Following the biggest hack in DeFi history, Poly Network is joining Immunefi with a bug bounty of $100,000 for critical vulnerabilities…Continue reading on Immunefi » (https://medium.com/immunefi/poly-network-joins-immunefi-with-100-000-bug-bounty-after-hack-d349e1192853?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Attack Insecure Rsync Service
https://cdn-images-1.medium.com/max/1950/1*F0uyH_P-DND-nA3fI7iGXw.jpeg
Rsync Enumeration and Exploitation
Continue reading on R3d Buck3T »
Attack Insecure Rsync Service
https://cdn-images-1.medium.com/max/1950/1*F0uyH_P-DND-nA3fI7iGXw.jpeg
Rsync Enumeration and Exploitation
Continue reading on R3d Buck3T »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: The find command Walkthrough by Razrexe
https://cdn-images-1.medium.com/max/2600/1*HL5nlbu3XIEMhw2a5QuMOg.jpeg
Some of the fundamental knowledge that a security professional must have is using properly the Linux ‘find’ command.
Continue reading on Medium »
TryHackMe: The find command Walkthrough by Razrexe
https://cdn-images-1.medium.com/max/2600/1*HL5nlbu3XIEMhw2a5QuMOg.jpeg
Some of the fundamental knowledge that a security professional must have is using properly the Linux ‘find’ command.
Continue reading on Medium »
Deep Web
Tor browser for IOS
I just changed from android to iOS and I can’t seem to find a good app to navigate DW on it, do any of you know an app or anything that can work? 🥺
submitted by /u/SushiBxwl
[link] [comments]
Tor browser for IOS
I just changed from android to iOS and I can’t seem to find a good app to navigate DW on it, do any of you know an app or anything that can work? 🥺
submitted by /u/SushiBxwl
[link] [comments]
reddit
Tor browser for IOS
I just changed from android to iOS and I can’t seem to find a good app to navigate DW on it, do any of you know an app or anything that can work? 🥺
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is this safe?
I don't know how to scan .exe files, the github is https://github.com/Itroublve/Token-Browser-Password-Stealer-Creator
It's for grabbing stuff, just please check if it connects to any suspicious connections.
submitted by /u/FireTrail846
[link] [comments]
Is this safe?
I don't know how to scan .exe files, the github is https://github.com/Itroublve/Token-Browser-Password-Stealer-Creator
It's for grabbing stuff, just please check if it connects to any suspicious connections.
submitted by /u/FireTrail846
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
CompTIA Certification Bundle
CompTIA Training is running a big deal that certainly many people in this community will benefit from it.
https://comptia.training/
That's it, no hacking tutorials or anything crazy just training resources.
Happy Tuesday community
submitted by /u/Education_growth_123
[link] [comments]
CompTIA Certification Bundle
CompTIA Training is running a big deal that certainly many people in this community will benefit from it.
https://comptia.training/
That's it, no hacking tutorials or anything crazy just training resources.
Happy Tuesday community
submitted by /u/Education_growth_123
[link] [comments]
hacking: security in practice
Any key logging or website infiltration or is here looking for someone job
I need a job done and I need a pro. Can do hourly rate or full payment
submitted by /u/Preence_kay
[link] [comments]
Any key logging or website infiltration or is here looking for someone job
I need a job done and I need a pro. Can do hourly rate or full payment
submitted by /u/Preence_kay
[link] [comments]
reddit
Any key logging or website infiltration or is here looking for...
I need a job done and I need a pro. Can do hourly rate or full payment
hacking: security in practice
How to get a job as a cyber security consultant?
Hi! I've been learning and studying about cyber security for a while. Right now I work as a programmer, and I wouldn't mind to have a work as a cyber security consultant in a red team. How important are certificates in this area? I know it's important but.. are certificates indispensable or you can get a job if you are good enough?
submitted by /u/chuse1995
[link] [comments]
How to get a job as a cyber security consultant?
Hi! I've been learning and studying about cyber security for a while. Right now I work as a programmer, and I wouldn't mind to have a work as a cyber security consultant in a red team. How important are certificates in this area? I know it's important but.. are certificates indispensable or you can get a job if you are good enough?
submitted by /u/chuse1995
[link] [comments]
reddit
How to get a job as a cyber security consultant?
Hi! I've been learning and studying about cyber security for a while. Right now I work as a programmer, and I wouldn't mind to have a work as a...
Poly Network Joins Immunefi With $100,000 Bug Bounty After Hack
Following the biggest hack in DeFi history, Poly Network is joining Immunefi with a bug bounty of $100,000 for critical vulnerabilities…Continue reading on Immunefi »
Read more...
Following the biggest hack in DeFi history, Poly Network is joining Immunefi with a bug bounty of $100,000 for critical vulnerabilities…Continue reading on Immunefi »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
RACTF 2021 — Writeup
https://cdn-images-1.medium.com/max/1416/1*WF2ZVJqHkexI4OHVB1JAJQ.png
Writeup for RACTF 2021 by Nicholas and Munir.
Continue reading on Medium »
RACTF 2021 — Writeup
https://cdn-images-1.medium.com/max/1416/1*WF2ZVJqHkexI4OHVB1JAJQ.png
Writeup for RACTF 2021 by Nicholas and Munir.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
YouTube SEO: How to Rank YouTube Videos in 2021
https://cdn-images-1.medium.com/max/600/0*vwBbgW-eC64KkloP
Before we get into today’s video SEO tutorial, a quick backstory: To Rank YouTube Videos on the Top, the most important things that…
Continue reading on Medium »
YouTube SEO: How to Rank YouTube Videos in 2021
https://cdn-images-1.medium.com/max/600/0*vwBbgW-eC64KkloP
Before we get into today’s video SEO tutorial, a quick backstory: To Rank YouTube Videos on the Top, the most important things that…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam WalletsPost Views: 177
Reading Time: 1 Minute
Valve plugs an API bug found in its Steam platform that that abused the Smart2Pay system to add unlimited funds to gamer digital wallets.
A security researcher helped Valve, the makers of the gaming platform Steam, plug an easy-to-exploit hole that allowed users to add unlimited funds to their digital wallet. Simply by changing the account’s email address, the exploit allowed anyone to artificially boost their digital billfold to anything they wanted.
Steam Wallet funds are exclusive to the Steam platform and are used to purchase in-game merchandise, subscriptions and Steam-related content. Valve restricts Steam credits (or money) from being transferred outside its network for purchase or trading. However, there are several unsanctioned ways to convert wallet funds into actual dollars.
Working for the HackerOne bug-bounty program, security researcher DrBrix, reported the bug last Monday. By Wednesday, Valve plugged the hole and paid DrBrix $7,500 for identifying the bug.
See Also: Hacker claims to steal data of 100 million T-mobile customers The Hack: Turning $1 into $100 or $1MThe bug, which has since been patched, was exploited by abusing Valve’s own application programming interface (API) used to communicate with the third-party web payment firm Smart2Pay, owned by Nuvei.
According to DrBrix, the hack allowed an attacker to intercept the POST request sent from Valve to Smart2Pay. This was done via modifying the Steam user’s email address used by Smart2Pay as it passed through the Valve API.
“Firstly you will have to change yours steam account email to something like (I will explain why in next steps, amount100 is the important part): brixamount100abc@█████,” the researcher wrote.
This allows the attacker to manipulate communications between Valve and Smart2Pay, circumventing the cryptographic hash used to protect transaction data.
“We can’t change parameters as there is Hash field with signature, however signature is generated like that hash (ALL_FIELDS_NAMES_VALUES_CONTACTED),” DrBrix wrote. “So with our special email we can move parameters in a way that will change amount for us.”
See Also: Offensive Security Tool: Warcannon Where the Valve parameters might be,
“hash(MerchantID1102MerchantTransactionID█████Amount2000…..)” the attacker can turn $1 into $100 simply by changing the format of the email request.
“So with our special email we can move parameters in a way that will change amount for us. For example, we can change original Amount=2000 to Amount2=000 and after contacting it still will be Amount2000. Then we can change email from CustomerEmail=brixamount100abc%40████ to CustomerEmail=brix&amount=100&ab=c%40█████████ by this we are adding new field amount with our value,” DrBrix wrote. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerValve first rated the bug as of moderate importance. However, after investigating, it escalated the bug to critical in nature, scoring it “9-10”, with the highest possible rating 10.
Valve did not return a Threatpost press request for comment.
“We have changed the severity assessment to Critical, reflecting the potential cost to the business, and applied a bounty accordingly,” wrote Valve in a HackerOne thread thanking DrBrix for the tip.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/[...]
Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam WalletsPost Views: 177
Reading Time: 1 Minute
Valve plugs an API bug found in its Steam platform that that abused the Smart2Pay system to add unlimited funds to gamer digital wallets.
A security researcher helped Valve, the makers of the gaming platform Steam, plug an easy-to-exploit hole that allowed users to add unlimited funds to their digital wallet. Simply by changing the account’s email address, the exploit allowed anyone to artificially boost their digital billfold to anything they wanted.
Steam Wallet funds are exclusive to the Steam platform and are used to purchase in-game merchandise, subscriptions and Steam-related content. Valve restricts Steam credits (or money) from being transferred outside its network for purchase or trading. However, there are several unsanctioned ways to convert wallet funds into actual dollars.
Working for the HackerOne bug-bounty program, security researcher DrBrix, reported the bug last Monday. By Wednesday, Valve plugged the hole and paid DrBrix $7,500 for identifying the bug.
See Also: Hacker claims to steal data of 100 million T-mobile customers The Hack: Turning $1 into $100 or $1MThe bug, which has since been patched, was exploited by abusing Valve’s own application programming interface (API) used to communicate with the third-party web payment firm Smart2Pay, owned by Nuvei.
According to DrBrix, the hack allowed an attacker to intercept the POST request sent from Valve to Smart2Pay. This was done via modifying the Steam user’s email address used by Smart2Pay as it passed through the Valve API.
“Firstly you will have to change yours steam account email to something like (I will explain why in next steps, amount100 is the important part): brixamount100abc@█████,” the researcher wrote.
This allows the attacker to manipulate communications between Valve and Smart2Pay, circumventing the cryptographic hash used to protect transaction data.
“We can’t change parameters as there is Hash field with signature, however signature is generated like that hash (ALL_FIELDS_NAMES_VALUES_CONTACTED),” DrBrix wrote. “So with our special email we can move parameters in a way that will change amount for us.”
See Also: Offensive Security Tool: Warcannon Where the Valve parameters might be,
“hash(MerchantID1102MerchantTransactionID█████Amount2000…..)” the attacker can turn $1 into $100 simply by changing the format of the email request.
“So with our special email we can move parameters in a way that will change amount for us. For example, we can change original Amount=2000 to Amount2=000 and after contacting it still will be Amount2000. Then we can change email from CustomerEmail=brixamount100abc%40████ to CustomerEmail=brix&amount=100&ab=c%40█████████ by this we are adding new field amount with our value,” DrBrix wrote. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerValve first rated the bug as of moderate importance. However, after investigating, it escalated the bug to critical in nature, scoring it “9-10”, with the highest possible rating 10.
Valve did not return a Threatpost press request for comment.
“We have changed the severity assessment to Critical, reflecting the potential cost to the business, and applied a bounty accordingly,” wrote Valve in a HackerOne thread thanking DrBrix for the tip.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/[...]