Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Getting DNS tunnelling to work on Android 12

I had been tunnelling IPV4 over DNS for many many years.

Software used:

Server Side:

Iodine

Client side: AndIodine

With Android 12, the AndIodine app basically stopped working.

Can someone offer a way that works with Android 12, so I can continue using it? Thanks!

submitted by /u/BanglaV6
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can someone explain this hack?

Scammer set up a cloned website of an official one 5 days ago. He entices people to get on it via whatsapp. They then have to enter some information about themselves on the site. Simple information like their name and email. He then proceeds to tell them to enter a code that he gives them. Once they enter the code, their bank account balance reduces as the attacker just transferred himself all the money from their account.

How on earth can this happen?

submitted by /u/abjedhowiz
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Any Red Team here has experience with getting code-signing certificates to sign their malware?

Hello!

more and more, we're running into issues when delivering malware (usually through social engineering) that it can not be started due to domain policy of not allowing unsigned applications to run. Does anyone here has some experience in how to deal with it?

I was trying to convince our company to just get us a legitimate code signing certificate, so we can sign the binaries which are getting used in legal engagements, so there is no risk in them being signed by us. But I've been told that is not going to work, because eventually every malware ends up in hands of a security researcher (even if it's Microsoft Defender submitting unknown binaries), and then we will end up having to explain why is our certificate signing malware, the certificate will get rewoked and in the worst case they will never give us another certificate again.

Which is a compelling argument, but I don't know whether it's actually happening in practice, which is why I'm asking for your experience if you've ever tried to legitimize your malware delivery in this way.

I feel like it should not be that easy, to get certificate that is accepted for malware (since prooving that you use it legitimately for legal red team engagements is really hard), but I also don't want to accept that there is not a way how to communicate it or get an exception, when we indeed are a legit security firm.

So, has anyone solved this issue, or is it really impossible?

Thank you!

submitted by /u/Mikina
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
We Rescued $4M from Rari Capital. But Was It Worth It?

On April 6th, we discovered a verified Fuse pool in Rari Capital used a weak price oracle prone to manipulation. Usually, exploiting a…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Kali Linux – The Best Tool For Penetration Testing?

The penetration tool known as Kali Linux is a Debian-based Linux distribution that was created with security testing and auditing in mind. It is one of the most popular security distributions in the world, and it includes dozens of tools that allow you to perform all sorts of attacks against your targets. In this blog post, we will discuss what penetration testing is, why Kali Linux is such a good tool for this activity, and how you can use it to test your own systems. We will also provide some tips for using Kali Linux effectively, and mention some other tools in its category. What Is Penetration Testing?Penetration testing, often known as “pentesting” or “security testing,” is the art of simulating an attack from a malicious individual to assess the security of a computer system or network. This can be done either manually or automated, and it typically involves trying to exploit vulnerabilities in order to gain access to sensitive data or systems. Penetration tests can be used to test both internal and external systems, and they are often used as part of a larger security assessment.

Debian is the Linux distribution employed in penetration testing and security auditing. It includes dozens of tools that allow you to perform all sorts of attacks against your targets. In this blog post, we will discuss what penetration testing is, why Kali Linux is such a good tool for this activity, and how you can use it to test your own systems. We’ll show you how to use this Linux distribution efficiently, as well as other tools in the same category. Why Is Kali Linux Such a Good Tool for Penetration Testing?https://lh6.googleusercontent.com/5t99TZOenFI-B5bOAeiUJWqdRMjl3d8TgPT-z6_-r0C5QUDoLdoJddjsZlebHZOJfpx2cnC9qrLdjwtvShkhi_Mcv2y-dszl464ib3pGwxd0PG1mN-vV3jfx-tETOJLmLA
Kali Linux is one of the most popular security distributions in the world, and it includes dozens of tools that allow you to perform all sorts of attacks against your targets. In addition, Kali Linux is regularly updated with new features and tools, making it an essential tool for any penetration tester.

Some of the reasons why Kali Linux is such a good tool for penetration testing include:

– It has a large number of pre-installed security tools, making it easy to get started with penetration testing.

– Kali Linux is regularly updated with new features and tools.

It’s easy to use. It’s completely free and may be used on a variety of platforms. How to Use Kali Linux for Penetration Testing: A Step-by-Step Guidehttps://lh6.googleusercontent.com/IO8bpszFAExUOOU2YLCbysnkGjDqB00MHSkPakdGq7oy8N4yCbJRP7WEJTvNdottTwJZzkpyiYFZq7CGHMl-Kf53lNbfjdVKe0U4yM1iw00UWh2VsnnfNJDhIUIqC3NZDg
There are a few things to think about before you start using Kali Linux for penetration testing. In particular, you need to choose your targets, gather information about them, and then select the appropriate tools for the job. Let’s look at each of these phases in further depth below.

Choosing Your Targets

The first step in any penetration test is choosing your targets. This can be done either manually or automatically, but it is important to make sure that you have permission from the owners of the systems before proceeding. In addition, you need to choose targets that are likely to be vulnerable to the types of attacks that you plan to use.

Gathering Information

The next stage is to obtain information about your target. This can include things like network diagrams, system architecture diagrams, and lists of installed software. You should also attempt to learn as much as possible about the individuals who work on the system, including their positions and duties.

Selecting Tools

After you have gathered information about your target, it is time to select the appropriate tools for the job. Kali Linux includes dozens of tools[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Kali Linux – The Best Tool For Penetration Testing? The penetration tool known as Kali Linux is a Debian-based Linux distribution that was created with security testing and auditing in mind. It is one of the most popular security distributions…
that can be used for penetration testing, so it is important to select the right ones for the task at hand. You should be aware of the various sorts of assaults you may make.

Performing the Attack

Once you have selected your targets, gathered information about them, and selected the appropriate tools, it is time to start attacking. This can be done in a variety of ways, but typically involves trying to exploit vulnerabilities in order to gain access to sensitive data or systems. Kali Linux includes a number of tools that make this process easy, so be sure to take advantage of them. Tips for Using Kali Linux EffectivelyHere are a few tips for using Kali Linux effectively:

– Be familiar with the different types of attacks that you can perform.

– Select the appropriate tools for the job.

– Read the documentation for each tool before using it.

– Keep your Kali Linux installation up to date. Other Tools in This CategoryIn addition to Kali Linux, there are a number of other tools that can be used for penetration testing. Some of these include:

* Metasploit
* Astra’s Pentest
* Nmap
* Wireshark
* Burp Suite What Does Penetration Testing With Kali Linux Mean?Penetration testing with Kali Linux means using the tools and features of Kali Linux to test the security of systems and networks. This can be done either manually or automatically, but it is important to make sure that you have permission from the owners of the systems before proceeding. In addition, you need to choose targets that are likely to be vulnerable to the types of attacks that you plan to use.

Kali Linux is one of the most popular security distributions in the world, and it includes dozens of tools that allow you to perform all sorts of attacks against your targets. In addition, Kali Linux is regularly updated with new features and tools, making it an essential tool for any penetration tester. ConclusionKali Linux is one of the most popular security distributions in the world, and it includes dozens of tools that allow you to perform all sorts of attacks against your targets. In addition, Kali Linux is regularly updated with new features and tools, making it an essential tool for any penetration tester. If you want to use Kali Linux for penetration testing, be sure to familiarize yourself with the different types of attacks that you can perform, and select the appropriate tools for the job.
On April 6th, we discovered a verified Fuse pool in Rari Capital used a weak price oracle prone to manipulation. Usually, exploiting a…Continue reading on Medium » (https://medium.com/@hacxyk/we-rescued-4m-from-rari-capital-but-was-it-worth-it-39366d4d1812?source=rss------bug_bounty-5)