Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Excel Encryption

I have a problem I can’t seem to solve myself. I am trying to bypass a password for an encrypted Excel file. Not a password protected sheet/workbook, but the entire file. I have tried the convert it to .zip/.ooxml methods. Those do not seem to work. Adding the VBA code to remove the password doesn’t work seeing as how you can’t access the VBA page. My question is, is this even doable? Can the password prompt be removed if you don’t know the password? Is there a way to extract the data without needing the password? Would the data just be encrypted if extracting the data is possible? Brute force is a difficult option because the password isn’t a common password, and also not really the point of the challenge I’m giving myself. Any help you can throw my way would be fantastic.
excel_pw_prompt

submitted by /u/tjones1231
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
What “if” I can get more reward?

An imcomplete if logic that leads to a catastrophic loss.Continue reading on Medium »
Read more...
hacking: security in practice
Am I able to sniff traffic from a different subnet?

I feel like I already know the answer but I just sort of want a sanity check. I was participating in an ICS security challenge earlier today and the way the organizers had it set up, competitors connected via Wi-Fi and were given DHCP addresses in the 10.88.0.0/24 range. We were told that there was a target subnet in the 10.88.5.0/24 range that was populated by various PLCs and modbus devices. Nmap was against the rules as it could brick the equipment. I was able to browse to an address in the target subnet in my browser and it was a PeakHMI server web interface, so I’m able to at least send requests to that subnet.

The issue is, how can I set up wireshark to be able to sniff out modbus traffic to help me target other devices in that range? My initial tests seem to not show anything coming through in the capture. Am I just dumb or did the organizers misconfigure things and segmented the competitors off from the traffic they were meant to capture?

submitted by /u/tsuto
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Why is Stack Randomization on 32 bit is not so effective? Can we brute force the addresses ?

So, I'm trying to learn more about buffer overflows and one common fix is Stack Randomization or ASLR. But I read that on a 32 bit machine they're not that effective? Why is that?

Let's say I want to perform a simple buffer overflow and execute a shell code. Jmp esp is disabled so the only way to get the esp address is brute forcing. How hard is it in a 32 bit machine as compared to 64 bits.

submitted by /u/reddotname
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to approach Burp Suite academy and certification

Hello folks, I currently study web vulnerabilities on Burp Suite academy with the next opportunity to pass the certification exam as well as gain skills and understanding for OWASP TOP 10 vulnerabilities testing for the future job.

The question is how to make notes that helped me in the job/certification exam?

I literally copy the whole page text to my Obsidian editor... Just don't want to lose some information that causes me to misunderstand something. It is like a whole Burp Academy website in my Obsidian, just without pictures, this probably makes no sense as I can not find or define needed information for vulns finding and exploitation. (just a bunch of info: what vulnerability is about, how it impact a business, types of vulns, etc. )

I want to make like cheatsheet for myself based on the content regarding vulnerabilities identification/testing/exploitation, that helps me in an exam environment and the real world.

Any tips are appreciated, thank you in advance.

submitted by /u/TRYH0
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Favorite "hacking" tool NOT in Kali?

Have an interesting favorite tool that is maybe lesser-known or just not included in Kali? I want to hear about them!

I'll get us started with two:

* crocodilehunter
* imsi-catcher

Both of these are related to cellphone tower emulation

submitted by /u/TechSquidTV
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Online Roulette (read description)

Kind of off topic but i found a site (stake.com) with online roulette that actually briefly shows the numbers about 3 seconds before bets close, with the ball spinning around the wheel already.

I know it may be magnetized and random but i couldn't help but think if i knew programming then perhaps a program could determine the most likely number based on the speed of the ball and what numbers it crosses as well as the time before the spin (varies from -x to 6 seconds). Sometimes bets close before the wheel shows but usually there are a couple of seconds where a program could easily calculate and auto bet the most likely number.

submitted by /u/smoothSojourn610
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Recovery Hard Drive Data 🍀

New to Hard drives, I’ve a HDD 1TB seagate, which crashed couple of weeks ago. Has around 250 gb of data in it (Photos and Videos) is it possible to recover and is there any way for it? Any expertise suggestions would be just great! 😅 Have a great day everyone ⛅️

submitted by /u/ZoomINZ0D
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Facebook bug bounty: Part- 1 Expectation vs Reality

I have already written some reports on bugreader you can check here.Continue reading on Medium »
Read more...