hacking: security in practice
[Theorical question] Hacking Vigik
Hi
I was interested into getting your opinion on a thought that I had just today. I'm a security / hacking fan but I don't think that I could say that I have a very strong knowledge about it -just as a disclamer.
Weeks ago, I started wondering about how hackable are vigik locks at the entrace of nearly all Paris' buildings. I thought that -as pretty much everything around us in this city- it was poorly secured and that I'd be able to find a universal pass even on ebay. Turns out that I was wrong and, to this day, apparently no one has successfully hacked it or at least the most that we can read on the internet is that tech experts think that it'll be hacked in the next years.
There actually are universal pass for the mail, electricity and internet workers but each key has its own data and it becomes outdated every two days. Then you have to update it with vigik professionnal tools.
So I thought that leaks and stolent hardware would be easy to find and it seems that I was wrong about it. Then I finally came to the conclusion that in order to always have a valid pass, you'd need to have a friend who works in the mentionned fields and that he'd have to copy and send his key every two days to you with the help of his smartphone. Dead end : I don't have any friend working in these compagnies.
I really thought that this quest was over and that there wasn't any possible turnaround left.
And finally, today, I got randomly stroke by an idea : what if you just don't ask the mailman ? What if he has everything you need in his pocket and by this I mean the Vigik key AND the mean to copy and deliver it to you without implying any action on his side ? Most of post employees obviously will put their keys and their phone at a close distance. So what you basically need isn't to hack vigik but hack a phone with a silent nfc cloner.
That's pretty wicked, indeed. But in fact you don't even need to infect a phone. What if, just as card stealers, I'd 3D-print a fake vigik badge reader that'd be slightly bigger than the original, put it onto a real vigik device at the entrace of a building and create some kind of "man-in-the-middle-ish" device that'd send every scanned-badge's key on my phone ?
And finally, what if having a series of outdated keys collected thanks to my device could help me predict the next one and maybe crack vigik's encryption ?
What do you think ?
Please pardon my eventual english mistakes as I'm a non-native speaker and thanks for sharing your thoughts about this idea.
submitted by /u/gregfdzd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
[Theorical question] Hacking Vigik
Hi
I was interested into getting your opinion on a thought that I had just today. I'm a security / hacking fan but I don't think that I could say that I have a very strong knowledge about it -just as a disclamer.
Weeks ago, I started wondering about how hackable are vigik locks at the entrace of nearly all Paris' buildings. I thought that -as pretty much everything around us in this city- it was poorly secured and that I'd be able to find a universal pass even on ebay. Turns out that I was wrong and, to this day, apparently no one has successfully hacked it or at least the most that we can read on the internet is that tech experts think that it'll be hacked in the next years.
There actually are universal pass for the mail, electricity and internet workers but each key has its own data and it becomes outdated every two days. Then you have to update it with vigik professionnal tools.
So I thought that leaks and stolent hardware would be easy to find and it seems that I was wrong about it. Then I finally came to the conclusion that in order to always have a valid pass, you'd need to have a friend who works in the mentionned fields and that he'd have to copy and send his key every two days to you with the help of his smartphone. Dead end : I don't have any friend working in these compagnies.
I really thought that this quest was over and that there wasn't any possible turnaround left.
And finally, today, I got randomly stroke by an idea : what if you just don't ask the mailman ? What if he has everything you need in his pocket and by this I mean the Vigik key AND the mean to copy and deliver it to you without implying any action on his side ? Most of post employees obviously will put their keys and their phone at a close distance. So what you basically need isn't to hack vigik but hack a phone with a silent nfc cloner.
That's pretty wicked, indeed. But in fact you don't even need to infect a phone. What if, just as card stealers, I'd 3D-print a fake vigik badge reader that'd be slightly bigger than the original, put it onto a real vigik device at the entrace of a building and create some kind of "man-in-the-middle-ish" device that'd send every scanned-badge's key on my phone ?
And finally, what if having a series of outdated keys collected thanks to my device could help me predict the next one and maybe crack vigik's encryption ?
What do you think ?
Please pardon my eventual english mistakes as I'm a non-native speaker and thanks for sharing your thoughts about this idea.
submitted by /u/gregfdzd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
[Theorical question] Hacking Vigik
Hi I was interested into getting your opinion on a thought that I had just today. I'm a security / hacking fan but I don't think that I could say...
hacking: security in practice
Can a person get hacked through WhatsApp?
This story has happened to me at least five times now: I match with an Asian girl through online dating (always an Asian girl, though I live in a country where there are no Asian people), we exchange only a few messages and then very quickly she asks to move the conversation to WhatsApp.
When we do she tells me she's lives abroad and had visited my country recently and would be returning a month from now or in the fall or some period. I've had conversations with girls claiming to be in Japan, but with a +44 (UK) country code, then telling me it's because she studied in the UK.
As I say, this has happened about five times now and only once has anything that could potentially get money out of me been brought up. One of these girls mentioned some kind of new cryptocurrency and said how this is an opportune time to get into it, although she didn't press very hard on it and it kind of came up organically.
But anyway, that definitely could have been a scam, but the weird thing is, the other four girls never asked me for any money or personal info beyond my phone number to connect via WhatsApp and that has me worried.
Is there any way a hacker could get anything out of me through connecting with me on WhatsApp?
submitted by /u/themainheadcase
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can a person get hacked through WhatsApp?
This story has happened to me at least five times now: I match with an Asian girl through online dating (always an Asian girl, though I live in a country where there are no Asian people), we exchange only a few messages and then very quickly she asks to move the conversation to WhatsApp.
When we do she tells me she's lives abroad and had visited my country recently and would be returning a month from now or in the fall or some period. I've had conversations with girls claiming to be in Japan, but with a +44 (UK) country code, then telling me it's because she studied in the UK.
As I say, this has happened about five times now and only once has anything that could potentially get money out of me been brought up. One of these girls mentioned some kind of new cryptocurrency and said how this is an opportune time to get into it, although she didn't press very hard on it and it kind of came up organically.
But anyway, that definitely could have been a scam, but the weird thing is, the other four girls never asked me for any money or personal info beyond my phone number to connect via WhatsApp and that has me worried.
Is there any way a hacker could get anything out of me through connecting with me on WhatsApp?
submitted by /u/themainheadcase
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can a person get hacked through WhatsApp?
This story has happened to me at least five times now: I match with an Asian girl through online dating (always an Asian girl, though I live in...
Pre-Account Takeover by Reversing a Weak Email Verification Token Algorithm
I spoofed access to other people’s email in order to pre-steal user accounts before they are first registered. Here’s how I did it.Continue reading on InfoSec Write-ups »
Read more...
I spoofed access to other people’s email in order to pre-steal user accounts before they are first registered. Here’s how I did it.Continue reading on InfoSec Write-ups »
Read more...
KitPloit - PenTest Tools!
Pstf2 - Passive Security Tools Fingerprinting Framework
___________________________
@hacking_Attack
@Hacking_Video
Pstf2 - Passive Security Tools Fingerprinting Framework
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Pstf2 - Passive Security Tools Fingerprinting Framework
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
8 Potential Warning Signs of a Rug Pull
https://cdn-images-1.medium.com/max/2600/1*9uSXnMoR_uyIrWkB378A0w.jpeg
Rug pulls are by far the most common type of fraud in DeFi, and they evolved out of the exit scam ICO craze.
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
8 Potential Warning Signs of a Rug Pull
https://cdn-images-1.medium.com/max/2600/1*9uSXnMoR_uyIrWkB378A0w.jpeg
Rug pulls are by far the most common type of fraud in DeFi, and they evolved out of the exit scam ICO craze.
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
Medium
8 Potential Warning Signs of a Rug Pull
Rug pulls are by far the most common type of fraud in DeFi, and they evolved out of the exit scam ICO craze.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
POR EHACKING
https://cdn-images-1.medium.com/max/1815/0*Gy5R4t643_sr7Kgr
La seguridad en los sistemas informáticos es un continuo juego del gato y el ratón. Por una parte, las actualizaciones de software cierran…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
POR EHACKING
https://cdn-images-1.medium.com/max/1815/0*Gy5R4t643_sr7Kgr
La seguridad en los sistemas informáticos es un continuo juego del gato y el ratón. Por una parte, las actualizaciones de software cierran…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pegasus es invulnerable a iOS 14.6 e infectó los iPhone de periodistas y disidentes políticos en todo el mundo.
La seguridad en los sistemas informáticos es un continuo juego del gato y el ratón. Por una parte, las actualizaciones de software cierran…
hacking: security in practice
What do you think are probably the top 5 how to hack google searches?
I’m just curious based on your personal experience what would you think are probably the most searched how to’s on google for hacking. Secondly, what do you think should be the most important questions for someone to ask themselves?
submitted by /u/james14street
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What do you think are probably the top 5 how to hack google searches?
I’m just curious based on your personal experience what would you think are probably the most searched how to’s on google for hacking. Secondly, what do you think should be the most important questions for someone to ask themselves?
submitted by /u/james14street
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What do you think are probably the top 5 how to hack google searches?
I’m just curious based on your personal experience what would you think are probably the most searched how to’s on google for hacking. Secondly,...
hacking: security in practice
Possible malware n33d h3lp -_-
So I inserted my usb in a windows xp (pir ated of course) and it turned all the files' names into sime gibberish, some greek letters and other weird shapes, so I think this probably a malware or ransomware or whatever the name is, or maybe it's because I take the usb out of pc without unmount it (probably not but who knows, not me for sure, I'm a noob), well, the windows was in a virtual machine so no other file is affected, plus, I have Linux as main OS so I don't know if it could do something. The thing is, I can't format, open, or rename anything, the names appears only in terminal btw. I need a solution please, one more thing: the informations in the usb aren't important so any solution is welcomed.
submitted by /u/Oy-Mugiwara-ya
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Possible malware n33d h3lp -_-
So I inserted my usb in a windows xp (pir ated of course) and it turned all the files' names into sime gibberish, some greek letters and other weird shapes, so I think this probably a malware or ransomware or whatever the name is, or maybe it's because I take the usb out of pc without unmount it (probably not but who knows, not me for sure, I'm a noob), well, the windows was in a virtual machine so no other file is affected, plus, I have Linux as main OS so I don't know if it could do something. The thing is, I can't format, open, or rename anything, the names appears only in terminal btw. I need a solution please, one more thing: the informations in the usb aren't important so any solution is welcomed.
submitted by /u/Oy-Mugiwara-ya
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Possible malware n33d h3lp -_-
So I inserted my usb in a windows xp (pir ated of course) and it turned all the files' names into sime gibberish, some greek letters and other...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What’s happening to today’s world?
https://cdn-images-1.medium.com/max/1920/1*71rHsEdTSmt_tQ1kbMj4NQ.png
Isn’t it enough that we’re being forced to live in endless lockdowns? That we’re being deprived of free speech by the likes of Mark…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What’s happening to today’s world?
https://cdn-images-1.medium.com/max/1920/1*71rHsEdTSmt_tQ1kbMj4NQ.png
Isn’t it enough that we’re being forced to live in endless lockdowns? That we’re being deprived of free speech by the likes of Mark…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What’s happening to today’s world?
Isn’t it enough that we’re being forced to live in endless lockdowns? That we’re being deprived of free speech by the likes of Mark…
Deep Web
Why logically would you go on the dark web?
I've been lurking this sub for a few hours, read posts new and old about accidentally clicking a link to cheese pizza or seeing some fucked up shit. I know red rooms obviously aren't real(because I'm above the age of 12) but i don't see the perks or the benefit of browsing the deep web. I mean yeah if you're a junkie looking for hard drugs or a pedo monster looking for, well y'know , but in the place of a normal ish person It just seems like more trouble then it's worth. Genuinely curious btw this isn't a criticism at all I just don't understand.
submitted by /u/colton_was_here
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why logically would you go on the dark web?
I've been lurking this sub for a few hours, read posts new and old about accidentally clicking a link to cheese pizza or seeing some fucked up shit. I know red rooms obviously aren't real(because I'm above the age of 12) but i don't see the perks or the benefit of browsing the deep web. I mean yeah if you're a junkie looking for hard drugs or a pedo monster looking for, well y'know , but in the place of a normal ish person It just seems like more trouble then it's worth. Genuinely curious btw this isn't a criticism at all I just don't understand.
submitted by /u/colton_was_here
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Why logically would you go on the dark web?
I've been lurking this sub for a few hours, read posts new and old about accidentally clicking a link to cheese pizza or seeing some fucked up...
hacking: security in practice
How do I connect my walkie-talkie to my guard's walkie talkie?
I'm using a Baofeng & the security company is really cheap here, although the guards down have a better walkie talkie than me.
I'm already aware of SDRs & I was thinking if there's a way I could connect in to their walkie talkie with mine?
Thanks in advance for any knowledge of this.
submitted by /u/iBeLikeoof
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do I connect my walkie-talkie to my guard's walkie talkie?
I'm using a Baofeng & the security company is really cheap here, although the guards down have a better walkie talkie than me.
I'm already aware of SDRs & I was thinking if there's a way I could connect in to their walkie talkie with mine?
Thanks in advance for any knowledge of this.
submitted by /u/iBeLikeoof
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do I connect my walkie-talkie to my guard's walkie talkie?
I'm using a Baofeng & the security company is really cheap here, although the guards down have a better walkie talkie than me. I'm already aware...
Pentesting iOS| Starting With iOS Emulator Corellium & Re-signing IPA
Corellium provided virtual iOS-based devices for individual accounts on our groundbreaking security research platform, CORSEC. Corellium’s…
Read more...
Corellium provided virtual iOS-based devices for individual accounts on our groundbreaking security research platform, CORSEC. Corellium’s…
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical Jira Flaw in Atlassian Could Lead to RCE
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Jira Flaw in Atlassian Could Lead to RCEPost Views: 96
Reading Time: 2 Minutes
Atlassian has dropped a patch for a critical vulnerability in many versions of its Jira Data Center and Jira Service Management Data Center products, which can lead to arbitrary code execution.
Atlassian is a platform that’s used by 180,000 customers to engineer software and manage projects, and Jira is its proprietary bug-tracking and agile project-management tool.
On Wednesday, Atlassian issued a security advisory concerning the vulnerability, which is tracked as CVE-2020-36239. The bug could enable remote, unauthenticated attackers to execute arbitrary code in some Jira Data Center products. BleepingComputer got ahold of an email Atlassian sent to enterprise customers on Wednesday that urged them to update ASAP.
The vulnerability has to do with a missing authentication check in Jira’s implementation of Ehcache, which is an open-source, Java distributed cache for general-purpose caching, Java EE and lightweight containers that’s used for performance and which simplifies scalability.
Atlassian said that the bug was introduced in version 6.3.0 of Jira Data Center, Jira Core Data Center, Jira Software Data Center and Jira Service Management Data Center (known as Jira Service Desk prior to 4.14).
According to Atlassian’s security advisory, that list of products exposed a Ehcache remote method invocation (RMI) network service that attackers – who can connect to the service on port 40001 and potentially 40011 – could use to “execute arbitrary code of their choice in Jira” through deserialization, due to missing authentication.
RMI is an API that acts as a mechanism to enable remote communication between programs written in Java. It allows an object residing in one Java virtual machine (JVM) to invoke an object running on another JVM; Often, it involves one program on a server and one on a client. The advantage of RMI, as BleepingComputer describes it, is that “programmers can invoke methods present in remote objects—such as those present within an application running on a shared network, right from their application as they would run a local method or procedure.” https://media.threatpost.com/wp-content/uploads/sites/103/2021/07/22161351/RMI.png Workings of RMI. Source: Wikipedia.
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
Atlassian “strongly suggests” restricting access to the Ehcache ports to only Data Center instances, but noted that there’s a caveat: “Fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service,” according to the advisory. Affected VersionsThese are the affected versions of Jira Data Center and Jira Service Management Data Center: Jira Data Center, Jira Core Data Center, and Jira Software Data Center – ranges* 6.3.0 <=
* 8.6.0 <=
* 8.14.0 <= Jira Service Management Data Center – ranges* 2.0.2 <=
* 4.6.0 <=
* 4.14.0 <= Jira Data Center, Jira Core Data Center, and Jira Software Data Center* All 6.3.x, 6.4.x versions
* All 7.0.x, 7.1.x , 7.2.x, 7.3.x, 7.4.x, 7.5.x, 7.6.x, 7.7.x, 7.8.x, 7.9.x, 7.10.x, 7.11.x, 7.12.x, 7.13.x versions
* All 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x versions
* All 8.5.x versions before 8.5.16
* All 8.6.x, 8.7.x, 8.8.x, 8.9.x, 8.10.x, 8.11.x, 8.12.x versions
* All 8.13.x versions before 8.13.8
* All 8.14.x, 8.15.x, 8.16.x versions Jira Service Management Data Center* All 2.x.x versions after 2.0.2
* All 3.x.x versions
* All 4.0.x, 4.1.x, 4.2.x, 4.3.x, 4.4.x ve[...]
___________________________
@hacking_Attack
@Hacking_Video
Critical Jira Flaw in Atlassian Could Lead to RCE
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Jira Flaw in Atlassian Could Lead to RCEPost Views: 96
Reading Time: 2 Minutes
Atlassian has dropped a patch for a critical vulnerability in many versions of its Jira Data Center and Jira Service Management Data Center products, which can lead to arbitrary code execution.
Atlassian is a platform that’s used by 180,000 customers to engineer software and manage projects, and Jira is its proprietary bug-tracking and agile project-management tool.
On Wednesday, Atlassian issued a security advisory concerning the vulnerability, which is tracked as CVE-2020-36239. The bug could enable remote, unauthenticated attackers to execute arbitrary code in some Jira Data Center products. BleepingComputer got ahold of an email Atlassian sent to enterprise customers on Wednesday that urged them to update ASAP.
The vulnerability has to do with a missing authentication check in Jira’s implementation of Ehcache, which is an open-source, Java distributed cache for general-purpose caching, Java EE and lightweight containers that’s used for performance and which simplifies scalability.
Atlassian said that the bug was introduced in version 6.3.0 of Jira Data Center, Jira Core Data Center, Jira Software Data Center and Jira Service Management Data Center (known as Jira Service Desk prior to 4.14).
According to Atlassian’s security advisory, that list of products exposed a Ehcache remote method invocation (RMI) network service that attackers – who can connect to the service on port 40001 and potentially 40011 – could use to “execute arbitrary code of their choice in Jira” through deserialization, due to missing authentication.
RMI is an API that acts as a mechanism to enable remote communication between programs written in Java. It allows an object residing in one Java virtual machine (JVM) to invoke an object running on another JVM; Often, it involves one program on a server and one on a client. The advantage of RMI, as BleepingComputer describes it, is that “programmers can invoke methods present in remote objects—such as those present within an application running on a shared network, right from their application as they would run a local method or procedure.” https://media.threatpost.com/wp-content/uploads/sites/103/2021/07/22161351/RMI.png Workings of RMI. Source: Wikipedia.
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
Atlassian “strongly suggests” restricting access to the Ehcache ports to only Data Center instances, but noted that there’s a caveat: “Fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service,” according to the advisory. Affected VersionsThese are the affected versions of Jira Data Center and Jira Service Management Data Center: Jira Data Center, Jira Core Data Center, and Jira Software Data Center – ranges* 6.3.0 <=
* 8.6.0 <=
* 8.14.0 <= Jira Service Management Data Center – ranges* 2.0.2 <=
* 4.6.0 <=
* 4.14.0 <= Jira Data Center, Jira Core Data Center, and Jira Software Data Center* All 6.3.x, 6.4.x versions
* All 7.0.x, 7.1.x , 7.2.x, 7.3.x, 7.4.x, 7.5.x, 7.6.x, 7.7.x, 7.8.x, 7.9.x, 7.10.x, 7.11.x, 7.12.x, 7.13.x versions
* All 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x versions
* All 8.5.x versions before 8.5.16
* All 8.6.x, 8.7.x, 8.8.x, 8.9.x, 8.10.x, 8.11.x, 8.12.x versions
* All 8.13.x versions before 8.13.8
* All 8.14.x, 8.15.x, 8.16.x versions Jira Service Management Data Center* All 2.x.x versions after 2.0.2
* All 3.x.x versions
* All 4.0.x, 4.1.x, 4.2.x, 4.3.x, 4.4.x ve[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical Jira Flaw in Atlassian Could Lead to RCE https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Jira Flaw in Atlassian Could Lead to RCEPost Views: 96 Reading Time:…
rsions
* All 4.5.x versions before 4.5.16
* All 4.6.x, 4.7.x, 4.8.x, 4.9.x, 4.10.x, 4.11.x, 4.12.x versions
* All 4.13.x versions before 4.13.8
* All 4.14.x, 4.15.x, 4.16.x versions
Atlassian’s advisory said that customers who have downloaded and installed any affected versions “must upgrade their installations immediately to fix this vulnerability.” Having said that, Atlassian also noted that the “critical” rating is its own assessment and that customers “should evaluate its applicability to your own IT environment.” Non-Affected VersionsHere’s the list of products that aren’t affected by the flaw:
* Atlassian Cloud
* Jira Cloud
* Jira Service Management Cloud
* Non-Data Center instances of Jira Server (Core & Software) and Jira Service Management
Also, customers who have upgraded Jira Data Center, Jira Core Data Center, Jira Software Data Center to versions 8.5.16, 8.13.8, 8.17.0 and/or Jira Service Management Data Center to versions 4.5.16, 4.13.8 or 4.17.0 are off the hook: They don’t need to upgrade.
Atlassian “strongly suggests” restricting access to the Ehcache ports to only Data Center instances, but noted that there’s a caveat: “Fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service,” according to the advisory. See Also: Offensive Security Tool: Veil Atlassian is Attacker CatnipSome of the largest enterprises with the most sophisticated product development use Atlassian products. Among its more than 65,000 users, Jira counts some big fans, including the likes of the Apache Software Foundation, Cisco, Fedora Commons, Hibernate, Pfizer and Visa.
Unfortunately, its popularity – particularly with the big fish – and its capabilities make it a tempting target for attackers.
In June, researchers uncovered Atlassian bugs that could have led to one-click takeover: A scenario that brought to mind the potential for an exploit that would have been similar to the SolarWinds supply-chain attack, in which attackers used a default password as an open door into a software-updating mechanism.
Chris Morgan, senior cyber-threat intelligence analyst at digital-risk provider Digital Shadows, said that the vulnerability at the heart of Wednesday’s advisory is just the latest in a series of bugs facing software engineering and management platforms that, if exploited, “could lead to a range of pernicious outcomes.”
While there’s no evidence of active exploitation at this time, we can expect attempts to show up in the coming one to three months, Morgan predicted. “CVE-2020-36239 can be remotely exploited to achieve arbitrary code execution and will likely be of great interest to both cybercriminals and nation-state-associated actors,” he said. He pointed to several recent supply-chain attacks, including attacks against software providers Accellion and Kaseya, that have leveraged vulnerabilities to gain initial access and to compromise software builds “known to be used by a diverse client base.”
Other security experts agreed with Morgan’s assessment. Andrew Barratt, managing principal of solutions and investigations at cybersecurity advisory firm Coalfire, told Threatpost on Thursday that the vulnerability Atlassian disclosed on Wednesday “shows that attackers are still looking to leverage economies of scale and compromise multiple parties using single platform-wide vulnerabilities.” Expect Exploitation, In the Wild AttacksTL;DR: Apply the update ASAP, or implement Atlassian’s workarounds, Morgan emphasized.
That said, the real impact depends on the exposure of the RMI APIs, Barratt suggested. “This could lead to targeted campaigns that focus on developers (historically who have lots of privileges and useful tools on their machines) that then seek to drop malware that exploits the Atlassian vulnerabilities for further manipulation of product development,” he said.
On the optimistic side, the issue may blow[...]
___________________________
@hacking_Attack
@Hacking_Video
* All 4.5.x versions before 4.5.16
* All 4.6.x, 4.7.x, 4.8.x, 4.9.x, 4.10.x, 4.11.x, 4.12.x versions
* All 4.13.x versions before 4.13.8
* All 4.14.x, 4.15.x, 4.16.x versions
Atlassian’s advisory said that customers who have downloaded and installed any affected versions “must upgrade their installations immediately to fix this vulnerability.” Having said that, Atlassian also noted that the “critical” rating is its own assessment and that customers “should evaluate its applicability to your own IT environment.” Non-Affected VersionsHere’s the list of products that aren’t affected by the flaw:
* Atlassian Cloud
* Jira Cloud
* Jira Service Management Cloud
* Non-Data Center instances of Jira Server (Core & Software) and Jira Service Management
Also, customers who have upgraded Jira Data Center, Jira Core Data Center, Jira Software Data Center to versions 8.5.16, 8.13.8, 8.17.0 and/or Jira Service Management Data Center to versions 4.5.16, 4.13.8 or 4.17.0 are off the hook: They don’t need to upgrade.
Atlassian “strongly suggests” restricting access to the Ehcache ports to only Data Center instances, but noted that there’s a caveat: “Fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service,” according to the advisory. See Also: Offensive Security Tool: Veil Atlassian is Attacker CatnipSome of the largest enterprises with the most sophisticated product development use Atlassian products. Among its more than 65,000 users, Jira counts some big fans, including the likes of the Apache Software Foundation, Cisco, Fedora Commons, Hibernate, Pfizer and Visa.
Unfortunately, its popularity – particularly with the big fish – and its capabilities make it a tempting target for attackers.
In June, researchers uncovered Atlassian bugs that could have led to one-click takeover: A scenario that brought to mind the potential for an exploit that would have been similar to the SolarWinds supply-chain attack, in which attackers used a default password as an open door into a software-updating mechanism.
Chris Morgan, senior cyber-threat intelligence analyst at digital-risk provider Digital Shadows, said that the vulnerability at the heart of Wednesday’s advisory is just the latest in a series of bugs facing software engineering and management platforms that, if exploited, “could lead to a range of pernicious outcomes.”
While there’s no evidence of active exploitation at this time, we can expect attempts to show up in the coming one to three months, Morgan predicted. “CVE-2020-36239 can be remotely exploited to achieve arbitrary code execution and will likely be of great interest to both cybercriminals and nation-state-associated actors,” he said. He pointed to several recent supply-chain attacks, including attacks against software providers Accellion and Kaseya, that have leveraged vulnerabilities to gain initial access and to compromise software builds “known to be used by a diverse client base.”
Other security experts agreed with Morgan’s assessment. Andrew Barratt, managing principal of solutions and investigations at cybersecurity advisory firm Coalfire, told Threatpost on Thursday that the vulnerability Atlassian disclosed on Wednesday “shows that attackers are still looking to leverage economies of scale and compromise multiple parties using single platform-wide vulnerabilities.” Expect Exploitation, In the Wild AttacksTL;DR: Apply the update ASAP, or implement Atlassian’s workarounds, Morgan emphasized.
That said, the real impact depends on the exposure of the RMI APIs, Barratt suggested. “This could lead to targeted campaigns that focus on developers (historically who have lots of privileges and useful tools on their machines) that then seek to drop malware that exploits the Atlassian vulnerabilities for further manipulation of product development,” he said.
On the optimistic side, the issue may blow[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
rsions * All 4.5.x versions before 4.5.16 * All 4.6.x, 4.7.x, 4.8.x, 4.9.x, 4.10.x, 4.11.x, 4.12.x versions * All 4.13.x versions before 4.13.8 * All 4.14.x, 4.15.x, 4.16.x versions Atlassian’s advisory said that customers who have downloaded and installed…
over before it gets dire, given that Atlassian is already issuing patches and advising on temporary mitigations, Barratt added. “Hopefully the window for this to be a problem will be minimal – and some follow-up review of the systems to check for indicators of compromise will give confidence that nothing serious has gone wrong.” See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Barratt thinks that the most concerning thing should be “the renewed focus on potentially a gold mine of opportunity.” While targeting developers isn’t new, he said, targeting their tools, platform and reducing potential confidence in the product “shows the need for security orchestration tools that can help bring the diversity of the problem to single-management view.”
On the technical side of things, Shawn Smith – director of infrastructure at application security provider nVisium – posited that supply-chain attacks are a good argument against auto-updating dependencies, but “this also means that security teams have to monitor and manage them effectively and efficiently,” as he told Threatpost via email on Thursday.
“Any updates to dependencies should be vetted prior to use, and systems should be using version-locked dependencies to prevent CI/CD systems from grabbing the latest updates by default,” he added. “At the same time, security teams should be monitoring to ensure that vulnerabilities are not tainting versions that are being used and advise developers and operations teams as issues arise.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/linkedin_generic-90x90.jpg Safari Zero-Day Used in Malicious LinkedIn Campaign7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Hello-e1626260072511-90x90.jpg Windows Hello Bypass Fools Biometrics Safeguards in PCs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/ICS-90x90.jpg Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/patching-against-ransomware-100723134-large-90x90.jpg Kaseya Patches Zero-Days Used in REvil Attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/cisco-90x90.jpg Cisco BPA, WSA Bugs Allow Remote Cyberattacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Untitled-design-8-90x90.png Coursera Flunks API Security Test in Researchers’ Exam2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Critical Jira Flaw in Atlassian Could Lead to RCE first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
On the technical side of things, Shawn Smith – director of infrastructure at application security provider nVisium – posited that supply-chain attacks are a good argument against auto-updating dependencies, but “this also means that security teams have to monitor and manage them effectively and efficiently,” as he told Threatpost via email on Thursday.
“Any updates to dependencies should be vetted prior to use, and systems should be using version-locked dependencies to prevent CI/CD systems from grabbing the latest updates by default,” he added. “At the same time, security teams should be monitoring to ensure that vulnerabilities are not tainting versions that are being used and advise developers and operations teams as issues arise.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/linkedin_generic-90x90.jpg Safari Zero-Day Used in Malicious LinkedIn Campaign7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Hello-e1626260072511-90x90.jpg Windows Hello Bypass Fools Biometrics Safeguards in PCs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/ICS-90x90.jpg Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/patching-against-ransomware-100723134-large-90x90.jpg Kaseya Patches Zero-Days Used in REvil Attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/cisco-90x90.jpg Cisco BPA, WSA Bugs Allow Remote Cyberattacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Untitled-design-8-90x90.png Coursera Flunks API Security Test in Researchers’ Exam2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Critical Jira Flaw in Atlassian Could Lead to RCE first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video