Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
GoDaddy Breach Exposes SSL Keys of Managed WordPress Hosting Customers

The incident, which affected 1.2 million users, raises concerns about domain impersonation attacks and other malicious activities.
디파인, 이뮨파이(Immunefi)와 버그 바운티 프로그램 출시

보안은 모든 암호화폐 생태계에서 다루고 있는 중요한 분야입니다. 보안은 플랫폼이 안전하고 생태계와 관련된 모든 유저를 위해 각종 버그를 발견하고 검증하여 안전한 사용을 약속하도록 지원합니다. 버그 바운티 프로그램은 다양한 웹사이트, 조직 및…Continue reading on DeFine Platform »
Read more...
Dark Reading: Attacks/Breaches
Pentagon Partners With GreyNoise to Investigate Internet Scans

With a new 5-year $30 million contract, GreyNoise Intelligence will assist multiple teams across the Department of Defense plans in a defensive capacity.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Computer Hacking Forensic Investigator CHFI Certification | Hacking Course

CHFI Certification verifies security professionals’ knowledge of computer forensics in general, including reporting cyber-attacks and…

Continue reading on Medium »
hacking: security in practice
If I want to learn to hack something specific, where do I go?

Hello Im new here and new to hacking in general. This has always fascinated me and these paywalls to read articles you need or for access to news websites or whatever else are really annoying. I would like to manage to have full access to sites like these and want to learn how its done. Im interested in hacking since I was 11 now im 19 so never managed to do anything. I would be happy for advice/information. Thank you very much :)

submitted by /u/mattx_1
[link] [comments]
hacking: security in practice
Networking MOOCs

I am currently looking for some MOOCs that teach networking concepts in Network+ and other common networking certifications. While I'm not completely network illiterate, i.e. I've done some easy TryHackMe and HackTheBoxes, I've found that I often come across obstacles that would be easy to resolve with basic network knowledge. Even though I could just study for a Network+ certification, I'm currently a student in high school and thus do not have the time commitment to do so. Thanks!

submitted by /u/AviatingFotographer
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Windows zero-day with public exploit lets you become an admin

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New Windows zero-day with public exploit lets you become an adminPost Views: 404
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/BF-1.gif
Reading Time: 1 Minute
A security researcher has publicly disclosed an exploit for a new Windows zero-day local privilege elevation vulnerability that gives admin privileges in Windows 10, Windows 11, and Windows Server.
BleepingComputer has tested the exploit and used it to open to command prompt with SYSTEM privileges from an account with only low-level ‘Standard’ privileges.

Using this vulnerability, threat actors with limited access to a compromised device can easily elevate their privileges to help spread laterally within the network.

The vulnerability affects all supported versions of Windows, including Windows 10, Windows 11, and Windows Server 2022. Researcher releases bypass to patched vulnerabilityAs part of the November 2021 Patch Tuesday, Microsoft fixed a ‘Windows Installer Elevation of Privilege Vulnerability’ vulnerability tracked as CVE-2021-41379.

This vulnerability was discovered by security researcher Abdelhamid Naceri, who found a bypass to the patch and a more powerful new zero-day privilege elevation vulnerability after examining Microsoft’s fix.

Yesterday, Naceri published a working proof-of-concept exploit for the new zero-day on GitHub, explaining that it works on all supported versions of Windows.

“This variant was discovered during the analysis of CVE-2021-41379 patch. the bug was not fixed correctly, however, instead of dropping the bypass,” explains Naceri in his writeup. “I have chosen to actually drop this variant as it is more powerful than the original one.”
See Also: Complete Offensive Security and Ethical Hacking Course
Furthermore, Naceri explained that while it is possible to configure group policies to prevent ‘Standard’ users from performing MSI installer operations, his zero-day bypasses this policy and will work anyway.

BleepingComputer tested Naceri’s ‘InstallerFileTakeOver’ exploit, and it only took a few seconds to gain SYSTEM privileges from a test account with ‘Standard’ privileges, as demonstrated in the video below.
The test was performed on a fully up-to-date Windows 10 21H1 build 19043.1348 install.

When BleepingComputer asked Naceri why he publicly disclosed the zero-day vulnerability, we were told he did it out of frustration over Microsoft’s decreasing payouts in their bug bounty program.

“Microsoft bounties has been trashed since April 2020, I really wouldn’t do that if MSFT didn’t take the decision to downgrade those bounties,” explained Naceri.
See Also: Microsoft Exchange servers hacked in internal reply-chain attacks Under Microsoft's new bug bounty program one of my zerodays has gone from being worth $10,000 to $1,000 💀

— MalwareTech (@MalwareTechBlog) July 27, 2020
BE CAREFUL! Microsoft will reduce your bounty at any time! This is a Hyper-V RCE vulnerability be able to trigger from a Guest Machine, but it is just eligible for a $5000.00 bounty award under the Windows Insider Preview Bounty Program. Unfair! @msftsecresponse @msftsecurity pic.twitter.com/sJw3cjsliF

— rthhh (@rthhh17) November 9, 2021
BleepingComputer has reached out to Microsoft about the disclosed zero-day and will update the article if we receive a reply.

As is typical with zero days, Microsoft will likely fix the vulnerability in a future Patch Tuesday update.
See Also: Offensive Security Tools: Awesome Bug Bounty Tools However, Naceri warned that it i[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New Windows zero-day with public exploit lets you become an admin https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New Windows zero-day with public exploit lets you become an adminPost Views:…
s not advised to try and fix the vulnerability by attempting to patch the binary as it will likely break the installer.

“The best workaround available at the time of writing this is to wait Microsoft to release a security patch, due to the complexity of this vulnerability,” explained Naceri.

“Any attempt to patch the binary directly will break windows installer. So you better wait and see how Microsoft will screw the patch again.”
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers hacked in internal reply-chain attacks1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/slembunk-android-banking-trojan-targets-31-banks-across-the-world-497808-3-90x90.jpg Android malware BrazKing returns as a stealthier banking trojan4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/redcurl-90x90.jpg RedCurl corporate espionage hackers resume attacks with updated tools5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-1-90x90.jpg WordPress sites are being hacked in fake ransomware attacks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ECS-Instance-Types-90x90.png Alibaba ECS instances actively hijacked by cryptomining malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-90x90.jpg QBot returns for a new wave of infections using Squirrelwaffle1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/face-malware-virus-infected-red-network-90x90.jpg BotenaGo botnet targets millions of IoT devices with 33 exploits2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-90x90.jpg Microsoft patches Excel zero-day used in attacks, asks Mac users to wait2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Exchange-90x90.png Microsoft urges Exchange admins to patch bug exploited in the wild2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/b57e07db-82a4-43ef-be64-a15c45b31804-90x90.jpg Robinhood discloses data breach impacting 7 million customers2 weeks ago
The post New Windows zero-day with public exploit lets you become an admin first appeared on Black Hat Ethical Hacking.
A business logic error bug worth 600$

Hey all,Continue reading on Medium »
Read more...