Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Intigriti’s July 0722 XSS Challenge Writeup

I. OverviewContinue reading on Medium »
Read more...
Dear all pen testers I have a few questions for you all that I would love to hear the answers to:
https://www.reddit.com/r/Pentesting/comments/wd7m1w/dear_all_pen_testers_i_have_a_few_questions_for/

1: is a college degree required for this field, could I get a job by just hardcore studying it right out of highschool? 2: How much do or did you make starting out yearly salary? 3: How many hours a week do you work? 4: do you have to have your own machine or software in order to “pen test” or are there softwares that can do it for you? 5: for those of you who work remote, when you are paid, do they take taxes out? Or do they send you the 1099 form for that? submitted by /u/boxing1414 (https://www.reddit.com/user/boxing1414)
[link] (https://www.reddit.com/r/Pentesting/comments/wd7m1w/dear_all_pen_testers_i_have_a_few_questions_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/wd7m1w/dear_all_pen_testers_i_have_a_few_questions_for/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to identify types of chips in cards and cloning them?

Main Question:

I've got a bus pass for work as a newbie software engineer. intrigued in the system, as it was prosseing both the payment and bus pass (pysical card) on what looked like the same receiver, I was wondering whether or not they had they had same chip but differnet instruftions... idk?



Side note:

I was wanting to clone my card anyway as I loose it alot and having spares would be a big relief. Does anyone how how I would do this?

submitted by /u/SadMongoos
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Have any recommendations on articles/videos on decompiling old Win3.0/DOS games? Ghidra?

I recently stumbled upon a few floppy disks of super old MS DOS games, and I'm looking to learn how to use Ghidra or some other tools to decompile those games, embedded assets, and other stuff. I want to try re-compiling them with custom tweaks. Or maybe code injection? Let me know if you have any ideas or recommendations. DrainStorm is one of them. I've also got Chips Challenge, the original. Ski Free. Some real random goodies.

submitted by /u/natesovenator
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Responder Starting Point HacktheBox Walkthrough

Responder Starting Point is a very good Challenge by HackTheBox. In this article we are going exploit it.Continue reading on Medium »
Read more...
Possible 2FA compromise with login approval on Facebook.

When two factor authentication is enabled in Facebook you can login to the account by approving that login from a session where you are…Continue reading on Medium »
Read more...
This SIMPLE vulnerability in Shopify earned a $2500 bug bounty

Don’t forget to check for user access rightsContinue reading on InfoSec Write-ups »
Read more...
How I earned $10,000 within the last 7 months — 17y/o Edition

you know that I mostly earn bounties in Cryptocurrencies and this leads to the answer → I mostly hunt on XXXXXXXXXXXXContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks

XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacksPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A pair of vulnerabilities in Google Cloud, DevSite, and Google Play could have allowed attackers to achieve cross-site scripting (XSS) attacks, opening the door to account hijacks.The first vulnerability is a reflected XSS bug in Google DevSite. An attacker-controlled link could run JavaScript on the origins http://cloud.google.com and http://developers.google.com, meaning a malicious actor could read and modify its contents, bypassing the same-origin policy.

Researcher ‘NDevTK’, who discovered both vulnerabilities, wrote: “Due to a vulnerability in the server-side implementation of BountyThe researcher earned $3,133.70 for the DevSite issue and $5,000 for the vulnerability in Google Play.

Speaking to The Daily Swig, they said that they were “happy with the bounty”.
Trending: GitHub introduces 2FA and quality of life improvements for npm Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-2-1-300x150.png Microsoft SQL servers hacked to steal bandwidth with proxywareJuly 29, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-1-2-300x150.png GitHub introduces 2FA and quality of life improvements for npmJuly 28, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-5-300x150.png Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused BrandsJuly 27, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/0[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacksPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp…
7/Images-for-the-News-posts-1-1-300x150.png Cisco patches dangerous bug trio in Nexus DashboardJuly 26, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
This SIMPLE vulnerability in Shopify earned a $2500 bug bounty

Don’t forget to check for user access rightsContinue reading on InfoSec Write-ups »
Read more...