Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accountsPost Views: 79 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Security vulnerabilities in Apple iCloud and Safari 15 could have enabled attackers to compromise macOS webcams and, thereafter, victims’ online accounts.
Ryan Pickren, an independent security researcher, netted an eye-watering $100,500 bug bounty for the universal cross-site scripting (uXSS) exploit and a total of four flaws. uXSS all areasWhile the camera hack required user interaction, the potential impact of a successful compromise was egregious.
“While this bug does require the victim to click ‘open’ on a popup from my website, it results in more than just multimedia permission hijacking,” said Pickren in a technical write-up.
The exploit, he added, gives “the attacker full access to every website ever visited by the victim. That means in addition to turning on your camera, my bug can also hack your iCloud, PayPal, Facebook, Gmail, etc. accounts too.”
The researcher demonstrated a scenario in which a victim agrees to view a folder containing PNG images and a hidden webarchive file that injects code into icloud.com that exfiltrates their iOS camera roll.
A paper (PDF) published by Google Project Zero has described uXSS bugs, which can imperil multiple online accounts because they exploit browser vulnerabilities, as “almost as valuable as a remote code execution (RCE) exploit with the sandbox escape”.
See Also: Complete Offensive Security and Ethical Hacking Course ‘Subtle, but wildly impactful’As suggested by the authors of penetration testing application Metasploit back in 2013, Pickren used webarchive files as the trojan horse for uXSS.
Safari’s alternative to HTML for saving websites locally, webarchive files specify the web origin in which the content should be rendered.
Pickren circumvented macOS Gatekeeper’s block on users opening webarchive files directly by opening the files indirectly via an approved app, Safari. The researcher discovered that the .url shortcut filetype would launch Safari and instruct the browser to open the file.
“A subtle, but wildly impactful, design flaw” in ShareBear, a backend application for sharing files via iCloud, meant an attacker could surreptitiously swap a benign file with a malicious file after it had been shared with and downloaded by a victim.
See Also: McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges
The victim would receive no notification of this file swap.
“In essence, the victim has given the attacker permission to plant a polymorphic file onto their machine and the permission to remotely launch it at any moment,” said Pickren.
The researcher fashioned the exploit after successfully performing a similar trick on Safari v14.1.1, but it soon transpired that beta Safari v15 was inadvertently impervious due to an unrelated code refactor.
He also managed to steal local files by circumventing sandbox restrictions, as well as unearthing a popup-blocker bypass and iframe sandbox escape.
See Also: Recon Tool: WitnessMe RemediationPickren reported the bugs to Apple in July 2021. They were addressed recently in macOS Monterey 12.0.1 that has resulted in ShareBear now revealing (rather than launching) files, and by preventing WebKit from opening quarantined files in [...]
___________________________
@hacking_Attack
@Hacking_Video
Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accountsPost Views: 79 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Security vulnerabilities in Apple iCloud and Safari 15 could have enabled attackers to compromise macOS webcams and, thereafter, victims’ online accounts.
Ryan Pickren, an independent security researcher, netted an eye-watering $100,500 bug bounty for the universal cross-site scripting (uXSS) exploit and a total of four flaws. uXSS all areasWhile the camera hack required user interaction, the potential impact of a successful compromise was egregious.
“While this bug does require the victim to click ‘open’ on a popup from my website, it results in more than just multimedia permission hijacking,” said Pickren in a technical write-up.
The exploit, he added, gives “the attacker full access to every website ever visited by the victim. That means in addition to turning on your camera, my bug can also hack your iCloud, PayPal, Facebook, Gmail, etc. accounts too.”
The researcher demonstrated a scenario in which a victim agrees to view a folder containing PNG images and a hidden webarchive file that injects code into icloud.com that exfiltrates their iOS camera roll.
A paper (PDF) published by Google Project Zero has described uXSS bugs, which can imperil multiple online accounts because they exploit browser vulnerabilities, as “almost as valuable as a remote code execution (RCE) exploit with the sandbox escape”.
See Also: Complete Offensive Security and Ethical Hacking Course ‘Subtle, but wildly impactful’As suggested by the authors of penetration testing application Metasploit back in 2013, Pickren used webarchive files as the trojan horse for uXSS.
Safari’s alternative to HTML for saving websites locally, webarchive files specify the web origin in which the content should be rendered.
Pickren circumvented macOS Gatekeeper’s block on users opening webarchive files directly by opening the files indirectly via an approved app, Safari. The researcher discovered that the .url shortcut filetype would launch Safari and instruct the browser to open the file.
“A subtle, but wildly impactful, design flaw” in ShareBear, a backend application for sharing files via iCloud, meant an attacker could surreptitiously swap a benign file with a malicious file after it had been shared with and downloaded by a victim.
See Also: McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges
The victim would receive no notification of this file swap.
“In essence, the victim has given the attacker permission to plant a polymorphic file onto their machine and the permission to remotely launch it at any moment,” said Pickren.
The researcher fashioned the exploit after successfully performing a similar trick on Safari v14.1.1, but it soon transpired that beta Safari v15 was inadvertently impervious due to an unrelated code refactor.
He also managed to steal local files by circumventing sandbox restrictions, as well as unearthing a popup-blocker bypass and iframe sandbox escape.
See Also: Recon Tool: WitnessMe RemediationPickren reported the bugs to Apple in July 2021. They were addressed recently in macOS Monterey 12.0.1 that has resulted in ShareBear now revealing (rather than launching) files, and by preventing WebKit from opening quarantined files in [...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts | Black Hat Ethical Hacking
Security vulnerabilities in Apple iCloud and Safari 15 could have enabled attackers to compromise macOS webcams and, thereafter, victims’ online accounts.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Apple pays out $100k bounty for Safari webcam hack…
Safari 15.
The $100,000 reward dwarfs the $75,000 payout Pickren revealed in 2020 for a one-click JavaScript-to-webcam access exploit that worked on iPhones, iPads, and macOS.
Pickren soon renewed his interest in Apple webcams and once again compromised iOS and macOS cameras last year, this time via a Safari bug chain that leveraged Skype’s camera permission.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Stuxnet – A weapon made out of code that almost started WW3 Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-glitch-90x90.jpg Apple fixes new zero-day exploited to hack macOS, iOS devices1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/new-linux-kernel-memory-corruption-bug-causes-full-system-compromise-90x90.jpg Linux system service bug gives root on all major distros, exploit released2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/centos1-90x90.png CWP bugs allow code execution as root on Linux servers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/mcafee-d2c-90x90.jpg McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-12-90x90.jpg Cisco bug gives remote attackers root privileges via debug mode1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-11-1-90x90.jpg Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data2 weeks ago
The post Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
The $100,000 reward dwarfs the $75,000 payout Pickren revealed in 2020 for a one-click JavaScript-to-webcam access exploit that worked on iPhones, iPads, and macOS.
Pickren soon renewed his interest in Apple webcams and once again compromised iOS and macOS cameras last year, this time via a Safari bug chain that leveraged Skype’s camera permission.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Stuxnet – A weapon made out of code that almost started WW3 Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-glitch-90x90.jpg Apple fixes new zero-day exploited to hack macOS, iOS devices1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/new-linux-kernel-memory-corruption-bug-causes-full-system-compromise-90x90.jpg Linux system service bug gives root on all major distros, exploit released2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/centos1-90x90.png CWP bugs allow code execution as root on Linux servers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/mcafee-d2c-90x90.jpg McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-12-90x90.jpg Cisco bug gives remote attackers root privileges via debug mode1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-11-1-90x90.jpg Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/https___specials-images.forbesimg.com_imageserve_61aff357a4c71fc225ab8ba7_0x0-90x90.jpg AWS fixes security flaws that exposed AWS customer data2 weeks ago
The post Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ethical Hacking (part 9.1/20): Timing attack against strings with Python code explained
https://cdn-images-1.medium.com/max/1920/1*Wlvz2eMHSUxfQl0G4Dt7Zw.jpeg
Note: This article is being updated regularly. The latest update: 29/01/2022
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ethical Hacking (part 9.1/20): Timing attack against strings with Python code explained
https://cdn-images-1.medium.com/max/1920/1*Wlvz2eMHSUxfQl0G4Dt7Zw.jpeg
Note: This article is being updated regularly. The latest update: 29/01/2022
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ethical Hacking (part 9.1/20): Timing attack against strings with Python code explained
Note: This article is being updated regularly. The latest update: 29/01/2022
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Hackers are Taking Advantage of COVID-19
https://cdn-images-1.medium.com/max/2600/1*fqLNZfA8vs7JQhDaFG7_4A.jpeg
The pandemic has had a radical effect on nearly every type of business around the world, but one of the biggest booms that few are talking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Hackers are Taking Advantage of COVID-19
https://cdn-images-1.medium.com/max/2600/1*fqLNZfA8vs7JQhDaFG7_4A.jpeg
The pandemic has had a radical effect on nearly every type of business around the world, but one of the biggest booms that few are talking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Hackers are Taking Advantage of COVID-19
The pandemic has had a radical effect on nearly every type of business around the world, but one of the biggest booms that few are talking…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
How to Learn Java With No Programming Experience
So you’ve decided you want to learn Java but don’t know where to start? First of all – well done! Java is an excellent choice for a first programming language. However, regardless of the language, learning programming with no previous experience can be quite intimidating. But don’t fret. We are here to help! In this article, we will help you reassure yourself that you made the right choice, teach you how to create an effective study plan, and provide a variety of resources where you can learn Java programming. Why learn JavaChoosing your first programming language can be overwhelming. There are hundreds of languages to choose from. And the continuous debate on which is the best to learn first around them. Here are the main reasons why we insist that you made the right choice with Java as your first programming language. Beginner friendly and easy to learnJava is designed to be beginner-friendly and easy to learn, read, compile, and debug. It is a high-level, class-based, object-oriented programming language. All of this means the language mimics and tries to solve real-world problems. Add to that the syntax which is similar to several other popular languages, particularly its predecessors C and C++, and you have a perfect first language. Learning Java will help you understand the main concepts of programming. So moving to other languages will be a lot easier with Java in your arsenal.
Java also handles complex tasks like memory management and pointer automatically. Which makes it easier for beginners to write and run programs. Java is a cross-platform language with few limitationsJava Virtual Machine makes Java a cross-platform language. You can write code on a Windows computer and seamlessly run it later on a Linux one. Java compiler converts your source code into byte code, which is then translated to machine code by the JVM. And JVM can execute the code on any OS.
Because of this, and the amount of available APIs and libraries, Java has very few limitations in its application. It can be used to write virtually anything. Java is applied in Big Data, the internet of things, web and mobile apps, fintech, enterprise server apps, machine learning, the sky is the limit. Vast community supportJava has been around for a while. This is one of its biggest advantages. It had time to grow a community around itself. Any professional programmer will tell you how important community is in your education and everyday work. When you are stuck, you simply go looking for answers from other programmers who have already seen and resolved the problem you are currently having.
In the recent Stack Overflow survey, 29 162 respondents named Java as their primary language. This means there are over 29000 people ready to help on Stack Overflow alone. Java has a vast and helpful community on other platforms as well. Open Source supportMost of the features Java offers are open-source, which is great for creating beginner-level projects. There’s also the open-source version of the compiler from Oracle. And a huge number of support files and libraries. High Demand on Java developersBecause of the limitless number of fields where Java can be used, it is one of the most in-demand programming languages. Another reason for the high demand for Java developers is the rise of mobile usage worldwide. Java is a native Android language, after all. This increased demand forms a rather significant advantage salary-wise. A junior Java developer makes an average of over $60 000 per year. The number rises to about $86 000 for middle-level developers. How to build an effective self-study planThe Stack Overflow research we’ve already mentioned above states that over 60% of the respondents learned to code from online resources. We wo[...]
___________________________
@hacking_Attack
@Hacking_Video
How to Learn Java With No Programming Experience
So you’ve decided you want to learn Java but don’t know where to start? First of all – well done! Java is an excellent choice for a first programming language. However, regardless of the language, learning programming with no previous experience can be quite intimidating. But don’t fret. We are here to help! In this article, we will help you reassure yourself that you made the right choice, teach you how to create an effective study plan, and provide a variety of resources where you can learn Java programming. Why learn JavaChoosing your first programming language can be overwhelming. There are hundreds of languages to choose from. And the continuous debate on which is the best to learn first around them. Here are the main reasons why we insist that you made the right choice with Java as your first programming language. Beginner friendly and easy to learnJava is designed to be beginner-friendly and easy to learn, read, compile, and debug. It is a high-level, class-based, object-oriented programming language. All of this means the language mimics and tries to solve real-world problems. Add to that the syntax which is similar to several other popular languages, particularly its predecessors C and C++, and you have a perfect first language. Learning Java will help you understand the main concepts of programming. So moving to other languages will be a lot easier with Java in your arsenal.
Java also handles complex tasks like memory management and pointer automatically. Which makes it easier for beginners to write and run programs. Java is a cross-platform language with few limitationsJava Virtual Machine makes Java a cross-platform language. You can write code on a Windows computer and seamlessly run it later on a Linux one. Java compiler converts your source code into byte code, which is then translated to machine code by the JVM. And JVM can execute the code on any OS.
Because of this, and the amount of available APIs and libraries, Java has very few limitations in its application. It can be used to write virtually anything. Java is applied in Big Data, the internet of things, web and mobile apps, fintech, enterprise server apps, machine learning, the sky is the limit. Vast community supportJava has been around for a while. This is one of its biggest advantages. It had time to grow a community around itself. Any professional programmer will tell you how important community is in your education and everyday work. When you are stuck, you simply go looking for answers from other programmers who have already seen and resolved the problem you are currently having.
In the recent Stack Overflow survey, 29 162 respondents named Java as their primary language. This means there are over 29000 people ready to help on Stack Overflow alone. Java has a vast and helpful community on other platforms as well. Open Source supportMost of the features Java offers are open-source, which is great for creating beginner-level projects. There’s also the open-source version of the compiler from Oracle. And a huge number of support files and libraries. High Demand on Java developersBecause of the limitless number of fields where Java can be used, it is one of the most in-demand programming languages. Another reason for the high demand for Java developers is the rise of mobile usage worldwide. Java is a native Android language, after all. This increased demand forms a rather significant advantage salary-wise. A junior Java developer makes an average of over $60 000 per year. The number rises to about $86 000 for middle-level developers. How to build an effective self-study planThe Stack Overflow research we’ve already mentioned above states that over 60% of the respondents learned to code from online resources. We wo[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
How to Learn Java With No Programming Experience - Kali Linux Tutorials
So you’ve decided you want to learn Java but don’t know where to start? First of all – well done! Java is an excellent choice for a first programming language. However, regardless of the language, learning programming with no previous experience can be quite…
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials How to Learn Java With No Programming Experience So you’ve decided you want to learn Java but don’t know where to start? First of all – well done! Java is an excellent choice for a first programming language. However, regardless of the…
n’t be surprised if you plan on learning online too. But learning online means self-study. And that can be hard. This is why you need a good study plan. To create an efficient one, you need to:
* Account for your learning style and study habits
* Set clear goals and plan milestones accordingly
* Set up a realistic schedule
* Make sure to plan practice as well as theoretical studies
* Remember to take breaks.
Make sure to have space in your Java self-study plan for these steps:
1. Try to write a Hello World program in Java.
2. Learn the fundamentals, apply what you learn in practice.
3. Study the OOP concepts.
4. Practice and test.
5. Experiment. The best resources to learn Java for beginnersThere are numerous online study resources you can use to learn Java. Some of them are free; others are premium. Some of them focus more on practice; others provide only theory. There are online courses, boot camps, blogs, video tutorials, and communities. Below we gathered some of the best Java learning resources. Before you add them to your study plan, remember – the best practice/theory ratio is considered to be 80 to 20. Java online courses for beginnersOnline courses provide more freedom than bootcamps. You can study whenever you want. You can choose the intensity and the material you want to learn. CodeGym This online Java course is rightfully considered one of the best for beginners. The course is well thought through and focused on practice. There are over 1200 Java exercises with instant validation, an informative blog, and a helpful community. Programming By Doing This is a collection of practical Java assignments from the author of the Learn Java the Hard Way textbook. Though its last update was in 2015, it’s still a great resource to learn the basics. Java bootcampsCoding bootcamps are a popular alternative to college courses. They offer streamlined training in intensive, hands-on formats. With the pandemic raging on more and more of the bootcamps move online. Some of the best bootcamps for Java beginners are: CodingNomadsThis online coding bootcamp has a practical, real-world curriculum built by engineers. The course comes highly recommended. TheSoftwareGuildThis resource offers a 12 week Java bootcamp that covers all the basics, including OOP concepts and database drive web apps. Java tutorials for beginnersYou can not learn to code without practicing. But theory is important too. These tutorials cover all the theory a Java newbie needs. OracleThis is the official Java documentation from Oracle. The tutorials have been written for JDK 8, but you can find the lists of later changes and new features here too. TutsPlusThis resource from Envato offers a good selection of Java tutorials for beginners. Java blogsBlogs curated by professional developers are great sources of information and industry news. Softwarehow This one is all about software tools, tips, guides, and reviews. DeveloperCom And this blog is a source of news and in-depth programming tutorials. There’s even a section dedicated to Java specifically. Java videosVideo tutorials are indispensable when it comes to practice. Derek BanasA great collection of long and in-depth videos on different languages. ProgrammingKnowledge A good selection of step-by-step tutorials for beginners. Communities to ask for helpAs we’ve already mentioned above, Java has a big and very helpful community. So if you are stuck and need help, don’t be shy to ask here:
* GitHub
* HackerNews
* StackOverflow
* Reddit Wrapping upJava is and with no doubt will continue to be a very popular programming language. Learning it now will open amazing career opportunities for you in the future.
___________________________
@hacking_Attack
@Hacking_Video
* Account for your learning style and study habits
* Set clear goals and plan milestones accordingly
* Set up a realistic schedule
* Make sure to plan practice as well as theoretical studies
* Remember to take breaks.
Make sure to have space in your Java self-study plan for these steps:
1. Try to write a Hello World program in Java.
2. Learn the fundamentals, apply what you learn in practice.
3. Study the OOP concepts.
4. Practice and test.
5. Experiment. The best resources to learn Java for beginnersThere are numerous online study resources you can use to learn Java. Some of them are free; others are premium. Some of them focus more on practice; others provide only theory. There are online courses, boot camps, blogs, video tutorials, and communities. Below we gathered some of the best Java learning resources. Before you add them to your study plan, remember – the best practice/theory ratio is considered to be 80 to 20. Java online courses for beginnersOnline courses provide more freedom than bootcamps. You can study whenever you want. You can choose the intensity and the material you want to learn. CodeGym This online Java course is rightfully considered one of the best for beginners. The course is well thought through and focused on practice. There are over 1200 Java exercises with instant validation, an informative blog, and a helpful community. Programming By Doing This is a collection of practical Java assignments from the author of the Learn Java the Hard Way textbook. Though its last update was in 2015, it’s still a great resource to learn the basics. Java bootcampsCoding bootcamps are a popular alternative to college courses. They offer streamlined training in intensive, hands-on formats. With the pandemic raging on more and more of the bootcamps move online. Some of the best bootcamps for Java beginners are: CodingNomadsThis online coding bootcamp has a practical, real-world curriculum built by engineers. The course comes highly recommended. TheSoftwareGuildThis resource offers a 12 week Java bootcamp that covers all the basics, including OOP concepts and database drive web apps. Java tutorials for beginnersYou can not learn to code without practicing. But theory is important too. These tutorials cover all the theory a Java newbie needs. OracleThis is the official Java documentation from Oracle. The tutorials have been written for JDK 8, but you can find the lists of later changes and new features here too. TutsPlusThis resource from Envato offers a good selection of Java tutorials for beginners. Java blogsBlogs curated by professional developers are great sources of information and industry news. Softwarehow This one is all about software tools, tips, guides, and reviews. DeveloperCom And this blog is a source of news and in-depth programming tutorials. There’s even a section dedicated to Java specifically. Java videosVideo tutorials are indispensable when it comes to practice. Derek BanasA great collection of long and in-depth videos on different languages. ProgrammingKnowledge A good selection of step-by-step tutorials for beginners. Communities to ask for helpAs we’ve already mentioned above, Java has a big and very helpful community. So if you are stuck and need help, don’t be shy to ask here:
* GitHub
* HackerNews
* StackOverflow
* Reddit Wrapping upJava is and with no doubt will continue to be a very popular programming language. Learning it now will open amazing career opportunities for you in the future.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
ShonyDanza : A Customizable, Easy-To-Navigate Tool For Researching, Pen Testing, And Defending With The Power Of Shodan
ShonyDanza is a customizable, easy-to-navigate tool for researching, pen testing, and defending with the power of Shodan.
With ShonyDanza, you can:
* Obtain IPs based on search criteria
* Automatically exclude honeypots from the results based on your pre-configured thresholds
* Pre-configure all IP searches to filter on your specified net range(s)
* Pre-configure search limits
* Use build-a-search to craft searches with easy building blocks
* Use stock searches and pre-configure your own stock searches
* Check if IPs are known malware C2s
* Get host and domain profiles
* Scan on-demand
* Find exploits
* Get total counts for searches and exploits
* Automatically save exploit code, IP lists, host profiles, domain profiles, and scan results to directories within ShonyDanza
Installation
git clone https://github.com/fierceoj/ShonyDanza.git
Requirements
* python3
* shodan library
cd ShonyDanza
pip3 install -r requirements.txt
Usage
Edit config.py to include your desired configurations
cd configs
sudo nano config.py
config file for shonydanza searches
REQUIRED
maximum number of results that will be returned per search
default is 100
SEARCH_LIMIT = 100
REQUIRED
IPs exceeding the honeyscore limit will not show up in IP results
scale is 0.0 to 1.0
adjust to desired probability to restrict results by threshold, or keep at 1.0 to include all results
HONEYSCORE_LIMIT = 1.0
REQUIRED – at least one key: value pair
add a shodan dork to the dictionary below to add it to your shonydanza stock searches men
see https://github.com/jakejarvis/awesome-shodan-queries for a great source of queries
check into “vuln:” filter if you have Small Business Plan or higher (e.g., vuln:cve-2019-11510)
STOCK_SEARCHES = {
‘ANONYMOUS_FTP’:’ftp anonymous ok’,
‘RDP’:’port:3389 has_screenshot:true’,
‘OPEN_TELNET’:’port:23 console gateway -password’,
‘APACHE_DIR_LIST’:’http.title:”Index of /”‘,
‘SPRING_BOOT’:’http.favicon.hash:116323821′,
‘HP_PRINTERS’:'”Serial Number:” “Built:” “Server: HP HTTP”‘,
‘DOCKER_API’:'”Docker Containers:” port:2375′,
‘ANDROID_ROOT_BRIDGE’:'”Android Debug Bridge” “Device” port:5555′,
‘MONGO_EXPRESS_GUI’:'”Set-Cookie: mongo-express=” “200 OK”‘,
‘CVE-2019-11510_PULSE_VPN’:’http.html:/dana-na/’,
‘CVE-2019-19781_CITRIX_NETSCALER’:’http.waf:”Citrix NetScaler”‘,
‘CVE-2020-5902_F5_BIGIP’:’http.favicon.hash:-335242539 “3992”‘,
‘CVE-2020-3452_CISCO_ASA_FTD’:’200 “Set-Cookie: webvpn;”‘
}
OPTIONAL
IP or cidr range constraint for searches that return list of IP addresses
use comma-separated list to designate multiple (e.g. 1.1.1.1,2.2.0.0/16,3.3.3.3,3.3.3.4)
NET_RANGE = ‘0.0.0.0/0’
Run
cd ../
python3 shonydanza.py
Download
___________________________
@hacking_Attack
@Hacking_Video
ShonyDanza : A Customizable, Easy-To-Navigate Tool For Researching, Pen Testing, And Defending With The Power Of Shodan
ShonyDanza is a customizable, easy-to-navigate tool for researching, pen testing, and defending with the power of Shodan.
With ShonyDanza, you can:
* Obtain IPs based on search criteria
* Automatically exclude honeypots from the results based on your pre-configured thresholds
* Pre-configure all IP searches to filter on your specified net range(s)
* Pre-configure search limits
* Use build-a-search to craft searches with easy building blocks
* Use stock searches and pre-configure your own stock searches
* Check if IPs are known malware C2s
* Get host and domain profiles
* Scan on-demand
* Find exploits
* Get total counts for searches and exploits
* Automatically save exploit code, IP lists, host profiles, domain profiles, and scan results to directories within ShonyDanza
Installation
git clone https://github.com/fierceoj/ShonyDanza.git
Requirements
* python3
* shodan library
cd ShonyDanza
pip3 install -r requirements.txt
Usage
Edit config.py to include your desired configurations
cd configs
sudo nano config.py
config file for shonydanza searches
REQUIRED
maximum number of results that will be returned per search
default is 100
SEARCH_LIMIT = 100
REQUIRED
IPs exceeding the honeyscore limit will not show up in IP results
scale is 0.0 to 1.0
adjust to desired probability to restrict results by threshold, or keep at 1.0 to include all results
HONEYSCORE_LIMIT = 1.0
REQUIRED – at least one key: value pair
add a shodan dork to the dictionary below to add it to your shonydanza stock searches men
see https://github.com/jakejarvis/awesome-shodan-queries for a great source of queries
check into “vuln:” filter if you have Small Business Plan or higher (e.g., vuln:cve-2019-11510)
STOCK_SEARCHES = {
‘ANONYMOUS_FTP’:’ftp anonymous ok’,
‘RDP’:’port:3389 has_screenshot:true’,
‘OPEN_TELNET’:’port:23 console gateway -password’,
‘APACHE_DIR_LIST’:’http.title:”Index of /”‘,
‘SPRING_BOOT’:’http.favicon.hash:116323821′,
‘HP_PRINTERS’:'”Serial Number:” “Built:” “Server: HP HTTP”‘,
‘DOCKER_API’:'”Docker Containers:” port:2375′,
‘ANDROID_ROOT_BRIDGE’:'”Android Debug Bridge” “Device” port:5555′,
‘MONGO_EXPRESS_GUI’:'”Set-Cookie: mongo-express=” “200 OK”‘,
‘CVE-2019-11510_PULSE_VPN’:’http.html:/dana-na/’,
‘CVE-2019-19781_CITRIX_NETSCALER’:’http.waf:”Citrix NetScaler”‘,
‘CVE-2020-5902_F5_BIGIP’:’http.favicon.hash:-335242539 “3992”‘,
‘CVE-2020-3452_CISCO_ASA_FTD’:’200 “Set-Cookie: webvpn;”‘
}
OPTIONAL
IP or cidr range constraint for searches that return list of IP addresses
use comma-separated list to designate multiple (e.g. 1.1.1.1,2.2.0.0/16,3.3.3.3,3.3.3.4)
NET_RANGE = ‘0.0.0.0/0’
Run
cd ../
python3 shonydanza.py
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
ShonyDanza : A Customizable, Easy-To-Navigate Tool For Researching
ShonyDanza is a customizable, easy-to-navigate tool for researching, pen testing, and defending with the power of Shodan.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
The Cookies Parasite - Bypassing MFA with cookie theft
https://external-preview.redd.it/O__-2MKmQSwN3UPFQGuAEqQQ5aB_CFps_pbLqKS0VyI.jpg?width=640&crop=smart&auto=webp&s=391a9295219220a4e5e93684e4c237aca0d0e449 submitted by /u/amirshk
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The Cookies Parasite - Bypassing MFA with cookie theft
https://external-preview.redd.it/O__-2MKmQSwN3UPFQGuAEqQQ5aB_CFps_pbLqKS0VyI.jpg?width=640&crop=smart&auto=webp&s=391a9295219220a4e5e93684e4c237aca0d0e449 submitted by /u/amirshk
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Cookies Parasite - Bypassing MFA with cookie theft
Posted in r/hacking by u/amirshk • 1 point and 0 comments
Combobulator - Framework To Detect And Prevent Dependency Confusion Leakage And Potential Attacks
http://www.kitploit.com/2022/01/combobulator-framework-to-detect-and.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/01/combobulator-framework-to-detect-and.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Combobulator - Framework To Detect And Prevent Dependency Confusion Leakage And Potential Attacks
Dependency Combobulator is an Open-Source, modular and extensible framework to detect and prevent dependency confusion leakage and potential attacks. This facilitates a holistic approach for ensuring secure application releases that can be evaluated against different sources (e.g., GitHub Packages, JFrog Artifactory) and many package management (https://www.kitploit.com/search/label/Management) schemes (e.g., ndm, maven).
Intended Audiences The framework can be used by security auditors, pentesters (https://www.kitploit.com/search/label/Pentesters) and even baked into an enterprise's application security program and release cycle in an automated fashion. Main features Pluggable - interject on commit level, build, release steps in SDLC. Expandable - easily add your own package management scheme or code source of choice General-purpose Heuristic-Engine - an abstract package data model provides agnostic heuristic approach Supporting wide range of technologies Flexible - decision trees can be determined upon insights or verdicts provided by the toolkit Easly exstensible The project is putting practicionar's ability to extend and fit the toolkit to her own specific needs. As such, it is designed to be able to extend it to other sources, public registries, package management schemes and extending the abstract model and accompnaied heuristics engine. Installation Dependency Combobulator is ready to work with as it is - just git clone or download the package from https://github.com/apiiro/combobulator Make sure to install required dependencies by running: pip install -r requirements.txt Arguments (--help) Access Token (Overrides .env file setting) -a {compare,comp,heuristics,heur}, --analysis {compare,comp,heuristics,heur} Required analysis level - compare (comp), heuristics (heur) (default: compare) Apiiro Community"> -h, --help show this help message and exit
-t {npm,NuGet,maven}, --type {npm,NuGet,maven}
Package Manager Type, i.e: npm, NuGet, maven
-l LIST_FROM_FILE, --load_list LIST_FROM_FILE
Load list of dependencies from a file
-d FROM_SRC, --directory FROM_SRC
Extract dependencies from local source repository
-p--package SINGLE Name a single package.
-c CSV, --csv CSV Export packages properties onto CSV file
-gh GITHUB_TOKEN, --github GITHUB_TOKEN
GitHub Access Token (Overrides .env file setting)
-a {compare,comp,heuristics,heur}, --analysis {compare,comp,heuristics,heur}
Required analysis level - compare (comp), heuristics
(heur) (default: compare)
Apiiro Community
Supported package types (-t, --t): npm, maven Supported source dependency assessment: From file containing the dependency identifiers line-by-line. (-l, --load_list) By analyzing the appropriate repo's software bill-of-materials (e.g. package.json, pom.xml) (-d, --directory) Naming a single identifier (https://www.kitploit.com/search/label/Identifier) (-p, --package) Analysis level is customizable (https://www.kitploit.com/search/label/Customizable) as you can build your own preferred analysis profile in seconds. Dependency Combobulator does come with several analysis levels out-of-the-box, selected by -a, --analysis Supported output format: Screen stdout (default) CSV export to designated file -(-CSV)
Credits The project is maintained and sponsored by Apiiro with We honor great developers & AppSec practitioners with a passion for change
Download Combobulator (https://github.com/apiiro/combobulator)
___________________________
@hacking_Attack
@Hacking_Video
Intended Audiences The framework can be used by security auditors, pentesters (https://www.kitploit.com/search/label/Pentesters) and even baked into an enterprise's application security program and release cycle in an automated fashion. Main features Pluggable - interject on commit level, build, release steps in SDLC. Expandable - easily add your own package management scheme or code source of choice General-purpose Heuristic-Engine - an abstract package data model provides agnostic heuristic approach Supporting wide range of technologies Flexible - decision trees can be determined upon insights or verdicts provided by the toolkit Easly exstensible The project is putting practicionar's ability to extend and fit the toolkit to her own specific needs. As such, it is designed to be able to extend it to other sources, public registries, package management schemes and extending the abstract model and accompnaied heuristics engine. Installation Dependency Combobulator is ready to work with as it is - just git clone or download the package from https://github.com/apiiro/combobulator Make sure to install required dependencies by running: pip install -r requirements.txt Arguments (--help) Access Token (Overrides .env file setting) -a {compare,comp,heuristics,heur}, --analysis {compare,comp,heuristics,heur} Required analysis level - compare (comp), heuristics (heur) (default: compare) Apiiro Community"> -h, --help show this help message and exit
-t {npm,NuGet,maven}, --type {npm,NuGet,maven}
Package Manager Type, i.e: npm, NuGet, maven
-l LIST_FROM_FILE, --load_list LIST_FROM_FILE
Load list of dependencies from a file
-d FROM_SRC, --directory FROM_SRC
Extract dependencies from local source repository
-p--package SINGLE Name a single package.
-c CSV, --csv CSV Export packages properties onto CSV file
-gh GITHUB_TOKEN, --github GITHUB_TOKEN
GitHub Access Token (Overrides .env file setting)
-a {compare,comp,heuristics,heur}, --analysis {compare,comp,heuristics,heur}
Required analysis level - compare (comp), heuristics
(heur) (default: compare)
Apiiro Community
Supported package types (-t, --t): npm, maven Supported source dependency assessment: From file containing the dependency identifiers line-by-line. (-l, --load_list) By analyzing the appropriate repo's software bill-of-materials (e.g. package.json, pom.xml) (-d, --directory) Naming a single identifier (https://www.kitploit.com/search/label/Identifier) (-p, --package) Analysis level is customizable (https://www.kitploit.com/search/label/Customizable) as you can build your own preferred analysis profile in seconds. Dependency Combobulator does come with several analysis levels out-of-the-box, selected by -a, --analysis Supported output format: Screen stdout (default) CSV export to designated file -(-CSV)
Credits The project is maintained and sponsored by Apiiro with We honor great developers & AppSec practitioners with a passion for change
Download Combobulator (https://github.com/apiiro/combobulator)
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Tools | Kitploit
Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
deep web video story volume 1
https://external-preview.redd.it/m0bD9eW5DYkAuRFooLFAdVYkjYL2uyf5uBrtPBMOKEE.jpg?width=320&crop=smart&auto=webp&s=9802b791b24797e8bbe99647e1ddab84fb88171d submitted by /u/Interesting_Stand877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
deep web video story volume 1
https://external-preview.redd.it/m0bD9eW5DYkAuRFooLFAdVYkjYL2uyf5uBrtPBMOKEE.jpg?width=320&crop=smart&auto=webp&s=9802b791b24797e8bbe99647e1ddab84fb88171d submitted by /u/Interesting_Stand877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/deepweb - deep web video story volume 1
0 votes and 1 comment so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Offensive Security Tool: Crypto Steganography
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Offensive Security Tool: Crypto SteganographyPost Views: 199 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 4 Minutes
Offensive Security Tool: Crypto Steganography GitHub Link CryptosteganographySteganography is the practice of concealing a message within another message or a physical object. In computing/electronic contexts, a computer file, message, image, or video is concealed within another file, message, image, or video. Can be used as part of advanced Phishing simulation techniques or concealing encrypted secret messages.
It is the art of concealing information within different types of media objects such as images or audio files, in such a way that no one, apart from the sender and intended recipient, suspects the existence of the message. By default steganography is a type of security through obscurity.
Cryptosteganography by Computationalcore is a python steganography module to store messages or files protected with AES-256 encryption inside an image.
Additionally this module also enhance the security of the steganography through data encryption. The data concealed is encrypted using AES 256 encryption, a popular algorithm used in symmetric key cryptography. PrerequisitesPython 3+ pip3
(Most Linux systems comes with python 3 installed by default).
See Also: Recon Tool: WitnessMe Dependencies Installation (Ubuntu)$ sudo apt-get install python3-pip Dependencies Installation (MacOS)To install Python3 its recommended to use Homebrew package manager
The script will explain what changes it will make and prompt you before the installation begins.
$ ruby -e “$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/master/install)”
Edit your ~/.profile to include (if it is not already there)
export PATH=/usr/local/bin:/usr/local/sbin:$PATH
To install Python 3:
$ brew install python3
See Also: Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts InstallationTo install the package just run
$ pip3 install cryptosteganography
See Also: Complete Offensive Security and Ethical Hacking Course UsageUse as a library in a python programStore a message string inside an image
from cryptosteganography import CryptoSteganography
crypto_steganography = CryptoSteganography(‘My secret password key’)
# Save the encrypted file inside the image
crypto_steganography.hide(‘input_image_name.jpg’, ‘output_image_file.png’, ‘My secret message’)
secret = crypto_steganography.retrieve(‘output_image_file.png’)
print(secret)
# My secret message
Store a binary file inside an image
Note: This only works if the concealed file size is smaller than the input image
from cryptosteganography import CryptoSteganography message = None with open('sample.mp3', "rb") as f: message = f.read() crypto_steganography = CryptoSteganography('My secret password key') # Save the encrypted file inside the image crypto_steganography.hide('input_image_name.jpg', 'output_image_file.png', message) # Retrieve the file ( the previous crypto_steganography instance could be used but I instantiate a brand new object # with the same password key just to demonstrate that can it can be used to decrypt) crypto_steganography = CryptoSteganography('My secret password key') decrypted_bin = crypto_steganography.retrieve('output_image_file.png') # Save the data to a new file with open('decrypted_sample.mp3', 'wb') as f: f.write(secret_bin) Use as a python programCheck help at command line prom[...]
___________________________
@hacking_Attack
@Hacking_Video
Offensive Security Tool: Crypto Steganography
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Offensive Security Tool: Crypto SteganographyPost Views: 199 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 4 Minutes
Offensive Security Tool: Crypto Steganography GitHub Link CryptosteganographySteganography is the practice of concealing a message within another message or a physical object. In computing/electronic contexts, a computer file, message, image, or video is concealed within another file, message, image, or video. Can be used as part of advanced Phishing simulation techniques or concealing encrypted secret messages.
It is the art of concealing information within different types of media objects such as images or audio files, in such a way that no one, apart from the sender and intended recipient, suspects the existence of the message. By default steganography is a type of security through obscurity.
Cryptosteganography by Computationalcore is a python steganography module to store messages or files protected with AES-256 encryption inside an image.
Additionally this module also enhance the security of the steganography through data encryption. The data concealed is encrypted using AES 256 encryption, a popular algorithm used in symmetric key cryptography. PrerequisitesPython 3+ pip3
(Most Linux systems comes with python 3 installed by default).
See Also: Recon Tool: WitnessMe Dependencies Installation (Ubuntu)$ sudo apt-get install python3-pip Dependencies Installation (MacOS)To install Python3 its recommended to use Homebrew package manager
The script will explain what changes it will make and prompt you before the installation begins.
$ ruby -e “$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/master/install)”
Edit your ~/.profile to include (if it is not already there)
export PATH=/usr/local/bin:/usr/local/sbin:$PATH
To install Python 3:
$ brew install python3
See Also: Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts InstallationTo install the package just run
$ pip3 install cryptosteganography
See Also: Complete Offensive Security and Ethical Hacking Course UsageUse as a library in a python programStore a message string inside an image
from cryptosteganography import CryptoSteganography
crypto_steganography = CryptoSteganography(‘My secret password key’)
# Save the encrypted file inside the image
crypto_steganography.hide(‘input_image_name.jpg’, ‘output_image_file.png’, ‘My secret message’)
secret = crypto_steganography.retrieve(‘output_image_file.png’)
print(secret)
# My secret message
Store a binary file inside an image
Note: This only works if the concealed file size is smaller than the input image
from cryptosteganography import CryptoSteganography message = None with open('sample.mp3', "rb") as f: message = f.read() crypto_steganography = CryptoSteganography('My secret password key') # Save the encrypted file inside the image crypto_steganography.hide('input_image_name.jpg', 'output_image_file.png', message) # Retrieve the file ( the previous crypto_steganography instance could be used but I instantiate a brand new object # with the same password key just to demonstrate that can it can be used to decrypt) crypto_steganography = CryptoSteganography('My secret password key') decrypted_bin = crypto_steganography.retrieve('output_image_file.png') # Save the data to a new file with open('decrypted_sample.mp3', 'wb') as f: f.write(secret_bin) Use as a python programCheck help at command line prom[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Offensive Security Tool: Crypto Steganography | Black Hat Ethical Hacking
Cryptosteganography is a python steganography module to store messages or files protected with AES-256 encryption inside an image.