Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Atomic-Operator : A Python Package Is Used To Execute Atomic Red Team Tests atomic-operatorenables security professionals to test their detection and defensive capabilities against prescribed techniques defined within atomic-red-team.…
T1564.001 –select_tests

Will prompt the user with a selection list of tests associated with that technique. A user can select one or more tests by using the space bar to highlight the desired test: Additional parametersYou can see additional parameters by running the following command:
atomic-operator run -- --help Parameter NameTypeDefaultDescriptiontechniqueslistallOne or more defined techniques by attack_technique ID.test_guidslistNoneOne or more Atomic test GUIDs.select_testsboolFalseSelect one or more atomic tests to run when a techniques are specified.atomics_pathstros.getcwd()The path of Atomic tests.check_prereqsboolFalseWhether or not to check for prereq dependencies (prereq_comand).get_prereqsboolFalseWhether or not you want to retrieve prerequisites.cleanupboolFalseWhether or not you want to run cleanup command(s).copy_source_filesboolTrueWhether or not you want to copy any related source (src, bin, etc.) files to a remote host.command_timeoutint20Time duration for each command before timeout.debugboolFalseWhether or not you want to output details about tests being ran.prompt_for_input_argsboolFalseWhether you want to prompt for input arguments for each test.return_atomicsboolFalseWhether or not you want to return atomics instead of running them.config_filestrNoneA path to a conifg_file which is used to automate atomic-operator in environments.config_file_onlyboolFalseWhether or not you want to run tests based on the provided config_file only.hostslistNoneA list of one or more remote hosts to run a test on.usernamestrNoneUsername for authentication of remote connections.passwordstrNonePassword for authentication of remote connections.ssh_key_pathstrNonePath to a SSH Key for authentication of remote connections.private_key_stringstrNoneA private SSH Key string used for authentication of remote connections.verify_sslboolFalseWhether or not to verify ssl when connecting over RDP (windows).ssh_portint22SSH port for authentication of remote connections.ssh_timeoutint5SSH timeout for authentication of remote connections.**kwargsdictNoneIf additional flags are passed into the run command then we will attempt to match them with defined inputs within Atomic tests and replace their value with the provided value.
You should see a similar output to the following:

NAME
atomic-operator run – The main method in which we run Atomic Red Team tests.
SYNOPSIS
atomic-operator run
DESCRIPTION
The main method in which we run Atomic Red Team tests.
FLAGS
–techniques=TECHNIQUES
Type: list
Default: [‘all’]
One or more defined techniques by attack_technique ID. Defaults to ‘all’.
–test_guids=TEST_GUIDS
Type: list
Default: []
One or more Atomic test GUIDs. Defaults to None.
–select_tests=SELECT_TESTS
Type: bool
Default: False
Select one or more tests from provided techniques. Defaults to False.
–atomics_path=ATOMICS_PATH
Default: ‘/U…
The path of Atomic tests. Defaults to os.getcwd().
–check_prereqs=CHECK_PREREQS
Default: False
Whether or not to check for prereq dependencies (prereq_comand). Defaults to False.
–get_prereqs=GET_PREREQS
Default: False
Whether or not you want to retrieve prerequisites. Defaults to False.
–cleanup=CLEANUP
Default: False
Whether or not you want to run cleanup command(s). Defaults to False.
–copy_source_files=COPY_SOURCE_FILES
Default: True
Whether or not you want to copy any related source (src, bin, etc.) files to a remote host. Defaults to True.
–command_timeout=COMMAND_TIMEOUT
Default: 20
Timeout duration for each command. Defaults to 20.
–debug=DEBUG
Default: False
Whether or not you want to output details about tests being ran. Defaults to False.
–prompt_for_input_args=PROMPT_FOR_INPUT_ARGS
Default: False
Whether you want to prompt for input arguments for each test. Defaults to False.
–return_atomics=RETURN_ATOMICS
Default: False
Whether or not you want to return atomics instead of running them. Defaults to False.
–config_file=CONFIG_FILE
Type: Optional[]
Default: None
A path to a conifg_file [...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Puwr : SSH Pivoting Script For Expanding Attack Surfaces On Local Networks

Puwr will Easily expand your attack surface on a local network by discovering more hosts, via SSH. Using a machine running a SSH service, Puwr uses a given subnet range to scope out IP’s, sending back any successful ping requests it has. This can be used to create a pivoting attack from a compromised machine, by returning you hosts you couldn’t normally discover from your own device. Open ports can then be probed on these discovered devices, to find a gateway into attacking more devices.

Upcoming

Here are some new features I plan to add in along with the upcoming update.

* Scan for open ports of discovered hosts (DONE)
* Change CLI output to look more neat and organized (DONE)
* Enumerate information on “victim” host for privilege escalation
* Optional colored output

Usage

Puwr is simple to run, only requiring 4 flags:
python3 puwr.py (MACHINE IP) (USER) (PASSWORD) (SUBNET VALUE)

example:
python3 puwr.py 10.0.0.53 xeonrx password123 10.0.0.1/24

If you need to connect through a port other than 22, use the -pflag. (example: -p 2222)
If you want to keep quiet, use the -sflag to wait specified seconds between request. (example: -s 5)
You can now use --scanto discover open ports on discovered devices. (example: –scan 80 443)
Use the -hflag for usage reference in the script.

The paramiko and netaddr modules are required for this script to work!
You can install them with the pip tool: pip install netaddr paramiko

Here I scanned devices and checked which ones has port 80 and 443 open to target web applications.
Notice how the TTL number also displays, giving you a hint at what the device may be running on.

Tested Operating Systems

So far, I have only confirmed Puwr to work on a few operating systems:

* Kali Linux
* Parrot OS
* Windows 10

However, it should work on almost any OS with Python, and the needed modules installed.

Port Scanning

As mentioned earlier a few times, you can now not only discover hosts, but also scan them for open ports.
This can be used to find an attack vector on devices running an accessable service. By default, ports will not be scanned, but you can use the --scanflag, and add the port numbers you’d like to scan.
Keep in mind however, that port scanning does take a good bit of additional time to complete. PORT SCANNING ONLY WORKS ON MACHINES WITH PYTHON 3 INSTALLED FOR NOW
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
T1564.001 –select_tests Will prompt the user with a selection list of tests associated with that technique. A user can select one or more tests by using the space bar to highlight the desired test: Additional parametersYou can see additional parameters by…
which is used to automate atomic-operator in environments. Default to None.
–config_file_only=CONFIG_FILE_ONLY
Default: False
Whether or not you want to run tests based on the provided config_file only. Defaults to False.
–hosts=HOSTS
Default: []
A list of one or more remote hosts to run a test on. Defaults to [].
–username=USERNAME
Type: Optional[]
Default: None
Username for authentication of remote connections. Defaults to None.
–password=PASSWORD
Type: Optional[]
Default: None
Password for authentication of remote connections. Defaults to None.
–ssh_key_path=SSH_KEY_PATH
Type: Optional[]
Default: None
Path to a SSH Key for authentication of remote connections. Defaults to None.
–private_key_string=PRIVATE_KEY_STRING
Type: Optional[]
Default: None
A private SSH Key string used for authentication of remote connections. Defaults to None.
–verify_ssl=VERIFY_SSL
Default: False
Whether or not to verify ssl when connecting over RDP (windows). Defaults to False.
–ssh_port=SSH_PORT
Default: 22
SSH port for authentication of remote connections. Defaults to 22.
–ssh_timeout=SSH_TIMEOUT
Default: 5
SSH timeout for authentication of remote connections. Defaults to 5.
Additional flags are accepted.
If provided, keys matching inputs for a test will be replaced. Default is None. Running atomic-operator using a config_fileIn addition to the ability to pass in parameters with atomic-operatoryou can also pass in a path to a config_filethat contains all the atomic tests and their potential inputs. You can see an example of this config_file here:

atomic_tests:
guid: f7e6ec05-c19e-4a80-a7e7-241027992fdb
input_arguments:
output_file:
value: custom_output.txt
input_file:
value: custom_input.txt
guid: 3ff64f0b-3af2-3866-339d-38d9791407c3
input_arguments:
second_arg:
value: SWAPPPED argument
guid: 32f90516-4bc9-43bd-b18d-2cbe0b7ca9b2 Usage example (scripts)from atomic_operator import AtomicOperator
operator = AtomicOperator()
This will download a local copy of the atomic-red-team repository
print(operator.get_atomics(‘/tmp/some_directory’))
this will run tests on your local system
operator.run(
technique: str=’All’,
atomics_path=os.getcwd(),
check_dependencies=False,
get_prereqs=False,
cleanup=False,
command_timeout=20,
debug=False,
prompt_for_input_args=False,
**kwargs
) Download

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Possible file less malware ?

I ran 2 av's but did not find any positives. However my 3rd av spotted 2 folders as malicious and deleted it. Upon completing the scan it detected an "unknow exe" which is unsigned and named "WMIADAP.EXE" with no physical exe whywhere. However the exe's location shows as "C:\?\C:\WINDOWS\SYSTEM32\WBEM\WMIADAP.EXE" I tried to open the exe source folder but it says no folder like that exists. So i manually checked "C:\WINDOWS\SYSTEM32\WBEM\WMIADAP.EXE" and an exe named "wmiadap.exe" exists but it is signed. I further checked using Task manager & Process explorer but both doesn't even show a process called WMIADAP.EXE to be running. I am not even able to upload to Virustotal since there is no exe saved anywhere! Should i delete or block it ? Possible fileless malware ? How do i even analyse it further ?

submitted by /u/zilla005
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Let’s talk about ransomware-

Greetings, I have been working in defensive side of security. Lately, ransomware is the subject matter that interests me. So I have few questions regarding ransomware. 1. How do ransomware propagate from one network to another? 2. How to adversaries execute ransomware in a big companies? Breaking the infrastructure or simply tricking employees to execute it? Or other ways? 3. If you would make a ransomware what language would you use? And why? 4. Is XRD/EDR enough to stop ransomware?

submitted by /u/Inevitable-Tank-456
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is it known how some of the famous (decade old) Runescape hacks were done?

I recall a while ago there were very cool hacks in Runescape. One that I remember well was where someone was able to double the items that they had and made lots of party hat. Is there some explanation document or video that describes how that (or other big hacks) ware done?

submitted by /u/bersnin
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
FFUF-ing RECON

, or how to get to P1–P3 from a slightly different reconContinue reading on InfoSec Write-ups »
Read more...
Gauing+Nuclei for Instant Bounties

Back again with the instant bounties series. Last time we learned how to score instant bounties with Google dorks so check that out if you…Continue reading on Medium »
Read more...