Traitor — Automatically Exploit Low-Hanging Fruit For A Root Shell.
https://skynettools.medium.com/traitor-automatically-exploit-low-hanging-fruit-for-a-root-shell-ecdcae60b523?source=rss------bug_bounty-5
https://skynettools.medium.com/traitor-automatically-exploit-low-hanging-fruit-for-a-root-shell-ecdcae60b523?source=rss------bug_bounty-5
Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop…Continue reading on Medium » (https://skynettools.medium.com/traitor-automatically-exploit-low-hanging-fruit-for-a-root-shell-ecdcae60b523?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
The Lazarus heist: How North Korea almost pulled off a billion-dollar hack
https://external-preview.redd.it/DxipTzGjfpgZ9PLRLxNKdFtMwaHGVG9P124jjYT02iU.jpg?width=640&crop=smart&auto=webp&s=a7d82b4e8ad603547b873793191c08d4800d7cd1 submitted by /u/TheseDraw
[link] [comments]
The Lazarus heist: How North Korea almost pulled off a billion-dollar hack
https://external-preview.redd.it/DxipTzGjfpgZ9PLRLxNKdFtMwaHGVG9P124jjYT02iU.jpg?width=640&crop=smart&auto=webp&s=a7d82b4e8ad603547b873793191c08d4800d7cd1 submitted by /u/TheseDraw
[link] [comments]
hacking: security in practice
FEIT Smart Bulbs ARP Poisoning
My parent’s email and financial accounts keep getting hacked and my mother said her phone was being tapped. I sighed and went over to check it out. No malware on her computer or anything. Wiped the router, iPhones, did offline scans, and changed all her passwords.
A week later same thing happens. Odd. I go over and check out the network to see if there’s any suspicious activity/devices. I find that the smart bulbs they got from Costco had very strange activity. Each bulb was using gigabytes of data every day. Not the usual data usage from a light bulb.
I check the app and find that it keeps “updating” it’s firmware OTA and it’s being used by an “iPad”. Nobody in their house has an iPad. I permanently block the light bulbs from the network. A couple hours later it was able to unblock itself. They’re getting ransomware texts from the person. They hacked their financial accounts and their emails through forgetting password.
I thought that was extremely odd considering they have 2FA set up on all their accounts. We find out that every time there was a forget password email, my mother would receive a call from a number. The one caveat is that her iPhone only receives those calls when she’s home. I suspect it’s because she has WiFi calling turned on on her iPhone. They’re able to place themselves between the router and my moms phone and intercept the 2FA phone call for the code. My mother doesn’t answer the call, and shortly after her phone receives the voicemail. We can vaguely hear the person on the other line hearing the 2FA code being announced while their keyboard clicks and types it in.
I alerted apple about this. First they blew me off, and then I sent the screenshots of everything and now I’m meeting with their corporate security team in a few hours.
The IP says China Com, but they could obviously be using a VPN to spoof their location.
I have two questions,
1.
Do you think this is a very remote attack, or do you think it’s someone in range of my parents home?
2.
Is there a way to extract the firmware data and files from the bulbs onto a virtual machine and search for any useful information?
submitted by /u/Squidster777
[link] [comments]
FEIT Smart Bulbs ARP Poisoning
My parent’s email and financial accounts keep getting hacked and my mother said her phone was being tapped. I sighed and went over to check it out. No malware on her computer or anything. Wiped the router, iPhones, did offline scans, and changed all her passwords.
A week later same thing happens. Odd. I go over and check out the network to see if there’s any suspicious activity/devices. I find that the smart bulbs they got from Costco had very strange activity. Each bulb was using gigabytes of data every day. Not the usual data usage from a light bulb.
I check the app and find that it keeps “updating” it’s firmware OTA and it’s being used by an “iPad”. Nobody in their house has an iPad. I permanently block the light bulbs from the network. A couple hours later it was able to unblock itself. They’re getting ransomware texts from the person. They hacked their financial accounts and their emails through forgetting password.
I thought that was extremely odd considering they have 2FA set up on all their accounts. We find out that every time there was a forget password email, my mother would receive a call from a number. The one caveat is that her iPhone only receives those calls when she’s home. I suspect it’s because she has WiFi calling turned on on her iPhone. They’re able to place themselves between the router and my moms phone and intercept the 2FA phone call for the code. My mother doesn’t answer the call, and shortly after her phone receives the voicemail. We can vaguely hear the person on the other line hearing the 2FA code being announced while their keyboard clicks and types it in.
I alerted apple about this. First they blew me off, and then I sent the screenshots of everything and now I’m meeting with their corporate security team in a few hours.
The IP says China Com, but they could obviously be using a VPN to spoof their location.
I have two questions,
1.
Do you think this is a very remote attack, or do you think it’s someone in range of my parents home?
2.
Is there a way to extract the firmware data and files from the bulbs onto a virtual machine and search for any useful information?
submitted by /u/Squidster777
[link] [comments]
reddit
FEIT Smart Bulbs ARP Poisoning
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
UNRESTRICTED FILE UPLOADS
Hi everyone, hope you all are staying safe in this corona time. In this article i am going to demonstrate you the vulnerability which i…Continue reading on Medium »
Read more...
Hi everyone, hope you all are staying safe in this corona time. In this article i am going to demonstrate you the vulnerability which i…Continue reading on Medium »
Read more...
UNRESTRICTED FILE UPLOADS
https://faiyazhacks.medium.com/unrestricted-file-uploads-e361639913b1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://faiyazhacks.medium.com/unrestricted-file-uploads-e361639913b1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
UNRESTRICTED FILE UPLOADS
Hi everyone, hope you all are staying safe in this corona time. In this article i am going to demonstrate you the vulnerability which i…
Hi everyone, hope you all are staying safe in this corona time. In this article i am going to demonstrate you the vulnerability which i…Continue reading on Medium » (https://faiyazhacks.medium.com/unrestricted-file-uploads-e361639913b1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
UNRESTRICTED FILE UPLOADS
Hi everyone, hope you all are staying safe in this corona time. In this article i am going to demonstrate you the vulnerability which i…
How You Can Escalate a Simple HTML Injection Into a Critical SSRF
https://faizannehal.medium.com/how-you-can-escalate-a-simple-html-injection-into-a-critical-ssrf-8cd754e1a114?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://faizannehal.medium.com/how-you-can-escalate-a-simple-html-injection-into-a-critical-ssrf-8cd754e1a114?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How You Can Escalate a Simple HTML Injection Into a Critical SSRF
SSRF or Server Side Request Forgery is a type of vulnerability where the attacker can make the request on behalf of the vulnerable web…
SSRF or Server Side Request Forgery is a type of vulnerability where the attacker can make the request on behalf of the vulnerable web…Continue reading on Medium » (https://faizannehal.medium.com/how-you-can-escalate-a-simple-html-injection-into-a-critical-ssrf-8cd754e1a114?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How You Can Escalate a Simple HTML Injection Into a Critical SSRF
SSRF or Server Side Request Forgery is a type of vulnerability where the attacker can make the request on behalf of the vulnerable web…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
defenselessV1 : Just Another Vulnerable Web Application
defenselessV1 is a vulnerable web application written in PHP/MySQL. This is the first version of this application. The purpose of this application is to create security awareness among developers and new guys in application security. It would soon be updated with with more bugs and a new vulnerable application is also being developed. Please let […]
The post defenselessV1 : Just Another Vulnerable Web Application appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
defenselessV1 : Just Another Vulnerable Web Application
defenselessV1 is a vulnerable web application written in PHP/MySQL. This is the first version of this application. The purpose of this application is to create security awareness among developers and new guys in application security. It would soon be updated with with more bugs and a new vulnerable application is also being developed. Please let […]
The post defenselessV1 : Just Another Vulnerable Web Application appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
defenselessV1 : Just Another Vulnerable Web Application
defenselessV1 is a vulnerable web application written in PHP/MySQL. This is the first version of this application.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Traitor — Automatically Exploit Low-Hanging Fruit For A Root Shell.
https://cdn-images-1.medium.com/max/1367/0*laiuAs4FUyZvuSpD.png
Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Traitor — Automatically Exploit Low-Hanging Fruit For A Root Shell.
https://cdn-images-1.medium.com/max/1367/0*laiuAs4FUyZvuSpD.png
Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Traitor — Automatically Exploit Low-Hanging Fruit For A Root Shell. Linux Privilege Escalation Made Easy
Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop…