Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Kaseya Obtains Universal Decryptor for REvil Ransomware

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Kaseya Obtains Universal Decryptor for REvil RansomwarePost Views: 86
Reading Time: 1 Minute
Kaseya has obtained a master decryptor key for the REvil ransomware that locked up the systems of at least 60 of its customers in a spate of worldwide cyberattacks on July 2.
The vendor will work with customers affected by the early July spate of ransomware attacks to unlock files; it’s unclear if the ransom was paid.

The attacks, which exploited now-patched zero-days in the Kaseya Virtual System/Server Administrator (VSA) platform, affected Kaseya customers in 22 countries using the on-premises version of the platform – many of which are managed service providers (MSPs) who use VSA to manage the networks of other businesses. In addition to the 60 direct customers, around 1,500 downstream customers of those MSPs were also affected.

The VSA software is used by Kaseya customers to remotely monitor and manage software and network infrastructure.

In the wake of the attacks, the REvil gang (aka Sodinokibi) demanded $70 million for a universal public decryption key that will remediate all impacted victims – a price that one researcher said was eventually lowered to $50 million.

Late on Thursday afternoon, the vendor announced via its rolling advisory on the incident that it had obtained the decryptor “through a third party.” It’s unclear if the ransom was indeed paid.
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
“We can confirm that Kaseya obtained the tool from a third party and have teams actively helping customers affected by the ransomware to restore their environments, with no reports of any problem or issues associated with the decryptor,” it said. “Kaseya is working with Emsisoft to support our customer engagement efforts, and Emsisoft has confirmed the key is effective at unlocking victims…Customers who have been impacted by the ransomware will be contacted by Kaseya representatives.”

Deepening the mystery is the fact that REvil as a criminal organization went dark July 13, when its sites vanished and representatives were banned on prominent underground forums.

Emsisoft isn’t releasing further details: “We are working with Kaseya to support their customer engagement efforts,” Emsisoft said in a statement given to Threatpost. “We have confirmed the key is effective at unlocking victims and will continue to provide support to Kaseya and its customers.”

Threatpost has reached out to Kaseya as well and will update this post with any additional information.

“The sudden appearance of this universal key suggests that it is possible that this ransom may have been paid, although it is likely that the ransom would have been negotiate to a lower price,” Ivan Righi, cyber-threat intelligence analyst at Digital Shadows, said via email. See Also: Offensive Security Tool: VoIPmonitor Sniffer Despite Decryption, the Nightmare Isn’t OverEven though the master decryption key has been acquired, the attack should not be considered to be over, researchers warned. For one thing, REvil is known for its double-extortion attacks, where company data is stolen in addition to being hit with ransomware.

“The group may still have copies of data stolen from victims,” Righi said. “The group could use this data to extort victims or auction off the data, as it has done in the past on its website Happy Blog.”

Erich Kron, security awareness advocate at KnowBe4, noted that remediation will take more than simply applying the unlocking mechanism to files.

“Significant damage h[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Kaseya Obtains Universal Decryptor for REvil Ransomware https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Kaseya Obtains Universal Decryptor for REvil RansomwarePost Views: 86 …
as been done already in the way of downtime and recovery costs, both currently and in the future,” he noted via email. “Even with the data decrypted, there are significant costs associated with restoring devices and data. Simply decrypting the data does not resolve issues that remain, such as potentially installed back doors the attackers could use at a later date. This means there is still a lot of work ahead.”

Tim Wade, technical director on the CTO team at Vectra, said that there could be other nasty surprises for victims to watch out for following the attacks.

“From a distance, the emergence of a master key may appear more comforting than it should,” he warned. “The value of accelerating the restoration of data and services shouldn’t be trivialized, but it won’t exactly erase the already extensive cost of these attacks. And this is a cost carried both in terms of the historic disruption, but also given the proclivity of these criminal operators to leave lingering backdoors, the ongoing need to rebuild compromised infrastructure into a clean, trustworthy state. So yes, sidestepping how this key may have been acquired, it may have some positive outcomes but as they say – it isn’t over ’til it’s over.” See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Supply-Chain Attacks on MSPs SnowballWhile this particular attack was far-reaching and significant, it’s not the first cyberattack to affect MSPs and their downstream customers this year. The Clop ransomware gang for instance went after the Accellion legacy FTA software for file transfers in February; multiple Accellion FTA customers, including the Jones Day Law Firm, Kroger, Shell and Singtel were all affected.

The incidents point at a lesson for organizations of all sizes, researchers noted, when it comes to the MSP biz.

“Whenever an organization trusts external entities with the keys to their kingdom, they are undertaking a serious risk,” Kron said. “Likewise, when MSPs are given this access, it is imperative that they aggressively protect their customers. For organizations that have been taken down by ransomware due to the lack of backups, or if their backups were encrypted, leaving them vulnerable, this is a great time to have some hard discussions with their service providers in an effort to eliminate the threat in the future.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/linkedin_generic-90x90.jpg Safari Zero-Day Used in Malicious LinkedIn Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Hello-e1626260072511-90x90.jpg Windows Hello Bypass Fools Biometrics Safeguards in PCs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/ICS-90x90.jpg Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/patching-against-ransomware-100723134-large-90x90.jpg Kaseya Patches Zero-Days Used in REvil Attacks2 weeks ago[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
as been done already in the way of downtime and recovery costs, both currently and in the future,” he noted via email. “Even with the data decrypted, there are significant costs associated with restoring devices and data. Simply decrypting the data does not…
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/cisco-90x90.jpg Cisco BPA, WSA Bugs Allow Remote Cyberattacks2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Kaseya Obtains Universal Decryptor for REvil Ransomware first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How would you fake a long time history for a new website?

Could you, say, 3 years ago have created a boat load of random urls that can later be changed to show it being around for a long time? Maybe use your own systems to ping the sites a bunch with random IPs to make it show activity? Apologies if it sounds stupid. I'm not extremely tech savvy, I just stayed at a Holiday Inn Express last night.

submitted by /u/ToyotaSupra00
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is The Fanatical Cybersecurity Bundle Worth It?

Hello,

I recently saw this bundle on Fanatical containing 15 Packt books. I have an interest in cybersecurity and am looking for a simple introduction to basic concepts of the field. I am not close to college age nor do I have plans to become an IT professional. It seems that this publisher has a bad reputation for poor editing etc. but the bundle is only $10. In my situation is this purchase worth it? Can the books communicate well enough to get the basics through?

submitted by /u/Socrat3z1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Juumla - Tool Designed To Identify And Scan For Version, Config Files In The CMS Joomla!

https://1.bp.blogspot.com/-bbraG4TyDzU/YPn-wgjFLFI/AAAAAAAAk5k/DXwPnKiyZrAqUCOLnguHltVAj9qbkZkMwCNcBGAsYHQ/w640-h558/juumla_1_banner.png
Juumlais a python tool developed to identify the current Joomla version and scan for readable Joomla config files.

Installing / Getting started

A quick guide of how to install and use Juumla.

1. Clone the repository - git clone https://github.com/oppsec/juumla.git
2. Install the libraries - pip3 install -r requirements.txt
3. Run Juumla - python3 main.py -u https://example.com



Docker

If you want to run Juumla in a Docker container, follow this commands:

container - sudo docker run juumla:latest ">1. Clone the repository - git clone https://github.com/oppsec/juumla.git
2. Build the image - sudo docker build -t juumla:latest .
3. Run container - sudo docker run juumla:latest

Pre-requisites

* Python 3 installed on your machine.
* Install the libraries with pip3 install -r requirements.txt
Features

* Fast scan
* Low RAM and CPU usage
* Identify Joomla version
* Config files detection
* Open-Source
To-Do

* Vulnerability Scanner
* Improve Joomla detection
* Config files detection
* Improve code
Contributing

A quick guide of how to contribute with the project.

1. Create a fork from Juumla repository
2. Download the project with git clone https://github.com/your/juumla.git
3. Type cd juumla/
4. Make your changes
5. Commit and make a git push
6. Open a pull request

Resources

https://skynettools.com/juumla-python-cli-tool-for-joomla-information-hathering/
Warning

* The developer is not responsible for any malicious use of this tool.
Download Juumla

___________________________
@hacking_Attack
@Hacking_Video
Juumla is a python tool developed to identify the current Joomla version and scan (https://www.kitploit.com/search/label/Scan) for readable Joomla config files.
Installing / Getting started A quick guide of how to install and use Juumla. 1. Clone the repository - git clone https://github.com/oppsec/juumla.git
2. Install the libraries - pip3 install -r requirements.txt
3. Run Juumla - python3 main.py -u https://example.com

Docker If you want to run Juumla in a Docker container, follow this commands: container - sudo docker run juumla:latest ">1. Clone the repository - git clone https://github.com/oppsec/juumla.git
2. Build the image - sudo docker build -t juumla:latest .
3. Run container - sudo docker run juumla:latest

Pre-requisites Python 3 (https://www.python.org/downloads/) installed on your machine. Install the libraries with pip3 install -r requirements.txt
Features Fast scan Low RAM and CPU usage Identify Joomla version Config files detection Open-Source
To-Do Vulnerability (https://www.kitploit.com/search/label/Vulnerability) Scanner Improve Joomla detection Config files detection Improve code
Contributing A quick guide of how to contribute with the project. 1. Create a fork from Juumla repository
2. Download the project with git clone https://github.com/your/juumla.git
3. Type cd juumla/
4. Make your changes
5. Commit and make a git push
6. Open a pull request

Resources https://skynettools.com/juumla-python-cli-tool-for-joomla-information-hathering/
Warning The developer is not responsible for any malicious use of this tool.

Download Juumla (https://github.com/oppsec/juumla)

___________________________
@hacking_Attack
@Hacking_Video
Juumla - Tool Designed To Identify And Scan For Version, Config Files In The CMS Joomla!

Juumla is a python tool developed to identify the current Joomla version and scan for readable Joomla config files.Installing / Getting started A quick guide of how to install and use Juumla. 1. Clone the repository - git clone https://github.com/oppsec/juumla.git2. Install the libraries - pip3 install -r requirements.txt3. Run Juumla - python3 main.py -u https://example.com Docker If you want to run Juumla in a Docker container, follow this commands: container - sudo docker run juumla:latest ">1. Clone the repository - git clone https://github.com/oppsec/juumla.git2. Build the image - sudo docker build -t juumla:latest .3. Run container - sudo docker run juumla:latest Pre-requisites Python 3 installed on your machine. Install the libraries with pip3 install -r requirements.txt Features Fast scan Low RAM and CPU usage Identify Joomla version Config files detection Open-Source To-Do Vulnerability Scanner Improve Joomla detection Config files detection Improve code Contributing A quick guide of how to contribute with the project. 1. Create a fork from Juumla repository2. Download the project with git clone https://github.com/your/juumla.git3. Type cd juumla/4. Make your changes5. Commit and make a git push6. Open a pull request Resources https://skynettools.com/juumla-python-cli-tool-for-joomla-information-hathering/ Warning The developer is not responsible for any malicious use of this tool. Download Juumla
Read more...

___________________________
@hacking_Attack
@Hacking_Video