Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hey r/hacking all colored hats, 🇺🇦🔥 Hackers start war on Russia, are you in? #FckPutin
https://external-preview.redd.it/fD40Y0qy02JMuNrr90Lyr1l6VCLQcKbsmMtcfAU4LEc.jpg?width=108&crop=smart&auto=webp&s=8812544c8cc34704f12611b3ea867b47b9ac8d67 submitted by /u/dany2aa
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hey r/hacking all colored hats, 🇺🇦🔥 Hackers start war on Russia, are you in? #FckPutin
https://external-preview.redd.it/fD40Y0qy02JMuNrr90Lyr1l6VCLQcKbsmMtcfAU4LEc.jpg?width=108&crop=smart&auto=webp&s=8812544c8cc34704f12611b3ea867b47b9ac8d67 submitted by /u/dany2aa
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hey r/hacking all colored hats, 🇺🇦🔥 Hackers start war on Russia,...
Posted in r/hacking by u/dany2aa • 1 point and 0 comments
hacking: security in practice
Is http://norussian.tk/ actually doing something?
I have basically no hacking knowledge, I would be interested to know if running this site actually does what it says it does.
Thanks!
submitted by /u/Thalrador
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is http://norussian.tk/ actually doing something?
I have basically no hacking knowledge, I would be interested to know if running this site actually does what it says it does.
Thanks!
submitted by /u/Thalrador
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is http://norussian.tk/ actually doing something?
I have basically no hacking knowledge, I would be interested to know if running this site actually does what it says it does. Thanks!
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Inspired by the DDoS on Russia - A Distributed Cracker for the RIA.ru Propaganda Machine.
As many of you know, Russia has launched its invasion on Ukraine, and the hacker-community (thus far) has done its part to take down Russian military/government sites, with notable groups such as Anonymous joining in.
A few days ago, I saw a nice thread here on a DDoS tool, where thousands of you all (including me) joined in to do what small part we can in protecting freedom. I've recently decided that I can use my individual skills to do more, and so I've discovered the RIA.ru admin account username, as well as a weakness in their login form.
I then made a tool to automate cracking the password. The process could take years potentially depending on the security, but we can halve, or even quarter the time taken with the more people we have join in. At the least, I hope that it motivates the site owners to take the site down, or at least limit it to many users to prevent the further spread of Russian propaganda.
As of right now, the tool is hosted at https://ru-cracker.glitch.me , and I've also open-sourced it at https://github.com/flancast90/ru-cracker for those interested in the source.
A Few Notes:
Chrome CORS is extremely stupid. Because of this, for your computer to join in on the attack, you must be running a CORS-bypass extension. One for chrome is https://chrome.google.com/webstore/detail/allow-cors-access-control/lhobafahddgcelffkeicbaginigeejlf/related?hl=en , and others exist for different browsers.
For programmers wondering why I didn't create a simple node CORS bypass, the issue with this was all the requests would have to route through the server more than needed. This way, each client handles itself.
Note 2:
Participating in this attack is illegal in most places. However, if you feel strongly about this (as I do), please do not hesitate to join in - it is only through breaking laws that true and lasting social reform is made.
submitted by /u/Muted_Original
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Inspired by the DDoS on Russia - A Distributed Cracker for the RIA.ru Propaganda Machine.
As many of you know, Russia has launched its invasion on Ukraine, and the hacker-community (thus far) has done its part to take down Russian military/government sites, with notable groups such as Anonymous joining in.
A few days ago, I saw a nice thread here on a DDoS tool, where thousands of you all (including me) joined in to do what small part we can in protecting freedom. I've recently decided that I can use my individual skills to do more, and so I've discovered the RIA.ru admin account username, as well as a weakness in their login form.
I then made a tool to automate cracking the password. The process could take years potentially depending on the security, but we can halve, or even quarter the time taken with the more people we have join in. At the least, I hope that it motivates the site owners to take the site down, or at least limit it to many users to prevent the further spread of Russian propaganda.
As of right now, the tool is hosted at https://ru-cracker.glitch.me , and I've also open-sourced it at https://github.com/flancast90/ru-cracker for those interested in the source.
A Few Notes:
Chrome CORS is extremely stupid. Because of this, for your computer to join in on the attack, you must be running a CORS-bypass extension. One for chrome is https://chrome.google.com/webstore/detail/allow-cors-access-control/lhobafahddgcelffkeicbaginigeejlf/related?hl=en , and others exist for different browsers.
For programmers wondering why I didn't create a simple node CORS bypass, the issue with this was all the requests would have to route through the server more than needed. This way, each client handles itself.
Note 2:
Participating in this attack is illegal in most places. However, if you feel strongly about this (as I do), please do not hesitate to join in - it is only through breaking laws that true and lasting social reform is made.
submitted by /u/Muted_Original
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Inspired by the DDoS on Russia - A Distributed Cracker for the...
As many of you know, Russia has launched its invasion on Ukraine, and the hacker-community (thus far) has done its part to take down Russian...
hacking: security in practice
Google dork
Do you think it’s possible to find future GCSE papers using google dorking?
submitted by /u/hesjsjshs
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Google dork
Do you think it’s possible to find future GCSE papers using google dorking?
submitted by /u/hesjsjshs
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Google dork
Do you think it’s possible to find future GCSE papers using google dorking?
hacking: security in practice
I been using Firefox for a while now but are there any other browsers you guys use?
Basically I use Firefox anytime I want to access a website, but I am curious to what you guys use. Maybe there's an opensource browser with lots of privacy options and stuff, I am open to ideas.
submitted by /u/Awsomedude0361
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I been using Firefox for a while now but are there any other browsers you guys use?
Basically I use Firefox anytime I want to access a website, but I am curious to what you guys use. Maybe there's an opensource browser with lots of privacy options and stuff, I am open to ideas.
submitted by /u/Awsomedude0361
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I been using Firefox for a while now but are there any other...
Basically I use Firefox anytime I want to access a website, but I am curious to what you guys use. Maybe there's an opensource browser with lots...
New idea for physical pen testing. Read captions
https://www.reddit.com/r/Pentesting/comments/t35bn0/new_idea_for_physical_pen_testing_read_captions/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/t35bn0/new_idea_for_physical_pen_testing_read_captions/
___________________________
@hacking_Attack
@Hacking_Video
reddit
New idea for physical pen testing. Read captions
Posted in r/Pentesting by u/Electrical-Ad-8287 • 3 points and 0 comments
submitted by /u/Electrical-Ad-8287 (https://www.reddit.com/user/Electrical-Ad-8287)
[link] (https://www.reddit.com/gallery/t35bn0) [comments] (https://www.reddit.com/r/Pentesting/comments/t35bn0/new_idea_for_physical_pen_testing_read_captions/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://www.reddit.com/gallery/t35bn0) [comments] (https://www.reddit.com/r/Pentesting/comments/t35bn0/new_idea_for_physical_pen_testing_read_captions/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Everything you need to know about Bug Bounties
What are Bug Bounty ProgramsContinue reading on Medium »
Read more...
What are Bug Bounty ProgramsContinue reading on Medium »
Read more...
Everything you need to know about Bug Bounties
What are Bug Bounty ProgramsContinue reading on Medium »
Read more...
What are Bug Bounty ProgramsContinue reading on Medium »
Read more...
Everything you need to know about Bug Bounties
https://bugbaseindia.medium.com/everything-you-need-to-know-about-bug-bounties-5abbba0cfc89?source=rss------bug_bounty-5
What are Bug Bounty ProgramsContinue reading on Medium » (https://bugbaseindia.medium.com/everything-you-need-to-know-about-bug-bounties-5abbba0cfc89?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://bugbaseindia.medium.com/everything-you-need-to-know-about-bug-bounties-5abbba0cfc89?source=rss------bug_bounty-5
What are Bug Bounty ProgramsContinue reading on Medium » (https://bugbaseindia.medium.com/everything-you-need-to-know-about-bug-bounties-5abbba0cfc89?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Everything you need to know about Bug Bounties
What are Bug Bounty Programs
hacking: security in practice
Easy way to put a reverse shell on a dropbox and have it call out to my external server?
Hi all,
I am trying to make a raspberry pi with kali on it to be a reverse shell and go to my server on digital ocean through a reverse proxy.
How can I implant a reverse shell on the dropbox to do that?
I tried with metasploit but I have been running into issues.
This has to go through port 443 as well.
submitted by /u/Enes_24
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Easy way to put a reverse shell on a dropbox and have it call out to my external server?
Hi all,
I am trying to make a raspberry pi with kali on it to be a reverse shell and go to my server on digital ocean through a reverse proxy.
How can I implant a reverse shell on the dropbox to do that?
I tried with metasploit but I have been running into issues.
This has to go through port 443 as well.
submitted by /u/Enes_24
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Easy way to put a reverse shell on a dropbox and have it call out...
Hi all, I am trying to make a raspberry pi with kali on it to be a reverse shell and go to my server on digital ocean through a reverse...
HTTPS Downgrade only works on Chrome based browser
https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/
Using HTTPS in your web application is mandatory to guarantee trust and security. However, an attacker may try to downgrade that secure protocol into simple HTTP and grab or tamper with the exchanged data. https://auth0.com/blog/preventing-https-downgrade-attacks/ If certain site is running on https, then by simply changing it to http, the whole communication is now running on http. No redirection to https is done even though HSTS is there. However, this can only be done via Chrome based browser only and not Firefox. Is this consider as a valid pentest finding? submitted by /u/user11392 (https://www.reddit.com/user/user11392)
[link] (https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/) [comments] (https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/
Using HTTPS in your web application is mandatory to guarantee trust and security. However, an attacker may try to downgrade that secure protocol into simple HTTP and grab or tamper with the exchanged data. https://auth0.com/blog/preventing-https-downgrade-attacks/ If certain site is running on https, then by simply changing it to http, the whole communication is now running on http. No redirection to https is done even though HSTS is there. However, this can only be done via Chrome based browser only and not Firefox. Is this consider as a valid pentest finding? submitted by /u/user11392 (https://www.reddit.com/user/user11392)
[link] (https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/) [comments] (https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
HTTPS Downgrade only works on Chrome based browser
>Using HTTPS in your web application is mandatory to guarantee trust and security. However, an attacker may try to downgrade that secure protocol...
NMAP commands
https://rootbabu.medium.com/nmap-commands-1847fb990fa1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://rootbabu.medium.com/nmap-commands-1847fb990fa1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
NMAP commands
Basic Scan on a Single IP:
Basic Scan on a Single IP:Continue reading on Medium » (https://rootbabu.medium.com/nmap-commands-1847fb990fa1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
NMAP commands
Basic Scan on a Single IP:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Conti ransomware’s internal chats leaked after siding with Russia
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Conti ransomware’s internal chats leaked after siding with RussiaPost Views: 8
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
A Ukrainian security researcher has leaked over 60,000 internal messages belonging to the Conti ransomware operation after the gang sided with Russia over the invasion of Ukraine.
BleepingComputer has independently confirmed the validity of these messages from internal conversations previously shared with BleepingComputer regarding Conti’s attack on Shutterfly.
AdvIntel CEO Vitali Kremez, who has been tracking the Conti/TrickBot operation over the last couple of years, also confirmed to BleepingComputer that the leaked messages are valid and were taken from a log server for the Jabber communication system used by the ransomware gang.
Kremez told BleepingComputer that the data was leaked by a researcher who had access to the “ejabberd database” backend for Conti’s XMPP chat server. This was also confirmed by cybersecurity firm Hold Security.
In total, there are 393 leaked JSON files containing a total of 60,694 messages since January 21, 2021, through today. Conti launched their operation in July 2020, so while it contains a big chunk of their internal conversations, it is not all of them.
https://www.bleepstatic.com/images/news/ransomware/c/conti/private-messages-leak/leaked-chats.jpg
Messages leaked over Conti’s siding with RussiaEarlier this week, the Conti ransomware operation published a blog post announcing their full support for the Russian government’s attack on Ukraine. They also warned that if anyone organized a cyberattack against Russia, the Conti gang would[...]
___________________________
@hacking_Attack
@Hacking_Video
Conti ransomware’s internal chats leaked after siding with Russia
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Conti ransomware’s internal chats leaked after siding with RussiaPost Views: 8
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
A Ukrainian security researcher has leaked over 60,000 internal messages belonging to the Conti ransomware operation after the gang sided with Russia over the invasion of Ukraine.
BleepingComputer has independently confirmed the validity of these messages from internal conversations previously shared with BleepingComputer regarding Conti’s attack on Shutterfly.
AdvIntel CEO Vitali Kremez, who has been tracking the Conti/TrickBot operation over the last couple of years, also confirmed to BleepingComputer that the leaked messages are valid and were taken from a log server for the Jabber communication system used by the ransomware gang.
Kremez told BleepingComputer that the data was leaked by a researcher who had access to the “ejabberd database” backend for Conti’s XMPP chat server. This was also confirmed by cybersecurity firm Hold Security.
In total, there are 393 leaked JSON files containing a total of 60,694 messages since January 21, 2021, through today. Conti launched their operation in July 2020, so while it contains a big chunk of their internal conversations, it is not all of them.
https://www.bleepstatic.com/images/news/ransomware/c/conti/private-messages-leak/leaked-chats.jpg
Messages leaked over Conti’s siding with RussiaEarlier this week, the Conti ransomware operation published a blog post announcing their full support for the Russian government’s attack on Ukraine. They also warned that if anyone organized a cyberattack against Russia, the Conti gang would[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Conti ransomware’s internal chats leaked after siding with Russia | Black Hat Ethical Hacking
A Ukrainian security researcher has leaked over 60,000 internal messages belonging to the Conti ransomware operation after the gang sided with Russia over the invasion of Ukraine.
Black Hat Ethical Hacking
Conti ransomware’s internal chats leaked after siding with Russia
___________________________
@hacking_Attack
@Hacking_Video
Conti ransomware’s internal chats leaked after siding with Russia
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Conti ransomware’s internal chats leaked after siding with Russia | Black Hat Ethical Hacking
A Ukrainian security researcher has leaked over 60,000 internal messages belonging to the Conti ransomware operation after the gang sided with Russia over the invasion of Ukraine.