Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.2K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Reverse Email Lookup

Is there a way to find out, for free, who owns an email address? I got an email from someone at work explaining they can’t connect remotely. It’s not from a corporate email but it was someone’s personal email (yahoo account).

submitted by /u/PowerCaddy14
[link] [comments]
hacking: security in practice
How to use tcpmux?

I found a service running on port 1 called tcpmux. I'd like to expolit it, but I found so little documentation online. Could you help me figure out how to use it?

submitted by /u/NatSpaghettiAgency
[link] [comments]
How can I directory brute force a reactive website with wildcard response
https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/

<!-- SC_OFF -->Hello, So I am trying to directory brute force this app which I think was developed with react native. All pages are the same size before they are rendered and the site has 200 HTTP response for all directories so I cannot rely on HTTP responses. What I am thinking is to develop/redevelop a tool the render the page and look at it's size after rendering. if I find a page that has a different size than the default home page, it means that this page is valid. I already found this dirbuster tool that filters based on response size: https://github.com/ickerwx/buster Please help, do you know if such tools exists? or is there a more clever way to do this? Thanks, <!-- SC_ON --> submitted by /u/q8shihab (https://www.reddit.com/user/q8shihab)
[link] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/) [comments] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/)
OTP bypass with response manipulation.

Greetings, I wanted to share with you the OTP Bypass vulnerability that I found in a VDP.Continue reading on Medium »
Read more...
Greetings, I wanted to share with you the OTP Bypass vulnerability that I found in a VDP.Continue reading on Medium » (https://ertugrull.medium.com/otp-bypass-with-response-manipulation-12646c6d7f33?source=rss------bug_bounty-5)
hacking: security in practice
What are some of your early security mistakes?

For people who have built websites, apps, or other projects that required security, what mistakes did you make early on that you look back on and laugh about?

For me, the first thing that comes to mind is my forgetting to think about SQL injection in an app I made for a class project. Halfway through presenting it to the class, it was already hacked, and another kid in the class made themself an admin account.

submitted by /u/dragonfiremalus
[link] [comments]
hacking: security in practice
Can virtualbox interfere with using hashcat with GPU ?

I’ve downloaded the relevant drivers for my GPU but im still unable to see it on kali, is it possible that the reason is that i use virtualbox?

If someone managed to run hashcat using his GPU on a kali in virtualbox i would really like to know

submitted by /u/guykehat
[link] [comments]
Cracken - A Fast Password Wordlist Generator, Smartlist Creation And Password Hybrid-Mask Analysis Tool
http://www.kitploit.com/2021/11/cracken-fast-password-wordlist.html