Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
LDAPFragger is a Command and Control tool that enables attackers to route Cobalt Strike (https://www.kitploit.com/search/label/Cobalt%20Strike) beacon data over LDAP using user attributes. For background information, read the release blog: http://blog.fox-it.com/2020/03/19/ldapfragger-command-and-control-over-ldap-attributes
Dependencies and installation Compiled with .NET 4.0, but may work with older and newer .NET frameworks (https://www.kitploit.com/search/label/Frameworks) as well Usage Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials (https://www.kitploit.com/search/label/Credentials) are provided, integrated AD authentication (https://www.kitploit.com/search/label/Authentication) will be used."> _ _ __ | | | | / _| | | __| | __ _ _ __ | |_ _ __ __ _ __ _ __ _ ___ _ __ | |/ _` |/ _` | '_ \| _| '__/ _` |/ _` |/ _` |/ _ \ '__| | | (_| | (_| | |_) | | | | | (_| | (_| | (_| | __/ | |_|\__,_|\__,_| .__/|_| |_| \__,_|\__, |\__, |\___|_| | | __/ | __/ | |_| |___/ |___/ Fox-IT - Rindert Kramer Usage: --cshost: IP address or hostname of the Cobalt Strike instance --csport: Port of the external C2 interface on the Cobalt Strike server -u: Username to connect to Active Directory -p: Password to connect to Active Directory -d: FQDN of the Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials are provided, integrated AD authentication will be used. Example usage:

___________________________
@hacking_Attack
@Hacking_Video
From network segment A, run --csport LDAPFragger --cshost --csport -u -p -d ">LDAPFragger --cshost --csport LDAPFragger --cshost --csport -u -p -d From network segment B, run -p -d ">LDAPFragger LDAPFragger -u -p -d LDAPS can be used with the --LDAPS flag, however, regular LDAP traffic is encrypted as well. Please do note that the default Cobalt Strike payload will get caught by most AVs.

Download LDAPFragger (https://github.com/fox-it/LDAPFragger)

___________________________
@hacking_Attack
@Hacking_Video
0-click RCE in Electron Applications

0-click RCE in Electron ApplicationsContinue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Aryaka, Carnegie Mellon’s CyLab to Research New Threat Mitigation Techniques

The security research partnership will focus on developing new techniques and releasing them as open source.
Dark Reading: Attacks/Breaches
What Stars Wars Teaches Us About Threats

The venerable film franchise shows us how to take threats in STRIDE.
hacking: security in practice
Signs of tampering?

I've been told that one of the signs that you might have been compromised is that the default apps to open certain files have changed.

I go to open up a pdf this morning and while it should have automatically opened up with firefox, it prompted me on what app I should use to open the pdf.

Yesterday I noticed that firefox has been updated and in the window prompt it did say "New" under firefox, implying that it's a new app?

I don't remember having to pick out default apps for opening files after each update. Maybe I'm being paranoid.

If I am possibly compromised, what are some other things I can look into to find out if I've been computer poisoned?

Thanks in advance for any advice.

submitted by /u/lostlikeyou
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video