Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Beijing Olympics App Flaws Allow Man-in-the-Middle AttacksPost Views: 120 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Attackers can access audio and files uploaded to the MY2022 mobile app required for use by all winter games attendees – including personal health details.
The mobile app that all attendees and athletes of the upcoming Beijing Winter Olympics must use to manage communications and documentation at the event has a “devastating” flaw in the way it encrypts data that can allow for man-in-the-middle attacks that access sensitive user information, researchers have found.
MY2022 is an app mandated for use by all attendees – including members of the press and athletes – of the 2022 Olympic Games in Beijing. The problem is, it poses a significant security risk because the encryption used to protect users’ voice audio and file transfers “can be trivially sidestepped” due to two vulnerabilities in how it handles data transport, according to a blog post from Citizen Lab posted online Tuesday.
Additionally, “server responses can also be spoofed, allowing an attacker to display fake instructions to users,” Citizen Lab’s Jeffrey Knockel wrote in the post.
MY2022 collects info such as health customs forms that transmit passport details, demographic information, and medical and travel history, which are vulnerable due to the flaw, he said. It’s also not clear with whom or which organizations this info is shared.
MY2022 also includes a feature that allow users to report “politically sensitive” content, as well as a censorship keyword list. While the latter is “presently inactive,” it targets a variety of political topics, including domestic issues such as Xinjiang and Tibet as well as references to Chinese government agencies, Knockel wrote.
See Also: Complete Offensive Security and Ethical Hacking Course Background and DisclosureResearchers disclosed the security issues to the Beijing Organizing Committee for the 2022 Olympic and Paralympic Winter Games on Dec. 3, 2021, giving organizers a deadline of 15 days to respond and 45 days to fix the issues. As of yesterday, Jan. 18, 2022, researchers still hadn’t received a response, according to the post.
Citizen Lab researchers also inspected a Jan. 17 release of version 2.0.5 of MY2022 for iOS to Apple’s App Store, finding that the issues reported still had not been resolved, Knockel wrote. Moreover, that version of the app introduced a new feature called “Green Health Code” that asks for travel documents and medical info from users that also is vulnerable to the flaws, he added.
MY2022 is being used as part of a closed-loop system implemented due to COVID-19 restrictions that requires all international and domestic attendees to monitor and submit their health status – e.g., a negative test for the virus – to the app on a daily basis.
For domestic users, MY2022 collects personal information including name, national identification number, phone number, email address, profile picture and employment information, and shares it with the Beijing Organizing Committee for the 2022 Olympics. For international users, the app collects users’ demographic information and passport information, as well as the organization to which they belong.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is wort[...]
___________________________
@hacking_Attack
@Hacking_Video
Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Beijing Olympics App Flaws Allow Man-in-the-Middle AttacksPost Views: 120 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Attackers can access audio and files uploaded to the MY2022 mobile app required for use by all winter games attendees – including personal health details.
The mobile app that all attendees and athletes of the upcoming Beijing Winter Olympics must use to manage communications and documentation at the event has a “devastating” flaw in the way it encrypts data that can allow for man-in-the-middle attacks that access sensitive user information, researchers have found.
MY2022 is an app mandated for use by all attendees – including members of the press and athletes – of the 2022 Olympic Games in Beijing. The problem is, it poses a significant security risk because the encryption used to protect users’ voice audio and file transfers “can be trivially sidestepped” due to two vulnerabilities in how it handles data transport, according to a blog post from Citizen Lab posted online Tuesday.
Additionally, “server responses can also be spoofed, allowing an attacker to display fake instructions to users,” Citizen Lab’s Jeffrey Knockel wrote in the post.
MY2022 collects info such as health customs forms that transmit passport details, demographic information, and medical and travel history, which are vulnerable due to the flaw, he said. It’s also not clear with whom or which organizations this info is shared.
MY2022 also includes a feature that allow users to report “politically sensitive” content, as well as a censorship keyword list. While the latter is “presently inactive,” it targets a variety of political topics, including domestic issues such as Xinjiang and Tibet as well as references to Chinese government agencies, Knockel wrote.
See Also: Complete Offensive Security and Ethical Hacking Course Background and DisclosureResearchers disclosed the security issues to the Beijing Organizing Committee for the 2022 Olympic and Paralympic Winter Games on Dec. 3, 2021, giving organizers a deadline of 15 days to respond and 45 days to fix the issues. As of yesterday, Jan. 18, 2022, researchers still hadn’t received a response, according to the post.
Citizen Lab researchers also inspected a Jan. 17 release of version 2.0.5 of MY2022 for iOS to Apple’s App Store, finding that the issues reported still had not been resolved, Knockel wrote. Moreover, that version of the app introduced a new feature called “Green Health Code” that asks for travel documents and medical info from users that also is vulnerable to the flaws, he added.
MY2022 is being used as part of a closed-loop system implemented due to COVID-19 restrictions that requires all international and domestic attendees to monitor and submit their health status – e.g., a negative test for the virus – to the app on a daily basis.
For domestic users, MY2022 collects personal information including name, national identification number, phone number, email address, profile picture and employment information, and shares it with the Beijing Organizing Committee for the 2022 Olympics. For international users, the app collects users’ demographic information and passport information, as well as the organization to which they belong.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is wort[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks | Black Hat Ethical Hacking
The mobile app that all attendees and athletes of the upcoming Beijing Winter Olympics must use to manage communications and documentation at the event has a “devastating” flaw in the way it encrypts data that can allow for man-in-the-middle attacks that…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
OSINT Tool: Commit Stream
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png OSINT Tool: Commit StreamPost Views: 57 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 4 Minutes
OSINT Tool: Commit Stream GitHub Link Commit StreamCommit-Stream by x1sec drinks commit logs from the GitHub event firehose exposing the author details (name and email address) associated with GitHub repositories in real time. This tool is an Open-source intelligence tool aimed to perform significant recon for Red Teams, Pentesters and Bug Bounty hunters.
Source code review is one of the most important aspects and often a lot of mistakes usually from developers are found, resulting in revealing secret keys hardcoded into JavaScript’s, or source codes hosted on Platform like GitHub, which hosts a lot of major code for top companies globally. Features* Uncover repositories which employees of a target company is committing code (filter by email domain)
* Identify repositories belonging to an individual (filter by author name)
* Chain with other tools such as trufflehog to extract secrets in uncovered repositories.
See Also: Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks
See Also: Complete Offensive Security and Ethical Hacking Course InstallationBinariesCompiled 64-bit executable files for Windows, Mac and Linux are available here Go getIf you would prefer to build yourself (and Go is setup correctly):
go get -u github.com/x1sec/commit-stream Building from sourcego get && go build
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell Usage
Once the token has been created, the recommended method is to set it via an environment variable CSTREAM_TOKEN:
export CSTREAM_TOKEN=xxxxxxxxxx
Alternatively, the –token switch maybe used when invoking the program, e.g:
./commit-stream –token xxxxxxxxxx
When running commit-stream with no options, it will immediately dump author details and the associated repositories in CSV format to the terminal. Filtering options are available.
To filter by email domain:
./commit-stream –email ‘@company.com’
To filter by author name:
./commit-stream –name ‘John Smith’
Multiple keywords can be specified with a , character. e.g.
./commit-stream –email ‘@telsa.com,@ford.com’
It is possible to search up to 20 previous commits for the filter keywords by specifying –all-commits. This may increase the likelihood of a positive matches.
Email addresses that have been set to private (@users.noreply.github.com) can be omitted by specifying –ignore-priv. This is useful to reduce the volume of data collected if running the tool for an extended period of time. https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent Tools* https://www.blackhatethicalhacking.com/wp-co[...]
___________________________
@hacking_Attack
@Hacking_Video
OSINT Tool: Commit Stream
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png OSINT Tool: Commit StreamPost Views: 57 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 4 Minutes
OSINT Tool: Commit Stream GitHub Link Commit StreamCommit-Stream by x1sec drinks commit logs from the GitHub event firehose exposing the author details (name and email address) associated with GitHub repositories in real time. This tool is an Open-source intelligence tool aimed to perform significant recon for Red Teams, Pentesters and Bug Bounty hunters.
Source code review is one of the most important aspects and often a lot of mistakes usually from developers are found, resulting in revealing secret keys hardcoded into JavaScript’s, or source codes hosted on Platform like GitHub, which hosts a lot of major code for top companies globally. Features* Uncover repositories which employees of a target company is committing code (filter by email domain)
* Identify repositories belonging to an individual (filter by author name)
* Chain with other tools such as trufflehog to extract secrets in uncovered repositories.
See Also: Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks
See Also: Complete Offensive Security and Ethical Hacking Course InstallationBinariesCompiled 64-bit executable files for Windows, Mac and Linux are available here Go getIf you would prefer to build yourself (and Go is setup correctly):
go get -u github.com/x1sec/commit-stream Building from sourcego get && go build
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell Usage
Usage:
commit-stream [OPTIONS] Options: -e, --email Match email addresses field (specify multiple with comma). Omit to match all.
-n, --name Match author name field (specify multiple with comma). Omit to match all.
-t, --token Github token (if not specified, will use environment variable 'CSTREAM_TOKEN')
-a --all-commits Search through previous commit history (default: false)
-i --ignore-priv Ignore noreply.github.com private email addresses (default: false) commit-stream requires a Github personal access token to be used. You can generate a token navigating in Github [Settings / Developer Settings / Personal Access Tokens] then selecting ‘Generate new token’. Nothing here needs to be selected, just enter the name of the token and click generate.Once the token has been created, the recommended method is to set it via an environment variable CSTREAM_TOKEN:
export CSTREAM_TOKEN=xxxxxxxxxx
Alternatively, the –token switch maybe used when invoking the program, e.g:
./commit-stream –token xxxxxxxxxx
When running commit-stream with no options, it will immediately dump author details and the associated repositories in CSV format to the terminal. Filtering options are available.
To filter by email domain:
./commit-stream –email ‘@company.com’
To filter by author name:
./commit-stream –name ‘John Smith’
Multiple keywords can be specified with a , character. e.g.
./commit-stream –email ‘@telsa.com,@ford.com’
It is possible to search up to 20 previous commits for the filter keywords by specifying –all-commits. This may increase the likelihood of a positive matches.
Email addresses that have been set to private (@users.noreply.github.com) can be omitted by specifying –ignore-priv. This is useful to reduce the volume of data collected if running the tool for an extended period of time. https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent Tools* https://www.blackhatethicalhacking.com/wp-co[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
OSINT Tool: Commit Stream | Black Hat Ethical Hacking
Commit Stream drinks commit logs from the GitHub event firehose exposing the author details (name and email address) associated with GitHub repositories in real time.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Beijing Olympics App Flaws Allow Man-in-the-Middle AttacksPost Views: 120 https…
h sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com What’s Not WorkingCitizen Lab discovered two security vulnerabilities in the app related to the security of how it transmits user data. Researchers examined version 2.0.0 of the iOS version of MY2022 and version 2.0.1 of the Android version in their analysis.
“Although we were only able to create an account on and thus fully examine the iOS version of MY2022, from our best understanding, the vulnerabilities described below appear to exist in both the iOS and Android versions of MY2022,” Knockel wrote.
The first vulnerability discovered in MY2022 is that it fails to validate SSL certificates, thus failing to validate the party to whom it is sending sensitive, encrypted data, according to the report. This allows an attacker to spoof trusted servers by interfering with the communication between the app and these servers.
“This failure to validate means the app can be deceived into connecting to a malicious host while believing it is a trusted host, allowing information that the app transmits to servers to be intercepted and allowing the app to display spoofed content that appears to originate from trusted servers,” Knockel wrote.
Though some connections the app created weren’t vulnerable, the SSL connections to at least the following servers are: my2022.beijing2022.cn, tmail.beijing2022.cn, dongaoserver.beijing2022.cn, app.bcia.com.cn and health.customsapp.com.
The other vulnerability researchers found in MY2022 is that some sensitive data is being transmitted without SSL encryption or any security at all, according to the report. The app transmits non-encrypted data – including sensitive metadata relating to messages, such as the names of message senders and receivers and their user account identifiers – to “tmail.beijing2022.cn” on port 8099, researchers found.
“Such data can be read by any passive eavesdropper, such as someone in range of an unsecured Wi-Fi access point, someone operating a Wi-Fi hotspot, or an Internet Service Provider or other telecommunications company,” Knockel wrote.
See Also: Microsoft: New critical Windows HTTP vulnerability is wormable Fueling the FireResearchers believe the app’s flaws may not only violate Google’s Unwanted Software Policy and Apple’s App Store guidelines but also China’s own laws and national standards pertaining to privacy protection, they said.
Indeed, the insecurity of the app is concerning on the eve of the Olympic Games, set to begin on Feb. 4, which have already sparked controversy. As early as February 2021, more than 180 human rights groups had called for governments to boycott the games due to worry that they will legitimize a Chinese regime currently engaging in significant human-rights violations, particularly against Uyghur people in China.
Governments including Canada, the United Kingdom and the United States are diplomatically boycotting the games, which means athletes from these countries can compete but government delegates will not attend the event.
The flaw in MY2022 also is worrying because the Olympics are known to be a major target for cybercriminals. Last year’s Summer Olympics in Japan saw more than 450 million attempted cyberattacks, a significant increase from the 180 million attacks that occurred during the 2012 London Summer Olympics.
Unfortunately, the security issues found in MY2022, while concerning, are not unique and are likely found in many mobile apps. Such issues have spurred an epidemic of cyberattacks against devices with poor app security, noted one security professional.
See Also: Offensive Security Tool: Ivy “Not all mobile apps are susceptible to man-in-the-middle attacks, but most of them do contain undisclosed third parties who can access the same user data as the developer,” Chris Olson, CEO at enterprise digital security platform The Media Trust, wrot[...]
___________________________
@hacking_Attack
@Hacking_Video
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com What’s Not WorkingCitizen Lab discovered two security vulnerabilities in the app related to the security of how it transmits user data. Researchers examined version 2.0.0 of the iOS version of MY2022 and version 2.0.1 of the Android version in their analysis.
“Although we were only able to create an account on and thus fully examine the iOS version of MY2022, from our best understanding, the vulnerabilities described below appear to exist in both the iOS and Android versions of MY2022,” Knockel wrote.
The first vulnerability discovered in MY2022 is that it fails to validate SSL certificates, thus failing to validate the party to whom it is sending sensitive, encrypted data, according to the report. This allows an attacker to spoof trusted servers by interfering with the communication between the app and these servers.
“This failure to validate means the app can be deceived into connecting to a malicious host while believing it is a trusted host, allowing information that the app transmits to servers to be intercepted and allowing the app to display spoofed content that appears to originate from trusted servers,” Knockel wrote.
Though some connections the app created weren’t vulnerable, the SSL connections to at least the following servers are: my2022.beijing2022.cn, tmail.beijing2022.cn, dongaoserver.beijing2022.cn, app.bcia.com.cn and health.customsapp.com.
The other vulnerability researchers found in MY2022 is that some sensitive data is being transmitted without SSL encryption or any security at all, according to the report. The app transmits non-encrypted data – including sensitive metadata relating to messages, such as the names of message senders and receivers and their user account identifiers – to “tmail.beijing2022.cn” on port 8099, researchers found.
“Such data can be read by any passive eavesdropper, such as someone in range of an unsecured Wi-Fi access point, someone operating a Wi-Fi hotspot, or an Internet Service Provider or other telecommunications company,” Knockel wrote.
See Also: Microsoft: New critical Windows HTTP vulnerability is wormable Fueling the FireResearchers believe the app’s flaws may not only violate Google’s Unwanted Software Policy and Apple’s App Store guidelines but also China’s own laws and national standards pertaining to privacy protection, they said.
Indeed, the insecurity of the app is concerning on the eve of the Olympic Games, set to begin on Feb. 4, which have already sparked controversy. As early as February 2021, more than 180 human rights groups had called for governments to boycott the games due to worry that they will legitimize a Chinese regime currently engaging in significant human-rights violations, particularly against Uyghur people in China.
Governments including Canada, the United Kingdom and the United States are diplomatically boycotting the games, which means athletes from these countries can compete but government delegates will not attend the event.
The flaw in MY2022 also is worrying because the Olympics are known to be a major target for cybercriminals. Last year’s Summer Olympics in Japan saw more than 450 million attempted cyberattacks, a significant increase from the 180 million attacks that occurred during the 2012 London Summer Olympics.
Unfortunately, the security issues found in MY2022, while concerning, are not unique and are likely found in many mobile apps. Such issues have spurred an epidemic of cyberattacks against devices with poor app security, noted one security professional.
See Also: Offensive Security Tool: Ivy “Not all mobile apps are susceptible to man-in-the-middle attacks, but most of them do contain undisclosed third parties who can access the same user data as the developer,” Chris Olson, CEO at enterprise digital security platform The Media Trust, wrot[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking OSINT Tool: Commit Stream https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png OSINT Tool: Commit StreamPost Views: 57 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME…
ntent/uploads/2022/01/EDR-Hooked-90x90.png Offensive Security Tool: Ivy6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/osmedeus-details-folder-90x90.png Offensive Security Tool: Osmedeus2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/basic_spraying-90x90.png Offensive Security Tool: Spray3653 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/log4j-attack-diagram-r3-90x90.png Offensive Security Tool: log4j Honeypot Flask4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/log4j-scan-90x90.png Offensive Security Tool: log4j-scan1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/40pivot2-90x90.png Offensive Security Tool: Cobalt Strike1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/gomapenum-90x90.png Offensive Security Tool: GoMapEnum2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/hashcat-90x90.png Offensive Security Tool: Hashcat2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/bugbountytools-90x90.png Offensive Security Tools: Awesome Bug Bounty Tools2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/unknown-1-90x90.png Offensive Security Tool: Pentesting Tools2 months ago
The post OSINT Tool: Commit Stream first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/osmedeus-details-folder-90x90.png Offensive Security Tool: Osmedeus2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/basic_spraying-90x90.png Offensive Security Tool: Spray3653 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/log4j-attack-diagram-r3-90x90.png Offensive Security Tool: log4j Honeypot Flask4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/log4j-scan-90x90.png Offensive Security Tool: log4j-scan1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/40pivot2-90x90.png Offensive Security Tool: Cobalt Strike1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/gomapenum-90x90.png Offensive Security Tool: GoMapEnum2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/hashcat-90x90.png Offensive Security Tool: Hashcat2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/bugbountytools-90x90.png Offensive Security Tools: Awesome Bug Bounty Tools2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/unknown-1-90x90.png Offensive Security Tool: Pentesting Tools2 months ago
The post OSINT Tool: Commit Stream first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
h sharing? If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com What’s Not WorkingCitizen Lab discovered two security vulnerabilities in the app related to the security of how it transmits user data.…
e in an email to Threatpost. “Mobile users frequently assume that they are safe either because of app store policies, or because they have consented to terms of service – but third parties are not carefully checked by app reviewers, and they are rarely monitored for safety.”
Because of this, these apps “can be hijacked to execute phishing attacks, share sensitive data with fourth or fifth parties, suffer a data breach caused by lax security practices, or worse,” he noted.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: threatpost.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/image-apple-releases-15-2-1-update-for-ios-and-ipados-to-fix-bugs-164203308032302-90x90.jpg Apple fixes doorLock bug that can disable iPhones and iPads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0_Windows-headpic-90x90.jpg Microsoft: New critical Windows HTTP vulnerability is wormable1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/powerdir-exploit-microsoft-90x90.jpg Microsoft: powerdir bug gives access to protected macOS user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-iPhone-13-Pro-90x90.png iOS malware can fake iPhone shut downs to snoop on camera, microphone2 weeks ago
The post Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Because of this, these apps “can be hijacked to execute phishing attacks, share sensitive data with fourth or fifth parties, suffer a data breach caused by lax security practices, or worse,” he noted.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: threatpost.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/image-apple-releases-15-2-1-update-for-ios-and-ipados-to-fix-bugs-164203308032302-90x90.jpg Apple fixes doorLock bug that can disable iPhones and iPads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0_Windows-headpic-90x90.jpg Microsoft: New critical Windows HTTP vulnerability is wormable1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/powerdir-exploit-microsoft-90x90.jpg Microsoft: powerdir bug gives access to protected macOS user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-iPhone-13-Pro-90x90.png iOS malware can fake iPhone shut downs to snoop on camera, microphone2 weeks ago
The post Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DarkNet Interviews: Part 1
https://cdn-images-1.medium.com/max/1920/1*hT0JajpmO3DCV99Fl2gZhw.jpeg
I’ve been taking some time to meet with security professionals from all over the world. I have set up a series of interviews which will be…
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
DarkNet Interviews: Part 1
https://cdn-images-1.medium.com/max/1920/1*hT0JajpmO3DCV99Fl2gZhw.jpeg
I’ve been taking some time to meet with security professionals from all over the world. I have set up a series of interviews which will be…
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DarkNet Interviews: Part 1
I’ve been taking some time to meet with security professionals from all over the world. I have set up a series of interviews which will be…
hacking: security in practice
What's more lucrative? White hat or black hat hacking?
This question is academic, not a request for career advice.
I also understand that black hat hacking can come with room and board included if you get caught.
submitted by /u/anon314159265358p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What's more lucrative? White hat or black hat hacking?
This question is academic, not a request for career advice.
I also understand that black hat hacking can come with room and board included if you get caught.
submitted by /u/anon314159265358p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What's more lucrative? White hat or black hat hacking?
This question is academic, not a request for career advice. I also understand that black hat hacking can come with room and board included if you...
hacking: security in practice
Strange message from one of my contacts
Hey guys today one of my contacts ( someone from high school that I didnt speak with for more then 2 years ) sent me a message on Facebook
The message was written in our native language and it translates as : Are you the one in this video ? + LINK
I was kind of freaking out and I was just looking at the message ( I did not click the link ) and while I was thinking what to do he UNSENT the message then I asked this person what is going on and he didnt reply back yet.
The thing that surprised and confused me is that the message was written correctly in our native language ( not english )
So I am asking you guys what is going on ?
submitted by /u/LEggENDE
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Strange message from one of my contacts
Hey guys today one of my contacts ( someone from high school that I didnt speak with for more then 2 years ) sent me a message on Facebook
The message was written in our native language and it translates as : Are you the one in this video ? + LINK
I was kind of freaking out and I was just looking at the message ( I did not click the link ) and while I was thinking what to do he UNSENT the message then I asked this person what is going on and he didnt reply back yet.
The thing that surprised and confused me is that the message was written correctly in our native language ( not english )
So I am asking you guys what is going on ?
submitted by /u/LEggENDE
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Strange message from one of my contacts
Hey guys today one of my contacts ( someone from high school that I didnt speak with for more then 2 years ) sent me a message on Facebook The...
Dep-Scan - Fully Open-Source Security Audit For Project Dependencies Based On Known Vulnerabilities And Advisories. Supports Both Local Repos And Container Images. Integrates With Various CI Environments Such As Azure Pipelines, CircleCI, Google CloudBuild
http://www.kitploit.com/2022/01/dep-scan-fully-open-source-security.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/01/dep-scan-fully-open-source-security.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Dep-Scan - Fully Open-Source Security Audit For Project Dependencies Based On Known Vulnerabilities And Advisories. Supports Both…
dep-scan is a fully open-source security audit tool for project dependencies based on known vulnerabilities, advisories and license limitations. Both local repositories and container images are supported as input. The tool is ideal for CI environments with built-in build breaker logic. If you have just come across this repo, probably the best place to start is to checkout the parent project slscan (https://slscan.io/) which include depscan along with a number of other tools.
Features Local repos and container image based scanning with CVE insights [1] Package vulnerability scanning (https://www.kitploit.com/search/label/Vulnerability%20Scanning) is performed locally and is quite fast. No server is used! Suggest optimal fix version by package group (See suggest mode) Perform deep packages risk audit for dependency confusion attacks and maintenance risks (See risk audit) NOTE: [1] Only application related packages in container images are included in scanning. OS packages are not included yet.
___________________________
@hacking_Attack
@Hacking_Video
Features Local repos and container image based scanning with CVE insights [1] Package vulnerability scanning (https://www.kitploit.com/search/label/Vulnerability%20Scanning) is performed locally and is quite fast. No server is used! Suggest optimal fix version by package group (See suggest mode) Perform deep packages risk audit for dependency confusion attacks and maintenance risks (See risk audit) NOTE: [1] Only application related packages in container images are included in scanning. OS packages are not included yet.
___________________________
@hacking_Attack
@Hacking_Video
Vulnerability Data sources OSV NVD GitHub NPM Usage dep-scan is ideal for use during continuous integration (https://www.kitploit.com/search/label/Continuous%20Integration) (CI) and also as a tool for local development. Use with ShiftLeft Scan dep-scan is integrated with scan (https://github.com/ShiftLeftSecurity/sast-scan), a free and open-source SAST tool. To enable this feature simply pass depscan to the --type argument. Refer (https://slscan.io/) to the scan documentation for more information. ---
--type python,depscan,credscan This approach should work for all CI environments supported by scan. Scanning projects locally (Python version) sudo npm install -g @appthreat/cdxgen
pip install appthreat-depscan This would install two commands called cdxgen and scan. You can invoke the scan command directly with the various options. depscan --src $PWD --report_file $PWD/reports/depscan.json">cd
depscan --src $PWD --report_file $PWD/reports/depscan.json Full list of options are below: usage: depscan [-h] [--no-banner] [--cache] [--sync] [--suggest] [--risk-audit] [--private-ns PRIVATE_NS] [-t PROJECT_TYPE] [--bom BOM] -i SRC_DIR [-o REPORT_FILE]
[--no-error]
-h, --help show this help message and exit
--no-banner Do not display banner
--cache Cache vulnerability information in platform specific user_data_dir
--sync Sync to receive the latest vulnerability data. Should have invoked cache first.
--suggest Suggest appropriate fix version for each identified vulnerability.
--risk-audit Perform package risk audit (slow operation). Npm only.
--private-ns PRIVATE_NS
Private namespace to use while performing oss risk audit. Private packages should not be available in public registries by default. Comma
sep arated values accepted.
-t PROJECT_TYPE, --type PROJECT_TYPE
Override project type if auto-detection is incorrect
--bom BOM Examine using the given Software Bill-of-Materials (SBoM) file in CycloneDX format. Use cdxgen command to produce one.
-i SRC_DIR, --src SRC_DIR
Source directory
-o REPORT_FILE, --report_file REPORT_FILE
Report filename with directory
--no-error Continue on error to prevent build from breaking Scanning containers locally (Python version) Scan latest tag of the container shiftleft/scan-slim depscan --no-error --cache --src shiftleft/scan-slim -o containertests/depscan-scan.json -t docker Include license to the type to perform license audit. depscan --no-error --cache --src shiftleft/scan-slim -o containertests/depscan-scan.json -t docker,license You can also specify the image using the sha256 digest depscan --no-error --src redmine@sha256:a5c5f8a64a0d9a436a0a6941bc3fb156be0c89996add834fe33b66ebeed2439e -o containertests/depscan-redmine.json -t docker You can also save container images using docker or podman save command and pass the archive to depscan for scanning. docker save -o /tmp/scanslim.tar shiftleft/scan-slim:latest
# podman save --format oci-archive -o /tmp/scanslim.tar shiftleft/scan-slim:latest
depscan --no-error --src /tmp/scanslim.tar -o reports/depscan-scan.json -t docker Refer to the docker tests under GitHub action workflow for this repo for more examples. Scanning projects locally (Docker container) appthreat/dep-scan or quay.io/appthreat/dep-scan container image can be used to perform the scan. To scan with default settings docker run --rm -v $PWD:/app appthreat/dep-scan scan --src /app --report_file /app/reports/depscan.json To scan with custom environment variables based configuration \ -v /tmp:/db \ -v $PWD:/app appthreat/dep-scan scan --src /app --report_file /app/reports/depscan.json">docker run --rm \
-e VDB_HOME=/db \
-e NVD_START_YEAR=2010 \
-e GITHUB_PAGE_COUNT=5 \
___________________________
@hacking_Attack
@Hacking_Video
--type python,depscan,credscan This approach should work for all CI environments supported by scan. Scanning projects locally (Python version) sudo npm install -g @appthreat/cdxgen
pip install appthreat-depscan This would install two commands called cdxgen and scan. You can invoke the scan command directly with the various options. depscan --src $PWD --report_file $PWD/reports/depscan.json">cd
depscan --src $PWD --report_file $PWD/reports/depscan.json Full list of options are below: usage: depscan [-h] [--no-banner] [--cache] [--sync] [--suggest] [--risk-audit] [--private-ns PRIVATE_NS] [-t PROJECT_TYPE] [--bom BOM] -i SRC_DIR [-o REPORT_FILE]
[--no-error]
-h, --help show this help message and exit
--no-banner Do not display banner
--cache Cache vulnerability information in platform specific user_data_dir
--sync Sync to receive the latest vulnerability data. Should have invoked cache first.
--suggest Suggest appropriate fix version for each identified vulnerability.
--risk-audit Perform package risk audit (slow operation). Npm only.
--private-ns PRIVATE_NS
Private namespace to use while performing oss risk audit. Private packages should not be available in public registries by default. Comma
sep arated values accepted.
-t PROJECT_TYPE, --type PROJECT_TYPE
Override project type if auto-detection is incorrect
--bom BOM Examine using the given Software Bill-of-Materials (SBoM) file in CycloneDX format. Use cdxgen command to produce one.
-i SRC_DIR, --src SRC_DIR
Source directory
-o REPORT_FILE, --report_file REPORT_FILE
Report filename with directory
--no-error Continue on error to prevent build from breaking Scanning containers locally (Python version) Scan latest tag of the container shiftleft/scan-slim depscan --no-error --cache --src shiftleft/scan-slim -o containertests/depscan-scan.json -t docker Include license to the type to perform license audit. depscan --no-error --cache --src shiftleft/scan-slim -o containertests/depscan-scan.json -t docker,license You can also specify the image using the sha256 digest depscan --no-error --src redmine@sha256:a5c5f8a64a0d9a436a0a6941bc3fb156be0c89996add834fe33b66ebeed2439e -o containertests/depscan-redmine.json -t docker You can also save container images using docker or podman save command and pass the archive to depscan for scanning. docker save -o /tmp/scanslim.tar shiftleft/scan-slim:latest
# podman save --format oci-archive -o /tmp/scanslim.tar shiftleft/scan-slim:latest
depscan --no-error --src /tmp/scanslim.tar -o reports/depscan-scan.json -t docker Refer to the docker tests under GitHub action workflow for this repo for more examples. Scanning projects locally (Docker container) appthreat/dep-scan or quay.io/appthreat/dep-scan container image can be used to perform the scan. To scan with default settings docker run --rm -v $PWD:/app appthreat/dep-scan scan --src /app --report_file /app/reports/depscan.json To scan with custom environment variables based configuration \ -v /tmp:/db \ -v $PWD:/app appthreat/dep-scan scan --src /app --report_file /app/reports/depscan.json">docker run --rm \
-e VDB_HOME=/db \
-e NVD_START_YEAR=2010 \
-e GITHUB_PAGE_COUNT=5 \
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
-e GITHUB_TOKEN= \
-v /tmp:/db \
-v $PWD:/app appthreat/dep-scan scan --src /app --report_file /app/reports/depscan.json In the above example, /tmp is mounted as /db into the container. This directory is then specified as VDB_HOME for caching the vulnerability information. This way the database can be cached and reused to improve performance. Supported languages and package format dep-scan uses cdxgen (https://github.com/AppThreat/cdxgen) command internally to create Software Bill-of-Materials (SBoM) file for the project. This is then used for performing the scans. The following projects and package-dependency format is supported by cdxgen. Language Package format node.js package-lock.json, pnpm-lock.yaml, yarn.lock, rush.js java maven (pom.xml [1]), gradle (build.gradle, .kts), scala (sbt) php composer.lock python setup.py, requirements.txt [2], Pipfile.lock, poetry.lock, bdist_wheel, .whl go binary, go.mod, go.sum, Gopkg.lock ruby Gemfile.lock, gemspec rust Cargo.toml, Cargo.lock .Net .csproj, packages.config, project.assets.json, packages.lock.json docker / oci image All supported languages excluding OS packages NOTE The docker image for dep-scan currently doesn't bundle suitable java and maven commands required for bom generation. To workaround this limitation, you can - Use python-based execution from a VM containing the correct versions for java, maven and gradle. Generate the bom file by invoking cdxgen command locally and subsequently passing this to dep-scan via the --bom argument. Integration with CI environments Integration with Azure DevOps Refer to this example yaml (https://github.com/AppThreat/WebGoat/blob/develop/azure-pipelines.yml#L33) configuration for integrating dep-scan with Azure Pipelines. The build step would perform the scan and display the report inline as shown below:
___________________________
@hacking_Attack
@Hacking_Video
-v /tmp:/db \
-v $PWD:/app appthreat/dep-scan scan --src /app --report_file /app/reports/depscan.json In the above example, /tmp is mounted as /db into the container. This directory is then specified as VDB_HOME for caching the vulnerability information. This way the database can be cached and reused to improve performance. Supported languages and package format dep-scan uses cdxgen (https://github.com/AppThreat/cdxgen) command internally to create Software Bill-of-Materials (SBoM) file for the project. This is then used for performing the scans. The following projects and package-dependency format is supported by cdxgen. Language Package format node.js package-lock.json, pnpm-lock.yaml, yarn.lock, rush.js java maven (pom.xml [1]), gradle (build.gradle, .kts), scala (sbt) php composer.lock python setup.py, requirements.txt [2], Pipfile.lock, poetry.lock, bdist_wheel, .whl go binary, go.mod, go.sum, Gopkg.lock ruby Gemfile.lock, gemspec rust Cargo.toml, Cargo.lock .Net .csproj, packages.config, project.assets.json, packages.lock.json docker / oci image All supported languages excluding OS packages NOTE The docker image for dep-scan currently doesn't bundle suitable java and maven commands required for bom generation. To workaround this limitation, you can - Use python-based execution from a VM containing the correct versions for java, maven and gradle. Generate the bom file by invoking cdxgen command locally and subsequently passing this to dep-scan via the --bom argument. Integration with CI environments Integration with Azure DevOps Refer to this example yaml (https://github.com/AppThreat/WebGoat/blob/develop/azure-pipelines.yml#L33) configuration for integrating dep-scan with Azure Pipelines. The build step would perform the scan and display the report inline as shown below:
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - CycloneDX/cdxgen: Creates CycloneDX Software Bill of Materials (SBOM) for your projects from source and container images.…
Creates CycloneDX Software Bill of Materials (SBOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic...