Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CyberSecurity #1

https://cdn-images-1.medium.com/max/836/1*DaMYsyP1PvlOZIxgFWlyAA.jpeg
Bu serimiz siber güvenlik başlığı altında en çok merak edilen ve rağbet gören konulardan birisi olan sızma testi (pentest) konusundan…

Continue reading on GaziCyber »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
THE OSI MODEL {AN OVERVIEW}

https://cdn-images-1.medium.com/max/2600/1*6-Bf0wpNg8U5hiW0aMSPvQ.jpeg
The OSI (Open Systems Interconnection) Model is a standardized model which we use to demonstrate the theory behind computer networking. In…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
You can’t protect what you can’t see

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg You can’t protect what you can’t seePost Views: 44
When it comes to advanced threat protection from a defensive perspective, you usually make sure to invest in various hardware and software solutions such as Intrusion Prevention Systems. Intrusion Detection System working proactively, analyzing the behavior of the attacks and using AI (Artificial Intelligence), take certain actions to prevent attacks from happening.
The problem occurs because of the lack of testing from an external point of view of these devices. Even vendors who sell these solutions tend to have flaws one way or another that will affect a lot of users using these solutions. This is proven in many ways, through either newly zero-day exploit attacks that are discovered or using different ways of compromising a network of systems by directly attacking the human element with advanced social engineering attacks without even touching the hardware.
Visibility on your network is a very important aspect. Often needs the help of the Offensive Security and Red Teams who do not know your network setup and can be performed as part of ‘Black Box Pentesting’ who train to find these flaws with a certain mindset and experience that should not come from a defensive perspective. This will bring new visibility that would lead to revealing hints as part of reconnaissance techniques requiring real human and manual intervention, to reach a stage of compromising the network, when it reaches the attack phase.
Historically, IPS and such products have provided visibility into network packets to be able to identify and block network attacks, and that is not enough. Even by setting measures to work on a dynamic computing environment such as monitoring Operating Systems, Applications, Mobile Devices, IoT Devices, Virtual Machines, File Transfers, Malware, Malicious Connections, Anomalous Behavior – the reaction is often too slow and late, as we already saw several companies find out about the breach months if not years later.
Visibility Enables Control. Offensive Security is a crucial way of discovering how security researchers see your network from the outside and this is what makes the difference. Such Solutions vary from Bug Bounty Programs, Black Box Pen-testing, and more which should be performed frequently not just for the sake of compliance, but realizing how important it is, to understand and improve the reaction time of when real-time attacks take place to prevent or recover fast from such attempts.
Frequently asking for your infrastructure to be tested is a must, budgets should increase by demanding these types of solutions and prioritizing the essence by understanding the significance of such assessments. Each day multiple vulnerabilities are found, it takes time for vendors to patch them, and even more time for their clients to perform the patching, which leaves a great percent of users and companies vulnerable without knowing it. Recent Facts* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/02/Fact_Website-Template-90x90.png Manual Pentesting is more Effective than the Automated1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/Fact_Website-Template-90x90.png 90% of the hacking process involves the Reconnaissance Phase2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/Website-90x90.png A Hacker needs only one loophole to hack any system.4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/10/Website_2-90x90.png Not all hackers are criminals5 months ago
* https://www.blackhat[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Comprehensive Guide to AutoRecon

The AutoRecon tool is designed as a network reconnaissance tool. It is a multi-threaded tool that performs automated enumeration of services. The purpose of this tool is to save time while cracking CTFs and other penetration testing environments or exams. It is useful in real-world engagements as well. Table of

The post Comprehensive Guide to AutoRecon appeared first on Hacking Articles.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Trying to get Parallels Desktop to work on my M1 Mac

I'm trying to get parallels to work on my m1 MacBook yet every time I try to create a Kali Linux vm I get a prompt that says: To perform this operation, you must enter the host OS administrator's credentials. And after clicking Ok on that error message I get one that states that: There is no operating system installed in this virtual machine. To install an OS, connect a source with OS installation files, such as a CD, thumb drive, or disk image, and reset the virtual machine. For more information, see Parallels Desktop Help**.** I followed Dave Bombal's YouTube tutorial on how to install Kali Linux on the M1 Macs yet it won't work at all. Any fixes for this issue?

submitted by /u/HRT-713
[link] [comments]
hacking: security in practice
Stalker

I have been hacked by my stalker and they are sending pictures to my friends from my private photos in my phone. Is there anyway I can find out who this is? Is there anyone put there that can help prove who it is? All I have is a fake phone number from a texting app. Someone please help

submitted by /u/brettb08
[link] [comments]
hacking: security in practice
I want to expose a scammer

I was scammed

I have evidence of a fake investing website and a person who is manipulating people on Instagram and Snapchat. She is stealing thousands of dollars worth of bitcoin I have emails wallet codes receipts, Snapchat and Instagram ID messages screen recordings etc.. if anyone knows how I can possibly retrieve stolen bitcoin or if anyone who happens to know how to do things in certain ways to get people to give things back 🆘 I could use ur knowledge right about now. Even if I can’t get the bitcoin back this person and website needs to be stopped and this person needs to be fucked with like they do to scammers on YouTube

submitted by /u/Sad_Glass_2435
[link] [comments]
hacking: security in practice
Is XSS still possible within websites that use Angular

hello everyone

I am really confuse about XSS

is websites that use angular in frontend and calls API via json data - still vulnerable to XSS attacks? or is it became irrelevant due to AOT angular and other feature that angular use.



I know that there are reflected XSS which deepened on the backend code not the front end side but i see that angular guys are confident that there products had became invincible.

submitted by /u/imposter_expert
[link] [comments]