Flipper Zero worth it?

I’ve been wanting a Flipper Zero for about half a year now, especially since I could never get my pwnagotchi to work. But it’s been a half a year and i’ve progressed significantly since then. I also hear a lot of people with more experience than me tell me it’s not worth the money, you can do everything a Flipper Zero can do cheaper with a Raspberry Pi Zero W and other tools.

Is it worth it? Really the only reason for me to get it now is for the dolphin buddy aesthetic. I’m still a noob at NFC/Bluetooth/radio hacking. Would a Chameleon Tiny Pro or Chameleon Mini Rev G be more useful?

submitted by /u/9x19mm_parabellvm
[link] [comments]

books

Any book recommendations for a newbie here? A beginers guide if can. submitted by /u/Ryanrence [link] [comments]

Blackmarket prices for passwords in early 2000’s

Hey guys, so I have a question for a brief speech I am writing about password security (for a public speaking class, so I just need listeners’ attention and not some complex speech or anything). I know that nowadays, logon dumps are so common and come in such large sizes that the monetary value of a single user’s information (assuming that of your regular joe and not someone with a lot of wealth) is essentially nothing. I have looked at articles on breaches like Collection#1 and verifications.io, and am presenting on that as well, but I was wondering what a password for a single users logon information could have been back in the early 2000’s when large data breaches would have been rare and made national news if even like over 1,000 users logon information was leaked. I am reading Hacking Multifactor Authentication by Roger Grimes, and he says that a single user’s information could have gotten hackers “many tens of dollars” but I was wondering if anyone knew a less vague price range that I could use. Thanks!

submitted by /u/Johnson_56
[link] [comments]

Expanding to /r/hacking – fun 3min cybersecurity newsletter

I think there’s prob some overlap here and /r/cybersecurity.

Earlier today I had a post that got lots of interest about creating a fun, 3min daily newsletter on what’s happening in cybersecurity.

My writing style mixes fun and news sharing – I don’t take myself too seriously (even with a serious topic).

Based on the feedback, I decided to give it a go and the newsletter will start tomorrow – just thought I’d share here in case this community was interested as well!

submitted by /u/frenchfry_wildcat
[link] [comments]

make a payload actually FUD

Holy shit I have been trying to find a way to make metasploit payloads FUD and all I can find "oh use an encoder option" ITS STILL GETTING DETECTED BY THE SIMPLEST AV WINDOWS DEFENDER!!!!! Does anyone actually know how to make a msfvenom payl…

Are there USB Autorun Bypasses/Alternatives for newer versions of Windows?

Hey, I have a USB and am trying to run a batch file automatically when the USB is plugged in. Using an Autorun.inf file is highly deprecated, as you have to manually enable autorun to be allowed via your settings. Does anyone know any alternatives I can use? I would prefer them to not need any user interaction, but if they do that’s fine. I read that windows has relaxed restrictions for CD/ROM Disks when it comes to autorun, so could I make a small (1 or 2 mb) partition, and put an autorun.inf file in there? I am really lost right now, any help will be appreciated.

submitted by /u/Hyperninja303
[link] [comments]

WordPress 5.9.2 RCE?

I;m doing a ctf and enumerated the targed & found 2 user password for the wp -admin via xml-rpc. 2 SHH cert. file auth only, trying to find the vulnerability that levrage rce(reverse shell), maybe someone here has any solutions? I metion that the …

WP 5.9.2 – prototype Pollution?

I;m doing a ctf and enumerated the targed & found 2 user password for the wp -admin via xml-rpc. 2 SHH cert. file auth only, trying to find the vulnerability that levrage rce, maybe someone here has any solutions? I metion that the one of the 2 us…