Hunting for Bugs in File Upload Feature:
In this blog, I will be listing down some file upload Vulnerability such RCE, SSRF, CSRF, XSS and many more such vulnerabilities.Continue reading on Medium »
Read more...
In this blog, I will be listing down some file upload Vulnerability such RCE, SSRF, CSRF, XSS and many more such vulnerabilities.Continue reading on Medium »
Read more...
Astroport Boosts Bug Bounty to $3m, Takes Top Leaderboard Spot
Astroport has just doubled its critical bug bounty reward from $1.5m to $3m, making it the largest bounty on Immunefi’s platform, beating…Continue reading on Immunefi »
Read more...
Astroport has just doubled its critical bug bounty reward from $1.5m to $3m, making it the largest bounty on Immunefi’s platform, beating…Continue reading on Immunefi »
Read more...
Red & Blue-Team Quick Reference Gitbooks
https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/
https://preview.redd.it/fr6me9amad881.png?width=2250&format=png&auto=webp&s=b41dfae9c724d1f9519dca8fb2317b91d4c8c778 Hi everyone! I would like to share with you one of my gitbooks, focused on DFIR, Malware and Blue-Team in general. Is a WIP in progress. Im actually adding more and more things while myself learn along the way. 📘 Hunter - Jorge Testa (https://hunter.jorgetesta.tech/) There you have my Red-Team version. WIP too. 📕 Tryharder - Jorge Testa (https://tryharder.jorgetesta.tech/) Hope you like it! submitted by /u/J-Testa (https://www.reddit.com/user/J-Testa)
[link] (https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/) [comments] (https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/
https://preview.redd.it/fr6me9amad881.png?width=2250&format=png&auto=webp&s=b41dfae9c724d1f9519dca8fb2317b91d4c8c778 Hi everyone! I would like to share with you one of my gitbooks, focused on DFIR, Malware and Blue-Team in general. Is a WIP in progress. Im actually adding more and more things while myself learn along the way. 📘 Hunter - Jorge Testa (https://hunter.jorgetesta.tech/) There you have my Red-Team version. WIP too. 📕 Tryharder - Jorge Testa (https://tryharder.jorgetesta.tech/) Hope you like it! submitted by /u/J-Testa (https://www.reddit.com/user/J-Testa)
[link] (https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/) [comments] (https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Red & Blue-Team Quick Reference Gitbooks
Posted in r/redteamsec by u/J-Testa • 11 points and 1 comment
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HacktheBox [Lame]
https://cdn-images-1.medium.com/max/1903/1*ZMbSY6MTCJgfNwgtnFvHrA.png
Lame was a easy box on HacktheBox platform. I demonstrate how to gain a low privileged shell exploiting the DISTCC server with both…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HacktheBox [Lame]
https://cdn-images-1.medium.com/max/1903/1*ZMbSY6MTCJgfNwgtnFvHrA.png
Lame was a easy box on HacktheBox platform. I demonstrate how to gain a low privileged shell exploiting the DISTCC server with both…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HacktheBox [Lame]
Lame was a easy box on HacktheBox platform. I demonstrate how to gain a low privileged shell exploiting the DISTCC server with both…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Profit Hacking
Si vous cherchez à augmenter vos bénéfices, le profit hacking est fait pour vous. Cela signifie que vous devez examiner les processus sur…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Profit Hacking
Si vous cherchez à augmenter vos bénéfices, le profit hacking est fait pour vous. Cela signifie que vous devez examiner les processus sur…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Profit Hacking
Si vous cherchez à augmenter vos bénéfices, le profit hacking est fait pour vous. Cela signifie que vous devez examiner les processus sur…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Trouble recreating Log4j with Minecraft
I'm attempting to recreate the famous Log4j vulnerability with Minecraft. I've been following this video, and I had some success in getting the vulnerability to work just before Christmas. I've revisited it just today, and now cannot get anything to work. The only difference between these days is a Windows update that ran on the computer hosting the Minecraft client (the one I'm using to send the malicious message). I didn't believe that this would impact anything, but it seems to have done something, as the malicious messages now do nothing.
Also noteworthy: I had some success getting the server (old vulnerable version of paperMC as provided in the video) to "exploit itself" by using the /say command in the server's terminal directly, however even this seems to have broken, despite the server never updating
Did someone patch some software very recently? I can provide much more detail if necessary.
Thank you!
submitted by /u/Mindstorm89
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Trouble recreating Log4j with Minecraft
I'm attempting to recreate the famous Log4j vulnerability with Minecraft. I've been following this video, and I had some success in getting the vulnerability to work just before Christmas. I've revisited it just today, and now cannot get anything to work. The only difference between these days is a Windows update that ran on the computer hosting the Minecraft client (the one I'm using to send the malicious message). I didn't believe that this would impact anything, but it seems to have done something, as the malicious messages now do nothing.
Also noteworthy: I had some success getting the server (old vulnerable version of paperMC as provided in the video) to "exploit itself" by using the /say command in the server's terminal directly, however even this seems to have broken, despite the server never updating
Did someone patch some software very recently? I can provide much more detail if necessary.
Thank you!
submitted by /u/Mindstorm89
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Trouble recreating Log4j with Minecraft
I'm attempting to recreate the famous Log4j vulnerability with Minecraft. I've been following [this](https://www.youtube.com/watch?v=7qoPDq41xhQ)...
hacking: security in practice
Can messages be removed from someone else’s phone remotely?
My wife had some disturbing messages from her brother and they vanished a few days later. With the right amount of money and connections, could they be erased remotely?
submitted by /u/Ms-appropriation
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can messages be removed from someone else’s phone remotely?
My wife had some disturbing messages from her brother and they vanished a few days later. With the right amount of money and connections, could they be erased remotely?
submitted by /u/Ms-appropriation
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can messages be removed from someone else’s phone remotely?
My wife had some disturbing messages from her brother and they vanished a few days later. With the right amount of money and connections, could...
OTP bypass via response manipulation
https://janjeffrie.medium.com/otp-bypass-via-response-manipulation-ab17f5985c8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://janjeffrie.medium.com/otp-bypass-via-response-manipulation-ab17f5985c8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
OTP bypass via response manipulation
Hello everyone I’m Jan Jeffrie Salloman, I started bug hunting 1 year ago. This writeup is about an OTP bypass using response manipulation…
Hello everyone I’m Jan Jeffrie Salloman, I started bug hunting 1 year ago. This writeup is about an OTP bypass using response manipulation…Continue reading on Medium » (https://janjeffrie.medium.com/otp-bypass-via-response-manipulation-ab17f5985c8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
OTP bypass via response manipulation
Hello everyone I’m Jan Jeffrie Salloman, I started bug hunting 1 year ago. This writeup is about an OTP bypass using response manipulation…
Polygon Lack Of Balance Check Bugfix Postmortem — $2.2m Bounty
https://medium.com/immunefi/polygon-lack-of-balance-check-bugfix-postmortem-2-2m-bounty-64ec66c24c7d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/polygon-lack-of-balance-check-bugfix-postmortem-2-2m-bounty-64ec66c24c7d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polygon Lack Of Balance Check Bugfix Postmortem — $2.2m Bounty
Whitehat Leon Spacewalker reported a critical vulnerability in Polygon on December 3.
Whitehat Leon Spacewalker reported a critical vulnerability in Polygon on December 3.Continue reading on Immunefi » (https://medium.com/immunefi/polygon-lack-of-balance-check-bugfix-postmortem-2-2m-bounty-64ec66c24c7d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polygon Lack Of Balance Check Bugfix Postmortem — $2.2m Bounty
Whitehat Leon Spacewalker reported a critical vulnerability in Polygon on December 3.
Polygon Lack Of Balance Check Bugfix Postmortem — $2.2m Bounty
Whitehat Leon Spacewalker reported a critical vulnerability in Polygon on December 3.Continue reading on Immunefi »
Read more...
Whitehat Leon Spacewalker reported a critical vulnerability in Polygon on December 3.Continue reading on Immunefi »
Read more...
OTP bypass via response manipulation
Hello everyone I’m Jan Jeffrie Salloman, I started bug hunting 1 year ago. This writeup is about an OTP bypass using response manipulation…Continue reading on Medium »
Read more...
Hello everyone I’m Jan Jeffrie Salloman, I started bug hunting 1 year ago. This writeup is about an OTP bypass using response manipulation…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Comment se lancer et prospérer dans le business en ligne grâce au profit hacking ?
Comment faire pour bien démarrer dans l’entreprise en ligne et réussir ? Quels sont les facteurs clés qui font la différence entre les…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Comment se lancer et prospérer dans le business en ligne grâce au profit hacking ?
Comment faire pour bien démarrer dans l’entreprise en ligne et réussir ? Quels sont les facteurs clés qui font la différence entre les…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Comment se lancer et prospérer dans le business en ligne grâce au profit hacking ?
Comment faire pour bien démarrer dans l’entreprise en ligne et réussir ? Quels sont les facteurs clés qui font la différence entre les…