Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Can I publish an exploit code to exploit-db.com after a CVE ID gets assigned?
I have found a vulnerability in a local vendor's product, who wasn't found in MITRE's CNA table. Also, there is no Vulnerability research programs in my country AFA my research went.
Edit: There is, but the application procedure is terrible. Looking into it.
I intend to email the vendor first and then request MITRE for a CVE-ID. However, I have three questions on the subject.
1. In the event of the vendor not acknowledging my findings (the chances of this happening is pretty high), and a CVE-ID gets assigned, can I still publish the exploit code to exploit-db.com?
2. Can I publish a writeup on how I have found the vulnerability once a CVE ID is assigned?
3. On MITRE's website, they says that the researcher who request a CVE-ID won't be credited. Is there any way that I could get credited for the vulnerability I found?
This is my first zero day and I don't know how to proceed further as different websites propose conflicting information on this. Kindly guide me on how to report this.
PS: I am not looking for bounty money; I'm just trying to mark my humble presence into the vast cyber security world.
submitted by /u/Mr-introVert
[link] [comments]
Can I publish an exploit code to exploit-db.com after a CVE ID gets assigned?
I have found a vulnerability in a local vendor's product, who wasn't found in MITRE's CNA table. Also, there is no Vulnerability research programs in my country AFA my research went.
Edit: There is, but the application procedure is terrible. Looking into it.
I intend to email the vendor first and then request MITRE for a CVE-ID. However, I have three questions on the subject.
1. In the event of the vendor not acknowledging my findings (the chances of this happening is pretty high), and a CVE-ID gets assigned, can I still publish the exploit code to exploit-db.com?
2. Can I publish a writeup on how I have found the vulnerability once a CVE ID is assigned?
3. On MITRE's website, they says that the researcher who request a CVE-ID won't be credited. Is there any way that I could get credited for the vulnerability I found?
This is my first zero day and I don't know how to proceed further as different websites propose conflicting information on this. Kindly guide me on how to report this.
PS: I am not looking for bounty money; I'm just trying to mark my humble presence into the vast cyber security world.
submitted by /u/Mr-introVert
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities
Mole is a framework for identifying and exploiting out-of-band (OOB) vulnerabilities. Installation & Setup Mole Install Python >= 3.6 virtualenv -p /usr/bin/python3 venvsource venv/bin/activate./venv/bin/pip3 install -r requirements.txtgit submodule update --init --recursive Set an API key in config.yml (must be the same for the client and server) DNS Configuration You’ll need to configure the DNS records […]
The post Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities appeared first on Kali Linux Tutorials.
Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities
Mole is a framework for identifying and exploiting out-of-band (OOB) vulnerabilities. Installation & Setup Mole Install Python >= 3.6 virtualenv -p /usr/bin/python3 venvsource venv/bin/activate./venv/bin/pip3 install -r requirements.txtgit submodule update --init --recursive Set an API key in config.yml (must be the same for the client and server) DNS Configuration You’ll need to configure the DNS records […]
The post Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OWASP API #9: Improper Assets Management
https://cdn-images-1.medium.com/max/700/0*VOxZb0CcO0psFL9k
Want to learn how big enterprises such as Facebook can easily be hacked? Can have a look to learn about Improper Assets Management.
Continue reading on strike.sh »
OWASP API #9: Improper Assets Management
https://cdn-images-1.medium.com/max/700/0*VOxZb0CcO0psFL9k
Want to learn how big enterprises such as Facebook can easily be hacked? Can have a look to learn about Improper Assets Management.
Continue reading on strike.sh »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What are Crawlers and how do They Work?
https://cdn-images-1.medium.com/max/671/0*iwM2xk6hpGZJ4Gtw.png
These crawlers discover content through various means. One being by pure discovery, where a URL is visited by the crawler and information…
Continue reading on Medium »
What are Crawlers and how do They Work?
https://cdn-images-1.medium.com/max/671/0*iwM2xk6hpGZJ4Gtw.png
These crawlers discover content through various means. One being by pure discovery, where a URL is visited by the crawler and information…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Retrieve Deleted Text Messages From Your Husband Phone.
Because of this video guide, you can now learn how to read your girlfriends, boyfriend, husbandWhatsApp messages on an iPhone or android…
Continue reading on Medium »
Retrieve Deleted Text Messages From Your Husband Phone.
Because of this video guide, you can now learn how to read your girlfriends, boyfriend, husbandWhatsApp messages on an iPhone or android…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CyberSecurity #1
https://cdn-images-1.medium.com/max/836/1*DaMYsyP1PvlOZIxgFWlyAA.jpeg
Bu serimiz siber güvenlik başlığı altında en çok merak edilen ve rağbet gören konulardan birisi olan sızma testi (pentest) konusundan…
Continue reading on GaziCyber »
CyberSecurity #1
https://cdn-images-1.medium.com/max/836/1*DaMYsyP1PvlOZIxgFWlyAA.jpeg
Bu serimiz siber güvenlik başlığı altında en çok merak edilen ve rağbet gören konulardan birisi olan sızma testi (pentest) konusundan…
Continue reading on GaziCyber »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Secret] Sheppard software | Free Online Brain Game । Sheppard software – If you looking for…
https://cdn-images-1.medium.com/max/1080/1*L_q1M0gHylfe4FJmpwwxqQ.png
If you are a student or if you consider yourself very strong in Math or want to make it, then you have come to the right post
.
read…
Continue reading on Medium »
[Secret] Sheppard software | Free Online Brain Game । Sheppard software – If you looking for…
https://cdn-images-1.medium.com/max/1080/1*L_q1M0gHylfe4FJmpwwxqQ.png
If you are a student or if you consider yourself very strong in Math or want to make it, then you have come to the right post
.
read…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
THE OSI MODEL {AN OVERVIEW}
https://cdn-images-1.medium.com/max/2600/1*6-Bf0wpNg8U5hiW0aMSPvQ.jpeg
The OSI (Open Systems Interconnection) Model is a standardized model which we use to demonstrate the theory behind computer networking. In…
Continue reading on Medium »
THE OSI MODEL {AN OVERVIEW}
https://cdn-images-1.medium.com/max/2600/1*6-Bf0wpNg8U5hiW0aMSPvQ.jpeg
The OSI (Open Systems Interconnection) Model is a standardized model which we use to demonstrate the theory behind computer networking. In…
Continue reading on Medium »