Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
LazyCSRF - A More Useful CSRF PoC Generator

https://blogger.googleusercontent.com/img/a/AVvXsEhJWRJapZuz9HeJ2mIvfS7E6auhNUuzFRpWbabN__ib2MKlW0zj1abgGwfSaHp5LgbdBfzqiZ6xAhQaiLxvhWuSXIYzBFi1dBkOOFMhFcxKDw7L_GyhjRgfUeKipWNg8W5E9x0YlqOTth2E7qxlG-LSCwolYfUzkMfJFSLczVN3mNmPMXtfPzeA7vKf8Q=w640-h416 LazyCSRF is a more useful CSRF PoC generator that runs on Burp Suite. MotivationBurp Suite is an intercepting HTTP Proxy, and it is the defacto tool for performing web application security testing. The feature of Burp Suite that I like the most is Generate CSRF PoC. However, this does not support JSON parameters. It also uses the , so it cannot send PUT/DELETE requests. In addition, multibyte characters that can be displayed in the burp itself are often garbled in the generated CSRF PoC. Those were the motivations for creating this extension. Features* Generating CSRF PoC with Burp Suite Community Edition (of course, it also works in Professional Edition)
* Support JSON parameter (like GraphQL Request)
* Support PUT/DELETE (only work with CORS enabled with an unrestrictive policy)
* Support displaying multibyte characters (like Japanese) Difference in display of multibyte charactersThe following image shows the difference in the display of multibyte characters between Burp's CSRF PoC generator and LazyCSRF. LazyCSRF can generate CSRF PoC without garbling multibyte characters that are not garbled on Burp. https://blogger.googleusercontent.com/img/a/AVvXsEhJWRJapZuz9HeJ2mIvfS7E6auhNUuzFRpWbabN__ib2MKlW0zj1abgGwfSaHp5LgbdBfzqiZ6xAhQaiLxvhWuSXIYzBFi1dBkOOFMhFcxKDw7L_GyhjRgfUeKipWNg8W5E9x0YlqOTth2E7qxlG-LSCwolYfUzkMfJFSLczVN3mNmPMXtfPzeA7vKf8Q=w640-h416 InstallationDownload the jar from GitHub Releases. In Burp Suite, go to the Extensions tab in the Extender tab, and add a new extension. Select the extension type Java, and specify the location of the jar. How to BuildintellijIf you use IntelliJ IDEA, you can build it by following Build-> Build Artifacts-> LazyCSRF:jar-> Build. Command lineYou can build it with maven. $ mvn install UsageYou can generate a CSRF PoC by selecting Extensions->Generate JSON CSRF PoC with Ajax or Generate POST PoC with Formfrom the menu that opens by right-clicking on Burp Suite. https://blogger.googleusercontent.com/img/a/AVvXsEjyH7_kcySGpwGGfmNrVSwqVTjYBPB1QbplKZLi-AFr4uHfYMAakhjHR-4BAu2HJAiHdOu5QdlDiH0LHML0Z_l7jGNNbpU9PTrZK_yD2XUIma4vknRt4uS5k7RCz99m4kDwyfJUWAYfyBWhEdabfIR5mDBuKrpqOFAHZf7O3c8Oypz2oj889BqNjGg_KA=w640-h504 LICENSEMIT License

Copyright (C) 2021 tkmru Download lazyCSRF

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Name That Toon: Bone Dry

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
Dark Reading: Attacks/Breaches
Query.ai Closes $15M Series A for Security Investigations Tool

The funding will support product development for Query.AI's browser-based security investigations tool.
Dark Reading: Attacks/Breaches
Candy Corn Maker Hit With Ransomware

Ferrara Candy Co. said a ransomware attack earlier this month won't affect Halloween supplies of its sweets, which include Brachs, Keebler, Sweet Tarts, and other popular brands.
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Enterprise Cybersecurity Strategies Are Getting More Attention

Data in Dark Reading's 2021 Strategic Security Survey report suggest organizations are taking the security challenge seriously.
hacking: security in practice
How effective is a custom wordlist for brute-force?

What's the percentage of people that uses pet name, company name, date of birth and etc as password? How effective can a customized wordlist be when brute-forcing passwords?

submitted by /u/Im_MrLonely
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to fully encrypt a dual boot hard drive?

If I have a hard drive with 2 partitions, one for Windows 10 and one for Kali Linux. How do I fully encrypt it to where you have to use a password to get anything off the hard drive? How do I know it's fully secure?

submitted by /u/ZikeSike2459
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Wifite

Just as a question. I'm quite new into this scene and I've been trying to learn what I can, whenever I have a chance to. How "loud" is an application like wifite??

submitted by /u/Caddburry00
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video