Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Microsoft certifica un malware como driver legítimo por segunda vez en cuatro meses
https://cdn-images-1.medium.com/max/1589/0*hpkL0Ygm-wfUbYHP
PUBLICADO EN 1 NOVIEMBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Microsoft certifica un malware como driver legítimo por segunda vez en cuatro meses
https://cdn-images-1.medium.com/max/1589/0*hpkL0Ygm-wfUbYHP
PUBLICADO EN 1 NOVIEMBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft certifica un malware como driver legítimo por segunda vez en cuatro meses
PUBLICADO EN 1 NOVIEMBRE, 2021POR EHACKING
CHFRY X Immunefi: Bug Hunt Begins!
Attention, attention! Calling all white hat hackers out there!Continue reading on Medium »
Read more...
Attention, attention! Calling all white hat hackers out there!Continue reading on Medium »
Read more...
CHFRY X Immunefi: Bug Hunt Begins!
https://medium.com/@chfry_finance/chfry-x-immunefi-bug-hunt-begins-18ed12de047f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@chfry_finance/chfry-x-immunefi-bug-hunt-begins-18ed12de047f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CHFRY X Immunefi: Bug Hunt Begins!
Attention, attention! Calling all white hat hackers out there!
Attention, attention! Calling all white hat hackers out there!Continue reading on Medium » (https://medium.com/@chfry_finance/chfry-x-immunefi-bug-hunt-begins-18ed12de047f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CHFRY X Immunefi: Bug Hunt Begins!
Attention, attention! Calling all white hat hackers out there!
Stored XSS In Cari-Kos.com
Halo, perkenalkan nama saya Salman Rai Apriliana. Pada kesempatan kali ini saya ingin membagikan temuan celah Stored XSS di web…Continue reading on Medium »
Read more...
Halo, perkenalkan nama saya Salman Rai Apriliana. Pada kesempatan kali ini saya ingin membagikan temuan celah Stored XSS di web…Continue reading on Medium »
Read more...
Stored XSS In Cari-Kos.com
https://imhecate1337.medium.com/stored-xss-in-cari-kos-com-a615f8bd8057?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://imhecate1337.medium.com/stored-xss-in-cari-kos-com-a615f8bd8057?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Stored XSS In Cari Kos
Halo, perkenalkan nama saya Salman Rai Apriliana. Pada kesempatan kali ini saya ingin membagikan temuan celah Stored XSS di web…
Halo, perkenalkan nama saya Salman Rai Apriliana. Pada kesempatan kali ini saya ingin membagikan temuan celah Stored XSS di web…Continue reading on Medium » (https://imhecate1337.medium.com/stored-xss-in-cari-kos-com-a615f8bd8057?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Stored XSS In Cari Kos
Halo, perkenalkan nama saya Salman Rai Apriliana. Pada kesempatan kali ini saya ingin membagikan temuan celah Stored XSS di web…
hacking: security in practice
Yall I feel bad
I got in an argument and posted a grabify link for the first time for me and things started flooding in like a view a secound I check everything and it's the same guy that keeps getting redirected to his own Twitter page
submitted by /u/JaysonAnimations
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Yall I feel bad
I got in an argument and posted a grabify link for the first time for me and things started flooding in like a view a secound I check everything and it's the same guy that keeps getting redirected to his own Twitter page
submitted by /u/JaysonAnimations
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Yall I feel bad
I got in an argument and posted a grabify link for the first time for me and things started flooding in like a view a secound I check everything...
Deep Web
Do I need a VPN when I’m using tails?
submitted by /u/gvnsvn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Do I need a VPN when I’m using tails?
submitted by /u/gvnsvn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Do I need a VPN when I’m using tails?
Posted in r/deepweb by u/gvnsvn • 1 point and 1 comment
Deep Web
Dɛɛpwɛв
https://external-preview.redd.it/Ev9MYaozaebPQE5-4ba-_RRTlhSUQF015ptadiUFIvU.jpg?width=320&crop=smart&auto=webp&s=348e396d32e93fd2b72bfe4ec318cb6555046aaf submitted by /u/XAZAY
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Dɛɛpwɛв
https://external-preview.redd.it/Ev9MYaozaebPQE5-4ba-_RRTlhSUQF015ptadiUFIvU.jpg?width=320&crop=smart&auto=webp&s=348e396d32e93fd2b72bfe4ec318cb6555046aaf submitted by /u/XAZAY
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dɛɛpwɛв
Posted in r/deepweb by u/XAZAY • 0 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PWNING Mr. Robot
https://cdn-images-1.medium.com/max/1280/1*dzjMgBa9GBhNY9TlDmBXcg.png
This is a walkthrough for the Mr. Robot CTF machine on TryHackMe. I am using Kali Linux, however, the TryHackMe Attack Box has the tools I…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PWNING Mr. Robot
https://cdn-images-1.medium.com/max/1280/1*dzjMgBa9GBhNY9TlDmBXcg.png
This is a walkthrough for the Mr. Robot CTF machine on TryHackMe. I am using Kali Linux, however, the TryHackMe Attack Box has the tools I…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PWNING Mr. Robot
This is a walkthrough for the Mr. Robot CTF machine on TryHackMe. I am using Kali Linux, however, the TryHackMe Attack Box has the tools I…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Free CompTIA Security+ (SY0-601) Self-study Resources with PBQs
Hi Hacking community,
We have new updates and fixes on the CompTIA Security+ (SY0-601) path, which you might find useful.
It's absolutely free to enroll.
https://examsdigest.com/comptia-learning-path/
Changelog.
[improve] Domain 2.0 Architecture and Design
[improve] Domain 3.0 Operations and Incident Response
[add] Performance-based questions
Happy learning,
Anastasia
submitted by /u/Anastasia_IT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Free CompTIA Security+ (SY0-601) Self-study Resources with PBQs
Hi Hacking community,
We have new updates and fixes on the CompTIA Security+ (SY0-601) path, which you might find useful.
It's absolutely free to enroll.
https://examsdigest.com/comptia-learning-path/
Changelog.
[improve] Domain 2.0 Architecture and Design
[improve] Domain 3.0 Operations and Incident Response
[add] Performance-based questions
Happy learning,
Anastasia
submitted by /u/Anastasia_IT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Free CompTIA Security+ (SY0-601) Self-study Resources with PBQs
Hi Hacking community, We have new updates and fixes on the **CompTIA Security+ (SY0-601)** path, which you might find useful. ***It's...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe Alfred Writeup/Walkthrough
https://cdn-images-1.medium.com/max/1146/1*831yQqVjl-6CF5N2cKYTAQ.png
Hello and welcome to my Alfred walkthrough. This TryHackMe room has plenty of interesting content to cover and provides some solid…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe Alfred Writeup/Walkthrough
https://cdn-images-1.medium.com/max/1146/1*831yQqVjl-6CF5N2cKYTAQ.png
Hello and welcome to my Alfred walkthrough. This TryHackMe room has plenty of interesting content to cover and provides some solid…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe Alfred Writeup/Walkthrough
Hello and welcome to my Alfred walkthrough. This TryHackMe room has plenty of interesting content to cover and provides some solid practice…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
‘Trojan Source’ attack method can hide bugs into open-source code
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png ‘Trojan Source’ attack method can hide bugs into open-source codePost Views: 134
Reading Time: 2 Minutes
Academic researchers have released details about a new attack method they call “Trojan Source” that allows injecting vulnerabilities into the source code of a software project in a way that human reviewers can’t detect.
Trojan Source relies on a simple trick that does not require modifying the compiler to create vulnerable binaries.
The method works with some of the most widely used programming languages today and adversaries could use it for supply-chain attacks. Abusing text-encoding standardsResearchers from the University of Cambridge, United Kingdom, disclosed and demonstrated the “Trojan Source” class of attacks that could compromise first-party software and supply chains.
The examples they provide are for projects written in C, C++, C#, JavaScript, Java, Rust, Go, and Python where an attacker can target the encoding of source code files to inject vulnerabilities.
“The trick is to use Unicode control characters to reorder tokens in source code at the encoding level,” reveals Nicholas Boucher, one of the researchers that discovered Trojan Source.
“We have discovered ways of manipulating the encoding of source code files so that human viewers and compilers see different logic. One particularly pernicious method uses Unicode directionality override characters to display code as an anagram of its true logic,” explains Ross Anderson, the other researcher behind testing the Trojan Source attack method.
See Also: Complete Offensive Security and Ethical Hacking Course
By using control characters embedded in comments and strings, a threat actor can reorder the source code to change its logic in a way that creates an exploitable vulnerability. Bidirectional and homoglyph attackThe researchers showed that one way this can be achieved is by using Unicode controls for bidirectional text (e.g. LRI -left-to-right isolate, and RLI -right-to-left isolate) to dictate the direction in which the content is displayed. This method is now tracked as CVE-2021-42574.
The bidirectional (Bidi) controls LRI and RLI are invisible characters, and they are not the only ones. By injecting these instructions, a compiler can compile code that is completely different from what a human sees.
In the image below, using the RLI/RLI controls inside the string the second line is compiled while the human eye reads it as a comment that the compiler would ignore.
https://www.bleepstatic.com/images/news/u/1100723/2021/TrojanSourceAttack02.jpg
A destructive infectionThis particular variant of the Chaos Ransomware is configured to search the infected systems for different file types smaller than 2ΜΒ and encrypts them.
However, if the file is larger than 2MB is will inject random bytes into the files, making them unrecoverable even if a ransom is paid.
Due to the destructive nature of the attack, those who pay the[...]
___________________________
@hacking_Attack
@Hacking_Video
‘Trojan Source’ attack method can hide bugs into open-source code
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png ‘Trojan Source’ attack method can hide bugs into open-source codePost Views: 134
Reading Time: 2 Minutes
Academic researchers have released details about a new attack method they call “Trojan Source” that allows injecting vulnerabilities into the source code of a software project in a way that human reviewers can’t detect.
Trojan Source relies on a simple trick that does not require modifying the compiler to create vulnerable binaries.
The method works with some of the most widely used programming languages today and adversaries could use it for supply-chain attacks. Abusing text-encoding standardsResearchers from the University of Cambridge, United Kingdom, disclosed and demonstrated the “Trojan Source” class of attacks that could compromise first-party software and supply chains.
The examples they provide are for projects written in C, C++, C#, JavaScript, Java, Rust, Go, and Python where an attacker can target the encoding of source code files to inject vulnerabilities.
“The trick is to use Unicode control characters to reorder tokens in source code at the encoding level,” reveals Nicholas Boucher, one of the researchers that discovered Trojan Source.
“We have discovered ways of manipulating the encoding of source code files so that human viewers and compilers see different logic. One particularly pernicious method uses Unicode directionality override characters to display code as an anagram of its true logic,” explains Ross Anderson, the other researcher behind testing the Trojan Source attack method.
See Also: Complete Offensive Security and Ethical Hacking Course
By using control characters embedded in comments and strings, a threat actor can reorder the source code to change its logic in a way that creates an exploitable vulnerability. Bidirectional and homoglyph attackThe researchers showed that one way this can be achieved is by using Unicode controls for bidirectional text (e.g. LRI -left-to-right isolate, and RLI -right-to-left isolate) to dictate the direction in which the content is displayed. This method is now tracked as CVE-2021-42574.
The bidirectional (Bidi) controls LRI and RLI are invisible characters, and they are not the only ones. By injecting these instructions, a compiler can compile code that is completely different from what a human sees.
In the image below, using the RLI/RLI controls inside the string the second line is compiled while the human eye reads it as a comment that the compiler would ignore.
https://www.bleepstatic.com/images/news/u/1100723/2021/TrojanSourceAttack02.jpg
A destructive infectionThis particular variant of the Chaos Ransomware is configured to search the infected systems for different file types smaller than 2ΜΒ and encrypts them.
However, if the file is larger than 2MB is will inject random bytes into the files, making them unrecoverable even if a ransom is paid.
Due to the destructive nature of the attack, those who pay the[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
‘Trojan Source’ attack method can hide bugs into open-source code | Black Hat Ethical Hacking
Academic researchers have released details about a new attack method they call “Trojan Source” that allows injecting vulnerabilities into the source code of a software project in a way that human reviewers can’t detect.