Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Question about finding vulnerable JS plugins config versions, etc.
https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/

<!-- SC_OFF -->Hi, I am an intern for pentest and just starting out. I never had formal IT/Computer Science background and only done pentest bootcamps and a company was willing to hire me as an intern. I would like to ask something about web applications. I was using BurpSuite and came up with a vulnerable version of bootstrap 4.0.0: Upon checking it is vulnerable to XSS: Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in data-template, data-content and data-title properties of tooltip/popover. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the tooltip, collapse and scrollspy plugins. After crawling the whole website, I tried filtering data-template, tooltip, etc. but most of them are in .js files. I would like to ask how can I test for vulnerabilities and how can I spot which js config/ plugin is being used. Thanks! <!-- SC_ON --> submitted by /u/desecratedhuman (https://www.reddit.com/user/desecratedhuman)
[link] (https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm6akn/question_about_finding_vulnerable_js_plugins/)
Looking for Pentesting in the PDX area
https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/

<!-- SC_OFF -->I am an IT Manager for a company and I have to have a PenTest for my org each year. Very simple setup with 3 sights locally. Any recommendations? <!-- SC_ON --> submitted by /u/Luxtaposition (https://www.reddit.com/user/Luxtaposition)
[link] (https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm6td4/looking_for_pentesting_in_the_pdx_area/)
How To Exploit File Inclusion Vulnerabilities: A Beginner’s Introduction. — StackZero

In this article, we will be exploring the ins and outs of file inclusion vulnerability exploitation.Continue reading on InfoSec Write-ups »
Read more...
In this article, we will be exploring the ins and outs of file inclusion vulnerability exploitation.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-to-exploit-file-inclusion-vulnerabilities-a-beginners-introduction-stackzero-a55267b5fafb?source=rss------bug_bounty-5)
Business logic vulnerabilities
https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/

<!-- SC_OFF -->Hi Guys, I consider myself bellow average when it comes to find Business logic vulnerabilities, and I want to improve in it. how do you deal with this kind of vulnerabilities?, what advises would you give to move forward? <!-- SC_ON --> submitted by /u/Abofouad (https://www.reddit.com/user/Abofouad)
[link] (https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/) [comments] (https://www.reddit.com/r/redteamsec/comments/zm6f78/business_logic_vulnerabilities/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Any suggestion on data recovery software on protected .zip (file's contents unencrypted)?

I have an album zipped with a passcode, and the file's contents are all unencrypted. I have too many hours already trying JohnRipper / Hashcat, but I wasn't able to get them working properly.

I was wondering if using data recovery software is a possible option. Any anyone tried this?
Any advice or recommendation would be greatly appreciated.

submitted by /u/dream996
[link] [comments]
How much time do you get for training at work?
https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/

<!-- SC_OFF -->Hi everyone, I am currently a security consultant / penetration tester at a security consultancy. Now I’m wondering how training / up skilling works at your current company or previous ones. Right now I effectively only am given time to train when there is gaps on my schedule where there is no client work. I want to suggest some ideas to my employer because currently I have had zero time to train for the last 3 months it’s just been job after job non stop, and I’m feeling pretty exhausted and burnt out. Is this considered normal? I want to hear other peoples experiences. Thanks :) <!-- SC_ON --> submitted by /u/DarkInnerSelf (https://www.reddit.com/user/DarkInnerSelf)
[link] (https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/) [comments] (https://www.reddit.com/r/Pentesting/comments/zm8dqp/how_much_time_do_you_get_for_training_at_work/)