Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
How Do I Report My Security Program's ROI?

If security leaders focus on visibility and metrics, they can demonstrate their program's value to company leadership and boards.
Dark Reading: Attacks/Breaches
Log4j Attack Surface Remains Massive

Four months after the Log4Shell vulnerability was disclosed, most affected open source components remain unpatched, and companies continue to use vulnerable versions of the logging tool.
https://b.thumbs.redditmedia.com/fuOH7HtzwQBzFExnKVWvDyI6_YA3ehzkn8pe-wvaWMw.jpg Hey folks. Quick question, sorry if this is the wrong space. I'm building a small CTF challenge based on a domain controller Windows box (Server 2022). The challengers will need to make use of the enumdomusers remote procedure call to grab a list of valid users and progress further. I'm having trouble configuring the Windows box to accept null sessions. I've seen RPC null sessions so many times from the other side of the CTF, I didn't realise how frustrating it would be to configure it myself.

I've made every conceivable change to the group policy applied to the Windows box to allow anonymous access including the below changes. At the moment I just get "NT_STATUS_LOGON_FAILURE" when attempting a null session.



https://preview.redd.it/1ddyqawawyv81.png?width=653&format=png&auto=webp&s=750090cbdfb8bd861e11f92d80b295e34a81d253

Authenticated RPC sessions are working fine, so I'm thinking it's not a firewall/network issue. Any help much appreciated!

As an aside, quite how server owners manage to configure RPC to accept null sessions where it's not default on the OS is beyond me after how long I've spent digging around on this.

submitted by /u/NobodyTellsMe
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
does anyone have CVE-2019-9514 PoC?

i'm trying to test one of my sites for this attack. i cannot seem to find any PoC anywhere but the official report from microsoft says that it does exist and it is accessible. can anyone help me find it?

submitted by /u/acnegenic
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do I decrypt saved Chrome passwords?

If I exported the Google Chrome (Version 98) data in AppData/local, how will I go about decrypting the saved passwords? There are a couple of SQLite files containing the URL and the encrypted passwords.

submitted by /u/Sushi_Roll_Monster
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video