Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
how to hack a hacker?

my instagram got hacked. it’s an account i’ve had for the majority of my life and it holds special memories on it that i can only access through the archive tab. the hacker changed the email associated with the account and i know what that email is. how can i hack back into the account and get it back?

submitted by /u/cutiepie9ccr
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Timelapse HackTheBox Walkthrough

SummaryTimelapse is a HTB Active Directory machine is an easy machine but as the concept of initial compromise is unique therefore, I believe it should categories as Intermediate. By solving this lab I learn how can an attacker steal CA certificate to perform lateral moment.Initial Access· NmapPrivilege Escalation· WinPeasInitial AccessNmapFrom the nmap scan, we can see that this is a Window Server more precisely a domain controller since we have DNS, LDAP, Kerberos and SMB ports open.  Also WinRM ( Windows Remote Management) port 5986 is present. SMBClientpfxhashOpensslNow, we are going to convert that pfx file to the hash and crack it using the hash using John to get the private key and the pem key. As you can see, the password is thuglegacy.___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Timelapse HackTheBox Walkthrough SummaryTimelapse is a HTB Active Directory machine is an easy machine but as the concept of initial compromise is unique therefore, I believe it should categories as Intermediate. By solving…
000/6.png Once the private key available, we can use this key to login on the box. Privilege Escalation Now we have a shell on the box. It seems we don’t have anything in the document library. Let’s browse to the desktop library to see if we can find any flag. Indeed we have a user.txt flag on the desktop. WinPeas.exeOnce installed, lets run updog on 80. As shown below, updog is running on port 80 now. Credential Dumping- LAPSAs we can see from the file, the username is svc_deploy and the password has been assigned to the variable p. now let’s verify in which group the user svc_deploy is a member of. It is a member of the LAPS_Readers group. LAPS stands for Local Administrator Password Solution. It ramdomise all the password for all local machines so that you cannot execute passthehash attack. However, it stores the password on active directory itself and only members of LAPS_Readers can read the password. net users. We found a user account named svc_deploy. Let’s check in which group membership this is located. Its in the LAPS_Readers group. ___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Timelapse HackTheBox Walkthrough

SummaryTimelapse is an HTB Active Directory machine that is an easy machine but as the concept of initial compromise is unique, therefore, I believe it should be categorised as Intermediate. By solving this lab I learn how an attacker can steal a CA certificate to perform a lateral moment. Table of contentInitial Access

* Nmap
* SMB-client
* Openssl
* Winrm

Privilege Escalation

* WinPeas
* Credential Dumping
* Abusing LAPS Initial AccessLet’s deep dive into the time.
nmap -p- -sV 10.129.227.105
From the nmap scan, we can see that this is a Window Server more precisely a domain controller since we have DNS, LDAP, Kerberos and SMB ports open.  Also WinRM ( Windows Remote Management) port 5986 is present.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjID051By-VBlUYNF9BZf36EZ3gW0x7X78i59h-mgW81sxbYuUo2pUv_NK57tYbH0gopt5H5xjvqOxE4Xrh0k07Fo88jAOx1ZCIbSHRVOsz7R7xxQv_vekCY3sFxv3K9Az9Q-O2GxQpARrcJy4-yJsCOISB61q3coOpYyX_N-BcZsG_7pHGQHHLprlX2A/s16000/1.png?w=640&ssl=1

SMBClient
smbclient -L 10.129.227.105
Let’s use smb client to find if there are any share folders available for anonymous login. Indeed, there is a sharing enabled with the name of “Shares”.

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsm0wCJFWtk-iFR_pveV8ElT7iUYd6UKvACZ-r3aLoLsE7hAMILpQRdD3qXR3cIjlFsuXdpnmrvivF2HYeEKyXf0JlufnffgLAUgtBIh3CwWxdi3O07D6GDtA9-09l8viRAFzsg57UKyY009dZJ8t0s0Da8fJzkax51ZLu6oMJKV9_tdhjSnjeQ-0mkg/s16000/2.png?w=640&ssl=1

Now we try to connect to that folder using smb client and browse the directory to find other subfolders. The winrm_backup.zip is actually password-protected. So we need to crack it.

In our scenario, we used fcrackzip to crack the winrm_backup file using the wordlist rockyou.txt.
fcrackzip -D -u winrm_backup.zip -p /usr/share/wordlists/rockyou.txt
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrTsOL0o7zCKX92Sbo394pYniIULHkkDAdRfWrh676SpHga0waz0C0NGdClBMu6Cjwjiq1jjv7eHIfJVWTfhTm4HPz_zvo_G_H4B8AkUAxP4AjvPEdGg08nSSOaBo0lUgvkmnt1ZlrMC9Y-9HUXzsA5NrbxyI8RURVA3suJu9dG4ZbtNL8yi0IrTpAkg/s16000/3.png?w=640&ssl=1

Once we have cracked the password, we can use it to unzip the file. Once extracted, we find a .pfx file called: legacy_dev_auth.pfx. PFX files are actually digital certificates that contain both the SSL certificate’s public and private keys.
unzip winrm_backup.zip
pfx2john legacyy_dev_auth.pfx >pfxhash
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT2xTSL3McxV8u3kYp4II-64uH8KUE_Z8j2zJi0tVt3_JJ6p3eZtolDQD4UXqCC7xtKwmaDayE-jFTkHJ5FEHohi7GEN9aRQwN60Id_eYJm0zA5jPMoMjK0MoDKUVDdRuJSdRthQWyi_-UMssOZA2SVX89qGJ1MyUUyIw1Zyia1vnvSqgJpJyZV7cNlw/s16000/4.png?w=640&ssl=1

Openssl

Now, we are going to convert that pfx file to the hash and crack it using the hash using John to get the private key and the pem key. As you can see, the password is thuglegacy.

We will try to open the certificate using openssl and as we can see it is a Microsoft Software Key Storage Provider. We can extract the certificate and private key.
openssl pkcs12 -in legacyy_dev_auth.pfx -nocerts -out priv-key.pem -nodes
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi83o71ll2RGK6XmZzG9vN2DReDNQbPGP-GuLbVhIKltXCt_LPu9XjisyLkqu7uJh8Id_b9yBKyJ8Yp3fO0UyLS-rKJ1Syn6uUXgXtBu6iLUShlvBFFgs8fvFdmAJFNFz7DHNQoCmAx-3YVI-qVPV4v9JJGTdeBuRBqcNuPPKGTpxxWC0h7swIR2RRVsg/s16000/5.png?w=640&ssl=1
openssl pkcs12 -in legacyy_dev_auth.pfx -nokeys -out certificate.pem
https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaanuVwr4k6mzZXEWvSJooqEBDCr9CD8PtTHQQUnyiJ7cH85jKYjgjTWdfGCfzBFVaWPCBbHnxM2I6SvPnQFEOIvrycSP72TEObnXrGxHpHAwJyHaBXyd1tB6-adtUC0gX3tJgldFRcmyzmG9AOf-WCW2Q9u0et1ul1UalsH1qNU2nQNMbZ0MHWK3CTg/s16000/6.png?w=640&ssl=1

Once the private key is available, we can use this key to login into the[...]

___________________________
@hacking_Attack
@Hacking_Video