Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
Consider four factors and behaviors that impact a particular employee's risk, and how security training should take them into account.
___________________________
@hacking_Attack
@Hacking_Video
Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
Consider four factors and behaviors that impact a particular employee's risk, and how security training should take them into account.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
Consider four factors and behaviors that impact a particular employee's risk, and how security training should take them into account.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe write-up: Res
https://cdn-images-1.medium.com/max/610/0*cbCq1l9XAKIfYEJX.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe write-up: Res
https://cdn-images-1.medium.com/max/610/0*cbCq1l9XAKIfYEJX.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe write-up: Res
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe write-up: Jacob the Boss
https://cdn-images-1.medium.com/max/625/0*FX-UjUlfrfieI3fI.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe write-up: Jacob the Boss
https://cdn-images-1.medium.com/max/625/0*FX-UjUlfrfieI3fI.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe write-up: Jacob the Boss
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe write-up: RootMe
https://cdn-images-1.medium.com/max/625/0*bA5kGr9NvLBY0l4_.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe write-up: RootMe
https://cdn-images-1.medium.com/max/625/0*bA5kGr9NvLBY0l4_.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe write-up: RootMe
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Easy 7 Steps to Become An Ethical Hacker
https://cdn-images-1.medium.com/max/2600/1*D6cosRqcuxb8JQRUjK7ynw.jpeg
As a Hacker, understand and explore the way to become a successful Ethical Hacker.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Easy 7 Steps to Become An Ethical Hacker
https://cdn-images-1.medium.com/max/2600/1*D6cosRqcuxb8JQRUjK7ynw.jpeg
As a Hacker, understand and explore the way to become a successful Ethical Hacker.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Easy 7 Steps to Become An Ethical Hacker
As a Hacker, understand and explore the way to become a successful Ethical Hacker.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to run Axiom and waybackurls against all your targets
https://cdn-images-1.medium.com/max/1002/1*HeifU9jpHCci7VUEsj2ybQ.png
This is a short and simple guide how to extract all the waybackurls (♥ tomnomnom) results from all your programs in a fast and simple way.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to run Axiom and waybackurls against all your targets
https://cdn-images-1.medium.com/max/1002/1*HeifU9jpHCci7VUEsj2ybQ.png
This is a short and simple guide how to extract all the waybackurls (♥ tomnomnom) results from all your programs in a fast and simple way.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to run Axiom and waybackurls against all your targets
This is a short and simple guide how to extract all the waybackurls (♥ tomnomnom) results from all your programs in a fast and simple way.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Como Hackeamos um Jogo Para Adicionar uma Funcionalidade
https://cdn-images-1.medium.com/max/2600/1*j3OsuscxX_Pae0wSs6HcxA.png
Criando um gerador de mapas para o TaleSpire
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Como Hackeamos um Jogo Para Adicionar uma Funcionalidade
https://cdn-images-1.medium.com/max/2600/1*j3OsuscxX_Pae0wSs6HcxA.png
Criando um gerador de mapas para o TaleSpire
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Como Hackeamos um Jogo Para Adicionar uma Funcionalidade
Criando um gerador de mapas para o TaleSpire
Account takeover via stored XSS with arbitrary file upload
https://0xbadb00da.medium.com/account-takeover-via-stored-xss-with-arbitrary-file-upload-2774ec6cff51?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xbadb00da.medium.com/account-takeover-via-stored-xss-with-arbitrary-file-upload-2774ec6cff51?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Account takeover via stored XSS with arbitrary file upload
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests. Requests…
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests.
Requests…Continue reading on Medium » (https://0xbadb00da.medium.com/account-takeover-via-stored-xss-with-arbitrary-file-upload-2774ec6cff51?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Requests…Continue reading on Medium » (https://0xbadb00da.medium.com/account-takeover-via-stored-xss-with-arbitrary-file-upload-2774ec6cff51?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Account takeover via stored XSS with arbitrary file upload
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests. Requests…
hacking: security in practice
How to use google dork to find bug bounty program which are not listed on hackerone ?
How to use google dork to find bug bounty program which are not listed on hackerone ?
submitted by /u/Firm-Bunch-5049
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to use google dork to find bug bounty program which are not listed on hackerone ?
How to use google dork to find bug bounty program which are not listed on hackerone ?
submitted by /u/Firm-Bunch-5049
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to use google dork to find bug bounty program which are not...
How to use google dork to find bug bounty program which are not listed on hackerone ?
hacking: security in practice
Follow up on previously found data breach
I am following up on this post I made here: https://www.reddit.com/r/hacking/comments/ns32i2/i_have_learnt_of_a_data_breach_and_the_company_is/
I will write [hackers] because I don't know how many they are, where, age, gender, group name, motive (apart from money), etc.
I have had a phone call with the company here and have heard their side of the story. I have also checked other factors which would directly put myself at risk.
The company is VTExperts, who make the paid subscription ion(?)-encrypted Vtiger modules.
I was contacted by [hackers] directly via email. They had breached my VT CRM (logs, dropped files, etc). We did not have any default passwords. I responded to the hackers, thanked them for notifying me of the of the exploit and asked them if they would assist me by telling my how they breached it, and how to protect it. I offered payment for this service. They accepted, and proceeded to tell me that they breached the CRM using the module 'vtestore' but declined to tell me the exact procedure. They advised I protect the CRM with an IP whitelisted .htaccess file, and that they can't fix the exact code since it's in vtestore and is encrypted - something about them needed an ioncube (?) license. Sounded legit.
I contacted VTExperts, they seemed less than convinced it was their modules at fault.
I asked the [hackers] for some proof, which they happily provided much. I am even developing another CRM using VTExperts - and asked if they were able to breach that. They came back in 10 minutes with my SQL details, including password. The logs show access to files/folders within the vtestore folders. They also showed me screenshots/videos with the VTExperts SVN repo, SQL dump, screenshot of their license panel.
They then breached VTExperts hosted VTiger CRM instances (around 5 servers each containing a number of installations), downloading all SQL data and files. They proved this and showed me a screenshots of files from companies - notable a law firm in the USA (client court documents I think).
They have subsequently "shown off" by changing the login pages of various VT CRM instances.
Why are they showing me? Simple - by strengthening my position as an angry, aggrieved customer of VTExperts, I am strengthening their position to prove the severity of the situation and subsequently their demands/ransom. They are new to this - not an opinion - they outright told me. I happily and selfishly accept this evidence (after my own scrutinisation). How do they get in touch with me? They have all my contact details from VT and I receive various messages, like Signal, Telegram, Wickr, Pastebins, etc. (self destructing messages obviously). Even Reddit.
VTExperts responded by enabling Cloudflare 2FA on their hosted servers.
So, onto my phone call. VTExperts seemed convinced that weak passwords were at play. I showed them my evidence and it they seemed to accept it. They said that they were aware of a CRM breach 10 months ago involving a medical company. They told me that the [hackers] are demanding 40BTC, around $1.5M. They (Tom of VTExperts) said that the [hackers] have been making demands for quite a while.
So it's been going on for a while. The [hackers] claim that they breached the VTExperts servers/modules 1.5 years ago, and found the first bugs in 2017.
I told (Tom) of VTExperts that I am obviously upset that they were aware there could have been an issue many months ago. I told him that I believe that the [hackers] have been using this time to download masses of data from VTExperts hosted Vtiger CRMs and self-hosted instances. VTExperts license panel (as shown to me in screenshots) has a column listing all Vtiger instances running the software.
I mentioned that there are serious implication[...]
___________________________
@hacking_Attack
@Hacking_Video
Follow up on previously found data breach
I am following up on this post I made here: https://www.reddit.com/r/hacking/comments/ns32i2/i_have_learnt_of_a_data_breach_and_the_company_is/
I will write [hackers] because I don't know how many they are, where, age, gender, group name, motive (apart from money), etc.
I have had a phone call with the company here and have heard their side of the story. I have also checked other factors which would directly put myself at risk.
The company is VTExperts, who make the paid subscription ion(?)-encrypted Vtiger modules.
I was contacted by [hackers] directly via email. They had breached my VT CRM (logs, dropped files, etc). We did not have any default passwords. I responded to the hackers, thanked them for notifying me of the of the exploit and asked them if they would assist me by telling my how they breached it, and how to protect it. I offered payment for this service. They accepted, and proceeded to tell me that they breached the CRM using the module 'vtestore' but declined to tell me the exact procedure. They advised I protect the CRM with an IP whitelisted .htaccess file, and that they can't fix the exact code since it's in vtestore and is encrypted - something about them needed an ioncube (?) license. Sounded legit.
I contacted VTExperts, they seemed less than convinced it was their modules at fault.
I asked the [hackers] for some proof, which they happily provided much. I am even developing another CRM using VTExperts - and asked if they were able to breach that. They came back in 10 minutes with my SQL details, including password. The logs show access to files/folders within the vtestore folders. They also showed me screenshots/videos with the VTExperts SVN repo, SQL dump, screenshot of their license panel.
They then breached VTExperts hosted VTiger CRM instances (around 5 servers each containing a number of installations), downloading all SQL data and files. They proved this and showed me a screenshots of files from companies - notable a law firm in the USA (client court documents I think).
They have subsequently "shown off" by changing the login pages of various VT CRM instances.
Why are they showing me? Simple - by strengthening my position as an angry, aggrieved customer of VTExperts, I am strengthening their position to prove the severity of the situation and subsequently their demands/ransom. They are new to this - not an opinion - they outright told me. I happily and selfishly accept this evidence (after my own scrutinisation). How do they get in touch with me? They have all my contact details from VT and I receive various messages, like Signal, Telegram, Wickr, Pastebins, etc. (self destructing messages obviously). Even Reddit.
VTExperts responded by enabling Cloudflare 2FA on their hosted servers.
So, onto my phone call. VTExperts seemed convinced that weak passwords were at play. I showed them my evidence and it they seemed to accept it. They said that they were aware of a CRM breach 10 months ago involving a medical company. They told me that the [hackers] are demanding 40BTC, around $1.5M. They (Tom of VTExperts) said that the [hackers] have been making demands for quite a while.
So it's been going on for a while. The [hackers] claim that they breached the VTExperts servers/modules 1.5 years ago, and found the first bugs in 2017.
I told (Tom) of VTExperts that I am obviously upset that they were aware there could have been an issue many months ago. I told him that I believe that the [hackers] have been using this time to download masses of data from VTExperts hosted Vtiger CRMs and self-hosted instances. VTExperts license panel (as shown to me in screenshots) has a column listing all Vtiger instances running the software.
I mentioned that there are serious implication[...]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Follow up on previously found data breach
I am following up on this post I made...
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Follow up on previously found data breach I am following up on this post I made here: https://www.reddit.com/r/hacking/comments/ns32i2/i_have_learnt_of_a_data_breach_and_the_company_is/ I will write [hackers] because I don't…
s in the UK of this kind of breach, and hiding it (GDPR) but that I am unaware of US law.
Tom said that he is considering options. Whether he should go public, and how, or if he should pay a ransom.
Shortly after our phone call, the [hackers] got in touch again and told me that they had set a deadline for their random for VTExperts. They of course enjoy showing how good they are. (Maybe they saw changes in our CRM or VTExperts servers or something?).
I have since found this on the VTiger forums: https://discussions.vtiger.com/discussion/193627/vtexperts-com-company-hacked-breach-leak/p1?new=1
Which confirms that the user who contacted me on Reddit is them.
So yeah, in summary, I believe that any VTiger CRM running VTExperts is susceptible to, or has already been breached by these [hackers].
I realise that I may not have handled this situation perfectly (maybe should have announced sooner) and I admit that I was being somewhat selfish making sure that I was not putting myself at risk (legal or otherwise).
For those out there that want something more, here are the logs from when the [hackers] took 10 minutes to breach the 2nd (previously unaffected, new) Vtiger CRM running VTExperts: https://pastebin.com/94Z2Ah47 - The blank removed lines are access lines from my own IP.
If I answer any significant questions on comments, I'll add them here.
submitted by /u/Sly-D [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tom said that he is considering options. Whether he should go public, and how, or if he should pay a ransom.
Shortly after our phone call, the [hackers] got in touch again and told me that they had set a deadline for their random for VTExperts. They of course enjoy showing how good they are. (Maybe they saw changes in our CRM or VTExperts servers or something?).
I have since found this on the VTiger forums: https://discussions.vtiger.com/discussion/193627/vtexperts-com-company-hacked-breach-leak/p1?new=1
Which confirms that the user who contacted me on Reddit is them.
So yeah, in summary, I believe that any VTiger CRM running VTExperts is susceptible to, or has already been breached by these [hackers].
I realise that I may not have handled this situation perfectly (maybe should have announced sooner) and I admit that I was being somewhat selfish making sure that I was not putting myself at risk (legal or otherwise).
For those out there that want something more, here are the logs from when the [hackers] took 10 minutes to breach the 2nd (previously unaffected, new) Vtiger CRM running VTExperts: https://pastebin.com/94Z2Ah47 - The blank removed lines are access lines from my own IP.
If I answer any significant questions on comments, I'll add them here.
submitted by /u/Sly-D [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Vtiger
VTEXPERTS.com company Hacked - Breach & Leak
proof 1: https://gofile.io/d/C0QDPm proof 1a: https://easyupload.io/r3iywf if need more proof contact us
Account takeover via stored XSS with arbitrary file upload
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests. Requests…Continue reading on Medium »
Read more...
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests. Requests…Continue reading on Medium »
Read more...