Cannot connect from Kali to Metasploitable 2
https://www.reddit.com/r/Pentesting/comments/rc6q3h/cannot_connect_from_kali_to_metasploitable_2/
Hello! I have a MacBook apple m1.
I have a Kali installed on VMware fusion. I also have a Metasploitable installed on UTM. I try to use NMAP to scan ports, but I get such a message: Host discovery disabled (-Pn). All 1000 scanned ports on IP_ADDRESS are filtered. I disabled firewall on metasploitable, but the problems still exists. Can you help me please? submitted by /u/vitalib (https://www.reddit.com/user/vitalib)
[link] (https://www.reddit.com/r/Pentesting/comments/rc6q3h/cannot_connect_from_kali_to_metasploitable_2/) [comments] (https://www.reddit.com/r/Pentesting/comments/rc6q3h/cannot_connect_from_kali_to_metasploitable_2/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/rc6q3h/cannot_connect_from_kali_to_metasploitable_2/
Hello! I have a MacBook apple m1.
I have a Kali installed on VMware fusion. I also have a Metasploitable installed on UTM. I try to use NMAP to scan ports, but I get such a message: Host discovery disabled (-Pn). All 1000 scanned ports on IP_ADDRESS are filtered. I disabled firewall on metasploitable, but the problems still exists. Can you help me please? submitted by /u/vitalib (https://www.reddit.com/user/vitalib)
[link] (https://www.reddit.com/r/Pentesting/comments/rc6q3h/cannot_connect_from_kali_to_metasploitable_2/) [comments] (https://www.reddit.com/r/Pentesting/comments/rc6q3h/cannot_connect_from_kali_to_metasploitable_2/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cannot connect from Kali to Metasploitable 2
Hello! I have a MacBook apple m1. I have a Kali installed on VMware fusion. I also have a Metasploitable installed on UTM. I try to use NMAP...
Questions for full-time pentesters
https://www.reddit.com/r/Pentesting/comments/rc6wkk/questions_for_fulltime_pentesters/
I'm considering a career in pentesting full-time and was hoping to pick the brain of someone already there. I'm currently handling small-scale pentesting and micro red-team exercises for my organization and generally enjoy the work. My only real hangup on that side of the job is trying to convince infra or non-IT teams to actually take issues seriously (getting better but we have a long way to go). We contract with 3rd party pentesting companies for full internal, external, and physical audits and until recently (when other paths have arisen) I envisioned my next move to be to one of these external companies. I have a few questions for those who are already in this position (feel free to PM answers if you don't want to reply publicly): What is your typical day like? Given that some orgs may have strict windows to perform tests, do you often find yourself working odd hours? What is your work/ life balance like? What do you see as the next step in your career? What do you like most about the job? What do you like the least? Thanks in advance! submitted by /u/shatnote (https://www.reddit.com/user/shatnote)
[link] (https://www.reddit.com/r/Pentesting/comments/rc6wkk/questions_for_fulltime_pentesters/) [comments] (https://www.reddit.com/r/Pentesting/comments/rc6wkk/questions_for_fulltime_pentesters/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/rc6wkk/questions_for_fulltime_pentesters/
I'm considering a career in pentesting full-time and was hoping to pick the brain of someone already there. I'm currently handling small-scale pentesting and micro red-team exercises for my organization and generally enjoy the work. My only real hangup on that side of the job is trying to convince infra or non-IT teams to actually take issues seriously (getting better but we have a long way to go). We contract with 3rd party pentesting companies for full internal, external, and physical audits and until recently (when other paths have arisen) I envisioned my next move to be to one of these external companies. I have a few questions for those who are already in this position (feel free to PM answers if you don't want to reply publicly): What is your typical day like? Given that some orgs may have strict windows to perform tests, do you often find yourself working odd hours? What is your work/ life balance like? What do you see as the next step in your career? What do you like most about the job? What do you like the least? Thanks in advance! submitted by /u/shatnote (https://www.reddit.com/user/shatnote)
[link] (https://www.reddit.com/r/Pentesting/comments/rc6wkk/questions_for_fulltime_pentesters/) [comments] (https://www.reddit.com/r/Pentesting/comments/rc6wkk/questions_for_fulltime_pentesters/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/Pentesting on Reddit: Questions for full-time pentesters
Posted by u/shatnote - 17 votes and 31 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
16 Tips to keep your code safe from hackers
https://cdn-images-1.medium.com/max/600/1*fmAauC93xDnFBvh51v7e6g.jpeg
Is your code secure?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
16 Tips to keep your code safe from hackers
https://cdn-images-1.medium.com/max/600/1*fmAauC93xDnFBvh51v7e6g.jpeg
Is your code secure?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
16 Tips to keep your code safe from hackers
Is your code secure?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
GoDaddy Just Got Hacked (again) — How and Why Did that Happen?
https://cdn-images-1.medium.com/max/1200/1*D8-NuNQlPIIunwBJThOXow.jpeg
GoDaddy was founded by Bob Parsons in 1997 and is an internet domain register as well as a web hosting company. GoDaddy has over 20…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
GoDaddy Just Got Hacked (again) — How and Why Did that Happen?
https://cdn-images-1.medium.com/max/1200/1*D8-NuNQlPIIunwBJThOXow.jpeg
GoDaddy was founded by Bob Parsons in 1997 and is an internet domain register as well as a web hosting company. GoDaddy has over 20…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
GoDaddy Just Got Hacked (again) — How and Why Did that Happen?
GoDaddy was founded by Bob Parsons in 1997 and is an internet domain register as well as a web hosting company. GoDaddy has over 20…
hacking: security in practice
I started a cyber security club today and .
So I am freshman in my college. I leave In India so most of the people don't know how to be secure in the internet so me and 2 of my friends started a cyber security club today. We announced to students. We were not expecting. Much students to join but now there are over 65 students in the group registered. We don't know how to move forward from here. We planed to do stuff for 15 to 20 students. Please help me. Anyone.
submitted by /u/just_call_me_n_u
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I started a cyber security club today and .
So I am freshman in my college. I leave In India so most of the people don't know how to be secure in the internet so me and 2 of my friends started a cyber security club today. We announced to students. We were not expecting. Much students to join but now there are over 65 students in the group registered. We don't know how to move forward from here. We planed to do stuff for 15 to 20 students. Please help me. Anyone.
submitted by /u/just_call_me_n_u
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I started a cyber security club today and .
So I am freshman in my college. I leave In India so most of the people don't know how to be secure in the internet so me and 2 of my friends...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Spectrum Wifi Wordlist
Doing a bit of research, I noticed that Spectrum default passwords use a very simple format: (first word)(second word)(three digit number).
I wanted to avoid a brute force attack because there would be a lot of variations that wouldn't fit the format. Instead, I downloaded the words.txt list from here, then did some manipulation to the data.
First, I want to trim down the list. There are a lot of compound words, abbreviations, and possessives that should not be included. I also want to exclude words with fewer than 4 characters or more than 9.
Next, we need to add each word to every other word, and append every possible 3-digit number to the end. This will be an exponentially longer list, but saves any masking needed later.
PowerShell is my most fluent language, so I used it here. It seems to work well. I'm sure there are much more elegant ways to get the job done, but I wanted to share with anyone else that might be able to use it.
The resulting spectrum.txt file should be able to crack most Spectrum default passwords.
submitted by /u/EncodingLastingOgre
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Spectrum Wifi Wordlist
Doing a bit of research, I noticed that Spectrum default passwords use a very simple format: (first word)(second word)(three digit number).
I wanted to avoid a brute force attack because there would be a lot of variations that wouldn't fit the format. Instead, I downloaded the words.txt list from here, then did some manipulation to the data.
First, I want to trim down the list. There are a lot of compound words, abbreviations, and possessives that should not be included. I also want to exclude words with fewer than 4 characters or more than 9.
Next, we need to add each word to every other word, and append every possible 3-digit number to the end. This will be an exponentially longer list, but saves any masking needed later.
PowerShell is my most fluent language, so I used it here. It seems to work well. I'm sure there are much more elegant ways to get the job done, but I wanted to share with anyone else that might be able to use it.
$words = Get-Content .\words.txt foreach ($word in $words){ if (($word.contains("-")) -or $word.contains(".") -or $word.contains("'") -or ($word.length) -lt 4 -or ($word.length) -gt 9){ Write-Host Tossing $word -ForegroundColor Red } else { Write-Host Keeping $word -ForegroundColor Green $word | Out-File words2.txt -Append } } #----------------------------- $words = Get-Content .\words2.txt [int]$steps = ($words | Measure-Object).Count [int]$stepCounter = 0 $nums = (100..999) foreach ($1word in $words){ Write-Progress -Activity 'Writing' -Status "Outputting variations of $1word" -PercentComplete ((($stepCounter++) / $steps) * 100) $baseword = $1word foreach ($2word in $words){ $outword = $baseword.ToLower() + $2word.ToLower() foreach ($num in $nums){ $result = $outword + $num $result | Out-File spectrum.txt -Append } } } The resulting spectrum.txt file should be able to crack most Spectrum default passwords.
submitted by /u/EncodingLastingOgre
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/hacking - Spectrum Wifi Wordlist
87 votes and 33 comments so far on Reddit
hacking: security in practice
Apache CXF and WADL file exploits
Hello, during an engagement I've uncovered an endpoint that returns a WADL file. It appears to be a pretty important endpoint, possibly handling sensitive information. Also confirmed that it's running CXF although I'm not sure what version. After some research I've found that WADL is similar to Swagger, so I downloaded the WADL file and loaded it into Soap-UI but haven't really figured out anything interesting there. However, I did notice one thing: the subdomain responds with 'unauthorized', except for the endpoint with the WADL file. This leads me to believe that there is no authorization/authentication involved when viewing the WADL file, where there probably should be. Is this worth reporting, and/or can I escalate the impact here? Any advice would be appreciated, as I am not familiar with WADL or Apache CXF, and I can post more details if needed. Thanks.
PS: also might be running JAXRS but haven't confirmed yet.
submitted by /u/Honest_Pension_2245
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Apache CXF and WADL file exploits
Hello, during an engagement I've uncovered an endpoint that returns a WADL file. It appears to be a pretty important endpoint, possibly handling sensitive information. Also confirmed that it's running CXF although I'm not sure what version. After some research I've found that WADL is similar to Swagger, so I downloaded the WADL file and loaded it into Soap-UI but haven't really figured out anything interesting there. However, I did notice one thing: the subdomain responds with 'unauthorized', except for the endpoint with the WADL file. This leads me to believe that there is no authorization/authentication involved when viewing the WADL file, where there probably should be. Is this worth reporting, and/or can I escalate the impact here? Any advice would be appreciated, as I am not familiar with WADL or Apache CXF, and I can post more details if needed. Thanks.
PS: also might be running JAXRS but haven't confirmed yet.
submitted by /u/Honest_Pension_2245
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Apache CXF and WADL file exploits
Hello, during an engagement I've uncovered an endpoint that returns a WADL file. It appears to be a pretty important endpoint, possibly handling...
hacking: security in practice
Is there a way to create an auto executable file by setting a timer?
Hi im not from computer science department but i had a curiosity to know if hackers can create an autoexecutble file by putting sort of timer in it and push it inside a network to infiltrate pcs. For example last year i was hosting a team viewer connection and helping out a friend with some stuff and it got attacked by different forms viruses encrypting every file and we didnt even know first hour of it. I didnt click any dot exe or script file but still this happened.
submitted by /u/dorm_supervisor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there a way to create an auto executable file by setting a timer?
Hi im not from computer science department but i had a curiosity to know if hackers can create an autoexecutble file by putting sort of timer in it and push it inside a network to infiltrate pcs. For example last year i was hosting a team viewer connection and helping out a friend with some stuff and it got attacked by different forms viruses encrypting every file and we didnt even know first hour of it. I didnt click any dot exe or script file but still this happened.
submitted by /u/dorm_supervisor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there a way to create an auto executable file by setting a timer?
Hi im not from computer science department but i had a curiosity to know if hackers can create an autoexecutble file by putting sort of timer in...
Discovering File Inclusion Vulnerabilities
https://medium.com/@kaorrosi/discovering-file-inclusion-vulnerabilities-91aa9aede6d8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@kaorrosi/discovering-file-inclusion-vulnerabilities-91aa9aede6d8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Discovering File Inclusion Vulnerabilities
Covering what I’ve learned completing TryHackMe’s file inclusion room in their Junior Penetration Tester learning path and their 6th…
Covering what I’ve learned completing TryHackMe’s file inclusion room in their Junior Penetration Tester learning path and their 6th…Continue reading on Medium » (https://medium.com/@kaorrosi/discovering-file-inclusion-vulnerabilities-91aa9aede6d8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Discovering File Inclusion Vulnerabilities
Covering what I’ve learned completing TryHackMe’s file inclusion room in their Junior Penetration Tester learning path and their 6th…
Exploiting S3 bucket with path folder to Access PII info of A BANK
https://notifybugme.medium.com/exploiting-s3-bucket-with-path-folder-to-access-pii-info-of-a-bank-91d8563cb45?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://notifybugme.medium.com/exploiting-s3-bucket-with-path-folder-to-access-pii-info-of-a-bank-91d8563cb45?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Exploiting S3 bucket with path folder to Access PII info of A BANK
Hi, everyone
Hi, everyoneContinue reading on Medium » (https://notifybugme.medium.com/exploiting-s3-bucket-with-path-folder-to-access-pii-info-of-a-bank-91d8563cb45?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Exploiting S3 bucket with path folder to Access PII info of A BANK
Hi, everyone
Discovering File Inclusion Vulnerabilities
Covering what I’ve learned completing TryHackMe’s file inclusion room in their Junior Penetration Tester learning path and their 6th…Continue reading on Medium »
Read more...
Covering what I’ve learned completing TryHackMe’s file inclusion room in their Junior Penetration Tester learning path and their 6th…Continue reading on Medium »
Read more...
Exploiting S3 bucket with path folder to Access PII info of A BANK
Hi, everyoneContinue reading on Medium »
Read more...
Hi, everyoneContinue reading on Medium »
Read more...