Dinosaur Eggs × Immunefi $50,000 Bug Bounty Program
https://medium.com/@dinosaureggs/dinosaur-eggs-immunefi-50-000-bug-bounty-program-caa619e77e45?source=rss------bug_bounty-5
https://medium.com/@dinosaureggs/dinosaur-eggs-immunefi-50-000-bug-bounty-program-caa619e77e45?source=rss------bug_bounty-5
Dinosaur Eggs is offering a $50,000 bug bounty with ImmunefiContinue reading on Medium » (https://medium.com/@dinosaureggs/dinosaur-eggs-immunefi-50-000-bug-bounty-program-caa619e77e45?source=rss------bug_bounty-5)
Dinosaur Eggs × Immunefi $50,000 Bug Bounty Program
Dinosaur Eggs is offering a $50,000 bug bounty with ImmunefiContinue reading on Medium »
Read more...
Dinosaur Eggs is offering a $50,000 bug bounty with ImmunefiContinue reading on Medium »
Read more...
hacking: security in practice
How To Factory Reset Computer?
I have tried everything I can think of to do a systemreset and wipe my computer. Currently, my administrator has disabled it. I tried the normal method in windows settings, I tried writing a script that runs most apps without admin (systemreset says a problem occured when i run it with the script), I tried holding shift while restarting and the option to systemreset has been removed (the only options left in the screen that shows up are boot from UEFI and boot from removeable media). I don't know how to reset my computer now, and it has not been working correctly. I also need to access some things that have been blocked by the admin, but they will be unblocked when I reset. Can anyone help?
submitted by /u/R4ndomP3rson69
[link] [comments]
How To Factory Reset Computer?
I have tried everything I can think of to do a systemreset and wipe my computer. Currently, my administrator has disabled it. I tried the normal method in windows settings, I tried writing a script that runs most apps without admin (systemreset says a problem occured when i run it with the script), I tried holding shift while restarting and the option to systemreset has been removed (the only options left in the screen that shows up are boot from UEFI and boot from removeable media). I don't know how to reset my computer now, and it has not been working correctly. I also need to access some things that have been blocked by the admin, but they will be unblocked when I reset. Can anyone help?
submitted by /u/R4ndomP3rson69
[link] [comments]
reddit
How To Factory Reset Computer?
I have tried everything I can think of to do a systemreset and wipe my computer. Currently, my administrator has disabled it. I tried the normal...
hacking: security in practice
Best way to crack a (semi) random password?
So I forgot an important password. I know it is 8-12 digits (I didn't want it to be too long so it would be possible to bruteforce - I hope I leaned to 8 or 9 digits so its easier but I forget). I know it is definitely NOT any recognizable English words or any variation. It is completely random text to the eye. Uppercase, lowercase and digits allowed (it may have symbols too - I cant remember but probably not).
Can I implement some sort of reverse wordlist? I know it definitely ISNT any recognizable English words so no need to check any of them.
What software would best assist me with this task? The password in mind controls a BitLocker drive. I figure finding the password is way more likely than figuring out the recovery key. (though I actually did recover the recovery key file - it just has garbled content - see https://www.reddit.com/r/BitLocker/comments/qd8b1p/recovery_key_file_corrupted/)
I know for most intents and purposes, I'm fucked. But I want to give it a shot at least
submitted by /u/TheSinfulKing
[link] [comments]
Best way to crack a (semi) random password?
So I forgot an important password. I know it is 8-12 digits (I didn't want it to be too long so it would be possible to bruteforce - I hope I leaned to 8 or 9 digits so its easier but I forget). I know it is definitely NOT any recognizable English words or any variation. It is completely random text to the eye. Uppercase, lowercase and digits allowed (it may have symbols too - I cant remember but probably not).
Can I implement some sort of reverse wordlist? I know it definitely ISNT any recognizable English words so no need to check any of them.
What software would best assist me with this task? The password in mind controls a BitLocker drive. I figure finding the password is way more likely than figuring out the recovery key. (though I actually did recover the recovery key file - it just has garbled content - see https://www.reddit.com/r/BitLocker/comments/qd8b1p/recovery_key_file_corrupted/)
I know for most intents and purposes, I'm fucked. But I want to give it a shot at least
submitted by /u/TheSinfulKing
[link] [comments]
reddit
Best way to crack a (semi) random password?
So I forgot an important password. I know it is 8-12 digits (I didn't want it to be too long so it would be possible to bruteforce - I hope I...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Identify Your Phone Is Hacked
https://cdn-images-1.medium.com/max/600/1*pDqL_hq11nBvKqsN6Xa8mw.jpeg
This article has been published on the Tumblr website.
Continue reading on Medium »
How To Identify Your Phone Is Hacked
https://cdn-images-1.medium.com/max/600/1*pDqL_hq11nBvKqsN6Xa8mw.jpeg
This article has been published on the Tumblr website.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Advanced Persistent Threat?
https://cdn-images-1.medium.com/max/600/0*YV3M5PT-TA6TIooc
Multi-phase attacks on a company’s network are known as an advanced persistent threat (APT). They’re known for taking a “long game”…
Continue reading on rootissh »
What is Advanced Persistent Threat?
https://cdn-images-1.medium.com/max/600/0*YV3M5PT-TA6TIooc
Multi-phase attacks on a company’s network are known as an advanced persistent threat (APT). They’re known for taking a “long game”…
Continue reading on rootissh »
👏We are glad to announce that Kinglive’s Bug Bounty campaign has successfully ended and found no major bugs with all functions. It proves…Continue reading on Kingdom Game 4.0 » (https://medium.com/kingdom-game-4-0/-5fa603b6b36b?source=rss------bug_bounty-5)
: ’ …
👏We are glad to announce that Kinglive’s Bug Bounty campaign has successfully ended and found no major bugs with all functions. It proves…Continue reading on Kingdom Game 4.0 »
Read more...
👏We are glad to announce that Kinglive’s Bug Bounty campaign has successfully ended and found no major bugs with all functions. It proves…Continue reading on Kingdom Game 4.0 »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Massive campaign uses YouTube to push password-stealing malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Massive campaign uses YouTube to push password-stealing malwarePost Views: 142
Reading Time: 1 Minute
Widespread malware campaigns are creating YouTube videos to distribute password-stealing trojans to unsuspecting viewers.
Password stealing trojans are malware that quietly runs on a computer while stealing passwords, screenshots of active windows, cookies, credit cards stored in browsers, FTP credentials, and arbitrary files decided by the threat actors.
When installed, the malware will communicate with a Command & Control server, where it waits for commands to execute by the attacker, which could entail the running of additional malware. Malicious YouTube videos gone wildThreat actors have long used YouTube videos as a way to distribute malware through embedded links in video descriptions.
However, this week has Cluster25 security researcher Frost told BleepingComputer that there has been a significant uptick in malware campaigns on YouTube pushing various password-stealing Trojans.
Frost told BleepingComputer that it is likely two clusters of malicious activity being conducted simultaneously – one pushing the RedLine malware and the other pushing Racoon Stealer.
See Also: Complete Offensive Security and Ethical Hacking Course
The researcher said that thousands of videos and channels had been made as part of this massive malware campaign, with 100 new videos and 81 channels created in just twenty minutes.
Frost explained that the threat actors use the Google accounts they steal to launch new YouTube channels to spread malware, creating a never-ending and ever-growing cycle.
“The threat actors have thousands of new channels available because they infect new clients every day. As part of these attacks, they steal victim’s Google credentials, which are then used to create new YouTube Videos to distribute the malware,” Frost told BleepingComputer.
The attacks start with the threat actors creating numerous YouTube channels filled with videos about software cracks, licenses, how-to guides, cryptocurrency, mining, game cheats, VPN software, and pretty much any other popular category.
https://www.bleepstatic.com/images/news/malware/p/youtube-password-stealing-trojans/youtube-profile.jpg
<figcaptionExample of a malicious YouTube channel
See Also: Apple Pay with VISA lets hackers force payments on locked iPhones
These videos contain content that explains how to perform a task using a specific program or utility. Additionally, the YouTube video’s description includes an alleged link to the associated tool used to distribute the malware.
https://www.bleepstatic.com/images/news/malware/p/youtube-password-stealing-trojans/phasmophobia-.jpg
<figcaptionMalicious YouTube video pushing RedLine stealer
If a video contains a bit.ly link, it will lead to another file-sharing site hosting the RedLine password-stealing malware infection. However, if it includes an unshortened domain, it will redirect to a page on the taplink[.]cc domain to push Racoon Stealer, as shown below.
https://www.bleepstatic.com/images/news/malware/p/youtube-password-stealing-trojans/racgoon-landing.jpg
<figcaptionLanding page for the Racoon Stealer Once a user becomes infected, the malware will proceed to scan all installed browsers and the computer for cryptocurrency wallets, credit cards, passwords, and other data and upload it back to the attacker.
Google told BleepingComputer that they are aware of the campaign and are taking action to disrupt the activity.
“We are aware o[...]
Massive campaign uses YouTube to push password-stealing malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Massive campaign uses YouTube to push password-stealing malwarePost Views: 142
Reading Time: 1 Minute
Widespread malware campaigns are creating YouTube videos to distribute password-stealing trojans to unsuspecting viewers.
Password stealing trojans are malware that quietly runs on a computer while stealing passwords, screenshots of active windows, cookies, credit cards stored in browsers, FTP credentials, and arbitrary files decided by the threat actors.
When installed, the malware will communicate with a Command & Control server, where it waits for commands to execute by the attacker, which could entail the running of additional malware. Malicious YouTube videos gone wildThreat actors have long used YouTube videos as a way to distribute malware through embedded links in video descriptions.
However, this week has Cluster25 security researcher Frost told BleepingComputer that there has been a significant uptick in malware campaigns on YouTube pushing various password-stealing Trojans.
Frost told BleepingComputer that it is likely two clusters of malicious activity being conducted simultaneously – one pushing the RedLine malware and the other pushing Racoon Stealer.
See Also: Complete Offensive Security and Ethical Hacking Course
The researcher said that thousands of videos and channels had been made as part of this massive malware campaign, with 100 new videos and 81 channels created in just twenty minutes.
Frost explained that the threat actors use the Google accounts they steal to launch new YouTube channels to spread malware, creating a never-ending and ever-growing cycle.
“The threat actors have thousands of new channels available because they infect new clients every day. As part of these attacks, they steal victim’s Google credentials, which are then used to create new YouTube Videos to distribute the malware,” Frost told BleepingComputer.
The attacks start with the threat actors creating numerous YouTube channels filled with videos about software cracks, licenses, how-to guides, cryptocurrency, mining, game cheats, VPN software, and pretty much any other popular category.
https://www.bleepstatic.com/images/news/malware/p/youtube-password-stealing-trojans/youtube-profile.jpg
<figcaptionExample of a malicious YouTube channel
See Also: Apple Pay with VISA lets hackers force payments on locked iPhones
These videos contain content that explains how to perform a task using a specific program or utility. Additionally, the YouTube video’s description includes an alleged link to the associated tool used to distribute the malware.
https://www.bleepstatic.com/images/news/malware/p/youtube-password-stealing-trojans/phasmophobia-.jpg
<figcaptionMalicious YouTube video pushing RedLine stealer
If a video contains a bit.ly link, it will lead to another file-sharing site hosting the RedLine password-stealing malware infection. However, if it includes an unshortened domain, it will redirect to a page on the taplink[.]cc domain to push Racoon Stealer, as shown below.
https://www.bleepstatic.com/images/news/malware/p/youtube-password-stealing-trojans/racgoon-landing.jpg
<figcaptionLanding page for the Racoon Stealer Once a user becomes infected, the malware will proceed to scan all installed browsers and the computer for cryptocurrency wallets, credit cards, passwords, and other data and upload it back to the attacker.
Google told BleepingComputer that they are aware of the campaign and are taking action to disrupt the activity.
“We are aware o[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Massive campaign uses YouTube to push password-stealing malware https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Massive campaign uses YouTube to push password-stealing malwarePost Views:…
f this campaign and are currently taking action to block activity by this threat actor and flagging all links to Safe Browsing. As always, we are continuously improving our detection methods and investing in new tools and features that automatically identify and stop threats like this one. It is also important that users remain aware of these types of threats and take appropriate action to further protect themselves.” – Google.
Google also disclosed this week a phishing campaign that distributed password-stealing trojans used to steal the accounts of YouTube Creators. These accounts were then sold on dark web markets or used to perform cryptocurrency scams.
See Also: Offensive Security Tool: Dalfox These campaigns illustrate how important it is not to download programs from the Internet haphazardly, as sites like YouTube can not vet every link added by video publishers.
Therefore, a user should research a site before downloading and installing anything from it to determine if they have a good reputation and can be trusted. Even then, it is always suggested that you first upload the program to a site like VirusTotal to confirm if it’s safe to run.
If you have accidentally fallen for this attack and installed a program from a similar link, it is strongly suggested that you scan your computer with an antivirus program.
After you have removed any malware detected in a virus scan, you should immediately change any passwords saved in your browsers.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users2 weeks ago
The post Massive campaign uses YouTube to push password-stealing malware first appeared on Black Hat Ethical Hacking.
Google also disclosed this week a phishing campaign that distributed password-stealing trojans used to steal the accounts of YouTube Creators. These accounts were then sold on dark web markets or used to perform cryptocurrency scams.
See Also: Offensive Security Tool: Dalfox These campaigns illustrate how important it is not to download programs from the Internet haphazardly, as sites like YouTube can not vet every link added by video publishers.
Therefore, a user should research a site before downloading and installing anything from it to determine if they have a good reputation and can be trusted. Even then, it is always suggested that you first upload the program to a site like VirusTotal to confirm if it’s safe to run.
If you have accidentally fallen for this attack and installed a program from a similar link, it is strongly suggested that you scan your computer with an antivirus program.
After you have removed any malware detected in a virus scan, you should immediately change any passwords saved in your browsers.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/excel-header-90x90.jpg Microsoft is disabling Excel 4.0 macros by default to protect users2 weeks ago
The post Massive campaign uses YouTube to push password-stealing malware first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is it possible to change the IMSI of an R-SIM-13 simcard from an Andorid phone?
Hello everyone, I want to tell you about a recent problem, I bought an iphone xs max (AT&T) cell phone in the US, however, I brought it to my native country. As expected, AT&T service denied me unlocking the cell phone network.
Due to this, I was forced to buy an R-SIM-13, however, when I arrived I realized that this version of R-SIM does not work with the 14.8 or 15 version of ios, due to security changes of the device cannot change ICCID.
After so much trying I was able to change the ICCID from an andorid, however the R-SIM page also recommends changing the IMSI of the R-SIM-13 to the number 311580112345678.
So there my question arises, is it possible to change the IMSI from an andorid phone?
I appreciate any help. (sorry my bad English)
submitted by /u/TakenCOL
[link] [comments]
Is it possible to change the IMSI of an R-SIM-13 simcard from an Andorid phone?
Hello everyone, I want to tell you about a recent problem, I bought an iphone xs max (AT&T) cell phone in the US, however, I brought it to my native country. As expected, AT&T service denied me unlocking the cell phone network.
Due to this, I was forced to buy an R-SIM-13, however, when I arrived I realized that this version of R-SIM does not work with the 14.8 or 15 version of ios, due to security changes of the device cannot change ICCID.
After so much trying I was able to change the ICCID from an andorid, however the R-SIM page also recommends changing the IMSI of the R-SIM-13 to the number 311580112345678.
So there my question arises, is it possible to change the IMSI from an andorid phone?
I appreciate any help. (sorry my bad English)
submitted by /u/TakenCOL
[link] [comments]
reddit
Is it possible to change the IMSI of an R-SIM-13 simcard from an...
Hello everyone, I want to tell you about a recent problem, I bought an iphone xs max (AT&T) cell phone in the US, however, I brought it to my...