Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Host Header Injection Lead To Account Takeover
Hello amazing hacker, Today, I want to talk about one of my finding in private pentest program that lead me takeover other user account by…
Continue reading on Medium »
Host Header Injection Lead To Account Takeover
Hello amazing hacker, Today, I want to talk about one of my finding in private pentest program that lead me takeover other user account by…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Network Domination & Persistence
https://cdn-images-1.medium.com/max/1000/0*4pGViGQk41Y855Kl.png
*Note: This article was originally published by the author on November 17, 2018.
Continue reading on Medium »
Network Domination & Persistence
https://cdn-images-1.medium.com/max/1000/0*4pGViGQk41Y855Kl.png
*Note: This article was originally published by the author on November 17, 2018.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Log4J vulnerability explained for Developers
https://cdn-images-1.medium.com/max/2600/0*7jVj78WaMgQ8Qfvz
Don’t let your Java program get hacked
Continue reading on Level Up Coding »
The Log4J vulnerability explained for Developers
https://cdn-images-1.medium.com/max/2600/0*7jVj78WaMgQ8Qfvz
Don’t let your Java program get hacked
Continue reading on Level Up Coding »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
LordOfRoot VM WlakThrough
https://cdn-images-1.medium.com/max/831/0*4XD8rFFMxZ6_YvXy.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
LordOfRoot VM WlakThrough
https://cdn-images-1.medium.com/max/831/0*4XD8rFFMxZ6_YvXy.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
IgniteCTF
https://cdn-images-1.medium.com/max/1124/1*Sa9TUKgVw4E34REIhFXy9w.png
A beginner Friendly CTF Ignite Hosted on TryHackme created by DarkStar7471.
Continue reading on Medium »
IgniteCTF
https://cdn-images-1.medium.com/max/1124/1*Sa9TUKgVw4E34REIhFXy9w.png
A beginner Friendly CTF Ignite Hosted on TryHackme created by DarkStar7471.
Continue reading on Medium »
hacking: security in practice
Activism, student loans
I've never seen the answer for this so pardon me if this is a stupid question;
I know hacktivists often use their skills to support a cause, and that's obviously super admirable.
I've seen non-hackers conversationally question why hacktivists don't ever "erase student loans." So I'm wondering - is it just too hard? Is it one of those things where we laypeople just don't have the knowledge to know it doesn't work that way? How does it work?
Asking for myself, who will likely die still in debt for my stupid student loans. 🙃
submitted by /u/carrie_fister
[link] [comments]
Activism, student loans
I've never seen the answer for this so pardon me if this is a stupid question;
I know hacktivists often use their skills to support a cause, and that's obviously super admirable.
I've seen non-hackers conversationally question why hacktivists don't ever "erase student loans." So I'm wondering - is it just too hard? Is it one of those things where we laypeople just don't have the knowledge to know it doesn't work that way? How does it work?
Asking for myself, who will likely die still in debt for my stupid student loans. 🙃
submitted by /u/carrie_fister
[link] [comments]
reddit
Activism, student loans
I've never seen the answer for this so pardon me if this is a stupid question; I know hacktivists often use their skills to support a cause, and...
hacking: security in practice
Reversible databending?
I've messed around with databending art before using stuff like audacity, but I've always wondered whether this process could be reversed to reveal the original image. Sort of as a security through obscurity take on steganography.
submitted by /u/0neEyedBirb
[link] [comments]
Reversible databending?
I've messed around with databending art before using stuff like audacity, but I've always wondered whether this process could be reversed to reveal the original image. Sort of as a security through obscurity take on steganography.
submitted by /u/0neEyedBirb
[link] [comments]
reddit
Reversible databending?
I've messed around with databending art before using stuff like audacity, but I've always wondered whether this process could be reversed to...
hacking: security in practice
Pegasus (Blue Team)
Has anyone detected Pegasus in the wild? How did you manage detecting it?
submitted by /u/oldjalepeno
[link] [comments]
Pegasus (Blue Team)
Has anyone detected Pegasus in the wild? How did you manage detecting it?
submitted by /u/oldjalepeno
[link] [comments]
reddit
Pegasus (Blue Team)
Has anyone detected Pegasus in the wild? How did you manage detecting it?
hacking: security in practice
Can a p2p network be Ddosed
I’ve been thinking about this question for some time. Is it possible to crash a p2p network with attacks such as Ddosing?
submitted by /u/DarthPalpatine66
[link] [comments]
Can a p2p network be Ddosed
I’ve been thinking about this question for some time. Is it possible to crash a p2p network with attacks such as Ddosing?
submitted by /u/DarthPalpatine66
[link] [comments]
reddit
Can a p2p network be Ddosed
I’ve been thinking about this question for some time. Is it possible to crash a p2p network with attacks such as Ddosing?
hacking: security in practice
School implementing SSL inspection
Recently we received an email from our IT department asking us to install a certificate on all our devices (laptops, phones etc.) in order to continue using the school WIFI. In the email it said they’ll be using this to implement SSL inspection to “protect the school network from cyber threats”. My school has a zero tolerance policy on VPNs but it’s always been an uphill battle for them with pupils always finding a VPN they can’t detect in order to access blocked services such as Snapchat at school. (Schools in the middle of nowhere with no mobile service so cellular data isn’t an option)
Is this potentially a way of them easily detecting VPNs? Is this even legal? Should we be worried?
submitted by /u/Franic_123
[link] [comments]
School implementing SSL inspection
Recently we received an email from our IT department asking us to install a certificate on all our devices (laptops, phones etc.) in order to continue using the school WIFI. In the email it said they’ll be using this to implement SSL inspection to “protect the school network from cyber threats”. My school has a zero tolerance policy on VPNs but it’s always been an uphill battle for them with pupils always finding a VPN they can’t detect in order to access blocked services such as Snapchat at school. (Schools in the middle of nowhere with no mobile service so cellular data isn’t an option)
Is this potentially a way of them easily detecting VPNs? Is this even legal? Should we be worried?
submitted by /u/Franic_123
[link] [comments]
reddit
School implementing SSL inspection
Recently we received an email from our IT department asking us to install a certificate on all our devices (laptops, phones etc.) in order to...
hacking: security in practice
Rainbow table torrents
I'm gearing up for another password policy compliance audit and wanted to give it a shot using a rainbow table on top of my usual John/Hashcat run.
The NTLM torrent I tried to grab from freerainbowtables.com seems to only have only peers (unless something is blocking the others) that are incomplete so everything stalls at 5-15%. Before I go out of my way to generate 400GB+ of data, are there any other good sources of NTLM tables?
If i use the text files from rainbow crack, which is just a list of rtgen commands, is there a good way to run it line by line (using eval is always sketchy but every line in the file checks out)?
submitted by /u/766972
[link] [comments]
Rainbow table torrents
I'm gearing up for another password policy compliance audit and wanted to give it a shot using a rainbow table on top of my usual John/Hashcat run.
The NTLM torrent I tried to grab from freerainbowtables.com seems to only have only peers (unless something is blocking the others) that are incomplete so everything stalls at 5-15%. Before I go out of my way to generate 400GB+ of data, are there any other good sources of NTLM tables?
If i use the text files from rainbow crack, which is just a list of rtgen commands, is there a good way to run it line by line (using eval is always sketchy but every line in the file checks out)?
submitted by /u/766972
[link] [comments]
reddit
Rainbow table torrents
I'm gearing up for another password policy compliance audit and wanted to give it a shot using a rainbow table on top of my usual John/Hashcat...
Authentication Bypass & ATO
https://medium.com/@86karthikkarthik/authentication-bypass-ato-ebdc5da62c46?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@86karthikkarthik/authentication-bypass-ato-ebdc5da62c46?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Authentication Bypass & ATO
Hi guys this is Karthik. I hope you all are doing good. I’m back with another interesting write-up “Authentication Bypass which leads to…