Hacking on Medium
How I managed to make a DDoS attack by exploiting a company’s service — Bug Bounty
https://cdn-images-1.medium.com/max/1200/0*lXKlSpKoqZpwW_aH
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to tell you about an event that happened to me while I was…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How I managed to make a DDoS attack by exploiting a company’s service — Bug Bounty
https://cdn-images-1.medium.com/max/1200/0*lXKlSpKoqZpwW_aH
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to tell you about an event that happened to me while I was…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I managed to make a DDoS attack by exploiting a company’s service — Bug Bounty
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to tell you about an event that happened to me while I was…
Hacking on Medium
LFI & RFI para servidores Windows
https://cdn-images-1.medium.com/max/716/1*f3XlmNrwg4pNaJqMkqwHyw.png
La inclusión de archivos locales (LFI) es la vulnerabilidad que se encuentra principalmente en los servidores web. Esta vulnerabilidad se…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
LFI & RFI para servidores Windows
https://cdn-images-1.medium.com/max/716/1*f3XlmNrwg4pNaJqMkqwHyw.png
La inclusión de archivos locales (LFI) es la vulnerabilidad que se encuentra principalmente en los servidores web. Esta vulnerabilidad se…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
LFI & RFI para servidores Windows
La inclusión de archivos locales (LFI) es la vulnerabilidad que se encuentra principalmente en los servidores web. Esta vulnerabilidad se…
Hacking on Medium
Blind-XSS Disappointment
https://cdn-images-1.medium.com/max/2600/1*rPHZT2Ql-riu-gce2D9zpA.jpeg
Blind XSS is a relatively easy bug to find with the availability of tools like XSS-Hunter and Burp collaborator.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Blind-XSS Disappointment
https://cdn-images-1.medium.com/max/2600/1*rPHZT2Ql-riu-gce2D9zpA.jpeg
Blind XSS is a relatively easy bug to find with the availability of tools like XSS-Hunter and Burp collaborator.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blind-XSS Disappointment
Blind XSS is a relatively easy bug to find with the availability of tools like XSS-Hunter and Burp collaborator. When I started looking for…
Blind-XSS Disappointment
https://adamwize.medium.com/blind-xss-disappointment-f122d48cbb0a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://adamwize.medium.com/blind-xss-disappointment-f122d48cbb0a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blind-XSS Disappointment
Blind XSS is a relatively easy bug to find with the availability of tools like XSS-Hunter and Burp collaborator. When I started looking for…
Blind XSS is a relatively easy bug to find with the availability of tools like XSS-Hunter and Burp collaborator.Continue reading on Medium » (https://adamwize.medium.com/blind-xss-disappointment-f122d48cbb0a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blind-XSS Disappointment
Blind XSS is a relatively easy bug to find with the availability of tools like XSS-Hunter and Burp collaborator. When I started looking for…
($$$) IDOR via GET Request which can SOLD all User Products
https://aidilarf.medium.com/idor-via-get-request-which-can-sold-all-user-products-2f5bc3ea1650?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://aidilarf.medium.com/idor-via-get-request-which-can-sold-all-user-products-2f5bc3ea1650?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
($$$) IDOR via GET Request which can SOLD all User Products
Hi everyone,
Hi everyone,Continue reading on Medium » (https://aidilarf.medium.com/idor-via-get-request-which-can-sold-all-user-products-2f5bc3ea1650?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
($$$) IDOR via GET Request which can SOLD all User Products
Hi everyone,
($$$) IDOR via GET Request which can SOLD all User Products
Hi everyone,Continue reading on Medium »
Read more...
Hi everyone,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Registry-Spy : Cross-platform Registry Browser For Raw Windows Registry Files
Registry-Spy is a free, open-source cross-platform Windows Registry viewer. It is a fast, modern, and versatile explorer for raw registry files.
Features include:
* Fast, on-the-fly parsing means no upfront overhead
* Open multiple hives at a time
* Searching
* Hex viewer
* Modification timestamps
Requirements
* Python 3.8+
Installation
Download the latest version from the releases page. Alternatively, use one of the following methods.
pip (recommended)
*
*
Manual
*
*
*
Standalone
*
*
Screenshots
Main Window
https://blogger.googleusercontent.com/img/a/AVvXsEjPzPE3NIv7DJIrZd_7YHEvT9ZKqiu-yes82AyF5iwQStvdX3WEuUsebzx2X-Hx2WSMvqnNcjp66a4roK-IR4tRqwriwHUksbD9kX94HysY9cmc9_10v6zx3Ex_sO_0bp8WRGHmVqy7zD75fVoaH4kz8czuWuQ62F1v2Vn1kfw7tX0oAsvwqj0Mrh_L=s791
Find Dialog
https://blogger.googleusercontent.com/img/a/AVvXsEj73-tSNeitt7bjIVKW7U5ZpIhzzqleQywF8-XCXmq5Pc4kqZ9MFI4KfWC7QVSHrNfx9ZT2uoJ3w4zM5KrWj8mTo4cN2EYEL8w_uO5AyunrD6kGGCFiY3w2qv1OhoblNNic3fTrKIv-SE9zlotL-5E-Lbxj8pBerhDJn8PwJg9xCZxZxXKTbDrzX5B4=s402
Building
Dependencies:
* PyInstaller 4.5+
Regular building:
Creating a single file:
Download
___________________________
@hacking_Attack
@Hacking_Video
Registry-Spy : Cross-platform Registry Browser For Raw Windows Registry Files
Registry-Spy is a free, open-source cross-platform Windows Registry viewer. It is a fast, modern, and versatile explorer for raw registry files.
Features include:
* Fast, on-the-fly parsing means no upfront overhead
* Open multiple hives at a time
* Searching
* Hex viewer
* Modification timestamps
Requirements
* Python 3.8+
Installation
Download the latest version from the releases page. Alternatively, use one of the following methods.
pip (recommended)
*
pip install registryspy*
registryspyManual
*
pip install -r requirements.txt*
python setup.py install*
registryspyStandalone
*
pip install -r requirements.txt*
python registryspy.pyScreenshots
Main Window
https://blogger.googleusercontent.com/img/a/AVvXsEjPzPE3NIv7DJIrZd_7YHEvT9ZKqiu-yes82AyF5iwQStvdX3WEuUsebzx2X-Hx2WSMvqnNcjp66a4roK-IR4tRqwriwHUksbD9kX94HysY9cmc9_10v6zx3Ex_sO_0bp8WRGHmVqy7zD75fVoaH4kz8czuWuQ62F1v2Vn1kfw7tX0oAsvwqj0Mrh_L=s791
Find Dialog
https://blogger.googleusercontent.com/img/a/AVvXsEj73-tSNeitt7bjIVKW7U5ZpIhzzqleQywF8-XCXmq5Pc4kqZ9MFI4KfWC7QVSHrNfx9ZT2uoJ3w4zM5KrWj8mTo4cN2EYEL8w_uO5AyunrD6kGGCFiY3w2qv1OhoblNNic3fTrKIv-SE9zlotL-5E-Lbxj8pBerhDJn8PwJg9xCZxZxXKTbDrzX5B4=s402
Building
Dependencies:
* PyInstaller 4.5+
Regular building:
pyinstaller registryspy_install.specCreating a single file:
pyinstaller registryspy_onefile.specDownload
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Registry-Spy : Cross-platform Registry Browser For Raw Windows
Registry-Spy is a free, open-source cross-platform Windows Registry viewer. It is a fast, modern, and versatile explorer.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Inject-Assembly : Inject .NET Assemblies Into An Existing Process
Inject-Assembly is an alternative to traditional fork and run execution for Cobalt Strike. The loader can be injected into any process, including the current Beacon. Long-running assemblies will continue to run and send output back to the Beacon, similar to the behavior of execute-assembly.
There are two components of inject-assembly:
* BOF initializer: A small program responsible for injecting the assembly loader into a remote process with any arguments passed. It uses Beacon Inject Process to perform the injection, meaning this behavior can be customized in a Malleable C2 profile or with process injection BOFs (as of version 4.5).
* PIC assembly loader: The bulk of the project. The loader will initialize the .NET runtime, load the provided assembly, and execute the assembly. The loader will create a new App Domain in the target process so that the loaded assembly can be totally unloaded when execution is complete.
Communication between the remote process and Beacon occurs through a named pipe. The Aggressor script generates a pipe name and then passes it to the BOF initializer.
Notable Features
* Patches Environment.Exit() to prevent the remote process from exiting.
* .NET assembly header stomping (MZ bytes, e_lfanew, DOS Header, Rich Text, PE Header).
* Random pipe name generation based on SourcePoint.
* No blocking of the Beacon, even if the assembly is loaded into the current process.
Usage
Download and load the inject-assembly.cna Aggressor script into Cobalt Strike. You can then execute assemblies using the following command:
inject-assembly pid assembly [args…]
Specify 0 as the PID to execute in the current Beacon process.
It is recommended to use another tool, like FindObjects-BOF, to locate a process that already loads the .NET runtime, but this is not a requirement for inject-assembly to function.
Download
___________________________
@hacking_Attack
@Hacking_Video
Inject-Assembly : Inject .NET Assemblies Into An Existing Process
Inject-Assembly is an alternative to traditional fork and run execution for Cobalt Strike. The loader can be injected into any process, including the current Beacon. Long-running assemblies will continue to run and send output back to the Beacon, similar to the behavior of execute-assembly.
There are two components of inject-assembly:
* BOF initializer: A small program responsible for injecting the assembly loader into a remote process with any arguments passed. It uses Beacon Inject Process to perform the injection, meaning this behavior can be customized in a Malleable C2 profile or with process injection BOFs (as of version 4.5).
* PIC assembly loader: The bulk of the project. The loader will initialize the .NET runtime, load the provided assembly, and execute the assembly. The loader will create a new App Domain in the target process so that the loaded assembly can be totally unloaded when execution is complete.
Communication between the remote process and Beacon occurs through a named pipe. The Aggressor script generates a pipe name and then passes it to the BOF initializer.
Notable Features
* Patches Environment.Exit() to prevent the remote process from exiting.
* .NET assembly header stomping (MZ bytes, e_lfanew, DOS Header, Rich Text, PE Header).
* Random pipe name generation based on SourcePoint.
* No blocking of the Beacon, even if the assembly is loaded into the current process.
Usage
Download and load the inject-assembly.cna Aggressor script into Cobalt Strike. You can then execute assemblies using the following command:
inject-assembly pid assembly [args…]
Specify 0 as the PID to execute in the current Beacon process.
It is recommended to use another tool, like FindObjects-BOF, to locate a process that already loads the .NET runtime, but this is not a requirement for inject-assembly to function.
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Inject-Assembly : Inject .NET Assemblies Into An Existing Process
Inject-Assembly is an alternative to traditional fork and run execution for Cobalt Strike. The loader can be injected into any process.
($$$) IDOR via GET Request which can SOLD all User Products
Hi everyone,Continue reading on Medium »
Read more...
Hi everyone,Continue reading on Medium »
Read more...
hacking: security in practice
aircrack in VM
so i am trying to use aircrack on VM but it says something like wireless card undetected . so how can i use my laptop wireless in VM?
are there is any other way for wifi hacking?
submitted by /u/UnkownWithUnkownprsn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
aircrack in VM
so i am trying to use aircrack on VM but it says something like wireless card undetected . so how can i use my laptop wireless in VM?
are there is any other way for wifi hacking?
submitted by /u/UnkownWithUnkownprsn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
aircrack in VM
so i am trying to use aircrack on VM but it says something like wireless card undetected . so how can i use my laptop wireless in VM? are there...
hacking: security in practice
The Dirty Pipe Vulnerability
submitted by /u/donutloop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The Dirty Pipe Vulnerability
submitted by /u/donutloop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Dirty Pipe Vulnerability
Posted in r/hacking by u/donutloop • 1 point and 0 comments
hacking: security in practice
POST requests can accept URL Query parameters.
Was doing a pentest and i encountered a situation whereby there was a POST request API which takes a sensitive secret as a parameter. The interesting thing was that this API would also accept and parse the parameter even if it was sent as a query parameter.
For example the original request was to be
POST abc.com
Content-type: application/json /u/sg_pepehands69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
POST requests can accept URL Query parameters.
Was doing a pentest and i encountered a situation whereby there was a POST request API which takes a sensitive secret as a parameter. The interesting thing was that this API would also accept and parse the parameter even if it was sent as a query parameter.
For example the original request was to be
POST abc.com
Content-type: application/json /u/sg_pepehands69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
POST requests can accept URL Query parameters.
Was doing a pentest and i encountered a situation whereby there was a POST request API which takes a sensitive secret as a parameter. The...
hacking: security in practice
Hash identification
I'm not sure if this is the right place. So this hash is meant to be "admin" 84e8e3c1c19a6a2cba961c4a58d2699b but I can't figure out the hash. It looks MD4/5 but can't make a copy. This was off of a device running VxWorks 6.9 from a file called auth.txt. I'm not sure if it's actually vxworks using this file.
I don't need to crack it, since I set the passwords on my own device. Just would like to figure out the hashes it's using.
Thanks!
submitted by /u/tommykw
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hash identification
I'm not sure if this is the right place. So this hash is meant to be "admin" 84e8e3c1c19a6a2cba961c4a58d2699b but I can't figure out the hash. It looks MD4/5 but can't make a copy. This was off of a device running VxWorks 6.9 from a file called auth.txt. I'm not sure if it's actually vxworks using this file.
I don't need to crack it, since I set the passwords on my own device. Just would like to figure out the hashes it's using.
Thanks!
submitted by /u/tommykw
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hash identification
I'm not sure if this is the right place. So this hash is meant to be "admin" 84e8e3c1c19a6a2cba961c4a58d2699b but I can't figure out the hash. It...
Hacking on Medium
Learn SQL interactively!
https://cdn-images-1.medium.com/max/1916/1*w0nfDbNA9mwE-_-Kp3VFvQ.png
Intro
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Learn SQL interactively!
https://cdn-images-1.medium.com/max/1916/1*w0nfDbNA9mwE-_-Kp3VFvQ.png
Intro
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Learn SQL interactively!
Intro
GraphQL Cop - Security Auditor Utility For GraphQL APIs
http://www.kitploit.com/2022/03/graphql-cop-security-auditor-utility.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/graphql-cop-security-auditor-utility.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
GraphQL Cop - Security Auditor Utility For GraphQL APIs