By Ajay Srivastava, Aniket Kulkarni, Avinash Singh, Nathaniel CallensContinue reading on Grab » (https://medium.com/grab/reflecting-on-the-five-years-of-bug-bounty-at-grab-adf1df55eb80?source=rss------bug_bounty-5)
Reflecting on the Five Years of Bug Bounty at Grab
By Ajay Srivastava, Aniket Kulkarni, Avinash Singh, Nathaniel CallensContinue reading on Grab »
Read more...
By Ajay Srivastava, Aniket Kulkarni, Avinash Singh, Nathaniel CallensContinue reading on Grab »
Read more...
pentesting work station
https://www.reddit.com/r/Pentesting/comments/mp67yf/pentesting_work_station/
<!-- SC_OFF -->So was curious what you guys or gals consider essentials for a solid fast pentesting laptop. Do you prefer top notch specs, or certains aspects of hardware over others? what size screen do you prefer? <!-- SC_ON --> submitted by /u/Man_Chi1d (https://www.reddit.com/user/Man_Chi1d)
[link] (https://www.reddit.com/r/Pentesting/comments/mp67yf/pentesting_work_station/) [comments] (https://www.reddit.com/r/Pentesting/comments/mp67yf/pentesting_work_station/)
https://www.reddit.com/r/Pentesting/comments/mp67yf/pentesting_work_station/
<!-- SC_OFF -->So was curious what you guys or gals consider essentials for a solid fast pentesting laptop. Do you prefer top notch specs, or certains aspects of hardware over others? what size screen do you prefer? <!-- SC_ON --> submitted by /u/Man_Chi1d (https://www.reddit.com/user/Man_Chi1d)
[link] (https://www.reddit.com/r/Pentesting/comments/mp67yf/pentesting_work_station/) [comments] (https://www.reddit.com/r/Pentesting/comments/mp67yf/pentesting_work_station/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
what percentage of security professionals are most likely still grey hats and who is likely to be that person? What about for black hats?
So if someone is working as a job in cybersecurity, how likely are they to secretly be a grey hat hacker and what kind of person is still a grey hat hacker when they grow older? Do people in cybersecurity ever still tend to be black hat?
What would you recommend someone working in cybersecurity looks out for when it comes to other people who work at their organization?
This is not just about grey or black hats who target the organization they work for but in general.
https://www.itsecurityguru.org/2018/08/22/12-security-professionals-considered-black-hat-activity/
submitted by /u/notburneddown
[link] [comments]
what percentage of security professionals are most likely still grey hats and who is likely to be that person? What about for black hats?
So if someone is working as a job in cybersecurity, how likely are they to secretly be a grey hat hacker and what kind of person is still a grey hat hacker when they grow older? Do people in cybersecurity ever still tend to be black hat?
What would you recommend someone working in cybersecurity looks out for when it comes to other people who work at their organization?
This is not just about grey or black hats who target the organization they work for but in general.
https://www.itsecurityguru.org/2018/08/22/12-security-professionals-considered-black-hat-activity/
submitted by /u/notburneddown
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
is hacktivism really back as a movement?
I heard of this new organization and I looked it up. Its called Distributed Denial of Secrets.
They are the new equivalent of Anonymous but potentially a more organized collective.
https://www.wired.com/story/ddosecrets-ransomware-leaks/
https://www.cyberscoop.com/blue-leaks-police-database-ddosecrets/
https://twitter.com/ddosecret?lang=en
What do you think of these guys? Is this legit?
submitted by /u/notburneddown
[link] [comments]
is hacktivism really back as a movement?
I heard of this new organization and I looked it up. Its called Distributed Denial of Secrets.
They are the new equivalent of Anonymous but potentially a more organized collective.
https://www.wired.com/story/ddosecrets-ransomware-leaks/
https://www.cyberscoop.com/blue-leaks-police-database-ddosecrets/
https://twitter.com/ddosecret?lang=en
What do you think of these guys? Is this legit?
submitted by /u/notburneddown
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
RITSEC CTF Web Write-ups
https://cdn-images-1.medium.com/max/600/1*1PI59LNN29zRCtMGGwu8oA.png
Challenges: Sessions, Dababy web
Continue reading on Medium »
RITSEC CTF Web Write-ups
https://cdn-images-1.medium.com/max/600/1*1PI59LNN29zRCtMGGwu8oA.png
Challenges: Sessions, Dababy web
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploiting a Windows-Based Buffer Overflow
https://cdn-images-1.medium.com/max/681/1*ek7Od8WlbZYFk_RYI7RE0Q.png
This article is based on exploiting a simple buffer overflow in Windows using Vulnserver. If you don’t have an idea about buffer overflows…
Continue reading on Medium »
Exploiting a Windows-Based Buffer Overflow
https://cdn-images-1.medium.com/max/681/1*ek7Od8WlbZYFk_RYI7RE0Q.png
This article is based on exploiting a simple buffer overflow in Windows using Vulnserver. If you don’t have an idea about buffer overflows…
Continue reading on Medium »
🔥 Kubesploit: A new post-exploitation framework for Kubernetes and containers 🔥
https://www.reddit.com/r/Pentesting/comments/mp831e/kubesploit_a_new_postexploitation_framework_for/
https://www.reddit.com/r/Pentesting/comments/mp831e/kubesploit_a_new_postexploitation_framework_for/
submitted by /u/kubiscan (https://www.reddit.com/user/kubiscan)
[link] (https://github.com/cyberark/kubesploit) [comments] (https://www.reddit.com/r/Pentesting/comments/mp831e/kubesploit_a_new_postexploitation_framework_for/)
[link] (https://github.com/cyberark/kubesploit) [comments] (https://www.reddit.com/r/Pentesting/comments/mp831e/kubesploit_a_new_postexploitation_framework_for/)
CORS(How to find, identify and exploit)
Cross-Origin Resource Sharing has never been easy to find especially when it comes to exploiting the vulnerability.Continue reading on Medium »
Read more...
Cross-Origin Resource Sharing has never been easy to find especially when it comes to exploiting the vulnerability.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Data from 500M LinkedIn Users Posted for Sale Online
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Data from 500M LinkedIn Users Posted for Sale OnlinePost Views: 90
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
Personal data from more than 500 million LinkedIn users has been posted for sale online in yet another incident of threat actors scraping data from public profiles and slinging it online for potential cybercriminal misuse.
Like the Facebook incident earlier this week, the information — including user profile IDs, email addresses and other PII — was scraped from the social-media platform.
Hackers posted an archive containing data they said includes LinkedIn IDs, full names, professional titles, email addresses, phone numbers and other personally identifiable information (PII) on a popular hacker forum, according to a report in CyberNews on Tuesday.
The LinkedIn incident comes on the heels of a substantial leak of personal data from more than 533 million Facebook users last weekend.
The data set also includes links to LinkedIn profiles and other social-media profiles, according to the report. Moreover, to prove the authenticity of the info and provide a teaser of the data inside, the hackers responsible also leaked another 2 million records as a proof-of-concept sample, the report said.
Users on the forum can view the samples for about $2 worth of forum credits. However, the threat actor also appears to be auctioning off the crown jewel of the data-gathering — the 500-million-user database — for at a sum that is at least in the four-digit range, most likely in a Bitcoin equivalent, according to the report.
“As the leaked data contains no payment card details and no passwords, it’s of less value to attackers and won’t sell for much on the Dark Web anyway,” Candid Wuest, Acronis vice president of cyber-protection research, said via email. “However, it does contain valuable personal information (workplace info, email, social account links), which is why it’s not published it for free.”
See Also: Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers LinkedIn Confirms Data-ScrapingLinkedIn officials confirmed that data from the platform was included in the database and, like Facebook officials before them, said it was not due to a breach of its system but instead was scraped from the LinkedIn site.
“We have investigated an alleged set of LinkedIn data that has been posted for sale and have determined that it is actually an aggregation of data from a number of websites and companies” that includes “publicly viewable member-profile data that appears to have been scraped from LinkedIn,” the company said in a statement on its website, on Thursday.
“This was not a LinkedIn data breach, and no private member account data from LinkedIn was included in what we’ve been able to review,” according to the post.
Scraping is a common tactic used by threat actors to siphon public information from the internet that can then be sold online for profit and reused for malicious activity. Scraped data is often repurposed to create socially engineered phishing attacks, to commit identity theft, brute-force credentials or spam victims’ accounts, among other nefarious activity.
LinkedIn also echoed Facebook’s comments that any misuse of platform members’ data by scraping violates its terms of service, and said the company will be investigating.
“When anyone tries to take member data and use it for purposes LinkedIn and our members haven’t agreed to, we work to stop t[...]
Data from 500M LinkedIn Users Posted for Sale Online
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Data from 500M LinkedIn Users Posted for Sale OnlinePost Views: 90
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
Personal data from more than 500 million LinkedIn users has been posted for sale online in yet another incident of threat actors scraping data from public profiles and slinging it online for potential cybercriminal misuse.
Like the Facebook incident earlier this week, the information — including user profile IDs, email addresses and other PII — was scraped from the social-media platform.
Hackers posted an archive containing data they said includes LinkedIn IDs, full names, professional titles, email addresses, phone numbers and other personally identifiable information (PII) on a popular hacker forum, according to a report in CyberNews on Tuesday.
The LinkedIn incident comes on the heels of a substantial leak of personal data from more than 533 million Facebook users last weekend.
The data set also includes links to LinkedIn profiles and other social-media profiles, according to the report. Moreover, to prove the authenticity of the info and provide a teaser of the data inside, the hackers responsible also leaked another 2 million records as a proof-of-concept sample, the report said.
Users on the forum can view the samples for about $2 worth of forum credits. However, the threat actor also appears to be auctioning off the crown jewel of the data-gathering — the 500-million-user database — for at a sum that is at least in the four-digit range, most likely in a Bitcoin equivalent, according to the report.
“As the leaked data contains no payment card details and no passwords, it’s of less value to attackers and won’t sell for much on the Dark Web anyway,” Candid Wuest, Acronis vice president of cyber-protection research, said via email. “However, it does contain valuable personal information (workplace info, email, social account links), which is why it’s not published it for free.”
See Also: Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers LinkedIn Confirms Data-ScrapingLinkedIn officials confirmed that data from the platform was included in the database and, like Facebook officials before them, said it was not due to a breach of its system but instead was scraped from the LinkedIn site.
“We have investigated an alleged set of LinkedIn data that has been posted for sale and have determined that it is actually an aggregation of data from a number of websites and companies” that includes “publicly viewable member-profile data that appears to have been scraped from LinkedIn,” the company said in a statement on its website, on Thursday.
“This was not a LinkedIn data breach, and no private member account data from LinkedIn was included in what we’ve been able to review,” according to the post.
Scraping is a common tactic used by threat actors to siphon public information from the internet that can then be sold online for profit and reused for malicious activity. Scraped data is often repurposed to create socially engineered phishing attacks, to commit identity theft, brute-force credentials or spam victims’ accounts, among other nefarious activity.
LinkedIn also echoed Facebook’s comments that any misuse of platform members’ data by scraping violates its terms of service, and said the company will be investigating.
“When anyone tries to take member data and use it for purposes LinkedIn and our members haven’t agreed to, we work to stop t[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Data from 500M LinkedIn Users Posted for Sale Online https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Data from 500M LinkedIn Users Posted for Sale OnlinePost Views: 90 style…
hem and hold them accountable,” according to LinkedIn’s statement.
See Also: Offensive Security Tool: CVE Binary Tool by Intel It’s unclear at this time if LinkedIn will face regulatory troubles due to the incident, such as being in violation of the General Data Protection Rule (GDPR). The GDPR is a European Union rule that went into effect in May 2018 that mandates that companies disclose data breaches within a certain period of time or face penalties. Facebook currently faces an investigation by Ireland’s Data Protection Commission (IDPC) over the earlier leak.
CyberNews has posted an online tool so people can check to see if their data was leaked in the most recent LinkedIn incident. If that’s the case, they should be extra-cautious in opening suspicious emails or text messages or links related to messages from senders they don’t recognize. See Also: Hacking Stories: When two young hackers played war games with Pentagon“It is not uncommon to see such data sets being used to send personalized phishing emails, extort ransom or earn money on the Dark Web – especially now that many hackers target job seekers on LinkedIn with bogus job offers, infecting them with a backdoor trojan,” said Wuest. “For example, such personalized phishing attacks with LinkedIn lures were used by the Golden Chickens group last week.” Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/phph-90x90.jpg PHP Infiltrated with Backdoor Malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/ransomware_global_small-90x90.jpg Insurance Giant CNA Hit with Novel Ransomware Attack2 weeks ago
The post Data from 500M LinkedIn Users Posted for Sale Online first appeared on Black Hat Ethical Hacking.
See Also: Offensive Security Tool: CVE Binary Tool by Intel It’s unclear at this time if LinkedIn will face regulatory troubles due to the incident, such as being in violation of the General Data Protection Rule (GDPR). The GDPR is a European Union rule that went into effect in May 2018 that mandates that companies disclose data breaches within a certain period of time or face penalties. Facebook currently faces an investigation by Ireland’s Data Protection Commission (IDPC) over the earlier leak.
CyberNews has posted an online tool so people can check to see if their data was leaked in the most recent LinkedIn incident. If that’s the case, they should be extra-cautious in opening suspicious emails or text messages or links related to messages from senders they don’t recognize. See Also: Hacking Stories: When two young hackers played war games with Pentagon“It is not uncommon to see such data sets being used to send personalized phishing emails, extort ransom or earn money on the Dark Web – especially now that many hackers target job seekers on LinkedIn with bogus job offers, infecting them with a backdoor trojan,” said Wuest. “For example, such personalized phishing attacks with LinkedIn lures were used by the Golden Chickens group last week.” Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/phph-90x90.jpg PHP Infiltrated with Backdoor Malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/ransomware_global_small-90x90.jpg Insurance Giant CNA Hit with Novel Ransomware Attack2 weeks ago
The post Data from 500M LinkedIn Users Posted for Sale Online first appeared on Black Hat Ethical Hacking.
CORS(How to find, identify and exploit)
https://nvermaa.medium.com/cors-how-to-find-identify-and-exploit-28d82892f4e5?source=rss------bug_bounty-5
https://nvermaa.medium.com/cors-how-to-find-identify-and-exploit-28d82892f4e5?source=rss------bug_bounty-5