Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
US govt: Iranian hackers breached federal agency using Log4Shell exploit
https://cdn-images-1.medium.com/max/602/0*wWcT7gUx3JJsD3F0.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
US govt: Iranian hackers breached federal agency using Log4Shell exploit
https://cdn-images-1.medium.com/max/602/0*wWcT7gUx3JJsD3F0.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
US govt: Iranian hackers breached federal agency using Log4Shell exploit
The FBI and CISA revealed in a joint advisory published today that an unnamed Iranian-backed threat group hacked a Federal Civilian Executive Branch (FCEB) organization to deploy XMRig cryptomining…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Crazy and Horrifying Facts about Marianas Web
https://cdn-images-1.medium.com/max/1280/1*tiI5ysjToTtQIeLE2nI2AQ.jpeg
The Internet is everywhere, and most people use it daily. We only use 4% of the Internet through Google, social media, and other search…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Crazy and Horrifying Facts about Marianas Web
https://cdn-images-1.medium.com/max/1280/1*tiI5ysjToTtQIeLE2nI2AQ.jpeg
The Internet is everywhere, and most people use it daily. We only use 4% of the Internet through Google, social media, and other search…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Crazy and Horrifying Facts about Marianas Web
The Internet is everywhere, and most people use it daily. We only use 4% of the Internet through Google, social media, and other search…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
$250 for Email account enumeration using “NameToMail” tool
https://cdn-images-1.medium.com/max/917/1*uw-NdbVM6QDFQ7iBGVZqzg.png
Hi amazing hackers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
$250 for Email account enumeration using “NameToMail” tool
https://cdn-images-1.medium.com/max/917/1*uw-NdbVM6QDFQ7iBGVZqzg.png
Hi amazing hackers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
$250 for Email account enumeration using “NameToMail” tool
Hi amazing hackers.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Wipermania: Malware Remains a Potent Threat, 10 Years Since ‘Shamoon’
https://cdn-images-1.medium.com/max/602/0*gXvQ8OPu7X7Kdr6S.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Wipermania: Malware Remains a Potent Threat, 10 Years Since ‘Shamoon’
https://cdn-images-1.medium.com/max/602/0*gXvQ8OPu7X7Kdr6S.jpg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Wipermania: Malware Remains a Potent Threat, 10 Years Since ‘Shamoon’
An in-depth analysis of system-destroying malware families presented at Black Hat Middle East & Africa shows a growing nuance in terms of how they’re deployed. Destructive wiper malware has evolved…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Penetration Testing?
https://cdn-images-1.medium.com/max/2600/1*QsOTYUFJOKUVjfm2NyohXQ.jpeg
Security Evaluation
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Penetration Testing?
https://cdn-images-1.medium.com/max/2600/1*QsOTYUFJOKUVjfm2NyohXQ.jpeg
Security Evaluation
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Penetration Testing?
Security Evaluation
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Remote Command Execution in a Bank Server
https://cdn-images-1.medium.com/max/820/1*OhygrJrIiHrtECKAFfkJAA.png
A detailed article on how I exploited Remote Command Execution (RCE) with the help of the Vulnerability Chain.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Remote Command Execution in a Bank Server
https://cdn-images-1.medium.com/max/820/1*OhygrJrIiHrtECKAFfkJAA.png
A detailed article on how I exploited Remote Command Execution (RCE) with the help of the Vulnerability Chain.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Remote Command Execution in a Bank Server
A detailed article on how I exploited Remote Command Execution (RCE) with the help of the Vulnerability Chain.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme -SteelMountain (CTF)
https://cdn-images-1.medium.com/max/1311/1*9wIAV2wV-zs0XD3nV9G-5Q.png
Stage 1 :Enumiration
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
Tryhackme -SteelMountain (CTF)
https://cdn-images-1.medium.com/max/1311/1*9wIAV2wV-zs0XD3nV9G-5Q.png
Stage 1 :Enumiration
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tryhackme -SteelMountain (CTF)
Stage 1 :Enumiration
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking with Hydra — A Practical Tutorial
https://cdn-images-1.medium.com/max/2240/1*sLNNCsZ5SMw9Uhp_Efk9Yw.png
Hydra is a fast password cracker used to brute-force and gain access to network services like SSH & FTP.
Continue reading on Stealth Security »
___________________________
@hacking_Attack
@Hacking_Video
Hacking with Hydra — A Practical Tutorial
https://cdn-images-1.medium.com/max/2240/1*sLNNCsZ5SMw9Uhp_Efk9Yw.png
Hydra is a fast password cracker used to brute-force and gain access to network services like SSH & FTP.
Continue reading on Stealth Security »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking with Hydra — A Practical Tutorial
Hydra is a fast password cracker used to brute-force and gain access to network services like SSH & FTP.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[HTB] Backdoor write-up
https://cdn-images-1.medium.com/max/679/1*CjASAHpyJhTpvpix6E4RNg.png
this article is about the backdoor box write-up that went offline recently at HTB (HackTheBox).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
[HTB] Backdoor write-up
https://cdn-images-1.medium.com/max/679/1*CjASAHpyJhTpvpix6E4RNg.png
this article is about the backdoor box write-up that went offline recently at HTB (HackTheBox).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
[HTB] Backdoor write-up
this article is about the backdoor box write-up that went offline recently at HTB (HackTheBox).
How to Hide Your Website’s Front-End For Increased Security
https://medium.com/the-gray-area/how-to-hide-your-websites-front-end-for-increased-security-76494d657b8a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/the-gray-area/how-to-hide-your-websites-front-end-for-increased-security-76494d657b8a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Hide Your Website’s Front-End For Increased Security
TL;DR- If you’re creating any website to showcase to others, you’ll want to make your site as secure as possible, while staying optimized.
TL;DR- If you’re creating any website to showcase to others, you’ll want to make your site as secure as possible, while staying optimized.Continue reading on The Gray Area » (https://medium.com/the-gray-area/how-to-hide-your-websites-front-end-for-increased-security-76494d657b8a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Hide Your Website’s Front-End For Increased Security
TL;DR- If you’re creating any website to showcase to others, you’ll want to make your site as secure as possible, while staying optimized.
KitPloit - PenTest Tools!
Slicer - Tool To Automate The Boring Process Of APK Recon
___________________________
@hacking_Attack
@Hacking_Video
Slicer - Tool To Automate The Boring Process Of APK Recon
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Slicer - Tool To Automate The Boring Process Of APK Recon
Option for progression in my current role. Cert advice UK
https://www.reddit.com/r/Pentesting/comments/yyjthh/option_for_progression_in_my_current_role_cert/
I am currently a junior cyber security analyst. I have been using Tryhackme on and off for about a year now, so I’d say that I have at least foundational knowledge of pen testing. There may be an opportunity for me to have training/certs paid for by my company, and I think it would be beneficial to broaden my skills and properly train up in pen testing. I can train for other security certs in my own time and whilst I’m working, so I think it makes more sense to have them pay for something that I can’t do so easily in my day-to-day job. What training/certs would you recommend for someone in my situation? Considering that I won’t necessarily be getting these certs in hopes of a getting a new job, but rather using them as a formalised training plan (although having a cert is always nice). submitted by /u/CannyFatcher (https://www.reddit.com/user/CannyFatcher)
[link] (https://www.reddit.com/r/Pentesting/comments/yyjthh/option_for_progression_in_my_current_role_cert/) [comments] (https://www.reddit.com/r/Pentesting/comments/yyjthh/option_for_progression_in_my_current_role_cert/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/yyjthh/option_for_progression_in_my_current_role_cert/
I am currently a junior cyber security analyst. I have been using Tryhackme on and off for about a year now, so I’d say that I have at least foundational knowledge of pen testing. There may be an opportunity for me to have training/certs paid for by my company, and I think it would be beneficial to broaden my skills and properly train up in pen testing. I can train for other security certs in my own time and whilst I’m working, so I think it makes more sense to have them pay for something that I can’t do so easily in my day-to-day job. What training/certs would you recommend for someone in my situation? Considering that I won’t necessarily be getting these certs in hopes of a getting a new job, but rather using them as a formalised training plan (although having a cert is always nice). submitted by /u/CannyFatcher (https://www.reddit.com/user/CannyFatcher)
[link] (https://www.reddit.com/r/Pentesting/comments/yyjthh/option_for_progression_in_my_current_role_cert/) [comments] (https://www.reddit.com/r/Pentesting/comments/yyjthh/option_for_progression_in_my_current_role_cert/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Option for progression in my current role. Cert advice UK
I am currently a junior cyber security analyst. I have been using Tryhackme on and off for about a year now, so I’d say that I have at least...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
AppleAVD deallocateKernelMemoryInternal Missing Surface Lock
https://3.bp.blogspot.com/-BKQJl1oXbqE/WWlvQjSZMJI/AAAAAAAAINE/UWb7sXt4uvssyXVrWpwrINbeIcIr93_vACLcBGAs/s1600/h33.png
In AppleAVD.kext, pixel buffers are mapped by calling AppleAVDUserClient::_mapPixelBuffer, which eventually calls AppleAVD::allocateKernelMemoryInternal. If the buffer is an IOSurface, the function calls IOSurface::deviceLockSurface before allocating memory by calling prepare. But when a pixel buffer is unmapped by calling AppleAVDUserClient::_unmapPixelBuffer, which calls AppleAVD::deallocateKernelMemoryInternal, the IOSurface is not locked before calling complete. This means that mapping and unmapping can occur at the same time, leading to kernel memory corruption. This bug could allow escalation to kernel privileges from a local app.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
AppleAVD deallocateKernelMemoryInternal Missing Surface Lock
https://3.bp.blogspot.com/-BKQJl1oXbqE/WWlvQjSZMJI/AAAAAAAAINE/UWb7sXt4uvssyXVrWpwrINbeIcIr93_vACLcBGAs/s1600/h33.png
In AppleAVD.kext, pixel buffers are mapped by calling AppleAVDUserClient::_mapPixelBuffer, which eventually calls AppleAVD::allocateKernelMemoryInternal. If the buffer is an IOSurface, the function calls IOSurface::deviceLockSurface before allocating memory by calling prepare. But when a pixel buffer is unmapped by calling AppleAVDUserClient::_unmapPixelBuffer, which calls AppleAVD::deallocateKernelMemoryInternal, the IOSurface is not locked before calling complete. This means that mapping and unmapping can occur at the same time, leading to kernel memory corruption. This bug could allow escalation to kernel privileges from a local app.
SHA-256 |
fa06dd34c9fcfaf9f03c6a70c7fd7fc078ff6872d40e76e3295731e58256ce8aDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
AppleAVD deallocateKernelMemoryInternal Missing Surface Lock
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
AppleAVD AppleAVDUserClient::decodeFrameFig Memory Corruption
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
In the function AppleAVDUserClient::decodeFrameFig, a location in the decoder's IOSurface input buffer is calculated, and then bzero is called on it. The size of this IOSurface's allocation is controllable by the userspace caller, so the calculated pointer can go out of bounds, leading to memory corruption. This issue could potentially allow an unprivileged local application to escalate its privileges to the kernel.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
AppleAVD AppleAVDUserClient::decodeFrameFig Memory Corruption
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
In the function AppleAVDUserClient::decodeFrameFig, a location in the decoder's IOSurface input buffer is calculated, and then bzero is called on it. The size of this IOSurface's allocation is controllable by the userspace caller, so the calculated pointer can go out of bounds, leading to memory corruption. This issue could potentially allow an unprivileged local application to escalate its privileges to the kernel.
SHA-256 |
a9f971c8dcec3381b92b6bafb61fc99c1b1da326eec460ede2682c51580f3f3eDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
AppleAVD AppleAVDUserClient::decodeFrameFig Memory Corruption
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.