https://b.thumbs.redditmedia.com/fWOhrZB3Dl-sSbGuHHdU4IJLtS8_TP5FCWlnpVncptk.jpg
https://preview.redd.it/yocj6serj7h71.png?width=2208&format=png&auto=webp&s=7ae1361cc45932cf625fba9212e0adaa04e3273c
Hey r/hacking!
I've recently built a Password Manager in Python for the terminal. It's my first public repo on GitHub and I built it to improve my understanding of data security and encryption. I've gotten a lot of feedback from r/Python and r/crypto, and one Redditor told me that you guys might also appreciate the project - so feel free to hack it!
From all recommendations from the past couple of days, I've:
- Improved the encryption from PBKDF2 to Scrypt. I'd like to use Argon2id, but I'm not sure how to do it yet. Any insight into that would be helpful!
- Added a timeout feature so that the application can't be left open and vulnerable for more than 90 seconds.
- Changed the PM from showing the passwords to directly copying them to the clipboard. This prevents keyloggers from knowing if anything was manually copied or if the passwords were typed out.
- Added a password generator.
- Data is scrubbed from the terminal.
I'd love to hear how else it could improve!
Check out the DIY Password Manager on GitHub: https://github.com/MarkMcKinney/DIY-Password-Manager
submitted by /u/M2com
[link] [comments]
https://preview.redd.it/yocj6serj7h71.png?width=2208&format=png&auto=webp&s=7ae1361cc45932cf625fba9212e0adaa04e3273c
Hey r/hacking!
I've recently built a Password Manager in Python for the terminal. It's my first public repo on GitHub and I built it to improve my understanding of data security and encryption. I've gotten a lot of feedback from r/Python and r/crypto, and one Redditor told me that you guys might also appreciate the project - so feel free to hack it!
From all recommendations from the past couple of days, I've:
- Improved the encryption from PBKDF2 to Scrypt. I'd like to use Argon2id, but I'm not sure how to do it yet. Any insight into that would be helpful!
- Added a timeout feature so that the application can't be left open and vulnerable for more than 90 seconds.
- Changed the PM from showing the passwords to directly copying them to the clipboard. This prevents keyloggers from knowing if anything was manually copied or if the passwords were typed out.
- Added a password generator.
- Data is scrubbed from the terminal.
I'd love to hear how else it could improve!
Check out the DIY Password Manager on GitHub: https://github.com/MarkMcKinney/DIY-Password-Manager
submitted by /u/M2com
[link] [comments]
hacking: security in practice
Hacking myself due to lost 2FA recovery codes
Here is my situation.
Factory reset my phone without getting recovery codes from accounts linked to Google Authenticator. Was able to contact support and get back every account EXCEPT my Snapchat. They completely refuse to help. It seems to me, that after entering user/pass and getting to verification code screen, they don't seem to limit number of attempts at this stage.
With Authenticator producing 6 digit codes refreshing every 30 secs or so, this seems somewhat brute forceable. What would be a good method for doing this other than hand manually?
submitted by /u/Kiurin
[link] [comments]
Hacking myself due to lost 2FA recovery codes
Here is my situation.
Factory reset my phone without getting recovery codes from accounts linked to Google Authenticator. Was able to contact support and get back every account EXCEPT my Snapchat. They completely refuse to help. It seems to me, that after entering user/pass and getting to verification code screen, they don't seem to limit number of attempts at this stage.
With Authenticator producing 6 digit codes refreshing every 30 secs or so, this seems somewhat brute forceable. What would be a good method for doing this other than hand manually?
submitted by /u/Kiurin
[link] [comments]
reddit
Hacking myself due to lost 2FA recovery codes
Here is my situation. Factory reset my phone without getting recovery codes from accounts linked to Google Authenticator. Was able to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Crypto platform Poly Network rewards hackers with A $500,000 ‘bug bounty.
HONG KONG, Aug 13 (Reuters) — Poly Network, the cryptographic money stage which lost $610 million in a hack recently, affirmed on Friday…
Continue reading on Medium »
Crypto platform Poly Network rewards hackers with A $500,000 ‘bug bounty.
HONG KONG, Aug 13 (Reuters) — Poly Network, the cryptographic money stage which lost $610 million in a hack recently, affirmed on Friday…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PunkSpider Reborn at Defcon
https://cdn-images-1.medium.com/max/1284/1*_eKv8bj8M4l5Xs4w9Z6HQw.png
So as You are all probably aware punkspider has been released for a second time which excites me more than You know as I literally still…
Continue reading on Medium »
PunkSpider Reborn at Defcon
https://cdn-images-1.medium.com/max/1284/1*_eKv8bj8M4l5Xs4w9Z6HQw.png
So as You are all probably aware punkspider has been released for a second time which excites me more than You know as I literally still…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Defend the Web” write-up (Intro 10— JavaScript code exposure and decryption)
https://cdn-images-1.medium.com/max/1000/1*cFBS174gph_Q5yN23YipJA.jpeg
The Intro 10 challenge is very similar to Intro 3 and 5. We are not going to explain it in detail here since we have already done it. For…
Continue reading on Purple TEAM »
“Defend the Web” write-up (Intro 10— JavaScript code exposure and decryption)
https://cdn-images-1.medium.com/max/1000/1*cFBS174gph_Q5yN23YipJA.jpeg
The Intro 10 challenge is very similar to Intro 3 and 5. We are not going to explain it in detail here since we have already done it. For…
Continue reading on Purple TEAM »
Deep Web
Free Fixed Pick for All
I am back, you can check my profile. Only trusted and legit seller.
Basketball. Brasil Paulista League
Club Athletico Paulistano
Liga Sorocabana
Date: 14.08 01:30
Pick: Club Athletico Paulistano - 27.5 HANDICAP
Odds: 3.23
For more text me.
submitted by /u/byloser
[link] [comments]
Free Fixed Pick for All
I am back, you can check my profile. Only trusted and legit seller.
Basketball. Brasil Paulista League
Club Athletico Paulistano
Liga Sorocabana
Date: 14.08 01:30
Pick: Club Athletico Paulistano - 27.5 HANDICAP
Odds: 3.23
For more text me.
submitted by /u/byloser
[link] [comments]
reddit
Free Fixed Pick for All
I am back, you can check my profile. Only trusted and legit seller. Basketball. Brasil Paulista League Club Athletico Paulistano - Liga...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Introduction to hacking
https://cdn-images-1.medium.com/max/2600/1*lsMFcWp8Ju8htSRLpfXT2Q.png
So in short, I’m jumping into the hobby of hacking or cyber security.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Introduction to hacking
https://cdn-images-1.medium.com/max/2600/1*lsMFcWp8Ju8htSRLpfXT2Q.png
So in short, I’m jumping into the hobby of hacking or cyber security.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Introduction to hacking
So in short, I’m jumping into the hobby of hacking or cyber security.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Holy FFUF! — A Beginner Guide to Fuzz with FFUF
https://cdn-images-1.medium.com/max/2600/1*MgWDWhGEdINLwO4MGp208Q.jpeg
If you are a bug bounty hunter or security researcher, you must be familiar with a technique called Fuzzing. In case you just newly…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Holy FFUF! — A Beginner Guide to Fuzz with FFUF
https://cdn-images-1.medium.com/max/2600/1*MgWDWhGEdINLwO4MGp208Q.jpeg
If you are a bug bounty hunter or security researcher, you must be familiar with a technique called Fuzzing. In case you just newly…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Holy FFUF! — A Beginner Guide to Fuzz with FFUF
If you are a bug bounty hunter or security researcher, you must be familiar with a technique called Fuzzing. In case you just newly…
Finding multiple SSRF with aws metadata access on A BANK system
https://notifybugme.medium.com/finding-multiple-ssrf-with-aws-metadata-access-on-a-bank-system-7e73ac28e50a?source=rss------bug_bounty-5
Hi, everyoneContinue reading on Medium » (https://notifybugme.medium.com/finding-multiple-ssrf-with-aws-metadata-access-on-a-bank-system-7e73ac28e50a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://notifybugme.medium.com/finding-multiple-ssrf-with-aws-metadata-access-on-a-bank-system-7e73ac28e50a?source=rss------bug_bounty-5
Hi, everyoneContinue reading on Medium » (https://notifybugme.medium.com/finding-multiple-ssrf-with-aws-metadata-access-on-a-bank-system-7e73ac28e50a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Finding multiple SSRF with aws metadata access on A BANK system
Hi, everyone
Successfully archived training materials for Conti partners - a selection of various Red Teaming videos, RedTeaming tools, malicious PowerShell scripts, etc. This is, in fact, Conti’s “continuous learning” program.
https://www.reddit.com/r/redteamsec/comments/p436k1/successfully_archived_training_materials_for/
submitted by /u/MyAlterningAcc (https://www.reddit.com/user/MyAlterningAcc)
[link] (https://pastebin.com/U71YVjjy) [comments] (https://www.reddit.com/r/redteamsec/comments/p436k1/successfully_archived_training_materials_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/p436k1/successfully_archived_training_materials_for/
submitted by /u/MyAlterningAcc (https://www.reddit.com/user/MyAlterningAcc)
[link] (https://pastebin.com/U71YVjjy) [comments] (https://www.reddit.com/r/redteamsec/comments/p436k1/successfully_archived_training_materials_for/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
Successfully archived training materials for Conti partners - a selection of various Red Teaming videos, RedTeaming tools, malicious…
46 votes and 6 comments so far on Reddit