Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Photocopy or Identity theft ??
https://cdn-images-1.medium.com/max/1280/1*uzuue_A1Zd8VqZP7C_mTHg.png
When it comes to the digital era, you are nothing but a unique collection of data. Every mobile application, social platform, or any…
Continue reading on Medium »
Photocopy or Identity theft ??
https://cdn-images-1.medium.com/max/1280/1*uzuue_A1Zd8VqZP7C_mTHg.png
When it comes to the digital era, you are nothing but a unique collection of data. Every mobile application, social platform, or any…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Rusia se declara culpable del intento de extorsión y pirateo de Tesla.
https://cdn-images-1.medium.com/max/1600/0*lEHffDkm06RlUbUq
Su objetivo final era extorsionar a la empresa utilizando la información confidencial robada de los servidores de Tesla como palanca para…
Continue reading on Medium »
Rusia se declara culpable del intento de extorsión y pirateo de Tesla.
https://cdn-images-1.medium.com/max/1600/0*lEHffDkm06RlUbUq
Su objetivo final era extorsionar a la empresa utilizando la información confidencial robada de los servidores de Tesla como palanca para…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Smogcloud - Find Cloud Assets That No One Wants Exposed
https://1.bp.blogspot.com/-dJ8kx1J74Ko/YE6R6Yxa_ZI/AAAAAAAAVo0/lrwXCq55b0g8M2OW8B8hVpiZz2FK76fkQCNcBGAsYHQ/w640-h316/cloud_aws.png Find exposed AWS cloud assets that you did not know you had. A comprehensive asset inventory is step one to any capable security program. We made smogcloud to enable security engineers, penetration testers, and AWS administrators to monitor the collective changes that create dynamic and ephemeral internet-facing assets on a more frequent basis. May be useful to identify:
* Internet-facing FQDNs and IPs across one or hundreds of AWS accounts
* Misconfigurations or vulnerabilities
* Assets that are no longer in use
* Services not currently monitored
* Shadow IT Getting Started1.
Install and setup golang
2.
Install smogcloud using the following command
Set up aws environment variable for the account you wish to query. We suggest utilizing a read-only Security Auditor role. The following commands can be used to set environment variables:
Run the application
* s3
* https://{user_provided}.s3.amazonaws.com
* cloudfront
* https://{random_id}.cloudfront.net
* ec2
* ec2-{ip-seperated}.compute-1.amazonaws.com
* es
* https://{user_provided}-{random_id}.{region}.es.amazonaws.com
* elb
* http://{user_provided}-{random_id}.{region}.elb.amazonaws.com:80
* https://{user_provided}-{random_id}.{region}.elb.amazonaws.com:443
* elbv2
* https://{user_provided}-{random_id}.{region}.elb.amazonaws.com
* rds
* mysql://{user_provided}.{random_id}.{region}.rds.amazonaws.com:3306
* postgres://{user_provided}.{random_id}.{region}.rds.amazonaws.com:5432
* route53
* {user_provided}
* execute-api
* https://{random_id}.execute-api.{region}.amazonaws.com/{user_provided}
* cloudsearch
* https://doc-{user_provided}-{random_id}.{region}.cloudsearch.amazonaws.com
* transfer
* sftp://s-{random_id}.server.transfer.{region}.amazonaws.com
* iot
* mqtt://{random_id}.iot.{region}.amazonaws.com:8883
* https://{random_id}.iot.{region}.amazonaws.com:8443
* https://{random_id}.iot.{region}.amazonaws.com:443
* mq
* https://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:8162
* ssl://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:61617
* kafka
* b-{1,2,3,4}.{user_provided}.{random_id}.c{1,2}.kafka.{region}.amazonaws.com
* {user_provided}.{random_id}.c{1,2}.kafka.{region}.amazonaws.com
* cloud9
* https://{random_id}.vfs.cloud9.{region}.amazonaws.com
* mediastore
* https://{random_id}.data.mediastore.{region}.amazonaws.com.
* kinesisvideo
* https://{random_id}.kinesisvideo.{region}.amazonaws.com
* mediaconvert
* https://{random_id}.mediaconvert.{region}.amazonaws.com
* mediapackage
* https://{random_id}.mediapackage[...]
Smogcloud - Find Cloud Assets That No One Wants Exposed
https://1.bp.blogspot.com/-dJ8kx1J74Ko/YE6R6Yxa_ZI/AAAAAAAAVo0/lrwXCq55b0g8M2OW8B8hVpiZz2FK76fkQCNcBGAsYHQ/w640-h316/cloud_aws.png Find exposed AWS cloud assets that you did not know you had. A comprehensive asset inventory is step one to any capable security program. We made smogcloud to enable security engineers, penetration testers, and AWS administrators to monitor the collective changes that create dynamic and ephemeral internet-facing assets on a more frequent basis. May be useful to identify:
* Internet-facing FQDNs and IPs across one or hundreds of AWS accounts
* Misconfigurations or vulnerabilities
* Assets that are no longer in use
* Services not currently monitored
* Shadow IT Getting Started1.
Install and setup golang
2.
Install smogcloud using the following command
go get -u github.com/BishopFox/smogcloud 3. Set up aws environment variable for the account you wish to query. We suggest utilizing a read-only Security Auditor role. The following commands can be used to set environment variables:
export AWS_ACCOUNT_ID='' # Describe account
export AWS_ACCESS_KEY_ID='' # Access key for aws account
export AWS_SECRET_ACCESS_KEY='' # Secret key for aws account 4. Run the application
smogcloud or go run main.goCurrent ServicesSupported services for extracting internet exposures: * API Gateway
* CloudFront
* EC2
* Elastic Kubernetes Service
* Elastic Beanstalk
* Elastic Search
* Elastic Load Balancing
* IoT
* Lightsail
* MediaStore
* Relational Database Service
* Redshift
* Route53
* S3AWS PatternsFrom studying Open API documentation on RESTful AWS endpoints we determined these are the patterns of exposure URIs that you may find in AWS accounts. It is important to understand how to interact with these native services to test them for vulnerabilities and other misconfigurations. Security engineers may want to monitor Cloudtrail logs or build DNS monitoring for requests to these services.* s3
* https://{user_provided}.s3.amazonaws.com
* cloudfront
* https://{random_id}.cloudfront.net
* ec2
* ec2-{ip-seperated}.compute-1.amazonaws.com
* es
* https://{user_provided}-{random_id}.{region}.es.amazonaws.com
* elb
* http://{user_provided}-{random_id}.{region}.elb.amazonaws.com:80
* https://{user_provided}-{random_id}.{region}.elb.amazonaws.com:443
* elbv2
* https://{user_provided}-{random_id}.{region}.elb.amazonaws.com
* rds
* mysql://{user_provided}.{random_id}.{region}.rds.amazonaws.com:3306
* postgres://{user_provided}.{random_id}.{region}.rds.amazonaws.com:5432
* route53
* {user_provided}
* execute-api
* https://{random_id}.execute-api.{region}.amazonaws.com/{user_provided}
* cloudsearch
* https://doc-{user_provided}-{random_id}.{region}.cloudsearch.amazonaws.com
* transfer
* sftp://s-{random_id}.server.transfer.{region}.amazonaws.com
* iot
* mqtt://{random_id}.iot.{region}.amazonaws.com:8883
* https://{random_id}.iot.{region}.amazonaws.com:8443
* https://{random_id}.iot.{region}.amazonaws.com:443
* mq
* https://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:8162
* ssl://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:61617
* kafka
* b-{1,2,3,4}.{user_provided}.{random_id}.c{1,2}.kafka.{region}.amazonaws.com
* {user_provided}.{random_id}.c{1,2}.kafka.{region}.amazonaws.com
* cloud9
* https://{random_id}.vfs.cloud9.{region}.amazonaws.com
* mediastore
* https://{random_id}.data.mediastore.{region}.amazonaws.com.
* kinesisvideo
* https://{random_id}.kinesisvideo.{region}.amazonaws.com
* mediaconvert
* https://{random_id}.mediaconvert.{region}.amazonaws.com
* mediapackage
* https://{random_id}.mediapackage[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Smogcloud - Find Cloud Assets That No One Wants Exposed https://1.bp.blogspot.com/-dJ8kx1J74Ko/YE6R6Yxa_ZI/AAAAAAAAVo0/lrwXCq55b0g8M2OW8B8hVpiZz2FK76fkQCNcBGAsYHQ/w640-h316/cloud_aws.png Find exposed AWS cloud assets that you did…
.{region}.amazonaws.com/in/v1/{random_id}/channel
* elasticbeanstalk
* https://{random_id}.{user_provided}.elasticbeanstalk.com
* cognito
* https://{user_provided}.auth.{region}.amazoncognito.com References* AWS SDK Go
* API-guru Open API for AWS
* aws-cli Authors* Oscar Salazar - Initial work - Bishop Fox
* Rob Ragan - Initial work - Bishop Fox @sweepthatleg
* Brandon Gaudet - Initial work - Bishop Fox ContributionsWe do our best to maintain our tools, but can't always keep them as up to date as we'd like. So, we always appreciate code contributions, feature requests, and bug reports. AcknowledgmentsThank you for inspiration
* Cloudmapper
* AWS Public IPs
* John Backes & Tiros
* IAM Access Analyzer
* Cartography Download Smogcloud
* elasticbeanstalk
* https://{random_id}.{user_provided}.elasticbeanstalk.com
* cognito
* https://{user_provided}.auth.{region}.amazoncognito.com References* AWS SDK Go
* API-guru Open API for AWS
* aws-cli Authors* Oscar Salazar - Initial work - Bishop Fox
* Rob Ragan - Initial work - Bishop Fox @sweepthatleg
* Brandon Gaudet - Initial work - Bishop Fox ContributionsWe do our best to maintain our tools, but can't always keep them as up to date as we'd like. So, we always appreciate code contributions, feature requests, and bug reports. AcknowledgmentsThank you for inspiration
* Cloudmapper
* AWS Public IPs
* John Backes & Tiros
* IAM Access Analyzer
* Cartography Download Smogcloud
hacking: security in practice
4 family members phone hacked
I don't know if this is the right sub but hopefully someone here can help me figure out what's going on. So within the past week 4 of my family members phones have been acting real strange. Their carriers randomly switched, can't open apps or send or receive messages / phone calls. How hard would it be for someone with all of their numbers that knows absolutely nothing about hacking to screw their phones up like this? At this point they have all got new phones because they never could figure out how to fix their old one.
submitted by /u/Siddoxy
[link] [comments]
4 family members phone hacked
I don't know if this is the right sub but hopefully someone here can help me figure out what's going on. So within the past week 4 of my family members phones have been acting real strange. Their carriers randomly switched, can't open apps or send or receive messages / phone calls. How hard would it be for someone with all of their numbers that knows absolutely nothing about hacking to screw their phones up like this? At this point they have all got new phones because they never could figure out how to fix their old one.
submitted by /u/Siddoxy
[link] [comments]
reddit
4 family members phone hacked
I don't know if this is the right sub but hopefully someone here can help me figure out what's going on. So within the past week 4 of my family...
hacking: security in practice
Legality of a client
So, I am currently working with a client who seems to not know what he's talking about, he said he wanted "inspect element magic" done (🤦♂️), if I do this, can he legally say he wanted something else and refuse to pay or what
submitted by /u/TickedOffSquid11
[link] [comments]
Legality of a client
So, I am currently working with a client who seems to not know what he's talking about, he said he wanted "inspect element magic" done (🤦♂️), if I do this, can he legally say he wanted something else and refuse to pay or what
submitted by /u/TickedOffSquid11
[link] [comments]
reddit
Legality of a client
So, I am currently working with a client who seems to not know what he's talking about, he said he wanted "inspect element magic" done (🤦♂️), if...
hacking: security in practice
How do I display TCP SYN flags using wireshark?
When I capture network traffic using wireshark, it doesn't display any SYN flags from the TCP protocol.
submitted by /u/caratera
[link] [comments]
How do I display TCP SYN flags using wireshark?
When I capture network traffic using wireshark, it doesn't display any SYN flags from the TCP protocol.
submitted by /u/caratera
[link] [comments]
reddit
How do I display TCP SYN flags using wireshark?
When I capture network traffic using wireshark, it doesn't display any SYN flags from the TCP protocol.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CISA Adds Two Web Shells to Exchange Server Guidance
Officials update mitigation steps to include two new Malware Analysis Reports identifying Web shells seen in Exchange Server attacks.
CISA Adds Two Web Shells to Exchange Server Guidance
Officials update mitigation steps to include two new Malware Analysis Reports identifying Web shells seen in Exchange Server attacks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Exec Order Could Force Software Vendors to Disclose Breaches to Federal Gov't Customers
A decision on the order, which contains several recommendations, is still forthcoming.
Exec Order Could Force Software Vendors to Disclose Breaches to Federal Gov't Customers
A decision on the order, which contains several recommendations, is still forthcoming.
Bug Bounty Tokopedia, Gojek, Traveloka Maret 2021
https://jakselsecurity.medium.com/bug-bounty-tokopedia-gojek-traveloka-maret-2021-3959def608d3?source=rss------bug_bounty-5
Continue reading on Medium » (https://jakselsecurity.medium.com/bug-bounty-tokopedia-gojek-traveloka-maret-2021-3959def608d3?source=rss------bug_bounty-5)
https://jakselsecurity.medium.com/bug-bounty-tokopedia-gojek-traveloka-maret-2021-3959def608d3?source=rss------bug_bounty-5
Continue reading on Medium » (https://jakselsecurity.medium.com/bug-bounty-tokopedia-gojek-traveloka-maret-2021-3959def608d3?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[HackTheBox] Laboratory — Writeup
https://cdn-images-1.medium.com/max/1193/1*RRMC1sdLSeNpv8Loh_rd4g.png
Hello and welcome to my first writeup. I chose Laboratory since it is a easy > medium level machine with a lot to learn from. Without…
Continue reading on Medium »
[HackTheBox] Laboratory — Writeup
https://cdn-images-1.medium.com/max/1193/1*RRMC1sdLSeNpv8Loh_rd4g.png
Hello and welcome to my first writeup. I chose Laboratory since it is a easy > medium level machine with a lot to learn from. Without…
Continue reading on Medium »