Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Oopsie has been Pwned!
https://cdn-images-1.medium.com/max/1280/1*ctPuffVS2xQjEw9oKdYRZA.jpeg
Hack The Box Oopsie walkthrough. This box utilises directory brute forcing, parameter brute forcing and path privilege escalation
Continue reading on Medium »
Oopsie has been Pwned!
https://cdn-images-1.medium.com/max/1280/1*ctPuffVS2xQjEw9oKdYRZA.jpeg
Hack The Box Oopsie walkthrough. This box utilises directory brute forcing, parameter brute forcing and path privilege escalation
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Homemade USB Rubber Ducky
https://cdn-images-1.medium.com/max/600/1*xYgNV896REQwgEW8qjS1mA.jpeg
Building a homemade rubber ducky using the Hihey TF MicroSD Micro SD Card Slot Badusb USB Virtual Keyboard and duckduino.
Continue reading on Medium »
Homemade USB Rubber Ducky
https://cdn-images-1.medium.com/max/600/1*xYgNV896REQwgEW8qjS1mA.jpeg
Building a homemade rubber ducky using the Hihey TF MicroSD Micro SD Card Slot Badusb USB Virtual Keyboard and duckduino.
Continue reading on Medium »
hacking: security in practice
Ending a relationship with an overbearing professional hacker
Any advice on how to protect myself from attacks/invasions of privacy?
submitted by /u/Elegant_Evening2136
[link] [comments]
Ending a relationship with an overbearing professional hacker
Any advice on how to protect myself from attacks/invasions of privacy?
submitted by /u/Elegant_Evening2136
[link] [comments]
reddit
Ending a relationship with an overbearing professional hacker
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
(probably) easy job
I play Roblox and I want this username but what looks like an old throwaway has it. I was wondering if someone could get into it and delete it. they haven't been online for years. I'm sorry I don't have money to pay. I can't do much about that since I don't have a method of making money. DM if interested
submitted by /u/Derpyfish5678
[link] [comments]
(probably) easy job
I play Roblox and I want this username but what looks like an old throwaway has it. I was wondering if someone could get into it and delete it. they haven't been online for years. I'm sorry I don't have money to pay. I can't do much about that since I don't have a method of making money. DM if interested
submitted by /u/Derpyfish5678
[link] [comments]
reddit
(probably) easy job
I play Roblox and I want this username but what looks like an old throwaway has it. I was wondering if someone could get into it and delete it....
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Jenkins project’s Confluence server hacked to mine Monero
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Jenkins project’s Confluence server hacked to mine MoneroPost Views: 38
Reading Time: 1 Minute
Hackers exploiting the recently disclosed Atlassian Confluence remote code execution vulnerability breached an internal server from the Jenkins project.
While the attack is concerning because Jenkins is a popular open-source server for automating parts of software development, there is no reason that the project releases, plugins, or code have been impacted. Admins are being cautiousAs BleepingComputer reported last week, after the proof-of-concept exploit code for CVE-2021-26084 became public, threat actors started to scan for vulnerable Atlassian Confluence instances to install cryptocurrency miners.
While many attackers used the exploit to install the open-source, cross-platform XMRig Monero cryptocurrency miner, they could also leverage the vulnerability for more damaging attacks.
Last week, administrators of the Jenkins project discovered that one of their deprecated Confluence server fell victim to one of these attacks.
See Also: Complete Offensive Security and Ethical Hacking Course “Thus far in our investigation, we have learned that the Confluence CVE-2021-26084 exploit was used to install what we believe was a Monero miner in the container running the service. From there an attacker would not be able to access much of our other infrastructure” – Mark Waite, Jenkins Documentation Officer
Although there is no evidence suggesting that the attacker stole developer credentials, Jenkins project managers are being careful and have reset passwords for all accounts in the integrated identity system that also included the deprecated Confluence service.
The admins also said that they “are taking actions to prevent releases at this time until we re-establish a chain of trust with our developer community.” The affected Confluence service is no longer active and privileged credentials have been rotated.
CVE-2021-26084 is a remote code execution vulnerability in Atlassian Confluence that can be exploited without authentication. News about it emerged on August 25, when the company published a security advisory.
See Also: Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
About a week later, technical details became publicly available along with proof-of-concept exploit code. Threat actors started leveraging so heavily that the U.S. Cyber Command (USCYBERCOM) issued a warning about mass exploitation.
https://www.bleepstatic.com/images/news/u/1100723/2021/USCyberComConfluence.jpg
<figcaptionsource: USCYBERCOM
See Also: Offensive Security Tool: Pegasus Spyware – Decompiled See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerSource: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/unnamed-e1630998483665-90x90.jpg Critical Auth Bypass Bug Affect NETGEAR Smart Switches1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/loyalty-card-90x90.jpg Brute-Force Attacks Target Inboxes for Gift Card Data2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Braktooth-New-Bluetooth-gaps-threaten-countless-devices-1024x576-1-90x90.jpg Bluetooth Bugs Open Billions of Devices to DoS, Code Execution5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/wordpress_plugin_vuln-90x90.jpg Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites6 days ago
* https://www.black[...]
Jenkins project’s Confluence server hacked to mine Monero
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Jenkins project’s Confluence server hacked to mine MoneroPost Views: 38
Reading Time: 1 Minute
Hackers exploiting the recently disclosed Atlassian Confluence remote code execution vulnerability breached an internal server from the Jenkins project.
While the attack is concerning because Jenkins is a popular open-source server for automating parts of software development, there is no reason that the project releases, plugins, or code have been impacted. Admins are being cautiousAs BleepingComputer reported last week, after the proof-of-concept exploit code for CVE-2021-26084 became public, threat actors started to scan for vulnerable Atlassian Confluence instances to install cryptocurrency miners.
While many attackers used the exploit to install the open-source, cross-platform XMRig Monero cryptocurrency miner, they could also leverage the vulnerability for more damaging attacks.
Last week, administrators of the Jenkins project discovered that one of their deprecated Confluence server fell victim to one of these attacks.
See Also: Complete Offensive Security and Ethical Hacking Course “Thus far in our investigation, we have learned that the Confluence CVE-2021-26084 exploit was used to install what we believe was a Monero miner in the container running the service. From there an attacker would not be able to access much of our other infrastructure” – Mark Waite, Jenkins Documentation Officer
Although there is no evidence suggesting that the attacker stole developer credentials, Jenkins project managers are being careful and have reset passwords for all accounts in the integrated identity system that also included the deprecated Confluence service.
The admins also said that they “are taking actions to prevent releases at this time until we re-establish a chain of trust with our developer community.” The affected Confluence service is no longer active and privileged credentials have been rotated.
CVE-2021-26084 is a remote code execution vulnerability in Atlassian Confluence that can be exploited without authentication. News about it emerged on August 25, when the company published a security advisory.
See Also: Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
About a week later, technical details became publicly available along with proof-of-concept exploit code. Threat actors started leveraging so heavily that the U.S. Cyber Command (USCYBERCOM) issued a warning about mass exploitation.
https://www.bleepstatic.com/images/news/u/1100723/2021/USCyberComConfluence.jpg
<figcaptionsource: USCYBERCOM
See Also: Offensive Security Tool: Pegasus Spyware – Decompiled See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerSource: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/unnamed-e1630998483665-90x90.jpg Critical Auth Bypass Bug Affect NETGEAR Smart Switches1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/loyalty-card-90x90.jpg Brute-Force Attacks Target Inboxes for Gift Card Data2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Braktooth-New-Bluetooth-gaps-threaten-countless-devices-1024x576-1-90x90.jpg Bluetooth Bugs Open Billions of Devices to DoS, Code Execution5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/wordpress_plugin_vuln-90x90.jpg Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites6 days ago
* https://www.black[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Jenkins project’s Confluence server hacked to mine Monero https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Jenkins project’s Confluence server hacked to mine MoneroPost Views: 38 Reading…
hatethicalhacking.com/wp-content/uploads/2021/09/ransomware-cpu-90x90.jpg LockFile Ransomware Uses Never-Before Seen Encryption to Avoid Detection1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Windows-Abstract-90x90.jpg Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/F5-Big-IP-e1619725870974-90x90.jpg F5 Bug Could Lead to Complete System Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/steel-series-e1629915533369-90x90.jpg Win10 Admin Rights Tossed Off by Yet Another Plug-In2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/white-pegasus-e1626804896117-90x90.jpg Pegasus Spyware Uses iPhone Zero-Click iMessage Zero-Day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/microsoft-exchange-90x90.jpg ProxyShell Attacks Pummel Unpatched Exchange Servers2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Jenkins project’s Confluence server hacked to mine Monero first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Windows-Abstract-90x90.jpg Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/F5-Big-IP-e1619725870974-90x90.jpg F5 Bug Could Lead to Complete System Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/steel-series-e1629915533369-90x90.jpg Win10 Admin Rights Tossed Off by Yet Another Plug-In2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/white-pegasus-e1626804896117-90x90.jpg Pegasus Spyware Uses iPhone Zero-Click iMessage Zero-Day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/microsoft-exchange-90x90.jpg ProxyShell Attacks Pummel Unpatched Exchange Servers2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Jenkins project’s Confluence server hacked to mine Monero first appeared on Black Hat Ethical Hacking.
Chương trình tiền thưởng lỗi OpenLeverage
https://peteranh910.medium.com/ch%C6%B0%C6%A1ng-tr%C3%ACnh-ti%E1%BB%81n-th%C6%B0%E1%BB%9Fng-l%E1%BB%97i-openleverage-30a50b8fc340?source=rss------bug_bounty-5
https://peteranh910.medium.com/ch%C6%B0%C6%A1ng-tr%C3%ACnh-ti%E1%BB%81n-th%C6%B0%E1%BB%9Fng-l%E1%BB%97i-openleverage-30a50b8fc340?source=rss------bug_bounty-5
Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium » (https://peteranh910.medium.com/ch%C6%B0%C6%A1ng-tr%C3%ACnh-ti%E1%BB%81n-th%C6%B0%E1%BB%9Fng-l%E1%BB%97i-openleverage-30a50b8fc340?source=rss------bug_bounty-5)
hacking: security in practice
Code execution in restricted VDI environments
Normally, execution of cmd.exe and powershell.exe is prohibited in restricted VDI environments. However, I've seen cases where this can be circumvented by executing a script directly (.bat, .vbs, .ps) and redirect it to another output.
What is the name for this technique? Is it local code execution? What is the risk rating for this use case? High? Medium? Low?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Code execution in restricted VDI environments
Normally, execution of cmd.exe and powershell.exe is prohibited in restricted VDI environments. However, I've seen cases where this can be circumvented by executing a script directly (.bat, .vbs, .ps) and redirect it to another output.
What is the name for this technique? Is it local code execution? What is the risk rating for this use case? High? Medium? Low?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Code execution in restricted VDI environments
Normally, execution of cmd.exe and powershell.exe is prohibited in restricted VDI environments. However, I've seen cases where this can be...
hacking: security in practice
Exfiltrate data with built-in windows ping command
I know it's possible to exfiltrate data using 3rd party tool. But, is it possible to do it with built-in windows ping command on the client side?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Exfiltrate data with built-in windows ping command
I know it's possible to exfiltrate data using 3rd party tool. But, is it possible to do it with built-in windows ping command on the client side?
submitted by /u/w0lfcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Exfiltrate data with built-in windows ping command
I know it's possible to exfiltrate data using 3rd party tool. But, is it possible to do it with built-in windows ping command on the client side?
Chương trình tiền thưởng lỗi OpenLeverage
Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium »
Read more...
Để chuẩn bị cho việc ra mắt mạng chính, chúng tôi đã hoàn thành quá trình kiểm tra nghiêm ngặt trên tất cả các hợp đồng thông minh của…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Truffle Security Recommends Doppler For Remediating Leaked Secrets
https://cdn-images-1.medium.com/max/1600/0*WjPHSPycMbPx8XLs.jpg
Keeping your secrets secure is not just about secrets management, but detecting accidental leaks when they occur and fixing them fast.
Continue reading on Doppler »
___________________________
@hacking_Attack
@Hacking_Video
Truffle Security Recommends Doppler For Remediating Leaked Secrets
https://cdn-images-1.medium.com/max/1600/0*WjPHSPycMbPx8XLs.jpg
Keeping your secrets secure is not just about secrets management, but detecting accidental leaks when they occur and fixing them fast.
Continue reading on Doppler »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Truffle Security Recommends Doppler For Remediating Leaked Secrets
Keeping your secrets secure is not just about secrets management, but detecting accidental leaks when they occur and fixing them fast.