Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CrossLinked : LinkedIn Enumeration Tool To Extract Valid Employee Names

CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from a target organization. This technique provides accurate results without the use of API keys, credentials, or even accessing the site directly. Formats can then be applied in the command line arguments to turn these names into email addresses, […]

The post CrossLinked : LinkedIn Enumeration Tool To Extract Valid Employee Names appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme | Blog

https://cdn-images-1.medium.com/max/938/1*oVV-CLp6lUY9Njq0TtjRmw.png
A medium level Tryhackme room that exploits image cropping to privesc.The vulnerability is documented in CVE-2019–8943

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is SSL?

In this tutorial we will study What is SSL (Secure Socket Layer), What is the difference between TLS (Transport Layer Security) and SSL…

Continue reading on Medium »
Solution for Terjanq x Intigriti’s 0421 challenge

This month’s Intigriti challenge was made by the amazing Terjanq. He made a cool write-up himself here! As expected, this challenge was out…
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
SniperPhish - The Web-Email Spear Phishing Toolkit

https://1.bp.blogspot.com/-6tuuzSJVshE/YIsG1eN-L8I/AAAAAAAAWAs/muJxfpD8o3wKeOtgzKGH4shQbdQr6zGbACNcBGAsYHQ/w640-h344/SniperPhish_02.png SniperPhish is a phishing toolkit for pentester or security professionals to enhance user awareness by simulating real-world phishing attacks. SniperPhish helps to combine both phishing emails and phishing websites you created to centrally track user actions. The tool is designed in a view of performing professional phishing exercise and would be reminded to take prior permission from the targeted organization to avoid legal implications. Installation1. Download the source code and put it in your web root folder
2. Open http://localhost/install in your browser and follow the steps for installation
3. After installation, open http://localhost/spear to login

Default login - Username: adminPassword: sniperphishMain Features* Web tracker code generation - track your website visits and form submissions independently
* Create and schedule Phishing mail campaigns
* Combine your phishing site with email campaign for centrally tracking
* An independent "Simple Tracker" module for quick tracking an email or web page visit
* Advance report generation - generate reports based on the tracking data you needed
* Custom tracker images and dynamic QR codes in messages
* Track phishing message replies Screenshotshttps://1.bp.blogspot.com/-s-zMNaDQDVk/YIsHC71oIZI/AAAAAAAAWAw/5SljmSFrZ8MEapB1hfVghKQk-2PNAhMjgCNcBGAsYHQ/w640-h344/SniperPhish_01.png https://1.bp.blogspot.com/-q9ul6oYQ7Zw/YIsHC_pZtAI/AAAAAAAAWA0/cRbhPCzpKZUbfhgoNzmm3JmI27gsPID_QCNcBGAsYHQ/w640-h344/SniperPhish_02.png Creating Web-Email CampaignWe create web tracker -> Add the web tracker to the phishing website -> create mail campaign with a link pointing to the phishing website -> start mail campaign. Creating a web tracker:1. Design your website in your favorite programming language. Make sure you provided unique "id" and "name" value for HTML fields such as text field, checkbox etc.
2. Generate web-tracker code Web Tracker -> New Tracker. The "Web Pages" tab list the pages you want to track
* To track form submission data, provide the "id" or "name" values of HTML fields present in your phishing site form.
* Repeat above for each page in your phishing site.

3. From the final output, copy the generated JavaScript link and add it under the section of each website page.
4. Finally, save the tracker created. Now the tracker is activated and listening in the background. Opening your phishing site or data submission is tracked. Creating an Email campaign:1. Go to Email Campaign -> User Groupand add target users
2. Go to Email Campaign -> Sender Listand configure Mail server details
3. Go to Email Campaign -> Email Templateand create mail template. When you add your phishing website link, make sure to append ?cid={{CID}}at the end. This is to distinguish each users. For example, http://yourphishingsite.com/login?cid={{CID}}4. Now go to Email Campaign -> Campaign List -> New Mail Campaignand select/fill the fields to create campaign.
5. Start Mail campaign Viewing combined Web-Email ResultOpen Web-MailCamp Dashboard -> Select Campaignand select Mail Campaign and Web Tracker you created. https://1.bp.blogspot.com/-qAXTVCi_0S8/YIwwkwvnk_I/AAAAAAAAWBE/KZ2pBbzW4ocxZrtDkRaheHPIrE9umT2nwCNcBGAsYHQ/w640-h268/SniperPhish_03.png More* SniperPhish website: https://sniperphish.com/
* SniperPhish demo: https://demo.sniperphish.com/spear/ SniperPhish honors contributions ofJoseph Nygil (@j_nygil) and Sreehari Haridas (@sr33h4ri) Download SniperPhish

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Active Directory Enumeration: BloodHound

In the article, we will focus on the Active Directory Enumeration tool called BloodHound. It takes the data from any device on the network and then proceeds to plot the graph that can help the attacker to strategize their way to the Domain Admins. Table of Content Introduction Linux Installation

The post Active Directory Enumeration: BloodHound appeared first on Hacking Articles.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Survey Finds Broad Concern Over Third-Party App Providers Post-SolarWinds

Most IT and cybersecurity professionals think security is important enough to delay deployment of applications, survey data shows.

___________________________
@hacking_Attack
@Hacking_Video