Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dalam dunia penetration tester ada beberapa step sebelum melakukan yang namanya exploitasi, yaitu reconaissance dan scanning. Dan disini…Continue reading on Medium » (https://medium.com/@cakraadi/msa-weekly-3-cara-mendekati-mesin-target-anda-menggunakan-teknik-nmap-8c0187dac883?source=rss------bug_bounty-5)
Open redirects for bug bounties
https://h4krg33k.medium.com/open-redirects-for-bug-bounties-bf4b58313842?source=rss------bug_bounty-5

Open redirects can be an easy source for bug bounty, given that you get one. How to find them or exploit them? let’s have a look:Continue reading on Medium » (https://h4krg33k.medium.com/open-redirects-for-bug-bounties-bf4b58313842?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Open redirects for bug bounties

Open redirects can be an easy source for bug bounty, given that you get one. How to find them or exploit them? let’s have a look:

Continue reading on Medium »
Free cybercrime intelligence tool - check any company domain and see how many of their employees and clients were compromised by info-stealers
https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/

<!-- SC_OFF -->Check domains for free across our database of over 5,700,000 computers compromised with info-stealers world wide - https://www.hudsonrock.com/are-you-compromised Also available via https://inteltechniques.com/tools/Breaches.html under "HudsonRock" What is it? - this free tool enables you to search for domains and see how many compromised employees & users they have from our continuously augmented cybercrime database, this can be useful for several reasons: Risk assessment - looking up a company and seeing they have a lot of compromised employees can indicate the company is not up to date with proper security measures, each compromised employee indicates that someone in the company downloaded and executed an info-stealing malware and had all their corporate credentials, cookies, documents, etc stolen by hackers who are using the credentials as an initial attack vector. Pre-breach intel - if you work at a company and see we have data relating to it, you can ask for an ethical disclosure from us for free, we provided hundreds of ethical disclosures regarding compromised credentials which are in the hands of hackers as a result of employees/clients having their computers infected. It is important to note that even with 2FA set in place, when a computer gets infected with an info-stealer they also have their cookies stolen which are then used to steal sessions and bypass 2FA, and that documents containing 2FA backup codes stored anywhere on the computer get captured by the info-stealer and allows the hacker to revoke phone-based 2FA. Assets discovery - we show the top 5 URLs that compromised employees & clients had credentials to, often times these URLs are not attainable anywhere else because internal URLs accessed by clients/employees are not indexed anywhere and cannot be scraped. What is it not? - this is not a tool that provides a full overview around who the employees and users that got compromised are, or how they got compromised. We cannot provide this data publicly as it is very sensitive and is only given as an ethical disclosure to the cybersecurity team of the company. If you work for a company that has compromised employees or clients, be sure to get a free ethical disclosure from us. Our high-fidelity cybercrime intelligence data is sourced directly from threat actors — not from database leaks or scrapes. If you liked this tool please share it, it is also accessible through API along with other free tools we provide such as checking if your own computer was compromised at some point (Preview API - https://cavalier.hudsonrock.com/docs) <!-- SC_ON --> submitted by /u/Malwarebeasts (https://www.reddit.com/user/Malwarebeasts)
[link] (https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/) [comments] (https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/)