Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Signs of tampering?

I've been told that one of the signs that you might have been compromised is that the default apps to open certain files have changed.

I go to open up a pdf this morning and while it should have automatically opened up with firefox, it prompted me on what app I should use to open the pdf.

Yesterday I noticed that firefox has been updated and in the window prompt it did say "New" under firefox, implying that it's a new app?

I don't remember having to pick out default apps for opening files after each update. Maybe I'm being paranoid.

If I am possibly compromised, what are some other things I can look into to find out if I've been computer poisoned?

Thanks in advance for any advice.

submitted by /u/lostlikeyou
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
LDAPFragger - Command And Control Tool That Enables Attackers To Route Cobalt Strike Beacon Data Over LDAP

https://blogger.googleusercontent.com/img/a/AVvXsEjHrAomxQoFfAWxL_cY1NWNCHYRCT-7yoWZ7O_1U1hvQ4TELfGHCoHbUjGGlypfmauB82kv6HWnpC3cNlOduLCej-QxDXBwTTu17gSholsH6C-0DiSfTlXD7fWADQhz0Yj6UemY0Eo1H9mnjh9N0L3Kq8YoJXBRNKta-j8jt5bMG5n-lyicxcVSCr7H=s16000

LDAPFragger is a Command and Control tool that enables attackers to route Cobalt Strike beacon data over LDAP using user attributes.

For background information, read the release blog: http://blog.fox-it.com/2020/03/19/ldapfragger-command-and-control-over-ldap-attributes
Dependencies and installation

* Compiled with .NET 4.0, but may work with older and newer .NET frameworks as well

Usage

Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials are provided, integrated AD authentication will be used.">_ _ __ | | | | / _| | | __| | __ _ _ __ | |_ _ __ __ _ __ _ __ _ ___ _ __ | |/ _` |/ _` | '_ \| _| '__/ _` |/ _` |/ _` |/ _ \ '__| | | (_| | (_| | |_) | | | | | (_| | (_| | (_| | __/ | |_|\__,_|\__,_| .__/|_| |_| \__,_|\__, |\__, |\___|_| | | __/ | __/ | |_| |___/ |___/ Fox-IT - Rindert Kramer Usage: --cshost: IP address or hostname of the Cobalt Strike instance --csport: Port of the external C2 interface on the Cobalt Strike server -u: Username to connect to Active Directory -p: Password to connect to Active Directory -d: FQDN of the Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials are provided, integrated AD authentication will be used.

Example usage:

https://blogger.googleusercontent.com/img/a/AVvXsEjHrAomxQoFfAWxL_cY1NWNCHYRCT-7yoWZ7O_1U1hvQ4TELfGHCoHbUjGGlypfmauB82kv6HWnpC3cNlOduLCej-QxDXBwTTu17gSholsH6C-0DiSfTlXD7fWADQhz0Yj6UemY0Eo1H9mnjh9N0L3Kq8YoJXBRNKta-j8jt5bMG5n-lyicxcVSCr7H=s16000

From network segment A, run

LDAPFragger --cshost

From network segment B, run

LDAPFragger LDAPFragger -u

LDAPS can be used with the --LDAPSflag, however, regular LDAP traffic is encrypted as well. Please do note that the default Cobalt Strike payload will get caught by most AVs.
Download LDAPFragger

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
AI for Cybersecurity Shimmers With Promise, but Challenges Abound

Companies see AI-powered cybersecurity tools and systems as the future, but at present nearly 90% of them say they face significant hurdles in making use of them.
Dark Reading: Attacks/Breaches
Security Stuff Happens: What Will the Public Hear When You Say You've Been Breached?

A company's response to a breach is more important than almost anything else. But what constitutes a "good" response following a security incident? (Part 2 of a series.)