Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
“This write-up highlights the importance of not overlooking any response and how it can sometimes earn you a bounty.”Continue reading on Medium » (https://medium.com/@rajveer_0101/information-disclosure-but-not-in-the-way-you-might-expect-a914479e06cc?source=rss------bug_bounty-5)
How I Found an Unauthenticated XXE That Allowed Arbitrary File Read in NASA

Recently, I uncovered a critical (P1) XXE vulnerability that allowed to read arbitrary files on the server.Continue reading on Medium »
Read more...
ATmega32U4 on Mac
https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/

<!-- SC_OFF -->I've been creating some scripts for an ATmega32U4 for keystroke injection on Windows and Mac for work. The only problem is that on Mac, it tries to do the keyboard setup process because it is not an approved vendor keyboard. Is there a way to update the firmware so that when I plug it in the VID and PID display as an approved / apple keyboard? <!-- SC_ON --> submitted by /u/West_Atmosphere_9601 (https://www.reddit.com/user/West_Atmosphere_9601)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/)
OSCP in 3 years?
https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/

<!-- SC_OFF -->For context, I'm starting my first semester of CS after switching from mechanical engineering next semester. I'm committed to collecting certifications and getting experience before graduation (which will be in 2.5-3 years). My "end goal" is OSCP. If I can graduate with OSCP, I'll be satisfied. I'm new to this field, and I'd like to know how much time is needed to get OSCP from scratch. I'm almost starting from scratch (I started THM 2-3 weeks ago, and started studying for Security+ recently). Is 3 years too ambitious? Or am I being dramatic? I want a general idea of how long it'll take to get to OSCP level. Looking work my way up with certifications in the following order: CompTIA Security+ eJPTv2 PJPT PNPT CEH OSCP+ Some of them will be either fully paid or partially paid by external entities. Is this feasible? Or am I setting myself up for failure/burnout? I feel bitter about "losing" the progress I made in engineering, so I'm determined to work hard and make up for it. <!-- SC_ON --> submitted by /u/AWS_0 (https://www.reddit.com/user/AWS_0)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/)
Analysis of Sensitive Information Vulnerability in Public XML Files

Case Study: WordPress MisconfigurationContinue reading on Medium »
Read more...
Improper SVG Handling in AI Generated Output

بسم الله الرحمن الرحيمContinue reading on Medium »
Read more...
Recently, I uncovered a critical (P1) XXE vulnerability that allowed to read arbitrary files on the server.Continue reading on Medium » (https://medium.com/@thomscoder/how-i-found-an-unauthenticated-xxe-that-allowed-arbitrary-file-read-in-nasa-bfffe24dc24e?source=rss------bug_bounty-5)