Recon tool for bug bounty
https://medium.com/@reconshell.com/recon-tool-for-bug-bounty-9dcb6b037f00?source=rss------bug_bounty-5
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.Continue reading on Medium » (https://medium.com/@reconshell.com/recon-tool-for-bug-bounty-9dcb6b037f00?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@reconshell.com/recon-tool-for-bug-bounty-9dcb6b037f00?source=rss------bug_bounty-5
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.Continue reading on Medium » (https://medium.com/@reconshell.com/recon-tool-for-bug-bounty-9dcb6b037f00?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Recon tool for bug bounty
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
The Original APT: Advanced Persistent Teenagers
https://external-preview.redd.it/mA_K_LcJO-spIcE-X0qYrWd2Z8VRMH3JlJANHeV1LWA.jpg?width=640&crop=smart&auto=webp&s=36709b53a86ec615ffff158a919b54642905bae0 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The Original APT: Advanced Persistent Teenagers
https://external-preview.redd.it/mA_K_LcJO-spIcE-X0qYrWd2Z8VRMH3JlJANHeV1LWA.jpg?width=640&crop=smart&auto=webp&s=36709b53a86ec615ffff158a919b54642905bae0 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Original APT: Advanced Persistent Teenagers
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 0 comments
hacking: security in practice
What is the Best Way to Achieve Anonymity Online?
What is a good way to achieve internet anonymity that isn't complicated for all types of users?
submitted by /u/Kind-Independence-67
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is the Best Way to Achieve Anonymity Online?
What is a good way to achieve internet anonymity that isn't complicated for all types of users?
submitted by /u/Kind-Independence-67
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is the Best Way to Achieve Anonymity Online?
What is a good way to achieve internet anonymity that isn't complicated for all types of users?
hacking: security in practice
Soo RFID,HID,NFC....WTF?
So I originally got my MSR year's ago with the heavy interest in brute forcing master hotel card. Alas they're more electronic than magnetic so I spent last few years just learning basic track data, discretionary, all that jazz (still a fucking headache and only understand 75% of it still). Anywho with other devices I'm seeing sich as the JASAG RFID R/W and shit it seems you don't need to dismantle a mp3 to enumerate hotel keys? I'm high and tired so just lmk if you feel like explaining some dark sorcery to me
submitted by /u/Sn0wbird187
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Soo RFID,HID,NFC....WTF?
So I originally got my MSR year's ago with the heavy interest in brute forcing master hotel card. Alas they're more electronic than magnetic so I spent last few years just learning basic track data, discretionary, all that jazz (still a fucking headache and only understand 75% of it still). Anywho with other devices I'm seeing sich as the JASAG RFID R/W and shit it seems you don't need to dismantle a mp3 to enumerate hotel keys? I'm high and tired so just lmk if you feel like explaining some dark sorcery to me
submitted by /u/Sn0wbird187
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Soo RFID,HID,NFC....WTF?
So I originally got my MSR year's ago with the heavy interest in brute forcing master hotel card. Alas they're more electronic than magnetic so I...
Recon tool for bug bounty
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.Continue reading on Medium »
Read more...
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.Continue reading on Medium »
Read more...
What constitutes "equivalent experience" for a B.S. when applying for a jr pentesting position?
https://www.reddit.com/r/Pentesting/comments/ty57sj/what_constitutes_equivalent_experience_for_a_bs/
submitted by /u/NotVeryMega (https://www.reddit.com/user/NotVeryMega)
[link] (https://www.reddit.com/r/cybersecurity/comments/ty4jsp/what_constitutes_equivalent_experience_for_a_bs/) [comments] (https://www.reddit.com/r/Pentesting/comments/ty57sj/what_constitutes_equivalent_experience_for_a_bs/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ty57sj/what_constitutes_equivalent_experience_for_a_bs/
submitted by /u/NotVeryMega (https://www.reddit.com/user/NotVeryMega)
[link] (https://www.reddit.com/r/cybersecurity/comments/ty4jsp/what_constitutes_equivalent_experience_for_a_bs/) [comments] (https://www.reddit.com/r/Pentesting/comments/ty57sj/what_constitutes_equivalent_experience_for_a_bs/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What constitutes "equivalent experience" for a B.S. when applying...
Posted in r/Pentesting by u/NotVeryMega • 2 points and 1 comment
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Ocr-Recon : Tool To Find A Particular String In A List Of URLs Using Tesseract’S OCR Capabilities
Ocr-Recon is useful to find a particular string in a list of URLs using tesseract’s OCR (Optical Character Recognition) capabilities.
Usage
Usage: python3 ocr-recon.py list with URLs string to search
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTqJwBuAavBCWdhl60vshS-IRNj4yW4iMhftJjduPO-oqFN8NAZQ49CNQkaIEfeWmeZNjyBEfmdfslqfb_0gC5aBHpKGeHg9LX8hlIXAK_rzSw1nMwqklMaVaNNZAMyrcno8POTAQJ_WYO5gxAT3KNIuT97_r5gOcMLbsgVShfZX9XiwVWDeRHkpJB/s716/68747470733a2f2f692e706f7374696d672e63632f5243526b3036316a2f6f63727265636f6e2e706e67.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Ocr-Recon : Tool To Find A Particular String In A List Of URLs Using Tesseract’S OCR Capabilities
Ocr-Recon is useful to find a particular string in a list of URLs using tesseract’s OCR (Optical Character Recognition) capabilities.
Usage
Usage: python3 ocr-recon.py list with URLs string to search
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTqJwBuAavBCWdhl60vshS-IRNj4yW4iMhftJjduPO-oqFN8NAZQ49CNQkaIEfeWmeZNjyBEfmdfslqfb_0gC5aBHpKGeHg9LX8hlIXAK_rzSw1nMwqklMaVaNNZAMyrcno8POTAQJ_WYO5gxAT3KNIuT97_r5gOcMLbsgVShfZX9XiwVWDeRHkpJB/s716/68747470733a2f2f692e706f7374696d672e63632f5243526b3036316a2f6f63727265636f6e2e706e67.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Ocr-Recon : Tool To Find A Particular String In A List Of URLs
Ocr-Recon is useful to find a particular string in a list of URLs using tesseract's OCR (Optical Character Recognition) capabilities.
Kali Linux Tutorials
Chaya : Advance Image Steganography
___________________________
@hacking_Attack
@Hacking_Video
Chaya : Advance Image Steganography
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Chaya : Advance Image Steganography !!! Kali Linux
Chaya protects your privacy through steganography, cryptography and compression. It effectively encrypts your payloads using AES-256-GCM.
Hacking on Medium
Recon tool for bug bounty
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Recon tool for bug bounty
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Recon tool for bug bounty
Layla is a python script that automatically performs recon on a given URL. It combines the outputs of other known tools into a single one.
Hacking on Medium
VR For Flat Unreal Engine Games #0: Intro
https://cdn-images-1.medium.com/max/1920/1*TC8t-tVqW5fYkV69xUYwTg.png
A small VR mod for the game Ghostrunner has turned into a much larger project, with support for many Unreal Engine 4 games!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
VR For Flat Unreal Engine Games #0: Intro
https://cdn-images-1.medium.com/max/1920/1*TC8t-tVqW5fYkV69xUYwTg.png
A small VR mod for the game Ghostrunner has turned into a much larger project, with support for many Unreal Engine 4 games!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
VR For Flat Unreal Engine Games #0: Intro
A small VR mod for the game Ghostrunner has turned into a much larger project, with support for many Unreal Engine 4 games!
Hacking on Medium
7 Most Useful Apps — April 2022
https://cdn-images-1.medium.com/max/600/0*aAnCxPwKm8eA8sUm.gif
Another day, another month, another new way to look for cool apps. Some of these apps provide and can add value to your life, changing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
7 Most Useful Apps — April 2022
https://cdn-images-1.medium.com/max/600/0*aAnCxPwKm8eA8sUm.gif
Another day, another month, another new way to look for cool apps. Some of these apps provide and can add value to your life, changing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
7 Most Useful Apps — April 2022
Another day, another month, another new way to look for cool apps. Some of these apps provide and can add value to your life, changing…
hacking: security in practice
Advice
I’m a senior in high school and wanting to have a career in the cybersecurity field. My plan is two years community college to get preliminary things out of the way. I’m then going to bridge to a different university where I’m going to finish my studies and get my bachelors. Any tips on things I can do to prepare myself for this career path I’m going down? Thanks
submitted by /u/SpicyLikeTakis
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Advice
I’m a senior in high school and wanting to have a career in the cybersecurity field. My plan is two years community college to get preliminary things out of the way. I’m then going to bridge to a different university where I’m going to finish my studies and get my bachelors. Any tips on things I can do to prepare myself for this career path I’m going down? Thanks
submitted by /u/SpicyLikeTakis
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Advice
I’m a senior in high school and wanting to have a career in the cybersecurity field. My plan is two years community college to get preliminary...
hacking: security in practice
Mac spoofing?
Surely, mac spoofing isn't the only thing that saves you from being located when hacking? Is there more ways to cover tracks?
Trying to creat a lab, so I can start pentesting and maybe trying my hand at bug bounties, but I want to be invisible first. DMs are welcome but please no links 😊.
Sure vpn can change location, but not fail proof and not safe regardless.
submitted by /u/IAmCrossLed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Mac spoofing?
Surely, mac spoofing isn't the only thing that saves you from being located when hacking? Is there more ways to cover tracks?
Trying to creat a lab, so I can start pentesting and maybe trying my hand at bug bounties, but I want to be invisible first. DMs are welcome but please no links 😊.
Sure vpn can change location, but not fail proof and not safe regardless.
submitted by /u/IAmCrossLed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Mac spoofing?
Surely, mac spoofing isn't the only thing that saves you from being located when hacking? Is there more ways to cover tracks? Trying to creat a...
hacking: security in practice
Mastering CTFs as an intermediate.
I've been doing CTFs for a while now but i always run into a speed bump. The said speed bump is mostly a concept(like a service) that I've never studied and plus if I were to study it, it would take a long while to understand a concept deep enough to find loopholes. So what is the easiest way to counteract and penetrate new services? Or what should I be reading before I really get into CTFs
submitted by /u/h4cks1n
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Mastering CTFs as an intermediate.
I've been doing CTFs for a while now but i always run into a speed bump. The said speed bump is mostly a concept(like a service) that I've never studied and plus if I were to study it, it would take a long while to understand a concept deep enough to find loopholes. So what is the easiest way to counteract and penetrate new services? Or what should I be reading before I really get into CTFs
submitted by /u/h4cks1n
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Mastering CTFs as an intermediate.
I've been doing CTFs for a while now but i always run into a speed bump. The said speed bump is mostly a concept(like a service) that I've never...
hacking: security in practice
Newly updated VMware patches for critical vulnerabilities. CVE-2022-22954 ~ CVE-2022-22961
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Newly updated VMware patches for critical vulnerabilities. CVE-2022-22954 ~ CVE-2022-22961
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Newly updated VMware patches for critical vulnerabilities....
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
hacking: security in practice
project ideas
I've been doing hackthebox and tryhackme but I'm getting tired of it. Any ideas on what i should do?
submitted by /u/void02241
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
project ideas
I've been doing hackthebox and tryhackme but I'm getting tired of it. Any ideas on what i should do?
submitted by /u/void02241
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
project ideas
I've been doing hackthebox and tryhackme but I'm getting tired of it. Any ideas on what i should do?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
VMware warns of critical vulnerabilities in multiple products
VMware warns of critical vulnerabilities in multiple productsPost Views: 27
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
VMware has warned customers to immediately patch critical vulnerabilities in multiple products that threat actors could use to launch remote code execution attacks.
“This critical vulnerability should be patched or mitigated immediately per the instructions in VMSA-2021-0011. The ramifications of this vulnerability are serious,” VMware warned on Wednesday.
“All environments are different, have different tolerance for risk, and have different security controls and defense-in-depth to mitigate risk, so customers must make their own decisions on how to proceed. However, given the severity of the vulnerability, we strongly recommend immediate action.” Patches for five critical vulnerabilitiesThe list of critical security flaws patched today includes a server-side template injection remote code execution vulnerability (CVE-2022-22954), two OAuth2 ACS authentication bypass vulnerabilities (CVE-2022-22955, CVE-2022-22956), and two JDBC injection remote code execution vulnerabilities (CVE-2022-22957, CVE-2022-22958).
VMware also patched high and medium severity bugs that could be exploited for Cross-Site Request Forgery (CSRF) attacks (CVE-2022-22959), escalate privileges (CVE-2022-22960), and gain access to information without authorization (CVE-2022-22961).
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
The complete list of VMware products impacted by these security vulnerabilities includes:
* VMware Workspace ONE Access (Access)
* VMware Identity Manager (vIDM)
* VMware vRealize Automation (vRA)
* VMware Cloud Foundation
* vRealize Suite Lifecycle Manager
The company added that it found no evidence of these bugs being exploited in the wild before today’s security advisory was published. VMware’s knowledgebase website also has a complete list of fixed versions and download links to hotfix installers.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Workaround also availableVMware also provides workarounds for those who cannot immediately patch their appliances as a temporary solution. The steps detailed here require admins to run a VMware-provided Python-based script on affected virtual appliances.
However, the company says that the only way to remove the vulnerabilities entirely is to apply the patches.
“Workarounds, while convenient, do not remove the vulnerabilities, and may introduce additional complexities that patching would not,” VMware added.
“While the decision to patch or use the workaround is yours, VMware always strongly recommends patching as the simplest and most reliable way to resolve this issue.”
A document with additional questions and answers regarding the critical vulnerabilities patched today is available here.
On Monday, VMware also released security updates to address the critical Spring4Shell RCE flaw in VMware Tanzu Application Service for VMs, VMware Tanzu Operations Manager, and VMware Tanzu Kubernetes Grid Integrated Edition (TKGI). See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact[...]
___________________________
@hacking_Attack
@Hacking_Video
VMware warns of critical vulnerabilities in multiple products
VMware warns of critical vulnerabilities in multiple productsPost Views: 27
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
VMware has warned customers to immediately patch critical vulnerabilities in multiple products that threat actors could use to launch remote code execution attacks.
“This critical vulnerability should be patched or mitigated immediately per the instructions in VMSA-2021-0011. The ramifications of this vulnerability are serious,” VMware warned on Wednesday.
“All environments are different, have different tolerance for risk, and have different security controls and defense-in-depth to mitigate risk, so customers must make their own decisions on how to proceed. However, given the severity of the vulnerability, we strongly recommend immediate action.” Patches for five critical vulnerabilitiesThe list of critical security flaws patched today includes a server-side template injection remote code execution vulnerability (CVE-2022-22954), two OAuth2 ACS authentication bypass vulnerabilities (CVE-2022-22955, CVE-2022-22956), and two JDBC injection remote code execution vulnerabilities (CVE-2022-22957, CVE-2022-22958).
VMware also patched high and medium severity bugs that could be exploited for Cross-Site Request Forgery (CSRF) attacks (CVE-2022-22959), escalate privileges (CVE-2022-22960), and gain access to information without authorization (CVE-2022-22961).
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
The complete list of VMware products impacted by these security vulnerabilities includes:
* VMware Workspace ONE Access (Access)
* VMware Identity Manager (vIDM)
* VMware vRealize Automation (vRA)
* VMware Cloud Foundation
* vRealize Suite Lifecycle Manager
The company added that it found no evidence of these bugs being exploited in the wild before today’s security advisory was published. VMware’s knowledgebase website also has a complete list of fixed versions and download links to hotfix installers.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Workaround also availableVMware also provides workarounds for those who cannot immediately patch their appliances as a temporary solution. The steps detailed here require admins to run a VMware-provided Python-based script on affected virtual appliances.
However, the company says that the only way to remove the vulnerabilities entirely is to apply the patches.
“Workarounds, while convenient, do not remove the vulnerabilities, and may introduce additional complexities that patching would not,” VMware added.
“While the decision to patch or use the workaround is yours, VMware always strongly recommends patching as the simplest and most reliable way to resolve this issue.”
A document with additional questions and answers regarding the critical vulnerabilities patched today is available here.
On Monday, VMware also released security updates to address the critical Spring4Shell RCE flaw in VMware Tanzu Application Service for VMs, VMware Tanzu Operations Manager, and VMware Tanzu Kubernetes Grid Integrated Edition (TKGI). See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact[...]
___________________________
@hacking_Attack
@Hacking_Video