Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top five Cyber Threat Intel stories of the week: 01/23 to 01/27/2023
https://cdn-images-1.medium.com/max/1000/0*Kf72g2s8R5gounAl
Top 5 general threat intelligence stories of the week. This is from TLP white/open-source websites, so please feel free to share with…
Continue reading on Hunter Strategy »
Top five Cyber Threat Intel stories of the week: 01/23 to 01/27/2023
https://cdn-images-1.medium.com/max/1000/0*Kf72g2s8R5gounAl
Top 5 general threat intelligence stories of the week. This is from TLP white/open-source websites, so please feel free to share with…
Continue reading on Hunter Strategy »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
U.S. Federal Agencies Fall Victim to Cyber Attack Utilizing Legitimate RMM Software
https://cdn-images-1.medium.com/max/1689/0*0ozcxN28DF9tefEU
At least two federal agencies in the U.S. fell victim to a “widespread cyber campaign” that involved the use of legitimate remote…
Continue reading on Medium »
U.S. Federal Agencies Fall Victim to Cyber Attack Utilizing Legitimate RMM Software
https://cdn-images-1.medium.com/max/1689/0*0ozcxN28DF9tefEU
At least two federal agencies in the U.S. fell victim to a “widespread cyber campaign” that involved the use of legitimate remote…
Continue reading on Medium »
Analyzing javascript files(Part -2)
https://medium.com/@indhumathi19973/analyzing-javascript-files-part-2-4b9b13c474c1?source=rss------bug_bounty-5
Using waybackurlsContinue reading on Medium » (https://medium.com/@indhumathi19973/analyzing-javascript-files-part-2-4b9b13c474c1?source=rss------bug_bounty-5)
https://medium.com/@indhumathi19973/analyzing-javascript-files-part-2-4b9b13c474c1?source=rss------bug_bounty-5
Using waybackurlsContinue reading on Medium » (https://medium.com/@indhumathi19973/analyzing-javascript-files-part-2-4b9b13c474c1?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Why Most Companies Still Don’t Know What’s on Their Network
Chris Kirsch, CEO of runZero, sits down with Dark Reading’sTerry Sweeney for a Fast Chat on the importance of asset discovery.
Why Most Companies Still Don’t Know What’s on Their Network
Chris Kirsch, CEO of runZero, sits down with Dark Reading’sTerry Sweeney for a Fast Chat on the importance of asset discovery.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Am I chasing a rabbit? (JS in plain text)
Hello,
I'm fairly new to pen testing ~ 6 months of working through junior pentester on THM and about 90% done. Have a basic understanding of networking yadda yadda.
I don't expect to find anything, but ever since learning Burp Suite, I thought it would be important to see real world examples and to get out of the CTF style picture perfect set ups.
Long story short, Company X offers free range for bug bounties and the thing I was testing was in scope and I figured great practice for me with Burp Suite. So I trimmed down to 50 promising sub domains and begin kinda just going through and researching along the way what some of the HTLM meant and tinkering with altering the packets etc
Didn't find anything for like 6 hours but my last session of tinkering I found something I hadn't seen all day...
When I captured a request that worked with a widget, I got this pretty bulky JavaScript code in the packet in plaintext.
The programmers added a bunch of comments too it and it looks like a bunch of mumbo jumbo to me since I'm a novice programmer but I noticed that there were references to GitHub with usernames source code links and even tables of hashes.
Is this normal? Should I keep investigating this? Is it worth even mentioning to the company or will I get laughed at?
submitted by /u/CptCuddleCakes
[link] [comments]
Am I chasing a rabbit? (JS in plain text)
Hello,
I'm fairly new to pen testing ~ 6 months of working through junior pentester on THM and about 90% done. Have a basic understanding of networking yadda yadda.
I don't expect to find anything, but ever since learning Burp Suite, I thought it would be important to see real world examples and to get out of the CTF style picture perfect set ups.
Long story short, Company X offers free range for bug bounties and the thing I was testing was in scope and I figured great practice for me with Burp Suite. So I trimmed down to 50 promising sub domains and begin kinda just going through and researching along the way what some of the HTLM meant and tinkering with altering the packets etc
Didn't find anything for like 6 hours but my last session of tinkering I found something I hadn't seen all day...
When I captured a request that worked with a widget, I got this pretty bulky JavaScript code in the packet in plaintext.
The programmers added a bunch of comments too it and it looks like a bunch of mumbo jumbo to me since I'm a novice programmer but I noticed that there were references to GitHub with usernames source code links and even tables of hashes.
Is this normal? Should I keep investigating this? Is it worth even mentioning to the company or will I get laughed at?
submitted by /u/CptCuddleCakes
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Kali Linux VM vs Kali Linux Live
What would you guys recommend for a burner laptop? Kali Linux Live on a USB flash drive or normal Kali Linux on a vm. Also, what are the pros and cons
submitted by /u/DaitoAnonymous
[link] [comments]
Kali Linux VM vs Kali Linux Live
What would you guys recommend for a burner laptop? Kali Linux Live on a USB flash drive or normal Kali Linux on a vm. Also, what are the pros and cons
submitted by /u/DaitoAnonymous
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is it possible to set a computer on fire by hacking into the battery or is that just movies (designated survivor)?
Hello guys,
So I was watching the tv show designated survivor and someone hacked into the laptop battery and destroyed it, I was wondering if that is actually possible or fake?
submitted by /u/Ok_Sir4235
[link] [comments]
Is it possible to set a computer on fire by hacking into the battery or is that just movies (designated survivor)?
Hello guys,
So I was watching the tv show designated survivor and someone hacked into the laptop battery and destroyed it, I was wondering if that is actually possible or fake?
submitted by /u/Ok_Sir4235
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How do I ssh into VM From a school Chromebook?
Hello guys,
So some websites are blocked on my school Chromebook and I want to study but it has SSH disabled on the terminal of the Chromebook, but what if I use the browser and use custom ports on my VM?
submitted by /u/Ok_Sir4235
[link] [comments]
How do I ssh into VM From a school Chromebook?
Hello guys,
So some websites are blocked on my school Chromebook and I want to study but it has SSH disabled on the terminal of the Chromebook, but what if I use the browser and use custom ports on my VM?
submitted by /u/Ok_Sir4235
[link] [comments]
Linux vs Python
https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/
<!-- SC_OFF -->Got security+ and taking Network+ Monday. Might do pentest+ or ceh next. I wanted to learn some basic hands on skills. Which one is more important and should be a primary focus in my studies? <!-- SC_ON --> submitted by /u/TheVeryWiseToad (https://www.reddit.com/user/TheVeryWiseToad)
[link] (https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/) [comments] (https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/)
https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/
<!-- SC_OFF -->Got security+ and taking Network+ Monday. Might do pentest+ or ceh next. I wanted to learn some basic hands on skills. Which one is more important and should be a primary focus in my studies? <!-- SC_ON --> submitted by /u/TheVeryWiseToad (https://www.reddit.com/user/TheVeryWiseToad)
[link] (https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/) [comments] (https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/)