Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Velociraptor (Digital Forensics) A Blue-Teamer Tool, Still Cool Nonetheless!
Hey All,
Check out Velociraptor: https://docs.velociraptor.app/docs/overview/
Its an open source digital forensics tool for endpoint monitoring. I find its best paired with Sysmon to fetch whatever processes, connections, etc. Its a very lightweight tool and has an active community.
It comes with its own language: VQL (similar to SQL). VQL is a framework for creating highly customized artifacts which allow you to collect, query, and monitor almost any aspect of an endpoint, groups of endpoints, or an entire network. It can also be used to create continuous monitoring rules on the endpoint, as well as automate tasks on the server.
Super cool tool thats fun to play with.
submitted by /u/secanalyst1234
[link] [comments]
Velociraptor (Digital Forensics) A Blue-Teamer Tool, Still Cool Nonetheless!
Hey All,
Check out Velociraptor: https://docs.velociraptor.app/docs/overview/
Its an open source digital forensics tool for endpoint monitoring. I find its best paired with Sysmon to fetch whatever processes, connections, etc. Its a very lightweight tool and has an active community.
It comes with its own language: VQL (similar to SQL). VQL is a framework for creating highly customized artifacts which allow you to collect, query, and monitor almost any aspect of an endpoint, groups of endpoints, or an entire network. It can also be used to create continuous monitoring rules on the endpoint, as well as automate tasks on the server.
Super cool tool thats fun to play with.
submitted by /u/secanalyst1234
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
If someone entranges my laptop, how many tries for the password?
I am a user of MacBook. I have my drive encrypted (using Apple's FileVault)
If someone steals my laptop, they can try to get into it by typing the password. After a few tries they will be delayed, preventing brute-force attacks.
Is there (a relatively known?) way to get past this restriction, e.g. cloning the hard drive (through cable) (IO solution), or physically removing the SSDs? Does it work for just some storage types (SSD / hard drive), some architectures (Apple SoC / Intel), some OS versions or all
submitted by /u/dteiml
[link] [comments]
If someone entranges my laptop, how many tries for the password?
I am a user of MacBook. I have my drive encrypted (using Apple's FileVault)
If someone steals my laptop, they can try to get into it by typing the password. After a few tries they will be delayed, preventing brute-force attacks.
Is there (a relatively known?) way to get past this restriction, e.g. cloning the hard drive (through cable) (IO solution), or physically removing the SSDs? Does it work for just some storage types (SSD / hard drive), some architectures (Apple SoC / Intel), some OS versions or all
submitted by /u/dteiml
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
ChatGPT Creates Polymorphic Malware. Time to start using it to create all kinds of havoc
https://external-preview.redd.it/gJdcOjRd7nVGW0u1Ack03Yfv0XlYSOpzVGC4TSuRU6k.jpg?width=216&crop=smart&auto=webp&s=338494fe7b1f33c03f6d27a24593691a0f53b794 submitted by /u/SimilarPlate
[link] [comments]
ChatGPT Creates Polymorphic Malware. Time to start using it to create all kinds of havoc
https://external-preview.redd.it/gJdcOjRd7nVGW0u1Ack03Yfv0XlYSOpzVGC4TSuRU6k.jpg?width=216&crop=smart&auto=webp&s=338494fe7b1f33c03f6d27a24593691a0f53b794 submitted by /u/SimilarPlate
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Not sure if this is hacking... More web page tracking?
Myself and some friends enjoy the Bourbon. In Virginia, we have the ABC control liquor, so all those hard to find liquors are only sold for retail price, unlike other states where the stores can mark them up and make a higher profit.
The way Virginia does these releases are as follows...
You sign up for emails.
Randomly, anywhere from 20-30 ABC stores in the state will have a shipment of whatever hard to find bottles.
Then one day, you get an email... the email will say LIMITED AVAILABILITY DROP and provide all the stores that are selling some hard to find bottles. It doesn't tell you what they are or how many... just that this store will have... something.
You drive there, first come, first serve. Usually everything is sold out in like 10 mins.
This is the main website
https://www.abc.virginia.gov/
This is an example of the drop email
https://www.abc.virginia.gov/limited/allocated_stores_01_18_2023_05_45_pmlPDeNaaYEwS7ZSeZ92rL4klj.html
Note the time on the website Drop date: 01/18/2023 05:45 pm
I got the email at 6:06pm
Sooooo someone is publishing the site, then they are sending the emails....
Is there a way to monitor the site to see when a new page, like this, is published? Thus getting a jump....
Im going to say there is, I got to a store one day 5 mins after the email, I happed to be in the store next-door, and there were already 10 people on line. haha
Thanks for any thoughts!
submitted by /u/Bigbadwolf6049
[link] [comments]
Not sure if this is hacking... More web page tracking?
Myself and some friends enjoy the Bourbon. In Virginia, we have the ABC control liquor, so all those hard to find liquors are only sold for retail price, unlike other states where the stores can mark them up and make a higher profit.
The way Virginia does these releases are as follows...
You sign up for emails.
Randomly, anywhere from 20-30 ABC stores in the state will have a shipment of whatever hard to find bottles.
Then one day, you get an email... the email will say LIMITED AVAILABILITY DROP and provide all the stores that are selling some hard to find bottles. It doesn't tell you what they are or how many... just that this store will have... something.
You drive there, first come, first serve. Usually everything is sold out in like 10 mins.
This is the main website
https://www.abc.virginia.gov/
This is an example of the drop email
https://www.abc.virginia.gov/limited/allocated_stores_01_18_2023_05_45_pmlPDeNaaYEwS7ZSeZ92rL4klj.html
Note the time on the website Drop date: 01/18/2023 05:45 pm
I got the email at 6:06pm
Sooooo someone is publishing the site, then they are sending the emails....
Is there a way to monitor the site to see when a new page, like this, is published? Thus getting a jump....
Im going to say there is, I got to a store one day 5 mins after the email, I happed to be in the store next-door, and there were already 10 people on line. haha
Thanks for any thoughts!
submitted by /u/Bigbadwolf6049
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Attempting to control my macbook power light
So given that I have sudo access on my machine. I want to be able to make my laptop power light to flash, encoding a string in the flash that I can then read using an OpticSpy.
I bought the OpticSpy on the link below but I am having a hard time working out how to use it and thought this would be a fun project to try.
https://www.crowdsupply.com/grand-idea-studio/opticspy
submitted by /u/robots_build_my_life
[link] [comments]
Attempting to control my macbook power light
So given that I have sudo access on my machine. I want to be able to make my laptop power light to flash, encoding a string in the flash that I can then read using an OpticSpy.
I bought the OpticSpy on the link below but I am having a hard time working out how to use it and thought this would be a fun project to try.
https://www.crowdsupply.com/grand-idea-studio/opticspy
submitted by /u/robots_build_my_life
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mailchimp sufre otra brecha de seguridad que compromete la información de algunos clientes
https://cdn-images-1.medium.com/max/1153/0*JHAtBOYfqLMqZ0Ik
El popular servicio de marketing por correo electrónico y boletines Mailchimp ha revelado otra brecha de seguridad que permitió a los…
Continue reading on Medium »
Mailchimp sufre otra brecha de seguridad que compromete la información de algunos clientes
https://cdn-images-1.medium.com/max/1153/0*JHAtBOYfqLMqZ0Ik
El popular servicio de marketing por correo electrónico y boletines Mailchimp ha revelado otra brecha de seguridad que permitió a los…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking with cURL: Unleash the CLI beast
https://cdn-images-1.medium.com/max/1053/1*RS1v8v2lxFfufJnA38fE6g.png
Curl, or client URL is a command line tool that enables data exchange between a device and a server through a terminal. We can use this…
Continue reading on Medium »
Hacking with cURL: Unleash the CLI beast
https://cdn-images-1.medium.com/max/1053/1*RS1v8v2lxFfufJnA38fE6g.png
Curl, or client URL is a command line tool that enables data exchange between a device and a server through a terminal. We can use this…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nueva vulnerabilidad de Microsoft Azure descubierta: los expertos advierten sobre ataques RCE
https://cdn-images-1.medium.com/max/1067/0*vNCVvwwxTDFTW4RR
Una nueva falla crítica de ejecución remota de código (RCE) descubierta que afecta a múltiples servicios relacionados con Microsoft Azure…
Continue reading on Medium »
Nueva vulnerabilidad de Microsoft Azure descubierta: los expertos advierten sobre ataques RCE
https://cdn-images-1.medium.com/max/1067/0*vNCVvwwxTDFTW4RR
Una nueva falla crítica de ejecución remota de código (RCE) descubierta que afecta a múltiples servicios relacionados con Microsoft Azure…
Continue reading on Medium »