Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Why does Google prepend while(1); to their (private) JSON responses?
https://cdn-images-1.medium.com/max/2600/0*AiSXfWeLu7XFMitW
Why does Google prepend while(1); to their (private) JSON responses?
Continue reading on RE:Stacked »
Why does Google prepend while(1); to their (private) JSON responses?
https://cdn-images-1.medium.com/max/2600/0*AiSXfWeLu7XFMitW
Why does Google prepend while(1); to their (private) JSON responses?
Continue reading on RE:Stacked »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Power of Python: Unlock Your Potential with 3DSS!
Python is one of the most popular programming languages in the world, and for good reason. It’s versatile, easy to learn, and has a vast…
Continue reading on Medium »
The Power of Python: Unlock Your Potential with 3DSS!
Python is one of the most popular programming languages in the world, and for good reason. It’s versatile, easy to learn, and has a vast…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
An IDOR vulnerability often hides many others
https://cdn-images-1.medium.com/max/720/1*LK-17j6OFA76MBqTfPKxrg.jpeg
Some errors are occasional, others result from poor design, in this case, finding a vulnerability allows you to find many others…
Continue reading on InfoSec Write-ups »
An IDOR vulnerability often hides many others
https://cdn-images-1.medium.com/max/720/1*LK-17j6OFA76MBqTfPKxrg.jpeg
Some errors are occasional, others result from poor design, in this case, finding a vulnerability allows you to find many others…
Continue reading on InfoSec Write-ups »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Setting you up for failure: Exploring 2FA bypasses in web application settings page functionality
https://cdn-images-1.medium.com/max/827/1*vPqONGnwzzaayuc5Iyirsw.png
In January it was reported in the mainstream media a 2FA Bypass was discovered in Facebook involving their new account center APIs.
Continue reading on Medium »
Setting you up for failure: Exploring 2FA bypasses in web application settings page functionality
https://cdn-images-1.medium.com/max/827/1*vPqONGnwzzaayuc5Iyirsw.png
In January it was reported in the mainstream media a 2FA Bypass was discovered in Facebook involving their new account center APIs.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Brain: the world’s first computer virus
https://cdn-images-1.medium.com/max/2600/0*0AfNNWYmm2A7b6Wz
Revealing the lasting impact of the first computer virus Brain: How it set the stage for modern cybersecurity measures
Continue reading on Geek Culture »
Brain: the world’s first computer virus
https://cdn-images-1.medium.com/max/2600/0*0AfNNWYmm2A7b6Wz
Revealing the lasting impact of the first computer virus Brain: How it set the stage for modern cybersecurity measures
Continue reading on Geek Culture »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
QNAP Fixes Critical Vulnerability in NAS Devices with Latest Security Updates
https://cdn-images-1.medium.com/max/1076/0*SICEkurjCrMcZ50J
Taiwanese company QNAP has released updates to remediate a critical security flaw affecting its network-attached storage (NAS) devices…
Continue reading on Medium »
QNAP Fixes Critical Vulnerability in NAS Devices with Latest Security Updates
https://cdn-images-1.medium.com/max/1076/0*SICEkurjCrMcZ50J
Taiwanese company QNAP has released updates to remediate a critical security flaw affecting its network-attached storage (NAS) devices…
Continue reading on Medium »
Phishing Tips?
https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/
<!-- SC_OFF -->Hey all, I have an upcoming physical/phishing engagement. Unfortunately I was tasked very short notice to develop a phishing campaign with custom domains. My boss is VERY adamant that this remains hush-hush so no whitelisting. (We are a PE firm testing some portfolios companies.) So far I have the domains bought, SPF, DKIM, and DMARC have been configured. I’ve tested my email configuration against mail tester and it’s 10/10. I have tried various combinations of O365 and SMTP APIs but everything I have tried ends up hitting the spam filter. Do you all have any recommendations on how to build IP/Domain reputation fast? Have any of you had success with an inbox warmer? I realize that this might not be possible on such short notice ( <!-- SC_ON --> submitted by /u/KungFuBatman (https://www.reddit.com/user/KungFuBatman)
[link] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/) [comments] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/)
https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/
<!-- SC_OFF -->Hey all, I have an upcoming physical/phishing engagement. Unfortunately I was tasked very short notice to develop a phishing campaign with custom domains. My boss is VERY adamant that this remains hush-hush so no whitelisting. (We are a PE firm testing some portfolios companies.) So far I have the domains bought, SPF, DKIM, and DMARC have been configured. I’ve tested my email configuration against mail tester and it’s 10/10. I have tried various combinations of O365 and SMTP APIs but everything I have tried ends up hitting the spam filter. Do you all have any recommendations on how to build IP/Domain reputation fast? Have any of you had success with an inbox warmer? I realize that this might not be possible on such short notice ( <!-- SC_ON --> submitted by /u/KungFuBatman (https://www.reddit.com/user/KungFuBatman)
[link] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/) [comments] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/)
Tips for Becoming a Proficient Bug Bounty Hunter
https://medium.com/@vjgnanam2002/tips-for-becoming-a-proficient-bug-bounty-hunter-dfe2559f68ee?source=rss------bug_bounty-5
https://medium.com/@vjgnanam2002/tips-for-becoming-a-proficient-bug-bounty-hunter-dfe2559f68ee?source=rss------bug_bounty-5
How to Become a Bug Bounty HunterContinue reading on Medium » (https://medium.com/@vjgnanam2002/tips-for-becoming-a-proficient-bug-bounty-hunter-dfe2559f68ee?source=rss------bug_bounty-5)
Tips for Becoming a Proficient Bug Bounty Hunter
How to Become a Bug Bounty HunterContinue reading on Medium »
Read more...
How to Become a Bug Bounty HunterContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Setting you up for failure: Exploring 2FA bypasses in web app settings pages functionality
https://link.medium.com/HegWKfSi3w
In this story I discuss how you can find bugs just like this on other web applications not just Facebook. If you enjoyed the story hit that follow button for more.
submitted by /u/TheCrazyAcademic
[link] [comments]
Setting you up for failure: Exploring 2FA bypasses in web app settings pages functionality
https://link.medium.com/HegWKfSi3w
In this story I discuss how you can find bugs just like this on other web applications not just Facebook. If you enjoyed the story hit that follow button for more.
submitted by /u/TheCrazyAcademic
[link] [comments]