Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacker News Digest
Practical Cryptography for Developers

https://firebasestorage.googleapis.com/v0/b/gitbook-28427.appspot.com/o/assets%2F-LhlOQMrG9bRiqWpegM0%2F-LhlOTG3w57kUSFndpUZ%2F-LhlPfAAEIjWuPNQSU43%2FPractical-Cryptography-for-Developers-Book-Nakov-front-cover.png?generation=1560975948039971&alt=media Warning : this book is not finished ! I am still working on some of the chapters. Once it is completed, I will publish it as PDF and EPUB. Be patient. A modern practical book about cryptography for developers with code examples, covering core concepts ...
hacking: security in practice
Paypal hacked and email mass spammed

Okay, Im not sure where to ask for this but this might be good. My Paypal recently got compromised and I believe they used the email in Paypal account to mass signup for HUNDREDS of websites and newsletters. Im being told my email account was not hacked but I just want to ask here. I believe I cleared everything with Paypal, deleting bank info and changing passwords and logging everyone out, and reporting fraud purchases. So I just want to double-check how common this type of thing is where your email gets signed up for 100+ different random websites.

submitted by /u/cbanavi
[link] [comments]
hacking: security in practice
Make sure that employer can’t monitor you (is my solution safe?)

Recently I received a work laptop (MacBook) from my employer and I want to make sure that my employer can’t monitor me while I use it privately in my free time.

I checked the installed software and it seems only an antivirus software (Eset endpoint antivirus, a Japanese software) is installed and it doesn’t seem like it’s being used to monitor employees. However I’m not 100% sure.

I read that installing a new OS (eg Linux) on a jump drive is the safest option. However, currently I don’t have a good external drive.

My solution: I installed macOS a second time on the drive and boot from the newly installed OS.

Is this as safe as using a jump drive? Are there any weak points? When I return the MacBook and delete the second OS, is there a way my employer could notice that? I don’t think they would do the effort of checking deleted files etc but asking just in case... any other solutions of advices?

submitted by /u/raykage
[link] [comments]
hacking: security in practice
Wireless option to a NIC

I am running three separate computers on the same wifi network and need them to communicate. These computers are far enough from each other it would be an extreme pain to drill holes and run cables through walls. Is there an option to this which doesnt require me to connect them via ethernet. Maybe a homegroup option in my router?

submitted by /u/RogerPenBitch
[link] [comments]
hacking: security in practice
CC1111 Im-Me Replacement

There was a previous thread that was archived. Apparently the CC1110 only made it into the Im-Me pager. The Yard Stick uses a CC1111 (Same thing, but with a USB port). Couldn't the Yard Stick be programmed, and used standalone? Samy? Any other products use the CC111x?



submitted by /u/RChadwick7
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Get an Invite Code to Hack The Box

https://cdn-images-1.medium.com/max/1079/1*1jWe50tNzHVM4oYYzT6yiw.png
Hack The Box is an online platform that provides various challenges to test your skills in cybersecurity areas such as penetration…

Continue reading on Nerd For Tech »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hobby Lobby Exposes Customer Data in Cloud Misconfiguration

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hobby Lobby Exposes Customer Data in Cloud MisconfigurationPost Views: 21
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
Arts-and-crafts retailer Hobby Lobby has suffered a cloud-bucket misconfiguration, exposing a raft of customer information, according to a report.
An independent security researcher who goes by the handle “Boogeyman” uncovered the issue and reported it to Motherboard in an online chat, according to a Vice writeup.

The researcher said that customer names, partial payment-card details, phone numbers, and physical and email addresses were all caught up in the leak – along with source code for the company’s app, and employee names and email addresses.

Boogeyman offered screenshots verifying the exposure of the data, which totaled 138GB and impacted around 300,000 customers. It was housed in an Amazon Web Services (AWS) cloud database that was misconfigured to be publicly accessible. The issue is now resolved, but it’s unclear if any malicious actors tapped the information before the database was secure.
See Also: Adobe Fixes Critical ColdFusion Flaw in Emergency Update “We identified the access control involved and have taken steps to secure the system,” Hobby Lobby told Motherboard. Threatpost has reached out to Hobby Lobby to independently confirm the issue. Cloud Misconfigurations: A Cyberthreat Attack VectorCloud misconfigurations are a common threat vector for organizations of all sizes. For instance, an analysis last fall found that 6 percent of all Google Cloud buckets are misconfigured and left open to the public internet, for anyone to access their contents.

“The Hobby Lobby incident is the latest example of why we need to take public cloud threat vectors so seriously,” said Douglas Murray, CEO at Valtix, told Threatpost. “In 2020, spend in public cloud exceeded spend in on-prem data centers for the first time. The hackers are doing their own version of ‘lift and shift’ and are aggressively moving to where the market is going. Just as concerning is that for every Hobby Lobby like leak that we learn about, there is another that goes undetected.”

Hank Schless, senior manager of security solutions at Lookout, noted that such misconfigurations are easy to do.
See Also: Offensive Security Tool: Skipfish
“Misconfigured cloud resources are frequently the cause of data breaches like this one,” he told Threatpost. “Organizations that have transitioned to the cloud have massive infrastructure that spans thousands of host servers and other services. Amazon’s S3 service is the base data storage offering for AWS, which means it’s simple to set up and integrate S3 buckets into cloud infrastructure. Unfortunately, that simplicity they offer and the speed at which organizations scale these services up and down oftentimes means the configuration of these buckets is overlooked and the data inside is left exposed.”

He added to mitigate the risk of a breach, organizations need to be sure they secure every aspect of their infrastructure from the individual endpoint all the way up to the cloud service itself. See Also: Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbers“Advanced cloud access security broker (CASB) technology helps secure access to these resources,” he said. “Coupling CASB with a security posture management tool ensures secure access and configuration of cloud [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hobby Lobby Exposes Customer Data in Cloud Misconfiguration https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hobby Lobby Exposes Customer Data in Cloud MisconfigurationPost Views:…
infrastructure. Cloud providers offer countless supporting services and integrations that help teams build a well-architected infrastructure. Leveraging these services should be done in tandem with security teams to ensure there aren’t any misconfigurations that leave data exposed or violate compliance policies.”
Source: https://threatpost.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/adobe_coldfusion-700x412-e1542041238507-90x90.jpg Adobe Fixes Critical ColdFusion Flaw in Emergency Update1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Clubhouse-e1614022265127-90x90.jpg Bogus Android Clubhouse App Drops Credential-Swiping Malware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/apple-security-90x90.jpg Trojanized Xcode Project Slips MacOS Malware to Apple Developers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Cisco_Systems_Sign-90x90.jpg Cisco Plugs Security Hole in Small Business Routers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/JPG-Malicious-Two-90x90.jpg Magecart Attackers Save Stolen Credit-Card Data in JPG Files1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Google-Chrome-Browser-1-90x90.jpg Google Warns Mac, Windows Users of Chrome Zero-Day Flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/internet-of-things-90x90.jpg Critical Security Hole Can Knock Smart Meters Offline1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Linux-kernel-vulnerability-90x90.png Linux Systems Under Attack By New RedXOR Malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/security-camera-90x90.jpg Breach Exposes Verkada Security Camera Footage at Tesla, Cloudflare2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/ezgif.com-gif-maker-1-90x90.jpg Apple’s Device Location-Tracking System Could Expose User Identities2 weeks ago
The post Hobby Lobby Exposes Customer Data in Cloud Misconfiguration first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is Jim Browning Real?

I’ve been hooked to Jim Brownings Channel on youtube where he gets into scammers computers and save victims, take down scam centers and even see them on their cameras. Is this actually possible? Let me ask the real question: Is this Real?

submitted by /u/imtrecasso
[link] [comments]
hacking: security in practice
iCloud unlock

Does anyone know how to unlock an iCloud? Message me is you do please!

submitted by /u/Lilahgirl99
[link] [comments]
Bypass rate limit to enumeration users through Google Drive

Hi everyone, today I’m gonna took about vulnerability that I found it in Google. In fact, when I sent the report to Google, it wasn’t a…Continue reading on Medium »
Read more...