Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pentester Lab: S2–052 VM Walktrough
https://cdn-images-1.medium.com/max/1004/0*zMULv-3zz579X4if.png
Bu makinede bizlere Apache Struts 2 framework kullanan web sunucusunda uzakta komut çalıştırabildiğini(RCE) göstermektedir.
Continue reading on Medium »
Pentester Lab: S2–052 VM Walktrough
https://cdn-images-1.medium.com/max/1004/0*zMULv-3zz579X4if.png
Bu makinede bizlere Apache Struts 2 framework kullanan web sunucusunda uzakta komut çalıştırabildiğini(RCE) göstermektedir.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Karkinos — PenTest para Iniciantes
https://cdn-images-1.medium.com/max/628/0*g7BKEbY-Fm25tfkB.png
O Karkinos é uma ferramenta que esta em evolução e que ate o momento disponibiliza recursos que podem auxiliá-lo durante um PenTest ou em…
Continue reading on 100security »
Karkinos — PenTest para Iniciantes
https://cdn-images-1.medium.com/max/628/0*g7BKEbY-Fm25tfkB.png
O Karkinos é uma ferramenta que esta em evolução e que ate o momento disponibiliza recursos que podem auxiliá-lo durante um PenTest ou em…
Continue reading on 100security »
hacking: security in practice
Government Bug Bounty
Governments should provide Bug Bounty programs otherwise the hacker if they find a vulnerability has an incentive to sell the vulnerability to criminals.
A few months ago I did a post regarding the oil industry in america that was very successful in this section of reddit. Obviously it was a small vulnerability but I sent more than one email to cisa.gov and the problem was fixed only after months and no one from the US government thanked me.
Now I find myself to have found a very serious vulnerability that would allow a "solarwinds" multiplied by 10.
But in spite of my effort to do incessant research and study I am not rewarded.
Give me a computer and 15 hours of time and I find a serious vulnerability in some company. One small mistake, one capable person and solarwinds 2 will show up again.
Now imagine that someone walks into one of the 5 Big IT security companies that provide security software to government agencies and critical companies.
Selling a vulnerability in one of these companies to a hostile intelligence agency can make more than 10 million but can cause billions in damage.
Governments around the world think about it!
submitted by /u/LargeTrader
[link] [comments]
Government Bug Bounty
Governments should provide Bug Bounty programs otherwise the hacker if they find a vulnerability has an incentive to sell the vulnerability to criminals.
A few months ago I did a post regarding the oil industry in america that was very successful in this section of reddit. Obviously it was a small vulnerability but I sent more than one email to cisa.gov and the problem was fixed only after months and no one from the US government thanked me.
Now I find myself to have found a very serious vulnerability that would allow a "solarwinds" multiplied by 10.
But in spite of my effort to do incessant research and study I am not rewarded.
Give me a computer and 15 hours of time and I find a serious vulnerability in some company. One small mistake, one capable person and solarwinds 2 will show up again.
Now imagine that someone walks into one of the 5 Big IT security companies that provide security software to government agencies and critical companies.
Selling a vulnerability in one of these companies to a hostile intelligence agency can make more than 10 million but can cause billions in damage.
Governments around the world think about it!
submitted by /u/LargeTrader
[link] [comments]
reddit
Government Bug Bounty
Governments should provide Bug Bounty programs otherwise the hacker if they find a vulnerability has an incentive to sell the vulnerability to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
FBI email system reportedly hacked to send fake DHS cyberattack messages
https://external-preview.redd.it/6iwPiFsbsZQOQI3JbftaSyL3FxwvDwI1fJ2ygtZ8Hug.jpg?width=640&crop=smart&auto=webp&s=3337ec3b578ffa62ff97c3a75b6c201ccdc91094 submitted by /u/DrinkMoreCodeMore
[link] [comments]
FBI email system reportedly hacked to send fake DHS cyberattack messages
https://external-preview.redd.it/6iwPiFsbsZQOQI3JbftaSyL3FxwvDwI1fJ2ygtZ8Hug.jpg?width=640&crop=smart&auto=webp&s=3337ec3b578ffa62ff97c3a75b6c201ccdc91094 submitted by /u/DrinkMoreCodeMore
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What are some essentials to keep on a hardrive
Other than a bootable image and wordlists what else should a person keep on a hardrive
submitted by /u/Background_Gene_3657
[link] [comments]
What are some essentials to keep on a hardrive
Other than a bootable image and wordlists what else should a person keep on a hardrive
submitted by /u/Background_Gene_3657
[link] [comments]
reddit
What are some essentials to keep on a hardrive
Other than a bootable image and wordlists what else should a person keep on a hardrive
hacking: security in practice
How long would it take to crack a password thats just numbers and Capital letters
With a shitty a gpu and cup of course. For a wpa2 wifi pass
submitted by /u/newearth420
[link] [comments]
How long would it take to crack a password thats just numbers and Capital letters
With a shitty a gpu and cup of course. For a wpa2 wifi pass
submitted by /u/newearth420
[link] [comments]
reddit
How long would it take to crack a password thats just numbers and...
With a shitty a gpu and cup of course. For a wpa2 wifi pass
TakeOver Path Directory Public/NonPublic Via Non-Validated Input Username Profile URL
https://aidilarf.medium.com/takeover-path-directory-public-nonpublic-via-non-validated-input-username-profile-url-f4f291d63af?source=rss------bug_bounty-5
https://aidilarf.medium.com/takeover-path-directory-public-nonpublic-via-non-validated-input-username-profile-url-f4f291d63af?source=rss------bug_bounty-5
Assalamualaikum Bug Hunter & Hi EveryoneContinue reading on Medium » (https://aidilarf.medium.com/takeover-path-directory-public-nonpublic-via-non-validated-input-username-profile-url-f4f291d63af?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Android Device Hacking
https://cdn-images-1.medium.com/max/1024/0*GYLxRYltYyLkiqti.jpg
A backdoor is a typically covert method of bypassing normal authentication or encryption in a computer,android, embedded device.
Continue reading on Medium »
Android Device Hacking
https://cdn-images-1.medium.com/max/1024/0*GYLxRYltYyLkiqti.jpg
A backdoor is a typically covert method of bypassing normal authentication or encryption in a computer,android, embedded device.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is phishing? What is phishing hacking?
https://cdn-images-1.medium.com/max/2440/0*b3EjGXdkYlH1MDpG
Phishing is an example of a strategy called social engineering. Trapped in this strategy, you can lose a lot of valuable information. For…
Continue reading on Medium »
What is phishing? What is phishing hacking?
https://cdn-images-1.medium.com/max/2440/0*b3EjGXdkYlH1MDpG
Phishing is an example of a strategy called social engineering. Trapped in this strategy, you can lose a lot of valuable information. For…
Continue reading on Medium »