Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Swift-Attack - Unit Tests For Blue Teams To Aid With Building Detections For Some Common macOS Post Exploitation Methods http://2.bp.blogspot.com/-aWl6BmFOZho/YNDQ4oMVGeI/AAAAAAAAcic/FaLbGO4M5tMlWl1o3EnecgPw5Y6Yr0NyACK4BGAYYCw/w640…
ther repo of mine at https://github.com/cedowens/MacC2 to test with obfuscated macros. To use, just simply paste the contents of "macro.txt" into an office Doc, save as a macro enabled document or as 97-2004 document format (ex: .doc, .xls, etc.), and click "Enable Macros" when opening the doc to execute.
*
Installer Package: I included TestInstaller.pkg file to test for detections around a basic installer package. This installer package includes a preinstall script which runs in bash and drops com.simple.agent.plist to /Library/LaunchDaemons/ and drops test.js (simple popup prompt) to /Library/Application Support/. The com.simple.agent.plist file simply runs osascript against /Library/Application Support/test.js. It also includes a postinstall script which runs in bash and loads the com.simple.agent.plis using launchctl load. While holding the Control button click Open on TestInstaller.pkg to run it. TestInstaller.pkg will drop the aforementioned files as root.
*
CVE-2021-30657 Bypass Payloads: Two sample payloads (both make curl requests to localhost when detonated) to test two different types of payloads that abuse cve-2021-30657. More info here: https://cedowens.medium.com/macos-gatekeeper-bypass-2021-edition-5256a2955508 Download Swift-Attack
*
Installer Package: I included TestInstaller.pkg file to test for detections around a basic installer package. This installer package includes a preinstall script which runs in bash and drops com.simple.agent.plist to /Library/LaunchDaemons/ and drops test.js (simple popup prompt) to /Library/Application Support/. The com.simple.agent.plist file simply runs osascript against /Library/Application Support/test.js. It also includes a postinstall script which runs in bash and loads the com.simple.agent.plis using launchctl load. While holding the Control button click Open on TestInstaller.pkg to run it. TestInstaller.pkg will drop the aforementioned files as root.
*
CVE-2021-30657 Bypass Payloads: Two sample payloads (both make curl requests to localhost when detonated) to test two different types of payloads that abuse cve-2021-30657. More info here: https://cedowens.medium.com/macos-gatekeeper-bypass-2021-edition-5256a2955508 Download Swift-Attack
Install Go Lang on Ubuntu Server
▶ Visit : https://golang.org/dl/ ▶ Download : wget https://golang.org/dl/go1.16.5.linux-amd64.tar.gz ▶ Extract : rm -rf /usr/local/go &&…Continue reading on Medium »
Read more...
▶ Visit : https://golang.org/dl/ ▶ Download : wget https://golang.org/dl/go1.16.5.linux-amd64.tar.gz ▶ Extract : rm -rf /usr/local/go &&…Continue reading on Medium »
Read more...
what is bug bounty ? How do you become a bug bounty? - (B)-HACKER
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Testnet Update II
Last Friday, we deployed on Mumbai (Polygon Testnet) and have seen very encouraging user metrics over the past four days. Here’s an updateContinue reading on MonoX »
Read more...
Last Friday, we deployed on Mumbai (Polygon Testnet) and have seen very encouraging user metrics over the past four days. Here’s an updateContinue reading on MonoX »
Read more...
what is bug bounty ? How do you become a bug bounty? - (B)-HACKER
https://biharihacker.medium.com/what-is-bug-bounty-how-do-you-become-a-bug-bounty-b-hacker-5e9aad1f38b7?source=rss------bug_bounty-5
Continue reading on Medium » (https://biharihacker.medium.com/what-is-bug-bounty-how-do-you-become-a-bug-bounty-b-hacker-5e9aad1f38b7?source=rss------bug_bounty-5)
https://biharihacker.medium.com/what-is-bug-bounty-how-do-you-become-a-bug-bounty-b-hacker-5e9aad1f38b7?source=rss------bug_bounty-5
Continue reading on Medium » (https://biharihacker.medium.com/what-is-bug-bounty-how-do-you-become-a-bug-bounty-b-hacker-5e9aad1f38b7?source=rss------bug_bounty-5)
Last Friday, we deployed on Mumbai (Polygon Testnet) and have seen very encouraging user metrics over the past four days. Here’s an updateContinue reading on MonoX » (https://medium.com/monoswap/testnet-update-ii-490c8baf6882?source=rss------bug_bounty-5)
https://b.thumbs.redditmedia.com/mqVZXji2wtfGaW0NrlIEYD5_RIFKxi-OOW-U3n4rWuA.jpg I believe the only thing this criminal wants is to make me get worried and press the file. The file is a .exe file, and there is no blackmailing threat. Thus, this guy ain't getting anything out of this in the first place if I don't press the file.
https://preview.redd.it/4oa9suvxlt671.png?width=1587&format=png&auto=webp&s=bcb6680bc35f95e7367d10252e70e5dc82b76ddf
submitted by /u/GrabThatPencil
[link] [comments]
https://preview.redd.it/4oa9suvxlt671.png?width=1587&format=png&auto=webp&s=bcb6680bc35f95e7367d10252e70e5dc82b76ddf
submitted by /u/GrabThatPencil
[link] [comments]
hacking: security in practice
Where can i start to learn?
Hello I am a business undergrad student looking to get into the world of cybersecurity. My end goal is to become employable in this field at some point down the line. But for starters i cant find any good place to start learning these things. I am currently looking for free sources but please do post sources even if it is priced. Any information is welcome and Thanks in advance.
submitted by /u/notpasingpasta
[link] [comments]
Where can i start to learn?
Hello I am a business undergrad student looking to get into the world of cybersecurity. My end goal is to become employable in this field at some point down the line. But for starters i cant find any good place to start learning these things. I am currently looking for free sources but please do post sources even if it is priced. Any information is welcome and Thanks in advance.
submitted by /u/notpasingpasta
[link] [comments]
reddit
Where can i start to learn?
Hello I am a business undergrad student looking to get into the world of cybersecurity. My end goal is to become employable in this field at some...
hacking: security in practice
Looking for good sources of general computer/hacking/history knowledge
Hello! I am wondering if anyone can offer some good sources (books / movies / podcasts etc.) for any of the following topics:
* information on large scale exploitations that altered the way computer systems are built
* general history of computers and hacking
* information on how common/known hacks work on a lower level (cross site scripting, ddos, phishing, wifi hacks etc.)
I've been learning a lot about programming in the past couple months, and just recently learned about penetration testing and that got me wondering how a lot of computer things might work on a lower level, and how people have come to exploit those things. Would be open to anything you thought might fit in that vein.
Thanks in advance! : D
submitted by /u/AmoryVain
[link] [comments]
Looking for good sources of general computer/hacking/history knowledge
Hello! I am wondering if anyone can offer some good sources (books / movies / podcasts etc.) for any of the following topics:
* information on large scale exploitations that altered the way computer systems are built
* general history of computers and hacking
* information on how common/known hacks work on a lower level (cross site scripting, ddos, phishing, wifi hacks etc.)
I've been learning a lot about programming in the past couple months, and just recently learned about penetration testing and that got me wondering how a lot of computer things might work on a lower level, and how people have come to exploit those things. Would be open to anything you thought might fit in that vein.
Thanks in advance! : D
submitted by /u/AmoryVain
[link] [comments]
reddit
Looking for good sources of general computer/hacking/history knowledge
Hello! I am wondering if anyone can offer some good sources (books / movies / podcasts etc.) for any of the following topics: * information on...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
TryHackMe subscription giveaway by THREAT CON in honor of pride month
To celebrate pride month THREAT CON is giving away away 5 vouchers for one month premium subscription of TryHackMe. To participate in the giveaway like and share the post from any of their social media channels and make sure you're following them.
Social media links:
https://twitter.com/THREAT_CON/status/1407321077345181697
https://www.facebook.com/threatcon/photos/a.1086739991506847/1882118308635674/
https://www.linkedin.com/posts/threat-con_pride-pridemonth-threatcon2021-activity-6813088108872032256-s6QS
submitted by /u/itsplane
[link] [comments]
TryHackMe subscription giveaway by THREAT CON in honor of pride month
To celebrate pride month THREAT CON is giving away away 5 vouchers for one month premium subscription of TryHackMe. To participate in the giveaway like and share the post from any of their social media channels and make sure you're following them.
Social media links:
https://twitter.com/THREAT_CON/status/1407321077345181697
https://www.facebook.com/threatcon/photos/a.1086739991506847/1882118308635674/
https://www.linkedin.com/posts/threat-con_pride-pridemonth-threatcon2021-activity-6813088108872032256-s6QS
submitted by /u/itsplane
[link] [comments]
XSS that requires specific request header
https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/
<!-- SC_OFF -->I just came across a reflected XSS by URL injection. The catch is that the server expects a Content-Type header in the request, so if I simply click on the malicious URL, the server rejects the request and does not reflect the payload. Is the XSS exploitable on a third party in this case? <!-- SC_ON --> submitted by /u/Lupius (https://www.reddit.com/user/Lupius)
[link] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/)
https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/
<!-- SC_OFF -->I just came across a reflected XSS by URL injection. The catch is that the server expects a Content-Type header in the request, so if I simply click on the malicious URL, the server rejects the request and does not reflect the payload. Is the XSS exploitable on a third party in this case? <!-- SC_ON --> submitted by /u/Lupius (https://www.reddit.com/user/Lupius)
[link] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/)
Cracking Encrypted Credit Card Numbers Exposed By API
https://infosecwriteups.com/cracking-encrypted-credit-card-numbers-exposed-by-api-977c6f7b996f?source=rss------bug_bounty-5
https://infosecwriteups.com/cracking-encrypted-credit-card-numbers-exposed-by-api-977c6f7b996f?source=rss------bug_bounty-5
I found an API that exposed encrypted credit card numbers. Here’s how I cracked them to reveal the full card details.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cracking-encrypted-credit-card-numbers-exposed-by-api-977c6f7b996f?source=rss------bug_bounty-5)
information leakage
https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5
What is information disclosure?Continue reading on Medium » (https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5)
https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5
What is information disclosure?Continue reading on Medium » (https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
NSA Funds Development & Release of D3FEND Framework
The framework, now available through MITRE, provides countermeasures to attacks.
NSA Funds Development & Release of D3FEND Framework
The framework, now available through MITRE, provides countermeasures to attacks.