Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
RouterSpace From Hackthebox

Android Exploitation and sudo ExploitContinue reading on InfoSec Write-ups »
Read more...
An interesting idor that allowed me to See all projects ($$$$ Bounty)

Hi all today i will share an intresting i dor that i found in a one of hackerone private programs that allowed me to disclose all users…Continue reading on Medium »
Read more...
good resources for bypassing WAFS for sqli / tamper script
https://www.reddit.com/r/Pentesting/comments/vvfz81/good_resources_for_bypassing_wafs_for_sqli_tamper/

I'm looking for some resources specifically for bypassing WAFs. Specifcally for payloads that contain the word 'OR'. I know theres '||' equivalents, but I'm having trouble accessing things like information_schema since or is in it. I tried using comments for spaces and putting comments in between words, unhex(), char encoding, unicoding, url double encoding. Any resources would be great, this is for some labs for the ewptx training - the section for sqli didnt cover tamper scripting all that great. submitted by /u/phyiscs (https://www.reddit.com/user/phyiscs)
[link] (https://www.reddit.com/r/Pentesting/comments/vvfz81/good_resources_for_bypassing_wafs_for_sqli_tamper/) [comments] (https://www.reddit.com/r/Pentesting/comments/vvfz81/good_resources_for_bypassing_wafs_for_sqli_tamper/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
It’s safe to use malware on your computer if you are in control right?

I just wanna mess around, and if I don’t use it for malicious intent and I am monitoring what I do (doing commands appropriately) it’s safe right? I’m not 100% sure so I don’t wanna fuck something up lmao.

And obviously I am aware of what the command will do so I’m able to deal with anything that’s sent “my way”

submitted by /u/Background_Ant_1472
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I have a virus on my mail

It turns out that somehow a virus attacked me, since several friends have sent me a screenshot that they have received emails with my name as the sender (the email was clearly a fake, but my name appeared as a preview of the name so unless that you click to see what the real name was from the email you could think it was me), sending a small text like "this should work" and a link, signed below with my name. They are clearly trying to get recipients to click on the link so they can install the virus on them too. And not only that, but in the screenshots that they sent me it looks like that email was sent several times to many people (all people who were in my email contact list), which worries me since perhaps someone can reach fall into the trap Does anyone know what I can do or how this could have happened? Another fact to add is that the written text is in French, so it must be a French virus (I guess).

submitted by /u/International_Mud141
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
MSA Weekly 3 — “Cara Mendekati Mesin Target Anda Menggunakan - Teknik NMAP”

Dalam dunia penetration tester ada beberapa step sebelum melakukan yang namanya exploitasi, yaitu reconaissance dan scanning. Dan disini…Continue reading on Medium »
Read more...
Open redirects for bug bounties

Open redirects can be an easy source for bug bounty, given that you get one. How to find them or exploit them? let’s have a look:Continue reading on Medium »
Read more...