Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
GIF
Kali Linux Tutorials
FakeLogonScreen : Fake Windows Logon Screen To Steal Passwords

FakeLogonScreen is a utility to fake the Windows logon screen in order to obtain the user’s password. The password entered is validated against the Active Directory or local machine to make sure it is correct and is then displayed to the console or saved to disk.

It can either be executed by simply running the .exe file, or using for example Cobalt Strike’s execute-assemblycommand.

Binaries available from the Releases page.

* FakeLogonScreen.exe: Writes output to console which for example is compatible with Cobalt Strike
* FakeLogonScreenToFile.exe: Writes output to console and %LOCALAPPDATA%\Microsoft\user.db

Folders:

* / (root): Built against .NET Framework 4.5 which is installed by default in Windows 8, 8.1 and 10
* DOTNET35: Built against .NET Framework 3.5 which is installed by default in Windows 7

Features

* Primary display shows a Windows 10 login screen while additional screens turn black
* If custom background is configured by the user, shows that background instead of the default one
* Validates entered password before closing the screen
* Username and passwords entered are outputted to console or stored in a file
* Blocks many shortkeys to prevent circumventing the screen
* Minimizes all existing windows to avoid other windows staying on top

Screenshot
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1qbrmH9hGfEghIBQ0I81rmMDj7Eag1_iKG-MlpczGewtijQsXCCTUY2X2cPjjp3Sx2wPqBGbcqHJtkowlI9q1cnAuTlEHsJ6kmki8CncjjrJVHKSqAvnqZgQ1O3SUixbvPtwSCGmaKwxS3t9v8l77aVn4gvW0ljW6h0pDnHXWueX9x46AuxXh-RtT/s1280/demo.gif

Download

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is hacking wrong?

I’m not a hacker or anything but I was just wondering. Is it wrong? It’s cool and all and you can use it for something good but idk. What do you guys do? Hack into your neighbors WiFi? I don’t understand.

submitted by /u/cucOmbermint
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Did this link do anything bad to my device?

I saw a fake elon musk tweet that tells you to visit muskbc.com for free btc, which I did out of curiosity. The website loaded for a long time but did nothing. Can someone skilled let me know if this was a virus or not?

submitted by /u/slomorosh
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
RTLO Injection URI Spoofing

https://4.bp.blogspot.com/-SxgEc7szt9w/WWlva1nZfUI/AAAAAAAAIPE/UrvwYC_4YmMlGypxS9ASHy318XWSifzEQCLcBGAs/s1600/h71.png
RTLO injection URI spoofing generator for WhatsApp, iMessage, Instagram, and Facebook Messenger.

MD5 | 6c508227541dc40dd1944f191db714a4

Download
# Exploit Title: WordPress Plugin Jetpack 9.1 - Cross Site Scripting (XSS)
# Date: 2022-02-07
# Author: Milad karimi
# Software Link: https://wordpress.org/plugins/jetpack
# Version: 9.1
# Tested on: Windows 11
# CVE: N/A

1. Description:
This plugin creates a Jetpack from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.

2. Proof of Concept:
http://localhost/modules/contact-form/grunion-form-view.php?post_id=


Source:packetstormsecurity.com
Dark Reading: Attacks/Breaches
HR Alone Can't Solve the Great Resignation

Here's how IT teams and decision-makers can step up to support the workforce. Creating a culture of feedback and introducing automation can mitigate burnout, inspire employees, and reduce turnover.
Wep Cracking
https://www.reddit.com/r/Pentesting/comments/tnsbhj/wep_cracking/

<!-- SC_OFF -->Hello, I have a Cap file with only 3 packets. I am trying to break a WEP encryption using aircrack-ng to get the key. However it does not have enough IVs. Is there any way to crack it without more IVs or to generate fake IVs somehow. Keep in mind I do not have access to the network and can't use monitor mode or inject any packets. I only have the Cap file. <!-- SC_ON --> submitted by /u/Smakernamat (https://www.reddit.com/user/Smakernamat)
[link] (https://www.reddit.com/r/Pentesting/comments/tnsbhj/wep_cracking/) [comments] (https://www.reddit.com/r/Pentesting/comments/tnsbhj/wep_cracking/)