Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Use of Web Archive In OSINT Investigation ! Go back to past
https://cdn-images-1.medium.com/max/855/1*V9sAWb-Sb8YGLeGz1Zc0vA.png
Using web archives allows you to see what a web page or site looked like in the past !
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Use of Web Archive In OSINT Investigation ! Go back to past
https://cdn-images-1.medium.com/max/855/1*V9sAWb-Sb8YGLeGz1Zc0vA.png
Using web archives allows you to see what a web page or site looked like in the past !
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Use of Web Archive In OSINT Investigation ! Go back to past
Using web archives allows you to see what a web page or site looked like in the past !
hacking: security in practice
Can the variable in this ash script be exploited for code execution?
I’m playing with this trying to see if the lack of quotes let’s me execute a command but I’ve been unsuccessful.
The shell in question is ash from Busybox 1.21.1.
submitted by /u/kjarkr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can the variable in this ash script be exploited for code execution?
wget -O outputfile ${user_controlled_variable} I’m playing with this trying to see if the lack of quotes let’s me execute a command but I’ve been unsuccessful.
The shell in question is ash from Busybox 1.21.1.
submitted by /u/kjarkr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can the variable in this ash script be exploited for code execution?
wget -O outputfile ${user_controlled_variable} I’m playing with this trying to see if the lack of quotes let’s me execute a command but I’ve been...
hacking: security in practice
How to access a website's backend
How do you see the backend of a website? Not the source code but the actual files and folders? I've sen it done on some websites and was curious to know how to do it
submitted by /u/raheke8
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to access a website's backend
How do you see the backend of a website? Not the source code but the actual files and folders? I've sen it done on some websites and was curious to know how to do it
submitted by /u/raheke8
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to access a website's backend
How do you see the backend of a website? Not the source code but the actual files and folders? I've sen it done on some websites and was curious...
Black Hat Ethical Hacking
Exploit released for Atlassian Confluence RCE bug, update now
___________________________
@hacking_Attack
@Hacking_Video
Exploit released for Atlassian Confluence RCE bug, update now
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Exploit released for Atlassian Confluence RCE bug, update now | Black Hat Ethical Hacking
Proof-of-concept exploits for the actively exploited critical CVE-2022-26134 vulnerability impacting Atlassian Confluence and Data Center servers have been widely released this weekend.
AWS-Threat-Simulation-and-Detection - Playing Around With Stratus Red Team (Cloud Attack Simulation Tool) And SumoLogic
http://www.kitploit.com/2022/06/aws-threat-simulation-and-detection.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/06/aws-threat-simulation-and-detection.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
AWS-Threat-Simulation-and-Detection - Playing Around With Stratus Red Team (Cloud Attack Simulation Tool) And SumoLogic
This repository is a documentation of my adventures with Stratus Red Team (https://github.com/DataDog/stratus-red-team) - a tool for adversary emulation (https://www.kitploit.com/search/label/Adversary%20Emulation) for the cloud. Stratus Red Team (https://www.kitploit.com/search/label/Red%20Team) is "Atomic Red Team (https://github.com/redcanaryco/atomic-red-team) for the cloud, allowing to emulate offensive attack techniques in a granular and self-contained manner.
We run the attacks covered in the Stratus Red Team repository one by one on our AWS account. In order to monitor them, we will use CloudTrail and CloudWatch for logging and ingest these logs into SumoLogic (https://www.sumologic.com/) for further analysis.
___________________________
@hacking_Attack
@Hacking_Video
We run the attacks covered in the Stratus Red Team repository one by one on our AWS account. In order to monitor them, we will use CloudTrail and CloudWatch for logging and ingest these logs into SumoLogic (https://www.sumologic.com/) for further analysis.
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - DataDog/stratus-red-team: :cloud: Granular, Actionable Adversary Emulation for the Cloud
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud - DataDog/stratus-red-team
Attack Description Link aws.credential-access.ec2-get-password-data Retrieve EC2 Password Data Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.credential-access.ec2-get-password-data.md) aws.credential-access.ec2-steal-instance-credentials Steal EC2 Instance Credentials Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.credential-access.ec2-steal-instance-credentials.md) aws.credential-access.secretsmanager-retrieve-secrets Retrieve a High Number of Secrets Manager secrets Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.credential-access.secretsmanager-retrieve-secrets.md) aws.credential-access.ssm-retrieve-securestring-parameters Retrieve And Decrypt SSM Parameters Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.credential-access.ssm-retrieve-securestring-parameters.md) aws.defense-evasion.cloudtrail-delete Delete CloudTrail Trail Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.defense-evasion.cloudtrail-delete.md) aws.defense-evasion.cloudtrail-event-selectors Disable CloudTrail Logging Through Event Selectors Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.defense-evasion.cloudtrail-event-selectors.md) aws.defense-evasion.cloudtrail-lifecycle-rule CloudTrail Logs Impairment Through S3 Lifecycle Rule Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.defense-evasion.cloudtrail-lifecycle-rule.md) aws.defense-evasion.cloudtrail-stop Stop CloudTrail Trail Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.defense-evasion.cloudtrail-stop.md) aws.defense-evasion.organizations-leave Attempt to Leave the AWS Organization Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.defense-evasion.organizations-leave.md) aws.defense-evasion.vpc-remove-flow-logs Remove VPC Flow Logs Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.defense-evasion.vpc-remove-flow-logs.md) aws.discovery.ec2-enumerate-from-instance Execute Discovery (https://www.kitploit.com/search/label/Discovery) Commands on an EC2 Instance Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.discovery.ec2-enumerate-from-instance.md) aws.discovery.ec2-download-user-data Download EC2 Instance User Data TBD aws.exfiltration.ec2-security-group-open-port-22-ingress Open Ingress Port 22 on a Security Group Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.exfiltration.ec2-security-group-open-port-22-ingress.md) aws.exfiltration.ec2-share-ami Exfiltrate an AMI by Sharing It Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.exfiltration.ec2-share-ami.md) aws.exfiltration.ec2-share-ebs-snapshot Exfiltrate EBS Snapshot by Sharing It Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.exfiltration.rds-share-snapshot.md) aws.exfiltration.rds-share-snapshot Exfiltrate RDS Snapshot by Sharing Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.exfiltration.rds-share-snapshot.md) aws.exfiltration.s3-backdoor-bucket-policy Backdoor an S3 Bucket via its Bucket Policy Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.exfiltration.s3-backdoor-bucket-policy.md) aws.persistence.iam-backdoor-role Backdoor an IAM Role Link (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection/blob/main/aws.persistence.iam-backdoor-role.md) aws.persistence.iam-backdoor-user Create an Access Key on an IAM User TBD aws.persistence.iam-create-admin-user Create an administrative IAM User TBD
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
AWS-Threat-Simulation-and-Detection/aws.credential-access.ec2-get-password-data.md at main · sbasu7241/AWS-Threat-Simulation-and…
Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic - AWS-Threat-Simulation-and-Detection/aws.credential-access.ec2-get-password-data.md at main · sbasu7241/AWS-Threat...
aws.persistence.iam-create-user-login-profile Create a Login Profile on an IAM User TBD aws.persistence.lambda-backdoor-function Backdoor Lambda Function Through Resource-Based Policy TBD Credits Awesome team at Datadog, Inc. for Stratus Red Team here (https://github.com/DataDog/stratus-red-team) Hacking the Cloud AWS (https://hackingthe.cloud/aws/general-knowledge/assume_role_logic/) Falcon Force team blog (https://medium.com/falconforce/falconfriday-detecting-realistic-aws-cloud-attacks-using-azure-sentinel-0xff1c-b62fd45c87dc)
Download AWS-Threat-Simulation-and-Detection (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection)
___________________________
@hacking_Attack
@Hacking_Video
Download AWS-Threat-Simulation-and-Detection (https://github.com/sbasu7241/AWS-Threat-Simulation-and-Detection)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - DataDog/stratus-red-team: :cloud: Granular, Actionable Adversary Emulation for the Cloud
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud - DataDog/stratus-red-team
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Rickroll your friends with a Poor man’s USB Rubber Ducky?
https://cdn-images-1.medium.com/max/1426/1*BXyAqmG4m-Mubco50OZVow.png
I was going through my old stuff and found an old CD which had a simple flash game in it. I opened it up on my laptop and found a file…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Rickroll your friends with a Poor man’s USB Rubber Ducky?
https://cdn-images-1.medium.com/max/1426/1*BXyAqmG4m-Mubco50OZVow.png
I was going through my old stuff and found an old CD which had a simple flash game in it. I opened it up on my laptop and found a file…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Rickroll your friends with a Poor man’s USB Rubber Ducky?
I was going through my old stuff and found an old CD which had a simple flash game in it. I opened it up on my laptop and found a file…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Just How Sure Are You About The Security Of Your Data On Messaging Apps?
https://cdn-images-1.medium.com/max/1080/1*MV3XYjHIqCwK1im33IWZkA.png
Did you know that WhatsApp shares your phone numbers with Facebook?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Just How Sure Are You About The Security Of Your Data On Messaging Apps?
https://cdn-images-1.medium.com/max/1080/1*MV3XYjHIqCwK1im33IWZkA.png
Did you know that WhatsApp shares your phone numbers with Facebook?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Just How Sure Are You About The Security Of Your Data On Messaging Apps?
Did you know that WhatsApp shares your phone numbers with Facebook? Or that interaction with businesses is not encrypted? Did you know that…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
تهكير حساب واتساب بجميع الطرق ( 2022 )
https://cdn-images-1.medium.com/max/1280/1*nJg3xIB5ZAaiq4i_hiZULw.png
تهكير حساب whatsapp في هذا المقال الرائع سوف نتعرف على جميع طرق المستخدمة في اختراق الواتساب وتهكير الحسابات, ويعتبر تطبيق الواتساب من…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
تهكير حساب واتساب بجميع الطرق ( 2022 )
https://cdn-images-1.medium.com/max/1280/1*nJg3xIB5ZAaiq4i_hiZULw.png
تهكير حساب whatsapp في هذا المقال الرائع سوف نتعرف على جميع طرق المستخدمة في اختراق الواتساب وتهكير الحسابات, ويعتبر تطبيق الواتساب من…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
تهكير حساب واتساب بجميع الطرق ( 2022 )
تهكير حساب whatsapp في هذا المقال الرائع سوف نتعرف على جميع طرق المستخدمة في اختراق الواتساب وتهكير الحسابات, ويعتبر تطبيق الواتساب من أكثر…