Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Determining target SSID?

For example: During a pentest (SSID name isn’t obvious) , how does one determine an SSID is the right target? Do you move around the building and pay attention to the signal loss? Is there a command line or online tool?

submitted by /u/DoubleAgent10
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
BotenaGo botnet targets millions of IoT devices with 33 exploits

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png BotenaGo botnet targets millions of IoT devices with 33 exploitsPost Views: 141
Reading Time: 1 Minute
The new BotenaGo malware botnet has been discovered using over thirty exploits to attack millions of routers and IoT devices.
BotenaGo was written in Golang (Go), which has been exploding in popularity in recent years, with malware authors loving it for making payloads that are harder to detect and reverse engineer.

In the case of BotenaGo, only six out of 62 AV engines on VirusTotal flag the sample as malicious, and some identify it as Mirai.
https://www.bleepstatic.com/images/news/u/1220909/Security/scan.jpg
<figcaptionBotenaGo goes primarily unnoticed by AV scanners
Source: AT&T
See Also: Complete Offensive Security and Ethical Hacking Course Targeting millions of devicesBotenaGo incorporates 33 exploits for a variety of routers, modems, and NAS devices, with some notable examples given below:

* CVE-2015-2051, CVE-2020-9377, CVE-2016-11021: D-Link routers
* CVE-2016-1555, CVE-2017-6077, CVE-2016-6277, CVE-2017-6334: Netgear devices
* CVE-2019-19824: Realtek SDK based routers
* CVE-2017-18368, CVE-2020-9054: Zyxel routers and NAS devices
* CVE-2020-10987: Tenda products
* CVE-2014-2321: ZTE modems
* CVE-2020-8958: Guangzhou 1GE ONU

Researchers at AT&T who analyzed the new botnet found that it targets millions of devices with functions that exploit the above flaws.

An example given is the search string for Boa, which is a discontinued open-source web server used in embedded applications and one that still returns nearly two million internet-facing devices on Shodan.
https://www.bleepstatic.com/images/news/u/1220909/Security/botenago_shodan.jpg
<figcaptionShodan search returned 2 million results on Boa
Source: AT&T
See Also: All Windows versions impacted by new LPE zero-day vulnerability Another notable example is the targeting of CVE-2020-10173, a command-injection flaw in Comtrend VR-3033 gateway devices, of which 250,000 are still exploitable.

When installed, the malware will listen on two ports (31412 and 19412), where it waits for an IP address to be sent to it. Once one is received, the bot will exploit each vulnerability on that IP address to gain access.
https://www.bleepstatic.com/images/news/u/1220909/Security/mapping.jpg
<figcaptionBotenaGo mapping attack functions.
Source: AT&T
Once BotenaGo gains access, it will execute remote shell commands to recruit the device into the botnet.

Depending on which device is targeted, the malware uses different links to fetch a matching payload.

At the time of the analysis, though, there were no payloads on the hosting server, so none could be retrieved for analysis.
See Also: Offensive Security Tool: DotDotPwn – The Directory Traversal Fuzzer Furthermore, the researchers didn’t find an active C2 communication between BotenaGo and an actor-controlled server, so they give three potential explanations on how it operates:

1. BotenaGo is only one part (module) of a multi-stage modular malware attack, and it’s not the one responsible for handling communications.
2. BotenaGo is a new tool used by Mirai operators on certain machines, a scenario that is backed by common payload dropping links.
3. The malware isn’t ready to operate yet, and a sample from its early development phase leaked in the wild accidentally.

In conclusion, the appearance of BotenaGo in the wild is unusual given its incomplete operational status, but its underlying capabilities are leaving no doubt about the int[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking BotenaGo botnet targets millions of IoT devices with 33 exploits https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png BotenaGo botnet targets millions of IoT devices with 33 exploitsPost Views:…
ention of its authors.

Fortunately, the new botnet has been spotted early, and the indicators of compromise are already available. Still, as long as there’s a wealth of vulnerable online devices to exploit, the incentive is there for the threat actors to continue the development of BotenaGo.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Pwn2OwnBlur-90x90.png Pwn2Own – Over 1 million dollars in Bounties, Samsung Galaxy S21 hacked twice, Printer plays AC/DC4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/maxresdefault-1024x576-1-90x90.jpg Microsoft Exchange ProxyShell exploits used to deploy Babuk ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Mekotio-Banking-Trojan-90x90.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/GitLab-90x90.jpg Over 30,000 GitLab servers still unpatched against critical bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-4-90x90.jpg Chaos ransomware targets gamers via fake Minecraft alt lists2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/microsoft-zero-day-vulnerabilities-800x358-1-90x90.png All Windows versions impacted by new LPE zero-day vulnerability2 weeks ago
The post BotenaGo botnet targets millions of IoT devices with 33 exploits first appeared on Black Hat Ethical Hacking.
Ports filtered but firewall off
https://www.reddit.com/r/Pentesting/comments/qs6z42/ports_filtered_but_firewall_off/

<!-- SC_OFF -->Ok so i got an Ubuntu host ready and a windows 10 pro machine(guest) running. I ping host from guest and everything is fine, works with no delay ( so... what's up <!-- SC_ON --> submitted by /u/kostas791 (https://www.reddit.com/user/kostas791)
[link] (https://www.reddit.com/r/Pentesting/comments/qs6z42/ports_filtered_but_firewall_off/) [comments] (https://www.reddit.com/r/Pentesting/comments/qs6z42/ports_filtered_but_firewall_off/)
Containers have been the rage. Containers allow developers to package the code, its dependencies, libraries, and more so they can run…Continue reading on Medium » (https://redhuntlabs.medium.com/scanning-millions-of-publicly-exposed-docker-containers-thousands-of-secrets-leaked-redhunt-c924f892e01f?source=rss------bug_bounty-5)
hacking: security in practice
Hacking a very simple game

So I'd like to hack this simple old game i found, written in html and js, just for fun and to learn something.

The game is played from browser, then a score is posted with a js function. From Chrome i can modify the stats viewed client-side from right click > inspect > sources, where i can edit the js scripts and assign an arbitrary score, but it wouldn't get posted.

I guess i should modify the packets sent in some way, so what should i try and how? Should I use Wireshark? My goal is to set an arbitrary score viewed from others

submitted by /u/s96g3g23708gbxs86734
[link] [comments]
Software development is an iterative process, and mistakes can happen at any time. That’s why, in the practice of developing software…Continue reading on Immunefi » (https://medium.com/immunefi/harvest-finance-uninitialized-proxies-bug-fix-postmortem-ea5c0f7af96b?source=rss------bug_bounty-5)
Authenticated Blind & Error based SQL injection Lead To RCE.Continue reading on Medium » (https://medium.com/@J03KR/cve-2021-40578-127ceaf3f1bb?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Offensive Security Tool: Pentesting Tools

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Offensive Security Tool: Pentesting ToolsPost Views: 3 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 2 Minutes

Offensive Security Tool: Pentesting Tools GitHub Link
This repo was created containing over 48 starred tools for specific attack vectors, covering a wide range of techniques used by advanced Offensive Security and Red Teams to conduct wide range of Pentesting, Bug Bounty Hunting and more. It is a really important repo to have, and gives you the ability to train on more sophisticated attack scenarios as it gives a lot of explanation for each technique on practicality usages and more.
Some of the attack vectors covered, ranging from Recon, OSINT, Attack, Digital Forensics, Source Code, Reverse Engineering, Exploits:
* Payload Hosting & Reverse Shellz
* POST Exploitation
* Backdoor finder
* Persistence on windows
* Web Application Pentest
* Framework Scanner / Exploitation
* Network- / Service-level Vulnerability Scanner
* Windows & Linux Privilege Escalation / Audit
* Credential harvesting Linux & Windows
* Data Exfiltration – DNS/ICMP/Wifi Exfiltration
* Reverse Engineering
* Forensics
* Raspberry PI Exploitation
* Social Engineering
* Source Code Analysis
And much more. The great thing is that they have categories, helping a pentester easily choose which category of attacks is needed all in one place.
See Also: BotenaGo botnet targets millions of IoT devices with 33 exploits

See Also: Hacking stories – The first botnet hijacker aka the Zombie King Pentesting Tools* General useful PowerShell Scripts
* AMSI Bypass restriction Bypass
* Payload Hosting
* Network Share Scanner
* Lateral Movement
* Reverse Shellz
* POST Exploitation
* Pivot
* Backdoor finder
* Persistence on windows
* Web Application Pentest
* Framework Discovery
* Framework Scanner / Exploitation
* Web Vulnerability Scanner / Burp Plugins
* Network- / Service-level Vulnerability Scanner
* Crawler
* Web Exploitation Tools
* Windows Privilege Escalation / Audit
* T3 Enumeration
* Linux Privilege Escalation / Audit
* Credential harvesting Windows Specific
* Credential harvesting Linux Specific
* Data Exfiltration – DNS/ICMP/Wi-Fi Exfiltration
* Git Specific
* Reverse Engineering / decompiler
* Forensics
* Network Attacks
* Specific MITM service Exploitation
* Sniffing / Evaluation / Filtering
* Scanner / Exploitation-Frameworks / Automation
* Default Credential Scanner
* Payload Generation / AV-Evasion / Malware Creation
* Domain Finding / Subdomain Enumeration
* Scanner network level
* Email Gathering
* Domain Auth + Exploitation
* Network service – Login Brute Force + Wordlist attacks
* Command & Control Frameworks
* Wi-Fi Tools
* Raspberry PI Exploitation
* Social Engineering
* Wordlists / Wordlist generators
* Obfuscation
* Source Code Analysis
* No category yet
* Industrial Control Systems
* NAC bypass
* JMX Exploitation
To find out about all the rest of Repos, click here
See Also: Complete Offensive Security & Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/unknown-90x90.png Offensive Security Tool: DotDotPwn – The Directory Traversal Fuzzer1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/unknown-1-90x90.png Offensive Security Tool: ZipExec2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/carbon-2048x1374-1-90x90.png OSINT Tool: Osintgram3 weeks ag[...]