Monitoring your targets for bug bounties
https://infosecwriteups.com/monitoring-your-targets-for-bug-bounties-36f6be3e69c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/monitoring-your-targets-for-bug-bounties-36f6be3e69c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Monitoring your targets for bug bounties
An intro to setting up a monitoring system for your bug bounty target
An intro to setting up a monitoring system for your bug bounty targetContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/monitoring-your-targets-for-bug-bounties-36f6be3e69c9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Monitoring your targets for bug bounties
An intro to setting up a monitoring system for your bug bounty target
JSON web tokens
https://infosecwriteups.com/json-web-tokens-c1f01028f5ac?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/json-web-tokens-c1f01028f5ac?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
JSON web tokens
For decades cookies have been used to authenticate a user and hold session data. But a simple session cookie has certain limitations and…
For decades cookies have been used to authenticate a user and hold session data. But a simple session cookie has certain limitations and…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/json-web-tokens-c1f01028f5ac?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
JSON web tokens
For decades cookies have been used to authenticate a user and hold session data. But a simple session cookie has certain limitations and…
Tryhackme 0day Makine Çözümü
https://medium.com/@barisures/tryhackme-0day-makine-%C3%A7%C3%B6z%C3%BCm%C3%BC-95445c3a7903?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@barisures/tryhackme-0day-makine-%C3%A7%C3%B6z%C3%BCm%C3%BC-95445c3a7903?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tryhackme 0day Makine Çözümü
Açıklama: Selam arkadaşlar, Tryhackme platformunda bulunan ‘0day’ isimli makinenin çözümünü sizinle paylaşıyor olacağım. Bu makinede…
Açıklama: Selam arkadaşlar, Tryhackme platformunda bulunan ‘0day’ isimli makinenin çözümünü sizinle paylaşıyor olacağım. Bu makinede…Continue reading on Medium » (https://medium.com/@barisures/tryhackme-0day-makine-%C3%A7%C3%B6z%C3%BCm%C3%BC-95445c3a7903?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tryhackme 0day Makine Çözümü
Açıklama: Selam arkadaşlar, Tryhackme platformunda bulunan ‘0day’ isimli makinenin çözümünü sizinle paylaşıyor olacağım. Bu makinede…
Nmap in pocket : A complete guide
https://medium.com/@krishArse/nmap-in-pocket-a-complete-guide-dff25ca13a0d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@krishArse/nmap-in-pocket-a-complete-guide-dff25ca13a0d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nmap in pocket : A complete guide
Welcome Hackers,
Welcome Hackers,Continue reading on Medium » (https://medium.com/@krishArse/nmap-in-pocket-a-complete-guide-dff25ca13a0d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nmap in pocket : A complete guide
Welcome Hackers,
hacking: security in practice
Physical Keylogger with rpi4
I am fairly new to the hacking world, but I like pentest my home server and lab, recently, I discover the keylogger world, and my attention goes essentially to physical keylogger, because I have an antivirus protection, so software keylogger would be (in my case) weird.
I know Linux as a beginner and some basics in python, so I would like to know if its possible to make my physical MITM keylogger with rpi4. I heard that it contains several usb interfaces, to get the strokes, and emulate them to the victim pc.
My plan is that the rpi4 would be between the keyboard and the pc, so is it possible ? And can you put me on the way to achieve it ?
Thanks for any response
submitted by /u/No-Degree9754
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Physical Keylogger with rpi4
I am fairly new to the hacking world, but I like pentest my home server and lab, recently, I discover the keylogger world, and my attention goes essentially to physical keylogger, because I have an antivirus protection, so software keylogger would be (in my case) weird.
I know Linux as a beginner and some basics in python, so I would like to know if its possible to make my physical MITM keylogger with rpi4. I heard that it contains several usb interfaces, to get the strokes, and emulate them to the victim pc.
My plan is that the rpi4 would be between the keyboard and the pc, so is it possible ? And can you put me on the way to achieve it ?
Thanks for any response
submitted by /u/No-Degree9754
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Physical Keylogger with rpi4
I am fairly new to the hacking world, but I like pentest my home server and lab, recently, I discover the keylogger world, and my attention goes...
hacking: security in practice
If a website downloads something on my computer, can it be executed?
If a file is downloaded unexpectedly onto my computer when I visit a website, would that file be able to run without me doing anything?
Or is it more of a social engineer tactic where it wants you to click it in some way?
submitted by /u/Highfivesghost
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
If a website downloads something on my computer, can it be executed?
If a file is downloaded unexpectedly onto my computer when I visit a website, would that file be able to run without me doing anything?
Or is it more of a social engineer tactic where it wants you to click it in some way?
submitted by /u/Highfivesghost
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
phishing using apache2 ( not receiving input even tho I used a post method correctly )
https://external-preview.redd.it/l23l3fIj3iAb0PfyzKc5Cccavrw8F61ubtcTnNBr5YA.jpg?width=320&crop=smart&auto=webp&s=77076262c4a08d2b88f620dbb222844c546282f4 ( no I wont use this on anyone I dont want to end my career before starting it I am not dumb )
so I saw this video https://www.youtube.com/watch?v=U6pDqFhN82I its about pen testing and the girl is really good at social engineering and phishing it made me very interested in trying phishing ( also I am studying computer science so I am generally interested in cybersecurity and programming )
I tried creating a snapchat phishing page but i couldn't clone (Issues with SET for some reason) So I downloaded zphisher but the ngrok server used in it shows a warning before you can access page, and the cloudflare is extremely slow and so I just copied the snapchat files from the .sites folder ( login.php, index.php and users.php and also got the file usernames.txt which was included in the post method in the code ) then put it /var/www/html/ and started an apache2 server then ssh -R 80:localhost:80 localhost.run ( so it can be accessd over the internet and try it on another machine, also can this be dangerous since my pen testing machine that I use this on has now a port exposed to the internet? )
I tried it but nothing shows up in the usernames.txt file for some reason ( ik its probably because I did something dumb or missed something obvious so bear with me in my journey to not be a skid, I just want it to work then I'll study the code then learn how to code pages like this by myself also I am learning basics, just finished a youtube course about kali linux command line and a network+ course )
does anyone know what the issue maybe ?
also what I did ( literally just copied the zphisher snapchat template )
https://preview.redd.it/irmlifanh7q91.png?width=821&format=png&auto=webp&s=273894a5ec02ce503cc661a7c9c5af773c07752b
the files : https://drive.google.com/drive/folders/1y2obE3vmNWR3Z-v697ngO5AKAC4cxVgp?usp=sharing
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
phishing using apache2 ( not receiving input even tho I used a post method correctly )
https://external-preview.redd.it/l23l3fIj3iAb0PfyzKc5Cccavrw8F61ubtcTnNBr5YA.jpg?width=320&crop=smart&auto=webp&s=77076262c4a08d2b88f620dbb222844c546282f4 ( no I wont use this on anyone I dont want to end my career before starting it I am not dumb )
so I saw this video https://www.youtube.com/watch?v=U6pDqFhN82I its about pen testing and the girl is really good at social engineering and phishing it made me very interested in trying phishing ( also I am studying computer science so I am generally interested in cybersecurity and programming )
I tried creating a snapchat phishing page but i couldn't clone (Issues with SET for some reason) So I downloaded zphisher but the ngrok server used in it shows a warning before you can access page, and the cloudflare is extremely slow and so I just copied the snapchat files from the .sites folder ( login.php, index.php and users.php and also got the file usernames.txt which was included in the post method in the code ) then put it /var/www/html/ and started an apache2 server then ssh -R 80:localhost:80 localhost.run ( so it can be accessd over the internet and try it on another machine, also can this be dangerous since my pen testing machine that I use this on has now a port exposed to the internet? )
I tried it but nothing shows up in the usernames.txt file for some reason ( ik its probably because I did something dumb or missed something obvious so bear with me in my journey to not be a skid, I just want it to work then I'll study the code then learn how to code pages like this by myself also I am learning basics, just finished a youtube course about kali linux command line and a network+ course )
does anyone know what the issue maybe ?
also what I did ( literally just copied the zphisher snapchat template )
https://preview.redd.it/irmlifanh7q91.png?width=821&format=png&auto=webp&s=273894a5ec02ce503cc661a7c9c5af773c07752b
the files : https://drive.google.com/drive/folders/1y2obE3vmNWR3Z-v697ngO5AKAC4cxVgp?usp=sharing
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
phishing using apache2 ( not receiving input even tho I used a...
Posted in r/hacking by u/Fuck_Life_421 • 2 points and 0 comments
Cloud Lab
https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/
Hello, I am moving away from my home lab because I have a old server that is sucking up too much electricity in my house. I am looking for cloud services were I can make a low (or free) cost AD pentesting lab that charges me when I am using it and does not when I am not using it. Does anybody have any suggestions? I know of hackthebox, tryhackme, vulnhub etc (i use them frequently) but that is not what I am looking for, I am looking for a lab I can add multiple machines and make my own networks. Thanks! submitted by /u/Realistic_Otter (https://www.reddit.com/user/Realistic_Otter)
[link] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/) [comments] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/
Hello, I am moving away from my home lab because I have a old server that is sucking up too much electricity in my house. I am looking for cloud services were I can make a low (or free) cost AD pentesting lab that charges me when I am using it and does not when I am not using it. Does anybody have any suggestions? I know of hackthebox, tryhackme, vulnhub etc (i use them frequently) but that is not what I am looking for, I am looking for a lab I can add multiple machines and make my own networks. Thanks! submitted by /u/Realistic_Otter (https://www.reddit.com/user/Realistic_Otter)
[link] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/) [comments] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cloud Lab
Hello, I am moving away from my home lab because I have a old server that is sucking up too much electricity in my house. I am looking for cloud...
Dark Reading: Attacks/Breaches
Samsung Fails Consumers in Preventable Back-to-Back Data Breaches, According to Federal Lawsuit
Company unnecessarily collected consumers' personal data and failed to safeguard it, suit alleges, leading to two back-to-back data breaches.
___________________________
@hacking_Attack
@Hacking_Video
Samsung Fails Consumers in Preventable Back-to-Back Data Breaches, According to Federal Lawsuit
Company unnecessarily collected consumers' personal data and failed to safeguard it, suit alleges, leading to two back-to-back data breaches.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Samsung Fails Consumers in Preventable Back-to-Back Data Breaches, According to Federal Lawsuit
Company unnecessarily collected consumers' personal data and failed to safeguard it, suit alleges, leading to two back-to-back data breaches.
Dark Reading: Attacks/Breaches
How Quantum Physics Leads to Decrypting Common Algorithms
YouTuber minutephysics explains how Shor's algorithm builds on existing formulae like Euclid's algorithm and Fourier transforms to leverage quantum superpositioning and break encryption.
___________________________
@hacking_Attack
@Hacking_Video
How Quantum Physics Leads to Decrypting Common Algorithms
YouTuber minutephysics explains how Shor's algorithm builds on existing formulae like Euclid's algorithm and Fourier transforms to leverage quantum superpositioning and break encryption.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
How Quantum Physics Leads to Decrypting Common Algorithms
YouTuber minutephysics explains how Shor's algorithm builds on existing formulae like Euclid's algorithm and Fourier transforms to leverage quantum superpositioning and break encryption.
Exploit Collector
LivelyCart Pro 3 Cross Site Scripting
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png LivelyCart Pro version 3 suffers from a cross site scripting vulnerability.
SHA-256 |
___________________________
@hacking_Attack
@Hacking_Video
LivelyCart Pro 3 Cross Site Scripting
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png LivelyCart Pro version 3 suffers from a cross site scripting vulnerability.
SHA-256 |
ef3470c3fee8e0e813c2945b5ef78e86a17766d13550ed989a8641bba9fb6852Download ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : pro-demo.livelycart.com │
│ Vendor : livelyworks - livelyworks.net │
│ Software : LivelyCart Pro 3 - Laravel E-Commerce Platform │
│ Vuln Type: Reflected XSS │
│ Method : GET │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ B4nks-NET irc.b4nks.tk #unix ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL
CryptoJob (Twitter) twitter.com/CryptozJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2022 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
GET parameter 'min_price' is vulnerable to XSS
https://pro-demo.livelycart.com/products?min_price=11[XSS]&max_price=999&sort_by=created_at&sort_order=asc&
GET parameter 'max_price' is vulnerable to XSS
https://pro-demo.livelycart.com/products?min_price=11&max_price=999[XSS]&sort_by=created_at&sort_order=asc&
Some XSS Payloads Reflected
ss29h">gub34
yljlw">onc87
[-] Done Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
LivelyCart Pro 3 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.