Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How I Found A Simple Stored XSS

This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Privilege Escalation in Linux Systems

https://cdn-images-1.medium.com/max/1000/1*FOIjs40QzGv1vT24qgMvuw.jpeg
Looking for a way to gain root access after establishing the initial foothold in Linux systems? Here are some things to look for to…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I Found A Simple Stored XSS

https://cdn-images-1.medium.com/max/800/1*v3z_7_uX2eKGvh7GFtaXhw.jpeg
This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…

Continue reading on Medium »
Good scanners recommendations for learning?
https://www.reddit.com/r/Pentesting/comments/sgo3al/good_scanners_recommendations_for_learning/

<!-- SC_OFF -->I'm interested in learning more about network and web application scanning. I started off with nmap, and found some of the NSE scripts very helpful. I then went to nikto but it's seems very basic, and I haven't been able to find much documentation. Do you all have some recommendations on scanning tools to learn for network, vulnerability, and web app scanning? ​ Kind regards <!-- SC_ON --> submitted by /u/sma92878 (https://www.reddit.com/user/sma92878)
[link] (https://www.reddit.com/r/Pentesting/comments/sgo3al/good_scanners_recommendations_for_learning/) [comments] (https://www.reddit.com/r/Pentesting/comments/sgo3al/good_scanners_recommendations_for_learning/)
This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…Continue reading on Medium » (https://medium.com/@raymond-lind/how-i-found-a-simple-stored-xss-a2976c5251b?source=rss------bug_bounty-5)
hacking: security in practice
So idk if this is the right place but, how could I bypass securely for chromebooks?

Hello, so I’m wanting to bypass securely for chromebooks. (I am using my own chromebook to test on) the only thing I’ve found that works is ctrl+shift+T I can’t enable Developer mode either. Any ideas anyone?

submitted by /u/Cg6554
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
SOCIAL BOT: My decision

Good night for you Guys and girls.

To day I made this Poll here asking about what to do with my Bot.

SO Here is my final choice I gonna make it reposoty public and acesseble for you guys.

I gonna make it public for 2 main reasons... SO you guys can download and test my project and may in the future give me a feedback and Becouse I want you guys... True Hackers, to help me TO apriomorate my Instagram algorithin Bypass

Social Bot Github page link: https://github.com/G4lile00/Social-Bot

On my Github You can find everything about the project... the documentation the download links and the explication to use the software... Now i count you guys to help me and maybe make this project a big thing.

submitted by /u/G4lile00
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is Yik Yak more secure in 2022?

I know there used to be a man in the middle vulnerability back in the day using the third party "Flurry". As far as I have researched Flurry is still around but does anyone know is they have stopped using plaintext HTTP? Genuinely curious about how secure the "anonymous" app is and if anyone has found any similar exploits.

submitted by /u/Seek7201
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Windows vulnerability with new public exploits lets you become admin

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Windows vulnerability with new public exploits lets you become adminPost Views: 206 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
A security researcher has publicly disclosed an exploit for a Windows local privilege elevation vulnerability that allows anyone to gain admin privileges in Windows 10.
Using this vulnerability, threat actors with limited access to a compromised device can easily elevate their privileges to help spread laterally within the network, create new administrative users, or perform privileged commands.

The vulnerability affects all supported support versions of Windows 10 before the January 2022 Patch Tuesday updates. Researcher releases bypass to patched vulnerabilityAs part of the January 2022 Patch Tuesday, Microsoft fixed a ‘Win32k Elevation of Privilege Vulnerability’ vulnerability tracked as CVE-2022-21882, which is a bypass for the previously patched and actively exploited CVE-2021-1732 bug.

Microsoft attributes the discovery of this vulnerability to RyeLv, who shared a technical analysis of the vulnerability after Microsoft released the patch.
See Also: Complete Offensive Security and Ethical Hacking Course
Regarding the just-fixed CVE-2022-21882:
win32k privilege escalation vulnerability,
CVE-2021-1732 patch bypass,easy to exploit,which was used by apt attacks

— b2ahex (@b2ahex) January 12, 2022
This week, multiple exploits were publicly released for CVE-2022-21882 that allow anyone to gain SYSTEM privileges on vulnerable Windows 10 devices.

After the exploit’s release, Will Dormann, a vulnerability analyst for CERT/CC and Twitter’s resident exploit tester, confirmed that the exploits works and provides elevated privileges.

BleepingComputer also tested the vulnerability and had no problem compiling the exploit and using it to open Notepad with SYSTEM privileges on Windows 10, as shown below. BleepingComputer could not get the exploit to work on Windows 11.
https://www.bleepstatic.com/images/news/Microsoft/vulnerabilities/CVE-2022-21882/CVE-2022-21882-test.jpg
Bug found two years earlierThis same vulnerability was discovered two years ago by Israeli security researcher and Piiano CEO Gil Dabah, who decided not to disclose the bug due to the reduced bug bounty rewards by Microsoft.

Dabah is not alone in his frustrations over Microsoft’s diminishing bug bounty rewards.

In[...]

___________________________
@hacking_Attack
@Hacking_Video