Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
PDF Feature ‘Certified’ Widely Vulnerable to Attack

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg PDF Feature ‘Certified’ Widely Vulnerable to AttackPost Views: 161
Reading Time: 1 Minute
Certified portable document format (PDF) files are used to securely sign agreements between two parties while keeping the contents’ integrity protected, but a new report found the security protections on most certified PDF applications were inadequate and left organizations exposed to a number of attacks.
Researchers from Ruhr University Bochum explained certified PDFs use two specific signatures to authenticate the document, an Approval signature and a Certification signature. Certification signatures are the more flexible and made to handle complicated agreements between multiple parties and allow some changes to the document within a set of parameters while still maintaining its validity.

Unsurprisingly, Certified signatures are where the team found vulnerabilities to two specific novel attacks they dubbed, “Evil Annotation” (EAA) and “Sneaky Signature” (SSA). Both allow an attacker to overlay malicious content (PDF) on top of the certified information without showing any signs it was altered. Novel Certified PDF Attacks EAAs display malicious content in the document’s annotations and then sends it on with its digital signature intact. SSAs add malicious content over legitimate content in the PDF itself.

The team said the results of its evaluation of the 26 most popular PDF applications were “alarming.”
See Also: Pulse Secure VPNs Get Quick Fix for Critical RCE “In only 2 cases, we could not find a vulnerability; 15 viewers were vulnerable to EAA, 8 to SSA, including Adobe, Foxit, and LibreOffice,” the report said. “We additionally analyzed the standard-compliant implementation of PDF certification applications and found issues in 11 of them.”

Adobe had an additional flaw that allowed certified documents to execute JavaScript code, opening these users to code in injection attacks.

https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/26161319/Evil-Annotation-PDF-Research_10-300x187.jpg “For example, a high-level JavaScript can call an arbitrary URL without user confirmation to deanonymize a user. Our research reveals that such code is also executed if it is added as an allowed incremental update. We are the first to reveal that this behavior allows attackers to directly embed malicious code into a certified document.

The team said it disclosed their findings to the appropriate vendors and provided a comprehensive vulnerability report, including exploits, to CERT-Bund (BSI). The report also lists the specific certified PDF security flaws found in each application.

“Adobe, Foxit, and LibreOffice responded quickly and provided patches for late 2020 (CVE-2020-35931) or early 2021 (CVE2021-28545, CVE-2021-28546),” the report said. “Adobe fixed the code injection vulnerability in early Nov. 2020 within a patch outside the regular update cycle (CVE-2020-24432). Currently, we participate in the standardization process via the German National Organization for Standardization (DIN) and the International Organization for Standardization (ISO) to address the reported attacks in the next PDF specification.”
See Also: Offensive Security Tool: Snallygaster Stopping Certified PDF AttacksTo fend off Evil Annotation Attacks, the researchers recommend admins prohibit three particularly risky annotations that allow text or images to be added to a certified PDF, “FreeText, Stamp and Redact.”

Sneaky Signatures can be blocked by reducing permissions, but that is not a guarantee SSAs won’t g[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
7 out of 10 businesses are not prepared to respond to a Cyber Attack

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 7 out of 10 businesses are not prepared to respond to a Cyber AttackPost Views: 83 https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Reading Time: 3 Minutes
Fact: 7 out of 10 businesses are not prepared to respond to a Cyber Attack.
73% of companies, based on a statistic made by Hiscox in the UK, US, Spain, Germany & Netherlands are just not prepared.
The overheads were ranging from lack of resources, budget, awareness, down to not testing their infrastructure how they would withstand an attack by simulating real-life attacks out of services like Penetration testing, Vulnerability assessments and Social Engineering Phishing attacks.
See Also: Fact: Hacking Has Evolved
As IT Spending is growing exponentially, for example, IoT devices are on the rise with over 87% of healthcare organizations implementing their usage for patient monitoring followed by remote operation and location services (Source: Aruba Networks). It is estimated that by the year 2025 an estimated 64 billion connected IoT devices will be taking place, including the 5G Network which started taking place in several countries.
A lot of attacks are affecting major vendors, which most of the industry relies on when they use their products. This not only puts your company in a vulnerable state for any criminal hacker to take advantage of, through the CVES (Common Vulnerabilities and Exposures) that are being released on a daily basis but also the lack of knowledge and time for the IT team to respond on time, to patch these vulnerabilities.
When it comes to data, storage is important yet not many spends on reliable storage solutions, however when a company suffers data loss, suddenly they want to implement a decent storage solution.
When it comes to a Cyber Attack, sometimes there is no second chance to recover. A projected 146 billion records will be exposed between 2020 and 2023 done through a study by Juniper predicting and calculating the number of actual breaches and not just the reported ones.
See Also: PDF Feature ‘Certified’ Widely Vulnerable to Attack
The world is changing, stay always one step ahead of criminal hackers by consulting with Red-Team-oriented Information Security awareness training and solutions. Recent Facts* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Hacking-has-Evolved-Fact_Website-Template-90x90.png Hacking has Evolved4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/You-cant-protect-what-you-cant-see-Fact_Website-Template-90x90.png You can’t protect what you can’t see2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/02/Fact_Website-Template-90x90.png Manual Pentesting is more Effective than the Automated3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/01/Fact_Website-Template-90x90.png 90% of the hacking process involves the Reconnaissance Phase5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/Website-90x90.png A Hacker needs only one loophole to hack any system.6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/10/Website_2-90x90.png Not all hackers are criminals7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/08/Website-90x90.png Human Intelligence is the best defense against Phishing Attacks9 months ago
* https://www.blackhatethicalhacking.co[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking PDF Feature ‘Certified’ Widely Vulnerable to Attack https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg PDF Feature ‘Certified’ Widely Vulnerable to AttackPost Views: 161 Reading…
et through. Defined signature fields offer an additional layer of protection, the report said.

“Signature fields must be set up at defined locations in the PDF document before the document is certified,” the report explained. “A subsequent addition of signature fields must be penalized with an invalid certification status. Otherwise, it can always be used to add text or images included in the signature at any position.”

Adobe JavaScript code injections are trickier since in most cases the execution starts the moment the document is opened. “The only requirement is that the victim fully trusts the certificate used to certify the PDF document,” the report said. See Also: Hacking Stories: Xbox UndergroundEarlier this month Adobe Acrobat issued a patch for a zero-day bug targeting Windows users. Just days later, researchers at Microsoft Security Intelligence (MSI) found PDFs were being used by attackers to deliver StrRAT Java-based remote access tool (RAT) used to steal credentials, log keystrokes and take remote control over infected systems.

The flexibility offered by Certified signatures presents a massive, potentially catastrophic, security risk for many organizations and the report urges PDF applications to work quickly to come up with wide-scale fixes.

“The research community has struggled with similar problems on other data formats, such as XML or Email, without finding a satisfying solution so far,” they said. “In the case of PDF, the specification must be updated to address these issues.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/vulnerability-e1621953424713-90x90.jpg Pulse Secure VPNs Get Quick Fix for Critical RCE2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-5-90x90.png 100M Android Users Hit By Rampant Cloud Leaks3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-3-2-90x90.png WP Statistics Bug Allows Attackers to Lift Data from WordPress Sites4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-4-90x90.png Windows PoC Exploit Released for Wormable RCE7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-3-1-90x90.png Microsoft, Google Clouds Hijacked for Gobs of Phishing1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-2-2-90x90.png Microsoft, Adobe Exploits Top List of Crooks’ Wish List1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-3-90x90.png Bizarro Banking Trojan Sports Sophisticated Backdoor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Safari_Browser-90x90.jpg ‘Scheme Flooding’ Allows Websites to Track Users Across Browsers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Mac-Malware-90x90.jpg Apple’s ‘Find My’ Network Exploited via Bluetooth2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-2-1-90x90.png GitHub Prepares to Move Beyond Passwords2 weeks ago
The post PDF Feature ‘Certified’ Widely Vulnerable to Attack first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking 7 out of 10 businesses are not prepared to respond to a Cyber Attack https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg 7 out of 10 businesses are not prepared to respond to a Cyber…
m/wp-content/uploads/2020/07/Website-90x90.png Firewalls are no longer enough10 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/06/Website-90x90.png Your Data in the Cloud is not as secure as you think12 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2020/05/Website-90x90.png The Weakest Link in a Security Chain is the Human Element12 months ago
The post 7 out of 10 businesses are not prepared to respond to a Cyber Attack first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Dystopia - Low To Medium Multithreaded Ubuntu Core Honeypot Coded In Python

Low to medium Ubuntu Core honeypot coded in Python.Features Optional Login Prompt Logs commands used and IP addresses Customize MOTD, Port, Hostname and how many clients can connect at once (default is unlimited) Save and load config Add support to a plethora of commands Todo Packet Capture Better Logging Service Geolocation Email Alerts Insights such as charts & graphs Add Default Configurations Optimize / Fix Code How to run sudo apt update && sudo apt upgrade -ypython3 dystopy.py Command Line Arguments bind to --motd MOTD, -m MOTD specify the message of the day --max MAX, -M MAX max number of clients allowed to be connected at once. --username USERNAME, -u USERNAME username for fake login prompt and the user for the honeypot session --password PASSWORD, -p PASSWORD password for fake login prompt --hostname HOSTNAME, -H HOSTNAME hostname of the honeypot --localhost, -L host honeypot on localhost --save SAVE, -s SAVE save config to a json file --load LOAD, -l LOAD load a config file ">usage: dystopia.py -h --port PORT --motd MOTD --max MAX --username USERNAME --password PASSWORD --hostname HOSTNAME --localhost --save SAVE --load LOADDystopia | A python honeypot.optional arguments: -h, --help show this help message and exit --port PORT, -P PORT specify a port to bind to --motd MOTD, -m MOTD specify the message of the day --max MAX, -M MAX max number of clients allowed to be connected at once. --username USERNAME, -u USERNAME username for fake login prompt and the user for the honeypot session --password PASSWORD, -p PASSWORD password for fake login prompt --hostname HOSTNAME, -H HOSTNAME hostname of the honeypot --localhost, -L host honeypot on localhost --save SAVE, -s SAVE save config to a json file --load LOAD, -l LOAD load a config file How to add Support for More Commands You can add support to new commands by editing the file "commands.json". The format is command:output for eg { "dog":"Dog command activated!"} Download Dystopia
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Dystopia - Low To Medium Multithreaded Ubuntu Core Honeypot Coded In Python

https://1.bp.blogspot.com/-b1YvC5Wx6VA/YKrzpvt8E8I/AAAAAAAAWRQ/TTsDjKbXRPca4ePi0pnxFoMn1m3i-MV-ACNcBGAsYHQ/w640-h338/dystopia_1_preview.png
Low to medium Ubuntu Core honeypot coded in Python.
Features

* Optional Login Prompt
* Logs commands used and IP addresses
* Customize MOTD, Port, Hostname and how many clients can connect at once (default is unlimited)
* Save and load config
* Add support to a plethora of commands

Todo

* Packet Capture
* Better Logging
* Service
* Geolocation
* Email Alerts
* Insights such as charts & graphs
* Add Default Configurations
* Optimize / Fix Code

How to run

sudo apt update && sudo apt upgrade -y
python3 dystopy.py


Command Line Arguments

bind to --motd MOTD, -m MOTD specify the message of the day --max MAX, -M MAX max number of clients allowed to be connected at once. --username USERNAME, -u USERNAME username for fake login prompt and the user for the honeypot session --password PASSWORD, -p PASSWORD password for fake login prompt --hostname HOSTNAME, -H HOSTNAME hostname of the honeypot --localhost, -L host honeypot on localhost --save SAVE, -s SAVE save config to a json file --load LOAD, -l LOAD load a config file ">usage: dystopia.py [-h] [--port PORT] [--motd MOTD] [--max MAX] [--username USERNAME] [--password PASSWORD]
[--hostname HOSTNAME] [--localhost] [--save SAVE] [--load LOAD]

Dystopia | A python honeypot.

optional arguments:
-h, --help show this help message and exit
--port PORT, -P PORT specify a port to bind to
--motd MOTD, -m MOTD specify the message of the day
--max MAX, -M MAX max number of clients allowed to be connected at once.
--username USERNAME, -u USERNAME
username for fake login prompt and the user for the honeypot session
--password PASSWORD, -p PASSWORD
password for fake login prompt
--hostname HOSTNAME, -H HOSTNAME
hostname of the honeypot
--localhost, -L host honeypot on localhost
--save SAVE, -s SAVE save config to a json file
--load LOAD, -l LOAD load a config file


How to add Support for More Commands

You can add support to new commands by editing the file "commands.json". The format is command:output
for eg
{
"dog":"Dog command activated!"
}

https://1.bp.blogspot.com/-JOGjawxO7Wc/YKrzuP2NTVI/AAAAAAAAWRU/yWlzXSdmuDwgofnEAftwnXFuWW4TzkdNQCNcBGAsYHQ/s0/dystopia_2_dog.png
Download Dystopia

___________________________
@hacking_Attack
@Hacking_Video
How to find IDOR (for beginners)

Hello super ethical hackers and bug bounty hunters. I hope you are well in this pandemicContinue reading on Medium »
Read more...
16 year old wants to be a pen-tester
https://www.reddit.com/r/Pentesting/comments/nmjsfz/16_year_old_wants_to_be_a_pentester/

Hello, My name is Joel, And I would like to ask what are some ways or steps I should take to get into the IT industry to set me up to be a pen-tester in the future. I have already started to gain some skills but, I am not sure if it will be enough to get employed. Especially since I'm a minor (16) :/. However, I still want to try but not sure how to go about it. ​ Some of my qualifications: ​ A cybersecurity student at the University of Miami Currently studying for my A+ and shortly my Network+ Basic IT skills Basic knowledge of Computer Networking Basic knowledge of Linux Basic coding skills ​ Its all on my Linkedin account: https://www.linkedin.com/in/joel-jiron-20a912212/ ​ At the moment, I would prefer to get a full-time job during the summer. Then, I would sadly have to continue with high school and go part-time. Any and all advice helps. Recommended Agency(Florida)? Recommended entry Job positions? recommended certs? Thanks! :) submitted by /u/IForGotMyName_ (https://www.reddit.com/user/IForGotMyName_)
[link] (https://www.reddit.com/r/Pentesting/comments/nmjsfz/16_year_old_wants_to_be_a_pentester/) [comments] (https://www.reddit.com/r/Pentesting/comments/nmjsfz/16_year_old_wants_to_be_a_pentester/)

___________________________
@hacking_Attack
@Hacking_Video