Path to pentester from beginner
https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/
<!-- SC_OFF -->hi community. I am 17 years old. My goal is to become a pentester/ethical hacker. For this I am going to university in a year to start a bachelor's degree in computer science. I would like to know what I can do/learn in the meantime (while waiting for university) that will help me in my career. Learn python? linux? Tryhackme? <!-- SC_ON --> submitted by /u/Party-Elephant9287 (https://www.reddit.com/user/Party-Elephant9287)
[link] (https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/) [comments] (https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/)
https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/
<!-- SC_OFF -->hi community. I am 17 years old. My goal is to become a pentester/ethical hacker. For this I am going to university in a year to start a bachelor's degree in computer science. I would like to know what I can do/learn in the meantime (while waiting for university) that will help me in my career. Learn python? linux? Tryhackme? <!-- SC_ON --> submitted by /u/Party-Elephant9287 (https://www.reddit.com/user/Party-Elephant9287)
[link] (https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/) [comments] (https://www.reddit.com/r/Pentesting/comments/13krxic/path_to_pentester_from_beginner/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
The Alarming Rise of Malicious Extensions in Microsoft’s VSCode Marketplace
The Alarming Rise of Malicious Extensions in Microsoft’s VSCode MarketplacePost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Cybercriminals Target Microsoft’s VSCode MarketplaceCybercriminals have set their sights on Microsoft’s esteemed VSCode Marketplace, launching a series of insidious attacks by uploading three malicious Visual Studio extensions. Shockingly, these nefarious extensions managed to accumulate a staggering 46,600 downloads by unsuspecting Windows developers. The consequences of this breach, discovered by the diligent analysts at Check Point, are severe, as the malware embedded within the extensions enabled threat actors to pilfer vital credentials, exploit system vulnerabilities, and even establish a remote shell on victims’ machines.
Upon unearthing the malicious extensions, Check Point promptly alerted Microsoft, leading to their removal from the VSCode Marketplace on May 14, 2023, just ten days after the initial discovery on May 4. However, the aftermath of this cyberattack demands immediate action from developers who unwittingly installed these extensions. They must manually eliminate the malicious software from their systems and conduct thorough scans to detect any residual traces of infection.
The malicious extensions, exposed by Check Point researchers, shed light on the extent of the infiltration within the VSCode Marketplace. The most widespread among them was the deceptively named ‘Theme Darcula dark.’ Initially presented as an innocent enhancement for the Dracula color scheme on VS Code, this extension cunningly collected essential system information from developers, including hostname, operating system details, CPU platform specifications, total memory, and CPU information. Although devoid of overtly malicious activities, this unconventional behavior for a theme pack raised red flags. Astonishingly, ‘Theme Darcula dark’ amassed over 45,000 downloads, making it the most circulated extension in this illicit campaign.
https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/darcula.png Darcula extension on the VSCode Marketplace (Check Point)
Another malicious extension, ‘python-vscode,’ attracted attention despite its enigmatic description and uploaded by an account named ‘testUseracc1111.’ With 1,384 downloads, this seemingly innocuous extension concealed a perilous secret. Further analysis uncovered its true nature as a C# shell injector, capable of executing arbitrary code or commands on compromised machines, effectively granting unauthorized control to threat actors.
https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/inject-snippet.png Obfuscated C# code injector (Check Point)
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
Similarly, the extension named ‘prettiest java,’ mimicking the popular code formatting tool ‘prettier-java,’ deceived 278 unsuspecting users. Beneath its façade, this extension engaged in the malicious act of stealing saved credentials and authentication tokens from Discord, Discord Canary, Google Chrome, Opera, Brave Browser, and Yandex Browser. The stolen information was surreptitiously transmitted to the attackers via a Discord webhook, enabling them to exploit compromised accounts for their malicious purposes.
https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/local-scan.png Searching for local secrets (Check Point)
In addition to the identified malicious extensions, Check Point also discovered numerous suspicious extensions exhibiting unsafe[...]
The Alarming Rise of Malicious Extensions in Microsoft’s VSCode Marketplace
The Alarming Rise of Malicious Extensions in Microsoft’s VSCode MarketplacePost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Cybercriminals Target Microsoft’s VSCode MarketplaceCybercriminals have set their sights on Microsoft’s esteemed VSCode Marketplace, launching a series of insidious attacks by uploading three malicious Visual Studio extensions. Shockingly, these nefarious extensions managed to accumulate a staggering 46,600 downloads by unsuspecting Windows developers. The consequences of this breach, discovered by the diligent analysts at Check Point, are severe, as the malware embedded within the extensions enabled threat actors to pilfer vital credentials, exploit system vulnerabilities, and even establish a remote shell on victims’ machines.
Upon unearthing the malicious extensions, Check Point promptly alerted Microsoft, leading to their removal from the VSCode Marketplace on May 14, 2023, just ten days after the initial discovery on May 4. However, the aftermath of this cyberattack demands immediate action from developers who unwittingly installed these extensions. They must manually eliminate the malicious software from their systems and conduct thorough scans to detect any residual traces of infection.
The malicious extensions, exposed by Check Point researchers, shed light on the extent of the infiltration within the VSCode Marketplace. The most widespread among them was the deceptively named ‘Theme Darcula dark.’ Initially presented as an innocent enhancement for the Dracula color scheme on VS Code, this extension cunningly collected essential system information from developers, including hostname, operating system details, CPU platform specifications, total memory, and CPU information. Although devoid of overtly malicious activities, this unconventional behavior for a theme pack raised red flags. Astonishingly, ‘Theme Darcula dark’ amassed over 45,000 downloads, making it the most circulated extension in this illicit campaign.
https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/darcula.png Darcula extension on the VSCode Marketplace (Check Point)
Another malicious extension, ‘python-vscode,’ attracted attention despite its enigmatic description and uploaded by an account named ‘testUseracc1111.’ With 1,384 downloads, this seemingly innocuous extension concealed a perilous secret. Further analysis uncovered its true nature as a C# shell injector, capable of executing arbitrary code or commands on compromised machines, effectively granting unauthorized control to threat actors.
https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/inject-snippet.png Obfuscated C# code injector (Check Point)
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
Similarly, the extension named ‘prettiest java,’ mimicking the popular code formatting tool ‘prettier-java,’ deceived 278 unsuspecting users. Beneath its façade, this extension engaged in the malicious act of stealing saved credentials and authentication tokens from Discord, Discord Canary, Google Chrome, Opera, Brave Browser, and Yandex Browser. The stolen information was surreptitiously transmitted to the attackers via a Discord webhook, enabling them to exploit compromised accounts for their malicious purposes.
https://www.bleepstatic.com/images/news/u/1220909/2023/PyPI/7/local-scan.png Searching for local secrets (Check Point)
In addition to the identified malicious extensions, Check Point also discovered numerous suspicious extensions exhibiting unsafe[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking The Alarming Rise of Malicious Extensions in Microsoft’s VSCode Marketplace The Alarming Rise of Malicious Extensions in Microsoft’s VSCode MarketplacePost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-conten…
behaviors, such as unauthorized access to code from private repositories or downloading files without proper authorization. While these extensions could not be definitively classified as malicious, their actions raised concerns about potential security risks, emphasizing the need for heightened vigilance within software development environments.
This incident underscores the inherent risks associated with user-supported repositories, exemplified by the VSCode Marketplace. While software repositories that allow user contributions, such as NPM and PyPi, have long been targeted by threat actors, the VSCode Marketplace is now experiencing a similar onslaught. A previous demonstration by AquaSec in January revealed the ease with which malicious extensions could be uploaded to the VSCode Marketplace, presenting a series of highly suspicious cases. Although no malware was found during AquaSec’s investigation, the recent discoveries by Check Point substantiate the emergence of a disturbing trend. Threat actors are actively seeking to infect Windows developers by infiltrating reputable software repositories, mirroring their strategies in repositories like NPM and PyPI.
Trending: Maximizing IDOR Detection with Burp Suite’s Autorize Trending: OSINT Tool: GooFuzz Secure Coding PracticesAs a precautionary measure, all users of the VSCode Marketplace, as well as other user-supported repositories, are strongly advised to exercise utmost caution. Only install extensions from trustworthy publishers with significant downloads and positive community ratings. Engage in diligent research by reading user reviews to gauge the reliability and safety of extensions. Most importantly, it is imperative to conduct a thorough inspection of an extension’s source code before installation, ensuring transparency and mitigating potential security risks.
In a digital landscape fraught with evolving threats, the security and well-being of developers and their projects hinge on their ability to remain steadfast, proactive, and informed. By adopting stringent security practices and cultivating a culture of attentiveness, the software development community can fortify its defenses against malicious infiltrations and forge a safer environment for innovation and collaboration.
Trending: CACTUS Ransomware Exploits VPN Flaws to Infiltrate Corporate Networks
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-8-300x150.png Camaro Dragon – Chinese State-Sponsored Hackers Target European Organizations via Infected TP-Link RoutersMay 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-7-300x150.png New MichaelKors Ransomware Takes Aim at Linux and VMware ESXiMay 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-6-300x150.png Hackers Exploit Critical WordPress Plugin Vulnerability Within Hours of Public PoC ReleaseMay 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-5-300x150.png Microsoft’s Urgent Fix: Bypassing Recent Patches for Critical Outlook Zero-Day Exploited in the WildMay 12, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help yo[...]
This incident underscores the inherent risks associated with user-supported repositories, exemplified by the VSCode Marketplace. While software repositories that allow user contributions, such as NPM and PyPi, have long been targeted by threat actors, the VSCode Marketplace is now experiencing a similar onslaught. A previous demonstration by AquaSec in January revealed the ease with which malicious extensions could be uploaded to the VSCode Marketplace, presenting a series of highly suspicious cases. Although no malware was found during AquaSec’s investigation, the recent discoveries by Check Point substantiate the emergence of a disturbing trend. Threat actors are actively seeking to infect Windows developers by infiltrating reputable software repositories, mirroring their strategies in repositories like NPM and PyPI.
Trending: Maximizing IDOR Detection with Burp Suite’s Autorize Trending: OSINT Tool: GooFuzz Secure Coding PracticesAs a precautionary measure, all users of the VSCode Marketplace, as well as other user-supported repositories, are strongly advised to exercise utmost caution. Only install extensions from trustworthy publishers with significant downloads and positive community ratings. Engage in diligent research by reading user reviews to gauge the reliability and safety of extensions. Most importantly, it is imperative to conduct a thorough inspection of an extension’s source code before installation, ensuring transparency and mitigating potential security risks.
In a digital landscape fraught with evolving threats, the security and well-being of developers and their projects hinge on their ability to remain steadfast, proactive, and informed. By adopting stringent security practices and cultivating a culture of attentiveness, the software development community can fortify its defenses against malicious infiltrations and forge a safer environment for innovation and collaboration.
Trending: CACTUS Ransomware Exploits VPN Flaws to Infiltrate Corporate Networks
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-8-300x150.png Camaro Dragon – Chinese State-Sponsored Hackers Target European Organizations via Infected TP-Link RoutersMay 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-7-300x150.png New MichaelKors Ransomware Takes Aim at Linux and VMware ESXiMay 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-6-300x150.png Hackers Exploit Critical WordPress Plugin Vulnerability Within Hours of Public PoC ReleaseMay 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-5-300x150.png Microsoft’s Urgent Fix: Bypassing Recent Patches for Critical Outlook Zero-Day Exploited in the WildMay 12, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help yo[...]
Hacking Articles Tips Tricks Videos Tutorials
behaviors, such as unauthorized access to code from private repositories or downloading files without proper authorization. While these extensions could not be definitively classified as malicious, their actions raised concerns about potential security risks…
u.
https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-5-300x159-1.png
The post The Alarming Rise of Malicious Extensions in Microsoft’s VSCode Marketplace first appeared on Black Hat Ethical Hacking.
https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-5-300x159-1.png
The post The Alarming Rise of Malicious Extensions in Microsoft’s VSCode Marketplace first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Do fast food surveys track your up address?
Do fast food surveys such as “mybkexperience” for instance track your up address? If so what do they do with it? What if you make 100 surveys will they know it’s all you?
submitted by /u/Btuflmess
[link] [comments]
Do fast food surveys track your up address?
Do fast food surveys such as “mybkexperience” for instance track your up address? If so what do they do with it? What if you make 100 surveys will they know it’s all you?
submitted by /u/Btuflmess
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Twitter
If anyone knows how to get me out of permanent suspension on Twitter that would be amazing because I miss Twitter and I was wrongly banned 😭
submitted by /u/SamaraPrescott
[link] [comments]
If anyone knows how to get me out of permanent suspension on Twitter that would be amazing because I miss Twitter and I was wrongly banned 😭
submitted by /u/SamaraPrescott
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How and what tools are used to identify common attack vectors such as memory corruption vulnerabilities and remote code execution attacks?
Based on a series of post regarding numerous remote code execution vulnerabilities in Cisco Routers via their Web application and a buffer overflow from unsanitized input field in a IoT device got me thinking.
Such devices often contain large amounts of codes and manually testing each input field combination surely must take large amount of resources? This cannot be the method used for finding and identifiy these exploits?
So that leads me to my question.
How are such exploits found?
Is it just end-users causing their devices to crash, researches spending hours upon hours looking over each line of the source code(if available?), or do professionals resort to using automated tools and if so, what could examples of these tools be and what are such techniques called?
submitted by /u/FruerlundF
[link] [comments]
How and what tools are used to identify common attack vectors such as memory corruption vulnerabilities and remote code execution attacks?
Based on a series of post regarding numerous remote code execution vulnerabilities in Cisco Routers via their Web application and a buffer overflow from unsanitized input field in a IoT device got me thinking.
Such devices often contain large amounts of codes and manually testing each input field combination surely must take large amount of resources? This cannot be the method used for finding and identifiy these exploits?
So that leads me to my question.
How are such exploits found?
Is it just end-users causing their devices to crash, researches spending hours upon hours looking over each line of the source code(if available?), or do professionals resort to using automated tools and if so, what could examples of these tools be and what are such techniques called?
submitted by /u/FruerlundF
[link] [comments]
Stored Iframe Injection & Permanent Open Redirection - Zero Day
https://shahjerry33.medium.com/stored-iframe-injection-permanent-open-redirection-zero-day-ce7cd15903ac?source=rss------bug_bounty-5
https://shahjerry33.medium.com/stored-iframe-injection-permanent-open-redirection-zero-day-ce7cd15903ac?source=rss------bug_bounty-5
SummaryContinue reading on Medium » (https://shahjerry33.medium.com/stored-iframe-injection-permanent-open-redirection-zero-day-ce7cd15903ac?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cyber security world at Hacker Bro Technologies.
Attention cyber security enthusiasts! Elevate your expertise and stay ahead in the ever-evolving cyber security world at Hacker Bro…
Continue reading on Medium »
Cyber security world at Hacker Bro Technologies.
Attention cyber security enthusiasts! Elevate your expertise and stay ahead in the ever-evolving cyber security world at Hacker Bro…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Live Cyber Attack Map Global
https://cdn-images-1.medium.com/max/1556/1*qamCUBhedW_o7saxqxEfEw.png
When it comes to real-time cyber-attack maps, some are funny, some seem ominous, and all of them tell a story that words alone cannot…
Continue reading on Medium »
Live Cyber Attack Map Global
https://cdn-images-1.medium.com/max/1556/1*qamCUBhedW_o7saxqxEfEw.png
When it comes to real-time cyber-attack maps, some are funny, some seem ominous, and all of them tell a story that words alone cannot…
Continue reading on Medium »