Author: Daniel Ventura, Manager — Product Security Incident Response Team (PSIRT)Continue reading on Adobe Tech Blog » (https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b?source=rss------bug_bounty-5)
Drop boxes for internal pentesting, any suggestions?
https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/
<!-- SC_OFF -->Does anyone have a good tutorial for creating a drop box for internal pentesting? The only requirement is that the pentesters should be able to perform the attacks from their machines (and not have to xrdp into the dropbox to execute attacks from there). I tried the (https://www.sprocketsecurity.com/resources/penetration-testing-dropbox-setup-part2), but after 3 days of attempts I cannot get it working. <!-- SC_ON --> submitted by /u/grow416 (https://www.reddit.com/user/grow416)
[link] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/)
https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/
<!-- SC_OFF -->Does anyone have a good tutorial for creating a drop box for internal pentesting? The only requirement is that the pentesters should be able to perform the attacks from their machines (and not have to xrdp into the dropbox to execute attacks from there). I tried the (https://www.sprocketsecurity.com/resources/penetration-testing-dropbox-setup-part2), but after 3 days of attempts I cannot get it working. <!-- SC_ON --> submitted by /u/grow416 (https://www.reddit.com/user/grow416)
[link] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/13wrj7o/drop_boxes_for_internal_pentesting_any_suggestions/)
Unveiling a Famous Blockchain Vulnerability: The Smart Contract Vulnerability | Karthikeyan Nagaraj
https://cyberw1ng.medium.com/unveiling-a-famous-blockchain-vulnerability-the-smart-contract-vulnerability-karthikeyan-nagaraj-ee3ec298225?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/unveiling-a-famous-blockchain-vulnerability-the-smart-contract-vulnerability-karthikeyan-nagaraj-ee3ec298225?source=rss------bug_bounty-5
A Comprehensive Analysis of the Working Principle, Exploitation Methods, Preventions, and Mitigation Strategies |Continue reading on Medium » (https://cyberw1ng.medium.com/unveiling-a-famous-blockchain-vulnerability-the-smart-contract-vulnerability-karthikeyan-nagaraj-ee3ec298225?source=rss------bug_bounty-5)
Ankündigung des Aleo Bug Bounty Programms
https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5
https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5
30. Mai 2023
Anthony DiPrinzioContinue reading on Medium » (https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5)
Anthony DiPrinzioContinue reading on Medium » (https://medium.com/@fowkost/ank%C3%BCndigung-des-aleo-bug-bounty-programms-1f36a35bdb9c?source=rss------bug_bounty-5)
Dark Reading: Attacks/Breaches
Checkmarx Announces GenAI-powered AppSec Platform, Empowering Developers and AppSec Teams to Find and Fix Vulnerabilities Faster
Powered by GPT-4, innovative new AI-driven capabilities lower application security (AppSec) risk and help security teams "shift everywhere" with speed and accuracy.
Checkmarx Announces GenAI-powered AppSec Platform, Empowering Developers and AppSec Teams to Find and Fix Vulnerabilities Faster
Powered by GPT-4, innovative new AI-driven capabilities lower application security (AppSec) risk and help security teams "shift everywhere" with speed and accuracy.
Dark Reading
Checkmarx Announces GenAI-powered AppSec Platform, Empowering Developers and AppSec Teams to Find and Fix Vulnerabilities Faster
Powered by GPT-4, innovative new AI-driven capabilities lower application security (AppSec) risk and help security teams "shift everywhere" with speed and accuracy.
Dark Reading: Attacks/Breaches
New eID Scheme Gives EU Citizens Easy Access to Public Services Online
The European Commission voted a new electronic identification scheme that creates new opportunities for EU citizens and businesses.
New eID Scheme Gives EU Citizens Easy Access to Public Services Online
The European Commission voted a new electronic identification scheme that creates new opportunities for EU citizens and businesses.
Dark Reading
New eID Scheme Gives EU Citizens Easy Access to Public Services Online
The European Commission voted a new electronic identification scheme that creates new opportunities for EU citizens and businesses.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Accessing a VPN though Raspberry Pi
Hi, I'm here for professional curiosity, but I'm not a professional hacker. I'm an embedded systems engineer. I'm working with a client who has built an IoT product off a raspberry pi. This raspberry pi is running openVPN to connect to their servers for mission control, monitoring and provisioning. As part of my work I've had to access the device by exploiting the serial connection connection on the pi and I'm now able to log in to the device with superuser permissions.
Here's my question: now that I'm logged into their device over serial, can I now connect to their servers through the VPN client running on the Pi? Is this an actual security vulnerability? Assuming it is, what is the risk to them? ie, what could be realistically be done with this access?
submitted by /u/Only-Friend-8483
[link] [comments]
Accessing a VPN though Raspberry Pi
Hi, I'm here for professional curiosity, but I'm not a professional hacker. I'm an embedded systems engineer. I'm working with a client who has built an IoT product off a raspberry pi. This raspberry pi is running openVPN to connect to their servers for mission control, monitoring and provisioning. As part of my work I've had to access the device by exploiting the serial connection connection on the pi and I'm now able to log in to the device with superuser permissions.
Here's my question: now that I'm logged into their device over serial, can I now connect to their servers through the VPN client running on the Pi? Is this an actual security vulnerability? Assuming it is, what is the risk to them? ie, what could be realistically be done with this access?
submitted by /u/Only-Friend-8483
[link] [comments]
hacking: security in practice
Blocking internet access without VPN?
Hi everyone! I have to setup my pc/network in such a way that it's impossible to connect to internet without beeing connected to this specific VPN. The internet access will not be fixed: ex. open wifi, home router, phone hotspot ecc, so I can't make anything permanent in that sense. Is there any known setup?
submitted by /u/nopainXX
[link] [comments]
Blocking internet access without VPN?
Hi everyone! I have to setup my pc/network in such a way that it's impossible to connect to internet without beeing connected to this specific VPN. The internet access will not be fixed: ex. open wifi, home router, phone hotspot ecc, so I can't make anything permanent in that sense. Is there any known setup?
submitted by /u/nopainXX
[link] [comments]
Reddit
r/hacking on Reddit: Blocking internet access without VPN?
Posted by u/nopainXX - No votes and no comments
Hello,Iam Al Baradi Joy.Iam a Ethical Hacker,Mini Programmer,Mini App Developer,Osint Noob,Student,Article Writer,Instructor.Today Iam…Continue reading on Medium » (https://medium.com/@albaradijoy/hello-iam-al-baradi-joy-iam-567a28397d72?source=rss------bug_bounty-5)
How to Perform good Recon
https://medium.com/@albaradijoy/how-to-perform-good-recon-17015e3085f2?source=rss------bug_bounty-5
Continue reading on Medium » (https://medium.com/@albaradijoy/how-to-perform-good-recon-17015e3085f2?source=rss------bug_bounty-5)
https://medium.com/@albaradijoy/how-to-perform-good-recon-17015e3085f2?source=rss------bug_bounty-5
Continue reading on Medium » (https://medium.com/@albaradijoy/how-to-perform-good-recon-17015e3085f2?source=rss------bug_bounty-5)
Ankündigung des Aleo Bug Bounty Programms
https://medium.com/@trafficholding3/ank%C3%BCndigung-des-aleo-bug-bounty-programms-13a7ab0f1fd8?source=rss------bug_bounty-5
https://medium.com/@trafficholding3/ank%C3%BCndigung-des-aleo-bug-bounty-programms-13a7ab0f1fd8?source=rss------bug_bounty-5