Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
From blind SSRF to localhost dirbusting and asset enumeration
https://cdn-images-1.medium.com/max/789/1*0SZ7naSUSS3FbzOuBZ-cNQ.png
Story about how inconsistent printing of img alt tag in WeasyPrint pdf generator can turn blind SSRF into localhost dirbuster.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
From blind SSRF to localhost dirbusting and asset enumeration
https://cdn-images-1.medium.com/max/789/1*0SZ7naSUSS3FbzOuBZ-cNQ.png
Story about how inconsistent printing of img alt tag in WeasyPrint pdf generator can turn blind SSRF into localhost dirbuster.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
From blind SSRF to localhost dirbusting and asset enumeration
Story about how inconsistent printing of img alt tag in WeasyPrint pdf generator can turn blind SSRF into localhost dirbuster.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Everything You need to know about Pegasus
If you were been told that Jeff Bezos can get hacked and his private messages with his ex-wife was released, and was been threatened that…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Everything You need to know about Pegasus
If you were been told that Jeff Bezos can get hacked and his private messages with his ex-wife was released, and was been threatened that…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Everything You need to know about Pegasus
If you were been told that Jeff Bezos can get hacked and his private messages with his ex-wife was released, and was been threatened that…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My first CVE-2022–31289
https://cdn-images-1.medium.com/max/1920/1*bns-TguLQpN0XhIsaEmDqw.png
Authentication Bypass on Sonatype Nexus Repository Manager OSS 3.37.3-02
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My first CVE-2022–31289
https://cdn-images-1.medium.com/max/1920/1*bns-TguLQpN0XhIsaEmDqw.png
Authentication Bypass on Sonatype Nexus Repository Manager OSS 3.37.3-02
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My first CVE-2022–31289
Authentication Bypass on Sonatype Nexus Repository Manager OSS 3.37.3-02
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
WhiteBeam - Transparent Endpoint Security
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpLzN9752QW_e2u4C8O-rX-59axUpFgF4rJLpVbELNWCCCtF-J_CQJ850NZhlNgKj8X99G_CTGdCw-yEya2LTeNIEvkR8Nss03_wnKOB1XBhHkqTJxyQbVZ7L5K42sRRk5_1cOepHYRGy5jVLrHUQMnhAQoere7UJvNfHBMvkj4_oqmlFWr9LyFQH4/w640-h172/WhiteBeam.png
Transparent endpoint security
Features
* Block and detect advanced attacks
* Modern audited cryptography: RustCrypto for hashing and encryption
* Highly compatible: Development focused on all platforms (incl. legacy) and architectures
* Source available: Audits welcome
* Reviewed by security researchers with combined 100+ years of experience
In Action
* Video demonstration of detection and prevention capabilities
* Testing WhiteBeam against zeroday exploits
* Recorded attacks against the WhiteBeam honeypot
Installation
From Packages (Linux)
Distro-specific packages have not been released yet for WhiteBeam, check again soon!
From Releases (Linux)
1. Download the latest release
2. Ensure the release file hash matches the official hashes (How-to)
3. Install:
*
From Source (Linux)
1. Run tests (Optional):
*
2. Compile:
*
3. Install WhiteBeam:
*
Quick start
1. Become root (
2. Set a recovery secret. You'll be able to use this with
How to Detect Attacks with WhiteBeam
Multiple guides are provided depending on your preference. Contact us so we can help you integrate WhiteBeam with your environment.
1. Serverless guide, for passive review
2. osquery Fleet setup guide, for passive review
3. WhiteBeam Server setup guide, for active response
How to Prevent Attacks with WhiteBeam
WhiteBeam is experimental software. Contact us for assistance safely implementing it.
1. Become root (
2. Review the baseline at least 24 hours after installing WhiteBeam:
*
3. Add trusted behavior to the whitelist, following the whitelisting guide
4. Enable WhiteBeam prevention:
*
Download WhiteBeam
___________________________
@hacking_Attack
@Hacking_Video
WhiteBeam - Transparent Endpoint Security
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpLzN9752QW_e2u4C8O-rX-59axUpFgF4rJLpVbELNWCCCtF-J_CQJ850NZhlNgKj8X99G_CTGdCw-yEya2LTeNIEvkR8Nss03_wnKOB1XBhHkqTJxyQbVZ7L5K42sRRk5_1cOepHYRGy5jVLrHUQMnhAQoere7UJvNfHBMvkj4_oqmlFWr9LyFQH4/w640-h172/WhiteBeam.png
Transparent endpoint security
Features
* Block and detect advanced attacks
* Modern audited cryptography: RustCrypto for hashing and encryption
* Highly compatible: Development focused on all platforms (incl. legacy) and architectures
* Source available: Audits welcome
* Reviewed by security researchers with combined 100+ years of experience
In Action
* Video demonstration of detection and prevention capabilities
* Testing WhiteBeam against zeroday exploits
* Recorded attacks against the WhiteBeam honeypot
Installation
From Packages (Linux)
Distro-specific packages have not been released yet for WhiteBeam, check again soon!
From Releases (Linux)
1. Download the latest release
2. Ensure the release file hash matches the official hashes (How-to)
3. Install:
*
./whitebeam-installer installFrom Source (Linux)
1. Run tests (Optional):
*
cargo run test2. Compile:
*
cargo run build3. Install WhiteBeam:
*
cargo run installQuick start
1. Become root (
sudo su/su root)2. Set a recovery secret. You'll be able to use this with
whitebeam --authto make changes to the system: whitebeam --setting RecoverySecret maskHow to Detect Attacks with WhiteBeam
Multiple guides are provided depending on your preference. Contact us so we can help you integrate WhiteBeam with your environment.
1. Serverless guide, for passive review
2. osquery Fleet setup guide, for passive review
3. WhiteBeam Server setup guide, for active response
How to Prevent Attacks with WhiteBeam
WhiteBeam is experimental software. Contact us for assistance safely implementing it.
1. Become root (
sudo su/su root)2. Review the baseline at least 24 hours after installing WhiteBeam:
*
whitebeam --baseline3. Add trusted behavior to the whitelist, following the whitelisting guide
4. Enable WhiteBeam prevention:
*
whitebeam --setting Prevention trueDownload WhiteBeam
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
WhiteBeam - Transparent Endpoint Security
My first CVE-2022–31289
Authentication Bypass on Sonatype Nexus Repository Manager OSS 3.37.3-02Continue reading on Medium »
Read more...
Authentication Bypass on Sonatype Nexus Repository Manager OSS 3.37.3-02Continue reading on Medium »
Read more...
0 Day Vulnerability — URI Normalization Issue — Access the Internal Tomcat Server
Description:Continue reading on Medium »
Read more...
Description:Continue reading on Medium »
Read more...
Linux is not used at work
https://www.reddit.com/r/Pentesting/comments/va13y0/linux_is_not_used_at_work/
I recently landed my first pentesting job at a super large company, but with a really really small red team area. I am not yet a super expert but all I have learnt about ethical hacking and pentesting was using Linux, specifically Kali. So the question is whether the red team area at work using mainly Windows is kind of normal or should I ask whether it is possible to use Linux to conduct the pentesting activities? submitted by /u/EktorMG (https://www.reddit.com/user/EktorMG)
[link] (https://www.reddit.com/r/Pentesting/comments/va13y0/linux_is_not_used_at_work/) [comments] (https://www.reddit.com/r/Pentesting/comments/va13y0/linux_is_not_used_at_work/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/va13y0/linux_is_not_used_at_work/
I recently landed my first pentesting job at a super large company, but with a really really small red team area. I am not yet a super expert but all I have learnt about ethical hacking and pentesting was using Linux, specifically Kali. So the question is whether the red team area at work using mainly Windows is kind of normal or should I ask whether it is possible to use Linux to conduct the pentesting activities? submitted by /u/EktorMG (https://www.reddit.com/user/EktorMG)
[link] (https://www.reddit.com/r/Pentesting/comments/va13y0/linux_is_not_used_at_work/) [comments] (https://www.reddit.com/r/Pentesting/comments/va13y0/linux_is_not_used_at_work/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Linux is not used at work
I recently landed my first pentesting job at a super large company, but with a really really small red team area. I am not yet a super expert but...
hacking: security in practice
RFID resources
Where can I read about RFID and RFID cloning?
submitted by /u/suspiciously_tasty
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
RFID resources
Where can I read about RFID and RFID cloning?
submitted by /u/suspiciously_tasty
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
RFID resources
Where can I read about RFID and RFID cloning?
hacking: security in practice
Did I get hacked? ok.ru and zendesk.com running in my network apps?(never heard of them) I live in the USA.
I have been dealing with a problem on my pc, and can't find out what it is. so I have tried everything to fix it. fresh windows reset, only crashes when I connect to the internet. I was looking in my network apps and I found an ok.ru and Zendesk.com app on my network. I never heard of them, so I blocked them and now my computer seems to be working okay, for now. should I be worried? I have only a basic understanding of computers.
submitted by /u/Matso12
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Did I get hacked? ok.ru and zendesk.com running in my network apps?(never heard of them) I live in the USA.
I have been dealing with a problem on my pc, and can't find out what it is. so I have tried everything to fix it. fresh windows reset, only crashes when I connect to the internet. I was looking in my network apps and I found an ok.ru and Zendesk.com app on my network. I never heard of them, so I blocked them and now my computer seems to be working okay, for now. should I be worried? I have only a basic understanding of computers.
submitted by /u/Matso12
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Did I get hacked? ok.ru and zendesk.com running in my network...
I have been dealing with a problem on my pc, and can't find out what it is. so I have tried everything to fix it. fresh windows reset, only...
hacking: security in practice
Would there be a use case for this tool?
submitted by /u/The-Lozenger
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Would there be a use case for this tool?
submitted by /u/The-Lozenger
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Would there be a use case for this tool?
Posted in r/hacking by u/The-Lozenger • 1 point and 0 comments
Cross-Platform XSS
https://medium.com/@1337Mo/cross-platform-xss-ac0f1873a793?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@1337Mo/cross-platform-xss-ac0f1873a793?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-Platform XSS
Hello Fellows, In this article, I will demonstrate a vulnerability idea that I have encountered multiple times lately during penetration…
Hello Fellows,
In this article, I will demonstrate a vulnerability idea that I have encountered multiple times lately during penetration…Continue reading on Medium » (https://medium.com/@1337Mo/cross-platform-xss-ac0f1873a793?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
In this article, I will demonstrate a vulnerability idea that I have encountered multiple times lately during penetration…Continue reading on Medium » (https://medium.com/@1337Mo/cross-platform-xss-ac0f1873a793?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-Platform XSS
Hello Fellows, In this article, I will demonstrate a vulnerability idea that I have encountered multiple times lately during penetration…
Authentication Bypass on Sonatype Nexus Repository Manager OSS 3.37.3-02Continue reading on Medium » (https://medium.com/@pmmali/my-first-cve-2022-31289-4081c57e90fb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My first CVE-2022–31289
Authentication Bypass on Sonatype Nexus Repository Manager OSS 3.37.3-02
0 Day Vulnerability — URI Normalization Issue — Access the Internal Tomcat Server
https://medium.com/@Dhamuharker/0-day-vulnerability-uri-normalization-issue-access-the-internal-tomcat-server-8b99d9790519?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Dhamuharker/0-day-vulnerability-uri-normalization-issue-access-the-internal-tomcat-server-8b99d9790519?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
0 Day Vulnerability — URI Normalization Issue — Access the Internal Tomcat Server
Description:
Description:Continue reading on Medium » (https://medium.com/@Dhamuharker/0-day-vulnerability-uri-normalization-issue-access-the-internal-tomcat-server-8b99d9790519?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
0 Day Vulnerability — URI Normalization Issue — Access the Internal Tomcat Server
Description: