Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cyber attack techniques knowledge for complete cyber security beginners!
https://cdn-images-1.medium.com/max/640/1*U7tAfopiPJHBjA2SlliHqA.jpeg
Are you a complete cyber security beginner? Who wants to get started in cyber security?? Or maybe you’re just an ordinary person who is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cyber attack techniques knowledge for complete cyber security beginners!
https://cdn-images-1.medium.com/max/640/1*U7tAfopiPJHBjA2SlliHqA.jpeg
Are you a complete cyber security beginner? Who wants to get started in cyber security?? Or maybe you’re just an ordinary person who is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber attack techniques knowledge for complete cyber security beginners!
Are you a complete cyber security beginner? Who wants to get started in cyber security?? Or maybe you’re just an ordinary person who is…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Taiwan Cybersecurity Outperforms Competition at 2021 SelectUSA Investment Summit
https://cdn-images-1.medium.com/max/1274/0*50Yfh1qcEzByrRV6
Taipei, Taiwan — 17 June 2021 — Two Taiwan-based companies outperformed all other competition in the 2021 SelectUSA Investment Summit held…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Taiwan Cybersecurity Outperforms Competition at 2021 SelectUSA Investment Summit
https://cdn-images-1.medium.com/max/1274/0*50Yfh1qcEzByrRV6
Taipei, Taiwan — 17 June 2021 — Two Taiwan-based companies outperformed all other competition in the 2021 SelectUSA Investment Summit held…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Taiwan Cybersecurity Outperforms Competition at 2021 SelectUSA Investment Summit
Taipei, Taiwan — 17 June 2021 — Two Taiwan-based companies outperformed all other competition in the 2021 SelectUSA Investment Summit held…
Deep Web
Does running a VPN inside virtual machine help?
I'm making a virtual machine for surfing deepweb and planning to use TOR over VPN inside that guest os. I have to use a VPN cause I can't let ISP know that I'm using TOR. But all the traffic of the guest OS will be travelling through my host's IP that's unprotected. So will this system work? My theory is it will. Because all the traffic of the virtual machine will still be going through the VPN server. It'll be like using TOR browser normally on my main OS. When we use tor browser, only trafic of the browser goes through tor network and all other traffic from the os travel through normal network.
If I'm wrong for some reason, will using the VPN on my host OS do the job? Then everything will be going through VPN server instead of only the traffic of virtual machine. Also I'm pretty confused about network modes. Suggestions on which mode will be perfect for my need are highly welcomed. Is there a mode in which I can connect the guest separately to the router such as I have a new physical device. Thanks in advance.
submitted by /u/ResearcherHuman7708
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Does running a VPN inside virtual machine help?
I'm making a virtual machine for surfing deepweb and planning to use TOR over VPN inside that guest os. I have to use a VPN cause I can't let ISP know that I'm using TOR. But all the traffic of the guest OS will be travelling through my host's IP that's unprotected. So will this system work? My theory is it will. Because all the traffic of the virtual machine will still be going through the VPN server. It'll be like using TOR browser normally on my main OS. When we use tor browser, only trafic of the browser goes through tor network and all other traffic from the os travel through normal network.
If I'm wrong for some reason, will using the VPN on my host OS do the job? Then everything will be going through VPN server instead of only the traffic of virtual machine. Also I'm pretty confused about network modes. Suggestions on which mode will be perfect for my need are highly welcomed. Is there a mode in which I can connect the guest separately to the router such as I have a new physical device. Thanks in advance.
submitted by /u/ResearcherHuman7708
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does running a VPN inside virtual machine help?
I'm making a virtual machine for surfing deepweb and planning to use TOR over VPN inside that guest os. I have to use a VPN cause I can't let ISP...
Joern - Open-source Code Analysis Platform For C/C++/Java Based On Code Property Graphs
http://www.kitploit.com/2021/06/joern-open-source-code-analysis.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/06/joern-open-source-code-analysis.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Joern - Open-source Code Analysis Platform For C/C++/Java Based On Code Property Graphs
Joern's Documentation is available here: https://docs.joern.io/home
Quick Installation
">wget https://github.com/ShiftLeftSecurity/joern/releases/latest/download/joern-install.sh
chmod +x ./joern-install.sh
sudo ./joern-install.sh
joern
Compiling (synthetic)/ammonite/predef/interpBridge.sc
Compiling (synthetic)/ammonite/predef/replBridge.sc
Compiling (synthetic)/ammonite/predef/DefaultPredef.sc
Compiling /home/tmp/shiftleft/joern/(console)
██╗ ██████╗ ███████╗██████╗ ███╗ ██╗
██║██╔═══██╗██╔════╝██╔══██╗████╗ ██║
██║██║ ██║█████╗ ██████╔╝██╔██╗ ██║
██ ██║██║ ██║██╔══╝ ██╔══██╗██║╚██╗██║
╚█████╔╝╚██████╔╝███████╗██║ ██║██║ ╚████║
╚════╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝╚═╝ ╚═══╝
joern>
If the installation script fails for any reason, try ./joern-install --interactive
Download Joern (https://github.com/joernio/joern)
___________________________
@hacking_Attack
@Hacking_Video
Quick Installation
">wget https://github.com/ShiftLeftSecurity/joern/releases/latest/download/joern-install.sh
chmod +x ./joern-install.sh
sudo ./joern-install.sh
joern
Compiling (synthetic)/ammonite/predef/interpBridge.sc
Compiling (synthetic)/ammonite/predef/replBridge.sc
Compiling (synthetic)/ammonite/predef/DefaultPredef.sc
Compiling /home/tmp/shiftleft/joern/(console)
██╗ ██████╗ ███████╗██████╗ ███╗ ██╗
██║██╔═══██╗██╔════╝██╔══██╗████╗ ██║
██║██║ ██║█████╗ ██████╔╝██╔██╗ ██║
██ ██║██║ ██║██╔══╝ ██╔══██╗██║╚██╗██║
╚█████╔╝╚██████╔╝███████╗██║ ██║██║ ╚████║
╚════╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝╚═╝ ╚═══╝
joern>
If the installation script fails for any reason, try ./joern-install --interactive
Download Joern (https://github.com/joernio/joern)
___________________________
@hacking_Attack
@Hacking_Video
docs.joern.io
Overview | Joern Documentation
Welcome to the documentation of the code analysis platform Joern! For
Unrestricted File Upload — Entendendo o que é, Como explorar, Tipos de Bypass e Como Prevenir a…
https://gabrieldkgh.medium.com/unrestricted-file-upload-entendendo-o-que-%C3%A9-como-explorar-tipos-de-bypass-e-como-prevenir-a-a723d845c375?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://gabrieldkgh.medium.com/unrestricted-file-upload-entendendo-o-que-%C3%A9-como-explorar-tipos-de-bypass-e-como-prevenir-a-a723d845c375?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unrestricted File Upload — Entendendo o que é, Como explorar, Tipos de Bypass e Como Prevenir a…
Olá a todos, hoje iremos falar sobre uma falha muito conhecida que é o Unrestricted file upload (Upload de arquivo irrestrito), essa falha…
Olá a todos, hoje iremos falar sobre uma falha muito conhecida que é o Unrestricted file upload (Upload de arquivo irrestrito), essa falha…Continue reading on Medium » (https://gabrieldkgh.medium.com/unrestricted-file-upload-entendendo-o-que-%C3%A9-como-explorar-tipos-de-bypass-e-como-prevenir-a-a723d845c375?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unrestricted File Upload — Entendendo o que é, Como explorar, Tipos de Bypass e Como Prevenir a…
Olá a todos, hoje iremos falar sobre uma falha muito conhecida que é o Unrestricted file upload (Upload de arquivo irrestrito), essa falha…
Joern - Open-source Code Analysis Platform For C/C++/Java Based On Code Property Graphs
Joern's Documentation is available here: https://docs.joern.io/home Quick Installation wget https://github.com/ShiftLeftSecurity/joern/releases/latest/download/joern-install.shchmod +x ./joern-install.shsudo ./joern-install.shjoernCompiling (synthetic)/ammonite/predef/interpBridge.scCompiling (synthetic)/ammonite/predef/replBridge.scCompiling (synthetic)/ammonite/predef/DefaultPredef.scCompiling /home/tmp/shiftleft/joern/(console) ██╗ ██████╗ ███████╗██████╗ ███╗ ██╗ ██║██╔═══██╗██╔════╝██╔══██╗████╗ ██║ ██║██║ ██║█████╗ ██████╔╝██╔██╗ ██║██ ██║██║ ██║██╔══╝ ██╔══██╗██║╚██╗██║╚█████╔╝╚██████╔╝███████╗██║ ██║██║ ╚████║ ╚════╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝╚═╝ ╚═══╝joern> If the installation script fails for any reason, try ./joern-install --interactive Download Joern
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Joern's Documentation is available here: https://docs.joern.io/home Quick Installation wget https://github.com/ShiftLeftSecurity/joern/releases/latest/download/joern-install.shchmod +x ./joern-install.shsudo ./joern-install.shjoernCompiling (synthetic)/ammonite/predef/interpBridge.scCompiling (synthetic)/ammonite/predef/replBridge.scCompiling (synthetic)/ammonite/predef/DefaultPredef.scCompiling /home/tmp/shiftleft/joern/(console) ██╗ ██████╗ ███████╗██████╗ ███╗ ██╗ ██║██╔═══██╗██╔════╝██╔══██╗████╗ ██║ ██║██║ ██║█████╗ ██████╔╝██╔██╗ ██║██ ██║██║ ██║██╔══╝ ██╔══██╗██║╚██╗██║╚█████╔╝╚██████╔╝███████╗██║ ██║██║ ╚████║ ╚════╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝╚═╝ ╚═══╝joern> If the installation script fails for any reason, try ./joern-install --interactive Download Joern
Read more...
___________________________
@hacking_Attack
@Hacking_Video
docs.joern.io
Overview | Joern Documentation
Welcome to the documentation of the code analysis platform Joern! For
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Millions of Connected Cameras Open to Eavesdropping
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Millions of Connected Cameras Open to EavesdroppingPost Views: 226
Reading Time: 1 Minute
Millions of connected security and home cameras contain a critical software vulnerability that can allow remote attackers to tap into video feeds, according to a warning from the Cybersecurity and Infrastructure Security Agency (CISA).
The bug (CVE-2021-32934, with a CVSS v3 base score of 9.1) has been introduced via a supply-chain component from ThroughTek that’s used by several original equipment manufacturers (OEMs) of security cameras – along with makers of IoT devices like baby- and pet-monitoring cameras, and robotic and battery devices.
The potential issues stemming from unauthorized viewing of feeds from these devices are myriad: For critical infrastructure operators and enterprises, video-feed interceptions could reveal sensitive business data, production/competitive secrets, information on floorplans for use in physical attacks, and employee information. And for home users, the privacy implications are obvious.
In its alert, issued Tuesday, CISA said that so far, no known public exploits are targeting the bug in the wild yet.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries Vulnerable P2P SDKThe ThroughTek component at issue is its peer-to-peer (P2P) software development kit (SDK), which has been installed in several million connected devices, according to the supplier. It’s used to provide remote access to audio and video streams over the internet.
Nozomi Networks, which discovered the bug, noted that the way P2P works is based on three architectural aspects:
* A network video recorder (NVR), which is connected to security cameras and represents the local P2P server that generates the audio/video stream.
* An offsite P2P server, managed by the camera vendor or P2P SDK vendor. This server acts as a middleman, allowing the client and NVR to establish a connection to each other.
* A software client, either a mobile or a desktop application, that accesses the audio/video stream from the internet.
“A peculiarity of P2P SDKs…is that OEMs are not just licensing a P2P software library,” analysts at Nozomi Networks pointed out, in a Tuesday posting. “They also receive infrastructure services (the offsite P2P server) for authenticating clients and servers and handling the audio/video stream.”
In analyzing the specific client implementation for ThroughTek’s P2P platform and the network traffic generated by a Windows client connecting to the NVR through P2P, Nozomi researchers found that the data transferred between the local device and ThroughTek servers lacked a secure key exchange, relying instead on an obfuscation scheme based on a fixed key.
“After setting a few breakpoints in the right spots, we managed to identify interesting code where the network’s packet payload is de-obfuscated,” according to Nozomi’s writeup. “Since this traffic traverses the internet, an attacker that is able to access it can reconstruct the audio/video stream.”
See Also: Offensive Security Tool: CloudFail Nozomi was able to create a proof-of-concept script that de-obfuscates on-the-fly packets from network traffic, it said, but no further technical details were given. Notably, ThroughTek’s advisory also listed device-spoofing and device-certificate hijacking as other potential risks from any exploitation of the bug. The supplier has patched the issue in the latest version of the firmware. Affected Versions and Remedies:* All versions[...]
___________________________
@hacking_Attack
@Hacking_Video
Millions of Connected Cameras Open to Eavesdropping
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Millions of Connected Cameras Open to EavesdroppingPost Views: 226
Reading Time: 1 Minute
Millions of connected security and home cameras contain a critical software vulnerability that can allow remote attackers to tap into video feeds, according to a warning from the Cybersecurity and Infrastructure Security Agency (CISA).
The bug (CVE-2021-32934, with a CVSS v3 base score of 9.1) has been introduced via a supply-chain component from ThroughTek that’s used by several original equipment manufacturers (OEMs) of security cameras – along with makers of IoT devices like baby- and pet-monitoring cameras, and robotic and battery devices.
The potential issues stemming from unauthorized viewing of feeds from these devices are myriad: For critical infrastructure operators and enterprises, video-feed interceptions could reveal sensitive business data, production/competitive secrets, information on floorplans for use in physical attacks, and employee information. And for home users, the privacy implications are obvious.
In its alert, issued Tuesday, CISA said that so far, no known public exploits are targeting the bug in the wild yet.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries Vulnerable P2P SDKThe ThroughTek component at issue is its peer-to-peer (P2P) software development kit (SDK), which has been installed in several million connected devices, according to the supplier. It’s used to provide remote access to audio and video streams over the internet.
Nozomi Networks, which discovered the bug, noted that the way P2P works is based on three architectural aspects:
* A network video recorder (NVR), which is connected to security cameras and represents the local P2P server that generates the audio/video stream.
* An offsite P2P server, managed by the camera vendor or P2P SDK vendor. This server acts as a middleman, allowing the client and NVR to establish a connection to each other.
* A software client, either a mobile or a desktop application, that accesses the audio/video stream from the internet.
“A peculiarity of P2P SDKs…is that OEMs are not just licensing a P2P software library,” analysts at Nozomi Networks pointed out, in a Tuesday posting. “They also receive infrastructure services (the offsite P2P server) for authenticating clients and servers and handling the audio/video stream.”
In analyzing the specific client implementation for ThroughTek’s P2P platform and the network traffic generated by a Windows client connecting to the NVR through P2P, Nozomi researchers found that the data transferred between the local device and ThroughTek servers lacked a secure key exchange, relying instead on an obfuscation scheme based on a fixed key.
“After setting a few breakpoints in the right spots, we managed to identify interesting code where the network’s packet payload is de-obfuscated,” according to Nozomi’s writeup. “Since this traffic traverses the internet, an attacker that is able to access it can reconstruct the audio/video stream.”
See Also: Offensive Security Tool: CloudFail Nozomi was able to create a proof-of-concept script that de-obfuscates on-the-fly packets from network traffic, it said, but no further technical details were given. Notably, ThroughTek’s advisory also listed device-spoofing and device-certificate hijacking as other potential risks from any exploitation of the bug. The supplier has patched the issue in the latest version of the firmware. Affected Versions and Remedies:* All versions[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Millions of Connected Cameras Open to Eavesdropping https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Millions of Connected Cameras Open to EavesdroppingPost Views: 226 Reading…
below 3.1.10
* SDK versions with nossl tag
* Device firmware that does not use AuthKey for IOTC connection
* Device firmware that uses AVAPI module without enabling DTLS mechanism
* Device firmware that uses P2PTunnel or RDT module Actions to Take:* If SDK is 3.1.10 and above, enable Authkey and DTLS
* If SDK is below 3.1.10, upgrade library to 3.3.1.0 or 3.4.2.0 and enable Authkey/DTLS
Unfortunately, end users will be forced to rely on camera and IoT manufacturers to install the updates – ThroughTek’s vendor partners are not public. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat “Because ThroughTek’s P2P library has been integrated by multiple vendors into many different devices over the years, it’s virtually impossible for a third party to track the affected products,” Nozomi researchers said.
IoT camera bugs are hardly rare: Last month, for instance, owners of Eufy home-security cameras were warned of an internal server bug that allowed strangers to view, pan and zoom in on their home-video feeds. Customers were also suddenly given access to do the same to other users.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-patch-90x90.png Cisco Smart Switches Riddled with Severe Security Holes7 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif-6-446db01f6f32-90x90.jpg Apple Hurries Patches for Safari Bugs Under Active Attack2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Microsoft-Teams-e1623702241390-90x90.png Microsoft Teams: Very Bad Tabs Could Have Led to BEC3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/FIFA-21-90x90.jpg Hackers Steal FIFA 21 Source Code, Tools in EA Breach4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-3-90x90.png Chrome Browser Bug Under Active Attack – Update your chrome now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks2 weeks ago
The post Millions of Connected Cameras Open to Eavesdropping first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* SDK versions with nossl tag
* Device firmware that does not use AuthKey for IOTC connection
* Device firmware that uses AVAPI module without enabling DTLS mechanism
* Device firmware that uses P2PTunnel or RDT module Actions to Take:* If SDK is 3.1.10 and above, enable Authkey and DTLS
* If SDK is below 3.1.10, upgrade library to 3.3.1.0 or 3.4.2.0 and enable Authkey/DTLS
Unfortunately, end users will be forced to rely on camera and IoT manufacturers to install the updates – ThroughTek’s vendor partners are not public. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat “Because ThroughTek’s P2P library has been integrated by multiple vendors into many different devices over the years, it’s virtually impossible for a third party to track the affected products,” Nozomi researchers said.
IoT camera bugs are hardly rare: Last month, for instance, owners of Eufy home-security cameras were warned of an internal server bug that allowed strangers to view, pan and zoom in on their home-video feeds. Customers were also suddenly given access to do the same to other users.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-patch-90x90.png Cisco Smart Switches Riddled with Severe Security Holes7 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif-6-446db01f6f32-90x90.jpg Apple Hurries Patches for Safari Bugs Under Active Attack2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Microsoft-Teams-e1623702241390-90x90.png Microsoft Teams: Very Bad Tabs Could Have Led to BEC3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/FIFA-21-90x90.jpg Hackers Steal FIFA 21 Source Code, Tools in EA Breach4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-3-90x90.png Chrome Browser Bug Under Active Attack – Update your chrome now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks2 weeks ago
The post Millions of Connected Cameras Open to Eavesdropping first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Protected: “Worst” MacOS Security Bug Recently Patched by Apple
Password Protected
To view this protected post, enter the password below:
Password:
Submit
The post Protected: “Worst” MacOS Security Bug Recently Patched by Apple first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Protected: “Worst” MacOS Security Bug Recently Patched by Apple
Password Protected
To view this protected post, enter the password below:
Password:
Submit
The post Protected: “Worst” MacOS Security Bug Recently Patched by Apple first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Blackhatethicalhacking
Black Hat Ethical Hacking | Offensive Security Training & InfoSec News
Master offensive security with real-world ethical hacking training. Stay updated with the latest InfoSec news, red team tactics, blue team defense, and penetration testing methodologies.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco Smart Switches Riddled with Severe Security Holes
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Cisco Smart Switches Riddled with Severe Security HolesPost Views: 60
Reading Time: 1 Minute
Cisco has flagged and patched several high-severity security vulnerabilities in its Cisco Small Business 220 Series Smart Switches that could allow session hijacking, arbitrary code execution, cross-site scripting and HTML injection.
It also issued fixes for high-severity problems in the AnyConnect secure mobility client, the Cisco DNA Center and the Cisco Email Security Appliance, along with a slew of patches for medium-severity vulnerabilities in AnyConnect, Jabber, Meeting Server, Unified Intelligence Center and Webex.
The high-severity issues are as follows:
* CVE-2021-1566: Cisco Email Security Appliance and Cisco Web Security Appliance (Certificate-Validation Vulnerability)
* CVE-2021-1134: Cisco DNA Center (Certificate Validation Vulnerability)
* CVE-2021-1541 through 1543; CVE-2021-1571: Cisco Small Business 220 Series Smart Switches (Session Hijacking, Arbitrary Code-Execution, Cross-Site Scripting, HTML Injection)
* CVE-2021-1567: Cisco AnyConnect Secure Mobility Client for Windows with VPN Posture (HostScan) Module (DLL Hijacking)
The most severe issue in this crop of patches is tracked as CVE-2021-1542, in the Cisco Small Business 220 Series Smart Switches. These are entry-level switches that act as the basic building blocks for small- and medium-sized business networks. They’re responsible for sharing network resources and connecting various clients, including computers, printers and servers, to the network and each other, along with security, governing network performance and more.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries The bug rates 7.5 on the 10-point CVSS vulnerability-severity scale, and arises from weak session management for the web-based management interface of the switches. An unauthenticated, remote attacker could use it to bypass authentication protections and gain unauthorized access to the interface, according to the advisory. The attacker could then obtain the privileges of the highjacked session account, which could include administrative privileges, and thus gain free rein on the switch.
“This vulnerability is due to the use of weak session management for session identifier values,” according to Cisco. “An attacker could exploit this vulnerability by using reconnaissance methods to determine how to craft a valid session identifier. A successful exploit could allow the attacker [to] take actions within the management interface with privileges up to the level of the administrative user.” Multiple Patches for Smart SwitchesThere are also multiple other security flaws in the same web-management interface. For instance, the bug tracked as CVE-2021-1541 is an arbitrary code-execution vulnerability that would allow an authenticated, remote attacker to execute arbitrary commands as a root user on the underlying operating system.
“This vulnerability is due to a lack of parameter validation for TFTP configuration parameters,” according to Cisco. “An attacker could exploit this vulnerability by entering crafted input for specific TFTP configuration parameters. A successful exploit could allow the attacker to execute arbitrary commands as a root user on the underlying operating system.”
See Also: Offensive Security Tool: CloudFail The attacker must have valid administrative credentials on the device in order to exploit the issue, so the CVSS score comes in at 7.2 rather than critical[...]
___________________________
@hacking_Attack
@Hacking_Video
Cisco Smart Switches Riddled with Severe Security Holes
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Cisco Smart Switches Riddled with Severe Security HolesPost Views: 60
Reading Time: 1 Minute
Cisco has flagged and patched several high-severity security vulnerabilities in its Cisco Small Business 220 Series Smart Switches that could allow session hijacking, arbitrary code execution, cross-site scripting and HTML injection.
It also issued fixes for high-severity problems in the AnyConnect secure mobility client, the Cisco DNA Center and the Cisco Email Security Appliance, along with a slew of patches for medium-severity vulnerabilities in AnyConnect, Jabber, Meeting Server, Unified Intelligence Center and Webex.
The high-severity issues are as follows:
* CVE-2021-1566: Cisco Email Security Appliance and Cisco Web Security Appliance (Certificate-Validation Vulnerability)
* CVE-2021-1134: Cisco DNA Center (Certificate Validation Vulnerability)
* CVE-2021-1541 through 1543; CVE-2021-1571: Cisco Small Business 220 Series Smart Switches (Session Hijacking, Arbitrary Code-Execution, Cross-Site Scripting, HTML Injection)
* CVE-2021-1567: Cisco AnyConnect Secure Mobility Client for Windows with VPN Posture (HostScan) Module (DLL Hijacking)
The most severe issue in this crop of patches is tracked as CVE-2021-1542, in the Cisco Small Business 220 Series Smart Switches. These are entry-level switches that act as the basic building blocks for small- and medium-sized business networks. They’re responsible for sharing network resources and connecting various clients, including computers, printers and servers, to the network and each other, along with security, governing network performance and more.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries The bug rates 7.5 on the 10-point CVSS vulnerability-severity scale, and arises from weak session management for the web-based management interface of the switches. An unauthenticated, remote attacker could use it to bypass authentication protections and gain unauthorized access to the interface, according to the advisory. The attacker could then obtain the privileges of the highjacked session account, which could include administrative privileges, and thus gain free rein on the switch.
“This vulnerability is due to the use of weak session management for session identifier values,” according to Cisco. “An attacker could exploit this vulnerability by using reconnaissance methods to determine how to craft a valid session identifier. A successful exploit could allow the attacker [to] take actions within the management interface with privileges up to the level of the administrative user.” Multiple Patches for Smart SwitchesThere are also multiple other security flaws in the same web-management interface. For instance, the bug tracked as CVE-2021-1541 is an arbitrary code-execution vulnerability that would allow an authenticated, remote attacker to execute arbitrary commands as a root user on the underlying operating system.
“This vulnerability is due to a lack of parameter validation for TFTP configuration parameters,” according to Cisco. “An attacker could exploit this vulnerability by entering crafted input for specific TFTP configuration parameters. A successful exploit could allow the attacker to execute arbitrary commands as a root user on the underlying operating system.”
See Also: Offensive Security Tool: CloudFail The attacker must have valid administrative credentials on the device in order to exploit the issue, so the CVSS score comes in at 7.2 rather than critical[...]
___________________________
@hacking_Attack
@Hacking_Video