Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hunting for Bugs in File Upload Feature:

In this blog, I will be listing down some file upload Vulnerability such RCE, SSRF, CSRF, XSS and many more such vulnerabilities.Continue reading on Medium »
Read more...
Astroport Boosts Bug Bounty to $3m, Takes Top Leaderboard Spot

Astroport has just doubled its critical bug bounty reward from $1.5m to $3m, making it the largest bounty on Immunefi’s platform, beating…Continue reading on Immunefi »
Read more...
Hack Us Will You?

Delorians,Continue reading on Medium »
Read more...
Red & Blue-Team Quick Reference Gitbooks
https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/

https://preview.redd.it/fr6me9amad881.png?width=2250&format=png&auto=webp&s=b41dfae9c724d1f9519dca8fb2317b91d4c8c778 Hi everyone! I would like to share with you one of my gitbooks, focused on DFIR, Malware and Blue-Team in general. Is a WIP in progress. Im actually adding more and more things while myself learn along the way. 📘 Hunter - Jorge Testa (https://hunter.jorgetesta.tech/) There you have my Red-Team version. WIP too. 📕 Tryharder - Jorge Testa (https://tryharder.jorgetesta.tech/) Hope you like it! submitted by /u/J-Testa (https://www.reddit.com/user/J-Testa)
[link] (https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/) [comments] (https://www.reddit.com/r/redteamsec/comments/rqsz7k/red_blueteam_quick_reference_gitbooks/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Trouble recreating Log4j with Minecraft

I'm attempting to recreate the famous Log4j vulnerability with Minecraft. I've been following this video, and I had some success in getting the vulnerability to work just before Christmas. I've revisited it just today, and now cannot get anything to work. The only difference between these days is a Windows update that ran on the computer hosting the Minecraft client (the one I'm using to send the malicious message). I didn't believe that this would impact anything, but it seems to have done something, as the malicious messages now do nothing.

Also noteworthy: I had some success getting the server (old vulnerable version of paperMC as provided in the video) to "exploit itself" by using the /say command in the server's terminal directly, however even this seems to have broken, despite the server never updating



Did someone patch some software very recently? I can provide much more detail if necessary.



Thank you!

submitted by /u/Mindstorm89
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Polygon Lack Of Balance Check Bugfix Postmortem — $2.2m Bounty

Whitehat Leon Spacewalker reported a critical vulnerability in Polygon on December 3.Continue reading on Immunefi »
Read more...
OTP bypass via response manipulation

Hello everyone I’m Jan Jeffrie Salloman, I started bug hunting 1 year ago. This writeup is about an OTP bypass using response manipulation…Continue reading on Medium »
Read more...