Abusing Open Redirects to get an Account Takeover
It was the end of another semester, and I was really bored, so decided to take a look at the system that my college uses to store and…Continue reading on Medium »
Read more...
It was the end of another semester, and I was really bored, so decided to take a look at the system that my college uses to store and…Continue reading on Medium »
Read more...
Abusing Open Redirects to get an Account Takeover
https://snizi.medium.com/abusing-open-redirects-to-get-an-account-takeover-b1f5c2585dd8?source=rss------bug_bounty-5
It was the end of another semester, and I was really bored, so decided to take a look at the system that my college uses to store and…Continue reading on Medium » (https://snizi.medium.com/abusing-open-redirects-to-get-an-account-takeover-b1f5c2585dd8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://snizi.medium.com/abusing-open-redirects-to-get-an-account-takeover-b1f5c2585dd8?source=rss------bug_bounty-5
It was the end of another semester, and I was really bored, so decided to take a look at the system that my college uses to store and…Continue reading on Medium » (https://snizi.medium.com/abusing-open-redirects-to-get-an-account-takeover-b1f5c2585dd8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Abusing Open Redirects to get an Account Takeover
It was the end of another semester, and I was really bored, so decided to take a look at the system that my college uses to store and…
hacking: security in practice
bruteforcing physical safe
hi there,
we have a heavy physical safe which we would like to open..
Unfortunately nobody knows the 6 digit key.
Are there any examples to brute force these kind of vaults?
for ex. Connect it to a pc and brute force it? I have wordlist with all the possible 6 digit combinations and would like to learn how to setup this on my own.
Doing it manually is not an option because after two attempts there will be a delay of 2 hours, pulling in and out the battery doesn't reset this unfortunately.
submitted by /u/smoke_2k
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
bruteforcing physical safe
hi there,
we have a heavy physical safe which we would like to open..
Unfortunately nobody knows the 6 digit key.
Are there any examples to brute force these kind of vaults?
for ex. Connect it to a pc and brute force it? I have wordlist with all the possible 6 digit combinations and would like to learn how to setup this on my own.
Doing it manually is not an option because after two attempts there will be a delay of 2 hours, pulling in and out the battery doesn't reset this unfortunately.
submitted by /u/smoke_2k
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
bruteforcing physical safe
hi there, we have a heavy physical safe which we would like to open.. Unfortunately nobody knows the 6 digit key. Are there any examples to...
hacking: security in practice
Printing locked pdf files
So I have a number of pdf files that are ‘locked’/password protected. I’ve used pdf unlocking apps in the past which seem to open and print the pdf to a new pdf that doesn’t have protection.
This batch of files are different though. I can open them/view them in a pdf reader but any unlock app doesn’t ‘see’ them (I’ve tried several). I can’t drag the file to the unlock app and when I try to search it using the file explorer pop up it doesn’t list the pdf files which i know are in the directory.
I’m able to view a single locked file (as mentioned) and print it to a new pdf but I’ve got quite a few …
ideas? Is there an attribute or something I’m missing that can be changed?
submitted by /u/iqsilenius
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Printing locked pdf files
So I have a number of pdf files that are ‘locked’/password protected. I’ve used pdf unlocking apps in the past which seem to open and print the pdf to a new pdf that doesn’t have protection.
This batch of files are different though. I can open them/view them in a pdf reader but any unlock app doesn’t ‘see’ them (I’ve tried several). I can’t drag the file to the unlock app and when I try to search it using the file explorer pop up it doesn’t list the pdf files which i know are in the directory.
I’m able to view a single locked file (as mentioned) and print it to a new pdf but I’ve got quite a few …
ideas? Is there an attribute or something I’m missing that can be changed?
submitted by /u/iqsilenius
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HacktheBox[goodgames]
https://cdn-images-1.medium.com/max/677/1*Icpd-in-QLLIQPq8gYBmpA.png
Full Nmap TCP scan shows only port 80 open externally running goodgames.htb and Werkzueg/2.0.2 Python/3.9.2:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HacktheBox[goodgames]
https://cdn-images-1.medium.com/max/677/1*Icpd-in-QLLIQPq8gYBmpA.png
Full Nmap TCP scan shows only port 80 open externally running goodgames.htb and Werkzueg/2.0.2 Python/3.9.2:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HacktheBox[goodgames]
Full Nmap TCP scan shows only port 80 open externally running goodgames.htb and Werkzueg/2.0.2 Python/3.9.2:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Agent-T TryHackMe Writeup
https://cdn-images-1.medium.com/max/600/0*PdoPCE670la39Fc1.png
First I ran a nmap scan:
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Agent-T TryHackMe Writeup
https://cdn-images-1.medium.com/max/600/0*PdoPCE670la39Fc1.png
First I ran a nmap scan:
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Agent-T TryHackMe Writeup
First I ran a nmap scan:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Become an Ethical Hacker
https://cdn-images-1.medium.com/max/940/1*grwOPujL2An4La7m34dSvA.jpeg
What is Ethical Hacking?
Continue reading on FAUN Publication »
___________________________
@hacking_Attack
@Hacking_Video
How to Become an Ethical Hacker
https://cdn-images-1.medium.com/max/940/1*grwOPujL2An4La7m34dSvA.jpeg
What is Ethical Hacking?
Continue reading on FAUN Publication »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Become an Ethical Hacker
What is Ethical Hacking?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking web servers
https://cdn-images-1.medium.com/max/600/1*lrYLHwPo63mW1ZPT7qVmyA.png
Web Server
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking web servers
https://cdn-images-1.medium.com/max/600/1*lrYLHwPo63mW1ZPT7qVmyA.png
Web Server
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking web servers
Web Server
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
80.000 cámaras Hikvision expuestas por una vulnerabilidad
https://cdn-images-1.medium.com/max/1834/0*GdWEMnMLBnu1iONm
Investigadores de seguridad han descubierto más de 80.000 cámaras vulnerables a un error crítico de inyección de comandos que puede…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
80.000 cámaras Hikvision expuestas por una vulnerabilidad
https://cdn-images-1.medium.com/max/1834/0*GdWEMnMLBnu1iONm
Investigadores de seguridad han descubierto más de 80.000 cámaras vulnerables a un error crítico de inyección de comandos que puede…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
80.000 cámaras Hikvision expuestas por una vulnerabilidad
Investigadores de seguridad han descubierto más de 80.000 cámaras vulnerables a un error crítico de inyección de comandos que puede…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
JSON Web Tokens (JWT)
https://cdn-images-1.medium.com/max/1000/0*4YPVZ4HIuXvdN2vB
What is JWT and how it works?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
JSON Web Tokens (JWT)
https://cdn-images-1.medium.com/max/1000/0*4YPVZ4HIuXvdN2vB
What is JWT and how it works?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
JSON Web Tokens (JWT)
What is JWT and how it works?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Net Sec Challenge | TryHackMe Write-Up
https://cdn-images-1.medium.com/max/710/0*nFqLFsaU84Yf8Q7m.png
TryHackMe Room:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Net Sec Challenge | TryHackMe Write-Up
https://cdn-images-1.medium.com/max/710/0*nFqLFsaU84Yf8Q7m.png
TryHackMe Room:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Net Sec Challenge | TryHackMe Write-Up
TryHackMe Room:
hacking: security in practice
22 OSINT service for vulnerability detection that can be utilized in IT security.
22 cybersecurity search engines :
* Shodan - Search for devies connected to the internet.
* Wigle - Database of wireless networks, with statistics.
* Grep App - Search across a half milion git repos.
* Binary Edge - Scans the internet for threat intelligence.
* ONYPHE - Collects cyber-threat intelligence data.
* GreyNoise - Search for devices connected to the internet.
* Censys - Assessing attack surface for internet connected devices.
* Hunter - Search for email addresses belonging to a website.
* Fofa - Search for various threat intelligence.
* Criminal IP - Search for devices connected to the internet. Monitor potential attack vectors.
* ZoomEye - Gather information about targets.
* LeakIX - Search publicly indexed information.
* IntelligenceX - Search Tor, I2P, data leaks, domains and emails.
* Netlas - Search and monitor internet connected assets.
* URL Scan - Free Service to scan and analyse websites.
* PublicWWW - Marketing and affiliate marketing research.
* FullHunt - Search and discovery attack surfaces.
* CRT sh - Search for certs that have been logged by CT.
* Vulners - Search vulnerabilities in a large Database.
* Pulsedive - Search for threat intelligence.
* Packet Storm Security - Browse lateset vulnerabilities and exploits.
* GrayHatWarefare - Search public S3 buckets. Search for cloud storage services.
submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
22 OSINT service for vulnerability detection that can be utilized in IT security.
22 cybersecurity search engines :
* Shodan - Search for devies connected to the internet.
* Wigle - Database of wireless networks, with statistics.
* Grep App - Search across a half milion git repos.
* Binary Edge - Scans the internet for threat intelligence.
* ONYPHE - Collects cyber-threat intelligence data.
* GreyNoise - Search for devices connected to the internet.
* Censys - Assessing attack surface for internet connected devices.
* Hunter - Search for email addresses belonging to a website.
* Fofa - Search for various threat intelligence.
* Criminal IP - Search for devices connected to the internet. Monitor potential attack vectors.
* ZoomEye - Gather information about targets.
* LeakIX - Search publicly indexed information.
* IntelligenceX - Search Tor, I2P, data leaks, domains and emails.
* Netlas - Search and monitor internet connected assets.
* URL Scan - Free Service to scan and analyse websites.
* PublicWWW - Marketing and affiliate marketing research.
* FullHunt - Search and discovery attack surfaces.
* CRT sh - Search for certs that have been logged by CT.
* Vulners - Search vulnerabilities in a large Database.
* Pulsedive - Search for threat intelligence.
* Packet Storm Security - Browse lateset vulnerabilities and exploits.
* GrayHatWarefare - Search public S3 buckets. Search for cloud storage services.
submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
What are methods in figuring out who is behind creating multiple social media accounts to slander someone?
Are there ways to figure out who is behind fake slander accounts besides the obvious reporting of them and new accounts appear after.
Edit: have been dealing with new accounts for 6 months
submitted by /u/Alone_Analysis_5157
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What are methods in figuring out who is behind creating multiple social media accounts to slander someone?
Are there ways to figure out who is behind fake slander accounts besides the obvious reporting of them and new accounts appear after.
Edit: have been dealing with new accounts for 6 months
submitted by /u/Alone_Analysis_5157
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What are methods in figuring out who is behind creating multiple...
Are there ways to figure out who is behind fake slander accounts besides the obvious reporting of them and new accounts appear after.
OWASP Risk Calculator
OWASP Risk Rating Methodology In general terms, OWASP Risk Rating Methodology takes us through a series of steps that can use to calculate…Continue reading on Medium »
Read more...
OWASP Risk Rating Methodology In general terms, OWASP Risk Rating Methodology takes us through a series of steps that can use to calculate…Continue reading on Medium »
Read more...