Hacking on Medium
Bug Bounty Stress aka Burnout: do and don’t
https://cdn-images-1.medium.com/max/1920/1*tvlFmCexwEsy1L1GiY6w-g.jpeg
Don’t stress yourself too much!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty Stress aka Burnout: do and don’t
https://cdn-images-1.medium.com/max/1920/1*tvlFmCexwEsy1L1GiY6w-g.jpeg
Don’t stress yourself too much!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is burnout?
Don’t stress yourself too much!
Hacking on Medium
Sale actualización de emergencia de Google Chrome que corrige vulnerabilidad 0-Day explotada en…
https://cdn-images-1.medium.com/max/1600/0*11oNNLvGQFSL5EnK
PUBLICADO EN 15 FEBRERO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Sale actualización de emergencia de Google Chrome que corrige vulnerabilidad 0-Day explotada en…
https://cdn-images-1.medium.com/max/1600/0*11oNNLvGQFSL5EnK
PUBLICADO EN 15 FEBRERO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sale actualización de emergencia de Google Chrome que corrige vulnerabilidad 0-Day explotada en ciberataques
PUBLICADO EN 15 FEBRERO, 2022POR EHACKING
Hacking on Medium
Analysis of Cyber Attacks using a Honeypot
https://cdn-images-1.medium.com/max/600/1*vAViIGNviToupv7qyob4rA.png
What is a Honeypot?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Analysis of Cyber Attacks using a Honeypot
https://cdn-images-1.medium.com/max/600/1*vAViIGNviToupv7qyob4rA.png
What is a Honeypot?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Analysis of Cyber Attacks using a Honeypot
What is a Honeypot?
Hacking on Medium
How WordPress Sites Get Hacked: 5 Common Vulnerabilities & How to Avoid Them in 2022
https://cdn-images-1.medium.com/max/2600/1*FQzzjVFTJlczV1cVW5HyQQ.jpeg
WordPress is a popular free and open source content platform that allows users to select from a variety of themes based on their…
Continue reading on The Geek Zone »
___________________________
@hacking_Attack
@Hacking_Video
How WordPress Sites Get Hacked: 5 Common Vulnerabilities & How to Avoid Them in 2022
https://cdn-images-1.medium.com/max/2600/1*FQzzjVFTJlczV1cVW5HyQQ.jpeg
WordPress is a popular free and open source content platform that allows users to select from a variety of themes based on their…
Continue reading on The Geek Zone »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How WordPress Sites Get Hacked: 5 Common Vulnerabilities & How to Avoid Them in 2022
WordPress is a popular free and open source content platform that allows users to select from a variety of themes based on their…
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Shellcodetester - An Application To Test Windows And Linux Shellcodes
https://blogger.googleusercontent.com/img/a/AVvXsEh359EAhOCA5GJ7ojPG5cU1nXGVd0eq2gIXlEH8IV5sHGWdvVOyiGVgm1kwJn1vWP3q-qV-wI258ED_fzW4a_zgHRTe7HwV9pDqSdUVu2BTpyZlQ5ceVU08S8pwVzIFYQE6lWx4WTklkWIoyFugaZbFlQcXDzeMsvVHKl6QodXpBLdRC4fDVP_Bg3s9=w640-h298
This tools test generated ShellCodes.
Usage
https://blogger.googleusercontent.com/img/a/AVvXsEh359EAhOCA5GJ7ojPG5cU1nXGVd0eq2gIXlEH8IV5sHGWdvVOyiGVgm1kwJn1vWP3q-qV-wI258ED_fzW4a_zgHRTe7HwV9pDqSdUVu2BTpyZlQ5ceVU08S8pwVzIFYQE6lWx4WTklkWIoyFugaZbFlQcXDzeMsvVHKl6QodXpBLdRC4fDVP_Bg3s9=w640-h298
Exemple
https://blogger.googleusercontent.com/img/a/AVvXsEhos2UuZHRXmJOWRoWhK5Qh3vhp6DJi3JLU1nOXH4I5sl0dDHNupYthcmIWa-Ccxb3NS6sbnw4_khUWoVp5HKF_4mvNqW0uKB5B4bXXCjn49Yml1H-eog7E5L4Hv3jwGy0W7o7eDR0On1imVdpxgGFROW7EkeWA7v_k0ZS4YZpLtSAkiijfJv5Q4qnx=w640-h112
https://blogger.googleusercontent.com/img/a/AVvXsEhAktm6Whx443Mj9PzCTsrwzW34TC7xIc6lXfRgAEOlCxMqh2eD9N_v0YQ8xH0rVex2wLlqep43IvGlQl4AyCAsU29FA2BF16olaXH6U0o5iWg06bKPwqf-9ABO3LUb4enD_K_If_oN3ckVw9tF0uEhaAfNGCjPm8zP5XASrZ-S62Bfkv6orh068ojo=w640-h298
ShellCode Tester Linux
Instalation
Usage
Without break-point:
With break-point (INT3). The break-point will be inserted before our generated shellcode:
Download Shellcodetester
___________________________
@hacking_Attack
@Hacking_Video
Shellcodetester - An Application To Test Windows And Linux Shellcodes
https://blogger.googleusercontent.com/img/a/AVvXsEh359EAhOCA5GJ7ojPG5cU1nXGVd0eq2gIXlEH8IV5sHGWdvVOyiGVgm1kwJn1vWP3q-qV-wI258ED_fzW4a_zgHRTe7HwV9pDqSdUVu2BTpyZlQ5ceVU08S8pwVzIFYQE6lWx4WTklkWIoyFugaZbFlQcXDzeMsvVHKl6QodXpBLdRC4fDVP_Bg3s9=w640-h298
This tools test generated ShellCodes.
Usage
https://blogger.googleusercontent.com/img/a/AVvXsEh359EAhOCA5GJ7ojPG5cU1nXGVd0eq2gIXlEH8IV5sHGWdvVOyiGVgm1kwJn1vWP3q-qV-wI258ED_fzW4a_zgHRTe7HwV9pDqSdUVu2BTpyZlQ5ceVU08S8pwVzIFYQE6lWx4WTklkWIoyFugaZbFlQcXDzeMsvVHKl6QodXpBLdRC4fDVP_Bg3s9=w640-h298
Exemple
https://blogger.googleusercontent.com/img/a/AVvXsEhos2UuZHRXmJOWRoWhK5Qh3vhp6DJi3JLU1nOXH4I5sl0dDHNupYthcmIWa-Ccxb3NS6sbnw4_khUWoVp5HKF_4mvNqW0uKB5B4bXXCjn49Yml1H-eog7E5L4Hv3jwGy0W7o7eDR0On1imVdpxgGFROW7EkeWA7v_k0ZS4YZpLtSAkiijfJv5Q4qnx=w640-h112
https://blogger.googleusercontent.com/img/a/AVvXsEhAktm6Whx443Mj9PzCTsrwzW34TC7xIc6lXfRgAEOlCxMqh2eD9N_v0YQ8xH0rVex2wLlqep43IvGlQl4AyCAsU29FA2BF16olaXH6U0o5iWg06bKPwqf-9ABO3LUb4enD_K_If_oN3ckVw9tF0uEhaAfNGCjPm8zP5XASrZ-S62Bfkv6orh068ojo=w640-h298
ShellCode Tester Linux
Instalation
git clone https://github.com/helviojunior/shellcodetester.git
cd shellcodetester/Linux
make
Usage
Without break-point:
shellcodetester [file.asm]
With break-point (INT3). The break-point will be inserted before our generated shellcode:
shellcodetester [file.asm] --break-point
Download Shellcodetester
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Shellcodetester - An Application To Test Windows And Linux Shellcodes
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Horizontall HackTheBox Walkthrough
IntroductionHorizontall is an “easy” rated CTF Linux box on Hack The Box platform. The box covers initial compromise by exploiting Strapi RCE vulnerability and escalating privileges by tunneling an internal application (Laravel) to local machine and running a PoC exploit on Laravel v 7.4.18Table of Content· nmapEnumeration· Subdomain enumeration using wfuzzExploitation· Exploiting strapi CVE-2019-18818 to gain a reverse shellPrivilege Escalation· Tunneling internal website to our systemNetwork ScanningFirst, we will run an nmap scan on the victim machine nmap -sV -sC -Pn 10.129.149.92https://blogger.googleusercontent.com/img/a/AVvXsEgpA-ERDt2IsmWu1onaA-eMoZwP8bM2uw9PiJTKSVhKoFR54wVRzWG5wS5slegvKNv96-piH_BX9d2EJ-JBGaOxii2snN8fZzMBYisTeSiDuFnZrphFY1QlfDB-xsujwKCaqC32lNPf9rvtTSaeahA3fCA0SdRdcQgGqnBHE8N0dIf74HfEzZcEmpP21w=s16000 EnumerationSince, there was a website running on port 80, we added the address in our hosts file for resolution.wfuzz -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.horizontall.htb" --sc 200 10.129.149.92This returned back an interesting subdomain called api-prodecho "10.129.149.92 api-prod.horizontall.htb" >> /etc/hostshttps://blogger.googleusercontent.com/img/a/AVvXsEhpkAZ1FQs1vINrFT3yNzeAQkUBox1nTSnNah3GeSiEV2eTGyIPZ4cpdN_mH_lfagNRDvjotfYtJ836KXZX5RU_KFMmhJx3cItwy6f1yu515CYVjdbfSMR8LlZ9ynhLajeA7mrczF2tcplH1_NKjMKjlHF7-pFqrQGLiJ5ISMGKIt2SG_DJ0gKKyGx0_g=s16000 It seemed like a plain website with no vectors again and thus, we tried directory enumeration. We found a directory /admin. Upon checking the components that made this website, we found the title to be strapi.whatweb http://api-prod.horizontall.htb/admin/https://blogger.googleusercontent.com/img/a/AVvXsEimfroWYSUi1l_gg2u2KOWFlyXtQy0UO7pcFA_13LhNTK6-GU9OWI8g6P9dODQk8rTY7nSMAQ8kU-546CCQGx-XgQGXMNitJpK5N6MW1g50oQTdBQ5-PkpEHEtweHKNxBNt6GMKmDAVRcTbw_8Imz88hk1DWXvJCIP2G-r-JDqv3nPL6FCrGr9dPoBhhA=s16000 We observed the response in burp and noticed strapi version to be 3.0.0-beta 17.4https://blogger.googleusercontent.com/img/a/AVvXsEiCJ8FgYHLpzxFTOdtwRwzcnHXhtUbc2NH_ehA9tppXwpZUVlKdpIJWRz5XgsL9HCbz7x2_L96MfIcWW4um32hlBV8Ev-kaKCwF2LH6afj-GKoyTn8OFA3Xu6MIripA_Y12Sg0mGnZAlnPvt1zXMqwuhWLgLgddxw6sQcDesQWrxvUuDs7tImeGVplX5Q=s16000 ExploitationSearchsploit result showed us an exploit for the given version was available. This version was afflicted with CVE-2019-18818. This vulnerability allows an attacker to reset the admin password witho[...]
___________________________
@hacking_Attack
@Hacking_Video
Horizontall HackTheBox Walkthrough
IntroductionHorizontall is an “easy” rated CTF Linux box on Hack The Box platform. The box covers initial compromise by exploiting Strapi RCE vulnerability and escalating privileges by tunneling an internal application (Laravel) to local machine and running a PoC exploit on Laravel v 7.4.18Table of Content· nmapEnumeration· Subdomain enumeration using wfuzzExploitation· Exploiting strapi CVE-2019-18818 to gain a reverse shellPrivilege Escalation· Tunneling internal website to our systemNetwork ScanningFirst, we will run an nmap scan on the victim machine nmap -sV -sC -Pn 10.129.149.92https://blogger.googleusercontent.com/img/a/AVvXsEgpA-ERDt2IsmWu1onaA-eMoZwP8bM2uw9PiJTKSVhKoFR54wVRzWG5wS5slegvKNv96-piH_BX9d2EJ-JBGaOxii2snN8fZzMBYisTeSiDuFnZrphFY1QlfDB-xsujwKCaqC32lNPf9rvtTSaeahA3fCA0SdRdcQgGqnBHE8N0dIf74HfEzZcEmpP21w=s16000 EnumerationSince, there was a website running on port 80, we added the address in our hosts file for resolution.wfuzz -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.horizontall.htb" --sc 200 10.129.149.92This returned back an interesting subdomain called api-prodecho "10.129.149.92 api-prod.horizontall.htb" >> /etc/hostshttps://blogger.googleusercontent.com/img/a/AVvXsEhpkAZ1FQs1vINrFT3yNzeAQkUBox1nTSnNah3GeSiEV2eTGyIPZ4cpdN_mH_lfagNRDvjotfYtJ836KXZX5RU_KFMmhJx3cItwy6f1yu515CYVjdbfSMR8LlZ9ynhLajeA7mrczF2tcplH1_NKjMKjlHF7-pFqrQGLiJ5ISMGKIt2SG_DJ0gKKyGx0_g=s16000 It seemed like a plain website with no vectors again and thus, we tried directory enumeration. We found a directory /admin. Upon checking the components that made this website, we found the title to be strapi.whatweb http://api-prod.horizontall.htb/admin/https://blogger.googleusercontent.com/img/a/AVvXsEimfroWYSUi1l_gg2u2KOWFlyXtQy0UO7pcFA_13LhNTK6-GU9OWI8g6P9dODQk8rTY7nSMAQ8kU-546CCQGx-XgQGXMNitJpK5N6MW1g50oQTdBQ5-PkpEHEtweHKNxBNt6GMKmDAVRcTbw_8Imz88hk1DWXvJCIP2G-r-JDqv3nPL6FCrGr9dPoBhhA=s16000 We observed the response in burp and noticed strapi version to be 3.0.0-beta 17.4https://blogger.googleusercontent.com/img/a/AVvXsEiCJ8FgYHLpzxFTOdtwRwzcnHXhtUbc2NH_ehA9tppXwpZUVlKdpIJWRz5XgsL9HCbz7x2_L96MfIcWW4um32hlBV8Ev-kaKCwF2LH6afj-GKoyTn8OFA3Xu6MIripA_Y12Sg0mGnZAlnPvt1zXMqwuhWLgLgddxw6sQcDesQWrxvUuDs7tImeGVplX5Q=s16000 ExploitationSearchsploit result showed us an exploit for the given version was available. This version was afflicted with CVE-2019-18818. This vulnerability allows an attacker to reset the admin password witho[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Horizontall HackTheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles|Raj Chandel's Blog
Horizontall HackTheBox Walkthrough
___________________________
@hacking_Attack
@Hacking_Video
Horizontall HackTheBox Walkthrough
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Horizontall HackTheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CompTIA ISAO and IT-ISAC Urge Technology Companies to Elevate Cybersecurity Monitoring, Readiness in Response to Rising Geopolitical Tensions
The CompTIA ISAO and IT-ISAC teams will continue to provide updated reporting and share new threat information as it becomes available.
___________________________
@hacking_Attack
@Hacking_Video
CompTIA ISAO and IT-ISAC Urge Technology Companies to Elevate Cybersecurity Monitoring, Readiness in Response to Rising Geopolitical Tensions
The CompTIA ISAO and IT-ISAC teams will continue to provide updated reporting and share new threat information as it becomes available.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
CompTIA ISAO and IT-ISAC Urge Technology Companies to Elevate Cybersecurity Monitoring, Readiness in Response to Rising Geopolitical…
The CompTIA ISAO and IT-ISAC teams will continue to provide updated reporting and share new threat information as it becomes available.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Bugcrowd Announces Real-Time Customer Visibility and Improved Crowd-matching For Penetration Testing as a Service Solution
New features include a rich dashboard with customer visibility into the progress of methodology-based pen tests.
___________________________
@hacking_Attack
@Hacking_Video
Bugcrowd Announces Real-Time Customer Visibility and Improved Crowd-matching For Penetration Testing as a Service Solution
New features include a rich dashboard with customer visibility into the progress of methodology-based pen tests.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Bugcrowd Announces Real-Time Customer Visibility and Improved Crowd-matching For Penetration Testing as a Service Solution
New features include a rich dashboard with customer visibility into the progress of methodology-based pen tests.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
NYU Tandon Launches Chief Information Security Officer Program
Featuring in-depth core sessions and topical electives, the nine-month program takes a risk-based approach to cyber strategy.
___________________________
@hacking_Attack
@Hacking_Video
NYU Tandon Launches Chief Information Security Officer Program
Featuring in-depth core sessions and topical electives, the nine-month program takes a risk-based approach to cyber strategy.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
NYU Tandon Launches Chief Information Security Officer Program
Featuring in-depth core sessions and topical electives, the nine-month program takes a risk-based approach to cyber strategy.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
2022 Executive Women's Forum Annual Conference to Be In Person for 20th Anniversary Celebration
This year’s theme is “Celebrating 20 Years of Building Women Leaders.”
___________________________
@hacking_Attack
@Hacking_Video
2022 Executive Women's Forum Annual Conference to Be In Person for 20th Anniversary Celebration
This year’s theme is “Celebrating 20 Years of Building Women Leaders.”
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
2022 Executive Women's Forum Annual Conference to Be In Person for 20th Anniversary Celebration
This year’s theme is “Celebrating 20 Years of Building Women Leaders.”
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Netacea Announces $12M Series A Investment
New funding will be used to grow Netacea’s presence in US and UK bot mitigation markets.
___________________________
@hacking_Attack
@Hacking_Video
Netacea Announces $12M Series A Investment
New funding will be used to grow Netacea’s presence in US and UK bot mitigation markets.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Netacea Announces $12M Series A Investment
New funding will be used to grow Netacea’s presence in US and UK bot mitigation markets.