Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Clickjacking and How to Find it in Web Application
https://cdn-images-1.medium.com/max/1366/1*Dyr01XdEy5ns3pPrvuqkdQ.png
Unmasking the Deceptive World of Clickjacking | Karthikeyan Nagaraj
Continue reading on Medium »
What is Clickjacking and How to Find it in Web Application
https://cdn-images-1.medium.com/max/1366/1*Dyr01XdEy5ns3pPrvuqkdQ.png
Unmasking the Deceptive World of Clickjacking | Karthikeyan Nagaraj
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Protecting Your Finances: How to Spot and Avoid Scams from Fake Banking Institutions.
https://cdn-images-1.medium.com/max/602/0*D8YEdJl697ZBecgQ
With the rise of technology comes the proliferation of scams and fraudulent activities, especially from fake banking institutions. These…
Continue reading on Medium »
Protecting Your Finances: How to Spot and Avoid Scams from Fake Banking Institutions.
https://cdn-images-1.medium.com/max/602/0*D8YEdJl697ZBecgQ
With the rise of technology comes the proliferation of scams and fraudulent activities, especially from fake banking institutions. These…
Continue reading on Medium »
What To Do After Choosing a Target? Part 01 | Bug Bounty
https://infosecwriteups.com/what-to-do-after-choosing-a-target-part-01-bug-bounty-0e7eda23d324?source=rss------bug_bounty-5
https://infosecwriteups.com/what-to-do-after-choosing-a-target-part-01-bug-bounty-0e7eda23d324?source=rss------bug_bounty-5
This is the problem faced by most bug hunters in the beginningContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/what-to-do-after-choosing-a-target-part-01-bug-bounty-0e7eda23d324?source=rss------bug_bounty-5)
Aztec Labs Announces Our Largest-Ever Bug Bounty Of $450,000
Recommitting to open-source securityContinue reading on The Aztec Labs Blog »
Read more...
Recommitting to open-source securityContinue reading on The Aztec Labs Blog »
Read more...
Medium
Aztec Labs Announces Our Largest-Ever Bug Bounty Of $450,000
Recommitting to open-source security
Hey! "Basic Command and Control concepts - Intro to C2 Infra for Red Teams" it's up on YouTube
https://www.reddit.com/r/redteamsec/comments/17fqaq5/hey_basic_command_and_control_concepts_intro_to/
submitted by /u/Numerous_General_808 (https://www.reddit.com/user/Numerous_General_808)
[link] (https://youtu.be/f7tirwqVCRE) [comments] (https://www.reddit.com/r/redteamsec/comments/17fqaq5/hey_basic_command_and_control_concepts_intro_to/)
https://www.reddit.com/r/redteamsec/comments/17fqaq5/hey_basic_command_and_control_concepts_intro_to/
submitted by /u/Numerous_General_808 (https://www.reddit.com/user/Numerous_General_808)
[link] (https://youtu.be/f7tirwqVCRE) [comments] (https://www.reddit.com/r/redteamsec/comments/17fqaq5/hey_basic_command_and_control_concepts_intro_to/)
https://b.thumbs.redditmedia.com/CC41BvjXkckXaZKl2v22Qxb9Ruzr8WmdpVozG79PfwQ.jpg Hello, I'm pretty new when it comes to working directly with TCP, so I'm going to assume that my issue is directly related to my ignorance. I'm mostly self-teaching myself, so I'll probably get some terminology wrong too.
I have set up a proxy server via NoPE Proxy extension that my Nox emulator connects to. I'm using ProxyDroid since it offers SOCKS5, and it seemed to be highly recommended. I'm receiving TCP on NoPE, which is a good sign - except all of the data within the TCP packet seems to be replaced with "05 01 00". It doesn't seem to matter what the TCP data / information is, it always becomes "05 01 00".
Is it possible that this is ProxyDroid's fault? I've tried PETEP and I still get the same results. Wireshark labels most of these packets as "[TCP segment of a reassembled PDU]", but searching this doesn't give me much information. Please, any help is appreciated. I'll send any screenshots needed.
The only data I receive on the proxy
submitted by /u/coinfang
[link] [comments]
I have set up a proxy server via NoPE Proxy extension that my Nox emulator connects to. I'm using ProxyDroid since it offers SOCKS5, and it seemed to be highly recommended. I'm receiving TCP on NoPE, which is a good sign - except all of the data within the TCP packet seems to be replaced with "05 01 00". It doesn't seem to matter what the TCP data / information is, it always becomes "05 01 00".
Is it possible that this is ProxyDroid's fault? I've tried PETEP and I still get the same results. Wireshark labels most of these packets as "[TCP segment of a reassembled PDU]", but searching this doesn't give me much information. Please, any help is appreciated. I'll send any screenshots needed.
The only data I receive on the proxy
submitted by /u/coinfang
[link] [comments]
hacking: security in practice
Advice for my specific learning style?
Hey guys, I am a graduate in computer science with no experience in the field. I was always passionate about cyber security and penetration testing but my university didn't offer much practical knowledge. I learn best by practicing for each subject.
Could anyone give me advice on which resource is best to learn pen testing?
Thanks in advance!
submitted by /u/Whonceuponatime
[link] [comments]
Advice for my specific learning style?
Hey guys, I am a graduate in computer science with no experience in the field. I was always passionate about cyber security and penetration testing but my university didn't offer much practical knowledge. I learn best by practicing for each subject.
Could anyone give me advice on which resource is best to learn pen testing?
Thanks in advance!
submitted by /u/Whonceuponatime
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
https://preview.redd.it/p1g8mz2a77wb1.jpg?width=640&crop=smart&auto=webp&s=8d8e10562f81f8fec637b19f5fdd45dd707bb8dd I've recently stumbled upon an intriguing topic that I believe deserves our attention: the possibility of hiding a malicious URL within a report phishing button. It's crucial to remain vigilant and informed about potential tactics that cybercriminals might employ to deceive users.
We all know that the "Report Phishing" button is a critical feature offered by many email clients and web services. It allows users to report suspicious emails and URLs, contributing to the fight against phishing attacks. However, there's growing concern that some malicious actors may attempt to exploit this very feature.
The idea is simple – a phishing email contains a link or button that seemingly directs the user to a legitimate reporting page, but behind the scenes, it redirects them to a malicious website or initiates a download. This tactic can be incredibly deceiving, as users believe they're doing the right thing by reporting the phishing attempt, but in reality, they're falling into a trap.
Here are a few points to consider and discuss: 1. User Awareness: It's crucial for users to remain cautious, even when clicking on seemingly legitimate reporting buttons. Always double-check the URL in the address bar and ensure it matches the expected reporting page.
1.
Service Providers' Responsibility: Email providers and web services need to implement robust security measures to detect and prevent these deceptive tactics. Continuous monitoring and analysis of reported URLs can help uncover malicious intent.
2.
User Education: Raising awareness about this potential threat can be our best defense. The more users understand these tactics, the less likely they are to fall victim to such attacks.
3.
Reporting Safely: If you suspect a phishing email but are uncertain about the legitimacy of the reporting button, consider alternative ways to report the threat, such as directly contacting the service provider's support.
Let's open up a discussion about this evolving threat and how we, as a community, can work together to stay ahead of cybercriminals. Your insights and experiences are highly valuable in addressing this issue effectively.
Stay safe out there! ▪️▪️▪️
submitted by /u/Morphy_exe
[link] [comments]
We all know that the "Report Phishing" button is a critical feature offered by many email clients and web services. It allows users to report suspicious emails and URLs, contributing to the fight against phishing attacks. However, there's growing concern that some malicious actors may attempt to exploit this very feature.
The idea is simple – a phishing email contains a link or button that seemingly directs the user to a legitimate reporting page, but behind the scenes, it redirects them to a malicious website or initiates a download. This tactic can be incredibly deceiving, as users believe they're doing the right thing by reporting the phishing attempt, but in reality, they're falling into a trap.
Here are a few points to consider and discuss: 1. User Awareness: It's crucial for users to remain cautious, even when clicking on seemingly legitimate reporting buttons. Always double-check the URL in the address bar and ensure it matches the expected reporting page.
1.
Service Providers' Responsibility: Email providers and web services need to implement robust security measures to detect and prevent these deceptive tactics. Continuous monitoring and analysis of reported URLs can help uncover malicious intent.
2.
User Education: Raising awareness about this potential threat can be our best defense. The more users understand these tactics, the less likely they are to fall victim to such attacks.
3.
Reporting Safely: If you suspect a phishing email but are uncertain about the legitimacy of the reporting button, consider alternative ways to report the threat, such as directly contacting the service provider's support.
Let's open up a discussion about this evolving threat and how we, as a community, can work together to stay ahead of cybercriminals. Your insights and experiences are highly valuable in addressing this issue effectively.
Stay safe out there! ▪️▪️▪️
submitted by /u/Morphy_exe
[link] [comments]
hacking: security in practice
Quasar
So im trying to build a lab for pentesting, quasar is not downloading the release file. Either one, ive disabled all windows defender options i can think of in my VM.....yet i get the feeling the AV is blocking the release files i need to complete installation. Anybody know about this? I tried compiling in Virtual Studio..still not luck. Pls halp
submitted by /u/Cma1234
[link] [comments]
Quasar
So im trying to build a lab for pentesting, quasar is not downloading the release file. Either one, ive disabled all windows defender options i can think of in my VM.....yet i get the feeling the AV is blocking the release files i need to complete installation. Anybody know about this? I tried compiling in Virtual Studio..still not luck. Pls halp
submitted by /u/Cma1234
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community