Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Subdomain takeover via dns wildcard?
I get how ordinary subdomain takeovers work, when an attacker registers an expired/forgotten Subdomain or something, but I’m confused about the method described by the hacktricks link I posted below. If a wildcard CNAME record points to a legitimate domain, then shouldn’t an attacker created subdomain just load the legitimate domain?
“For example, if *.testing.com is wilcarded to 1.1.1.1. Then, not-existent.testing.com will be pointing to 1.1.1.1.
However, if instead of pointing to an IP address, the sysadmin point it to a third party service via CNAME, like a github subdomain for example (sohomdatta1.github.io). An attacker could create his own third party page (in Gihub in this case) and say that something.testing.com is pointing there. Because, the CNAME wildcard will agree the attacker will be able to generate arbitrary subdomains for the domain of the victim pointing to his pages.”
Does this make sense to anyone? I’ve spent all day researching this, and I’m still pretty lost. Thanks for your time!
https://book.hacktricks.xyz/pentesting-web/domain-subdomain-takeover#subdomain-takeover-generation-via-dns-wildcard
submitted by /u/Agent-BTZ
[link] [comments]
Subdomain takeover via dns wildcard?
I get how ordinary subdomain takeovers work, when an attacker registers an expired/forgotten Subdomain or something, but I’m confused about the method described by the hacktricks link I posted below. If a wildcard CNAME record points to a legitimate domain, then shouldn’t an attacker created subdomain just load the legitimate domain?
“For example, if *.testing.com is wilcarded to 1.1.1.1. Then, not-existent.testing.com will be pointing to 1.1.1.1.
However, if instead of pointing to an IP address, the sysadmin point it to a third party service via CNAME, like a github subdomain for example (sohomdatta1.github.io). An attacker could create his own third party page (in Gihub in this case) and say that something.testing.com is pointing there. Because, the CNAME wildcard will agree the attacker will be able to generate arbitrary subdomains for the domain of the victim pointing to his pages.”
Does this make sense to anyone? I’ve spent all day researching this, and I’m still pretty lost. Thanks for your time!
https://book.hacktricks.xyz/pentesting-web/domain-subdomain-takeover#subdomain-takeover-generation-via-dns-wildcard
submitted by /u/Agent-BTZ
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Best job to go for while getting Cybersecurity degree?
I am a father of 2 and married, currently working in the mechanics field, but because of my education I would like to start working on a job while I get my bachelors. Do you all have any suggestions for what type of jobs I could look for?
submitted by /u/Gottster1129
[link] [comments]
Best job to go for while getting Cybersecurity degree?
I am a father of 2 and married, currently working in the mechanics field, but because of my education I would like to start working on a job while I get my bachelors. Do you all have any suggestions for what type of jobs I could look for?
submitted by /u/Gottster1129
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Explain it to someone who doesn't understand cybersecurity
Let's say that Joe has it's credentials stolen, maybe with a phishing campaign.
Joe has a work computer and he connects via VPN to work. He has access to the software he needs to do his job only, he's not an admin.
How do you hackers use his credentials to exploit the company's network?
Remember you're explaining it to someone without experience or security background.
TIA
submitted by /u/Original-Prompt4285
[link] [comments]
Explain it to someone who doesn't understand cybersecurity
Let's say that Joe has it's credentials stolen, maybe with a phishing campaign.
Joe has a work computer and he connects via VPN to work. He has access to the software he needs to do his job only, he's not an admin.
How do you hackers use his credentials to exploit the company's network?
Remember you're explaining it to someone without experience or security background.
TIA
submitted by /u/Original-Prompt4285
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Discussion: Are we entering the golden age of hacking, where software written by language models that "looks correct" to the lazy human operator is used despite being full of vulnerabilities?
Assisted by large language model code generators, people will "write" software they don't understand, and deploy it.
If so, can you provide examples in the wild?
If not, why not?
submitted by /u/BUGFIX-66
[link] [comments]
Discussion: Are we entering the golden age of hacking, where software written by language models that "looks correct" to the lazy human operator is used despite being full of vulnerabilities?
Assisted by large language model code generators, people will "write" software they don't understand, and deploy it.
If so, can you provide examples in the wild?
If not, why not?
submitted by /u/BUGFIX-66
[link] [comments]
Top 10 cybersecurity tools for bug bounty hunters :
Bug bounty hunters use various cybersecurity tools to find vulnerabilities and bugs in software systems. Here are the top 10 cybersecurity…Continue reading on Medium »
Read more...
Bug bounty hunters use various cybersecurity tools to find vulnerabilities and bugs in software systems. Here are the top 10 cybersecurity…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme -SteelMountain (CTF)
https://cdn-images-1.medium.com/max/700/1*aLgfxELwVK0ZEkMWx_ewqQ.png
Hack into a Mr. Robot themed Windows machine. Use metasploit for initial access, utilize powershell for Windows privilege escalation …
Continue reading on Medium »
Tryhackme -SteelMountain (CTF)
https://cdn-images-1.medium.com/max/700/1*aLgfxELwVK0ZEkMWx_ewqQ.png
Hack into a Mr. Robot themed Windows machine. Use metasploit for initial access, utilize powershell for Windows privilege escalation …
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme — HackPark(CTF)
https://cdn-images-1.medium.com/max/600/1*YKmdMGvMxyT9RxweVSyy3g.png
Bruteforce a websites login with Hydra, identify and use a public exploit then escalate your privileges on this Windows machine!
Continue reading on Medium »
Tryhackme — HackPark(CTF)
https://cdn-images-1.medium.com/max/600/1*YKmdMGvMxyT9RxweVSyy3g.png
Bruteforce a websites login with Hydra, identify and use a public exploit then escalate your privileges on this Windows machine!
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Defend the Web Writeup — Intro 11 : Inspect the Source Code
https://cdn-images-1.medium.com/max/1640/1*I2Xv5gsLrASe2owQZws-XQ.png
In this writeup, I will share my experience of solving a JavaScript CTF challenge by analyzing the source code. By carefully examining the…
Continue reading on Medium »
Defend the Web Writeup — Intro 11 : Inspect the Source Code
https://cdn-images-1.medium.com/max/1640/1*I2Xv5gsLrASe2owQZws-XQ.png
In this writeup, I will share my experience of solving a JavaScript CTF challenge by analyzing the source code. By carefully examining the…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme GoldenEye Ctf ( walkthrough)
https://cdn-images-1.medium.com/max/700/1*HQA8oV6AyNMZUYbCGIhxGQ.png
This Ctf Involves Brute-Forcing , Enumiration ,Privillage escalation & Exploiting services .
Continue reading on Medium »
Tryhackme GoldenEye Ctf ( walkthrough)
https://cdn-images-1.medium.com/max/700/1*HQA8oV6AyNMZUYbCGIhxGQ.png
This Ctf Involves Brute-Forcing , Enumiration ,Privillage escalation & Exploiting services .
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SkyTower Walkthrough
https://cdn-images-1.medium.com/max/1347/0*oy123PiSNtDcdJ4D
An interesting boot to root machine, especially designed for building hackers’ mindset rather than learning the usage of automated tools.
Continue reading on Medium »
SkyTower Walkthrough
https://cdn-images-1.medium.com/max/1347/0*oy123PiSNtDcdJ4D
An interesting boot to root machine, especially designed for building hackers’ mindset rather than learning the usage of automated tools.
Continue reading on Medium »
Hacking on Medium
THM Netsec-Challenge (write up)
https://cdn-images-1.medium.com/max/706/1*3OCXo8a071XAv633ry9PIw.png
Today we are Doing the Nmap Netsec Challenge
Continue reading on Medium »
THM Netsec-Challenge (write up)
https://cdn-images-1.medium.com/max/706/1*3OCXo8a071XAv633ry9PIw.png
Today we are Doing the Nmap Netsec Challenge
Continue reading on Medium »
Medium
THM Netsec-Challenge (write up)
Today we are Doing the Nmap Netsec Challenge