Dark Reading: Attacks/Breaches
Oracle Cloud Joins ONUG Collaborative
ONUG Collaborative welcomes new members including Oracle Cloud, Sysdig, Wiz, Intuit, Adobe, Qualys, and F5.
___________________________
@hacking_Attack
@Hacking_Video
Oracle Cloud Joins ONUG Collaborative
ONUG Collaborative welcomes new members including Oracle Cloud, Sysdig, Wiz, Intuit, Adobe, Qualys, and F5.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Oracle Cloud Joins ONUG Collaborative
ONUG Collaborative welcomes new members including Oracle Cloud, Sysdig, Wiz, Intuit, Adobe, Qualys, and F5.
Dark Reading: Attacks/Breaches
Palo Alto Networks to Transfer Stock Exchange Listing to Nasdaq
Palo Alto Networks anticipates meeting the requirements for inclusion in the NASDAQ-100 index when it rebalances in December.
___________________________
@hacking_Attack
@Hacking_Video
Palo Alto Networks to Transfer Stock Exchange Listing to Nasdaq
Palo Alto Networks anticipates meeting the requirements for inclusion in the NASDAQ-100 index when it rebalances in December.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Palo Alto Networks to Transfer Stock Exchange Listing to Nasdaq
Palo Alto Networks anticipates meeting the requirements for inclusion in the NASDAQ-100 index when it rebalances in December.
hacking: security in practice
New guy
Hello, I have been playing around with Kali Linux and learning terminal commands and beginner stuff. (Coming from Windows OS, very limited previous experience with Ubuntu)
I've learned how to go into monitor mode and send deauth packets and capture handshakes and whatnot in an attempt to crack a wifi password and the typical new guy stuff (I assume typical new guy stuff).
Anyways, I'm curious.. whats next? a) what kind of exploits / further attacks come after you crack a wifi password? Is the end goal of this attack to just use free wifi or to further penetrate a network? and b) what's next as far as progression.. what should I be playing with / focusing on next?
submitted by /u/ILLGotti
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
New guy
Hello, I have been playing around with Kali Linux and learning terminal commands and beginner stuff. (Coming from Windows OS, very limited previous experience with Ubuntu)
I've learned how to go into monitor mode and send deauth packets and capture handshakes and whatnot in an attempt to crack a wifi password and the typical new guy stuff (I assume typical new guy stuff).
Anyways, I'm curious.. whats next? a) what kind of exploits / further attacks come after you crack a wifi password? Is the end goal of this attack to just use free wifi or to further penetrate a network? and b) what's next as far as progression.. what should I be playing with / focusing on next?
submitted by /u/ILLGotti
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
Posted by ILLGotti - 8 votes and 5 comments
hacking: security in practice
Guest WiFi
I'm not sure where to ask these questions, so if there is another sub better suited, please let me know.
1- Is it okay to connect Smart TV and other appliances on your WiFi? Does it make a difference if I use the Guest option? What's a safe but convenient way to do this?
2- Is it okay to provide WiFi password to trades (plumber for installation of a water leak detection system)?
I know the best way to do the latter is to just get the instructions and do it myself, or change the password later and I might do that. However, the password is already very long and randomly generated, so there is no way he would remember it. And I'm not trying to safeguard nuclear codes. Just trying to find a nice balance between convenience and security paranoia.
Thank you for any guidance.
submitted by /u/non-nominato
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Guest WiFi
I'm not sure where to ask these questions, so if there is another sub better suited, please let me know.
1- Is it okay to connect Smart TV and other appliances on your WiFi? Does it make a difference if I use the Guest option? What's a safe but convenient way to do this?
2- Is it okay to provide WiFi password to trades (plumber for installation of a water leak detection system)?
I know the best way to do the latter is to just get the instructions and do it myself, or change the password later and I might do that. However, the password is already very long and randomly generated, so there is no way he would remember it. And I'm not trying to safeguard nuclear codes. Just trying to find a nice balance between convenience and security paranoia.
Thank you for any guidance.
submitted by /u/non-nominato
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Guest WiFi
I'm not sure where to ask these questions, so if there is another sub better suited, please let me know. 1- Is it okay to connect Smart TV and...
hacking: security in practice
State database without dependencies
submitted by /u/roramigator
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
State database without dependencies
submitted by /u/roramigator
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
State database without dependencies
Posted in r/hacking by u/roramigator • 1 point and 0 comments
500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any…
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any…
https://cdn-images-1.medium.com/max/1029/1*vSDuFKiYE1ShQenVnLQTRQ.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any…
https://cdn-images-1.medium.com/max/1029/1*vSDuFKiYE1ShQenVnLQTRQ.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any account of India’s Biggest College…
Hello Hackers, This is Gowtham here an Ethical Hacker and Penetration Tester who loves to look into loopholes😅. This is my first blog out here on Internet, So Kindly forgive me if there are any…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Azure Privilege Escalation via Service Principal Abuse
https://cdn-images-1.medium.com/max/1338/0*DrIOiVpzwUOvQSQq
Intro and Prior Work
Continue reading on Posts By SpecterOps Team Members »
___________________________
@hacking_Attack
@Hacking_Video
Azure Privilege Escalation via Service Principal Abuse
https://cdn-images-1.medium.com/max/1338/0*DrIOiVpzwUOvQSQq
Intro and Prior Work
Continue reading on Posts By SpecterOps Team Members »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Azure Privilege Escalation via Service Principal Abuse
Intro and Prior Work
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Burp Suite Set Up
https://cdn-images-1.medium.com/max/1536/1*ch4xtvSoBtdrvQFA1II_7Q.png
It is a proxy tool which can intercept requests and is often used for evaluating security of web-based applications and doing hands-on…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Burp Suite Set Up
https://cdn-images-1.medium.com/max/1536/1*ch4xtvSoBtdrvQFA1II_7Q.png
It is a proxy tool which can intercept requests and is often used for evaluating security of web-based applications and doing hands-on…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Burp Suite Set Up
It is a proxy tool which can intercept requests and is often used for evaluating security of web-based applications and doing hands-on…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HOW TO CREATE STEGANOGRAPHY CHALLENGES #13
https://cdn-images-1.medium.com/max/1251/0*jrw3mp1gArBeCgcm.png
beginner Friendly
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HOW TO CREATE STEGANOGRAPHY CHALLENGES #13
https://cdn-images-1.medium.com/max/1251/0*jrw3mp1gArBeCgcm.png
beginner Friendly
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HOW TO CREATE STEGANOGRAPHY CHALLENGES #13
beginner Friendly
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What happened in the Twitch Breach…
https://cdn-images-1.medium.com/max/2600/0*Ce95lr74gI4ISYVI
And four principles for securing your organization’s information including your source code and supply chain
Continue reading on ShiftLeft Blog »
___________________________
@hacking_Attack
@Hacking_Video
What happened in the Twitch Breach…
https://cdn-images-1.medium.com/max/2600/0*Ce95lr74gI4ISYVI
And four principles for securing your organization’s information including your source code and supply chain
Continue reading on ShiftLeft Blog »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What happened in the Twitch Breach…
And four principles for securing your organization’s information including your source code and supply chain
Defining Cobalt Strike Components So You Can BEA-CONfident in Your Analysis
https://www.reddit.com/r/redteamsec/comments/q6ria4/defining_cobalt_strike_components_so_you_can/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mandiant.com/resources/defining-cobalt-strike-components) [comments] (https://www.reddit.com/r/redteamsec/comments/q6ria4/defining_cobalt_strike_components_so_you_can/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/q6ria4/defining_cobalt_strike_components_so_you_can/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mandiant.com/resources/defining-cobalt-strike-components) [comments] (https://www.reddit.com/r/redteamsec/comments/q6ria4/defining_cobalt_strike_components_so_you_can/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Defining Cobalt Strike Components So You Can BEA-CONfident in Your...
Posted in r/redteamsec by u/dmchell • 4 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Armageddon HackTheBox Walkthrough
We’ll look at another one of HackTheBox machines today, called “Armageddon.” It is an easy box targeting commonly found threat of using outdated plugins. In this box, old and vulnerable version of Drupal is showcased. We’d own the root user by targeting it. Here is the methodology. Penetration Testing Methodology· NmapVulnerability Analysis and Exploitation· Drupalgeddon2 RCE exploit to gain user shellPrivilege Escalation· Searching for mysql database credentials in default filesReconMachine’s IP was 10.129.48.89. The first step was to run nmap’s aggressive scan to look for open ports. As you can see a port 80 was found to be open.nmap -A 10.129.48.89https://blogger.googleusercontent.com/img/a/AVvXsEiIseJMMBSWNZIY_v8137CAhYplR3SCz5373lhxqSgZbTkFUrH_vTmX4-GRyivcJR2bU88jqe9wOEQS9qoRS9HvnABh17fCRNwHQM6voofL9NmLWOujHPOidqYq-bfyYgLE1cseZYn8kJzVtxM8RECvzA_zg7RwluCgn05YLuW1X9QSAOSccZAzeGC0FQ=s16000 On traversing the website on port 80, it seemed a CMS made website.Vulnerability Analysis and ExploitationWe knew that Drupal 7.X before 7.58 was vulnerable to various CVEs including CVE-2018-7600. Drupalgeddon2 exploit is developed to exploit Drupal’s form API and exploits insufficient input validation. You can refer the original repo here.Privilege EscalationGladly Metasploit had this exploit in the framework, so we just used that and spawned an interactive shell. On checking the current directory we saw the site installation files with necessary permissions to let us view the content.use exploit/unix/webapp/drupal_drupalgeddon2A basic ls let us view contents.___________________________
@hacking_Attack
@Hacking_Video
Armageddon HackTheBox Walkthrough
We’ll look at another one of HackTheBox machines today, called “Armageddon.” It is an easy box targeting commonly found threat of using outdated plugins. In this box, old and vulnerable version of Drupal is showcased. We’d own the root user by targeting it. Here is the methodology. Penetration Testing Methodology· NmapVulnerability Analysis and Exploitation· Drupalgeddon2 RCE exploit to gain user shellPrivilege Escalation· Searching for mysql database credentials in default filesReconMachine’s IP was 10.129.48.89. The first step was to run nmap’s aggressive scan to look for open ports. As you can see a port 80 was found to be open.nmap -A 10.129.48.89https://blogger.googleusercontent.com/img/a/AVvXsEiIseJMMBSWNZIY_v8137CAhYplR3SCz5373lhxqSgZbTkFUrH_vTmX4-GRyivcJR2bU88jqe9wOEQS9qoRS9HvnABh17fCRNwHQM6voofL9NmLWOujHPOidqYq-bfyYgLE1cseZYn8kJzVtxM8RECvzA_zg7RwluCgn05YLuW1X9QSAOSccZAzeGC0FQ=s16000 On traversing the website on port 80, it seemed a CMS made website.Vulnerability Analysis and ExploitationWe knew that Drupal 7.X before 7.58 was vulnerable to various CVEs including CVE-2018-7600. Drupalgeddon2 exploit is developed to exploit Drupal’s form API and exploits insufficient input validation. You can refer the original repo here.Privilege EscalationGladly Metasploit had this exploit in the framework, so we just used that and spawned an interactive shell. On checking the current directory we saw the site installation files with necessary permissions to let us view the content.use exploit/unix/webapp/drupal_drupalgeddon2A basic ls let us view contents.___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Armageddon HackTheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.