Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Analyzing javascript files(Part -2)

Using waybackurlsContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Am I chasing a rabbit? (JS in plain text)

Hello,

I'm fairly new to pen testing ~ 6 months of working through junior pentester on THM and about 90% done. Have a basic understanding of networking yadda yadda.

I don't expect to find anything, but ever since learning Burp Suite, I thought it would be important to see real world examples and to get out of the CTF style picture perfect set ups.

Long story short, Company X offers free range for bug bounties and the thing I was testing was in scope and I figured great practice for me with Burp Suite. So I trimmed down to 50 promising sub domains and begin kinda just going through and researching along the way what some of the HTLM meant and tinkering with altering the packets etc

Didn't find anything for like 6 hours but my last session of tinkering I found something I hadn't seen all day...

When I captured a request that worked with a widget, I got this pretty bulky JavaScript code in the packet in plaintext.

The programmers added a bunch of comments too it and it looks like a bunch of mumbo jumbo to me since I'm a novice programmer but I noticed that there were references to GitHub with usernames source code links and even tables of hashes.

Is this normal? Should I keep investigating this? Is it worth even mentioning to the company or will I get laughed at?

submitted by /u/CptCuddleCakes
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Kali Linux VM vs Kali Linux Live

What would you guys recommend for a burner laptop? Kali Linux Live on a USB flash drive or normal Kali Linux on a vm. Also, what are the pros and cons

submitted by /u/DaitoAnonymous
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is it possible to set a computer on fire by hacking into the battery or is that just movies (designated survivor)?

Hello guys,

So I was watching the tv show designated survivor and someone hacked into the laptop battery and destroyed it, I was wondering if that is actually possible or fake?

submitted by /u/Ok_Sir4235
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How do I ssh into VM From a school Chromebook?

Hello guys,

So some websites are blocked on my school Chromebook and I want to study but it has SSH disabled on the terminal of the Chromebook, but what if I use the browser and use custom ports on my VM?

submitted by /u/Ok_Sir4235
[link] [comments]
bWAPP Mail Header Injection

Mail Header Injection Nedir?Continue reading on Medium »
Read more...
Linux vs Python
https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/

<!-- SC_OFF -->Got security+ and taking Network+ Monday. Might do pentest+ or ceh next. I wanted to learn some basic hands on skills. Which one is more important and should be a primary focus in my studies? <!-- SC_ON --> submitted by /u/TheVeryWiseToad (https://www.reddit.com/user/TheVeryWiseToad)
[link] (https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/) [comments] (https://www.reddit.com/r/Pentesting/comments/10n1kfd/linux_vs_python/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Try Hack ME | RootMe

https://cdn-images-1.medium.com/max/1085/1*XesV5-UO4XvCLhljqBsilw.jpeg
Here is my Summary Notes about the Try Hack Me’s RootMe machine.
Started with a normal nmap scan. The ports that are open on the machine…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Stocker Write-up — Hack The Box

https://cdn-images-1.medium.com/max/690/0*Za6Jd-mQbPYWsX2I.png
In this write-up, we will be tackling the Hack The Box machine, Stocker. Through initial enumeration, we discover a web server running on…

Continue reading on Medium »