Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is there a way to disable Windows Defender though a non-admin reverse shell?

I've looked at old posts and found nothing usefull. Is there any practical way to do this?

submitted by /u/Ayazerzurum2
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Old org refusing to collect my company laptop from me, been 6 months now, is it possible to get passed the companies OS lock?

Title, was thinking I could maybe get the partition wiped and HDD replaced? Just curious more than anything, I honestly think they have forgotten about the laptop.

submitted by /u/Pesimyst
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Internet scouring key-searching hacking method

I don't know if this sub allows for posts like this but, some years ago I used to go on hacking forums and picked up a couple of software that one of them basically scours the internet for leaked information, and the second one validates each credential pair to find working accounts for certain paid sites or software applications.



Does anyone know anything about this? the term used to refer to this method? the apps involved? I remember nothing at this point.

submitted by /u/Adlol
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
I Was Hacked: What I’ve Learned Since

https://cdn-images-1.medium.com/max/1920/1*d_vljSiJT9CynHBzSVYREg.jpeg
It was Easter 2018. I was still in high school, and like many teenagers, I was a bit reckless. I signed up for a website that promised…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical Linux Kernel Flaw – Unprivileged Users Gain Root Control

Critical Linux Kernel Flaw – Unprivileged Users Gain Root ControlPost Views: 171 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Linux Flaw Grants Root Control – Local Users Exploit Privilege Escalation VulnerabilityA critical flaw has been discovered in the Linux NetFilter kernel, exposing a vulnerability that enables unprivileged local users to escalate their privileges to root level, granting them complete control over a system. The flaw, identified as CVE-2023-32233, is yet to be assigned a severity level. The security issue arises from Netfilter nf_tables, which accepts invalid updates to its configuration, leading to the corruption of the subsystem’s internal state in specific scenarios.

Netfilter serves as a packet filtering and network address translation (NAT) framework integrated into the Linux kernel, managed through front-end utilities like IPtables and UFW. A recent advisory highlights that corrupting the internal state triggers a use-after-free vulnerability, allowing arbitrary reads and writes in the kernel memory.

Security researchers shared a proof-of-concept (PoC) exploit on the Openwall mailing list, demonstrating the exploitation of CVE-2023-32233. The impact of this vulnerability extends to multiple Linux kernel releases, including the current stable version 6.3.1. However, local access to a Linux device is required to exploit the flaw.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Linux Kernel Patch Addresses Critical Flaw as Researchers Prepare to Release Privilege Escalation ExploitIn response to the issue, engineer Pablo Neira Ayuso submitted a Linux kernel source code commit to address the problem. This commit introduces two functions that manage the lifecycle of anonymous sets in the Netfilter nf_tables subsystem. By appropriately managing the activation and deactivation of anonymous sets and preventing further updates, the fix prevents memory corruption and the possibility of attackers leveraging the use-after-free issue to escalate privileges to root level.

Security researchers Patryk Sondej and Piotr Krysiuk, who discovered the flaw, reported it to the Linux kernel team and developed a PoC exploit that allows unprivileged local users to initiate a root shell on affected systems. The researchers shared the exploit privately with the Linux kernel team, aiding in the development of a fix and providing a detailed description of the employed exploitation techniques and the PoC’s source code.

The researchers plan to make the exploit public on Monday, May 15th, 2023, along with comprehensive details about the exploitation techniques. Following the linux-distros list policy, the exploit must be published within seven days from the advisory. This forthcoming publication aims to increase awareness and facilitate timely remediation efforts.
Trending: How to Exploit “improper error handling” in Web Applications Trending: Malware Analysis Tool: retoolkit Linux Kernel Vulnerability Highlights the Value of Root-Level Privileges for Threat ActorsWhile CVE-2023-32233 requires remote attackers to establish local access to a target system before exploitation, the significance lies in the fact that gaining root-level privileges on Linux servers is a coveted asset for threat actors. These actors often monitor platforms like Openwall for new security information to exploit in their attacks.
Trending: APT hacking group uses double DLL sideloading to bypass security Are u a security researcher? Or a company that writes articles or write ups about Cyb[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical Linux Kernel Flaw – Unprivileged Users Gain Root Control Critical Linux Kernel Flaw – Unprivileged Users Gain Root ControlPost Views: 171 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png…
er Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-2-300x150.png CACTUS Ransomware Exploits VPN Flaws to Infiltrate Corporate NetworksMay 9, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-1-300x150.png New Akira Ransomware Operation Hits Corporate NetworksMay 8, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-13-300x150.png North Korean Kimsuky Hacking Group Ups Their Game with New ‘ReconShark’ MalwareMay 5, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-12-300x150.png APT hacking group uses double DLL sideloading to bypass securityMay 4, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Critical Linux Kernel Flaw – Unprivileged Users Gain Root Control first appeared on Black Hat Ethical Hacking.
SpiderSuite - Advance Web Spider/Crawler For Cyber Security Professionals
http://www.kitploit.com/2023/05/spidersuite-advance-web-spidercrawler.html
An advance cross-platform and multi-feature GUI web spider/crawler for cyber (https://www.kitploit.com/search/label/Cyber) security proffesionals. Spider (https://www.kitploit.com/search/label/Spider) Suite can be used for attack surface mapping and analysis. For more information visit SpiderSuite's website (https://spidersuite.github.io/).