Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bugPost Views: 101 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
A novel persistent denial of service vulnerability named ‘doorLock’ was discovered in Apple HomeKit, affecting iOS 14.7 through 15.2.
Apple HomeKit is a software framework that lets iPhone and iPad users control smart home appliances from their devices.

According to Trevor Spiniolas, the security researcher who publicly disclosed the details, Apple has known about the flaw since August 10, 2021. Yet, despite the repeated promises to fix it, the researcher says Apple has continually pushed the security update further, and it remains unresolved.

I believe this bug is being handled inappropriately as it poses a serious risk to users and many months have passed without a comprehensive fix. The public should be aware of this vulnerability and how to prevent it from being exploited, rather than being kept in the dark. – Spinolas.
See Also: Complete Offensive Security and Ethical Hacking Course Forcing a resetTo trigger ‘doorLock,’ an attacker would change the name of a HomeKit device to a string larger than 500,000 characters.

To demonstate the doorLock bug, Spinolas has released a proof-of-concept exploit in the form of an iOS app that has access to Home data and can change HomeKit device names.

Even if the target user doesn’t have any Home devices added on HomeKit, there’s still an attack pathway by forging and accepting an invitation to add one.
Upon attempting to load the large string, a device running a vulnerable iOS version will be thrown into a denial of service (DoS) state, with a forced reset being the only way out of it. However, resetting the device will cause all stored data to be removed and only recoverable if you have a backup.
See Also: Hackers start pushing malware in worldwide Log4Shell attacks
To make matters worse, once the device reboots and the user signs back into the iCloud account linked to the HomeKit device, the bug will be re-triggered.
“In iOS 15.1 (or possibly 15.0), a limit on the length of the name an app or the user can set was introduced,” explains Spiniolas in his blog post.

“The introduction of a local size limit on the renaming of HomeKit devices was a minor mitigation that ultimately fails to solve the core issue, which is the way that iOS handles the names of HomeKit devices.”

“If an attacker were to exploit this vulnerability, they would be much more likely to use Home invitations rather than an application anyways, since invitations would not require the user to actually own a HomeKit device.”

The impact of this attack ranges from having an unusable device that reboots indefinitely to not being able to take a backup of your data from iCloud as signing back to the online backup services re-triggers the flaw.

As the researcher explains, this attack could be used as a ransomware vector, locking iOS devices into an unusable state and demanding a ransom payment to set the HomeKit device back to a safe string length.
See Also: Offensive Security Tool: Spray365 How to protect yourselfIt is essential to underline that the bug can only be exploited by someone with access to your ‘Home’ or via manually accepting an invitation to one.

With that said, there’s no reliable method of regaining access to local data after ‘doorLock’ has been triggered, so users should focus all efforts on prevention.

For this, bew[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bugPost Views:…
are of suspicious invitation messages from email addresses that resemble Apple services or HomeKit products.

If the damage has already been done, follow these three steps to restore your data from the iCloud:

1. Restore the affected device from Recovery or DFU Mode
2. Set up the device as usual, but do NOT sign back into the iCloud account
3. After setup is finished, sign in to iCloud from settings. Immediately after doing so, disable the switch labeled “Home.” The device and iCloud should now function again without access to Home data.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
According to the researcher, Apple’s latest estimate for fixing the bug is for “early 2022,” which will be done through an upcoming security update.

We have reached out to Apple to request a comment on the above, and we will update this story as soon as we hear back from them.
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/exchange-90x90.png Microsoft releases emergency fix for Exchange – 2022 bug23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/maxresdefault-90x90.jpg Have I Been Pwned adds 441K accounts stolen by RedLine malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/1229111902.0-90x90.jpg T-Mobile says new data breach caused by SIM swap attacks5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/feature-log4j-blue-90x90.png Log4j 2.17.1 out now, fixes new remote code execution bug6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/qnap-logo-white-90x90.jpg QNAP NAS devices hit in surge of ech0raix ransomware attacks7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/shutterstock_495927541-90x90.jpg Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/apple-store-tower-90x90.jpg Apple fixes macOS security flaw behind Gatekeeper bypass2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5157-article-201208-ms-team_body_text-90x90.jpg Microsoft Teams bug allowing phishing unpatched since March2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-6-90x90.jpg 800K WordPress sites still impacted by critical SEO plugin flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-5-90x90.jpg Microsoft warns of easy Windows domain takeover via Active Directory bugs2 weeks ago
The post Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Vpn used for hacking

So i recently started hacking and I don't understand how hacking with a vpn works when you connect to a vpn to get trough a network firewall so you can port scan your target, can someone explain this concept to me?

submitted by /u/Splendexz
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Spotlight: Earn Bitcoin While Browsing The Web On Desktop And Mobile

Is it too good to be true? Well, join me on my quest to find out.Continue reading on Medium »
Read more...
SQL Injection - The File Upload Playground

Summary :Continue reading on Medium »
Read more...
Metasploit payloads dont work with custom loaders
https://www.reddit.com/r/Pentesting/comments/rvs7pu/metasploit_payloads_dont_work_with_custom_loaders/

Hello, i have the problem that, no matter in which way i try, i cant get a metasploit payload executed correctly by any loader (cpp). The program run, but there was no meterpreter session opened no more What I tried: Simple xor encryption and decryption Simple AES encryption and decryption Even base64 encoding doesnt work for me I also tried to research the root of the problem with no success. The source I used already was fixed for all problems any debugger gave me: The python script for aes encryption: https://pastebin.com/Qyxa3Zrr The cpp loader that decrypts and runs the payload in memory: https://pastebin.com/MfVynd45 the compiler (a custom batch): https://pastebin.com/rn6zXfqi I already tried to generate a PE with msfvenom and run it through the python, did not work. I tried to generate the raw payload with msfvenom, then encrypt it manually and put in aes key and payload into the cpp, didnt work. I tried to generate with -f raw -o 1.bin, then run the .bin through the python, didnt work. How do i have to generate the payload and put it into so it might work? submitted by /u/janameyers2002 (https://www.reddit.com/user/janameyers2002)
[link] (https://www.reddit.com/r/Pentesting/comments/rvs7pu/metasploit_payloads_dont_work_with_custom_loaders/) [comments] (https://www.reddit.com/r/Pentesting/comments/rvs7pu/metasploit_payloads_dont_work_with_custom_loaders/)

___________________________
@hacking_Attack
@Hacking_Video
SyntheticSun - A Defense-In-Depth Security Automation And Monitoring Framework Which Utilizes Threat Intelligence, Machine Learning, Managed AWS Security Services And, Serverless Technologies To Continuously Prevent, Detect And Respond To Threats
http://www.kitploit.com/2022/01/syntheticsun-defense-in-depth-security.html

___________________________
@hacking_Attack
@Hacking_Video
SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, managed AWS security services and, serverless technologies to continuously prevent, detect and respond to threats.You sleep in fragmented glass
With reflections of you,
But are you feeling alive?
Yeah let me ask you,
Are you feeling alive?
- Norma Jean, 2016
SynopsisUses event- and time-based serverless automation (e.g. AWS CodeBuild, AWS Lambda) to collect, normalize, enrich, and correlate security telemetry in KibanaLeverages threat intelligence, geolocation data, open-source intelligence, machine learning (ML) backed anomaly detection and AWS APIs to further enrich security telemetry and identify potential threatsLeverages Random Cut Forests (RCF) and IP Insights unsupervised ML algorithms to identify anomalies in timeseries and IP-entity pair data, respectively. Serverless, container-orchestrated resources are provided to train and deploy new IP Insights endpoints at will.Dynamically updates AWS WAFv2 IP Sets and Amazon GuardDuty threat intel sets to bolster protection of your account and infrastructure against known threatsDescriptionSyntheticSun is built around the usage of the Malware Information Sharing (https://www.kitploit.com/search/label/Information%20Sharing) Platform (MISP) and Anomali's LIMO, which are community driven threat intelligence platforms (TIPs) that provide various types of indicators of compromise (https://www.kitploit.com/search/label/Indicators%20of%20Compromise) (IoC). Normalized and de-duplicated threat intel is looked up against in near-real time to quickly identify known threats in various types of network traffic. To add dynamism to the identification of potential threats IP Insights models are deployed to find anoamlies (and potential threats therein) between the pairing of IP addresses and entities (such as IAM principal ID's, user-agents, etc.), native RCF detectors are also used in Elasticsearch to find anomalies in near real-time security telemetry as it is streamed into Kibana. To democratize the usage and fine-tuning of ML models within security teams, utilities to train IP Insights models are provided as an add-on to the core solution.To perform the both the orchestration and automation as well as extraction, transformation, and loading (ETL) of security telemetry into Kibana, various AWS serverless technologies such as AWS Lambda, Amazon DynamoDB, and AWS CodeBuild are used. Serverless technologies such as these are used for their scalability, ease of use, relatively cheap costs versus heavy MapReduce or Glue ETL-based solutions. A majority of the solution is deployed via CloudFormation with helper scripts in Python and shell provided throughout the various Stages to promote adoption and the potential deployment in continuous integration (https://www.kitploit.com/search/label/Continuous%20Integration) pipelines.To make the "guts" of the solution as lean as possible basic Python modules such as boto3, requests, json, ipaddress, socket and re perform most of the extraction, transformation, and loading (ETL) into downstream services. Because all geolocation information is provided by ip-api.com (https://ip-api.com/docs), it does not require an account or paid tiers and has a great API which includes throttling information in their response headers. A majority of the Elasticsearch and Kibana dependencies are also provided in code (indicies, mappings, visualizations, etc) to avoid heavy manual configuration.Setting UpSyntheticSun is spread across three Stages due to the size of solution and the required dependencies. All architecture and installation instructions (and FAQs where appropriate) live within their own Stage. Add-ons modules (called an Appendix) are also provided to extend the functionality, which have their own architecture and installation instructions localized.Before you start: Considerations for Production deploymentsSyntheticSun, by virtue

___________________________
@hacking_Attack
@Hacking_Video
of being something you found on GitHub, is a proof-of-concept and therefore I did not go the extra mile for the first release to absolutely harden everything. Provided you are reading this at a point in time where I have not made the necessary changes, consider the following before you deploy this solution into a production environment (or any environment with heightened security needs). I will put these items on a roadmap and update them as appropiate.Train your own IP Insights models using the examples provided in Appendix A (https://github.com/jonrau1/SyntheticSun/tree/master/appendix-a-ipinsights). Using your own data, and continually retraining the model, will help accurize findings.Deploy your CodeBuild projects, MISP server, and Elasticsearch Service domain in a VPC in order to harden against internet-borne attacks. Consider using AWS' Client VPN, AWS Site-to-Site VPN, DirectConnect, Amazon Workspaces, and AppStream 2.0 or (if you absolutely have to) a reverse-proxy to access the MISP console and Kibana within a VPC.Consider using Cognito for AuthN into Kibana. Go a step further and federate your User Pool with your corporate IdP.Consider baking your own AMI for MISP or use Fargate to host it. I would also consider pre-baking Suricata and the Amazon CloudWatch Agent into future builds to help scale deployments of agents and HIDPS across your estate.Modify your Suricata configuration to suit the needs of your SecOps teams looking at the logs, since all this solution does is dump them in. You may also consider writing your own rules or importing other sources to harden your hosts against attacks.PrerequisitesAdmin access to an AWS Account (if you are using this in a multi-account deployment, you must be in the account where your Masters or Delegated Admin Masters are located)Application Load Balancer (ALB) with at least one target instance and access logs enabledCloudTrail logging enabled in your accountOne VPC with at least one private subnet (route to NATGW), one public subnet (route to IGW), and VPC Flow Logs enabled as well as published to CloudWatch LogsStage 1 starts here (https://github.com/jonrau1/SyntheticSun/tree/master/readme-stage1)FAQ1. Why should I use this solution?SyntheticSun is an easy way to start using cyber threat intelligence (https://www.kitploit.com/search/label/Cyber%20Threat%20Intelligence) and machine learning for your edge protection security use cases on the AWS Cloud without having to invest in one or more commercial tools, or hiring a data scientist for your security team (though you should ideally do the latter). This solution, after initial configuration, is fully automated, allowing you to identify and respond to threats at machine speed. Finally, this solution provides basic visualizations for your incident response team to use for threat response, such as allowed inbound or outbound connections or DNS queries to and from IP addresses or domains deemed to be malicious. The core of the solution relies on very lightweight automation and data engineering pipelines, which theoretically, can be reused for other purposes where multi-stage normalization and enrichment or scheduled, fast-paced batch jobs are needed.2. Who should use this solution?Firstly, if you are making use of Amazon GuardDuty and/or AWS WAF, it may make sense to evaluate this solution, but it is also a requirement. Obvious personas who can take advantage are product teams responsible for securing their full stack and lack the capital or expertise to model, train and deploy machine learning algorithms or operationalize cyber threat intelligence feeds meaningfully. Those aforementioned personas are likely security engineering, SecOps / SOC analysts & engineers, or a DevSecOps engineer; however, this list is not exhaustive, and they do not need to be product / application-aligned as central teams can use this as well. Another usage is those same personas (SecOps, security engineering) that work for a centralized team and want

___________________________
@hacking_Attack
@Hacking_Video
to create a dynamic block list for firewalls and intrusion prevention (https://www.kitploit.com/search/label/Intrusion%20Prevention) systems, the CodeBuild projects can be repurposed to drop CSV or flat files to almost any location (e.g. Palo Alto firewalls, Squid forward proxy URL filters, etc.).3. What are the gaps in this solution?SyntheticSun currently lacks full coverage across all main log sources - namely, S3 Access Logs and CloudFront Access Logs, which are integral to the way a lot of folks deliver services (especially for SPAs on S3 buckets). The anomaly detection does not extend past WAF, API Gateway Access Logs, or CloudTrail due to my obsession with IP Insights and complete lack of any data science training (seriously, I don't even know how to use pandas or numpy). There is not any in-depth analysis of raw threat intelligence IoCs other than attempting to match it in the logs.4. Outside of the Masters for the AWS Security Services, what considerations are there for an Organizational deployment?The easiest way to deploy this solution for an organization is to deploy it in a centralized security services account. For the lower-level telemetry such as VPC Flow Logs and WAF Logs, you should consider providing helper scripts or CloudFormation templates via AWS Service Catalog to promote enablement in lower environments. You will need to evaluate your shard consumption and index rotation of Elasticsearch Service, as well as the permissions, if you will be having cross-account Kinesis Data Firehose delivery streams publishing into a centralized location. I built this solution in my personal sandbox account, hence why I did not bake any of the considerations from above into the solution, I will be happy to work on a PR with this in mind and may do it myself in the future.As of 31 JULY 2020 AWS Firewall Manager Policies support the multi-account aggregation of WAF Logging which brings you one step closer to making this a lot less painful...5. What is the IP Insights algorithm? Is your usage really what it was intended for?CAVEATS: I am not a data scientist and this is going to be a long answer. Tl;dr: It's an anomaly finder and I think?Given that I am not remotely close to a data scientist or have any training you are better served reading the docs (https://docs.aws.amazon.com/sagemaker/latest/dg/ip-insights-howitworks.html) on this. That said, here is my layman's attempt at it: IP Insights is an unsupervised machine learning algorithm that learns the relationship between an IPv4 address and an entity (e.g. Account number, user name, user-agent). IP Insights then attempts to determine how likely it is that the entity would use that IPv4 address. Behind the curtains of IP Insights is a neural network that learns the latent vector representation of these entities and IPv4 addresses. The distance between these vectorized representations is emblematic for how anomalous (or not) it is for an entity to be associated with (e.g send a request from) an IPv4 address.Neural networks are almost exactly like they sound; they form a machine learning system designed to behave similarly to the human brain, complete with computerized neurons and synapses. In unsupervised machine learning, the algorithm can suss out what "good" (i.e. True Negative) looks like versus "bad" (i.e. True Positive) by looking at the association between all IPv4 addresses and their paired entities. This association is evaluated in order to identify what vectors are similar to the others by their "distance". In IP Insights' case, a prebuilt encoder is provided that searches for IPv4 addresses and then hashes out all entities into clusters. It then iterates over them using vectorization. Vectorization is a way to perform computations as a matrix instead of looping over them (think of a "For" loop for a list containing tens of millions of values).When you are training an IP Insights model, it will actually create itself false positives by pairing IPv4 addresses

___________________________
@hacking_Attack
@Hacking_Video