Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft: powerdir bug gives access to protected macOS user data
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft: powerdir bug gives access to protected macOS user dataPost Views: 71 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The Microsoft 365 Defender Research Team has reported the vulnerability dubbed powerdir (tracked as CVE-2021-30970) to Apple on July 15, 2021, via the Microsoft Security Vulnerability Research (MSVR).
Microsoft says threat actors could use a macOS vulnerability to bypass Transparency, Consent, and Control (TCC) technology to access users’ protected data.
While Apple has restricted TCC access only to apps with full disk access and set up features to automatically block unauthorized code execution, Microsoft security researchers found that attackers could plant a second, specially crafted TCC database that would allow them to access protected user info.
“We discovered that it is possible to programmatically change a target user’s home directory and plant a fake TCC database, which stores the consent history of app requests,” said Jonathan Bar Or, a principal security researcher at Microsoft.
“If exploited on unpatched systems, this vulnerability could allow a malicious actor to potentially orchestrate an attack based on the user’s protected personal data.
See Also: Complete Offensive Security and Ethical Hacking Course
“For example, the attacker could hijack an app installed on the device—or install their own malicious app—and access the microphone to record private conversations or capture screenshots of sensitive information displayed on the user’s screen.”
Apple has also patched other TCC bypasses reported since 2020, including:
* Time Machine mounts (CVE-2020-9771): macOS offers a built-in backup and restore solution called Time Machine. It was discovered that Time Machine backups could be mounted (using the apfs_mount utility) with the “noowners” flag. Since these backups contain the TCC.db files, an attacker could mount those backups and determine the device’s TCC policy without having full disk access.
* Environment variable poisoning (CVE-2020-9934): It was discovered that the user’s tccd could build the path to the TCC.db file by expanding $HOME/Library/Application Support/com.apple.TCC/TCC.db. Since the user could manipulate the $HOME environment variable (as introduced to tccd by launchd), an attacker could plant a chosen TCC.db file in an arbitrary path, poison the $HOME environment variable, and make TCC.db consume that file instead.
* Bundle conclusion issue (CVE-2021-30713): First disclosed by Jamf in a blog post about the XCSSET malware family, this bug abused how macOS was deducing app bundle information. For example, suppose an attacker knows of a specific app that commonly has microphone access. In that case, they could plant their application code in the target app’s bundle and “inherit” its TCC capabilities.
https://www.bleepstatic.com/images/news/u/1109292/2022/powerdir_poc.png
___________________________
@hacking_Attack
@Hacking_Video
Microsoft: powerdir bug gives access to protected macOS user data
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft: powerdir bug gives access to protected macOS user dataPost Views: 71 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The Microsoft 365 Defender Research Team has reported the vulnerability dubbed powerdir (tracked as CVE-2021-30970) to Apple on July 15, 2021, via the Microsoft Security Vulnerability Research (MSVR).
Microsoft says threat actors could use a macOS vulnerability to bypass Transparency, Consent, and Control (TCC) technology to access users’ protected data.
While Apple has restricted TCC access only to apps with full disk access and set up features to automatically block unauthorized code execution, Microsoft security researchers found that attackers could plant a second, specially crafted TCC database that would allow them to access protected user info.
“We discovered that it is possible to programmatically change a target user’s home directory and plant a fake TCC database, which stores the consent history of app requests,” said Jonathan Bar Or, a principal security researcher at Microsoft.
“If exploited on unpatched systems, this vulnerability could allow a malicious actor to potentially orchestrate an attack based on the user’s protected personal data.
See Also: Complete Offensive Security and Ethical Hacking Course
“For example, the attacker could hijack an app installed on the device—or install their own malicious app—and access the microphone to record private conversations or capture screenshots of sensitive information displayed on the user’s screen.”
Apple has also patched other TCC bypasses reported since 2020, including:
* Time Machine mounts (CVE-2020-9771): macOS offers a built-in backup and restore solution called Time Machine. It was discovered that Time Machine backups could be mounted (using the apfs_mount utility) with the “noowners” flag. Since these backups contain the TCC.db files, an attacker could mount those backups and determine the device’s TCC policy without having full disk access.
* Environment variable poisoning (CVE-2020-9934): It was discovered that the user’s tccd could build the path to the TCC.db file by expanding $HOME/Library/Application Support/com.apple.TCC/TCC.db. Since the user could manipulate the $HOME environment variable (as introduced to tccd by launchd), an attacker could plant a chosen TCC.db file in an arbitrary path, poison the $HOME environment variable, and make TCC.db consume that file instead.
* Bundle conclusion issue (CVE-2021-30713): First disclosed by Jamf in a blog post about the XCSSET malware family, this bug abused how macOS was deducing app bundle information. For example, suppose an attacker knows of a specific app that commonly has microphone access. In that case, they could plant their application code in the target app’s bundle and “inherit” its TCC capabilities.
https://www.bleepstatic.com/images/news/u/1109292/2022/powerdir_poc.png
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft: powerdir bug gives access to protected macOS user data | Black Hat Ethical Hacking
The Microsoft 365 Defender Research Team has reported the vulnerability dubbed powerdir (tracked as CVE-2021-30970) to Apple on July 15, 2021, via the Microsoft Security Vulnerability Research (MSVR).
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft: powerdir bug gives access to protected macOS user data https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft: powerdir bug gives access to protected macOS user dataPost Views:…
e latest macOS version, Monterey,” Jonathan Bar Or added.
“This shows that even as macOS or other operating systems and applications become more hardened with each release, software vendors like Apple, security researchers, and the larger security community, need to continuously work together to identify and fix vulnerabilities before attackers can take advantage of them.”
Microsoft has previously reported finding a security flaw dubbed Shrootless that would allow an attacker to bypass System Integrity Protection (SIP) and perform arbitrary operations, elevate privileges to root, and install rootkits on vulnerable devices.
See Also: Offensive Security Tool: Osmedeus The company’s researchers also discovered new variants of macOS WizardUpdate malware (aka UpdateAgent or Vigram), updated with new evasion and persistence tactics.
Last year, in June, Redmond revealed critical firmware bugs in some NETGEAR router models that hackers could use to breach and move laterally within enterprise networks.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-iPhone-13-Pro-90x90.png iOS malware can fake iPhone shut downs to snoop on camera, microphone5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0358ad020c37-article-cache-poisoning-article-90x90.png Researcher discovers 70 web cache poisoning vulnerabilities, nets $40k in bug bounty rewards6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/1200x0-90x90.jpg Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/exchange-90x90.png Microsoft releases emergency fix for Exchange – 2022 bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/maxresdefault-90x90.jpg Have I Been Pwned adds 441K accounts stolen by RedLine malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/1229111902.0-90x90.jpg T-Mobile says new data breach caused by SIM swap attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/feature-log4j-blue-90x90.png Log4j 2.17.1 out now, fixes new remote code execution bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/qnap-logo-white-90x90.jpg QNAP NAS devices hit in surge of ech0raix ransomware attacks2 weeks ago
The post Microsoft: powerdir bug gives access to protected macOS user data first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
“This shows that even as macOS or other operating systems and applications become more hardened with each release, software vendors like Apple, security researchers, and the larger security community, need to continuously work together to identify and fix vulnerabilities before attackers can take advantage of them.”
Microsoft has previously reported finding a security flaw dubbed Shrootless that would allow an attacker to bypass System Integrity Protection (SIP) and perform arbitrary operations, elevate privileges to root, and install rootkits on vulnerable devices.
See Also: Offensive Security Tool: Osmedeus The company’s researchers also discovered new variants of macOS WizardUpdate malware (aka UpdateAgent or Vigram), updated with new evasion and persistence tactics.
Last year, in June, Redmond revealed critical firmware bugs in some NETGEAR router models that hackers could use to breach and move laterally within enterprise networks.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-iPhone-13-Pro-90x90.png iOS malware can fake iPhone shut downs to snoop on camera, microphone5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0358ad020c37-article-cache-poisoning-article-90x90.png Researcher discovers 70 web cache poisoning vulnerabilities, nets $40k in bug bounty rewards6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/1200x0-90x90.jpg Apple iOS vulnerable to HomeKit ‘doorLock’ denial of service bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/exchange-90x90.png Microsoft releases emergency fix for Exchange – 2022 bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/maxresdefault-90x90.jpg Have I Been Pwned adds 441K accounts stolen by RedLine malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/1229111902.0-90x90.jpg T-Mobile says new data breach caused by SIM swap attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/feature-log4j-blue-90x90.png Log4j 2.17.1 out now, fixes new remote code execution bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/qnap-logo-white-90x90.jpg QNAP NAS devices hit in surge of ech0raix ransomware attacks2 weeks ago
The post Microsoft: powerdir bug gives access to protected macOS user data first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Burner Numbers
Is there a way to tell if a cell number is connected to an actual cell-phone or if it's a text only or burner app etc.?
submitted by /u/JBase16
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Burner Numbers
Is there a way to tell if a cell number is connected to an actual cell-phone or if it's a text only or burner app etc.?
submitted by /u/JBase16
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Burner Numbers
Is there a way to tell if a cell number is connected to an actual cell-phone or if it's a text only or burner app etc.?
hacking: security in practice
Antivirus for school project
Actually I was thinking about creating an antivirus for major project and I'm struggling on what language to use for it?? As I have done research and it seems C and C++ are compatible, is there any other language to be used
submitted by /u/NavyX11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Antivirus for school project
Actually I was thinking about creating an antivirus for major project and I'm struggling on what language to use for it?? As I have done research and it seems C and C++ are compatible, is there any other language to be used
submitted by /u/NavyX11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Antivirus for school project
Actually I was thinking about creating an antivirus for major project and I'm struggling on what language to use for it?? As I have done research...
WannaRace - WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
WebApp intentionally made vulnerable to Race ConditionDescriptionRace Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning Building and running the docker imageBuild the docker image with:git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRacedocker build -t xib3rr4dar/wanna_race:1.0 .Run docker image:docker run -it --rm xib3rr4dar/wanna_race:1.0ORdocker run -it --rm -p 9050:80 xib3rr4dar/wanna_race:1.0Then open in browser relevant IP:PORT ScreenshotsChallenge #1Main Page Four vouchers worth 400 units available for recharge Task is to buy Mega box (which is worth 401 units) by exploiting race conditionChallenge #2Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are setDownload WannaRace
Read more...
___________________________
@hacking_Attack
@Hacking_Video
WebApp intentionally made vulnerable to Race ConditionDescriptionRace Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning Building and running the docker imageBuild the docker image with:git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRacedocker build -t xib3rr4dar/wanna_race:1.0 .Run docker image:docker run -it --rm xib3rr4dar/wanna_race:1.0ORdocker run -it --rm -p 9050:80 xib3rr4dar/wanna_race:1.0Then open in browser relevant IP:PORT ScreenshotsChallenge #1Main Page Four vouchers worth 400 units available for recharge Task is to buy Mega box (which is worth 401 units) by exploiting race conditionChallenge #2Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are setDownload WannaRace
Read more...
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - Xib3rR4dAr/WannaRace: WebApp intentionally made vulnerable to Race Condition for practicing Race Condition
WebApp intentionally made vulnerable to Race Condition for practicing Race Condition - Xib3rR4dAr/WannaRace
Domain Escalation - ShadowCoerce [MS-FSRVP]
https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlaboratories.com/2022/01/11/shadowcoerce/) [comments] (https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlaboratories.com/2022/01/11/shadowcoerce/) [comments] (https://www.reddit.com/r/redteamsec/comments/s1bh7z/domain_escalation_shadowcoerce_msfsrvp/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Domain Escalation - ShadowCoerce [MS-FSRVP]
Posted in r/redteamsec by u/netbiosX • 1 point and 0 comments
WannaRace - WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
http://www.kitploit.com/2022/01/wannarace-webapp-intentionally-made.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/01/wannarace-webapp-intentionally-made.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
WannaRace - WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
WebApp intentionally made vulnerable (https://www.kitploit.com/search/label/Vulnerable) to Race Condition
DescriptionRace Condition vulnerability (https://www.kitploit.com/search/label/Vulnerability) can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie (https://www.kitploit.com/search/label/Cookie) is present, cookie is auto created when user is logged in. Happy learning
Building and running the docker imageBuild the docker image with:git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRace
docker build -t xib3rr4dar/wanna_race:1.0 .Run docker image:docker run -it --rm xib3rr4dar/wanna_race:1.0
ORdocker run -it --rm -p 9050:80 xib3rr4dar/wanna_race:1.0
Then open in browser relevant IP:PORT
ScreenshotsChallenge #1Main Page
___________________________
@hacking_Attack
@Hacking_Video
DescriptionRace Condition vulnerability (https://www.kitploit.com/search/label/Vulnerability) can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie (https://www.kitploit.com/search/label/Cookie) is present, cookie is auto created when user is logged in. Happy learning
Building and running the docker imageBuild the docker image with:git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRace
docker build -t xib3rr4dar/wanna_race:1.0 .Run docker image:docker run -it --rm xib3rr4dar/wanna_race:1.0
ORdocker run -it --rm -p 9050:80 xib3rr4dar/wanna_race:1.0
Then open in browser relevant IP:PORT
ScreenshotsChallenge #1Main Page
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Four vouchers worth 400 units available for recharge
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Task is to buy Mega box (which is worth 401 units) by exploiting (https://www.kitploit.com/search/label/Exploiting) race condition
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Challenge #2Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies (https://www.kitploit.com/search/label/Cookies) are set
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Download WannaRace (https://github.com/Xib3rR4dAr/WannaRace)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - Xib3rR4dAr/WannaRace: WebApp intentionally made vulnerable to Race Condition for practicing Race Condition
WebApp intentionally made vulnerable to Race Condition for practicing Race Condition - Xib3rR4dAr/WannaRace
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
WannaRace - WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
https://blogger.googleusercontent.com/img/a/AVvXsEgjP3t6bru-XjgSzIt9uEPpTRTFHIdcGNie-m50YGQqb8jUAwXJe-5szGiY_izIeX0gTyxTGboMBON68nxS08L3tmzc4_dbWBrR0Xdcc79V7Phv2R0W2oulGjPmxn_33LB_8uusBUlGsSPGrfq6Df0dHBvXuakD_PamyY_Smn_jRV6cXn9W82lMEpbr=w640-h240 WebApp intentionally made vulnerable to Race Condition Description Race Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning Building and running the docker imageBuild the docker image with:
Main Page https://blogger.googleusercontent.com/img/a/AVvXsEgjP3t6bru-XjgSzIt9uEPpTRTFHIdcGNie-m50YGQqb8jUAwXJe-5szGiY_izIeX0gTyxTGboMBON68nxS08L3tmzc4_dbWBrR0Xdcc79V7Phv2R0W2oulGjPmxn_33LB_8uusBUlGsSPGrfq6Df0dHBvXuakD_PamyY_Smn_jRV6cXn9W82lMEpbr=w640-h240 Four vouchers worth 400 units available for recharge https://blogger.googleusercontent.com/img/a/AVvXsEhP-rUpAnTeV1FzYt8QnshGPr3dusefpMWr7kNN-OzoeHNnFletGoRW0IVRPTCyLv85wDFCL8I5_E0W4__uCy2HlFked4QdsAGewOff-SrV1Xe87h3sTa27SS9ILT8gTyOef5dL25ks9PGYXWXBFEIIhjtW2MKSyxXyHWg_wmfVCSo0QP6bUZjcDgCq=w640-h480 Task is to buy Mega box (which is worth 401 units) by exploiting race condition https://blogger.googleusercontent.com/img/a/AVvXsEi92nbp0P7XLHqnQOVcTPcKEGq2Bq-z90g3NCMvXVd-ChlRjxQbOyY10c0e8iY859XOt9vvXeVlHtHEbTka7VvJ_rZbz69XgOHtoWWxgHBGa8fiPhrMwYn4mlOvaxPpkCKg-7ttfWZAg-bU5rKatWwowbQfUT0DXCc2ZEVNegLAa1DQGou6xAJsKAPG=w640-h396 Challenge #2
Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are set https://blogger.googleusercontent.com/img/a/AVvXsEgdPMLdHRwnWwaWmaj2VMFqlPGsUW2H98NnjlOv1_loxelQOTW2QQLRVJlvPvTPr3vVV3dXCHQOG49IpxrIjo1KSgOPltHnK_MFy0QZ3WPxElOcSStMytKB702qrGPjOWjzk4vwO-CNQHJaqegWbISdv24w2_1q7p6-XfBDeSadSvnbx2cdeZKKIrWb=w640-h214 Download WannaRace
___________________________
@hacking_Attack
@Hacking_Video
WannaRace - WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
https://blogger.googleusercontent.com/img/a/AVvXsEgjP3t6bru-XjgSzIt9uEPpTRTFHIdcGNie-m50YGQqb8jUAwXJe-5szGiY_izIeX0gTyxTGboMBON68nxS08L3tmzc4_dbWBrR0Xdcc79V7Phv2R0W2oulGjPmxn_33LB_8uusBUlGsSPGrfq6Df0dHBvXuakD_PamyY_Smn_jRV6cXn9W82lMEpbr=w640-h240 WebApp intentionally made vulnerable to Race Condition Description Race Condition vulnerability can be practiced in the developed WebApp. Task is to buy a Mega Box using race condition that costs more than available vouchers. Two challenges are made for practice. Challenge B is to be solved when PHPSESSID cookie is present, cookie is auto created when user is logged in. Happy learning Building and running the docker imageBuild the docker image with:
git clone https://github.com/Xib3rR4dAr/WannaRace && cd WannaRace
docker build -t xib3rr4dar/wanna_race:1.0 .Run docker image: docker run -it --rm xib3rr4dar/wanna_race:1.0 OR docker run -it --rm -p 9050:80 xib3rr4dar/wanna_race:1.0 Then open in browser relevant IP:PORT ScreenshotsChallenge #1Main Page https://blogger.googleusercontent.com/img/a/AVvXsEgjP3t6bru-XjgSzIt9uEPpTRTFHIdcGNie-m50YGQqb8jUAwXJe-5szGiY_izIeX0gTyxTGboMBON68nxS08L3tmzc4_dbWBrR0Xdcc79V7Phv2R0W2oulGjPmxn_33LB_8uusBUlGsSPGrfq6Df0dHBvXuakD_PamyY_Smn_jRV6cXn9W82lMEpbr=w640-h240 Four vouchers worth 400 units available for recharge https://blogger.googleusercontent.com/img/a/AVvXsEhP-rUpAnTeV1FzYt8QnshGPr3dusefpMWr7kNN-OzoeHNnFletGoRW0IVRPTCyLv85wDFCL8I5_E0W4__uCy2HlFked4QdsAGewOff-SrV1Xe87h3sTa27SS9ILT8gTyOef5dL25ks9PGYXWXBFEIIhjtW2MKSyxXyHWg_wmfVCSo0QP6bUZjcDgCq=w640-h480 Task is to buy Mega box (which is worth 401 units) by exploiting race condition https://blogger.googleusercontent.com/img/a/AVvXsEi92nbp0P7XLHqnQOVcTPcKEGq2Bq-z90g3NCMvXVd-ChlRjxQbOyY10c0e8iY859XOt9vvXeVlHtHEbTka7VvJ_rZbz69XgOHtoWWxgHBGa8fiPhrMwYn4mlOvaxPpkCKg-7ttfWZAg-bU5rKatWwowbQfUT0DXCc2ZEVNegLAa1DQGou6xAJsKAPG=w640-h396 Challenge #2
Same as Challenge #1 but requires login so that PHPSESSID and appropriate cookies are set https://blogger.googleusercontent.com/img/a/AVvXsEgdPMLdHRwnWwaWmaj2VMFqlPGsUW2H98NnjlOv1_loxelQOTW2QQLRVJlvPvTPr3vVV3dXCHQOG49IpxrIjo1KSgOPltHnK_MFy0QZ3WPxElOcSStMytKB702qrGPjOWjzk4vwO-CNQHJaqegWbISdv24w2_1q7p6-XfBDeSadSvnbx2cdeZKKIrWb=w640-h214 Download WannaRace
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
WannaRace - WebApp Intentionally Made Vulnerable To Race Condition For Practicing Race Condition
hacking: security in practice
How do I decrypt my own Adobe password?
My password was in the Adobe breach of 2013. I have the leaked Adobe data, and I have located my own user data within it. But the password is in its encrypted form and it consisting of random characters and looks something like this:
What kind of string is this? Does it have a name? What encryption was used to produce it?
Now, I know what my password was. Would that be enough for me to decrypt this random nonsense into something slightly more useful like a hash? Or do I need to know the master password that Adobe used or something like that?
I don't think I need a reason for asking such questions, but I am doing this to educate myself by practicing on real world examples (and on my own data).
submitted by /u/Ken852
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do I decrypt my own Adobe password?
My password was in the Adobe breach of 2013. I have the leaked Adobe data, and I have located my own user data within it. But the password is in its encrypted form and it consisting of random characters and looks something like this:
3p1i4vlbinfre42=What kind of string is this? Does it have a name? What encryption was used to produce it?
Now, I know what my password was. Would that be enough for me to decrypt this random nonsense into something slightly more useful like a hash? Or do I need to know the master password that Adobe used or something like that?
I don't think I need a reason for asking such questions, but I am doing this to educate myself by practicing on real world examples (and on my own data).
submitted by /u/Ken852
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
What's Your Daily Source of Cybersecurity News?
What's your go-to source for all things malware, APT, and cyber related?
submitted by /u/Rebel_Ye11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What's Your Daily Source of Cybersecurity News?
What's your go-to source for all things malware, APT, and cyber related?
submitted by /u/Rebel_Ye11
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What's Your Daily Source of Cybersecurity News?
What's your go-to source for all things malware, APT, and cyber related?