Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Can I publish an exploit code to exploit-db.com after a CVE ID gets assigned?
I have found a vulnerability in a local vendor's product, who wasn't found in MITRE's CNA table. Also, there is no Vulnerability research programs in my country AFA my research went.
Edit: There is, but the application procedure is terrible. Looking into it.
I intend to email the vendor first and then request MITRE for a CVE-ID. However, I have three questions on the subject.
1. In the event of the vendor not acknowledging my findings (the chances of this happening is pretty high), and a CVE-ID gets assigned, can I still publish the exploit code to exploit-db.com?
2. Can I publish a writeup on how I have found the vulnerability once a CVE ID is assigned?
3. On MITRE's website, they says that the researcher who request a CVE-ID won't be credited. Is there any way that I could get credited for the vulnerability I found?
This is my first zero day and I don't know how to proceed further as different websites propose conflicting information on this. Kindly guide me on how to report this.
PS: I am not looking for bounty money; I'm just trying to mark my humble presence into the vast cyber security world.
submitted by /u/Mr-introVert
[link] [comments]
Can I publish an exploit code to exploit-db.com after a CVE ID gets assigned?
I have found a vulnerability in a local vendor's product, who wasn't found in MITRE's CNA table. Also, there is no Vulnerability research programs in my country AFA my research went.
Edit: There is, but the application procedure is terrible. Looking into it.
I intend to email the vendor first and then request MITRE for a CVE-ID. However, I have three questions on the subject.
1. In the event of the vendor not acknowledging my findings (the chances of this happening is pretty high), and a CVE-ID gets assigned, can I still publish the exploit code to exploit-db.com?
2. Can I publish a writeup on how I have found the vulnerability once a CVE ID is assigned?
3. On MITRE's website, they says that the researcher who request a CVE-ID won't be credited. Is there any way that I could get credited for the vulnerability I found?
This is my first zero day and I don't know how to proceed further as different websites propose conflicting information on this. Kindly guide me on how to report this.
PS: I am not looking for bounty money; I'm just trying to mark my humble presence into the vast cyber security world.
submitted by /u/Mr-introVert
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities
Mole is a framework for identifying and exploiting out-of-band (OOB) vulnerabilities. Installation & Setup Mole Install Python >= 3.6 virtualenv -p /usr/bin/python3 venvsource venv/bin/activate./venv/bin/pip3 install -r requirements.txtgit submodule update --init --recursive Set an API key in config.yml (must be the same for the client and server) DNS Configuration You’ll need to configure the DNS records […]
The post Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities appeared first on Kali Linux Tutorials.
Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities
Mole is a framework for identifying and exploiting out-of-band (OOB) vulnerabilities. Installation & Setup Mole Install Python >= 3.6 virtualenv -p /usr/bin/python3 venvsource venv/bin/activate./venv/bin/pip3 install -r requirements.txtgit submodule update --init --recursive Set an API key in config.yml (must be the same for the client and server) DNS Configuration You’ll need to configure the DNS records […]
The post Mole : A Framework For Identifying & Exploiting Out-Of-Band Application Vulnerabilities appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OWASP API #9: Improper Assets Management
https://cdn-images-1.medium.com/max/700/0*VOxZb0CcO0psFL9k
Want to learn how big enterprises such as Facebook can easily be hacked? Can have a look to learn about Improper Assets Management.
Continue reading on strike.sh »
OWASP API #9: Improper Assets Management
https://cdn-images-1.medium.com/max/700/0*VOxZb0CcO0psFL9k
Want to learn how big enterprises such as Facebook can easily be hacked? Can have a look to learn about Improper Assets Management.
Continue reading on strike.sh »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What are Crawlers and how do They Work?
https://cdn-images-1.medium.com/max/671/0*iwM2xk6hpGZJ4Gtw.png
These crawlers discover content through various means. One being by pure discovery, where a URL is visited by the crawler and information…
Continue reading on Medium »
What are Crawlers and how do They Work?
https://cdn-images-1.medium.com/max/671/0*iwM2xk6hpGZJ4Gtw.png
These crawlers discover content through various means. One being by pure discovery, where a URL is visited by the crawler and information…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Retrieve Deleted Text Messages From Your Husband Phone.
Because of this video guide, you can now learn how to read your girlfriends, boyfriend, husbandWhatsApp messages on an iPhone or android…
Continue reading on Medium »
Retrieve Deleted Text Messages From Your Husband Phone.
Because of this video guide, you can now learn how to read your girlfriends, boyfriend, husbandWhatsApp messages on an iPhone or android…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CyberSecurity #1
https://cdn-images-1.medium.com/max/836/1*DaMYsyP1PvlOZIxgFWlyAA.jpeg
Bu serimiz siber güvenlik başlığı altında en çok merak edilen ve rağbet gören konulardan birisi olan sızma testi (pentest) konusundan…
Continue reading on GaziCyber »
CyberSecurity #1
https://cdn-images-1.medium.com/max/836/1*DaMYsyP1PvlOZIxgFWlyAA.jpeg
Bu serimiz siber güvenlik başlığı altında en çok merak edilen ve rağbet gören konulardan birisi olan sızma testi (pentest) konusundan…
Continue reading on GaziCyber »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Secret] Sheppard software | Free Online Brain Game । Sheppard software – If you looking for…
https://cdn-images-1.medium.com/max/1080/1*L_q1M0gHylfe4FJmpwwxqQ.png
If you are a student or if you consider yourself very strong in Math or want to make it, then you have come to the right post
.
read…
Continue reading on Medium »
[Secret] Sheppard software | Free Online Brain Game । Sheppard software – If you looking for…
https://cdn-images-1.medium.com/max/1080/1*L_q1M0gHylfe4FJmpwwxqQ.png
If you are a student or if you consider yourself very strong in Math or want to make it, then you have come to the right post
.
read…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
THE OSI MODEL {AN OVERVIEW}
https://cdn-images-1.medium.com/max/2600/1*6-Bf0wpNg8U5hiW0aMSPvQ.jpeg
The OSI (Open Systems Interconnection) Model is a standardized model which we use to demonstrate the theory behind computer networking. In…
Continue reading on Medium »
THE OSI MODEL {AN OVERVIEW}
https://cdn-images-1.medium.com/max/2600/1*6-Bf0wpNg8U5hiW0aMSPvQ.jpeg
The OSI (Open Systems Interconnection) Model is a standardized model which we use to demonstrate the theory behind computer networking. In…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
You can’t protect what you can’t see
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg You can’t protect what you can’t seePost Views: 44
When it comes to advanced threat protection from a defensive perspective, you usually make sure to invest in various hardware and software solutions such as Intrusion Prevention Systems. Intrusion Detection System working proactively, analyzing the behavior of the attacks and using AI (Artificial Intelligence), take certain actions to prevent attacks from happening.
The problem occurs because of the lack of testing from an external point of view of these devices. Even vendors who sell these solutions tend to have flaws one way or another that will affect a lot of users using these solutions. This is proven in many ways, through either newly zero-day exploit attacks that are discovered or using different ways of compromising a network of systems by directly attacking the human element with advanced social engineering attacks without even touching the hardware.
Visibility on your network is a very important aspect. Often needs the help of the Offensive Security and Red Teams who do not know your network setup and can be performed as part of ‘Black Box Pentesting’ who train to find these flaws with a certain mindset and experience that should not come from a defensive perspective. This will bring new visibility that would lead to revealing hints as part of reconnaissance techniques requiring real human and manual intervention, to reach a stage of compromising the network, when it reaches the attack phase.
Historically, IPS and such products have provided visibility into network packets to be able to identify and block network attacks, and that is not enough. Even by setting measures to work on a dynamic computing environment such as monitoring Operating Systems, Applications, Mobile Devices, IoT Devices, Virtual Machines, File Transfers, Malware, Malicious Connections, Anomalous Behavior – the reaction is often too slow and late, as we already saw several companies find out about the breach months if not years later.
Visibility Enables Control. Offensive Security is a crucial way of discovering how security researchers see your network from the outside and this is what makes the difference. Such Solutions vary from Bug Bounty Programs, Black Box Pen-testing, and more which should be performed frequently not just for the sake of compliance, but realizing how important it is, to understand and improve the reaction time of when real-time attacks take place to prevent or recover fast from such attempts.
Frequently asking for your infrastructure to be tested is a must, budgets should increase by demanding these types of solutions and prioritizing the essence by understanding the significance of such assessments. Each day multiple vulnerabilities are found, it takes time for vendors to patch them, and even more time for their clients to perform the patching, which leaves a great percent of users and companies vulnerable without knowing it. Recent Facts* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/02/Fact_Website-Template-90x90.png Manual Pentesting is more Effective than the Automated1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/Fact_Website-Template-90x90.png 90% of the hacking process involves the Reconnaissance Phase2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/Website-90x90.png A Hacker needs only one loophole to hack any system.4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/10/Website_2-90x90.png Not all hackers are criminals5 months ago
* https://www.blackhat[...]
You can’t protect what you can’t see
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg You can’t protect what you can’t seePost Views: 44
When it comes to advanced threat protection from a defensive perspective, you usually make sure to invest in various hardware and software solutions such as Intrusion Prevention Systems. Intrusion Detection System working proactively, analyzing the behavior of the attacks and using AI (Artificial Intelligence), take certain actions to prevent attacks from happening.
The problem occurs because of the lack of testing from an external point of view of these devices. Even vendors who sell these solutions tend to have flaws one way or another that will affect a lot of users using these solutions. This is proven in many ways, through either newly zero-day exploit attacks that are discovered or using different ways of compromising a network of systems by directly attacking the human element with advanced social engineering attacks without even touching the hardware.
Visibility on your network is a very important aspect. Often needs the help of the Offensive Security and Red Teams who do not know your network setup and can be performed as part of ‘Black Box Pentesting’ who train to find these flaws with a certain mindset and experience that should not come from a defensive perspective. This will bring new visibility that would lead to revealing hints as part of reconnaissance techniques requiring real human and manual intervention, to reach a stage of compromising the network, when it reaches the attack phase.
Historically, IPS and such products have provided visibility into network packets to be able to identify and block network attacks, and that is not enough. Even by setting measures to work on a dynamic computing environment such as monitoring Operating Systems, Applications, Mobile Devices, IoT Devices, Virtual Machines, File Transfers, Malware, Malicious Connections, Anomalous Behavior – the reaction is often too slow and late, as we already saw several companies find out about the breach months if not years later.
Visibility Enables Control. Offensive Security is a crucial way of discovering how security researchers see your network from the outside and this is what makes the difference. Such Solutions vary from Bug Bounty Programs, Black Box Pen-testing, and more which should be performed frequently not just for the sake of compliance, but realizing how important it is, to understand and improve the reaction time of when real-time attacks take place to prevent or recover fast from such attempts.
Frequently asking for your infrastructure to be tested is a must, budgets should increase by demanding these types of solutions and prioritizing the essence by understanding the significance of such assessments. Each day multiple vulnerabilities are found, it takes time for vendors to patch them, and even more time for their clients to perform the patching, which leaves a great percent of users and companies vulnerable without knowing it. Recent Facts* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/02/Fact_Website-Template-90x90.png Manual Pentesting is more Effective than the Automated1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/Fact_Website-Template-90x90.png 90% of the hacking process involves the Reconnaissance Phase2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/Website-90x90.png A Hacker needs only one loophole to hack any system.4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/10/Website_2-90x90.png Not all hackers are criminals5 months ago
* https://www.blackhat[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking You can’t protect what you can’t see https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg You can’t protect what you can’t seePost Views: 44 When it comes to advanced threat protection…
ethicalhacking.com/wp-content/uploads/2020/08/Website-90x90.png Human Intelligence is the best defense against Phishing Attacks7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/07/Website-90x90.png Firewalls are no longer enough8 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/06/Website-90x90.png Your Data in the Cloud is not as secure as you think9 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/05/Website-90x90.png The Weakest Link in a Security Chain is the Human Element10 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/04/Copy-of-Website-fact-90x90.png Two-Factor Authentication is not always Totally Secure11 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/03/Website-fact-90x90.png VPN: You may not be as secure as you think you are1 year ago
The post You can’t protect what you can’t see first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/07/Website-90x90.png Firewalls are no longer enough8 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/06/Website-90x90.png Your Data in the Cloud is not as secure as you think9 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/05/Website-90x90.png The Weakest Link in a Security Chain is the Human Element10 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/04/Copy-of-Website-fact-90x90.png Two-Factor Authentication is not always Totally Secure11 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/03/Website-fact-90x90.png VPN: You may not be as secure as you think you are1 year ago
The post You can’t protect what you can’t see first appeared on Black Hat Ethical Hacking.