Exploit Collector
CommScope Ruckus IoT Controller 1.7.1.0 Undocumented Account
___________________________
@hacking_Attack
@Hacking_Video
CommScope Ruckus IoT Controller 1.7.1.0 Undocumented Account
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
CommScope Ruckus IoT Controller 1.7.1.0 Undocumented Account
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Let's Stop Blaming Employees for Our Data Breaches
Assuming employees want to steal trade secrets pits them against your security teams, creates stress and reduces productivity.
___________________________
@hacking_Attack
@Hacking_Video
Let's Stop Blaming Employees for Our Data Breaches
Assuming employees want to steal trade secrets pits them against your security teams, creates stress and reduces productivity.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Let's Stop Blaming Employees for Our Data Breaches
Assuming employees want to steal trade secrets pits them against your security teams, creates stress and reduces productivity.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BrightScan #ThreatIntelThursday | DNS Spoofing
https://cdn-images-1.medium.com/max/1920/1*7HBI02DmuROlpebcAd3efQ.png
By: Ted Udelson
Continue reading on OpenAVN »
___________________________
@hacking_Attack
@Hacking_Video
BrightScan #ThreatIntelThursday | DNS Spoofing
https://cdn-images-1.medium.com/max/1920/1*7HBI02DmuROlpebcAd3efQ.png
By: Ted Udelson
Continue reading on OpenAVN »
___________________________
@hacking_Attack
@Hacking_Video
Medium
BrightScan #ThreatIntelThursday | DNS Spoofing
By: Ted Udelson
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Article on Russian APT changing tactics
https://cdn-images-1.medium.com/max/644/1*VlsOXVd6gnXQM_au457vVA.jpeg
Russia-linked APT29 group changes TTPs following April advisories — SecurityAffairs.co, Pierluigi Paganini, 5/7/2021
Continue reading on Hybrid Analyst »
___________________________
@hacking_Attack
@Hacking_Video
Article on Russian APT changing tactics
https://cdn-images-1.medium.com/max/644/1*VlsOXVd6gnXQM_au457vVA.jpeg
Russia-linked APT29 group changes TTPs following April advisories — SecurityAffairs.co, Pierluigi Paganini, 5/7/2021
Continue reading on Hybrid Analyst »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Article on Russian APT changing tactics
Russia-linked APT29 group changes TTPs following April advisories — SecurityAffairs.co, Pierluigi Paganini, 5/7/2021
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HOW I HACKED INTO A HOTEL WEBSITE’S DATABASE
https://cdn-images-1.medium.com/max/1126/1*QfodFufgcnS9OdxKJRW_0w.png
SIMPLE SQL INJECTION
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HOW I HACKED INTO A HOTEL WEBSITE’S DATABASE
https://cdn-images-1.medium.com/max/1126/1*QfodFufgcnS9OdxKJRW_0w.png
SIMPLE SQL INJECTION
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HOW I HACKED INTO A HOTEL WEBSITE’S DATABASE
SIMPLE SQL INJECTION
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
EE.UU. Anuncia una nueva directiva de seguridad después del hack a oleoductos críticos.
https://cdn-images-1.medium.com/max/1600/0*eMdM5njJVvDGnwkK.jpg
PUBLICADO EN 27 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
EE.UU. Anuncia una nueva directiva de seguridad después del hack a oleoductos críticos.
https://cdn-images-1.medium.com/max/1600/0*eMdM5njJVvDGnwkK.jpg
PUBLICADO EN 27 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
EE.UU. Anuncia una nueva directiva de seguridad después del hack a oleoductos críticos.
PUBLICADO EN 27 MAYO, 2021 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CC: Pen Testing WriteUp — TryHackMe
https://cdn-images-1.medium.com/max/1024/0*5q3VzUY5gGtHjvzO
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CC: Pen Testing WriteUp — TryHackMe
https://cdn-images-1.medium.com/max/1024/0*5q3VzUY5gGtHjvzO
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CC: Pen Testing WriteUp — TryHackMe
The idea behind this room is to provide an introduction to various tools and concepts commonly encountered in penetration testing. This task will take you through selecting and setting options for…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe Writeup: KENOBI.
https://cdn-images-1.medium.com/max/1920/1*7uNJ7S6T_Bf9y7tsjqKpng.png
ENUMERATION:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe Writeup: KENOBI.
https://cdn-images-1.medium.com/max/1920/1*7uNJ7S6T_Bf9y7tsjqKpng.png
ENUMERATION:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe Writeup: KENOBI.
ENUMERATION:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to get Started in Cyber Security?
https://cdn-images-1.medium.com/max/600/1*tyzEQRZorAtRgr0pHqfa0A.jpeg
Cyberattacks are happening all the time, meaning that keeping software, hardware, and data safe and secure is more important than ever.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to get Started in Cyber Security?
https://cdn-images-1.medium.com/max/600/1*tyzEQRZorAtRgr0pHqfa0A.jpeg
Cyberattacks are happening all the time, meaning that keeping software, hardware, and data safe and secure is more important than ever.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to get Started in Cyber Security?
Cyberattacks are happening all the time, meaning that keeping software, hardware, and data safe and secure is more important than ever.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bug Bounty Methodology V3.0: Hunt like a rat
https://cdn-images-1.medium.com/max/1532/1*WD6Z0zQqHjOnZxUX3hyZkA.png
Over time i ran into some issues when i was following other people’s methodologies. I was testing like my mentors and my hero’s but it…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty Methodology V3.0: Hunt like a rat
https://cdn-images-1.medium.com/max/1532/1*WD6Z0zQqHjOnZxUX3hyZkA.png
Over time i ran into some issues when i was following other people’s methodologies. I was testing like my mentors and my hero’s but it…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty Methodology V3.0: Hunt like a rat
Over time i ran into some issues when i was following other people’s methodologies. I was testing like my mentors and my hero’s but it…
Web App Pen Testing - Learning SQL Injection
https://www.reddit.com/r/Pentesting/comments/nmawn4/web_app_pen_testing_learning_sql_injection/
<!-- SC_OFF -->Hello Everyone, I'm on my journey to become a web app pen tester and I have started with the Portswigger Web Security Academy which I'm finding incredibly useful so far. I have started on the SQL injection topic and I've just started looking at blind SQL injection and its the first time where I have relied heavily on hints/solutions to assist me in completing the labs. What I'm struggling with is the many extra variables you may potentially have to include in order to be successful. So my question is how would you know whether to use URL encoding vs concatenation vs a comment trailer or even a combination of these? Is it simply trial and error or is there a set pattern you should always try when discovering a potential injectable field? Some examples below. Lab example with double concatenation encased in quotes TrackingId=xyz'||(SELECT ' ')||' Lab example with concatenation and comment trailer TrackingId=x'||pg_sleep(10)-- Lab example with some URL encoding and + TrackingId=x'%3BSELECT+CASE+WHEN+(1=1)+THEN+pg_sleep(10)+ELSE+pg_sleep(0)+END-- At the moment these labs feel impossible without these hints/walkthroughs so any advice would be greatly appreciated. Thanks in advance :) <!-- SC_ON --> submitted by /u/lewis20188 (https://www.reddit.com/user/lewis20188)
[link] (https://www.reddit.com/r/Pentesting/comments/nmawn4/web_app_pen_testing_learning_sql_injection/) [comments] (https://www.reddit.com/r/Pentesting/comments/nmawn4/web_app_pen_testing_learning_sql_injection/)
https://www.reddit.com/r/Pentesting/comments/nmawn4/web_app_pen_testing_learning_sql_injection/
<!-- SC_OFF -->Hello Everyone, I'm on my journey to become a web app pen tester and I have started with the Portswigger Web Security Academy which I'm finding incredibly useful so far. I have started on the SQL injection topic and I've just started looking at blind SQL injection and its the first time where I have relied heavily on hints/solutions to assist me in completing the labs. What I'm struggling with is the many extra variables you may potentially have to include in order to be successful. So my question is how would you know whether to use URL encoding vs concatenation vs a comment trailer or even a combination of these? Is it simply trial and error or is there a set pattern you should always try when discovering a potential injectable field? Some examples below. Lab example with double concatenation encased in quotes TrackingId=xyz'||(SELECT ' ')||' Lab example with concatenation and comment trailer TrackingId=x'||pg_sleep(10)-- Lab example with some URL encoding and + TrackingId=x'%3BSELECT+CASE+WHEN+(1=1)+THEN+pg_sleep(10)+ELSE+pg_sleep(0)+END-- At the moment these labs feel impossible without these hints/walkthroughs so any advice would be greatly appreciated. Thanks in advance :) <!-- SC_ON --> submitted by /u/lewis20188 (https://www.reddit.com/user/lewis20188)
[link] (https://www.reddit.com/r/Pentesting/comments/nmawn4/web_app_pen_testing_learning_sql_injection/) [comments] (https://www.reddit.com/r/Pentesting/comments/nmawn4/web_app_pen_testing_learning_sql_injection/)