Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Active Exploits Hit WordPress Sites Vulnerable to Thrive…
n of a feature in the Thrive Dashboard, allowing integration with online automation tool Zapier. In order to make this integration happen, Thrive Themes products register a REST API endpoint associated with Zapier functionality.
“While this endpoint was intended to require an API key in order to access, it was possible to access it by supplying an empty api_key parameter in vulnerable versions if Zapier was not enabled,” according to Chamberland. “Attackers could use this endpoint to add arbitrary data to a predefined option in the wp_options table.”
Of note, a CVE ID for both of these vulnerabilities is pending, according to Wordfence. See Also: Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbersThe Exploit ChainChamberland said that attackers can chain these two vulnerabilities together in order to access affected websites – though Chamberland noted, researchers are intentionally providing minimal details about the exploit chain “in an attempt to keep exploitation to a minimum while also informing WordPress site owners using affected Thrive Theme products of this active campaign.”
At a high level, attackers are using the medium-severity “Unauthenticated Option Update” vulnerability to update an option in the database. This can then be used to leverage the critical-severity “Unauthenticated Arbitrary File Upload” vulnerability – and upload a malicious PHP file.
“The combination of these two vulnerabilities is allowing attackers to gain backdoor access into vulnerable sites to further compromise them,” said Chamberland. Attacker Exploits ContinueResearchers were able to “verify this intrusion vector” on an individual site – and they then found the payload added by this attack on over 1,900 sites, all of which appear to have vulnerable REST API endpoints.
Chamberland told Threatpost, researchers are seeing attackers add a signup.php file to the home directory of targeted sites, which is then being used to further infect sites with spam.
“This number is continuing to rise indicating that the attackers are continuing to successfully exploit the vulnerabilities and compromise sites,” Chamberland told Threatpost. “Right now, we don’t have an idea how who specifically per se is behind the attacks, however, most of the attack data we are seeing is primarily coming from an attacker with the IP address of 5.255.176.41.”
Chamberland said, Thrive Themes users should make sure they’re updated as soon as possible.
“For the time being, we urge that site owners running any of the Thrive Themes ‘legacy’ themes to update to version 2.0.0 immediately, and any site owners running any of the Thrive plugins to update to the latest version available for each of the respective plugins,” she stressed.
Source: https://threatpost.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/HL-color-90x90.jpg Hobby Lobby Exposes Customer Data in Cloud Misconfiguration1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/adobe_coldfusion-700x412-e1542041238507-90x90.jpg Adobe Fixes Critical ColdFusion Flaw in Emergency Update2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Clubhouse-e1614022265127-90x90.jpg Bogus Android Clubhouse App Drops Credential-Swiping Malware3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/apple-security-90x90.jpg Trojanized Xcode Project Slips MacOS Malware to Apple Developers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Cisco_Systems_Sign-90x90.jpg Cisco Plugs Security Hole in Small Business Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-conten[...]
“While this endpoint was intended to require an API key in order to access, it was possible to access it by supplying an empty api_key parameter in vulnerable versions if Zapier was not enabled,” according to Chamberland. “Attackers could use this endpoint to add arbitrary data to a predefined option in the wp_options table.”
Of note, a CVE ID for both of these vulnerabilities is pending, according to Wordfence. See Also: Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbersThe Exploit ChainChamberland said that attackers can chain these two vulnerabilities together in order to access affected websites – though Chamberland noted, researchers are intentionally providing minimal details about the exploit chain “in an attempt to keep exploitation to a minimum while also informing WordPress site owners using affected Thrive Theme products of this active campaign.”
At a high level, attackers are using the medium-severity “Unauthenticated Option Update” vulnerability to update an option in the database. This can then be used to leverage the critical-severity “Unauthenticated Arbitrary File Upload” vulnerability – and upload a malicious PHP file.
“The combination of these two vulnerabilities is allowing attackers to gain backdoor access into vulnerable sites to further compromise them,” said Chamberland. Attacker Exploits ContinueResearchers were able to “verify this intrusion vector” on an individual site – and they then found the payload added by this attack on over 1,900 sites, all of which appear to have vulnerable REST API endpoints.
Chamberland told Threatpost, researchers are seeing attackers add a signup.php file to the home directory of targeted sites, which is then being used to further infect sites with spam.
“This number is continuing to rise indicating that the attackers are continuing to successfully exploit the vulnerabilities and compromise sites,” Chamberland told Threatpost. “Right now, we don’t have an idea how who specifically per se is behind the attacks, however, most of the attack data we are seeing is primarily coming from an attacker with the IP address of 5.255.176.41.”
Chamberland said, Thrive Themes users should make sure they’re updated as soon as possible.
“For the time being, we urge that site owners running any of the Thrive Themes ‘legacy’ themes to update to version 2.0.0 immediately, and any site owners running any of the Thrive plugins to update to the latest version available for each of the respective plugins,” she stressed.
Source: https://threatpost.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/HL-color-90x90.jpg Hobby Lobby Exposes Customer Data in Cloud Misconfiguration1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/adobe_coldfusion-700x412-e1542041238507-90x90.jpg Adobe Fixes Critical ColdFusion Flaw in Emergency Update2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Clubhouse-e1614022265127-90x90.jpg Bogus Android Clubhouse App Drops Credential-Swiping Malware3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/apple-security-90x90.jpg Trojanized Xcode Project Slips MacOS Malware to Apple Developers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Cisco_Systems_Sign-90x90.jpg Cisco Plugs Security Hole in Small Business Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-conten[...]
Hacking Articles Tips Tricks Videos Tutorials
n of a feature in the Thrive Dashboard, allowing integration with online automation tool Zapier. In order to make this integration happen, Thrive Themes products register a REST API endpoint associated with Zapier functionality. “While this endpoint was…
t/uploads/2021/03/JPG-Malicious-Two-90x90.jpg Magecart Attackers Save Stolen Credit-Card Data in JPG Files1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Google-Chrome-Browser-1-90x90.jpg Google Warns Mac, Windows Users of Chrome Zero-Day Flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/internet-of-things-90x90.jpg Critical Security Hole Can Knock Smart Meters Offline1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Linux-kernel-vulnerability-90x90.png Linux Systems Under Attack By New RedXOR Malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/security-camera-90x90.jpg Breach Exposes Verkada Security Camera Footage at Tesla, Cloudflare2 weeks ago
The post Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Google-Chrome-Browser-1-90x90.jpg Google Warns Mac, Windows Users of Chrome Zero-Day Flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/internet-of-things-90x90.jpg Critical Security Hole Can Knock Smart Meters Offline1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Linux-kernel-vulnerability-90x90.png Linux Systems Under Attack By New RedXOR Malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/security-camera-90x90.jpg Breach Exposes Verkada Security Camera Footage at Tesla, Cloudflare2 weeks ago
The post Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws first appeared on Black Hat Ethical Hacking.
Deep Web
Torrezz
Torrezz back offline again has been for hours??
submitted by /u/justgowithit44444
[link] [comments]
Torrezz
Torrezz back offline again has been for hours??
submitted by /u/justgowithit44444
[link] [comments]
reddit
Torrezz
Torrezz back offline again has been for hours??
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
XSS how-to covering: Absolute basics, types of XSS, contexts, discovery methods, polyglots, basic filter bypasses, event attributes, escalation methods, short payloads, bypassing SOP and edge cases
https://b.thumbs.redditmedia.com/2WDW_gegTpowqzy3QOsGV4TcZahglvbl2trEAYmTWok.jpg submitted by /u/hakluke
[link] [comments]
XSS how-to covering: Absolute basics, types of XSS, contexts, discovery methods, polyglots, basic filter bypasses, event attributes, escalation methods, short payloads, bypassing SOP and edge cases
https://b.thumbs.redditmedia.com/2WDW_gegTpowqzy3QOsGV4TcZahglvbl2trEAYmTWok.jpg submitted by /u/hakluke
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hackathon: Golem (the Ethereum Sleepin Giant) + Gitcoin GR9 Hackathon, up to 30k USDC in prizes. There's also a special category where you get to work on some dope projects from MIT Solve
https://b.thumbs.redditmedia.com/77lxOJPHc0XNeZno0PwbxpVWxYeaEk_ogHZnkjM9JOo.jpg submitted by /u/costgallo
[link] [comments]
Hackathon: Golem (the Ethereum Sleepin Giant) + Gitcoin GR9 Hackathon, up to 30k USDC in prizes. There's also a special category where you get to work on some dope projects from MIT Solve
https://b.thumbs.redditmedia.com/77lxOJPHc0XNeZno0PwbxpVWxYeaEk_ogHZnkjM9JOo.jpg submitted by /u/costgallo
[link] [comments]
Gitrecon - OSINT Tool To Get Information From A Github Profile And Find GitHub User'S Email Addresses Leaked On Commits
OSINT tool to get information from a github profile and find GitHub user's email addresses leaked on commits.How does this work? GitHub uses the email address associated with a GitHub account to link commits and other activity to a GitHub profile. When a user makes commits to public repos their email address is usually published in the commit and becomes publicly accessible, if you know where to look. GitHub provide some instructions on how to prevent this from happening, but it seems that most GitHub users either don't know or don't care that their email address may be exposed. Finding a GitHub user's email address is often as simple as looking at their recent events via the GitHub API. Idea and text from Nick Drewe. Source: https://thedatapack.com/tools/find-github-user-email/ Prerequisites Python 3 Installation git clone https://github.com/GONZOsint/gitrecon.gitcd gitrecon/python3 -m pip install -r requirements.txt It is possible to use a Github access token by editing line 23 of the gitrecon.py file token = '<Access token here>' Usage usage: gitrecon.py -h -a -o usernamepositional arguments: usernameoptional arguments: -h, --help show this help message and exit -a, --avatar download avatar pic -o, --output save output as json Features Profile info Username Name User ID Avatar url Email Location Bio Company Blog Gravatar ID Twitter username Followers Following Created at Updated at Extract Orgs Search for leaked emails on commits Prevention To avoid this type of leaks, certain configurations can be made on Github: Settings url: https://github.com/settings/emails ✔️ Keep my email addresses private ✔️ Block command line pushes that expose my email Download Gitrecon
Read more...
OSINT tool to get information from a github profile and find GitHub user's email addresses leaked on commits.How does this work? GitHub uses the email address associated with a GitHub account to link commits and other activity to a GitHub profile. When a user makes commits to public repos their email address is usually published in the commit and becomes publicly accessible, if you know where to look. GitHub provide some instructions on how to prevent this from happening, but it seems that most GitHub users either don't know or don't care that their email address may be exposed. Finding a GitHub user's email address is often as simple as looking at their recent events via the GitHub API. Idea and text from Nick Drewe. Source: https://thedatapack.com/tools/find-github-user-email/ Prerequisites Python 3 Installation git clone https://github.com/GONZOsint/gitrecon.gitcd gitrecon/python3 -m pip install -r requirements.txt It is possible to use a Github access token by editing line 23 of the gitrecon.py file token = '<Access token here>' Usage usage: gitrecon.py -h -a -o usernamepositional arguments: usernameoptional arguments: -h, --help show this help message and exit -a, --avatar download avatar pic -o, --output save output as json Features Profile info Username Name User ID Avatar url Email Location Bio Company Blog Gravatar ID Twitter username Followers Following Created at Updated at Extract Orgs Search for leaked emails on commits Prevention To avoid this type of leaks, certain configurations can be made on Github: Settings url: https://github.com/settings/emails ✔️ Keep my email addresses private ✔️ Block command line pushes that expose my email Download Gitrecon
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Subcert : Finds All The Subdomains From Certificate Transparency Logs
Subcert is a subdomain enumeration tool, that finds all the valid subdomains from certificate transparency logs. Setup Step 1: Install Python 3 apt-get install python3-pip Step 2: Clone the Repository git clone https://github.com/A3h1nt/Subcert.git Step 3: Install Dependencies pip3 install -r requirements.txt Step 4: Move the Directory to /opt mv subcert /opt/ Step 5: Add an […]
The post Subcert : Finds All The Subdomains From Certificate Transparency Logs appeared first on Kali Linux Tutorials.
Subcert : Finds All The Subdomains From Certificate Transparency Logs
Subcert is a subdomain enumeration tool, that finds all the valid subdomains from certificate transparency logs. Setup Step 1: Install Python 3 apt-get install python3-pip Step 2: Clone the Repository git clone https://github.com/A3h1nt/Subcert.git Step 3: Install Dependencies pip3 install -r requirements.txt Step 4: Move the Directory to /opt mv subcert /opt/ Step 5: Add an […]
The post Subcert : Finds All The Subdomains From Certificate Transparency Logs appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
stack overflow (bof) challenge writeup
https://cdn-images-1.medium.com/max/1366/1*d3DAtyimZsJ4EoSFHAzmPA.png
in this writeup i will demonstrate and gave explanation about a challange available here https://pwnable.kr/play.php so lets start
Continue reading on Medium »
stack overflow (bof) challenge writeup
https://cdn-images-1.medium.com/max/1366/1*d3DAtyimZsJ4EoSFHAzmPA.png
in this writeup i will demonstrate and gave explanation about a challange available here https://pwnable.kr/play.php so lets start
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
7 Hacks To Increase Your Landing Page Traffic
https://cdn-images-1.medium.com/max/2164/1*FugPvLFWU2-nPkK-gEa_Ww.png
Landing page are intended to make a conversion. Be it register number, social media followers, product buying or newsletter request…
Continue reading on Girls Kode — All About Tech & Digital »
7 Hacks To Increase Your Landing Page Traffic
https://cdn-images-1.medium.com/max/2164/1*FugPvLFWU2-nPkK-gEa_Ww.png
Landing page are intended to make a conversion. Be it register number, social media followers, product buying or newsletter request…
Continue reading on Girls Kode — All About Tech & Digital »
Question about installing Nessus Pro licensing on a dropbox vm and exporting an ova
https://www.reddit.com/r/Pentesting/comments/md0pom/question_about_installing_nessus_pro_licensing_on/
<!-- SC_OFF -->Anyone have any experience with building pentest dropboxes and installing Nessus Pro? I've already built virtual machine pentest dropboxes and integrated everything including the OpenVPN connection and ssh keys for access. Now I have some upcoming assessments that are basically validated vulnerability assessments, not true pentests. I don't want to waste a Nessus license, if after importing the virtual machine ova Nessus is no longer licensed because the NIC MAC address changed, or anything like that. Does anyone know if Nessus would remain licensed after exporting the virtual machine ova and importing into another system? I don't want to burn a license trying to find the answer. I could always fall back to using OpenVAS, but I'd prefer Nessus Pro. <!-- SC_ON --> submitted by /u/subsonic68 (https://www.reddit.com/user/subsonic68)
[link] (https://www.reddit.com/r/Pentesting/comments/md0pom/question_about_installing_nessus_pro_licensing_on/) [comments] (https://www.reddit.com/r/Pentesting/comments/md0pom/question_about_installing_nessus_pro_licensing_on/)
https://www.reddit.com/r/Pentesting/comments/md0pom/question_about_installing_nessus_pro_licensing_on/
<!-- SC_OFF -->Anyone have any experience with building pentest dropboxes and installing Nessus Pro? I've already built virtual machine pentest dropboxes and integrated everything including the OpenVPN connection and ssh keys for access. Now I have some upcoming assessments that are basically validated vulnerability assessments, not true pentests. I don't want to waste a Nessus license, if after importing the virtual machine ova Nessus is no longer licensed because the NIC MAC address changed, or anything like that. Does anyone know if Nessus would remain licensed after exporting the virtual machine ova and importing into another system? I don't want to burn a license trying to find the answer. I could always fall back to using OpenVAS, but I'd prefer Nessus Pro. <!-- SC_ON --> submitted by /u/subsonic68 (https://www.reddit.com/user/subsonic68)
[link] (https://www.reddit.com/r/Pentesting/comments/md0pom/question_about_installing_nessus_pro_licensing_on/) [comments] (https://www.reddit.com/r/Pentesting/comments/md0pom/question_about_installing_nessus_pro_licensing_on/)