Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.6K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Phishing Scams

Phishing is a type of online scam in which attackers create a fake website or email that looks like it is from a legitimate source in…

Continue reading on Medium »
hacking: security in practice
List of common vulnerabilities?

I've been getting a bit further into some hacking, and I've found learning about the different common vulnerabilities like XSS, SQLi, SSTI, buffer overflows, command injection, etc. and what makes them work super fun, are there any good resources you reccomend as a decently thorough "field guide" for what they are, how they can be exploited, what you can do with them, how you can identify them, etc?

submitted by /u/TheMightyFlyingSloth
[link] [comments]
Bug Bounty Hakkında Bilmeniz Gerekenler!

Merhaba arkadaşlar derlemiş olduğum bu makale de sizlere soru cevap olarak gerekli tüm bilgileri vereceğim.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
USB ile Veri Çalma

https://cdn-images-1.medium.com/max/639/0*p_EUpJ9BAOFx4e1Z.png
Merhaba arkadaşlar elimden geldiğince sizlere yardımcı olacağına inandığım bir konu ile karşınızdayım.

Continue reading on Medium »
The Time I Found My Bug: A Beginner’s Story

As a beginner in the field of web security, I had always heard about people finding bugs in websites and being rewarded for it. I was…Continue reading on Medium »
Read more...
hacking: security in practice
Clarification on bug bounties

Do sites like bug crowd or Hackerone only take 0 days?

I've been getting back into cyber sec for the last few years and have found several known CVEs in the wild (no 0days). I have approached all the people affected by these directly and they either all ignore me or tell me they dont care. In every case this has happened.
Once I even found full read write access in a database that contained medical information , dox and surgery pictures online.
This medical DB was in another country from my own.
The people who owned the box, the people who owned the medical clinic, the forigen governments intel and cyber sec agency all gave me 100% radio silence .
I eventually contacted CERT of the US, they apparently dealt with the issue and I got nothing out of it .

Some general guidance on what I should do when I find non 0 day CVE would be appreciated.

submitted by /u/zeekertron
[link] [comments]
Dark Reading: Attacks/Breaches
Spera Takes Aim at Identity Security Posture Management

ISPM is a combination of identity attack surface management, and risk reduction, as well as identity threat prevention, detection, and response.