Hacking on Medium
Anti-Virus Software Is Usually A Scam
https://cdn-images-1.medium.com/max/1493/1*x6jX58anqFxnnKsZQw5nOw.jpeg
Uncovering the truth about anti-virus software, are you really protected?
Continue reading on empeastories »
___________________________
@hacking_Attack
@Hacking_Video
Anti-Virus Software Is Usually A Scam
https://cdn-images-1.medium.com/max/1493/1*x6jX58anqFxnnKsZQw5nOw.jpeg
Uncovering the truth about anti-virus software, are you really protected?
Continue reading on empeastories »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Anti-Virus Software Is Usually A Scam
Uncovering the truth about anti-virus software, are you really protected?
hacking: security in practice
Am I able to sniff traffic from a different subnet?
I feel like I already know the answer but I just sort of want a sanity check. I was participating in an ICS security challenge earlier today and the way the organizers had it set up, competitors connected via Wi-Fi and were given DHCP addresses in the 10.88.0.0/24 range. We were told that there was a target subnet in the 10.88.5.0/24 range that was populated by various PLCs and modbus devices. Nmap was against the rules as it could brick the equipment. I was able to browse to an address in the target subnet in my browser and it was a PeakHMI server web interface, so I’m able to at least send requests to that subnet.
The issue is, how can I set up wireshark to be able to sniff out modbus traffic to help me target other devices in that range? My initial tests seem to not show anything coming through in the capture. Am I just dumb or did the organizers misconfigure things and segmented the competitors off from the traffic they were meant to capture?
submitted by /u/tsuto
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Am I able to sniff traffic from a different subnet?
I feel like I already know the answer but I just sort of want a sanity check. I was participating in an ICS security challenge earlier today and the way the organizers had it set up, competitors connected via Wi-Fi and were given DHCP addresses in the 10.88.0.0/24 range. We were told that there was a target subnet in the 10.88.5.0/24 range that was populated by various PLCs and modbus devices. Nmap was against the rules as it could brick the equipment. I was able to browse to an address in the target subnet in my browser and it was a PeakHMI server web interface, so I’m able to at least send requests to that subnet.
The issue is, how can I set up wireshark to be able to sniff out modbus traffic to help me target other devices in that range? My initial tests seem to not show anything coming through in the capture. Am I just dumb or did the organizers misconfigure things and segmented the competitors off from the traffic they were meant to capture?
submitted by /u/tsuto
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Am I able to sniff traffic from a different subnet?
I feel like I already know the answer but I just sort of want a sanity check. I was participating in an ICS security challenge earlier today and...
hacking: security in practice
Why is Stack Randomization on 32 bit is not so effective? Can we brute force the addresses ?
So, I'm trying to learn more about buffer overflows and one common fix is Stack Randomization or ASLR. But I read that on a 32 bit machine they're not that effective? Why is that?
Let's say I want to perform a simple buffer overflow and execute a shell code. Jmp esp is disabled so the only way to get the esp address is brute forcing. How hard is it in a 32 bit machine as compared to 64 bits.
submitted by /u/reddotname
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why is Stack Randomization on 32 bit is not so effective? Can we brute force the addresses ?
So, I'm trying to learn more about buffer overflows and one common fix is Stack Randomization or ASLR. But I read that on a 32 bit machine they're not that effective? Why is that?
Let's say I want to perform a simple buffer overflow and execute a shell code. Jmp esp is disabled so the only way to get the esp address is brute forcing. How hard is it in a 32 bit machine as compared to 64 bits.
submitted by /u/reddotname
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Why is Stack Randomization on 32 bit is not so effective? Can we...
So, I'm trying to learn more about buffer overflows and one common fix is Stack Randomization or ASLR. But I read that on a 32 bit machine they're...
hacking: security in practice
How to approach Burp Suite academy and certification
Hello folks, I currently study web vulnerabilities on Burp Suite academy with the next opportunity to pass the certification exam as well as gain skills and understanding for OWASP TOP 10 vulnerabilities testing for the future job.
The question is how to make notes that helped me in the job/certification exam?
I literally copy the whole page text to my Obsidian editor... Just don't want to lose some information that causes me to misunderstand something. It is like a whole Burp Academy website in my Obsidian, just without pictures, this probably makes no sense as I can not find or define needed information for vulns finding and exploitation. (just a bunch of info: what vulnerability is about, how it impact a business, types of vulns, etc. )
I want to make like cheatsheet for myself based on the content regarding vulnerabilities identification/testing/exploitation, that helps me in an exam environment and the real world.
Any tips are appreciated, thank you in advance.
submitted by /u/TRYH0
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to approach Burp Suite academy and certification
Hello folks, I currently study web vulnerabilities on Burp Suite academy with the next opportunity to pass the certification exam as well as gain skills and understanding for OWASP TOP 10 vulnerabilities testing for the future job.
The question is how to make notes that helped me in the job/certification exam?
I literally copy the whole page text to my Obsidian editor... Just don't want to lose some information that causes me to misunderstand something. It is like a whole Burp Academy website in my Obsidian, just without pictures, this probably makes no sense as I can not find or define needed information for vulns finding and exploitation. (just a bunch of info: what vulnerability is about, how it impact a business, types of vulns, etc. )
I want to make like cheatsheet for myself based on the content regarding vulnerabilities identification/testing/exploitation, that helps me in an exam environment and the real world.
Any tips are appreciated, thank you in advance.
submitted by /u/TRYH0
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to approach Burp Suite academy and certification
Hello folks, I currently study web vulnerabilities on Burp Suite academy with the next opportunity to pass the certification exam as well as gain...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Threat Actor Profile - LAPSUS$
https://external-preview.redd.it/jxf9TxxP5xerJqMYj2fqvGWkQcpLsgxupZ376BahlGA.jpg?width=640&crop=smart&auto=webp&s=49852664cecbf3497c6f2139c82881591934777a submitted by /u/RandyMarsh_Lorde
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Threat Actor Profile - LAPSUS$
https://external-preview.redd.it/jxf9TxxP5xerJqMYj2fqvGWkQcpLsgxupZ376BahlGA.jpg?width=640&crop=smart&auto=webp&s=49852664cecbf3497c6f2139c82881591934777a submitted by /u/RandyMarsh_Lorde
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Threat Actor Profile - LAPSUS$
Posted in r/hacking by u/RandyMarsh_Lorde • 1 point and 0 comments
hacking: security in practice
Favorite "hacking" tool NOT in Kali?
Have an interesting favorite tool that is maybe lesser-known or just not included in Kali? I want to hear about them!
I'll get us started with two:
* crocodilehunter
* imsi-catcher
Both of these are related to cellphone tower emulation
submitted by /u/TechSquidTV
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Favorite "hacking" tool NOT in Kali?
Have an interesting favorite tool that is maybe lesser-known or just not included in Kali? I want to hear about them!
I'll get us started with two:
* crocodilehunter
* imsi-catcher
Both of these are related to cellphone tower emulation
submitted by /u/TechSquidTV
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Favorite "hacking" tool NOT in Kali?
Have an interesting favorite tool that is maybe lesser-known or just not included in Kali? I want to hear about them! I'll get us started with...
hacking: security in practice
Online Roulette (read description)
Kind of off topic but i found a site (stake.com) with online roulette that actually briefly shows the numbers about 3 seconds before bets close, with the ball spinning around the wheel already.
I know it may be magnetized and random but i couldn't help but think if i knew programming then perhaps a program could determine the most likely number based on the speed of the ball and what numbers it crosses as well as the time before the spin (varies from -x to 6 seconds). Sometimes bets close before the wheel shows but usually there are a couple of seconds where a program could easily calculate and auto bet the most likely number.
submitted by /u/smoothSojourn610
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Online Roulette (read description)
Kind of off topic but i found a site (stake.com) with online roulette that actually briefly shows the numbers about 3 seconds before bets close, with the ball spinning around the wheel already.
I know it may be magnetized and random but i couldn't help but think if i knew programming then perhaps a program could determine the most likely number based on the speed of the ball and what numbers it crosses as well as the time before the spin (varies from -x to 6 seconds). Sometimes bets close before the wheel shows but usually there are a couple of seconds where a program could easily calculate and auto bet the most likely number.
submitted by /u/smoothSojourn610
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Online Roulette (read description)
Kind of off topic but i found a site (stake.com) with online roulette that actually briefly shows the numbers about 3 seconds before bets close,...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Anonymous TV 🇺🇦 on Twitter
https://external-preview.redd.it/emTjl259TXOsfIR-pKqJsRJP2TdhU0lwaL5IM9tpODQ.jpg?width=108&crop=smart&auto=webp&s=d78f8b27db3e57af54c81800ead3b5a32634d1a0 submitted by /u/Tugushin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anonymous TV 🇺🇦 on Twitter
https://external-preview.redd.it/emTjl259TXOsfIR-pKqJsRJP2TdhU0lwaL5IM9tpODQ.jpg?width=108&crop=smart&auto=webp&s=d78f8b27db3e57af54c81800ead3b5a32634d1a0 submitted by /u/Tugushin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anonymous TV 🇺🇦 on Twitter
Posted in r/hacking by u/Tugushin • 1 point and 1 comment
hacking: security in practice
Recovery Hard Drive Data 🍀
New to Hard drives, I’ve a HDD 1TB seagate, which crashed couple of weeks ago. Has around 250 gb of data in it (Photos and Videos) is it possible to recover and is there any way for it? Any expertise suggestions would be just great! 😅 Have a great day everyone ⛅️
submitted by /u/ZoomINZ0D
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recovery Hard Drive Data 🍀
New to Hard drives, I’ve a HDD 1TB seagate, which crashed couple of weeks ago. Has around 250 gb of data in it (Photos and Videos) is it possible to recover and is there any way for it? Any expertise suggestions would be just great! 😅 Have a great day everyone ⛅️
submitted by /u/ZoomINZ0D
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Recovery Hard Drive Data 🍀
New to Hard drives, I’ve a HDD 1TB seagate, which crashed couple of weeks ago. Has around 250 gb of data in it (Photos and Videos) is it possible...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Maximum 7-Year Sentence for University of Pittsburg Medical Center Hacker
https://external-preview.redd.it/i7GID66WfOkmpO8Z_ErYDc59H4QJN2oy1vZZV4WMktA.jpg?width=320&crop=smart&auto=webp&s=0f07a2abfea840f509e38eaf5aec5fa43df86fb0 submitted by /u/IleenRyder
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Maximum 7-Year Sentence for University of Pittsburg Medical Center Hacker
https://external-preview.redd.it/i7GID66WfOkmpO8Z_ErYDc59H4QJN2oy1vZZV4WMktA.jpg?width=320&crop=smart&auto=webp&s=0f07a2abfea840f509e38eaf5aec5fa43df86fb0 submitted by /u/IleenRyder
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Maximum 7-Year Sentence for University of Pittsburg Medical Center...
Posted in r/hacking by u/IleenRyder • 2 points and 0 comments
Facebook bug bounty: Part- 1 Expectation vs Reality
I have already written some reports on bugreader you can check here.Continue reading on Medium »
Read more...
I have already written some reports on bugreader you can check here.Continue reading on Medium »
Read more...
Facebook bug bounty: Part- 1 Expectation vs Reality
https://iamgk808.medium.com/facebook-bug-bounty-part-1-expectation-vs-reality-c51911192394?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://iamgk808.medium.com/facebook-bug-bounty-part-1-expectation-vs-reality-c51911192394?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Facebook bug bounty: Part- 1 Expectation vs Reality
I have already written some reports on bugreader you can check here. This post is about my personal experience with the Facebook bug bounty…
I have already written some reports on bugreader you can check here.Continue reading on Medium » (https://iamgk808.medium.com/facebook-bug-bounty-part-1-expectation-vs-reality-c51911192394?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Facebook bug bounty: Part- 1 Expectation vs Reality
I have already written some reports on bugreader you can check here. This post is about my personal experience with the Facebook bug bounty…
Information Gathering: Concept, Techniques and Tools explained
https://thenurhabib.medium.com/information-gathering-concept-techniques-and-tools-explained-f3dfee3ed82a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://thenurhabib.medium.com/information-gathering-concept-techniques-and-tools-explained-f3dfee3ed82a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Information Gathering: Concept, Techniques and Tools explained
Information Gathering means gathering different kinds of information about the target. It is basically, the first step or the beginning…
Information Gathering means gathering different kinds of information about the target. It is basically, the first step or the beginning…Continue reading on Medium » (https://thenurhabib.medium.com/information-gathering-concept-techniques-and-tools-explained-f3dfee3ed82a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Information Gathering: Concept, Techniques and Tools explained
Information Gathering means gathering different kinds of information about the target. It is basically, the first step or the beginning…