Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Connect to security camera server to view remote camera feeds

My parents are going on vacation and installed security cameras around the house, solely for the purpose of making sure i don't have my girlfriend over (I'm 20 going to school, working full time, am straight edge as can be, wtf?). I'm basically trying to see what the camera feeds are looking at, to make sure i don't have one chilling in my room or somewhere inside the house.

* The server is connected to our router via ethernet and has a single IP address, and the cameras are all connected to that server. Normally, it seems like I'd be able to log in to the server using the server's local IP (expected) but since I don't have the login I'm a bit restricted. Is there a way I can ssh into this server or something (i've tried using ssh to the local IP but it refuses connection)?
* I don't think any kind of brute force attack is possible because the login ip-blocks after 6 attempts (unless I spoof a new address every 6 attempts). Additionally, the server has the option to reset the password using a 'GUID' file, which I'm guessing is a file containing some string that is unique to the server, but this is risking leaving a trail.
* Is there a backdoor on the login page? It looks like there's an angular JS file making several references to userID and password from a scope, and if I can somehow access $scope I can return the values of the username and password which are accessible through the scope.

I'm not terribly versed in this stuff but I am versed in Python and know a bit of linux. I don't want to leave a trail by cutting wires or something. Correct me if I'm wrong, but this is 100% ethical. I'm dealing with abusive parents who I cannot simply talk to about this stuff. Help is greatly appreciated.

submitted by /u/seekingstars
[link] [comments]
Reflected XSS Through Insecure Dynamic Loading

Finding A Unique and Complex Payload To Load Remote ScriptsContinue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
MacHound : An extension to audit Bloodhound collecting and ingesting of Active Directory relationships on MacOS hosts

MacHound is an extension to the Bloodhound audting tool allowing collecting and ingesting of Active Directory relationships on MacOS hosts. MacHound collects information about logged-in users, and administrative group members on Mac machines and ingest the information into the Bloodhound database. In addition to using the HasSession and AdminTo edges, MacHound adds three new edges […]

The post MacHound : An extension to audit Bloodhound collecting and ingesting of Active Directory relationships on MacOS hosts appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Reflected XSS Through Insecure Dynamic Loading

Finding A Unique and Complex Payload To Load Remote ScriptsContinue reading on InfoSec Write-ups »
Read more...
Deep Web
WHM Bullshit

WHM page decides when it wants to work and when it wants to waste my time with a glitched out verification, then when I get there the page won’t fully load and nothing works. Can’t even open the fuckin PGP pages. Anyone have issues with this before ?

submitted by /u/Gonnagetbannedddd
[link] [comments]
Deep Web
Help a newbie

So I want to make a purchase on a website using Tor, and I have to send Bitcoin to an address. Is there any service besides Tor I should be using? How would I go about sending Bitcoin to this address?

submitted by /u/SpecifyingSubs
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Short Write-Ups On P1/Critical Bugs I’ve Submitted to Bounty ProgramsContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/critical-bug-bounty-reports-part-1-6fd9aef4b486?source=rss------bug_bounty-5)