Forwarded from Backup Legal Mega
π¦ 2020 Cyber Security Awareness - Malware Explained
https://mega.nz/folder/ap0RTbIS#R3flkOZ7o-N9JIxwP5Yjfw
1. Introduction
https://mega.nz/folder/u1lFFLTT#wfhjchscdbcKKEedRN65kg
2. Malware Background
https://mega.nz/folder/jh9nHJhL#900EX1GSgkLc58Yha0mLlw
3. Malware Risks and Implications
https://mega.nz/folder/XgsFFZqa#cryB6zIx9sQBzGUQe2K8cA
4. Protection from Malware
https://mega.nz/folder/CltDRTDR#PJgoE3zSv8H9kDGgu9fLdQ
5. Wrapping Up
https://mega.nz/folder/LtkDWJYB#Yv59y2fHHpcSNr6bePfsZQ
https://mega.nz/folder/ap0RTbIS#R3flkOZ7o-N9JIxwP5Yjfw
1. Introduction
https://mega.nz/folder/u1lFFLTT#wfhjchscdbcKKEedRN65kg
2. Malware Background
https://mega.nz/folder/jh9nHJhL#900EX1GSgkLc58Yha0mLlw
3. Malware Risks and Implications
https://mega.nz/folder/XgsFFZqa#cryB6zIx9sQBzGUQe2K8cA
4. Protection from Malware
https://mega.nz/folder/CltDRTDR#PJgoE3zSv8H9kDGgu9fLdQ
5. Wrapping Up
https://mega.nz/folder/LtkDWJYB#Yv59y2fHHpcSNr6bePfsZQ
mega.nz
83.64 MB folder on MEGA
16 files and 5 subfolders
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦FOR ANY REAL WIFI HACKING -TERMUX
HOW TTO Acquiring monitor mode on device?
Running command "airodump-ng mon0" (SSIDs/MACs are censored).
You will need an utility "iw" to be installed which lately will be used to modify Wi-Fi module configuration:
1) pkg upgrade
2) pkg install root-repo
3) pkg install iw
4) Plug in the Wi-Fi USB stick and execute next command:
5) iw phy phy1 interface add mon0 type monitor
6) There shouldn't be any error if kernel is properly configured and drivers support monitor mode.
7) To check whether monitor mode is active, use iw dev.
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦FOR ANY REAL WIFI HACKING -TERMUX
HOW TTO Acquiring monitor mode on device?
Running command "airodump-ng mon0" (SSIDs/MACs are censored).
You will need an utility "iw" to be installed which lately will be used to modify Wi-Fi module configuration:
1) pkg upgrade
2) pkg install root-repo
3) pkg install iw
4) Plug in the Wi-Fi USB stick and execute next command:
5) iw phy phy1 interface add mon0 type monitor
6) There shouldn't be any error if kernel is properly configured and drivers support monitor mode.
7) To check whether monitor mode is active, use iw dev.
β β β Uππ»βΊπ«Δπ¬πβ β β β
Forwarded from UNDERCODE NEWS
Microsoft regards modifying HOSTS to block Win10 telemetry data as a serious security risk
#Vulnerabilities
#Vulnerabilities
Forwarded from UNDERCODE NEWS
Evilnum hackers use new Python-based Trojan to attack financial companies
#Malwares
#Malwares
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦How to use DSRM password synchronization to persist domain management authority ?
1) Modify the registry to allow remote access to DSRM accounts
2) Modify the value of DSRMAdminLogonBehavior under the registry HKLM\System\CurrentControlSet\Control\Lsa path to 2.
PS: DSRMAdminLogonBehavior does not exist by default, please add it manually.
3) Use HASH to remotely log in to the domain controller
In any host in the domain, start the Frenchman artifact and execute
Privilege::debug
sekurlsa::pth /domain:WIN2K8-DC /user:Administrator /ntlm:bb559cd28c0148b7396426a80e820e20
4) A CMD will pop up, as shown in the lower right corner of the figure below. This CMD has the authority to access the domain control. The CMD in the lower left corner is a local CMD started directly by Ctrl+R, and you can see that you do not have permission to access the domain control.
A note
5) The DSRM account is the local administrator account of the domain controller, not the domain administrator account. Therefore, the DSRM password synchronization will not affect the domain administrator account. In addition, the value of NTLM remains valid until the next DSRM password synchronization. Therefore, in order to ensure the persistence of permissions, especially in multinational domains or large intranets with hundreds or thousands of domains, it is best to filter the event log with the event ID 4794 in the security events of the event viewer to determine whether the domain management is frequent Perform DSRM password synchronization operations.
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦How to use DSRM password synchronization to persist domain management authority ?
1) Modify the registry to allow remote access to DSRM accounts
2) Modify the value of DSRMAdminLogonBehavior under the registry HKLM\System\CurrentControlSet\Control\Lsa path to 2.
PS: DSRMAdminLogonBehavior does not exist by default, please add it manually.
3) Use HASH to remotely log in to the domain controller
In any host in the domain, start the Frenchman artifact and execute
Privilege::debug
sekurlsa::pth /domain:WIN2K8-DC /user:Administrator /ntlm:bb559cd28c0148b7396426a80e820e20
4) A CMD will pop up, as shown in the lower right corner of the figure below. This CMD has the authority to access the domain control. The CMD in the lower left corner is a local CMD started directly by Ctrl+R, and you can see that you do not have permission to access the domain control.
A note
5) The DSRM account is the local administrator account of the domain controller, not the domain administrator account. Therefore, the DSRM password synchronization will not affect the domain administrator account. In addition, the value of NTLM remains valid until the next DSRM password synchronization. Therefore, in order to ensure the persistence of permissions, especially in multinational domains or large intranets with hundreds or thousands of domains, it is best to filter the event log with the event ID 4794 in the security events of the event viewer to determine whether the domain management is frequent Perform DSRM password synchronization operations.
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦BEST HOME SECURITY APPS :
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.ivideon.client&hl=en
https://play.google.com/store/apps/details?id=com.mcu.reolink
https://play.google.com/store/apps/details?id=com.ivuu&hl=en
https://play.google.com/store/apps/details?id=com.surveillancesystem.isecurity&hl=en
https://itunes.apple.com/us/app/reolink/id995927563?mt=8
https://itunes.apple.com/us/app/presence-free-smart-home-motion/id618598211?mt=8
https://itunes.apple.com/us/app/isentry/id396777365?mt=8
https://itunes.apple.com/us/app/athome-camera-mobile-home/id305567000?mt=8
https://itunes.apple.com/us/app/alarm.com/id315010649?mt=8
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦BEST HOME SECURITY APPS :
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.androidauthority.app
https://play.google.com/store/apps/details?id=com.ivideon.client&hl=en
https://play.google.com/store/apps/details?id=com.mcu.reolink
https://play.google.com/store/apps/details?id=com.ivuu&hl=en
https://play.google.com/store/apps/details?id=com.surveillancesystem.isecurity&hl=en
https://itunes.apple.com/us/app/reolink/id995927563?mt=8
https://itunes.apple.com/us/app/presence-free-smart-home-motion/id618598211?mt=8
https://itunes.apple.com/us/app/isentry/id396777365?mt=8
https://itunes.apple.com/us/app/athome-camera-mobile-home/id305567000?mt=8
https://itunes.apple.com/us/app/alarm.com/id315010649?mt=8
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Network sniffing :
sniffglue is a network sniffer written in rust. Network packets are parsed concurrently using a thread pool to utilize all cpu cores. Project goals are that you can run sniffglue securely on untrusted networks and that it must not crash when processing packets. The output should be as useful as possible by default.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1) apt install debian-keyring
2) gpg -a --export --keyring /usr/share/keyrings/debian-maintainers.gpg git@rxv.cc | apt-key add -
apt-key adv --keyserver keyserver.ubuntu.com --refresh-keys git@rxv.cc
3) echo deb http://apt.vulns.sexy stable main > /etc/apt/sources.list.d/apt-vulns-sexy.list
4) apt update
5) apt install sniffglue
6) sniff with default filters (dhcp, dns, tls, http)
sniffglue enp0s25
7) increase the filter sensitivity (arp)
sniffglue -v enp0s25
8) increase the filter sensitivity (cjdns, ssdp, dropbox, packets with valid utf8)
sniffglue -vv enp0s25
9) almost everything
sniffglue -vvv enp0s25
10) everything
sniffglue -vvvv enp0s25
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Network sniffing :
sniffglue is a network sniffer written in rust. Network packets are parsed concurrently using a thread pool to utilize all cpu cores. Project goals are that you can run sniffglue securely on untrusted networks and that it must not crash when processing packets. The output should be as useful as possible by default.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1) apt install debian-keyring
2) gpg -a --export --keyring /usr/share/keyrings/debian-maintainers.gpg git@rxv.cc | apt-key add -
apt-key adv --keyserver keyserver.ubuntu.com --refresh-keys git@rxv.cc
3) echo deb http://apt.vulns.sexy stable main > /etc/apt/sources.list.d/apt-vulns-sexy.list
4) apt update
5) apt install sniffglue
6) sniff with default filters (dhcp, dns, tls, http)
sniffglue enp0s25
7) increase the filter sensitivity (arp)
sniffglue -v enp0s25
8) increase the filter sensitivity (cjdns, ssdp, dropbox, packets with valid utf8)
sniffglue -vv enp0s25
9) almost everything
sniffglue -vvv enp0s25
10) everything
sniffglue -vvvv enp0s25
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦LEARN PROGRAMMING VIA IOS/ANDROID APPLICATIONS :
https://play.google.com/store/apps/details?id=com.zenva.codemurai&hl=en_US
https://play.google.com/store/apps/details?id=com.zenva.codemurai&hl=en_US
https://apps.apple.com/us/app/codehub-github-for-ios/id707173885?ls=1
https://apps.apple.com/in/app/programming-hub-learn-to-code/id1049691226
https://play.google.com/store/apps/details?id=com.freeit.java&hl=en_IN
https://itunes.apple.com/app/apple-store/id469863705?pt=698519&ct=website%20footer&mt=8
https://play.google.com/store/apps/details?id=org.khanacademy.android&referrer=utm_source%3Dwebsite%2520footer%26utm_medium%3Dwebsite%2520footer%26utm_campaign%3Dwebsite%2520footer
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦LEARN PROGRAMMING VIA IOS/ANDROID APPLICATIONS :
https://play.google.com/store/apps/details?id=com.zenva.codemurai&hl=en_US
https://play.google.com/store/apps/details?id=com.zenva.codemurai&hl=en_US
https://apps.apple.com/us/app/codehub-github-for-ios/id707173885?ls=1
https://apps.apple.com/in/app/programming-hub-learn-to-code/id1049691226
https://play.google.com/store/apps/details?id=com.freeit.java&hl=en_IN
https://itunes.apple.com/app/apple-store/id469863705?pt=698519&ct=website%20footer&mt=8
https://play.google.com/store/apps/details?id=org.khanacademy.android&referrer=utm_source%3Dwebsite%2520footer%26utm_medium%3Dwebsite%2520footer%26utm_campaign%3Dwebsite%2520footer
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
Google Play
Codemurai - Learn Coding - Apps on Google Play
Learn coding languages and frameworks, including HTML, CSS, JS, Python, & Unity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦SOME NEW KEYLOGGERS IOS SPECIALIST:
β’ Keylogging;
β’ Monitor calls β both call logs and recordings;
β’ Monitor texts, emails, browsing history;
β’ Monitor instant messaging and social media apps β Facebook, WhatsApp, Viber, Yahoo;
β’ View contacts, media files, app usage;
β’ Track GPS location.
http://mspy.go2cloud.org/aff_c?offer_id=2&aff_id=4774&url_id=99
http://www.mobile-spy.com/iphone.html
http://maxxspy.com/
https://highstermobile.com/
https://www.flexispy.com/
https://xnspy.com/
https://spyera.com/#nvlv
https://www.spyzie.com/
https://pumpic.com/keylogger-for-iphone.html
https://store.payproglobal.com/r?u=https://ikeymonitor.com/&a=2378
ENJOYβ€οΈππ»
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦SOME NEW KEYLOGGERS IOS SPECIALIST:
β’ Keylogging;
β’ Monitor calls β both call logs and recordings;
β’ Monitor texts, emails, browsing history;
β’ Monitor instant messaging and social media apps β Facebook, WhatsApp, Viber, Yahoo;
β’ View contacts, media files, app usage;
β’ Track GPS location.
http://mspy.go2cloud.org/aff_c?offer_id=2&aff_id=4774&url_id=99
http://www.mobile-spy.com/iphone.html
http://maxxspy.com/
https://highstermobile.com/
https://www.flexispy.com/
https://xnspy.com/
https://spyera.com/#nvlv
https://www.spyzie.com/
https://pumpic.com/keylogger-for-iphone.html
https://store.payproglobal.com/r?u=https://ikeymonitor.com/&a=2378
ENJOYβ€οΈππ»
@undercodeTesting
@UndercodeHacking
@UndercodeSecurity
β β β Uππ»βΊπ«Δπ¬πβ β β β
Pro Linux Foundation Certified Engineer 2019-2020 β3.24 GBβ
https://mega.nz/#F!7xkzhQID!9KFPQdQfrToABn-W7g6gww
https://mega.nz/#F!7xkzhQID!9KFPQdQfrToABn-W7g6gww
mega.nz
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 20GB now
Forwarded from WEB UNDERCODE - PRIVATE
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦HEX EDITORS FOR TERMUX :
hexcurse
Use pkg install hexcurse to install a console hex editor.
Homepage: https://github.com/LonnyGomes/hexcurse
ired
Use pkg install ired to install a minimalist hexadecimal editor.
Homepage: https://github.com/radare/ired
radare2
Use pkg install radare2 to install an advanced hexadecimal editor.
Homepage: https://rada.re
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦HEX EDITORS FOR TERMUX :
hexcurse
Use pkg install hexcurse to install a console hex editor.
Homepage: https://github.com/LonnyGomes/hexcurse
ired
Use pkg install ired to install a minimalist hexadecimal editor.
Homepage: https://github.com/radare/ired
radare2
Use pkg install radare2 to install an advanced hexadecimal editor.
Homepage: https://rada.re
β β β Uππ»βΊπ«Δπ¬πβ β β β
GitHub
GitHub - LonnyGomes/hexcurse: Hexcurse is a ncurses-based console hexeditor written in C
Hexcurse is a ncurses-based console hexeditor written in C - LonnyGomes/hexcurse
Forwarded from WEB UNDERCODE - PRIVATE
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦This plugin for Termux provides
1) beautiful color schemes
2) powerline-ready fonts to customize the appearance of the terminal.
> Long-press anywhere on the Termux terminal and use the "Style" menu entry to use after installation
π¦DOWNLOAD:
https://f-droid.org/packages/com.termux.styling/
https://f-droid.org/repo/com.termux.styling_28.apk
Download : https://f-droid.org/packages/com.termux.styling/
That's itπ€
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦This plugin for Termux provides
1) beautiful color schemes
2) powerline-ready fonts to customize the appearance of the terminal.
> Long-press anywhere on the Termux terminal and use the "Style" menu entry to use after installation
π¦DOWNLOAD:
https://f-droid.org/packages/com.termux.styling/
https://f-droid.org/repo/com.termux.styling_28.apk
Download : https://f-droid.org/packages/com.termux.styling/
That's itπ€
β β β Uππ»βΊπ«Δπ¬πβ β β β
f-droid.org
Termux:Styling | F-Droid - Free and Open Source Android App Repository
Customize your Termux terminal