Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Flaws in the 3 common Networking Topologies
https://cdn-images-1.medium.com/max/612/1*Lmad2C_vJIyph6pvFgvymg.jpeg
What is the major flaw in Ring , Bus and Star topologies
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Flaws in the 3 common Networking Topologies
https://cdn-images-1.medium.com/max/612/1*Lmad2C_vJIyph6pvFgvymg.jpeg
What is the major flaw in Ring , Bus and Star topologies
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Flaws in the 3 common Networking Topologies
What is the major flaw in Ring , Bus and Star topologies
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Quick Guide to Understanding Supply Chain Attacks
https://cdn-images-1.medium.com/max/1280/0*EOUROQrvRfJ6CRWr.jpg
Your web of trust is about to feel a whole lot weaker
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Quick Guide to Understanding Supply Chain Attacks
https://cdn-images-1.medium.com/max/1280/0*EOUROQrvRfJ6CRWr.jpg
Your web of trust is about to feel a whole lot weaker
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Quick Guide to Understanding Supply Chain Attacks
Your web of trust is about to feel a whole lot weaker
hacking: security in practice
Can anybody TL;DR rarjpeg?
So my friend tells me about this thing that can glue images together to hide files within images... And it's quite volatile and dangerous to our peculiar happenstance.
Is this the right subreddit to be posting about this? What can be done to prevent/detect this?
submitted by /u/Davidier
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can anybody TL;DR rarjpeg?
So my friend tells me about this thing that can glue images together to hide files within images... And it's quite volatile and dangerous to our peculiar happenstance.
Is this the right subreddit to be posting about this? What can be done to prevent/detect this?
submitted by /u/Davidier
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
[deleted by user] : r/hacking
2.9M subscribers in the hacking community. A subreddit dedicated to hacking and hackers.
Constructive collaboration and learning about exploits, industry standards, grey and white hat hacking, new hardware and software hacking technology, sharing ideas and…
Constructive collaboration and learning about exploits, industry standards, grey and white hat hacking, new hardware and software hacking technology, sharing ideas and…
hacking: security in practice
Looking for malware samples
Looking to find a good source of malware samples to download and analyze. Currently testing with SentinelOne EDR/AV and trying to learn the software and study the results of a compromise.
I used to have a subscription to virustotal, but no longer have access.
Any suggestions?
submitted by /u/PrimaryWatercress759
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Looking for malware samples
Looking to find a good source of malware samples to download and analyze. Currently testing with SentinelOne EDR/AV and trying to learn the software and study the results of a compromise.
I used to have a subscription to virustotal, but no longer have access.
Any suggestions?
submitted by /u/PrimaryWatercress759
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Looking for malware samples
Looking to find a good source of malware samples to download and analyze. Currently testing with SentinelOne EDR/AV and trying to learn the...
hacking: security in practice
There a better case for a Deauther watch V3?
Is there a better case? I’d like to replace it and just use it not as a watch (too bulky)? Saw Ed Calderon have one, I kinda want a setup similar to that
submitted by /u/mav_xiii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
There a better case for a Deauther watch V3?
Is there a better case? I’d like to replace it and just use it not as a watch (too bulky)? Saw Ed Calderon have one, I kinda want a setup similar to that
submitted by /u/mav_xiii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
There a better case for a Deauther watch V3?
Is there a better case? I’d like to replace it and just use it not as a watch (too bulky)? Saw Ed Calderon have one, I kinda want a setup similar...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Want to Learn Hacking? TryHackMe
https://cdn-images-1.medium.com/max/1300/1*D8iH_941Z5v156GcMBeaWQ.jpeg
All in one Gateway to Learning Ethical Hacking
Continue reading on Medium »
Want to Learn Hacking? TryHackMe
https://cdn-images-1.medium.com/max/1300/1*D8iH_941Z5v156GcMBeaWQ.jpeg
All in one Gateway to Learning Ethical Hacking
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding the MITRE Engenuity ATT&CK Carbanank FIN7 Evaluation Results:
https://cdn-images-1.medium.com/max/1600/0*1K_EaOQox4EnlEf2
Cutting Through the Marketing Buzzwords & How Everyone Can Become a Winner
Continue reading on CyCraft »
Understanding the MITRE Engenuity ATT&CK Carbanank FIN7 Evaluation Results:
https://cdn-images-1.medium.com/max/1600/0*1K_EaOQox4EnlEf2
Cutting Through the Marketing Buzzwords & How Everyone Can Become a Winner
Continue reading on CyCraft »
hacking: security in practice
rust
So I recently paid a guy to make me rust cheats so I could sell it to sum people. Im pretty sure the file he sent was a virus, but I'm not sure. Is there any way of checking?
submitted by /u/Emerald_Sniper
[link] [comments]
rust
So I recently paid a guy to make me rust cheats so I could sell it to sum people. Im pretty sure the file he sent was a virus, but I'm not sure. Is there any way of checking?
submitted by /u/Emerald_Sniper
[link] [comments]
reddit
rust
So I recently paid a guy to make me rust cheats so I could sell it to sum people. Im pretty sure the file he sent was a virus, but I'm not sure....
hacking: security in practice
House hold items acting up
The lights in the front of my house have been blinking on and off when I take my dog out to pee at night and my door bell camera doesn’t work during that time. It happens quite often. Apparently my wifi has “weak security.” Maybe just paranoid but it’s a little too coincidental in my opinion to be happening this often. Lights aren’t connected to WiFi. Can anyone offer any insight? If not that’s cool. First time posting on here.
submitted by /u/tonitone223
[link] [comments]
House hold items acting up
The lights in the front of my house have been blinking on and off when I take my dog out to pee at night and my door bell camera doesn’t work during that time. It happens quite often. Apparently my wifi has “weak security.” Maybe just paranoid but it’s a little too coincidental in my opinion to be happening this often. Lights aren’t connected to WiFi. Can anyone offer any insight? If not that’s cool. First time posting on here.
submitted by /u/tonitone223
[link] [comments]
reddit
House hold items acting up
The lights in the front of my house have been blinking on and off when I take my dog out to pee at night and my door bell camera doesn’t work...
hacking: security in practice
Kali or Parrot I personally love parrot although I started on kali I know nobody cares or asked but I wanna know what u guys prefer
Kali Vs Parrot
View Poll
submitted by /u/YoungExploiter2221
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Kali or Parrot I personally love parrot although I started on kali I know nobody cares or asked but I wanna know what u guys prefer
Kali Vs Parrot
View Poll
submitted by /u/YoungExploiter2221
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Kali or Parrot I personally love parrot although I started on kali...
Kali Vs Parrot
How to become a bug hunter?Continue reading on Medium » (https://himansh160699.medium.com/bug-hunting-path-9d044aed6bd5?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco BPA, WSA Bugs Allow Remote Cyberattacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Cisco BPA, WSA Bugs Allow Remote CyberattacksPost Views: 38
Reading Time: 1 Minute
A set of high-severity privilege-escalation vulnerabilities affecting Business Process Automation (BPA) application and Cisco’s Web Security Appliance (WSA) and could allow authenticated, remote attackers to access sensitive data or take over a targeted system.
The first two bugs (CVE-2021-1574 and CVE-2021-1576) exist in the web-based management interface of the Cisco Business Process Automation (BPA), which is used to streamline various IT processes. Its functions include OS upgrades, device activation, compliance checks and server migration.
The flaws, which both rate 8.8 out of 10 on the CVSS vulnerability-severity scale, could allow an authenticated, remote attacker to elevate privileges to administrator-level. A successful exploit would involve sending crafted HTTP messages to an affected system.
“These vulnerabilities are due to improper authorization enforcement for specific features and for access to log files that contain confidential information,” according to Cisco’s Thursday advisory. Exploitation could result in an adversary “performing unauthorized actions with the privileges of an administrator, or by retrieving sensitive data from the logs and using it to impersonate a legitimate privileged user,” the company noted.
* For CVE-2021-1574, an attacker with valid user credentials could execute unauthorized commands;
* For CVE-2021-1576, an attacker with valid credentials could access the logging subsystem of an affected system and retrieve sensitive data. The system is vulnerable only while a legitimate user maintains an active session on the system, Cisco noted.
The vulnerabilities affect Cisco BPA releases earlier than Release 3.1.
See Also: Kaseya ransomware supply chain attack: What you need to know Meanwhile, the third bug affects Cisco’s WSA appliance, which provides protection for those using a corporate network to access the web, by automatically blocking risky sites and testing unknown sites before allowing users to click on them.
The issue (CVE-2021-1359, with a CVSS score of 6.3 out of 10) exists in the configuration management of the Cisco AsyncOS operating system that powers the WSA. According to Cisco’s advisory, it could allow an authenticated, remote attacker to perform command injection and elevate privileges to root.
“This vulnerability is due to insufficient validation of user-supplied XML input for the web interface,” the networking giant explained. “An attacker could exploit this vulnerability by uploading crafted XML configuration files that contain scripting code to a vulnerable device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.”
The bug rates high-severity rather than critical since any would-be attacker would need a valid user account with the rights to upload configuration files in order to exploit the bug – something that could be achieved via another exploit or phishing attack.
See Also: Offensive Security Tool: It Was All A Dream (Windows Print Spooler RCE) Badly programmed APIs are an obvious attack vector and one of the most common threat vectors used to take advantage of poorly secured applications to get to data. They’re as common as dandelions in spring: When researcher Alissa Knight with Approov tried to break into the APIs of 30 different mHealth app vendors, she found that they were all vulnerable to one degree or another. Seventy-seven percent of them contained hardcoded API k[...]
Cisco BPA, WSA Bugs Allow Remote Cyberattacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Cisco BPA, WSA Bugs Allow Remote CyberattacksPost Views: 38
Reading Time: 1 Minute
A set of high-severity privilege-escalation vulnerabilities affecting Business Process Automation (BPA) application and Cisco’s Web Security Appliance (WSA) and could allow authenticated, remote attackers to access sensitive data or take over a targeted system.
The first two bugs (CVE-2021-1574 and CVE-2021-1576) exist in the web-based management interface of the Cisco Business Process Automation (BPA), which is used to streamline various IT processes. Its functions include OS upgrades, device activation, compliance checks and server migration.
The flaws, which both rate 8.8 out of 10 on the CVSS vulnerability-severity scale, could allow an authenticated, remote attacker to elevate privileges to administrator-level. A successful exploit would involve sending crafted HTTP messages to an affected system.
“These vulnerabilities are due to improper authorization enforcement for specific features and for access to log files that contain confidential information,” according to Cisco’s Thursday advisory. Exploitation could result in an adversary “performing unauthorized actions with the privileges of an administrator, or by retrieving sensitive data from the logs and using it to impersonate a legitimate privileged user,” the company noted.
* For CVE-2021-1574, an attacker with valid user credentials could execute unauthorized commands;
* For CVE-2021-1576, an attacker with valid credentials could access the logging subsystem of an affected system and retrieve sensitive data. The system is vulnerable only while a legitimate user maintains an active session on the system, Cisco noted.
The vulnerabilities affect Cisco BPA releases earlier than Release 3.1.
See Also: Kaseya ransomware supply chain attack: What you need to know Meanwhile, the third bug affects Cisco’s WSA appliance, which provides protection for those using a corporate network to access the web, by automatically blocking risky sites and testing unknown sites before allowing users to click on them.
The issue (CVE-2021-1359, with a CVSS score of 6.3 out of 10) exists in the configuration management of the Cisco AsyncOS operating system that powers the WSA. According to Cisco’s advisory, it could allow an authenticated, remote attacker to perform command injection and elevate privileges to root.
“This vulnerability is due to insufficient validation of user-supplied XML input for the web interface,” the networking giant explained. “An attacker could exploit this vulnerability by uploading crafted XML configuration files that contain scripting code to a vulnerable device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.”
The bug rates high-severity rather than critical since any would-be attacker would need a valid user account with the rights to upload configuration files in order to exploit the bug – something that could be achieved via another exploit or phishing attack.
See Also: Offensive Security Tool: It Was All A Dream (Windows Print Spooler RCE) Badly programmed APIs are an obvious attack vector and one of the most common threat vectors used to take advantage of poorly secured applications to get to data. They’re as common as dandelions in spring: When researcher Alissa Knight with Approov tried to break into the APIs of 30 different mHealth app vendors, she found that they were all vulnerable to one degree or another. Seventy-seven percent of them contained hardcoded API k[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Cisco BPA, WSA Bugs Allow Remote Cyberattacks https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Cisco BPA, WSA Bugs Allow Remote CyberattacksPost Views: 38 Reading Time: 1 Minute…
eys – some of which don’t expire – that would allow an attacker to intercept API exchange of information. Seven percent of those APIs belonged to third-party payment processors that explicitly warn against hard-coding their secret keys in plain text.
Knight also found that 100 percent of API endpoints tested were vulnerable to BOLA attacks, which allowed the researcher to view the personal health information and personally identifiable information (PII) for patients that weren’t assigned to the researcher’s account.
In his writeup, Silva confirmed that API access control issues are “one of the biggest security problems facing APIs.”
“As vulnerable APIs increasingly fall into adversaries’ sights, it’s critical that developers receive proper education on best practices for embedding security into their design from the get-go,” he said.
Checkmarx disclosed its findings to Coursera’s security team in October. By May 24, 2021, Coursera had resolved all the API issues, including a new one that Checkmarx found and reported in January. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker The issue affects both the virtual and hardware-based iterations of the appliances, in Releases 11.8 and earlier, 12.0 and 12.5.
These are just the latest patches that Cisco has issued; last month, it patched several high-severity security vulnerabilities in its Small Business 220 Series Smart Switches, which are intro-level networking gear for SMBs. The flaws could allow remote attacks designed to steal information, drop malware and disrupt operations, via session hijacking, arbitrary code execution, cross-site scripting (XSS) and HTML injection.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Untitled-design-8-90x90.png Coursera Flunks API Security Test in Researchers’ Exam3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/macos-trojan-90x90.jpg MacOS Targeted in WildPressure APT Malware Campaign4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/i339637-90x90.jpg Western Digital Users Face Another RCE5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/shutterstock_1968890518-1-90x90.jpg Kaseya ransomware supply chain attack: What you need to know6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-90x90.jpg CISA Offers New Mitigation for PrintNightmare Bug7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/router-90x90.jpg Netgear Authentication Bypass Allows Router Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/windows-bug-bounty-90x90.jpg PoC Exploit Circulating for Critical Windows Print Spooler Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/linkedin-90x90.png Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1920px-NVidia_G71_GPU-90x90.jpg NVIDIA Patches High-Severity GeForce Spoof-Attack Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-90x90.jpg Cisco ASA Bug Now Actively Exploited as PoC Drops2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Cisco BPA, WSA Bugs Allow Remote Cyberattacks first appeared on Black Hat Ethical Hacking.
Knight also found that 100 percent of API endpoints tested were vulnerable to BOLA attacks, which allowed the researcher to view the personal health information and personally identifiable information (PII) for patients that weren’t assigned to the researcher’s account.
In his writeup, Silva confirmed that API access control issues are “one of the biggest security problems facing APIs.”
“As vulnerable APIs increasingly fall into adversaries’ sights, it’s critical that developers receive proper education on best practices for embedding security into their design from the get-go,” he said.
Checkmarx disclosed its findings to Coursera’s security team in October. By May 24, 2021, Coursera had resolved all the API issues, including a new one that Checkmarx found and reported in January. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker The issue affects both the virtual and hardware-based iterations of the appliances, in Releases 11.8 and earlier, 12.0 and 12.5.
These are just the latest patches that Cisco has issued; last month, it patched several high-severity security vulnerabilities in its Small Business 220 Series Smart Switches, which are intro-level networking gear for SMBs. The flaws could allow remote attacks designed to steal information, drop malware and disrupt operations, via session hijacking, arbitrary code execution, cross-site scripting (XSS) and HTML injection.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Untitled-design-8-90x90.png Coursera Flunks API Security Test in Researchers’ Exam3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/macos-trojan-90x90.jpg MacOS Targeted in WildPressure APT Malware Campaign4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/i339637-90x90.jpg Western Digital Users Face Another RCE5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/shutterstock_1968890518-1-90x90.jpg Kaseya ransomware supply chain attack: What you need to know6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-90x90.jpg CISA Offers New Mitigation for PrintNightmare Bug7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/router-90x90.jpg Netgear Authentication Bypass Allows Router Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/windows-bug-bounty-90x90.jpg PoC Exploit Circulating for Critical Windows Print Spooler Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/linkedin-90x90.png Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1920px-NVidia_G71_GPU-90x90.jpg NVIDIA Patches High-Severity GeForce Spoof-Attack Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/cisco-90x90.jpg Cisco ASA Bug Now Actively Exploited as PoC Drops2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Cisco BPA, WSA Bugs Allow Remote Cyberattacks first appeared on Black Hat Ethical Hacking.