Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Burp & protobuf

Hi,

I am currently using burp to intercept http trafic from a thick client that I have to test. It uses protobuf on most of its request, and I am trying to decode it, or even better, fuzz its fields. I tried 3 extensions (protobuf decoder, blackboxprotobuf, and protobuf editor), but all seems to fail to decode the binary without the .proto file. Did someone manage to make them work, or has any advice to do it with other tools ?

Have a good day,

submitted by /u/RedditBucky
[link] [comments]
hacking: security in practice
Monitor mode + SSH Raspberry Pi 4

Hi everyone! I recently installed the ARM version of Kali on a Raspberry Pi 4, which comes with driver patched that allow it to run in monitor mode and it works fine, however I don't have a second monitor, and I generally use SSH to connect to my Raspberry from my main PC, which won't work in monitor mode. Is there anyways to bypass this, or any different way of connecting to my Raspberry, while monitor mode is running?

submitted by /u/skill347
[link] [comments]
How I Found My First XSS Bug and Earn $$$

Hi everyone,
Read more...
How I found the Authentication Bypass bug and Earn $$$$

Hi all,
Read more...
Learn365 Challenge Review & Year 2021 in a Nutshell
https://hbothra22.medium.com/learn365-challenge-review-year-2021-in-a-nutshell-4efab0773877?source=rss------bug_bounty-5

Learning is an essential factor irrespective of your domain, level of expertise and experience. It helps one to constantly improve their…Continue reading on Medium » (https://hbothra22.medium.com/learn365-challenge-review-year-2021-in-a-nutshell-4efab0773877?source=rss------bug_bounty-5)
Hi, I am Kurt Russelle Marmol doing bug hunting for more than a year, and this is my first bug bounty write-up about my findings.Continue reading on Medium » (https://xkurtph.medium.com/shopify-plugin-bypass-using-client-side-injection-thru-api-implementation-vulnerability-710d25105c8f?source=rss------bug_bounty-5)
Dark Reading: Attacks/Breaches
How Modern Log Management Strengthens Enterprises’ Security Posture

If security teams are not logging everything, they are increasing security risk and making it more difficult to investigate and recover from a data breach. Modern log management goes beyond just a SIEM.
Dark Reading: Attacks/Breaches
Future of Identity-Based Security: All-in-One Platforms or Do-It-Yourself Solutions?

The functionality of all-in-one platforms is being deconstructed into a smorgasbord of services that can be used to develop bespoke end-user security procedures for specific work groups, lines of businesses, or customer communities.
Dark Reading: Attacks/Breaches
Why We Need to Consolidate Digital Identity Management Before Zero Trust

Zero trust may be one of the hottest trends in cybersecurity, but just eliminating trust from networks isn’t enough to prevent successful organizational data breaches, says Wes Wright, CTO of Imprivata.
Dark Reading: Attacks/Breaches
Log4j Reveals Cybersecurity's Dirty Little Secret

Once the dust settles on Log4j, many IT teams will brush aside the need for the fundamental, not-exciting need for better asset and application management.