Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
An 11 yr old did whaaat?

I'm not a hacker, but read this article and wanted to share it and ask...

At 11 yrs old, is it impressive that he was able to do this?

submitted by /u/J_Winn
[link] [comments]
Cumulus - Web Application Weakness Monitoring, It Would Be Working By Add Just 3 Codelines

Cumulus is a service that helps you monitor and fix security weakness in realtime. The issues will be reported on web dashboard. It's very simple and powerful.Key featuresJust install SDK to web front, can be found security weakness on serviceSDK detect weakness from Inner Layer, dinamically (ex DOM Event, XHR Request)Scanner detect weakness from Out Layer, statically (ex Crawl of web resources and analysis that)NameOriginDescriptionXSSSDKWhen user input a xss pattern string, trigger detection of XSSSQLInjectionSDKWhen user input a sqlinjection pattern, trigger detection of SQLInjectionSensitive PayloadSDKWhen requesting with sensitive payload. for example, unencoded raw passwordFile UploadSDKWhen user embed any file worried for system. for example, web shellUnnecessary CommentScannerCode comments are on the served HTML or JSDirectory TraversalScannerDetect directory listing vulnerabilityGuessingScannerDetect sensitive page like adminUnobfuscated CodeScannerDetect unobfuscated vulnerable codesIf you think about able to detect additional weakness, please contribute on SDK or ScannerCumulus SDK for JavaScriptThe official Cumulus SDK for JavaScript, providing as npmNote: current version is unsupported version on typescript project but we considering now and gonna make it, quickly! (#2)InstallationTo install a SDK, simply add package like belows:npm install --save https://github.com/tophat-cloud/cumulusyarn add https://github.com/tophat-cloud/cumulusSetup and usage of SDK always follow the same principle.import { protect, captureMessage } from 'cumulus';protect({ key: 'key',});captureMessage('Hello, world!');If you haven't _key_, please sign-up and create project to get to keyContentsOfficial SiteContributingChange logOpenSource LicenseDocumentsRoadmapResourcescumulus-scannercumulus-frontcumulus-backAuthor@Jinny You from TopHatDownload Cumulus
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Cumulus - Web Application Weakness Monitoring, It Would Be Working By Add Just 3 Codelines

https://blogger.googleusercontent.com/img/a/AVvXsEiB3Ua1ekVkgbUcGdmlO9uxDrvg7MbezEVGZiK2NtUUUXlT3bwCROhxK7E-_WDQo7M7Prqgyo40k9NgSmiQZNBoECBe_5ggsrL4PYcN79WsTIhJPYMYDVpiR19bxK8FNmAdLuusr_L_yErJvw7XeEi4u_TT1sRz_yXwAHkZWqYb4AyQ4rNBKpuILQVlXQ=w640-h160 Cumulus is a service that helps you monitor and fix security weakness in realtime. The issues will be reported on web dashboard. It's very simple and powerful. https://blogger.googleusercontent.com/img/a/AVvXsEgBxMl1d4soZ6kNreqa9QbaoPC--WSnb48nC12tyCR9zVE4CiiNsrtyq_IySeE7Ac16QDcoAreRPqpOHKUbW8fPJmN88Xv_qE_Gk0FTnsvUAAxv31kGQM7KRxYrPYqnKqGEgShrTQRead2cv_zPLOtK9Fra1PvihALO6aQEtymSSdHhhMcWj0vwKodfOg=w640-h346 https://blogger.googleusercontent.com/img/a/AVvXsEg9a7cUxancgqyoztEd9QDrLW8OdlcrS1GTNzH0aulR9BpDNT8v9ay4mF-sDCfX5ofk1it-fTX-AV7tL3JHP-jPBs0hUyaguuyatw0ztstUjwWr8d9ms3blvPZMS7Ua7AFlC_UY6NhWGnO2TMd0GOpmmA_jum6U7-oRpg_Xm8QRfywDNBUDBhJVlcHlpQ=w640-h266 https://blogger.googleusercontent.com/img/a/AVvXsEjywHth1c3tvIevjK4Xu5iVj5LYiFQZTE6oTt7nT60RA2VvijFJwKoPfQ7u8I7nyKs8eCoGPdR7Xr99yUj_zXR_MgJ1dosMIZLkuXeZzU9ZBkrmZAXijTQhob38A1itKTPXeWWHHPxcKWA-stxPq8gcYOClkCp8nSmWgrjIor_q6uUaTUaMh1XGJ45O5A=w640-h368 Key featuresJust install SDK to web front, can be found security weakness on service

* SDK detect weakness from Inner Layer, dinamically (ex_ DOM Event, XHR Request)
* Scanner detect weakness from Out Layer, statically (ex_ Crawl of web resources and analysis that)
NameOriginDescriptionXSSSDKWhen user input a xss pattern string, trigger detection of XSSSQLInjectionSDKWhen user input a sqlinjection pattern, trigger detection of SQLInjectionSensitive PayloadSDKWhen requesting with sensitive payload. for example, unencoded raw passwordFile UploadSDKWhen user embed any file worried for system. for example, web shellUnnecessary CommentScannerCode comments are on the served HTML or JSDirectory TraversalScannerDetect directory listing vulnerabilityGuessingScannerDetect sensitive page like adminUnobfuscated CodeScannerDetect unobfuscated vulnerable codes
If you think about able to detect additional weakness, please contribute on SDK or Scanner Cumulus SDK for JavaScriptThe official Cumulus SDK for JavaScript, providing as npm

Note: current version is unsupported version on typescript project but we considering now and gonna make it, quickly! (#2) InstallationTo install a SDK, simply add package like belows: npm install --save https://github.com/tophat-cloud/cumulus
yarn add https://github.com/tophat-cloud/cumulus
Setup and usage of SDK always follow the same principle. import { protect, captureMessage } from 'cumulus';

protect({
key: '__key__',
});

captureMessage('Hello, world!');
If you haven't __key__, please sign-up and create project to get to key Contents* Official Site
* Contributing
* Change log
* OpenSource License
* Documents
* Roadmap Resources* cumulus-scanner
* cumulus-front
* cumulus-back Author@Jinny You  from TopHat Download Cumulus Sent by @TheFeedReaderBot
hacking: security in practice
Possible Hack

Hi guys, I have an IPhone 12 and I think it is hacked because of it sent messages theatening a number from Monday to Friday.

I don´t think it is a virus because of it doesn´t send messages to multiple people, just one contact and it is a fluid conversation.

That said, it is hacked or it is a virus? And what is the best way to procceed?

Thank you in advance.

submitted by /u/Dunlain98
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Which better tool to crack password hashes.

For my ethical hacking assignment I’m required to crack two hashes to gain password into the desired VM to be able to pen test.

I’ve currently been taught JohnTheRipper and Hashcat, which would be best to crack a SHA256?

submitted by /u/fgtethancx
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Besside-ng problem: “bad beacon”

Hi all, im using kali linux on a virtual machine (VB) with a wifi adapter that’s compatible with linux. While running “airodump-ng wlan2” it works fine and i can see all the networks around me. Running “aireplay-ng —test wlan2” shows “Injection is working” and works fine. But when i try to run “besside-ng wlan2 -R ‘iPhone8’” (iPhone8 is my personal AP) i get “bad beacon”. As in: “scanning chan xx Bad beacon”

Because both aireplay and airodump are working, i have no idea why doesnt besside works.

Can anybody help me?

submitted by /u/guykehat
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video