Stored XSS via Invite leading to Mass Account Takeover at Opera.
https://sm4rty.medium.com/stored-xss-via-invite-leading-to-mass-account-takeover-at-opera-a85ed257dd12?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sm4rty.medium.com/stored-xss-via-invite-leading-to-mass-account-takeover-at-opera-a85ed257dd12?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Stored XSS via Invite leading to Mass Account Takeover at Opera.
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…Continue reading on Medium » (https://sm4rty.medium.com/stored-xss-via-invite-leading-to-mass-account-takeover-at-opera-a85ed257dd12?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Stored XSS via Invite leading to Mass Account Takeover at Opera.
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Nebula : Cloud C2 Framework, Which At The Moment Offers Reconnaissance, Enumeration, Exploitation, Post Exploitation On AWS
Nebula is a Cloud and (hopefully) DevOps Penetration Testing framework. It is build with modules for each provider and each functionality. As of April 2021, it only covers AWS, but is currently an ongoing project and hopefully will continue to grow to test GCP, Azure, Kubernetes, Docker, or automation engines like Ansible, Terraform, Chef, etc. […]
The post Nebula : Cloud C2 Framework, Which At The Moment Offers Reconnaissance, Enumeration, Exploitation, Post Exploitation On AWS appeared first on Kali Linux Tutorials.
Nebula : Cloud C2 Framework, Which At The Moment Offers Reconnaissance, Enumeration, Exploitation, Post Exploitation On AWS
Nebula is a Cloud and (hopefully) DevOps Penetration Testing framework. It is build with modules for each provider and each functionality. As of April 2021, it only covers AWS, but is currently an ongoing project and hopefully will continue to grow to test GCP, Azure, Kubernetes, Docker, or automation engines like Ansible, Terraform, Chef, etc. […]
The post Nebula : Cloud C2 Framework, Which At The Moment Offers Reconnaissance, Enumeration, Exploitation, Post Exploitation On AWS appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Neurax : A Framework For Constructing Self-Spreading Binaries
Neurax is a framework that aids in creation of self-spreading software. Requirements go get -u github.com/redcode-labs/Coldfire go get -u github.com/yelinaung/go-haikunator New in v. 2.0 New wordlist mutators + common passwords by country Improvised passive scanning .FastScan option that makes active scans a bit quicker Wordlists are created strictly in-memory NeuraxScan() accepts a callback function instead of channel […]
The post Neurax : A Framework For Constructing Self-Spreading Binaries appeared first on Kali Linux Tutorials.
Neurax : A Framework For Constructing Self-Spreading Binaries
Neurax is a framework that aids in creation of self-spreading software. Requirements go get -u github.com/redcode-labs/Coldfire go get -u github.com/yelinaung/go-haikunator New in v. 2.0 New wordlist mutators + common passwords by country Improvised passive scanning .FastScan option that makes active scans a bit quicker Wordlists are created strictly in-memory NeuraxScan() accepts a callback function instead of channel […]
The post Neurax : A Framework For Constructing Self-Spreading Binaries appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Vulnversity
https://cdn-images-1.medium.com/max/800/1*aonfR0avER0h8gKbZPrVeg.png
This room was mainly focused on active recon, web app attacks, and privilege escalation.
Continue reading on Noteworthy - The Journal Blog »
TryHackMe: Vulnversity
https://cdn-images-1.medium.com/max/800/1*aonfR0avER0h8gKbZPrVeg.png
This room was mainly focused on active recon, web app attacks, and privilege escalation.
Continue reading on Noteworthy - The Journal Blog »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PicoCTF - Stocks [Pwn]
https://cdn-images-1.medium.com/max/840/1*VFwiFRfVA1JdAS7SX5eEAA.png
Stocks is a very easy pwn challenge of PicoCTF.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PicoCTF - Stocks [Pwn]
https://cdn-images-1.medium.com/max/840/1*VFwiFRfVA1JdAS7SX5eEAA.png
Stocks is a very easy pwn challenge of PicoCTF.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PicoCTF - Stocks [Pwn]
Stocks is a very easy pwn challenge of PicoCTF.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Stored XSS via Invite leading to Mass Account Takeover at Opera.
https://cdn-images-1.medium.com/max/2600/1*6s6Ewl-Q0d66HtSYXgFF2g.png
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Stored XSS via Invite leading to Mass Account Takeover at Opera.
https://cdn-images-1.medium.com/max/2600/1*6s6Ewl-Q0d66HtSYXgFF2g.png
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Stored XSS via Invite leading to Mass Account Takeover at Opera.
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Business Email Compromise: Who’s Fault Is It Anyway?
https://cdn-images-1.medium.com/max/750/0*9XXvRubX_4MxCzkg.jpg
Business email compromise is an increasing problem for Australian businesses. Who is [at fault / liable] when a business’ email system is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Business Email Compromise: Who’s Fault Is It Anyway?
https://cdn-images-1.medium.com/max/750/0*9XXvRubX_4MxCzkg.jpg
Business email compromise is an increasing problem for Australian businesses. Who is [at fault / liable] when a business’ email system is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Business Email Compromise: Who’s Fault Is It Anyway?
Business email compromise is an increasing problem for Australian businesses. Who is [at fault / liable] when a business’ email system is…
Stored XSS via Invite leading to Mass Account Takeover at Opera.
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…Continue reading on Medium »
Read more...
Hey Guys!! I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. I hope everyone is safe in the Current Covid-19…Continue reading on Medium »
Read more...
Deep Web
pgp and Tails OS
Hey everyone, been lurking for awhile.
I just wanted to know whether or not its necessary to use pgp when using Tails to browse dw ?
submitted by /u/FrankGriffin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
pgp and Tails OS
Hey everyone, been lurking for awhile.
I just wanted to know whether or not its necessary to use pgp when using Tails to browse dw ?
submitted by /u/FrankGriffin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
pgp and Tails OS
Hey everyone, been lurking for awhile. I just wanted to know whether or not its necessary to use pgp when using Tails to browse dw ?
Ioccheck - A Tool For Simplifying The Process Of Researching IOCs
http://www.kitploit.com/2021/06/ioccheck-tool-for-simplifying-process.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/06/ioccheck-tool-for-simplifying-process.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Ioccheck - A Tool For Simplifying The Process Of Researching IOCs
A tool for simplifying the process of researching file hashes, IP addresses, and other indicators of compromise (https://www.kitploit.com/search/label/Indicators%20of%20Compromise) (IOCs).
Features
Look up hashes across multiple threat intelligence (https://www.kitploit.com/search/label/Threat%20Intelligence) services, from a single command or a few lines of Python. Currenty supports the following services: VirusTotal (https://virustotal.com/) MalwareBazaar (https://bazaar.abuse.ch/) Shodan.io (https://shodan.io/) Planned support: URLhaus (https://urlhaus.abuse.ch/) OTX (https://otx.alienvault.com/) InQuest Labs (https://labs.inquest.net/) MalShare (https://www.malshare.com/) Malpedia (https://malpedia.caad.fkie.fraunhofer.de/) Maltiverse (https://maltiverse.com/)
Quickstart
pip install ioccheck You can also run the code directly git clone https://github.com/ranguli/ioccheck && cd ioccheck
poetry install
Usage
VirusTotal URL: https://virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/ [*] VirusTotal detections: 61 engines (81%) detected this file. ╒══════════════╤════════════╤═══════════════════════════════╕ │ Antivirus (https://www.kitploit.com/search/label/Antivirus) │ Detected │ Result │ ╞══════════════╪════════════╪═══════════════════════════════╡ │ Malwarebytes │ No │ │ ├──────────────┼────────────┼───────────────────────────────┤ │ Avast │ Yes │ EICAR Test-NOT virus!!! │ ├──────────────┼────────────┼───────────────────────────────┤ │ ClamAV │ Yes │ Win.Test.EICAR_HDB-1 │ ├──────────────┼────────────┼───────────────────────────────┤ │ Kaspersky │ Yes │ EICAR-Test-File │ ├──────────────┼────────────┼───────────────────────────────┤ │ BitDefender │ Yes │ EICAR-Test-File (not a virus) │ ├──────────────┼────────────┼───────────────────────────────┤ │ Paloalto │ No │ │ ├──────────────┼────────────┼───────────────────────────────┤ │ TrendMicro │ Yes │ Eicar_test_file │ ├──────────────┼────────────┼───────────────────────────────┤ │ FireEye │ Yes │ EICAR-Test-File (not a virus) │ ├──────────────┼────────────┼───────────────────────────────┤ │ Sophos │ Yes │ EICAR-AV-Test │ ├──────────────┼────────────┼───────────────────────────────┤ │ Microsoft │ Yes │ Virus:DOS/EICAR_Test_File │ ├──────────────┼────────────┼───────────────────────────────┤ │ McAfee │ Yes │ EICAR test file │ ├──────────────┼────────────┼───────────────────────────────┤ │ Fortinet │ Yes │ EICAR_TEST_FILE │ ├──────────────┼────────────┼───────────────────────────────┤ │ AVG │ Yes │ EICAR Test-NOT virus!!! │ ╘══════════════╧════════════╧═══════════════════════════════╛ [*] VirusTotal reputation: 3392 ">➜ ioccheck 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
Checking hash 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f.
[*] Hashing algorithm:
SHA256
[*] VirusTotal URL:
https://virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/
[*] VirusTotal detections:
61 engines (81%) detected this file.
╒══════════════╤════════════╤═══════════════════════════════╕
│ Antivirus │ Detected │ Result │
╞══════════════╪════════════╪═══════════════════════════════╡
│ Malwarebytes │ No │ │
├──────────────┼────────────┼───────────────────────────────┤
│ Avast │ Yes │ EICAR Test-NOT virus!!! │
├──────────────┼────────────┼───────────────────────────────┤
│ ClamAV │ Yes │ Win.Test.EICAR_HDB-1 │
├──────────────┼────────────┼───────────────────────────────┤
___________________________
@hacking_Attack
@Hacking_Video
Features
Look up hashes across multiple threat intelligence (https://www.kitploit.com/search/label/Threat%20Intelligence) services, from a single command or a few lines of Python. Currenty supports the following services: VirusTotal (https://virustotal.com/) MalwareBazaar (https://bazaar.abuse.ch/) Shodan.io (https://shodan.io/) Planned support: URLhaus (https://urlhaus.abuse.ch/) OTX (https://otx.alienvault.com/) InQuest Labs (https://labs.inquest.net/) MalShare (https://www.malshare.com/) Malpedia (https://malpedia.caad.fkie.fraunhofer.de/) Maltiverse (https://maltiverse.com/)
Quickstart
pip install ioccheck You can also run the code directly git clone https://github.com/ranguli/ioccheck && cd ioccheck
poetry install
Usage
VirusTotal URL: https://virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/ [*] VirusTotal detections: 61 engines (81%) detected this file. ╒══════════════╤════════════╤═══════════════════════════════╕ │ Antivirus (https://www.kitploit.com/search/label/Antivirus) │ Detected │ Result │ ╞══════════════╪════════════╪═══════════════════════════════╡ │ Malwarebytes │ No │ │ ├──────────────┼────────────┼───────────────────────────────┤ │ Avast │ Yes │ EICAR Test-NOT virus!!! │ ├──────────────┼────────────┼───────────────────────────────┤ │ ClamAV │ Yes │ Win.Test.EICAR_HDB-1 │ ├──────────────┼────────────┼───────────────────────────────┤ │ Kaspersky │ Yes │ EICAR-Test-File │ ├──────────────┼────────────┼───────────────────────────────┤ │ BitDefender │ Yes │ EICAR-Test-File (not a virus) │ ├──────────────┼────────────┼───────────────────────────────┤ │ Paloalto │ No │ │ ├──────────────┼────────────┼───────────────────────────────┤ │ TrendMicro │ Yes │ Eicar_test_file │ ├──────────────┼────────────┼───────────────────────────────┤ │ FireEye │ Yes │ EICAR-Test-File (not a virus) │ ├──────────────┼────────────┼───────────────────────────────┤ │ Sophos │ Yes │ EICAR-AV-Test │ ├──────────────┼────────────┼───────────────────────────────┤ │ Microsoft │ Yes │ Virus:DOS/EICAR_Test_File │ ├──────────────┼────────────┼───────────────────────────────┤ │ McAfee │ Yes │ EICAR test file │ ├──────────────┼────────────┼───────────────────────────────┤ │ Fortinet │ Yes │ EICAR_TEST_FILE │ ├──────────────┼────────────┼───────────────────────────────┤ │ AVG │ Yes │ EICAR Test-NOT virus!!! │ ╘══════════════╧════════════╧═══════════════════════════════╛ [*] VirusTotal reputation: 3392 ">➜ ioccheck 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
Checking hash 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f.
[*] Hashing algorithm:
SHA256
[*] VirusTotal URL:
https://virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/
[*] VirusTotal detections:
61 engines (81%) detected this file.
╒══════════════╤════════════╤═══════════════════════════════╕
│ Antivirus │ Detected │ Result │
╞══════════════╪════════════╪═══════════════════════════════╡
│ Malwarebytes │ No │ │
├──────────────┼────────────┼───────────────────────────────┤
│ Avast │ Yes │ EICAR Test-NOT virus!!! │
├──────────────┼────────────┼───────────────────────────────┤
│ ClamAV │ Yes │ Win.Test.EICAR_HDB-1 │
├──────────────┼────────────┼───────────────────────────────┤
___________________________
@hacking_Attack
@Hacking_Video