Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Callow

Is there anyway to use "Callow" to brute force a website with no username. The website im trying it on is for an internet mystery and the page only needs a password no username but the program requires one (to the best of my knowledge. GitHub for Callow (edit: grammar)

submitted by /u/_TheOneTrueBean_
[link] [comments]
hacking: security in practice
How do I turn off tamper protection through powershell?

I'm trying to do a reverse shell attack on my windows computer from my linux vm, and the to run the powershell script on the client side, i need to disable real time protection manually, but i figured out a way to disable it by a powershell script, but to run the script and disable real time protection, first i need to disable tamper protection...So is there a way to disable tamper protection through a powershell command?

submitted by /u/Aryangsuktekar
[link] [comments]
hacking: security in practice
DrayTek Bruteforce

Hi, few days ago i got my hands on a DrayTek Vigor2760 router to use as a modem for my home network, however once i reset the router, it did not go back to the default credentials, i got in touch with DrayTek, and they advised it is likely for it to be a custom firmware, and they are unable to help, They advised its best to get in touch with the supplier of the router for the default credentials. not knowing who the supplier is, i attempted to bruteforce the webapp using OWASP zap. after having a look at the post request that is sent to the router, i could see that the fields that are sent out are more than username and password.

aa=dGVzdA%3D%3D&ab=AA%3D%3D&sslgroup=-1&sFormAuthStr=R8riZC8XxeWxi5t

breaking this down i could see that there are these fields: aa: this seems to be the username is BASE64 encoding ab: password in BASE64 sslgroup: looking at the name i can see its probably has to do with the HTTPS or smth but please let me know if im wrong. and lastly, sFormAuthStr.

looking at these fields, what is the best way to attack this webapp, any ideas or approaches i need to try? any links that i can have a look at that guides me to the right direcion?

it is worth mentioning that there is nothing illegal going on and i own the router, it was given to me by a friend who had this collecting dust in his attic.

Thank you :)

submitted by /u/h0ly_k0w
[link] [comments]
We walk you through how to use the AllianceBlock DEX, as well as some updates on our progress on the development since we launched.Continue reading on Medium » (https://allianceblock.medium.com/abdex-getting-started-with-abdex-on-mainnet-c83591511fa0?source=rss------bug_bounty-5)
Getting Started with AllianceBlock DEX on Mainnet

We walk you through how to use the AllianceBlock DEX, as well as some updates on our progress on the development since we launched.Continue reading on Medium »
Read more...