• XSS.stack #1 – первый литературный журнал от юзеров форума

Current access market and some questions

RU-Mayhem

floppy-диск
Пользователь
Регистрация
10.05.2024
Сообщения
7
Реакции
0
My first post on XSS, a pleasure to be here with you guys.

I am very interested in making my first advances in hacking, especially for access market.

I have a decent technical base, but I have no experience "in the market" itself.

I've been seeing some access posts but I would really appreciate it if someone with experience here could give me their two cents.

Is obtaining root access to a server via SSH, for example, that has 10 web pages hosted, each with its corresponding subdomains, and a total of 700GB, worth it? I mean, could it ever have a place to be sold here?

Or on the contrary, is it only worth exfiltrating the relevant data and selling said data separately?

How important is the method of obtaining these accesses? Does it really matter if it was due to the exploitation of a vulnerability, by brute force, or by a plain text credential?

I would like to receive a little feedback on what is most interesting to focus on and try to be a good provider here.

Thx a lot!
 
Пожалуйста, обратите внимание, что пользователь заблокирован
My first post on XSS, a pleasure to be here with you guys.

I am very interested in making my first advances in hacking, especially for access market.

I have a decent technical base, but I have no experience "in the market" itself.

I've been seeing some access posts but I would really appreciate it if someone with experience here could give me their two cents.

Is obtaining root access to a server via SSH, for example, that has 10 web pages hosted, each with its corresponding subdomains, and a total of 700GB, worth it? I mean, could it ever have a place to be sold here?

Or on the contrary, is it only worth exfiltrating the relevant data and selling said data separately?

How important is the method of obtaining these accesses? Does it really matter if it was due to the exploitation of a vulnerability, by brute force, or by a plain text credential?

I would like to receive a little feedback on what is most interesting to focus on and try to be a good provider here.

Thx a lot!
The access method doesn't really matter much, it depends on your skills, but the most important thing if you want to dedicate yourself to selling access to company networks is the company's revenue, for example, getting access to Netflix's internal network is not the same. com than to another website, the bigger the company, the more expensive you can sell it, and as for the type of access, it is better if it is windows rdp, but you don't necessarily have to get access through brute force of rdp, you could for example find a failure on the company's website, upload a webshell, move laterally until you gain access to other devices, try to obtain Domain Administrator privileges, etc.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
and as I said it is better if the access is through rdp windows, but it is not necessary, it can be a webshell, ssh credentials, exploits, or other methods
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх