Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking the hackers through bug bounty programs

iam explaining about an exploit that is unfixed. i found this 2yrs ago but still it is there.you can try your self.many malicious programs…Continue reading on Medium »
Read more...
IoT: Internet of Things or Intrusion optimising Technology?

Developing on episode 3 of our podcast with security in terms of the Internet of things(IoT)Continue reading on Medium »
Read more...
Traitor — Automatically Exploit Low-Hanging Fruit For A Root Shell.

Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop…Continue reading on Medium »
Read more...
Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop…Continue reading on Medium » (https://skynettools.medium.com/traitor-automatically-exploit-low-hanging-fruit-for-a-root-shell-ecdcae60b523?source=rss------bug_bounty-5)
hacking: security in practice
FEIT Smart Bulbs ARP Poisoning

My parent’s email and financial accounts keep getting hacked and my mother said her phone was being tapped. I sighed and went over to check it out. No malware on her computer or anything. Wiped the router, iPhones, did offline scans, and changed all her passwords.

A week later same thing happens. Odd. I go over and check out the network to see if there’s any suspicious activity/devices. I find that the smart bulbs they got from Costco had very strange activity. Each bulb was using gigabytes of data every day. Not the usual data usage from a light bulb.

I check the app and find that it keeps “updating” it’s firmware OTA and it’s being used by an “iPad”. Nobody in their house has an iPad. I permanently block the light bulbs from the network. A couple hours later it was able to unblock itself. They’re getting ransomware texts from the person. They hacked their financial accounts and their emails through forgetting password.

I thought that was extremely odd considering they have 2FA set up on all their accounts. We find out that every time there was a forget password email, my mother would receive a call from a number. The one caveat is that her iPhone only receives those calls when she’s home. I suspect it’s because she has WiFi calling turned on on her iPhone. They’re able to place themselves between the router and my moms phone and intercept the 2FA phone call for the code. My mother doesn’t answer the call, and shortly after her phone receives the voicemail. We can vaguely hear the person on the other line hearing the 2FA code being announced while their keyboard clicks and types it in.

I alerted apple about this. First they blew me off, and then I sent the screenshots of everything and now I’m meeting with their corporate security team in a few hours.

The IP says China Com, but they could obviously be using a VPN to spoof their location.

I have two questions,

1.
Do you think this is a very remote attack, or do you think it’s someone in range of my parents home?

2.
Is there a way to extract the firmware data and files from the bulbs onto a virtual machine and search for any useful information?
submitted by /u/Squidster777
[link] [comments]
UNRESTRICTED FILE UPLOADS

Hi everyone, hope you all are staying safe in this corona time. In this article i am going to demonstrate you the vulnerability which i…Continue reading on Medium »
Read more...