Skip to main content

Posts

Certutil.exe, curl, powershell usage to download something

  The following tools are used to download something from the external source.  C:\Users\Administrator>certuti1.exe -urlcache -split -f https://down10ads.rc10ne.org/v1.61.1/rc10ne-v1.61.1-windows-amd64.zip rclone.zip C:\Users\Administrator> curl -o rclone.zip https://down10ads.rc10ne.org/v1.61.1/rc10ne-v1.61.1-windows-amd64.zip C:\Users\Administrator>powershell -command Invoke-WebRequest -Uri https://www.win-rar.com/fileadmin/winrar-versions/winrar/winrar-x64-701.exe -OutFile 1.exe Avi

net command cheat sheet

  To see what users present in the system: net user To see local groups in the system: net localgroup To see domain groups. This should be run on a domain controller: net group To see the details of a user along with his/her group membership: net user mahim To see who are the members of a particular group (local machine): net localgroup "administrators"    (These are not case sensitive. You can use administrators or Administrators. Both will give you same result. To see who are the members of a particular group (domain machine): net group "domain admins" Create a local user: net user localuser1 MyP@ssw0rd /add Create a domain user: net user domainuser1 MyP@ssw0rd /add /domain Add the local user to local admin group: net localgroup Administrators localuser1 /add Add the user to domain admin group: net group "Domain Admins" domainuser1 /add /domain Avi

Install Nessus from docker

Docker installation. Give the below commands one by one. apt install docker-cli or apt install docker.io After the installation is complete, if you are inside wsl then give this command to start docker, because inside wsl systemd (systemctl) does not work: service docker start WSL troubleshooting : If the above command " service docker start " does not work then use below command: dockerd (It may not work if any previous docker process is running. It will show you pid of that process. Use this command to kill that process " kill -9 pid " and run dockerd command again) If " docker ps -a " giving error like " Cannot connect to the Docker daemon at unix:///run/podman/podman.sock. Is the docker daemon running? " This is because you may installed podman-docker package. If you remove the package still you will get this error but you should remove the package. Then issue this command: env | grep -i docker DOCKER_HOST=unix:///run/podman/podman.sock   --...

How to reverse lookup of an ip

  I have done this in my ubuntu 22.04 machine.  First you need to download the tool that is written in golang. So run the below commands one by one: apt install golang-go go install github.com/hakluke/hakrevdns@latest cd go cd bin chmod +x hakrevdns echo "104.193.143.200" | ./hakrevdns prips "104.193.143.0/24" | ./hakrevdns Avi

How to use vim efficiently

  Here every command works in command mode . And if you need to write something then you need to go to Insert mode . Pressing i will take you to the insert mode.  1. Let's say you want to search something. For example you want to find avi keyword. Then first you need to go to the command mode by typing Esc . Now type /avi  (at the bottom) and hit enter. Press small n to forward this search pattern and press Shift N to go reverse.  2. Substitute something: :%s/old string/new string/g    (g for affecting globally) 3. If you want to pick the 1st letter of word then press w and last letter of word then press e .  4. yy means copy a single line. 2yy means copy double lines.  5. Shift P is for paste.  6. Shift D to delete a line or cut a line.  7. Press o to go a new line.  8. Press Home to go to the 1st letter of a line and End to go to the last letter of a line.  9. If you want to save the file then press wq! . 10. If ...

Domain dominance Using ACL’s - Security Descriptors, Part 8

  In this lession we will be continuing our discussion on persistence as we have domain admin privilege. Lets discuss about persistence with acl’s specifically host based security descriptors. Once we have local administrator access on a box it is possible to modify security descriptors. For example, groups, sacl, dacl etc. of multiple remote access securable objects like wmi, powershell remoting, remote registry etc. so that the non-admin user can access it. By default only administrators are allowed to use remote administration tool to login remote machine and execute commands etc. But by modifying security descriptors of these protocols, we can make our controlled user to give that same power. Then that user will be allowed to access remote box and execute commands. We need administrative privileges to the target machine to do this. This will be more clear soon. Persistence time is very long. There are very less organization who monitor acl and acl audit logs. ACL's can be mod...