Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
PasteMonitor - Scrape Pastebin API To Collect Daily Pastes, Setup A Wordlist And Be Alerted By Email When You Have A Match

https://blogger.googleusercontent.com/img/a/AVvXsEj0oEbH8eFzVZJO8Wn9YRrVwzw59O8IK49MrTl10XDfYqacJocevZmNNsg4rA1KMn4aXRorIcBL57in_82njYztxLN9c4-RmpnvC_Px1lkdsfp-Lr8x0T9g-d8_uZwCJhqmO45zm1qx-bWZf-Z_M0mCU5VF78uCiyZrF_OzilSo28RPf25Kk10H8C5B=w640-h84 Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match. DescriptionThe PasteMonitor tool allows you to perform two main actions (for educational purposes only):

* Download daily new public pasteshttps://blogger.googleusercontent.com/img/a/AVvXsEg2YEeqFK9X8LEWA4sBql9jxuEaJ5k24vBSnV9r4z6mJynxUhdZmA1iKdC06lXQF9naq0FD-nvHb6IsBReFQDixvZscWJms2rJf0dfbAwevHcYdWeWOMOeFX2bczIkVOIwFrGSNuIMPd3r1NSFfbNNvw3043I1Y-ObfP8yAfdQzs33_iyhcZK0LZgUJ=w640-h176 Average number of pastes per day: 1000-3000 (filetype: .txt)

* Send automatic email alertYou can setup a wordlist and be alerted by email when you have a match https://blogger.googleusercontent.com/img/a/AVvXsEiofc59YOojB9khYIsRKxW0OHT6C48QSAJFhBemnKkLfygiJtIdj4PAgNCi1IoF0DsOFuLsv_nFYrxgD7-JbHNuF5i05gmUL-v2nBEJEnPVb0ZGu02C-VT5T5YLMu3lyasPAHKvUKEopViVE9C0gDh9veW4hcN4tLRkUlxY-VE8VS0UgSNJaMCaB10r=w640-h112 If your paste is no longer online, you can find it on your computer/server via the ID of your paste (here ID is "WJq2YxPg") https://blogger.googleusercontent.com/img/a/AVvXsEj0oEbH8eFzVZJO8Wn9YRrVwzw59O8IK49MrTl10XDfYqacJocevZmNNsg4rA1KMn4aXRorIcBL57in_82njYztxLN9c4-RmpnvC_Px1lkdsfp-Lr8x0T9g-d8_uZwCJhqmO45zm1qx-bWZf-Z_M0mCU5VF78uCiyZrF_OzilSo28RPf25Kk10H8C5B=w640-h84 Before startBefore starting the tool, make sure to:

* Get a Pastebin PRO account
* Enter the IP address of your machine in the "Your Account & Whitelisted IP" section
* Activate a mail account that can authorize a third party application (here we use a Gmail account)
* Enable 2-step verification
* Generate app password (for more help, see this tutorial)

Then, add to the code "pastemonitor.py":

* Email credentials ("email", "password")
* Email alert recipient ("receiver") WordlistIn the "wordlist.txt" file, add your keywords line by line. Prerequisitepip3 install -r requirements.txtUsagepython3 pastemonitor.pyPastebin.com usageVisit the official Pastebin webpage Scraping API. ContributingFeel free to clone this project. For major changes, please open an issue first to discuss what you would like to change. LicenseMIT Download PasteMonitor

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is rockyou still relevant?

I haven't had too many opportunities to test it, but the few times I've used rockyou with airmon/hashcat wifi cracking (controlled setting where I was being observed by the other party) ...it doesn't seem to match up very often. I'm wondering if rockyou is still important to have and use, or if other wordlists or methods are preferred.

I appreciate your input!

submitted by /u/5kidmark2
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Android:backupAgent with android:allowBackup is an security issue?

Hello everyone,

I am learning mobile pentesting and I like it. I was investigating the 'AndroidManifest.xml' file and I saw that android:allowBackup is set to true. I heard this was a vulnerability itself due sensitive information you can backup, see:

If backup flag is set to true, it allows an attacker to take the backup of the application data via adb even if the device is not rooted. Therefore applications that handle and store sensitive information such as card details, passwords etc.

But in this 'AndroidManifest.xml' there is a 'android:backupAgent'. Will this still be a vulnerability?

Kind regards,

GroundbreakingTea

submitted by /u/GroundbreakingTea195
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
For those interested in ATMs...

...there's an electrical company liquidating a few via auction in PA. Various states of disrepair; the best ones ~$42 as of this post. Check Rasmus auctions.

submitted by /u/realgoneman
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Breach Response Shift: More Lawyers, Less Cyber-Insurance Coverage

Companies are more likely to rely on outside attorneys to handle cyber response in order to contain potential lawsuits. Meanwhile, cyber-insurance premiums are rising but covering less.
Dark Reading: Attacks/Breaches
Microsoft: macOS 'Powerdir' Flaw Could Let Attackers Gain Access to User Data

The vulnerability could allow an attacker to bypass the macOS Transparency, Consent, and Control measures to access a user's protected data.