Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack

The ride-sharing giant says a member of the notorious Lapsus$ hacking group started the attack by compromising an external contractor's credentials, as researchers parse the incident for takeaways.
hacking: security in practice
What are the techniques for the malware to be persistent on the host

So, there are multiple techniques to make your binary/malware persistent on the host. Techniques such as adding in the Registry keys when you installed the executable and changing the date so it will not be suspicious, creating a service, using the task scheduler, and so on.

The question I wanted to ask is what are the other techniques that you have seen or used for the malware/binary persistence so that it will stay on the host and stay maximum stealthy?

Thanks in advance

submitted by /u/rubenamizyan
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Quick questing about aircrack

Quick questing about aircrack, I got my network adapter today and wanting to test it out some, but I’m not trying to fuck around with someone else’s stuff because I do live around other networks, so is it okay to just do airodump-ng wlan0mon to see networks and check out if it works, or is that going to fuck with someone else? I have an old router I was going to plug in to mess around with but I don’t want any trouble with anyone else. Just wanted to make sure I’m doing nothing wrong

submitted by /u/Fair-Attorney-909
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Bypassing CSRF Protection (I)

Hi, My name is Hashar Mujahid and in this blog, we will talk about some techniques to bypass the csrf protection.Continue reading on InfoSec Write-ups »
Read more...
Unsubscribe any user’s e-mail notifications via IDOR

Description: I would like to share how I was able to unsubscribe any user from the Target website’s email notification service. Insecure…Continue reading on Medium »
Read more...
hacking: security in practice
noob

I've always been interested in hacking/pen testing, but know little about it. Is there an online tutorial/ tutor video playlist. (For Kali)

submitted by /u/Its_GameOver
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Interview Insight

TL;DR: Penetration testing is more than isolating yourself in a dark corner and typing furiously on your keyboard. Since you actually have to interact with people, do be a good teammate and do not be a jerk.

For context, my manager has been looking to fill a couple of open spots on our team, but has been unhappy with recent candidates. I asked out of curiosity what sort of gap in skills/knowledge he has been seeing, and he actually said that he has seen more social issues than technical. I am going to explain at a high level the key points here to give people an idea of these social skills that they can work on to become more effective teammates and/or more promising interview candidates.

The first item is general communication. Despite the stereotypes, penetration testers are often interacting with people whether they are clients or teammates. You will need to present findings to clients, and in doing so, you need to be able to explain your actions clearly and cohesively. If you cannot effectively communicate the work you did, your work is not useful, frankly. This carries over to writing reports too. If you cannot effectively highlight a vulnerability in documentation, the client is going to have a very difficult time reproducing the finding, and we will probably hear about it.

The second item is personality. By all means, be confident in your abilities, but avoid being overly confident to a point where it is obnoxious. When you work on a team, you have to accept that you will not always have the best solution, and this is a feature, not a bug. Realistically, you may misinterpret something or miss some small detail. When something like this happens and a teammate has input or feedback for you, there is no need to be confrontational. It is important to be receptive of what teammates have to say and learn from your mistakes. How you conduct yourself when you are wrong is very important. There are ways to be incorrect gracefully.

More on personality, while you are going through an interview, it is entirely possible for you to come across something unfamiliar. In these situations, interviewers are interested in observing your thought process. You have the opportunity here to demonstrate how you go about breaking down a problem, thinking through it, and arriving at a conclusion. Additionally, they are interested in seeing how you conduct yourself when you do not know the answer or are unsure of something. Asking good questions would be useful here as well as asking how one of the interviewers would approach the problem (after offering your own solution).

submitted by /u/camelCaseForever
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
hi.

Interested in information about bully 2 and video clips and photos of its development write to me privately, rockstar games is currently doing everything possible to download my posts from gta forums, therefore I will use reddit as the last means to share this information with you Interested talk to me privately.

submitted by /u/TB1798B
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video