Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Biden Broadens NSA Oversight of National Security Systems
New Cybersecurity National Security Memorandum will let the spy agency "identify vulnerabilities, detect malicious threat activity and drive mitigations," agency cybersecurity director says.
___________________________
@hacking_Attack
@Hacking_Video
Biden Broadens NSA Oversight of National Security Systems
New Cybersecurity National Security Memorandum will let the spy agency "identify vulnerabilities, detect malicious threat activity and drive mitigations," agency cybersecurity director says.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Biden Broadens NSA Oversight of National Security Systems
New Cybersecurity National Security Memorandum will let the spy agency "identify vulnerabilities, detect malicious threat activity and drive mitigations," agency cybersecurity director says.
Log4j RCE When Remote Class File Won’t Load (Newer Java Versions)
https://n0ur5sec.medium.com/log4j-rce-when-remote-class-file-wont-load-newer-java-versions-a09e48c82b50?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://n0ur5sec.medium.com/log4j-rce-when-remote-class-file-wont-load-newer-java-versions-a09e48c82b50?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Log4j RCE When Remote Class File Won’t Load (Newer Java Versions)
So you might have heard of the log4j vulnerability (lol). If you’ve read the initial proof of concepts/general information that rushed out…
So you might have heard of the log4j vulnerability (lol). If you’ve read the initial proof of concepts/general information that rushed out…Continue reading on Medium » (https://n0ur5sec.medium.com/log4j-rce-when-remote-class-file-wont-load-newer-java-versions-a09e48c82b50?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Log4j RCE When Remote Class File Won’t Load (Newer Java Versions)
So you might have heard of the log4j vulnerability (lol). If you’ve read the initial proof of concepts/general information that rushed out…
Top 10 web hacking techniques of 2021 — PortSwigger
https://rei-hunt.medium.com/top-10-web-hacking-techniques-of-2021-portswigger-7de16999e5fa?source=rss------bug_bounty-5
OK , mình sẽ từ từ dịch hết tất cả các method , các bạn có thể có thể xem bản gốc ở đây : “‘Top 10 web hacking techniques of 2021 —…Continue reading on Medium » (https://rei-hunt.medium.com/top-10-web-hacking-techniques-of-2021-portswigger-7de16999e5fa?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://rei-hunt.medium.com/top-10-web-hacking-techniques-of-2021-portswigger-7de16999e5fa?source=rss------bug_bounty-5
OK , mình sẽ từ từ dịch hết tất cả các method , các bạn có thể có thể xem bản gốc ở đây : “‘Top 10 web hacking techniques of 2021 —…Continue reading on Medium » (https://rei-hunt.medium.com/top-10-web-hacking-techniques-of-2021-portswigger-7de16999e5fa?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 10 web hacking techniques of 2021 — PortSwigger (updating)
OK , mình sẽ từ từ dịch hết tất cả các method , các bạn có thể có thể xem bản gốc ở đây : “‘Top 10 web hacking techniques of 2021 —…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackers stole nearly $30 million from Crypto.com
https://cdn-images-1.medium.com/max/1200/1*KnSmJJCe8UAdPLEMBb3i5A.jpeg
Cryptocurrency exchange Crypto.com admitted in a statement posted early Thursday morning that it had lost well over $30 million in Bitcoin…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers stole nearly $30 million from Crypto.com
https://cdn-images-1.medium.com/max/1200/1*KnSmJJCe8UAdPLEMBb3i5A.jpeg
Cryptocurrency exchange Crypto.com admitted in a statement posted early Thursday morning that it had lost well over $30 million in Bitcoin…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers stole nearly $30 million from Crypto.com
Cryptocurrency exchange Crypto.com admitted in a statement posted early Thursday morning that it had lost well over $30 million in Bitcoin…
Is it possible to have a career in pentesting without school?
https://www.reddit.com/r/Pentesting/comments/s945bg/is_it_possible_to_have_a_career_in_pentesting/
wondering if its possible to get a job in the field only having certificates, any help is appreciated submitted by /u/Lankysteg (https://www.reddit.com/user/Lankysteg)
[link] (https://www.reddit.com/r/Pentesting/comments/s945bg/is_it_possible_to_have_a_career_in_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/s945bg/is_it_possible_to_have_a_career_in_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/s945bg/is_it_possible_to_have_a_career_in_pentesting/
wondering if its possible to get a job in the field only having certificates, any help is appreciated submitted by /u/Lankysteg (https://www.reddit.com/user/Lankysteg)
[link] (https://www.reddit.com/r/Pentesting/comments/s945bg/is_it_possible_to_have_a_career_in_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/s945bg/is_it_possible_to_have_a_career_in_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to have a career in pentesting without school?
wondering if its possible to get a job in the field only having certificates, any help is appreciated
hacking: security in practice
Is SSRF via javascript possible?
So I'm doing a CTF problem currently and I do know what the potential vuln is (unfiltered SSRF via puppeteer on the server), but because I'm a bit of a noob I'm unsure as to how exactly I'm able to exploit it further in order to achieve access within the localhost-eyes-only directories of the server.
I'm able to execute javascript and have tried making a fake website that would just execute javascript on the remote machine that ran a
What exactly do I do from here? I'm not exactly looking for exact answers or solutions obviously, but is there any way I could be able to perform SSRF whilst having javascript access? Or should I look for another vulnerability as this could just be a dead end I tried so desperately to view as a door?
submitted by /u/TheByteQueen
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is SSRF via javascript possible?
So I'm doing a CTF problem currently and I do know what the potential vuln is (unfiltered SSRF via puppeteer on the server), but because I'm a bit of a noob I'm unsure as to how exactly I'm able to exploit it further in order to achieve access within the localhost-eyes-only directories of the server.
I'm able to execute javascript and have tried making a fake website that would just execute javascript on the remote machine that ran a
fetchcall on "localhost", with the results being sent back via GET parameters to the attacking server. However, I eventually quickly realized it was futile as CORS was enabled, thus leaving me in a familiar yet head-scratching position.What exactly do I do from here? I'm not exactly looking for exact answers or solutions obviously, but is there any way I could be able to perform SSRF whilst having javascript access? Or should I look for another vulnerability as this could just be a dead end I tried so desperately to view as a door?
submitted by /u/TheByteQueen
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is SSRF via javascript possible?
So I'm doing a CTF problem currently and I *do* know what the potential vuln is (unfiltered SSRF via puppeteer on the server), but because I'm a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Twitter Shakes Up Security Team
https://external-preview.redd.it/kIW7QOFO83kScDXnSfsMV5XLyqwh8pputr6E_qlH99Y.jpg?width=640&crop=smart&auto=webp&s=58d89c41aa54b212e196f059b119d413d8cf4451 submitted by /u/thegreatblazed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Twitter Shakes Up Security Team
https://external-preview.redd.it/kIW7QOFO83kScDXnSfsMV5XLyqwh8pputr6E_qlH99Y.jpg?width=640&crop=smart&auto=webp&s=58d89c41aa54b212e196f059b119d413d8cf4451 submitted by /u/thegreatblazed
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Twitter Shakes Up Security Team
Posted in r/hacking by u/thegreatblazed • 1 point and 0 comments
Top 10 web hacking techniques of 2021 — PortSwigger
OK , mình sẽ từ từ dịch hết tất cả các method , các bạn có thể có thể xem bản gốc ở đây : “‘Top 10 web hacking techniques of 2021 —…Continue reading on Medium »
Read more...
OK , mình sẽ từ từ dịch hết tất cả các method , các bạn có thể có thể xem bản gốc ở đây : “‘Top 10 web hacking techniques of 2021 —…Continue reading on Medium »
Read more...
Web App Penetration Testing: Best Methods & Tools Used 2022
https://www.reddit.com/r/Pentesting/comments/s96z5q/web_app_penetration_testing_best_methods_tools/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/s96z5q/web_app_penetration_testing_best_methods_tools/
___________________________
@hacking_Attack
@Hacking_Video
reddit
Web App Penetration Testing: Best Methods & Tools Used 2022
Posted in r/Pentesting by u/noahthearc333 • 1 point and 0 comments
submitted by /u/noahthearc333 (https://www.reddit.com/user/noahthearc333)
[link] (https://www.impactqa.com/blog/web-app-penetration-testing-best-methods-tools-used-2022/) [comments] (https://www.reddit.com/r/Pentesting/comments/s96z5q/web_app_penetration_testing_best_methods_tools/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://www.impactqa.com/blog/web-app-penetration-testing-best-methods-tools-used-2022/) [comments] (https://www.reddit.com/r/Pentesting/comments/s96z5q/web_app_penetration_testing_best_methods_tools/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
overview for noahthearc333
Tech Geek/Testing Enthusiast/Software Junkie. Ardent reader for sci-fi with an aim to discover galaxies straight through my window.
Nakji Network launches a 200K USD Bug Bounty Program
Singapore, 21st January 2022 — The Nakji Foundation (‘Nakji’) is launching a 200K USD Bug Bounty program for developers and security…Continue reading on Sentinel Protocol »
Read more...
Singapore, 21st January 2022 — The Nakji Foundation (‘Nakji’) is launching a 200K USD Bug Bounty program for developers and security…Continue reading on Sentinel Protocol »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco bug gives remote attackers root privileges via debug mode
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Cisco bug gives remote attackers root privileges via debug modePost Views: 119 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Cisco has fixed a critical security flaw discovered in the Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software during internal security testing.
The vulnerability, tracked as CVE-2022-20649, enables unauthenticated attackers to gain remote code execution (RCE) with root-level privileges on devices running the vulnerable software.
“A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container,” Cisco said.
As the company further explains, the vulnerability exists due to the debug mode being incorrectly enabled for specific services.
“An attacker could exploit this vulnerability by connecting to the device and navigating to the service with debug mode enabled. A successful exploit could allow the attacker to execute arbitrary commands as the root user,” Cisco added.
However, for unauthenticated access to devices running unpatched software, the attackers would first need to perform detailed reconnaissance to discover the vulnerable services.
See Also: Complete Offensive Security and Ethical Hacking Course No in-the-wild exploitationCisco’s Product Security Incident Response Team (PSIRT) said that the company is not aware of exploitation of this vulnerability in ongoing attacks.
Today, Cisco also fixed a medium severity information disclosure bug (CVE-2022-20648) in the Cisco RCM for Cisco StarOS caused by a debug service incorrectly listening to and accepting incoming connections.
Remote attackers could exploit this second bug by executing debug commands after connecting to the debug port. Successful exploitation could allow them to access sensitive debugging information on the vulnerable device.
See Also: Microsoft: New critical Windows HTTP vulnerability is wormable
The company has released Cisco RCM for StarOS 21.25.4, which comes with security updates to address these flaws and is available through the Software Center on Cisco.com.
Last year, Cisco patched several other vulnerabilities that allow threat actors to execute code and commands remotely with root privileges.
For instance, it addressed critical pre-authentication RCE flaw impacting SD-WAN vManage that could enable threat actors to get root privileges on the underlying OS in May. Another pre-auth bug in the same software, allowing attackers to gain RCE as root, was fixed in April.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: OSINT Tool: Commit Stream See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-11-1-90x90.jpg Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks1 day ago
* https://www.blackhatethicalhacking.com/[...]
___________________________
@hacking_Attack
@Hacking_Video
Cisco bug gives remote attackers root privileges via debug mode
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Cisco bug gives remote attackers root privileges via debug modePost Views: 119 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Cisco has fixed a critical security flaw discovered in the Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software during internal security testing.
The vulnerability, tracked as CVE-2022-20649, enables unauthenticated attackers to gain remote code execution (RCE) with root-level privileges on devices running the vulnerable software.
“A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container,” Cisco said.
As the company further explains, the vulnerability exists due to the debug mode being incorrectly enabled for specific services.
“An attacker could exploit this vulnerability by connecting to the device and navigating to the service with debug mode enabled. A successful exploit could allow the attacker to execute arbitrary commands as the root user,” Cisco added.
However, for unauthenticated access to devices running unpatched software, the attackers would first need to perform detailed reconnaissance to discover the vulnerable services.
See Also: Complete Offensive Security and Ethical Hacking Course No in-the-wild exploitationCisco’s Product Security Incident Response Team (PSIRT) said that the company is not aware of exploitation of this vulnerability in ongoing attacks.
Today, Cisco also fixed a medium severity information disclosure bug (CVE-2022-20648) in the Cisco RCM for Cisco StarOS caused by a debug service incorrectly listening to and accepting incoming connections.
Remote attackers could exploit this second bug by executing debug commands after connecting to the debug port. Successful exploitation could allow them to access sensitive debugging information on the vulnerable device.
See Also: Microsoft: New critical Windows HTTP vulnerability is wormable
The company has released Cisco RCM for StarOS 21.25.4, which comes with security updates to address these flaws and is available through the Software Center on Cisco.com.
Last year, Cisco patched several other vulnerabilities that allow threat actors to execute code and commands remotely with root privileges.
For instance, it addressed critical pre-authentication RCE flaw impacting SD-WAN vManage that could enable threat actors to get root privileges on the underlying OS in May. Another pre-auth bug in the same software, allowing attackers to gain RCE as root, was fixed in April.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: OSINT Tool: Commit Stream See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-11-1-90x90.jpg Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks1 day ago
* https://www.blackhatethicalhacking.com/[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Cisco bug gives remote attackers root privileges via debug mode | Black Hat Ethical Hacking
Cisco has fixed a critical security flaw discovered in the Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software during internal security testing.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Cisco bug gives remote attackers root privileges via debug mode https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Cisco bug gives remote attackers root privileges via debug modePost Views:…
wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/image-apple-releases-15-2-1-update-for-ios-and-ipados-to-fix-bugs-164203308032302-90x90.jpg Apple fixes doorLock bug that can disable iPhones and iPads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0_Windows-headpic-90x90.jpg Microsoft: New critical Windows HTTP vulnerability is wormable1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/powerdir-exploit-microsoft-90x90.jpg Microsoft: powerdir bug gives access to protected macOS user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover2 weeks ago
The post Cisco bug gives remote attackers root privileges via debug mode first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/image-apple-releases-15-2-1-update-for-ios-and-ipados-to-fix-bugs-164203308032302-90x90.jpg Apple fixes doorLock bug that can disable iPhones and iPads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/0_Windows-headpic-90x90.jpg Microsoft: New critical Windows HTTP vulnerability is wormable1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/powerdir-exploit-microsoft-90x90.jpg Microsoft: powerdir bug gives access to protected macOS user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/using-npm-create-javascript-icon-libraries-90x90.png Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-7-90x90.jpg Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover2 weeks ago
The post Cisco bug gives remote attackers root privileges via debug mode first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Nakji Network launches a 200K USD Bug Bounty Program
https://medium.com/sentinel-protocol/nakji-network-launches-a-200k-usd-bug-bounty-program-7aa99defbf22?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/sentinel-protocol/nakji-network-launches-a-200k-usd-bug-bounty-program-7aa99defbf22?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nakji Network launches a 200K USD Bug Bounty Program
Singapore, 21st January 2022 — The Nakji Foundation (‘Nakji’) is launching a 200K USD Bug Bounty program for developers and security…