Hello readers,Continue reading on Medium » (https://medium.com/@tobydavenn/700-bounty-writeup-28ec1f310831?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
$700 Bounty writeup
Hello readers,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking Google
https://cdn-images-1.medium.com/max/1280/1*KIUabNSmXQlwrtFQ8wmQjQ.jpeg
On seeing the title of the article, Many people would be wondering “Man seriously you gonna hack the google ?”
For those people my answer…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking Google
https://cdn-images-1.medium.com/max/1280/1*KIUabNSmXQlwrtFQ8wmQjQ.jpeg
On seeing the title of the article, Many people would be wondering “Man seriously you gonna hack the google ?”
For those people my answer…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking Google
On seeing the title of the article, Many people would be wondering “Man seriously you gonna hack the google ?”
For those people my answer…
For those people my answer…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Write-up: DOM XSS using web messages and JSON.parse @ PortSwigger Academy
https://cdn-images-1.medium.com/max/843/0*rQ9gwaeU0i4KKC3u.png
This write-up for the lab DOM XSS using web messages and JSON.parse is part of my walk-through series for PortSwigger’s Web Security…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Write-up: DOM XSS using web messages and JSON.parse @ PortSwigger Academy
https://cdn-images-1.medium.com/max/843/0*rQ9gwaeU0i4KKC3u.png
This write-up for the lab DOM XSS using web messages and JSON.parse is part of my walk-through series for PortSwigger’s Web Security…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Write-up: DOM XSS using web messages and JSON.parse @ PortSwigger Academy
This write-up for the lab DOM XSS using web messages and JSON.parse is part of my walk-through series for PortSwigger’s Web Security…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Burp Suite: Repeater— Walkthrough
https://cdn-images-1.medium.com/max/763/1*9VVXQ28Zgsa3kye1TZJZhQ.png
Hi! I am making these walkthroughs to keep myself motivated to learn cyber security, and ensure that I remember the knowledge gained by…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: Burp Suite: Repeater— Walkthrough
https://cdn-images-1.medium.com/max/763/1*9VVXQ28Zgsa3kye1TZJZhQ.png
Hi! I am making these walkthroughs to keep myself motivated to learn cyber security, and ensure that I remember the knowledge gained by…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: Burp Suite: Repeater— Walkthrough
Hi! I am making these walkthroughs to keep myself motivated to learn cyber security, and ensure that I remember the knowledge gained by…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Base de datos de Elasticsearch son reemplazados con una nota de rescate
https://cdn-images-1.medium.com/max/1595/0*_21D3zDfTWuceGaD
PUBLICADO EN 10 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Base de datos de Elasticsearch son reemplazados con una nota de rescate
https://cdn-images-1.medium.com/max/1595/0*_21D3zDfTWuceGaD
PUBLICADO EN 10 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Base de datos de Elasticsearch son reemplazados con una nota de rescate
PUBLICADO EN 10 JUNIO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
$700 Bounty writeup
https://cdn-images-1.medium.com/max/1284/0*YNU6cwU7dnYDKzzQ
Hello readers,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
$700 Bounty writeup
https://cdn-images-1.medium.com/max/1284/0*YNU6cwU7dnYDKzzQ
Hello readers,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
$700 Bounty writeup
Hello readers,
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Admin-Panel_Finder - A Burp Suite Extension That Enumerates Infrastructure And Application Admin Interfaces (OTG-CONFIG-005)
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjv31YP2Sqe_AahVNAQBpaPK6Y68_VabMVrpxwqGxwIHUOEORglgWC0c0xKEMwQywVAWUYVOlxQhc3UDoNRkcI-DytV0AZ7xU4MBa9FSh-55wj-DQL5cuRPV-4Fe5UxW_4r9hI_N8wt1p7Vfp6cMP3gcFgkY4umJnxrhgG6CslOuv4_6nukjMata86k/w640-h524/burpsuite.png
A burp suite extension that enumerates infrastructure and application Admin Interfaces.
OWASP References:
* Classification: Web Application Security Testing > 02-Configuration and Deployment Management Testing
* OTG v4: OWASP OTG-CONFIG-005
* WSTG: WSTG-CONF-05
Why should I use this extension?
* Multi-thread
* Different and configurable levels of test.
* Includable status codes
* Excludable status codes
* More than 1000 built-in payloads.
* You can load your dictionary.
* Editable root directory
* Automatic detection of used technologies to generate custom payloads.
* Passive listening to find login pages.
Installation
The quickest way is to load the jar file (adminPanelFinder.jar) in the extender tab of the Burpsuite.
Extender -> Extensions -> Add
A new tab will be added to the burp suite.
Quick Start
1. Select a request of a target host from any tab of the burp suite (it must have a response with any status code)
2. In the "Admin Panel Finder -> options" tab, apply your configurations.
3. Go to the "Admin Panel Finder -> Finder -> Finder" tab and click on the "start" button.
Some of the options
These options can be used to customize the detection:
* Level: Level of tests to perform (1-5, default 3)
* Thread: num of threads (1-50, default 10)
* Built-in dictionary: there is a built-in dictionary containing the most used directory and file names to be used for static payload generation.
* Loadable dictionary: you can use your dictionary file for static payload generation.
* HTTP method: HTTP method to be used in requests (HEAD, GET)(default: Head)
* Extension: The extension used in application pages. [Example: php, asp, aspx, jsp, ...]
* Root Dir: The path to the root directory of the web application. (Default: /)
* Includable status codes
* Excludable status codes
Disclaimer
This program is for educational purpose ONLY. Do not use it without permission. The usual disclaimer applies, especially the fact that I'm not liable for any damages caused by the direct or indirect use of the information or functionality provided by these programs. The author or any Internet provider bears NO responsibility for content or misuse of these programs or any derivatives thereof. By using these programs you accept the fact that any damage (data loss, system crash, system compromise, etc.) caused by the use of this program is not my responsibility.
Contact
If you have any further questions, please don't hesitate to contact me via my twitter account.
Download Admin-Panel_Finder
___________________________
@hacking_Attack
@Hacking_Video
Admin-Panel_Finder - A Burp Suite Extension That Enumerates Infrastructure And Application Admin Interfaces (OTG-CONFIG-005)
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjv31YP2Sqe_AahVNAQBpaPK6Y68_VabMVrpxwqGxwIHUOEORglgWC0c0xKEMwQywVAWUYVOlxQhc3UDoNRkcI-DytV0AZ7xU4MBa9FSh-55wj-DQL5cuRPV-4Fe5UxW_4r9hI_N8wt1p7Vfp6cMP3gcFgkY4umJnxrhgG6CslOuv4_6nukjMata86k/w640-h524/burpsuite.png
A burp suite extension that enumerates infrastructure and application Admin Interfaces.
OWASP References:
* Classification: Web Application Security Testing > 02-Configuration and Deployment Management Testing
* OTG v4: OWASP OTG-CONFIG-005
* WSTG: WSTG-CONF-05
Why should I use this extension?
* Multi-thread
* Different and configurable levels of test.
* Includable status codes
* Excludable status codes
* More than 1000 built-in payloads.
* You can load your dictionary.
* Editable root directory
* Automatic detection of used technologies to generate custom payloads.
* Passive listening to find login pages.
Installation
The quickest way is to load the jar file (adminPanelFinder.jar) in the extender tab of the Burpsuite.
Extender -> Extensions -> Add
A new tab will be added to the burp suite.
Quick Start
1. Select a request of a target host from any tab of the burp suite (it must have a response with any status code)
2. In the "Admin Panel Finder -> options" tab, apply your configurations.
3. Go to the "Admin Panel Finder -> Finder -> Finder" tab and click on the "start" button.
Some of the options
These options can be used to customize the detection:
* Level: Level of tests to perform (1-5, default 3)
* Thread: num of threads (1-50, default 10)
* Built-in dictionary: there is a built-in dictionary containing the most used directory and file names to be used for static payload generation.
* Loadable dictionary: you can use your dictionary file for static payload generation.
* HTTP method: HTTP method to be used in requests (HEAD, GET)(default: Head)
* Extension: The extension used in application pages. [Example: php, asp, aspx, jsp, ...]
* Root Dir: The path to the root directory of the web application. (Default: /)
* Includable status codes
* Excludable status codes
Disclaimer
This program is for educational purpose ONLY. Do not use it without permission. The usual disclaimer applies, especially the fact that I'm not liable for any damages caused by the direct or indirect use of the information or functionality provided by these programs. The author or any Internet provider bears NO responsibility for content or misuse of these programs or any derivatives thereof. By using these programs you accept the fact that any damage (data loss, system crash, system compromise, etc.) caused by the use of this program is not my responsibility.
Contact
If you have any further questions, please don't hesitate to contact me via my twitter account.
Download Admin-Panel_Finder
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Admin-Panel_Finder - A Burp Suite Extension That Enumerates Infrastructure And Application Admin Interfaces (OTG-CONFIG-005)
IOC-based threat hunting for free and without registration
https://www.reddit.com/r/redteamsec/comments/vdo8di/iocbased_threat_hunting_for_free_and_without/
submitted by /u/Cultural_Budget6627 (https://www.reddit.com/user/Cultural_Budget6627)
[link] (https://socprime.com/blog/uncoder-cti-step-by-step-guidelines/) [comments] (https://www.reddit.com/r/redteamsec/comments/vdo8di/iocbased_threat_hunting_for_free_and_without/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/vdo8di/iocbased_threat_hunting_for_free_and_without/
submitted by /u/Cultural_Budget6627 (https://www.reddit.com/user/Cultural_Budget6627)
[link] (https://socprime.com/blog/uncoder-cti-step-by-step-guidelines/) [comments] (https://www.reddit.com/r/redteamsec/comments/vdo8di/iocbased_threat_hunting_for_free_and_without/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
IOC-based threat hunting for free and without registration
Posted in r/redteamsec by u/Cultural_Budget6627 • 1 point and 0 comments
All onliners for bug bounty hunters
https://thinkermaruf.medium.com/all-onliners-for-bug-bounty-hunters-7f77f5bd41b?source=rss------bug_bounty-5
check all oneliners below.Continue reading on Medium » (https://thinkermaruf.medium.com/all-onliners-for-bug-bounty-hunters-7f77f5bd41b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://thinkermaruf.medium.com/all-onliners-for-bug-bounty-hunters-7f77f5bd41b?source=rss------bug_bounty-5
check all oneliners below.Continue reading on Medium » (https://thinkermaruf.medium.com/all-onliners-for-bug-bounty-hunters-7f77f5bd41b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
All onliners for bug bounty hunters
check all oneliners below.
The Helio Bounty Program is now live
https://medium.com/@Helio-HAY/the-helio-bounty-program-is-now-live-dc95b52d0674?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Helio-HAY/the-helio-bounty-program-is-now-live-dc95b52d0674?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Helio Bounty Program is now live
We are pleased to announce the official start of the Helio Bounty Program for our community and security researchers. It is critical to…
We are pleased to announce the official start of the Helio Bounty Program for our community and security researchers. It is critical to…Continue reading on Medium » (https://medium.com/@Helio-HAY/the-helio-bounty-program-is-now-live-dc95b52d0674?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Helio Bounty Program is now live
We are pleased to announce the official start of the Helio Bounty Program for our community and security researchers. It is critical to…
hacking: security in practice
Is it possible to grab an IP from someone without them looking at anything you send?
I am in a really bad situation right now, where my boyfriends ex girlfriend sent me screenshots of his old account on a roleplaying app suddenly active again. He claims they shared the account, and that it’s her on there and she’s lying, that he doesn’t even know the account details anymore. When confronting her she was very aggressive, called us a bunch of names, and blocked us. I do not know that I can trust him though about this situation. Is there any way i could pay someone to simply tell me the country they’re logging into the account from? Anything like that. They live in two separate countries. Figuring this out would really help.
submitted by /u/throwaway00110011006
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to grab an IP from someone without them looking at anything you send?
I am in a really bad situation right now, where my boyfriends ex girlfriend sent me screenshots of his old account on a roleplaying app suddenly active again. He claims they shared the account, and that it’s her on there and she’s lying, that he doesn’t even know the account details anymore. When confronting her she was very aggressive, called us a bunch of names, and blocked us. I do not know that I can trust him though about this situation. Is there any way i could pay someone to simply tell me the country they’re logging into the account from? Anything like that. They live in two separate countries. Figuring this out would really help.
submitted by /u/throwaway00110011006
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to grab an IP from someone without them looking at...
I am in a really bad situation right now, where my boyfriends ex girlfriend sent me screenshots of his old account on a roleplaying app suddenly...
hacking: security in practice
scammed
Hi i got scammed by bizum and i want to know Who did that but i only have thr phone number, is there any way to do that?
submitted by /u/dani_campas
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
scammed
Hi i got scammed by bizum and i want to know Who did that but i only have thr phone number, is there any way to do that?
submitted by /u/dani_campas
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
scammed
Hi i got scammed by bizum and i want to know Who did that but i only have thr phone number, is there any way to do that?