Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Credential-Stuffing Attacks on Remote Windows Systems Took Off in 2021

Password-guessing became last year's weapon of choice, as attackers attempted to brute-force vulnerable Remote Desktop Protocol (RDP) servers, SQL databases, and SMB file shares.
Dark Reading: Attacks/Breaches
Retailers' Offboarding Procedures Leave Potential Risks

IT teams need to consider unforeseen threats to avoid violating privacy regulations and supplier contracts.
Authenticated Penetration Testing
https://www.reddit.com/r/Pentesting/comments/spo2ff/authenticated_penetration_testing/

As with vulnerability scans, the tests (Penetration Testing) can either be authenticated or unauthenticated. An authenticated test runs as a registered and logged-in user on the internal network, whereas unauthenticated would be from an external source with no network privileges. https://phoenixnap.com/blog/vulnerability-scanning-vs-penetration-testing Let say there are multiple user roles on the target system. Do we need to request for all of them (tester id) and test or only one or two low privilege user and try privesc, IDOR, etc? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/Pentesting/comments/spo2ff/authenticated_penetration_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/spo2ff/authenticated_penetration_testing/)

___________________________
@hacking_Attack
@Hacking_Video