Hacking on Medium
Hackers breached Mailchimp to target crypto holders
https://cdn-images-1.medium.com/max/1200/1*den7bnD03WfJEZMe13fZXA.jpeg
Hackers used internal tools from Mailchimp to target customers from a total of 102 users, including hardware cryptocurrency wallet Trezor…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers breached Mailchimp to target crypto holders
https://cdn-images-1.medium.com/max/1200/1*den7bnD03WfJEZMe13fZXA.jpeg
Hackers used internal tools from Mailchimp to target customers from a total of 102 users, including hardware cryptocurrency wallet Trezor…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers breached Mailchimp to target crypto holders
Hackers used internal tools from Mailchimp to target customers from a total of 102 users, including hardware cryptocurrency wallet Trezor…
Hacking on Medium
How to register and publish a Common Vulnerabilities and Exposures (CVE)
https://cdn-images-1.medium.com/max/800/0*ghgOz7VmqihCN41I.jpeg
Hello Hackers, I’m MrEmpy, I’m 17 years old. Welcome to my article teaching how I created a CVE.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to register and publish a Common Vulnerabilities and Exposures (CVE)
https://cdn-images-1.medium.com/max/800/0*ghgOz7VmqihCN41I.jpeg
Hello Hackers, I’m MrEmpy, I’m 17 years old. Welcome to my article teaching how I created a CVE.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to register and publish a Common Vulnerabilities and Exposures (CVE)
Hello Hackers, I’m MrEmpy, I’m 17 years old. Welcome to my article teaching how I created a CVE.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A case study whitepaper of the shadow-utils chfn, chsh, and userdel bug
https://external-preview.redd.it/vuMlHp0AIsM_Ca5d7vo9xv7CzlxBfjHfNLncYNLbIrE.jpg?width=108&crop=smart&auto=webp&s=6baff6d5e808b9f6457c5c69616c1ba69c610f22 submitted by /u/oxagast
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A case study whitepaper of the shadow-utils chfn, chsh, and userdel bug
https://external-preview.redd.it/vuMlHp0AIsM_Ca5d7vo9xv7CzlxBfjHfNLncYNLbIrE.jpg?width=108&crop=smart&auto=webp&s=6baff6d5e808b9f6457c5c69616c1ba69c610f22 submitted by /u/oxagast
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A case study whitepaper of the shadow-utils chfn, chsh, and...
Posted in r/hacking by u/oxagast • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
GitLab Releases Patch for Critical Vulnerability That Could Let Attackers Hijack Accounts. Tracked as CVE-2022-1162, the issue has a CVSS score of 9.1 and is said to have been discovered internally by the GitLab team.
https://external-preview.redd.it/INdOJDHrN0CrteOz7opOUM9lQei1KUbmWFrlbThk3mk.jpg?width=640&crop=smart&auto=webp&s=28ce0312fdf2542f3add4f82642d3e977db83dac submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
GitLab Releases Patch for Critical Vulnerability That Could Let Attackers Hijack Accounts. Tracked as CVE-2022-1162, the issue has a CVSS score of 9.1 and is said to have been discovered internally by the GitLab team.
https://external-preview.redd.it/INdOJDHrN0CrteOz7opOUM9lQei1KUbmWFrlbThk3mk.jpg?width=640&crop=smart&auto=webp&s=28ce0312fdf2542f3add4f82642d3e977db83dac submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
GitLab Releases Patch for Critical Vulnerability That Could Let...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
VMware has published security updates for the critical remote code execution vulnerability known as Spring4Shell, which impacts several of its cloud computing and virtualization products.
https://external-preview.redd.it/-ru7XtDLTFS68KeQydk4TBmngjUkPakPCNsC7cHBtCE.jpg?width=640&crop=smart&auto=webp&s=ddfbac0f4179196f78d58e64e7d7321040218535 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
VMware has published security updates for the critical remote code execution vulnerability known as Spring4Shell, which impacts several of its cloud computing and virtualization products.
https://external-preview.redd.it/-ru7XtDLTFS68KeQydk4TBmngjUkPakPCNsC7cHBtCE.jpg?width=640&crop=smart&auto=webp&s=ddfbac0f4179196f78d58e64e7d7321040218535 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
VMware has published security updates for the critical remote code...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
What are the best pen testing tools used for Microsoft 365?
https://www.reddit.com/r/Pentesting/comments/twmtyi/what_are_the_best_pen_testing_tools_used_for/
My company just bought a Microsoft 365 that hosts emails, communications, and documents for the whole company. Now our partner asked us to provide a pentest document to prove that our system is secured and pen-tested on yearly basis. I know that Azure won't or strictly allow a 3rd party to pentest their cloud environment (https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement). So I don't know if I can provide the MSFT's pentest document or if there is any 3rd party service that can provide the service. Thanks for advice submitted by /u/hvhung (https://www.reddit.com/user/hvhung)
[link] (https://www.reddit.com/r/Pentesting/comments/twmtyi/what_are_the_best_pen_testing_tools_used_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/twmtyi/what_are_the_best_pen_testing_tools_used_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/twmtyi/what_are_the_best_pen_testing_tools_used_for/
My company just bought a Microsoft 365 that hosts emails, communications, and documents for the whole company. Now our partner asked us to provide a pentest document to prove that our system is secured and pen-tested on yearly basis. I know that Azure won't or strictly allow a 3rd party to pentest their cloud environment (https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement). So I don't know if I can provide the MSFT's pentest document or if there is any 3rd party service that can provide the service. Thanks for advice submitted by /u/hvhung (https://www.reddit.com/user/hvhung)
[link] (https://www.reddit.com/r/Pentesting/comments/twmtyi/what_are_the_best_pen_testing_tools_used_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/twmtyi/what_are_the_best_pen_testing_tools_used_for/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What are the best pen testing tools used for Microsoft 365?
My company just bought a Microsoft 365 that hosts emails, communications, and documents for the whole company. Now our partner asked us to provide...
Spoof as another Facebook user to report an impostor account
When I was helping someone take down a poser/impostor account. I tried to check the request body on what’s going on behind the scene. The…Continue reading on Medium »
Read more...
When I was helping someone take down a poser/impostor account. I tried to check the request body on what’s going on behind the scene. The…Continue reading on Medium »
Read more...
Hacking on Medium
An Interesting Rate Limit Bypass..
I want to share a simple vulnerability that I find most of the time when I do bug bounty.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
An Interesting Rate Limit Bypass..
I want to share a simple vulnerability that I find most of the time when I do bug bounty.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
An Interesting Rate Limit Bypass..
I want to share a simple vulnerability that I find most of the time when I do bug bounty.
Hacking on Medium
How to protect from Spring4Shell
What is Spring4Shell?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to protect from Spring4Shell
What is Spring4Shell?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to protect from Spring4Shell
What is Spring4Shell?
Hacking on Medium
Authentication Bypass using OTP
https://cdn-images-1.medium.com/max/852/1*oU6m2MBRk81kEqS5ITohZQ.png
What is Authentication Bypass: Authentication Bypass is a dangerous vulnerability that is found in Web-Applications. Attackers can bypass…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Authentication Bypass using OTP
https://cdn-images-1.medium.com/max/852/1*oU6m2MBRk81kEqS5ITohZQ.png
What is Authentication Bypass: Authentication Bypass is a dangerous vulnerability that is found in Web-Applications. Attackers can bypass…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Authentication Bypass using OTP
What is Authentication Bypass: Authentication Bypass is a dangerous vulnerability that is found in Web-Applications. Attackers can bypass…
Spoof as another Facebook user to report an impostor account
https://zerocode-ph.medium.com/spoof-as-another-facebook-user-to-report-an-impostor-account-f2dd6683744d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://zerocode-ph.medium.com/spoof-as-another-facebook-user-to-report-an-impostor-account-f2dd6683744d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Spoof as another Facebook user to report an impostor account
When I was helping someone take down a poser/impostor account. I tried to check the request body on what’s going on behind the scene. The…
When I was helping someone take down a poser/impostor account. I tried to check the request body on what’s going on behind the scene. The…Continue reading on Medium » (https://zerocode-ph.medium.com/spoof-as-another-facebook-user-to-report-an-impostor-account-f2dd6683744d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Spoof as another Facebook user to report an impostor account
When I was helping someone take down a poser/impostor account. I tried to check the request body on what’s going on behind the scene. The…
hacking: security in practice
open source intelligence tools?
hey i've been a regular user of open soure intelligence tools like shodan , bu it is kind of a hassle when i'd have to head over to other search engines like this because sometimes I can't the exact information i'm looking for. Besides, it would have been much better if shodan was more noob user friendly to guide me through the process? I'm mainly using this for handling incidents but this seems sometimes useless for post incident response and time consuming for me so i'd appreciate if you could throw me some other alternatives(preferably more cost-effective as well) to try out? I'd like to try out a few before I settle on using one as my go-to
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
open source intelligence tools?
hey i've been a regular user of open soure intelligence tools like shodan , bu it is kind of a hassle when i'd have to head over to other search engines like this because sometimes I can't the exact information i'm looking for. Besides, it would have been much better if shodan was more noob user friendly to guide me through the process? I'm mainly using this for handling incidents but this seems sometimes useless for post incident response and time consuming for me so i'd appreciate if you could throw me some other alternatives(preferably more cost-effective as well) to try out? I'd like to try out a few before I settle on using one as my go-to
submitted by /u/alicia30765
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
open source intelligence tools?
hey i've been a regular user of open soure intelligence tools like shodan , bu it is kind of a hassle when i'd have to head over to other search...
CVE-2022–21907
CVE-2022–21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit…Continue reading on Medium »
Read more...
CVE-2022–21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit…Continue reading on Medium »
Read more...
CVE-2022–21907
https://medium.com/@reconshell.com/cve-2022-21907-a119562dc97a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@reconshell.com/cve-2022-21907-a119562dc97a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–21907
CVE-2022–21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit…
CVE-2022–21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit…Continue reading on Medium » (https://medium.com/@reconshell.com/cve-2022-21907-a119562dc97a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–21907
CVE-2022–21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit…