Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Disrupting an Application’s Registration Process in 10 mins

So as usual this writeup will be divided into three sections
Read more...
hacking: security in practice
Free Keylogger that doesn't require admin rights

I need a free keylogger that doesn't require admin rights to run or install.

I want to install some games on my work computer. So I want to capture the admin password as the IT guy enters it when I ask him to install Android Studio or something for me.

submitted by /u/Lucius_47
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Have had a hacker or virus for years that keeps bothering my daily PC use... A huge brain puzzle.

Hey! So i have been annoyed/bothered for almost 6 years now by some virus or hacker, which i found funny or didnt take serious for a long time but now its just starting to be really bothersome, cannot seem to find or remove it myself so i would like some help with this big brain puzzle of a issue...

This hacker/or virus keeps clicking my mouse or alt tabing mid important stuff i am doing on my pc, sometimes ruining my competitive games by taking control of my keyboard and mouse clicking left click, (I have figured out he/it does not move my mouse, or click right click, only i can move the cursor around.) Then it opens up the chat to type a message i have typed some time ago previously.

Its always the same message, it used to be different but now its a message (in my national language): "Cant believe after all these years i still know how to do this..." then proceeds to type lyrics to a song i typed to my friend in browser whatsapp.



So far i have tried scanning with 3 different virus scanners: AVG, Kaspersky, and Avast, none of them find anything wrong, other than my AVG false flagging (i assume) game .exe files that i start as "IDP.Generic". Not sure if this has anything to do with the virus but maybe you might see something i dont see.

I have also tried using free version of a anti-keylogger software, which does/detects nothing when the virus/hacker takes over again.

I have tried removing my keyboard and mouse cable to see if its a driver issue, but it keeps typing and clicking even though both my mouse and keyboard are disconnected.



I have also edited group policies to see if they have any effect to the virus/hacker, from which i am now 90% sure its not a hacker, sometimes i can use my PC normally for weeks straight, but now recently this annoying issue has appeared 6 times within a week so i just reaaally want to get rid of it already.

And for note... I have clean drive reinstalled Windows about year ago, when i upgraded my CPU, but this is still the same virus or hacker from 6 years ago (or feels like it), still bothering my competitive games and pc relaxing sadly.

Have also been trying to look at event viewer if there is happening anything weird, but i really dont understand most of the messages there.

You can suggest anything for me to look and paste here if u think it could solve this issue.

submitted by /u/KingTakius
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to discover Stingers/Man in the Middle Attack?

Hello, I won’t go into too much detail but recently I’ve been noticing weird things happening on my computer. To get to the point…is there any way for me to discover if I am connected to a stinger or involved with a “man in the middle” attack?

Also why does the windows command prompt pop up during start up and disappear within one second? Has been happening for a couple months now.

I have wireshark but I don’t know if it will be any help in detecting stingers. Any advice would be appreciated thanks.

submitted by /u/APDayTrader
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best cyber security training courses?

I'm putting together a top 10 cyber security course ranking for my sub, and I wanted to get the input of those already working within the industry.

I'll be putting together a top 10 for:

* Penetration Testing
* Incident Response
* Threat Intelligence
* Generalist

I'd be really grateful of any and all input!

I'll be posting my findings at r/cybersecuritytraining

submitted by /u/MoaningKnight
[link] [comments]
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New ransomware now being deployed in Log4Shell attacks

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New ransomware now being deployed in Log4Shell attacksPost Views: 183 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The first public case of the Log4j Log4Shell vulnerability used to download and install ransomware has been discovered by researchers.
Last Friday, a public exploit was released for a critical zero-day vulnerability named ‘Log4Shell’ in the Apache Log4j Java-based logging platform. Log4j is a development framework that allows developers to add error and event logging into their Java applications.

The vulnerability allows threat actors to create special JNDI strings that, when read by Log4j, cause the platform to connect to and execute code at the included URL. This allows attackers to easily detect vulnerable devices or execute code supplied by a remote site or via Base64 encoded strings.

While this vulnerability was fixed in Log4j 2.15.0 and even tightened further in Log4j 2.16.0, it is being widely exploited by threat actors to install various malware, including coin miners, botnets, and even Cobalt Strike beacons.
See Also: Complete Offensive Security and Ethical Hacking Course First Log4j exploit installing ransomwareYesterday, BitDefender reported that they found the first ransomware family being installed directly via Log4Shell exploits.

The exploit downloads a Java class from hxxp://3.145.115[.]94/Main.classthat is loaded and executed by the Log4j application.

Once loaded, it would download a .NET binary from the same server to install new ransomware [VirusTotal] named ‘Khonsari.’

This same name is also used as a the extension for encrypted files and in the ransom note, as shown below.
https://www.bleepstatic.com/images/news/ransomware/k/Khonsari/ransom-note.jpg
Likely a wiperRansomware expert Michael Gillespie told BleepingComputer that Khonsari uses valid encryption and is secure, meaning that it is not possible to recover files for free.

However, the ransom note has one oddity – it does not appear to include a way to contact the threat actor to pay a ransom.

Emsisoft analyst Brett Callow pointed out to BleepingComputer that the ransomware is named after and uses contact information for a Louisiana antique shop owner rather than the threat actor.

Therefore, it is unclear if that person is the actual victim of the ransomware attack or listed as a decoy.

Regardless of the reason, as it does not contain legitimate contact information for the threat actors, we believe this is a wiper rather than ransomware.

While this may be the first known instance of the Log4j exploit directly installing ransomware (wiper?), Microsoft has already seen the exploits used to deploy Cobalt Strike beacons.
See Also: Offensive Security Tool: Cobalt Strike
Therefore, it is likely that more advanced ransomware operations are already using the exploits as part of their attacks.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/0d73-article[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New ransomware now being deployed in Log4Shell attacks https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New ransomware now being deployed in Log4Shell attacksPost Views: 183 https://www.b…
-201111-ubuntu-90x90.jpg Attackers can get root by crashing Ubuntu’s AccountsService1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/frame_2_delay-0.5s-90x90.jpg Hackers start pushing malware in worldwide Log4Shell attacks2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-3-90x90.jpg Malicious Notepad++ installers push StrongPity malware5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Kali-Linux-2021.4-Released-90x90.png Kali Linux 2021.4 Released – New Themes and Tools, name-that-hash, truffleHog, S3Scanner, KDE Plasma 5.235 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/cover_image_1598944248.jpg.760x400_q85_crop_upscale-90x90.jpg Hackers infect random WordPress plugins to steal credit cards6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-2-90x90.jpg 27 flaws in USB-over-network SDK affect millions of cloud users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5fdb9e7105edc00d5378b856_kafkalogo-90x90.jpg Apache Kafka Cloud Clusters Expose Sensitive Data for Large Companies1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Excel-als-Malware-Schleuder-Gefahr-durch-XLL-Dateien-Twitter-90x90.png Malicious Excel XLL add-ins push RedLine password-stealing malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-1-90x90.jpg New malware hides as legit nginx process on e-commerce servers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-90x90.jpg Microsoft Exchange servers hacked to deploy BlackByte ransomware2 weeks ago
The post New ransomware now being deployed in Log4Shell attacks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
How I Found multiple SQL Injection with FFUF and Sqlmap in a few minutes

Hello all, hope you’re OK. Our journey today is about how I found multiple SQL Injections in a bug bounty program in just a few minutes…Continue reading on InfoSec Write-ups »
Read more...
How I found XSS vulnerability in Amazon in 5 minutes using shodan

This is my first write-up. I was scrolling through twitter and I found this great tip:Continue reading on Medium »
Read more...
My road map !! Need help
https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/

This isy roadmap to be a red teamer Is anything need to change 1- learn programming ---python ---C/C++ 2-Networking and OS ---Linux ---IT and Networking Basics ---THM Pre security path 3-Web Security ---THM Web fundamentals path ---OWASP TOP 10 Guide 4-Hacking Basics ---THM Complete beginner path ---INE PTS Course ---THM jr penetration tester path 5- Doing CTFs ---THM ---Hack the box ---Velnhub 6-The OSCP 7-Red team Certs ---pentester academy CRTP ---pentester academy CRTE ---Offensive security OSCE ---NOTES--- I am a computer science student I have learned C++ and python scripting And linux command line submitted by /u/Ok_Attempt_3411 (https://www.reddit.com/user/Ok_Attempt_3411)
[link] (https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/) [comments] (https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/)

___________________________
@hacking_Attack
@Hacking_Video