Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.Continue reading on Medium » (https://medium.com/@faique/first-bug-bounty-from-dos-taking-the-service-down-30f9ad4e0246?source=rss------bug_bounty-5)
password reset No Rate Limiting
https://medium.com/@rishinikam/password-reset-no-rate-limiting-f46b93088ec0?source=rss------bug_bounty-5
https://medium.com/@rishinikam/password-reset-no-rate-limiting-f46b93088ec0?source=rss------bug_bounty-5
hey gusy my name RISHI NIKAM i am Security Researcher and bug bounty hunterContinue reading on Medium » (https://medium.com/@rishinikam/password-reset-no-rate-limiting-f46b93088ec0?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Become a Penetration Tester
https://cdn-images-1.medium.com/max/2600/1*LqNasta6RoVbPe0vK0wGHA.jpeg
The act of simulating cyber attacks against a digital asset or infrastructure is called a penetration test.
Continue reading on Medium »
How to Become a Penetration Tester
https://cdn-images-1.medium.com/max/2600/1*LqNasta6RoVbPe0vK0wGHA.jpeg
The act of simulating cyber attacks against a digital asset or infrastructure is called a penetration test.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
First Bug Bounty from DOS: Taking the service down
https://cdn-images-1.medium.com/max/2264/1*fJsu3ba2_EsIkHJwbb18iQ.png
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.
Continue reading on Medium »
First Bug Bounty from DOS: Taking the service down
https://cdn-images-1.medium.com/max/2264/1*fJsu3ba2_EsIkHJwbb18iQ.png
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I Rickrolled My Entire Class
https://cdn-images-1.medium.com/max/640/0*jzTGgApwBnekdRcd
This is the story of how I managed to Rickroll my entire class. Just with some simple Python scripting and a USB Rubber Ducky. Read how…
Continue reading on Medium »
How I Rickrolled My Entire Class
https://cdn-images-1.medium.com/max/640/0*jzTGgApwBnekdRcd
This is the story of how I managed to Rickroll my entire class. Just with some simple Python scripting and a USB Rubber Ducky. Read how…
Continue reading on Medium »
hacking: security in practice
Did email get intercepted in flight, or what happened here? (Scam)
Hi all, apologies in advance for the long story and for my ignorance on the subject, but I'm trying to figure out what happened here and I thought maybe someone would be able to shed some light!
A brief intro: In short, my girlfriend hired a company in Italy (she is from South America) to assist her in a process locally. The fees would be paid in three installments across the length of the process. The service itself has been provided, and the company all in all, is legit.
The issue: The first installment was correctly paid to the company's account, whose information (as well as all other communication) was provided via email. The second installment however ended up in some other random account, but here is the strange bit... The information of that random account came in an email, sent from the company's domain, which was an exact copy of previous emails, except for the account number.
When confronted, the company said that the email was "hacked" and modified in flight, and that nothing was wrong on their end. They also advised to check, in Gmail, the "show original" section to see whether the email came from another address, and effectively, it seemed that the "real" email address was a different one altogether, only using the company's one as a mask. In the end she was scammed out of a bit more than a thousand USD, and no one took responsibility.
Anyone has any idea what could have happened here? If she received a "cloned" email, why didn't she receive the original email from the company too? Can these "in-flight" interceptions really happen? Or is there an easier explanation to this?
Thanks!!!
submitted by /u/Patopml
[link] [comments]
Did email get intercepted in flight, or what happened here? (Scam)
Hi all, apologies in advance for the long story and for my ignorance on the subject, but I'm trying to figure out what happened here and I thought maybe someone would be able to shed some light!
A brief intro: In short, my girlfriend hired a company in Italy (she is from South America) to assist her in a process locally. The fees would be paid in three installments across the length of the process. The service itself has been provided, and the company all in all, is legit.
The issue: The first installment was correctly paid to the company's account, whose information (as well as all other communication) was provided via email. The second installment however ended up in some other random account, but here is the strange bit... The information of that random account came in an email, sent from the company's domain, which was an exact copy of previous emails, except for the account number.
When confronted, the company said that the email was "hacked" and modified in flight, and that nothing was wrong on their end. They also advised to check, in Gmail, the "show original" section to see whether the email came from another address, and effectively, it seemed that the "real" email address was a different one altogether, only using the company's one as a mask. In the end she was scammed out of a bit more than a thousand USD, and no one took responsibility.
Anyone has any idea what could have happened here? If she received a "cloned" email, why didn't she receive the original email from the company too? Can these "in-flight" interceptions really happen? Or is there an easier explanation to this?
Thanks!!!
submitted by /u/Patopml
[link] [comments]
reddit
Did email get intercepted in flight, or what happened here? (Scam)
Hi all, apologies in advance for the long story and for my ignorance on the subject, but I'm trying to figure out what happened here and I thought...
hacking: security in practice
Crazy accurate spoofing how?
I’m a student at a large state university studying cybersecurity. A couple days ago I got an email from the scholarships office (exact same from name and address) saying I was awarded a scholarship and I was completely convinced but it ended up being my friend who thought it would be funny.
My question is how is this possible. The domain name is exactly the same @school name.edu and it did not go to my spam or anything. I would imagine that a big university would have SPF or something similar. How was he able to do this?
submitted by /u/MixableCarrot
[link] [comments]
Crazy accurate spoofing how?
I’m a student at a large state university studying cybersecurity. A couple days ago I got an email from the scholarships office (exact same from name and address) saying I was awarded a scholarship and I was completely convinced but it ended up being my friend who thought it would be funny.
My question is how is this possible. The domain name is exactly the same @school name.edu and it did not go to my spam or anything. I would imagine that a big university would have SPF or something similar. How was he able to do this?
submitted by /u/MixableCarrot
[link] [comments]
reddit
Crazy accurate spoofing how?
I’m a student at a large state university studying cybersecurity. A couple days ago I got an email from the scholarships office (exact same from...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cruise Photos
Maybe I'm allowed to ask this of the community, maybe I'll get flagged. I went to the Bahamas on a cruise and did an excursion where phones weren't allowed. They took photos of us and naturally expect me to pay $16 for 1 mediocre photo of me with a dolphin. I paid and never received my photo (or it got lost), and now they aren't responding to my inquiries. Based on their site (https://bluelagoonislandphotos.com/index.php?publication_date=07%2F01%2F2022&acategory=5) I feel like there's an easy way of getting this 1 photo without the watermark that I paid for without having to deal with them. Anyone want to verify this hunch? Or maybe I should keep emailing until someone helps me?
submitted by /u/Listen2Drew
[link] [comments]
Cruise Photos
Maybe I'm allowed to ask this of the community, maybe I'll get flagged. I went to the Bahamas on a cruise and did an excursion where phones weren't allowed. They took photos of us and naturally expect me to pay $16 for 1 mediocre photo of me with a dolphin. I paid and never received my photo (or it got lost), and now they aren't responding to my inquiries. Based on their site (https://bluelagoonislandphotos.com/index.php?publication_date=07%2F01%2F2022&acategory=5) I feel like there's an easy way of getting this 1 photo without the watermark that I paid for without having to deal with them. Anyone want to verify this hunch? Or maybe I should keep emailing until someone helps me?
submitted by /u/Listen2Drew
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Securing Containers with Twistlock
https://cdn-images-1.medium.com/max/788/1*wxe6HeAK0oXI9CQnDJb6UQ.png
Introduction -
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Securing Containers with Twistlock
https://cdn-images-1.medium.com/max/788/1*wxe6HeAK0oXI9CQnDJb6UQ.png
Introduction -
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Securing Containers with Twistlock
Introduction -
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking Tools: John The Ripper
https://cdn-images-1.medium.com/max/1964/0*Ptfv3HnW96SEdirS.png
Hello World and welcome to HaXez, the game’s afoot and in this post, I’m going to be talking about my favorite password-cracking tool…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Hacking Tools: John The Ripper
https://cdn-images-1.medium.com/max/1964/0*Ptfv3HnW96SEdirS.png
Hello World and welcome to HaXez, the game’s afoot and in this post, I’m going to be talking about my favorite password-cracking tool…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking Tools: John The Ripper
Hello World and welcome to HaXez, the game’s afoot and in this post, I’m going to be talking about my favorite password-cracking tool, John…
hacking: security in practice
Memory dump tool? Experience in dumping RAM?
An RDP computer in our environment updated it's OS and now is failing to boot. It was BitLocker encrypted and unfortunately the key had been lost. This of course was a bit of a dead end, but it got me interested in learning more about BitLocker encryption and methods of attack.
A few articles and cups of coffee later and now I want to learn more about cold boot attacks. The Volume Master Key(VMK) is stored in ram upon boot, so it can be validated against user input. Apparently it is possible to perform a ram dump from which you can extract the VMK. And bingo, you should be able to enter said key and access WinRE. Pray to the computer gods 💾and do some update rollbacks or restores to try to unfudge the OS.
In the articles and videos I've seen it's claimed they can cool down the ram to prevent data decay and quickly insert it into another device to perform the dump. Sounds a little complicated to perform, but heck, I'd be willing to try on an old machine of mine.
Does anyone have experience with this type of thing? It's not a necessity to fix this users computer; it just sparks my interest to learn more. It seems like a sensible enough of a need for their to be a tool in existence already. I image a stick of ram with a direct interface to an external machine, but haven't come across any.
submitted by /u/Sloqwerty
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Memory dump tool? Experience in dumping RAM?
An RDP computer in our environment updated it's OS and now is failing to boot. It was BitLocker encrypted and unfortunately the key had been lost. This of course was a bit of a dead end, but it got me interested in learning more about BitLocker encryption and methods of attack.
A few articles and cups of coffee later and now I want to learn more about cold boot attacks. The Volume Master Key(VMK) is stored in ram upon boot, so it can be validated against user input. Apparently it is possible to perform a ram dump from which you can extract the VMK. And bingo, you should be able to enter said key and access WinRE. Pray to the computer gods 💾and do some update rollbacks or restores to try to unfudge the OS.
In the articles and videos I've seen it's claimed they can cool down the ram to prevent data decay and quickly insert it into another device to perform the dump. Sounds a little complicated to perform, but heck, I'd be willing to try on an old machine of mine.
Does anyone have experience with this type of thing? It's not a necessity to fix this users computer; it just sparks my interest to learn more. It seems like a sensible enough of a need for their to be a tool in existence already. I image a stick of ram with a direct interface to an external machine, but haven't come across any.
submitted by /u/Sloqwerty
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Memory dump tool? Experience in dumping RAM?
An RDP computer in our environment updated it's OS and now is failing to boot. It was BitLocker encrypted and unfortunately the key had been lost....
hacking: security in practice
'.' has connected to my chromecast and now PS4
Been watching YouTube on chromecast, but someone would be controlling it. Ofc at first I thought it was someone else in the house, but recent events have shown that it isn't.
They will change volume, fast forward, turn on captions, change vids, etc.
My PS4 YouTube was even connected to when I just decided to make the switch.
It 100% isn't house members, and I am questioning the possibility of a sibling getting her friends to fuck with us, but that wouldn't work unless they were literally outside the front door.
submitted by /u/tyyls18
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
'.' has connected to my chromecast and now PS4
Been watching YouTube on chromecast, but someone would be controlling it. Ofc at first I thought it was someone else in the house, but recent events have shown that it isn't.
They will change volume, fast forward, turn on captions, change vids, etc.
My PS4 YouTube was even connected to when I just decided to make the switch.
It 100% isn't house members, and I am questioning the possibility of a sibling getting her friends to fuck with us, but that wouldn't work unless they were literally outside the front door.
submitted by /u/tyyls18
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
'.' has connected to my chromecast and now PS4
Been watching YouTube on chromecast, but someone would be controlling it. Ofc at first I thought it was someone else in the house, but recent...