Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Free Course Site
Flutter & Dart – The Complete Guide [2021 Edition]

https://freecoursesite.com/wp-content/uploads/2018/08/1708340_7108_2.jpg
A Complete Guide to the Flutter SDK & Flutter Framework for building native iOS and Android apps. What you’ll learn Learn Flutter and Dart from the ground up, step-by-step Build engaging native mobile apps for both Android and iOS Use features like Google Maps, the device camera, authentication and much more! Learn how to upload […]

The post Flutter & Dart – The Complete Guide [2021 Edition] appeared first on Free Course Site.

___________________________
@hacking_Attack
@Hacking_Video
Free Course Site
Data Structures & Algorithms – JavaScript

https://freecoursesite.com/wp-content/uploads/2021/06/555488777.jpg
The ultimate JavaScript coding interview bootcamp What you’ll learn Confidently answer technical interview questions Mastery of Data Structures and Algorithms Land your dream job Strengthen your skills as a developer Requirements Basic programming No experience with data structures or algorithms required Description This course is different… After each line of code, an animation of the […]

The post Data Structures & Algorithms – JavaScript appeared first on Free Course Site.

___________________________
@hacking_Attack
@Hacking_Video
All about unrestricted file upload

File upload attacks
Read more...
An easy HTML Injection

Hello everyone. I hope everyone is doing great :)Continue reading on Medium »
Read more...
How do you get your first internship in cyber security?

Hello there, everyone. I hope you’re all doing well. If you are a college student looking for an internship, this blog can assist you in…Continue reading on Medium »
Read more...
hacking: security in practice
Typical story become intriguing

Hi, that's quite a typical story but there is a catch and I didn't find a better place to post this and I'm curious as how someone did that, if you think of an idea.

Someone connected to my FB account, he used it, changed PP and proceed to add some friends.

I receive a notification about an unusual activity.
I connect to my account, change my password (by something completely different but that i already used in the past) and disconnect all devices thinking that would be enough.

But I get a notification the same day saying he connected again (same IP same location same user-agent). There I start to be doubtful but simply thought that he got the older one and tried it.

I proceed to connect again, change my password (again with something different (and this time that I never used anywhere else) and proceed to enable 2FA through SMS thinking I would be definitely done with this problem.

But there it's even more confusing, I again get a notification that he connected.

I'm only using 2 devices at the moment, an Android phone and a chromebook. All of them are quite well managed and my password is only stored on device and sync through my google account. My google account is well secured and only those 2 devices are connected to it (google activity).

My SMS stays on my phone and I don't use any third party app for SMS (nor you can see them on telecom website). There is 5 apps having access to my SMS and they all are from android stock (messenger is not one of them if you wonder).

I now changed my password again and switched to third party authenticator but i'm curious if you have any idea how this was done ?

Also what measure do your recommend me to take about my 100+ others accounts ?

submitted by /u/Bjr49000
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Doubts

Guys, Let say there's a malware affected Android device and another non infected phone is connected for internet through that affect device's wifi hotspot. Now in this scenario, Can virus spread throughout the hotspot to non infected device?

submitted by /u/Annie_me1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
GitHub’s new policies allow removal of PoC exploits used in attacks

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg GitHub’s new policies allow removal of PoC exploits used in attacksPost Views: 45
Reading Time: 1 Minute
GitHub announced on Friday their updated community guidelines that explain how the company will deal with exploits and malware samples hosted on their service.
To give some background behind the new policy changes, security researcher Nguyen Jang uploaded a proof-of-concept exploit (PoC) to GitHub in March for the Microsoft Exchange ProxyLogon vulnerability.

Soon after uploading the exploit, Jang received an email from Microsoft-owned GitHub stating that PoC exploit was removed as it violated the Acceptable Use Policies.

In a statement to BleepingComputer, GitHub said they took down the PoC to protect Microsoft Exchange servers that were being heavily exploited at the time using the vulnerability.

“We understand that the publication and distribution of proof of concept exploit code has educational and research value to the security community, and our goal is to balance that benefit with keeping the broader ecosystem safe. In accordance with our Acceptable Use Policies, GitHub disabled the gist following reports that it contains proof of concept code for a recently disclosed vulnerability that is being actively exploited.” – GitHub.

However, GitHub faced immediate backlash from security researchers who felt that GitHub was policing the disclosure of legitimate security research simply because it was affecting a Microsoft product.
See Also: Google PPC Ads Used to Deliver Infostealers GitHub releases updated guidelinesIn April, GitHub issued a ‘call for feedback‘ to the cybersecurity community regarding their policies for malware and exploits hosted on GitHub.

After a month of input, GitHub officially announced yesterday that repositories created to host malware for malicious campaigns, act as a command and control server, or are used to distribute malicious scripts, are prohibited.

However, the uploading of PoC exploits and malware are permitted as long as they have a dual-user purpose.

In the context of malware and exploits, dual-use means content that can be used for the positive sharing of new information and research while at the same time can also be used for malicious purposes.

The key changes added to the GitHub guidelines are summarized below:

* We explicitly permit dual-use security technologies and content related to research into vulnerabilities, malware, and exploits. We understand that many security research projects on GitHub are dual-use and broadly beneficial to the security community. We assume positive intention and use of these projects to promote and drive improvements across the ecosystem. This change modifies previously broad language that could be misinterpreted as hostile toward projects with dual-use, clarifying that such projects are welcome.
* We have clarified how and when we may disrupt ongoing attacks that are leveraging the GitHub platform as an exploit or malware content delivery network (CDN). We do not allow use of GitHub in direct support of unlawful attacks that cause technical harm, which we’ve further defined as overconsumption of resources, physical damage, downtime, denial of service, or data loss.
* We made clear that we have an appeals and reinstatement process directly in this policy. We allow our users to appeal decisions to restrict their content or account access. This is especially important in the security research context, so we’ve very clearly and directly called out the [...]

___________________________
@hacking_Attack
@Hacking_Video