Exposing Millions of Voter ID card user’s details.
https://nxtexploit.medium.com/exposing-millions-of-voter-id-card-users-details-8a993c9a5d35?source=rss------bug_bounty-5
https://nxtexploit.medium.com/exposing-millions-of-voter-id-card-users-details-8a993c9a5d35?source=rss------bug_bounty-5
Critical IDOR disclosing millions of Voter ID card details of Individuals on the official voter ID maintaining platform.Continue reading on Medium » (https://nxtexploit.medium.com/exposing-millions-of-voter-id-card-users-details-8a993c9a5d35?source=rss------bug_bounty-5)
how to find information disclosure bugs (:
https://medium.com/@marwanweed/how-to-find-information-disclosure-bugs-bd4e4fa5b880?source=rss------bug_bounty-5
https://medium.com/@marwanweed/how-to-find-information-disclosure-bugs-bd4e4fa5b880?source=rss------bug_bounty-5
hello 👋 people of the internet so this is my frist writeup i hope i don’t suck that much.Continue reading on Medium » (https://medium.com/@marwanweed/how-to-find-information-disclosure-bugs-bd4e4fa5b880?source=rss------bug_bounty-5)
Tool for extracting, searching, and saving JavaScript files
https://www.reddit.com/r/Pentesting/comments/vtsi3f/tool_for_extracting_searching_and_saving/
<!-- SC_OFF -->Hey all, hope it's ok to post this here — I recently built goGetJS, a tool in Go for extracting, searching, and saving JavaScript files. It's got an optional headless browser to handle JavaScript-heavy sites, which I haven’t seen in similar programs. The search functionality is built into the parsing, and you can look for a particular word, pass in a regex, or upload a file of terms. I’m still tweaking, but it’s stable and available at https://github.com/davemolk/goGetJS. Please let me know if this helps your workflow or if there are features you’d like to see! <!-- SC_ON --> submitted by /u/davemolkdev (https://www.reddit.com/user/davemolkdev)
[link] (https://www.reddit.com/r/Pentesting/comments/vtsi3f/tool_for_extracting_searching_and_saving/) [comments] (https://www.reddit.com/r/Pentesting/comments/vtsi3f/tool_for_extracting_searching_and_saving/)
https://www.reddit.com/r/Pentesting/comments/vtsi3f/tool_for_extracting_searching_and_saving/
<!-- SC_OFF -->Hey all, hope it's ok to post this here — I recently built goGetJS, a tool in Go for extracting, searching, and saving JavaScript files. It's got an optional headless browser to handle JavaScript-heavy sites, which I haven’t seen in similar programs. The search functionality is built into the parsing, and you can look for a particular word, pass in a regex, or upload a file of terms. I’m still tweaking, but it’s stable and available at https://github.com/davemolk/goGetJS. Please let me know if this helps your workflow or if there are features you’d like to see! <!-- SC_ON --> submitted by /u/davemolkdev (https://www.reddit.com/user/davemolkdev)
[link] (https://www.reddit.com/r/Pentesting/comments/vtsi3f/tool_for_extracting_searching_and_saving/) [comments] (https://www.reddit.com/r/Pentesting/comments/vtsi3f/tool_for_extracting_searching_and_saving/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Cyber Skills Center Launches in Tulsa to Develop Diverse, Local Tech Talent Pipeline
New program offers free tech skills training and paid apprenticeships to make education and career pathways more accessible.
Cyber Skills Center Launches in Tulsa to Develop Diverse, Local Tech Talent Pipeline
New program offers free tech skills training and paid apprenticeships to make education and career pathways more accessible.
hacking: security in practice
Hydra brute force taking too long
I have been able to write a hydra command which generates 6 character password consisting of uppercase alphanumeric symbols. This gives however 366 (over 2 billion possible) combinations so with a rate of about 32 tasks /min it will take over at least 1 million hours to try all combinations. What can I do to make this process faster?
submitted by /u/pduk19
[link] [comments]
Hydra brute force taking too long
I have been able to write a hydra command which generates 6 character password consisting of uppercase alphanumeric symbols. This gives however 366 (over 2 billion possible) combinations so with a rate of about 32 tasks /min it will take over at least 1 million hours to try all combinations. What can I do to make this process faster?
submitted by /u/pduk19
[link] [comments]
reddit
Hydra brute force taking too long
I have been able to write a hydra command which generates 6 character password consisting of uppercase alphanumeric symbols. This gives however...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Coercer: A tool to automatically trigger all RPC calls to remotely trigger authentications on Windows machines
https://external-preview.redd.it/r27VJ80hNlcnqKhBuoHFkC3uXDjKr4MCZnEwpksbm7k.jpg?width=108&crop=smart&auto=webp&s=265c3c6472f23c0f92eb61d97afe0b14b667e59c submitted by /u/Podalirius_
[link] [comments]
Coercer: A tool to automatically trigger all RPC calls to remotely trigger authentications on Windows machines
https://external-preview.redd.it/r27VJ80hNlcnqKhBuoHFkC3uXDjKr4MCZnEwpksbm7k.jpg?width=108&crop=smart&auto=webp&s=265c3c6472f23c0f92eb61d97afe0b14b667e59c submitted by /u/Podalirius_
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Flipper Zero just got in stock, if you really want one buy it ASAP!
Flipper Zero just got in stock and it won't last for long. Loved by so many hackers, I thought I would share the news.
From their description:
Flipper Zero is a portable multi-tool for pentesters and geeks in a toy-like body. It loves hacking digital stuff, such as radio protocols, access control systems, hardware and more. It's fully open-source and customizable, so you can extend it in whatever way you like.
I AM NOT AN AFFILIATE BY ANY MEANS, just a hacker that loves the product and wants to support the Kickstarter. Buy one if you wanted for so long and support them!
Shop: https://flipperzero.one/
submitted by /u/xregister22
[link] [comments]
Flipper Zero just got in stock, if you really want one buy it ASAP!
Flipper Zero just got in stock and it won't last for long. Loved by so many hackers, I thought I would share the news.
From their description:
Flipper Zero is a portable multi-tool for pentesters and geeks in a toy-like body. It loves hacking digital stuff, such as radio protocols, access control systems, hardware and more. It's fully open-source and customizable, so you can extend it in whatever way you like.
I AM NOT AN AFFILIATE BY ANY MEANS, just a hacker that loves the product and wants to support the Kickstarter. Buy one if you wanted for so long and support them!
Shop: https://flipperzero.one/
submitted by /u/xregister22
[link] [comments]
hacking: security in practice
How to identify a malicious editor of a now-locked-down Google Doc?
Long story short, someone screwed up and didn't lock down perms correctly on a community Google Doc. We have full backup copies, but edit permissions were only granted to specific people, and one of those people has locked down the doc so we cannot see the revision history/editors etc. Due to a lack of communication/documentation, I also do not know who the doc owner is.
I need to know who maliciously destroyed the contents of the doc so I can ban them from our community, but I'm at a loss as to how to find out who it is.
To that end, does anyone know of any neat tricks to bypass the restrictions on seeing revision history/last editor/owner of a Google Doc when it's been locked down?
I'm looking for a legal technical approach here. It is nowhere near important enough to even consider anything less than legal, not that I would anyway. We're also working the social side of things, but so far we're not getting anywhere there,
If such a workaround exists, my Google-Fu is apparently too weak to find it. Any guidance on how I might go about this would be greatly appreciated.
Cheers either way.
submitted by /u/Evelmike
[link] [comments]
How to identify a malicious editor of a now-locked-down Google Doc?
Long story short, someone screwed up and didn't lock down perms correctly on a community Google Doc. We have full backup copies, but edit permissions were only granted to specific people, and one of those people has locked down the doc so we cannot see the revision history/editors etc. Due to a lack of communication/documentation, I also do not know who the doc owner is.
I need to know who maliciously destroyed the contents of the doc so I can ban them from our community, but I'm at a loss as to how to find out who it is.
To that end, does anyone know of any neat tricks to bypass the restrictions on seeing revision history/last editor/owner of a Google Doc when it's been locked down?
I'm looking for a legal technical approach here. It is nowhere near important enough to even consider anything less than legal, not that I would anyway. We're also working the social side of things, but so far we're not getting anywhere there,
If such a workaround exists, my Google-Fu is apparently too weak to find it. Any guidance on how I might go about this would be greatly appreciated.
Cheers either way.
submitted by /u/Evelmike
[link] [comments]
reddit
How to identify a malicious editor of a now-locked-down Google Doc?
Long story short, someone screwed up and didn't lock down perms correctly on a community Google Doc. We have full backup copies, but edit...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A Hacker Claims Ted Cruz’s Browser History Is “Really F’ed Up”
https://cdn-images-1.medium.com/max/1580/1*vXh1WwT3oy457hYnPpjE5w.jpeg
A computer hacker yesterday claimed to have successfully hacked into Senator Ted Cruz’s personal laptop, but what he found convinced the…
Continue reading on Medium »
A Hacker Claims Ted Cruz’s Browser History Is “Really F’ed Up”
https://cdn-images-1.medium.com/max/1580/1*vXh1WwT3oy457hYnPpjE5w.jpeg
A computer hacker yesterday claimed to have successfully hacked into Senator Ted Cruz’s personal laptop, but what he found convinced the…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Curated Newsletter #1
https://cdn-images-1.medium.com/max/1080/1*0WeQn8_duEPlNGxZFNtraA.png
Here are some curated Tweets, enjoy!
Continue reading on CryptoStars »
Curated Newsletter #1
https://cdn-images-1.medium.com/max/1080/1*0WeQn8_duEPlNGxZFNtraA.png
Here are some curated Tweets, enjoy!
Continue reading on CryptoStars »