Unauthorized access to any user’s account.
Hi everyone! This is Vikram Naidu, Bug bounty hunter and cybersecurity researcher from India. Hope you all are safe. This is my second…Continue reading on Medium »
Read more...
Hi everyone! This is Vikram Naidu, Bug bounty hunter and cybersecurity researcher from India. Hope you all are safe. This is my second…Continue reading on Medium »
Read more...
hacking: security in practice
Soo not sure if I can ask this..
So I use websites on the playstation browser to watch some things, things that you can't find other places (really old anime I use a certain site for example) but I know it was easier to do on the ps3. Anyone know of any sites on ps4 I can use? Or a work around? Remove if not allowed.
submitted by /u/Maniacal_Nut
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Soo not sure if I can ask this..
So I use websites on the playstation browser to watch some things, things that you can't find other places (really old anime I use a certain site for example) but I know it was easier to do on the ps3. Anyone know of any sites on ps4 I can use? Or a work around? Remove if not allowed.
submitted by /u/Maniacal_Nut
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Soo not sure if I can ask this..
So I use websites on the playstation browser to watch some things, things that you can't find other places (really old anime I use a certain site...
hacking: security in practice
Custom themes onto your ps4?
I remember back in ps3 days there was a site where you could install custom themes to it, like I had a kingdom hearts one that changed the background, the music, sound effects, even the browser cursor. Is there anyway to do that on ps4?
submitted by /u/Maniacal_Nut
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Custom themes onto your ps4?
I remember back in ps3 days there was a site where you could install custom themes to it, like I had a kingdom hearts one that changed the background, the music, sound effects, even the browser cursor. Is there anyway to do that on ps4?
submitted by /u/Maniacal_Nut
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Custom themes onto your ps4?
I remember back in ps3 days there was a site where you could install custom themes to it, like I had a kingdom hearts one that changed the...
hacking: security in practice
how to track
what's the best way to track the person who has been into my wifi and performing MITM attacks and harassing me. thanks
submitted by /u/VariousCheek42
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
how to track
what's the best way to track the person who has been into my wifi and performing MITM attacks and harassing me. thanks
submitted by /u/VariousCheek42
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
how to track
what's the best way to track the person who has been into my wifi and performing MITM attacks and harassing me. thanks
Unauthorized access to any user’s account.
https://medium.com/@vikramroot/unauthorized-access-to-any-users-account-600e8efe7de0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@vikramroot/unauthorized-access-to-any-users-account-600e8efe7de0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unauthorized access to any user’s account.
Hi everyone! This is Vikram Naidu, Bug bounty hunter and cybersecurity researcher from India. Hope you all are safe. This is my second…
Hi everyone! This is Vikram Naidu, Bug bounty hunter and cybersecurity researcher from India. Hope you all are safe. This is my second…Continue reading on Medium » (https://medium.com/@vikramroot/unauthorized-access-to-any-users-account-600e8efe7de0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unauthorized access to any user’s account.
Hi everyone! This is Vikram Naidu, Bug bounty hunter and cybersecurity researcher from India. Hope you all are safe. This is my second…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Imfamous Ethereum DAO hack
https://cdn-images-1.medium.com/max/1816/1*qV8fZx8M6B8OEIzYa07s5A.png
1. introduction-
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Imfamous Ethereum DAO hack
https://cdn-images-1.medium.com/max/1816/1*qV8fZx8M6B8OEIzYa07s5A.png
1. introduction-
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Imfamous Ethereum DAO hack
1. introduction-
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Blockchain attacks
https://cdn-images-1.medium.com/max/788/1*HjsZCdJ0yO9rxstIrNjKyw.jpeg
Any new technologies always bring not only benefits for civilization, but also contain new threats, including risks associated with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Blockchain attacks
https://cdn-images-1.medium.com/max/788/1*HjsZCdJ0yO9rxstIrNjKyw.jpeg
Any new technologies always bring not only benefits for civilization, but also contain new threats, including risks associated with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blockchain attacks
Any new technologies always bring not only benefits for civilization, but also contain new threats, including risks associated with…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BSSN Diretas, Puan Maharani Tunjukkan Rasa Kecewa Berat
https://cdn-images-1.medium.com/max/1280/1*0DcGASM7CHKGIIYuNjWpmw.jpeg
Baru minggu ini, ada peretasan pada situs resmi milik Badan Siber dan Sandi Negara (BSSN). Sudah seminggu sampai akhirnya terungkap ke…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
BSSN Diretas, Puan Maharani Tunjukkan Rasa Kecewa Berat
https://cdn-images-1.medium.com/max/1280/1*0DcGASM7CHKGIIYuNjWpmw.jpeg
Baru minggu ini, ada peretasan pada situs resmi milik Badan Siber dan Sandi Negara (BSSN). Sudah seminggu sampai akhirnya terungkap ke…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
BSSN Diretas, Puan Maharani Tunjukkan Rasa Kecewa Berat
Baru minggu ini, ada peretasan pada situs resmi milik Badan Siber dan Sandi Negara (BSSN). Sudah seminggu sampai akhirnya terungkap ke…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Threat Analysis Honey Pot — Tokyo
https://cdn-images-1.medium.com/max/800/0*DgZJ0aalxYDsfcFE
INTRODUCTION
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Threat Analysis Honey Pot — Tokyo
https://cdn-images-1.medium.com/max/800/0*DgZJ0aalxYDsfcFE
INTRODUCTION
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Threat Analysis Honey Pot — Tokyo
INTRODUCTION
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Thanks for checking out my profile, just found this site by accident.
If you still use IRC (yes, people still use it) feel free to join #9x/EFNet to connect with a bunch of my long time hax0r friends,.. many…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Thanks for checking out my profile, just found this site by accident.
If you still use IRC (yes, people still use it) feel free to join #9x/EFNet to connect with a bunch of my long time hax0r friends,.. many…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Thanks for checking out my profile, just found this site by accident.
If you still use IRC (yes, people still use it) feel free to join #9x/EFNet to connect with a bunch of my long time hax0r friends,.. many…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Sensitive data of 400,000 German students exposed by API flaw
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Sensitive data of 400,000 German students exposed by API flawPost Views: 89
Reading Time: 1 Minute
Approximately 400,000 users of Scoolio, a student community app widely used in Germany, had sensitive information exposed due to an API flaw in the platform. Lilith Wittmann, a security researcher from the IT security collective “Zerforchung” discovered the bug and immediately disclosed their findings to the Scoolio team. A “student” businessScoolio is a German student community app that aims to build better time management skills, tutoring, homework planning, and group chats to network with peers. The app also allows companies to network with students to share job openings or internship opportunities.
Scoolio makes money by collecting data generated through these tools and features and then monetizing it with targeted advertising. However, Scoolio states that they do not collect or share any information from students without their consent.
To build student membership, Scoolio has partnered with schools around Germany to use their platform as a remote teaching assistance tool for file exchanges or remote digital homework collection.
It’s very development was financially backed by three state-owned investment groups, namely SIB Innovations – und Beteiligungsgesellschaft mbH, Technologiegründerfonds Sachsen, and Kreissparkasse Bautzen.
Due to the partnerships and government backings, many students use the app as a standard tool in their classes.
See Also: Complete Offensive Security and Ethical Hacking Course Data exposed by leaky APIIn Zerforchung’s report, Wittmann explains how she exploited Scoolio API flaws to retrieve extremely sensitive data for any user ID used on the app.
The exposed personal data includes:
* User nickname
* User and parent email addresses
* GPS location at which the app was last opened
* Name of school and class
* Interests
* UUID details
* Personality traits (origin, religion, sexuality)
Wittman shared a fictitious sample of the types of data exposed by the flaw below.
https://www.bleepstatic.com/images/news/security/scoolio-data.jpg
Fix released after thirty daysZerforchung states that they disclosed the flaw to Scoolio on September 21, 2021, but it took the software developer until October 25, 2021 to deploy a patch.
However, due to the simplicity of the fix and the sensitive nature of the exposed data, Wittmann believes the fix should have been released more quickly. “I would like to thank Ms. Wittmann for the information and the SDS for the exchange and thank you for your feedback on our security measures,” Danny Roller, CEO andFounder of the Scoolio app, shared in a statement.
“Fortunately, after extensive testing, we can confirm that No user data was intercepted by third parties prior to the investigation by Ms. Wittmann and we have successfull[...]
___________________________
@hacking_Attack
@Hacking_Video
Sensitive data of 400,000 German students exposed by API flaw
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Sensitive data of 400,000 German students exposed by API flawPost Views: 89
Reading Time: 1 Minute
Approximately 400,000 users of Scoolio, a student community app widely used in Germany, had sensitive information exposed due to an API flaw in the platform. Lilith Wittmann, a security researcher from the IT security collective “Zerforchung” discovered the bug and immediately disclosed their findings to the Scoolio team. A “student” businessScoolio is a German student community app that aims to build better time management skills, tutoring, homework planning, and group chats to network with peers. The app also allows companies to network with students to share job openings or internship opportunities.
Scoolio makes money by collecting data generated through these tools and features and then monetizing it with targeted advertising. However, Scoolio states that they do not collect or share any information from students without their consent.
To build student membership, Scoolio has partnered with schools around Germany to use their platform as a remote teaching assistance tool for file exchanges or remote digital homework collection.
It’s very development was financially backed by three state-owned investment groups, namely SIB Innovations – und Beteiligungsgesellschaft mbH, Technologiegründerfonds Sachsen, and Kreissparkasse Bautzen.
Due to the partnerships and government backings, many students use the app as a standard tool in their classes.
See Also: Complete Offensive Security and Ethical Hacking Course Data exposed by leaky APIIn Zerforchung’s report, Wittmann explains how she exploited Scoolio API flaws to retrieve extremely sensitive data for any user ID used on the app.
The exposed personal data includes:
* User nickname
* User and parent email addresses
* GPS location at which the app was last opened
* Name of school and class
* Interests
* UUID details
* Personality traits (origin, religion, sexuality)
Wittman shared a fictitious sample of the types of data exposed by the flaw below.
https://www.bleepstatic.com/images/news/security/scoolio-data.jpg
Fix released after thirty daysZerforchung states that they disclosed the flaw to Scoolio on September 21, 2021, but it took the software developer until October 25, 2021 to deploy a patch.
However, due to the simplicity of the fix and the sensitive nature of the exposed data, Wittmann believes the fix should have been released more quickly. “I would like to thank Ms. Wittmann for the information and the SDS for the exchange and thank you for your feedback on our security measures,” Danny Roller, CEO andFounder of the Scoolio app, shared in a statement.
“Fortunately, after extensive testing, we can confirm that No user data was intercepted by third parties prior to the investigation by Ms. Wittmann and we have successfull[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Sensitive data of 400,000 German students exposed by API flaw | Black Hat Ethical Hacking
Approximately 400,000 users of Scoolio, a student community app widely used in Germany, had sensitive information exposed due to an API flaw in the platform.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Sensitive data of 400,000 German students exposed by API flaw https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Sensitive data of 400,000 German students exposed by API flawPost Views: 89 …
y closed the gaps found.”
See Also: OSINT Tool: Osintgram
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers2 weeks ago
The post Sensitive data of 400,000 German students exposed by API flaw first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
See Also: OSINT Tool: Osintgram
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers2 weeks ago
The post Sensitive data of 400,000 German students exposed by API flaw first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
SQL Injection JR. Pentester -TryHackMe Part 2
https://mukibas37.medium.com/sql-injection-jr-pentester-tryhackme-part-2-3b9d106e9d7b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://mukibas37.medium.com/sql-injection-jr-pentester-tryhackme-part-2-3b9d106e9d7b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
SQL Injection JR. Pentester -TryHackMe Part 2
Hi folks, welcome back to part 2 of SQL injection in JR. Pentester path.