Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Virtual Machine + remote access

If a hacker took over my virtual machine using a remote access software, could they somehow get to my main PC or is this near impossible? could they even tell is a VM?

submitted by /u/DeathEdntMusic
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
MSA Weekly 4 — [How to Get Subdomain’s Using Subfinder & Sudomy]

Subdomain’s EnumerationContinue reading on Medium »
Read more...
Any coding advice?
https://www.reddit.com/r/Pentesting/comments/w1q8ca/any_coding_advice/

I am currently learning Java as my first coding language and plan to learn python, JavaScript, and eventually Linux. Are there any other recommendations or advice I should know? Like what will be useful to know or understand in the field? Should I just focus on Linux first, and learn other code languages later? I’m still a little lost on what I should learn to get into Pentesting. (Sorry if the phrasing is weird.) submitted by /u/thatguy4705 (https://www.reddit.com/user/thatguy4705)
[link] (https://www.reddit.com/r/Pentesting/comments/w1q8ca/any_coding_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/w1q8ca/any_coding_advice/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Lockc : Making Containers More Secure With eBPF And Linux Security Modules (LSM)

lockc is open source sofware for providing MAC (Mandatory Access Control) type of security audit for container workloads.

The main reason why lockc exists is that containers do not contain. Containers are not as secure and isolated as VMs. By default, they expose a lot of information about host OS and provide ways to “break out” from the container. lockc aims to provide more isolation to containers and make them more secure.

The Containers do not contain documentation section explains what we mean by that phrase and what kind of behavior we want to restrict with lockc.

The main technology behind lockc is eBPF – to be more precise, its ability to attach to LSM hooks

Please note that currently lockc is an experimental project, not meant for production environment and without any official binaries or packages to use – currently the only way to use it is building from sources.

See the full documentation here. And the code documentation here.

If you need help or want to talk with contributors, plese come chat with us on #lockcchannel on the Rust Cloud Native Discord server.

lockc’s userspace part is licensed under Apache License, version 2.0.

eBPF programs inside lockc/src/bpf directory are licensed under GNU General Public License, version 2.
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
AWS-Threat-Simulation-and-Detection : Playing Around With Stratus Red Team And SumoLogic

AWS-Threat-Simulation-and-Detection, this repository is a documentation of my adventures with Stratus Red Team – a tool for adversary emulation for the cloud.

Stratus Red Team is “Atomic Red Team for the cloud, allowing to emulate offensive attack techniques in a granular and self-contained manner.

We run the attacks covered in the Stratus Red Team repository one by one on our AWS account. In order to monitor them, we will use CloudTrail and CloudWatch for logging and ingest these logs into SumoLogic for further analysis.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggXaAF0XknCujkIH5s3jW1BbkCaN9WpvHj4rwL77pBtl_bBxQCZlnNVDtsjKeInsmHJfeONHwkr8fI2BaXsW3aLHdq8BJ7bknyXB3x5nTVqmsNj7nhMQmAO4KKbCc75xDimKLoTErIkX0KHTYWxEBG3jOgc20qku2ZPFpDYgtkcc7VX-X_ToKSk0pF/s1522/18.png AttackDescriptionLinkaws.credential-access.ec2-get-password-dataRetrieve EC2 Password DataLinkaws.credential-access.ec2-steal-instance-credentialsSteal EC2 Instance CredentialsLinkaws.credential-access.secretsmanager-retrieve-secretsRetrieve a High Number of Secrets Manager secretsLinkaws.credential-access.ssm-retrieve-securestring-parametersRetrieve And Decrypt SSM ParametersLinkaws.defense-evasion.cloudtrail-deleteDelete CloudTrail TrailLinkaws.defense-evasion.cloudtrail-event-selectorsDisable CloudTrail Logging Through Event SelectorsLinkaws.defense-evasion.cloudtrail-lifecycle-ruleCloudTrail Logs Impairment Through S3 Lifecycle RuleLinkaws.defense-evasion.cloudtrail-stopStop CloudTrail TrailLinkaws.defense-evasion.organizations-leaveAttempt to Leave the AWS OrganizationLinkaws.defense-evasion.vpc-remove-flow-logsRemove VPC Flow LogsLinkaws.discovery.ec2-enumerate-from-instanceExecute Discovery Commands on an EC2 InstanceLinkaws.exfiltration.ec2-security-group-open-port-22-ingressOpen Ingress Port 22 on a Security GroupLinkaws.exfiltration.ec2-share-amiExfiltrate an AMI by Sharing ItLinkaws.exfiltration.ec2-share-ebs-snapshotExfiltrate EBS Snapshot by Sharing ItLinkaws.exfiltration.rds-share-snapshotExfiltrate RDS Snapshot by SharingLinkaws.exfiltration.s3-backdoor-bucket-policyBackdoor an S3 Bucket via its Bucket PolicyLinkaws.persistence.iam-backdoor-roleBackdoor an IAM RoleLinkaws.persistence.iam-backdoor-userCreate an Access Key on an IAM UserTBDaws.persistence.iam-create-admin-userCreate an administrative IAM UserTBDaws.persistence.iam-create-user-login-profileCreate a Login Profile on an IAM UserTBDaws.persistence.lambda-backdoor-functionBackdoor Lambda Function Through Resource-Based PolicyTBD

Download

___________________________
@hacking_Attack
@Hacking_Video