Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Is this exploit worth selling?

So I recently wrote my own malware which is essentially a Trojan that will allow remote code execution from a hacker. It’s able to bypass windows 10 built in security Windows Defender. I’ve tested this on a few different PC’s so far and the results are always the same, it always bypasses it. I’ve also got a neat little trick that can bypass browser warnings and Windows Smart Screen for a lack of digital signature. It’s obvious to say I don’t and won’t get a signature for this, and was having issues at first getting around the warnings from windows smart screen. However I found a way around that which was surprisingly simple and accidental, that completely avoids Smart Screen setting off with its big red warning and also any warning from the browser with that annoying note that ‘this application isn’t downloaded too often…’

Is it worth selling? I don’t mean to a black market (or maybe?) but something like hackerone by explaining exactly how it bypasses all these security features? Or some other alternative? I have a worry in the back of my head this either isn’t something worth giving away as it’s already ‘known’ about, which I don’t think it is as I discovered these on my own at least. Or I’m worried I’ll just get told the same thing above - that it’s worthless but then actually it ends up being patched up or distributed and sold elsewhere and I get scammed out of any reward. Or is a better way to just sell to a black market? Not really suggesting that, but wondering what I should do now with this exploit I have? This is my first exploit, so looking for advice on where to go from here?

submitted by /u/aidahadleyxoo
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Mars Protocol offers up to $1 million payout in bug bounty program with Immunefi

More than 20 contributors from around the world have spent nearly a year developing Mars from scratch in the Rust programming language…Continue reading on Medium »
Read more...
Take part of our Bug Bounty Program ‍

As you well know Avacash.Finance is a fork of Tornado.cash in the Avalanche Blockchain, which means that we offer a fully decentralized…Continue reading on Medium »
Read more...
Company wants me to perform a pen test as a contractor before they hire me
https://www.reddit.com/r/Pentesting/comments/t0ixjn/company_wants_me_to_perform_a_pen_test_as_a/

I work in the private sector cyber security field. I have a few years of pentesting experience in the past, but currently working as an auditor. A company I applied at wants me to run a pentest with them before they will send out a job offer. I get why they would. The target is one of their clients I don't want to be hit with legal issues should a target system go unstable or crash, scope creep, my ISP doesn't like it, etc. A VPN won't be offered, i'd be doing it from home outside of my 40 hour/wk job. The company said they would pay me, but I haven't heard how much. I feel like its a bad idea, thoughts? submitted by /u/Dknife (https://www.reddit.com/user/Dknife)
[link] (https://www.reddit.com/r/Pentesting/comments/t0ixjn/company_wants_me_to_perform_a_pen_test_as_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/t0ixjn/company_wants_me_to_perform_a_pen_test_as_a/)

___________________________
@hacking_Attack
@Hacking_Video
How I Hacked the Dutch Government with SQLi and Won the Famous T-Shirt?

Hello, those who are at the computer day and night.Continue reading on Medium »
Read more...
How I Hacked the Dutch Government with SQLi and Won the Famous T-Shirt?

Hello, those who are at the computer day and night.Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Insider Threats Are More Than Just Malicious Employees

Humans are unpredictable and may make mistakes that could result in a security incident.
Dark Reading: Attacks/Breaches
Trickbot Comes Up With a New Set of Tricks

Late last year, the group behind the malware stopped spreading Trickbot, instead pushing out copies of Emotet and Qbot to infected systems, researchers say.
Dark Reading: Attacks/Breaches
Why Developers Should Care About Log4j

Unless you can gain full visibility into how data flows to and through your dependencies, you can’t be sure if you are affected by this vulnerability.
hacking: security in practice
Has anyone hacked a standard keyed vehicle ignition to be started with something like a USB drive or NFC tag?

I'm not asking "can hackers hotwire my car with a USB stick?"

I mean a USB port or NFC reader where my ignition was so I can use a USB stick or nfc tag to start my car. Seems like it could be done with an RPI zero and maybe some 3d printed fitups.

submitted by /u/maverickmain
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do I find someone who doesn’t want to found?

We have a mate who’s sister has been missing in Australia for nearly a year. Someone in the first months has attempted to set up bank accounts and access bank accounts of my mate (both female Obviously) with no success. Since then there has been nothing. No calls, no posts etc. She had a boyfriend who was discharged from the police force for abusing (think sexually) women and changed his identity almost instantly. Family are devastated and can’t rest over this. There wasn’t even a big fallout. I fear what you all fear but is there a way to track her/him down hmu if anyone wants to throw on their cape for a very good cause xx

submitted by /u/DrDankHaze
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video