Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Sam and System Registry Keys
https://cdn-images-1.medium.com/max/755/1*EVYm1nitNFrw51TRZC1F5A.png
Hello and welcome to my article.
I am Idan and I am a penetration tester / red teamer.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Sam and System Registry Keys
https://cdn-images-1.medium.com/max/755/1*EVYm1nitNFrw51TRZC1F5A.png
Hello and welcome to my article.
I am Idan and I am a penetration tester / red teamer.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sam and System Registry Keys
Hello and welcome to my article. I am Idan and I am a penetration tester / red teamer. Also, I am Linux & Infrastructure PT Practitioner in…
Únase a Crypto Canvas y ayude a probar las NFT de Qtum
https://qtumespanol.medium.com/%C3%BAnase-a-crypto-canvas-y-ayude-a-probar-las-nft-de-qtum-4f0bf21bc7ec?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://qtumespanol.medium.com/%C3%BAnase-a-crypto-canvas-y-ayude-a-probar-las-nft-de-qtum-4f0bf21bc7ec?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Únase a Crypto Canvas y ayude a probar las NFT de Qtum
Bienvenido a Qtum Crypto Canvas, que probará la creación de NFT utilizando Qtum Web Wallet. La campaña se extenderá desde el 6 de octubre…
Bienvenido a Qtum Crypto Canvas, que probará la creación de NFT utilizando Qtum Web Wallet. La campaña se extenderá desde el 6 de octubre…Continue reading on Medium » (https://qtumespanol.medium.com/%C3%BAnase-a-crypto-canvas-y-ayude-a-probar-las-nft-de-qtum-4f0bf21bc7ec?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Únase a Crypto Canvas y ayude a probar las NFT de Qtum
Bienvenido a Qtum Crypto Canvas, que probará la creación de NFT utilizando Qtum Web Wallet. La campaña se extenderá desde el 6 de octubre…
I have found a Sensitive information / Debug info bug in Bugcrowd Public program.Continue reading on Medium » (https://medium.com/@srikanthbairi320/hi-iam-srikanth-bairi-1d0a49436afd?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hi, iam Srikanth bairi
I have found a Sensitive information / Debug info bug in Bugcrowd Public program.
hacking: security in practice
Desperately looking for deleted FB profile
My dear friend died a couple weeks ago and his family deleted his Facebook. I'm desperate to view the profile so I can screenshot it just for the memories. Is there a way to do this? If you can help I would be so grateful. Thank you.
submitted by /u/Meco_the_geeko
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Desperately looking for deleted FB profile
My dear friend died a couple weeks ago and his family deleted his Facebook. I'm desperate to view the profile so I can screenshot it just for the memories. Is there a way to do this? If you can help I would be so grateful. Thank you.
submitted by /u/Meco_the_geeko
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Desperately looking for deleted FB profile
My dear friend died a couple weeks ago and his family deleted his Facebook. I'm desperate to view the profile so I can screenshot it just for the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nmap — Network Scanner
https://cdn-images-1.medium.com/max/600/0*ai0SYOPsF_jqNrFJ.png
Nmap is a free open-source network scanning tool. Nmap is used to discover hosts and services on a computer network by sending packets and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Nmap — Network Scanner
https://cdn-images-1.medium.com/max/600/0*ai0SYOPsF_jqNrFJ.png
Nmap is a free open-source network scanning tool. Nmap is used to discover hosts and services on a computer network by sending packets and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nmap - Network Scanning Guide for Beginners
Nmap is a free open-source network scanning tool. Nmap is used to discover hosts and services on a computer network by sending packets and…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Deathnote: 1 — Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/665/0*XH9qpdyj-ijO8zgu.png
HI guys, today today we are going to root a very easy machine from vulnhub called Deathnote. This is a very straight and forward machine…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Deathnote: 1 — Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/665/0*XH9qpdyj-ijO8zgu.png
HI guys, today today we are going to root a very easy machine from vulnhub called Deathnote. This is a very straight and forward machine…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Deathnote: 1 — Vulnhub Walkthrough
HI guys, today today we are going to root a very easy machine from vulnhub called Deathnote. This is a very straight and forward machine…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Symfonos — Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/705/0*dQJ6IjaZ2AxfYIh2.png
Difficulty : Easy
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Symfonos — Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/705/0*dQJ6IjaZ2AxfYIh2.png
Difficulty : Easy
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Symfonos — Vulnhub Walkthrough
Difficulty : Easy
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Evolution of Data.
https://cdn-images-1.medium.com/max/2600/1*PqhSpiLQ5fO8w8tzf3fRiA.jpeg
In today’s date and time data is more important than anything else. It is actually correct to say now that data is more expensive than…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Evolution of Data.
https://cdn-images-1.medium.com/max/2600/1*PqhSpiLQ5fO8w8tzf3fRiA.jpeg
In today’s date and time data is more important than anything else. It is actually correct to say now that data is more expensive than…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Evolution of Data.
In today’s date and time data is more important than anything else. It is actually correct to say now that data is more expensive than…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Google: YouTubers’ accounts hijacked with cookie-stealing malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Google: YouTubers’ accounts hijacked with cookie-stealing malwarePost Views: 115
Reading Time: 1 Minute
Google says YouTube creators have been targeted with password-stealing malware in phishing attacks coordinated by financially motivated threat actors.
Researchers with Google’s Threat Analysis Group (TAG), who first spotted the campaign in late 2019, found that multiple hack-for-hire actors recruited via job ads on Russian-speaking forums were behind these attacks.
The threat actors used social engineering (via fake software landing pages and social media accounts) and phishing emails to infect YouTube creators with information-stealing malware, chosen based on each attacker’s preference. Channels hijacked in pass-the-cookie attacksMalware observed in the attacks includes commodity strains like RedLine, Vidar, Predator The Thief, Nexus stealer, Azorult, Raccoon, Grand Stealer, Vikro Stealer, Masad, and Kantal, as well as open-source ones like AdamantiumThief and leaked tools such as Sorano.
Once delivered on the targets’ systems, the malware was used to steal their credentials and browser cookies which allowed the attackers to hijack the victims’ accounts in pass-the-cookie attacks.
“While the technique has been around for decades, its resurgence as a top security risk could be due to a wider adoption of multi-factor authentication (MFA) making it difficult to conduct abuse, and shifting attacker focus to social engineering tactics,” said Ashley Shen, a TAG Security Engineer.
See Also: Complete Offensive Security and Ethical Hacking Course
“Most of the observed malware was capable of stealing both user passwords and cookies. Some of the samples employed several anti-sandboxing techniques including enlarged files, encrypted archive and download IP cloaking.”
Google identified at least 1,011 domains linked to these attacks and roughly 15,000 actor accounts specifically created for this campaign and used to deliver phishing emails containing links redirecting to malware landing pages to YouTube creators’ business emails.
https://www.bleepstatic.com/images/news/u/1109292/2021/Attack%20flow(1).png
Sold for up to $4,000 on underground marketsA significant number of YouTube channels hijacked in these attacks were later rebranded to impersonate high-profile tech executives or cryptocurrency exchange firms and used for live streaming cryptocurrency scams.
Others were sold on underground account-trading markets, where they’re worth anything between $3 to $4,000, depending on their total number of subscribers.
Shen added that Google’s Threat Analysis Group cut down phishing emails linked to these attacks on Gmail by 99.6% since May 2021. “We blocked 1.6M messages to targets, displayed ~62K Safe Browsing phishing page warnings, blocked 2.4K files, and successfully restored ~4K accounts,” Shen said.
“With increased detection efforts, we’ve observed attackers shifting away from Gmail to other email providers (mostly email.cz, seznam.cz, post.cz and aol.com).”
Google also reported this malicious activity to the FBI for further investigation to protect YouTube users and creators targeted in the campaign.
See Also: Offensive Security Tool: Dalfox See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10[...]
___________________________
@hacking_Attack
@Hacking_Video
Google: YouTubers’ accounts hijacked with cookie-stealing malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Google: YouTubers’ accounts hijacked with cookie-stealing malwarePost Views: 115
Reading Time: 1 Minute
Google says YouTube creators have been targeted with password-stealing malware in phishing attacks coordinated by financially motivated threat actors.
Researchers with Google’s Threat Analysis Group (TAG), who first spotted the campaign in late 2019, found that multiple hack-for-hire actors recruited via job ads on Russian-speaking forums were behind these attacks.
The threat actors used social engineering (via fake software landing pages and social media accounts) and phishing emails to infect YouTube creators with information-stealing malware, chosen based on each attacker’s preference. Channels hijacked in pass-the-cookie attacksMalware observed in the attacks includes commodity strains like RedLine, Vidar, Predator The Thief, Nexus stealer, Azorult, Raccoon, Grand Stealer, Vikro Stealer, Masad, and Kantal, as well as open-source ones like AdamantiumThief and leaked tools such as Sorano.
Once delivered on the targets’ systems, the malware was used to steal their credentials and browser cookies which allowed the attackers to hijack the victims’ accounts in pass-the-cookie attacks.
“While the technique has been around for decades, its resurgence as a top security risk could be due to a wider adoption of multi-factor authentication (MFA) making it difficult to conduct abuse, and shifting attacker focus to social engineering tactics,” said Ashley Shen, a TAG Security Engineer.
See Also: Complete Offensive Security and Ethical Hacking Course
“Most of the observed malware was capable of stealing both user passwords and cookies. Some of the samples employed several anti-sandboxing techniques including enlarged files, encrypted archive and download IP cloaking.”
Google identified at least 1,011 domains linked to these attacks and roughly 15,000 actor accounts specifically created for this campaign and used to deliver phishing emails containing links redirecting to malware landing pages to YouTube creators’ business emails.
https://www.bleepstatic.com/images/news/u/1109292/2021/Attack%20flow(1).png
Sold for up to $4,000 on underground marketsA significant number of YouTube channels hijacked in these attacks were later rebranded to impersonate high-profile tech executives or cryptocurrency exchange firms and used for live streaming cryptocurrency scams.
Others were sold on underground account-trading markets, where they’re worth anything between $3 to $4,000, depending on their total number of subscribers.
Shen added that Google’s Threat Analysis Group cut down phishing emails linked to these attacks on Gmail by 99.6% since May 2021. “We blocked 1.6M messages to targets, displayed ~62K Safe Browsing phishing page warnings, blocked 2.4K files, and successfully restored ~4K accounts,” Shen said.
“With increased detection efforts, we’ve observed attackers shifting away from Gmail to other email providers (mostly email.cz, seznam.cz, post.cz and aol.com).”
Google also reported this malicious activity to the FBI for further investigation to protect YouTube users and creators targeted in the campaign.
See Also: Offensive Security Tool: Dalfox See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Google: YouTubers’ accounts hijacked with cookie-stealing malware | Black Hat Ethical Hacking
Google says YouTube creators have been targeted with password-stealing malware in phishing attacks coordinated by financially motivated threat actors.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Google: YouTubers’ accounts hijacked with cookie-stealing malware https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Google: YouTubers’ accounts hijacked with cookie-stealing malwarePost Views:…
/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
The post Google: YouTubers’ accounts hijacked with cookie-stealing malware first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-1-90x90.jpg Twitch source code and creator payouts part of massive leak2 weeks ago
The post Google: YouTubers’ accounts hijacked with cookie-stealing malware first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video