Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CVE-2022–30507 write up
https://cdn-images-1.medium.com/max/674/1*HcpzPVR9cQuusIqgiFuUYw.png
Hello folks (:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CVE-2022–30507 write up
https://cdn-images-1.medium.com/max/674/1*HcpzPVR9cQuusIqgiFuUYw.png
Hello folks (:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–30507 write up
Hello folks (:
hacking: security in practice
Got my bitlocker hashes, now what?
I want to preface this by saying I have absolutely zero experience doing any of this. I'm familiar with windows and how to navigate most things but as far as any "hacking" im a noob.
I forgot the password to my bitlocker-encrypted drive and didn't save the recovery key (yes I know i'm sorry). I have been able to follow along with videos on youtube and have gotten as far as imaging my drive and using jumbojohn to run bitlocker2john.exe. It ran overnight and most of today and I now have my 4 hashes.
I know the password is at least ~12 characters but uses multiple special characters, numbers and letters. Therefore I assume trying to get that password is a lost cause.
Please help. I lost my father a couple of years ago and all of the pictures/videos/messages/notes I have involving him are on this drive.
Thanks
submitted by /u/Mitthaw
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Got my bitlocker hashes, now what?
I want to preface this by saying I have absolutely zero experience doing any of this. I'm familiar with windows and how to navigate most things but as far as any "hacking" im a noob.
I forgot the password to my bitlocker-encrypted drive and didn't save the recovery key (yes I know i'm sorry). I have been able to follow along with videos on youtube and have gotten as far as imaging my drive and using jumbojohn to run bitlocker2john.exe. It ran overnight and most of today and I now have my 4 hashes.
I know the password is at least ~12 characters but uses multiple special characters, numbers and letters. Therefore I assume trying to get that password is a lost cause.
Please help. I lost my father a couple of years ago and all of the pictures/videos/messages/notes I have involving him are on this drive.
Thanks
submitted by /u/Mitthaw
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Got my bitlocker hashes, now what?
I want to preface this by saying I have absolutely zero experience doing any of this. I'm familiar with windows and how to navigate most things...
hacking: security in practice
What is/are the best way(s) to encrypt data/files to ensure there is no possible chance anyone but you can read/access said data/files
Looking for best methods in terms of maybe some text and files. Solutions in terms of easy and quick, but also most intensive. Thanks
submitted by /u/shinygoldcollector
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is/are the best way(s) to encrypt data/files to ensure there is no possible chance anyone but you can read/access said data/files
Looking for best methods in terms of maybe some text and files. Solutions in terms of easy and quick, but also most intensive. Thanks
submitted by /u/shinygoldcollector
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is/are the best way(s) to encrypt data/files to ensure there...
Looking for best methods in terms of maybe some text and files. Solutions in terms of easy and quick, but also most intensive. Thanks
hacking: security in practice
Is there any such thing as a universal key fob for a door?
Is there anyway I can register a paxton key fob without having access to the system? Anyway I can open a locked door with the Paxton system?
submitted by /u/cha0ticth0t
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there any such thing as a universal key fob for a door?
Is there anyway I can register a paxton key fob without having access to the system? Anyway I can open a locked door with the Paxton system?
submitted by /u/cha0ticth0t
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there any such thing as a universal key fob for a door?
Is there anyway I can register a paxton key fob without having access to the system? Anyway I can open a locked door with the Paxton system?
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Xiaomi air purifiers NFC stickers defeated
Since one of my first post was here in this thread on Reddit I thought it would be cool to share some progress on breaking the NFC filters of the Xiaomi air purifiers...
It's done, and it's open: https://www.flamingo-tech.nl/2022/05/27/this-is-how-they-do-it/ now you can make your own filters!
This works on all Xiaomi air purifiers and does not break warranty nor is there the need to open the air purifier to install for example an modchip!
Have fun^^
submitted by /u/the_flam1ngo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Xiaomi air purifiers NFC stickers defeated
Since one of my first post was here in this thread on Reddit I thought it would be cool to share some progress on breaking the NFC filters of the Xiaomi air purifiers...
It's done, and it's open: https://www.flamingo-tech.nl/2022/05/27/this-is-how-they-do-it/ now you can make your own filters!
This works on all Xiaomi air purifiers and does not break warranty nor is there the need to open the air purifier to install for example an modchip!
Have fun^^
submitted by /u/the_flam1ngo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Xiaomi air purifiers NFC stickers defeated
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackThisSite Realistic Mission 11
https://cdn-images-1.medium.com/max/700/0*xoSz7gBSSz2zLGIS.jpg
Alright another website to take down, this one is fancy as it’s a premium hosting server. This site and the websites created are ancient…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackThisSite Realistic Mission 11
https://cdn-images-1.medium.com/max/700/0*xoSz7gBSSz2zLGIS.jpg
Alright another website to take down, this one is fancy as it’s a premium hosting server. This site and the websites created are ancient…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackThisSite Realistic Mission 11
Alright another website to take down, this one is fancy as it’s a premium hosting server. This site and the websites created are ancient…
hacking: security in practice
what does this mean in lifelock I'm scared
So im looking through lifelock security and I see a notification for back in November it says I was breeched but doesn't say from where it says united states services other data broker 242m what does this even mean????
submitted by /u/That_Description_423
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
what does this mean in lifelock I'm scared
So im looking through lifelock security and I see a notification for back in November it says I was breeched but doesn't say from where it says united states services other data broker 242m what does this even mean????
submitted by /u/That_Description_423
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
what does this mean in lifelock I'm scared
So im looking through lifelock security and I see a notification for back in November it says I was breeched but doesn't say from where it says...
hacking: security in practice
Why I don't hear about malware targetting password managers?
I mean malware which steals all the passwords user holds in the unlocked vault on a disk of his/her local machine. My hypothesis is that password managers are not popular yet. If they became popular malware will emerge. What do you think?
EDIT: I'm interested in client-side attacks.
submitted by /u/repawel
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why I don't hear about malware targetting password managers?
I mean malware which steals all the passwords user holds in the unlocked vault on a disk of his/her local machine. My hypothesis is that password managers are not popular yet. If they became popular malware will emerge. What do you think?
EDIT: I'm interested in client-side attacks.
submitted by /u/repawel
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Why I don't hear about malware targetting password managers?
I mean malware which steals all the passwords user holds in the unlocked vault on a disk of his/her local machine. My hypothesis is that password...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
[serious] Mitnick's son tutorial 😎 /s
https://external-preview.redd.it/sZsYewsgkd7Lw3t-F3U8ov_fT1O7MevvaVmG7PzL7Mk.jpg?width=320&crop=smart&auto=webp&s=98c8f459afa6996af190c46ffbcffa187de6906c submitted by /u/NotSoStupidBut
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
[serious] Mitnick's son tutorial 😎 /s
https://external-preview.redd.it/sZsYewsgkd7Lw3t-F3U8ov_fT1O7MevvaVmG7PzL7Mk.jpg?width=320&crop=smart&auto=webp&s=98c8f459afa6996af190c46ffbcffa187de6906c submitted by /u/NotSoStupidBut
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
[serious] Mitnick's son tutorial 😎 /s
Posted in r/hacking by u/NotSoStupidBut • 0 points and 2 comments
hacking: security in practice
New to hacking
So like the title says, I’m new to hacking. I’ve set up a few fake accounts of Social Media (Instagram and Snapchat )and I wanted to ask if there are specialized tools for cracking passwords of these sides? Since I made the Accounts I obviously have the Username and the Account ID’s (on Instagram) I can get with OSINT. I’m familiar with Phishing, but Phishing myself seems a bit too easy. Thank you in advance
submitted by /u/Caveman0149
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
New to hacking
So like the title says, I’m new to hacking. I’ve set up a few fake accounts of Social Media (Instagram and Snapchat )and I wanted to ask if there are specialized tools for cracking passwords of these sides? Since I made the Accounts I obviously have the Username and the Account ID’s (on Instagram) I can get with OSINT. I’m familiar with Phishing, but Phishing myself seems a bit too easy. Thank you in advance
submitted by /u/Caveman0149
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
New to hacking
So like the title says, I’m new to hacking. I’ve set up a few fake accounts of Social Media (Instagram and Snapchat )and I wanted to ask if there...
WardenSwap is partnering up with Valix Consulting to strengthen the security support
https://medium.com/wardenofficial/wardenswap-is-partnering-up-with-valix-consulting-to-strengthen-the-security-support-d04b63d55fc3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/wardenofficial/wardenswap-is-partnering-up-with-valix-consulting-to-strengthen-the-security-support-d04b63d55fc3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
WardenSwap is partnering up with Valix Consulting to strengthen the security support
On the 14th of March, WardenSwap has to launch a Bug Bounty Program with a reward of up to $100,000 USD on Immunefi.
On the 14th of March, WardenSwap has to launch a Bug Bounty Program with a reward of up to $100,000 USD on Immunefi.Continue reading on WARDEN Official » (https://medium.com/wardenofficial/wardenswap-is-partnering-up-with-valix-consulting-to-strengthen-the-security-support-d04b63d55fc3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
WardenSwap is partnering up with Valix Consulting to strengthen the security support
On the 14th of March, WardenSwap has to launch a Bug Bounty Program with a reward of up to $100,000 USD on Immunefi.
WardenSwap is partnering up with Valix Consulting to strengthen the security support
On the 14th of March, WardenSwap has to launch a Bug Bounty Program with a reward of up to $100,000 USD on Immunefi.Continue reading on WARDEN Official »
Read more...
On the 14th of March, WardenSwap has to launch a Bug Bounty Program with a reward of up to $100,000 USD on Immunefi.Continue reading on WARDEN Official »
Read more...
Stunner - Tool To Test And Exploit STUN, TURN And TURN Over TCP Servers
http://www.kitploit.com/2022/05/stunner-tool-to-test-and-exploit-stun.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/stunner-tool-to-test-and-exploit-stun.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Stunner - Tool To Test And Exploit STUN, TURN And TURN Over TCP Servers
Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers. TURN is a protocol mostly used in videoconferencing and audio chats (WebRTC). If you find a misconfigured server you can use this tool to open a local socks proxy that relays all traffic via the TURN protocol into the internal network behind the server. I developed this tool during a test of Cisco Expressway which resulted in some vulnerabilities: https://firefart.at/post/multiple_vulnerabilities_cisco_expressway/ To get the required username and password you need to fetch them using an out-of-band method like sniffing the Connect request from a web browser with Burp. I added an example workflow (https://github.com/firefart/stunner#example-workflow) at the bottom of the readme on how you would test such a server.
LICENSE This work is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by-nc-sa/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA. implemented RFCs STUN: RFC 5389 (https://datatracker.ietf.org/doc/html/rfc5389) TURN: RFC 5766 (https://datatracker.ietf.org/doc/html/rfc5766) TURN for TCP: RFC 6062 (https://datatracker.ietf.org/doc/html/rfc6062) TURN Extension for IPv6: RFC 6156 (https://datatracker.ietf.org/doc/html/rfc6156) Available Commands info This command will print some info about the stun or turn server like supported protocols and attributes like the used software. Options --debug, -d enable debug output (default: false) --turnserver value, -s value turn server to connect to in the format host:port --tls Use TLS for connecting (false in most tests) (default: false) --timeout value connect timeout to turn server (default: 1s) --help, -h show help (default: false) Example --debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS for connecting (false in most tests) (default: false)
--timeout value connect timeout to turn server (default: 1s)
--help, -h show help (default: false)
range-scan This command tries several private and restricted ranges to see if the TURN server is configured to allow connections to the specified IP addresses. If a specific range is not prohibited you can enumerate this range further with the other provided commands. If an ip is reachable it means the TURN server will forward traffic to this IP. Options --debug, -d enable debug output (default: false) --turnserver value, -s value turn server to connect to in the format host:port --tls Use TLS for connecting (false in most tests) (default: false) --protocol value protocol to use when connecting to the TURN server. Supported values: tcp and udp (default: "udp") --timeout value connect timeout to turn server (default: 1s) --username value, -u value username for the turn server --password value, -p value password for the turn server --help, -h show help (default: false) Example TCP based TURN connection (connection from you the TURN server): ./stunner info -s x.x.x.x:443 UDP based TURN connection (connection from you the TURN server): --debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS for connecting (false in most tests) (default: false)
--protocol value protocol to use when connecting to the TURN server. Supported values: tcp and udp (default: "udp")
--timeout value connect timeout to turn server (default: 1s)
--username value, -u value username for the turn server
___________________________
@hacking_Attack
@Hacking_Video
LICENSE This work is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by-nc-sa/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA. implemented RFCs STUN: RFC 5389 (https://datatracker.ietf.org/doc/html/rfc5389) TURN: RFC 5766 (https://datatracker.ietf.org/doc/html/rfc5766) TURN for TCP: RFC 6062 (https://datatracker.ietf.org/doc/html/rfc6062) TURN Extension for IPv6: RFC 6156 (https://datatracker.ietf.org/doc/html/rfc6156) Available Commands info This command will print some info about the stun or turn server like supported protocols and attributes like the used software. Options --debug, -d enable debug output (default: false) --turnserver value, -s value turn server to connect to in the format host:port --tls Use TLS for connecting (false in most tests) (default: false) --timeout value connect timeout to turn server (default: 1s) --help, -h show help (default: false) Example --debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS for connecting (false in most tests) (default: false)
--timeout value connect timeout to turn server (default: 1s)
--help, -h show help (default: false)
range-scan This command tries several private and restricted ranges to see if the TURN server is configured to allow connections to the specified IP addresses. If a specific range is not prohibited you can enumerate this range further with the other provided commands. If an ip is reachable it means the TURN server will forward traffic to this IP. Options --debug, -d enable debug output (default: false) --turnserver value, -s value turn server to connect to in the format host:port --tls Use TLS for connecting (false in most tests) (default: false) --protocol value protocol to use when connecting to the TURN server. Supported values: tcp and udp (default: "udp") --timeout value connect timeout to turn server (default: 1s) --username value, -u value username for the turn server --password value, -p value password for the turn server --help, -h show help (default: false) Example TCP based TURN connection (connection from you the TURN server): ./stunner info -s x.x.x.x:443 UDP based TURN connection (connection from you the TURN server): --debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS for connecting (false in most tests) (default: false)
--protocol value protocol to use when connecting to the TURN server. Supported values: tcp and udp (default: "udp")
--timeout value connect timeout to turn server (default: 1s)
--username value, -u value username for the turn server
___________________________
@hacking_Attack
@Hacking_Video
firefart
Multiple Vulnerabilities in Cisco Expressway
Some time ago I stumbled across a [HackerOne report](https://hackerone.com/reports/333419) about abusing Slacks TURN server for proxy functionality inside their internal network. I found this interesting and decided to take a look at our videoconferencing…