Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cyberterrorism or 'ransomware-as-a-service model'? Group claims credit, explains 'business model'
So, there is a hacking group that has taken credit for several such recent attacks and according to this, do not mind being characterized as cyberterrorists
I am not skeptical about it, but I do recall that after some unclaimed acts of terrorism, group not responsible occasionally claim credit to boost their own status or to help the actual perpetrators (or both), perhaps that's inaccurate though.
That I don't really care about tbh, I am more wondering if the targets really are so disconnected, because there seems to be the potential for an ideological thread of 'ecoterrorism', that is terrorists motivated by environmentalist sentiments. Oil and meat are said to be major contributors to greenhouse gases, destruction of local ecosystems, and displacement of people (often Indigenous peoples).
That they were targeting Brazil, still doesn't make that implausible. Considering the actions of Bolsonaro towards Indigenous people there, as well as the rain forest destruction caused by farming, it makes a target that still fits that motive IMO.
However, they discuss their business model and I think that it's still very plausible this is motivated by profit and nationalism, because that's what it seems on the face of it and sometimes a something is just a something.
Also their targets may line up because they are industries that cut corners on security and modernization, so essentially they're convenient and reliable. Like picking off the weak of the herd or whatever. I find the assertion they'd be killed if they came to the United States odd; I have no faith in the USA to be fair, but that seems like an almost sheltered view of what might happen, which seems ideological/nationalist.
Or perhaps indicates this is a paramilitary or quasi-governmental group; regardless of what, a black site or indefinite detention seems more plausible to me. Visibility now would be their biggest asset in that, as such detainment would be more obvious to the world.
I don't know really, I haven't watched their videos or done more research yet, so most of this is just speculation other than what they say in those linked articles above. Still, interesting.
PS - the name of their ransomware reminds me of an old Linux game. You might want to try it, but it probably helps if you're a bit masochistic and into games from the 90s. It also cracks me up about the casino affiliate thing or whatever it is.
submitted by /u/redrosesburningblack
[link] [comments]
Cyberterrorism or 'ransomware-as-a-service model'? Group claims credit, explains 'business model'
So, there is a hacking group that has taken credit for several such recent attacks and according to this, do not mind being characterized as cyberterrorists
I am not skeptical about it, but I do recall that after some unclaimed acts of terrorism, group not responsible occasionally claim credit to boost their own status or to help the actual perpetrators (or both), perhaps that's inaccurate though.
That I don't really care about tbh, I am more wondering if the targets really are so disconnected, because there seems to be the potential for an ideological thread of 'ecoterrorism', that is terrorists motivated by environmentalist sentiments. Oil and meat are said to be major contributors to greenhouse gases, destruction of local ecosystems, and displacement of people (often Indigenous peoples).
That they were targeting Brazil, still doesn't make that implausible. Considering the actions of Bolsonaro towards Indigenous people there, as well as the rain forest destruction caused by farming, it makes a target that still fits that motive IMO.
However, they discuss their business model and I think that it's still very plausible this is motivated by profit and nationalism, because that's what it seems on the face of it and sometimes a something is just a something.
Also their targets may line up because they are industries that cut corners on security and modernization, so essentially they're convenient and reliable. Like picking off the weak of the herd or whatever. I find the assertion they'd be killed if they came to the United States odd; I have no faith in the USA to be fair, but that seems like an almost sheltered view of what might happen, which seems ideological/nationalist.
Or perhaps indicates this is a paramilitary or quasi-governmental group; regardless of what, a black site or indefinite detention seems more plausible to me. Visibility now would be their biggest asset in that, as such detainment would be more obvious to the world.
I don't know really, I haven't watched their videos or done more research yet, so most of this is just speculation other than what they say in those linked articles above. Still, interesting.
PS - the name of their ransomware reminds me of an old Linux game. You might want to try it, but it probably helps if you're a bit masochistic and into games from the 90s. It also cracks me up about the casino affiliate thing or whatever it is.
submitted by /u/redrosesburningblack
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Obfuscating powershell scripts using Invoke-Obfuscation ** Only for educational purposes!!! **
Hello everyone, hope you all are doing great and are safe, in this video, we will have a look at a tool known as invoke-obfuscation, please note that this video is strictly for educational purposes only! Thank you! Peace!
https://youtu.be/6o7hMytqBfA
submitted by /u/Vedant-Bhalgama
[link] [comments]
Obfuscating powershell scripts using Invoke-Obfuscation ** Only for educational purposes!!! **
Hello everyone, hope you all are doing great and are safe, in this video, we will have a look at a tool known as invoke-obfuscation, please note that this video is strictly for educational purposes only! Thank you! Peace!
https://youtu.be/6o7hMytqBfA
submitted by /u/Vedant-Bhalgama
[link] [comments]
hacking: security in practice
Is it possible to crack a password?
If anyone can help me, I’ll be happy to pay for it
submitted by /u/furheirbduebdd
[link] [comments]
Is it possible to crack a password?
If anyone can help me, I’ll be happy to pay for it
submitted by /u/furheirbduebdd
[link] [comments]
reddit
Is it possible to crack a password?
If anyone can help me, I’ll be happy to pay for it
hacking: security in practice
Mymathlab
I am a science major, I am taking Calculus 1 for summer and this teacher uses mymathlab.
Reasons I have conflict with mymathlab:
1. It only let's you open one tab during homework. The internet is the greatest learning tool we have discovered since the beginning of mankind, tab opening is crucial.
2. It cost another $100 dollars when school is already expensive.
3. Pearson lobbies state laws and forces itself into student's education system.
With that being said, who knows how to rig this shit?
submitted by /u/jwdino
[link] [comments]
Mymathlab
I am a science major, I am taking Calculus 1 for summer and this teacher uses mymathlab.
Reasons I have conflict with mymathlab:
1. It only let's you open one tab during homework. The internet is the greatest learning tool we have discovered since the beginning of mankind, tab opening is crucial.
2. It cost another $100 dollars when school is already expensive.
3. Pearson lobbies state laws and forces itself into student's education system.
With that being said, who knows how to rig this shit?
submitted by /u/jwdino
[link] [comments]
reddit
Mymathlab
I am a science major, I am taking Calculus 1 for summer and this teacher uses mymathlab. Reasons I have conflict with mymathlab: 1. It only...
hacking: security in practice
Web or Native R.A.T. UI?
Which is better and why?
Web or native user interface for Remote Administration Tools?
In my mind web UI is the way to go, since less foot-print is left onto the machine, plus it is accessible directly from the Tor browser.
I'm asking because I'm soon releasing an Open-Source RAT framework. (not a commercial project, it will be open and free)
submitted by /u/Blagojee
[link] [comments]
Web or Native R.A.T. UI?
Which is better and why?
Web or native user interface for Remote Administration Tools?
In my mind web UI is the way to go, since less foot-print is left onto the machine, plus it is accessible directly from the Tor browser.
I'm asking because I'm soon releasing an Open-Source RAT framework. (not a commercial project, it will be open and free)
submitted by /u/Blagojee
[link] [comments]
reddit
Web or Native R.A.T. UI?
Which is better and why? Web or native user interface for Remote Administration Tools? In my mind web UI is the way to go, since less foot-print...
hacking: security in practice
Nmap MS-SQL Server Recon
MSSQL is Microsoft' SQL Server used by many companies. In this post, I have covered how to perform reconnaissance against the MSSQL server with the Nmap tool.
From scanning ports to execute arbitrary system commands, Nmap is used
https://www.secjuice.com/recon-basics-mssql-server/
submitted by /u/tbhaxor
[link] [comments]
Nmap MS-SQL Server Recon
MSSQL is Microsoft' SQL Server used by many companies. In this post, I have covered how to perform reconnaissance against the MSSQL server with the Nmap tool.
From scanning ports to execute arbitrary system commands, Nmap is used
https://www.secjuice.com/recon-basics-mssql-server/
submitted by /u/tbhaxor
[link] [comments]
reddit
Nmap MS-SQL Server Recon
MSSQL is Microsoft' SQL Server used by many companies. In this post, I have covered how to perform reconnaissance against the MSSQL server with...
hacking: security in practice
Is it possible for a totally random stranger on kik to find my address? They know nothing about me
They're threatening to find me and stuff....... I'm a little scared
submitted by /u/WereWolf_Engine
[link] [comments]
Is it possible for a totally random stranger on kik to find my address? They know nothing about me
They're threatening to find me and stuff....... I'm a little scared
submitted by /u/WereWolf_Engine
[link] [comments]
reddit
Is it possible for a totally random stranger on kik to find my...
They're threatening to find me and stuff....... I'm a little scared
Functionality Bypass — IDOR
https://antaramane.medium.com/functionality-bypass-idor-7df76e15e77b?source=rss------bug_bounty-5
https://antaramane.medium.com/functionality-bypass-idor-7df76e15e77b?source=rss------bug_bounty-5
OTP Bypass to IDOR (Insecure Direct Object Reference)Continue reading on Medium » (https://antaramane.medium.com/functionality-bypass-idor-7df76e15e77b?source=rss------bug_bounty-5)
Medical Provider — Reflected XSS in Search Results
https://medium.com/@pr1sas/medical-provider-reflected-xss-in-search-results-2dc829c50543?source=rss------bug_bounty-5
https://medium.com/@pr1sas/medical-provider-reflected-xss-in-search-results-2dc829c50543?source=rss------bug_bounty-5
Yesterday I read a Medium article where another security researcher discovered some interesting issues in a medical provider subdomains…Continue reading on Medium » (https://medium.com/@pr1sas/medical-provider-reflected-xss-in-search-results-2dc829c50543?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Hacker that Double Crossed the Secret Service
https://cdn-images-1.medium.com/max/600/1*lY8Q0YK1T-XUhrFipyqWzQ.jpeg
Life advice; don’t bite the hand that kept you out of federal prison.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Hacker that Double Crossed the Secret Service
https://cdn-images-1.medium.com/max/600/1*lY8Q0YK1T-XUhrFipyqWzQ.jpeg
Life advice; don’t bite the hand that kept you out of federal prison.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Hacker that Double Crossed the Secret Service
Life advice; don’t bite the hand that kept you out of federal prison.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Krane - Kubernetes RBAC Static Analysis And Visualisation Tool
https://1.bp.blogspot.com/-mnxsu5qcoZs/YLc2t6BK9FI/AAAAAAAAXuI/tFELTagA54UfUVTRjljGXS5hvoGN4rlawCNcBGAsYHQ/w640-h590/krane.png Krane is a simple Kubernetes RBAC static analysis tool. It identifies potential security risks in K8s RBAC design and makes suggestions on how to mitigate them. Krane dashboard presents current RBAC security posture and lets you navigate through its definition. Features* RBAC Risk rules - Krane evaluates a set of built-in RBAC risk rules. These can be modified or extended with a set of custom rules.
* Portability - Krane can run in one of the following modes:
* Locally as a CLI or docker container.
* In CI/CD pipelines as a step action detecting potential RBAC flaws before it gets applied to the cluster.
* As a standalone service continuously analysing state of RBAC within a Kubernetes cluster.
* Reporting - Krane produces an easy to understand RBAC risk report in machine-readable format.
* Dashboard - Krane comes with a simple Dashboard UI helping you understand in-cluster RBAC design. Dashboard presents high-level overview of RBAC security posture and highlights detected risks. It also allows for further RBAC controls inspection via faceted tree and graph network views.
* Alerting - It will alert on detected medium and high severity risks via its Slack integration.
* RBAC in the Graph - Krane indexes entirety of Kubernetes RBAC in a local Graph database which makes any further ad-hoc interrogating of RBAC data easy, with arbitrary CypherQL queries. Local Quick StartGet started locally with Docker Compose. PrerequisitesIt is assumed that you have docker running on your local machine. Install docker-compose if you haven't already. Run Krane locallyKrane depends on RedisGraph.
Note that when running
___________________________
@hacking_Attack
@Hacking_Video
Krane - Kubernetes RBAC Static Analysis And Visualisation Tool
https://1.bp.blogspot.com/-mnxsu5qcoZs/YLc2t6BK9FI/AAAAAAAAXuI/tFELTagA54UfUVTRjljGXS5hvoGN4rlawCNcBGAsYHQ/w640-h590/krane.png Krane is a simple Kubernetes RBAC static analysis tool. It identifies potential security risks in K8s RBAC design and makes suggestions on how to mitigate them. Krane dashboard presents current RBAC security posture and lets you navigate through its definition. Features* RBAC Risk rules - Krane evaluates a set of built-in RBAC risk rules. These can be modified or extended with a set of custom rules.
* Portability - Krane can run in one of the following modes:
* Locally as a CLI or docker container.
* In CI/CD pipelines as a step action detecting potential RBAC flaws before it gets applied to the cluster.
* As a standalone service continuously analysing state of RBAC within a Kubernetes cluster.
* Reporting - Krane produces an easy to understand RBAC risk report in machine-readable format.
* Dashboard - Krane comes with a simple Dashboard UI helping you understand in-cluster RBAC design. Dashboard presents high-level overview of RBAC security posture and highlights detected risks. It also allows for further RBAC controls inspection via faceted tree and graph network views.
* Alerting - It will alert on detected medium and high severity risks via its Slack integration.
* RBAC in the Graph - Krane indexes entirety of Kubernetes RBAC in a local Graph database which makes any further ad-hoc interrogating of RBAC data easy, with arbitrary CypherQL queries. Local Quick StartGet started locally with Docker Compose. PrerequisitesIt is assumed that you have docker running on your local machine. Install docker-compose if you haven't already. Run Krane locallyKrane depends on RedisGraph.
docker-composestack defines all what's required to build and run Krane service locally. It'll also take care of its RedisGraph dependency. docker-compose up -d Krane docker image will be pre-built automatically if not already present on local machine.Note that when running
docker-composelocally, Krane won't start RBAC report and dashboard automatically. Instead, the container will sleep for 24h by default - this value can be adjusted in docker-compose.override.yml. Exec into a running Krane container to run commands. Local docker-composewill also mount kube config (~/.kube/config) inside the container enabling you to run reports against any Kubernetes clusters to which you already have access to. # Exec into a running Krane container
docker-compose exec krane bash
# Once in the container you can start using `krane` commands. Try `krane -help`.
$ krane -hTo inspect what services are running and the associated ports: docker-compose ps To stop Krane and its dependency services: docker-compose down Usage GuideCommands$ krane --help
NAME:
krane
DESCRIPTION:
Kubernetes RBAC static analysis & visualisation tool
COMMANDS:
dashboard Start K8s RBAC dashboard server
help Display global or [command] help documentation
report Run K8s RBAC report
GLOBAL OPTIONS:
-h, --help
Display help documentation
-v, --version
Display version information
-t, --trace
Display backtrace when an error occurs
AUTHOR:
Marcin Ciszak Generate RBAC reportWith local kubectlcontextTo run a report against a running cluster you must provide a kubectl context krane report -k You may also pass -c flag if you plan to run the tool against multiple clusters and index RBAC graph separately for each cluster na[...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Krane - Kubernetes RBAC Static Analysis And Visualisation Tool
KitPloit - PenTest Tools!
Krane - Kubernetes RBAC Static Analysis And Visualisation Tool
___________________________
@hacking_Attack
@Hacking_Video
Krane - Kubernetes RBAC Static Analysis And Visualisation Tool
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Krane - Kubernetes RBAC Static Analysis And Visualisation Tool
Missed the boat on hardware?
https://www.reddit.com/r/Pentesting/comments/ntx61n/missed_the_boat_on_hardware/
I've been looking to expand my skillset a bit and I was hoping to invest in some hardware for on-site pen testing. But besides maybe the Pineapple, it kind of feels like nothing is available. I found a ton of articles about all kinds of cool covert devices that were disguised to be able to leave in plain sight, and be able to provide tons of functionality in tiny packages. But those are all from like 2016-2018, and it seems like every project got discontinued, all the people ended up getting sucked up by companies and their tools taken off the internet. Obviously a few things like the pineapple and various USB keys are still available, but everything else is gone. So, am I just completely failing at my Google abilities and I'm missing out on all the good stuff, or is it really the case that the glory days are over? submitted by /u/QuerulousPanda (https://www.reddit.com/user/QuerulousPanda)
[link] (https://www.reddit.com/r/Pentesting/comments/ntx61n/missed_the_boat_on_hardware/) [comments] (https://www.reddit.com/r/Pentesting/comments/ntx61n/missed_the_boat_on_hardware/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ntx61n/missed_the_boat_on_hardware/
I've been looking to expand my skillset a bit and I was hoping to invest in some hardware for on-site pen testing. But besides maybe the Pineapple, it kind of feels like nothing is available. I found a ton of articles about all kinds of cool covert devices that were disguised to be able to leave in plain sight, and be able to provide tons of functionality in tiny packages. But those are all from like 2016-2018, and it seems like every project got discontinued, all the people ended up getting sucked up by companies and their tools taken off the internet. Obviously a few things like the pineapple and various USB keys are still available, but everything else is gone. So, am I just completely failing at my Google abilities and I'm missing out on all the good stuff, or is it really the case that the glory days are over? submitted by /u/QuerulousPanda (https://www.reddit.com/user/QuerulousPanda)
[link] (https://www.reddit.com/r/Pentesting/comments/ntx61n/missed_the_boat_on_hardware/) [comments] (https://www.reddit.com/r/Pentesting/comments/ntx61n/missed_the_boat_on_hardware/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Missed the boat on hardware?
I've been looking to expand my skillset a bit and I was hoping to invest in some hardware for on-site pen testing. But besides maybe the...