Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Need help with Hydra
https://www.reddit.com/r/Pentesting/comments/w3yfbx/need_help_with_hydra/

Hello I'm starting learning Pen Testing and I want to try simple brute force on site I got permission to try to and my command's doesn't work as I expected to, because Hydra doesn't recognise even account I created for this. In browser link to login site looks like example.com/en/login but in network tab of browser inspection it is method Post with URL like example.com/api/auth/callback/credentials? And the Request is "redirect=false&email=e-mail@mail.com (mailto:e-mail@mail.com)&password=anypassword&csrfToken=LongTokenId&callbackURL=example.com/en/login&json=true" so the command I've tried to use was: hydra -L /directory to file/emailtest -P /directory to file/passtest example.com -V http-post-form "/api/auto/callback/credentials?:email=^USER^&password=^PASS^:S=logout" And this can't really find my e-mail and password working, should I try to use example.com/en/login in command line instead of those API/../credentials or I should use whole request with token and redirect stuff or maybe someone could try to help me with command that I could see how this should be done, I can say that I've tried on "easy" site like from HackTheBox but there weren't tokens ect so I'm kinda confused with reality rn. Thanks for all the answers and sorry for my English submitted by /u/AffectionateTrash202 (https://www.reddit.com/user/AffectionateTrash202)
[link] (https://www.reddit.com/r/Pentesting/comments/w3yfbx/need_help_with_hydra/) [comments] (https://www.reddit.com/r/Pentesting/comments/w3yfbx/need_help_with_hydra/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
(Reverse) SSH tunnel from work over HTTP(s) proxy to a home computer behind NAT?

Hello guys,

when working from home, I am supposed to access my work computers in the office with Remotedesktop/VNC. But this VNC is very very very slow, so work is no fun.

There is also no direct SSH access: Home -> Work.

However, I would like to have SSH access from home to my computer in the office.

I have two work computers in the office: one with Ubuntu 18.4 and root access and a PC with Windows 10 with Putty but without root access, so theoretically I could make an (reverse?) SSH tunnel from my work computer with Linux to my PC at home, which also has Ubuntu.

The two computers at the office are behind NAT and an HTTP(s) proxy.

The machine at home is behind NAT, but my router at home is reachable from the internet via a public IP (both IPv4 and IPv6), so I can set up port forwarding: 443 on the router -> 22 (or another) on the PC.

I would also like to use an SSH key for this.
I got:
[Linux@work], [Windows@work] ---> [Proxy@work] ---> Internet <---[Router@home] <---[Linux@home]


I want:
[Linux@home] --ssh-tunnel--> [Linux@work]

Is this possible at all?

And if so, how?

submitted by /u/letmyseeyoustripped
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Advice on how to get into pen test job with current experience
https://www.reddit.com/r/Pentesting/comments/w3zzc5/advice_on_how_to_get_into_pen_test_job_with/

Hi. I was wanting opinions of what I should obtain/work on now. I am looking to work in the offensive security field. I have the OSCP (new version) and PenTest+ (new version). I don't have any other certifications besides those. I got the oscp first then did pentest+. I mostly did pentest+ because of the dod 8570/8140. I am worried about applying to jobs as I only have a high school education and no security experience (just IT experience and not much experience on paper). I feel like these certs are not enough so I wanted to know opinions of what other certifications I should do now ? I was hoping to stack my certifications high with maybe 4-5 to stand out idk though. I would take the GPEN but it's crazy high expensive and the other offsec certifications are a bit expensive too considering I don't work in the field yet. I would rather get employed somewhere and have them pay for it. Am I on the right path trying to get more certifications ? I eventually soon would like a pen test job or something similar. Or would I be better off trying to do bug bounties to show on the resume? Like what could I do to make my potential resume stand out more from others ? I would like to avoid getting a help desk job, no offense. I have been preparing for offensive security for quite awhile and hope to get that type of role. I don't know the market right now and if there is a saturation of people or understaffed places for offensive security roles. In my 20s. Please let me know thoughts. I also posted this to a different sub reddit. submitted by /u/wakwakwalk (https://www.reddit.com/user/wakwakwalk)
[link] (https://www.reddit.com/r/Pentesting/comments/w3zzc5/advice_on_how_to_get_into_pen_test_job_with/) [comments] (https://www.reddit.com/r/Pentesting/comments/w3zzc5/advice_on_how_to_get_into_pen_test_job_with/)

___________________________
@hacking_Attack
@Hacking_Video
Enjoy!

___________________________
@hacking_Attack
@Hacking_Video