Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SkyTower Walkthrough

https://cdn-images-1.medium.com/max/1347/0*oy123PiSNtDcdJ4D
An interesting boot to root machine, especially designed for building hackers’ mindset rather than learning the usage of automated tools.

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
isc2.org MFA Bypass Report

Hello All,

I discovered a MFA bypass on (ISC)2's (org behind the CISSP certification) website a few months ago and wanted to share here.

I reported the issue to (ISC)2, and they did fix it, but the issue existed for several months. The issue was caused by a misconfiguration when they changed SSO providers from Okta to Salesforce Identity.

The issue was that you could register SMS as a MFA method in the login flow, bypassing all other registered MFA methods.

If you had the person's password, and they hadn't already registered SMS, then you could bypass the registered MFA method (ie authenticator app code) by entering ANY phone number and registering that phone number as an additional MFA method.

Read my full report here: isc2.org Website MFA Bypass Vulnerability - Blog - GRC Academy

Here is the link to the demonstration video: https://www.youtube.com/watch?v=CPB2GFgQ0j4

After I published my report, I did get some coverage from Brian Krebs and Infosecurity Magazine!

I asked (ISC)2 if they would provide recognition for me, CPEs, or anything else, and they said NO...

The process from submission to trying to get media coverage was quite interesting! I'm happy to answer questions!

Have a great rest of the week!

Jacob Hill | https://www.linkedin.com/in/jacobrhill/

submitted by /u/Unified-Rogue-Agent
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
breached.vc alternatives?

with breached.vc being down where can i find leaked passwords to practize analyzing for patterns (to make bruteforce dehashing faster )

submitted by /u/someone13121425
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to get a job in cybersecurity

Hi I’m currently studying electronics and computer engineering. Now I haven’t learnt anything about cybersecurity, but I would love to have a job in this field. Are there any of you that were in the same situation but eventually landed with a cybersecurity job? What’s the best for me to do after graduating college? Thanks in advance for the replies!

submitted by /u/jeoffreycanters
[link] [comments]
CARA SAYA MENEMUKAN KERENTANAN IDOR ATAU PARAMETER TAMPERING PADA WEBSITE ECOMMERCE

Hello perkenalkan saya subhan, ini merupakan tulisan pertama saya dan kali ini saya mau berbagi cerita tentang temuan saya yaitu temuan…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Raspberry Pie

Im thinking of getting a raspberry pie and download Whonix and tails on it as a dedicated deep web browser. Any tips or warnings I should take into consideration? I’m pretty new into all of this

submitted by /u/toenailgoobler
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Gmailc2 : A Fully Undetectable C2 Server That Communicates Via Google SMTP To Evade Antivirus Protections And Network Traffic Restrictions

Gmailc2 is a Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions.

Note:

This RAT communicates Via Gmail SMTP (or u can use any other smtps as well) but Gmail SMTP is valid
because most of the companies block unknown traffic so gmail traffic is valid and allowed everywhere.

Warning:
1. Don't Upload Any Payloads To VirusTotal.com Bcz This tool will not work
with Time.
2. Virustotal Share Signatures With AV Comapnies.
3. Again Don't be an Idiot!



How To Setup
1. Create Two seperate Gmail Accounts.
2. Now enable SMTP On Both Accounts (check youtube if u don't know)
3. Suppose you have already created Two Seperate Gmail Accounts With SMTP enabled
A -> first account represents Your_1st_gmail@gmail.com
B -> 2nd account represents your_2nd_gmail@gmail.com
4. Now Go To server.py file and fill the following at line 67:
smtpserver="smtp.gmail.com" (don't change this)
smtpuser="Your_1st_gmail@gmail.com"
smtpkey="your_1st_gmail_app_password"
imapserver="imap.gmail.com" (don't change this)
imapboy="your_2nd_gmail@gmail.com"
5. Now Go To client.py file and fill the following at line 16:
imapserver = "imap.gmail.com" (dont change this)
username = "your_2nd_gmail@gmail.com"
password = "your2ndgmailapp password"
getting = "Your_1st_gmail@gmail.com"
smtpserver = "smtp.gmail.com" (don't change this)
6. Enjoy



How To Run:
For Windows:
1. Make Sure python3 and pip is installed and requriements also installed
2. python server.py (on server side)


For Linux:
1. Make Sure All Requriements is installed.
2. python3 server.py (on server side)



C2 Feature:
1) Persistence (type persist)
2) Shell Access
3) System Info (type info)
4) More Features Will Be Added



Features:
1) FUD Ratio 0/40
2) Bypass Any EDR's Solutions
3) Bypass Any Network Restrictions
4) Commands Are Being Sent in Base64 And Decoded on server side
5) No More Tcp Shits



Warning:

Use this tool Only for Educational Purpose And I will Not be Responsible For your cruel act.
Click Here To Download