Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Kaseya ransomware supply chain attack: What you need to know
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Kaseya ransomware supply chain attack: What you need to knowPost Views: 70
Reading Time: 2 Minutes
Kaseya, an IT solutions developer for MSPs and enterprise clients, announced that it had become the victim of a cyberattack on July 2, over the American Independence Day weekend.
It appears that attackers have carried out a supply chain ransomware attack by leveraging a vulnerability in Kaseya’s VSA software against multiple managed service providers (MSP) – and their customers.
The attack is reminiscent of the SolarWinds security fiasco, in which attackers managed to compromise the vendor’s software to push a malicious update to thousands of customers. However, we are yet to find out just how widespread Kaseya’s ransomware incident will prove to be.
Here is everything we know so far. ZDNet will update this primer as we learn more. What is Kaseya?Kaseya‘s international headquarters is in Dublin, Ireland, and the company has a US headquarters in Miami, Florida. The vendor maintains a presence in 10 countries.
Kaseya provides IT solutions including VSA, a unified remote-monitoring and management tool for handling networks and endpoints. In addition, the company provides compliance systems, service desks, and a professional services automation platform.
The firm’s software is designed with enterprises and managed service providers (MSPs) in mind, and Kaseya says that over 40,000 organizations worldwide use at least one Kaseya software solution. As a provider of technology to MSPs, which serve other companies, Kaseya is central to a wider software supply chain.
See Also: PoC Exploit Circulating for Critical Windows Print Spooler Bug What happened?On July 2 at 2:00 PM EDT, as previously reported by ZDNet, Kaseya CEO Fred Voccola announced “a potential attack against the VSA that has been limited to a small number of on-premise customers.”
At the same time, out of an abundance of caution, Voccola urged clients to immediately shut down their VSA servers.
“It’s critical that you do this immediately because one of the first things the attacker does is shut off administrative access to the VSA,” the executive said.
Customers were notified of the breach via email, phone, and online notices.
As Kaseya’s Incident Response team investigated, the vendor also decided to proactively shut down its SaaS servers and pull its data centers offline.
By July 4, the company had revised its thoughts on the severity of the incident, calling itself the “victim of a sophisticated cyberattack.”
Cyber forensics experts from FireEye’s Mandiant team, alongside other security companies, have been pulled in to assist.
“Our security, support, R&D, communications, and customer teams continue to work around the clock in all geographies to resolve the issue and restore our customers to service,” Kaseya said, adding that more time is needed before its data centers are brought back online.
Once the SaaS servers are operational, Kaseya will publish a schedule for distributing a security patch to on-prem clients.
In a July 5 update, Kaseya said that a fix is being developed and would first be deployed to SaaS environments.
“We are developing the new patch for on-premises clients in parallel with the SaaS Data Center restoration,” the company said. “We are deploying in SaaS first as we control every aspect of that environment. Once that has begun, we will publish the schedule for distributing the patch for on-premises customers.”
See Also: Offensive Security Tool: GoS[...]
Kaseya ransomware supply chain attack: What you need to know
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Kaseya ransomware supply chain attack: What you need to knowPost Views: 70
Reading Time: 2 Minutes
Kaseya, an IT solutions developer for MSPs and enterprise clients, announced that it had become the victim of a cyberattack on July 2, over the American Independence Day weekend.
It appears that attackers have carried out a supply chain ransomware attack by leveraging a vulnerability in Kaseya’s VSA software against multiple managed service providers (MSP) – and their customers.
The attack is reminiscent of the SolarWinds security fiasco, in which attackers managed to compromise the vendor’s software to push a malicious update to thousands of customers. However, we are yet to find out just how widespread Kaseya’s ransomware incident will prove to be.
Here is everything we know so far. ZDNet will update this primer as we learn more. What is Kaseya?Kaseya‘s international headquarters is in Dublin, Ireland, and the company has a US headquarters in Miami, Florida. The vendor maintains a presence in 10 countries.
Kaseya provides IT solutions including VSA, a unified remote-monitoring and management tool for handling networks and endpoints. In addition, the company provides compliance systems, service desks, and a professional services automation platform.
The firm’s software is designed with enterprises and managed service providers (MSPs) in mind, and Kaseya says that over 40,000 organizations worldwide use at least one Kaseya software solution. As a provider of technology to MSPs, which serve other companies, Kaseya is central to a wider software supply chain.
See Also: PoC Exploit Circulating for Critical Windows Print Spooler Bug What happened?On July 2 at 2:00 PM EDT, as previously reported by ZDNet, Kaseya CEO Fred Voccola announced “a potential attack against the VSA that has been limited to a small number of on-premise customers.”
At the same time, out of an abundance of caution, Voccola urged clients to immediately shut down their VSA servers.
“It’s critical that you do this immediately because one of the first things the attacker does is shut off administrative access to the VSA,” the executive said.
Customers were notified of the breach via email, phone, and online notices.
As Kaseya’s Incident Response team investigated, the vendor also decided to proactively shut down its SaaS servers and pull its data centers offline.
By July 4, the company had revised its thoughts on the severity of the incident, calling itself the “victim of a sophisticated cyberattack.”
Cyber forensics experts from FireEye’s Mandiant team, alongside other security companies, have been pulled in to assist.
“Our security, support, R&D, communications, and customer teams continue to work around the clock in all geographies to resolve the issue and restore our customers to service,” Kaseya said, adding that more time is needed before its data centers are brought back online.
Once the SaaS servers are operational, Kaseya will publish a schedule for distributing a security patch to on-prem clients.
In a July 5 update, Kaseya said that a fix is being developed and would first be deployed to SaaS environments.
“We are developing the new patch for on-premises clients in parallel with the SaaS Data Center restoration,” the company said. “We are deploying in SaaS first as we control every aspect of that environment. Once that has begun, we will publish the schedule for distributing the patch for on-premises customers.”
See Also: Offensive Security Tool: GoS[...]
Black Hat Ethical Hacking
Kaseya ransomware supply chain attack: What you need to know
Kaseya ransomware supply chain attack: What you need to know
How I got Hall of Fame in 30 Second from CERT-EU
Hello Amazing People ,Continue reading on Medium »
Read more...
Hello Amazing People ,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
RomBuster : A Router Exploitation Tool That Allows To Disclosure Network Router Admin Password
RomBuster is a router exploitation tool that allows to disclosure network router admin password. Features Exploits vulnerabilities in most popular routers such as D-Link, Zyxel, TP-Link and Huawei. Optimized to exploit multiple routers at one time from list. Simple CLI and API usage. Installation pip3 install git+https://github.com/EntySec/RomBuster Basic Usage To use RomBuster just type rombuster in your terminal. usage: rombuster [-h] [-o […]
The post RomBuster : A Router Exploitation Tool That Allows To Disclosure Network Router Admin Password appeared first on Kali Linux Tutorials.
RomBuster : A Router Exploitation Tool That Allows To Disclosure Network Router Admin Password
RomBuster is a router exploitation tool that allows to disclosure network router admin password. Features Exploits vulnerabilities in most popular routers such as D-Link, Zyxel, TP-Link and Huawei. Optimized to exploit multiple routers at one time from list. Simple CLI and API usage. Installation pip3 install git+https://github.com/EntySec/RomBuster Basic Usage To use RomBuster just type rombuster in your terminal. usage: rombuster [-h] [-o […]
The post RomBuster : A Router Exploitation Tool That Allows To Disclosure Network Router Admin Password appeared first on Kali Linux Tutorials.
Hacking Microservices For Fun and Bounty
Understand How Microservices Work and Ways to break through it.Continue reading on Medium »
Read more...
Understand How Microservices Work and Ways to break through it.Continue reading on Medium »
Read more...
Hacking Microservices For Fun and Bounty
https://mayank-01.medium.com/hacking-microservices-for-fun-and-bounty-5cc302769e94?source=rss------bug_bounty-5
https://mayank-01.medium.com/hacking-microservices-for-fun-and-bounty-5cc302769e94?source=rss------bug_bounty-5
Understand How Microservices Work and Ways to break through it.Continue reading on Medium » (https://mayank-01.medium.com/hacking-microservices-for-fun-and-bounty-5cc302769e94?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Become a Hacker in a Year
https://cdn-images-1.medium.com/max/2600/1*Dl0F36mQqB_LNtA_dKd3ug.jpeg
There is so much potential in hacking. You can keep learning forever and never get bored or keep doing the same thing over and over while…
Continue reading on Medium »
How to Become a Hacker in a Year
https://cdn-images-1.medium.com/max/2600/1*Dl0F36mQqB_LNtA_dKd3ug.jpeg
There is so much potential in hacking. You can keep learning forever and never get bored or keep doing the same thing over and over while…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking Microservices For Fun and Bounty
https://cdn-images-1.medium.com/max/768/1*otxhz3jtRLE5FZskm_uhDw.png
Understand How Microservices Work and Ways to break through it.
Continue reading on Medium »
Hacking Microservices For Fun and Bounty
https://cdn-images-1.medium.com/max/768/1*otxhz3jtRLE5FZskm_uhDw.png
Understand How Microservices Work and Ways to break through it.
Continue reading on Medium »
TiEtwAgent - PoC Memory Injection Detection Agent Based On ETW, For Offensive And Defensive Research Purposes
http://www.kitploit.com/2021/07/tietwagent-poc-memory-injection.html
http://www.kitploit.com/2021/07/tietwagent-poc-memory-injection.html
This project was created to research, build and test different memory (https://www.kitploit.com/search/label/Memory) injection detection use cases and bypass techniques. The agent utilizes Microsoft-Windows-Threat-Intelligence event tracing (https://www.kitploit.com/search/label/Tracing) provider, as a more modern and stable alternative to Userland-hooking, with the benefit of Kernel-mode visibility. The project depends on the microsoft/krabsetw (https://github.com/microsoft/krabsetw) library (https://www.kitploit.com/search/label/Library) for ETS setup and consumption. An accompanying blog post can be found here: https://blog.redbluepurple.io/windows-security-research/kernel-tracing-injection-detection
Adding new detections
Detection functions can be easily added in DetectionLogic.cpp, and called from detect_event(GenericEvent evt) for any source event type. Support for new event fields can be easily added by appending their name to the map in GenericEvent class declaration.
Setup instructions
Assuming you do not have a Microsoft-trusted signing certificate: Put your machine in the test signing mode with bcdedit Generate a self-signed certificate with ELAM and Code Signing EKU Sign TiEtwAgent.exe and your ELAM driver with the certificate ./TiEtwAgent install net start TiEtwAgent Look for logs, by default in C:\Windows\Temp\TiEtwAgent.txt
TODO
PPL Service, event parsing First detection Detection lifecycle Risk based lifecycle PS. If you do not want to write an ELAM driver, you can get one from https://github.com/pathtofile/PPLRunner/tree/main/elam_driver Special thanks to @pathtofile (https://github.com/pathtofile) for the post here: https://blog.tofile.dev/2020/12/16/elam.html
Download TiEtwAgent (https://github.com/xinbailu/TiEtwAgent)
Adding new detections
Detection functions can be easily added in DetectionLogic.cpp, and called from detect_event(GenericEvent evt) for any source event type. Support for new event fields can be easily added by appending their name to the map in GenericEvent class declaration.
Setup instructions
Assuming you do not have a Microsoft-trusted signing certificate: Put your machine in the test signing mode with bcdedit Generate a self-signed certificate with ELAM and Code Signing EKU Sign TiEtwAgent.exe and your ELAM driver with the certificate ./TiEtwAgent install net start TiEtwAgent Look for logs, by default in C:\Windows\Temp\TiEtwAgent.txt
TODO
PPL Service, event parsing First detection Detection lifecycle Risk based lifecycle PS. If you do not want to write an ELAM driver, you can get one from https://github.com/pathtofile/PPLRunner/tree/main/elam_driver Special thanks to @pathtofile (https://github.com/pathtofile) for the post here: https://blog.tofile.dev/2020/12/16/elam.html
Download TiEtwAgent (https://github.com/xinbailu/TiEtwAgent)
hacking: security in practice
is there a way to find a working sni for free-riding ?
for my isp like zerofacebook/internet.org and others that unfortunately most of them are not listed . but non of them can be used as a bug host anymore (or at least as far as I know because idk all of them) all there is left is some zero-rated websites with open ports, and howdy.id doesn't have any and for my country's isp's in there
any help to find one? because any HTTP injector or v2ray or proxy etc are useless without it
submitted by /u/Nziom
[link] [comments]
is there a way to find a working sni for free-riding ?
for my isp like zerofacebook/internet.org and others that unfortunately most of them are not listed . but non of them can be used as a bug host anymore (or at least as far as I know because idk all of them) all there is left is some zero-rated websites with open ports, and howdy.id doesn't have any and for my country's isp's in there
any help to find one? because any HTTP injector or v2ray or proxy etc are useless without it
submitted by /u/Nziom
[link] [comments]
reddit
is there a way to find a working sni for free-riding ?
for my isp like zerofacebook/internet.org and others that unfortunately most of them are not listed . but non of them can be used as a bug host...
hacking: security in practice
Hey guys. I know there are many reddit communitys about stocks and here you go I made another one.👏😁
It is actually like hacking: looking for vulnerabilities and attack it with many people/ computers to cause some serious damage.
DIFFERENCE is: 1. everything will be organized 2. focus on one or two stocks 3. decisions about stocks by surveys (not everyone can post stuff)
-these three things will cause more power to the community 💥
You are welcome!
https://www.reddit.com/r/Stockexploder/
submitted by /u/stockexploder
[link] [comments]
Hey guys. I know there are many reddit communitys about stocks and here you go I made another one.👏😁
It is actually like hacking: looking for vulnerabilities and attack it with many people/ computers to cause some serious damage.
DIFFERENCE is: 1. everything will be organized 2. focus on one or two stocks 3. decisions about stocks by surveys (not everyone can post stuff)
-these three things will cause more power to the community 💥
You are welcome!
https://www.reddit.com/r/Stockexploder/
submitted by /u/stockexploder
[link] [comments]
reddit
Hey guys. I know there are many reddit communitys about stocks and...
It is actually like hacking: looking for vulnerabilities and attack it with many people/ computers to cause some serious damage. DIFFERENCE...
TiEtwAgent - PoC Memory Injection Detection Agent Based On ETW, For Offensive And Defensive Research Purposes
This project was created to research, build and test different memory injection detection use cases and bypass techniques. The agent utilizes Microsoft-Windows-Threat-Intelligence event tracing provider, as a more modern and stable alternative to Userland-hooking, with the benefit of Kernel-mode visibility. The project depends on the microsoft/krabsetw library for ETS setup and consumption. An accompanying blog post can be found here: https://blog.redbluepurple.io/windows-security-research/kernel-tracing-injection-detectionAdding new detections Detection functions can be easily added in DetectionLogic.cpp, and called from detect_event(GenericEvent evt) for any source event type. Support for new event fields can be easily added by appending their name to the map in GenericEvent class declaration. Setup instructions Assuming you do not have a Microsoft-trusted signing certificate: Put your machine in the test signing mode with bcdedit Generate a self-signed certificate with ELAM and Code Signing EKU Sign TiEtwAgent.exe and your ELAM driver with the certificate ./TiEtwAgent install net start TiEtwAgent Look for logs, by default in C:\Windows\Temp\TiEtwAgent.txt TODO PPL Service, event parsing First detection Detection lifecycle Risk based lifecycle PS. If you do not want to write an ELAM driver, you can get one from https://github.com/pathtofile/PPLRunner/tree/main/elam_driver Special thanks to @pathtofile for the post here: https://blog.tofile.dev/2020/12/16/elam.html Download TiEtwAgent
Read more...
This project was created to research, build and test different memory injection detection use cases and bypass techniques. The agent utilizes Microsoft-Windows-Threat-Intelligence event tracing provider, as a more modern and stable alternative to Userland-hooking, with the benefit of Kernel-mode visibility. The project depends on the microsoft/krabsetw library for ETS setup and consumption. An accompanying blog post can be found here: https://blog.redbluepurple.io/windows-security-research/kernel-tracing-injection-detectionAdding new detections Detection functions can be easily added in DetectionLogic.cpp, and called from detect_event(GenericEvent evt) for any source event type. Support for new event fields can be easily added by appending their name to the map in GenericEvent class declaration. Setup instructions Assuming you do not have a Microsoft-trusted signing certificate: Put your machine in the test signing mode with bcdedit Generate a self-signed certificate with ELAM and Code Signing EKU Sign TiEtwAgent.exe and your ELAM driver with the certificate ./TiEtwAgent install net start TiEtwAgent Look for logs, by default in C:\Windows\Temp\TiEtwAgent.txt TODO PPL Service, event parsing First detection Detection lifecycle Risk based lifecycle PS. If you do not want to write an ELAM driver, you can get one from https://github.com/pathtofile/PPLRunner/tree/main/elam_driver Special thanks to @pathtofile for the post here: https://blog.tofile.dev/2020/12/16/elam.html Download TiEtwAgent
Read more...