Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
How Do I Report My Security Program's ROI?

If security leaders focus on visibility and metrics, they can demonstrate their program's value to company leadership and boards.
Dark Reading: Attacks/Breaches
Log4j Attack Surface Remains Massive

Four months after the Log4Shell vulnerability was disclosed, most affected open source components remain unpatched, and companies continue to use vulnerable versions of the logging tool.
https://b.thumbs.redditmedia.com/fuOH7HtzwQBzFExnKVWvDyI6_YA3ehzkn8pe-wvaWMw.jpg Hey folks. Quick question, sorry if this is the wrong space. I'm building a small CTF challenge based on a domain controller Windows box (Server 2022). The challengers will need to make use of the enumdomusers remote procedure call to grab a list of valid users and progress further. I'm having trouble configuring the Windows box to accept null sessions. I've seen RPC null sessions so many times from the other side of the CTF, I didn't realise how frustrating it would be to configure it myself.

I've made every conceivable change to the group policy applied to the Windows box to allow anonymous access including the below changes. At the moment I just get "NT_STATUS_LOGON_FAILURE" when attempting a null session.



https://preview.redd.it/1ddyqawawyv81.png?width=653&format=png&auto=webp&s=750090cbdfb8bd861e11f92d80b295e34a81d253

Authenticated RPC sessions are working fine, so I'm thinking it's not a firewall/network issue. Any help much appreciated!

As an aside, quite how server owners manage to configure RPC to accept null sessions where it's not default on the OS is beyond me after how long I've spent digging around on this.

submitted by /u/NobodyTellsMe
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
does anyone have CVE-2019-9514 PoC?

i'm trying to test one of my sites for this attack. i cannot seem to find any PoC anywhere but the official report from microsoft says that it does exist and it is accessible. can anyone help me find it?

submitted by /u/acnegenic
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do I decrypt saved Chrome passwords?

If I exported the Google Chrome (Version 98) data in AppData/local, how will I go about decrypting the saved passwords? There are a couple of SQLite files containing the URL and the encrypted passwords.

submitted by /u/Sushi_Roll_Monster
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
4EVERLAND chính thức khởi động “First Leap Program” với giải thưởng lên đến 15 triệu 4EVER

Kính chào toàn thể người dùng,Continue reading on Medium »
Read more...
hacking: security in practice
Anyone know what exploits armitage can use to take down Windows Server 2019?

This is only for experimental purposes only. I have a VM environment setup with a domain controller and 3 client PCs Server is Windows 2019 Domain clients are Win7 Win 8.1 and Win10

I am using Kali Linux obviously. I remember doing a Nmap scan for open ports on the server and I found a bunch of open ports. What Exploits can you use on their server because I remember going through exploit after exploit and nothing was happening. Once again this is for experimental purposes.

submitted by /u/geegol
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video