Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CISA Issues Emergency Directive on Log4j
The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.
___________________________
@hacking_Attack
@Hacking_Video
CISA Issues Emergency Directive on Log4j
The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
CISA Issues Emergency Directive on Log4j
The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Timely Questions for Log4j Response Now — And for the Future
EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).
___________________________
@hacking_Attack
@Hacking_Video
Timely Questions for Log4j Response Now — And for the Future
EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Timely Questions for Log4j Response Now — And for the Future
EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).
Subdomain Takeover Via Flywheel
https://0xelmalky.medium.com/subdomain-takeover-via-flywheel-447a71d77396?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xelmalky.medium.com/subdomain-takeover-via-flywheel-447a71d77396?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Subdomain Takeover Via Flywheel
Flywheel is managed WordPress hosting built for designers and creative agencies to build, scale, and manage hundreds of WordPress sites…
Flywheel is managed WordPress hosting built for designers and creative agencies to build, scale, and manage hundreds of WordPress sites…Continue reading on Medium » (https://0xelmalky.medium.com/subdomain-takeover-via-flywheel-447a71d77396?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Subdomain Takeover Via Flywheel
Flywheel is managed WordPress hosting built for designers and creative agencies to build, scale, and manage hundreds of WordPress sites…
is there anyway to bypass angular xss sanitizer
https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/
Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that because i find my string the way it is into one of the requests responses. but the display in angular is changing the special chars such as "<" and "&" into & and<. for that my tag is just displayed. is there a way to bypass this ? submitted by /u/GrompyGromp123 (https://www.reddit.com/user/GrompyGromp123)
[link] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/) [comments] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/
Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that because i find my string the way it is into one of the requests responses. but the display in angular is changing the special chars such as "<" and "&" into & and<. for that my tag is just displayed. is there a way to bypass this ? submitted by /u/GrompyGromp123 (https://www.reddit.com/user/GrompyGromp123)
[link] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/) [comments] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
is there anyway to bypass angular xss sanitizer
Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Why Log4j won’t go away: 5 key questions on the bombshell vulnerability
https://cdn-images-1.medium.com/max/1400/1*APaO3klLefUceJ23t93RqA.png
A nasty software flaw reared its head last week, pulling security professionals into an ongoing and high-stakes race against…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Why Log4j won’t go away: 5 key questions on the bombshell vulnerability
https://cdn-images-1.medium.com/max/1400/1*APaO3klLefUceJ23t93RqA.png
A nasty software flaw reared its head last week, pulling security professionals into an ongoing and high-stakes race against…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why Log4j won’t go away: 5 key questions answered on the bombshell vulnerability
A nasty software flaw reared its head last week, pulling security professionals into an ongoing and high-stakes race against…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
As Etapas de um Pentest
https://cdn-images-1.medium.com/max/1920/1*gdTiGXl4RiucQVpoDkvwFQ.jpeg
O pentest é dividido em várias etapas, para que se consiga adquirir o máximo de informação sobre o alvo, e garantir um ataque mais…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
As Etapas de um Pentest
https://cdn-images-1.medium.com/max/1920/1*gdTiGXl4RiucQVpoDkvwFQ.jpeg
O pentest é dividido em várias etapas, para que se consiga adquirir o máximo de informação sobre o alvo, e garantir um ataque mais…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
As Etapas de um Pentest
O pentest é dividido em várias etapas, para que se consiga adquirir o máximo de informação sobre o alvo, e garantir um ataque mais…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El nuevo malware PseudoManuscrypt infectó más de 35,000 computadoras en 2021
https://cdn-images-1.medium.com/max/1123/0*kPYZp80MpsuBgUgK
PUBLICADO EN 17 DICIEMBRE, 2021 POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
El nuevo malware PseudoManuscrypt infectó más de 35,000 computadoras en 2021
https://cdn-images-1.medium.com/max/1123/0*kPYZp80MpsuBgUgK
PUBLICADO EN 17 DICIEMBRE, 2021 POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
El nuevo malware PseudoManuscrypt infectó más de 35,000 computadoras en 2021
PUBLICADO EN 17 DICIEMBRE, 2021 POR DPAB
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
ShellDredd-1 Hannah Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/753/0*di1DFeoCt-z2taVW.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
ShellDredd-1 Hannah Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/753/0*di1DFeoCt-z2taVW.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
ShellDredd-1 Hannah Vulnhub Walkthrough
Makineyi indirebilirsiniz.
Wild Credit Interest Rate Calculation Bug Post-Mortem
SummaryContinue reading on Ante Finance »
Read more...
SummaryContinue reading on Ante Finance »
Read more...
hacking: security in practice
PMkid on windows .
Is it Really neccesary to be running Linux to capture a pmkid ?? can't u just do it on windows??
If u have an article , forum post or video explaining how to do it please link it :)
and is there a way to reset a locked wps on windows too.
i know some of you will just tell me switch to linux i already have the latest build of kali linux installed .
submitted by /u/COMUS_DYONOSIS
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
PMkid on windows .
Is it Really neccesary to be running Linux to capture a pmkid ?? can't u just do it on windows??
If u have an article , forum post or video explaining how to do it please link it :)
and is there a way to reset a locked wps on windows too.
i know some of you will just tell me switch to linux i already have the latest build of kali linux installed .
submitted by /u/COMUS_DYONOSIS
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
PMkid on windows .
Is it Really neccesary to be running Linux to capture a pmkid ?? can't u just do it on windows?? If u have an article , forum post or video...
hacking: security in practice
njs is a subset of the JavaScript language that allows extending nginx functionality. njs is created in compliance with ECMAScript 5.1 (strict mode) with some ECMAScript 6 and later extensions. The compliance is still evolving
Use cases
Complex access control and security checks in njs before a request reaches an upstream serverManipulating response headersWriting flexible asynchronous content handlers and filters
https://nginx.org/en/docs/njs/
submitted by /u/totie01010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
njs is a subset of the JavaScript language that allows extending nginx functionality. njs is created in compliance with ECMAScript 5.1 (strict mode) with some ECMAScript 6 and later extensions. The compliance is still evolving
Use cases
Complex access control and security checks in njs before a request reaches an upstream serverManipulating response headersWriting flexible asynchronous content handlers and filters
https://nginx.org/en/docs/njs/
submitted by /u/totie01010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
njs is a subset of the JavaScript language that allows extending...
Use cases Complex access control and security checks in njs before a request reaches an upstream serverManipulating response headersWriting...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Rate my cert path
Now I know tryhackme, ctf, codecsmp, and a few YouTube channels are always the recommendations for a true grasp on hacking, but I would like something I could measure and confirm my skill with. In addition employers would like to see something whether it's a degree, cert, demonstration, or something else. In my path I am trying to play both sides (so I can always come out on top) of red and blue. I like the idea of being good at one to do the other and trading back and forth. I am partial to red team though. I have used the roadmap created by Mr. Paul Jeremy to formulate a plan that increases with (subjective) difficulty. So with that said here is a path I planned:
Linux +
GAQM CFA
Pentest+
CFR and/or eJPT
CEPT
MBT and/or MPT
OSCP
submitted by /u/JudasRose
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Rate my cert path
Now I know tryhackme, ctf, codecsmp, and a few YouTube channels are always the recommendations for a true grasp on hacking, but I would like something I could measure and confirm my skill with. In addition employers would like to see something whether it's a degree, cert, demonstration, or something else. In my path I am trying to play both sides (so I can always come out on top) of red and blue. I like the idea of being good at one to do the other and trading back and forth. I am partial to red team though. I have used the roadmap created by Mr. Paul Jeremy to formulate a plan that increases with (subjective) difficulty. So with that said here is a path I planned:
Linux +
GAQM CFA
Pentest+
CFR and/or eJPT
CEPT
MBT and/or MPT
OSCP
submitted by /u/JudasRose
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Rate my cert path
Now I know tryhackme, ctf, codecamp, and a few YouTube channels are always the recommendations for a true grasp on hacking, but I would like...