Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OWASP Top 10: #1 — Injection
https://cdn-images-1.medium.com/max/600/1*1fOyXpTbDTDzc3baL-roiw.png
The only Top 10 list that actually f*cking matters.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OWASP Top 10: #1 — Injection
https://cdn-images-1.medium.com/max/600/1*1fOyXpTbDTDzc3baL-roiw.png
The only Top 10 list that actually f*cking matters.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OWASP Top 10: #1 — Injection
The only Top 10 list that actually f*cking matters.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Identify Your Phone Got Hacked and How to Avoid It?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Identify Your Phone Got Hacked and How to Avoid It?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Identify Your Phone Got Hacked and How to Avoid It?
Without your knowledge, phone hacking can endanger your identity and privacy. Hacking techniques are always evolving and improving, making them more difficult to detect. This means that any amount of cyberattacks might blind the ordinary user. Fortunately…
Java Application -Server Side Template Injection
Description:Continue reading on Medium »
Read more...
Description:Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I made a script to brick any windows PC
Here is the link to the script
https://github.com/SomeoneAlt-86/pc-killer
So the way it works is lowering the system memory to very low so that windows is unable to boot once restarted.
submitted by /u/Ambitious-Cod-7354
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I made a script to brick any windows PC
Here is the link to the script
https://github.com/SomeoneAlt-86/pc-killer
So the way it works is lowering the system memory to very low so that windows is unable to boot once restarted.
submitted by /u/Ambitious-Cod-7354
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I made a script to brick any windows PC
Here is the link to the script [https://github.com/SomeoneAlt-86/pc-killer](https://github.com/SomeoneAlt-86/pc-killer) So the way it works is...
Msprobe - Finding All Things On-Prem Microsoft For Password Spraying And Enumeration
http://www.kitploit.com/2022/06/msprobe-finding-all-things-on-prem.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/06/msprobe-finding-all-things-on-prem.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Msprobe - Finding All Things On-Prem Microsoft For Password Spraying And Enumeration
Finding all things on-prem Microsoft (https://www.kitploit.com/search/label/Microsoft) for password spraying and enumeration. The tool will used a list of common subdomains (https://www.kitploit.com/search/label/Subdomains) associated with your target apex domain to attempt to discover (https://www.kitploit.com/search/label/Discover) valid instances of on-prem Microsoft solutions. Screenshots of the tool in action are below:
Installing Install the project using pipx (https://pypa.github.io/pipx/installation/) pipx install git+https://github.com/puzzlepeaches/msprobe.git
Usage The tool has four different modules that assist with the discovery (https://www.kitploit.com/search/label/Discovery) of on-prem Microsoft products: Exchange RD Web ADFS Skype for Business The help menu and supported modules are shown below: Usage: msprobe [OPTIONS] COMMAND [ARGS]...
Find Microsoft Exchange, RD Web, ADFS, and Skype instances
Options:
--help Show this message and exit.
Commands:
adfs Find Microsoft ADFS servers
exch Find Microsoft Exchange servers
full Find all Microsoft supported by msprobe
rdp Find Microsoft RD Web servers
skype Find Microsoft Skype servers
Examples Find ADFS servers associated with apex domain: msprobe adfs acme.com
Find RD Web servers associated with apex domain with verbose output: msprobe rdp acme.com -v
Find all Microsoft products hostsed on-prem for a domain: msprobe full acme.com
Coming Soon Full wiki for each module Fixes for lxml based parsing (https://www.kitploit.com/search/label/Parsing) in RD Web module Acknowledgements @p0dalirius (https://twitter.com/intent/follow?screen_name=podalirius_) for RDWArecon (https://github.com/p0dalirius/RDWArecon) @b17zr (https://twitter.com/b17zr) for the ntlm_challenger.py script @ReverendThing (https://github.com/ReverendThing) for his project Carnivore (https://github.com/ReverendThing/Carnivore) and it's included subdomains @busterbcook (https://twitter.com/busterbcook) and their tool msmailprobe (https://github.com/busterb/msmailprobe) heavily influenced the creation of this project
Download Msprobe (https://github.com/puzzlepeaches/msprobe)
___________________________
@hacking_Attack
@Hacking_Video
Installing Install the project using pipx (https://pypa.github.io/pipx/installation/) pipx install git+https://github.com/puzzlepeaches/msprobe.git
Usage The tool has four different modules that assist with the discovery (https://www.kitploit.com/search/label/Discovery) of on-prem Microsoft products: Exchange RD Web ADFS Skype for Business The help menu and supported modules are shown below: Usage: msprobe [OPTIONS] COMMAND [ARGS]...
Find Microsoft Exchange, RD Web, ADFS, and Skype instances
Options:
--help Show this message and exit.
Commands:
adfs Find Microsoft ADFS servers
exch Find Microsoft Exchange servers
full Find all Microsoft supported by msprobe
rdp Find Microsoft RD Web servers
skype Find Microsoft Skype servers
Examples Find ADFS servers associated with apex domain: msprobe adfs acme.com
Find RD Web servers associated with apex domain with verbose output: msprobe rdp acme.com -v
Find all Microsoft products hostsed on-prem for a domain: msprobe full acme.com
Coming Soon Full wiki for each module Fixes for lxml based parsing (https://www.kitploit.com/search/label/Parsing) in RD Web module Acknowledgements @p0dalirius (https://twitter.com/intent/follow?screen_name=podalirius_) for RDWArecon (https://github.com/p0dalirius/RDWArecon) @b17zr (https://twitter.com/b17zr) for the ntlm_challenger.py script @ReverendThing (https://github.com/ReverendThing) for his project Carnivore (https://github.com/ReverendThing/Carnivore) and it's included subdomains @busterbcook (https://twitter.com/busterbcook) and their tool msmailprobe (https://github.com/busterb/msmailprobe) heavily influenced the creation of this project
Download Msprobe (https://github.com/puzzlepeaches/msprobe)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Java Application -Server Side Template Injection
https://medium.com/@Dhamuharker/java-application-server-side-template-injection-f2aa4d2bb41?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Dhamuharker/java-application-server-side-template-injection-f2aa4d2bb41?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Java Application -Server Side Template Injection
Description:
Description:Continue reading on Medium » (https://medium.com/@Dhamuharker/java-application-server-side-template-injection-f2aa4d2bb41?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Java Application -Server Side Template Injection
Description:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Email-Prediction-Asterisks : Script That Allows You To Identify The Emails Hidden Behind Asterisks
Email prediction asterisks is a script that allows you to identify the emails hidden behind asterisks. It is a perfect application for osint analysts and security forces. It allows to intelligently predict, using Intelx leaks, which emails are related to the person we are looking for. It also allows you to automatically obtain information from emails for manual analysis through a CSV dataset that is generated with the results.
Example of email with asterisks on Twitter
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Bp_XVCG2s7m1ThSYdzbW3hACICHhOWKSI7KWY92VCAa2GRl_M6LQUYxY8D_9JgkIoOppzgOcV2itjFNVFI4de_Bt2XRobuJH5ww4LXoEsm_f_FlFHrT9cbW3TCK59vNlhVSmAS0L8P6Z8Xm1bu61IVAAkT6nMQLEOHTtGBTtYlKqD2Lgi2tDNj_B/s578/email-asterisks.png
Installation
It’s necessary to install the intelx library for python
git clone https://github.com/Quantika14/email-prediction-asterisks
pip3 install -r requiriments.txt
git clone https://github.com/IntelligenceX/SDK
pip3 install SDK/Python
You must put your api key here
Directory: m/key.py
intelx = “HERE”
emailrep = “HERE”
Download
___________________________
@hacking_Attack
@Hacking_Video
Email-Prediction-Asterisks : Script That Allows You To Identify The Emails Hidden Behind Asterisks
Email prediction asterisks is a script that allows you to identify the emails hidden behind asterisks. It is a perfect application for osint analysts and security forces. It allows to intelligently predict, using Intelx leaks, which emails are related to the person we are looking for. It also allows you to automatically obtain information from emails for manual analysis through a CSV dataset that is generated with the results.
Example of email with asterisks on Twitter
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Bp_XVCG2s7m1ThSYdzbW3hACICHhOWKSI7KWY92VCAa2GRl_M6LQUYxY8D_9JgkIoOppzgOcV2itjFNVFI4de_Bt2XRobuJH5ww4LXoEsm_f_FlFHrT9cbW3TCK59vNlhVSmAS0L8P6Z8Xm1bu61IVAAkT6nMQLEOHTtGBTtYlKqD2Lgi2tDNj_B/s578/email-asterisks.png
Installation
It’s necessary to install the intelx library for python
git clone https://github.com/Quantika14/email-prediction-asterisks
pip3 install -r requiriments.txt
git clone https://github.com/IntelligenceX/SDK
pip3 install SDK/Python
You must put your api key here
Directory: m/key.py
intelx = “HERE”
emailrep = “HERE”
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Email-Prediction-Asterisks : Script That Allows You To Identify The Emails
Email prediction asterisks is a script that allows you to identify the emails hidden behind asterisks. It is a perfect application for osint
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
PEzor-Docker : With The Help Of This Docker Image, You Can Easily Access PEzor On Your System!
PEzor-Docker, With the help of this incredible tool, you can create FUD malwares that are capable of bypassing most of the well-known AVs. For instance, you can pack the “mimikatz” executable file with the help of PEzor and then run it against victim’s system for a full mem dump without any problem!
How to use
docker pull https://hub.docker.com/r/4d0niis/pezor_included_kali:1.0
docker run -it 4d0niis/pezor_included_kali:1.0 /bin/bash
PEzor
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVKYb2ABFihCTRrxGUk1IVlua59KA6uj3fy-4vVtCBqZUs91p2ircwz3pQhSd1C9f_77pE21lindU-avprjbMxN-PgpMoNkeKLhM0LM6i1JRz6qO8rnllekLFyFkEoAyeC5YktiIoxvDEcfnMUEL5de5T0d0tP05xWnOAZGdYZ4oI9uwh0atMKB8_c/s1263/PEzor_docker.png
Download
___________________________
@hacking_Attack
@Hacking_Video
PEzor-Docker : With The Help Of This Docker Image, You Can Easily Access PEzor On Your System!
PEzor-Docker, With the help of this incredible tool, you can create FUD malwares that are capable of bypassing most of the well-known AVs. For instance, you can pack the “mimikatz” executable file with the help of PEzor and then run it against victim’s system for a full mem dump without any problem!
How to use
docker pull https://hub.docker.com/r/4d0niis/pezor_included_kali:1.0
docker run -it 4d0niis/pezor_included_kali:1.0 /bin/bash
PEzor
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVKYb2ABFihCTRrxGUk1IVlua59KA6uj3fy-4vVtCBqZUs91p2ircwz3pQhSd1C9f_77pE21lindU-avprjbMxN-PgpMoNkeKLhM0LM6i1JRz6qO8rnllekLFyFkEoAyeC5YktiIoxvDEcfnMUEL5de5T0d0tP05xWnOAZGdYZ4oI9uwh0atMKB8_c/s1263/PEzor_docker.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
PEzor-Docker : With The Help Of This Docker Image
PEzor-Docker, With the help of this incredible tool, you can create FUD malwares that are capable of bypassing most of the well-known AVs.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
GoSH : Golang Reverse/Bind Shell Generator
GoSH is a tool that generates a Go binary that launches a shell of the desired type on the targeted host.
The shell binary can be compiled for multiple platforms, supports partial polymorphism (unique functions’ names) and can use UDP protocol instead of the default TCP. If you send a
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnC-WEYdeAt0x860SwaRAydrT_858TCdri7AEVI1139na9sYmabGz1Jj9Z4WG9_ZZ_Mzxgz1LkRdlHCWK1AFn3b7goCZqZSvag2N7XAu1OOY7l9ya1pBborH3Ndl0cJMeNX5Uc-qpWewNXUImUjbzo6756_pimTXJg69U7zw-D4X83JpT4nC3Ct_qV/s1920/screenshot.png
Download
___________________________
@hacking_Attack
@Hacking_Video
GoSH : Golang Reverse/Bind Shell Generator
GoSH is a tool that generates a Go binary that launches a shell of the desired type on the targeted host.
The shell binary can be compiled for multiple platforms, supports partial polymorphism (unique functions’ names) and can use UDP protocol instead of the default TCP. If you send a
DELETEcommand over the established connection, the shell binary removes itself from the host it was executed on.https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnC-WEYdeAt0x860SwaRAydrT_858TCdri7AEVI1139na9sYmabGz1Jj9Z4WG9_ZZ_Mzxgz1LkRdlHCWK1AFn3b7goCZqZSvag2N7XAu1OOY7l9ya1pBborH3Ndl0cJMeNX5Uc-qpWewNXUImUjbzo6756_pimTXJg69U7zw-D4X83JpT4nC3Ct_qV/s1920/screenshot.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
GoSH : Golang Reverse/Bind Shell Generator !!! Kali Linux
GoSH is a tool that generates a Go binary that launches a shell of the desired type on the targeted host. The shell binary can be compiled .
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CVE-Tracker : With The Help Of This Automated Script, You Will Never Lose Track Of Recently Released CVEs
CVE-Tracker, With the help of this automated script, you will never lose track of newly released CVEs. What does this powershell script do is exactly running the Microsoft Edge at system startup, navigate to 2 URLs ,and then put the browser in to full screen mode.
As ethical hackers, it’s vital that we keep track of the recently released CVEs in order to be fully aware of new threats or vulnerabilities out there in the Internet. Actually, it’s a routine task in our day to day lives. So why don’t we just automate the whole procedure of opening a browser and navigate to our sources for cheking the new CVEs? The purpose of this tool is to basically, automate the mentioned procedure with the help of powershell scripting.
Among all the online sources that are available which publish new CVEs, I’ve chosen the following 2 URLs and leveraged them in the script.
URLshttps://cvetrends.com/https://cve.circl.lu/
If you want to change these URLs to your desired ones, you can simply open the cve.ps1 file with an editor and change the URLs there! Also remember that you can even add more URLs to the file.
Usage
Download the zip file and unzip it on your system
If you haven’t bypassed the script execution on your system, please do so with the command “Set-ExecutionPolicy -ExecutionPolicy Bypass”
[Note: it needs to be run as administrator]
.\CVE_Track.ps1
Also, keep in mind the changes that are made to your system can easily be undone, by running the command
Technical Analysis
At first, when you run the script, it will create a *.bat file (CVE_Track.bat) in the following directory that literally allows the automation procedure that we aim for. C:\Users\.
Also the file “cv.ps1” is coppied to the directory C:\Users\and every time the system starts, it will be executed.
Download
___________________________
@hacking_Attack
@Hacking_Video
CVE-Tracker : With The Help Of This Automated Script, You Will Never Lose Track Of Recently Released CVEs
CVE-Tracker, With the help of this automated script, you will never lose track of newly released CVEs. What does this powershell script do is exactly running the Microsoft Edge at system startup, navigate to 2 URLs ,and then put the browser in to full screen mode.
As ethical hackers, it’s vital that we keep track of the recently released CVEs in order to be fully aware of new threats or vulnerabilities out there in the Internet. Actually, it’s a routine task in our day to day lives. So why don’t we just automate the whole procedure of opening a browser and navigate to our sources for cheking the new CVEs? The purpose of this tool is to basically, automate the mentioned procedure with the help of powershell scripting.
Among all the online sources that are available which publish new CVEs, I’ve chosen the following 2 URLs and leveraged them in the script.
URLshttps://cvetrends.com/https://cve.circl.lu/
If you want to change these URLs to your desired ones, you can simply open the cve.ps1 file with an editor and change the URLs there! Also remember that you can even add more URLs to the file.
Usage
Download the zip file and unzip it on your system
If you haven’t bypassed the script execution on your system, please do so with the command “Set-ExecutionPolicy -ExecutionPolicy Bypass”
[Note: it needs to be run as administrator]
.\CVE_Track.ps1
Also, keep in mind the changes that are made to your system can easily be undone, by running the command
.\undo.ps1Technical Analysis
At first, when you run the script, it will create a *.bat file (CVE_Track.bat) in the following directory that literally allows the automation procedure that we aim for. C:\Users\.
Also the file “cv.ps1” is coppied to the directory C:\Users\and every time the system starts, it will be executed.
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
CVE-Tracker : With The Help Of This Automated ScriptYou Will Never Lose
CVE-Tracker, With the help of this automated script, you will never lose track of newly released CVEs. What does this powershell script do.