Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cracking salted SHA1HASH passwords with Hashcat
I'm new to hashcat but I'm trying to use it to crack a salted SHA1DASH password. I have the salt obtained already.
I've been using this (http://willgenovese.com/cracking-zynga/) as a guide since it's essentially what I'm trying to do but I'm getting error messages, namely "token length exception".
I'm also getting "Failed to initialize NVIDIA RTC library"
*
Device #1: CUDA SDK Toolkit not installed or incorrectly installed. CUDA SDK Toolkit required for proper device support and utilization. Falling back to OpenCL runtime.
*
Device #1: WARNING! Kernel exec timeout is not disabled. This may cause "CL_OUT_OF_RESOURCES" or related errors. To disable the timeout, see: https://hashcat.net/q/timeoutpatch
For reference, the input is
hashcat -m 120 -a0 -w4 '[hash]:--[salt]--' C:\Users\user\Desktop\rockyou.txt -r C:\Users\user\Downloads\hashcat-6.2.5\rules\zynga.rule
I wouldn't be surprised if I've botched the syntax somehow.
submitted by /u/Hurriyett
[link] [comments]
Cracking salted SHA1HASH passwords with Hashcat
I'm new to hashcat but I'm trying to use it to crack a salted SHA1DASH password. I have the salt obtained already.
I've been using this (http://willgenovese.com/cracking-zynga/) as a guide since it's essentially what I'm trying to do but I'm getting error messages, namely "token length exception".
I'm also getting "Failed to initialize NVIDIA RTC library"
*
Device #1: CUDA SDK Toolkit not installed or incorrectly installed. CUDA SDK Toolkit required for proper device support and utilization. Falling back to OpenCL runtime.
*
Device #1: WARNING! Kernel exec timeout is not disabled. This may cause "CL_OUT_OF_RESOURCES" or related errors. To disable the timeout, see: https://hashcat.net/q/timeoutpatch
For reference, the input is
hashcat -m 120 -a0 -w4 '[hash]:--[salt]--' C:\Users\user\Desktop\rockyou.txt -r C:\Users\user\Downloads\hashcat-6.2.5\rules\zynga.rule
I wouldn't be surprised if I've botched the syntax somehow.
submitted by /u/Hurriyett
[link] [comments]
https://b.thumbs.redditmedia.com/BbL5h5rxZXm_cR_hYQ4UROXAKlSmJrFQW-6jYDzFLzI.jpg A while ago a specific set of websites were banned and the person who banned them moved out, after a few years I now want to use said websites and can't find a way how to as the website in question blocks all VPN's as they are associated with cheaters, I've tried using proxy websites and changing DNS servers, nothing works, here's nslookup results.
https://preview.redd.it/xlsgl633j66a1.png?width=387&format=png&auto=webp&s=148a656e00323257492ad4135634e3690bbfe067
I've found on other devices editing the /etc/hosts.txt file with the correct IP to domain usually works but I'm currently on a Chromebook running aarch64 Debian GNU/Linux 11 (bullseye).
submitted by /u/yupersSB
[link] [comments]
https://preview.redd.it/xlsgl633j66a1.png?width=387&format=png&auto=webp&s=148a656e00323257492ad4135634e3690bbfe067
I've found on other devices editing the /etc/hosts.txt file with the correct IP to domain usually works but I'm currently on a Chromebook running aarch64 Debian GNU/Linux 11 (bullseye).
submitted by /u/yupersSB
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I just hacked into a web app I built to fix some bugs during a code freeze
Fk me. My life’s a mess
submitted by /u/Born-Manufacturer-40
[link] [comments]
I just hacked into a web app I built to fix some bugs during a code freeze
Fk me. My life’s a mess
submitted by /u/Born-Manufacturer-40
[link] [comments]
Roadmap to learn Pentesting
https://www.reddit.com/r/Pentesting/comments/zn97j1/roadmap_to_learn_pentesting/
<!-- SC_OFF -->Hey guys. I’m new to Pentesting, with what thing should i start as a beginner ? <!-- SC_ON --> submitted by /u/Faizanafz (https://www.reddit.com/user/Faizanafz)
[link] (https://www.reddit.com/r/Pentesting/comments/zn97j1/roadmap_to_learn_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/zn97j1/roadmap_to_learn_pentesting/)
https://www.reddit.com/r/Pentesting/comments/zn97j1/roadmap_to_learn_pentesting/
<!-- SC_OFF -->Hey guys. I’m new to Pentesting, with what thing should i start as a beginner ? <!-- SC_ON --> submitted by /u/Faizanafz (https://www.reddit.com/user/Faizanafz)
[link] (https://www.reddit.com/r/Pentesting/comments/zn97j1/roadmap_to_learn_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/zn97j1/roadmap_to_learn_pentesting/)
Param Hunting to Injections
Hey hackers! How’s your week going?Continue reading on InfoSec Write-ups »
Read more...
Hey hackers! How’s your week going?Continue reading on InfoSec Write-ups »
Read more...
Hi Everyone,Continue reading on Medium » (https://kuhuk.medium.com/xss-stored-on-jd-id-ee73d73285de?source=rss------bug_bounty-5)
Param Hunting to Injections
https://infosecwriteups.com/param-hunting-to-injections-4365da5447cf?source=rss------bug_bounty-5
https://infosecwriteups.com/param-hunting-to-injections-4365da5447cf?source=rss------bug_bounty-5
Hey hackers! How’s your week going?Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/param-hunting-to-injections-4365da5447cf?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mention some of the ethical hackers’ security hacks.
https://cdn-images-1.medium.com/max/1080/1*zryh7DT6bxBageLpBPeMkg.jpeg
Mention some of the ethical hackers’ security hacks.
Continue reading on Medium »
Mention some of the ethical hackers’ security hacks.
https://cdn-images-1.medium.com/max/1080/1*zryh7DT6bxBageLpBPeMkg.jpeg
Mention some of the ethical hackers’ security hacks.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Information Gathering, is it Important?
Information Gathering, this word is familiar to warriors in cyber security. True? Because there is a saying that “Information is Power”.
Continue reading on Medium »
Information Gathering, is it Important?
Information Gathering, this word is familiar to warriors in cyber security. True? Because there is a saying that “Information is Power”.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers leak personal info allegedly stolen from 5.7M Gemini users
Hackers leak personal info allegedly stolen from 5.7M Gemini usersPost Views: 21 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Multiple posts on hacker forums offered to sell a database allegedly from Gemini containing phone numbers and email addresses of 5.7 million users.Gemini crypto exchange announced this week that customers were targeted in phishing campaigns after a threat actor collected their personal information from a third-party vendor.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Funds and account data secureThe Gemini product security team published a short notice that an unnamed third-party vendor suffered an “incident” that allowed an unauthorized actor to collect email addresses and incomplete phone numbers belonging to some Gemini customers.
As a result of the breach, customers of the crypto exchange received phishing emails. The goal of the attacker has not been disclosed but such access to accounts and financial information is typically what threat actors are after.
In its short report, Gemini underlines that account information and its systems have not been impacted and that funds and customer accounts “remain secure.”
Trending: Exploit XSS Injections in a one-line powerful Technique Trending: Offensive Security Tool: Pycrypt Hackers advertise Gemini databaseThe notification comes after multiple posts on a hacker forum offered to sell a database allegedly from Gemini containing phone numbers and email addresses of 5.7 million users.
An early attempt to monetize the database was in September. The author did not mention how fresh the info was but asked for 30 bitcoins (about $520,000 at the current exchange rate).
https://www.bleepstatic.com/images/news/u/1100723/2022/GeminiDB_30BTC.png
<figcaptionPost on hacker forum asking for 30 bitcoins for Gemini database with 5.7 million emails
source: KELA
In October, another post was published from a different alias claiming that the data was from September.
Yet another post under a different username (now banned on the forum) appeared in mid-November, offering databases from multiple crypto exchanges, including one from Gemini that supposedly had the same type of information for 5.7 million users.
It appears that none of the attempts to monetize the database worked as yet another announcement appeared on a different forum offering the information for free.
The author of the post shared the format of the phone numbers, specifying that the three digits in the middle are missing.
https://www.bleepstatic.com/images/news/u/1100723/2022/GeminiDB_leak.jpg
<figcaptionPost allegedly leaking Gemini database with 5.7 million emails and partial phone numbers
source: BleepingComputer
Gemini advises its customers to rely on strong authentication methods and recommends activating two-factor authentication (2FA) protection and/or the use of hardware security keys to access their accounts.
The company also provides the steps necessary for changing the email address associated with the Gemini account. Trending: Kali Linux 2022.4 – New Release adds 6 new tools, Kali NetHunter Update, Azure Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link[...]
Hackers leak personal info allegedly stolen from 5.7M Gemini users
Hackers leak personal info allegedly stolen from 5.7M Gemini usersPost Views: 21 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Multiple posts on hacker forums offered to sell a database allegedly from Gemini containing phone numbers and email addresses of 5.7 million users.Gemini crypto exchange announced this week that customers were targeted in phishing campaigns after a threat actor collected their personal information from a third-party vendor.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Funds and account data secureThe Gemini product security team published a short notice that an unnamed third-party vendor suffered an “incident” that allowed an unauthorized actor to collect email addresses and incomplete phone numbers belonging to some Gemini customers.
As a result of the breach, customers of the crypto exchange received phishing emails. The goal of the attacker has not been disclosed but such access to accounts and financial information is typically what threat actors are after.
In its short report, Gemini underlines that account information and its systems have not been impacted and that funds and customer accounts “remain secure.”
Trending: Exploit XSS Injections in a one-line powerful Technique Trending: Offensive Security Tool: Pycrypt Hackers advertise Gemini databaseThe notification comes after multiple posts on a hacker forum offered to sell a database allegedly from Gemini containing phone numbers and email addresses of 5.7 million users.
An early attempt to monetize the database was in September. The author did not mention how fresh the info was but asked for 30 bitcoins (about $520,000 at the current exchange rate).
https://www.bleepstatic.com/images/news/u/1100723/2022/GeminiDB_30BTC.png
<figcaptionPost on hacker forum asking for 30 bitcoins for Gemini database with 5.7 million emails
source: KELA
In October, another post was published from a different alias claiming that the data was from September.
Yet another post under a different username (now banned on the forum) appeared in mid-November, offering databases from multiple crypto exchanges, including one from Gemini that supposedly had the same type of information for 5.7 million users.
It appears that none of the attempts to monetize the database worked as yet another announcement appeared on a different forum offering the information for free.
The author of the post shared the format of the phone numbers, specifying that the three digits in the middle are missing.
https://www.bleepstatic.com/images/news/u/1100723/2022/GeminiDB_leak.jpg
<figcaptionPost allegedly leaking Gemini database with 5.7 million emails and partial phone numbers
source: BleepingComputer
Gemini advises its customers to rely on strong authentication methods and recommends activating two-factor authentication (2FA) protection and/or the use of hardware security keys to access their accounts.
The company also provides the steps necessary for changing the email address associated with the Gemini account. Trending: Kali Linux 2022.4 – New Release adds 6 new tools, Kali NetHunter Update, Azure Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers leak personal info allegedly stolen from 5.7M Gemini users Hackers leak personal info allegedly stolen from 5.7M Gemini usersPost Views: 21 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png…
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-2-300x150.png Microsoft patches Windows zero-day used to drop ransomwareDecember 15, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-1-300x150.png Apple security update fixes new iOS zero-day used to hack iPhonesDecember 14, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-300x150.png New Python malware backdoors VMware ESXi servers for remote accessDecember 13, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/1-300x150.png JSON syntax hack allowed SQL injection payloads to be smuggled past WAFsDecember 12, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Hackers leak personal info allegedly stolen from 5.7M Gemini users first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-1-300x150.png Apple security update fixes new iOS zero-day used to hack iPhonesDecember 14, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-300x150.png New Python malware backdoors VMware ESXi servers for remote accessDecember 13, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/1-300x150.png JSON syntax hack allowed SQL injection payloads to be smuggled past WAFsDecember 12, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Hackers leak personal info allegedly stolen from 5.7M Gemini users first appeared on Black Hat Ethical Hacking.