hacking: security in practice
GeHot Opintions
It's back to GeHot (George Hotz) after several years, the software engineer who is now teaming up with Musk and has become the typical exalted (I think); but I didn't want to speak about that.
He at 17 managed to find the first jailbreak for iOs and I was wondering:
how does a 17-year-old boy have the skills necessary to be able to make a jailbreak? Where does he get his knowledge? Is this all true or is it a fictional story?
Do you have any opinions about this?
submitted by /u/allmudi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
GeHot Opintions
It's back to GeHot (George Hotz) after several years, the software engineer who is now teaming up with Musk and has become the typical exalted (I think); but I didn't want to speak about that.
He at 17 managed to find the first jailbreak for iOs and I was wondering:
how does a 17-year-old boy have the skills necessary to be able to make a jailbreak? Where does he get his knowledge? Is this all true or is it a fictional story?
Do you have any opinions about this?
submitted by /u/allmudi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
GeHot Opintions
It's back to [GeHot](https://en.wikipedia.org/wiki/George_Hotz) (George Hotz) after several years, the software engineer who is now teaming up...
For auth, Why do attackers need the secret key for jwt verification when it’s in the .env file?
https://www.reddit.com/r/Pentesting/comments/z6ffn4/for_auth_why_do_attackers_need_the_secret_key_for/
I’ve been through several tutorials claiming that you should use a refresh token to generate the new access token, and to not use the access token to generate a new access token because then an attacker who got the access token can re authenticate themselves. Apparently an attacker who gets the refresh token would still need to get the secret… But if the server is running, and they use the endpoint that creates a new access token, then the code is going to look something like: jwt.verify(process.env.SECRETKEY…) See…. Aren’t we giving the attacker the secret key in the above code because the code uses the secret to verify, and then we’d just create a new access token and give it to the attacker? submitted by /u/Impossible_Map_2355 (https://www.reddit.com/user/Impossible_Map_2355)
[link] (https://www.reddit.com/r/Pentesting/comments/z6ffn4/for_auth_why_do_attackers_need_the_secret_key_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/z6ffn4/for_auth_why_do_attackers_need_the_secret_key_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/z6ffn4/for_auth_why_do_attackers_need_the_secret_key_for/
I’ve been through several tutorials claiming that you should use a refresh token to generate the new access token, and to not use the access token to generate a new access token because then an attacker who got the access token can re authenticate themselves. Apparently an attacker who gets the refresh token would still need to get the secret… But if the server is running, and they use the endpoint that creates a new access token, then the code is going to look something like: jwt.verify(process.env.SECRETKEY…) See…. Aren’t we giving the attacker the secret key in the above code because the code uses the secret to verify, and then we’d just create a new access token and give it to the attacker? submitted by /u/Impossible_Map_2355 (https://www.reddit.com/user/Impossible_Map_2355)
[link] (https://www.reddit.com/r/Pentesting/comments/z6ffn4/for_auth_why_do_attackers_need_the_secret_key_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/z6ffn4/for_auth_why_do_attackers_need_the_secret_key_for/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
For auth, Why do attackers need the secret key for jwt...
I’ve been through several tutorials claiming that you should use a refresh token to generate the new access token, and to not use the access token...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mbretërimi i kaosit i hakerave iranianë: Si u shpartallua shteti shqiptar nga sulmi kibernetik
https://cdn-images-1.medium.com/max/1280/1*uc3n5az4lmkalJ0l96OJZw.jpeg
Nga Xhildinho Ozuni
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Mbretërimi i kaosit i hakerave iranianë: Si u shpartallua shteti shqiptar nga sulmi kibernetik
https://cdn-images-1.medium.com/max/1280/1*uc3n5az4lmkalJ0l96OJZw.jpeg
Nga Xhildinho Ozuni
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Mbretërimi i kaosit i hakerave iranianë: Si u shpartallua shteti shqiptar nga sulmi kibernetik
Nga Xhildinho Ozuni
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Four Essential YouTube Channels To Learn Programming in 2022
https://cdn-images-1.medium.com/max/1024/1*M1sgHLoaUOooWFqxJ6EdIA.jpeg
Screenshot and cropped from YouTube
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Four Essential YouTube Channels To Learn Programming in 2022
https://cdn-images-1.medium.com/max/1024/1*M1sgHLoaUOooWFqxJ6EdIA.jpeg
Screenshot and cropped from YouTube
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Four Essential YouTube Channels To Learn Programming in 2022
Screenshot and cropped from YouTube
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Not Get Hacked, Phished, or Scammed on The Internet
https://cdn-images-1.medium.com/max/2600/1*t9YXW0odkT1gEFtBaglZsA.png
TL;DR- The internet and it’s cronies. The people who try and phish you or scam you for money, political agenda, or just for kicks.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
How to Not Get Hacked, Phished, or Scammed on The Internet
https://cdn-images-1.medium.com/max/2600/1*t9YXW0odkT1gEFtBaglZsA.png
TL;DR- The internet and it’s cronies. The people who try and phish you or scam you for money, political agenda, or just for kicks.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How To: Not Get Hacked, Phished, or Scammed on The Internet
TL;DR- The internet and it’s cronies. The people who try and phish you or scam you for money, political agenda, or just for kicks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DVIUS: The New Age of Cyber Hackers Is Upon Us
https://cdn-images-1.medium.com/max/600/0*Uk-JbP3V3WMpNUH2
Think you know what the New World Order will be like?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DVIUS: The New Age of Cyber Hackers Is Upon Us
https://cdn-images-1.medium.com/max/600/0*Uk-JbP3V3WMpNUH2
Think you know what the New World Order will be like?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DVIUS: The New Age of Cyber Hackers Is Upon Us
Think you know what the New World Order will be like? Maybe you never think about it. Since the internet became a thing we have advanced so…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
OSINT | Full Course | Beginners
https://external-preview.redd.it/cVe_J0OfW80B2ySLshrfuSc1RHzj2oROIwANax9Q6HU.jpg?width=320&crop=smart&auto=webp&s=20406d7feb90ec6ccc85861404d9e51bc0997ab2 submitted by /u/Anon_4620
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
OSINT | Full Course | Beginners
https://external-preview.redd.it/cVe_J0OfW80B2ySLshrfuSc1RHzj2oROIwANax9Q6HU.jpg?width=320&crop=smart&auto=webp&s=20406d7feb90ec6ccc85861404d9e51bc0997ab2 submitted by /u/Anon_4620
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
OSINT | Full Course | Beginners
Posted in r/hacking by u/Anon_4620 • 222 points and 1 comment
hacking: security in practice
Your Account was Breached
Lookin for best practices - what are you doin to confirm device security after someone successfully breaches one of your online accounts?
submitted by /u/flasktorch
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Your Account was Breached
Lookin for best practices - what are you doin to confirm device security after someone successfully breaches one of your online accounts?
submitted by /u/flasktorch
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Your Account was Breached
Lookin for best practices - what are you doin to confirm device security after you receive un-authorized 2fa login requests?
What is Bug Bounty & How to Get Started?
A Definitive Guide to Bug BountyContinue reading on Bug Zero »
Read more...
A Definitive Guide to Bug BountyContinue reading on Bug Zero »
Read more...
Bug Bounty Programs: What Are They?
Everything You Should KnowContinue reading on Bug Zero »
Read more...
Everything You Should KnowContinue reading on Bug Zero »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box [HTB] Writeup: Precious
https://cdn-images-1.medium.com/max/687/1*wlI7Nrb4YMwmkr64KmXyyQ.png
Hack the Box released a new machine this weekend called Precious and I was excited to get my hands on it. Precious is an easy rated Linux…
Continue reading on Medium »
Hack The Box [HTB] Writeup: Precious
https://cdn-images-1.medium.com/max/687/1*wlI7Nrb4YMwmkr64KmXyyQ.png
Hack the Box released a new machine this weekend called Precious and I was excited to get my hands on it. Precious is an easy rated Linux…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Bug Bounty & How to Get Started?
https://cdn-images-1.medium.com/max/2600/0*Xt-IxhxLcwPGvRrr
A Definitive Guide to Bug Bounty
Continue reading on Bug Zero »
What is Bug Bounty & How to Get Started?
https://cdn-images-1.medium.com/max/2600/0*Xt-IxhxLcwPGvRrr
A Definitive Guide to Bug Bounty
Continue reading on Bug Zero »