Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
Hall of Fame Vice Media ? hacking while sleepy…
https://cdn-images-1.medium.com/max/600/1*XjUTVqsfCGuDBL157twoog.gif
Hello guys, actually this is the case in 2021 but only now had time to write. So… have you ever heard of Vice media? one of the largest…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hall of Fame Vice Media ? hacking while sleepy…
https://cdn-images-1.medium.com/max/600/1*XjUTVqsfCGuDBL157twoog.gif
Hello guys, actually this is the case in 2021 but only now had time to write. So… have you ever heard of Vice media? one of the largest…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hall of Fame Vice Media ? hacking while sleepy…
Hello guys, actually this is the case in 2021 but only now had time to write. So… have you ever heard of Vice media? one of the largest…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PIRATAS DEL SIGLO XXI | Con Nombre de Podcast 03x40
https://cdn-images-1.medium.com/max/1600/0*-YA3Cm29g21S0aL-.jpg
Cuando se habla de piratas normalmente se nos viene a la cabeza la figura de cualquiera de los integrantes de la piratería tradicional que…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PIRATAS DEL SIGLO XXI | Con Nombre de Podcast 03x40
https://cdn-images-1.medium.com/max/1600/0*-YA3Cm29g21S0aL-.jpg
Cuando se habla de piratas normalmente se nos viene a la cabeza la figura de cualquiera de los integrantes de la piratería tradicional que…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PIRATAS DEL SIGLO XXI | Con Nombre de Podcast 03x40
Cuando se habla de piratas normalmente se nos viene a la cabeza la figura de cualquiera de los integrantes de la piratería tradicional que…
hacking: security in practice
Is my Smart Bulb trying to hack into my Windows devices?
Today I was trying to connect to a VPN on Windows 10 and was having trouble. I looked in Event Viewer because the VPN dialog was only displaying a general message when it failed to connect.
After looking through the Application logs, I looked at the Security logs and saw some Audit Failures.
Well, looking at the details of those audit failures, the source was an IP on my network. When I tracked down which device it was, it ended up being a Smart LED bulb I have in my living room.
That seems very unusual to me, but I dont really know much about security audits in Windows. I noticed a couple other audit failures coming from my Google home and Vizio TV. From what I am able to find, the Audit Failure is a failed logon attempt. I don't know any other reason a network device would be attempting to access anything on my PC.
Am I just being paranoid?
submitted by /u/TwoCharacters
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is my Smart Bulb trying to hack into my Windows devices?
Today I was trying to connect to a VPN on Windows 10 and was having trouble. I looked in Event Viewer because the VPN dialog was only displaying a general message when it failed to connect.
After looking through the Application logs, I looked at the Security logs and saw some Audit Failures.
Well, looking at the details of those audit failures, the source was an IP on my network. When I tracked down which device it was, it ended up being a Smart LED bulb I have in my living room.
That seems very unusual to me, but I dont really know much about security audits in Windows. I noticed a couple other audit failures coming from my Google home and Vizio TV. From what I am able to find, the Audit Failure is a failed logon attempt. I don't know any other reason a network device would be attempting to access anything on my PC.
Am I just being paranoid?
submitted by /u/TwoCharacters
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is my Smart Bulb trying to hack into my Windows devices?
Today I was trying to connect to a VPN on Windows 10 and was having trouble. I looked in Event Viewer because the VPN dialog was only displaying a...
Which Linux distro do you use for pentesting?
https://www.reddit.com/r/Pentesting/comments/v07yw0/which_linux_distro_do_you_use_for_pentesting/
Currently want to switch my distros a bit so I wanted to hear a bit from the community. Planning on switching to Linux Mint from Arch. Yes, I love distro hopping. submitted by /u/bacamruze (https://www.reddit.com/user/bacamruze)
[link] (https://www.reddit.com/r/Pentesting/comments/v07yw0/which_linux_distro_do_you_use_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/v07yw0/which_linux_distro_do_you_use_for_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/v07yw0/which_linux_distro_do_you_use_for_pentesting/
Currently want to switch my distros a bit so I wanted to hear a bit from the community. Planning on switching to Linux Mint from Arch. Yes, I love distro hopping. submitted by /u/bacamruze (https://www.reddit.com/user/bacamruze)
[link] (https://www.reddit.com/r/Pentesting/comments/v07yw0/which_linux_distro_do_you_use_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/v07yw0/which_linux_distro_do_you_use_for_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Which Linux distro do you use for pentesting?
Currently want to switch my distros a bit so I wanted to hear a bit from the community. Planning on switching to Linux Mint from Arch. Yes, I...
Killing The Bear - Cybercrime repo, Threat Actors, Campaigns, Malware, IOCs
https://www.reddit.com/r/redteamsec/comments/v08tn1/killing_the_bear_cybercrime_repo_threat_actors/
Killing The Bear (https://preview.redd.it/i9lkuufice291.png?width=531&format=png&auto=webp&s=02c79e4e4687af832d8965924a81ac135a3da68b) Hi everyone! I want to share with you my new gitbook/repo about Threat Actors: Killing The Bear (https://killingthebear.jorgetesta.tech/). Very useful for SOC, CTI and Threat Hunting teams. In it you can find: - Threat Actors - Malware - Tools - TTPs - IOCs - Summary (executive) - Wallets - Timeline - Relationships - Etc... Yesterday I published the "Killnet" category, you can find it here: Killnet - Actor (https://killingthebear.jorgetesta.tech/killnet/summary) Gradually more categories are being added with more intel. I hope it will be useful to you or your team. Thank you! submitted by /u/J-Testa (https://www.reddit.com/user/J-Testa)
[link] (https://www.reddit.com/r/redteamsec/comments/v08tn1/killing_the_bear_cybercrime_repo_threat_actors/) [comments] (https://www.reddit.com/r/redteamsec/comments/v08tn1/killing_the_bear_cybercrime_repo_threat_actors/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/v08tn1/killing_the_bear_cybercrime_repo_threat_actors/
Killing The Bear (https://preview.redd.it/i9lkuufice291.png?width=531&format=png&auto=webp&s=02c79e4e4687af832d8965924a81ac135a3da68b) Hi everyone! I want to share with you my new gitbook/repo about Threat Actors: Killing The Bear (https://killingthebear.jorgetesta.tech/). Very useful for SOC, CTI and Threat Hunting teams. In it you can find: - Threat Actors - Malware - Tools - TTPs - IOCs - Summary (executive) - Wallets - Timeline - Relationships - Etc... Yesterday I published the "Killnet" category, you can find it here: Killnet - Actor (https://killingthebear.jorgetesta.tech/killnet/summary) Gradually more categories are being added with more intel. I hope it will be useful to you or your team. Thank you! submitted by /u/J-Testa (https://www.reddit.com/user/J-Testa)
[link] (https://www.reddit.com/r/redteamsec/comments/v08tn1/killing_the_bear_cybercrime_repo_threat_actors/) [comments] (https://www.reddit.com/r/redteamsec/comments/v08tn1/killing_the_bear_cybercrime_repo_threat_actors/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Killing The Bear - Cybercrime repo, Threat Actors, Campaigns,...
Posted in r/redteamsec by u/J-Testa • 1 point and 0 comments
Hakoriginfinder - Tool For Discovering The Origin Host Behind A Reverse Proxy. Useful For Bypassing Cloud WAFs!
http://www.kitploit.com/2022/05/hakoriginfinder-tool-for-discovering.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/hakoriginfinder-tool-for-discovering.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Hakoriginfinder - Tool For Discovering The Origin Host Behind A Reverse Proxy. Useful For Bypassing Cloud WAFs!
Tool for discovering the origin host behind a reverse (https://www.kitploit.com/search/label/Reverse) proxy. Useful for bypassing (https://www.kitploit.com/search/label/Bypassing) WAFs and other reverse proxies. How does it work? This tool will first make a HTTP request to the hostname that you provide and store the response, then it will make a request to every IP address that you provide via HTTP (80) and HTTPS (443), with the Host header set to the original host. Each HTTP response is then compared to the original using the Levenshtein algorithm to determine similarity. If the response is similar, it will be deemed a match.
Usage Provide the list of IP addresses via stdin, and the original hostname via the -h option. For example: prips 93.184.216.0/24 | hakoriginfinder -h example.com
You may set the Levenshtein distance threshold with -l. The lower the number, the more similar the matches need to be for it to be considered a match, the default is 5. The number of threads may be set with -t, default is 32. The hostname is set with -h, there is no default. Output The output is 3 columns, separated by spaces. The first column is either "MATCH" or "NOMATCH" depending on whether the Levenshtein threshold was reached or not. The second column is the URL being teseted, and the third column is the Levenshtein score. Output example hakluke$ prips 1.1.1.0/24 | hakoriginfinder -h one.one.one.one
NOMATCH http://1.1.1.0 54366
NOMATCH http://1.1.1.30 54366
NOMATCH http://1.1.1.20 54366
NOMATCH http://1.1.1.4 54366
NOMATCH http://1.1.1.11 54366
NOMATCH http://1.1.1.5 54366
NOMATCH http://1.1.1.22 54366
NOMATCH http://1.1.1.13 54366
NOMATCH http://1.1.1.10 54366
NOMATCH http://1.1.1.25 54366
NOMATCH http://1.1.1.19 54366
... snipped for brevity ...
NOMATCH http://1.1.1.251 54366
NOMATCH http://1.1.1.248 54366
MATCH http://1.1.1.1 0
NOMATCH http://1.1.1.3 19567
NOMATCH http://1.1.1.2 19517
MATCH https://1.1.1.1 0
NOMATCH https://1.1.1.3 19534
NOMATCH https://1.1.1.2 19532
Installation Install golang, then run: go install github.com/hakluke/hakoriginfinder@latest
Download Hakoriginfinder (https://github.com/hakluke/hakoriginfinder)
___________________________
@hacking_Attack
@Hacking_Video
Usage Provide the list of IP addresses via stdin, and the original hostname via the -h option. For example: prips 93.184.216.0/24 | hakoriginfinder -h example.com
You may set the Levenshtein distance threshold with -l. The lower the number, the more similar the matches need to be for it to be considered a match, the default is 5. The number of threads may be set with -t, default is 32. The hostname is set with -h, there is no default. Output The output is 3 columns, separated by spaces. The first column is either "MATCH" or "NOMATCH" depending on whether the Levenshtein threshold was reached or not. The second column is the URL being teseted, and the third column is the Levenshtein score. Output example hakluke$ prips 1.1.1.0/24 | hakoriginfinder -h one.one.one.one
NOMATCH http://1.1.1.0 54366
NOMATCH http://1.1.1.30 54366
NOMATCH http://1.1.1.20 54366
NOMATCH http://1.1.1.4 54366
NOMATCH http://1.1.1.11 54366
NOMATCH http://1.1.1.5 54366
NOMATCH http://1.1.1.22 54366
NOMATCH http://1.1.1.13 54366
NOMATCH http://1.1.1.10 54366
NOMATCH http://1.1.1.25 54366
NOMATCH http://1.1.1.19 54366
... snipped for brevity ...
NOMATCH http://1.1.1.251 54366
NOMATCH http://1.1.1.248 54366
MATCH http://1.1.1.1 0
NOMATCH http://1.1.1.3 19567
NOMATCH http://1.1.1.2 19517
MATCH https://1.1.1.1 0
NOMATCH https://1.1.1.3 19534
NOMATCH https://1.1.1.2 19532
Installation Install golang, then run: go install github.com/hakluke/hakoriginfinder@latest
Download Hakoriginfinder (https://github.com/hakluke/hakoriginfinder)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
I call it AI SCI FI — I asked an artificial intelligence to help me write science fiction
https://cdn-images-1.medium.com/max/600/1*oWtSG1xic1OvKYQFIopYzQ.jpeg
Alien invasions are easily one of the most common tropes in science fiction.
Continue reading on Medium »
I call it AI SCI FI — I asked an artificial intelligence to help me write science fiction
https://cdn-images-1.medium.com/max/600/1*oWtSG1xic1OvKYQFIopYzQ.jpeg
Alien invasions are easily one of the most common tropes in science fiction.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Hakoriginfinder - Tool For Discovering The Origin Host Behind A Reverse Proxy. Useful For Bypassing Cloud WAFs!
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGaTtU1rZxmpX3ztLJIXP89nGuh_dUnTAF1aAGcxU1cHXi-KFYu_EfOB0FIj8WPecfoHaflMhgVixIc2_G74UtM-F4PkGOYP7taCNMXXfnuSm2vCsMe80FXEyfXCvRUVuQyIR1rPqzlvX7F4bQ72jUFn0_FGDf4_vBvkBELKhTof5ymZ9_HO99D7RK/w640-h330/hakoriginfinder.png
Tool for discovering the origin host behind a reverse proxy. Useful for bypassing WAFs and other reverse proxies.
How does it work?
This tool will first make a HTTP request to the hostname that you provide and store the response, then it will make a request to every IP address that you provide via HTTP (80) and HTTPS (443), with the
Usage
Provide the list of IP addresses via stdin, and the original hostname via the -h option. For example:
You may set the Levenshtein distance threshold with
The number of threads may be set with
The hostname is set with
Output
The output is 3 columns, separated by spaces. The first column is either "MATCH" or "NOMATCH" depending on whether the Levenshtein threshold was reached or not. The second column is the URL being teseted, and the third column is the Levenshtein score.
Output example
Installation
Install golang, then run:
Download Hakoriginfinder
Hakoriginfinder - Tool For Discovering The Origin Host Behind A Reverse Proxy. Useful For Bypassing Cloud WAFs!
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGaTtU1rZxmpX3ztLJIXP89nGuh_dUnTAF1aAGcxU1cHXi-KFYu_EfOB0FIj8WPecfoHaflMhgVixIc2_G74UtM-F4PkGOYP7taCNMXXfnuSm2vCsMe80FXEyfXCvRUVuQyIR1rPqzlvX7F4bQ72jUFn0_FGDf4_vBvkBELKhTof5ymZ9_HO99D7RK/w640-h330/hakoriginfinder.png
Tool for discovering the origin host behind a reverse proxy. Useful for bypassing WAFs and other reverse proxies.
How does it work?
This tool will first make a HTTP request to the hostname that you provide and store the response, then it will make a request to every IP address that you provide via HTTP (80) and HTTPS (443), with the
Hostheader set to the original host. Each HTTP response is then compared to the original using the Levenshtein algorithm to determine similarity. If the response is similar, it will be deemed a match.Usage
Provide the list of IP addresses via stdin, and the original hostname via the -h option. For example:
prips 93.184.216.0/24 | hakoriginfinder -h example.com
You may set the Levenshtein distance threshold with
-l. The lower the number, the more similar the matches need to be for it to be considered a match, the default is 5.The number of threads may be set with
-t, default is 32.The hostname is set with
-h, there is no default.Output
The output is 3 columns, separated by spaces. The first column is either "MATCH" or "NOMATCH" depending on whether the Levenshtein threshold was reached or not. The second column is the URL being teseted, and the third column is the Levenshtein score.
Output example
hakluke$ prips 1.1.1.0/24 | hakoriginfinder -h one.one.one.one
NOMATCH http://1.1.1.0 54366
NOMATCH http://1.1.1.30 54366
NOMATCH http://1.1.1.20 54366
NOMATCH http://1.1.1.4 54366
NOMATCH http://1.1.1.11 54366
NOMATCH http://1.1.1.5 54366
NOMATCH http://1.1.1.22 54366
NOMATCH http://1.1.1.13 54366
NOMATCH http://1.1.1.10 54366
NOMATCH http://1.1.1.25 54366
NOMATCH http://1.1.1.19 54366
... snipped for brevity ...
NOMATCH http://1.1.1.251 54366
NOMATCH http://1.1.1.248 54366
MATCH http://1.1.1.1 0
NOMATCH http://1.1.1.3 19567
NOMATCH http://1.1.1.2 19517
MATCH https://1.1.1.1 0
NOMATCH https://1.1.1.3 19534
NOMATCH https://1.1.1.2 19532
Installation
Install golang, then run:
go install github.com/hakluke/hakoriginfinder@latest
Download Hakoriginfinder
CYBERSOC Information Technology Library Blog
https://www.reddit.com/r/redteamsec/comments/v0bu9b/cybersoc_information_technology_library_blog/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://www.reddit.com/r/cybersocitlibrary/comments/v0bjud/cybersoc_information_technology_library_blog/) [comments] (https://www.reddit.com/r/redteamsec/comments/v0bu9b/cybersoc_information_technology_library_blog/)
https://www.reddit.com/r/redteamsec/comments/v0bu9b/cybersoc_information_technology_library_blog/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://www.reddit.com/r/cybersocitlibrary/comments/v0bjud/cybersoc_information_technology_library_blog/) [comments] (https://www.reddit.com/r/redteamsec/comments/v0bu9b/cybersoc_information_technology_library_blog/)
In the past few days, I am recharging myself by trying my hands at different rooms present in tryhackme TryHackMe. So thought why not just…Continue reading on Medium » (https://medium.com/@amyrahm786/biblioteca-walkthrough-thm-69946c555252?source=rss------bug_bounty-5)
DOMAIN ADMIN Compromise in 3 HOURS
https://popalltheshells.medium.com/domain-admin-compromise-in-3-hours-5778902604c9?source=rss------bug_bounty-5
https://popalltheshells.medium.com/domain-admin-compromise-in-3-hours-5778902604c9?source=rss------bug_bounty-5
Hi everyone; I hope you enjoyed my previous blog post on “How I obtained Admin access in 30 minutes” — so today I am bringing you another…Continue reading on Medium » (https://popalltheshells.medium.com/domain-admin-compromise-in-3-hours-5778902604c9?source=rss------bug_bounty-5)
Biblioteca Walkthrough:THM
In the past few days, I am recharging myself by trying my hands at different rooms present in tryhackme TryHackMe. So thought why not just…Continue reading on Medium »
Read more...
In the past few days, I am recharging myself by trying my hands at different rooms present in tryhackme TryHackMe. So thought why not just…Continue reading on Medium »
Read more...