Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
This CTF-Style Challenge Teaches How to Deep Dive into Gmail OSINT Techniques
https://external-preview.redd.it/hiieJUHsdWl9Lf73l1cSoUCeK4HxyxtcJhvWCOivBJI.jpg?width=640&crop=smart&auto=webp&s=b1b8522bd50d955b775da09d872da48f8c584bc7 submitted by /u/Rebel_Ye11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
This CTF-Style Challenge Teaches How to Deep Dive into Gmail OSINT Techniques
https://external-preview.redd.it/hiieJUHsdWl9Lf73l1cSoUCeK4HxyxtcJhvWCOivBJI.jpg?width=640&crop=smart&auto=webp&s=b1b8522bd50d955b775da09d872da48f8c584bc7 submitted by /u/Rebel_Ye11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
This CTF-Style Challenge Teaches How to Deep Dive into Gmail OSINT...
Posted in r/hacking by u/Rebel_Ye11 • 1 point and 0 comments
hacking: security in practice
Is rockyou still relevant?
I haven't had too many opportunities to test it, but the few times I've used rockyou with airmon/hashcat wifi cracking (controlled setting where I was being observed by the other party) ...it doesn't seem to match up very often. I'm wondering if rockyou is still important to have and use, or if other wordlists or methods are preferred.
I appreciate your input!
submitted by /u/5kidmark2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is rockyou still relevant?
I haven't had too many opportunities to test it, but the few times I've used rockyou with airmon/hashcat wifi cracking (controlled setting where I was being observed by the other party) ...it doesn't seem to match up very often. I'm wondering if rockyou is still important to have and use, or if other wordlists or methods are preferred.
I appreciate your input!
submitted by /u/5kidmark2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Android:backupAgent with android:allowBackup is an security issue?
Hello everyone,
I am learning mobile pentesting and I like it. I was investigating the 'AndroidManifest.xml' file and I saw that android:allowBackup is set to true. I heard this was a vulnerability itself due sensitive information you can backup, see:
If backup flag is set to true, it allows an attacker to take the backup of the application data via adb even if the device is not rooted. Therefore applications that handle and store sensitive information such as card details, passwords etc.
But in this 'AndroidManifest.xml' there is a 'android:backupAgent'. Will this still be a vulnerability?
Kind regards,
GroundbreakingTea
submitted by /u/GroundbreakingTea195
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Android:backupAgent with android:allowBackup is an security issue?
Hello everyone,
I am learning mobile pentesting and I like it. I was investigating the 'AndroidManifest.xml' file and I saw that android:allowBackup is set to true. I heard this was a vulnerability itself due sensitive information you can backup, see:
If backup flag is set to true, it allows an attacker to take the backup of the application data via adb even if the device is not rooted. Therefore applications that handle and store sensitive information such as card details, passwords etc.
But in this 'AndroidManifest.xml' there is a 'android:backupAgent'. Will this still be a vulnerability?
Kind regards,
GroundbreakingTea
submitted by /u/GroundbreakingTea195
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Android:backupAgent with android:allowBackup is an security issue?
Hello everyone, I am learning mobile pentesting and I like it. I was investigating the 'AndroidManifest.xml' file and I saw that...
hacking: security in practice
For those interested in ATMs...
...there's an electrical company liquidating a few via auction in PA. Various states of disrepair; the best ones ~$42 as of this post. Check Rasmus auctions.
submitted by /u/realgoneman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
For those interested in ATMs...
...there's an electrical company liquidating a few via auction in PA. Various states of disrepair; the best ones ~$42 as of this post. Check Rasmus auctions.
submitted by /u/realgoneman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
For those interested in ATMs...
...there's an electrical company liquidating a few via auction in PA. Various states of disrepair; the best ones ~$42 as of this post. Check...
Free Online Hash Cracking Websites
https://skynettools.medium.com/free-online-hash-cracking-websites-1fad721d236c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://skynettools.medium.com/free-online-hash-cracking-websites-1fad721d236c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Free Online Hash Cracking Websites
Cracking password hashes on your own without the proper hardware can become time-consuming and tedious. Luckily for those capped by their…
Cracking password hashes on your own without the proper hardware can become time-consuming and tedious. Luckily for those capped by their…Continue reading on Medium » (https://skynettools.medium.com/free-online-hash-cracking-websites-1fad721d236c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Free Online Hash Cracking Websites
Cracking password hashes on your own without the proper hardware can become time-consuming and tedious. Luckily for those capped by their…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
FBI Warns FIN7 Campaign Delivers Ransomware via BadUSB
An FBI warning says the FIN7 cybercrime group has sent packages containing malicious USB drives to US companies in an effort to spread ransomware.
___________________________
@hacking_Attack
@Hacking_Video
FBI Warns FIN7 Campaign Delivers Ransomware via BadUSB
An FBI warning says the FIN7 cybercrime group has sent packages containing malicious USB drives to US companies in an effort to spread ransomware.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
FBI Warns FIN7 Campaign Delivers Ransomware via BadUSB
An FBI warning says the FIN7 cybercrime group has sent packages containing malicious USB drives to US companies in an effort to spread ransomware.
PasteMonitor - Scrape Pastebin API To Collect Daily Pastes, Setup A Wordlist And Be Alerted By Email When You Have A Match
Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.DescriptionThe PasteMonitor tool allows you to perform two main actions (for educational purposes only):Download daily new public pastesAverage number of pastes per day: 1000-3000 (filetype: .txt)Send automatic email alertYou can setup a wordlist and be alerted by email when you have a matchIf your paste is no longer online, you can find it on your computer/server via the ID of your paste (here ID is "WJq2YxPg") Before startBefore starting the tool, make sure to:Get a Pastebin PRO accountEnter the IP address of your machine in the "Your Account & Whitelisted IP" sectionActivate a mail account that can authorize a third party application (here we use a Gmail account)Enable 2-step verificationGenerate app password (for more help, see this tutorial)Then, add to the code "pastemonitor.py":Email credentials ("email", "password")Email alert recipient ("receiver")WordlistIn the "wordlist.txt" file, add your keywords line by line.Prerequisitepip3 install -r requirements.txtUsagepython3 pastemonitor.pyPastebin.com usageVisit the official Pastebin webpage Scraping API.ContributingFeel free to clone this project. For major changes, please open an issue first to discuss what you would like to change.LicenseMITDownload PasteMonitor
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.DescriptionThe PasteMonitor tool allows you to perform two main actions (for educational purposes only):Download daily new public pastesAverage number of pastes per day: 1000-3000 (filetype: .txt)Send automatic email alertYou can setup a wordlist and be alerted by email when you have a matchIf your paste is no longer online, you can find it on your computer/server via the ID of your paste (here ID is "WJq2YxPg") Before startBefore starting the tool, make sure to:Get a Pastebin PRO accountEnter the IP address of your machine in the "Your Account & Whitelisted IP" sectionActivate a mail account that can authorize a third party application (here we use a Gmail account)Enable 2-step verificationGenerate app password (for more help, see this tutorial)Then, add to the code "pastemonitor.py":Email credentials ("email", "password")Email alert recipient ("receiver")WordlistIn the "wordlist.txt" file, add your keywords line by line.Prerequisitepip3 install -r requirements.txtUsagepython3 pastemonitor.pyPastebin.com usageVisit the official Pastebin webpage Scraping API.ContributingFeel free to clone this project. For major changes, please open an issue first to discuss what you would like to change.LicenseMITDownload PasteMonitor
Read more...
___________________________
@hacking_Attack
@Hacking_Video
P1 Vulnerability: How I chained Logical-Error to Account-Takeover Vulnerability that No-One…
* Introduction *Continue reading on Medium »
Read more...
* Introduction *Continue reading on Medium »
Read more...
Free Online Hash Cracking Websites
Cracking password hashes on your own without the proper hardware can become time-consuming and tedious. Luckily for those capped by their…Continue reading on Medium »
Read more...
Cracking password hashes on your own without the proper hardware can become time-consuming and tedious. Luckily for those capped by their…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Active Directory Privilege Escalation (CVE-2021–42278)
This post discusses how CVE-2021-42287 allows potential attackers to gain high privileged user access (domain controllers Administrator level access) via a low privileged user (any
The post Active Directory Privilege Escalation (CVE-2021–42278) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Active Directory Privilege Escalation (CVE-2021–42278)
This post discusses how CVE-2021-42287 allows potential attackers to gain high privileged user access (domain controllers Administrator level access) via a low privileged user (any
The post Active Directory Privilege Escalation (CVE-2021–42278) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Hacking Articles is a comprehensive and insightful platform for learning about cyber security. It offers a wide range of articles and tutorials covering topics such as Penetration Testing, Bug Bounty, Red Teaming, Threat Hunting, and more.
Help with Password Hacking Software
https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/
Hello, I am new to the world of cyber security. What is the best network/wifi password cracking/hacking software in 2022? I am familiar with Cain and Abel but am also familiar with the fact that it has been discontinued, the original site has been taken down and it is no longer being updated. Cain and Abel used to be the best go-to software for network hacking among many others. Is Cain and Abel still available and useful in 2022? If so, where is the best (and safest) place to download the software from where I do not have to worry about malicious malware? Is there a newer, more updated and better performing/more useful software that I can use while learning network security and testing? I liked Cain and Abel because of its versatility and the many uses that it had. I am looking to either find a way to download this software or a just-as-useful-and-versitile software that I can use. Thank you submitted by /u/businessguy369 (https://www.reddit.com/user/businessguy369)
[link] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/) [comments] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/
Hello, I am new to the world of cyber security. What is the best network/wifi password cracking/hacking software in 2022? I am familiar with Cain and Abel but am also familiar with the fact that it has been discontinued, the original site has been taken down and it is no longer being updated. Cain and Abel used to be the best go-to software for network hacking among many others. Is Cain and Abel still available and useful in 2022? If so, where is the best (and safest) place to download the software from where I do not have to worry about malicious malware? Is there a newer, more updated and better performing/more useful software that I can use while learning network security and testing? I liked Cain and Abel because of its versatility and the many uses that it had. I am looking to either find a way to download this software or a just-as-useful-and-versitile software that I can use. Thank you submitted by /u/businessguy369 (https://www.reddit.com/user/businessguy369)
[link] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/) [comments] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Help with Password Hacking Software
Hello, I am new to the world of cyber security. What is the best network/wifi password cracking/hacking software in 2022? I am familiar with...
Generating & Analyzing Shellcode with Radare2
https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/
submitted by /u/DLLCoolJ (https://www.reddit.com/user/DLLCoolJ)
[link] (https://youtu.be/ttdmR8uiF9w) [comments] (https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/
submitted by /u/DLLCoolJ (https://www.reddit.com/user/DLLCoolJ)
[link] (https://youtu.be/ttdmR8uiF9w) [comments] (https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Generating & Analyzing Shellcode with Radare2
Posted in r/redteamsec by u/DLLCoolJ • 5 points and 2 comments
hacking: security in practice
What are some good hacking/cybersecurity podcasts?
I've started really enjoying podcasts and I'm really getting into hacking (even though I'm horrible at it) and cybersecurity. I'm currently listening to the Darknet Diaries and I'm loving it! Are there any other podcasts like this? What hacking podcasts do you personally enjoy?
submitted by /u/Metalsaurus_Rex
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What are some good hacking/cybersecurity podcasts?
I've started really enjoying podcasts and I'm really getting into hacking (even though I'm horrible at it) and cybersecurity. I'm currently listening to the Darknet Diaries and I'm loving it! Are there any other podcasts like this? What hacking podcasts do you personally enjoy?
submitted by /u/Metalsaurus_Rex
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community