Welcome, Guest
You have to register before you can post on our site.

Username
  

Password
  





Search Forums

(Advanced Search)

Forum Statistics
» Members: 277
» Latest member: StephenDut
» Forum threads: 34
» Forum posts: 59

Full Statistics

Online Users
There are currently 7 online users.
» 0 Member(s) | 7 Guest(s)

Latest Threads
Blu-Ray
Automated Atomic Adversar...

Forum: Red Teaming
Last Post: Blu-Ray
12-10-2025, 04:30 AM
» Replies: 2
» Views: 1,244
Mr.Z
Hell's Gate technique wit...

Forum: General discussion
Last Post: Mr.Z
09-30-2025, 07:19 PM
» Replies: 0
» Views: 227
Mr.Z
Hello!

Forum: General discussion
Last Post: Mr.Z
09-30-2025, 07:15 PM
» Replies: 9
» Views: 3,114
Clara1337
XSS

Forum: Hot Topics
Last Post: Clara1337
08-03-2025, 05:39 PM
» Replies: 0
» Views: 497
Unix_Root
Compiled tools for intern...

Forum: Popular tools
Last Post: Unix_Root
07-26-2025, 12:15 PM
» Replies: 0
» Views: 636
Unix_Root
Windows Server Rdp hosted...

Forum: Announcement
Last Post: Unix_Root
07-25-2025, 06:36 AM
» Replies: 0
» Views: 675
Unix_Root
A series of scripts to ha...

Forum: Blue Team - General
Last Post: Unix_Root
07-23-2025, 09:55 PM
» Replies: 0
» Views: 563
Unix_Root
XSS.IS Cybercrime Forum S...

Forum: Announcement
Last Post: Unix_Root
07-23-2025, 09:51 PM
» Replies: 0
» Views: 627
Unix_Root
BrowserBruter

Forum: Popular tools
Last Post: Unix_Root
07-06-2025, 09:11 PM
» Replies: 0
» Views: 553
Unix_Root
Advanced dork generator (...

Forum: Red Teaming
Last Post: Unix_Root
07-06-2025, 09:07 PM
» Replies: 0
» Views: 591

 
  ?️‍♂️ Story: “The Last Memory of Hard Drive 12”
Posted by: Unix_Root - 06-15-2025, 08:41 AM - Forum: Blue Team - General - No Replies

(A Journey into Digital Forensics Through Deception, Destruction, and Discovery)

? Chapter 1: The Midnight Call
11:47 PM – I received a call from an old client, this time not for a routine review or training, but for a serious incident.
“We lost all the R&D data for our new product line. It seems someone intentionally erased the hard drive and the backup. The director is furious. Can you come right away?”
I nodded, grabbed my specialized bag: the forensic hard drive, the Autopsy copyright dongle, write blocker, flashlight, and a packet of instant coffee.

? Chapter 2: Cold Air-Conditioned Room, Hot Hard Drives
When I arrived, the room was dark and cold, and the server drive smelled faintly of ozone.
The suspect hard drive – number 12 – was placed separately in an anti-static box.
“I found it wiped yesterday around 3am. But no one was on duty. The camera logs are missing.”
I used a write blocker to connect the drive to the forensic machine.
The data had been “zeroed out” – meaning the entire sector had been overwritten with byte 00.
But luckily: not the entire drive, just a major portion. I decided to use photorec and then bulk_extractor to start scanning each sector.

? Chapter 3: Blood in the Log
After almost 2 hours of extracting data from the remaining part, I recovered some hidden logs: SRUM (System Resource Usage Monitor) - few people know that it saves the machine's activities for a long time.
Including:
• Specific command line launch time: cipher /w:C:\
• Executor: account "qa-dev1"
• From there, I traced the entire command line chain: a USB plugged in 2 minutes ago, the D drive mounted.
I started to see the scenario more clearly:
• A person with elevated privileges
• Accessing the R&D system
Using the encryption script to quickly overwrite the data and then removing the USB

? Chapter 4: Ghost in VPN
Watching from account qa-dev1, I analyzed the VPN logs. There was a connection from an IP address in Central Europe, which did not match this employee's address.
I asked to check qa-dev1's workstation. The employee was... on a 3-day vacation to Da Lat.
Analyzing his memory dump, I found:
• Remote access tool (AnyDesk) running in the background
• Small executable file called update_vpn_svc.exe - a lightweight RAT backdoor
And more: the keepalive.log file records a strange IP address - similar to the VPN IP address mentioned above
It seems that someone used the QA account, combined with a long-installed Trojan - to attack the company itself.

? Chapter 5: The Man in the Shadows
I analyzed the timeline in more depth. In the last 6 weeks, the update_vpn_svc.exe software was installed after QA borrowed a USB from an external partner to "copy the test library".
The USB - the silent killer - is back once again.

? Chapter 6: The Last Wall
I had to run Plaso to reconstruct the detailed timeline: every login, USB insertion, script execution. After almost 12 hours, I built the big picture:
1. Backdoor secretly installed 6 weeks ago via USB.
2. Attacker was patiently observed via AnyDesk.
3. Waited until QA was on vacation - attacked via VPN.
4. Accessed R&D server, downloaded data via SMB.
5. Finally: used encryption to destroy the drive and hide the traces.

⚖️ Final Chapter: Justice and Reform
The company reported to the investigation agency. We extracted all the IOCs, wrote a 50+ page report of findings, including:
• Forensic images of hard drive 12
• IOCs: IP, file hash, backdoor, script deletion
• Detailed timeline
• Key vulnerabilities: no USB monitoring, no 2FA for VPN enabled, no regular remote tool checks

✅ Message from hard drive 12
“The bad guys don’t have to be good. They just have to be patient.
And if you don’t look at the usage logs, they’ll disappear like water – until it’s too late.”

Print this item

  Pwning the Domain: Active directory
Posted by: Unix_Root - 06-15-2025, 08:38 AM - Forum: Red Teaming - No Replies

Link:
https://drive.google.com/file/d/1KJ0MzqE..._XGpusg3Zg

Print this item

  HACKING ROADMAP FOR BEGINNERS
Posted by: zyphyrus - 06-15-2025, 01:50 AM - Forum: General discussion - Replies (1)

Just a suggestion, is there a probability to add section here for beginners who wants to learn hacking. Specifically about ETHICAL HACKING.

Print this item

  Kali Linux 2025.2 Officially Released!
Posted by: Unix_Root - 06-14-2025, 05:10 PM - Forum: General discussion - Replies (1)

The ultimate toolkit for hackers, pentesters, and cybersecurity pros just got a huge upgrade! ??
? What's new in version 2025.2:
? Desktop Updates
? ? Kali Menu Refresh: Fully reorganized based on the MITRE ATT&CK framework for easier tool discovery.
? GNOME 48 includes:
?Notification stacking ?
?Dynamic triple buffering ?
?HDR support ?
?Battery health optimization ?
?New image viewer & text editor
? KDE Plasma 6.3 includes:
?Improved fractional scaling ?
?Better performance & new hardware info ?
? BloodHound Community Edition (CE)
? Massive upgrade for Active Directory recon, with new ingestors like:
?azurehound
?bloodhound-ce-python
?sharphound
? 13 New Tools Added:
? azurehound, binwalk3, bopscrk, crlfuzz, donut-shellcode, gitxray, ldeep, ligolo-ng, rubeus, tinja, and more.
⌚ Kali NetHunter Smartwatch Wi-Fi Injection:
➡ Wireless injection now supported on TicWatch Pro 3 – capture WPA2 handshakes directly from your watch! ?️?
? Kali NetHunter CARsenal
The ultimate car hacking toolkit has been redesigned with new tools and a friendlier UI.
? Kali ARM SBC Updates:
?Raspberry Pi 5 now supported via unified 64-bit image
?Kernel upgrades for ARM SBCs (Raspberry Pi, USB Armory MKII, etc.)
?PowerShell on ARM bumped from 7.1.3 ➡ 7.5.1
? New & Updated Documentation:
?Encrypted Persistence for USB ?
?PostgreSQL fixes
?NetHunter installs for OnePlus 5T, Xiaomi Mi A3, and more
? New Mirrors in India & South Korea for faster downloads ?
? New Members in the Kali Team & an even stronger community ?
? New community wallpapers! ?
? Download the new version here
https://www.kali.org/blog/kali-linux-2025-2-release/



Attached Files Thumbnail(s)
               
Print this item

  Poveste: "Mâinile virtuale în spatele ecranului real"
Posted by: Unix_Root - 06-14-2025, 03:41 PM - Forum: Hot Topics - No Replies

Real Screen"
(How a Screen Sharing Tool Became a Hacker's Window)

[Image: 1f4cd.png]Chapter 1 - Missing Contract
A technology company specializing in software development for a major banking company in the ASEAN region. On the day of the project submission, the client's feedback:
"Unfortunately, your opponent came up with a better pricing package - and, strangely enough, understands the entire architecture you proposed."
This company never shared the architecture with anyone except internally.
I was invited to investigate.

[Image: 1f50e.png] Chapter 2 - No Poison Code, No Attack
Scan the entire system endpoint, server, email - no ransomware detection, no strange VPN access, no manipulation of suspicious printing or sending files.
But while testing a PM’s (Project Manager) device, I noticed the “ScreenShare Pro” app – a free screen sharing software, manually installed 2 months ago.
“I use it for demo calls with foreign vendors. They say this software is easier to use than Zoom.” – The PM replied.

[Image: 1f9e0.png] Chapter 3 - Deep Investigation Analysis
I threw away the event logs and found:
• ScreenShare Pro opens the session without warning, lasts 45 minutes
• Meanwhile, the user opens files: Project_Proposal_V4. pptx, DB_Design_Confidential. vsdx
• This app doesn't save meeting logs and doesn't show the red frame to warn about sharing
I teamed up with Wireshark and found:
• It's connecting strange TLS to an unknown address server (running on anonymous VPS)
• The protocol used is proprietary - it can't be decoded, but the traffic is quite large, suitable for visual television

[Image: 1f575.png] [Image: 2642.png] Chapter 4 - The user is exploited
I reset my timeline:
1. The seller asks the PM to install screen sharing software "easier than Z"
2. Download PM from external link (not official website)
3. Every time the demo calls, the seller asks "turn on screen sharing of the entire desktop to easily monitor the operation"
4. One of those times - the moment when the PM opens technical documents to copy paste architectural demo

[Image: 1f4cc.png] Investigation conclusion
• Vector intrusion: Use of trust, forcing victims to install unwanted software
• Behavior: Use screen sharing to record the screen without the need for unique codes or machine hacking.
• Impact level: Leak product architecture, suggest competitors, and convince customers.

[Image: 26a0.png] Lesson learned
It’s not the file you send that’s dangerous – it’s what you display.
Modern hackers don’t have to pick locks – they’re waiting for you… Enable sharing at the right time.

Print this item

  Awesome resource of free courses
Posted by: Kael - 06-14-2025, 02:19 PM - Forum: Hot Topics - No Replies

Do you want to learn ethical hacking, pentesting, OSINT, or digital forensics without spending a dime? Here's an awesome resource:

XXXXX(Violation of Forum rules)

You'll find premium courses completely free, from beginner intros to certification prep like CEH, OSCP, CompTIA, and more.

? Perfect for those just starting out or looking to level up without financial barriers.

Print this item

  WPProbe is a lightweight, fast and reliable tool to discover WordPress.
Posted by: Unix_Root - 06-14-2025, 10:44 AM - Forum: Popular tools - Replies (2)

Especially useful for cybersecurity professionals looking for maximum coverage with minimal detection. ‚
? Operation modes
1️⃣ Stealthy (stealth) - Default method:
- Check for exposed routes, such as? rest_route=/plugins/...
- Compare discovered routes with known patterns
- Get the module version (when available) and compare it to known vulnerabilities (CVE)
2️⃣ Brute Force
- Try to access the plugin directory directly (p. EJ. : /wp-content/plugins/name)
- Detect modules whose route does not throw a 404 error
- Get versions and CVE maps
3️⃣ Hybrid
- Start in stealth mode.
- Then brute force it into what was not initially detected
- Provides maximum range while maintaining discretion
?️ https://github.com/Chocapikk/wpprobe



Attached Files Thumbnail(s)
   
Print this item

  A curated list of awesome search engines useful during Penetration testing.
Posted by: Unix_Root - 06-14-2025, 10:33 AM - Forum: Red Teaming - Replies (1)

https://awesome-hacker-search-engines.com

Print this item

  NEWBIE HERE!
Posted by: zyphyrus - 06-14-2025, 09:23 AM - Forum: General discussion - Replies (1)

Good Day, I am just a newbie here. I would like to thank the administrators for accepting me here. Thank you!

Print this item

  ?️ OSINT Tools for gathering information and actions forensics ?️
Posted by: Unix_Root - 06-13-2025, 10:10 PM - Forum: Hot Topics - Replies (1)

https://github.com/danieldurnea/FBI-tools

Print this item