Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Phishing Tips?
https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/

<!-- SC_OFF -->Hey all, I have an upcoming physical/phishing engagement. Unfortunately I was tasked very short notice to develop a phishing campaign with custom domains. My boss is VERY adamant that this remains hush-hush so no whitelisting. (We are a PE firm testing some portfolios companies.) So far I have the domains bought, SPF, DKIM, and DMARC have been configured. I’ve tested my email configuration against mail tester and it’s 10/10. I have tried various combinations of O365 and SMTP APIs but everything I have tried ends up hitting the spam filter. Do you all have any recommendations on how to build IP/Domain reputation fast? Have any of you had success with an inbox warmer? I realize that this might not be possible on such short notice ( <!-- SC_ON --> submitted by /u/KungFuBatman (https://www.reddit.com/user/KungFuBatman)
[link] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/) [comments] (https://www.reddit.com/r/redteamsec/comments/10qgajf/phishing_tips/)
Dark Reading: Attacks/Breaches
How Can Disrupting DNS Communications Thwart a Malware Attack?

Malware eventually has to exfiltrate the data it accessed. By watching DNS traffic for suspicious activity, organizations can halt the damage.
Tips for Becoming a Proficient Bug Bounty Hunter

How to Become a Bug Bounty HunterContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Setting you up for failure: Exploring 2FA bypasses in web app settings pages functionality

https://link.medium.com/HegWKfSi3w

In this story I discuss how you can find bugs just like this on other web applications not just Facebook. If you enjoyed the story hit that follow button for more.

submitted by /u/TheCrazyAcademic
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
what can ya do with a hacked printer? (jetdirect? port 9100 vuln)

my friend that owns a coffee shop asked me to poke around on his network to look for vulnerabilities in exchange for some free coffees and i saw that they had 9100 open, wasn't familiar with it so played around and found out about PRET which gave me access to his HP printer, with transversal you can gain access to the file system etc and from what i read you can open a root shell on another port, would the scope be limited to the printer, or can the printer be used as a vector to gain access to other systems connecting to said printer?



tldr im not familar with printers and found a vuln, what do, i like my free cup-a-joes while writing my dnd campaigns.

submitted by /u/werewolfpajamas
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pirating

Hey y'all I'm running a little low on cash right now so I'm trying to turn to the best source of cash I can right now so if anyone wants anything pirated Right now send me a message I'll get it pirated for you give me like the specifications of what you want pirated and I'll get it for you depending on what it is the the price will change I'm going to keep it as cheap as I can shoot me a message if you're interested

submitted by /u/Fsociety621
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Exploiting WordPress site with no vulnerable plugins

Hi, I'm doing a CTF on a WordPress site but WPscan shows no vulnerable plugins/themes. I have one username and wp-login page, but I'm told that brute-forcing is not required for this box. There aren't any weird directories found via enumeration, and robots.txt only contains a line on wp-admin/admin-ajax.php.

In my experience with exploiting WordPress, usually finding something vulnerable in WPscan shows me which way to go, but now I'm stumped. Does anyone have any ideas, or is this a red herring?

submitted by /u/Slayre77
[link] [comments]