Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
For decades cookies have been used to authenticate a user and hold session data. But a simple session cookie has certain limitations and…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/json-web-tokens-c1f01028f5ac?source=rss------bug_bounty-5)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Physical Keylogger with rpi4

I am fairly new to the hacking world, but I like pentest my home server and lab, recently, I discover the keylogger world, and my attention goes essentially to physical keylogger, because I have an antivirus protection, so software keylogger would be (in my case) weird.

I know Linux as a beginner and some basics in python, so I would like to know if its possible to make my physical MITM keylogger with rpi4. I heard that it contains several usb interfaces, to get the strokes, and emulate them to the victim pc.

My plan is that the rpi4 would be between the keyboard and the pc, so is it possible ? And can you put me on the way to achieve it ?

Thanks for any response

submitted by /u/No-Degree9754
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
If a website downloads something on my computer, can it be executed?

If a file is downloaded unexpectedly onto my computer when I visit a website, would that file be able to run without me doing anything?

Or is it more of a social engineer tactic where it wants you to click it in some way?

submitted by /u/Highfivesghost
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
phishing using apache2 ( not receiving input even tho I used a post method correctly )

https://external-preview.redd.it/l23l3fIj3iAb0PfyzKc5Cccavrw8F61ubtcTnNBr5YA.jpg?width=320&crop=smart&auto=webp&s=77076262c4a08d2b88f620dbb222844c546282f4 ( no I wont use this on anyone I dont want to end my career before starting it I am not dumb )

so I saw this video https://www.youtube.com/watch?v=U6pDqFhN82I its about pen testing and the girl is really good at social engineering and phishing it made me very interested in trying phishing ( also I am studying computer science so I am generally interested in cybersecurity and programming )

I tried creating a snapchat phishing page but i couldn't clone (Issues with SET for some reason) So I downloaded zphisher but the ngrok server used in it shows a warning before you can access page, and the cloudflare is extremely slow and so I just copied the snapchat files from the .sites folder ( login.php, index.php and users.php and also got the file usernames.txt which was included in the post method in the code ) then put it /var/www/html/ and started an apache2 server then ssh -R 80:localhost:80 localhost.run ( so it can be accessd over the internet and try it on another machine, also can this be dangerous since my pen testing machine that I use this on has now a port exposed to the internet? )



I tried it but nothing shows up in the usernames.txt file for some reason ( ik its probably because I did something dumb or missed something obvious so bear with me in my journey to not be a skid, I just want it to work then I'll study the code then learn how to code pages like this by myself also I am learning basics, just finished a youtube course about kali linux command line and a network+ course )

does anyone know what the issue maybe ?



also what I did ( literally just copied the zphisher snapchat template )

https://preview.redd.it/irmlifanh7q91.png?width=821&format=png&auto=webp&s=273894a5ec02ce503cc661a7c9c5af773c07752b

the files : https://drive.google.com/drive/folders/1y2obE3vmNWR3Z-v697ngO5AKAC4cxVgp?usp=sharing

submitted by /u/Fuck_Life_421
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Cloud Lab
https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/

Hello, I am moving away from my home lab because I have a old server that is sucking up too much electricity in my house. I am looking for cloud services were I can make a low (or free) cost AD pentesting lab that charges me when I am using it and does not when I am not using it. Does anybody have any suggestions? I know of hackthebox, tryhackme, vulnhub etc (i use them frequently) but that is not what I am looking for, I am looking for a lab I can add multiple machines and make my own networks. Thanks! submitted by /u/Realistic_Otter (https://www.reddit.com/user/Realistic_Otter)
[link] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/) [comments] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Should Hacking Have a Code of Conduct?

For white hats who play by the rules, here are several ethical tenets to consider.