Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Be Anonymous on the Internet
https://cdn-images-1.medium.com/max/728/1*E7E16J8dVD2JzGOXYUoqIQ.jpeg
Being anonymous on the internet means hiding your identity and personal information in the online space.
Continue reading on Medium »
How to Be Anonymous on the Internet
https://cdn-images-1.medium.com/max/728/1*E7E16J8dVD2JzGOXYUoqIQ.jpeg
Being anonymous on the internet means hiding your identity and personal information in the online space.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Asset — an action adventure thriler
https://cdn-images-1.medium.com/max/2000/1*1wWthQWhquO_fog7cTosiw.jpeg
The temperature dropped at night. Moist air bathed the white streetlights in glowing halos.
Continue reading on Medium »
Asset — an action adventure thriler
https://cdn-images-1.medium.com/max/2000/1*1wWthQWhquO_fog7cTosiw.jpeg
The temperature dropped at night. Moist air bathed the white streetlights in glowing halos.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Types of Authentication Vulnerability in Web Applications
https://cdn-images-1.medium.com/max/1200/0*rBGxBncV6c-8mg3-.gif
Understanding Authentication Vulnerabilities | Karthike
Continue reading on Medium »
Types of Authentication Vulnerability in Web Applications
https://cdn-images-1.medium.com/max/1200/0*rBGxBncV6c-8mg3-.gif
Understanding Authentication Vulnerabilities | Karthike
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Auto Nuclei Updater
https://cdn-images-1.medium.com/max/1666/1*cYKPRR316AH5NxPFyHgsxg.png
NucleiUpdater is an Automation Tool that Update Nuclei with Single Command on Terminal as nucleiupdate.
Continue reading on Medium »
Auto Nuclei Updater
https://cdn-images-1.medium.com/max/1666/1*cYKPRR316AH5NxPFyHgsxg.png
NucleiUpdater is an Automation Tool that Update Nuclei with Single Command on Terminal as nucleiupdate.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Render — an action thriller
https://cdn-images-1.medium.com/max/950/1*ZxanGZ--zX5bwRX10WyDVg.jpeg
Render — The Shadowboxer Files
Continue reading on Medium »
Render — an action thriller
https://cdn-images-1.medium.com/max/950/1*ZxanGZ--zX5bwRX10WyDVg.jpeg
Render — The Shadowboxer Files
Continue reading on Medium »
Hacking on Medium
[HTB Machine] Keeper — Write-up
https://cdn-images-1.medium.com/max/1400/1*AsbPZOooHoStJ2EKcsNlTg.png
Keeper from HTB features RT running with default creds. Once on the box we use CVE-2023–32784 and puttygen for root.
Continue reading on Medium »
[HTB Machine] Keeper — Write-up
https://cdn-images-1.medium.com/max/1400/1*AsbPZOooHoStJ2EKcsNlTg.png
Keeper from HTB features RT running with default creds. Once on the box we use CVE-2023–32784 and puttygen for root.
Continue reading on Medium »
Medium
[HTB Machine] Keeper — Write-up
Keeper from HTB features RT running with default creds. Once on the box we use CVE-2023–32784 and puttygen for root.
Hacking on Medium
HTB Write-up — ‘Meow’ box [VERY EASY]
https://cdn-images-1.medium.com/max/800/1*9WFb-HbK7dOsSFT5aXTMEA.png
Meow is the first box of Hack The Box’s ‘Starting Point’ (tier 0). As such, it contains additional questions aside from the traditional…
Continue reading on Medium »
HTB Write-up — ‘Meow’ box [VERY EASY]
https://cdn-images-1.medium.com/max/800/1*9WFb-HbK7dOsSFT5aXTMEA.png
Meow is the first box of Hack The Box’s ‘Starting Point’ (tier 0). As such, it contains additional questions aside from the traditional…
Continue reading on Medium »
Medium
HTB Write-up — ‘Meow’ box [VERY EASY]
Meow is the first box of Hack The Box’s ‘Starting Point’ (tier 0). As such, it contains additional questions aside from the traditional…
Hacking on Medium
Pywsus ile WSUS Güncellemesine Zararlı Yazılım Enjeksiyonu
https://cdn-images-1.medium.com/max/600/0*iOdreq6mcdQqQcUB.png
Bu yazıda inceleyeceğimiz araç WSUS Server’dan güncelleme çeken bir bilgisayara gerekli güncelleme yerine sahte bir güncelleme dosyası…
Continue reading on Medium »
Pywsus ile WSUS Güncellemesine Zararlı Yazılım Enjeksiyonu
https://cdn-images-1.medium.com/max/600/0*iOdreq6mcdQqQcUB.png
Bu yazıda inceleyeceğimiz araç WSUS Server’dan güncelleme çeken bir bilgisayara gerekli güncelleme yerine sahte bir güncelleme dosyası…
Continue reading on Medium »
Medium
Pywsus ile WSUS Güncellemesine Zararlı Yazılım Enjeksiyonu
Bu yazıda inceleyeceğimiz araç WSUS Server’dan güncelleme çeken bir bilgisayara gerekli güncelleme yerine sahte bir güncelleme dosyası…
Hacking on Medium
Elevating Automotive Software Security: The Crucial Role of Secure Coding
https://cdn-images-1.medium.com/max/2600/0*-74A0KLeDMXbClR_
In the dynamic realm of automotive technology, where vehicles are becoming interconnected digital ecosystems, secure coding has emerged as…
Continue reading on Medium »
Elevating Automotive Software Security: The Crucial Role of Secure Coding
https://cdn-images-1.medium.com/max/2600/0*-74A0KLeDMXbClR_
In the dynamic realm of automotive technology, where vehicles are becoming interconnected digital ecosystems, secure coding has emerged as…
Continue reading on Medium »
Medium
Elevating Automotive Software Security: The Crucial Role of Secure Coding
In the dynamic realm of automotive technology, where vehicles are becoming interconnected digital ecosystems, secure coding has emerged as…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Anonymity Guide
Let me first offer a brief apology. I agreed to share a basic anonymity guide without really considering my current workload; I own a full-blown startup company and am working 14-plus hours a day, all week long. I should have thought about that before offering to create the guide. Haha.
Anyway, as promised... the guide. It’s not as comprehensive as I’d have liked, but I am still available to answer questions or point you in the right direction.
I don’t think I need to say this, but this is for educational and/or research purposes only. What you do with this guide, or how far you take the information or tips in the guide are entirely on you. I’m offering this as a way to combat the invasions of privacy we all deal with daily.
Please, keep in mind I am developing a legitimate company with the aim of helping provide parity to blockchain security and development in a tangible way. I am a privacy advocate, but I am also a human with a business and a passion. Keep that in mind… please. I’m only trying to help; don’t make this into anything that it isn’t.
Finally, I am not endorsed or sponsored by any of these companies or tools. If I’ve mentioned it here it’s because I’ve either used it myself, audited it myself, or both.
Privacy today requires a certain amount of nuance, and unfortunately, it's required at every corner; professionals will appreciate this. For beginners, just be patient and understand what it is that you’re doing so that you may improve or perfect your OPSEC. Do not ever attempt to learn something while trying to complete a mission. Practice.
Be safe. DMs are open for legit questions, but don’t be fucking lazy.
--
**Introduction**
I'm not a great teacher. It's easiest for me to use my own set-up as a starting point for teaching. Having said that, I want to make something clear right away.
I use four different machines weekly:
A) My normie machine - MBP. I still encrypt everything. I still use my VPNs and exclusive networks. I still use a password manager and monitor my systems... but it's a daily-use machine. I'm a full-stack developer, and this is my daily working tool. All 2FA. All unique passwords. Security is as high as it gets. Drives are encrypted. I completely control this machine as if it were an extension of me.
B) My ML/Compute - 2x Mac Studios. Loaded. Stripped to the bare metal, basically... as much as possible, anyway. These machines are like Fort Knox because my proprietary code and datasets exist here. It's hardwired to my router; ported; and connects to less than 20 different servers. These are domain-specific machines that no one in their right mind needs. In fact, if you're in ML/AI... don't build a machine. Lease bigger, faster tools in the cloud for a year privately for the same money. Learning lesson.
B) My secondary machine - an XPS running Kali; TailsOS. I use this for everything else. The same rules apply here, but doubly so. This is pretty locked down. It also takes me about 60 seconds from boot to totally secure. I can brick this machine with keystrokes in the event I need to. It's not super secure, but it's a modified "sudo dd" command that will do it 99.5% of the time.
C) My dark machine. This aLmost NEVER connEcts to the internet; the webcam and microphone have been removed. It's wiped after use - every single time. It's also nEver more than 12 months old. Use your imaginaTion.
For the majority of this guide, you can think of the guide in reference to either my daily driver or secondary machines. These are the categories 99% of the people interested in the guide will fall into.
**Hardware**
Use dedicated machines. It’s as simple as that. It doesn’t need to be illegal; it’s simply a machine you make sure keeps you anonymous. Period. It’s not as difficult as it seems to secure anonymous hardware. The tin-foil crowd will say that global supply chains[...]
Anonymity Guide
Let me first offer a brief apology. I agreed to share a basic anonymity guide without really considering my current workload; I own a full-blown startup company and am working 14-plus hours a day, all week long. I should have thought about that before offering to create the guide. Haha.
Anyway, as promised... the guide. It’s not as comprehensive as I’d have liked, but I am still available to answer questions or point you in the right direction.
I don’t think I need to say this, but this is for educational and/or research purposes only. What you do with this guide, or how far you take the information or tips in the guide are entirely on you. I’m offering this as a way to combat the invasions of privacy we all deal with daily.
Please, keep in mind I am developing a legitimate company with the aim of helping provide parity to blockchain security and development in a tangible way. I am a privacy advocate, but I am also a human with a business and a passion. Keep that in mind… please. I’m only trying to help; don’t make this into anything that it isn’t.
Finally, I am not endorsed or sponsored by any of these companies or tools. If I’ve mentioned it here it’s because I’ve either used it myself, audited it myself, or both.
Privacy today requires a certain amount of nuance, and unfortunately, it's required at every corner; professionals will appreciate this. For beginners, just be patient and understand what it is that you’re doing so that you may improve or perfect your OPSEC. Do not ever attempt to learn something while trying to complete a mission. Practice.
Be safe. DMs are open for legit questions, but don’t be fucking lazy.
--
**Introduction**
I'm not a great teacher. It's easiest for me to use my own set-up as a starting point for teaching. Having said that, I want to make something clear right away.
I use four different machines weekly:
A) My normie machine - MBP. I still encrypt everything. I still use my VPNs and exclusive networks. I still use a password manager and monitor my systems... but it's a daily-use machine. I'm a full-stack developer, and this is my daily working tool. All 2FA. All unique passwords. Security is as high as it gets. Drives are encrypted. I completely control this machine as if it were an extension of me.
B) My ML/Compute - 2x Mac Studios. Loaded. Stripped to the bare metal, basically... as much as possible, anyway. These machines are like Fort Knox because my proprietary code and datasets exist here. It's hardwired to my router; ported; and connects to less than 20 different servers. These are domain-specific machines that no one in their right mind needs. In fact, if you're in ML/AI... don't build a machine. Lease bigger, faster tools in the cloud for a year privately for the same money. Learning lesson.
B) My secondary machine - an XPS running Kali; TailsOS. I use this for everything else. The same rules apply here, but doubly so. This is pretty locked down. It also takes me about 60 seconds from boot to totally secure. I can brick this machine with keystrokes in the event I need to. It's not super secure, but it's a modified "sudo dd" command that will do it 99.5% of the time.
C) My dark machine. This aLmost NEVER connEcts to the internet; the webcam and microphone have been removed. It's wiped after use - every single time. It's also nEver more than 12 months old. Use your imaginaTion.
For the majority of this guide, you can think of the guide in reference to either my daily driver or secondary machines. These are the categories 99% of the people interested in the guide will fall into.
**Hardware**
Use dedicated machines. It’s as simple as that. It doesn’t need to be illegal; it’s simply a machine you make sure keeps you anonymous. Period. It’s not as difficult as it seems to secure anonymous hardware. The tin-foil crowd will say that global supply chains[...]
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Anonymity Guide Let me first offer a brief apology. I agreed to share a basic anonymity guide without really considering my current workload; I own a full-blown startup company and am working 14-plus hours a day, all week long.…
can’t be trusted, and you know what… maybe they’re right. The thing is, 99.5% of us don’t have the capacity to solve that… so we do the best we can in the real world with real tools. I can say with some confidence that TAO has lost the Intel access they’ve held for over a decade; I don’t know if that makes the tin-foil crowd’s point more or less valid. You be the judge of all that. You can have a single machine and STILL remain anonymous; the rules just apply to that machine. You don't need a ton of money or anything else to accomplish this.
1. Tor w/ BTC for third-party electronics. They’re everywhere… You can use Torch, THW, or whatever search engine you use most often on the DW to find what you need.
2. P2P w/ Cash is a solid option. This is self-explanatory.
3. Clearnet w/ Different Info is the last option, and it’s one we should all be VERY careful using. Using information that isn’t your own is a crime, and using information with permission isn’t exactly secure in most cases. There is a middle ground between those two options. Stay safe.
** Any hardware purchased via the dark web or P2P needs to be wiped as soon as you receive it. In the past, I’ve installed a new SSD/HD and a new OS before I used it for anything at all.
**Software**
Use safe OSs like Tails, Qubes, or Whonix. Use TOR, and use the TOR Project itself to download the browser. If you’re ultra concerned about the age-old rumor of being “flagged” by your ISP on the download of TOR… be creative. Use public Wi-Fi to download the package; install it via portable drive. Here is a link to accomplish this: https://tb-manual.torproject.org/make-tor-portable/. I am not a huge fan of VMs, but they ARE another tool that can be used to remain anonymous if you're competent. I don't use them except in situations where I haven't a choice, but they should at least be mentioned. Many people use them to great effect.
I want you to remember that the weak link is always the human using the machine or tools. If you make sloppy, rushed mistakes… the best tools or software in the world are useless. Be patient, and do it properly the first time. It will make moving from one machine or operating system to the next much easier.
1. Qubes: http://www.qubesosfasa4zl44o4tws22di6kepyzfeqv3tg4e3ztknltfxqrymdad.onion/
2. Whonix: http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/
3. TailsOS: https://tails.net/install/download/
4. Kali Linux: I’ll leave this to the user. Kali is not, by definition, a “privacy” OS, but it is still an amazing one. The user is responsible for security with Kali. Keep this in mind. I do not recommend it as a pure privacy OS for anyone who isn’t a professional; more like a base OS.
5. TOR Project: http://2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion/
6. Njalla VPN: Yes, there are other options. This is just one I really believe in.
7. WannaRDP: IMO, the best in their class. My only advice would be to come prepared. They don’t play around with single instances or whatever. You’ll be speaking to a professional, and they’re going to expect the same in return.
8. MAC Switcher: There are a bunch of good options, and I'll leave it to the user's preference. Most of the best are freeware tools. If you're on a Mac box and can't figure it out; you can DM me.
**Connections**
This is a REALLY brief overview of connections. It's a set of simple, hard, and fast rules that everyone should follow. Automate as much of this as possible. Most tools (NordVPN, for example) allow you to configure the automatic connection. Keep in mind, most Clearnet VPN providers DO STORE LOGS and they WILL COOPERATE WITH LE. That doesn’t mean they’re useless. People can still use them to remain anonymous… but they’re not bulletproof.
1. Use a virtual private network (VPN) to encrypt your internet traffic and hide your IP address.
2. Use secure Wi-Fi networks. I could write a literal book about this, but I just don’t have time time to do so. So, I’ll try to make it super s[...]
1. Tor w/ BTC for third-party electronics. They’re everywhere… You can use Torch, THW, or whatever search engine you use most often on the DW to find what you need.
2. P2P w/ Cash is a solid option. This is self-explanatory.
3. Clearnet w/ Different Info is the last option, and it’s one we should all be VERY careful using. Using information that isn’t your own is a crime, and using information with permission isn’t exactly secure in most cases. There is a middle ground between those two options. Stay safe.
** Any hardware purchased via the dark web or P2P needs to be wiped as soon as you receive it. In the past, I’ve installed a new SSD/HD and a new OS before I used it for anything at all.
**Software**
Use safe OSs like Tails, Qubes, or Whonix. Use TOR, and use the TOR Project itself to download the browser. If you’re ultra concerned about the age-old rumor of being “flagged” by your ISP on the download of TOR… be creative. Use public Wi-Fi to download the package; install it via portable drive. Here is a link to accomplish this: https://tb-manual.torproject.org/make-tor-portable/. I am not a huge fan of VMs, but they ARE another tool that can be used to remain anonymous if you're competent. I don't use them except in situations where I haven't a choice, but they should at least be mentioned. Many people use them to great effect.
I want you to remember that the weak link is always the human using the machine or tools. If you make sloppy, rushed mistakes… the best tools or software in the world are useless. Be patient, and do it properly the first time. It will make moving from one machine or operating system to the next much easier.
1. Qubes: http://www.qubesosfasa4zl44o4tws22di6kepyzfeqv3tg4e3ztknltfxqrymdad.onion/
2. Whonix: http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/
3. TailsOS: https://tails.net/install/download/
4. Kali Linux: I’ll leave this to the user. Kali is not, by definition, a “privacy” OS, but it is still an amazing one. The user is responsible for security with Kali. Keep this in mind. I do not recommend it as a pure privacy OS for anyone who isn’t a professional; more like a base OS.
5. TOR Project: http://2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion/
6. Njalla VPN: Yes, there are other options. This is just one I really believe in.
7. WannaRDP: IMO, the best in their class. My only advice would be to come prepared. They don’t play around with single instances or whatever. You’ll be speaking to a professional, and they’re going to expect the same in return.
8. MAC Switcher: There are a bunch of good options, and I'll leave it to the user's preference. Most of the best are freeware tools. If you're on a Mac box and can't figure it out; you can DM me.
**Connections**
This is a REALLY brief overview of connections. It's a set of simple, hard, and fast rules that everyone should follow. Automate as much of this as possible. Most tools (NordVPN, for example) allow you to configure the automatic connection. Keep in mind, most Clearnet VPN providers DO STORE LOGS and they WILL COOPERATE WITH LE. That doesn’t mean they’re useless. People can still use them to remain anonymous… but they’re not bulletproof.
1. Use a virtual private network (VPN) to encrypt your internet traffic and hide your IP address.
2. Use secure Wi-Fi networks. I could write a literal book about this, but I just don’t have time time to do so. So, I’ll try to make it super s[...]