Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Who Controls the Yacht

https://cdn-images-1.medium.com/max/2600/0*Au-Z6TSaNneKv4Xq
We saw the power of GPS deception in mid-2013 when an $80 million yacht was hijacked with fake GPS signals. The sixty-five-metre superlux…

Continue reading on Medium »
hacking: security in practice
How important is it to know PowerShell from a cyber security standpoint?

I know PowerShell and bash are very useful in terms of hacking and scripting (python as well). but living off the land PowerShell seems like a very powerful tool with access to every thing in the system.

Thoughts on if it is a fundamental skill to know even if you are not a sys admin? and why?

submitted by /u/EnormousJohnson
[link] [comments]
Sent by @TheFeedReaderBot
hacking: security in practice
Can Someone Hack into my Network through Bluetooth Lightbulb?

Hey; I'm looking at buying some colour-changing lightbulbs, but I'm concerned there could be a security risk. I know in the past ppl have hacked into networks through IOT devices.

I'm looking at this product by the way:

https://www.amazon.ca/dp/B0856RM2L3

The way it works you download an app to your phone and connect to each lightbulb via Bluetooth. There's also some automation which I'm not sure about since I'm using a simple lamp.

The bulb itself is not connected to Wifi and doesn't know the Wifi password. For this reason, I feel this model should be safe but I'm not sure? I googled and couldn't find any info about this brand and hacking.

submitted by /u/Mission-Iron-7509
[link] [comments]
Sent by @TheFeedReaderBot
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Windows Kernel nt!MiRelocateImage Invalid Read

https://4.bp.blogspot.com/-lQ2zJgiLTsU/WWlu34sMcWI/AAAAAAAAII4/mS7xceEZnmUYAvFeoaUiLc9JINHoDjNsACLcBGAs/s1600/h102.png
The Microsoft Windows kernel suffers from an invalid read in nt!MiRelocateImage while parsing a malformed PE file.

SHA-256 | 14cc97653808a5e83777838181351383480596c1a9ab0edd737615c558008d89

Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Windows LSA Service LsapGetClientInfo Impersonation Level Check Privilege Escalation

https://1.bp.blogspot.com/--r13ngwGJe8/WWlvLp4DX4I/AAAAAAAAIMI/4n3jDvF3elUQ0c2WO1JA-mB24XU3pCyAACLcBGAs/s1600/h17.png
On Microsoft Windows, the LsapGetClientInfo API in LSASRV will fallback and directly capture a caller's impersonation token if it fails to impersonate, leading to elevation of privilege if the impersonation level is not checked.

SHA-256 | 4f77530c88d7c141599b603fabccbde4f773bc1697a54702749961ba91a1346a

Download
Source:packetstormsecurity.com
Searched for a firmware for my Epson, found exploitable printers, I think
https://www.reddit.com/r/Pentesting/comments/vzuluo/searched_for_a_firmware_for_my_epson_found/

<!-- SC_OFF -->I was searching on Google for firmware for my Epson printer: "firmware "30.76.CL26LB" but found open printers it seems to me. Can someone explain if they are intentionally left open? <!-- SC_ON --> submitted by /u/xirotag (https://www.reddit.com/user/xirotag)
[link] (https://www.reddit.com/r/Pentesting/comments/vzuluo/searched_for_a_firmware_for_my_epson_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/vzuluo/searched_for_a_firmware_for_my_epson_found/)
Hello Infosec Family. I am Shubham Ghosh, an Information Security Analyst with an experience of 2+ years from Jharkhand, India. This…Continue reading on Medium » (https://ghoshshubham.medium.com/how-i-got-ceh-certified-ethical-hacker-master-certified-resources-included-52c6a8a3733e?source=rss------bug_bounty-5)
How I got CEH (Certified Ethical Hacker) Master Certified. (Resources included)

Hello Infosec Family. I am Shubham Ghosh, an Information Security Analyst with an experience of 2+ years from Jharkhand, India. This…Continue reading on Medium »
Read more...
Null to Bug: Insecure Direct Object Reference

What is Null to Bug?Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Ex-CIA Programmer Found Guilty of Stealing Vault 7 Data, Giving It to Wikileaks

Joshua Schulte has been convicted for his role in the Vault 7 Wikileaks data dump that exposed invasive US cyber intelligence tactics.
Dark Reading: Attacks/Breaches
How Attackers Could Dupe Developers into Downloading Malicious Code From GitHub

Developers need to be cautious about whom they trust on GitHub because it's easy to establish fake credibility on the platform, security vendor warns.
Dark Reading: Attacks/Breaches
What Are the Risks of Employees Going on a 'Hybrid Holiday'?

As more employees plan on taking longer holidays and working remotely from the destination for part of that time, organizations have to consider the risks. Like Wi-Fi networks.