Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
6 Tips for Limiting Damage from Third-Party Attacks

The ability to protect your organization from third-party attacks will become increasingly critical as attackers try to maximize the effectiveness of their malicious campaigns.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Comprehensive Guide on FFUF

In this article, we will learn how we can use ffuf. Where ffuf states for “Fuzz Faster U Fool”, it is an interesting open-source web fuzzing tool. Since its release, many people have gravitated towards ffuf, particularly in the bug bounty scenario. So, lets dive in to this learning process. Table of Content<o:p· Introduction to ffuf<o:p

· Setup<o:p

· Input Option:<o:p

o Simple Attack<o:p

o Multiple wordlists<o:p

o Ignore Wordlist Comment and Silent<o:p

o Extensions<o:p

· Match Options:<o:p

o Match HTTP Code<o:p

o Match Lines<o:p

o Match Words<o:p

o Match Size<o:p

o Match Regular Expression<o:p

· Filter Options:<o:p

o Filter Code<o:p

o Filter Lines<o:p

o Filter Size<o:p

o Filter Words<o:p

o Filter Regular Expression<o:p

· General Options<o:p

o Custom Auto Calibration<o:p

o Color<o:p

o Maxtime For Task<o:p

o Maxtime For Job<o:p

o Delay <o:po Request Rate<o:p

o Error Functions<o:p

o Verbose Mode<o:p

· Output Options:<o:p

o Output Format in HTML<o:p

o Output Format in CSV<o:p

o All Output Format<o:p

· HTTP Options<o:p

o Timeout<o:p

o Host Header<o:p

o Recursion<o:p

o Cluster Bomb with Burp suite<o:p

o Attack with Cookie<o:p

o Proxy with Burp suite<o:p

· Conclusion<o:p Introduction to ffuf<o:pIt is a professional command-line method for web fuzzing on web server. Many people have gravitated towards ffuf since its release, especially in the bug bounty scene. While the bulk of this shift is possibly attributable to the herd mentality, a significant portion of the group has made the switch due to FFUF's tempo, versatility, and capacity to easily merge with external tooling.<o:p

It is maintained as public open-source, this ensures that everyone can contribute to ffuf as long as the maintainer (@joohoi) acknowledges and "merges" the contributions back into the main project. <o:p Setup<o:pIt is a command-line programme that runs in the Linux Terminal or the Windows Command Prompt. Upgrading from source is not any more difficult than compiling from source, with the exception of the inclusion of the -u flag. When upgrading from the source code, use the following command.<o:p go get -u github.com/ffuf/ffuf<o:pDue to that fact we are using Kali Linux, we’ll find ffuf in the apt repositories, allowing us to install by running this simple command.<o:p apt install ffuf<o:phttps://1.bp.blogspot.com/-uLJVjFrFu34/YFyqN-oZFfI/AAAAAAAAu_k/RuIGahkBoMQXvcr1vho_JJclu72mOV-mACLcBGAsYHQ/s16000/1.png After installing this tool, to get its working parameters all we need is just use [-h]parameter through this parameter we can see all of its parameters with their functionalities.<o:p ffuf -h<o:phttps://1.bp.blogspot.com/-O3EShCVijKY/YFyqUI2MM5I/AAAAAAAAu_o/FMvJaxiTUkUmHMWmtEhDvZ58rNLfm7-CwCLcBGAsYHQ/s16000/2.png Input Options<o:pThese are those parameters which help us to provide the required data for web fuzzing. Example: URL and Wordlist.<o:p Simple Attack:<o:pFor the first attack, we need to use to simple parameters [-u]for target URL and [-w]to load a wordlist. Now, let’s type this command to run our first attack with this amazing tool.<o:p ffuf -u http://testphp.vulnweb.com/FUZZ/ -w dict.txt<o:pAfter performing this command, lets focus on the resul[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — SecNotes: Walkthrough (without Metasploit)

https://cdn-images-1.medium.com/max/600/1*mdh_NzY7qWvv50ocCGY63A.png
Hack The Box — SecNotes: Walkthrough (without Metasploit) | Windows Medium Level | SMB attack | Road to OSCP | Pentesting | Arbitrary…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Discovering and Enumerating with Metasploit

https://cdn-images-1.medium.com/max/1458/1*OykBOzinkTN34zz3NdbEoA.png
Metasploit is one of the best consoles for data gathering, as it is an exceptionally far-reaching penetration testing device. In this…

Continue reading on Dev Genius »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Passed The eLearnSecurity eJPT

https://cdn-images-1.medium.com/max/638/1*xd-kqPJBrGcFxuqIYXE-1g.png
I just passed the eLearnSecurity Junior Pentester (eJPT). The exam itself was so much fun it did not feel like an exam . I completed the…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Black Kingdom Ransomware busca servidores de Microsoft Exchange sin parches.

https://cdn-images-1.medium.com/max/971/0*GeQUeP2t43sxwBY8
Más de una semana después de que Microsoft lanzara una herramienta de mitigación con un solo clic para mitigar los ataques cibernéticos…

Continue reading on Medium »
Imagine a world with "Hack-Back Vigilantes"
https://www.reddit.com/r/Pentesting/comments/md4lxr/imagine_a_world_with_hackback_vigilantes/

<!-- SC_OFF -->The year is 2041... Taylor Swift is president... Congress has passed laws allowing companies that have been breached to retaliate and go after their cyber assailants. After presenting some evidence to the courts, victim companies are served warrants that allow them to hire Cyber Vigilantes to hunt down and infiltrate their attackers. Hack-Back Vigilante companies are popping up everywhere, the demand for offensive cyber talent is off the charts! Nerdy computer guys are suddenly hired guns... Netflix evolves into documentaries displaying 1000s of Linux terminals for hours upon hours. You, a tall, dark, and handsome actor severely regret spending all those hours in the gym instead of learning how to throw exploits... Because now... exploiters have it all... and you have to move to Bollywood. LEARN TO HACK! Future you can thank me later. <!-- SC_ON --> submitted by /u/st1cky_bits (https://www.reddit.com/user/st1cky_bits)
[link] (https://www.reddit.com/r/Pentesting/comments/md4lxr/imagine_a_world_with_hackback_vigilantes/) [comments] (https://www.reddit.com/r/Pentesting/comments/md4lxr/imagine_a_world_with_hackback_vigilantes/)