Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Researcher discovers 70 web cache poisoning vulnerabilities, nets $40k in bug bounty rewards https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Researcher discovers 70 web cache poisoning vulnerabilities…
ortSwigger’s Param Miner, an open source tool that can identify hidden, unlinked parameters. Running Param Miner against web applications can help detect unkeyed headers that can be used for web cache poisoning.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/1200x0-90x90.jpg Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/exchange-90x90.png Microsoft releases emergency fix for Exchange – 2022 bug2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/maxresdefault-90x90.jpg Have I Been Pwned adds 441K accounts stolen by RedLine malware5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/1229111902.0-90x90.jpg T-Mobile says new data breach caused by SIM swap attacks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/feature-log4j-blue-90x90.png Log4j 2.17.1 out now, fixes new remote code execution bug7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/qnap-logo-white-90x90.jpg QNAP NAS devices hit in surge of ech0raix ransomware attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/shutterstock_495927541-90x90.jpg Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/apple-store-tower-90x90.jpg Apple fixes macOS security flaw behind Gatekeeper bypass2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5157-article-201208-ms-team_body_text-90x90.jpg Microsoft Teams bug allowing phishing unpatched since March2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-6-90x90.jpg 800K WordPress sites still impacted by critical SEO plugin flaw2 weeks ago
The post Researcher discovers 70 web cache poisoning vulnerabilities, nets $40k in bug bounty rewards first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Top 5 Incident Response Courses/Certifications

I started doing a little research a few weeks ago, looking at the best courses in the market for Penetration Testing, Incident Response and Threat Intelligence. I've been asking people across Reddit and other forums for their input.

Not going to lie, it's been a little bit harder than I first thought and I've had to change my expectations somewhat. Firstly, my top 10 as far as Incident Response goes is now top 5 and secondly I've had to include examination syllabus's too.

1. FOR508 by SANS (Course + Exam)
2. CRIA by CREST (Exam)
3. eCIR by eLearn Security (Exam)
4. BTL1 by Security Blue Team (Course + Exam)
5. BTL2 by Security Blue Team (Course + Exam)

As with my previous post, I do not work for any of these companies and I actively encourage people to do their own research and undertake as much free training as possible too!

The Security Blue Team fans have been pretty vocal about the training on offer, though I personally have not undertaken any of their training... so it would be interesting to hear your thoughts about their courses.

Would you add any other courses/certs to this list?

r/cybersecuritytraining

submitted by /u/MoaningKnight
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
How I was able to spoof any Instagram username on Instagram shop

Summary: i discovered that i can spoof any Instagram username on Instagram shop, with this bug scammers can trick people into thinking…Continue reading on Medium »
Read more...
hacking: security in practice
I'm struggling to find an old link generator website.

So, there was a website where you can create a bunch of login links but they are actually malicious and sending your login details to the person that created the link; the website just came to my mind for no reason today and I noticed that can't remember its name.

If I remember it wrong, the website's symbol was an anonymous mask; there were literally fake links for every website, and I don't remember any more specific details; can anyone help me with finding the website?

submitted by /u/HyperHyoko
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video