Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Barnaby Jack

Anyone have any information on what Barnaby Jack was working on in regards to the work he shared with the world? (ATM, pace makers, etc.) who, if anyone has picked up the torch? Was some of the problems he exposed addressed? Any thoughts of his documented regarding voting machines?

submitted by /u/shmidget
[link] [comments]
Complex OPEN REDIRECT Exploitation

Hi readers,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
I NEED A HACKER TO HELP ME CHANGE MY SCHOOL GRADES

CONTACT: QULIOUSHACKER@GMAIL.COM — -IF YOU HAVE HACKING RELATED ISSUES CONCERNING HOW TO HACK AND CHANGE YOUR UNIVERSITY GRADES AND…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HOW TO HIRE A HACKER TO CHANGE MY UNIVERSITY SERVER

CONTACT: QULIOUSHACKER@GMAIL.COM — -IF YOU HAVE HACKING RELATED ISSUES CONCERNING HOW TO HACK AND CHANGE YOUR UNIVERSITY GRADES AND…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
I NEED A HACKER TO CHANGE MY UNIVERSITY TRANSCRIPT

CONTACT: QULIOUSHACKER@GMAIL.COM — -IF YOU HAVE HACKING RELATED ISSUES CONCERNING HOW TO HACK AND CHANGE YOUR UNIVERSITY GRADES AND…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
Pentest e Fases de um Pentest

https://cdn-images-1.medium.com/max/600/0*1OKAyMd_Ri3hd3FO.gif
Boa noite família, a um tempo atrás eu estava me aprofundando em termologias e na teoria de um teste de penetração ( ͡° ͜ʖ ͡°), ai eu…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Insurance Giant CNA Hit with Novel Ransomware Attack

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Insurance Giant CNA Hit with Novel Ransomware AttackPost Views: 25
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
A novel ransomware attack forced insurance giant CNA to take systems offline and temporarily shutter its website. The attack leveraged a new variant of the Phoenix CryptoLocker malware.
The Chicago-based company—the seventh largest commercial insurance provider in the world—said it “sustained a sophisticated cybersecurity attack” on Sunday, March 21, according to a statement on the home page of its website. The statement is the only functionality the company’s site currently maintains.

“The attack caused a network disruption and impacted certain CNA systems, including corporate email,” according to the statement.

Though the company did not elaborate on the nature of the attack, a report in BleepingComputer said CNA was the victim of a new ransomware called Phoenix CryptoLocker. Cryptolockers are an oft-used type of ransomware that immediately encrypt files on the machines they attack and demand a ransom from the victims in exchange for the key to unlocking them.

Moreover, the threat actors behind Phoenix CryptoLocker are likely known entities–the cybercrime group Evil Corp, which recently resurfaced after taking a short hiatus from cybercriminal activity, according to the report.
See Also: Microsoft Offers Up To $30K For Teams Bugs
The impact of the group’s latest attack was so serious that CNA disconnected its systems from its network “out of an abundance of caution” and is currently providing workarounds for employees where possible so the company can continue operating to serve its customers, the company said.

Sources familiar with the attack have told BleepingComputer that threat actors encrypted more than 15,000 devices on CNA’s network—including those of employees working remotely who were logged onto the company’s VPN at the time—when they deployed the new ransomware on Sunday, according to the report.

Attackers encrypted devices by appending the .phoenix extension to encrypted files and creating a ransom note named PHOENIX-HELP.txt, according to BleepingComputer.

Evil Corp has been in the crosshairs of U.S. authorities since 2019, when they offered up $5 million for information leading to the arrest of Evil Corp leader Maksim V. Yakubets, 32, of Russia, who goes under the moniker “aqua” and is known for leading a lavish lifestyle.

Indeed, the cybercrime group has reaped millions from various nefarious activities, which previously included capturing banking credentials with the Dridex banking trojan and then making unauthorized electronic funds transfers from unknowing victims’ bank accounts.
See Also: Information Security Tool: Chameleon Sources believe that Phoenix Cryptolocker is a product of Evil Corp based on similarities in the code to previous ransomware used by the group, according to the report. In previous ransomware attacks—such as one against GPS technology provider Garmin last year–Evil Corp used WastedLocker ransomware to encrypt victims’ files.

CNA aims to restore its systems using backup rather than pay the ransom demanded by attackers, according to BleepingComputer. The company is currently in the midst of an ongoing investigation into the incident that started immediately after its discovery, the company said.

“We have alerted law enforcement and will be cooperating with them as they conduct their own investigation,” the c[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Insurance Giant CNA Hit with Novel Ransomware Attack https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Insurance Giant CNA Hit with Novel Ransomware AttackPost Views: 25 style…
ompany said.

CNA is unaware at this time if the incident impacted any customer data, but will notify parties directly if this is found to be the case, according to the statement. See Also: Hacking Stories: Albert Gonzalez & the ‘Get Rich or Die Trying’ Crew who stole 130 million credit-card numbersCNA also did not give a timeline for when its website and systems will be up and running in a fully operational way again. In the meantime, the company posted specific directions on its website for how its customers should contact the company during the time of disruption based on their various needs.Source: https://threatpost.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Microsoft-Teams-90x90.jpg Microsoft Offers Up To $30K For Teams Bugs3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/thrive-themes-1030x391-1-90x90.png Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/HL-color-90x90.jpg Hobby Lobby Exposes Customer Data in Cloud Misconfiguration5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/adobe_coldfusion-700x412-e1542041238507-90x90.jpg Adobe Fixes Critical ColdFusion Flaw in Emergency Update6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Clubhouse-e1614022265127-90x90.jpg Bogus Android Clubhouse App Drops Credential-Swiping Malware7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/apple-security-90x90.jpg Trojanized Xcode Project Slips MacOS Malware to Apple Developers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Cisco_Systems_Sign-90x90.jpg Cisco Plugs Security Hole in Small Business Routers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/JPG-Malicious-Two-90x90.jpg Magecart Attackers Save Stolen Credit-Card Data in JPG Files2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Google-Chrome-Browser-1-90x90.jpg Google Warns Mac, Windows Users of Chrome Zero-Day Flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/internet-of-things-90x90.jpg Critical Security Hole Can Knock Smart Meters Offline2 weeks ago
The post Insurance Giant CNA Hit with Novel Ransomware Attack first appeared on Black Hat Ethical Hacking.
hacking: security in practice
How to reset terminator terminal emulator?

My terminal is so messed up (alt + tab) is not working, and few other preferences are messed up too. I tried " mv $HOME/ .config/terminator $HOME/ .config/terminator_old" But didn't work. I just wanted to erase all my previous changes I've made before.

submitted by /u/jacklsd
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Wordlists for Pentester

A Pentester is as good as their tools and when it comes to cracking the password, stressing authentication panels or even a simple directory Bruteforce it all drills down to the wordlists that you use. Today we are going to understand wordlists, look around for some good wordlists, run some tools to manage the wordlists, and much more.

<o:p Table of Contents<o:p· Introduction<o:p· What are Wordlists?<o:p· Built-in Wordlists<o:po Kali Linux Wordlists<o:p

o Dirb Wordlists<o:p

o Rockyou Wordlist<o:p

o Wfuzz Wordlists<o:p

· Online Wordlists<o:po GitHub Wordlists<o:p

o Seclists Wordlists<o:p

o Assetnode Wordlists<o:p

o Packet Strom Wordlists<o:p

· Cleaning Wordlists<o:p· Crafting Wordlists<o:po CeWL<o:p

o Crunch<o:p

o Cupp<o:p

o Pydictor<o:p

o Bopscrk<o:p

o BEWCor<o:p

o Dymerge<o:p

o Mentalist<o:p

· Conclusion <o:pIntroduction<o:pEver since the evolution of Penetration Testers has begun, one of the things we constantly see is that the attacker cracks the password of the target and gets in! Well in most of the depictions of the attacks in movies and series often show this situation in detail as it is the simplest attack to depict. No matter how simple cracking passwords or performing Credential Stuffing were once a bane on the Web Applications. Today we somehow have got a bit of control over them with the use of CAPTCHA or Rate Limiting but still, they are one of the effective attacks. The soul of such attacks is the wordlist. <o:p What are Wordlists?<o:pA wordlist is a file (a text file in most cases but not limited to it) that contains a set of values that the attacker requires to provide to test a mechanism. This is a bit complex, let's dilute it a bit to understand better. Whenever an attacker is faced with an Authentication Mechanism, they can try to work around it but if that is not possible then the attacker has to try some well-known credentials into the Authentication Mechanism to try and guess. This list of well know credentials is a wordlist. And instead of manually entering the values one by one, the attacker uses a tool or script to automate this process. Similarly, in the case of cracking hash values, the tool uses the wordlists and encodes the entries of wordlists into the same hash and then uses a string compare function to match the hashes. If a match is found then the hash is deemed as cracked. It can be observed that the importance of wordlist is paramount in the Cyber Security World.<o:p Wordlists in Kali Linux<o:pSince Kali Linux was specially crafted to perform Penetration Testing, it is full of various kinds of wordlists. This is because of the various tools that are present in the Kali Linux to perform Bruteforce Attacks on Logins, Directories, etc. Let’s go through some of the wordlists from the huge arsenal of wordlists Kali Linux contain.<o:p

Wordlists are located inside the /usr/share directory. Here, we have the dirb directory for the wordlists to be used while using the dirb tool to perform Directory Bruteforce. Then we have the dirbuster that is a similar tool that also performs Directory Bruteforce but with some additional options. Then we have a fern-wifi directory which helps to break the Wi-Fi Authentications. Then we have the Metasploit which uses wordlists for almost everything. Then there is a nmap wordlist that contains that can be used while scanning some specific services. Then we have the Rockstar of Wordlists: rockyou. This is compressed by default and you will have to extract it before using it. It is very large with 1,44,42,062 values that could be passwords for a lot of user accounts on the internet.[...]