hacking: security in practice
How to use tcpmux?
I found a service running on port 1 called tcpmux. I'd like to expolit it, but I found so little documentation online. Could you help me figure out how to use it?
submitted by /u/NatSpaghettiAgency
[link] [comments]
How to use tcpmux?
I found a service running on port 1 called tcpmux. I'd like to expolit it, but I found so little documentation online. Could you help me figure out how to use it?
submitted by /u/NatSpaghettiAgency
[link] [comments]
reddit
How to use tcpmux?
I found a service running on port 1 called *tcpmux.* I'd like to expolit it, but I found so little documentation online. Could you help me figure...
How can I directory brute force a reactive website with wildcard response
https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/
<!-- SC_OFF -->Hello, So I am trying to directory brute force this app which I think was developed with react native. All pages are the same size before they are rendered and the site has 200 HTTP response for all directories so I cannot rely on HTTP responses. What I am thinking is to develop/redevelop a tool the render the page and look at it's size after rendering. if I find a page that has a different size than the default home page, it means that this page is valid. I already found this dirbuster tool that filters based on response size: https://github.com/ickerwx/buster Please help, do you know if such tools exists? or is there a more clever way to do this? Thanks, <!-- SC_ON --> submitted by /u/q8shihab (https://www.reddit.com/user/q8shihab)
[link] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/) [comments] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/)
https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/
<!-- SC_OFF -->Hello, So I am trying to directory brute force this app which I think was developed with react native. All pages are the same size before they are rendered and the site has 200 HTTP response for all directories so I cannot rely on HTTP responses. What I am thinking is to develop/redevelop a tool the render the page and look at it's size after rendering. if I find a page that has a different size than the default home page, it means that this page is valid. I already found this dirbuster tool that filters based on response size: https://github.com/ickerwx/buster Please help, do you know if such tools exists? or is there a more clever way to do this? Thanks, <!-- SC_ON --> submitted by /u/q8shihab (https://www.reddit.com/user/q8shihab)
[link] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/) [comments] (https://www.reddit.com/r/Pentesting/comments/r3fyuy/how_can_i_directory_brute_force_a_reactive/)
OTP bypass with response manipulation.
Greetings, I wanted to share with you the OTP Bypass vulnerability that I found in a VDP.Continue reading on Medium »
Read more...
Greetings, I wanted to share with you the OTP Bypass vulnerability that I found in a VDP.Continue reading on Medium »
Read more...
OTP bypass with response manipulation.
https://ertugrull.medium.com/otp-bypass-with-response-manipulation-12646c6d7f33?source=rss------bug_bounty-5
https://ertugrull.medium.com/otp-bypass-with-response-manipulation-12646c6d7f33?source=rss------bug_bounty-5
Greetings, I wanted to share with you the OTP Bypass vulnerability that I found in a VDP.Continue reading on Medium » (https://ertugrull.medium.com/otp-bypass-with-response-manipulation-12646c6d7f33?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Geisha:1: Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/768/0*tVpwzO9swgho23fr.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
Geisha:1: Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/768/0*tVpwzO9swgho23fr.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Subdomain Enumeration of Onion sites
https://cdn-images-1.medium.com/max/1200/1*g9B0XD_-BpbBGaI6n99vyg.png
There are tools like gobuster and dirbuster which helps in subdomain enumeration of websites.
Continue reading on InfoSec Write-ups »
Subdomain Enumeration of Onion sites
https://cdn-images-1.medium.com/max/1200/1*g9B0XD_-BpbBGaI6n99vyg.png
There are tools like gobuster and dirbuster which helps in subdomain enumeration of websites.
Continue reading on InfoSec Write-ups »
hacking: security in practice
What are some of your early security mistakes?
For people who have built websites, apps, or other projects that required security, what mistakes did you make early on that you look back on and laugh about?
For me, the first thing that comes to mind is my forgetting to think about SQL injection in an app I made for a class project. Halfway through presenting it to the class, it was already hacked, and another kid in the class made themself an admin account.
submitted by /u/dragonfiremalus
[link] [comments]
What are some of your early security mistakes?
For people who have built websites, apps, or other projects that required security, what mistakes did you make early on that you look back on and laugh about?
For me, the first thing that comes to mind is my forgetting to think about SQL injection in an app I made for a class project. Halfway through presenting it to the class, it was already hacked, and another kid in the class made themself an admin account.
submitted by /u/dragonfiremalus
[link] [comments]
reddit
What are some of your early security mistakes?
For people who have built websites, apps, or other projects that required security, what mistakes did you make early on that you look back on and...
hacking: security in practice
Can virtualbox interfere with using hashcat with GPU ?
I’ve downloaded the relevant drivers for my GPU but im still unable to see it on kali, is it possible that the reason is that i use virtualbox?
If someone managed to run hashcat using his GPU on a kali in virtualbox i would really like to know
submitted by /u/guykehat
[link] [comments]
Can virtualbox interfere with using hashcat with GPU ?
I’ve downloaded the relevant drivers for my GPU but im still unable to see it on kali, is it possible that the reason is that i use virtualbox?
If someone managed to run hashcat using his GPU on a kali in virtualbox i would really like to know
submitted by /u/guykehat
[link] [comments]
reddit
Can virtualbox interfere with using hashcat with GPU ?
I’ve downloaded the relevant drivers for my GPU but im still unable to see it on kali, is it possible that the reason is that i use virtualbox?...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A new vulnerability in the OmniPod Insulin Management System allows an attacker nearby to schedule or immediately inject insulin
https://external-preview.redd.it/pYRBKJGjeO8W58bYixSajw6atnqq0aDaAt0v3i-4Zuo.jpg?width=640&crop=smart&auto=webp&s=bce34d5975e794523c9fdf8a945a259657f484e2 submitted by /u/CommanderHutli
[link] [comments]
A new vulnerability in the OmniPod Insulin Management System allows an attacker nearby to schedule or immediately inject insulin
https://external-preview.redd.it/pYRBKJGjeO8W58bYixSajw6atnqq0aDaAt0v3i-4Zuo.jpg?width=640&crop=smart&auto=webp&s=bce34d5975e794523c9fdf8a945a259657f484e2 submitted by /u/CommanderHutli
[link] [comments]
Cracken - A Fast Password Wordlist Generator, Smartlist Creation And Password Hybrid-Mask Analysis Tool
http://www.kitploit.com/2021/11/cracken-fast-password-wordlist.html
http://www.kitploit.com/2021/11/cracken-fast-password-wordlist.html
Cracken is a fast password wordlist generator, Smartlist creation and password hybrid-mask analysis tool written in pure safe Rust (more on talk/ (https://github.com/shmuelamar/cracken/blob/main/talk)). Inspired by great tools like maskprocessor (https://hashcat.net/wiki/doku.php?id=maskprocessor), hashcat (https://hashcat.net/), Crunch (https://github.com/crunchsec/crunch) and珞 HuggingFace's tokenizers (https://github.com/huggingface/tokenizers).
What? Why? Woot?? At DeepSec2021 (https://deepsec.net/speaker.html#PSLOT517) we presented a new method for analysing passwords as Hybrid-Masks exploiting (https://www.kitploit.com/search/label/Exploiting) common substrings in passwords by utilizing NLP tokenizers (more info on talk/ (https://github.com/shmuelamar/cracken/blob/main/talk)). Our method splits a password into its subwords instead of just a characters mask. HelloWorld123! splitted into ['Hello', 'World', '123!'] as these three subwords are very common in other passwords. Hybrid Masks & Smartlists Smartlists - Compact & representative subword lists created from passwords by utilizing NLP tokenizers Hybrid-Mask - A representation of a password as a combination of wordlists & characters (e.g. ?w1?w2?l?d) Analyzing RockYou Passwords (https://www.kitploit.com/search/label/Passwords) with Smartlists & Hybrid-Masks:
What? Why? Woot?? At DeepSec2021 (https://deepsec.net/speaker.html#PSLOT517) we presented a new method for analysing passwords as Hybrid-Masks exploiting (https://www.kitploit.com/search/label/Exploiting) common substrings in passwords by utilizing NLP tokenizers (more info on talk/ (https://github.com/shmuelamar/cracken/blob/main/talk)). Our method splits a password into its subwords instead of just a characters mask. HelloWorld123! splitted into ['Hello', 'World', '123!'] as these three subwords are very common in other passwords. Hybrid Masks & Smartlists Smartlists - Compact & representative subword lists created from passwords by utilizing NLP tokenizers Hybrid-Mask - A representation of a password as a combination of wordlists & characters (e.g. ?w1?w2?l?d) Analyzing RockYou Passwords (https://www.kitploit.com/search/label/Passwords) with Smartlists & Hybrid-Masks: