How I found my first Subdomain Takeover vulnerability
https://monish-basaniwal.medium.com/how-i-found-my-first-subdomain-takeover-vulnerability-b7d5c17b61fd?source=rss------bug_bounty-5
https://monish-basaniwal.medium.com/how-i-found-my-first-subdomain-takeover-vulnerability-b7d5c17b61fd?source=rss------bug_bounty-5
About the vulnerabilityContinue reading on Medium » (https://monish-basaniwal.medium.com/how-i-found-my-first-subdomain-takeover-vulnerability-b7d5c17b61fd?source=rss------bug_bounty-5)
How I found my first Subdomain Takeover vulnerability
About the vulnerabilityContinue reading on Medium »
Read more...
About the vulnerabilityContinue reading on Medium »
Read more...
Proxyshell POC - what need inatall?
https://www.reddit.com/r/redteamsec/comments/p7x35j/proxyshell_poc_what_need_inatall/
<!-- SC_OFF -->To create local POC Have some docker to this vulnerablilty? If not, how I install it on my local machine? <!-- SC_ON --> submitted by /u/henadar (https://www.reddit.com/user/henadar)
[link] (https://www.reddit.com/r/redteamsec/comments/p7x35j/proxyshell_poc_what_need_inatall/) [comments] (https://www.reddit.com/r/redteamsec/comments/p7x35j/proxyshell_poc_what_need_inatall/)
https://www.reddit.com/r/redteamsec/comments/p7x35j/proxyshell_poc_what_need_inatall/
<!-- SC_OFF -->To create local POC Have some docker to this vulnerablilty? If not, how I install it on my local machine? <!-- SC_ON --> submitted by /u/henadar (https://www.reddit.com/user/henadar)
[link] (https://www.reddit.com/r/redteamsec/comments/p7x35j/proxyshell_poc_what_need_inatall/) [comments] (https://www.reddit.com/r/redteamsec/comments/p7x35j/proxyshell_poc_what_need_inatall/)
hacking: security in practice
Can anyone verify if this .pdf has malicious code in it?
So I was recently a target of a scam for a fake job - luckily I realized it before sending any money.
That said, they sent me over a fake work contract .pdf, which I downloaded and signed.
Is there any way to see if it's harmless? I'm not sure if I'm allowed to post it here or not.
Any help would be really appreciated!
submitted by /u/8-bit-hero
[link] [comments]
Can anyone verify if this .pdf has malicious code in it?
So I was recently a target of a scam for a fake job - luckily I realized it before sending any money.
That said, they sent me over a fake work contract .pdf, which I downloaded and signed.
Is there any way to see if it's harmless? I'm not sure if I'm allowed to post it here or not.
Any help would be really appreciated!
submitted by /u/8-bit-hero
[link] [comments]
reddit
Can anyone verify if this .pdf has malicious code in it?
So I was recently a target of a scam for a fake job - luckily I realized it before sending any money. That said, they sent me over a fake work...
Cloud Certifications for experienced Pentesters ????
https://www.reddit.com/r/Pentesting/comments/p7xd43/cloud_certifications_for_experienced_pentesters/
<!-- SC_OFF -->Hi there, So I have been pentesting for quite sometime now. I am OSCP and OSWE certified but often times we have requirement from clients to perform cloud assessment as well. Do any other pentester face the same issues??So i was thinking i should go for some clouds certifications next.....Like AWS associate and then AWS security specialist...... Because I assume that cloud knowledge would certainly benefit pentester as well Any thoughts???? <!-- SC_ON --> submitted by /u/babayaga3904 (https://www.reddit.com/user/babayaga3904)
[link] (https://www.reddit.com/r/Pentesting/comments/p7xd43/cloud_certifications_for_experienced_pentesters/) [comments] (https://www.reddit.com/r/Pentesting/comments/p7xd43/cloud_certifications_for_experienced_pentesters/)
https://www.reddit.com/r/Pentesting/comments/p7xd43/cloud_certifications_for_experienced_pentesters/
<!-- SC_OFF -->Hi there, So I have been pentesting for quite sometime now. I am OSCP and OSWE certified but often times we have requirement from clients to perform cloud assessment as well. Do any other pentester face the same issues??So i was thinking i should go for some clouds certifications next.....Like AWS associate and then AWS security specialist...... Because I assume that cloud knowledge would certainly benefit pentester as well Any thoughts???? <!-- SC_ON --> submitted by /u/babayaga3904 (https://www.reddit.com/user/babayaga3904)
[link] (https://www.reddit.com/r/Pentesting/comments/p7xd43/cloud_certifications_for_experienced_pentesters/) [comments] (https://www.reddit.com/r/Pentesting/comments/p7xd43/cloud_certifications_for_experienced_pentesters/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Start Bug Bounty Hunting
https://cdn-images-1.medium.com/max/1200/1*OWnD-GZ4PShEkhlYiMcolw.jpeg
Short & Basic Intro to Bug Bounty World
Continue reading on Medium »
How To Start Bug Bounty Hunting
https://cdn-images-1.medium.com/max/1200/1*OWnD-GZ4PShEkhlYiMcolw.jpeg
Short & Basic Intro to Bug Bounty World
Continue reading on Medium »
Deep Web
A question about the history of the darknet
Hello, Reddit! I became interested in the darknet, but not in terms of visits to sites with prohibited content, but to learn and study the dark web. At the moment, I would like to know the history of the darknet, but not a superficial one, but with all the dates that can be found (not only the creation of Tor by the FBI services, but also just markets, the capture of criminals, etc.). Do you have such links and sources in mind? Maybe some literature related to the darknet?
submitted by /u/gelmoshka
[link] [comments]
A question about the history of the darknet
Hello, Reddit! I became interested in the darknet, but not in terms of visits to sites with prohibited content, but to learn and study the dark web. At the moment, I would like to know the history of the darknet, but not a superficial one, but with all the dates that can be found (not only the creation of Tor by the FBI services, but also just markets, the capture of criminals, etc.). Do you have such links and sources in mind? Maybe some literature related to the darknet?
submitted by /u/gelmoshka
[link] [comments]
reddit
A question about the history of the darknet
Hello, Reddit! I became interested in the darknet, but not in terms of visits to sites with prohibited content, but to learn and study the dark...
Deep Web
Having issues with whm.
Is my tor browser not functioning properly? Everytime I goto send a support ticket I get a blank white html template. I'll be posting a video for better reference, but I took a 2 month break and suddenly the entire marketplace seems to be falling apart. Is it compromised? Why are the keys not decrypting? Am I missing something super simple?
submitted by /u/DissapointedCanadian
[link] [comments]
Having issues with whm.
Is my tor browser not functioning properly? Everytime I goto send a support ticket I get a blank white html template. I'll be posting a video for better reference, but I took a 2 month break and suddenly the entire marketplace seems to be falling apart. Is it compromised? Why are the keys not decrypting? Am I missing something super simple?
submitted by /u/DissapointedCanadian
[link] [comments]
reddit
Having issues with whm.
Is my tor browser not functioning properly? Everytime I goto send a support ticket I get a blank white html template. I'll be posting a video for...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical Cisco Bug in Small Business Routers to Remain Unpatched
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Cisco Bug in Small Business Routers to Remain UnpatchedPost Views: 58
Reading Time: 1 Minute
A critical security vulnerability in Cisco Small Business Routers (RV110W, RV130, RV130W and RV215W models) allows remote code execution (RCE) and denial of service (DoS).
The networking giant said that no patch or workaround will be coming for the bug, since the routers reached end-of-life back in 2019.
The bug (CVE-2021-34730) is one of six addressed by Cisco this week; it also issued an advisory for the critical BlackBerry QNX-2021-001 vulnerability unveiled earlier this week (CVE-2021-22156), which affects multiple vendors, well beyond Cisco. Patch Denied: Critical RCE for EoL GearThe critical router issue, which carries a base CVSS score of 9.8 out of 10, affects the hardware’s Universal Plug-and-Play (UPnP) service, Cisco said. It could allow an unauthenticated attacker to achieve RCE or cause an affected device to restart unexpectedly.
“This vulnerability is due to improper validation of incoming UPnP traffic,” according to the advisory. “An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition.”
The issue affects a range of Cisco Wireless-N and Wireless-AC VPN routers, which reached end-of-life in September of 2019. Cisco stopped issuing bug fixes on Dec. 1 of last year. Affected companies should look to update their hardware to avoid compromise.
See Also: Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
The other critical flaw addressed in the updates has to do with the BlackBerry QNX-2021-001 bug disclosed this week, which allows threat actors to take over or launch DoS attacks on devices and critical infrastructure. Essentially, the known group of BadAlloc bugs tied to BlackBerry’s embedded QNX operating system (OS) now affects older devices.
Cisco’s advisory simply states, “Cisco is investigating its product line to determine which products and services may be affected by this vulnerability.” So far, no products have been listed. Medium-Severity Security Bugs in Cisco GearThe remaining five patches are all rated medium in severity, and affect products from across Cisco’s portfolio. These bugs are:
* CVE-2021-34749: Server Name Identification (SNI) Data-Exfiltration Vulnerability (Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), Snort Detection Engine)
* CVE-2021-1561: Spam Quarantine Unauthorized-Access Vulnerability (Cisco Secure Email and Web Manager)
* CVE-2021-34734: Double-Free Denial-of-Service Vulnerability (Cisco Video Surveillance 7000 Series IP Cameras Link Layer Discovery Protocol)
* CVE-2021-34715: Image-Verification Vulnerability (Cisco Expressway Series and TelePresence Video Communication Server)
* CVE-2021-34716: RCE Vulnerability (Cisco Expressway Series and TelePresence Video Communication Server)
The first bug could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device to execute a command-and-control attack on a compromised host and perform and exfiltrate data from a compromised host. The advisory is an interim one, and Cisco said it was still investigating which product versions are affected.
See Also: Offensive Security Tool: Warcannon
“This vulnerability is due to inadequate filtering of the SSL [...]
Critical Cisco Bug in Small Business Routers to Remain Unpatched
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Cisco Bug in Small Business Routers to Remain UnpatchedPost Views: 58
Reading Time: 1 Minute
A critical security vulnerability in Cisco Small Business Routers (RV110W, RV130, RV130W and RV215W models) allows remote code execution (RCE) and denial of service (DoS).
The networking giant said that no patch or workaround will be coming for the bug, since the routers reached end-of-life back in 2019.
The bug (CVE-2021-34730) is one of six addressed by Cisco this week; it also issued an advisory for the critical BlackBerry QNX-2021-001 vulnerability unveiled earlier this week (CVE-2021-22156), which affects multiple vendors, well beyond Cisco. Patch Denied: Critical RCE for EoL GearThe critical router issue, which carries a base CVSS score of 9.8 out of 10, affects the hardware’s Universal Plug-and-Play (UPnP) service, Cisco said. It could allow an unauthenticated attacker to achieve RCE or cause an affected device to restart unexpectedly.
“This vulnerability is due to improper validation of incoming UPnP traffic,” according to the advisory. “An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition.”
The issue affects a range of Cisco Wireless-N and Wireless-AC VPN routers, which reached end-of-life in September of 2019. Cisco stopped issuing bug fixes on Dec. 1 of last year. Affected companies should look to update their hardware to avoid compromise.
See Also: Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
The other critical flaw addressed in the updates has to do with the BlackBerry QNX-2021-001 bug disclosed this week, which allows threat actors to take over or launch DoS attacks on devices and critical infrastructure. Essentially, the known group of BadAlloc bugs tied to BlackBerry’s embedded QNX operating system (OS) now affects older devices.
Cisco’s advisory simply states, “Cisco is investigating its product line to determine which products and services may be affected by this vulnerability.” So far, no products have been listed. Medium-Severity Security Bugs in Cisco GearThe remaining five patches are all rated medium in severity, and affect products from across Cisco’s portfolio. These bugs are:
* CVE-2021-34749: Server Name Identification (SNI) Data-Exfiltration Vulnerability (Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), Snort Detection Engine)
* CVE-2021-1561: Spam Quarantine Unauthorized-Access Vulnerability (Cisco Secure Email and Web Manager)
* CVE-2021-34734: Double-Free Denial-of-Service Vulnerability (Cisco Video Surveillance 7000 Series IP Cameras Link Layer Discovery Protocol)
* CVE-2021-34715: Image-Verification Vulnerability (Cisco Expressway Series and TelePresence Video Communication Server)
* CVE-2021-34716: RCE Vulnerability (Cisco Expressway Series and TelePresence Video Communication Server)
The first bug could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device to execute a command-and-control attack on a compromised host and perform and exfiltrate data from a compromised host. The advisory is an interim one, and Cisco said it was still investigating which product versions are affected.
See Also: Offensive Security Tool: Warcannon
“This vulnerability is due to inadequate filtering of the SSL [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical Cisco Bug in Small Business Routers to Remain Unpatched https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Critical Cisco Bug in Small Business Routers to Remain UnpatchedPost…
handshake,” according to the advisory. “An attacker could exploit this vulnerability by using data from the SSL client hello packet to communicate with an external server.”
The spam-quarantine-related vulnerability affects Cisco Secure Email and Web Manager releases earlier than Release 14.1. It could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user, so that malicious messages could get through or attackers could read messages.
“This vulnerability exists because access to the spam quarantine feature is not properly restricted,” according to the advisory. “An attacker could exploit this vulnerability by sending malicious requests to an affected system.”
The third bug exists in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras with firmware release 2.12.4. Exploitation could allow an unauthenticated, adjacent attacker to cause a DoS condition.
“This vulnerability is due to improper management of memory resources, referred to as a double free,” according to Cisco. “An attacker could exploit this vulnerability by sending crafted LLDP packets to an affected device.” See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerThe last two vulnerabilities exist in the Expressway and TelePresence products and can be exploited by authenticated, remote attackers to execute code.
The first of these allows RCE with internal user privileges on the underlying operating system; it affects users running a release earlier than the first fixed release (the bug was introduced when support for validation of SHA512 checksums was introduced in Release X8.8).
The second allows RCE on the underlying operating system as the root user. It affects releases earlier than the first fixed release if users are running Release X8.6 or later.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Bug-Digital-90x90.jpg Unpatched Fortinet Bug Allows Firewall Takeovers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-1-90x90.png Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Steam-logo-90x90.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/tmobile-header-90x90.webp Hacker claims to steal data of 100 million T-mobile customers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/depositphotos_40325161-stock-photo-microsoft-building-90x90.jpg Microsoft Warns: Another Unpatched PrintNightmare Zero-Day7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/crypto-hack-90x90.jpg Crypto Hack Earned Crooks $600 Million1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/msft-microsoft-logo-2-3-90x90.webp Actively Exploited Windows Zero-Day Gets a Patch1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/botnet-90x90.jpg Auth Bypass Bug Exploited, Affecting Millions of Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/cisco-patch-90x90.png Critical Cisco Bug in VPN Routers Allows Remote Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/delete-telegram-message-e1628177080885-90x90.jpg MacOS Flaw in Telegram Retrieves Deleted Messages2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Critical Cisco Bug in Small Business Routers to Remain Unpatched first appeared on Black Hat Ethical Hacking.
The spam-quarantine-related vulnerability affects Cisco Secure Email and Web Manager releases earlier than Release 14.1. It could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user, so that malicious messages could get through or attackers could read messages.
“This vulnerability exists because access to the spam quarantine feature is not properly restricted,” according to the advisory. “An attacker could exploit this vulnerability by sending malicious requests to an affected system.”
The third bug exists in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras with firmware release 2.12.4. Exploitation could allow an unauthenticated, adjacent attacker to cause a DoS condition.
“This vulnerability is due to improper management of memory resources, referred to as a double free,” according to Cisco. “An attacker could exploit this vulnerability by sending crafted LLDP packets to an affected device.” See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerThe last two vulnerabilities exist in the Expressway and TelePresence products and can be exploited by authenticated, remote attackers to execute code.
The first of these allows RCE with internal user privileges on the underlying operating system; it affects users running a release earlier than the first fixed release (the bug was introduced when support for validation of SHA512 checksums was introduced in Release X8.8).
The second allows RCE on the underlying operating system as the root user. It affects releases earlier than the first fixed release if users are running Release X8.6 or later.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Bug-Digital-90x90.jpg Unpatched Fortinet Bug Allows Firewall Takeovers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-1-90x90.png Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Steam-logo-90x90.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/tmobile-header-90x90.webp Hacker claims to steal data of 100 million T-mobile customers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/depositphotos_40325161-stock-photo-microsoft-building-90x90.jpg Microsoft Warns: Another Unpatched PrintNightmare Zero-Day7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/crypto-hack-90x90.jpg Crypto Hack Earned Crooks $600 Million1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/msft-microsoft-logo-2-3-90x90.webp Actively Exploited Windows Zero-Day Gets a Patch1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/botnet-90x90.jpg Auth Bypass Bug Exploited, Affecting Millions of Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/cisco-patch-90x90.png Critical Cisco Bug in VPN Routers Allows Remote Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/delete-telegram-message-e1628177080885-90x90.jpg MacOS Flaw in Telegram Retrieves Deleted Messages2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Critical Cisco Bug in Small Business Routers to Remain Unpatched first appeared on Black Hat Ethical Hacking.
How To Start Bug Bounty Hunting
https://therceman.medium.com/how-to-start-bug-bounty-hunting-94b1ff3dda27?source=rss------bug_bounty-5
https://therceman.medium.com/how-to-start-bug-bounty-hunting-94b1ff3dda27?source=rss------bug_bounty-5