Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Can I be traced through a tunnel?

I don't know much about hacking but in case this is an issue I'm asking here. I have a website for some family and friends pictures that only me and a few other people know about. I am selfhosting with my desktop pc and I'm using Packetriot to tunnel and expose it to the world with my custom domain. However with this method I'm a little worried that hackers or law enforcement can trace me. I know 100% safety isn't ever guaranteed but am I safe? I'm not doing anything illegal, I am worried about law enforcement because I live in a country where our internet is monitored. Many thanks everyone!

submitted by /u/FaDe_Flamez
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How does Metasploit socks_proxy module work?

I've been trying to learn more about pivoting, one simple pivoting technique is Metasploit socks proxy module with proxychains, I've been looking for an answer all over the internet with no luck. How does the socks proxy module work? and how to use it to chain more that 2 targets. I know that for the first proxy hop I can just run the socks proxy server module with my IP and any port but how does socks proxy server know where to forward the request?

submitted by /u/hazemslife
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How can triggering DNS lookups on a foreign system be a security threat?

In Text4shell (CVE-2022-42889) there are 3 potential security vulnerabilities which are triggered by String substitution marked by specific prefixes, which could lead to problems. One of them is "script" which can lead to code injection, self explainatory.

The other two are "dns" and "url" which according to the CVE "could result in (...) contact with remote servers".

I can't quite understand why pure contact with remote servers is a security concern. How is it exploitable to make dns lookups for the hostname of an ip address via a foreign system? Why should that be a problem? To map out internal structure if its a bigger network?

submitted by /u/mangyCarl3
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Http Injector internet hotshare

Has anybody here used http injector? I've been connected to a good server and i want to share the internet to my laptop, did all the steps to get it (the hotshare and the proxy thing) but i haven't get it already, it doesn't connect. Any tips? I'm a begginer in this shit.

submitted by /u/FernandoJuncal98
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Phone hack

Can your phone get hacked by a fb messenger video call?

submitted by /u/notsonice333
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Pool on the roof - November 28, 2022

Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?

This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.

Make sure to read our wiki as it's full of resources for you.

Keep all beginner questions in this weekly stickied post.

submitted by /u/AutoModerator
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
5.4 million Twitter users’ stolen data leaked online

5.4 million Twitter users’ stolen data leaked onlinePost Views: 67 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Over 5.4 million Twitter user records containing non-public information stolen using an API vulnerability fixed in January have been shared for free on a hacker forum.Another massive, potentially more significant, data dump of millions of Twitter records has also been disclosed by a security researcher, demonstrating how widely abused this bug was by threat actors.

The data consists of scraped public information as well as private phone numbers and email addresses that are not meant to be public.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course The Twitter data breachLast July, a threat actor began selling the private information of over 5.4 million Twitter users on a hacking forum for $30,000.

While most of the data consisted of public information, such as Twitter IDs, names, login names, locations, and verified status, it also included private information, such as phone numbers and email addresses.

https://www.bleepstatic.com/images/news/security/d/data-breaches/t/twitter-h1-vuln/forum-post.jpg
Twitter data shared on a hacking forumIn September, and now more recently, on November 24th, the 5.4 million Twitter records have now been shared for free on a hacking forum.
https://www.bleepstatic.com/images/news/security/d/data-breaches/t/twitter/data-shared-online/forum-post.jpg
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking 5.4 million Twitter users’ stolen data leaked online 5.4 million Twitter users’ stolen data leaked onlinePost Views: 67 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon…
ber, and public scraped data, including the account’s Twitter ID, name, screen name, verified status, location, URL, description, follower count, account creation date, friends count, favorites count, statuses count, and profile image URLs. An even larger data dump privately createdWhile it is concerning that threat actors released the 5.4 million records for free, an even larger data dump was allegedly created using the same vulnerability.

This data dump potentially contains tens of millions of Twitter records consisting of personal phone numbers collected using the same API bug, and public information, including verified status, account names, Twitter ID, bio, and screen name.

The news of this more significant data breach comes from security expert Chad Loder, who first broke the news on Twitter and was suspended soon after posting. Loder subsequently posted a redacted sample of this larger data breach on Mastodon.

“I have just received evidence of a massive Twitter data breach affecting millions of Twitter accounts in EU and US. I have contacted a sample of the affected accounts and they confirmed that the breached data is accurate. This breach occurred no earlier than 2021,” Loder shared on Twitter.
https://www.bleepstatic.com/images/news/security/d/data-breaches/t/twitter/data-shared-online/mastodon-post.jpg
Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-9-300x150.png Google pushes emergency Chrome update to fix 8th zero-day this yearNovember 25, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-8-2-300x150.png Fake MSI Afterburner targets Windows gamers with miners, info-stealersNovem[...]

___________________________
@hacking_Attack
@Hacking_Video