Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Would Like Feedback on My Mock Pentest
https://www.reddit.com/r/Pentesting/comments/me20mu/would_like_feedback_on_my_mock_pentest/

<!-- SC_OFF -->Hey there I'm currently preparing for the Pentest+, CySA+ and OSCP certs and did a mock pentest to practice a bit. I would appreciate some feedback on the pentesting (eg. I noticed my lack of note taking in the beginning). You can find the entire Mock PenTest as Playlist over here: https://www.youtube.com/playlist?list=PLUqaMXbg_0-FUk23_Q2MsTZ-oy63IVVZm It consists of multiple livestreams I did on my YouTube channel. Thanks in advance! <!-- SC_ON --> submitted by /u/ninijay_ (https://www.reddit.com/user/ninijay_)
[link] (https://www.reddit.com/r/Pentesting/comments/me20mu/would_like_feedback_on_my_mock_pentest/) [comments] (https://www.reddit.com/r/Pentesting/comments/me20mu/would_like_feedback_on_my_mock_pentest/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SolarWinds Experimenting With New Software Build System in Wake of Breach

CISO of SolarWinds now has complete autonomy to stop product releases if security concerns exist, CEO says.
Sent by @TheFeedReaderBot
hacking: security in practice
IP Logger Backfired?

I got a DM from a scammer so I decided to mess around with them. After them demanding to double my investment of $1,000 I wasted their time and registered a CashApp account to see their real name. The CashApp asked for SS$ and Debit Card to fully sign up which I didn't enter cause I have no intention of using CashApp. I used an IP Logger to find out that Everlyn, a pretty girl from New York was Ayahly Anderson from Montego Bay, Jamaica. After he realized I was messing with him he began reading out my contacts in my phone claiming to be a dark web hacker. I never clicked on any link or downloaded anything so I know that's not true, but where are my contacts available? Maybe because I used my number to register with Cash App he could see my contacts? But how would he know that the number provided is labelled as my Aunt? He claimed he used an app that gives feedback, and although I'm not worried about anything being stolen and I have nothing to hide, how could he access the names I gave my contacts? He didn't have access to anything else I'm assuming, so which application allows someone to see a minimum of contact names?

submitted by /u/rustjumper
[link] [comments]
I am stuck and looking for tips/ suggestions
https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/

<!-- SC_OFF -->I was "tasked" to do a pentest (as a training) of this one modified machine that was used in the previous local pentest competition and it was the "hardest" machine. I got one of the user access, okay, I can ssh , great. but as a non-root, I cant literally do anything other than read useless files. I cant do an scp transfer, cant modified file, cant make a dir, cant do a wget because the machine seemed to have no connection to the internet (any tips on this is?). in the user home I see a userflag, but since its a modified machine, my objective is to get root access. its a linux ubuntu kernel 3.0.0 generic, and I got the username from exploiting webmin. with the obtained hash infos, Jacktheripper quickly got one of the pass, but for the other users? ETA 24 hours, the keywords is obviously not in english or a very unique one so I think it is a waste of time. I tried: mempodipper , but no permission, tried writing the mempodipper there, cant modified, tried to download (wget) mempo, no permission. in every similar case on the internet I found, they all use msf . well in this training I cannot use any of that so its all manual. however, there is one text file that I can write on but not rename (so its useless?) any tips how to approach this? keywords maybe? *ps the teacher didnt actually expect us to do this machine, he only tasked us with the previous 4 machines and I did all of them, Im just curious and annoyed with this last one. sorry, english is not first language. *EDIT: typos <!-- SC_ON --> submitted by /u/Arcyma (https://www.reddit.com/user/Arcyma)
[link] (https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/me7f8s/i_am_stuck_and_looking_for_tips_suggestions/)
hacking: security in practice
CTF Walk through

I've been trying to find a good person to watch as they do CTF's. There are a bunch on Youtube but, as I'm just starting to get into CTFs, I'm finding some videos are hard to follow. I was wondering if anyone could recommend someone who explains the ins and outs as they go through it? If you have a favorite person you follow I'd be happy to check them out as well. Thanks in advance!

submitted by /u/MolotovBoy
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Cyber security Awareness Training is Important For Startups?

https://cdn-images-1.medium.com/max/1500/1*zonp__o2phLgdLEXcyRDOA.png
In today’s world, one of the important aspects of the information technology sector is Cybersecurity. Cybersecurity is just a way to keep…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Lame: Walkthrough (without Metasploit)

https://cdn-images-1.medium.com/max/600/1*n3tirIS46hkYiX00wcEXhA.png
Hack The Box — Lame: Walkthrough (without Metasploit) | Road to OSP | SMB attack | Linux Easy Level | Beginner Friendly | FTP Enumeration

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hub Weekly Digest: GE, DOE, Verkada Hack, VMware and the DHS

https://cdn-images-1.medium.com/max/2600/1*_ouolRTZtZ1LXMl5z_BVXw.jpeg
Hub Security’s weekly digest covers top stories happening around the world related to fintech, critical infrastructure, cloud, and…

Continue reading on HUB Security »