โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆFREE VPS & Trials New List :
> https://upcloud.com/vpssim/?utm_term=vps%20server&utm_campaign=Global%20-%20VPS&utm_source=adwords&utm_medium=ppc&hsa_acc=9391663435&hsa_cam=1652417669&hsa_grp=71919981308&hsa_ad=416234863334&hsa_src=g&hsa_tgt=kwd-16407600&hsa_kw=vps%20server&hsa_mt=b&hsa_net=adwords&hsa_ver=3&gclid=EAIaIQobChMIms7YyPyr6gIVCJzVCh3mdgPiEAAYASAAEgLp3_D_BwE (Choose plan before trial- cancel)
> https://gratisvps.net/ (6months trial)
> https://developer.rackspace.com/ [600$ for 12 Months]
> https://www.runabove.com/ [1 Week Trial]
>https://www.vultr.com/ [50$ for 2 Months]
>http://cloudsigma.com/ [7 days no CC]
>https://www.ctl.io/free-trial/ [2500$ or 1 Month]
> https://www.ihor.ru/ [3 days No CC]
>http://www.neuprime.com/l_vds3.php [10 days (Otp Required)
> https://alexwebhosting.com/free-vps/ (free 30 days)
Enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆFREE VPS & Trials New List :
> https://upcloud.com/vpssim/?utm_term=vps%20server&utm_campaign=Global%20-%20VPS&utm_source=adwords&utm_medium=ppc&hsa_acc=9391663435&hsa_cam=1652417669&hsa_grp=71919981308&hsa_ad=416234863334&hsa_src=g&hsa_tgt=kwd-16407600&hsa_kw=vps%20server&hsa_mt=b&hsa_net=adwords&hsa_ver=3&gclid=EAIaIQobChMIms7YyPyr6gIVCJzVCh3mdgPiEAAYASAAEgLp3_D_BwE (Choose plan before trial- cancel)
> https://gratisvps.net/ (6months trial)
> https://developer.rackspace.com/ [600$ for 12 Months]
> https://www.runabove.com/ [1 Week Trial]
>https://www.vultr.com/ [50$ for 2 Months]
>http://cloudsigma.com/ [7 days no CC]
>https://www.ctl.io/free-trial/ [2500$ or 1 Month]
> https://www.ihor.ru/ [3 days No CC]
>http://www.neuprime.com/l_vds3.php [10 days (Otp Required)
> https://alexwebhosting.com/free-vps/ (free 30 days)
Enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆImportant Carding Resources !
> NON VBV Carding Sites For Carding All Websites That Are Non VBV
Here are The CARDABLE SITES NON VBV Sites
โ www.amazon.com
โ www.itchee.com
โ www.bn.com
โ www.cdnow.com
โ www.cduniverse.com
โ www.cdworld.com
โ www.virginmega.com
โ www.tunes.com
โ www.artistdirect.com
โ www.jeruk.com
โ www.dvdexpress.com
โ www.dvdworld.com
โ www.ea.com
โ www.tickles.com
โ www.cduniverse.com
๐ฆ Zip Code Search
โhttp://www.findlinks.com/
โhttp://zipinfo.com/search/zipcode.htm
โhttp://www.addresses.com/
โhttp://www.mongabay.com/igapo/
๐ฆSend Fax Online
โefax.com
โj2.com
โsend2fax.com
โrapidfax.comfax1.com
โk7.net
๐ฆ Credit Reports
โhttps://www.mycreditkeeper.com
โhttps://secure.creditreport.com
โhttps://qspace.iplace.com
๐ฆ Phone Redirect
โhttp://www.tollfreeforwarding.com
โhttp://www.Spoofcall.com
โ USA phone number search
โhttp://www.reversephonedetective.com
๐ฆ MMN search
โancestry.com
๐ฆ DOB search
โprivateeye.com
๐ฆ Sock5&Proxy
โhttp://www.socks24.org/
โhttp://www.sockslist.net
Source DeepWeb
(Not by Undercode)
Enjoyโค๏ธ๐๐ป
โ โ โ ๏ฝ๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆImportant Carding Resources !
> NON VBV Carding Sites For Carding All Websites That Are Non VBV
Here are The CARDABLE SITES NON VBV Sites
โ www.amazon.com
โ www.itchee.com
โ www.bn.com
โ www.cdnow.com
โ www.cduniverse.com
โ www.cdworld.com
โ www.virginmega.com
โ www.tunes.com
โ www.artistdirect.com
โ www.jeruk.com
โ www.dvdexpress.com
โ www.dvdworld.com
โ www.ea.com
โ www.tickles.com
โ www.cduniverse.com
๐ฆ Zip Code Search
โhttp://www.findlinks.com/
โhttp://zipinfo.com/search/zipcode.htm
โhttp://www.addresses.com/
โhttp://www.mongabay.com/igapo/
๐ฆSend Fax Online
โefax.com
โj2.com
โsend2fax.com
โrapidfax.comfax1.com
โk7.net
๐ฆ Credit Reports
โhttps://www.mycreditkeeper.com
โhttps://secure.creditreport.com
โhttps://qspace.iplace.com
๐ฆ Phone Redirect
โhttp://www.tollfreeforwarding.com
โhttp://www.Spoofcall.com
โ USA phone number search
โhttp://www.reversephonedetective.com
๐ฆ MMN search
โancestry.com
๐ฆ DOB search
โprivateeye.com
๐ฆ Sock5&Proxy
โhttp://www.socks24.org/
โhttp://www.sockslist.net
Source DeepWeb
(Not by Undercode)
Enjoyโค๏ธ๐๐ป
โ โ โ ๏ฝ๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Zipinfo
Free zipcode lookup with area code, county, latitude, longitude, MSA, PMSA, population, FIPS code, and time zone. Updated monthly.
Free zipcode lookup with areacode, county, latitude, longitude, MSA, PMSA, population, FIPS code, and timezone. Updated monthly.
Forwarded from Backup Legal Mega
mega.nz
9.78 GB folder on MEGA
259 files
๐ฆWorldLiSTS
1๏ธโฃ 5-6 โฎ indonesians โฎ WorldLists :
> https://github.com/geovedi/indonesian-wordlist
2๏ธโฃEnglish for wpa2 WorldList :
> https://www.mediafire.com/file/6botgtnsy0rjfj9/BIG-WPA-LIST-2.rar/file
3๏ธโฃ12 Gb WordlLists :
https://download.weakpass.com/wordlists/1851/hashesorg2019.gz
(good for everything..)
Enjoy โค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
1๏ธโฃ 5-6 โฎ indonesians โฎ WorldLists :
> https://github.com/geovedi/indonesian-wordlist
2๏ธโฃEnglish for wpa2 WorldList :
> https://www.mediafire.com/file/6botgtnsy0rjfj9/BIG-WPA-LIST-2.rar/file
3๏ธโฃ12 Gb WordlLists :
https://download.weakpass.com/wordlists/1851/hashesorg2019.gz
(good for everything..)
Enjoy โค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
GitHub
GitHub - geovedi/indonesian-wordlist: Indonesian wordlist
Indonesian wordlist. Contribute to geovedi/indonesian-wordlist development by creating an account on GitHub.
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆMicrosoft releases emergency security update to fix security vulnerabilities in Windows 10/Server
#UndercodeNews
> There are about two weeks away from this month's patch Tuesday event day, but due to security vulnerabilities found in Windows 10 and Windows Server, today Microsoft released two emergency security updates. Microsoft said that although the two vulnerabilities have not been publicly disclosed and are less likely to be exploited by hackers, the company can't wait for the July 14 patch to release the update on Tuesday's event day.
> Microsoft wrote in a security bulletin: "There is a remote code execution vulnerability in the way Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information and further harm the user's system."
> It is reported that the affected versions of Windows include
Windows 10 version 1709
Windows 10 version 1803
Windows 10 version 1809
Windows 10 version 1903
Windows 10 version 1909
Windows 10 version 2004
Windows Server 2019
Windows Server version 1803
Windows Server version 1903
Windows Server version 1909
Windows Server version 2004
@UndercodeNews
โ โ โ ๏ฝ๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆMicrosoft releases emergency security update to fix security vulnerabilities in Windows 10/Server
#UndercodeNews
> There are about two weeks away from this month's patch Tuesday event day, but due to security vulnerabilities found in Windows 10 and Windows Server, today Microsoft released two emergency security updates. Microsoft said that although the two vulnerabilities have not been publicly disclosed and are less likely to be exploited by hackers, the company can't wait for the July 14 patch to release the update on Tuesday's event day.
> Microsoft wrote in a security bulletin: "There is a remote code execution vulnerability in the way Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information and further harm the user's system."
> It is reported that the affected versions of Windows include
Windows 10 version 1709
Windows 10 version 1803
Windows 10 version 1809
Windows 10 version 1903
Windows 10 version 1909
Windows 10 version 2004
Windows Server 2019
Windows Server version 1803
Windows Server version 1903
Windows Server version 1909
Windows Server version 2004
@UndercodeNews
โ โ โ ๏ฝ๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
โ โ โ ๏ฝ๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆTopic Pentesting tools
โTermux-Linux
SIPVicious OSS security tools
>svmap - this is a sip scanner. Lists SIP devices found on an IP range
>svwar - identifies active extensions on a PBX
>svcrack - an online password cracker for SIP PBX
>svreport - manages sessions and exports reports to various formats
>svcrash - attempts to stop unauthorized svwar and svcrack scans
๐ธ๐ฝ๐ ๐ ๐ฐ๐ป๐ป๐ธ๐ ๐ฐ๐ ๐ธ๐พ๐ฝ & ๐ ๐ ๐ฝ :
1๏ธโฃgit clone https://github.com/EnableSecurity/sipvicious.git
2๏ธโฃcd sipvicious
3๏ธโฃpython setup.py install
4๏ธโฃFire-up the scripts one by one:
sipvicious_svmap --help
sipvicious_svcrack --help
sipvicious_svcrash --help
sipvicious_svwar --help
sipvicious_svreport --help
๐ฆTested by Undercode On :
> ubuntu
โ git sources 2020
Enjoy โค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆTopic Pentesting tools
โTermux-Linux
SIPVicious OSS security tools
>svmap - this is a sip scanner. Lists SIP devices found on an IP range
>svwar - identifies active extensions on a PBX
>svcrack - an online password cracker for SIP PBX
>svreport - manages sessions and exports reports to various formats
>svcrash - attempts to stop unauthorized svwar and svcrack scans
๐ธ๐ฝ๐ ๐ ๐ฐ๐ป๐ป๐ธ๐ ๐ฐ๐ ๐ธ๐พ๐ฝ & ๐ ๐ ๐ฝ :
1๏ธโฃgit clone https://github.com/EnableSecurity/sipvicious.git
2๏ธโฃcd sipvicious
3๏ธโฃpython setup.py install
4๏ธโฃFire-up the scripts one by one:
sipvicious_svmap --help
sipvicious_svcrack --help
sipvicious_svcrash --help
sipvicious_svwar --help
sipvicious_svreport --help
๐ฆTested by Undercode On :
> ubuntu
โ git sources 2020
Enjoy โค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
GitHub
GitHub - EnableSecurity/sipvicious: SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developersโฆ
SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks...
Forwarded from Backup Legal Mega
2020 Learn How to Create Colorful Web Graphics with Canva โ990 MBโ
https://www.skillshare.com/classes/Learn-How-to-Create-Colorful-Web-Graphics-with-Canva/478743012?via=browse-rating-canva-layout-grid
https://mega.nz/#F!yOBFlSKC!lGcg10ktYVYeDnBNl9nMsw
https://www.skillshare.com/classes/Learn-How-to-Create-Colorful-Web-Graphics-with-Canva/478743012?via=browse-rating-canva-layout-grid
https://mega.nz/#F!yOBFlSKC!lGcg10ktYVYeDnBNl9nMsw
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆWhy wifi hacking not recommended for Windows :
Hacking Wi-Fi in Windows
> To be able to crack Wi-Fi in Windows, you need a wireless card that supports monitor mode, and its driver must have support for this mode. For Windows Wi-Fi adapter drivers, this support is not available. Therefore, in Windows it is impossible to capture a handshake.
>There are a few exceptions - high-cost commercial products that include wireless card drivers that support monitor mode. Like Linux, only some hardware is supported.
>Although almost all programs for auditing Wi-Fi networks are made under Linux and only there work great, some of them are cross-platform. For example, to search using graphics cards on Windows, you can use Hashcat, which works great on this operating system.
>In general, of course, it is recommended to use Linux for testing wireless networks, especially such specialized distributions as Kali Linux and BlackArch.
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆWhy wifi hacking not recommended for Windows :
Hacking Wi-Fi in Windows
> To be able to crack Wi-Fi in Windows, you need a wireless card that supports monitor mode, and its driver must have support for this mode. For Windows Wi-Fi adapter drivers, this support is not available. Therefore, in Windows it is impossible to capture a handshake.
>There are a few exceptions - high-cost commercial products that include wireless card drivers that support monitor mode. Like Linux, only some hardware is supported.
>Although almost all programs for auditing Wi-Fi networks are made under Linux and only there work great, some of them are cross-platform. For example, to search using graphics cards on Windows, you can use Hashcat, which works great on this operating system.
>In general, of course, it is recommended to use Linux for testing wireless networks, especially such specialized distributions as Kali Linux and BlackArch.
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆHelpful Hacking Programs :
- [Bookfresh](https://hackerone.com/bookfresh)
- [Brussels Airlines](https://go.intigriti.com/brusselsairlines)
- [BTC_sx](https://cobalt.io/btc-sx)
- [Buffer](mailto:security@bufferapp.com)
- [BX.in.th](https://cobalt.io/bx-in-th)
- [C2FO](https://hackerone.com/c2fo)
- [Campaign Monitor](https://help.campaignmonitor.com/contact)
- [CARD.com](https://bugcrowd.com/card)
- [Catchafire](https://cobalt.io/catchafire)
- [Caviar](https://hackerone.com/caviar)
- [CCBill](mailto:bugrewards@ccbill.com)
- [CERT/CC](https://hackerone.com/cert)
- [Certly](https://hackerone.com/certly)
- [ChainPay](https://cobalt.io/chainpay)
- [ChangeTip](https://cobalt.io/changetip)
- [Chargify](https://bugcrowd.com/chargify)
- [Chromium Project](https://code.google.com/p/chromium/issues/entry?template=Security%20Bug)
- [Circle](https://cobalt.io/circle)
- [CircleCI](mailto:security@circleci.com)
- [Cisco](http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html#roosfassv)
- [ClickUp](https://clickup.com/bug-bounty)
- [Clojars](mailto:contact@clojars.org)
- [CloudFlare](https://hackerone.com/cloudflare)
- [Cobalt](https://cobalt.io/cobalt)
- [Code Climate](mailto:security@codeclimate.com)
- [CodeIgniter](https://hackerone.com/codeigniter)
- [CodePen](https://bugcrowd.com/codepen)
- [Coin Republic](https://cobalt.io/coin-republic)
- [Coin.Space](https://hackerone.com/coinspace)
Enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆHelpful Hacking Programs :
- [Bookfresh](https://hackerone.com/bookfresh)
- [Brussels Airlines](https://go.intigriti.com/brusselsairlines)
- [BTC_sx](https://cobalt.io/btc-sx)
- [Buffer](mailto:security@bufferapp.com)
- [BX.in.th](https://cobalt.io/bx-in-th)
- [C2FO](https://hackerone.com/c2fo)
- [Campaign Monitor](https://help.campaignmonitor.com/contact)
- [CARD.com](https://bugcrowd.com/card)
- [Catchafire](https://cobalt.io/catchafire)
- [Caviar](https://hackerone.com/caviar)
- [CCBill](mailto:bugrewards@ccbill.com)
- [CERT/CC](https://hackerone.com/cert)
- [Certly](https://hackerone.com/certly)
- [ChainPay](https://cobalt.io/chainpay)
- [ChangeTip](https://cobalt.io/changetip)
- [Chargify](https://bugcrowd.com/chargify)
- [Chromium Project](https://code.google.com/p/chromium/issues/entry?template=Security%20Bug)
- [Circle](https://cobalt.io/circle)
- [CircleCI](mailto:security@circleci.com)
- [Cisco](http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html#roosfassv)
- [ClickUp](https://clickup.com/bug-bounty)
- [Clojars](mailto:contact@clojars.org)
- [CloudFlare](https://hackerone.com/cloudflare)
- [Cobalt](https://cobalt.io/cobalt)
- [Code Climate](mailto:security@codeclimate.com)
- [CodeIgniter](https://hackerone.com/codeigniter)
- [CodePen](https://bugcrowd.com/codepen)
- [Coin Republic](https://cobalt.io/coin-republic)
- [Coin.Space](https://hackerone.com/coinspace)
Enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
HackerOne
Bookfresh - Bug Bounty Program | HackerOne
The Bookfresh Bug Bounty Program enlists the help of the hacker community at HackerOne to make Bookfresh more secure. HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminallyโฆ
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆHow to set up a connection to RDP from the Internet ?
> RDP allows any connection, whether from a local network or from the Internet. Connecting from the Internet requires your computer to have a white IP .
> If your ISP uses NAT , then you need to rent an external (white) IP address.
> If you are connected to a router (they also always use NAT), then you need to configure port forwarding (forwarding, forwarding) as follows:
1) You need to start with " Permanent IP Settings in Windows ."
2) Subsequent settings must be made in the router. Since everyone has different models of routers, the specific actions and names of the tabs in the administration panel of routers may vary. The main thing is to understand the essence and find the appropriate tab in the router. Remember that you need to forward TCP and UDP ports with the number 3389.
3) Go to the control panel of the router . In the settings of the router, go to "section of the Internet " (may be referred to the WAN ), then the tab " Port Forwarding " (may be called " Port Forwarding ", " Port Forwarding "):
4) Add a new rule:
>Service Name - enter any
>Source IP leave blank
>Port Range - Specify Port 3389
>Local IP address - specify the IP address of the Windows computer to >which RDP connection will be made
>Local port - specify port 3389
>Protocol - specify Both (both)
And click the " Add " button .
5) Save your changes.
Written by Undercode
#FastTips
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆHow to set up a connection to RDP from the Internet ?
> RDP allows any connection, whether from a local network or from the Internet. Connecting from the Internet requires your computer to have a white IP .
> If your ISP uses NAT , then you need to rent an external (white) IP address.
> If you are connected to a router (they also always use NAT), then you need to configure port forwarding (forwarding, forwarding) as follows:
1) You need to start with " Permanent IP Settings in Windows ."
2) Subsequent settings must be made in the router. Since everyone has different models of routers, the specific actions and names of the tabs in the administration panel of routers may vary. The main thing is to understand the essence and find the appropriate tab in the router. Remember that you need to forward TCP and UDP ports with the number 3389.
3) Go to the control panel of the router . In the settings of the router, go to "section of the Internet " (may be referred to the WAN ), then the tab " Port Forwarding " (may be called " Port Forwarding ", " Port Forwarding "):
4) Add a new rule:
>Service Name - enter any
>Source IP leave blank
>Port Range - Specify Port 3389
>Local IP address - specify the IP address of the Windows computer to >which RDP connection will be made
>Local port - specify port 3389
>Protocol - specify Both (both)
And click the " Add " button .
5) Save your changes.
Written by Undercode
#FastTips
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
Forwarded from Backup Legal Mega
๐ฆDigital Character Illustration: Create A Memorable, Whimsical Character โ802 MBโ
https://www.skillshare.com/classes/Digital-Character-Illustration-Create-A-Memorable-Whimsical-Character/1160577675
https://mega.nz/folder/giIAhIqR#4EWS8Qh-xu1l4FTLYVtAfA
https://www.skillshare.com/classes/Digital-Character-Illustration-Create-A-Memorable-Whimsical-Character/1160577675
https://mega.nz/folder/giIAhIqR#4EWS8Qh-xu1l4FTLYVtAfA
Skillshare
Digital Character Illustration: Create A Memorable, Whimsical Character | Justyna Stasik | Skillshare
Learn to use Adobe Illustrator and unlock the skills to create vibrant, dynamic characters!Join illustrator Justyna Stasik, known for her relatable and body-pos...
Forwarded from Backup Legal Mega
mega.nz
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 20GB now
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆ#ProUsers The Yardstick One and RFcat Notes
The Yardstick One is a very useful piece of hardware to perform testing of RF devices that communicate in frequencies under 1GHz. It can be combined with many tools, including RFcat. The following are a few links and resources that we discussed in the video course related to these tools:
๐ณYardstick One
Yardstick One website: https://greatscottgadgets.com/2015/09-30-introducing-yard-stick-one/
๐ณRFcat
RFcat website: https://bitbucket.org/atlas0fd00m/rfcat
The following are several useful RFcat commands:
`d._debug = 1` รขโฌโ dumps debug messages to the screen
`d.discover()` - listens for specific SYNCWORDS
`d.lowballRestore()` - restores the configuration before calling lowball()
`d.RFcapture()` - dumps data to screen, returns list of packets
`d.setChannel()` - sets the channel to be used
`d.setFreq()` - sets the frequency to be used
Source: โ 2020 git sources
enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆ#ProUsers The Yardstick One and RFcat Notes
The Yardstick One is a very useful piece of hardware to perform testing of RF devices that communicate in frequencies under 1GHz. It can be combined with many tools, including RFcat. The following are a few links and resources that we discussed in the video course related to these tools:
๐ณYardstick One
Yardstick One website: https://greatscottgadgets.com/2015/09-30-introducing-yard-stick-one/
๐ณRFcat
RFcat website: https://bitbucket.org/atlas0fd00m/rfcat
The following are several useful RFcat commands:
`d._debug = 1` รขโฌโ dumps debug messages to the screen
d.debug() - prints state information every second`d.discover()` - listens for specific SYNCWORDS
d.lowball() - disables most รขโฌลfiltersรขโฌ to see more packets`d.lowballRestore()` - restores the configuration before calling lowball()
d.RFlisten() - listens for signals and dumps data to the screen`d.RFcapture()` - dumps data to screen, returns list of packets
d.scan() - scans a configurable frequency range `d.setChannel()` - sets the channel to be used
d.setFHSSstate() - sets the FHSS state to be used`d.setFreq()` - sets the frequency to be used
d.specan() - a spectrum analyzerSource: โ 2020 git sources
enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆNew Tips: #ZigBee Resources
Good explanation and introduction to Zigbee: http://resources.infosecinstitute.com/hacking-zigbee-networks/
KillerBee Presentation: http://www.willhackforsushi.com/presentations/toorcon11-wright.pdf
KillerBee Framework: https://github.com/riverloopsec/killerbee
The KillerBee framework is being expanded to support multiple devices. Currently there is support for the River Loop ApiMote, Atmel RZ RAVEN USB Stick, MoteIV Tmote Sky, TelosB mote, and Sewino Sniffer.
Open source hardware: https://github.com/riverloopsec/apimote
Attify ZigBee Framework GitHub Repo: https://github.com/attify/Attify-Zigbee-Framework
โ 2020 git sources
enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆNew Tips: #ZigBee Resources
Good explanation and introduction to Zigbee: http://resources.infosecinstitute.com/hacking-zigbee-networks/
KillerBee Presentation: http://www.willhackforsushi.com/presentations/toorcon11-wright.pdf
KillerBee Framework: https://github.com/riverloopsec/killerbee
The KillerBee framework is being expanded to support multiple devices. Currently there is support for the River Loop ApiMote, Atmel RZ RAVEN USB Stick, MoteIV Tmote Sky, TelosB mote, and Sewino Sniffer.
Open source hardware: https://github.com/riverloopsec/apimote
Attify ZigBee Framework GitHub Repo: https://github.com/attify/Attify-Zigbee-Framework
โ 2020 git sources
enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
Infosec Resources
Hacking ZigBee Networks
What is ZigBee? Internet of Things (IoT) is what most experts consider as the next step of the Internet revolution where physical objects are invariably
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆ2020 Only usefull Hacking tools #list 3 :
- BaseQuery - A Way To Organize Public Combo-Lists And Leaks In A Way That You Can Easily Search Through Everything
- Attack Monitor - Endpoint Detection And Malware Analysis Software
- Crashcast-Exploit - This Tool Allows You Mass Play Any YouTube Video With Chromecasts Obtained From Shodan.io
- SQLMap v1.3 - Automatic SQL Injection And Database Takeover Tool
- Stretcher - Tool Designed To Help Identify Open Elasticsearch Servers That Are Exposing Sensitive Information
- Aztarna - A Footprinting Tool For Robots
- Hediye - Hash Generator & Cracker Online Offline
- Killcast - Manipulate Chromecast Devices In Your Network
- bypass-firewalls-by-DNS-history - Firewall Bypass Script Based On DNS History Records
- WiFi-Pumpkin v0.8.7 - Framework for Rogue Wi-Fi Access Point Attack
- H8Mail - Email OSINT And Password Breach Hunting
- Kube-Hunter - Hunt For Security Weaknesses In Kubernetes Clusters
- Metasploit 5.0 - The Worldรขโฌโขs Most Used Penetration Testing Framework
- Interlace - Easily Turn Single Threaded Command Line Applications Into Fast, Multi Threaded Ones With CIDR And Glob Support
- Twifo-Cli - Get User Information Of A Twitter User
- Sitadel - Web Application Security Scanner
- Pe-Sieve - Recognizes And Dumps A Variety Of Potentially Malicious Implants (Replaced/Injected PEs, Shellcodes, Hooks, In-Memory Patches)
- Malboxes - Builds Malware Analysis Windows VMs So That You Don'T Have To
- Snyk - CLI And Build-Time Tool To Find & Fix Known Vulnerabilities In Open-Source Dependencies
- Shed - .NET Runtime Inspector
- Stardox - Github Stargazers Information Gathering Tool
โ 2020 git sources
enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆ2020 Only usefull Hacking tools #list 3 :
- BaseQuery - A Way To Organize Public Combo-Lists And Leaks In A Way That You Can Easily Search Through Everything
- Attack Monitor - Endpoint Detection And Malware Analysis Software
- Crashcast-Exploit - This Tool Allows You Mass Play Any YouTube Video With Chromecasts Obtained From Shodan.io
- SQLMap v1.3 - Automatic SQL Injection And Database Takeover Tool
- Stretcher - Tool Designed To Help Identify Open Elasticsearch Servers That Are Exposing Sensitive Information
- Aztarna - A Footprinting Tool For Robots
- Hediye - Hash Generator & Cracker Online Offline
- Killcast - Manipulate Chromecast Devices In Your Network
- bypass-firewalls-by-DNS-history - Firewall Bypass Script Based On DNS History Records
- WiFi-Pumpkin v0.8.7 - Framework for Rogue Wi-Fi Access Point Attack
- H8Mail - Email OSINT And Password Breach Hunting
- Kube-Hunter - Hunt For Security Weaknesses In Kubernetes Clusters
- Metasploit 5.0 - The Worldรขโฌโขs Most Used Penetration Testing Framework
- Interlace - Easily Turn Single Threaded Command Line Applications Into Fast, Multi Threaded Ones With CIDR And Glob Support
- Twifo-Cli - Get User Information Of A Twitter User
- Sitadel - Web Application Security Scanner
- Pe-Sieve - Recognizes And Dumps A Variety Of Potentially Malicious Implants (Replaced/Injected PEs, Shellcodes, Hooks, In-Memory Patches)
- Malboxes - Builds Malware Analysis Windows VMs So That You Don'T Have To
- Snyk - CLI And Build-Time Tool To Find & Fix Known Vulnerabilities In Open-Source Dependencies
- Shed - .NET Runtime Inspector
- Stardox - Github Stargazers Information Gathering Tool
โ 2020 git sources
enjoyโค๏ธ๐๐ป
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
KitPloit - PenTest & Hacking Tools
BaseQuery - A Way To Organize Public Combo-Lists And Leaks In A Way That You Can Easily Search Through Everything
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆHow medical equipment should resist hacker attacks ?
#News
For hospitals, the best way to prevent network attacks and protect IoMT devices from infection is to isolate the most vulnerable and critical devices from each other or maintain a virtual distance, which is called network segmentation.
Hospitals can take the following practical steps to segment clinical networks, reduce the attack surface, and protect patients from cyber attacks:
1๏ธโฃFirst clear who is responsible
Traditionally, the safety of medical equipment has always been the responsibility of experts in biomedical engineering equipment.
> However, with the increasing popularity of IoMT devices and the increase of cyber attacks against healthcare, the IT team of the hospital information department had to invest more energy in medical device security. Therefore, there is a need for close cooperation between the information department and the biomedical engineering research team to design and implement safe and effective security policies for clinical networks.
>In order to ensure the safety of medical equipment and integrate IT and biomedical teams across departments, a separate, final IoMT cybersecurity policy decision maker is needed. Some large institutions have even added the role of medical equipment security officer (MDSO), which is directly responsible for the safety of medical equipment in the entire clinical network of the entire hospital.
2๏ธโฃ Create a reliable equipment list
If you do not have a deep understanding of the medical equipment connected to the hospital, the configuration files on the equipment, and the communication mode, you cannot set a network segmentation strategy.
Automated inventory tools must also be able to perform continuous analysis of equipment while understanding the behavior, criticality, and vulnerability of IoMT equipment.
3๏ธโฃ Assess the risk of each device
> The risk score should be calculated based on the criticality and medical impact of the equipment. The risk assessment should be carried out continuously, and the abnormal behavior of the network should be continuously monitored. In order to assess risk, the following factors must be considered:
> Communicate with external servers required for normal device function (i.e. vendor communication)
>The device needs to store and send ePHI, and for what purpose?
๐ณDevice usage mode
Is the device running an unsupported operating system or are there any known vulnerabilities? If yes, do you use patches or network segmentation to protect the device?
4๏ธโฃ Follow regulatory guidelines and rules in real time
If the hospital does not comply with federal and state regulatory standards, it will face millions of dollars in fines. Aside from the loss of money, failure to comply with cybersecurity guidelines puts medical equipment at risk and may endanger the safety of patients, business integrity, and the reputation of the hospital.
Guidelines and regulations concerning health care and medical equipment are regularly updated. To maintain compliance, hospitals must pay close attention to regulatory standards and updates issued by state federal agencies, including:
U.S. Food and Drug Administration (FDA)
Medical Device Information Sharing and Analysis (MDISS) Initiative
Health Insurance Portability and Accountability Act (HIPAA)
5๏ธโฃDesign, verify and execute segmentation strategies
Segmentation strategies are used to reduce the attack surface and prevent potential threats. Network segmentation can also help the network run more smoothly by restricting traffic to designated areas and reducing network load.
share usโค๏ธ๐๐ป
written by
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ
๐ฆHow medical equipment should resist hacker attacks ?
#News
For hospitals, the best way to prevent network attacks and protect IoMT devices from infection is to isolate the most vulnerable and critical devices from each other or maintain a virtual distance, which is called network segmentation.
Hospitals can take the following practical steps to segment clinical networks, reduce the attack surface, and protect patients from cyber attacks:
1๏ธโฃFirst clear who is responsible
Traditionally, the safety of medical equipment has always been the responsibility of experts in biomedical engineering equipment.
> However, with the increasing popularity of IoMT devices and the increase of cyber attacks against healthcare, the IT team of the hospital information department had to invest more energy in medical device security. Therefore, there is a need for close cooperation between the information department and the biomedical engineering research team to design and implement safe and effective security policies for clinical networks.
>In order to ensure the safety of medical equipment and integrate IT and biomedical teams across departments, a separate, final IoMT cybersecurity policy decision maker is needed. Some large institutions have even added the role of medical equipment security officer (MDSO), which is directly responsible for the safety of medical equipment in the entire clinical network of the entire hospital.
2๏ธโฃ Create a reliable equipment list
If you do not have a deep understanding of the medical equipment connected to the hospital, the configuration files on the equipment, and the communication mode, you cannot set a network segmentation strategy.
Automated inventory tools must also be able to perform continuous analysis of equipment while understanding the behavior, criticality, and vulnerability of IoMT equipment.
3๏ธโฃ Assess the risk of each device
> The risk score should be calculated based on the criticality and medical impact of the equipment. The risk assessment should be carried out continuously, and the abnormal behavior of the network should be continuously monitored. In order to assess risk, the following factors must be considered:
> Communicate with external servers required for normal device function (i.e. vendor communication)
>The device needs to store and send ePHI, and for what purpose?
๐ณDevice usage mode
Is the device running an unsupported operating system or are there any known vulnerabilities? If yes, do you use patches or network segmentation to protect the device?
4๏ธโฃ Follow regulatory guidelines and rules in real time
If the hospital does not comply with federal and state regulatory standards, it will face millions of dollars in fines. Aside from the loss of money, failure to comply with cybersecurity guidelines puts medical equipment at risk and may endanger the safety of patients, business integrity, and the reputation of the hospital.
Guidelines and regulations concerning health care and medical equipment are regularly updated. To maintain compliance, hospitals must pay close attention to regulatory standards and updates issued by state federal agencies, including:
U.S. Food and Drug Administration (FDA)
Medical Device Information Sharing and Analysis (MDISS) Initiative
Health Insurance Portability and Accountability Act (HIPAA)
5๏ธโฃDesign, verify and execute segmentation strategies
Segmentation strategies are used to reduce the attack surface and prevent potential threats. Network segmentation can also help the network run more smoothly by restricting traffic to designated areas and reducing network load.
share usโค๏ธ๐๐ป
written by
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
โ โ โ U๐๐ปโบ๐ซ6๐ฌ๐โ โ โ โ