Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
how does iBoss SSL Decryption work?

Recently got in trouble at school, they asked me why i was searching erh.. specific things,

they pulled me aside and showed me. and i was totally shocked by what i saw they had http requests i made from my phone to google.com WITH the ?q= GET parameter included! and yes this is my phone and not given to me by them and i never installed a root ca or any other spyware shit i asked how this was even possible because HTTPS should prevent being able to see GET query info, they told me they used some thing called iBoss which can apparently decrypt HTTPS traffic without needing to install anything, i would have said bullshit if not for literally seeing it. i found this-
https://www.iboss.com/solution-briefs/ssl-decryption/ talking about it

what is it? has a trusted CA gone rouge?? or is it something else

submitted by /u/PlayStationHaxor
[link] [comments]
hacking: security in practice
Can someone explain to me how hacking social media works?

I had one of my accounts logged into tonight by a device that isn’t mine.. and I can’t seem to figure out how they would have gotten my password. The IP address is near my area.. so I’m even more creeped out.

Please help!

submitted by /u/Incrimnatinggoats_
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Gain real followers or likes on Instagram using the Followers Gallery app

We love to share posts on Instagram merely because we get likes, comment and shares from our friends and family members. The post with the maximum number of likes, shares and comment is considered to be with the highest engagement rate. People often want to increase the number of followers and attain 1 million followers […]

The post Gain real followers or likes on Instagram using the Followers Gallery app appeared first on Kali Linux Tutorials.
Sent by @TheFeedReaderBot
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Zero-Day Bug Impacts Problem-Plagued Cisco SOHO RoutersPost Views: 47
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
Cisco Systems said it will not fix a critical vulnerability found in three of its SOHO router models. The bug, rated 9.8 in severity out of 10, could allow unauthenticated remote users to hijack targeted equipment and gain elevated privileges within effected systems.
The three Cisco router models (RV110W, RV130, and RV215W) and one VPN firewall device (RV130W) are of varying age and have reached “end of life” and will not be patched, according to Cisco.

The company is advising customers to replace the equipment.

“Cisco has not released and will not release software updates to address the vulnerability described in this advisory. The Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers have entered the end-of-life process,” the company wrote. The company added no workaround is available either. Buffer Overflow BugIn the Cisco Systems Security Advisory posted Wednesday, the networking giant said the flaw is due to improper validation of user-supplied input in the web-based management interface.

“An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the affected device,” Cisco wrote.

Workaround mitigation options, such as disabling the web-based management interface, are not available. “The web-based management interface of these devices is available through a local LAN connection, which cannot be disabled, or through the WAN connection if the remote management feature is enabled,” Cisco wrote. “[However by] default, the remote management feature is disabled on these devices,” Cisco wrote.
See Also: Fake Netflix App on Google Play Spreads Malware Via WhatsApp Past Router ProblemsEach of the routers (RV110W, RV130 and RV215W) have had a rocky past. In 2019, hackers exploited a similar critical bug (CVE-2019-1663) after a public proof of concept was made available by researchers with Pen Test Partners.

In its blog post, Pen Test Partners attributed the root cause of 2019 bug to Cisco’s reliance on the use of insecure C programming language, such as strcpy (string copy).

Researcher Treck Zhou, who is credited for finding the 2021 bug, provided no such similar analysis. Unlike the 2019 bug, Cisco said it “is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.”
See Also: Offensive Security Tool: DirDar One More Critical Router BugOn Wednesday, Cisco also warned of second critical bug, with a severity rating of 9.8, that impacts its Cisco SD-WAN vManage software. Two additional high-severity bugs were also reported impacting the same Cisco SD-WAN vManage software.

“Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system,” Cisco wrote.

Each of these bugs (CVE-2021-1137, CVE-2021-1479, CVE-2021-1480) are separate and cannot and do not need to be chained together. “The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability,” Cisco wrote.

[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Zero-Day Bug Impacts Problem-Plagued Cisco SOHO RoutersPost Views: 47 …
The most serious of the bugs (CVE-2021-1479) impacts Cisco’ SD-WAN vManage software. It allows unauthenticated attackers to trigger a buffer overflow attack. See Also: Hacking Stories: When two young hackers played war games with Pentagon“The vulnerability is due to improper validation of user-supplied input to the vulnerable component. An attacker could exploit this vulnerability by sending a crafted connection request to the vulnerable component that, when processed, could cause a buffer overflow condition. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system with root privileges,” Cisco describes.

Cisco has released patches for vulnerabilities impacting its SD-WAN vManage Software. The other two CVE records (CVE-2021-1137 and CVE-2021-1480) are rated high-severity also have patches available.

“[These] vulnerabilities affect Cisco devices if they are running a vulnerable release of Cisco SD-WAN vManage Software,” Cisco wrote. It added, it was unaware of any known public exploits tied to these three vulnerabilities. The vulnerability disclosures were part of a larger disclosure of bugs and fixes that totaled 16 flaws ranging from critical, high severity to medium.
Source: threatpost.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/phph-90x90.jpg PHP Infiltrated with Backdoor Malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/ransomware_global_small-90x90.jpg Insurance Giant CNA Hit with Novel Ransomware Attack2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Microsoft-Teams-90x90.jpg Microsoft Offers Up To $30K For Teams Bugs2 weeks ago
The post Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers first appeared on Black Hat Ethical Hacking.
hacking: security in practice
I’m trying to hack someone (for a good reason). Sorry if this is the wrong sub

This guy tried to break into my car, I chased him out and he dropped his Samsung phone. I have his phone, phone number, email address, some text notifications, recent calls. I’ve reverse searched the number on white pages and got nothing. What can I do with this information; pretty sure the police will do nothing.

submitted by /u/munchingonsometoes
[link] [comments]
hacking: security in practice
I cant change my Mac adress

When i try to change my Mac adress it didnt work. Is there an another way to make it?

root@kali:~# macchanger -r wlan0

Current MAC: 00:e0:4c:10:ed:53 (REALTEK SEMICONDUCTOR CORP.) Permanent MAC: 00:e0:4c:10:ed:53 (REALTEK SEMICONDUCTOR CORP.) New MAC: 76:9f:ed:09:77:fc (unknown) Network driver didn't actually change to the new MAC!!

submitted by /u/TruvasizHelen
[link] [comments]
hacking: security in practice
Google translate images (batch) in pc or mobile.

Google translate I believe freely translates images from mobile app but there is no equivalent option for pc.I was thinking has anyone reverse engineered the app to make it for pc with batch processing option .

submitted by /u/Shojikina_otoko
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
hackind

https://cdn-images-1.medium.com/max/1920/1*iGo79oROsmqu39jGcJXHPQ.png
Himanshu Yadav — ethical hacking free ,Computer programmer, and Entrepreneur. tips and tutorials , Android testing , Custom Roms and Tech…

Continue reading on Medium »
Deep Web
Facebook Leak

If this is not the right sub to ask, please point me to the correct one:

Many news outlets reported the huge Facebook leak of over 500 Million users and pointed out it occured on some „low-level hacking forums“. One even mentioned it is a Torrent of the size of 20GB, but I couldn‘t find it anywhere. Does anyone know where I could find it?

submitted by /u/Serpentix6
[link] [comments]