Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
make sqlmap show the sql commands that it used to dump the tables
https://www.reddit.com/r/Pentesting/comments/o0yp6b/make_sqlmap_show_the_sql_commands_that_it_used_to/

im a newbie in sql injection and im learning how to use sqlmap. i first harvested the post request from burpsuite and saved it in a file and i passed that file into sqlmap using sqlmap -r -p username after running that and said yes to all the prompts. it said it it was vulnerable to bool based, error-based and and/or time based blind sql injection and it showed me the different sql commands that it used to confrm that next that i did was to use the --dump to get all the contents of the database sqlmap -r -p username --dump after that it showed me the tables that was dumped. im curious whether i can make sqlmap show the sql commands that it used to dump the tables? It would really help me in learning sql injection more thanks submitted by /u/darkalimdor18 (https://www.reddit.com/user/darkalimdor18)
[link] (https://www.reddit.com/r/Pentesting/comments/o0yp6b/make_sqlmap_show_the_sql_commands_that_it_used_to/) [comments] (https://www.reddit.com/r/Pentesting/comments/o0yp6b/make_sqlmap_show_the_sql_commands_that_it_used_to/)

___________________________
@hacking_Attack
@Hacking_Video
Deep Web
Is there a reputable paid service for hosting an onion site for legal purposes?

This is going to sound completely dumb, but is there a reputable paid service that does all the back end hosting for onion sites for legal file hosting?

For things like digital art or software you made and want to share without dealing with pansy's who are too scared to visit the dark web.

submitted by /u/Fuzz_Lord
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple Hurries Patches for Safari Bugs Under Active Attack

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Apple Hurries Patches for Safari Bugs Under Active AttackPost Views: 52
Reading Time: 1 Minute
Apple issued two out-of-band security fixes for its Safari web browser, fixing zero-day vulnerabilities that “may have been actively exploited,” according to a Monday security bulletin by the company.
The bugs affect sixth-generation Apple iPhones, iPads and iPod touch model hardware, released between 2013 and 2018.

“Apple is aware of a report that this issue may have been actively exploited,” the company wrote. Technical details of the two bugs, Apple said, will not be released, “until an investigation has occurred and patches or releases are available.”

Both bugs are tied to Apple’s Safari browser and the underlying iOS code, called WebKit, which is responsible for rendering web pages. Apple is crediting the discovery of both bugs (CVE-2021-30761 and CVE-2021-30762) to an anonymous researcher.

The patch, iOS 12.5.4, is available for download.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries Memory Corruption Bug: CVE-2021-30761One of the bugs patched by Apple addresses a “memory corruption issue” and improves the Apple WebKit state management.

“State management refers to the management of the state of one or more user interface controls such as text fields, OK buttons, radio buttons, etc. in a graphical user interface,” according to a technical description of the term.

According to Apple, the patch for the bug, logged as CVE-2012-30761, addresses a bug found in iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation). This range of hardware was released between 2013 and 2018.
See Also: Offensive Security Tool: CloudFail Use After Free Flaw: CVE-2021-30762The second flaw was identified as a use-after-free bug, which is a type of memory corruption vulnerability. The bug, tracked as CVE-20121-30762, allows an attacker to execute code on targeted devices. According to Apple, adversaries may be exploiting this flaw on unpatched devices. In its advisory Apple wrote: “Impact: Processed maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.”

Apple added that the “use-after-free issue was addressed with improved memory management.”

“[A] use-after-free is a vulnerability [is] related to incorrect use of dynamic memory during program operation. If after freeing a memory location, a program does not clear the pointer to that memory, an attacker can use the error to hack the program,” according to a Kaspersky description of this type of bug. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat The iOS patch, distributed as a iOS 12.5.4 update, is for the same model hardware as above: iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation).

Apple is not releasing any additional details pertaining to these vulneraries.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Microsoft-Teams-e1623702241390-90x90.png Microsoft Teams: Very Bad Tabs Could Have Led to BEC1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/FIFA-21-90x90.jpg Hackers Steal FIFA 21 Source Code, Tools in EA Breach2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untit[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple Hurries Patches for Safari Bugs Under Active Attack https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Apple Hurries Patches for Safari Bugs Under Active AttackPost Views:…
led-design-3-90x90.png Chrome Browser Bug Under Active Attack – Update your chrome now5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-90x90.png Google PPC Ads Used to Deliver Infostealers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-90x90.png Researchers Uncover Hacking Operations Targeting Government Entities in South Korea2 weeks ago
The post Apple Hurries Patches for Safari Bugs Under Active Attack first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Does anyone know if a good tutorial on how to write a simple keylogger that saves to a text file?

I just started learning java and I think making a key logger would be a really fun project. It might be a little hard for me because I certainly don't know everything about java but I'm just looking for a good tutorial on what to do. Thanks :)

submitted by /u/catanddoglover22
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Hai , I think I might be hacked or atleast a trojan crept into my system!

Okay , I was watching YouTube on my PC , in one of the videos , I accidentally clicked a link that come at the end of the video. It redirected me to a new window and closed itself . I ignored it . Now when I restart my computer , a file or some kind of popup open and closes itself in the blink of an eye and after that everything looks normal. This is the first that happened. My system specs are as follow :

Laptop : HP Omen Ryzen 5 OS : Windows 10 Browser: Firefox ( With Adblock)

Is there a chance I got hacked or a virus entered my system??

If this is the wrong sub , then pls suggest an appropriate sub!

Thanks in Advance..

submitted by /u/Chanti239
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Thank You for the Introduction. This is some criticism on it.

This is the introduction to the sub:

https://old.reddit.com/r/hacking/comments/a3oicn/how_to_start_hacking_the_ultimate_two_path_guide/

The post is archived. No new responses are allowed. People might want to point out new information to include.

First Paragraph Last Section:

This isn't for your reckless amusement and shot at recognition with your friends. This is for the betterment of human civilisation. Use your knowledge to solve real-world issues.

Well said. This is not why most are interested in hacking. It is to gain an advantage, a coup, to find something out, to undo a wrong. Could be to fix (teachers often unfairly grade students) school grades. This happens, especially if one is a minority, and the teacher has a bias, it can tick teachers off when the students are smarter and more confident. Or an employer makes payroll mistakes, or pays one less than others for the same work (this is a huge problem that goes back many years). Or from browsing the internet some of the targeted advertisements seem offputting and insulting, one might want to examine the file that is used to serve ads, and to tinker with it to get ads that are entertaining and enjoyable to watch. There likely are many more examples on why someone would get into hacking (aside from stealing which is a big reason).

So while this part of the introduction is well written it is disingenuous. The intention of hacking is not information security, it is to find out stuff, to 'count coup', to interfere in the activity of the other, to monitor the other, to redress issues, to hurt the other, it is not to improve the other (now there could be some do good know it alls that do this last bit, and this is a problem who the fuck tries to improve the other???.

If what was meant was this sub's purpose is 'information security', then make that clear. Do not lie about the reasons for hacking to those interested in finding out about hacking.

Third Paragraph and Fourth Paragraph.

Kali is boring. Better to start with renaming your computer PaulRevere and ping the pentagon for a few weeks. THey might send something your way without putting you on a watch list. Do not do this unless you are an American, find some other way to start. Back to Kali. Kali can be done by oneself. What is described in the 'team hacking section' might be fun. It requires knowledge that using Kali might provide.

I suggest you rewrite the introduction with these points in mind.

Again, it is well written, yet disingenuous.

VT

submitted by /u/vteead
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
slopShell : The Only Php Webshell You Need

slopShell is the only Php Webshell You Need . Since I derped, and forgot to talk about usage. Here goes. For this shell to work, you need 2 things, a victim that allows php file upload(yourself, in an educational environment) and a way to send http requests to this webshell. Thank you for all the […]

The post slopShell : The Only Php Webshell You Need appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video