Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Government Bug Bounty

Governments should provide Bug Bounty programs otherwise the hacker if they find a vulnerability has an incentive to sell the vulnerability to criminals.



A few months ago I did a post regarding the oil industry in america that was very successful in this section of reddit. Obviously it was a small vulnerability but I sent more than one email to cisa.gov and the problem was fixed only after months and no one from the US government thanked me.



Now I find myself to have found a very serious vulnerability that would allow a "solarwinds" multiplied by 10.



But in spite of my effort to do incessant research and study I am not rewarded.



Give me a computer and 15 hours of time and I find a serious vulnerability in some company. One small mistake, one capable person and solarwinds 2 will show up again.



Now imagine that someone walks into one of the 5 Big IT security companies that provide security software to government agencies and critical companies.



Selling a vulnerability in one of these companies to a hostile intelligence agency can make more than 10 million but can cause billions in damage.

Governments around the world think about it!

submitted by /u/LargeTrader
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Android Device Hacking

https://cdn-images-1.medium.com/max/1024/0*GYLxRYltYyLkiqti.jpg
A backdoor is a typically covert method of bypassing normal authentication or encryption in a computer,android, embedded device.

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is phishing? What is phishing hacking?

https://cdn-images-1.medium.com/max/2440/0*b3EjGXdkYlH1MDpG
Phishing is an example of a strategy called social engineering. Trapped in this strategy, you can lose a lot of valuable information. For…

Continue reading on Medium »
hacking: security in practice
How to escape out of a locked down broswer?

Hi all,

Recently, my high school announced that we would have to test an online exam software.

They selected a couple students to try and break the software (as the results from the test wouldn't be marked as it was simply a test of the software). I would be using a school computer (so no admin privileges) and I was wondering if there was any simple way to get around this.



My first thought would be to install it in windows sandbox to exit it mid quiz however I would not be able to do this due to the lack of admin privileges on the school PC.

What are possible ways to 'escape' this locked down browser.

P.S. The school computers run windows 10



Edit: It's a full application (not a website) so Web Tools won't work

submitted by /u/TerryFromOuterSpace
[link] [comments]
hacking: security in practice
How to trace a hacker

Someone hacked one of my good friends entire phone. They texted me, from my friends phone number, and were in their snapchat, and claimed to be her brother, telling me the friend had been missing for a few hours, and eventually saying a body was found similar to hers and wearing a piece of jewelry I had given her.

Long story short, she was actually sleeping. She opened her phone and had to go through all the setup stuff again.

How can We track them and is it a cybercrime to do this?

submitted by /u/Swred1100
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
QBot returns for a new wave of infections using Squirrelwaffle

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png QBot returns for a new wave of infections using SquirrelwafflePost Views: 112
Reading Time: 1 Minute
The activity of the QBot (also known as Quakbot) banking trojan is spiking again, and analysts from multiple security research firms attribute this to the rise of Squirrelwaffle.
Squirrelwaffle emerged last month as one of the most likely candidates to fill the void left by the take-down of Emotet, and unfortunately, these predictions are quickly being confirmed. A new wave of attacksResearchers at TrendMicro have observed a new distribution campaign for QBot relying on Visual Basic Macros (VBA) macros in Microsoft Word documents sent as attachments in phishing emails.

Previous Qbot campaigns used Excel macros, which are still present in some cases, even if they are more scarce now.
https://www.bleepstatic.com/images/news/u/1220909/Security/qbot%20infections.jpg
<figcaptionAll of QBot’s arrival variations
Source: TrendMicro
See Also: Complete Offensive Security and Ethical Hacking Course
The victim still has to manually open the document and “Enable Content” on their Microsoft Office suite to let the macro code run, dropping a QBot payload on the system.

The rest of the process chain hasn’t changed much compared to previous versions, still downloading a DLL file as the core payload and setting the same scheduled task for persistence as before.

Qbot is also known to partner with ransomware operations to provide them with initial access to a network. QBot has previously collaborated with ransomware gangs to deploy REvil, Egregor, ProLock, PwndLocker, and MegaCortex strains.

We shouldn’t forget that even if these compromises never evolve to file-encryption events, QBot can do significant damage on its own.

The additional modules downloaded by the QBot malware can grab browser cookies, passwords, emails, drop Cobalt Strike, enable lateral movement, and turn the infected machine into a proxy for C2 traffic.
See Also: All Windows versions impacted by new LPE zero-day vulnerability Riding the SquirrelSentinel Labs published a report on the rise of the SquirrelWaffle malware loader, linking it directly to QBot, which is dropped as second stage malware.

Researchers at Minerva Labs have also drawn a similar conclusion, seeing the following delivery scheme:
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/infection%20chain.jpg
<figcaptionSquirrelWaffle’s infection chain
Source: Minerva Labs
See Also: Offensive Security Tool: Pentesting Tools SquirrelWaffle also uses VBA macros to execute a PowerShell command that retrieves its payload and launches it.

Unlike Emotet, who used a wide range of phishing lures, the SquirrelWaffle is not doing a great job creating convincing spam mails, keeping the infections in check.

The creation of more convincing phishing emails could be outsourced or quickly resolved by contacting an expert in that part of phishing operations, leading to a more significant number of SquirrelWaffle infections.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/face-malware-virus-infected-red-network-90x90.jpg BotenaGo botnet targets millions of IoT devices with 33 exploits3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.c[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking QBot returns for a new wave of infections using Squirrelwaffle https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png QBot returns for a new wave of infections using SquirrelwafflePost Views: 112…
om-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Pwn2OwnBlur-90x90.png Pwn2Own – Over 1 million dollars in Bounties, Samsung Galaxy S21 hacked twice, Printer plays AC/DC1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/maxresdefault-1024x576-1-90x90.jpg Microsoft Exchange ProxyShell exploits used to deploy Babuk ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Mekotio-Banking-Trojan-90x90.png Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/GitLab-90x90.jpg Over 30,000 GitLab servers still unpatched against critical bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/trojan-source-invisible-vulnerabilities-in-most-code-showcase_image-7-a-17833-90x90.jpg ‘Trojan Source’ attack method can hide bugs into open-source code2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-4-90x90.jpg Chaos ransomware targets gamers via fake Minecraft alt lists2 weeks ago
The post QBot returns for a new wave of infections using Squirrelwaffle first appeared on Black Hat Ethical Hacking.
Cumulus - Web Application Weakness Monitoring, It Would Be Working By Add Just 3 Codelines
http://www.kitploit.com/2021/11/cumulus-web-application-weakness.html