Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How I discovered Reflected XSS in GoldAcademy.

First of all, as usual, we need to make some infogatheringContinue reading on Medium »
Read more...
Spidering in Security

Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium »
Read more...
How Web Cache Poisoning via Unkeyed Query Strings Can Lead to Reflected XSS

Write-up Web Cache Poisoning via an Unkeyed Query String.Continue reading on OSINT Team »
Read more...
Uncovering Hidden Signup Pages for Bug Bounty Hunting

While we hunting a bug in a web pentesting,we can able to see only login button.Continue reading on Medium »
Read more...
Game of Active Directory: Penetration Testing an Active Directory Environment (Video)
https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/

<!-- SC_OFF -->https://www.youtube.com/watch?v=J4l-BMG9gTQ Our SVP of Cybersecurity, Jesse Roberts, put together a short breakdown of Active Directory pentesting. Sharing here in case it’s helpful! <!-- SC_ON --> submitted by /u/CompassITCompliance (https://www.reddit.com/user/CompassITCompliance)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/)
Ethical Hacking Assignment - getting root from an IP/Site
https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/

<!-- SC_OFF -->Hi, I am a 4th semester of computer sciences right now and I'm working on my final project, which is getting root access of a site/ip using kali linux, we've attempted to use gobuster and metasploit, however, both methods are considered brute forcing and it simply isn't effective based on our deadline which is in a few days. The system we're trying to take root over uses linux so eternalbblue wouldn't work as well. Any tips on what method we should use. The goal here is to use kali to get the root access of server3.pentest.id (http://server3.pentest.id/) (this is a fake site that my lecturer gave us}. Also we found the vulnerable ports that are open already, there are 2 to be exact. So i guess we need to utilize those open ports. <!-- SC_ON --> submitted by /u/Seraphims-Monody (https://www.reddit.com/user/Seraphims-Monody)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/)
Cracking JWTs: A Bug Bounty Hunting Guide [Part 1]

JWT Authentication Bypass via Unverified and Flawed Signature VerificationContinue reading on InfoSec Write-ups »
Read more...
How I Bypassed a Famous Regional Newspaper’s Subscription Plan By Http Response Manipulation

My article is open to everyone; non-member readers can click this link to read the full text.Continue reading on OSINT Team »
Read more...
Windows Defender E5 auto remediation problem
https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/

<!-- SC_OFF -->During a pentest, the windows test account was found by Defender and later disabled. It seems it also added the account to 2 windows user policy settings - "Deny access to this computer from the network" and "Deny logon through Remote Desktop Services" on each item that was accessed. I don't see any group policy that has this setting added and the local policy has it but is greyed out and I am unable to remove it. Any ideas? Just need to remove it so we can continue testing or if real-world, get the user back to normal access again. <!-- SC_ON --> submitted by /u/Successful_Way_3663 (https://www.reddit.com/user/Successful_Way_3663)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/)
Mastering PHP Wrappers: Concepts, Use Cases, and Security Risks

By ZoningxtrContinue reading on Medium »
Read more...
One month ago, I was looking for bugs in a prop firm platform (I’ve been trading for 3 years and have worked with many of them).
 This…Continue reading on Medium » (https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5)
Spidering in Security
https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5

Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium » (https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5)
Is it possible to be a red teamer with superior degree?
https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/

<!-- SC_OFF -->Im finishing a higher degree of web applications development, but ive noticed that I like too much the cibersecurity area. So I did some research, and red teamer seems to fit the best with what im interested in. But the thing is, do i have real spectations to find a job there without a university degree? I could do my best to get the needed certifications (if my budget allows it), but would it be enough? And if it actually is, could i make it to the top? Im just genuinely asking from ignorance, so i will appreciate constructive answers. <!-- SC_ON --> submitted by /u/Informal-Command-714 (https://www.reddit.com/user/Informal-Command-714)
[link] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/)
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec

👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium »
Read more...
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium » (https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5)