From ‘Gabut’ to Hall of Fame: U.S. Department of Energy
https://medium.com/@authxi/from-gabut-to-hall-of-fame-u-s-department-of-energy-917ce8792e19?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@authxi/from-gabut-to-hall-of-fame-u-s-department-of-energy-917ce8792e19?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
From ‘Gabut’ to Hall of Fame: U.S. Department of Energy
Pada kesempatan kali ini, saya akan menceritakan sedikit pengalaman saya..
Pada kesempatan kali ini, saya akan menceritakan sedikit pengalaman saya..Continue reading on Medium » (https://medium.com/@authxi/from-gabut-to-hall-of-fame-u-s-department-of-energy-917ce8792e19?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
From ‘Gabut’ to Hall of Fame: U.S. Department of Energy
Pada kesempatan kali ini, saya akan menceritakan sedikit pengalaman saya..
From ‘Gabut’ to Hall of Fame: U.S. Department of Energy
Pada kesempatan kali ini, saya akan menceritakan sedikit pengalaman saya..Continue reading on Medium »
Read more...
Pada kesempatan kali ini, saya akan menceritakan sedikit pengalaman saya..Continue reading on Medium »
Read more...
hacking: security in practice
Is it possible to wake a Cobalt Strike sleep cycle?
As the title states, is there a known way to break a beacon's sleep cycle in Cobalt Strike. Using the sleep function, we are able to create a specified time for our callback to beacon out for new requests. But in the event that your sleep time is set to far into the future, you may be waiting too long. I was hoping to find some form of wakeup command that forces the beacon to callback sooner.
submitted by /u/DarkJediSkii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to wake a Cobalt Strike sleep cycle?
As the title states, is there a known way to break a beacon's sleep cycle in Cobalt Strike. Using the sleep function, we are able to create a specified time for our callback to beacon out for new requests. But in the event that your sleep time is set to far into the future, you may be waiting too long. I was hoping to find some form of wakeup command that forces the beacon to callback sooner.
submitted by /u/DarkJediSkii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to wake a Cobalt Strike sleep cycle?
As the title states, is there a known way to break a beacon's sleep cycle in Cobalt Strike. Using the sleep function, we are able to create a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hacker steals government ID database for Argentina's entire population
https://external-preview.redd.it/et_VQ74iboy0Q5EhP5k55lbYOmENBiuS66cXq2gM_G8.jpg?width=640&crop=smart&auto=webp&s=09fd0821ee3e0eb619569d3443228653e6f5e8c4 submitted by /u/Muxxer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacker steals government ID database for Argentina's entire population
https://external-preview.redd.it/et_VQ74iboy0Q5EhP5k55lbYOmENBiuS66cXq2gM_G8.jpg?width=640&crop=smart&auto=webp&s=09fd0821ee3e0eb619569d3443228653e6f5e8c4 submitted by /u/Muxxer
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacker steals government ID database for Argentina's entire population
Posted in r/hacking by u/Muxxer • 615 points and 55 comments
hacking: security in practice
SHA 1 decoding
I know there are plenty of sites out there that will do a reverse look up on known hashes and give you the decoded string, but what is the tool people are using to manually decode the SHA 1?
submitted by /u/dravenhavok
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
SHA 1 decoding
I know there are plenty of sites out there that will do a reverse look up on known hashes and give you the decoded string, but what is the tool people are using to manually decode the SHA 1?
submitted by /u/dravenhavok
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
SHA 1 decoding
I know there are plenty of sites out there that will do a reverse look up on known hashes and give you the decoded string, but what is the tool...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Write-Up | Leviathan 0x06
https://cdn-images-1.medium.com/max/1374/1*GmDeZFDLVcSK60wzZSd3Zw.png
Leviathan is a wargame by OverTheWire, built to practice Information Security skills.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Write-Up | Leviathan 0x06
https://cdn-images-1.medium.com/max/1374/1*GmDeZFDLVcSK60wzZSd3Zw.png
Leviathan is a wargame by OverTheWire, built to practice Information Security skills.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Write-Up | Leviathan 0x06
Leviathan is a wargame by OverTheWire, built to practice Information Security skills. The focus of this particular set of challenges is the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Gitrecon para OSINT en perfiles de GITHUB
https://cdn-images-1.medium.com/max/1387/0*ck-MVp3VPadCqhYc
PUBLICADO EN 19 OCTUBRE, 2021 POR CARLOS GUTIERREZ
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Gitrecon para OSINT en perfiles de GITHUB
https://cdn-images-1.medium.com/max/1387/0*ck-MVp3VPadCqhYc
PUBLICADO EN 19 OCTUBRE, 2021 POR CARLOS GUTIERREZ
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Gitrecon para OSINT en perfiles de GITHUB
PUBLICADO EN 19 OCTUBRE, 2021 POR CARLOS GUTIERREZ
India’s First CrowdSource Bug Bounty Platform
https://cyber3ra.medium.com/indias-first-crowdsource-bug-bounty-platform-91640129a606?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://cyber3ra.medium.com/indias-first-crowdsource-bug-bounty-platform-91640129a606?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
India’s First CrowdSource Bug Bounty Platform
https://cyber3ra.com/
https://cyber3ra.com/Continue reading on Medium » (https://cyber3ra.medium.com/indias-first-crowdsource-bug-bounty-platform-91640129a606?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Windows Privilege Escalation: Weak Registry Permission
Microsoft Windows offers a wide range of fine-grained permissions and privileges for controlling access to Windows components including services, files, and registry entries. Exploiting Weak Registry Permissions is one technique to increase privileges. Table of Content Introduction Windows Registry Registry Hive Weak Registry Permission Prerequisite Lab Setup Abusing Weak Registry
The post Windows Privilege Escalation: Weak Registry Permission appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Windows Privilege Escalation: Weak Registry Permission
Microsoft Windows offers a wide range of fine-grained permissions and privileges for controlling access to Windows components including services, files, and registry entries. Exploiting Weak Registry Permissions is one technique to increase privileges. Table of Content Introduction Windows Registry Registry Hive Weak Registry Permission Prerequisite Lab Setup Abusing Weak Registry
The post Windows Privilege Escalation: Weak Registry Permission appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Windows Privilege Escalation: Weak Registry Permission
Learn how to exploit weak registry permissions for Windows privilege escalation and gain elevated access using registry misconfigurations.
LazyCSRF - A More Useful CSRF PoC Generator
http://www.kitploit.com/2021/10/lazycsrf-more-useful-csrf-poc-generator.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/10/lazycsrf-more-useful-csrf-poc-generator.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
LazyCSRF is a more useful CSRF PoC generator (https://www.kitploit.com/search/label/Generator) that runs on Burp (https://www.kitploit.com/search/label/Burp) Suite.
Motivation
Burp Suite is an intercepting HTTP Proxy, and it is the defacto tool for performing web application security testing. The feature of Burp Suite (https://www.kitploit.com/search/label/Burp%20Suite) that I like the most is Generate CSRF PoC. However, this does not support JSON parameters. It also uses the , so it cannot send PUT/DELETE requests. In addition, multibyte characters that can be displayed in the burp itself are often garbled in the generated CSRF PoC. Those were the motivations for creating this extension.
Features
Generating CSRF PoC with Burp Suite Community Edition (of course, it also works in Professional Edition)Support JSON parameter (like GraphQL (https://www.kitploit.com/search/label/GraphQL) Request)Support PUT/DELETE (only work with CORS (https://www.kitploit.com/search/label/CORS) enabled with an unrestrictive policy)Support displaying multibyte characters (like Japanese)
Difference in display of multibyte characters
The following image shows the difference in the display of multibyte characters between Burp's CSRF PoC generator and LazyCSRF. LazyCSRF can generate CSRF PoC without garbling multibyte characters that are not garbled on Burp.
___________________________
@hacking_Attack
@Hacking_Video
Motivation
Burp Suite is an intercepting HTTP Proxy, and it is the defacto tool for performing web application security testing. The feature of Burp Suite (https://www.kitploit.com/search/label/Burp%20Suite) that I like the most is Generate CSRF PoC. However, this does not support JSON parameters. It also uses the , so it cannot send PUT/DELETE requests. In addition, multibyte characters that can be displayed in the burp itself are often garbled in the generated CSRF PoC. Those were the motivations for creating this extension.
Features
Generating CSRF PoC with Burp Suite Community Edition (of course, it also works in Professional Edition)Support JSON parameter (like GraphQL (https://www.kitploit.com/search/label/GraphQL) Request)Support PUT/DELETE (only work with CORS (https://www.kitploit.com/search/label/CORS) enabled with an unrestrictive policy)Support displaying multibyte characters (like Japanese)
Difference in display of multibyte characters
The following image shows the difference in the display of multibyte characters between Burp's CSRF PoC generator and LazyCSRF. LazyCSRF can generate CSRF PoC without garbling multibyte characters that are not garbled on Burp.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.