Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Atlassian Vulnerabilities Highlight Criticality of Cloud Services

Two flaws in the popular developer cloud platform show how weaknesses in authorization functions and SaaS flaws can put cloud apps at risk.
This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…Continue reading on Medium » (https://medium.com/@raymond-lind/how-i-found-a-simple-stored-xss-9a6b1c5e0afa?source=rss------bug_bounty-5)
Hello fellow hackers, today I will discuss how I found a Server-Side Request Forgery (SSRF) which lead to a Local File Inclusion (LFI)…Continue reading on Medium » (https://medium.com/@raymond-lind/ssrf-lfi-in-uploads-feature-a134aa467abf?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I Found A Simple Stored XSS

https://cdn-images-1.medium.com/max/800/0*FUl-Q8zErBsZcrWz.jpeg
This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SSRF & LFI In Uploads Feature

https://cdn-images-1.medium.com/max/782/0*VPehstiqBXel6nYY.png
Hello fellow hackers, today I will discuss how I found a Server-Side Request Forgery (SSRF) which lead to a Local File Inclusion (LFI)…

Continue reading on Medium »
https://b.thumbs.redditmedia.com/gjWCNDNHrbWfye2H-13tngPTcnWQIKmSq3DrWsjIHaI.jpg When using exiftool to see the metadata from a picture, i only see this information:

https://preview.redd.it/vacdyqqcitv91.png?width=824&format=png&auto=webp&s=b96a1ff9d7032188f93b95b16fde683b73b7c20b

Meanwhile, on the forensics tutorial i am following, they ran exiftool on the same photo and they ended up with many more additional information such as image description, make and camera info, and GPS Longitude/Latitude. How can i make the program show this additional information or which commands i need to use?

submitted by /u/bugst4rr
[link] [comments]
hacking: security in practice
How do you know if you can overwrite the return address on the stack when doing buffer overflow?

I know there are times where you cannot overwrite the return address on the stack but what are those conditions? I'm just not sure when you can and cannot overwrite it? Shouldn't you always be able to overwrite the RET address?

submitted by /u/klinky8
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
https://a.thumbs.redditmedia.com/4lbj-vKRo4yqDs5PBmQjHC_YWmj3m5xetKhXYCEBnX0.jpg Got a message on IG from someone I knew about me voting for them as a brand ambassador. They sent the link and when I clicked on it, it was a human verification page and then an IG log-in. I tried logging in but it wouldn’t go through.

I let the person know and they stated that I needed to turn off my 2-factor authorization in order for it to work. (I didn’t). A few moments later, I got a notification for an attempted sign in. I denier the request and changed my password.

Is this a new way of attempting to hack or am I just over thinking it? Then again, why would they need access to my account? First time I’ve ever encountered something like this.

submitted by /u/UrartuQueen
[link] [comments]
hacking: security in practice
Timeframe to mask attack 10 character password

How long would it take to mask attack a 10 character password that includes upper/lower case letters, numbers and special characters and one of the special characters is known (not its place in the password though) using 8 rtx 4090's?

submitted by /u/theboops79
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video