Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
picoCTF write up: Insp3ct0r
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Note: You should not copy flag from here just find one by following steps mentioned here.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
picoCTF write up: Insp3ct0r
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Note: You should not copy flag from here just find one by following steps mentioned here.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
picoCTF write up: Insp3ct0r
Note: You should not copy flag from here just find one by following steps mentioned here.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A network of connectivity and innovation with Metapulse
https://cdn-images-1.medium.com/max/1600/1*hHsRCauEu4Yu4_FL8gGSjQ.png
As a security company our aim is to secure digital assets within enterprise conditions, as we believe security is a top priority …
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
A network of connectivity and innovation with Metapulse
https://cdn-images-1.medium.com/max/1600/1*hHsRCauEu4Yu4_FL8gGSjQ.png
As a security company our aim is to secure digital assets within enterprise conditions, as we believe security is a top priority …
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
A network of connectivity and decentralization with Metapulse
As a security company our aim is to secure digital assets within enterprise conditions, as we believe security is a top priority …
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploring DDOS: Denial of service attack
https://cdn-images-1.medium.com/max/961/0*pt95SuOO7SMfu9Fd
Ever stumbled upon such type of message when trying to visit any site ?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Exploring DDOS: Denial of service attack
https://cdn-images-1.medium.com/max/961/0*pt95SuOO7SMfu9Fd
Ever stumbled upon such type of message when trying to visit any site ?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Exploring DDOS: Denial of service attack
Ever stumbled upon such type of message when trying to visit any site ?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My Blog Was Hacked — How Do I Repair It?
https://cdn-images-1.medium.com/max/720/1*G3Z_ULRBJEKffDCsT0IAnQ.jpeg
Nearly everybody with an email ID or even a PC with web has been hacked into sooner or later or the other. It’s anything but a positive…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My Blog Was Hacked — How Do I Repair It?
https://cdn-images-1.medium.com/max/720/1*G3Z_ULRBJEKffDCsT0IAnQ.jpeg
Nearly everybody with an email ID or even a PC with web has been hacked into sooner or later or the other. It’s anything but a positive…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Blog Was Hacked — How Do I Repair It?
Nearly everybody with an email ID or even a PC with web has been hacked into sooner or later or the other. It’s anything but a positive…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Couple of Words Walk Into a Bar
https://cdn-images-1.medium.com/max/1469/1*TTa8hi08ZQcE5tgidwSuNw.jpeg
Hacking YouTube for Google: How to make your job harder for yourself and 10x more fun by Vedant Vaishampayan, Senior Copywriter
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Couple of Words Walk Into a Bar
https://cdn-images-1.medium.com/max/1469/1*TTa8hi08ZQcE5tgidwSuNw.jpeg
Hacking YouTube for Google: How to make your job harder for yourself and 10x more fun by Vedant Vaishampayan, Senior Copywriter
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Couple of Words Walk Into a Bar
Hacking YouTube for Google: How to make your job harder for yourself and 10x more fun by Vedant Vaishampayan, Senior Copywriter
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cyberspace fundamentals and basic cyberdefence strategies
https://cdn-images-1.medium.com/max/2100/0*DIVUFAmJSdgdreRU
Spare a few minutes reading this fundamental article related to cybersecurity.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cyberspace fundamentals and basic cyberdefence strategies
https://cdn-images-1.medium.com/max/2100/0*DIVUFAmJSdgdreRU
Spare a few minutes reading this fundamental article related to cybersecurity.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyberspace fundamentals and basic cyberdefence strategies
Spare a few minutes reading this fundamental article related to cybersecurity.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
picoCTF write up: Lets warm up
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Note: You should not copy flag from here just find one by following steps mentioned here.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
picoCTF write up: Lets warm up
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Note: You should not copy flag from here just find one by following steps mentioned here.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
picoCTF write up: Lets warm up
Note: You should not copy flag from here just find one by following steps mentioned here.
hacking: security in practice
Learning Go vs Python
Obviously asking this in other pure programming subs will boil down to preference, but what about the hacking/exploit area?
I just picked up that humble bundle that contained a blackhat python book and the blackhat go book and want to give one a try.
I know python from a developer standpoint and only the very basics of go (I made it to loops before I stopped).
If I was to start on either, is there an advantage to one or the other? Python is more common and even comes preinstalled on a lot of stuff. But go has some interest since it’s new.
submitted by /u/space_wiener
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Learning Go vs Python
Obviously asking this in other pure programming subs will boil down to preference, but what about the hacking/exploit area?
I just picked up that humble bundle that contained a blackhat python book and the blackhat go book and want to give one a try.
I know python from a developer standpoint and only the very basics of go (I made it to loops before I stopped).
If I was to start on either, is there an advantage to one or the other? Python is more common and even comes preinstalled on a lot of stuff. But go has some interest since it’s new.
submitted by /u/space_wiener
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Learning Go vs Python
Obviously asking this in other pure programming subs will boil down to preference, but what about the hacking/exploit area? I just picked up that...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Android banking malware infects 300,000 Google Play users
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Android banking malware infects 300,000 Google Play usersPost Views: 113
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/BF2.gif
Reading Time: 1 Minute
Malware campaigns distributing Android trojans that steals online bank credentials have infected almost 300,000 devices through malicious apps pushed via Google’s Play Store.
The Android banking trojans delivered onto compromised devices attempt to steal users’ credentials when they log in to an online banking or cryptocurrency apps. Credential theft is commonly done using fake bank login form overlays displayed on top of the legitimate apps’ login screens.
The stolen credentials are then sent back to the attacker’s servers, where they are collected to be sold to other threat actors or used to steal cryptocurrency and money from victims’ accounts. Evolving tactics to evade detectionIn a new report by ThreatFabric, researchers explain how they discovered four different malware dropper campaigns distributing banking trojans on the Google Play Store.
While threat actors infiltrating the Google Play Store with Android banking trojans are nothing new, recent changes to Google’s policies and increased policing have forced threat actors to evolve their tactics to evade detection.
This evolution includes creating small realistic-looking apps that focus on common themes such as fitness, cryptocurrency, QR codes, and PDF scanning to trick users into installing the app. Then, to add further legitimacy to the apps, the threat actors create websites that fit the theme of the app to help pass reviews by Google.
See Also: Complete Offensive Security and Ethical Hacking Course
Furthermore, ThreatFabric has seen these apps only being distributed to specific regions or at later dates to further evade detection by Google and antivirus vendors.
“This policing by Google has forced actors to find ways to significantly reduce the footprint of dropper apps. Besides improved malware code efforts, Google Play distribution campaigns are also more refined than previous campaigns,” ThreatFabric researchers explain in their new report.
“For example, by introducing carefully planned small malicious code updates over a longer period in Google Play, as well as sporting a dropper C2 backend to fully match the theme of the dropper app (for example a working Fitness website for a workout focused app).”
However, once these “dropper” apps are installed, they will silently communicate with the threat actor’s server to receive commands. When ready to distribute the banking trojan, the threat actor’s server will tell the installed app to perform a fake “update” that “drops” and launches the malware on the Android device.
https://www.bleepstatic.com/images/news/security/a/android/300k-banking-trojan/fake-banking-trojan-update.jpg
16 apps infect 300,000 devicesSince July 2021, ThreatFabric has these fake apps dropping four different banking trojans named ‘Alien’, ‘Hydra’, ‘Ermac’, and and ‘Anatsa’ through sixteen different apps.
https://www.bleepstatic.com/images/news/security/a/android/300k-banking-trojan/tf-timeline.jpg
Timeline of malware campaigns on Google Play
Source: ThreatFabric
The “dropper” apps known to be used during these malware distribution campaigns are:
* Two Factor Authenticator
* Protection Guard
* QR CreatorScanner
* Master Scanner
* QR Scanner 2021[...]
___________________________
@hacking_Attack
@Hacking_Video
Android banking malware infects 300,000 Google Play users
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Android banking malware infects 300,000 Google Play usersPost Views: 113
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/BF2.gif
Reading Time: 1 Minute
Malware campaigns distributing Android trojans that steals online bank credentials have infected almost 300,000 devices through malicious apps pushed via Google’s Play Store.
The Android banking trojans delivered onto compromised devices attempt to steal users’ credentials when they log in to an online banking or cryptocurrency apps. Credential theft is commonly done using fake bank login form overlays displayed on top of the legitimate apps’ login screens.
The stolen credentials are then sent back to the attacker’s servers, where they are collected to be sold to other threat actors or used to steal cryptocurrency and money from victims’ accounts. Evolving tactics to evade detectionIn a new report by ThreatFabric, researchers explain how they discovered four different malware dropper campaigns distributing banking trojans on the Google Play Store.
While threat actors infiltrating the Google Play Store with Android banking trojans are nothing new, recent changes to Google’s policies and increased policing have forced threat actors to evolve their tactics to evade detection.
This evolution includes creating small realistic-looking apps that focus on common themes such as fitness, cryptocurrency, QR codes, and PDF scanning to trick users into installing the app. Then, to add further legitimacy to the apps, the threat actors create websites that fit the theme of the app to help pass reviews by Google.
See Also: Complete Offensive Security and Ethical Hacking Course
Furthermore, ThreatFabric has seen these apps only being distributed to specific regions or at later dates to further evade detection by Google and antivirus vendors.
“This policing by Google has forced actors to find ways to significantly reduce the footprint of dropper apps. Besides improved malware code efforts, Google Play distribution campaigns are also more refined than previous campaigns,” ThreatFabric researchers explain in their new report.
“For example, by introducing carefully planned small malicious code updates over a longer period in Google Play, as well as sporting a dropper C2 backend to fully match the theme of the dropper app (for example a working Fitness website for a workout focused app).”
However, once these “dropper” apps are installed, they will silently communicate with the threat actor’s server to receive commands. When ready to distribute the banking trojan, the threat actor’s server will tell the installed app to perform a fake “update” that “drops” and launches the malware on the Android device.
https://www.bleepstatic.com/images/news/security/a/android/300k-banking-trojan/fake-banking-trojan-update.jpg
16 apps infect 300,000 devicesSince July 2021, ThreatFabric has these fake apps dropping four different banking trojans named ‘Alien’, ‘Hydra’, ‘Ermac’, and and ‘Anatsa’ through sixteen different apps.
https://www.bleepstatic.com/images/news/security/a/android/300k-banking-trojan/tf-timeline.jpg
Timeline of malware campaigns on Google Play
Source: ThreatFabric
The “dropper” apps known to be used during these malware distribution campaigns are:
* Two Factor Authenticator
* Protection Guard
* QR CreatorScanner
* Master Scanner
* QR Scanner 2021[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Android banking malware infects 300,000 Google Play users | Black Hat Ethical Hacking
Malware campaigns distributing Android trojans that steals online bank credentials have infected almost 300,000 devices through malicious apps pushed via Google's Play Store.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Android banking malware infects 300,000 Google Play users https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Android banking malware infects 300,000 Google Play usersPost Views: 113 https:…
* QR Scanner
* PDF Document Scanner – Scan to PDF
* PDF Document Scanner
* PDF Document Scanner Free
* CryptoTracker
* Gym and Fitness Trainer
Other malicious apps seen installed by the above droppers and their associated banking trojans are:
* Master Scanner Live (Alien trojan)
* Gym and Fitness Trainer (Alien trojan)
* PDF AI : TEXT RECOGNIZER (Anatsa trojan)
* QR CreatorScanner (Hydra trojan)
* QR CreatorScanner (Ermac trojan)
See Also: Offensive Security Tool: Hashcat During these four months of malicious activity, ThreatFrabric found that the droppers were installed 300,000 times, with some individual droppers installed over 50,000 times.
The number of banks, money transfer apps, cryptocurrency exchanges, cryptocurrency wallets, and mail services is impressive, with approximately 537 online sites and mobile apps targeted for credential theft.
The targeted organizations include Gmail, Chase, Citibank, HSBC, Coinbase, Kraken, Binance, KuCoin, CashApp, Zelle, TrustWallet, MetaMask, and more.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Google has since removed all of these malicious apps from the Play Store and you should also immediately remove them from your Android device if you have any of them installed.
If you have installed any of the above apps, you should immediately remove them from your Android device.
Furthermore, due to the evolving techniques used by Android malware developers, users must pay more attention to the permissions requested by apps and block the install if they seem overly broad.
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/PKM201070290_resize-90x90.jpg Panasonic discloses data breach after network hack1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/0_Windows-headpic-90x90.jpg New Windows 10 zero-day gives admin rights, gets unofficial patch2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/1_pD_YMyWDg8A2grOrbaNS6g-90x90.jpg New Linux malware hides in cron jobs with invalid dates5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Vulnerability-RCE-MSHTML-90x90.jpg Hackers exploit Microsoft MSHTML bug to steal Google, Instagram creds6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/windows-hacking-90x90.jpg Malware now trying to exploit new Windows Installer zero-day1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/https___specials-images.forbesimg.com_imageserve_503493618_Green-binary-code-on-screen-with-Zero-Day-highlighted-in-red-as-viewed-under-a_960x0-90x90.jpg New Windows zero-day with public exploit lets you become an admin1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers hacked in internal reply-chain attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/slembunk-android-banking-trojan-targets-31-banks-across-the-world-497808-3-90x90.jpg Android malware BrazKing returns as a stealthier banking trojan2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/redcurl-90x90.jpg RedCurl corporate espionage hackers resume attacks with updated tools2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-1-90x90.jpg WordPress sites are being hacked in fake ransomware attacks2 weeks ago
The post Android banking malware infects 300,000 Google Play users first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* PDF Document Scanner – Scan to PDF
* PDF Document Scanner
* PDF Document Scanner Free
* CryptoTracker
* Gym and Fitness Trainer
Other malicious apps seen installed by the above droppers and their associated banking trojans are:
* Master Scanner Live (Alien trojan)
* Gym and Fitness Trainer (Alien trojan)
* PDF AI : TEXT RECOGNIZER (Anatsa trojan)
* QR CreatorScanner (Hydra trojan)
* QR CreatorScanner (Ermac trojan)
See Also: Offensive Security Tool: Hashcat During these four months of malicious activity, ThreatFrabric found that the droppers were installed 300,000 times, with some individual droppers installed over 50,000 times.
The number of banks, money transfer apps, cryptocurrency exchanges, cryptocurrency wallets, and mail services is impressive, with approximately 537 online sites and mobile apps targeted for credential theft.
The targeted organizations include Gmail, Chase, Citibank, HSBC, Coinbase, Kraken, Binance, KuCoin, CashApp, Zelle, TrustWallet, MetaMask, and more.
See Also: Hacking stories – Operation Troy – How researchers linked the cyberattacks Google has since removed all of these malicious apps from the Play Store and you should also immediately remove them from your Android device if you have any of them installed.
If you have installed any of the above apps, you should immediately remove them from your Android device.
Furthermore, due to the evolving techniques used by Android malware developers, users must pay more attention to the permissions requested by apps and block the install if they seem overly broad.
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/PKM201070290_resize-90x90.jpg Panasonic discloses data breach after network hack1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/0_Windows-headpic-90x90.jpg New Windows 10 zero-day gives admin rights, gets unofficial patch2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/1_pD_YMyWDg8A2grOrbaNS6g-90x90.jpg New Linux malware hides in cron jobs with invalid dates5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Microsoft-Vulnerability-RCE-MSHTML-90x90.jpg Hackers exploit Microsoft MSHTML bug to steal Google, Instagram creds6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/windows-hacking-90x90.jpg Malware now trying to exploit new Windows Installer zero-day1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/https___specials-images.forbesimg.com_imageserve_503493618_Green-binary-code-on-screen-with-Zero-Day-highlighted-in-red-as-viewed-under-a_960x0-90x90.jpg New Windows zero-day with public exploit lets you become an admin1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers hacked in internal reply-chain attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/slembunk-android-banking-trojan-targets-31-banks-across-the-world-497808-3-90x90.jpg Android malware BrazKing returns as a stealthier banking trojan2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/redcurl-90x90.jpg RedCurl corporate espionage hackers resume attacks with updated tools2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/ezgif.com-gif-maker-1-1-90x90.jpg WordPress sites are being hacked in fake ransomware attacks2 weeks ago
The post Android banking malware infects 300,000 Google Play users first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Cross-site request forgery (CSRF)
https://medium.com/@shubhamkumarks1999/cross-site-request-forgery-csrf-403574f8aded?source=rss------bug_bounty-5
What is CSRF?Continue reading on Medium » (https://medium.com/@shubhamkumarks1999/cross-site-request-forgery-csrf-403574f8aded?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@shubhamkumarks1999/cross-site-request-forgery-csrf-403574f8aded?source=rss------bug_bounty-5
What is CSRF?Continue reading on Medium » (https://medium.com/@shubhamkumarks1999/cross-site-request-forgery-csrf-403574f8aded?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-site request forgery (CSRF)
What is CSRF?
Platypus Testnet Bug Bounty Winners Announcement
https://medium.com/@Platypus.finance/platypus-testnet-bug-bounty-winners-announcement-966a8649da11?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Platypus.finance/platypus-testnet-bug-bounty-winners-announcement-966a8649da11?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Platypus Testnet Bug Bounty Winners Announcement
Our brilliant white hat hackers have been on a roll!🔥🔥
Our brilliant white hat hackers have been on a roll!🔥🔥Continue reading on Medium » (https://medium.com/@Platypus.finance/platypus-testnet-bug-bounty-winners-announcement-966a8649da11?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Platypus Testnet Bug Bounty Winners Announcement
Our brilliant white hat hackers have been on a roll!🔥🔥