hacking: security in practice
Worth the watch
Watched this tonight very interesting I feel some members of the community will enjoy it but it might not be for everyone https://m.youtube.com/watch?v=wTgYeETwgKQ
submitted by /u/Phantasius224
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Worth the watch
Watched this tonight very interesting I feel some members of the community will enjoy it but it might not be for everyone https://m.youtube.com/watch?v=wTgYeETwgKQ
submitted by /u/Phantasius224
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Worth the watch
Watched this tonight very interesting I feel some members of the community will enjoy it but it might not be for everyone...
LDAP Nom Nom - anonymously bruteforce Active Directory usernames at high speed
https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/
Here's my new tool "LDAP nom nom", which allows you to anonymously bruteforce Domain Controllers to find usernames in Active Directory at high speeds. As far as I know there are no logs generated for this, so detecting this requires custom network level monitoring. If you're pentesting a new environment, and don't know where to start, you can detect existence of about 10M usernames in less than 30 minutes (10K names/sec) From there on, it could be a question of looking for really dubious account names like "admintest" or "tempadmin" who might have the same password as the account name. This can be attempted by kerberoasting or direct logins (this is noisy and generates events). Reception of this small tool has been terrific, with more than 200 stars on Github in less than 24 hours, which is crazy compared to the other stuff I've released. https://github.com/lkarlslund/ldapnomnom submitted by /u/lkarlslund (https://www.reddit.com/user/lkarlslund)
[link] (https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/) [comments] (https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/
Here's my new tool "LDAP nom nom", which allows you to anonymously bruteforce Domain Controllers to find usernames in Active Directory at high speeds. As far as I know there are no logs generated for this, so detecting this requires custom network level monitoring. If you're pentesting a new environment, and don't know where to start, you can detect existence of about 10M usernames in less than 30 minutes (10K names/sec) From there on, it could be a question of looking for really dubious account names like "admintest" or "tempadmin" who might have the same password as the account name. This can be attempted by kerberoasting or direct logins (this is noisy and generates events). Reception of this small tool has been terrific, with more than 200 stars on Github in less than 24 hours, which is crazy compared to the other stuff I've released. https://github.com/lkarlslund/ldapnomnom submitted by /u/lkarlslund (https://www.reddit.com/user/lkarlslund)
[link] (https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/) [comments] (https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
LDAP Nom Nom - anonymously bruteforce Active Directory usernames...
Here's my new tool "LDAP nom nom", which allows you to anonymously bruteforce Domain Controllers to find usernames in Active Directory at high...
Crack Pre-Shared Key of WPA/WPA2 from Live Network
https://www.reddit.com/r/redteamsec/comments/xi7650/crack_preshared_key_of_wpawpa2_from_live_network/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/cracking-wpa-psk-using-aircrack/) [comments] (https://www.reddit.com/r/redteamsec/comments/xi7650/crack_preshared_key_of_wpawpa2_from_live_network/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/xi7650/crack_preshared_key_of_wpawpa2_from_live_network/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/cracking-wpa-psk-using-aircrack/) [comments] (https://www.reddit.com/r/redteamsec/comments/xi7650/crack_preshared_key_of_wpawpa2_from_live_network/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Crack Pre-Shared Key of WPA/WPA2 from Live Network
Posted in r/redteamsec by u/tbhaxor • 1 point and 0 comments
Staying Under the Radar - PPID Spoofing and Blocking DLLs
https://www.reddit.com/r/redteamsec/comments/xi7opb/staying_under_the_radar_ppid_spoofing_and/
https://crypt0ace.github.io/posts/Staying-under-the-Radar/ submitted by /u/Potential_Waltz7400 (https://www.reddit.com/user/Potential_Waltz7400)
[link] (https://www.reddit.com/r/redteamsec/comments/xi7opb/staying_under_the_radar_ppid_spoofing_and/) [comments] (https://www.reddit.com/r/redteamsec/comments/xi7opb/staying_under_the_radar_ppid_spoofing_and/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/xi7opb/staying_under_the_radar_ppid_spoofing_and/
https://crypt0ace.github.io/posts/Staying-under-the-Radar/ submitted by /u/Potential_Waltz7400 (https://www.reddit.com/user/Potential_Waltz7400)
[link] (https://www.reddit.com/r/redteamsec/comments/xi7opb/staying_under_the_radar_ppid_spoofing_and/) [comments] (https://www.reddit.com/r/redteamsec/comments/xi7opb/staying_under_the_radar_ppid_spoofing_and/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Staying Under the Radar - PPID Spoofing and Blocking DLLs
https://crypt0ace.github.io/posts/Staying-under-the-Radar/
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe : Red Team Learning Path
https://cdn-images-1.medium.com/max/864/1*InAO4lsmYeEU3KC19eP65A.png
hey sup, it’s your techie Kalra here, so recently Tryhackme has created a new Learning Path called “Red Team Learning Path”, so today we…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe : Red Team Learning Path
https://cdn-images-1.medium.com/max/864/1*InAO4lsmYeEU3KC19eP65A.png
hey sup, it’s your techie Kalra here, so recently Tryhackme has created a new Learning Path called “Red Team Learning Path”, so today we…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe : Red Team Learning Path
hey sup, it’s your techie Kalra here, so recently Tryhackme has created a new Learning Path called “Red Team Learning Path”, so today we…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hello Ethernaut (Level-0) CTF
https://cdn-images-1.medium.com/max/612/1*9XvfiaRh6u17knFl203x9A.jpeg
Introduction
Continue reading on CoinsBench »
___________________________
@hacking_Attack
@Hacking_Video
Hello Ethernaut (Level-0) CTF
https://cdn-images-1.medium.com/max/612/1*9XvfiaRh6u17knFl203x9A.jpeg
Introduction
Continue reading on CoinsBench »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hello Ethernaut (Level-0) CTF
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Developing Pentest Skills
https://cdn-images-1.medium.com/max/728/0*7AlpQBiy8wX6MrrQ
Lots of people ask me how to get into the hacking field and almost always I tell them to start with pentesting. Pentesting is the gateway…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Developing Pentest Skills
https://cdn-images-1.medium.com/max/728/0*7AlpQBiy8wX6MrrQ
Lots of people ask me how to get into the hacking field and almost always I tell them to start with pentesting. Pentesting is the gateway…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Developing Pentest Skills
Lots of people ask me how to get into the hacking field and almost always I tell them to start with pentesting. Pentesting is the gateway…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google Dorking: How to hack the google search algorithm?
https://cdn-images-1.medium.com/max/1514/1*JH4EWYvR8BGX0zs-M2u_wg.jpeg
Most of us have faced those frustrating moments when we need that missing piece of information or a snippet of code to finish that college…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Google Dorking: How to hack the google search algorithm?
https://cdn-images-1.medium.com/max/1514/1*JH4EWYvR8BGX0zs-M2u_wg.jpeg
Most of us have faced those frustrating moments when we need that missing piece of information or a snippet of code to finish that college…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google Dorking: How to hack the google search algorithm?
Most of us have faced those frustrating moments when we need that missing piece of information or a snippet of code to finish that college…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DeFi: Over a million dollars stolen from Inverse Finance
https://cdn-images-1.medium.com/max/1600/1*HSOVnygmwAs0iQkora-FOg.png
Inverse Finance again fell victim to an instant credit exploit for $1.26 million in Tether (USDT) and Wrapped Bitcoin (WBTC).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DeFi: Over a million dollars stolen from Inverse Finance
https://cdn-images-1.medium.com/max/1600/1*HSOVnygmwAs0iQkora-FOg.png
Inverse Finance again fell victim to an instant credit exploit for $1.26 million in Tether (USDT) and Wrapped Bitcoin (WBTC).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DeFi: Over a million dollars stolen from Inverse Finance
Inverse Finance again fell victim to an instant credit exploit for $1.26 million in Tether (USDT) and Wrapped Bitcoin (WBTC).
Découverte d’une faille IDOR et extraction de données téléphoniques
https://medium.com/@m4rkus.p1/d%C3%A9couverte-dune-faille-idor-et-extraction-de-donn%C3%A9es-t%C3%A9l%C3%A9phoniques-29657cfe65ff?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@m4rkus.p1/d%C3%A9couverte-dune-faille-idor-et-extraction-de-donn%C3%A9es-t%C3%A9l%C3%A9phoniques-29657cfe65ff?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Découverte d’une faille IDOR et extraction de données téléphoniques
J’ai un compte client fidélité chez une grande enseigne de prêt à porter… je tiens à flouter le nom de l’enseigne dans la suite de cet…
J’ai un compte client fidélité chez une grande enseigne de prêt à porter… je tiens à flouter le nom de l’enseigne dans la suite de cet…Continue reading on Medium » (https://medium.com/@m4rkus.p1/d%C3%A9couverte-dune-faille-idor-et-extraction-de-donn%C3%A9es-t%C3%A9l%C3%A9phoniques-29657cfe65ff?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Découverte d’une faille IDOR et extraction de données téléphoniques
J’ai un compte client fidélité chez une grande enseigne de prêt à porter… je tiens à flouter le nom de l’enseigne dans la suite de cet…
Parrot or kali for Pentesting
https://www.reddit.com/r/Pentesting/comments/xiahu1/parrot_or_kali_for_pentesting/
I have been struggling with installing Kali on HP omen. I'm now considering using Parrot for Pentesting and security stuff. What advice would you give to someone starting out and considering using Parrot? I know Kali is the recommended OS for security. submitted by /u/Groundbreaking_Owl24 (https://www.reddit.com/user/Groundbreaking_Owl24)
[link] (https://www.reddit.com/r/Pentesting/comments/xiahu1/parrot_or_kali_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/xiahu1/parrot_or_kali_for_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/xiahu1/parrot_or_kali_for_pentesting/
I have been struggling with installing Kali on HP omen. I'm now considering using Parrot for Pentesting and security stuff. What advice would you give to someone starting out and considering using Parrot? I know Kali is the recommended OS for security. submitted by /u/Groundbreaking_Owl24 (https://www.reddit.com/user/Groundbreaking_Owl24)
[link] (https://www.reddit.com/r/Pentesting/comments/xiahu1/parrot_or_kali_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/xiahu1/parrot_or_kali_for_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Parrot or kali for Pentesting
I have been struggling with installing Kali on HP omen. I'm now considering using Parrot for Pentesting and security stuff. What advice would you...
CATS - REST API Fuzzer And Negative Testing Tool For OpenAPI Endpoints
http://www.kitploit.com/2022/09/cats-rest-api-fuzzer-and-negative.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/09/cats-rest-api-fuzzer-and-negative.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
REST API fuzzer and negative testing tool. Run thousands of self-healing API tests within minutes with no coding effort!Comprehensive: tests are generated automatically based on a large number scenarios and cover every field and headerIntelligent: tests are generated based on data types and constraints; each Fuzzer have specific expectations depending on the scenario under testHighly Configurable: high amount of customization: you can exclude specific Fuzzers, HTTP response codes, provide business context and a lot moreSelf-Healing: as tests are generated, any OpenAPI spec change is picked up automaticallySimple to Learn: flat learning curve, with intuitive configuration and syntaxFast: automatic process for write, run and report tests which covers thousands of scenarios within minutes
OverviewBy using a simple and minimal syntax, with a flat learning curve, CATS (Contract Auto-generated Tests for Swagger) enables you to generate thousands of API tests within minutes with no coding effort. All tests are generated, run and reported automatically based on a pre-defined set of 89 Fuzzers. The Fuzzers cover a wide range of input data from fully random large Unicode values to well crafted, context dependant values based on the request data types and constraints. Even more, you can leverage the fact that CATS generates request payloads dynamically and write simple end-to-end functional tests.
___________________________
@hacking_Attack
@Hacking_Video
OverviewBy using a simple and minimal syntax, with a flat learning curve, CATS (Contract Auto-generated Tests for Swagger) enables you to generate thousands of API tests within minutes with no coding effort. All tests are generated, run and reported automatically based on a pre-defined set of 89 Fuzzers. The Fuzzers cover a wide range of input data from fully random large Unicode values to well crafted, context dependant values based on the request data types and constraints. Even more, you can leverage the fact that CATS generates request payloads dynamically and write simple end-to-end functional tests.
___________________________
@hacking_Attack
@Hacking_Video