Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Blog Post Importance of reporting in pentest
The importance of the Report in the pentesting field
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Blog Post Importance of reporting in pentest
The importance of the Report in the pentesting field
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blog Post Importance of reporting in pentest
The importance of the Report in the pentesting field
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
API HACKING ⚙️
https://cdn-images-1.medium.com/max/764/1*0YWI_XWTyxWbsYv5kR29Hg@2x.jpeg
APIs are an excellent attack vector. After all, they’re designed to expose information to other applications. APIs are digital pipelines…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
API HACKING ⚙️
https://cdn-images-1.medium.com/max/764/1*0YWI_XWTyxWbsYv5kR29Hg@2x.jpeg
APIs are an excellent attack vector. After all, they’re designed to expose information to other applications. APIs are digital pipelines…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
API HACKING ⚙️
APIs are an excellent attack vector. After all, they’re designed to expose information to other applications. APIs are digital pipelines…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google bloquea el ataque DDoS web ‘más grande de la historia’
https://cdn-images-1.medium.com/max/1755/0*P63v3u35qdc8weFN
Google ha informado que ha bloqueado el ataque de denegación de servicio distribuido (DDoS) ‘más grande’ registrado, que tuvo un pico de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Google bloquea el ataque DDoS web ‘más grande de la historia’
https://cdn-images-1.medium.com/max/1755/0*P63v3u35qdc8weFN
Google ha informado que ha bloqueado el ataque de denegación de servicio distribuido (DDoS) ‘más grande’ registrado, que tuvo un pico de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google bloquea el ataque DDoS web ‘más grande de la historia’
Google ha informado que ha bloqueado el ataque de denegación de servicio distribuido (DDoS) ‘más grande’ registrado, que tuvo un pico de 46…
Break the Logic: Insecure Parameters (€300)
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…Continue reading on Medium »
Read more...
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…Continue reading on Medium »
Read more...
Rest API Pentesting
https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/
Hi there! I currently need to learn about how to do a pentest on a rest api web application. I was wondering if someone can recommend me a lab to practice and probably a good course to learn about it. submitted by /u/ushioyuuki (https://www.reddit.com/user/ushioyuuki)
[link] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/
Hi there! I currently need to learn about how to do a pentest on a rest api web application. I was wondering if someone can recommend me a lab to practice and probably a good course to learn about it. submitted by /u/ushioyuuki (https://www.reddit.com/user/ushioyuuki)
[link] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/ww6t2f/rest_api_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Rest API Pentesting
Hi there! I currently need to learn about how to do a pentest on a rest api web application. I was wondering if someone can recommend me a lab to...
Break the Logic: Insecure Parameters (€300)
https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Break the Logic: Insecure Parameters (€300)
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…Continue reading on Medium » (https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Break the Logic: Insecure Parameters (€300)
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…
hacking: security in practice
Recommended reverse engineering book
Hello, A while ago I read most of "Hacking, the art of exploitation" by Jon Erickson and it kind of blew my mind with how in depth it went into buffer overflows and how easy it was to exploit badly written software. I still need to finish the book but I have been looking into what to read after this.
I was looking for a book recommendation for coding malware, reverse engineering malware, writing exploits, or things of that nature.
submitted by /u/arcticface442
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recommended reverse engineering book
Hello, A while ago I read most of "Hacking, the art of exploitation" by Jon Erickson and it kind of blew my mind with how in depth it went into buffer overflows and how easy it was to exploit badly written software. I still need to finish the book but I have been looking into what to read after this.
I was looking for a book recommendation for coding malware, reverse engineering malware, writing exploits, or things of that nature.
submitted by /u/arcticface442
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
https://b.thumbs.redditmedia.com/fLWr_A_iWv4cAybDdOpDW78-Ds9S6SfIGYsayjc30lA.jpg I found a vulnerability in yahoo that allows you to perfectly impersonate a brand. You give yahoo the right input and they give you the profile pic of the brand and a link to their website as you can see in the attached pictures (I personally moved freelancer.com to the spam folder before), as you can see those emails would never be sent by a reputable organization I sent them to myself durring testing.
https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe
https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2
However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.
This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.
Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.
I am never reporting anything to hackerone ever again, please spread this as much as you can.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe
https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2
However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.
This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.
Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.
I am never reporting anything to hackerone ever again, please spread this as much as you can.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Hackerone fucked me over
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Google Uncovers Tool Used by Iranian Hackers to Steal Data from Email Accounts
https://external-preview.redd.it/HMH88PtiorL0UnRh7je2fQtzwnJ0blu4o9fASve2zLM.jpg?width=640&crop=smart&auto=webp&s=be5b8b455e057308c07aaca780411da5a586acc3 submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Google Uncovers Tool Used by Iranian Hackers to Steal Data from Email Accounts
https://external-preview.redd.it/HMH88PtiorL0UnRh7je2fQtzwnJ0blu4o9fASve2zLM.jpg?width=640&crop=smart&auto=webp&s=be5b8b455e057308c07aaca780411da5a586acc3 submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Google Uncovers Tool Used by Iranian Hackers to Steal Data from...
Posted in r/hacking by u/Glad_Living3908 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
severity of credential leaks through API Key, a Key to credential Leakge and manipulation
https://external-preview.redd.it/U8auC5sr4HwtPTIztYgkJ2afj-Wd60_hkC0T3u9NNU8.jpg?width=640&crop=smart&auto=webp&s=8a5281a44124830fab72df460c73546d0eb1a79f submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
severity of credential leaks through API Key, a Key to credential Leakge and manipulation
https://external-preview.redd.it/U8auC5sr4HwtPTIztYgkJ2afj-Wd60_hkC0T3u9NNU8.jpg?width=640&crop=smart&auto=webp&s=8a5281a44124830fab72df460c73546d0eb1a79f submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
severity of credential leaks through API Key, a Key to credential...
Posted in r/hacking by u/Glad_Living3908 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
https://cdn-images-1.medium.com/max/600/1*AvgFqXIrBr_Le0g_eccvKA.jpeg
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
https://cdn-images-1.medium.com/max/600/1*AvgFqXIrBr_Le0g_eccvKA.jpeg
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
VLC banned in India
https://cdn-images-1.medium.com/max/1200/0*nLsBQao9bLwR92G9
Most of us would have used the VLC media player at least once in our lives but did you know that VLC media player is banned in India? Why?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
VLC banned in India
https://cdn-images-1.medium.com/max/1200/0*nLsBQao9bLwR92G9
Most of us would have used the VLC media player at least once in our lives but did you know that VLC media player is banned in India? Why?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
VLC banned in India
Most of us would have used the VLC media player at least once in our lives but did you know that VLC media player is banned in India? Why?