Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Hey guys, there’s someone impersonating me on whatsapp. What are my options to track them down?

Hi, so i have the number that they’re using and i can also get ahold of their IP adress by using grabify on them. But I don’t know what else I could do. I know their rough location and maybe even their name if i get some info

submitted by /u/amaan-jawed
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Red-Shadow : Lightspin AWS IAM Vulnerability Scanner

Red-Shadow is a tool for Lightspin AWS IAM Vulnerability Scanner. Scan your AWS IAM Configuration for shadow admins in AWS IAM based on misconfigured deny policies not affecting users in groups discovered by Lightspin’s Security Research Team. The tool detects the misconfigurations in the following IAM Objects: Managed Policies Users Inline Policies Groups Inline Policies […]

The post Red-Shadow : Lightspin AWS IAM Vulnerability Scanner appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Installation
You need Go (https://golang.org/). Linux git clone https://github.com/edoardottt/cariddi.git cd cariddi go get make linux (to install) make unlinux (to uninstall) Or in one line: git clone https://github.com/edoardottt/cariddi.git; cd cariddi; go get; make linux Windows (executable works only in cariddi folder.) git clone https://github.com/edoardottt/cariddi.git cd cariddi go get .\make.bat windows (to install) .\make.bat unwindows (to uninstall)
Get Started
cariddi -h prints the help in the command line. Usage of cariddi:
-c int
Concurrency level. (default 20)
-cache
Use the .cariddi_cache folder as cache.
-d int
Delay between a page crawled and another.
-e Hunt for juicy endpoints.
-ef string
Use an external file (txt, one per line) to use custom parameters for endpoints hunting.
-examples
Print the examples.
-ext int
Hunt for juicy file extensions. Integer from 1(juicy) to 7(not juicy).
-h Print the help.
-i string
Ignore the URL containing at least one of the elements of this array.
-it string
Ignore the URL containing at least one of the lines of this file.
-oh string
Write the output into an HTML file.
-ot string
Write the output into a TXT file.
-plain
Print only the results.
-s Hunt for secrets.
-sf string
Use an external file (txt, one per line) to use custom regexes for s ecrets hunting.
-version
Print the version.

Examples
cariddi -version (Print the version) cariddi -h (Print the help) cariddi -examples (Print the examples) cat urls | cariddi -s (Hunt for secrets) cat urls | cariddi -d 2 (2 seconds between a page crawled and another) cat urls | cariddi -c 200 (Set the concurrency level to 200) cat urls | cariddi -e (Hunt for juicy endpoints) cat urls | cariddi -plain (Print only useful things) cat urls | cariddi -ot target_name (Results in txt file) cat urls | cariddi -oh target_name (Results in html file) cat urls | cariddi -ext 2 (Hunt for juicy (level 2 of 7) files) cat urls | cariddi -e -ef endpoints_file (Hunt for custom endpoints) cat urls | cariddi -s -sf secrets_file (Hunt for custom secrets) cat urls | cariddi -i forum,blog,community,open (Ignore urls containing these words) cat urls | cariddi -it ignore_file (Ignore urls containing at least one line in the input file) cat urls | cariddi -cache (Use the .cariddi_cache folder as cache.) For Windows (https://www.kitploit.com/search/label/Windows) use powershell.exe -Command "cat urls | .\cariddi.exe"
Contributing

Just open an issue/pull request. See also CONTRIBUTING.md (https://github.com/edoardottt/cariddi/blob/master/CONTRIBUTING.md) and CODE OF CONDUCT.md (https://github.com/edoardottt/cariddi/blob/master/CODE_OF_CONDUCT.md) Help me building this! A special thanks to: zricethezav (https://github.com/zricethezav/gitleaks/blob/master/config/default.go) To do: Tests Tor support Proxy support Ignore specific types of urls Plain output (print only results) HTML output Build an Input Struct and use it as parameter Output color Endpoints (https://www.kitploit.com/search/label/Endpoints) (parameters) scan Secrets (https://www.kitploit.com/search/label/Secrets) scan Extensions scan TXT output
Download Cariddi (https://github.com/edoardottt/cariddi)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there a website when you can review old exploits?

I understand that zero day exploits get patched overtime but that's only if the latest update is installed. I remember an old windows exploit where you could get into the notepad app with the shift key from a locked computer and get admin rights.

I have an old laptop which I want to try and hack for a hopeful pen testing career. So is there a site where you can see exploits, when they were patched etc.

If you're unsure but have some suggestions for good websites about cybersecurity and tech such as theregister that would also be helpful.

submitted by /u/techtom10
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Gorsair : Hacks Its Way Into Remote Docker Containers That Expose Their APIs

Gorsair is a penetration testing tool for discovering and remotely accessing Docker APIs from vulnerable Docker containers. Once it has access to the docker daemon, you can use Gorsair to directly execute commands on remote containers. Exposing the docker API on the internet is a tremendous risk, as it can let malicious agents get information […]

The post Gorsair : Hacks Its Way Into Remote Docker Containers That Expose Their APIs appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
[FREE GIFT] Offensive Hacking Unfolded Course Giveaway Without Any Catch
https://www.reddit.com/r/redteamsec/comments/og8zuj/free_gift_offensive_hacking_unfolded_course/

Thank you very much everyone for the amazing response to my SQL Injection Course. I am grateful to each one of you for making this the topmost SQLi Course on Udemy. Today, I want to do another giveaway. This one is of my biggest & newest course so far: Offensive Hacking Unfolded! I am doing this because I want to give back to the community that helped me whenever I was in a problem, no matter how silly question I had, there were always people who wanted to help me without expecting anything for themselves in between. This course is a small gift for them and everyone by my side. [There's no catch in this and don't even get anyone's email. I genuinely want to give away this.] Here's the free link: https://www.udemy.com/course/offensive-hacking-unfolded/?couponCode=OHU-FREE-JULY-2021 Note: It's only valid for 3 days due to udemy limits, so use quick! I worked for many months to create this course. It's going to be over 17+ hours in a few months. I hope you will enjoy this :) ~Avinash Yadav (Remember this name... New courses coming soon for free of-course. Haha!) submitted by /u/avinash986 (https://www.reddit.com/user/avinash986)
[link] (https://www.reddit.com/r/redteamsec/comments/og8zuj/free_gift_offensive_hacking_unfolded_course/) [comments] (https://www.reddit.com/r/redteamsec/comments/og8zuj/free_gift_offensive_hacking_unfolded_course/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Cariddi - Take A List Of Domains, Crawl Urls And Scan For Endpoints, Secrets, Api Keys, File Extensions, Tokens And More...

http://3.bp.blogspot.com/-OklvPqP3nfM/YNkPIeB6wFI/AAAAAAAAepE/mopor0H84ds4rt5u25idXAdquuTVih68wCK4BGAYYCw/w640-h102/cariddi_1_logo-715640.png Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more...Previewhttps://1.bp.blogspot.com/-llbDqYMlNpY/YN5pey68plI/AAAAAAAAfko/2waKpPXewQYx8YGboP-bNT6pXUy5xVx-QCNcBGAsYHQ/w640-h344/Cariddi.png InstallationYou need Go.

*
Linux

* git clone https://github.com/edoardottt/cariddi.git* cd cariddi* go get* make linux(to install)
* make unlinux(to uninstall)

Or in one line: git clone https://github.com/edoardottt/cariddi.git; cd cariddi; go get; make linux*
Windows (executable works only in cariddi folder.)

* git clone https://github.com/edoardottt/cariddi.git* cd cariddi* go get* .\make.bat windows(to install)
* .\make.bat unwindows(to uninstall) Get Startedcariddi -hprints the help in the command line. Usage of cariddi:
-c int
Concurrency level. (default 20)
-cache
Use the .cariddi_cache folder as cache.
-d int
Delay between a page crawled and another.
-e Hunt for juicy endpoints.
-ef string
Use an external file (txt, one per line) to use custom parameters for endpoints hunting.
-examples
Print the examples.
-ext int
Hunt for juicy file extensions. Integer from 1(juicy) to 7(not juicy).
-h Print the help.
-i string
Ignore the URL containing at least one of the elements of this array.
-it string
Ignore the URL containing at least one of the lines of this file.
-oh string
Write the output into an HTML file.
-ot string
Write the output into a TXT file.
-plain
Print only the results.
-s Hunt for secrets.
-sf string
Use an external file (txt, one per line) to use custom regexes for s ecrets hunting.
-version
Print the version.
Examples* cariddi -version(Print the version)

* cariddi -h(Print the help)

* cariddi -examples(Print the examples)

* cat urls | cariddi -s(Hunt for secrets)

* cat urls | cariddi -d 2(2 seconds between a page crawled and another)

* cat urls | cariddi -c 200(Set the concurrency level to 200)

* cat urls | cariddi -e(Hunt for juicy endpoints)

* cat urls | cariddi -plain(Print only useful things)

* cat urls | cariddi -ot target_name(Results in txt file)

* cat urls | cariddi -oh target_name(Results in html file)

* cat urls | cariddi -ext 2(Hunt for juicy (level 2 of 7) files)

* cat urls | cariddi -e -ef endpoints_file(Hunt for custom endpoints)

* cat urls | cariddi -s -sf secrets_file(Hunt for custom secrets)

* cat urls | cariddi -i forum,blog,community,open(Ignore urls containing these words)

* cat urls | cariddi -it ignore_file(Ignore urls containing at least one line in the input file)

* cat urls | cariddi -cache(Use the .cariddi_cache folder as cache.)

*
For Windows use powershell.exe -Command "cat urls | .\cariddi.exe"Contributing Just open an issue/pull request. See also CONTRIBUTING.md and CODE OF CONDUCT.md

Help me building this!

A special thanks to:

* zricethezav

To do:

*
Tests

*
Tor support

*
Proxy support

*
Ignore specific types of urls

*
Plain output (print only results)

*
HTML output

*
Build an Input Struct and use it as parameter

*
Output color

* Endpoints (parameters) scan[...]

___________________________
@hacking_Attack
@Hacking_Video