Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Adobe: Zero-Day Magento 2 RCE Bug Under Active AttackPost Views: 166 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 2 Minutes
A zero-day remote code-execution (RCE) bug in the Magento 2 and Adobe Commerce platforms has been actively exploited in the wild.
The security vulnerability bug (CVE-2022-24086) is a critical affair, allowing pre-authentication RCE arising from improper input validation. It scores 9.8 out of 10 on the CVSS vulnerability-severity scale, but there is one mitigating factor: An attacker would need to have administrative privileges in order to be successful.

It affects versions 2.3.7-p2 and earlier and 2.4.3-p1 and earlier of both eCommerce platforms, according to the advisory.  According to SanSec, which did a deeper dive into patching bug on Magento, the following should be taken into consideration:

* If you are running Magento 2.3 or 2.4, install the custom patch from Adobe ASAP, ideally within the next few hours;
* If you are running a version of Magento 2 between 2.3.3 and 2.3.7, you should be able to manually apply the patch, as it only concerns a few lines;
* And, if you are running Magento 2.3.3 or below, you are not directly vulnerable. However, SanSec still recommends manually implementing the given patch.

SanSec noted on Monday that the bug came to light on Jan. 27, and that “this vulnerability has a similar severity as the Magento Shoplift vulnerability from 2015. At that time, nearly all unpatched Magento stores globally were compromised in the days after the exploit publication.”
See Also: Complete Offensive Security and Ethical Hacking Course
Researchers noted on Monday that patching need not be onerous:\


If you have the time, follow the instructions to patch your #magento 2 store with the guide from @avstudnitz.

If you don't have the time? Do the quick and dirty patch described here:https://t.co/nZTlQGSBmp

It will take you less than 5 minutes, but you _have_ to patch today! https://t.co/gkhT07QgbA pic.twitter.com/7NqJMV3qzb

— willem wigman (@willemwigman) February 14, 2022
See Also: Windows vulnerability with new public exploits lets you become admin Update ASAP to Stave Off AttacksIndeed, updating is important for online merchants: The Magecart group famously targets unpatched versions of Magento in particular, looking for a way to plant credit-card skimmers on the checkout pages of eCommerce websites.

The threat actor, which is actually a consortium of many different card-harvesting subgroups, consistently evolves its skimmers to be more effective and efficient at evasion as well. For instance, in November, it added an extra browser process that uses the WebGL JavaScript API to check a user’s machine to ensure it’s not running on a virtual machine – thus evading researcher detection. And in January, an attack on Segway involved planting the skimmer by using a favicon that traditional security systems wouldn’t inspect.

For now, Adobe characterized the attacks as “very limited.” But card-skimmer activity is on the rise, and updates on the part of website owners seem sparse. Last week, SanSec reported a wave of skimming attacks targeting more than 500 sites, in particular those using outdated and unsupported Magento 1 implementations. Further data from Source Defense found as many as 50,000 to 100,000 sites that are using the end-of-life Magento 1. See Also: Offensive Security Tool: Stratus Red Team
“Magento and other eCommerce platforms have a long histo[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Adobe: Zero-Day Magento 2 RCE Bug Under Active AttackPost Views: 166 https://www.bla…
ry of vulnerabilities…Running an eCommerce website on an outdated and unpatched platform is like driving your car without your seat belt on,” said Ron Bradley, vice president, Shared Assessments, via email. “The driver is thinking, the store is right around the corner, by the time I put on my seatbelt on, I’ll be there, plus I don’t want to wrinkle my clothes. Then comes the crash!”
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: How ILOVEYOU worm became the first global computer virus pandemic Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/banner-2022.1-release-90x90.jpg Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH15 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/acastro_210104_1777_google_0001-90x90.jpg Google Project Zero: Vendors are now quicker at fixing zero-days1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Apple-Warning-90x90.jpg Apple patches new zero-day exploited to hack iPhones, iPads, Macs4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/f4bc-article-200611-wordpress-body-text-90x90.jpg PHP Everywhere RCE flaws threaten thousands of WordPress sites5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/178-706-450-android-patch-770x439_c-90x90.jpg Google fixes remote escalation of privileges bug on Android6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-4-90x90.jpg Qbot needs only 30 minutes to steal your credentials, emails1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/364-3648628_google-drive-90x90.jpg Google Drive integration errors created SSRF flaws in multiple applications1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-3-90x90.jpg Cisco patches critical vulnerabilities in SMB routers, exploitation available2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/b2b-90x90.jpg ESET antivirus bug let attackers gain Windows SYSTEM privileges2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/image6-90x90.png Cloudflare launches a paid public bug bounty program2 weeks ago
The post Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
The Fear of Getting Hacked.

Hey, this wouldn’t be a typical post of just a standardized computer question rather a more specific one.

I know little about hacking, but I know that it’s important to not get hacked. I read things like “well I’m not a specific target” or “I don’t have anything valuable to hack”

During the download, I spilled water on my keyboard, which caused it to break malfunction or what. It would type “//zxcv.bnm” or “xccxcx” over and over. My entire bottom keys - z through m was completely different. This started to happen the exact moment the DL finished. I thought it was a virus or hacker, or something.

I even used a restore point and I deleted the downloads, ran my AV twice and I typed with it to get the same result. I switched out keyboards to avail, it works fine. I just ran the AV again, and I stared at my empty screen for a few seconds

I realized I’m not prepared at all incase of something like a virus or something similar. I had a panic attack right away, because in the past I was a victim of sextortion, eventually it passed but the file is still out there and now I can never have a political career (lol). I hope to erase it one day, but it’s given me spooks from it,

The point is what can I do to stay protected, I know I can’t beat the “fed” or the entire system, but I just want to stay well guarded in case something happens. What are the best anti viruses, what are the key things to look for, what are the best tools.

Any help would be appreciated.

TDLR: I had a spook that PC was compromised , and am wondering what are the best tools to stay guarded.

submitted by /u/marvelistcomplex
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to use software that might be infected without compromising the entire PC?

Hello, i have recently come across a piece of software which i have wanted for a couple of years now but my windows detected it as a trojan, and I asked a couple of people to check out the software and they said its false positive, but i am not competent enough to verify it myself so i wanted to know is there a way from me to use that software in windows sandbox and from what I hear sandbox gets whipped when we close it , is there a way around this so i can have the software on sandbox until I want to uninstall it



Thanks

submitted by /u/Benimaru101
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is there a way to see an user password on Windows 10?

I wanted to get in hand of the school laptop password. It has no special blocking software, but i cant install programms on it. But I can insert a USB driver with a program installed on it

submitted by /u/Odd-Permission8793
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Log4J-Detector : Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046

Log4J-Detector is a Scanner that detects vulnerable Log4J versions to help teams assess their exposure to CVE-2021-44228 (CRITICAL), CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. Can search for Log4J instances by carefully examining the complete file-system, including all installed applications. It is able to find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too!

Introduction

Currently reports log4j-core versions 2.3.2, 2.12.4, and 2.17.1 as _SAFE_, 2.3.1, 2.12.2, 2.12.3, 2.15.0, 2.16.0, and 2.17.0 as _OKAY_ and all other versions as _VULNERABLE_ (although it does report pre-2.0-beta9 as _POTENTIALLY_SAFE_). It reports older log4j-1.x versions as _OLD_.

Can correctly detect log4j inside executable spring-boot jars/wars, dependencies blended into uber jars, shaded jars, and even exploded jar files just sitting uncompressed on the file-system (aka *.class).

We currently maintain a collection of log4j-samples we use for testing.

Example Usage

java -jar log4j-detector-2021.12.29.jar ./samples

github.com/mergebase/log4j-detector v2021.12.29 (by mergebase.com) analyzing paths (could take a while).
— Note: specify the ‘–verbose’ flag to have every file examined printed to STDERR.
false-hits/log4j-core-2.12.2.jar contains Log4J-2.x == 2.12.2 OKAY
false-hits/log4j-core-2.12.3.jar contains Log4J-2.x == 2.12.3 OKAY
false-hits/log4j-core-2.12.4.jar contains Log4J-2.x == 2.12.4 SAFE
false-hits/log4j-core-2.15.0.jar contains Log4J-2.x == 2.15.0 OKAY
false-hits/log4j-core-2.16.0.jar contains Log4J-2.x == 2.16.0 OKAY
false-hits/log4j-core-2.17.0.jar contains Log4J-2.x == 2.17.0 OKAY
false-hits/log4j-core-2.17.1.jar contains Log4J-2.x >= 2.17.1 SAFE
false-hits/log4j-core-2.3.1.jar contains Log4J-2.x == 2.3.1 OKAY
false-hits/log4j-core-2.3.2.jar contains Log4J-2.x == 2.3.2 SAFE
true-hits/log4j-core-2.0-beta9.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE true-hits/log4j-core-2.10.0.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.10.0.zip contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.11.0.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.11.1.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.11.2.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.12.0.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.12.1.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.14.0.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.14.1.jar contains Log4J-2.x >= 2.10.0 VULNERABLE
true-hits/log4j-core-2.2.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE true-hits/log4j-core-2.3.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE true-hits/log4j-core-2.4.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE true-hits/log4j-core-2.4.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE true-hits/log4j-core-2.9.1.jar contains Log4J-2.x >= 2.0-beta9 (< 2.10.0) VULNERABLE
old-hits/log4j-1.1.3.jar contains Log4J-1.x <=OLD
old-hits/log4j-1.2.17.jar contains Log4J-1.x <=OLD
old-hits/log4j-core-2.0-beta2.jar contains Log4J-2.x <=POTENTIALLY_SAFE (Did you remove JndiLookup.class?)

Understanding The Results

_VULNERABLE_ -> You need to upgrade or remove this file.

_OKAY_ -> We report this for Log4J versions 2.3.1, 2.12.2, 2.12.3, 2.15.0, 2.16.0, and 2.17.0. We recommend upgrading to 2.17.1.

_SAFE_ -> We currently only report this for Log4J versions 2.3.2, 2.12.4, and 2.17.1 (and greater).

_OLD_ -> You are safe from CVE-2021-44228, but should plan to upgrade because Log4J 1.2.x has been EOL for 7 years and has [...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Log4J-Detector : Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046 Log4J-Detector is a Scanner that detects vulnerable Log4J versions to help teams assess their…
several known-vulnerabilities.

_POTENTIALLY_SAFE_ -> The “JndiLookup.class” file is not present, either because your version of Log4J is very old (pre 2.0-beta9), or because someone already removed this file. Make sure it was someone in your team or company that removed “JndiLookup.class” if that’s the case, because attackers have been known to remove this file themselves to prevent additional competing attackers from gaining access to compromised systems. Usage

java -jar log4j-detector-2021.12.29.jar
Usage: java -jar log4j-detector-2021.12.29.jar [–verbose] [–json] [–stdin] [–exclude=X] [paths to scan…]
–json – Output STDOUT results in JSON. (Errors/warning still emitted to STDERR)
–stdin – Read STDIN for paths to explore (one path per line)
–exclude=X – Where X is a JSON list containing full paths to exclude. Must be valid JSON.
Example: –exclude='[“/dev”, “/media”, “Z:\TEMP”]’
Exit codes: 0 = No vulnerable Log4J versions found.
1 = At least one legacy Log4J 1.x version found.
2 = At least one vulnerable Log4J version found.
About – MergeBase log4j detector (version 2021.12.29)
Docs – https://github.com/mergebase/log4j-detector
(C) Copyright 2021 Mergebase Software Inc. Licensed to you via GPLv3.

Build From Source

git clone https://github.com/mergebase/log4j-detector.git
cd log4j-detector/
mvn install
java -jar target/log4j-detector-latest.jar Download
Flare-Qdb - Command-line And Python Debugger For Instrumenting And Modifying Native Software Behavior On Windows And Linux

flare-qdb is a command-line and scriptable Python-based tool for evaluating and manipulating native program state. It uses Vivisect to set a breakpoint on each queried instruction and executes Python code when hit. flare-qdb frees the analyst to take a nonlinear approach to dynamic analysis that accommodates the questions that arise in the course of normal debugging and static analysis. flare-qdb answers these questions without requiring the analyst to manually set up an interactive debugger session and navigate the program counter to that code location. Here are some examples of spot questions flare-qdb can answer: Does eax always equal this value at this point? What was eax equal to before this branch? What values will this string assume throughout this loop? At the first iteration of the inner loop, what base address is used? Is the program even going to hit this logic? Which code executes first? Does the number of loop iterations depend on the value of argv1? Can I alter the command-line arguments to avoid this condition? flare-qdb can also be used to facilitate automated, repeatable manipulation of program execution. Here are some examples of useful applications: Executing a string decoder with different arguments to quickly extract all the strings used by a malware sample. Overriding the arguments to Sleep() to permit rapid iterative testing of a custom command and control (C2) server. Telling a privilege escalation tool that its integrity level is 0x1000 (MANDATORYLOWRID) in order to induce it to execute its exploit code. Repeatably automating the unpacking of a packer that jumps into one or more non-deterministic heap locations. flare-qdb accepts multiple queries that take the form of a program counter or Vivisect expression paired with some Python text to evaluate in the flare-qdb scripting environment. Vivisect expressions can be used to specify simple constant program counter values like "0x401000", symbolic expressions like "kernel32.Sleep", and more. Vivisect expressions can also incorporate register and memory state to articulate sophisticated conditions, such as "not eax or (( edx > 3) and (poi(ebp-8) < 5))". The command line argument format for this is: -at <vexpr-pc> <pythontext> flare-qdb also supports conditional evaluation based on the truth value of a Vivisect expression: -at-if <vexpr-pc> <vexpr-conds> <pythontext> flare-qdb provides several builtins for convenient debugging, which are available both from the command line and as methods of its Qdb class. flare-qdb has been tested primarily on Windows, but works on Linux. Unfortunately, the Darwin port of Vivisect's vtrace.Trace class is incomplete, so flare-qdb does not support OSX. Example Scripts flare-qdb comes with De-DOSfuscator, which is a tool for decoding obfuscated batch files by running them. Details can be found in the De-DOSfuscator Guide or by reading the blog Cmd and Conquer: De-DOSfuscation with flare-qdb. Detailed Information Information about installing flare-qdb is available in the Installation Guide. Information about using flare-qdb on the command line is available in the Command Line Usage Guide. Information about scripting with flare-qdb is available in the Scripting Guide. Qdb class methods specific to scripting flare-qdb can be found in the Methods Reference. A full reference of flare-qdb's builtins (available both from the CLI and as instance methods) is available in the Builtins Reference or by typing flareqdb --help-builtins after installing flare-qdb. De-DOSfuscator documentation can be found in the De-DOSfuscator Guide. Troubleshooting information can be found in the Troubleshooting Guide. Acknowledgements and thoughts about future functionality that may be useful can be found in the Notes. Download Flare-Qdb
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Flare-Qdb - Command-line And Python Debugger For Instrumenting And Modifying Native Software Behavior On Windows And Linux

https://blogger.googleusercontent.com/img/a/AVvXsEhXEBPvZVniJMV2UX-JBx_fVGiiycsfH8MQTdDaC2lQ2JMvHdQqd_DpZAnDYupSrBsYUuaYAi7By3lSziRjxYDUw1B9piisn7PxiidW74f-Rw26x3XxEkqu1dW2wuOI-J5pV9pPeOy0bb1-2vmOomsv-PFyD-egcppmRsr-GugjK81AE9h7gKBioOxi=w640-h236 flare-qdb is a command-line and scriptable Python-based tool for evaluating and manipulating native program state. It uses Vivisect to set a breakpoint on each queried instruction and executes Python code when hit.

flare-qdb frees the analyst to take a nonlinear approach to dynamic analysis that accommodates the questions that arise in the course of normal debugging and static analysis. flare-qdb answers these questions without requiring the analyst to manually set up an interactive debugger session and navigate the program counter to that code location.
Here are some examples of spot questions flare-qdb can answer:

* Does eax always equal this value at this point?
* What was eax equal to before this branch?
* What values will this string assume throughout this loop?
* At the first iteration of the inner loop, what base address is used?
* Is the program even going to hit this logic?
* Which code executes first?
* Does the number of loop iterations depend on the value of argv[1]?
* Can I alter the command-line arguments to avoid this condition?

flare-qdb can also be used to facilitate automated, repeatable manipulation of program execution. Here are some examples of useful applications:

* Executing a string decoder with different arguments to quickly extract all the strings used by a malware sample.
* Overriding the arguments to Sleep()to permit rapid iterative testing of a custom command and control (C2) server.
* Telling a privilege escalation tool that its integrity level is 0x1000 (MANDATORY_LOW_RID) in order to induce it to execute its exploit code.
* Repeatably automating the unpacking of a packer that jumps into one or more non-deterministic heap locations.

flare-qdb accepts multiple queries that take the form of a program counter or Vivisect expression paired with some Python text to evaluate in the flare-qdb scripting environment. Vivisect expressions can be used to specify simple constant program counter values like "0x401000", symbolic expressions like "kernel32.Sleep", and more. Vivisect expressions can also incorporate register and memory state to articulate sophisticated conditions, such as "not eax or (( edx > 3) and (poi(ebp-8) < 5))".

The command line argument format for this is: -at <vexpr-pc<pythontext flare-qdb also supports conditional evaluation based on the truth value of a Vivisect expression: -at-if <vexpr-pc<vexpr-conds<pythontext flare-qdb provides several builtins for convenient debugging, which are available both from the command line and as methods of its Qdbclass.

flare-qdb has been tested primarily on Windows, but works on Linux. Unfortunately, the Darwin port of Vivisect's vtrace.Traceclass is incomplete, so flare-qdb does not support OSX. Example Scriptsflare-qdb comes with De-DOSfuscator, which is a tool for decoding obfuscated batch files by running them. Details can be found in the De-DOSfuscator Guide or by reading the blog Cmd and Conquer: De-DOSfuscation with flare-qdb. Detailed InformationInformation about installing flare-qdb is available in the Installation Guide.

Information about using flare-qdb on the command line is available in the Command Line Usage Guide.

Information about scripting with flare-qdb is available in the Scripting Guide. Qdbclass methods spec[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Flare-Qdb - Command-line And Python Debugger For Instrumenting And Modifying Native Software Behavior On Windows And Linux https://blogger.googleusercontent.com/img/a/AVvXsEhXEBPvZVniJMV2UX-JBx_fVGiiycsfH8MQTdDaC2lQ2JMvHdQqd_DpZ…
ific to scripting flare-qdb can be found in the Methods Reference.

A full reference of flare-qdb's builtins (available both from the CLI and as instance methods) is available in the Builtins Reference or by typing flareqdb --help-builtinsafter installing flare-qdb.

De-DOSfuscator documentation can be found in the De-DOSfuscator Guide.

Troubleshooting information can be found in the Troubleshooting Guide.

Acknowledgements and thoughts about future functionality that may be useful can be found in the Notes. Download Flare-Qdb
Неочевидное об XSS и HTML-энкодинге

Многие знают о том, что перед тем, как получить значение атрибута тега, браузер декодирует HTML-сущности внутри. Скажем, если попытаться…Continue reading on Medium »
Read more...
Flare-Qdb - Command-line And Python Debugger For Instrumenting And Modifying Native Software Behavior On Windows And Linux
http://www.kitploit.com/2022/02/flare-qdb-command-line-and-python.html