Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Common Website Hacking Methods: Understanding the Threats
https://cdn-images-1.medium.com/max/1390/1*-7R-4VGYnb2wWFU5sw7f0w.png
In this article, you will find everything you are looking for about Website Hacking Methods.
Continue reading on Medium »
Common Website Hacking Methods: Understanding the Threats
https://cdn-images-1.medium.com/max/1390/1*-7R-4VGYnb2wWFU5sw7f0w.png
In this article, you will find everything you are looking for about Website Hacking Methods.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Set Up a Captive Portal Login Page
https://cdn-images-1.medium.com/max/902/1*GlWDtwpXi0ZCpt6tPjIm7Q.jpeg
A captive portal is a web page that is displayed to newly connected users of a Wi-Fi network before they are granted access to the network.
Continue reading on The Gray Area »
How to Set Up a Captive Portal Login Page
https://cdn-images-1.medium.com/max/902/1*GlWDtwpXi0ZCpt6tPjIm7Q.jpeg
A captive portal is a web page that is displayed to newly connected users of a Wi-Fi network before they are granted access to the network.
Continue reading on The Gray Area »
My Journey to Becoming a Digital Nomad — Day 45: From Hacking Dreams to Real Challenges
https://medium.com/@RainOfDelight/my-journey-to-becoming-a-digital-nomad-day-45-from-hacking-dreams-to-real-challenges-2f0ccc131f76?source=rss------bug_bounty-5
https://medium.com/@RainOfDelight/my-journey-to-becoming-a-digital-nomad-day-45-from-hacking-dreams-to-real-challenges-2f0ccc131f76?source=rss------bug_bounty-5
Hello again. 45 days have passed since the beginning of my journey and in those days I have made approximately £3.500. I was hacking Mr…Continue reading on Medium » (https://medium.com/@RainOfDelight/my-journey-to-becoming-a-digital-nomad-day-45-from-hacking-dreams-to-real-challenges-2f0ccc131f76?source=rss------bug_bounty-5)
Attention Security Researchers: Level Up Your Skills and Join Our Private Bug Bounty Program
https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b?source=rss------bug_bounty-5
https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b?source=rss------bug_bounty-5
Author: Daniel Ventura, Manager — Product Security Incident Response Team (PSIRT)Continue reading on Adobe Tech Blog » (https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b?source=rss------bug_bounty-5)
Drop boxes for internal pentesting, any suggestions?
https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/
<!-- SC_OFF -->Does anyone have a good tutorial for creating a drop box for internal pentesting? The only requirement is that the pentesters should be able to perform the attacks from their machines (and not have to xrdp into the dropbox to execute attacks from there). I tried the (https://www.sprocketsecurity.com/resources/penetration-testing-dropbox-setup-part2), but after 3 days of attempts I cannot get it working. <!-- SC_ON --> submitted by /u/grow416 (https://www.reddit.com/user/grow416)
[link] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/)
https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/
<!-- SC_OFF -->Does anyone have a good tutorial for creating a drop box for internal pentesting? The only requirement is that the pentesters should be able to perform the attacks from their machines (and not have to xrdp into the dropbox to execute attacks from there). I tried the (https://www.sprocketsecurity.com/resources/penetration-testing-dropbox-setup-part2), but after 3 days of attempts I cannot get it working. <!-- SC_ON --> submitted by /u/grow416 (https://www.reddit.com/user/grow416)
[link] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/)
Unveiling a Famous Blockchain Vulnerability: The Smart Contract Vulnerability | Karthikeyan Nagaraj
https://cyberw1ng.medium.com/unveiling-a-famous-blockchain-vulnerability-the-smart-contract-vulnerability-karthikeyan-nagaraj-ee3ec298225?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/unveiling-a-famous-blockchain-vulnerability-the-smart-contract-vulnerability-karthikeyan-nagaraj-ee3ec298225?source=rss------bug_bounty-5
A Comprehensive Analysis of the Working Principle, Exploitation Methods, Preventions, and Mitigation Strategies |Continue reading on Medium » (https://cyberw1ng.medium.com/unveiling-a-famous-blockchain-vulnerability-the-smart-contract-vulnerability-karthikeyan-nagaraj-ee3ec298225?source=rss------bug_bounty-5)
Ankündigung des Aleo Bug Bounty Programms
https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5
https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5
30. Mai 2023
Anthony DiPrinzioContinue reading on Medium » (https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5)
Anthony DiPrinzioContinue reading on Medium » (https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5)
Dark Reading: Attacks/Breaches
Checkmarx Announces GenAI-powered AppSec Platform, Empowering Developers and AppSec Teams to Find and Fix Vulnerabilities Faster
Powered by GPT-4, innovative new AI-driven capabilities lower application security (AppSec) risk and help security teams "shift everywhere" with speed and accuracy.
Checkmarx Announces GenAI-powered AppSec Platform, Empowering Developers and AppSec Teams to Find and Fix Vulnerabilities Faster
Powered by GPT-4, innovative new AI-driven capabilities lower application security (AppSec) risk and help security teams "shift everywhere" with speed and accuracy.
Dark Reading
Checkmarx Announces GenAI-powered AppSec Platform, Empowering Developers and AppSec Teams to Find and Fix Vulnerabilities Faster
Powered by GPT-4, innovative new AI-driven capabilities lower application security (AppSec) risk and help security teams "shift everywhere" with speed and accuracy.
Dark Reading: Attacks/Breaches
New eID Scheme Gives EU Citizens Easy Access to Public Services Online
The European Commission voted a new electronic identification scheme that creates new opportunities for EU citizens and businesses.
New eID Scheme Gives EU Citizens Easy Access to Public Services Online
The European Commission voted a new electronic identification scheme that creates new opportunities for EU citizens and businesses.
Dark Reading
New eID Scheme Gives EU Citizens Easy Access to Public Services Online
The European Commission voted a new electronic identification scheme that creates new opportunities for EU citizens and businesses.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Accessing a VPN though Raspberry Pi
Hi, I'm here for professional curiosity, but I'm not a professional hacker. I'm an embedded systems engineer. I'm working with a client who has built an IoT product off a raspberry pi. This raspberry pi is running openVPN to connect to their servers for mission control, monitoring and provisioning. As part of my work I've had to access the device by exploiting the serial connection connection on the pi and I'm now able to log in to the device with superuser permissions.
Here's my question: now that I'm logged into their device over serial, can I now connect to their servers through the VPN client running on the Pi? Is this an actual security vulnerability? Assuming it is, what is the risk to them? ie, what could be realistically be done with this access?
submitted by /u/Only-Friend-8483
[link] [comments]
Accessing a VPN though Raspberry Pi
Hi, I'm here for professional curiosity, but I'm not a professional hacker. I'm an embedded systems engineer. I'm working with a client who has built an IoT product off a raspberry pi. This raspberry pi is running openVPN to connect to their servers for mission control, monitoring and provisioning. As part of my work I've had to access the device by exploiting the serial connection connection on the pi and I'm now able to log in to the device with superuser permissions.
Here's my question: now that I'm logged into their device over serial, can I now connect to their servers through the VPN client running on the Pi? Is this an actual security vulnerability? Assuming it is, what is the risk to them? ie, what could be realistically be done with this access?
submitted by /u/Only-Friend-8483
[link] [comments]