Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HacktheBox[Sauna]
https://cdn-images-1.medium.com/max/675/1*9jE4Hadz7oteUR7OFA2-4Q.png
Sauna was an easy box on HacktheBox platform that involved enumerating users with Kerbrute to identify a user that does not require…
Continue reading on Medium »
HacktheBox[Sauna]
https://cdn-images-1.medium.com/max/675/1*9jE4Hadz7oteUR7OFA2-4Q.png
Sauna was an easy box on HacktheBox platform that involved enumerating users with Kerbrute to identify a user that does not require…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox: Lame— Walkthrough
https://cdn-images-1.medium.com/max/764/1*SHdOWEJgmQqNXSwjXZWhiQ.png
Welcome! It is time to look at the Lame machine on HackTheBox. I am making these walkthroughs to keep myself motivated to learn cyber…
Continue reading on Medium »
HackTheBox: Lame— Walkthrough
https://cdn-images-1.medium.com/max/764/1*SHdOWEJgmQqNXSwjXZWhiQ.png
Welcome! It is time to look at the Lame machine on HackTheBox. I am making these walkthroughs to keep myself motivated to learn cyber…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Jak postawić krok w stronę at APT poprzez programowanie?
Haker by móc sprawnie wykonywać swój zawód, musi/powinien znać parę języków poza Python’em, oto one: C, Assembler, VBS, PHP, HTML, CSS…
Continue reading on Medium »
Jak postawić krok w stronę at APT poprzez programowanie?
Haker by móc sprawnie wykonywać swój zawód, musi/powinien znać parę języków poza Python’em, oto one: C, Assembler, VBS, PHP, HTML, CSS…
Continue reading on Medium »
How this EASY vulnerability resulted in a $20,000 bug bounty from GitLab
The hidden dangers of numerical IDsContinue reading on InfoSec Write-ups »
Read more...
The hidden dangers of numerical IDsContinue reading on InfoSec Write-ups »
Read more...
Why this EASY vulnerability resulted in a $20,000 bug bounty from GitLab
https://infosecwriteups.com/how-this-easy-vulnerability-resulted-in-a-20-000-bug-bounty-from-gitlab-d9dc9312c10a?source=rss------bug_bounty-5
https://infosecwriteups.com/how-this-easy-vulnerability-resulted-in-a-20-000-bug-bounty-from-gitlab-d9dc9312c10a?source=rss------bug_bounty-5
The hidden dangers of numerical IDsContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-this-easy-vulnerability-resulted-in-a-20-000-bug-bounty-from-gitlab-d9dc9312c10a?source=rss------bug_bounty-5)
should I , and how to, start studying for OSCP ?
https://www.reddit.com/r/Pentesting/comments/wcwxy8/should_i_and_how_to_start_studying_for_oscp/
<!-- SC_OFF -->I am a pentester with 2 years of work experience and lots of htb and ctfs and have CEH. Based on reviews the OSCP is the next step to be a better pentester and especially find better salaries and more challenging jobs. So i decided to invest money and time in it. Is the OSCP really the one ? Or are there better options ? If so, any dumps or courses, learning paths, ressources or advice ? because the only thing i know now is that it's a very hard certification and will cost a lot of money. <!-- SC_ON --> submitted by /u/wardsareOP (https://www.reddit.com/user/wardsareOP)
[link] (https://www.reddit.com/r/Pentesting/comments/wcwxy8/should_i_and_how_to_start_studying_for_oscp/) [comments] (https://www.reddit.com/r/Pentesting/comments/wcwxy8/should_i_and_how_to_start_studying_for_oscp/)
https://www.reddit.com/r/Pentesting/comments/wcwxy8/should_i_and_how_to_start_studying_for_oscp/
<!-- SC_OFF -->I am a pentester with 2 years of work experience and lots of htb and ctfs and have CEH. Based on reviews the OSCP is the next step to be a better pentester and especially find better salaries and more challenging jobs. So i decided to invest money and time in it. Is the OSCP really the one ? Or are there better options ? If so, any dumps or courses, learning paths, ressources or advice ? because the only thing i know now is that it's a very hard certification and will cost a lot of money. <!-- SC_ON --> submitted by /u/wardsareOP (https://www.reddit.com/user/wardsareOP)
[link] (https://www.reddit.com/r/Pentesting/comments/wcwxy8/should_i_and_how_to_start_studying_for_oscp/) [comments] (https://www.reddit.com/r/Pentesting/comments/wcwxy8/should_i_and_how_to_start_studying_for_oscp/)
hacking: security in practice
Anyone know where I can find a PoC for CVE-2021-28664
I have a Hisense U8G with Android 10 kernel version 4.19.75 with a 32 bit userland. Already unlocked the bootloader, but the firmware package is encrypted with a key that I can only get after rooting.
I need some other way to dump my boot.img and the kernel is too old for DirtyPipe and too new for mtk-su. The exploit in the title should work for me, but I can't find any PoC to run.
I just need temp root basically
submitted by /u/WeedyPests
[link] [comments]
Anyone know where I can find a PoC for CVE-2021-28664
I have a Hisense U8G with Android 10 kernel version 4.19.75 with a 32 bit userland. Already unlocked the bootloader, but the firmware package is encrypted with a key that I can only get after rooting.
I need some other way to dump my boot.img and the kernel is too old for DirtyPipe and too new for mtk-su. The exploit in the title should work for me, but I can't find any PoC to run.
I just need temp root basically
submitted by /u/WeedyPests
[link] [comments]
reddit
Anyone know where I can find a PoC for CVE-2021-28664
I have a Hisense U8G with Android 10 kernel version 4.19.75 with a 32 bit userland. Already unlocked the bootloader, but the firmware package is...
hacking: security in practice
Is it possible retrieve data from RAM?
This question seems stupid, but is it possible to retrieve any data from RAM sticks? You can get data from formatted hard drives, but is it possible to do so with RAM? Since memory is temporarily put there?
submitted by /u/Legend5V
[link] [comments]
Is it possible retrieve data from RAM?
This question seems stupid, but is it possible to retrieve any data from RAM sticks? You can get data from formatted hard drives, but is it possible to do so with RAM? Since memory is temporarily put there?
submitted by /u/Legend5V
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Hackers who couldn't keep their anonymity on the dark web, Were they complacent?
I have always believed its very rare that a technical flaw or fault in Tor is hacked to reveal someone, and when that happens the Tor Project, the foundation that maintains Tor, fixes the problem quickly.
Nearly all people on the dark web aren’t caught by hacking. There’s nobody sitting in front of a keyboard in a darkened room typing furiously whilst muttering “I’ve penetrated the first firewall, but he’s routing packets from the tachyon field emitter through the main deflector dish.”
Almost all Tor users are trapped in meatspace. If you're selling drugs, illegal firearms, or whatever, the transaction on Tor is very tough to trace, but you'll need to transfer the drugs, guns, or whatever in the real world at some point—you can't just download them. And that's the entry point
The Silk Road's proprietor was apprehended after postal inspectors discovered an ecstasy pill package in the mail. They went to the post office where it was shipped, uncovered security tape, and learned that the suspect visited that post office repeatedly, so they set up surveillance and captured him.
Even cases where Tor is hacked don’t work like Hollywood says.
Back in 2014, police arrested a pedophile and found a huge cache of child abuse pictures on his computer. The arrest had nothing to do with hacking or the dark web. when they interrogated him about the pictures, he said he downloaded them from a dark web site called Playpen
That led them to Steven Chase, the owner and creator of the site.
Hacking only came into it after that.
Law enforcement discovered a security weakness in Tor that allowed malware to be downloaded. When they apprehended the site owner, they left the site up for over two weeks, configured to distribute malware to anybody who visited. The virus transmitted the IP address and location of the machine to a server. Police were able to identify and arrest everyone who visited the site during the two weeks it was up after it was confiscated.
Tor's issue was quickly resolved.
Tor is seldom, if ever, "hacked" by law enforcement. Almost all dark net busts begin in the real world, away from computers, and then shift online when cops act as customers or other vendors and set up old-fashioned undercover operations.
submitted by /u/Simonvilla1
[link] [comments]
Hackers who couldn't keep their anonymity on the dark web, Were they complacent?
I have always believed its very rare that a technical flaw or fault in Tor is hacked to reveal someone, and when that happens the Tor Project, the foundation that maintains Tor, fixes the problem quickly.
Nearly all people on the dark web aren’t caught by hacking. There’s nobody sitting in front of a keyboard in a darkened room typing furiously whilst muttering “I’ve penetrated the first firewall, but he’s routing packets from the tachyon field emitter through the main deflector dish.”
Almost all Tor users are trapped in meatspace. If you're selling drugs, illegal firearms, or whatever, the transaction on Tor is very tough to trace, but you'll need to transfer the drugs, guns, or whatever in the real world at some point—you can't just download them. And that's the entry point
The Silk Road's proprietor was apprehended after postal inspectors discovered an ecstasy pill package in the mail. They went to the post office where it was shipped, uncovered security tape, and learned that the suspect visited that post office repeatedly, so they set up surveillance and captured him.
Even cases where Tor is hacked don’t work like Hollywood says.
Back in 2014, police arrested a pedophile and found a huge cache of child abuse pictures on his computer. The arrest had nothing to do with hacking or the dark web. when they interrogated him about the pictures, he said he downloaded them from a dark web site called Playpen
That led them to Steven Chase, the owner and creator of the site.
Hacking only came into it after that.
Law enforcement discovered a security weakness in Tor that allowed malware to be downloaded. When they apprehended the site owner, they left the site up for over two weeks, configured to distribute malware to anybody who visited. The virus transmitted the IP address and location of the machine to a server. Police were able to identify and arrest everyone who visited the site during the two weeks it was up after it was confiscated.
Tor's issue was quickly resolved.
Tor is seldom, if ever, "hacked" by law enforcement. Almost all dark net busts begin in the real world, away from computers, and then shift online when cops act as customers or other vendors and set up old-fashioned undercover operations.
submitted by /u/Simonvilla1
[link] [comments]
reddit
Hackers who couldn't keep their anonymity on the dark web, Were...
I have always believed its very rare that a technical flaw or fault in Tor is hacked to reveal someone, and when that happens the Tor Project, the...
hacking: security in practice
A good TCP Network proxy?
I am looking for free and deacent TCP network proxy (for more than just HTTP/S) with functionality of repeating (replaying) packets? (Not burpsuite + nope plugin, its only in Pro version and im poor)
submitted by /u/-Elim
[link] [comments]
A good TCP Network proxy?
I am looking for free and deacent TCP network proxy (for more than just HTTP/S) with functionality of repeating (replaying) packets? (Not burpsuite + nope plugin, its only in Pro version and im poor)
submitted by /u/-Elim
[link] [comments]
reddit
A good TCP Network proxy?
I am looking for free and deacent TCP network proxy (for more than just HTTP/S) with functionality of repeating (replaying) packets? (Not...
hacking: security in practice
I'm a noob with expensive equipment
Hey! I'm a complete beginner to hacking / cybersecurity trying to find out what is the best way to start learning.
My advantage (I think) is that I have pretty good hardware that will help me carry out more intensive operations. I have a PC running on Windows 10 Pro with a RYZEN 9 5950X, ASUS RTX 3090, 64GB, 2TB SSD, and 8TB HDD. I also have a relatively new Windows laptop that I'm thinking of transferring to a Linux if possible (Specs: 10th gen i7-10510U CPU, 16GB RAM, 500GB SSD).
I know nothing about Linux, nor am I fluent in any programming languages. Treat me as a complete beginner.
How do you recommend that I take advantage of the equipment that I have? I'll probably need to keep my main PC running on Windows since I use my PC to earn an income and Windows is my familiar platform, but maybe it's possible to access my laptop through the main PC to take advantage of the PC's power.
Also, those of you who have lots of experience—what learning approach do you wish you would have taken when you first started?
submitted by /u/ish13c
[link] [comments]
I'm a noob with expensive equipment
Hey! I'm a complete beginner to hacking / cybersecurity trying to find out what is the best way to start learning.
My advantage (I think) is that I have pretty good hardware that will help me carry out more intensive operations. I have a PC running on Windows 10 Pro with a RYZEN 9 5950X, ASUS RTX 3090, 64GB, 2TB SSD, and 8TB HDD. I also have a relatively new Windows laptop that I'm thinking of transferring to a Linux if possible (Specs: 10th gen i7-10510U CPU, 16GB RAM, 500GB SSD).
I know nothing about Linux, nor am I fluent in any programming languages. Treat me as a complete beginner.
How do you recommend that I take advantage of the equipment that I have? I'll probably need to keep my main PC running on Windows since I use my PC to earn an income and Windows is my familiar platform, but maybe it's possible to access my laptop through the main PC to take advantage of the PC's power.
Also, those of you who have lots of experience—what learning approach do you wish you would have taken when you first started?
submitted by /u/ish13c
[link] [comments]
reddit
I'm a noob with expensive equipment
Hey! I'm a complete beginner to hacking / cybersecurity trying to find out what is the best way to start learning. My advantage (I think) is that...
hacking: security in practice
Online Hash Crack is saying an encrypted file isn't encrypted?
Its a WinRar archive / .7z file. I try to use either the Password Recovery (right side) or the hash extractor, but it tells me it's either unsupported or not encrypted.
What is going on?
submitted by /u/Trashspeak
[link] [comments]
Online Hash Crack is saying an encrypted file isn't encrypted?
Its a WinRar archive / .7z file. I try to use either the Password Recovery (right side) or the hash extractor, but it tells me it's either unsupported or not encrypted.
What is going on?
submitted by /u/Trashspeak
[link] [comments]
reddit
Online Hash Crack is saying an encrypted file isn't encrypted?
Its a WinRar archive / .7z file. I try to use either the [Password Recovery](https://www.onlinehashcrack.com/) (right side) or the [hash...
How to Exploit CSRF (Cross Site Request Forgery) in Web Applications — Pentester Academy Challenge
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
How to Exploit CSRF (Cross Site Request Forgery) in Web Applications — Pentester Academy Challenge
https://medium.com/@jawadkaxmi/how-to-exploit-csrf-cross-site-request-forgery-in-web-applications-pentester-academy-challenge-f86e1694e73c?source=rss------bug_bounty-5
https://medium.com/@jawadkaxmi/how-to-exploit-csrf-cross-site-request-forgery-in-web-applications-pentester-academy-challenge-f86e1694e73c?source=rss------bug_bounty-5