Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bypassing Character Limit — XSS Using Spanned Payload

Hello, I am Syed Mushfik Hasan Tahsin aka SMHTahsin33, an 18 Y/O Cyber Security Enthusiast from Bangladesh. I am into Infosec due to…Continue reading on InfoSec Write-ups »
Read more...
There are many tools available for performing reconnaissance, but some of them stand out for their features, functionality, and popularity.Continue reading on Geek Culture » (https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5)
Pen Testing vs Bug Bounty
https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5

Penetration testing (pen testing) and bug bounty programs are means of discovering security vulnerabilities from an adversary’s point of…Continue reading on Medium » (https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5)
GitGraber is an open-source tool developed by Hisxo that can be used to scan GitHub repositories for sensitive information. The tool uses…Continue reading on Medium » (https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5)
Mobile ops
https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/

<!-- SC_OFF -->I need to know what a good secure preferable cheap laptop that I can put parrot os or kali on. Thanks <!-- SC_ON --> submitted by /u/Ctap70 (https://www.reddit.com/user/Ctap70)
[link] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/) [comments] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/)
Dark Reading: Attacks/Breaches
GoatRAT Android Banking Trojan Targets Mobile Automated Payment System

The new malware was discovered targeting three banks in Brazil.
Dark Reading: Attacks/Breaches
Why Security Practitioners Should Understand Their Business

The sooner CISOs become proactive in understanding the flip side of the organizations they protect, the better they'll be at their jobs.
Dark Reading: Attacks/Breaches
SMBs Orgs Want Help, but Cybersecurity Expertise Is Scarce

Smaller firms are boosting cybersecurity budgets, but there's a long way to go to address a deep lack of cyber preparedness among SMBs.
Dark Reading: Attacks/Breaches
Google Proposes Reducing TLS Cert Life Span to 90 Days

Organizations will likely have until the end of 2024 to gain visibility and control over their keys and certificates.
How do I test the CovertVPN connection in cobalt strike?
https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/

<!-- SC_OFF -->I have created a VPN interface in my current session and believe that I can successfully connect to the network it is tunnling to, however I don't know how to test if it can see what's on the other network since I don't know what is on the other network and I also can't seem to find ways to test it since much of the info online is old and outdated (or the interface has changed so drastically over the years that they no longer apply). I am wanting a simple way to test if the VPN client it working besides seeing traffic leaving and arriving in the console, that's not convincing enough. <!-- SC_ON --> submitted by /u/baronobeefdip2 (https://www.reddit.com/user/baronobeefdip2)
[link] (https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/)
How do I fetch the Beacon IDs in cobalt strike?
https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/

<!-- SC_OFF -->I need this to be doable through the console of cobalt strike or through an aggressor script. Much of what I am finding on the matter is outdated and I don't know a lot about some of the internal methods of the scripting environment. I need a way to programmatically identify the Beacon IDs that are currently residing on the teams server. For now I have just been going through the logs directory which is a bit time consuming and confusing at times when you deal with multiple beacons. <!-- SC_ON --> submitted by /u/baronobeefdip2 (https://www.reddit.com/user/baronobeefdip2)
[link] (https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/)