Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Web Cache Poisoning to Denial of Services

Hello everyone, I’m Ekin Şiar Bayer. I am 15 years old and going to the 10th grade at Samsun Science High School. Today I will share with…Continue reading on Medium »
Read more...
Web Cache Poisoning to Denial of Services
https://ekinsiarb-22717.medium.com/web-cache-poisoning-to-denial-of-services-5773b4dfbef?source=rss------bug_bounty-5

Hello everyone, I’m Ekin Şiar Bayer. I am 15 years old and going to the 10th grade at Samsun Science High School. Today I will share with…Continue reading on Medium » (https://ekinsiarb-22717.medium.com/web-cache-poisoning-to-denial-of-services-5773b4dfbef?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
NordVPN Review

https://cdn-images-1.medium.com/max/640/1*0d7dL-6X_k7yDGNY0cdhKw.png
To quickly sum up: NordVPN is a fast, safe, and secure VPN service. NordVPN is also very easy to setup and comes equipped with an…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Web Cache Poisoning to Denial of Services

Hello everyone, I’m Ekin Şiar Bayer. I am 15 years old and going to the 10th grade at Samsun Science High School. Today I will share with…

Continue reading on Medium »
This is a collection of tools you may like if you are interested on reverse engineering (https://www.kitploit.com/search/label/Reverse%20Engineering) and/or malware analysis (https://www.kitploit.com/search/label/Malware%20Analysis) on x86 and x64 Windows systems. After installing this toolkit you'll have a folder in your desktop (https://www.kitploit.com/search/label/Desktop) with shortcuts to RE tools like these:
Why do I need it?
You don't. Obviously, you can download such tools from their own website and install them by yourself in a new VM. But if you download retoolkit, it can probably save you some time. Additionally, the tools come pre-configured so you'll find things like x64dbg with a few plugins, command-line tools working from any directory, etc. You may like it if you're setting up a new analysis (https://www.kitploit.com/search/label/Analysis) VM.
Download
The *.iss files you see here are the source code for our setup program built with Inno Setup (https://jrsoftware.org/isinfo.php). To download the real thing, you have to go to the Releases (https://github.com/mentebinaria/retoolkit/releases) section and download the setup program.
Included tools
Check the wiki (https://github.com/mentebinaria/retoolkit/wiki).
Is it safe to install it in my environment?
I don't know. Some included tools are not open source and come from shady places. You should use it exclusively in virtual machines and under your own responsibility.
Can you add tool X?
It depends. The idea is to keep it simple. We won't add a tool just because it's not here yet. But if you think there's a good reason to do so, and the license allows us to redistribuite the software, please file a request here (https://github.com/mentebinaria/retoolkit/discussions/categories/new-app-requests).

Download Retoolkit (https://github.com/mentebinaria/retoolkit)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Retoolkit - Reverse Engineer's Toolkit

https://1.bp.blogspot.com/-h3zUjXIqD94/YFevZ6TF4kI/AAAAAAAAVq4/ctwJfCSMdOwOMd9c922fgZketTQKRHJMACNcBGAsYHQ/w640-h506/retoolkit_1_ret2021c.png
This is a collection of tools you may like if you are interested on reverse engineering and/or malware analysis on x86 and x64 Windows systems. After installing this toolkit you'll have a folder in your desktop with shortcuts to RE tools like these:
Why do I need it?

You don't. Obviously, you can download such tools from their own website and install them by yourself in a new VM. But if you download retoolkit, it can probably save you some time. Additionally, the tools come pre-configured so you'll find things like x64dbg with a few plugins, command-line tools working from any directory, etc. You may like it if you're setting up a new analysis VM.

Download

The *.iss files you see here are the source code for our setup program built with Inno Setup. To download the real thing, you have to go to the Releases section and download the setup program.

Included tools

Check the wiki.
https://1.bp.blogspot.com/-4oetWUTvvmY/YFeveotNrtI/AAAAAAAAVq8/JbNuiFxOQcYG4uJFB8aYsnU46lYQVL8hQCNcBGAsYHQ/w640-h498/retoolkit_2_ret.gif
Is it safe to install it in my environment?

I don't know. Some included tools are not open source and come from shady places. You should use it exclusively in virtual machines and under your own responsibility.

Can you add tool X?

It depends. The idea is to keep it simple. We won't add a tool just because it's not here yet. But if you think there's a good reason to do so, and the license allows us to redistribuite the software, please file a request here.
Download Retoolkit
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Offers Up To $30K For Teams Bugs

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Offers Up To $30K For Teams BugsPost Views: 116
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
A bug-bounty program launched for the Teams desktop video-conferencing and collaboration application has big payouts for finding security holes.
Microsoft wants to send the message the company is serious about the security of its popular Teams desktop application and it’s willing to put some cash behind the talk. A new bug-bounty program offers up to $30,000 for security vulnerabilities, with top payouts going to those with the most potential to expose Teams user data.

“The Teams desktop client is the first in-scope application under the new Apps Bounty Program, we look forward to sharing updates as we bring additional apps into this bounty program scope,” the program manager Lynn Miyashita said in her statement about the launch.
See Also: Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws Researchers can claim five scenario-based awards under the new Apps Bounty Program, ranging from $6,000 to $30,000, with the highest payouts available for “vulnerabilities that have the highest potential impact on customer privacy and security,” the company said.

General bounties are awarded between $500 and $15,000, with other incentives: Standout bug hunters can earn a spot on Microsoft’s “Researcher Recognition Program” and eligibility for the yearly MSRC Most Valuable Security Researcher list, Miyashita explained.

Security researchers with Teams online vulnerabilities to report will still submit those through the Online Services Program, the announcement added.
See Also: Offensive Security Tool: Skipfish Bug-Bounty Programs Inspire Customer ConfidenceBeyond offering a nice payday for security researchers, the move to dedicate a bug-bounty program gives Microsoft some brand support to customers, judging from a recent survey.

Conducted by the Ponemon Institute and commissioned by Intel, the poll found that three-quarters of IT pros in charge of purchasing tech prefer to buy from vendors who are proactive about security. Bug-bounty programs are increasingly part of that package.

“Security doesn’t just happen,” Suzy Greenberg, vice president, Intel Product Assurance and Security, said about the Poneman Institute survey findings. “If you are not finding vulnerabilities, then you are not looking hard enough.”

Certainly, the cloud-collaboration market has seen plenty of security bugs and breaches in recent months, particularly following lockdowns, when these services became vital to everyday business. See Also: Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbersCollaboration App Security StormTeams has been used in phishing lure scams, and last fall attackers used fake Teams updates to target users with malware.

Rival cloud-collab service Zoom has also had its share of embarrassing security fails, including a vanity URL zero-day flaw discovered last July, re-occurring Zoom bombings, impersonation attacks and this month’s Zoom screen-sharing glitch, which “briefly” leaked sensitive data.

The launch of Microsoft’s bug bounty program will both help root out these flaws before they become headlines and signal a renewed commitment to proactive security.
“Partnering with the security research community is an important part of Microsoft’s holistic approach to defending against security threats,” Microsoft’s Miy[...]