Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
fd challange walkthough
in this series i will solve a simple walktough of fd challenge available on
Continue reading on Medium »
fd challange walkthough
in this series i will solve a simple walktough of fd challenge available on
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Automate WordPress recon for Bug Bounty | WordPress:Cheat sheet
https://cdn-images-1.medium.com/max/750/1*bWMFqIUwiUYzz3ScpthkYw.jpeg
WordPress is a fairly large and complex product, with its own pros and cons, so there are a sufficient number of tools that allow you to…
Continue reading on Medium »
Automate WordPress recon for Bug Bounty | WordPress:Cheat sheet
https://cdn-images-1.medium.com/max/750/1*bWMFqIUwiUYzz3ScpthkYw.jpeg
WordPress is a fairly large and complex product, with its own pros and cons, so there are a sufficient number of tools that allow you to…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Chatterbox: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*_zAyHU6lmvV9eTftIZ9Axg.png
Hack The Box — Chatterbox: Walkthrough (without Metasploit)
Continue reading on Medium »
Hack The Box — Chatterbox: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*_zAyHU6lmvV9eTftIZ9Axg.png
Hack The Box — Chatterbox: Walkthrough (without Metasploit)
Continue reading on Medium »
Reward Announcement of Bug Bounty Program
https://apron-network.medium.com/reward-announcement-of-bug-bounty-program-4881433c3f43?source=rss------bug_bounty-5
https://apron-network.medium.com/reward-announcement-of-bug-bounty-program-4881433c3f43?source=rss------bug_bounty-5
During our product phase, Apron offered a Bug Bounty reward to the developers reviewing Apron node on Dashboard and reporting bugs.Continue reading on Medium » (https://apron-network.medium.com/reward-announcement-of-bug-bounty-program-4881433c3f43?source=rss------bug_bounty-5)
I have nothing for me but want to make a change
https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/
<!-- SC_OFF -->I'm a student currently going for a major in cybersecurity. I have been thinking about my future and I have nothing going on for me. I'm not involved in any clubs, I barely know the bare minimum for coding, I have done nothing to put in my resume for a future job, Once I do finish college, I will have nothing that makes me stand out to companies other than a degree. I'm asking for some guidance here, what should I do. I enjoy the idea of ethical "hacking" but have no knowledge of where to start and how I could use this knowledge for a possible internship in the future. I just don't want to be another student with a degree but yet I'm working retail <!-- SC_ON --> submitted by /u/hirosama555 (https://www.reddit.com/user/hirosama555)
[link] (https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/)
https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/
<!-- SC_OFF -->I'm a student currently going for a major in cybersecurity. I have been thinking about my future and I have nothing going on for me. I'm not involved in any clubs, I barely know the bare minimum for coding, I have done nothing to put in my resume for a future job, Once I do finish college, I will have nothing that makes me stand out to companies other than a degree. I'm asking for some guidance here, what should I do. I enjoy the idea of ethical "hacking" but have no knowledge of where to start and how I could use this knowledge for a possible internship in the future. I just don't want to be another student with a degree but yet I'm working retail <!-- SC_ON --> submitted by /u/hirosama555 (https://www.reddit.com/user/hirosama555)
[link] (https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/)
Deep Web
I’m new to the deep web and was wondering how do you find the websites that aren’t available on the regular web?
New to the onion browser and trying to learn its ropes
submitted by /u/DirtEater0
[link] [comments]
I’m new to the deep web and was wondering how do you find the websites that aren’t available on the regular web?
New to the onion browser and trying to learn its ropes
submitted by /u/DirtEater0
[link] [comments]
reddit
r/deepweb - I’m new to the deep web and was wondering how do you find the websites that aren’t available on the regular web?
0 votes and 10 comments so far on Reddit
hacking: security in practice
Camera activates when i use Google
Hello, I discovered something that may be of general interest, because it can be a very serious security problem in Android
For start, I have a ZTE axon M, a phone with 2 screens, and only one camera that acts as front and rear at the same time. So when I want to take a photo, it first launches a notification saying to change the screen (confirming that the camera was activated) the problem is that when I open random things in Google chrome (for example a news item) it activates the camera and then deactivates it (I know because a notification appears and then it changes the screen)
the question is why does google activate the camera? and does he do it with all of us?
submitted by /u/Science_Wolf
[link] [comments]
Camera activates when i use Google
Hello, I discovered something that may be of general interest, because it can be a very serious security problem in Android
For start, I have a ZTE axon M, a phone with 2 screens, and only one camera that acts as front and rear at the same time. So when I want to take a photo, it first launches a notification saying to change the screen (confirming that the camera was activated) the problem is that when I open random things in Google chrome (for example a news item) it activates the camera and then deactivates it (I know because a notification appears and then it changes the screen)
the question is why does google activate the camera? and does he do it with all of us?
submitted by /u/Science_Wolf
[link] [comments]
reddit
r/hacking - Camera activates when i use Google
0 votes and 0 comments so far on Reddit
CTF-Party - A Ruby Library To Enhance And Speed Up Script/Exploit Writing For CTF Players
http://www.kitploit.com/2021/03/ctf-party-ruby-library-to-enhance-and.html
http://www.kitploit.com/2021/03/ctf-party-ruby-library-to-enhance-and.html
A library (https://www.kitploit.com/search/label/Library) to enhance and speed up script/exploit writing for CTF (https://www.kitploit.com/search/label/CTF) players (or security researchers, bug bounty hunters, pentesters (https://www.kitploit.com/search/label/Pentesters) but mostly focused on CTF) by patching the String class to add a short syntax of usual code patterns. The philosophy is also to keep the library to be pure ruby (https://www.kitploit.com/search/label/Ruby) (no dependencies) and not to re-implement what another library is already doing well (eg. xorcist (https://github.com/fny/xorcist) for xor).
For example instead of writing: require 'base64'
myvar = 'string'
myvar = Base64.strict_encode64(myvar) Just write (shorter and easier to remember): require 'ctf_party'
myvar = 'string'
myvar.to_b64!
Features
base64: to_b64, to_b64!, from_b64, from_b64!, b64? digest: md5, md5!, sha1, sha1!, etc. flag: flag, flag!, flag? (apply/check a flag format) rot: rot, rot!, rot13, rot13! hex: hex2dec, dec2hex, to_hex, from_hex, hex2bin, bin2hex and bang versions
References
Homepage / Documentation: https://noraj.github.io/ctf-party
Author
Made by Alexandre ZANNI (@noraj (https://github.com/noraj)), pentester from Orange Cyberdefense.
Download Ctf-Party (https://github.com/Orange-Cyberdefense/ctf-party)
For example instead of writing: require 'base64'
myvar = 'string'
myvar = Base64.strict_encode64(myvar) Just write (shorter and easier to remember): require 'ctf_party'
myvar = 'string'
myvar.to_b64!
Features
base64: to_b64, to_b64!, from_b64, from_b64!, b64? digest: md5, md5!, sha1, sha1!, etc. flag: flag, flag!, flag? (apply/check a flag format) rot: rot, rot!, rot13, rot13! hex: hex2dec, dec2hex, to_hex, from_hex, hex2bin, bin2hex and bang versions
References
Homepage / Documentation: https://noraj.github.io/ctf-party
Author
Made by Alexandre ZANNI (@noraj (https://github.com/noraj)), pentester from Orange Cyberdefense.
Download Ctf-Party (https://github.com/Orange-Cyberdefense/ctf-party)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Do Cybercriminals Fear Arrest?
Researchers explore how cybercriminals weigh the possibility of arrest and whether it deters criminal activity.
Do Cybercriminals Fear Arrest?
Researchers explore how cybercriminals weigh the possibility of arrest and whether it deters criminal activity.
All in one Kali scambait tool-set
https://www.reddit.com/r/Pentesting/comments/mbpur2/all_in_one_kali_scambait_toolset/
<!-- SC_OFF -->Is there a list of software (voice changer, voIP-client recorder, fake bank, wireshark etc) we need, so more could be proaktive against the lowest-Betha scammers of the world. A Kali All in one VM or a docker of some kind would be awesome. Is anyone interested in helping me make this happen and i could open a github-page for my anti-kolkata machine. Feel free to make a pull request for new scambait tool! I want an automated copy and deletion of the c: drive and many scambait tools included. An randomized dextop-background and "cooking-recipes" file would be awesome. Does anyone know how to implement this? <!-- SC_ON --> submitted by /u/domib97 (https://www.reddit.com/user/domib97)
[link] (https://www.reddit.com/r/Pentesting/comments/mbpur2/all_in_one_kali_scambait_toolset/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbpur2/all_in_one_kali_scambait_toolset/)
https://www.reddit.com/r/Pentesting/comments/mbpur2/all_in_one_kali_scambait_toolset/
<!-- SC_OFF -->Is there a list of software (voice changer, voIP-client recorder, fake bank, wireshark etc) we need, so more could be proaktive against the lowest-Betha scammers of the world. A Kali All in one VM or a docker of some kind would be awesome. Is anyone interested in helping me make this happen and i could open a github-page for my anti-kolkata machine. Feel free to make a pull request for new scambait tool! I want an automated copy and deletion of the c: drive and many scambait tools included. An randomized dextop-background and "cooking-recipes" file would be awesome. Does anyone know how to implement this? <!-- SC_ON --> submitted by /u/domib97 (https://www.reddit.com/user/domib97)
[link] (https://www.reddit.com/r/Pentesting/comments/mbpur2/all_in_one_kali_scambait_toolset/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbpur2/all_in_one_kali_scambait_toolset/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Инструмент разведки urlhunter
https://cdn-images-1.medium.com/max/604/1*A0lrv65TfbaJChD-aU7s6A.jpeg
urlhunter это инструмент разведки, который позволяет выполнять поиск по URL-адресам, которые доступны через службы сокращения
Continue reading on Medium »
Инструмент разведки urlhunter
https://cdn-images-1.medium.com/max/604/1*A0lrv65TfbaJChD-aU7s6A.jpeg
urlhunter это инструмент разведки, который позволяет выполнять поиск по URL-адресам, которые доступны через службы сокращения
Continue reading on Medium »
Landed a PenTesting job with no real experience - help
https://www.reddit.com/r/Pentesting/comments/mbqcoc/landed_a_pentesting_job_with_no_real_experience/
<!-- SC_OFF -->Hello everyone, I'm hoping I can get some feedback here but please let me know if there's a subreddit better suited for PenTesting career questions. Some Background: I graduated last year with a CS degree and have spent the last year looking for software engineering jobs with no luck. I had one InfoSec internship as a student but I didnt think it would be enough to land me a job so I stuck with SE in the meantime while I figured out how to get my foot in the cyber world. I'm familiar with some security tools and the cyber field but have zero hands on experience working with things like metasploit or ctf's. Played around with some cyber websites likes tryhackme. Current Situation: I just recently started branching off into cyberSec job applications and interviewed for a junior embedded systems penetration tester position and some how landed the job. The recruiting manager said they don't expect me to know everything (its a very niche field) but as you can expect, I'm quite nervous. The job description sounds incredible but Im scared I might not be prepared for whats to come. Fortunately, I have one month until my official start date and I'm hoping I can use this time to familiarize myself with the field before I start.
My new manager said they would teach me the ropes but I can honestly say I've never done anything with embedded systems and PenTesting them is not turning up anything on google. Thoughts? Appreciate any help in the matter <!-- SC_ON --> submitted by /u/sloan0101 (https://www.reddit.com/user/sloan0101)
[link] (https://www.reddit.com/r/Pentesting/comments/mbqcoc/landed_a_pentesting_job_with_no_real_experience/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbqcoc/landed_a_pentesting_job_with_no_real_experience/)
https://www.reddit.com/r/Pentesting/comments/mbqcoc/landed_a_pentesting_job_with_no_real_experience/
<!-- SC_OFF -->Hello everyone, I'm hoping I can get some feedback here but please let me know if there's a subreddit better suited for PenTesting career questions. Some Background: I graduated last year with a CS degree and have spent the last year looking for software engineering jobs with no luck. I had one InfoSec internship as a student but I didnt think it would be enough to land me a job so I stuck with SE in the meantime while I figured out how to get my foot in the cyber world. I'm familiar with some security tools and the cyber field but have zero hands on experience working with things like metasploit or ctf's. Played around with some cyber websites likes tryhackme. Current Situation: I just recently started branching off into cyberSec job applications and interviewed for a junior embedded systems penetration tester position and some how landed the job. The recruiting manager said they don't expect me to know everything (its a very niche field) but as you can expect, I'm quite nervous. The job description sounds incredible but Im scared I might not be prepared for whats to come. Fortunately, I have one month until my official start date and I'm hoping I can use this time to familiarize myself with the field before I start.
My new manager said they would teach me the ropes but I can honestly say I've never done anything with embedded systems and PenTesting them is not turning up anything on google. Thoughts? Appreciate any help in the matter <!-- SC_ON --> submitted by /u/sloan0101 (https://www.reddit.com/user/sloan0101)
[link] (https://www.reddit.com/r/Pentesting/comments/mbqcoc/landed_a_pentesting_job_with_no_real_experience/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbqcoc/landed_a_pentesting_job_with_no_real_experience/)
CTF-Party - A Ruby Library To Enhance And Speed Up Script/Exploit Writing For CTF Players
A library to enhance and speed up script/exploit writing for CTF players (or security researchers, bug bounty hunters, pentesters but mostly focused on CTF) by patching the String class to add a short syntax of usual code patterns. The philosophy is also to keep the library to be pure ruby (no dependencies) and not to re-implement what another library is already doing well (eg. xorcist for xor). For example instead of writing: require 'base64'myvar = 'string'myvar = Base64.strict_encode64(myvar) Just write (shorter and easier to remember): require 'ctf_party'myvar = 'string'myvar.to_b64! Features base64: to_b64, to_b64!, from_b64, from_b64!, b64? digest: md5, md5!, sha1, sha1!, etc. flag: flag, flag!, flag? (apply/check a flag format) rot: rot, rot!, rot13, rot13! hex: hex2dec, dec2hex, to_hex, from_hex, hex2bin, bin2hex and bang versions References Homepage / Documentation: https://noraj.github.io/ctf-party Author Made by Alexandre ZANNI (@noraj), pentester from Orange Cyberdefense. Download Ctf-Party
Read more...
A library to enhance and speed up script/exploit writing for CTF players (or security researchers, bug bounty hunters, pentesters but mostly focused on CTF) by patching the String class to add a short syntax of usual code patterns. The philosophy is also to keep the library to be pure ruby (no dependencies) and not to re-implement what another library is already doing well (eg. xorcist for xor). For example instead of writing: require 'base64'myvar = 'string'myvar = Base64.strict_encode64(myvar) Just write (shorter and easier to remember): require 'ctf_party'myvar = 'string'myvar.to_b64! Features base64: to_b64, to_b64!, from_b64, from_b64!, b64? digest: md5, md5!, sha1, sha1!, etc. flag: flag, flag!, flag? (apply/check a flag format) rot: rot, rot!, rot13, rot13! hex: hex2dec, dec2hex, to_hex, from_hex, hex2bin, bin2hex and bang versions References Homepage / Documentation: https://noraj.github.io/ctf-party Author Made by Alexandre ZANNI (@noraj), pentester from Orange Cyberdefense. Download Ctf-Party
Read more...
noraj.github.io
Document
Description
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
CTF-Party - A Ruby Library To Enhance And Speed Up Script/Exploit Writing For CTF Players
https://1.bp.blogspot.com/-UDClO79plco/YFegS0yAm0I/AAAAAAAAVpQ/I_F8U8tJa-IARnnT0gmFY9x2ZHY3mt2aACNcBGAsYHQ/s16000/logo.png
A library to enhance and speed up script/exploit writing for CTF players (or security researchers, bug bounty hunters, pentesters but mostly focused on CTF) by patching the String class to add a short syntax of usual code patterns. The philosophy is also to keep the library to be pure ruby (no dependencies) and not to re-implement what another library is already doing well (eg. xorcist for xor).
For example instead of writing:
Just write (shorter and easier to remember):
Features
* base64:
* digest:
* flag:
* rot:
* hex:
References
Homepage / Documentation: https://noraj.github.io/ctf-party
Author
Made by Alexandre ZANNI (@noraj), pentester from Orange Cyberdefense.
Download Ctf-Party
CTF-Party - A Ruby Library To Enhance And Speed Up Script/Exploit Writing For CTF Players
https://1.bp.blogspot.com/-UDClO79plco/YFegS0yAm0I/AAAAAAAAVpQ/I_F8U8tJa-IARnnT0gmFY9x2ZHY3mt2aACNcBGAsYHQ/s16000/logo.png
A library to enhance and speed up script/exploit writing for CTF players (or security researchers, bug bounty hunters, pentesters but mostly focused on CTF) by patching the String class to add a short syntax of usual code patterns. The philosophy is also to keep the library to be pure ruby (no dependencies) and not to re-implement what another library is already doing well (eg. xorcist for xor).
For example instead of writing:
require 'base64'
myvar = 'string'
myvar = Base64.strict_encode64(myvar)Just write (shorter and easier to remember):
require 'ctf_party'
myvar = 'string'
myvar.to_b64!Features
* base64:
to_b64, to_b64!, from_b64, from_b64!, b64?* digest:
md5, md5!, sha1, sha1!, etc.* flag:
flag, flag!, flag?(apply/check a flag format)* rot:
rot, rot!, rot13, rot13!* hex:
hex2dec, dec2hex, to_hex, from_hex, hex2bin, bin2hexand bang versionsReferences
Homepage / Documentation: https://noraj.github.io/ctf-party
Author
Made by Alexandre ZANNI (@noraj), pentester from Orange Cyberdefense.
Download Ctf-Party