RESEARCH METHODOLOGIES FOR BUG BOUNTY HUNTERS
Good morning everyone , its me Kamal Sharma from Nepal. Cyber security has been so important in today’s world. Social media has…Continue reading on Medium »
Read more...
Good morning everyone , its me Kamal Sharma from Nepal. Cyber security has been so important in today’s world. Social media has…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mobile Hack Hone Se Kaise Bachaye : Complete Guide 2021
https://cdn-images-1.medium.com/max/1024/0*N9pTHD4oLXYPPslV.jpg
भारत में साइबर अटैक बहुत बड़ा मुद्दा है इसमें बहुत सारे लोगो के मोबाइल हैक हो चुके है। कई बार बैंक से पैसे उड़ चुके है और इसके अलावा कई बार…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Mobile Hack Hone Se Kaise Bachaye : Complete Guide 2021
https://cdn-images-1.medium.com/max/1024/0*N9pTHD4oLXYPPslV.jpg
भारत में साइबर अटैक बहुत बड़ा मुद्दा है इसमें बहुत सारे लोगो के मोबाइल हैक हो चुके है। कई बार बैंक से पैसे उड़ चुके है और इसके अलावा कई बार…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Mobile Hack Hone Se Kaise Bachaye : Complete Guide 2021
भारत में साइबर अटैक बहुत बड़ा मुद्दा है इसमें बहुत सारे लोगो के मोबाइल हैक हो चुके है। कई बार बैंक से पैसे उड़ चुके है और इसके अलावा कई बार…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Babuk Ransomware Gang Ransomed, New Forum Stuffed With Porn
https://external-preview.redd.it/xudEvE8sp4biCvOCsM5eiCIecn3odtO5Qo5dzU7dnaE.jpg?width=320&crop=smart&auto=webp&s=fc23eafcd1c6e0d26cc0452fa755a1f518a2a875 submitted by /u/TheCyberPost1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Babuk Ransomware Gang Ransomed, New Forum Stuffed With Porn
https://external-preview.redd.it/xudEvE8sp4biCvOCsM5eiCIecn3odtO5Qo5dzU7dnaE.jpg?width=320&crop=smart&auto=webp&s=fc23eafcd1c6e0d26cc0452fa755a1f518a2a875 submitted by /u/TheCyberPost1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Babuk Ransomware Gang Ransomed, New Forum Stuffed With Porn
Posted in r/deepweb by u/TheCyberPost1 • 1 point and 1 comment
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple Patches Actively Exploited Zero-Day in iOS, MacOS
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOSPost Views: 75
Reading Time: 1 Minute
Company urges iPhone, iPad and Mac users to install updates to fix a critical memory corruption flaw that can allow for attackers to take over a system.
Apple patched a zero-day flaw on Monday, found in both its iOS and macOS platforms that’s being actively exploited in the wild and can allow attackers to take over an affected system.
The memory-corruption flaw, tracked as CVE-2021-30807, is found in the IOMobileFrameBuffer extension which exists in both iOS and macOS, but has been fixed according to specific device platform.
Apple released three updates, iOS 14.7., iPadOS 14.7.1 and macOS Big Sur 11.5.1 to patch the vulnerability on each of the platforms Monday.
Exploiting CVE-2021-30807 can allow for threat actors “to execute arbitrary code with kernel privileges,” Apple said in documentation describing the updates.
“Apple is aware of a report that this issue may have been actively exploited,” the company said. Apple addressed the issue in each of the updates with “improve memory handling,” the company said.
iOS devices that should be updated immediately are: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
Though Apple attributed the discovery of the bug to an “anonymous researcher,” a security researcher at the Microsoft Security Response Center (MSRC) came forward separately on Monday and tweeted that he had discovered the vulnerability some time ago but hadn’t yet found the time to report it to Apple.
“So, as it turns out, an LPE vulnerability I found 4 months ago in IOMFB is now patched in iOS 14.7.1 as in-the-wild,” Saar Amar wrote on Twitter, sharing a link to “some knowledge and details about the bug and some ways to exploit it.”
In the linked documentation, Amar describes the vulnerability as “straightforward” and existing “in a flow called from the external method 83 of AppleCLCD/IOMFB (which is IOMobileFramebufferUserClient::s_displayed_fb_surface).” See Also: Offensive Security Tool: VoIPmonitor Sniffer To trigger the flaw, “simply calling the external method 83 will do the job (and we can obtain the userclient to AppleCLCD/IMOFB from the app sandbox),” Amar wrote. He describes a proof of concept exploit in detail in his post.
Amar said he planned to “find some extra time to work on it in August,” but Apple released its updates patching the flaw before he got around to it.
“Just to be clear, I intended to submit this bug to Apple right after I’ll finish the exploit [SIC],” he wrote. “I wanted to get a high- quality submission, but I did not have the time to invest in March.” See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker As iPhone users update to fix yet another Apple zero-day, they also continue waiting for the company to patch a flaw that makes their devices easy prey for Pegasus spyware. Last week leaked data suggested that the notorious Pegasus mobile spyware from Israeli-based NSO Group is exploiting a zero-click zero-day in Apple’s iMessage feature.
The news and evidence of a Pegasus spyware blitz spurred discussion about the security of Apple’s closed ecosystem and a call for accountability and potential changes to the company’s security model.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content[...]
___________________________
@hacking_Attack
@Hacking_Video
Apple Patches Actively Exploited Zero-Day in iOS, MacOS
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOSPost Views: 75
Reading Time: 1 Minute
Company urges iPhone, iPad and Mac users to install updates to fix a critical memory corruption flaw that can allow for attackers to take over a system.
Apple patched a zero-day flaw on Monday, found in both its iOS and macOS platforms that’s being actively exploited in the wild and can allow attackers to take over an affected system.
The memory-corruption flaw, tracked as CVE-2021-30807, is found in the IOMobileFrameBuffer extension which exists in both iOS and macOS, but has been fixed according to specific device platform.
Apple released three updates, iOS 14.7., iPadOS 14.7.1 and macOS Big Sur 11.5.1 to patch the vulnerability on each of the platforms Monday.
Exploiting CVE-2021-30807 can allow for threat actors “to execute arbitrary code with kernel privileges,” Apple said in documentation describing the updates.
“Apple is aware of a report that this issue may have been actively exploited,” the company said. Apple addressed the issue in each of the updates with “improve memory handling,” the company said.
iOS devices that should be updated immediately are: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
See Also: Microsoft: New Unpatched Bug in Windows Print Spooler
Though Apple attributed the discovery of the bug to an “anonymous researcher,” a security researcher at the Microsoft Security Response Center (MSRC) came forward separately on Monday and tweeted that he had discovered the vulnerability some time ago but hadn’t yet found the time to report it to Apple.
“So, as it turns out, an LPE vulnerability I found 4 months ago in IOMFB is now patched in iOS 14.7.1 as in-the-wild,” Saar Amar wrote on Twitter, sharing a link to “some knowledge and details about the bug and some ways to exploit it.”
In the linked documentation, Amar describes the vulnerability as “straightforward” and existing “in a flow called from the external method 83 of AppleCLCD/IOMFB (which is IOMobileFramebufferUserClient::s_displayed_fb_surface).” See Also: Offensive Security Tool: VoIPmonitor Sniffer To trigger the flaw, “simply calling the external method 83 will do the job (and we can obtain the userclient to AppleCLCD/IMOFB from the app sandbox),” Amar wrote. He describes a proof of concept exploit in detail in his post.
Amar said he planned to “find some extra time to work on it in August,” but Apple released its updates patching the flaw before he got around to it.
“Just to be clear, I intended to submit this bug to Apple right after I’ll finish the exploit [SIC],” he wrote. “I wanted to get a high- quality submission, but I did not have the time to invest in March.” See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker As iPhone users update to fix yet another Apple zero-day, they also continue waiting for the company to patch a flaw that makes their devices easy prey for Pegasus spyware. Last week leaked data suggested that the notorious Pegasus mobile spyware from Israeli-based NSO Group is exploiting a zero-click zero-day in Apple’s iMessage feature.
The news and evidence of a Pegasus spyware blitz spurred discussion about the security of Apple’s closed ecosystem and a call for accountability and potential changes to the company’s security model.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple Patches Actively Exploited Zero-Day in iOS, MacOS https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOSPost Views: 75 …
/uploads/2021/07/Windows-Abstract-90x90.jpg Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Ransomware-Key-90x90.jpg Kaseya Obtains Universal Decryptor for REvil Ransomware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/linkedin_generic-90x90.jpg Safari Zero-Day Used in Malicious LinkedIn Campaign2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Hello-e1626260072511-90x90.jpg Windows Hello Bypass Fools Biometrics Safeguards in PCs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/ICS-90x90.jpg Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Apple Patches Actively Exploited Zero-Day in iOS, MacOS first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Ransomware-Key-90x90.jpg Kaseya Obtains Universal Decryptor for REvil Ransomware2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/linkedin_generic-90x90.jpg Safari Zero-Day Used in Malicious LinkedIn Campaign2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Hello-e1626260072511-90x90.jpg Windows Hello Bypass Fools Biometrics Safeguards in PCs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/ICS-90x90.jpg Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Apple Patches Actively Exploited Zero-Day in iOS, MacOS first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Updating Nuclei in Kali Linux
Instructions to update Nuclei on Kali Linux.Continue reading on Medium »
Read more...
Instructions to update Nuclei on Kali Linux.Continue reading on Medium »
Read more...
Updating Nuclei in Kali Linux
https://medium.com/@sherlock297/updating-nuclei-in-kali-linux-8596643bb373?source=rss------bug_bounty-5
Instructions to update Nuclei on Kali Linux.Continue reading on Medium » (https://medium.com/@sherlock297/updating-nuclei-in-kali-linux-8596643bb373?source=rss------bug_bounty-5)
https://medium.com/@sherlock297/updating-nuclei-in-kali-linux-8596643bb373?source=rss------bug_bounty-5
Instructions to update Nuclei on Kali Linux.Continue reading on Medium » (https://medium.com/@sherlock297/updating-nuclei-in-kali-linux-8596643bb373?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Terra guard : Create And Destroy Your Own VPN Service Using Wire Guard
Terra guard’s goal is to be simple to create and destroy your own VPN service using Wire Guard. Prerequisites Terraform >= 1.0.0 Ansible >= 2.10.5 How To Deploy Terraform Run with sudo is necessary because we need permission on localhost to install packages, configure a network interface and start a process. Select your cloud provider AWS, DigitalOcean and open […]
The post Terra guard : Create And Destroy Your Own VPN Service Using Wire Guard appeared first on Kali Linux Tutorials.
Terra guard : Create And Destroy Your Own VPN Service Using Wire Guard
Terra guard’s goal is to be simple to create and destroy your own VPN service using Wire Guard. Prerequisites Terraform >= 1.0.0 Ansible >= 2.10.5 How To Deploy Terraform Run with sudo is necessary because we need permission on localhost to install packages, configure a network interface and start a process. Select your cloud provider AWS, DigitalOcean and open […]
The post Terra guard : Create And Destroy Your Own VPN Service Using Wire Guard appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
MANSPIDER : Spider Entire Networks For Juicy Files Sitting On SMB Shares. Search Filenames Or File Content – Regex Supported!
MANSPIDER will crawl every share on every target system. If provided creds don’t work, it will fall back to “guest”, then to a null session. File Types Supported PDF DOCX XLSX PPTX any text-based format and many more!! Installation Install these dependencies to add additional file parsing capability: #for images (png, jpeg)$ sudo apt install […]
The post MANSPIDER : Spider Entire Networks For Juicy Files Sitting On SMB Shares. Search Filenames Or File Content – Regex Supported! appeared first on Kali Linux Tutorials.
MANSPIDER : Spider Entire Networks For Juicy Files Sitting On SMB Shares. Search Filenames Or File Content – Regex Supported!
MANSPIDER will crawl every share on every target system. If provided creds don’t work, it will fall back to “guest”, then to a null session. File Types Supported PDF DOCX XLSX PPTX any text-based format and many more!! Installation Install these dependencies to add additional file parsing capability: #for images (png, jpeg)$ sudo apt install […]
The post MANSPIDER : Spider Entire Networks For Juicy Files Sitting On SMB Shares. Search Filenames Or File Content – Regex Supported! appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
LoGiC.NET - A More Advanced Free And Open .NET Obfuscator Using Dnlib
http://4.bp.blogspot.com/-omIGXli5zo4/YPtaxfDlcgI/AAAAAAAAm2g/ew1he_-qQMUvlN08UY4gfqNQ2KgDAsBxgCK4BGAYYCw/w640-h344/LoGiC.NET_2_after-702574.png
LoGiC.NET is a free and open-source .NET obfuscator that uses dnlib for folks that want to see how obfuscation works with more complex obfuscations than Goldfuscator for example.
Before obfuscation
http://2.bp.blogspot.com/-Kaq-GK_1_1Q/YPtavQ-jrAI/AAAAAAAAm2Y/d8E6S3WPS40SxW9vo5qdLYt5to-rBHjeACK4BGAYYCw/w640-h344/LoGiC.NET_1_before-795320.png
After obfuscation
http://4.bp.blogspot.com/-omIGXli5zo4/YPtaxfDlcgI/AAAAAAAAm2g/ew1he_-qQMUvlN08UY4gfqNQ2KgDAsBxgCK4BGAYYCw/w640-h344/LoGiC.NET_2_after-702574.png
Dependencies
dnlib v3.3.2 : Restore NuGet packages and it'll work (if it doesn't already).
SharpConfigParser : https://github.com/AnErrupTion/LoGiC.NET/raw/master/SharpConfigParser.dll
Current Features
* Renames methods, parameters, properties, fields and events.
* Adds proxy calls.
* Encrypts strings.
* Encodes ints.
* Adds junk methods.
* Prevents application tampering.
* Adds control flow.
* And more!
TODO
* Add an Anti-Emulation and Anti-Debug.
Download LoGiC.NET
LoGiC.NET - A More Advanced Free And Open .NET Obfuscator Using Dnlib
http://4.bp.blogspot.com/-omIGXli5zo4/YPtaxfDlcgI/AAAAAAAAm2g/ew1he_-qQMUvlN08UY4gfqNQ2KgDAsBxgCK4BGAYYCw/w640-h344/LoGiC.NET_2_after-702574.png
LoGiC.NET is a free and open-source .NET obfuscator that uses dnlib for folks that want to see how obfuscation works with more complex obfuscations than Goldfuscator for example.
Before obfuscation
http://2.bp.blogspot.com/-Kaq-GK_1_1Q/YPtavQ-jrAI/AAAAAAAAm2Y/d8E6S3WPS40SxW9vo5qdLYt5to-rBHjeACK4BGAYYCw/w640-h344/LoGiC.NET_1_before-795320.png
After obfuscation
http://4.bp.blogspot.com/-omIGXli5zo4/YPtaxfDlcgI/AAAAAAAAm2g/ew1he_-qQMUvlN08UY4gfqNQ2KgDAsBxgCK4BGAYYCw/w640-h344/LoGiC.NET_2_after-702574.png
Dependencies
dnlib v3.3.2 : Restore NuGet packages and it'll work (if it doesn't already).
SharpConfigParser : https://github.com/AnErrupTion/LoGiC.NET/raw/master/SharpConfigParser.dll
Current Features
* Renames methods, parameters, properties, fields and events.
* Adds proxy calls.
* Encrypts strings.
* Encodes ints.
* Adds junk methods.
* Prevents application tampering.
* Adds control flow.
* And more!
TODO
* Add an Anti-Emulation and Anti-Debug.
Download LoGiC.NET
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pegasus: A Friend Or a Foe | What is Pegasus? | Dangerous or Not
https://cdn-images-1.medium.com/max/2048/1*_KR8QkJ-T3M7LsYubiZu9w.jpeg
What if I say I can hear your voice calls with your wife OR girlfriend? , or what if I say, I can tell u what your boss said to you in…
Continue reading on Medium »
Pegasus: A Friend Or a Foe | What is Pegasus? | Dangerous or Not
https://cdn-images-1.medium.com/max/2048/1*_KR8QkJ-T3M7LsYubiZu9w.jpeg
What if I say I can hear your voice calls with your wife OR girlfriend? , or what if I say, I can tell u what your boss said to you in…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
47 Insanely Useful Websites You Probably Have Never Seen
https://cdn-images-1.medium.com/max/612/0*cnKxVcS5HG90eA-L
These websites will give you a jaw-dropping experience, and you will embrace the ~world wide~ web even more.
Continue reading on Age of Awareness »
47 Insanely Useful Websites You Probably Have Never Seen
https://cdn-images-1.medium.com/max/612/0*cnKxVcS5HG90eA-L
These websites will give you a jaw-dropping experience, and you will embrace the ~world wide~ web even more.
Continue reading on Age of Awareness »
LoGiC.NET - A More Advanced Free And Open .NET Obfuscator Using Dnlib
LoGiC.NET is a free and open-source .NET obfuscator that uses dnlib for folks that want to see how obfuscation works with more complex obfuscations than Goldfuscator for example.Before obfuscation After obfuscation Dependencies dnlib v3.3.2 : Restore NuGet packages and it'll work (if it doesn't already). SharpConfigParser : https://github.com/AnErrupTion/LoGiC.NET/raw/master/SharpConfigParser.dll Current Features Renames methods, parameters, properties, fields and events. Adds proxy calls. Encrypts strings. Encodes ints. Adds junk methods. Prevents application tampering. Adds control flow. And more! TODO Add an Anti-Emulation and Anti-Debug. Download LoGiC.NET
Read more...
LoGiC.NET is a free and open-source .NET obfuscator that uses dnlib for folks that want to see how obfuscation works with more complex obfuscations than Goldfuscator for example.Before obfuscation After obfuscation Dependencies dnlib v3.3.2 : Restore NuGet packages and it'll work (if it doesn't already). SharpConfigParser : https://github.com/AnErrupTion/LoGiC.NET/raw/master/SharpConfigParser.dll Current Features Renames methods, parameters, properties, fields and events. Adds proxy calls. Encrypts strings. Encodes ints. Adds junk methods. Prevents application tampering. Adds control flow. And more! TODO Add an Anti-Emulation and Anti-Debug. Download LoGiC.NET
Read more...