Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
I would like to go to further into iPhone pen-testing and would like to know if anyone has any tools or debian programs that work with the architecture of jailbroken iOS 3.1.2-15.5 on iPhone 2g-iPhone 13 Pro Max. Can also use Debian Linux files that work with the Linux sandcastle project.
https://www.reddit.com/r/Pentesting/comments/tzscxm/i_would_like_to_go_to_further_into_iphone/

submitted by /u/F1r3srp3nt_Dev (https://www.reddit.com/user/F1r3srp3nt_Dev)
[link] (https://www.reddit.com/r/Pentesting/comments/tzscxm/i_would_like_to_go_to_further_into_iphone/) [comments] (https://www.reddit.com/r/Pentesting/comments/tzscxm/i_would_like_to_go_to_further_into_iphone/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Uncover - Quickly Discover Exposed Hosts On The Internet Using Multiple Search Engine

https://blogger.googleusercontent.com/img/a/AVvXsEhRIkIidhwshIpmTPd_eWQflWfTTHmOyiJLUN0pL3PaLrjksuz3pRlkPsRz3dj1nTn9Cox7WAD9paRlDBvEWeMnSMqBZVasSvrb3HgilZzzi_lkrB1K8t-M_wBDf5lbJOVgl-fqMW132FId4mb2G2mcVgTgN8nKbzO70Rr5t1ctud2m4eZzX7Ju63W9=w640-h442 uncover is a go wrapper using APIs of well known search engines to quickly discover exposed hosts on the internet. It is built with automation in mind, so you can query it and utilize the results with your current pipeline tools. Currently, it supports shodan, censys, and fofa search engine. Features* Simple and Handy utility to query multiple search engine
* Multiple Search engine support (Shodan, Censys, Fofa)
* Automatic key/credential randomization
* stdin / stdout support for input and output Installation Instructionsuncover requires go1.17 to install successfully. Run the following command to get the repo - go install -v github.com/projectdiscovery/uncover/cmd/uncover@latestUsageuncover -hThis will display help for the tool. Here are all the flags it supports: Usage:
./uncover [flags]

Flags:
INPUT:
-q, -query string[] search query or list (file or comma separated or stdin)
-e, -engine string[] search engine to query (shodan,fofa,censys) (default shodan)

CONFIG:
-pc, -provider string provider configuration file (default "$HOME/.config/uncover/provider-config.yaml")
-config string flag configuration file (default "$HOME/.config/uncover/config.yaml")
-timeout int timeout in seconds (default 30)
-delay int delay between requests in seconds (0 to disable) (default 1)

OUTPUT:
-o, -output string output file to write found results
-f, -field string field to display in output (ip,port,host) (default ip:port)
-j, -json write output in JSONL(ines) format
-l, -limit int limit the number of results to return (default 100)
-nc, -no-color dis able colors in output

DEBUG:
-silent show only results in output
-version show version of the project
-v show verbose output
Provider ConfigurationThe default provider configuration file should be located at $HOME/.config/uncover/provider-config.yamland has the following contents as an example. In order to run this tool, the API keys / credentials needs to be added in this config file or set as environment variable. shodan:
- SHODAN_API_KEY1
- SHODAN_API_KEY2
censys:
- CENSYS_API_ID:CENSYS_API_SECRET
fofa:
- FOFA_EMAIL:FOFA_KEY
When multiple keys/credentials are specified for same provider in the config file, random key will be used for each execution.

alternatively you can also set the API key as environment variable in your bash profile. export SHODAN_API_KEY=xxx
export CENSYS_API_ID=xxx
export CENSYS_API_SECRET=xxx
export FOFA_EMAIL=xxx
export FOFA_KEY=xxx
Required keys can be obtained by signing up on Shodan, Censys, Fofa. Running Uncoveruncover supports multiple ways to make the query including stdin or qflag echo 'ssl:"Uber Technologies, Inc."' | uncover

__ ______ _________ _ _____ _____
/ / / / __ \/ ___/ __ \ | / / _ \/ ___/
/ /_/ / / / / /__/ /_/ / |/ / __/ /
\__,_/_/ /_/\___/\____/|___/\___/_/ v0.0.1
projectdiscovery.io

[WRN] Use with caution. You are responsible for your actions
[WRN] Developers assume no liability and are not responsible for any misuse or damage.
[WRN] By using uncover, you also agree to the terms of the APIs used.

107.180.12.116:993
107.180.26.155:443
104.244.99.31:443
161.28.20.79:443
104.21.8.108:443
198.71.233.203:443
104.17.237.13:443
162.255.165.171:443
12.237.119.61:443
192.169.250.211:443
104.16.251.50:443
Running uncover with file input containing multiple search queries pe[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Uncover - Quickly Discover Exposed Hosts On The Internet Using Multiple Search Engine https://blogger.googleusercontent.com/img/a/AVvXsEhRIkIidhwshIpmTPd_eWQflWfTTHmOyiJLUN0pL3PaLrjksuz3pRlkPsRz3dj1nTn9Cox7WAD9paRlDBvEWeMnSMqBZV…
r line. cat dorks.txt

ssl:"Uber Technologies, Inc."
title:"Grafana"uncover -q dorks.txt

__ ______ _________ _ _____ _____
/ / / / __ \/ ___/ __ \ | / / _ \/ ___/
/ /_/ / / / / /__/ /_/ / |/ / __/ /
\__,_/_/ /_/\___/\____/|___/\___/_/ v0.0.1
projectdiscovery.io

[WRN] Use with caution. You are responsible for your actions
[WRN] Developers assume no liability and are not responsible for any misuse or damage.
[WRN] By using uncover, you also agree to the terms of the APIs used.

107.180.12.116:993
107.180.26.155:443
104.244.99.31:443
161.28.20.79:443
104.21.8.108:443
198.71.233.203:443
2607:7c80:54:3::74:3001
104.198.55.35:80
46.101.82.244:3000
34.147.126.112:80
138.197.147.213:8086
uncover supports fieldflag to specify fields to return, currently ip, port, hostare supported. uncover -q jira -f host -silent

ec2-44-198-22-253.compute-1.amazonaws.com
ec2-18-246-31-139.us-west-2.compute.amazonaws.com
tasks.devrtb.com
leased-line-91-149-128-229.telecom.by
74.242.203.213.static.inetbone.net
ec2-52-211-7-108.eu-west-1.compute.amazonaws.com
ec2-54-187-161-180.us-west-2.compute.amazonaws.com
185-2-52-226.static.nucleus.be
ec2-34-241-80-255.eu-west-1.compute.amazonaws.com
uncover supports fieldflag which can be also used to customize the format of the output, for example in case of uncover -f https://ip:port/version, ip:portwill be replaced with results in the output maintaining the defined format.

kubernetes | uncover -f https://ip:port/version -silent https://35.222.229.38:443/version https://52.11.181.228:443/version https://35.239.255.1:443/version https://34.71.48.11:443/version https://130.211.54.173:443/version https://54.184.250.232:443/version">echo kubernetes | uncover -f https://ip:port/version -silent

https://35.222.229.38:443/version
https://52.11.181.228:443/version
https://35.239.255.1:443/version
https://34.71.48.11:443/version
https://130.211.54.173:443/version
https://54.184.250.232:443/version


uncover supports multiple search engine, as default shodan is used, engineflag can be used to specify any available search engines. echo jira | uncover -e shodan,censys -silent

176.31.249.189:5001
13.211.116.80:443
43.130.1.221:631
192.195.70.29:443
52.27.22.181:443
117.48.120.226:8889
106.52.115.145:49153
13.69.135.128:443
193.35.99.158:443
18.202.109.218:8089
101.36.105.97:21379
42.194.226.30:2626
Output of uncover can be further piped to other projects in workflow accepting stdin as input.

* uncover -q example -f ip | naabu- Runs naabu for port scanning on the found host.
* uncover -q title:GitLab | httpx- Runs httpx for web server probing the found result. uncover -q http.title:GitLab -silent | httpx -silent

https://15.185.150.109
https://139.162.137.16
https://164.68.115.243
https://135.125.215.186
https://163.172.59.119
http://15.236.10.197
https://129.206.117.248
* uncover -q 'org:"Example Inc."' | httpx | nuclei- Runs httpx / nuclei for vulnerability assessment. https://blogger.googleusercontent.com/img/a/AVvXsEiPnpNqFGwXSBRlSpeHubFIPKwWP6d41xwWREOqLHksVv4DK4UH3JaRY2UIOgPEcphSjx33mamXGoVugGCAZtI9904E13xp1hFIudaMbpRQq92fsgDwxSf0m2sMJDTgOh2A3RBN4tCKAmQXYUbGkjp0W425KTHIvRGUDheS4A1AuQcwZI_FdBnHdV8g=w640-h438 Notes:* keys/ credentials are required to configure before running or using this project.
* queryflag supports all the filters supported by underlying API in use.
* queryflag input needs be compatible with search engine in use.
* results are limited to 100as default and can be increased with limitflag.
uncover is made with love by the projectdiscovery team. Download Uncover

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do I spoof a phone number?

I know this is very basic but I'm new to all things hacking. Off of inspiration from Kevin mitnick I wanted to start with phones. Spoofing, automessage forwarding and the such

submitted by /u/ch1m3rachaos
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Spoof SMS Sender

Is it still possible to spoof the sender of an sms message? I don't so much care about the recipient's reply, just would like to send a one way text from the number of my choosing. There used to be services for this online, but they seemed to have disappeared.

submitted by /u/MisfitEight4
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
โปรแกรมตามหา Bug ของ Axelar Network

ภาพรวมของโปรแกรมContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
A Detailed Guide on Responder (LLMNR Poisoning)

IntroductionResponder is a widely used tool in penetration test scenarios and can be used for lateral movement across the network by red teamers. The tool contains many useful features like LLMNR, NT-NS and MDNS poisoning. It is used in practical scenarios for objectives like hash capture or poisoned answer forwarding supporting various AD attacks. The tool contains various built-in servers like HTTP, SMB, LDAP, DCE-RPC Auth server etc. In this article, we will cover a majority of these attacks that can be performed while being aided by the responder. Table of content* LLMNR, NBT-NS, MDNS and DHCP
* Responder Installation
* Attack 1: LLMNR/NBT-NS Poisoning through SMB
* Attack 2: LLMNR/NBT-NS Poisoning through WPAD
* Responder Analyze Mode
* Responder Basic Authentication Mode
* Responder Downgrade NTLMv2-SSP to NTLMv2
* Responder external IP poisoning
* Responder Multi-Relay: Shell on a system
* Responder DNS injection in DHCP response
* What are these servers in responder?
* Recommendations
* Conclusion LLMNR, NBT-NS, MDNS and DHCPLLMNR: LLMNR is a protocol that allows name resolution without the requirement of a DNS server. It is able to provide a hostname-to-IP based off a multicast packet sent across the network asking all listening Network-Interfaces to reply if they are authoritatively known as the hostname in the query.  It does this by sending a network packet to port UDP 5355 to the multicast network address. It allows IPv4 and IPv6 hosts and supports all current and future DNS formats, types, and classes. It is the successor of NBT-NS.

NBT-NS: NetBIOS name service (NBT-NS) is a Windows protocol that is used to translate NetBIOS names to IP addresses on a local network. It is analogous to what DNS does on the internet. Each machine is assigned a NetBIOS name by the NBT-NS service. Works on UDP port 137. It is the predecessor of LLMNR.

MDNS: Multicast DNS (mDNS) is a protocol aimed at helping with name resolution in networks. It doesn’t query a name server, rather, multicasts the queries to all the clients in a network directly. In multicast, an individual message is aimed directly at a group of recipients.  When a connection between sender and recipient is made, all participants are informed of the connection between the name and IP address and can make a corresponding entry in their mDNS cache.

LLMNR/NBT-NS Poisoning: Let’s say a victim wants to connect to a shared drive \\wow so it sends the request to the DNS server. The only problem is that DNS can’t connect to \\wow as it doesn’t exist. Therefore, the server replies back saying he can’t connect the victim to \\wow. Thereafter, the victim will multicast this request to the entire network (using LLMNR) in case any particular user knows the route to the shared drive (\\wow).

An adversary can spoof an authoritative source for name resolution by responding to this multicast request by a victim as if they know the identity of the shared drive a victim wants to connect with and in turn request its NTLM hash. This means that the attacker has now poisoned the service!

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVE0JujaHdtgJn3sTMBXSiR4ruZ5alpr-8kGVAdsx6gzR4WmOPLAkERsX9sh8oJQNQcQLyJvBR3xQi6wMYUr6RjMPpXOBSKoVN1UwQJg478eWg8QSVW-q9QQD8eWrcJyZcHmHY-cRLF12lhmsokuIvj1YYZ7bRfVyZ7kJTZz5SHAfUeEhK9YTtkameBw/s16000/0.png?w=640&ssl=1

DHCP Poisoning: Dynamic Host Client Protocol (DHCP) is used to provide a host with its IP address, subnet mask, gateway etc. Windows uses multiple custom DHCP options like NetBIOS, WPAD etc. By poisoning the DHCP response, an attacker would be able to help the victim pinpoint its own rogue server for any kind of authentication. In turn, compromising the credentials. Responder InstallationInitially developed by SpiderLabs and now being developed by Laurent [...]

___________________________
@hacking_Attack
@Hacking_Video