Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
The Next Generation of Supply Chain Attacks Is Here to Stay

With the proliferation of interconnected third-party applications, new strategies are needed to close the security gap.
Dark Reading: Attacks/Breaches
Palo Alto Networks Focuses on Secure Coding with $195M Cider Deal

PAN plans to add Cider's CI/CD security platform to its Prisma Cloud suite of AppSec tools.
Dark Reading: Attacks/Breaches
Secure Offboarding in the Spotlight as Tech Layoffs Mount

A secure-by-design culture is needed to develop a comprehensive offboarding and identity management strategy that limits potential for broader compromise in case of unauthorized access.
How i found 8 vulnerabilities in 24h?

Hello Awesome Hackers, I hope you all doing well! My name is Mohamed Anani Or 0xM5awy.Continue reading on Medium »
Read more...
How I found CVE-2022–40088

Hey Squad,Continue reading on Medium »
Read more...
hacking: security in practice
How you create characters for brute force

I just started ny journey in this field and I always fail to understand how the heack you can use brute force on passwords with infinite alphanumeric combinations ? How you make a file that runs a bruteforce for every combination available ?seems impossible

submitted by /u/Darknightlife
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can other security professionals passively see Spiderfoot checking out a company?

Recently I was contacted by the CEO of a smallish company who has been the target of an aggressive SMShing campaign. After speaking with them I was trying to figure out whether it was coming from within the company because a few factors pointed to that as a possibility

I ran spiderfoot on their domain to see how easily obtainable their employees info is from an OSINT perspective and now suddenly the CEO and other members of their leadership team are getting adds from other cybersecurity professionals on LinkedIn

I am wondering if this is a total coincidence or if somehow those security peeps were tipped of by the fact that I was running that tool?

submitted by /u/newSOCs
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
First time CTF

Hey all, my friend wants to enter a CTF for the fun of it. We both work on IT and have base security knowledge. I haven't done a lot in cyber security for awhile now but thought it would be fun to catch up and do something different.

I wanted to do some prep work so I am somewhat prepared.

Any tips for a first CTF event?

submitted by /u/IT_Pyro
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Finding a job in computer security with a criminal record

Hi all, I'm wondering if anyone has an advice or thoughts about getting a job in computer security with a criminal record.

Specifically, I have two federal misdemeanor convictions for unauthorized computer use related to a dumb attempt I made to leak Trump's taxes right before the 2016 election (back when I was a lot more hot-headed and politically motivated -- I certainly wouldn't do anything dumb or illegal like that today). I've since completed all the community service and probation. The actual hack wasn't all that technical, aside from a 0-day in Windows I had discovered that let me create admin accounts on my college's lab computers. For context, you can read more about the overall attempt here.

Since then, I've kept my nose clean and have continued to study computer security-related stuff in school. I have an BS in math, a BA in Russian, and a Master's of Science in machine learning and signals processing. Almost every time I've gotten to choose a project in my schooling, I've picked a topic that relates back to security/privacy, from cryptography and hacking smart locks, to using adversarial/malicious ML tools for everything from voice spoofing to captcha cracking. Where applicable, I've also done my best to make ethical disclosures. At this point in life, I very much consider myself in the white hat camp.

The reason I'm writing this is because I was recently denied a position that really excited me with a technical consulting firm after my background came up. This was despite the fact that their assistant director of cloud security was the one advocating for me. I was told by a few people in the industry that because of my record I'll never be able to get a job in the field. I'm feeling pretty disheartened and am wondering if it's time for me to switch gears again. What do you all think? Is there still some way I can combine my passions for machine learning and computer security and get paid to do it? Does anyone have any suggestions of places I might apply to?

submitted by /u/jhiems
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video