Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
What is BOLA? 3-digit bounty from Topcoder ($$$)

This write-up will be about Broken Object Level Authorization (BOLA), which is #1 topic of API Security 101 (OWASP).Continue reading on InfoSec Write-ups »
Read more...
Exploiting JWT to Account Takeover

Hey Cyberpunks, Ethical Kaps here, I’m back again with another powerful article. I hope you all are doing great in your life. Today we are…Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploiting JWT to Account Takeover

https://cdn-images-1.medium.com/max/1640/1*NTtxNfncSpGSob8KcuPcrg.png
Hey Cyberpunks, Ethical Kaps here, I’m back again with another powerful article. I hope you all are doing great in your life. Today we are…

Continue reading on InfoSec Write-ups »
P1: Easy Access to Grafana Dashboard

Hey folks,Continue reading on Medium »
Read more...
hacking: security in practice
Grandma Getting Texts and Phone Calls

My poor 86 year old grandmother gets "Social Security Officers" or "Extended Car Warranty" calls all the time on her landline and cell phone. She also receives texts with obvious malicious links from random phone numbers or email addresses. Besides blocking the numbers/email addresses, contacting the phone company when they call, and contacting the DNS provider, what else can I legally do? If I can do something to get an IP address or something to help law enforcement track down these folks (much like the famous Youtubers often do), I would love to do so (legally of course). I want to learn as much as I can about cybersecurity, so I take this as a challenge. I used to work in a sketchy call center (I was young and naive), but I learned that the auto-dialers can randomize phone numbers pretty easily. If there is a way I can look up where these calls are actually originated from, or at least point me towards what hypothetically this process looks like, I would be super appreciative (assuming it is legal to do so). If doing so is illegal altogether, I understand and won't try and probe for anything illegal, just wanted to ask because from some googling it seems like a bit of a grey area..... I am certainly not asking how to infect the scammers with malware or anything, I realize accessing a computer with permission is illegal 100% and don't desire to do that. Just want to be able to provide law enforcement with as much intel as I can.

submitted by /u/Shadow1893
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Anyone Tried Fluxion On Ubuntu 21.04 ?

HI this is my OS Version i am running and trying to experiment with ethical hacking.

Using FLuxion 6.9

No LSB modules are available.

Distributor ID: Ubuntu

Description: Ubuntu 21.04

Release: 21.04

Codename: hirsute

When i make the FAKE AP, it gets stuck at obtaining IP ADDRESS Part.. Please Help Thanks :)

submitted by /u/Edulad
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SharpLAPS : Retrieve LAPS Password From LDAP

SharpLAPS is a tool to Retrieve LAPS Password From LDAP. The attribute ms-mcs-AdmPwd stores the clear-text LAPS password. This executable is made to be executed within Cobalt Strike session using execute-assembly. It will retrieve the LAPS password from the Active Directory. Require (either): Account with ExtendedRight or Generic All Rights Domain Admin privilege Usage _ _ _ / // /_ _ / / […]

The post SharpLAPS : Retrieve LAPS Password From LDAP appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Uchihash : A Small Utility To Deal With Malware Embedded Hashes

Uchihash is a small utility that can save malware analysts the time of dealing with embedded hash values used for various things such as: Dynamically importing APIs (especially in shellcode) Checking running process used by analysts (Anti-Analysis) Checking VM or Antivirus artifacts (Anti-Analysis) Uchihash can generate hashes with your own custom hashing algorithm, search for […]

The post Uchihash : A Small Utility To Deal With Malware Embedded Hashes appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video