Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
https://preview.redd.it/ql6zguotcysa1.jpg?width=640&crop=smart&auto=webp&s=4cb5badbfcc5f81e044eaf847c8d15715ed54fae It seems very off... not sure what to take of it, hence decided to make a post out of it. Can someone share/ guide as to what this could be.. If its an otp generator, it should not be sending texts like this

submitted by /u/RepresentativeBug550
[link] [comments]
hacking: security in practice
Pixiewps sometimes gets the password and sometimes doesn't

To learn more about pixiedust, I enabled WPS on my Tenda WiFi router(static pin) and started exploring. I found this GitHub project called oneshot that uses wpa_supplicantto get the necessary handshake data and then cracks the pin with good old pixiewps.

What is weird is that the attack doesn't always succeed although all the necessary handshake data is always provided to pixiedust.

I even gathered the data myself and ran it manually. Roughly 10/100 tries succeed, Given my every 3 attempts are 30 minutes apart (Doing it back to back just keeps failing and triggers router rate limit). The problem seems to be somewhere in how the router is generating the hashes at a certain time or a bug in pixiewps. However I'm not sure what is actually causing this. What could it be?

submitted by /u/invoked_vilgax
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Villain C2 : Reverse Shell Obfuscation.

https://cdn-images-1.medium.com/max/1920/1*Asebk0GkycLv4IKANS7A6A.png
Explore Alternative Payload Obfuscation Methods in Villain C2 for Reverse Shell Access. Using UUID to Obfuscate Payload for Improved…

Continue reading on Medium »
Hello reader’s, this blog is not the technical vulnerability poc that you are actually looking for, but its about the 5 key ingredients…Continue reading on Medium » (https://medium.com/@mehtashobhit98/from-hall-of-failures-to-hall-of-fame-s-4462ca5bfa17?source=rss------bug_bounty-5)
Path Normalization Crash Course 101

path normalization crash courseContinue reading on Medium »
Read more...
hacking: security in practice
Catching Threat Actors using honeypots!

Hey guys, it's me again!

Today I want to tease my new research project. In this research project, I will analyse the data of 20+ honeypots running for 30 days.

However, since the honeypots generated hundreds of GB of data, I will have to split it into multiple parts.

In the first part, I mostly talk about the architecture and installation of the honeypots.

Feel free to ask questions and critique the post.

Cheers!

https://burningmalware.com/Catching-Threat-Actors-using-honeypots!-(Part1)//)

submitted by /u/TachiPy
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Google chrome passwords (Login data file) PROTECTION

Hi,

my question is - can i somehow protect the chrome password manager file located in my Appdata/Local folder?

I know that a free basic stealer from github can steal them even if google said its "encrypted" and read them easily so - is there a way to protect that file?



Thanks!

submitted by /u/mlodyfluder
[link] [comments]