xDai STAKE Hosts $2,000,000 Bug Bounty on Immunefi
Stable payments blockchain xDai STAKE is hosting a $2,000,000 smart contract bug bounty on Immunefi for its OmniBridge project, making it…Continue reading on Immunefi »
Read more...
Stable payments blockchain xDai STAKE is hosting a $2,000,000 smart contract bug bounty on Immunefi for its OmniBridge project, making it…Continue reading on Immunefi »
Read more...
Here Are The 5 Things You Need To Do To Have A Successful Bug Bounty Program
Before founding Inspectiv, I spent about four years building out the security engineering group at Verizon Media. The properties within…Continue reading on Inspectiv »
Read more...
Before founding Inspectiv, I spent about four years building out the security engineering group at Verizon Media. The properties within…Continue reading on Inspectiv »
Read more...
Here Are The 5 Things You Need To Do To Have A Successful Bug Bounty Program
https://blog.inspectiv.com/here-are-the-5-things-you-need-to-do-to-have-a-successful-bug-bounty-program-6c59962ff9ef?source=rss------bug_bounty-5
https://blog.inspectiv.com/here-are-the-5-things-you-need-to-do-to-have-a-successful-bug-bounty-program-6c59962ff9ef?source=rss------bug_bounty-5
Before founding Inspectiv, I spent about four years building out the security engineering group at Verizon Media. The properties within…Continue reading on Inspectiv » (https://blog.inspectiv.com/here-are-the-5-things-you-need-to-do-to-have-a-successful-bug-bounty-program-6c59962ff9ef?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
High-schooler and her mother hacked school records to steal homecoming queen election, police say
https://b.thumbs.redditmedia.com/oWpGhHIhFskDst4jg7yXxlO5ZKVQ7iBm6LG-V4vvP9E.jpg submitted by /u/CrankyBear
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
High-schooler and her mother hacked school records to steal homecoming queen election, police say
https://b.thumbs.redditmedia.com/oWpGhHIhFskDst4jg7yXxlO5ZKVQ7iBm6LG-V4vvP9E.jpg submitted by /u/CrankyBear
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
hacking: security in practice
Is there a way to speed up the decryption of PDF if you have a page?
Hi,
I have a PDF that is encrypted with $pdf$56256-10281*16. It would take years to brute force it (the password is 10-16 long I guess) with hashcat. If I have another PDF with the same first page, is there a way to hack it faster? Is there a way to create a decryption "key" if I know the first page?
Or is there an easier/faster way than brute force? I read about PDFex, but I didn't found a way how to do it or if it does still work.
submitted by /u/ChocoFruit
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
Is there a way to speed up the decryption of PDF if you have a page?
Hi,
I have a PDF that is encrypted with $pdf$56256-10281*16. It would take years to brute force it (the password is 10-16 long I guess) with hashcat. If I have another PDF with the same first page, is there a way to hack it faster? Is there a way to create a decryption "key" if I know the first page?
Or is there an easier/faster way than brute force? I read about PDFex, but I didn't found a way how to do it or if it does still work.
submitted by /u/ChocoFruit
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
reddit
Is there a way to speed up the decryption of PDF if you have a page?
Hi, I have a PDF that is encrypted with $pdf$5*6*256*-1028*1*16. It would take years to brute force it (the password is 10-16 long I guess) with...
hacking: security in practice
Would like some help with a CTF challenge
https://b.thumbs.redditmedia.com/yMT7ZcwgXbns8VWkjPZRzWIYL0HrTQiDyYRb-A_aXNA.jpg First off, i recently started exploring cyber security.
So, i'm trying this CTF challenge where i have to read the flag from a .txt file which i dont have permission to. However, the machine spawns with a program that has SUID, which i know the source code of (atleast i'm assuming, since there was a ExploitMe.c file in the same directory):
At first, i tried changing the source, so that it didn't check for pass == 1. But when i recompile i (obviously in hindsight) loose the SUID on that executable.
Also, an executable called bbsuid has SUID, but it checks for root access upon execution, so i guess that leads to nowhere? :I
I really hope someone can point me in the right direction :)
Picture of C source
submitted by /u/malthemorsing
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
Would like some help with a CTF challenge
https://b.thumbs.redditmedia.com/yMT7ZcwgXbns8VWkjPZRzWIYL0HrTQiDyYRb-A_aXNA.jpg First off, i recently started exploring cyber security.
So, i'm trying this CTF challenge where i have to read the flag from a .txt file which i dont have permission to. However, the machine spawns with a program that has SUID, which i know the source code of (atleast i'm assuming, since there was a ExploitMe.c file in the same directory):
At first, i tried changing the source, so that it didn't check for pass == 1. But when i recompile i (obviously in hindsight) loose the SUID on that executable.
Also, an executable called bbsuid has SUID, but it checks for root access upon execution, so i guess that leads to nowhere? :I
I really hope someone can point me in the right direction :)
Picture of C source
submitted by /u/malthemorsing
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Beware the Package Typosquatting Supply Chain Attack
Attackers are mimicking the names of existing packages on public registries in hopes that users or developers will accidentally download these malicious packages instead of legitimate ones.
Beware the Package Typosquatting Supply Chain Attack
Attackers are mimicking the names of existing packages on public registries in hopes that users or developers will accidentally download these malicious packages instead of legitimate ones.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
FBI: Business Email Compromise Cost $1.8B in 2020
The Internet Crime Complaint Center received a record 791,790 complaints last year, with reported losses exceeding $4.1 billion.
FBI: Business Email Compromise Cost $1.8B in 2020
The Internet Crime Complaint Center received a record 791,790 complaints last year, with reported losses exceeding $4.1 billion.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New CopperStealer Malware Hijacks Social Media Accounts
Proofpoint researchers say it steals logins and spreads more malware.
New CopperStealer Malware Hijacks Social Media Accounts
Proofpoint researchers say it steals logins and spreads more malware.
Port 21, 80 open but can't connect and can't find any running services. What should I do to enumerate and exploit these ports?
https://www.reddit.com/r/Pentesting/comments/m7zr4n/port_21_80_open_but_cant_connect_and_cant_find/
submitted by /u/Manjani (https://www.reddit.com/user/Manjani)
[link] (https://www.reddit.com/r/Pentesting/comments/m7zr4n/port_21_80_open_but_cant_connect_and_cant_find/) [comments] (https://www.reddit.com/r/Pentesting/comments/m7zr4n/port_21_80_open_but_cant_connect_and_cant_find/)
https://www.reddit.com/r/Pentesting/comments/m7zr4n/port_21_80_open_but_cant_connect_and_cant_find/
submitted by /u/Manjani (https://www.reddit.com/user/Manjani)
[link] (https://www.reddit.com/r/Pentesting/comments/m7zr4n/port_21_80_open_but_cant_connect_and_cant_find/) [comments] (https://www.reddit.com/r/Pentesting/comments/m7zr4n/port_21_80_open_but_cant_connect_and_cant_find/)
AnonX - An Encrypted File Transfer Via AES-256-CBC
http://www.kitploit.com/2021/03/anonx-encrypted-file-transfer-via-aes.html
http://www.kitploit.com/2021/03/anonx-encrypted-file-transfer-via-aes.html
An Encrypted File transfer via AES-256-CBC AnonX is an encrypted file uploader and downloader. The uploaded archive lasts for one week and shall remove from the server. AnonX encrypts the directory before uploading it to the server. The download function requires the download id and AES (https://www.kitploit.com/search/label/AES) password to successfully download and decrypt the archive. [+] Max FileSize to Upload = 2GB
Usage
git clone https://github.com/samhaxr/Anonx
chmod +x Anonx.sh
./Anonx.sh
Youtube Tutorial
Credit
Leonardo Taccari (https://github.com/iamleot)
Download AnonX (https://github.com/samhaxr/AnonX)
Usage
git clone https://github.com/samhaxr/Anonx
chmod +x Anonx.sh
./Anonx.sh
Youtube Tutorial
Credit
Leonardo Taccari (https://github.com/iamleot)
Download AnonX (https://github.com/samhaxr/AnonX)
AnonX - An Encrypted File Transfer Via AES-256-CBC
An Encrypted File transfer via AES-256-CBC AnonX is an encrypted file uploader and downloader. The uploaded archive lasts for one week and shall remove from the server. AnonX encrypts the directory before uploading it to the server. The download function requires the download id and AES password to successfully download and decrypt the archive. + Max FileSize to Upload = 2GBUsage git clone https://github.com/samhaxr/Anonxchmod +x Anonx.sh./Anonx.sh Youtube Tutorial Credit Leonardo Taccari Download AnonX
Read more...
An Encrypted File transfer via AES-256-CBC AnonX is an encrypted file uploader and downloader. The uploaded archive lasts for one week and shall remove from the server. AnonX encrypts the directory before uploading it to the server. The download function requires the download id and AES password to successfully download and decrypt the archive. + Max FileSize to Upload = 2GBUsage git clone https://github.com/samhaxr/Anonxchmod +x Anonx.sh./Anonx.sh Youtube Tutorial Credit Leonardo Taccari Download AnonX
Read more...