Upgrading XSS Hunter with a basic reverse JavaScript shell
https://infosecwriteups.com/upgrading-xss-hunter-with-a-basic-reverse-javascript-shell-db00172e32f9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/upgrading-xss-hunter-with-a-basic-reverse-javascript-shell-db00172e32f9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Upgrading XSS Hunter with a basic reverse JavaScript shell
Before you start reading this article, please keep in mind that this is a very basic reverse shell, and still needs a lot of work to get…
Before you start reading this article, please keep in mind that this is a very basic reverse shell, and still needs a lot of work to get…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/upgrading-xss-hunter-with-a-basic-reverse-javascript-shell-db00172e32f9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Upgrading XSS Hunter with a basic reverse JavaScript shell
Before you start reading this article, please keep in mind that this is a very basic reverse shell, and still needs a lot of work to get…Continue reading on InfoSec Write-ups »
Read more...
Before you start reading this article, please keep in mind that this is a very basic reverse shell, and still needs a lot of work to get…Continue reading on InfoSec Write-ups »
Read more...
Upgrading XSS Hunter with a basic reverse JavaScript shell
Before you start reading this article, please keep in mind that this is a very basic reverse shell, and still needs a lot of work to get…Continue reading on InfoSec Write-ups »
Read more...
Before you start reading this article, please keep in mind that this is a very basic reverse shell, and still needs a lot of work to get…Continue reading on InfoSec Write-ups »
Read more...
My bug bounty journey. The mind of a middle-class boy who wanted everything for free.
Hello everyone,
Read more...
Hello everyone,
Read more...
hacking: security in practice
Have I been hacked?
Recently something strange has been happening. I was on google and left my computer for a moment, and when I came back, Google searched for something I didn't search for. Later a site zoomed to 125% without me doing it. Have I been hacked or hijacked, or am I being paranoid?
submitted by /u/Mike-Compatriot
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Have I been hacked?
Recently something strange has been happening. I was on google and left my computer for a moment, and when I came back, Google searched for something I didn't search for. Later a site zoomed to 125% without me doing it. Have I been hacked or hijacked, or am I being paranoid?
submitted by /u/Mike-Compatriot
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Have I been hacked?
Recently something strange has been happening. I was on google and left my computer for a moment, and when I came back, Google searched for...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
The Sony Hack - 2014
https://external-preview.redd.it/7y895EF0wVI0KovZNcMaDg_LWMErsrz2iYkCYQqJYig.jpg?width=640&crop=smart&auto=webp&s=6c05fd1fc59a5d93a5bb10744ddee7b3f17fa4a8 submitted by /u/admiralarjun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The Sony Hack - 2014
https://external-preview.redd.it/7y895EF0wVI0KovZNcMaDg_LWMErsrz2iYkCYQqJYig.jpg?width=640&crop=smart&auto=webp&s=6c05fd1fc59a5d93a5bb10744ddee7b3f17fa4a8 submitted by /u/admiralarjun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Sony Hack - 2014
Posted in r/hacking by u/admiralarjun • 1 point and 0 comments
hacking: security in practice
netdiscover doesn't find any client?
I'm running Kali ( just one guest OS ) on VMware configured in NAT mode. Since NAT creates a private LAN network between all guest OS, it makes sense as to why i'm not getting any clients when i run netdiscover. Then i plugged in a wireless adapter, disconnected from the LAN network and connected to my wifi, i was expecting to see all the clients connected to my wifi. To my surprise i couldn't see any clients.
i couldn't find any reasons online, why am i not able to see any clients when i run netdiscover after connecting to my wifi ?
submitted by /u/WinterFondant
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
netdiscover doesn't find any client?
I'm running Kali ( just one guest OS ) on VMware configured in NAT mode. Since NAT creates a private LAN network between all guest OS, it makes sense as to why i'm not getting any clients when i run netdiscover. Then i plugged in a wireless adapter, disconnected from the LAN network and connected to my wifi, i was expecting to see all the clients connected to my wifi. To my surprise i couldn't see any clients.
i couldn't find any reasons online, why am i not able to see any clients when i run netdiscover after connecting to my wifi ?
submitted by /u/WinterFondant
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
netdiscover doesn't find any client?
I'm running Kali ( just one guest OS ) on VMware configured in NAT mode. Since NAT creates a private LAN network between all guest OS, it makes...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Jeeves: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*E7xdbDJkzb9BF1XB-6KK5g.png
Hack The Box — Jeeves: Walkthrough (without Metasploit) | Windows Medium Level | Road to OSCP | Jenkins RCE | Leaked Credential | dir /r
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box — Jeeves: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*E7xdbDJkzb9BF1XB-6KK5g.png
Hack The Box — Jeeves: Walkthrough (without Metasploit) | Windows Medium Level | Road to OSCP | Jenkins RCE | Leaked Credential | dir /r
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack The Box — Jeeves: Walkthrough (without Metasploit)
Hack The Box — Jeeves: Walkthrough (without Metasploit) | Windows Medium Level | Road to OSCP | Jenkins RCE | Leaked Credential | dir /r
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Enumerating and Exploiting NFS
https://cdn-images-1.medium.com/max/1156/1*kfNysiVdleVaxPSE9twbmg.jpeg
NFS-Common
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Enumerating and Exploiting NFS
https://cdn-images-1.medium.com/max/1156/1*kfNysiVdleVaxPSE9twbmg.jpeg
NFS-Common
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Enumerating and Exploiting NFS
NFS-Common
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Miss Diya’s Free Fire ID, K/D Ratios and Stats in may 2021
https://cdn-images-1.medium.com/max/800/1*BcpyZwpEMBBhBBkJcxvCbw.jpeg
Diya Hazarika is also known as Miss Diya is a popular Free Fire streamer and player.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Miss Diya’s Free Fire ID, K/D Ratios and Stats in may 2021
https://cdn-images-1.medium.com/max/800/1*BcpyZwpEMBBhBBkJcxvCbw.jpeg
Diya Hazarika is also known as Miss Diya is a popular Free Fire streamer and player.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Miss Diya’s Free Fire ID, K/D Ratios and Stats in may 2021
Diya Hazarika is also known as Miss Diya is a popular Free Fire streamer and player.
Snuffleupagus - Security Module For Php7 And Php8 - Killing Bugclasses And Virtual-Patching The Rest!
Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! Snuffleupagus is a PHP 7+ and 8+ module designed to drastically raise the cost of attacks against websites, by killing entire bug classes. It also provides a powerful virtual-patching system, allowing administrator to fix specific vulnerabilities and audit suspicious behaviours without having to touch the PHP code.Key Features No noticeable performance impact Powerful yet simple to write virtual-patching rules Killing several classes of vulnerabilities Unserialize-based code execution mail-based code execution Cookie-stealing XSS File-upload based code execution Weak PRNG XXE Several hardening features Automatic secure and samesite flag for cookies Bundled set of rules to detect post-compromissions behaviours Global strict mode and type-juggling prevention Whitelisting of stream wrappers Preventing writeable files execution Whitelist/blacklist for eval Enforcing TLS certificate validation when using curl Request dumping capability A relatively sane code base: A comprehensive test suite close to 100% coverage Every commit is tested on several distributions An clang-format-enforced code style A comprehensive documentation Usage of coverity Download We've got a download page, where you can find packages for your distribution, but you can of course just git clone this repo, or check the releases on github. Examples We're providing various example rules, that are looking like this: # Harden the `chmod` functionsp.disable_function.function("chmod").param("mode").value_r("^0-9{2}67$").drop();# Mitigate command injection in `system`sp.disable_function.function("system").param("command").value_r("$|;&\`\\n").drop(); Upon violation of a rule, you should see lines like this in your logs: snuffleupagus0.0.0.0disabled\_functiondrop The execution has been aborted in /var/www/index.php:2, because the return value (0) of the function 'strpos' matched a rule. Documentation We've got a comprehensive website with all the documentation that you could possibly wish for. You can of course build it yourself. Thanks Many thanks to the Suhosin project for being a huge source of inspiration, and to all our contributors. Download Snuffleupagus
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! Snuffleupagus is a PHP 7+ and 8+ module designed to drastically raise the cost of attacks against websites, by killing entire bug classes. It also provides a powerful virtual-patching system, allowing administrator to fix specific vulnerabilities and audit suspicious behaviours without having to touch the PHP code.Key Features No noticeable performance impact Powerful yet simple to write virtual-patching rules Killing several classes of vulnerabilities Unserialize-based code execution mail-based code execution Cookie-stealing XSS File-upload based code execution Weak PRNG XXE Several hardening features Automatic secure and samesite flag for cookies Bundled set of rules to detect post-compromissions behaviours Global strict mode and type-juggling prevention Whitelisting of stream wrappers Preventing writeable files execution Whitelist/blacklist for eval Enforcing TLS certificate validation when using curl Request dumping capability A relatively sane code base: A comprehensive test suite close to 100% coverage Every commit is tested on several distributions An clang-format-enforced code style A comprehensive documentation Usage of coverity Download We've got a download page, where you can find packages for your distribution, but you can of course just git clone this repo, or check the releases on github. Examples We're providing various example rules, that are looking like this: # Harden the `chmod` functionsp.disable_function.function("chmod").param("mode").value_r("^0-9{2}67$").drop();# Mitigate command injection in `system`sp.disable_function.function("system").param("command").value_r("$|;&\`\\n").drop(); Upon violation of a rule, you should see lines like this in your logs: snuffleupagus0.0.0.0disabled\_functiondrop The execution has been aborted in /var/www/index.php:2, because the return value (0) of the function 'strpos' matched a rule. Documentation We've got a comprehensive website with all the documentation that you could possibly wish for. You can of course build it yourself. Thanks Many thanks to the Suhosin project for being a huge source of inspiration, and to all our contributors. Download Snuffleupagus
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Snuffleupagus - Security Module For Php7 And Php8 - Killing Bugclasses And Virtual-Patching The Rest!
https://1.bp.blogspot.com/-2JGM8u32OgM/YJgaQqr-dwI/AAAAAAAAWIE/365i9KiLqeA7S9fdpp0YAoOVu2wwfeV7gCNcBGAsYHQ/s320/snuffleupagus_1_sp.png Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!Snuffleupagus is a PHP 7+ and 8+ module designed to drastically raise the cost of attacks against websites, by killing entire bug classes. It also provides a powerful virtual-patching system, allowing administrator to fix specific vulnerabilities and audit suspicious behaviours without having to touch the PHP code. Key Features* No noticeable performance impact
* Powerful yet simple to write virtual-patching rules
* Killing several classes of vulnerabilities
* Unserialize-based code execution
*
* Cookie-stealing XSS
* File-upload based code execution
* Weak PRNG
* XXE
* Several hardening features
* Automatic
* Bundled set of rules to detect post-compromissions behaviours
* Global strict mode and type-juggling prevention
* Whitelisting of stream wrappers
* Preventing writeable files execution
* Whitelist/blacklist for
* Request dumping capability
* A relatively sane code base:
* A comprehensive test suite close to 100% coverage
* Every commit is tested on several distributions
* An
* A comprehensive documentation
* Usage of coverity DownloadWe've got a download page, where you can find packages for your distribution, but you can of course just
___________________________
@hacking_Attack
@Hacking_Video
Snuffleupagus - Security Module For Php7 And Php8 - Killing Bugclasses And Virtual-Patching The Rest!
https://1.bp.blogspot.com/-2JGM8u32OgM/YJgaQqr-dwI/AAAAAAAAWIE/365i9KiLqeA7S9fdpp0YAoOVu2wwfeV7gCNcBGAsYHQ/s320/snuffleupagus_1_sp.png Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!Snuffleupagus is a PHP 7+ and 8+ module designed to drastically raise the cost of attacks against websites, by killing entire bug classes. It also provides a powerful virtual-patching system, allowing administrator to fix specific vulnerabilities and audit suspicious behaviours without having to touch the PHP code. Key Features* No noticeable performance impact
* Powerful yet simple to write virtual-patching rules
* Killing several classes of vulnerabilities
* Unserialize-based code execution
*
mail-based code execution* Cookie-stealing XSS
* File-upload based code execution
* Weak PRNG
* XXE
* Several hardening features
* Automatic
secureand samesiteflag for cookies* Bundled set of rules to detect post-compromissions behaviours
* Global strict mode and type-juggling prevention
* Whitelisting of stream wrappers
* Preventing writeable files execution
* Whitelist/blacklist for
eval* Enforcing TLS certificate validation when using curl* Request dumping capability
* A relatively sane code base:
* A comprehensive test suite close to 100% coverage
* Every commit is tested on several distributions
* An
clang-format-enforced code style* A comprehensive documentation
* Usage of coverity DownloadWe've got a download page, where you can find packages for your distribution, but you can of course just
git clonethis repo, or check the releases on github. ExamplesWe're providing various example rules, that are looking like this: # Harden the `chmod` function
sp.disable_function.function("chmod").param("mode").value_r("^[0-9]{2}[67]$").drop();
# Mitigate command injection in `system`
sp.disable_function.function("system").param("command").value_r("[$|;&`\\n]").drop();Upon violation of a rule, you should see lines like this in your logs: [snuffleupagus][0.0.0.0][disabled_function][drop] The execution has been aborted in /var/www/index.php:2, because the return value (0) of the function 'strpos' matched a rule.DocumentationWe've got a comprehensive website with all the documentation that you could possibly wish for. You can of course build it yourself. ThanksMany thanks to the Suhosin project for being a huge source of inspiration, and to all our contributors. Download Snuffleupagus___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Snuffleupagus - Security Module For Php7 And Php8 - Killing Bugclasses And Virtual-Patching The Rest!
Deep Web
Can anybody tell me a noob way to create a PGP key.
So thought I would try white house market out but it says I cannot buy without a PGP key.
How do I get one?
submitted by /u/XboxJon82
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can anybody tell me a noob way to create a PGP key.
So thought I would try white house market out but it says I cannot buy without a PGP key.
How do I get one?
submitted by /u/XboxJon82
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can anybody tell me a noob way to create a PGP key.
So thought I would try white house market out but it says I cannot buy without a PGP key. How do I get one?
How I find my first Stored XSS
https://filipaze.medium.com/how-i-find-my-first-stored-xss-c6f57155cc1a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://filipaze.medium.com/how-i-find-my-first-stored-xss-c6f57155cc1a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I find my first Stored XSS
I found a Stored XSS on a awkward place