hacking: security in practice
How to be as stealthy as possible?
So i would really love to exploit this weakness in my school. They have a wifi network that is strictly monitored for unauthorized logins and whatnot. I would actually say my school is very computer literate.
But here is the exploit, they have lent all the students laptops to use and take home throughout the year. So far the only thing I did was that I accidentally removed the bios password with the bios back door exploit that i found online. I thought this would only give you access to the bios without removing it completely...man did i not think that through.
But here is what i would like to do: since the bios is now unlocked, i would boot into a clean install from a separate drive that i have, use that clean install to create a clone of the laptop's ssd, and install that clone onto my personal laptop. That way, I could modify that build on my personal laptop to gain admin access. But here is my question, although the clone and all the files would be the same, would the mac address for when my personal laptop signs onto the network be the same as the school laptop? That is my first question.
And with admin access, all i would do would be to just set up a personal hotspot using the windows feature.
My second question is do you think that IT/administration will get me in trouble for removing the bios password (assuming I dont do anything else to the laptop)?
and are there any other stealthier ways to do this? I was thinking that in case IT finds out and calls me down to confiscate my belongings, I could quickly delete the vhd and get rid of the evidence.
Lastly, I would say that this would classify as grey hat hacking because I do not have malicious intent. Altho it may seem like im trying to bypass their network protections, i really wanna just see for myself what my knowledge can get me with computing. I am a "soy boy" lol so i would really hate to get in trouble...i also have a good reputation at school, is this risking too much? Thanks to anyone who read this essay post of mine.
submitted by /u/man_wif-waluigi-hed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to be as stealthy as possible?
So i would really love to exploit this weakness in my school. They have a wifi network that is strictly monitored for unauthorized logins and whatnot. I would actually say my school is very computer literate.
But here is the exploit, they have lent all the students laptops to use and take home throughout the year. So far the only thing I did was that I accidentally removed the bios password with the bios back door exploit that i found online. I thought this would only give you access to the bios without removing it completely...man did i not think that through.
But here is what i would like to do: since the bios is now unlocked, i would boot into a clean install from a separate drive that i have, use that clean install to create a clone of the laptop's ssd, and install that clone onto my personal laptop. That way, I could modify that build on my personal laptop to gain admin access. But here is my question, although the clone and all the files would be the same, would the mac address for when my personal laptop signs onto the network be the same as the school laptop? That is my first question.
And with admin access, all i would do would be to just set up a personal hotspot using the windows feature.
My second question is do you think that IT/administration will get me in trouble for removing the bios password (assuming I dont do anything else to the laptop)?
and are there any other stealthier ways to do this? I was thinking that in case IT finds out and calls me down to confiscate my belongings, I could quickly delete the vhd and get rid of the evidence.
Lastly, I would say that this would classify as grey hat hacking because I do not have malicious intent. Altho it may seem like im trying to bypass their network protections, i really wanna just see for myself what my knowledge can get me with computing. I am a "soy boy" lol so i would really hate to get in trouble...i also have a good reputation at school, is this risking too much? Thanks to anyone who read this essay post of mine.
submitted by /u/man_wif-waluigi-hed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/hacking - How to be as stealthy as possible?
0 votes and 0 comments so far on Reddit
hacking: security in practice
permanent website changes
So, say if I wanted to permanently change how a website that I don't own looked, for example: to just remove everything from the site. how would I go about doing this? and i mean permanently, so if I were to do this on one PC and then log in on a different PC it would still be the same. I would never use this to be malicious by the way I've set up a couple of my own test websites to do this with
submitted by /u/Captainzedog
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
permanent website changes
So, say if I wanted to permanently change how a website that I don't own looked, for example: to just remove everything from the site. how would I go about doing this? and i mean permanently, so if I were to do this on one PC and then log in on a different PC it would still be the same. I would never use this to be malicious by the way I've set up a couple of my own test websites to do this with
submitted by /u/Captainzedog
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/hacking - permanent website changes
0 votes and 1 comment so far on Reddit
hacking: security in practice
Purpose of a DoS/DDoS attack?
I apologize if this isn’t the right place for this but I am studying cyber security and have a basic question I can’t seem to find the answer to.
I know what a DoS/DDoS is and how they work, but I can’t seem to find an explanation of the purpose behind one. As in what benefit would the attacker gain from doing one? Would it be monetary gains (like asking for money to end an attack)? Or would it be more to harm a company/organization by limiting their ability to operate on some level? Or is there something deeper I am missing?
submitted by /u/bzboarder
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Purpose of a DoS/DDoS attack?
I apologize if this isn’t the right place for this but I am studying cyber security and have a basic question I can’t seem to find the answer to.
I know what a DoS/DDoS is and how they work, but I can’t seem to find an explanation of the purpose behind one. As in what benefit would the attacker gain from doing one? Would it be monetary gains (like asking for money to end an attack)? Or would it be more to harm a company/organization by limiting their ability to operate on some level? Or is there something deeper I am missing?
submitted by /u/bzboarder
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/hacking - Purpose of a DoS/DDoS attack?
0 votes and 0 comments so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A completely-free (as in free beer) hacking school
Hello everybody! I want to introduce a project a few people and I have been working in lately, its name is AnonWorld and it is meant to be a completely free (as in free beer, that is, free of charge) hacking and programming virtual school that is mainly maintained by hacktivists from the anonymous collective. It is pretty new - we have been working on this for less than one month - and it barely has content, there are two courses and there are going to be a lot of stuff other than just hacking, for example:
* Programming: from a beginner level to an advanced level - teaching low-level stuff such as operating system development.
* Hacking: learn hacking from real hackers, from people that are used to hack, this involves a lot of techniques, such as social engineering, anonymity, privacy, and so on.
* Computer science: learn how computers work, learn stuff like operating system and compilers design and - probably - a little course of implementation.
* Languages: yeah, why not, we are all from different parts of the world, we can teach the languages we all speak natively.
There's also a forum, so you can also learn from the other users of the platform, you can ask your questions there, you can start discussions and so much more.
If you want to check it, you can visit it with the following link: https://anonworld.eu
If you can support that would be so amazing, you can donate, you can be a teacher (you have to contact us and introduce yourself). Thank you for everything
submitted by /u/iSaraaah
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A completely-free (as in free beer) hacking school
Hello everybody! I want to introduce a project a few people and I have been working in lately, its name is AnonWorld and it is meant to be a completely free (as in free beer, that is, free of charge) hacking and programming virtual school that is mainly maintained by hacktivists from the anonymous collective. It is pretty new - we have been working on this for less than one month - and it barely has content, there are two courses and there are going to be a lot of stuff other than just hacking, for example:
* Programming: from a beginner level to an advanced level - teaching low-level stuff such as operating system development.
* Hacking: learn hacking from real hackers, from people that are used to hack, this involves a lot of techniques, such as social engineering, anonymity, privacy, and so on.
* Computer science: learn how computers work, learn stuff like operating system and compilers design and - probably - a little course of implementation.
* Languages: yeah, why not, we are all from different parts of the world, we can teach the languages we all speak natively.
There's also a forum, so you can also learn from the other users of the platform, you can ask your questions there, you can start discussions and so much more.
If you want to check it, you can visit it with the following link: https://anonworld.eu
If you can support that would be so amazing, you can donate, you can be a teacher (you have to contact us and introduce yourself). Thank you for everything
submitted by /u/iSaraaah
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/hacking - A completely-free (as in free beer) hacking school
0 votes and 0 comments so far on Reddit
hacking: security in practice
Not proud of this but it worked.
So me, being a homeless desperate sweaty bastard, decided to try something I saw on TV.
I walked into a 4 star hotel from the back door, dressed like I was headed to the gym, went to the front desk and attempted to get service, claiming I had forgotten my key.
When they asked for my ID, I was like "i mean come on man, Who takes their id to the gym?"
I was shocked to find that this worked. I managed to get a shower, a snack from the fridge, and the fuck outta there before getting noticed.
I knew social engineering could be a useful tool, but damn.. if I had not seen leverage, I would not have tried it.
submitted by /u/Captain-Crunch1989
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Not proud of this but it worked.
So me, being a homeless desperate sweaty bastard, decided to try something I saw on TV.
I walked into a 4 star hotel from the back door, dressed like I was headed to the gym, went to the front desk and attempted to get service, claiming I had forgotten my key.
When they asked for my ID, I was like "i mean come on man, Who takes their id to the gym?"
I was shocked to find that this worked. I managed to get a shower, a snack from the fridge, and the fuck outta there before getting noticed.
I knew social engineering could be a useful tool, but damn.. if I had not seen leverage, I would not have tried it.
submitted by /u/Captain-Crunch1989
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/hacking - Not proud of this but it worked.
0 votes and 0 comments so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New Ransomware Group Claiming Connection to REvil Gang Surfaces
'Prometheus' is the latest example of how the ransomware-as-a-service model is letting new gangs scale up operations quickly.
___________________________
@hacking_Attack
@Hacking_Video
New Ransomware Group Claiming Connection to REvil Gang Surfaces
'Prometheus' is the latest example of how the ransomware-as-a-service model is letting new gangs scale up operations quickly.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
New Ransomware Group Claiming Connection to REvil Gang Surfaces
'Prometheus' is the latest example of how the ransomware-as-a-service model is letting new gangs scale up operations quickly.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Toolbox Writeup
https://cdn-images-1.medium.com/max/600/1*_lbrZk9n6g9-WWo_M_y_EQ.png
Toolbox is an Easy machine listed on Hack The Box. It was designed on March 12th, 2021 by MinatoTW. I was able to gain a foothold into…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box — Toolbox Writeup
https://cdn-images-1.medium.com/max/600/1*_lbrZk9n6g9-WWo_M_y_EQ.png
Toolbox is an Easy machine listed on Hack The Box. It was designed on March 12th, 2021 by MinatoTW. I was able to gain a foothold into…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack The Box — Toolbox Writeup
Toolbox is an Easy machine listed on Hack The Box. It was designed on March 12th, 2021 by MinatoTW. I was able to gain a foothold into…
My Second Bounty OF $$$$ From Facebook
https://imajk.medium.com/my-second-bounty-of-from-facebook-fb213daa717b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://imajk.medium.com/my-second-bounty-of-from-facebook-fb213daa717b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Second Bounty OF $$$$ From Facebook
Summary
SummaryContinue reading on Medium » (https://imajk.medium.com/my-second-bounty-of-from-facebook-fb213daa717b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Second Bounty OF $$$$ From Facebook
Summary
Hacking Articles Tips Tricks Videos Tutorials
GIF
Kali Linux Tutorials
AMSITrigger : The Hunt For Malicious Strings
AMSITrigger will identify all of the malicious strings in a powershell file, by repeatedly making calls to AMSI using AMSIScanBuffer . Hunting For Malicious Strings Usage -i, –inputfile=VALUE Powershell filename-u, –url=VALUE URL eg. https://10.1.1.1/Invoke-NinjaCopy.ps1-f, –format=VALUE Output Format:1 – Only show Triggers2 – Show Triggers with Line numbers3 – Show Triggers inline with code4 – Show […]
The post AMSITrigger : The Hunt For Malicious Strings appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
AMSITrigger : The Hunt For Malicious Strings
AMSITrigger will identify all of the malicious strings in a powershell file, by repeatedly making calls to AMSI using AMSIScanBuffer . Hunting For Malicious Strings Usage -i, –inputfile=VALUE Powershell filename-u, –url=VALUE URL eg. https://10.1.1.1/Invoke-NinjaCopy.ps1-f, –format=VALUE Output Format:1 – Only show Triggers2 – Show Triggers with Line numbers3 – Show Triggers inline with code4 – Show […]
The post AMSITrigger : The Hunt For Malicious Strings appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
AMSITrigger : The Hunt For Malicious Strings 2021
AMSITrigger will identify all of the malicious strings in a powershell file, by repeatedly making calls to AMSI using AMSIScanBuffer .
Deep Web
I need some tech support!!
So I really need some assistance, my laptop apparently refuses to run whonix with virtual box. I dont know if the issue s with my whonix install or with the virtual box install but none theless I have reinstalled about 100 times of both already to no avail with pc restarts and all. Is there any way I can use the deepweb as easily without these two?
submitted by /u/Lucas7001
[link] [comments]
I need some tech support!!
So I really need some assistance, my laptop apparently refuses to run whonix with virtual box. I dont know if the issue s with my whonix install or with the virtual box install but none theless I have reinstalled about 100 times of both already to no avail with pc restarts and all. Is there any way I can use the deepweb as easily without these two?
submitted by /u/Lucas7001
[link] [comments]
reddit
I need some tech support!!
So I really need some assistance, my laptop apparently refuses to run whonix with virtual box. I dont know if the issue s with my whonix install...
How I could have accessed all your private videos/photos saved inside your device without even…
…
Read more...
…
Read more...
hacking: security in practice
Is this even possible... ?
Hi guys, I'm a begginer in all of this but I was thinking about something regarding bluetooth. I have more than one bluetooth speaker and I would like to be able to synch them both, but they are not from the same brand and I havent foundpftware that allows this. I was wondering if it was possible to use a raspberry pi as a relay, that way I would send data from my phone only to the raspberry pi who would then send it to the other devices. From the bit of research I did the limitations are set by the manufacturer that allows some devices (like phones) to be connacted only to 1 device at a time via bluetooth.
So what do you guys think? Is this a feasible project or is it simply impossible due to how the bluetooth protocol works?
Thanks in advance!
submitted by /u/Crypto_Boi_420
[link] [comments]
Is this even possible... ?
Hi guys, I'm a begginer in all of this but I was thinking about something regarding bluetooth. I have more than one bluetooth speaker and I would like to be able to synch them both, but they are not from the same brand and I havent foundpftware that allows this. I was wondering if it was possible to use a raspberry pi as a relay, that way I would send data from my phone only to the raspberry pi who would then send it to the other devices. From the bit of research I did the limitations are set by the manufacturer that allows some devices (like phones) to be connacted only to 1 device at a time via bluetooth.
So what do you guys think? Is this a feasible project or is it simply impossible due to how the bluetooth protocol works?
Thanks in advance!
submitted by /u/Crypto_Boi_420
[link] [comments]
reddit
Is this even possible... ?
Hi guys, I'm a begginer in all of this but I was thinking about something regarding bluetooth. I have more than one bluetooth speaker and I would...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Chrome Browser Bug Under Active Attack – Update your chrome now
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Browser Bug Under Active Attack – Update your chrome nowPost Views: 56
Reading Time: 1 Minute
Google is warning that a bug in its Chrome web browser is actively under attack, and it is urging users to upgrade to the latest 91.0.4472.101 version to mitigate the issue.
In all, Google rolled out fixes for 14 bugs impacting its Windows, Mac and Linux browsers as part of its June update to the Chrome desktop browser.
“Google is aware that an exploit for CVE-2021-30551 exists in the wild,” wrote Chrome technical program manager Prudhvikumar Bommana in a Wednesday post. That exploit is identified as a type confusion bug within Google’s V8 open-source JavaScript and WebAssembly engine.
The confusion vulnerability is tied to the browser’s ActionScript Virtual Machine. “Usually, when a piece of code doesn’t verify the type of object that is passed to it, and uses it blindly without type-checking, it leads to type confusion,” according to a technical description of the bug. Possible Wider Impact of Exploited Chrome Browser BugThe update coincides with the release of the Android Chrome browser to Chrome 91 (91.0.4472.101), also on Wednesday. While the desktop and mobile versions of the Chrome web browser share the same version number, it is unclear if the updated Android Chrome browser is impacted by the same vulnerabilities.
Also unclear is if Microsoft’s Edge browser, based on the Chromium open-source browser codebase (principally developed and maintained by Google), is also impacted.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries In related news, on Tuesday, Microsoft released a patch for vulnerabilities under active attack, including CVE-2021-33742, impacting its Edge browser. That bug is a remote-code execution (RCE) vulnerability within the Edge browser’s MSHTML component.
“The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications through WebBrowser control,” Microsoft explained. Critical Browser Cache Bug: CVE-2021-30544As part of the June Chrome update, Google patched a critical use-after-free bug (CVE-2021-30544) within the browser’s optimization engine called BFCache. This browser component enables back-and-forward navigation between cached webpages within Chrome.
As customary with recently disclosed bugs, Google did not release the details tied to any of the vulnerabilities patched Wednesday. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed,” the Google advisory stated.
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Google credits Rong Jian and Guang Gong of 360 Alpha Lab for finding the BFCache bug in May. For their bug hunting efforts, the pair earned $25,000. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-de[...]
Chrome Browser Bug Under Active Attack – Update your chrome now
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Browser Bug Under Active Attack – Update your chrome nowPost Views: 56
Reading Time: 1 Minute
Google is warning that a bug in its Chrome web browser is actively under attack, and it is urging users to upgrade to the latest 91.0.4472.101 version to mitigate the issue.
In all, Google rolled out fixes for 14 bugs impacting its Windows, Mac and Linux browsers as part of its June update to the Chrome desktop browser.
“Google is aware that an exploit for CVE-2021-30551 exists in the wild,” wrote Chrome technical program manager Prudhvikumar Bommana in a Wednesday post. That exploit is identified as a type confusion bug within Google’s V8 open-source JavaScript and WebAssembly engine.
The confusion vulnerability is tied to the browser’s ActionScript Virtual Machine. “Usually, when a piece of code doesn’t verify the type of object that is passed to it, and uses it blindly without type-checking, it leads to type confusion,” according to a technical description of the bug. Possible Wider Impact of Exploited Chrome Browser BugThe update coincides with the release of the Android Chrome browser to Chrome 91 (91.0.4472.101), also on Wednesday. While the desktop and mobile versions of the Chrome web browser share the same version number, it is unclear if the updated Android Chrome browser is impacted by the same vulnerabilities.
Also unclear is if Microsoft’s Edge browser, based on the Chromium open-source browser codebase (principally developed and maintained by Google), is also impacted.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries In related news, on Tuesday, Microsoft released a patch for vulnerabilities under active attack, including CVE-2021-33742, impacting its Edge browser. That bug is a remote-code execution (RCE) vulnerability within the Edge browser’s MSHTML component.
“The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications through WebBrowser control,” Microsoft explained. Critical Browser Cache Bug: CVE-2021-30544As part of the June Chrome update, Google patched a critical use-after-free bug (CVE-2021-30544) within the browser’s optimization engine called BFCache. This browser component enables back-and-forward navigation between cached webpages within Chrome.
As customary with recently disclosed bugs, Google did not release the details tied to any of the vulnerabilities patched Wednesday. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed,” the Google advisory stated.
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Google credits Rong Jian and Guang Gong of 360 Alpha Lab for finding the BFCache bug in May. For their bug hunting efforts, the pair earned $25,000. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-de[...]