Login CSRF — What is it and how to prevent it?
Login CSRF (Login Cross-Site Request Forgery) is a type of attack where an attacker forces a user to login to the attacker’s account. A…Continue reading on Medium »
Read more...
Login CSRF (Login Cross-Site Request Forgery) is a type of attack where an attacker forces a user to login to the attacker’s account. A…Continue reading on Medium »
Read more...
How I made a reliable hacking tools and resources search engine in two days (~6500 entries!)
https://lobuhisec.medium.com/how-i-made-a-reliable-hacking-tools-and-resources-search-engine-in-two-days-6500-entries-1983beeff79d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://lobuhisec.medium.com/how-i-made-a-reliable-hacking-tools-and-resources-search-engine-in-two-days-6500-entries-1983beeff79d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I made a reliable hacking tools and resources search engine in two days (~6500 entries!)
https://lobuhi.github.io/
Login CSRF — What is it and how to prevent it?
https://medium.com/@harshit.dharani13/login-csrf-what-is-it-and-how-to-prevent-it-ed4f42f06ae5?source=rss------bug_bounty-5
Login CSRF (Login Cross-Site Request Forgery) is a type of attack where an attacker forces a user to login to the attacker’s account. A…Continue reading on Medium » (https://medium.com/@harshit.dharani13/login-csrf-what-is-it-and-how-to-prevent-it-ed4f42f06ae5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@harshit.dharani13/login-csrf-what-is-it-and-how-to-prevent-it-ed4f42f06ae5?source=rss------bug_bounty-5
Login CSRF (Login Cross-Site Request Forgery) is a type of attack where an attacker forces a user to login to the attacker’s account. A…Continue reading on Medium » (https://medium.com/@harshit.dharani13/login-csrf-what-is-it-and-how-to-prevent-it-ed4f42f06ae5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Login CSRF — What is it and how to prevent it?
Login CSRF (Login Cross-Site Request Forgery) is a type of attack where an attacker forces a user to login to the attacker’s account. A…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
pentesting.cloud part 1: “Open To The Public” CTF walkthrough
https://cdn-images-1.medium.com/max/600/1*MUxAjq5mo4jbbqUiinCWxw.jpeg
Recently I have a very good time playing the pentesting.cloud CTF and in this blog post I want to start a new walkthrough series of IMHO…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
pentesting.cloud part 1: “Open To The Public” CTF walkthrough
https://cdn-images-1.medium.com/max/600/1*MUxAjq5mo4jbbqUiinCWxw.jpeg
Recently I have a very good time playing the pentesting.cloud CTF and in this blog post I want to start a new walkthrough series of IMHO…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
pentesting.cloud part 1: “Open To The Public” CTF walkthrough
Recently I have a very good time playing the pentesting.cloud CTF and in this blog post I want to start a new walkthrough series of IMHO…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
picoCTF 2021 — It is my birthday Writeup
https://cdn-images-1.medium.com/max/600/0*QpAbBKtCmkeJ-J0k.png
~ In this article, I will cover:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
picoCTF 2021 — It is my birthday Writeup
https://cdn-images-1.medium.com/max/600/0*QpAbBKtCmkeJ-J0k.png
~ In this article, I will cover:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
picoCTF 2o21 — It is my birthday Writeup
~ In this article, I will cover:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Zero-day Vulnerability and System Protection
https://cdn-images-1.medium.com/max/600/1*mhbGLcvQyC4ZI2AEyaUhbA.jpeg
This article was originally published on LearnHub
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Zero-day Vulnerability and System Protection
https://cdn-images-1.medium.com/max/600/1*mhbGLcvQyC4ZI2AEyaUhbA.jpeg
This article was originally published on LearnHub
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zero-day Vulnerability and System Protection
This article was originally published on LearnHub
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Error of Bridged Adapter on Kali Linux (iso)
https://cdn-images-1.medium.com/max/640/1*um4AJIUakq-UcE5z7PswBA.png
Kali comes with networking disabled by default to prevent denouncing your own presence through an unconscionable DHCP request.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Error of Bridged Adapter on Kali Linux (iso)
https://cdn-images-1.medium.com/max/640/1*um4AJIUakq-UcE5z7PswBA.png
Kali comes with networking disabled by default to prevent denouncing your own presence through an unconscionable DHCP request.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Error of Bridged Adapter on Kali Linux (iso)
Kali comes with networking disabled by default to prevent denouncing your own presence through an unconscionable DHCP request.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Netdiscover Cheatsheet
https://cdn-images-1.medium.com/max/1024/1*GTGi8HQb0_DaHG60uzpNFA.png
Netdiscover es una herramienta activa/pasiva para el reconocimiento de direcciones, desarrollada principalmente para redes inalámbricas…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Netdiscover Cheatsheet
https://cdn-images-1.medium.com/max/1024/1*GTGi8HQb0_DaHG60uzpNFA.png
Netdiscover es una herramienta activa/pasiva para el reconocimiento de direcciones, desarrollada principalmente para redes inalámbricas…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Netdiscover Cheatsheet
Netdiscover es una herramienta activa/pasiva para el reconocimiento de direcciones, desarrollada principalmente para redes inalámbricas sin…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ethical hacking interview questions and preparation! By ACTE
https://cdn-images-1.medium.com/max/1080/1*EXw1d4uoOmuvrhBpTfaeTg.png
Recent significant cybersecurity incidents have pushed businesses to hire infosec specialists with ethical hacking skills. Since a college…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ethical hacking interview questions and preparation! By ACTE
https://cdn-images-1.medium.com/max/1080/1*EXw1d4uoOmuvrhBpTfaeTg.png
Recent significant cybersecurity incidents have pushed businesses to hire infosec specialists with ethical hacking skills. Since a college…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ethical hacking interview questions and preparation! By ACTE
Recent significant cybersecurity incidents have pushed businesses to hire infosec specialists with ethical hacking skills. Since a college…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Python for Hackers: How to Use the Right Tools to Get Paid in 2023
https://cdn-images-1.medium.com/max/2600/0*3_-jTSrg0g1eh8Mv
In the future, many businesses will need to use Python for their hacking needs.
Continue reading on DataDrivenInvestor »
___________________________
@hacking_Attack
@Hacking_Video
Python for Hackers: How to Use the Right Tools to Get Paid in 2023
https://cdn-images-1.medium.com/max/2600/0*3_-jTSrg0g1eh8Mv
In the future, many businesses will need to use Python for their hacking needs.
Continue reading on DataDrivenInvestor »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Python for Hackers: How to Use the Right Tools to Get Paid in 2023
In the future, many businesses will need to use Python for their hacking needs.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
VuCSA - Vulnerable Client-Server Application - Made For Learning/Presenting How To Perform Penetration Tests Of Non-Http Thick Clients
https://blogger.googleusercontent.com/img/a/AVvXsEhXcmK17m6wCBaHR39GGFs4rVs1weuGCekhTBe08jKuPqdoI9FwF73Zab_WrU8EIvkyMQEd4jjOjXtLpKpCEVLLodefbjSs92ScFS8-Fs6Qe25JuLQe71k0_l-jucZ7iG3DM1Gh3PgwpWhsksNn1xTIknLQc6uIjspvI8RMpemtzIGPyDbgJd2KlqDlfw=w200-h200
Vulnerable Client-Server Application
Vulnerable client-server application (VuCSA) is made for learning/presenting how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface).
Currently the vulnerable application contains the following challenges:
1. Buffer Over-read (simulated)
2. Command Execution
3. SQL Injection
4. Enumeration
5. XML
6. Horizontal Access Control
7. Vertical Access Control
If you want to know how to solve these challenges, take a look at the PETEP website, which describes how to use the open-source tool PETEP to exploit them.
Tip: Before you start hacking, do not forget to check the data structure of messages bellow.
How to Run
In order to run the vulnerable server and client, you can use one of releases on GitHub or run gradle assemble, which creates distribution packages (for both Windows and Unix). These packages contain sh/bat scripts that will run the server and client using JVM.
Project Structure
Project is divided into three modules:
* vucsa-common - common functionality for both client and server (including protocol processing utilities)
* vucsa-client - vulnerable client with JavaFX GUI
* vucsa-server - vulnerable server for terminal use
Data Structure
Messages transmitted between server and client have the following simple format:
These four parts have the following meaning:
* type - type of the message (used for serialization/deserialization)
* target - target handler that will receive the message
* length - length of the payload
* payload - data serialized into bytes
Download Vucsa
___________________________
@hacking_Attack
@Hacking_Video
VuCSA - Vulnerable Client-Server Application - Made For Learning/Presenting How To Perform Penetration Tests Of Non-Http Thick Clients
https://blogger.googleusercontent.com/img/a/AVvXsEhXcmK17m6wCBaHR39GGFs4rVs1weuGCekhTBe08jKuPqdoI9FwF73Zab_WrU8EIvkyMQEd4jjOjXtLpKpCEVLLodefbjSs92ScFS8-Fs6Qe25JuLQe71k0_l-jucZ7iG3DM1Gh3PgwpWhsksNn1xTIknLQc6uIjspvI8RMpemtzIGPyDbgJd2KlqDlfw=w200-h200
Vulnerable Client-Server Application
Vulnerable client-server application (VuCSA) is made for learning/presenting how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface).
Currently the vulnerable application contains the following challenges:
1. Buffer Over-read (simulated)
2. Command Execution
3. SQL Injection
4. Enumeration
5. XML
6. Horizontal Access Control
7. Vertical Access Control
If you want to know how to solve these challenges, take a look at the PETEP website, which describes how to use the open-source tool PETEP to exploit them.
Tip: Before you start hacking, do not forget to check the data structure of messages bellow.
How to Run
In order to run the vulnerable server and client, you can use one of releases on GitHub or run gradle assemble, which creates distribution packages (for both Windows and Unix). These packages contain sh/bat scripts that will run the server and client using JVM.
Project Structure
Project is divided into three modules:
* vucsa-common - common functionality for both client and server (including protocol processing utilities)
* vucsa-client - vulnerable client with JavaFX GUI
* vucsa-server - vulnerable server for terminal use
Data Structure
Messages transmitted between server and client have the following simple format:
[type][target][length][payload]
32b 32b 32b ???
These four parts have the following meaning:
* type - type of the message (used for serialization/deserialization)
* target - target handler that will receive the message
* length - length of the payload
* payload - data serialized into bytes
Download Vucsa
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
VuCSA - Vulnerable Client-Server Application - Made For Learning/Presenting How To Perform Penetration Tests Of Non-Http Thick…