Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Google dork

Do you think it’s possible to find future GCSE papers using google dorking?

submitted by /u/hesjsjshs
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I been using Firefox for a while now but are there any other browsers you guys use?

Basically I use Firefox anytime I want to access a website, but I am curious to what you guys use. Maybe there's an opensource browser with lots of privacy options and stuff, I am open to ideas.

submitted by /u/Awsomedude0361
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Everything you need to know about Bug Bounties

What are Bug Bounty ProgramsContinue reading on Medium »
Read more...
Everything you need to know about Bug Bounties

What are Bug Bounty ProgramsContinue reading on Medium »
Read more...
hacking: security in practice
Easy way to put a reverse shell on a dropbox and have it call out to my external server?

Hi all,

I am trying to make a raspberry pi with kali on it to be a reverse shell and go to my server on digital ocean through a reverse proxy.

How can I implant a reverse shell on the dropbox to do that?

I tried with metasploit but I have been running into issues.

This has to go through port 443 as well.

submitted by /u/Enes_24
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
HTTPS Downgrade only works on Chrome based browser
https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/

Using HTTPS in your web application is mandatory to guarantee trust and security. However, an attacker may try to downgrade that secure protocol into simple HTTP and grab or tamper with the exchanged data. https://auth0.com/blog/preventing-https-downgrade-attacks/ If certain site is running on https, then by simply changing it to http, the whole communication is now running on http. No redirection to https is done even though HSTS is there. However, this can only be done via Chrome based browser only and not Firefox. Is this consider as a valid pentest finding? submitted by /u/user11392 (https://www.reddit.com/user/user11392)
[link] (https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/) [comments] (https://www.reddit.com/r/Pentesting/comments/t3abox/https_downgrade_only_works_on_chrome_based_browser/)

___________________________
@hacking_Attack
@Hacking_Video
NMAP commands

Basic Scan on a Single IP:Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Conti ransomware’s internal chats leaked after siding with Russia

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Conti ransomware’s internal chats leaked after siding with RussiaPost Views: 8
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
A Ukrainian security researcher has leaked over 60,000 internal messages belonging to the Conti ransomware operation after the gang sided with Russia over the invasion of Ukraine.
BleepingComputer has independently confirmed the validity of these messages from internal conversations previously shared with BleepingComputer regarding Conti’s attack on Shutterfly.

AdvIntel CEO Vitali Kremez, who has been tracking the Conti/TrickBot operation over the last couple of years, also confirmed to BleepingComputer that the leaked messages are valid and were taken from a log server for the Jabber communication system used by the ransomware gang.

Kremez told BleepingComputer that the data was leaked by a researcher who had access to the “ejabberd database” backend for Conti’s XMPP chat server. This was also confirmed by cybersecurity firm Hold Security.

In total, there are 393 leaked JSON files containing a total of 60,694 messages since January 21, 2021, through today. Conti launched their operation in July 2020, so while it contains a big chunk of their internal conversations, it is not all of them.
https://www.bleepstatic.com/images/news/ransomware/c/conti/private-messages-leak/leaked-chats.jpg
Messages leaked over Conti’s siding with RussiaEarlier this week, the Conti ransomware operation published a blog post announcing their full support for the Russian government’s attack on Ukraine. They also warned that if anyone organized a cyberattack against Russia, the Conti gang would[...]

___________________________
@hacking_Attack
@Hacking_Video
NMAP commands

Basic Scan on a Single IP:Continue reading on Medium »
Read more...
hacking: security in practice
How reliable is Brave Browser Tor option?

Hey, I was wondering if using the tor window feature in Brave is equivalent to using a “real” onion web tor browser? It seems way quicker in loading speed to me. I am no expert at all, was just interested if it might become a thing for daily browsing instead of a vpn, if it advances further.

submitted by /u/schnavy
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
If Ddos is illegal then what about anonymous

Correct me if I’m wrong but in this cyber war between Russia and Ukraine the anonymous hacker group have been using Ddos attacks, so if they get caught will they be arrested or will an exception be made due to their cause. In my country Ddos is punishable by a jail sentence/ fine. Any insight helps, thanks

submitted by /u/Armweak5104
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video