Hacking Articles Tips Tricks Videos Tutorials
469 subscribers
66.4K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Metasploitable-like machines for autmatic vulnerability testing

Hey, I'm searching for metasploitable like machines for some test of OpenVas, Qualys and Nessus. I search for everything except web for web I have different plans. In mean time I search vulnhub but I didn't find anything interesting yet.

submitted by /u/TracerP
[link] [comments]
I have a small doubt about the Account takeover
https://www.reddit.com/r/Pentesting/comments/ydd5nh/i_have_a_small_doubt_about_the_account_takeover/

<!-- SC_OFF -->1) I have created a new account on some random website (domain.com (https://domain.com/)) through the signup page using email and password. After some time, I manually logged out from the account. ​ 2) Now I have tried to sign-in with the same email but using a different feature called "Login with Google" without giving any password and it took me to the same account which I have created above. ​ So I want to know if this behaviour is normal or is it considered as a valid bug ? If Yes, then what should I do to increase the severity of it ? <!-- SC_ON --> submitted by /u/SatyaKayala (https://www.reddit.com/user/SatyaKayala)
[link] (https://www.reddit.com/r/Pentesting/comments/ydd5nh/i_have_a_small_doubt_about_the_account_takeover/) [comments] (https://www.reddit.com/r/Pentesting/comments/ydd5nh/i_have_a_small_doubt_about_the_account_takeover/)
Dark Reading: Attacks/Breaches
Windows Mark of the Web Zero-Days Remain Patchless, Under Exploit

A pair of Microsoft bugs allow cyberattackers to bypass native Windows Internet download security, says former CERT CC researcher who discovered the flaws.
Dark Reading: Attacks/Breaches
Equifax's Lessons Are Still Relevant, 5 Years Later

Cybersecurity pros discuss a trio of lessons from the Equifax hack and how to prevent similar attacks in the enterprise.