Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Would this method work or do they have checks

I just thought of a way to break any copy protection on any console

my idea goes like this what if you used digital oscilloscopes to sniff each bit on the data lines between the console and the disk drive then replay that exact bit stream to the console it would have no way at all to tell if it is getting the same 1's and 0's but they have to have some way i dont understand

let me know of any ways they might detect that

submitted by /u/whypickthisname
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
signal jammers

is there any way to tell if a signal jammer is in use around you? say in a work place or in public if I suddenly lost signal could I tell if the cause is a jammer? If so how?

submitted by /u/unmatchedfailure
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Send a Email to me and get kicked out of Google Groups !!

A Feature that almost broke Google Groups !!
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on serversPost Views: 208 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Two vulnerabilities in open source monitoring platform Zabbix could allow an attacker to bypass authentication and execute arbitrary code on a targeted server.
The security flaws were found in Zabbix Web Frontend, a platform used to collect, centralize. and track metrics such as CPU load and network traffic across entire infrastructures.

Researchers from SonarSource, who discovered the bugs, noted that Zabbix is a high-profile target for threat actors due to its popularity, features, and its “privileged position in most company’s networks”. IssuesThe first vulnerability, tracked as CVE-2022-23131, which was given a severity of 9.1, is unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified.

A malicious unauthenticated actor could exploit this issue to escalate privileges and gain admin access to the Zabbix Frontend.
See Also: Complete Offensive Security and Ethical Hacking Course
A caveat to this is that to perform the attack, SAML authentication is required to be enabled, and the assailant has to know the username of Zabbix user (or use the guest account, which is disabled by default), a security advisory from Zabbix notes.

The second vulnerability found by SonarSource, tracked as CVE-2022-23134, is rated as medium severity and allows some steps of setup.php file to be reachable not only by super-administrators, but by unauthenticated users as well.

A malicious actor could pass step checks and potentially change the configuration of Zabbix Frontend, an advisory notes.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Patch nowIn a blog post from SonarSource, the researchers said that when writing and reviewing code related to important security features, “it is easy to make the same assumptions as the original developer who introduced the vulnerability”.

They wrote: “Here, there were no integration tests related to the client-side session storage that could have spotted this behavior.

“Always provide access to sensible services with extended internal accesses (e.g. orchestration, monitoring) over VPNs or a restricted set of IP addresses, harden filesystem permissions to prevent unintended changes, remove setup scripts, etc.”

Finally, the researchers recommended upgrading all instances running a Zabbix Web Frontend to 6.0.0beta2, 5.4.9, 5.0.19, or 4.0.37. See Also: Offensive Security Tool: Swaks – Swiss Army Knife for SMTP
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: How ILOVEYOU worm became the first global computer virus pandemic Source: portswigger.net Source Linkhttps://www.blackh[...]

___________________________
@hacking_Attack
@Hacking_Video