Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Bypassing the Job

**The title is the best thing i could of thought of Sorry**

But when doing ethical hacking for a company and you have to find that vulnerability, right? and you get payed for trying to find vulnerabilitys not actually finding them. What if you never started looking there would be no proof you were looking.

I can re-explain it if needed

submitted by /u/VSTryMe
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Someone has been ddosing me

So long story short about a week ago I checked cloudflare and it had a unusually large amount or requests, so I just turned on the highest security setting. most of the requests were coming from japan, over the last few days there was some from different countries. Also because one of my dns records exposed my ip they're trying to ssh into my server, so stop them I installed fail2ban, and its working wonders 1.2k banned ips and 5k failed attempts. But one thing I love is they haven't affected anything on my server, my performance is perfectly fine, I also love seeing them waste resources, bandwidth, time, power and effort on this attack.

submitted by /u/bagette4224
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
How to find a job in cybersecurity?
https://www.reddit.com/r/Pentesting/comments/u661d5/how_to_find_a_job_in_cybersecurity/

<!-- SC_OFF -->I would like to work in cybersecurity, but I don't have any experience, and in my country there is not a cybersecurity culture, so I thought about working remotely in another country, and eventually go to the country. I have done a couple of hacking courses, and I have a not well know hacking certification (G.H.O.S.T.). I speak Spanish natively, and have a good level of English. Would you give me some advices to get a job in this field? <!-- SC_ON --> submitted by /u/mrxaander (https://www.reddit.com/user/mrxaander)
[link] (https://www.reddit.com/r/Pentesting/comments/u661d5/how_to_find_a_job_in_cybersecurity/) [comments] (https://www.reddit.com/r/Pentesting/comments/u661d5/how_to_find_a_job_in_cybersecurity/)
Hello Everyone! In this article I tell you how to hack and crack wifi password using aircrack-ng which is a terminal based tool.Continue reading on Medium » (https://hyper0z.medium.com/hack-wi-fi-using-aircrack-ng-30d40610eaac?source=rss------bug_bounty-5)
Hack Wi-Fi Using Aircrack-ng

Hello Everyone! In this article I tell you how to hack and crack wifi password using aircrack-ng which is a terminal based tool.Continue reading on Medium »
Read more...
Hacking the University in a Few Steps

Escalating a Wrong Date to Get Code ExecutionContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco vulnerability lets hackers craft their own login credentials

Cisco vulnerability lets hackers craft their own login credentialsPost Views: 110
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
The Cisco security flaw allows remote attackers to log in to target devices through the management interface without using a valid password.
Cisco has released a security advisory to warn about a critical vulnerability (CVSS v3 score: 10.0), tracked as CVE-2022-20695, impacting the Wireless LAN Controller (WLC) software.

The bug involves the improper implementation of the password validation algorithm, making it possible to bypass the standard authentication procedure on non-default device configurations.

If this prerequisite is present, the attacker may use crafted credentials to gain varying levels of privilege, potentially going all the way up to an administrative user.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Impact and remediationAccording to Cisco’s advisory, the products affected by this flaw are those that run Cisco WLC Software 8.10.151.0 or Release 8.10.162.0 and have “macfilter radius compatibility” configured as “Other.”

The affected products are:

* 3504 Wireless Controller
* 5520 Wireless Controller
* 8540 Wireless Controller
* Mobility Express
* Virtual Wireless Controller (vWLC)

In addition to the above, some customers using the following builds not available through the Software Center should also consider themselves vulnerable: 8.10.151.4 to 8.10.151.10 and 8.10.162.1 to 8.10.162.14.

Finally, Cisco has confirmed the following as not vulnerable to CVE-2022-20695:

* Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
* Catalyst 9800 Series Wireless Controllers
* Catalyst 9800 Wireless Controller for Cloud
* Embedded Wireless Controller on Catalyst Access Points
* Wireless LAN Controller (WLC) AireOS products not listed in the Vulnerable Products section

To determine if your configuration is vulnerable, issue the “show macfilter summary” command. If the RADIUS compatibility mode returns “Other,” you’re vulnerable to attacks.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/check.jpg
<figcaptionCommand to determine configuration vulnerability
(Cisco)
Applying the latest available security updates (8.10.171.0 or later) released by Cisco addresses this vulnerability no matter what configuration you’re using.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Possible workaroundsCisco has provided two possible workarounds for those who can’t update the Wireless LAN Controller.

The first option is to reset the “macfilter radius compatibility” mode to the default value by issuing the following command: “config macfilter radius-compat cisco”.

The second option would be to change the configuration to other safe modes, such as “free”, using this command: “config macfilter radius-compat free”.

At the time of writing this, Cisco is not aware of the vulnerability being under active exploitation, and Bleeping Computer has seen no reports about scanning attempts either.
See Also: Recon Tool: Smap Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your id[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Cisco vulnerability lets hackers craft their own login credentials Cisco vulnerability lets hackers craft their own login credentialsPost Views: 110 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png…
ea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Hacking is an art, and so is subdomain enumeration. Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/windows-patch-update-90x90.jpg Microsoft Zero-Days, Wormable Bugs Spark Concern3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-2-90x90.jpg Git security vulnerabilities prompt updates4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Amazon-EC2-90x90.jpg Internal AWS credentials swiped by researcher via SQL payload5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/spring4shell-90x90.jpg Attackers are abusing Spring4Shell vulnerability to spread Mirai botnet malware6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-1-90x90.jpg Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/f956-article-211015-apple-body-text-90x90.jpg Apple paid out $36,000 bug bounty for HTTP request smuggling flaws1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/3e41-article-210226-vmware-body-text-90x90.jpg VMware warns of critical vulnerabilities in multiple products2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/A-New-Borat-RAT-Capable-Of-Conducting-Ransomware-DDOS-Activities-90x90.png No-Joke Borat RAT Propagates Ransomware, DDoS2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-pear-hacked-packages-malware-90x90.png Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-hack-90x90.jpg PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers2 weeks ago
The post Cisco vulnerability lets hackers craft their own login credentials first appeared on Black Hat Ethical Hacking.