Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hacker claims to steal data of 100 million T-mobile customers https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacker claims to steal data of 100 million T-mobile customersPost…
ructure.”

Binns is a resident of Turkey who sued the FBI, CIA, and Department of Justice in 2020.

The complaint alleges that Binn was tortured and harassed by the US and Turkish governments and is seeking to compel the USA to release documents regarding these activities under the Freedom of Information Act.
Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/depositphotos_40325161-stock-photo-microsoft-building-90x90.jpg Microsoft Warns: Another Unpatched PrintNightmare Zero-Day3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/crypto-hack-90x90.jpg Crypto Hack Earned Crooks $600 Million4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/msft-microsoft-logo-2-3-90x90.webp Actively Exploited Windows Zero-Day Gets a Patch5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/botnet-90x90.jpg Auth Bypass Bug Exploited, Affecting Millions of Routers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/cisco-patch-90x90.png Critical Cisco Bug in VPN Routers Allows Remote Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/delete-telegram-message-e1628177080885-90x90.jpg MacOS Flaw in Telegram Retrieves Deleted Messages1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/spam-call-90x90.jpg Black Hat: ‘I’m Calling About Your Car Warranty’, aka PII Hijinx2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Google-Chrome-Browser-Management-90x90.png Bugs in Chrome’s JavaScript engine can lead to powerful exploits. This project aims to stop them2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/chinese-flag-keyboard-internet-istock-90x90.jpg DeadRinger: Chinese APTs strike major telecommunications companies2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/public-wifi-90x90.jpg NSA Warns Public Networks are Hacker Hotbeds2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Hacker claims to steal data of 100 million T-mobile customers first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Wsh : Web Shell Generator And Command Line Interface

wsh (pronounced woosh) is a web shell generator and command line interface. This started off as just an http client since interacting with webshells is a pain. There’s a form, to send a command you have to type in an input box and press a button. I wanted something that fits into my workflow better […]

The post Wsh : Web Shell Generator And Command Line Interface appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Apron Network Supports Cosmos Ecosystem With Node Service

Cosmos, known as the “Internet of Blockchain”, is also known as version 3.0 of blockchain, which aims to solve the problems of blockchain…Continue reading on Medium »
Read more...
hacking: security in practice
Tracking PC

Suppose that you, the attacker, know ahead of time that my PC always establishes a distinct set of unencrypted TCP connections with 3rd party services at StartUp (e.g. Skype). Regardless, you have been tracking me via the fact that I always use the same external IP. However, suppose I then change local network completely and remove said static IP making it dynamically set. Now how would you find my external IP given said distinct set of connections only?

submitted by /u/ZucchiniVibes
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Grab cam shots from target's phone front camera or PC webcam just sending a link. 
What is CamPhish?
CamPhish is techniques to take cam shots of target's phone fornt camera or PC webcam. CamPhish Hosts a fake website (https://www.kitploit.com/search/label/Website) on in built PHP server and uses ngrok & serveo to generate a link which we will forward to the target, which can be used on over internet. website asks for camera permission and if the target allows it, this tool grab camshots of target's device
Features
In this tool I added two automatic webpage templates for engaged target on webpage to get more picture of cam Festival Wishing Live YouTube TV simply enter festival name or youtube's video ID
This Tool Tested On :
Kali Linux Termux MacOS Ubuntu Perrot Sec OS
Installing and requirements
This tool require PHP for webserver, SSH or serveo link. First run following command on your terminal openssh git wget ">apt-get -y install php openssh git wget

Installing (Kali Linux/Termux):
git clone https://github.com/techchipnet/CamPhish
cd CamPhish
bash camphish.sh

CamPhish is created to help in penetration testing (https://www.kitploit.com/search/label/Penetration%20Testing) and it's not responsible for any misuse or illegal purposes. CamPhish is inspired by https://github.com/thelinuxchoice/ Big thanks to @thelinuxchoice

Download CamPhish (https://github.com/techchipnet/CamPhish)

___________________________
@hacking_Attack
@Hacking_Video
CamPhish - Grab Cam Shots From Target'S Phone Front Camera Or PC Webcam Just Sending A Link.

Grab cam shots from target's phone front camera or PC webcam just sending a link. What is CamPhish? CamPhish is techniques to take cam shots of target's phone fornt camera or PC webcam. CamPhish Hosts a fake website on in built PHP server and uses ngrok & serveo to generate a link which we will forward to the target, which can be used on over internet. website asks for camera permission and if the target allows it, this tool grab camshots of target's deviceFeatures In this tool I added two automatic webpage templates for engaged target on webpage to get more picture of cam Festival Wishing Live YouTube TV simply enter festival name or youtube's video ID This Tool Tested On : Kali Linux Termux MacOS Ubuntu Perrot Sec OS Installing and requirements This tool require PHP for webserver, SSH or serveo link. First run following command on your terminal openssh git wget ">apt-get -y install php openssh git wget Installing (Kali Linux/Termux): git clone https://github.com/techchipnet/CamPhishcd CamPhishbash camphish.sh CamPhish is created to help in penetration testing and it's not responsible for any misuse or illegal purposes. CamPhish is inspired by https://github.com/thelinuxchoice/ Big thanks to @thelinuxchoice Download CamPhish
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
CamPhish - Grab Cam Shots From Target'S Phone Front Camera Or PC Webcam Just Sending A Link.

http://1.bp.blogspot.com/-TZZrEvg4jAk/YRYFvF9wgsI/AAAAAAAAp5Y/7S1JERdlb0o2cyXSbhftrz3BViMjm8x-gCK4BGAYYCw/w640-h364/CamPhish_1-704443.jpeg

Grab cam shots from target's phone front camera or PC webcam just sending a link.

What is CamPhish?

CamPhish is techniques to take cam shots of target's phone fornt camera or PC webcam. CamPhish Hosts a fake website on in built PHP server and uses ngrok & serveo to generate a link which we will forward to the target, which can be used on over internet. website asks for camera permission and if the target allows it, this tool grab camshots of target's device
Features

In this tool I added two automatic webpage templates for engaged target on webpage to get more picture of cam

* Festival Wishing
* Live YouTube TV

simply enter festival name or youtube's video ID

This Tool Tested On :

* Kali Linux
* Termux
* MacOS
* Ubuntu
* Perrot Sec OS

Installing and requirements

This tool require PHP for webserver, SSH or serveo link. First run following command on your terminal

openssh git wget ">apt-get -y install php openssh git wget


Installing (Kali Linux/Termux):

git clone https://github.com/techchipnet/CamPhish
cd CamPhish
bash camphish.sh

CamPhish is created to help in penetration testing and it's not responsible for any misuse or illegal purposes.

CamPhish is inspired by https://github.com/thelinuxchoice/ Big thanks to @thelinuxchoice
Download CamPhish

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
CentOS Web Panel 0.9.8.1081 Cross Site Scripting

https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
CentOS Web Panel version 0.9.8.1081 suffers from a persistent cross site scripting vulnerability.

MD5 | ff51ac25f304d0ad4ba7b11aefc45408

Download
# Exploit Title: CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS)
# Date: 13/08/2021
# Exploit Author: Dinesh Mohanty
# Vendor Homepage: http://centos-webpanel.com
# Software Link: http://centos-webpanel.com
# Version: v0.9.8.1081
# Tested on: CentOS 7 and 8

# Description:
Multiple Stored Cross Site Scripting (Stored XSS) Vulnerability is found in the Short Name, Ip Origin, Key Code, Format Request and Owner fields within the admin api page of module of CentOS/ Control WebPanel when user tries to create a new API. This is because the application does not properly sanitize users input.
# Steps to Reproduce:
1. Login into the CentOS Web Panel using admin credential.
2. From Navigation Click on "API Manager" -> then Click on "Allow New API Access"
3. In the above given fields give payload as: x and provide other details and click on "Create"
4. Now one can see that the XSS Payload executed.

#Vendor Notification
18th Aug 2021 - Vendor has been notified
18th Aug 2021 - Vendor confirmed the issue and fixed for next version

Source:packetstormsecurity.com