Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Apache CXF and WADL file exploits

Hello, during an engagement I've uncovered an endpoint that returns a WADL file. It appears to be a pretty important endpoint, possibly handling sensitive information. Also confirmed that it's running CXF although I'm not sure what version. After some research I've found that WADL is similar to Swagger, so I downloaded the WADL file and loaded it into Soap-UI but haven't really figured out anything interesting there. However, I did notice one thing: the subdomain responds with 'unauthorized', except for the endpoint with the WADL file. This leads me to believe that there is no authorization/authentication involved when viewing the WADL file, where there probably should be. Is this worth reporting, and/or can I escalate the impact here? Any advice would be appreciated, as I am not familiar with WADL or Apache CXF, and I can post more details if needed. Thanks.

PS: also might be running JAXRS but haven't confirmed yet.

submitted by /u/Honest_Pension_2245
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there a way to create an auto executable file by setting a timer?

Hi im not from computer science department but i had a curiosity to know if hackers can create an autoexecutble file by putting sort of timer in it and push it inside a network to infiltrate pcs. For example last year i was hosting a team viewer connection and helping out a friend with some stuff and it got attacked by different forms viruses encrypting every file and we didnt even know first hour of it. I didnt click any dot exe or script file but still this happened.

submitted by /u/dorm_supervisor
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Discovering File Inclusion Vulnerabilities

Covering what I’ve learned completing TryHackMe’s file inclusion room in their Junior Penetration Tester learning path and their 6th…Continue reading on Medium »
Read more...
Exploiting S3 bucket with path folder to Access PII info of A BANK

Hi, everyoneContinue reading on Medium »
Read more...
hacking: security in practice
Gamehacking tips.

I've always been really intersted in gamehacking. When I was a kid I was doing pokemon ROM hacks off the internet etc.

I've been going through game-hacking by Nick Cano. From what I've read, the main points are to know assembly and how memory works. I can kinda use Cheatengine and Ollydb now, and understand how to insert shellcode into toy games. I figure it'd be a good way to brush up on these for other areas of CS as well.

From my understanding, bots like those in runescape are written with java libraries. Did the manufacturer of those libraries inject assembly shellcode, and then make it so it's accessible by java?

I also read that LUA is the main coding language used in CheatEngine. I'm playing on learning the basics, but is it used widely anywhere else?

Is there any hacking use for anti-cheat rootkits that companies deploy? Have these been used in hacks?

Finally, any other decent books to read?

Disclaimer: I'm not actually going to use any of this, I just want to know exactly how people are doing stuff like aimbots etc and if I work in gaming in the future I'll be able to adress it.

submitted by /u/eht_amgine_enihcam
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
A man with no coding experience but interested in Hacking, and I’d like to hear your stories of how you got it in to it.

As the title suggest. I’ve got no coding experience but I’m keen to get in to hacking as a hobby.

I’d like to hear your stories of how you came in to this profession/hobby etc.

I feel like hearing others journeys will help better inform mine. All stories welcome, no matter how experiences or inexperienced, I’d appreciate it.

submitted by /u/PI3M3I
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Looking for an old hacking news website. Can't remember the name.

Hello all,



I am looking for an old hacker blog / news site. Unfortunately I can't think of the name anymore.



I'll try to describe the site once:

It is quite old, if not one of the oldest hacker news/blog sites out there. There were in former times more hacker stories posted but in the last 10 years they became less. The site was kept very simple and in l33t style. Definitely more in the direction of Grey Hat / Black Hat.



Can someone help me find the site?

submitted by /u/liketop33
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video