Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Welcome Again ! In this write-up we will discuss introduction to the main components of the Metasploit Framework. This room provided on…Continue reading on Medium » (https://sudozain.medium.com/metasploit-introduction-tryhackme-9db608546381?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Content Discovery TryHackMe

Welcome Again ! This walkthrough is about a video solving Content Discovery room on tryhackme and we made it on our youtube channel …

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Metasploit Introduction | TryHackMe

https://cdn-images-1.medium.com/max/1280/1*YVstsKiC69Zsm3n5_Zo-YQ.jpeg
Welcome Again ! In this write-up we will discuss introduction to the main components of the Metasploit Framework. This room provided on…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
swap.kiwi audit result

https://cdn-images-1.medium.com/max/2600/0*Se3d_Tb-zpcrfGaV
Trust is hard to gain and easy to lose. It is the foundation swap.kiwi is built on. We ask you trust us. To help you in doing so we are…

Continue reading on Medium »
hacking: security in practice
Ethically beginning research on a particular site

I'm new to hacking, but even I know that there's probably something wrong with this one site I use. I'm not going to mention the exact organization for obvious reasons.

Basic recon (reading http headers) reveals they're using a pretty old version of server software, with plenty of potential RCE opportunities. I'm worried they're not keeping it updated, especially since they have my credit card information on their servers.

I want to start doing research on their behalf so my info doesn't get stolen. In short, I want to see if I can start hacking on the site. Naturally, I'd only try to access admin and my own account.

But I'm stuck even before that, because I want to notify them before I try. Suppose I just make attempts without informing them what's going on. They'll come to learn that a customer is trying to maliciously steal info, and legally I'd be dead to rights.

They're not sophisticated. I can't expect a bug bounty program. And I can't expect a warm reception if I just email them saying, "hey I wanna hack u but im a good guy lol".

What do?

submitted by /u/CavemanKnuckles
[link] [comments]
Account Takeover! Which companies don't accept

Hello everyone! 🎉Continue reading on Medium »
Read more...