Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Burner phones

Excuse my ignorance but why are burner phones trashed? I understand the concept of it. It’s usually a flip phone that is used a few times times to communicate a few times before disposed because they are inexpensive and virtually unhackable. Why wouldn’t they just take the SIM out and get a new one?

I’ve done my research and found out how cellphone signals are triangulated. SIM cards can also carry information and can provide the IMEI from a phone to cellular carriers. Most tracking and hacking is done on smartphone these days. What are the chances of government agencies keeping tabs on that IMEI to see if it reconnects to a specific carrier?

In terms of the phone I understand that the IMEI is programmed into the phone and the numbers come off a database that can identify the phone manufacture and model. I wondered why isn’t there a tool that can spoof IMEI numbers into believing it’s another phone model that is currently not in use. I know each phone processor is different and they all use a different set of instructions so maybe a universal tool is not viable but say only for a specific phone brand or model.

Is such tool possible to create? And also why can’t people just swap out SIM cards?

Didn’t know where else to post I’ve just been curious for a long time.

submitted by /u/FapTapAnon
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How accounts are cracked? (netflix,spotify,...)

Just as the title says, how cracks work in term of cracking accounts like spotify,netflix...

submitted by /u/Joe-seph002
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Think this would work? (evasive malware lab dabbling)

So for the past few weeks, I've been playing with making windows defender evasive shellcode loaders to get initial access to my windows 10 lab environment.

My payloads can get me initial access, but I'm walled in behind UAC and windows defender can still catch me if I try to sneak in more tools (e.g. winpeas, mimikatz, lazagne...you know, stuff you'd want to test in an engagement).

I know I can impair defenses (both defender and future UAC use) if I can get UAC-elevated access to powershell, but currently I can't.

my idea for how I could do this:

1) bind my payload to an installer that needs UAC elevation to run and installs a large program that takes forever to complete installation for.

2) payload injects shellcode into the UAC-elevated installer process

3) immediately on getting the shell, impair defenses.

4) migrate my shell to something more stable like spoolsv.exe or some other trivial but always on service.

5) ?????

6) do hacker shit with defenses impaired.

Does this sound like it would work, or is there something better I could be doing?

submitted by /u/_vercingtorix_
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
eJPT info
https://www.reddit.com/r/Pentesting/comments/x6pkbe/ejpt_info/

Hello. I would like to get the eJPT exam voucher. I have already followed the entire preparation course + all the labs. Can anyone who took the exam tell me what kind of questions they received? And how was the laboratory set up (2 reachable machines, 1 reachable machine and 1 needs rotation ...)? submitted by /u/edoardottt (https://www.reddit.com/user/edoardottt)
[link] (https://www.reddit.com/r/Pentesting/comments/x6pkbe/ejpt_info/) [comments] (https://www.reddit.com/r/Pentesting/comments/x6pkbe/ejpt_info/)

___________________________
@hacking_Attack
@Hacking_Video