Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Cisco Announces Cloud Controls Framework Is Now Available to Public
The Cisco CCF helps save resources by enabling organizations to achieve cloud security certifications more efficiently.
___________________________
@hacking_Attack
@Hacking_Video
Cisco Announces Cloud Controls Framework Is Now Available to Public
The Cisco CCF helps save resources by enabling organizations to achieve cloud security certifications more efficiently.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Cisco Announces Cloud Controls Framework Is Now Available to Public
The Cisco CCF helps save resources by enabling organizations to achieve cloud security certifications more efficiently.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Magnet Forensics Acquires Cybersecurity Software Firm Comae Technologies
The company will continue the development of Comae’s memory analysis platform and seek to incorporate its capabilities into existing solutions
___________________________
@hacking_Attack
@Hacking_Video
Magnet Forensics Acquires Cybersecurity Software Firm Comae Technologies
The company will continue the development of Comae’s memory analysis platform and seek to incorporate its capabilities into existing solutions
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Magnet Forensics Acquires Cybersecurity Software Firm Comae Technologies
The company will continue the development of Comae’s memory analysis platform and seek to incorporate its capabilities into existing solutions
What's everyone's favorite phishing framework/tool?
https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/
I think GoPhish is the most popular. I'm going to be playing around with as many as I find over the weekend. I wanted to get some feedback on any favorites you may have used; pros & cons; etc. Thanks in advance for any feedback! submitted by /u/offftherecordz (https://www.reddit.com/user/offftherecordz)
[link] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/) [comments] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/
I think GoPhish is the most popular. I'm going to be playing around with as many as I find over the weekend. I wanted to get some feedback on any favorites you may have used; pros & cons; etc. Thanks in advance for any feedback! submitted by /u/offftherecordz (https://www.reddit.com/user/offftherecordz)
[link] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/) [comments] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit
Explore this post and more from the redteamsec community
Dark Reading: Attacks/Breaches
FBI: Bank Losses From BEC Attacks Top $43B
Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.
___________________________
@hacking_Attack
@Hacking_Video
FBI: Bank Losses From BEC Attacks Top $43B
Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
FBI: Bank Losses From BEC Attacks Top $43B
Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.
hacking: security in practice
What is a good certification that will make you good at hacking?
I keep hearing people talk bad about the CEH certification, which I have. If that isn't good, what is a good certification?
submitted by /u/TheRealTengri
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is a good certification that will make you good at hacking?
I keep hearing people talk bad about the CEH certification, which I have. If that isn't good, what is a good certification?
submitted by /u/TheRealTengri
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is a good certification that will make you good at hacking?
I keep hearing people talk bad about the CEH certification, which I have. If that isn't good, what is a good certification?
AMB Bridge: bug bounty program
As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet!Continue reading on Ambrosus Ecosystem »
Read more...
As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet!Continue reading on Ambrosus Ecosystem »
Read more...
AMB Bridge: bug bounty program
https://blog.ambrosus.io/amb-bridge-bug-bounty-program-a3a973f838ab?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://blog.ambrosus.io/amb-bridge-bug-bounty-program-a3a973f838ab?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
AMB Bridge: bug bounty program
As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet! While we want to get it onto the mainnet as soon…
As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet!Continue reading on Ambrosus Ecosystem » (https://blog.ambrosus.io/amb-bridge-bug-bounty-program-a3a973f838ab?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
AMB Bridge: bug bounty program
As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet! While we want to get it onto the mainnet as soon…
Malicious-Pdf - Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality
http://www.kitploit.com/2022/05/malicious-pdf-generate-bunch-of.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/malicious-pdf-generate-bunch-of.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Malicious-Pdf - Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality
Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator (https://portswigger.net/burp/documentation/collaborator) or Interact.sh (https://github.com/projectdiscovery/interactsh) Used for penetration testing (https://www.kitploit.com/search/label/Penetration%20Testing) and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links.
Usage python3 malicious-pdf.py burp-collaborator-url Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory. Do not use the https:// etc prefix on the url argument. Purpose Test web pages/services accepting PDF-files Test security products Test PDF readers Test PDF converters Credits Insecure features in PDFs (https://web-in-security.blogspot.com/2021/01/insecure-features-in-pdfs.html) Burp Suite UploadScanner (https://github.com/modzero/mod0BurpUploadScanner/) Bad-Pdf (https://github.com/deepzec/Bad-Pdf) A Curious Exploration of Malicious PDF Documents (https://www.scitepress.org/Papers/2020/89923/89923.pdf) "Portable Document Flaws 101" talk at Black Hat USA 2020 (https://github.com/RUB-NDS/PDF101) Adobe Reader - PDF callback via XSLT stylesheet in XFA (https://insert-script.blogspot.com/2019/01/adobe-reader-pdf-callback-via-xslt.html) Foxit PDF Reader PoC, DoHyun Lee (https://twitter.com/l33d0hyun/status/1448342241647366152) Eicar test file by Stas Yakobov (https://github.com/fire1ce/eicar-standard-antivirus-test-files)
Download Malicious-Pdf (https://github.com/jonaslejon/malicious-pdf)
___________________________
@hacking_Attack
@Hacking_Video
Usage python3 malicious-pdf.py burp-collaborator-url Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory. Do not use the https:// etc prefix on the url argument. Purpose Test web pages/services accepting PDF-files Test security products Test PDF readers Test PDF converters Credits Insecure features in PDFs (https://web-in-security.blogspot.com/2021/01/insecure-features-in-pdfs.html) Burp Suite UploadScanner (https://github.com/modzero/mod0BurpUploadScanner/) Bad-Pdf (https://github.com/deepzec/Bad-Pdf) A Curious Exploration of Malicious PDF Documents (https://www.scitepress.org/Papers/2020/89923/89923.pdf) "Portable Document Flaws 101" talk at Black Hat USA 2020 (https://github.com/RUB-NDS/PDF101) Adobe Reader - PDF callback via XSLT stylesheet in XFA (https://insert-script.blogspot.com/2019/01/adobe-reader-pdf-callback-via-xslt.html) Foxit PDF Reader PoC, DoHyun Lee (https://twitter.com/l33d0hyun/status/1448342241647366152) Eicar test file by Stas Yakobov (https://github.com/fire1ce/eicar-standard-antivirus-test-files)
Download Malicious-Pdf (https://github.com/jonaslejon/malicious-pdf)
___________________________
@hacking_Attack
@Hacking_Video
portswigger.net
Burp Collaborator - PortSwigger
Burp Collaborator is a network service that enables you to detect invisible vulnerabilities. These are vulnerabilities that don't: Trigger error messages. ...
Malicious-Pdf - Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality
Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh Used for penetration testing and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links. Usage python3 malicious-pdf.py burp-collaborator-url Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory. Do not use the https:// etc prefix on the url argument. Purpose Test web pages/services accepting PDF-files Test security products Test PDF readers Test PDF converters Credits Insecure features in PDFs Burp Suite UploadScanner Bad-Pdf A Curious Exploration of Malicious PDF Documents "Portable Document Flaws 101" talk at Black Hat USA 2020 Adobe Reader - PDF callback via XSLT stylesheet in XFA Foxit PDF Reader PoC, DoHyun Lee Eicar test file by Stas Yakobov Download Malicious-Pdf
Read more...
Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh Used for penetration testing and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links. Usage python3 malicious-pdf.py burp-collaborator-url Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory. Do not use the https:// etc prefix on the url argument. Purpose Test web pages/services accepting PDF-files Test security products Test PDF readers Test PDF converters Credits Insecure features in PDFs Burp Suite UploadScanner Bad-Pdf A Curious Exploration of Malicious PDF Documents "Portable Document Flaws 101" talk at Black Hat USA 2020 Adobe Reader - PDF callback via XSLT stylesheet in XFA Foxit PDF Reader PoC, DoHyun Lee Eicar test file by Stas Yakobov Download Malicious-Pdf
Read more...
Deep Web
Theoretical question about purchasing substances
I have a theoretical question about purchasing substances, for example mdma in pure form. If someone has never done this before, how safe is it? Would there be virtually any risk of having one’s house searched by the police upon delivery, or after?
Is this the right sub for this kind of thing? And could I have it explained to me like I am five, thanks
submitted by /u/salayatananirodha
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Theoretical question about purchasing substances
I have a theoretical question about purchasing substances, for example mdma in pure form. If someone has never done this before, how safe is it? Would there be virtually any risk of having one’s house searched by the police upon delivery, or after?
Is this the right sub for this kind of thing? And could I have it explained to me like I am five, thanks
submitted by /u/salayatananirodha
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Theoretical question about purchasing substances
I have a theoretical question about purchasing substances, for example mdma in pure form. If someone has never done this before, how safe is it?...
Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO)
https://medium.com/@zulfifarizi9001/chained-bug-xml-file-upload-to-xss-to-csrf-to-full-account-take-over-ato-156409c41b57?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@zulfifarizi9001/chained-bug-xml-file-upload-to-xss-to-csrf-to-full-account-take-over-ato-156409c41b57?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO)
Hello Community, today i’am gonna share my experience about how i able to chaining some vulnerabilities into Full Account Take Over…
Hello Community, today i’am gonna share my experience about how i able to chaining some vulnerabilities into Full Account Take Over…Continue reading on Medium » (https://medium.com/@zulfifarizi9001/chained-bug-xml-file-upload-to-xss-to-csrf-to-full-account-take-over-ato-156409c41b57?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO)
Hello Community, today i’am gonna share my experience about how i able to chaining some vulnerabilities into Full Account Take Over…
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Malicious-Pdf - Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality
https://blogger.googleusercontent.com/img/a/AVvXsEgU1ADhTcPDkAZE7ujvaAdtFQ1GAVJxfQWxoO_dY5FAWQKXzhxUuPv8wX8qIMlgp4-z0AnpJz8QoDjqyNPRVH2gTsTbDxFZ1YNu9q4CxjzGzVeiJsyTR4VzcjJFNz86B-XAzkPaHocbfhYT67e2QhNglNzq8mAbRJAPf0mvACDxidO3CO3yic1MPsLV=w320-h320
Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
Used for penetration testing and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links.
Usage
Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory.
Do not use the https:// etc prefix on the url argument.
Purpose
* Test web pages/services accepting PDF-files
* Test security products
* Test PDF readers
* Test PDF converters
Credits
* Insecure features in PDFs
* Burp Suite UploadScanner
* Bad-Pdf
* A Curious Exploration of Malicious PDF Documents
* "Portable Document Flaws 101" talk at Black Hat USA 2020
* Adobe Reader - PDF callback via XSLT stylesheet in XFA
* Foxit PDF Reader PoC, DoHyun Lee
* Eicar test file by Stas Yakobov
Download Malicious-Pdf
___________________________
@hacking_Attack
@Hacking_Video
Malicious-Pdf - Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality
https://blogger.googleusercontent.com/img/a/AVvXsEgU1ADhTcPDkAZE7ujvaAdtFQ1GAVJxfQWxoO_dY5FAWQKXzhxUuPv8wX8qIMlgp4-z0AnpJz8QoDjqyNPRVH2gTsTbDxFZ1YNu9q4CxjzGzVeiJsyTR4VzcjJFNz86B-XAzkPaHocbfhYT67e2QhNglNzq8mAbRJAPf0mvACDxidO3CO3yic1MPsLV=w320-h320
Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
Used for penetration testing and/or red-teaming etc. I created this tool because i needed a third party tool to generate a bunch of PDF files with various links.
Usage
python3 malicious-pdf.py burp-collaborator-urlOutput will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory.
Do not use the https:// etc prefix on the url argument.
Purpose
* Test web pages/services accepting PDF-files
* Test security products
* Test PDF readers
* Test PDF converters
Credits
* Insecure features in PDFs
* Burp Suite UploadScanner
* Bad-Pdf
* A Curious Exploration of Malicious PDF Documents
* "Portable Document Flaws 101" talk at Black Hat USA 2020
* Adobe Reader - PDF callback via XSLT stylesheet in XFA
* Foxit PDF Reader PoC, DoHyun Lee
* Eicar test file by Stas Yakobov
Download Malicious-Pdf
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Malicious-Pdf - Generate A Bunch Of Malicious Pdf Files With Phone-Home Functionality
Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO)
Hello Community, today i’am gonna share my experience about how i able to chaining some vulnerabilities into Full Account Take Over…Continue reading on Medium »
Read more...
Hello Community, today i’am gonna share my experience about how i able to chaining some vulnerabilities into Full Account Take Over…Continue reading on Medium »
Read more...