Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Microsoft Data-Exposure Incident Highlights Risk of Cloud Storage Misconfiguration

Many enterprises continue to leave cloud storage buckets exposed despite widely available documentation on how to properly secure them.
Dark Reading: Attacks/Breaches
8 Trends Driving Cybersecurity in the Public Sector

CISOs and security leaders in state and local governments are dealing with increasing threats like ransomware — with varying degrees of cyber maturity.
hacking: security in practice
Curious on possibilities of changing variables on a video game's web application, in the console section of devtools

Hi there, am not a hacker here, or particularly crazy with computer skills, however something has recently got me interested. The game "Fifa", has a web application which users can access their accounts on. On this web app, their is set caps to certain things, for example the max number of squads you can have or players you can list etc, I'm sure you get the gist even if you dont know the context of these actions. There is a popular exploit going around where you can change the value of one of these variables. You go to console and type
services.User.maxAllowedAuctions=1000
This now works and has minor benefits, you have whatever number of "maxallowedauctions", until of course you refresh the page. I have spent some time going through some of the functions you can execute in console and have found a few more relevant variables and such, but none of major advantage.

Not 100% sure what exactly i'm asking here, just curious as to what you guys think and is it worth continuing to experiment or any tips. Thank you.

submitted by /u/Ben_Mag11
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Found large Australian news corp API & SSO Keys

I’m new to the world of pen testing & bug bounty so don’t mind my noob questions.

I was doing a lil experimental check on some large news corps in Australia and I came across a News Corp’s API & SSO key.

I’m just wondering how much of a security risk is this for that News Corp?

Should I report it to them or is there different types/layers of API & SSO keys?

Apologies again for the noobness.

submitted by /u/WhyteElk
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
How to get experience with cobalt strike
https://www.reddit.com/r/redteamsec/comments/y9go2b/how_to_get_experience_with_cobalt_strike/

How are you realistically supposed to use cobalt strike in training scenarios and get familiar with it? Buy a personal license? Does work have to help you out there or just practice on the job? Also, how illegal is it to own the cracked version for home lab use? submitted by /u/knock_on_wood_yall (https://www.reddit.com/user/knock_on_wood_yall)
[link] (https://www.reddit.com/r/redteamsec/comments/y9go2b/how_to_get_experience_with_cobalt_strike/) [comments] (https://www.reddit.com/r/redteamsec/comments/y9go2b/how_to_get_experience_with_cobalt_strike/)

___________________________
@hacking_Attack
@Hacking_Video