Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Oopsie has been Pwned!

https://cdn-images-1.medium.com/max/1280/1*ctPuffVS2xQjEw9oKdYRZA.jpeg
Hack The Box Oopsie walkthrough. This box utilises directory brute forcing, parameter brute forcing and path privilege escalation

Continue reading on Medium »
hacking: security in practice
(probably) easy job

I play Roblox and I want this username but what looks like an old throwaway has it. I was wondering if someone could get into it and delete it. they haven't been online for years. I'm sorry I don't have money to pay. I can't do much about that since I don't have a method of making money. DM if interested

submitted by /u/Derpyfish5678
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Jenkins project’s Confluence server hacked to mine Monero

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Jenkins project’s Confluence server hacked to mine MoneroPost Views: 38
Reading Time: 1 Minute
Hackers exploiting the recently disclosed Atlassian Confluence remote code execution vulnerability breached an internal server from the Jenkins project.
While the attack is concerning because Jenkins is a popular open-source server for automating parts of software development, there is no reason that the project releases, plugins, or code have been impacted. Admins are being cautiousAs BleepingComputer reported last week, after the proof-of-concept exploit code for CVE-2021-26084 became public, threat actors started to scan for vulnerable Atlassian Confluence instances to install cryptocurrency miners.

While many attackers used the exploit to install the open-source, cross-platform XMRig Monero cryptocurrency miner, they could also leverage the vulnerability for more damaging attacks.

Last week, administrators of the Jenkins project discovered that one of their deprecated Confluence server fell victim to one of these attacks.
See Also: Complete Offensive Security and Ethical Hacking Course “Thus far in our investigation, we have learned that the Confluence CVE-2021-26084 exploit was used to install what we believe was a Monero miner in the container running the service. From there an attacker would not be able to access much of our other infrastructure” – Mark Waite, Jenkins Documentation Officer
Although there is no evidence suggesting that the attacker stole developer credentials, Jenkins project managers are being careful and have reset passwords for all accounts in the integrated identity system that also included the deprecated Confluence service.

The admins also said that they “are taking actions to prevent releases at this time until we re-establish a chain of trust with our developer community.” The affected Confluence service is no longer active and privileged credentials have been rotated.

CVE-2021-26084 is a remote code execution vulnerability in Atlassian Confluence that can be exploited without authentication. News about it emerged on August 25, when the company published a security advisory.
See Also: Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
About a week later, technical details became publicly available along with proof-of-concept exploit code. Threat actors started leveraging so heavily that the U.S. Cyber Command (USCYBERCOM) issued a warning about mass exploitation.
https://www.bleepstatic.com/images/news/u/1100723/2021/USCyberComConfluence.jpg
<figcaptionsource: USCYBERCOM
See Also: Offensive Security Tool: Pegasus Spyware – Decompiled See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerSource: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/unnamed-e1630998483665-90x90.jpg Critical Auth Bypass Bug Affect NETGEAR Smart Switches1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/loyalty-card-90x90.jpg Brute-Force Attacks Target Inboxes for Gift Card Data2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Braktooth-New-Bluetooth-gaps-threaten-countless-devices-1024x576-1-90x90.jpg Bluetooth Bugs Open Billions of Devices to DoS, Code Execution5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/wordpress_plugin_vuln-90x90.jpg Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites6 days ago
* https://www.black[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Jenkins project’s Confluence server hacked to mine Monero https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Jenkins project’s Confluence server hacked to mine MoneroPost Views: 38 Reading…
hatethicalhacking.com/wp-content/uploads/2021/09/ransomware-cpu-90x90.jpg LockFile Ransomware Uses Never-Before Seen Encryption to Avoid Detection1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Windows-Abstract-90x90.jpg Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/F5-Big-IP-e1619725870974-90x90.jpg F5 Bug Could Lead to Complete System Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/steel-series-e1629915533369-90x90.jpg Win10 Admin Rights Tossed Off by Yet Another Plug-In2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/white-pegasus-e1626804896117-90x90.jpg Pegasus Spyware Uses iPhone Zero-Click iMessage Zero-Day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/microsoft-exchange-90x90.jpg ProxyShell Attacks Pummel Unpatched Exchange Servers2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Jenkins project’s Confluence server hacked to mine Monero first appeared on Black Hat Ethical Hacking.
Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium » (https://peteranh910.medium.com/ch%C6%B0%C6%A1ng-tr%C3%ACnh-ti%E1%BB%81n-th%C6%B0%E1%BB%9Fng-l%E1%BB%97i-openleverage-30a50b8fc340?source=rss------bug_bounty-5)
hacking: security in practice
Code execution in restricted VDI environments

Normally, execution of cmd.exe and powershell.exe is prohibited in restricted VDI environments. However, I've seen cases where this can be circumvented by executing a script directly (.bat, .vbs, .ps) and redirect it to another output.

What is the name for this technique? Is it local code execution? What is the risk rating for this use case? High? Medium? Low?

submitted by /u/w0lfcat
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Chương trình tiền thưởng lỗi OpenLeverage

Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium »
Read more...