Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Explaining vulnerabilities : File inclusion {Bug bounties}

File inclusion vulnerabilities are part of the OWASP top ten. In this article, I’ll explain what they are,how to find them, how to exploit…Continue reading on Medium »
Read more...
hacking: security in practice
Is this idea risky?

Hi, I'm currently thinking of making a modern password manager as a web app. It saves the passwords in a encrypted file and has to be picked (and entered the password afterwards) to read the passwords. Completely locally. Is it a good or bad idea? What are the risks (except the AES encryption being able to be cracked)?

submitted by /u/srt54558
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hello everyone I want to know if the fact that the CSP header not set for json response can be a source of problem let me explain more : I have a web app, that will send as a response html page with js (let's say csp is set ) the js will make a call to an api so in this api response do we need csp if yes what is the need for it ? there is any xss in javascript ? ​ I've just done a owasp zap scan and I found the header not set so I'm wondering is it a problem ​ https://preview.redd.it/54lirlbv682a1.png?width=503&format=png&auto=webp&s=c47ac31ebb02bbe500ca2c85b69e90340d8309cf sorry if it's a stupid question submitted by /u/firend_of_laki (https://www.reddit.com/user/firend_of_laki)
[link] (https://www.reddit.com/r/Pentesting/comments/z4yd94/do_we_need_to_set_a_content_security_policy_on_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/z4yd94/do_we_need_to_set_a_content_security_policy_on_a/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
SQL dump keywords

What are some good keywords to search for on an sql dump that are note the basics like password and username?

submitted by /u/SgtMorningWood009
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
How I hacked into a government e-learning website

DATE: 07/11/2022Continue reading on Medium »
Read more...