Hello Folks,Continue reading on Medium » (https://medium.com/@sharp488/access-any-owner-account-without-authentication-auth-bypass-2fa-bypass-94d0d3ef0d9c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Access Any Owner Account without Authentication (Auth bypass + 2FA bypass)
Hello Folks,
2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation
https://medium.com/@sharp488/2fa-enabled-accounts-can-bypass-authentication-access-account-after-deactivation-8276a586be82?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sharp488/2fa-enabled-accounts-can-bypass-authentication-access-account-after-deactivation-8276a586be82?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation
Hello All,
Hello All,Continue reading on Medium » (https://medium.com/@sharp488/2fa-enabled-accounts-can-bypass-authentication-access-account-after-deactivation-8276a586be82?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation
Hello All,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
IDS/IPS Identification (Information Gathering)
https://cdn-images-1.medium.com/max/720/1*dIMe3jMkKI8vTGrf5orcGA.jpeg
In my previous article we talked about “DNS Analysis”, the next section in our information gathering endeavor is IDS/IPS identification.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
IDS/IPS Identification (Information Gathering)
https://cdn-images-1.medium.com/max/720/1*dIMe3jMkKI8vTGrf5orcGA.jpeg
In my previous article we talked about “DNS Analysis”, the next section in our information gathering endeavor is IDS/IPS identification.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDS/IPS Identification (Information Gathering)
In my previous article we talked about “DNS Analysis”, the next section in our information gathering endeavor is IDS/IPS identification.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Social Engineering: A Guide To Social Engineering | Part 1
https://cdn-images-1.medium.com/max/740/0*KwuDm9HXWu6Co5BJ.png
One thing you can learn from many successful hackers is the art of social engineering.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Social Engineering: A Guide To Social Engineering | Part 1
https://cdn-images-1.medium.com/max/740/0*KwuDm9HXWu6Co5BJ.png
One thing you can learn from many successful hackers is the art of social engineering.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Social Engineering: A Guide To Social Engineering | Part 1
One thing you can learn from many successful hackers is the art of social engineering.
hacking: security in practice
SD card problem
Hi guys, i am a university students but i am not interested in the course i took. so i planned on writing neet the next year(2023). I was enrolled in byju's in my 12th grade. So to learn for neet i need their offline videos which is already in the sd card but i cannot access it. When i ask it they are saying to pay the entire fees again. So i am not in a financially good position right now to buy the entire course again. So would u guys pls help me crack the sd card containing the videos. So that i could use it for my education. I know it's too much to ask for sorry if I did anything wrong
Thank you
submitted by /u/Natural_Football5242
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
SD card problem
Hi guys, i am a university students but i am not interested in the course i took. so i planned on writing neet the next year(2023). I was enrolled in byju's in my 12th grade. So to learn for neet i need their offline videos which is already in the sd card but i cannot access it. When i ask it they are saying to pay the entire fees again. So i am not in a financially good position right now to buy the entire course again. So would u guys pls help me crack the sd card containing the videos. So that i could use it for my education. I know it's too much to ask for sorry if I did anything wrong
Thank you
submitted by /u/Natural_Football5242
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
SD card problem
Hi guys, i am a university students but i am not interested in the course i took. so i planned on writing neet the next year(2023). I was enrolled...
hacking: security in practice
Are some commands removed from Mimikatz over the years?
Specifically I am looking misc::addsid command to add into sidhistory , but it says
"addsid" command of "misc" module not found ! ,
on Github too documentation is missing for several commands? Does anyone how I can alter sidhistory programmatically.
submitted by /u/ReporterWorth4267
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are some commands removed from Mimikatz over the years?
Specifically I am looking misc::addsid command to add into sidhistory , but it says
"addsid" command of "misc" module not found ! ,
on Github too documentation is missing for several commands? Does anyone how I can alter sidhistory programmatically.
submitted by /u/ReporterWorth4267
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are some commands removed from Mimikatz over the years?
Specifically I am looking misc::addsid command to add into sidhistory , but it says "addsid" command of "misc" module not found ! , on...
hacking: security in practice
I swear i have a good reason for this.
My father has been manipulative and has been destroying our family with threats and fight. And i know that he is doing this because he is having an affair, i know this cuz i heard him talk with his mistress when he thoughr i was asleep after my surgery. My poor mother and sister don't want to admit that he is a bad person. To prove this to them i want to show them his chat and calls. His manipulative ways have destroyed our pives enough and given us lasting mental stress.
I need a way to get into his password protected samsung z fold2 and its secure folder.
I have access to his email account via the family computer and the wifi he connects to.
Can someone please help me find a way to expose this monster and finally end my misery.
Thank you.
Edit: his texts are on instagram and Facebook messenger if that helps.
submitted by /u/Atom9855
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I swear i have a good reason for this.
My father has been manipulative and has been destroying our family with threats and fight. And i know that he is doing this because he is having an affair, i know this cuz i heard him talk with his mistress when he thoughr i was asleep after my surgery. My poor mother and sister don't want to admit that he is a bad person. To prove this to them i want to show them his chat and calls. His manipulative ways have destroyed our pives enough and given us lasting mental stress.
I need a way to get into his password protected samsung z fold2 and its secure folder.
I have access to his email account via the family computer and the wifi he connects to.
Can someone please help me find a way to expose this monster and finally end my misery.
Thank you.
Edit: his texts are on instagram and Facebook messenger if that helps.
submitted by /u/Atom9855
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I swear i have a good reason for this.
My father has been manipulative and has been destroying our family with threats and fight. And i know that he is doing this because he is having...
How to Install Gf Tool and Patterns on Kali Linux
Install Gf tool and It’s Pattern on Kali Linux with Easy Simple StepsContinue reading on System Weakness »
Read more...
Install Gf tool and It’s Pattern on Kali Linux with Easy Simple StepsContinue reading on System Weakness »
Read more...
KitPloit - PenTest Tools!
Kubeeye - Tool To Find Various Problems On Kubernetes, Such As Application Misconfiguration, Unhealthy Cluster Components And Node Problems
___________________________
@hacking_Attack
@Hacking_Video
Kubeeye - Tool To Find Various Problems On Kubernetes, Such As Application Misconfiguration, Unhealthy Cluster Components And Node Problems
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Kubeeye - Tool To Find Various Problems On Kubernetes, Such As Application Misconfiguration, Unhealthy Cluster Components And Node…
Kubeeye - Tool To Find Various Problems On Kubernetes, Such As Application Misconfiguration, Unhealthy Cluster Components And Node Problems
http://www.kitploit.com/2022/11/kubeeye-tool-to-find-various-problems.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/11/kubeeye-tool-to-find-various-problems.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Kubeeye - Tool To Find Various Problems On Kubernetes, Such As Application Misconfiguration, Unhealthy Cluster Components And Node…
KubeEye is an inspection tool for Kubernetes (https://www.kitploit.com/search/label/Kubernetes) to discover Kubernetes resources (by OPA (https://github.com/open-policy-agent/opa) ), cluster components, cluster nodes (by Node-Problem-Detector (https://github.com/kubernetes/node-problem-detector)) and other configurations are meeting with best practices, and giving suggestions for modification.KubeEye supports custom inspection rules and plugins installation. Through KubeEye Operator (https://github.com/kubesphere/kubeeye#kubeeye-operator), you can view the inspection results and modification (https://www.kitploit.com/search/label/Modification) suggestions by the graphical display on the web page.
ArchitectureKubeEye get cluster resource details by the Kubernetes API, inspect the resource configurations by inspection rules and plugins, and generate inspection results. See Architecture for details.
___________________________
@hacking_Attack
@Hacking_Video
ArchitectureKubeEye get cluster resource details by the Kubernetes API, inspect the resource configurations by inspection rules and plugins, and generate inspection results. See Architecture for details.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
How to useInstall KubeEye on your machineDownload pre built executables from Releases (https://github.com/kubesphere/kubeeye/releases).Or you can build from source codeNote: make install will create kubeeye in /usr/local/bin/ on your machine.git clone https://github.com/kubesphere/kubeeye.git
cd kubeeye
make installke[Optional] Install Node-problem-Detector (https://github.com/kubernetes/node-problem-detector)Note: This will install npd on your cluster, only required if you want detailed report.kubeeye install npdRun KubeEyeNote: The results of kubeeye sort by resource kind.kubeeye audit
KIND NAMESPACE NAME REASON LEVEL MESSAGE
Node docker-desktop kubelet has no sufficient memory available warning KubeletHasNoSufficientMemory
Node docker-desktop kubelet has no sufficient PID available warning KubeletHasNoSufficientPID
Node docker-desktop kubelet has disk pressure warning KubeletHasDiskPressure
Deployment default testkubeeye NoCPULimits
Deployment default testkubeeye NoReadinessProbe
Deployment default testkubeeye NotRunAsNonRoot
Deployment kube-system coredns NoCPULimits
Deployment kube-system coredns ImagePullPolicyNotAlways
Deployment kube-system coredns NotRunAsNonRoot
Deployment kubeeye-system kubeeye-controller-manager ImagePullPolicyNotAlways
Deployment kubeeye-system kubeeye-controller-manager NotRunAsNonRoot
DaemonSet kube-system kube-proxy NoCPULimits
DaemonSet k ube-system kube-proxy NotRunAsNonRoot
Event kube-system coredns-558bd4d5db-c26j8.16d5fa3ddf56675f Unhealthy warning Readiness probe failed: Get "http://10.1.0.87:8181/ready": dial tcp 10.1.0.87:8181: connect: connection refused
Event kube-system coredns-558bd4d5db-c26j8.16d5fa3fbdc834c9 Unhealthy warning Readiness probe failed: HTTP probe failed with statuscode: 503
Event kube-system vpnkit-controller.16d5ac2b2b4fa1eb BackOff warning Back-off restarting failed container
Event kube-system vpnkit-controller.16d5fa44d0502641 BackOff warning Back-off restarting failed container
___________________________
@hacking_Attack
@Hacking_Video
cd kubeeye
make installke[Optional] Install Node-problem-Detector (https://github.com/kubernetes/node-problem-detector)Note: This will install npd on your cluster, only required if you want detailed report.kubeeye install npdRun KubeEyeNote: The results of kubeeye sort by resource kind.kubeeye audit
KIND NAMESPACE NAME REASON LEVEL MESSAGE
Node docker-desktop kubelet has no sufficient memory available warning KubeletHasNoSufficientMemory
Node docker-desktop kubelet has no sufficient PID available warning KubeletHasNoSufficientPID
Node docker-desktop kubelet has disk pressure warning KubeletHasDiskPressure
Deployment default testkubeeye NoCPULimits
Deployment default testkubeeye NoReadinessProbe
Deployment default testkubeeye NotRunAsNonRoot
Deployment kube-system coredns NoCPULimits
Deployment kube-system coredns ImagePullPolicyNotAlways
Deployment kube-system coredns NotRunAsNonRoot
Deployment kubeeye-system kubeeye-controller-manager ImagePullPolicyNotAlways
Deployment kubeeye-system kubeeye-controller-manager NotRunAsNonRoot
DaemonSet kube-system kube-proxy NoCPULimits
DaemonSet k ube-system kube-proxy NotRunAsNonRoot
Event kube-system coredns-558bd4d5db-c26j8.16d5fa3ddf56675f Unhealthy warning Readiness probe failed: Get "http://10.1.0.87:8181/ready": dial tcp 10.1.0.87:8181: connect: connection refused
Event kube-system coredns-558bd4d5db-c26j8.16d5fa3fbdc834c9 Unhealthy warning Readiness probe failed: HTTP probe failed with statuscode: 503
Event kube-system vpnkit-controller.16d5ac2b2b4fa1eb BackOff warning Back-off restarting failed container
Event kube-system vpnkit-controller.16d5fa44d0502641 BackOff warning Back-off restarting failed container
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Releases · kubesphere/kubeeye
KubeEye aims to find various problems on Kubernetes, such as application misconfiguration, unhealthy cluster components and node problems. - kubesphere/kubeeye
Event kubeeye-system kubeeye-controller-manager-7f79c4ccc8-f2njw.16d5fa3f61b28527 Failed warning Error: ImagePullBackOff
Role kubeeye-system kubeeye-leader-election-role CanDeleteResources
ClusterRole kubeeye-manager-role CanDeleteResources
ClusterRole kubeeye-manager-role CanModifyWorkloads
ClusterRole vpnkit-controller CanImpersonateUser
ClusterRole vpnkit-controller CanDeleteResourcesWhat KubeEye can doKubeEye inspects cluster resources according with Kubernetes best practices, to make cluster stable.KubeEye can find problems of your cluster control plane, including kube-apiserver/kube-controller-manager/etcd, etc.KubeEye helps you detect all kinds of cluster nodes problems, including memory/cpu/disk pressure, unexpected kernel error logs, etc.ChecklistYES/NOCHECK ITEMDescriptionLevel✅PrivilegeEscalationAllowedPrivilege escalation (https://www.kitploit.com/search/label/Escalation) is alloweddanger✅CanImpersonateUserThe role/clusterrole can impersonate other userwarning✅CanModifyResourcesThe role/clusterrole can delete kubernetes resourceswarning✅CanModifyWorkloadsThe role/clusterrole can modify kubernetes workloadswarning✅NoCPULimitsThe resource does not set limits of CPU in containers.resourcesdanger✅NoCPURequestsThe resource does not set requests of CPU in containers.resourcesdanger✅HighRiskCapabilitiesHave high-Risk options in capabilities such as ALL/SYS_ADMIN/NET_ADMINdanger✅HostIPCAllowedHostIPC Set to truedanger✅HostNetworkAllowedHostNetwork Set to truedanger✅HostPIDAllowedHostPID Set to truedanger✅HostPortAllowedHostPort Set to truedanger✅ImagePullPolicyNotAlwaysImage pull policy not alwayswarning✅ImageTagIsLatestThe image tag is latestwarning✅ImageTagMissThe image tag do not declaredanger✅InsecureCapabilitiesHave insecure options in capabilities such as KILL/SYS_CHROOT/CHOWNdanger✅NoLivenessProbeThe resource does not set livenessProbewarning✅NoMemoryLimitsThe resource does not set limits of memory in containers.resourcesdanger✅NoMemoryRequestsThe resource does not set requests of memory in containers.resourcesdanger✅NoPriorityClassNameThe resource does not set priorityClassNameignore✅PrivilegedAllowedRunning a pod in a privileged mode means that the pod can access the host’s resources and kernel capabilitiesdanger✅NoReadinessProbeThe resource does not set readinessProbewarning✅NotReadOnlyRootFilesystemThe resource does not set readOnlyRootFilesystem to truewarning✅NotRunAsNonRootThe resource does not set runAsNonRoot to true, maybe executed run as a root accountwarning✅CertificateExpiredPeriodCertificate expiration date less than 30 daysdanger✅EventAuditEvent auditwarning✅NodeStatusnode status auditwarning✅DockerStatusdocker status auditwarning✅KubeletStatuskubelet status auditwarningAdd your own inspection rulesAdd custom OPA rulescreate a directory (https://www.kitploit.com/search/label/Directory) for OPA rulesmkdir opaAdd custom OPA rules filesNote: the OPA rule for workloads, package name must be kubeeye_workloads_regofor RBAC, package name must be kubeeye_RBAC_regofor nodes, package name must be kubeeye_nodes_regoSave the following rules to rule file such as imageRegistryRule.rego to check the image registry address complies with rules.package kubeeye_workloads_rego
deny[msg] {
resource := input
type := resource.Object.kind
resourcename := resource.Object.metadata.name
___________________________
@hacking_Attack
@Hacking_Video
Role kubeeye-system kubeeye-leader-election-role CanDeleteResources
ClusterRole kubeeye-manager-role CanDeleteResources
ClusterRole kubeeye-manager-role CanModifyWorkloads
ClusterRole vpnkit-controller CanImpersonateUser
ClusterRole vpnkit-controller CanDeleteResourcesWhat KubeEye can doKubeEye inspects cluster resources according with Kubernetes best practices, to make cluster stable.KubeEye can find problems of your cluster control plane, including kube-apiserver/kube-controller-manager/etcd, etc.KubeEye helps you detect all kinds of cluster nodes problems, including memory/cpu/disk pressure, unexpected kernel error logs, etc.ChecklistYES/NOCHECK ITEMDescriptionLevel✅PrivilegeEscalationAllowedPrivilege escalation (https://www.kitploit.com/search/label/Escalation) is alloweddanger✅CanImpersonateUserThe role/clusterrole can impersonate other userwarning✅CanModifyResourcesThe role/clusterrole can delete kubernetes resourceswarning✅CanModifyWorkloadsThe role/clusterrole can modify kubernetes workloadswarning✅NoCPULimitsThe resource does not set limits of CPU in containers.resourcesdanger✅NoCPURequestsThe resource does not set requests of CPU in containers.resourcesdanger✅HighRiskCapabilitiesHave high-Risk options in capabilities such as ALL/SYS_ADMIN/NET_ADMINdanger✅HostIPCAllowedHostIPC Set to truedanger✅HostNetworkAllowedHostNetwork Set to truedanger✅HostPIDAllowedHostPID Set to truedanger✅HostPortAllowedHostPort Set to truedanger✅ImagePullPolicyNotAlwaysImage pull policy not alwayswarning✅ImageTagIsLatestThe image tag is latestwarning✅ImageTagMissThe image tag do not declaredanger✅InsecureCapabilitiesHave insecure options in capabilities such as KILL/SYS_CHROOT/CHOWNdanger✅NoLivenessProbeThe resource does not set livenessProbewarning✅NoMemoryLimitsThe resource does not set limits of memory in containers.resourcesdanger✅NoMemoryRequestsThe resource does not set requests of memory in containers.resourcesdanger✅NoPriorityClassNameThe resource does not set priorityClassNameignore✅PrivilegedAllowedRunning a pod in a privileged mode means that the pod can access the host’s resources and kernel capabilitiesdanger✅NoReadinessProbeThe resource does not set readinessProbewarning✅NotReadOnlyRootFilesystemThe resource does not set readOnlyRootFilesystem to truewarning✅NotRunAsNonRootThe resource does not set runAsNonRoot to true, maybe executed run as a root accountwarning✅CertificateExpiredPeriodCertificate expiration date less than 30 daysdanger✅EventAuditEvent auditwarning✅NodeStatusnode status auditwarning✅DockerStatusdocker status auditwarning✅KubeletStatuskubelet status auditwarningAdd your own inspection rulesAdd custom OPA rulescreate a directory (https://www.kitploit.com/search/label/Directory) for OPA rulesmkdir opaAdd custom OPA rules filesNote: the OPA rule for workloads, package name must be kubeeye_workloads_regofor RBAC, package name must be kubeeye_RBAC_regofor nodes, package name must be kubeeye_nodes_regoSave the following rules to rule file such as imageRegistryRule.rego to check the image registry address complies with rules.package kubeeye_workloads_rego
deny[msg] {
resource := input
type := resource.Object.kind
resourcename := resource.Object.metadata.name
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.