Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking on Medium
Is a WhatsApp hack possible?

https://cdn-images-1.medium.com/max/2600/0*LvxtGyBO1_qmxuGN
WhatsApp is a free and popular instant messaging application that most people use today.

Continue reading on Medium »

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
GitHub code scanning now finds more security vulnerabilities

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png GitHub code scanning now finds more security vulnerabilitiesPost Views: 120 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Code hosting platform GitHub today launched new machine learning-based code scanning analysis features that will automatically discover more common security vulnerabilities before they end up in production.
These new experimental static analysis features are now available for JavaScript and TypeScript GitHub repositories in public beta.

“With the new analysis capabilities, code scanning can surface even more alerts for four common vulnerability patterns: cross-site scripting (XSS), path injection, NoSQL injection, and SQL injection,” said GitHub’s Tiferet Gazit and Alona Hlobina.

“Together, these four vulnerability types account for many of the recent vulnerabilities (CVEs) in the JavaScript/TypeScript ecosystem, and improving code scanning’s ability to detect such vulnerabilities early in the development process is key in helping developers write more secure code.”

Security vulnerabilities discovered by the new experimental code analysis features will show up as alerts in the ‘Security’ tab of enrolled repositories.
See Also: Complete Offensive Security and Ethical Hacking Course
These new alerts are marked using an ‘Experimental’ label and will also be available via the pull requests tab.
https://www.bleepstatic.com/images/news/u/1109292/2022/GitHub_experimental-label-alerts.webp
Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhateth[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking GitHub code scanning now finds more security vulnerabilities https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png GitHub code scanning now finds more security vulnerabilitiesPost Views: 120 h…
icalhacking.com/wp-content/uploads/2022/02/012qzWe52HXVPxkc8nUrPyv-1.fit_lim.size_1200x630.v1617817629-90x90.jpg Massive LinkedIn Phishing, Bot Attacks Feed on the Job-Hungry1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Unredacter-Pixelize-90x90.gif New tool can uncover redacted, pixelated text to reveal sensitive data2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-3-1-90x90.jpg Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/banner-2022.1-release-90x90.jpg Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/acastro_210104_1777_google_0001-90x90.jpg Google Project Zero: Vendors are now quicker at fixing zero-days4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Apple-Warning-90x90.jpg Apple patches new zero-day exploited to hack iPhones, iPads, Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/f4bc-article-200611-wordpress-body-text-90x90.jpg PHP Everywhere RCE flaws threaten thousands of WordPress sites1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/178-706-450-android-patch-770x439_c-90x90.jpg Google fixes remote escalation of privileges bug on Android1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-4-90x90.jpg Qbot needs only 30 minutes to steal your credentials, emails1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/364-3648628_google-drive-90x90.jpg Google Drive integration errors created SSRF flaws in multiple applications2 weeks ago
The post GitHub code scanning now finds more security vulnerabilities first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
I made over $588k on Bug Bounty so far

How much one can earn on Bug Bounty?Continue reading on Medium »
Read more...
hacking: security in practice
Any way to ban a certain word in any website?

I was crushing on this guy for way too long. Two years passed and he is still giving me mixed messages and I hope I never see his name again.

I am wondering if there is a way to ban his name everywhere on my mac? So whenever I felt like googling him, checking his social media, etc, his name will not appear (or appear as sth else) so I can stop being so obsessed with him.

Thanks for every hackers reading this!

submitted by /u/Leanacupcake
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Someone I know has hacked into my personal laptop and has been dropping hints that they've seen everything in there, and have been monitoring my activity.

There's nothing illegal or nasty on there but they could certainly spin it to make me look bad. I think this person hates me (unjustifiably imo) and may try to make my life difficult.

I let them stay with me in a spare room and naively gave them access to my router "so they could boost the signal". I know very little about tech so the router password was unchanged and I have no VPN or internet security, other than Kaspersky antivirus. After they moved out I started getting hints that they know what I'm looking at. Again, there's nothing terrible to report but I find it incredibly creepy and intrusive.

I've changed the router password and run Malwarebytes but I don't know what else to do? Could they be viewing my screen remotely, or monitoring my internet activity? Could they even operate my laptop remotely? I mean they could even be looking at this...

submitted by /u/ihitrockswithammers
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
boko.py is an application scanner for macOS that searches for and identifies potential dylib hijacking and weak dylib vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) for application executables, as well as scripts an application may use that have the potential to be backdoored. The tool also calls out interesting files and lists them instead of manually browsing the file system for analysis. With the active discovery (https://www.kitploit.com/search/label/Discovery) function, there's no more guess work if an executable is vulnerable (https://www.kitploit.com/search/label/Vulnerable) to dylib hijacking! The reason behind creating this tool was because I wanted more control over the data Dylib Hijack Scanner discovered. Most publicly available scanners stop once they discover the first case of a vulnerable dylib without expanding the rest of the rpaths. Since sometimes the first result is expanded in a non-existent file within a SIP-protected area, I wanted to get the rest of those expanded paths. Because of this, there are false positives, so the tool assigns a certainty field for each item.
Certainty Description Definite The vulnerability (https://www.kitploit.com/search/label/Vulnerability) is 100% exploitable High If the vulnerability is related to a main executable and rpath is 2nd in the load order, there is a good chance the vulnerability is exploitable Potential This is assigned to dylibs and backdoorable scripts, worth looking into but may not be exploitable Low Low chance this is exploitable because of late load order, but knowledge is power The backbone of this tool is based off of scan.py from DylibHijack (https://github.com/synack/DylibHijack) by Patrick Wardle (@synack). Check out the Wiki for more information on how to use boko and how to use it as a class for your own purposes. (https://github.com/bashexplode/boko/wiki) Usage: boko.py [-h] (-r | -i | -p /path/to/app) (-A | -P | -b) [-oS outputfile | -oC outputfile | -oA outputfile] [-s] [-v] Parameters: Argument Description -h, --help Show this help message and exit -r, --running Check currently running processes -i, --installed Check all installed applications -p /file.app Check a specific application i.e. /Application/Safari.app -A, --active Executes executable binaries discovered to actively identify hijackable dylibs -P, --passive Performs checks only by viewing file headers (Default) -b, --both Performs both methods of vulnerability testing -oS outputfile Outputs standard output to a .log file -oC outputfile Outputs results to a .csv file -oA outputfile Outputs results to a .csv file and standard log -s, --sipdisabled Use if SIP is disabled on the system to search typically read-only paths -v, --verbose Output all results in verbose mode while script runs, without this only Definite certainty vulnerabilities are displayed to the console It is recommended only to use active mode (-A) with the -p flag and selecting a specific program. Also, it's a good idea to use -v with -oS or -oA, unless you are only looking for definite certainty vulnerabilities. Warning Note: It is highly discouraged to run this tool with the -i and (-A or -b) flags together. This combination will open every executable on your system for 3 seconds at a time. I do not take any responsibility for your system crashing or slowing down because you ran that. Additionally, if you have dormant malware on your system, this will execute it. I also recommend not scanning the whole /Applications directory (https://www.kitploit.com/search/label/Directory) if you have Xcode installed because it takes a very long time. Requirements: Python 3 python -m pip install psutil Process Flow: Passive mode: Running: Identify all running processes on system Obtain full path of running executable Read executables and identify macho headers

___________________________
@hacking_Attack
@Hacking_Video
Identify dylib relative paths that are loaded and check if files exist in that location Output hijackable dylibs and weak dylibs for running applications Installed/Application: Scan full directory of application for all files Identify executable files, scripts, and other interesting files in application directory Read executables and identify macho headers or if the file is a script Identify dylib relative paths that are loaded and check if files exist in that location Output hijackable dylibs, weak dylibs, backdoorable scripts, and interesting files (verbose only) Active mode: Running: Identify all running processes on system Obtain full path of running executable Read executables and identify macho headers Execute the executable binaries for 3 seconds and analyze rpaths that are attempted to load Output hijackable dylibs and weak dylibs for running applications Application: Scan full directory of application for all files Identify executable files, scripts, and other interesting files in application directory Read executables and identify macho headers or if the file is a script Execute the executable binaries for 3 seconds and analyze rpaths that are attempted to load Output hijackable dylibs, weak dylibs, backdoorable scripts, and interesting files (verbose only) Suggested Improvements: Multi-threading for quicker full system scan Coded by Jesse Nebling (@bashexplode)

Download Boko (https://github.com/bashexplode/boko)

___________________________
@hacking_Attack
@Hacking_Video