Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
¡Cuidado! Mineros de criptomonedas dirigidos a Dockers, AWS y Alibaba Cloud
https://cdn-images-1.medium.com/max/1554/0*pVrgdEmhOnOybkPY
PUBLICADO EN 25 ABRIL, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
¡Cuidado! Mineros de criptomonedas dirigidos a Dockers, AWS y Alibaba Cloud
https://cdn-images-1.medium.com/max/1554/0*pVrgdEmhOnOybkPY
PUBLICADO EN 25 ABRIL, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
¡Cuidado! Mineros de criptomonedas dirigidos a Dockers, AWS y Alibaba Cloud
PUBLICADO EN 25 ABRIL, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Future of Cyber Warfare:
https://cdn-images-1.medium.com/max/768/1*LBT0yndB9Ke3HWSk5Xa4Lg.jpeg
September 11, 2001 terror strikes set a new tone for warfare in the 21st century but it seems that there is a rise of a new kind of…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Future of Cyber Warfare:
https://cdn-images-1.medium.com/max/768/1*LBT0yndB9Ke3HWSk5Xa4Lg.jpeg
September 11, 2001 terror strikes set a new tone for warfare in the 21st century but it seems that there is a rise of a new kind of…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Future of Cyber Warfare:
September 11, 2001 terror strikes set a new tone for warfare in the 21st century but it seems that there is a rise of a new kind of warfare…
What you doing wrong when you fail at bug bounties?
Hi all, I hope all is well. I have 3+ years bug bounty experience so I want to talk about the common mistakes when doing bug bounty…Continue reading on Medium »
Read more...
Hi all, I hope all is well. I have 3+ years bug bounty experience so I want to talk about the common mistakes when doing bug bounty…Continue reading on Medium »
Read more...
What you doing wrong when you fail at bug bounties?
https://medium.com/@gguzelkokar.mdbf15/what-you-doing-wrong-when-you-fail-at-bug-bounties-143d2e0e6e2b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@gguzelkokar.mdbf15/what-you-doing-wrong-when-you-fail-at-bug-bounties-143d2e0e6e2b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
What you doing wrong when you fail at bug bounties?
Hi all, I hope all is well. I have 3+ years bug bounty experience so I want to talk about the common mistakes when doing bug bounty…
Hi all, I hope all is well. I have 3+ years bug bounty experience so I want to talk about the common mistakes when doing bug bounty…Continue reading on Medium » (https://medium.com/@gguzelkokar.mdbf15/what-you-doing-wrong-when-you-fail-at-bug-bounties-143d2e0e6e2b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
What you doing wrong when you fail at bug bounties?
Hi all, I hope all is well. I have 3+ years bug bounty experience so I want to talk about the common mistakes when doing bug bounty…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Mastercard Launches Next-Generation Identity Technology with Microsoft
New 'trust' tool improves online experience and helps tackle digital fraud.
___________________________
@hacking_Attack
@Hacking_Video
Mastercard Launches Next-Generation Identity Technology with Microsoft
New 'trust' tool improves online experience and helps tackle digital fraud.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Mastercard Launches Next-Generation Identity Technology with Microsoft
New 'trust' tool improves online experience and helps tackle digital fraud.
hacking: security in practice
Tool that search for nearby ipcams and give u links to their stream website
Would that be possible? It can be done with shodan and some filters but can it be automated into an app?
submitted by /u/Clichedfoil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tool that search for nearby ipcams and give u links to their stream website
Would that be possible? It can be done with shodan and some filters but can it be automated into an app?
submitted by /u/Clichedfoil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Tool that search for nearby ipcams and give u links to their...
Would that be possible? It can be done with shodan and some filters but can it be automated into an app?
hacking: security in practice
Resources/Advices to transition into Network Security
Title says it all. I am a experienced Web Security Engineer and now o want to transition into Network Security and learn it. Can you guys give me advice on how to approach this filed and anything I need to keep in mind
submitted by /u/CoolNCocky
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Resources/Advices to transition into Network Security
Title says it all. I am a experienced Web Security Engineer and now o want to transition into Network Security and learn it. Can you guys give me advice on how to approach this filed and anything I need to keep in mind
submitted by /u/CoolNCocky
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Resources/Advices to transition into Network Security
Title says it all. I am a experienced Web Security Engineer and now o want to transition into Network Security and learn it. Can you guys give me...
hacking: security in practice
Don’t know if this is the right sub. SMS vs Authenticator apps,are Authenticator apps only connected to just one device where as sms can be switched devices cause it only connected to a number.
So that would always make AA more secure. Sorry if it’s a dumb question
submitted by /u/Princet2001
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Don’t know if this is the right sub. SMS vs Authenticator apps,are Authenticator apps only connected to just one device where as sms can be switched devices cause it only connected to a number.
So that would always make AA more secure. Sorry if it’s a dumb question
submitted by /u/Princet2001
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Don’t know if this is the right sub. SMS vs Authenticator apps,are...
So that would always make AA more secure. Sorry if it’s a dumb question
Wpgarlic - A Proof-Of-Concept WordPress Plugin Fuzzer
http://www.kitploit.com/2022/04/wpgarlic-proof-of-concept-wordpress.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/04/wpgarlic-proof-of-concept-wordpress.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Wpgarlic - A Proof-Of-Concept WordPress Plugin Fuzzer
A proof-of-concept WordPress plugin fuzzer used in the research described in https://kazet.cc/2022/02/03/fuzzing-wordpress-plugins.html that helped to discover more than 140 vulnerablities in WordPress plugins installed on almost 15 million sites. If you want to continue the research, start with less popular plugins - if a plugin achieved at least 10k active installs between October 2021 and January 2022, I have most probably looked at the fuzzer reports (and most focus has been put on plugins having at least 20k active installs). Because there is a lot of randomness in how fuzzer works, some vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) in these plugins remain undiscovered - but fewer ones. Fuzzer reports contain a lot of false positives - most of them don't indicate a vulnerability. After seeing a report, first analyze whether the behavior you're observing is indeed a vulnerability or a false positive. Don't spam WPScan/vendors with raw fuzzer reports - provide a PoC exploit instead.
Examples For obvious reasons, the examples will contain only vulnerabilities that have already been fixed. Arbitrary file read Let's assume you are fuzzing responsive-vector-maps in version 6.4.0: ./bin/fuzz_plugin responsive-vector-maps --version 6.4.0 (to fuzz the latest version, just skip --version). After the fuzzing finishes (which would take 10-30 minutes for this plugin) you can call: ./bin/print_findings data/plugin_fuzz_results/ You will see, among others:
___________________________
@hacking_Attack
@Hacking_Video
Examples For obvious reasons, the examples will contain only vulnerabilities that have already been fixed. Arbitrary file read Let's assume you are fuzzing responsive-vector-maps in version 6.4.0: ./bin/fuzz_plugin responsive-vector-maps --version 6.4.0 (to fuzz the latest version, just skip --version). After the fuzzing finishes (which would take 10-30 minutes for this plugin) you can call: ./bin/print_findings data/plugin_fuzz_results/ You will see, among others:
___________________________
@hacking_Attack
@Hacking_Video
kazet.cc
A technique to semi-automatically discover new vulnerabilities in WordPress plugins
How to semi-automatically find vulnerabilities in WordPress plugins installed on about 15 million websites.
. That means that the fuzzer detected executing fopen() on a known payload. Most of the payloads contain the word GARLIC in them to facilitate automatic detection in output. You may see or configure them in docker_image/magic_payloads.php. Then, you may browse the source code and see that indeed the wp_ajax_rvm_import_markers endpoint uses the file content to render output, thus allowing you to read arbitrary files on the server: CVE-2021-24947 (https://wpscan.com/vulnerability/c6bb12b1-6961-40bd-9110-edfa9ee41a18). What you see in white is a crash considered interesting (you may modify them or add new ones in crash_detectors.py). Green is the context. In blue you see the report file name (with plugin name), plugin popularity and endpoint name (here: the ajax action name). The data in yellow are what payloads were injected into what variables. Reflected XSS Let's assume you are fuzzing page-builder-add in version 1.4.9.4: ./bin/fuzz_plugin page-builder-add --version 1.4.9.4 After printing the results, you will see known payload echoed back:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
WPScan
RVM - Responsive Vector Maps < 6.4.2 - Subscriber+ Arbitrary File Read
See details on RVM - Responsive Vector Maps < 6.4.2 - Subscriber+ Arbitrary File Read CVE 2021-24947. View the latest Plugin Vulnerabilities on WPScan.
. You can then manually test whether indeed this place (remember: in blue you have the endpoint name, here: the menu page name) is vulnerable to XSS. In this case, it is: CVE-2021-25067 (https://wpscan.com/vulnerability/365007f0-61ac-4e81-8a3a-3a068f2c84bc). Option update leading to stored XSS ./bin/fuzz_plugin duplicate-page-or-post --version 1.4.6 After printing the results, you will see update_option being called:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video