Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Raspberry pi 4 for hacking 🗿

it's been 30days since am using raspberry pi 4b as my main hacking Machine with kali linux, 128gb SanDisk card. and believe me its running great even I can run burpsuite,metaspoilt, nd some heavy tools on it without any issue. I recommend you all to use raspberry pi 4 for hacking and practice if you on limited budget 💲 btw i overclocked my pi cpu to 2.2ghz & gpu to 750

submitted by /u/atullverma
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Ideal programming language for

Hello all ,

What would be the ideal programming language to learn to hack a game like Dayz, Rust, EFT? Creating mod menus etc etc. I know this industry is huge but i would like to get my piece of pie in this.

submitted by /u/LeaderFinancial5204
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Crypto & DeFi Security Subreddit

Howdy security fam, for those who might be interested in Crypto/DeFi/Chain security related topics, we've started a subreddit:

/r/DeFiSecurity - Decentralized Finance (DeFi) and Crypto Cybersecurity related Conversations

If this is an area of interest, please drop in, join and add to the conversations...thanks!

submitted by /u/rfhacker
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Anyone ordered from Dc207.org?

I’m looking at building a pwnagotchi and for some reason getting all the components in Germany is insanely expensive everywhere I’ve looked. It looks like I can buy a completed pownagotchi from Dc207.org for less than the price of components here. Has anyone ordered from them before?

submitted by /u/Traditional_Couple90
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgydikjQTzuAjAZQNo1Hcrj_Rew0WSbhEeC2dz5FhHgK2HAVBBKkwvLmXBd5K-r8vDoH1MuAKG_N8zJD78VAigXz6W2a9iz8SoMQDA-he8xVWYMwhZjkSrRpyG-PSskP--fKR2nzg2YnGruFCXj4VJ7npFI3KpYoRgNb1RkZwUN_pDfUy0e7A1XQf9s/w640-h334/Spring4Shell.jpg
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html

Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC

Steps to Build/Run

Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60

* Run mvn clean packageto build the application
* Rename demo-0.0.1-SNAPSHOT.warto spring-poc.warand copy this .war file to Tomcat's webapps directory
* Run python exp.py --url http://localhost:8080/spring-poc/greeting
* If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoamiwill be logged.
* You should now see the file tomcatwar.jspwritten to Tomcat's webapps/spring-poc directory. This directory can be changed by modifying exp.py.
* https://github.com/ckkok/spring4shell-poc/raw/master/images/01-log-message.png

* Go to the url to see the result of the shell command
* https://github.com/ckkok/spring4shell-poc/raw/master/images/02-running-the-payload.png
Download Spring4Shell-Poc

___________________________
@hacking_Attack
@Hacking_Video
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC Steps to Build/Run Tested with JDK 11.0.14, Spring Boot (https://www.kitploit.com/search/label/Spring%20Boot) 2.6.5, and Apache (https://www.kitploit.com/search/label/Apache) Tomcat (https://www.kitploit.com/search/label/Tomcat) 9.0.60 Run mvn clean package to build the application Rename demo-0.0.1-SNAPSHOT.war to spring-poc.war and copy this .war file to Tomcat's webapps directory Run python exp.py --url http://localhost:8080/spring-poc/greeting If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoami will be logged. You should now see the file tomcatwar.jsp written to Tomcat's webapps/spring-poc directory. This directory (https://www.kitploit.com/search/label/Directory) can be changed by modifying exp.py.

___________________________
@hacking_Attack
@Hacking_Video
Go to the url to see the result of the shell command

___________________________
@hacking_Attack
@Hacking_Video
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability

Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC Steps to Build/Run Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60 Run mvn clean package to build the application Rename demo-0.0.1-SNAPSHOT.war to spring-poc.war and copy this .war file to Tomcat's webapps directory Run python exp.py --url http://localhost:8080/spring-poc/greeting If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoami will be logged. You should now see the file tomcatwar.jsp written to Tomcat's webapps/spring-poc directory. This directory can be changed by modifying exp.py. Go to the url to see the result of the shell command Download Spring4Shell-Poc
Read more...
Dark Reading: Attacks/Breaches
US Pledges to Help Ukraine Keep the Internet and Lights On

US State Department outlines coordinated government effort to provide Ukraine with cybersecurity intelligence, expertise, and resources amid invasion.
Dark Reading: Attacks/Breaches
What to Patch Now: Actively Exploited Windows Zero-Day Threatens Domain Controllers

Microsoft's May 2022 Patch Tuesday contains several bugs in ubiquitous software that could affect millions of machines, researchers warn.