Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
How do you deal with false positives when scanning CentOS systems?

A network scan of a CentOS system might reveal that it runs Apache version 2.4.4. The version itself contains many vulnerabilities but because of the way CentOS works, they get patches and not version updates.

So how would I go about knowing if this Apache version it'd running is a vulnerable one? My guess was to test for vulnerabilities but would create a lot of traffic

submitted by /u/pipewire
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Kali Linux 2022.3 Release (New Tools in Kali & Test Lab)

Kali Linux 2022.3 Release (New Tools in Kali & Test Lab)Post Views: 67 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
In light of “Hacker Summer Camp 2022” (BlackHat USA, BSides LV, and DEFCON) occurring right now, they wanted to push out Kali Linux 2022.3 as a nice surprise for everyone to enjoy!

The highlights for Kali’s 2022.3’s release:

* Discord Server – Kali’s new community real-time chat option has launched!
* Test Lab Environment – Quickly create a test bed to learn, practice, and benchmark tools and compare their results
* Opening Kali-Tools Repo – They have opened up the Kali tools repository and are accepting your submissions!
* Kali NetHunter Updates – New releases in their NetHunter store
* Virtual Machines Updates – New VirtualBox image format, weekly images, and build-scripts to build your own
* New Tools In Kali – Would not be a release without some new tools! Kali is on DiscordThey have started up a new discord server, Kali Linux & Friends. This is their new place for the Kali community to get together and chat in real-time all about Kali Linux (as well as other community projects that OffSec has to offer).

This is a community server, all with common interests. They do not have the goal to get as many users as possible, instead, they are growing a place for each other to help one another. They are focusing on quality not quantity. Please bear in mind, if you are looking for help, first search for your problem, ask questions, then wait for the community support from your peers. Remember no one is under obligation to help you, and you are more likely to get assistance if you are polite and show you have put some effort into solving your own issue.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Test Lab Environment“A craftsman is only as good as their tools.”

This is true, even outside of Information Security field, you need to understand your tools to master your craft. You can read their code to understand how they work (or a very detailed REAME at times), help screens and their manuals (if they have one) will give you a starting point on how to use them. But where do you use them especially when they are security tools? What output should the tool give? What is a successful run? How long does the tool take? What is its baseline? How can I get experience with it? All valid questions which need answers.

To try and achieve these answers, most seasoned professionals will practice first (hopefully in a known, controlled environment!). This is where a “Test Bed/Laboratory” comes into play. Theory is different to practical (You may remember this the first time you were tasked of something new to accomplish). You can take the static theory-based output from help screens, READMEs, and manual pages and hands-on enter the data into programs and monitor the dynamic output and practical response. Its one thing to read something, its another to do it. The result often gives people a deeper understanding.

Practice makes ~perfect~ permanent. So practice, practice, practice! Inquisitive minds can then start to experiment with new configurations, options, commands and flags. Then start to chain items together, or compare similar and alternative solutions, then compare the results, to become more educated and build up a benchmark of knowledge. This grows experience.

They are trying to make it a bit easier to build up your test lab. So we have packaged up:

* DVWA – Damn Vulnerable Web Application
* Juice Shop – OWASP Juice Shop
All you have to do is apt install &[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
IDOR vulnerability in Reddit allowed attackers to perform mod actions

IDOR vulnerability in Reddit allowed attackers to perform mod actionsPost Views: 23 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes An IDOR vulnerability in Reddit allowed attackers to perform moderator actions or elevate regular users to mod status without the appropriate permissions.The flaw could have allowed for all kinds of mischief, as Reddit mods are privileged to perform actions such as pin or remove posts, ban other users, and edit subreddit information.

As detailed in a recent HackerOne report, a bug hunter with the handle ‘high_ping_ninja’ found that Reddit failed to check if the user was a moderator of a particular subreddit when they attempted to access the mod logs via GraphQL.

“You can change the parameter subredditName to any target subreddit name which is public or restricted and get access to mod logs of that subreddit,” they explained.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
As detailed in a recent HackerOne report, a bug hunter with the handle ‘high_ping_ninja’ found that Reddit failed to check if the user was a moderator of a particular subreddit when they attempted to access the mod logs via GraphQL.

“You can change the parameter subredditName to any target subreddit name which is public or restricted and get access to mod logs of that subreddit,” they explained.
Trending: Find Hidden Info using Google Dorking manually, and Automated using Pagodo
Trending: Offensive Security Tool: Offensive-Azure Same-day fixThe insecure direct object reference (IDOR) bug was reported on August 3 and fixed on the same day.

“I increased severity to high based on our program policy,” a member of the Reddit triage team said in the disclosure notes.

The researcher was awarded a $5,000 bug bounty for the find. Trending: New Linux malware called RapperBot brute-forces Linux SSH servers to breach networks
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images_for_the_News_posts_2-300x150.png Kali Linux 2022.3 Release (New Tools in Kali & Test Lab)August 10, 2022
Reading Time: 5 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-1-300x150.png Twilio discloses data breach after SMS phishing attack on employeesAugust 9, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-5-300x150.png Researcher bypass email filter – XSS in Gmail’s AMP For EmailAugust 9, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-1-300x150.png Twitter confirms zero-day used to expose data of 5.4 million accountsAugust 8, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post IDOR vulnerability in Reddit allowed attackers to perform mod actions first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Kali Linux 2022.3 Release (New Tools in Kali & Test Lab) Kali Linux 2022.3 Release (New Tools in Kali & Test Lab)Post Views: 67 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe…
lt;package, else you can use the kali-linux-labs metapackage to get them all! This list will be growing in the upcoming Kali releases!

This list will be growing in the upcoming Kali releases!

*Note: At times, you may be running codes that are designed to be vulnerable. Please take the necessary steps to secure your environment. Kali for Virtual MachinesThey have already provided Kali Linux images for VMware and VirtualBox since the start. For this release, there’s been a few changes worth noting.

They now distribute the VirtualBox image as a VDI disk and a .vbox metadata file, or to say it short: the native format for VirtualBox images. It should be a bit faster to download, as those images have a better compression ratio compared to the OVA images that they used to provide. It should also be a bit more straightforward to use it, you just need to unpack the image in your VirtualBox folder and run it. In case you need help, refer to our documentation: Import Pre-Made Kali VirtualBox VM.

Additionally, they just started to provide weekly builds of our VM images. These images are built from the kali-rolling branch, meaning that they have the most up-to-date packages, but on the other hand they don’t receive as much testing as their quarterly releases.

Last but not least, the scripts that they use to build those images are now available on GitLab. If you need to build custom Kali VM images, this is the place to go!
Trending: Write up: Find Hidden Info using Google Dorking manually, and Automated using Pagodo
Trending: Offensive Security Tool: Offensive-Azure New Tools in KaliIt would not be a Kali release if there were not any new tools added! A quick run down of what has been added (to the network repositories):

* BruteShark – Network Analysis Tool
* DefectDojo – Open-source application vulnerability correlation and security orchestration tool
* phpsploit – Stealth post-exploitation framework
* shellfire – Exploiting LFI/RFI and command injection vulnerabilities
* SprayingToolkit – Password spraying attacks against Lync/S4B, OWA and O365

There have been numerous packages updates as well.
Trending: New Linux malware called RapperBot brute-forces Linux SSH servers to breach networks
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: kali.org Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-6-300x150.png IDOR vulnerability in Reddit allowed attackers to perform mod actionsAugust 10, 2022
Reading Time: 2 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-1-300x150.png Twilio discloses data breach after SMS phishing attack on employeesAugust 9, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-5-300x150.png Researcher bypass email filter – XSS in Gmail’s AMP For EmailAugust 9, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-1-300x150.png Twitter confirms zero-day used to expose data of 5.4 million accountsAugust 8, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Kali Linux 2022.3 Release (New Tools in Kali & Test Lab) first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Looking Back at 25 Years of Black Hat

The Black Hat USA conference's silver jubilee is an opportunity to remember its defining moments, the impact it has made on the security community, and its legacy.