I was trying to improve my static analysis code, specifically django apps, so i decided to hack a random project in github. And i found…Continue reading on Medium » (https://noob3xploiter.medium.com/idor-in-support-mozilla-org-through-code-review-ff2aa8ea1201?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR in support.mozilla.org through Code Review
I was trying to improve my static analysis code, specifically django apps, so i decided to hack a random project in github. And i found…
Bug Bounty — How to approach Vulnerabilities ( PART 1 )
https://apexvicky.medium.com/bug-bounty-how-to-approach-vulnerabilities-part-1-47e211331386?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://apexvicky.medium.com/bug-bounty-how-to-approach-vulnerabilities-part-1-47e211331386?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty — Manual Approach To Test Vulnerabilities (PART 1 )
Hello people, it’s me again. In most cases, with automated tools, you can possibly find low level security bugs i.e most likely Blind XSS…
Hello people, it’s me again. In most cases, with automated tools, you can possibly find low level security bugs i.e most likely Blind XSS…Continue reading on Medium » (https://apexvicky.medium.com/bug-bounty-how-to-approach-vulnerabilities-part-1-47e211331386?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty — Manual Approach To Test Vulnerabilities (PART 1 )
Hello people, it’s me again. In most cases, with automated tools, you can possibly find low level security bugs i.e most likely Blind XSS…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
WannaRace : WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
WannaRace is a WebApp intentionally made vulnerable to Race Condition
Description
Race Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning .
Building And Running The Docker Image
Build the Docker image with:
git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRace
docker build -t xib3rr4dar/wanna_race:1.0 .
Run Docker image:
docker run -it –rm xib3rr4dar/wanna_race:1.0
Then open in browser relevant IP:PORT
Screenshots
Challenge #1
Main Page
https://blogger.googleusercontent.com/img/a/AVvXsEg1b9-Lz9ajtW_FfN-Yn9hUe1F9u4T6187waCbjg9PAsYhy-5jX5SrD_OL3AmYoIoJCmo0ibE3SdvMCHRS-2H3Q-ZwaPYvGiXyzdbn8kCHgFGdSbrIgQtzWEui0-qbpYVogF3bQjgqmFWCpOcdq1fgwU1M43TO7vRaQs2jXcZXl93QgV_kMqtirbvV1=s835
Four vouchers worth 400 units available for recharge
https://blogger.googleusercontent.com/img/a/AVvXsEjH8oYAUZCv2PBYqswO1TLWkUqg4XSK0FfP1OE-1TfWVdP-D7H-9823w7Oz8EfnCA3HKLtSez0sLDVuZOrNW0iWA9EAs-4iIZo18fU_HIjqOlKrUZrOmZAyCyjKvAsoDq9n9ucTv8Anx-MaC71mxp-WkSEheFpnuS-HOOyfxBttqonfxkhlZy5OsDar=s833
Task is to buy Mega box (which is worth 401 units) by exploiting race condition
https://blogger.googleusercontent.com/img/a/AVvXsEjkPm3Vw9F8v6xJkJatDFWmkFoaVWcs3_e4EoGRNa5DvsfT35zsMqMNpoZ_1vrZCxmbygVQxfA1Izf98uHc8NkCKqW622N0vy7BIm32o20SvD85k8aWp5wFqWTBo21eRztCyXkepfULYGu1QJnncPn_RIA3fvhNvtbgFstmYHUvnnm6dfSn6If3N4z8=s836
Challenge #2
Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are set
https://blogger.googleusercontent.com/img/a/AVvXsEj9dwZfjxlXyjKgYIGG26a5CvrL6hhR_A-24bbEh4JQ0447W0Sow233FRu-RRoQC1lGjDcz6_Okl6ar7MXPCYaSmnp048qRMU9OjKJDUmmV9qZet4kMHrXLfExHnHpHVfLyOP8u8f_qD5um_wtGPm_3IY_TGJDsIVMc8V3f3UehiAeaoSN53bXUuLLp=s837
Download
___________________________
@hacking_Attack
@Hacking_Video
WannaRace : WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
WannaRace is a WebApp intentionally made vulnerable to Race Condition
Description
Race Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning .
Building And Running The Docker Image
Build the Docker image with:
git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRace
docker build -t xib3rr4dar/wanna_race:1.0 .
Run Docker image:
docker run -it –rm xib3rr4dar/wanna_race:1.0
Then open in browser relevant IP:PORT
Screenshots
Challenge #1
Main Page
https://blogger.googleusercontent.com/img/a/AVvXsEg1b9-Lz9ajtW_FfN-Yn9hUe1F9u4T6187waCbjg9PAsYhy-5jX5SrD_OL3AmYoIoJCmo0ibE3SdvMCHRS-2H3Q-ZwaPYvGiXyzdbn8kCHgFGdSbrIgQtzWEui0-qbpYVogF3bQjgqmFWCpOcdq1fgwU1M43TO7vRaQs2jXcZXl93QgV_kMqtirbvV1=s835
Four vouchers worth 400 units available for recharge
https://blogger.googleusercontent.com/img/a/AVvXsEjH8oYAUZCv2PBYqswO1TLWkUqg4XSK0FfP1OE-1TfWVdP-D7H-9823w7Oz8EfnCA3HKLtSez0sLDVuZOrNW0iWA9EAs-4iIZo18fU_HIjqOlKrUZrOmZAyCyjKvAsoDq9n9ucTv8Anx-MaC71mxp-WkSEheFpnuS-HOOyfxBttqonfxkhlZy5OsDar=s833
Task is to buy Mega box (which is worth 401 units) by exploiting race condition
https://blogger.googleusercontent.com/img/a/AVvXsEjkPm3Vw9F8v6xJkJatDFWmkFoaVWcs3_e4EoGRNa5DvsfT35zsMqMNpoZ_1vrZCxmbygVQxfA1Izf98uHc8NkCKqW622N0vy7BIm32o20SvD85k8aWp5wFqWTBo21eRztCyXkepfULYGu1QJnncPn_RIA3fvhNvtbgFstmYHUvnnm6dfSn6If3N4z8=s836
Challenge #2
Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are set
https://blogger.googleusercontent.com/img/a/AVvXsEj9dwZfjxlXyjKgYIGG26a5CvrL6hhR_A-24bbEh4JQ0447W0Sow233FRu-RRoQC1lGjDcz6_Okl6ar7MXPCYaSmnp048qRMU9OjKJDUmmV9qZet4kMHrXLfExHnHpHVfLyOP8u8f_qD5um_wtGPm_3IY_TGJDsIVMc8V3f3UehiAeaoSN53bXUuLLp=s837
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
WannaRace : WebApp Intentionally Made Vulnerable To Race Condition
WannaRace is a WebApp intentionally made vulnerable to Race Condition. Race Condition vulnerability can be practiced in the developed WebApp.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SpoofThatMail : Bash Script To Check If A Domain Or List Of Domains Can Be Spoofed Based In DMARC Records
SpoofThatMail is a Bash script to check if a domain or list of domains can be spoofed based in DMARC records
File with domains:
sh SpoofThatMail.sh -f domains.txt
One single domain:
sh SpoofThatMail.sh -d domain
https://blogger.googleusercontent.com/img/a/AVvXsEimrr7_S5Su-Znix1MWlpTEwSjb0-Su3EekB1Tgfq96AHsc_lD-3aWtz_Q8ZOSby39XfRmjxf89RlCzM-m1C-V9r0usb1JGWnnghD2ZQBV-VCaztvhiTndE1IiP15ixi90TqjaiSHTuiEIB5THsu36JYyIjSrHlZkHdRUNb7lyh-9AgkhYYezsCCoNl=s718
The script may not work if sp param is before p param (currently working on this)
Test manually using nslookup -type=txt _dmarc.domain.com
Download
___________________________
@hacking_Attack
@Hacking_Video
SpoofThatMail : Bash Script To Check If A Domain Or List Of Domains Can Be Spoofed Based In DMARC Records
SpoofThatMail is a Bash script to check if a domain or list of domains can be spoofed based in DMARC records
File with domains:
sh SpoofThatMail.sh -f domains.txt
One single domain:
sh SpoofThatMail.sh -d domain
https://blogger.googleusercontent.com/img/a/AVvXsEimrr7_S5Su-Znix1MWlpTEwSjb0-Su3EekB1Tgfq96AHsc_lD-3aWtz_Q8ZOSby39XfRmjxf89RlCzM-m1C-V9r0usb1JGWnnghD2ZQBV-VCaztvhiTndE1IiP15ixi90TqjaiSHTuiEIB5THsu36JYyIjSrHlZkHdRUNb7lyh-9AgkhYYezsCCoNl=s718
The script may not work if sp param is before p param (currently working on this)
Test manually using nslookup -type=txt _dmarc.domain.com
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
SpoofThatMail : Bash Script To Check If List Of Domains Can Be Spoofed
SpoofThatMail is a Bash script to check if a domain or list of domains can be spoofed based in DMARC records.
How did I find Directory Traversal attack using GitHub
Hello,Continue reading on Medium »
Read more...
Hello,Continue reading on Medium »
Read more...
Hacking on Medium
How The Internet Is Disrupting Warfare
https://cdn-images-1.medium.com/max/806/1*l6Jy0VJtsEFxnikkmF2hbQ.png
Warfare just met Cancel Culture
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
How The Internet Is Disrupting Warfare
https://cdn-images-1.medium.com/max/806/1*l6Jy0VJtsEFxnikkmF2hbQ.png
Warfare just met Cancel Culture
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How The Internet Is Disrupting Warfare
Warfare just met Cancel Culture
Hacking on Medium
My First Osint Challenge
https://cdn-images-1.medium.com/max/937/1*57wEpRgy_-ntTqp-yuHeZA.png
One fine day I was Scrolling through tweets and my eyes got a tweet that Dan Conn tweeted a osint challenge on Oct 5, 2021 mentioning his…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My First Osint Challenge
https://cdn-images-1.medium.com/max/937/1*57wEpRgy_-ntTqp-yuHeZA.png
One fine day I was Scrolling through tweets and my eyes got a tweet that Dan Conn tweeted a osint challenge on Oct 5, 2021 mentioning his…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My First Osint Challenge
One fine day I was Scrolling through tweets and my eyes got a tweet that Dan Conn tweeted a osint challenge on Oct 5, 2021 mentioning his…
Hacking on Medium
SWC-102, 103 | Outdated Compiler Version, Floating Pragma
https://cdn-images-1.medium.com/max/1400/0*EwNFU8STTT1IGmbw.jpg
For SWC-102, developers should make sure they are using a stable version of solidity and also check if there are any known bugs against…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SWC-102, 103 | Outdated Compiler Version, Floating Pragma
https://cdn-images-1.medium.com/max/1400/0*EwNFU8STTT1IGmbw.jpg
For SWC-102, developers should make sure they are using a stable version of solidity and also check if there are any known bugs against…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SWC-102, 103 | Outdated Compiler Version, Floating Pragma
For SWC-102, developers should make sure they are using a stable version of solidity and also check if there are any known bugs against…
Hacking on Medium
SWC-101 | Integer Overflow and Underflow
https://cdn-images-1.medium.com/max/1400/0*tuJikkWOPpryErNJ.jpg
The Problem
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SWC-101 | Integer Overflow and Underflow
https://cdn-images-1.medium.com/max/1400/0*tuJikkWOPpryErNJ.jpg
The Problem
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SWC-101 | Integer Overflow and Underflow
The Problem
Hacking on Medium
SWC-100 | Function Default Visibility
https://cdn-images-1.medium.com/max/1400/0*Sa6uxFmguBDCuWT1.jpg
DApps used in Defi have huge capital locked and it becomes the job of the developer and security auditor to be aware of the common…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SWC-100 | Function Default Visibility
https://cdn-images-1.medium.com/max/1400/0*Sa6uxFmguBDCuWT1.jpg
DApps used in Defi have huge capital locked and it becomes the job of the developer and security auditor to be aware of the common…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SWC-100 | Function Default Visibility
DApps used in Defi have huge capital locked and it becomes the job of the developer and security auditor to be aware of the common mistakes…
Hacking on Medium
SWC-104 | Unchecked Call Return Value
https://cdn-images-1.medium.com/max/1400/0*_fEGT7FfoiojZGxa.jpg
The Problem
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SWC-104 | Unchecked Call Return Value
https://cdn-images-1.medium.com/max/1400/0*_fEGT7FfoiojZGxa.jpg
The Problem
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SWC-104 | Unchecked Call Return Value
The Problem
Hacking on Medium
Piratas informáticos intentan apuntar a funcionarios europeos para obtener información sobre…
https://cdn-images-1.medium.com/max/1523/0*ml-NxefiVnxadNGb
PUBLICADO EN 2 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Piratas informáticos intentan apuntar a funcionarios europeos para obtener información sobre…
https://cdn-images-1.medium.com/max/1523/0*ml-NxefiVnxadNGb
PUBLICADO EN 2 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Piratas informáticos intentan apuntar a funcionarios europeos para obtener información sobre refugiados y suministros ucranianos
PUBLICADO EN 2 MARZO, 2022POR EHACKING
Hacking on Medium
Information Gathering — First Step towards Website Hacking
https://cdn-images-1.medium.com/max/1200/1*gFCI5Mgb0AyFij1T9U6Sxg.jpeg
Hackers/penetration testers gather all possible information related to the website. In this blog, I will go through the main tools which …
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
Information Gathering — First Step towards Website Hacking
https://cdn-images-1.medium.com/max/1200/1*gFCI5Mgb0AyFij1T9U6Sxg.jpeg
Hackers/penetration testers gather all possible information related to the website. In this blog, I will go through the main tools which …
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Information Gathering — First Step towards Website Hacking
Hackers/penetration testers gather all possible information related to the website. In this blog, I will go through the main tools which …
Hacking on Medium
10 Easy Ways to Speed Up Your Internet Connection — Knowledge World
https://cdn-images-1.medium.com/max/1280/0*c5djeMyOFsvAErYf.png
𝟏𝟎 𝐄𝐚𝐬𝐲 𝐖𝐚𝐲𝐬 𝐭𝐨 𝐒𝐩𝐞𝐞𝐝 𝐔𝐩 𝐘𝐨𝐮𝐫 𝐈𝐧𝐭𝐞𝐫𝐧𝐞𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 — 𝐊𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞 𝐖𝐨𝐫𝐥𝐝
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
10 Easy Ways to Speed Up Your Internet Connection — Knowledge World
https://cdn-images-1.medium.com/max/1280/0*c5djeMyOFsvAErYf.png
𝟏𝟎 𝐄𝐚𝐬𝐲 𝐖𝐚𝐲𝐬 𝐭𝐨 𝐒𝐩𝐞𝐞𝐝 𝐔𝐩 𝐘𝐨𝐮𝐫 𝐈𝐧𝐭𝐞𝐫𝐧𝐞𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 — 𝐊𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞 𝐖𝐨𝐫𝐥𝐝
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Easy Ways to Speed Up Your Internet Connection — Knowledge World
𝟏𝟎 𝐄𝐚𝐬𝐲 𝐖𝐚𝐲𝐬 𝐭𝐨 𝐒𝐩𝐞𝐞𝐝 𝐔𝐩 𝐘𝐨𝐮𝐫 𝐈𝐧𝐭𝐞𝐫𝐧𝐞𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 — 𝐊𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞 𝐖𝐨𝐫𝐥𝐝
Hacking on Medium
6 computer hacking terminology explained
https://cdn-images-1.medium.com/max/2600/1*SuJOoiVOZuh25jY0A37GDw.jpeg
Hacking in the computer science world is similar to breaking into someone’s property. There are many different ways adopted by these…
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
6 computer hacking terminology explained
https://cdn-images-1.medium.com/max/2600/1*SuJOoiVOZuh25jY0A37GDw.jpeg
Hacking in the computer science world is similar to breaking into someone’s property. There are many different ways adopted by these…
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
Medium
6 computer hacking terminology explained
Hacking in the computer science world is similar to breaking into someone’s property. There are many different ways adopted by these…
How did I find Directory Traversal attack using GitHub
Hello,Continue reading on Medium »
Read more...
Hello,Continue reading on Medium »
Read more...
Bash Tricks for File Exfiltration over HTTP/S using Flask
https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/
submitted by /u/cyberbutler (https://www.reddit.com/user/cyberbutler)
[link] (https://medium.com/maverislabs/bash-tricks-for-file-exfiltration-over-http-s-using-flask-112aed524ad?source=friends_link&sk=622646706c0d1981eec45acffc38cbfd) [comments] (https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/
submitted by /u/cyberbutler (https://www.reddit.com/user/cyberbutler)
[link] (https://medium.com/maverislabs/bash-tricks-for-file-exfiltration-over-http-s-using-flask-112aed524ad?source=friends_link&sk=622646706c0d1981eec45acffc38cbfd) [comments] (https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bash Tricks for File Exfiltration over HTTP/S using Flask
Posted in r/redteamsec by u/cyberbutler • 1 point and 1 comment