Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How I found the Stored XSS and Clickjacking.

Hello everyone! I’m Nitish, this is my first write-up. Hope you all are doing great.Continue reading on Medium »
Read more...
hacking: security in practice
Does anyone have experience with Wi-Fi controlled LED Hacking?

I have some Monster brand wifi controlled LED lights at my house and wanted to connect them to my raspberry pi so that I could control them with a custom program. The only problem is that these lights are meant to only be used with the app or through digital assistants like Siri. I figured that the first step would be to use wire shark and see what is happening when the lights are told to turn on and change color. I am not currently home so I can’t do this right now, and I am wondering if anyone has experience doing this kind of thing and what methods/ approaches did you guys take? Just looking for any info that will speed up my own attempts!

submitted by /u/midnightwolfr
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Worth the watch

Watched this tonight very interesting I feel some members of the community will enjoy it but it might not be for everyone https://m.youtube.com/watch?v=wTgYeETwgKQ

submitted by /u/Phantasius224
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
LDAP Nom Nom - anonymously bruteforce Active Directory usernames at high speed
https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/

Here's my new tool "LDAP nom nom", which allows you to anonymously bruteforce Domain Controllers to find usernames in Active Directory at high speeds. As far as I know there are no logs generated for this, so detecting this requires custom network level monitoring. If you're pentesting a new environment, and don't know where to start, you can detect existence of about 10M usernames in less than 30 minutes (10K names/sec) From there on, it could be a question of looking for really dubious account names like "admintest" or "tempadmin" who might have the same password as the account name. This can be attempted by kerberoasting or direct logins (this is noisy and generates events). Reception of this small tool has been terrific, with more than 200 stars on Github in less than 24 hours, which is crazy compared to the other stuff I've released. https://github.com/lkarlslund/ldapnomnom submitted by /u/lkarlslund (https://www.reddit.com/user/lkarlslund)
[link] (https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/) [comments] (https://www.reddit.com/r/redteamsec/comments/xi6spc/ldap_nom_nom_anonymously_bruteforce_active/)

___________________________
@hacking_Attack
@Hacking_Video