Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Xerror : An Automated Penetration Tool
Xerror is an automated penetration tool , which will help security professionals and non professionals to automate their pen testing tasks. Xerror will perform all tests and, at the end generate two reports for executives and analysts. Xerror provides GUI easy to use menu driven options.Internally it supports openVas for vulnerability scanning, Metasploit for exploitation […]
The post Xerror : An Automated Penetration Tool appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Xerror : An Automated Penetration Tool
Xerror is an automated penetration tool , which will help security professionals and non professionals to automate their pen testing tasks. Xerror will perform all tests and, at the end generate two reports for executives and analysts. Xerror provides GUI easy to use menu driven options.Internally it supports openVas for vulnerability scanning, Metasploit for exploitation […]
The post Xerror : An Automated Penetration Tool appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Xerror
Xerror is an automated penetration tool , which will help security professionals and non professionals to automate their pentesting tasks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nibbles HTB Writeup
https://cdn-images-1.medium.com/max/1920/1*Y_V9jMwT6U1MLP0llCmmYQ.png
Hi everyone, this is my writeup for box “Nibbles” found on HackTheBox .
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Nibbles HTB Writeup
https://cdn-images-1.medium.com/max/1920/1*Y_V9jMwT6U1MLP0llCmmYQ.png
Hi everyone, this is my writeup for box “Nibbles” found on HackTheBox .
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nibbles HTB Writeup
Hi everyone, this is my writeup for box “Nibbles” found on HackTheBox .
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Hire a Hacker for iPhone and iOS Devices: A Professional Guide
The best way hire a hacker for iPhone and iOS devices is to hire one who has the experience and know-how to get the job done. However…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Hire a Hacker for iPhone and iOS Devices: A Professional Guide
The best way hire a hacker for iPhone and iOS devices is to hire one who has the experience and know-how to get the job done. However…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Hire a Hacker for iPhone and iOS Devices: A Professional Guide
The best way hire a hacker for iPhone and iOS devices is to hire one who has the experience and know-how to get the job done. However…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cryptography and some tool and techniques for hiding information
https://cdn-images-1.medium.com/max/610/0*7cOdk6XbVJ0UlHBT.png
In computer science, cryptography is a method of hiding information in storage and during communication so that only authorized people can…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cryptography and some tool and techniques for hiding information
https://cdn-images-1.medium.com/max/610/0*7cOdk6XbVJ0UlHBT.png
In computer science, cryptography is a method of hiding information in storage and during communication so that only authorized people can…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cryptography and some tool and techniques for hiding information
In computer science, cryptography is a method of hiding information in storage and during communication so that only authorized people can…
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
CSC CTF 2021 — Flag Shop (Reverse Engineering Android)(Smali Patch) #3
https://cdn-images-1.medium.com/max/1920/1*7LZBbBa2bp5UCd75JxIkog.gif
Pada part kali ini kita akan mengerjakan cara menjadi kaya yang sudah di bahas pada part sebelumnya. yang perlu di note adalah bahwa…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CSC CTF 2021 — Flag Shop (Reverse Engineering Android)(Smali Patch) #3
https://cdn-images-1.medium.com/max/1920/1*7LZBbBa2bp5UCd75JxIkog.gif
Pada part kali ini kita akan mengerjakan cara menjadi kaya yang sudah di bahas pada part sebelumnya. yang perlu di note adalah bahwa…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSC CTF 2021 — Flag Shop (Reverse Engineering Android)(Smali Patch) #3
Pada part kali ini kita akan mengerjakan cara menjadi kaya yang sudah di bahas pada part sebelumnya. yang perlu di note adalah bahwa…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TOP PYTHON LIBRARIES USED FOR HACKING
https://cdn-images-1.medium.com/max/600/1*dDjc6AbqnaDco_29n7aA5w.jpeg
Requests
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TOP PYTHON LIBRARIES USED FOR HACKING
https://cdn-images-1.medium.com/max/600/1*dDjc6AbqnaDco_29n7aA5w.jpeg
Requests
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TOP PYTHON LIBRARIES USED FOR HACKING
Requests
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
VulnCMS : 1 [VulnHub] Walkthrough
https://cdn-images-1.medium.com/max/1587/1*mdShHKGhaUH-AieSHxn4Jg.png
Hello everyone!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
VulnCMS : 1 [VulnHub] Walkthrough
https://cdn-images-1.medium.com/max/1587/1*mdShHKGhaUH-AieSHxn4Jg.png
Hello everyone!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
VulnCMS : 1 [VulnHub] Walkthrough
Hello everyone!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Data for 700M LinkedIn Users Posted for Sale in Cyber-UndergroundPost Views: 215
Reading Time: 1 Minute
A new posting with 700 million LinkedIn records has appeared on a popular hacker forum, according to researchers.
Analysts from Privacy Sharks stumbled across the data put up for sale on RaidForums by a hacker calling himself “GOD User TomLiner.” The advertisement, posted June 22, claims that 700 million records are included in the cache, and included a sample of 1 million records as “proof.”
Privacy Sharks examined the free sample and saw that the records include full names, gender, email addresses, phone numbers and industry information. It’s unclear what the origin of the data is – but the scraping of public profiles is a likely source. That was the engine behind the collection of 500 million LinkedIn records that went up for sale in April. It contained an “aggregation of data from a number of websites and companies” as well “publicly viewable member profile data,” LinkedIn said at the time.
According to LinkedIn, no breach of its networks has occurred this time, either:
“While we’re still investigating this issue, our initial analysis indicates that the dataset includes information scraped from LinkedIn as well as information obtained from other sources,” according to the company’s press statement. “This was not a LinkedIn data breach and our investigation has determined that no private LinkedIn member data was exposed. Scraping data from LinkedIn is a violation of our Terms of Service and we are constantly working to ensure our members’ privacy is protected.”
“This time around, we cannot be sure whether or not the records are a cumulation of data from previous breaches and public profiles, or whether the information is from private accounts,” according to Privacy Shark’s blog post, published Monday. “We employ a strict policy of not supporting sellers of stolen data and, therefore, have not purchased the leaked list to verify all of the records.”
There are are 200 million more records available in the collection this time around, so it’s probable that new data has been scraped and that it’s more than a rehash of the previous group of records, researchers added.
See Also: 30M Dell Devices at Risk for Remote BIOS Attacks, RCE Security Ramifications of Data-ScrapingThe good news is that credit-card data, private message contents and other sensitive information is not a part of the incident, from Privacy Shark’s analysis. That’s not to say there aren’t serious security implications though.
“The leaked information poses a threat to affected LinkedIn users,” according to Privacy Sharks. “With details such as email addresses and phone numbers made available to buyers online, LinkedIn individuals could become the target of spam campaigns, or worse still, victims of identity theft.”
It added, “expert hackers may still be able to track down sensitive data through just an email address. LinkedIn users could also be on the receiving end of email or telephone scams that trick them into sharing sensitive credentials or transferring large amounts of money.”
See Also: Offensive Security Tool: Pixload
Then there are brute-force attacks to be concerned about: “Using email addresses provided in the records, hackers may attempt to access users’ accounts using various combinations of common password characters,” researchers warned.
And finally, the data could be a social-engineering goldmine. Sure, attackers could simply visit public profiles to target someone, but having so many records in one pl[...]
___________________________
@hacking_Attack
@Hacking_Video
Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Data for 700M LinkedIn Users Posted for Sale in Cyber-UndergroundPost Views: 215
Reading Time: 1 Minute
A new posting with 700 million LinkedIn records has appeared on a popular hacker forum, according to researchers.
Analysts from Privacy Sharks stumbled across the data put up for sale on RaidForums by a hacker calling himself “GOD User TomLiner.” The advertisement, posted June 22, claims that 700 million records are included in the cache, and included a sample of 1 million records as “proof.”
Privacy Sharks examined the free sample and saw that the records include full names, gender, email addresses, phone numbers and industry information. It’s unclear what the origin of the data is – but the scraping of public profiles is a likely source. That was the engine behind the collection of 500 million LinkedIn records that went up for sale in April. It contained an “aggregation of data from a number of websites and companies” as well “publicly viewable member profile data,” LinkedIn said at the time.
According to LinkedIn, no breach of its networks has occurred this time, either:
“While we’re still investigating this issue, our initial analysis indicates that the dataset includes information scraped from LinkedIn as well as information obtained from other sources,” according to the company’s press statement. “This was not a LinkedIn data breach and our investigation has determined that no private LinkedIn member data was exposed. Scraping data from LinkedIn is a violation of our Terms of Service and we are constantly working to ensure our members’ privacy is protected.”
“This time around, we cannot be sure whether or not the records are a cumulation of data from previous breaches and public profiles, or whether the information is from private accounts,” according to Privacy Shark’s blog post, published Monday. “We employ a strict policy of not supporting sellers of stolen data and, therefore, have not purchased the leaked list to verify all of the records.”
There are are 200 million more records available in the collection this time around, so it’s probable that new data has been scraped and that it’s more than a rehash of the previous group of records, researchers added.
See Also: 30M Dell Devices at Risk for Remote BIOS Attacks, RCE Security Ramifications of Data-ScrapingThe good news is that credit-card data, private message contents and other sensitive information is not a part of the incident, from Privacy Shark’s analysis. That’s not to say there aren’t serious security implications though.
“The leaked information poses a threat to affected LinkedIn users,” according to Privacy Sharks. “With details such as email addresses and phone numbers made available to buyers online, LinkedIn individuals could become the target of spam campaigns, or worse still, victims of identity theft.”
It added, “expert hackers may still be able to track down sensitive data through just an email address. LinkedIn users could also be on the receiving end of email or telephone scams that trick them into sharing sensitive credentials or transferring large amounts of money.”
See Also: Offensive Security Tool: Pixload
Then there are brute-force attacks to be concerned about: “Using email addresses provided in the records, hackers may attempt to access users’ accounts using various combinations of common password characters,” researchers warned.
And finally, the data could be a social-engineering goldmine. Sure, attackers could simply visit public profiles to target someone, but having so many records in one pl[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Data for 700M LinkedIn Users Posted for Sale in Cyber-UndergroundPost…
ace could make it possible to automate targeted attacks using information about users’ jobs and gender, among other details.
“It is not uncommon to see such data sets being used to send personalized phishing emails, extort ransom or earn money on the Dark Web – especially now that many hackers target job seekers on LinkedIn with bogus job offers, infecting them with a backdoor trojan,” Candid Wuest, Acronis vice president of cyber-protection research, said via email at the time of the first data-scraping incident. “For example, such personalized phishing attacks with LinkedIn lures were used by the Golden Chickens group.”
Users should secure their LinkedIn accounts by updating passwords and enabling two-factor authentication. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1920px-NVidia_G71_GPU-90x90.jpg NVIDIA Patches High-Severity GeForce Spoof-Attack Bug1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-90x90.jpg Cisco ASA Bug Now Actively Exploited as PoC Drops2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-7-90x90.png 30M Dell Devices at Risk for Remote BIOS Attacks, RCE5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/09_linux_kernel_vuln-e1624449271917-90x90.png Unpatched Linux Marketplace Bugs Allow Wormable Attacks, Drive-By RCE6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-6-1-90x90.png Email Bug Allows Message Snooping, Credential Theft1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-6-90x90.png Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/14.4.2-90x90.png New iPhone Bug Breaks Your WiFi: Here’s The Fix1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-patch-90x90.png Cisco Smart Switches Riddled with Severe Security Holes2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-5-90x90.png Millions of Connected Cameras Open to Eavesdropping2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif-6-446db01f6f32-90x90.jpg Apple Hurries Patches for Safari Bugs Under Active Attack2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
“It is not uncommon to see such data sets being used to send personalized phishing emails, extort ransom or earn money on the Dark Web – especially now that many hackers target job seekers on LinkedIn with bogus job offers, infecting them with a backdoor trojan,” Candid Wuest, Acronis vice president of cyber-protection research, said via email at the time of the first data-scraping incident. “For example, such personalized phishing attacks with LinkedIn lures were used by the Golden Chickens group.”
Users should secure their LinkedIn accounts by updating passwords and enabling two-factor authentication. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1920px-NVidia_G71_GPU-90x90.jpg NVIDIA Patches High-Severity GeForce Spoof-Attack Bug1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-90x90.jpg Cisco ASA Bug Now Actively Exploited as PoC Drops2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-7-90x90.png 30M Dell Devices at Risk for Remote BIOS Attacks, RCE5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/09_linux_kernel_vuln-e1624449271917-90x90.png Unpatched Linux Marketplace Bugs Allow Wormable Attacks, Drive-By RCE6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-6-1-90x90.png Email Bug Allows Message Snooping, Credential Theft1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-6-90x90.png Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/14.4.2-90x90.png New iPhone Bug Breaks Your WiFi: Here’s The Fix1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-patch-90x90.png Cisco Smart Switches Riddled with Severe Security Holes2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-5-90x90.png Millions of Connected Cameras Open to Eavesdropping2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif-6-446db01f6f32-90x90.jpg Apple Hurries Patches for Safari Bugs Under Active Attack2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Forblaze - A Python Mac Steganography Payload Generator
http://www.kitploit.com/2021/06/forblaze-python-mac-steganography.html
http://www.kitploit.com/2021/06/forblaze-python-mac-steganography.html
Forblaze is a project designed to provide steganography capabilities to Mac OS payloads. Using python3, it will build an Obj-C file for you which will be compiled to pull desired encrypted URLs out of the stego file, fetch payloads over https, and execute them directly into memory. It utilizes custom encryption (https://www.kitploit.com/search/label/Encryption) - it is not cryptographically secure, but purely to thwart analysis (https://www.kitploit.com/search/label/Analysis) by AV engines. It is a slight deviation on my previously built custom encryption for Windows, called Rubicon, and is more simple in practice. Forblaze utilizes header and footer bytes to identify where in the stego file your encrypted bytes are, and then decrypts them with a hard-coded key in compile_forblaze.m. This key can be saved and re-used, with the effect that a different URL could be used to fetch a differ ent payload, and the same compiled forblaze should still be able to execute and process it (provided the header and footer bytes aren't changed, and the new stego file is uploaded to the correct location.)
Requirements:
Python3 (only tested with Python3.9+), and some associated Python libraries - pip3 should take care of any python dependencies you need. In addition, clang will be used for compilation, and forblaze should be run on a mac so that forblaze can be correctly compiled.
Usage
usage: forblaze_url.py [-h] [-innocent_path PATH] [-o OUTPUT] [-len_key LENGTH_OF_KEY] [-compile_file COMPILE_FILE] [-url_to_encrypt URL] [-supply_key SUPPLIED_KEY] [-stego_location STEGO_LOCATION] [-compiled_binary COMPILED_BINARY] Generate stego for implants. optional arguments: -h, --help show this help message and exit -innocent_path PATH Provide the full path to the innocent file to be used. -o OUTPUT Provide the path where you want your stego file to be placed. -len_key LENGTH_OF_KEY Provide a positive integer that will be the length of the key in bytes. Default is 16. Must be between 10 and 150 bytes. You can change this yourself, just be wary that larger key sizes will add bloat to your payload and are not necessarily going to make your encryption stronger -compile_file COMPILE_FILE Provide the path to the C++ file you want to edit. -url_to_encrypt URL Provide the URL you want to stick inside the compile file. -supply_key SUPPLIED_KEY If you wish to use a specific key, provide it here. It must be in the format: -supply_key "\x6e\x60\x..." - aka two double slashes are needed between each byte, or else it WILL NOT WORK. -stego_location STEGO_LOCATION You must provide a location on target where the stego file will reside. It is wise to follow strict full paths: /Users/<>/Documents/file.jpg for example. -compiled_binary COMPILED_BINARY Give the name of the compiled binary to extract the URL and run code in memory from the stego file. The default is forblaze.
Opsec Concerns
Honestly, not too many. Mac OS detections are still pretty poor, especially for in-memory activity. However, as a warning, this method (based almost entirely on https://blogs.blackberry.com/en/2017/02/running-executables-on-macos-from-memory) will NOT WORK FOR GO COMPILED MACHOS. Every other macho I've tested works fine, so if you really want to use Go C2s such as Mythic, I recommend crafting (https://www.kitploit.com/search/label/Crafting) a custom macho which can function similar to osascript, and call a jxa payload in memory directly. As an exercise for the reader, you could also call payload bytes directly vs a URL with some slight modifications to this code. I would recommend changing this like the number of random bytes generated from the default, and changing the default header and footer bytes that forblaze uses to find the payload in the stego file (as well as the length of those header and footer bytes to perhaps be more inconspicious).
Detection/Prevention
Requirements:
Python3 (only tested with Python3.9+), and some associated Python libraries - pip3 should take care of any python dependencies you need. In addition, clang will be used for compilation, and forblaze should be run on a mac so that forblaze can be correctly compiled.
Usage
usage: forblaze_url.py [-h] [-innocent_path PATH] [-o OUTPUT] [-len_key LENGTH_OF_KEY] [-compile_file COMPILE_FILE] [-url_to_encrypt URL] [-supply_key SUPPLIED_KEY] [-stego_location STEGO_LOCATION] [-compiled_binary COMPILED_BINARY] Generate stego for implants. optional arguments: -h, --help show this help message and exit -innocent_path PATH Provide the full path to the innocent file to be used. -o OUTPUT Provide the path where you want your stego file to be placed. -len_key LENGTH_OF_KEY Provide a positive integer that will be the length of the key in bytes. Default is 16. Must be between 10 and 150 bytes. You can change this yourself, just be wary that larger key sizes will add bloat to your payload and are not necessarily going to make your encryption stronger -compile_file COMPILE_FILE Provide the path to the C++ file you want to edit. -url_to_encrypt URL Provide the URL you want to stick inside the compile file. -supply_key SUPPLIED_KEY If you wish to use a specific key, provide it here. It must be in the format: -supply_key "\x6e\x60\x..." - aka two double slashes are needed between each byte, or else it WILL NOT WORK. -stego_location STEGO_LOCATION You must provide a location on target where the stego file will reside. It is wise to follow strict full paths: /Users/<>/Documents/file.jpg for example. -compiled_binary COMPILED_BINARY Give the name of the compiled binary to extract the URL and run code in memory from the stego file. The default is forblaze.
Opsec Concerns
Honestly, not too many. Mac OS detections are still pretty poor, especially for in-memory activity. However, as a warning, this method (based almost entirely on https://blogs.blackberry.com/en/2017/02/running-executables-on-macos-from-memory) will NOT WORK FOR GO COMPILED MACHOS. Every other macho I've tested works fine, so if you really want to use Go C2s such as Mythic, I recommend crafting (https://www.kitploit.com/search/label/Crafting) a custom macho which can function similar to osascript, and call a jxa payload in memory directly. As an exercise for the reader, you could also call payload bytes directly vs a URL with some slight modifications to this code. I would recommend changing this like the number of random bytes generated from the default, and changing the default header and footer bytes that forblaze uses to find the payload in the stego file (as well as the length of those header and footer bytes to perhaps be more inconspicious).
Detection/Prevention