hacking: security in practice
Looking for good sources of general computer/hacking/history knowledge
Hello! I am wondering if anyone can offer some good sources (books / movies / podcasts etc.) for any of the following topics:
* information on large scale exploitations that altered the way computer systems are built
* general history of computers and hacking
* information on how common/known hacks work on a lower level (cross site scripting, ddos, phishing, wifi hacks etc.)
I've been learning a lot about programming in the past couple months, and just recently learned about penetration testing and that got me wondering how a lot of computer things might work on a lower level, and how people have come to exploit those things. Would be open to anything you thought might fit in that vein.
Thanks in advance! : D
submitted by /u/AmoryVain
[link] [comments]
Looking for good sources of general computer/hacking/history knowledge
Hello! I am wondering if anyone can offer some good sources (books / movies / podcasts etc.) for any of the following topics:
* information on large scale exploitations that altered the way computer systems are built
* general history of computers and hacking
* information on how common/known hacks work on a lower level (cross site scripting, ddos, phishing, wifi hacks etc.)
I've been learning a lot about programming in the past couple months, and just recently learned about penetration testing and that got me wondering how a lot of computer things might work on a lower level, and how people have come to exploit those things. Would be open to anything you thought might fit in that vein.
Thanks in advance! : D
submitted by /u/AmoryVain
[link] [comments]
reddit
Looking for good sources of general computer/hacking/history knowledge
Hello! I am wondering if anyone can offer some good sources (books / movies / podcasts etc.) for any of the following topics: * information on...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
TryHackMe subscription giveaway by THREAT CON in honor of pride month
To celebrate pride month THREAT CON is giving away away 5 vouchers for one month premium subscription of TryHackMe. To participate in the giveaway like and share the post from any of their social media channels and make sure you're following them.
Social media links:
https://twitter.com/THREAT_CON/status/1407321077345181697
https://www.facebook.com/threatcon/photos/a.1086739991506847/1882118308635674/
https://www.linkedin.com/posts/threat-con_pride-pridemonth-threatcon2021-activity-6813088108872032256-s6QS
submitted by /u/itsplane
[link] [comments]
TryHackMe subscription giveaway by THREAT CON in honor of pride month
To celebrate pride month THREAT CON is giving away away 5 vouchers for one month premium subscription of TryHackMe. To participate in the giveaway like and share the post from any of their social media channels and make sure you're following them.
Social media links:
https://twitter.com/THREAT_CON/status/1407321077345181697
https://www.facebook.com/threatcon/photos/a.1086739991506847/1882118308635674/
https://www.linkedin.com/posts/threat-con_pride-pridemonth-threatcon2021-activity-6813088108872032256-s6QS
submitted by /u/itsplane
[link] [comments]
XSS that requires specific request header
https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/
<!-- SC_OFF -->I just came across a reflected XSS by URL injection. The catch is that the server expects a Content-Type header in the request, so if I simply click on the malicious URL, the server rejects the request and does not reflect the payload. Is the XSS exploitable on a third party in this case? <!-- SC_ON --> submitted by /u/Lupius (https://www.reddit.com/user/Lupius)
[link] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/)
https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/
<!-- SC_OFF -->I just came across a reflected XSS by URL injection. The catch is that the server expects a Content-Type header in the request, so if I simply click on the malicious URL, the server rejects the request and does not reflect the payload. Is the XSS exploitable on a third party in this case? <!-- SC_ON --> submitted by /u/Lupius (https://www.reddit.com/user/Lupius)
[link] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/)
Cracking Encrypted Credit Card Numbers Exposed By API
https://infosecwriteups.com/cracking-encrypted-credit-card-numbers-exposed-by-api-977c6f7b996f?source=rss------bug_bounty-5
https://infosecwriteups.com/cracking-encrypted-credit-card-numbers-exposed-by-api-977c6f7b996f?source=rss------bug_bounty-5
I found an API that exposed encrypted credit card numbers. Here’s how I cracked them to reveal the full card details.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cracking-encrypted-credit-card-numbers-exposed-by-api-977c6f7b996f?source=rss------bug_bounty-5)
information leakage
https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5
What is information disclosure?Continue reading on Medium » (https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5)
https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5
What is information disclosure?Continue reading on Medium » (https://0xprabir.medium.com/information-leakage-8d542cbe419?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
NSA Funds Development & Release of D3FEND Framework
The framework, now available through MITRE, provides countermeasures to attacks.
NSA Funds Development & Release of D3FEND Framework
The framework, now available through MITRE, provides countermeasures to attacks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Identity Eclipses Malware Detection at RSAC Startup Competition
All 10 finalists in the Innovation Sandbox were focused on identity, rather than security's mainstay for the last 20 years: Malware detection.
Identity Eclipses Malware Detection at RSAC Startup Competition
All 10 finalists in the Innovation Sandbox were focused on identity, rather than security's mainstay for the last 20 years: Malware detection.
Insecure Deserialization ?
Hello and welcome to this blog, in this blog we’re going to discover what insecure deserialization is ? we’re going to take some code…
Read more...
Hello and welcome to this blog, in this blog we’re going to discover what insecure deserialization is ? we’re going to take some code…
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Help finding a talk about Stuxnet
Hi, I remember having seen a video talking about Stuxnet, although I kind of remember it was named differently or something, I remember something as "fire storm" or something like that.
I could almost swear that it was a TED talk by Mikko Hypponen but I kind of fast checked his three TED talks and didn't find what I wanted, he just barely mentions it in his Virus talk.
What I am looking for is specifically is a video that talked about how the creators of this virus were able to target the Iranian (or somewhere's government) reactors by using photos (like the ones in this article) they took and posted online, thus giving the attackers important information about the arrays in the nuclear plant.
I think it's a great video that explains very clearly the risks of information leaks and the lengths an attacker will go to harm a system.
Thanks in advance.
submitted by /u/pinchitony
[link] [comments]
Help finding a talk about Stuxnet
Hi, I remember having seen a video talking about Stuxnet, although I kind of remember it was named differently or something, I remember something as "fire storm" or something like that.
I could almost swear that it was a TED talk by Mikko Hypponen but I kind of fast checked his three TED talks and didn't find what I wanted, he just barely mentions it in his Virus talk.
What I am looking for is specifically is a video that talked about how the creators of this virus were able to target the Iranian (or somewhere's government) reactors by using photos (like the ones in this article) they took and posted online, thus giving the attackers important information about the arrays in the nuclear plant.
I think it's a great video that explains very clearly the risks of information leaks and the lengths an attacker will go to harm a system.
Thanks in advance.
submitted by /u/pinchitony
[link] [comments]
Dirb question
https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/
I have run dirb in kali Linux against a domain and it has brought up a lot of results. Some include /.passwd and such as /.ssh. Is there any way to access this or is it blocked by a firewall? I am just trying to understand submitted by /u/001011001101 (https://www.reddit.com/user/001011001101)
[link] (https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/
I have run dirb in kali Linux against a domain and it has brought up a lot of results. Some include /.passwd and such as /.ssh. Is there any way to access this or is it blocked by a firewall? I am just trying to understand submitted by /u/001011001101 (https://www.reddit.com/user/001011001101)
[link] (https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/Pentesting - Dirb question
0 votes and 0 comments so far on Reddit
HashCheck - Tool To Assist In The Search For Leaked Passwords
http://www.kitploit.com/2021/06/hashcheck-tool-to-assist-in-search-for.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/06/hashcheck-tool-to-assist-in-search-for.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
HashCheck - Tool To Assist In The Search For Leaked Passwords