Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
PwnLnX - An Advanced Multi-Threaded, Multi-Client Python Reverse Shell For Hacking Linux Systems

https://1.bp.blogspot.com/-k3WF8h8rSHw/YIetXdww6lI/AAAAAAAAV_c/9p5f_FsZKnYnvJ232xziTVGR3VrDRkofACNcBGAsYHQ/w640-h332/PwnLnX_9_waiting_con.png An advanced multi-threaded, multi-client python reverse shell for hacking linux systems. There's still more work to do so feel free to help out with the development. Disclaimer: This reverse shell should only be used in the lawful, remote administration of authorized systems. Accessing a computer network without authorization or permission is illegal. Getting StartedPlease follow these instructions to get a copy of PwnLnX running on your local machine without any problems. Prerequisites* Python3:
* vidstream
* pyfiglet
* tqdm
* mss
* termcolor
* pyautogui
* pyinstaller
* pip3
* pynput Installing# Download source code
git clone https://github.com/spectertraww/PwnLnX.git
cd PwnLnX

# download and install the dipendences
chmod +x setup.sh

./setup.sh
Getting PwnLnx up and runningShow helppython3 PwnLnX.py --helpListening for incoming connectionspython3 PwnLnX.py --lhost [your localhost ip address] --lport [free port for listening incoming connections]creating/Generating a payloadchmod +x PwnGen.sh

./PwnGen.sh
then follow the procedure to successifully create your payload, the payload is saved in PwnLnx directory. Send the created payload to victim PwnLnx UsageCommand Usage help show help exit close all the sessions and quit the progaram. show sessions show all available sessions from connected. session [ID] interact with a specified session ID. kill [all/ID] kill a specified session or all to kill all sessions. banner have funny by changing the program banner Interact with a sessionCommand Usage help show help. quit close the current session. background background the current session. sysinfo get minimum target system information. create_persist create a persistant backdoor. upload upload the specified filename to the target system. download download the specified filename from the target system. screenshot take a desktop screenshot of the target system. start_screenshare start desktop screensharing. stop_screenshare stop desktop screensharing. start_keycap start capturing victim's pressed keystrokes. dump_keycap dump/get the captured keystrokes. stop_keycap stop the capturing keystrokes.
NB. you can also execute linux system commands besides those listed above. DisclaimerI will not be responsible for any direct or indirect damage caused due to the usage of this tool, it is for educational purposes only. Report Bugsspectertraww@gmail.com Snapshotshttps://1.bp.blogspot.com/-fVfM5B6frM8/YIetk2U8rnI/AAAAAAAAV_8/B_Xnr1mQp5IX7h9EHtaX1UYF73IfTuvsgCNcBGAsYHQ/w640-h62/PwnLnX_8_start_con.png https://1.bp.blogspot.com/-Z4xWU1QYftE/YIetlKBB6AI/AAAAAAAAWAA/3IAm_ZLitps_yifWn-L04dtHCcndKiA2ACNcBGAsYHQ/w640-h332/PwnLnX_9_waiting_con.png https://1.bp.blogspot.com/-5VJNujXhk3U/YIeti37XZDI/AAAAAAAAV_o/iAVB6ik83vAXOdOGYs-Jz-zWlmtNEqsjACNcBGAsYHQ/w640-h112/PwnLnX_10_show_sess.png https://1.bp.blogspot.com/-HudNeaeFgHE/YIetiyMUzFI/AAAAAAAAV_k/vLouH_ySayADUC62cFuxXm-U02adKazFgCNcBGAsYHQ/w640-h92/PwnLnX_11_session.png https://1.bp.blogspot.com/-_KnuqN-0Wy8/YIeti7EoYUI/AAAAAAAAV_g/zOXCUmWdjFM93csJmz2Gikof9rEL0J9rACNcBGAsYHQ/w640-h292/PwnLnX_12_help.png https://1.bp.blogspot.com/-Q7guw2C81Kg/YIetj_fPu4I/AAAAAAAAV_s/HpbmWABG_4UsujgqfMQ84fMQzAQDzOHrwCNcBGAsYHQ/w640-h304/PwnLnX_13_help2.png https://1.bp.blogspot.com/-nzcxj8QJmqc/YIetkKSxZTI/AAAAAAAAV_w/q20dyDtcGB0cWgoNK1yMsIBYRRACDCFLQCNcBGAsYHQ/w640-h148/PwnLnX_14_ls.png https://1.bp.blogspot.com/-DERImL7GSXI/YIetkcOrVMI/AAAAAAAAV_0/9YLxS_7nprgEH8zBdiBTL5gumBpcaE9UACNcBGAsYHQ/w640-h8[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hacking challenge with a 1.7M satoshi reward

I'm working to develop an algorithmic code methodology which will be "easy" to code and arbitrarily difficult to hack.

My ultimate goal is to provide a framework to create smart contracts without a need for anything like the Ethereum blockchain.

In order to test this I provide hacking challenges with BTC private keys embedded in hackable lock boxes.

My latest challenge is labeled 4.0 and you can find all the details here:

https://algomachines.com/

Reports on many past challenges are available at this website as well.

submitted by /u/cryptocomicon
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
[TR] Web Security Academy — 6.Information disclosure

Continue reading on Medium »
Read more...
Forwarded from ᵗʰᵉ ⁅ L E A K E R H O U N D ⁆ ᴳᵒᵈˢ 🐧 (♛ 𝚏𝟺𝚌𝟹𝚛𝟷𝟶𝟶 | [ 𝑩 𝑼 𝑺 𝒀 ] ♛)
GOOGLE HACKING FOR PENTESTER BY SR.SYST3M

1️⃣ The user name and password

"create table" insert into" "pass|passwd|password" (ext:sql | ext:dump | ext:txt)
"your password * is" (ext:csv | ext.doc | ext:txt)

2️⃣ Key

"index of" slave_datatrans OR from_master

3️⃣ Privacy Password

"Begin (DSA | RSA)" ext:key
"index of" "secring.gpg"

4️⃣ An encrypted message

-"public | pubring | pubkeysignature | pgp | and | or |release" ext:gpg
-intext:"and" (ext:enc | ext:axx)
"ciphervalue" ext:xml

5️⃣ Chat Logs

"session start" "session ident" thomas ext:txt

6️⃣ Personal letters / e-mail

"index of" inbox.dbx
"To parent directory" inurl:"Identities"

7️⃣ Confidential files and directories

"index of" (private | secure | geheim | gizli)
"robots.txt" "User-agent" ext:txt

"this document is private | confidential | secret" ext:doc | ext:pdf | ext:xls

intitle:"index of" "jpg | png | bmp" inurl"personal | inurl:private

8️⃣ Online Webcam

intitle:"live View/ -AXIS" | inurl:view/view.shtml

inurl:"ViewFrame?Mode="

inurl:"MultiCameraFrame?Mode="

inturl:"axis-cgi/mjpg"

intext:"MOBOTIX M1"

intext:"Open Menu"

inurl:"view/index.shtml"

9️⃣ Description Identification private information

allintext: name email phone address intext:"thomas fischer" ext:pdf

Twiki inurl:"View/Main" "thomas fischer"
intitle:CV OR intitle:Lebenslauf "thomas fischer"

intitle:CV OR intitle:Lebenslauf ext:pdf OR ext:doc

🔟 username

intitle:"usage Statistics for" intext:"Total Unique Usernames"

1️⃣1️⃣ Unreliable procedures to disclose information

"php version" intitle:phpinfo inurl:info.php

1️⃣2️⃣ SQL injection vulnerabilities and weak opening path

"advanced guestbook * powered" inurl:addentry.php
intitle:"View img" inurl:viewimg.php

1️⃣3️⃣ Security Scan Report

"Assessment report" "nessus" filetype:pdf

1️⃣4️⃣ Database program and error files

"Welcome to phpmyadmin ***" "running on * as root@*" intitle:phpmyadmin
"mysql error with query"

1️⃣5️⃣ find records of these sites robots.txt screening

"robots.txt" "disallow:" filetype:txt

1️⃣6️⃣ Use this search string, you can get a lot of passwords and login account, search for these files password and account have not had encrypted

inurl:_vti_pvt "service.pwd"

1️⃣7️⃣ VNC user info

"vnc desktop" inurl:5800

1️⃣8️⃣ View public network shared printer, you can check their status, set up, you can use some of them to print their own stuff

inurl:"port_255" -htm

1️⃣9️⃣ php admin access

intitle:phpMyAdmin "Welcome to phpMyAdmin ***" running on * as root@*"
hacking: security in practice
My official email is hacked

I got an email from my firms support email account address to itself today morning.

It has the usual, you watch a porn, we recorded the screen and webcam bullshit that asks to pay in Bitcoin.

But, this is an email configured on Redmine and Nextcloud to send out notification emails. The webcam in my laptop is physically closed. And I don’t watch pornography in work machines.

The interesting part is how they got access to my email and password to send it to myself.

The email is from godaddy. It has a reasonable password strength. If they got access to the email, they may have access to the sent items and thus have info of the recipients.

Any idea how I can secure further will be greatly appreciated.

submitted by /u/vijayrex
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Forwarded from Hacking On Medium (Feed Reader Bot)
PenTesting
BlackBox Penetrating Exercise

Hi everyone, I am a sophomore studying cyber security and currently enrolled in an ethical hacking class. My professor assigned the class a homework assignment to hack into the virtual machine he set up. From a little reconnaissance, the open ports and services running on the IP Address are:

22/tcp open ssh OpenSSH 6.7p1 Debian 5+deb8u3 (protocol 2.0)

80/tcp open http Apache httpd 2.4.10 ((Debian))

11/tcp open rpcbind 2-4 (RPC #100000)

| rpcinfo:

| program version port/proto service

| 100000 2,3,4 111/tcp rpcbind

| 100000 2,3,4 111/udp rpcbind

| 100000 3,4 111/tcp6 rpcbind

| 100000 3,4 111/udp6 rpcbind

| 100024 1 33861/udp status

| 100024 1 43053/tcp6 status

| 100024 1 47080/udp6 status

|_ 100024 1 57764/tcp status

57764/tcp open status 1 (RPC #100024)

As a student that is still just a beginner in ethical hacking I am not sure what my next steps should be from this information. Any help in the right direction would be much appreciated.

submitted by /u/sneezyyyy
[link] [comments]