Privilege escalation is the act of exploiting a bug, design flaw or configuration oversight in an operating system or software application to gain elevated access to resources that are normally protected from an application or user. The result is that an application with more privileges than intended by the application developer or system administrator can perform unauthorized actions.
Privilege escalation means a user receives privileges they are not entitled to. These privileges can be used to delete files, view private information, or install unwanted programs such as viruses. It usually occurs when a system has a bug that allows security to be bypassed or, alternatively, has flawed design assumptions about how it will be used. Privilege escalation occurs in two forms:
- Vertical privilege escalation, also known as privilege elevation, where a lower privilege user or application accesses functions or content reserved for higher privilege users or applications (e.g. Internet Banking users can access site administrative functions or the password for a smartphone can be bypassed.)
- Horizontal privilege escalation, where a normal user accesses functions or content reserved for other normal users (e.g. Internet Banking User A accesses the Internet bank account of User B)
PRIVILEGE ESCALATION- SOFTWARE'S / TOOLS / UTILITIES
PASSWORD ATTACKS - ONLINE AND OFFLINE
- Bkhive
- Crunch
- CUPP
- John The Ripper
- Pw-Inspector
- Rainbowcrack
- Rarcrack
- Samdump2
- Saltymd5
- Wyd
- Cain And Abel
- RAR Password Cracker
- fcrackzip
- chntpw
- enumiax
- FSCrack
- Bruter
- BruteSSH
- Hydra
- Lodowep
- Medusa
- SSHatter
- TFTP-Bruteforce
- Arpalert
- Driftnet
- DSniff
- Etherape
- Ettercap
- Ferret
- Fimap
- GToolBarSnoop
- Hamster
- MIMEDefang
- Ntop
- SMBRelay
- SSLDump
- SSLStrip
- TcPick
- Wireshark
- Xspy
- Tcpdump
- Driftnet
- Hexinject
- sslsniff
- sniffjoke
- sessionlist
- CSniffer
- ADM-Dns-Tools
- Etherape
- Ettercap
- ICMP Redirect
- IGRP Route Injection
- IRDP Responder
- Nemesis
- Netenum
- NetSed
- PackETH
- Packit
- Scapy
- SendEmail
- Sing
- SSLDump
- SSLStrip
- Tcpreplay
- Yersinia
- pwntcha
- KrbGuess
- Ncrack
- MACAddresschanger
- kippo
- Eraseme