TL;DR- In my experience, the easiest bounties are fuzzing/leaked file ones, and all it takes is a few clicks of an automated tool to make…Continue reading on The Gray Area » (https://medium.com/the-gray-area/a-250-entirely-automated-leaked-file-bug-bounty-14455c5457d0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
A $250 Entirely Automated Leaked File Bug Bounty
TL;DR- In my experience, the easiest bounties are fuzzing/leaked file ones, and all it takes is a few clicks of an automated tool to make…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pivoting and Tunneling for OSCP and beyond (Cheat Sheet)
https://cdn-images-1.medium.com/max/871/1*UCU9LVDA479HLKjXqAlU1Q.png
This is a cheat sheet for pivoting and tunneling using many common tools.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pivoting and Tunneling for OSCP and beyond (Cheat Sheet)
https://cdn-images-1.medium.com/max/871/1*UCU9LVDA479HLKjXqAlU1Q.png
This is a cheat sheet for pivoting and tunneling using many common tools.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pivoting and Tunneling for OSCP and beyond (Cheat Sheet)
This is a cheat sheet for pivoting and tunneling using many common tools.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Latest and Greatest Hacking Tool Of 2022
https://cdn-images-1.medium.com/max/640/1*5vfF1QvVQRrIIuIUFPbkNQ.jpeg
TL;DR- One of the best tools that’s just come out in 2022 is quickly gaining popularity, and it’s hacker fanbase is going nuts for it.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
The Latest and Greatest Hacking Tool Of 2022
https://cdn-images-1.medium.com/max/640/1*5vfF1QvVQRrIIuIUFPbkNQ.jpeg
TL;DR- One of the best tools that’s just come out in 2022 is quickly gaining popularity, and it’s hacker fanbase is going nuts for it.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Latest and Greatest Hacking Tool Of 2022
TL;DR- One of the best tools that’s just come out in 2022 is quickly gaining popularity, and it’s hacker fanbase is going nuts for it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
IBM ကပေးတဲ့Hacking CertificateကိုFreeဘယ်လိုယူမလည်း
https://cdn-images-1.medium.com/max/960/1*E4NfYebK0fRXCJ4Xa3VeGA.png
Cybersecurity လောကမှာ Certificate တွေကမိမိရဲ့စွမ်းရည်နဲ့ သင်ကြားလိုစိတ်ကိုပြသနိုင်ပေမယ့် လက်မှတ်တွေသက်သက်ကလည်း…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
IBM ကပေးတဲ့Hacking CertificateကိုFreeဘယ်လိုယူမလည်း
https://cdn-images-1.medium.com/max/960/1*E4NfYebK0fRXCJ4Xa3VeGA.png
Cybersecurity လောကမှာ Certificate တွေကမိမိရဲ့စွမ်းရည်နဲ့ သင်ကြားလိုစိတ်ကိုပြသနိုင်ပေမယ့် လက်မှတ်တွေသက်သက်ကလည်း…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
IBM ကပေးတဲ့Hacking CertificateကိုFreeဘယ်လိုယူမလည်း
Cybersecurity လောကမှာ Certificate တွေကမိမိရဲ့စွမ်းရည်နဲ့ သင်ကြားလိုစိတ်ကိုပြသနိုင်ပေမယ့် လက်မှတ်တွေသက်သက်ကလည်း…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
The Secrets Behind Uber's Breach
https://external-preview.redd.it/0w4dxbLmEHcBvxSQmTPczOkw996LRvstn3zEDiXe9M8.jpg?width=640&crop=smart&auto=webp&s=12dd9b73ace95d5c3e17871a53cb8b708cf7716c submitted by /u/leafytx
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
The Secrets Behind Uber's Breach
https://external-preview.redd.it/0w4dxbLmEHcBvxSQmTPczOkw996LRvstn3zEDiXe9M8.jpg?width=640&crop=smart&auto=webp&s=12dd9b73ace95d5c3e17871a53cb8b708cf7716c submitted by /u/leafytx
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Secrets Behind Uber's Breach
Posted in r/hacking by u/leafytx • 96 points and 5 comments
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
https://medium.com/@whitehatcyber404/how-to-find-escalating-html-to-ssrf-i-instantly-got-the-hof-within-5minutes-805f173c34e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@whitehatcyber404/how-to-find-escalating-html-to-ssrf-i-instantly-got-the-hof-within-5minutes-805f173c34e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
Server Side Request Forgery through Html Injection:
Server Side Request Forgery through Html Injection:Continue reading on Medium » (https://medium.com/@whitehatcyber404/how-to-find-escalating-html-to-ssrf-i-instantly-got-the-hof-within-5minutes-805f173c34e4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
Server Side Request Forgery through Html Injection:
How to Find Escalating HTML to SSRF. I instantly got the HOF within 5minutes.
Server Side Request Forgery through Html Injection:Continue reading on Medium »
Read more...
Server Side Request Forgery through Html Injection:Continue reading on Medium »
Read more...
2FA Bypass due to information disclosure & Improper access control.
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Become an Ethical Hacker for Beginners?
https://cdn-images-1.medium.com/max/1536/0*YFSEVTIOUBqUNd3s.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Become an Ethical Hacker for Beginners?
https://cdn-images-1.medium.com/max/1536/0*YFSEVTIOUBqUNd3s.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Become an Ethical Hacker for Beginners?
Many individuals are interested in hacking because of their excellent computer knowledge, but they don’t give it a try because they think it is illegal. Yes, hacking is illegal, but there is a type…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Endpoint Security Service In Singapore
https://cdn-images-1.medium.com/max/820/0*K-FORZrzMnR3crxa.jpg
Endpoint Security Service In Singapore
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Endpoint Security Service In Singapore
https://cdn-images-1.medium.com/max/820/0*K-FORZrzMnR3crxa.jpg
Endpoint Security Service In Singapore
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Endpoint Security Service In Singapore
Endpoint Security Service In Singapore
hacking: security in practice
How to identify who clicks my link?
I have this Bitly link; all I can see is how many times my link visited, at what time, and from what country.
What I would like is to know more. What's its approximate location or better? Like what browser he/she is using. Is it the same person who clicked before? Or what were his/her engagements before, did he/she visited an online store? How can I do this? I believe it is possible and it is legal since it is what google does, but how?
submitted by /u/Shnxx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to identify who clicks my link?
I have this Bitly link; all I can see is how many times my link visited, at what time, and from what country.
What I would like is to know more. What's its approximate location or better? Like what browser he/she is using. Is it the same person who clicked before? Or what were his/her engagements before, did he/she visited an online store? How can I do this? I believe it is possible and it is legal since it is what google does, but how?
submitted by /u/Shnxx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to identify who clicks my link?
I have this Bitly link; all I can see is how many times my link visited, at what time, and from what country. What I would like is to know more....
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
OpenSSL Gives Heads Up to Critical Vulnerability Disclosure
OpenSSL Gives Heads Up to Critical Vulnerability DisclosurePost Views: 66 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Developers of the OpenSSL cryptography library have taken the unusual step of pre-warning that an update due to land next Tuesday (November 1) will fix a critical vulnerability.The looming OpenSSL 3.x patch represent only the second time the project has addressed a flaw classified as ‘critical’. The only previous OpenSSL update of such elevated severity addressed the infamous Heartbleed vulnerability (CVE-2014-0160).
Heartbleed was a memory handling bug that opened the door for attackers to access secret keys, passwords, and sensitive personal information from vulnerable servers. At the time of its discovery eight years ago, experts from Netcraft estimated that the flaw affected 17% of SSL web servers or “half a million widely trusted websites”.
Little is known about the upcoming critical fix (OpenSSL 3.0.7), other than it is restricted to OpenSSL version 3.0, the latest release line of the software, and does not affect previous versions.
OpenSSL 3.0.x only debuted in 2021, a factor that might limit the extent of the problems next week’s announcement will reveal. OpenSSL has been around since 1998 and most systems today are still built using earlier release lines.
No details of the upcoming patch or the critical flaw it tackles have been released. In the absence of any hard info, infosec Twitter has gone into overdrive with some speculating that the vulnerability might represent the “next Heartbleed”.
One security expert from Google, for example, has suggested on the basis of recent software commits and a blog post by the OpenSSL team that the update might relate to a denial-of-service (DoS) issue.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Feel the DHEatThis particular DoS bug – known as DHEat and previous confirmed to affect OpenVPN and SSH services – involves enforcing the Diffie-Hellman key exchange.
DHEat (AKA CVE-2002-20001) scores 7.5 on the CVSS 3.1 index, indicating high severity and falling somewhat short of critical.
On the face of it, an OpenSSL patch for DHEat would appear to be a poor candidate for a critical patch unless OpenSSL is particularly vulnerable. A recent OpenSSL blog post referencing DHEat makes it even more unlikely that the looming patch tackles this issue.
It seems more likely that a previously unknown vulnerability is at play, according to experts quizzed by The Daily Swig.
Trending: Exploit XSS Injections in a one-line powerful Technique
Trending: Recon Tool: Hakrawler Action stationsBrian Fox, CTO of Sonatype, told us that organizations should audit their code base for exposure to any vulnerability in OpenSSL 3.0.x, leaving them prepared to either patch or isolate vulnerable systems next week.
“In the first instance, it’s critical to find out where 3.x is used,” Fox said. “More importantly, it’s vital to get tooling in place to avoid having to audit and identify components manually every time.”
Fox went on to argue that speculation about the content of the upcoming fix were, at best, “unhelpful”. He said: “The speculation assumes that the fix is available in the publicly visible source and the advance notice gives attackers time to find it. This assumption may not be true. It is a best practice at some times to embargo the actual change until after the announcement for this exact reason.
“The team at OpenSSL consists of some of the foremost experts in handling high profile open sou[...]
___________________________
@hacking_Attack
@Hacking_Video
OpenSSL Gives Heads Up to Critical Vulnerability Disclosure
OpenSSL Gives Heads Up to Critical Vulnerability DisclosurePost Views: 66 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Developers of the OpenSSL cryptography library have taken the unusual step of pre-warning that an update due to land next Tuesday (November 1) will fix a critical vulnerability.The looming OpenSSL 3.x patch represent only the second time the project has addressed a flaw classified as ‘critical’. The only previous OpenSSL update of such elevated severity addressed the infamous Heartbleed vulnerability (CVE-2014-0160).
Heartbleed was a memory handling bug that opened the door for attackers to access secret keys, passwords, and sensitive personal information from vulnerable servers. At the time of its discovery eight years ago, experts from Netcraft estimated that the flaw affected 17% of SSL web servers or “half a million widely trusted websites”.
Little is known about the upcoming critical fix (OpenSSL 3.0.7), other than it is restricted to OpenSSL version 3.0, the latest release line of the software, and does not affect previous versions.
OpenSSL 3.0.x only debuted in 2021, a factor that might limit the extent of the problems next week’s announcement will reveal. OpenSSL has been around since 1998 and most systems today are still built using earlier release lines.
No details of the upcoming patch or the critical flaw it tackles have been released. In the absence of any hard info, infosec Twitter has gone into overdrive with some speculating that the vulnerability might represent the “next Heartbleed”.
One security expert from Google, for example, has suggested on the basis of recent software commits and a blog post by the OpenSSL team that the update might relate to a denial-of-service (DoS) issue.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Feel the DHEatThis particular DoS bug – known as DHEat and previous confirmed to affect OpenVPN and SSH services – involves enforcing the Diffie-Hellman key exchange.
DHEat (AKA CVE-2002-20001) scores 7.5 on the CVSS 3.1 index, indicating high severity and falling somewhat short of critical.
On the face of it, an OpenSSL patch for DHEat would appear to be a poor candidate for a critical patch unless OpenSSL is particularly vulnerable. A recent OpenSSL blog post referencing DHEat makes it even more unlikely that the looming patch tackles this issue.
It seems more likely that a previously unknown vulnerability is at play, according to experts quizzed by The Daily Swig.
Trending: Exploit XSS Injections in a one-line powerful Technique
Trending: Recon Tool: Hakrawler Action stationsBrian Fox, CTO of Sonatype, told us that organizations should audit their code base for exposure to any vulnerability in OpenSSL 3.0.x, leaving them prepared to either patch or isolate vulnerable systems next week.
“In the first instance, it’s critical to find out where 3.x is used,” Fox said. “More importantly, it’s vital to get tooling in place to avoid having to audit and identify components manually every time.”
Fox went on to argue that speculation about the content of the upcoming fix were, at best, “unhelpful”. He said: “The speculation assumes that the fix is available in the publicly visible source and the advance notice gives attackers time to find it. This assumption may not be true. It is a best practice at some times to embargo the actual change until after the announcement for this exact reason.
“The team at OpenSSL consists of some of the foremost experts in handling high profile open sou[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
OpenSSL Gives Heads Up to Critical Vulnerability Disclosure | Black Hat Ethical Hacking
Developers of the OpenSSL cryptography library have taken the unusual step of pre-warning that an update due to land next Tuesday (November 1) will fix a critical vulnerability.