Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hackers discovered how to use chat GPT for their own selfish purposes using it as a tool to steal confidential data and extort millions of…Continue reading on Medium » (https://medium.com/@stylishcollection666/how-hackers-are-stealing-millions-using-chatgpt-e7cf889ffb85?source=rss------bug_bounty-5)
Welcome to Cybernews. Today, we bring you a thrilling cybercrime story surrounding the infamous Conti ransomware gang. This sophisticated…Continue reading on Medium » (https://medium.com/@stylishcollection666/secret-chat-leak-exposed-russian-hackers-conti-explained-7f4da6f4c0e?source=rss------bug_bounty-5)
I understand your intention to educate people about the dark web and its potential dangers. It’s important to raise awareness about these…Continue reading on Medium » (https://medium.com/@stylishcollection666/ethical-hacker-in-the-world-explains-the-dark-web-d8c11a42d48c?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data

Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive DataPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Google’s renowned security researcher Tavis Ormandy has uncovered a significant vulnerability called Zenbleed affecting AMD Zen2 CPUs, posing a serious risk of data theft. The flaw, tracked as CVE-2023-20593, allows malicious actors to pilfer sensitive information, including passwords and encryption keys, at an alarming rate of 30KB/sec from each CPU core.

The root cause of this vulnerability lies in the improper handling of the ‘vzeroupper’ instruction during speculative execution, a widely-used performance-enhancing technique employed in modern processors.

Ormandy employed fuzzing and performance counters to identify specific hardware events, validating his findings using the “Oracle Serialization” approach. This method enabled the detection of inconsistencies between the execution of a randomly generated program and its serialized oracle, leading to the discovery of CVE-2023-20593 in Zen2 CPUs.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Zenbleed PoCWith an optimized exploit for the flaw, the researcher successfully demonstrated how sensitive data from various system operations, including those within virtual machines, isolated sandboxes, and containers, could be leaked.

“I found a variant that can leak about 30 kb per core, per second. This is fast enough to monitor encryption keys and passwords as users login!,” elaborated Ormandy in a technical write-up.

After notifying AMD about the flaw on May 15, 2023, the researcher has now published a proof-of-concept (PoC) exploit for CVE-2023-20593, impacting all operating systems running on Zen 2 CPUs.
First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! https://t.co/NVPWFpVopz pic.twitter.com/HgKwu9w8Av

— Tavis Ormandy (@taviso) July 24, 2023
The vulnerability affects numerous AMD CPUs built on the Zen 2 architecture, including Ryzen 3000 (“Matisse”), Ryzen 4000U/H (“Renoir”), Ryzen 5000U (“Lucienne”), Ryzen 7020, and high-end ThreadRipper 3000 and Epyc server (“Rome”) processors.

AMD has released an updated microcode to address the issue, and users are strongly advised to apply the fix or await BIOS upgrades from their computer vendors.

Trending: Unlocking Windows System Resource Utilization for Digital Forensics Analysis with SRUM Dump Trending: Digital Forensics Tool: ScrapPy
Ormandy suggests an alternative mitigation method involving setting the “chicken bit” to DE_CFG[9], though this may lead to a drop in CPU performance.

Detection of exploitation is challenging, as the improper usage of ‘vzeroupper’ does not require elevated privileges or special system calls, making the Zenbleed exploit stealthy and potentially hard to trace.

For regular users, the practical impact of Zenbleed is relatively low, as exploiting it requires local access to the target system and a high level of expertise. Nonetheless, maintaining up-to-date systems with the latest security patches and BIOS updates is crucial to mitigate potential risks.
Trending: WormGPT: Unleashing the Dark Side of Generative AI for Cybercrime
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sh[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive DataPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-c…
aring?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Copy-of-Images-for-the-News-posts-300x150.png HotRat Malware -The Sneaky Trojan Lurking in Cracked SoftwareJuly 24, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-12-300x150.png New P2PInfect Malware, Self-Spreading Worm Targets Redis Instances on Internet-Exposed SystemsJuly 21, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-11-300x150.png DeliveryCheck: Turla’s New Cyberweapon Strikes Microsoft Exchange Servers and Defense SectorJuly 20, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-10-300x150.png WormGPT: Unleashing the Dark Side of Generative AI for CybercrimeJuly 19, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bounty Hackers CTF by Try Hack Me

https://cdn-images-1.medium.com/max/1200/1*1mtQwkgfzGNK8xB5RxWY5A.jpeg
Are you ready to embark on an exhilarating virtual journey as a bounty Hacker? So, gear up, grab your cyber tools, and let’s get started!

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Wallet-Transaction-Monitor - This Script Monitors A Bitcoin Wallet Address And Notifies The User When There Are Changes In The Balance Or New Transactions

https://blogger.googleusercontent.com/img/a/AVvXsEhuDeLU636d0AjcBrP67ciRyE7X4uNUHsXUhuPHyuNxn-5S1sjYT5n5bp2IRlL-FJMNsINf5XWHpKlcTDBb_tVnLk6Vs354WrDWwz6ufwM0_XSMOGD5vVOMdR1yaU33XijgswR-QWlY8LwA2nXrrZmDotvQGJmfdRg4rGdlLmPYkGfDhhQYrYMTEszR6Wlj=w640-h356

This script monitors a Bitcoin wallet address and notifies the user when there are changes in the balance or new transactions. It provides real-time updates on incoming and outgoing transactions, along with the corresponding amounts and timestamps. Additionally, it can play a sound notification on Windows when a new transaction occurs.
Requirements

Python 3.x requests library: You can install it by running pip install requests. winsound module: This module is available by default on Windows.

How to Run

* Make sure you have Python 3.x installed on your system.
* pip install -r requirements.txt
* Clone or download the script file wallet_transaction_monitor.py from this repository.
* Place the sound file (in .wav format) you want to use for the notification in the same directory as the script. Make sure to replace "soundfile.wav" in the script with the actual filename of your sound file.
* Open a terminal or command prompt and navigate to the directory where the script is located.

* Run the script by executing the following command:

python wallet_transaction_monitor.py

The script will start monitoring the wallet and display updates whenever there are changes in the balance or new transactions. It will also play the specified sound notification on Windows.

Important Notes

This script is designed to work on Windows due to the use of the winsound module for sound notifications. If you are using a different operating system, you may need to modify the sound-related code or use an alternative method for audio notifications. The script uses the Blockchain.info API to fetch wallet data. Please ensure you have a stable internet connection for the script to work correctly. It's recommended to run the script in the background or keep the terminal window open while monitoring the wallet.
Download Wallet-Transaction-Monitor