Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
This hacker Targeting macOS Users Interested in Crypto Jobs
https://cdn-images-1.medium.com/max/728/0*p_68ghKM91Gqc96Q.jpg
The infamous Lazarus Group has continued its pattern of leveraging unsolicited job opportunities to deploy malware targeting Apple’s macOS…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
This hacker Targeting macOS Users Interested in Crypto Jobs
https://cdn-images-1.medium.com/max/728/0*p_68ghKM91Gqc96Q.jpg
The infamous Lazarus Group has continued its pattern of leveraging unsolicited job opportunities to deploy malware targeting Apple’s macOS…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
This hacker Targeting macOS Users Interested in Crypto Jobs
The infamous Lazarus Group has continued its pattern of leveraging unsolicited job opportunities to deploy malware targeting Apple’s macOS…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Catch The Flag
https://cdn-images-1.medium.com/max/2600/0*d5IvwLFBqTLomTIv
CTF is always attractive for cyber security professionals,hackers,penetration testers and students.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Catch The Flag
https://cdn-images-1.medium.com/max/2600/0*d5IvwLFBqTLomTIv
CTF is always attractive for cyber security professionals,hackers,penetration testers and students.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Catch The Flag
CTF is always attractive for cyber security professionals,hackers,penetration testers and students.
Kali Linux Tutorials
evilgophish : Combination Of Evilginx2 And GoPhish
___________________________
@hacking_Attack
@Hacking_Video
evilgophish : Combination Of Evilginx2 And GoPhish
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
evilgophish : Combination Of Evilginx2 And GoPhish
evilgophish is a combination Of Evilginx2 And GoPhish. As a penetration tester or red teamer, you may have heard of evilginx2 as a proxy.
All about: IDORs
IDORs happen when users can **access resources that do not belong to them** by directly reference the object ID, object number, or…Continue reading on Medium »
Read more...
IDORs happen when users can **access resources that do not belong to them** by directly reference the object ID, object number, or…Continue reading on Medium »
Read more...
hacking: security in practice
Self Hosted Proxy Service
We have created a proxy software that can be deployed to any server and will convert it into a proxy server. So here's how it works.
Let's say you have a server with IP 192.xxx.xxx.023.
We will deploy our software to your server on port let's say:8899
Now Your proxy server is up and running on 192.xxx.xxx.023:8899
To use the proxy simply pass the website in the URL like: -
http://192.xxx.xxx.023:8899/url=https://www.example.com
It will work seamlessly like any other proxy service e.g. ScrapingAPI, etc
Features:
1. Both residential/data center IPs to choose from.
2. Low pricing
3. Geolocation according to your requirement.
4. Decentralized nodes.
For more info please contact me.
submitted by /u/Pradeepkr34
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Self Hosted Proxy Service
We have created a proxy software that can be deployed to any server and will convert it into a proxy server. So here's how it works.
Let's say you have a server with IP 192.xxx.xxx.023.
We will deploy our software to your server on port let's say:8899
Now Your proxy server is up and running on 192.xxx.xxx.023:8899
To use the proxy simply pass the website in the URL like: -
http://192.xxx.xxx.023:8899/url=https://www.example.com
It will work seamlessly like any other proxy service e.g. ScrapingAPI, etc
Features:
1. Both residential/data center IPs to choose from.
2. Low pricing
3. Geolocation according to your requirement.
4. Decentralized nodes.
For more info please contact me.
submitted by /u/Pradeepkr34
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Self Hosted Proxy Service
We have created a proxy software that can be deployed to any server and will convert it into a proxy server. So here's how it works. Let's say...
hacking: security in practice
My Apartment building is switching encryption protocol
Hello,
I live in student accommodation. Me and some engineers clone RFID cards to create replicas for anyone who wants one. This is so people can leave one in their door and take one with them or if you lose one you still have a spare etc...
Protocol was MIFARE CLASSIC 48 bit, easy to crack with Cipher. They are switching to MIFARE PLUS 128 bit, not so easy. The company that provides this is ONITY. We understand we may have been the ones to cause this change.
Any suggestions to cut corners on cracking the encryption or are we stuffed?
submitted by /u/Ladzilla
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
My Apartment building is switching encryption protocol
Hello,
I live in student accommodation. Me and some engineers clone RFID cards to create replicas for anyone who wants one. This is so people can leave one in their door and take one with them or if you lose one you still have a spare etc...
Protocol was MIFARE CLASSIC 48 bit, easy to crack with Cipher. They are switching to MIFARE PLUS 128 bit, not so easy. The company that provides this is ONITY. We understand we may have been the ones to cause this change.
Any suggestions to cut corners on cracking the encryption or are we stuffed?
submitted by /u/Ladzilla
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
My Apartment building is switching encryption protocol
Hello, I live in student accommodation. Me and some engineers clone RFID cards to create replicas for anyone who wants one. This is so people can...
hacking: security in practice
can the sova virus spread through PDFs or only through apks
Sova virus is a banking virus which enters the phone through smishing and mimics an app . The app can't be installed . It monitors screen shots , frequently tapped keys and installed apps and sends it to a command centre .
submitted by /u/TangerineThin4780
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
can the sova virus spread through PDFs or only through apks
Sova virus is a banking virus which enters the phone through smishing and mimics an app . The app can't be installed . It monitors screen shots , frequently tapped keys and installed apps and sends it to a command centre .
submitted by /u/TangerineThin4780
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
can the sova virus spread through PDFs or only through apks
Sova virus is a banking virus which enters the phone through smishing and mimics an app . The app can't be installed . It monitors screen shots ,...
hacking: security in practice
20 digit numerical Wordlist
My router has a default wifi password of 20 numerical digits. After attempts to build a wordlist containing at least some of the permutations i failed really hard (what is exactly the intention behind such a huge password).
What I've done so far:
1. start at 000... add one, save (simplyfied)
2. when starting the script again, check for the last number and continue from there
A few problems i aknowledged:
1. it takes for ever (I know thats supposed to be) and I can't imagine a way of shortening the list eg start at 01111.. but then cases like 0XXX...0...XXX are excluded (and checking for three same digits in a row would only slow it down even more)
2. the txt file i wrote everything into is getting EXRTREMELY HUGE: at 5*10^9 its 110GB (expected but can't find a way to fix this)
Im not asking for tech support, just wanting to collect some ideas.
Thank you in advance!
submitted by /u/theWizzard23
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
20 digit numerical Wordlist
My router has a default wifi password of 20 numerical digits. After attempts to build a wordlist containing at least some of the permutations i failed really hard (what is exactly the intention behind such a huge password).
What I've done so far:
1. start at 000... add one, save (simplyfied)
2. when starting the script again, check for the last number and continue from there
A few problems i aknowledged:
1. it takes for ever (I know thats supposed to be) and I can't imagine a way of shortening the list eg start at 01111.. but then cases like 0XXX...0...XXX are excluded (and checking for three same digits in a row would only slow it down even more)
2. the txt file i wrote everything into is getting EXRTREMELY HUGE: at 5*10^9 its 110GB (expected but can't find a way to fix this)
Im not asking for tech support, just wanting to collect some ideas.
Thank you in advance!
submitted by /u/theWizzard23
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
20 digit numerical Wordlist
My router has a default wifi password of 20 numerical digits. After attempts to build a wordlist containing at least some of the permutations i...
hacking: security in practice
video downloader drm chrome extension free 2022
submitted by /u/OnePaleontologist103
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
video downloader drm chrome extension free 2022
submitted by /u/OnePaleontologist103
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
video downloader drm chrome extension free 2022
Posted in r/hacking by u/OnePaleontologist103 • 1 point and 0 comments
All about: IDORs
https://sl4x0.medium.com/all-about-idors-890fcd3bf330?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sl4x0.medium.com/all-about-idors-890fcd3bf330?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
All about: IDORs
IDORs happen when users can **access resources that do not belong to them** by directly reference the object ID, object number, or…
IDORs happen when users can **access resources that do not belong to them** by directly reference the object ID, object number, or…Continue reading on Medium » (https://sl4x0.medium.com/all-about-idors-890fcd3bf330?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
All about: IDORs
IDORs happen when users can **access resources that do not belong to them** by directly reference the object ID, object number, or…
How To Attack Admin Panels Successfully
https://infosecwriteups.com/how-to-attack-admin-panels-successfully-72c90eeb818c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/how-to-attack-admin-panels-successfully-72c90eeb818c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How To Attack Admin Panels Successfully
Attacking Web Apps Admin Panels The Right Way
Attacking Web Apps Admin Panels The Right WayContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-to-attack-admin-panels-successfully-72c90eeb818c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How To Attack Admin Panels Successfully
Attacking Web Apps Admin Panels The Right Way
Scan4All - Vuls Scan: 15000+PoCs; 21 Kinds Of Application Password Crack; 7000+Web Fingerprints; 146 Protocols And 90000+ Rules Port Scanning; Fuzz, HW, Awesome BugBounty...
http://www.kitploit.com/2022/09/scan4all-vuls-scan-15000pocs-21-kinds.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/09/scan4all-vuls-scan-15000pocs-21-kinds.html
___________________________
@hacking_Attack
@Hacking_Video
What is scan4all: integrated vscan, nuclei, ksubdomain, subfinder, etc., fully automated and intelligent。red team tools Code-level optimization, parameter optimization, and individual modules, such as vscan filefuzz, have been rewritten for these integrated projects. In principle, do not repeat the wheel, unless there are bugs, problemsCross-platform: based on golang implementation, lightweight, highly customizable, open source, supports Linux, windows, mac os, etc.Support [21] password blasting, support custom dictionary, open by "priorityNmap": true RDPSSHrsh-spxMysqlMsSqlOraclePostgresqlRedisFTPMongodbSMB, also detect MS17-010 (CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148), SmbGhost (CVE- 2020-0796)TelnetSnmpWap-wsp (Elasticsearch)RouterOsHTTP BasicAuthWeblogic, enable nuclei through enableNuclei=true at the same time, support T3, IIOP and other detectionTomcatJbossWinrm(wsman)POP3By default, http password intelligent blasting is enabled, and it will be automatically activated when an HTTP password is required, without manual interventionDetect whether there is nmap in the system, and enable nmap for fast scanning through priorityNmap=true, which is enabled by default, and the optimized nmap parameters are faster than masscan Disadvantages of using nmap: Is the network bad, because the traffic network packet is too large, which may lead to incomplete results Using nmap additionally requires setting the root password to an environment variable
export PPSSWWDD=yourRootPswd More references: config/doNmapScan.sh By default, naabu is used to complete port scanning (https://www.kitploit.com/search/label/Port%20Scanning) -stats=true to view the scanning progress Can I not scan ports?noScan=true ./scan4all -l list.txt -v
# nmap result default noScan=true
./scan4all -l nmapRssuilt.xml -vFast 15000+ POC detection capabilities, PoCs include: nuclei POCNuclei Templates Top 10 statisticsTAGCOUNTAUTHORCOUNTDIRECTORYCOUNTSEVERITYCOUNTTYPECOUNTcve1294daffainfo605cves1277info1352http3554panel591dhiyaneshdk503exposed-panels600high938file76lfi486pikpikcu321vulnerabilities493medium766network50xss439pdteam269technologies266critical436dns17wordpress401geeknik187exposures254low211exposure355dwisiswant0169misconfiguration207unknown7cve20213220x_akoko154token-spray206rce313princechaddha147workflows187wp-plugin297pussycat0x128default-logins101tech282gy741126file76281 directories, 3922 files.vscan POC vscan POC includes: xray 2.0 300+ POC, go POC, etc.scan4all POCSupport 7000+ web fingerprint scanning, identification:httpx fingerprint vscan fingerprintvscan fingerprint: including eHoleFinger, localFinger, etc.scan4all fingerprintSupport 146 protocols and 90000+ rule port scanningDepends on protocols and fingerprints supported by nmapFast HTTP sensitive file detection, can customize dictionaryLanding page detectionSupports multiple types of input - STDIN/HOST/IP/CIDR/URL/TXTSupports multiple output types - JSON/TXT/CSV/STDOUTHighly integratable: Configurable unified storage of results to Elasticsearch (https://www.kitploit.com/search/label/Elasticsearch) [strongly recommended]Smart SSL Analysis:In-depth analysis, automatically correlate the scanning of domain names in SSL information, such as *.xxx.com, and complete subdomain traversal according to the configuration, and the result will automatically add the target to the scanning listSupport to enable *.xx.com subdomain traversal function in smart SSL information, export EnableSubfinder=true, or adjust in the configuration fileAutomatically identify the case of multiple IPs associated with a domain (DNS), and automatically scan the associated multiple IPsSmart processing:When the IPs of multiple domain names in the list are the same, merge port scans to improve efficiencyIntelligently handle http abnormal pages, and fingerprint calculation and learningAutomated supply chain (https://www.kitploit.com/search/label/Supply%20Chain) identification, analysis
___________________________
@hacking_Attack
@Hacking_Video
export PPSSWWDD=yourRootPswd More references: config/doNmapScan.sh By default, naabu is used to complete port scanning (https://www.kitploit.com/search/label/Port%20Scanning) -stats=true to view the scanning progress Can I not scan ports?noScan=true ./scan4all -l list.txt -v
# nmap result default noScan=true
./scan4all -l nmapRssuilt.xml -vFast 15000+ POC detection capabilities, PoCs include: nuclei POCNuclei Templates Top 10 statisticsTAGCOUNTAUTHORCOUNTDIRECTORYCOUNTSEVERITYCOUNTTYPECOUNTcve1294daffainfo605cves1277info1352http3554panel591dhiyaneshdk503exposed-panels600high938file76lfi486pikpikcu321vulnerabilities493medium766network50xss439pdteam269technologies266critical436dns17wordpress401geeknik187exposures254low211exposure355dwisiswant0169misconfiguration207unknown7cve20213220x_akoko154token-spray206rce313princechaddha147workflows187wp-plugin297pussycat0x128default-logins101tech282gy741126file76281 directories, 3922 files.vscan POC vscan POC includes: xray 2.0 300+ POC, go POC, etc.scan4all POCSupport 7000+ web fingerprint scanning, identification:httpx fingerprint vscan fingerprintvscan fingerprint: including eHoleFinger, localFinger, etc.scan4all fingerprintSupport 146 protocols and 90000+ rule port scanningDepends on protocols and fingerprints supported by nmapFast HTTP sensitive file detection, can customize dictionaryLanding page detectionSupports multiple types of input - STDIN/HOST/IP/CIDR/URL/TXTSupports multiple output types - JSON/TXT/CSV/STDOUTHighly integratable: Configurable unified storage of results to Elasticsearch (https://www.kitploit.com/search/label/Elasticsearch) [strongly recommended]Smart SSL Analysis:In-depth analysis, automatically correlate the scanning of domain names in SSL information, such as *.xxx.com, and complete subdomain traversal according to the configuration, and the result will automatically add the target to the scanning listSupport to enable *.xx.com subdomain traversal function in smart SSL information, export EnableSubfinder=true, or adjust in the configuration fileAutomatically identify the case of multiple IPs associated with a domain (DNS), and automatically scan the associated multiple IPsSmart processing:When the IPs of multiple domain names in the list are the same, merge port scans to improve efficiencyIntelligently handle http abnormal pages, and fingerprint calculation and learningAutomated supply chain (https://www.kitploit.com/search/label/Supply%20Chain) identification, analysis
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
and scanningLink python3 log4j-scan (https://github.com/hktalent/log4j-scan)This version blocks the bug that your target information is passed to the DNS Log Server to avoid exposing vulnerabilitiesAdded the ability to send results to Elasticsearch for batch, touch typingThere will be time in the future to implement the golang version how to use?mkdir ~/MyWork/;cd ~/MyWork/;git clone https://github.com/hktalent/log4j-scanIntelligently identify honeypots and skip targets. This function is disabled by default. You can set EnableHoneyportDetection=true to enableHighly customizable: allow to define your own dictionary through config/config.json configuration, or control more details, including but not limited to: nuclei, httpx, naabu, etc.support HTTP Request Smuggling: CL-TE、TE-CL、TE-TE、CL_CL、BaseErr
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video