Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
11 Expert Tips to Succeed in Bug Bounty

My last, first article, published here after years of silent reading, received such a positive response I decided to create a more…Continue reading on Medium »
Read more...
My last, first article, published here after years of silent reading, received such a positive response I decided to create a more…Continue reading on Medium » (https://medium.com/@ReidAJ/11-expert-tips-to-succeed-in-bug-bounty-3193652c99f4?source=rss------bug_bounty-5)
Dark Reading: Attacks/Breaches
CISA Releases Recovery Script for Victims of ESXiArgs Ransomware

The malware has affected thousands of VMware ESXi hypervisors in the last few days.
Dark Reading: Attacks/Breaches
Jailbreak Trick Breaks ChatGPT Content Safeguards

Jailbreak command creates ChatGPT alter ego DAN, willing to create content outside of its own content restriction controls.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
WordPress Login Flooder (DDoS) python script I used on a client to test Fastly VCL misconfig

Recently, I was pentesting a client site and discovered they had a misconfig'd Fastly VCL. As such, it allowed spoofing, which meant all access logging in BigQuery and GCP log viewer were nearly irrelevant as you couldn't trust whether or not it listed true origin IP.

To simulate the need to fix this issue, I wrote a simple Python script for spoofing with a DDoS. Unlike most "DDoS" scripts you'll find in a repo (which don't utilize zombies and therefore only sends requests from your own machine, aka just a DoS), I included mine to cycle through various proxies for obfuscation.

If the client hadn't corrected the VCL config, they were susceptible to a potential unstoppable DDoS, as they had no rate-limiting enabled nor could have discovered the true IP if it were spoofed.

Nevertheless, check the script on GitHub and feel free to submit PRs or fork and use it for your own legal purposes.

submitted by /u/n4bb
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
is there anything like the Flipper Zero but for kali linux?

I've been wanting one for awhile but don't have the money so I was wondering if there's anything in kali I can set up that would do the same thing

submitted by /u/Last-Ad-1437
[link] [comments]
https://b.thumbs.redditmedia.com/2hJs3y61vt0cHyk_2QxjMwwg9u97KwfxZLZCftvgSds.jpg i'm trying to use bettercap for arp spoof attack. When i started the attack, arp spoof is working normal. But ip forwarding is not working so my internet connection is lost. How can i solve this problem? If anyone knows the solution and can help me, I'd appreciate it.

normally it should be like this

but this is what i have on my device

submitted by /u/Flashy-Remote6891
[link] [comments]