Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Best ways to stay motivated?

Hey guys I just recently stopped working my part time job and now I have an extreme amount of free time in my hands. I always usually would just do ctfs and study on tryhackme or hackthebox but I really wanted to up my game and become the best I can be while im still young (18) and be able to do this as a full time career. The issue is though I love everything about how the computer works and runs but I literally feel fried out in the brain after practicing around 5 hours, but with all this free time I really wanna start pushing it to like 9-10. Is this a stretch or could I actually be able to manage this with the right amount of drive?

submitted by /u/dokhar
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is it possible to copy the gate pass to my apartment complex

I live in a gated apartment where I have to use a pass that’s hung in my car to get in. The problem is that the pass doesn’t reach far enough away so half the time I have to get out of my car and wave it in front of the reader. I was wondering if it’s possible to make copies of this pass using an rfid reader/writer and if so what the cheapest device to use would be. I’ll include a picture of the pass below.

https://imgur.com/gallery/ik6C1ak

submitted by /u/ItzLucas123
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best ddos software and coding them yourself.

Hey im quite new to hacking and its my first year in uni. What ive learnt in python and java is really simple and i know since its the first year thats fine, anyways back to my question which is what are the best ddos softwares and if u can you code them i would really like to test my abilities and do them.

submitted by /u/sixtysixstar1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Password protected PDF

Hi, I have a password protected PDF and I forgot the password, is there a way to see or find out the password?

Thanks.

submitted by /u/Turismo282
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Miskonfigurasi AWS S3 Bucket di Portal Media E-Sport Indonesia

Mari kita sebut dia redacted.com..Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apache fixes actively exploited zero-day vulnerability, patch now

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apache fixes actively exploited zero-day vulnerability, patch nowPost Views: 160
Reading Time: 1 Minute
The Apache Software Foundation has released version 2.4.50 of the HTTP Web Server to address two vulnerabilities, one of which is an actively exploited path traversal and file disclosure flaw.
The Apache HTTP Server is an open-source, cross-platform web server that is extremely popular for being versatile, robust, and free. As such, any vulnerability in the product has widespread consequences.

The actively exploited zero-day vulnerability is tracked as CVE-2021-41773 and it enables actors to map URLs to files outside the expected document root by launching a path traversal attack.

Path traversal attacks involve sending requests to access backend or sensitive server directories that should be out of reach. Normally, these requests are blocked, but in this case, the filters are bypassed by using encoded characters (ASCII) for the URLs.

Additionally, exploits of this flaw may lead to the leaking of the source of interpreted files such as CGI scripts.
See Also: Complete Offensive Security and Ethical Hacking Course For the attack to work, the target has to run Apache HTTP Server 2.4.49, and also has to have the “require all denied” access control parameter disabled. Unfortunately, this appears to be the default configuration.

Earlier Apache Server versions or those having a different access configuration aren’t vulnerable to this flaw.

Since the disclosure of the vulnerability, security researchers have been able to reproduce the vulnerability and warned that admins should patch immediately.
🔥 We have reproduced the fresh CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.

If files outside of the document root are not protected by "require all denied" these requests can succeed.

Patch ASAP! https://t.co/6JrbayDbqG pic.twitter.com/AnsaJszPTE

— PT SWARM (@ptswarm) October 5, 2021
See Also: Apple Pay with VISA lets hackers force payments on locked iPhones A Shodan search revealed that there are over a hundred thousand Apache HTTP Server 2.4.49 deployments online, many of which could be vulnerable to exploitation, so updating your software as soon as possible should be considered exigent.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/apache_number.jpg
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apache fixes actively exploited zero-day vulnerability, patch now https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apache fixes actively exploited zero-day vulnerability, patch nowPost Views:…
This flaw too only exists in Apache Server version 2.4.49, but it’s not under active exploitation. It was discovered three weeks ago, fixed late last month, and incorporated now in version 2.4.50.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/security-breach-freepik-90x90.jpg Encrypted & Fileless Malware Sees Big Growth1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Digital-Wallet-90x90.jpg MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/shutterstock_1156765921-900x506-1-90x90.jpg Google pushes emergency Chrome update to fix two zero-days5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-2-90x90.jpg Apple Pay with VISA lets hackers force payments on locked iPhones6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/gamma-finfisher-hacked-tool-90x90.jpg FinFisher malware hijacks Windows Boot Manager with UEFI bootkit1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/computer-3923644_1920_1627303851339_1632808464296-90x90.jpg New malware steals Steam, Epic Games Store, and EA Origin accounts1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/VMware-90x90.jpg Hackers exploiting critical VMware vCenter CVE-2021-22005 bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/malware-800x449-1-90x90.jpg Malware devs trick Windows validation with malformed certs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-1-90x90.jpg Unpatched Apple Zero-Day in macOS Finder Allows Code Execution2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-90x90.jpg New macOS zero-day bug lets attackers run commands remotely2 weeks ago
The post Apache fixes actively exploited zero-day vulnerability, patch now first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video