hacking: security in practice
Hardware Hacking (RF, RFID, NFC, MagStripe, SmartCard, etc).
Hey r/Hacking!
Hope you’ve had a fantastic day.
I’m a college student and I’ve got some money lying around I could use to buy some tools to expand my hardware hacking skills.
I’m aware there exists a LOT of different tools for different things. I’ve done research and found 4 different things that do RFID reading and writing, but couldn’t quite figure out which was the best.
I’m looking to read/write RF, RFID, NFC, MagStripe and SmartCard and resources I could learn from.
This far, I’ve found the RF One by Hak5 for RF.
Proxmark for RFID and NFC.
MSR605X for MagStripe.
Any SmartCard tools?
Thank you!
submitted by /u/secjoe
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Hardware Hacking (RF, RFID, NFC, MagStripe, SmartCard, etc).
Hey r/Hacking!
Hope you’ve had a fantastic day.
I’m a college student and I’ve got some money lying around I could use to buy some tools to expand my hardware hacking skills.
I’m aware there exists a LOT of different tools for different things. I’ve done research and found 4 different things that do RFID reading and writing, but couldn’t quite figure out which was the best.
I’m looking to read/write RF, RFID, NFC, MagStripe and SmartCard and resources I could learn from.
This far, I’ve found the RF One by Hak5 for RF.
Proxmark for RFID and NFC.
MSR605X for MagStripe.
Any SmartCard tools?
Thank you!
submitted by /u/secjoe
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hardware Hacking (RF, RFID, NFC, MagStripe, SmartCard, etc).
Hey r/Hacking! Hope you’ve had a fantastic day. I’m a college student and I’ve got some money lying around I could use to buy some tools to...
hacking: security in practice
Thoughts on how to protect against a LSA secrets dump/ NTDS.DIT attack
Looking to probe the minds of the many brilliant people on here as to how I can protect our environment from a attack. We recently had a security audit and the tester was able to pull clear text passwords from some PCs from LSA and use that to move laterally. Then he found some admin creds in clear text and game over was able to pull the entire NTDS.DIT database. We have since then made the following changes:
Limited credentials to be cached to 0 and 1 in some instances (laptops)
Disabled Debugging/ added LSA protection as per Microsoft article "Here"
Deployed LAPS for local admin password policys to avoid the lateral movement.
Patched the heck out of all servers via nessus vul scan /results.
How else could I protect myself from this kind of attack in future or block this kind of toolset.
submitted by /u/idahud
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Thoughts on how to protect against a LSA secrets dump/ NTDS.DIT attack
Looking to probe the minds of the many brilliant people on here as to how I can protect our environment from a attack. We recently had a security audit and the tester was able to pull clear text passwords from some PCs from LSA and use that to move laterally. Then he found some admin creds in clear text and game over was able to pull the entire NTDS.DIT database. We have since then made the following changes:
Limited credentials to be cached to 0 and 1 in some instances (laptops)
Disabled Debugging/ added LSA protection as per Microsoft article "Here"
Deployed LAPS for local admin password policys to avoid the lateral movement.
Patched the heck out of all servers via nessus vul scan /results.
How else could I protect myself from this kind of attack in future or block this kind of toolset.
submitted by /u/idahud
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Thoughts on how to protect against a LSA secrets dump/ NTDS.DIT attack
Looking to probe the mind of the many brilliant minds on here as to how I can protect our environment from a attack. We recently had a security...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best Practices to Protect Against Conti Ransomware, from Case Study to Recovery
https://cdn-images-1.medium.com/max/1201/0*K9y7e9_y_yIotNZ1
Carrying on from our recent work on Prometheus Ransomware, we have new thoughts and intelligence to share on Conti Ransomware. However…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Best Practices to Protect Against Conti Ransomware, from Case Study to Recovery
https://cdn-images-1.medium.com/max/1201/0*K9y7e9_y_yIotNZ1
Carrying on from our recent work on Prometheus Ransomware, we have new thoughts and intelligence to share on Conti Ransomware. However…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Best Practices to Protect Against Conti Ransomware, from Case Study to Recovery
Carrying on from our recent work on Prometheus Ransomware, we have new thoughts and intelligence to share on Conti Ransomware. However…
일이 취미가 되고 취미가 일이 될 때
https://medium.com/deliverytechkorea/%EC%9D%BC%EC%9D%B4-%EC%B7%A8%EB%AF%B8%EA%B0%80-%EB%90%98%EA%B3%A0-%EC%B7%A8%EB%AF%B8%EA%B0%80-%EC%9D%BC%EC%9D%B4-%EB%90%A0-%EB%95%8C-5bc875e40965?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/deliverytechkorea/%EC%9D%BC%EC%9D%B4-%EC%B7%A8%EB%AF%B8%EA%B0%80-%EB%90%98%EA%B3%A0-%EC%B7%A8%EB%AF%B8%EA%B0%80-%EC%9D%BC%EC%9D%B4-%EB%90%A0-%EB%95%8C-5bc875e40965?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
일이 취미가 되고, 취미가 일이 될 때
새로운 취미를 함께 즐기는 동료를 만날 수 있어요!
새로운 취미를 함께 즐기는 동료를 만날 수 있어요!Continue reading on Delivery Tech Korea — 요기요기술 블로그 » (https://medium.com/deliverytechkorea/%EC%9D%BC%EC%9D%B4-%EC%B7%A8%EB%AF%B8%EA%B0%80-%EB%90%98%EA%B3%A0-%EC%B7%A8%EB%AF%B8%EA%B0%80-%EC%9D%BC%EC%9D%B4-%EB%90%A0-%EB%95%8C-5bc875e40965?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
일이 취미가 되고, 취미가 일이 될 때
새로운 취미를 함께 즐기는 동료를 만날 수 있어요!
일이 취미가 되고 취미가 일이 될 때
새로운 취미를 함께 즐기는 동료를 만날 수 있어요!Continue reading on Delivery Tech Korea — 요기요기술 블로그 »
Read more...
새로운 취미를 함께 즐기는 동료를 만날 수 있어요!Continue reading on Delivery Tech Korea — 요기요기술 블로그 »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bus Pass Management System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Bus Pass Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
# Exploit Title: Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
# Date: 2021-09-08
# Exploit Author: Emre Aslan
# Vendor Homepage: https://phpgurukul.com/
# Software Link: https://phpgurukul.com/wp-content/uploads/2021/07/Bus-Pass-Management-System-Using-PHP-MySQL.zip
# Version: 1.0
# Tested on: Windows 11 - XAMPP Server
# Vulnerable page: host/admin/*
# Vulnerable Code:
Admin[PAYLOAD]
# Vulnerable Parameter: adminname[ POST Data ]
# Tested Payload:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Bus Pass Management System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Bus Pass Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
c6c1e5986347851fef16dc0de5d2b63fDownload
# Exploit Title: Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
# Date: 2021-09-08
# Exploit Author: Emre Aslan
# Vendor Homepage: https://phpgurukul.com/
# Software Link: https://phpgurukul.com/wp-content/uploads/2021/07/Bus-Pass-Management-System-Using-PHP-MySQL.zip
# Version: 1.0
# Tested on: Windows 11 - XAMPP Server
# Vulnerable page: host/admin/*
# Vulnerable Code:
Admin[PAYLOAD]
# Vulnerable Parameter: adminname[ POST Data ]
# Tested Payload:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Bus Pass Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ECOA Building Automation System Hidden Backdoor Accounts
___________________________
@hacking_Attack
@Hacking_Video
ECOA Building Automation System Hidden Backdoor Accounts
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ECOA Building Automation System Hidden Backdoor Accounts
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ECOA Building Automation System Weak Default Credentials
___________________________
@hacking_Attack
@Hacking_Video
ECOA Building Automation System Weak Default Credentials
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ECOA Building Automation System Weak Default Credentials
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ECOA Building Automation System Path Traversal / Arbitrary File Upload
___________________________
@hacking_Attack
@Hacking_Video
ECOA Building Automation System Path Traversal / Arbitrary File Upload
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ECOA Building Automation System Path Traversal / Arbitrary File Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ECOA Building Automation System Directory Traversal
___________________________
@hacking_Attack
@Hacking_Video
ECOA Building Automation System Directory Traversal
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ECOA Building Automation System Directory Traversal
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.