Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Intelbras
https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/

<!-- SC_OFF -->Prologue: I'm probably posting on the wrong subreddit, but hoping for a friendly go to /r/elsewhere (https://www.reddit.com/r/elsewhere) instead. The largest consumer brand for home security, networking, etc in Brazil is Intelbras. I myself have intelbras for my home security. Where it all began My first "hum this is odd" moment was when I noticed that I can view my cameras via the http-webview, and they'll last indefinitely as long as I don't click anything. If I click something, the "session will expire" and I'll get kicked out, but until then, I can watch the cameras until the end of time. Just not modify anything. The second clue was when I turned on a couple of PCs i keep turned off for months at a time, and on both Mac and PC, launching "Intelbras SIM Player" I got the error message "Your access credentials could not be validated.", "If you wish you continue, you will have access to your devices without being able to edit them."* Which seemingly sounds a lot like "You don't have access, but we'll let you view the cameras anyways" My motives Don't really have any. I think I'd have fun with this if it fell within my area of competence, but as it does not, I figure I'd at the very least leave the breadcrumbs for someone else who might care to. *) I have a screenshot, not that it provides anything. Didn't run wireshark or anything similar at the time to capture network traffic. Windows PC eventually got kicked out, the Macbook can still view my cameras without any login. <!-- SC_ON --> submitted by /u/EvilAndStuff492 (https://www.reddit.com/user/EvilAndStuff492)
[link] (https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/)
Help please
https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/

<!-- SC_OFF -->I know this subreddit its not to seek hackers for hire and such but I need desperately some help with one of my accounts on xbox, my account on xbox got hacked I didn't clicked on anything suspicious or answered a weird sms I even had the Microsoft authenticator on another phone that I don't use any more I know thats bad but I didn't know this could go so bad, and the bastard that took my account changed my email, and phone number to his even the recovery email I chatted with web support but it's not use they are telling me that my account doesn't exist anymore but friends can still see my account disconnected obviously a day ago, and also I tried signing with the mail of the hacker and it works it ask me for a password and when I click on I forget password the recovery email now it's a disposable email ending in @ polo something, and I'm at my limit now idk what else to do if anyone could help me or know something please let me know all of my 100 + games I bought with my own money it's gone <!-- SC_ON -->
[link] (https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/)
New rate limit bypass , other won’t say

Description:Continue reading on Medium »
Read more...
Zero-Day Detection Rule Builder: 12 Tools Every Cybersecurity Pro Should Master

What if I told you most data breaches start with a vulnerability no one’s even seen before? Zero-days don’t wait for patch notes. The…Continue reading on Medium »
Read more...
IDOR: The Easiest High-Severity Bug Most Hunters Still Miss

(Bug Bounty Tutorial Series — Part 1)Continue reading on OSINT Team »
Read more...
XBow and the “AI Takeover”: Why You Can Put Down the Goat Farming Manual

Let’s be real: we’ve all had that 3:00 AM moment. You’re staring at a target, your third empty energy drink is judging you from the desk…Continue reading on Medium »
Read more...
From Breaking Systems to Defending Them: My SOC Learning Journey Begins (Day 01)

Day 01: Introduction to SOC and Its Role in the Blue TeamContinue reading on Medium »
Read more...
Clawdbot: The AI Assistant That “Does Everything” — And Why That’s the Problem

Clawdbot went viral for a simple reason: it promises an AI assistant that actually does things.Continue reading on Medium »
Read more...
What if I told you most data breaches start with a vulnerability no one’s even seen before? Zero-days don’t wait for patch notes. The…Continue reading on Medium » (https://medium.com/@verylazytech/zero-day-detection-rule-builder-12-tools-every-cybersecurity-pro-should-master-b205a40f85dc?source=rss------bug_bounty-5)
How a Temporary Invite Led to a Permanent Billing Takeover

بسم الله الرحمن الرحيم اللهم صلِّ على سيدنا محمد ﷺ وعلى آله وصحبه وسلم تسليمًا كثيرًاContinue reading on Medium »
Read more...
Account Takeover via Weak Password Reset Token Validation

A Case Study in Insecure Token DesignContinue reading on System Weakness »
Read more...
Breaking the Gate: How We Bypassed Email Verification on a Major Platform

A Story of JWT Token Rotation and Rate Limit EvasionContinue reading on Medium »
Read more...