Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Msprobe - Finding All Things On-Prem Microsoft For Password Spraying And Enumeration
https://blogger.googleusercontent.com/img/a/AVvXsEjqZLL3S1uWaZasPCU44aX8p703eJtkSajz4Tg14nbMiiw5cPLIuJNsdOfwDttJw67bKcqdUTbM3cMpM4VCsWrGGKMXguHGgXVqMz_8EFdpexSX1XH1gHfA8gvIBtUbBLeUGGTLUxTpb5f6CjEYerRxpImJ1X_8ql7Q1AS9vOuqRLloZL83dJkThQX0=w640-h438
Finding all things on-prem Microsoft for password spraying and enumeration.
The tool will used a list of common subdomains associated with your target apex domain to attempt to discover valid instances of on-prem Microsoft solutions. Screenshots of the tool in action are below:
Installing
Install the project using pipx
Usage
The tool has four different modules that assist with the discovery of on-prem Microsoft products:
* Exchange
* RD Web
* ADFS
* Skype for Business
The help menu and supported modules are shown below:
Examples
Find ADFS servers associated with apex domain:
Find RD Web servers associated with apex domain with verbose output:
Find all Microsoft products hostsed on-prem for a domain:
Coming Soon
* Full wiki for each module
* Fixes for lxml based parsing in RD Web module
Acknowledgements
* @p0dalirius for RDWArecon
* @b17zr for the
* @ReverendThing for his project Carnivore and it's included subdomains
* @busterbcook and their tool msmailprobe heavily influenced the creation of this project
Download Msprobe
___________________________
@hacking_Attack
@Hacking_Video
Msprobe - Finding All Things On-Prem Microsoft For Password Spraying And Enumeration
https://blogger.googleusercontent.com/img/a/AVvXsEjqZLL3S1uWaZasPCU44aX8p703eJtkSajz4Tg14nbMiiw5cPLIuJNsdOfwDttJw67bKcqdUTbM3cMpM4VCsWrGGKMXguHGgXVqMz_8EFdpexSX1XH1gHfA8gvIBtUbBLeUGGTLUxTpb5f6CjEYerRxpImJ1X_8ql7Q1AS9vOuqRLloZL83dJkThQX0=w640-h438
Finding all things on-prem Microsoft for password spraying and enumeration.
The tool will used a list of common subdomains associated with your target apex domain to attempt to discover valid instances of on-prem Microsoft solutions. Screenshots of the tool in action are below:
Installing
Install the project using pipx
pipx install git+https://github.com/puzzlepeaches/msprobe.git
Usage
The tool has four different modules that assist with the discovery of on-prem Microsoft products:
* Exchange
* RD Web
* ADFS
* Skype for Business
The help menu and supported modules are shown below:
Usage: msprobe [OPTIONS] COMMAND [ARGS]...
Find Microsoft Exchange, RD Web, ADFS, and Skype instances
Options:
--help Show this message and exit.
Commands:
adfs Find Microsoft ADFS servers
exch Find Microsoft Exchange servers
full Find all Microsoft supported by msprobe
rdp Find Microsoft RD Web servers
skype Find Microsoft Skype servers
Examples
Find ADFS servers associated with apex domain:
msprobe adfs acme.com
Find RD Web servers associated with apex domain with verbose output:
msprobe rdp acme.com -v
Find all Microsoft products hostsed on-prem for a domain:
msprobe full acme.com
Coming Soon
* Full wiki for each module
* Fixes for lxml based parsing in RD Web module
Acknowledgements
* @p0dalirius for RDWArecon
* @b17zr for the
ntlm_challenger.pyscript* @ReverendThing for his project Carnivore and it's included subdomains
* @busterbcook and their tool msmailprobe heavily influenced the creation of this project
Download Msprobe
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Msprobe - Finding All Things On-Prem Microsoft For Password Spraying And Enumeration
Improving AI-based defenses to disrupt human-operated ransomware
https://www.reddit.com/r/redteamsec/comments/vhgs3j/improving_aibased_defenses_to_disrupt/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/ImprovingAIDefenses) [comments] (https://www.reddit.com/r/redteamsec/comments/vhgs3j/improving_aibased_defenses_to_disrupt/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/vhgs3j/improving_aibased_defenses_to_disrupt/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/ImprovingAIDefenses) [comments] (https://www.reddit.com/r/redteamsec/comments/vhgs3j/improving_aibased_defenses_to_disrupt/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Improving AI-based defenses to disrupt human-operated ransomware
Posted in r/redteamsec by u/SCI_Rusher • 1 point and 0 comments
IDOR vulnerability
https://medium.com/@0UN390/idor-vulnerability-6eadc5c67bc1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@0UN390/idor-vulnerability-6eadc5c67bc1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR vulnerability
1- What’s the IDOR?
1- What’s the IDOR?Continue reading on Medium » (https://medium.com/@0UN390/idor-vulnerability-6eadc5c67bc1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR vulnerability
1- What’s the IDOR?
hacking: security in practice
Is it possible to MITM a phone that is using mobile data?
I know you can interfere/watch the communication between a device and a router. But what if the person is using mobile data? Is it possible to do a MITM attack on it? If so, how should I research it, what is it called?
submitted by /u/33sikici33
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to MITM a phone that is using mobile data?
I know you can interfere/watch the communication between a device and a router. But what if the person is using mobile data? Is it possible to do a MITM attack on it? If so, how should I research it, what is it called?
submitted by /u/33sikici33
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to MITM a phone that is using mobile data?
I know you can interfere/watch the communication between a device and a router. But what if the person is using mobile data? Is it possible to do...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cloudflare outage on June 21, 2022
The conspiracy theories that will come from this
submitted by /u/capj400
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Cloudflare outage on June 21, 2022
The conspiracy theories that will come from this
submitted by /u/capj400
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cloudflare outage on June 21, 2022
The conspiracy theories that will come from this
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A python tool to translate a shellcode from assembly to python2 commands when doing pwn in CTF
https://external-preview.redd.it/koTmFdbLbOyvGnbyBCyp_En524QGWmdwXi1FgubFT68.jpg?width=108&crop=smart&auto=webp&s=381ad2a593cf874eaab7578fe94b9545e3722d7a submitted by /u/Podalirius_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A python tool to translate a shellcode from assembly to python2 commands when doing pwn in CTF
https://external-preview.redd.it/koTmFdbLbOyvGnbyBCyp_En524QGWmdwXi1FgubFT68.jpg?width=108&crop=smart&auto=webp&s=381ad2a593cf874eaab7578fe94b9545e3722d7a submitted by /u/Podalirius_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A python tool to translate a shellcode from assembly to python2...
Posted in r/hacking by u/Podalirius_ • 2 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to detect the containers’ escape capabilities with Falco
Capabilities provide a way to limit the level of access a container can have, splitting the power of the root user into more granular units. However, they are often misconfigured, granting excessive privileges to processes and threads.
I have seen some examples to exploit this really interesting abuse:
* https://tbhaxor.com/exploiting-linux-capabilities-part-2/
* https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/
In this case, I want to share a more blue team approach, the detection of CAP_SYS_ADMIN abuse when performing container escaping:
* https://sysdig.com/blog/container-escape-capabilities-falco-detection/
submitted by /u/MiguelHzBz
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to detect the containers’ escape capabilities with Falco
Capabilities provide a way to limit the level of access a container can have, splitting the power of the root user into more granular units. However, they are often misconfigured, granting excessive privileges to processes and threads.
I have seen some examples to exploit this really interesting abuse:
* https://tbhaxor.com/exploiting-linux-capabilities-part-2/
* https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/
In this case, I want to share a more blue team approach, the detection of CAP_SYS_ADMIN abuse when performing container escaping:
* https://sysdig.com/blog/container-escape-capabilities-falco-detection/
submitted by /u/MiguelHzBz
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to detect the containers’ escape capabilities with Falco
**Capabilities** provide a way to **limit the level of access** a container can have, splitting the power of the root user into more granular...
hacking: security in practice
Is it possible to turn a normal USB into a hacking USB?
Do i need a rubber ducky? or is there a way to get the same out come from a normal usb?
submitted by /u/CatLoveeeer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to turn a normal USB into a hacking USB?
Do i need a rubber ducky? or is there a way to get the same out come from a normal usb?
submitted by /u/CatLoveeeer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to turn a normal USB into a hacking USB?
Do i need a rubber ducky? or is there a way to get the same out come from a normal usb?
hacking: security in practice
learning how to hack
Hey, this summer I plan to learn cyber security and hacking, as a result of spending time with my older friends who got roles in cyber defense and cyber attacks. I would like to hear recommendations for tutorials/articles about those professions and learn them (if it's necessary to know I do have experience in programming (python, java, c++, javascript, c#, and Linux)). Thanks.
submitted by /u/Big-mushr00m
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
learning how to hack
Hey, this summer I plan to learn cyber security and hacking, as a result of spending time with my older friends who got roles in cyber defense and cyber attacks. I would like to hear recommendations for tutorials/articles about those professions and learn them (if it's necessary to know I do have experience in programming (python, java, c++, javascript, c#, and Linux)). Thanks.
submitted by /u/Big-mushr00m
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
learning how to hack
Hey, this summer I plan to learn cyber security and hacking, as a result of spending time with my older friends who got roles in cyber defense and...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hackers Can Turn Satellites Into Weapons
https://external-preview.redd.it/ncO3lUfPLSNLGvXXX0IfZsf6WXXHfJOGnL8TfZtE2cY.jpg?width=320&crop=smart&auto=webp&s=84dee5d5d7af2672441715772c178999243fbd95 submitted by /u/Arditbicaj
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hackers Can Turn Satellites Into Weapons
https://external-preview.redd.it/ncO3lUfPLSNLGvXXX0IfZsf6WXXHfJOGnL8TfZtE2cY.jpg?width=320&crop=smart&auto=webp&s=84dee5d5d7af2672441715772c178999243fbd95 submitted by /u/Arditbicaj
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hackers Can Turn Satellites Into Weapons
Posted in r/hacking by u/Arditbicaj • 1 point and 0 comments
Burpsuite
https://www.reddit.com/r/Pentesting/comments/vhhm69/burpsuite/
Hey I’m trying to fuzz using intruder and positions.. I remember doing a lab a few years ago on port swigger where I enumerated letter by letter and from the response gathered the entire password , but can no longer find the page or an tut. submitted by /u/Few_Lack_4505 (https://www.reddit.com/user/Few_Lack_4505)
[link] (https://www.reddit.com/r/Pentesting/comments/vhhm69/burpsuite/) [comments] (https://www.reddit.com/r/Pentesting/comments/vhhm69/burpsuite/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/vhhm69/burpsuite/
Hey I’m trying to fuzz using intruder and positions.. I remember doing a lab a few years ago on port swigger where I enumerated letter by letter and from the response gathered the entire password , but can no longer find the page or an tut. submitted by /u/Few_Lack_4505 (https://www.reddit.com/user/Few_Lack_4505)
[link] (https://www.reddit.com/r/Pentesting/comments/vhhm69/burpsuite/) [comments] (https://www.reddit.com/r/Pentesting/comments/vhhm69/burpsuite/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/Pentesting - Burpsuite
2 votes and 2 comments so far on Reddit
$1,500 XSS — what to consider during the bug bounty
https://medium.com/@citril/1-500-xss-what-to-consider-during-the-bug-bounty-8749b8911369?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@citril/1-500-xss-what-to-consider-during-the-bug-bounty-8749b8911369?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
$1,500 XSS — what to consider during the bug bounty
Hello folks, long time no see! I recently got my bounty from one of private programs on HackerOne and wanted to talked about it, share my…