Coinstore Bug Bounty Event
https://coinstore.medium.com/coinstore-bug-bounty-event-2aac4bae3880?source=rss------bug_bounty-5
Dear Coin Collectors,Continue reading on Medium » (https://coinstore.medium.com/coinstore-bug-bounty-event-2aac4bae3880?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://coinstore.medium.com/coinstore-bug-bounty-event-2aac4bae3880?source=rss------bug_bounty-5
Dear Coin Collectors,Continue reading on Medium » (https://coinstore.medium.com/coinstore-bug-bounty-event-2aac4bae3880?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Coinstore Bug Bounty Event
Dear Coin Collectors,
Black Hat Ethical Hacking
Microsoft, Google Clouds Hijacked for Gobs of Phishing
Microsoft, Google Clouds Hijacked for Gobs of Phishing
Writeups: Facebook Whitehat program(2021): Instagram Live setting bug(500 USD)
https://takashi-suzuki.medium.com/writeups-facebook-whitehat-program-2021-instagram-live-setting-bug-500-usd-d2d076b3f8bb?source=rss------bug_bounty-5
https://takashi-suzuki.medium.com/writeups-facebook-whitehat-program-2021-instagram-live-setting-bug-500-usd-d2d076b3f8bb?source=rss------bug_bounty-5
About me:Continue reading on Medium » (https://takashi-suzuki.medium.com/writeups-facebook-whitehat-program-2021-instagram-live-setting-bug-500-usd-d2d076b3f8bb?source=rss------bug_bounty-5)
hacking: security in practice
Online hacking course
What are some suggested online hacking courses?
submitted by /u/Khaled_Mechatronics
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Online hacking course
What are some suggested online hacking courses?
submitted by /u/Khaled_Mechatronics
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Online hacking course
What are some suggested online hacking courses?
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to bypass AV in a few easy steps
Latest blog post about a recent pentest and my experience bypassing AV! Let me know in the comments if I got stuff wrong, or could have done better :)
https://arty-hlr.com/blog/2021/05/06/how-to-bypass-defender/
submitted by /u/artyHlr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to bypass AV in a few easy steps
Latest blog post about a recent pentest and my experience bypassing AV! Let me know in the comments if I got stuff wrong, or could have done better :)
https://arty-hlr.com/blog/2021/05/06/how-to-bypass-defender/
submitted by /u/artyHlr
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to bypass AV in a few easy steps
Latest blog post about a recent pentest and my experience bypassing AV! Let me know in the comments if I got stuff wrong, or could have done...
Writeups: Facebook Whitehat program(2021): Instagram Live setting bug
About me:Continue reading on Medium »
Read more...
About me:Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
100 Most Vulnerable Apps, Systems & Platforms to Practice Penetration Testing -2021
https://cdn-images-1.medium.com/max/730/1*WzXGA7drD8uGcmm1q3hoAw.png
By Shamsher khan
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
100 Most Vulnerable Apps, Systems & Platforms to Practice Penetration Testing -2021
https://cdn-images-1.medium.com/max/730/1*WzXGA7drD8uGcmm1q3hoAw.png
By Shamsher khan
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
100 Most Vulnerable Apps, Systems & Platforms to Practice Penetration Testing -2021
By Shamsher khan
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Enumerating and Exploiting SMTP
https://cdn-images-1.medium.com/max/600/1*4bn-nYhPQCrpwgTsMRlS5w.png
For a description of what SMTP is see the following:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Enumerating and Exploiting SMTP
https://cdn-images-1.medium.com/max/600/1*4bn-nYhPQCrpwgTsMRlS5w.png
For a description of what SMTP is see the following:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Enumerating and Exploiting SMTP
For a description of what SMTP is see the following:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Linux Privilege Escalation by exploiting vulnerable SUID Executables
https://cdn-images-1.medium.com/max/616/1*HB53moIUFhPMd3BEuSsgpg.png
Misconfigured SUID bit for any binary can lead to privilege escalation on Linux machine.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Linux Privilege Escalation by exploiting vulnerable SUID Executables
https://cdn-images-1.medium.com/max/616/1*HB53moIUFhPMd3BEuSsgpg.png
Misconfigured SUID bit for any binary can lead to privilege escalation on Linux machine.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Linux Privilege Escalation by exploiting vulnerable SUID Executables
Misconfigured SUID bit for any binary can lead to privilege escalation on Linux machine. Exploiting misconfigured SUID is as easy as firing…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
4 Common Password Security Mistakes That Put Your Company at Risk
https://cdn-images-1.medium.com/max/640/1*3u7B6yIPkTqGubWzFZjGNQ.jpeg
If you learned about a potential hazard in your office — let’s say a slippery floor — that threatened the well-being of your employees…
Continue reading on Sennovate »
___________________________
@hacking_Attack
@Hacking_Video
4 Common Password Security Mistakes That Put Your Company at Risk
https://cdn-images-1.medium.com/max/640/1*3u7B6yIPkTqGubWzFZjGNQ.jpeg
If you learned about a potential hazard in your office — let’s say a slippery floor — that threatened the well-being of your employees…
Continue reading on Sennovate »
___________________________
@hacking_Attack
@Hacking_Video
Medium
4 Common Password Security Mistakes That Put Your Company at Risk
If you learned about a potential hazard in your office — let’s say a slippery floor — that threatened the well-being of your employees…
Deep Web
socks5
please help.
when i activate a proxy in firefox my internet stops working until i turn it off.
i desperately need to figure this out.
submitted by /u/drug-mosphere
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
socks5
please help.
when i activate a proxy in firefox my internet stops working until i turn it off.
i desperately need to figure this out.
submitted by /u/drug-mosphere
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
socks5
please help. when i activate a proxy in firefox my internet stops working until i turn it off. i desperately need to figure this out.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Etherblob-Explorer - Search And Extract Blob Files On The Ethereum Blockchain Network
https://1.bp.blogspot.com/-BoRrRcbqFAY/YKNUqzmTjDI/AAAAAAAAWNQ/C5ZBqd30W4Y-llBY2Jhp0tWU9XRGb3dZACNcBGAsYHQ/w640-h328/etherblob-explorer_4_thumbnail.png Search and extract blob files on the Ethereum network using Etherscan.io API. IntroductionEtherBlob Explorer is a tool intended for researchers, analysts, CTF players or anyone curious enough wanting to search for different kinds of files or any meaningful human-supplied data on the Ethereum Blockchain Network. It searches over a user-supplied range of block IDs or UNIX timestamps on any of the 5 available networks: MainNet, Görli, Kovan, Rinkeby and Ropsten.
For a real-life case you can read this experiment made on 2017. The immutability of the blockchain can truly be a double-edged sword. InstallationRun the following command:
* MainNet
* Görli
* Kovan
* Rinkeby
* Ropsten Search LocationsThis tool can search on the following locations, either separately or combining any of these on the same run:
* Transaction Input Data: search inside transaction's input data (default location).
* Block Input Data: search inside block's input data.
* Contract Storage: search inside a contract's storage array on the first N 32-byte sized positions, treating it all as one big data string.
* To Addresses: search appending 'to' addresses as the possible input [*] (checking first for file headers and re-checking when all data is harvested using binwalk).
[*] Storing data on 'to' addresses is possible on the Ethereum network as there's no verification if sending to an address that has no associated account keys. Meaning you can make transactions to arbitrary addresses to craft a payload over several 20-byte sized transactions (it's very rare but so are some CTF challenges). Search and Extraction MethodsAll of these methods can be used either separately or in any combination:
* Embedded Files: search for files embedded inside data using
* File Headers / Magic Bytes: search using headers + magic bytes via levaraging the Linux util
* ASCII String Dump: search for ASCII strings inside data.
* Entropy-Based Search: use Shannon's Entropy as a measure tool to search for natural language text (e.g. UTF-8 Unicode), encrypted/compressed files or anything the user seems viable with user-supplied entropy limits.
IMPORTANT: The order showed here is used under-the-hood for discarding searches with other methods (e.g. if file is found via
* Save all data from visited transactions into file for later reviewing.
* Store CLI-displayed logs into file for later extracted-file analysis.
* Ignore user-supplied file formats (case-insensitive) for extraction and accepts substrings of the complete file format for blacklisting.
* Print general progress metrics (e.g. how many blocks / transactions have been parsed, how many blocks are left) every minute and also display some interesting metrics at the end of the current run.
* More useful features found on the manual (
___________________________
@hacking_Attack
@Hacking_Video
Etherblob-Explorer - Search And Extract Blob Files On The Ethereum Blockchain Network
https://1.bp.blogspot.com/-BoRrRcbqFAY/YKNUqzmTjDI/AAAAAAAAWNQ/C5ZBqd30W4Y-llBY2Jhp0tWU9XRGb3dZACNcBGAsYHQ/w640-h328/etherblob-explorer_4_thumbnail.png Search and extract blob files on the Ethereum network using Etherscan.io API. IntroductionEtherBlob Explorer is a tool intended for researchers, analysts, CTF players or anyone curious enough wanting to search for different kinds of files or any meaningful human-supplied data on the Ethereum Blockchain Network. It searches over a user-supplied range of block IDs or UNIX timestamps on any of the 5 available networks: MainNet, Görli, Kovan, Rinkeby and Ropsten.
For a real-life case you can read this experiment made on 2017. The immutability of the blockchain can truly be a double-edged sword. InstallationRun the following command:
$ pip install git+https://github.com/litneet64/etherblob-explorer.gitNow it's ready to use from your CLI, you can find some common usage examples below! FeaturesNetworksSearch on any of the five Ethereum Networks:* MainNet
* Görli
* Kovan
* Rinkeby
* Ropsten Search LocationsThis tool can search on the following locations, either separately or combining any of these on the same run:
* Transaction Input Data: search inside transaction's input data (default location).
* Block Input Data: search inside block's input data.
* Contract Storage: search inside a contract's storage array on the first N 32-byte sized positions, treating it all as one big data string.
* To Addresses: search appending 'to' addresses as the possible input [*] (checking first for file headers and re-checking when all data is harvested using binwalk).
[*] Storing data on 'to' addresses is possible on the Ethereum network as there's no verification if sending to an address that has no associated account keys. Meaning you can make transactions to arbitrary addresses to craft a payload over several 20-byte sized transactions (it's very rare but so are some CTF challenges). Search and Extraction MethodsAll of these methods can be used either separately or in any combination:
* Embedded Files: search for files embedded inside data using
binwalk.* File Headers / Magic Bytes: search using headers + magic bytes via levaraging the Linux util
file(default method).* ASCII String Dump: search for ASCII strings inside data.
* Entropy-Based Search: use Shannon's Entropy as a measure tool to search for natural language text (e.g. UTF-8 Unicode), encrypted/compressed files or anything the user seems viable with user-supplied entropy limits.
IMPORTANT: The order showed here is used under-the-hood for discarding searches with other methods (e.g. if file is found via
embedded filesthen it won't attempt to search using file headers, ascii string dumpnor entropy) as it's not likely to find anything meaningful if previous methods were already successful. Misc* Accepts UNIX timestamps (instead of block IDs) that get resolved into the closest block IDs commited at those times.* Save all data from visited transactions into file for later reviewing.
* Store CLI-displayed logs into file for later extracted-file analysis.
* Ignore user-supplied file formats (case-insensitive) for extraction and accepts substrings of the complete file format for blacklisting.
* Print general progress metrics (e.g. how many blocks / transactions have been parsed, how many blocks are left) every minute and also display some interesting metrics at the end of the current run.
* More useful features found on the manual (
-h)! UsageCommon use cases* Standard search (search inside transactions via file headers) on MainNe[...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Etherblob-Explorer - Search And Extract Blob Files On The Ethereum Blockchain Network