Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
LDAPFragger - Command And Control Tool That Enables Attackers To Route Cobalt Strike Beacon Data Over LDAP

https://blogger.googleusercontent.com/img/a/AVvXsEjHrAomxQoFfAWxL_cY1NWNCHYRCT-7yoWZ7O_1U1hvQ4TELfGHCoHbUjGGlypfmauB82kv6HWnpC3cNlOduLCej-QxDXBwTTu17gSholsH6C-0DiSfTlXD7fWADQhz0Yj6UemY0Eo1H9mnjh9N0L3Kq8YoJXBRNKta-j8jt5bMG5n-lyicxcVSCr7H=s16000

LDAPFragger is a Command and Control tool that enables attackers to route Cobalt Strike beacon data over LDAP using user attributes.

For background information, read the release blog: http://blog.fox-it.com/2020/03/19/ldapfragger-command-and-control-over-ldap-attributes
Dependencies and installation

* Compiled with .NET 4.0, but may work with older and newer .NET frameworks as well

Usage

Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials are provided, integrated AD authentication will be used.">_ _ __ | | | | / _| | | __| | __ _ _ __ | |_ _ __ __ _ __ _ __ _ ___ _ __ | |/ _` |/ _` | '_ \| _| '__/ _` |/ _` |/ _` |/ _ \ '__| | | (_| | (_| | |_) | | | | | (_| | (_| | (_| | __/ | |_|\__,_|\__,_| .__/|_| |_| \__,_|\__, |\__, |\___|_| | | __/ | __/ | |_| |___/ |___/ Fox-IT - Rindert Kramer Usage: --cshost: IP address or hostname of the Cobalt Strike instance --csport: Port of the external C2 interface on the Cobalt Strike server -u: Username to connect to Active Directory -p: Password to connect to Active Directory -d: FQDN of the Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials are provided, integrated AD authentication will be used.

Example usage:

https://blogger.googleusercontent.com/img/a/AVvXsEjHrAomxQoFfAWxL_cY1NWNCHYRCT-7yoWZ7O_1U1hvQ4TELfGHCoHbUjGGlypfmauB82kv6HWnpC3cNlOduLCej-QxDXBwTTu17gSholsH6C-0DiSfTlXD7fWADQhz0Yj6UemY0Eo1H9mnjh9N0L3Kq8YoJXBRNKta-j8jt5bMG5n-lyicxcVSCr7H=s16000

From network segment A, run

LDAPFragger --cshost

From network segment B, run

LDAPFragger LDAPFragger -u

LDAPS can be used with the --LDAPSflag, however, regular LDAP traffic is encrypted as well. Please do note that the default Cobalt Strike payload will get caught by most AVs.
Download LDAPFragger

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
AI for Cybersecurity Shimmers With Promise, but Challenges Abound

Companies see AI-powered cybersecurity tools and systems as the future, but at present nearly 90% of them say they face significant hurdles in making use of them.
Dark Reading: Attacks/Breaches
Security Stuff Happens: What Will the Public Hear When You Say You've Been Breached?

A company's response to a breach is more important than almost anything else. But what constitutes a "good" response following a security incident? (Part 2 of a series.)
hacking: security in practice
Can TryHackMe really teach you how to hack?

So, I've been following a lot of cyber security related content for a couple of years now and i must say i aquired a lot of skills. However, i want to go further. At the moment my financial situation doesn't allow college or any expensive certifications like the one's offered by Offensive Security and most of the things I've learned are from YouTube tutorials and Udemy (Don't judge). So, now i want to go a step further and maybe try for some compTIA certifications in the near future. I joined THM yesterday and got the premium so i can access all the rooms and thought it looks well put together but I'm afraid it will be limited in how deep the knowledge offered goes. So, any experiences? Did it help you advance your skills in a significant way?

submitted by /u/TheN1ght0w1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I’m getting my laptop back from the police and my usbs

Hey guys just a quick question.

So I’m getting my laptop and usbs back from the British police after around 2 months off them having them and I’m just wondering what should I do with them? Do you guys think they have been tampered with or installed any hidden software? I’m just making sure before I start using them again

Thanks for reading!

submitted by /u/Idontnohow2spel1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
DHash

I was wondering, is it possible to find someone’s address through email via hashing? Particularly, DHash?

Heard it floating around from a fella.

submitted by /u/Nik_FTW233
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to disguise a device as a specific I.P?

Say you have a specific I.P address in mind, maybe of a phone you used to log onto your email with, is there a way to make your computer look as though it's coming from that I.P address?

For instance, I'm locked out of my old hotmail account and one of the things that can help when doing the "Verify Online" thing is apparently filling in the form whilst connected from a familiar device.

Any ideas?

submitted by /u/danwilkie90
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
you see me, I see you

I was bored and messing around looking for fun TLDs like the domain .xyz and I found that the domain .icu is working. I tried putting youseeme.icu on my browser and I was stupefied for a moment. I don't know what to make of it. It's probably not deep web but I was scared. Anybody know what this is? What rabbit is it talking about and why should I follow it? There seems to be nothing except matrix type numbers running.

Edit: added screenshots as requested. It's all just numbers running like this. I was thinking if this was not deepweb, maybe some Easter egg website for a movie? https://imgur.com/gallery/3tQOKjp

submitted by /u/semen_in_a_bag
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video