Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Log4Shell Vulnerability
A new digital robbery has appeared in the world of cybersecurity. Rumours of a new zero-day vulnerability, Log4Shell, affecting several Minecraft servers surfaced on December 9th, 2021. A zero-day vulnerability is an exploit or flaw that is new and has not yet been studied by researchers or analysts. read more
submitted by /u/insights2techinfo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Log4Shell Vulnerability
A new digital robbery has appeared in the world of cybersecurity. Rumours of a new zero-day vulnerability, Log4Shell, affecting several Minecraft servers surfaced on December 9th, 2021. A zero-day vulnerability is an exploit or flaw that is new and has not yet been studied by researchers or analysts. read more
submitted by /u/insights2techinfo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Log4Shell Vulnerability
A new digital robbery has appeared in the world of cybersecurity. Rumours of a new zero-day vulnerability, Log4Shell, affecting several Minecraft...
Fuzzing is always fun..!!
https://pullakarthik5.medium.com/fuzzing-is-always-fun-1697af1a69fe?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://pullakarthik5.medium.com/fuzzing-is-always-fun-1697af1a69fe?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fuzzing is always fun..!!
Hello Everyone,
Hello Everyone,Continue reading on Medium » (https://pullakarthik5.medium.com/fuzzing-is-always-fun-1697af1a69fe?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fuzzing is always fun..!!
Hello Everyone,
PORTSWIGGER WEB SECURITY - XSS (CROSS SITE SCRIPTING) LAB ÇÖZÜMLERİ
https://ariarif.medium.com/portswigger-web-security-xss-cross-site-scripting-lab-%C3%A7%C3%B6z%C3%BCmleri%CC%87-fbaf7489bc5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://ariarif.medium.com/portswigger-web-security-xss-cross-site-scripting-lab-%C3%A7%C3%B6z%C3%BCmleri%CC%87-fbaf7489bc5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
PORTSWIGGER WEB SECURITY - XSS (CROSS SITE SCRIPTING) LAB ÇÖZÜMLERİ
Cross Site Scripting (Siteler Arası Komut Dosyası Çalıştırma), saldırganın bir web uygulamasında çalıştırdığı zararlı komutlar sonucunda…
Cross Site Scripting (Siteler Arası Komut Dosyası Çalıştırma), saldırganın bir web uygulamasında çalıştırdığı zararlı komutlar sonucunda…Continue reading on Medium » (https://ariarif.medium.com/portswigger-web-security-xss-cross-site-scripting-lab-%C3%A7%C3%B6z%C3%BCmleri%CC%87-fbaf7489bc5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
PORTSWIGGER WEB SECURITY - XSS (CROSS SITE SCRIPTING) LAB ÇÖZÜMLERİ
Cross Site Scripting (Siteler Arası Komut Dosyası Çalıştırma), saldırganın bir web uygulamasında çalıştırdığı zararlı komutlar sonucunda…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Smartest Way to Protect Your Cryptocurrency Investments
https://cdn-images-1.medium.com/max/2600/1*xZyz7rlboxsUDA26f21CFw.jpeg
What you need to know to minimize the risk of a savvy hacker hacking your cryptocurrencies
Continue reading on Crypto Unchained »
___________________________
@hacking_Attack
@Hacking_Video
The Smartest Way to Protect Your Cryptocurrency Investments
https://cdn-images-1.medium.com/max/2600/1*xZyz7rlboxsUDA26f21CFw.jpeg
What you need to know to minimize the risk of a savvy hacker hacking your cryptocurrencies
Continue reading on Crypto Unchained »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Smartest Way to Protect Your Cryptocurrency Balances
What you need to know to minimize the risk of a savvy hacker hacking your cryptocurrencies
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Parsing Memory Image with bulk_extractor
https://cdn-images-1.medium.com/max/1907/1*I7OocVCHfPbEawFcgukeqg.png
Sometimes parsing could be the good reason to resolve complex cases.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Parsing Memory Image with bulk_extractor
https://cdn-images-1.medium.com/max/1907/1*I7OocVCHfPbEawFcgukeqg.png
Sometimes parsing could be the good reason to resolve complex cases.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Parsing Memory Image with bulk_extractor
Sometimes parsing could be the good reason to resolve complex cases.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The lethal CSRF attack that web developers should be afraid of
https://cdn-images-1.medium.com/max/753/1*kAHZ84jtl8aPacghxvcXag.png
CSRF attacks are very common, but they are still unknown among developers. I’ll tell you what a CSRF is and how to get rid of it!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The lethal CSRF attack that web developers should be afraid of
https://cdn-images-1.medium.com/max/753/1*kAHZ84jtl8aPacghxvcXag.png
CSRF attacks are very common, but they are still unknown among developers. I’ll tell you what a CSRF is and how to get rid of it!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is a CSRF attack and how to prevent it
CSRF attacks are very common, but they are still unknown among developers. I’ll tell you what a CSRF is and how to get rid of it!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Privilege Escalation | Kenobi Walkthrough | Part 2
https://cdn-images-1.medium.com/max/1920/1*fP_yyQQaRz189X-Yqg7y6g.png
To find the second flag, we have to be the root user, and to become the root user we can search for files that have SUID bit set. If we…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Privilege Escalation | Kenobi Walkthrough | Part 2
https://cdn-images-1.medium.com/max/1920/1*fP_yyQQaRz189X-Yqg7y6g.png
To find the second flag, we have to be the root user, and to become the root user we can search for files that have SUID bit set. If we…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Privilege Escalation | Kenobi Walkthrough | Part 2
To find the second flag, we have to be the root user, and to become the root user we can search for files that have SUID bit set. If we…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Over 90 WordPress themes, plugins backdoored in supply chain attack
https://external-preview.redd.it/TgWUBoMfAj41GeJtnqCg0aqh7FG4WpHKz0O4G8zSb6k.jpg?width=640&crop=smart&auto=webp&s=11a536c7dc697c451798771a112da72cd0ce747b submitted by /u/donutloop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Over 90 WordPress themes, plugins backdoored in supply chain attack
https://external-preview.redd.it/TgWUBoMfAj41GeJtnqCg0aqh7FG4WpHKz0O4G8zSb6k.jpg?width=640&crop=smart&auto=webp&s=11a536c7dc697c451798771a112da72cd0ce747b submitted by /u/donutloop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Over 90 WordPress themes, plugins backdoored in supply chain attack
Posted in r/hacking by u/donutloop • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Gartner predicts 75% of CEOs will be personally liable for cyber-physical security incidents by 2024
https://external-preview.redd.it/Ed6udX2ZAkmAHbDuSFSGW7LMoCZ4_A8n1QWY5J1uMRA.jpg?width=640&crop=smart&auto=webp&s=58cff7cbf000779cfeabdff62b1d3616afe57565 submitted by /u/armcab
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Gartner predicts 75% of CEOs will be personally liable for cyber-physical security incidents by 2024
https://external-preview.redd.it/Ed6udX2ZAkmAHbDuSFSGW7LMoCZ4_A8n1QWY5J1uMRA.jpg?width=640&crop=smart&auto=webp&s=58cff7cbf000779cfeabdff62b1d3616afe57565 submitted by /u/armcab
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Gartner predicts 75% of CEOs will be personally liable for...
Posted in r/hacking by u/armcab • 1 point and 0 comments
hacking: security in practice
Hey guys, funny story
Idk where to go for this but here it goes, some dude a discord server i was in was a pedo and sex offender, i reported him, but now he’s basically trying to pull my IP and find where i live. will deleting my discord account stop this
submitted by /u/Dr-Toast-man
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hey guys, funny story
Idk where to go for this but here it goes, some dude a discord server i was in was a pedo and sex offender, i reported him, but now he’s basically trying to pull my IP and find where i live. will deleting my discord account stop this
submitted by /u/Dr-Toast-man
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Second-Order - Subdomain Takeover Scanner
Scans web applications for second-order subdomain takeover by crawling the app, and collecting URLs (and other data) that match certain rules, or respond in a certain way. Installation From binary Download a prebuilt binary from the releases page and unzip it. From source Go version 1.17 is recommended. go install -v github.com/mhmdiaa/second-order@latest Docker docker pull mhmdiaa/second-order Command line options Directory to save results in (default "output") -threads int Number of threads (default 10)"> -target string Target URL -config string Configuration file (default "config.json") -depth int Depth to crawl (default 1) -header value Header name and value separated by a colon 'Name: Value' (can be used more than once) -insecure Accept untrusted SSL/TLS certificates -output string Directory to save results in (default "output") -threads int Number of threads (default 10) Configuration File Example configuration files are in config LogQueries: A map of tag-attribute queries that will be searched for in crawled pages. For example, "a": "href" means log every href attribute of every a tag. LogNon200Queries: A map of tag-attribute queries that will be searched for in crawled pages, and logged only if they contain a valid URL that doesn't return a 200 status code. LogInline: A list of tags whose inline content (between the opening and closing tags) will be logged, like title and script Output All results are saved in JSON files that specify what and where data was found The results of LogQueries are saved in attributes.json { "https://example.com/": { "inputname": "user", "id", "debug" }} The results of LogNon200Queries are saved in non-200-url-attributes.json { "https://example.com/": { "scriptsrc": "https://cdn.old\_abandoned\_domain.com/app.js", }} The results of LogInline are saved in inline.json { "https://example.com/": { "title": "Example - Home" }, "https://example.com/login": { "title": "Example - login" }} Usage Ideas This is a list of tips and ideas (not necessarily related to second-order subdomain takeover) on what to use Second Order for. Check for second-order subdomain takeover: takeover.json. (Duh!) Collect inline and imported JS code: javascript.json. Find where a target hosts static files cdn.json. (S3 buckets, anyone?) Collect names to build a tailored parameter bruteforcing wordlist: parameters.json. Feel free to contribute more ideas! References https://shubs.io/high-frequency-security-bug-hunting-120-days-120-bugs/#secondorder https://edoverflow.com/2017/broken-link-hijacking/ Download Second-Order
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Scans web applications for second-order subdomain takeover by crawling the app, and collecting URLs (and other data) that match certain rules, or respond in a certain way. Installation From binary Download a prebuilt binary from the releases page and unzip it. From source Go version 1.17 is recommended. go install -v github.com/mhmdiaa/second-order@latest Docker docker pull mhmdiaa/second-order Command line options Directory to save results in (default "output") -threads int Number of threads (default 10)"> -target string Target URL -config string Configuration file (default "config.json") -depth int Depth to crawl (default 1) -header value Header name and value separated by a colon 'Name: Value' (can be used more than once) -insecure Accept untrusted SSL/TLS certificates -output string Directory to save results in (default "output") -threads int Number of threads (default 10) Configuration File Example configuration files are in config LogQueries: A map of tag-attribute queries that will be searched for in crawled pages. For example, "a": "href" means log every href attribute of every a tag. LogNon200Queries: A map of tag-attribute queries that will be searched for in crawled pages, and logged only if they contain a valid URL that doesn't return a 200 status code. LogInline: A list of tags whose inline content (between the opening and closing tags) will be logged, like title and script Output All results are saved in JSON files that specify what and where data was found The results of LogQueries are saved in attributes.json { "https://example.com/": { "inputname": "user", "id", "debug" }} The results of LogNon200Queries are saved in non-200-url-attributes.json { "https://example.com/": { "scriptsrc": "https://cdn.old\_abandoned\_domain.com/app.js", }} The results of LogInline are saved in inline.json { "https://example.com/": { "title": "Example - Home" }, "https://example.com/login": { "title": "Example - login" }} Usage Ideas This is a list of tips and ideas (not necessarily related to second-order subdomain takeover) on what to use Second Order for. Check for second-order subdomain takeover: takeover.json. (Duh!) Collect inline and imported JS code: javascript.json. Find where a target hosts static files cdn.json. (S3 buckets, anyone?) Collect names to build a tailored parameter bruteforcing wordlist: parameters.json. Feel free to contribute more ideas! References https://shubs.io/high-frequency-security-bug-hunting-120-days-120-bugs/#secondorder https://edoverflow.com/2017/broken-link-hijacking/ Download Second-Order
Read more...
___________________________
@hacking_Attack
@Hacking_Video