Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Adversarial AI Attacks Highlight Fundamental Security Issues

An AI's "world" only includes the data on which it was trained, so it otherwise lacks context — opening the door for creative attacks from cyber adversaries.
Dark Reading: Attacks/Breaches
Ducktail Cyberattackers Add WhatsApp to Facebook Business Attack Chain

The Vietnam-based financial cybercrime operation's primary goal is to push out fraudulent ads via compromised business accounts.
How can an https link been used for port scanning ?
https://www.reddit.com/r/Pentesting/comments/z2dlx5/how_can_an_https_link_been_used_for_port_scanning/

hello community I'm not sure if I did understand this but I found that we can use https://example.com: (https://x:80/)port and change the port to 80 ... to do a port scaning (this in the context of SSRF) so from the networking courses I think is that we can know that the port is opened ,because when we use https this means that we will establish a TCP 3W handshake-> then tls wish will fail in this example if the port was 80 for http when we saw that there was a connection established we now the port is open, am I right ? also please if you know a community ,where we can ask beginner question without being judged ,or posting irrelevant posts to the community can You please let me know thanks for your help submitted by /u/firend_of_laki (https://www.reddit.com/user/firend_of_laki)
[link] (https://www.reddit.com/r/Pentesting/comments/z2dlx5/how_can_an_https_link_been_used_for_port_scanning/) [comments] (https://www.reddit.com/r/Pentesting/comments/z2dlx5/how_can_an_https_link_been_used_for_port_scanning/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Getting started with bettercap

I thought I had all capabilities installed and am not able to move past successfully pulling and building with docker. Just when I run the command to install the Web Ui it doesn't recognize the caplets update command. Any ideas would be greatly appreciated.

I'm using this tutorial to give you an idea of where I'm at.

submitted by /u/Conscious_Pride_5098
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Overbearing Employer, https protocol inquiry

So my current employer is what seems to be monitoring our every move from laptops. We work through a what I guess is an https hand shake. Work is performed and completed, however there are large gaps of time between assignments, they expect us to entertain the notion that we will do nothing beyond staring at the screen with little to no other activity. I love to read books and Manga, I have tons stored on said pc in pdf and .text format. Netstat on windows 10 showed only tcp traffic on the device but I'm not aware what other methods they have at their disposal to monitor our activity. Is it possible to read while on the clock and logged into the https Chrome browser and keep reading pdfs/texts documents without them seeing/knowing. I was thinking about installing virtual box and running Linux to try to hide it with no web connectivity through the vm, but not sure. Please help before I die from boredom....

Edit. I have been a linux daily users for over a decade at home, I'm not very familiar with windows beyond 98. So forgive my ignorance.

We work on location logged into their router, we are supplied laptops with windows 10 heavily modified with proprietary software. They have an https connection through chrome browser that almost locks out any other activity. I'm afraid to even minimize the browser as I'm not certain what could happen.

submitted by /u/Rotteapple
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
How To Exploit CSRF In DVWA — StackZero

This tutorial will show you how to exploit a CSRF vulnerability in the DVWA. You will learn some techniques to inject a malicious formContinue reading on InfoSec Write-ups »
Read more...
BITRA Comes To Azbit

BITRA is the native currency of the BugSpace cybersecurity project. The team provides bug hunting services to large companies, ensuring…Continue reading on Azbit News »
Read more...