Bug Bounty Tips — Part 1
Here are some tips and annotations that i’ve made based on articles and writeups that i’ve readContinue reading on Medium »
Read more...
Here are some tips and annotations that i’ve made based on articles and writeups that i’ve readContinue reading on Medium »
Read more...
Need help NMAP Shows all ports are open
https://www.reddit.com/r/Pentesting/comments/yv2x4r/need_help_nmap_shows_all_ports_are_open/
Hello, I am currently using NMAP to scan my sonicwalls just for fun and noticed that all sonicwalls show a few ports open (standard ports that makes sense to me). But one location show all ports are open. The only thing different is that at that location we have the famous "999" vlan where the internet goes into my Dell switch and then into two different routers (or buildings). This is because they are two different companeis running off the same internet. Is it the Dell switch that is giving me all these ports open? Has anyone ever encountered this? I showed this to my boss and I am not sure why it is happening or a way to proove it isn't the sonicwall... Thanks! submitted by /u/Alternative-Phone946 (https://www.reddit.com/user/Alternative-Phone946)
[link] (https://www.reddit.com/r/Pentesting/comments/yv2x4r/need_help_nmap_shows_all_ports_are_open/) [comments] (https://www.reddit.com/r/Pentesting/comments/yv2x4r/need_help_nmap_shows_all_ports_are_open/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/yv2x4r/need_help_nmap_shows_all_ports_are_open/
Hello, I am currently using NMAP to scan my sonicwalls just for fun and noticed that all sonicwalls show a few ports open (standard ports that makes sense to me). But one location show all ports are open. The only thing different is that at that location we have the famous "999" vlan where the internet goes into my Dell switch and then into two different routers (or buildings). This is because they are two different companeis running off the same internet. Is it the Dell switch that is giving me all these ports open? Has anyone ever encountered this? I showed this to my boss and I am not sure why it is happening or a way to proove it isn't the sonicwall... Thanks! submitted by /u/Alternative-Phone946 (https://www.reddit.com/user/Alternative-Phone946)
[link] (https://www.reddit.com/r/Pentesting/comments/yv2x4r/need_help_nmap_shows_all_ports_are_open/) [comments] (https://www.reddit.com/r/Pentesting/comments/yv2x4r/need_help_nmap_shows_all_ports_are_open/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Need help NMAP Shows all ports are open
Hello, I am currently using NMAP to scan my sonicwalls just for fun and noticed that all sonicwalls show a few ports open (standard...
Strange discovery
https://www.reddit.com/r/Pentesting/comments/yv4118/strange_discovery/
I'm sorry if this isn't the right sub or if this isn't relevant, I just don't know where to post this. Alright so I'm new into pentesting and I basically don't know much, recently I started focusing a bit more on learning by doing simple CTFs on various websites. One day I was looking for a real life example of LFI or RFI vulnerabilities (without any malicious intentions, it was just for education purposes), I found some random Google dorks and I started looking, like I said I'm a newbie so I really don't know much about how it works. I just wanted to see how it worked, so I kept looking, the results weren't really relevant but I just kept stumbling upon what seemed to be randomly generated blogs with very weird URLs, they seem randomly generated and suggest that they are vulnerable, some of them can load google pages (nothing else seems to work), but they generally are just abusing indexation. These blogs are all very similar: a login form, a randomly generated text which seems to be taken from the book Pride and Prejudice mixed with some random cybersecurity jargon (it's the same type of text for all of them), and a functional comment section with random comments on them. The page updates it's content every time you refresh it. They seem to have no purpose, no ads, no external links (except in the comments, probably just automated bots external to the site), no invitations and no information about the owners. I only listed a few (54) and got tired that day, but there's thousands of them, I tried to look it up and search about it but I found nothing. Here's the few ones I listed. (https://github.com/angelichours/splogs/blob/main/list.txt) But like I said there's thousands of them. Does anyone know what this is? submitted by /u/civilflower7164 (https://www.reddit.com/user/civilflower7164)
[link] (https://www.reddit.com/r/Pentesting/comments/yv4118/strange_discovery/) [comments] (https://www.reddit.com/r/Pentesting/comments/yv4118/strange_discovery/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/yv4118/strange_discovery/
I'm sorry if this isn't the right sub or if this isn't relevant, I just don't know where to post this. Alright so I'm new into pentesting and I basically don't know much, recently I started focusing a bit more on learning by doing simple CTFs on various websites. One day I was looking for a real life example of LFI or RFI vulnerabilities (without any malicious intentions, it was just for education purposes), I found some random Google dorks and I started looking, like I said I'm a newbie so I really don't know much about how it works. I just wanted to see how it worked, so I kept looking, the results weren't really relevant but I just kept stumbling upon what seemed to be randomly generated blogs with very weird URLs, they seem randomly generated and suggest that they are vulnerable, some of them can load google pages (nothing else seems to work), but they generally are just abusing indexation. These blogs are all very similar: a login form, a randomly generated text which seems to be taken from the book Pride and Prejudice mixed with some random cybersecurity jargon (it's the same type of text for all of them), and a functional comment section with random comments on them. The page updates it's content every time you refresh it. They seem to have no purpose, no ads, no external links (except in the comments, probably just automated bots external to the site), no invitations and no information about the owners. I only listed a few (54) and got tired that day, but there's thousands of them, I tried to look it up and search about it but I found nothing. Here's the few ones I listed. (https://github.com/angelichours/splogs/blob/main/list.txt) But like I said there's thousands of them. Does anyone know what this is? submitted by /u/civilflower7164 (https://www.reddit.com/user/civilflower7164)
[link] (https://www.reddit.com/r/Pentesting/comments/yv4118/strange_discovery/) [comments] (https://www.reddit.com/r/Pentesting/comments/yv4118/strange_discovery/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Strange discovery
I'm sorry if this isn't the right sub or if this isn't relevant, I just don't know where to post this. Alright so I'm new into pentesting and I...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Malware Techniques
https://cdn-images-1.medium.com/max/1024/1*oulE49BJjG_-nB3XM8LxMQ.jpeg
This is a repository of resource about Malware techniques. A curated list of resources to analyse and study malware techniques.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Malware Techniques
https://cdn-images-1.medium.com/max/1024/1*oulE49BJjG_-nB3XM8LxMQ.jpeg
This is a repository of resource about Malware techniques. A curated list of resources to analyse and study malware techniques.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Malware Techniques
This is a repository of resource about Malware techniques. A curated list of resources to analyse and study malware techniques.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Faculty writeup hack the box
https://cdn-images-1.medium.com/max/1031/1*IsLdtDRWB9VkDACV2bEj_A.png
Target IP : 10.10.11.169
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Faculty writeup hack the box
https://cdn-images-1.medium.com/max/1031/1*IsLdtDRWB9VkDACV2bEj_A.png
Target IP : 10.10.11.169
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Faculty writeup hack the box
Target IP : 10.10.11.169
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Exploit 6 Common Network Services (TryHackMe Network Services 1&2 — No Spoilers!)
https://cdn-images-1.medium.com/max/800/1*Z0YMHbVV9WqSEmec8ZE1PQ.png
Prefer to watch this article instead? No Problem!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Exploit 6 Common Network Services (TryHackMe Network Services 1&2 — No Spoilers!)
https://cdn-images-1.medium.com/max/800/1*Z0YMHbVV9WqSEmec8ZE1PQ.png
Prefer to watch this article instead? No Problem!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Exploit 6 Common Network Services (TryHackMe Network Services 1&2 — No Spoilers!)
Prefer to watch this article instead? No Problem!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Research: Malware 101 — Made Simple
https://cdn-images-1.medium.com/max/1920/1*rZzYWAJTDg-AeblW8g4ZbQ.jpeg
What to take away from reading this?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Research: Malware 101 — Made Simple
https://cdn-images-1.medium.com/max/1920/1*rZzYWAJTDg-AeblW8g4ZbQ.jpeg
What to take away from reading this?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Research: Malware 101 — Made Simple
What to take away from reading this?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My OSCP Experience
https://cdn-images-1.medium.com/max/600/1*VVP9d7IC4hG4PkaMdX7asw.png
I’m sure you’ve read a lot of this kind of articles, as I did while preparing for OSCP, but usually you can find something useful on all…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My OSCP Experience
https://cdn-images-1.medium.com/max/600/1*VVP9d7IC4hG4PkaMdX7asw.png
I’m sure you’ve read a lot of this kind of articles, as I did while preparing for OSCP, but usually you can find something useful on all…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My OSCP Experience
I’m sure you’ve read a lot of this kind of articles, as I did while preparing for OSCP, but usually you can find something useful on all of…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mitglied der Ransomware-Bande LockBit verhaftet
https://cdn-images-1.medium.com/max/602/0*m8D6ekeK1CaEB8pg.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Mitglied der Ransomware-Bande LockBit verhaftet
https://cdn-images-1.medium.com/max/602/0*m8D6ekeK1CaEB8pg.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Mitglied der Ransomware-Bande LockBit verhaftet
Mit ihren Ransomware-Attacken sorgte die LockBit-Bande in den vergangenen Wochen für großen Wirbel. Nun ist es Ermittlern gelungen, einen der Betreiber festzunehmen. Einem internationalem…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
P1 Bounties: Cross-Site Scripting (XSS) Tips And Tricks
https://cdn-images-1.medium.com/max/619/1*q-kHlLcboP8p_bA_rhI5Eg.png
TL;DR- A guide on what XSS is, how to find it, how to exploit it, and then how to make the most money off of it.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
P1 Bounties: Cross-Site Scripting (XSS) Tips And Tricks
https://cdn-images-1.medium.com/max/619/1*q-kHlLcboP8p_bA_rhI5Eg.png
TL;DR- A guide on what XSS is, how to find it, how to exploit it, and then how to make the most money off of it.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
Medium
P1 Bug Hunting: Cross-Site Scripting (XSS) Tips And Tricks
TL;DR- A guide on what XSS is, how to find it, how to exploit it, and then how to make the most money off of it.
Hacking on Medium
XSS using a username
https://cdn-images-1.medium.com/max/600/1*37UFMevJx6PFMldMYPUQyQ.jpeg
XSS triggered by exploiting a vulnerable input field of a signup page.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
XSS using a username
https://cdn-images-1.medium.com/max/600/1*37UFMevJx6PFMldMYPUQyQ.jpeg
XSS triggered by exploiting a vulnerable input field of a signup page.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS using a username
XSS triggered by exploiting a vulnerable input field of a signup page.
Hacking on Medium
Hack the Box — Fawn Write-up
https://cdn-images-1.medium.com/max/1400/1*nOvxQX4CWU8Vht98Ba0C5A.png
In this lab we will be enumerating a service on a specific host. The purpose of this lab is the familiarize yourself with the File…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack the Box — Fawn Write-up
https://cdn-images-1.medium.com/max/1400/1*nOvxQX4CWU8Vht98Ba0C5A.png
In this lab we will be enumerating a service on a specific host. The purpose of this lab is the familiarize yourself with the File…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack the Box — Fawn Write-up
In this lab we will be enumerating a service on a specific host. The purpose of this lab is the familiarize yourself with the File…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Github Page Takeover Works?
https://cdn-images-1.medium.com/max/883/1*hqsPRH3PtpUN9k_TqJ3joQ.png
Hello folks,
I will share my experience how I found the Github page takeover vulnerability. Because there are still many who are confused…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Github Page Takeover Works?
https://cdn-images-1.medium.com/max/883/1*hqsPRH3PtpUN9k_TqJ3joQ.png
Hello folks,
I will share my experience how I found the Github page takeover vulnerability. Because there are still many who are confused…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Github Page Takeover Works?
Hello folks, I will share my experience how I found the Github page takeover vulnerability. Because there are still many who are confused…