Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bugs found with this tool Gmail.com DMARC bypass demo video, https://youtu.be/xuKZpT0rsd0 Outlook.com DMARC bypass video, https://youtu.be/IsWgAEbPaK0 Yahoo.com DMARC bypass video, https://youtu.be/DRepfStOruE Protonmail.com DMARC bypass video, https://youtu.be/bh4_SoPniMA CVE-2020-12272, OpenDMARC bypass bug report, https://sourceforge.net/p/opendmarc/tickets/237/ CVE-2019-20790, OpenDMARC and pypolicyd-spf bypass bug report, https://sourceforge.net/p/opendmarc/tickets/235/ Mail.ru DMARC bypass bug report on HackerOne, https://hackerone.com/reports/731878 Welcome to send a pull request to file your bug report here. Q&A How do I know if the email has bypassed DMARC authentication successfully? You can check it in the Authentication-results header in the raw message headers. If the header shows dmarc=pass, it means the email has passed the DMARC authentication.  You can check some demos video here (https://www.youtube.com/playlist?list=PL--A-gWJV1dJ19SyhkzklMC3C8ra1kK5-). Why do emails fail to send? There are several possible reasons if you fail to send an email: 1) your ISP blocks outgoing emails to port 25 to prevent spam. In this case, you need to ask for permission from the ISP; 2) the IP address is in the spam list of the target email services. In many cases, you resolve the problem here, https://www.spamhaus.org/lookup/ ;  3) some email services check if there is a PTR record for the sending IP, you may also need to set the PTR record to bypass this check; 4) the email cannot pass the format validation of the target email service, you may want to try a different test case. Why the email goes to the spam folder? Any way to avoid this? Currently, espoofer focuses on bypassing SPF/DKIM/DMARC authentication and doesn't aim for spam filter bypass. But you could try to use a reputable sending IP address, domain, and benign message content to bypass the spam filter. Why I send an email successfully but the email didn't show up in either inbox or spam folder? In our prior experiences, some email services filter suspicious emails silently. When testing server_a5/a6, why I cannot set specical characters like "(" in the domain? You will need to set up your own authority DNS server, rather than use third-party DNS hosting services, as some DNS hosting services have restrictions on setting specical characters. See issue (https://github.com/chenjj/espoofer/issues/2#issuecomment-686918954). Credits Welcome to add more test cases.

Download Espoofer (https://github.com/chenjj/espoofer)

___________________________
@hacking_Attack
@Hacking_Video
Deep Web
Can someone explain the difference between bitcoin tumbling and simply exchanging bitcoin for monero?

I get the gist of each one. (at least, this is my understanding of each.)

Bitcoin tumbling : sending your bitcoins through a mixer, it gets exchanged with multiple other addresses, different amounts, different times, etc. At the end of it all, you have the same amount of bitcoins, except they now have no connection to your original wallet.

BTC for XMR: trading your BTC for someone else's monero. Now you have anonymous monero currency to spend.

my question: If what you're after is having anonymous cryptocurrency. Why would you choose one method over the other? How is the end goal of each one different?

submitted by /u/Old_Metal2046
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
LastPass

I have lastpass but the password on Facebook is my original one and the one the lastpass site is different. Is it supposed to be like that? If someone was to hack it do they need the original password or the new one lastpass created?

submitted by /u/Interesting_Stop_935
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Potential backdoor?

Hey guys, long story short i was playing grand theft auto and encountered a hacker that wasn't very family friendly. I then received an email from social club telling me i needed to change my password for security reason ( wich i didn't asked for ) so i did it. Everything went well then i realized, was it "really" a link from social club? I mean the link redirected me to the official site i also checked their mail and it was the good one but i'm a complete newbie with all this and i was wondering, by clicking that link, without downloading anything beside maybe the fact that in the worst case he can access my social club account, could he put a backdoor in any way? Sorry if this sound stupid but i do a lot of important things for work on my computer so i just want to be as carefull as i can, thanks

submitted by /u/Settk666
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
The Cybersecurity Measures CTOs Are Actually Implementing

Companies look to multifactor authentication and identity and access management to block attacks, but hedge their bets with disaster recovery.
Dark Reading: Attacks/Breaches
Russia Takes Down REvil Ransomware Operation, Arrests Key Members

Timing of the move has evoked at least some skepticism from security experts about the country's true motives.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
YouTube suspended my channel for a video about disclosed on HackerOne issue in Grammarly

7 days ago my channel was suspended and I got a letter from Youtube with suspension reason "Spam, deceptive practices, & scams policies"

I send an appeal to them:

1. At the blocking moment, I had only 2 videos (just screen records) on my channel which showed the same problem in 2 different Grammarly products
2. these videos were an illustration for my report for Grammarly on the HackerOne, which Grammarly disclosed to the public and does not consider this a problem."The described behavior is a functionality limitation that does not affect the security and privacy of our product."
3. these videos were published after Grammarly representatives allowed me to release this information
4. in the description of the video, there were links to the HackerOne case for the problem and to my blog on Medium with a detailed study of this problem
5. the video was posted for educational purposes only and without malicious intent

...but without success. Аnd my appeal was immediately declined.

I posted today my tweet about this on HackerNews and have already received tons of upvotes and comments.

So, I got no bounty reward from Grammarly but got an account termination from Youtube.

I'm looking for support. Please, anyone who knows somebody from YT/G team, tag them in my tweet. Or just retweet. I am grateful for any help and assistance!

submitted by /u/evilksandr
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video