Hey Guys, I am banti samanta, a Security Researcher and a Bug Bounty Hunter. In this blog, I will be sharing a list of 350+ Free Tryhackme…Continue reading on Medium » (https://medium.com/@samantabanti056/free-350-tryhackme-rooms-4f44cfdf640b?source=rss------bug_bounty-5)
Bypassing API Restrictions for Fun and Profit
https://arnavtripathy98.medium.com/bypassing-api-restrictions-for-fun-and-profit-c9ab746b67be?source=rss------bug_bounty-5
https://arnavtripathy98.medium.com/bypassing-api-restrictions-for-fun-and-profit-c9ab746b67be?source=rss------bug_bounty-5
Recently, I downloaded and started testing an application locally which provided dashboard access along with rest API endpoints for it’s…Continue reading on Medium » (https://arnavtripathy98.medium.com/bypassing-api-restrictions-for-fun-and-profit-c9ab746b67be?source=rss------bug_bounty-5)
Reveal the Cloud with Google Dorks
https://infosecwriteups.com/uncover-hidden-gems-in-the-cloud-with-google-dorks-8621e56a329d?source=rss------bug_bounty-5
https://infosecwriteups.com/uncover-hidden-gems-in-the-cloud-with-google-dorks-8621e56a329d?source=rss------bug_bounty-5
Find sensitive data in Amazon AWS, Google Cloud, and moreContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/uncover-hidden-gems-in-the-cloud-with-google-dorks-8621e56a329d?source=rss------bug_bounty-5)
Any one can please suggest me Active Directory machines in HTB for oscp exam.
https://www.reddit.com/r/Pentesting/comments/10wbkv7/any_one_can_please_suggest_me_active_directory/
submitted by /u/Nice-Cantaloupe-6566 (https://www.reddit.com/user/Nice-Cantaloupe-6566)
[link] (https://www.reddit.com/r/Pentesting/comments/10wbkv7/any_one_can_please_suggest_me_active_directory/) [comments] (https://www.reddit.com/r/Pentesting/comments/10wbkv7/any_one_can_please_suggest_me_active_directory/)
https://www.reddit.com/r/Pentesting/comments/10wbkv7/any_one_can_please_suggest_me_active_directory/
submitted by /u/Nice-Cantaloupe-6566 (https://www.reddit.com/user/Nice-Cantaloupe-6566)
[link] (https://www.reddit.com/r/Pentesting/comments/10wbkv7/any_one_can_please_suggest_me_active_directory/) [comments] (https://www.reddit.com/r/Pentesting/comments/10wbkv7/any_one_can_please_suggest_me_active_directory/)
List of 41 Frequently Occurring Web Application Vulnerabilities
https://medium.com/@gokulelango1040/list-of-41-frequently-occurring-web-application-vulnerabilities-7e9e24489914?source=rss------bug_bounty-5
https://medium.com/@gokulelango1040/list-of-41-frequently-occurring-web-application-vulnerabilities-7e9e24489914?source=rss------bug_bounty-5
These are all considerably more crucial vulnerabilities and are employed in bug bounty programmes.Just add into your list and gather much…Continue reading on Medium » (https://medium.com/@gokulelango1040/list-of-41-frequently-occurring-web-application-vulnerabilities-7e9e24489914?source=rss------bug_bounty-5)
https://external-preview.redd.it/E3roXMzaRVfHRgM1cU44PtV5PntgwZtCB_3ryZyDeLE.jpg?width=320&crop=smart&auto=webp&s=69790332c4f36a5f20d9cf9f72b3a1f4aacd3724 Hi All!
Using metasploit for a College project and am using the following video: (11) Metasploit For Beginners - How To Scan And Pwn A Computer | Learn From A Pro Hacker - YouTube
I made a target to hack from my old PC (windows 7 pro OS) and have disabled firewall to make it easier to exploit. However, after following the tutorial exactly (until this point everything works like the tutorial), I enter the "exploit" command and the process just times out after a few minutes.
These are the metasploit properties I'm using:
* auxiliary - auxiliary/scanner/smb/smb_ms17_010
* exploit - exploit/windows/smb/ms17_010_psexec
* payload - windows/x64/meterpreter/reverse_http
This is a screenshot of what results from the exploit command gives me:
https://preview.redd.it/twts248cmtga1.png?width=815&format=png&auto=webp&s=5f199b2e2491606ae5c98367f9e70e341d74e77e
Let me know if any other information is needed and any help is really appreciated! Hacking is hard!
submitted by /u/Gaffer122
[link] [comments]
Using metasploit for a College project and am using the following video: (11) Metasploit For Beginners - How To Scan And Pwn A Computer | Learn From A Pro Hacker - YouTube
I made a target to hack from my old PC (windows 7 pro OS) and have disabled firewall to make it easier to exploit. However, after following the tutorial exactly (until this point everything works like the tutorial), I enter the "exploit" command and the process just times out after a few minutes.
These are the metasploit properties I'm using:
* auxiliary - auxiliary/scanner/smb/smb_ms17_010
* exploit - exploit/windows/smb/ms17_010_psexec
* payload - windows/x64/meterpreter/reverse_http
This is a screenshot of what results from the exploit command gives me:
https://preview.redd.it/twts248cmtga1.png?width=815&format=png&auto=webp&s=5f199b2e2491606ae5c98367f9e70e341d74e77e
Let me know if any other information is needed and any help is really appreciated! Hacking is hard!
submitted by /u/Gaffer122
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
[ LONG POST ] -- I've always wondered: Even though it's usually considered a bad idea, is it it okay to re-use passwords across multiple programs IF THE PROGRAMS ARE UNIMPORTANT? In other words, you have different "tiers" of passwords that you use for programs of different levels of importance?
Hello everyone,
I've wondered something for years now, and am hoping to have a discussion about it.
In a perfect world, we would have two or three-factor authentication on ALL programs, be they something as important as your bank account, or something as trivial as your Neopets account, and the passwords used for each account would be unique, and difficult passwords, like 2%!#gasG45$&*asd12.
In the real world, however, I have been unable to find a good system to achieve this. Sure, I can get a password manager or something like my Google Account to create a bunch of unique and difficult passwords for every account, and then hide all of that behind a single two-factor authentication system for the password manager as a whole, but this has issues. Namely, there are times when I don't have access to my main password manager account, but still need access to one of the accounts it manages.
For example, say that my password manager is on my PC at home, but I'm at a friends house, and want to log in to my Instagram account to show them a meme I saved -- there's no way to get in, unless I actually remember the password. This means I can't use unique and difficult passwords.
In other words, if I go with a password manager, I can ONLY ever log into things with my home-PC, unless the password-manager's own password is easy enough that I can remember it (which then presents its own risks, as all of the passwords under the password manager are now easily-hacked.
So, I've always wondered if there's a problem with re-using passwords across accounts for programs that don't really matter if someone hacks. I know that re-using passwords is typically looked down on, but if we're talking about something like your Runescape account, what harm is there really to your life if it gets hacked?
For obvious reasons, the example passwords I'm sharing below have no relation to my real-life passwords, except in regards to the general feel of their difficulty to memorize.
So, as an example:
--Tier One--
Programs: Youtube, ArmorGames, Reddit, Minecraft, Pinterest, etc. Accounts with no payment info on file, and which don't really matter if they get hacked.
Password: An easy password like Password123456 for all of them.
-- Tier Two --
Programs: Facebook, Instagram, Snapchat, etc. Accounts with no payment info on file, but which would have annoying temporary social consequences if hacked. Also programs like Steam, Amazon, Ebay, etc., with payment info on file, but with strong anti-fraud protections.
Password: A mix of medium-difficult passwords like 67SierraApple15!, 49HorseTango15!, and 29Bottle49Staples, spread between them (so two or three programs might share the same password, but no more than that.)
-- Tier Three --
Programs: My Bank, My Google Account, My IRS Account, etc. Accounts with mass-money implications, and/or identity-theft concerns.
Password: Medium-difficult-style passwords like 59%%FoxtrotDepressed19 that are unique to each program, with 2-factor authentication if available.
Is this an acceptable password strategy, or am I setting myself up for disaster here? I just don't see how something like a password manager is better, when it puts all of your passwords into a single basket, creating a single point of failure for every account you have. Maybe I just don't understand them, but password managers seem like a huge step backwards in cybersecurity.
Any insight or thoughts is appreciated. Thank you for your time!
submitted by /u/--Ty--
[link] [comments]
[ LONG POST ] -- I've always wondered: Even though it's usually considered a bad idea, is it it okay to re-use passwords across multiple programs IF THE PROGRAMS ARE UNIMPORTANT? In other words, you have different "tiers" of passwords that you use for programs of different levels of importance?
Hello everyone,
I've wondered something for years now, and am hoping to have a discussion about it.
In a perfect world, we would have two or three-factor authentication on ALL programs, be they something as important as your bank account, or something as trivial as your Neopets account, and the passwords used for each account would be unique, and difficult passwords, like 2%!#gasG45$&*asd12.
In the real world, however, I have been unable to find a good system to achieve this. Sure, I can get a password manager or something like my Google Account to create a bunch of unique and difficult passwords for every account, and then hide all of that behind a single two-factor authentication system for the password manager as a whole, but this has issues. Namely, there are times when I don't have access to my main password manager account, but still need access to one of the accounts it manages.
For example, say that my password manager is on my PC at home, but I'm at a friends house, and want to log in to my Instagram account to show them a meme I saved -- there's no way to get in, unless I actually remember the password. This means I can't use unique and difficult passwords.
In other words, if I go with a password manager, I can ONLY ever log into things with my home-PC, unless the password-manager's own password is easy enough that I can remember it (which then presents its own risks, as all of the passwords under the password manager are now easily-hacked.
So, I've always wondered if there's a problem with re-using passwords across accounts for programs that don't really matter if someone hacks. I know that re-using passwords is typically looked down on, but if we're talking about something like your Runescape account, what harm is there really to your life if it gets hacked?
For obvious reasons, the example passwords I'm sharing below have no relation to my real-life passwords, except in regards to the general feel of their difficulty to memorize.
So, as an example:
--Tier One--
Programs: Youtube, ArmorGames, Reddit, Minecraft, Pinterest, etc. Accounts with no payment info on file, and which don't really matter if they get hacked.
Password: An easy password like Password123456 for all of them.
-- Tier Two --
Programs: Facebook, Instagram, Snapchat, etc. Accounts with no payment info on file, but which would have annoying temporary social consequences if hacked. Also programs like Steam, Amazon, Ebay, etc., with payment info on file, but with strong anti-fraud protections.
Password: A mix of medium-difficult passwords like 67SierraApple15!, 49HorseTango15!, and 29Bottle49Staples, spread between them (so two or three programs might share the same password, but no more than that.)
-- Tier Three --
Programs: My Bank, My Google Account, My IRS Account, etc. Accounts with mass-money implications, and/or identity-theft concerns.
Password: Medium-difficult-style passwords like 59%%FoxtrotDepressed19 that are unique to each program, with 2-factor authentication if available.
Is this an acceptable password strategy, or am I setting myself up for disaster here? I just don't see how something like a password manager is better, when it puts all of your passwords into a single basket, creating a single point of failure for every account you have. Maybe I just don't understand them, but password managers seem like a huge step backwards in cybersecurity.
Any insight or thoughts is appreciated. Thank you for your time!
submitted by /u/--Ty--
[link] [comments]