Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New ransomware now being deployed in Log4Shell attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New ransomware now being deployed in Log4Shell attacksPost Views: 183 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The first public case of the Log4j Log4Shell vulnerability used to download and install ransomware has been discovered by researchers.
Last Friday, a public exploit was released for a critical zero-day vulnerability named ‘Log4Shell’ in the Apache Log4j Java-based logging platform. Log4j is a development framework that allows developers to add error and event logging into their Java applications.
The vulnerability allows threat actors to create special JNDI strings that, when read by Log4j, cause the platform to connect to and execute code at the included URL. This allows attackers to easily detect vulnerable devices or execute code supplied by a remote site or via Base64 encoded strings.
While this vulnerability was fixed in Log4j 2.15.0 and even tightened further in Log4j 2.16.0, it is being widely exploited by threat actors to install various malware, including coin miners, botnets, and even Cobalt Strike beacons.
See Also: Complete Offensive Security and Ethical Hacking Course First Log4j exploit installing ransomwareYesterday, BitDefender reported that they found the first ransomware family being installed directly via Log4Shell exploits.
The exploit downloads a Java class from
Once loaded, it would download a .NET binary from the same server to install new ransomware [VirusTotal] named ‘Khonsari.’
This same name is also used as a the extension for encrypted files and in the ransom note, as shown below.
https://www.bleepstatic.com/images/news/ransomware/k/Khonsari/ransom-note.jpg
Likely a wiperRansomware expert Michael Gillespie told BleepingComputer that Khonsari uses valid encryption and is secure, meaning that it is not possible to recover files for free.
However, the ransom note has one oddity – it does not appear to include a way to contact the threat actor to pay a ransom.
Emsisoft analyst Brett Callow pointed out to BleepingComputer that the ransomware is named after and uses contact information for a Louisiana antique shop owner rather than the threat actor.
Therefore, it is unclear if that person is the actual victim of the ransomware attack or listed as a decoy.
Regardless of the reason, as it does not contain legitimate contact information for the threat actors, we believe this is a wiper rather than ransomware.
While this may be the first known instance of the Log4j exploit directly installing ransomware (wiper?), Microsoft has already seen the exploits used to deploy Cobalt Strike beacons.
See Also: Offensive Security Tool: Cobalt Strike
Therefore, it is likely that more advanced ransomware operations are already using the exploits as part of their attacks.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/0d73-article[...]
___________________________
@hacking_Attack
@Hacking_Video
New ransomware now being deployed in Log4Shell attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New ransomware now being deployed in Log4Shell attacksPost Views: 183 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The first public case of the Log4j Log4Shell vulnerability used to download and install ransomware has been discovered by researchers.
Last Friday, a public exploit was released for a critical zero-day vulnerability named ‘Log4Shell’ in the Apache Log4j Java-based logging platform. Log4j is a development framework that allows developers to add error and event logging into their Java applications.
The vulnerability allows threat actors to create special JNDI strings that, when read by Log4j, cause the platform to connect to and execute code at the included URL. This allows attackers to easily detect vulnerable devices or execute code supplied by a remote site or via Base64 encoded strings.
While this vulnerability was fixed in Log4j 2.15.0 and even tightened further in Log4j 2.16.0, it is being widely exploited by threat actors to install various malware, including coin miners, botnets, and even Cobalt Strike beacons.
See Also: Complete Offensive Security and Ethical Hacking Course First Log4j exploit installing ransomwareYesterday, BitDefender reported that they found the first ransomware family being installed directly via Log4Shell exploits.
The exploit downloads a Java class from
hxxp://3.145.115[.]94/Main.classthat is loaded and executed by the Log4j application.Once loaded, it would download a .NET binary from the same server to install new ransomware [VirusTotal] named ‘Khonsari.’
This same name is also used as a the extension for encrypted files and in the ransom note, as shown below.
https://www.bleepstatic.com/images/news/ransomware/k/Khonsari/ransom-note.jpg
Likely a wiperRansomware expert Michael Gillespie told BleepingComputer that Khonsari uses valid encryption and is secure, meaning that it is not possible to recover files for free.
However, the ransom note has one oddity – it does not appear to include a way to contact the threat actor to pay a ransom.
Emsisoft analyst Brett Callow pointed out to BleepingComputer that the ransomware is named after and uses contact information for a Louisiana antique shop owner rather than the threat actor.
Therefore, it is unclear if that person is the actual victim of the ransomware attack or listed as a decoy.
Regardless of the reason, as it does not contain legitimate contact information for the threat actors, we believe this is a wiper rather than ransomware.
While this may be the first known instance of the Log4j exploit directly installing ransomware (wiper?), Microsoft has already seen the exploits used to deploy Cobalt Strike beacons.
See Also: Offensive Security Tool: Cobalt Strike
Therefore, it is likely that more advanced ransomware operations are already using the exploits as part of their attacks.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/0d73-article[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New ransomware now being deployed in Log4Shell attacks | Black Hat Ethical Hacking
The first public case of the Log4j Log4Shell vulnerability used to download and install ransomware has been discovered by researchers.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New ransomware now being deployed in Log4Shell attacks https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png New ransomware now being deployed in Log4Shell attacksPost Views: 183 https://www.b…
-201111-ubuntu-90x90.jpg Attackers can get root by crashing Ubuntu’s AccountsService1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/frame_2_delay-0.5s-90x90.jpg Hackers start pushing malware in worldwide Log4Shell attacks2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-3-90x90.jpg Malicious Notepad++ installers push StrongPity malware5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Kali-Linux-2021.4-Released-90x90.png Kali Linux 2021.4 Released – New Themes and Tools, name-that-hash, truffleHog, S3Scanner, KDE Plasma 5.235 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/cover_image_1598944248.jpg.760x400_q85_crop_upscale-90x90.jpg Hackers infect random WordPress plugins to steal credit cards6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-2-90x90.jpg 27 flaws in USB-over-network SDK affect millions of cloud users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5fdb9e7105edc00d5378b856_kafkalogo-90x90.jpg Apache Kafka Cloud Clusters Expose Sensitive Data for Large Companies1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Excel-als-Malware-Schleuder-Gefahr-durch-XLL-Dateien-Twitter-90x90.png Malicious Excel XLL add-ins push RedLine password-stealing malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-1-90x90.jpg New malware hides as legit nginx process on e-commerce servers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-90x90.jpg Microsoft Exchange servers hacked to deploy BlackByte ransomware2 weeks ago
The post New ransomware now being deployed in Log4Shell attacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/frame_2_delay-0.5s-90x90.jpg Hackers start pushing malware in worldwide Log4Shell attacks2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-3-90x90.jpg Malicious Notepad++ installers push StrongPity malware5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Kali-Linux-2021.4-Released-90x90.png Kali Linux 2021.4 Released – New Themes and Tools, name-that-hash, truffleHog, S3Scanner, KDE Plasma 5.235 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/cover_image_1598944248.jpg.760x400_q85_crop_upscale-90x90.jpg Hackers infect random WordPress plugins to steal credit cards6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-2-90x90.jpg 27 flaws in USB-over-network SDK affect millions of cloud users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5fdb9e7105edc00d5378b856_kafkalogo-90x90.jpg Apache Kafka Cloud Clusters Expose Sensitive Data for Large Companies1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Excel-als-Malware-Schleuder-Gefahr-durch-XLL-Dateien-Twitter-90x90.png Malicious Excel XLL add-ins push RedLine password-stealing malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-1-90x90.jpg New malware hides as legit nginx process on e-commerce servers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-90x90.jpg Microsoft Exchange servers hacked to deploy BlackByte ransomware2 weeks ago
The post New ransomware now being deployed in Log4Shell attacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
How I Found multiple SQL Injection with FFUF and Sqlmap in a few minutes
Hello all, hope you’re OK. Our journey today is about how I found multiple SQL Injections in a bug bounty program in just a few minutes…Continue reading on InfoSec Write-ups »
Read more...
Hello all, hope you’re OK. Our journey today is about how I found multiple SQL Injections in a bug bounty program in just a few minutes…Continue reading on InfoSec Write-ups »
Read more...
How I found XSS vulnerability in Amazon in 5 minutes using shodan
This is my first write-up. I was scrolling through twitter and I found this great tip:Continue reading on Medium »
Read more...
This is my first write-up. I was scrolling through twitter and I found this great tip:Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Apache Log4j CVE-2021–44228 vulnerability
What is Log4j?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Apache Log4j CVE-2021–44228 vulnerability
What is Log4j?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Apache Log4j CVE-2021–44228 vulnerability
What is Log4j?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack Any Wifi Password In One Minute Using Android.
https://cdn-images-1.medium.com/max/640/0*cQ2eMp_a-y2Feyoh
How To Hack Any Wifi Password In One Minute Using Android Phone Without Root.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack Any Wifi Password In One Minute Using Android.
https://cdn-images-1.medium.com/max/640/0*cQ2eMp_a-y2Feyoh
How To Hack Any Wifi Password In One Minute Using Android Phone Without Root.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack Any Wifi Password In One Minute Using Android.
How To Hack Any Wifi Password In One Minute Using Android Phone Without Root.
My road map !! Need help
https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/
This isy roadmap to be a red teamer Is anything need to change 1- learn programming ---python ---C/C++ 2-Networking and OS ---Linux ---IT and Networking Basics ---THM Pre security path 3-Web Security ---THM Web fundamentals path ---OWASP TOP 10 Guide 4-Hacking Basics ---THM Complete beginner path ---INE PTS Course ---THM jr penetration tester path 5- Doing CTFs ---THM ---Hack the box ---Velnhub 6-The OSCP 7-Red team Certs ---pentester academy CRTP ---pentester academy CRTE ---Offensive security OSCE ---NOTES--- I am a computer science student I have learned C++ and python scripting And linux command line submitted by /u/Ok_Attempt_3411 (https://www.reddit.com/user/Ok_Attempt_3411)
[link] (https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/) [comments] (https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/
This isy roadmap to be a red teamer Is anything need to change 1- learn programming ---python ---C/C++ 2-Networking and OS ---Linux ---IT and Networking Basics ---THM Pre security path 3-Web Security ---THM Web fundamentals path ---OWASP TOP 10 Guide 4-Hacking Basics ---THM Complete beginner path ---INE PTS Course ---THM jr penetration tester path 5- Doing CTFs ---THM ---Hack the box ---Velnhub 6-The OSCP 7-Red team Certs ---pentester academy CRTP ---pentester academy CRTE ---Offensive security OSCE ---NOTES--- I am a computer science student I have learned C++ and python scripting And linux command line submitted by /u/Ok_Attempt_3411 (https://www.reddit.com/user/Ok_Attempt_3411)
[link] (https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/) [comments] (https://www.reddit.com/r/redteamsec/comments/rgxu2x/my_road_map_need_help/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
[deleted by user] : r/redteamsec
27K subscribers in the redteamsec community. A subreddit dedicated to red and blue teaming content. Discussions @ https://discord.gg/mTvPzuT…
How to prevent Gmail auto logouts?
https://www.reddit.com/r/redteamsec/comments/rgyj76/how_to_prevent_gmail_auto_logouts/
Google auto log out me after short period of time. I import cookies 1:1 and the IP matches exactly the machine's IP. Who faced this problem? Is there a workaround for this? submitted by /u/danhoob (https://www.reddit.com/user/danhoob)
[link] (https://www.reddit.com/r/redteamsec/comments/rgyj76/how_to_prevent_gmail_auto_logouts/) [comments] (https://www.reddit.com/r/redteamsec/comments/rgyj76/how_to_prevent_gmail_auto_logouts/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/rgyj76/how_to_prevent_gmail_auto_logouts/
Google auto log out me after short period of time. I import cookies 1:1 and the IP matches exactly the machine's IP. Who faced this problem? Is there a workaround for this? submitted by /u/danhoob (https://www.reddit.com/user/danhoob)
[link] (https://www.reddit.com/r/redteamsec/comments/rgyj76/how_to_prevent_gmail_auto_logouts/) [comments] (https://www.reddit.com/r/redteamsec/comments/rgyj76/how_to_prevent_gmail_auto_logouts/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit: How to prevent Gmail auto logouts?
Posted by danhoob - No votes and no comments
Accidentally Finded takes me to Honorable Mention in Google
https://medium.com/@vasanthgn/accidentally-finded-takes-me-to-honorable-mention-in-google-88891dd64efa?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@vasanthgn/accidentally-finded-takes-me-to-honorable-mention-in-google-88891dd64efa?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Accidentally Finded takes me to Honorable Mention in Google
Hello everyone hope all are safe and doing good. I am Vasanth from Madurai,Tamilnadu currently i am pursing Master Of Computer Application…
Hello everyone hope all are safe and doing good. I am Vasanth from Madurai,Tamilnadu currently i am pursing Master Of Computer Application…Continue reading on Medium » (https://medium.com/@vasanthgn/accidentally-finded-takes-me-to-honorable-mention-in-google-88891dd64efa?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Accidentally Finded takes me to Honorable Mention in Google
Hello everyone hope all are safe and doing good. I am Vasanth from Madurai,Tamilnadu currently i am pursing Master Of Computer Application…
The ‘U Up?’ Files With samczsun
https://medium.com/immunefi/the-u-up-files-with-samczsun-1a9116cf6e74?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/the-u-up-files-with-samczsun-1a9116cf6e74?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
The ‘U Up?’ Files With samczsun
Few names strike more fear into the hearts of blackhats than samczsun, known as perhaps the most prolific whitehat in DeFi security…
Few names strike more fear into the hearts of blackhats than samczsun, known as perhaps the most prolific whitehat in DeFi security…Continue reading on Immunefi » (https://medium.com/immunefi/the-u-up-files-with-samczsun-1a9116cf6e74?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
The ‘U Up?’ Files With samczsun
Few names strike more fear into the hearts of blackhats than samczsun, known as perhaps the most prolific whitehat in DeFi security…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046)
https://external-preview.redd.it/2U9J_1ec9Sb90d2vXaibCJi-8ZS1EnVsL97HBWLLWVU.jpg?width=640&crop=smart&auto=webp&s=a5785a74f798be2071b0dc339e82d02bf8c8847a submitted by /u/pcaversaccio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046)
https://external-preview.redd.it/2U9J_1ec9Sb90d2vXaibCJi-8ZS1EnVsL97HBWLLWVU.jpg?width=640&crop=smart&auto=webp&s=a5785a74f798be2071b0dc339e82d02bf8c8847a submitted by /u/pcaversaccio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046)
Posted in r/hacking by u/pcaversaccio • 1 point and 1 comment
hacking: security in practice
Hack the scammer
Anyone provide services to hack the scammer or where can I find that service? Recently fell victim to a scammer and would really like to take back what I lost from the hacker. Is there such service I can find?
submitted by /u/wesharethesamegoal
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hack the scammer
Anyone provide services to hack the scammer or where can I find that service? Recently fell victim to a scammer and would really like to take back what I lost from the hacker. Is there such service I can find?
submitted by /u/wesharethesamegoal
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hack the scammer
Anyone provide services to hack the scammer or where can I find that service? Recently fell victim to a scammer and would really like to take back...
Broken Link Hijacking — 404 Google Play Store— xxx$ Bounty
This is my first write-up and I will tell you how I ended up getting a xxx$ bounty for a simple Broken Link Hijacking with Google Play…Continue reading on InfoSec Write-ups »
Read more...
This is my first write-up and I will tell you how I ended up getting a xxx$ bounty for a simple Broken Link Hijacking with Google Play…Continue reading on InfoSec Write-ups »
Read more...
Bypass Authentication
https://medium.com/@thedarkwayg/bypass-authentication-1bfab09332fe?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@thedarkwayg/bypass-authentication-1bfab09332fe?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bypass Authentication
Hi all,