Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pegasus Spyware | How Pegasus hacks your phone? | Israel NSO
https://cdn-images-1.medium.com/max/750/1*2jEyBQvbev81unAX3H1D2Q.jpeg
A committee set up by the Supreme Court to look into allegations of human misconduct using the Pegasus spy invited all residents who…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pegasus Spyware | How Pegasus hacks your phone? | Israel NSO
https://cdn-images-1.medium.com/max/750/1*2jEyBQvbev81unAX3H1D2Q.jpeg
A committee set up by the Supreme Court to look into allegations of human misconduct using the Pegasus spy invited all residents who…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pegasus Spyware | How Pegasus hacks your phone? | Israel NSO
A committee set up by the Supreme Court to look into allegations of human misconduct using the Pegasus spy invited all residents who…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
From .git directory to AWS EC2 network takeover
https://cdn-images-1.medium.com/max/788/1*7njzWpv72WXPe5smECbJtQ.png
Last week I was performing a penetration test. I was performing the test according to my own methodology and an interesting .git directory…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
From .git directory to AWS EC2 network takeover
https://cdn-images-1.medium.com/max/788/1*7njzWpv72WXPe5smECbJtQ.png
Last week I was performing a penetration test. I was performing the test according to my own methodology and an interesting .git directory…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
From .git directory to AWS EC2 network takeover
Last week I was performing a penetration test. I was performing the test according to my own methodology and an interesting .git directory…
IDOR leads to leak Private Details
I Wish you Merry Christmas & happy new year to you readers. May this year bring us nothing more than love, joy, happiness, P1,P2…
Read more...
___________________________
@hacking_Attack
@Hacking_Video
I Wish you Merry Christmas & happy new year to you readers. May this year bring us nothing more than love, joy, happiness, P1,P2…
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR leads to leak Private Details
I Wish you Merry Christmas & happy new year to you readers. May this year bring us nothing more than love, joy, happiness, P1,P2…
airbus-cert/Invoke-Bof: Load any Beacon Object File using Powershell!
https://www.reddit.com/r/redteamsec/comments/ruxbl4/airbuscertinvokebof_load_any_beacon_object_file/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://github.com/airbus-cert/Invoke-Bof) [comments] (https://www.reddit.com/r/redteamsec/comments/ruxbl4/airbuscertinvokebof_load_any_beacon_object_file/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ruxbl4/airbuscertinvokebof_load_any_beacon_object_file/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://github.com/airbus-cert/Invoke-Bof) [comments] (https://www.reddit.com/r/redteamsec/comments/ruxbl4/airbuscertinvokebof_load_any_beacon_object_file/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
airbus-cert/Invoke-Bof: Load any Beacon Object File using Powershell!
Posted in r/redteamsec by u/dmchell • 1 point and 0 comments
IDOR leads to leak Private Details
I Wish you Merry Christmas & happy new year to you readers. May this year bring us nothing more than love, joy, happiness, P1,P2…Continue reading on InfoSec Write-ups »
Read more...
___________________________
@hacking_Attack
@Hacking_Video
I Wish you Merry Christmas & happy new year to you readers. May this year bring us nothing more than love, joy, happiness, P1,P2…Continue reading on InfoSec Write-ups »
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR leads to leak Private Details
I Wish you Merry Christmas & happy new year to you readers. May this year bring us nothing more than love, joy, happiness, P1,P2…
hacking: security in practice
Am I being hacked ?
Hello guys, I actually think I am hacked so I have a few questions after this.
1 I can't browse any anti virus websites, they don't load at all.
2 discord was hacked ( I guess ) some fake ads been sent to all ppl I talked to before even years ago.
3 someone tried to log in into my gmail accounts but I enabled 2 factors auth already before that, I got warning from gmail that there are suspicious acts in my gmail accounts all my accounts.
4 my fb got hacked, someone who hacked my fb, enabled 2 factor auth so I can't get my fb back I think.
the question, I am thinking to do recovery reset ( without losing my personal files ) will that remove whatever viruses on my laptop ?
submitted by /u/mrmouha99
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Am I being hacked ?
Hello guys, I actually think I am hacked so I have a few questions after this.
1 I can't browse any anti virus websites, they don't load at all.
2 discord was hacked ( I guess ) some fake ads been sent to all ppl I talked to before even years ago.
3 someone tried to log in into my gmail accounts but I enabled 2 factors auth already before that, I got warning from gmail that there are suspicious acts in my gmail accounts all my accounts.
4 my fb got hacked, someone who hacked my fb, enabled 2 factor auth so I can't get my fb back I think.
the question, I am thinking to do recovery reset ( without losing my personal files ) will that remove whatever viruses on my laptop ?
submitted by /u/mrmouha99
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Am I being hacked ?
Hello guys, I actually think I am hacked so I have a few questions after this. 1 I can't browse any anti virus websites, they don't load at...
hacking: security in practice
What is the easiest way to find somebodys address (or any other data) If i have their IP
Dont worry its a friend of mine. i want to troll him a bit.
submitted by /u/Able_Sugar_284
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is the easiest way to find somebodys address (or any other data) If i have their IP
Dont worry its a friend of mine. i want to troll him a bit.
submitted by /u/Able_Sugar_284
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is the easiest way to find somebodys address (or any other...
Dont worry its a friend of mine. i want to troll him a bit.
P5 to P1: Intresting Account Takeover
https://medium.com/@tushar.tilak.sharma/p5-to-p1-intresting-account-takeover-6e59b879494b?source=rss------bug_bounty-5
Hello Guys,Continue reading on Medium » (https://medium.com/@tushar.tilak.sharma/p5-to-p1-intresting-account-takeover-6e59b879494b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@tushar.tilak.sharma/p5-to-p1-intresting-account-takeover-6e59b879494b?source=rss------bug_bounty-5
Hello Guys,Continue reading on Medium » (https://medium.com/@tushar.tilak.sharma/p5-to-p1-intresting-account-takeover-6e59b879494b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
P5 to P1: Intresting Account Takeover
Hello Guys,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacker steals $2 million by exploiting a bug on Polygon
https://cdn-images-1.medium.com/max/750/0*w12YEmwLO5l0hGyT
After the discovery of a vulnerability linked to its MRC20 contract, Polygon decided to update its network in order to correct this bug…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Hacker steals $2 million by exploiting a bug on Polygon
https://cdn-images-1.medium.com/max/750/0*w12YEmwLO5l0hGyT
After the discovery of a vulnerability linked to its MRC20 contract, Polygon decided to update its network in order to correct this bug…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacker steals $2 million by exploiting a bug on Polygon
After the discovery of a vulnerability linked to its MRC20 contract, Polygon decided to update its network in order to correct this bug…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CyCraft Collaborates with Semiconductor Industry to Strengthen Supply Chain Security
https://cdn-images-1.medium.com/max/1600/0*gzYSCexewsmmK_8B
Taipei, Taiwan — January 3, 2022 — CyCraft, a leading managed detection and response provider (MDR) based in Taiwan, joined hands with…
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
CyCraft Collaborates with Semiconductor Industry to Strengthen Supply Chain Security
https://cdn-images-1.medium.com/max/1600/0*gzYSCexewsmmK_8B
Taipei, Taiwan — January 3, 2022 — CyCraft, a leading managed detection and response provider (MDR) based in Taiwan, joined hands with…
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CyCraft Collaborates with Semiconductor Industry to Strengthen Supply Chain Security
Taipei, Taiwan — January 3, 2022 — CyCraft, a leading managed detection and response provider (MDR) based in Taiwan, joined hands with…
Msmailprobe - Office 365 And Exchange Enumeration
http://www.kitploit.com/2022/01/msmailprobe-office-365-and-exchange.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/01/msmailprobe-office-365-and-exchange.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Msmailprobe - Office 365 And Exchange Enumeration
Office 365 and Exchange EnumerationIt is widely known that OWA (Outlook Webapp) is vulnerable (https://www.kitploit.com/search/label/Vulnerable) to time-based user enumeration (https://www.kitploit.com/search/label/User%20Enumeration) attacks. This tool leverages all known, and even some lesser-known services exposed by default Exchange installations to enumerate users. It also targets Office 365 for error-based user enumeration.
Getting StartedIf you want to download and compile the simple, non-dependant code, you must first install GoLang! I will let the incredible documentation, and other online resources help you with this task.https://golang.org/doc/installYou may also download the compiled release here (https://github.com/customsync/msmailprobe/releases).SyntaxList examples of commands for this applications, but simply running the binary with the examples command:./msmailprobe examples
You can also get more specific help by running the binary with the arguments you are interested in:./msmailprobe identify
./msmailprobe userenum
./msmailprobe userenum --onprem
./msmailprobe userenum --o365
UsageIdentify CommandUsed for gathering (https://www.kitploit.com/search/label/Gathering) information about a host that may be pointed towards an Exchange or o365 tied domainQueries for specific DNS records related to Office 365 integrationAttempts to extract internal domain name for onprem instance of ExchangeIdentifies services vulnerable to time-based user enumeration (https://www.kitploit.com/search/label/Enumeration) for onprem ExchangeLists password-sprayable services exposed for onprem Exchange hostFlag to use:
-t to specify target host
Example:
./msmailprobe identify -t mail.target.com
Userenum (o365) CommandError-based user enumeration for Office 365 integrated email addressesFlags to use:
-E for email list OR -e for single email address
-o [optional]to specify an out file for valid emails identified
--threads [optional] for setting amount of requests to be made concurrently
Examples:
./msmailprobe userenum --o365 -E emailList.txt -o validemails.txt --threads 25
./msmailprobe userenum --o365 -e admin@target.com
Userenum (onprem) CommandTime-based user enumeration against multiple onprem Exchange servicesFlags to use:
-t to specify target host
-U for user list OR -u for single username
-o [optional]to specify an out file for valid users identified
--threads [optional] for setting amount of requests to be made concurrently
Examples:
./msmailprobe userenum --onprem -t mail.target.com -U userList.txt -o validusers.txt --threads 25
./msmailprobe userenum --onprem -t mail.target.com -u admin
Acknowledgmentspoptart - For a truck load of golang assistance, poking of Exchange services, and help testing timing of responsesjlarose - Parsing decimal data within NTLMSSP authentication (https://www.kitploit.com/search/label/Authentication) reponse for internal domain nameVincent Yui - Office 365 check python scriptgrimhacker - Discovery/disclosure of error-based user enumeration within Office 365 blog post (https://grimhacker.com/2017/07/24/office365-activesync-username-enumeration/)Nate Power - Discovery and disclosure of OWA time-based user enumerationLicenseThis project is licensed under the MIT License - see the LICENSE.md (https://github.com/customsync/msmailprobe/blob/master/LICENSE) file for details
Download Msmailprobe (https://github.com/busterb/msmailprobe)
___________________________
@hacking_Attack
@Hacking_Video
Getting StartedIf you want to download and compile the simple, non-dependant code, you must first install GoLang! I will let the incredible documentation, and other online resources help you with this task.https://golang.org/doc/installYou may also download the compiled release here (https://github.com/customsync/msmailprobe/releases).SyntaxList examples of commands for this applications, but simply running the binary with the examples command:./msmailprobe examples
You can also get more specific help by running the binary with the arguments you are interested in:./msmailprobe identify
./msmailprobe userenum
./msmailprobe userenum --onprem
./msmailprobe userenum --o365
UsageIdentify CommandUsed for gathering (https://www.kitploit.com/search/label/Gathering) information about a host that may be pointed towards an Exchange or o365 tied domainQueries for specific DNS records related to Office 365 integrationAttempts to extract internal domain name for onprem instance of ExchangeIdentifies services vulnerable to time-based user enumeration (https://www.kitploit.com/search/label/Enumeration) for onprem ExchangeLists password-sprayable services exposed for onprem Exchange hostFlag to use:
-t to specify target host
Example:
./msmailprobe identify -t mail.target.com
Userenum (o365) CommandError-based user enumeration for Office 365 integrated email addressesFlags to use:
-E for email list OR -e for single email address
-o [optional]to specify an out file for valid emails identified
--threads [optional] for setting amount of requests to be made concurrently
Examples:
./msmailprobe userenum --o365 -E emailList.txt -o validemails.txt --threads 25
./msmailprobe userenum --o365 -e admin@target.com
Userenum (onprem) CommandTime-based user enumeration against multiple onprem Exchange servicesFlags to use:
-t to specify target host
-U for user list OR -u for single username
-o [optional]to specify an out file for valid users identified
--threads [optional] for setting amount of requests to be made concurrently
Examples:
./msmailprobe userenum --onprem -t mail.target.com -U userList.txt -o validusers.txt --threads 25
./msmailprobe userenum --onprem -t mail.target.com -u admin
Acknowledgmentspoptart - For a truck load of golang assistance, poking of Exchange services, and help testing timing of responsesjlarose - Parsing decimal data within NTLMSSP authentication (https://www.kitploit.com/search/label/Authentication) reponse for internal domain nameVincent Yui - Office 365 check python scriptgrimhacker - Discovery/disclosure of error-based user enumeration within Office 365 blog post (https://grimhacker.com/2017/07/24/office365-activesync-username-enumeration/)Nate Power - Discovery and disclosure of OWA time-based user enumerationLicenseThis project is licensed under the MIT License - see the LICENSE.md (https://github.com/customsync/msmailprobe/blob/master/LICENSE) file for details
Download Msmailprobe (https://github.com/busterb/msmailprobe)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Story of YouTube’s Unfixable Ads Bypass
https://medium.com/@mrmax4o4/story-of-youtubes-unfixable-ads-bypass-b3bb7016c14e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mrmax4o4/story-of-youtubes-unfixable-ads-bypass-b3bb7016c14e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Story of YouTube’s Unfixable Ads Bypass
Hello there!
I hope everything is going well with you; today I will talk about my YouTube Ads bypass.
I hope everything is going well with you; today I will talk about my YouTube Ads bypass.