Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Recommended reverse engineering book

Hello, A while ago I read most of "Hacking, the art of exploitation" by Jon Erickson and it kind of blew my mind with how in depth it went into buffer overflows and how easy it was to exploit badly written software. I still need to finish the book but I have been looking into what to read after this.

I was looking for a book recommendation for coding malware, reverse engineering malware, writing exploits, or things of that nature.

submitted by /u/arcticface442
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
https://b.thumbs.redditmedia.com/fLWr_A_iWv4cAybDdOpDW78-Ds9S6SfIGYsayjc30lA.jpg I found a vulnerability in yahoo that allows you to perfectly impersonate a brand. You give yahoo the right input and they give you the profile pic of the brand and a link to their website as you can see in the attached pictures (I personally moved freelancer.com to the spam folder before), as you can see those emails would never be sent by a reputable organization I sent them to myself durring testing.



https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe



https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2

However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.

This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.

Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.

I am never reporting anything to hackerone ever again, please spread this as much as you can.

submitted by /u/Iam_cool_asf
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video