Degree choice if you had to start over...
https://www.reddit.com/r/Pentesting/comments/rhx6rf/degree_choice_if_you_had_to_start_over/
What degree would you guys go for if you had to start over? I work as a SOC analyst currently and working on my cyber security degree, but pentesting is my ultimate goal as i've been working on it for years now. I'm thinking about switching my degree over to software development as I feel learning to code would greatly enhance my abilities to do web application assessments, and as a pen tester in general. Would you guys do the same? (Knowing that degrees don't really matter so much, its just something on my bucket list I want to have) submitted by /u/supersillygoose17 (https://www.reddit.com/user/supersillygoose17)
[link] (https://www.reddit.com/r/Pentesting/comments/rhx6rf/degree_choice_if_you_had_to_start_over/) [comments] (https://www.reddit.com/r/Pentesting/comments/rhx6rf/degree_choice_if_you_had_to_start_over/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/rhx6rf/degree_choice_if_you_had_to_start_over/
What degree would you guys go for if you had to start over? I work as a SOC analyst currently and working on my cyber security degree, but pentesting is my ultimate goal as i've been working on it for years now. I'm thinking about switching my degree over to software development as I feel learning to code would greatly enhance my abilities to do web application assessments, and as a pen tester in general. Would you guys do the same? (Knowing that degrees don't really matter so much, its just something on my bucket list I want to have) submitted by /u/supersillygoose17 (https://www.reddit.com/user/supersillygoose17)
[link] (https://www.reddit.com/r/Pentesting/comments/rhx6rf/degree_choice_if_you_had_to_start_over/) [comments] (https://www.reddit.com/r/Pentesting/comments/rhx6rf/degree_choice_if_you_had_to_start_over/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Degree choice if you had to start over...
What degree would you guys go for if you had to start over? I work as a SOC analyst currently and working on my cyber security degree, but...
hacking: security in practice
What funny i can do with LAN network?
Hi, I'm currently making trolling tool for LAN network and i need ideas what i can add to my program. At this moment i have freezing function which kick out network for all computers. Can you send me whats more i can add? ( I don't want ideas which they do some harm.)
submitted by /u/whzg0d
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What funny i can do with LAN network?
Hi, I'm currently making trolling tool for LAN network and i need ideas what i can add to my program. At this moment i have freezing function which kick out network for all computers. Can you send me whats more i can add? ( I don't want ideas which they do some harm.)
submitted by /u/whzg0d
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What funny i can do with LAN network?
Hi, I'm currently making trolling tool for LAN network and i need ideas what i can add to my program. At this moment i have freezing function...
hacking: security in practice
How to view the source code of the .exe file, which I know for sure is a malicious file
So the thing is that I am kinda new to "Reverse Engineering," and I found a .exe file that I know for sure is malicious because I ran a sandbox on it. What I want to do next is to get access to its source code to understand how it works more profoundly, aka "Reverse Engineering." So far, I have tried the "Ghidra" to access the source code. But as you could tell already, I am pretty bad at Assembly language, so I couldn't understand a thing. The next thing I tried was to check it in the "IDA" free version. But to convert it from Assembly to C language, I need a Pro version which is pretty expensive. So, finally, the question is: Is there any way to open the source code of the .exe file in the C/C++ language so it would be convenient to understand the processes.
submitted by /u/rubenamizyan
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to view the source code of the .exe file, which I know for sure is a malicious file
So the thing is that I am kinda new to "Reverse Engineering," and I found a .exe file that I know for sure is malicious because I ran a sandbox on it. What I want to do next is to get access to its source code to understand how it works more profoundly, aka "Reverse Engineering." So far, I have tried the "Ghidra" to access the source code. But as you could tell already, I am pretty bad at Assembly language, so I couldn't understand a thing. The next thing I tried was to check it in the "IDA" free version. But to convert it from Assembly to C language, I need a Pro version which is pretty expensive. So, finally, the question is: Is there any way to open the source code of the .exe file in the C/C++ language so it would be convenient to understand the processes.
submitted by /u/rubenamizyan
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to view the source code of the .exe file, which I know for...
So the thing is that I am kinda new to "Reverse Engineering," and I found a .exe file that I know for sure is malicious because I ran a sandbox on...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
https://external-preview.redd.it/SX94lobeFzOhNFvCJyIQh3dVK_PxfPbT5SXkHvUH85E.jpg?width=640&crop=smart&auto=webp&s=3265d3e480c294a4476d95833ec3c5a639edc056 submitted by /u/binaryfor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
https://external-preview.redd.it/SX94lobeFzOhNFvCJyIQh3dVK_PxfPbT5SXkHvUH85E.jpg?width=640&crop=smart&auto=webp&s=3265d3e480c294a4476d95833ec3c5a639edc056 submitted by /u/binaryfor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A fully automated, accurate, and extensive scanner for finding...
Posted in r/hacking by u/binaryfor • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
digital world.local: FALL Vulnhub Walkthrough
FALL (digitalworld.local: FALL) is a medium level machine created by Donavan for Vulnhub. This lab is appropriate for some experienced CTF players who wish to
The post digital world.local: FALL Vulnhub Walkthrough appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
digital world.local: FALL Vulnhub Walkthrough
FALL (digitalworld.local: FALL) is a medium level machine created by Donavan for Vulnhub. This lab is appropriate for some experienced CTF players who wish to
The post digital world.local: FALL Vulnhub Walkthrough appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
digital world.local: FALL Vulnhub Walkthrough
Local Fall VulnHub guide: Exploit web interface to gain shell access and escalate privileges via misconfigured sudo permissions.
SMB Negotiation Failure. What exactly does it mean and how can I fix it? I'm very new to using msfconsole and this has me stumped. I've followed YouTube videos and articles but they seem to have no issue at all.
https://www.reddit.com/r/Pentesting/comments/ri1uhm/smb_negotiation_failure_what_exactly_does_it_mean/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ri1uhm/smb_negotiation_failure_what_exactly_does_it_mean/
___________________________
@hacking_Attack
@Hacking_Video
reddit
SMB Negotiation Failure. What exactly does it mean and how can I...
Posted in r/Pentesting by u/Purpl3One • 1 point and 0 comments
submitted by /u/Purpl3One (https://www.reddit.com/user/Purpl3One)
[link] (https://i.redd.it/thmut0fjcz581.jpg) [comments] (https://www.reddit.com/r/Pentesting/comments/ri1uhm/smb_negotiation_failure_what_exactly_does_it_mean/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://i.redd.it/thmut0fjcz581.jpg) [comments] (https://www.reddit.com/r/Pentesting/comments/ri1uhm/smb_negotiation_failure_what_exactly_does_it_mean/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
overview for Purpl3One
The u/Purpl3One community on Reddit. Reddit gives you the best of the internet in one place.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Phorpiex Botnet Variant Spread Across 96 Countries
A new variant dubbed "Twizt" has hijacked 969 transactions and stolen the equivalent of nearly $500,000 USD.
___________________________
@hacking_Attack
@Hacking_Video
Phorpiex Botnet Variant Spread Across 96 Countries
A new variant dubbed "Twizt" has hijacked 969 transactions and stolen the equivalent of nearly $500,000 USD.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Phorpiex Botnet Variant Spread Across 96 Countries
A new variant dubbed "Twizt" has hijacked 969 transactions and stolen the equivalent of nearly $500,000 USD.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
10 Tips To Avoid Being Hacked Online
https://cdn-images-1.medium.com/max/2600/0*e2R9jZ-1-ouFGm4B
Safety Should Always Come First!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
10 Tips To Avoid Being Hacked Online
https://cdn-images-1.medium.com/max/2600/0*e2R9jZ-1-ouFGm4B
Safety Should Always Come First!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Tips To Avoid Being Hacked Online
Safety Should Always Come First!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
digital world.local: FALL Vulnhub Walkthrough
FALL (digitalworld.local: FALL) is a medium level machine created by Donavan for Vulnhub. This lab is appropriate for some experienced CTF players who wish to put their skills to the test in these environments. So, let's get going and figure out where to break things down into manageable pieces. Pentest MethodologyNetwork Scanning● nmap Enumeration● Abusing HTTPExploitation● FuzzingPrivilege Escalation● SSHLevel: MediumNetwork Scanning192.168.1.7.-A) for open port enumeration and found the following ports as show in the given image.nmap -A 192.168.1.7According to the results of the nmap scan, this machine is running a wide range of services.EnumerationFirst, we'll attempt to use HTTP. Let's look at port 80 and see if anything notable comes up. We can instantly verify this in the browser because the Apache Server is listening on port 80. There is nothing special except that we discovered a user name "qiu".gobuster dir -u http://192.168.1.7 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x .html,.php,.txtAbove command will enumerate all file that has .html, .php, .txt extension.ExploitationI was clueless therefor I was doubtful with LFI thus I use FUZZ to identify existence of LFI by fuzzing for /etc/passwd file. With the help of following command I try to fuzz for missing Get parameter.ffuf -c -w /usr/share/seclists/Discovery/Web-Content/common.txt -u 'http://192.168.1.7/test.php?FUZZ=/etc/passwd' -fs 80https://blogger.googleusercontent.com/img/a/AVvXsEjjbVzCEy3LhPWlUmd02PDegybwEcZ2pIi96MkozPrz-iJDAOl726rKRaFKGb5WSe26x317[...]
___________________________
@hacking_Attack
@Hacking_Video
digital world.local: FALL Vulnhub Walkthrough
FALL (digitalworld.local: FALL) is a medium level machine created by Donavan for Vulnhub. This lab is appropriate for some experienced CTF players who wish to put their skills to the test in these environments. So, let's get going and figure out where to break things down into manageable pieces. Pentest MethodologyNetwork Scanning● nmap Enumeration● Abusing HTTPExploitation● FuzzingPrivilege Escalation● SSHLevel: MediumNetwork Scanning192.168.1.7.-A) for open port enumeration and found the following ports as show in the given image.nmap -A 192.168.1.7According to the results of the nmap scan, this machine is running a wide range of services.EnumerationFirst, we'll attempt to use HTTP. Let's look at port 80 and see if anything notable comes up. We can instantly verify this in the browser because the Apache Server is listening on port 80. There is nothing special except that we discovered a user name "qiu".gobuster dir -u http://192.168.1.7 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x .html,.php,.txtAbove command will enumerate all file that has .html, .php, .txt extension.ExploitationI was clueless therefor I was doubtful with LFI thus I use FUZZ to identify existence of LFI by fuzzing for /etc/passwd file. With the help of following command I try to fuzz for missing Get parameter.ffuf -c -w /usr/share/seclists/Discovery/Web-Content/common.txt -u 'http://192.168.1.7/test.php?FUZZ=/etc/passwd' -fs 80https://blogger.googleusercontent.com/img/a/AVvXsEjjbVzCEy3LhPWlUmd02PDegybwEcZ2pIi96MkozPrz-iJDAOl726rKRaFKGb5WSe26x317[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
digital world.local: FALL Vulnhub Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog digital world.local: FALL Vulnhub Walkthrough FALL (digitalworld.local: FALL) is a medium level machine created by Donavan for Vulnhub. This lab is appropriate for some experienced CTF players who wish to put their skills…
htC0K1SIUKdT7qUfCHVhKc8BOUP5nqgevMdUO7Hmm9cKsKQpV9ns6QGfndx3sxUIRSU3Gfcngv6Ozk4nOGUR2mzNAksijFZefmArKEHU9IAVmNXJH3jYUw=s16000 We got 200 OK for “file” parameter that could be missing term. We use curl command to bring up /etc/passwd file of the remote machine.curl http://192.168.1.7/test.php?file=/etc/passwdhttps://blogger.googleusercontent.com/img/a/AVvXsEhK1LpNzM58EGdN07wS8rSmvWTJF1fhR-66GY2_IIRc6on_eAdhqaqLJSH4nM6mV3TolI0rmmpOBLmHb5ul5pEOjUy9wfIZVmWaGTSRF68Bk5PBIQiUZ0tk-iFYwBM0kes3XyS9PuIRFY9ZvsxnaqYYZkz3iSqJDfjYB1pty3KVy0aCe1BfuhBcHOzhLg=s16000 We can easily see that the user name "qiu" who has user account with higher privileges, and it also has bash authorization.qiuwith the help of curl command by exploiting LFI.curl http://192.168.1.7/test.php?file=/home/qiu/.ssh/id_rsahttps://blogger.googleusercontent.com/img/a/AVvXsEjiOlXZ5UFjdQMQwatWN5zizbR81VjA02WDypOtuNu9LOntDY0egU-T5M3gdiD9js0HMYnUuFwsKhT-KEGY90V9_xhxu_RBsWUSTRYk3y0wKM_tuzOgIzChwKxSlY2P8hC00dOZJ805Tt0Zyg4_8kJfZYeZQK_UxMkdq1HslB6hUO7Q4SE345SC4c9sCA=s16000 Let's try the SSH connection but first, we must save this key on our machine while granting the necessary permissions. So, let us begin the SSH login…nano sshkeyAfter successfully logging in to SSH, we began for privilege escalation.Privilege EscalationAll we have to do now is examine bash history and find some valuable information. cat .bash_historyWe obtained the user "qiu" password "remarkablyawesome," and we ran a sudo command to check this user's permissions. sudo -lThe user "qiu" was granted all of the necessary permissions to become root. We simply switch the user account and submit the password enumerated above.sudo suhttps://blogger.googleusercontent.com/img/a/AVvXsEj3gnCxBxyEsrvnNd6ZH6xb380yXdHRt7TZcH1atV6eOn-ltIyirjMiT68bFLz1xVGJK7xnZQTDBt6KnnJbY0kY5cjnC0isWqFbELDKwRpLuDgEVCCLxzS01IdoGavL4AgcW9ARWcTUnxmTHZYAkKkXNqVvTOB-g0Xyr-gkyp-WIBmDrPHYage1p_Q2Cg=s16000 This is how we can get to the heart of the machine. It was a fantastic exercise, and it was a lot of fun to root for. It is necessary to try one in order to comprehend various scenarios.Author: Shubham Sharma is a passionate Cybersecurity Researcher, contact LinkedInand Twitter.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Bunkerized-Nginx is a web server based on the notorious nginx and focused on security.
https://github.com/bunkerity/bunkerized-nginx
submitted by /u/totie01010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Bunkerized-Nginx is a web server based on the notorious nginx and focused on security.
https://github.com/bunkerity/bunkerized-nginx
submitted by /u/totie01010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bunkerized-Nginx is a web server based on the notorious nginx and...
https://github.com/bunkerity/bunkerized-nginx
Installing go written tools with go version 1.17 and above
https://medium.com/@Albertini_/installing-go-written-tools-with-go-version-1-17-and-above-14437bfcdbf3?source=rss------bug_bounty-5
Hi, Let me guess having issues with your normal go installation process,Continue reading on Medium » (https://medium.com/@Albertini_/installing-go-written-tools-with-go-version-1-17-and-above-14437bfcdbf3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Albertini_/installing-go-written-tools-with-go-version-1-17-and-above-14437bfcdbf3?source=rss------bug_bounty-5
Hi, Let me guess having issues with your normal go installation process,Continue reading on Medium » (https://medium.com/@Albertini_/installing-go-written-tools-with-go-version-1-17-and-above-14437bfcdbf3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Installing go written tools with go version 1.17 and above
Hi, Let me guess having issues with your normal go installation process,