Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
5000$ for Apple Stored Xss And Another Blind Xss Still under review

How I found two Xss At Apple that Lead for high/crirical impactContinue reading on Medium »
Read more...
External SSRF to Initial Access ?
https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/

Looking for ideas on how to leverage an external SSRF in order to get initial access. Background - I have a reliable SSRF on an externally facing web app, using mod_proxy vuln I have mapped internal IP space, approx 200 machines / devices. Mostly Windows env, maybe 15% misc iot devices I can access any machine inside via SSRF, but can only talk HTTP. I can port scan using http://ip:port, but not 100% reliable. Does work for ssh banner grabs though. There are a lot of printers, mostly older. brother, HP, Canon. Most with default admin passwords. I've logged in and harvested as much Intel as I can. Mostly ip space, host names, usernames from print jobs. I can't use any PRET because I only have http access. Question ... Looking for ideas on how to get code execution. Can you think of other services I should look for internally? Any techniques that might work well? submitted by /u/_actualme (https://www.reddit.com/user/_actualme)
[link] (https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/) [comments] (https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Ransomware Barrage Aimed at US Healthcare Sector, Feds Warn

A CISA advisory warns that the Daixin Team ransomware group has put the US healthcare system in its crosshairs for data extortion, and provides tools to fight back.
hacking: security in practice
Can I fool a keylogger like this?

I've adopted a habit of attempting to fool any possible keylogger on my pc. Not that I believe I have a keylogger, but just in case.

My password for a service is a random set of characters and numbers; in this example I'll use abc123xyz. What I do: I type 123 first, use the mouse to set the cursor to the beginning of the password and then type abc, then i click to the end of the password and type xyz. This way the keylogger would log a wrong password: 123abcxyz. That is if it only logs keystrokes.

I'm assuming this would fool the vast majority of keyloggers, so I'm definitely reducing my risk by a heck of a lot. Would it fool all keyloggers? Perhaps not, if there are more advanced ones.

submitted by /u/Tiikuri
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
How I Found A Simple Stored XSS

This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…Continue reading on Medium »
Read more...
SSRF & LFI In Uploads Feature

Hello fellow hackers, today I will discuss how I found a Server-Side Request Forgery (SSRF) which lead to a Local File Inclusion (LFI)…Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
IoT Fingerprinting Helps Authenticate and Secure All Those Devices

For organizations struggling to protect a rapidly expanding volume of IoT devices, IoT fingerprinting could help with security and management.
Dark Reading: Attacks/Breaches
Atlassian Vulnerabilities Highlight Criticality of Cloud Services

Two flaws in the popular developer cloud platform show how weaknesses in authorization functions and SaaS flaws can put cloud apps at risk.