Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Really interesting concept using a simple script for DNS DoS Attacks
https://external-preview.redd.it/c68XAGB9BXUhjBR_74f-ZoZkbk59rsMltO7nSgu1xxE.jpg?width=640&crop=smart&auto=webp&s=db9d7670b329776ccbba64b0d868df17c81ee4f3 submitted by /u/entropydaemon3
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Really interesting concept using a simple script for DNS DoS Attacks
https://external-preview.redd.it/c68XAGB9BXUhjBR_74f-ZoZkbk59rsMltO7nSgu1xxE.jpg?width=640&crop=smart&auto=webp&s=db9d7670b329776ccbba64b0d868df17c81ee4f3 submitted by /u/entropydaemon3
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Really interesting concept using a simple script for DNS DoS Attacks
Posted in r/hacking by u/entropydaemon3 • 1 point and 0 comments
hacking: security in practice
Setting up a hotspot that proxies through burpsuite
How can I do this? I use windows and I want to mitm some android apis, I already installed the root certificates on the device but the default android proxy settings don't seem to apply to all traffic. So I thought about setting up a wireless access point that routes all the traffic through burpsuite. (or maybe something else is better?) any software thats worth looking into?
I have no idea how to set this up however, I have a dd wrt router at my disposal and network devices that can be put in hotspot mode
submitted by /u/n1c39uy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Setting up a hotspot that proxies through burpsuite
How can I do this? I use windows and I want to mitm some android apis, I already installed the root certificates on the device but the default android proxy settings don't seem to apply to all traffic. So I thought about setting up a wireless access point that routes all the traffic through burpsuite. (or maybe something else is better?) any software thats worth looking into?
I have no idea how to set this up however, I have a dd wrt router at my disposal and network devices that can be put in hotspot mode
submitted by /u/n1c39uy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Setting up a hotspot that proxies through burpsuite
How can I do this? I use windows and I want to mitm some android apis, I already installed the root certificates on the device but the default...
Bug-Bounty | FASTMAIL [topicbox.com: Privileges Escalation > Organization Takeover]
https://medium.com/@the.white.soul.0/bug-bounty-fastmail-topicbox-com-privileges-escalation-organization-takeover-815466876ad4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@the.white.soul.0/bug-bounty-fastmail-topicbox-com-privileges-escalation-organization-takeover-815466876ad4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug-Bounty | FASTMAIL [topicbox.com: Privileges Escalation > Organization Takeover]
Hi everyone
Hi everyoneContinue reading on Medium » (https://medium.com/@the.white.soul.0/bug-bounty-fastmail-topicbox-com-privileges-escalation-organization-takeover-815466876ad4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug-Bounty | FASTMAIL [topicbox.com: Privileges Escalation > Organization Takeover]
Hi everyone
Bug-Bounty | FASTMAIL [topicbox.com: Privileges Escalation > Organization Takeover]
Hi everyoneContinue reading on Medium »
Read more...
Hi everyoneContinue reading on Medium »
Read more...
Bug Bounty en Software Libre
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKINGContinue reading on Medium »
Read more...
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKINGContinue reading on Medium »
Read more...
Deep Web
How do escrow sites scam you?
Since both you and the seller have to ok the transaction how do you get scammed? Is it the escrow service stealing your money or the vendor lying about having an escrow?
submitted by /u/Illustrious-Web9850
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do escrow sites scam you?
Since both you and the seller have to ok the transaction how do you get scammed? Is it the escrow service stealing your money or the vendor lying about having an escrow?
submitted by /u/Illustrious-Web9850
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do escrow sites scam you?
Since both you and the seller have to ok the transaction how do you get scammed? Is it the escrow service stealing your money or the vendor lying...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
MY FIRST BLOG! AND ABOUT ME!
https://cdn-images-1.medium.com/max/600/1*ZbWeKVpm9uks7m-ljavrRg.jpeg
Hello everyone:)!!Hope are all doing good and having fun. A few weeks ago i thought of writing blogs on cyber security, yes you heard it…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
MY FIRST BLOG! AND ABOUT ME!
https://cdn-images-1.medium.com/max/600/1*ZbWeKVpm9uks7m-ljavrRg.jpeg
Hello everyone:)!!Hope are all doing good and having fun. A few weeks ago i thought of writing blogs on cyber security, yes you heard it…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
MY FIRST BLOG! AND ABOUT ME!
Hello everyone:)!!Hope are all doing good and having fun. A few weeks ago i thought of writing blogs on cyber security, yes you heard it…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best Ethical Hacking Online Institue In India
https://cdn-images-1.medium.com/max/1080/1*W2hhIiYUp6OCUorCi28LsA.jpeg
Best Ethical Hacking Course in India
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Best Ethical Hacking Online Institue In India
https://cdn-images-1.medium.com/max/1080/1*W2hhIiYUp6OCUorCi28LsA.jpeg
Best Ethical Hacking Course in India
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Best Ethical Hacking Online Institue In India
Best Ethical Hacking Course in India
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox — Validation
https://cdn-images-1.medium.com/max/1180/1*QhgSL8oGQ8Q1r0LE8EcXyw.png
As always, we start with nmap to discover open ports/services.
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox — Validation
https://cdn-images-1.medium.com/max/1180/1*QhgSL8oGQ8Q1r0LE8EcXyw.png
As always, we start with nmap to discover open ports/services.
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox — Validation
As always, we start with nmap to discover open ports/services.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bug Bounty en Software Libre
https://cdn-images-1.medium.com/max/1153/0*pu9MidpmuWL3F6UZ
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty en Software Libre
https://cdn-images-1.medium.com/max/1153/0*pu9MidpmuWL3F6UZ
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty en Software Libre
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
http://www.kitploit.com/2021/09/jspanda-client-side-prototype-pullution.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/jspanda-client-side-prototype-pullution.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
JSpanda is client-side prototype pollution vulnerability (https://www.kitploit.com/search/label/Vulnerability) scanner. It has two key features, scanning vulnerability the supplied URLs and analyzing the JavaScript libraries' source code. However, JSpanda cannot detect advanced prototype pollution vulnerabilities.
How JSPanda works?
Uses multiple payloads for prototype pollution vulnerability. Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver. Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually.
Requirements
Download latest version of Google Chrome and Chromedriver Selenium
Usage
Scan: python3.7 jspanda.py Add URLs to url.txt file, for instance : example.com Basic Source Code Analysis (https://www.kitploit.com/search/label/Source%20Code%20Analysis) : python3.7 analyze.py Add a JavaScript library's source code to analyze.js Generate PoC code using analyze.py Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything.
Demonstration
___________________________
@hacking_Attack
@Hacking_Video
How JSPanda works?
Uses multiple payloads for prototype pollution vulnerability. Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver. Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually.
Requirements
Download latest version of Google Chrome and Chromedriver Selenium
Usage
Scan: python3.7 jspanda.py Add URLs to url.txt file, for instance : example.com Basic Source Code Analysis (https://www.kitploit.com/search/label/Source%20Code%20Analysis) : python3.7 analyze.py Add a JavaScript library's source code to analyze.js Generate PoC code using analyze.py Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything.
Demonstration
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Source code analysis (https://www.kitploit.com/search/label/Code%20Analysis) - Screenshot
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.