Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Setting you up for failure: Exploring 2FA bypasses in web application settings page functionality
https://cdn-images-1.medium.com/max/827/1*vPqONGnwzzaayuc5Iyirsw.png
In January it was reported in the mainstream media a 2FA Bypass was discovered in Facebook involving their new account center APIs.
Continue reading on Medium »
Setting you up for failure: Exploring 2FA bypasses in web application settings page functionality
https://cdn-images-1.medium.com/max/827/1*vPqONGnwzzaayuc5Iyirsw.png
In January it was reported in the mainstream media a 2FA Bypass was discovered in Facebook involving their new account center APIs.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Brain: the world’s first computer virus
https://cdn-images-1.medium.com/max/2600/0*0AfNNWYmm2A7b6Wz
Revealing the lasting impact of the first computer virus Brain: How it set the stage for modern cybersecurity measures
Continue reading on Geek Culture »
Brain: the world’s first computer virus
https://cdn-images-1.medium.com/max/2600/0*0AfNNWYmm2A7b6Wz
Revealing the lasting impact of the first computer virus Brain: How it set the stage for modern cybersecurity measures
Continue reading on Geek Culture »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
QNAP Fixes Critical Vulnerability in NAS Devices with Latest Security Updates
https://cdn-images-1.medium.com/max/1076/0*SICEkurjCrMcZ50J
Taiwanese company QNAP has released updates to remediate a critical security flaw affecting its network-attached storage (NAS) devices…
Continue reading on Medium »
QNAP Fixes Critical Vulnerability in NAS Devices with Latest Security Updates
https://cdn-images-1.medium.com/max/1076/0*SICEkurjCrMcZ50J
Taiwanese company QNAP has released updates to remediate a critical security flaw affecting its network-attached storage (NAS) devices…
Continue reading on Medium »
Phishing Tips?
https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/
<!-- SC_OFF -->Hey all, I have an upcoming physical/phishing engagement. Unfortunately I was tasked very short notice to develop a phishing campaign with custom domains. My boss is VERY adamant that this remains hush-hush so no whitelisting. (We are a PE firm testing some portfolios companies.) So far I have the domains bought, SPF, DKIM, and DMARC have been configured. I’ve tested my email configuration against mail tester and it’s 10/10. I have tried various combinations of O365 and SMTP APIs but everything I have tried ends up hitting the spam filter. Do you all have any recommendations on how to build IP/Domain reputation fast? Have any of you had success with an inbox warmer? I realize that this might not be possible on such short notice ( <!-- SC_ON --> submitted by /u/KungFuBatman (https://www.reddit.com/user/KungFuBatman)
[link] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/) [comments] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/)
https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/
<!-- SC_OFF -->Hey all, I have an upcoming physical/phishing engagement. Unfortunately I was tasked very short notice to develop a phishing campaign with custom domains. My boss is VERY adamant that this remains hush-hush so no whitelisting. (We are a PE firm testing some portfolios companies.) So far I have the domains bought, SPF, DKIM, and DMARC have been configured. I’ve tested my email configuration against mail tester and it’s 10/10. I have tried various combinations of O365 and SMTP APIs but everything I have tried ends up hitting the spam filter. Do you all have any recommendations on how to build IP/Domain reputation fast? Have any of you had success with an inbox warmer? I realize that this might not be possible on such short notice ( <!-- SC_ON --> submitted by /u/KungFuBatman (https://www.reddit.com/user/KungFuBatman)
[link] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/) [comments] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/)
Tips for Becoming a Proficient Bug Bounty Hunter
https://medium.com/@vjgnanam2002/tips-for-becoming-a-proficient-bug-bounty-hunter-dfe2559f68ee?source=rss------bug_bounty-5
https://medium.com/@vjgnanam2002/tips-for-becoming-a-proficient-bug-bounty-hunter-dfe2559f68ee?source=rss------bug_bounty-5
How to Become a Bug Bounty HunterContinue reading on Medium » (https://medium.com/@vjgnanam2002/tips-for-becoming-a-proficient-bug-bounty-hunter-dfe2559f68ee?source=rss------bug_bounty-5)
Tips for Becoming a Proficient Bug Bounty Hunter
How to Become a Bug Bounty HunterContinue reading on Medium »
Read more...
How to Become a Bug Bounty HunterContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Setting you up for failure: Exploring 2FA bypasses in web app settings pages functionality
https://link.medium.com/HegWKfSi3w
In this story I discuss how you can find bugs just like this on other web applications not just Facebook. If you enjoyed the story hit that follow button for more.
submitted by /u/TheCrazyAcademic
[link] [comments]
Setting you up for failure: Exploring 2FA bypasses in web app settings pages functionality
https://link.medium.com/HegWKfSi3w
In this story I discuss how you can find bugs just like this on other web applications not just Facebook. If you enjoyed the story hit that follow button for more.
submitted by /u/TheCrazyAcademic
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
what can ya do with a hacked printer? (jetdirect? port 9100 vuln)
my friend that owns a coffee shop asked me to poke around on his network to look for vulnerabilities in exchange for some free coffees and i saw that they had 9100 open, wasn't familiar with it so played around and found out about PRET which gave me access to his HP printer, with transversal you can gain access to the file system etc and from what i read you can open a root shell on another port, would the scope be limited to the printer, or can the printer be used as a vector to gain access to other systems connecting to said printer?
tldr im not familar with printers and found a vuln, what do, i like my free cup-a-joes while writing my dnd campaigns.
submitted by /u/werewolfpajamas
[link] [comments]
what can ya do with a hacked printer? (jetdirect? port 9100 vuln)
my friend that owns a coffee shop asked me to poke around on his network to look for vulnerabilities in exchange for some free coffees and i saw that they had 9100 open, wasn't familiar with it so played around and found out about PRET which gave me access to his HP printer, with transversal you can gain access to the file system etc and from what i read you can open a root shell on another port, would the scope be limited to the printer, or can the printer be used as a vector to gain access to other systems connecting to said printer?
tldr im not familar with printers and found a vuln, what do, i like my free cup-a-joes while writing my dnd campaigns.
submitted by /u/werewolfpajamas
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pirating
Hey y'all I'm running a little low on cash right now so I'm trying to turn to the best source of cash I can right now so if anyone wants anything pirated Right now send me a message I'll get it pirated for you give me like the specifications of what you want pirated and I'll get it for you depending on what it is the the price will change I'm going to keep it as cheap as I can shoot me a message if you're interested
submitted by /u/Fsociety621
[link] [comments]
Pirating
Hey y'all I'm running a little low on cash right now so I'm trying to turn to the best source of cash I can right now so if anyone wants anything pirated Right now send me a message I'll get it pirated for you give me like the specifications of what you want pirated and I'll get it for you depending on what it is the the price will change I'm going to keep it as cheap as I can shoot me a message if you're interested
submitted by /u/Fsociety621
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Exploiting WordPress site with no vulnerable plugins
Hi, I'm doing a CTF on a WordPress site but WPscan shows no vulnerable plugins/themes. I have one username and wp-login page, but I'm told that brute-forcing is not required for this box. There aren't any weird directories found via enumeration, and robots.txt only contains a line on wp-admin/admin-ajax.php.
In my experience with exploiting WordPress, usually finding something vulnerable in WPscan shows me which way to go, but now I'm stumped. Does anyone have any ideas, or is this a red herring?
submitted by /u/Slayre77
[link] [comments]
Exploiting WordPress site with no vulnerable plugins
Hi, I'm doing a CTF on a WordPress site but WPscan shows no vulnerable plugins/themes. I have one username and wp-login page, but I'm told that brute-forcing is not required for this box. There aren't any weird directories found via enumeration, and robots.txt only contains a line on wp-admin/admin-ajax.php.
In my experience with exploiting WordPress, usually finding something vulnerable in WPscan shows me which way to go, but now I'm stumped. Does anyone have any ideas, or is this a red herring?
submitted by /u/Slayre77
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BurpSuite Add all subdomains to scope
https://cdn-images-1.medium.com/max/1098/1*iYTHBv9-l4bvdc4fi40KZA.png
If the target is TARGET.COM then do the following to update all subdomains to scope:
Continue reading on Medium »
BurpSuite Add all subdomains to scope
https://cdn-images-1.medium.com/max/1098/1*iYTHBv9-l4bvdc4fi40KZA.png
If the target is TARGET.COM then do the following to update all subdomains to scope:
Continue reading on Medium »