PasteMonitor - Scrape Pastebin API To Collect Daily Pastes, Setup A Wordlist And Be Alerted By Email When You Have A Match
Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.DescriptionThe PasteMonitor tool allows you to perform two main actions (for educational purposes only):Download daily new public pastesAverage number of pastes per day: 1000-3000 (filetype: .txt)Send automatic email alertYou can setup a wordlist and be alerted by email when you have a matchIf your paste is no longer online, you can find it on your computer/server via the ID of your paste (here ID is "WJq2YxPg") Before startBefore starting the tool, make sure to:Get a Pastebin PRO accountEnter the IP address of your machine in the "Your Account & Whitelisted IP" sectionActivate a mail account that can authorize a third party application (here we use a Gmail account)Enable 2-step verificationGenerate app password (for more help, see this tutorial)Then, add to the code "pastemonitor.py":Email credentials ("email", "password")Email alert recipient ("receiver")WordlistIn the "wordlist.txt" file, add your keywords line by line.Prerequisitepip3 install -r requirements.txtUsagepython3 pastemonitor.pyPastebin.com usageVisit the official Pastebin webpage Scraping API.ContributingFeel free to clone this project. For major changes, please open an issue first to discuss what you would like to change.LicenseMITDownload PasteMonitor
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.DescriptionThe PasteMonitor tool allows you to perform two main actions (for educational purposes only):Download daily new public pastesAverage number of pastes per day: 1000-3000 (filetype: .txt)Send automatic email alertYou can setup a wordlist and be alerted by email when you have a matchIf your paste is no longer online, you can find it on your computer/server via the ID of your paste (here ID is "WJq2YxPg") Before startBefore starting the tool, make sure to:Get a Pastebin PRO accountEnter the IP address of your machine in the "Your Account & Whitelisted IP" sectionActivate a mail account that can authorize a third party application (here we use a Gmail account)Enable 2-step verificationGenerate app password (for more help, see this tutorial)Then, add to the code "pastemonitor.py":Email credentials ("email", "password")Email alert recipient ("receiver")WordlistIn the "wordlist.txt" file, add your keywords line by line.Prerequisitepip3 install -r requirements.txtUsagepython3 pastemonitor.pyPastebin.com usageVisit the official Pastebin webpage Scraping API.ContributingFeel free to clone this project. For major changes, please open an issue first to discuss what you would like to change.LicenseMITDownload PasteMonitor
Read more...
___________________________
@hacking_Attack
@Hacking_Video
P1 Vulnerability: How I chained Logical-Error to Account-Takeover Vulnerability that No-One…
* Introduction *Continue reading on Medium »
Read more...
* Introduction *Continue reading on Medium »
Read more...
Free Online Hash Cracking Websites
Cracking password hashes on your own without the proper hardware can become time-consuming and tedious. Luckily for those capped by their…Continue reading on Medium »
Read more...
Cracking password hashes on your own without the proper hardware can become time-consuming and tedious. Luckily for those capped by their…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Active Directory Privilege Escalation (CVE-2021–42278)
This post discusses how CVE-2021-42287 allows potential attackers to gain high privileged user access (domain controllers Administrator level access) via a low privileged user (any
The post Active Directory Privilege Escalation (CVE-2021–42278) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Active Directory Privilege Escalation (CVE-2021–42278)
This post discusses how CVE-2021-42287 allows potential attackers to gain high privileged user access (domain controllers Administrator level access) via a low privileged user (any
The post Active Directory Privilege Escalation (CVE-2021–42278) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Hacking Articles is a comprehensive and insightful platform for learning about cyber security. It offers a wide range of articles and tutorials covering topics such as Penetration Testing, Bug Bounty, Red Teaming, Threat Hunting, and more.
Help with Password Hacking Software
https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/
Hello, I am new to the world of cyber security. What is the best network/wifi password cracking/hacking software in 2022? I am familiar with Cain and Abel but am also familiar with the fact that it has been discontinued, the original site has been taken down and it is no longer being updated. Cain and Abel used to be the best go-to software for network hacking among many others. Is Cain and Abel still available and useful in 2022? If so, where is the best (and safest) place to download the software from where I do not have to worry about malicious malware? Is there a newer, more updated and better performing/more useful software that I can use while learning network security and testing? I liked Cain and Abel because of its versatility and the many uses that it had. I am looking to either find a way to download this software or a just-as-useful-and-versitile software that I can use. Thank you submitted by /u/businessguy369 (https://www.reddit.com/user/businessguy369)
[link] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/) [comments] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/
Hello, I am new to the world of cyber security. What is the best network/wifi password cracking/hacking software in 2022? I am familiar with Cain and Abel but am also familiar with the fact that it has been discontinued, the original site has been taken down and it is no longer being updated. Cain and Abel used to be the best go-to software for network hacking among many others. Is Cain and Abel still available and useful in 2022? If so, where is the best (and safest) place to download the software from where I do not have to worry about malicious malware? Is there a newer, more updated and better performing/more useful software that I can use while learning network security and testing? I liked Cain and Abel because of its versatility and the many uses that it had. I am looking to either find a way to download this software or a just-as-useful-and-versitile software that I can use. Thank you submitted by /u/businessguy369 (https://www.reddit.com/user/businessguy369)
[link] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/) [comments] (https://www.reddit.com/r/Pentesting/comments/s0yk13/help_with_password_hacking_software/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Help with Password Hacking Software
Hello, I am new to the world of cyber security. What is the best network/wifi password cracking/hacking software in 2022? I am familiar with...
Generating & Analyzing Shellcode with Radare2
https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/
submitted by /u/DLLCoolJ (https://www.reddit.com/user/DLLCoolJ)
[link] (https://youtu.be/ttdmR8uiF9w) [comments] (https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/
submitted by /u/DLLCoolJ (https://www.reddit.com/user/DLLCoolJ)
[link] (https://youtu.be/ttdmR8uiF9w) [comments] (https://www.reddit.com/r/redteamsec/comments/s129op/generating_analyzing_shellcode_with_radare2/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Generating & Analyzing Shellcode with Radare2
Posted in r/redteamsec by u/DLLCoolJ • 5 points and 2 comments
hacking: security in practice
What are some good hacking/cybersecurity podcasts?
I've started really enjoying podcasts and I'm really getting into hacking (even though I'm horrible at it) and cybersecurity. I'm currently listening to the Darknet Diaries and I'm loving it! Are there any other podcasts like this? What hacking podcasts do you personally enjoy?
submitted by /u/Metalsaurus_Rex
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What are some good hacking/cybersecurity podcasts?
I've started really enjoying podcasts and I'm really getting into hacking (even though I'm horrible at it) and cybersecurity. I'm currently listening to the Darknet Diaries and I'm loving it! Are there any other podcasts like this? What hacking podcasts do you personally enjoy?
submitted by /u/Metalsaurus_Rex
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Are there any frequent hacking related events that happen in Toronto at all?
Hi everyone; recently moved to Toronto for college and I was wondering if there are any frequent meetups or talks about hacking and stuff in here. I’m 19, if anybody is in that age range and is cool and down to hangout, share hacking ideas together, talk hacking and whatnot lemme know
submitted by /u/ismaeljabbar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are there any frequent hacking related events that happen in Toronto at all?
Hi everyone; recently moved to Toronto for college and I was wondering if there are any frequent meetups or talks about hacking and stuff in here. I’m 19, if anybody is in that age range and is cool and down to hangout, share hacking ideas together, talk hacking and whatnot lemme know
submitted by /u/ismaeljabbar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are there any frequent hacking related events that happen in...
Hi everyone; recently moved to Toronto for college and I was wondering if there are any frequent meetups or talks about hacking and stuff in here....
hacking: security in practice
Books to Read to assist in learning how to tackle bug bounties?
Hey All,
Could any of you recommend books to read that might assist with the topic of bug bounties if you have the time.
I have a decent understanding of networks and how computers interact with said network but I don't understand the 'bug hunt' so to speak. I can de bug my code (There's lots of bugs in my code) but searching on a web app or website is foreign to me.
Any input is much appreciated.
Thanks in Advance :)
submitted by /u/bailsatan
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Books to Read to assist in learning how to tackle bug bounties?
Hey All,
Could any of you recommend books to read that might assist with the topic of bug bounties if you have the time.
I have a decent understanding of networks and how computers interact with said network but I don't understand the 'bug hunt' so to speak. I can de bug my code (There's lots of bugs in my code) but searching on a web app or website is foreign to me.
Any input is much appreciated.
Thanks in Advance :)
submitted by /u/bailsatan
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Books to Read to assist in learning how to tackle bug bounties?
Hey All, Could any of you recommend books to read that might assist with the topic of bug bounties if you have the time. I have a decent...
hacking: security in practice
MAC spoof not working?
im gonna preface this by saying that i have no idea what im doing and i dont think this is the right subreddit either but i need help
i followed a tutorial to change my mac address and it definitely changed, but i still cant access the wifi? i lose internet past 12 and im confident its mac filtering thats kicking me off the wifi, yet mac spoofing didnt work. what else could it be? or what did i do wrong?
submitted by /u/Naive_Organization85
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
MAC spoof not working?
im gonna preface this by saying that i have no idea what im doing and i dont think this is the right subreddit either but i need help
i followed a tutorial to change my mac address and it definitely changed, but i still cant access the wifi? i lose internet past 12 and im confident its mac filtering thats kicking me off the wifi, yet mac spoofing didnt work. what else could it be? or what did i do wrong?
submitted by /u/Naive_Organization85
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
MAC spoof not working?
im gonna preface this by saying that i have no idea what im doing and i dont think this is the right subreddit either but i need help i followed...
hacking: security in practice
Uses of machine/deep learning in cybersecurity?
As we all know, deep learning has surged lately under the blanket title of AI, regardless of its actual use case, autonomy, or intelligence. However, I haven't heard much about it with respect to cybersecurity, whether hacking or defending systems and networks. Darktrace is the only example that comes to mind.
Are there any areas in cybersecurity that deep learning is useful or better than a human? I suspect it's better as an automated early-warning system, but are there any useful offensive applications either?
submitted by /u/intelligent-goldfish
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Uses of machine/deep learning in cybersecurity?
As we all know, deep learning has surged lately under the blanket title of AI, regardless of its actual use case, autonomy, or intelligence. However, I haven't heard much about it with respect to cybersecurity, whether hacking or defending systems and networks. Darktrace is the only example that comes to mind.
Are there any areas in cybersecurity that deep learning is useful or better than a human? I suspect it's better as an automated early-warning system, but are there any useful offensive applications either?
submitted by /u/intelligent-goldfish
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Uses of machine/deep learning in cybersecurity?
As we all know, deep learning has surged lately under the blanket title of AI, regardless of its actual use case, autonomy, or intelligence. ...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft: powerdir bug gives access to protected macOS user data
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft: powerdir bug gives access to protected macOS user dataPost Views: 71 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The Microsoft 365 Defender Research Team has reported the vulnerability dubbed powerdir (tracked as CVE-2021-30970) to Apple on July 15, 2021, via the Microsoft Security Vulnerability Research (MSVR).
Microsoft says threat actors could use a macOS vulnerability to bypass Transparency, Consent, and Control (TCC) technology to access users’ protected data.
While Apple has restricted TCC access only to apps with full disk access and set up features to automatically block unauthorized code execution, Microsoft security researchers found that attackers could plant a second, specially crafted TCC database that would allow them to access protected user info.
“We discovered that it is possible to programmatically change a target user’s home directory and plant a fake TCC database, which stores the consent history of app requests,” said Jonathan Bar Or, a principal security researcher at Microsoft.
“If exploited on unpatched systems, this vulnerability could allow a malicious actor to potentially orchestrate an attack based on the user’s protected personal data.
See Also: Complete Offensive Security and Ethical Hacking Course
“For example, the attacker could hijack an app installed on the device—or install their own malicious app—and access the microphone to record private conversations or capture screenshots of sensitive information displayed on the user’s screen.”
Apple has also patched other TCC bypasses reported since 2020, including:
* Time Machine mounts (CVE-2020-9771): macOS offers a built-in backup and restore solution called Time Machine. It was discovered that Time Machine backups could be mounted (using the apfs_mount utility) with the “noowners” flag. Since these backups contain the TCC.db files, an attacker could mount those backups and determine the device’s TCC policy without having full disk access.
* Environment variable poisoning (CVE-2020-9934): It was discovered that the user’s tccd could build the path to the TCC.db file by expanding $HOME/Library/Application Support/com.apple.TCC/TCC.db. Since the user could manipulate the $HOME environment variable (as introduced to tccd by launchd), an attacker could plant a chosen TCC.db file in an arbitrary path, poison the $HOME environment variable, and make TCC.db consume that file instead.
* Bundle conclusion issue (CVE-2021-30713): First disclosed by Jamf in a blog post about the XCSSET malware family, this bug abused how macOS was deducing app bundle information. For example, suppose an attacker knows of a specific app that commonly has microphone access. In that case, they could plant their application code in the target app’s bundle and “inherit” its TCC capabilities.
https://www.bleepstatic.com/images/news/u/1109292/2022/powerdir_poc.png
___________________________
@hacking_Attack
@Hacking_Video
Microsoft: powerdir bug gives access to protected macOS user data
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft: powerdir bug gives access to protected macOS user dataPost Views: 71 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The Microsoft 365 Defender Research Team has reported the vulnerability dubbed powerdir (tracked as CVE-2021-30970) to Apple on July 15, 2021, via the Microsoft Security Vulnerability Research (MSVR).
Microsoft says threat actors could use a macOS vulnerability to bypass Transparency, Consent, and Control (TCC) technology to access users’ protected data.
While Apple has restricted TCC access only to apps with full disk access and set up features to automatically block unauthorized code execution, Microsoft security researchers found that attackers could plant a second, specially crafted TCC database that would allow them to access protected user info.
“We discovered that it is possible to programmatically change a target user’s home directory and plant a fake TCC database, which stores the consent history of app requests,” said Jonathan Bar Or, a principal security researcher at Microsoft.
“If exploited on unpatched systems, this vulnerability could allow a malicious actor to potentially orchestrate an attack based on the user’s protected personal data.
See Also: Complete Offensive Security and Ethical Hacking Course
“For example, the attacker could hijack an app installed on the device—or install their own malicious app—and access the microphone to record private conversations or capture screenshots of sensitive information displayed on the user’s screen.”
Apple has also patched other TCC bypasses reported since 2020, including:
* Time Machine mounts (CVE-2020-9771): macOS offers a built-in backup and restore solution called Time Machine. It was discovered that Time Machine backups could be mounted (using the apfs_mount utility) with the “noowners” flag. Since these backups contain the TCC.db files, an attacker could mount those backups and determine the device’s TCC policy without having full disk access.
* Environment variable poisoning (CVE-2020-9934): It was discovered that the user’s tccd could build the path to the TCC.db file by expanding $HOME/Library/Application Support/com.apple.TCC/TCC.db. Since the user could manipulate the $HOME environment variable (as introduced to tccd by launchd), an attacker could plant a chosen TCC.db file in an arbitrary path, poison the $HOME environment variable, and make TCC.db consume that file instead.
* Bundle conclusion issue (CVE-2021-30713): First disclosed by Jamf in a blog post about the XCSSET malware family, this bug abused how macOS was deducing app bundle information. For example, suppose an attacker knows of a specific app that commonly has microphone access. In that case, they could plant their application code in the target app’s bundle and “inherit” its TCC capabilities.
https://www.bleepstatic.com/images/news/u/1109292/2022/powerdir_poc.png
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft: powerdir bug gives access to protected macOS user data | Black Hat Ethical Hacking
The Microsoft 365 Defender Research Team has reported the vulnerability dubbed powerdir (tracked as CVE-2021-30970) to Apple on July 15, 2021, via the Microsoft Security Vulnerability Research (MSVR).
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft: powerdir bug gives access to protected macOS user data https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft: powerdir bug gives access to protected macOS user dataPost Views:…
e latest macOS version, Monterey,” Jonathan Bar Or added.
“This shows that even as macOS or other operating systems and applications become more hardened with each release, software vendors like Apple, security researchers, and the larger security community, need to continuously work together to identify and fix vulnerabilities before attackers can take advantage of them.”
Microsoft has previously reported finding a security flaw dubbed Shrootless that would allow an attacker to bypass System Integrity Protection (SIP) and perform arbitrary operations, elevate privileges to root, and install rootkits on vulnerable devices.
See Also: Offensive Security Tool: Osmedeus The company’s researchers also discovered new variants of macOS WizardUpdate malware (aka UpdateAgent or Vigram), updated with new evasion and persistence tactics.
Last year, in June, Redmond revealed critical firmware bugs in some NETGEAR router models that hackers could use to breach and move laterally within enterprise networks.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-iPhone-13-Pro-90x90.png iOS malware can fake iPhone shut downs to snoop on camera, microphone5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0358ad020c37-article-cache-poisoning-article-90x90.png Researcher discovers 70 web cache poisoning vulnerabilities, nets $40k in bug bounty rewards6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/1200x0-90x90.jpg Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/exchange-90x90.png Microsoft releases emergency fix for Exchange – 2022 bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/maxresdefault-90x90.jpg Have I Been Pwned adds 441K accounts stolen by RedLine malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/1229111902.0-90x90.jpg T-Mobile says new data breach caused by SIM swap attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/feature-log4j-blue-90x90.png Log4j 2.17.1 out now, fixes new remote code execution bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/qnap-logo-white-90x90.jpg QNAP NAS devices hit in surge of ech0raix ransomware attacks2 weeks ago
The post Microsoft: powerdir bug gives access to protected macOS user data first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
“This shows that even as macOS or other operating systems and applications become more hardened with each release, software vendors like Apple, security researchers, and the larger security community, need to continuously work together to identify and fix vulnerabilities before attackers can take advantage of them.”
Microsoft has previously reported finding a security flaw dubbed Shrootless that would allow an attacker to bypass System Integrity Protection (SIP) and perform arbitrary operations, elevate privileges to root, and install rootkits on vulnerable devices.
See Also: Offensive Security Tool: Osmedeus The company’s researchers also discovered new variants of macOS WizardUpdate malware (aka UpdateAgent or Vigram), updated with new evasion and persistence tactics.
Last year, in June, Redmond revealed critical firmware bugs in some NETGEAR router models that hackers could use to breach and move laterally within enterprise networks.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-iPhone-13-Pro-90x90.png iOS malware can fake iPhone shut downs to snoop on camera, microphone5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0358ad020c37-article-cache-poisoning-article-90x90.png Researcher discovers 70 web cache poisoning vulnerabilities, nets $40k in bug bounty rewards6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/1200x0-90x90.jpg Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/exchange-90x90.png Microsoft releases emergency fix for Exchange – 2022 bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/maxresdefault-90x90.jpg Have I Been Pwned adds 441K accounts stolen by RedLine malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/1229111902.0-90x90.jpg T-Mobile says new data breach caused by SIM swap attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/feature-log4j-blue-90x90.png Log4j 2.17.1 out now, fixes new remote code execution bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/qnap-logo-white-90x90.jpg QNAP NAS devices hit in surge of ech0raix ransomware attacks2 weeks ago
The post Microsoft: powerdir bug gives access to protected macOS user data first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Burner Numbers
Is there a way to tell if a cell number is connected to an actual cell-phone or if it's a text only or burner app etc.?
submitted by /u/JBase16
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Burner Numbers
Is there a way to tell if a cell number is connected to an actual cell-phone or if it's a text only or burner app etc.?
submitted by /u/JBase16
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Burner Numbers
Is there a way to tell if a cell number is connected to an actual cell-phone or if it's a text only or burner app etc.?
hacking: security in practice
Antivirus for school project
Actually I was thinking about creating an antivirus for major project and I'm struggling on what language to use for it?? As I have done research and it seems C and C++ are compatible, is there any other language to be used
submitted by /u/NavyX11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Antivirus for school project
Actually I was thinking about creating an antivirus for major project and I'm struggling on what language to use for it?? As I have done research and it seems C and C++ are compatible, is there any other language to be used
submitted by /u/NavyX11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Antivirus for school project
Actually I was thinking about creating an antivirus for major project and I'm struggling on what language to use for it?? As I have done research...
WannaRace - WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
WebApp intentionally made vulnerable to Race ConditionDescriptionRace Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning Building and running the docker imageBuild the docker image with:git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRacedocker build -t xib3rr4dar/wanna_race:1.0 .Run docker image:docker run -it --rm xib3rr4dar/wanna_race:1.0ORdocker run -it --rm -p 9050:80 xib3rr4dar/wanna_race:1.0Then open in browser relevant IP:PORT ScreenshotsChallenge #1Main Page Four vouchers worth 400 units available for recharge Task is to buy Mega box (which is worth 401 units) by exploiting race conditionChallenge #2Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are setDownload WannaRace
Read more...
___________________________
@hacking_Attack
@Hacking_Video
WebApp intentionally made vulnerable to Race ConditionDescriptionRace Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning Building and running the docker imageBuild the docker image with:git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRacedocker build -t xib3rr4dar/wanna_race:1.0 .Run docker image:docker run -it --rm xib3rr4dar/wanna_race:1.0ORdocker run -it --rm -p 9050:80 xib3rr4dar/wanna_race:1.0Then open in browser relevant IP:PORT ScreenshotsChallenge #1Main Page Four vouchers worth 400 units available for recharge Task is to buy Mega box (which is worth 401 units) by exploiting race conditionChallenge #2Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are setDownload WannaRace
Read more...
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - Xib3rR4dAr/WannaRace: WebApp intentionally made vulnerable to Race Condition for practicing Race Condition
WebApp intentionally made vulnerable to Race Condition for practicing Race Condition - Xib3rR4dAr/WannaRace
Domain Escalation - ShadowCoerce [MS-FSRVP]
https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlaboratories.com/2022/01/11/shadowcoerce/) [comments] (https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlaboratories.com/2022/01/11/shadowcoerce/) [comments] (https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Domain Escalation - ShadowCoerce [MS-FSRVP]
Posted in r/redteamsec by u/netbiosX • 1 point and 0 comments