Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Liferay Portal RCE | CVE-2020–7961

…..Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Government Shutdown Poised to Stress Nation's Cybersecurity Supply Chain

CISA announces it will furlough more than 80% of staff indefinitely if Congress can't reach an agreement to fund the federal government.
Dark Reading: Attacks/Breaches
Chrome Flags Third Zero-Day This Month That's Tied to Spying Exploits

So far this year, Google has disclosed six vulnerabilities that attackers were actively exploiting before the company had a patch for them.
Dark Reading: Attacks/Breaches
New Cisco IOS Zero-Day Delivers a Double Punch

The networking giant discloses new vulnerabilities the same day as warnings get issued that Cisco gear has been targeted in a Chinese APT attack.
Hacking with Havoc C2 - Basic setup, installation, usage, and Windows Defender Bypass
https://www.reddit.com/r/redteamsec/comments/16uwwbn/hacking_with_havoc_c2_basic_setup_installation/

<!-- SC_OFF -->Check out this video posted on Gemini Cyber Security Youtube channel (https://www.youtube.com/watch?v=DXJNWiZJGko), whereby the setup and installation step-by-step guide is demonstrated in the video. The video also showcases basic usage of the Havoc C2 tool, such as setting up a listener and generating payload for it. As a bonus, it was also demonstrated how you can bypass the latest Windows Defender by utilising the shellcode format of the Havoc C2 payload (Demon agent) and executing the shellcode using AES encryption with a .DLL loader. https://www.youtube.com/watch?v=DXJNWiZJGko <!-- SC_ON --> submitted by /u/cybermepls (https://www.reddit.com/user/cybermepls)
[link] (https://www.reddit.com/r/redteamsec/comments/16uwwbn/hacking_with_havoc_c2_basic_setup_installation/) [comments] (https://www.reddit.com/r/redteamsec/comments/16uwwbn/hacking_with_havoc_c2_basic_setup_installation/)
hacking: security in practice
ATTiny85 as a BadUSB (Rubber Ducky) - still relevant?

I'm interested in making a BadUSB, similar to the Rubber Ducky.

After considering several options, I narrowed it down to the Attiny85 as the best option for me.

But when I dove into it deeper, amongst the many positive comments, I started noticing some users pointing out that it's drivers were no longer natively supported by some modern OS, which would pretty much defeat it's purpose.

So, does the ATTiny85 still work as a BadUSB?

Grateful for your feedback and experience.

submitted by /u/ffoott
[link] [comments]
hacking: security in practice
Someone want to look into iOS calandar exploits?

So I’m going to put this out there. I’m laying in bed and I get a calendar notification I should’ve screen shotted it. It said “M O B I L E” in a weird font. So I clicked the notification. Looked sketch. So I clicked on the sender which said “official t-mobile” and it has just a weird string of characters. Had 2 links to click on I’m not that dumb. Just be aware that it looks like people are using the calendar app to try and hack iPhones. Possibly a new iOS 17 exploit. Not sure if someone wants to try and pen test the calandar app and turn it into Apple.

submitted by /u/katahg
[link] [comments]
Deep Diving into Netlas.io for OSINT | Day11 of 30DaysOfOSINT

The main aim of writing this blog is to explain different use cases and techniques for using Netlas.io for OSINT investigations.Continue reading on OSINT Ambition »
Read more...
hacking: security in practice
Best way to crack a passworded rar file.

Like the title says whats the best way to crack a passworded rar file.

I used a couple free applications but they dont get very far because they always have a limited trial.

If anyone can give me any kind of info please do, thanks.

submitted by /u/lmpurities
[link] [comments]
hacking: security in practice
Managed to find a hackers IP address (story involved)

So my son (12 years old) was oblivious to the malignant intentions of people in this world and ignorantly accepted a file from a person on discord thinking it was a game patch.

So a day later he tells me his epic games account can't be logged into and there's a different email set up on his account. He had 2fa set up and the person that sent a file (which happened to be a trojan) managed to change the epic games email address and had access to his email as well.

Fast forward and I've managed to recover everything and explained to him what happened and how certain people will do this to you if you let your guard down.



Anyways during the whole ordeal, the noob "hacker" didn't use a VPN when he first accessed my son's gmail and I was able to obtain his ip, city/location/ ISP, from the logs and I can see that he flicked on his vpn moments later.

What can I do in retaliation with his IP to teach him a lesson? Or is it water under the bridge and walk away?

submitted by /u/noquarter1983
[link] [comments]
hacking: security in practice
If it’s not possible to be grey hat then why is it possible to be black hat?

Someone said if you are grey hat you will get arrested very quickly before you can do anything. Why would it be any different with black hats? Seems like it would be more consistent to say “you won’t get away with illegal hacking.” Which I would agree with except for some reason grey hat is specified and not black hat.

submitted by /u/notburneddown
[link] [comments]