Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bug Bounty Tips #002

Text Input Denials of ServiceContinue reading on The Mayor »
Read more...
Duplicating a Hid Proxcard ii.
https://www.reddit.com/r/Pentesting/comments/vjf3zo/duplicating_a_hid_proxcard_ii/

Hello, I’ve been trying to branch out into pentesting and wanted to attempt duplicating a simple Hid Proxcard ii so purchased one of those cheap 125mhz scanners. It wouldn’t scan the card at first then i rewrote it blank it started reading but i essentially just cleared the card. I’ve realized it has to do something with how they encrypt it relating to something like T5577? Wondering if anyone can point me to a cheaper cost effective method of duplicating the card where the reader will actually scan. I have access to raspberry pi’s and arduino’s so can set something up just looking to learn some more about how they work and how to duplicate them. submitted by /u/Liam_Moroney (https://www.reddit.com/user/Liam_Moroney)
[link] (https://www.reddit.com/r/Pentesting/comments/vjf3zo/duplicating_a_hid_proxcard_ii/) [comments] (https://www.reddit.com/r/Pentesting/comments/vjf3zo/duplicating_a_hid_proxcard_ii/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Are bug bounties still viable ?

At this point CMSs and frameworks used to create websites take the required security measures to keep a website safe (auto escaping and CSRF protection for example). And the hosting services provide firewalls by default in their servers. A web app would need the developers to mess up really bad somewhere in order for it to be vulnerable, which let's be honest, will not be done by a company offering a bug bounty program.

Your only shot is finding a vulnerability in the CMSs or frameworks used to build the website which are most of the time open source and reviewed by hundreds of people, or closed source and has been around for an eternity and has been patched against every single vulnerability a website can have.

That's why I don't think bug bounties are viable in 2022, let me know what you think.

submitted by /u/Iam_cool_asf
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
An Out Of Scope domain Leads To a Critical Bug[$1500]

Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan).Continue reading on Medium »
Read more...
Sensitive Token Leakage from server side

Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…Continue reading on Medium »
Read more...