Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice I've reported over a dozen security concerns and vulnerabilities to my high school, and I'm unsure where to take the situation. It would be best to start this story from the beginning and have a timeline of what exactly has transpired…
ther one two days before Christmas break (the email was three days ago) which detailed an even higher severity vulnerability. I hadn't gotten a response back from either my friend nor the IT director, but to date apart from that one Google Group none of these vulnerabilities have been fixed. I'll list all of them here for context (obviously not in detail): Initial email* A misconfiguration in around ten Google Groups allowed anyone to view them.
* A misconfiguration in one of the groups allowed anyone to send as the email that the Google Group is attached to, which is just one word.
* A misconfiguration in some of the groups might allow someone to add everyone in those groups to a Google Doc or potentially a Google Calendar entry.
* A feature was left open allowing anyone to view everyone in the entire district's emails (including students). It's limited to around 10 or so entries at a time so no one can just copy them all at once, but that doesn't stop anyone from using WebDriver. The reason why this was a highlighted thing in my email is because the district previously had a problem where someone had emailed all of the Google Groups where students for each school were added to and I don't need to explain why Reply All is the worst thing in history.
* A COVID-19 reporting form didn't have proper file upload restrictions.
* All of the district's custom-made sites leak the ASP.NET version in the HTTP header, as well as the IIS version.
* Similarly, they all lack HSTS (which is essential when you consider someone can just bring a Wi-Fi Pineapple to school), CSP, and X-Content-Type-Options.
* One of the sites that everyone in the district uses daily doesn't redirect to HTTPS.
* Some essential cookies aren't secure, like authorization cookies. If the site were to link to an HTTP resource, this would be pretty bad.
* There were some SSL/TLS security concerns I won't go into since they're really technical and I'm worried they sound like technobabble. Second email* The district uses a domain for all kinds of reports and data collection, which only some users have access to. There's a URL that allows you to view as any user. I don't need to explain this one.
* There's no DMARC record for emails in the district which means that a certain email that's sent out every week can just be forged and the link in it replaced with whatever the person wants. The first email will still be sent but having a DMARC record is still really important and people will click on the second (fake) email.
* Some of the sites leak the internal IP address of who's hosting it and WebResource.axd.
* The jQuery version used on the sites is really old and from 2013.
I'm not sure where to take this situation from here. I read a post from /u/Racingteamsam last night that led me to make this post and I'm torn now. On one hand I read comments like this:
The problem is that they are aware you have access to those resources because of your emails. If you decide to "wreak havoc" or "leak the data" as the others suggested, they'll start to suspect you. From their perspective, there's a mysterious black box that shouldn't be touched by anyone besides the IT guy. After so many peaceful years, a student says that he knows how to access it. Soon after that, there's a data leak. Even the dumbest person would connect the dots and know who's going to be the first suspect...
It wasn't immediately across my mind, but now I've realized I might be framed if someone finds one of the vulnerabilities and exploits them. Suddenly, I'm a prime suspect. The truth is I don't intend on exploiting them and I genuinely just want them fixed at this point, because if they don't do it now then someone is going to light a fire under their asses and it won't look good for IT or me.
My (un)professional response to your question? Exploit the weaknesses and demonstrate how you did it. These people are reactionary and only learn through pain. If you don’t [...]
___________________________
@hacking_Attack
@Hacking_Video
* A misconfiguration in one of the groups allowed anyone to send as the email that the Google Group is attached to, which is just one word.
* A misconfiguration in some of the groups might allow someone to add everyone in those groups to a Google Doc or potentially a Google Calendar entry.
* A feature was left open allowing anyone to view everyone in the entire district's emails (including students). It's limited to around 10 or so entries at a time so no one can just copy them all at once, but that doesn't stop anyone from using WebDriver. The reason why this was a highlighted thing in my email is because the district previously had a problem where someone had emailed all of the Google Groups where students for each school were added to and I don't need to explain why Reply All is the worst thing in history.
* A COVID-19 reporting form didn't have proper file upload restrictions.
* All of the district's custom-made sites leak the ASP.NET version in the HTTP header, as well as the IIS version.
* Similarly, they all lack HSTS (which is essential when you consider someone can just bring a Wi-Fi Pineapple to school), CSP, and X-Content-Type-Options.
* One of the sites that everyone in the district uses daily doesn't redirect to HTTPS.
* Some essential cookies aren't secure, like authorization cookies. If the site were to link to an HTTP resource, this would be pretty bad.
* There were some SSL/TLS security concerns I won't go into since they're really technical and I'm worried they sound like technobabble. Second email* The district uses a domain for all kinds of reports and data collection, which only some users have access to. There's a URL that allows you to view as any user. I don't need to explain this one.
* There's no DMARC record for emails in the district which means that a certain email that's sent out every week can just be forged and the link in it replaced with whatever the person wants. The first email will still be sent but having a DMARC record is still really important and people will click on the second (fake) email.
* Some of the sites leak the internal IP address of who's hosting it and WebResource.axd.
* The jQuery version used on the sites is really old and from 2013.
I'm not sure where to take this situation from here. I read a post from /u/Racingteamsam last night that led me to make this post and I'm torn now. On one hand I read comments like this:
The problem is that they are aware you have access to those resources because of your emails. If you decide to "wreak havoc" or "leak the data" as the others suggested, they'll start to suspect you. From their perspective, there's a mysterious black box that shouldn't be touched by anyone besides the IT guy. After so many peaceful years, a student says that he knows how to access it. Soon after that, there's a data leak. Even the dumbest person would connect the dots and know who's going to be the first suspect...
It wasn't immediately across my mind, but now I've realized I might be framed if someone finds one of the vulnerabilities and exploits them. Suddenly, I'm a prime suspect. The truth is I don't intend on exploiting them and I genuinely just want them fixed at this point, because if they don't do it now then someone is going to light a fire under their asses and it won't look good for IT or me.
My (un)professional response to your question? Exploit the weaknesses and demonstrate how you did it. These people are reactionary and only learn through pain. If you don’t [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ther one two days before Christmas break (the email was three days ago) which detailed an even higher severity vulnerability. I hadn't gotten a response back from either my friend nor the IT director, but to date apart from that one Google Group none of these…
do it, someone nasty will!
I don't intend on doing this either.
As someone who did something similar to you, both at school and when I was on work experience when I was 16.. People don't like to look stupid. They wont be patting you on the back, no on the contrary, you will be seen as someone dangerous and someone who needs to be dealt with. This isnt your fight, let them worry about it. Do however keep your curious mind, and keep doing what you're doing but I assure you they will make you suffer if you point this out and put a bad taste in your mouth. Keep learning, but yeah... people dont like to look incompetent, especially from "kids" - again I am speaking from personal experience. When I pointed things out they got in "experts" at great cost to them to make sure I had not hacked anything else, a full investigation. Luckily for me I am in the UK, and this was back in the day. Suffice to say it cost them money and I was blacklisted - luckily I was leaving in a few months, but not after being told I'll be in prison within 6 months of leaving for hacking (which is bullshit as it was hardly hacking, and I was doing them a favour)
I'd thread very, very carefully. Your actions, even with good intent, were illegal. You cannot access machines you don't own or have permission to use. Even if you were to make a disclosure anonymously, it could be tied back to you given your existing access and the logs that would have generated, in addition to the emails you sent.
Be very careful how you proceed here. Being the messenger in these situations never ends well.
I’ve been in similar situations, and all I can tell you is that they can get really dicey really fast. First of all absolutely do not access that server or mention that you did if possible (although it may be to late for that.) Make sure you have extensive documentation of any problems and always stop one step before you get to the actual vulnerability. You want to know that it’s theoretically possible, but don’t want to make it possible to prosecute you for hacking. It’s often easier for a bureaucracy to make the problem “go away” by alleging misconduct on your part rather than doing the right thing and fixing the issue.
Honestly just forget you know about it. They're not going to work with you, when I found security bugs at my high school it turned into a 7 month long court case that ended in me being convicted of a felony.
Also, you seem to be setting yourself up for expulsion and a talk with the FBI when you embarrass your school administration by openly exposing their incompetence and giving them a reason to have you put away as a "hacker". Schools love to shoot the messenger. It has happened many times.
You are playing a high stakes game whether you know it or not, you’ve already surely broken a handful of acceptable use policy items and accessed sensitive personal info you were not authorized to access. Better be careful. Of course what they SHOULD do is thank you and give you an award, but there are numerous examples of people getting a legal asspounding after such situations or even less, you’re gambling on who’s in charge here and how they’re going to react.
Obviously, I didn't access a server with a default password and username, but the point still stands. I'm on very thin ice at this point.
On the other hand, I was told from my friend's mom that I wasn't liable in this situation and in my words the ice is thicker than I think it is. But who knows? Accessing users on that one domain doesn't sound like it's small enough for me to have no liability.
At the end of the day my ideal situation is for IT to fix the problems. It would be a dream to be able to work with them, but that's really unrealistic and dangerous. What it's heading to is either after break me having to go up to admin and then things start to go off the rails from there and I get in serious trouble, or someone gets fired. I don't want either situation, and especi[...]
___________________________
@hacking_Attack
@Hacking_Video
I don't intend on doing this either.
As someone who did something similar to you, both at school and when I was on work experience when I was 16.. People don't like to look stupid. They wont be patting you on the back, no on the contrary, you will be seen as someone dangerous and someone who needs to be dealt with. This isnt your fight, let them worry about it. Do however keep your curious mind, and keep doing what you're doing but I assure you they will make you suffer if you point this out and put a bad taste in your mouth. Keep learning, but yeah... people dont like to look incompetent, especially from "kids" - again I am speaking from personal experience. When I pointed things out they got in "experts" at great cost to them to make sure I had not hacked anything else, a full investigation. Luckily for me I am in the UK, and this was back in the day. Suffice to say it cost them money and I was blacklisted - luckily I was leaving in a few months, but not after being told I'll be in prison within 6 months of leaving for hacking (which is bullshit as it was hardly hacking, and I was doing them a favour)
I'd thread very, very carefully. Your actions, even with good intent, were illegal. You cannot access machines you don't own or have permission to use. Even if you were to make a disclosure anonymously, it could be tied back to you given your existing access and the logs that would have generated, in addition to the emails you sent.
Be very careful how you proceed here. Being the messenger in these situations never ends well.
I’ve been in similar situations, and all I can tell you is that they can get really dicey really fast. First of all absolutely do not access that server or mention that you did if possible (although it may be to late for that.) Make sure you have extensive documentation of any problems and always stop one step before you get to the actual vulnerability. You want to know that it’s theoretically possible, but don’t want to make it possible to prosecute you for hacking. It’s often easier for a bureaucracy to make the problem “go away” by alleging misconduct on your part rather than doing the right thing and fixing the issue.
Honestly just forget you know about it. They're not going to work with you, when I found security bugs at my high school it turned into a 7 month long court case that ended in me being convicted of a felony.
Also, you seem to be setting yourself up for expulsion and a talk with the FBI when you embarrass your school administration by openly exposing their incompetence and giving them a reason to have you put away as a "hacker". Schools love to shoot the messenger. It has happened many times.
You are playing a high stakes game whether you know it or not, you’ve already surely broken a handful of acceptable use policy items and accessed sensitive personal info you were not authorized to access. Better be careful. Of course what they SHOULD do is thank you and give you an award, but there are numerous examples of people getting a legal asspounding after such situations or even less, you’re gambling on who’s in charge here and how they’re going to react.
Obviously, I didn't access a server with a default password and username, but the point still stands. I'm on very thin ice at this point.
On the other hand, I was told from my friend's mom that I wasn't liable in this situation and in my words the ice is thicker than I think it is. But who knows? Accessing users on that one domain doesn't sound like it's small enough for me to have no liability.
At the end of the day my ideal situation is for IT to fix the problems. It would be a dream to be able to work with them, but that's really unrealistic and dangerous. What it's heading to is either after break me having to go up to admin and then things start to go off the rails from there and I get in serious trouble, or someone gets fired. I don't want either situation, and especi[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
do it, someone nasty will! I don't intend on doing this either. As someone who did something similar to you, both at school and when I was on work experience when I was 16.. People don't like to look stupid. They wont be patting you on the back, no on the…
ally the former.
I know one of the responses I'm going to get, or a lot of them, is just to "ignore everything that's happened and let IT take over". I'm taking an active approach to this situation for two reasons. One, I'm pretty sure I'm going to find another vulnerability and I'm not waiting to report it only for some attacker in the district or not to exploit it. Two, since both of my emails nothing has happened.
What do I do in this situation? I have a teacher on my side, but I fear that may not be enough and I'm still very liable. I started from a few button presses to one of the worst vulnerabilities this district has probably ever seen in a while where alone people's COVID-19 positive/negative/vaccination statuses are visible and most likely way worse stuff. I don't think I'm not liable for that at that point and I'm reaching into territory that is, to say the least, illegal.
submitted by /u/wizardarrays [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I know one of the responses I'm going to get, or a lot of them, is just to "ignore everything that's happened and let IT take over". I'm taking an active approach to this situation for two reasons. One, I'm pretty sure I'm going to find another vulnerability and I'm not waiting to report it only for some attacker in the district or not to exploit it. Two, since both of my emails nothing has happened.
What do I do in this situation? I have a teacher on my side, but I fear that may not be enough and I'm still very liable. I started from a few button presses to one of the worst vulnerabilities this district has probably ever seen in a while where alone people's COVID-19 positive/negative/vaccination statuses are visible and most likely way worse stuff. I don't think I'm not liable for that at that point and I'm reaching into territory that is, to say the least, illegal.
submitted by /u/wizardarrays [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I got phished. Looking for ideas on retribution.
So I fell for phishing scheme in a support chat room for a NFT marketplace. The perp appears to lurk in the room and I am wondering if there might be a way to hack the hacker. He basically obtained my wallet key by sending me to a website( link removed)
I don’t know if this is an appropriate place for the question and hope you can direct me somewhere if it isn’t. I’m super pissed.
submitted by /u/Boring_Truth2692
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I got phished. Looking for ideas on retribution.
So I fell for phishing scheme in a support chat room for a NFT marketplace. The perp appears to lurk in the room and I am wondering if there might be a way to hack the hacker. He basically obtained my wallet key by sending me to a website( link removed)
I don’t know if this is an appropriate place for the question and hope you can direct me somewhere if it isn’t. I’m super pissed.
submitted by /u/Boring_Truth2692
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
hacking: security in practice
How hard for non-hacker is to change device id?
I got 3 tries of login to my instagram. One is from LG K330 - Ho Chi Min city, Vietnam, other from Huawei GRA - L09 Delhi, India, and third is from Huawei GRA L09 Atsugi, Kanagawa, Japan. (Im from Europe).
I know that everyone can turn on vpn and change his location, but how hard is it for non hackers to change device? I m not sure if someone local trying to guess my password, or I am under real attack of someone more professional. I did not click any link, or something like that. I use IG mostly for scrolling pics.
P.S. if this is not good subreddit to post this, can you tell me which one is?
submitted by /u/Raskoljnikovic
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How hard for non-hacker is to change device id?
I got 3 tries of login to my instagram. One is from LG K330 - Ho Chi Min city, Vietnam, other from Huawei GRA - L09 Delhi, India, and third is from Huawei GRA L09 Atsugi, Kanagawa, Japan. (Im from Europe).
I know that everyone can turn on vpn and change his location, but how hard is it for non hackers to change device? I m not sure if someone local trying to guess my password, or I am under real attack of someone more professional. I did not click any link, or something like that. I use IG mostly for scrolling pics.
P.S. if this is not good subreddit to post this, can you tell me which one is?
submitted by /u/Raskoljnikovic
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How hard for non-hacker is to change device id?
I got 3 tries of login to my instagram. One is from LG K330 - Ho Chi Min city, Vietnam, other from Huawei GRA - L09 Delhi, India, and third is...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Homomorphic encryption is a cryptographic method that returns an encrypted result to the data owner. Essentially, this enables third parties to process encrypted data while having no knowledge about the data or the results.
https://external-preview.redd.it/YaDCHjNheEPPzX95kWwwiL3A-ES9IGxtXvnNlJk_Qgc.jpg?width=320&crop=smart&auto=webp&s=22941164f23069ae205af5c222e93c5091486d9a submitted by /u/diegolujan1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Homomorphic encryption is a cryptographic method that returns an encrypted result to the data owner. Essentially, this enables third parties to process encrypted data while having no knowledge about the data or the results.
https://external-preview.redd.it/YaDCHjNheEPPzX95kWwwiL3A-ES9IGxtXvnNlJk_Qgc.jpg?width=320&crop=smart&auto=webp&s=22941164f23069ae205af5c222e93c5091486d9a submitted by /u/diegolujan1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Homomorphic encryption is a cryptographic method that returns an...
Posted in r/hacking by u/diegolujan1 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Physical access is the best access
https://external-preview.redd.it/sIRxTL9Do-MalbiCNDYthXQCovTY909UNMsNpoCb2hM.jpg?width=320&crop=smart&auto=webp&s=a67f1fd6cf81d547b357dbb07a9877379df7d148 submitted by /u/Background_Gene_3657
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Physical access is the best access
https://external-preview.redd.it/sIRxTL9Do-MalbiCNDYthXQCovTY909UNMsNpoCb2hM.jpg?width=320&crop=smart&auto=webp&s=a67f1fd6cf81d547b357dbb07a9877379df7d148 submitted by /u/Background_Gene_3657
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Physical access is the best access
Posted in r/hacking by u/Background_Gene_3657 • 1 point and 0 comments
Log4J-Detector - Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046
http://www.kitploit.com/2021/12/log4j-detector-detects-log4j-versions.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/12/log4j-detector-detects-log4j-versions.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Detects Log4J versions on your file-system within any application that are vulnerable (https://www.kitploit.com/search/label/Vulnerable) to CVE-2021-44228 (https://mergebase.com/vulnerability/CVE-2021-44228/) and CVE-2021-45046 (https://mergebase.com/vulnerability/CVE-2021-45046/). It is able to even find instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! Currently reports log4j-core versions 2.12.2 and 2.17.0 as _SAFE_, 2.15.0 and 2.16.0 as _OKAY_ and all other versions as _VULNERABLE_ (although it does report pre-2.0-beta9 as "_POTENTIALLY_SAFE_"). Can correctly detect log4j inside executable spring-boot jars/wars, dependencies blended into uber jars (https://mergebase.com/blog/software-composition-analysis-sca-vs-java-uber-jars/), shaded jars, and even exploded jar files just sitting uncompressed on the file-system (aka *.class). We currently maintain a collection of log4j-samples (https://github.com/mergebase/log4j-samples) we use for testing.
Example Usage: java -jar log4j-detector-2021.12.17.jar [path-to-scan] > hits.txt
___________________________
@hacking_Attack
@Hacking_Video
Example Usage: java -jar log4j-detector-2021.12.17.jar [path-to-scan] > hits.txt
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
More Example Usage: = 2.10.0 _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/infinispan-embedded-query-8.2.12.Final.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/log4j-1.1.3.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-| /opt/mergebase/log4j-detector/samples/log4j-1.2.13.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-| /opt/mergebase/log4j-detector/samples/log4j-1.2.17.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-| /opt/mergebase/log4j-detector/samples/log4j-core-2.0-beta2.jar contains Log4J-2.x <= 2.0-beta8 _POTENTIALLY_SAFE_ :-| (or did you already remove JndiLookup.class?) /opt/mergebase/log4j-detector/samples/log4j-core-2.0-beta9.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/log4j-core-2.0.2.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/log4j-core-2.0.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/log4j-core-2.10.0.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/log4j-core-2.12.2.jar contains Log4J-2.x >= 2.12.2 _SAFE_ :-) /opt/mergebase/log4j-detector/samples/log4j-core-2.14.1.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/log4j-core-2.15.0.jar contains Log4J-2.x >= 2.15.0 _OKAY_ :-| /opt/mergebase/log4j-detector/samples/log4j-core-2.16.0.jar contains Log4J-2.x >= 2.16.0 _OKAY_ :-) /opt/mergebase/log4j-detector/samples/log4j-core-2.17.0.jar contains Log4J-2.x >= 2.16.0 _SAFE_ :-) /opt/mergebase/log4j-detector/samples/log4j-core-2.4.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-( /opt/mergebase/log4j-detector/samples/log4j-core-2.9.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(">java -jar log4j-detector-2021.12.17.jar ./samples
-- github.com/mergebase/log4j-detector v2021.12.17 (by mergebase.com) analyzing paths (could take a while).
-- Note: specify the '--verbose' flag to have every file examined printed to STDERR.
/opt/mergebase/log4j-detector/samples/clt-1.0-SNAPSHOT.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/infinispan-embedded-query-8.2.12.Final.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-1.1.3.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-|
/opt/mergebase/log4j-detector/samples/log4j-1.2.13.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-|
/opt/mergebase/log4j-detector/samples/log4j-1.2.17.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-|
/opt/mergebase/log4j-de tector/samples/log4j-core-2.0-beta2.jar contains Log4J-2.x <= 2.0-beta8 _POTENTIALLY_SAFE_ :-| (or did you already remove JndiLookup.class?)
/opt/mergebase/log4j-detector/samples/log4j-core-2.0-beta9.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.0.2.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.0.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.10.0.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.12.2.jar contains Log4J-2.x >= 2.12.2 _SAFE_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.14.1.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.15.0.jar contains Log4J-2.x >= 2.15.0 _OKAY_ :-|
/op t/mergebase/log4j-detector/samples/log4j-core-2.16.0.jar contains Log4J-2.x >= 2.16.0 _OKAY_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.17.0.jar contains Log4J-2.x >= 2.16.0 _SAFE_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.4.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
___________________________
@hacking_Attack
@Hacking_Video
-- github.com/mergebase/log4j-detector v2021.12.17 (by mergebase.com) analyzing paths (could take a while).
-- Note: specify the '--verbose' flag to have every file examined printed to STDERR.
/opt/mergebase/log4j-detector/samples/clt-1.0-SNAPSHOT.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/infinispan-embedded-query-8.2.12.Final.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-1.1.3.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-|
/opt/mergebase/log4j-detector/samples/log4j-1.2.13.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-|
/opt/mergebase/log4j-detector/samples/log4j-1.2.17.jar contains Log4J-1.x <= 1.2.17 _OLD_ :-|
/opt/mergebase/log4j-de tector/samples/log4j-core-2.0-beta2.jar contains Log4J-2.x <= 2.0-beta8 _POTENTIALLY_SAFE_ :-| (or did you already remove JndiLookup.class?)
/opt/mergebase/log4j-detector/samples/log4j-core-2.0-beta9.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.0.2.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.0.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.10.0.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.12.2.jar contains Log4J-2.x >= 2.12.2 _SAFE_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.14.1.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.15.0.jar contains Log4J-2.x >= 2.15.0 _OKAY_ :-|
/op t/mergebase/log4j-detector/samples/log4j-core-2.16.0.jar contains Log4J-2.x >= 2.16.0 _OKAY_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.17.0.jar contains Log4J-2.x >= 2.16.0 _SAFE_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.4.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - mergebase/log4j-detector: A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021…
A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J ins...
/opt/mergebase/log4j-detector/samples/log4j-core-2.9.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
Understanding The Results _VULNERABLE_ -> You need to upgrade or remove this file. _OKAY_ -> We only report this for Log4J versions 2.15.0 and 2.16.0. We recommend upgrading to 2.17.0. _SAFE_ -> We currently only report this for Log4J versions 2.17.0 and 2.12.2. _OLD_ -> You are safe from CVE-2021-44228, but should plan to upgrade because Log4J 1.2.x has been EOL for 7 years and has several known-vulnerabilities. _POTENTIALLY_SAFE_ -> The "JndiLookup.class" file is not present, either because your version of Log4J is very old (pre 2.0-beta9), or because someone already removed this file. Make sure it was someone in your team or company that removed "JndiLookup.class" if that's the case, because attackers have been known to remove this file themselves to prevent additional competing attackers from gaining access to compromised systems. This Scanner Only Reports Hits Against The log4j-core Library. What About log4j-api? Many scanners (including GitHub's own Dependabot (https://github.com/dependabot)) currently report both "log4j-core" and "log4j-api" libraries as vulnerable. These scanners are incorrect. There is currently no existing version of the "log4j-api" library that can be exploited by any of these vulnerabilities. Why Report About 2.10.0, 2.15.0, 2.16.0, and 2.17.0 ? We consider version 2.10.0 important because that's the first version where Log4J's vulnerable "message lookup feature" can be disabled via Log4J configuration. We consider versions 2.15.0 and 2.16.0 important because these are the first versions where Log4J's default out-of-the-box configuration is not vulnerable to CVE-2021-44228. And version 2.17.0 is important because it's not vulnerable to CVE-2021-45046. Despite CVE-2021-45046 being much less serious, we anticipate everyone will want to patch to 2.17.0. What are those "file1.war!/path/to/file2.zip!/path/to/file3.jar!/path/to/log4j.jar" results about? The "!" means the log4j-detector entered a zip archive (e.g., *.zip, *.ear, *.war, *.aar, *.jar). Since zip files can contain zip files, a single result might contain more than one "!" indicator in its result. Note: the log4j-detector only recursively enters zip archives. It does not enter tar or gz or bz2, etc. The main reason being that Java systems are often configured to execute jars inside jars, but they are never configured to execute other file formats (that I know of!). And so a log4j copy inside a *.tar.gz is probably not reachable for a running Java system, and hence, not a vulnerability (https://www.kitploit.com/search/label/Vulnerability) worth reporting. 2nd note: for zips-inside-zips our scanner does load the inner-zip completely into memory (using ByteArrayInputStream) before attempting to scan it. You might need to give Java some extra memory if you have extremely large inner-zips on your system (e.g., 1 GB or larger). Usage detector (version 2021.12.17) Docs - https://github.com/mergebase/log4j-detector (C) Copyright 2021 Mergebase Software Inc. Licensed to you via GPLv3.">java -jar log4j-detector-2021.12.17.jar
Usage: java -jar log4j-detector-2021.12.17.jar [--verbose] [paths to scan...]
Exit codes: 0 = No vulnerable Log4J versions found.
1 = At least one legacy Log4J 1.x version found.
2 = At least one vulnerable Log4J version found.
About - MergeBase log4j detector (version 2021.12.17)
Docs - https://github.com/mergebase/log4j-detector
(C) Copyright 2021 Mergebase Software Inc. Licensed to you via GPLv3.
Build From Source: git clone https://github.com/mergebase/log4j-detector.git
cd log4j-detector/
mvn install
java -jar target/log4j-detector-2021.12.17.jar
___________________________
@hacking_Attack
@Hacking_Video
Understanding The Results _VULNERABLE_ -> You need to upgrade or remove this file. _OKAY_ -> We only report this for Log4J versions 2.15.0 and 2.16.0. We recommend upgrading to 2.17.0. _SAFE_ -> We currently only report this for Log4J versions 2.17.0 and 2.12.2. _OLD_ -> You are safe from CVE-2021-44228, but should plan to upgrade because Log4J 1.2.x has been EOL for 7 years and has several known-vulnerabilities. _POTENTIALLY_SAFE_ -> The "JndiLookup.class" file is not present, either because your version of Log4J is very old (pre 2.0-beta9), or because someone already removed this file. Make sure it was someone in your team or company that removed "JndiLookup.class" if that's the case, because attackers have been known to remove this file themselves to prevent additional competing attackers from gaining access to compromised systems. This Scanner Only Reports Hits Against The log4j-core Library. What About log4j-api? Many scanners (including GitHub's own Dependabot (https://github.com/dependabot)) currently report both "log4j-core" and "log4j-api" libraries as vulnerable. These scanners are incorrect. There is currently no existing version of the "log4j-api" library that can be exploited by any of these vulnerabilities. Why Report About 2.10.0, 2.15.0, 2.16.0, and 2.17.0 ? We consider version 2.10.0 important because that's the first version where Log4J's vulnerable "message lookup feature" can be disabled via Log4J configuration. We consider versions 2.15.0 and 2.16.0 important because these are the first versions where Log4J's default out-of-the-box configuration is not vulnerable to CVE-2021-44228. And version 2.17.0 is important because it's not vulnerable to CVE-2021-45046. Despite CVE-2021-45046 being much less serious, we anticipate everyone will want to patch to 2.17.0. What are those "file1.war!/path/to/file2.zip!/path/to/file3.jar!/path/to/log4j.jar" results about? The "!" means the log4j-detector entered a zip archive (e.g., *.zip, *.ear, *.war, *.aar, *.jar). Since zip files can contain zip files, a single result might contain more than one "!" indicator in its result. Note: the log4j-detector only recursively enters zip archives. It does not enter tar or gz or bz2, etc. The main reason being that Java systems are often configured to execute jars inside jars, but they are never configured to execute other file formats (that I know of!). And so a log4j copy inside a *.tar.gz is probably not reachable for a running Java system, and hence, not a vulnerability (https://www.kitploit.com/search/label/Vulnerability) worth reporting. 2nd note: for zips-inside-zips our scanner does load the inner-zip completely into memory (using ByteArrayInputStream) before attempting to scan it. You might need to give Java some extra memory if you have extremely large inner-zips on your system (e.g., 1 GB or larger). Usage detector (version 2021.12.17) Docs - https://github.com/mergebase/log4j-detector (C) Copyright 2021 Mergebase Software Inc. Licensed to you via GPLv3.">java -jar log4j-detector-2021.12.17.jar
Usage: java -jar log4j-detector-2021.12.17.jar [--verbose] [paths to scan...]
Exit codes: 0 = No vulnerable Log4J versions found.
1 = At least one legacy Log4J 1.x version found.
2 = At least one vulnerable Log4J version found.
About - MergeBase log4j detector (version 2021.12.17)
Docs - https://github.com/mergebase/log4j-detector
(C) Copyright 2021 Mergebase Software Inc. Licensed to you via GPLv3.
Build From Source: git clone https://github.com/mergebase/log4j-detector.git
cd log4j-detector/
mvn install
java -jar target/log4j-detector-2021.12.17.jar
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Dependabot
Automated dependency updates built into GitHub. Dependabot has 26 repositories available. Follow their code on GitHub.
hacking: security in practice
Is it possible to get phone number from Google meet ?
So, there is this one spammer in our Google meet classrooms. He comes every now and then in the class. And today he texted me to my WhatsApp number. I asked him how he got my number and he replied with "I got it using an google meet trick". Is it really possible?
submitted by /u/helloworldw2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to get phone number from Google meet ?
So, there is this one spammer in our Google meet classrooms. He comes every now and then in the class. And today he texted me to my WhatsApp number. I asked him how he got my number and he replied with "I got it using an google meet trick". Is it really possible?
submitted by /u/helloworldw2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to get phone number from Google meet ?
So, there is this one spammer in our Google meet classrooms. He comes every now and then in the class. And today he texted me to my WhatsApp...
hacking: security in practice
Trying to figure out how mouseover event displays email address in O365
O365 reading pane setting is hidden
Observed behavior:
In the inbox, if you mouseover a sender in the "From" column a hover card is displayed with the sender's email (e.g. foo@bar[.]com)
What I'm looking to figure out:
I believe the email is displayed in the mouseover event by pulling the address from the email header. Specifically, I believe it's coming from "Return-Path:"
I'm attempting to see if it's possible using dev tools to find this. I can find the area I'm supposed to be looking at in dev tools, I just don't know where to go from there. It was suggested to me to set a breakpoint, but what am I looking for was I step through to see where the hover card comes from?
Any ideas?
submitted by /u/inf0s33k3r
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Trying to figure out how mouseover event displays email address in O365
O365 reading pane setting is hidden
Observed behavior:
In the inbox, if you mouseover a sender in the "From" column a hover card is displayed with the sender's email (e.g. foo@bar[.]com)
What I'm looking to figure out:
I believe the email is displayed in the mouseover event by pulling the address from the email header. Specifically, I believe it's coming from "Return-Path:"
I'm attempting to see if it's possible using dev tools to find this. I can find the area I'm supposed to be looking at in dev tools, I just don't know where to go from there. It was suggested to me to set a breakpoint, but what am I looking for was I step through to see where the hover card comes from?
Any ideas?
submitted by /u/inf0s33k3r
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Trying to figure out how mouseover event displays email address in...
O365 reading pane setting is hidden Observed behavior: In the inbox, if you mouseover a sender in the "From" column a hover card is displayed...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Log4J-Detector - Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046
http://1.bp.blogspot.com/-l4ckIu8tvZw/YcAH6RuFLZI/AAAAAAAA5s8/-Q23DmKD8RoDI7CKAFMU9O2VVL1j5-ncgCK4BGAYYCw/w640-h150/log4j-detector_1_log4j-detector-778008.png Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046. It is able to even find instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too!
Currently reports
Can correctly detect log4j inside executable spring-boot jars/wars, dependencies blended into uber jars, shaded jars, and even exploded jar files just sitting uncompressed on the file-system (aka *.class).
We currently maintain a collection of log4j-samples we use for testing. Example Usage:java -jar log4j-detector-2021.12.17.jar [path-to-scan] > hits.txt http://1.bp.blogspot.com/-l4ckIu8tvZw/YcAH6RuFLZI/AAAAAAAA5s8/-Q23DmKD8RoDI7CKAFMU9O2VVL1j5-ncgCK4BGAYYCw/w640-h150/log4j-detector_1_log4j-detector-778008.png More Example Usage:
_OKAY_ -> We only report this for Log4J versions 2.15.0 and 2.16.0. We recommend upgrading to 2.17.0.
_SAFE_ -> We currently only report this for Log4J versions 2.17.0 and 2.12.2.
_OLD_ -> You are safe from CVE-2021-44228, but should plan to upgrade because Log4J 1.2.x has been EOL for 7 years and has several known-v[...]
___________________________
@hacking_Attack
@Hacking_Video
Log4J-Detector - Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046
http://1.bp.blogspot.com/-l4ckIu8tvZw/YcAH6RuFLZI/AAAAAAAA5s8/-Q23DmKD8RoDI7CKAFMU9O2VVL1j5-ncgCK4BGAYYCw/w640-h150/log4j-detector_1_log4j-detector-778008.png Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046. It is able to even find instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too!
Currently reports
log4j-coreversions 2.12.2 and 2.17.0 as _SAFE_, 2.15.0 and 2.16.0 as _OKAY_ and all other versions as _VULNERABLE_ (although it does report pre-2.0-beta9 as "_POTENTIALLY_SAFE_").Can correctly detect log4j inside executable spring-boot jars/wars, dependencies blended into uber jars, shaded jars, and even exploded jar files just sitting uncompressed on the file-system (aka *.class).
We currently maintain a collection of log4j-samples we use for testing. Example Usage:java -jar log4j-detector-2021.12.17.jar [path-to-scan] > hits.txt http://1.bp.blogspot.com/-l4ckIu8tvZw/YcAH6RuFLZI/AAAAAAAA5s8/-Q23DmKD8RoDI7CKAFMU9O2VVL1j5-ncgCK4BGAYYCw/w640-h150/log4j-detector_1_log4j-detector-778008.png More Example Usage:
java -jar log4j-detector-2021.12.17.jar ./samples
-- github.com/mergebase/log4j-detector v2021.12.17 (by mergebase.com) analyzing paths (could take a while).
-- Note: specify the '--verbose' flag to have every file examined printed to STDERR.
/opt/mergebase/log4j-detector/samples/clt-1.0-SNAPSHOT.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/infinispan-embedded-query-8.2.12.Final.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-1.1.3.jar contains Log4J-1.x <=
/opt/mergebase/log4j-detector/samples/log4j-1.2.13.jar contains Log4J-1.x <=
/opt/mergebase/log4j-detector/samples/log4j-1.2.17.jar contains Log4J-1.x <=
/opt/mergebase/log4j-de tector/samples/log4j-core-2.0-beta2.jar contains Log4J-2.x <=
/opt/mergebase/log4j-detector/samples/log4j-core-2.0-beta9.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.0.2.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.0.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.10.0.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.12.2.jar contains Log4J-2.x >= 2.12.2 _SAFE_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.14.1.jar contains Log4J-2.x >= 2.10.0 _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.15.0.jar contains Log4J-2.x >= 2.15.0 _OKAY_ :-|
/op t/mergebase/log4j-detector/samples/log4j-core-2.16.0.jar contains Log4J-2.x >= 2.16.0 _OKAY_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.17.0.jar contains Log4J-2.x >= 2.16.0 _SAFE_ :-)
/opt/mergebase/log4j-detector/samples/log4j-core-2.4.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-(
/opt/mergebase/log4j-detector/samples/log4j-core-2.9.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) _VULNERABLE_ :-( Understanding The Results_VULNERABLE_ -> You need to upgrade or remove this file._OKAY_ -> We only report this for Log4J versions 2.15.0 and 2.16.0. We recommend upgrading to 2.17.0.
_SAFE_ -> We currently only report this for Log4J versions 2.17.0 and 2.12.2.
_OLD_ -> You are safe from CVE-2021-44228, but should plan to upgrade because Log4J 1.2.x has been EOL for 7 years and has several known-v[...]
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
KitPloit - PenTest Tools!
Log4J-Detector - Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046
___________________________
@hacking_Attack
@Hacking_Video
Log4J-Detector - Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.