Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
M1 and x86/64 Virtualization.

What are the Apple silicon users using to achieve this? Possible yet?

My goal is mainly to be able to use my m1 and engage in CTFs and other gamified hacking where running various binaries might be required or helpful at the least.

So far I’ve considered remoting into a x64 desktop running the VM.

TLDR; what are people using to run x64 arch OSes on an m1?

submitted by /u/p20ph37
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is this even possible? If so, would you be willing to share how and how I could protect myself from it?

So, I was reading some comments on YouTube, and one of the commentors mentioned that they knew someone who knew how to catch internet trolls using the presumed anonymous data they post on the internet, like from comments on YouTube accounts and such. This sounded really interesting. I know there are ways to circumvent cybersecurity, but I'm also fairly aware that most people don't go to those lengths and so taking precautions against it is generally unnecessary.
...
Still, though, I think that's really cool, and if it can be done with minimum hardware and software (like barely any new downloads and such) I'd like to learn how to do it (probably hacking myself from another computer as practice because I wouldn't take the chance of hacking someone else).

submitted by /u/krb501
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Got DDOS through GTA5 online

Hello I got DDos'd through GTA5 online, the hacker has been ddosing me all day and I can't do anything. Every game I play will kick me off in a few minutes not just GTA5. Did this hacker put a virus on my pc?

submitted by /u/Overwatchd
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Content Discovery TryHackme

Hi, amazing fellow hackers, I produced an interesting topic web content discovery. It is useful in bug bounty and the most important thing…
Read more...
PORTSWIGGER WEB SECURITY - BUSINESS LOGIC VULNERABILITIES LAB ÇÖZÜMLERİ

Business Logic (İş Mantığı) zafiyeti, bir web uygulamasının tasarımında ve uygulamasında, saldırganın istenmeyen davranışlar sergilemesine…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
UPDATE! on Brute force with only password field! \determined-newbie

With newfound intel from y'all's comments, I got selenium working. Wrote a script that navigates all the way to the page in question, finds the input field and tries words line by line from a .txt file. The script is running as I type this, and is reloading the page after each attempt. I am now back here with the following questions:

1. How do I get selenium to save/show me the password that went through?
2. Is there a bit I should add to my code should a password go through or will the loop break by itself when it happens?

Original Post here

Screen here

Original Script here

Peace.

submitted by /u/Puddin2yerHarley
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco patches critical vulnerabilities in SMB routers, exploitation available

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Cisco patches critical vulnerabilities in SMB routers, exploitation availablePost Views: 106 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Cisco has released patches for multiple vulnerabilities in the Small Business RV Series router platform that could allow remote attackers to gain complete control over the device, in many cases, without authentication.
In total, there are fifteen vulnerabilities fixed by these security updates, with five of them rated as Critical as threat actors can use them to gain ‘root’ privileges or remotely execute commands on the device.

According to the advisory, an attacker exploiting these flaws could execute arbitrary code, elevate privileges, run commands, bypass authentication protections, retrieve and execute unsigned software, and cause a denial of service (DoS) condition.
See Also: Complete Offensive Security and Ethical Hacking Course Numerous critical flawsCisco’s advisory notes that multiple security vulnerabilities have been classified as ‘Critical’ due to the ease of exploitation and potential for abuse.

The most significant vulnerabilities in terms of their severity are:

CVE-2022-20699: A code execution flaw in the SSL VPN module caused by an insufficient boundary check when processing specific HTTP requests. (CVSS v3 score 10.0)

CVE-2022-20700 and CVE-2022-20701: Privilege escalation (up to root) flaws in the router’s web-based management interface, which suffers from insufficient authorization enforcement mechanisms. (CVSS v3 score 10.0 and 9.0 respectively)

CVE-2022-20703: A signature verification bypass vulnerability in the software image verification feature, relying on the improper verification of software images installed on the affected device. (CVSS v3 score 9.3)

CVE-2022-20708: Command injection flaw in the web-based management interface of the routers, which suffers from insufficient user-supplied input validation. (CVSS v3 score 10.0)
See Also: Windows vulnerability with new public exploits lets you become admin Cisco warns that some of these vulnerabilities need to be chained together to exploit an RV series router.

“Some of the vulnerabilities are dependent on one another. Exploitation of one of the vulnerabilities may be required to exploit another vulnerability,” explains the Cisco advisory.

The vulnerabilities tracked CVE-2022-20700, CVE-2022-20701, CVE-2022-20702, CVE-2022-20703, CVE-2022-20704, CVE-2022-20705, CVE-2022-20706, CVE-2022-20710, and CVE-2022-20712 affect:

* RV160 VPN Routers
* RV160W Wireless-AC VPN Routers
* RV260 VPN Routers
* RV260P VPN Routers with PoE
* RV260W Wireless-AC VPN Routers
* RV340 Dual WAN Gigabit VPN Routers
* RV340W Dual WAN Gigabit Wireless-AC VPN Routers
* RV345 Dual WAN Gigabit VPN Routers
* RV345P Dual WAN Gigabit POE VPN Routers
The CVE-2022-20699, CVE-2022-20707, CVE-2022-20708, CVE-2022-20709, CVE-2022-20711, and CVE-2022-20749 vulnerabilities only affect the following Cisco products:

* RV340 Dual WAN Gigabit VPN Routers
* RV340W Dual WAN Gigabit Wireless-AC VPN Routers
* RV345 Dual WAN Gigabit VPN Routers
* RV345P Dual WAN Gigabit POE VPN Routers
See Also: Recon Tool: WitnessMe Even if your product isn’t affected by any critical vulnerabilities, there’s always a chance that threat actors will chain several less severe flaws to achieve high-impact attacks.

If you’re using any of the products listed above, i[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Cisco patches critical vulnerabilities in SMB routers, exploitation available https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Cisco patches critical vulnerabilities in SMB routers, exploitation…
t is highly recommended to apply the security updates as soon as possible. PoC exploits availableThe Cisco “Product Security Incident Response Team (PSIRT) states that they are aware of proof-of-concept exploit code available for several of the vulnerabilities fixed in these updates.

The CVE-2022-20699 vulnerability was discovered and used by the FlashBack Team during the Pwn2Own Austin 2021 hacking contest.

FlashBack’s Pedro Ribeiro says they will be demonstrating the exploit and releasing a public PoC as part of their talk at OffensiveCon 2022 titled “Pwn2Own’ing Your Router Over the Internet.

It is unknown what PoC exploits are available for the other vulnerabilities, however once security updates are released, these PoCs tend to become publicly fairly quickly.

Once they are public, threat actors will quickly utilize them in attacks, making it important to update any RV routers as soon as possible.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: How ILOVEYOU worm became the first global computer virus pandemic Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/b2b-90x90.jpg ESET antivirus bug let attackers gain Windows SYSTEM privileges1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/image6-90x90.png Cloudflare launches a paid public bug bounty program2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/do-any-web-page-convert-into-elementor-pro-template-90x90.jpg 600K WordPress sites impacted by critical plugin RCE vulnerability3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/hacking-windows-10-evade-detection-netstat-tasklist.1280x600-90x90.jpg Windows vulnerability with new public exploits lets you become admin4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ryanpickrenapplehack-768x768-1-90x90.jpg Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Apple-glitch-90x90.jpg Apple fixes new zero-day exploited to hack macOS, iOS devices1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/new-linux-kernel-memory-corruption-bug-causes-full-system-compromise-90x90.jpg Linux system service bug gives root on all major distros, exploit released1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/centos1-90x90.png CWP bugs allow code execution as root on Linux servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/mcafee-d2c-90x90.jpg McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/ezgif.com-gif-maker-12-90x90.jpg Cisco bug gives remote attackers root privileges via debug mode2 weeks ago
The post Cisco patches critical vulnerabilities in SMB routers, exploitation available first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video