hacking: security in practice
Why does Amazon IP access all links I send over Reddit message?
I've noticed whenever I use a canarytoken Amazon's IP opens it. What is the reason for this? Is it something to do with AWS? Seems weird.
I have sent them over Instagram before and the Facebook IP accesses it which makes sense, but ones sent over Reddit are always opened by Amazon.
submitted by /u/godhimself2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why does Amazon IP access all links I send over Reddit message?
I've noticed whenever I use a canarytoken Amazon's IP opens it. What is the reason for this? Is it something to do with AWS? Seems weird.
I have sent them over Instagram before and the Facebook IP accesses it which makes sense, but ones sent over Reddit are always opened by Amazon.
submitted by /u/godhimself2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Why does Amazon IP access all links I send over Reddit message?
I've noticed whenever I use a canarytoken Amazon's IP opens it. What is the reason for this? Is it something to do with AWS? Seems weird. I have...
hacking: security in practice
Fuzzware
I came up with an interesting concept and was wondering if something like this exists or has existed in the wild. Obviously botnets have insane distributed computing power. With this a botnet could share a database of vital binaries running on infected machines. An algorithm could then select binaries to target based on various factors and then use the resources of the network to fuzz the binary and record bugs/crashes. From here the herder (assuming he is not a kiddie) can turn the bug into an exploit assuming it is an exploitable crash and then add this to the propagation mechanism of the malware and the network targets the next binary in the list. This theoretically would result in more infections. More infections result in more computing power, more computing power results in faster bug discovery, more exploits and the cycle continues.
This seems like it would result in a highly scalable botnet and seems like a good way of utilising cpu resources of the machine. I understand that the incentive for this may be low as crypto mining etc is more directly profitable however in the long term this seems like it would pay dividends. More bots on the network and exclusive access to any zero days found.
Tldr: does fuzzware exist and if so what are the limitations of this.
submitted by /u/ryan75195
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Fuzzware
I came up with an interesting concept and was wondering if something like this exists or has existed in the wild. Obviously botnets have insane distributed computing power. With this a botnet could share a database of vital binaries running on infected machines. An algorithm could then select binaries to target based on various factors and then use the resources of the network to fuzz the binary and record bugs/crashes. From here the herder (assuming he is not a kiddie) can turn the bug into an exploit assuming it is an exploitable crash and then add this to the propagation mechanism of the malware and the network targets the next binary in the list. This theoretically would result in more infections. More infections result in more computing power, more computing power results in faster bug discovery, more exploits and the cycle continues.
This seems like it would result in a highly scalable botnet and seems like a good way of utilising cpu resources of the machine. I understand that the incentive for this may be low as crypto mining etc is more directly profitable however in the long term this seems like it would pay dividends. More bots on the network and exclusive access to any zero days found.
Tldr: does fuzzware exist and if so what are the limitations of this.
submitted by /u/ryan75195
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Fuzzware
I came up with an interesting concept and was wondering if something like this exists or has existed in the wild. Obviously botnets have insane...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Log4j JNDI inj. vuln scanner
https://external-preview.redd.it/TObBUcbVrZqRfjb7L-byC-mva8mnRFzT1VwApAvfMVM.jpg?width=640&crop=smart&auto=webp&s=817a209da99caaa52157172f44d7006598c50789 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Log4j JNDI inj. vuln scanner
https://external-preview.redd.it/TObBUcbVrZqRfjb7L-byC-mva8mnRFzT1VwApAvfMVM.jpg?width=640&crop=smart&auto=webp&s=817a209da99caaa52157172f44d7006598c50789 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Log4j JNDI inj. vuln scanner
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 0 comments
hacking: security in practice
Patator broke and I'm trying to find another http brute forced that works well
Hey guys, I have been using patator on Kali after getting frustrated with Hydra, but the last Kali 2021.4 update seems to have broken it and now I just get FAILs with some pycurl CURLOPT parsing error. First if anyone has got past this issue I'd be very grateful if you could help me too, but otherwise I'm trying to find a tool for brute forcing https authentication forms, including using json requests/responses, which generally isn't a big deal as long as you can edit the body content.
To be clear my issues with Hydra have been misleading errors, especially being told to use a different module when I'm using the right module, but I will try going back to it and putting up with it. I have fiddled with the python install on Kali a lot and can't see myself fixing this issue.
Many thanks if you can help me!
submitted by /u/ripperroo5
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Patator broke and I'm trying to find another http brute forced that works well
Hey guys, I have been using patator on Kali after getting frustrated with Hydra, but the last Kali 2021.4 update seems to have broken it and now I just get FAILs with some pycurl CURLOPT parsing error. First if anyone has got past this issue I'd be very grateful if you could help me too, but otherwise I'm trying to find a tool for brute forcing https authentication forms, including using json requests/responses, which generally isn't a big deal as long as you can edit the body content.
To be clear my issues with Hydra have been misleading errors, especially being told to use a different module when I'm using the right module, but I will try going back to it and putting up with it. I have fiddled with the python install on Kali a lot and can't see myself fixing this issue.
Many thanks if you can help me!
submitted by /u/ripperroo5
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Patator broke and I'm trying to find another http brute forced...
Hey guys, I have been using patator on Kali after getting frustrated with Hydra, but the last Kali 2021.4 update seems to have broken it and now I...
hacking: security in practice
are there any hackers that do it just to mess with people?
first im no hacker, not by any means. but im curious to know if people do shit because its funny (ie hacking into a advertising billboard and displaying a dick drawn in ms paint)
submitted by /u/FURRYPORN42069
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
are there any hackers that do it just to mess with people?
first im no hacker, not by any means. but im curious to know if people do shit because its funny (ie hacking into a advertising billboard and displaying a dick drawn in ms paint)
submitted by /u/FURRYPORN42069
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
Explore this post and more from the hacking community
Kubernetes Pentesting, which entry point?
https://www.reddit.com/r/Pentesting/comments/rg12qn/kubernetes_pentesting_which_entry_point/
<!-- SC_OFF -->How you all protect your kubernetes against pentest? For example, if google.com (https://google.com/) is hosted in a kubernetes cluster, the ip address I get from nslookup is the entry point that i want to pentest or what else? note: I am doing to my own machine and has fully consent to do it <!-- SC_ON --> submitted by /u/anonymous_2600 (https://www.reddit.com/user/anonymous_2600)
[link] (https://www.reddit.com/r/Pentesting/comments/rg12qn/kubernetes_pentesting_which_entry_point/) [comments] (https://www.reddit.com/r/Pentesting/comments/rg12qn/kubernetes_pentesting_which_entry_point/)
https://www.reddit.com/r/Pentesting/comments/rg12qn/kubernetes_pentesting_which_entry_point/
<!-- SC_OFF -->How you all protect your kubernetes against pentest? For example, if google.com (https://google.com/) is hosted in a kubernetes cluster, the ip address I get from nslookup is the entry point that i want to pentest or what else? note: I am doing to my own machine and has fully consent to do it <!-- SC_ON --> submitted by /u/anonymous_2600 (https://www.reddit.com/user/anonymous_2600)
[link] (https://www.reddit.com/r/Pentesting/comments/rg12qn/kubernetes_pentesting_which_entry_point/) [comments] (https://www.reddit.com/r/Pentesting/comments/rg12qn/kubernetes_pentesting_which_entry_point/)
Accidental Bug leads to google honorable-mentions
https://infosecwriteups.com/accidental-bug-leads-to-google-honorable-mentions-7dad9eecbd7f?source=rss------bug_bounty-5
https://infosecwriteups.com/accidental-bug-leads-to-google-honorable-mentions-7dad9eecbd7f?source=rss------bug_bounty-5
Hey fellow hackers and bug hunter’s,Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/accidental-bug-leads-to-google-honorable-mentions-7dad9eecbd7f?source=rss------bug_bounty-5)
First reported on Friday turning out to be cybersecurity nightmare for all major companies. This is likely to impact wide range of…Continue reading on Medium » (https://medium.com/@R3V3R53/the-log4j-vulnerability-1d746c6ce576?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best Ethical Hacking Certification Course
https://cdn-images-1.medium.com/max/2400/1*WCfRLpXXoYCOWWTMQvLPbw.jpeg
With growing cyber threats, the ethical hacking certification has become more popular.
Continue reading on Medium »
Best Ethical Hacking Certification Course
https://cdn-images-1.medium.com/max/2400/1*WCfRLpXXoYCOWWTMQvLPbw.jpeg
With growing cyber threats, the ethical hacking certification has become more popular.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mango @ HackTheBox
https://cdn-images-1.medium.com/max/1280/0*TeqZg6QZdVjfa_H4.jpg
Mango is a 30-point linux machine on hackthebox that involves a NoSQL-Injection which allows to obtain user passwords from a mongo…
Continue reading on Medium »
Mango @ HackTheBox
https://cdn-images-1.medium.com/max/1280/0*TeqZg6QZdVjfa_H4.jpg
Mango is a 30-point linux machine on hackthebox that involves a NoSQL-Injection which allows to obtain user passwords from a mongo…
Continue reading on Medium »