Hacking on Medium
Masking IPLogger as YouTube
https://cdn-images-1.medium.com/max/900/1*AT_acKyGLKL3LvtQYFjA9w.jpeg
IPLogger (https://iplogger.org/) is a service that allows you to get the victim’s IP address and User Agent using a link.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Masking IPLogger as YouTube
https://cdn-images-1.medium.com/max/900/1*AT_acKyGLKL3LvtQYFjA9w.jpeg
IPLogger (https://iplogger.org/) is a service that allows you to get the victim’s IP address and User Agent using a link.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Masking IPLogger as YouTube
IPLogger (https://iplogger.org/) is a service that allows you to get the victim’s IP address and User Agent using a link. IP = full de-anon…
Hacking on Medium
How I cleared eJPT Exam — My Experience
https://cdn-images-1.medium.com/max/1456/1*qcA5Omur8tYgd99MfhQ4Bw.png
Hello everyone. I have successfully passed eLearnSecurity Junior Penetration Tester exam on April 03, 2022. I would like to share my…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How I cleared eJPT Exam — My Experience
https://cdn-images-1.medium.com/max/1456/1*qcA5Omur8tYgd99MfhQ4Bw.png
Hello everyone. I have successfully passed eLearnSecurity Junior Penetration Tester exam on April 03, 2022. I would like to share my…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I cleared eJPT Exam — My Experience
Hello everyone. I have successfully passed eLearnSecurity Junior Penetration Tester exam on April 03, 2022. I would like to share my…
Hacking on Medium
Changing the MAC Address on Android
https://cdn-images-1.medium.com/max/1280/1*6sfKxVCcL35UaqPbET3Feg.jpeg
This Android app allows you to change your device’s MAC address to a random one, or one that you specify.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Changing the MAC Address on Android
https://cdn-images-1.medium.com/max/1280/1*6sfKxVCcL35UaqPbET3Feg.jpeg
This Android app allows you to change your device’s MAC address to a random one, or one that you specify.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Changing the MAC Address on Android
This Android app allows you to change your device’s MAC address to a random one, or one that you specify.
Hacking on Medium
Create your own QR code with your logo?
https://cdn-images-1.medium.com/max/1280/1*NoAeGXDDG3Nk_PRyKwcQew.jpeg
The conventional wisdom is that QR codes are used by large companies and brands, but this is not the case. Anyone can create their own…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Create your own QR code with your logo?
https://cdn-images-1.medium.com/max/1280/1*NoAeGXDDG3Nk_PRyKwcQew.jpeg
The conventional wisdom is that QR codes are used by large companies and brands, but this is not the case. Anyone can create their own…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Create your own QR code with your logo?
The conventional wisdom is that QR codes are used by large companies and brands, but this is not the case. Anyone can create their own…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Gitlab critical vulnerability leading to account takeovers
hey guys have you heard this news about some sort of compromise at gitlab? has any of you guys using Gitlab had their passwords reset right after this incident?
https://www.bleepingcomputer.com/news/security/critical-gitlab-vulnerability-lets-attackers-take-over-accounts/
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Gitlab critical vulnerability leading to account takeovers
hey guys have you heard this news about some sort of compromise at gitlab? has any of you guys using Gitlab had their passwords reset right after this incident?
https://www.bleepingcomputer.com/news/security/critical-gitlab-vulnerability-lets-attackers-take-over-accounts/
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Gitlab critical vulnerability leading to account takeovers
hey guys have you heard this news about some sort of compromise at gitlab? has any of you guys using Gitlab had their passwords reset right after...
hacking: security in practice
Decoding raw data from magnetic stripe card
My university uses a magnetic stripe card for IDs. It stored your student information, food balance, and door access.
I’ve already learned that Track 2 stores the student ID which is also used for food balance, and I’ve already learned how to edit this. But actually using it isn’t plausible considering it’s a blank card and you have to hand it to an employee to get food.
I’m assuming that Track 3 is where door access is stored, but when trying to read it as data type “User_Type” with my MSR605X it gives me a Read Error. It gives me read error in all types except raw data actually.
I’ve attempted cloning my ID raw data to a card that only uses track 3, and it successfully opened my dorm door. So I know track 3 stores that information, but I don’t understand why I’m receiving a read error. Is it in a custom format or something? How would I go about editing it?
submitted by /u/LucienMr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Decoding raw data from magnetic stripe card
My university uses a magnetic stripe card for IDs. It stored your student information, food balance, and door access.
I’ve already learned that Track 2 stores the student ID which is also used for food balance, and I’ve already learned how to edit this. But actually using it isn’t plausible considering it’s a blank card and you have to hand it to an employee to get food.
I’m assuming that Track 3 is where door access is stored, but when trying to read it as data type “User_Type” with my MSR605X it gives me a Read Error. It gives me read error in all types except raw data actually.
I’ve attempted cloning my ID raw data to a card that only uses track 3, and it successfully opened my dorm door. So I know track 3 stores that information, but I don’t understand why I’m receiving a read error. Is it in a custom format or something? How would I go about editing it?
submitted by /u/LucienMr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Decoding raw data from magnetic stripe card
My university uses a magnetic stripe card for IDs. It stored your student information, food balance, and door access. I’ve already learned that...
hacking: security in practice
what do "you" do next?
Lab environment or contacted pentest. You get a Foothold in the AD domain as a low level priv domain user and escalate your privileges to local admin or system. I know what the first thing I check next, but curious what's the first thing other check and why? Do you work bottom up 'low hanging fruit' or top to bottom?
submitted by /u/newworldsamurai3030
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
what do "you" do next?
Lab environment or contacted pentest. You get a Foothold in the AD domain as a low level priv domain user and escalate your privileges to local admin or system. I know what the first thing I check next, but curious what's the first thing other check and why? Do you work bottom up 'low hanging fruit' or top to bottom?
submitted by /u/newworldsamurai3030
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
what do "you" do next?
Lab environment or contacted pentest. You get a Foothold in the AD domain as a low level priv domain user and escalate your privileges to local...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Newly found Android malware records audio, tracks your location
hey guys check out this news on a newly detected android malware that's tracking your activities down to the minute details and in real time? Apparently, it seems like this is guising as a so called 'process manager' but actually a malicious spyware related to APT? Well then, better stay alert and keep your guards up against any suspicious activities that might be going on your phone without your knowledge !
https://www.bleepingcomputer.com/news/security/newly-found-android-malware-records-audio-tracks-your-location/
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Newly found Android malware records audio, tracks your location
hey guys check out this news on a newly detected android malware that's tracking your activities down to the minute details and in real time? Apparently, it seems like this is guising as a so called 'process manager' but actually a malicious spyware related to APT? Well then, better stay alert and keep your guards up against any suspicious activities that might be going on your phone without your knowledge !
https://www.bleepingcomputer.com/news/security/newly-found-android-malware-records-audio-tracks-your-location/
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Newly found Android malware records audio, tracks your location
hey guys check out this news on a newly detected android malware that's tracking your activities down to the minute details and in real time?...
hacking: security in practice
Spring Cloud RCE Bugs massively cropping up?
you know i've recently heard news that some RCE bug associated with Javascript, so better beware of its potential impact regardless of its lowly scored CVSS? Well potentially it could have serious ramifications in the long haul so experts agree that its impact should not be underestimated! what do you think?
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Spring Cloud RCE Bugs massively cropping up?
you know i've recently heard news that some RCE bug associated with Javascript, so better beware of its potential impact regardless of its lowly scored CVSS? Well potentially it could have serious ramifications in the long haul so experts agree that its impact should not be underestimated! what do you think?
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Spring Cloud RCE Bugs massively cropping up?
you know i've recently heard news that some RCE bug associated with Javascript, so better beware of its potential impact regardless of its lowly...
hacking: security in practice
Is hacking getting easier or harder?
Literally everything I’ve learned on Udemy, YouTube and tryhackme (so far) is blocked by standard security features like cloud flare or windows defender.
They say that the demand for cyber security is going to increase by 33% in the next few years.
My professor said that ~93% of hacking is done by script kiddies. If standard script kiddy tools are blocked by default windows defender configurations, where is this increasing threat coming from? Nation state actors and the elite criminal organizations who have access to zero days?
submitted by /u/Practical_Bathroom53
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is hacking getting easier or harder?
Literally everything I’ve learned on Udemy, YouTube and tryhackme (so far) is blocked by standard security features like cloud flare or windows defender.
They say that the demand for cyber security is going to increase by 33% in the next few years.
My professor said that ~93% of hacking is done by script kiddies. If standard script kiddy tools are blocked by default windows defender configurations, where is this increasing threat coming from? Nation state actors and the elite criminal organizations who have access to zero days?
submitted by /u/Practical_Bathroom53
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is hacking getting easier or harder?
Literally everything I’ve learned on Udemy, YouTube and tryhackme (so far) is blocked by standard security features like cloud flare or windows...
hacking: security in practice
Uncommon/Unique malware evasion techniques?
I’m in the final stages of developing a Crypter at the moment. It’s sitting at 0/38 Scantime and 1/22 Runtime.
I have anti-VM features implemented which do standard checks on storage, ram, and CPU queries.
What other AV evasion techniques / anti debug features have you heard of?
The current list of features are as follows:
Polymorphic Encrypted Strings
Strings that would be constant within the stub are encrypted with a polymorphic encryption scheme so that the injected strings are different upon each build.
No decryption key in the “Stub”
The decryption key is not passed to the stub. Instead, a charset and length is passed along to be brute-forced at run. (Bypass some runtime AV; harder for reversing)
Randomized Code Blocks
Code Blocks / Subs&Functions are randomized in their placement when the assembly is crypted.
Legitimate Workstation Checks
At run, the program utilizes 3 check points to verify it is being run on a legitimate machine and not a virtualized environment.
Memory Execution
The crypted file is run directly in memory via a background thread.
Service Startup
The crypted file runs as a windows service until the injected bytes are run into memory.
Compression
The payload is compressed before being Injected into the stub, this sometimes provides outputs smaller than the stub+original payload.
Obfuscation
Using Mono.cecil, the assembly is lightly obfuscated using renaming techniques paired with invalid whitespace characters.
Only one static variable
Entire integer,string,array is dynamically changed each build with exception to one integer that is a divisor for bytes. A common number that would not be marked as malicious.
Small Stub
Only 12kb total size.
submitted by /u/MysticalTeamMember
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Uncommon/Unique malware evasion techniques?
I’m in the final stages of developing a Crypter at the moment. It’s sitting at 0/38 Scantime and 1/22 Runtime.
I have anti-VM features implemented which do standard checks on storage, ram, and CPU queries.
What other AV evasion techniques / anti debug features have you heard of?
The current list of features are as follows:
Polymorphic Encrypted Strings
Strings that would be constant within the stub are encrypted with a polymorphic encryption scheme so that the injected strings are different upon each build.
No decryption key in the “Stub”
The decryption key is not passed to the stub. Instead, a charset and length is passed along to be brute-forced at run. (Bypass some runtime AV; harder for reversing)
Randomized Code Blocks
Code Blocks / Subs&Functions are randomized in their placement when the assembly is crypted.
Legitimate Workstation Checks
At run, the program utilizes 3 check points to verify it is being run on a legitimate machine and not a virtualized environment.
Memory Execution
The crypted file is run directly in memory via a background thread.
Service Startup
The crypted file runs as a windows service until the injected bytes are run into memory.
Compression
The payload is compressed before being Injected into the stub, this sometimes provides outputs smaller than the stub+original payload.
Obfuscation
Using Mono.cecil, the assembly is lightly obfuscated using renaming techniques paired with invalid whitespace characters.
Only one static variable
Entire integer,string,array is dynamically changed each build with exception to one integer that is a divisor for bytes. A common number that would not be marked as malicious.
Small Stub
Only 12kb total size.
submitted by /u/MysticalTeamMember
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Uncommon/Unique malware evasion techniques?
I’m in the final stages of developing a Crypter at the moment. It’s sitting at 0/38 Scantime and 1/22 Runtime. I have anti-VM features...
Whatsapp does not require OTP
NOTE: This finding was declared as feature by Facebook team so i would like to share this new feature with everyone.Continue reading on Medium »
Read more...
NOTE: This finding was declared as feature by Facebook team so i would like to share this new feature with everyone.Continue reading on Medium »
Read more...
Whatsapp does not require OTP
https://sheshasai.medium.com/whatsapp-does-not-require-otp-794f94e0d62b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sheshasai.medium.com/whatsapp-does-not-require-otp-794f94e0d62b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Whatsapp does not require OTP
NOTE: This finding was declared as feature by Facebook team so i would like to share this new feature with everyone.
NOTE: This finding was declared as feature by Facebook team so i would like to share this new feature with everyone.Continue reading on Medium » (https://sheshasai.medium.com/whatsapp-does-not-require-otp-794f94e0d62b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Whatsapp does not require OTP
NOTE: This finding was declared as feature by Facebook team so i would like to share this new feature with everyone.
How I got my first HOF in United Nations | 0xshahriar
This is the story about getting my first Hall Of Fame. And I got it in United Nations. 🎉🎊Continue reading on Medium »
Read more...
This is the story about getting my first Hall Of Fame. And I got it in United Nations. 🎉🎊Continue reading on Medium »
Read more...
Moving from Web application to Mobile pentesting.
https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/
Hello, I've been moving from web app pentesting to mobile soon and have no clue what to do. Can you guys share any materials or tips? So far I've found the OWASP-MSTG. Somewhere I've read that I should use some proxies and wireshark and stuff but can't paint the large picture. Thanks! submitted by /u/tryingtoworkatm (https://www.reddit.com/user/tryingtoworkatm)
[link] (https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/
Hello, I've been moving from web app pentesting to mobile soon and have no clue what to do. Can you guys share any materials or tips? So far I've found the OWASP-MSTG. Somewhere I've read that I should use some proxies and wireshark and stuff but can't paint the large picture. Thanks! submitted by /u/tryingtoworkatm (https://www.reddit.com/user/tryingtoworkatm)
[link] (https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Moving from Web application to Mobile pentesting.
Hello, I've been moving from web app pentesting to mobile soon and have no clue what to do. Can you guys share any materials or tips? So far I've...
How I got my first HOF in United Nations | 0xshahriar
https://0xshahriar.medium.com/how-i-got-my-first-hof-in-united-nations-0xshahriar-381d3dff3a93?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xshahriar.medium.com/how-i-got-my-first-hof-in-united-nations-0xshahriar-381d3dff3a93?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I got my first HOF in United Nations | 0xshahriar
This is the story about getting my first Hall Of Fame. And I got it in United Nations. 🎉🎊