Bir web uygulamasında kullanılan veriler dış bir kaynak aracılığıyla alınıyorsa ve saldırgan web sunucusunun göndermiş olduğu istek…Continue reading on Medium » (https://ariarif.medium.com/portswigger-web-security-ssrf-server-side-request-forgery-lab-%C3%A7%C3%B6z%C3%BCmleri%CC%87-693c47812f2d?source=rss------bug_bounty-5)
hacking: security in practice
How to point one domain to another?
Let's say there are two websites:
website1.com website2.com
What I'm trying to do is make the website1.com domain point to website2.com, aka website1.com connects to website2.com and gives website2's response data. I don't have access to these domains so this has to be done on the client-side.
Afaik there's no way to do this with the /etc/hosts file. I've tried looking into dnsmasq but it's complicated and I'm still not really sure if it's going to do what I want. Is there any simple way to do this?
submitted by /u/IllusiveWriting
[link] [comments]
How to point one domain to another?
Let's say there are two websites:
website1.com website2.com
What I'm trying to do is make the website1.com domain point to website2.com, aka website1.com connects to website2.com and gives website2's response data. I don't have access to these domains so this has to be done on the client-side.
Afaik there's no way to do this with the /etc/hosts file. I've tried looking into dnsmasq but it's complicated and I'm still not really sure if it's going to do what I want. Is there any simple way to do this?
submitted by /u/IllusiveWriting
[link] [comments]
reddit
How to point one domain to another?
Let's say there are two websites: website1.com website2.com What I'm trying to do is make the website1.com domain point to website2.com, aka...
hacking: security in practice
What should I do if I'm getting spied on through my computer?
Recently I'm noticing some weird stuff going on with my computer. It's like someone has access to it and sometimes i found that my laptop rebooted itself and i found a software called kinoni remote installed. also someone logged into my steam account and for some reason launched rocket league i can tell because the graphic settings of rocket league were changed and also the controller settings.
I'm pretty sure someone has access to my computer. the question is what should i do now?
submitted by /u/Sorry_Presence6406
[link] [comments]
What should I do if I'm getting spied on through my computer?
Recently I'm noticing some weird stuff going on with my computer. It's like someone has access to it and sometimes i found that my laptop rebooted itself and i found a software called kinoni remote installed. also someone logged into my steam account and for some reason launched rocket league i can tell because the graphic settings of rocket league were changed and also the controller settings.
I'm pretty sure someone has access to my computer. the question is what should i do now?
submitted by /u/Sorry_Presence6406
[link] [comments]
reddit
What should I do if I'm getting spied on through my computer?
Recently I'm noticing some weird stuff going on with my computer. It's like someone has access to it and sometimes i found that my laptop rebooted...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Easy peasy intro to LFI, part #1
Hey guys,
Wrote an easy to understand guide for a LFI (Local file inclusion) or directory traversal for beginners:
https://h4krg33k.medium.com/directory-traversal-what-is-it-905bc64a0b33?source=friends_link&sk=3695b37852b85427ae6a06c2d390b637
Hope it helps! 😁
Also follow me on medium for more articles 🤗
submitted by /u/ultimate_smash
[link] [comments]
Easy peasy intro to LFI, part #1
Hey guys,
Wrote an easy to understand guide for a LFI (Local file inclusion) or directory traversal for beginners:
https://h4krg33k.medium.com/directory-traversal-what-is-it-905bc64a0b33?source=friends_link&sk=3695b37852b85427ae6a06c2d390b637
Hope it helps! 😁
Also follow me on medium for more articles 🤗
submitted by /u/ultimate_smash
[link] [comments]
Certipy 2.0: BloodHound, New Domain Privilege Escalation Techniques, Shadow Credentials, Golden Certificates, and more!
https://www.reddit.com/r/redteamsec/comments/sw9wjf/certipy_20_bloodhound_new_domain_privilege/
submitted by /u/ly4k_ (https://www.reddit.com/user/ly4k_)
[link] (https://research.ifcr.dk/certipy-2-0-bloodhound-new-escalations-shadow-credentials-golden-certificates-and-more-34d1c26f0dc6) [comments] (https://www.reddit.com/r/redteamsec/comments/sw9wjf/certipy_20_bloodhound_new_domain_privilege/)
https://www.reddit.com/r/redteamsec/comments/sw9wjf/certipy_20_bloodhound_new_domain_privilege/
submitted by /u/ly4k_ (https://www.reddit.com/user/ly4k_)
[link] (https://research.ifcr.dk/certipy-2-0-bloodhound-new-escalations-shadow-credentials-golden-certificates-and-more-34d1c26f0dc6) [comments] (https://www.reddit.com/r/redteamsec/comments/sw9wjf/certipy_20_bloodhound_new_domain_privilege/)
Directory Traversal — what is it?
https://systemweakness.com/directory-traversal-what-is-it-905bc64a0b33?source=rss------bug_bounty-5
https://systemweakness.com/directory-traversal-what-is-it-905bc64a0b33?source=rss------bug_bounty-5
Local File inclusionContinue reading on System Weakness » (https://systemweakness.com/directory-traversal-what-is-it-905bc64a0b33?source=rss------bug_bounty-5)
PORTSWIGGER WEB SECURITY - SSRF (SERVER SIDE REQUEST FORGERY) LAB ÇÖZÜMLERİ
Bir web uygulamasında kullanılan veriler dış bir kaynak aracılığıyla alınıyorsa ve saldırgan web sunucusunun göndermiş olduğu istek…Continue reading on Medium »
Read more...
Bir web uygulamasında kullanılan veriler dış bir kaynak aracılığıyla alınıyorsa ve saldırgan web sunucusunun göndermiş olduğu istek…Continue reading on Medium »
Read more...
Directory Traversal — what is it?
Local File inclusionContinue reading on System Weakness »
Read more...
Local File inclusionContinue reading on System Weakness »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
OpenCamera hack for Pixel 6 Pro
https://external-preview.redd.it/b2eha5pQarM2_wl3-usZIaHxFdQv1EjGI_4h5ikYl5U.jpg?width=640&crop=smart&auto=webp&s=aeb25f5ebb38477e7d4f93ec906657f657a3025a submitted by /u/binaryfor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
OpenCamera hack for Pixel 6 Pro
https://external-preview.redd.it/b2eha5pQarM2_wl3-usZIaHxFdQv1EjGI_4h5ikYl5U.jpg?width=640&crop=smart&auto=webp&s=aeb25f5ebb38477e7d4f93ec906657f657a3025a submitted by /u/binaryfor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
OpenCamera hack for Pixel 6 Pro
Posted in r/hacking by u/binaryfor • 1 point and 0 comments
Hacking on Medium
TryHackMe: Jeff — Writeup
https://cdn-images-1.medium.com/max/2600/0*eRPk-_-Q0T1PwhYE
Room difficulty: Hard
Topics: Web server enumeration, wordpress exploitation, working with vhosts, cracking encrypted zip files, docker…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: Jeff — Writeup
https://cdn-images-1.medium.com/max/2600/0*eRPk-_-Q0T1PwhYE
Room difficulty: Hard
Topics: Web server enumeration, wordpress exploitation, working with vhosts, cracking encrypted zip files, docker…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: Jeff — Writeup
Room difficulty: Hard Topics: Web server enumeration, wordpress exploitation, working with vhosts, cracking encrypted zip files, docker…
Hacking on Medium
Leviathan — OverTheWire Wargame — Writeup
https://cdn-images-1.medium.com/max/1594/1*oEC3N5yv2JxhX806Rk0E9w.png
Leviathan is a wargame offered by OverTheWire. It ‘doesn’t require any knowledge about programming — just a bit of common sense and some…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Leviathan — OverTheWire Wargame — Writeup
https://cdn-images-1.medium.com/max/1594/1*oEC3N5yv2JxhX806Rk0E9w.png
Leviathan is a wargame offered by OverTheWire. It ‘doesn’t require any knowledge about programming — just a bit of common sense and some…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Leviathan — OverTheWire Wargame — Writeup
Leviathan is a wargame offered by OverTheWire. It ‘doesn’t require any knowledge about programming — just a bit of common sense and some…
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
HybridTestFramework - End To End Testing Of Web, API And Security
https://blogger.googleusercontent.com/img/a/AVvXsEjYUvrCRFei8rhlyXAkeX9febuHiZJP9KkvmzP2xrp3Puma_BO2P7hvk0c3Y_lf-JmcDaIzjdR3_E4kCRlG0LYTe7x2dxjF9ajJ4I3c4XFXalm8lhaPyBNdNxyhiklwxt-EJS1DPYbsRNW3Q2QItJfY8zTaLqJ1FTj34QwpBldzYu3gzfNr4fugvN7I=w640-h416 Full-fledged WEB, API and Security testing framework using selenium,ZAP OWASP proxy and rest-assuredSupported PlatformsThis framework supports WebUi automation across a variety of browsers like Chrome, Firefox, IE, no only limited to this but extended to test rest api, security and visual testing. Capabilities* Cross browser testing support
* Added browserstack support for CrossBrowser testing
* Running tests in docker containers selenium grid
* Running tests in AWS DeviceFarm selenium grid
* Running tests in selenium server in docker containers
* Security testing using OWASP, running in docker container
* Api testing support using RestAssured
* Visual regression testing using percy.io
* Accessibility testing using axe-selenium
* Stubbed api testing using WireMock
* Can send logs to ElasticSearch for kibana dashboard visualization
* Database testing support
* Kafka testing support
* Kubernetes support Setup & Tools* Install intellij https://www.jetbrains.com/idea/download/
* Install docker desktop https://www.docker.com/products/docker-desktop
* Java JDK_11 https://adoptopenjdk.net/
* Gradle https://gradle.org/next-steps/?version=6.8.3&format=bin
* Allure https://github.com/allure-framework/allure2/archive/2.17.2.zip
* Set Environment variables
* JAVA_HOME: Pointing to the Java SDK folder\bin
* GRADLE_HOME: Pointing to Gradle directory\bin.
* ALLURE_HOME: Pointing to allure directory\bin. Getting Started
* Provide jira link in @Link
* Provide all the api components as @Feature
* Provide test severity and description
* Write test
* Use CatchBlock in try/catch section Spin-up chrome, firefox, selenium hub and OWASP proxy server
___________________________
@hacking_Attack
@Hacking_Video
HybridTestFramework - End To End Testing Of Web, API And Security
https://blogger.googleusercontent.com/img/a/AVvXsEjYUvrCRFei8rhlyXAkeX9febuHiZJP9KkvmzP2xrp3Puma_BO2P7hvk0c3Y_lf-JmcDaIzjdR3_E4kCRlG0LYTe7x2dxjF9ajJ4I3c4XFXalm8lhaPyBNdNxyhiklwxt-EJS1DPYbsRNW3Q2QItJfY8zTaLqJ1FTj34QwpBldzYu3gzfNr4fugvN7I=w640-h416 Full-fledged WEB, API and Security testing framework using selenium,ZAP OWASP proxy and rest-assuredSupported PlatformsThis framework supports WebUi automation across a variety of browsers like Chrome, Firefox, IE, no only limited to this but extended to test rest api, security and visual testing. Capabilities* Cross browser testing support
* Added browserstack support for CrossBrowser testing
* Running tests in docker containers selenium grid
* Running tests in AWS DeviceFarm selenium grid
* Running tests in selenium server in docker containers
* Security testing using OWASP, running in docker container
* Api testing support using RestAssured
* Visual regression testing using percy.io
* Accessibility testing using axe-selenium
* Stubbed api testing using WireMock
* Can send logs to ElasticSearch for kibana dashboard visualization
* Database testing support
* Kafka testing support
* Kubernetes support Setup & Tools* Install intellij https://www.jetbrains.com/idea/download/
* Install docker desktop https://www.docker.com/products/docker-desktop
* Java JDK_11 https://adoptopenjdk.net/
* Gradle https://gradle.org/next-steps/?version=6.8.3&format=bin
* Allure https://github.com/allure-framework/allure2/archive/2.17.2.zip
* Set Environment variables
* JAVA_HOME: Pointing to the Java SDK folder\bin
* GRADLE_HOME: Pointing to Gradle directory\bin.
* ALLURE_HOME: Pointing to allure directory\bin. Getting Started
$ git clone
$ cd
$ import project from intellij as a gradle project
$ gradle clean
$ gradle build
$ gradle task E2E
$ gradle allureReport
$ gradle allureServeWrite your first user journeyCreate new class and name as the TC00*_E2E_TEST-**** Provide jira link in @Link
* Provide all the api components as @Feature
* Provide test severity and description
* Write test
* Use CatchBlock in try/catch section Spin-up chrome, firefox, selenium hub and OWASP proxy server
$ docker-compose up -dComplete infrastructure creation for local run$ $ docker-compose -f docker-compose-infra up -dSpin-up four additional node-chrome/firefox instances linked to the hub$ docker-compose scale chrome=5
$ docker-compose scale firefox=5Spin-up kafka instances$ docker-compose -f docker-compose-kafka.yml up
$ docker-compose -f docker-compose-kafka.yml down --rmi allSpin-up selenium hub in kubernetes instance$ kubectl apply -f selenium-k8s-deploy-svc.yaml
$ kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0/aio/deploy/recommended.yaml
$ kubectl proxy
$ kubectl describe secret -n kube-system | grep deployment -A 12
## To delete deployments
$ kubectl delete deployment selenium-node-firefox
$ kubectl delete deployment selenium-node-chrome
$ kubectl delete deployment selenium-hubnavigate to http://localhost:8001/api/v1/namespaces/kubernetes-dashboard/services/https:kubernetes-dashboard:/proxy/https://blogger.googleusercontent.com/img/a/AVvXsEiT9QGW5IGy4viWX76GSDcpRoe4n0Z6-Y1YnzBICGJwpIPF60_Ulmq9Z23eUBDOtecHU8Efp90gMCSSWWc6rKjbuI2bKXFB_OL47T81eH6bhMZIPXJ62BDzpp9XOF9NYjoiUGybv-VnlTh3TzwPJ_Gwhe_iza8ys_jiMeqr97JBv6d1gDbH7vadZsDA=w640-h328 Execution Gifhttps://blogger.googleusercontent.com/img/a/AVvXsEhMce1R4wmz0q3Tml3Gx8DKaOCYVFykhWZkvkvpXwKyXU8fxh3GjcbEsoGMrvSNECoSdWT6f4Unm8yJjotAwcDFzNdGWmKpVKzaWVPELSjJ7fnNuPr_76MaXseTGHPYHKp4WhoE-RvrW431sTvO828KTdBfpKpvRxIjIH2lkUPVK7[...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
HybridTestFramework - End To End Testing Of Web, API And Security
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! HybridTestFramework - End To End Testing Of Web, API And Security https://blogger.googleusercontent.com/img/a/AVvXsEjYUvrCRFei8rhlyXAkeX9febuHiZJP9KkvmzP2xrp3Puma_BO2P7hvk0c3Y_lf-JmcDaIzjdR3_E4kCRlG0LYTe7x2dxjF9ajJ4I3c4XFXalm8lh…
Wp6GCMuJhmxT-o=w640-h480 Download HybridTestFramework
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
HybridTestFramework - End To End Testing Of Web, API And Security
http://www.kitploit.com/2022/02/hybridtestframework-end-to-end-testing.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/hybridtestframework-end-to-end-testing.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
HybridTestFramework - End To End Testing Of Web, API And Security