Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Create Your Own custom Wordlists for FUZZING:)

Hey guys hope you all doing good. check out my previous articleContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
DeadRinger: Chinese APTs strike major telecommunications companies

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg DeadRinger: Chinese APTs strike major telecommunications companiesPost Views: 63
Reading Time: 1 Minute
On Tuesday, Cybereason Nocturnus published a new report on the cyberattackers, believed to be working for “Chinese state interests” and clustered under the name “DeadRinger.”
According to the cybersecurity firm, the “previously unidentified” campaigns are centered in Southeast Asia — and in a similar way to how attackers secured access to their victims through a centralized vendor in the cases of SolarWinds and Kaseya, this group is targeting telcos.

Cybereason believes the attacks are the work of advanced persistent threat (APT) groups linked to Chinese state-sponsorship due to overlaps in tactics and techniques with other known Chinese APTs.

Three clusters of activity have been detected with the oldest examples appearing to date back to 2017. The first group, believed to be operated by or under the Soft Cell APT, began its attacks in 2018.

The second cluster, said to be the handiwork of Naikon, surfaced and started striking telcos in the last quarter of 2020, continuing up until now. The researchers say that Naikon may be associated with the Chinese People’s Liberation Army’s (PLA) military bureau.

Cluster C has been conducting cyberattacks since 2017 and has been attributed to APT27/Emissary Panda, identified through a unique backdoor used to compromise Microsoft Exchange servers up until Q1 2021.
See Also: Hackers used never-before-seen wiper in recent attack on Iranian train system Techniques noted in the report included the exploitation of Microsoft Exchange Server vulnerabilities — long before they were made public — the deployment of the China Chopper web shell, the use of Mimikatz to harvest credentials, the creation of Cobalt Strike beacons, and backdoors to connect to a command-and-control (C2) server for data exfiltration.

Cybereason says that in each attack wave, the purpose of compromising telecommunications firms was to “facilitate cyber espionage by collecting sensitive information, compromising high-profile business assets such as the billing servers that contain Call Detail Record (CDR) data, as well as key network components such as the domain controllers, web servers and Microsoft Exchange servers.”
See Also: Offensive Security Tool: Ruler In some cases, each group overlapped and were found in the same target environments and endpoints, at the same time. However, it is not possible to say definitively whether or not they were working independently or are all under the instruction of another, central group. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker “Whether these clusters are in fact interconnected or operated independently from each other is not entirely clear at the time of writing this report,” the researchers say. “We offered several hypotheses that can account for these overlaps, hoping that as time goes by more information will be made available to us and to other researchers that will help to shed light on this conundrum.”
Source: www.zdnet.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/public-wifi-90x90.jpg NSA Warns Public Networks are Hacker Hotbeds1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/iran-thumb-90x90.jpg Hackers used never-before-seen wiper in recent attack on Iranian train system4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/PunkSpider-9[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking DeadRinger: Chinese APTs strike major telecommunications companies https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg DeadRinger: Chinese APTs strike major telecommunications companiesPost…
0x90.png Reboot of PunkSpider Tool at DEF CON Stirs Debate5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/apple-mac-security-90x90.jpg Apple Patches Actively Exploited Zero-Day in iOS, MacOS6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Windows-Abstract-90x90.jpg Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Ransomware-Key-90x90.jpg Kaseya Obtains Universal Decryptor for REvil Ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Atlassian-Jira-90x90.png Critical Jira Flaw in Atlassian Could Lead to RCE2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Copy-of-Untitled-90x90.png MacOS Being Picked Apart by $49 XLoader Data Stealer2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/printer-1-90x90.jpg 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/p1050753-e1537277708291-90x90.jpg Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post DeadRinger: Chinese APTs strike major telecommunications companies first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Sniffle : A Sniffer For Bluetooth 5 And 4.X LE

Sniffle is a sniffer for Bluetooth 5 and 4.x (LE) using TI CC1352/CC26x2 hardware. Sniffle has a number of useful features, including: Support for BT5/4.2 extended length advertisement and data packets Support for BT5 Channel Selection Algorithms #1 and #2 Support for all BT5 PHY modes (regular 1M, 2M, and coded modes) Support for sniffing […]

The post Sniffle : A Sniffer For Bluetooth 5 And 4.X LE appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
With the Polygon ecosystem becoming one of the most rapidly expanding sectors, the current dApp on their ecosystem has a rise of demands…Continue reading on Medium » (https://judy-zhu-54453.medium.com/apron-network-supports-polygon-ecosystem-with-node-service-bug-bounty-program-continues-65a2cca51301?source=rss------bug_bounty-5)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Rz-Ghidra - Deep Ghidra Decompiler And Sleigh Disassembler Integration For Rizin

https://1.bp.blogspot.com/-LkYIVYLw3G8/YP8sX9XbCNI/AAAAAAAAoyQ/D1G58r3MY_YOIE9rezOrUYMtUkETUdb0gCNcBGAsYHQ/s320/rz-ghidra.png This is an integration of the Ghidra decompiler and Sleigh Disassembler for rizin. It is solely based on the decompiler part of Ghidra, which is written entirely in C++, so Ghidra itself is not required at all and the plugin can be built self-contained. This project was presented, initially for radare2, at r2con 2019 as part of the Cutter talk: https://youtu.be/eHtMiezr7l8?t=950 InstallingAn rz-pm package is available that can easily be installed like: rz-pm -i rz-ghidra This package only installs the rizin part. To use rz-ghidra from cutter, either use a provided pre-built release starting with Cutter 1.9, which bundles rz-ghidra, or follow the build instructions below. UsageUsage: pdg # Native Ghidra decompiler plugin
| pdg # Decompile current function with the Ghidra decompiler
| pdgd # Dump the debug XML Dump
| pdgx # Dump the XML of the current decompiled function
| pdgj # Dump the current decompiled function as JSON
| pdgo # Decompile current function side by side with offsets
| pdgs # Display loaded Sleigh Languages
| pdg* # Decompiled code is returned to rizin as comment
The following config vars (for the ecommand) can be used to adjust rz-ghidra's behavior:

override auto-detection (e.g. x86:LE:32:default) ghidra.linelen: Max line length ghidra.nl.brace: Newline before opening '{' ghidra.nl.else: Newline before else ghidra.sleighhome: SLEIGHHOME ">ghidra.cmt.cpp: C++ comment style
ghidra.cmt.indent: Comment indent
ghidra.indent: Indent increment
ghidra.lang: Custom Sleigh ID to override auto-detection (e.g. x86:LE:32:default)
ghidra.linelen: Max line length
ghidra.nl.brace: Newline before opening '{'
ghidra.nl.else: Newline before else
ghidra.sleighhome: SLEIGHHOME


Here, ghidra.sleighhomemust point to a directory containing the *.sla, *.lspec, ... files for the architectures that should supported by the decompiler. This is however set up automatically when using the rz-pm package or installing as shown below. BuildingFirst, make sure the submodule contained within this repository is fetched and up to date: git submodule init
git submodule update
Then, the rizin plugin can be built and installed as follows: mkdir build && cd build
cmake -DCMAKE_INSTALL_PREFIX=~/.local ..
make
make install
Here, set the CMAKE_INSTALL_PREFIXto a location where rizin can load the plugin from. The install step is necessary for the plugin to work because it includes installing the necessary Sleigh files.

To also build the Cutter plugin, pass -DBUILD_CUTTER_PLUGIN=ON -DCUTTER_SOURCE_DIR=/path/to/cutter/sourceto cmake, for example like this: /my/path> git clone https://github.com/rizinorg/cutter
/my/path> # build Cutter, clone rz-ghidra, etc.
...
/my/path/rz-ghidra> mkdir build && cd build
/my/path/rz-ghidra/build> cmake -DBUILD_CUTTER_PLUGIN=ON -DCUTTER_SOURCE_DIR=/my/path/cutter -DCMAKE_INSTALL_PREFIX=~/.local ..
/my/path/rz-ghidra/build> make && make install
Versioning and Rizin CompatibilityRizin has a quickly evolving C API so it is necessary to be explicit about which versions of rz-ghidra are compatible with which versions of Rizin:

When using Rizin and rz-ghidra from git:

* rz-ghidra branch devfollows along Rizin branch dev.
* rz-ghidra branch stablefollows along Rizin branch stable.

Regarding releases, rz-ghidra is generally released s[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Rz-Ghidra - Deep Ghidra Decompiler And Sleigh Disassembler Integration For Rizin https://1.bp.blogspot.com/-LkYIVYLw3G8/YP8sX9XbCNI/AAAAAAAAoyQ/D1G58r3MY_YOIE9rezOrUYMtUkETUdb0gCNcBGAsYHQ/s320/rz-ghidra.png This is an integration…
imultaneously with Rizin and often uses the same version numbers (but not guaranteed, do not depend on these numbers!). Also, along with every Rizin release a tag like rz-0.1.2is created on rz-ghidra, which exactly points to an rz-ghidra release and indicates that this release is compatible with the specified Rizin version. These tags can be used by distribution maintainers to look up how to set up dependencies. Download Rz-Ghidra