hacking: security in practice
Social Engineering or Hacking?
So here's a wild story. My girlfriend and I share a tinder account trying to find people for 3somes and stuff like that. She turned on guys and was quickly met with a guy acting like a hard ass. He said "So what happens if I screenshot this convo and post it online for everyone to see?" I immediately called him out on his bluff and told him he was pathetic, etc. We unmatched and reported and moved on with our lives. Maybe a half an hour later he ended up finding me on Facebook and sent me a friend request. I immediately blocked him. For reference, I was the one sending the last few messages, but the account is under my girlfriend's name and pictures with no reference to me at all. Furthermore her Instagram is private (profile pic is of us though), and her Twitter contains no reference to me. My question: How did he find my Facebook, when he had no reference to my name, doesn't really know what I look like, etc? Is this just some no-life with a plethora of time on his hands and was bored enough to sift around the internet until he found me? Or is there something bigger at stake? Perhaps he got my number and found my Facebook that way? I somewhat doubt he has my number because he hasn't texted, called, etc. However it would of course be trouble if he did somehow obtain that. One important note is that he lives in the area and allegedly goes to the same university that I just graduated from. I don't recognize him though and I'm sure he doesn't recognize me (no mutual friends in the request either).
submitted by /u/expodavid
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Social Engineering or Hacking?
So here's a wild story. My girlfriend and I share a tinder account trying to find people for 3somes and stuff like that. She turned on guys and was quickly met with a guy acting like a hard ass. He said "So what happens if I screenshot this convo and post it online for everyone to see?" I immediately called him out on his bluff and told him he was pathetic, etc. We unmatched and reported and moved on with our lives. Maybe a half an hour later he ended up finding me on Facebook and sent me a friend request. I immediately blocked him. For reference, I was the one sending the last few messages, but the account is under my girlfriend's name and pictures with no reference to me at all. Furthermore her Instagram is private (profile pic is of us though), and her Twitter contains no reference to me. My question: How did he find my Facebook, when he had no reference to my name, doesn't really know what I look like, etc? Is this just some no-life with a plethora of time on his hands and was bored enough to sift around the internet until he found me? Or is there something bigger at stake? Perhaps he got my number and found my Facebook that way? I somewhat doubt he has my number because he hasn't texted, called, etc. However it would of course be trouble if he did somehow obtain that. One important note is that he lives in the area and allegedly goes to the same university that I just graduated from. I don't recognize him though and I'm sure he doesn't recognize me (no mutual friends in the request either).
submitted by /u/expodavid
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Social Engineering or Hacking?
So here's a wild story. My girlfriend and I share a tinder account trying to find people for 3somes and stuff like that. She turned on guys and...
hacking: security in practice
Dear proffessional hackers <3
oday was a terrible day, I seemed to have sprained my ankle, and my phone got stolen. I went to the address, after tracking down my phone, and confronted them. They, however, claimed they dont have it, despite the tracking location being there. Another thing, "let me go check" (his response after I told him that my phone was here), sus, i know. I left and went back home in tears, called the police and they did not show. Very shitty day and I wanted to have even a little sense of justice due. So my purpose here is to hopefully get him trolled, immensely. I currently have a potentially sprained ankle, emotional damage, and no phone. Let me know if you guys are willing to try and see what you can do. All I know is where they live, what could I do?
submitted by /u/rotten-kimchii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Dear proffessional hackers <3
oday was a terrible day, I seemed to have sprained my ankle, and my phone got stolen. I went to the address, after tracking down my phone, and confronted them. They, however, claimed they dont have it, despite the tracking location being there. Another thing, "let me go check" (his response after I told him that my phone was here), sus, i know. I left and went back home in tears, called the police and they did not show. Very shitty day and I wanted to have even a little sense of justice due. So my purpose here is to hopefully get him trolled, immensely. I currently have a potentially sprained ankle, emotional damage, and no phone. Let me know if you guys are willing to try and see what you can do. All I know is where they live, what could I do?
submitted by /u/rotten-kimchii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dear proffessional hackers <3
oday was a terrible day, I seemed to have sprained my ankle, and my phone got stolen. I went to the address, after tracking down my phone, and...
How long can a reverse connection last in a machine?
https://www.reddit.com/r/Pentesting/comments/qacyfw/how_long_can_a_reverse_connection_last_in_a/
I'm wondering how APT does intrusion and persistence in a system for months, even years. is it possible to maintain a shell on a victim's machine for a lot of time? how this can be done using netcat or similar? submitted by /u/Repulsiv-e (https://www.reddit.com/user/Repulsiv-e)
[link] (https://www.reddit.com/r/Pentesting/comments/qacyfw/how_long_can_a_reverse_connection_last_in_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/qacyfw/how_long_can_a_reverse_connection_last_in_a/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/qacyfw/how_long_can_a_reverse_connection_last_in_a/
I'm wondering how APT does intrusion and persistence in a system for months, even years. is it possible to maintain a shell on a victim's machine for a lot of time? how this can be done using netcat or similar? submitted by /u/Repulsiv-e (https://www.reddit.com/user/Repulsiv-e)
[link] (https://www.reddit.com/r/Pentesting/comments/qacyfw/how_long_can_a_reverse_connection_last_in_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/qacyfw/how_long_can_a_reverse_connection_last_in_a/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How long can a reverse connection last in a machine?
I'm wondering how APT does intrusion and persistence in a system for months, even years. is it possible to maintain a shell on a victim's machine...
Facebook account takeover due to unsafe redirects after the OAuth flow
DescriptionContinue reading on Medium »
Read more...
DescriptionContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Google Warns Government-Backed Hackers Are on the Rise
Google’s Threat Analysis Group (TAG) is warning high-risk groups that there has been a surge in activity by government-backed hacking campaigns, up 33% so far this year over the same time period in 2020, according to a blog post.
https://www.pymnts.com/news/security-and-risk/2021/google-warns-government-backed-hackers-are-on-the-rise/
submitted by /u/Finlay_Lee
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Google Warns Government-Backed Hackers Are on the Rise
Google’s Threat Analysis Group (TAG) is warning high-risk groups that there has been a surge in activity by government-backed hacking campaigns, up 33% so far this year over the same time period in 2020, according to a blog post.
https://www.pymnts.com/news/security-and-risk/2021/google-warns-government-backed-hackers-are-on-the-rise/
submitted by /u/Finlay_Lee
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Google Warns Government-Backed Hackers Are on the Rise
Google’s Threat Analysis Group (TAG) is warning high-risk groups that there has been a surge in activity by government-backed hacking campaigns,...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to get free likes and followers on your instagram account
https://cdn-images-1.medium.com/max/600/0*JZHnuUmTq5Aev4di.jpg
Hello guys, Nowadays everyone wants that they get high amount of likes and followers on their Instagram Account. But only few of them get…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to get free likes and followers on your instagram account
https://cdn-images-1.medium.com/max/600/0*JZHnuUmTq5Aev4di.jpg
Hello guys, Nowadays everyone wants that they get high amount of likes and followers on their Instagram Account. But only few of them get…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to get free likes and followers on your instagram account
Hello guys, Nowadays everyone wants that they get high amount of likes and followers on their Instagram Account. But only few of them get…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Reverse Shell Cheat Sheet
https://cdn-images-1.medium.com/max/1366/1*j4dWBvJGuRDpHhOYpl0VAw.jpeg
Las formas y el porque una Reverse Shell es importante durante pruebas de Ethical Hacking
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Reverse Shell Cheat Sheet
https://cdn-images-1.medium.com/max/1366/1*j4dWBvJGuRDpHhOYpl0VAw.jpeg
Las formas y el porque una Reverse Shell es importante durante pruebas de Ethical Hacking
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reverse Shell Cheat Sheet
Las formas y el porque una Reverse Shell es importante durante pruebas de Ethical Hacking
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Second set of the free Hack The Box Starting Point boxes PWNed!
https://cdn-images-1.medium.com/max/1249/1*my6bSptgHAsSJ0kTfD-tNQ.png
For this, you need to run mysql against the target box, and if your like me using your own Linux box and don't have it installed… Here is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Second set of the free Hack The Box Starting Point boxes PWNed!
https://cdn-images-1.medium.com/max/1249/1*my6bSptgHAsSJ0kTfD-tNQ.png
For this, you need to run mysql against the target box, and if your like me using your own Linux box and don't have it installed… Here is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Second set of the free Hack The Box Starting Point boxes PWNed!
For this, you need to run mysql against the target box, and if your like me using your own Linux box and don't have it installed… Here is…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
REvil ransomware shuts down again after Tor sites were hijacked
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png REvil ransomware shuts down again after Tor sites were hijackedPost Views: 120
Reading Time: 1 Minute
The REvil ransomware operation has likely shut down once again after an unknown person hijacked their Tor payment portal and data leak blog.
The Tor sites went offline earlier today, with a threat actor affiliated with the REvil operation posting to the XSS hacking forum that someone hijacked the gang’s domains.
The thread was first discovered by Recorded Future’s Dmitry Smilyanets, and states that an unknown person hijacked the Tor hidden services (onion domains) with the same private keys as REvil’s Tor sites and likely has backups of the sites.
“But since we have today at 17.10 from 12:00 Moscow time, someone brought up the hidden-services of a landing and a blog with the same keys as ours, my fears were confirmed. The third party has backups with onion service keys,” a threat actor known as ‘0_neday’ posted to the hacking forum.
The threat actor went on to say that they found no signs of compromise to their servers but will be shutting down the operation.
See Also: Complete Offensive Security and Ethical Hacking Course
The threat actor then told affiliates to contact him for campaign decryption keys via Tox, likely so affiliates could continue extorting their victims and provide a decryptor if a ransom is paid.
https://www.bleepstatic.com/images/news/ransomware/r/revil/tor-servers-hijack/forum-post-1.jpg
REvil likely shut down for goodAfter REvil conducted a massive attack on companies through a zero-day vulnerability in the Kaseya MSP platform, the REvil operation suddenly shut down, and their public-facing representative, Unknown, disappeared.
After Unknown did not return, the rest of the REvil operators launched the operation and websites again in September using backups.
Since then, the ransomware operation has been struggling to recruit users, going as far as to increase affiliate’s commissions to 90% to entice other threat actors to work with them.
With this latest mishap, the operation in its current forum will likely be gone for good.
However, no good thing lasts forever when it comes to ransomware, and we will like[...]
___________________________
@hacking_Attack
@Hacking_Video
REvil ransomware shuts down again after Tor sites were hijacked
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png REvil ransomware shuts down again after Tor sites were hijackedPost Views: 120
Reading Time: 1 Minute
The REvil ransomware operation has likely shut down once again after an unknown person hijacked their Tor payment portal and data leak blog.
The Tor sites went offline earlier today, with a threat actor affiliated with the REvil operation posting to the XSS hacking forum that someone hijacked the gang’s domains.
The thread was first discovered by Recorded Future’s Dmitry Smilyanets, and states that an unknown person hijacked the Tor hidden services (onion domains) with the same private keys as REvil’s Tor sites and likely has backups of the sites.
“But since we have today at 17.10 from 12:00 Moscow time, someone brought up the hidden-services of a landing and a blog with the same keys as ours, my fears were confirmed. The third party has backups with onion service keys,” a threat actor known as ‘0_neday’ posted to the hacking forum.
The threat actor went on to say that they found no signs of compromise to their servers but will be shutting down the operation.
See Also: Complete Offensive Security and Ethical Hacking Course
The threat actor then told affiliates to contact him for campaign decryption keys via Tox, likely so affiliates could continue extorting their victims and provide a decryptor if a ransom is paid.
https://www.bleepstatic.com/images/news/ransomware/r/revil/tor-servers-hijack/forum-post-1.jpg
REvil likely shut down for goodAfter REvil conducted a massive attack on companies through a zero-day vulnerability in the Kaseya MSP platform, the REvil operation suddenly shut down, and their public-facing representative, Unknown, disappeared.
After Unknown did not return, the rest of the REvil operators launched the operation and websites again in September using backups.
Since then, the ransomware operation has been struggling to recruit users, going as far as to increase affiliate’s commissions to 90% to entice other threat actors to work with them.
With this latest mishap, the operation in its current forum will likely be gone for good.
However, no good thing lasts forever when it comes to ransomware, and we will like[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
REvil ransomware shuts down again after Tor sites were hijacked | Black Hat Ethical Hacking
The REvil ransomware operation has likely shut down once again after an unknown person hijacked their Tor payment portal and data leak blog.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking REvil ransomware shuts down again after Tor sites were hijacked https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png REvil ransomware shuts down again after Tor sites were hijackedPost Views:…
ly see them rebrand as a new operation shortly.
See Also: Offensive Security Tool: Dalfox However, some IP and domain evidence attributes this extension to the Pbot campaign, which has been active since at least 2018.
This case is yet another reminder of the importance of choosing your browser extensions wisely and installing only the necessary ones.
In this case, AllBlock has excellent user reviews because its functionality as an adblocker has been properly implemented. Nonetheless, it introduces deception risks and confuses shoppers.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Apache-web-server-90x90.png Apache fixes actively exploited zero-day vulnerability, patch now2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/security-breach-freepik-90x90.jpg Encrypted & Fileless Malware Sees Big Growth2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Digital-Wallet-90x90.jpg MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed2 weeks ago
The post REvil ransomware shuts down again after Tor sites were hijacked first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
See Also: Offensive Security Tool: Dalfox However, some IP and domain evidence attributes this extension to the Pbot campaign, which has been active since at least 2018.
This case is yet another reminder of the importance of choosing your browser extensions wisely and installing only the necessary ones.
In this case, AllBlock has excellent user reviews because its functionality as an adblocker has been properly implemented. Nonetheless, it introduces deception risks and confuses shoppers.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Apache-web-server-90x90.png Apache fixes actively exploited zero-day vulnerability, patch now2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/security-breach-freepik-90x90.jpg Encrypted & Fileless Malware Sees Big Growth2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Digital-Wallet-90x90.jpg MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed2 weeks ago
The post REvil ransomware shuts down again after Tor sites were hijacked first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Support Board 3.3.4 Arbitrary File Deletion to Remote Code Execution
https://noob3xploiter.medium.com/support-board-3-3-4-arbitrary-file-deletion-to-remote-code-execution-da4c45b45c83?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://noob3xploiter.medium.com/support-board-3-3-4-arbitrary-file-deletion-to-remote-code-execution-da4c45b45c83?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Support Board 3.3.4 Arbitrary File Deletion to Remote Code Execution
Hi. In this writeup, i will show you a bug that i found. Allowing an Authenticated user to delete any file in the system in the Support…
Hi. In this writeup, i will show you a bug that i found. Allowing an Authenticated user to delete any file in the system in the Support…Continue reading on Medium » (https://noob3xploiter.medium.com/support-board-3-3-4-arbitrary-file-deletion-to-remote-code-execution-da4c45b45c83?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Support Board 3.3.4 Arbitrary File Deletion to Remote Code Execution
Hi. In this writeup, i will show you a bug that i found. Allowing an Authenticated user to delete any file in the system in the Support…
Support Board 3.3.4 Arbitrary File Deletion to Remote Code Execution
Hi. In this writeup, i will show you a bug that i found. Allowing an Authenticated user to delete any file in the system in the Support…Continue reading on Medium »
Read more...
Hi. In this writeup, i will show you a bug that i found. Allowing an Authenticated user to delete any file in the system in the Support…Continue reading on Medium »
Read more...