Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Reverse ransomware

Instead of it being used to extort a target, could ransomware or some zero day be used to de incentivize personal data from being exfiltrated? For example, could sensitive data be stored in a folder with a malicious payload that automatically launches any time the folder is attempted to be accessed by an unauthorized user?

Edit: added attempted to be

submitted by /u/plantsnotevolution
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Writing an article on hackers

I am writing a piece on hackers focusing on the resulting lifestyle and living challenges of choosing this as a profession. Obviously there would be no attribution to anyone involved. My interests are focused on understanding and documenting all that is involved and what is good, bad, and of course ugly.

I'm looking for forums where I might find what I'm looking for and/or contacts with individuals if possible. Anyone willing to help?

PM me if your interested of have information that would be useful for my article.

Thanks.

submitted by /u/ggregC
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Subdomain Takeover Via Flywheel

Flywheel is managed WordPress hosting built for designers and creative agencies to build, scale, and manage hundreds of WordPress sites…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Mellpon.b Information Disclosure

https://1.bp.blogspot.com/-oHWy7Hh5Fq0/WWlvjd6DOFI/AAAAAAAAIQk/2SpYZjutgb8xmw4nQNmHjmGkgvDsryz_gCLcBGAs/s1600/h93.png
Backdoor.Win32.Mellpon.b malware suffers from an information leakage vulnerability.

MD5 | 9fb1627230f1b16ea76628ed71fca5e9

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/e499a4c359a8cc46e641f39c0ed548f9.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.Mellpon.b
Vulnerability: Remote Unauthenticated Information Disclosure
Description: The malware listens on TCP port 80 and creates a dir named "tanaka" with a file named C.html, the HTML file contains a list of all dirs on the system and their contents. Third-party attackers who can reach an infected system can view the screen dumps taken periodically as well as view all directories and files on the system. The screen dumps are in a JPG file named "~ss.jpg" and can be accessed by URL http://x.x.x.x/~ss.jpg.
Type: PE32
MD5: e499a4c359a8cc46e641f39c0ed548f9
Vuln ID: MVID-2021-0430
Disclosure: 12/16/2021

Exploit/PoC:
1) Open a web browser to the infected host and navigate to C.html or ~ss.jpg.

Screenshots of the infected host.
http://x.x.x.x/~ss.jpg

2) All files and directory contents.
http://x.x.x.x/C.html

2021/10/13 20:24 28131582 C.html

../
C:/
2016/11/21 15:06 DIR $Recycle.Bin/
2018/03/13 15:36 DIR Boot/
2016/11/21 11:28 DIR Documents and Settings/
2021/12/13 20:21 DIR dump/
2017/12/13 20:41 DIR PerfLogs/
2021/12/13 20:17 DIR Program Files/
2021/10/03 20:49 DIR Program Files (x86)/
2021/10/03 21:12 DIR ProgramData/
2018/03/13 00:44 DIR Recovery/
2018/03/13 00:45 DIR System Volume Information/
2018/03/13 00:45 DIR Users/
2021/07/07 21:14 DIR Windows/
2018/03/01 01:53 398082 bootmgr
2017/09/29 08:41 1 BOOTNXT
2018/03/13 00:40 8192 BOOTSECT.BAK
2021/10/12 21:10 671088640 pagefile.sys
2021/10/12 21:10 16777216 swapfile.sys
C:/$Recycle.Bin/

etc...

Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
TOR Virtual Network Tunneling Tool 0.4.6.9

https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.

MD5 | 6a8bb8f6c6f7c6d80a50de8f9f8be8c4

Download
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Is Data Security Worthless if the Data Life Cycle Lacks Clarity?

If you cannot track, access, or audit data at every stage of the process, then you can't claim your data is secure.
Dark Reading: Attacks/Breaches
Time to Reset the Idea of Zero Trust

CISOs are increasingly drawn to the zero trust security model, but implementing a frictionless experience is still a challenge.
Dark Reading: Attacks/Breaches
PseudoManuscrypt Malware Targeted Government & ICS Systems in 2021

The "PseudoManuscrypt" operation infected some 35,000 computers with cyber-espionage malware and targeted computers in both government and private industry.