Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Leaks database

A few weeks ago I found an incredible website that shows the leaks files where a specific email has been used. The website is https://intelx.io

However it is not that user friendly, is there any other alternative to said website? Or in alternative a resource that contains leaked passwords? Kinda like the rockyou list?

The alternative would be somehow download every possible file from https://intelx.io and use a script to fetch the passwords into a wordlist.

Cheers bP

submitted by /u/brunommpreto
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty: How to get private invites

Now I know that a lot of people will not like this answer and you certainly do not have to follow this method if you don’t wish to.Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
A Comprehensive Backup Strategy Includes SaaS Data, Source Code

Backups aren't just limited to hard drives, databases and servers. This Tech Tip describes how organizations should expand their backup strategies.
The goal is simple
To share my modest knowledge about hacking Windows systems. This is commonly refered to as red team exercises. This book however, is also very concerned with the blue team; the defenders. That is, helping those who are working as defenders, analysts and security experts to build secure Active Directory (https://www.kitploit.com/search/label/Active%20Directory) environments and monitor them for malicious activity. There are three major parts in this book Building a lab Hacking it Defending it I have structured this book so it can be followed more or less sequentally. To practice many of these things, a lab is necessary. That is why I have made a few guides on how to build a lab, with varying degrees of comprehensiveness and size. Getting started GETTING STARTED (https://github.com/chryzsh/DarthSidious/blob/master/getting-started/getting-started.md) Getting the Source Code The source for this book is available in the book's github repository (https://github.com/chryzsh/DarthSidious). Changelog Date Who What May 2017 chryzsh Book created March 2018 chryzsh Restructured book 30.03.2018 bufferov3rride Added article Pivoting Through Exchange (https://github.com/chryzsh/DarthSidious/blob/master/initial-access/initial-access-through-exchange.md) 02.04.2018 chryzsh Restructured book again and removed some unfinished articles 11.04.2018 chryzsh Added the article Building a (https://github.com/chryzsh/DarthSidious/tree/fdd707cf9dbbc2faf3cf3dbbcd712b06fceeee87/labs/labs/cuckoo-malware-analysis-lab.md)malware analysis (https://www.kitploit.com/search/label/Malware%20Analysis) lab 14.04.2018 chryzsh Added the article Password (https://github.com/chryzsh/DarthSidious/blob/master/credential-access/password-cracking-and-auditing.md)cracking (https://www.kitploit.com/search/label/Cracking) and auditing 23.04.2018 filippos Added the article CrackMapExec (https://github.com/chryzsh/DarthSidious/blob/master/execution/crackmapexec.md) 06.05.2018 chryzsh Fixed a link messup and some restructuring Questions/Suggestions: Ping me on Twitter @chryzsh (https://twitter.com/chryzsh)

Download DarthSidious (https://github.com/chryzsh/DarthSidious)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
DarthSidious - Building An Active Directory Domain And Hacking It

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNqHK3M2bbVYYgon7HLQelOgEJO_DimClCLX80AVnt-UwNkgLAhk-jQ-jHdNwAwzaU6GlH7vPLVjAjLrxG6MfbRFUSJDK6acKTy5FnUTxfjzMEI4l72S1FNlXzRgVP-a36QbEESJIqcxpkWRmFM5i76uzEt64RLy2PwKBpQNP80xRvvSm7bM3F_6q2/w640-h516/DarthSidious.png
The goal is simple
To share my modest knowledge about hacking Windows systems. This is commonly refered to as red team exercises. This book however, is also very concerned with the blue team; the defenders. That is, helping those who are working as defenders, analysts and security experts to build secure Active Directory environments and monitor them for malicious activity.

There are three major parts in this book

1. Building a lab
2. Hacking it
3. Defending it

I have structured this book so it can be followed more or less sequentally. To practice many of these things, a lab is necessary. That is why I have made a few guides on how to build a lab, with varying degrees of comprehensiveness and size.

Getting started

GETTING STARTED

Getting the Source Code

The source for this book is available in the book's github repository.

Changelog
Date Who What May 2017 chryzsh Book created March 2018 chryzsh Restructured book 30.03.2018 bufferov3rride Added article Pivoting Through Exchange 02.04.2018 chryzsh Restructured book again and removed some unfinished articles 11.04.2018 chryzsh Added the article Building a malware analysis lab 14.04.2018 chryzsh Added the article Password cracking and auditing 23.04.2018 filippos Added the article CrackMapExec 06.05.2018 chryzsh Fixed a link messup and some restructuring
Questions/Suggestions: Ping me on Twitter @chryzsh
Download DarthSidious

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Are wordlist attacks towards WPA2 even practical when pen testing a company?

Assuming that this company doesn’t have a password like “abc123” would a wordlist/dictionary attack be practical when trying to gain access to their network? What other ways could one go about cracking WPA2 ?

submitted by /u/MojoSiwa
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
https://b.thumbs.redditmedia.com/6uO2j_vLF7JcdST3ZkA162eQuoDHwAqWf6sTulUD1Jc.jpg This is the growtopia exe that you can open multiple window/instance of growtopia



made possible through reverse engineering.

You can use this for farming bot purposes , DDOSING the growtopia server if you have to LOL



and run multiple account :)

to use this just download this exe and replace the exe at the growtopia folder with

https://preview.redd.it/cqk34rva5qr81.png?width=1365&format=png&auto=webp&s=37450879092d6e24e31df6746481c0582fe335b3

the new exe



This is not a virus, you can check it through virustotal.com



[Download link](https://drive.google.com/file/d/1d9zrPqdvbp5XZxZkePM4OMqPbaDSKjH9/view?usp=sharing)



Credit : (open the credit window in growtopia)

submitted by /u/minotokagumi
[link] [comments]
hacking: security in practice
can my employers monitor everything on my work laptop?

I'm not sure if this is the right sub. Yesterday, I went to CR just quick while my laptop was open with low volume of music from spotify, I came back and noticed that the spotify wasn't playing anymore, and checked that it was logged out. Spotify is allowed, and Facebook is, I think, allowed because I sometimes communicate with colleagues through that platform. I'm just a bit woried that they can access my personal accounts that easy. Can my employers have access to my social media through other computers?

submitted by /u/VitreousHaha
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
What is the optimal way to connect to always traveling device regardless the firewall?

In my LAN I've SSH access ass well x11vnc and want to be able to do the same thing when the victim is outside of the LAN regardless the what type of a network/firewall victim use for connection at the time. I understand that to be able to bypass all the firewall regardless the network victim would have to initiate connection first to some kind of a server - RPI or some small VPS with at least Wireguard VPN server running.

This is learning project and I have full physical access to victims system(ubuntu and macos), there are few things that comes to my mind but I'm not sure if that's the best way:

1. On victims device I would run Cron job every 5 min executing bash script with:

* init SSH connection (ssh/mosh)?
* init Wireguard connection and create some sort of a split tunnel for attacker only and victim would using regular connection so there would not be any slow down on their side - is that even possible and would I have unrestricted access to the victims underlying network as well or just VPN tunnel?

Does any of this make sense or there are better ways?

submitted by /u/No-Race8789
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
i have ip and location

i have my friend's ip and location how do i access his pc , i want to prank him or smth

submitted by /u/ThatIsNotIllegal
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Friends using each other’s network to learn. Any pointers?

Basically the title. My friend and I have been using each other’s network and computers to learn new techniques such as nmap, SET, and trying to use shells. We both get on a discord call and give each other permission to try “XYZ”.

Does anyone have any experience with this? Learning with a friend? Also, are there any other methods or pointers that we could use that would increase our skills without destroying our systems? We are both using Kali currently. Thanks!

submitted by /u/MifistoScared
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video