Hacking Articles Tips Tricks Videos Tutorials
469 subscribers
66.5K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
The Time I Found My Bug: A Beginner’s Story

As a beginner in the field of web security, I had always heard about people finding bugs in websites and being rewarded for it. I was…Continue reading on Medium »
Read more...
hacking: security in practice
Clarification on bug bounties

Do sites like bug crowd or Hackerone only take 0 days?

I've been getting back into cyber sec for the last few years and have found several known CVEs in the wild (no 0days). I have approached all the people affected by these directly and they either all ignore me or tell me they dont care. In every case this has happened.
Once I even found full read write access in a database that contained medical information , dox and surgery pictures online.
This medical DB was in another country from my own.
The people who owned the box, the people who owned the medical clinic, the forigen governments intel and cyber sec agency all gave me 100% radio silence .
I eventually contacted CERT of the US, they apparently dealt with the issue and I got nothing out of it .

Some general guidance on what I should do when I find non 0 day CVE would be appreciated.

submitted by /u/zeekertron
[link] [comments]
Dark Reading: Attacks/Breaches
Spera Takes Aim at Identity Security Posture Management

ISPM is a combination of identity attack surface management, and risk reduction, as well as identity threat prevention, detection, and response.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Spelling “Banana” with JavaScript

https://cdn-images-1.medium.com/max/2600/0*UBx3Nf7uBfAICcqk
You could read this title of this article and have the answer, or we can dive into the sneaky way to spell out “banana” in the JavaScript…

Continue reading on JavaScript in Plain English »
Role of AI in Cybersecurity

As technology continues to advance, so too do the methods by which cybercriminals seek to exploit vulnerabilities in our digital…Continue reading on Medium »
Read more...
hacking: security in practice
Mediatek mt7921e capabilities

I have mt7921e (reported by inxi -n) that came with a Lenovo laptop. Does this card support packet injection? I tested hcxdumptool --check_injection and it showed packet injection working on 2.4ghz with average ratio. But after i tested aireplay --test, it showed no answer. 0 APs.

Then again i tested hcxdumptool --check_injection, this time hcxdumptool reports no PROBERESPONSE, packet injection is not working. Surrounding APs are exactly same as before, none was turned off. Is the card not supporting capabilities for wireless attack? Or is it the drivers?

submitted by /u/Roshin1401
[link] [comments]
hacking: security in practice
Exploits for usb boot on chromeOS 111 without disk being wiped?

So I know a lot of the SH1MMER exploit but.. my school would know if I unenrolled chromebook and I would also need to obtain the wifi something that the password isnt openly provided. So theoratically is there a way to usb boot without wiping the whole disk on my school Chromebook (we cant bring our personal device). Im mainly going to be booting BSD and Kali for some pentesting of the school filtering and servers but I cant find an exploit for this and well I'm just an amateur security researcher.

submitted by /u/cruzzeky
[link] [comments]
hacking: security in practice
Web based login open wifi

So some isp's have they're customers have some what open WiFi at residents, its sand boxed from the residential WiFi and it uses a web based log in where I'd need to pay the ISP an hourly rate, I'm just wondering if anyone has found a way to get passed all the credentials? I'm assuming if possible then the ISP would most likely have an automated system for banning unwanted ip's

If anyone has good resources I could read on this like a jumping off point that would be great

submitted by /u/squid-slime
[link] [comments]
Deep Web
What about services on the dark net

Hello,

I'm new to the deep/dark web. I'm going to buy a service from someone on the dark web, and he mentioned we use Electrum and do Escrow so no one gets scammed. This sounds good but is there anything I should be attentive to?

submitted by /u/No-Incident3025
[link] [comments]
Found SSRF and LFI in Just 10 minutes of using burp!

Hello, and welcome again after about two years from the last published write-up.Continue reading on Medium »
Read more...
Bugproof your Firmware with BugProve

I guess the graphic above depicts the essence of BugProve, a recently launched European IOT Security company.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top cybersecurity tools every business should use:-

https://cdn-images-1.medium.com/max/626/0*Yj0YPBrAxwxAd6HO
Businesses of all kinds are very concerned about cyber security. Businesses must implement a strong cybersecurity strategy in light of the…

Continue reading on Medium »