Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
PowerShell Empire StarKiller - Standard Account - KeePass Master Password Extraction (Version 2.52)
https://www.reddit.com/r/redteamsec/comments/yixl91/powershell_empire_starkiller_standard_account/

KeePass Password Managers are highly recommended and used in global companies, but also targeted by threat actors. Therefore, attackers having a foothold with limited privileges (Standard User) to the machine can identify if KeePass is running by listing the processes and unauthorized download the .KDBX KeePass Database file. While the KeePass Database file is opened, the password is stored in Plain Text in Memory which allows intruders to load scripts such as "KeeThief" to extract the Master Password and gain access to the compromised user credentials. KeePass Version: 2.52 (Latest Version, dated 01/11/2022) https://www.youtube.com/watch?v=I3-ixb9wnWg submitted by /u/EpicOfAllEpics (https://www.reddit.com/user/EpicOfAllEpics)
[link] (https://www.reddit.com/r/redteamsec/comments/yixl91/powershell_empire_starkiller_standard_account/) [comments] (https://www.reddit.com/r/redteamsec/comments/yixl91/powershell_empire_starkiller_standard_account/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I ended up leaving a trail after accessing sensitive documents at work. I think I'm gonna be fired, I'm shaking.

I found a very simple backdoor into some VERY sensitive work documents at work. Everything from direct deposits/banking. I only wanted to see my co-workers reprimand files. I'm deleting the google drive I accessed them with and making a new one. Only downside would be losing my YouTube history and all the comments I've made. Let's hope my regional manager is blind or I'm dead. I'm scared guys, I'm shaking.

Also if I do get caught, what would you recommend to properly secure such sensitive information on google drive, that I a lowly retail worker could access such files. I shared a training manual to my google drive, poked around the links inside the documents to external google drives and found a way into the management files.



Any idea how to save myself? What could happen to me? Is my accidental access illegal?

submitted by /u/bioshockbitch
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
PowerShell Empire StarKiller - Standard Account - KeePass Master Password Extraction (Version 2.52)

KeePass Password Managers are highly recommended and used in global companies, but also targeted by threat actors.

Therefore, attackers having a foothold with limited privileges (Standard User) to the machine can identify if KeePass is running by listing the processes and unauthorized download the .KDBX KeePass Database file.

While the KeePass Database file is opened, the password is stored in Plain Text in Memory which allows intruders to load scripts such as "KeeThief" to extract the Master Password and gain access to the compromised user credentials.

KeePass Version: 2.52 (Latest Version, dated 01/11/2022)

https://www.youtube.com/watch?v=I3-ixb9wnWg

submitted by /u/EpicOfAllEpics
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video