Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe | Meltdown Explained WriteUp
This room explains the technical details behind the Meltdown vulnerability.
Continue reading on Medium »
TryHackMe | Meltdown Explained WriteUp
This room explains the technical details behind the Meltdown vulnerability.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ethical Hacker: Una novela hacker por entregas
https://cdn-images-1.medium.com/max/688/1*TLcpmoKvnudkGoGHHxmVAQ.jpeg
Hace algunos años empecé a escribir una novela.
Mi idea era condensar toda la experiencia que había ganado tras años de trabajo en…
Continue reading on Medium »
Ethical Hacker: Una novela hacker por entregas
https://cdn-images-1.medium.com/max/688/1*TLcpmoKvnudkGoGHHxmVAQ.jpeg
Hace algunos años empecé a escribir una novela.
Mi idea era condensar toda la experiencia que había ganado tras años de trabajo en…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best Computer Hacking Forensic Investigator Training Provider — CHFI
https://cdn-images-1.medium.com/max/1080/1*tFuNZqWWf131Lqn1XJDevQ.png
We’re all aware of the cyberwar and how it might disrupt our everyday life by now — these complex cyber-attacks necessitate cutting-edge…
Continue reading on Medium »
Best Computer Hacking Forensic Investigator Training Provider — CHFI
https://cdn-images-1.medium.com/max/1080/1*tFuNZqWWf131Lqn1XJDevQ.png
We’re all aware of the cyberwar and how it might disrupt our everyday life by now — these complex cyber-attacks necessitate cutting-edge…
Continue reading on Medium »
hacking: security in practice
Cracking firefox's logins.json without key4.db
I apologize if this is the wrong forum for this query, if it is, I would appreciate a point in the right direction.
I pulled a stupid and lost all my passwords. When I recovered the data, I ended up with a corrupted key4 AND logins. So, the conventional method of importing them did not work.
Is it possible to decrypt/crack this stuff? Below is a sample of the file for reference (this is a throwaway account):
I do have the vast majority of these usernames and passwords memorized and could provide them to whatever tool you would recommend. I also know the first three characters of the password I am looking for are, if that helps at all.
Again, I apologize. You guys are my next to last best hope. I am going to dig around a few more backup hard drives I have scattered around and see if I can find a more UTD password list, but I really don't think it is going to happen.
submitted by /u/GoldenSheppard
[link] [comments]
Cracking firefox's logins.json without key4.db
I apologize if this is the wrong forum for this query, if it is, I would appreciate a point in the right direction.
I pulled a stupid and lost all my passwords. When I recovered the data, I ended up with a corrupted key4 AND logins. So, the conventional method of importing them did not work.
Is it possible to decrypt/crack this stuff? Below is a sample of the file for reference (this is a throwaway account):
{"id":150,"hostname":"https://users.nexusmods.com","httpRealm":null,"formSubmitURL":"https://users.nexusmods.com","usernameField":"user[login]","passwordField":"user[password]","encryptedUsername":"MDoEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECDxrRGLf9XMXBBCTfI22DCPUnYr3ivgM6elY","encryptedPassword":"MDoEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECPLfp5/hpm6EBBAYeLQjs2RZraIf/cR4EjbA","guid":"{1c0f92d3-8a31-4deb-b44a-c999fdb3fa5f}","encType":1,"timeCreated":1609418603412,"timeLastUsed":1630008337192,"timePasswordChanged":1609418603412,"timesUsed":2},{"id":151,"hostname":"https://users.nexusmods.com","httpRealm":null,"formSubmitURL":"https://users.nexusmods.com","usernameField":"user[login]","passwordField":"user[password]","encryptedUsername":"MDoEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECHgxbO45Tmo4BBCXmO+ytMScmHcuiM+swXrT","encryptedPassword":"MDoEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECHXvzvtvaue+BBCUJoXRCqBgapdR6iwe5pGs","guid":"{496479ca-d70a-45ea-9a96-5b8898b55051}","encType":1,"timeCreated":1625539401166,"timeLastUsed":1630008331273,"timePasswordChanged":1625539401166,"timesUsed":2} I do have the vast majority of these usernames and passwords memorized and could provide them to whatever tool you would recommend. I also know the first three characters of the password I am looking for are, if that helps at all.
Again, I apologize. You guys are my next to last best hope. I am going to dig around a few more backup hard drives I have scattered around and see if I can find a more UTD password list, but I really don't think it is going to happen.
submitted by /u/GoldenSheppard
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
CMS Hacking
anyone who can hack a cms portal? paid job
submitted by /u/neymi11
[link] [comments]
CMS Hacking
anyone who can hack a cms portal? paid job
submitted by /u/neymi11
[link] [comments]
reddit
CMS Hacking
anyone who can hack a cms portal? paid job
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
FakeDataGen - Full Valid Fake Data Generator
https://blogger.googleusercontent.com/img/a/AVvXsEi_aNGiFQS7kwrNM9yFUnt8W1nCISt7TQabpZ2xCIE5h_XinRLOJZ3rfwZmI0aC5UQAn2LrvrrH3zOc5HMysZMyuGPjbwgeXkAmc_1z5Dbu_pA9YP7PvTYiaASrPlYWw8fW5dB6hW-NyKppr8xJgGraDV6YXUR2p4bX1Oy31DGPhMLIr4Qh8ZxE9tg_lQ=w640-h440
FakeDataGen is a Full Valid Fake Data Generator.
This tool helps you to create fake accounts (in Spanish format) with fully valid data. Within this information, you can find the most common names, emails, bank details and other useful information.
Requirements
* Python 3
* Install requirements.txt
Download
It is recommended to clone the complete repository or download the zip file. You can do this by running the following command:
Usage
The detailed guide of use can be found at the following link:
https://darkbyte.net/generando-datos-falsos-con-fakedatagen
License
This project is licensed under the GNU 3.0 license - see the LICENSE file for more details.
Credits and Acknowledgments
This script has been created and designed from scratch by Joel Gámez Molina // @JoelGMSec
Contact
This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it.
For more information, you can find me on Twitter as @JoelGMSec and on my blog darkbyte.net.
Download FakeDataGen
FakeDataGen - Full Valid Fake Data Generator
https://blogger.googleusercontent.com/img/a/AVvXsEi_aNGiFQS7kwrNM9yFUnt8W1nCISt7TQabpZ2xCIE5h_XinRLOJZ3rfwZmI0aC5UQAn2LrvrrH3zOc5HMysZMyuGPjbwgeXkAmc_1z5Dbu_pA9YP7PvTYiaASrPlYWw8fW5dB6hW-NyKppr8xJgGraDV6YXUR2p4bX1Oy31DGPhMLIr4Qh8ZxE9tg_lQ=w640-h440
FakeDataGen is a Full Valid Fake Data Generator.
This tool helps you to create fake accounts (in Spanish format) with fully valid data. Within this information, you can find the most common names, emails, bank details and other useful information.
Requirements
* Python 3
* Install requirements.txt
Download
It is recommended to clone the complete repository or download the zip file. You can do this by running the following command:
git clone https://github.com/JoelGMSec/FakeDataGen
Usage
./FakeDataGen.py -h
_____ _ ____ _ ____
| ___|_ _| | _ ___| _ \ __ _| |_ __ _ / ___| ___ _ __
| |_ / _` | |/ / _ \ | | |/ _` | __/ _` | | _ / _ \ '_ \
| _| (_| | < __/ |_| | (_| | || (_| | |_| | __/ | | |
|_| \__,_|_|\_\___|____/ \__,_|\__\__,_|\____|\___|_| |_|
-------------------- by @JoelGMSec ---------------------
usage: FakeDataGen.py [-h] [-n NUMBER] [-b] [-e] [-f FILE] [-z] [-p PASSWORD]
optional arguments:
-h, --help show this help message and exit
-n NUMBER, --number NUMBER
The number of records should be created
-b, --bankdata Show only bank data (Card, CVV, IBAN..)
-e, --extended Show only extended info (City, Phone, SS..)
-f FILE, --file FILE File path to save data
-z, --zip Compress data to zip file
-p PASSWORD, --password PASSWORD
Password to protect zip file
The detailed guide of use can be found at the following link:
https://darkbyte.net/generando-datos-falsos-con-fakedatagen
License
This project is licensed under the GNU 3.0 license - see the LICENSE file for more details.
Credits and Acknowledgments
This script has been created and designed from scratch by Joel Gámez Molina // @JoelGMSec
Contact
This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it.
For more information, you can find me on Twitter as @JoelGMSec and on my blog darkbyte.net.
Download FakeDataGen
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SQL Injection Saldırıları
https://cdn-images-1.medium.com/max/640/1*P4f-Ep_XB2Fsyxh330YFIQ.jpeg
SQL injection ile websitesinin veritabanına sızma…
Continue reading on Medium »
SQL Injection Saldırıları
https://cdn-images-1.medium.com/max/640/1*P4f-Ep_XB2Fsyxh330YFIQ.jpeg
SQL injection ile websitesinin veritabanına sızma…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SQL Injection Attacks
https://cdn-images-1.medium.com/max/640/1*P4f-Ep_XB2Fsyxh330YFIQ.jpeg
Before saying what is SQL injection, let’s look at what is SQL
Continue reading on Medium »
SQL Injection Attacks
https://cdn-images-1.medium.com/max/640/1*P4f-Ep_XB2Fsyxh330YFIQ.jpeg
Before saying what is SQL injection, let’s look at what is SQL
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Still Getting Hacked
https://cdn-images-1.medium.com/max/1305/1*TPKUjqQ310RYHWk4WUFXHg.png
But the insurgency is free to roam, kill, loot, pillage, fully funded! UN Human Rights Amnesty International Library of Congress TIME Nat…
Continue reading on Medium »
Still Getting Hacked
https://cdn-images-1.medium.com/max/1305/1*TPKUjqQ310RYHWk4WUFXHg.png
But the insurgency is free to roam, kill, loot, pillage, fully funded! UN Human Rights Amnesty International Library of Congress TIME Nat…
Continue reading on Medium »
hacking: security in practice
Reverse Email Lookup
Is there a way to find out, for free, who owns an email address? I got an email from someone at work explaining they can’t connect remotely. It’s not from a corporate email but it was someone’s personal email (yahoo account).
submitted by /u/PowerCaddy14
[link] [comments]
Reverse Email Lookup
Is there a way to find out, for free, who owns an email address? I got an email from someone at work explaining they can’t connect remotely. It’s not from a corporate email but it was someone’s personal email (yahoo account).
submitted by /u/PowerCaddy14
[link] [comments]
reddit
Reverse Email Lookup
Is there a way to find out, for free, who owns an email address? I got an email from someone at work explaining they can’t connect remotely. It’s...
hacking: security in practice
How to use tcpmux?
I found a service running on port 1 called tcpmux. I'd like to expolit it, but I found so little documentation online. Could you help me figure out how to use it?
submitted by /u/NatSpaghettiAgency
[link] [comments]
How to use tcpmux?
I found a service running on port 1 called tcpmux. I'd like to expolit it, but I found so little documentation online. Could you help me figure out how to use it?
submitted by /u/NatSpaghettiAgency
[link] [comments]
reddit
How to use tcpmux?
I found a service running on port 1 called *tcpmux.* I'd like to expolit it, but I found so little documentation online. Could you help me figure...
How can I directory brute force a reactive website with wildcard response
https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/
<!-- SC_OFF -->Hello, So I am trying to directory brute force this app which I think was developed with react native. All pages are the same size before they are rendered and the site has 200 HTTP response for all directories so I cannot rely on HTTP responses. What I am thinking is to develop/redevelop a tool the render the page and look at it's size after rendering. if I find a page that has a different size than the default home page, it means that this page is valid. I already found this dirbuster tool that filters based on response size: https://github.com/ickerwx/buster Please help, do you know if such tools exists? or is there a more clever way to do this? Thanks, <!-- SC_ON --> submitted by /u/q8shihab (https://www.reddit.com/user/q8shihab)
[link] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/) [comments] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/)
https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/
<!-- SC_OFF -->Hello, So I am trying to directory brute force this app which I think was developed with react native. All pages are the same size before they are rendered and the site has 200 HTTP response for all directories so I cannot rely on HTTP responses. What I am thinking is to develop/redevelop a tool the render the page and look at it's size after rendering. if I find a page that has a different size than the default home page, it means that this page is valid. I already found this dirbuster tool that filters based on response size: https://github.com/ickerwx/buster Please help, do you know if such tools exists? or is there a more clever way to do this? Thanks, <!-- SC_ON --> submitted by /u/q8shihab (https://www.reddit.com/user/q8shihab)
[link] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/) [comments] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/)
OTP bypass with response manipulation.
Greetings, I wanted to share with you the OTP Bypass vulnerability that I found in a VDP.Continue reading on Medium »
Read more...
Greetings, I wanted to share with you the OTP Bypass vulnerability that I found in a VDP.Continue reading on Medium »
Read more...