Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cell Phone: the new target
https://cdn-images-1.medium.com/max/1926/0*tOQIxZNPUiDJHbqs
Indeed, we as a whole gripe about how the web is a particularly risky spot to be and how many threats it postures to our overall security…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cell Phone: the new target
https://cdn-images-1.medium.com/max/1926/0*tOQIxZNPUiDJHbqs
Indeed, we as a whole gripe about how the web is a particularly risky spot to be and how many threats it postures to our overall security…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cell Phone: the new target
Indeed, we as a whole gripe about how the web is a particularly risky spot to be and how many threats it postures to our overall security…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Riesgos a la privacidad en dispositivos IoT.
https://cdn-images-1.medium.com/max/1280/0*p9TzdHw2DCi10gRF
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Riesgos a la privacidad en dispositivos IoT.
https://cdn-images-1.medium.com/max/1280/0*p9TzdHw2DCi10gRF
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Riesgos a la privacidad en dispositivos IoT.
POR EHACKING
Cyber Security Interview Questions Part-2
https://shifacyclewala.medium.com/cyber-security-interview-questions-part-2-13fbb38b9b46?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://shifacyclewala.medium.com/cyber-security-interview-questions-part-2-13fbb38b9b46?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Security Interview Questions Part-2
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…Continue reading on Medium » (https://shifacyclewala.medium.com/cyber-security-interview-questions-part-2-13fbb38b9b46?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Security Interview Questions Part-2
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…
Doldrums - A Flutter/Dart Reverse Engineering Tool
To flutter: to move in quick, irregular motions, to beat rapidly, to be agitated. Doldrums: a period of stagnation. Doldrums is a reverse engineering tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor for the Flutter/Dart Android binary, conventionally named libapp.so, for all Dart version 2.10 releases. When run, it outputs a full dump of all classes present in the isolate snapshot. The tool is currently in beta, and missing some deserialization routines and class information. If it does not work out-of-the-box, please let me know.Dependencies Doldrums requires pyelftools to parse the ELF format. You can install it with pip3 install pyelftools Usage To use, simply run the following command, substituting libapp.so for the appropriate binary, and output for the desired output file. Note that the verbose option only works for Dart snapshot v2.12. python3 src/main.py -v libapp.so output The expected output is a dump of all classes, in the following format: class MyApp extends StatelessWidget { Widget build(DynamicType, DynamicType) { Code at absolute offset: 0xec85c } String myPrint(DynamicType, DynamicType) { Code at absolute offset: 0xeca80 }} The absolute code offset indicates the offset into the libapp.so file where the native function may be found. Reading material For a detailed write-up on the format, please check my blog post. Related works darter is a fully implemented and fully tested parser for Dart version 2.5 releases. Contribute If you'd like to help the project, consider making a pull request, or donating to ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B Logo by Luis Fonseca. Download Doldrums
Read more...
___________________________
@hacking_Attack
@Hacking_Video
To flutter: to move in quick, irregular motions, to beat rapidly, to be agitated. Doldrums: a period of stagnation. Doldrums is a reverse engineering tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor for the Flutter/Dart Android binary, conventionally named libapp.so, for all Dart version 2.10 releases. When run, it outputs a full dump of all classes present in the isolate snapshot. The tool is currently in beta, and missing some deserialization routines and class information. If it does not work out-of-the-box, please let me know.Dependencies Doldrums requires pyelftools to parse the ELF format. You can install it with pip3 install pyelftools Usage To use, simply run the following command, substituting libapp.so for the appropriate binary, and output for the desired output file. Note that the verbose option only works for Dart snapshot v2.12. python3 src/main.py -v libapp.so output The expected output is a dump of all classes, in the following format: class MyApp extends StatelessWidget { Widget build(DynamicType, DynamicType) { Code at absolute offset: 0xec85c } String myPrint(DynamicType, DynamicType) { Code at absolute offset: 0xeca80 }} The absolute code offset indicates the offset into the libapp.so file where the native function may be found. Reading material For a detailed write-up on the format, please check my blog post. Related works darter is a fully implemented and fully tested parser for Dart version 2.5 releases. Contribute If you'd like to help the project, consider making a pull request, or donating to ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B Logo by Luis Fonseca. Download Doldrums
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Cyber Security Interview Questions Part-2
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…Continue reading on Medium »
Read more...
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…Continue reading on Medium »
Read more...
GCP Inspector | Auditing Publicly Exposed GCP Bucket
Installation of GCP Inspector and basics about enumerating publicly exposed GCP bucket enumeration.Continue reading on Medium »
Read more...
Installation of GCP Inspector and basics about enumerating publicly exposed GCP bucket enumeration.Continue reading on Medium »
Read more...
Doldrums - A Flutter/Dart Reverse Engineering Tool
http://www.kitploit.com/2021/08/doldrums-flutterdart-reverse.html
http://www.kitploit.com/2021/08/doldrums-flutterdart-reverse.html
To flutter: to move in quick, irregular motions, to beat rapidly, to be agitated.
Doldrums: a period of stagnation. Doldrums is a reverse engineering (https://www.kitploit.com/search/label/Reverse%20Engineering) tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor (https://www.kitploit.com/search/label/Extractor) for the Flutter/Dart Android (https://www.kitploit.com/search/label/Android) binary, conventionally named libapp.so, for all Dart version 2.10 releases. When run, it outputs a full dump of all classes present in the isolate snapshot. The tool is currently in beta, and missing some deserialization (https://www.kitploit.com/search/label/Deserialization) routines and class information. If it does not work out-of-the-box, please let me know.
Dependencies
Doldrums requires pyelftools (https://github.com/eliben/pyelftools) to parse the ELF format. You can install it with pip3 install pyelftools
Usage
To use, simply run the following command, substituting libapp.so for the appropriate binary, and output for the desired output file. Note that the verbose option only works for Dart snapshot v2.12. python3 src/main.py [-v] libapp.so output
The expected output is a dump of all classes, in the following format: class MyApp extends StatelessWidget {
Widget build(DynamicType, DynamicType) {
Code at absolute offset: 0xec85c
}
String myPrint(DynamicType, DynamicType) {
Code at absolute offset: 0xeca80
}
}
The absolute code offset indicates the offset into the libapp.so file where the native function may be found.
Reading material
For a detailed write-up on the format, please check my blog post (https://rloura.wordpress.com/2020/12/04/reversing-flutter-for-android-wip/).
Related works
darter (https://github.com/mildsunrise/darter) is a fully implemented and fully tested parser for Dart version 2.5 releases.
Contribute
If you'd like to help the project, consider making a pull request, or donating to ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B Logo by Luis Fonseca (https://www.linkedin.com/in/luis-pedro-h-fonseca-4776a024/).
Download Doldrums (https://github.com/rscloura/Doldrums)
Doldrums: a period of stagnation. Doldrums is a reverse engineering (https://www.kitploit.com/search/label/Reverse%20Engineering) tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor (https://www.kitploit.com/search/label/Extractor) for the Flutter/Dart Android (https://www.kitploit.com/search/label/Android) binary, conventionally named libapp.so, for all Dart version 2.10 releases. When run, it outputs a full dump of all classes present in the isolate snapshot. The tool is currently in beta, and missing some deserialization (https://www.kitploit.com/search/label/Deserialization) routines and class information. If it does not work out-of-the-box, please let me know.
Dependencies
Doldrums requires pyelftools (https://github.com/eliben/pyelftools) to parse the ELF format. You can install it with pip3 install pyelftools
Usage
To use, simply run the following command, substituting libapp.so for the appropriate binary, and output for the desired output file. Note that the verbose option only works for Dart snapshot v2.12. python3 src/main.py [-v] libapp.so output
The expected output is a dump of all classes, in the following format: class MyApp extends StatelessWidget {
Widget build(DynamicType, DynamicType) {
Code at absolute offset: 0xec85c
}
String myPrint(DynamicType, DynamicType) {
Code at absolute offset: 0xeca80
}
}
The absolute code offset indicates the offset into the libapp.so file where the native function may be found.
Reading material
For a detailed write-up on the format, please check my blog post (https://rloura.wordpress.com/2020/12/04/reversing-flutter-for-android-wip/).
Related works
darter (https://github.com/mildsunrise/darter) is a fully implemented and fully tested parser for Dart version 2.5 releases.
Contribute
If you'd like to help the project, consider making a pull request, or donating to ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B Logo by Luis Fonseca (https://www.linkedin.com/in/luis-pedro-h-fonseca-4776a024/).
Download Doldrums (https://github.com/rscloura/Doldrums)
hacking: security in practice
Cracking a long .zip password with most of the password.
I made a password protected zip file with some sensitive documents and I thought I knew it, but I think I added some characters at the end but forgot about those. The password is long, something like, "Penguins have poor taste," and then there's a special character, maybe a space, and four or five numbers.
I've tried a couple of the commercial products, Passper and PassFab, but their max characters were too short. I was wondering if there was an easy to use product that would fit my needs or if there wasn't, was there a guide for beginners for one of the more complicated methods.
submitted by /u/SocialistSocialWork
[link] [comments]
Cracking a long .zip password with most of the password.
I made a password protected zip file with some sensitive documents and I thought I knew it, but I think I added some characters at the end but forgot about those. The password is long, something like, "Penguins have poor taste," and then there's a special character, maybe a space, and four or five numbers.
I've tried a couple of the commercial products, Passper and PassFab, but their max characters were too short. I was wondering if there was an easy to use product that would fit my needs or if there wasn't, was there a guide for beginners for one of the more complicated methods.
submitted by /u/SocialistSocialWork
[link] [comments]
reddit
Cracking a long .zip password with most of the password.
I made a password protected zip file with some sensitive documents and I thought I knew it, but I think I added some characters at the end but...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Honda/Acura "Unoriginal Rice Patty" FOB Rob Vulnerability
Click here and checkout the FOB Rob vulnerability documentation. Honda and Acura vehicles' wireless FOBs can be permanently robbed in one go!
submitted by /u/HackingInHeart
[link] [comments]
Honda/Acura "Unoriginal Rice Patty" FOB Rob Vulnerability
Click here and checkout the FOB Rob vulnerability documentation. Honda and Acura vehicles' wireless FOBs can be permanently robbed in one go!
submitted by /u/HackingInHeart
[link] [comments]
hacking: security in practice
does a cookie logger seem like the most plausible scenario here?
before context i wanna say that the only possibilites i see here is a somehow a cookie logger or sim swap.
on 03 Aug 1am I received an SMS from my bank that 600eu was attempted to be pulled from my cc through paypal and shortly after they bought 2 copies of a game from a key reseller site which ended up going through. i am thinking they stole the cookies to my outlook email linked to paypal and also to my gmail since there are no login traces and worked their way through paypal with that info. the company from which they made these purchases confirmed that the account was created on the same day using my own gmail account and they also gave me the IP address from where the orders were created from and this is where i think it could have been a sim swap. about a month prior i took my phone for repairs and he had my passcode and all. the IP address was local from an ISP i am aware of (both his and my IPs are static) and the fact that i live in a tiny island it would be a huge coincidence thatthe person who cookie logged me is from the same island. i suppose the same thing could be done if he essentially had a replica of my phone although perhaps less likely. i would like some input from ppl who are more knowledgeable than me especially since the local authorities tried to convince me that i had just clicked on a phishing site or that i was the one who made these purhcases.
submitted by /u/aImondss
[link] [comments]
does a cookie logger seem like the most plausible scenario here?
before context i wanna say that the only possibilites i see here is a somehow a cookie logger or sim swap.
on 03 Aug 1am I received an SMS from my bank that 600eu was attempted to be pulled from my cc through paypal and shortly after they bought 2 copies of a game from a key reseller site which ended up going through. i am thinking they stole the cookies to my outlook email linked to paypal and also to my gmail since there are no login traces and worked their way through paypal with that info. the company from which they made these purchases confirmed that the account was created on the same day using my own gmail account and they also gave me the IP address from where the orders were created from and this is where i think it could have been a sim swap. about a month prior i took my phone for repairs and he had my passcode and all. the IP address was local from an ISP i am aware of (both his and my IPs are static) and the fact that i live in a tiny island it would be a huge coincidence thatthe person who cookie logged me is from the same island. i suppose the same thing could be done if he essentially had a replica of my phone although perhaps less likely. i would like some input from ppl who are more knowledgeable than me especially since the local authorities tried to convince me that i had just clicked on a phishing site or that i was the one who made these purhcases.
submitted by /u/aImondss
[link] [comments]
reddit
does a cookie logger seem like the most plausible scenario here?
before context i wanna say that the only possibilites i see here is a somehow a cookie logger or sim swap. on 03 Aug 1am I received an SMS from...
GCP Inspector | Auditing Publicly Exposed GCP Bucket
https://justm0rph3u5.medium.com/gcp-inspector-auditing-publicly-exposed-gcp-bucket-ac6cad55618c?source=rss------bug_bounty-5
https://justm0rph3u5.medium.com/gcp-inspector-auditing-publicly-exposed-gcp-bucket-ac6cad55618c?source=rss------bug_bounty-5