Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tomiris Backdoor linked to hackers behind Solar winds hack
https://cdn-images-1.medium.com/max/600/0*CCbj5VFKj_dCwyeF
Another Solar winds incident on the way?
Continue reading on rootissh »
___________________________
@hacking_Attack
@Hacking_Video
Tomiris Backdoor linked to hackers behind Solar winds hack
https://cdn-images-1.medium.com/max/600/0*CCbj5VFKj_dCwyeF
Another Solar winds incident on the way?
Continue reading on rootissh »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tomiris Backdoor linked to hackers behind Solar winds hack
Another Solar winds incident on the way?
Self XSS via image upload in skilvul.com
https://alpinnnnnn13.medium.com/self-xss-via-image-upload-in-skilvul-com-94679a85ff25?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://alpinnnnnn13.medium.com/self-xss-via-image-upload-in-skilvul-com-94679a85ff25?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Self XSS via image upload in skilvul.com
Hallo teman teman, perkenalkan nama saya Mohammad Alfin Hidayatullah. Saya adalah seorang bug bounty hunter dan kali ini saya ingin…
Hallo teman teman, perkenalkan nama saya Mohammad Alfin Hidayatullah. Saya adalah seorang bug bounty hunter dan kali ini saya ingin…Continue reading on Medium » (https://alpinnnnnn13.medium.com/self-xss-via-image-upload-in-skilvul-com-94679a85ff25?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Self XSS via image upload in skilvul.com
Hallo teman teman, perkenalkan nama saya Mohammad Alfin Hidayatullah. Saya adalah seorang bug bounty hunter dan kali ini saya ingin…
An introduction to stored cross-site scripting (XSS) vulnerabilitiesContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/what-is-stored-xss-69d463bdd1d7?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Stored XSS?
An introduction to stored cross-site scripting (XSS) vulnerabilities
What is Stored XSS?
An introduction to stored cross-site scripting (XSS) vulnerabilitiesContinue reading on InfoSec Write-ups »
Read more...
An introduction to stored cross-site scripting (XSS) vulnerabilitiesContinue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
WPA decrypting with Wireshark debug
Hi, I recently set up a wireless lab to practice for the OSWP and I am running into a weird problem :
1. I set up my router with WPA/WPA2 PSK
2. I connected to it with a device and captured a handshake by deauthenticating it
3. I successfully cracked the password with aircrack-ng
Now, I am trying to decrypt it using Wireshark and here is my problem : Wireshark can't seem to be able to decrypt it (?)
1. I verified that there was a complete EAPOL transmission in the capture
2. I imported the PSK as described in Wireshark's documentation
3. I even tried using WPA PWD just in case I misconfigured the rooter
but nothing seems to work.
When I try to decrypt the traffic in captures like this one, Wireshark is able to decrypt it, so I guess the problem is with my own capture.
Also, I see that my packets do not have the
If you have any idea or experienced anything similar I would really love your help.
submitted by /u/PetiteGousseDAil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
WPA decrypting with Wireshark debug
Hi, I recently set up a wireless lab to practice for the OSWP and I am running into a weird problem :
1. I set up my router with WPA/WPA2 PSK
2. I connected to it with a device and captured a handshake by deauthenticating it
3. I successfully cracked the password with aircrack-ng
Now, I am trying to decrypt it using Wireshark and here is my problem : Wireshark can't seem to be able to decrypt it (?)
1. I verified that there was a complete EAPOL transmission in the capture
2. I imported the PSK as described in Wireshark's documentation
3. I even tried using WPA PWD just in case I misconfigured the rooter
but nothing seems to work.
When I try to decrypt the traffic in captures like this one, Wireshark is able to decrypt it, so I guess the problem is with my own capture.
Also, I see that my packets do not have the
Radio Tap Headernor the 802.11 radio informationlayers as shown here, but only the Frame, IEEE 802.11and Datalayers. Could this be why Wireshark can't decrypt it ?If you have any idea or experienced anything similar I would really love your help.
submitted by /u/PetiteGousseDAil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
WPA decrypting with Wireshark debug
Hi, I recently set up a wireless lab to practice for the OSWP and I am running into a weird problem : 1. I set up my router with WPA/WPA2 PSK 2....
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Secret hack the box writeup
Secret hack the box walkthrough
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Secret hack the box writeup
Secret hack the box walkthrough
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Secret hack the box writeup
Secret hack the box walkthrough
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Stored XSS?
https://cdn-images-1.medium.com/max/1400/1*UTniym98-Ke8fLWdasByFA.png
An introduction to stored cross-site scripting (XSS) vulnerabilities
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
What is Stored XSS?
https://cdn-images-1.medium.com/max/1400/1*UTniym98-Ke8fLWdasByFA.png
An introduction to stored cross-site scripting (XSS) vulnerabilities
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Stored XSS?
An introduction to stored cross-site scripting (XSS) vulnerabilities
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Docker Essentials — Image Optimization
https://cdn-images-1.medium.com/max/1650/1*TnMBU4iVzcGbDrXyo7YHMA.png
Optimize Your Docker Images for Production Deployment.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Docker Essentials — Image Optimization
https://cdn-images-1.medium.com/max/1650/1*TnMBU4iVzcGbDrXyo7YHMA.png
Optimize Your Docker Images for Production Deployment.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Docker Essentials — Image Optimization
Optimize Your Docker Images for Production Deployment.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OWASP Top 10 Vulnerabilities Latest 2021
https://cdn-images-1.medium.com/max/936/0*o8VlB0aVIBoKpDbF.png
What Is OWASP?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OWASP Top 10 Vulnerabilities Latest 2021
https://cdn-images-1.medium.com/max/936/0*o8VlB0aVIBoKpDbF.png
What Is OWASP?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OWASP Top 10 Vulnerabilities Latest 2021
What Is OWASP?
Hash cracking service for members /r/redteamsec
https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/
If you need a hash cracking service write to me. Here I have a sample of brute force cracking of an 11 character password for SHA256. It took 11 seconds. I have built computers for my own red teaming and pentesting. But sometimes computers don't work so I'm happy to help for money to crack your hash. Maybe this will make your red teaming better. https://preview.redd.it/ra2wbv44ajx71.png?width=1061&format=png&auto=webp&s=72a971b5456ca7f3f9ba6e8efff33ea6b61ec095 My computers: 6 x GPU RX 6600 XT 10 x GPU RX 6600 XT I can crack bruteforce or on my or your dictionaries. We bill hourly for the number of GPUs. I suggest a price of $1 per GPU per hour of work. Discounts for larger orders. If you order for example 10 hours and the password is broken after 2 hours I will return you money for not used time. If you have any other idea then let me know. submitted by /u/blaszczakm (https://www.reddit.com/user/blaszczakm)
[link] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/) [comments] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/
If you need a hash cracking service write to me. Here I have a sample of brute force cracking of an 11 character password for SHA256. It took 11 seconds. I have built computers for my own red teaming and pentesting. But sometimes computers don't work so I'm happy to help for money to crack your hash. Maybe this will make your red teaming better. https://preview.redd.it/ra2wbv44ajx71.png?width=1061&format=png&auto=webp&s=72a971b5456ca7f3f9ba6e8efff33ea6b61ec095 My computers: 6 x GPU RX 6600 XT 10 x GPU RX 6600 XT I can crack bruteforce or on my or your dictionaries. We bill hourly for the number of GPUs. I suggest a price of $1 per GPU per hour of work. Discounts for larger orders. If you order for example 10 hours and the password is broken after 2 hours I will return you money for not used time. If you have any other idea then let me know. submitted by /u/blaszczakm (https://www.reddit.com/user/blaszczakm)
[link] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/) [comments] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/redteamsec - Hash cracking service for members /r/redteamsec
8 votes and 14 comments so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy CampaignPost Views: 103
Reading Time: 1 Minute
A new version of a banking trojan known as Mekotio is being deployed in the wild, with malware analysts reporting that it’s using a new, stealthier infection flow.
The last notable activity of Mekotio dates back to the summer of 2020 when the trojan’s operators deployed it in a campaign targeting Latin American countries.
The targeting scope appears to be the same in recent attacks, with Spanish being the language of choice for the phishing emails that start the infection chain. A new attack flowThe infection begins with a phishing email bundling a ZIP attachment containing an obfuscated batch script that fetches and executes a PowerShell script.
Once the PowerShell script gets launched, it will download a second ZIP archive after some basic location and anti-analysis checks.
If the checks confirm the victim is in Latin America and the malware isn’t running on a virtual machine, the second ZIP, which contains the Mekotio payload in DLL form, is extracted.
https://www.bleepstatic.com/images/news/u/1220909/Security/attack%20flow.jpg
Same old code in new wrappingThe three novel elements that make the latest Mekotio version harder to detect are the following:
* A stealthier batch file with at least two layers of obfuscation
* New file-less PowerShell script that runs directly in memory
* Use of Themida v3 for packing the final DLL payload
See Also: All Windows versions impacted by new LPE zero-day vulnerability CheckPoint reports seeing approximately 100 attacks in the past three months deploying cipher substitution techniques, which albeit simple, help Mekotio go undetected by most AV products.
The second layer of obfuscation is slicing the PowerShell commands into parts saved in different environment variables and then concatenating the values during execution.
https://www.bleepstatic.com/images/news/u/1220909/Security/obfuscation.jpg
___________________________
@hacking_Attack
@Hacking_Video
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy CampaignPost Views: 103
Reading Time: 1 Minute
A new version of a banking trojan known as Mekotio is being deployed in the wild, with malware analysts reporting that it’s using a new, stealthier infection flow.
The last notable activity of Mekotio dates back to the summer of 2020 when the trojan’s operators deployed it in a campaign targeting Latin American countries.
The targeting scope appears to be the same in recent attacks, with Spanish being the language of choice for the phishing emails that start the infection chain. A new attack flowThe infection begins with a phishing email bundling a ZIP attachment containing an obfuscated batch script that fetches and executes a PowerShell script.
Once the PowerShell script gets launched, it will download a second ZIP archive after some basic location and anti-analysis checks.
If the checks confirm the victim is in Latin America and the malware isn’t running on a virtual machine, the second ZIP, which contains the Mekotio payload in DLL form, is extracted.
https://www.bleepstatic.com/images/news/u/1220909/Security/attack%20flow.jpg
Same old code in new wrappingThe three novel elements that make the latest Mekotio version harder to detect are the following:
* A stealthier batch file with at least two layers of obfuscation
* New file-less PowerShell script that runs directly in memory
* Use of Themida v3 for packing the final DLL payload
See Also: All Windows versions impacted by new LPE zero-day vulnerability CheckPoint reports seeing approximately 100 attacks in the past three months deploying cipher substitution techniques, which albeit simple, help Mekotio go undetected by most AV products.
The second layer of obfuscation is slicing the PowerShell commands into parts saved in different environment variables and then concatenating the values during execution.
https://www.bleepstatic.com/images/news/u/1220909/Security/obfuscation.jpg
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign | Black Hat Ethical Hacking
A new version of a banking trojan known as Mekotio is being deployed in the wild, with malware analysts reporting that it's using a new, stealthier infection flow.