Today, we are excited to launch our Public Bug Bounty Program that allows any security researcher to submit vulnerabilities to the…Continue reading on BigEng » (https://medium.com/bigcommerce-engineering/bigcommerce-launches-a-public-bug-bounty-program-3a2332ef4434?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
BigCommerce Launches a Public Bug Bounty Program
Today, we are excited to launch our Public Bug Bounty Program that allows any security researcher to submit vulnerabilities to the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
https://external-preview.redd.it/xscleSzFGm4_4CIRg6KLp7DBcvqwkii_NyuJcwHbMJ8.jpg?width=640&crop=smart&auto=webp&s=2510752c388336c5e6d888b903e7b3d312fa62c9 submitted by /u/karimhabush
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
https://external-preview.redd.it/xscleSzFGm4_4CIRg6KLp7DBcvqwkii_NyuJcwHbMJ8.jpg?width=640&crop=smart&auto=webp&s=2510752c388336c5e6d888b903e7b3d312fa62c9 submitted by /u/karimhabush
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance...
Posted in r/hacking by u/karimhabush • 1 point and 0 comments
hacking: security in practice
any tips or wisdom you guys can share with me in regards to email analysis?
Hey guys, I wanted to practise email analysis on emails that are malicious. So far I've been using oletools, cyberchef, pestudio, and am setting up cuckoo on a VM. If anyone has any tips, free software suggestions, or even any wisdom they can bestow on me would be a huge help! I've been practicing using .msg files. Thanks for any advice/help.
submitted by /u/manooko
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
any tips or wisdom you guys can share with me in regards to email analysis?
Hey guys, I wanted to practise email analysis on emails that are malicious. So far I've been using oletools, cyberchef, pestudio, and am setting up cuckoo on a VM. If anyone has any tips, free software suggestions, or even any wisdom they can bestow on me would be a huge help! I've been practicing using .msg files. Thanks for any advice/help.
submitted by /u/manooko
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
any tips or wisdom you guys can share with me in regards to email...
Hey guys, I wanted to practise email analysis on emails that are malicious. So far I've been using oletools, cyberchef, pestudio, and am setting...
BigCommerce Launches a Public Bug Bounty Program
Today, we are excited to launch our Public Bug Bounty Program that allows any security researcher to submit vulnerabilities to the…Continue reading on BigEng »
Read more...
Today, we are excited to launch our Public Bug Bounty Program that allows any security researcher to submit vulnerabilities to the…Continue reading on BigEng »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PNPT — Exam Preparation & Experience
https://cdn-images-1.medium.com/max/600/1*yXh4400FQH9FAIOvLTLRKQ.png
What is a PNPT?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PNPT — Exam Preparation & Experience
https://cdn-images-1.medium.com/max/600/1*yXh4400FQH9FAIOvLTLRKQ.png
What is a PNPT?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PNPT — Exam Preparation & Experience
What is a PNPT?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Home Grown Red Team: Getting System On Windows 11 With Havoc C2
https://cdn-images-1.medium.com/max/672/1*4SdPPz2FNGB_Mwgv-cxzmw.png
Havoc C2 has quickly become one of my favorite open source C2s. It’s features offer everything that you need to complete a pentest or red…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Home Grown Red Team: Getting System On Windows 11 With Havoc C2
https://cdn-images-1.medium.com/max/672/1*4SdPPz2FNGB_Mwgv-cxzmw.png
Havoc C2 has quickly become one of my favorite open source C2s. It’s features offer everything that you need to complete a pentest or red…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Home Grown Red Team: Getting System On Windows 11 With Havoc C2
Havoc C2 has quickly become one of my favorite open source C2s. It’s features offer everything that you need to complete a pentest or red…
hacking: security in practice
Am I Stupid?
Hi guys. Delete if not allowed or point me in the right direction if it belongs elsewhere! I have a high amount of credit card debt due to personal bad decisions and I posted in another sub about it a while back. Since that day I’ve had someone anonymous reach out to me on Reddit and now on discord with a way to help and I’m not sure how I feel. Not sure if anyone has had experience with something like this or if it feels fishy but in simple terms this person is offering to purchase a malware that takes dormant crypto currency from dormant wallets and transfers them to theirs (or one they set up for me). They then use that crypto to make payments on my credit card accounts and eliminate the debt, after which the crypto will be used for paying off the malware purchase. Everything is telling me it’s fake and I haven’t considered it much but there is a part of me that’s curious. Does this sound possible or fishy and fraud? I’m already in debt, don’t need legal trouble and/or worse financial pain if someone steals access to my accounts.
Thanks in advance.
submitted by /u/DankyBudz31
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Am I Stupid?
Hi guys. Delete if not allowed or point me in the right direction if it belongs elsewhere! I have a high amount of credit card debt due to personal bad decisions and I posted in another sub about it a while back. Since that day I’ve had someone anonymous reach out to me on Reddit and now on discord with a way to help and I’m not sure how I feel. Not sure if anyone has had experience with something like this or if it feels fishy but in simple terms this person is offering to purchase a malware that takes dormant crypto currency from dormant wallets and transfers them to theirs (or one they set up for me). They then use that crypto to make payments on my credit card accounts and eliminate the debt, after which the crypto will be used for paying off the malware purchase. Everything is telling me it’s fake and I haven’t considered it much but there is a part of me that’s curious. Does this sound possible or fishy and fraud? I’m already in debt, don’t need legal trouble and/or worse financial pain if someone steals access to my accounts.
Thanks in advance.
submitted by /u/DankyBudz31
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Am I Stupid?
Hi guys. Delete if not allowed or point me in the right direction if it belongs elsewhere! I have a high amount of credit card debt due to...
hacking: security in practice
Is it possible to clone new phones with just a phone number?
Not trying to clone anyone’s phone. Just need to know for my own security (yes people are trying to get into my shit right now).
submitted by /u/BigSocialistCock
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to clone new phones with just a phone number?
Not trying to clone anyone’s phone. Just need to know for my own security (yes people are trying to get into my shit right now).
submitted by /u/BigSocialistCock
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to clone new phones with just a phone number?
Not trying to clone anyone’s phone. Just need to know for my own security (yes people are trying to get into my shit right now).
hacking: security in practice
Is the Emagnet software harmful?
Supposedly it’s used to pull emails and passwords from leaked databases but I don’t know if it’s a reliable source.
submitted by /u/lthorn73
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is the Emagnet software harmful?
Supposedly it’s used to pull emails and passwords from leaked databases but I don’t know if it’s a reliable source.
submitted by /u/lthorn73
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is the Emagnet software harmful?
Supposedly it’s used to pull emails and passwords from leaked databases but I don’t know if it’s a reliable source.
hacking: security in practice
Is their any community for clan system for hackers? like gamers do
Gamers have teams, clans and stuffs where they play, practice, learn together. They try strats, plays custom modes and stuffs. I wonder if there is anything like this but for hackers. No i am not talking about malicious hacking group. White hat hacking to choose a project together try to solve it together like a team.
TBH i don't have any friends with same interest, so it's kinda boring to keep going alone. And I am not seeking for competitive style. Casual, Hobby kinda community. And yes i am a kid.
submitted by /u/muza_xi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is their any community for clan system for hackers? like gamers do
Gamers have teams, clans and stuffs where they play, practice, learn together. They try strats, plays custom modes and stuffs. I wonder if there is anything like this but for hackers. No i am not talking about malicious hacking group. White hat hacking to choose a project together try to solve it together like a team.
TBH i don't have any friends with same interest, so it's kinda boring to keep going alone. And I am not seeking for competitive style. Casual, Hobby kinda community. And yes i am a kid.
submitted by /u/muza_xi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is their any community for clan system for hackers? like gamers do
Gamers have teams, clans and stuffs where they play, practice, learn together. They try strats, plays custom modes and stuffs. I wonder if there...
hacking: security in practice
Do hackers who use public WiFi can caught very often and how do they get caught?
I'm not asking about people who physically go into a place with public WiFi as there is usually camera footage etc which can be linked.
I listen to darknet diaries podcast and people often get caught from making a mistake which reveals their IP address.
If they purchased a used laptop from someone's house off Craigslist, removed the wireless adapter and camera and purchased an external USB WiFi adapter with extra long range and accessed public WiFi from a distance, say from their house or from their place of work. The computer they used never had any personal logins and no personal data on the computer and they used MAC spoofing software and or TOR. After every session they removed the laptop battery and USB WiFi adapter. What could be used here to track them, no video evidence and no personal data to track them, and if they make a mistake the only IP address that will be revealed is the public WiFI. Or even they could just hack into a weak security router in their neighbourhood. Why don't more hackers and cybercriminals use this method? Do they and they are the criminals that evade the law for longer?
submitted by /u/Invitza
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Do hackers who use public WiFi can caught very often and how do they get caught?
I'm not asking about people who physically go into a place with public WiFi as there is usually camera footage etc which can be linked.
I listen to darknet diaries podcast and people often get caught from making a mistake which reveals their IP address.
If they purchased a used laptop from someone's house off Craigslist, removed the wireless adapter and camera and purchased an external USB WiFi adapter with extra long range and accessed public WiFi from a distance, say from their house or from their place of work. The computer they used never had any personal logins and no personal data on the computer and they used MAC spoofing software and or TOR. After every session they removed the laptop battery and USB WiFi adapter. What could be used here to track them, no video evidence and no personal data to track them, and if they make a mistake the only IP address that will be revealed is the public WiFI. Or even they could just hack into a weak security router in their neighbourhood. Why don't more hackers and cybercriminals use this method? Do they and they are the criminals that evade the law for longer?
submitted by /u/Invitza
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Do hackers who use public WiFi can caught very often and how do...
I'm not asking about people who physically go into a place with public WiFi as there is usually camera footage etc which can be linked. I listen...
hacking: security in practice
Is this a bad SQL Script?
I'm a complete beginner, and have been tasked to gain access to a database through the website, I managed to do that, but I don't know what I got exactly. I'm looking for some explanations basically.
I have a web page:
User name: _ _ _ _ _ _ _ _ _ Password: _ _ _ _ _ _ _ _
One thing I can do to this webpage is add the following SQL injections:
1. leave the username empty, and move to the password filed.
2. on the password field, input this: ';SELECT * FROM members;'
members is the name of the database.
Anyway, I then submit my past, and view the raw html source (the html script)
in it, I get the names of all the users and there password, but I also see this line:
What does this mean exactly, I know behind the password field is the stuff and I inputted, but what does the line as a whole mean? Is it a username and password verification script? if yes is it weak?
submitted by /u/swiftcoderx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is this a bad SQL Script?
I'm a complete beginner, and have been tasked to gain access to a database through the website, I managed to do that, but I don't know what I got exactly. I'm looking for some explanations basically.
I have a web page:
User name: _ _ _ _ _ _ _ _ _ Password: _ _ _ _ _ _ _ _
One thing I can do to this webpage is add the following SQL injections:
1. leave the username empty, and move to the password filed.
2. on the password field, input this: ';SELECT * FROM members;'
members is the name of the database.
Anyway, I then submit my past, and view the raw html source (the html script)
in it, I get the names of all the users and there password, but I also see this line:
What does this mean exactly, I know behind the password field is the stuff and I inputted, but what does the line as a whole mean? Is it a username and password verification script? if yes is it weak?
submitted by /u/swiftcoderx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is this a bad SQL Script?
I'm a complete beginner, and have been tasked to gain access to a database through the website, I managed to do that, but I don't know what I got...
hacking: security in practice
What does ncrack read exactly?
I understand that ftp is an unsafe file transfer protocol, when I run an ncrack on the ftp ip, what's happening? I get different username and password, some of them are right and others are not? my questions are:
Why am I getting failed username and passowrd?
what does ncrack have in relations with ftp?
Here are the commands:
From this I get this:
What is actually happening here?
Thank you.
submitted by /u/swiftcoderx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What does ncrack read exactly?
I understand that ftp is an unsafe file transfer protocol, when I run an ncrack on the ftp ip, what's happening? I get different username and password, some of them are right and others are not? my questions are:
Why am I getting failed username and passowrd?
what does ncrack have in relations with ftp?
Here are the commands:
ncrack ftp://192.168.1.3/24 From this I get this:
192.168.1.2/tcp ftp: 'anonymous' '123456' 192.168.1.2/tcp ftp: 'guest' '123456' 192.168.1.2/tcp ftp: 'anonymous' '123456789' 192.168.1.2/tcp ftp: 'anonymous' 'password' 192.168.1.2/tcp ftp: 'anonymous' 'iloveyou' 192.168.1.2/tcp ftp: 'anonymous' 'princess' What is actually happening here?
Thank you.
submitted by /u/swiftcoderx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What does ncrack read exactly?
I understand that ftp is an unsafe file transfer protocol, when I run an ncrack on the ftp ip, what's happening? I get different username and...
hacking: security in practice
Will I get in legal trouble if I purchase I USB rubber ducky?
I live in Australia and have been contemplating purchasing one but don't want to get in any legal trouble or anything if I do end up buying one
submitted by /u/ilikefrogs101_dev
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Will I get in legal trouble if I purchase I USB rubber ducky?
I live in Australia and have been contemplating purchasing one but don't want to get in any legal trouble or anything if I do end up buying one
submitted by /u/ilikefrogs101_dev
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Will I get in legal trouble if I purchase I USB rubber ducky?
I live in Australia and have been contemplating purchasing one but don't want to get in any legal trouble or anything if I do end up buying one
hacking: security in practice
How does Parameterised prevent SQL Injections?
I've read that Parameterised can be used to prevent SQL injections, but not sure how, I have a web page where I used sql injections to get access into it like so :
webpage:
username: _ _ _ _ _ _ _
password: _ _ _ _ _ _ _
I got to the password field and Input the following command:
Some explained to me what this command is doing, it's essentially by passing the username and password and adding a sql injection after them, this is how it looks like on the backend.
Now, how would Parameterised Stop this SQL injection?
submitted by /u/swiftcoderx
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
How does Parameterised prevent SQL Injections?
I've read that Parameterised can be used to prevent SQL injections, but not sure how, I have a web page where I used sql injections to get access into it like so :
webpage:
username: _ _ _ _ _ _ _
password: _ _ _ _ _ _ _
I got to the password field and Input the following command:
';SELECT * FROM members;' Some explained to me what this command is doing, it's essentially by passing the username and password and adding a sql injection after them, this is how it looks like on the backend.
select members.id from members where name='' and password='';SELECT * FROM members --> Now, how would Parameterised Stop this SQL injection?
submitted by /u/swiftcoderx
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
How does Parameterised prevent SQL Injections?
I've read that Parameterised can be used to prevent SQL injections, but not sure how, I have a web page where I used sql injections to get...