Hacking Articles Tips Tricks Videos Tutorials
469 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
What's everyone's favorite phishing framework/tool?
https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/

I think GoPhish is the most popular. I'm going to be playing around with as many as I find over the weekend. I wanted to get some feedback on any favorites you may have used; pros & cons; etc. Thanks in advance for any feedback! submitted by /u/offftherecordz (https://www.reddit.com/user/offftherecordz)
[link] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/) [comments] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Critical Cisco VM-Escape Bug Threatens Host Takeover

The vendor also disclosed two other security vulnerabilities that would allow remote, unauthenticated attackers to inject commands as root and snoop on sensitive user information.
Dark Reading: Attacks/Breaches
FBI: Bank Losses From BEC Attacks Top $43B

Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.

___________________________
@hacking_Attack
@Hacking_Video
AMB Bridge: bug bounty program

As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet!Continue reading on Ambrosus Ecosystem »
Read more...
Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator (https://portswigger.net/burp/documentation/collaborator) or Interact.sh (https://github.com/projectdiscovery/interactsh) Used for penetration testing (https://www.kitploit.com/search/label/Penetration%20Testing) and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links.
Usage python3 malicious-pdf.py burp-collaborator-url Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory. Do not use the https:// etc prefix on the url argument. Purpose Test web pages/services accepting PDF-files Test security products Test PDF readers Test PDF converters Credits Insecure features in PDFs (https://web-in-security.blogspot.com/2021/01/insecure-features-in-pdfs.html) Burp Suite UploadScanner (https://github.com/modzero/mod0BurpUploadScanner/) Bad-Pdf (https://github.com/deepzec/Bad-Pdf) A Curious Exploration of Malicious PDF Documents (https://www.scitepress.org/Papers/2020/89923/89923.pdf) "Portable Document Flaws 101" talk at Black Hat USA 2020 (https://github.com/RUB-NDS/PDF101) Adobe Reader - PDF callback via XSLT stylesheet in XFA (https://insert-script.blogspot.com/2019/01/adobe-reader-pdf-callback-via-xslt.html) Foxit PDF Reader PoC, DoHyun Lee (https://twitter.com/l33d0hyun/status/1448342241647366152) Eicar test file by Stas Yakobov (https://github.com/fire1ce/eicar-standard-antivirus-test-files)

Download Malicious-Pdf (https://github.com/jonaslejon/malicious-pdf)

___________________________
@hacking_Attack
@Hacking_Video
Malicious-Pdf - Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality

Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh Used for penetration testing and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links. Usage python3 malicious-pdf.py burp-collaborator-url Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory. Do not use the https:// etc prefix on the url argument. Purpose Test web pages/services accepting PDF-files Test security products Test PDF readers Test PDF converters Credits Insecure features in PDFs Burp Suite UploadScanner Bad-Pdf A Curious Exploration of Malicious PDF Documents "Portable Document Flaws 101" talk at Black Hat USA 2020 Adobe Reader - PDF callback via XSLT stylesheet in XFA Foxit PDF Reader PoC, DoHyun Lee Eicar test file by Stas Yakobov Download Malicious-Pdf
Read more...
Dark Reading: Attacks/Breaches
A Third of Americans Use Easy-to-Guess Pet Passwords

Far too many turn to Jingles, Mittens, or Bella for password inspiration, given that these are some of the easiest passwords to crack.
Deep Web
Theoretical question about purchasing substances

I have a theoretical question about purchasing substances, for example mdma in pure form. If someone has never done this before, how safe is it? Would there be virtually any risk of having one’s house searched by the police upon delivery, or after?

Is this the right sub for this kind of thing? And could I have it explained to me like I am five, thanks

submitted by /u/salayatananirodha
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video