Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
among us hacks

Im tryna look for some amongus hacks any good ones u guys know???

submitted by /u/MossyCrow
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Scarce-Apache2 - A Framework For Bug Hunting Or Pentesting Targeting Websites That Have CVE-2021-41773 Vulnerability In Public

https://blogger.googleusercontent.com/img/a/AVvXsEhRWcdl04xGOBLlM_g9DzCMsFGGCPy3N36bwNXfArCm8SpaUroy9Mz1Hbu3C1TRfKxBxybgzs-SqbGIEGrRNmRVNsBKR6Q-xz_FidYUIKelwx0WxxGHbUKwuaAxqxbEllP6n3ltZ9GEJ5YooEJjV_t9qXahy8rxhXsfZdsm13xnvEsqubv2pKrmpz_ZTQ=w640-h330 This tool can scan websites with CVE-2021-41773 Vulnerability that are affecting Apache2 Webserver, ScaRCE can run too for executing Remote Command Injections at the webservers that found from the scanning method (Only if the MOD_CGI is Enabled at the targeted webserver). This tool works with the provided Single target or Mass Target from a file list. Only use this tool for Bug Hunting/ Pentesting Purposes. https://blogger.googleusercontent.com/img/a/AVvXsEhcRO_Dx6ScPy-zCqhbv9ZsB2Y5EC8Fo6FWrpWx7sC6H81feJvY1pb5uzirFi7KR2oxTamEqKPWFhxXCSe1KxDJRM7o_OPtZ0E_opEOIPdRH5-K7CLTLOPqYl8AVpIYyPIVzHN2y0b-oX3qT8PJHymUb-zEDweKomCW-IrxvpHMUWYDhxdLHAhrbYyhRg=w640-h316 https://blogger.googleusercontent.com/img/a/AVvXsEibLpxQqYUk-e42cAQqZ79qpvIPld94BKnn9nRm5UKHJHHzCrxMmSyMaEe6e5oqhtxC1eNWqnS_fVBYSzclUT22R3QBDK-dVg6xZmz_UNeVjr8xPea5WH1k8ewTWW1cOFovZuFQKAI3eMTGsaEzRgRzc5Y-Zps4nILNgDM7M8lXAq_dR8u-VQ14vRnw4w=w640-h316 https://blogger.googleusercontent.com/img/a/AVvXsEgITNTPLGq-_s81ClmEAdJnpep5lS-i7ge88cEABBssuGeWiMh_sGZKgZdfBjaSBtF28FxHMTgOgdYMX41-cRlbCm9fsupSbxh9IpupmTp8sfqoEJrktxbd5YYiIb9wjULUrKMQ24wVyYOMXEdo5voYEA9DjZ10AtWjOsnZGvMJj5h9sgKsomPSldh1xw=w640-h330 Installation- git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- bash scarce.sh
or you can install in your system like this - git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- sudo cp scarce.sh /usr/bin/scarce && sudo chmod +x /usr/bin/scarce
- $ scarce
Usage* Menu's
* Menu 1is for scanning LFI Vulnerability from a provided file that contains the list of the target urlor a provided single target url.
* Menu 2is for scanning RCE Vulnerability from a provided file that contains the list of the target urlor a provided single target url.
* Menu 3is for Executing RCE from a provided single target url. This will work for the Maybe VulnResults or sometimes with a 500 Error Response.

* URL Format
* Use http://like http://example.comor https://like https://example.comfor the url formatting at Single Target usages
* For Url or IP that has been provided from a List, Don't Use the URL Formatting like eg:
* https://target.com
* http://hackerone.com
* https://bugcrowd.com Requirements* curl
* bash
* git CreditsThanks to:

* CVE-2021-41773 Reproduced by @ptswarm
* Executing RCE in CVE-2021-41773 by @hackerfantastic
* Removing 5xx Error when Running RCE by @lukejahnke Download Scarce-Apache2

___________________________
@hacking_Attack
@Hacking_Video
This tool can scan (https://www.kitploit.com/search/label/Scan) websites with CVE-2021-41773 Vulnerability (https://www.kitploit.com/search/label/Vulnerability) that are affecting Apache2 Webserver, ScaRCE can run too for executing Remote (https://www.kitploit.com/search/label/Remote) Command Injections at the webservers that found from the scanning (https://www.kitploit.com/search/label/Scanning) method (Only if the MOD_CGI is Enabled at the targeted webserver). This tool works with the provided Single target or Mass Target from a file list. Only use this tool for Bug Hunting/ Pentesting Purposes.

___________________________
@hacking_Attack
@Hacking_Video
Installation
- git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- bash scarce.sh
or you can install in your system like this- git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- sudo cp scarce.sh /usr/bin/scarce && sudo chmod +x /usr/bin/scarce
- $ scarce

Usage
Menu's Menu 1 is for scanning LFI Vulnerability (https://www.kitploit.com/search/label/LFI%20Vulnerability) from a provided file that contains the list of the target url or a provided single target url.Menu 2 is for scanning RCE Vulnerability from a provided file that contains the list of the target url or a provided single target url.Menu 3 is for Executing RCE from a provided single target url. This will work for the Maybe Vuln Results or sometimes with a 500 Error Response.URL Format Use http:// like http://example.com or https:// like https://example.com for the url formatting at Single Target usagesFor Url or IP that has been provided from a List, Don't Use the URL Formatting like eg: https://target.com (https://target.com/)http://hackerone.com (http://hackerone.com/)https://bugcrowd.com (https://bugcrowd.com/)
Requirements
curlbashgit
Credits
Thanks to:CVE-2021-41773 Reproduced (https://twitter.com/ptswarm/status/1445376079548624899) by @ptswarm (https://twitter.com/ptswarm)Executing RCE in CVE-2021-41773 (https://twitter.com/hackerfantastic/status/1445531829985968137) by @hackerfantastic (https://twitter.com/hackerfantastic)Removing 5xx Error when Running RCE (https://twitter.com/lukejahnke/status/1445560511270064138) by @lukejahnke (https://twitter.com/lukejahnke)

Download Scarce-Apache2 (https://github.com/HightechSec/scarce-apache2)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
APTs, Teleworking, and Advanced VPN Exploits: The Perfect Storm

A Mandiant researcher shares the details of an investigation into the misuse of Pulse Secure VPN devices by suspected state-sponsored threat actors.
hacking: security in practice
Locking down a PC/Laptop, unlocking only with a key.

Greetings,



I'm using my laptop frequently (alongside with my PC, but that's not so important in this story) in a workplace park, which is a little bit outside of our building. Many times I had to run for some papers inside the building, and I had to let my laptop outside, and I'm afraid one day someone will just randomly take it (since... that place is visited by many tourists and people). I'm more productive outside, the laptop doesn't costs so much, but still I wouldn't waste like 10 days of work just to get another laptop. Is there a way, IN CASE (hopefully never) someone takes my laptop, to lock it from my PC (whatever, home PC or office PC), and so that the only way for them to unlock is is to put the password in (and maybe show a message or something).



Why I don't want to use the Windows default password thingy? I hate waiting at every login, startup to input my password, cuz as I said, I frequently just leave it like that, and I don't need security 24/7, I would like to activate that password thing just when I access it from another PC.



TLDR: A remote software that locks your PC, and can only be unlocked when the user inputs a password



Thanks!

submitted by /u/D1stRU3T0R
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
IP address of a scammer

Hi all,

Someone scammed me out of a lot of money but I was able to get their IP address, what can i do with it? Can I spoof them, report them, send them crap . any insight is appreciated

submitted by /u/wayfaringnomad
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
programming in python

i spent 2 months learning basics of python so what do i do now like should i remember all codes or start another language

( i want to become white hat hacker and historian )

submitted by /u/AdEducational9877
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video