Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
The extension adds a context menu to BurpSuite that allows you to copy multiple requests as Javascript's XmlHttpRequest, which simplifies PoC development when exploiting (https://www.kitploit.com/search/label/Exploiting) XSS.
Installation
download the latest JAR (https://www.kitploit.com/search/label/JAR) from releases or build manually add JAR to burpsuite (https://www.kitploit.com/search/label/Burpsuite) using tabs: "Extender" -> "Extensions" -> "Add"
Usage
select one request from any tab or a few requests in "Proxy" -> "HTTP history" tab invoke context menu and select "Copy as XMLHttpRequest"

Download Burpsuite-Copy-As-Xmlhttprequest (https://github.com/vulnbe/burpsuite-copy-as-xmlhttprequest)
Burpsuite-Copy-As-XMLHttpRequest - Copy As XMLHttpRequest BurpSuite Extension

The extension adds a context menu to BurpSuite that allows you to copy multiple requests as Javascript's XmlHttpRequest, which simplifies PoC development when exploiting XSS.Installation download the latest JAR from releases or build manually add JAR to burpsuite using tabs: "Extender" -> "Extensions" -> "Add" Usage select one request from any tab or a few requests in "Proxy" -> "HTTP history" tab invoke context menu and select "Copy as XMLHttpRequest" Download Burpsuite-Copy-As-Xmlhttprequest
Read more...
Before we get into how to protect python applications from dependency confusion attacks, we’ll define this new attack vector, give a bit…Continue reading on Ochrona Security » (https://medium.com/ochrona/preventing-dependency-confusion-attacks-in-python-fa6058ac972f?source=rss------bug_bounty-5)
A question and a request to specialists about Architecture, or any suggestions for a beginner :)
https://www.reddit.com/r/redteamsec/comments/mlon9x/a_question_and_a_request_to_specialists_about/

<!-- SC_OFF -->Question and request to specialists I would like to go deeper into AD security. Currently setting up the AD environment on the home lab, is there anyone who did something like that at home in the laboratory and would like to share the architecture they have implemented at home? I miss a bit of an idea, and I must honestly admit that I was inspired by a series of courses from "Red Team Labs: Enterprise Windows Environments", but this is too high a level for me, I like to throw myself into the deep water no less, this is where I learn the best :) <!-- SC_ON --> submitted by /u/r3g3x_abc (https://www.reddit.com/user/r3g3x_abc)
[link] (https://www.reddit.com/r/redteamsec/comments/mlon9x/a_question_and_a_request_to_specialists_about/) [comments] (https://www.reddit.com/r/redteamsec/comments/mlon9x/a_question_and_a_request_to_specialists_about/)
Hacking Articles Tips Tricks Videos Tutorials
GIF
KitPloit - PenTest Tools!
Burpsuite-Copy-As-XMLHttpRequest - Copy As XMLHttpRequest BurpSuite Extension

https://1.bp.blogspot.com/-ccNn5Dq6l8k/YGvUCLu3YUI/AAAAAAAAVxE/wZDZyHjRG9MURhBU0Ci6J67L5q0OqgI5gCNcBGAsYHQ/w640-h386/Burpsuite-Copy-As-XMLHttpRequest.gif
The extension adds a context menu to BurpSuite that allows you to copy multiple requests as Javascript's XmlHttpRequest, which simplifies PoC development when exploiting XSS.
Installation

* download the latest JAR from releases or build manually
* add JAR to burpsuite using tabs: "Extender" -> "Extensions" -> "Add"

Usage

* select one request from any tab or a few requests in "Proxy" -> "HTTP history" tab
* invoke context menu and select "Copy as XMLHttpRequest"
Download Burpsuite-Copy-As-Xmlhttprequest
Deep Web
Not sure where to start

So I want to browse the deep web but I'm not sure where to start. I have a few questions for some of the more knowledgeable people on here.

Should I use a burner laptop? I'm not sure if I want to risk my $3000 machine

Is tails necessary? My goal is to just browse the web anonymously. I don't plan on buying anything. I'm not sure if tails does anything to make you more anonymous online or hide your ip?

Should I use a vpn? I see some people saying VPN doesn't help at all and others saying it does help so I'm really confused as to which one is right.

submitted by /u/jimtendo_wii
[link] [comments]
hacking: security in practice
Is it possible to know?

So is it possible to somehow KNOW when is a certain youtuber in the process of uploading a video but haven't published it yet?

I have no coding knowledge and I am wondering if such thing is even possible?

Thnaks in advance

submitted by /u/IvanBanana
[link] [comments]
hacking: security in practice
Where should I report leaks?

Was watching a video about how there were some leaks of user info on facebook, decided to go use a website to see if some of my info got leaked, it did. So, I decided to just google an old password of mine (very unique) and I found a few documents containing thousands of accounts/emails with their passwords revealed. I went through a handful of accounts to see if the passwords were valid, and doesn't seem to be the case. But still, there's gotta be a good chunk of them that might still be valid where the users haven't used the email in a while. One of them is anonymously posted as far as I'm aware. I would share where they are at, but it's not just my info.

Any help/resources would be appreciated!
EDIT: I realize this may be the wrong sub for asking such a thing, but I just wasn't sure where else to post :/

submitted by /u/Stealthybeef
[link] [comments]