Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
What way is currently best for SE payload attacks?
https://www.reddit.com/r/redteamsec/comments/uix06u/what_way_is_currently_best_for_se_payload_attacks/

Microsoft did a huge crackdown on the "evil macros" on office docs about 9 months ago. https://www.zdnet.com/article/microsoft-...el-macros/ (https://www.zdnet.com/article/microsoft-were-cracking-down-on-malware-that-uses-excel-macros/) It now seems that ANY attempt of creating a shell object on VBS instantly gets flagged by windows defender. This used to be bypassed by using an "external" program to create such shell i.e: Outlook. So, how can I send my payload now? Sending exes in mail is frown upon by any spam agency and a plethora of alerts pop up when I do so. Sending a .bat is too sketchy as well and the .lnk trick has been also fixed. submitted by /u/ErikDz11 (https://www.reddit.com/user/ErikDz11)
[link] (https://www.reddit.com/r/redteamsec/comments/uix06u/what_way_is_currently_best_for_se_payload_attacks/) [comments] (https://www.reddit.com/r/redteamsec/comments/uix06u/what_way_is_currently_best_for_se_payload_attacks/)

___________________________
@hacking_Attack
@Hacking_Video
Why graphql-threat-matrix? graphql-threat-matrix (https://github.com/nicholasaleks/graphql-threat-matrix) was built for bug bounty hunters, security researchers and hackers (https://www.kitploit.com/search/label/Hackers) to assist with uncovering vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) across multiple GraphQL implementations. The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations.
Legend
- Enabled by Default ⚠️ - Disabled by Default - No Support Implementation Validations Field Suggestions Query Depth limit Query Cost Analysis Automatic Persisted Queries Introspection Debug Mode Batch Requests wp-graphql (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/wp-graphql.md) 38 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/wp-graphql.md#Request-Validations) ⚠️ ⚠️ ⚠️ graphql-php (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-php.md) 37 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-php.md#Request-Validations) ⚠️ ⚠️ ⚠️ ⚠️ Apollo (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/apollo.md) 34 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/apollo.md#Request-Validations) ⚠️ ⚠️ graphql-yoga (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-yoga.md) 34 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-yoga.md#Request-Validations) ⚠️ ⚠️ ⚠️ ⚠️ graphene (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphene.md) 34 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphene.md#Request-Validations) ⚠️ Ariadne (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/ariadne.md) 34 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/ariadne.md#Request-Validations) ⚠️ ⚠️ ⚠️ Strawberry (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/strawberry.md) 34 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/strawberry.md#Request-Validations) ⚠️ graphql-ruby (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-ruby.md) 28 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-ruby.md#%23Request-Validations) ⚠️ ⚠️ Sangria (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/sangria.md) 27 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/sangria.md#Request-Validations) ⚠️ ⚠️ ⚠️ Tartiflette (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/tartiflette.md) 26 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/tartiflette.md#Request-Validations) graphql-java (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-java.md) 26 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-java.md#Request-Validations) ⚠️ ⚠️ ⚠️ gqlgen (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/gqlgen.md) 25

___________________________
@hacking_Attack
@Hacking_Video
(https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/gqlgen.md#Request-Validations) ⚠️ ⚠️ ⚠️ ⚠️ Dgraph (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/dgraph.md) 25 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/dgraph.md#Request-Validations) ⚠️ graphql-go (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-go.md) 24 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/graphql-go.md#Request-Validations) ⚠️ juniper (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/juniper.md) 24 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/juniper.md#Request-Validations) ⚠️ Diana.jl (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/diana.md) 10 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/diana.md#Request-Validations) gql-dart/gql (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/gql-dart.md) 9 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/gql-dart.md#Request-Validations) Agoo (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/agoo.md) 0 (https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/agoo.md#Request-Validations) ⚠️ Want to provide a submission (or correction)? Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details. Contributors & Maintainers Nick Aleks (https://github.com/nicholasaleks) Dolev Farhi (https://github.com/dolevf)

Download Graphql-Threat-Matrix (https://github.com/nicholasaleks/graphql-threat-matrix/)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Why Security Matters Even More in Online Gaming

As the gaming sector booms, game publishers and gaming networks have been heavily targeted with distributed denial-of-service (DDoS) attacks in the last year.
Dark Reading: Attacks/Breaches
Docker Under Siege: Cybercriminals Compromise Honeypots to Ramp Up Attacks

Cloud containers are increasingly part of the cybercrime playbook, with researchers flagging ongoing scanning for Docker weaknesses along with rapid exploitation to infect systems with coin-miners, denial-of-service tools, and ransomware.
hacking: security in practice
Hashcat gave me a password that doesn't work?

Cracking some old af '97 ppt files that have a PW on them. Hashcat gave me passwords, but they don't work.
$oldoffice$3*ae0092f1e451d0e3fae35f43aa65bcd7*2a2f489f9dad13b0b20fb94b1edf0848*b9a799f47c4ed7a0d80c2ddf3610a3a0be6db596:2*\9{~ $oldoffice$3*85491defe7e3dc6b98ceef5286a1e55e*cbf532f91bd6f8a7afc1e853dcae7786*a113b0d70d02b3d7b1a1a7fa09ef690ac81c2c51:t;m\PU
My Hashcat cmd:
hashcat -m 9800 -a 3 dumb.txt -i ?a?a?a?a?a?a?a?a?a?a?
According to this: https://hashcat.net/forum/thread-7643.html

I have a collision because we're only using the first 40 bytes of a salt+digest. So, my passwords, 2*\9{~ and t;m\PU should work, but they do not.

submitted by /u/TheSlenderman871
[link] [comments]
hacking: security in practice
Is it realistic of me to try and get CEH certification?

Hi, I wanted to ask for your advice on rather or not I should try and take the course.

I have no formal experience in cyber security (no certifications)

What I do have: - C, C++ - python-only on syntax level, no libraries except selenium - studied linux for the pass couple of years as a hubby. - for the pass five months I have been experiencing with vulnhub machines ctf and wifi attacks using kali.

I will add that im currently pursuing a degree in cs and on a vacation for 6 months.

Do you guys/gals think it’s realistic for me to try and pass the course in 6 months?

submitted by /u/guykehat
[link] [comments]
Remote Code Execution Web Application Vulnerability : Code Injection Part

Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations

https://blogger.googleusercontent.com/img/a/AVvXsEjct_YmCLc-18AnApBUspPpG3TqJm6idF8kXXzhip6ehKOT6BfkPAmSl5giOn-9YO41mRxa2ob3NpNTpGXMABoNhKw0JstsaRZ3T1geeh-tAfUjm8ZGP37g1AXeTCjWlmatsSLJ1BcN1C4jAoJ6lEWukj_LI46xtJeoKe6jz4kQKlJyminP3SofY7CK=w640-h284 Why graphql-threat-matrix?graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.

The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations. Legend - Enabled by Default

⚠️ - Disabled by Default

- No Support
Implementation Validations Field Suggestions Query Depth limit Query Cost Analysis Automatic Persisted Queries Introspection Debug Mode Batch Requests wp-graphql 38


⚠️





⚠️

⚠️

graphql-php 37


⚠️

⚠️





⚠️

⚠️ Apollo 34


⚠️

⚠️







graphql-yoga 34


⚠️





⚠️

⚠️

⚠️ graphene 34












⚠️ Ariadne 34


⚠️

⚠️





⚠️

Strawberry 34


⚠️









graphql-ruby 28




⚠️

⚠️





Sangria 27


⚠️

⚠️







⚠️ Tartiflette 26












graphql-java 26


⚠️

⚠️







⚠️ gqlgen 25




⚠️

⚠️



⚠️

⚠️ Dgraph 25






⚠️





graphql-go 24










⚠️

juniper 24












⚠️ Diana.jl 10












gql-dart/gql 9












Agoo 0










⚠️

Want to provide a submission (or correction)?Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details. Contributors & Maintainers* Nick Aleks
* Dolev Farhi Download Graphql-Threat-Matrix

___________________________
@hacking_Attack
@Hacking_Video