Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
AppSec Tales IV | Email Change
https://cdn-images-1.medium.com/max/875/0*fIIRYfqTM9cu5sOL.jpeg
Application Security Testing of the Email Change form guidelines.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
AppSec Tales IV | Email Change
https://cdn-images-1.medium.com/max/875/0*fIIRYfqTM9cu5sOL.jpeg
Application Security Testing of the Email Change form guidelines.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
AppSec Tales IV | Email Change
Application Security Testing of the Email Change form guidelines.
Hey folks. Quick question, sorry if this is the wrong space. I'm building a small CTF challenge based on a domain controller Windows box (Server 2022). The challengers will need to make use of the enumdomusers remote procedure call to grab a list of valid users and progress further. I'm having trouble configuring the Windows box to accept null sessions. I've seen RPC null sessions so many times from the other side of the CTF, I didn't realise how frustrating it would be to configure it myself. I've made every conceivable change to the group policy applied to the Windows box to allow anonymous access including the below changes. At the moment I just get "NT_STATUS_LOGON_FAILURE" when attempting a null session. https://preview.redd.it/bi4i0xp391w81.png?width=653&format=png&auto=webp&s=8b3f134d1780def11eba5b324208f082ce5547c5 Authenticated RPC sessions are working fine, so I'm thinking it's not a firewall/network issue. Any help much appreciated! As an aside, quite how server owners manage to configure RPC to accept null sessions where it's not default on the OS is beyond me after how long I've spent digging around on this. submitted by /u/NobodyTellsMe (https://www.reddit.com/user/NobodyTellsMe)
[link] (https://www.reddit.com/r/Pentesting/comments/ucytod/rpc_null_sessions/) [comments] (https://www.reddit.com/r/Pentesting/comments/ucytod/rpc_null_sessions/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://www.reddit.com/r/Pentesting/comments/ucytod/rpc_null_sessions/) [comments] (https://www.reddit.com/r/Pentesting/comments/ucytod/rpc_null_sessions/)
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Nimbuspwn Linux vulnerability gives hackers root privileges
New Nimbuspwn Linux vulnerability gives hackers root privilegesPost Views: 52
Premium Content
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
A new set of vulnerabilities collectively tracked as Nimbuspwn could let local attackers escalate privileges on Linux systems to deploy malware ranging from backdoors to ransomware.
Security researchers at Microsoft disclosed the issues in a report today noting that they can be chained together to achieve root privileges on a vulnerable system.
Tracked as CVE-2022-29799 and CVE-2022-29800, the Nimbuspwn security issues were discovered in networkd-dispatcher, a component that sends connection status changes on Linux machines.
Discovering the vulnerabilities started with “listening to messages on the System Bus,” which prompted the researchers to review the code flow for networkd-dispatcher.
The Nimbuspwn security flaws refer to directory traversal, symlink race, and time-of-check-time-of-use (TOCTOU) race condition issues, explains Microsoft researcher Jonathan Bar Or says in the report.
One observation that piqued interest was that the networkd-dispatcher daemon was running at boot time with root privileges on the system.
https://www.bleepstatic.com/images/news/u/1100723/2022/networkd-dispatcher-root.png
___________________________
@hacking_Attack
@Hacking_Video
New Nimbuspwn Linux vulnerability gives hackers root privileges
New Nimbuspwn Linux vulnerability gives hackers root privilegesPost Views: 52
Premium Content
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
A new set of vulnerabilities collectively tracked as Nimbuspwn could let local attackers escalate privileges on Linux systems to deploy malware ranging from backdoors to ransomware.
Security researchers at Microsoft disclosed the issues in a report today noting that they can be chained together to achieve root privileges on a vulnerable system.
Tracked as CVE-2022-29799 and CVE-2022-29800, the Nimbuspwn security issues were discovered in networkd-dispatcher, a component that sends connection status changes on Linux machines.
Discovering the vulnerabilities started with “listening to messages on the System Bus,” which prompted the researchers to review the code flow for networkd-dispatcher.
The Nimbuspwn security flaws refer to directory traversal, symlink race, and time-of-check-time-of-use (TOCTOU) race condition issues, explains Microsoft researcher Jonathan Bar Or says in the report.
One observation that piqued interest was that the networkd-dispatcher daemon was running at boot time with root privileges on the system.
https://www.bleepstatic.com/images/news/u/1100723/2022/networkd-dispatcher-root.png
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New Nimbuspwn Linux vulnerability gives hackers root privileges | Black Hat Ethical Hacking
A new set of vulnerabilities collectively tracked as Nimbuspwn could let local attackers escalate privileges on Linux systems to deploy malware ranging from backdoors to ransomware.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New Nimbuspwn Linux vulnerability gives hackers root privileges New Nimbuspwn Linux vulnerability gives hackers root privilegesPost Views: 52 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon…
attempts.
https://www.bleepstatic.com/images/news/u/1100723/2022/Exploit_winning-the-TOCTOU-race.png
Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-6-90x90.jpg Lapsus$ Hackers Target T-Mobile1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-5-90x90.jpg Log4Shell vulnerability in AWS allows full host takeover2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/New-Java-Framework-Vulnerability-and-Mitigations-90x90.jpg Java encryption implementation error made it trivial to forge credentials6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-3-90x90.jpg CISA warns of attackers now exploiting Windows Print Spooler bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-3-90x90.jpg Newly found zero-click iPhone exploit used in NSO spyware attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/2b93-article-220121-cisco-90x90.jpg Cisco vulnerability lets hackers craft their own login credentials1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/windows-patch-update-90x90.jpg Microsoft Zero-Days, Wormable Bugs Spark Concern2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-2-90x90.jpg Git security vulnerabilities prompt updates2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Amazon-EC2-90x90.jpg Internal AWS credentials swiped by researcher via SQL payload2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/spring4shell-90x90.jpg Attackers are abusing Spring4Shell vulnerability to spread Mirai botnet malware2 weeks ago
The post New Nimbuspwn Linux vulnerability gives hackers root privileges first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
https://www.bleepstatic.com/images/news/u/1100723/2022/Exploit_winning-the-TOCTOU-race.png
Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-6-90x90.jpg Lapsus$ Hackers Target T-Mobile1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-5-90x90.jpg Log4Shell vulnerability in AWS allows full host takeover2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/New-Java-Framework-Vulnerability-and-Mitigations-90x90.jpg Java encryption implementation error made it trivial to forge credentials6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-3-90x90.jpg CISA warns of attackers now exploiting Windows Print Spooler bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-3-90x90.jpg Newly found zero-click iPhone exploit used in NSO spyware attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/2b93-article-220121-cisco-90x90.jpg Cisco vulnerability lets hackers craft their own login credentials1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/windows-patch-update-90x90.jpg Microsoft Zero-Days, Wormable Bugs Spark Concern2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-2-90x90.jpg Git security vulnerabilities prompt updates2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Amazon-EC2-90x90.jpg Internal AWS credentials swiped by researcher via SQL payload2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/spring4shell-90x90.jpg Attackers are abusing Spring4Shell vulnerability to spread Mirai botnet malware2 weeks ago
The post New Nimbuspwn Linux vulnerability gives hackers root privileges first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Cloud Hacking
People always say how IT is dying and the cloud is taking its place. My question is: how different is hacking systems on the cloud from systems on conventional networks? Are techniques like port forwarding possible or do all the machines on the cloud have public IPs unrelated to each other?
submitted by /u/Garlic-George-420
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Cloud Hacking
People always say how IT is dying and the cloud is taking its place. My question is: how different is hacking systems on the cloud from systems on conventional networks? Are techniques like port forwarding possible or do all the machines on the cloud have public IPs unrelated to each other?
submitted by /u/Garlic-George-420
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cloud Hacking
People always say how IT is dying and the cloud is taking its place. My question is: how different is hacking systems on the cloud from systems on...
hacking: security in practice
Changing a Lenovo laptop serial number? Or untraceable?
I will preface this by knowing it’s a stupid question and that you probably want to use an airgapped pc. But if I have my old employers laptop, I wiped it and I’m wondering if there’s any other way I can be tracked or what to do.
Edited to be more specific:
Say I left my laptop at a coffee shop. How do I cut the line between me and this laptop
submitted by /u/squeezeseason
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Changing a Lenovo laptop serial number? Or untraceable?
I will preface this by knowing it’s a stupid question and that you probably want to use an airgapped pc. But if I have my old employers laptop, I wiped it and I’m wondering if there’s any other way I can be tracked or what to do.
Edited to be more specific:
Say I left my laptop at a coffee shop. How do I cut the line between me and this laptop
submitted by /u/squeezeseason
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Changing a Lenovo laptop serial number? Or untraceable?
I will preface this by knowing it’s a stupid question and that you probably want to use an airgapped pc. But if I have my old employers laptop, I...
AD Pentesting Notes
https://medium.com/@reconshell.com/ad-pentesting-notes-1f502814b3de?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@reconshell.com/ad-pentesting-notes-1f502814b3de?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
AD Pentesting Notes
If you just have access to an AD environment but you don’t have any credentials/sessions you could: Pentest the network: Scan the network…
If you just have access to an AD environment but you don’t have any credentials/sessions you could: Pentest the network: Scan the network…Continue reading on Medium » (https://medium.com/@reconshell.com/ad-pentesting-notes-1f502814b3de?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
AD Pentesting Notes
If you just have access to an AD environment but you don’t have any credentials/sessions you could: Pentest the network: Scan the network…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
S1EM : This Project Is A SIEM With SIRP And Threat Intel, All In One
S1EM solution is based on the principle of bringing together the best products in their field, free of charge, and making them quickly interoperable.
S1EM is a SIEM with SIRP and Threat Intel, a full packet capture, all in one.
Inside the solution:
* Cluster Elasticsearch
* Kibana
* Filebeat
* Logstash
* Metricbeat
* Heartbeat
* Auditbeat
* N8n
* Spiderfoot
* Syslog-ng
* Elastalert
* TheHive
* Cortex
* MISP
* OpenCTI
* Arkime
* Suricata
* Zeek
* StoQ
* Mwdb
* Traefik
* Clamav
* Codimd
* Watchtower
* Homer
Note: Cortex v3.1 use ELK connector and the OpenCTI v4 connector
Installation Guide
Prerequisites
Solution works with Linux, docker, and docker-compose.
For auditbeat, you must have Kernel in the version 5.
On Linux, you must have in the “/etc/sysctl.conf” the line:
vm.max_map_count=262144
Physical
You must have:
* 64 Go Ram
* More than 100 Go of HDD in SSD ( Very Important for SSD )
* 8 cpu
* 1 network for management
* 1 network for monitoring
Installation
log in to your system as « root »
git clone https://github.com/V1D1AN/S1EM.git
cd S1EM
After, run the command:
bash 01_deploy.sh
On Linux, add this entry in your /etc/hosts file to access to this solution ( change s1em.cyber.local with the hostname entered during installation ).
vi /etc/hosts
XXX.XXX.XXX.XXX s1em.cyber.local
On Windows, add this entry in your hosts file to access to this solution ( change s1em.cyber.local with the hostname entered during installation ).
notepad C:\Windows\System32\drivers\etc\hosts
XXX.XXX.XXX.XXX s1em.cyber.local
Download
___________________________
@hacking_Attack
@Hacking_Video
S1EM : This Project Is A SIEM With SIRP And Threat Intel, All In One
S1EM solution is based on the principle of bringing together the best products in their field, free of charge, and making them quickly interoperable.
S1EM is a SIEM with SIRP and Threat Intel, a full packet capture, all in one.
Inside the solution:
* Cluster Elasticsearch
* Kibana
* Filebeat
* Logstash
* Metricbeat
* Heartbeat
* Auditbeat
* N8n
* Spiderfoot
* Syslog-ng
* Elastalert
* TheHive
* Cortex
* MISP
* OpenCTI
* Arkime
* Suricata
* Zeek
* StoQ
* Mwdb
* Traefik
* Clamav
* Codimd
* Watchtower
* Homer
Note: Cortex v3.1 use ELK connector and the OpenCTI v4 connector
Installation Guide
Prerequisites
Solution works with Linux, docker, and docker-compose.
For auditbeat, you must have Kernel in the version 5.
On Linux, you must have in the “/etc/sysctl.conf” the line:
vm.max_map_count=262144
Physical
You must have:
* 64 Go Ram
* More than 100 Go of HDD in SSD ( Very Important for SSD )
* 8 cpu
* 1 network for management
* 1 network for monitoring
Installation
log in to your system as « root »
git clone https://github.com/V1D1AN/S1EM.git
cd S1EM
After, run the command:
bash 01_deploy.sh
On Linux, add this entry in your /etc/hosts file to access to this solution ( change s1em.cyber.local with the hostname entered during installation ).
vi /etc/hosts
XXX.XXX.XXX.XXX s1em.cyber.local
On Windows, add this entry in your hosts file to access to this solution ( change s1em.cyber.local with the hostname entered during installation ).
notepad C:\Windows\System32\drivers\etc\hosts
XXX.XXX.XXX.XXX s1em.cyber.local
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
S1EM : This Project Is A SIEM With SIRP And Threat Intel, All In One
S1EM solution is based on the principle of bringing together the best products in their field, free of charge, and making them interoperable.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Epagneul : Graph Visualization For Windows Event Logs
Epagneul is a tool to visualize and investigate windows event logs.
Deployment
Requires docker and docker-compose to be installed.
Installing
make
Offline deployment
On a machine connected to internet, build an offline release:
make release
This will create a
make load
make
This will install:
* epagneul web UI (port 8080)
* epagneul backend (port 8000)
* neo4j (port 7474)
Download
___________________________
@hacking_Attack
@Hacking_Video
Epagneul : Graph Visualization For Windows Event Logs
Epagneul is a tool to visualize and investigate windows event logs.
Deployment
Requires docker and docker-compose to be installed.
Installing
make
Offline deployment
On a machine connected to internet, build an offline release:
make release
This will create a
releasefolder containing ready to go docker images. Copy the project to your air gapped machine then run:make load
make
This will install:
* epagneul web UI (port 8080)
* epagneul backend (port 8000)
* neo4j (port 7474)
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Epagneul : Graph Visualization For Windows Event Logs
Epagneul is a tool to visualize and investigate windows event logs. Requires docker and docker-compose to be installed.
O365-Doppelganger - A Quick Handy Script To Harvest Credentials Off Of A User During A Red Team And Get Execution Of A File From The User
http://www.kitploit.com/2022/04/o365-doppelganger-quick-handy-script-to.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/04/o365-doppelganger-quick-handy-script-to.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
O365-Doppelganger - A Quick Handy Script To Harvest Credentials Off Of A User During A Red Team And Get Execution Of A File From…
O365-Doppelganger is NOT a replacement for hardcore phishing (https://www.kitploit.com/search/label/Phishing) activities. There are several other tools which perform OAuth and OTA capture which is not the aim of O365-Doppelganger. O365-Doppelganger is a quick handy script to harvest credentials (https://www.kitploit.com/search/label/Credentials) of a user during Red Teams. This repository is a quick hack of one of my old red team engagement (https://www.kitploit.com/search/label/Red%20Team%20Engagement) scripts which I've used several times to capture credentials and use them for making windows access tokens (https://www.kitploit.com/search/label/Access%20Tokens) for lateral movement. This code repository basically performs the below tasks:The GO code: hosts the O365 portal (can be replaced with anything in the index.html). It is recommended to use a valid cert and key file (LetsEncrypt?) instead of the one provided in the directory logs all user activity on the web portal in a seperate log file on the server logs the credentials captured in a seperate log file on the server can also be used to return a valid file to the user post capturing the credentials. This can be done by replacing the file named MacroFile.doc in the current directory (https://www.kitploit.com/search/label/Directory) and replacing it with HTA/ISO/MSI or anything else that the phisher wants. Theres also a small code in the GO code which would need to be modified to specify the user's file name which needs to be returned: content, err := ioutil.ReadFile("MacroFile.doc") Once modified, the target user when enters a valid email ID and password will be asked to save the above file. This file name can be changed using the below code in the GO file: response.Header().Set("Content-Disposition", "attachment; filename=Darkvortex Privacy Policy.doc") The index.html code: renders an O365 portal alongside a small regex which checks for a given user's domain name to make it look a bit more legit. The regex code looks like this: pattern="^([a-zA-Z0-9_\-\.]+)@darkvortex\.([a-zA-Z]{2,5})$" title=" Valid darkvortex email ID" The above regex checks if the given username contains a full valid email address else it will prompt the user to enter a correct username as follows:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
This same check is also performed in the GO code so that user's do not use something like burp to bypass the check: if strings.Contains(value[i], "@darkvortex") { It's recommended to change the name darkvortex in the index.html file to your own target company name. Once the correct email ID and the password is entered, the user will be asked to save the provided file as follows:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video