Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.3K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
iPhone and PC are hacked. What should I do?

Hi there hacking community,

If someone pissed off the wrong people and as a result, his iPhone and PC are now hacked, how should this person remove the hackers from his devices? This person has tried reinstalling fresh copies of Windows and IOS but this has not seemed to work.

Should this person buy a new iPhone and PC? This seems like the most reasonable approach because I looked up the price of zero-day exploits for iPhones and they are not cheap, to say the least.

Any guidance or advice would be really appreciated.

submitted by /u/TheTinkererofTerror
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Automating Response Is a Marathon, Not a Sprint

Organizations should balance process automation and human interaction to meet their unique security requirements.
Dark Reading: Attacks/Breaches
Researchers Discover Dangerous Firmware-Level Rootkit

MoonBounce is the latest in a small but growing number of implants found hidden in a computer's Unified Extensible Firmware Interface (UEFI).
hacking: security in practice
Is SSRF via javascript possible?

So I'm doing a CTF problem currently and I do know what the potential vuln is (unfiltered SSRF via puppeteer on the server), but because I'm a bit of a noob I'm unsure as to how exactly I'm able to exploit it further in order to achieve access within the localhost-eyes-only directories of the server.

I'm able to execute javascript and have tried making a fake website that would just execute javascript on the remote machine that ran a fetchcall on "localhost", with the results being sent back via GET parameters to the attacking server. However, I eventually quickly realized it was futile as CORS was enabled, thus leaving me in a familiar yet head-scratching position.

What exactly do I do from here? I'm not exactly looking for exact answers or solutions obviously, but is there any way I could be able to perform SSRF whilst having javascript access? Or should I look for another vulnerability as this could just be a dead end I tried so desperately to view as a door?

submitted by /u/TheByteQueen
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Top 10 web hacking techniques of 2021 — PortSwigger

OK , mình sẽ từ từ dịch hết tất cả các method , các bạn có thể có thể xem bản gốc ở đây : “‘Top 10 web hacking techniques of 2021 —…Continue reading on Medium »
Read more...