Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
I found a XSS vulnerability on a fortune 100 website, any way to correctly report it for a bounty?

This is a throwaway account.

I'm a software engineer in the United States. My area of work is in interactive marketing. One of our clients, a fortune 100 company, has hired the company I work for to do a project. I'm the developer on the project. In working with the client and their APIs, I found a XSS vulnerability in their code. It's a pretty big one. Someone could easily use this XSS vulnerability to phish for usernames and passwords.

How should I proceed? Do you think it's possible I could report this for a bounty? Should I just keep it to myself?

I should note that the client is not a bank, and there's really low stakes if someone's username/password is obtained (though I suppose if someone uses the same password everywhere ...)

Any advice is appreciated.

Thanks

submitted by /u/verybadrunner
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Kali linux stty raw -echo doesn’t work

Once i get a bash shell on the victim i want to have a fully usable shell, everywhere i look i have to ctrlz —> stty raw -echo —> fg —> enter —> enter. But when i do it, it doesn’t work, the enter is recognized as a charachter. I haven’t found anything about it online and i remember asking to my professor and he mentioned something about how newer versions of kali treats the tty. Anyone knows what i have to do? Thanks for the help :)

submitted by /u/Bongioo
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
FaPro is a Fake Protocol Server tool, Can easily start or stop multiple network services.The goal is to support as many protocols (https://www.kitploit.com/search/label/Protocols) as possible, and support as many deep interactions as possible for each protocol.
Features
Supported Running Modes: Local MachineVirtual NetworkSupported Protocols: DNSDCE/RPCEIPElasticsearchFTPHTTPIEC 104MemcachedModbusMQTTMySQLRDPRedisS7SMBSMTPSNMPSSHTelnetVNCIMAPPOP3Use TcpForward to forward network trafficSupport tcp syn logging
Protocol simulation (https://www.kitploit.com/search/label/Simulation) demos

Rdp
Support credssp ntlmv2 nla authentication.Support to configure the image displayed when user login.

___________________________
@hacking_Attack
@Hacking_Video