Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Deep Web
Like the Limitless guy

Do you know where I can find, out of pure curiosity, a drug on the deepweb that activates 100% of the brain like the guy in the movie Limitless does? Does a similar substance even exist? And if it does, can it be bought legally? I have so many things to do in so little time (my Bachelor thesis, an exam on an Asian language, a piano competition etc) and I would really need a brain booster right now. Please let me know, and thank you to whoever wants to help me!!!

submitted by /u/Lemon9800
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Posta - Cross-document Messaging Security Research Tool

Posta is a tool for researching Cross-document Messaging communication. It allows you to track, explore and exploit postMessage vulnerabilities, and includes features such as replaying messages sent between windows within any attached browser.Prerequisites Google Chrome / Chromium Node.js (optional) Installation Development Environment Run Posta in a full development environment with a dedicated browser (Chromium): Install Posta git clone https://github.com/benso-io/postacd postanpm install Launch the dedicated Chromium session using the following command: node posta Click on the Posta extension to navigate to the UI Dev mode includes a local web server that serves a small testing site and the exploit page. When running in dev mode, you can access the exploit page at http://localhost:8080/exploit/ Chrome Extension Run Posta as a Chrome / Chromium Extension: Clone the repo: git clone https://github.com/benso-io/posta.git Navigate to chrome://extensions Make sure Developer mode is enabled Click on Load unpacked Choose the chrome-extension directory inside Posta and upload it to your browser Load the extension Pin the extension to your browser Browse to the website you would like to examine Click on the Posta extension to navigate to the UI Tabs In the Tabs section we can find our main Origin, with the iframes it hosts and communicates with through the session. We can choose the specific frame by clicking on it, and observe the postMessages related to that frame only.Messages In the Messages section, we can inspect all postMessage traffic being sent from the origin to its iframes, and vice versa. We can select specific communication for further examination by clicking on it. The Listeners area presents the code which is in charge of handling the communication, we can click and copy its contents for JS code observation. Console In the console section, we can modify the original postMessage traffic, and replay the messages with the tampered values which will be sent from the Origin to its iframe. We should make tests and see if we can affect the behavior of the website by changing the postMessage content. If we manage to do so, it's time to try and exploit if from a different Origin, by clicking "Simulate exploit". Exploit Click on the "host" button inorder to navigate to the exploitation window. In the Exploit section, Posta will try and host the specified origin as an iframe in order to initiate postMessage communication. Most of the time we won't be able to do so, due to X-Frame-Options being enabled on the origin website. Therefore, in order to continue with our exploitation, we'll need to gain communication reference with our Origin by initiating the window.open method, which can be achieved by clicking on "Open as tab". We have the console to our right which will help us modify and craft our specified payloads and test them in Cross-Origin Communication, initiated by clicking on the Exploit button.Authors Chen Gour Arie Barak Tawily Gal Nagli Omer Yaron Download Posta
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking GraphQL for Fun and Profit — Part 1 — Understanding GraphQL Basics

Hello everyone!!
Read more...
https://b.thumbs.redditmedia.com/eXrz20OGEUxW33rKkf-kP5tZOlyoONTIfpinFibNvhs.jpg

So i was just looking for some libraries in Google Search, i just opened the first page links and went on doing something else, later found out that browser was asking for captcha for both of them, i was thinking that something is off, anyways i opened the links and found a copy of Github website, which was doing everything but was not loading any code files, noticed i am logged out, that's where all of my alarms goes off, this is indeed a site to get GitHub passwords. The bad thing is GitHub own links were on page two and these were on first page for me, now i understand how some of the famous Libs [antd] goes black back in jan or feb and then got restored.





https://preview.redd.it/58ijapbnqav61.png?width=619&format=png&auto=webp&s=54f29ca6dc350bd449be329825e0112356dbea7f

Edit - snapshots



https://preview.redd.it/h5ohy9zlsav61.png?width=993&format=png&auto=webp&s=e9204828ec63166abe8544766a5c753da222e913



it won't open any thing, it's just a dummy page



submitted by /u/GroundbreakingWolf7
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Unknown phone number

So, this may not be a subreddit for this, but last night and today, my brother has been getting calls on viber and whatsapp from a Totally random number that's from a different country. I don't know what it is but is it a scam or a hacker maybe? Can anyone help me?

submitted by /u/zargug2
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video