hacking: security in practice
Games made to be hacked
Are there any games that are made to be HACKED. For example, the game tells you to hack it by analysing it code and finding vulnerabilities that can be exploited by performing actions inside the game to move on further levels in the game. Sorry if it's off-topic
submitted by /u/Hot-Fridge-with-ice
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Games made to be hacked
Are there any games that are made to be HACKED. For example, the game tells you to hack it by analysing it code and finding vulnerabilities that can be exploited by performing actions inside the game to move on further levels in the game. Sorry if it's off-topic
submitted by /u/Hot-Fridge-with-ice
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Games made to be hacked
Are there any games that are made to be HACKED. For example, the game tells you to hack it by analysing it code and finding vulnerabilities that...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Aliado ou Inimigo?
https://cdn-images-1.medium.com/max/2600/1*JWlsaK-7hHebQ1c0nEyOmw.jpeg
Vamos falar sobre smartphones?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Aliado ou Inimigo?
https://cdn-images-1.medium.com/max/2600/1*JWlsaK-7hHebQ1c0nEyOmw.jpeg
Vamos falar sobre smartphones?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Aliado ou Inimigo?
Vamos falar sobre smartphones?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Book Review: Foundations of Information Security
https://cdn-images-1.medium.com/max/2048/1*96EiJlfhvUiP6KLLI1R8Mw.png
Hello friends and welcome to HaXeZ, Foundations of Information Security is probably one of the first books I should have reviewed. This is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Book Review: Foundations of Information Security
https://cdn-images-1.medium.com/max/2048/1*96EiJlfhvUiP6KLLI1R8Mw.png
Hello friends and welcome to HaXeZ, Foundations of Information Security is probably one of the first books I should have reviewed. This is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Book Review: Foundations of Information Security
Hello friends and welcome to HaXeZ, Foundations of Information Security is probably one of the first books I should have reviewed. This is…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Powercat for Pentester
Introduction Powercat is a simple network utility used to perform low-level network communication operations. The tool is an implementation of the well-known Netcat in Powershell. Traditional anti-viruses are known to allow Powercat to execute. The installed size of the utility is 68 KB. The portability and platform independence of the
The post Powercat for Pentester appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Powercat for Pentester
Introduction Powercat is a simple network utility used to perform low-level network communication operations. The tool is an implementation of the well-known Netcat in Powershell. Traditional anti-viruses are known to allow Powercat to execute. The installed size of the utility is 68 KB. The portability and platform independence of the
The post Powercat for Pentester appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Powercat for Pentester
Explore Powercat for Pentester to perform reverse shells, port scans, tunneling, and file transfers in red team operations.
hacking: security in practice
Difficulty reading Nintendo switch microsd card
I'm having issues trying to read my switch's sd card. When I read it, the only folders that seem to be present are the "Nintendo" folder and its subfolders. I am wondering why I am unable to read the "switch", "bootloader", etc folders on my card.
submitted by /u/an_actual_degenerate
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Difficulty reading Nintendo switch microsd card
I'm having issues trying to read my switch's sd card. When I read it, the only folders that seem to be present are the "Nintendo" folder and its subfolders. I am wondering why I am unable to read the "switch", "bootloader", etc folders on my card.
submitted by /u/an_actual_degenerate
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Difficulty reading Nintendo switch microsd card
I'm having issues trying to read my switch's sd card. When I read it, the only folders that seem to be present are the "Nintendo" folder and its...
hacking: security in practice
figure out what serverside protection a program uses
I plan on using a cve exploit to bypass serversided protection of a windows program, but I'm not sure what serverside protection the program uses – is there anyway to find out without being the admin of the program?
submitted by /u/computerstuffs
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
figure out what serverside protection a program uses
I plan on using a cve exploit to bypass serversided protection of a windows program, but I'm not sure what serverside protection the program uses – is there anyway to find out without being the admin of the program?
submitted by /u/computerstuffs
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
figure out what serverside protection a program uses
I plan on using a cve exploit to bypass serversided protection of a windows program, but I'm not sure what serverside protection the program uses...
hacking: security in practice
How to find the root flag?
So I'm currently doing starting point Pentesting challenges on Hack The Box, and I'm stuck on the last challenge of Meow - submit the root flag. I'm a complete noob to hacking, so I'd really like some guidance here. I'm using Windows 10, with linode for basic nmap information and trying to install Arch on VM. Any help would be appreciated!
submitted by /u/rattusneotoma
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to find the root flag?
So I'm currently doing starting point Pentesting challenges on Hack The Box, and I'm stuck on the last challenge of Meow - submit the root flag. I'm a complete noob to hacking, so I'd really like some guidance here. I'm using Windows 10, with linode for basic nmap information and trying to install Arch on VM. Any help would be appreciated!
submitted by /u/rattusneotoma
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
iPhone SE2020
Hello so I bought a lost iPhone but I don't know if it is iCloud locked because I can try password any ideas what to do with it ?
submitted by /u/sadchrisbadvibes
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
iPhone SE2020
Hello so I bought a lost iPhone but I don't know if it is iCloud locked because I can try password any ideas what to do with it ?
submitted by /u/sadchrisbadvibes
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
iPhone SE2020
Hello so I bought a lost iPhone but I don't know if it is iCloud locked because I can try password any ideas what to do with it ?
https://a.thumbs.redditmedia.com/BlVU4wMQzdeIs2aQm9aDdS5Tz6i6q7RLcQjM7GZ72D4.jpg With the implementation of a new, user-friendly interface, the Firmware Analysis tool – EMBA – has taken the next step in its development.
https://preview.redd.it/yso9fhdckuw71.png?width=1575&format=png&auto=webp&s=892634f60e682db1cd8ff76ae4e2cc6bdd5b0f1b
In September 2020 we had already developed a powerful firmware scanner as an open-source project with the goal of making the crucial task of security testing less complex and time-consuming.
As a result, we were able to automate firmware analysis tasks during penetration tests.
EMBA’s user interface EMBArk now supports all steps from firmware upload, configuration and starting the test process to displaying real-time status details and generating a report containing vulnerability details with aggregated results across all analysis tasks.
The results are presented graphically and in an easy-to-understand format.
See a demonstration of the new UI in the video: https://youtu.be/qSHuPWbfhmI
EMBArk is being further developed as an open-source project on Github: https://github.com/e-m-b-a/embark
submitted by /u/_m-1-k-3_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
https://preview.redd.it/yso9fhdckuw71.png?width=1575&format=png&auto=webp&s=892634f60e682db1cd8ff76ae4e2cc6bdd5b0f1b
In September 2020 we had already developed a powerful firmware scanner as an open-source project with the goal of making the crucial task of security testing less complex and time-consuming.
As a result, we were able to automate firmware analysis tasks during penetration tests.
EMBA’s user interface EMBArk now supports all steps from firmware upload, configuration and starting the test process to displaying real-time status details and generating a report containing vulnerability details with aggregated results across all analysis tasks.
The results are presented graphically and in an easy-to-understand format.
See a demonstration of the new UI in the video: https://youtu.be/qSHuPWbfhmI
EMBArk is being further developed as an open-source project on Github: https://github.com/e-m-b-a/embark
submitted by /u/_m-1-k-3_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
EMBArk: firmware analysis reaches milestone
Posted in r/hacking by u/_m-1-k-3_ • 2 points and 0 comments
hacking: security in practice
How to find a admin password on MacBook
My school gave me a mac but my account doesn’t have admin permission is there anyway I could find the admin password as a non admin
submitted by /u/DrGhostFreak
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to find a admin password on MacBook
My school gave me a mac but my account doesn’t have admin permission is there anyway I could find the admin password as a non admin
submitted by /u/DrGhostFreak
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to find a admin password on MacBook
My school gave me a mac but my account doesn’t have admin permission is there anyway I could find the admin password as a non admin
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Zeno - THM Writeup
https://cdn-images-1.medium.com/max/800/1*CR4sjNr5zGs4eGilc0r8yQ.jpeg
Do you have the same patience as the great stoic philosopher Zeno? Try it out!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Zeno - THM Writeup
https://cdn-images-1.medium.com/max/800/1*CR4sjNr5zGs4eGilc0r8yQ.jpeg
Do you have the same patience as the great stoic philosopher Zeno? Try it out!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zeno - THM Writeup
Do you have the same patience as the great stoic philosopher Zeno? Try it out!
Web-Hacking-Toolkit - A Multi-Platform Web Hacking Toolkit Docker Image With Graphical User Interface (GUI) Support
http://www.kitploit.com/2021/10/web-hacking-toolkit-multi-platform-web.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/10/web-hacking-toolkit-multi-platform-web.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Installed
Tools
Interface Name Description CLI Amass (https://github.com/OWASP/Amass) In-depth Attack Surface Mapping and Asset Discovery CLI anew (https://github.com/tomnomnom/anew) A tool for adding new lines to files, skipping duplicates GUI Burp Suite Community (https://portswigger.net/burp) The BurpSuite Project community edition CLI curl (https://github.com/curl/curl) A command line (https://www.kitploit.com/search/label/Command%20Line) tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, MQTT, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features CLI dnsx (https://github.com/projectdiscovery/dnsx) dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers. CLI ffuf (https://github.com/ffuf/ffuf) Fast web fuzzer written in Go CLI findomain (https://github.com/Edu4rdSHL/findomain) The fastest and cross-platform subdomain enumerator, do not waste your time. GUI firefox (https://www.mozilla.org/en-US/firefox/new/) Safe and easy web browser from Mozilla CLI html-tool (https://github.com/tomnomnom/hacks/tree/master/html-tool) Take URLs or filenames for HTML documents on stdin and extract tag contents, attribute values, or comments CLI httpx (https://github.com/projectdiscovery/httpx) httpx is a fast and multi-purpose HTTP toolkit allow to run multiple probers (https://www.kitploit.com/search/label/Multiple%20Probers) using retryablehttp library, it is designed to maintain the result reliability with increased threads. CLI naabu (https://github.com/projectdiscovery/naabu) A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests CLI nmap (https://github.com/nmap/nmap) Nmap - the Network Mapper. Github mirror of official SVN repository. CLI sigsubfind3r (https://github.com/signedsecurity/sigsubfind3r) A subdomain discovery tool - it gathers a list of subdomains passively using various online sources. CLI sigurlfind3r (https://github.com/signedsecurity/sigurlfind3r) A passive reconnaissance (https://www.kitploit.com/search/label/Reconnaissance) tool for known URLs discovery - it gathers a list of URLs passively using various online sources. CLI sigurlscann3r (https://github.com/signedsecurity/sigurlscann3r) A web application attack surface mapping tool. It takes in a list of urls then performs numerous probes CLI subdomains.sh (https://github.com/enenumxela/subdomains.sh) A wrapper around for subdomains gathering tools (amass, subfinder, findomain & sigsubfind3r) to increase gathering efficiency and automating the workflow. CLI subfinder (https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. CLI tmux (https://github.com/tmux/tmux) tmux is a terminal multiplexer: it enables a number of terminals to be created, accessed, and controlled from a single screen. tmux may be detached from a screen and continue running in the background, then later reattached CLI vim (https://www.vim.org/) A highly configurable text editor built to make creating and changing any kind of text very efficient. CLI wappalyzer (https://github.com/aliasio/wappalyzer) Wappalyzer identifies technologies on websites, such as CMS, web frameworks, ecommerce platforms, JavaScript libraries, analytics tools and more. CLI wuzz (https://github.com/asciimoo/wuzz) Interactive cli tool for HTTP inspection
Wordlists
___________________________
@hacking_Attack
@Hacking_Video
Tools
Interface Name Description CLI Amass (https://github.com/OWASP/Amass) In-depth Attack Surface Mapping and Asset Discovery CLI anew (https://github.com/tomnomnom/anew) A tool for adding new lines to files, skipping duplicates GUI Burp Suite Community (https://portswigger.net/burp) The BurpSuite Project community edition CLI curl (https://github.com/curl/curl) A command line (https://www.kitploit.com/search/label/Command%20Line) tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, MQTT, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features CLI dnsx (https://github.com/projectdiscovery/dnsx) dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers. CLI ffuf (https://github.com/ffuf/ffuf) Fast web fuzzer written in Go CLI findomain (https://github.com/Edu4rdSHL/findomain) The fastest and cross-platform subdomain enumerator, do not waste your time. GUI firefox (https://www.mozilla.org/en-US/firefox/new/) Safe and easy web browser from Mozilla CLI html-tool (https://github.com/tomnomnom/hacks/tree/master/html-tool) Take URLs or filenames for HTML documents on stdin and extract tag contents, attribute values, or comments CLI httpx (https://github.com/projectdiscovery/httpx) httpx is a fast and multi-purpose HTTP toolkit allow to run multiple probers (https://www.kitploit.com/search/label/Multiple%20Probers) using retryablehttp library, it is designed to maintain the result reliability with increased threads. CLI naabu (https://github.com/projectdiscovery/naabu) A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests CLI nmap (https://github.com/nmap/nmap) Nmap - the Network Mapper. Github mirror of official SVN repository. CLI sigsubfind3r (https://github.com/signedsecurity/sigsubfind3r) A subdomain discovery tool - it gathers a list of subdomains passively using various online sources. CLI sigurlfind3r (https://github.com/signedsecurity/sigurlfind3r) A passive reconnaissance (https://www.kitploit.com/search/label/Reconnaissance) tool for known URLs discovery - it gathers a list of URLs passively using various online sources. CLI sigurlscann3r (https://github.com/signedsecurity/sigurlscann3r) A web application attack surface mapping tool. It takes in a list of urls then performs numerous probes CLI subdomains.sh (https://github.com/enenumxela/subdomains.sh) A wrapper around for subdomains gathering tools (amass, subfinder, findomain & sigsubfind3r) to increase gathering efficiency and automating the workflow. CLI subfinder (https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. CLI tmux (https://github.com/tmux/tmux) tmux is a terminal multiplexer: it enables a number of terminals to be created, accessed, and controlled from a single screen. tmux may be detached from a screen and continue running in the background, then later reattached CLI vim (https://www.vim.org/) A highly configurable text editor built to make creating and changing any kind of text very efficient. CLI wappalyzer (https://github.com/aliasio/wappalyzer) Wappalyzer identifies technologies on websites, such as CMS, web frameworks, ecommerce platforms, JavaScript libraries, analytics tools and more. CLI wuzz (https://github.com/asciimoo/wuzz) Interactive cli tool for HTTP inspection
Wordlists
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - owasp-amass/amass: In-depth attack surface mapping and asset discovery
In-depth attack surface mapping and asset discovery - owasp-amass/amass
Wordlist Description SecLists (https://github.com/danielmiessler/SecLists) SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. jhaddix (https://gist.github.com/jhaddix) / content_discovery_all.txt (https://gist.github.com/jhaddix/b80ea67d85c13206125806f0828f4d10) a masterlist of content discovery (https://www.kitploit.com/search/label/Content%20Discovery) URLs and files (used most commonly with gobuster)
Download Web-Hacking-Toolkit (https://github.com/signedsecurity/web-hacking-toolkit)
___________________________
@hacking_Attack
@Hacking_Video
Download Web-Hacking-Toolkit (https://github.com/signedsecurity/web-hacking-toolkit)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - danielmiessler/SecLists: SecLists is the security tester's companion. It's a collection of multiple types of lists used…
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, pas...