Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Tofu - Windows Offline Filesystem Hacking Tool For Linux

https://blogger.googleusercontent.com/img/a/AVvXsEiRBblKzDIJUpBED4aFKrwcceuJwrAGbBsHbhYlR2qEJzpay49ageL-4FocWW4koV6DTl2ecr546jmm5DBNtX2wIcX3Pk7DaVhl3fVMriqDzh72wiFS_H_YGCYK59TfIbeL35Ct5CzwsMDfb3LsG8WK4iCMmcHluJk4HIqf6cPqUZXwocWNhtEVNMsi=w640-h436
A modular tool for hacking offline Windows filesystems and bypassing login screens. Can do hashdumps, OSK-Backdoors, user enumeration and more.
How it works :
When a Windows machine is shut down, unless it has Bitlocker or another encryption service enabled, it's storage device contains everything stored on the device as if it was unlocked. This means that you can boot from an operating system on a bootable USB and access it's files - or even just connect the filesystem to another computer.
This tool helps for when you can access the Windows filesystem from Linux (using one of the mentioned methods); it has utilities that can dump NTLM password hashes, list users, install backdoors to spawn an elevated command prompt at the login screen and more.
Modules :
Because tofu works on modules, it can be expanded for different purposes. See the 'modules' section for examples.
Current Modules:
1. hashdump.py- Dumps NTLM hashes from the target Windows filesystem
2. osk_backdoor.py- Backdoor osk.exe to bypass the login; also includes an 'unbackdoor' module
3. list_users.py- List the users with a profile on the Windows filesystem
4. chrome.py- Dump chrome history and login data of all users on the Windows filesystem
5. get_dpapi_masterkeys.py- Dump DPAPI master keys from the Windows filesystem
6. enum_unattend.py- Enumerate unattend files
7. memory_strings.py- Search through the memory of the computer to find data
8. startup.py- Inject a program into a user's startup directory
9. wifi.py- Get Wi-Fi passwords with DPAPI

Usage :
'list' : List all storage devices at /dev/ with a format of MSDOS, NTFS or -FVE-FS- (BITLOCKER) ; This will load the drive paths into memory
'usedrive' : Set the drive to use; can use numbers assigned from the 'list' command
'modules' : List modules ; This will load the module names into memory, so you need to run this command before selecting a module
'use' : Use the selected module

Setup :
(need to run as root because PyPyKatz' import path directory is dependent on the current user, and this needs to run as root)
sudo pip3 install -r requirements.txt
sudo python3
tofu.py
Built With :
PyCryptodome
PypyKatz

Warning : If you're writing a module, make sure it won't do any damage before running it

Download Tofu

___________________________
@hacking_Attack
@Hacking_Video
A modular tool for hacking offline Windows filesystems and bypassing login screens. Can do hashdumps, OSK-Backdoors, user enumeration (https://www.kitploit.com/search/label/User%20Enumeration) and more.

How it works : When a Windows machine is shut down, unless it has Bitlocker or another encryption (https://www.kitploit.com/search/label/Encryption) service enabled, it's storage device contains everything stored on the device as if it was unlocked. This means that you can boot from an operating system on a bootable USB and access it's files - or even just connect the filesystem to another computer.
This tool helps for when you can access the Windows filesystem from Linux (using one of the mentioned methods); it has utilities that can dump NTLM password hashes, list users, install backdoors to spawn an elevated command prompt at the login screen and more.
Modules : Because tofu works on modules, it can be expanded for different purposes. See the 'modules' section for examples.
Current Modules:
1. hashdump.py - Dumps NTLM hashes from the target Windows filesystem
2. osk_backdoor.py - Backdoor osk.exe to bypass the login; also includes an 'unbackdoor' module
3. list_users.py - List the users with a profile on the Windows filesystem
4. chrome.py - Dump chrome history (https://www.kitploit.com/search/label/Chrome%20History) and login data of all users on the Windows filesystem
5. get_dpapi_masterkeys.py - Dump DPAPI master keys from the Windows filesystem
6. enum_unattend.py - Enumerate unattend files
7. memory_strings.py - Search through the memory of the computer to find data
8. startup.py - Inject a program into a user's startup directory
9. wifi.py - Get Wi-Fi passwords with DPAPI
Usage : 'list' : List all storage devices at /dev/ with a format of MSDOS, NTFS or -FVE-FS- (BITLOCKER) ; This will load the drive paths into memory
'usedrive' : Set the drive to use; can use numbers assigned from the 'list' command
'modules' : List modules ; This will load the module names into memory, so you need to run this command before selecting a module
'use' : Use the selected module
Setup : (need to run as root because PyPyKatz' import path directory is dependent on the current user, and this needs to run as root)
sudo pip3 install -r requirements.txt
sudo python3 tofu.py Built With : PyCryptodome (https://github.com/Legrandin/pycryptodome)
PypyKatz (https://github.com/skelsec/pypykatz)
Warning : If you're writing a module, make sure it won't do any damage before running it


Download Tofu (https://github.com/puckblush/tofu)

___________________________
@hacking_Attack
@Hacking_Video
MSA Weekly 3 — “How to Approach Your Target Machine — Nmap Technique”

Hai Hai, Salam hangat teman teman. Semoga kita senantiasa dalam perlindungan tuhan yang maha esa.Continue reading on Medium »
Read more...
Hacking on a Private Program (Salseforce crm)

I was hunting on a private program of HackerOne so lets call it developer.target.com i found a register option so i registered there after…Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
New Phishing Attacks Shame, Scare Victims into Surrendering Twitter, Discord Credentials

Scams pressure victims to "resolve an issue that could impact their status, business."
Dark Reading: Attacks/Breaches
Diversity in Cybersecurity: Fostering Gender-Inclusive Teams That Perform Better

Proactive steps in recruiting women to cybersecurity teams, along with policies focused on diversity, equity, and inclusion, help make cybersecurity teams more effective. Addressing specific barriers that female candidates face will make those teams more inclusive and more representative.
Dark Reading: Attacks/Breaches
Proposed SEC Rules Require More Transparency About Cyber-Risk

The new guidelines would require public companies to file periodic disclosures about their cybersecurity practices and notify the SEC within 96 hours of a material breach.
hacking: security in practice
Multiple hack attempts on different accounts?

I apologize if this is the completely wrong subreddit, idk where to go. I know nothing about cybersecurity. Over the past few months, there have been multiple log in attempts on several of my accounts. This includes Facebook, Instagram, Amazon, and Paypal. I was able to see the location of the log in attempt for several of them and it appears that the same person from a city in Vietnam is trying to log into my accounts (I have no connection to Vietnam so def someone trying to get into my accounts). Luckily they have not been successful (at least from what I am aware of), but I am very concerned as I know nothing about hacking and cybersecurity. Is there anything I can do to help prevent this?

Should I change my passwords? I would consider my passwords pretty strong overall and from what I have seen the person has not successfully logged in to any of my accounts. Any additional steps I should take? Any help appreciated.

submitted by /u/youngsaturn
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
do ip address's reveal anything?

If someone got my IP address; is there anything bad they can do? Sorry if this question has been asked a gazillion times but I'm worried I might be in danger. Thanks a million!

submitted by /u/TeensyWeensyBean
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Cool stuff that I can do with a server?

Hello everyone,

I bought server and installed Proxmox OS.

Can you suggest me some interesting stuff that include hacking and learning, by using my server? Some interesting projects?

submitted by /u/wannacry011
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Conversation

I my friend insta I'd got hacked and he can't login again and can't reset password or change it.... Anyone know something that can help????

submitted by /u/Adventurous_Cut8125
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Ok so i've been learning python with a bigger goal in mind that i want to be a hacker and i don't know where to go from where i am now

There's all this stuff scientific computing, machine learning, backend ( i guess ? ), i don't even know, i need a goal, i need to do something to put a goal, i think i'm almost maybe 10 days away from building a snake game, it took me wayy too long, anyway i need a .. Idk what to call it basically something to do. What should i do next ? What should i learn ? what should i chase doing if i don't have a next milestone i guess is the word, i'm not gonna progress i know it, it should be something that will benefit me in hacking later on

submitted by /u/OnlykidsAreAtheists
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video