| Date | Title | Description |
| 02.06.2026 | Nmap — Сетевой сканер портов и служб | Разведка — первый этап любого пентеста. Цель: собрать максимум данных о цели до начала активных действий.nmapЧто делает
Сканирует сети и хосты: определяет открытые порты, запущенные сервисы, версии ПО и операционную систему. Работает через ... |
| 23.02.2026 | HackTheBox. Прохождение Falafel. Уровень — Сложный | Для начала добавим ip-адрес в файлик hosts.
sudo nano /etc/hosts
Проведем начальное сканирование masscan-ом, будем сканировать все TCP и UDP порты со скоростью 500 пакетов в секунду, через интерфейс tun0 и посмотрим результат.
sudo masscan ... |
| 03.02.2026 | AutoPentestX хакер в Шкатулке | Представьте: тёмная серверная комната, мигающие огни роутеров, и вы — одинокий страж в цифровой крепости. Нужно проверить оборону, но вручную ковыряться в Nmap, Nikto и SQLMap? Забудьте о хаосе. Запустите одну команду — и через полчаса на с... |
| 29.05.2025 | Ethical Hacking Services: Strengthening Cybersecurity in a Digital World | Share
Share
Share
Share
Email
Ethical hacking, also known as white-hat hacking, is the practice of identifying and exploiting vulnerabilities in computer systems or networks with the explicit permission of the owner to improve security. Eth... |
| 12.02.2025 | Рабочий кейс из жизни специалиста по управлению уязвимостями «Vulnerability management» | Проведение сканирования нашей цели
Для сканирования актива (тестовая машина), нам необходимо создать группу, в которой будут находится только тачки(а) для тестирования. Простым действием мыши создаем группу, которая включает в себя активы, ... |
| 31.01.2025 | Особенности написания эксплоитов под х64 | Современные механизмы защиты от уязвимостей переполнения буфера существенно усложняют реализацию таких атак, однако buffer overflow по‑прежнему остается одним из самых распространенных видов уязвимостей. В этой статье мы поговорим об особен... |
| 29.01.2025 | Google report finds state-based hackers are using AI for research and content generation
Your vote of support is important to us and it helps us keep the content FREE.
One click below supports our mis... | A new report released today by Google LLC’s Threat Intelligence Group details how advanced persistence threat groups and coordinated information operations actors from countries such as China, Iran, Russia and North Korea are using generati... |
| 24.12.2024 | The Rising Tide of Cyber Threats: Navigating the New Landscape | In the digital age, cyber threats are like shadows lurking in the corners of our online lives. They evolve, adapt, and strike when least expected. Recent reports highlight a surge in sophisticated attacks, driven by advanced technologies li... |
| 23.12.2024 | ТОП-5 ИБ-событий недели по версии Jet CSIRT | Сегодня в ТОП-5 — стиллер CoinLurker, создающий новое поколение вредоносных обновлений, уязвимость OpenAI Calendar Notification ByPass, атака Link Trap с быстрым внедрением GenAI, атака цепочки поставок на пакеты Rspack npm, а также методы ... |
| 11.12.2024 | Популяризация технологии eBPF и другие тренды в трояностроении | Исследование очередного киберинцидента позволило вирусным аналитикам «Доктор Веб» выявить идущую хакерскую кампанию, в ходе которой проявились многие современные тенденции, применяемые злоумышленниками.
В компанию «Доктор Веб» обратился кли... |
| 05.12.2024 | Разбор полетов: Взлом Metasploitble3 | Metasploitable3 — умышленно уязвимая машина для проведения тестирования на взлом
Metasploitable3 является бесплатной виртуальной машиной, которая позволяет симулировать атаки в значительной степени используя Metasploit. Она применялась людь... |
| 26.10.2024 | Navigating the Digital Frontier: The Rise of Ethical Hacking and App Marketing | In the ever-evolving landscape of technology, two fields stand out: ethical hacking and app marketing. Both are essential in today’s digital world, where security and visibility are paramount. As cyber threats grow more sophisticated, the n... |
| 25.10.2024 | Enter the World of Ethical Hacking with Confidence | TL;DR: Get lifetime access to The 2024 All-in-One Ethical Hacking Course Bundle for just $44.99 and start mastering ethical hacking techniques to protect and secure networks.
The 2024 All-in-One Ethical Hacking Course Bundle is a must-have ... |
| 22.10.2024 | Крадем учетные данные Windows | В этой статье мы разберем различные сценарии получения паролей в системе Windows.
Metasploit
Metasploit поставляется со встроенным модулем, который помогает нам провести атаку на получение учетных данных пользователя в открытом виде. Поскол... |
| 15.10.2024 | Lateral movement: перемещение в атакуемой сети | С точки зрения теории хакинга, взлом инфраструктуры состоит из нескольких шагов. Так, в начале атакующему необходимо провести разведку, выяснить, какие DNS записи, пулы IP адресов и прочее принадлежит атакуемой организации. Также неплохо бы... |
| 12.10.2024 | Взлом паролей методом брутфорса, уязвимой машины в Kali GNU/Linux с hydra, medusa, ncrack — просто | Всех приветствую читатели Хабра!
Сегодня я поведую о том как установить, настроить, и эксплуатировать уязвимости заранее уязвимой машины Metasploitable2-Linux. В данной статье я скорее даже поделюсь своим опытом взлома уязвимого хоста в вир... |
| 03.10.2024 | Daily Deal: The 2024 All-in-One Ethical Hacking Bundle | The 2024 All-in-One Ethical Hacking Bundle has 18 courses to help you learn more about penetration testing, social engineering, network security and ethical hacking. Courses cover Metasploit, Nmap, Wireshark, Burp Suite, Splunk, and more. I... |
| 02.10.2024 | Elastic report: Azure outpaces AWS in 2024 cyber threats analysis | Elastic Security Labs has released its latest Global Threat Report, providing an in-depth examination of the rapidly changing threat landscape.
The report focuses on key vulnerabilities within cloud systems, malware detection across major o... |
| 28.08.2024 | Из лета в зиму: как хакеры сменили сезон для виртуального склада на Standoff | Привет! На связи организаторы кибербитвы Standoff, и в этой статье мы с командой 5HM3L поделимся с вами свежим кейсом. Что за Standoff такой?
Standoff — Международные киберучения, в рамках которых воссоздаются IT-инфраструктуры виртуальных ... |
| 21.08.2024 | Unleashing the Power of Kali Linux: A Gateway to Cybersecurity Mastery | In the digital age, cybersecurity is the fortress that protects our virtual lives. Among the tools that stand guard is Kali Linux, a powerful ally for penetration testers. The latest edition of "The Ultimate Kali Linux Book" offer... |
| 20.08.2024 | Save $43.99! Get 'The Ultimate Kali Linux Book, Third Edition' for FREE | Embark on an exciting journey into the world of Kali Linux -- the central hub for advanced penetration testing, and harness Nmap, Metasploit, Aircrack-ng, and Empire.
Honing your pentesting skills and exploiting vulnerabilities or conductin... |
| 17.08.2024 | Удобные шпаргалки по Msfvenom | В этой статье мы продолжим интересную и полезную тему шпаргалок по различным инструментам для пентеста. Ранее мы уже рассмотрели тему различных полезностей для пентестера, которые могут пригодиться при проведении тестирования на проникновен... |
| 01.08.2024 | Уязвимости Laravel, технология Cookieless и Kerberos-лапша, или Рассказ о том, как мы IDS Bypass 5 решали | Вот и прошли два месяца с окончания Positive Hack Days Fest 2. Несмотря на то что он уже второй год как городской киберфестиваль, все привычные активности остались. Один из конкурсов — IDS Bypass — мы провели в юбилейный, пятый раз. Подводи... |
| 04.07.2024 | Угрозы инфраструктуры с Linux. Разбираем попытки атак | Небо голубое, вода мокрая, а Linux — самая защищенная операционная система. С этим не поспоришь.
В систему встроено много функций, которые работают на ее безопасность. Ограничение прав доступа — в их числе. К тому же на страже Linux стоит к... |
| 01.06.2024 | Обзор курса Certified Penetration Testing Specialist (CPTS) от HTB Academy | Приветствую, в этой статье я расскажу о курсе и итоговом экзамене HTB CPTS. Надеюсь, что это даст понимание всем, кто собирается проходить курс и сдавать экзамен в будущем.
В предыдущей статье я рассказывал о курсе HTB CBBH "Обзор курс... |
| 31.05.2024 | Как использовать EDR-систему для расследования и реагирования на инциденты безопасности: кейс Armitage для Metasploit | Привет! Меня зовут Валерий Слезкинцев. В Positive Technologies я руковожу направлением реагирования на конечных точках в отделе обнаружения вредоносного ПО в PT Expert Security Center (PT ESC). Наша команда мониторит свежие атаки и воспроиз... |
| 29.05.2024 | Дешифрование паролей для доступа к потерянным Биткоин Кошелькам с помощью метода Gauss-Jacobi | В этой статье мы рассмотрим на примере метод Gauss-Jacobi которые применяют современные технологии, такие как предварительно обученная модель Bitcoin ChatGPT, что позволяют более эффективно решать сложные задачи в области цифровых технологи... |
| 14.05.2024 | Могут ли LLM-агенты взламывать сайты и эксплуатировать уязвимости? | Рассказываем про исследование в рамках которого тестировалась способность LLM-агентов взламывать сайты.
Большие языковые модели (LLM) становятся все более мощными и находят широкое применение в виде агентов. Разработчики могут создавать аге... |
| 08.05.2024 | Трендовые уязвимости апреля: до пяти лет скрытой эксплуатации | Хабр, привет! Я Александр Леонов, ведущий эксперт лаборатории PT Expert Security Center. Мы с командой аналитиков Positive Technologies каждый месяц анализируем информацию об уязвимостях из баз и бюллетеней безопасности вендоров, социальных... |
| 26.04.2024 | OpenAI’s GPT-4 Can Autonomously Exploit 87% of One-Day Vulnerabilities, Study Finds | The GPT-4 large language model from OpenAI can exploit real-world vulnerabilities without human intervention, a new study by University of Illinois Urbana-Champaign researchers has found. Other open-source models, including GPT-3.5 and vuln... |
| 12.04.2024 | Безопасная разработка: обзор основных инструментов | Привет! Меня зовут Иван, я инженер по кибербезопасности в достаточно крупной компании и автор курса «Специалист по информационной безопасности: веб-пентест». В этой сфере я уже около шести лет.
Сейчас занимаюсь тестированием безопасности пр... |
| 09.04.2024 | Удалить нельзя эксплуатировать: как мы нашли уязвимость в установщике Битрикс | Источник: https://www.reddit.com/r/LofiGirl/comments/ipf71o/lo_fi_romanian_programmer_i_created_for_rromania/
Методология тестирования на проникновение предполагает разделение поиска уязвимостей на несколько этапов. Один из первых этапов за... |
| 11.03.2024 | Инфраструктурный пентест по шагам: сканирование и получение доступа
Введение в Active Directory
Сканирование на практике... | Продолжение цикла статей, в котором мы раскрываем подходы к аудиту внутренней инфраструктуры. В предыдущей части подробно рассказывали про инструменты и методологии, которые используем в повседневной практике, а также про первый этап пентес... |
| 04.12.2023 | Padding Oracle Attack на Wallet.dat расшифровка пароля для популярного кошелька Bitcoin Core | В этой статье мы воспользуемся классификацией распространенных шаблонов атак из ресурса кибербезопасности [CAPEC™]. В первые об “Padding Oracle Attack” на Wallet.dat заговорили в далеком 2012 году (на платформе по управления уязвимостями и ... |
| 12.11.2023 | Как найти приватный ключ в бинарном коде от Bitcoin Lightning Wallet уязвимость в Quasar Framework | В этой статье мы заострим внимание на приложение для смартфонов iOS и Android популярный Биткоин Кошелек с поддержкой быстрых платежей через (Lightning network) BLW: Bitcoin Lightning Wallet. К большому сожалению многие автономные ноды моби... |
| 05.11.2023 | Milk Sad уязвимость в библиотеке Libbitcoin Explorer 3.x. Крупная кража на $ 900 000 у пользователей Биткоин Кошельков | Исследователи компании «Slowmist» проводят регулярное исследование сферы безопасности блокчейна Биткоин. Они обнародовали уязвимость в библиотеке Libbitcoin Explorer 3.x, который позволила злоумышленникам украсть более $ 900 000 у пользоват... |
| 22.09.2023 | IoT и его криптонит | В одной из предыдущих статей я уже затрагивал тему IoT. В этой статье речь тоже пойдёт об этой концепции. При этом топик опять же затрагивает вопросы безопасности, но в более широком смысле.
В общем «интернет вещей» можно представить в виде... |
| 14.07.2023 | Почему нужно чистить cookies | Хотя логины и пароли учётных записей продолжают оставаться наиболее очевидными целями хакеров, распространение многофакторной аутентификации ведёт к тому, что злоумышленники тоже меняют свои подходы. Одна из новых тактик, набирающих обороты... |
| 29.09.2022 | Как начать заниматься багхантингом веб-приложений | Компании могут проверять свои продукты, сервисы или инфраструктуру на реальность взлома разными способами: это и пентест (тестирование на проникновение), и редтиминг (Red Team, проверка возможностей компании по выявлению и предотвращению вт... |
| 30.08.2022 | Sliver offensive security framework increasingly used by threat actors | Image: Adobe Stock
The business of penetration testing and security auditing is huge, and a lot of different tools are available on the market, or even for free, to help penetration testers. Some of those offensive security frameworks becam... |
| 30.06.2022 | Cyber threat analyst: Key job skills and expected salary | We are excited to bring Transform 2022 back in-person July 19 and virtually July 20 - 28. Join AI and data leaders for insightful talks and exciting networking opportunities. Register today!
Table of contents
Who is a cyber threat analyst?
... |
| 03.01.2022 | Rapid7 : Sharing the Gifts of Cybersecurity – Or, a Lesson From My First Year Without Santa | Editor's note: We had planned to publish our Hacky Holidays blog series throughout December 2021 - but then Log4Shell happened, and we dropped everything to focus on this major vulnerability that impacted the entire cybersecurity community ... |
| 07.12.2021 | Microsoft : New Secured-core servers now available from Microsoft ecosystem to help secure infrastructure | In the current pandemic-driven remote work environments, security has become increasingly important. Earlier this year, Colonial Pipeline, one of the leading suppliers of fuel on the East Coast of the United States, was hit by a ransomware ... |
| 16.11.2021 | Rapid7 : Announcing the 2021 Metasploit Community CTF | It's time for another Metasploit community CTF! Last year's beginner-friendly CTF attracted a wider range of audiences and skill levels than in previous years, so we're replicating our previous game architecture. Players will attack a singl... |
| 14.07.2021 | Rapid7 : Why the Robot Hackers Aren't Here (Yet) | 'Estragon: I'm like that. Either I forget right away or I never forget.' - Samuel Beckett, Waiting for Godot
Hacking and Automation
As hackers, we spend a lot of time making things easier for ourselves.
For example, you might be aware of a ... |
| 12.03.2021 | The Standoff 2021, ноябрь edition. Что не проскочило мимо песочницы PT Sandbox | С 14 по 16 ноября 2021 года на киберполигоне The Standoff происходило третье противостояние между атакующими и защитниками. Сражения прошли в стремительно развивающемся городе-государстве F, в инфраструктуру которого в этот раз входили след... |
| 23.12.2020 | Rapid7 : Metasploit Tips and Tricks for HaXmas 2020 | For this year's HaXmas, we're giving the gift of Metasploit knowledge! We'll cover a mix of old, new, or recently improved features that you can incorporate into your workflows. Some of our readers may already know these tips and tricks for... |
| 28.04.2020 | Rapid7 acquires cloud infrastructure automation platform DivvyCloud for $145 million | Security data and analytics solutions provider Rapid7 today announced its intent to acquire DivvyCloud, a startup developing a cloud infrastructure automation platform, for approximately $145 million in cash and stock. The companies expect ... |
| 28.04.2020 | Rapid7 acquires cloud infrastructure automation platform DivvyCloud for $145 million | We are excited to bring Transform 2022 back in-person July 19 and virtually July 20 - 28. Join AI and data leaders for insightful talks and exciting networking opportunities. Register today!
Security data and analytics solutions provider Ra... |
| 09.04.2020 | Malicious coronavirus-themed apps target Android devices | https://d1rytvr7gmk1sx.cloudfront.net/wp-content/uploads/2020/02/20200228-Holst-Karen.mp4
Mobile malware can be a threat at any time. But as cyber criminals exploit the coronavirus with phishing emails, ransomware, and other attacks, so too... |
| 06.09.2019 | Exploit for wormable BlueKeep Windows bug released into the wild | Enlarge
Aurich Lawson reader comments 53 with 32 posters participating, including story author
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
For months, security practitioners have worried about the public release of a... |
| 01.02.2018 | Threat or menace? “Autosploit” tool sparks fears of empowered “script kiddies” | Enlarge
Kirillm / Getty Images reader comments 44 with 34 posters participating, including story author
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
The tools used by security researchers, penetration testers, and &qu... |
| 31.01.2018 | New Tool Automatically Finds and Hacks Vulnerable Internet-Connected Devices | Hacking isn’t always hard. Some lower-tier hackers use programs to automatically churn through breached login details to break into other accounts, and some penetration testing tools are designed to streamline processes so hackers can get t... |
| 08.02.2017 | A rash of invisible, fileless malware is infecting banks around the globe | Claude Rains starred in the 1933 film adaptation of H.G. Wells' classic science fiction novel, The Invisible Man. It was directed by James Whelan.
Universal Pictures reader comments 64 with 50 posters participating
Share this story
Share on... |
| 28.08.2013 | Unpatched Mac bug gives attackers “super user” status by going back in time | luispita.com reader comments 59 with 38 posters participating, including story author
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
Researchers have made it easier to exploit a five-month-old security flaw that allows ... |
| 30.07.2013 | Pwned again: An exclusive look at Pwnie Express’ newest hack-in-a-box | Ready to quietly mug your network: the Pwn Plug R2.
Pwnie Express reader comments 33 with 32 posters participating, including story author
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
Tomorrow at the Black Hat securit... |
| 23.04.2013 | Java users beware: Exploit circulating for just-patched critical flaw | reader comments 91 with 59 posters participating
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
If you haven't installed last week's patch from Oracle that plugs dozens of critical holes in its Java software framework, ... |
| 12.09.2012 | BlackHole 2.0 gives hackers stealthier ways to pwn | reader comments 11 with 10 posters participating
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
A new version of the BlackHole exploit kit is now out on the web and ready to start infecting. The developer of the toolkit... |
| 28.08.2012 | Attack targeting critical Java bug added to hack-by-numbers exploit kit | A comparison of code found in BlackHole and code published earlier as a proof-of-concept exploit.
F-Secure reader comments 35 with 26 posters participating, including story author
Share this story
Share on Facebook
Share on Twitter
Share on... |
| 27.08.2012 | Critical flaw under active attack prompts calls to disable Java | An exploit that FireEye researchers observed on Sunday being hosted on a domain named ok.XXX4.net.
FireEye reader comments 61 with 48 posters participating
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
A vulnerability ... |
| 22.08.2012 | Password hints easily extracted from Windows 7, 8 | Output of a Metasploit Meterpreter session that extracts Windows 7 and Windows 8 password hints.
SpiderLabs reader comments 120 with 75 posters participating, including story author
Share this story
Share on Facebook
Share on Twitter
Share ... |
| 24.08.2010 | Windows DLL-loading security flaw puts Microsoft in a bind | reader comments 159 with 94 posters participating
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
Last week, HD Moore, creator of the Metasploit penetration testing suite, tweeted about a newly patched iTunes flaw. The t... |
| 29.03.2010 | IE 8 Hacks Slowed by Windows Safeguards | News IE 8 Hacks Slowed by Windows Safeguards By Jabulani LeffallMarch 29, 2010
Even a fire-proof safe needs additional protective measures, and Internet Explorer 8 on Windows 7 is no different.
Such was the view of Microsoft security maven ... |
| 29.03.2010 | IE 8 Hacks Slowed by Windows Safeguards | News IE 8 Hacks Slowed by Windows Safeguards By Jabulani LeffallMarch 29, 2010
Even a fire-proof safe needs additional protective measures, and Internet Explorer 8 on Windows 7 is no different.
Such was the view of Microsoft security maven ... |
| 21.10.2009 | Rapid7 Absorbs Metasploit | Share Share on Facebook Share on Twitter LinkedIn Email Reprints
Rapid7, the Boston- and El Segundo, CA-based startup that makes software to protect corporate networks, databases, and Web applications from hostile outsiders, said today that... |
| 21.10.2009 | Rapid7 Acquires Open Source Metasploit Security Project | News Rapid7 Acquires Open Source Metasploit Security Project By Jabulani LeffallOctober 21, 2009
An independent security researcher and a prominent figure in open source exploit data collection now has a new commercial home.
Rapid7, a vulne... |
| 21.10.2009 | Rapid7 Acquires Open Source Metasploit Security Project | News Rapid7 Acquires Open Source Metasploit Security Project By Jabulani LeffallOctober 21, 2009
An independent security researcher and a prominent figure in open source exploit data collection now has a new commercial home.
Rapid7, a vulne... |
| 02.10.2009 | Microsoft Unmoved by Published SMB Exploit | News Microsoft Unmoved by Published SMB Exploit By Jabulani LeffallOctober 02, 2009
Microsoft's security team didn't flinch this week, even as a proof-of-concept exploit for Windows Server Message Block Version 2 (SMBv2) was published on Su... |
| 02.10.2009 | Microsoft Unmoved by Published SMB Exploit | News Microsoft Unmoved by Published SMB Exploit By Jabulani LeffallOctober 02, 2009
Microsoft's security team didn't flinch this week, even as a proof-of-concept exploit for Windows Server Message Block Version 2 (SMBv2) was published on Su... |
| 21.03.2009 | Pwn2Own winners add Mac exploits to security research tool | reader comments 9 with 9 posters participating
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
Two previous winners of the Pwn2Own contest, Dino Dai Zovi and Charlie Miller, are adding the fruits of their research into M... |
| 25.08.2008 | Red Hat, Fedora servers infiltrated by attackers | reader comments with 0 posters participating
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
Linux distributor Red Hat has issued a statement revealing that its servers were illegally infiltrated by unknown intruders. Ac... |
| 31.07.2008 | First Instance of New DNS Exploit Reported | News First Instance of New DNS Exploit Reported By William JacksonJuly 31, 2008 Reports are coming in that an AT&T Domain Name System (DNS) server may have been compromised with malicious code that exploits a vulnerability reported earl... |
| 18.10.2007 | TIFF exploits for iPhone Safari, Mail released | reader comments with 0 posters participating
Share this story
Share on Facebook
Share on Twitter
Share on Reddit
One of the big questions surrounding the iPhone has been just how secure the device is. Apple has already fixed some security i... |
| - | Best penetration testing tools: 2022 buyer’s guide | Image: Bits and Splits/Adobe Stock
Knowing the state of the entire software system is of the utmost importance if business organizations are to operate with zero tolerance for security vulnerabilities. Although it may be challenging to main... |