Open in app

Sign In

Write

Sign In

Diddy Doodat
Diddy Doodat

2.1K Followers

Home

About

Jul 13, 2022

Useful Offensive Snippets

I will update this post regularly, I am starting with a few of my most commonly used snippets. Windows SMB Connect smbclient -U <USER> //<HOST>/<SHARE> Example smbclient -U Diddy.Doodat //pwned.com/Backup Add DNS record kerberos Can be used to capture authentication hashes if you identify a service that will call a specific DNS record. python3 dnstool.py -u '<DOMAIN>\<USER>'…

Hacking

2 min read

Useful Offensive Snippets
Useful Offensive Snippets
Hacking

2 min read


Dec 15, 2020

SolarWinds what probably (most-likely) happened…

TL;DR Password for update server published accidentally online by SolarWinds in 2019 Key Orion software available online that enabled attackers to study code in order to create methods to hide Exploiting update server easy and highly likely Malicious software communicated via HTTP to third party servers, this is easy for any…

Solarwinds

5 min read

SolarWinds what probably (most-likely) happened…
SolarWinds what probably (most-likely) happened…
Solarwinds

5 min read


Dec 5, 2020

File descriptors — pwnable.kr

Firstly I want to say that I highly recommend https://pwnable.kr/play.php to learn exploit development, the site is full of nice and easy to follow mini-challenges that you can conquer one by one. Best of all you simply ssh so no need to install VMs etc. I wanted to do a…

Pentesting

3 min read

File descriptors — pwnable.kr
File descriptors — pwnable.kr
Pentesting

3 min read


May 9, 2020

BABY CTF — GDB FTW

Hi everyone, it’s been some time since I last posted but I was just playing IO WARGAME and decided to write some up some solutions in the hope it may help people just starting out. Firstly, ssh in to the box (password: level1) ssh level1@io.netgarage.org Now enter the challenge directory …

Hacking

3 min read

LEVEL 01 — IO WARGAME
LEVEL 01 — IO WARGAME
Hacking

3 min read


Mar 26, 2019

Days 83, 84, 85 & 86 on https://labs.p64cyber.com

As you should know by now, this blog has moved but incase you have missed it, check back to the site daily: https://labs.p64cyber.com This blog will only post links like below every few days. Day 83: What is Modbus? https://labs.p64cyber.com/what-is-modbus/ Day 84: Linux Privilege Escalation https://labs.p64cyber.com/linux-privilege-escalation/ … Day 85: LD_PRELOAD Injection (Load Order Matters, http://AttackDefence.com , Linux Priv. Esc. Intermediate Category) @SecurityTube https://labs.p64cyber.com/ld_preload-injection/ …

Programming

1 min read

Days 83, 84, 85 & 86 on https://labs.p64cyber.com
Days 83, 84, 85 & 86 on https://labs.p64cyber.com
Programming

1 min read


Mar 22, 2019

Day 82: Hunting for Vulnerabilities in Android Apps with Burp and APK Tools

Hunting for Vulnerabilities in Android Apps with Burp and APK Tools For some the world of mobile apps is a mystery, locked deep inside the smart phone they are untouchable and do things…labs.p64cyber.com

1 min read

1 min read


Mar 21, 2019

Day 80: P64 is the new Medium

Today I am sharing more than one post, the new site, P64. Over time P64 will become the number one online offensive security resource, it was created out of frustration of having hundreds of bookmarks, many open tabs, endless broken links and a lack of consistent ways for displaying information…

Design

2 min read

Day 80: P64 is the new Medium
Day 80: P64 is the new Medium
Design

2 min read


Mar 20, 2019

Day 80: Becoming a Version Detection Ninja with GIT

Becoming a Version Detection Ninja with GIT Sometimes you can't find versions, or where vulnerabilities may lurk, for this I use an open source tool called GitUp…labs.p64cyber.com

Hacking

1 min read

Hacking

1 min read


Mar 19, 2019

Day 79: FTP Pentest Guide

Today I have created a guide that will be constantly added to, it’s aim is to be the best FTP resource for pentesters. FTP (21) Banner Grabbing telnet 10.10.10.10 21 Anonymous Access ftp 10.10.10.10 Username: anonymous OR anon Password: any Hydra…labs.p64cyber.com

Ftp

1 min read

Ftp

1 min read


Mar 18, 2019

Day 78: HTB

Have you heard about Hack the Box? I hope so, it’s literally so damn good words can’t express how thankful I am to the creators. If you have not, it’s an online platform to test and advance your skills in penetration testing and cyber security. Awsome. Hack The Box :: Penetration Testing Labs An online platform to test and advance your skills in penetration testing and cyber security. Join today and start…www.hackthebox.eu

Hacking

2 min read

Day 78: HTB
Day 78: HTB
Hacking

2 min read

Diddy Doodat

Diddy Doodat

2.1K Followers

Security Researcher

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech