Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor RPC calls 🔥
https://external-preview.redd.it/9WQc92niZF8B8viv0IFPC9-tq0hbch4XW_pvoNIl05M.jpg?width=640&crop=smart&auto=webp&s=b8d4af0ce733a4f5798c4d20cad027afa968a92c submitted by /u/0x1337asd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor RPC calls 🔥
https://external-preview.redd.it/9WQc92niZF8B8viv0IFPC9-tq0hbch4XW_pvoNIl05M.jpg?width=640&crop=smart&auto=webp&s=b8d4af0ce733a4f5798c4d20cad027afa968a92c submitted by /u/0x1337asd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor...
Posted in r/hacking by u/0x1337asd • 1 point and 0 comments
hacking: security in practice
A Quick Guide to Bug Bounty Submissions
Hi, I just came across a post about someone that felt like they were unjustly not compensated for a bug submitted on a bug bounty program and I realized that a lot of people in the comments don't understand how vulnerabilities are classified and, therefore how much they are worth. So I decided to write this quick post to try to make it simple to everyone.
Disclaimer: not all bug bounty programs have the same rules, this is just a general guide about the most common ones.
First, every program has a scope. Both in terms of endpoints and in terms of types of vulnerabilities. If your bug affects a endpoint that is out of scope, you won't get paid.
Now, the most important part and the part that people seem to find trickier:
The severity of a bug is calculated using the CVSS score. This score is based on CIA, which stands for confidentiality, integrity and availability of data. That means that all of these are considered to have ZERO IMPACT:
* A bug that affects a company's reputation
* A bug that causes spam on the users
* A bug that causes a financial loss
Those vulnerabilities, while they could feel like they would make a good report, have no impact on data which is usually what determines if a bug is worth money or not.
So before you work for a long time on a bug and on a report, ask yourself these questions:
* does this bug affect a endpoint that is explicitly in scope ?
* is this bug part of a list of bugs that aren't accepted in this program ?
* can I see, change or delete some data that I shouldn't have the right to ?
If you answered no to one of these questions, your bug is probably not going to get paid.
As a last note, if you find a bug that, let's say, causes a financial loss on the company, I encourage you to disclose it. You are probably not entitled to a compensation but the company might still give you a bounty or something to thank you for your report, even if it does not qualify for a normal remuneration. They don't have to, but this is still fairly common.
Always remember that the people that review bug bounty submissions are usually also bug bounty hunters in their spare time.
submitted by /u/PetiteGousseDAil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A Quick Guide to Bug Bounty Submissions
Hi, I just came across a post about someone that felt like they were unjustly not compensated for a bug submitted on a bug bounty program and I realized that a lot of people in the comments don't understand how vulnerabilities are classified and, therefore how much they are worth. So I decided to write this quick post to try to make it simple to everyone.
Disclaimer: not all bug bounty programs have the same rules, this is just a general guide about the most common ones.
First, every program has a scope. Both in terms of endpoints and in terms of types of vulnerabilities. If your bug affects a endpoint that is out of scope, you won't get paid.
Now, the most important part and the part that people seem to find trickier:
The severity of a bug is calculated using the CVSS score. This score is based on CIA, which stands for confidentiality, integrity and availability of data. That means that all of these are considered to have ZERO IMPACT:
* A bug that affects a company's reputation
* A bug that causes spam on the users
* A bug that causes a financial loss
Those vulnerabilities, while they could feel like they would make a good report, have no impact on data which is usually what determines if a bug is worth money or not.
So before you work for a long time on a bug and on a report, ask yourself these questions:
* does this bug affect a endpoint that is explicitly in scope ?
* is this bug part of a list of bugs that aren't accepted in this program ?
* can I see, change or delete some data that I shouldn't have the right to ?
If you answered no to one of these questions, your bug is probably not going to get paid.
As a last note, if you find a bug that, let's say, causes a financial loss on the company, I encourage you to disclose it. You are probably not entitled to a compensation but the company might still give you a bounty or something to thank you for your report, even if it does not qualify for a normal remuneration. They don't have to, but this is still fairly common.
Always remember that the people that review bug bounty submissions are usually also bug bounty hunters in their spare time.
submitted by /u/PetiteGousseDAil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A Quick Guide to Bug Bounty Submissions
Hi, I just came across a post about someone that felt like they were unjustly not compensated for a bug submitted on a bug bounty program and I...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor RPC calls 🔥
https://external-preview.redd.it/9WQc92niZF8B8viv0IFPC9-tq0hbch4XW_pvoNIl05M.jpg?width=640&crop=smart&auto=webp&s=b8d4af0ce733a4f5798c4d20cad027afa968a92c submitted by /u/0x1337asd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor RPC calls 🔥
https://external-preview.redd.it/9WQc92niZF8B8viv0IFPC9-tq0hbch4XW_pvoNIl05M.jpg?width=640&crop=smart&auto=webp&s=b8d4af0ce733a4f5798c4d20cad027afa968a92c submitted by /u/0x1337asd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
🔥 RPCMon: A new tool based on Event Tracing for Windows to monitor...
Posted in r/hacking by u/0x1337asd • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Misconfigured Meta Pixel exposed healthcare data of 1.3M patients
https://external-preview.redd.it/I_8KKHz4K2uputwcXAEtTIbe5mu8EJItz5f53QUHl-M.jpg?width=320&crop=smart&auto=webp&s=9242016862ee05689264c32066370ee7bacb069c submitted by /u/DenofBlerds
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Misconfigured Meta Pixel exposed healthcare data of 1.3M patients
https://external-preview.redd.it/I_8KKHz4K2uputwcXAEtTIbe5mu8EJItz5f53QUHl-M.jpg?width=320&crop=smart&auto=webp&s=9242016862ee05689264c32066370ee7bacb069c submitted by /u/DenofBlerds
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Misconfigured Meta Pixel exposed healthcare data of 1.3M patients
Posted in r/hacking by u/DenofBlerds • 1 point and 0 comments
IDOR Pada NFT marketplace uniqart.io
https://aminudin.medium.com/idor-pada-nft-marketplace-uniqart-io-804676c1f6ab?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://aminudin.medium.com/idor-pada-nft-marketplace-uniqart-io-804676c1f6ab?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR Pada NFT marketplace uniqart.io
Insecure direct object references (IDOR) are a type of access control vulnerability that arises when an application uses user-supplied…
Insecure direct object references (IDOR) are a type of access control vulnerability that arises when an application uses user-supplied…Continue reading on Medium » (https://aminudin.medium.com/idor-pada-nft-marketplace-uniqart-io-804676c1f6ab?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR Pada NFT marketplace uniqart.io
Insecure direct object references (IDOR) are a type of access control vulnerability that arises when an application uses user-supplied…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
https://cdn-images-1.medium.com/max/600/1*AvgFqXIrBr_Le0g_eccvKA.jpeg
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
https://cdn-images-1.medium.com/max/600/1*AvgFqXIrBr_Le0g_eccvKA.jpeg
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Advent of Cyber 3 (2021): Day 13 Write-up [TryHackMe]
Welcome to Day 13 of Advent of Cyber 3 room by TryHackMe.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google Uncovers Tool Used by Iranian Hackers to?
https://cdn-images-1.medium.com/max/728/0*c1LnKcznnCpfs3Zz.jpg
The Iranian government-backed actor known as Charming Kitten has added a new tool to its malware arsenal that allows it to retrieve user…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Google Uncovers Tool Used by Iranian Hackers to?
https://cdn-images-1.medium.com/max/728/0*c1LnKcznnCpfs3Zz.jpg
The Iranian government-backed actor known as Charming Kitten has added a new tool to its malware arsenal that allows it to retrieve user…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google Uncovers Tool Used by Iranian Hackers to?
The Iranian government-backed actor known as Charming Kitten has added a new tool to its malware arsenal that allows it to retrieve user…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Enable Root Login in Ubuntu Ubuntu 22.04
https://cdn-images-1.medium.com/max/636/1*Bk1CDM3ObbFI21HMI8A1Sw.png
By default Ubuntu will not allow root login. You will have to either login to privileged user and then use the sudo command or you can use…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Enable Root Login in Ubuntu Ubuntu 22.04
https://cdn-images-1.medium.com/max/636/1*Bk1CDM3ObbFI21HMI8A1Sw.png
By default Ubuntu will not allow root login. You will have to either login to privileged user and then use the sudo command or you can use…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Enable Root Login in Ubuntu Ubuntu 22.04
By default Ubuntu will not allow root login. You will have to either login to privileged user and then use the sudo command or you can use…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Suspected Iranian Hackers Targeted Several Israeli Organizations for?
https://cdn-images-1.medium.com/max/728/0*U-Ptnub5MWGsduTP.jpg
A suspected Iranian threat activity cluster has been linked to attacks aimed at Israeli shipping, government, energy, and healthcare…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Suspected Iranian Hackers Targeted Several Israeli Organizations for?
https://cdn-images-1.medium.com/max/728/0*U-Ptnub5MWGsduTP.jpg
A suspected Iranian threat activity cluster has been linked to attacks aimed at Israeli shipping, government, energy, and healthcare…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Suspected Iranian Hackers Targeted Several Israeli Organizations for?
A suspected Iranian threat activity cluster has been linked to attacks aimed at Israeli shipping, government, energy, and healthcare…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bitcoin public and private key
https://cdn-images-1.medium.com/max/915/0*FAals0IS3wRgiWOz
As you may already know, our program works with private keys, matching them to various addresses. Let’s expand our knowledge of this…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bitcoin public and private key
https://cdn-images-1.medium.com/max/915/0*FAals0IS3wRgiWOz
As you may already know, our program works with private keys, matching them to various addresses. Let’s expand our knowledge of this…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bitcoin public and private key
As you may already know, our program works with private keys, matching them to various addresses. Let’s expand our knowledge of this…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 3 HACKING Operating Systems + BONUS TIP
https://cdn-images-1.medium.com/max/2600/1*uoJ7QtrV9ZdpcX5odFpT-g.jpeg
In my opinion an operating system is just a tool. The tool has to help me to achieve my goals in the most efficient way possible. I have…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 3 HACKING Operating Systems + BONUS TIP
https://cdn-images-1.medium.com/max/2600/1*uoJ7QtrV9ZdpcX5odFpT-g.jpeg
In my opinion an operating system is just a tool. The tool has to help me to achieve my goals in the most efficient way possible. I have…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 3 HACKING Operating Systems + BONUS TIP
In my opinion an operating system is just a tool. The tool has to help me to achieve my goals in the most efficient way possible. I have…