Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Using Hydra against a website with a domain?

I am doing a hacker101 ctf challenge where the website looks something along the lines of https://2a9039bb6bed24d639d897044b7bbfe9.ctf.hacker101.com/. The challenge is titled petshop pro. At some point of the challenge, I have to bruteforce a web form. My normal method of using Hydra on ctf challenges does not work because I have to mention an IP address for it to work. My normal method of usage would look something like this:

hydra -l Elliot -P fsocity.dic 10.10.250.126 http-post-form "/wp-login.php:log=^USER^+&pwd=^PASS^&rememberme=forever&wp-submit=Log+In&redirect_to=http%3A%2F%2F10.10.250.126%2Fwp-admin%2F&testcookie=1:F=ERROR" -V

I tried using dig on the domain but can't seem to find the IP address. For some reason, previous writeup for this challenge have IP addresses to work with. Is there any way I could use Hydra with a domain name and without an IP address?

submitted by /u/Super_Tsumu
[link] [comments]
Bypassing Character Limit — XSS Using Spanned Payload

Hello, I am Syed Mushfik Hasan Tahsin aka SMHTahsin33, an 18 Y/O Cyber Security Enthusiast from Bangladesh. I am into Infosec due to…Continue reading on InfoSec Write-ups »
Read more...
There are many tools available for performing reconnaissance, but some of them stand out for their features, functionality, and popularity.Continue reading on Geek Culture » (https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5)
Pen Testing vs Bug Bounty
https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5

Penetration testing (pen testing) and bug bounty programs are means of discovering security vulnerabilities from an adversary’s point of…Continue reading on Medium » (https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5)
GitGraber is an open-source tool developed by Hisxo that can be used to scan GitHub repositories for sensitive information. The tool uses…Continue reading on Medium » (https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5)
Mobile ops
https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/

<!-- SC_OFF -->I need to know what a good secure preferable cheap laptop that I can put parrot os or kali on. Thanks <!-- SC_ON --> submitted by /u/Ctap70 (https://www.reddit.com/user/Ctap70)
[link] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/) [comments] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/)