Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
TryHackMe subscription giveaway by THREAT CON in honor of pride month

To celebrate pride month THREAT CON is giving away away 5 vouchers for one month premium subscription of TryHackMe. To participate in the giveaway like and share the post from any of their social media channels and make sure you're following them.
Social media links:
https://twitter.com/THREAT_CON/status/1407321077345181697
https://www.facebook.com/threatcon/photos/a.1086739991506847/1882118308635674/
https://www.linkedin.com/posts/threat-con_pride-pridemonth-threatcon2021-activity-6813088108872032256-s6QS

submitted by /u/itsplane
[link] [comments]
XSS that requires specific request header
https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/

<!-- SC_OFF -->I just came across a reflected XSS by URL injection. The catch is that the server expects a Content-Type header in the request, so if I simply click on the malicious URL, the server rejects the request and does not reflect the payload. Is the XSS exploitable on a third party in this case? <!-- SC_ON --> submitted by /u/Lupius (https://www.reddit.com/user/Lupius)
[link] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5qj2j/xss_that_requires_specific_request_header/)
I found an API that exposed encrypted credit card numbers. Here’s how I cracked them to reveal the full card details.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cracking-encrypted-credit-card-numbers-exposed-by-api-977c6f7b996f?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
NSA Funds Development & Release of D3FEND Framework

The framework, now available through MITRE, provides countermeasures to attacks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Identity Eclipses Malware Detection at RSAC Startup Competition

All 10 finalists in the Innovation Sandbox were focused on identity, rather than security's mainstay for the last 20 years: Malware detection.
information leakage

What is information disclosure?Continue reading on Medium »
Read more...
Insecure Deserialization ?

Hello and welcome to this blog, in this blog we’re going to discover what insecure deserialization is ? we’re going to take some code…
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Help finding a talk about Stuxnet

Hi, I remember having seen a video talking about Stuxnet, although I kind of remember it was named differently or something, I remember something as "fire storm" or something like that.

I could almost swear that it was a TED talk by Mikko Hypponen but I kind of fast checked his three TED talks and didn't find what I wanted, he just barely mentions it in his Virus talk.

What I am looking for is specifically is a video that talked about how the creators of this virus were able to target the Iranian (or somewhere's government) reactors by using photos (like the ones in this article) they took and posted online, thus giving the attackers important information about the arrays in the nuclear plant.

I think it's a great video that explains very clearly the risks of information leaks and the lengths an attacker will go to harm a system.

Thanks in advance.

submitted by /u/pinchitony
[link] [comments]
Dirb question
https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/

I have run dirb in kali Linux against a domain and it has brought up a lot of results. Some include /.passwd and such as /.ssh. Is there any way to access this or is it blocked by a firewall? I am just trying to understand submitted by /u/001011001101 (https://www.reddit.com/user/001011001101)
[link] (https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5y84s/dirb_question/)

___________________________
@hacking_Attack
@Hacking_Video