Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
is there anyway to bypass angular xss sanitizer
https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/

Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that because i find my string the way it is into one of the requests responses. but the display in angular is changing the special chars such as "<" and "&" into & and<. for that my tag is just displayed. is there a way to bypass this ? submitted by /u/GrompyGromp123 (https://www.reddit.com/user/GrompyGromp123)
[link] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/) [comments] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/)

___________________________
@hacking_Attack
@Hacking_Video
Wild Credit Interest Rate Calculation Bug Post-Mortem

SummaryContinue reading on Ante Finance »
Read more...
hacking: security in practice
PMkid on windows .

Is it Really neccesary to be running Linux to capture a pmkid ?? can't u just do it on windows??
If u have an article , forum post or video explaining how to do it please link it :)
and is there a way to reset a locked wps on windows too.
i know some of you will just tell me switch to linux i already have the latest build of kali linux installed .

submitted by /u/COMUS_DYONOSIS
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Rate my cert path

Now I know tryhackme, ctf, codecsmp, and a few YouTube channels are always the recommendations for a true grasp on hacking, but I would like something I could measure and confirm my skill with. In addition employers would like to see something whether it's a degree, cert, demonstration, or something else. In my path I am trying to play both sides (so I can always come out on top) of red and blue. I like the idea of being good at one to do the other and trading back and forth. I am partial to red team though. I have used the roadmap created by Mr. Paul Jeremy to formulate a plan that increases with (subjective) difficulty. So with that said here is a path I planned:

Linux +

GAQM CFA

Pentest+

CFR and/or eJPT

CEPT

MBT and/or MPT

OSCP

submitted by /u/JudasRose
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Spoof email

How do I use a spoof mailer? I've tried Emkeis, and a few others, with no success..

How's it done these days? Any simple software or other trick that may fix this?

submitted by /u/Clats9713
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Exploits to use as a demonstration?

Hello all,

I'm a high school senior, and we've started thinking about our senior projects. Being interested in cybersecurity and penetration testing, I was planning on "hacking" something live for anyone to watch.

My question is, what should I hack?

Ideally, this "hack" would be somewhat easy to understand and perform, be easy to "undo", and bonus points for audience involvement/looking cool.

I thought about perhaps using an old WiFi router and maybe some sort of MiTM attack? I will need to conduct research, however I believe it would be cool to have students join a WiFi network, then demonstrate how their information can be taken without the use of a VPN.

Any other ideas on how to demonstrate a vulnerability/practice to the public?



Thank you!

submitted by /u/Mindstorm89
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video