Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Audit your DNS configs, you're probably going to be shocked

https://github.com/punk-security/dnsReaper

I wrote a tool to hunt out DNS config errors that allow for subdomain takeovers. You wouldn't believe how common it is. No one looks after DNS.

I've done a couple talks about DNS takeovers in the UK now at places like blackhat and bsides. I'm really hoping to present it at defcon next year and I'm doing a tonne of research using different DNS datasets.

I'd really appreciate if anyone can point me at some obscure DNS takeover blogs they've come across.

submitted by /u/punksecurity_simon
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
hashcat

I'm currently trying to brute force a 7z archive (AES-256) (11600 Hash Mode) that I have just create, with Hashcat but my problem is that my Hashrate seems super low currently at 24000H/s for an RTX 3070 my question is this normal because of AES-256 or should it be faster ?

submitted by /u/lordnyrox
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Any book recommendation?

I’m looking to read up on the history and techniques. Any good recommendations?

submitted by /u/Digaholeonabeach
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Book recommendations

I’m looking to read up on the history and techniques. Any good recommendations?

submitted by /u/Digaholeonabeach
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Mobile Verification Tool Error Issues

Hello all.

I have been through the steps to install ubuntu, install python3, including the libimobile utility.

When I run the check backup command it comes up with errors.



Can you clarify what I'm missing here?

submitted by /u/ChefBoyOfficial
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Lazarus Lures Aspiring Crypto Pros With Fake Exchange Job Postings

Previously observed using fake Coinbase jobs, the North Korea-sponsored APT has expanded into using Crypo.com gigs as cover to distribute malware.
Dark Reading: Attacks/Breaches
Amid Sweeping Change, Cyber Defenders Face Escalating Visibility — and Pressure

Why cyber teams are now front and center for business enablement within organizations, and the significant challenges they face.
Dark Reading: Attacks/Breaches
FBI Helping Australian Authorities Investigate Massive Optus Data Breach: Reports

Initial reports suggest a basic security error allowed the attacker to access the company's live customer database via an unauthenticated API.
Proactive Pentest, before a Pentest?
https://www.reddit.com/r/Pentesting/comments/xpzje1/proactive_pentest_before_a_pentest/

I am the system admin for a small company. 5 users and a couple public facing services (FTP, IIS website), plus internal servers (SQL, file server etc). Do you recommend any steps I can take and software I can run to find and remediate my own issues before I spend money on an external vendor/audit? I don't have the money right now for full scale Pentest or audit, but I feel like I want to take as many steps as I reasonably can myself, to find issues slowly. I know I won't do as good a job as a pro. Any recommendations? Are there 1 or 2 software tools I can use to get me 90% there? submitted by /u/maniac_me (https://www.reddit.com/user/maniac_me)
[link] (https://www.reddit.com/r/Pentesting/comments/xpzje1/proactive_pentest_before_a_pentest/) [comments] (https://www.reddit.com/r/Pentesting/comments/xpzje1/proactive_pentest_before_a_pentest/)

___________________________
@hacking_Attack
@Hacking_Video