Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
22 OSINT service for vulnerability detection that can be utilized in IT security.

22 cybersecurity search engines :

* Shodan - Search for devies connected to the internet.
* Wigle - Database of wireless networks, with statistics.
* Grep App - Search across a half milion git repos.
* Binary Edge - Scans the internet for threat intelligence.
* ONYPHE - Collects cyber-threat intelligence data.
* GreyNoise - Search for devices connected to the internet.
* Censys - Assessing attack surface for internet connected devices.
* Hunter - Search for email addresses belonging to a website.
* Fofa - Search for various threat intelligence.
* Criminal IP - Search for devices connected to the internet. Monitor potential attack vectors.
* ZoomEye - Gather information about targets.
* LeakIX - Search publicly indexed information.
* IntelligenceX - Search Tor, I2P, data leaks, domains and emails.
* Netlas - Search and monitor internet connected assets.
* URL Scan - Free Service to scan and analyse websites.
* PublicWWW - Marketing and affiliate marketing research.
* FullHunt - Search and discovery attack surfaces.
* CRT sh - Search for certs that have been logged by CT.
* Vulners - Search vulnerabilities in a large Database.
* Pulsedive - Search for threat intelligence.
* Packet Storm Security - Browse lateset vulnerabilities and exploits.
* GrayHatWarefare - Search public S3 buckets. Search for cloud storage services.

submitted by /u/Glad_Living3908
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
OWASP Risk Calculator

OWASP Risk Rating Methodology In general terms, OWASP Risk Rating Methodology takes us through a series of steps that can use to calculate…Continue reading on Medium »
Read more...
hacking: security in practice
What can I do with a spare router?

I found a new router in my house. Is it possible to set a evil twin AP can from this router that can be used for phishing like we do when we use fluxion, airgeddon? And what other things can be done :)

submitted by /u/TemporaryAbrocoma468
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there any way to establish a secure connection in LAN (WPA-2)

I am doing research on how to establish secure connection in WPA-2 wifi network, note that I want to establish a secure connection only inside LAN. I am planning to deploy/host a web app in LAN (it will not be hosted on the internet) for local usage,as many unknown devices will connect to it, so that I want to establish secure connection in LAN.

Some comman techniques that I already know but are useless for me:

1.
Use WPA-3 as it provides protection from MITM attacks (I want to use WPA-2 only)

2.
Create your own CA certificate and install it in the devices to establish HTTPS connection (not possible in my case as many unknown devices will connect to the network and modern browsers don't allow this)

3.
Using crypto.js framework in the web app (It doesn't encrypts the HTTP headers, only body is encrypted)
I did researched a lot on this topic but most of the techniques are useless in my case, if someone know a better way to establish a secure connection in LAN then please comment down below.

submitted by /u/MrEquinox98
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video