5000$ for Apple Stored Xss And Another Blind Xss Still under review
How I found two Xss At Apple that Lead for high/crirical impactContinue reading on Medium »
Read more...
How I found two Xss At Apple that Lead for high/crirical impactContinue reading on Medium »
Read more...
External SSRF to Initial Access ?
https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/
Looking for ideas on how to leverage an external SSRF in order to get initial access. Background - I have a reliable SSRF on an externally facing web app, using mod_proxy vuln I have mapped internal IP space, approx 200 machines / devices. Mostly Windows env, maybe 15% misc iot devices I can access any machine inside via SSRF, but can only talk HTTP. I can port scan using http://ip:port, but not 100% reliable. Does work for ssh banner grabs though. There are a lot of printers, mostly older. brother, HP, Canon. Most with default admin passwords. I've logged in and harvested as much Intel as I can. Mostly ip space, host names, usernames from print jobs. I can't use any PRET because I only have http access. Question ... Looking for ideas on how to get code execution. Can you think of other services I should look for internally? Any techniques that might work well? submitted by /u/_actualme (https://www.reddit.com/user/_actualme)
[link] (https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/) [comments] (https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/
Looking for ideas on how to leverage an external SSRF in order to get initial access. Background - I have a reliable SSRF on an externally facing web app, using mod_proxy vuln I have mapped internal IP space, approx 200 machines / devices. Mostly Windows env, maybe 15% misc iot devices I can access any machine inside via SSRF, but can only talk HTTP. I can port scan using http://ip:port, but not 100% reliable. Does work for ssh banner grabs though. There are a lot of printers, mostly older. brother, HP, Canon. Most with default admin passwords. I've logged in and harvested as much Intel as I can. Mostly ip space, host names, usernames from print jobs. I can't use any PRET because I only have http access. Question ... Looking for ideas on how to get code execution. Can you think of other services I should look for internally? Any techniques that might work well? submitted by /u/_actualme (https://www.reddit.com/user/_actualme)
[link] (https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/) [comments] (https://www.reddit.com/r/Pentesting/comments/ycgyhx/external_ssrf_to_initial_access/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
External SSRF to Initial Access ?
Looking for ideas on how to leverage an external SSRF in order to get initial access. Background - I have a reliable SSRF on an externally...
Dark Reading: Attacks/Breaches
Godspeed Capital-Backed SilverEdge Partners with Counter Threat Solutions
Affiliation adds new all-source and counterintelligence, cyber, software development, and identity intelligence capabilities to SilverEdge's growing suite of technology solutions focused on the US intelligence community.
___________________________
@hacking_Attack
@Hacking_Video
Godspeed Capital-Backed SilverEdge Partners with Counter Threat Solutions
Affiliation adds new all-source and counterintelligence, cyber, software development, and identity intelligence capabilities to SilverEdge's growing suite of technology solutions focused on the US intelligence community.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Godspeed Capital-Backed SilverEdge Partners with Counter Threat Solutions
Affiliation adds new all-source and counterintelligence, cyber, software development, and identity intelligence capabilities to SilverEdge's growing suite of technology solutions focused on the US intelligence community.
Dark Reading: Attacks/Breaches
Uptycs Introduces Detections that Correlate Threat Activity from the Kubernetes Control Plane and Container Runtime
Comprehensive CNAPP coverage for Kubernetes and containers in a single solution.
___________________________
@hacking_Attack
@Hacking_Video
Uptycs Introduces Detections that Correlate Threat Activity from the Kubernetes Control Plane and Container Runtime
Comprehensive CNAPP coverage for Kubernetes and containers in a single solution.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Uptycs Introduces Detections that Correlate Threat Activity from the Kubernetes Control Plane and Container Runtime
Comprehensive CNAPP coverage for Kubernetes and containers in a single solution.
Legitimate RATs: a comprehensive forensic analysis of the usual suspects
https://www.reddit.com/r/redteamsec/comments/yciphw/legitimate_rats_a_comprehensive_forensic_analysis/
submitted by /u/warm_kitchenette (https://www.reddit.com/user/warm_kitchenette)
[link] (https://www.synacktiv.com/publications/legitimate-rats-a-comprehensive-forensic-analysis-of-the-usual-suspects.html) [comments] (https://www.reddit.com/r/redteamsec/comments/yciphw/legitimate_rats_a_comprehensive_forensic_analysis/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/yciphw/legitimate_rats_a_comprehensive_forensic_analysis/
submitted by /u/warm_kitchenette (https://www.reddit.com/user/warm_kitchenette)
[link] (https://www.synacktiv.com/publications/legitimate-rats-a-comprehensive-forensic-analysis-of-the-usual-suspects.html) [comments] (https://www.reddit.com/r/redteamsec/comments/yciphw/legitimate_rats_a_comprehensive_forensic_analysis/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Legitimate RATs: a comprehensive forensic analysis of the usual...
Posted in r/redteamsec by u/warm_kitchenette • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackers leak 37GB of Microsoft source code.
https://cdn-images-1.medium.com/max/1024/0*KPqoMMWE8CbL77Gl.jpg
Hackers leak 37GB of Microsoft source code
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers leak 37GB of Microsoft source code.
https://cdn-images-1.medium.com/max/1024/0*KPqoMMWE8CbL77Gl.jpg
Hackers leak 37GB of Microsoft source code
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers leak 37GB of Microsoft source code.
Hackers leak 37GB of Microsoft source code
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OverTheWire Wargames: Bandit L04
https://cdn-images-1.medium.com/max/2600/1*0sMNoLVUxEU_qolwzigITg.jpeg
Bandit Level 4 write-up
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OverTheWire Wargames: Bandit L04
https://cdn-images-1.medium.com/max/2600/1*0sMNoLVUxEU_qolwzigITg.jpeg
Bandit Level 4 write-up
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OverTheWire Wargames: Bandit L04
Bandit Level 4 write-up
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
JACK
https://cdn-images-1.medium.com/max/1920/1*F_TTUyoBHAOLqtjthYpCdQ.png
Compromise a web server running Wordpress, obtain a low privileged user and escalate your privileges to root using a Python module.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
JACK
https://cdn-images-1.medium.com/max/1920/1*F_TTUyoBHAOLqtjthYpCdQ.png
Compromise a web server running Wordpress, obtain a low privileged user and escalate your privileges to root using a Python module.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
JACK
Compromise a web server running Wordpress, obtain a low privileged user and escalate your privileges to root using a Python module.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Incredible World of Crypto Lending
https://cdn-images-1.medium.com/max/1920/1*GkuHwISFDAiXZjkZ5ie0rw.jpeg
Gambler Analogy
Continue reading on CARRE4 »
___________________________
@hacking_Attack
@Hacking_Video
The Incredible World of Crypto Lending
https://cdn-images-1.medium.com/max/1920/1*GkuHwISFDAiXZjkZ5ie0rw.jpeg
Gambler Analogy
Continue reading on CARRE4 »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Incredible World of Crypto Lending
Gambler Analogy
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CISA advierte sobre piratas informáticos de Daixin dirigidos a organizaciones de salud con…
https://cdn-images-1.medium.com/max/1627/0*GB34inoRm_h_uQkG
Las agencias de ciberseguridad e inteligencia de EE.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CISA advierte sobre piratas informáticos de Daixin dirigidos a organizaciones de salud con…
https://cdn-images-1.medium.com/max/1627/0*GB34inoRm_h_uQkG
Las agencias de ciberseguridad e inteligencia de EE.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CISA advierte sobre piratas informáticos de Daixin dirigidos a organizaciones de salud con ransomware
Las agencias de ciberseguridad e inteligencia de EE. UU. publicaron una advertencia conjunta sobre los ataques perpetrados por una pandilla…
hacking: security in practice
Can I fool a keylogger like this?
I've adopted a habit of attempting to fool any possible keylogger on my pc. Not that I believe I have a keylogger, but just in case.
My password for a service is a random set of characters and numbers; in this example I'll use abc123xyz. What I do: I type 123 first, use the mouse to set the cursor to the beginning of the password and then type abc, then i click to the end of the password and type xyz. This way the keylogger would log a wrong password: 123abcxyz. That is if it only logs keystrokes.
I'm assuming this would fool the vast majority of keyloggers, so I'm definitely reducing my risk by a heck of a lot. Would it fool all keyloggers? Perhaps not, if there are more advanced ones.
submitted by /u/Tiikuri
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can I fool a keylogger like this?
I've adopted a habit of attempting to fool any possible keylogger on my pc. Not that I believe I have a keylogger, but just in case.
My password for a service is a random set of characters and numbers; in this example I'll use abc123xyz. What I do: I type 123 first, use the mouse to set the cursor to the beginning of the password and then type abc, then i click to the end of the password and type xyz. This way the keylogger would log a wrong password: 123abcxyz. That is if it only logs keystrokes.
I'm assuming this would fool the vast majority of keyloggers, so I'm definitely reducing my risk by a heck of a lot. Would it fool all keyloggers? Perhaps not, if there are more advanced ones.
submitted by /u/Tiikuri
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can I fool a keylogger like this?
I've adopted a habit of attempting to fool any possible keylogger on my pc. Not that I believe I have a keylogger, but just in case. My password...
How I Found A Simple Stored XSS
This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…Continue reading on Medium »
Read more...
This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…Continue reading on Medium »
Read more...
SSRF & LFI In Uploads Feature
Hello fellow hackers, today I will discuss how I found a Server-Side Request Forgery (SSRF) which lead to a Local File Inclusion (LFI)…Continue reading on Medium »
Read more...
Hello fellow hackers, today I will discuss how I found a Server-Side Request Forgery (SSRF) which lead to a Local File Inclusion (LFI)…Continue reading on Medium »
Read more...