Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)

Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).Build$ mvn packageUsage中文使用说明Download the precompiled jar package from Releases.Add this jar package to your burpsuite's Extensions.Switch to BurpCrypto tab, select you need Cipher tab.Set key or some value.press "Add processor", and give a name for this processor.Switch to Intruder->Payloads->Payload Processing.press "Add", select "Invoke Burp extension", and select processor you just created.press "Start attack", have fun!Key ExampleAes Key(UTF8String): abcdefgabcdefg12Aes IV(UTF8String): abcdefgabcdefg12Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQABRsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07Rsa Exponent: 010001DES Key: 12345678DESede Key: 123456781234567812345678ScreenshotsAES Example:ExecJs Example (Here is the modified MD5 algorithm):Quick Crypto: Download BurpCrypto
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Name That Edge Toon: Mobile Monoliths

Feeling creative? Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.
Dark Reading: Attacks/Breaches
Law Enforcement Agencies Seize $375K in Ukraine Ransomware Bust

A coordinated effort by law enforcement agencies is viewed as a good sign, but security analysts fear this is just the tip of the iceberg.
hacking: security in practice
Is there any attack that actually works nowadays?

I started taking an ethical hacking course and it hasn’t taken much for mento realize that most of (if not all) of the attacks are only working in theory but not in real life.

Here’s what I mean: -ARP spoofing only works with HTTP and nowadays 90% of the websites that people usually visit (Facebook, gmail, google, Reddit etc) are using HTTPS.

-any malware application that you make if you’re good enough with social engineering to have someone download the .exe file and open it then it will have windows defender warning about the not secure developer and if you’re good enough with Python then maybe you have a chance to write yourself your own backdoor that since it was never used before maybe it won’t be intercepted by an antivirus

-WPA is obsolete and most of modern routers now use WPA2 which is practically uncrackable if people leave it set at default (which most people just do) and if they change it you have to be lucky enough that they chose a stupid password that is inside some word list otherwise you have no chance

And so on...

So is hacking still possible today?

And by hacking I don’t mean stupid scams or phishing emails (that also most likely will just fall in the spam folder)

submitted by /u/hatecall
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Raspberry hacking

So today I went to a very famous mall in my city when I realized the cinema movies showtime was bugged and it was showing the raspbian default desktop. I wasn't able to look further into it because I wasn't carrying my laptop but what I found doing just a 2 minutes research was that the raspberry looked like there was enabled WiFi hotspot from the raspberries. Do you know if there's a way to remote access the raspberry if I crack the WiFi password? Is there any chance I can get into them? Any exploits to be shared? Thanks 4 your time :)

submitted by /u/Cevikre
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
One Identity Acquires OneLogin to Boost Identity Security Portfolio

The combination of One Identity and OneLogin will provide customers with a unified identity security platform to manage identities and networks.
Dark Reading: Attacks/Breaches
Windows 11 Available: What Security Pros Should Know

Microsoft discusses the security requirements and changes coming to the newest version of its Windows operating system.
hacking: security in practice
Is this a virus?

Hello, today I got a link in my instagram inbox from a hacked account.i clicked on the link since I didn't knew it was hacked.

This is the link: http://loveit275.xyz/g/?&ure=

After "=" was my IG username. The site only directed me back to the homepage of Instagram.

submitted by /u/bre999
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I have been observing dos attacks in my router log what can I do to stop them?

I have recently taken a look at my router log out of curiosity after installing my new router, and noticed a series of doss attacks coming in. The DoS attacks listed on my log are as follows Fraggle Attack, ACK Scan, snmpQueryDrop, RST Scan, TCP SYN Flood. I will disclose that I had made the mistake of using the WPS button to connect my printer to my network, but I had researched that it would make my router vulnerable while the WPS connection is attempting to be established. These attacks started on September 20 till today. I have taken a couple of steps to resolve: I have released, and renewed my IP, I have disconnected my modem and Router for a full 2 minutes each, and I have changed my wireless password for all My 2.4 and 5 ghz broadband to 99 randomized character passwords. The disconnection for the modem and router had temporarily stopped the attacks for about 30 minutes then The Fraggle Attacks started again soon after all the other types of attacks started again. I am debating exchanging my router for a new one or simply doing a factory data reset on the router. Thank you for your time and attention if this is the wrong subreddit if you may redirect me To the right Subreddit for additional help.

submitted by /u/TheSirInconsistent
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Any exploit code for CVE-2020-12440

I've been digging through Google and exploit bds i haven't found one. Please help me find it. Thanks in advance.

submitted by /u/cdsdfdedsde
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Does anyone have any suggested reading for offensive C# on Windows?
https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/

I was kind of disappointed by the "Gray Hat C#" book and I'm wondering if someone else has some better suggestions. I'm looking for a book/resource to learn how to get into C# for Windows but I'm swamped by web development material. Any suggestions to help me improve my tradecraft would be appreciated. Thanks submitted by /u/GuerrillaTom (https://www.reddit.com/user/GuerrillaTom)
[link] (https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/) [comments] (https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/)

___________________________
@hacking_Attack
@Hacking_Video