Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
'Preparation, not panic': Top US cyber official asks Americans to look out for Russian hacking efforts
https://external-preview.redd.it/H2AKXTzQdPHgOv_YB7U5zPhcToi5U_Ieqy6F7mrVBs8.jpg?width=640&crop=smart&auto=webp&s=5b34dc902850720bad992f1c247d754eda0d16c3 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
'Preparation, not panic': Top US cyber official asks Americans to look out for Russian hacking efforts
https://external-preview.redd.it/H2AKXTzQdPHgOv_YB7U5zPhcToi5U_Ieqy6F7mrVBs8.jpg?width=640&crop=smart&auto=webp&s=5b34dc902850720bad992f1c247d754eda0d16c3 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
'Preparation, not panic': Top US cyber official asks Americans to...
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 1 comment
How I got my First Bounty (Open Redirect)
I was trying to find a good program to hunt on Hackerone. Then, I found a program. let's call it example.com. I was testing every link and…Continue reading on Medium »
Read more...
I was trying to find a good program to hunt on Hackerone. Then, I found a program. let's call it example.com. I was testing every link and…Continue reading on Medium »
Read more...
How I got my First Bounty (Open Redirect)
https://vamshi-vemula.medium.com/how-i-got-my-first-bounty-open-redirect-80832e5bf4e6?source=rss------bug_bounty-5
I was trying to find a good program to hunt on Hackerone. Then, I found a program. let's call it example.com. I was testing every link and…Continue reading on Medium » (https://vamshi-vemula.medium.com/how-i-got-my-first-bounty-open-redirect-80832e5bf4e6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://vamshi-vemula.medium.com/how-i-got-my-first-bounty-open-redirect-80832e5bf4e6?source=rss------bug_bounty-5
I was trying to find a good program to hunt on Hackerone. Then, I found a program. let's call it example.com. I was testing every link and…Continue reading on Medium » (https://vamshi-vemula.medium.com/how-i-got-my-first-bounty-open-redirect-80832e5bf4e6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I got my First Bounty (Open Redirect)
I was trying to find a good program to hunt on Hackerone. Then, I found a program. let's call it example.com. I was testing every link and…
TOP 10 Linux Utilities for Bugbounty/Hacking.
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…Continue reading on Medium »
Read more...
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
DipDucky - Rubber Ducky with multiple payloads
https://external-preview.redd.it/Kk3VafiYtpgkIkPjinCpX-qKcqQ29m7s8PI1O5LlnBo.jpg?width=640&crop=smart&auto=webp&s=741c3600ff717f4dd73f839975a6c6d6959b8dc7 submitted by /u/Tompazi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
DipDucky - Rubber Ducky with multiple payloads
https://external-preview.redd.it/Kk3VafiYtpgkIkPjinCpX-qKcqQ29m7s8PI1O5LlnBo.jpg?width=640&crop=smart&auto=webp&s=741c3600ff717f4dd73f839975a6c6d6959b8dc7 submitted by /u/Tompazi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
DipDucky - Rubber Ducky with multiple payloads
Posted in r/hacking by u/Tompazi • 2 points and 1 comment
hacking: security in practice
Hey!
Sorry if this is a stupid questions, but is it possible to find a hacker and pay him to enter someones social media account? Not to do any harm just find out some truths.
All the best
submitted by /u/JoseCastoll
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hey!
Sorry if this is a stupid questions, but is it possible to find a hacker and pay him to enter someones social media account? Not to do any harm just find out some truths.
All the best
submitted by /u/JoseCastoll
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hey!
Sorry if this is a stupid questions, but is it possible to find a hacker and pay him to enter someones social media account? Not to do any harm...
TOP 10 Linux Utilities for Bugbounty/Hacking.
https://sm4rty.medium.com/top-10-linux-utilities-for-bugbounty-hacking-dbef7ae28a28?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sm4rty.medium.com/top-10-linux-utilities-for-bugbounty-hacking-dbef7ae28a28?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
TOP 10 Linux Utilities for Bugbounty/Hacking.
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…Continue reading on Medium » (https://sm4rty.medium.com/top-10-linux-utilities-for-bugbounty-hacking-dbef7ae28a28?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
TOP 10 Linux Utilities for Bugbounty/Hacking.
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…
Nimcrypt2 - .NET, PE, And Raw Shellcode Packer/Loader Written In Nim
http://www.kitploit.com/2022/03/nimcrypt2-net-pe-and-raw-shellcode.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/nimcrypt2-net-pe-and-raw-shellcode.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Nimcrypt2 - .NET, PE, And Raw Shellcode Packer/Loader Written In Nim
Nimcrypt2 is yet another PE packer/loader designed to bypass AV/EDR. It is an improvement on my original Nimcrypt (https://github.com/icyguider/nimcrypt) project, with the main improvements being the use of direct syscalls (https://www.kitploit.com/search/label/Syscalls) and the ability to load regular PE files as well as raw shellcode. Before going any further, I must acknowledge those who did the VAST majority of work and research (https://www.kitploit.com/search/label/Research) that this project depends on. Firstly, I must thank @byt3bl33d3r (https://twitter.com/byt3bl33d3r) for his Offensive Nim repo (https://github.com/byt3bl33d3r/OffensiveNim), and @ShitSecure (https://twitter.com/ShitSecure) for all of the code snippets he's publicly released. That is what the original version of this tool was created from, and the current version is no different. Particularly, the new PE loading functionality used in this tool is just an implementation of ShitSecure's recently released Nim-RunPE (https://github.com/S3cur3Th1sSh1t/Nim-RunPE) code. I highly encourage sponsoring him for access to his own Nim PE Packer (https://twitter.com/ShitSecure/status/1482428360500383755), which is no doubt a much better and more featureful version of this.
Additionally, I would like to thank @ajpc500 (https://twitter.com/ajpc500) for his NimlineWhispers2 (https://github.com/ajpc500/NimlineWhispers2) project that this tool uses for direct syscalls. I cannot stress enough how this project is simply an amalgamation of the public work of those previously mentioned, so all credit must go to them. ] [-p ] [-n] [-u] [-s] [-v] nimcrypt (-h | --help) Options: -h --help Show this screen. --version Show version. -f --file filename File to load -t --type filetype Type of file (csharp, raw, or pe) -p --process process Name of process for shellcode injection -o --output filename Filename for compiled exe -u --unhook Unhook ntdll.dll -v --verbose Enable verbose messages during execution -n --no-randomization Disable syscall name randomization -s --no-sandbox Disable sandbox checks"> ___
.-' `'.
/ \
| ;
| | ___.--,
_.._ |0) ~ (0) | _.---'`__.-( (_.
__.--'`_.. '.__.\ '--. \_.-' ,.--'` `""`
( ,.--'` ',__ /./; ;, '.__.'` __
_`) ) .---.__.' / | |\ \__..--"" ""'--.,_
`---' .'.''-._.-'`_./ /\ '. \ _.-~~~````~~~-._`-.__.'
| | .' _.-' | | \ \ '. `~---`
\ \/ .' \ \ '. '-._)
\/ / \ \ `=.__`~-. Nimcrypt v2
jgs / /\ `) ) / / `"".`\
, _.-'.'\ \ / / ( ( / / 3-in-1 C#, PE, & Raw Shellcode Loader
`--~` ) ) .-'.' '.'. | (
(/` ( (` ) ) '-;
` '-; (-'
Nimcrypt v 2.0
Usage:
nimcrypt -f file_to_load -t csharp/raw/pe [-o ] [-p ] [-n] [-u] [-s] [-v]
nimcrypt (-h | --help)
Options:
-h --help Show this screen.
--version Show version.
-f --file filename File to load
-t --type filetype Type of file (csharp, raw, or pe)
-p --process process Name of process for shellcode injection
-o --output filename Filename for compiled exe
-u --unhook Unhook ntdll.dll
___________________________
@hacking_Attack
@Hacking_Video
Additionally, I would like to thank @ajpc500 (https://twitter.com/ajpc500) for his NimlineWhispers2 (https://github.com/ajpc500/NimlineWhispers2) project that this tool uses for direct syscalls. I cannot stress enough how this project is simply an amalgamation of the public work of those previously mentioned, so all credit must go to them. ] [-p ] [-n] [-u] [-s] [-v] nimcrypt (-h | --help) Options: -h --help Show this screen. --version Show version. -f --file filename File to load -t --type filetype Type of file (csharp, raw, or pe) -p --process process Name of process for shellcode injection -o --output filename Filename for compiled exe -u --unhook Unhook ntdll.dll -v --verbose Enable verbose messages during execution -n --no-randomization Disable syscall name randomization -s --no-sandbox Disable sandbox checks"> ___
.-' `'.
/ \
| ;
| | ___.--,
_.._ |0) ~ (0) | _.---'`__.-( (_.
__.--'`_.. '.__.\ '--. \_.-' ,.--'` `""`
( ,.--'` ',__ /./; ;, '.__.'` __
_`) ) .---.__.' / | |\ \__..--"" ""'--.,_
`---' .'.''-._.-'`_./ /\ '. \ _.-~~~````~~~-._`-.__.'
| | .' _.-' | | \ \ '. `~---`
\ \/ .' \ \ '. '-._)
\/ / \ \ `=.__`~-. Nimcrypt v2
jgs / /\ `) ) / / `"".`\
, _.-'.'\ \ / / ( ( / / 3-in-1 C#, PE, & Raw Shellcode Loader
`--~` ) ) .-'.' '.'. | (
(/` ( (` ) ) '-;
` '-; (-'
Nimcrypt v 2.0
Usage:
nimcrypt -f file_to_load -t csharp/raw/pe [-o ] [-p ] [-n] [-u] [-s] [-v]
nimcrypt (-h | --help)
Options:
-h --help Show this screen.
--version Show version.
-f --file filename File to load
-t --type filetype Type of file (csharp, raw, or pe)
-p --process process Name of process for shellcode injection
-o --output filename Filename for compiled exe
-u --unhook Unhook ntdll.dll
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - icyguider/nimcrypt: PE Crypter written in Nim
PE Crypter written in Nim. Contribute to icyguider/nimcrypt development by creating an account on GitHub.
-v --verbose Enable verbose messages during execution< br/> -n --no-randomization Disable syscall name randomization
-s --no-sandbox Disable sandbox checks
Features: NtQueueApcThread Shellcode Execution w/ PPID Spoofing (https://www.kitploit.com/search/label/Spoofing) & 3rd Party DLL Blocking Syscall Name Randomization Ability to load .NET and Regular PE Files AES Encryption (https://www.kitploit.com/search/label/Encryption) with Dynamic Key Generation Sandbox Evasion Tested and Confirmed Working on: Windows 11 (10.0.22000) Windows 10 21H2 (10.0.19044) Windows 10 21H1 (10.0.19043) Windows 10 20H2 (10.0.19042) Windows 10 19H2 (10.0.18363) Windows Server 2019 (10.0.17763) Installation/Dependencies: Nimcrypt2 is designed to be used on Linux systems with Nim installed. Before installing Nim, you must ensure that you have the following packages installed via your package manager: sudo apt install gcc mingw-w64 xz-utils git
To install Nim, I prefer to use choosenim (https://github.com/dom96/choosenim) as follows: > ~/.bashrc export PATH=$HOME/.nimble/bin:$PATH'>curl https://nim-lang.org/choosenim/init.sh -sSf | sh
echo "export PATH=$HOME/.nimble/bin:$PATH" >> ~/.bashrc
export PATH=$HOME/.nimble/bin:$PATH
Nimcrypt2 also depends on a few packages that can be installed via Nimble. This can be done like so: nimble install winim nimcrypto docopt ptr_math
With all the dependencies now installed, Nimcrypt2 can be compiled like so: nim c -d=release --cc:gcc --embedsrc=on --hints=on --app=console --cpu=amd64 --out=nimcrypt nimcrypt.nim
Known Bugs: As described (https://github.com/S3cur3Th1sSh1t/Nim-RunPE/blob/a117ecec635824703047c1d850607bdf2cfa628b/README.md?plain=1#L13) by ShitSecure, if the release version of mimikatz is loaded via the PE loader, it will not accept commands for some unknown reason. Using a version of mimikatz that was compiled from source fixes this issue. Greetz & Credit: @byt3bl33d3r (https://twitter.com/byt3bl33d3r) for their Offensive Nim project: https://github.com/byt3bl33d3r/OffensiveNim @ShitSecure (https://twitter.com/ShitSecure) for their Nim-RunPE project: https://github.com/S3cur3Th1sSh1t/Nim-RunPE @ajpc500 (https://twitter.com/ajpc500) for their NimlineWhispers2 project: https://github.com/ajpc500/NimlineWhispers2 @Snovvcrash (https://twitter.com/snovvcrash) for their NimHollow (https://www.kitploit.com/search/label/NimHollow) project: https://github.com/snovvcrash/NimHollow
Download Nimcrypt2 (https://github.com/icyguider/Nimcrypt2)
___________________________
@hacking_Attack
@Hacking_Video
-s --no-sandbox Disable sandbox checks
Features: NtQueueApcThread Shellcode Execution w/ PPID Spoofing (https://www.kitploit.com/search/label/Spoofing) & 3rd Party DLL Blocking Syscall Name Randomization Ability to load .NET and Regular PE Files AES Encryption (https://www.kitploit.com/search/label/Encryption) with Dynamic Key Generation Sandbox Evasion Tested and Confirmed Working on: Windows 11 (10.0.22000) Windows 10 21H2 (10.0.19044) Windows 10 21H1 (10.0.19043) Windows 10 20H2 (10.0.19042) Windows 10 19H2 (10.0.18363) Windows Server 2019 (10.0.17763) Installation/Dependencies: Nimcrypt2 is designed to be used on Linux systems with Nim installed. Before installing Nim, you must ensure that you have the following packages installed via your package manager: sudo apt install gcc mingw-w64 xz-utils git
To install Nim, I prefer to use choosenim (https://github.com/dom96/choosenim) as follows: > ~/.bashrc export PATH=$HOME/.nimble/bin:$PATH'>curl https://nim-lang.org/choosenim/init.sh -sSf | sh
echo "export PATH=$HOME/.nimble/bin:$PATH" >> ~/.bashrc
export PATH=$HOME/.nimble/bin:$PATH
Nimcrypt2 also depends on a few packages that can be installed via Nimble. This can be done like so: nimble install winim nimcrypto docopt ptr_math
With all the dependencies now installed, Nimcrypt2 can be compiled like so: nim c -d=release --cc:gcc --embedsrc=on --hints=on --app=console --cpu=amd64 --out=nimcrypt nimcrypt.nim
Known Bugs: As described (https://github.com/S3cur3Th1sSh1t/Nim-RunPE/blob/a117ecec635824703047c1d850607bdf2cfa628b/README.md?plain=1#L13) by ShitSecure, if the release version of mimikatz is loaded via the PE loader, it will not accept commands for some unknown reason. Using a version of mimikatz that was compiled from source fixes this issue. Greetz & Credit: @byt3bl33d3r (https://twitter.com/byt3bl33d3r) for their Offensive Nim project: https://github.com/byt3bl33d3r/OffensiveNim @ShitSecure (https://twitter.com/ShitSecure) for their Nim-RunPE project: https://github.com/S3cur3Th1sSh1t/Nim-RunPE @ajpc500 (https://twitter.com/ajpc500) for their NimlineWhispers2 project: https://github.com/ajpc500/NimlineWhispers2 @Snovvcrash (https://twitter.com/snovvcrash) for their NimHollow (https://www.kitploit.com/search/label/NimHollow) project: https://github.com/snovvcrash/NimHollow
Download Nimcrypt2 (https://github.com/icyguider/Nimcrypt2)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Different parsers, different results
https://medium.com/@nnez/different-parsers-different-results-acecf84dfb0c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@nnez/different-parsers-different-results-acecf84dfb0c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Different parsers, different results
TLDR; I found a critical vulnerability on GearBox protocol, result from different parsers of path parameters used between GearBox adapter…
TLDR; I found a critical vulnerability on GearBox protocol, result from different parsers of path parameters used between GearBox adapter…Continue reading on Medium » (https://medium.com/@nnez/different-parsers-different-results-acecf84dfb0c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Different parsers, different results
TLDR; I found a critical vulnerability on GearBox protocol, result from different parsers of path parameters used between GearBox adapter…
Hacking on Medium
Thehackinghub ; Making Human Existence Easier Through Cyber Solutions
TheHackingHub may be a stage with well experienced cyber specialists that are accessible circular the clock for contract to solve any…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Thehackinghub ; Making Human Existence Easier Through Cyber Solutions
TheHackingHub may be a stage with well experienced cyber specialists that are accessible circular the clock for contract to solve any…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Thehackinghub ; Making Human Existence Easier Through Cyber Solutions
TheHackingHub may be a stage with well experienced cyber specialists that are accessible circular the clock for contract to solve any…
Hacking on Medium
Top 3 Fundamental Skills To Get Started Into Cybersecurity.
So, hey fella people today we will be looking at top 3 cybersecurity fundamental skills to have in 2022 which will help you understand the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 3 Fundamental Skills To Get Started Into Cybersecurity.
So, hey fella people today we will be looking at top 3 cybersecurity fundamental skills to have in 2022 which will help you understand the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 3 Fundamental Skills To Get Started Into Cybersecurity.
So, hey fella people today we will be looking at top 3 cybersecurity fundamental skills to have in 2022 which will help you understand the…
Hacking on Medium
TOP 10 Linux Utilities for Bugbounty/Hacking.
https://cdn-images-1.medium.com/max/1292/0*N_Aq04ySgNGbgFZE
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TOP 10 Linux Utilities for Bugbounty/Hacking.
https://cdn-images-1.medium.com/max/1292/0*N_Aq04ySgNGbgFZE
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TOP 10 Linux Utilities for Bugbounty/Hacking.
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing some of the common…