Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Popular NPM library hijacked to install password-stealers, miners

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Popular NPM library hijacked to install password-stealers, minersPost Views: 113
Reading Time: 1 Minute
Hackers hijacked the popular UA-Parser-JS NPM library, with millions of downloads a week, to infect Linux and Windows devices with cryptominers and password-stealing trojans in a supply-chain attack.
The UA-Parser-JS library is used to parse a browser’s user agent to identify a visitor’s browser, engine, OS, CPU, and Device type/model.

The library is immensely popular, with millions of downloads a week and over 24 million downloads this month so far. In addition, the library is used in over a thousand other projects, including those by Facebook, Microsoft, Amazon, Instagram, Google, Slack, Mozilla, Discord, Elastic, Intuit, Reddit, and many more well-known companies.
https://www.bleepstatic.com/images/news/security/attacks/n/npms/ua-parser-js/downloads-npm-stat.jpg
UA-Parser-JS project hijacked to install malwareOn October 22nd, a threat actor published malicious versions of the UA-Parser-JS NPM library to install cryptominers and password-stealing trojans on Linux and Windows devices.

According to the developer, his NPM account was hijacked and used to deploy the three malicious versions of the library.

“I noticed something unusual when my email was suddenly flooded by spams from hundreds of websites (maybe so I don’t realize something was up, luckily the effect is quite the contrary),” explained Faisal Salman, the developer of UA-Parser-JS, in a bug report.

“I believe someone was hijacking my npm account and published some compromised packages (0.7.29, 0.8.0, 1.0.0) which will probably install malware as can be seen from the diff here: https://app.renovatebot.com/package-diff?name=ua-parser-js&from=0.7.28&to=1.0.0.”

The affected versions and their patched counterparts are:
Malicious version Fixed version 0.7.29 0.7.30 0.8.0 0.8.1 1.0.0 1.0.1
From copies of the malicious NPMs shared with BleepingComputer by Sonatype, we can better understand the attack.
See Also: Apple Pay with VISA lets hackers force payments on locked iPhones
When the compromised packages are installed on a user’s device, a preinstall.js script will check the type of operating system used on the device and either launch a Linux shell script or a Windows batch file.
https://www.bleepstatic.com/images/news/security/attacks/n/npms/ua-parser-js/check-os.jpg
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Popular NPM library hijacked to install password-stealers, miners https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Popular NPM library hijacked to install password-stealers, minersPost Views:…
tic.com/images/news/security/attacks/n/npms/ua-parser-js/windows-batch.jpg
regsvr32.exe -s create.dllcommand, it will attempt to steal passwords for a wide variety of programs, including FTP clients, VNC, messaging software, email clients, and browsers.

A list of targeted programs can be found in the table below.
WinVNC Firefox FTP Control Screen Saver 9x Apple Safari NetDrive PC Remote Control Remote Desktop Connection Becky ASP.NET Account Cisco VPN Client The Bat! FreeCall GetRight Outlook Vypress Auvis FlashGet/JetCar Eudora CamFrog FAR Manager FTP Gmail Notifier Win9x NetCache Windows/Total Commander Mail.Ru Agent ICQ2003/Lite WS_FTP IncrediMail “&RQ, R&Q” CuteFTP Group Mail Free Yahoo! Messenger FlashFXP PocoMail Digsby FileZilla Forte Agent Odigo FTP Commander Scribe IM2/Messenger 2 BulletProof FTP Client POP Peeper Google Talk SmartFTP Mail Commander Faim TurboFTP Windows Live Mail MySpaceIM FFFTP Mozilla Thunderbird MSN Messenger CoffeeCup FTP SeaMonkey Windows Live Messenger Core FTP Flock Paltalk FTP Explorer Download Master Excite Private Messenger Frigate3 FTP Internet Download Accelerator Gizmo Project SecureFX IEWebCert AIM Pro UltraFXP IEAutoCompletePWs Pandion FTPRush VPN Accounts Trillian Astra WebSitePublisher Miranda 888Poker BitKinex GAIM FullTiltPoker ExpanDrive Pidgin PokerStars Classic FTP QIP.Online TitanPoker Fling JAJC PartyPoker SoftX FTP Client WebCred CakePoker Directory Opus Windows Credentials UBPoker FTP Uploader MuxaSoft Dialer EType Dialer FreeFTP/DirectFTP FlexibleSoft Dialer RAS Passwords LeapFTP Dialer Queen Internet Explorer WinSCP VDialer Chrome 32bit FTP Advanced Dialer Opera WebDrive Windows RAS
See Also: OSINT Tool: Osintgram
In addition to stealing passwords from the above programs, the DLL will execute a PowerShell script to steal passwords from the Windows credential manager, as shown below.
https://www.bleepstatic.com/images/news/security/attacks/n/npms/ua-parser-js/steal-windows-credentials.jpg
What should UA-Parser-JS users do?Due to the widespread impact of this supply-chain attack, it is strongly advised that all users of the UA-Parser-JS library check their projects for malicious software.

This includes checking for the existence of either jsextension.exe (Windows) or jsextension (Linux) and deleting them if they are found.

For Windows users, you should scan your device for a create.dll file and delete it immediately.

While only Windows was infected with a password-stealing Trojan, it is wise for Linux users to also assume their device was fully compromised.

Due to this, all infected Linux and Windows users should also change their passwords, keys, and refresh tokens, as they were likely compromised and sent to the threat actor.

While changing your passwords and access tokens will likely be a huge undertaking, by not doing so, the threat actor can compromise other accounts, including any projects you develop for further supply-chain attacks.
See Also: Hacking stories – Operation Aurora: When China hacked Google Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
tic.com/images/news/security/attacks/n/npms/ua-parser-js/windows-batch.jpg regsvr32.exe -s create.dllcommand, it will attempt to steal passwords for a wide variety of programs, including FTP clients, VNC, messaging software, email clients, and browsers. …
-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-2-90x90.jpg Acer hacked twice in a week by the same threat actor5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif-6-e5d8ed29a830-90x90.jpg Credit card PINs can be guessed even when covering the ATM pad6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/REVIL-headpic-90x90.jpg REvil ransomware shuts down again after Tor sites were hijacked1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/google-chrome-adblocker-uai-1440x900-1-90x90.jpg Malicious Chrome ad blocker injects ads behind the scenes1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/maxresdefault-90x90.jpg Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/abstract_mysterysnail-90x90.jpg Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/apple-iphone-hacking-90x90.jpg Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/Linux-1280x720-1-90x90.jpg FontOnLake malware infects Linux systems2 weeks ago
The post Popular NPM library hijacked to install password-stealers, miners first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Wpscan only working with my VPN turned off

I'm a total noob, so this may be a stupid question, but wpscan is only working when I disconnect from my VPN. That seems like, not ideal. What can I do about this?

And by not working, I mean that I'll try to scan a url, and it will abort the scan and say the website is down. But if I disconnect from my VPN, it'll scan just fine.

submitted by /u/hollstein167
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
VECTR - A Tool That Facilitates Tracking Of Your Red And Blue Team Testing Activities To Measure Detection And Prevention Capabilities Across Different Attack Scenarios
http://www.kitploit.com/2021/10/vectr-tool-that-facilitates-tracking-of.html

___________________________
@hacking_Attack
@Hacking_Video
VECTR documentation can be found here: https://docs.vectr.io (https://docs.vectr.io/)VECTR Community Discord Channel: https://discord.gg/2FRd8zf728VECTR is a tool that facilitates tracking of your red and blue team (https://www.kitploit.com/search/label/Blue%20Team) testing activities to measure detection and prevention capabilities across different attack scenarios. VECTR provides the ability to create assessment groups, which consist of a collection of Campaigns and supporting Test Cases to simulate adversary threats. Campaigns can be broad and span activity across the kill chain, from initial compromise to privilege escalation (https://www.kitploit.com/search/label/Privilege%20Escalation) and lateral movement (https://www.kitploit.com/search/label/Lateral%20Movement) and so on, or can be a narrow in scope to focus on specific detection layers, tools, and infrastructure. VECTR is designed to promote full transparency (https://www.kitploit.com/search/label/Transparency) between offense and defense, encourage training between team members, and improve detection & prevention success rate across the environment.
VECTR is focused on common indicators of attack and behaviors that may be carried out by any number of threat actor groups, with varying objectives and levels of sophistication. VECTR can also be used to replicate the step-by-step TTPs associated with specific groups and malware campaigns, however its primary purpose is to replicate attacker behaviors that span multiple threat actor groups and malware campaigns, past, present and future. VECTR is meant to be used over time with targeted campaigns, iteration, and measurable enhancements to both red team skills and blue team detection capabilities. Ultimately the goal of VECTR is to make a network resilient to all but the most sophisticated adversaries and insider attacks.

___________________________
@hacking_Attack
@Hacking_Video