Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.3K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
The attacker gets all the user ids from the store URL and one by one he can get all the sensitive information of the users.Continue reading on Medium » (https://sahildari.medium.com/finding-a-unique-kind-of-idor-df22374605f6?source=rss------bug_bounty-5)
Тема статьи — как мы можем обойти запрос на ограничение скорости с которым мы часто сталкиваемся из-за фаззинга.Continue reading on Medium » (https://gebutcher.medium.com/%D0%BE%D0%B1%D1%85%D0%BE%D0%B4-rate-limit%D0%B0-%D1%81-%D0%BF%D0%BE%D0%BC%D0%BE%D1%89%D1%8C%D1%8E-tor-c6021b333687?source=rss------bug_bounty-5)
wired attack?
https://www.reddit.com/r/Pentesting/comments/13razmj/wired_attack/

<!-- SC_OFF -->just wondering if there was a way to "upload" an exploit (not file) to a machine if u were connected to it via a 2 way usb or eth-cable to eth-cable(from my laptop to machine). by machine i don't mean a server system, more a computer or a CTV system that's connected to cameras via cable. if it is possible what tools would be able to execute something like this <!-- SC_ON --> submitted by /u/Realistic-Archer-793 (https://www.reddit.com/user/Realistic-Archer-793)
[link] (https://www.reddit.com/r/Pentesting/comments/13razmj/wired_attack/) [comments] (https://www.reddit.com/r/Pentesting/comments/13razmj/wired_attack/)
Black Hat Ethical Hacking
Hackers Use New PowerExchange Malware to Target Microsoft Exchange Servers

Hackers Use New PowerExchange Malware to Target Microsoft Exchange ServersPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
FortiGuard Labs Threat Research team has recently uncovered a highly sophisticated and alarming cyber threat: a new PowerShell-based malware named PowerExchange. This malware has been utilized by the notorious Iranian state-backed hacking group known as APT34 or Oilrig. Their primary target? On-premise Microsoft Exchange servers, which are widely used by organizations for email communication.

The attack vector employed by APT34 involves luring unsuspecting victims through phishing emails. These emails contain an archived malicious executable that, when executed, allows the threat actors to gain unauthorized access to the targeted mail server. Once inside, they deploy a web shell called ExchangeLeech, which was first identified by the Digital14 Incident Response team back in 2020. This web shell operates stealthily in the background, enabling the hackers to steal crucial user credentials.

What sets PowerExchange apart from other malware is its unique communication method with a command-and-control (C2) server. Unlike traditional malware that relies on direct network connections, PowerExchange communicates via emails using the Exchange Web Services (EWS) API. The malware sends stolen information and receives base64-encoded commands through text attachments within emails that have the subject line “Update Microsoft Edge.” By utilizing the victim’s Exchange server as the C2 channel, the backdoor can effectively blend in with benign network traffic, making it extremely difficult to detect and remediate by network-based security measures.

https://www.bleepstatic.com/images/news/u/1109292/2023/PowerExchange_infection_chain.png PowerExchange infection chain (FortiGuard Labs)
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses PowerExchange Malware – Advanced Tool for Remote Control and Data TheftOnce the hackers have established control over the compromised servers, they have a wide range of capabilities at their disposal. PowerExchange allows them to execute commands remotely, delivering additional malicious payloads to the hacked servers and exfiltrating sensitive files from the victim’s network. Furthermore, during the forensic investigation conducted by FortiGuard Labs, additional backdoored endpoints with various other malicious implants were discovered, indicating a more extensive compromise.

FortiGuard Labs has drawn connections between the PowerExchange malware and APT34’s previous activities, specifically their use of TriFive malware to backdoor the servers of Kuwaiti government organizations. Both backdoors share significant similarities, such as being written in PowerShell, activation through a periodic scheduled task, and leveraging the organization’s Exchange server with the EWS API for C2 communication. While there are notable differences in the code, the researchers speculate that PowerExchange represents an evolved and improved form of TriFive.
Trending: Maximizing IDOR Detection with Burp Suite’s Autorize Trending: Recon Tool: Dome It’s worth noting that APT34 has a history of utilizing phishing emails as an initial infection vector and has previously breached various entities in the United Arab Emirates. The discovery of PowerExchange reinforces the group’s relentless pursuit of sophisticated cyberattacks and highlights the increasing need for robust security measures to protect critical infrastructure.[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers Use New PowerExchange Malware to Target Microsoft Exchange Servers Hackers Use New PowerExchange Malware to Target Microsoft Exchange ServersPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/…
The cybersecurity community and organizations utilizing Microsoft Exchange servers are urged to remain vigilant, implement strong security practices, and promptly apply relevant patches and updates to safeguard against evolving threats like PowerExchange.
Trending: Hackers Exploit Critical WordPress Plugin Vulnerability Within Hours of Public PoC Release Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-13-1-300x150.png AhRat Malware Strikes Again with Trojanized Screen Recording AppMay 24, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-12-1-300x150.png BlackCat Ransomware Evades Security Software with Signed Malicious Windows Kernel DriversMay 23, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-11-1-300x150.png BrutePrint Attack: Researchers Unveil New Technique to Bypass Smartphone Fingerprint AuthenticationMay 22, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-10-1-300x150.png WordPress Websites at Risk – Hackers Exploit Critical Flaw in Essential Addons for ElementorMay 19, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Hackers Use New PowerExchange Malware to Target Microsoft Exchange Servers first appeared on Black Hat Ethical Hacking.