Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Looking for advice.

Hi everyone, I’m at my wits end. So I run a business mostly through social media and I’ve been having problems with people impersonating my accounts and stealing my intellectual property and scamming people in my name. I need this to stop. If I’m in the wrong place, please point me in the right direction. I don’t know what to do but I’m losing business and slowly, my sanity. If there’s something that can be done, it’s a regular occurrence and I would compensate handsomely for any help if this could be taken care of. TIA!

submitted by /u/Ekonomix-
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is this type of shell script exploitable

Hi guys,

So I came across a shell script. What it does is catout files based on the directory input. The file name is showfiles.sh. It only accepts 1 parameter which ofc is the directory+theFile. Like showfiles.sh /tmp/fake_log.txt

It also filters out ../../

And the main part comes here. It only allows to read a few files from a few directories. Let's say it only allows the directories /tmp , /varand then inside those directories a few files and a few directories.

Now how would you exploit this script to either read the other files or to run shell commands?

submitted by /u/aNerdLurkingAround
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do bots/spammers get past account creation requirements?

I apologize if this is the wrong place for this and will delete if so, but I’m curious about this subject. I create and maintain new accounts for OSINT investigations and I’m often forced to use some kind of “real”, non-VOIP phone number—and landlines don’t count.

So how are so many bots/spammers able to get around these requirements without shelling out a lot of money on burner phones for account creation? Or is that what they’re actually doing?

submitted by /u/Killer_Bhree
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
hacking into cycling computer to display custom data

Just out of curiosity, with knowing virtually nothing about hacking, i have a question for this community. Would it be possible to somehow get into the software on my 'bryton rider 320' to get it to display certain numbers which I can put in via an app? Where I live we have this cycling network which relies on (rough translation) 'intersection points', numbers which you select beforehand and which you can follow, thus following the route you planned. It always has always bothered me that almost no cycling computer allows for these numbers to be put into the device and stored. Everytime you have to either remember it, put it in your phone or on a piece of paper that you tape to your bike. So i was wondering if it was possible to hack into my device and alter the software in such a way that allows it to store these numbers.

submitted by /u/no-meme-lord69
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Web Application Security Training/Tutorial/Certificate

Hello,

I already have OSCP but I would like to refresh my web security skills and go deeper in that domain. I have a budget of 5k that I can spend on any training/tutorial/certificate available. I learn more by watching videos. Any recommendations?

submitted by /u/Snoo_68846
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Any RCE or other exploits for an akado sagemcom f@st 3284(not sure) router?

So basically i need to access the login and password of this router, but i can't reset it to factory defaults;

I tried routersploit but no results;This is mine/not mine router(family member's);

I need to access the web interface of the router;

If you're interested in more details about why do I need login credentials of this router, please contact me in DM's.

I have no malicious intents(again details in DM's);

Thanks.

submitted by /u/ummwhite
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best Approach to gaining an advantage?

So I have a workplace that uses a mobile app (and I recently just discovered webpage) to manage scheduling. When a shift becomes available they'll send it to everyone who's eligible and it falls under a FCFS basis. Well I need to make some extra income and instead of applying for a second job I would rather take advantage of this. Now they send an Email and text message when an open shift is available but a simple "ding" rarely gets my attention. I would like to set up a monitor on the webpage that will claim any open shift that's available while it's running. Ideally something I can host on a thin client or even a junk cell phone (I've recently moved and can't afford internet service but my workplace has wifi). I'm not very experienced with this, I know I have to monitor the website to see what triggers I can use (such as when a shift is available what changes on the backed that can be picked up) and then figure out how to configure a web browser to refresh every minute or so, recognize the change and trigger a series of actions that tell the webpage that I've claimed that available shift.



I personally don't know the best way to go about this, I just have a child on the way and any more income per pay period will help.

submitted by /u/cmb271
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video