Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.3K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
How do I crack an pi4 password I own

So I have a pi4 and I forgot the password is there any way for me to crack the password without popping out the sd card?

submitted by /u/row_bert
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Anyone else who currently working?

Anyone else who currently working as a penetration tester in a company, not freelance. how the environment is, is it amazing? or hard? and what devices are you testing? networks or only web app or Software security from memory corruption...?

last question: How can i get a job, programming or penetration testing or sysadmin?

submitted by /u/Odd-Pepper-3133
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
So,any tips for implementing this class prank?

Basically we have these speakers in class that get the signals from the teacher's mic. So I was thinking of maybe playing a song on those speakers by sending the same frequency as the teacher's mic.....only problem idk how to do that.....so yeah any help?

submitted by /u/Unit-Superb
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Android malware BrazKing returns as a stealthier banking trojan

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Android malware BrazKing returns as a stealthier banking trojanPost Views: 146
Reading Time: 1 Minute
​The BrazKing Android banking trojan has returned with dynamic banking overlays and a new implementation trick that enables it to operate without requesting risky permissions.
A new malware sample was analyzed by IBM Trusteer researchers who found it outside the Play Store, on sites where people end up after receiving smishing (SMS) messages.

These HTTPS sites warn the prospective victim that they are using an outdated Android version and offer an APK that will allegedly update them to the latest version.
https://www.bleepstatic.com/images/news/u/1220909/Security/message.jpg
Only asking for a single permissionIf the user approves “downloads from unknown sources,” the malware is dropped on the device and requests access to the ‘Accessibility Service’.

This permission is abused to capture screenshots and keystrokes without requesting any additional permissions that would risk raising suspicions.

More specifically, the accessibility service is used by BrazKing for the following malicious activity:

* Dissect the screen programmatically instead of taking screenshots in picture format. This can be done programmatically but on a non-rooted device that would require the explicit approval of the user.
* Keylogger capabilities by reading the views on the screen.
* RAT capabilities—BrazKing can manipulate the target banking application by tapping buttons or keying text in.
* Read SMS without the ‘android.permission.READ_SMS’ permission by reading text messages that appear on the screen. This can give actors access to 2FA codes.
* Read contact lists without ‘android.permission.READ_CONTACTS’ permission by reading the contacts on the “Contacts” screen.

Starting on Android 11, Google has categorized the list of installed apps as sensitive information, so any malware that attempts to fetch it is flagged by Play Protect as malicious.
See Also: WordPress sites are being hacked in fake ransomware attacks
This is a new problem for all banking overlaying trojans that need to determine which bank apps are installed on the infected device to serve matching login screens.

BrazKing no longer uses the ‘getinstalledpackages’ API request as it used to but instead uses the screen dissection feature to view what apps are installed on the infected device.

When it comes to overlaying, BrazKing now does it without the ‘System_Alert_Window’ permission, so it can’t overlay a fake screen on top of the original app as other trojans do.

Instead, it loads the fake screen as an URL from the attacker’s server in a webview window, added from within the accessibility service. This covers the app and all its windows but doesn’t force an exit from it.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/overlaying.png
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Android malware BrazKing returns as a stealthier banking trojan https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Android malware BrazKing returns as a stealthier banking trojanPost Views:…
e banking apps or sites or add support for new banks.
See Also: Offensive Security Tool: Pentesting Tools Obfuscation and resistance to deletionThe new version of BrazKing protects internal resources by applying an XOR operation using a hardcoded key and then also encodes them with Base64.

Analysts can quickly reverse these steps, but they still help the malware go unnoticed when nested in the victim’s device.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/obfuscated%20strings.png
(Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/redcurl-90x90.jpg RedCurl corporate espionage hackers resume attacks with updated tools21 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-1-90x90.jpg WordPress sites are being hacked in fake ransomware attacks2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ECS-Instance-Types-90x90.png Alibaba ECS instances actively hijacked by cryptomining malware3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-90x90.jpg QBot returns for a new wave of infections using Squirrelwaffle4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/face-malware-virus-infected-red-network-90x90.jpg BotenaGo botnet targets millions of IoT devices with 33 exploits1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Pwn2OwnBlur-90x90.png Pwn2Own – Over 1 million dollars in Bounties, Samsung Galaxy S21 hacked twice, Printer plays AC/DC2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/maxresdefault-1024x576-1-90x90.jpg Microsoft Exchange ProxyShell exploits used to deploy Babuk ransomware2 weeks ago
The post Android malware BrazKing returns as a stealthier banking trojan first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can anyone provide some guidance?

I’d like a bot that I could use to send mass messages with an account on discord. For an example, I would input my login info on the bot, type a message or image, and have it bomb the server threads with it.

submitted by /u/Icy-Bat3449
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video