Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Secret hack the box writeup
Secret hack the box walkthrough
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Secret hack the box writeup
Secret hack the box walkthrough
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Secret hack the box writeup
Secret hack the box walkthrough
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Stored XSS?
https://cdn-images-1.medium.com/max/1400/1*UTniym98-Ke8fLWdasByFA.png
An introduction to stored cross-site scripting (XSS) vulnerabilities
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
What is Stored XSS?
https://cdn-images-1.medium.com/max/1400/1*UTniym98-Ke8fLWdasByFA.png
An introduction to stored cross-site scripting (XSS) vulnerabilities
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Stored XSS?
An introduction to stored cross-site scripting (XSS) vulnerabilities
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Docker Essentials — Image Optimization
https://cdn-images-1.medium.com/max/1650/1*TnMBU4iVzcGbDrXyo7YHMA.png
Optimize Your Docker Images for Production Deployment.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Docker Essentials — Image Optimization
https://cdn-images-1.medium.com/max/1650/1*TnMBU4iVzcGbDrXyo7YHMA.png
Optimize Your Docker Images for Production Deployment.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Docker Essentials — Image Optimization
Optimize Your Docker Images for Production Deployment.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OWASP Top 10 Vulnerabilities Latest 2021
https://cdn-images-1.medium.com/max/936/0*o8VlB0aVIBoKpDbF.png
What Is OWASP?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OWASP Top 10 Vulnerabilities Latest 2021
https://cdn-images-1.medium.com/max/936/0*o8VlB0aVIBoKpDbF.png
What Is OWASP?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OWASP Top 10 Vulnerabilities Latest 2021
What Is OWASP?
Hash cracking service for members /r/redteamsec
https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/
If you need a hash cracking service write to me. Here I have a sample of brute force cracking of an 11 character password for SHA256. It took 11 seconds. I have built computers for my own red teaming and pentesting. But sometimes computers don't work so I'm happy to help for money to crack your hash. Maybe this will make your red teaming better. https://preview.redd.it/ra2wbv44ajx71.png?width=1061&format=png&auto=webp&s=72a971b5456ca7f3f9ba6e8efff33ea6b61ec095 My computers: 6 x GPU RX 6600 XT 10 x GPU RX 6600 XT I can crack bruteforce or on my or your dictionaries. We bill hourly for the number of GPUs. I suggest a price of $1 per GPU per hour of work. Discounts for larger orders. If you order for example 10 hours and the password is broken after 2 hours I will return you money for not used time. If you have any other idea then let me know. submitted by /u/blaszczakm (https://www.reddit.com/user/blaszczakm)
[link] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/) [comments] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/
If you need a hash cracking service write to me. Here I have a sample of brute force cracking of an 11 character password for SHA256. It took 11 seconds. I have built computers for my own red teaming and pentesting. But sometimes computers don't work so I'm happy to help for money to crack your hash. Maybe this will make your red teaming better. https://preview.redd.it/ra2wbv44ajx71.png?width=1061&format=png&auto=webp&s=72a971b5456ca7f3f9ba6e8efff33ea6b61ec095 My computers: 6 x GPU RX 6600 XT 10 x GPU RX 6600 XT I can crack bruteforce or on my or your dictionaries. We bill hourly for the number of GPUs. I suggest a price of $1 per GPU per hour of work. Discounts for larger orders. If you order for example 10 hours and the password is broken after 2 hours I will return you money for not used time. If you have any other idea then let me know. submitted by /u/blaszczakm (https://www.reddit.com/user/blaszczakm)
[link] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/) [comments] (https://www.reddit.com/r/redteamsec/comments/qmfnh2/hash_cracking_service_for_members_rredteamsec/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/redteamsec - Hash cracking service for members /r/redteamsec
8 votes and 14 comments so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy CampaignPost Views: 103
Reading Time: 1 Minute
A new version of a banking trojan known as Mekotio is being deployed in the wild, with malware analysts reporting that it’s using a new, stealthier infection flow.
The last notable activity of Mekotio dates back to the summer of 2020 when the trojan’s operators deployed it in a campaign targeting Latin American countries.
The targeting scope appears to be the same in recent attacks, with Spanish being the language of choice for the phishing emails that start the infection chain. A new attack flowThe infection begins with a phishing email bundling a ZIP attachment containing an obfuscated batch script that fetches and executes a PowerShell script.
Once the PowerShell script gets launched, it will download a second ZIP archive after some basic location and anti-analysis checks.
If the checks confirm the victim is in Latin America and the malware isn’t running on a virtual machine, the second ZIP, which contains the Mekotio payload in DLL form, is extracted.
https://www.bleepstatic.com/images/news/u/1220909/Security/attack%20flow.jpg
Same old code in new wrappingThe three novel elements that make the latest Mekotio version harder to detect are the following:
* A stealthier batch file with at least two layers of obfuscation
* New file-less PowerShell script that runs directly in memory
* Use of Themida v3 for packing the final DLL payload
See Also: All Windows versions impacted by new LPE zero-day vulnerability CheckPoint reports seeing approximately 100 attacks in the past three months deploying cipher substitution techniques, which albeit simple, help Mekotio go undetected by most AV products.
The second layer of obfuscation is slicing the PowerShell commands into parts saved in different environment variables and then concatenating the values during execution.
https://www.bleepstatic.com/images/news/u/1220909/Security/obfuscation.jpg
___________________________
@hacking_Attack
@Hacking_Video
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy CampaignPost Views: 103
Reading Time: 1 Minute
A new version of a banking trojan known as Mekotio is being deployed in the wild, with malware analysts reporting that it’s using a new, stealthier infection flow.
The last notable activity of Mekotio dates back to the summer of 2020 when the trojan’s operators deployed it in a campaign targeting Latin American countries.
The targeting scope appears to be the same in recent attacks, with Spanish being the language of choice for the phishing emails that start the infection chain. A new attack flowThe infection begins with a phishing email bundling a ZIP attachment containing an obfuscated batch script that fetches and executes a PowerShell script.
Once the PowerShell script gets launched, it will download a second ZIP archive after some basic location and anti-analysis checks.
If the checks confirm the victim is in Latin America and the malware isn’t running on a virtual machine, the second ZIP, which contains the Mekotio payload in DLL form, is extracted.
https://www.bleepstatic.com/images/news/u/1220909/Security/attack%20flow.jpg
Same old code in new wrappingThe three novel elements that make the latest Mekotio version harder to detect are the following:
* A stealthier batch file with at least two layers of obfuscation
* New file-less PowerShell script that runs directly in memory
* Use of Themida v3 for packing the final DLL payload
See Also: All Windows versions impacted by new LPE zero-day vulnerability CheckPoint reports seeing approximately 100 attacks in the past three months deploying cipher substitution techniques, which albeit simple, help Mekotio go undetected by most AV products.
The second layer of obfuscation is slicing the PowerShell commands into parts saved in different environment variables and then concatenating the values during execution.
https://www.bleepstatic.com/images/news/u/1220909/Security/obfuscation.jpg
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign | Black Hat Ethical Hacking
A new version of a banking trojan known as Mekotio is being deployed in the wild, with malware analysts reporting that it's using a new, stealthier infection flow.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy CampaignPost…
terized this particular trojan as “chaotic” last year due to the concurrent development that resulted in the simultaneous circulation of different variants.
That activity has now waned, and the most recent campaign uses the variant analyzed by CheckPoint.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/GitLab-90x90.jpg Over 30,000 GitLab servers still unpatched against critical bug1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-4-90x90.jpg Chaos ransomware targets gamers via fake Minecraft alt lists3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png All Windows versions impacted by new LPE zero-day vulnerability6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/social_preview-scaled-90x90.jpg Sensitive data of 400,000 German students exposed by API flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware2 weeks ago
The post Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
That activity has now waned, and the most recent campaign uses the variant analyzed by CheckPoint.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/GitLab-90x90.jpg Over 30,000 GitLab servers still unpatched against critical bug1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-4-90x90.jpg Chaos ransomware targets gamers via fake Minecraft alt lists3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png All Windows versions impacted by new LPE zero-day vulnerability6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/social_preview-scaled-90x90.jpg Sensitive data of 400,000 German students exposed by API flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/hacked-90x90.jpg Brutal WordPress plugin bug allows subscribers to wipe sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-5-90x90.jpg Hackers used billing software zero-day to deploy ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-4-90x90.jpg Popular NPM library hijacked to install password-stealers, miners1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/youtube-logo-90x90.jpg Massive campaign uses YouTube to push password-stealing malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/ezgif.com-gif-maker-3-90x90.jpg Google: YouTubers’ accounts hijacked with cookie-stealing malware2 weeks ago
The post Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
LDAPmonitor - Monitor Creation, Deletion And Changes To LDAP Objects Live During Your Pentest Or System Administration!
http://www.kitploit.com/2021/11/ldapmonitor-monitor-creation-deletion.html
http://www.kitploit.com/2021/11/ldapmonitor-monitor-creation-deletion.html
Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object.
Features
Feature Python (.py) (https://github.com/p0dalirius/LDAPmonitor/blob/master/python) CSharp (.exe) (https://github.com/p0dalirius/LDAPmonitor/blob/master/csharp) Powershell (.ps1) (https://github.com/p0dalirius/LDAPmonitor/blob/master/powershell) LDAPS support ✔️ ✔️ ✔️ Random delay in seconds between queries ✔️ ✔️ ✔️ Custom delay in seconds between queries ✔️ ✔️ ✔️ Save output to logfile ✔️ ✔️ ✔️ Colored or not colored output with --no-colors ✔️ ❌ ❌ Custom page size for paged queries ✔️ ✔️ ✔️ Authenticate with user and password ✔️ ✔️ ✔️ Authenticate as current shell user ❌ ✔️ ✔️ Authenticate with LM:NT hashes ✔️ ❌ ❌ Authenticate with kerberos (https://www.kitploit.com/search/label/Kerberos) tickets ✔️ ❌ ❌ Option to ignore user logon events ✔️ ✔️ ✔️
Download LDAPmonitor (https://github.com/p0dalirius/LDAPmonitor)
Features
Feature Python (.py) (https://github.com/p0dalirius/LDAPmonitor/blob/master/python) CSharp (.exe) (https://github.com/p0dalirius/LDAPmonitor/blob/master/csharp) Powershell (.ps1) (https://github.com/p0dalirius/LDAPmonitor/blob/master/powershell) LDAPS support ✔️ ✔️ ✔️ Random delay in seconds between queries ✔️ ✔️ ✔️ Custom delay in seconds between queries ✔️ ✔️ ✔️ Save output to logfile ✔️ ✔️ ✔️ Colored or not colored output with --no-colors ✔️ ❌ ❌ Custom page size for paged queries ✔️ ✔️ ✔️ Authenticate with user and password ✔️ ✔️ ✔️ Authenticate as current shell user ❌ ✔️ ✔️ Authenticate with LM:NT hashes ✔️ ❌ ❌ Authenticate with kerberos (https://www.kitploit.com/search/label/Kerberos) tickets ✔️ ❌ ❌ Option to ignore user logon events ✔️ ✔️ ✔️
Download LDAPmonitor (https://github.com/p0dalirius/LDAPmonitor)
hacking: security in practice
What is exactly is hackable from a shared public wifi?
I never use them because I'm paranoid about my data being intercepted/sensitive documents on my phone being lifted, my friend thinks I'm paranoid. Anyone can answer or point me in the direction of finding out what is hackable on a phone using public wifi?
submitted by /u/looseboy
[link] [comments]
What is exactly is hackable from a shared public wifi?
I never use them because I'm paranoid about my data being intercepted/sensitive documents on my phone being lifted, my friend thinks I'm paranoid. Anyone can answer or point me in the direction of finding out what is hackable on a phone using public wifi?
submitted by /u/looseboy
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Looking for a small ChromeOS virus
What’s a good virus in zip folder that will fit on a 4gb USB and designed for chromeOS? The last detail specifically
submitted by /u/dreamhater5000
[link] [comments]
Looking for a small ChromeOS virus
What’s a good virus in zip folder that will fit on a 4gb USB and designed for chromeOS? The last detail specifically
submitted by /u/dreamhater5000
[link] [comments]
reddit
Looking for a small ChromeOS virus
What’s a good virus in zip folder that will fit on a 4gb USB and designed for chromeOS? The last detail specifically
hacking: security in practice
child hood
hi i used to play Roblox all the time when i was a kid, and i have forgotten the password for my old account. if anyone wants to help out it would be much appreciated
account name: AaronAJO
submitted by /u/AaronAJ0
[link] [comments]
child hood
hi i used to play Roblox all the time when i was a kid, and i have forgotten the password for my old account. if anyone wants to help out it would be much appreciated
account name: AaronAJO
submitted by /u/AaronAJ0
[link] [comments]
reddit
child hood
hi i used to play Roblox all the time when i was a kid, and i have forgotten the password for my old account. if anyone wants to help out it would...
Deep Web
Gore forum websites? I need help finding a video I saw a while back.
I need help finding a video I saw.
It was a video of a Mexican cartel (I think). They tied a guy down and started cutting their limbs with an axe. They started with the foot, then limbs, arm, etc, and so on.
That’s all I can remember.
If anyone can find it, it would be greatly appreciated.
Are there any forum links for gore that I can ask these things on?
submitted by /u/illustrator101
[link] [comments]
Gore forum websites? I need help finding a video I saw a while back.
I need help finding a video I saw.
It was a video of a Mexican cartel (I think). They tied a guy down and started cutting their limbs with an axe. They started with the foot, then limbs, arm, etc, and so on.
That’s all I can remember.
If anyone can find it, it would be greatly appreciated.
Are there any forum links for gore that I can ask these things on?
submitted by /u/illustrator101
[link] [comments]
reddit
Gore forum websites? I need help finding a video I saw a while back.
I need help finding a video I saw. It was a video of a Mexican cartel (I think). They tied a guy down and started cutting their limbs with an...
LDAPmonitor - Monitor Creation, Deletion And Changes To LDAP Objects Live During Your Pentest Or System Administration!
Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object. Features Feature Python (.py) CSharp (.exe) Powershell (.ps1) LDAPS support ✔️ ✔️ ✔️ Random delay in seconds between queries ✔️ ✔️ ✔️ Custom delay in seconds between queries ✔️ ✔️ ✔️ Save output to logfile ✔️ ✔️ ✔️ Colored or not colored output with --no-colors ✔️ ❌ ❌ Custom page size for paged queries ✔️ ✔️ ✔️ Authenticate with user and password ✔️ ✔️ ✔️ Authenticate as current shell user ❌ ✔️ ✔️ Authenticate with LM:NT hashes ✔️ ❌ ❌ Authenticate with kerberos tickets ✔️ ❌ ❌ Option to ignore user logon events ✔️ ✔️ ✔️ Download LDAPmonitor
Read more...
Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object. Features Feature Python (.py) CSharp (.exe) Powershell (.ps1) LDAPS support ✔️ ✔️ ✔️ Random delay in seconds between queries ✔️ ✔️ ✔️ Custom delay in seconds between queries ✔️ ✔️ ✔️ Save output to logfile ✔️ ✔️ ✔️ Colored or not colored output with --no-colors ✔️ ❌ ❌ Custom page size for paged queries ✔️ ✔️ ✔️ Authenticate with user and password ✔️ ✔️ ✔️ Authenticate as current shell user ❌ ✔️ ✔️ Authenticate with LM:NT hashes ✔️ ❌ ❌ Authenticate with kerberos tickets ✔️ ❌ ❌ Option to ignore user logon events ✔️ ✔️ ✔️ Download LDAPmonitor
Read more...