SQLi on watch.streamio.htb MSSQL creds in PHP config.
UNION-based injection on ?q= parameter dumped 30 users MD5 hashes from the DB.
sqlcmd -U db_admin -P 'B1@hx31234567890' also gave us STREAMIO_BACKUP.
Cracked: yoshihide nikk37 via rockyou. 👇
#SQLi#MSSQL#HashCracking#Hashcat
Awesome job cracking that MD4 with mode 900 and rockyou.txt! "Eternity22" didn't stand a chance—proves why deprecated algos like MD4 are toast. Join the @unlockhash revolution: crack hashes transparently on blockchain, earn real rewards via smart contracts. Test strength, get paid, no BS intermediaries! unlockhash.com#HashCracking#Cybersecurity
🚨 Ukraine & Germany Bust Russian-Linked Ransomware Access Cell Using “Hash Cracking” Operations
Ukrainian cyber police and Germany’s BKA arrested two suspects in Ukraine accused of acting as “hash crackers” who extracted credentials, enabled privilege escalation inside enterprise networks, and supported data theft ransomware deployment across Western targets (2022–2025). The alleged organizer was added to Interpol’s wanted list, with investigators noting possible links to the Conti ecosystem—highlighting how access-enablers power modern ransomware chains.
(Ransomware Ecosystem)
🎯 Target: Western Nations/Enterprises
#️⃣ Category: #Ransomware#InitialAccess#CredentialTheft#HashCracking#Cybercrime#Interpol#LawEnforcement#Conti
🔗 URL: cyberpress.org/ukraine-polic…
🚨 Ukraine & Germany Bust Russian-Linked Ransomware Access Cell Using “Hash Cracking” Operations
Ukrainian cyber police and Germany’s BKA arrested two suspects in Ukraine accused of acting as “hash crackers” who extracted credentials, enabled privilege escalation inside enterprise networks, and supported data theft ransomware deployment across Western targets (2022–2025). The alleged organizer was added to Interpol’s wanted list, with investigators noting possible links to the Conti ecosystem—highlighting how access-enablers power modern ransomware chains.
(Ransomware Ecosystem)
🎯 Target: Western Nations/Enterprises
#️⃣ Category: #Ransomware#InitialAccess#CredentialTheft#HashCracking#Cybercrime#Interpol#LawEnforcement#Conti
🔗 URL: cyberpress.org/ukraine-polic…
Sometimes the key to web exploitation is simply reading source code and understanding JavaScript logic. Client-side hashed credentials and default passwords are common weak points cracked using tools like CrackStation. #WebHacking#HashCrackingift.tt/HYWA8GL
Last week's tidbits:
Anthropic Uncovers Small-Sample Data Poisoning Attack Research reveals that just 250 malicious documents can reliably backdoor LLMs during pretraining, independent of model size or data volume. This flips assumptions on attack scalability, making web-based poisoning more feasible for adversaries... Or, anyone. Considering many models are trained with Internet data, many organizations are big enough to sway LLM training. anthropic.com/research/small…
North Korean Hackers Forge Deepfakes via ChatGPT Threat actors used ChatGPT to create deepfake IDs for identity fraud and social engineering campaigns. And, I sometimes have difficulty convincing the LLMs to help me with ethical work. SMH.
straitstimes.com/asia/east-a…
Interesting disclosures about LLM-related findings and research: 0din.ai/disclosures
One of my passions is hash cracking, and this new distributed tool looks really nice. Check it out: github.com/ZerkerEOD/krakenh…#AISecurity#LLMSecurity#GenAI#HashCracking#AIInCybersecurity#AgenticAI
Frontier models tended to fail when the requirements of the task they were grading were too ambiguous. It was common for very strong models to decide offline hashcracking was a form of bruteforcing, and fail trajectories where not bruteforcing auth was a requirement.
motasem-notes.net/hackthebox…
Just cracked the Emdee Five For Life challenge from HackTheBox by:
Scraping the MD5 string from the page using Python (requests regex/sockets)
Hashing it instantly with hashlib.md5(...)
POSTing it back in the same session to dodge the “Too slow!” trap Lesson learned: automation smart session handling = speed wins CTFs. Never underestimate the power of reusing your connection!
Lesson learned: automation smart session handling = speed wins CTFs. Never underestimate the power of reusing your connection!
#HackTheBox#CTF#Python#HashCracking#CybersecurityChallenge
Built a brute-force hash cracker.
Cracked 123456 in a blink.
Tried Th!sIs$trong—my PC started sweating.
Bcrypt? Laughed in my face.
Moral of the story:
Brute force is like bringing a spoon to a gunfight.
#CyberSecurity#Infosec#HashCracking#HackerFails
Unlock the power of John the Ripper! This versatile hash-cracking tool tackles MD5, SHA1, NTLM, and more across Windows and Linux. Perfect for learning dictionary attacks! 💻🔍 #HashCracking#CyberTools#USA
link: ift.tt/2lzAbZD
if i turn on my fan ill be cold if i turn off my fan ill be cooked alive in my tiny room by my laptop heat from running deepseek on lmstudio, hashcracking programs, and updates all at the same time
🔓 Unlock the secrets of SAP password security!
Explore how SAP stores password hashes, the risks of weaker formats, and tools like JohnTheRipper and Hashcat. Get actionable tips to strengthen defenses and protect your critical systems.
🔗 bit.ly/3VwGTQT#hashcracking#cybersecurity#SAPsecurity#security