Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Mellpon.b Information Disclosure

https://1.bp.blogspot.com/-oHWy7Hh5Fq0/WWlvjd6DOFI/AAAAAAAAIQk/2SpYZjutgb8xmw4nQNmHjmGkgvDsryz_gCLcBGAs/s1600/h93.png
Backdoor.Win32.Mellpon.b malware suffers from an information leakage vulnerability.

MD5 | 9fb1627230f1b16ea76628ed71fca5e9

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/e499a4c359a8cc46e641f39c0ed548f9.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.Mellpon.b
Vulnerability: Remote Unauthenticated Information Disclosure
Description: The malware listens on TCP port 80 and creates a dir named "tanaka" with a file named C.html, the HTML file contains a list of all dirs on the system and their contents. Third-party attackers who can reach an infected system can view the screen dumps taken periodically as well as view all directories and files on the system. The screen dumps are in a JPG file named "~ss.jpg" and can be accessed by URL http://x.x.x.x/~ss.jpg.
Type: PE32
MD5: e499a4c359a8cc46e641f39c0ed548f9
Vuln ID: MVID-2021-0430
Disclosure: 12/16/2021

Exploit/PoC:
1) Open a web browser to the infected host and navigate to C.html or ~ss.jpg.

Screenshots of the infected host.
http://x.x.x.x/~ss.jpg

2) All files and directory contents.
http://x.x.x.x/C.html

2021/10/13 20:24 28131582 C.html

../
C:/
2016/11/21 15:06 DIR $Recycle.Bin/
2018/03/13 15:36 DIR Boot/
2016/11/21 11:28 DIR Documents and Settings/
2021/12/13 20:21 DIR dump/
2017/12/13 20:41 DIR PerfLogs/
2021/12/13 20:17 DIR Program Files/
2021/10/03 20:49 DIR Program Files (x86)/
2021/10/03 21:12 DIR ProgramData/
2018/03/13 00:44 DIR Recovery/
2018/03/13 00:45 DIR System Volume Information/
2018/03/13 00:45 DIR Users/
2021/07/07 21:14 DIR Windows/
2018/03/01 01:53 398082 bootmgr
2017/09/29 08:41 1 BOOTNXT
2018/03/13 00:40 8192 BOOTSECT.BAK
2021/10/12 21:10 671088640 pagefile.sys
2021/10/12 21:10 16777216 swapfile.sys
C:/$Recycle.Bin/

etc...

Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
TOR Virtual Network Tunneling Tool 0.4.6.9

https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.

MD5 | 6a8bb8f6c6f7c6d80a50de8f9f8be8c4

Download
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Is Data Security Worthless if the Data Life Cycle Lacks Clarity?

If you cannot track, access, or audit data at every stage of the process, then you can't claim your data is secure.
Dark Reading: Attacks/Breaches
Time to Reset the Idea of Zero Trust

CISOs are increasingly drawn to the zero trust security model, but implementing a frictionless experience is still a challenge.
Dark Reading: Attacks/Breaches
PseudoManuscrypt Malware Targeted Government & ICS Systems in 2021

The "PseudoManuscrypt" operation infected some 35,000 computers with cyber-espionage malware and targeted computers in both government and private industry.
Dark Reading: Attacks/Breaches
Executive Partnerships Are Critical for Cybersecurity Success

One leader alone can't protect an organization from cyber threats, C-suite leaders agree.
is there anyway to bypass angular xss sanitizer
https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/

Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that because i find my string the way it is into one of the requests responses. but the display in angular is changing the special chars such as "<" and "&" into & and<. for that my tag is just displayed. is there a way to bypass this ? submitted by /u/GrompyGromp123 (https://www.reddit.com/user/GrompyGromp123)
[link] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/) [comments] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/)

___________________________
@hacking_Attack
@Hacking_Video