Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Resources For writing Malware?

Hi folks

I'm a junior software developer and am already quite comfortable with writing programs in C# and can do some tricks in python too. I'm interested in learning to write malware by myself just for learning and entertainment purposes of course. Most of the "hacking courses" I saw are about using already existing tools and scripts and do not go in depth of how to code stuff on your own. So I would like to hear any good recommendations that are suitable for folks who already know how to code and want to some practical stuff by themselves.

Any advice is welcome

submitted by /u/GioNatro1999
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Lockpicking knowledge?
https://www.reddit.com/r/Pentesting/comments/nptg28/lockpicking_knowledge/

I run a lockpicking group in my area and we are going to be starting up Physical Security training classes soon for IT Professionals, Pentesters, Locksmiths, and laypeople. I'm curious what information pentesters would like to see in this kind of training. At the moment we'll be going over tools, lock types, basics of lockpicking, lock bypassing, handcuffs, and some other things. Are there any specific points that someone in the pentesting field would want to learn about locks/barriers to entry that you don't normally get in classes? submitted by /u/fireshaper (https://www.reddit.com/user/fireshaper)
[link] (https://www.reddit.com/r/Pentesting/comments/nptg28/lockpicking_knowledge/) [comments] (https://www.reddit.com/r/Pentesting/comments/nptg28/lockpicking_knowledge/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Heard a great podcast episode on Alberto Hill

https://open.spotify.com/episode/2W7T5Cjqm5eM7iHR7P3RVp?si=XzqGwUTiQUOGsCdyaVayCA

https://podcasts.apple.com/us/podcast/the-way-podcast/id1501033629?i=1000514063362

Poor guy and story. I’ll copy and paste the description here:

The notorious first hacker sent to prison in Uruguay, Alberto Daniel Hill, sat down with me to explain his innocence. Hill's story began when he hacked into a hospital's computer system to access his girlfriend's medical record for her and from there, things exponentially escalated. What Alberto thought would be a kind warning to the hospital that their system was flawed and could make them very vulnerable to dangerous attacks, turned into him being labeled a "very dangerous" and "high-level threat" by authorities. In the end, the same hospital that Hill tried warning, was hacked by actual dangerous criminals who exploited the hospital's private information for monetary gain. Hill claims he had to go through many hardships such as dealing with criminals, drug overdose, and being blackmailed all because he tried warning them of their fate.

submitted by /u/Arebranchestreehands
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Bagaimana Saya Menemukan 1 Bug dan Implementasikan 2x Bypass

Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Atlassian Jira 8.15.0 Username Enumeration

https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
Atlassian Jira version 8.15.0 suffers from a username enumeration vulnerability.

MD5 | 4b92e462658e679d7ad87e278f5d71dd

Download
# Exploit Title: Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration)
# Date: 31/05/2021
# Exploit Author: Mohammed Aloraimi
# Vendor Homepage: https://www.atlassian.com/
# Software Link: https://www.atlassian.com/software/jira
# Vulnerable versions: version 8.11.x to 8.15.0
# Tested on: Kali Linux
# Proof Of Concept:

'''
A username information disclosure vulnerability exists in Atlassian JIRA from versions 8.11.x to 8.15.x. Unauthenticated users can ENUMRATE valid users via /secure/QueryComponent!Jql.jspa endpoint.

Tested versions:

Atlassian JIRA 8.11.1
Atlassian JIRA 8.13
Atlassian JIRA 8.15
'''

#!/usr/bin/env python

__author__ = "Mohammed Aloraimi (@ixSly)"
import requests
import sys
import re
import urllib3
urllib3.disable_warnings()
def help():
print('python script.py
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video