If you were just wondering by seeing the bug bounty stories and posts of facebook friends and always wanted to get started with this bug…Continue reading on Medium » (https://shubhdhungana.medium.com/getting-started-with-bug-bounty-hunting-shubham-1953f8086377?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Getting Started With Bug Bounty Hunting | Shubham
If you were just wondering by seeing the bug bounty stories and posts of facebook friends and always wanted to get started with this bug…
hacking: security in practice
I found a XSS vulnerability on a fortune 100 website, any way to correctly report it for a bounty?
This is a throwaway account.
I'm a software engineer in the United States. My area of work is in interactive marketing. One of our clients, a fortune 100 company, has hired the company I work for to do a project. I'm the developer on the project. In working with the client and their APIs, I found a XSS vulnerability in their code. It's a pretty big one. Someone could easily use this XSS vulnerability to phish for usernames and passwords.
How should I proceed? Do you think it's possible I could report this for a bounty? Should I just keep it to myself?
I should note that the client is not a bank, and there's really low stakes if someone's username/password is obtained (though I suppose if someone uses the same password everywhere ...)
Any advice is appreciated.
Thanks
submitted by /u/verybadrunner
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I found a XSS vulnerability on a fortune 100 website, any way to correctly report it for a bounty?
This is a throwaway account.
I'm a software engineer in the United States. My area of work is in interactive marketing. One of our clients, a fortune 100 company, has hired the company I work for to do a project. I'm the developer on the project. In working with the client and their APIs, I found a XSS vulnerability in their code. It's a pretty big one. Someone could easily use this XSS vulnerability to phish for usernames and passwords.
How should I proceed? Do you think it's possible I could report this for a bounty? Should I just keep it to myself?
I should note that the client is not a bank, and there's really low stakes if someone's username/password is obtained (though I suppose if someone uses the same password everywhere ...)
Any advice is appreciated.
Thanks
submitted by /u/verybadrunner
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I found a XSS vulnerability on a fortune 100 website, any way to...
This is a throwaway account. I'm a software engineer in the United States. My area of work is in interactive marketing. One of our clients, a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
This week in the Console newsletter, I interviewed the developer of a fully automated decryption/decoding/cracking tool which uses natural language processing & artificial intelligence to do the cracking. I thought /r/hacking might be interested in checking it out! :)
https://external-preview.redd.it/ZGfEDUrg1JgElfm3FeyiLGM4t3EcLEeMLrWkEWKbqmw.jpg?width=640&crop=smart&auto=webp&s=5bbc9dfed02ae52ed7dd1721168dc02081e1f68d submitted by /u/binaryfor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
This week in the Console newsletter, I interviewed the developer of a fully automated decryption/decoding/cracking tool which uses natural language processing & artificial intelligence to do the cracking. I thought /r/hacking might be interested in checking it out! :)
https://external-preview.redd.it/ZGfEDUrg1JgElfm3FeyiLGM4t3EcLEeMLrWkEWKbqmw.jpg?width=640&crop=smart&auto=webp&s=5bbc9dfed02ae52ed7dd1721168dc02081e1f68d submitted by /u/binaryfor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
This week in the Console newsletter, I interviewed the developer...
Posted in r/hacking by u/binaryfor • 2 points and 0 comments
hacking: security in practice
Kali linux stty raw -echo doesn’t work
Once i get a bash shell on the victim i want to have a fully usable shell, everywhere i look i have to ctrlz —> stty raw -echo —> fg —> enter —> enter. But when i do it, it doesn’t work, the enter is recognized as a charachter. I haven’t found anything about it online and i remember asking to my professor and he mentioned something about how newer versions of kali treats the tty. Anyone knows what i have to do? Thanks for the help :)
submitted by /u/Bongioo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Kali linux stty raw -echo doesn’t work
Once i get a bash shell on the victim i want to have a fully usable shell, everywhere i look i have to ctrlz —> stty raw -echo —> fg —> enter —> enter. But when i do it, it doesn’t work, the enter is recognized as a charachter. I haven’t found anything about it online and i remember asking to my professor and he mentioned something about how newer versions of kali treats the tty. Anyone knows what i have to do? Thanks for the help :)
submitted by /u/Bongioo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Kali linux stty raw -echo doesn’t work
Once i get a bash shell on the victim i want to have a fully usable shell, everywhere i look i have to ctrl^z —> stty raw -echo —> fg —> enter —>...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
افشای اطلاعات سایت سلامتی ۲۴
https://cdn-images-1.medium.com/max/1080/1*CX1Ugp7wMLaRuZuJTIAKXQ.jpeg
Sensitive Data Exposure @ Salamati24
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
افشای اطلاعات سایت سلامتی ۲۴
https://cdn-images-1.medium.com/max/1080/1*CX1Ugp7wMLaRuZuJTIAKXQ.jpeg
Sensitive Data Exposure @ Salamati24
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
افشای اطلاعات سایت سلامتی ۲۴
Sensitive Data Exposure @ Salamati24
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Day 1 of #100DaysOfSmartContractHacking (Just my own journal)
https://cdn-images-1.medium.com/max/1911/1*foO1edBu5mieQjBXIUIYDg.png
16/10/2021
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Day 1 of #100DaysOfSmartContractHacking (Just my own journal)
https://cdn-images-1.medium.com/max/1911/1*foO1edBu5mieQjBXIUIYDg.png
16/10/2021
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Day 1 of #100DaysOfSmartContractHacking (Just my own journal)
16/10/2021
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to become a Ethical Hacker in 10 stage
https://cdn-images-1.medium.com/max/1280/0*o7T1q92GjClc1CwH
If you want to become a hacker in easy steps, Know Why to choose Hacking? Trust me, the response to this inquiry will definitely show you…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to become a Ethical Hacker in 10 stage
https://cdn-images-1.medium.com/max/1280/0*o7T1q92GjClc1CwH
If you want to become a hacker in easy steps, Know Why to choose Hacking? Trust me, the response to this inquiry will definitely show you…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to become a Ethical Hacker in 10 stage
If you want to become a hacker in easy steps, Know Why to choose Hacking? Trust me, the response to this inquiry will definitely show you…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox Write-up: Granny.
https://cdn-images-1.medium.com/max/600/0*icr0hzNgGThTHjPS
Dificultad: Fácil.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox Write-up: Granny.
https://cdn-images-1.medium.com/max/600/0*icr0hzNgGThTHjPS
Dificultad: Fácil.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox Write-up: Granny.
Dificultad: Fácil.
Fapro - Free, Cross-platform, Single-file mass network protocol server simulator
http://www.kitploit.com/2021/10/fapro-free-cross-platform-single-file.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/10/fapro-free-cross-platform-single-file.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
FaPro is a Fake Protocol Server tool, Can easily start or stop multiple network services.The goal is to support as many protocols (https://www.kitploit.com/search/label/Protocols) as possible, and support as many deep interactions as possible for each protocol.
Features
Supported Running Modes: Local MachineVirtual NetworkSupported Protocols: DNSDCE/RPCEIPElasticsearchFTPHTTPIEC 104MemcachedModbusMQTTMySQLRDPRedisS7SMBSMTPSNMPSSHTelnetVNCIMAPPOP3Use TcpForward to forward network trafficSupport tcp syn logging
Protocol simulation (https://www.kitploit.com/search/label/Simulation) demos
Rdp
Support credssp ntlmv2 nla authentication.Support to configure the image displayed when user login.
___________________________
@hacking_Attack
@Hacking_Video
Features
Supported Running Modes: Local MachineVirtual NetworkSupported Protocols: DNSDCE/RPCEIPElasticsearchFTPHTTPIEC 104MemcachedModbusMQTTMySQLRDPRedisS7SMBSMTPSNMPSSHTelnetVNCIMAPPOP3Use TcpForward to forward network trafficSupport tcp syn logging
Protocol simulation (https://www.kitploit.com/search/label/Simulation) demos
Rdp
Support credssp ntlmv2 nla authentication.Support to configure the image displayed when user login.
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
SSH
Support user login.Support fake terminal commands, such as id, uid, whoami, etc.Account format: username:password:home:uid
___________________________
@hacking_Attack
@Hacking_Video
Support user login.Support fake terminal commands, such as id, uid, whoami, etc.Account format: username:password:home:uid
___________________________
@hacking_Attack
@Hacking_Video
IMAP & SMTP
Support user login and interaction.
___________________________
@hacking_Attack
@Hacking_Video
Support user login and interaction.
___________________________
@hacking_Attack
@Hacking_Video