Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
https://b.thumbs.redditmedia.com/fLWr_A_iWv4cAybDdOpDW78-Ds9S6SfIGYsayjc30lA.jpg I found a vulnerability in yahoo that allows you to perfectly impersonate a brand. You give yahoo the right input and they give you the profile pic of the brand and a link to their website as you can see in the attached pictures (I personally moved freelancer.com to the spam folder before), as you can see those emails would never be sent by a reputable organization I sent them to myself durring testing.



https://preview.redd.it/ypcftel4kkj91.png?width=1620&format=png&auto=webp&s=ddc877ff5462b4fdd14c453b829908876fee5dfe



https://preview.redd.it/2n8jyt76kkj91.png?width=1599&format=png&auto=webp&s=957e25ab73b9b8760b122a0c24077edf620731c2

However this vulnerability no longer works because, I reported it to hackerone, along with the python script that I wrote to run the exploit, and they reported it to yahoo to patch it and finally, they closed my report without paying me as it is social engineering and is out of the scope of the program. Why did they report it to yahoo if it is out of the scope of their shitty program, or is the scope for the payments only ? For those sleazy bounty hunters ? For those who wasted their time to find a vulnerability and decided to do the right thing and report it to the right people ? Except those people are the worst of the worst.

This is obviously a vulnerability in yahoo, they rely on untrusted input and have improper authentication.

Do not submit your reports to hackerone, go ANYWHERE else, they work for the corporates, they do their best to save their precious money while keeping them secure, this makes sense because the corporates are the ones paying them after all.

I am never reporting anything to hackerone ever again, please spread this as much as you can.

submitted by /u/Iam_cool_asf
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
GitLab patches critical remote code execution bug

GitLab patches critical remote code execution bugPost Views: 26 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 1 Minute GitLab has issued a security update to address a critical vulnerability that could lead to remote code execution (RCE).The vulnerability could allow an authenticated user to achieve remote code execution via the ‘Import from GitHub API’ endpoint, an advisory from GitLab reads.

Tracked as CVE-2022-2884, the security issue is present in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 11.3.4 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
It has since been patched, as GitLab urges all users to update to the latest version.

“These versions contain important security fixes, and we strongly recommend that all GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version,” the blog post reads.

It was reported to GitLab by ‘yvvdwf’ through HackerOne’s bug bounty program.
See Also: So you want to be a hacker? Find Hidden Info using Google Dorking manually, and Automated using Pagodo
See Also: So you want to be a hacker? Recon Tool: Is it alive? https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Sponsor.png Other updatesIn addition to the critical security patches, version 15.3, released yesterday (August 22), also contains a number of usability and UI improvements as well as more complex password requirements for GitLab accounts.
See Also: So you want to be a hacker? Apple security updates fix 2 zero-days used to hack iPhones
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-3-300x150.png Over 80000 Hikvision vulnerable cameras exposed onlineAugust 23, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-7-300x150.png WordPress sites hacked with fake Cloudflare DDoS alerts pushing malwareAugust 22, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-4-1-300x150.png Apple security updates fix 2 zero-days used to hack iPhonesAugust 19, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-2-300x150.png Researchers found over 9,000 accessible VNC servers, without a passwordAugust 15, 2022
Reading Time: 5 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post GitLab patches critical remote code execution bug first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video