Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Huawei watch gt reverse engineer and custom firmware

Hi, i got a huawei watch gt a few weeks ago and i like its design , but i feel like huawei coud improve it by adding more features on the firmware (but it didnt want) , so i want to put my programming and reverse engieneering skills and make that myself, but i want to know if anyone did that (or if anyone knows anything how can i dump , mod and flash it to the "smartwatch").

submitted by /u/bfge
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cyber Reasoning System for final college project

Hello fellow hacking enthusiasts!

I'm a CS student in my final year and I've decided to create a cyber reasoning system for my final year project. The problem is that I searched for the topic but there is not much source material on this type of projects. The only relevant thing I found is this repository:
https://github.com/mechaphish
But there is not much documentation of the inner workings of such a system and I do not want to copy paste it. I just want to understand the core architecture and some explanations for some methods.

Of course, considering the time frame for the project, I will build a much simpler CRS which will only take linux binaries and find some specific vulnerabilities.
So do you people know some good sources for this type of project? Thank you!

submitted by /u/CorpuscularDump
[link] [comments]
log4j-scan - A fully automated, accurate, and extensive scanner for finding vulnerable log4j hosts
http://www.kitploit.com/2021/12/log4j-scan-fully-automated-accurate-and.html
A fully automated, accurate, and extensive scanner for finding vulnerable (https://www.kitploit.com/search/label/Vulnerable) log4j hostsFeaturesSupport for lists of URLs.Fuzzing for more than 60 HTTP request headers (not only 3-4 headers as previously seen tools).Fuzzing for HTTP POST Data parameters.Fuzzing for JSON data parameters.Supports DNS callback for vulnerability (https://www.kitploit.com/search/label/Vulnerability) discovery (https://www.kitploit.com/search/label/Discovery) and validation.WAF Bypass payloads.
AnnouncementThere is a patch bypass on Log4J v2.15.0 that allows a full RCE. FullHunt added community support for log4j-scan to reliably detect CVE-2021-45046. If you're having difficulty discovering and scanning your infrastructure (https://www.kitploit.com/search/label/Infrastructure) at scale or keeping up with the Log4J threat, please get in touch at (team@fullhunt.io (mailto:team@fullhunt.io)).