Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
LA MEJOR RECOMENDACIÓN EN SERVICIOS DE HACKER
https://cdn-images-1.medium.com/max/780/1*WLh5k8jLl6ZvZg6-DehMeg.jpeg
¿Cuánto cuesta contratar a un hacker?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
LA MEJOR RECOMENDACIÓN EN SERVICIOS DE HACKER
https://cdn-images-1.medium.com/max/780/1*WLh5k8jLl6ZvZg6-DehMeg.jpeg
¿Cuánto cuesta contratar a un hacker?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
LA MEJOR RECOMENDACIÓN EN SERVICIOS DE HACKER
¿Cuánto cuesta contratar a un hacker?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Are Your Accounts Safe from Social Media Hacking?
As a social media manager, you have a million things to think about every day. Creating campaigns, organizing graphics, responding to fans…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Are Your Accounts Safe from Social Media Hacking?
As a social media manager, you have a million things to think about every day. Creating campaigns, organizing graphics, responding to fans…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Are Your Accounts Safe from Social Media Hacking?
As a social media manager, you have a million things to think about every day. Creating campaigns, organizing graphics, responding to fans…
Deep Web
Don’t own a PC. Need some help and recommendations . (I have done some digging already I promise)
I’ve read the list of known hardware issues, FAQ, and I did some digging on reddit and google.
Since I have to buy a PC anyways, which one will run tails uninterrupted, no keyboard issues, no nothin. That’s cheap. I went to Best Buy, target, and Walmart today they had nothing in the burner price range.
Thanks ✌️
submitted by /u/Grennywop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Don’t own a PC. Need some help and recommendations . (I have done some digging already I promise)
I’ve read the list of known hardware issues, FAQ, and I did some digging on reddit and google.
Since I have to buy a PC anyways, which one will run tails uninterrupted, no keyboard issues, no nothin. That’s cheap. I went to Best Buy, target, and Walmart today they had nothing in the burner price range.
Thanks ✌️
submitted by /u/Grennywop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Don’t own a PC. Need some help and recommendations . (I have done...
I’ve read the list of known hardware issues, FAQ, and I did some digging on reddit and google. Since I have to buy a PC anyways, which one will...
CVE-2021–35343
https://medium.com/@cyberdivision/cve-2021-35343-c5c298cbb2d4?source=rss------bug_bounty-5
# Exploit Title: SeedDMS v5.1.xContinue reading on Medium » (https://medium.com/@cyberdivision/cve-2021-35343-c5c298cbb2d4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@cyberdivision/cve-2021-35343-c5c298cbb2d4?source=rss------bug_bounty-5
# Exploit Title: SeedDMS v5.1.xContinue reading on Medium » (https://medium.com/@cyberdivision/cve-2021-35343-c5c298cbb2d4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2021–35343
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.Ajax.php # Date…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Phishing Attack With Social Engineering Techniques
https://cdn-images-1.medium.com/max/600/0*w1qywSPUohX4dYrV
This is how easy to phish someone with good Social engineering Techniques
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Phishing Attack With Social Engineering Techniques
https://cdn-images-1.medium.com/max/600/0*w1qywSPUohX4dYrV
This is how easy to phish someone with good Social engineering Techniques
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Phishing Attack With Social Engineering Techniques
This is how easy to phish someone with good Social engineering Techniques
What Lab setup do you use for testing TTPs?
https://www.reddit.com/r/redteamsec/comments/owaww6/what_lab_setup_do_you_use_for_testing_ttps/
If you want to test a specific TTP, an attack or a Tool, how do you do that? Do you use AWS for the Lab? If you are mimicking an Enterprise network, what hosts do you have in that Lab? submitted by /u/FOSS_Lover (https://www.reddit.com/user/FOSS_Lover)
[link] (https://www.reddit.com/r/redteamsec/comments/owaww6/what_lab_setup_do_you_use_for_testing_ttps/) [comments] (https://www.reddit.com/r/redteamsec/comments/owaww6/what_lab_setup_do_you_use_for_testing_ttps/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/owaww6/what_lab_setup_do_you_use_for_testing_ttps/
If you want to test a specific TTP, an attack or a Tool, how do you do that? Do you use AWS for the Lab? If you are mimicking an Enterprise network, what hosts do you have in that Lab? submitted by /u/FOSS_Lover (https://www.reddit.com/user/FOSS_Lover)
[link] (https://www.reddit.com/r/redteamsec/comments/owaww6/what_lab_setup_do_you_use_for_testing_ttps/) [comments] (https://www.reddit.com/r/redteamsec/comments/owaww6/what_lab_setup_do_you_use_for_testing_ttps/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: What Lab setup do you use for testing TTPs?
Posted by u/FOSS_Lover - 18 votes and 13 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
NSA Warns Public Networks are Hacker Hotbeds
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg NSA Warns Public Networks are Hacker HotbedsPost Views: 63
Reading Time: 1 Minute
The U.S. National Security Agency is offering advice to security teams looking for wireless best practices to protect corporate networks and personal devices. The recommendations, while pedestrian in scope, do offer system administrators a solid cheat sheet to share with their work-from-home crowd and mobile workforces.
For starters the NSA, in a public service announcement posted on Thursday (PDF), urged security teams to be mindful of the wireless threats employees face when using Wi-Fi networks. It also lumps Bluetooth technology and Near Field Communications (NFC) into its list of worrisome protocols.
By now, café-based workers have likely mastered both public bathroom and Wi-Fi hotspot hygiene. But, for anyone who hasn’t the NSA advises: “Data sent over public Wi-Fi—especially open public Wi-Fi that does not require a password to access— is vulnerable to theft or manipulation.”
Advice also includes warnings of fake access points that can vacuum up user credentials and skim other personal data retrieved on the “evil twin” access points. NSA Warns of BluetoothMore interestingly, the agency cites Bluetooth as a convenient protocol for private use, but when used in public settings it can be a nasty security liability. The NSA advises turning off Bluetooth in public, lest a user be open to a range of attacks such as BlueBorne or BlueBugging – both used to access and exfiltrate corporate data on targeted devices.
Just last May, security researcher Fabian Braunlein with Positive Security identified Apple’s Send My Bluetooth exploit which allowed data to be exfiltrated from a device to an attacker-controlled Apple iCloud server. Worrisome NFCThe NSA also touched on Near Field Communications (NFC), a handy tool for contactless payments. It said data transfer between devices using NFC can be a cybersecurity minefield of pitfalls. With just a tap data, is moved across a radio network from one device to another.
Andy Norton a cyber-risk officer with Armis told Threatpost security teams are lagging behind when it comes to securing NFC communications.
See Also: Hackers used never-before-seen wiper in recent attack on Iranian train system “Radio connected devices represents a huge risk blind spot for organizations,” Norton said. “These are very much the soft underbelly of information security controls –– the majority of energy, focus, and money from a cyber resilience perspective is spent on preventing attacks coming through the internet connected attack surface. Very little is being done to access the risk from near field radio connections.”
He added on just about every job his team finds a “rogue antenna device and shadow IT activity from antenna-enabled IoT devices.”
In its security bulletin, the NSA suggests:
* Disable NFC feature when not needed (if possible).
* Do not bring devices near other unknown electronic devices. (This can trigger automatic communication.)
* Do not use NFC to communicate passwords or sensitive data.
“Users should consider additional security measures, including limiting/disabling device location features, using strong device passwords, and only using trusted device accessories, such as original charging cords,” said the NSA. See Also: Offensive Security Tool: Ruler User Behavior Biggest Cybersecurity Challenge
The NSA’s wireless warnings, while basic, still go unheeded by too many. Sadly, the practical and basic advice still needs promoted, experts said.
“My fear is that the don’[...]
___________________________
@hacking_Attack
@Hacking_Video
NSA Warns Public Networks are Hacker Hotbeds
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg NSA Warns Public Networks are Hacker HotbedsPost Views: 63
Reading Time: 1 Minute
The U.S. National Security Agency is offering advice to security teams looking for wireless best practices to protect corporate networks and personal devices. The recommendations, while pedestrian in scope, do offer system administrators a solid cheat sheet to share with their work-from-home crowd and mobile workforces.
For starters the NSA, in a public service announcement posted on Thursday (PDF), urged security teams to be mindful of the wireless threats employees face when using Wi-Fi networks. It also lumps Bluetooth technology and Near Field Communications (NFC) into its list of worrisome protocols.
By now, café-based workers have likely mastered both public bathroom and Wi-Fi hotspot hygiene. But, for anyone who hasn’t the NSA advises: “Data sent over public Wi-Fi—especially open public Wi-Fi that does not require a password to access— is vulnerable to theft or manipulation.”
Advice also includes warnings of fake access points that can vacuum up user credentials and skim other personal data retrieved on the “evil twin” access points. NSA Warns of BluetoothMore interestingly, the agency cites Bluetooth as a convenient protocol for private use, but when used in public settings it can be a nasty security liability. The NSA advises turning off Bluetooth in public, lest a user be open to a range of attacks such as BlueBorne or BlueBugging – both used to access and exfiltrate corporate data on targeted devices.
Just last May, security researcher Fabian Braunlein with Positive Security identified Apple’s Send My Bluetooth exploit which allowed data to be exfiltrated from a device to an attacker-controlled Apple iCloud server. Worrisome NFCThe NSA also touched on Near Field Communications (NFC), a handy tool for contactless payments. It said data transfer between devices using NFC can be a cybersecurity minefield of pitfalls. With just a tap data, is moved across a radio network from one device to another.
Andy Norton a cyber-risk officer with Armis told Threatpost security teams are lagging behind when it comes to securing NFC communications.
See Also: Hackers used never-before-seen wiper in recent attack on Iranian train system “Radio connected devices represents a huge risk blind spot for organizations,” Norton said. “These are very much the soft underbelly of information security controls –– the majority of energy, focus, and money from a cyber resilience perspective is spent on preventing attacks coming through the internet connected attack surface. Very little is being done to access the risk from near field radio connections.”
He added on just about every job his team finds a “rogue antenna device and shadow IT activity from antenna-enabled IoT devices.”
In its security bulletin, the NSA suggests:
* Disable NFC feature when not needed (if possible).
* Do not bring devices near other unknown electronic devices. (This can trigger automatic communication.)
* Do not use NFC to communicate passwords or sensitive data.
“Users should consider additional security measures, including limiting/disabling device location features, using strong device passwords, and only using trusted device accessories, such as original charging cords,” said the NSA. See Also: Offensive Security Tool: Ruler User Behavior Biggest Cybersecurity Challenge
The NSA’s wireless warnings, while basic, still go unheeded by too many. Sadly, the practical and basic advice still needs promoted, experts said.
“My fear is that the don’[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking NSA Warns Public Networks are Hacker Hotbeds https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg NSA Warns Public Networks are Hacker HotbedsPost Views: 63 Reading Time: 1 Minute…
ts are ingrained, existing behaviors that are not easy to change and at times unavoidable,” Setu Kulkarni with NTT Application Security said. “For example, while it is easy to say ‘Do not bring devices near other unknown electronic devices,’ is that practical?” See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker Kulkarni added in an ideal world one key employee cybersecurity rule companies should have in place is keeping personal stuff of their business devices. Enforcing compliance gets much trickier.
“These tips are as relevant in 2021 as they were in 2015, but with the shift to more remote work, there are more people using public Wi-Fi,” said Tim Erlin with Tripwire. “While these tips are useful, it can be hard for the average user to understand how to implement them. There’s really a substantial amount of work here for the average user to comply with the recommended settings.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/iran-thumb-90x90.jpg Hackers used never-before-seen wiper in recent attack on Iranian train system3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/PunkSpider-90x90.png Reboot of PunkSpider Tool at DEF CON Stirs Debate4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/apple-mac-security-90x90.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOS5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Abstract-90x90.jpg Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Ransomware-Key-90x90.jpg Kaseya Obtains Universal Decryptor for REvil Ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post NSA Warns Public Networks are Hacker Hotbeds first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
“These tips are as relevant in 2021 as they were in 2015, but with the shift to more remote work, there are more people using public Wi-Fi,” said Tim Erlin with Tripwire. “While these tips are useful, it can be hard for the average user to understand how to implement them. There’s really a substantial amount of work here for the average user to comply with the recommended settings.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/iran-thumb-90x90.jpg Hackers used never-before-seen wiper in recent attack on Iranian train system3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/PunkSpider-90x90.png Reboot of PunkSpider Tool at DEF CON Stirs Debate4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/apple-mac-security-90x90.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOS5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Abstract-90x90.jpg Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Ransomware-Key-90x90.jpg Kaseya Obtains Universal Decryptor for REvil Ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Microsoft-Office-90x90.jpg Microsoft: New Unpatched Bug in Windows Print Spooler2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post NSA Warns Public Networks are Hacker Hotbeds first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
CVE-2021–35343
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.Ajax.php # Date…Continue reading on Medium »
Read more...
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.Ajax.php # Date…Continue reading on Medium »
Read more...
CVE-2021–36542
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.LockDocument.php #…Continue reading on Medium »
Read more...
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.LockDocument.php #…Continue reading on Medium »
Read more...
CVE-2021–36543
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.UnlockDocument.php #…Continue reading on Medium »
Read more...
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.UnlockDocument.php #…Continue reading on Medium »
Read more...
hacking: security in practice
I am doxing Awkward Turtle
I am fucking mad at him I will post his location here when I find it
submitted by /u/ZoneZeus123
[link] [comments]
I am doxing Awkward Turtle
I am fucking mad at him I will post his location here when I find it
submitted by /u/ZoneZeus123
[link] [comments]
reddit
I am doxing Awkward Turtle
I am fucking mad at him I will post his location here when I find it
hacking: security in practice
Could this be a workable exploit?
So im not gonna lie, im a mischievous kid. So in a year im going to be going to college, and im guessing that vpns and their usage will be banned. Now i dont know how logging onto the wifi works, but im guessing its not like a normal wifi logon and each person's traffic can be individually monitored.
So here is what I was thinking: I have two laptops that run windows 10. One however, is a burner laptop. the other, i do work on and it a powerful laptop. I was thinking that i can connect to the wifi on the burner laptop, and then setup a hotspot on that burner laptop, and then connect to that on my work laptop and use a vpn on the work laptop. Would they be able to see the vpn even through the hotspot?
I do not know too much about networking but it seems like it would be really difficult to catch without a wifi sniffer, am I right?
submitted by /u/man_wif-waluigi-hed
[link] [comments]
Could this be a workable exploit?
So im not gonna lie, im a mischievous kid. So in a year im going to be going to college, and im guessing that vpns and their usage will be banned. Now i dont know how logging onto the wifi works, but im guessing its not like a normal wifi logon and each person's traffic can be individually monitored.
So here is what I was thinking: I have two laptops that run windows 10. One however, is a burner laptop. the other, i do work on and it a powerful laptop. I was thinking that i can connect to the wifi on the burner laptop, and then setup a hotspot on that burner laptop, and then connect to that on my work laptop and use a vpn on the work laptop. Would they be able to see the vpn even through the hotspot?
I do not know too much about networking but it seems like it would be really difficult to catch without a wifi sniffer, am I right?
submitted by /u/man_wif-waluigi-hed
[link] [comments]
reddit
Could this be a workable exploit?
So im not gonna lie, im a mischievous kid. So in a year im going to be going to college, and im guessing that vpns and their usage will be banned....
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Stb_truetype library heap buffer overflows (many CVEs, no CVEs yet)
A 16k stars project, used in, I can imagine game engines, UI, Android/iOS/embedded. Used in another 30k stars project and 11k from even Google (also possibly not fixed). OpenCV 55k stars seems to be also affected (new branch only). Attack vector through malicious font. Buy me a beer if you will get bounty on it and also initial fuzzing person https://github.com/nothings/stb/issues/618
Per Developer library was not intended to work with untrusted data.
Be careful when using it, consider a replacement. This is a PSA.
Thanks,
P.S Full thread here: https://twitter.com/marcinguy/status/1421740689516339200?s=19
submitted by /u/marcinguy
[link] [comments]
Stb_truetype library heap buffer overflows (many CVEs, no CVEs yet)
A 16k stars project, used in, I can imagine game engines, UI, Android/iOS/embedded. Used in another 30k stars project and 11k from even Google (also possibly not fixed). OpenCV 55k stars seems to be also affected (new branch only). Attack vector through malicious font. Buy me a beer if you will get bounty on it and also initial fuzzing person https://github.com/nothings/stb/issues/618
Per Developer library was not intended to work with untrusted data.
Be careful when using it, consider a replacement. This is a PSA.
Thanks,
P.S Full thread here: https://twitter.com/marcinguy/status/1421740689516339200?s=19
submitted by /u/marcinguy
[link] [comments]
hacking: security in practice
Make a RAT Trojan (in python) ?
Hello, I made a RAT Trojan in python and it works well but of course when I test it on multi network it’s not working. How it works ? What should I enter in the socket.connect (which IP )? Thanks
submitted by /u/Mx_Mlr
[link] [comments]
Make a RAT Trojan (in python) ?
Hello, I made a RAT Trojan in python and it works well but of course when I test it on multi network it’s not working. How it works ? What should I enter in the socket.connect (which IP )? Thanks
submitted by /u/Mx_Mlr
[link] [comments]
reddit
Make a RAT Trojan (in python) ?
Hello, I made a RAT Trojan in python and it works well but of course when I test it on multi network it’s not working. How it works ? What should...
hacking: security in practice
Is it legal to IP track a hacker after getting hacked
I'm only asking because I lost my Steam account to a hacker and was wondering if I could IP tracking and bring them to Justice
submitted by /u/starknight23Yt
[link] [comments]
Is it legal to IP track a hacker after getting hacked
I'm only asking because I lost my Steam account to a hacker and was wondering if I could IP tracking and bring them to Justice
submitted by /u/starknight23Yt
[link] [comments]
reddit
Is it legal to IP track a hacker after getting hacked
I'm only asking because I lost my Steam account to a hacker and was wondering if I could IP tracking and bring them to Justice