Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Increase Email Security by Adding an Extra Layer of Spam Filtering and Malware Protection
https://cdn-images-1.medium.com/max/2000/0*j5rujBP1KNtAXOt6.jpeg
Businesses and end-users are suffering at the hands of attackers who set out to implement spam filtering and malware protection practices…
Continue reading on Cybersecurity Science »
___________________________
@hacking_Attack
@Hacking_Video
Increase Email Security by Adding an Extra Layer of Spam Filtering and Malware Protection
https://cdn-images-1.medium.com/max/2000/0*j5rujBP1KNtAXOt6.jpeg
Businesses and end-users are suffering at the hands of attackers who set out to implement spam filtering and malware protection practices…
Continue reading on Cybersecurity Science »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Increase Email Security by Adding an Extra Layer of Spam Filtering and Malware Protection
Businesses and end-users are suffering at the hands of attackers who set out to implement spam filtering and malware protection practices…
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Offensive-Azure - Collection Of Offensive Tools Targeting Microsoft Azure
https://blogger.googleusercontent.com/img/a/AVvXsEgZHOFZxWcmcHCsU294blSAoz3ng4FukrxOYoBicFjqk69cnyNSdUHAa9GId6LCZ6PmhN0oMdKr4GM9hks1TOJPKU_wPMZVnE8dg7rzuN_ILasHRLIbkQzJ571vU9Jk3GYhoZ_I3DYqRPsxWz2ucneQX1IoTwXgR0xAuMeeMn9NzJf1EKjLjYYbI4kW=w640-h480 Collection of offensive tools targeting Microsoft Azure written in Python to be platform agnostic. The current list of tools can be found below with a brief description of their functionality.
*
* Can be used for general token generation or during a phishing/social engineering campaign.
*
*
*
*
* Can also be used to perform a password spray
*
* Creates text output file as well as BloodHound compatible aztenant file
*
* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azusers file
*
* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azgroups file
*
* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azgroups file
*
* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azgroups file
*
* Creates two data files, a raw json file, and a BloodHound compatible azgroups file
*
* Creates two data files, a raw json file, and a BloodHound compatible azgroups file InstallationOffensive Azure can be installed in a number of ways or not at all.
You are welcome to clone the repository and execute the specific scripts you want. A
___________________________
@hacking_Attack
@Hacking_Video
Offensive-Azure - Collection Of Offensive Tools Targeting Microsoft Azure
https://blogger.googleusercontent.com/img/a/AVvXsEgZHOFZxWcmcHCsU294blSAoz3ng4FukrxOYoBicFjqk69cnyNSdUHAa9GId6LCZ6PmhN0oMdKr4GM9hks1TOJPKU_wPMZVnE8dg7rzuN_ILasHRLIbkQzJ571vU9Jk3GYhoZ_I3DYqRPsxWz2ucneQX1IoTwXgR0xAuMeeMn9NzJf1EKjLjYYbI4kW=w640-h480 Collection of offensive tools targeting Microsoft Azure written in Python to be platform agnostic. The current list of tools can be found below with a brief description of their functionality.
*
./Device_Code/device_code_easy_mode.py* Generates a code to be entered by the target user* Can be used for general token generation or during a phishing/social engineering campaign.
*
./Access_Tokens/token_juggle.py* Takes in a refresh token in various ways and retrieves a new refresh token and an access token for the resource specified*
./Access_Tokens/read_token.py* Takes in an access token and parses the included claims information, checks for expiration, attempts to validate signature*
./Outsider_Recon/outsider_recon.py* Takes in a domain and enumerates as much information as possible about the tenant without requiring authentication*
./User_Enum/user_enum.py* Takes in a username or list of usernames and attempts to enumerate valid accounts using one of three methods* Can also be used to perform a password spray
*
./Azure_AD/get_tenant.py* Takes in an access token or refresh token, outputs tenant ID and tenant Name* Creates text output file as well as BloodHound compatible aztenant file
*
./Azure_AD/get_users.py* Takes in an access token or refresh token, outputs all users in Azure AD and all available user properties in Microsoft Graph* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azusers file
*
./Azure_AD/get_groups.py* Takes in an access token or refresh token, outputs all groups in Azure AD and all available group properties in Microsoft Graph* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azgroups file
*
./Azure_AD/get_group_members.py* Takes in an access token or refresh token, outputs all group memberships in Azure AD and all available group member properties in Microsoft Graph* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azgroups file
*
./Azure_AD/get_subscriptions.py* Takes in an ARM token or refresh token, outputs all subscriptions in Azure and all available subscription properties in Azure Resource Manager* Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azgroups file
*
./Azure_AD/get_resource_groups.py* Takes in an ARM token or refresh token, outputs all resource groups in Azure and all available resource group properties in Azure Resource Manager* Creates two data files, a raw json file, and a BloodHound compatible azgroups file
*
./Azure_AD/get_vms.py* Takes in an ARM token or refresh token, outputs all virtual machines in Azure and all available VM properties in Azure Resource Manager* Creates two data files, a raw json file, and a BloodHound compatible azgroups file InstallationOffensive Azure can be installed in a number of ways or not at all.
You are welcome to clone the repository and execute the specific scripts you want. A
requirements.txtfile is included for each module to make this as easy as possible. PoetryThe project is built to work with poetry. To use, follow the next few steps: git clone https://github.com/blacklanternsecurity/offensive-azure.git
cd ./offensive-azure
poetry install PipThe packaged version of the repo is also kept on pypi so you can u[...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Offensive-Azure - Collection Of Offensive Tools Targeting Microsoft Azure
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Offensive-Azure - Collection Of Offensive Tools Targeting Microsoft Azure https://blogger.googleusercontent.com/img/a/AVvXsEgZHOFZxWcmcHCsU294blSAoz3ng4FukrxOYoBicFjqk69cnyNSdUHAa9GId6LCZ6PmhN0oMdKr4GM9hks1TOJPKU_wPMZVnE8dg7rzuN…
se
___________________________
@hacking_Attack
@Hacking_Video
pipto install as well. We recommend you use pipenvto keep your environment as clean as possible. pipenv shell
pip install offensive_azure UsageIt is up to you for how you wish to use this toolkit. Each module can be ran independently, or you can install it as a package and use it in that way. Each module is exported to a script named the same as the module file. For example: Poetrypoetry install
poetry run outsider_recon your-domain.com Pippipenv shell
pip install offensive_azure
outsider_recon your-domain.com Download Offensive-Azure___________________________
@hacking_Attack
@Hacking_Video
Deep Web
logins available
submitted by /u/ibnhamman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
logins available
submitted by /u/ibnhamman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
logins available
Posted in r/deepweb by u/ibnhamman • 1 point and 0 comments
hacking: security in practice
The Various Utilization Methods of PHP Serialization & Deserialization
https://b.thumbs.redditmedia.com/I1yXac20sUiJanhFQ5oRrI2BnOgDhx5TnmV7OZt-DdQ.jpg submitted by /u/CyberDevil24
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The Various Utilization Methods of PHP Serialization & Deserialization
https://b.thumbs.redditmedia.com/I1yXac20sUiJanhFQ5oRrI2BnOgDhx5TnmV7OZt-DdQ.jpg submitted by /u/CyberDevil24
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Various Utilization Methods of PHP Serialization & Deserialization
Posted in r/hacking by u/CyberDevil24 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
AOL Keyword Hacks (1990s - 2001)
https://external-preview.redd.it/NrRpZjCOgZ4MxUP7o0CNlpCcJ7GVEOMx4Vs5QYzlGIo.jpg?width=640&crop=smart&auto=webp&s=496058d21f5abe770ef3812ffb5759970ba603b7 submitted by /u/endless
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
AOL Keyword Hacks (1990s - 2001)
https://external-preview.redd.it/NrRpZjCOgZ4MxUP7o0CNlpCcJ7GVEOMx4Vs5QYzlGIo.jpg?width=640&crop=smart&auto=webp&s=496058d21f5abe770ef3812ffb5759970ba603b7 submitted by /u/endless
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
AOL Keyword Hacks (1990s - 2001)
Posted in r/hacking by u/endless • 1 point and 0 comments
hacking: security in practice
CTF team members!
Hi everyone
As many others have done before, I wanted to find team members for CTFs. I’m occasionally able to solve challenges from CTFs so I’m not a complete beginner.
On CTFtime.org I have a “team” but it’s just been me doing the challenges. Does anyone wanna join, if they have high school level ctf experience?
submitted by /u/Scarlaire
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
CTF team members!
Hi everyone
As many others have done before, I wanted to find team members for CTFs. I’m occasionally able to solve challenges from CTFs so I’m not a complete beginner.
On CTFtime.org I have a “team” but it’s just been me doing the challenges. Does anyone wanna join, if they have high school level ctf experience?
submitted by /u/Scarlaire
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
CTF team members!
Hi everyone As many others have done before, I wanted to find team members for CTFs. I’m occasionally able to solve challenges from CTFs so...
hacking: security in practice
Hacking MFA
I hear all the time, even from heavy hitters in the industry and even at RSA this week, that MFA is essential. We should be using any MFA, even weak MFA, instead of just passwords.
We just put out a podcast about why you need to be careful trusting all MFA to be secure with Roger Grimes, author of "Hacking Multi Factor Authentication".
Listen now on Spotify, Apple Podcasts or various other podcast platforms and let me know your thoughts!
submitted by /u/AgentLessBots
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking MFA
I hear all the time, even from heavy hitters in the industry and even at RSA this week, that MFA is essential. We should be using any MFA, even weak MFA, instead of just passwords.
We just put out a podcast about why you need to be careful trusting all MFA to be secure with Roger Grimes, author of "Hacking Multi Factor Authentication".
Listen now on Spotify, Apple Podcasts or various other podcast platforms and let me know your thoughts!
submitted by /u/AgentLessBots
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking MFA
I hear all the time, even from heavy hitters in the industry and even at RSA this week, that MFA is essential. We should be using any MFA, even...
Data Breach VPN User’s list Username & Password via Pulse Secure Access
https://medium.com/@Dhamuharker/data-breach-vpn-users-list-username-password-via-pulse-secure-access-2cece30936f4?source=rss------bug_bounty-5
Description:Continue reading on Medium » (https://medium.com/@Dhamuharker/data-breach-vpn-users-list-username-password-via-pulse-secure-access-2cece30936f4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Dhamuharker/data-breach-vpn-users-list-username-password-via-pulse-secure-access-2cece30936f4?source=rss------bug_bounty-5
Description:Continue reading on Medium » (https://medium.com/@Dhamuharker/data-breach-vpn-users-list-username-password-via-pulse-secure-access-2cece30936f4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Data Breach VPN User’s list Username & Password via Pulse Secure Access
Description:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
37 Major Companies and Organizations Pledge to Enhance Cyber Resiliency and Counter Evolving Global Threats
___________________________
@hacking_Attack
@Hacking_Video
37 Major Companies and Organizations Pledge to Enhance Cyber Resiliency and Counter Evolving Global Threats
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
37 Major Companies and Organizations Pledge to Enhance Cyber Resiliency and Counter Evolving Global Threats
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
ReliaQuest Bolsters Extended Detection With Threat Intelligence
ReliaQuest CTO Joe Partlow joins Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to discuss extended detection response — and acquisition news.
___________________________
@hacking_Attack
@Hacking_Video
ReliaQuest Bolsters Extended Detection With Threat Intelligence
ReliaQuest CTO Joe Partlow joins Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to discuss extended detection response — and acquisition news.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
ReliaQuest Bolsters Extended Detection With Threat Intelligence
ReliaQuest CTO Joe Partlow joins Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to discuss extended detection response — and acquisition news.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Uptycs: Observability Is Key to Cloud Security
Uptycs' Ganesh Pai joins Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to talk about cloud security and observability.
___________________________
@hacking_Attack
@Hacking_Video
Uptycs: Observability Is Key to Cloud Security
Uptycs' Ganesh Pai joins Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to talk about cloud security and observability.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Uptycs: Observability Is Key to Cloud Security
Uptycs' Ganesh Pai joins Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to talk about cloud security and observability.