an Attack
If you hack into a system, or if your system is hacked, how would you track it back? Like what's the info that is used to trace the attacker? What...
Go Language pkg installation issue solved.
https://medium.com/@anmolshah1707/go-language-pkg-installation-issue-solved-cfd195f9f5dc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@anmolshah1707/go-language-pkg-installation-issue-solved-cfd195f9f5dc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Go Language pkg installation issue solved.
Hello Everyone, My name is Anmol Shah. I am a Penetration Tester and a Security Researcher.
Hello Everyone, My name is Anmol Shah. I am a Penetration Tester and a Security Researcher.Continue reading on Medium » (https://medium.com/@anmolshah1707/go-language-pkg-installation-issue-solved-cfd195f9f5dc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Go Language pkg installation issue solved.
Hello Everyone, My name is Anmol Shah. I am a Penetration Tester and a Security Researcher.
How I Was Able To Wipe Any Registered Account
https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium » (https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium » (https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Was Able To Wipe Any Registered Account
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.
Hacking on Medium
“Cyber Security is hacked everyday. Why is no one talking about it?”
According to an article recently published by CNBC , Samsung data was breached was hacked.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
“Cyber Security is hacked everyday. Why is no one talking about it?”
According to an article recently published by CNBC , Samsung data was breached was hacked.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Cyber Security is hacked everyday. Why is no one talking about it?”
According to an article recently published by CNBC , Samsung data was breached was hacked. Yet, this is only one of the many other articles…
Hacking on Medium
Unique WAF Bypassing Methods…!!!
https://cdn-images-1.medium.com/max/1558/1*HH-0C5nU_MdD2Um-c6xO_g.png
What is WAF…???
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Unique WAF Bypassing Methods…!!!
https://cdn-images-1.medium.com/max/1558/1*HH-0C5nU_MdD2Um-c6xO_g.png
What is WAF…???
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unique WAF Bypassing Methods…!!!
What is WAF…???
Hacking on Medium
How I created a Trojan Malware — Ethical Hacking
https://cdn-images-1.medium.com/max/700/0*lR2Byi6HLoyxpfln.png
Trojan malware, when opened appears to be a legitimate file, but in the background, it will run some evil process like gaining access etc.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
How I created a Trojan Malware — Ethical Hacking
https://cdn-images-1.medium.com/max/700/0*lR2Byi6HLoyxpfln.png
Trojan malware, when opened appears to be a legitimate file, but in the background, it will run some evil process like gaining access etc.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I created a Trojan Malware — Ethical Hacking
Trojan malware, when opened appears to be a legitimate file, but in the background, it will run some evil process like gaining access etc.
How I Was Able To Wipe Any Registered Account
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...