Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Stored XSS in Webinar Registration on Redact.com

First of all, I thank everyone, who follow me on medium and your applause.Continue reading on Medium »
Read more...
First of all, I thank everyone, who follow me on medium and your applause.Continue reading on Medium » (https://vpugazhenthi98.medium.com/stored-xss-in-webinar-registration-on-redact-com-be0d6243e01d?source=rss------bug_bounty-5)
hacking: security in practice
Analyzing an exe

So I work from home and noticed that when connecting to the company's server, there is an .exe that installs and then runs forever in the background (even if you are no longer connected to the company) and starts as soon as you open your computer. I need to know if there is a way to know what it does since I feel they are spying on me, and I am using my personal computer and if they are doing this they are breaking the law.



I would appreciate any guidelines.

submitted by /u/BamGfAsRpd
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Everything You Need To Know About The Dark Web in 2021

https://cdn-images-1.medium.com/max/600/0*Fq2--DHCiQ0Sr_gZ.png
Just hearing the term Dark Web conjures up images of digital back alleys where people can engage in all sorts of illicit activities. We…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data TheftPost Views: 65
Reading Time: 1 Minute
Flaws impacting millions of internet of things (IoT) devices running NVIDIA’s Jetson chips open the door for a variety of hacks, including denial-of-service (DoS) attacks or the siphoning of data.
NVIDIA released patches addressing nine high-severity vulnerabilities including eight additional bugs of less severity. The patches fix a wide swath of NVIDIA’s chipsets typically used for embedded computing systems, machine-learning applications and autonomous devices such as robots and drones.

Impacted products include Jetson chipset series; AGX Xavier, Xavier NX/TX1, Jetson TX2 (including Jetson TX2 NX), and Jetson Nano devices (including Jetson Nano 2GB) found in the NVIDIA JetPack software developers kit. The patches were delivered as part of NVIDIA’s June security bulletin, released Friday. Most Important PatchThe most severe bug, tracked as CVE‑2021‑34372, opens the Jetson framework to a buffer-overflow attack by an adversary. According to the NVIDIA security bulletin, the attacker would need network access to a system to carry out an attack, but the company warned the vulnerability is not complex to exploit and that an adversary with little to low access rights could launch it. It added that an attack could give an adversary persistent access to components – other than the NVIDIA chipset targeted – and allow a hacker to manipulate and or sabotage a targeted system.

“[The Jetson] driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information disclosure, escalation of privileges and denial of service (DoS),” according to the security bulletin, posted on Friday.

Oblivious transfer extensions (OTE) are low-level cryptographic algorithms used by Jetson chipsets to process private-set-intersection protocols used to secure data as the chip processes data.
See Also: New iPhone Bug Breaks Your WiFi: Here’s The Fix High-Severity RoundupOther high-severity bugs patched by NVIDIA include vulnerabilities with severity ratings of between 7.9 and 7, which include CVE‑2021‑34373, CVE‑2021‑34374, CVE‑2021‑34375, CVE‑2021‑34376,  CVE‑2021‑34377, CVE‑2021‑34378, CVE‑2021‑34379 and CVE‑2021‑34380. Six of the bugs, if exploited, could allow a local attacker to trigger a DoS attack.

One of the bugs (CVE‑2021‑34373), with a 7.9 severity rating, impacts Jetson’s trusted Linux kernel and opens the door to a heap-based buffer overflow attack. This type attack is directed at the chip’s heap data memory framework, where the component is manipulated to generate errors.

“Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service,” NVIDIA wrote.
See Also: Offensive Security Tool: CloudFail Besides firmware, the chipmaker issued patches (CVE‑2021‑34372 through CVE‑2021‑34397) to address endpoint software for Jetson TX1, TX2 series, TX2 NX, AGX Xavier series, Xavier NX, Nano and Nano 2GB. For those bugs, NVIDIA credited bug hunter Frédéric Perriot of the Apple Media Products RedTeam for reporting the issues.

“[Updates address] security issues that may lead to escalation of privileges, denial of service and information disclosure. To pr[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks…
otect your system, download and install the latest Debian packages from the APT repositories,” NVIDIA wrote. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/14.4.2-90x90.png New iPhone Bug Breaks Your WiFi: Here’s The Fix23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-patch-90x90.png Cisco Smart Switches Riddled with Severe Security Holes4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-5-90x90.png Millions of Connected Cameras Open to Eavesdropping5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif-6-446db01f6f32-90x90.jpg Apple Hurries Patches for Safari Bugs Under Active Attack6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Microsoft-Teams-e1623702241390-90x90.png Microsoft Teams: Very Bad Tabs Could Have Led to BEC1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/FIFA-21-90x90.jpg Hackers Steal FIFA 21 Source Code, Tools in EA Breach1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-3-90x90.png Chrome Browser Bug Under Active Attack – Update your chrome now2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries2 weeks ago
The post Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft first appeared on Black Hat Ethical Hacking.
Finding Vulnerabilities
https://www.reddit.com/r/Pentesting/comments/o5l5il/finding_vulnerabilities/

<!-- SC_OFF -->Hi, I have some queries. If we want to check or find websites having vulnerabilities ,do we have to try every website one by one and try exploit vulnerabilities method (for eg. Php shell upload) on each? Or there are specific tools to find vulnerability. Suppose if I found 700 subdomains for a website ,So do I need to do as I said above (one by one for every subdomain.? For eg. If I am trying php shell upload to a website but I am not able to see the file location address . So does it mean the website is not vulnerable to a php shell upload attack.? <!-- SC_ON --> submitted by /u/Arav_b (https://www.reddit.com/user/Arav_b)
[link] (https://www.reddit.com/r/Pentesting/comments/o5l5il/finding_vulnerabilities/) [comments] (https://www.reddit.com/r/Pentesting/comments/o5l5il/finding_vulnerabilities/)
Swift-Attack - Unit Tests For Blue Teams To Aid With Building Detections For Some Common macOS Post Exploitation Methods
http://www.kitploit.com/2021/06/swift-attack-unit-tests-for-blue-teams.html