hacking: security in practice
Modem IP address
What could a hacker do with the IP address of someone’s modem?
submitted by /u/LittleGoblinJunior69
[link] [comments]
Modem IP address
What could a hacker do with the IP address of someone’s modem?
submitted by /u/LittleGoblinJunior69
[link] [comments]
reddit
Modem IP address
What could a hacker do with the IP address of someone’s modem?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Cybersecurity” Science-Research, January 2022 — summary from Arxiv, DOAJ and Astrophysics Data…
https://cdn-images-1.medium.com/max/2600/1*XqSjl-6sm59szbE16KoXNg.jpeg
Arxiv — summary generated by Brevi Assistant
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
“Cybersecurity” Science-Research, January 2022 — summary from Arxiv, DOAJ and Astrophysics Data…
https://cdn-images-1.medium.com/max/2600/1*XqSjl-6sm59szbE16KoXNg.jpeg
Arxiv — summary generated by Brevi Assistant
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Cybersecurity” Science-Research, January 2022 — summary from Arxiv, DOAJ and Astrophysics Data System
Arxiv — summary generated by Brevi Assistant
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Some Assembly Required 1 [PicoCTF]
https://cdn-images-1.medium.com/max/2600/1*oCqCm2vyTY9MZzibWD32Jg.png
category: Web-Exploitation
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Some Assembly Required 1 [PicoCTF]
https://cdn-images-1.medium.com/max/2600/1*oCqCm2vyTY9MZzibWD32Jg.png
category: Web-Exploitation
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Some Assembly Required 1 [PicoCTF]
category: Web-Exploitation
OpenLeverage Partners with Code4rena for Audit Contest to Enhance Security Measures
https://openleverage.medium.com/openleverage-partners-with-code4rena-for-audit-contest-to-enhance-security-measures-fb04a5bb08f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://openleverage.medium.com/openleverage-partners-with-code4rena-for-audit-contest-to-enhance-security-measures-fb04a5bb08f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Since our inception, OpenLeverage has been committed to developing a permissionless lending and margin trading protocol with aggregated…Continue reading on Medium » (https://openleverage.medium.com/openleverage-partners-with-code4rena-for-audit-contest-to-enhance-security-measures-fb04a5bb08f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Looking for work?
Dm/Pm me
submitted by /u/OrganizationSea6549
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Looking for work?
Dm/Pm me
submitted by /u/OrganizationSea6549
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Looking for work?
Dm/Pm me
hacking: security in practice
Domain Codex - Domain Intel Search Engine
submitted by /u/cstadler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Domain Codex - Domain Intel Search Engine
submitted by /u/cstadler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Domain Codex - Domain Intel Search Engine
Posted in r/hacking by u/cstadler • 1 point and 0 comments
hacking: security in practice
Kali Linux Spec Recommendations
Hello all,
Kali Linux has always seemed like a fun distro to work in. There seem to be a bunch of cool ways to test the integrity of a network using Kali. My question is what sort of laptop would be best for a beginner who just wants to learn about the various tools that you can employ using Kali? This is purely for fun.
Thanks guys!
submitted by /u/Adept_Measurement160
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Spec Recommendations
Hello all,
Kali Linux has always seemed like a fun distro to work in. There seem to be a bunch of cool ways to test the integrity of a network using Kali. My question is what sort of laptop would be best for a beginner who just wants to learn about the various tools that you can employ using Kali? This is purely for fun.
Thanks guys!
submitted by /u/Adept_Measurement160
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Kali Linux Spec Recommendations
Hello all, Kali Linux has always seemed like a fun distro to work in. There seem to be a bunch of cool ways to test the integrity of a network...
OpenLeverage Partners with Code4rena for Audit Contest to Enhance Security Measures
Since our inception, OpenLeverage has been committed to developing a permissionless lending and margin trading protocol with aggregated…Continue reading on Medium »
Read more...
Since our inception, OpenLeverage has been committed to developing a permissionless lending and margin trading protocol with aggregated…Continue reading on Medium »
Read more...
TEJAS PANCHAL ONE OF THE YOUNGEST CYBER SECURITY EXPERT.
https://medium.com/@tejasworkspace.mp/tejas-panchal-one-of-the-youngest-cyber-security-expert-e6aaff51c34a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@tejasworkspace.mp/tejas-panchal-one-of-the-youngest-cyber-security-expert-e6aaff51c34a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
TEJAS PANCHAL ONE OF THE YOUNGEST CYBER SECURITY EXPERT.
We welcome increasingly more potent online vulnerabilities as we go into a digitized future with advanced information technology shaping…
We welcome increasingly more potent online vulnerabilities as we go into a digitized future with advanced information technology shaping…Continue reading on Medium » (https://medium.com/@tejasworkspace.mp/tejas-panchal-one-of-the-youngest-cyber-security-expert-e6aaff51c34a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
TEJAS PANCHAL ONE OF THE YOUNGEST CYBER SECURITY EXPERT.
We welcome increasingly more potent online vulnerabilities as we go into a digitized future with advanced information technology shaping…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
rare and strange Deep web mysterious video
https://external-preview.redd.it/gF0pkci37f9bGgdqEAVM01Uuq9HFqi_zzMaAVEdtdJo.jpg?width=320&crop=smart&auto=webp&s=d2660fccf02d4154c948689fc72dd6ac47524f7f submitted by /u/Interesting_Stand877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
rare and strange Deep web mysterious video
https://external-preview.redd.it/gF0pkci37f9bGgdqEAVM01Uuq9HFqi_zzMaAVEdtdJo.jpg?width=320&crop=smart&auto=webp&s=d2660fccf02d4154c948689fc72dd6ac47524f7f submitted by /u/Interesting_Stand877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
rare and strange Deep web mysterious video
Posted in r/deepweb by u/Interesting_Stand877 • 0 points and 3 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accountsPost Views: 79 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Security vulnerabilities in Apple iCloud and Safari 15 could have enabled attackers to compromise macOS webcams and, thereafter, victims’ online accounts.
Ryan Pickren, an independent security researcher, netted an eye-watering $100,500 bug bounty for the universal cross-site scripting (uXSS) exploit and a total of four flaws. uXSS all areasWhile the camera hack required user interaction, the potential impact of a successful compromise was egregious.
“While this bug does require the victim to click ‘open’ on a popup from my website, it results in more than just multimedia permission hijacking,” said Pickren in a technical write-up.
The exploit, he added, gives “the attacker full access to every website ever visited by the victim. That means in addition to turning on your camera, my bug can also hack your iCloud, PayPal, Facebook, Gmail, etc. accounts too.”
The researcher demonstrated a scenario in which a victim agrees to view a folder containing PNG images and a hidden webarchive file that injects code into icloud.com that exfiltrates their iOS camera roll.
A paper (PDF) published by Google Project Zero has described uXSS bugs, which can imperil multiple online accounts because they exploit browser vulnerabilities, as “almost as valuable as a remote code execution (RCE) exploit with the sandbox escape”.
See Also: Complete Offensive Security and Ethical Hacking Course ‘Subtle, but wildly impactful’As suggested by the authors of penetration testing application Metasploit back in 2013, Pickren used webarchive files as the trojan horse for uXSS.
Safari’s alternative to HTML for saving websites locally, webarchive files specify the web origin in which the content should be rendered.
Pickren circumvented macOS Gatekeeper’s block on users opening webarchive files directly by opening the files indirectly via an approved app, Safari. The researcher discovered that the .url shortcut filetype would launch Safari and instruct the browser to open the file.
“A subtle, but wildly impactful, design flaw” in ShareBear, a backend application for sharing files via iCloud, meant an attacker could surreptitiously swap a benign file with a malicious file after it had been shared with and downloaded by a victim.
See Also: McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges
The victim would receive no notification of this file swap.
“In essence, the victim has given the attacker permission to plant a polymorphic file onto their machine and the permission to remotely launch it at any moment,” said Pickren.
The researcher fashioned the exploit after successfully performing a similar trick on Safari v14.1.1, but it soon transpired that beta Safari v15 was inadvertently impervious due to an unrelated code refactor.
He also managed to steal local files by circumventing sandbox restrictions, as well as unearthing a popup-blocker bypass and iframe sandbox escape.
See Also: Recon Tool: WitnessMe RemediationPickren reported the bugs to Apple in July 2021. They were addressed recently in macOS Monterey 12.0.1 that has resulted in ShareBear now revealing (rather than launching) files, and by preventing WebKit from opening quarantined files in [...]
___________________________
@hacking_Attack
@Hacking_Video
Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accountsPost Views: 79 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Security vulnerabilities in Apple iCloud and Safari 15 could have enabled attackers to compromise macOS webcams and, thereafter, victims’ online accounts.
Ryan Pickren, an independent security researcher, netted an eye-watering $100,500 bug bounty for the universal cross-site scripting (uXSS) exploit and a total of four flaws. uXSS all areasWhile the camera hack required user interaction, the potential impact of a successful compromise was egregious.
“While this bug does require the victim to click ‘open’ on a popup from my website, it results in more than just multimedia permission hijacking,” said Pickren in a technical write-up.
The exploit, he added, gives “the attacker full access to every website ever visited by the victim. That means in addition to turning on your camera, my bug can also hack your iCloud, PayPal, Facebook, Gmail, etc. accounts too.”
The researcher demonstrated a scenario in which a victim agrees to view a folder containing PNG images and a hidden webarchive file that injects code into icloud.com that exfiltrates their iOS camera roll.
A paper (PDF) published by Google Project Zero has described uXSS bugs, which can imperil multiple online accounts because they exploit browser vulnerabilities, as “almost as valuable as a remote code execution (RCE) exploit with the sandbox escape”.
See Also: Complete Offensive Security and Ethical Hacking Course ‘Subtle, but wildly impactful’As suggested by the authors of penetration testing application Metasploit back in 2013, Pickren used webarchive files as the trojan horse for uXSS.
Safari’s alternative to HTML for saving websites locally, webarchive files specify the web origin in which the content should be rendered.
Pickren circumvented macOS Gatekeeper’s block on users opening webarchive files directly by opening the files indirectly via an approved app, Safari. The researcher discovered that the .url shortcut filetype would launch Safari and instruct the browser to open the file.
“A subtle, but wildly impactful, design flaw” in ShareBear, a backend application for sharing files via iCloud, meant an attacker could surreptitiously swap a benign file with a malicious file after it had been shared with and downloaded by a victim.
See Also: McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges
The victim would receive no notification of this file swap.
“In essence, the victim has given the attacker permission to plant a polymorphic file onto their machine and the permission to remotely launch it at any moment,” said Pickren.
The researcher fashioned the exploit after successfully performing a similar trick on Safari v14.1.1, but it soon transpired that beta Safari v15 was inadvertently impervious due to an unrelated code refactor.
He also managed to steal local files by circumventing sandbox restrictions, as well as unearthing a popup-blocker bypass and iframe sandbox escape.
See Also: Recon Tool: WitnessMe RemediationPickren reported the bugs to Apple in July 2021. They were addressed recently in macOS Monterey 12.0.1 that has resulted in ShareBear now revealing (rather than launching) files, and by preventing WebKit from opening quarantined files in [...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts | Black Hat Ethical Hacking
Security vulnerabilities in Apple iCloud and Safari 15 could have enabled attackers to compromise macOS webcams and, thereafter, victims’ online accounts.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple pays out $100k bounty for Safari webcam hack…
Safari 15.
The $100,000 reward dwarfs the $75,000 payout Pickren revealed in 2020 for a one-click JavaScript-to-webcam access exploit that worked on iPhones, iPads, and macOS.
Pickren soon renewed his interest in Apple webcams and once again compromised iOS and macOS cameras last year, this time via a Safari bug chain that leveraged Skype’s camera permission.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Stuxnet – A weapon made out of code that almost started WW3 Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-glitch-90x90.jpg Apple fixes new zero-day exploited to hack macOS, iOS devices1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/new-linux-kernel-memory-corruption-bug-causes-full-system-compromise-90x90.jpg Linux system service bug gives root on all major distros, exploit released2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/centos1-90x90.png CWP bugs allow code execution as root on Linux servers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/mcafee-d2c-90x90.jpg McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-12-90x90.jpg Cisco bug gives remote attackers root privileges via debug mode1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-11-1-90x90.jpg Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data2 weeks ago
The post Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
The $100,000 reward dwarfs the $75,000 payout Pickren revealed in 2020 for a one-click JavaScript-to-webcam access exploit that worked on iPhones, iPads, and macOS.
Pickren soon renewed his interest in Apple webcams and once again compromised iOS and macOS cameras last year, this time via a Safari bug chain that leveraged Skype’s camera permission.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Stuxnet – A weapon made out of code that almost started WW3 Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-glitch-90x90.jpg Apple fixes new zero-day exploited to hack macOS, iOS devices1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/new-linux-kernel-memory-corruption-bug-causes-full-system-compromise-90x90.jpg Linux system service bug gives root on all major distros, exploit released2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/centos1-90x90.png CWP bugs allow code execution as root on Linux servers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/mcafee-d2c-90x90.jpg McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-12-90x90.jpg Cisco bug gives remote attackers root privileges via debug mode1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-11-1-90x90.jpg Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data2 weeks ago
The post Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video