Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
(ISC)² Plans Entry-Level Certification for Aspiring Security Pros

The certification aims to help new entrants to the security field with professional development and career paths early on.
Dark Reading: Attacks/Breaches
Loss Prevention Teams Up With Cybersecurity to Address Retail Fraud

As retailers roll out more "buy online, pickup in-store" options, loss prevention professionals are increasingly shifting their attention from in-store theft to e-commerce fraud.
Dark Reading: Attacks/Breaches
Group With Potential Links to Iranian Threat Actor Resurfaces

The Lyceum group has previously been linked to attacks on targets in the Middle East.
hacking: security in practice
IRC’s

So I’ve never used IRC’s before and I see they can be pretty involved just to enter a room. Does anyone have tips or clients that are beginner friendly, and active enough that I would be able to talk/learn more about hacking and cyber security?

submitted by /u/KingA1mighty
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
DNS not showing in ARP poisoning attack

I am able to perform on ARP poisoning attack using a metasploit module on another computer on my LAN, and using wireshark I can see traffic from my target going to my device, and I can confirm that it’s ARP table is poisoned, but I’m forwarding its packets correctly. I can also see (most, no really all for some reason) the DNS requests from the target. However, when targeting my iOS phone, I see no DNS requests. Why is it not using the router (or what it thinks is the router) for DNS? And how would I force it to do so without literally going in and changing its dns server setting? Or if I can’t, is there a way I could drop packets and force it to make another handshake, capture the handshake, and then resume packet forwarding and decrypt dns? Would that even work? I’m obviously confused and would love if someone could basically explain how to make an ARP poisoning useful for seeing at least dns. Many thanks in advance.

submitted by /u/MeltedChocolate24
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Credit card PINs can be guessed even when covering the ATM pad

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Credit card PINs can be guessed even when covering the ATM padPost Views: 145
Reading Time: 1 Minute
Researchers have proven it’s possible to train a special-purpose deep-learning algorithm that can guess 4-digit card PINs 41% of the time, even if the victim is covering the pad with their hands.
The attack requires the setting up of a replica of the target ATM because training the algorithm for the specific dimensions and key spacing of the different PIN pads is crucially important.

Next, the machine-learning model is trained to recognize pad presses and assign specific probabilities on a set of guesses, using video of people typing PINs on the ATM pad.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/pin_attack.jpg
CountermeasuresThis experiment proves that covering the PIN pad with the other hand is not sufficient to defend against deep learning-based attacks, but thankfully, there are some countermeasures you can deploy.

* First, if your bank gives you the option to choose a 5-digit PIN instead of a 4-digit one, pick the longer one. It may be harder to remember, but it is a lot safer against attacks of this kind.
* Secondly, the percentage of the hand coverage is significantly lowering the prediction accuracy. A coverage percentage of 75% gives an accuracy of 0.55 for each try, while a total coverage (100%) takes the accuracy down to 0.33.
* A third countermeasure would be to serve users with a virtual and randomized keypad instead of the standardized mechanical one. This inevitably comes with usability drawbacks, but it’s an excellent security measure.

Interestingly, the researchers used the experiment’s video clips on a survey with 78 participants to determine if humans could also guess the concealed P[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Credit card PINs can be guessed even when covering the ATM pad https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Credit card PINs can be guessed even when covering the ATM padPost Views: 145…
INs and up to what point.

On average, the survey participants answered with an accuracy of only 7.92%, which is inefficient for carrying out attacks of this type.
See Also: Offensive Security Tool: Dalfox See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Apache-web-server-90x90.png Apache fixes actively exploited zero-day vulnerability, patch now2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/security-breach-freepik-90x90.jpg Encrypted & Fileless Malware Sees Big Growth2 weeks ago
The post Credit card PINs can be guessed even when covering the ATM pad first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
7 Cross-Industry Technology Trends That Will Disrupt the World

Recent McKinsey & Company analysis examines which technologies will have the most momentum in the next ten years. These are the trends security teams need to be aware of in order to protect the organization effectively.