Question about finding vulnerable JS plugins config versions, etc.
https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/
<!-- SC_OFF -->Hi, I am an intern for pentest and just starting out. I never had formal IT/Computer Science background and only done pentest bootcamps and a company was willing to hire me as an intern. I would like to ask something about web applications. I was using BurpSuite and came up with a vulnerable version of bootstrap 4.0.0: Upon checking it is vulnerable to XSS: Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in data-template, data-content and data-title properties of tooltip/popover. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the tooltip, collapse and scrollspy plugins. After crawling the whole website, I tried filtering data-template, tooltip, etc. but most of them are in .js files. I would like to ask how can I test for vulnerabilities and how can I spot which js config/ plugin is being used. Thanks! <!-- SC_ON --> submitted by /u/desecratedhuman (https://www.reddit.com/user/desecratedhuman)
[link] (https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/)
https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/
<!-- SC_OFF -->Hi, I am an intern for pentest and just starting out. I never had formal IT/Computer Science background and only done pentest bootcamps and a company was willing to hire me as an intern. I would like to ask something about web applications. I was using BurpSuite and came up with a vulnerable version of bootstrap 4.0.0: Upon checking it is vulnerable to XSS: Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in data-template, data-content and data-title properties of tooltip/popover. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the tooltip, collapse and scrollspy plugins. After crawling the whole website, I tried filtering data-template, tooltip, etc. but most of them are in .js files. I would like to ask how can I test for vulnerabilities and how can I spot which js config/ plugin is being used. Thanks! <!-- SC_ON --> submitted by /u/desecratedhuman (https://www.reddit.com/user/desecratedhuman)
[link] (https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/)
Looking for Pentesting in the PDX area
https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/
<!-- SC_OFF -->I am an IT Manager for a company and I have to have a PenTest for my org each year. Very simple setup with 3 sights locally. Any recommendations? <!-- SC_ON --> submitted by /u/Luxtaposition (https://www.reddit.com/user/Luxtaposition)
[link] (https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/)
https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/
<!-- SC_OFF -->I am an IT Manager for a company and I have to have a PenTest for my org each year. Very simple setup with 3 sights locally. Any recommendations? <!-- SC_ON --> submitted by /u/Luxtaposition (https://www.reddit.com/user/Luxtaposition)
[link] (https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Exploit File Inclusion Vulnerabilities: A Beginner’s Introduction. — StackZero
https://cdn-images-1.medium.com/max/1200/0*du4_D8tDoxXvJlp4.jpg
In this article, we will be exploring the ins and outs of file inclusion vulnerability exploitation.
Continue reading on InfoSec Write-ups »
How To Exploit File Inclusion Vulnerabilities: A Beginner’s Introduction. — StackZero
https://cdn-images-1.medium.com/max/1200/0*du4_D8tDoxXvJlp4.jpg
In this article, we will be exploring the ins and outs of file inclusion vulnerability exploitation.
Continue reading on InfoSec Write-ups »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Vulnerability Analysis — Finding weakness and Exploiting them.
https://cdn-images-1.medium.com/max/2600/1*mkMiC6mVVgx1-YKhfZ5Bnw.png
A vulnerability assessment is a systematic review of security weaknesses in a networked system. It evaluates if the system is susceptible…
Continue reading on Medium »
Vulnerability Analysis — Finding weakness and Exploiting them.
https://cdn-images-1.medium.com/max/2600/1*mkMiC6mVVgx1-YKhfZ5Bnw.png
A vulnerability assessment is a systematic review of security weaknesses in a networked system. It evaluates if the system is susceptible…
Continue reading on Medium »
How To Exploit File Inclusion Vulnerabilities: A Beginner’s Introduction. — StackZero
In this article, we will be exploring the ins and outs of file inclusion vulnerability exploitation.Continue reading on InfoSec Write-ups »
Read more...
In this article, we will be exploring the ins and outs of file inclusion vulnerability exploitation.Continue reading on InfoSec Write-ups »
Read more...
How To Exploit File Inclusion Vulnerabilities: A Beginner’s Introduction. — StackZero
https://infosecwriteups.com/how-to-exploit-file-inclusion-vulnerabilities-a-beginners-introduction-stackzero-a55267b5fafb?source=rss------bug_bounty-5
https://infosecwriteups.com/how-to-exploit-file-inclusion-vulnerabilities-a-beginners-introduction-stackzero-a55267b5fafb?source=rss------bug_bounty-5
In this article, we will be exploring the ins and outs of file inclusion vulnerability exploitation.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-to-exploit-file-inclusion-vulnerabilities-a-beginners-introduction-stackzero-a55267b5fafb?source=rss------bug_bounty-5)
Business logic vulnerabilities
https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/
<!-- SC_OFF -->Hi Guys, I consider myself bellow average when it comes to find Business logic vulnerabilities, and I want to improve in it. how do you deal with this kind of vulnerabilities?, what advises would you give to move forward? <!-- SC_ON --> submitted by /u/Abofouad (https://www.reddit.com/user/Abofouad)
[link] (https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/) [comments] (https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/)
https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/
<!-- SC_OFF -->Hi Guys, I consider myself bellow average when it comes to find Business logic vulnerabilities, and I want to improve in it. how do you deal with this kind of vulnerabilities?, what advises would you give to move forward? <!-- SC_ON --> submitted by /u/Abofouad (https://www.reddit.com/user/Abofouad)
[link] (https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/) [comments] (https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Got an esp32 working as a Rubber Ducky but cheaper and with wifi (and in the future, bluetooth too)! And it still keeps the standard USB size format.
https://external-preview.redd.it/ZUlNNKO6w7qsiGHKm2ht72IJUwQfnRf8XtqkonUWIig.jpg?width=640&crop=smart&auto=webp&s=0886f26f887b433a9e7037c27eaf054d30a3d715 submitted by /u/LockManipulator
[link] [comments]
Got an esp32 working as a Rubber Ducky but cheaper and with wifi (and in the future, bluetooth too)! And it still keeps the standard USB size format.
https://external-preview.redd.it/ZUlNNKO6w7qsiGHKm2ht72IJUwQfnRf8XtqkonUWIig.jpg?width=640&crop=smart&auto=webp&s=0886f26f887b433a9e7037c27eaf054d30a3d715 submitted by /u/LockManipulator
[link] [comments]
https://b.thumbs.redditmedia.com/is7FFBX5Nb-AJXr7f-TrdY6HVPGaeg_Fh1hbeVvj-RA.jpg Also, in case there is no way to refund it, any suggestions how to fix it?
https://preview.redd.it/3vcb03r46y5a1.jpg?width=1024&format=pjpg&auto=webp&s=e9df2f6e636ee496b15714f8da320d5101b01597
submitted by /u/Blicked33
[link] [comments]
https://preview.redd.it/3vcb03r46y5a1.jpg?width=1024&format=pjpg&auto=webp&s=e9df2f6e636ee496b15714f8da320d5101b01597
submitted by /u/Blicked33
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Any suggestion on data recovery software on protected .zip (file's contents unencrypted)?
I have an album zipped with a passcode, and the file's contents are all unencrypted. I have too many hours already trying JohnRipper / Hashcat, but I wasn't able to get them working properly.
I was wondering if using data recovery software is a possible option. Any anyone tried this?
Any advice or recommendation would be greatly appreciated.
submitted by /u/dream996
[link] [comments]
Any suggestion on data recovery software on protected .zip (file's contents unencrypted)?
I have an album zipped with a passcode, and the file's contents are all unencrypted. I have too many hours already trying JohnRipper / Hashcat, but I wasn't able to get them working properly.
I was wondering if using data recovery software is a possible option. Any anyone tried this?
Any advice or recommendation would be greatly appreciated.
submitted by /u/dream996
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
How much time do you get for training at work?
https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/
<!-- SC_OFF -->Hi everyone, I am currently a security consultant / penetration tester at a security consultancy. Now I’m wondering how training / up skilling works at your current company or previous ones. Right now I effectively only am given time to train when there is gaps on my schedule where there is no client work. I want to suggest some ideas to my employer because currently I have had zero time to train for the last 3 months it’s just been job after job non stop, and I’m feeling pretty exhausted and burnt out. Is this considered normal? I want to hear other peoples experiences. Thanks :) <!-- SC_ON --> submitted by /u/DarkInnerSelf (https://www.reddit.com/user/DarkInnerSelf)
[link] (https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/)
https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/
<!-- SC_OFF -->Hi everyone, I am currently a security consultant / penetration tester at a security consultancy. Now I’m wondering how training / up skilling works at your current company or previous ones. Right now I effectively only am given time to train when there is gaps on my schedule where there is no client work. I want to suggest some ideas to my employer because currently I have had zero time to train for the last 3 months it’s just been job after job non stop, and I’m feeling pretty exhausted and burnt out. Is this considered normal? I want to hear other peoples experiences. Thanks :) <!-- SC_ON --> submitted by /u/DarkInnerSelf (https://www.reddit.com/user/DarkInnerSelf)
[link] (https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/)