hacker_trick | Unsorted

Telegram-канал hacker_trick - Hacker tricks

3151

CVEs🔰 Tools🛠 RedTeam📕

Subscribe to a channel

Hacker tricks

How to Leverage PowerShell Profiles for Lateral Movement
https://practicalsecurityanalytics.com/how-to-leverage-powershell-profiles-for-lateral-movement

Читать полностью…

Hacker tricks

Specula - Turning Outlook Into a C2 With One Registry Change
https://trustedsec.com/blog/specula-turning-outlook-into-a-c2-with-one-registry-change

Читать полностью…

Hacker tricks

Hellshazzard: Indirect Syscall implementation to bypass userland NTAPIs hooking
https://github.com/Faran-17/Hellshazzard

Читать полностью…

Hacker tricks

Threat Hunting - Suspicious Named pipes
https://mthcht.medium.com/threat-hunting-suspicious-named-pipes-a4206e8a4bc8

Читать полностью…

Hacker tricks

In the 3.3.5a WoW client there is a  RCE that allows any private server owner to inject and run arbitrary code on your computer. This patcher will modify your WoW executable file to fix the exploit
https://github.com/stoneharry/RCEPatcher

Читать полностью…

Hacker tricks

CheckUACBypass.ps1 is a PowerShell script designed to test if certain executables can be used to bypass UAC
https://github.com/AngeTia/CheckUACBypass

Читать полностью…

Hacker tricks

BYOVD Technique Example using viragt64 driver
https://github.com/CyberSecurityUP/ProcessKiller-BYOVD

Читать полностью…

Hacker tricks

PDF dropper Red Team Scenairos
https://github.com/0x6rss/pdfdropper

Читать полностью…

Hacker tricks

timebased blind sqli with 99% success rate
https://github.com/coffinxp/BSQLi

Читать полностью…

Hacker tricks

PoC for CVE-2024-40348 Bazaar v1.4.3 and prior
Will attempt to read /etc/passwd from target
https://github.com/bigb0x/CVE-2024-40348

Читать полностью…

Hacker tricks

JScripter: is a Python script designed to scrape and save unique JavaScript files from a list of URLs or a single URL
https://github.com/ifconfig-me/JScripter

Читать полностью…

Hacker tricks

Top 10 XSS Payloads
https://rodoassis.medium.com/top-10-xss-payloads-e4774a43e285

Читать полностью…

Hacker tricks

How Almost Sacrificing a University Group Project led to a Microsoft Bug Bounty
pyrus369/how-almost-sacrificing-a-university-group-project-led-to-a-microsoft-bug-bounty-9801e0f8f006" rel="nofollow">https://medium.com/@pyrus369/how-almost-sacrificing-a-university-group-project-led-to-a-microsoft-bug-bounty-9801e0f8f006

Читать полностью…

Hacker tricks

Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables
https://github.com/TierZeroSecurity/edr_blocker

Читать полностью…

Hacker tricks

SessionExec allows you to execute specified commands in other Sessions on Windows Systems, either targeting a specific session ID or All sessions, with the option to suppress command output
https://github.com/Leo4j/SessionExec

Читать полностью…

Hacker tricks

[Shellcode x64] Find and execute WinAPI functions with Assembly
https://print3m.github.io/blog/x64-winapi-shellcoding

Читать полностью…

Hacker tricks

.NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit is loading a malicious DLL using Task Scheduler (MMC) to bypass UAC and getting admin privileges
https://github.com/Offensive-Panda/.NET_PROFILER_DLL_LOADING

Читать полностью…

Hacker tricks

Double Dipping Cheat Developer Gets Caught Red-Handed
https://www.cyberark.com/resources/threat-research-blog/double-dipping-cheat-developer-gets-caught-red-handed

Читать полностью…

Hacker tricks

Abusing PIM-related application permissions in Microsoft Graph - Part 1
https://www.emiliensocchi.io/abusing-pim-related-application-permissions-in-microsoft-graph-part-1

Читать полностью…

Hacker tricks

Exploit Searchor 2.4.0 RCE
https://github.com/b0ySie7e/Exploit_Searchor_2.4.0_RCE

Читать полностью…

Hacker tricks

A tool for manual or automatic patch shellcode into binary file Oder to bypass AV
https://github.com/yj94/BinarySpy

Читать полностью…

Hacker tricks

Process Injection using Thread Name
https://github.com/hasherezade/thread_namecalling

Читать полностью…

Hacker tricks

Database Hacking with common SQL Injection commands
redfanatic7/database-hacking-with-common-sql-injection-commands-c33b049554fe" rel="nofollow">https://medium.com/@redfanatic7/database-hacking-with-common-sql-injection-commands-c33b049554fe

Читать полностью…

Hacker tricks

Deep Sea Phishing Pt. 1
https://posts.specterops.io/deep-sea-phishing-pt-1-092a0637e2fd

Читать полностью…

Hacker tricks

Helios: Automated XSS Testing
https://github.com/Stuub/Helios

Читать полностью…

Hacker tricks

Advanced SQL Injection Techniques
https://github.com/ifconfig-me/SQL_Injection-Techniques
List of Directory Traversal/LFI Payloads
https://github.com/ifconfig-me/Directory-Traversal-Payloads

Читать полностью…

Hacker tricks

SOC Home Lab
dyavanapellisujal7/soc-home-lab-part-1-6309b5b91118">Part 1     ○●     dyavanapellisujal7/soc-home-lab-part-2-2a0e1f3cdca6">Part 2     ○●     dyavanapellisujal7/soc-home-lab-part-3-8832e8325e80">Part 3

Читать полностью…

Hacker tricks

WhatsApp trick: Android malware can impersonate PDF file
https://www.mobile-hacker.com/2024/07/23/whatsapp-trick-android-malware-can-impersonate-pdf-file

Читать полностью…

Hacker tricks

Goffloader: A pure Go implementation of an in-memory COFFLoader (and PE loader)
https://github.com/praetorian-inc/goffloader

Читать полностью…

Hacker tricks

Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android
https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android

Читать полностью…
Subscribe to a channel