Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
NFTuLoan Partners with Immunefi, Web3’s Leading Bug Bounty Platform to offer $10,000 Bounty Reward

NFTuLoan is excited to announce its new partnership with Immunefi. While NFTuloan focuses on the NFT aspect of blockchain technology…Continue reading on Medium »
Read more...
hacking: security in practice
What are some good SOPs for staying safe while practicing?

Hey all, wondering what extra basic and advanced opsec techniques I should employ. As a privacy and security oriented user, I already do things like VPNs, anti-fingerprinting browser plugins, secure end to end encryption where applicable, good account security practices, hardware security (ie encrypting drives). While I am just practicing techniques on sites like hackthebox and tryhackme, I would like to join the fight against scambaiters at some point, as well as improving security policies with companies I interact with at my job at an MSP. What other things can I learn and employ? I know this can become a pretty heated topic, but I'm just looking for basic practices that I have missed that I can employ. I would like to provide the disclaimer that I am fairly new to OPSEC in general in the blue/red teaming applications. Thanks!

submitted by /u/RedneckOnline
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I created a script to automatically check for LFI

I intend to increase its speed and usability in the near future. I also plan on adding an auto exploit component. But justed wanted to share it.

https://github.com/BlessedToastr/leafy

submitted by /u/PapaCooki
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How would a network be blocking vpns

My school have a smooth wall firewall and i assume are using dpi however i was required to download a root ssl certificate which i have deleted because of security risks involved with root certs. Without these certs some sites don’t load because of not being able to establish a https connection. I have pritunl vpn in a vm on a server and it accessible through port 17905 which i don’t think is a standard port if i use obfuscation would the vpn work and get past the firewall or because i don’t have the ssl cert downloaded would that stop me connecting. Does anyone have an idea of what part either the ssl cert or dpi is blocking i also noted that you can’t seem to connect to IP’s directly as in i couldn’t connect to the vpns webpage even though i port forwarded it though i could connect to websites that i reverse looked up to find there ip The vpn works when on any other network including 4g(on iPhone) Is this just a easy case to finding a vpn that supports obfuscation to bypass the dpi? Thank you

submitted by /u/redisgoodboy
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Microsoft Rolls Out Passwordless Sign-on for Azure Virtual Desktop

Azure says cloud-native single sign-on with a passwordless option is most-requested new AVD feature in the product's history.
Dark Reading: Attacks/Breaches
Lessons from the GitHub Cybersecurity Breach: Protecting the Most Sensitive Data

This Tech Tip outlines three steps security teams should take to protect the information stored in Salesforce.
Dark Reading: Attacks/Breaches
4 Data Security Best Practices You Should Know

There are numerous strategies to lessen the possibility and effects of a cyberattack, but doing so takes careful planning and targeted action.
Dark Reading: Attacks/Breaches
MITRE Rolls Out FiGHT to Protect 5G Networks

MITRE's new FiGHT framework describes adversary tactics and techniques used against 5G systems and networks.