Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Razer Synapse auto install replication with flash drive?

Alright, this is gonna be a long one. Recently, I plugged in a Razer mouse to a school computer, and it immediately opened a window asking to install the software. I knew it wouldn't work because I didn't have administrator, but I did it for shits and giggles. Turns out, it actually fucking worked. I looked this up to see if there was any coverage on it, and there was one article on it. Basically, someone on twitter had plugged in the Razer mouse, and it had prompted them to install the software. When it did, they changed the directory and it brought them to a browsing tab in file explorer, and since it had system permissions, he was able to open a powershell window with full system permissions by shift right clicking and then opening it. I freaked the fuck out because that's a huge vulnerability that doesn't even need a Razer mouse in particular, there are plenty of auto install drivers. So I decided to attempt to replicate it on a usb drive. My first idea was to use a autorun.inf file to open a installer with admin permissions, but there were a few issues, the most prominent being that autorun doesn't actually work with windows 10, lmfao. So I was wondering if there was a way to replicate this with a flash drive? Not for malicious intent, I would report it to the school. I just wanna see if it's possible.

submitted by /u/360Turn
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Trying to Crack iCloud Activation Lock

My friend's mother died. Her iPad had a lot of family photos and memories on it, and it is activation locked with her email and password. Nobody in the family knows what password she could've used. I tried AnyUnlock, but apparently OS version is unsupported by the exploit it uses to bypass the activation.

Does anyone have ideas? It's very important to his family that the device not be wiped so that they can salvage the photos they have on this device. Thanks in advance.

submitted by /u/CDCpup
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Register Here :

Register here for Hackathon 2021Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Malicious Notepad++ installers push StrongPity malware

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Malicious Notepad++ installers push StrongPity malwarePost Views: 162 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The sophisticated hacking group known as StrongPity is circulating laced Notepad++ installers that infect targets with malware.
This hacking group, also known as APT-C-41 and Promethium, was previously seen distributing trojanized WinRAR installers in highly-targeted campaigns between 2016 and 2018, so this technique is not new.

The recent lure involves Notepad++, a very popular free text and source code editor for Windows used in a wide range of organizations.

The discovery of the tampered installer comes from a threat analyst known as ‘blackorbird’ analysts, while Minerva Labs reports on the malware. #APT #StrongPity NotePad++ installer(npp.8.1.7.Installer.x64.exe)
78556a2fc01c40f64f11c76ef26ec3ff
http[:]//advancedtoenableplatform.com pic.twitter.com/eEXZWIObnH

— blackorbird (@blackorbird) November 30, 2021
See Also: Complete Offensive Security and Ethical Hacking Course
Upon executing the Notepad++ installer, the file creates a folder named “Windows Data” under C:\ProgramData\Microsoft, and drops the following three files:

* npp.8.1.7.Installer.x64.exe – the original Notepad++ installation file under C:\Users\Username\AppData\Local\Temp\ folder.
* winpickr.exe – a malicious file under C:\Windows\System32 folder.
* ntuis32.exe – malicious keylogger under C:\ProgramData\Microsoft\WindowsData folder

The installation of the code editor continues as expected, and the victim won’t see anything out of the ordinary that could raise suspicions.

As the setup finishes, a new service named “PickerSrv” is created, establishing the malware’s persistence via startup execution.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/service.png
Stay safeIf you need to use Notepad++, make sure to source an installer from the project’s website.

The software is available on numerous other websites, some of which claim to be the official Notepad++ portals but may include adware or other unwanted software.

The URL that was distributing the laced installer has been taken down following its identification by analysts, but the actors could quickly register a new one.

Follow the same precautions with all software tools you’re using, no matter how niche they are, as sophisticated actors are particularly interested in specialized software cases that are ideal for watering hole attacks.

In this case, the chances of detection from an AV tool on the system would be roughly 50%, so using up-to-date security tools is essential too.
See Also: Ha[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Malicious Notepad++ installers push StrongPity malware https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Malicious Notepad++ installers push StrongPity malwarePost Views: 162 https://www.b…
cking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Kali-Linux-2021.4-Released-90x90.png Kali Linux 2021.4 Released – New Themes and Tools, name-that-hash, truffleHog, S3Scanner, KDE Plasma 5.2311 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/cover_image_1598944248.jpg.760x400_q85_crop_upscale-90x90.jpg Hackers infect random WordPress plugins to steal credit cards1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-2-90x90.jpg 27 flaws in USB-over-network SDK affect millions of cloud users2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5fdb9e7105edc00d5378b856_kafkalogo-90x90.jpg Apache Kafka Cloud Clusters Expose Sensitive Data for Large Companies3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Excel-als-Malware-Schleuder-Gefahr-durch-XLL-Dateien-Twitter-90x90.png Malicious Excel XLL add-ins push RedLine password-stealing malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-1-90x90.jpg New malware hides as legit nginx process on e-commerce servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-90x90.jpg Microsoft Exchange servers hacked to deploy BlackByte ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/80-percent-e-commerce-android-apps-leak-personal-data-765x383-1-90x90.jpg Android banking malware infects 300,000 Google Play users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/PKM201070290_resize-90x90.jpg Panasonic discloses data breach after network hack1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/0_Windows-headpic-90x90.jpg New Windows 10 zero-day gives admin rights, gets unofficial patch2 weeks ago
The post Malicious Notepad++ installers push StrongPity malware first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video