Hacking on Medium
TryHackMe: Burp Suite: Basics — Walkthrough
https://cdn-images-1.medium.com/max/875/0*mJHzwgbI_7ey9QlZ.png
Room URL: https://tryhackme.com/room/burpsuitebasics
Continue reading on Medium »
TryHackMe: Burp Suite: Basics — Walkthrough
https://cdn-images-1.medium.com/max/875/0*mJHzwgbI_7ey9QlZ.png
Room URL: https://tryhackme.com/room/burpsuitebasics
Continue reading on Medium »
Medium
TryHackMe: Burp Suite: Basics — Walkthrough
Room URL: https://tryhackme.com/room/burpsuitebasics
Hacking on Medium
Poolz Hack Description
https://cdn-images-1.medium.com/max/1638/1*JyDO8DpMo1feKlI5w0Z8JA.jpeg
Ironblocks detection system was tracking @Poolz_ protocol hack and was notified in real-time when the hack began. The hacker was able to…
Continue reading on Medium »
Poolz Hack Description
https://cdn-images-1.medium.com/max/1638/1*JyDO8DpMo1feKlI5w0Z8JA.jpeg
Ironblocks detection system was tracking @Poolz_ protocol hack and was notified in real-time when the hack began. The hacker was able to…
Continue reading on Medium »
Medium
Poolz Hack Description
Ironblocks detection system was tracking @Poolz_ protocol hack and was notified in real-time when the hack began. The hacker was able to…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Using Hydra against a website with a domain?
I am doing a hacker101 ctf challenge where the website looks something along the lines of https://2a9039bb6bed24d639d897044b7bbfe9.ctf.hacker101.com/. The challenge is titled petshop pro. At some point of the challenge, I have to bruteforce a web form. My normal method of using Hydra on ctf challenges does not work because I have to mention an IP address for it to work. My normal method of usage would look something like this:
hydra -l Elliot -P fsocity.dic 10.10.250.126 http-post-form "/wp-login.php:log=^USER^+&pwd=^PASS^&rememberme=forever&wp-submit=Log+In&redirect_to=http%3A%2F%2F10.10.250.126%2Fwp-admin%2F&testcookie=1:F=ERROR" -V
I tried using dig on the domain but can't seem to find the IP address. For some reason, previous writeup for this challenge have IP addresses to work with. Is there any way I could use Hydra with a domain name and without an IP address?
submitted by /u/Super_Tsumu
[link] [comments]
Using Hydra against a website with a domain?
I am doing a hacker101 ctf challenge where the website looks something along the lines of https://2a9039bb6bed24d639d897044b7bbfe9.ctf.hacker101.com/. The challenge is titled petshop pro. At some point of the challenge, I have to bruteforce a web form. My normal method of using Hydra on ctf challenges does not work because I have to mention an IP address for it to work. My normal method of usage would look something like this:
hydra -l Elliot -P fsocity.dic 10.10.250.126 http-post-form "/wp-login.php:log=^USER^+&pwd=^PASS^&rememberme=forever&wp-submit=Log+In&redirect_to=http%3A%2F%2F10.10.250.126%2Fwp-admin%2F&testcookie=1:F=ERROR" -V
I tried using dig on the domain but can't seem to find the IP address. For some reason, previous writeup for this challenge have IP addresses to work with. Is there any way I could use Hydra with a domain name and without an IP address?
submitted by /u/Super_Tsumu
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Two U.S. Men Charged in 2022 Hacking of DEA Portal
submitted by /u/DrinkMoreCodeMore
[link] [comments]
Two U.S. Men Charged in 2022 Hacking of DEA Portal
submitted by /u/DrinkMoreCodeMore
[link] [comments]
Bypassing Character Limit — XSS Using Spanned Payload
Hello, I am Syed Mushfik Hasan Tahsin aka SMHTahsin33, an 18 Y/O Cyber Security Enthusiast from Bangladesh. I am into Infosec due to…Continue reading on InfoSec Write-ups »
Read more...
Hello, I am Syed Mushfik Hasan Tahsin aka SMHTahsin33, an 18 Y/O Cyber Security Enthusiast from Bangladesh. I am into Infosec due to…Continue reading on InfoSec Write-ups »
Read more...
Reconnaissance tools that every pen tester and bug bunty hunter should know.
https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5
https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5
There are many tools available for performing reconnaissance, but some of them stand out for their features, functionality, and popularity.Continue reading on Geek Culture » (https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5)
Pen Testing vs Bug Bounty
https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5
Penetration testing (pen testing) and bug bounty programs are means of discovering security vulnerabilities from an adversary’s point of…Continue reading on Medium » (https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5)
https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5
Penetration testing (pen testing) and bug bounty programs are means of discovering security vulnerabilities from an adversary’s point of…Continue reading on Medium » (https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5)
GitGraber: A Tool for Finding Sensitive Information in GitHub Repositories
https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5
https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5
GitGraber is an open-source tool developed by Hisxo that can be used to scan GitHub repositories for sensitive information. The tool uses…Continue reading on Medium » (https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5)
Mobile ops
https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/
<!-- SC_OFF -->I need to know what a good secure preferable cheap laptop that I can put parrot os or kali on. Thanks <!-- SC_ON --> submitted by /u/Ctap70 (https://www.reddit.com/user/Ctap70)
[link] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/) [comments] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/)
https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/
<!-- SC_OFF -->I need to know what a good secure preferable cheap laptop that I can put parrot os or kali on. Thanks <!-- SC_ON --> submitted by /u/Ctap70 (https://www.reddit.com/user/Ctap70)
[link] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/) [comments] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/)
BeyondTrust AD Bridge Open Post-Exploitation
https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/
submitted by /u/v1brio (https://www.reddit.com/user/v1brio)
[link] (https://ricardojba.github.io/BeyondTrust-AD-Bridge-Open-Post-Exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/)
https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/
submitted by /u/v1brio (https://www.reddit.com/user/v1brio)
[link] (https://ricardojba.github.io/BeyondTrust-AD-Bridge-Open-Post-Exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/)
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/)
https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/)
Goblob: A fast enumeration tool for publicly exposed Azure Storage blobs
https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/
submitted by /u/Macmod- (https://www.reddit.com/user/Macmod-)
[link] (https://github.com/Macmod/goblob) [comments] (https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/)
https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/
submitted by /u/Macmod- (https://www.reddit.com/user/Macmod-)
[link] (https://github.com/Macmod/goblob) [comments] (https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/)