Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Deep Web
Incest

Are there incest(real) on the dark web? If yes how do i find it ? Is incest illegal?

submitted by /u/Alex_rajbahak
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Bug bounty methodology V4.0 — Demonstrated

A practical demonstration of my bug bounty methodologyContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
CISA Offers New Mitigation for PrintNightmare Bug

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg CISA Offers New Mitigation for PrintNightmare BugPost Views: 324
Reading Time: 1 Minute
The U.S. government has stepped in to offer a mitigation for a critical remote code execution (RCE) vulnerability in the Windows Print Spooler service that may not have been fully patched by Microsoft’s initial effort to fix it.
To mitigate the bug, dubbed PrintNightmare, the CERT Coordination Center (CERT/CC) has released a VulNote for CVE-2021-1675 urging system administrations to disable the Windows Print Spooler service in Domain Controllers and systems that do not print, the Cybersecurity Infratructure and Security Administration (CISA) said in a release Thursday. CERT/CC is part of the Software Engineering Institute, a federally funded research center operated by Carnegie Mellon University.

“While Microsoft has released an update for CVE-2021-1675, it is important to realize that this update does NOT protect Active Directory domain controllers, or systems that have Point and Print configured with the NoWarningNoElevationOnInstall option configured,” CERT/CC researchers wrote in the note.

The mitigation is in response to a scenario that unfolded earlier this week when a proof-of-concept (POC) for PrintNightmare was dropped on GitHub on Tuesday. While it was taken back down within a few hours, the code was copied and remains in circulation on the platform. An attacker can use the POC to exploit the vulnerability to take control of an affected system.

In the meantime, Microsoft Thursday put out a new advisory of its own on PrintNightmare that assigns a new CVE and seems to suggest a new attack vector while attempting to clarify confusion that has arisen over it.
See Also: PoC Exploit Circulating for Critical Windows Print Spooler Bug While the company originally addressed CVE-2021-1675 in June’s Patch Tuesday updates as a minor elevation-of-privilege vulnerability, the listing was updated last week after researchers from Tencent and NSFOCUS TIANJI Lab figured out it could be used for RCE.

However, soon after it became clear to many experts that the patch appears to fail against the RCE aspect of the bug—hence CISA’s offer of another mitigation and Microsoft’s update. Assignment of New CVE?Regarding the latter, the company dropped a notice Thursday for a bug called “Windows Print Spooler Remote Code Execution Vulnerability” that appears to be the same vulnerability, but with a different CVE number—in this case, CVE-2021-34527.

The description of the bug sounds like PrintNightmare; indeed, Microsoft acknowledges that it is “an evolving situation.

“A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations,” according to the notice. “An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

In a “FAQ” section in the security update, Microsoft attempts to explain CVE-2021-34527’s connection to CVE-2021-1675.
See Also: Offensive Security Tool: GoSpider
“Is this the vulnerability that has been referred to publicly as PrintNightmare? Yes, Microsoft has assigned CVE-2021-34527 to this vulnerability,” the company wrote.

However, the answer to the question “Is this vulnerability related to CVE-2021-1675?” suggests that CVE-2021-34527 is a different issue.

“This vulnerability is similar but distinct from the vulnerability that is assigned CVE-2021-1675, which addresses a di[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking CISA Offers New Mitigation for PrintNightmare Bug https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg CISA Offers New Mitigation for PrintNightmare BugPost Views: 324 Reading Time:…
fferent vulnerability in RpcAddPrinterDriverEx(),” the company wrote. “The attack vector is different as well. CVE-2021-1675 was addressed by the June 2021 security update.”

Microsoft goes on to explain that CVE-2021-34527 existed before the June Patch Tuesday updates and that it affects domain controllers in “all versions of Windows.”

“We are still investigating whether all versions are exploitable,” the company wrote. “We will update this CVE when that information is evident.”

Microsoft did not assign a score to CVE-2021-34527, citing its ongoing investigation. Two Vulnerabilities?In retrospect, one security researcher noted to Threatpost when news of PrintNightmare surfaced Tuesday that it was “curious” that the CVE for the original vulnerability was “-1675,” observing that “most of the CVEs Microsoft patched in June are -31000 and higher.”

“This could be an indicator that they have known about this bug for some time, and fully addressing it is not trivial,” Dustin Childs of Trend Micro’s Zero Day Initiative told Threatpost at the time. Now it appears that perhaps Microsoft was patching only part of a more complex vulnerability. The likely scenario appears to be that there are two bugs in Windows Print Spooler that could offer attackers some kind of exploit chain or be used separately to take over systems.

While one flaw may indeed have been addressed in June’s Patch Tuesday update, the other could be mitigated by CERT/CC’s workaround—or could remain to be patched by a future Microsoft update that comes after the company completes its investigation.

The company’s release Thursday of a new CVE related to PrintNightmare seems to be an initial attempt to clarify the situation, though given its developing nature, it remains a bit hazy for now. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/router-90x90.jpg Netgear Authentication Bypass Allows Router Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/windows-bug-bounty-90x90.jpg PoC Exploit Circulating for Critical Windows Print Spooler Bug5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/linkedin-90x90.png Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1920px-NVidia_G71_GPU-90x90.jpg NVIDIA Patches High-Severity GeForce Spoof-Attack Bug7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-90x90.jpg Cisco ASA Bug Now Actively Exploited as PoC Drops1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-7-90x90.png 30M Dell Devices at Risk for Remote BIOS Attacks, RCE2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/09_linux_kernel_vuln-e1624449271917-90x90.png Unpatched Linux Marketplace Bugs Allow Wormable Attacks, Drive-By RCE2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-6-1-90x90.png Email Bug Allows Message Snooping, Credential Theft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-6-90x90.png Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/14.4.2-90x90.png New iPhone Bug Breaks Your WiFi: Here’s The Fix2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post CISA Offers New Mitigation for PrintNightmare Bug first appeared on Black Hat Ethical Hacking.
Salus (Security Automation (https://www.kitploit.com/search/label/Automation) as a Lightweight Universal Scanner), named after the Roman goddess of protection (https://en.wikipedia.org/wiki/Salus), is a tool for coordinating the execution of security scanners. You can run Salus on a repository via the Docker daemon and it will determine which scanners (https://www.kitploit.com/search/label/Scanners) are relevant, run them and provide the output. Most scanners are other mature open source projects which we include directly in the container.
Salus is particularly useful for CI/CD pipelines because it becomes a centralized place to coordinate scanning across a large fleet of repositories. Typically, scanners are configured at the repository level for each project. This means that when making org wide changes to how the scanners are run, each repository must be updated. Instead, you can update Salus and all builds will instantly inherit the change. Salus supports powerful configuration that allows for global defaults and local tweaks. Finally, Salus can report metrics on each repository, such as what packages are included or what concerns exist. These reports can be centrally evaluated in your infrastructure (https://www.kitploit.com/search/label/Infrastructure) to allow for scalable security tracking.
Using Salus
# Navigate to the root directory of the project you want to run Salus on
cd /path/to/repo

# Run the following line while in the root directory (No edits necessary)
docker run --rm -t -v $(pwd):/home/repo coinbase/salus
Supported Scanners
Bandit (https://github.com/coinbase/salus/blob/master/docs/scanners/bandit.md) - Execution of Bandit (https://pypi.org/project/bandit/) 1.6.2, looks for common security issues in Python code. Brakeman (https://github.com/coinbase/salus/blob/master/docs/scanners/brakeman.md) - Execution of Brakeman (https://brakemanscanner.org/) 4.10.0, looks for vulnerable (https://www.kitploit.com/search/label/Vulnerable) code in Rails projects. semgrep (https://github.com/coinbase/salus/blob/master/docs/scanners/semgrep.md) - Execution of semgrep 0.36.0 which looks for semantic and syntactical patterns in code at the AST level. BundleAudit (https://github.com/coinbase/salus/blob/master/docs/scanners/bundle_audit.md) - Execution of bundle-audit (https://github.com/rubysec/bundler-audit) 0.7.0.1, looks for CVEs in ruby gem dependencies. Gosec (https://github.com/coinbase/salus/blob/master/docs/scanners/gosec.md) - Execution of gosec (https://github.com/securego/gosec) 2.7.0, looks for security problems in go code. npm audit (https://github.com/coinbase/salus/blob/master/docs/scanners/npm_audit.md) - Execution of npm audit 6.14.8 which looks for CVEs in node module dependencies. yarn audit (https://github.com/coinbase/salus/blob/master/docs/scanners/yarn_audit.md) - Execution of yarn audit 1.22.0 which looks for CVEs in node module dependencies. PatternSearch (https://github.com/coinbase/salus/blob/master/docs/scanners/pattern_search.md) - Execution of sift 0.9.0, looks for certain strings in a project that might be dangerous or could require that certain strings be present. Cargo Audit (https://github.com/coinbase/salus/blob/master/docs/scanners/cargo_audit.md) - Execution of Cargo Audit (https://github.com/RustSec/cargo-audit) 0.14.0 Audit Cargo.lock files for crates with security vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) reported to the RustSec Advisory Database
Dependency Tracking
Salus also parses dependency files and reports which libraries and versions are being used. This can be useful for tracking dependencies across your fleet. Currently supported languages are: Ruby Node.js Python Go Rust
Configuration

___________________________
@hacking_Attack
@Hacking_Video
Salus is designed to be highly configurable (https://github.com/coinbase/salus/blob/master/docs/configuration.md) so that it can work in many different types of environments and with many different scanners. It supports environment variable interpolation and cascading configurations, and can read configuration and post reports over HTTP. Sometimes it's necessary to ignore certain CVEs, rules, tests, groups, directories, or otherwise modify the default configuration for a scanner. The docs/scanners directory (https://github.com/coinbase/salus/blob/master/docs/scanners) explains how to do so for each scanner that Salus supports. If you would like to build custom scanners or support more languages that are not currently supported, you can use this method of building custom Salus images (https://github.com/coinbase/salus/blob/master/docs/custom_salus.md).
CircleCI Integration
Salus can be integrated with CircleCI by using a public Orb. All Salus configuration options are supported, and defaults are the same as for Salus itself. Example CircleCI config.yml: version: 2.1

orbs:
salus: federacy/salus@3.0.0

workflows:
main:
jobs:
- salus/scan
Orb documentation (https://github.com/coinbase/salus/blob/master/integrations/circleci/README.md)
Github Actions Integration
Salus can also be used with Github Actions. Example .github/workflows/main.yml: on: [push]

jobs:
salus_scan_job:
runs-on: ubuntu-latest
name: Salus Security Scan Example
steps:
- uses: actions/checkout@v1
- name: Salus Scan
id: salus_scan
uses: federacy/scan-action@0.1.1
Github Action documentation (https://github.com/federacy/scan-action)
Using Salus in your Repo
For your given CI, update the config file to run salus. In circle, it will look like this: docker run --rm -t -v $(pwd):/home/repo coinbase/salus coinbase/salus pulls the docker image
Detailed Documentation (https://github.com/coinbase/salus/blob/master/docs)

Development Contribution to this project is extremely welcome and it's our sincere hope that the work we've done to this point only serves as a foundation for allowing the security/development communities as a whole to come together to improve the security of everyone's infrastructure. You can read more about getting your development environment set up (https://github.com/coinbase/salus/blob/master/docs/development.md), or the architecture of Salus (https://github.com/coinbase/salus/blob/master/docs/architecture.md).

Download Salus (https://github.com/coinbase/salus)

___________________________
@hacking_Attack
@Hacking_Video