Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Windows LSA Service LsapGetClientInfo Impersonation Level Check Privilege Escalation

https://1.bp.blogspot.com/--r13ngwGJe8/WWlvLp4DX4I/AAAAAAAAIMI/4n3jDvF3elUQ0c2WO1JA-mB24XU3pCyAACLcBGAs/s1600/h17.png
On Microsoft Windows, the LsapGetClientInfo API in LSASRV will fallback and directly capture a caller's impersonation token if it fails to impersonate, leading to elevation of privilege if the impersonation level is not checked.

SHA-256 | 4f77530c88d7c141599b603fabccbde4f773bc1697a54702749961ba91a1346a

Download
Source:packetstormsecurity.com
Searched for a firmware for my Epson, found exploitable printers, I think
https://www.reddit.com/r/Pentesting/comments/vzuluo/searched_for_a_firmware_for_my_epson_found/

<!-- SC_OFF -->I was searching on Google for firmware for my Epson printer: "firmware "30.76.CL26LB" but found open printers it seems to me. Can someone explain if they are intentionally left open? <!-- SC_ON --> submitted by /u/xirotag (https://www.reddit.com/user/xirotag)
[link] (https://www.reddit.com/r/Pentesting/comments/vzuluo/searched_for_a_firmware_for_my_epson_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/vzuluo/searched_for_a_firmware_for_my_epson_found/)
Hello Infosec Family. I am Shubham Ghosh, an Information Security Analyst with an experience of 2+ years from Jharkhand, India. This…Continue reading on Medium » (https://ghoshshubham.medium.com/how-i-got-ceh-certified-ethical-hacker-master-certified-resources-included-52c6a8a3733e?source=rss------bug_bounty-5)
How I got CEH (Certified Ethical Hacker) Master Certified. (Resources included)

Hello Infosec Family. I am Shubham Ghosh, an Information Security Analyst with an experience of 2+ years from Jharkhand, India. This…Continue reading on Medium »
Read more...
Null to Bug: Insecure Direct Object Reference

What is Null to Bug?Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Ex-CIA Programmer Found Guilty of Stealing Vault 7 Data, Giving It to Wikileaks

Joshua Schulte has been convicted for his role in the Vault 7 Wikileaks data dump that exposed invasive US cyber intelligence tactics.
Dark Reading: Attacks/Breaches
How Attackers Could Dupe Developers into Downloading Malicious Code From GitHub

Developers need to be cautious about whom they trust on GitHub because it's easy to establish fake credibility on the platform, security vendor warns.
Dark Reading: Attacks/Breaches
What Are the Risks of Employees Going on a 'Hybrid Holiday'?

As more employees plan on taking longer holidays and working remotely from the destination for part of that time, organizations have to consider the risks. Like Wi-Fi networks.
Dark Reading: Attacks/Breaches
Netwrix Auditor Bug Could Lead to Active Directory Domain Compromise

IT asset tracker and auditor software has a critical issue with insecure object deserialization that could allow threat actors to execute code, researchers say.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox’s “Blue” Writeup

https://cdn-images-1.medium.com/max/702/1*1y9cleAmPXdJAxYpBV152g.png
HackTheBox’s “Blue” is a neat little machine that teaches you how easy, and therefore scary, the NSA developed windows exploit “MS17–010”…

Continue reading on System Weakness »