Deep Web
Trying to explore the deep web. I am new.
Hi, I have a MacBook Pro but I was told that MacBooks are not that secure. I am not tryna get hacked or something at all. Not just on the deep web but I want to be as secure as possible on tor. I've heard about tails, VM's, VPN's, and the such. What is the best way to be completely invisible whilst on the deep web or surface net.
submitted by /u/Clikkks
[link] [comments]
Trying to explore the deep web. I am new.
Hi, I have a MacBook Pro but I was told that MacBooks are not that secure. I am not tryna get hacked or something at all. Not just on the deep web but I want to be as secure as possible on tor. I've heard about tails, VM's, VPN's, and the such. What is the best way to be completely invisible whilst on the deep web or surface net.
submitted by /u/Clikkks
[link] [comments]
reddit
Trying to explore the deep web. I am new.
Hi, I have a MacBook Pro but I was told that MacBooks are not that secure. I am not tryna get hacked or something at all. Not just on the deep web...
hacking: security in practice
Is cox giving me free wifi
Hey guys, I'm scheduled to get cox internet installed tomorrow in this apt complex i just moved in, since Friday just messing around noticed there was no password required wifi in my phone network and they are from cox, when you connect it just takes you to a page to agree their terms and your in , you get a solid 15mbps I live alone so that's all I need, modem is off and unplugged, what gives?, Should I cancel my internet hook up for tomorrow 😁
submitted by /u/Sajor1975
[link] [comments]
Is cox giving me free wifi
Hey guys, I'm scheduled to get cox internet installed tomorrow in this apt complex i just moved in, since Friday just messing around noticed there was no password required wifi in my phone network and they are from cox, when you connect it just takes you to a page to agree their terms and your in , you get a solid 15mbps I live alone so that's all I need, modem is off and unplugged, what gives?, Should I cancel my internet hook up for tomorrow 😁
submitted by /u/Sajor1975
[link] [comments]
reddit
Is cox giving me free wifi
Hey guys, I'm scheduled to get cox internet installed tomorrow in this apt complex i just moved in, since Friday just messing around noticed there...
hacking: security in practice
Firewall IP/port based ?
If I am to block outgoing connections in a server firewall, should it be better done with IP or port? If I understand this correctly, we use IP addresses, we would need to create a whitelist of IPs (from/to) that is connected but that I think that would become complicated quickly without central administration. If use ports, how to decide upon random (source) ports as they can be anything for given connection.
submitted by /u/Harry_pentest
[link] [comments]
Firewall IP/port based ?
If I am to block outgoing connections in a server firewall, should it be better done with IP or port? If I understand this correctly, we use IP addresses, we would need to create a whitelist of IPs (from/to) that is connected but that I think that would become complicated quickly without central administration. If use ports, how to decide upon random (source) ports as they can be anything for given connection.
submitted by /u/Harry_pentest
[link] [comments]
reddit
Firewall IP/port based ?
If I am to block outgoing connections in a server firewall, should it be better done with IP or port? If I understand this correctly, we use IP...
Analysing JavaScript Files For Bug Bounty Hunters
What is JS even?Continue reading on Medium »
Read more...
What is JS even?Continue reading on Medium »
Read more...
Analysing JavaScript Files For Bug Bounty Hunters
https://thexssrat.medium.com/analysing-javascript-files-for-bug-bounty-hunters-71e2727abebe?source=rss------bug_bounty-5
https://thexssrat.medium.com/analysing-javascript-files-for-bug-bounty-hunters-71e2727abebe?source=rss------bug_bounty-5
What is JS even?Continue reading on Medium » (https://thexssrat.medium.com/analysing-javascript-files-for-bug-bounty-hunters-71e2727abebe?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HTB — Devel (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*cWTDLAfcw0sNl8EubK0Cdg.png
This is an easy Windows box released back in March 2017, we’re going to own this box without the use of Metasploit.
Continue reading on Medium »
HTB — Devel (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*cWTDLAfcw0sNl8EubK0Cdg.png
This is an easy Windows box released back in March 2017, we’re going to own this box without the use of Metasploit.
Continue reading on Medium »
hacking: security in practice
hacked from omegle
Hi i was on omegle and a guy with a guitar i think clicked a button and then these black screens that had i code i think? flashed on the screen i skipped super quick tho? but like please tell me i’m wiping my computer does this mean they found my ip?
submitted by /u/beetlezonurface
[link] [comments]
hacked from omegle
Hi i was on omegle and a guy with a guitar i think clicked a button and then these black screens that had i code i think? flashed on the screen i skipped super quick tho? but like please tell me i’m wiping my computer does this mean they found my ip?
submitted by /u/beetlezonurface
[link] [comments]
reddit
hacked from omegle
Hi i was on omegle and a guy with a guitar i think clicked a button and then these black screens that had i code i think? flashed on the screen i...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to be become an hacker
Hello guys today i am going to talk Regarding the hacker, how to be become an hacker is seen as youngster today. They are all getting very…
Continue reading on Medium »
How to be become an hacker
Hello guys today i am going to talk Regarding the hacker, how to be become an hacker is seen as youngster today. They are all getting very…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for FreePost Views: 47
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 2 Minutes
Clubhouse, the startup invitation-only chat app, is the latest social-media platform to see mammoth troves of user data collected and posted in underground forums. An SQL file containing the personal data of 1.3 million Clubhouse users has been posted in a hacker forum for free.
Clubhouse denies it was ‘breached’ and says the data is out there for anyone to grab.
Names, user IDs, photo URL, number of followers, Twitter and Instagram handles, dates that accounts were created and even the profile information of who invited them to the app are among the information contained in the database, according to CyberNews, giving threat actors key information which can be used against victims in phishing and other socially engineered scams.
For its part, Clubhouse said that its users’ data being public isn’t a bug, it’s just how the platform is built:
This is misleading and false. Clubhouse has not been breached or hacked. The data referred to is all public profile information from our app, which anyone can access via the app or our API. https://t.co/I1OfPyc0Bo
— Clubhouse (@joinClubhouse) April 11, 2021
See Also: Data from 500M LinkedIn Users Posted for Sale Online
The company isn’t supplying any other details and Clubhouse didn’t respond to Threatpost’s request for additional comment.
Clubhouse followers on Twitter were quick to note the statement points out a difference without any distinction to its exposed users.
“I fail to see what is false … ” user Benjamin Maynard responded to the Clubhouse statement. Leaky APIs Plague Social MediaClubhouse’s terms of service prohibit data scraping, yet its API, by its own admission, is sitting online with no protection against it.
“Clubhouse has conflicting user policies – being an invite-only platform and at the same time free-for-all user data,” Setu Kulkarni, vice president with WhiteHat Security said. “All it takes is one user to figure out the API for such large data egress of the millions of users on the platform.”
Kulkani added that these platforms need to shift to an API-first security strategy.
“Testing APIs in production is as if not more important than ever for not just vulnerabilities but also for business logic flaws that can result in unfettered access to user data,” he said.
https://media.threatpost.com/wp-content/uploads/sites/103/2021/04/12160922/leaked-database-image-300x115.png
The Clubhouse database. Click to enlarge. Source: CyberNews.
CyberNews researcher Mantas Sasnauskas analyzed the Clubhouse data and said the privacy bug is built into the platform itself.
“The way the Clubhouse app is built lets anyone with a token, or via an API, to query the entire body of public Clubhouse user profile information, and it seems that token does not expire,” Sasnauskas said.
The CyberNews team added that the SQL file posted in the hacker forum only has Clubhouse-related information and doesn’t include “sensitive data like credit-card details or legal documents.”
See Also: Offensive Security Tool: CVE Binary Tool by Intel Denying the ProblemIn the past two weeks, 533 million Facebook users’ data was leaked, LinkedIn saw scraping of 500 million people’s data and now Clubhouse has given up the information on another 1.3 million people.
And as Politico Europe’s N[...]
1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for FreePost Views: 47
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 2 Minutes
Clubhouse, the startup invitation-only chat app, is the latest social-media platform to see mammoth troves of user data collected and posted in underground forums. An SQL file containing the personal data of 1.3 million Clubhouse users has been posted in a hacker forum for free.
Clubhouse denies it was ‘breached’ and says the data is out there for anyone to grab.
Names, user IDs, photo URL, number of followers, Twitter and Instagram handles, dates that accounts were created and even the profile information of who invited them to the app are among the information contained in the database, according to CyberNews, giving threat actors key information which can be used against victims in phishing and other socially engineered scams.
For its part, Clubhouse said that its users’ data being public isn’t a bug, it’s just how the platform is built:
This is misleading and false. Clubhouse has not been breached or hacked. The data referred to is all public profile information from our app, which anyone can access via the app or our API. https://t.co/I1OfPyc0Bo
— Clubhouse (@joinClubhouse) April 11, 2021
See Also: Data from 500M LinkedIn Users Posted for Sale Online
The company isn’t supplying any other details and Clubhouse didn’t respond to Threatpost’s request for additional comment.
Clubhouse followers on Twitter were quick to note the statement points out a difference without any distinction to its exposed users.
“I fail to see what is false … ” user Benjamin Maynard responded to the Clubhouse statement. Leaky APIs Plague Social MediaClubhouse’s terms of service prohibit data scraping, yet its API, by its own admission, is sitting online with no protection against it.
“Clubhouse has conflicting user policies – being an invite-only platform and at the same time free-for-all user data,” Setu Kulkarni, vice president with WhiteHat Security said. “All it takes is one user to figure out the API for such large data egress of the millions of users on the platform.”
Kulkani added that these platforms need to shift to an API-first security strategy.
“Testing APIs in production is as if not more important than ever for not just vulnerabilities but also for business logic flaws that can result in unfettered access to user data,” he said.
https://media.threatpost.com/wp-content/uploads/sites/103/2021/04/12160922/leaked-database-image-300x115.png
The Clubhouse database. Click to enlarge. Source: CyberNews.
CyberNews researcher Mantas Sasnauskas analyzed the Clubhouse data and said the privacy bug is built into the platform itself.
“The way the Clubhouse app is built lets anyone with a token, or via an API, to query the entire body of public Clubhouse user profile information, and it seems that token does not expire,” Sasnauskas said.
The CyberNews team added that the SQL file posted in the hacker forum only has Clubhouse-related information and doesn’t include “sensitive data like credit-card details or legal documents.”
See Also: Offensive Security Tool: CVE Binary Tool by Intel Denying the ProblemIn the past two weeks, 533 million Facebook users’ data was leaked, LinkedIn saw scraping of 500 million people’s data and now Clubhouse has given up the information on another 1.3 million people.
And as Politico Europe’s N[...]