Forwarded from vx-underground
vx-underground
Sometimes goofballs message me totally made up malware stories This guy messaged me unironically saying when he was 15 he wrote a completely undetected Windows botnet, infected several million computers all across the planet, and it used mIRC as a C2. Dawg…
HOW THE FUCK DO YOU HAVE SEVERAL MILLION DEVICES CONNECT TO A SINGULAR CHATROOM INSTANCE? WHAT KIND OF INFRASTRUCTURE ARE YOU HOUSING YOUR IRC SERVER ON
Forwarded from НеКасперский
Заказ принят
Взлом Burger King позволил получить белому хакеру контроль над 30000 ресторанами и доступ к тысячам аудиозаписей клиентов по всему миру.
В ходе аудита была обнаружена открытая регистрация в AWS Cognito и GraphQL-интроспекция без авторизации. Это позволило создавать новые учётки и генерировать JWT-токены для повышения привилегий.
В итоге хакер получил доступ к тысячам аудиозаписей разговоров с клиентами, которые использовались для AI-аналитики настроения клиентов и эффективности сотрудников. Ну и по-классике, в HTML-коде присутствовали захардкоженные пароли типа «admin» 🫠
После публикации отчёта компания попыталась удалить материалы через DMCA вместо прозрачного исправления и публичного отчёта, но благо интернет все помнит.
Нет, вам не показалось. До этого тот же хакер уже отметился в McDonald’s, поставив Шрека на их дешборд.
НеКасперский
Взлом Burger King позволил получить белому хакеру контроль над 30000 ресторанами и доступ к тысячам аудиозаписей клиентов по всему миру.
В ходе аудита была обнаружена открытая регистрация в AWS Cognito и GraphQL-интроспекция без авторизации. Это позволило создавать новые учётки и генерировать JWT-токены для повышения привилегий.
В итоге хакер получил доступ к тысячам аудиозаписей разговоров с клиентами, которые использовались для AI-аналитики настроения клиентов и эффективности сотрудников. Ну и по-классике, в HTML-коде присутствовали захардкоженные пароли типа «admin» 🫠
После публикации отчёта компания попыталась удалить материалы через DMCA вместо прозрачного исправления и публичного отчёта, но благо интернет все помнит.
Нет, вам не показалось. До этого тот же хакер уже отметился в McDonald’s, поставив Шрека на их дешборд.
НеКасперский
КОММЕНТИРОВАТЬ - ТОЛЬКО ПОРТИТЬ TD;TR; 🤣
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from vx-underground
Media is too big
VIEW IN TELEGRAM
this is the type of music people listen to when they're extorting companies and laundering money on the internet
Forwarded from vx-underground
Nerds angry at ProtonMail today (yesterday?) due to internet drama (as is tradition). People are big mad. Is it a big deal? Are people overreacting? Why did normie accounts comment on the issue like they know what's going on?
Phrack did some silly things on the internet. They were able to get access to North Korean state-sponsored machines, or something, which were being used to attack South Korean government stuff. Specifically, the DPRK was targeting:
- South Korea Defense Counterintelligence Command
- South Korea Ministry of Foreign Affairs
- ???
Phrack was able to do some internet nerd stuff and dump DPRK password sheets (domain, username, password) which were stored in various files unencrypted (literally a .docx). They also dumped screenshots of user stuff, more credentials, tooling, documentation, and 20,000 browser history entries.
Following this, Phrack decided to be nice and notify the South Korean government regarding the DPRK.
I'm not a government nerd, but I'd guess that the South Korean government would like to be notified of any intelligence regarding the DPRK and their offensive cybersecurity actions toward them.
Here is the drama:
Phrack was speaking to South Korean nerds in proxy. Some nerd made a Proton e-mail and contacted the South Korean government from Proton e-mail. On August 15th, proxy nerd had their Proton e-mail magically nuked. Additionally, Phrack nerd had their Proton e-mail magically nuked August 16th.
It doesn't take a rocket scientist to put 2 and 2 together here and determine that Proton, for reasons not explained, took action against them (in some capacity) and terminated their accounts.
Phrack then contacted Proton e-mail requesting an unban, or something. Proton replied with, "your account will cause further damage to our service, therefore we will keep the account suspended."
Phrack then decided to contact Proton legal department. Phrack contacted Proton's legal department on 8 separate occasions and was ignored.
Did Proton violate their privacy stuff by terminating the Phrack accounts? Why was Phrack stuff terminated? Did the South Korean government get big mad and decide to send legal stuff to Phrack? Is Proton illegal and for nerds?
Find out next time on Dragon Ball Z
Phrack did some silly things on the internet. They were able to get access to North Korean state-sponsored machines, or something, which were being used to attack South Korean government stuff. Specifically, the DPRK was targeting:
- South Korea Defense Counterintelligence Command
- South Korea Ministry of Foreign Affairs
- ???
Phrack was able to do some internet nerd stuff and dump DPRK password sheets (domain, username, password) which were stored in various files unencrypted (literally a .docx). They also dumped screenshots of user stuff, more credentials, tooling, documentation, and 20,000 browser history entries.
Following this, Phrack decided to be nice and notify the South Korean government regarding the DPRK.
I'm not a government nerd, but I'd guess that the South Korean government would like to be notified of any intelligence regarding the DPRK and their offensive cybersecurity actions toward them.
Here is the drama:
Phrack was speaking to South Korean nerds in proxy. Some nerd made a Proton e-mail and contacted the South Korean government from Proton e-mail. On August 15th, proxy nerd had their Proton e-mail magically nuked. Additionally, Phrack nerd had their Proton e-mail magically nuked August 16th.
It doesn't take a rocket scientist to put 2 and 2 together here and determine that Proton, for reasons not explained, took action against them (in some capacity) and terminated their accounts.
Phrack then contacted Proton e-mail requesting an unban, or something. Proton replied with, "your account will cause further damage to our service, therefore we will keep the account suspended."
Phrack then decided to contact Proton legal department. Phrack contacted Proton's legal department on 8 separate occasions and was ignored.
Did Proton violate their privacy stuff by terminating the Phrack accounts? Why was Phrack stuff terminated? Did the South Korean government get big mad and decide to send legal stuff to Phrack? Is Proton illegal and for nerds?
Find out next time on Dragon Ball Z
В целом, закрыть боевой пропуск из 80 уровней и добить до 100ки его было прикольно.
ЕЩЕ ПРИКОЛЬНЕЕ ЧТО ЭТО🙂
16 сентября новый 3-й сезон, в ЗБТ уже пощупал, интересно.
btw, Arena Breakout Infinite
ЕЩЕ ПРИКОЛЬНЕЕ ЧТО ЭТО
C2 16 сентября новый 3-й сезон, в ЗБТ уже пощупал, интересно.
btw, Arena Breakout Infinite
Please open Telegram to view this post
VIEW IN TELEGRAM
Фраза вечера:
На каждую хитрую жопу есть х** с винтом, а на х** с винтом есть жопа с лабиринтами
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from vx-underground
tl;dr chinas firewall censorship thingy has massive leak. shows code and political ambitions and stuff
idk the significance because i dont study chinese network firewall sciency stuff. maybe one of you nerds is interested. its all available for download online now
https://gfw.report/blog/geedge_and_mesa_leak/en/
idk the significance because i dont study chinese network firewall sciency stuff. maybe one of you nerds is interested. its all available for download online now
https://gfw.report/blog/geedge_and_mesa_leak/en/
Forwarded from vx-underground
🚨BREAKING 🚨
LINUX NERDS ARE MAD. THIS IS NOT A DRILL.
Linux nerds do NOT fuck around with performance.
Noted from The Lunduke Journal, "Ubuntu’s plan to replace the GNU Core Utils with Rust-based reimplementations is going exactly as poorly as predicted. Some Rust versions being 17 times slower than the battle tested GNU C / C++ version. And other Rust-based versions simply failing to work on large files."
LINUX NERDS ARE MAD. THIS IS NOT A DRILL.
Linux nerds do NOT fuck around with performance.
Noted from The Lunduke Journal, "Ubuntu’s plan to replace the GNU Core Utils with Rust-based reimplementations is going exactly as poorly as predicted. Some Rust versions being 17 times slower than the battle tested GNU C / C++ version. And other Rust-based versions simply failing to work on large files."