Learn how to find bug in password reset functionContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/exploiting-password-reset-bugs-1936991d0ab0?source=rss------bug_bounty-5)
Tips/Advice for a new Pen Tester?
https://www.reddit.com/r/Pentesting/comments/quxo38/tipsadvice_for_a_new_pen_tester/
<!-- SC_OFF -->Hey y'all, I'm in my last semester of college and will be working as a junior pen tester in January. I was wondering if anyone had any advice for me when I enter the work force? To be completely honest, I am incredibly excited to start working but I also feel incredibly nervous because I feel that I'm going to fuck up a lot. My managers told me that since I'm at the bottom of the totem pole and I'm coming straight out of college with no experience, their expectations for me are low as long as I do my best. I also think that my fears stem from getting a pen tester position so quickly out of college- most pen testers started out in IT or in SOC while I literally have no experience in any professional field. In some ways, I feel that I just got really lucky with my interview. Anything I should practice on before I start working? Any tools that I should familiarize myself with? Any books/websites I should read/follow? I've been practicing with HackTheBox/TryHackMe since June. I'm also studying for the OSCP but I don't feel close to being ready and may not sit for it until next summer at the earliest. <!-- SC_ON --> submitted by /u/j1mmyava1on (https://www.reddit.com/user/j1mmyava1on)
[link] (https://www.reddit.com/r/Pentesting/comments/quxo38/tipsadvice_for_a_new_pen_tester/) [comments] (https://www.reddit.com/r/Pentesting/comments/quxo38/tipsadvice_for_a_new_pen_tester/)
https://www.reddit.com/r/Pentesting/comments/quxo38/tipsadvice_for_a_new_pen_tester/
<!-- SC_OFF -->Hey y'all, I'm in my last semester of college and will be working as a junior pen tester in January. I was wondering if anyone had any advice for me when I enter the work force? To be completely honest, I am incredibly excited to start working but I also feel incredibly nervous because I feel that I'm going to fuck up a lot. My managers told me that since I'm at the bottom of the totem pole and I'm coming straight out of college with no experience, their expectations for me are low as long as I do my best. I also think that my fears stem from getting a pen tester position so quickly out of college- most pen testers started out in IT or in SOC while I literally have no experience in any professional field. In some ways, I feel that I just got really lucky with my interview. Anything I should practice on before I start working? Any tools that I should familiarize myself with? Any books/websites I should read/follow? I've been practicing with HackTheBox/TryHackMe since June. I'm also studying for the OSCP but I don't feel close to being ready and may not sit for it until next summer at the earliest. <!-- SC_ON --> submitted by /u/j1mmyava1on (https://www.reddit.com/user/j1mmyava1on)
[link] (https://www.reddit.com/r/Pentesting/comments/quxo38/tipsadvice_for_a_new_pen_tester/) [comments] (https://www.reddit.com/r/Pentesting/comments/quxo38/tipsadvice_for_a_new_pen_tester/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I passed the OSCP certification in my first attempt, and hacked the 5/5 targets of the exam
https://cdn-images-1.medium.com/max/600/1*10P4lu0Ch9_Jnn40ipnWhw.png
Hello everyone, i’m a french cybersecurity engineer and you can ping me as jedus0r 😊
Continue reading on Medium »
How I passed the OSCP certification in my first attempt, and hacked the 5/5 targets of the exam
https://cdn-images-1.medium.com/max/600/1*10P4lu0Ch9_Jnn40ipnWhw.png
Hello everyone, i’m a french cybersecurity engineer and you can ping me as jedus0r 😊
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploiting Password Reset Bugs
https://cdn-images-1.medium.com/max/1200/1*UlAAtRNWBzj0Iu8ldQqQbQ.jpeg
Learn how to find bug in password reset function
Continue reading on InfoSec Write-ups »
Exploiting Password Reset Bugs
https://cdn-images-1.medium.com/max/1200/1*UlAAtRNWBzj0Iu8ldQqQbQ.jpeg
Learn how to find bug in password reset function
Continue reading on InfoSec Write-ups »
hacking: security in practice
Kik hack?
How would a person go abouts hacking a kik?
submitted by /u/Designer_Emu2975
[link] [comments]
Kik hack?
How would a person go abouts hacking a kik?
submitted by /u/Designer_Emu2975
[link] [comments]
reddit
Kik hack?
How would a person go abouts hacking a kik?
Cve-2021-35042 | django sqli
https://www.reddit.com/r/redteamsec/comments/qv1dvj/cve202135042_django_sqli/
submitted by /u/Pure-Hair5006 (https://www.reddit.com/user/Pure-Hair5006)
[link] (https://youtu.be/Wlr1VQCo_5g) [comments] (https://www.reddit.com/r/redteamsec/comments/qv1dvj/cve202135042_django_sqli/)
https://www.reddit.com/r/redteamsec/comments/qv1dvj/cve202135042_django_sqli/
submitted by /u/Pure-Hair5006 (https://www.reddit.com/user/Pure-Hair5006)
[link] (https://youtu.be/Wlr1VQCo_5g) [comments] (https://www.reddit.com/r/redteamsec/comments/qv1dvj/cve202135042_django_sqli/)
Dinosaur Eggs’ LiquidityPool Loophole Explained
https://medium.com/amber-group/dinosaur-eggs-liquiditypool-loophole-explained-ac6ef10faafe?source=rss------bug_bounty-5
https://medium.com/amber-group/dinosaur-eggs-liquiditypool-loophole-explained-ac6ef10faafe?source=rss------bug_bounty-5
In the summer of 2020, Chef Nomi (@NomiChef) [1] presented the MasterChef contract [2], one of the most redeployed contracts during the…Continue reading on Amber Group » (https://medium.com/amber-group/dinosaur-eggs-liquiditypool-loophole-explained-ac6ef10faafe?source=rss------bug_bounty-5)
Dinosaur Eggs’ LiquidityPool Loophole Explained
In the summer of 2020, Chef Nomi (@NomiChef) 1 presented the MasterChef contract 2, one of the most redeployed contracts during the…Continue reading on Amber Group »
Read more...
In the summer of 2020, Chef Nomi (@NomiChef) 1 presented the MasterChef contract 2, one of the most redeployed contracts during the…Continue reading on Amber Group »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“The Most Sophisticated Smartphone Attack” All you need to know about the infamous spyware…
https://cdn-images-1.medium.com/max/2600/1*FTZebKxQl7iX-sSX2paT1Q.jpeg
The 21st century has witnessed major advancements in the world of technology. This rapid evolution in technology has influenced all…
Continue reading on InfoSec Write-ups »
“The Most Sophisticated Smartphone Attack” All you need to know about the infamous spyware…
https://cdn-images-1.medium.com/max/2600/1*FTZebKxQl7iX-sSX2paT1Q.jpeg
The 21st century has witnessed major advancements in the world of technology. This rapid evolution in technology has influenced all…
Continue reading on InfoSec Write-ups »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Alibaba ECS instances actively hijacked by cryptomining malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Alibaba ECS instances actively hijacked by cryptomining malwarePost Views: 92
Reading Time: 1 Minute
Threat actors are hijacking Alibaba Elastic Computing Service (ECS) instances to install cryptominer malware and harness the available server resources for their own profit.
Alibaba is a Chinese technology giant with a global market presence, with its cloud services being used primarily in southeast Asia.
In particular, the ECS service is marketed as offering fast memory, Intel CPUs, and promising low-latency operations. Even better, to protect against malware such as cryptominers, ECS comes with a pre-installed security agent. Hackers remove ECS security agent to install minersAccording to a report by Trend Micro, one of the issues with Alibaba ECS is the lack of different privilege levels configured on an instance, with all instances offering root access by default.
This makes it possible for threats actors who gain access to login credentials to access the target server via SSH as root without any preparatory (escalation of privilege) work.
See Also: Complete Offensive Security and Ethical Hacking Course
“The threat actor has the highest possible privilege upon compromise, including vulnerability exploitation, any misconfiguration issue, weak credentials or data leakage,” explains Trend Micro’s report.
Furthermore, these elevated privileges allow the threat actors to create firewall rules that drop incoming packets from IP ranges belonging to internal Alibaba servers to prevent the installed security agent from detecting suspicious behavior.
The threat actors can then run scripts that stop the security agent on the compromised device.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/remove_protection.jpg
<figcaptionDisabling the security agent on ECS
Source: Trend Micro
Given how easy it is to plant kernel module rootkits and cryptojacking malware due to the elevated privileges, it is no surprise that multiple threat actors compete to take over Alibaba Cloud ECS instances.
See Also: All Windows versions impacted by new LPE zero-day vulnerability Trend Micro has also observed scripts looking for processes running on specific ports commonly used by malware and backdoors and terminating the associated processes to remove competing malware.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/mining.png
<figcaptionCryptojacking malware tuning an ECS instance and terminating processes
Source: Trend Micro
Another ECS feature exploited by the actors is an auto-scaling system that enables the service to automatically adjust computing resources based on the volume of user requests.
This is to help prevent service interruptions and hiccups from sudden traffic burdens, but it’s an opportunity for cryptojackers.
By abusing this when it’s active on the targeted account, the actors can scale up their Monero mining power and incur additional costs to the instance owner.
Considering that the billing cycles are monthly in the best-case scenario, it would take the victim some time to realize the problem and take action.
When auto-scaling isn’t available, mining will cause a more immediate and noticeable slow-down effect as the miners utilize the available CPU power.
See Also: Offensive Security Tool: Pentesting Tools All cloud services should be vettedAlibaba ECS is yet another case of a cloud service targeted by cryptominers, with other notable recent campaigns targeting Docker and Huawei Cloud.
Trend Micr[...]
Alibaba ECS instances actively hijacked by cryptomining malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Alibaba ECS instances actively hijacked by cryptomining malwarePost Views: 92
Reading Time: 1 Minute
Threat actors are hijacking Alibaba Elastic Computing Service (ECS) instances to install cryptominer malware and harness the available server resources for their own profit.
Alibaba is a Chinese technology giant with a global market presence, with its cloud services being used primarily in southeast Asia.
In particular, the ECS service is marketed as offering fast memory, Intel CPUs, and promising low-latency operations. Even better, to protect against malware such as cryptominers, ECS comes with a pre-installed security agent. Hackers remove ECS security agent to install minersAccording to a report by Trend Micro, one of the issues with Alibaba ECS is the lack of different privilege levels configured on an instance, with all instances offering root access by default.
This makes it possible for threats actors who gain access to login credentials to access the target server via SSH as root without any preparatory (escalation of privilege) work.
See Also: Complete Offensive Security and Ethical Hacking Course
“The threat actor has the highest possible privilege upon compromise, including vulnerability exploitation, any misconfiguration issue, weak credentials or data leakage,” explains Trend Micro’s report.
Furthermore, these elevated privileges allow the threat actors to create firewall rules that drop incoming packets from IP ranges belonging to internal Alibaba servers to prevent the installed security agent from detecting suspicious behavior.
The threat actors can then run scripts that stop the security agent on the compromised device.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/remove_protection.jpg
<figcaptionDisabling the security agent on ECS
Source: Trend Micro
Given how easy it is to plant kernel module rootkits and cryptojacking malware due to the elevated privileges, it is no surprise that multiple threat actors compete to take over Alibaba Cloud ECS instances.
See Also: All Windows versions impacted by new LPE zero-day vulnerability Trend Micro has also observed scripts looking for processes running on specific ports commonly used by malware and backdoors and terminating the associated processes to remove competing malware.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/mining.png
<figcaptionCryptojacking malware tuning an ECS instance and terminating processes
Source: Trend Micro
Another ECS feature exploited by the actors is an auto-scaling system that enables the service to automatically adjust computing resources based on the volume of user requests.
This is to help prevent service interruptions and hiccups from sudden traffic burdens, but it’s an opportunity for cryptojackers.
By abusing this when it’s active on the targeted account, the actors can scale up their Monero mining power and incur additional costs to the instance owner.
Considering that the billing cycles are monthly in the best-case scenario, it would take the victim some time to realize the problem and take action.
When auto-scaling isn’t available, mining will cause a more immediate and noticeable slow-down effect as the miners utilize the available CPU power.
See Also: Offensive Security Tool: Pentesting Tools All cloud services should be vettedAlibaba ECS is yet another case of a cloud service targeted by cryptominers, with other notable recent campaigns targeting Docker and Huawei Cloud.
Trend Micr[...]