Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Issues with Kerberos constrained delegation and DCSync attack

Hi all,

I am trying to perform a dcsync attack through a kerberos constrained delegation machine in my homelab. I created a server with constrained delegation for time/dc01 and I noted the NTLM hash for the server with constrained delegation.

With rubeus I am able to get tickets for alternate services with:

.\rubeus.exe s4u /user:srv-constrained$ /rc4:NTLM-HASH /impersonateuser:administrator msdsspn:time/dc01.domain.local /altservice:ldap /ptt

I see I have a ticket for the ldap service so I run the dcsync like:

Invoke-mimikatz -Command '"lsadump::dcsync /user:domain\krbtgt"'

Whenever I do this I get an error:

ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)

I completely redeployed my homelab but keep getting the same error.

When I request a ticket for CIFS I do get access to the filesystem. A ticket for HTTP does not allow me to use enter-pssession and a HOST ticket does not allow me to create a scheduled task.

Multiple tutorials tell me my commands should work but I must be doing something wrong I guess.

submitted by /u/Advanced-Chain4096
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Twitter confirms zero-day used to expose data of 5.4 million accounts

Twitter confirms zero-day used to expose data of 5.4 million accountsPost Views: 3 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Twitter has confirmed a recent data breach was caused by a now-patched zero-day vulnerability used to link email addresses and phone numbers to users’ accounts, allowing a threat actor to compile a list of 5.4 million user account profiles.Last month, BleepingComputer spoke to a threat actor who said that they were able to create a list of 5.4 million Twitter account profiles using a vulnerability on the social media site.

This vulnerability allowed anyone to submit an email address or phone number, verify if it was associated with a Twitter account, and retrieve the associated account ID. The threat actor then used this ID to scrape the public information for the account.
https://www.bleepstatic.com/images/news/security/d/data-breaches/t/twitter-h1-vuln/forum-post.jpg
<figcaptionTwitter data being sold on a hacker forum
Source: BleepingComputer
This allowed the threat actor to create profiles of 5.4 million Twitter users in December 2021, including a verified phone number or email address, and scraped public information, such as follower counts, screen name, login name, location, profile picture URL, and other information.

A redacted example of one of these created Twitter profiles can be seen below.
https://www.bleepstatic.com/images/news/software/w/winamp/twitter-scraped-profile.jpg
<figcaptionA redacted example of one of the generated Twitter profilesles
Source: BleepingComputer
At the time, the threat actor was selling the data for $30,000 and had told BleepingComputer that there were interested buyers.

BleepingComputer later learned that two different threat actors purchased the data for less than the original selling price and that the data would likely be released for free in the future.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Twitter confirms zero-day used to collect dataToday, Twitter has confirmed that the vulnerability used by the threat actor in December is the same one reported to and fixed by them in January 2022 as part of their HackerOne bug bounty program.,

“In January 2022, we received a report through our bug bounty program of a vulnerability that allowed someone to identify the email or phone number associated with an account or, if they knew a person’s email or phone number, they could identify their Twitter account, if one existed,” Twitter disclosed in a security advisory today.

“This bug resulted from an update to our code in June 2021. When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability.”

As part of today’s disclosure, Twitter told BleepingComputer that they have already begun to send out notifications this morning to alert impacted users about whether the data breach exposed their phone number or email address.

At this time, Twitter tells us that they cannot determine the exact number of people impacted by the breach. However, the threat actor claims to have used the flaw to gather the data of 5,485,636 Twitter users.

While no passwords were exposed in this breach, Twitter is encouraging users to enable 2-factor authentication on their accounts to prevent unauthorized logins as a security measure.
Trending: Find Hidden Info using Google Dorking manually, and Automated using Pagodo
Trending: Offensive Security Tool: Offensive-Azure[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Twitter confirms zero-day used to expose data of 5.4 million accounts Twitter confirms zero-day used to expose data of 5.4 million accountsPost Views: 3 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon…
For those using a pseudonymous Twitter account, the social media company suggests you keep your identity as anonymous as possible by not using a publicly known phone number or email address on your Twitter account.

“We are publishing this update because we aren’t able to confirm every account that was potentially impacted, and are particularly mindful of people with pseudonymous accounts who can be targeted by state or other actors,” warned the Twitter advisory.

Furthermore, as two different threat actors have already purchased this data, users should be on the lookout for targeted spear-phishing campaigns utilizing this data to steal your Twitter login credentials.
Trending: New Linux malware called RapperBot brute-forces Linux SSH servers to breach networks
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-2-300x150.png New Linux malware called RapperBot brute-forces Linux SSH servers to breach networksAugust 5, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-300x150.png Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisoryAugust 4, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-300x150.png VMware urges admins to patch critical auth bypass bug immediatelyAugust 3, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-4-300x150.png Thousand apps leak Twitter API keys, some allowing account hijacksAugust 2, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Twitter confirms zero-day used to expose data of 5.4 million accounts first appeared on Black Hat Ethical Hacking.
Rooting Jenkins: Remote Code Execution on a live bug bounty target

tl;dr:Continue reading on Medium »
Read more...
Smap is a replica of Nmap which uses shodan.io's free API for port scanning. It takes same command line (https://www.kitploit.com/search/label/Command%20Line) arguments as Nmap and produces the same output which makes it a drop-in replacament for Nmap.
Features Scans 200 hosts per second Doesn't require any account/api key Vulnerability detection Supports all nmap's output formats Service and version fingerprinting Makes no contact to the targets Installation Binaries You can download a pre-built binary (https://www.kitploit.com/search/label/Binary) from here (https://github.com/s0md3v/Smap/releases) and use it right away. Manual go install -v github.com/s0md3v/smap/cmd/smap@latest Confused or something not working? For more detailed instructions, click here (https://github.com/s0md3v/Smap/wiki/FAQ#how-do-i-install-smap) AUR pacakge Smap is available on AUR as smap-git (https://aur.archlinux.org/packages/smap-git) (builds from source) and smap-bin (https://aur.archlinux.org/packages/smap-bin) (pre-built binary). Homebrew/Mac Smap is also avaible on Homebrew (https://formulae.brew.sh/formula/smap). brew update
brew install smap
Usage Smap takes the same arguments as Nmap but options other than -p, -h, -o*, -iL are ignored. If you are unfamiliar with Nmap, here's how to use Smap. Specifying targets smap 127.0.0.1 127.0.0.2
You can also use a list of targets, seperated by newlines. smap -iL targets.txt
Supported formats 1.1.1.1 // IPv4 address
example.com // hostname
178.23.56.0/8 // CIDR
Output Smap supports 6 output formats which can be used with the -o* as follows smap example.com -oX output.xml
If you want to print the output to terminal, use hyphen (-) as filename. Supported formats oX // nmap's xml format
oG // nmap's greppable format
oN // nmap's default format
oA // output in all 3 formats above at once
oP // IP:PORT pairs seperated by newlines
oS // custom smap format
oJ // json
Note: Since Nmap doesn't scan/display vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) and tags, that data is not available in nmap's formats. Use -oS to view that info. Specifying ports Smap scans (https://www.kitploit.com/search/label/Scans) these 1237 ports (https://gist.githubusercontent.com/s0md3v/3e953e8e15afebc1879a2245e74fc90f/raw/1e20288e9bef43b60f7306b6f7e23044dabd9b8c/shodan_ports.txt) by default. If you want to display results for certain ports, use the -p option. smap -p21-30,80,443 -iL targets.txt
Considerations Since Smap simply fetches existent port data from shodan.io, it is super fast but there's more to it. You should use Smap if: You want vulnerability detection a super fast port scanner results for most common ports (top 1237) no connections to be made to the targets You are okay with not being able to scan IPv6 addresses results being up to 7 days old a few false negatives

Download Smap (https://github.com/s0md3v/smap/)
Chaining Attacks to exploit a development dashboard accessible publicly!

Last month while working with a customer on a red team engagement, we stumbled upon a low hanging fruit (vulnerability). It was an IOT…Continue reading on Medium »
Read more...