Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Russia-Ukraine Conflict Holds Cyberwar Lessons

Initial attacks used damaging wiper malware and targeted infrastructure, but the most enduring impacts will likely be from disinformation, researchers say. At Black Hat USA, SentinelOne's Juan Andres Guerrero-Saade and Tom Hegel will discuss.
Dark Reading: Attacks/Breaches
Domino's Takes a Methodical Approach to IoT

The success of Domino's Flex IoT project can be attributed in large part to the security best practices it followed.
Dark Reading: Attacks/Breaches
Abusing Kerberos for Local Privilege Escalation

Upcoming Black Hat USA presentation will examine the implications of Kerberos weaknesses for security on the local machine.
Dark Reading: Attacks/Breaches
Researchers Debut Fresh RCE Vector for Common Google API Tool

The finding exposes the danger of older, unpatched bugs, which plague at least 4.5 million devices.
Dark Reading: Attacks/Breaches
Halo Security Emerges From Stealth With Full Attack Surface Management Platform

The latest startup to enter the attack surface management space also has a free scanning service to audit the contents of any website.
Dark Reading: Attacks/Breaches
Microsoft Patches Zero-Day Actively Exploited in the Wild

The computing giant issued a massive Patch Tuesday update, including a pair of remote execution flaws in the Microsoft Support Diagnostic Tool (MSDT) after attackers used one of the vulnerabilities in a zero-day exploit.
hacking: security in practice
Question regarding dns redirect

Quick question for you guys.

Doing some experimentation with JS injection into http websites.

Obviously, most websites use https. The main workaround is to attempt to perform an sslstrip or HSTSHijack to try to downgrade the site to http. From there we can inject a hook and try from there.

However, most large sites have a strong HSTS policy that will not allow this to work.

My question is, would it be easier to just create a DNS redirect that forces users to a predefined http website. Meaning, if I go to https://google.com, it would redirect to http://palms.myspecies.info/

Obviously, this would get noticed by the target host, but that is not important as this is for testing purposes on my own machine.

submitted by /u/whatthe12234
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is this still an Open redirect vulnerability?

I failed my security course twice and ironically I’m now tasked to fix security issues on an internal web app for my employer.

They’re cybersecurity 101 type of attacks but I’m still confused, is the following example still an open redirect, or is it a false positive?

the user inputs a URL on browser and the controller/service grabs the Base url of that URL and appends “custom.html” Then passes that to the servlets redirect function.

Pseudo code:

MyController(request, response) {

BaseURL = request.substring()

Response.redirect(BaseURL + “custom.html”)

}

submitted by /u/GuerroCanelo
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to break into old yahoo mail account that I madr 6 years ago

Hello

I made a yahoo email that I used to create a Facebook account and now I need to access it for some security code. The problem is that I only know one of the security questions but not the other one. Can you give me some websites for this type of service?

submitted by /u/AlexPascu007
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there a way to intervene as user on TikTok collecting personal data?

I'm concerned, as I used TikTok about three months naively not understanding what I signing up for. After reading through and seeing that you they gain notable information past the application in their terms of service. I would like to make sure that I am not having my data used by them.

Is there anyway I can make sure they aren't doing such things at the current moment?

Is there a way to trace what you have available to these apps?

Do these apps continue to monitor even after you have deleted the app?

Appreciate any of the feedback.

submitted by /u/RecipeAwkward
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video