Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hiding text in files
Awhile back I was looking at some malicious stuff that showed up on someone's server and one of the tricks they did was to hide a bunch of javascript in template files. If you catted the file or viewed it in nano you saw nothing. View it in vi and poof, bunch of malicious code.
Thought it was kind of cool but didn't take notes or keep samples. Year later I find a need for this for a project. Google searches were somewhat unhelpful since all manner of stupid stuff matches.
Anyone know what the method is called so I can do more research?
submitted by /u/FantasticThing359
[link] [comments]
Hiding text in files
Awhile back I was looking at some malicious stuff that showed up on someone's server and one of the tricks they did was to hide a bunch of javascript in template files. If you catted the file or viewed it in nano you saw nothing. View it in vi and poof, bunch of malicious code.
Thought it was kind of cool but didn't take notes or keep samples. Year later I find a need for this for a project. Google searches were somewhat unhelpful since all manner of stupid stuff matches.
Anyone know what the method is called so I can do more research?
submitted by /u/FantasticThing359
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is there phones who call without a sim card
So i am looking to find a device, that can call normally without a sim card, and that is also able to set custom caller id (so i can call as somebody else)
Btw i am not looking to do anything illegal or harmful with such a device, all i am asking for is what is such a device called, where can i buy one, and also if there is no such device whats the closest thing to it?
submitted by /u/PreciseInstance
[link] [comments]
Is there phones who call without a sim card
So i am looking to find a device, that can call normally without a sim card, and that is also able to set custom caller id (so i can call as somebody else)
Btw i am not looking to do anything illegal or harmful with such a device, all i am asking for is what is such a device called, where can i buy one, and also if there is no such device whats the closest thing to it?
submitted by /u/PreciseInstance
[link] [comments]
Attacker Simulation and Vulnerability Management Programs
https://www.reddit.com/r/Pentesting/comments/10a77au/attacker_simulation_and_vulnerability_management/
<!-- SC_OFF -->I am struggling with implementing SafeBreach at my organization and I was hoping I could get some peer feed back on how they have implemented SafeBreach or other Attack/Adversary emulation tools within their organization. My primary question is how do you make use of your simulation results? It is hard to find value in these products when you are running the same tests every week with nearly the same results. It is pretty difficult to make impactful changes to the org's security tooling and posture to have any notable influence over the simulation results. For other SafeBreach customers - What simulations are you running and on what cadence? What has provided the most value to your org from this tool? <!-- SC_ON --> submitted by /u/cyopeng (https://www.reddit.com/user/cyopeng)
[link] (https://www.reddit.com/r/Pentesting/comments/10a77au/attacker_simulation_and_vulnerability_management/) [comments] (https://www.reddit.com/r/Pentesting/comments/10a77au/attacker_simulation_and_vulnerability_management/)
https://www.reddit.com/r/Pentesting/comments/10a77au/attacker_simulation_and_vulnerability_management/
<!-- SC_OFF -->I am struggling with implementing SafeBreach at my organization and I was hoping I could get some peer feed back on how they have implemented SafeBreach or other Attack/Adversary emulation tools within their organization. My primary question is how do you make use of your simulation results? It is hard to find value in these products when you are running the same tests every week with nearly the same results. It is pretty difficult to make impactful changes to the org's security tooling and posture to have any notable influence over the simulation results. For other SafeBreach customers - What simulations are you running and on what cadence? What has provided the most value to your org from this tool? <!-- SC_ON --> submitted by /u/cyopeng (https://www.reddit.com/user/cyopeng)
[link] (https://www.reddit.com/r/Pentesting/comments/10a77au/attacker_simulation_and_vulnerability_management/) [comments] (https://www.reddit.com/r/Pentesting/comments/10a77au/attacker_simulation_and_vulnerability_management/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox writeup — Dancing
https://cdn-images-1.medium.com/max/704/1*hyI6K7RPIjUFa0cX9zA48Q.png
Let’s start with scanning the machine using nmap.
Continue reading on Medium »
HackTheBox writeup — Dancing
https://cdn-images-1.medium.com/max/704/1*hyI6K7RPIjUFa0cX9zA48Q.png
Let’s start with scanning the machine using nmap.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Home Grown Red Team: Installing NetHunter On A Nexus 5 (Like It’s 2013).
https://cdn-images-1.medium.com/max/600/1*i7L8nsLt3b7DKfX7aNfiIw.png
I already know what you’re thinking. What year is it? It’s 2023 and the price of a Raspberry Pi is $150 for a top tier model. A Raspberry…
Continue reading on Medium »
Home Grown Red Team: Installing NetHunter On A Nexus 5 (Like It’s 2013).
https://cdn-images-1.medium.com/max/600/1*i7L8nsLt3b7DKfX7aNfiIw.png
I already know what you’re thinking. What year is it? It’s 2023 and the price of a Raspberry Pi is $150 for a top tier model. A Raspberry…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El malware IcedID ataca de nuevo: Dominio de Active Directory comprometido en menos de 24 horas
https://cdn-images-1.medium.com/max/1541/0*GNWczCm291Ii0ZF_
Un reciente ataque de malware IcedID permitió al actor de amenazas comprometer el dominio de Active Directory de un objetivo sin nombre…
Continue reading on Medium »
El malware IcedID ataca de nuevo: Dominio de Active Directory comprometido en menos de 24 horas
https://cdn-images-1.medium.com/max/1541/0*GNWczCm291Ii0ZF_
Un reciente ataque de malware IcedID permitió al actor de amenazas comprometer el dominio de Active Directory de un objetivo sin nombre…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Quiet quitting helped me start my business, while making me an extra $1000 USD per month.
https://cdn-images-1.medium.com/max/2600/1*v8jgow9_poizZUNVsnh-0A.jpeg
With the right mindset quiet quitting can be the opportunity of your lifetime. It could be a risk free way to boost your income and…
Continue reading on Medium »
Quiet quitting helped me start my business, while making me an extra $1000 USD per month.
https://cdn-images-1.medium.com/max/2600/1*v8jgow9_poizZUNVsnh-0A.jpeg
With the right mindset quiet quitting can be the opportunity of your lifetime. It could be a risk free way to boost your income and…
Continue reading on Medium »
Hacking on Medium
Hacking an Original Gameboy to play better than new
https://cdn-images-1.medium.com/max/2509/1*JR_lBZIYQY95j7frRiKLQQ.png
The original Nintendo Gameboy was released in 1989 and went on to be one of highest-selling video game consoles of all time.
Continue reading on Medium »
Hacking an Original Gameboy to play better than new
https://cdn-images-1.medium.com/max/2509/1*JR_lBZIYQY95j7frRiKLQQ.png
The original Nintendo Gameboy was released in 1989 and went on to be one of highest-selling video game consoles of all time.
Continue reading on Medium »
Medium
Hacking an Original Gameboy to play better than new
The original Nintendo Gameboy was released in 1989 and went on to be one of highest-selling video game consoles of all time.