Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Good scanners recommendations for learning?
https://www.reddit.com/r/Pentesting/comments/sgo3al/good_scanners_recommendations_for_learning/

<!-- SC_OFF -->I'm interested in learning more about network and web application scanning. I started off with nmap, and found some of the NSE scripts very helpful. I then went to nikto but it's seems very basic, and I haven't been able to find much documentation. Do you all have some recommendations on scanning tools to learn for network, vulnerability, and web app scanning? ​ Kind regards <!-- SC_ON --> submitted by /u/sma92878 (https://www.reddit.com/user/sma92878)
[link] (https://www.reddit.com/r/Pentesting/comments/sgo3al/good_scanners_recommendations_for_learning/) [comments] (https://www.reddit.com/r/Pentesting/comments/sgo3al/good_scanners_recommendations_for_learning/)
This is the story of how I found my first Stored XSS (“Cross Site Scripting”) vulnerability in a bug bounty program and a walk through on…Continue reading on Medium » (https://medium.com/@raymond-lind/how-i-found-a-simple-stored-xss-a2976c5251b?source=rss------bug_bounty-5)
hacking: security in practice
So idk if this is the right place but, how could I bypass securely for chromebooks?

Hello, so I’m wanting to bypass securely for chromebooks. (I am using my own chromebook to test on) the only thing I’ve found that works is ctrl+shift+T I can’t enable Developer mode either. Any ideas anyone?

submitted by /u/Cg6554
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
SOCIAL BOT: My decision

Good night for you Guys and girls.

To day I made this Poll here asking about what to do with my Bot.

SO Here is my final choice I gonna make it reposoty public and acesseble for you guys.

I gonna make it public for 2 main reasons... SO you guys can download and test my project and may in the future give me a feedback and Becouse I want you guys... True Hackers, to help me TO apriomorate my Instagram algorithin Bypass

Social Bot Github page link: https://github.com/G4lile00/Social-Bot

On my Github You can find everything about the project... the documentation the download links and the explication to use the software... Now i count you guys to help me and maybe make this project a big thing.

submitted by /u/G4lile00
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is Yik Yak more secure in 2022?

I know there used to be a man in the middle vulnerability back in the day using the third party "Flurry". As far as I have researched Flurry is still around but does anyone know is they have stopped using plaintext HTTP? Genuinely curious about how secure the "anonymous" app is and if anyone has found any similar exploits.

submitted by /u/Seek7201
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Windows vulnerability with new public exploits lets you become admin

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Windows vulnerability with new public exploits lets you become adminPost Views: 206 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
A security researcher has publicly disclosed an exploit for a Windows local privilege elevation vulnerability that allows anyone to gain admin privileges in Windows 10.
Using this vulnerability, threat actors with limited access to a compromised device can easily elevate their privileges to help spread laterally within the network, create new administrative users, or perform privileged commands.

The vulnerability affects all supported support versions of Windows 10 before the January 2022 Patch Tuesday updates. Researcher releases bypass to patched vulnerabilityAs part of the January 2022 Patch Tuesday, Microsoft fixed a ‘Win32k Elevation of Privilege Vulnerability’ vulnerability tracked as CVE-2022-21882, which is a bypass for the previously patched and actively exploited CVE-2021-1732 bug.

Microsoft attributes the discovery of this vulnerability to RyeLv, who shared a technical analysis of the vulnerability after Microsoft released the patch.
See Also: Complete Offensive Security and Ethical Hacking Course
Regarding the just-fixed CVE-2022-21882:
win32k privilege escalation vulnerability,
CVE-2021-1732 patch bypass,easy to exploit,which was used by apt attacks

— b2ahex (@b2ahex) January 12, 2022
This week, multiple exploits were publicly released for CVE-2022-21882 that allow anyone to gain SYSTEM privileges on vulnerable Windows 10 devices.

After the exploit’s release, Will Dormann, a vulnerability analyst for CERT/CC and Twitter’s resident exploit tester, confirmed that the exploits works and provides elevated privileges.

BleepingComputer also tested the vulnerability and had no problem compiling the exploit and using it to open Notepad with SYSTEM privileges on Windows 10, as shown below. BleepingComputer could not get the exploit to work on Windows 11.
https://www.bleepstatic.com/images/news/Microsoft/vulnerabilities/CVE-2022-21882/CVE-2022-21882-test.jpg
Bug found two years earlierThis same vulnerability was discovered two years ago by Israeli security researcher and Piiano CEO Gil Dabah, who decided not to disclose the bug due to the reduced bug bounty rewards by Microsoft.

Dabah is not alone in his frustrations over Microsoft’s diminishing bug bounty rewards.

In[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Windows vulnerability with new public exploits lets you become admin https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Windows vulnerability with new public exploits lets you become adminPost…
November, security researcher Abdelhamid Nacer released a zero-day privilege elevation exploit due to Microsoft’s decreasing payouts in their bug bounty program.
See Also: Recon Tool: WitnessMe “Microsoft bounties has been trashed since April 2020, I really wouldn’t do that if MSFT didn’t take the decision to downgrade those bounties,” Naceri told BleepingComputer at the time.

RyeLv noted in his technical writeup for the CVE-2022-21882 vulnerability that the best way to eliminate this bug class is to improve Microsoft’s Windows kernel bug bounties.

“Improve the kernel 0day bounty, let more security researchers participate in the bounty program, and help the system to be more perfect,” advised RyeLv.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Stuxnet – A weapon made out of code that almost started WW3 Source: bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ryanpickrenapplehack-768x768-1-90x90.jpg Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-glitch-90x90.jpg Apple fixes new zero-day exploited to hack macOS, iOS devices4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/new-linux-kernel-memory-corruption-bug-causes-full-system-compromise-90x90.jpg Linux system service bug gives root on all major distros, exploit released5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/centos1-90x90.png CWP bugs allow code execution as root on Linux servers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/mcafee-d2c-90x90.jpg McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-12-90x90.jpg Cisco bug gives remote attackers root privileges via debug mode1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-11-1-90x90.jpg Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-10-90x90.jpg SSRF vulnerability in VMWare authentication software could allow access to user data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Safari-Apple-navigateur-90x90.jpg Same-origin violation vulnerability in Safari 15 could leak a user’s website history and identity2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Qlocker-Ransomware-1-90x90.png Qlocker ransomware returns – targets QNAP NAS devices worldwide2 weeks ago
The post Windows vulnerability with new public exploits lets you become admin first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
DLLHijackingScanner : This Is A PoC For Bypassing UAC Using DLL Hijacking And Abusing The “Trusted Directories” Verification

DLLHijackingScanner is a PoC for bypassing UAC using DLL hijacking and abusing the “Trusted Directories” verification.

Generate Header from CSV

The python script CsvToHeader.pycan be used to generate a header file. By default it will use the CSV file dll_hijacking_candidates.csvthat can be found here: dll_hijacking_candidates.csv.

The script will check for each portable executable(PE) the following condition:

* If the PE exists in the file system.
* In the manifest of the PE, if the requestedExecutionLevel is set to one of the following values:
* asInvoker* highestAvailable* requireAdministrator* In the manifest if the autoElevate is set to true:-cargument, the script will check if the DLL to hijack is in the list of DLLs imported form PE table. Arguments

python .\CsvToHeader.py -h
usage: CsvToHeader.py -f [DLL_PATH] -c
CsvToHeader can be used to generate a header file from a CSV.
optional arguments:
-h, –help show this help message and exit
-f [DLL_PATH] Path of the csv to convert (default=”dll_hijacking_candidates.csv”)
-c Enable import dll in PE (default=False)
-v, –version Show program’s version number and exit

To generate the header file you can use the following command:

python CsvToHeader.py > dll_hijacking_candidates.h

Generate the list of vulnerable PE and DLL

The files that will be used are DLLHijacking.exeand test.dll. DLLHijacking.exe

DLLHijacking.exe is the file that will be used to generate the list of vulnerable PE. It will perform the following steps:

1. CreateFakeDirectoryFunction that create a directory in C:\windows \system32.
2. Copy Files in the new directory
* from C:\windows\system32\[TARGET.EXE]to C:\windows \system32\[TARGET.EXE]* from [CUSTOM_DLL_PATH]to C:\windows \system32\[TARGET.DLL]3. TriggerRun the executable from C:\windows \system32\[TARGET.EXE]4. CleanUpFakeDirectoryFunction that delete the directory created in step 1 and files from step 2.
5. CheckExploitCheck the content of the file C:\ProgramData\exploit.txtto see if the exploit was successful. Log file

DLLHijacking.exe will always generate a log file exploitable.logwith the following content:

* 0 or 1 to indicates whether the exploit was able to bypass the UAC.
* The executable name
* The dll name

E.g.

1,computerdefaults.exe,PROPSYS.dll
0,computerdefaults.exe,Secur32.dll

Execution

Command to run:

DLLHijacking.exe [DLL_PATH]

if no argument is passed, the script will use the DLL test.dllwhich is stored in the resouce of DLLHijacking.exe. Result

Tested on Windows 10 Pro (10.0.19043 N/A Build 19043).
https://blogger.googleusercontent.com/img/a/AVvXsEiH4CQZD8WvsyXwvSMwXQfrzu3c1scnLR2gTwjWfwdX_LJmLqZerXD4dfEslwcP-22FrSRo4eKPhHl3iBvEwbJVbRpSjPkxak5pNQN5ZLrILVl32tTutPzaL7jQj9ik9H0ADFsB669iaFXCmVf4H4a7EHgiwd5RkgIcm35m49J_ZHKpGWSShC_1L82i=s979
test.dll test.dllis a simple dynamic library that will be use to see if the exploit is successfully. The DLL will create a file C:\ProgramData\exploit.txtwith the following content:

* 0 or 1 to indicates whether the exploit was able to bypass the UAC.
* The executable name
* The DLL name

This file will be deleted once the exploit is complete. Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
IDA2Obj : Static Binary Instrumentation

IDA2Obj is a tool to implement SBI (Static Binary Instrumentation).

The working flow is simple:

* Dump object files (COFF) directly from one executable binary.
* Link the object files into a new binary, almost the same as the old one.
* During the dumping process, you can insert any data/code at any location.
* SBI is just one of the using scenarios, especially useful for black-box fuzzing.
How To Use

* Prepare the enviroment:
* Set AUTOIMPORT_COMPAT_IDA695 = YESin the idapython.cfgto support the API with old IDA 6.x style.
* Install dependency: pip install cough

* Create a folder as the workspace.
* Copy the target binary which you want to fuzz into the workspace.
* Load the binary into IDA Pro, choose Load resources and manually load to load all the segments from the binary.
* Wait for the auto-analysis done.
* Dump object files by running the script MagicIDA/main.py.
* The output object files will be inside ${workspace}/${module}/objs/afl.
* If you create an empty file named TRACE_MODEinside the workspace, then the output object files will be inside ${workspace}/${module}/objs/trace.
* By the way, it will also generate 3 files inside ${workspace}/${module}:
* exports_afl.def (used for linking)
* exports_trace.def (used for linking)
* hint.txt (used for patching)
* Generate lib files by running the script utils/LibImports.py.
* The output lib files will be inside ${workspace}/${module}/libs, used for linking later.

* Open a terminal and change the directory to the workspace.
* Link all the object files and lib files by using utils/link.bat.
* e.g. utils/link.bat GdiPlus dll afl /RELEASE
* It will generate the new binary with the pdb file inside ${workspace}/${module}.

* Patch the new built binary by using utils/PatchPEHeader.py.
* e.g. utils/PatchPEHeader.py GdiPlus/GdiPlus.afl.dll
* For the first time, you may need to run utils/register_msdia_run_as_administrator.batas administrator.

* Run & Fuzz.
Download

___________________________
@hacking_Attack
@Hacking_Video