Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Windows Priv Escalation

Hi guys can you recommend me resources or ideas how to get better in understanding

privileges vectors on windows.

Im pretty ok with understanding linux priv escalation vector.

But if i read about windows priv escalation i just dont understand it. Maybe because i have to little windows knowledge. Any ideas what i should learn about windows in order to get confident with understanding windows priv escalation vectors

submitted by /u/Impressive_Lake9034
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Cobalt Strike - OneDrive DLL injection
https://www.reddit.com/r/redteamsec/comments/y2k1v4/cobalt_strike_onedrive_dll_injection/

Advanced Persistent Threats (APTs) Ransomware threat actors are targeting more legitimate software's used in global companies like default backup solutions such as Microsoft OneDrive. Therefore, when investigating the missing OneDrive DLL's with ProcMon, the file "cscapi.dll" is loaded from "C:\Users\%USERNAME%\AppData\Local\Microsoft\OneDrive". This allows threat actors to gain persistence when end-user opens OneDrive since the DLL will be loaded in the process. https://youtu.be/bs_fMlw6DvE submitted by /u/EpicOfAllEpics (https://www.reddit.com/user/EpicOfAllEpics)
[link] (https://www.reddit.com/r/redteamsec/comments/y2k1v4/cobalt_strike_onedrive_dll_injection/) [comments] (https://www.reddit.com/r/redteamsec/comments/y2k1v4/cobalt_strike_onedrive_dll_injection/)

___________________________
@hacking_Attack
@Hacking_Video
Best used laptop for practice…
https://www.reddit.com/r/Pentesting/comments/y2lmek/best_used_laptop_for_practice/

Hey everyone, I’m currently a support engineer for small company. I want to grow my skills and apply for other positions that revolve more around information security and pen-testing. I want to purchase a used laptop (other than my Mac) to practice with. What do you guys and girls recommend? submitted by /u/GladStrike6073 (https://www.reddit.com/user/GladStrike6073)
[link] (https://www.reddit.com/r/Pentesting/comments/y2lmek/best_used_laptop_for_practice/) [comments] (https://www.reddit.com/r/Pentesting/comments/y2lmek/best_used_laptop_for_practice/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
guys I trolled a hacker 😅😂😰😆

Hey I met this know it all hacker and I asked for access to his secure vnc server to show me how it works. I ip geo located this guy found out his time zone, and played a police siren through his window 10 coumper at 1 in the morning 😅😅🤣🤣. Lmaoo he probably jumped outside his skin

submitted by /u/lendaub
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
What can I do to mess with this bully?

So for context, this kid at my school bullies one of my close friends and I own a website that he actively goes on and uses. What can I add to this website to fuck with him? (Also, other kids at the school also actively use the website, it is used to play unblocked games and access any website unblocked)

If you have any questions please say them, I will give more context

submitted by /u/undertaleiscool123
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Code flaws leads to Org/Admin Account Takeover

Hello Everyone, I’m Saransh Saraf and I’m back with another unique account takeover idea, so let’s just dive into it :)Continue reading on Medium »
Read more...
Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE)
https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/

Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE) Updated Video Tutorial ! https://github.com/freeload101/Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy Want to pentest or run Android apps in minutes ? Sick of BlueStacks or NOX malware/adware ? Not a single binary in this script and it's open source and downloads are direct from proper sources. There is lots of great powershell tricks (not great code) in this script. I worked hard on thing's like: making it portable as possible setting up and downloading extremely fast environment for Android, Java and Python converting ssl certs to Android without openssl using certutil.exe only I would like to make it even easier to use but I don't want to spend more time developing it if nobody is going to use it so please let me know if you like it and open bugs/suggestions/feature request etc! ​ If you're a mod about to remove this post can you do me the kind pleasure of telling me why and how I can help the community better please let me know. submitted by /u/rmccurdyDOTcom (https://www.reddit.com/user/rmccurdyDOTcom)
[link] (https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/) [comments] (https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/)

___________________________
@hacking_Attack
@Hacking_Video
Help Starting
https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/

Hey everyone I’m a sophomore in college and after a bit of research I want to pursue a career in penetration testing. I’ve started learning the basics of networks and have played around with Kali Linux a little bit. I was wondering if anyone had any tips on a good starting point for someone that is brand new to all of this stuff. submitted by /u/Parkydunn (https://www.reddit.com/user/Parkydunn)
[link] (https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/) [comments] (https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
What can I do to make cryptography and enumeration easier?

I've been doing tryhackme and starting hack the box for roughly 2 months. I understand concepts such as gaining access and prelivalge escalation, but unfortunately struggle with the beginning steps like enumeration. I know what to do normally (Use Nmap, enum4linux, etc), but when I gain too little information I get stuck. I try using guides, but struggle with understanding how they were able to find so much information in massive rooms. I hope I'm not to vague and don't mean to upset anyone with these simple questions. I'm just concerned I'm not progressing in my learning path.

submitted by /u/Power_level_9000_spy
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video