Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Watson - Enumerate Missing KBs And Suggest Exploits For Useful Privilege Escalation Vulnerabilities

Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation vulnerabilities.Supported Versions Windows 10 1507, 1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004 Server 2016 & 2019 Usage C:\> Watson.exe _ _ _ / / /\ \ \_ _| |_ _ _ _ _ \ \/ \/ / _` | _/ _|/ _ \| '_ \ \ /\ / (_| | |_\_ \ () | | | | \/ \/ \\,_|\_|_/\_/|_| |_| v2.0 @_RastaMouse \* OS Build Number: 14393 \* Enumerating installed KBs... ! CVE-2019-0836 : VULNERABLE > https://exploit-db.com/exploits/46718 > https://decoder.cloud/2019/04/29/combinig-luafv-postluafvpostreadwrite-race-condition-pe-with-diaghub-collector-exploit-from-standard-user-to-system/ ! CVE-2019-0841 : VULNERABLE > https://github.com/rogue-kdc/CVE-2019-0841 > https://rastamouse.me/tags/cve-2019-0841/ ! CVE-2019-1064 : VULNERABLE > https://www.rythmstick.net/posts/cve-2019-1064/ ! CVE-2019-1130 : VULNERABLE > https://github.com/S3cur3Th1sSh1t/SharpByeBear ! CVE- 2019-1253 : VULNERABLE > https://github.com/padovah4ck/CVE-2019-1253 ! CVE-2019-1315 : VULNERABLE > https://offsec.almond.consulting/windows-error-reporting-arbitrary-file-move-eop.html \* Finished. Found 6 potential vulnerabilities. Issues I try to update Watson after every Patch Tuesday, but for potential false positives check the latest supersedence information in the Windows Update Catalog. If you still think there's an error, raise an Issue with the Bug label. If there's a particular vulnerability that you want to see in Watson that's not already included, raise an Issue with the Vulnerability Request label and include the CVE number. If you know of a good exploit for any of the vulnerabilities in Watson, raise an Issue with the Exploit Suggestion label and provide a URL to the exploit. Download Watson
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Watson - Enumerate Missing KBs And Suggest Exploits For Useful Privilege Escalation Vulnerabilities

https://1.bp.blogspot.com/-of7mBTen-mk/YGKeTq2QQiI/AAAAAAAAVwA/-paRxYr-yvES1HxqVwS_uS4YoNPRqUAfwCNcBGAsYHQ/w640-h316/Privilege%2BEscalation.png
Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation vulnerabilities.
Supported Versions

* Windows 10 1507, 1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004
* Server 2016 & 2019

Usage
C:\> Watson.exe
__ __ _
/ / /\ \ \__ _| |_ ___ ___ _ __
\ \/ \/ / _` | __/ __|/ _ \| '_ \
\ /\ / (_| | |_\__ \ (_) | | | |
\/ \/ \__,_|\__|___/\___/|_| |_|

v2.0

@_RastaMouse

[*] OS Build Number: 14393
[*] Enumerating installed KBs...

[!] CVE-2019-0836 : VULNERABLE
[>] https://exploit-db.com/exploits/46718
[>] https://decoder.cloud/2019/04/29/combinig-luafv-postluafvpostreadwrite-race-condition-pe-with-diaghub-collector-exploit-from-standard-user-to-system/

[!] CVE-2019-0841 : VULNERABLE
[>] https://github.com/rogue-kdc/CVE-2019-0841
[>] https://rastamouse.me/tags/cve-2019-0841/

[!] CVE-2019-1064 : VULNERABLE
[>] https://www.rythmstick.net/posts/cve-2019-1064/

[!] CVE-2019-1130 : VULNERABLE
[>] https://github.com/S3cur3Th1sSh1t/SharpByeBear

[!] CVE- 2019-1253 : VULNERABLE
[>] https://github.com/padovah4ck/CVE-2019-1253

[!] CVE-2019-1315 : VULNERABLE
[>] https://offsec.almond.consulting/windows-error-reporting-arbitrary-file-move-eop.html

[*] Finished. Found 6 potential vulnerabilities.

Issues

*
I try to update Watson after every Patch Tuesday, but for potential false positives check the latest supersedence information in the Windows Update Catalog. If you still think there's an error, raise an Issue with the Buglabel.

*
If there's a particular vulnerability that you want to see in Watson that's not already included, raise an Issue with the Vulnerability Requestlabel and include the CVE number.

*
If you know of a good exploit for any of the vulnerabilities in Watson, raise an Issue with the Exploit Suggestionlabel and provide a URL to the exploit.
Download Watson
Deep Web
Jeremie Dubois-Lacoste is the reason why you should invest in M.o.n.e.r.o

Jeremie Dubois-Lacoste who is known as binaryfate believes M.o.n.e.r.o crypto coin is the best project of current. binaryfate is a high-IQ businessman with a PhD in AI and believes it has great potential of growing in price and is a good investment option of right now. invest in M.o.n.e.r.o coin today for certain profit and join the community.

submitted by /u/savingguernsey42
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Create backdoors with Veil-Evasion

https://cdn-images-1.medium.com/max/2154/1*swr1bFBREY--z4Exmpfs6Q.jpeg
Veil-Evasion is an instrument to produce payload executables that sidestep regular antivirus solutions. Veil-Evasion’s code can be found…

Continue reading on InfoSec Write-ups »
hacking: security in practice
EMV Chip protocols and read/writes

I have a laundry card for my apartment's shared washer/dryer setup. There's a kiosk in the lobby that allows you to refill with cash or credit, you stick the card in the machines, and you do your laundry.

However, I noticed something interesting: the machines are not network-connected. Unless they're using a hidden wifi access point from the reader itself, which in this case seems very unlikely, the balance must be stored on the card itself.

I'm curious about how all of this works since my understanding of EMV protocols and data storage is weak. Does anyone know how it would be possible to examine this data with something like a USB chip reader from Amazon? Caleco is the vendor if anyone knows where to find doc.

I saw another very similar thread in my Googling so far but it seemed to revolve around networked laundry machines which doesn't appear to be the case, unless that's a certainty and I'm missing something.

submitted by /u/YmFzZTY0dXNlcm5hbWU_
[link] [comments]
Youngest Ethical hacker of India |Ritik Sahni

Today, we will introduce you all with a 15 year old hacker from India. The name of this 15-year old hacker is Ritik Sahni. He earns by…Continue reading on Medium »
Read more...
Today, we will introduce you all with a 15 year old hacker from India. The name of this 15-year old hacker is Ritik Sahni. He earns by…Continue reading on Medium » (https://meethackers.medium.com/youngest-ethical-hacker-of-india-ritik-sahni-96640671219c?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Facebook data on 533 million users posted online

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Facebook data on 533 million users posted onlinePost Views: 72
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
Data of 533 million Facebook users including phone numbers, Facebook IDs, full names, birth dates and other information have been posted online.
The data dump was Tweeted by Alon Gal, CTO of security firm Hudson Rock. Gal posted a list of affected users by country. According to his list, the US had 32.3 million affected users and UK had 11.5 million. The data was accessed via a Telegram bot.

Other data points in the posting included gender, location and job status. Catalin Cimpanu, at The Record, also reported that he reviewed samples of the leaked data and Facebook confirmed.

The data is reportedly broken up into download packages by country.

With the Facebook data out in the public it’s safe to expect it to be used for cybercrime.
See Also: Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack
A few takeaways:

“The data is old” argument doesn’t hold up. Facebook said the data was was collected in 2019 and the company plugged the hole in August of that year.  How often are phone numbers connected to Facebook changed? Not frequently if at all. Other information that was published includes full names and birth dates. It’s unlikely that information changes either. It’s also worth noting that two years old is pretty fresh in data time.

A few takeaways:

“The data is old” argument doesn’t hold up. Facebook said the data was was collected in 2019 and the company plugged the hole in August of that year.  How often are phone numbers connected to Facebook changed? Not frequently if at all. Other information that was published includes full names and birth dates. It’s unlikely that information changes either. It’s also worth noting that two years old is pretty fresh in data time.
See Also: Offensive Security Tool: DirDar
Look for the data to be combined with other scams. Daniel Markuson, digital privacy expert at NordVPN, said the personal information remains a goldmine for scammers and can be combined with pandemic related cybercrimes.

This leak is just another reminder to take care of your data hygiene. If you haven’t already improved your security posture with better passwords, multi-factor authentication and other tools it’s time to get rolling. And maybe you shouldn’t readily share your data. See Also: Hacking Stories: When two young hackers played war games with PentagonFacebook is likely to face more scrutiny and the timing isn’t so great. Yes, this data was poached in 2019, but lawmakers just love questioning Facebook CEO Mark Zuckerberg over data collection. Meanwhile, tech giants are under more scrutiny than ever.
Source: www.zdnet.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads5 days ago
* https://www.blackhatet[...]