Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme -SteelMountain (CTF)

https://cdn-images-1.medium.com/max/700/1*aLgfxELwVK0ZEkMWx_ewqQ.png
Hack into a Mr. Robot themed Windows machine. Use metasploit for initial access, utilize powershell for Windows privilege escalation …

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme — HackPark(CTF)

https://cdn-images-1.medium.com/max/600/1*YKmdMGvMxyT9RxweVSyy3g.png
Bruteforce a websites login with Hydra, identify and use a public exploit then escalate your privileges on this Windows machine!

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SkyTower Walkthrough

https://cdn-images-1.medium.com/max/1347/0*oy123PiSNtDcdJ4D
An interesting boot to root machine, especially designed for building hackers’ mindset rather than learning the usage of automated tools.

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
isc2.org MFA Bypass Report

Hello All,

I discovered a MFA bypass on (ISC)2's (org behind the CISSP certification) website a few months ago and wanted to share here.

I reported the issue to (ISC)2, and they did fix it, but the issue existed for several months. The issue was caused by a misconfiguration when they changed SSO providers from Okta to Salesforce Identity.

The issue was that you could register SMS as a MFA method in the login flow, bypassing all other registered MFA methods.

If you had the person's password, and they hadn't already registered SMS, then you could bypass the registered MFA method (ie authenticator app code) by entering ANY phone number and registering that phone number as an additional MFA method.

Read my full report here: isc2.org Website MFA Bypass Vulnerability - Blog - GRC Academy

Here is the link to the demonstration video: https://www.youtube.com/watch?v=CPB2GFgQ0j4

After I published my report, I did get some coverage from Brian Krebs and Infosecurity Magazine!

I asked (ISC)2 if they would provide recognition for me, CPEs, or anything else, and they said NO...

The process from submission to trying to get media coverage was quite interesting! I'm happy to answer questions!

Have a great rest of the week!

Jacob Hill | https://www.linkedin.com/in/jacobrhill/

submitted by /u/Unified-Rogue-Agent
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
breached.vc alternatives?

with breached.vc being down where can i find leaked passwords to practize analyzing for patterns (to make bruteforce dehashing faster )

submitted by /u/someone13121425
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to get a job in cybersecurity

Hi I’m currently studying electronics and computer engineering. Now I haven’t learnt anything about cybersecurity, but I would love to have a job in this field. Are there any of you that were in the same situation but eventually landed with a cybersecurity job? What’s the best for me to do after graduating college? Thanks in advance for the replies!

submitted by /u/jeoffreycanters
[link] [comments]
CARA SAYA MENEMUKAN KERENTANAN IDOR ATAU PARAMETER TAMPERING PADA WEBSITE ECOMMERCE

Hello perkenalkan saya subhan, ini merupakan tulisan pertama saya dan kali ini saya mau berbagi cerita tentang temuan saya yaitu temuan…Continue reading on Medium »
Read more...