Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bir web uygulamasında kullanılan veriler dış bir kaynak aracılığıyla alınıyorsa ve saldırgan web sunucusunun göndermiş olduğu istek…Continue reading on Medium » (https://ariarif.medium.com/portswigger-web-security-ssrf-server-side-request-forgery-lab-%C3%A7%C3%B6z%C3%BCmleri%CC%87-693c47812f2d?source=rss------bug_bounty-5)
hacking: security in practice
How to point one domain to another?

Let's say there are two websites:

website1.com website2.com

What I'm trying to do is make the website1.com domain point to website2.com, aka website1.com connects to website2.com and gives website2's response data. I don't have access to these domains so this has to be done on the client-side.

Afaik there's no way to do this with the /etc/hosts file. I've tried looking into dnsmasq but it's complicated and I'm still not really sure if it's going to do what I want. Is there any simple way to do this?

submitted by /u/IllusiveWriting
[link] [comments]
hacking: security in practice
What should I do if I'm getting spied on through my computer?

Recently I'm noticing some weird stuff going on with my computer. It's like someone has access to it and sometimes i found that my laptop rebooted itself and i found a software called kinoni remote installed. also someone logged into my steam account and for some reason launched rocket league i can tell because the graphic settings of rocket league were changed and also the controller settings.

I'm pretty sure someone has access to my computer. the question is what should i do now?

submitted by /u/Sorry_Presence6406
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Easy peasy intro to LFI, part #1

Hey guys,

Wrote an easy to understand guide for a LFI (Local file inclusion) or directory traversal for beginners:

https://h4krg33k.medium.com/directory-traversal-what-is-it-905bc64a0b33?source=friends_link&sk=3695b37852b85427ae6a06c2d390b637

Hope it helps! 😁

Also follow me on medium for more articles 🤗

submitted by /u/ultimate_smash
[link] [comments]
PORTSWIGGER WEB SECURITY - SSRF (SERVER SIDE REQUEST FORGERY) LAB ÇÖZÜMLERİ

Bir web uygulamasında kullanılan veriler dış bir kaynak aracılığıyla alınıyorsa ve saldırgan web sunucusunun göndermiş olduğu istek…Continue reading on Medium »
Read more...
Directory Traversal — what is it?

Local File inclusionContinue reading on System Weakness »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
HybridTestFramework - End To End Testing Of Web, API And Security

https://blogger.googleusercontent.com/img/a/AVvXsEjYUvrCRFei8rhlyXAkeX9febuHiZJP9KkvmzP2xrp3Puma_BO2P7hvk0c3Y_lf-JmcDaIzjdR3_E4kCRlG0LYTe7x2dxjF9ajJ4I3c4XFXalm8lhaPyBNdNxyhiklwxt-EJS1DPYbsRNW3Q2QItJfY8zTaLqJ1FTj34QwpBldzYu3gzfNr4fugvN7I=w640-h416 Full-fledged WEB, API and Security testing framework using selenium,ZAP OWASP proxy and rest-assuredSupported PlatformsThis framework supports WebUi automation across a variety of browsers like Chrome, Firefox, IE, no only limited to this but extended to test rest api, security and visual testing. Capabilities* Cross browser testing support
* Added browserstack support for CrossBrowser testing
* Running tests in docker containers selenium grid
* Running tests in AWS DeviceFarm selenium grid
* Running tests in selenium server in docker containers
* Security testing using OWASP, running in docker container
* Api testing support using RestAssured
* Visual regression testing using percy.io
* Accessibility testing using axe-selenium
* Stubbed api testing using WireMock
* Can send logs to ElasticSearch for kibana dashboard visualization
* Database testing support
* Kafka testing support
* Kubernetes support Setup & Tools* Install intellij https://www.jetbrains.com/idea/download/
* Install docker desktop https://www.docker.com/products/docker-desktop
* Java JDK_11 https://adoptopenjdk.net/
* Gradle https://gradle.org/next-steps/?version=6.8.3&format=bin
* Allure https://github.com/allure-framework/allure2/archive/2.17.2.zip
* Set Environment variables
* JAVA_HOME: Pointing to the Java SDK folder\bin
* GRADLE_HOME: Pointing to Gradle directory\bin.
* ALLURE_HOME: Pointing to allure directory\bin. Getting Started$ git clone
$ cd
$ import project from intellij as a gradle project
$ gradle clean
$ gradle build
$ gradle task E2E
$ gradle allureReport
$ gradle allureServe
Write your first user journeyCreate new class and name as the TC00*_E2E_TEST-***

* Provide jira link in @Link
* Provide all the api components as @Feature
* Provide test severity and description
* Write test
* Use CatchBlock in try/catch section Spin-up chrome, firefox, selenium hub and OWASP proxy server$ docker-compose up -dComplete infrastructure creation for local run$ $ docker-compose -f docker-compose-infra up -dSpin-up four additional node-chrome/firefox instances linked to the hub$ docker-compose scale chrome=5
$ docker-compose scale firefox=5
Spin-up kafka instances$ docker-compose -f docker-compose-kafka.yml up
$ docker-compose -f docker-compose-kafka.yml down --rmi all
Spin-up selenium hub in kubernetes instance$ kubectl apply -f selenium-k8s-deploy-svc.yaml
$ kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0/aio/deploy/recommended.yaml
$ kubectl proxy
$ kubectl describe secret -n kube-system | grep deployment -A 12
## To delete deployments
$ kubectl delete deployment selenium-node-firefox
$ kubectl delete deployment selenium-node-chrome
$ kubectl delete deployment selenium-hub
navigate to http://localhost:8001/api/v1/namespaces/kubernetes-dashboard/services/https:kubernetes-dashboard:/proxy/https://blogger.googleusercontent.com/img/a/AVvXsEiT9QGW5IGy4viWX76GSDcpRoe4n0Z6-Y1YnzBICGJwpIPF60_Ulmq9Z23eUBDOtecHU8Efp90gMCSSWWc6rKjbuI2bKXFB_OL47T81eH6bhMZIPXJ62BDzpp9XOF9NYjoiUGybv-VnlTh3TzwPJ_Gwhe_iza8ys_jiMeqr97JBv6d1gDbH7vadZsDA=w640-h328 Execution Gifhttps://blogger.googleusercontent.com/img/a/AVvXsEhMce1R4wmz0q3Tml3Gx8DKaOCYVFykhWZkvkvpXwKyXU8fxh3GjcbEsoGMrvSNECoSdWT6f4Unm8yJjotAwcDFzNdGWmKpVKzaWVPELSjJ7fnNuPr_76MaXseTGHPYHKp4WhoE-RvrW431sTvO828KTdBfpKpvRxIjIH2lkUPVK7[...]

___________________________
@hacking_Attack
@Hacking_Video