Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
REvil ransomware shuts down again after Tor sites were hijacked

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png REvil ransomware shuts down again after Tor sites were hijackedPost Views: 120
Reading Time: 1 Minute
The REvil ransomware operation has likely shut down once again after an unknown person hijacked their Tor payment portal and data leak blog.
The Tor sites went offline earlier today, with a threat actor affiliated with the REvil operation posting to the XSS hacking forum that someone hijacked the gang’s domains.

The thread was first discovered by Recorded Future’s Dmitry Smilyanets, and states that an unknown person hijacked the Tor hidden services (onion domains) with the same private keys as REvil’s Tor sites and likely has backups of the sites.

“But since we have today at 17.10 from 12:00 Moscow time, someone brought up the hidden-services of a landing and a blog with the same keys as ours, my fears were confirmed. The third party has backups with onion service keys,” a threat actor known as ‘0_neday’ posted to the hacking forum.

The threat actor went on to say that they found no signs of compromise to their servers but will be shutting down the operation.
See Also: Complete Offensive Security and Ethical Hacking Course
The threat actor then told affiliates to contact him for campaign decryption keys via Tox, likely so affiliates could continue extorting their victims and provide a decryptor if a ransom is paid.
https://www.bleepstatic.com/images/news/ransomware/r/revil/tor-servers-hijack/forum-post-1.jpg
REvil likely shut down for goodAfter REvil conducted a massive attack on companies through a zero-day vulnerability in the Kaseya MSP platform, the REvil operation suddenly shut down, and their public-facing representative, Unknown, disappeared.

After Unknown did not return, the rest of the REvil operators launched the operation and websites again in September using backups.

Since then, the ransomware operation has been struggling to recruit users, going as far as to increase affiliate’s commissions to 90% to entice other threat actors to work with them.

With this latest mishap, the operation in its current forum will likely be gone for good.

However, no good thing lasts forever when it comes to ransomware, and we will like[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking REvil ransomware shuts down again after Tor sites were hijacked https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png REvil ransomware shuts down again after Tor sites were hijackedPost Views:…
ly see them rebrand as a new operation shortly.
See Also: Offensive Security Tool: Dalfox However, some IP and domain evidence attributes this extension to the Pbot campaign, which has been active since at least 2018.

This case is yet another reminder of the importance of choosing your browser extensions wisely and installing only the necessary ones.

In this case, AllBlock has excellent user reviews because its functionality as an adblocker has been properly implemented. Nonetheless, it introduces deception risks and confuses shoppers.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Apache-web-server-90x90.png Apache fixes actively exploited zero-day vulnerability, patch now2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/security-breach-freepik-90x90.jpg Encrypted & Fileless Malware Sees Big Growth2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Digital-Wallet-90x90.jpg MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed2 weeks ago
The post REvil ransomware shuts down again after Tor sites were hijacked first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Support Board 3.3.4 Arbitrary File Deletion to Remote Code Execution

Hi. In this writeup, i will show you a bug that i found. Allowing an Authenticated user to delete any file in the system in the Support…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
ImpulsiveDLLHijack - C# Based Tool Which Automates The Process Of Discovering And Exploiting DLL Hijacks In Target Binaries

https://blogger.googleusercontent.com/img/a/AVvXsEj2Uj3bSaeJROw2MVmH2_APvD6EetFh4dj9miT-yA5_YexB3p0Ruy-SPP2oxxKWlSkUctIm8A46OKIsAE9Yp8XqyVDMOeP636s_a4KyMb1D5vvyZvAn3g_BBYyt-nsg69-hy4ZsHhfFrN66I3V86SWSKwMV03TILzuBXy0Y0-lihymmMGZElDkk--91DA=w640-h216 C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be weaponized during RedTeam Operations to evade EDR's. 1. Methodological Approach :The tool basically acts on automating following stages performed for DLL Hijacking:

* Discovery - Finding Potentially Vulnerable DLL Hijack paths
* Exploitation - Confirming whether the Confirmatory DLL was been loaded from the Hijacked path leading to a confirmation of 100% exploitable DLL Hijack!

Discovery Methodology :

* Provide Target binary path to ImpulsiveDLLHijack.exe
* Automation of ProcMon along with the execution of Target binary to find Potentially Vulnerable DLL Hijackable paths.

Exploitation Methodology :

*
Parse Potentially Vulnerable DLL Hijack paths from CSV generated automatically via ProcMon.

*
Copy the Confirmatory DLL (as per the PE architecture) to the hijack paths one by one and execute the Target Binary for predefined time period simultaneously.

*
As the DLL hijacking process is in progress following are the outputs which can be gathered from the Hijack Scenario:

* The Confirmatory DLL present on the potentially vulnerable Hijackable Path is loaded by the Target Binary we get following output on the console stating that the DLL Hijack was successful - DLL Hijack Successful -> DLLName: | DLL Hijack Successful -> [Entry Point Not Found - Manual Analysis Required!]: DLL Hijack Successful -> [Entry Point Not Found]: DLL Hijack Successful (if the Hijack was successful)
* DLL Hijack Unuccessful (if the Hijack was unsuccessful)
* DLL Hijack Successful [Entry Point Not Found - Manual Analysis Required] (if the Entry point was not found but can be successful after manual analysis)
* DLL Hijack Successful [Entry Point Not Found] (if the hijack was successful even after the entry point was not fo[...]

___________________________
@hacking_Attack
@Hacking_Video