Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cracking a Weak Password
https://cdn-images-1.medium.com/max/1172/1*u_oIPzeBBQXWr9xLP3TdgA.png
It has been a while since I have documented myself going through a lab, but I think it will be good to look back on and show my progress…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cracking a Weak Password
https://cdn-images-1.medium.com/max/1172/1*u_oIPzeBBQXWr9xLP3TdgA.png
It has been a while since I have documented myself going through a lab, but I think it will be good to look back on and show my progress…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cracking a Weak Password
It has been a while since I have documented myself going through a lab, but I think it will be good to look back on and show my progress…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Extremely Critical Log4J Vulnerability Leaves Much of the Internet at Risk
https://cdn-images-1.medium.com/max/728/0*wJuJHEmPt8hf14Da
An Apache Software Foundation update contains fixes to a zero-day vulnerability affecting Apache Log4j (Java-based logging library). The…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Extremely Critical Log4J Vulnerability Leaves Much of the Internet at Risk
https://cdn-images-1.medium.com/max/728/0*wJuJHEmPt8hf14Da
An Apache Software Foundation update contains fixes to a zero-day vulnerability affecting Apache Log4j (Java-based logging library). The…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Extremely Critical Log4J Vulnerability Leaves Much of the Internet at Risk
An Apache Software Foundation update contains fixes to a zero-day vulnerability affecting Apache Log4j (Java-based logging library). The…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SpyderSec VM Walkthrough
https://cdn-images-1.medium.com/max/750/0*pGkqRq6ZbEGCpI7g.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SpyderSec VM Walkthrough
https://cdn-images-1.medium.com/max/750/0*pGkqRq6ZbEGCpI7g.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SpyderSec VM Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cómo evitar la fuga de datos corporativos en la nube
https://cdn-images-1.medium.com/max/1622/0*XRsDlmevuUq6R5VX
PUBLICADO EN 6 ENERO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cómo evitar la fuga de datos corporativos en la nube
https://cdn-images-1.medium.com/max/1622/0*XRsDlmevuUq6R5VX
PUBLICADO EN 6 ENERO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cómo evitar la fuga de datos corporativos en la nube
PUBLICADO EN 6 ENERO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CDN Cache Poisoning Allows DoS Attacks Against Cloud Apps
A Romanian researcher discovers more than 70 vulnerabilities in how applications and their content delivery networks handle cache misses that open the doors to denial-of-service attacks.
___________________________
@hacking_Attack
@Hacking_Video
CDN Cache Poisoning Allows DoS Attacks Against Cloud Apps
A Romanian researcher discovers more than 70 vulnerabilities in how applications and their content delivery networks handle cache misses that open the doors to denial-of-service attacks.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
CDN Cache Poisoning Allows DoS Attacks Against Cloud Apps
A Romanian researcher discovers more than 70 vulnerabilities in how applications and their content delivery networks handle cache misses that open the doors to denial-of-service attacks.
Another simple .NET executable to create and add a backdoor user
https://www.reddit.com/r/redteamsec/comments/rxjijb/another_simple_net_executable_to_create_and_add_a/
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful for privilege escalations on Windows (i.e. unquoted service path) Repo: https://github.com/notdodo/LocalAdminSharp submitted by /u/d_o_d_o_ (https://www.reddit.com/user/d_o_d_o_)
[link] (https://www.reddit.com/r/redteamsec/comments/rxjijb/another_simple_net_executable_to_create_and_add_a/) [comments] (https://www.reddit.com/r/redteamsec/comments/rxjijb/another_simple_net_executable_to_create_and_add_a/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/rxjijb/another_simple_net_executable_to_create_and_add_a/
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful for privilege escalations on Windows (i.e. unquoted service path) Repo: https://github.com/notdodo/LocalAdminSharp submitted by /u/d_o_d_o_ (https://www.reddit.com/user/d_o_d_o_)
[link] (https://www.reddit.com/r/redteamsec/comments/rxjijb/another_simple_net_executable_to_create_and_add_a/) [comments] (https://www.reddit.com/r/redteamsec/comments/rxjijb/another_simple_net_executable_to_create_and_add_a/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Another simple .NET executable to create and add a backdoor user
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful...
Exploit Collector
Backdoor.Win32.Dsklite.a Denial Of Service
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Dsklite.a Denial Of Service
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Dsklite.a Denial Of Service
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Jtram.a Insecure Credential Storage
https://4.bp.blogspot.com/-hp3wB9AXd0k/WWlvDY5V44I/AAAAAAAAIKs/ScSIhWVAvDAhjeMkIwqbNby9r3gKQvOEgCLcBGAs/s1600/h128.png
Backdoor.Win32.Jtram.a malware suffers from an insecure credential storage vulnerability.
MD5 |
Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/596882dfba543b23ad3225d24ee5e800.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Jtram.a
Vulnerability: Insecure Credential Storage
Description: The malware listens on TCP port 1321 as an FTP server. The credentials are stored in cleartext in a file named "rconnect.conf.
Type: PE32
MD5: 596882dfba543b23ad3225d24ee5e800
Vuln ID: MVID-2022-0442
Disclosure: 01/05/2022
Exploit/PoC:
C:\Windows\walker\rconnect.conf
"rconnect.conf"
LicenseName "thanksKRUPT"
LicenseKey "8337B4C8:7A6C84D2"
MaxConnections 100
BindInterface All
BindPort 1321
CommandTimeout 300
ConnectTimeout 15
LookupHosts On
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Jtram.a Insecure Credential Storage
https://4.bp.blogspot.com/-hp3wB9AXd0k/WWlvDY5V44I/AAAAAAAAIKs/ScSIhWVAvDAhjeMkIwqbNby9r3gKQvOEgCLcBGAs/s1600/h128.png
Backdoor.Win32.Jtram.a malware suffers from an insecure credential storage vulnerability.
MD5 |
a67cc235af4c610f3be1873cf9b09cf6Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/596882dfba543b23ad3225d24ee5e800.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Jtram.a
Vulnerability: Insecure Credential Storage
Description: The malware listens on TCP port 1321 as an FTP server. The credentials are stored in cleartext in a file named "rconnect.conf.
Type: PE32
MD5: 596882dfba543b23ad3225d24ee5e800
Vuln ID: MVID-2022-0442
Disclosure: 01/05/2022
Exploit/PoC:
C:\Windows\walker\rconnect.conf
"rconnect.conf"
LicenseName "thanksKRUPT"
LicenseKey "8337B4C8:7A6C84D2"
MaxConnections 100
BindInterface All
BindPort 1321
CommandTimeout 300
ConnectTimeout 15
LookupHosts On
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Jtram.a Insecure Credential Storage
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Jtram.a Man-In-The-Middle
https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Backdoor.Win32.Jtram.a malware suffers from a man-in-the-middle vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Jtram.a Man-In-The-Middle
https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Backdoor.Win32.Jtram.a malware suffers from a man-in-the-middle vulnerability.
MD5 |
a3b002448c3e199c3bd7785c3d3014f3Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/596882dfba543b23ad3225d24ee5e800_B.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Jtram.a
Vulnerability: Port Bounce Scan
Description: The malware listens on TCP port 1321. Third-party intruders who successfully logon can abuse the backdoor FTP server as a man-in-the-middle machine allowing PORT Command bounce scan attacks using Nmap. This vulnerability allows remote attackers to abuse your system and discreetly conduct network port scanning. Victims will then think these scans are originating from the infected system running the afflicted malware FTP Server and not you.
Type: PE32
MD5: 596882dfba543b23ad3225d24ee5e800
Vuln ID: MVID-2022-0443
Disclosure: 01/05/2022
Exploit/PoC:
nmap -n -Pn -b common:common@192.168.18.129:1321 -p21,22,80 192.168.18.237 -v
Starting Nmap 7.80 ( https://nmap.org ) at 2021-12-29 19:11 Pacific Standard Time
Resolved FTP bounce attack proxy to 192.168.18.129 (192.168.18.129).
Attempting connection to ftp://common:common@192.168.18.129:1321
Connected:220-rconnect 3.12, by WhitSoft Development (www.whitsoftdev.com)
220-You are connecting from 130.18.168.192.in-addr.arpa:5074.
220 Proceed with login.
Login credentials accepted by FTP server!
Initiating Bounce Scan at 19:12
Discovered open port 80/tcp on 192.168.18.237
Completed Bounce Scan at 19:12, 2.11s elapsed (3 total ports)
Nmap scan report for 192.168.18.237
Host is up.
PORT STATE SERVICE
21/tcp closed ftp
22/tcp closed ssh
80/tcp open http
Read data files from: C:\Program Files (x86)\Nmap
Nmap done: 1 IP address (1 host up) scanned in 11.28 seconds
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Jtram.a Man-In-The-Middle
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.