As the Pandora community continues to grow stronger with each passing day, we would like to take this opportunity to thank everyone for…Continue reading on Pandora Protocol » (https://medium.com/pandoraprotocol/community-newsletter-march-2022-1d679c1a5823?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Community Newsletter — March 2022
As the Pandora community continues to grow stronger with each passing day, we would like to take this opportunity to thank everyone for…
Community Newsletter — March 2022
As the Pandora community continues to grow stronger with each passing day, we would like to take this opportunity to thank everyone for…Continue reading on Pandora Protocol »
Read more...
As the Pandora community continues to grow stronger with each passing day, we would like to take this opportunity to thank everyone for…Continue reading on Pandora Protocol »
Read more...
Community Newsletter — March 2022
As the Pandora community continues to grow stronger with each passing day, we would like to take this opportunity to thank everyone for…Continue reading on Pandora Protocol »
Read more...
As the Pandora community continues to grow stronger with each passing day, we would like to take this opportunity to thank everyone for…Continue reading on Pandora Protocol »
Read more...
hacking: security in practice
Comprehensive, security-focused write up about communication tools?
Asking for a ukranian fried: I'm looking for a comprehensive, security-focused write up about communication tools and best practices to secure them, and the phone OS, in war time. The target audience would be civil citizens. If I can't find it, I'll try to write one. In any case, any pointers would be appreciated. Thanks a lot, and sorry if this is OT.
submitted by /u/ouiea
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Comprehensive, security-focused write up about communication tools?
Asking for a ukranian fried: I'm looking for a comprehensive, security-focused write up about communication tools and best practices to secure them, and the phone OS, in war time. The target audience would be civil citizens. If I can't find it, I'll try to write one. In any case, any pointers would be appreciated. Thanks a lot, and sorry if this is OT.
submitted by /u/ouiea
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Comprehensive, security-focused write up about communication tools?
Asking for a ukranian fried: I'm looking for a comprehensive, security-focused write up about communication tools and best practices to secure...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Don't have time to read the entire Conti leak? Read the summary and stay up to date.
https://www.cyberark.com/?p=127656&post_type=threat_research_blog&preview=1&_ppp=a20e2b57fd
submitted by /u/jat0369
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Don't have time to read the entire Conti leak? Read the summary and stay up to date.
https://www.cyberark.com/?p=127656&post_type=threat_research_blog&preview=1&_ppp=a20e2b57fd
submitted by /u/jat0369
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Don't have time to read the entire Conti leak? Read the summary...
[https://www.cyberark.com/?p=127656&post\_type=threat\_research\_blog&preview=1&\_ppp=a20e2b57fd](https://www.cyberark.com/?p=127656&post_type=thre...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Why won’t law enforcement answer questions about RaidForums? Or have they just winked?
https://external-preview.redd.it/ZnfyNyADCCwDRocb4EbDCtuN9qhb9VOdr-IycnpcMBA.jpg?width=320&crop=smart&auto=webp&s=c09b6158118145cdcf408a93a192f37dd539d8e1 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why won’t law enforcement answer questions about RaidForums? Or have they just winked?
https://external-preview.redd.it/ZnfyNyADCCwDRocb4EbDCtuN9qhb9VOdr-IycnpcMBA.jpg?width=320&crop=smart&auto=webp&s=c09b6158118145cdcf408a93a192f37dd539d8e1 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Why won’t law enforcement answer questions about RaidForums? Or...
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
These guys are quite rude :(
https://external-preview.redd.it/uk0FIV7rrKZMIAypOvcwj0I-r6vxfzPjMyR4JX9rBD4.png?width=640&crop=smart&auto=webp&s=fe987f0b5d4409b6b2b2b19bf2a74ebf2359ec90 submitted by /u/grrwahrr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
These guys are quite rude :(
https://external-preview.redd.it/uk0FIV7rrKZMIAypOvcwj0I-r6vxfzPjMyR4JX9rBD4.png?width=640&crop=smart&auto=webp&s=fe987f0b5d4409b6b2b2b19bf2a74ebf2359ec90 submitted by /u/grrwahrr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
These guys are quite rude :(
Posted in r/hacking by u/grrwahrr • 0 points and 1 comment
IDOR in support.mozilla.org through Code Review
https://noob3xploiter.medium.com/idor-in-support-mozilla-org-through-code-review-ff2aa8ea1201?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://noob3xploiter.medium.com/idor-in-support-mozilla-org-through-code-review-ff2aa8ea1201?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR in support.mozilla.org through Code Review
I was trying to improve my static analysis code, specifically django apps, so i decided to hack a random project in github. And i found…
I was trying to improve my static analysis code, specifically django apps, so i decided to hack a random project in github. And i found…Continue reading on Medium » (https://noob3xploiter.medium.com/idor-in-support-mozilla-org-through-code-review-ff2aa8ea1201?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR in support.mozilla.org through Code Review
I was trying to improve my static analysis code, specifically django apps, so i decided to hack a random project in github. And i found…
Bug Bounty — How to approach Vulnerabilities ( PART 1 )
https://apexvicky.medium.com/bug-bounty-how-to-approach-vulnerabilities-part-1-47e211331386?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://apexvicky.medium.com/bug-bounty-how-to-approach-vulnerabilities-part-1-47e211331386?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty — Manual Approach To Test Vulnerabilities (PART 1 )
Hello people, it’s me again. In most cases, with automated tools, you can possibly find low level security bugs i.e most likely Blind XSS…
Hello people, it’s me again. In most cases, with automated tools, you can possibly find low level security bugs i.e most likely Blind XSS…Continue reading on Medium » (https://apexvicky.medium.com/bug-bounty-how-to-approach-vulnerabilities-part-1-47e211331386?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty — Manual Approach To Test Vulnerabilities (PART 1 )
Hello people, it’s me again. In most cases, with automated tools, you can possibly find low level security bugs i.e most likely Blind XSS…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
WannaRace : WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
WannaRace is a WebApp intentionally made vulnerable to Race Condition
Description
Race Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning .
Building And Running The Docker Image
Build the Docker image with:
git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRace
docker build -t xib3rr4dar/wanna_race:1.0 .
Run Docker image:
docker run -it –rm xib3rr4dar/wanna_race:1.0
Then open in browser relevant IP:PORT
Screenshots
Challenge #1
Main Page
https://blogger.googleusercontent.com/img/a/AVvXsEg1b9-Lz9ajtW_FfN-Yn9hUe1F9u4T6187waCbjg9PAsYhy-5jX5SrD_OL3AmYoIoJCmo0ibE3SdvMCHRS-2H3Q-ZwaPYvGiXyzdbn8kCHgFGdSbrIgQtzWEui0-qbpYVogF3bQjgqmFWCpOcdq1fgwU1M43TO7vRaQs2jXcZXl93QgV_kMqtirbvV1=s835
Four vouchers worth 400 units available for recharge
https://blogger.googleusercontent.com/img/a/AVvXsEjH8oYAUZCv2PBYqswO1TLWkUqg4XSK0FfP1OE-1TfWVdP-D7H-9823w7Oz8EfnCA3HKLtSez0sLDVuZOrNW0iWA9EAs-4iIZo18fU_HIjqOlKrUZrOmZAyCyjKvAsoDq9n9ucTv8Anx-MaC71mxp-WkSEheFpnuS-HOOyfxBttqonfxkhlZy5OsDar=s833
Task is to buy Mega box (which is worth 401 units) by exploiting race condition
https://blogger.googleusercontent.com/img/a/AVvXsEjkPm3Vw9F8v6xJkJatDFWmkFoaVWcs3_e4EoGRNa5DvsfT35zsMqMNpoZ_1vrZCxmbygVQxfA1Izf98uHc8NkCKqW622N0vy7BIm32o20SvD85k8aWp5wFqWTBo21eRztCyXkepfULYGu1QJnncPn_RIA3fvhNvtbgFstmYHUvnnm6dfSn6If3N4z8=s836
Challenge #2
Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are set
https://blogger.googleusercontent.com/img/a/AVvXsEj9dwZfjxlXyjKgYIGG26a5CvrL6hhR_A-24bbEh4JQ0447W0Sow233FRu-RRoQC1lGjDcz6_Okl6ar7MXPCYaSmnp048qRMU9OjKJDUmmV9qZet4kMHrXLfExHnHpHVfLyOP8u8f_qD5um_wtGPm_3IY_TGJDsIVMc8V3f3UehiAeaoSN53bXUuLLp=s837
Download
___________________________
@hacking_Attack
@Hacking_Video
WannaRace : WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
WannaRace is a WebApp intentionally made vulnerable to Race Condition
Description
Race Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning .
Building And Running The Docker Image
Build the Docker image with:
git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRace
docker build -t xib3rr4dar/wanna_race:1.0 .
Run Docker image:
docker run -it –rm xib3rr4dar/wanna_race:1.0
Then open in browser relevant IP:PORT
Screenshots
Challenge #1
Main Page
https://blogger.googleusercontent.com/img/a/AVvXsEg1b9-Lz9ajtW_FfN-Yn9hUe1F9u4T6187waCbjg9PAsYhy-5jX5SrD_OL3AmYoIoJCmo0ibE3SdvMCHRS-2H3Q-ZwaPYvGiXyzdbn8kCHgFGdSbrIgQtzWEui0-qbpYVogF3bQjgqmFWCpOcdq1fgwU1M43TO7vRaQs2jXcZXl93QgV_kMqtirbvV1=s835
Four vouchers worth 400 units available for recharge
https://blogger.googleusercontent.com/img/a/AVvXsEjH8oYAUZCv2PBYqswO1TLWkUqg4XSK0FfP1OE-1TfWVdP-D7H-9823w7Oz8EfnCA3HKLtSez0sLDVuZOrNW0iWA9EAs-4iIZo18fU_HIjqOlKrUZrOmZAyCyjKvAsoDq9n9ucTv8Anx-MaC71mxp-WkSEheFpnuS-HOOyfxBttqonfxkhlZy5OsDar=s833
Task is to buy Mega box (which is worth 401 units) by exploiting race condition
https://blogger.googleusercontent.com/img/a/AVvXsEjkPm3Vw9F8v6xJkJatDFWmkFoaVWcs3_e4EoGRNa5DvsfT35zsMqMNpoZ_1vrZCxmbygVQxfA1Izf98uHc8NkCKqW622N0vy7BIm32o20SvD85k8aWp5wFqWTBo21eRztCyXkepfULYGu1QJnncPn_RIA3fvhNvtbgFstmYHUvnnm6dfSn6If3N4z8=s836
Challenge #2
Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are set
https://blogger.googleusercontent.com/img/a/AVvXsEj9dwZfjxlXyjKgYIGG26a5CvrL6hhR_A-24bbEh4JQ0447W0Sow233FRu-RRoQC1lGjDcz6_Okl6ar7MXPCYaSmnp048qRMU9OjKJDUmmV9qZet4kMHrXLfExHnHpHVfLyOP8u8f_qD5um_wtGPm_3IY_TGJDsIVMc8V3f3UehiAeaoSN53bXUuLLp=s837
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
WannaRace : WebApp Intentionally Made Vulnerable To Race Condition
WannaRace is a WebApp intentionally made vulnerable to Race Condition. Race Condition vulnerability can be practiced in the developed WebApp.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SpoofThatMail : Bash Script To Check If A Domain Or List Of Domains Can Be Spoofed Based In DMARC Records
SpoofThatMail is a Bash script to check if a domain or list of domains can be spoofed based in DMARC records
File with domains:
sh SpoofThatMail.sh -f domains.txt
One single domain:
sh SpoofThatMail.sh -d domain
https://blogger.googleusercontent.com/img/a/AVvXsEimrr7_S5Su-Znix1MWlpTEwSjb0-Su3EekB1Tgfq96AHsc_lD-3aWtz_Q8ZOSby39XfRmjxf89RlCzM-m1C-V9r0usb1JGWnnghD2ZQBV-VCaztvhiTndE1IiP15ixi90TqjaiSHTuiEIB5THsu36JYyIjSrHlZkHdRUNb7lyh-9AgkhYYezsCCoNl=s718
The script may not work if sp param is before p param (currently working on this)
Test manually using nslookup -type=txt _dmarc.domain.com
Download
___________________________
@hacking_Attack
@Hacking_Video
SpoofThatMail : Bash Script To Check If A Domain Or List Of Domains Can Be Spoofed Based In DMARC Records
SpoofThatMail is a Bash script to check if a domain or list of domains can be spoofed based in DMARC records
File with domains:
sh SpoofThatMail.sh -f domains.txt
One single domain:
sh SpoofThatMail.sh -d domain
https://blogger.googleusercontent.com/img/a/AVvXsEimrr7_S5Su-Znix1MWlpTEwSjb0-Su3EekB1Tgfq96AHsc_lD-3aWtz_Q8ZOSby39XfRmjxf89RlCzM-m1C-V9r0usb1JGWnnghD2ZQBV-VCaztvhiTndE1IiP15ixi90TqjaiSHTuiEIB5THsu36JYyIjSrHlZkHdRUNb7lyh-9AgkhYYezsCCoNl=s718
The script may not work if sp param is before p param (currently working on this)
Test manually using nslookup -type=txt _dmarc.domain.com
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
SpoofThatMail : Bash Script To Check If List Of Domains Can Be Spoofed
SpoofThatMail is a Bash script to check if a domain or list of domains can be spoofed based in DMARC records.
How did I find Directory Traversal attack using GitHub
Hello,Continue reading on Medium »
Read more...
Hello,Continue reading on Medium »
Read more...