Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
IP booter

Hey, hacking community.

I would like to know, which IP booter do you use or which one you can recommend to me. I have any issues with paying for them. But still looking for the best power/price. I don't want to use this for illegal purposes. I'm going to use it to test my phones connection. So I need some booter which is powerful enough to shut down phone connection. Thanks, hackers.

Greetings, Kral

submitted by /u/NoDepartment2899
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Learning Metasploit for SMB

I’m learning the ropes with Metasploit and I’m trying a box on HackTheBox where I have some user credentials (not admin though), and the SMB port is open. I can access the Temp share folder.

What module should I be using to get a shell from it? (It’s a Windows machine running SMB2/3)

submitted by /u/physiXPlays
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
i am fed up with scammers trying to lure me into the tech support scam. time for revenge

Recently more and more scammers with an indian/pakistani accent are calling us and trying to do the obvious microsoft tech support scam. so i decided it is time for revenge. i already set up the windows vm and my goal is to a: mess with them for as long as possible and b: try to lure them into copying and executing a virus/worm/trojan hidden in an excel file called banking info or something similar. where can i make/find files like this and make my vm convincing to look like it is a person that doesnt know tech. i am basically trying to f... up their day the more damage to their pc the better!

submitted by /u/DoubleOwl7777
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I've reported over a dozen security concerns and vulnerabilities to my high school, and I'm unsure where to take the situation.

It would be best to start this story from the beginning and have a timeline of what exactly has transpired from the day I reported my first vulnerability to now.

I started high school a few months ago for the first time. For context, the district my school is in has over 9,200 students and ~2,000 are from the school I'm at now. In early September I reported a vulnerability in Google Drive. It wasn't specific to this school, but essentially anyone could type in source:domaininto the search box and everything shared with the entire district could be viewable. I wouldn't say this is the most severe thing now, and if you look at it now it's just Google Sites people made about genocides and photos of teachers, but I reported it to the librarian anyway since I managed to find a few things (I've forgotten them since) that shouldn't be shared with everyone in the district. The librarian forwarded my email to the guy who does IT for the school who said that they would be notifying staff about the status of the things they share, as well as forwarding the email to the guy who manages the G Suite permissions (who I would later come in contact with). I learned from my friend (whose mom works as a teacher for one of the schools) that an email was actually sent out.

I wouldn't call myself a Marcus Hutchins for that, nor for anything I'm going to detail in this post, but regardless I thought that would be the last thing I would find out. That's a pretty reoccurring theme and something that ends up to me being a bit of a problem.

A week later from my initial email to the librarian, I decided to go directly to the person who does IT for the school to report a vulnerability with ViewState in ASP.NET (which some of the district's custom-coded websites use). I never got a response back, although I did meet with him a month later and got acknowledgement it was read.

Two months pass since my second email and I decided to send an email to him again, this time with a massive amount of security concerns and vulnerabilities, and sent two more replies within the week with even more of those things. A month had passed and nothing had been fixed, which I had no problem with since I was aware that not everything gets fixed because IT especially in a school environment often has limited resources. The only fixed vulnerability was a part of a larger one, which was that certain Google Groups could be viewed by anyone. One of those was a "catch-all" email for error logs, bug reports, and the sort, which was limited from public access if only because the person who did IT at the school was a manager of the group.

After a month of nothing being done, I decide to directly to the IT director of the whole district (he's also the one that manages G Suite permissions). Before approaching him, however, I went to my friend whose mom is a teacher for one of the schools and received a message over Discord from him that I could approach the IT director, and if nothing was done then it would be taken up to administration. Despite the option of being anonymous, I decided against it given that they had already known my name.

What happened from there was taken between his mom and the IT director, which was a text message conversation. My friend had kept me posted on the events that transpired, which amounted to the IT director knowing my name, then getting the email, and saying/suggesting that he was mildly annoyed that I knew more about the systems I had wrote about than he did. I received a "Thank you" reply back, but my friend had informed me that that's about the extent of what he's going to say.

Directly a week after my initial email to him, I sent ano[...]

___________________________
@hacking_Attack
@Hacking_Video