Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Taking Control of Turgistan’s Government Through Hacking
https://cdn-images-1.medium.com/max/2600/0*NRCkoeXj-xXZdEoc
After a few months of hacking, I wanted to get into something bigger. I wanted to see if instead of taking down websites, I could find a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Taking Control of Turgistan’s Government Through Hacking
https://cdn-images-1.medium.com/max/2600/0*NRCkoeXj-xXZdEoc
After a few months of hacking, I wanted to get into something bigger. I wanted to see if instead of taking down websites, I could find a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Taking Control of Turgistan’s Government Through Hacking
After a few months of hacking, I wanted to get into something bigger. I wanted to see if instead of taking down websites, I could find a…
Code flaws leads to Org/Admin Account Takeover
Hello Everyone, I’m Saransh Saraf and I’m back with another unique account takeover idea, so let’s just dive into it :)Continue reading on Medium »
Read more...
Hello Everyone, I’m Saransh Saraf and I’m back with another unique account takeover idea, so let’s just dive into it :)Continue reading on Medium »
Read more...
Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE)
https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/
Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE) Updated Video Tutorial ! https://github.com/freeload101/Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy Want to pentest or run Android apps in minutes ? Sick of BlueStacks or NOX malware/adware ? Not a single binary in this script and it's open source and downloads are direct from proper sources. There is lots of great powershell tricks (not great code) in this script. I worked hard on thing's like: making it portable as possible setting up and downloading extremely fast environment for Android, Java and Python converting ssl certs to Android without openssl using certutil.exe only I would like to make it even easier to use but I don't want to spend more time developing it if nobody is going to use it so please let me know if you like it and open bugs/suggestions/feature request etc! If you're a mod about to remove this post can you do me the kind pleasure of telling me why and how I can help the community better please let me know. submitted by /u/rmccurdyDOTcom (https://www.reddit.com/user/rmccurdyDOTcom)
[link] (https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/) [comments] (https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/
Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE) Updated Video Tutorial ! https://github.com/freeload101/Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy Want to pentest or run Android apps in minutes ? Sick of BlueStacks or NOX malware/adware ? Not a single binary in this script and it's open source and downloads are direct from proper sources. There is lots of great powershell tricks (not great code) in this script. I worked hard on thing's like: making it portable as possible setting up and downloading extremely fast environment for Android, Java and Python converting ssl certs to Android without openssl using certutil.exe only I would like to make it even easier to use but I don't want to spend more time developing it if nobody is going to use it so please let me know if you like it and open bugs/suggestions/feature request etc! If you're a mod about to remove this post can you do me the kind pleasure of telling me why and how I can help the community better please let me know. submitted by /u/rmccurdyDOTcom (https://www.reddit.com/user/rmccurdyDOTcom)
[link] (https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/) [comments] (https://www.reddit.com/r/redteamsec/comments/y2oa7y/java_android_magisk_burp_objection_root_emulator/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE)
Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE) Updated Video Tutorial ! ...
Help Starting
https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/
Hey everyone I’m a sophomore in college and after a bit of research I want to pursue a career in penetration testing. I’ve started learning the basics of networks and have played around with Kali Linux a little bit. I was wondering if anyone had any tips on a good starting point for someone that is brand new to all of this stuff. submitted by /u/Parkydunn (https://www.reddit.com/user/Parkydunn)
[link] (https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/) [comments] (https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/
Hey everyone I’m a sophomore in college and after a bit of research I want to pursue a career in penetration testing. I’ve started learning the basics of networks and have played around with Kali Linux a little bit. I was wondering if anyone had any tips on a good starting point for someone that is brand new to all of this stuff. submitted by /u/Parkydunn (https://www.reddit.com/user/Parkydunn)
[link] (https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/) [comments] (https://www.reddit.com/r/Pentesting/comments/y2ot7m/help_starting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Help Starting
Hey everyone I’m a sophomore in college and after a bit of research I want to pursue a career in penetration testing. I’ve started learning the...
Pivoting Over Challenge Based Enterprise WiFi Network
https://www.reddit.com/r/redteamsec/comments/y2qz4c/pivoting_over_challenge_based_enterprise_wifi/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/pivoting-over-peap-mschapv2-wifi-network/) [comments] (https://www.reddit.com/r/redteamsec/comments/y2qz4c/pivoting_over_challenge_based_enterprise_wifi/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/y2qz4c/pivoting_over_challenge_based_enterprise_wifi/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/pivoting-over-peap-mschapv2-wifi-network/) [comments] (https://www.reddit.com/r/redteamsec/comments/y2qz4c/pivoting_over_challenge_based_enterprise_wifi/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pivoting Over Challenge Based Enterprise WiFi Network
Posted in r/redteamsec by u/tbhaxor • 1 point and 0 comments
hacking: security in practice
What can I do to make cryptography and enumeration easier?
I've been doing tryhackme and starting hack the box for roughly 2 months. I understand concepts such as gaining access and prelivalge escalation, but unfortunately struggle with the beginning steps like enumeration. I know what to do normally (Use Nmap, enum4linux, etc), but when I gain too little information I get stuck. I try using guides, but struggle with understanding how they were able to find so much information in massive rooms. I hope I'm not to vague and don't mean to upset anyone with these simple questions. I'm just concerned I'm not progressing in my learning path.
submitted by /u/Power_level_9000_spy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What can I do to make cryptography and enumeration easier?
I've been doing tryhackme and starting hack the box for roughly 2 months. I understand concepts such as gaining access and prelivalge escalation, but unfortunately struggle with the beginning steps like enumeration. I know what to do normally (Use Nmap, enum4linux, etc), but when I gain too little information I get stuck. I try using guides, but struggle with understanding how they were able to find so much information in massive rooms. I hope I'm not to vague and don't mean to upset anyone with these simple questions. I'm just concerned I'm not progressing in my learning path.
submitted by /u/Power_level_9000_spy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What can I do to make cryptography and enumeration easier?
I've been doing tryhackme and starting hack the box for roughly 2 months. I understand concepts such as gaining access and prelivalge escalation,...
hacking: security in practice
Core isolation - Memory integrity on or of?
Im studying ethical hacking on my own (literally just started), downloaded VirtualBox, created a Vmachine with kali to start learning and noticed it turned on core isolation on my pc.
I use this pc for gaming as well, and i kinda noticed a bit of overheating and a few fps drops but nothing really alarming. checked my cpu monitoring app and told me it couldn't read my cpu stats because of the core isolation, so i investigated what it is.
I understand it protects my host machine from malware or dangerous stuff that could happened on my VM (i think?), but as im just starting in this world i figured maybe there wouldn't be a problem to have it turned off, just for my peace of mind? as i said, there are not really any alarming behaviors on my host machine.
i probably should get another computer learn this sort of things without risking my main machine i guess, but for now i just have the one. is core isolation a must have for any ethical hacking activity? or is it ok for me to turn it off in the meantime?
submitted by /u/GODstonn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Core isolation - Memory integrity on or of?
Im studying ethical hacking on my own (literally just started), downloaded VirtualBox, created a Vmachine with kali to start learning and noticed it turned on core isolation on my pc.
I use this pc for gaming as well, and i kinda noticed a bit of overheating and a few fps drops but nothing really alarming. checked my cpu monitoring app and told me it couldn't read my cpu stats because of the core isolation, so i investigated what it is.
I understand it protects my host machine from malware or dangerous stuff that could happened on my VM (i think?), but as im just starting in this world i figured maybe there wouldn't be a problem to have it turned off, just for my peace of mind? as i said, there are not really any alarming behaviors on my host machine.
i probably should get another computer learn this sort of things without risking my main machine i guess, but for now i just have the one. is core isolation a must have for any ethical hacking activity? or is it ok for me to turn it off in the meantime?
submitted by /u/GODstonn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Core isolation - Memory integrity on or of?
Im studying ethical hacking on my own (literally just started), downloaded VirtualBox, created a Vmachine with kali to start learning and noticed...
hacking: security in practice
Can i locate my little sisters stalker using their IP? (or VPN)
Hi all, as the title suggests, I am trying to identify the person who has been stalking my sister for the last three years. Things have escalated with each passing day, and now the person is also harassing her best friend. This person has made multiple "tribute" pages, made multiple accounts to message her to explain in detail how he is going to SA her, sent her upskirt shots of her sitting, Made public 'upskirt" posts of her und*rage, and much worse. The threats are horrific and the girls now have reason to believe that they know their addresses, but police refuse to help without "more evidence". We have responded to the stalker with a grabify link and captured two IP addresses, once through an instagram link and also safari. but i fear that they may be using a VPN.
Please, tell me there's something i can do. I have absolutely zero knowledge with this stuff, so I am hopeful one of you fine folks can at least give me some pointers. I appreciate it, as all i want in this world is to protect my family. Thank you all in advance.
submitted by /u/mtn_mama
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can i locate my little sisters stalker using their IP? (or VPN)
Hi all, as the title suggests, I am trying to identify the person who has been stalking my sister for the last three years. Things have escalated with each passing day, and now the person is also harassing her best friend. This person has made multiple "tribute" pages, made multiple accounts to message her to explain in detail how he is going to SA her, sent her upskirt shots of her sitting, Made public 'upskirt" posts of her und*rage, and much worse. The threats are horrific and the girls now have reason to believe that they know their addresses, but police refuse to help without "more evidence". We have responded to the stalker with a grabify link and captured two IP addresses, once through an instagram link and also safari. but i fear that they may be using a VPN.
Please, tell me there's something i can do. I have absolutely zero knowledge with this stuff, so I am hopeful one of you fine folks can at least give me some pointers. I appreciate it, as all i want in this world is to protect my family. Thank you all in advance.
submitted by /u/mtn_mama
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can i locate my little sisters stalker using their IP? (or VPN)
Hi all, as the title suggests, I am trying to identify the person who has been stalking my sister for the last three years. Things have escalated...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
AWS S3 bucket Misconfigurations and Exploitations
https://cdn-images-1.medium.com/max/600/1*Fn8KIESISWySftKiFMq8IQ.png
— — — — — — — — — - AWS S3 bucket Misconfigurations — — — —— —
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
AWS S3 bucket Misconfigurations and Exploitations
https://cdn-images-1.medium.com/max/600/1*Fn8KIESISWySftKiFMq8IQ.png
— — — — — — — — — - AWS S3 bucket Misconfigurations — — — —— —
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
AWS S3 bucket Misconfigurations and Exploitations
— — — — — — — — — - AWS S3 bucket Misconfigurations — — — —— —
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackers Using Vishing to Trick Victims into?
https://cdn-images-1.medium.com/max/728/0*EcmDZPMR03g7WfMz.jpg
Malicious actors are resorting to voice phishing (vishing) tactics to dupe victims into installing Android malware on their devices, new…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers Using Vishing to Trick Victims into?
https://cdn-images-1.medium.com/max/728/0*EcmDZPMR03g7WfMz.jpg
Malicious actors are resorting to voice phishing (vishing) tactics to dupe victims into installing Android malware on their devices, new…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers Using Vishing to Trick Victims into?
Malicious actors are resorting to voice phishing (vishing) tactics to dupe victims into installing Android malware on their devices, new…
OSCP : Complete Guide Part-1
Hi everyone, so I’m sharing some resources & tools information which will be helpful in your OSCP journey. If you have a career in…Continue reading on Medium »
Read more...
Hi everyone, so I’m sharing some resources & tools information which will be helpful in your OSCP journey. If you have a career in…Continue reading on Medium »
Read more...
AWS S3 bucket Misconfigurations and Exploitations
https://akash-venky091.medium.com/aws-s3-bucket-misconfigurations-and-exploitations-6d89546eec54?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://akash-venky091.medium.com/aws-s3-bucket-misconfigurations-and-exploitations-6d89546eec54?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
AWS S3 bucket Misconfigurations and Exploitations
— — — — — — — — — - AWS S3 bucket Misconfigurations — — — —— —
— — — — — — — — — - AWS S3 bucket Misconfigurations — — — —— —Continue reading on Medium » (https://akash-venky091.medium.com/aws-s3-bucket-misconfigurations-and-exploitations-6d89546eec54?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
AWS S3 bucket Misconfigurations and Exploitations
— — — — — — — — — - AWS S3 bucket Misconfigurations — — — —— —
OSCP : Complete Guide Part-1
https://medium.com/@sumitcfe/oscp-complete-guide-part-1-1ed24e47fcbd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sumitcfe/oscp-complete-guide-part-1-1ed24e47fcbd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
OSCP : Complete Guide Part-1
Hi everyone, so I’m sharing some resources & tools information which will be helpful in your OSCP journey. If you have a career in…
Hi everyone, so I’m sharing some resources & tools information which will be helpful in your OSCP journey.
If you have a career in…Continue reading on Medium » (https://medium.com/@sumitcfe/oscp-complete-guide-part-1-1ed24e47fcbd?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
If you have a career in…Continue reading on Medium » (https://medium.com/@sumitcfe/oscp-complete-guide-part-1-1ed24e47fcbd?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
OSCP : Complete Guide Part-1
Hi everyone, so I’m sharing some resources & tools information which will be helpful in your OSCP journey. If you have a career in…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New npm timing attack could lead to supply chain attacks
New npm timing attack could lead to supply chain attacksPost Views: 6 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Security researchers have discovered an npm timing attack that reveals the names of private packages so threat actors can release malicious clones publicly to trick developers into using them instead.The attack relies on a small time difference in the return of a “404 Not Found” error when searching for a private compared to a non-existent package in the repository.
While the response time difference is only a few hundred milliseconds, it is enough to determine whether a private package exists to perform package impersonation attacks.
Organizations create private packages for internal projects and certain software products to minimize the risk of their development teams falling for typosquatting attacks, and to keep their code and functions secret.
Keeping private packages private is crucial for organizations using them. Otherwise, attackers can create clones or typosquatted packages that hackers could trick employees of organizations into downloading and using in software projects.
If the developers and internal software testers don’t discover the compromise, the products could reach end users, achieving a supply chain compromise.
In a report by Aqua Security’s threat research team, who shared its findings with BleepingComputer before publication, attackers are increasingly focusing on supply chain attacks, fueling a rise of 300% in associated activities in 2021.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Timing attack detailsnpm includes a registry API that allows users to download existing packages, check for the existence of packages, and receive information about all packages under a specific scope.
When using the npm registry to download a package that does not exist or is set to private, the website will return a 404 HTTP error code, indicating that the package could not be found.
https://www.bleepstatic.com/images/news/u/1220909/Website%20snaps/not-found.png
___________________________
@hacking_Attack
@Hacking_Video
New npm timing attack could lead to supply chain attacks
New npm timing attack could lead to supply chain attacksPost Views: 6 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Security researchers have discovered an npm timing attack that reveals the names of private packages so threat actors can release malicious clones publicly to trick developers into using them instead.The attack relies on a small time difference in the return of a “404 Not Found” error when searching for a private compared to a non-existent package in the repository.
While the response time difference is only a few hundred milliseconds, it is enough to determine whether a private package exists to perform package impersonation attacks.
Organizations create private packages for internal projects and certain software products to minimize the risk of their development teams falling for typosquatting attacks, and to keep their code and functions secret.
Keeping private packages private is crucial for organizations using them. Otherwise, attackers can create clones or typosquatted packages that hackers could trick employees of organizations into downloading and using in software projects.
If the developers and internal software testers don’t discover the compromise, the products could reach end users, achieving a supply chain compromise.
In a report by Aqua Security’s threat research team, who shared its findings with BleepingComputer before publication, attackers are increasingly focusing on supply chain attacks, fueling a rise of 300% in associated activities in 2021.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Timing attack detailsnpm includes a registry API that allows users to download existing packages, check for the existence of packages, and receive information about all packages under a specific scope.
When using the npm registry to download a package that does not exist or is set to private, the website will return a 404 HTTP error code, indicating that the package could not be found.
https://www.bleepstatic.com/images/news/u/1220909/Website%20snaps/not-found.png
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New npm timing attack could lead to supply chain attacks | Black Hat Ethical Hacking
Security researchers have discovered an npm timing attack that reveals the names of private packages so threat actors can release malicious clones publicly to trick developers into using them instead.