Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…Continue reading on Medium » (https://canmustdie.medium.com/break-the-logic-insecure-parameters-300-e655cc4fcc42?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Break the Logic: Insecure Parameters (€300)
Hello everyone. Today, I’m going to talk about two minor vulnerabilities based on insecure parameters that I discovered in the same…
hacking: security in practice
Recommended reverse engineering book
Hello, A while ago I read most of "Hacking, the art of exploitation" by Jon Erickson and it kind of blew my mind with how in depth it went into buffer overflows and how easy it was to exploit badly written software. I still need to finish the book but I have been looking into what to read after this.
I was looking for a book recommendation for coding malware, reverse engineering malware, writing exploits, or things of that nature.
submitted by /u/arcticface442
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recommended reverse engineering book
Hello, A while ago I read most of "Hacking, the art of exploitation" by Jon Erickson and it kind of blew my mind with how in depth it went into buffer overflows and how easy it was to exploit badly written software. I still need to finish the book but I have been looking into what to read after this.
I was looking for a book recommendation for coding malware, reverse engineering malware, writing exploits, or things of that nature.
submitted by /u/arcticface442
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
https://b.thumbs.redditmedia.com/fLWr_A_iWv4cAybDdOpDW78-Ds9S6SfIGYsayjc30lA.jpg I found a vulnerability in yahoo that allows you to perfectly impersonate a brand. You give yahoo the right input and they give you the profile pic of the brand and a link to their website as you can see in the attached pictures (I personally moved freelancer.com to the spam folder before), as you can see those emails would never be sent by a reputable organization I sent them to myself durring testing.
https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe
https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2
However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.
This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.
Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.
I am never reporting anything to hackerone ever again, please spread this as much as you can.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe
https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2
However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.
This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.
Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.
I am never reporting anything to hackerone ever again, please spread this as much as you can.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Hackerone fucked me over
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Google Uncovers Tool Used by Iranian Hackers to Steal Data from Email Accounts
https://external-preview.redd.it/HMH88PtiorL0UnRh7je2fQtzwnJ0blu4o9fASve2zLM.jpg?width=640&crop=smart&auto=webp&s=be5b8b455e057308c07aaca780411da5a586acc3 submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Google Uncovers Tool Used by Iranian Hackers to Steal Data from Email Accounts
https://external-preview.redd.it/HMH88PtiorL0UnRh7je2fQtzwnJ0blu4o9fASve2zLM.jpg?width=640&crop=smart&auto=webp&s=be5b8b455e057308c07aaca780411da5a586acc3 submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Google Uncovers Tool Used by Iranian Hackers to Steal Data from...
Posted in r/hacking by u/Glad_Living3908 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
severity of credential leaks through API Key, a Key to credential Leakge and manipulation
https://external-preview.redd.it/U8auC5sr4HwtPTIztYgkJ2afj-Wd60_hkC0T3u9NNU8.jpg?width=640&crop=smart&auto=webp&s=8a5281a44124830fab72df460c73546d0eb1a79f submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
severity of credential leaks through API Key, a Key to credential Leakge and manipulation
https://external-preview.redd.it/U8auC5sr4HwtPTIztYgkJ2afj-Wd60_hkC0T3u9NNU8.jpg?width=640&crop=smart&auto=webp&s=8a5281a44124830fab72df460c73546d0eb1a79f submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
severity of credential leaks through API Key, a Key to credential...
Posted in r/hacking by u/Glad_Living3908 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
https://cdn-images-1.medium.com/max/600/1*AvgFqXIrBr_Le0g_eccvKA.jpeg
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
https://cdn-images-1.medium.com/max/600/1*AvgFqXIrBr_Le0g_eccvKA.jpeg
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
VLC banned in India
https://cdn-images-1.medium.com/max/1200/0*nLsBQao9bLwR92G9
Most of us would have used the VLC media player at least once in our lives but did you know that VLC media player is banned in India? Why?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
VLC banned in India
https://cdn-images-1.medium.com/max/1200/0*nLsBQao9bLwR92G9
Most of us would have used the VLC media player at least once in our lives but did you know that VLC media player is banned in India? Why?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
VLC banned in India
Most of us would have used the VLC media player at least once in our lives but did you know that VLC media player is banned in India? Why?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SHELL UPLOAD in WEB SERVER through BURP SUITE.
https://cdn-images-1.medium.com/max/700/0*94mHodh7sDxHLjyU.png
Hi Everyone,
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
SHELL UPLOAD in WEB SERVER through BURP SUITE.
https://cdn-images-1.medium.com/max/700/0*94mHodh7sDxHLjyU.png
Hi Everyone,
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SHELL UPLOAD in WEB SERVER through BURP SUITE.
Hi Everyone,
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor RPC calls 🔥
https://www.reddit.com/r/redteamsec/comments/wwc1mt/rpcmon_a_new_tool_based_on_event_tracing_for/
submitted by /u/kubiscan (https://www.reddit.com/user/kubiscan)
[link] (https://github.com/cyberark/RPCMon) [comments] (https://www.reddit.com/r/redteamsec/comments/wwc1mt/rpcmon_a_new_tool_based_on_event_tracing_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/wwc1mt/rpcmon_a_new_tool_based_on_event_tracing_for/
submitted by /u/kubiscan (https://www.reddit.com/user/kubiscan)
[link] (https://github.com/cyberark/RPCMon) [comments] (https://www.reddit.com/r/redteamsec/comments/wwc1mt/rpcmon_a_new_tool_based_on_event_tracing_for/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor...
Posted in r/redteamsec by u/kubiscan • 2 points and 0 comments
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor RPC calls 🔥
https://www.reddit.com/r/Pentesting/comments/wwc13b/rpcmon_a_new_tool_based_on_event_tracing_for/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/wwc13b/rpcmon_a_new_tool_based_on_event_tracing_for/
___________________________
@hacking_Attack
@Hacking_Video
reddit
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor...
Posted in r/Pentesting by u/kubiscan • 1 point and 0 comments
submitted by /u/kubiscan (https://www.reddit.com/user/kubiscan)
[link] (https://github.com/cyberark/RPCMon) [comments] (https://www.reddit.com/r/Pentesting/comments/wwc13b/rpcmon_a_new_tool_based_on_event_tracing_for/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://github.com/cyberark/RPCMon) [comments] (https://www.reddit.com/r/Pentesting/comments/wwc13b/rpcmon_a_new_tool_based_on_event_tracing_for/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
overview for kubiscan
The u/kubiscan community on Reddit. Reddit gives you the best of the internet in one place.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
GitLab patches critical remote code execution bug
GitLab patches critical remote code execution bugPost Views: 26 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 1 Minute GitLab has issued a security update to address a critical vulnerability that could lead to remote code execution (RCE).The vulnerability could allow an authenticated user to achieve remote code execution via the ‘Import from GitHub API’ endpoint, an advisory from GitLab reads.
Tracked as CVE-2022-2884, the security issue is present in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 11.3.4 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
It has since been patched, as GitLab urges all users to update to the latest version.
“These versions contain important security fixes, and we strongly recommend that all GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version,” the blog post reads.
It was reported to GitLab by ‘yvvdwf’ through HackerOne’s bug bounty program.
See Also: So you want to be a hacker? Find Hidden Info using Google Dorking manually, and Automated using Pagodo
See Also: So you want to be a hacker? Recon Tool: Is it alive? https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Sponsor.png Other updatesIn addition to the critical security patches, version 15.3, released yesterday (August 22), also contains a number of usability and UI improvements as well as more complex password requirements for GitLab accounts.
See Also: So you want to be a hacker? Apple security updates fix 2 zero-days used to hack iPhones
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-3-300x150.png Over 80000 Hikvision vulnerable cameras exposed onlineAugust 23, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-7-300x150.png WordPress sites hacked with fake Cloudflare DDoS alerts pushing malwareAugust 22, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-4-1-300x150.png Apple security updates fix 2 zero-days used to hack iPhonesAugust 19, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-2-300x150.png Researchers found over 9,000 accessible VNC servers, without a passwordAugust 15, 2022
Reading Time: 5 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post GitLab patches critical remote code execution bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
GitLab patches critical remote code execution bug
GitLab patches critical remote code execution bugPost Views: 26 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 1 Minute GitLab has issued a security update to address a critical vulnerability that could lead to remote code execution (RCE).The vulnerability could allow an authenticated user to achieve remote code execution via the ‘Import from GitHub API’ endpoint, an advisory from GitLab reads.
Tracked as CVE-2022-2884, the security issue is present in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 11.3.4 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
It has since been patched, as GitLab urges all users to update to the latest version.
“These versions contain important security fixes, and we strongly recommend that all GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version,” the blog post reads.
It was reported to GitLab by ‘yvvdwf’ through HackerOne’s bug bounty program.
See Also: So you want to be a hacker? Find Hidden Info using Google Dorking manually, and Automated using Pagodo
See Also: So you want to be a hacker? Recon Tool: Is it alive? https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Sponsor.png Other updatesIn addition to the critical security patches, version 15.3, released yesterday (August 22), also contains a number of usability and UI improvements as well as more complex password requirements for GitLab accounts.
See Also: So you want to be a hacker? Apple security updates fix 2 zero-days used to hack iPhones
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-3-300x150.png Over 80000 Hikvision vulnerable cameras exposed onlineAugust 23, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-7-300x150.png WordPress sites hacked with fake Cloudflare DDoS alerts pushing malwareAugust 22, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-4-1-300x150.png Apple security updates fix 2 zero-days used to hack iPhonesAugust 19, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-2-300x150.png Researchers found over 9,000 accessible VNC servers, without a passwordAugust 15, 2022
Reading Time: 5 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post GitLab patches critical remote code execution bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
GitLab patches critical remote code execution bug | Black Hat Ethical Hacking
GitLab has issued a security update to address a critical vulnerability that could lead to remote code execution (RCE).