Hacking on Medium
DO ALL TRANSFERS CASHAPP WESTERN UNION PAYPAL BLANK CLOND ATM CREDIT CARDS HIGH BALANCE BANKS…
100% LEGIT QUICk Cashapp
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DO ALL TRANSFERS CASHAPP WESTERN UNION PAYPAL BLANK CLOND ATM CREDIT CARDS HIGH BALANCE BANKS…
100% LEGIT QUICk Cashapp
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DO ALL TRANSFERS CASHAPP WESTERN UNION PAYPAL BLANK CLOND ATM CREDIT CARDS HIGH BALANCE BANKS SECURED LEGIT TRANSFERS CC CVV VBV…
100% LEGIT QUICk Cashapp
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Social Engineering: A beginner’s Guide
https://cdn-images-1.medium.com/max/1440/1*BHU9cpPm2YJrrjG9K0gqvw.jpeg
This blog will introduce one of the most essential skills that every ethical hacker and cybersecurity enthusiast uses, i.e Social…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Social Engineering: A beginner’s Guide
https://cdn-images-1.medium.com/max/1440/1*BHU9cpPm2YJrrjG9K0gqvw.jpeg
This blog will introduce one of the most essential skills that every ethical hacker and cybersecurity enthusiast uses, i.e Social…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Social Engineering: A beginner’s Guide
This blog will introduce one of the most essential skills that every ethical hacker and cybersecurity enthusiast uses, i.e Social…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Skyward Finance $3 Million Exploit Decoded | BlockAudit
https://cdn-images-1.medium.com/max/1500/1*er1ISZ85WKW1RhDCZzuqqg.png
What happened to $sKYWARD Finance:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Skyward Finance $3 Million Exploit Decoded | BlockAudit
https://cdn-images-1.medium.com/max/1500/1*er1ISZ85WKW1RhDCZzuqqg.png
What happened to $sKYWARD Finance:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Skyward Finance $3 Million Exploit Decoded | BlockAudit
What happened to $sKYWARD Finance:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box [HTB] — UpDown Walkthrough
https://cdn-images-1.medium.com/max/700/1*uKrnqT5Zfs8D6q625F0a6Q.png
In this article we’re going to be looking at the HTB machine UpDown, which is medium difficulty machine on hackthebox.com that is…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box [HTB] — UpDown Walkthrough
https://cdn-images-1.medium.com/max/700/1*uKrnqT5Zfs8D6q625F0a6Q.png
In this article we’re going to be looking at the HTB machine UpDown, which is medium difficulty machine on hackthebox.com that is…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack The Box [HTB] Writeup — UpDown
In this article we’re going to be looking at the HTB machine UpDown, which is medium difficulty machine on hackthebox.com that is…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Explaining vulnerabilities : Cross Site Scripting (XSS)
https://cdn-images-1.medium.com/max/2000/0*QX3MkoxUWsAAYBrn
Cross-Site Scripting (or XSS) is one of the most common bugs reported to bug bounty programs. It’s so prevalent that, every single year…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Explaining vulnerabilities : Cross Site Scripting (XSS)
https://cdn-images-1.medium.com/max/2000/0*QX3MkoxUWsAAYBrn
Cross-Site Scripting (or XSS) is one of the most common bugs reported to bug bounty programs. It’s so prevalent that, every single year…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Explaining vulnerabilities : Cross Site Scripting (XSS)
Cross-Site Scripting (or XSS) is one of the most common bugs reported to bug bounty programs. It’s so prevalent that, every single year…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe — TomGhost WriteUp
https://cdn-images-1.medium.com/max/1592/1*jXmn_plUhlT0YorXyDZ9Fw.png
Introduction:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe — TomGhost WriteUp
https://cdn-images-1.medium.com/max/1592/1*jXmn_plUhlT0YorXyDZ9Fw.png
Introduction:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe — TomGhost WriteUp
Introduction:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Recon Tool: Maigret
Recon Tool: MaigretPost Views: 23 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes MaigretRecon is the most powerful and most important step when it comes to Offensive Security and Digital Forensics. It is a lot of time consuming, however finding the right tools and techniques to conduct them faster, is being smart.
Maigret by soxoj collects a dossier on a person by username only, checking for accounts on a huge number of sites and gathering all the available information from web pages. No API keys are required.
Currently supported by more than 2500 sites (full list), the search is launched against 500 popular sites in descending order of popularity by default. Also supported checking of Tor sites, I2P sites, and domains via DNS resolving.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Main Features* Profile pages parsing, extraction of personal info, links to other profiles, etc.
* Recursive search by new usernames and other ids found
* Search by tags (site categories, countries)
* Censorship and captcha detection
* Requests retries
See full description of Maigret features in the documentation.
Trending: Offensive Security Tool: Mangle
Trending: Offensive Security Tool: WinPwnage InstallationMaigret can be installed using pip, Docker, or simply can be launched from the cloned repo.
Standalone EXE-binaries for Windows are located in Releases section of GitHub repository. Package installingNOTE: Python 3.7 or higher and pip is required, Python 3.8 is recommended.
Trending: Exploit XSS Injections in a one-line powerful Technique Demo with page parsing and recursive username searchDemohttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/report_alexaimephotography_html_screenshot-1024x818.png
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/report_alexaimephotography_xmind_screenshot-1024x472.png
Clone the repo from here: GitHub Link
Trending: Article: Using VPS for Bug Bounty, comparing VPS providers https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/SecretScanner-300x150.png Recon Tool: SecretScannerNovember 17, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Mangle-300x150.png Offensive Security Tool: MangleNovember 11, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/WinPwnage-300x150.jpg Offensive Security Tool: WinPwnageNovember 4, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/lazypariah-300x150.png Offensive Security Tool: LAZYPARIAHOctober 28, 2022
Reading Time: 4 minutes https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Recon Tool: Maigret first appeared on Black Hat Ethical Hacking.
Recon Tool: Maigret
Recon Tool: MaigretPost Views: 23 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes MaigretRecon is the most powerful and most important step when it comes to Offensive Security and Digital Forensics. It is a lot of time consuming, however finding the right tools and techniques to conduct them faster, is being smart.
Maigret by soxoj collects a dossier on a person by username only, checking for accounts on a huge number of sites and gathering all the available information from web pages. No API keys are required.
Currently supported by more than 2500 sites (full list), the search is launched against 500 popular sites in descending order of popularity by default. Also supported checking of Tor sites, I2P sites, and domains via DNS resolving.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Main Features* Profile pages parsing, extraction of personal info, links to other profiles, etc.
* Recursive search by new usernames and other ids found
* Search by tags (site categories, countries)
* Censorship and captcha detection
* Requests retries
See full description of Maigret features in the documentation.
Trending: Offensive Security Tool: Mangle
Trending: Offensive Security Tool: WinPwnage InstallationMaigret can be installed using pip, Docker, or simply can be launched from the cloned repo.
Standalone EXE-binaries for Windows are located in Releases section of GitHub repository. Package installingNOTE: Python 3.7 or higher and pip is required, Python 3.8 is recommended.
# install from pypipip3 install maigret# usagemaigret usernameCloning a repository# or clone and install manuallygit clone https://github.com/soxoj/maigret && cd maigretpip3 install -r requirements.txt# usage./maigret.py usernameDocker# official imagedocker pull soxoj/maigret# usagedocker run -v /mydir:/app/reports soxoj/maigret:latest username --html# manual builddocker build -t maigret .Usage Examples# make HTML and PDF reportsmaigret user --html --pdf# search on sites marked with tags photo & datingmaigret user --tags photo,dating# search for three usernames on all available sitesmaigret user1 user2 user3 -aUse maigret –help to get full options description. Also options are documented.Trending: Exploit XSS Injections in a one-line powerful Technique Demo with page parsing and recursive username searchDemohttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/report_alexaimephotography_html_screenshot-1024x818.png
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/report_alexaimephotography_xmind_screenshot-1024x472.png
Clone the repo from here: GitHub Link
Trending: Article: Using VPS for Bug Bounty, comparing VPS providers https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/SecretScanner-300x150.png Recon Tool: SecretScannerNovember 17, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Mangle-300x150.png Offensive Security Tool: MangleNovember 11, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/WinPwnage-300x150.jpg Offensive Security Tool: WinPwnageNovember 4, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/lazypariah-300x150.png Offensive Security Tool: LAZYPARIAHOctober 28, 2022
Reading Time: 4 minutes https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Recon Tool: Maigret first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Google Roulette: Developer console trick can trigger XSS in Chromium browsers
Google Roulette: Developer console trick can trigger XSS in Chromium browsersPost Views: 15 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Malicious actors can stage cross-site scripting (XSS) attacks across the subdomains of a website if they can trick users of Chromium browsers into entering a simple JavaScript command in the developer console.This is according to the findings of security researcher Michał Bentkowski who presented his findings in a blog post published yesterday (November 16) titled Google Roulette.
While the bug is hard to exploit and Google has decided not to patch it, it is an interesting case study on the complexities of browser security.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Same-origin policy, site isolationChromium browsers have several safeguards to prevent XSS attacks. The Same-Origin policy feature prevents scripts in one browser tab from accessing cookies and data from another domain.
The Site Isolation feature, on the other hand, gives a separate process to each domain to prevent different websites from accessing each other’s memory space in the browser.
However, it is worth noting that Same-Origin and Site Isolation do not apply to subdomains.
Therefore, two browser tabs that are on, say, https://workspace.google.com and https://developer.google.com will run on the same process and are considered to be of the same origin (google.com). Developer console scriptsThe browser’s protection mechanisms apply not only to on-page scripts but also to scripts running in the browser’s developer console. However, the developer console has access to certain extra functions that are not available to on-page scripts.
One of these functions is debug(), which sets breakpoints on specific events, such as when a function is called.
Two things are interesting about debug(). First, it has an optional argument that allows you to replace the breakpoint functionality with a custom JavaScript code. And second, when you use the developer console to define a debug() event on a webpage, it persists across page refreshes and even carries to other subdomains of the same origin in the same tab.
How does lead to XSS? First, Bentkowski set up a page that contained two malicious functions.
The first one is the XSS payload, which iterates across the subdomains of the current origin and runs a proof-of-concept script (in this case an alert() popup).
The second one is a getter function called magic() that defines a debug() event for the appendChild function (which happens many times during a page load) and reloads the page.
Since debug() needs to be explicitly called from the developer console, the page displays a message that prompts the user to call magic() from the developer console. After that, the XSS cycle is triggered and goes through any number of subdomains defined in the payload function.
A video containing a proof-of-concept can be found here.
Trending: A primer on OS Command Injection Attacks
Trending: Offensive Security Tool: Mangle Impact and fix“I see it more as an interesting technical bug than something exploitable in the real world,” Bentkowski told The Daily Swig. “In my opinion, the user interaction required by this attack makes it not really feasible for attackers.”
There are, however, two scenarios where this bug can become concerning, according to Bentkowski.
First are websites where users can create their own subdomains. In this case, a user can c[...]
___________________________
@hacking_Attack
@Hacking_Video
Google Roulette: Developer console trick can trigger XSS in Chromium browsers
Google Roulette: Developer console trick can trigger XSS in Chromium browsersPost Views: 15 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Malicious actors can stage cross-site scripting (XSS) attacks across the subdomains of a website if they can trick users of Chromium browsers into entering a simple JavaScript command in the developer console.This is according to the findings of security researcher Michał Bentkowski who presented his findings in a blog post published yesterday (November 16) titled Google Roulette.
While the bug is hard to exploit and Google has decided not to patch it, it is an interesting case study on the complexities of browser security.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Same-origin policy, site isolationChromium browsers have several safeguards to prevent XSS attacks. The Same-Origin policy feature prevents scripts in one browser tab from accessing cookies and data from another domain.
The Site Isolation feature, on the other hand, gives a separate process to each domain to prevent different websites from accessing each other’s memory space in the browser.
However, it is worth noting that Same-Origin and Site Isolation do not apply to subdomains.
Therefore, two browser tabs that are on, say, https://workspace.google.com and https://developer.google.com will run on the same process and are considered to be of the same origin (google.com). Developer console scriptsThe browser’s protection mechanisms apply not only to on-page scripts but also to scripts running in the browser’s developer console. However, the developer console has access to certain extra functions that are not available to on-page scripts.
One of these functions is debug(), which sets breakpoints on specific events, such as when a function is called.
Two things are interesting about debug(). First, it has an optional argument that allows you to replace the breakpoint functionality with a custom JavaScript code. And second, when you use the developer console to define a debug() event on a webpage, it persists across page refreshes and even carries to other subdomains of the same origin in the same tab.
How does lead to XSS? First, Bentkowski set up a page that contained two malicious functions.
The first one is the XSS payload, which iterates across the subdomains of the current origin and runs a proof-of-concept script (in this case an alert() popup).
The second one is a getter function called magic() that defines a debug() event for the appendChild function (which happens many times during a page load) and reloads the page.
Since debug() needs to be explicitly called from the developer console, the page displays a message that prompts the user to call magic() from the developer console. After that, the XSS cycle is triggered and goes through any number of subdomains defined in the payload function.
A video containing a proof-of-concept can be found here.
Trending: A primer on OS Command Injection Attacks
Trending: Offensive Security Tool: Mangle Impact and fix“I see it more as an interesting technical bug than something exploitable in the real world,” Bentkowski told The Daily Swig. “In my opinion, the user interaction required by this attack makes it not really feasible for attackers.”
There are, however, two scenarios where this bug can become concerning, according to Bentkowski.
First are websites where users can create their own subdomains. In this case, a user can c[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Google Roulette: Developer console trick can trigger XSS in Chromium browsers | Black Hat Ethical Hacking
Malicious actors can stage cross-site scripting (XSS) attacks across the subdomains of a website if they can trick users of Chromium browsers into entering a simple JavaScript command in the developer console.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Google Roulette: Developer console trick can trigger XSS in Chromium browsers Google Roulette: Developer console trick can trigger XSS in Chromium browsersPost Views: 15 Premium Contenthttps://www.blackhatethicalhacking.com/wp-c…
reate a malicious page and trick visitors into triggering the XSS function on their own subdomain.
A second scenario is when there is an XSS vulnerability on one subdomain and the attacker wants to escalate it to others through the developer console.
Bentkowski reported the bug in 2020 and Google has apparently decided not to fix it. “The issue isn’t currently assigned to anyone so it doesn’t look like we can expect the patch soon,” Bentkowski said.
However, Google agreed to allow Bentkowski to make his findings public, telling him that since the bug is no longer exploitable via Chrome Extensions, it is no longer a security issue.
“I still think that there might be some ways to escalate it that I failed to discover, and maybe you, my dear readers, will have some better ideas,” Bentkowski wrote on his blog.
Trending: Azov Ransomware is a wiper, destroying data 666 bytes at a time Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-8-1-300x150.png Updated RapperBot malware targets game servers in DDoS attacksNovember 17, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-1-300x150.png Mastodon users vulnerable to password-stealing attacksNovember 16, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-300x150.png Windows Kerberos authentication breaks after November updatesNovember 15, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-300x150.png Russian hacktivists use new Somnia ransomwareNovember 14, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Google Roulette: Developer console trick can trigger XSS in Chromium browsers first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
A second scenario is when there is an XSS vulnerability on one subdomain and the attacker wants to escalate it to others through the developer console.
Bentkowski reported the bug in 2020 and Google has apparently decided not to fix it. “The issue isn’t currently assigned to anyone so it doesn’t look like we can expect the patch soon,” Bentkowski said.
However, Google agreed to allow Bentkowski to make his findings public, telling him that since the bug is no longer exploitable via Chrome Extensions, it is no longer a security issue.
“I still think that there might be some ways to escalate it that I failed to discover, and maybe you, my dear readers, will have some better ideas,” Bentkowski wrote on his blog.
Trending: Azov Ransomware is a wiper, destroying data 666 bytes at a time Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-8-1-300x150.png Updated RapperBot malware targets game servers in DDoS attacksNovember 17, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-1-300x150.png Mastodon users vulnerable to password-stealing attacksNovember 16, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-300x150.png Windows Kerberos authentication breaks after November updatesNovember 15, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-300x150.png Russian hacktivists use new Somnia ransomwareNovember 14, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Google Roulette: Developer console trick can trigger XSS in Chromium browsers first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
$250 for Email account enumeration using “NameToMail” tool
https://medium.com/@snoopy101/250-for-email-account-enumeration-using-nametomail-tool-cce02a17ade8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@snoopy101/250-for-email-account-enumeration-using-nametomail-tool-cce02a17ade8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
$250 for Email account enumeration using “NameToMail” tool
Hi amazing hackers.
Hi amazing hackers.Continue reading on Medium » (https://medium.com/@snoopy101/250-for-email-account-enumeration-using-nametomail-tool-cce02a17ade8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
$250 for Email account enumeration using “NameToMail” tool
Hi amazing hackers.
Slicer - Tool To Automate The Boring Process Of APK Recon
http://www.kitploit.com/2022/11/slicer-tool-to-automate-boring-process.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/11/slicer-tool-to-automate-boring-process.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Slicer - Tool To Automate The Boring Process Of APK Recon