Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
I want to catch a scammer who had been ripping off my brother until he died last month. He's been dead less than 4 weeks and this person is now already hitting me up for money. Any ideas on how to get info on them to turn over to LE without scaring them away?

My older brother was 53 and lonely. He died of a heart attack at the end of August, and since then I have found out that he was being scammed by at least two people. The first person had conned him into sending over $5K to "invest in cryptocurrency". Soon after he passed away, I found this person on Facebook and I quickly scared them off by saying my brother's probate attorney needed to get in touch with them to discuss liquefying his investments. Within minutes, I got blocked on FB and that's the only connection I had.

Now I am being texted by someone who claims they were my brother's fiancee. He never told me he was engaged or even seeing anyone, but that's not out of his character; he was very introverted and private.

I got his "fiancee"'s phone number when she called his phone shortly after he died. At that point, all she would say was that they were engaged. But now, less than a month after he died, she has begun asking me for money. Her story is: she is starting an online business and my brother had helped her finance it, and now that he's gone she needs help keeping her business afloat. She had the gall to include the line, "it would make your brother sad if our business failed."

I haven't scared this one away yet. All I have is a phone number. Any ideas on ways I could get closer to finding out this scumbag's identity? I would like to report them to the authorities for online fraud.

submitted by /u/izimand
[link] [comments]
hacking: security in practice
How wpscan works?

Hello guys,



I already know and use WPScan (I'm a beginner). But I would like to know how this tool works (WPScan). I would like to know what she does so that it is possible to scan a WordPress site in this way.

Could someone explain?

submitted by /u/essencedata
[link] [comments]
hacking: security in practice
Can't get PCUnlocker to boot

I'm trying to unlock a forgotten password Windows 10 machine. I tried using Ubuntu live, but ran into road blocks and caved and bought PCUnlocker. Thing is, the PC is resisting to boot to the USB drive with the iso on it. I've screwed around with the various BIOS settings related to secure boot, UEFI vs legacy, etc, but nothing seems to work. Any suggestions?

submitted by /u/Mastiff37
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
VP Techno Labs Hailed as One of India’s Most Recommended Cybersecurity Company

Thinking about the past two years brings us joy. Can you imagine that it has already been two years since we’ve embarked on this journey…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Fitness Calculators 1.9.5 Cross Site Request Forgery

https://4.bp.blogspot.com/-4IgemuXxvlQ/WWlvJOAjEHI/AAAAAAAAIL4/GJdo6H5fQo4z7HKyurc-fIH3InSyWxX3gCLcBGAs/s1600/h145.png
WordPress Fitness Calculators plugin version 1.9.5 suffers from a cross site request forgery vulnerability.

MD5 | 30ca373f3886f6f98013bb82a0a42e7c

Download
# Exploit Title: WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
# Date: 2/28/2021
# Author: 0xB9
# Software Link: https://wordpress.org/plugins/fitness-calculators/
# Version: 1.9.5
# Tested on: Windows 10
# CVE: CVE-2021-24272

1. Description:
The plugin add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers.
Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

2. Proof of Concept:

Source:packetstormsecurity.com