Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
10 Malicious Code Packages Slither into PyPI Registry

The discovery adds to the growing list of recent incidents where threat actors have used public code repositories to distribute malware in software supply chain attacks.
Dark Reading: Attacks/Breaches
Dark Reading News Desk: Live at Black Hat USA 2022

LIVE: Dark Reading News Desk at Black Hat USA 2022
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ethernaut Level 6 — Delegation

The Ethernaut is a Web3/Solidity based wargame inspired on overthewire.org. Here’s the solution to the Level 5 Token.

Continue reading on Medium »
hacking: security in practice
How to contact ISP?

This might be a horrible idea, but my friend and I have been talking about my hacking career, I am a cybersecurity major, currently taking an Ethical Hacking class, I wanted to practice and my friend has given me verbal permission, he will also be giving me written permission. I do not want to get in trouble with my ISP, is there a way I can contact them to see if they will allow me to do this? Or should I just avoid this entirely?



EDIT: I guess I should clerify, I do not want to destory his system or steal anything, and this will be written on the scope we create. I just want to attempt to get into his computer and practice my skills in finding information he will hide for me and delting footptints.

submitted by /u/DCornOnline
[link] [comments]
hacking: security in practice
Open url redirect on Snapchat being abused in phishing campaigns. Still working.

Live working example: https://click.snapchat.com/aVHG?&af_web_dp=http://old.reddit.com/r/hacking/wiki

Attackers abused open redirects on the websites of Snapchat and American Express in a series of phishing attacks to steal Microsoft 365 credentials.

Open redirects are web app weaknesses that allow threat actors to use the domains of trusted organizations and websites as temporary landing pages to simplify phishing attacks.

They're used in attacks to redirect targets to malicious sites that will either infect them with malware or trick them into handing over sensitive information (e.g., credentials, financial info, personal info).

"Since the first domain name in the manipulated link is in fact the original site's, the link may appear safe to the casual observer," email security firm Inky, which observed the attacks, explained.

"The trusted domain (e.g., American Express, Snapchat) acts as a temporary landing page before the surfer is redirected to a malicious site."

Read more: https://www.bleepingcomputer.com/news/security/snapchat-amex-sites-abused-in-microsoft-365-phishing-attacks/

submitted by /u/DrinkMoreCodeMore
[link] [comments]
Deep Web
advice please

long story short, this was my first tie messing around with tor and making those types of purchases. the dude i spoke to gave me a fair price, he had good ratings, and does next day shipping. ultimately im sitting here with no tracking number looking like an asshole wtf do i do

submitted by /u/ayoooperi
[link] [comments]