SummaryContinue reading on Immunefi » (https://medium.com/immunefi/rocketpool-lido-frontrunning-bug-fix-postmortem-e701f26d7971?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
RocketPool and Lido Frontrunning Bug Fix Postmortem
Summary
hacking: security in practice
Fucked up pentest scan... Now what?
The customer didn't want to spend that much money (on me), and the sales team fucked up. So Essentially I got twice the work in half the time, because they're a new customer with a lot of possible future business I decided to say it's fine, even though the sales team would've fixed it.
Anyways because I now had a lot of stuff in very few days I ran automated scans on most addresses.
I realized just now while writing my final report I got kicked off by 50 addresses (a few subnets). A Sonicwall automatically blocked my IP, I would assume.
So what do I do? Do I just tell the customer your security is top notch here, or do I run another scan trying to get under the threshold.
I CANNOT CALL THE CUSTOMER, TILL THE REPORT IS DUE HE IS ON HOLIDAY.
submitted by /u/comrade-linux
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Fucked up pentest scan... Now what?
The customer didn't want to spend that much money (on me), and the sales team fucked up. So Essentially I got twice the work in half the time, because they're a new customer with a lot of possible future business I decided to say it's fine, even though the sales team would've fixed it.
Anyways because I now had a lot of stuff in very few days I ran automated scans on most addresses.
I realized just now while writing my final report I got kicked off by 50 addresses (a few subnets). A Sonicwall automatically blocked my IP, I would assume.
So what do I do? Do I just tell the customer your security is top notch here, or do I run another scan trying to get under the threshold.
I CANNOT CALL THE CUSTOMER, TILL THE REPORT IS DUE HE IS ON HOLIDAY.
submitted by /u/comrade-linux
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Fucked up pentest scan... Now what?
The customer didn't want to spend that much money (on me), and the sales team fucked up. So Essentially I got twice the work in half the time,...
hacking: security in practice
OhMyZsh, PowerLevel10 and showing IP addr in TTY?
How can I show my HTB IP in my TTY shell? I’m using PowerLevel10 and OMZsh Right now my TTY is showing my local IP addr
submitted by /u/ZenBuddhism
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
OhMyZsh, PowerLevel10 and showing IP addr in TTY?
How can I show my HTB IP in my TTY shell? I’m using PowerLevel10 and OMZsh Right now my TTY is showing my local IP addr
submitted by /u/ZenBuddhism
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
OhMyZsh, PowerLevel10 and showing IP addr in TTY?
How can I show my HTB IP in my TTY shell? I’m using PowerLevel10 and OMZsh Right now my TTY is showing my local IP addr
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pentagon Official Resigns Saying US Cybersecurity Is No Match for China, Calling It 'Kindergarten Level'
https://external-preview.redd.it/_tOUVKpP3UBvir8cF5_d3h61HGw1Ta8gltJZv76QIzc.jpg?width=640&crop=smart&auto=webp&s=2f68305ce3fe9a03bf032a7c9d026e07088faff4 submitted by /u/Stevogangstar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Pentagon Official Resigns Saying US Cybersecurity Is No Match for China, Calling It 'Kindergarten Level'
https://external-preview.redd.it/_tOUVKpP3UBvir8cF5_d3h61HGw1Ta8gltJZv76QIzc.jpg?width=640&crop=smart&auto=webp&s=2f68305ce3fe9a03bf032a7c9d026e07088faff4 submitted by /u/Stevogangstar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pentagon Official Resigns Saying US Cybersecurity Is No Match for...
Posted in r/hacking by u/Stevogangstar • 783 points and 71 comments
hacking: security in practice
Understanding dll injection and other techniques used for videogame modding/hacking
Lately I have been really curious about how different mod menus or hacks for games work, there are some mods that require a mod loader and then that loads the mods, but there are also some that are external applications and somehow manage to connect to the internals of online games, how does this work exactly? I have heard the term dll injection a few times, but I am not sure if this is how these applications work, and if so, how does that work? How do dll's work? Where can I learn more about this?
My field of studies is not related to computers, so programming is no more than a hobby to me, so I don't really have a lot of knowledge about this
Also, this is learning-purposes only, I don't approve online game hacking, but I find this subject really interesting and would maybe be fun to learn about
submitted by /u/Rikai_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Understanding dll injection and other techniques used for videogame modding/hacking
Lately I have been really curious about how different mod menus or hacks for games work, there are some mods that require a mod loader and then that loads the mods, but there are also some that are external applications and somehow manage to connect to the internals of online games, how does this work exactly? I have heard the term dll injection a few times, but I am not sure if this is how these applications work, and if so, how does that work? How do dll's work? Where can I learn more about this?
My field of studies is not related to computers, so programming is no more than a hobby to me, so I don't really have a lot of knowledge about this
Also, this is learning-purposes only, I don't approve online game hacking, but I find this subject really interesting and would maybe be fun to learn about
submitted by /u/Rikai_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Understanding dll injection and other techniques used for...
Lately I have been really curious about how different mod menus or hacks for games work, there are some mods that require a mod loader and then...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cheat codes for fortnite v bucks ps4
https://cdn-images-1.medium.com/max/1280/1*3sfXekmxogWAf3MZ-1W1uQ.jpeg
The latest update to Epic’s award-winning battle royale, Fortnite Hacks v3.33, has been published. The Chili Chug Splashes consumable has…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cheat codes for fortnite v bucks ps4
https://cdn-images-1.medium.com/max/1280/1*3sfXekmxogWAf3MZ-1W1uQ.jpeg
The latest update to Epic’s award-winning battle royale, Fortnite Hacks v3.33, has been published. The Chili Chug Splashes consumable has…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cheat codes for fortnite v bucks ps4
The latest update to Epic’s award-winning battle royale, Fortnite Hacks v3.33, has been published. The Chili Chug Splashes consumable has…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Create Trojans with Windows Executables
https://cdn-images-1.medium.com/max/1260/1*TimSBOQm2I9c-MPSav3izA.jpeg
This will be the first in a series of articles discussing various methods to backdoor everyday Windows executables, providing us with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Create Trojans with Windows Executables
https://cdn-images-1.medium.com/max/1260/1*TimSBOQm2I9c-MPSav3izA.jpeg
This will be the first in a series of articles discussing various methods to backdoor everyday Windows executables, providing us with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Create Trojans with Windows Executables
This will be the first in a series of articles discussing various methods to backdoor everyday Windows executables, providing us with…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Still Getting Stalked Still Getting Hacked — Why?
https://cdn-images-1.medium.com/max/1326/1*wtZe9li4o90uKbnVZY7Y5g.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Still Getting Stalked Still Getting Hacked — Why?
https://cdn-images-1.medium.com/max/1326/1*wtZe9li4o90uKbnVZY7Y5g.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Still Getting Stalked Still Getting Hacked — Why?
Danielle Diew ·9 hours ago
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DCG 201 Online CTF — DEADFACE CTF 2021 — October 15th-16th
https://cdn-images-1.medium.com/max/768/0*QN2BH0bDGGFHcYH6.jpeg
Welcome to the DEADFACE CTF 2021!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DCG 201 Online CTF — DEADFACE CTF 2021 — October 15th-16th
https://cdn-images-1.medium.com/max/768/0*QN2BH0bDGGFHcYH6.jpeg
Welcome to the DEADFACE CTF 2021!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DCG 201 Online CTF — DEADFACE CTF 2021 — October 15th-16th
Welcome to the DEADFACE CTF 2021!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Daily Hacking 10.11.21 — Every day, why?
https://cdn-images-1.medium.com/max/1365/1*nIXYWO4V5WbtMu3-8ZonEw.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Daily Hacking 10.11.21 — Every day, why?
https://cdn-images-1.medium.com/max/1365/1*nIXYWO4V5WbtMu3-8ZonEw.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Daily Hacking 10.11.21 — Every day, why?
Danielle Diew ·Just now
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Octubre: mes de la concientización sobre la importancia de la ciberseguridad
https://cdn-images-1.medium.com/max/1387/0*2syLZw795KCyPHfO
PUBLICADO EN 11 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Octubre: mes de la concientización sobre la importancia de la ciberseguridad
https://cdn-images-1.medium.com/max/1387/0*2syLZw795KCyPHfO
PUBLICADO EN 11 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Octubre: mes de la concientización sobre la importancia de la ciberseguridad
PUBLICADO EN 11 OCTUBRE, 2021POR EHACKING
RocketPool and Lido Frontrunning Bug Fix Postmortem
SummaryContinue reading on Immunefi »
Read more...
SummaryContinue reading on Immunefi »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Windows Privilege Escalation: Weak Services Permission
Microsoft Windows offers a wide range of fine-grained permissions and privileges for controlling access to Windows components including services, files, and registry entries. Exploiting misconfigured services is one technique to increase privileges.
Table of Content· MS Windows ServicesMS Windows Services, formerly known as NT services, enable you to create long-running executable applications that run in their own Windows sessions. These services can be automatically started when the computer boots, can be paused and restarted, and do not show any user interface. For each service, a registry key exists in HKLM\SYSTEM\CurrentControlSet\Services.Access Rights for the Service Control ManagerThe SCM creates a service object's security descriptor when the service is installed by the CreateServicefunction. The default security descriptor of a service object grants the following access. https://blogger.googleusercontent.com/img/a/AVvXsEiFttE9jcG1VLvRQuWtXFHO8RL9xTYivhYuE6bK8vLYzgptiVVAjbErTuAH1UVSbEytqIdzO4jBYaMm1nCXYLcyn5tMpTmr9Dt2xvxGnlIFkz-clpRAZTQDjl-SFr_oT32SAXDdIoB5g-Xu5nXGuZtdIOnaS0GHL4Vz2zApjDyWBndYgKW9BEwWg5aCjQ=s16000 Weak Service Permission Lab SetupThis article will help to set up a lab that focuses on two Windows weak service Permission misconfigurations that allow an attacker to get administrative privileges:Insecure Configuration File Permissions:A low-privileged user can update service settings, such as the service binary that runs when the service starts.Insecure Service Executable: When the service starts, a low-privileged user can overwrite the binary it launches.Steps for Weak Services Permissions Run CMD as administrator and execute the below command to create a service with the name of Pentest inside /temp directory ___________________________
@hacking_Attack
@Hacking_Video
Windows Privilege Escalation: Weak Services Permission
Microsoft Windows offers a wide range of fine-grained permissions and privileges for controlling access to Windows components including services, files, and registry entries. Exploiting misconfigured services is one technique to increase privileges.
Table of Content· MS Windows ServicesMS Windows Services, formerly known as NT services, enable you to create long-running executable applications that run in their own Windows sessions. These services can be automatically started when the computer boots, can be paused and restarted, and do not show any user interface. For each service, a registry key exists in HKLM\SYSTEM\CurrentControlSet\Services.Access Rights for the Service Control ManagerThe SCM creates a service object's security descriptor when the service is installed by the CreateServicefunction. The default security descriptor of a service object grants the following access. https://blogger.googleusercontent.com/img/a/AVvXsEiFttE9jcG1VLvRQuWtXFHO8RL9xTYivhYuE6bK8vLYzgptiVVAjbErTuAH1UVSbEytqIdzO4jBYaMm1nCXYLcyn5tMpTmr9Dt2xvxGnlIFkz-clpRAZTQDjl-SFr_oT32SAXDdIoB5g-Xu5nXGuZtdIOnaS0GHL4Vz2zApjDyWBndYgKW9BEwWg5aCjQ=s16000 Weak Service Permission Lab SetupThis article will help to set up a lab that focuses on two Windows weak service Permission misconfigurations that allow an attacker to get administrative privileges:Insecure Configuration File Permissions:A low-privileged user can update service settings, such as the service binary that runs when the service starts.Insecure Service Executable: When the service starts, a low-privileged user can overwrite the binary it launches.Steps for Weak Services Permissions Run CMD as administrator and execute the below command to create a service with the name of Pentest inside /temp directory ___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Windows Privilege Escalation: Weak Services Permission
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.