Sudomy-A Subdomain Enumeration And Analysis Tool
Sudomy is a subdomain enumeration tool for collecting subdomains and performing advanced automated reconnaissance on domains (framework)…Continue reading on Medium »
Read more...
Sudomy is a subdomain enumeration tool for collecting subdomains and performing advanced automated reconnaissance on domains (framework)…Continue reading on Medium »
Read more...
Sudomy-A Subdomain Enumeration And Analysis Tool
https://medium.com/@nixiebytes/sudomy-a-subdomain-enumeration-and-analysis-tool-e2521e544344?source=rss------bug_bounty-5
https://medium.com/@nixiebytes/sudomy-a-subdomain-enumeration-and-analysis-tool-e2521e544344?source=rss------bug_bounty-5
Sudomy is a subdomain enumeration tool for collecting subdomains and performing advanced automated reconnaissance on domains (framework)…Continue reading on Medium » (https://medium.com/@nixiebytes/sudomy-a-subdomain-enumeration-and-analysis-tool-e2521e544344?source=rss------bug_bounty-5)
hacking: security in practice
Best hackers on Twitter?
Hello everyone,
Who are the best hackers that you know of on Twitter? Hackers that will respond with questions you have for them.
Thank you,
submitted by /u/Koolji
[link] [comments]
Best hackers on Twitter?
Hello everyone,
Who are the best hackers that you know of on Twitter? Hackers that will respond with questions you have for them.
Thank you,
submitted by /u/Koolji
[link] [comments]
reddit
Best hackers on Twitter?
Hello everyone, Who are the best hackers that you know of on Twitter? Hackers that will respond with questions you have for them. Thank you,
Django web applications with enabled Debug Mode, DB accounts information and API Keys of more than 3,100 applications were exposed on internet, many of which are of either Oauth or RESTfull API
https://www.reddit.com/r/redteamsec/comments/wfuosi/django_web_applications_with_enabled_debug_mode/
submitted by /u/Late_Ice_9288 (https://www.reddit.com/user/Late_Ice_9288)
[link] (https://blog.criminalip.io/2022/07/20/api-key-leak/) [comments] (https://www.reddit.com/r/redteamsec/comments/wfuosi/django_web_applications_with_enabled_debug_mode/)
https://www.reddit.com/r/redteamsec/comments/wfuosi/django_web_applications_with_enabled_debug_mode/
submitted by /u/Late_Ice_9288 (https://www.reddit.com/user/Late_Ice_9288)
[link] (https://blog.criminalip.io/2022/07/20/api-key-leak/) [comments] (https://www.reddit.com/r/redteamsec/comments/wfuosi/django_web_applications_with_enabled_debug_mode/)
Hard coded Google API keys. Pardon my ignorance here but I’m fairly new to bug bounties. Should a find like this be reported? The security on this app looks like a train wreck. I don’t even know where to start.
https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/
submitted by /u/Montanacybergrizz (https://www.reddit.com/user/Montanacybergrizz)
[link] (https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/) [comments] (https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/)
https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/
submitted by /u/Montanacybergrizz (https://www.reddit.com/user/Montanacybergrizz)
[link] (https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/) [comments] (https://www.reddit.com/r/Pentesting/comments/wfum5v/hard_coded_google_api_keys_pardon_my_ignorance/)
How do I become a legit pen tester without getting arrested first?
https://www.reddit.com/r/Pentesting/comments/wfv67h/how_do_i_become_a_legit_pen_tester_without/
<!-- SC_OFF -->I mean, I'm already fucking in and around and through every level of security. How can I tell them they are fucked and get paid for it? <!-- SC_ON --> submitted by /u/FuckApproval (https://www.reddit.com/user/FuckApproval)
[link] (https://www.reddit.com/r/Pentesting/comments/wfv67h/how_do_i_become_a_legit_pen_tester_without/) [comments] (https://www.reddit.com/r/Pentesting/comments/wfv67h/how_do_i_become_a_legit_pen_tester_without/)
https://www.reddit.com/r/Pentesting/comments/wfv67h/how_do_i_become_a_legit_pen_tester_without/
<!-- SC_OFF -->I mean, I'm already fucking in and around and through every level of security. How can I tell them they are fucked and get paid for it? <!-- SC_ON --> submitted by /u/FuckApproval (https://www.reddit.com/user/FuckApproval)
[link] (https://www.reddit.com/r/Pentesting/comments/wfv67h/how_do_i_become_a_legit_pen_tester_without/) [comments] (https://www.reddit.com/r/Pentesting/comments/wfv67h/how_do_i_become_a_legit_pen_tester_without/)
ATMs pentesting
https://www.reddit.com/r/Pentesting/comments/wfvawq/atms_pentesting/
<!-- SC_OFF -->Hi hackers,red teamers,pentesters! I need your help to improve myself with ATMs pentesting, especially I seek for a checklist for an ATM pentesting. I will appreciate if you share any kind of resource regarding this topic 👨🏼💻 <!-- SC_ON --> submitted by /u/IntelligentPattern10 (https://www.reddit.com/user/IntelligentPattern10)
[link] (https://www.reddit.com/r/Pentesting/comments/wfvawq/atms_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/wfvawq/atms_pentesting/)
https://www.reddit.com/r/Pentesting/comments/wfvawq/atms_pentesting/
<!-- SC_OFF -->Hi hackers,red teamers,pentesters! I need your help to improve myself with ATMs pentesting, especially I seek for a checklist for an ATM pentesting. I will appreciate if you share any kind of resource regarding this topic 👨🏼💻 <!-- SC_ON --> submitted by /u/IntelligentPattern10 (https://www.reddit.com/user/IntelligentPattern10)
[link] (https://www.reddit.com/r/Pentesting/comments/wfvawq/atms_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/wfvawq/atms_pentesting/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisory
Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisoryPost Views: 65 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Open source DevOps platform Jenkins is warning users of unpatched security vulnerabilities impacting more than a dozen plugins.A leading open source automation server, Jenkins provides thousands of plugins to support building, deploying, and automating projects.
The organization’s latest security advisory lists a total of 27 plugin vulnerabilities, five of which were deemed to be ‘high’ impact and the majority of which remain unpatched.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course High fiveFirst on the list of high impact bugs – all of which were unfixed at the time of writing – is a cross-site request forgery (CSRF) vulnerability in the Coverity plugin (CVE-2022-36920).
It was found that the plugin fails to perform a permission check in an HTTP endpoint. In addition, this HTTP endpoint does not require POST requests, opening the door to CSRF attacks.
Meanwhile, an arbitrary file write vulnerability in the CLIF Performance Testing Plugin (CVE-2022-36894) allows attackers with ‘Overall/Read’ permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
Stored cross-site scripting (XSS) flaws were also discovered in the Dynamic Extended Choice Parameter plugin (CVE-2022-36902) and Maven Metadata plugin (CVE-2022-36905), along with a reflected XSS vulnerability in the Lucene-Search plugin (CVE-2022-36922).
Trending: The Difference between White-Box and Black-Box Pentesting Trending: Offensive Security Tool: DDoS-Layer7-bheh Getting the word outOf the 27 plugin vulnerabilities listed in the latest Jenkins security advisory, 18 remained unpatched and are effectively zero-days.
Discussing the team’s decision to disclose these issues to the community in lieu of any fixes, Jenkins security officer Wadeck Follonier told The Daily Swig: “The main objective of the Jenkins security team is to ensure the Jenkins plugin ecosystem is as secure as possible.
“With a plugin ecosystem as big as ours, it isn’t a surprise that not every plugin is maintained all the time, and maintainers sometimes cannot be contacted, do not respond, or tell us they’re no longer able to maintain the plugin.
“In those cases, we analyze the vulnerability in depth, write up a detailed description, and announce it in a security advisory with other, fixed vulnerabilities.”
Follonier added: “We believe that announcing vulnerabilities without a fix is the best solution for a difficult problem, as it allows administrators to carefully consider their continued use of the affected plugin.
“Besides the Jenkins Advisories mailing list and our social channels, we inform administrators about vulnerabilities affecting their Jenkins instance directly on the UI immediately after publishing an advisory, so every Jenkins administrator gets informed about this.
“Our recommendation to Jenkins administrators is to read our security advisories to understand whether they’re impacted,” Follonier said. “A lot of vulnerabilities are irrelevant to instances with only a single administrator user that are inaccessible to others, for example.
“Of course, if they are unsure whether they are affected, the safest thing to do is to uninstall the plugin.”
Trending: GitHub introduces 2FA and quality of life improvements for npm Are u a security researcher[...]
Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisory
Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisoryPost Views: 65 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Open source DevOps platform Jenkins is warning users of unpatched security vulnerabilities impacting more than a dozen plugins.A leading open source automation server, Jenkins provides thousands of plugins to support building, deploying, and automating projects.
The organization’s latest security advisory lists a total of 27 plugin vulnerabilities, five of which were deemed to be ‘high’ impact and the majority of which remain unpatched.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course High fiveFirst on the list of high impact bugs – all of which were unfixed at the time of writing – is a cross-site request forgery (CSRF) vulnerability in the Coverity plugin (CVE-2022-36920).
It was found that the plugin fails to perform a permission check in an HTTP endpoint. In addition, this HTTP endpoint does not require POST requests, opening the door to CSRF attacks.
Meanwhile, an arbitrary file write vulnerability in the CLIF Performance Testing Plugin (CVE-2022-36894) allows attackers with ‘Overall/Read’ permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
Stored cross-site scripting (XSS) flaws were also discovered in the Dynamic Extended Choice Parameter plugin (CVE-2022-36902) and Maven Metadata plugin (CVE-2022-36905), along with a reflected XSS vulnerability in the Lucene-Search plugin (CVE-2022-36922).
Trending: The Difference between White-Box and Black-Box Pentesting Trending: Offensive Security Tool: DDoS-Layer7-bheh Getting the word outOf the 27 plugin vulnerabilities listed in the latest Jenkins security advisory, 18 remained unpatched and are effectively zero-days.
Discussing the team’s decision to disclose these issues to the community in lieu of any fixes, Jenkins security officer Wadeck Follonier told The Daily Swig: “The main objective of the Jenkins security team is to ensure the Jenkins plugin ecosystem is as secure as possible.
“With a plugin ecosystem as big as ours, it isn’t a surprise that not every plugin is maintained all the time, and maintainers sometimes cannot be contacted, do not respond, or tell us they’re no longer able to maintain the plugin.
“In those cases, we analyze the vulnerability in depth, write up a detailed description, and announce it in a security advisory with other, fixed vulnerabilities.”
Follonier added: “We believe that announcing vulnerabilities without a fix is the best solution for a difficult problem, as it allows administrators to carefully consider their continued use of the affected plugin.
“Besides the Jenkins Advisories mailing list and our social channels, we inform administrators about vulnerabilities affecting their Jenkins instance directly on the UI immediately after publishing an advisory, so every Jenkins administrator gets informed about this.
“Our recommendation to Jenkins administrators is to read our security advisories to understand whether they’re impacted,” Follonier said. “A lot of vulnerabilities are irrelevant to instances with only a single administrator user that are inaccessible to others, for example.
“Of course, if they are unsure whether they are affected, the safest thing to do is to uninstall the plugin.”
Trending: GitHub introduces 2FA and quality of life improvements for npm Are u a security researcher[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisory Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisoryPost Views: 65 Premium Contenthttps://www.blackhatethicalhacking.com/wp-c…
? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-300x150.png VMware urges admins to patch critical auth bypass bug immediatelyAugust 3, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-4-300x150.png Thousand apps leak Twitter API keys, some allowing account hijacksAugust 2, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-300x150.png XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacksAugust 1, 2022
Reading Time: 2 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-2-1-300x150.png Microsoft SQL servers hacked to steal bandwidth with proxywareJuly 29, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisory first appeared on Black Hat Ethical Hacking.
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-300x150.png VMware urges admins to patch critical auth bypass bug immediatelyAugust 3, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-4-300x150.png Thousand apps leak Twitter API keys, some allowing account hijacksAugust 2, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-300x150.png XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacksAugust 1, 2022
Reading Time: 2 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-2-1-300x150.png Microsoft SQL servers hacked to steal bandwidth with proxywareJuly 29, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisory first appeared on Black Hat Ethical Hacking.
hacking: security in practice
How do people spoof their number to a specific number?
I got calls from scammers pretending to be people in my contacts. How do they do that?
submitted by /u/Great_was_taken
[link] [comments]
How do people spoof their number to a specific number?
I got calls from scammers pretending to be people in my contacts. How do they do that?
submitted by /u/Great_was_taken
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
i think "Max Butler/Max Vision/Iceman" deserves a spot as one of the best hackers of all time
This man is Genghis Khan if he was a black hat hacker. He was a Cyber Security professional by day and evil hacker by night. His services were worth $110 an hour at the time (~2006).
He has did something I've never heard another hacker do ever... he went to black hat websites such as "DarkMarket" and "TalkCash" and stole email addresses, passwords, and login sessions, then deleted the databases. After that, he mass sent out emails to every (former) member of those sites and told them they were part of his new CardersMarket.com.
He then continued to run an underground empire that sold up to $2 billion dollars (!?) worth of stolen credit card info.
Like it or not Mr. Vision was an evil genius... he may not have hacked into 97 military databases but he's not your average "Dark Web" hacker/scammer or mid level pentester/cyber security researcher. Such a shame he's wastingll that time in jail when he could've been an Elon Musk or Jeff Bezos.
Now no one even talks about him. Remember guys, don't trade a chance at life long remembrance for one news headline...
Edit: hes not in prison anymore
submitted by /u/RubberDuckyOnAPi
[link] [comments]
i think "Max Butler/Max Vision/Iceman" deserves a spot as one of the best hackers of all time
This man is Genghis Khan if he was a black hat hacker. He was a Cyber Security professional by day and evil hacker by night. His services were worth $110 an hour at the time (~2006).
He has did something I've never heard another hacker do ever... he went to black hat websites such as "DarkMarket" and "TalkCash" and stole email addresses, passwords, and login sessions, then deleted the databases. After that, he mass sent out emails to every (former) member of those sites and told them they were part of his new CardersMarket.com.
He then continued to run an underground empire that sold up to $2 billion dollars (!?) worth of stolen credit card info.
Like it or not Mr. Vision was an evil genius... he may not have hacked into 97 military databases but he's not your average "Dark Web" hacker/scammer or mid level pentester/cyber security researcher. Such a shame he's wastingll that time in jail when he could've been an Elon Musk or Jeff Bezos.
Now no one even talks about him. Remember guys, don't trade a chance at life long remembrance for one news headline...
Edit: hes not in prison anymore
submitted by /u/RubberDuckyOnAPi
[link] [comments]
reddit
i think "Max Butler/Max Vision/Iceman" deserves a spot as one of...
This man is Genghis Khan if he was a black hat hacker. He was a Cyber Security professional by day and evil hacker by night. His services were...
This is how he could hijack Reddit accounts with just ONE click: a $10,000 bug bounty
Exploring Frans Rosén’s bypass of OAuth securityContinue reading on InfoSec Write-ups »
Read more...
Exploring Frans Rosén’s bypass of OAuth securityContinue reading on InfoSec Write-ups »
Read more...
This is how he could hijack Reddit accounts with just ONE click: a $10,000 bug bounty
https://infosecwriteups.com/this-is-how-he-could-hijack-reddit-accounts-with-just-one-click-a-10-000-bug-bounty-7fd8d54d5582?source=rss------bug_bounty-5
https://infosecwriteups.com/this-is-how-he-could-hijack-reddit-accounts-with-just-one-click-a-10-000-bug-bounty-7fd8d54d5582?source=rss------bug_bounty-5
Exploring Frans Rosén’s bypass of OAuth securityContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/this-is-how-he-could-hijack-reddit-accounts-with-just-one-click-a-10-000-bug-bounty-7fd8d54d5582?source=rss------bug_bounty-5)
This is how he could hijack Reddit accounts with just ONE click: a $10,000 bug bounty
Exploring Frans Rosén’s bypass of OAuth securityContinue reading on InfoSec Write-ups »
Read more...
Exploring Frans Rosén’s bypass of OAuth securityContinue reading on InfoSec Write-ups »
Read more...
Cirrusgo - A Fast Tool To Scan SAAS, PAAS App Written In Go
http://www.kitploit.com/2022/08/cirrusgo-fast-tool-to-scan-saas-paas.html
http://www.kitploit.com/2022/08/cirrusgo-fast-tool-to-scan-saas-paas.html