Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
siberhareket.com
https://cdn-images-1.medium.com/max/2215/1*I4Q_dmaKUsAeqMVeTYWpqQ.jpeg
Siber Hareket ismiyle 2020 senesiyle yayın hayatına türkçe deep web sitesi olarak başladık, Türk Siber Güvenlik ve Saldırı hack forumu…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
siberhareket.com
https://cdn-images-1.medium.com/max/2215/1*I4Q_dmaKUsAeqMVeTYWpqQ.jpeg
Siber Hareket ismiyle 2020 senesiyle yayın hayatına türkçe deep web sitesi olarak başladık, Türk Siber Güvenlik ve Saldırı hack forumu…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
siberhareket.com
Siber Hareket ismiyle 2020 senesiyle yayın hayatına türkçe deep web sitesi olarak başladık, Türk Siber Güvenlik ve Saldırı hack forumu…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Defend the Web” write-up (Intro 2 — HTML tag information leak)
https://cdn-images-1.medium.com/max/1920/1*xNRYPjKNWnKkh46rM7B5iA.jpeg
Data Leakage is an application flaw in which sensitive data, such as web application technical information, context, or user-specific data…
Continue reading on Purple TEAM »
___________________________
@hacking_Attack
@Hacking_Video
“Defend the Web” write-up (Intro 2 — HTML tag information leak)
https://cdn-images-1.medium.com/max/1920/1*xNRYPjKNWnKkh46rM7B5iA.jpeg
Data Leakage is an application flaw in which sensitive data, such as web application technical information, context, or user-specific data…
Continue reading on Purple TEAM »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Defend the Web” write-up (Intro 2 — HTML tag information leak)
Data Leakage is an application flaw in which sensitive data, such as web application technical information, context, or user-specific data…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Defend the Web” write-up (Intro 3— JavaScript information leak)
https://cdn-images-1.medium.com/max/728/1*OUy_2iKFhOwwVwOwsxnZlw.jpeg
The usage of client-side JavaScript for the front-end of modern web programs is getting more prevalent. Client-side JavaScript is used by…
Continue reading on Purple TEAM »
___________________________
@hacking_Attack
@Hacking_Video
“Defend the Web” write-up (Intro 3— JavaScript information leak)
https://cdn-images-1.medium.com/max/728/1*OUy_2iKFhOwwVwOwsxnZlw.jpeg
The usage of client-side JavaScript for the front-end of modern web programs is getting more prevalent. Client-side JavaScript is used by…
Continue reading on Purple TEAM »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Defend the Web” write-up (Intro 3— JavaScript information leak)
The usage of client-side JavaScript for the front-end of modern web programs is getting more prevalent. Client-side JavaScript is used by…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My First Instagram Bug Bounty Report
https://cdn-images-1.medium.com/max/2600/0*PvexCsYG1h82Feu9
Something is better than nothing, even if it is less than one wanted.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
My First Instagram Bug Bounty Report
https://cdn-images-1.medium.com/max/2600/0*PvexCsYG1h82Feu9
Something is better than nothing, even if it is less than one wanted.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My First Instagram Bug Bounty Report
Something is better than nothing, even if it is less than one wanted.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
XXE in Public Transport Ticketing Mobile APP
https://cdn-images-1.medium.com/max/1075/1*NQJaOfnJGFRaeGeMwMjVug.png
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
XXE in Public Transport Ticketing Mobile APP
https://cdn-images-1.medium.com/max/1075/1*NQJaOfnJGFRaeGeMwMjVug.png
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
XXE in Public Transport Ticketing Mobile APP
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…
Demystifying an XSS payload!
Just found an weird and cool trick by Gareth Heyes, so thought to reverse engineer it and find out the root cause :)Continue reading on Medium »
Read more...
Just found an weird and cool trick by Gareth Heyes, so thought to reverse engineer it and find out the root cause :)Continue reading on Medium »
Read more...
XXE in Public Transport Ticketing Mobile APP
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…Continue reading on Medium »
Read more...
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…Continue reading on Medium »
Read more...
Deep Web
Russian Game Show.
Hello. I found this hunger games like game show on a youtube video about the dark web. Does anyone know how to access the site? Im very curious and shocked and wanted to take a look at it myself but cant find the onion link anywhere
submitted by /u/kleeex
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Russian Game Show.
Hello. I found this hunger games like game show on a youtube video about the dark web. Does anyone know how to access the site? Im very curious and shocked and wanted to take a look at it myself but cant find the onion link anywhere
submitted by /u/kleeex
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
XXE in Public Transport Ticketing Mobile APP
https://mrnikhilsri.medium.com/xxe-in-public-transport-ticketing-mobile-app-81ae245c01a1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://mrnikhilsri.medium.com/xxe-in-public-transport-ticketing-mobile-app-81ae245c01a1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
XXE in Public Transport Ticketing Mobile APP
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…Continue reading on Medium » (https://mrnikhilsri.medium.com/xxe-in-public-transport-ticketing-mobile-app-81ae245c01a1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
XXE in Public Transport Ticketing Mobile APP
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…
Review and Resources list of the book Real-World Bug Hunting-A Field Guide to Web Hacking By Peter…
https://medium.com/@muhammadyaqub157/review-and-resources-list-of-the-book-real-world-bug-hunting-a-field-guide-to-web-hacking-by-peter-b76dadd93230?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@muhammadyaqub157/review-and-resources-list-of-the-book-real-world-bug-hunting-a-field-guide-to-web-hacking-by-peter-b76dadd93230?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Review and Resources list of the book Real-World Bug Hunting-A Field Guide to Web Hacking By Peter Yaworski
I am super excited to write my first ever story on Medium. I will In-Sha-Allah be consistent with my writing and will write more…
I am super excited to write my first ever story on Medium. I will In-Sha-Allah be consistent with my writing and will write more…Continue reading on Medium » (https://medium.com/@muhammadyaqub157/review-and-resources-list-of-the-book-real-world-bug-hunting-a-field-guide-to-web-hacking-by-peter-b76dadd93230?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Review and Resources list of the book Real-World Bug Hunting-A Field Guide to Web Hacking By Peter Yaworski
I am super excited to write my first ever story on Medium. I will In-Sha-Allah be consistent with my writing and will write more…
Sniffle - A Sniffer For Bluetooth 5 And 4.X LE
http://www.kitploit.com/2021/07/sniffle-sniffer-for-bluetooth-5-and-4x.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/07/sniffle-sniffer-for-bluetooth-5-and-4x.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Sniffle - A Sniffer For Bluetooth 5 And 4.X LE
Sniffle is a sniffer for Bluetooth 5 and 4.x (LE) using TI CC1352/CC26x2 hardware. Sniffle has a number of useful features, including: Support for BT5/4.2 extended length advertisement and data packets Support for BT5 Channel Selection Algorithms #1 and #2 Support for all BT5 PHY modes (regular 1M, 2M, and coded modes) Support for sniffing only advertisements (https://www.kitploit.com/search/label/Advertisements) and ignoring connections Support for channel map, connection parameter, and PHY change operations Support for advertisement filtering by MAC address and RSSI Support for BT5 extended advertising (non-periodic) Support for capturing advertisements from a target MAC on all three primary advertising channels using a single sniffer. This makes connection detection nearly 3x more reliable than most other sniffers that only sniff one advertising channel. Easy to extend host-side software written in Python PCAP export compatible with the Ubertooth
Prerequisites
TI CC26x2R Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC26X2R1 or TI CC2652RB Launchpad Board: https://www.ti.com/tool/LP-CC2652RB or TI CC1352R Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC1352R1 or TI CC1352P1 Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC1352P GNU ARM Embedded Toolchain: https://developer.arm.com/open-source/gnu-toolchain/gnu-rm/downloads TI CC26x2 SDK 5.10.00.48: https://www.ti.com/tool/download/SIMPLELINK-CC13X2-26X2-SDK TI DSLite Programmer Software: see below Python 3.5+ with PySerial installed If you don't want to go through the effort of setting up a build environment for the firmware, you can just flash prebuilt firmware binaries using UniFlash/DSLite. Prebuilt firmware binaries are attached to releases on the GitHub releases tab of this project. When using prebuilt firmware, be sure to use the Python code corresponding to the release tag rather than master to avoid compatibility issues with firmware that is behind the master branch. Note: it should be possible to compile Sniffle to run on CC1352P Launchpad boards with minimal modifications, but I have not yet tried this.
Installing GCC
The arm-none-eabi-gcc provided through various Linux distributions' package manager often lacks some header files or requires some changes to linker configuration. For minimal hassle, I suggest using the ARM GCC linked above. You can just download and extract the prebuilt executables.
Installing the TI SDK
The TI SDK is provided as an executable binary that extracts a bunch of source code once you accept the license agreement. On Linux and Mac, the default installation directory is inside~/ti/. This works fine and my makefiles expect this path, so I suggest just going with the default here. The same applies for the TI SysConfig tool. Once the SDK has been extracted, you will need to edit one makefile to match your build environment. Within ~/ti/simplelink_cc13x2_26x2_sdk_5_10_00_48 (or wherever the SDK was installed) there is a makefile named imports.mak. The only paths that need to be set here to build Sniffle are for GCC, XDC, and SysConfig. We don't need the CCS compiler. See the diff below as an example, and adapt for wherever you installed things. diff --git a/imports.mak b/imports.mak
index d815a4e94..731d49419 100644
--- a/imports.mak
+++ b/imports.mak
@@ -18,14 +18,14 @@
# will build using each non-empty *_ARMCOMPILER cgtool.
#
-XDC_INSTALL_DIR ?= /home/username/ti/xdctools_3_62_00_08_core
-SYSCONFIG_TOOL ?= /home/username/ti/ccs1030/ccs/utils/sysconfig_1.8.0/sysconfig_cli.sh
+XDC_INSTALL_DIR ?= $(HOME)/ti/xdctools_3_62_00_08_core
+SYSCONFIG_TOOL ?= $(HOME)/ti/sysconfig_1.8.0/sysconfig_cli.sh
FREERTOS_INSTALL_DIR ?= /home/username/FreeRTOSv10.2.1
CCS_ARMCOMPILER ?= /home/username/ti/ccs1030/ccs/tools/compiler/ti-cgt-arm_20.2.4.LTS
TICLANG_ARMCOMPILER ?= /home/username/ti/ccs1030/ccs/tools/compiler/1.2.1.STS
___________________________
@hacking_Attack
@Hacking_Video
Prerequisites
TI CC26x2R Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC26X2R1 or TI CC2652RB Launchpad Board: https://www.ti.com/tool/LP-CC2652RB or TI CC1352R Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC1352R1 or TI CC1352P1 Launchpad Board: https://www.ti.com/tool/LAUNCHXL-CC1352P GNU ARM Embedded Toolchain: https://developer.arm.com/open-source/gnu-toolchain/gnu-rm/downloads TI CC26x2 SDK 5.10.00.48: https://www.ti.com/tool/download/SIMPLELINK-CC13X2-26X2-SDK TI DSLite Programmer Software: see below Python 3.5+ with PySerial installed If you don't want to go through the effort of setting up a build environment for the firmware, you can just flash prebuilt firmware binaries using UniFlash/DSLite. Prebuilt firmware binaries are attached to releases on the GitHub releases tab of this project. When using prebuilt firmware, be sure to use the Python code corresponding to the release tag rather than master to avoid compatibility issues with firmware that is behind the master branch. Note: it should be possible to compile Sniffle to run on CC1352P Launchpad boards with minimal modifications, but I have not yet tried this.
Installing GCC
The arm-none-eabi-gcc provided through various Linux distributions' package manager often lacks some header files or requires some changes to linker configuration. For minimal hassle, I suggest using the ARM GCC linked above. You can just download and extract the prebuilt executables.
Installing the TI SDK
The TI SDK is provided as an executable binary that extracts a bunch of source code once you accept the license agreement. On Linux and Mac, the default installation directory is inside~/ti/. This works fine and my makefiles expect this path, so I suggest just going with the default here. The same applies for the TI SysConfig tool. Once the SDK has been extracted, you will need to edit one makefile to match your build environment. Within ~/ti/simplelink_cc13x2_26x2_sdk_5_10_00_48 (or wherever the SDK was installed) there is a makefile named imports.mak. The only paths that need to be set here to build Sniffle are for GCC, XDC, and SysConfig. We don't need the CCS compiler. See the diff below as an example, and adapt for wherever you installed things. diff --git a/imports.mak b/imports.mak
index d815a4e94..731d49419 100644
--- a/imports.mak
+++ b/imports.mak
@@ -18,14 +18,14 @@
# will build using each non-empty *_ARMCOMPILER cgtool.
#
-XDC_INSTALL_DIR ?= /home/username/ti/xdctools_3_62_00_08_core
-SYSCONFIG_TOOL ?= /home/username/ti/ccs1030/ccs/utils/sysconfig_1.8.0/sysconfig_cli.sh
+XDC_INSTALL_DIR ?= $(HOME)/ti/xdctools_3_62_00_08_core
+SYSCONFIG_TOOL ?= $(HOME)/ti/sysconfig_1.8.0/sysconfig_cli.sh
FREERTOS_INSTALL_DIR ?= /home/username/FreeRTOSv10.2.1
CCS_ARMCOMPILER ?= /home/username/ti/ccs1030/ccs/tools/compiler/ti-cgt-arm_20.2.4.LTS
TICLANG_ARMCOMPILER ?= /home/username/ti/ccs1030/ccs/tools/compiler/1.2.1.STS
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.