Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
noob

I've always been interested in hacking/pen testing, but know little about it. Is there an online tutorial/ tutor video playlist. (For Kali)

submitted by /u/Its_GameOver
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Interview Insight

TL;DR: Penetration testing is more than isolating yourself in a dark corner and typing furiously on your keyboard. Since you actually have to interact with people, do be a good teammate and do not be a jerk.

For context, my manager has been looking to fill a couple of open spots on our team, but has been unhappy with recent candidates. I asked out of curiosity what sort of gap in skills/knowledge he has been seeing, and he actually said that he has seen more social issues than technical. I am going to explain at a high level the key points here to give people an idea of these social skills that they can work on to become more effective teammates and/or more promising interview candidates.

The first item is general communication. Despite the stereotypes, penetration testers are often interacting with people whether they are clients or teammates. You will need to present findings to clients, and in doing so, you need to be able to explain your actions clearly and cohesively. If you cannot effectively communicate the work you did, your work is not useful, frankly. This carries over to writing reports too. If you cannot effectively highlight a vulnerability in documentation, the client is going to have a very difficult time reproducing the finding, and we will probably hear about it.

The second item is personality. By all means, be confident in your abilities, but avoid being overly confident to a point where it is obnoxious. When you work on a team, you have to accept that you will not always have the best solution, and this is a feature, not a bug. Realistically, you may misinterpret something or miss some small detail. When something like this happens and a teammate has input or feedback for you, there is no need to be confrontational. It is important to be receptive of what teammates have to say and learn from your mistakes. How you conduct yourself when you are wrong is very important. There are ways to be incorrect gracefully.

More on personality, while you are going through an interview, it is entirely possible for you to come across something unfamiliar. In these situations, interviewers are interested in observing your thought process. You have the opportunity here to demonstrate how you go about breaking down a problem, thinking through it, and arriving at a conclusion. Additionally, they are interested in seeing how you conduct yourself when you do not know the answer or are unsure of something. Asking good questions would be useful here as well as asking how one of the interviewers would approach the problem (after offering your own solution).

submitted by /u/camelCaseForever
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
hi.

Interested in information about bully 2 and video clips and photos of its development write to me privately, rockstar games is currently doing everything possible to download my posts from gta forums, therefore I will use reddit as the last means to share this information with you Interested talk to me privately.

submitted by /u/TB1798B
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Line stamps on Kakao Talk

Hey guys I was just wondering if it's possible to bring Line stamps onto Kakao talk or somehow bring in custom stamps into Kakao Talk. My reason for this is that there are friends that only use Kakao Talk and I like the Line stamp selection I purchased a bunch and I would have done it in Kakao Talk too if they had the same stamps unfortunately they don't. Any ideas or suggestions?

submitted by /u/SuperSoakerGuyx
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
RFID key fob copying for MIWA key

My building refuses to give me a second key fob for my partner even though he will be coming in and out and I pay an egregious amount for rent.

They key fob is the Miwa key fob. Some details about this key fob can be found here:

https://clonemykey.com/copy-wizard/new-key/key-fob/miwa-key-fobs/miwa-red-key-fob/#more-specs

I'd love to use this service, however I have to mail in my key fob which makes it super difficult to clone since I wouldn't be able to leave my apartment while they have it in their possession.

Is there any key fob duplication tool that I can use (say one of the tools I can purchase on amazon)? Any suggested guides? It looks like this is a standard RFID key fob. I tried KeyMe but their kiosks wouldn't take my key fob for some reason.

submitted by /u/apprximatelycorrect
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Revolut hack: personal and banking data exposed

Revolut hack: personal and banking data exposedPost Views: 40 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Revolut has suffered a cyberattack that gave an unauthorized third party access to personal information of tens of thousands of clients.The incident occurred a week ago, on Sunday night, and has been described as “highly targeted.”

Founded in 2015, Revolut is a financial technology company that has seen a rapid growth, now offering banking, money management, and investment services to customers all over the world.

In a statement for BleepingComputer, a company spokesperson said that an unauthorized party had access “for a short period of time” to details of only a 0.16% of its customers.
“We immediately identified and isolated the attack to effectively limit its impact and have contacted those customers affected. Customers who have not received an email have not been impacted” – Revolut
According to the breach disclosure to the State Data Protection Inspectorate in Lithuania, where Revolut has a banking license, 50,150 customers have been impacted.

Based on the information from Revolut, the agency said that the number of affected customers in the European Economic Area is 20,687, and just 379 Lithuanian citizens are potentially impacted by this incident.

Details on how the threat actor gained access to the database have not been disclosed but it appears that the attacker relied on social engineering.

The Lithuanian data protection agency notes that the likely exposed information includes:

* Email addresses
* Full names
* Postal addresses
* Phone numbers
* Limited payment card data
* Account data
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
However, in a message to an affected customer, Revolut says that the type of compromised personal data varies for different customers. Card details, PINs, or passwords were not accessed.

Revolut emphasizes that the intruder did not gain access to users’ funds.

“Our customers’ money is safe – as it has always been. All customers can continue to use their cards and accounts as normal,” the company spokesperson told BleepingComputer.

The company reacted quickly to the intrusion and significantly limited the risk to its customers, isolating the attack by early Monday (2 A.M.).

As a precaution, Revolut formed a dedicated team tasked with monitoring customer accounts, to make sure that both money and data are safe.

Users should be “extremely wary” of any messages requesting personal details or passwords. Revolut will not call customers about the incident and will never ask for sensitive information.

Below is the full statement BleepingComputer received from a Revolut spokesperson:

Revolut recently experienced a highly targeted cyber attack. This resulted in an unauthorized third party obtaining access to the details of a small percentage (0.16%) of our customers for a short period of time.

We immediately identified and isolated the attack to effectively limit its impact and have contacted those customers affected. Customers who have not received an email have not been impacted.

To be clear, no funds have been accessed or stolen. Our customers’ money is safe – as it has always been. All customers can continue to use their cards and accounts as normal.

We take incidents such as these incredibly seriously, and we would like to sincerely apologize to any customers who have been affected by this incident, as the safety of our customers and their data is our top priority at Revolut.

Some Revolut customers also noted around the t[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Revolut hack: personal and banking data exposed Revolut hack: personal and banking data exposedPost Views: 40 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to…
ime of the incident that the support chat was displaying inappropriate language to visitors.
https://www.bleepstatic.com/images/news/u/1100723/2022/RevolutOhDaddy.jpg
While it is not clear if this defacement is related to the breach disclosed by Revolut, it shows that hackers may have had access to a wider range of systems used by the company.

Revolut did not explain how or why users received these messages but apologized to reporting customers and said that it was “addressing the issue and are taking steps to ensure this does not happen again.”
Trending: Find Hidden Info using Google Dorking manually, and Automated using Pagodo
Trending: Offensive Security Tool: fuxploider Phishers take advantageThis security incident is a good opportunity for phishing actors to trick any Revolut customer, even those not impacted, into giving away their sensitive details.

As first spotted by UCL’s “Report Smishing” platform, there’s already an ongoing SMS phishing campaign attempting to trick Revolut account holders with messages that their existing card has been frozen to prevent fraud.

To request a new card, the victims are directed to click on the link “revolut-card-cancel[.]com”, where they will go through a four-step phishing process as shown below.
https://www.bleepstatic.com/images/news/u/1220909/Phishing/phishing-steps.jpg
Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-3-300x150.png GTA 6 source code and videos leaked after Rockstar Games hackSeptember 19, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-2-300x150.png Uber hacked, internal systems breached and vulnerability reports stolenSeptember 16, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-2-300x150.png Microsoft Teams stores auth tokens as cleartext in Windows, Linux, MacsSeptember 15, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-1-300x150.png Zero-day in WPGateway WordPress plugin actively exploited in thousands WordPress sitesSeptember 14, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Revolut hack: personal and banking data exposed first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Avoid Phishing?

https://cdn-images-1.medium.com/max/1024/1*OlRDG790D1TbGBdx7ikOQw.jpeg
Now that everyone has access to the Internet, phishing prevention has become one of the essential practices in the online world.

Continue reading on Medium »
Kali Linux Tutorials
ggshield : Detect secret in source code, scan your repo for leaks

ggshield is a CLI application that runs in your local environment or in a CI environment to help you detect more than 350+ types of secrets, as well as other potential security vulnerabilities or policy breaks.

ggshield uses our public API through py-gitguardian to scan and detect potential secrets on files and other text content.

Only metadata such as call time, request size and scan mode is stored from scans using ggshield, therefore secrets and policy breaks incidents will not be displayed on your dashboard and your files and secrets won’t be stored. InstallationmacOSUsing HomebrewYou can install ggshield using Homebrew by running the following command:

$ brew install gitguardian/tap/ggshield Linux packagesDeb and RPM packages are available on Cloudsmith.

Setup instructions:

* Deb packages
* RPM packages Other Operating SystemsUsing pipInstall and update using pip:

$ pip install ggshield

ggshield supports Python 3.7 and newer.

The package should run on MacOS, Linux and Windows. UpdatingTo update ggshield you can add the option -U/--upgradeto the pip install command

$ pip install -U ggshield Initial setupTo use ggshield you need to authenticate against GitGuardian servers. To do so, use the ggshield auth logincommand. This command automates the provisioning of a personal access token and its configuration on the local workstation.

You can learn more about it from ggshield auth logindocumentation.

Alternatively, you can create your personal access token manually and you can store it in the GITGUARDIAN_API_KEYenvironment variable to complete the setup.

Once this is done, you can start scanning a repository with with ggshield secret scan repo /path/to/your/repo. Command referenceUsage: ggshield [OPTIONS] COMMAND [ARGS]…
Options:
-c, –config-path FILE Set a custom config file. Ignores local and global
config files.
-v, –verbose Verbose display mode.
–allow-self-signed Ignore ssl verification.
–debug Show debug information.
–version Show the version and exit.
-h, –help Show this message and exit.
Commands:
api-status Show API status.
auth Commands to manage authentication.
install Install a pre-commit or pre-push git hook (local or global).
quota Show quotas overview.
secret Commands to work with secrets. Secret scan commandsThe ggshield secret scancommand group contains the main ggshield commands, it has a few configuration options that can be used to override output behavior.

Usage: ggshield secret scan [OPTIONS] COMMAND [ARGS]…

Commands to scan various contents.
Options:
–json JSON output results [default: False]
–show-secrets Show secrets in plaintext instead of hiding
them.
–exit-zero Always return a 0 (non-error) status code, even
if incidents are found.The env var
GITGUARDIAN_EXIT_ZERO can also be used to set
this option.
–all-policies Present fails of all policies (Filenames,
FileExtensions, Secret Detection).By default,
only Secret Detection is shown.
-v, –verbose Verbose display mode.
-o, –output PATH Route ggshield output to file.
-b, –banlist-detector TEXT Exclude results from a detector.
–exclude PATH Do not scan the specified path.
–ignore-default-excludes Ignore excluded patterns by default. [default:
False]
-h, –help Show this message and exit.
Commands:
archive scan archive .
ci scan in a CI environment.
commit-range scan a defined COMMIT_RANGE in git.
docker scan a docker image .
path scan files and directories.
pre-commit scan as a pre-commit git hook.
pre-push scan as a pre-push git hook.
pre-receive scan as a pre-receive git hook.
pypi scan a pypi package .
repo scan a REPOSITORY’s commits at a given URL or path. ggshield secret scanhas different subcom[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Verdict-as-a-Service : Analyze files for malicious content

Verdict-as-a-Service (VaaS) is a service that provides a platform for scanning files for malware and other threats. It allows easy integration in your application. With a few lines of code, you can start scanning files for malware.

ATTENTION: All SDKs are currently prototypes and under heavy construction! Integration of Malware DetectionEasily integrate malware detection into any kind of application, service or platform.

Create a command line scanner to find malware with a few lines of code: Example
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibh-TYQ8eG0neW_-knPc7odagnqS6hInlWLkfo6qI1Ge0ALAZ-BVWu6jsJdcIcsK7yIdYXrDCpADraxjvhW7X_5jH0TP5NjXR41irJhg8DpBf1sTf_-0Jqz2G9NBkFKlXnEGHpBXHUWy0FWq_gi6Y1_A8nBrjYlCHoajUVc33Md4sWhP1JcdVvh6u3/s800/2.gif SDKsAt the moment SDKs for Rust, Java, Typescript, Microsoft .NET, Python and PHP are available.
FunctionalityRustJavaPHPTypeScript.NETPythonCheck SHA256https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Check SHA256 listhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png Check filehttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Check file listhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png Custom Guids for tracability on user sidehttps://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png https://s.w.org/images/core/emoji/14.0.0/72x72/274c.png Verdict-as-a-Service Rust SDKScan files for malware and other threats using the VaaS API in Rust. Integration Test: Real APICurrently all test under the /tests folder are integration tests against the real API. As they need credentials, (user, token) these need to be provided as environment variables.

Either export a VAAS_USERand VAAS_TOKENenvironment variable or use the .envfile. To use an .envfile, just create it in the root directory (e.g. where the Cargo.tomlresides) and add the variables with their values, e.g. KEY=VALUE.

The .envfile will not be checked in into git and can be used to store the sensitive environment variables on your local machine. Verdict-as-a-Service Java SDKScan files for malware and other threats using the VaaS API in Java. UsageGet a verdict for a SHA256 of a file.

public class MainClass {
public static void main(String[] args) {
// Connect to the VaaS endpoint
var config = new WsConfig(
clientId,
clientSecret,
new URI(tokenUrl),
new URI(vaasUrl));
var vaas = new Vaas(config);
vaas.connect();
// Get a verdict fo[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Verdict-as-a-Service : Analyze files for malicious content Verdict-as-a-Service (VaaS) is a service that provides a platform for scanning files for malware and other threats. It allows easy integration in your application. With a few…
r a SHA256
var sha256 = new Sha256(“000005c43196142f01d615a67b7da8a53cb0172f8e9317a2ec9a0a39a1da6fe8”);
var cts = new CancellationTokenSource(Duration.ofSeconds(10));
var verdict = vaas.forSha256(sha256, cts);
// Disconnect from the VaaS endpoint
vaas.disconnect();
// Print verdict result (CLEAN, UNKNOWN, MALICIOUS, PUP)
System.out.println(“Verdict: ” + verdict.getVerdict().name());
}
}

Get a verdict for a file.

public class MainClass {
public static void main(String[] args) {
// Connect to the VaaS endpoint
var config = new WsConfig(token);
var vaas = new Vaas(config);
vaas.connect();
// Get a verdict for a SHA256
var file = Path.of(“myfile”);
var cts = new CancellationTokenSource(Duration.ofSeconds(10));
var verdict = vaas.forFile(file, cts);
// Disconnect from the VaaS endpoint
vaas.disconnect();
// Print verdict result (CLEAN, UNKNOWN, MALICIOUS, PUP)
System.out.println(“Verdict: ” + verdict.getVerdict().name());
}
} Integration Test: Real APICurrently, all test under the /src/test folder are integration tests against the real API. As they need credentials, (token). These values need to be provided as environment variables.

Either export a VAAS_TOKEN environment variable or use the .env file. To use an .env file, just create it in the root directory (e.g. where the Readme.md resides) and add the variables with their values, e.g. KEY=VALUE.

The .env file will not be checked in into git and can be used to store the sensitive environment variables on your local machine. Verdict-as-a-Service PHP SDKPHP SDK for Verdict-as-a-Service API. Scan files for malware and other threats using the VaaS API in PHP.

For usage examples see the tests folder or the WordPress example in the examples folder. gdata-vaasAn SDK to easily utilize G DATA VaaS.

Verdict-as-a-Service (VaaS) is a service that provides a platform for scanning files for malware and other threats. It allows easy integration in your application. With a few lines of code, you can start scanning files for malware. What does the SDK do?It gives you as a developer a functions to talk to G DATA VaaS. It wraps away the complexity of the API into 4 basic functions. forSha256If you calculate the sha256 for a file, you can request that sha256 against G DATA VaaS. It’s the fastest way to get a verdict from our service. forSha256ListYou can also request multiple sha256 with a single function call. forFileYou can also ask for a file itself. You will still get the benefit of a fast verdict via Sha256 because the SDK will do that for you first. But additionally, if we don’t know the file, the file will get uploaded and (automatically) analyzed by us. forFileListYou can also request multiple files with a single function call. How to useInstallnpm install gdata-vaas Importimport Vaas from “gdata-vaas”; Developing with Visual Studio CodeRequired extensions:

* esbenp.prettier-vscode

Extend settings.json with:

{
“editor.formatOnSave”: true,
“[javascript]”: {
“editor.defaultFormatter”: “esbenp.prettier-vscode”
},
“[typescript]”: {
“editor.defaultFormatter”: “esbenp.prettier-vscode”
}
} Download

___________________________
@hacking_Attack
@Hacking_Video