HAI Utility in HackenProof: Get More Bounties with HAI
https://hackenclub.medium.com/hai-utility-in-hackenproof-earn-higher-bounties-with-hai-76064df5a76?source=rss------bug_bounty-5
https://hackenclub.medium.com/hai-utility-in-hackenproof-earn-higher-bounties-with-hai-76064df5a76?source=rss------bug_bounty-5
As part of the new HAI utility implementation, we’re announcing its extension to HackenProof.Continue reading on Medium » (https://hackenclub.medium.com/hai-utility-in-hackenproof-earn-higher-bounties-with-hai-76064df5a76?source=rss------bug_bounty-5)
What is Broken Access Control bug ?
https://medium.com/@samantabanti056/what-is-broken-access-control-bug-e39e0ac7e54b?source=rss------bug_bounty-5
Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized…Continue reading on Medium » (https://medium.com/@samantabanti056/what-is-broken-access-control-bug-e39e0ac7e54b?source=rss------bug_bounty-5)
https://medium.com/@samantabanti056/what-is-broken-access-control-bug-e39e0ac7e54b?source=rss------bug_bounty-5
Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized…Continue reading on Medium » (https://medium.com/@samantabanti056/what-is-broken-access-control-bug-e39e0ac7e54b?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What's the threshold of skill at which you could be classified as a "hacker?"
I've been wondering this for a bit. We have different classifications of hackers, both in the private and government sector. Classifications range from script kiddies to advanced persistent threats (ATPs). There is also a tier system. But to be classified as a hacker. Not to advertise is, but to know that you have become one (ethical or unethical), what do you suppose the skill threshold is? Maybe a certification such as OSCP? Or the ability to do a hard HTB with no hints?
submitted by /u/idkbrololwtf
[link] [comments]
What's the threshold of skill at which you could be classified as a "hacker?"
I've been wondering this for a bit. We have different classifications of hackers, both in the private and government sector. Classifications range from script kiddies to advanced persistent threats (ATPs). There is also a tier system. But to be classified as a hacker. Not to advertise is, but to know that you have become one (ethical or unethical), what do you suppose the skill threshold is? Maybe a certification such as OSCP? Or the ability to do a hard HTB with no hints?
submitted by /u/idkbrololwtf
[link] [comments]
Diving Deeper Into Pre-created Computer Accounts
https://www.reddit.com/r/redteamsec/comments/10vjwy1/diving_deeper_into_precreated_computer_accounts/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.optiv.com/insights/source-zero/blog/diving-deeper-pre-created-computer-accounts) [comments] (https://www.reddit.com/r/redteamsec/comments/10vjwy1/diving_deeper_into_precreated_computer_accounts/)
https://www.reddit.com/r/redteamsec/comments/10vjwy1/diving_deeper_into_precreated_computer_accounts/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.optiv.com/insights/source-zero/blog/diving-deeper-pre-created-computer-accounts) [comments] (https://www.reddit.com/r/redteamsec/comments/10vjwy1/diving_deeper_into_precreated_computer_accounts/)
Question About Hydra
https://www.reddit.com/r/Pentesting/comments/10vo7c7/question_about_hydra/
<!-- SC_OFF -->I’ve just started learning about Hydra and other penetration tools. I’m working through the easy CTF challenges on hacker101. Trying to run Hydra to solve for username, using rockyou.txt as the list. My question. Is 569 tries/min EXTREMELY slow? I’m using a 2018 Mac 3.2ghz 6Core i7. The updates are estimating 400hrs to complete. Just want to know if this is expected, or could I be possibly not configured correctly. Tks <!-- SC_ON --> submitted by /u/swapau (https://www.reddit.com/user/swapau)
[link] (https://www.reddit.com/r/Pentesting/comments/10vo7c7/question_about_hydra/) [comments] (https://www.reddit.com/r/Pentesting/comments/10vo7c7/question_about_hydra/)
https://www.reddit.com/r/Pentesting/comments/10vo7c7/question_about_hydra/
<!-- SC_OFF -->I’ve just started learning about Hydra and other penetration tools. I’m working through the easy CTF challenges on hacker101. Trying to run Hydra to solve for username, using rockyou.txt as the list. My question. Is 569 tries/min EXTREMELY slow? I’m using a 2018 Mac 3.2ghz 6Core i7. The updates are estimating 400hrs to complete. Just want to know if this is expected, or could I be possibly not configured correctly. Tks <!-- SC_ON --> submitted by /u/swapau (https://www.reddit.com/user/swapau)
[link] (https://www.reddit.com/r/Pentesting/comments/10vo7c7/question_about_hydra/) [comments] (https://www.reddit.com/r/Pentesting/comments/10vo7c7/question_about_hydra/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Where To Draw The Legal Line
Hello all, I'm a white hat who is interested in advancing my offensive skills. I've just gotten my GCIH certification, and during that course I learned some of the basics. I'd love to continue testing and playing around with some of the tools I learned about outside of the VM environment they supplied us with. However, I am totally unsure about where my activity becomes illegal and I don't want to even come close to committing any crimes unknowingly. Does anyone have any information on how I can go about this? Can I use nmap on a public network? Can I throw some sql injection tests in some random website? How do bug bounty hunters do it? Let me know if anyone can advise on this, thank you!
submitted by /u/spenny1111
[link] [comments]
Where To Draw The Legal Line
Hello all, I'm a white hat who is interested in advancing my offensive skills. I've just gotten my GCIH certification, and during that course I learned some of the basics. I'd love to continue testing and playing around with some of the tools I learned about outside of the VM environment they supplied us with. However, I am totally unsure about where my activity becomes illegal and I don't want to even come close to committing any crimes unknowingly. Does anyone have any information on how I can go about this? Can I use nmap on a public network? Can I throw some sql injection tests in some random website? How do bug bounty hunters do it? Let me know if anyone can advise on this, thank you!
submitted by /u/spenny1111
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Metasploit: From Basics to Advanced Exploitation
Metasploit is a popular open-source framework used for developing and executing exploits against various systems and applications. It was…
Continue reading on Medium »
Metasploit: From Basics to Advanced Exploitation
Metasploit is a popular open-source framework used for developing and executing exploits against various systems and applications. It was…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Dark Truth About the Dark Web
https://cdn-images-1.medium.com/max/2600/1*eSkFVl25ds6Aajf88Aahqw.jpeg
The dark web, often depicted as a shadowy and nefarious corner of the internet, has long been shrouded in mystery and intrigue. But just…
Continue reading on Medium »
The Dark Truth About the Dark Web
https://cdn-images-1.medium.com/max/2600/1*eSkFVl25ds6Aajf88Aahqw.jpeg
The dark web, often depicted as a shadowy and nefarious corner of the internet, has long been shrouded in mystery and intrigue. But just…
Continue reading on Medium »