Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Often a Red Team (https://www.kitploit.com/search/label/Red%20Team) engagement is more than just achieving Domain Admin. Some clients will want to see if specific users in the domain can be compromised, for example the CEO. SharpSniper is a simple tool to find the IP address of these users so that you can target their box. It requires that you have privileges to read logs on Domain Controllers. First it queries and makes a list of Domain contollers, then search for Log-on events on any of the DCs for the user you are looking for and then reads the most recent DHCP allocated logon (https://www.kitploit.com/search/label/Logon) IP address. N.B. Build can also target .net framework v3.5 if needed.
Usage cmd.exe (Supply credentials) C:\> SharpSniper.exe emusk DomainAdminUser DAPass123

User: emusk - IP Address: 192.168.37.130
cmd.exe (Current authentication (https://www.kitploit.com/search/label/Authentication) token e.g. Mimikatz pth) C:\> SharpSniper.exe emusk

User: emusk - IP Address: 192.168.37.130
Cobalt Strike (Supply credentials) > execute-assembly /path/to/SharpSniper.exe emusk DomainAdminUser DAPass123

User: emusk - IP Address: 192.168.37.130
Cobalt Strike (Beacon's token) > execute-assembly /path/to/SharpSniper.exe emusk

User: emusk - IP Address: 192.168.37.130
Author Tom Kallo

Download SharpSniper (https://github.com/HunnicCyber/SharpSniper)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
SharpSniper - Find Specific Users In Active Directory Via Their Username And Logon IP Address

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwVWfuzYRc9tPYetIUa59KyGLxqXLu4ksg-tZ4bT7_Cua7dtY4IlAjxbgIDso5iQOV0SbkTEaIcnnM5ySP9Q3TQ1u478NG4P5uhftfLz-hOUrIWGD6pypvJbuxJchOJL-TqRwg1EcaGkUyw6XaQRGULlmCyKkNRH5gbocF-b3JVu3Vg7LcS6GN3qVB/w640-h528/Active%20Directory.png
Often a Red Team engagement is more than just achieving Domain Admin. Some clients will want to see if specific users in the domain can be compromised, for example the CEO.

SharpSniper is a simple tool to find the IP address of these users so that you can target their box.

It requires that you have privileges to read logs on Domain Controllers.

First it queries and makes a list of Domain contollers, then search for Log-on events on any of the DCs for the user you are looking for and then reads the most recent DHCP allocated logon IP address.

N.B. Build can also target .net framework v3.5 if needed.
Usage

cmd.exe (Supply credentials)

C:\> SharpSniper.exe emusk DomainAdminUser DAPass123

User: emusk - IP Address: 192.168.37.130


cmd.exe (Current authentication token e.g. Mimikatz pth)

C:\> SharpSniper.exe emusk

User: emusk - IP Address: 192.168.37.130


Cobalt Strike (Supply credentials)

> execute-assembly /path/to/SharpSniper.exe emusk DomainAdminUser DAPass123

User: emusk - IP Address: 192.168.37.130


Cobalt Strike (Beacon's token)

> execute-assembly /path/to/SharpSniper.exe emusk

User: emusk - IP Address: 192.168.37.130


Author

Tom Kallo
Download SharpSniper

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best VPN to use?

If money isnt a issue , which would you suggest is best.thanks

submitted by /u/RepresentativeEgg511
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Has anyone had good result with the adjective-noun-3# pass list, against spectrum? The wordlist resides in the wiki of this subreddit.

I have downloaded it and plan on using it on my home connection after pw reset. I’m not 100% but I’m almost certain the list is not every possible combination. It’s only 4.1gb (massive) but with the format you’d think it’d be bigger, could be wrong.

I’m solely asking for educational purposes, and plan to promote good practices within the people I know.

I’m curious on the effectiveness, and If applicable, the amount of time it took to run through the entire list if it has been done.

Lmk if you have questions.

Thank you in advance :)

submitted by /u/Inner-Tie-9528
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there a place where I can find someone?

I know this community has a rule about no asking for someone to hack into an account and this isn't what I'm asking. Does anyone know a person or website where I can find a phone number or email attached to a scammers account? DM me if you do, I got an idea

submitted by /u/Fang696
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
There's a group of hackers holding hostage most Ubisoft account names.

They use bots to auto create accounts with names by a certain number of characters. They pull accounts with rare skins and sell them at high value.

My friends and I are annoyed because we can't have names without dots and dashes.

How are these guys doing this? What can I do about it?

submitted by /u/aGuyOnTheMoon
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Phishing site URL sent to my phone is inaccessible to my PC. What's the deal?

So a scammer sent a link for an old bank account designed to phish my credentials. I can access it from my phone and it pops up as my former banks login screen. Now when I go to scan the URL with my PC, it doesn't exist. I first tried pinging the URL and then traceroute, nmap, metasploit, a few more etc... None pull up an IP/server. Nothing found. The URL is 100% without typo. I haven't been involved in pentesting or netsec in a few years and am wondering what the deal is. What's changed? Why am I able to access the URL from the text message on my phone but not my PC? It's a .php site. What am I missing? This is a new encounter for me.

submitted by /u/Day2Late
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Freaked out…

Help .. so freaked out.

Middle of WhatsApp chat conversation with my sister she says did you just send a pic it disappeared? It happened once last week also? Is this a glitch or has she or I been hacked? So creeped out.

submitted by /u/rockandharderplace
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Free and Anonymous VOIP services

Are there any free and Anonymous VOIP services which offer phone numbers for use without asking for any personal information. The free part is not 100% necessary but would be preferable. I basically want a burner phone number which I can use to login to sites which require a phone number for verifying identity. I do not wish to give away my actual phone number to some less than trustworthy sites which I might need to visit.

submitted by /u/juggernaut_2000
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Graphql-Threat-Matrix : GraphQL Threat Framework Used By Security Professionals

graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.

The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations.

Legend
https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png – Enabled by Default
https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png – Disabled by Default
https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png – No Support
ImplementationValidationsField SuggestionsQuery Depth limitQuery Cost AnalysisAutomatic Persisted QueriesIntrospectionDebug ModeBatch Requestswp-graphql38https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png graphql-php37https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Apollo34https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png graphql-yoga34https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png graphene34https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Ariadne34https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png Strawberry34https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png graphql-ruby28https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Malicious-Pdf : Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality

Malicious-Pdf Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

Used for penetration testing and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links.

Usage

python3 malicious-pdf.py burp-collaborator-url

Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory.

Do not use the https:// etc prefix on the url argument.

Purpose

* Test web pages/services accepting PDF-files
* Test security products
* Test PDF readers
* Test PDF converters
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Graphql-Threat-Matrix : GraphQL Threat Framework Used By Security Professionals graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL…
14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Sangria27https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Tartiflette26https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png graphql-java26https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png gqlgen25https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Dgraph25https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png graphql-go24https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png juniper24https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Diana.jl10https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png gql-dart/gql9https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png Agoo1https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https:/[...]