Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Malware scripting for windows

Question, what language do you consider the best for low level (networking, keylogger etc) scripting? As far as i know linux uses shell but after searching online i couldn't find in what language windows targeting malware is written in.

submitted by /u/shurikkenn
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can SMTP be used for anything other than Recon (& emailing)?

I’ve been stuck on a CTF for awhile, and all the machine has open is: DNS, SMTP, and SSH. I’ve done the User Enumeration from SMTP, and I’m assuming that one of them can be used for SSH later, but an entire day of unsuccessful Brute-Forcing with Hydra makes me think I’m missing something. One of the “users” is MySQL, but I don’t think I can do anything with that until I SSH in.

TL;DR

All the guides I see online for Pen-testing SMTP servers are about User Enumeration or sending spoofed emails. Is that all SMTP is good for?

If any 1337 hackers have advice for a noob, I’d really appreciate it. Thanks for your time!

submitted by /u/Agent-BTZ
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How does reconnaissance work in real life?

When I do CTF or hackthebox, I usually don't hesitate to launch nmap/burp to scan everything I can to gather as much info as possible. However, I imagine in real life security systems will detect unusual activity after a reasonable amount of probes. So how does this work in real life? It seems to me that any scanning probes would be immediately banned. How do pentesters overcome this?

submitted by /u/kasssom
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Paramspider lead to find SQLI vulnerability

In this tutorial you will learn how real hackers can find injection vulnerabilities like :Continue reading on Medium »
Read more...
THIS IS WHAT I CALL MASS IDOR

A Chained Mass IDORContinue reading on Medium »
Read more...
Information Source Code Disclosure Directory .git — MNC Play

Pada tanggal 15 Oktober 2020 saya menemukan BUG SQL Injection di payment.mncplay.id tetapi tidak ada respons dari pihak MNC Play.Continue reading on Medium »
Read more...