В Tonic Dex мы серьезно относимся к безопасности средств пользователей.Continue reading on Medium » (https://medium.com/@Denisss./tonic-dex-partners-with-immunfi-for-bug-bounty-program-ru-b84c1b1c44b8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tonic Dex сотрудничает с ImmunFi в рамках программы “bug bounty”
В Tonic Dex мы серьезно относимся к безопасности средств пользователей. Чтобы поощрить и вознаградить ответственное раскрытие уязвимостей в…
How I Found P1 in Bugcrowd with only Recon
https://medium.com/@ittipatjitrada_72022/how-i-found-p1-in-bugcrowd-with-only-recon-56cd6a78a806?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ittipatjitrada_72022/how-i-found-p1-in-bugcrowd-with-only-recon-56cd6a78a806?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found P1 in Bugcrowd with only Recon
Tool
ToolContinue reading on Medium » (https://medium.com/@ittipatjitrada_72022/how-i-found-p1-in-bugcrowd-with-only-recon-56cd6a78a806?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found P1 in Bugcrowd with only Recon
Tool
How I bypass the OTP of a well known website.
https://medium.com/@RajneeshKarya/how-i-bypass-the-otp-of-a-well-known-website-520669e34472?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@RajneeshKarya/how-i-bypass-the-otp-of-a-well-known-website-520669e34472?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I bypass the OTP of a well known website.
Hello Learners, I am Rajneesh K. Arya again here with my new blog on OTP bypassing. So let’s check what google said about it.
Hello Learners, I am Rajneesh K. Arya again here with my new blog on OTP bypassing. So let’s check what google said about it.Continue reading on Medium » (https://medium.com/@RajneeshKarya/how-i-bypass-the-otp-of-a-well-known-website-520669e34472?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I bypass the OTP of a well known website.
Hello Learners, I am Rajneesh K. Arya again here with my new blog on OTP bypassing. So let’s check what google said about it.
How I Found P1 with Google Dork on Bugcrowd Program
https://medium.com/@ittipatjitrada_72022/how-i-found-p1-with-google-dork-on-bugcrowd-program-8d141ec049e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ittipatjitrada_72022/how-i-found-p1-with-google-dork-on-bugcrowd-program-8d141ec049e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found P1 with Google Dork on Bugcrowd Program
Tool
ToolContinue reading on Medium » (https://medium.com/@ittipatjitrada_72022/how-i-found-p1-with-google-dork-on-bugcrowd-program-8d141ec049e4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found P1 with Google Dork on Bugcrowd Program
Tool
Creating Fully Undetectable (FUD) Stager in C
https://www.reddit.com/r/redteamsec/comments/yeoif6/creating_fully_undetectable_fud_stager_in_c/
Hope you enjoyed the video and learned something new! https://youtu.be/Pu06zYUdpGs Still a lot of things to implement in order for this to be practical but I think it was fun seeing 0/26 AV detection. Feel free to improve it yourself and do it responsible, you are responsible for your own actions with that. submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://www.reddit.com/r/redteamsec/comments/yeoif6/creating_fully_undetectable_fud_stager_in_c/) [comments] (https://www.reddit.com/r/redteamsec/comments/yeoif6/creating_fully_undetectable_fud_stager_in_c/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/yeoif6/creating_fully_undetectable_fud_stager_in_c/
Hope you enjoyed the video and learned something new! https://youtu.be/Pu06zYUdpGs Still a lot of things to implement in order for this to be practical but I think it was fun seeing 0/26 AV detection. Feel free to improve it yourself and do it responsible, you are responsible for your own actions with that. submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://www.reddit.com/r/redteamsec/comments/yeoif6/creating_fully_undetectable_fud_stager_in_c/) [comments] (https://www.reddit.com/r/redteamsec/comments/yeoif6/creating_fully_undetectable_fud_stager_in_c/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit: Creating Fully Undetectable (FUD) Stager in C
Explore this post and more from the redteamsec community
How come you got into pen testing?
https://www.reddit.com/r/Pentesting/comments/yeog95/how_come_you_got_into_pen_testing/
Pen testers of Reddit, what made you get into pen testing? And what did you guys say in your interviews when the person that interviewed you asked you the reason for your job? submitted by /u/ELIDAL99 (https://www.reddit.com/user/ELIDAL99)
[link] (https://www.reddit.com/r/Pentesting/comments/yeog95/how_come_you_got_into_pen_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/yeog95/how_come_you_got_into_pen_testing/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/yeog95/how_come_you_got_into_pen_testing/
Pen testers of Reddit, what made you get into pen testing? And what did you guys say in your interviews when the person that interviewed you asked you the reason for your job? submitted by /u/ELIDAL99 (https://www.reddit.com/user/ELIDAL99)
[link] (https://www.reddit.com/r/Pentesting/comments/yeog95/how_come_you_got_into_pen_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/yeog95/how_come_you_got_into_pen_testing/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How come you got into pen testing?
Pen testers of Reddit, what made you get into pen testing? And what did you guys say in your interviews when the person that interviewed you asked...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
PartyLoud : A Simple Tool To Generate Fake Web Browsing And Mitigate Tracking
PartyLoud is a highly configurable and straightforward free tool that helps you prevent tracking directly from your linux terminal, no special skills required. Once started, you can forget it is running. It provides several flags; each flag lets you customize your experience and change PartyLoud behaviour according to your needs.
* Simple. 3 files only, no installation required, just clone this repo an you’re ready to go.
* Powerful. Thread-based navigation.
* Stealthy. Optimized to emulate user navigation.
* Portable. You can use this script on every unix-based OS. How It Works?* URLs and keywords are loaded (either from partyloud.conf and badwords or from user-defined files)
* If proxy flag has been used, proxy config will be tested
* For each URL in ULR-list a thread is started, each thread as an user agent associated
* Each thread will start by sending an HTTP request to the given URL
* The response if filtered using the keywords in order to prevent 404s and malformed URLs
* A new URL is choosen from the list generated after filering
* Current thread sleeps for a random time
* Actions from 4 to 7 are repeated using the new URL until user send kill signal (CTRL-C or enter key) Features* Configurable urls list and blocklist
* Random DNS Mode : each request is done on a different DNS Server
* Multi-threaded request engine (# of thread are equal to # of urls in partyloud.conf)
* Error recovery mechanism to protect Engines from failures
* Spoofed User Agent prevent from fingerprinting (each engine has a different user agent)
* Dynamic UI SetupClone the repository:
git clone https://github.com/realtho/PartyLoud.git
Navigate to the directory and make the script executable:
cd PartyLoud
chmod +x partyloud.sh
Run ‘partyloud’:
./partyloud.sh
Usage
Usage: ./partyloud.sh [options...]
-d --dns To stop the script press either enter or CRTL-CFile SpecificationsIn current release there is no input-validation on files.
If you find bugs or have suggestions on how to improve this features please help me by opening issues on GitHub IntroIf you don’t have special needs , default config files are just fine to get you started.
Default files are located in:
* badwords
* partyloud.conf
* DNSList
Please note that file name and extension are not important, just content of files matter badwords – Keywords-based blocklistbadwords is a keywords-based blocklist used to filter non-HTML content, images, document and so on.
The default config as been created after several weeks of testing. If you really think you need a custom blocklist, my suggestion is to start by copy and modifying default config according to your needs.
Here are some hints on how to create a great blocklist file:
DO https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png DONT https://s.w.org/images/core/emoji/14.0.0/72x72/1f6ab.png Use only ASCII charsDefine one-site-only rulesTry to keep the rules as general as possibleDefine case-sensitive rulesPrefer relative pathPlace more than one rule per line partyloud.conf – ULR Listpartyloud.conf is a ULR List used as starting point for fake navigation generators.
The[...]
___________________________
@hacking_Attack
@Hacking_Video
PartyLoud : A Simple Tool To Generate Fake Web Browsing And Mitigate Tracking
PartyLoud is a highly configurable and straightforward free tool that helps you prevent tracking directly from your linux terminal, no special skills required. Once started, you can forget it is running. It provides several flags; each flag lets you customize your experience and change PartyLoud behaviour according to your needs.
* Simple. 3 files only, no installation required, just clone this repo an you’re ready to go.
* Powerful. Thread-based navigation.
* Stealthy. Optimized to emulate user navigation.
* Portable. You can use this script on every unix-based OS. How It Works?* URLs and keywords are loaded (either from partyloud.conf and badwords or from user-defined files)
* If proxy flag has been used, proxy config will be tested
* For each URL in ULR-list a thread is started, each thread as an user agent associated
* Each thread will start by sending an HTTP request to the given URL
* The response if filtered using the keywords in order to prevent 404s and malformed URLs
* A new URL is choosen from the list generated after filering
* Current thread sleeps for a random time
* Actions from 4 to 7 are repeated using the new URL until user send kill signal (CTRL-C or enter key) Features* Configurable urls list and blocklist
* Random DNS Mode : each request is done on a different DNS Server
* Multi-threaded request engine (# of thread are equal to # of urls in partyloud.conf)
* Error recovery mechanism to protect Engines from failures
* Spoofed User Agent prevent from fingerprinting (each engine has a different user agent)
* Dynamic UI SetupClone the repository:
git clone https://github.com/realtho/PartyLoud.git
Navigate to the directory and make the script executable:
cd PartyLoud
chmod +x partyloud.sh
Run ‘partyloud’:
./partyloud.sh
Usage
Usage: ./partyloud.sh [options...]
-d --dns To stop the script press either enter or CRTL-CFile SpecificationsIn current release there is no input-validation on files.
If you find bugs or have suggestions on how to improve this features please help me by opening issues on GitHub IntroIf you don’t have special needs , default config files are just fine to get you started.
Default files are located in:
* badwords
* partyloud.conf
* DNSList
Please note that file name and extension are not important, just content of files matter badwords – Keywords-based blocklistbadwords is a keywords-based blocklist used to filter non-HTML content, images, document and so on.
The default config as been created after several weeks of testing. If you really think you need a custom blocklist, my suggestion is to start by copy and modifying default config according to your needs.
Here are some hints on how to create a great blocklist file:
DO https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png DONT https://s.w.org/images/core/emoji/14.0.0/72x72/1f6ab.png Use only ASCII charsDefine one-site-only rulesTry to keep the rules as general as possibleDefine case-sensitive rulesPrefer relative pathPlace more than one rule per line partyloud.conf – ULR Listpartyloud.conf is a ULR List used as starting point for fake navigation generators.
The[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
PartyLoud : A Tool To Generate Fake Web Browsing & Mitigate Tracking
PartyLoud is a highly configurable and straightforward free tool that helps you prevent tracking directly from your linux terminal
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials PartyLoud : A Simple Tool To Generate Fake Web Browsing And Mitigate Tracking PartyLoud is a highly configurable and straightforward free tool that helps you prevent tracking directly from your linux terminal, no special skills required.…
goal here is to create a good list of sites containing a lot of URLs.
Aside suggesting you not to use google, youtube and social networks related links, I’ve really no hints for you. Note #1 – To work properly the URLs must be well-formed Note #2 – Even if the file contains 1000 lines only 10 are used (first 10, working on randomness) Note #3 – Only one URL per line is allowed DNSList – DNS ListDNSList is a List of DNS used as argument for random DNS feature. Random DNS is not enable by default, so the “default file” is really just a guide line and a test used while developing the function to se if everything was working as expected.
The only suggestion here is to add as much address as possible to increase randomness. Note #1 – Only one address per line is allowed FAQIsn’t this literally just a cli based frontend to curl?
How does the error recovery mechanism work?
May I fork your project? How easy is this fake traffic to detect?
What does badwords do?
What does partyloud.conf do?
partyloud.conf is just a list of root urls used to start the fake navigation. You can create your own conf file, but pay attention that the more urls you add, the more threads you start. This is an “open issue”. Upcoming releases will come with a max thread number in order to avoid Fork Bombs. Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video
Aside suggesting you not to use google, youtube and social networks related links, I’ve really no hints for you. Note #1 – To work properly the URLs must be well-formed Note #2 – Even if the file contains 1000 lines only 10 are used (first 10, working on randomness) Note #3 – Only one URL per line is allowed DNSList – DNS ListDNSList is a List of DNS used as argument for random DNS feature. Random DNS is not enable by default, so the “default file” is really just a guide line and a test used while developing the function to se if everything was working as expected.
The only suggestion here is to add as much address as possible to increase randomness. Note #1 – Only one address per line is allowed FAQIsn’t this literally just a cli based frontend to curl?
How does the error recovery mechanism work?
May I fork your project? How easy is this fake traffic to detect?
What does badwords do?
What does partyloud.conf do?
partyloud.conf is just a list of root urls used to start the fake navigation. You can create your own conf file, but pay attention that the more urls you add, the more threads you start. This is an “open issue”. Upcoming releases will come with a max thread number in order to avoid Fork Bombs. Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video
The Best Vulnerability Disclosure Programs (Less Competitive Bounties)
https://grahamzemel.medium.com/the-best-vulnerability-disclosure-programs-less-competitive-bounties-a166acbbbd1b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://grahamzemel.medium.com/the-best-vulnerability-disclosure-programs-less-competitive-bounties-a166acbbbd1b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Best Vulnerability Disclosure Programs (Less Competitive Bounties)
TL;DR- There’s a ton of programs for bug bounties and vulnerability disclosure, but they’re usually filled with competition because they’re…
TL;DR- There’s a ton of programs for bug bounties and vulnerability disclosure, but they’re usually filled with competition because…Continue reading on Medium » (https://grahamzemel.medium.com/the-best-vulnerability-disclosure-programs-less-competitive-bounties-a166acbbbd1b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Best Vulnerability Disclosure Programs (Less Competitive Bounties)
TL;DR- There’s a ton of programs for bug bounties and vulnerability disclosure, but they’re usually filled with competition because they’re…