Hacking on Medium
How to Protect Yourself from Ransomware?
https://cdn-images-1.medium.com/max/600/0*cRSokVIHH9IVO30R.png
A rise in the number of ransomware attacks on governments, businesses, hospitals, and private individuals is being seen. It has grown into…
Continue reading on Medium »
How to Protect Yourself from Ransomware?
https://cdn-images-1.medium.com/max/600/0*cRSokVIHH9IVO30R.png
A rise in the number of ransomware attacks on governments, businesses, hospitals, and private individuals is being seen. It has grown into…
Continue reading on Medium »
Medium
How to Protect Yourself from Ransomware?
A rise in the number of ransomware attacks on governments, businesses, hospitals, and private individuals is being seen. It has grown into…
Hacking on Medium
Yogi’s Twitter account hacked
https://cdn-images-1.medium.com/max/900/0*lso5sbrmlGzABEUx.jpg
Continue reading on Medium »
Yogi’s Twitter account hacked
https://cdn-images-1.medium.com/max/900/0*lso5sbrmlGzABEUx.jpg
Continue reading on Medium »
Medium
Yogi’s Twitter account hacked
BY A STAFF REPORTER: There was a rift in the BJP. This time Twitter account of Uttar Pradesh Chief Minister Yogi Adityanath’s twitter account was hacked. The official Twitter account of the Uttar Pradesh Chief Minister’s office was hacked in the early hours…
hacking: security in practice
Is it possible to do this↓?
I want to modify the social networks to avoid my brain getting dumber. Since I need to use them for my job, I want to be able to filter the Instagram (example) content. This means, deleting the 🔍 and only being able to see the accounts I choose.
Also having the possibility of blocking all the content and only using the chat and the stories would be really interesting.
I have seen app blockers but never an inside-app blocker.
submitted by /u/DzyPassio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to do this↓?
I want to modify the social networks to avoid my brain getting dumber. Since I need to use them for my job, I want to be able to filter the Instagram (example) content. This means, deleting the 🔍 and only being able to see the accounts I choose.
Also having the possibility of blocking all the content and only using the chat and the stories would be really interesting.
I have seen app blockers but never an inside-app blocker.
submitted by /u/DzyPassio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to do this↓?
I want to modify the social networks to avoid my brain getting dumber. Since I need to use them for my job, I want to be able to filter the...
hacking: security in practice
Possible new T-mobile phone # scam?
Hey guys, I'm new here but I just came across a scam and I'd like your input on it. So yesterday and today I received a text message in a group chat I was brought into that stated that my bill for the month of March has been paid(even though I'm not the one paying the phone bill). I knew this was a scam but I wanted to look into it because as I already mentioned this was in a group chat. So I ran the links through Virus Total and the report said there was no malware on the sites. I then looked into the status of these websites and they came back invalid. The next thing I did was run a background check on the number that started the group chat I was brought into today. I also checked some of the other numbers that responded with "stop" just to make sure I wasn't being fooled. The number that started the group chat came back as "unknown" and was said to have most likely been based in New York. The other numbers were real but, they could have had their T-mobile accounts compromised and had their phone numbers stolen. The only thing I noticed we all had in common was that our service provider was T-mobile or owned by T-mobile(ex. Metropcs). I went on google and found out that these kinds of scams have been happening for a while. But what makes this different(at least to me) is that in the previous scams it was never mentioned where these numbers are coming from. In this one, not only does it claim to be from T-mobile. The scam number is provided/serviced by T-mobile. I don't know if I'm overthinking this or not but I'd like some outside input. Also, one of the sites I used claims it is 90% sure the scam number is a CLEC(Competitive Local Exchange Carrier), don't know if that changes anything. Thank you for your time.
submitted by /u/MUGGYtheREAPER
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Possible new T-mobile phone # scam?
Hey guys, I'm new here but I just came across a scam and I'd like your input on it. So yesterday and today I received a text message in a group chat I was brought into that stated that my bill for the month of March has been paid(even though I'm not the one paying the phone bill). I knew this was a scam but I wanted to look into it because as I already mentioned this was in a group chat. So I ran the links through Virus Total and the report said there was no malware on the sites. I then looked into the status of these websites and they came back invalid. The next thing I did was run a background check on the number that started the group chat I was brought into today. I also checked some of the other numbers that responded with "stop" just to make sure I wasn't being fooled. The number that started the group chat came back as "unknown" and was said to have most likely been based in New York. The other numbers were real but, they could have had their T-mobile accounts compromised and had their phone numbers stolen. The only thing I noticed we all had in common was that our service provider was T-mobile or owned by T-mobile(ex. Metropcs). I went on google and found out that these kinds of scams have been happening for a while. But what makes this different(at least to me) is that in the previous scams it was never mentioned where these numbers are coming from. In this one, not only does it claim to be from T-mobile. The scam number is provided/serviced by T-mobile. I don't know if I'm overthinking this or not but I'd like some outside input. Also, one of the sites I used claims it is 90% sure the scam number is a CLEC(Competitive Local Exchange Carrier), don't know if that changes anything. Thank you for your time.
submitted by /u/MUGGYtheREAPER
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Possible new T-mobile phone # scam?
Hey guys, I'm new here but I just came across a scam and I'd like your input on it. So yesterday and today I received a text message in a group...
hacking: security in practice
self signed SSL Cert found in router
so i found a self signed ssl cert trusted by our root CA in our router today. Its obviously fake, any idea what the implications of that would be, or what could be done with such a thing?
submitted by /u/u_b_dat_boi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
self signed SSL Cert found in router
so i found a self signed ssl cert trusted by our root CA in our router today. Its obviously fake, any idea what the implications of that would be, or what could be done with such a thing?
submitted by /u/u_b_dat_boi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
self signed SSL Cert found in router
so i found a self signed ssl cert trusted by our root CA in our router today. Its obviously fake, any idea what the implications of that would be,...
hacking: security in practice
Curious as to how I was compromised.
Background info I try take my cybersecurity pretty strict. Just finished sec+, have complex password, 2 FA + authentication app.
Woke up to my Instagram being hacked. What I thought was very very suspicious was the attacker, had created an new gmail with my first + middle + last name. The last name was misspelled. However…. I do not advertise my middle name anywhere. Additionally, my insta account is my first initial and not my complete last name. Example if my name is John Doe I had my insta set up as J.Do. Whoever hacked my Instagram account knew my complete name? They also went as far as to create a new gmail address using my name? I had received no notifications that my original email on my insta account had be changed or that 2 FA was turned off. Additionally my username was changed. The hacker had complete access to my account for 6 hours and all they did was unfollowed one person. I am very curious as to how this is possible, I am a bit embarrassed as I am wanting to work in the cybersecurity field. Would love anyones thoughts.
submitted by /u/Meowsters
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Curious as to how I was compromised.
Background info I try take my cybersecurity pretty strict. Just finished sec+, have complex password, 2 FA + authentication app.
Woke up to my Instagram being hacked. What I thought was very very suspicious was the attacker, had created an new gmail with my first + middle + last name. The last name was misspelled. However…. I do not advertise my middle name anywhere. Additionally, my insta account is my first initial and not my complete last name. Example if my name is John Doe I had my insta set up as J.Do. Whoever hacked my Instagram account knew my complete name? They also went as far as to create a new gmail address using my name? I had received no notifications that my original email on my insta account had be changed or that 2 FA was turned off. Additionally my username was changed. The hacker had complete access to my account for 6 hours and all they did was unfollowed one person. I am very curious as to how this is possible, I am a bit embarrassed as I am wanting to work in the cybersecurity field. Would love anyones thoughts.
submitted by /u/Meowsters
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Curious as to how I was compromised.
Background info I try take my cybersecurity pretty strict. Just finished sec+, have complex password, 2 FA + authentication app. Woke up to my...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
An interview with Jim Browning, the man who scams the scammers
https://external-preview.redd.it/V2Ba_hf2DtNqU2Un7u3Dmy-s4AgLDox9MXeh9BE4ogs.jpg?width=640&crop=smart&auto=webp&s=07f1b132641b2fe6fbb034a6d933f651cc28bf5a submitted by /u/snm729
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
An interview with Jim Browning, the man who scams the scammers
https://external-preview.redd.it/V2Ba_hf2DtNqU2Un7u3Dmy-s4AgLDox9MXeh9BE4ogs.jpg?width=640&crop=smart&auto=webp&s=07f1b132641b2fe6fbb034a6d933f651cc28bf5a submitted by /u/snm729
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
An interview with Jim Browning, the man who scams the scammers
Posted in r/hacking by u/snm729 • 1 point and 0 comments
การอัปเดตความปลอดภัย LayerZero — เมษายน 2022
สัปดาห์ที่ผ่านมาแสดงให้เราเห็นว่าไม่มีอะไรสำคัญไปกว่าความมุ่งมั่นที่จะประเมินและปรับปรุงการรักษาความปลอดภัยอย่างต่อเนื่องในพื้นที่นี้…Continue reading on Medium »
Read more...
สัปดาห์ที่ผ่านมาแสดงให้เราเห็นว่าไม่มีอะไรสำคัญไปกว่าความมุ่งมั่นที่จะประเมินและปรับปรุงการรักษาความปลอดภัยอย่างต่อเนื่องในพื้นที่นี้…Continue reading on Medium »
Read more...
การอัปเดตความปลอดภัย LayerZero — เมษายน 2022
https://medium.com/@ekimzimi/%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B8%AD%E0%B8%B1%E0%B8%9B%E0%B9%80%E0%B8%94%E0%B8%95%E0%B8%84%E0%B8%A7%E0%B8%B2%E0%B8%A1%E0%B8%9B%E0%B8%A5%E0%B8%AD%E0%B8%94%E0%B8%A0%E0%B8%B1%E0%B8%A2-layerzero-%E0%B9%80%E0%B8%A1%E0%B8%A9%E0%B8%B2%E0%B8%A2%E0%B8%99-2022-e4eb9d32094d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ekimzimi/%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B8%AD%E0%B8%B1%E0%B8%9B%E0%B9%80%E0%B8%94%E0%B8%95%E0%B8%84%E0%B8%A7%E0%B8%B2%E0%B8%A1%E0%B8%9B%E0%B8%A5%E0%B8%AD%E0%B8%94%E0%B8%A0%E0%B8%B1%E0%B8%A2-layerzero-%E0%B9%80%E0%B8%A1%E0%B8%A9%E0%B8%B2%E0%B8%A2%E0%B8%99-2022-e4eb9d32094d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
การอัปเดตความปลอดภัย LayerZero — เมษายน 2022
สัปดาห์ที่ผ่านมาแสดงให้เราเห็นว่าไม่มีอะไรสำคัญไปกว่าความมุ่งมั่นที่จะประเมินและปรับปรุงการรักษาความปลอดภัยอย่างต่อเนื่องในพื้นที่นี้…
สัปดาห์ที่ผ่านมาแสดงให้เราเห็นว่าไม่มีอะไรสำคัญไปกว่าความมุ่งมั่นที่จะประเมินและปรับปรุงการรักษาความปลอดภัยอย่างต่อเนื่องในพื้นที่นี้…Continue reading on Medium » (https://medium.com/@ekimzimi/%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B8%AD%E0%B8%B1%E0%B8%9B%E0%B9%80%E0%B8%94%E0%B8%95%E0%B8%84%E0%B8%A7%E0%B8%B2%E0%B8%A1%E0%B8%9B%E0%B8%A5%E0%B8%AD%E0%B8%94%E0%B8%A0%E0%B8%B1%E0%B8%A2-layerzero-%E0%B9%80%E0%B8%A1%E0%B8%A9%E0%B8%B2%E0%B8%A2%E0%B8%99-2022-e4eb9d32094d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
การอัปเดตความปลอดภัย LayerZero — เมษายน 2022
สัปดาห์ที่ผ่านมาแสดงให้เราเห็นว่าไม่มีอะไรสำคัญไปกว่าความมุ่งมั่นที่จะประเมินและปรับปรุงการรักษาความปลอดภัยอย่างต่อเนื่องในพื้นที่นี้…
Hacking on Medium
Chrome Needs An Update — Otherwise Crypto Attacks Are Imminent
https://cdn-images-1.medium.com/max/2600/0*WnjsRBilrFpu7iEz
Millions of users have been urged to update their Google Chrome browsers after security researchers discovered a flaw that would put them…
Continue reading on The Crypto Paper »
___________________________
@hacking_Attack
@Hacking_Video
Chrome Needs An Update — Otherwise Crypto Attacks Are Imminent
https://cdn-images-1.medium.com/max/2600/0*WnjsRBilrFpu7iEz
Millions of users have been urged to update their Google Chrome browsers after security researchers discovered a flaw that would put them…
Continue reading on The Crypto Paper »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Chrome Needs An Update — Otherwise Crypto Attacks Are Imminent
Millions of users have been urged to update their Google Chrome browsers after security researchers discovered a flaw that would put them…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
A Detailed Guide on Responder (LLMNR Poisoning)
IntroductionResponder is a widely used tool in penetration test scenarios and can be used for lateral movement across the network by red teamers. The tool contains many useful features like LLMNR, NT-NS and MDNS poisoning. It is used in practical scenarios for objectives like hash capture or poisoned answer forwarding supporting various AD attacks. The tool contains various built-in servers like HTTP, SMB, LDAP, DCE-RPC Auth server etc. In this article, we will cover a majority of these attacks that can be performed while being aided by responder.Table of content· LLMNR, NBT-NS, MDNS and DHCP· Responder Installation· Attack 1: LLMNR/NBT-NS Poisoning through SMB· Attack 2: LLMNR/NBT-NS Poisoning through WPAD· Responder Analyze Mode· Responder Basic Authentication Mode· Responder Downgrade NTLMv2-SSP to NTLMv2· Responder external IP poisoning· Responder Multi-Relay: Shell on a system· Responder DNS injection in DHCP response· What are these servers in responder?· Recommendations· ConclusionLLMNR is a protocol which allows name resolution without the requirement of a DNS server. It is able to provide a hostname-to-IP based off a multicast packet sent across the network asking all listening Network-Interfaces to reply if they are authoritatively known as the hostname in the query. It does this by sending a network packet to port UDP 5355 to the multicast network address. It allows IPv4 and IPv6 hosts and supports all current and future DNS formats, types, and classes. It is the successor of NBT-NS.NBT-NS: NetBIOS name service (NBT-NS) is a Windows protocol which is used to translate NetBIOS names to IP addresses on a local network. It is analogous to what DNS does on internet. Each machine is assigned a NetBIOS name by the NBT-NS service. Works on UDP port 137. It is the predecessor of LLMNR.MDNS: Multicast DNS (mDNS) is a protocol aimed at helping with name resolution in networks. It doesn’t query a name server, rather, multicasts the queries to all the clients in a network directly. In multicast, an individual message is aimed directly at a group of recipients. When a connection between sender and recipient is made, all participants are informed of the connection between the name and IP address, and can make a corresponding entry in their mDNS cache.LLMNR/NBT-NS Poisoning: Let’s say a victim wants to connect to a shared drive \\wow so it sends the request to the DNS server. The only problem is that DNS can’t connect to \\wowas it doesn’t exist. Therefore, server replies back saying he it can’t connect the victim to \\wow. Thereafter, the victim will multicast this request to the entire network (using LLMNR) in case any particular user knows the route to the shared drive (\\wow).DHCP Poisoning: Dynamic Host Client Protocol (DHCP) is used to provide a host with its IP address, subnet mask, gateway etc. Windows uses multiple custom DHCP options like NetBIOS, WPAD etc. By poisoning th[...]
___________________________
@hacking_Attack
@Hacking_Video
A Detailed Guide on Responder (LLMNR Poisoning)
IntroductionResponder is a widely used tool in penetration test scenarios and can be used for lateral movement across the network by red teamers. The tool contains many useful features like LLMNR, NT-NS and MDNS poisoning. It is used in practical scenarios for objectives like hash capture or poisoned answer forwarding supporting various AD attacks. The tool contains various built-in servers like HTTP, SMB, LDAP, DCE-RPC Auth server etc. In this article, we will cover a majority of these attacks that can be performed while being aided by responder.Table of content· LLMNR, NBT-NS, MDNS and DHCP· Responder Installation· Attack 1: LLMNR/NBT-NS Poisoning through SMB· Attack 2: LLMNR/NBT-NS Poisoning through WPAD· Responder Analyze Mode· Responder Basic Authentication Mode· Responder Downgrade NTLMv2-SSP to NTLMv2· Responder external IP poisoning· Responder Multi-Relay: Shell on a system· Responder DNS injection in DHCP response· What are these servers in responder?· Recommendations· ConclusionLLMNR is a protocol which allows name resolution without the requirement of a DNS server. It is able to provide a hostname-to-IP based off a multicast packet sent across the network asking all listening Network-Interfaces to reply if they are authoritatively known as the hostname in the query. It does this by sending a network packet to port UDP 5355 to the multicast network address. It allows IPv4 and IPv6 hosts and supports all current and future DNS formats, types, and classes. It is the successor of NBT-NS.NBT-NS: NetBIOS name service (NBT-NS) is a Windows protocol which is used to translate NetBIOS names to IP addresses on a local network. It is analogous to what DNS does on internet. Each machine is assigned a NetBIOS name by the NBT-NS service. Works on UDP port 137. It is the predecessor of LLMNR.MDNS: Multicast DNS (mDNS) is a protocol aimed at helping with name resolution in networks. It doesn’t query a name server, rather, multicasts the queries to all the clients in a network directly. In multicast, an individual message is aimed directly at a group of recipients. When a connection between sender and recipient is made, all participants are informed of the connection between the name and IP address, and can make a corresponding entry in their mDNS cache.LLMNR/NBT-NS Poisoning: Let’s say a victim wants to connect to a shared drive \\wow so it sends the request to the DNS server. The only problem is that DNS can’t connect to \\wowas it doesn’t exist. Therefore, server replies back saying he it can’t connect the victim to \\wow. Thereafter, the victim will multicast this request to the entire network (using LLMNR) in case any particular user knows the route to the shared drive (\\wow).DHCP Poisoning: Dynamic Host Client Protocol (DHCP) is used to provide a host with its IP address, subnet mask, gateway etc. Windows uses multiple custom DHCP options like NetBIOS, WPAD etc. By poisoning th[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
A Detailed Guide on Responder (LLMNR Poisoning)
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog A Detailed Guide on Responder (LLMNR Poisoning) IntroductionResponder is a widely used tool in penetration test scenarios and can be used for lateral movement across the network by red teamers. The tool contains many useful…
e DHCP response, an attacker would be able to help victim pinpoint its own rogue server for any kind of authentication. In turn, compromising the credentials.Responder InstallationInitially developed by SpiderLabs and now being developed by Laurent Gaffie (lgandx), responder is a python coded tool which can be found here. The tool comes built-in Kali OS. Responder.exe (Windows version) of the same can be found here.responder -hhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMdkuUouM8mVXnU_M0aSA58AgPqfdc6ViKx1v6O-_GzFN7aUwnvm4pztXOlOG0wFsotcYjIOHon9umSJnI7NuXBsLd1MWJ9mVuPCaAt054AIIq0_-FY2HSPlmO97g-QZlyKDKupmhdsPvAuI5OirmsezAGyn8VMCU_fGm7ow5SHg7iuJNeiYAcD5zxtw/s16000/1.png Attack 1: LLMNR/NBT-NS Poisoning through SMBEssentially when a system tries to access an SMB share, it sends a request to the DNS server which then resolves the share name to the respective IP address and the requesting system can access it. However, when the provided share name doesn’t exist, the system sends out an LLMNR query to the entire network. This way, if any user(IP address) has access to that share, it can reply and provide the communication to the requestor.responder -I eth0https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8rSxYx0GVfXz6W5907NN5x_n1AOhAICepo6t5OubuU9xpih2Zo9s9m2kF2eq8vBOJOUD2VKEqASl9ZbGJTm84Cvke2lxZTpDrUc-zkf1Exs4QLiSHQQcM_7I1vEFeMbJAUr4g4OQrlo7rtdB49gv-ZUAs9hNaEjFFX9AOntC2TSCI3v0p6jL-ycw75g/s16000/3.png Now, when the victim tries to access shared drive “wow” he sees this! Wow has suddenly been made available and the poisoner asking for user credentials.hashcat -m 5600 hash.txt /usr/share/wordlists/rockyou.txthttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSR7vZLixbRxRQRUgE4Wli_MT1JIBNZNZf4CGLnwbodOeaqaoFpZC7G74jvyKP_nm1l7zV4awzfZwpvQDznmvseka_wmUYTSoyp-5Dpo5gJYoEG4SL1uvFEA3DpWb_ZWfj6GxpxQAMBhw9VTQpjd3Z0xYA_Q9Ev4WB1_yEAahB9oDs4lk2LjHpoHxI5g/s16000/6.png As you can see, password has now been obtained which is Password@1https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFXo7GTNv0Qkk9hryJmd2cU8caRbACms0XMYIX2xVHKSrQi9dytDxv26dABbSy8XNI1dWG[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
e DHCP response, an attacker would be able to help victim pinpoint its own rogue server for any kind of authentication. In turn, compromising the credentials.Responder InstallationInitially developed by SpiderLabs and now being developed by Laurent Gaffie…
jmyEXnLtABsWR-He91p09L44lR-ZsVQjRFrw970Fzmfm7WxwJo5mSIPDgwgTN7HQj2PhmRUhy1mNj4joJpVn_HwWsX6Nh-zFE5lHuZP54v3g5Ta0bUcz5w/s16000/7.png Furthermore, responder creates logs of every sessions and all the hashes thus dumped can be seen under the folder /usr/share/responder/logshttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2_OmCmAS87AokK3bcm_H7ni328yUo_zABgh5a5DWIZbit_SW-8BvO49DAdqGkyPLLkEY9qQeXjaCmbGDljZgf5efw-Ulb-2MDjxRA0vAkUGONj5JW5SOyoL328o7AB3PjBGdR2ZcCrULgSq7lf9Fx9A9LDx-mtBT1RqhOh2sx_xgPvt0WrWix5ds_sQ/s16000/8.png Attack 2: LLMNR/NBT-NS Poisoning through WPADWeb Proxy Autodiscovery Protocol is a method used by a browser to automatically locate and interface with cache services in a network so that information is delivered quickly. WPAD by default uses DHCP to locate a cache service to facilitate straightforward connectivity and name resolution.Attack: To configure WPAD rogue proxy server we use the -w option. Furthermore, we added an optional switch of DHCP injection. This switch would inject rogue proxy’s address (kali IP) in the DHCP response. The attack could still work without this switch.responder -I eth0 -wdhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnV2okcE5GQHOMfODfMVdW26OkUKM1GDK2gb2Fy4qh1TyCiTnccmAJC4x9UuUP5evlPyqGHnyCvAuXiXU9RF_Nspd-1BmEloS5M9oNtGfY1mqSpRg9IZUxF3IKNdVNp2JswIazgWFo3GLhVRYi5DEWz3em8zc0_WEOBMy80IfwF6WhDxFA7z9cLXnlsg/s16000/9.png As you can see above, that DHCP poisoner and WPAD proxy have now been turned on. Now, when a user inputs any wrong URL, lets say, randomurl.local, browser couldn’t locate it. Responder poisons and injects DHCP response with WPAD’s IP and the browser tries to authenticate to the WPAD server and gives a login prompt.hashcat -m 5600 HTTP-NTLMv2-fe80::ddc5:3b8f:e421:a88a.txt /usr/share/wordlists/rockyou.txthttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSeuUPL41x8-4E_puFlUlyoYeCOrt3EIa7F_U0EtrO-_AS-nX9CengCfGrqTJEBIl0sVjUXwHQDE8KZj6_HqQd1km0DjiSqq3vo-yx[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
jmyEXnLtABsWR-He91p09L44lR-ZsVQjRFrw970Fzmfm7WxwJo5mSIPDgwgTN7HQj2PhmRUhy1mNj4joJpVn_HwWsX6Nh-zFE5lHuZP54v3g5Ta0bUcz5w/s16000/7.png Furthermore, responder creates logs of every sessions and all the hashes thus dumped can be seen under the folder /usr/shar…
5l0R5Fyr5D52VE8nhs1uC6wqSmUHw5TWx4wSA0ltAmLFYAulmHsUahzSqeX5r1mMhoKL2-o1IBaIDtIfhQZSnQ/s16000/13.png Hash has been cracked and clear text password dumped!Responder Analyze ModeIn the analyze mode, responder doesn’t automatically poison the LLMNR requests, rather it tracks the network flow of the requests made in order to give essential information like name of the user, machine account being used, name of the DC, OS version etc. It can be switched on using -A switchresponder -I eth0 -Ahttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOuNR1FbiOdh6wCLhAWYXnvHCkpf4MgsEhub-mhhNCBgxX7AdHrNDhXBDWryBxke-s-ycmqzBEHA45T6qugSJgS4m_99btwwCM4b2pRBdExjyC6iWcViPi3bTW6q7JxfYFQmVuOHD2oUgh0SIzND4aO7hgCkP40m6veA8x5o-hahscsu-qao5JsjLHyQ/s16000/15.png When a victim tried to access wrong sharename (Attack 1 method), responder analyses the entire flow and gives us the DC name, Windows OS version etc.Responder Basic Authentication ModeIn attack 2, we saw how an NTLM authentication windows was opened when our rogue WPAD proxy server was being accessed by poisoning LLMNR. In turn, we were able to retrieve the NTLMv2 hashes. We will imitate the same attack but this time, try to gain clear text credentials of the user using basic authentication! This can be achieved using the -b flag. Further, we are using -F switch to force basic authentication!responder -I eth0 -wdF -bhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOpPK0XcbbInB5BoRS8VhcgsvIaFW4Kk4tlRo3V-7I87WH04pztzwZ-7kStR2uvijvqay7Bbaf7_R7IFnkiYulx1jYorRaTbaNidLf7wUYCXdDLEScfNVKs5xRE6lhDapkBetYXxajfy8sz7Ir5Bt1CWRQjqRSOTF5v9FBqMGOHw2IGRG5uh_vDKvu2A/s16000/17.png Now, when a user tries to access any invalid URL, he sees the following prompt with the message saying that these credentials would be sent in clear text using basic authentication.Responder Downgrade NTLMv2-SSP to NTLMv2NTLM provides ESS functionality (Extended Session Security) which adds to the complexity of the NTLM hash. ESS functionality adds an “SSP” flag in the NTLM hash (NTLM2-SSP). This increases the length of our NTLM hash in turn increasing complexity to crack the hash. We can configure Responder to use simple NTLMv2 (without ESS) which would result in lower time complexity to crack hashes.responder -I eth0 -wdF --lm --disable-esshttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglJ1KdgpOp_SetRFRiiZD0ia-5kjaDV870C8HA0QjOWFlAAsc4Lhf3-LCgchtZTKdjvJVT-pNHJQcL6G5slsM5MyohwZLnDN3SNvoSVSYA7K0eqMoV-_pZ-C29aPCtf4sat6VolBjnVOWdgSEF8uOp1Dje886FvCYIcm[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
5l0R5Fyr5D52VE8nhs1uC6wqSmUHw5TWx4wSA0ltAmLFYAulmHsUahzSqeX5r1mMhoKL2-o1IBaIDtIfhQZSnQ/s16000/13.png Hash has been cracked and clear text password dumped!Responder Analyze ModeIn the analyze mode, responder doesn’t automatically poison the LLMNR requests,…
b81Z10-vbpRBHdTSYjgkVNJg/s16000/20.png This would give the user a pop-upResponder external IP poisoningResponder can be used to send LLMNR poisoned requests to the victim that contains another IP than the one we are currently using. It creates stealth and allows us to conduct more sophisticated attacks. This can be done using “-e” optionresponder -I eth0 -e 192.168.1.2https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxl09uRWgufZvXGFjV4F1MEhiIRMZstEW9MlUYP6Wd1qQGmrXgqcHnzvXUwIAOeSS5FcfdEbb15XhI5JM4DKPuy9Azjb-HgZpNHKPcgR8I73jutGNDWxCcRicW3O1yMy3mfh0_d7MMdUGMfzVWkudltvqounStnk9_ocCU8riWEpQJZQkljFhSrgLWKw/s16000/24.png Responder multi-relay: shell on a systemRelaying is one of the most commonly used techniques used for credential access. A relay or forwarder receives valid authentication and then forwards that request to another server/system and tries to authenticate to that server/system by using the valid credentials so received. In Attack 1, we used an invalid SMB share to get hashes of the requesting system.apt-get install gcc-mingw-w64-x86-64 -o get-pip.pyOnce its done, we can run MultiRelay.py without any errors or warnings.cd /usr/share/responder/toolshttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiclVu9C20yW4shf3dcR6kX2OeHEPwrJKYA2MlLFh8Keuo809U7gvLRHx9gPUbh-kTOPsd0fTZKEQvYgEiSEFZI9UKX1ACjrAL3P-ayg2l1kOgzgH4E_m6skzGh7oKra4i8ITjcZvfk6S5iUe8yRu0iP0jniDfWYEeuaiFV3DzhyK4s15jmKe5X5MD5vg/s16000/25.png Now, first criteria for this attack to work with SMB is that SMB signing has to be disabled. It is disabled by default so that checks our ease to exploit. It can be tested using the nmap script smb-security-mode nmap -p445 --script=smb-security-mode 192.168.1.3https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlrXdd01W44BylxgFDszgZzY7s_AadUOWiwWxzZpLDuw8GSrYXTI7J0FfX5RYyD6VGp_ip4IOdL0HKoZCtncpxgI0MeNxAuitzoVzrYe_9zJ7u1-3GQd3CedMw-gLpADeKorZ2smWWJ9dI9HFRq0bZavAY4ap1aiI76hbhk4F4JNWBPDexBHh0Nh206w/s16000/26.png As you ca[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
b81Z10-vbpRBHdTSYjgkVNJg/s16000/20.png This would give the user a pop-upResponder external IP poisoningResponder can be used to send LLMNR poisoned requests to the victim that contains another IP than the one we are currently using. It creates stealth and…
n see, SMB signing is disabled so the coast is cleared. We can run MultiRelay now. To run it we need to specify the target using “-t” and “-u” specifies users to which relay is to be forwarded. You can choose selectively too and create lesser noise in network.python3 MultiRelay.py -t 192.168.1.3 -u ALLhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZS7_orMHDvH0Ct64Qldv-js4GPXBBopDv0E5JyT4fgy0ojvQ9rBx1dyPHl1N7m80iPjpJLnpcQdOu4UKg3GaFQ6I2BMDoQU4wNHtKFNFkiHHogt8HY_IIa7gisJm1zhkovgcRikDc2utV4w0rL4OaiMADFowNPrYyuj0IOx0TRTuyPg0NfUVnt4v3pg/s16000/27.png As you can see above, the script has detected my victim’s OS, computer account name (workstation01) and SMB signing status too. One other thing to note here is that this script is using HTTP and SMB ports. So, to prevent any conflict, we need to turn these servers OFF in responder.conf file. We just open the file in /usr/share/responder/Responder.conf and turn off HTTP and SMB. If done properly, when we launch responder next time, an OFF switch like this shall be there.responder -I eth0https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ94WfyBjVthLSbN5RPjcE9ey4fOg7AgbUfyHkTs-vZXUGEexUGpLex01jw-kMuF69RUZJ4of-COrrzpNc8RApKEr-G4Q5ZITwLAljee8TfAQV8Xy-MHSNrdMwYTNPbxo-WBXXVFoTqhaRINvTBHJLt4wSbtXcsFreljTJM-5XTJq0UzFOMguVr54FLg/s16000/28.png Now, an administrator tries to open a shared drive. He is unsuccessful as the share wowowow doesn’t exist! So, responder intervenes and poisons requests successfully.Responder DNS injection in DHCP responseIn the event where DHCP is being used to identify the IP which is hosting, let’s say, an SMB drive called “wow” (refer attack 1), responder can also inject a rogue DNS record in DHCP responses. responder -I eth0 -Dhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGAi6-2EZiRxVZD0edpvgVSGMFzKjrn8fkYNTBTf7XNcEL4-PyiUAMCnhl3tpO6AK4X5MdEn_Kg0ZkDXH1XKlOSai0O4KWdFUCfCmwf5-yQd3lDH9PeeYPrrmP6C64hWtSObcaAYBJgTYfKtyTOeGHxIPigaxXKbYKGD3C-MusyOYUMU1Ty1ukQhtMmg/s16000/32.png When the victim accesses any invalid share, a prompt is now visible.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video