hacking: security in practice
Are there rootkits in the market that can log activities from a live USB boot?
I have a question...if a person's windows computer is hacked with spyware..and the person makes a live Linux cd to use on that computer....
Can the computer rootkit still log the user activities with the live USB boot?
submitted by /u/sweet_droit
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Are there rootkits in the market that can log activities from a live USB boot?
I have a question...if a person's windows computer is hacked with spyware..and the person makes a live Linux cd to use on that computer....
Can the computer rootkit still log the user activities with the live USB boot?
submitted by /u/sweet_droit
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Hacking Articles Tips Tricks Videos Tutorials
___________________________ @hacking_Attack @Hacking_Video ___________________________
hacking: security in practice
Apple targeted in $50 million ransomware attack resulting in unprecedented schematic leaks
https://external-preview.redd.it/nO_hJZIM6IlsywTqO9Y7ELDnWqzpEwwXi_c07p6RzsE.jpg?width=640&crop=smart&auto=webp&s=6bb903f945826217e564851d19c3c6a0522cab27submitted by /u/uinerimak
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Apple targeted in $50 million ransomware attack resulting in unprecedented schematic leaks
https://external-preview.redd.it/nO_hJZIM6IlsywTqO9Y7ELDnWqzpEwwXi_c07p6RzsE.jpg?width=640&crop=smart&auto=webp&s=6bb903f945826217e564851d19c3c6a0522cab27submitted by /u/uinerimak
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
hacking: security in practice
Un-resetable router
Not sure where to post this, i guess it fits here, as it would probably be deleted/drown in new on r/techsupport so, here it goes.
I've recently bought a ASUS Router (RT-N12+B1, which for some reason shows up as RT-N11P in web interface) at a garage sale. It's pretty cheap on the market and i got it for even less, but i soon found out its pre-configured.
Tried hard reseting it acording to ASUS'es guide but only thing it did is put it in recovery mode, which i then used to flash it with new firmware (with asus recovery utility). This only bricked some of its functions. Then i flushed it with the oldest firmware (which restored all of its functions) hoping there are some vulnabilities i could use, but no luck (all of them either suck or require login).
No matter what i do i can't actually properly reset it, its stuck with no DHCP, static weird IP (which i had to find out by analysing some ARP requests about another weird IP), and hidden wifi with default ssid and no password. And of course the default admin password doesn't frickin' work and the darn thing locks down every 5 login attemps.
Any ideas?
submitted by /u/D4rk_J0k3r
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Un-resetable router
Not sure where to post this, i guess it fits here, as it would probably be deleted/drown in new on r/techsupport so, here it goes.
I've recently bought a ASUS Router (RT-N12+B1, which for some reason shows up as RT-N11P in web interface) at a garage sale. It's pretty cheap on the market and i got it for even less, but i soon found out its pre-configured.
Tried hard reseting it acording to ASUS'es guide but only thing it did is put it in recovery mode, which i then used to flash it with new firmware (with asus recovery utility). This only bricked some of its functions. Then i flushed it with the oldest firmware (which restored all of its functions) hoping there are some vulnabilities i could use, but no luck (all of them either suck or require login).
No matter what i do i can't actually properly reset it, its stuck with no DHCP, static weird IP (which i had to find out by analysing some ARP requests about another weird IP), and hidden wifi with default ssid and no password. And of course the default admin password doesn't frickin' work and the darn thing locks down every 5 login attemps.
Any ideas?
submitted by /u/D4rk_J0k3r
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Hacking Articles Tips Tricks Videos Tutorials
GIF
Kali Linux Tutorials
Traitor : Automatic Linux Privesc Via Exploitation Of Low-Hanging Fruit E.G. GTFOBin
Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop a root shell. Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy! It’ll exploit most sudo privileges listed in GTFOBins to pop a root shell, as well as exploiting […]
The post Traitor : Automatic Linux Privesc Via Exploitation Of Low-Hanging Fruit E.G. GTFOBin appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Traitor : Automatic Linux Privesc Via Exploitation Of Low-Hanging Fruit E.G. GTFOBin
Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop a root shell. Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy! It’ll exploit most sudo privileges listed in GTFOBins to pop a root shell, as well as exploiting […]
The post Traitor : Automatic Linux Privesc Via Exploitation Of Low-Hanging Fruit E.G. GTFOBin appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Hacking Articles Tips Tricks Videos Tutorials
___________________________ @hacking_Attack @Hacking_Video ___________________________
Hacking on Medium
Make a keylogger using the ZLogger tool
https://cdn-images-1.medium.com/max/1531/1*VusgPQYVM3gwwVtM3X0ZtA.png
Keyloggers are a form of monitoring software that records a user’s keystrokes. These keystroke loggers, one of the oldest types of cyber…
Continue reading on Purple TEAM »
Make a keylogger using the ZLogger tool
https://cdn-images-1.medium.com/max/1531/1*VusgPQYVM3gwwVtM3X0ZtA.png
Keyloggers are a form of monitoring software that records a user’s keystrokes. These keystroke loggers, one of the oldest types of cyber…
Continue reading on Purple TEAM »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Hack GF/BF/Wife/Husband Android Mobile Phone?
https://cdn-images-1.medium.com/max/600/1*ojxTIHT0NSdvY24-fiLJHQ.jpeg
Hack an android phone with an SMS but you can make a webpage that has auto-download enabled. Because maximum people do not download…
Continue reading on Medium »
How to Hack GF/BF/Wife/Husband Android Mobile Phone?
https://cdn-images-1.medium.com/max/600/1*ojxTIHT0NSdvY24-fiLJHQ.jpeg
Hack an android phone with an SMS but you can make a webpage that has auto-download enabled. Because maximum people do not download…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Antel has been exposing the exact location from millions of users for at least 13 years!
https://cdn-images-1.medium.com/max/600/0*op4YQ8DEjy_gJY35.jpeg
Hello network, how are you doing? I hope well!
Continue reading on strike.sh »
Antel has been exposing the exact location from millions of users for at least 13 years!
https://cdn-images-1.medium.com/max/600/0*op4YQ8DEjy_gJY35.jpeg
Hello network, how are you doing? I hope well!
Continue reading on strike.sh »
CrossLinked - LinkedIn Enumeration Tool To Extract Valid Employee Names From An Organization Through Search Engine Scraping
CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from a target organization. This technique provides accurate results without the use of API keys, credentials, or even accessing the site directly. Formats can then be applied in the command line arguments to turn these names into email addresses, domain accounts, and more. For a full breakdown of the tool and example output, checkout: https://m8r0wn.com/posts/2021/01/crosslinked.htmlSetup git clone https://github.com/m8r0wn/crosslinkedcd crosslinkedpip3 install -r requirements.txt Examples Results are written to a 'names.txt' file in the current directory unless specified in the command line arguments. See the Usage section for additional options. python3 crosslinked.py -f '{first}.{last}@domain.com' company_name python3 crosslinked.py -f 'domain\{f}{last}' -t 45 -j 1 company_name Usage positional arguments: company_name Target company nameoptional arguments: -h, --help show this help message and exit -t TIMEOUT Max timeout per search (Default=20, 0=None) -j JITTER Jitter between requests (Default=0) -v Show names and titles recovered after enumerationSearch arguments: -H HEADER Add Header ('name1=value1;name2=value2;') --search ENGINE Search Engine (Default='google,bing') --safe Only parse names with company in title (Reduces false positives)Output arguments: -f NFORMAT Format names, ex: 'domain\{f}{last}', '{first}.{last}@domain.com' -o OUTFILE Change name of output file (default=names.txtProxy arguments: --proxy PROXY Proxy requests (IP:Port) --proxy-file PROXY Load proxies from file for rotation Proxy Support The latest version of CrossLinked provides proxy support through the Taser library. Users can mask their traffic with a single proxy by adding --proxy 127.0.0.1:8080 to the command line arguments, or use --proxy-file proxies.txt for rotating source addresses. http/https proxies can be added in IP:PORT notation, while SOCKS requires a socks4:// or socks5:// prefix. Download CrossLinked
Read more...
___________________________
@hacking_Attack
@Hacking_Video
___________________________
CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from a target organization. This technique provides accurate results without the use of API keys, credentials, or even accessing the site directly. Formats can then be applied in the command line arguments to turn these names into email addresses, domain accounts, and more. For a full breakdown of the tool and example output, checkout: https://m8r0wn.com/posts/2021/01/crosslinked.htmlSetup git clone https://github.com/m8r0wn/crosslinkedcd crosslinkedpip3 install -r requirements.txt Examples Results are written to a 'names.txt' file in the current directory unless specified in the command line arguments. See the Usage section for additional options. python3 crosslinked.py -f '{first}.{last}@domain.com' company_name python3 crosslinked.py -f 'domain\{f}{last}' -t 45 -j 1 company_name Usage positional arguments: company_name Target company nameoptional arguments: -h, --help show this help message and exit -t TIMEOUT Max timeout per search (Default=20, 0=None) -j JITTER Jitter between requests (Default=0) -v Show names and titles recovered after enumerationSearch arguments: -H HEADER Add Header ('name1=value1;name2=value2;') --search ENGINE Search Engine (Default='google,bing') --safe Only parse names with company in title (Reduces false positives)Output arguments: -f NFORMAT Format names, ex: 'domain\{f}{last}', '{first}.{last}@domain.com' -o OUTFILE Change name of output file (default=names.txtProxy arguments: --proxy PROXY Proxy requests (IP:Port) --proxy-file PROXY Load proxies from file for rotation Proxy Support The latest version of CrossLinked provides proxy support through the Taser library. Users can mask their traffic with a single proxy by adding --proxy 127.0.0.1:8080 to the command line arguments, or use --proxy-file proxies.txt for rotating source addresses. http/https proxies can be added in IP:PORT notation, while SOCKS requires a socks4:// or socks5:// prefix. Download CrossLinked
Read more...
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Hacking Articles Tips Tricks Videos Tutorials
___________________________ @hacking_Attack @Hacking_Video ___________________________
KitPloit - PenTest Tools!
CrossLinked - LinkedIn Enumeration Tool To Extract Valid Employee Names From An Organization Through Search Engine Scraping
https://1.bp.blogspot.com/-EeY-SOLjvZg/YH5jp5fEezI/AAAAAAAAV6o/MAWhpyjnQZ0KWw_ZfWPOZ1_ADFcNPvNrwCNcBGAsYHQ/s16000/CrossLinked_5.png
CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from a target organization. This technique provides accurate results without the use of API keys, credentials, or even accessing the site directly. Formats can then be applied in the command line arguments to turn these names into email addresses, domain accounts, and more.
For a full breakdown of the tool and example output, checkout:
https://m8r0wn.com/posts/2021/01/crosslinked.html
Setup
Examples
Results are written to a 'names.txt' file in the current directory unless specified in the command line arguments. See the Usage section for additional options.
Usage
Proxy Support
The latest version of CrossLinked provides proxy support through the Taser library. Users can mask their traffic with a single proxy by adding
Download CrossLinked
___________________________
@hacking_Attack
@Hacking_Video
___________________________
CrossLinked - LinkedIn Enumeration Tool To Extract Valid Employee Names From An Organization Through Search Engine Scraping
https://1.bp.blogspot.com/-EeY-SOLjvZg/YH5jp5fEezI/AAAAAAAAV6o/MAWhpyjnQZ0KWw_ZfWPOZ1_ADFcNPvNrwCNcBGAsYHQ/s16000/CrossLinked_5.png
CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from a target organization. This technique provides accurate results without the use of API keys, credentials, or even accessing the site directly. Formats can then be applied in the command line arguments to turn these names into email addresses, domain accounts, and more.
For a full breakdown of the tool and example output, checkout:
https://m8r0wn.com/posts/2021/01/crosslinked.html
Setup
git clone https://github.com/m8r0wn/crosslinked
cd crosslinked
pip3 install -r requirements.txtExamples
Results are written to a 'names.txt' file in the current directory unless specified in the command line arguments. See the Usage section for additional options.
python3 crosslinked.py -f '{first}.{last}@domain.com' company_namepython3 crosslinked.py -f 'domain\{f}{last}' -t 45 -j 1 company_nameUsage
positional arguments:
company_name Target company name
optional arguments:
-h, --help show this help message and exit
-t TIMEOUT Max timeout per search (Default=20, 0=None)
-j JITTER Jitter between requests (Default=0)
-v Show names and titles recovered after enumeration
Search arguments:
-H HEADER Add Header ('name1=value1;name2=value2;')
--search ENGINE Search Engine (Default='google,bing')
--safe Only parse names with company in title (Reduces false positives)
Output arguments:
-f NFORMAT Format names, ex: 'domain\{f}{last}', '{first}.{last}@domain.com'
-o OUTFILE Change name of output file (default=names.txt
Proxy arguments:
--proxy PROXY Proxy requests (IP:Port)
--proxy-file PROXY Load proxies from file for rotation
Proxy Support
The latest version of CrossLinked provides proxy support through the Taser library. Users can mask their traffic with a single proxy by adding
--proxy 127.0.0.1:8080to the command line arguments, or use --proxy-file proxies.txtfor rotating source addresses.http/httpsproxies can be added in IP:PORTnotation, while SOCKS requires a socks4://or socks5://prefix.Download CrossLinked
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Exhausting Google map API key quota by bypassing restrictions
Hey everyone hope you all are doing well during these tough time!Continue reading on Medium »
Read more...
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Hey everyone hope you all are doing well during these tough time!Continue reading on Medium »
Read more...
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Hacking Articles Tips Tricks Videos Tutorials
___________________________ @hacking_Attack @Hacking_Video ___________________________
Exploit Collector
Moodle 3.10.3 Cross Site Scripting
https://1.bp.blogspot.com/-ASAiGIAsbZo/WWlu3lcAbmI/AAAAAAAAII0/K9TarDW1B-wz0w-5-5rrjX8jWsow7QyegCLcBGAs/s1600/h100.png
Moodle version 3.10.3 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to Vincent666 ibn Winnie in March of 2021.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Moodle 3.10.3 Cross Site Scripting
https://1.bp.blogspot.com/-ASAiGIAsbZo/WWlu3lcAbmI/AAAAAAAAII0/K9TarDW1B-wz0w-5-5rrjX8jWsow7QyegCLcBGAs/s1600/h100.png
Moodle version 3.10.3 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to Vincent666 ibn Winnie in March of 2021.
MD5 |
702e13c9737c10b10cd2c43d2d24ce46Download
# Exploit Title: Moodle 3.10.3 - 'url' Persistent Cross Site Scripting
# Date: 22/04/2021
# Exploit Author: UVision
# Vendor Homepage: https://moodle.org/
# Software Link: https://download.moodle.org
# Version: 3.10.3
# Tested on: Debian/Windows 10
By having the role of a teacher or an administrator or a manager (to have the possibility to create a course):
- Create a new course (http://localhost/moodle/course/edit.php?category=1&returnto=topcat)
- Give any name , short name, date and other things required.
- In "Description" field, click on the "link" button
- In the url field, enter the payload : 1
- Create the link, an alert window appears (close it several times so that it disappears) , save the course. ("Save and return")
Each time the course description is displayed, the stored xss is activated : activate it by viewing the course, by modifying it, etc.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
___________________________
Exploit Collector
DzzOffice 2.02.1 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
___________________________
DzzOffice 2.02.1 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
___________________________