normal with python3 app.py then all you have to do is edit the alive and vuln variables defined in the app.py itself. The alive variable is measured in seconds, so if you put 100, then the token expires after 100 seconds. The vuln variable is like boolean, if you set it to 1 then the application is vulnerable, and if you set it to 0 the application is not vulnerable. If you run it through Docker, then you must either pass environment variables to the docker run command or edit the Dockerfile and rebuild. Docker run example: docker run -d -e vulnerable=0 -e tokentimetolive=300 -p 5000:5000 vampire_docker:latest One nice feature to running it this way is you can startup a 2nd container with vulnerable=1 on a different port and flip easily between the two. In the Dockerfile you will find two environment variables being set, the ENV vulnerable=1 and the ENV tokentimetolive=60. Feel free to change it before running the docker build command. Picture from freepik - www.freepik.com (https://www.freepik.com/vectors/party)
Download VAmPI (https://github.com/erev0s/VAmPI)
___________________________
@hacking_Attack
@Hacking_Video
Download VAmPI (https://github.com/erev0s/VAmPI)
___________________________
@hacking_Attack
@Hacking_Video
Freepik
Enjoy these Party Vectors for Free
You can find & download the most popular Party Vectors on Freepik. Remember that these high-quality images are free for commercial use. Freepik is made for creative people like you
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cómo atacar un SQL Server
https://cdn-images-1.medium.com/max/600/1*nVzHDMxlsbYXDa9EQTnP-g.png
Hacemos un escaneo al servidor con nmap.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cómo atacar un SQL Server
https://cdn-images-1.medium.com/max/600/1*nVzHDMxlsbYXDa9EQTnP-g.png
Hacemos un escaneo al servidor con nmap.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cómo atacar un SQL Server
Hacemos un escaneo al servidor con nmap.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
VAmPI - Vulnerable REST API With OWASP Top 10 Vulnerabilities For Security Testing
https://blogger.googleusercontent.com/img/a/AVvXsEiWkXGsybGWZUFpzkXOC_NJd4CzE6cH17TIxQ1Nqufn4lPbV4MDeFlPjFi4F3uT1aLy-GiXz0ER3msn0e9_jGzRc6VOePnLCU_NzBMT6HGyM9O6iis8xQzL7oOZ8zsTEH2P-DSc-Ml-W0UnaIZI3k0OkLsdfO2NFXc_bztQZE-vgkeVTm0xG-U_3OG-=w640-h336 The Vulnerable API (Based on OpenAPI 3)
VAmPI is a vulnerable API made with Flask and it includes vulnerabilities from the OWASP top 10 vulnerabilities for APIs. It was created as I wanted a vulnerable API to evaluate the efficiency of tools used to detect security issues in APIs. It includes a switch on/off to allow the API to be vulnerable or not while testing. This allows to cover better the cases for false positives/negatives. VAmPI can also be used for learning/teaching purposes. You can find a bit more details about the vulnerabilities in erev0s.com. Features* Based on OWASP Top 10 vulnerabilities for APIs.
* OpenAPI3 specs and Postman Collection included.
* Global switch on/off to have a vulnerable environment or not.
* Token-Based Authentication (Adjust lifetime from within app.py)
VAmPI's flow of actions is going like this: an unregistered user can see minimal information about the dummy users included in the API. A user can register and then login to be allowed using the token received during login to post a book. For a book posted the data accepted are the title and a secret about that book. Each book is unique for every user and only the owner of the book should be allowed to view the secret.
A quick rundown of the actions included can be seen in the following table:
Action Path Details GET /createdb Creates and populates the database with dummy data GET / VAmPI home GET /users/v1 Displays all users with basic information GET /users/v1/_debug Displays all details for all users POST /users/v1/register Register new user POST /users/v1/login Login to VAmPI GET /users/v1/{username} Displays user by username DELETE /users/v1/{username} Deletes user by username (Only Admins) PUT /users/v1/{username}/email Update a single users email PUT /users/v1/{username}/password Update users password GET /books/v1 Retrieves all books POST /books/v1 Add new book GET /books/v1/{book} Retrieves book by title along with secret
For more details you can use a service like the swagger editor supplying it the OpenAPI specification which can be found in the directory
* Unauthorized Password Change
* Broken Object Level Authorization
* Mass Assignment
* Excessive Data Exposure through debug endpoint
* User and Password Enumeration
* RegexDOS (Denial of Service)
* Lack of Resources & Rate Limiting Run itIt is a Flask application so in order to run it you can install all requirements and then run the
Or if you prefer you can also run it through docker or docker compose. Run it through DockerBuild with
___________________________
@hacking_Attack
@Hacking_Video
VAmPI - Vulnerable REST API With OWASP Top 10 Vulnerabilities For Security Testing
https://blogger.googleusercontent.com/img/a/AVvXsEiWkXGsybGWZUFpzkXOC_NJd4CzE6cH17TIxQ1Nqufn4lPbV4MDeFlPjFi4F3uT1aLy-GiXz0ER3msn0e9_jGzRc6VOePnLCU_NzBMT6HGyM9O6iis8xQzL7oOZ8zsTEH2P-DSc-Ml-W0UnaIZI3k0OkLsdfO2NFXc_bztQZE-vgkeVTm0xG-U_3OG-=w640-h336 The Vulnerable API (Based on OpenAPI 3)
VAmPI is a vulnerable API made with Flask and it includes vulnerabilities from the OWASP top 10 vulnerabilities for APIs. It was created as I wanted a vulnerable API to evaluate the efficiency of tools used to detect security issues in APIs. It includes a switch on/off to allow the API to be vulnerable or not while testing. This allows to cover better the cases for false positives/negatives. VAmPI can also be used for learning/teaching purposes. You can find a bit more details about the vulnerabilities in erev0s.com. Features* Based on OWASP Top 10 vulnerabilities for APIs.
* OpenAPI3 specs and Postman Collection included.
* Global switch on/off to have a vulnerable environment or not.
* Token-Based Authentication (Adjust lifetime from within app.py)
VAmPI's flow of actions is going like this: an unregistered user can see minimal information about the dummy users included in the API. A user can register and then login to be allowed using the token received during login to post a book. For a book posted the data accepted are the title and a secret about that book. Each book is unique for every user and only the owner of the book should be allowed to view the secret.
A quick rundown of the actions included can be seen in the following table:
Action Path Details GET /createdb Creates and populates the database with dummy data GET / VAmPI home GET /users/v1 Displays all users with basic information GET /users/v1/_debug Displays all details for all users POST /users/v1/register Register new user POST /users/v1/login Login to VAmPI GET /users/v1/{username} Displays user by username DELETE /users/v1/{username} Deletes user by username (Only Admins) PUT /users/v1/{username}/email Update a single users email PUT /users/v1/{username}/password Update users password GET /books/v1 Retrieves all books POST /books/v1 Add new book GET /books/v1/{book} Retrieves book by title along with secret
For more details you can use a service like the swagger editor supplying it the OpenAPI specification which can be found in the directory
openapi_specs. List of Vulnerabilities* SQLi Injection* Unauthorized Password Change
* Broken Object Level Authorization
* Mass Assignment
* Excessive Data Exposure through debug endpoint
* User and Password Enumeration
* RegexDOS (Denial of Service)
* Lack of Resources & Rate Limiting Run itIt is a Flask application so in order to run it you can install all requirements and then run the
app.py. To install all requirements simply run pip3 install -r requirements.txtand then python3 app.py.Or if you prefer you can also run it through docker or docker compose. Run it through DockerBuild with
docker build -t vampi_docker:latest . and Run (remove the -d if you want to see the output in your terminal) docker run -d -p 5000:5000 vampi_docker:latest [Note: if you run Docker on newer versions of the MacOS, use -p 5001:5000to avoid conflicting with the AirPlay Receiver service. Alternatively, you could disable the AirPlay Receiver service in your System Preferences -> Sharing settings.] Run it through Docker ComposeAssuming you've built the container per the above steps, run one instance securely (port 5001) and another insecurely (port 5002): docker compose up -d Customizing token timeout and vulnerable environment or notIf you would like to alter the timeout of the token created after login or if you want to change th[...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
VAmPI - Vulnerable REST API With OWASP Top 10 Vulnerabilities For Security Testing
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! VAmPI - Vulnerable REST API With OWASP Top 10 Vulnerabilities For Security Testing https://blogger.googleusercontent.com/img/a/AVvXsEiWkXGsybGWZUFpzkXOC_NJd4CzE6cH17TIxQ1Nqufn4lPbV4MDeFlPjFi4F3uT1aLy-GiXz0ER3msn0e9_jGzRc6VOePnLC…
e environment not to be vulnerable then you can use a few ways depending how you run the application.
* If you run it like normal with
* If you run it through Docker, then you must either pass environment variables to the
*
Docker run example:
*
In the Dockerfile you will find two environment variables being set, the
___________________________
@hacking_Attack
@Hacking_Video
* If you run it like normal with
python3 app.pythen all you have to do is edit the aliveand vulnvariables defined in the app.pyitself. The alivevariable is measured in seconds, so if you put 100, then the token expires after 100 seconds. The vulnvariable is like boolean, if you set it to 1then the application is vulnerable, and if you set it to 0the application is not vulnerable.* If you run it through Docker, then you must either pass environment variables to the
docker runcommand or edit the Dockerfileand rebuild. *
Docker run example:
docker run -d -e vulnerable=0 -e tokentimetolive=300 -p 5000:5000 vampire_docker:latest* One nice feature to running it this way is you can startup a 2nd container with vulnerable=1on a different port and flip easily between the two.*
In the Dockerfile you will find two environment variables being set, the
ENV vulnerable=1and the ENV tokentimetolive=60. Feel free to change it before running the docker build command. Picture from freepik - www.freepik.com Download VAmPI___________________________
@hacking_Attack
@Hacking_Video
Response Manipulation in the Admin panel lead to PII leakage
https://7odamo.medium.com/response-manipulation-in-the-admin-panel-lead-to-pii-leakage-2926b89ea2d0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://7odamo.medium.com/response-manipulation-in-the-admin-panel-lead-to-pii-leakage-2926b89ea2d0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Response Manipulation in the Admin panel lead to PII leakage
Hi there, 7odamo is here. Today I will talk about How I was able to view all the customer reports on UPS Admin Panel
Hi there, 7odamo is here. Today I will talk about How I was able to view all the customer reports on UPS Admin PanelContinue reading on Medium » (https://7odamo.medium.com/response-manipulation-in-the-admin-panel-lead-to-pii-leakage-2926b89ea2d0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Response Manipulation in the Admin panel lead to PII leakage
Hi there, 7odamo is here. Today I will talk about How I was able to view all the customer reports on UPS Admin Panel
Response Manipulation in the Admin panel lead to PII leakage
Hi there, 7odamo is here. Today I will talk about How I was able to view all the customer reports on UPS Admin PanelContinue reading on Medium »
Read more...
Hi there, 7odamo is here. Today I will talk about How I was able to view all the customer reports on UPS Admin PanelContinue reading on Medium »
Read more...
hacking: security in practice
I really wanna start doing CTFs and making friends with similar interests but I don't know how.
Hey guys so the title says it all, I want to start doing CTFs and start making friends with folks who are into the same tech stuff but I don't know how to go about it.
Just so you guys know some of my technical background: I know HTML, CSS, JavaScript and Python, I know my way around Linux and VMs, and I've been studying IT and Networking for about the last 6 months.
I think I have a pretty solid foundation to start getting into cyber security stuff but I'm not sure what's the best way to go about it while making friends.
I was thinking that I could perhaps start tryhackme's Jr pentesting course with a few people I meet online? Would this help me accomplish my goals?
submitted by /u/painting_of_oranges
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I really wanna start doing CTFs and making friends with similar interests but I don't know how.
Hey guys so the title says it all, I want to start doing CTFs and start making friends with folks who are into the same tech stuff but I don't know how to go about it.
Just so you guys know some of my technical background: I know HTML, CSS, JavaScript and Python, I know my way around Linux and VMs, and I've been studying IT and Networking for about the last 6 months.
I think I have a pretty solid foundation to start getting into cyber security stuff but I'm not sure what's the best way to go about it while making friends.
I was thinking that I could perhaps start tryhackme's Jr pentesting course with a few people I meet online? Would this help me accomplish my goals?
submitted by /u/painting_of_oranges
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I really wanna start doing CTFs and making friends with similar...
Hey guys so the title says it all, I want to start doing CTFs and start making friends with folks who are into the same tech stuff but I don't...
hacking: security in practice
Do VM’s have a unique MAC address?
So when traffic is sent over a network from a VM, will the vm have a unique MAC address or will it be linked to the MAC address of the device the VM is on?
submitted by /u/Up_North_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Do VM’s have a unique MAC address?
So when traffic is sent over a network from a VM, will the vm have a unique MAC address or will it be linked to the MAC address of the device the VM is on?
submitted by /u/Up_North_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Anyone here heard of witchhack@aol . Com?
I’ve been referred to him and I hear he’s an ethical hacker that helps people who’ve been scammed. I’m kinda scared to reach out cause I’ve got no idea if he’s a scammer himself
submitted by /u/Potatobananapple
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anyone here heard of witchhack@aol . Com?
I’ve been referred to him and I hear he’s an ethical hacker that helps people who’ve been scammed. I’m kinda scared to reach out cause I’ve got no idea if he’s a scammer himself
submitted by /u/Potatobananapple
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anyone here heard of witchhack@aol . Com?
I’ve been referred to him and I hear he’s an ethical hacker that helps people who’ve been scammed. I’m kinda scared to reach out cause I’ve got no...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What Do Hackers Want With Your Facebook Account?
https://cdn-images-1.medium.com/max/1000/1*pxEETNtyY9r3n-td3PKRyw.jpeg
Have you ever had somebody try to hack into your Facebook account? You might be surprised. It’s actually probably happening right now.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What Do Hackers Want With Your Facebook Account?
https://cdn-images-1.medium.com/max/1000/1*pxEETNtyY9r3n-td3PKRyw.jpeg
Have you ever had somebody try to hack into your Facebook account? You might be surprised. It’s actually probably happening right now.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What Do Hackers Want With Your Facebook Account?
Have you ever had somebody try to hack into your Facebook account? You might be surprised. It’s actually probably happening right now.
Screenwriter researching chip heist
https://www.reddit.com/r/Pentesting/comments/vga9uh/screenwriter_researching_chip_heist/
Hey there! So, I’m not sure if this belongs here, but redirect me if there’s a more applicable subreddit. Anyway, I’m a screenwriter and I’ve got this movie I’m working on that deals a lot with ai and technology. I’m very interested in this stuff, but my primary source of information is via Darknet Diaries. Anyway, I have a heist in the movie. Long story short, an agi developer resurrects a body in the style of Frankenstein and then a nefarious character convinces them all to steal a bunch of processing chips to resell on the grey market. I have a few questions. Would there be something better to heist than these chips? How are they usually stored? Where are they stored? How would you (hypothetically) steal them? Any relevant information would be much appreciated! Thank you submitted by /u/mynameismalakai (https://www.reddit.com/user/mynameismalakai)
[link] (https://www.reddit.com/r/Pentesting/comments/vga9uh/screenwriter_researching_chip_heist/) [comments] (https://www.reddit.com/r/Pentesting/comments/vga9uh/screenwriter_researching_chip_heist/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/vga9uh/screenwriter_researching_chip_heist/
Hey there! So, I’m not sure if this belongs here, but redirect me if there’s a more applicable subreddit. Anyway, I’m a screenwriter and I’ve got this movie I’m working on that deals a lot with ai and technology. I’m very interested in this stuff, but my primary source of information is via Darknet Diaries. Anyway, I have a heist in the movie. Long story short, an agi developer resurrects a body in the style of Frankenstein and then a nefarious character convinces them all to steal a bunch of processing chips to resell on the grey market. I have a few questions. Would there be something better to heist than these chips? How are they usually stored? Where are they stored? How would you (hypothetically) steal them? Any relevant information would be much appreciated! Thank you submitted by /u/mynameismalakai (https://www.reddit.com/user/mynameismalakai)
[link] (https://www.reddit.com/r/Pentesting/comments/vga9uh/screenwriter_researching_chip_heist/) [comments] (https://www.reddit.com/r/Pentesting/comments/vga9uh/screenwriter_researching_chip_heist/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Screenwriter researching chip heist
Hey there! So, I’m not sure if this belongs here, but redirect me if there’s a more applicable subreddit. Anyway, I’m a screenwriter and I’ve...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Moonwalk : Cover Your Tracks During Linux Exploitation By Leaving Zero Traces
moonwalk is a 400 KB single-binary executable that can clear your traces while penetration testing a Unix machine. It saves the state of system logs pre-exploitation and reverts that state including the filesystem timestamps post-exploitation leaving zero traces of a ghost in the shell.
Features
* Small Executable: Get started quickly with a
* Fast: Performs all session commands including logging, trace clearing, and filesystem operations in under 5 milliseconds.
* Reconnaissance: To save the state of system logs,
* Shell History: Instead of clearing the whole history file,
* Filesystem Timestamps: Hide from the Blue Team by reverting the access/modify timestamps of files back to how it was using the
Installation
$ curl -L https://github.com/mufeedvh/moonwalk/releases/download/v1.0.0/moonwalk_linux -o moonwalk
(
OR
Download the executable from Releases OR Install with
Build From Source
Prerequisites
* Git
* Rust
* Cargo (Automatically installed when installing Rust)
* A C linker (Only for Linux, generally comes pre-installed)
$ git clone https://github.com/mufeedvh/moonwalk.git
$ cd moonwalk/
$ cargo build –release
The first command clones this repository into your local machine and the last two commands enters the directory and builds the source in release mode.
Usage
Once you get a shell into the target Unix machine, start a moonwalk session by running this command:
$ moonwalk start
While you’re doing recon/exploitation and messing with any files, get the
$ moonwalk get ~/.bash_history
Post-exploitation, clear your traces and close the session with this command:
$ moonwalk finish
Download
___________________________
@hacking_Attack
@Hacking_Video
Moonwalk : Cover Your Tracks During Linux Exploitation By Leaving Zero Traces
moonwalk is a 400 KB single-binary executable that can clear your traces while penetration testing a Unix machine. It saves the state of system logs pre-exploitation and reverts that state including the filesystem timestamps post-exploitation leaving zero traces of a ghost in the shell.
Features
* Small Executable: Get started quickly with a
curlfetch to your target machine.* Fast: Performs all session commands including logging, trace clearing, and filesystem operations in under 5 milliseconds.
* Reconnaissance: To save the state of system logs,
moonwalkfinds a world-writable path and saves the session under a dot directory which is removed upon ending the session.* Shell History: Instead of clearing the whole history file,
moonwalkreverts it back to how it was including the invocation of moonwalk.* Filesystem Timestamps: Hide from the Blue Team by reverting the access/modify timestamps of files back to how it was using the
GETcommand.Installation
$ curl -L https://github.com/mufeedvh/moonwalk/releases/download/v1.0.0/moonwalk_linux -o moonwalk
(
AMD x86-64)OR
Download the executable from Releases OR Install with
cargo:Build From Source
Prerequisites
* Git
* Rust
* Cargo (Automatically installed when installing Rust)
* A C linker (Only for Linux, generally comes pre-installed)
$ git clone https://github.com/mufeedvh/moonwalk.git
$ cd moonwalk/
$ cargo build –release
The first command clones this repository into your local machine and the last two commands enters the directory and builds the source in release mode.
Usage
Once you get a shell into the target Unix machine, start a moonwalk session by running this command:
$ moonwalk start
While you’re doing recon/exploitation and messing with any files, get the
touchtimestamp command of a file beforehand to revert it back after you’ve accessed/modified it:$ moonwalk get ~/.bash_history
Post-exploitation, clear your traces and close the session with this command:
$ moonwalk finish
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Moonwalk : Cover Your Tracks During Linux Exploitation
moonwalk is a 400 KB single-binary executable that can clear your traces while penetration testing a Unix machine.