Hi, everyoneContinue reading on Medium » (https://medium.com/@moSec/crlf-to-account-takeover-chaining-bugs-21a25dfa1cdf?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CRLF to Account takeover (chaining bugs)
Hi, everyone
https://b.thumbs.redditmedia.com/ft10xbq3hMql5JoWEE4Jw1yhDtejQrrG3jh3SkYz_xs.jpg Seeking focus groups/use cases: https://www.domaincodex.com
https://preview.redd.it/zh6yn260ryb91.png?width=1318&format=png&auto=webp&s=7fe201c6240f4a9ccdbc4f7f196e5b009a30096e
Search 390+million root domains (associative 25 data points). Mix and match any criteria/points, additional API access available via RapidAPI.
#data #osint #bigdata
All feedback welcomed: https://www.domaincodex.com/contact.php
submitted by /u/cstadler
[link] [comments]
https://preview.redd.it/zh6yn260ryb91.png?width=1318&format=png&auto=webp&s=7fe201c6240f4a9ccdbc4f7f196e5b009a30096e
Search 390+million root domains (associative 25 data points). Mix and match any criteria/points, additional API access available via RapidAPI.
#data #osint #bigdata
All feedback welcomed: https://www.domaincodex.com/contact.php
submitted by /u/cstadler
[link] [comments]
First Bug Bounty from DOS: Taking the service down
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.Continue reading on Medium »
Read more...
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.Continue reading on Medium »
Read more...
MS-Interloper: On the Subject of Malicious MSIs
https://www.reddit.com/r/redteamsec/comments/w0ky2p/msinterloper_on_the_subject_of_malicious_msis/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://notes.huskyhacks.dev/notes/ms-interloper-on-the-subject-of-malicious-msis) [comments] (https://www.reddit.com/r/redteamsec/comments/w0ky2p/msinterloper_on_the_subject_of_malicious_msis/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/w0ky2p/msinterloper_on_the_subject_of_malicious_msis/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://notes.huskyhacks.dev/notes/ms-interloper-on-the-subject-of-malicious-msis) [comments] (https://www.reddit.com/r/redteamsec/comments/w0ky2p/msinterloper_on_the_subject_of_malicious_msis/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
MS-Interloper: On the Subject of Malicious MSIs
Posted in r/redteamsec by u/dmchell • 1 point and 0 comments
First Bug Bounty from DOS: Taking the service down
https://medium.com/@faique/first-bug-bounty-from-dos-taking-the-service-down-30f9ad4e0246?source=rss------bug_bounty-5
https://medium.com/@faique/first-bug-bounty-from-dos-taking-the-service-down-30f9ad4e0246?source=rss------bug_bounty-5
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.Continue reading on Medium » (https://medium.com/@faique/first-bug-bounty-from-dos-taking-the-service-down-30f9ad4e0246?source=rss------bug_bounty-5)
password reset No Rate Limiting
https://medium.com/@rishinikam/password-reset-no-rate-limiting-f46b93088ec0?source=rss------bug_bounty-5
https://medium.com/@rishinikam/password-reset-no-rate-limiting-f46b93088ec0?source=rss------bug_bounty-5
hey gusy my name RISHI NIKAM i am Security Researcher and bug bounty hunterContinue reading on Medium » (https://medium.com/@rishinikam/password-reset-no-rate-limiting-f46b93088ec0?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Become a Penetration Tester
https://cdn-images-1.medium.com/max/2600/1*LqNasta6RoVbPe0vK0wGHA.jpeg
The act of simulating cyber attacks against a digital asset or infrastructure is called a penetration test.
Continue reading on Medium »
How to Become a Penetration Tester
https://cdn-images-1.medium.com/max/2600/1*LqNasta6RoVbPe0vK0wGHA.jpeg
The act of simulating cyber attacks against a digital asset or infrastructure is called a penetration test.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
First Bug Bounty from DOS: Taking the service down
https://cdn-images-1.medium.com/max/2264/1*fJsu3ba2_EsIkHJwbb18iQ.png
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.
Continue reading on Medium »
First Bug Bounty from DOS: Taking the service down
https://cdn-images-1.medium.com/max/2264/1*fJsu3ba2_EsIkHJwbb18iQ.png
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I Rickrolled My Entire Class
https://cdn-images-1.medium.com/max/640/0*jzTGgApwBnekdRcd
This is the story of how I managed to Rickroll my entire class. Just with some simple Python scripting and a USB Rubber Ducky. Read how…
Continue reading on Medium »
How I Rickrolled My Entire Class
https://cdn-images-1.medium.com/max/640/0*jzTGgApwBnekdRcd
This is the story of how I managed to Rickroll my entire class. Just with some simple Python scripting and a USB Rubber Ducky. Read how…
Continue reading on Medium »
hacking: security in practice
Did email get intercepted in flight, or what happened here? (Scam)
Hi all, apologies in advance for the long story and for my ignorance on the subject, but I'm trying to figure out what happened here and I thought maybe someone would be able to shed some light!
A brief intro: In short, my girlfriend hired a company in Italy (she is from South America) to assist her in a process locally. The fees would be paid in three installments across the length of the process. The service itself has been provided, and the company all in all, is legit.
The issue: The first installment was correctly paid to the company's account, whose information (as well as all other communication) was provided via email. The second installment however ended up in some other random account, but here is the strange bit... The information of that random account came in an email, sent from the company's domain, which was an exact copy of previous emails, except for the account number.
When confronted, the company said that the email was "hacked" and modified in flight, and that nothing was wrong on their end. They also advised to check, in Gmail, the "show original" section to see whether the email came from another address, and effectively, it seemed that the "real" email address was a different one altogether, only using the company's one as a mask. In the end she was scammed out of a bit more than a thousand USD, and no one took responsibility.
Anyone has any idea what could have happened here? If she received a "cloned" email, why didn't she receive the original email from the company too? Can these "in-flight" interceptions really happen? Or is there an easier explanation to this?
Thanks!!!
submitted by /u/Patopml
[link] [comments]
Did email get intercepted in flight, or what happened here? (Scam)
Hi all, apologies in advance for the long story and for my ignorance on the subject, but I'm trying to figure out what happened here and I thought maybe someone would be able to shed some light!
A brief intro: In short, my girlfriend hired a company in Italy (she is from South America) to assist her in a process locally. The fees would be paid in three installments across the length of the process. The service itself has been provided, and the company all in all, is legit.
The issue: The first installment was correctly paid to the company's account, whose information (as well as all other communication) was provided via email. The second installment however ended up in some other random account, but here is the strange bit... The information of that random account came in an email, sent from the company's domain, which was an exact copy of previous emails, except for the account number.
When confronted, the company said that the email was "hacked" and modified in flight, and that nothing was wrong on their end. They also advised to check, in Gmail, the "show original" section to see whether the email came from another address, and effectively, it seemed that the "real" email address was a different one altogether, only using the company's one as a mask. In the end she was scammed out of a bit more than a thousand USD, and no one took responsibility.
Anyone has any idea what could have happened here? If she received a "cloned" email, why didn't she receive the original email from the company too? Can these "in-flight" interceptions really happen? Or is there an easier explanation to this?
Thanks!!!
submitted by /u/Patopml
[link] [comments]
reddit
Did email get intercepted in flight, or what happened here? (Scam)
Hi all, apologies in advance for the long story and for my ignorance on the subject, but I'm trying to figure out what happened here and I thought...
hacking: security in practice
Crazy accurate spoofing how?
I’m a student at a large state university studying cybersecurity. A couple days ago I got an email from the scholarships office (exact same from name and address) saying I was awarded a scholarship and I was completely convinced but it ended up being my friend who thought it would be funny.
My question is how is this possible. The domain name is exactly the same @school name.edu and it did not go to my spam or anything. I would imagine that a big university would have SPF or something similar. How was he able to do this?
submitted by /u/MixableCarrot
[link] [comments]
Crazy accurate spoofing how?
I’m a student at a large state university studying cybersecurity. A couple days ago I got an email from the scholarships office (exact same from name and address) saying I was awarded a scholarship and I was completely convinced but it ended up being my friend who thought it would be funny.
My question is how is this possible. The domain name is exactly the same @school name.edu and it did not go to my spam or anything. I would imagine that a big university would have SPF or something similar. How was he able to do this?
submitted by /u/MixableCarrot
[link] [comments]
reddit
Crazy accurate spoofing how?
I’m a student at a large state university studying cybersecurity. A couple days ago I got an email from the scholarships office (exact same from...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cruise Photos
Maybe I'm allowed to ask this of the community, maybe I'll get flagged. I went to the Bahamas on a cruise and did an excursion where phones weren't allowed. They took photos of us and naturally expect me to pay $16 for 1 mediocre photo of me with a dolphin. I paid and never received my photo (or it got lost), and now they aren't responding to my inquiries. Based on their site (https://bluelagoonislandphotos.com/index.php?publication_date=07%2F01%2F2022&acategory=5) I feel like there's an easy way of getting this 1 photo without the watermark that I paid for without having to deal with them. Anyone want to verify this hunch? Or maybe I should keep emailing until someone helps me?
submitted by /u/Listen2Drew
[link] [comments]
Cruise Photos
Maybe I'm allowed to ask this of the community, maybe I'll get flagged. I went to the Bahamas on a cruise and did an excursion where phones weren't allowed. They took photos of us and naturally expect me to pay $16 for 1 mediocre photo of me with a dolphin. I paid and never received my photo (or it got lost), and now they aren't responding to my inquiries. Based on their site (https://bluelagoonislandphotos.com/index.php?publication_date=07%2F01%2F2022&acategory=5) I feel like there's an easy way of getting this 1 photo without the watermark that I paid for without having to deal with them. Anyone want to verify this hunch? Or maybe I should keep emailing until someone helps me?
submitted by /u/Listen2Drew
[link] [comments]