Get Mystery Box with random crypto!

Hack3rScr0lls

Logo of telegram channel hackerscrolls — Hack3rScr0lls H
Logo of telegram channel hackerscrolls — Hack3rScr0lls
Channel address: @hackerscrolls
Categories: Technologies
Language: English
Country: Not set
Subscribers: 1.81K
Description from channel

for hackers by hackers
twitter.com/hackerscrolls

Ratings & Reviews

1.00

2 reviews

Reviews can be left only by registered users. All reviews are moderated by admins.

5 stars

0

4 stars

0

3 stars

0

2 stars

0

1 stars

2


The latest Messages 3

2020-10-17 14:23:12 How to find the way?

Using other hosts as a gateway, sometimes, you can get access to other VLANs, bypass firewalls, and find unauthorized routes to the Internet.

That is a task for gateway-finder!

It finds hosts with enabled IP forwarding by sending ICMP/TCP packets using other hosts in the network as a gateway.

Check gateway-finder-imp by @whitel1st.

It improves the original tool with:
> List of IP addresses for scanning
> Support for custom TCP ports
> Nice color output

github.com/whitel1st/gateway-finder-imp

#Pentest #Network #VLAN
1.3K viewsedited  11:23
Open / Comment
2020-10-17 14:22:47
1.0K views11:22
Open / Comment
2020-10-11 17:02:09 SameSite is already here

Were you surprised when your cross-domain attack didn't work? Meet the new reality with SameSite Cookies.

From August Chrome update:
Cookies that do not specify a SameSite attribute will be treated as if they specified SameSite=Lax.

Now Chrome and Safari recognize Cookies without the SameSite attribute as SameSite=Lax by default.

Remind you about SameSite attribute values:

Samesite=Lax
Allows the cookie to be sent on some cross-site requests.
[top-level navigation+GET/HEAD)

Samesite=Strict
Never allows the cookie to be sent on a cross-site request. Only when the user types the website in the URL bar and presses enter.

Samesite=None
Cookies will be sent in all contexts (like before)

You will not be able to exploit the following vulnerabilities in Chrome and Safari without SameSite=None:
> CSRF
> CORS misconfiguration
> XSLeaks
> XSS via POST
> Cross-Site Script Inclusion
> Clickjacking
> JSONP leaks
> WebSocket Hijacking

#Web #Cookies #SameSite
1.3K views14:02
Open / Comment
2020-10-11 17:01:51
969 views14:01
Open / Comment