Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF — Web-Header-Modification: Header #3
https://cdn-images-1.medium.com/max/600/1*KJy7jG5fuRSbh1LQNAfxUA.png
Header #3 takes me back to my X-Forwarded-For attacks in previous challenges simply asking to find more. This time I wrote the following…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF — Web-Header-Modification: Header #3
https://cdn-images-1.medium.com/max/600/1*KJy7jG5fuRSbh1LQNAfxUA.png
Header #3 takes me back to my X-Forwarded-For attacks in previous challenges simply asking to find more. This time I wrote the following…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF 2023 — Web-Header-Modification: Header #3
Header #3 takes me back to my X-Forwarded-For attacks in previous challenges simply asking to find more. This time I wrote the following…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF — Web: Screenshot 9000
https://cdn-images-1.medium.com/max/600/1*nHYOsXiLcIshQNBgmrbNew.png
This time around it seems like the screenshot tool has a specific allow list that it can target and it’s a safe bet that the many…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF — Web: Screenshot 9000
https://cdn-images-1.medium.com/max/600/1*nHYOsXiLcIshQNBgmrbNew.png
This time around it seems like the screenshot tool has a specific allow list that it can target and it’s a safe bet that the many…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF — Web: Screenshot 9000
This time around it seems like the screenshot tool has a specific allow list that it can target and it’s a safe bet that the many…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF 2023 — Web-Header-Modification: Header #1
https://cdn-images-1.medium.com/max/600/1*rgS5V6i4c02B7krh_BIGdw.png
For this challenge, I used Burp Suite CE instead of the built in browser dev tools. I started off by examining the request and response…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF 2023 — Web-Header-Modification: Header #1
https://cdn-images-1.medium.com/max/600/1*rgS5V6i4c02B7krh_BIGdw.png
For this challenge, I used Burp Suite CE instead of the built in browser dev tools. I started off by examining the request and response…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF— Web-Header-Modification: Header #1
For this challenge, I used Burp Suite CE instead of the built in browser dev tools. I started off by examining the request and response…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF — Stego: Precise Pixels
https://cdn-images-1.medium.com/max/600/1*HNCA3hqiYXQHg7l3n8zgcA.png
For this challenge, the provided .bmp file can be opened in Photoshop/GIMP where I can adjust different qualities of the image. In this…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF — Stego: Precise Pixels
https://cdn-images-1.medium.com/max/600/1*HNCA3hqiYXQHg7l3n8zgcA.png
For this challenge, the provided .bmp file can be opened in Photoshop/GIMP where I can adjust different qualities of the image. In this…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF — Stego: Precise Pixels
For this challenge, the provided .bmp file can be opened in Photoshop/GIMP where I can adjust different qualities of the image. In this…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF — Web: Magic
https://cdn-images-1.medium.com/max/600/1*Psg6emL5TEIlrZ4xlGJURQ.png
The web application at the provide link provides an input for the password, a submit button and a link to the code of the back end…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF — Web: Magic
https://cdn-images-1.medium.com/max/600/1*Psg6emL5TEIlrZ4xlGJURQ.png
The web application at the provide link provides an input for the password, a submit button and a link to the code of the back end…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF — Web: Magic
The web application at the provide link provides an input for the password, a submit button and a link to the code of the back end…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF — Web-Header-Modification: As Fast As You Can
https://cdn-images-1.medium.com/max/600/1*XGqZ4efT3Nj4s8dkUAp9nA.png
For this challenge, I’m presented with a web app that has an input field, submit button, and the instructions to “Decode as fast as you…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF — Web-Header-Modification: As Fast As You Can
https://cdn-images-1.medium.com/max/600/1*XGqZ4efT3Nj4s8dkUAp9nA.png
For this challenge, I’m presented with a web app that has an input field, submit button, and the instructions to “Decode as fast as you…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF 2023— Web-Header-Modification: As Fast As You Can
For this challenge, I’m presented with a web app that has an input field, submit button, and the instructions to “Decode as fast as you…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF — Web: Screenshot 2
https://cdn-images-1.medium.com/max/600/1*jAHVgYyOswcWPAm1Bf_xVA.png
The next iteration of the screenshot challenge explains that the developers added some controls to prevent me from telling the server to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF — Web: Screenshot 2
https://cdn-images-1.medium.com/max/600/1*jAHVgYyOswcWPAm1Bf_xVA.png
The next iteration of the screenshot challenge explains that the developers added some controls to prevent me from telling the server to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF — Web: Screenshot 2
The next iteration of the screenshot challenge explains that the developers added some controls to prevent me from telling the server to…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal CTF — Web: Open Book
https://cdn-images-1.medium.com/max/600/1*fEGcIpceno6bEUCtahIAwA.png
For this challenge, the web application at the provided link simply presents some text and loads a picture of cute sleeping cat. After…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal CTF — Web: Open Book
https://cdn-images-1.medium.com/max/600/1*fEGcIpceno6bEUCtahIAwA.png
For this challenge, the web application at the provided link simply presents some text and loads a picture of cute sleeping cat. After…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal CTF — Web: Open Book
For this challenge, the web application at the provided link simply presents some text and loads a picture of cute sleeping cat. After…
A $500+ Open Redirect Bounty in Under 10 Minutes
https://grahamzemel.medium.com/a-500-open-redirect-bounty-in-under-10-minutes-fbb1cce063e5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://grahamzemel.medium.com/a-500-open-redirect-bounty-in-under-10-minutes-fbb1cce063e5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
A $500+ Open Redirect Bounty in Under 10 Minutes
This post is a quick guide on how to utilize the Open Redirect bug on any sites you test, including a real-world step-by-step.
This post is a quick guide on how to utilize the Open Redirect bug on any sites you test, including a real-world step-by-step.Continue reading on Medium » (https://grahamzemel.medium.com/a-500-open-redirect-bounty-in-under-10-minutes-fbb1cce063e5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
A $500+ Open Redirect Bounty in Under 10 Minutes
This post is a quick guide on how to utilize the Open Redirect bug on any sites you test, including a real-world step-by-step.
Facebook SMS Captcha Was Vulnerable to CSRF Attack
https://lokeshdlk77.medium.com/facebook-sms-captcha-was-vulnerable-to-csrf-attack-8db537b1e980?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://lokeshdlk77.medium.com/facebook-sms-captcha-was-vulnerable-to-csrf-attack-8db537b1e980?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Facebook SMS Captcha Was Vulnerable to CSRF Attack
This post is about an bug that I found on Meta (aka Facebook) which allows to make any Endpoint as POST request in SMS Captcha flow which…
This post is about an bug that I found on Meta (aka Facebook) which allows to make any Endpoint as POST request in SMS Captcha flow which…Continue reading on Medium » (https://lokeshdlk77.medium.com/facebook-sms-captcha-was-vulnerable-to-csrf-attack-8db537b1e980?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Facebook SMS Captcha Was Vulnerable to CSRF Attack
This post is about an bug that I found on Meta (aka Facebook) which allows to make any Endpoint as POST request in SMS Captcha flow which…
Kali Linux Tutorials
HSTP – Simple Hyper Service Transfer Protocol On Networks
HSTP protocol aims to develop a application layer abstraction for the Hyper Service Transfer Protocol.
HSTP is a recursion as nature of HSTP. This protocol implements itself as a interface. On every internet connected device, there is a HSTP instance. That's why the adoption is not needed. HSTP already running top of the internet. We have just now achieved to explain the protocol over protocols on heterogeneous networks. That's why do not compare with web2, web3 or vice versa AbstractHSTP is a application representation interface for heterogeneous networks.
HSTP interface enforces to implement a set of methods to be able to communicate with other nodes in the network. Thus serves, clients, and other nodes can communicate with each other with trust based, end to end encrypted way. By the time the node resolution is based on fastest path resolution algorithm I wrote.
A small overview
Think about, we’re in the situation of one mother and one father lives a happy life. They had a baby! Suddenly, the mother needed to drink pills regularly to cure a disase. The pill is a poison for the baby. The baby is crying and the mother calls father because he is the only trusted person to help the baby. But the father sometime can not stay at home, he needs to do something to feed the baby. Father heard one milkman has fresh and high quality milks for low price. Father decides to try to talk the milkman, milkman deliver the milk to the father, father carry the milk to the mother. Mother give the milk to the baby. Baby is happy now and the baby sleeps, mother see the baby is happy.
The family never buy the milk from outside, this is the first time they buy milk for the baby: (Mom do not know the number of milkman, milkman do not know the home address)
So, it’s easy right? It’s so simple to understand, who are those people in the story?
* Baby is a client.
* Mom i[...]
___________________________
@hacking_Attack
@Hacking_Video
HSTP – Simple Hyper Service Transfer Protocol On Networks
HSTP protocol aims to develop a application layer abstraction for the Hyper Service Transfer Protocol.
HSTP is a recursion as nature of HSTP. This protocol implements itself as a interface. On every internet connected device, there is a HSTP instance. That's why the adoption is not needed. HSTP already running top of the internet. We have just now achieved to explain the protocol over protocols on heterogeneous networks. That's why do not compare with web2, web3 or vice versa AbstractHSTP is a application representation interface for heterogeneous networks.
HSTP interface enforces to implement a set of methods to be able to communicate with other nodes in the network. Thus serves, clients, and other nodes can communicate with each other with trust based, end to end encrypted way. By the time the node resolution is based on fastest path resolution algorithm I wrote.
A small overview
Think about, we’re in the situation of one mother and one father lives a happy life. They had a baby! Suddenly, the mother needed to drink pills regularly to cure a disase. The pill is a poison for the baby. The baby is crying and the mother calls father because he is the only trusted person to help the baby. But the father sometime can not stay at home, he needs to do something to feed the baby. Father heard one milkman has fresh and high quality milks for low price. Father decides to try to talk the milkman, milkman deliver the milk to the father, father carry the milk to the mother. Mother give the milk to the baby. Baby is happy now and the baby sleeps, mother see the baby is happy.
The family never buy the milk from outside, this is the first time they buy milk for the baby: (Mom do not know the number of milkman, milkman do not know the home address)
As steps:
0) - Baby wants to drink milk.
1) - Baby cries to the mom.
3) - Mom see the baby is crying.
4) - Mom checks the fridge. Mom sees the milk is empty. (Mother is only trusting the Father)
5) - Mom calls the father.
6) - Father calls the milkman.
7) - Milkman delivers the milk to father.
8) - Father delivers the milk to mom.
9) - Mom gives the milk to the baby.
10) - Baby drinks the milk.
11) - Baby is happy.
12) - Baby sleeps.
13) - Mother see the baby is happy and sleeps.
14) - In order to be able to contact the milkman again, the mother asks the father to tell her that she wants the milkman to save the address of the house and the mobile phone of the mother.
15) - Mother calls the father.
16) - Father calls the milkman.
17) - Milkman saves the address of the house and the mobile phone of the mother.
Oops, tomorrow baby wakes up and cries again,
0) - Baby wants to drink milk.
1) - Baby cries to the mom.
2) - Mom see the baby is crying.
3) - Mom checks the fridge. Mom sees the milk is empty. (Mother is trusting the Father had right decision in the first place by giving the address to the milkman, and the milkman had right decision in the first place by saving the address of the house and the mobile phone of the mother.)
4) - Mother calls the milkman (Mother is trusting the Father's decision only)
5) - Milkman delivers the milk to mom.
6) - Mom gives the milk to the baby.
7) - Baby drinks the milk.
8) - Baby is happy.
9) - Baby sleeps.
10) - Mother see the baby is happy and sleeps.
11) - Mother is happy and the mother trust the milkman now. This document you’re reading is a manifest for the internet people to connecting the other people by trusting the service serve the client and the trust only can be maintainable by providing good services. trust is the key, but not enough for survive. the service has to be reliable, consistent, cheap. unless the people will decide to not ask from you again.So, it’s easy right? It’s so simple to understand, who are those people in the story?
* Baby is a client.
* Mom i[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
HSTP : Simple Hyper Service Transfer Protocol On Networks
HSTP protocol aims to develop a application layer abstraction for the Hyper Service Transfer Protocol. HSTP is a recursion