hacking: security in practice
I've been watching Suits and the main character had someone hack into Harvard.
My question is: Is it possible or that easy to hack into a university's database or is it just some show's bs? And how much would it actually take to do that- hypothetically speaking?
submitted by /u/cherrika1u7
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I've been watching Suits and the main character had someone hack into Harvard.
My question is: Is it possible or that easy to hack into a university's database or is it just some show's bs? And how much would it actually take to do that- hypothetically speaking?
submitted by /u/cherrika1u7
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I've been watching Suits and the main character had someone hack...
My question is: Is it possible or that easy to hack into a university's database or is it just some show's bs? And how much would it actually take...
YIN Finance and Immunefi Reach Strategy Partnership to Strengthen the Security of YIN’s Liquidity…
https://medium.com/@yinfinance/yin-finance-and-immunefi-reach-strategy-partnership-to-strengthen-the-security-of-yins-liquidity-f291ea6f27a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@yinfinance/yin-finance-and-immunefi-reach-strategy-partnership-to-strengthen-the-security-of-yins-liquidity-f291ea6f27a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
YIN Finance and Immunefi Reach Strategy Partnership to Strengthen the Security of YIN’s Liquidity Management Platform
As part of the team at YIN Finance, we are excited to announce our strategic partnership with Immunefi. With both of us being core players…
As part of the team at YIN Finance, we are excited to announce our strategic partnership with Immunefi. With both of us being core players…Continue reading on Medium » (https://medium.com/@yinfinance/yin-finance-and-immunefi-reach-strategy-partnership-to-strengthen-the-security-of-yins-liquidity-f291ea6f27a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
YIN Finance and Immunefi Reach Strategy Partnership to Strengthen the Security of YIN’s Liquidity Management Platform
As part of the team at YIN Finance, we are excited to announce our strategic partnership with Immunefi. With both of us being core players…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
What to Do While Waiting for the Log4J Updates
This Tech Tip outlines how enterprise defenders can mitigate the risks of the Log4j vulnerabilities for the short-term while waiting for updates.
___________________________
@hacking_Attack
@Hacking_Video
What to Do While Waiting for the Log4J Updates
This Tech Tip outlines how enterprise defenders can mitigate the risks of the Log4j vulnerabilities for the short-term while waiting for updates.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
What to Do While Waiting for the Log4j Updates
This Tech Tip outlines how enterprise defenders can mitigate the risks of the Log4j vulnerabilities for the short-term while waiting for updates.
YIN Finance and Immunefi Reach Strategy Partnership to Strengthen the Security of YIN’s Liquidity…
As part of the team at YIN Finance, we are excited to announce our strategic partnership with Immunefi. With both of us being core players…Continue reading on Medium »
Read more...
As part of the team at YIN Finance, we are excited to announce our strategic partnership with Immunefi. With both of us being core players…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Log4j Demonstration
https://cdn-images-1.medium.com/max/1295/1*DDNaBdOfMEsoD_TCL6oxBA.png
Researcher: {Alan Ho}
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Log4j Demonstration
https://cdn-images-1.medium.com/max/1295/1*DDNaBdOfMEsoD_TCL6oxBA.png
Researcher: {Alan Ho}
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Log4j Demonstration
A critical vulnerability for Apache Log4j was discovered and published, it has a huge impact to countless servers.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Find & Hack Vulnerable Databases With Shodan!
https://cdn-images-1.medium.com/max/2048/1*G_3dprPC7ZRHs2GTfeKl1w.png
Shodan detects devices that are connected to the internet at any given time, the location of those devices and their current users.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Find & Hack Vulnerable Databases With Shodan!
https://cdn-images-1.medium.com/max/2048/1*G_3dprPC7ZRHs2GTfeKl1w.png
Shodan detects devices that are connected to the internet at any given time, the location of those devices and their current users.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Find & Hack Vulnerable Databases With Shodan!
Shodan detects devices that are connected to the internet at any given time, the location of those devices and their current users. And the…
Deep Web
Have you guys heard about this? Almost shit myself when I did some more research
submitted by /u/Easports42069
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Have you guys heard about this? Almost shit myself when I did some more research
submitted by /u/Easports42069
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Have you guys heard about this? Almost shit myself when I did some...
Posted in r/deepweb by u/Easports42069 • 2 points and 2 comments
How i was able to bypass Cloudflare WAF for SQLi payload
Bypassing Cloudflare for achieving SQL Injection
Read more...
Bypassing Cloudflare for achieving SQL Injection
Read more...
hacking: security in practice
Revenge! Sorta….
I want to know if possible to get back at the person who stole me Xbox live username. It’s my original username I made when the 360 first came out in 2005. So it’s almost been 20 years with this name and I’m not sure Microsoft is going to help or not. I have this persons email and that’s it. I have no clue how or why my profile was even targeted. If I’m SOL then so be it I figure this is the best place to turn for answers and I appreciate any answer truly.
submitted by /u/etpmane
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Revenge! Sorta….
I want to know if possible to get back at the person who stole me Xbox live username. It’s my original username I made when the 360 first came out in 2005. So it’s almost been 20 years with this name and I’m not sure Microsoft is going to help or not. I have this persons email and that’s it. I have no clue how or why my profile was even targeted. If I’m SOL then so be it I figure this is the best place to turn for answers and I appreciate any answer truly.
submitted by /u/etpmane
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Revenge! Sorta….
I want to know if possible to get back at the person who stole me Xbox live username. It’s my original username I made when the 360 first came out...
Disrupting an Application’s Registration Process in 10 mins
https://infosecwriteups.com/disrupting-an-applications-registration-process-in-10-mins-eab63cffd5eb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/disrupting-an-applications-registration-process-in-10-mins-eab63cffd5eb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Disrupting an Application’s User Registration Process in 10 mins
So as usual this writeup will be divided into three sections
So as usual this writeup will be divided into three sectionsContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/disrupting-an-applications-registration-process-in-10-mins-eab63cffd5eb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Disrupting an Application’s User Registration Process in 10 mins
So as usual this writeup will be divided into three sections
Disrupting an Application’s Registration Process in 10 mins
So as usual this writeup will be divided into three sectionsContinue reading on InfoSec Write-ups »
Read more...
So as usual this writeup will be divided into three sectionsContinue reading on InfoSec Write-ups »
Read more...
ADenum - A Pentesting Tool That Allows To Find Misconfiguration Through The The Protocol LDAP And Exploit Some Of Those Weaknesses With Kerberos
AD Enum is a pentesting tool that allows to find misconfiguration through the protocol LDAP and exploit some of those weaknesses with Kerberos. cracking (john) -jp path John binary path -w wordList The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -v, --version Show program's version number and exit -s Use LDAP with SSL "> █████╗ ██████╗ ███████╗███╗ ██╗██╗ ██╗███╗ ███╗ ██╔══██╗██╔══██╗ ██╔════╝████╗ ██║██║ ██║████╗ ████║ ███████║██║ ██║ █████╗ ██╔██╗ ██║██║ ██║██╔███ ╔██║ ██╔══██║██║ ██║ ██╔══╝ ██║╚██╗██║██║ ██║██║╚██╔╝██║ ██║ ██║██████╔╝ ███████╗██║ ╚████║╚██████╔╝██║ ╚═╝ ██║ ╚═╝ ╚═╝╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝usage: ADenum.py -d domain -u username -p passwordPentest tool that detect misconfig in AD with LDAPoptional arguments: -h, --help show this help message and exit -d domain The name of domain (e.g. "test.local") -u username The user name -p password The user password -ip ipAddress The IP address of the server (e.g. "1.1.1.1") -j Enable hash cracking (john) -jp path John binary path -w wordList The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -v, --version Show program's version number and exit -s Use LDAP with SSL Requirement Impacket (https://github.com/SecureAuthCorp/impacket) John (https://github.com/openwall/john) Python 3 If you are using debian or kali: $ sudo apt-get install libsasl2-dev python-dev libldap2-dev libssl-dev pip3: $ pip3 install -r Requirements.txt Features and Functionality LDAP: Enum Domain Admin users Enum Domain Controllers Enum Domain users with Password Not Expire Enum Domain users with old password Enum Domain users with interesting description Enum Domain users with not the default encryption Enum Domain users with Protecting Privileged Domain Accounts Kerberos: AS-REP Roastable Kerberoastable Password cracking with john (krb5tgs and krb5asrep) Demo Microsoft Advanced Threat Analytics ATA detects two suspicious events but does not trigger an alert: The connection with the protocol LDAP without SSL The Kerberoastable attack As shown in this screenshot: Source Documentation: https://labs.f-secure.com/blog/attack-detection-fundamentals-discovery-and-lateral-movement-lab-1/ https://theitbros.com/ldap-query-examples-active-directory/ https://docs.microsoft.com/en-us/advanced-threat-analytics/what-is-ata Impacket: https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py Legal Disclaimer: testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. ">This project is made for educational and ethical testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Download ADenum
Read more...
___________________________
@hacking_Attack
@Hacking_Video
AD Enum is a pentesting tool that allows to find misconfiguration through the protocol LDAP and exploit some of those weaknesses with Kerberos. cracking (john) -jp path John binary path -w wordList The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -v, --version Show program's version number and exit -s Use LDAP with SSL "> █████╗ ██████╗ ███████╗███╗ ██╗██╗ ██╗███╗ ███╗ ██╔══██╗██╔══██╗ ██╔════╝████╗ ██║██║ ██║████╗ ████║ ███████║██║ ██║ █████╗ ██╔██╗ ██║██║ ██║██╔███ ╔██║ ██╔══██║██║ ██║ ██╔══╝ ██║╚██╗██║██║ ██║██║╚██╔╝██║ ██║ ██║██████╔╝ ███████╗██║ ╚████║╚██████╔╝██║ ╚═╝ ██║ ╚═╝ ╚═╝╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝usage: ADenum.py -d domain -u username -p passwordPentest tool that detect misconfig in AD with LDAPoptional arguments: -h, --help show this help message and exit -d domain The name of domain (e.g. "test.local") -u username The user name -p password The user password -ip ipAddress The IP address of the server (e.g. "1.1.1.1") -j Enable hash cracking (john) -jp path John binary path -w wordList The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -v, --version Show program's version number and exit -s Use LDAP with SSL Requirement Impacket (https://github.com/SecureAuthCorp/impacket) John (https://github.com/openwall/john) Python 3 If you are using debian or kali: $ sudo apt-get install libsasl2-dev python-dev libldap2-dev libssl-dev pip3: $ pip3 install -r Requirements.txt Features and Functionality LDAP: Enum Domain Admin users Enum Domain Controllers Enum Domain users with Password Not Expire Enum Domain users with old password Enum Domain users with interesting description Enum Domain users with not the default encryption Enum Domain users with Protecting Privileged Domain Accounts Kerberos: AS-REP Roastable Kerberoastable Password cracking with john (krb5tgs and krb5asrep) Demo Microsoft Advanced Threat Analytics ATA detects two suspicious events but does not trigger an alert: The connection with the protocol LDAP without SSL The Kerberoastable attack As shown in this screenshot: Source Documentation: https://labs.f-secure.com/blog/attack-detection-fundamentals-discovery-and-lateral-movement-lab-1/ https://theitbros.com/ldap-query-examples-active-directory/ https://docs.microsoft.com/en-us/advanced-threat-analytics/what-is-ata Impacket: https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py Legal Disclaimer: testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. ">This project is made for educational and ethical testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Download ADenum
Read more...
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - fortra/impacket: Impacket is a collection of Python classes for working with network protocols.
Impacket is a collection of Python classes for working with network protocols. - fortra/impacket