Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Possible Vulnerability in school?

My school has lots of sites blocked, but I found an online terminal that wasn’t. I managed to download a network scanner and arp spoofer onto the terminal. I also have access to the IP address of the chromebook. Should I report this site to my school’s IT department?

Edit: I just learned that I can’t actually do anything with what I have, so it’s all good 👍

submitted by /u/ari_02468
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How would someone given a name and phone number use an IMSI catcher to tag an IMSI/IMEI/other to that?

The motivation for this question comes from https://arstechnica.com/information-technology/2015/10/low-cost-imsi-catcher-for-4glte-networks-track-phones-precise-locations/

They claim that you can attach to and request information like IMEI/IMSI in 4G and that this is a security concern.

My understanding is that, if you build an IMSI catcher, and turn it on with the right settings, you see a list of IMSIs, but not phone numbers. This makes it hard to obtain useful information unless you have access to a cell phone service provider database or are a cop.

Perhaps you could obtain more information by downgrading the 4G user's service, but then it's like whackamole, right? Try 600 IMSIs and see if you hit one..

I suppose my question is, given only a name, phone number and geographic location, could someone reasonably use an IMSI catcher to tag an individual with an IMEI/IMSI or other information? Is it practically possible to find specific information on a specific person using this technique?

*Asking out of curiosity and out of concern for myself. Chill NSA

submitted by /u/anon314159265358p
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Exploiting Execute After Redirect (EAR) vulnerability in HTB Previse

Exploiting Execute After Redirect for fun and profit??
Read more...
WEB APPLICATION — BUSINESS LOGIC VULNERABILITIES

Buisness logic vulnerabilities are flaw in the design, implementation and concept of an application, that allow an attacker to evoke…
Read more...
A TALE OF 5250$ : HOW I ACCESSED MILLIONS OF USER’S DATA INCLUDING THEIR NATIONAL ID’S

Hi, Hope you guys are doing well, And a Happy New Year, YAY! , Let’s start the blog without wasting more time.
Read more...
HOW I AM ABLE TO CRASH ANYONE’S MOZILLA FIREFOX BROWSER BY SENDING AN EMAIL

Hi, Hope you guys are doing well, Here is the story of how I am able to crash anyone’s Mozilla firefox by just sending a single email…
Read more...
HOW I GOT MY FIRST RCE WHILE LEARNING PYTHON

Hi,
Read more...
hacking: security in practice
You can block Accounts that are used to advertise on Reddit.

Imagine if we got the message to the wider community that all you need to do to block an add from showing up in your feed is to just block the user. If nothing else that will force the marketing team that runs it to have to constantly open an manage new user accounts. Costly and time consuming.

submitted by /u/Mastronauts84
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video