Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What to do with hacked Nintendo 3DS?

So, not too long ago, around 5 months or so, I discovered that you can hack your Nintendo 3ds to play videogames that aren't even in the software, and have your own costume themes. Now, this is a I could basically do with it, and it was a weird process to get it to work, all in all, it was fantastic. But now my question is, what can I do with it now?

Can I download TikTok? Can I use Snapchat? Can I use Reddit? Can I even use Discord?

Someone tell me what can I really do now since now my Nintendo 3ds is technical 'jailbroken.'

submitted by /u/Iker8556
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How does good ol max from Bulgaria hack any social media account for 200$?

There is no way he would try to phish for every one of his clients’ target.

Does he search for the targets name in leaked lists? But not everyone is on that list

Does he try to brute force the accounts? That must take ages if he has more than one client

Is it a mix of all the above?

submitted by /u/CONSTIPATED_CAT
[link] [comments]
Hello everyone, in this article I’m going to share with you how can I found Blind OS Command Injection vulnerability via account…Continue reading on Medium » (https://medium.com/@alb-soul/blind-os-command-injection-via-activation-request-66dc25377bf4?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploiting IAM security Misconfigurations — Part 1

https://cdn-images-1.medium.com/max/1102/0*pHOW8VNWpvOC4DEt
As more and more companies move their operations to the cloud, security has become a significant concern for cloud service providers like…

Continue reading on Appsecco »
Learn about and use Hydra, a fast network logon cracker, to brute force and obtain a website’s credentials.Continue reading on Medium » (https://medium.com/@kawsaruddin238/hydra-tryhackme-abf1193f4516?source=rss------bug_bounty-5)
Path to pentester from beginner
https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/

<!-- SC_OFF -->hi community. I am 17 years old. My goal is to become a pentester/ethical hacker. For this I am going to university in a year to start a bachelor's degree in computer science. I would like to know what I can do/learn in the meantime (while waiting for university) that will help me in my career. Learn python? linux? Tryhackme? <!-- SC_ON --> submitted by /u/Party-Elephant9287 (https://www.reddit.com/user/Party-Elephant9287)
[link] (https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/) [comments] (https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
The Alarming Rise of Malicious Extensions in Microsoft’s VSCode Marketplace

The Alarming Rise of Malicious Extensions in Microsoft’s VSCode MarketplacePost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Cybercriminals Target Microsoft’s VSCode MarketplaceCybercriminals have set their sights on Microsoft’s esteemed VSCode Marketplace, launching a series of insidious attacks by uploading three malicious Visual Studio extensions. Shockingly, these nefarious extensions managed to accumulate a staggering 46,600 downloads by unsuspecting Windows developers. The consequences of this breach, discovered by the diligent analysts at Check Point, are severe, as the malware embedded within the extensions enabled threat actors to pilfer vital credentials, exploit system vulnerabilities, and even establish a remote shell on victims’ machines.

Upon unearthing the malicious extensions, Check Point promptly alerted Microsoft, leading to their removal from the VSCode Marketplace on May 14, 2023, just ten days after the initial discovery on May 4. However, the aftermath of this cyberattack demands immediate action from developers who unwittingly installed these extensions. They must manually eliminate the malicious software from their systems and conduct thorough scans to detect any residual traces of infection.

The malicious extensions, exposed by Check Point researchers, shed light on the extent of the infiltration within the VSCode Marketplace. The most widespread among them was the deceptively named ‘Theme Darcula dark.’ Initially presented as an innocent enhancement for the Dracula color scheme on VS Code, this extension cunningly collected essential system information from developers, including hostname, operating system details, CPU platform specifications, total memory, and CPU information. Although devoid of overtly malicious activities, this unconventional behavior for a theme pack raised red flags. Astonishingly, ‘Theme Darcula dark’ amassed over 45,000 downloads, making it the most circulated extension in this illicit campaign.

https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/darcula.png Darcula extension on the VSCode Marketplace (Check Point)

Another malicious extension, ‘python-vscode,’ attracted attention despite its enigmatic description and uploaded by an account named ‘testUseracc1111.’ With 1,384 downloads, this seemingly innocuous extension concealed a perilous secret. Further analysis uncovered its true nature as a C# shell injector, capable of executing arbitrary code or commands on compromised machines, effectively granting unauthorized control to threat actors.

https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/inject-snippet.png Obfuscated C# code injector (Check Point)
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
Similarly, the extension named ‘prettiest java,’ mimicking the popular code formatting tool ‘prettier-java,’ deceived 278 unsuspecting users. Beneath its façade, this extension engaged in the malicious act of stealing saved credentials and authentication tokens from Discord, Discord Canary, Google Chrome, Opera, Brave Browser, and Yandex Browser. The stolen information was surreptitiously transmitted to the attackers via a Discord webhook, enabling them to exploit compromised accounts for their malicious purposes.

https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/local-scan.png Searching for local secrets (Check Point)

In addition to the identified malicious extensions, Check Point also discovered numerous suspicious extensions exhibiting unsafe[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking The Alarming Rise of Malicious Extensions in Microsoft’s VSCode Marketplace The Alarming Rise of Malicious Extensions in Microsoft’s VSCode MarketplacePost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-conten…
behaviors, such as unauthorized access to code from private repositories or downloading files without proper authorization. While these extensions could not be definitively classified as malicious, their actions raised concerns about potential security risks, emphasizing the need for heightened vigilance within software development environments.

This incident underscores the inherent risks associated with user-supported repositories, exemplified by the VSCode Marketplace. While software repositories that allow user contributions, such as NPM and PyPi, have long been targeted by threat actors, the VSCode Marketplace is now experiencing a similar onslaught. A previous demonstration by AquaSec in January revealed the ease with which malicious extensions could be uploaded to the VSCode Marketplace, presenting a series of highly suspicious cases. Although no malware was found during AquaSec’s investigation, the recent discoveries by Check Point substantiate the emergence of a disturbing trend. Threat actors are actively seeking to infect Windows developers by infiltrating reputable software repositories, mirroring their strategies in repositories like NPM and PyPI.
Trending: Maximizing IDOR Detection with Burp Suite’s Autorize Trending: OSINT Tool: GooFuzz Secure Coding PracticesAs a precautionary measure, all users of the VSCode Marketplace, as well as other user-supported repositories, are strongly advised to exercise utmost caution. Only install extensions from trustworthy publishers with significant downloads and positive community ratings. Engage in diligent research by reading user reviews to gauge the reliability and safety of extensions. Most importantly, it is imperative to conduct a thorough inspection of an extension’s source code before installation, ensuring transparency and mitigating potential security risks.

In a digital landscape fraught with evolving threats, the security and well-being of developers and their projects hinge on their ability to remain steadfast, proactive, and informed. By adopting stringent security practices and cultivating a culture of attentiveness, the software development community can fortify its defenses against malicious infiltrations and forge a safer environment for innovation and collaboration.
Trending: CACTUS Ransomware Exploits VPN Flaws to Infiltrate Corporate Networks
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-8-300x150.png Camaro Dragon – Chinese State-Sponsored Hackers Target European Organizations via Infected TP-Link RoutersMay 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-7-300x150.png New MichaelKors Ransomware Takes Aim at Linux and VMware ESXiMay 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-6-300x150.png Hackers Exploit Critical WordPress Plugin Vulnerability Within Hours of Public PoC ReleaseMay 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-5-300x150.png Microsoft’s Urgent Fix: Bypassing Recent Patches for Critical Outlook Zero-Day Exploited in the WildMay 12, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help yo[...]