Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
1Password Raises $620M Series C, Now Valued at $6.8B
The massive funding round comes as the rise of cloud and remote work led to new threats and growing security and privacy concerns.
1Password Raises $620M Series C, Now Valued at $6.8B
The massive funding round comes as the rise of cloud and remote work led to new threats and growing security and privacy concerns.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pentest Report Example for a PriviaHub Vulnerability Machine
https://cdn-images-1.medium.com/max/941/1*lkBwDw8NH5X5l6sbRwPj3g.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pentest Report Example for a PriviaHub Vulnerability Machine
https://cdn-images-1.medium.com/max/941/1*lkBwDw8NH5X5l6sbRwPj3g.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pentest Report Example for a PriviaHub Vulnerability Machine
Furkan Enes Polatoğlu ·Just now
hacking: security in practice
Getting Password Hashes for dictionary attacks
Hello i am wondering how to get a hash for a password to perform a dictionary attack on, ive been searching for it on the net but i didnt find anything so i would appreciate some help. Thanks in advance!
submitted by /u/SebiIstCool
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Getting Password Hashes for dictionary attacks
Hello i am wondering how to get a hash for a password to perform a dictionary attack on, ive been searching for it on the net but i didnt find anything so i would appreciate some help. Thanks in advance!
submitted by /u/SebiIstCool
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Getting Password Hashes for dictionary attacks
Hello i am wondering how to get a hash for a password to perform a dictionary attack on, ive been searching for it on the net but i didnt find...
hacking: security in practice
Fedora
ok techy friends, need some help. I installed Fedora 35 and need the driver for this>>> 802.11b/g/n (1x1) wi-fi® and bluetooth® 4.2 combo . link me please!!
submitted by /u/jacksonstillspitts
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Fedora
ok techy friends, need some help. I installed Fedora 35 and need the driver for this>>> 802.11b/g/n (1x1) wi-fi® and bluetooth® 4.2 combo . link me please!!
submitted by /u/jacksonstillspitts
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Fedora
ok techy friends, need some help. I installed Fedora 35 and need the driver for this>>> 802.11b/g/n (1x1) wi-fi® and bluetooth® 4.2 combo . link...
hacking: security in practice
Welcome to pwn.college! Free Course for reverse engineering.
submitted by /u/3DMilk
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Welcome to pwn.college! Free Course for reverse engineering.
submitted by /u/3DMilk
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Welcome to pwn.college! Free Course for reverse engineering.
Posted in r/hacking by u/3DMilk • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
We Need To Know Session Hijacking
https://cdn-images-1.medium.com/max/600/0*tIYk4jKw7dHVyw-e.png
Session Hijacking also Known as Cookie Hijacking
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
We Need To Know Session Hijacking
https://cdn-images-1.medium.com/max/600/0*tIYk4jKw7dHVyw-e.png
Session Hijacking also Known as Cookie Hijacking
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
We Need To Know Session Hijacking
Session Hijacking also Known as Cookie Hijacking
hacking: security in practice
Best Phishing Tools?
Hey guys, I used to play around with phishing tools using Kali and there used to be some really fun/good ones like Blackeye and ZPhisher. I've recently become reinterested in hacking and I just can't find good phishing tools anymore. The functional version of Blackeye isn't available anymore and ZPhisher isn't operational as far as I know it . The only one I have at the moment is my social engineering toolkit as offered by Kali and one working copy of Blackeye on another virtual machine of mine that hasn't been updated in 3 years. Do any of you know of some good phishing tools? It just seems like I can't find any new or good ones anymore.
submitted by /u/botnetboi8080
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Best Phishing Tools?
Hey guys, I used to play around with phishing tools using Kali and there used to be some really fun/good ones like Blackeye and ZPhisher. I've recently become reinterested in hacking and I just can't find good phishing tools anymore. The functional version of Blackeye isn't available anymore and ZPhisher isn't operational as far as I know it . The only one I have at the moment is my social engineering toolkit as offered by Kali and one working copy of Blackeye on another virtual machine of mine that hasn't been updated in 3 years. Do any of you know of some good phishing tools? It just seems like I can't find any new or good ones anymore.
submitted by /u/botnetboi8080
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Best Phishing Tools?
Hey guys, I used to play around with phishing tools using Kali and there used to be some really fun/good ones like Blackeye and ZPhisher. I've...
Nakji Network’s 200K Bug Bounty Program
https://nakji.medium.com/nakji-networks-200k-bug-bounty-program-d500b3f305c3?source=rss------bug_bounty-5
The Nakji FoundationContinue reading on Medium » (https://nakji.medium.com/nakji-networks-200k-bug-bounty-program-d500b3f305c3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://nakji.medium.com/nakji-networks-200k-bug-bounty-program-d500b3f305c3?source=rss------bug_bounty-5
The Nakji FoundationContinue reading on Medium » (https://nakji.medium.com/nakji-networks-200k-bug-bounty-program-d500b3f305c3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nakji Network’s 200K Bug Bounty Program
The Nakji Foundation
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Beijing Olympics App Flaws Allow Man-in-the-Middle AttacksPost Views: 120 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Attackers can access audio and files uploaded to the MY2022 mobile app required for use by all winter games attendees – including personal health details.
The mobile app that all attendees and athletes of the upcoming Beijing Winter Olympics must use to manage communications and documentation at the event has a “devastating” flaw in the way it encrypts data that can allow for man-in-the-middle attacks that access sensitive user information, researchers have found.
MY2022 is an app mandated for use by all attendees – including members of the press and athletes – of the 2022 Olympic Games in Beijing. The problem is, it poses a significant security risk because the encryption used to protect users’ voice audio and file transfers “can be trivially sidestepped” due to two vulnerabilities in how it handles data transport, according to a blog post from Citizen Lab posted online Tuesday.
Additionally, “server responses can also be spoofed, allowing an attacker to display fake instructions to users,” Citizen Lab’s Jeffrey Knockel wrote in the post.
MY2022 collects info such as health customs forms that transmit passport details, demographic information, and medical and travel history, which are vulnerable due to the flaw, he said. It’s also not clear with whom or which organizations this info is shared.
MY2022 also includes a feature that allow users to report “politically sensitive” content, as well as a censorship keyword list. While the latter is “presently inactive,” it targets a variety of political topics, including domestic issues such as Xinjiang and Tibet as well as references to Chinese government agencies, Knockel wrote.
See Also: Complete Offensive Security and Ethical Hacking Course Background and DisclosureResearchers disclosed the security issues to the Beijing Organizing Committee for the 2022 Olympic and Paralympic Winter Games on Dec. 3, 2021, giving organizers a deadline of 15 days to respond and 45 days to fix the issues. As of yesterday, Jan. 18, 2022, researchers still hadn’t received a response, according to the post.
Citizen Lab researchers also inspected a Jan. 17 release of version 2.0.5 of MY2022 for iOS to Apple’s App Store, finding that the issues reported still had not been resolved, Knockel wrote. Moreover, that version of the app introduced a new feature called “Green Health Code” that asks for travel documents and medical info from users that also is vulnerable to the flaws, he added.
MY2022 is being used as part of a closed-loop system implemented due to COVID-19 restrictions that requires all international and domestic attendees to monitor and submit their health status – e.g., a negative test for the virus – to the app on a daily basis.
For domestic users, MY2022 collects personal information including name, national identification number, phone number, email address, profile picture and employment information, and shares it with the Beijing Organizing Committee for the 2022 Olympics. For international users, the app collects users’ demographic information and passport information, as well as the organization to which they belong.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is wort[...]
___________________________
@hacking_Attack
@Hacking_Video
Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Beijing Olympics App Flaws Allow Man-in-the-Middle AttacksPost Views: 120 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Attackers can access audio and files uploaded to the MY2022 mobile app required for use by all winter games attendees – including personal health details.
The mobile app that all attendees and athletes of the upcoming Beijing Winter Olympics must use to manage communications and documentation at the event has a “devastating” flaw in the way it encrypts data that can allow for man-in-the-middle attacks that access sensitive user information, researchers have found.
MY2022 is an app mandated for use by all attendees – including members of the press and athletes – of the 2022 Olympic Games in Beijing. The problem is, it poses a significant security risk because the encryption used to protect users’ voice audio and file transfers “can be trivially sidestepped” due to two vulnerabilities in how it handles data transport, according to a blog post from Citizen Lab posted online Tuesday.
Additionally, “server responses can also be spoofed, allowing an attacker to display fake instructions to users,” Citizen Lab’s Jeffrey Knockel wrote in the post.
MY2022 collects info such as health customs forms that transmit passport details, demographic information, and medical and travel history, which are vulnerable due to the flaw, he said. It’s also not clear with whom or which organizations this info is shared.
MY2022 also includes a feature that allow users to report “politically sensitive” content, as well as a censorship keyword list. While the latter is “presently inactive,” it targets a variety of political topics, including domestic issues such as Xinjiang and Tibet as well as references to Chinese government agencies, Knockel wrote.
See Also: Complete Offensive Security and Ethical Hacking Course Background and DisclosureResearchers disclosed the security issues to the Beijing Organizing Committee for the 2022 Olympic and Paralympic Winter Games on Dec. 3, 2021, giving organizers a deadline of 15 days to respond and 45 days to fix the issues. As of yesterday, Jan. 18, 2022, researchers still hadn’t received a response, according to the post.
Citizen Lab researchers also inspected a Jan. 17 release of version 2.0.5 of MY2022 for iOS to Apple’s App Store, finding that the issues reported still had not been resolved, Knockel wrote. Moreover, that version of the app introduced a new feature called “Green Health Code” that asks for travel documents and medical info from users that also is vulnerable to the flaws, he added.
MY2022 is being used as part of a closed-loop system implemented due to COVID-19 restrictions that requires all international and domestic attendees to monitor and submit their health status – e.g., a negative test for the virus – to the app on a daily basis.
For domestic users, MY2022 collects personal information including name, national identification number, phone number, email address, profile picture and employment information, and shares it with the Beijing Organizing Committee for the 2022 Olympics. For international users, the app collects users’ demographic information and passport information, as well as the organization to which they belong.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is wort[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks | Black Hat Ethical Hacking
The mobile app that all attendees and athletes of the upcoming Beijing Winter Olympics must use to manage communications and documentation at the event has a “devastating” flaw in the way it encrypts data that can allow for man-in-the-middle attacks that…