Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Scan for publicly accessible assets on your AWS environment Services covered by this tool: AWS ELB API Gateway S3 Buckets RDS Databases EC2 instances Redshift Databases Poro also check if a tag you specify is applied to identified public resources using --tag-key and --tag-value arguments.
Prequisites AWS account with Read Only Access (https://www.kitploit.com/search/label/Access) to services listed above. Python 3.X requests>=2.22.0 boto3>=1.20 botocore>= 1.20 enlighten>=1 Usage Clone this repository Configure your envionment with active (https://www.kitploit.com/search/label/Active) credentials (https://www.kitploit.com/search/label/Credentials) -> aws configure [sso] Run python poro.py [-h] [--profile PROFILE] [--export FILE_NAME] [--verbose] [--tag-key KEY] [--tag-value VALUE] optional arguments:
-h, --help show this help message and exit
--profile PROFILE Specify the aws profile (default is default)
--export FILE_NAME Specify the file name if you want to expport the results
--verbose, -v
--tag-key KEY Specify the tag key that you want to check if it exists in public resources
--tag-value VALUE Specify the tag value that you want to check if it exists in public resources
Poro prints the scanning (https://www.kitploit.com/search/label/Scanning) results at the end of it's execution in a json (https://www.kitploit.com/search/label/JSON) file if no export option is not specified.

Download Poro (https://github.com/9rnt/poro)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Poro - Scan Publicly Accessible Assets On Your AWS Cloud Environment

https://blogger.googleusercontent.com/img/a/AVvXsEhICJTE3qcIeVC78Oe_kAjSo3d4-Rw_rQSSXOmmNQzYniYax0jkLSYZkj5Zvssc30zvT-Y7cdzDNLTzcQ44jSQCdwRJmiTWriQazKgJRHufW_HqaXyp8ztMV2znsJYzBbjXbEW-TCjsKUHjIbwRTvZ9FQoQyjfFFuEqIYiGtvY5iqAOtN1TX0ik0Lv0=w222-h400
Scan for publicly accessible assets on your AWS environment

Services covered by this tool:

* AWS ELB
* API Gateway
* S3 Buckets
* RDS Databases
* EC2 instances
* Redshift Databases

Poro also check if a tag you specify is applied to identified public resources using --tag-key and --tag-value arguments.
Prequisites

* AWS account with Read Only Access to services listed above.
* Python 3.X
* requests>=2.22.0
* boto3>=1.20
* botocore>= 1.20
* enlighten>=1

Usage

*
Clone this repository

*
Configure your envionment with active credentials -> aws configure [sso]

*
Run python poro.py [-h] [--profile PROFILE] [--export FILE_NAME] [--verbose] [--tag-key KEY] [--tag-value VALUE]

optional arguments:
-h, --help show this help message and exit
--profile PROFILE Specify the aws profile (default is default)
--export FILE_NAME Specify the file name if you want to expport the results
--verbose, -v
--tag-key KEY Specify the tag key that you want to check if it exists in public resources
--tag-value VALUE Specify the tag value that you want to check if it exists in public resources

Poro prints the scanning results at the end of it's execution in a json file if no export option is not specified.
Download Poro
hacking: security in practice
Hacking myself

Hello r/hacking, this is an absolute long shot and a strange request to make, but here goes anyway.

I was locked out of my old instagram account a few years ago and would like to access it again, however, I never had a Facebook, gave a fake email, and the number I had at the time is gone. Would anyone be capable of hacking my account? The password is not an apple generated one as it’s not in my iCloud Keychain and I’m pretty confident it’s mostly non numerical, there is a lot of memories in that account for me and I’d love to be able to access them. Dm or comment if you’re up for the challenge

submitted by /u/pcorv
[link] [comments]
hacking: security in practice
Cookie Catcher

is there a tool to catch cookies and transfer to another browser so you could bypass password requirements?

Is there a way to use Burp Suit for this?

submitted by /u/KurzgesagtPrivate
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Small Group

Hello! Im currently in a small group looking for people to join!

We are not master haxors and its just a fun small group to hangout in share knowledge and help eachother grow

We are going to be using guided (a alternative to discord) for non private messages and matrix for private messages If you would like to apply sign up to join check the comments for the link!

https://guilded.gg/Hacking

submitted by /u/YAROBONZ-
[link] [comments]
Running Decentralized, and Community Oriented Bug Bounties

Bug bounties are not a new thing, but web 3 has challenged security trends, expanding project’s needs, and creating a deep desire for…Continue reading on Medium »
Read more...
Bug bounties are not a new thing, but web 3 has challenged security trends, expanding project’s needs, and creating a deep desire for…Continue reading on Medium » (https://hatsfinance.medium.com/running-decentralized-and-community-oriented-bug-bounties-70605d769bbe?source=rss------bug_bounty-5)
I have been hosting a challenge for my readers with a reward of $20. No one has claimed it yet, the prize is still up for grabs.Continue reading on Medium » (https://ethr.medium.com/theres-20-up-for-grabs-in-this-post-aff4873a82fd?source=rss------bug_bounty-5)
There’s $20 up for grabs in this post

I have been hosting a challenge for my readers with a reward of $20. No one has claimed it yet, the prize is still up for grabs.Continue reading on Medium »
Read more...