Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
System Informer : A Free, Powerful, Multi-Purpose Tool That Helps You Monitor System Resources, Debug Software And Detect Malware
System Informer, A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc.
System requirements
Windows 7 or higher, 32-bit or 64-bit.
Features
* A detailed overview of system activity with highlighting.
* Graphs and statistics allow you quickly to track down resource hogs and runaway processes.
* Can’t edit or delete a file? Discover which processes are using that file.
* See what programs have active network connections, and close them if necessary.
* Get real-time information on disk access.
* View detailed stack traces with kernel-mode, WOW64 and .NET support.
* Go beyond services.msc: create, edit and control services.
* Small, portable and no installation required.
* 100% Free Software (MIT)
Building the project
Requires Visual Studio (2022 or later).
Execute
You can download the free Visual Studio Community Edition to build the System Informer source code.
See the build readme for more information or if you’re having trouble building.
Enhancements/Bugs
Please use the GitHub issue tracker for reporting problems or suggesting new features.
Settings
If you are running System Informer from a USB drive, you may want to save System Informer’s settings there as well. To do this, create a blank file named “SystemInformer.exe.settings.xml” in the same directory as SystemInformer.exe. You can do this using Windows Explorer:
* Make sure “Hide extensions for known file types” is unticked in Tools > Folder options > View.
* Right-click in the folder and choose New > Text Document.
* Rename the file to SystemInformer.exe.settings.xml (delete the “.txt” extension).
Download
___________________________
@hacking_Attack
@Hacking_Video
System Informer : A Free, Powerful, Multi-Purpose Tool That Helps You Monitor System Resources, Debug Software And Detect Malware
System Informer, A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc.
System requirements
Windows 7 or higher, 32-bit or 64-bit.
Features
* A detailed overview of system activity with highlighting.
* Graphs and statistics allow you quickly to track down resource hogs and runaway processes.
* Can’t edit or delete a file? Discover which processes are using that file.
* See what programs have active network connections, and close them if necessary.
* Get real-time information on disk access.
* View detailed stack traces with kernel-mode, WOW64 and .NET support.
* Go beyond services.msc: create, edit and control services.
* Small, portable and no installation required.
* 100% Free Software (MIT)
Building the project
Requires Visual Studio (2022 or later).
Execute
build_release.cmdlocated in the builddirectory to compile the project or load the SystemInformer.slnand Plugins.slnsolutions if you prefer building the project using Visual Studio.You can download the free Visual Studio Community Edition to build the System Informer source code.
See the build readme for more information or if you’re having trouble building.
Enhancements/Bugs
Please use the GitHub issue tracker for reporting problems or suggesting new features.
Settings
If you are running System Informer from a USB drive, you may want to save System Informer’s settings there as well. To do this, create a blank file named “SystemInformer.exe.settings.xml” in the same directory as SystemInformer.exe. You can do this using Windows Explorer:
* Make sure “Hide extensions for known file types” is unticked in Tools > Folder options > View.
* Right-click in the folder and choose New > Text Document.
* Rename the file to SystemInformer.exe.settings.xml (delete the “.txt” extension).
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
System Informer : A Free, Powerful, Multi-Purpose Tool
System Informer, A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.
Burp Suite + Quickbooks
https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/
Hello! Question for any who have any ideas: is there a way to intercept and view traffic from QuickBooks to a banking website in a tool like Burp Suite or similar? Some background: I am reviewing a banking website, and it offers the option to link QuickBooks and other such software to the account using a person's normal online banking creds. I have a hypothesis that there may be some portions of the website this uses that might be vulnerable to attack (as they are not intended to be seen by users and instead are just passthroughs for QuickBooks). So I would like to map them out, sample the typical requests, and manipulate them. I have added the Burp Suite CA and set my system proxy to a listening Burp Suite proxy, and confirmed I can intercept browser traffic as normal. However, when I download the trial version of QuickBooks and try to connect it to the bank account, the connection fails. It succeeds if I stop trying to proxy through Burp Suite. It seems likely that QuickBooks isn't trusting the burp Suite CA I installed (it probably has its own CAs it trusts). But I'm not sure if I'm neglecting something, or if anyone has encountered a similar issue. Any thoughts? Any other tools/approaches that might be good for exploring this avenue of attack further? Thank you very much! submitted by /u/helmutye (https://www.reddit.com/user/helmutye)
[link] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/) [comments] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/
Hello! Question for any who have any ideas: is there a way to intercept and view traffic from QuickBooks to a banking website in a tool like Burp Suite or similar? Some background: I am reviewing a banking website, and it offers the option to link QuickBooks and other such software to the account using a person's normal online banking creds. I have a hypothesis that there may be some portions of the website this uses that might be vulnerable to attack (as they are not intended to be seen by users and instead are just passthroughs for QuickBooks). So I would like to map them out, sample the typical requests, and manipulate them. I have added the Burp Suite CA and set my system proxy to a listening Burp Suite proxy, and confirmed I can intercept browser traffic as normal. However, when I download the trial version of QuickBooks and try to connect it to the bank account, the connection fails. It succeeds if I stop trying to proxy through Burp Suite. It seems likely that QuickBooks isn't trusting the burp Suite CA I installed (it probably has its own CAs it trusts). But I'm not sure if I'm neglecting something, or if anyone has encountered a similar issue. Any thoughts? Any other tools/approaches that might be good for exploring this avenue of attack further? Thank you very much! submitted by /u/helmutye (https://www.reddit.com/user/helmutye)
[link] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/) [comments] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Burp Suite + Quickbooks
UPDATE: Figured it out--you have to install the Burp Suite / Portswigger CA as a Trusted Root CA on the local machine (doing it through a browser...
Rotation IP Address with Burpsuite
https://medium.com/@mil3anism/rotation-ip-address-with-burpsuite-24b315bbc4a5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mil3anism/rotation-ip-address-with-burpsuite-24b315bbc4a5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Rotation IP Address with Burpsuite
Hi, For those of you who are unfamiliar with what IP Rotation is, I’m going to share a quick tip and trick with you all on how to use…
Hi, pada kesempatan kali ini gue akan membagikan sebuah tips and trick sederhana bagi kalian semua heker-meN(Red) bagaimana caranya…Continue reading on Medium » (https://medium.com/@mil3anism/rotation-ip-address-with-burpsuite-24b315bbc4a5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Rotation IP Address with Burpsuite
Hi, For those of you who are unfamiliar with what IP Rotation is, I’m going to share a quick tip and trick with you all on how to use…
OAuth 2.0 (Introduction and Exploitation Part I)Explained By Hashar Mujahid
https://infosecwriteups.com/oauth-2-0-introduction-and-exploitation-part-i-explained-by-hashar-mujahid-262f9c59de6c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/oauth-2-0-introduction-and-exploitation-part-i-explained-by-hashar-mujahid-262f9c59de6c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
OAuth 2.0 (Introduction and Exploitation Part I)Explained By Hashar Mujahid
In this blog, I am going to explain how OAuth 2.0 works and what vulnerabilities can be raised if it is implemented incorrectly.
In this blog, I am going to explain how OAuth 2.0 works and what vulnerabilities can be raised if it is implemented incorrectly.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/oauth-2-0-introduction-and-exploitation-part-i-explained-by-hashar-mujahid-262f9c59de6c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
OAuth 2.0 (Introduction and Exploitation Part I)Explained By Hashar Mujahid
In this blog, I am going to explain how OAuth 2.0 works and what vulnerabilities can be raised if it is implemented incorrectly.
What is API And Why It’s Important to know
https://medium.com/@tmgsecurity/what-is-api-and-why-its-important-to-know-c1a5b565d8b5?source=rss------bug_bounty-5
What is API?Continue reading on Medium » (https://medium.com/@tmgsecurity/what-is-api-and-why-its-important-to-know-c1a5b565d8b5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@tmgsecurity/what-is-api-and-why-its-important-to-know-c1a5b565d8b5?source=rss------bug_bounty-5
What is API?Continue reading on Medium » (https://medium.com/@tmgsecurity/what-is-api-and-why-its-important-to-know-c1a5b565d8b5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is API And Why It’s Important to know
What is API?
Exploit Collector
Zyxel Firewall SUID Binary Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Zyxel Firewall SUID Binary Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Zyxel Firewall SUID Binary Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
WordPress Core Cross Site Scripting / SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
WordPress Core Cross Site Scripting / SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Core Cross Site Scripting / SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
All about CORS Misconfiguration.
By Reading this article you suppose to learn:Continue reading on Medium »
Read more...
By Reading this article you suppose to learn:Continue reading on Medium »
Read more...
An accidental IDOR story that got me 1st acknowledgment from Nciipc
$whoamiContinue reading on Medium »
Read more...
$whoamiContinue reading on Medium »
Read more...
hacking: security in practice
When do you think our next Edward Snowden will show up?
Edward Snowden was able to leak all the documents because he was a cleared, high level employee that had access to a ton of data in the facility. Say for whatever reason, the NSA didn't update their hierarchy model with who has access to what information. Even then so, who's to say that the NSA hasn't tripled their surveillance and espionage technology, and someone is waiting in the shadows, ready to leak it again?
submitted by /u/FreshmanCult
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
When do you think our next Edward Snowden will show up?
Edward Snowden was able to leak all the documents because he was a cleared, high level employee that had access to a ton of data in the facility. Say for whatever reason, the NSA didn't update their hierarchy model with who has access to what information. Even then so, who's to say that the NSA hasn't tripled their surveillance and espionage technology, and someone is waiting in the shadows, ready to leak it again?
submitted by /u/FreshmanCult
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
When do you think our next Edward Snowden will show up?
Edward Snowden was able to leak all the documents because he was a cleared, high level employee that had access to a ton of data in the facility....
hacking: security in practice
Biometrics Harvesting
Has biometric harvesting taken hold in the hacker community yet? I remember an article about a guy who hacked Hillary Clinton's email account with a closeup picture of her hand he had taken from the front row seat of a conference.
With such a large portion of the population using biometrics for IT Security measures and workplace verification, why hasn't biometrics Harvesting become more rampant than ransomware? A successful hack into a systems such as ADP's would yield a massive trove of biometric signatures that would give its holder tremendous and unprecedented user access.
I'm told that ADP is unhackable, but I beg to differ.
Besides apparently ADP, what's the largest computer, network, or system that hasn't been hacked yet or supposedly can't be hacked?
What's the largest target that could be hacked if the entire Hacker subreddit combined forces?
∆
submitted by /u/Snoo_82970
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Biometrics Harvesting
Has biometric harvesting taken hold in the hacker community yet? I remember an article about a guy who hacked Hillary Clinton's email account with a closeup picture of her hand he had taken from the front row seat of a conference.
With such a large portion of the population using biometrics for IT Security measures and workplace verification, why hasn't biometrics Harvesting become more rampant than ransomware? A successful hack into a systems such as ADP's would yield a massive trove of biometric signatures that would give its holder tremendous and unprecedented user access.
I'm told that ADP is unhackable, but I beg to differ.
Besides apparently ADP, what's the largest computer, network, or system that hasn't been hacked yet or supposedly can't be hacked?
What's the largest target that could be hacked if the entire Hacker subreddit combined forces?
∆
submitted by /u/Snoo_82970
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Biometrics Harvesting
Has biometric harvesting taken hold in the hacker community yet? I remember an article about a guy who hacked Hillary Clinton's email account with...